From bcabcb618c4461fc97fe12fab67635df8da9578a Mon Sep 17 00:00:00 2001 From: MacRimi Date: Tue, 22 Sep 2026 18:24:59 +0200 Subject: [PATCH] feat(oci): run official container images as native LXC containers Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) --- .github/scripts/build_translation_cache.py | 270 +- .github/workflows/build-translation-cache.yml | 7 + .gitignore | 14 +- AppImage/components/audit-comparison.tsx | 49 +- AppImage/components/audit-report.tsx | 103 +- AppImage/components/disk-exclusions.tsx | 264 + AppImage/components/host-backup.tsx | 8 +- AppImage/components/settings.tsx | 3 + AppImage/components/storage-overview.tsx | 47 +- AppImage/components/virtual-machines.tsx | 27 +- AppImage/messages/de/common.json | 46 +- AppImage/messages/en/common.json | 71 +- AppImage/messages/es/common.json | 75 +- AppImage/messages/fr/common.json | 46 +- AppImage/messages/it/common.json | 42 +- AppImage/messages/pt/common.json | 42 +- AppImage/messages/sk/common.json | 12 + AppImage/messages/sv/common.json | 40 +- AppImage/scripts/audit_checks.py | 50 +- AppImage/scripts/audit_store.py | 36 +- AppImage/scripts/build_appimage.sh | 1 + AppImage/scripts/disk_identity.py | 76 + AppImage/scripts/disk_temperature_history.py | 130 +- AppImage/scripts/flask_audit_routes.py | 27 +- AppImage/scripts/flask_health_routes.py | 116 + AppImage/scripts/flask_server.py | 75 +- AppImage/scripts/health_persistence.py | 79 +- AppImage/scripts/lxc_apps.py | 72 +- AppImage/scripts/oci_manager.py | 17 +- install_proxmenux.sh | 9 + install_proxmenux_beta.sh | 8 +- lang/de.json | 2002 +++ lang/es.json | 1957 +++ lang/fr.json | 2008 +++ lang/it.json | 1988 +++ lang/pt.json | 2007 +++ lang/sk.json | 1998 +++ lang/sv.json | 1981 +++ oci/PACKAGE-CONTENTS.md | 13 + oci/README.md | 484 + .../secure-gateway.json} | 0 oci/catalog/apps/2fauth.json | 423 + oci/catalog/apps/actualbudget.json | 400 + oci/catalog/apps/adguard-home.json | 481 + oci/catalog/apps/adguardhome-sync.json | 248 + oci/catalog/apps/adminer.json | 360 + oci/catalog/apps/airsonic-advanced.json | 431 + oci/catalog/apps/albyhub.json | 463 + oci/catalog/apps/alist-sync.json | 400 + oci/catalog/apps/alist.json | 401 + oci/catalog/apps/altus.json | 373 + oci/catalog/apps/amule.json | 465 + oci/catalog/apps/anaconda3.json | 434 + oci/catalog/apps/anythingllm.json | 441 + oci/catalog/apps/apprise-api.json | 265 + oci/catalog/apps/archivebox.json | 747 + oci/catalog/apps/ardour.json | 369 + oci/catalog/apps/audacity.json | 372 + oci/catalog/apps/audiobookshelf.json | 476 + oci/catalog/apps/autobrr.json | 405 + oci/catalog/apps/azahar.json | 264 + oci/catalog/apps/babybuddy.json | 248 + oci/catalog/apps/bambustudio.json | 279 + oci/catalog/apps/bazarr.json | 275 + oci/catalog/apps/beaverhabittracker.json | 444 + oci/catalog/apps/beets.json | 273 + oci/catalog/apps/bentopdf.json | 418 + oci/catalog/apps/bitcoin-knots.json | 247 + oci/catalog/apps/blade-of-agony.json | 256 + oci/catalog/apps/blender.json | 373 + oci/catalog/apps/blinko.json | 581 + oci/catalog/apps/boinc.json | 421 + oci/catalog/apps/bookstack.json | 297 + oci/catalog/apps/brave.json | 273 + oci/catalog/apps/budge.json | 248 + oci/catalog/apps/calibre-web.json | 279 + oci/catalog/apps/calibre.json | 522 + oci/catalog/apps/calligra.json | 373 + oci/catalog/apps/changedetection.io.json | 255 + oci/catalog/apps/chatbot-ui.json | 385 + oci/catalog/apps/chatgpt-next-web.json | 416 + oci/catalog/apps/chrome.json | 280 + oci/catalog/apps/chromium.json | 280 + oci/catalog/apps/cloudbeaver.json | 403 + oci/catalog/apps/cloudflared.json | 394 + oci/catalog/apps/clumoove.json | 662 + oci/catalog/apps/code-server.json | 290 + oci/catalog/apps/codeproject-ai.json | 417 + oci/catalog/apps/convertx.json | 427 + oci/catalog/apps/cops.json | 264 + oci/catalog/apps/copyparty.json | 434 + oci/catalog/apps/crafty.json | 535 + oci/catalog/apps/cura.json | 372 + oci/catalog/apps/darktable.json | 373 + oci/catalog/apps/databag.json | 393 + oci/catalog/apps/davos.json | 257 + oci/catalog/apps/ddclient.json | 225 + oci/catalog/apps/ddns-go.json | 401 + oci/catalog/apps/ddns-updater.json | 552 + oci/catalog/apps/deepseek-ocr-nvidia.json | 476 + oci/catalog/apps/deluge.json | 293 + oci/catalog/apps/dify.json | 1080 ++ oci/catalog/apps/digikam.json | 272 + oci/catalog/apps/diskover.json | 600 + oci/catalog/apps/docker-volume-backup.json | 328 + oci/catalog/apps/docmost.json | 588 + oci/catalog/apps/dogwalk.json | 268 + oci/catalog/apps/dokuwiki.json | 248 + oci/catalog/apps/dolphin.json | 272 + oci/catalog/apps/doplarr.json | 351 + oci/catalog/apps/doplarr_rs.json | 209 + oci/catalog/apps/dosbox-staging.json | 264 + oci/catalog/apps/doublecommander.json | 389 + oci/catalog/apps/downtify.json | 459 + oci/catalog/apps/dsh-harness.json | 405 + oci/catalog/apps/duckdns.json | 370 + oci/catalog/apps/duckstation.json | 269 + oci/catalog/apps/duplicati.json | 321 + oci/catalog/apps/eden.json | 268 + oci/catalog/apps/emby-official.json | 486 + oci/catalog/apps/emby.json | 464 + oci/catalog/apps/embystat.json | 428 + oci/catalog/apps/emulatorjs.json | 555 + oci/catalog/apps/esphome.json | 421 + oci/catalog/apps/etherpad.json | 522 + oci/catalog/apps/excalidraw.json | 363 + oci/catalog/apps/faster-whisper.json | 276 + oci/catalog/apps/ferdium.json | 373 + oci/catalog/apps/filebrowser-quantum.json | 390 + oci/catalog/apps/filedrop.json | 427 + oci/catalog/apps/fileflows.json | 632 + oci/catalog/apps/filezilla.json | 373 + oci/catalog/apps/firefly.json | 495 + oci/catalog/apps/firefox.json | 280 + oci/catalog/apps/flaresolverr.json | 435 + oci/catalog/apps/flexget.json | 286 + oci/catalog/apps/flowise.json | 495 + oci/catalog/apps/flycast.json | 268 + oci/catalog/apps/foldingathome.json | 262 + oci/catalog/apps/freecad.json | 373 + oci/catalog/apps/freshrss-official.json | 445 + oci/catalog/apps/freshrss.json | 241 + oci/catalog/apps/frigate.json | 1130 ++ oci/catalog/apps/gateway-go.json | 401 + oci/catalog/apps/gimp.json | 373 + oci/catalog/apps/gitea.json | 432 + oci/catalog/apps/github-desktop.json | 480 + oci/catalog/apps/gitqlient.json | 373 + oci/catalog/apps/glances.json | 510 + oci/catalog/apps/gopeed.json | 437 + oci/catalog/apps/grafana.json | 401 + oci/catalog/apps/grav.json | 241 + oci/catalog/apps/grocy.json | 250 + oci/catalog/apps/gzdoom.json | 269 + oci/catalog/apps/habridge.json | 255 + oci/catalog/apps/handbrake-jlesage.json | 610 + oci/catalog/apps/handbrake.json | 392 + oci/catalog/apps/haos-one.json | 754 + oci/catalog/apps/healthchecks.json | 381 + oci/catalog/apps/hedgedoc.json | 318 + oci/catalog/apps/heimdall.json | 255 + oci/catalog/apps/helium.json | 264 + oci/catalog/apps/hermes.json | 510 + oci/catalog/apps/hishtory-server.json | 238 + oci/catalog/apps/holoplay.json | 390 + oci/catalog/apps/homeassistant-official.json | 515 + oci/catalog/apps/homeassistant.json | 376 + oci/catalog/apps/homebridge.json | 382 + oci/catalog/apps/htpcmanager.json | 241 + oci/catalog/apps/hugo.json | 446 + oci/catalog/apps/immich.json | 1979 +++ oci/catalog/apps/index-tts.json | 423 + oci/catalog/apps/inkscape.json | 373 + oci/catalog/apps/intellij-idea.json | 272 + oci/catalog/apps/jackett.json | 271 + oci/catalog/apps/jdownloader.json | 1017 ++ oci/catalog/apps/jellyfin-official.json | 528 + oci/catalog/apps/jellyfin.json | 643 + oci/catalog/apps/jellyseerr.json | 433 + oci/catalog/apps/jenkins.json | 439 + oci/catalog/apps/joplin.json | 268 + oci/catalog/apps/kali-linux.json | 373 + oci/catalog/apps/karakeep.json | 622 + oci/catalog/apps/kasm.json | 444 + oci/catalog/apps/kavita-jvmilazz0.json | 444 + oci/catalog/apps/kavita.json | 258 + oci/catalog/apps/kdenlive.json | 373 + oci/catalog/apps/keepassxc.json | 373 + oci/catalog/apps/kicad.json | 373 + oci/catalog/apps/kimai.json | 569 + oci/catalog/apps/kometa.json | 260 + oci/catalog/apps/komga.json | 484 + oci/catalog/apps/krita.json | 379 + oci/catalog/apps/label-studio.json | 427 + oci/catalog/apps/langflow.json | 505 + oci/catalog/apps/lazylibrarian.json | 281 + oci/catalog/apps/ldap-auth.json | 252 + oci/catalog/apps/librechat.json | 1305 ++ oci/catalog/apps/libredb-studio.json | 500 + oci/catalog/apps/libreoffice.json | 389 + oci/catalog/apps/librespeed.json | 304 + oci/catalog/apps/librewolf.json | 380 + oci/catalog/apps/lidarr.json | 275 + oci/catalog/apps/limnoria.json | 241 + oci/catalog/apps/linkwarden.json | 701 + oci/catalog/apps/llama-factory-nvidia.json | 404 + oci/catalog/apps/llamacpp.json | 430 + oci/catalog/apps/lm-studio.json | 256 + oci/catalog/apps/logseq.json | 502 + oci/catalog/apps/lollypop.json | 373 + oci/catalog/apps/luanti.json | 232 + oci/catalog/apps/lucky.json | 397 + oci/catalog/apps/lychee.json | 320 + oci/catalog/apps/lyrionmusicserver.json | 579 + oci/catalog/apps/makemkv.json | 455 + oci/catalog/apps/mame.json | 285 + oci/catalog/apps/manyfold.json | 279 + oci/catalog/apps/mariadb.json | 283 + oci/catalog/apps/mastodon.json | 521 + oci/catalog/apps/maybe.json | 766 + oci/catalog/apps/mediaelch.json | 372 + oci/catalog/apps/medusa-official.json | 477 + oci/catalog/apps/medusa.json | 273 + oci/catalog/apps/melonds.json | 265 + oci/catalog/apps/memos.json | 428 + oci/catalog/apps/mineos-node.json | 468 + oci/catalog/apps/minisatip.json | 373 + oci/catalog/apps/mkvtoolnix.json | 376 + oci/catalog/apps/mongodb.json | 444 + oci/catalog/apps/mongodb4.json | 444 + oci/catalog/apps/monica-official.json | 594 + oci/catalog/apps/monica.json | 311 + oci/catalog/apps/motioneye.json | 426 + oci/catalog/apps/msedge.json | 386 + oci/catalog/apps/mstream.json | 257 + oci/catalog/apps/mullvad-browser.json | 486 + oci/catalog/apps/mylar3.json | 273 + oci/catalog/apps/myspeed.json | 402 + oci/catalog/apps/mysql-workbench.json | 479 + oci/catalog/apps/n8n.json | 420 + oci/catalog/apps/navidrome.json | 477 + oci/catalog/apps/netbird.json | 467 + oci/catalog/apps/netbox.json | 395 + oci/catalog/apps/netdata.json | 679 + oci/catalog/apps/netronome.json | 468 + oci/catalog/apps/nextcloud-official.json | 413 + oci/catalog/apps/nextcloud-stack.json | 613 + oci/catalog/apps/nextcloud.json | 257 + oci/catalog/apps/nginx.json | 262 + oci/catalog/apps/nginxproxymanager.json | 457 + oci/catalog/apps/ngircd.json | 241 + oci/catalog/apps/node-red.json | 401 + oci/catalog/apps/nzbfast.json | 511 + oci/catalog/apps/nzbget.json | 272 + oci/catalog/apps/nzbhydra2.json | 258 + oci/catalog/apps/obsidian.json | 373 + oci/catalog/apps/ollama.json | 463 + oci/catalog/apps/ombi.json | 248 + oci/catalog/apps/onlyoffice.json | 264 + oci/catalog/apps/open-webui-cuda.json | 468 + oci/catalog/apps/open-webui-ollama.json | 469 + oci/catalog/apps/open-webui.json | 451 + oci/catalog/apps/openclaw.json | 502 + oci/catalog/apps/openhab.json | 543 + oci/catalog/apps/openhands.json | 471 + oci/catalog/apps/openlist.json | 437 + oci/catalog/apps/openshot.json | 372 + oci/catalog/apps/openspeedtest.json | 365 + oci/catalog/apps/openssh-server.json | 390 + oci/catalog/apps/openvscode-server.json | 269 + oci/catalog/apps/opera.json | 379 + oci/catalog/apps/opodsync.json | 399 + oci/catalog/apps/orcaslicer.json | 273 + oci/catalog/apps/oscam.json | 352 + oci/catalog/apps/overseerr.json | 420 + oci/catalog/apps/pairdrop.json | 252 + oci/catalog/apps/paperless-ngx.json | 669 + oci/catalog/apps/pcsx2.json | 272 + oci/catalog/apps/pdfding.json | 487 + oci/catalog/apps/peanut.json | 411 + oci/catalog/apps/pelorus.json | 349 + oci/catalog/apps/petio.json | 533 + oci/catalog/apps/photoprism.json | 471 + oci/catalog/apps/phpmyadmin.json | 255 + oci/catalog/apps/pidgin.json | 373 + oci/catalog/apps/pihole.json | 506 + oci/catalog/apps/pinchflat.json | 459 + oci/catalog/apps/pingvin-share.json | 442 + oci/catalog/apps/piper.json | 290 + oci/catalog/apps/piwigo.json | 257 + oci/catalog/apps/planka.json | 304 + oci/catalog/apps/playit-agent.json | 335 + oci/catalog/apps/plex-official.json | 528 + oci/catalog/apps/plex.json | 471 + oci/catalog/apps/pocketbase.json | 400 + oci/catalog/apps/podfetch.json | 460 + oci/catalog/apps/portainer.json | 457 + oci/catalog/apps/postgresql.json | 454 + oci/catalog/apps/ppsspp.json | 256 + oci/catalog/apps/projectsend.json | 257 + oci/catalog/apps/prowlarr.json | 241 + oci/catalog/apps/psitransfer.json | 422 + oci/catalog/apps/pwndrop.json | 248 + oci/catalog/apps/pycharm.json | 264 + oci/catalog/apps/pydio-cells.json | 333 + oci/catalog/apps/pyload-ng.json | 264 + oci/catalog/apps/qbittorrent-hotio.json | 468 + oci/catalog/apps/qbittorrent.json | 300 + oci/catalog/apps/qdirstat.json | 389 + oci/catalog/apps/qui.json | 524 + oci/catalog/apps/radarr.json | 275 + oci/catalog/apps/ragflow.json | 1283 ++ oci/catalog/apps/raneto.json | 241 + oci/catalog/apps/rawtherapee.json | 373 + oci/catalog/apps/rclone.json | 946 ++ oci/catalog/apps/rdtclient.json | 479 + oci/catalog/apps/readarr.json | 492 + oci/catalog/apps/remmina.json | 273 + oci/catalog/apps/resilio-sync.json | 280 + oci/catalog/apps/retroarch-inglebard.json | 371 + oci/catalog/apps/retroarch.json | 269 + oci/catalog/apps/romm.json | 826 + oci/catalog/apps/roonserver.json | 630 + oci/catalog/apps/rpcs3.json | 273 + oci/catalog/apps/rsnapshot.json | 259 + oci/catalog/apps/rustdesk.json | 373 + oci/catalog/apps/sabnzbd.json | 275 + oci/catalog/apps/scummvm.json | 378 + oci/catalog/apps/sealskin.json | 287 + oci/catalog/apps/seerr.json | 459 + oci/catalog/apps/shadps4.json | 256 + oci/catalog/apps/shotcut.json | 372 + oci/catalog/apps/sickchill.json | 492 + oci/catalog/apps/sickgear.json | 273 + oci/catalog/apps/signal.json | 268 + oci/catalog/apps/siyuan-note.json | 426 + oci/catalog/apps/smokeping.json | 356 + oci/catalog/apps/snapdrop.json | 434 + oci/catalog/apps/snapotter.json | 529 + oci/catalog/apps/sonarr.json | 275 + oci/catalog/apps/speedtest-tracker.json | 325 + oci/catalog/apps/spotube.json | 373 + oci/catalog/apps/sqlitebrowser.json | 373 + .../apps/stable-diffusion-webui-nvidia.json | 520 + oci/catalog/apps/steam.json | 395 + oci/catalog/apps/stremio.json | 480 + oci/catalog/apps/suite-arr.json | 335 + oci/catalog/apps/sure.json | 785 + oci/catalog/apps/swag.json | 471 + oci/catalog/apps/swingmusic.json | 420 + oci/catalog/apps/synclounge.json | 210 + oci/catalog/apps/syncthing.json | 372 + oci/catalog/apps/syslog-ng.json | 279 + oci/catalog/apps/tailscale.json | 466 + oci/catalog/apps/tandoor.json | 544 + oci/catalog/apps/taskingai.json | 843 ++ oci/catalog/apps/tasmoadmin.json | 423 + oci/catalog/apps/tautulli.json | 241 + oci/catalog/apps/tdarr.json | 684 + oci/catalog/apps/teable.json | 668 + oci/catalog/apps/telegram.json | 269 + oci/catalog/apps/thelounge.json | 241 + oci/catalog/apps/threadfin.json | 444 + oci/catalog/apps/thunderbird.json | 269 + oci/catalog/apps/transmission.json | 331 + oci/catalog/apps/trilium.json | 408 + oci/catalog/apps/turbodiffusion-nvidia.json | 515 + oci/catalog/apps/tvheadend.json | 408 + oci/catalog/apps/twingate-connector.json | 445 + oci/catalog/apps/ubooquity.json | 303 + oci/catalog/apps/ungoogled-chromium.json | 380 + oci/catalog/apps/unifi-controller.json | 532 + .../apps/unifi-network-application.json | 367 + oci/catalog/apps/unpackerr.json | 436 + oci/catalog/apps/uptimekuma.json | 401 + oci/catalog/apps/v2raya.json | 487 + oci/catalog/apps/vaultwarden.json | 462 + oci/catalog/apps/virt-manager.json | 499 + oci/catalog/apps/vivaldi.json | 272 + oci/catalog/apps/vlc.json | 272 + oci/catalog/apps/vocechat.json | 411 + oci/catalog/apps/vscode.json | 368 + oci/catalog/apps/vscodium-web.json | 268 + oci/catalog/apps/vscodium.json | 380 + oci/catalog/apps/wallabag.json | 446 + oci/catalog/apps/webcord.json | 373 + oci/catalog/apps/webdav.json | 466 + oci/catalog/apps/webgrabplus.json | 319 + oci/catalog/apps/webstation.json | 372 + oci/catalog/apps/webtop.json | 273 + oci/catalog/apps/weixin.json | 269 + oci/catalog/apps/weknora.json | 1124 ++ oci/catalog/apps/wg-easy.json | 509 + oci/catalog/apps/wikijs.json | 299 + oci/catalog/apps/winegui.json | 256 + oci/catalog/apps/wireguard.json | 440 + oci/catalog/apps/wireshark.json | 483 + oci/catalog/apps/wps-office.json | 372 + oci/catalog/apps/xbackbone.json | 248 + oci/catalog/apps/xemu.json | 273 + oci/catalog/apps/yaak.json | 372 + oci/catalog/apps/your_spotify.json | 273 + oci/catalog/apps/zen.json | 265 + oci/catalog/apps/znc.json | 241 + oci/catalog/apps/zotero.json | 372 + oci/catalog/apps/ztnet.json | 602 + oci/catalog/categories.json | 188 + oci/catalog/curated/amule.json | 465 + oci/catalog/curated/codeproject-ai.json | 417 + oci/catalog/curated/docker-volume-backup.json | 328 + oci/catalog/curated/emby-official.json | 481 + oci/catalog/curated/filebrowser-quantum.json | 390 + oci/catalog/curated/fileflows.json | 627 + oci/catalog/curated/frigate.json | 1130 ++ oci/catalog/curated/haos-one.json | 754 + oci/catalog/curated/immich.json | 1979 +++ oci/catalog/curated/jdownloader.json | 1017 ++ oci/catalog/curated/jellyfin-official.json | 523 + oci/catalog/curated/llamacpp.json | 430 + oci/catalog/curated/makemkv.json | 455 + oci/catalog/curated/mkvtoolnix.json | 376 + oci/catalog/curated/nextcloud-stack.json | 613 + oci/catalog/curated/open-webui-cuda.json | 463 + oci/catalog/curated/open-webui-ollama.json | 469 + oci/catalog/curated/open-webui.json | 451 + oci/catalog/curated/paperless-ngx.json | 669 + oci/catalog/curated/plex-official.json | 523 + oci/catalog/curated/rclone.json | 946 ++ oci/catalog/curated/roonserver.json | 625 + oci/catalog/curated/seerr.json | 459 + oci/catalog/curated/stremio.json | 475 + oci/catalog/curated/suite-arr.json | 335 + oci/catalog/curated/tandoor.json | 544 + oci/catalog/curated/tasmoadmin.json | 423 + oci/catalog/curated/tdarr.json | 684 + oci/catalog/curated/unpackerr.json | 436 + oci/catalog/exclusions.json | 29 + oci/catalog/generation-report-curated.json | 27 + oci/catalog/generation-report-imported.json | 158 + oci/catalog/generation-report.json | 206 + oci/catalog/index.json | 12622 ++++++++++++++++ oci/catalog/overlays/2fauth.json | 51 + oci/catalog/overlays/adguardhome-sync.json | 132 + oci/catalog/overlays/airsonic-advanced.json | 15 + oci/catalog/overlays/alist-sync.json | 15 + oci/catalog/overlays/alist.json | 19 + oci/catalog/overlays/altus.json | 15 + oci/catalog/overlays/amule.json | 11 + oci/catalog/overlays/anaconda3.json | 60 + oci/catalog/overlays/archivebox.json | 6 + oci/catalog/overlays/ardour.json | 15 + oci/catalog/overlays/audacity.json | 15 + oci/catalog/overlays/babybuddy.json | 15 + oci/catalog/overlays/blender.json | 15 + oci/catalog/overlays/boinc.json | 15 + oci/catalog/overlays/bookstack.json | 107 + oci/catalog/overlays/calibre.json | 15 + oci/catalog/overlays/calligra.json | 15 + oci/catalog/overlays/chatbot-ui.json | 6 + oci/catalog/overlays/clumoove.json | 6 + oci/catalog/overlays/copyparty.json | 21 + oci/catalog/overlays/crafty.json | 60 + oci/catalog/overlays/cura.json | 15 + oci/catalog/overlays/darktable.json | 15 + oci/catalog/overlays/ddclient.json | 9 + oci/catalog/overlays/deepseek-ocr-nvidia.json | 6 + oci/catalog/overlays/dify.json | 6 + oci/catalog/overlays/diskover.json | 14 + oci/catalog/overlays/doplarr.json | 6 + oci/catalog/overlays/doplarr_rs.json | 10 + oci/catalog/overlays/doublecommander.json | 15 + oci/catalog/overlays/duckdns.json | 65 + oci/catalog/overlays/duplicati.json | 79 + oci/catalog/overlays/etherpad.json | 131 + oci/catalog/overlays/ferdium.json | 15 + oci/catalog/overlays/filezilla.json | 15 + oci/catalog/overlays/flexget.json | 81 + oci/catalog/overlays/flowise.json | 73 + oci/catalog/overlays/freecad.json | 15 + oci/catalog/overlays/gimp.json | 15 + oci/catalog/overlays/github-desktop.json | 15 + oci/catalog/overlays/gitqlient.json | 15 + oci/catalog/overlays/glances.json | 99 + oci/catalog/overlays/grafana.json | 15 + oci/catalog/overlays/grocy.json | 14 + oci/catalog/overlays/handbrake-jlesage.json | 99 + oci/catalog/overlays/handbrake.json | 29 + oci/catalog/overlays/hedgedoc.json | 6 + oci/catalog/overlays/hermes.json | 83 + oci/catalog/overlays/homebridge.json | 15 + oci/catalog/overlays/index-tts.json | 45 + oci/catalog/overlays/inkscape.json | 15 + oci/catalog/overlays/jellyfin.json | 317 + oci/catalog/overlays/jenkins.json | 19 + oci/catalog/overlays/kali-linux.json | 15 + oci/catalog/overlays/karakeep.json | 6 + oci/catalog/overlays/kdenlive.json | 15 + oci/catalog/overlays/keepassxc.json | 15 + oci/catalog/overlays/kicad.json | 15 + oci/catalog/overlays/kimai.json | 30 + oci/catalog/overlays/kometa.json | 9 + oci/catalog/overlays/krita.json | 15 + oci/catalog/overlays/librechat.json | 6 + oci/catalog/overlays/libredb-studio.json | 81 + oci/catalog/overlays/libreoffice.json | 15 + oci/catalog/overlays/librewolf.json | 15 + oci/catalog/overlays/limnoria.json | 10 + oci/catalog/overlays/linkwarden.json | 14 + oci/catalog/overlays/llamacpp.json | 8 + oci/catalog/overlays/lollypop.json | 15 + oci/catalog/overlays/lucky.json | 15 + oci/catalog/overlays/mastodon.json | 6 + oci/catalog/overlays/maybe.json | 6 + oci/catalog/overlays/mediaelch.json | 15 + oci/catalog/overlays/memos.json | 8 + oci/catalog/overlays/mineos-node.json | 68 + oci/catalog/overlays/mongodb4.json | 19 + oci/catalog/overlays/monica-official.json | 17 + oci/catalog/overlays/monica.json | 6 + oci/catalog/overlays/motioneye.json | 29 + oci/catalog/overlays/msedge.json | 15 + oci/catalog/overlays/mullvad-browser.json | 15 + oci/catalog/overlays/mysql-workbench.json | 15 + oci/catalog/overlays/netbox.json | 197 + oci/catalog/overlays/netdata.json | 159 + oci/catalog/overlays/nzbget.json | 15 + oci/catalog/overlays/obsidian.json | 15 + oci/catalog/overlays/ollama.json | 22 + oci/catalog/overlays/openclaw.json | 13 + oci/catalog/overlays/openhands.json | 6 + oci/catalog/overlays/openlist.json | 58 + oci/catalog/overlays/openshot.json | 15 + oci/catalog/overlays/openssh-server.json | 134 + oci/catalog/overlays/openvscode-server.json | 6 + oci/catalog/overlays/opera.json | 15 + oci/catalog/overlays/pelorus.json | 15 + oci/catalog/overlays/petio.json | 11 + oci/catalog/overlays/photoprism.json | 53 + oci/catalog/overlays/phpmyadmin.json | 59 + oci/catalog/overlays/pidgin.json | 15 + oci/catalog/overlays/planka.json | 6 + oci/catalog/overlays/playit-agent.json | 10 + oci/catalog/overlays/plex.json | 58 + oci/catalog/overlays/pocketbase.json | 15 + oci/catalog/overlays/portainer.json | 6 + oci/catalog/overlays/postgresql.json | 80 + oci/catalog/overlays/pydio-cells.json | 52 + oci/catalog/overlays/pyload-ng.json | 15 + oci/catalog/overlays/qbittorrent-hotio.json | 19 + oci/catalog/overlays/qdirstat.json | 15 + oci/catalog/overlays/ragflow.json | 6 + oci/catalog/overlays/raneto.json | 15 + oci/catalog/overlays/rawtherapee.json | 15 + oci/catalog/overlays/readarr.json | 6 + oci/catalog/overlays/romm.json | 36 + oci/catalog/overlays/rsnapshot.json | 10 + oci/catalog/overlays/rustdesk.json | 15 + oci/catalog/overlays/sealskin.json | 6 + oci/catalog/overlays/shotcut.json | 15 + oci/catalog/overlays/siyuan-note.json | 15 + oci/catalog/overlays/snapotter.json | 82 + oci/catalog/overlays/speedtest-tracker.json | 135 + oci/catalog/overlays/spotube.json | 15 + oci/catalog/overlays/sqlitebrowser.json | 15 + oci/catalog/overlays/sure.json | 6 + oci/catalog/overlays/swag.json | 145 + oci/catalog/overlays/taskingai.json | 6 + oci/catalog/overlays/teable.json | 19 + oci/catalog/overlays/thelounge.json | 11 + .../overlays/turbodiffusion-nvidia.json | 8 + oci/catalog/overlays/ungoogled-chromium.json | 15 + .../overlays/unifi-network-application.json | 6 + oci/catalog/overlays/unpackerr.json | 10 + oci/catalog/overlays/vaultwarden.json | 74 + oci/catalog/overlays/virt-manager.json | 6 + oci/catalog/overlays/wallabag.json | 43 + oci/catalog/overlays/webcord.json | 15 + oci/catalog/overlays/webdav.json | 6 + oci/catalog/overlays/webstation.json | 15 + oci/catalog/overlays/weknora.json | 6 + oci/catalog/overlays/wg-easy.json | 130 + oci/catalog/overlays/wireguard.json | 100 + oci/catalog/overlays/wireshark.json | 15 + oci/catalog/overlays/wps-office.json | 15 + oci/catalog/overlays/yaak.json | 15 + oci/catalog/overlays/your_spotify.json | 6 + oci/catalog/overlays/znc.json | 15 + oci/catalog/overlays/zotero.json | 15 + oci/catalog/overlays/ztnet.json | 6 + oci/catalog/volume-policy.json | 120 + oci/proxmenux-oci.sh | 40 + oci/remote/allocate_private_network.py | 118 + oci/remote/configure_jellyfin_encoding.py | 101 + oci/remote/configure_rclone_mount.sh | 203 + oci/remote/haos_healthcheck.py | 172 + oci/remote/install_generic_stack.py | 775 + oci/remote/install_generic_stack.sh | 4 + oci/remote/install_immich_stack.sh | 570 + oci/remote/install_nextcloud_stack.sh | 553 + oci/remote/install_oci.sh | 1918 +++ oci/remote/install_paperless_stack.sh | 542 + oci/remote/install_tandoor_stack.sh | 505 + oci/remote/nvidia_lxc_mount_lab.sh | 30 + oci/remote/oci_accelerators.py | 124 + oci/remote/oci_gpu_devices.py | 149 + oci/remote/oci_host_mounts.py | 74 + oci/remote/oci_image_cache.py | 107 + oci/remote/oci_immich_ml.sh | 112 + oci/remote/oci_installation_state.py | 244 + oci/remote/oci_instance_transaction.py | 1239 ++ oci/remote/oci_instances.py | 387 + oci/remote/oci_native_stack.py | 180 + oci/remote/oci_native_stack.sh | 42 + oci/remote/oci_nvidia_dynamic.py | 57 + oci/remote/oci_nvidia_refresh.py | 145 + oci/remote/oci_nvidia_runtime.py | 165 + oci/remote/oci_nvidia_setup.sh | 81 + oci/remote/oci_remove.py | 167 + oci/remote/oci_runtime.py | 110 + oci/remote/oci_runtime_settings.py | 115 + oci/remote/oci_stack_native.py | 720 + oci/remote/oci_stack_plan.py | 61 + oci/remote/oci_stack_replay.py | 571 + oci/remote/oci_stack_transaction.py | 209 + oci/remote/oci_ui.py | 118 + oci/remote/oci_ui.sh | 136 + oci/remote/oci_update_current.py | 173 + oci/remote/oci_update_lab.py | 247 + oci/remote/rclone_mount_publish.py | 116 + oci/remote/stack_dependency_hook.sh | 128 + oci/remote/unshift_oci_rootfs.py | 66 + oci/remote/verify_oci_archive.py | 130 + oci/requirements.txt | 2 + oci/schemas/oci-template.schema.json | 346 + oci/src/proxmenux_oci/__init__.py | 3 + oci/src/proxmenux_oci/__main__.py | 5 + oci/src/proxmenux_oci/arr_suite.py | 129 + oci/src/proxmenux_oci/casaos.py | 989 ++ oci/src/proxmenux_oci/catalog.py | 762 + oci/src/proxmenux_oci/cli.py | 622 + oci/src/proxmenux_oci/console.py | 134 + oci/src/proxmenux_oci/converter.py | 1664 ++ oci/src/proxmenux_oci/custom.py | 574 + oci/src/proxmenux_oci/custom_mounts.py | 63 + oci/src/proxmenux_oci/github_source.py | 205 + oci/src/proxmenux_oci/gpu.py | 88 + oci/src/proxmenux_oci/host.py | 82 + oci/src/proxmenux_oci/i18n.py | 65 + oci/src/proxmenux_oci/images.py | 51 + oci/src/proxmenux_oci/installer.py | 1507 ++ oci/src/proxmenux_oci/management.py | 353 + oci/src/proxmenux_oci/network.py | 125 + oci/src/proxmenux_oci/operations.py | 35 + oci/src/proxmenux_oci/recreation.py | 234 + oci/src/proxmenux_oci/stack.py | 379 + oci/src/proxmenux_oci/ui.py | 235 + .../collectors/collect_source_host.sh | 2 +- .../backup_restore/lib_host_backup_common.sh | 4 +- .../backup_restore/run_scheduled_backup.sh | 33 + scripts/global/common-functions.sh | 37 + scripts/global/update-pve-safe.sh | 52 +- scripts/global/update-pve8.sh | 51 +- scripts/global/update-pve9_2.sh | 61 +- scripts/menus/main_menu.sh | 4 +- scripts/oci/oci_manager_apps.sh | 70 + scripts/post_install/auto_post_install.sh | 6 +- .../post_install/customizable_post_install.sh | 6 +- .../en/docs/monitor/health-monitor.json | 2 +- .../es/docs/monitor/health-monitor.json | 2 +- web/package.json | 3 - 670 files changed, 221410 insertions(+), 215 deletions(-) create mode 100644 AppImage/components/disk-exclusions.tsx create mode 100644 AppImage/scripts/disk_identity.py create mode 100644 oci/PACKAGE-CONTENTS.md create mode 100644 oci/README.md rename oci/{catalog.json => addons/secure-gateway.json} (100%) create mode 100644 oci/catalog/apps/2fauth.json create mode 100644 oci/catalog/apps/actualbudget.json create mode 100644 oci/catalog/apps/adguard-home.json create mode 100644 oci/catalog/apps/adguardhome-sync.json create mode 100644 oci/catalog/apps/adminer.json create mode 100644 oci/catalog/apps/airsonic-advanced.json create mode 100644 oci/catalog/apps/albyhub.json create mode 100644 oci/catalog/apps/alist-sync.json create mode 100644 oci/catalog/apps/alist.json create mode 100644 oci/catalog/apps/altus.json create mode 100644 oci/catalog/apps/amule.json create mode 100644 oci/catalog/apps/anaconda3.json create mode 100644 oci/catalog/apps/anythingllm.json create mode 100644 oci/catalog/apps/apprise-api.json create mode 100644 oci/catalog/apps/archivebox.json create mode 100644 oci/catalog/apps/ardour.json create mode 100644 oci/catalog/apps/audacity.json create mode 100644 oci/catalog/apps/audiobookshelf.json create mode 100644 oci/catalog/apps/autobrr.json create mode 100644 oci/catalog/apps/azahar.json create mode 100644 oci/catalog/apps/babybuddy.json create mode 100644 oci/catalog/apps/bambustudio.json create mode 100644 oci/catalog/apps/bazarr.json create mode 100644 oci/catalog/apps/beaverhabittracker.json create mode 100644 oci/catalog/apps/beets.json create mode 100644 oci/catalog/apps/bentopdf.json create mode 100644 oci/catalog/apps/bitcoin-knots.json create mode 100644 oci/catalog/apps/blade-of-agony.json create mode 100644 oci/catalog/apps/blender.json create mode 100644 oci/catalog/apps/blinko.json create mode 100644 oci/catalog/apps/boinc.json create mode 100644 oci/catalog/apps/bookstack.json create mode 100644 oci/catalog/apps/brave.json create mode 100644 oci/catalog/apps/budge.json create mode 100644 oci/catalog/apps/calibre-web.json create mode 100644 oci/catalog/apps/calibre.json create mode 100644 oci/catalog/apps/calligra.json create mode 100644 oci/catalog/apps/changedetection.io.json create mode 100644 oci/catalog/apps/chatbot-ui.json create mode 100644 oci/catalog/apps/chatgpt-next-web.json create mode 100644 oci/catalog/apps/chrome.json create mode 100644 oci/catalog/apps/chromium.json create mode 100644 oci/catalog/apps/cloudbeaver.json create mode 100644 oci/catalog/apps/cloudflared.json create mode 100644 oci/catalog/apps/clumoove.json create mode 100644 oci/catalog/apps/code-server.json create mode 100644 oci/catalog/apps/codeproject-ai.json create mode 100644 oci/catalog/apps/convertx.json create mode 100644 oci/catalog/apps/cops.json create mode 100644 oci/catalog/apps/copyparty.json create mode 100644 oci/catalog/apps/crafty.json create mode 100644 oci/catalog/apps/cura.json create mode 100644 oci/catalog/apps/darktable.json create mode 100644 oci/catalog/apps/databag.json create mode 100644 oci/catalog/apps/davos.json create mode 100644 oci/catalog/apps/ddclient.json create mode 100644 oci/catalog/apps/ddns-go.json create mode 100644 oci/catalog/apps/ddns-updater.json create mode 100644 oci/catalog/apps/deepseek-ocr-nvidia.json create mode 100644 oci/catalog/apps/deluge.json create mode 100644 oci/catalog/apps/dify.json create mode 100644 oci/catalog/apps/digikam.json create mode 100644 oci/catalog/apps/diskover.json create mode 100644 oci/catalog/apps/docker-volume-backup.json create mode 100644 oci/catalog/apps/docmost.json create mode 100644 oci/catalog/apps/dogwalk.json create mode 100644 oci/catalog/apps/dokuwiki.json create mode 100644 oci/catalog/apps/dolphin.json create mode 100644 oci/catalog/apps/doplarr.json create mode 100644 oci/catalog/apps/doplarr_rs.json create mode 100644 oci/catalog/apps/dosbox-staging.json create mode 100644 oci/catalog/apps/doublecommander.json create mode 100644 oci/catalog/apps/downtify.json create mode 100644 oci/catalog/apps/dsh-harness.json create mode 100644 oci/catalog/apps/duckdns.json create mode 100644 oci/catalog/apps/duckstation.json create mode 100644 oci/catalog/apps/duplicati.json create mode 100644 oci/catalog/apps/eden.json create mode 100644 oci/catalog/apps/emby-official.json create mode 100644 oci/catalog/apps/emby.json create mode 100644 oci/catalog/apps/embystat.json create mode 100644 oci/catalog/apps/emulatorjs.json create mode 100644 oci/catalog/apps/esphome.json create mode 100644 oci/catalog/apps/etherpad.json create mode 100644 oci/catalog/apps/excalidraw.json create mode 100644 oci/catalog/apps/faster-whisper.json create mode 100644 oci/catalog/apps/ferdium.json create mode 100644 oci/catalog/apps/filebrowser-quantum.json create mode 100644 oci/catalog/apps/filedrop.json create mode 100644 oci/catalog/apps/fileflows.json create mode 100644 oci/catalog/apps/filezilla.json create mode 100644 oci/catalog/apps/firefly.json create mode 100644 oci/catalog/apps/firefox.json create mode 100644 oci/catalog/apps/flaresolverr.json create mode 100644 oci/catalog/apps/flexget.json create mode 100644 oci/catalog/apps/flowise.json create mode 100644 oci/catalog/apps/flycast.json create mode 100644 oci/catalog/apps/foldingathome.json create mode 100644 oci/catalog/apps/freecad.json create mode 100644 oci/catalog/apps/freshrss-official.json create mode 100644 oci/catalog/apps/freshrss.json create mode 100644 oci/catalog/apps/frigate.json create mode 100644 oci/catalog/apps/gateway-go.json create mode 100644 oci/catalog/apps/gimp.json create mode 100644 oci/catalog/apps/gitea.json create mode 100644 oci/catalog/apps/github-desktop.json create mode 100644 oci/catalog/apps/gitqlient.json create mode 100644 oci/catalog/apps/glances.json create mode 100644 oci/catalog/apps/gopeed.json create mode 100644 oci/catalog/apps/grafana.json create mode 100644 oci/catalog/apps/grav.json create mode 100644 oci/catalog/apps/grocy.json create mode 100644 oci/catalog/apps/gzdoom.json create mode 100644 oci/catalog/apps/habridge.json create mode 100644 oci/catalog/apps/handbrake-jlesage.json create mode 100644 oci/catalog/apps/handbrake.json create mode 100644 oci/catalog/apps/haos-one.json create mode 100644 oci/catalog/apps/healthchecks.json create mode 100644 oci/catalog/apps/hedgedoc.json create mode 100644 oci/catalog/apps/heimdall.json create mode 100644 oci/catalog/apps/helium.json create mode 100644 oci/catalog/apps/hermes.json create mode 100644 oci/catalog/apps/hishtory-server.json create mode 100644 oci/catalog/apps/holoplay.json create mode 100644 oci/catalog/apps/homeassistant-official.json create mode 100644 oci/catalog/apps/homeassistant.json create mode 100644 oci/catalog/apps/homebridge.json create mode 100644 oci/catalog/apps/htpcmanager.json create mode 100644 oci/catalog/apps/hugo.json create mode 100644 oci/catalog/apps/immich.json create mode 100644 oci/catalog/apps/index-tts.json create mode 100644 oci/catalog/apps/inkscape.json create mode 100644 oci/catalog/apps/intellij-idea.json create mode 100644 oci/catalog/apps/jackett.json create mode 100644 oci/catalog/apps/jdownloader.json create mode 100644 oci/catalog/apps/jellyfin-official.json create mode 100644 oci/catalog/apps/jellyfin.json create mode 100644 oci/catalog/apps/jellyseerr.json create mode 100644 oci/catalog/apps/jenkins.json create mode 100644 oci/catalog/apps/joplin.json create mode 100644 oci/catalog/apps/kali-linux.json create mode 100644 oci/catalog/apps/karakeep.json create mode 100644 oci/catalog/apps/kasm.json create mode 100644 oci/catalog/apps/kavita-jvmilazz0.json create mode 100644 oci/catalog/apps/kavita.json create mode 100644 oci/catalog/apps/kdenlive.json create mode 100644 oci/catalog/apps/keepassxc.json create mode 100644 oci/catalog/apps/kicad.json create mode 100644 oci/catalog/apps/kimai.json create mode 100644 oci/catalog/apps/kometa.json create mode 100644 oci/catalog/apps/komga.json create mode 100644 oci/catalog/apps/krita.json create mode 100644 oci/catalog/apps/label-studio.json create mode 100644 oci/catalog/apps/langflow.json create mode 100644 oci/catalog/apps/lazylibrarian.json create mode 100644 oci/catalog/apps/ldap-auth.json create mode 100644 oci/catalog/apps/librechat.json create mode 100644 oci/catalog/apps/libredb-studio.json create mode 100644 oci/catalog/apps/libreoffice.json create mode 100644 oci/catalog/apps/librespeed.json create mode 100644 oci/catalog/apps/librewolf.json create mode 100644 oci/catalog/apps/lidarr.json create mode 100644 oci/catalog/apps/limnoria.json create mode 100644 oci/catalog/apps/linkwarden.json create mode 100644 oci/catalog/apps/llama-factory-nvidia.json create mode 100644 oci/catalog/apps/llamacpp.json create mode 100644 oci/catalog/apps/lm-studio.json create mode 100644 oci/catalog/apps/logseq.json create mode 100644 oci/catalog/apps/lollypop.json create mode 100644 oci/catalog/apps/luanti.json create mode 100644 oci/catalog/apps/lucky.json create mode 100644 oci/catalog/apps/lychee.json create mode 100644 oci/catalog/apps/lyrionmusicserver.json create mode 100644 oci/catalog/apps/makemkv.json create mode 100644 oci/catalog/apps/mame.json create mode 100644 oci/catalog/apps/manyfold.json create mode 100644 oci/catalog/apps/mariadb.json create mode 100644 oci/catalog/apps/mastodon.json create mode 100644 oci/catalog/apps/maybe.json create mode 100644 oci/catalog/apps/mediaelch.json create mode 100644 oci/catalog/apps/medusa-official.json create mode 100644 oci/catalog/apps/medusa.json create mode 100644 oci/catalog/apps/melonds.json create mode 100644 oci/catalog/apps/memos.json create mode 100644 oci/catalog/apps/mineos-node.json create mode 100644 oci/catalog/apps/minisatip.json create mode 100644 oci/catalog/apps/mkvtoolnix.json create mode 100644 oci/catalog/apps/mongodb.json create mode 100644 oci/catalog/apps/mongodb4.json create mode 100644 oci/catalog/apps/monica-official.json create mode 100644 oci/catalog/apps/monica.json create mode 100644 oci/catalog/apps/motioneye.json create mode 100644 oci/catalog/apps/msedge.json create mode 100644 oci/catalog/apps/mstream.json create mode 100644 oci/catalog/apps/mullvad-browser.json create mode 100644 oci/catalog/apps/mylar3.json create mode 100644 oci/catalog/apps/myspeed.json create mode 100644 oci/catalog/apps/mysql-workbench.json create mode 100644 oci/catalog/apps/n8n.json create mode 100644 oci/catalog/apps/navidrome.json create mode 100644 oci/catalog/apps/netbird.json create mode 100644 oci/catalog/apps/netbox.json create mode 100644 oci/catalog/apps/netdata.json create mode 100644 oci/catalog/apps/netronome.json create mode 100644 oci/catalog/apps/nextcloud-official.json create mode 100644 oci/catalog/apps/nextcloud-stack.json create mode 100644 oci/catalog/apps/nextcloud.json create mode 100644 oci/catalog/apps/nginx.json create mode 100644 oci/catalog/apps/nginxproxymanager.json create mode 100644 oci/catalog/apps/ngircd.json create mode 100644 oci/catalog/apps/node-red.json create mode 100644 oci/catalog/apps/nzbfast.json create mode 100644 oci/catalog/apps/nzbget.json create mode 100644 oci/catalog/apps/nzbhydra2.json create mode 100644 oci/catalog/apps/obsidian.json create mode 100644 oci/catalog/apps/ollama.json create mode 100644 oci/catalog/apps/ombi.json create mode 100644 oci/catalog/apps/onlyoffice.json create mode 100644 oci/catalog/apps/open-webui-cuda.json create mode 100644 oci/catalog/apps/open-webui-ollama.json create mode 100644 oci/catalog/apps/open-webui.json create mode 100644 oci/catalog/apps/openclaw.json create mode 100644 oci/catalog/apps/openhab.json create mode 100644 oci/catalog/apps/openhands.json create mode 100644 oci/catalog/apps/openlist.json create mode 100644 oci/catalog/apps/openshot.json create mode 100644 oci/catalog/apps/openspeedtest.json create mode 100644 oci/catalog/apps/openssh-server.json create mode 100644 oci/catalog/apps/openvscode-server.json create mode 100644 oci/catalog/apps/opera.json create mode 100644 oci/catalog/apps/opodsync.json create mode 100644 oci/catalog/apps/orcaslicer.json create mode 100644 oci/catalog/apps/oscam.json create mode 100644 oci/catalog/apps/overseerr.json create mode 100644 oci/catalog/apps/pairdrop.json create mode 100644 oci/catalog/apps/paperless-ngx.json create mode 100644 oci/catalog/apps/pcsx2.json create mode 100644 oci/catalog/apps/pdfding.json create mode 100644 oci/catalog/apps/peanut.json create mode 100644 oci/catalog/apps/pelorus.json create mode 100644 oci/catalog/apps/petio.json create mode 100644 oci/catalog/apps/photoprism.json create mode 100644 oci/catalog/apps/phpmyadmin.json create mode 100644 oci/catalog/apps/pidgin.json create mode 100644 oci/catalog/apps/pihole.json create mode 100644 oci/catalog/apps/pinchflat.json create mode 100644 oci/catalog/apps/pingvin-share.json create mode 100644 oci/catalog/apps/piper.json create mode 100644 oci/catalog/apps/piwigo.json create mode 100644 oci/catalog/apps/planka.json create mode 100644 oci/catalog/apps/playit-agent.json create mode 100644 oci/catalog/apps/plex-official.json create mode 100644 oci/catalog/apps/plex.json create mode 100644 oci/catalog/apps/pocketbase.json create mode 100644 oci/catalog/apps/podfetch.json create mode 100644 oci/catalog/apps/portainer.json create mode 100644 oci/catalog/apps/postgresql.json create mode 100644 oci/catalog/apps/ppsspp.json create mode 100644 oci/catalog/apps/projectsend.json create mode 100644 oci/catalog/apps/prowlarr.json create mode 100644 oci/catalog/apps/psitransfer.json create mode 100644 oci/catalog/apps/pwndrop.json create mode 100644 oci/catalog/apps/pycharm.json create mode 100644 oci/catalog/apps/pydio-cells.json create mode 100644 oci/catalog/apps/pyload-ng.json create mode 100644 oci/catalog/apps/qbittorrent-hotio.json create mode 100644 oci/catalog/apps/qbittorrent.json create mode 100644 oci/catalog/apps/qdirstat.json create mode 100644 oci/catalog/apps/qui.json create mode 100644 oci/catalog/apps/radarr.json create mode 100644 oci/catalog/apps/ragflow.json create mode 100644 oci/catalog/apps/raneto.json create mode 100644 oci/catalog/apps/rawtherapee.json create mode 100644 oci/catalog/apps/rclone.json create mode 100644 oci/catalog/apps/rdtclient.json create mode 100644 oci/catalog/apps/readarr.json create mode 100644 oci/catalog/apps/remmina.json create mode 100644 oci/catalog/apps/resilio-sync.json create mode 100644 oci/catalog/apps/retroarch-inglebard.json create mode 100644 oci/catalog/apps/retroarch.json create mode 100644 oci/catalog/apps/romm.json create mode 100644 oci/catalog/apps/roonserver.json create mode 100644 oci/catalog/apps/rpcs3.json create mode 100644 oci/catalog/apps/rsnapshot.json create mode 100644 oci/catalog/apps/rustdesk.json create mode 100644 oci/catalog/apps/sabnzbd.json create mode 100644 oci/catalog/apps/scummvm.json create mode 100644 oci/catalog/apps/sealskin.json create mode 100644 oci/catalog/apps/seerr.json create mode 100644 oci/catalog/apps/shadps4.json create mode 100644 oci/catalog/apps/shotcut.json create mode 100644 oci/catalog/apps/sickchill.json create mode 100644 oci/catalog/apps/sickgear.json create mode 100644 oci/catalog/apps/signal.json create mode 100644 oci/catalog/apps/siyuan-note.json create mode 100644 oci/catalog/apps/smokeping.json create mode 100644 oci/catalog/apps/snapdrop.json create mode 100644 oci/catalog/apps/snapotter.json create mode 100644 oci/catalog/apps/sonarr.json create mode 100644 oci/catalog/apps/speedtest-tracker.json create mode 100644 oci/catalog/apps/spotube.json create mode 100644 oci/catalog/apps/sqlitebrowser.json create mode 100644 oci/catalog/apps/stable-diffusion-webui-nvidia.json create mode 100644 oci/catalog/apps/steam.json create mode 100644 oci/catalog/apps/stremio.json create mode 100644 oci/catalog/apps/suite-arr.json create mode 100644 oci/catalog/apps/sure.json create mode 100644 oci/catalog/apps/swag.json create mode 100644 oci/catalog/apps/swingmusic.json create mode 100644 oci/catalog/apps/synclounge.json create mode 100644 oci/catalog/apps/syncthing.json create mode 100644 oci/catalog/apps/syslog-ng.json create mode 100644 oci/catalog/apps/tailscale.json create mode 100644 oci/catalog/apps/tandoor.json create mode 100644 oci/catalog/apps/taskingai.json create mode 100644 oci/catalog/apps/tasmoadmin.json create mode 100644 oci/catalog/apps/tautulli.json create mode 100644 oci/catalog/apps/tdarr.json create mode 100644 oci/catalog/apps/teable.json create mode 100644 oci/catalog/apps/telegram.json create mode 100644 oci/catalog/apps/thelounge.json create mode 100644 oci/catalog/apps/threadfin.json create mode 100644 oci/catalog/apps/thunderbird.json create mode 100644 oci/catalog/apps/transmission.json create mode 100644 oci/catalog/apps/trilium.json create mode 100644 oci/catalog/apps/turbodiffusion-nvidia.json create mode 100644 oci/catalog/apps/tvheadend.json create mode 100644 oci/catalog/apps/twingate-connector.json create mode 100644 oci/catalog/apps/ubooquity.json create mode 100644 oci/catalog/apps/ungoogled-chromium.json create mode 100644 oci/catalog/apps/unifi-controller.json create mode 100644 oci/catalog/apps/unifi-network-application.json create mode 100644 oci/catalog/apps/unpackerr.json create mode 100644 oci/catalog/apps/uptimekuma.json create mode 100644 oci/catalog/apps/v2raya.json create mode 100644 oci/catalog/apps/vaultwarden.json create mode 100644 oci/catalog/apps/virt-manager.json create mode 100644 oci/catalog/apps/vivaldi.json create mode 100644 oci/catalog/apps/vlc.json create mode 100644 oci/catalog/apps/vocechat.json create mode 100644 oci/catalog/apps/vscode.json create mode 100644 oci/catalog/apps/vscodium-web.json create mode 100644 oci/catalog/apps/vscodium.json create mode 100644 oci/catalog/apps/wallabag.json create mode 100644 oci/catalog/apps/webcord.json create mode 100644 oci/catalog/apps/webdav.json create mode 100644 oci/catalog/apps/webgrabplus.json create mode 100644 oci/catalog/apps/webstation.json create mode 100644 oci/catalog/apps/webtop.json create mode 100644 oci/catalog/apps/weixin.json create mode 100644 oci/catalog/apps/weknora.json create mode 100644 oci/catalog/apps/wg-easy.json create mode 100644 oci/catalog/apps/wikijs.json create mode 100644 oci/catalog/apps/winegui.json create mode 100644 oci/catalog/apps/wireguard.json create mode 100644 oci/catalog/apps/wireshark.json create mode 100644 oci/catalog/apps/wps-office.json create mode 100644 oci/catalog/apps/xbackbone.json create mode 100644 oci/catalog/apps/xemu.json create mode 100644 oci/catalog/apps/yaak.json create mode 100644 oci/catalog/apps/your_spotify.json create mode 100644 oci/catalog/apps/zen.json create mode 100644 oci/catalog/apps/znc.json create mode 100644 oci/catalog/apps/zotero.json create mode 100644 oci/catalog/apps/ztnet.json create mode 100644 oci/catalog/categories.json create mode 100644 oci/catalog/curated/amule.json create mode 100644 oci/catalog/curated/codeproject-ai.json create mode 100644 oci/catalog/curated/docker-volume-backup.json create mode 100644 oci/catalog/curated/emby-official.json create mode 100644 oci/catalog/curated/filebrowser-quantum.json create mode 100644 oci/catalog/curated/fileflows.json create mode 100644 oci/catalog/curated/frigate.json create mode 100644 oci/catalog/curated/haos-one.json create mode 100644 oci/catalog/curated/immich.json create mode 100644 oci/catalog/curated/jdownloader.json create mode 100644 oci/catalog/curated/jellyfin-official.json create mode 100644 oci/catalog/curated/llamacpp.json create mode 100644 oci/catalog/curated/makemkv.json create mode 100644 oci/catalog/curated/mkvtoolnix.json create mode 100644 oci/catalog/curated/nextcloud-stack.json create mode 100644 oci/catalog/curated/open-webui-cuda.json create mode 100644 oci/catalog/curated/open-webui-ollama.json create mode 100644 oci/catalog/curated/open-webui.json create mode 100644 oci/catalog/curated/paperless-ngx.json create mode 100644 oci/catalog/curated/plex-official.json create mode 100644 oci/catalog/curated/rclone.json create mode 100644 oci/catalog/curated/roonserver.json create mode 100644 oci/catalog/curated/seerr.json create mode 100644 oci/catalog/curated/stremio.json create mode 100644 oci/catalog/curated/suite-arr.json create mode 100644 oci/catalog/curated/tandoor.json create mode 100644 oci/catalog/curated/tasmoadmin.json create mode 100644 oci/catalog/curated/tdarr.json create mode 100644 oci/catalog/curated/unpackerr.json create mode 100644 oci/catalog/exclusions.json create mode 100644 oci/catalog/generation-report-curated.json create mode 100644 oci/catalog/generation-report-imported.json create mode 100644 oci/catalog/generation-report.json create mode 100644 oci/catalog/index.json create mode 100644 oci/catalog/overlays/2fauth.json create mode 100644 oci/catalog/overlays/adguardhome-sync.json create mode 100644 oci/catalog/overlays/airsonic-advanced.json create mode 100644 oci/catalog/overlays/alist-sync.json create mode 100644 oci/catalog/overlays/alist.json create mode 100644 oci/catalog/overlays/altus.json create mode 100644 oci/catalog/overlays/amule.json create mode 100644 oci/catalog/overlays/anaconda3.json create mode 100644 oci/catalog/overlays/archivebox.json create mode 100644 oci/catalog/overlays/ardour.json create mode 100644 oci/catalog/overlays/audacity.json create mode 100644 oci/catalog/overlays/babybuddy.json create mode 100644 oci/catalog/overlays/blender.json create mode 100644 oci/catalog/overlays/boinc.json create mode 100644 oci/catalog/overlays/bookstack.json create mode 100644 oci/catalog/overlays/calibre.json create mode 100644 oci/catalog/overlays/calligra.json create mode 100644 oci/catalog/overlays/chatbot-ui.json create mode 100644 oci/catalog/overlays/clumoove.json create mode 100644 oci/catalog/overlays/copyparty.json create mode 100644 oci/catalog/overlays/crafty.json create mode 100644 oci/catalog/overlays/cura.json create mode 100644 oci/catalog/overlays/darktable.json create mode 100644 oci/catalog/overlays/ddclient.json create mode 100644 oci/catalog/overlays/deepseek-ocr-nvidia.json create mode 100644 oci/catalog/overlays/dify.json create mode 100644 oci/catalog/overlays/diskover.json create mode 100644 oci/catalog/overlays/doplarr.json create mode 100644 oci/catalog/overlays/doplarr_rs.json create mode 100644 oci/catalog/overlays/doublecommander.json create mode 100644 oci/catalog/overlays/duckdns.json create mode 100644 oci/catalog/overlays/duplicati.json create mode 100644 oci/catalog/overlays/etherpad.json create mode 100644 oci/catalog/overlays/ferdium.json create mode 100644 oci/catalog/overlays/filezilla.json create mode 100644 oci/catalog/overlays/flexget.json create mode 100644 oci/catalog/overlays/flowise.json create mode 100644 oci/catalog/overlays/freecad.json create mode 100644 oci/catalog/overlays/gimp.json create mode 100644 oci/catalog/overlays/github-desktop.json create mode 100644 oci/catalog/overlays/gitqlient.json create mode 100644 oci/catalog/overlays/glances.json create mode 100644 oci/catalog/overlays/grafana.json create mode 100644 oci/catalog/overlays/grocy.json create mode 100644 oci/catalog/overlays/handbrake-jlesage.json create mode 100644 oci/catalog/overlays/handbrake.json create mode 100644 oci/catalog/overlays/hedgedoc.json create mode 100644 oci/catalog/overlays/hermes.json create mode 100644 oci/catalog/overlays/homebridge.json create mode 100644 oci/catalog/overlays/index-tts.json create mode 100644 oci/catalog/overlays/inkscape.json create mode 100644 oci/catalog/overlays/jellyfin.json create mode 100644 oci/catalog/overlays/jenkins.json create mode 100644 oci/catalog/overlays/kali-linux.json create mode 100644 oci/catalog/overlays/karakeep.json create mode 100644 oci/catalog/overlays/kdenlive.json create mode 100644 oci/catalog/overlays/keepassxc.json create mode 100644 oci/catalog/overlays/kicad.json create mode 100644 oci/catalog/overlays/kimai.json create mode 100644 oci/catalog/overlays/kometa.json create mode 100644 oci/catalog/overlays/krita.json create mode 100644 oci/catalog/overlays/librechat.json create mode 100644 oci/catalog/overlays/libredb-studio.json create mode 100644 oci/catalog/overlays/libreoffice.json create mode 100644 oci/catalog/overlays/librewolf.json create mode 100644 oci/catalog/overlays/limnoria.json create mode 100644 oci/catalog/overlays/linkwarden.json create mode 100644 oci/catalog/overlays/llamacpp.json create mode 100644 oci/catalog/overlays/lollypop.json create mode 100644 oci/catalog/overlays/lucky.json create mode 100644 oci/catalog/overlays/mastodon.json create mode 100644 oci/catalog/overlays/maybe.json create mode 100644 oci/catalog/overlays/mediaelch.json create mode 100644 oci/catalog/overlays/memos.json create mode 100644 oci/catalog/overlays/mineos-node.json create mode 100644 oci/catalog/overlays/mongodb4.json create mode 100644 oci/catalog/overlays/monica-official.json create mode 100644 oci/catalog/overlays/monica.json create mode 100644 oci/catalog/overlays/motioneye.json create mode 100644 oci/catalog/overlays/msedge.json create mode 100644 oci/catalog/overlays/mullvad-browser.json create mode 100644 oci/catalog/overlays/mysql-workbench.json create mode 100644 oci/catalog/overlays/netbox.json create mode 100644 oci/catalog/overlays/netdata.json create mode 100644 oci/catalog/overlays/nzbget.json create mode 100644 oci/catalog/overlays/obsidian.json create mode 100644 oci/catalog/overlays/ollama.json create mode 100644 oci/catalog/overlays/openclaw.json create mode 100644 oci/catalog/overlays/openhands.json create mode 100644 oci/catalog/overlays/openlist.json create mode 100644 oci/catalog/overlays/openshot.json create mode 100644 oci/catalog/overlays/openssh-server.json create mode 100644 oci/catalog/overlays/openvscode-server.json create mode 100644 oci/catalog/overlays/opera.json create mode 100644 oci/catalog/overlays/pelorus.json create mode 100644 oci/catalog/overlays/petio.json create mode 100644 oci/catalog/overlays/photoprism.json create mode 100644 oci/catalog/overlays/phpmyadmin.json create mode 100644 oci/catalog/overlays/pidgin.json create mode 100644 oci/catalog/overlays/planka.json create mode 100644 oci/catalog/overlays/playit-agent.json create mode 100644 oci/catalog/overlays/plex.json create mode 100644 oci/catalog/overlays/pocketbase.json create mode 100644 oci/catalog/overlays/portainer.json create mode 100644 oci/catalog/overlays/postgresql.json create mode 100644 oci/catalog/overlays/pydio-cells.json create mode 100644 oci/catalog/overlays/pyload-ng.json create mode 100644 oci/catalog/overlays/qbittorrent-hotio.json create mode 100644 oci/catalog/overlays/qdirstat.json create mode 100644 oci/catalog/overlays/ragflow.json create mode 100644 oci/catalog/overlays/raneto.json create mode 100644 oci/catalog/overlays/rawtherapee.json create mode 100644 oci/catalog/overlays/readarr.json create mode 100644 oci/catalog/overlays/romm.json create mode 100644 oci/catalog/overlays/rsnapshot.json create mode 100644 oci/catalog/overlays/rustdesk.json create mode 100644 oci/catalog/overlays/sealskin.json create mode 100644 oci/catalog/overlays/shotcut.json create mode 100644 oci/catalog/overlays/siyuan-note.json create mode 100644 oci/catalog/overlays/snapotter.json create mode 100644 oci/catalog/overlays/speedtest-tracker.json create mode 100644 oci/catalog/overlays/spotube.json create mode 100644 oci/catalog/overlays/sqlitebrowser.json create mode 100644 oci/catalog/overlays/sure.json create mode 100644 oci/catalog/overlays/swag.json create mode 100644 oci/catalog/overlays/taskingai.json create mode 100644 oci/catalog/overlays/teable.json create mode 100644 oci/catalog/overlays/thelounge.json create mode 100644 oci/catalog/overlays/turbodiffusion-nvidia.json create mode 100644 oci/catalog/overlays/ungoogled-chromium.json create mode 100644 oci/catalog/overlays/unifi-network-application.json create mode 100644 oci/catalog/overlays/unpackerr.json create mode 100644 oci/catalog/overlays/vaultwarden.json create mode 100644 oci/catalog/overlays/virt-manager.json create mode 100644 oci/catalog/overlays/wallabag.json create mode 100644 oci/catalog/overlays/webcord.json create mode 100644 oci/catalog/overlays/webdav.json create mode 100644 oci/catalog/overlays/webstation.json create mode 100644 oci/catalog/overlays/weknora.json create mode 100644 oci/catalog/overlays/wg-easy.json create mode 100644 oci/catalog/overlays/wireguard.json create mode 100644 oci/catalog/overlays/wireshark.json create mode 100644 oci/catalog/overlays/wps-office.json create mode 100644 oci/catalog/overlays/yaak.json create mode 100644 oci/catalog/overlays/your_spotify.json create mode 100644 oci/catalog/overlays/znc.json create mode 100644 oci/catalog/overlays/zotero.json create mode 100644 oci/catalog/overlays/ztnet.json create mode 100644 oci/catalog/volume-policy.json create mode 100755 oci/proxmenux-oci.sh create mode 100644 oci/remote/allocate_private_network.py create mode 100644 oci/remote/configure_jellyfin_encoding.py create mode 100755 oci/remote/configure_rclone_mount.sh create mode 100644 oci/remote/haos_healthcheck.py create mode 100644 oci/remote/install_generic_stack.py create mode 100755 oci/remote/install_generic_stack.sh create mode 100755 oci/remote/install_immich_stack.sh create mode 100755 oci/remote/install_nextcloud_stack.sh create mode 100755 oci/remote/install_oci.sh create mode 100755 oci/remote/install_paperless_stack.sh create mode 100755 oci/remote/install_tandoor_stack.sh create mode 100755 oci/remote/nvidia_lxc_mount_lab.sh create mode 100644 oci/remote/oci_accelerators.py create mode 100644 oci/remote/oci_gpu_devices.py create mode 100644 oci/remote/oci_host_mounts.py create mode 100644 oci/remote/oci_image_cache.py create mode 100755 oci/remote/oci_immich_ml.sh create mode 100644 oci/remote/oci_installation_state.py create mode 100644 oci/remote/oci_instance_transaction.py create mode 100644 oci/remote/oci_instances.py create mode 100644 oci/remote/oci_native_stack.py create mode 100755 oci/remote/oci_native_stack.sh create mode 100644 oci/remote/oci_nvidia_dynamic.py create mode 100644 oci/remote/oci_nvidia_refresh.py create mode 100644 oci/remote/oci_nvidia_runtime.py create mode 100755 oci/remote/oci_nvidia_setup.sh create mode 100644 oci/remote/oci_remove.py create mode 100644 oci/remote/oci_runtime.py create mode 100644 oci/remote/oci_runtime_settings.py create mode 100644 oci/remote/oci_stack_native.py create mode 100644 oci/remote/oci_stack_plan.py create mode 100644 oci/remote/oci_stack_replay.py create mode 100644 oci/remote/oci_stack_transaction.py create mode 100644 oci/remote/oci_ui.py create mode 100644 oci/remote/oci_ui.sh create mode 100644 oci/remote/oci_update_current.py create mode 100644 oci/remote/oci_update_lab.py create mode 100644 oci/remote/rclone_mount_publish.py create mode 100755 oci/remote/stack_dependency_hook.sh create mode 100644 oci/remote/unshift_oci_rootfs.py create mode 100755 oci/remote/verify_oci_archive.py create mode 100644 oci/requirements.txt create mode 100644 oci/schemas/oci-template.schema.json create mode 100644 oci/src/proxmenux_oci/__init__.py create mode 100644 oci/src/proxmenux_oci/__main__.py create mode 100644 oci/src/proxmenux_oci/arr_suite.py create mode 100644 oci/src/proxmenux_oci/casaos.py create mode 100644 oci/src/proxmenux_oci/catalog.py create mode 100644 oci/src/proxmenux_oci/cli.py create mode 100644 oci/src/proxmenux_oci/console.py create mode 100644 oci/src/proxmenux_oci/converter.py create mode 100644 oci/src/proxmenux_oci/custom.py create mode 100644 oci/src/proxmenux_oci/custom_mounts.py create mode 100644 oci/src/proxmenux_oci/github_source.py create mode 100644 oci/src/proxmenux_oci/gpu.py create mode 100644 oci/src/proxmenux_oci/host.py create mode 100644 oci/src/proxmenux_oci/i18n.py create mode 100644 oci/src/proxmenux_oci/images.py create mode 100644 oci/src/proxmenux_oci/installer.py create mode 100644 oci/src/proxmenux_oci/management.py create mode 100644 oci/src/proxmenux_oci/network.py create mode 100644 oci/src/proxmenux_oci/operations.py create mode 100644 oci/src/proxmenux_oci/recreation.py create mode 100644 oci/src/proxmenux_oci/stack.py create mode 100644 oci/src/proxmenux_oci/ui.py create mode 100755 scripts/oci/oci_manager_apps.sh diff --git a/.github/scripts/build_translation_cache.py b/.github/scripts/build_translation_cache.py index 7efabb8a..3a5b70cd 100644 --- a/.github/scripts/build_translation_cache.py +++ b/.github/scripts/build_translation_cache.py @@ -79,6 +79,21 @@ PROTECTED_TECHNICAL_TERMS = ( "ZFS", "SSH", "fork", + # Vendor, API and acceleration names. A label like "NVIDIA (NVDEC/CUDA)" + # is a product name end to end: every provider hands it back as it came, + # and without these entries that correct answer is read as a failure and + # the string is dropped from the catalogue. + "VA-API", + "NVIDIA", + "NVDEC", + "NVENC", + "WebUI", + "Intel", + "CUDA", + "KFD", + "GPU", + "CPU", + "AMD", ) TECHNICAL_TERM_RE = re.compile( "|".join( @@ -91,6 +106,36 @@ TRANSLATE_CALL_RE = re.compile( r"""translate\s+(?P["'])(?P(?:\\.|(?! (?P=quote) ).)*?)(?P=quote)""", re.VERBOSE | re.DOTALL, ) +# Providers that answer the same thing every time for the same input, so a +# second attempt cannot produce a different result. `appimage` shells out to a +# binary that may reach a network service, so it is not on the list. +DETERMINISTIC_PROVIDERS = frozenset({"argos"}) + + +def protect_catalog_titles(directories) -> None: + """Add every application name in the catalog to the protected glossary. + + They are product names, and a translator treats them as words: "HAOS One" + comes back as "HAOS Man". Protecting them costs nothing and the failure it + prevents reaches the reader as an application that does not exist. + """ + global TECHNICAL_TERM_RE + titles: set[str] = set() + for directory in directories: + for path in sorted(Path(directory).rglob("*.json")): + try: + data = json.loads(path.read_text(encoding="utf-8")) + except (OSError, ValueError): + continue + title = ((data.get("catalog_ui") or {}).get("title") or {}).get("en_US") + if isinstance(title, str) and title.strip(): + titles.add(title.strip()) + if not titles: + return + terms = tuple(sorted(set(PROTECTED_TECHNICAL_TERMS) | titles, key=len, reverse=True)) + TECHNICAL_TERM_RE = re.compile( + "|".join(re.escape(term) for term in terms), re.IGNORECASE) + print(f"Protected application names: {len(titles)}", flush=True) def protect_technical_terms(text: str) -> tuple[str, list[str]]: @@ -99,7 +144,7 @@ def protect_technical_terms(text: str) -> tuple[str, list[str]]: def _swap(match: re.Match[str]) -> str: protected.append(match.group(0)) - return f"__PMX_TERM_{len(protected) - 1}__" + return f"PMXTERM{len(protected) - 1:03d}" return TECHNICAL_TERM_RE.sub(_swap, text), protected @@ -107,7 +152,7 @@ def protect_technical_terms(text: str) -> tuple[str, list[str]]: def restore_technical_terms(text: str, protected: list[str]) -> str: """Restore glossary terms exactly as they appeared in the source.""" for index, original in enumerate(protected): - text = text.replace(f"__PMX_TERM_{index}__", original) + text = text.replace(f"PMXTERM{index:03d}", original) return text @@ -161,6 +206,93 @@ def extract_translate_texts( return sorted(found) +PYTHON_TRANSLATE_CALLS = {"translate", "N_"} +CATALOG_TEXT_KEYS = {"prompt", "enable_prompt", "path_prompt", "size_prompt", "label", "warning"} +CATALOG_TEXT_LISTS = {"stack_completion_notes", "completion_notes"} + + +def extract_python_texts(directories: Iterable[Path]) -> list[str]: + """translate("...") and N_("...") calls with a literal argument. The parser + joins implicitly concatenated literals, so wrapped strings are found whole.""" + found: dict[str, None] = {} + for directory in directories: + for path in sorted(directory.rglob("*.py")): + try: + tree = ast.parse(path.read_text(encoding="utf-8")) + except (SyntaxError, UnicodeDecodeError): + continue + for node in ast.walk(tree): + if (isinstance(node, ast.Call) and getattr(node.func, "id", None) in PYTHON_TRANSLATE_CALLS + and node.args and isinstance(node.args[0], ast.Constant) + and isinstance(node.args[0].value, str)): + text = node.args[0].value.strip() + if text: + found.setdefault(text, None) + return sorted(found) + + +def extract_catalog_texts(directories: Iterable[Path]) -> list[str]: + """User-visible text stored in the OCI catalog JSON: prompts, labels, + warnings, completion notes, category labels and descriptive usernames.""" + found: dict[str, None] = {} + + def add(value: object) -> None: + if isinstance(value, str) and value.strip(): + found.setdefault(value.strip(), None) + + def walk(value: object, key: str = "") -> None: + if isinstance(value, dict): + for child_key, child in value.items(): + if child_key in CATALOG_TEXT_KEYS: + add(child) + elif child_key in CATALOG_TEXT_LISTS and isinstance(child, list): + for item in child: + add(item) + elif child_key == "username" and isinstance(child, str) and " " in child: + add(child) + elif child_key == "catalog_ui" and isinstance(child, dict): + # What the application detail screen shows: the tagline, + # and the description only where there is no tagline. The + # catalog stores the source English; the translation lives + # in the language cache with every other string. + tagline = (child.get("tagline") or {}).get("en_US") + add(tagline or (child.get("description") or {}).get("en_US")) + elif child_key == "labels" and key == "" and isinstance(child, dict): + for item in child.values(): + add(item) + walk(child, child_key) + elif isinstance(value, list): + for item in value: + walk(item, key) + + for directory in directories: + for path in sorted(directory.rglob("*.json")): + try: + walk(json.loads(path.read_text(encoding="utf-8"))) + except (OSError, ValueError): + continue + return sorted(found) + + +def translate_argos(text: str, dest_lang: str) -> str: + """LibreTranslate's engine, running locally. + + A public endpoint answers a few thousand strings and then starts + refusing — and the library wrapper around it returns the English + unchanged rather than raising, which writes the source text into the + catalogue as if it were a translation. Local models have no quota and + no silent failure mode. + """ + try: + import argostranslate.translate as argos # type: ignore + except Exception as exc: + raise RuntimeError( + "argostranslate is not installed. Install argostranslate and the " + "en->target packages, or run with another provider." + ) from exc + return argos.translate(text, "en", dest_lang) + + def translate_googletrans(text: str, dest_lang: str, context: str) -> str: try: from googletrans import Translator # type: ignore @@ -302,7 +434,9 @@ def translate_text( appimage_path: Path, ) -> str: protected_text, protected_terms = protect_technical_terms(text) - if provider == "googletrans": + if provider == "argos": + translated = translate_argos(protected_text, dest_lang) + elif provider == "googletrans": translated = translate_googletrans(protected_text, dest_lang, context) elif provider == "google-web": translated = translate_google_web(protected_text, dest_lang, context, timeout) @@ -328,6 +462,32 @@ def load_language_cache(path: Path) -> dict[str, str]: return {str(text): str(value) for text, value in data.items()} +def is_fully_protected(source: str) -> bool: + """Whether the string is glossary terms and punctuation, nothing else. + + "Docker Volume Backup" and "NVIDIA (NVDEC/CUDA)" are product and API + names from end to end. Coming back unchanged is the right answer for + them, so the guard below must not read it as a silent failure and throw + the result away. + """ + return not re.search(r"[A-Za-z]{2,}", TECHNICAL_TERM_RE.sub(" ", source)) + + +def looks_untranslated(source: str, result: str) -> bool: + """Whether a provider handed back the text it was given. + + A single technical word legitimately survives translation — Docker, GPU, + LXC — but a sentence coming back byte-identical means the provider failed + without saying so. Accepting it writes English into the catalogue, where + it counts as translated and is never looked at again. + """ + if source.strip() != result.strip(): + return False + if is_fully_protected(source): + return False + return len([word for word in re.findall(r"[A-Za-z]{2,}", source)]) >= 3 + + def write_language_cache(path: Path, cache: dict[str, str]) -> None: path.parent.mkdir(parents=True, exist_ok=True) tmp_path = path.with_suffix(path.suffix + ".tmp") @@ -343,6 +503,30 @@ def build_arg_parser() -> argparse.ArgumentParser: description="Extract translate calls from scripts/ and build json/cache.json." ) parser.add_argument("--scripts-dir", default="scripts", type=Path) + parser.add_argument( + "--extra-dir", + action="append", + default=[], + type=Path, + metavar="PATH", + help="Extra directory scanned for translate calls in .sh files. Repeatable.", + ) + parser.add_argument( + "--python-dir", + action="append", + default=[], + type=Path, + metavar="PATH", + help="Directory scanned for translate()/N_() calls in .py files. Repeatable.", + ) + parser.add_argument( + "--catalog-dir", + action="append", + default=[], + type=Path, + metavar="PATH", + help="Directory of OCI catalog JSON files with user-visible text. Repeatable.", + ) parser.add_argument( "--extra-file", action="append", @@ -375,7 +559,7 @@ def build_arg_parser() -> argparse.ArgumentParser: ) parser.add_argument( "--provider", - choices=("appimage", "googletrans", "google-web"), + choices=("argos", "appimage", "googletrans", "google-web"), default="appimage", help="Translation provider to use. Default: appimage", ) @@ -388,6 +572,10 @@ def build_arg_parser() -> argparse.ArgumentParser: parser.add_argument("--context", default=DEFAULT_CONTEXT) parser.add_argument("--timeout", default=30, type=int) parser.add_argument("--sleep", default=0.15, type=float) + parser.add_argument("--retries", default=4, type=int, + help="Attempts per string before giving up on it.") + parser.add_argument("--retry-wait", default=15, type=float, + help="Seconds before the first retry; it doubles each time.") parser.add_argument( "--refresh", action="store_true", @@ -430,13 +618,26 @@ def main() -> int: return 1 texts = extract_translate_texts(scripts_dir, args.extra_file) + for directory in args.extra_dir: + if directory.is_dir(): + texts += extract_translate_texts(directory.resolve()) + texts += extract_python_texts(d.resolve() for d in args.python_dir if d.is_dir()) + catalog_dirs = [d.resolve() for d in args.catalog_dir if d.is_dir()] + protect_catalog_titles(catalog_dirs) + texts += extract_catalog_texts(catalog_dirs) + texts = sorted(dict.fromkeys(text for text in texts if "$" not in text and "`" not in text)) if args.limit > 0: texts = texts[: args.limit] existing_by_lang = { lang: load_language_cache(output_dir / f"{lang}.json") for lang in languages } - next_by_lang: dict[str, dict[str, str]] = {lang: {} for lang in languages} + # Seeded with what is already translated so a periodic save — or an + # interrupted run — writes a superset of the file it replaces, never a + # truncated one. + next_by_lang: dict[str, dict[str, str]] = { + lang: dict(existing_by_lang.get(lang, {})) for lang in languages + } print(f"Found {len(texts)} unique translate strings.", flush=True) print(f"Output directory: {output_dir}", flush=True) print(f"Languages: {', '.join(languages)}", flush=True) @@ -459,20 +660,51 @@ def main() -> int: continue print(f"[{done}/{total}] {lang} ({index}/{len(texts)}): {text[:80]}", flush=True) - try: - next_by_lang[lang][text] = translate_text( - text, - lang, - args.provider, - args.context, - args.timeout, - args.appimage_path, - ) - print(f" => {next_by_lang[lang][text][:100]}", flush=True) - except Exception as exc: - next_by_lang[lang][text] = existing.get(text, text) - failures.append((text, lang, str(exc))) - print(f" failed: {exc}", file=sys.stderr, flush=True) + # A rate limit is a "come back later", not an answer. Retrying with + # a growing wait recovers it; giving up on the first one is what + # left thousands of strings untranslated. + value, last_error = None, None + for attempt in range(1, args.retries + 1): + unchanged = False + try: + value = translate_text( + text, + lang, + args.provider, + args.context, + args.timeout, + args.appimage_path, + ) + if looks_untranslated(text, value): + value = None + unchanged = True + raise RuntimeError("the provider returned the source text unchanged") + break + except Exception as exc: + last_error = exc + # Unchanged text from a remote provider is how a rate limit + # shows up, so it is worth waiting for. A local engine is + # deterministic: asking again returns the same string, and + # the backoff only buys minutes of sleeping per phrase. + if unchanged and args.provider in DETERMINISTIC_PROVIDERS: + break + if attempt < args.retries: + wait = args.retry_wait * (2 ** (attempt - 1)) + print(f" retry {attempt}/{args.retries - 1} in {wait}s: {exc}", + file=sys.stderr, flush=True) + time.sleep(wait) + if value is not None: + next_by_lang[lang][text] = value + print(f" => {value[:100]}", flush=True) + else: + # The key is left out on purpose. Writing the English here + # would count as a translation on the next run and the string + # would never be translated again. + previous = existing.get(text) + if previous: + next_by_lang[lang][text] = previous + failures.append((text, lang, str(last_error))) + print(f" failed: {last_error}", file=sys.stderr, flush=True) if args.save_every > 0 and index % args.save_every == 0: write_language_cache(output_dir / f"{lang}.json", next_by_lang[lang]) time.sleep(args.sleep) diff --git a/.github/workflows/build-translation-cache.yml b/.github/workflows/build-translation-cache.yml index aa3f67fe..11fcce04 100644 --- a/.github/workflows/build-translation-cache.yml +++ b/.github/workflows/build-translation-cache.yml @@ -18,6 +18,9 @@ on: - 'menu' - 'install_proxmenux.sh' - 'install_proxmenux_beta.sh' + - 'oci/src/**/*.py' + - 'oci/remote/*.sh' + - 'oci/catalog/**/*.json' - '.github/scripts/build_translation_cache.py' - '.github/workflows/build-translation-cache.yml' workflow_dispatch: @@ -79,6 +82,10 @@ jobs: --extra-file menu \ --extra-file install_proxmenux.sh \ --extra-file install_proxmenux_beta.sh \ + --extra-dir oci/remote \ + --python-dir oci/src \ + --python-dir oci/remote \ + --catalog-dir oci/catalog \ --output-dir lang \ --provider googletrans \ $REFRESH_FLAG diff --git a/.gitignore b/.gitignore index 94bbb09e..0af426b3 100644 --- a/.gitignore +++ b/.gitignore @@ -41,13 +41,15 @@ Thumbs.db /web/.next /web/out -# Build artifacts generated by web's prebuild + build scripts. -# `prebuild` runs `sync:scripts` which rsyncs ../scripts/ into -# public/scripts/. `build` runs pagefind --site out which writes the -# search index into public/pagefind/. Both are regenerated fresh by -# the GitHub Pages CI on every deploy; committing them would just -# bloat the repo and produce constant noise in `git status`. +# Search index written by `build`: pagefind --site out produces it into +# public/pagefind/ and the GitHub Pages CI regenerates it on every deploy, +# so committing it would only bloat the repo and add noise to `git status`. /web/public/pagefind/ + +# Left ignored so the copy that `sync:scripts` used to generate disappears +# from a working tree that still has it. The docs link to the scripts on +# GitHub, never to a copy served from the site, and pagefind indexes HTML +# only — so nothing read it and the static export was publishing it anyway. /web/public/scripts/ # Cache diff --git a/AppImage/components/audit-comparison.tsx b/AppImage/components/audit-comparison.tsx index 0718e5e9..7f5b29e1 100644 --- a/AppImage/components/audit-comparison.tsx +++ b/AppImage/components/audit-comparison.tsx @@ -4,8 +4,8 @@ import { useCallback, useEffect, useState } from "react" import { Badge } from "./ui/badge" import { Button } from "./ui/button" import { - ChevronDown, ChevronRight, Flag, Loader2, MinusCircle, - PlusCircle, ShieldOff, TrendingUp, + ArrowDownRight, ArrowUpRight, ChevronDown, ChevronRight, Flag, Loader2, + MinusCircle, PlusCircle, ShieldOff, TrendingUp, } from "lucide-react" import { fetchApi } from "../lib/api-config" import { useT, useI18n } from "../lib/i18n/provider" @@ -24,6 +24,12 @@ import { useT, useI18n } from "../lib/i18n/provider" * only the first is progress, and merging them would tell the reader a * problem went away when the decision was to live with it. * + * The same care applies to a finding that is still reported. One that + * was already failing has not appeared now, so it is shown as having got + * worse or better with where it came from, rather than as new — reading + * "new" against work that lowered a critical to a warning would punish + * exactly the reader who fixed something. + * * It sits inside the assessment rather than in a view of its own, * because "what changed since last time" is context for the run being * read, not a separate place to visit. @@ -33,12 +39,18 @@ interface Finding { check_id: string area: string classification: string + // Only the findings that moved carry where they came from. + previous_classification?: string + previous_affected?: number + affected_count?: number } interface Comparison { from: string to: string new: Finding[] + worse: Finding[] + better: Finding[] resolved: Finding[] accepted: Finding[] unchanged: Finding[] @@ -46,8 +58,23 @@ interface Comparison { unverified: Finding[] } +/** What moved, in the reader's terms: the gravity when that is what + * changed, otherwise how many objects the finding now covers. */ +function movement(f: Finding, t: (k: string) => string): string | null { + if (!f.previous_classification) return null + if (f.previous_classification !== f.classification) { + return `${t(`audit.classifications.${f.previous_classification}`)} → ${t( + `audit.classifications.${f.classification}`, + )}` + } + if (f.previous_affected === undefined || f.affected_count === undefined) return null + return `${f.previous_affected} → ${f.affected_count}` +} + const GROUPS = [ { key: "new", Icon: PlusCircle, tone: "text-amber-500" }, + { key: "worse", Icon: ArrowUpRight, tone: "text-red-400" }, + { key: "better", Icon: ArrowDownRight, tone: "text-emerald-400" }, { key: "resolved", Icon: MinusCircle, tone: "text-green-500" }, { key: "accepted", Icon: ShieldOff, tone: "text-indigo-400" }, { key: "retired", Icon: Flag, tone: "text-muted-foreground" }, @@ -199,11 +226,19 @@ export function AuditComparison({ runId, isBaseline, onBaselineSet }: {

- {(comparison[key] || []).map((f) => ( - - {t(`audit.checks.${f.check_id}.title`)} - - ))} + {(comparison[key] || []).map((f) => { + const moved = movement(f, t) + return ( + + {t(`audit.checks.${f.check_id}.title`)} + {moved && ( + + {moved} + + )} + + ) + })}
), diff --git a/AppImage/components/audit-report.tsx b/AppImage/components/audit-report.tsx index a90b3ac3..671b9f5a 100644 --- a/AppImage/components/audit-report.tsx +++ b/AppImage/components/audit-report.tsx @@ -44,7 +44,14 @@ interface Finding { collected_at?: number check_version?: number sources?: Array<{ source: string; collected_at: number; error?: string }> - exception?: { reason: string; accepted_by: string; accepted_at: number; expires_at?: number | null } | null + exception?: { + reason: string; accepted_by: string; accepted_at: number + expires_at?: number | null + // Asks for the decision to be looked at again on this date. It does + // not withdraw it: an acceptance can stand indefinitely and still + // come back for review. + review_at?: number | null + } | null } interface Run { @@ -117,6 +124,7 @@ export function AuditReport() { const [accepting, setAccepting] = useState(null) const [reason, setReason] = useState("") const [expiryDays, setExpiryDays] = useState("") + const [reviewDays, setReviewDays] = useState("") const [saving, setSaving] = useState(false) const [progress, setProgress] = useState({ completed: 0, total: 0 }) // The profile decides which question the page answers, so it governs @@ -165,9 +173,11 @@ export function AuditReport() { // Expiry changes a decision, not the assessment. One local timer and // a focus refresh keep it current without periodic scans or idle polling. useEffect(() => { - const expiry = findings.flatMap((f) => f.exception?.expires_at ? [f.exception.expires_at] : []) - if (!expiry.length) return - const delay = Math.max(100, Math.min(2147483647, Math.min(...expiry) * 1000 - Date.now() + 100)) + const now = Date.now() / 1000 + const due = findings.flatMap((f) => [f.exception?.expires_at, f.exception?.review_at] + .filter((t): t is number => !!t && t > now)) + if (!due.length) return + const delay = Math.max(100, Math.min(2147483647, Math.min(...due) * 1000 - Date.now() + 100)) const id = setTimeout(refresh, delay) return () => clearTimeout(id) }, [findings, refresh]) @@ -235,6 +245,7 @@ export function AuditReport() { reason: reason.trim(), } if (expiryDays) body.expires_in_days = Number(expiryDays) + if (reviewDays) body.review_in_days = Number(reviewDays) const data: any = await fetchApi("/api/audit/exceptions", { method: "POST", body: JSON.stringify(body), @@ -243,6 +254,7 @@ export function AuditReport() { setAccepting(null) setReason("") setExpiryDays("") + setReviewDays("") await refresh() } catch (e) { setError(e instanceof Error ? e.message : String(e)) @@ -277,6 +289,9 @@ export function AuditReport() { [findings, areaFilter]) const acceptedCount = summary.accepted || 0 + const reviewDueCount = findings.filter( + (f) => f.exception?.review_at && f.exception.review_at * 1000 <= Date.now(), + ).length const unverifiedChecks = findings.filter( (f) => f.classification === "unverified" || f.incomplete) const ageDays = latest?.finished_at @@ -299,6 +314,26 @@ export function AuditReport() { return text === key ? t("audit.summaryFallback") : text } + // A check's plain-language texts are optional. Those that do not carry + // them yet render nothing, rather than the raw key a missing lookup + // returns, so the section can gain them one area at a time. + const optional = (key: string) => { + const text = t(key) + return text === key ? null : text + } + + // What to do about a finding depends on what was found, not on what was + // checked: an outcome that is not a problem has no next step, and one + // that could not be evaluated has nothing to act on either. + const nextStepOf = (f: Finding) => { + if (f.classification === "not_applicable") return null + if (f.classification === "unverified" || f.incomplete) return t("audit.couldNotEvaluate") + if (f.classification !== "critical" && f.classification !== "warning") { + return t("audit.noActionNeeded") + } + return f.summary_key ? optional(`audit.checks.${f.check_id}.nextStep.${f.summary_key}`) : null + } + const notApplicableText = (f: Finding) => { if (f.summary_key) return "" return f.classification === "not_applicable" ? t("audit.notApplicableScope") : "" @@ -594,6 +629,15 @@ export function AuditReport() { {t("audit.acceptedNotice", { count: String(acceptedCount) })}

)} + + {/* A decision that asked to be revisited says so here, where it + is read without going to look for it. The acceptance still + stands; this is a reminder, not a lapse. */} + {reviewDueCount > 0 && ( +

+ {t("audit.reviewDueNotice", { count: String(reviewDueCount) })} +

+ )} )} @@ -671,6 +715,17 @@ export function AuditReport() { {open && ( + {optional(`audit.checks.${f.check_id}.explanation`) && ( +
+

+ {t("audit.detail.whatItMeans")} +

+

+ {optional(`audit.checks.${f.check_id}.explanation`)} +

+
+ )} +

{t("audit.detail.why")} @@ -680,6 +735,15 @@ export function AuditReport() {

+ {nextStepOf(f) && ( +
+

+ {t("audit.detail.whatToDo")} +

+

{nextStepOf(f)}

+
+ )} + {f.exception && (

@@ -692,7 +756,13 @@ export function AuditReport() { {f.exception.expires_at && <> · {t("audit.expires", { when: new Date(f.exception.expires_at * 1000).toLocaleString(), })}} + {f.exception.review_at && <> · {t("audit.reviewOn", { + when: new Date(f.exception.review_at * 1000).toLocaleDateString(), + })}}

+ {!!f.exception.review_at && f.exception.review_at * 1000 <= Date.now() && ( +

{t("audit.reviewDue")}

+ )}
)} @@ -728,7 +798,7 @@ export function AuditReport() { + + + ) : ( + + )} + + )} + + {t("settings.diskExclusions.description")} + + + {loading ? ( +
+
+
+ ) : disks.length === 0 ? ( +
+ +

{t("settings.diskExclusions.empty")}

+
+ ) : ( +
+
+ + {t("settings.diskExclusions.disk")} + + + {t("settings.diskExclusions.periodicReads")} + +
+ +
+ {disks.map((disk) => { + const excluded = pending.has(disk.key) ? pending.get(disk.key)! : disk.excluded + return ( +
+
+
+ + {disk.name || "—"} + + + {transportLabel(disk)} + + {excluded && ( + + {t("settings.diskExclusions.excluded")} + + )} + {!excluded && disk.idle && ( + + {t("storage.idle")} + + )} + {!disk.present && ( + + {t("settings.diskExclusions.notConnected")} + + )} +
+ + {[disk.model, formatSize(disk.size_bytes), disk.serial].filter(Boolean).join(" · ")} + +
+ +
+ { + setPending((m) => { + const next = new Map(m) + if (!checked === disk.excluded) next.delete(disk.key) + else next.set(disk.key, !checked) + return next + }) + }} + className={`data-[state=checked]:bg-blue-600 data-[state=unchecked]:bg-input border border-border ${!editMode ? "opacity-60" : ""}`} + /> +
+
+ ) + })} +
+ + {error &&

{error}

} + +
+ +

+ {t("settings.diskExclusions.help")} +
+ {t("settings.diskExclusions.idleHelp")} +

+
+
+ )} + + + ) +} diff --git a/AppImage/components/host-backup.tsx b/AppImage/components/host-backup.tsx index 1a2f5e6c..9226f0cd 100644 --- a/AppImage/components/host-backup.tsx +++ b/AppImage/components/host-backup.tsx @@ -6177,7 +6177,13 @@ function AddDestinationDialog({ // back to the URL match; default 22 when neither is set. const port = editing.ssh_port ?? (ssh[3] ? Number(ssh[3]) : 22) setBorgSshPort(String(port || 22)) - setBorgSshRemotePath(`/${ssh[4]}`) + // `./path` (relative to the SSH user's home) and `~/path` are Borg + // path forms of their own — only an absolute path gets the slash + // the URL dropped. + const remotePath = ssh[4] + setBorgSshRemotePath( + remotePath.startsWith("./") || remotePath.startsWith("~/") ? remotePath : `/${remotePath}`, + ) setBorgSshKeyPath(editing.ssh_key_path || "/root/.ssh/proxmenux_borg") setBorgRepo("") } else { diff --git a/AppImage/components/settings.tsx b/AppImage/components/settings.tsx index dc6ae31e..a49968f6 100644 --- a/AppImage/components/settings.tsx +++ b/AppImage/components/settings.tsx @@ -8,6 +8,7 @@ import { Button } from "./ui/button" import { NotificationSettings } from "./notification-settings" import { HealthThresholds } from "./health-thresholds" import { LxcUpdateDetection } from "./lxc-update-detection" +import { DiskExclusions } from "./disk-exclusions" import { ScriptTerminalModal } from "./script-terminal-modal" import { Select, SelectContent, SelectItem, SelectTrigger, SelectValue } from "./ui/select" import { Switch } from "./ui/switch" @@ -1862,6 +1863,8 @@ export function Settings() { + + {/* Health Monitor Thresholds — placed above Notifications because the values configured here drive what triggers the notifications below. */} diff --git a/AppImage/components/storage-overview.tsx b/AppImage/components/storage-overview.tsx index 277a13d6..0437e62e 100644 --- a/AppImage/components/storage-overview.tsx +++ b/AppImage/components/storage-overview.tsx @@ -2,7 +2,7 @@ import { useEffect, useState } from "react" import { Card, CardContent, CardDescription, CardHeader, CardTitle } from "@/components/ui/card" -import { HardDrive, Database, AlertTriangle, CheckCircle2, XCircle, Square, Thermometer, Archive, Info, Clock, Usb, Server, Activity, FileText, Play, Loader2, Download, Plus, Trash2, Settings, Power } from "lucide-react" +import { HardDrive, Database, AlertTriangle, CheckCircle2, XCircle, Square, Thermometer, Archive, Info, Clock, Usb, Server, Activity, FileText, Play, Loader2, Download, Plus, Trash2, Settings, Power, Moon, EyeOff } from "lucide-react" import { Badge } from "@/components/ui/badge" import { Progress } from "@/components/ui/progress" import { Dialog, DialogContent, DialogDescription, DialogHeader, DialogTitle } from "@/components/ui/dialog" @@ -70,6 +70,8 @@ interface DiskInfo { // badge AND to suppress the (stale) temperature value, so the // operator understands the graph is frozen on purpose — issue #232. standby?: boolean + idle?: boolean + excluded?: boolean health: string power_on_hours?: number smart_status?: string @@ -434,7 +436,21 @@ export function StorageOverview() { // spun-down drive. Centralised here because the same pattern shows up // in 4 different disk-list views (system / data / pool / other) and we // want them all to behave identically — issue #232 fix. - const renderDiskTempOrStandby = (disk: DiskInfo) => { + // Why a disk shows no live temperature, when it doesn't: excluded by the + // user, parked, or idle and deliberately not read. Shared by every view + // that paints a disk's temperature, so they cannot disagree. + const renderNoReadingBadge = (disk: DiskInfo) => { + if (disk.excluded) { + return ( + + + {t("storage.diskExcluded")} + + ) + } if (disk.standby) { return ( ) } + if (disk.idle) { + return ( + + + {t("storage.idle")} + + ) + } + return null + } + + const renderDiskTempOrStandby = (disk: DiskInfo) => { + const noReading = renderNoReadingBadge(disk) + if (noReading) return noReading if (disk.temperature > 0) { return (
@@ -533,14 +566,8 @@ export function StorageOverview() { {/* Header line 2: size + temperature/standby. */}
{disk.size_formatted} - {disk.standby ? ( - - - {t("storage.standby")} - + {renderNoReadingBadge(disk) ? ( + renderNoReadingBadge(disk) ) : disk.temperature > 0 ? ( { ) : ( {t("vmLxc.updates.imageInstalledTag")} {" "} - {image.tag} + {image.tag || image.local_digest?.slice(0, 19)} )}
@@ -5758,11 +5760,17 @@ const handleDownloadLogs = async (vmid: number, vmName: string) => { {t("vmLxc.updates.imageUpToDate")} )} - {image.update_available === null && ( + {image.update_available === null && !image.pinned && ( {t("vmLxc.updates.imageDigestUnknown")} )} + {image.pinned && ( + + + {t("vmLxc.updates.imagePinned")} + + )}
@@ -5772,11 +5780,17 @@ const handleDownloadLogs = async (vmid: number, vmName: string) => { {t("vmLxc.updates.imageUpToDate")} )} - {image.update_available === null && ( + {image.update_available === null && !image.pinned && ( {t("vmLxc.updates.imageDigestUnknown")} )} + {image.pinned && ( + + + {t("vmLxc.updates.imagePinned")} + + )} {image.update_available === true && (image.update_targets || []).map((target) => (
+ ) : aw.docker_pinned ? ( +
+ + {t("vmLxc.updates.imagePinned")} +
) : null ) : (
{t("vmLxc.updates.versionTrackingPendingShort")}
diff --git a/AppImage/messages/de/common.json b/AppImage/messages/de/common.json index 1d497923..ade5a4eb 100644 --- a/AppImage/messages/de/common.json +++ b/AppImage/messages/de/common.json @@ -208,7 +208,7 @@ "notApplicable": "n / A", "error": "Fehler", "system": "System", - "standby": "Stehen zu", + "standby": "Standby", "standbyTitle": "Das Laufwerk befindet sich im Standby-Modus – Smartctl wurde übersprungen, um es im Ruhezustand zu halten", "filesystemCorruption": "Dateisystembeschädigung erkannt", "ioErrorOne": "{count} E/A-Fehler in 5 Min", @@ -2206,7 +2206,7 @@ "password": "Passwort", "usernamePlaceholder": "Geben Sie Ihren Benutzernamen ein", "passwordPlaceholder": "Geben Sie Ihr Passwort ein", - "rememberMe": "Erinnere dich an mich", + "rememberMe": "Anmeldedaten merken", "missingCredentials": "Bitte geben Sie Benutzernamen und Passwort ein", "missingTotp": "Bitte geben Sie Ihren 2FA-Code ein", "invalidCredentials": "Falscher Benutzername oder Passwort", @@ -3396,7 +3396,7 @@ }, "roles": { "active": "aktiv", - "standby": "stehen zu", + "standby": "Standby", "down": "runter" }, "empty": { @@ -5208,6 +5208,9 @@ "noFindings": "No findings match the current filter.", "affectedCount": "{count} affected", "acceptedNotice": "{count} accepted risk(s) recorded on this host.", + "reviewOn": "Überprüfen am: {when}", + "reviewDue": "Zur Überprüfung fällig — die Entscheidung gilt weiter", + "reviewDueNotice": "{count} akzeptierte Entscheidung(en) stehen zur Überprüfung an.", "states": { "fail": "Failed", "warn": "Warning", @@ -5228,6 +5231,8 @@ }, "detail": { "why": "Context", + "whatItMeans": "Was das bedeutet", + "whatToDo": "Was zu tun ist", "evidence": "Evidence", "affected": "Affected", "acceptedRisk": "Accepted risk", @@ -5674,20 +5679,23 @@ }, "summaryFallback": "The check could not be evaluated", "acceptRisk": { - "action": "Accept risk", - "revoke": "Return to active", - "title": "Accept this risk", - "reasonLabel": "Reason", - "reasonHelp": "Required. It is recorded together with the author and the date.", - "reasonPlaceholder": "e.g. Lab containers, not covered on purpose", - "expiryLabel": "Review after", - "expiryHelp": "When the period ends the finding becomes active again.", - "expiryNever": "Does not expire", - "expiry90": "90 days", - "expiry180": "180 days", - "expiry365": "1 year", - "cancel": "Cancel", - "confirm": "Accept risk" + "action": "Risiko akzeptieren", + "revoke": "Wieder aktivieren", + "title": "Dieses Risiko akzeptieren", + "reasonLabel": "Begründung", + "reasonHelp": "Erforderlich. Sie wird zusammen mit Urheber und Datum festgehalten.", + "reasonPlaceholder": "z. B. Labor-Container, absichtlich nicht abgedeckt", + "expiryLabel": "Gilt nicht mehr nach", + "expiryHelp": "Nach Ablauf des Zeitraums wird der Befund wieder aktiv.", + "expiryNever": "Läuft nicht ab", + "reviewLabel": "An Überprüfung erinnern", + "reviewHelp": "Die Entscheidung gilt weiter; sie wird nur wieder in Erinnerung gerufen.", + "reviewNever": "Keine Erinnerung", + "expiry90": "90 Tage", + "expiry180": "180 Tage", + "expiry365": "1 Jahr", + "cancel": "Abbrechen", + "confirm": "Risiko akzeptieren" }, "incomplete": "Unvollständige Nachweise", "progress": "{completed} von {total} geprüft", @@ -6085,6 +6093,10 @@ "unchanged": "{count} Prüfungen ergaben dasselbe wie zuvor.", "new": "Neu", "newNote": "jetzt gemeldet, vorher nicht", + "worse": "Verschlechtert", + "worseNote": "weiterhin gemeldet, und schwerwiegender oder weiter reichend als zuvor", + "better": "Verbessert", + "betterNote": "weiterhin gemeldet, aber weniger schwerwiegend oder weniger weit reichend als zuvor", "resolved": "Behoben", "resolvedNote": "nicht mehr gemeldet, und niemand hat sie akzeptiert", "accepted": "Akzeptiert", diff --git a/AppImage/messages/en/common.json b/AppImage/messages/en/common.json index 904cb69e..34ce516d 100644 --- a/AppImage/messages/en/common.json +++ b/AppImage/messages/en/common.json @@ -807,7 +807,11 @@ "friday": "Friday", "saturday": "Saturday" } - } + }, + "idle": "Idle", + "idleTitle": "Not read while nothing is using it, so it can spin down. Its temperature is shown again as soon as the disk is in use.", + "diskExcluded": "Excluded", + "diskExcludedTitle": "Excluded from periodic reads in Settings." }, "details": { "temperature": { @@ -1404,6 +1408,8 @@ "imageUpToDate": "Up to date", "imageInstalledTag": "installed tag", "imageDigestUnknown": "Digest unavailable", + "imagePinned": "Pinned to a digest", + "imagePinnedTitle": "This container runs the exact image its digest names. A newer tag does not change it; editing the reference in its configuration does.", "dockerPendingSummary": "{count} Docker image update(s) detected. Update with the owning Docker or Compose workflow.", "postApplyChecking": "Verifying update result…", "postApplyAllOk": "{count} package(s) applied successfully — nothing pending.", @@ -2197,6 +2203,18 @@ "reset": "Restore default", "hint": "Drag to reorder · On touch, long-press first", "customActive": "Using custom navigation order." + }, + "diskExclusions": { + "title": "Disk exclusions", + "description": "Disks that are never read on a schedule, so they can spin down on their own timer.", + "empty": "No physical disks found.", + "disk": "Disk", + "periodicReads": "Periodic reads", + "excluded": "Excluded", + "notConnected": "Not connected", + "saveFailed": "Could not save the disk exclusions.", + "help": "An excluded disk gets no scheduled temperature or SMART reads — not even a power-mode query — so it is left entirely alone. Opening its SMART details still reads it.", + "idleHelp": "Mechanical disks with no activity are already left alone automatically until something uses them again." } }, "login": { @@ -5208,6 +5226,11 @@ "noFindings": "No findings match the current filter.", "affectedCount": "{count} affected", "acceptedNotice": "{count} accepted risk(s) recorded on this host.", + "noActionNeeded": "Nothing to do. This check found what it expects to find.", + "couldNotEvaluate": "This check could not be evaluated, so it reports nothing either way. The evidence records what it was unable to read.", + "reviewOn": "Review on: {when}", + "reviewDue": "Due for review — the decision still stands", + "reviewDueNotice": "{count} accepted decision(s) are due for review.", "states": { "fail": "Failed", "warn": "Warning", @@ -5228,6 +5251,8 @@ }, "detail": { "why": "Context", + "whatItMeans": "What this means", + "whatToDo": "What to do", "evidence": "Evidence", "affected": "Affected", "acceptedRisk": "Accepted risk", @@ -5240,6 +5265,13 @@ "backup": { "guest_coverage": { "title": "Backup coverage", + "explanation": "A backup protects only what a job actually selects. This check pairs the guests on this node with the jobs that run here, so a guest nobody backs up appears as such instead of being assumed to be covered by something else.", + "nextStep": { + "noJobs": "Create a backup job on this node and select the guests holding data you would not want to rebuild by hand. A job that exists but is disabled selects nothing.", + "uncovered": "Decide, for each of these guests, whether it holds anything worth keeping. Add the ones that do to a job; for the ones that do not, declare that in the policy so they stop being counted here.", + "excludedData": "Open each job's exclusion list and confirm that what it leaves out is data you can afford to lose. An exclusion added to make a job faster protects nothing it skips.", + "uncoveredExpected": "The policy declares these guests as requiring a backup and no enabled job selects them. Either add them to a job or change what the policy declares, so the two agree." + }, "rationale": "Enabled backup jobs on this node, the guests each one selects, and guest data excluded from them. Configured coverage does not prove that a usable backup exists. Whether an unselected guest was meant to be protected comes from the declared policy.", "summary": { "noJobs": "No backup job is defined on this node for the {total} guests it holds", @@ -5252,6 +5284,12 @@ }, "last_backup_age": { "title": "Age of stored backups", + "explanation": "A job that exists is not the same as a copy that exists. This check reads the newest stored copy of each guest and how long ago it was written, which is how far back you would have to go if you had to restore today.", + "nextStep": { + "stale": "Find out why the job stopped producing copies for these guests: it may have been disabled, its schedule may never fire, or its runs may be failing. The run results check reports how each job last ended.", + "noBackups": "No stored copy matches any guest on this node. If the jobs write to a destination this node cannot read, that is expected; otherwise they are producing nothing.", + "attention": "Review the guests listed. Each one either has no recent copy or has one older than the age in use." + }, "rationale": "Age: time elapsed since the latest stored backup. Limit used: the reference age against which that backup is compared.", "summary": { "recent": "All {total} guest/destination checks meet the stated age policy", @@ -5263,6 +5301,12 @@ }, "retention_defined": { "title": "Backup retention", + "explanation": "Retention decides how many copies are kept and for how long. Without it a destination fills until it stops accepting new copies, and a backup that cannot be written is the one you find out about on the day you need it.", + "nextStep": { + "missing": "Set a retention on these jobs, or on the storage they write to. Proxmox takes the job's setting first, then the storage's, then the node default.", + "notDeclared": "These jobs keep every copy they make. That is a deliberate choice for some destinations, but confirm the destination has room to keep growing.", + "onServer": "These jobs write to a backup server, which prunes them under its own rules. What it keeps cannot be read from this node, so check the retention there." + }, "rationale": "Retention as Proxmox resolves it: the job's setting, then the storage's, then the node default. Retention applied by a backup server is not readable from this node.", "summary": { "allDefined": "All {total} jobs resolve a retention setting", @@ -5274,6 +5318,11 @@ }, "verification_state": { "title": "Backup verification", + "explanation": "Verification reads a stored copy back and confirms it is intact. It is the difference between a copy that exists and a copy that can be read — a distinction that only matters on the day you need it.", + "nextStep": { + "failed": "A copy that fails verification cannot be relied on. Check whether an earlier copy of the same guest verified, and look at the storage the failed copies live on.", + "notVerified": "Nothing has confirmed that these copies can be read back. A backup server can verify on a schedule of its own, separately from the job that wrote them." + }, "rationale": "The verification result Proxmox Backup Server records for each guest's newest copy, and whether an earlier copy of the same guest verified. Verification reads a stored copy back; it is not a restore.", "summary": { "allVerified": "The newest copy of all {total} guests has been verified intact", @@ -5284,6 +5333,11 @@ }, "job_results": { "title": "Backup run results", + "explanation": "How each job's most recent run ended, as this node recorded it. A job can be configured perfectly and still fail every night, and this is where that shows.", + "nextStep": { + "someFailed": "Read the error in the task log for these runs. A run that ends with an error produced no usable copy for the guests it covers.", + "recovered": "These guests failed an earlier run and have succeeded since. The earlier error is still worth reading: a failure that resolved itself often returns." + }, "rationale": "How each guest's most recent recorded run ended, from the node's task log. Only the latest run is graded. The log is retained for a limited period.", "summary": { "allSucceeded": "All {total} recorded backup runs ended without error", @@ -5294,6 +5348,12 @@ }, "host_recovery": { "title": "Host recovery", + "explanation": "Backing up the guests does not restore the node. This check looks at whether the node's own configuration — its storage definitions, its network, its users — is stored anywhere, which is what rebuilding the host itself depends on.", + "nextStep": { + "noHostBackup": "Nothing stores this node's own configuration. Rebuilding it would mean reconstructing the storage, network and user definitions by hand, from whatever notes exist.", + "attention": "Review the host configuration records listed. Each has something worth looking at: a run that failed, a destination that is gone, or a copy older than the age in use.", + "scheduledOnly": "A timer will produce host configuration backups, but none is stored yet. Until the first one runs, the node's own configuration is not protected." + }, "rationale": "Host backups as ProxMenux records them: each job it ran, when, whether it succeeded, the destination it wrote to and whether that copy is still there. A job writing to a backup server names no local path. Encryption keys are reported by count and recorded escrow mode only.", "summary": { "noHostBackup": "No host configuration backup is stored and no timer produces one", @@ -5680,9 +5740,12 @@ "reasonLabel": "Reason", "reasonHelp": "Required. It is recorded together with the author and the date.", "reasonPlaceholder": "e.g. Lab containers, not covered on purpose", - "expiryLabel": "Review after", + "expiryLabel": "Stops applying after", "expiryHelp": "When the period ends the finding becomes active again.", "expiryNever": "Does not expire", + "reviewLabel": "Remind me to review", + "reviewHelp": "The decision stays in force; it is only brought back to your attention.", + "reviewNever": "No reminder", "expiry90": "90 days", "expiry180": "180 days", "expiry365": "1 year", @@ -6085,6 +6148,10 @@ "unchanged": "{count} checks reported the same result as before.", "new": "New", "newNote": "reported now and not before", + "worse": "Worse", + "worseNote": "still reported, and graver or reaching further than before", + "better": "Better", + "betterNote": "still reported, but less grave or reaching less far than before", "resolved": "Resolved", "resolvedNote": "no longer reported, and nobody accepted them", "accepted": "Accepted", diff --git a/AppImage/messages/es/common.json b/AppImage/messages/es/common.json index 816fabba..edeafa5c 100644 --- a/AppImage/messages/es/common.json +++ b/AppImage/messages/es/common.json @@ -208,7 +208,7 @@ "notApplicable": "n / A", "error": "Error", "system": "Sistema", - "standby": "Apoyar", + "standby": "En reposo", "standbyTitle": "La unidad está en espera: se omitió smartctl para mantenerla apagada", "filesystemCorruption": "Se detectó corrupción en el sistema de archivos", "ioErrorOne": "{count} Error de E/S en 5 minutos", @@ -808,6 +808,10 @@ "saturday": "Sábado" } }, + "idle": "En reposo", + "idleTitle": "No se lee mientras nada lo usa, para que pueda apagarse. Su temperatura vuelve a mostrarse en cuanto el disco se usa.", + "diskExcluded": "Excluido", + "diskExcludedTitle": "Excluido de las lecturas periódicas en Ajustes.", "savedSmartData": "datos SMART guardados" }, "details": { @@ -1383,6 +1387,8 @@ "imageUpToDate": "Actualizada", "imageInstalledTag": "etiqueta instalada", "imageDigestUnknown": "Digest no disponible", + "imagePinned": "Anclada a un digest", + "imagePinnedTitle": "Este contenedor ejecuta exactamente la imagen que indica su digest. Un tag más reciente no la cambia; para cambiarla hay que editar la referencia en su configuración.", "dockerPendingSummary": "Se detectaron {count} actualización(es) de imágenes Docker. Actualízalas con su flujo de Docker o Compose.", "postApplyChecking": "Comprobando resultado de la actualización…", "postApplyAllOk": "{count} paquete(s) aplicados correctamente — nada pendiente.", @@ -2198,6 +2204,18 @@ "reset": "Restaurar por defecto", "hint": "Arrastra para reordenar · En táctil, mantén pulsado primero", "customActive": "Usando orden de navegación personalizado." + }, + "diskExclusions": { + "title": "Exclusiones de discos", + "description": "Discos que nunca se leen de forma periódica, para que puedan apagarse con su propio temporizador.", + "empty": "No se han encontrado discos físicos.", + "disk": "Disco", + "periodicReads": "Lecturas periódicas", + "excluded": "Excluido", + "notConnected": "No conectado", + "saveFailed": "No se pudieron guardar las exclusiones de discos.", + "help": "Un disco excluido no recibe lecturas periódicas de temperatura ni de SMART —ni siquiera la consulta de su estado de energía—, así que el Monitor no lo consulta en absoluto. Abrir sus detalles SMART sí lo lee.", + "idleHelp": "Los discos mecánicos sin actividad ya no se consultan automáticamente, para no sacarlos del reposo, hasta que algo vuelve a usarlos." } }, "login": { @@ -2206,7 +2224,7 @@ "password": "Contraseña", "usernamePlaceholder": "Ingrese su nombre de usuario", "passwordPlaceholder": "Introduce tu contraseña", - "rememberMe": "Acuérdate de mí", + "rememberMe": "Recordar", "missingCredentials": "Por favor ingrese nombre de usuario y contraseña", "missingTotp": "Por favor ingresa tu código 2FA", "invalidCredentials": "Nombre de usuario o contraseña incorrectos", @@ -3396,7 +3414,7 @@ }, "roles": { "active": "activo", - "standby": "apoyar", + "standby": "en espera", "down": "abajo" }, "empty": { @@ -5208,6 +5226,11 @@ "noFindings": "Ningún hallazgo coincide con el filtro actual.", "affectedCount": "{count} afectados", "acceptedNotice": "{count} riesgo(s) aceptado(s) registrados en este host.", + "noActionNeeded": "No hay nada que hacer. Esta comprobación ha encontrado lo que espera encontrar.", + "couldNotEvaluate": "Esta comprobación no se ha podido evaluar, así que no afirma nada en ningún sentido. La evidencia recoge qué no pudo leer.", + "reviewOn": "Revisar el: {when}", + "reviewDue": "Toca revisarla — la decisión sigue en vigor", + "reviewDueNotice": "{count} decisión(es) aceptada(s) esperan revisión.", "states": { "fail": "Fallo", "warn": "Aviso", @@ -5228,6 +5251,8 @@ }, "detail": { "why": "Contexto", + "whatItMeans": "Qué significa", + "whatToDo": "Qué hacer", "evidence": "Evidencia", "affected": "Afectados", "acceptedRisk": "Riesgo aceptado", @@ -5240,6 +5265,13 @@ "backup": { "guest_coverage": { "title": "Cobertura de backups", + "explanation": "Un backup solo protege lo que un trabajo selecciona de verdad. Esta comprobación cruza los invitados de este nodo con los trabajos que se ejecutan aquí, de modo que un invitado al que nadie respalda aparece como tal en lugar de darse por cubierto por algo.", + "nextStep": { + "noJobs": "Crea un trabajo de backup en este nodo y selecciona los invitados que guarden datos que no querrías rehacer a mano. Un trabajo que existe pero está deshabilitado no selecciona nada.", + "uncovered": "Decide, para cada uno de estos invitados, si guarda algo que merezca conservarse. Añade a un trabajo los que sí; para los que no, decláralo en la política y dejarán de contarse aquí.", + "excludedData": "Abre la lista de exclusiones de cada trabajo y confirma que lo que deja fuera son datos que puedes permitirte perder. Una exclusión añadida para acelerar un trabajo no protege nada de lo que omite.", + "uncoveredExpected": "La política declara que estos invitados requieren backup y ningún trabajo activo los selecciona. Añádelos a un trabajo o cambia lo que declara la política, para que ambas cosas coincidan." + }, "rationale": "Trabajos de backup habilitados en este nodo, los invitados que selecciona cada uno y los datos del invitado excluidos de ellos. La cobertura configurada no demuestra que exista una copia utilizable. Si un invitado no seleccionado debía protegerse lo indica la política declarada.", "summary": { "noJobs": "No hay ningún trabajo de backup definido en este nodo para los {total} invitados que alberga", @@ -5252,6 +5284,12 @@ }, "last_backup_age": { "title": "Antigüedad de las copias almacenadas", + "explanation": "Que exista un trabajo no es lo mismo que exista una copia. Esta comprobación lee la copia más reciente de cada invitado y cuánto hace que se escribió, que es hasta dónde tendrías que retroceder si hoy hubiera que restaurar.", + "nextStep": { + "stale": "Averigua por qué el trabajo dejó de producir copias de estos invitados: puede estar deshabilitado, su programación puede no dispararse nunca, o sus ejecuciones pueden estar fallando. La comprobación de resultados indica cómo terminó cada trabajo.", + "noBackups": "Ninguna copia almacenada corresponde a un invitado de este nodo. Si los trabajos escriben en un destino que este nodo no puede leer, es lo esperable; si no, no están produciendo nada.", + "attention": "Revisa los invitados de la lista. Cada uno no tiene copia reciente o la que tiene supera la antigüedad en uso." + }, "rationale": "Antigüedad: tiempo transcurrido desde la última copia almacenada. Límite utilizado: antigüedad de referencia con la que se compara esa copia.", "summary": { "recent": "Las {total} comprobaciones de máquina/destino cumplen el criterio de antigüedad indicado", @@ -5263,6 +5301,12 @@ }, "retention_defined": { "title": "Retención de backups", + "explanation": "La retención decide cuántas copias se conservan y durante cuánto tiempo. Sin ella un destino se llena hasta dejar de admitir copias nuevas, y un backup que no se puede escribir es justo del que te enteras el día que lo necesitas.", + "nextStep": { + "missing": "Define una retención en estos trabajos, o en el almacenamiento donde escriben. Proxmox toma primero el ajuste del trabajo, después el del almacenamiento y por último el del nodo.", + "notDeclared": "Estos trabajos conservan todas las copias que hacen. En algunos destinos es una decisión deliberada, pero confirma que el destino tiene sitio para seguir creciendo.", + "onServer": "Estos trabajos escriben en un servidor de backup, que las poda con sus propias reglas. Lo que conserva no se puede leer desde este nodo, así que comprueba la retención allí." + }, "rationale": "La retención tal como la resuelve Proxmox: el ajuste del trabajo, después el del almacenamiento y después el valor por defecto del nodo. La retención que aplica un servidor de backup no se puede leer desde este nodo.", "summary": { "allDefined": "Los {total} trabajos resuelven un ajuste de retención", @@ -5274,6 +5318,11 @@ }, "verification_state": { "title": "Verificación de las copias", + "explanation": "La verificación vuelve a leer una copia almacenada y confirma que está íntegra. Es la diferencia entre una copia que existe y una copia que se puede leer, una distinción que solo importa el día que la necesitas.", + "nextStep": { + "failed": "No se puede confiar en una copia que no supera la verificación. Comprueba si una copia anterior del mismo invitado sí la superó, y revisa el almacenamiento donde residen las que han fallado.", + "notVerified": "Nada ha confirmado que estas copias se puedan volver a leer. Un servidor de backup puede verificarlas con una programación propia, independiente del trabajo que las escribió." + }, "rationale": "El resultado de verificación que Proxmox Backup Server registra para la copia más reciente de cada invitado, y si una copia anterior del mismo invitado se verificó. La verificación lee una copia almacenada; no es una restauración.", "summary": { "allVerified": "La copia más reciente de los {total} invitados se ha verificado íntegra", @@ -5284,6 +5333,11 @@ }, "job_results": { "title": "Resultado de las ejecuciones de backup", + "explanation": "Cómo terminó la última ejecución de cada trabajo, según lo registró este nodo. Un trabajo puede estar perfectamente configurado y aun así fallar todas las noches, y es aquí donde eso se ve.", + "nextStep": { + "someFailed": "Lee el error en el registro de tareas de estas ejecuciones. Una ejecución que termina con error no ha producido ninguna copia utilizable de los invitados que cubre.", + "recovered": "Estos invitados fallaron en una ejecución anterior y desde entonces han terminado bien. El error anterior merece leerse igualmente: un fallo que se arregló solo suele volver." + }, "rationale": "Cómo terminó la ejecución más reciente de cada invitado, según el registro de tareas del nodo. Solo se gradúa la última. El registro se conserva un tiempo limitado.", "summary": { "allSucceeded": "Las {total} ejecuciones de backup registradas terminaron sin error", @@ -5294,6 +5348,12 @@ }, "host_recovery": { "title": "Recuperación del host", + "explanation": "Respaldar los invitados no restaura el nodo. Esta comprobación mira si la configuración del propio nodo —sus definiciones de almacenamiento, su red, sus usuarios— está guardada en algún sitio, que es de lo que depende poder reconstruir el host.", + "nextStep": { + "noHostBackup": "Nada guarda la configuración de este nodo. Reconstruirlo supondría rehacer a mano las definiciones de almacenamiento, red y usuarios, a partir de las notas que haya.", + "attention": "Revisa los registros de configuración del host de la lista. Cada uno tiene algo que mirar: una ejecución que falló, un destino que ya no está, o una copia más antigua que el límite en uso.", + "scheduledOnly": "Un temporizador producirá backups de la configuración del host, pero todavía no hay ninguno guardado. Hasta que se ejecute el primero, la configuración del nodo no está protegida." + }, "rationale": "Backups del host tal como los registra ProxMenux: cada trabajo que ejecutó, cuándo, si terminó bien, el destino donde escribió y si esa copia sigue ahí. Un trabajo que escribe en un servidor de backup no nombra ninguna ruta local. Las claves de cifrado se exponen solo por recuento y modo de custodia registrado.", "summary": { "noHostBackup": "No hay ningún backup de la configuración del host almacenado ni temporizador que lo genere", @@ -5680,9 +5740,12 @@ "reasonLabel": "Motivo", "reasonHelp": "Obligatorio. Queda registrado junto al autor y la fecha.", "reasonPlaceholder": "p. ej. Contenedores de laboratorio, sin cobertura a propósito", - "expiryLabel": "Revisar dentro de", + "expiryLabel": "Deja de aplicarse tras", "expiryHelp": "Al cumplirse el plazo el hallazgo vuelve a estado activo.", "expiryNever": "No caduca", + "reviewLabel": "Recordarme revisarla", + "reviewHelp": "La decisión sigue en vigor; solo vuelve a tu atención.", + "reviewNever": "Sin recordatorio", "expiry90": "90 días", "expiry180": "180 días", "expiry365": "1 año", @@ -6085,6 +6148,10 @@ "unchanged": "{count} comprobaciones dieron el mismo resultado que antes.", "new": "Nuevos", "newNote": "se informan ahora y antes no", + "worse": "Empeoraron", + "worseNote": "se siguen informando, y son más graves o alcanzan a más que antes", + "better": "Mejoraron", + "betterNote": "se siguen informando, pero son menos graves o alcanzan a menos que antes", "resolved": "Resueltos", "resolvedNote": "ya no se informan, y nadie los aceptó", "accepted": "Aceptados", diff --git a/AppImage/messages/fr/common.json b/AppImage/messages/fr/common.json index 0b2b50a5..b69daf67 100644 --- a/AppImage/messages/fr/common.json +++ b/AppImage/messages/fr/common.json @@ -208,7 +208,7 @@ "notApplicable": "n / A", "error": "Erreur", "system": "Système", - "standby": "Attendre", + "standby": "Veille", "standbyTitle": "Le lecteur est en veille - smartctl a été ignoré pour le maintenir en veille", "filesystemCorruption": "Corruption du système de fichiers détectée", "ioErrorOne": "{count} Erreur d'E/S dans 5 min", @@ -2206,7 +2206,7 @@ "password": "Mot de passe", "usernamePlaceholder": "Entrez votre nom d'utilisateur", "passwordPlaceholder": "Entrez votre mot de passe", - "rememberMe": "Souviens-toi de moi", + "rememberMe": "Mémoriser", "missingCredentials": "Veuillez entrer votre nom d'utilisateur et votre mot de passe", "missingTotp": "Veuillez entrer votre code 2FA", "invalidCredentials": "Nom d'utilisateur ou mot de passe incorrect", @@ -3396,7 +3396,7 @@ }, "roles": { "active": "actif", - "standby": "attendre", + "standby": "secours", "down": "vers le bas" }, "empty": { @@ -5208,6 +5208,9 @@ "noFindings": "No findings match the current filter.", "affectedCount": "{count} affected", "acceptedNotice": "{count} accepted risk(s) recorded on this host.", + "reviewOn": "À revoir le : {when}", + "reviewDue": "À revoir — la décision reste en vigueur", + "reviewDueNotice": "{count} décision(s) acceptée(s) sont à revoir.", "states": { "fail": "Failed", "warn": "Warning", @@ -5228,6 +5231,8 @@ }, "detail": { "why": "Context", + "whatItMeans": "Ce que cela signifie", + "whatToDo": "Que faire", "evidence": "Evidence", "affected": "Affected", "acceptedRisk": "Accepted risk", @@ -5674,20 +5679,23 @@ }, "summaryFallback": "The check could not be evaluated", "acceptRisk": { - "action": "Accept risk", - "revoke": "Return to active", - "title": "Accept this risk", - "reasonLabel": "Reason", - "reasonHelp": "Required. It is recorded together with the author and the date.", - "reasonPlaceholder": "e.g. Lab containers, not covered on purpose", - "expiryLabel": "Review after", - "expiryHelp": "When the period ends the finding becomes active again.", - "expiryNever": "Does not expire", - "expiry90": "90 days", - "expiry180": "180 days", - "expiry365": "1 year", - "cancel": "Cancel", - "confirm": "Accept risk" + "action": "Accepter le risque", + "revoke": "Remettre en actif", + "title": "Accepter ce risque", + "reasonLabel": "Motif", + "reasonHelp": "Obligatoire. Il est enregistré avec son auteur et la date.", + "reasonPlaceholder": "ex. Conteneurs de laboratoire, non couverts volontairement", + "expiryLabel": "Cesse de s'appliquer après", + "expiryHelp": "À la fin de la période, le constat redevient actif.", + "expiryNever": "N'expire pas", + "reviewLabel": "Me rappeler de la revoir", + "reviewHelp": "La décision reste en vigueur ; elle revient seulement à votre attention.", + "reviewNever": "Pas de rappel", + "expiry90": "90 jours", + "expiry180": "180 jours", + "expiry365": "1 an", + "cancel": "Annuler", + "confirm": "Accepter le risque" }, "incomplete": "Preuves incomplètes", "progress": "{completed} sur {total} vérifiés", @@ -6085,6 +6093,10 @@ "unchanged": "{count} contrôles ont donné le même résultat qu'avant.", "new": "Nouveaux", "newNote": "signalés maintenant et pas avant", + "worse": "Aggravés", + "worseNote": "toujours signalés, et plus graves ou plus étendus qu'avant", + "better": "Améliorés", + "betterNote": "toujours signalés, mais moins graves ou moins étendus qu'avant", "resolved": "Résolus", "resolvedNote": "plus signalés, et personne ne les a acceptés", "accepted": "Acceptés", diff --git a/AppImage/messages/it/common.json b/AppImage/messages/it/common.json index 067d676d..55db610c 100644 --- a/AppImage/messages/it/common.json +++ b/AppImage/messages/it/common.json @@ -2206,7 +2206,7 @@ "password": "Password", "usernamePlaceholder": "Inserisci il tuo nome utente", "passwordPlaceholder": "Inserisci la tua password", - "rememberMe": "Ricordati di me", + "rememberMe": "Ricorda", "missingCredentials": "Inserisci nome utente e password", "missingTotp": "Inserisci il tuo codice 2FA", "invalidCredentials": "Nome utente o password errati", @@ -5208,6 +5208,9 @@ "noFindings": "No findings match the current filter.", "affectedCount": "{count} affected", "acceptedNotice": "{count} accepted risk(s) recorded on this host.", + "reviewOn": "Da rivedere il: {when}", + "reviewDue": "Da rivedere — la decisione resta valida", + "reviewDueNotice": "{count} decisione/i accettata/e da rivedere.", "states": { "fail": "Failed", "warn": "Warning", @@ -5228,6 +5231,8 @@ }, "detail": { "why": "Context", + "whatItMeans": "Che cosa significa", + "whatToDo": "Cosa fare", "evidence": "Evidence", "affected": "Affected", "acceptedRisk": "Accepted risk", @@ -5674,20 +5679,23 @@ }, "summaryFallback": "The check could not be evaluated", "acceptRisk": { - "action": "Accept risk", - "revoke": "Return to active", - "title": "Accept this risk", - "reasonLabel": "Reason", - "reasonHelp": "Required. It is recorded together with the author and the date.", - "reasonPlaceholder": "e.g. Lab containers, not covered on purpose", - "expiryLabel": "Review after", - "expiryHelp": "When the period ends the finding becomes active again.", - "expiryNever": "Does not expire", - "expiry90": "90 days", - "expiry180": "180 days", - "expiry365": "1 year", - "cancel": "Cancel", - "confirm": "Accept risk" + "action": "Accetta il rischio", + "revoke": "Riporta tra gli attivi", + "title": "Accetta questo rischio", + "reasonLabel": "Motivo", + "reasonHelp": "Obbligatorio. Viene registrato insieme all'autore e alla data.", + "reasonPlaceholder": "es. Container di laboratorio, non coperti di proposito", + "expiryLabel": "Smette di applicarsi dopo", + "expiryHelp": "Alla fine del periodo il rilievo torna attivo.", + "expiryNever": "Non scade", + "reviewLabel": "Ricordami di rivederla", + "reviewHelp": "La decisione resta valida; torna solo alla tua attenzione.", + "reviewNever": "Nessun promemoria", + "expiry90": "90 giorni", + "expiry180": "180 giorni", + "expiry365": "1 anno", + "cancel": "Annulla", + "confirm": "Accetta il rischio" }, "incomplete": "Evidenze incomplete", "progress": "Verificati {completed} di {total}", @@ -6085,6 +6093,10 @@ "unchanged": "{count} controlli hanno dato lo stesso risultato di prima.", "new": "Nuovi", "newNote": "segnalati ora e prima no", + "worse": "Peggiorati", + "worseNote": "ancora segnalati, e più gravi o più estesi di prima", + "better": "Migliorati", + "betterNote": "ancora segnalati, ma meno gravi o meno estesi di prima", "resolved": "Risolti", "resolvedNote": "non più segnalati, e nessuno li ha accettati", "accepted": "Accettati", diff --git a/AppImage/messages/pt/common.json b/AppImage/messages/pt/common.json index ea53e624..a8cb4e3f 100644 --- a/AppImage/messages/pt/common.json +++ b/AppImage/messages/pt/common.json @@ -2206,7 +2206,7 @@ "password": "Senha", "usernamePlaceholder": "Digite seu nome de usuário", "passwordPlaceholder": "Digite sua senha", - "rememberMe": "Lembre de mim", + "rememberMe": "Lembrar", "missingCredentials": "Por favor insira nome de usuário e senha", "missingTotp": "Por favor, insira seu código 2FA", "invalidCredentials": "Nome de usuário ou senha incorretos", @@ -5208,6 +5208,9 @@ "noFindings": "No findings match the current filter.", "affectedCount": "{count} affected", "acceptedNotice": "{count} accepted risk(s) recorded on this host.", + "reviewOn": "Rever em: {when}", + "reviewDue": "A rever — a decisão continua em vigor", + "reviewDueNotice": "{count} decisão(ões) aceite(s) aguardam revisão.", "states": { "fail": "Failed", "warn": "Warning", @@ -5228,6 +5231,8 @@ }, "detail": { "why": "Context", + "whatItMeans": "O que isto significa", + "whatToDo": "O que fazer", "evidence": "Evidence", "affected": "Affected", "acceptedRisk": "Accepted risk", @@ -5674,20 +5679,23 @@ }, "summaryFallback": "The check could not be evaluated", "acceptRisk": { - "action": "Accept risk", - "revoke": "Return to active", - "title": "Accept this risk", - "reasonLabel": "Reason", - "reasonHelp": "Required. It is recorded together with the author and the date.", - "reasonPlaceholder": "e.g. Lab containers, not covered on purpose", - "expiryLabel": "Review after", - "expiryHelp": "When the period ends the finding becomes active again.", - "expiryNever": "Does not expire", - "expiry90": "90 days", - "expiry180": "180 days", - "expiry365": "1 year", - "cancel": "Cancel", - "confirm": "Accept risk" + "action": "Aceitar risco", + "revoke": "Voltar a ativo", + "title": "Aceitar este risco", + "reasonLabel": "Motivo", + "reasonHelp": "Obrigatório. É registado junto com o autor e a data.", + "reasonPlaceholder": "ex. Contentores de laboratório, não cobertos de propósito", + "expiryLabel": "Deixa de aplicar-se após", + "expiryHelp": "No fim do período o achado volta a ficar ativo.", + "expiryNever": "Não expira", + "reviewLabel": "Lembrar-me de rever", + "reviewHelp": "A decisão continua em vigor; apenas volta à sua atenção.", + "reviewNever": "Sem lembrete", + "expiry90": "90 dias", + "expiry180": "180 dias", + "expiry365": "1 ano", + "cancel": "Cancelar", + "confirm": "Aceitar risco" }, "incomplete": "Evidência incompleta", "progress": "Verificadas {completed} de {total}", @@ -6085,6 +6093,10 @@ "unchanged": "{count} verificações deram o mesmo resultado que antes.", "new": "Novos", "newNote": "reportados agora e antes não", + "worse": "Pioraram", + "worseNote": "continuam a ser reportados, e são mais graves ou mais abrangentes do que antes", + "better": "Melhoraram", + "betterNote": "continuam a ser reportados, mas são menos graves ou menos abrangentes do que antes", "resolved": "Resolvidos", "resolvedNote": "já não são reportados, e ninguém os aceitou", "accepted": "Aceites", diff --git a/AppImage/messages/sk/common.json b/AppImage/messages/sk/common.json index df8a8079..46bef54a 100644 --- a/AppImage/messages/sk/common.json +++ b/AppImage/messages/sk/common.json @@ -5208,6 +5208,9 @@ "noFindings": "Aktuálnemu filtru nezodpovedajú žiadne zistenia.", "affectedCount": "ovplyvnené: {count}", "acceptedNotice": "Na tomto serveri je zaznamenaných {count} prijatých rizík.", + "reviewOn": "Skontrolovať dňa: {when}", + "reviewDue": "Čaká na kontrolu — rozhodnutie stále platí", + "reviewDueNotice": "{count} prijaté rozhodnutie/a čaká na kontrolu.", "states": { "fail": "Zlyhalo", "warn": "Upozornenie", @@ -5228,6 +5231,8 @@ }, "detail": { "why": "Súvislosti", + "whatItMeans": "Čo to znamená", + "whatToDo": "Čo urobiť", "evidence": "Podklady", "affected": "Ovplyvnené", "acceptedRisk": "Prijaté riziko", @@ -5683,6 +5688,9 @@ "expiryLabel": "Znova preveriť po", "expiryHelp": "Po uplynutí obdobia bude zistenie opäť aktívne.", "expiryNever": "Bez vypršania", + "reviewLabel": "Pripomenúť kontrolu", + "reviewHelp": "Rozhodnutie stále platí; iba sa znova dostane do pozornosti.", + "reviewNever": "Bez pripomienky", "expiry90": "90 dní", "expiry180": "180 dní", "expiry365": "1 rok", @@ -6085,6 +6093,10 @@ "unchanged": "{count} kontrol dalo rovnaký výsledok ako predtým.", "new": "Nové", "newNote": "hlásené teraz a predtým nie", + "worse": "Zhoršené", + "worseNote": "stále sa hlásia a sú závažnejšie alebo majú väčší rozsah než predtým", + "better": "Zlepšené", + "betterNote": "stále sa hlásia, ale sú menej závažné alebo majú menší rozsah než predtým", "resolved": "Vyriešené", "resolvedNote": "už sa nehlásia a nikto ich neprijal", "accepted": "Prijaté", diff --git a/AppImage/messages/sv/common.json b/AppImage/messages/sv/common.json index 59b069cb..dd1fde8e 100644 --- a/AppImage/messages/sv/common.json +++ b/AppImage/messages/sv/common.json @@ -5208,6 +5208,9 @@ "noFindings": "No findings match the current filter.", "affectedCount": "{count} affected", "acceptedNotice": "{count} accepted risk(s) recorded on this host.", + "reviewOn": "Granska den: {when}", + "reviewDue": "Dags att granska — beslutet gäller fortfarande", + "reviewDueNotice": "{count} accepterade beslut väntar på granskning.", "states": { "fail": "Failed", "warn": "Warning", @@ -5228,6 +5231,8 @@ }, "detail": { "why": "Context", + "whatItMeans": "Vad detta betyder", + "whatToDo": "Vad du gör", "evidence": "Evidence", "affected": "Affected", "acceptedRisk": "Accepted risk", @@ -5674,20 +5679,23 @@ }, "summaryFallback": "The check could not be evaluated", "acceptRisk": { - "action": "Accept risk", - "revoke": "Return to active", - "title": "Accept this risk", - "reasonLabel": "Reason", - "reasonHelp": "Required. It is recorded together with the author and the date.", - "reasonPlaceholder": "e.g. Lab containers, not covered on purpose", - "expiryLabel": "Review after", - "expiryHelp": "When the period ends the finding becomes active again.", - "expiryNever": "Does not expire", - "expiry90": "90 days", - "expiry180": "180 days", - "expiry365": "1 year", - "cancel": "Cancel", - "confirm": "Accept risk" + "action": "Acceptera risken", + "revoke": "Återför till aktiva", + "title": "Acceptera den här risken", + "reasonLabel": "Orsak", + "reasonHelp": "Obligatorisk. Den sparas tillsammans med upphovsperson och datum.", + "reasonPlaceholder": "t.ex. Labbcontainrar, medvetet inte täckta", + "expiryLabel": "Slutar gälla efter", + "expiryHelp": "När perioden tar slut blir fyndet aktivt igen.", + "expiryNever": "Upphör inte", + "reviewLabel": "Påminn mig om att granska", + "reviewHelp": "Beslutet gäller fortfarande; det lyfts bara fram igen.", + "reviewNever": "Ingen påminnelse", + "expiry90": "90 dagar", + "expiry180": "180 dagar", + "expiry365": "1 år", + "cancel": "Avbryt", + "confirm": "Acceptera risken" }, "incomplete": "Ofullständiga underlag", "progress": "Kontrollerat {completed} av {total}", @@ -6085,6 +6093,10 @@ "unchanged": "{count} kontroller gav samma resultat som förut.", "new": "Nya", "newNote": "rapporteras nu men inte förut", + "worse": "Försämrade", + "worseNote": "rapporteras fortfarande, och är allvarligare eller når längre än förut", + "better": "Förbättrade", + "betterNote": "rapporteras fortfarande, men är mindre allvarliga eller når kortare än förut", "resolved": "Åtgärdade", "resolvedNote": "rapporteras inte längre, och ingen accepterade dem", "accepted": "Accepterade", diff --git a/AppImage/scripts/audit_checks.py b/AppImage/scripts/audit_checks.py index 3deff054..e7cf1b8f 100644 --- a/AppImage/scripts/audit_checks.py +++ b/AppImage/scripts/audit_checks.py @@ -691,6 +691,37 @@ def run_assessment(profile: str = "full", return run_id +def _scope(finding: dict) -> int: + """How many objects a finding covers. A check that named three guests + and now names nine describes a larger problem, even at the same + gravity.""" + return len(finding.get("affected") or []) + + +def _movement(previous: dict, current: dict) -> int: + """Whether a finding present in both runs got worse (1), better (-1) or + held (0). Gravity decides; scope only breaks a tie, because a finding + takes the gravity of its gravest object and dropping from critical to + warning is progress however many objects it now names.""" + before = audit_store.CLASS_ORDER.get(previous["classification"]) + after = audit_store.CLASS_ORDER.get(current["classification"]) + if before is not None and after is not None and before != after: + return 1 if after < before else -1 + before_scope, after_scope = _scope(previous), _scope(current) + if after_scope != before_scope: + return 1 if after_scope > before_scope else -1 + return 0 + + +def _against(current: dict, previous: dict) -> dict: + """A finding carrying where it came from, so the reader is told what + moved instead of only what it is now.""" + return {**current, + "previous_classification": previous["classification"], + "previous_affected": _scope(previous), + "affected_count": _scope(current)} + + def compare_runs(base_run: str, other_run: str) -> dict[str, list[dict]]: """Classify how findings moved between two runs. @@ -700,6 +731,12 @@ def compare_runs(base_run: str, other_run: str) -> dict[str, list[dict]]: that merges them would tell its reader the problem went away when the decision was to live with it. + A finding that was already failing and still fails is never new. It + either got worse, got better without being resolved, or held: reporting + a warning that became critical as new hides that it was already there, + and reporting a critical that dropped to a warning as new tells the + reader their work created a problem. + ``unchanged`` is kept so a report can state that the rest of the surface held steady rather than leaving it unaccounted for. """ @@ -708,6 +745,7 @@ def compare_runs(base_run: str, other_run: str) -> dict[str, list[dict]]: other = {f["check_id"]: f for f in audit_store.get_findings(other_run)} new, resolved, accepted, unchanged, unverified = [], [], [], [], [] + worse, better = [], [] for check_id, current in other.items(): previous = base.get(check_id) was = previous["classification"] in problems if previous else False @@ -718,8 +756,16 @@ def compare_runs(base_run: str, other_run: str) -> dict[str, list[dict]]: unverified.append(current) elif now and current.get("decision") == audit_store.DECISION_ACCEPTED: accepted.append(current) - elif now and (not was or previous["classification"] != current["classification"]): + elif now and not was: new.append(current) + elif now and was: + moved = _movement(previous, current) + if moved > 0: + worse.append(_against(current, previous)) + elif moved < 0: + better.append(_against(current, previous)) + else: + unchanged.append(current) elif was and not now: if current.get("decision") == audit_store.DECISION_ACCEPTED: accepted.append(current) @@ -738,6 +784,8 @@ def compare_runs(base_run: str, other_run: str) -> dict[str, list[dict]]: return { "new": new, + "worse": worse, + "better": better, "resolved": resolved, "accepted": accepted, "unchanged": unchanged, diff --git a/AppImage/scripts/audit_store.py b/AppImage/scripts/audit_store.py index 253ec991..d31c3001 100644 --- a/AppImage/scripts/audit_store.py +++ b/AppImage/scripts/audit_store.py @@ -229,12 +229,19 @@ def init_db() -> None: -- Accepted risks outlive the run that surfaced them, so they -- are keyed by check rather than by finding. expires_at NULL -- means the acceptance does not lapse on its own. + -- + -- review_at is deliberately not expires_at. Expiry withdraws + -- the decision and the finding becomes a problem again on its + -- own; a review date leaves the decision standing and only + -- brings it back to the reader, so "remind me in a year" no + -- longer has to be spelled as "stop accepting this in a year". CREATE TABLE IF NOT EXISTS audit_exceptions ( check_id TEXT PRIMARY KEY, reason TEXT NOT NULL, accepted_by TEXT NOT NULL, accepted_at INTEGER NOT NULL, - expires_at INTEGER + expires_at INTEGER, + review_at INTEGER ); CREATE INDEX IF NOT EXISTS idx_audit_findings_run @@ -250,7 +257,7 @@ def init_db() -> None: "audit_findings": {"raw_state": "TEXT", "exception_snapshot": "TEXT", "scope": "TEXT", "details": "TEXT", "classification": "TEXT", "raw_classification": "TEXT", "decision": "TEXT"}, - "audit_exceptions": {"scope": "TEXT"}, + "audit_exceptions": {"scope": "TEXT", "review_at": "INTEGER"}, }.items(): present = {row[1] for row in conn.execute(f"PRAGMA table_info({table})")} for name, kind in columns.items(): @@ -503,12 +510,17 @@ def check_history(check_id: str, limit: int = 30) -> list[dict[str, Any]]: # --------------------------------------------------------------------------- def accept_risk(check_id: str, reason: str, accepted_by: str, - expires_at: Optional[int] = None, *, scope: str) -> None: + expires_at: Optional[int] = None, *, scope: str, + review_at: Optional[int] = None) -> None: """Record a deliberate decision to leave a finding unresolved. A reason is mandatory: an acceptance without one is indistinguishable from having silenced the check, which is what this register exists to prevent. + + ``review_at`` asks to be reminded of the decision on a date without + withdrawing it. It is independent of ``expires_at``: an acceptance + can stand indefinitely and still come back for review. """ if not (reason or "").strip(): raise ValueError("an accepted risk requires a reason") @@ -516,18 +528,21 @@ def accept_risk(check_id: str, reason: str, accepted_by: str, raise ValueError("an accepted risk requires an assessed scope") if expires_at is not None and expires_at <= time.time(): raise ValueError("expiry must be in the future") + if review_at is not None and review_at <= time.time(): + raise ValueError("the review date must be in the future") init_db() conn = _connect() try: conn.execute("BEGIN IMMEDIATE") decision = dict(check_id=check_id, reason=reason.strip(), accepted_by=accepted_by, - accepted_at=int(time.time()), expires_at=expires_at, scope=scope) + accepted_at=int(time.time()), expires_at=expires_at, scope=scope, + review_at=review_at) conn.execute( "INSERT OR REPLACE INTO audit_exceptions " - "(check_id, reason, accepted_by, accepted_at, expires_at, scope) " - "VALUES (?, ?, ?, ?, ?, ?)", + "(check_id, reason, accepted_by, accepted_at, expires_at, scope, review_at) " + "VALUES (?, ?, ?, ?, ?, ?, ?)", (check_id, reason.strip(), accepted_by, int(time.time()), - expires_at, scope), + expires_at, scope, review_at), ) conn.execute("INSERT INTO audit_exception_events (check_id, action, happened_at, decision) " "VALUES (?, 'accepted', ?, ?)", @@ -643,6 +658,13 @@ def all_exceptions() -> list[dict[str, Any]]: item["lapsed"] = bool( item["expires_at"] is not None and item["expires_at"] <= now ) + # Due for review, and still in force: the decision holds, it is + # only asking to be looked at again. + item["review_due"] = bool( + item.get("review_at") is not None + and item["review_at"] <= now + and not item["lapsed"] + ) out.append(item) return out finally: diff --git a/AppImage/scripts/build_appimage.sh b/AppImage/scripts/build_appimage.sh index 5d3e799e..494c90f9 100755 --- a/AppImage/scripts/build_appimage.sh +++ b/AppImage/scripts/build_appimage.sh @@ -138,6 +138,7 @@ cp "$SCRIPT_DIR/mount_monitor.py" "$APP_DIR/usr/bin/" 2>/dev/null || echo "⚠ cp "$SCRIPT_DIR/lxc_mount_points.py" "$APP_DIR/usr/bin/" 2>/dev/null || echo "⚠️ lxc_mount_points.py not found" cp "$SCRIPT_DIR/disk_temperature_history.py" "$APP_DIR/usr/bin/" 2>/dev/null || echo "⚠️ disk_temperature_history.py not found" cp "$SCRIPT_DIR/smartctl_resolver.py" "$APP_DIR/usr/bin/" 2>/dev/null || echo "⚠️ smartctl_resolver.py not found" +cp "$SCRIPT_DIR/disk_identity.py" "$APP_DIR/usr/bin/" 2>/dev/null || echo "⚠️ disk_identity.py not found" cp "$SCRIPT_DIR/health_thresholds.py" "$APP_DIR/usr/bin/" 2>/dev/null || echo "⚠️ health_thresholds.py not found" cp "$SCRIPT_DIR/managed_installs.py" "$APP_DIR/usr/bin/" 2>/dev/null || echo "⚠️ managed_installs.py not found" cp "$SCRIPT_DIR/lxc_apps.py" "$APP_DIR/usr/bin/" 2>/dev/null || echo "⚠️ lxc_apps.py not found" diff --git a/AppImage/scripts/disk_identity.py b/AppImage/scripts/disk_identity.py new file mode 100644 index 00000000..e6b652cd --- /dev/null +++ b/AppImage/scripts/disk_identity.py @@ -0,0 +1,76 @@ +""" +Physical disks and a stable identity for each, read without touching them. + +Everything here comes from udev's database and /sys through lsblk, which +reads these columns without opening the block device. A drive that is +asleep, or idle and about to be, is not disturbed by being listed. + +The identity matters because a kernel name is not one: a USB drive can be +sda on one boot and sdb on the next, so anything the user attaches to a +disk has to follow the disk, not the letter it happened to get. +""" + +import re +import subprocess +from typing import Any, Dict, List + +_LSBLK_TIMEOUT = 5 +_FIELD_RE = re.compile(r'(\w+)="([^"]*)"') +_SKIP_PREFIXES = ("loop", "zd", "nbd", "ram", "sr") + + +def disk_key(serial: str, wwn: str, name: str) -> str: + """Stable identity: the serial where udev knows one, then the WWN, + and only as a last resort the kernel name.""" + serial = (serial or "").strip() + wwn = (wwn or "").strip() + if serial: + return f"serial:{serial}" + if wwn: + return f"wwn:{wwn}" + return f"name:{name}" + + +def list_physical_disks() -> List[Dict[str, Any]]: + """Every physical disk with its identity and the facts the interface + shows about it. Returns an empty list if lsblk cannot be read.""" + try: + proc = subprocess.run( + ["lsblk", "-d", "-n", "-P", "-b", "-o", + "NAME,TYPE,MODEL,SERIAL,WWN,SIZE,TRAN,ROTA"], + capture_output=True, text=True, timeout=_LSBLK_TIMEOUT, + ) + except (subprocess.TimeoutExpired, OSError): + return [] + if proc.returncode != 0: + return [] + + disks: List[Dict[str, Any]] = [] + for line in proc.stdout.splitlines(): + fields = dict(_FIELD_RE.findall(line)) + name = fields.get("NAME", "") + if fields.get("TYPE") != "disk" or not name or name.startswith(_SKIP_PREFIXES): + continue + serial = fields.get("SERIAL", "").strip() + wwn = fields.get("WWN", "").strip() + try: + size = int(fields.get("SIZE") or 0) + except ValueError: + size = 0 + disks.append({ + "name": name, + "key": disk_key(serial, wwn, name), + "model": fields.get("MODEL", "").strip(), + "serial": serial, + "size_bytes": size, + "transport": fields.get("TRAN", "").strip(), + "rotational": fields.get("ROTA", "").strip() == "1", + }) + return disks + + +def names_for_keys(keys) -> set: + """Current kernel names of the disks whose identity is in ``keys``.""" + if not keys: + return set() + return {d["name"] for d in list_physical_disks() if d["key"] in keys} diff --git a/AppImage/scripts/disk_temperature_history.py b/AppImage/scripts/disk_temperature_history.py index 5c392837..baecafbd 100644 --- a/AppImage/scripts/disk_temperature_history.py +++ b/AppImage/scripts/disk_temperature_history.py @@ -410,8 +410,133 @@ def _extract_temperature(data: dict[str, Any]) -> Optional[float]: # --------------------------------------------------------------------------- +# ── Leaving idle and excluded disks alone ────────────────────────── +# +# `-n standby` keeps a periodic reader from waking a disk that is asleep. +# It does not let an awake one fall asleep: a drive's spin-down timer +# counts time without commands, and a read every minute resets it, so an +# unused drive whose timer is longer than that never spins down — and a +# drive that parks its heads when idle loads them again on every read. +# +# So a rotational disk with no I/O since it was last looked at is not read +# at all, not even asked for its power mode. The counters come from +# /proc/diskstats, which costs no disk access, and a SMART query does not +# move them — passthrough commands are not accounted as reads or writes — +# so any change means something else used the disk. A disk in use is +# already awake, and reading it then costs nothing. Solid-state disks have +# no spindle and no heads, and keep their reading. +# +# A disk seen for the first time is read once, so a Monitor that has just +# started still has values to show; after that it is left alone for as +# long as nothing uses it. + +READ = "read" +IDLE = "idle" +EXCLUDED = "excluded" + +_last_io: dict[str, tuple[int, int]] = {} +_idle_state: dict[str, float] = {} +_IDLE_TTL = 600 # same horizon as the standby badge + + +def _read_diskstats() -> dict[str, tuple[int, int]]: + """Reads and writes completed per device, from /proc/diskstats.""" + out: dict[str, tuple[int, int]] = {} + try: + with open("/proc/diskstats") as f: + for line in f: + parts = line.split() + if len(parts) < 8: + continue + try: + out[parts[2]] = (int(parts[3]), int(parts[7])) + except ValueError: + continue + except OSError: + pass + return out + + +def _is_rotational(disk_name: str) -> bool: + try: + with open(f"/sys/block/{disk_name}/queue/rotational") as f: + return f.read().strip() == "1" + except OSError: + return False + + +_EXCLUDED_TTL = 15 +_excluded_cache: Optional[tuple[float, set]] = None + + +def excluded_disk_names() -> set: + """Kernel names of the disks the user excluded. Fails open: if the + list cannot be read, nothing is excluded rather than everything. + Held for a few seconds, since every reader asks for every disk.""" + global _excluded_cache + now = time.time() + with _cache_lock: + if _excluded_cache is not None and _excluded_cache[0] > now: + return set(_excluded_cache[1]) + names: set = set() + try: + from health_persistence import health_persistence + keys = health_persistence.get_excluded_disk_keys() + if keys: + from disk_identity import names_for_keys + names = names_for_keys(keys) + except Exception: + names = set() + with _cache_lock: + _excluded_cache = (now + _EXCLUDED_TTL, set(names)) + return names + + +def invalidate_disk_exclusions() -> None: + """Apply a change to the exclusion list on the next read.""" + global _excluded_cache + with _cache_lock: + _excluded_cache = None + + +_excluded_disk_names = excluded_disk_names + + +def disk_read_policy(disk_name: str, excluded: Optional[set] = None) -> str: + """Whether a periodic reader may touch this disk now: READ, IDLE or + EXCLUDED. Shared by every reader that runs on its own, so the + temperature poller and the storage view cannot disagree about a disk. + ``excluded`` lets a caller that checks many disks pass the list once.""" + if excluded is None: + excluded = _excluded_disk_names() + if disk_name in excluded: + _idle_state.pop(disk_name, None) + return EXCLUDED + if not _is_rotational(disk_name): + return READ + current = _read_diskstats().get(disk_name) + with _cache_lock: + previous = _last_io.get(disk_name) + if current is not None: + _last_io[disk_name] = current + if current is None or previous is None or current != previous: + _idle_state.pop(disk_name, None) + return READ + _idle_state[disk_name] = time.time() + return IDLE + + +def is_disk_idle(disk_name: str) -> bool: + """True while the disk is being left alone for having no I/O.""" + ts = _idle_state.get(disk_name) + return ts is not None and (time.time() - ts) < _IDLE_TTL + + def record_all_disk_temperatures() -> int: - """Sample every non-USB disk and persist its temperature. + """Sample the disks that may be read now and persist their temperature. + + USB disks are included. A disk the user excluded, or a rotational one + with no I/O since the last cycle, is skipped — see ``disk_read_policy``. Sampling fans out across a thread pool so a host with N disks pays roughly the time of the slowest single ``smartctl`` call instead of @@ -419,7 +544,8 @@ def record_all_disk_temperatures() -> int: threading is enough — no need for asyncio. Returns the number of rows actually written. """ - disks = _list_target_disks() + excluded = _excluded_disk_names() + disks = [d for d in _list_target_disks() if disk_read_policy(d, excluded) == READ] if not disks: return 0 now = int(time.time()) diff --git a/AppImage/scripts/flask_audit_routes.py b/AppImage/scripts/flask_audit_routes.py index 82e571cd..0ef6bfe8 100644 --- a/AppImage/scripts/flask_audit_routes.py +++ b/AppImage/scripts/flask_audit_routes.py @@ -309,22 +309,29 @@ def accept_exception(): finding.get('incomplete') or not finding.get('scope')): return jsonify(success=False, message="This finding cannot be accepted"), 400 - expires_at = None - days = data.get('expires_in_days') - if days is not None: - try: - if isinstance(days, bool) or int(days) != float(days) or not 1 <= int(days) <= 3650: - raise ValueError("invalid expiry") - expires_at = int(time.time()) + int(days) * 86400 - except (TypeError, ValueError): - return jsonify({"success": False, - "message": "Invalid expiry"}), 400 + def _in_days(value, label): + """A day count from now, or None. Same bounds as the expiry so a + reminder cannot be set further out than a decision can last.""" + if value is None: + return None + if isinstance(value, bool) or int(value) != float(value) or not 1 <= int(value) <= 3650: + raise ValueError(f"invalid {label}") + return int(time.time()) + int(value) * 86400 + + try: + expires_at = _in_days(data.get('expires_in_days'), 'expiry') + # Independent of the expiry: it brings the decision back to the + # reader on that date without withdrawing it. + review_at = _in_days(data.get('review_in_days'), 'review date') + except (TypeError, ValueError) as e: + return jsonify({"success": False, "message": str(e)}), 400 audit_store.accept_risk( check_id, reason, accepted_by=_actor(), expires_at=expires_at, scope=finding['scope'], + review_at=review_at, ) return jsonify({"success": True}) except ValueError as e: diff --git a/AppImage/scripts/flask_health_routes.py b/AppImage/scripts/flask_health_routes.py index 7d5c13c2..e04cd5b8 100644 --- a/AppImage/scripts/flask_health_routes.py +++ b/AppImage/scripts/flask_health_routes.py @@ -5,6 +5,7 @@ Flask routes for health monitoring with persistence support from flask import Blueprint, jsonify, request from health_monitor import health_monitor from health_persistence import health_persistence +from jwt_middleware import require_auth, require_admin_scope # Sprint 13: remote-mount monitor (NFS/CIFS/SMB) — separate module so a # missing helper doesn't crash the health blueprint. @@ -17,6 +18,7 @@ except ImportError: health_bp = Blueprint('health', __name__) @health_bp.route('/api/health/status', methods=['GET']) +@require_auth def get_health_status(): """Get overall health status summary""" try: @@ -26,6 +28,7 @@ def get_health_status(): return jsonify({'error': str(e)}), 500 @health_bp.route('/api/health/details', methods=['GET']) +@require_auth def get_health_details(): """Get detailed health status with all checks""" try: @@ -58,6 +61,7 @@ def get_system_info(): return jsonify({'error': str(e)}), 500 @health_bp.route('/api/health/acknowledge', methods=['POST']) +@require_admin_scope def acknowledge_error(): """ Acknowledge/dismiss an error manually. @@ -156,6 +160,7 @@ def acknowledge_error(): return jsonify({'error': str(e)}), 500 @health_bp.route('/api/health/un-acknowledge', methods=['POST']) +@require_admin_scope def unacknowledge_error(): """ Re-enable a previously dismissed error. @@ -203,6 +208,7 @@ def unacknowledge_error(): @health_bp.route('/api/health/active-errors', methods=['GET']) +@require_auth def get_active_errors(): """Get all active persistent errors""" try: @@ -213,6 +219,7 @@ def get_active_errors(): return jsonify({'error': str(e)}), 500 @health_bp.route('/api/health/dismissed', methods=['GET']) +@require_auth def get_dismissed_errors(): """ Get dismissed errors that are still within their suppression period. @@ -225,6 +232,7 @@ def get_dismissed_errors(): return jsonify({'error': str(e)}), 500 @health_bp.route('/api/health/full', methods=['GET']) +@require_auth def get_full_health(): """ Get complete health data in a single request: detailed status + active errors + dismissed. @@ -271,6 +279,7 @@ def get_full_health(): return jsonify({'error': str(e)}), 500 @health_bp.route('/api/health/cleanup-orphans', methods=['POST']) +@require_admin_scope def cleanup_orphan_errors(): """ Clean up errors for devices that no longer exist in the system. @@ -331,6 +340,7 @@ def cleanup_orphan_errors(): return jsonify({'error': str(e)}), 500 @health_bp.route('/api/health/pending-notifications', methods=['GET']) +@require_auth def get_pending_notifications(): """ Get events pending notification (for future Telegram/Gotify/Discord integration). @@ -343,6 +353,7 @@ def get_pending_notifications(): return jsonify({'error': str(e)}), 500 @health_bp.route('/api/health/mark-notified', methods=['POST']) +@require_admin_scope def mark_events_notified(): """ Mark events as notified after notification was sent successfully. @@ -364,6 +375,7 @@ def mark_events_notified(): @health_bp.route('/api/health/settings', methods=['GET']) +@require_auth def get_health_settings(): """ Get per-category suppression duration settings. @@ -377,6 +389,7 @@ def get_health_settings(): @health_bp.route('/api/health/settings', methods=['POST']) +@require_admin_scope def save_health_settings(): """ Save per-category suppression duration settings. @@ -422,6 +435,7 @@ def save_health_settings(): # ── Remote Storage Exclusions Endpoints ── @health_bp.route('/api/health/remote-storages', methods=['GET']) +@require_auth def get_remote_storages(): """ Get list of all remote storages with their exclusion status. @@ -472,6 +486,7 @@ def get_remote_storages(): @health_bp.route('/api/health/storage-exclusions', methods=['GET']) +@require_auth def get_storage_exclusions(): """Get all storage exclusions.""" try: @@ -482,6 +497,7 @@ def get_storage_exclusions(): @health_bp.route('/api/health/storage-exclusions', methods=['POST']) +@require_admin_scope def save_storage_exclusion(): """ Add or update a storage exclusion. @@ -535,6 +551,7 @@ def save_storage_exclusion(): @health_bp.route('/api/health/storage-exclusions/', methods=['DELETE']) +@require_admin_scope def delete_storage_exclusion(storage_name): """Remove a storage from the exclusion list.""" try: @@ -555,6 +572,7 @@ def delete_storage_exclusion(storage_name): # ═══════════════════════════════════════════════════════════════════════════ @health_bp.route('/api/health/interfaces', methods=['GET']) +@require_auth def get_network_interfaces(): """Get all network interfaces with their exclusion status.""" try: @@ -615,6 +633,7 @@ def get_network_interfaces(): @health_bp.route('/api/health/interface-exclusions', methods=['GET']) +@require_auth def get_interface_exclusions(): """Get all interface exclusions.""" try: @@ -625,6 +644,7 @@ def get_interface_exclusions(): @health_bp.route('/api/health/interface-exclusions', methods=['POST']) +@require_admin_scope def save_interface_exclusion(): """ Add or update an interface exclusion. @@ -677,6 +697,7 @@ def save_interface_exclusion(): @health_bp.route('/api/health/interface-exclusions/', methods=['DELETE']) +@require_admin_scope def delete_interface_exclusion(interface_name): """Remove an interface from the exclusion list.""" try: @@ -692,7 +713,102 @@ def delete_interface_exclusion(interface_name): return jsonify({'error': str(e)}), 500 +@health_bp.route('/api/health/disks', methods=['GET']) +@require_auth +def get_disks_for_exclusion(): + """Physical disks with whether each is excluded from periodic reads. + + Listed from udev and /sys only, so opening the settings page does not + touch a disk the user is about to exclude precisely to leave it alone. + """ + try: + from disk_identity import list_physical_disks + import disk_temperature_history as _dth + excluded = {e['disk_key']: e for e in health_persistence.get_excluded_disks()} + present = set() + result = [] + for disk in list_physical_disks(): + present.add(disk['key']) + entry = excluded.get(disk['key']) + result.append({ + **disk, + 'excluded': entry is not None, + 'excluded_at': entry.get('excluded_at') if entry else None, + 'idle': _dth.is_disk_idle(disk['name']), + 'present': True, + }) + # An excluded disk that is not connected right now — an unplugged USB + # drive — stays in the list, so its exclusion can still be seen and + # removed rather than silently waiting for it to come back. + for key, entry in excluded.items(): + if key in present: + continue + result.append({ + 'name': entry.get('disk_name') or '', + 'key': key, + 'model': entry.get('model') or '', + 'serial': entry.get('serial') or '', + 'size_bytes': 0, + 'transport': '', + 'rotational': False, + 'excluded': True, + 'excluded_at': entry.get('excluded_at'), + 'idle': False, + 'present': False, + }) + result.sort(key=lambda d: (not d['present'], d['name'])) + return jsonify({'disks': result}) + except Exception as e: + return jsonify({'error': str(e)}), 500 + + +@health_bp.route('/api/health/disk-exclusions', methods=['POST']) +@require_admin_scope +def save_disk_exclusion(): + """Exclude a disk from periodic reads. + + Request body: {"disk_key": "serial:WD-...", "disk_name": "sdb", + "model": "...", "serial": "...", "reason": "..."} + The key is the one /api/health/disks reports; it follows the disk + across kernel renames. + """ + try: + data = request.get_json(silent=True) or {} + disk_key = str(data.get('disk_key') or '').strip() + if not disk_key or ':' not in disk_key or len(disk_key) > 200: + return jsonify({'error': 'a valid disk_key is required'}), 400 + ok = health_persistence.exclude_disk( + disk_key, + disk_name=str(data.get('disk_name') or '')[:64] or None, + model=str(data.get('model') or '')[:128] or None, + serial=str(data.get('serial') or '')[:128] or None, + reason=str(data.get('reason') or '')[:500] or None, + ) + if not ok: + return jsonify({'error': 'Failed to save exclusion'}), 500 + import disk_temperature_history as _dth + _dth.invalidate_disk_exclusions() + return jsonify({'success': True, 'disk_key': disk_key}) + except Exception as e: + return jsonify({'error': str(e)}), 500 + + +@health_bp.route('/api/health/disk-exclusions/', methods=['DELETE']) +@require_admin_scope +def delete_disk_exclusion(disk_key): + """Put a disk back under periodic reads.""" + try: + if not health_persistence.remove_disk_exclusion(disk_key): + return jsonify({'error': 'Disk not found in exclusions'}), 404 + import disk_temperature_history as _dth + _dth.invalidate_disk_exclusions() + return jsonify({'success': True, 'disk_key': disk_key}) + except Exception as e: + return jsonify({'error': str(e)}), 500 + + @health_bp.route('/api/mounts', methods=['GET']) +@require_auth def get_remote_mounts(): """Sprint 13: list NFS/CIFS/SMB mounts on the host AND inside every running LXC, with per-mount health (reachable / stale / read-only). diff --git a/AppImage/scripts/flask_server.py b/AppImage/scripts/flask_server.py index b1e6cffb..6790784d 100644 --- a/AppImage/scripts/flask_server.py +++ b/AppImage/scripts/flask_server.py @@ -1616,8 +1616,10 @@ _system_info_cache = { 'proxmox_version_time': 0, 'available_updates': 0, 'available_updates_time': 0, + 'available_updates_stamp': 0.0, } _SYSTEM_INFO_CACHE_TTL = 21600 # 6 hours - update notifications are sent once per 24h +_AVAILABLE_UPDATES_MIN_INTERVAL = 30 # seconds between apt recounts when apt state moves # Cache for pvesh cluster resources (reduces repeated API calls) _pvesh_cache = { @@ -3316,15 +3318,39 @@ def get_proxmox_version(): _system_info_cache['proxmox_version_time'] = now return proxmox_version +def _apt_state_stamp(): + """Newest mtime of the files that decide what `apt list --upgradable` + answers: dpkg's status file (what is installed) and apt's package + lists (what is on offer). Any upgrade moves it — whichever way the + packages were installed.""" + newest = 0.0 + for path in ('/var/lib/dpkg/status', '/var/lib/apt/lists', '/var/cache/apt/pkgcache.bin'): + try: + newest = max(newest, os.path.getmtime(path)) + except OSError: + pass + return newest + + def get_available_updates(): - """Get the number of available package updates. Cached for 6 hours.""" + """Get the number of available package updates. Cached for 6 hours, + or until apt's own state moves — an upgrade that finishes two minutes + after the count was taken must not leave the overview showing what + was pending before it ran.""" global _system_info_cache - + now = time.time() - if _system_info_cache['available_updates_time'] > 0 and \ - now - _system_info_cache['available_updates_time'] < _SYSTEM_INFO_CACHE_TTL: - return _system_info_cache['available_updates'] - + stamp = _apt_state_stamp() + age = now - _system_info_cache['available_updates_time'] + if _system_info_cache['available_updates_time'] > 0: + # dpkg rewrites its status file once per package, so during an + # upgrade the stamp moves with every one of them. The floor keeps + # that from turning each overview poll into an apt call. + if age < _AVAILABLE_UPDATES_MIN_INTERVAL: + return _system_info_cache['available_updates'] + if stamp == _system_info_cache['available_updates_stamp'] and age < _SYSTEM_INFO_CACHE_TTL: + return _system_info_cache['available_updates'] + available_updates = 0 try: # Use apt list --upgradable to count available updates @@ -3340,6 +3366,7 @@ def get_available_updates(): _system_info_cache['available_updates'] = available_updates _system_info_cache['available_updates_time'] = now + _system_info_cache['available_updates_stamp'] = stamp return available_updates # AGREGANDO FUNCIÓN PARA PARSEAR PROCESOS DE INTEL_GPU_TOP (SIN -J) @@ -4123,9 +4150,13 @@ def get_storage_info(): # temperature graph isn't a monitor bug — the # disk is parked. See issue #232. in_standby = False + in_idle = False + in_excluded = False try: import disk_temperature_history as _dth in_standby = _dth.is_disk_in_standby(disk_name) + in_idle = _dth.is_disk_idle(disk_name) + in_excluded = disk_name in _dth.excluded_disk_names() except Exception: pass physical_disks[disk_name] = { @@ -4135,6 +4166,8 @@ def get_storage_info(): 'size_bytes': disk_size_bytes, 'temperature': smart_data.get('temperature', 0), 'standby': in_standby, + 'idle': in_idle, + 'excluded': in_excluded, 'health': smart_data.get('health', 'unknown'), 'power_on_hours': smart_data.get('power_on_hours', 0), 'smart_status': smart_data.get('smart_status', 'unknown'), @@ -4860,6 +4893,22 @@ def get_smart_data(disk_name): if cached and now - cached[0] < _SMART_RESULT_TTL: return dict(cached[1]) + # Excluded, or rotational with no I/O since it was last looked at: send + # it nothing — not even the power-mode question below, which is still a + # command. Serve what is known, without a temperature that would only be + # stale. Same rule as the temperature poller, so the two agree. + try: + import disk_temperature_history as _dth + policy = _dth.disk_read_policy(disk_name) + except Exception: + policy = 'read' + if policy != 'read': + base = dict(cached[1]) if cached else _smart_default_payload() + base['temperature'] = 0 + base['excluded'] = policy == 'excluded' + base['idle'] = policy == 'idle' + return base + if _hdd_in_standby(disk_name): # Keep serving the last known values (temperature blanked, since # we don't have a fresh one) so the card stays populated while @@ -14433,7 +14482,7 @@ def api_health_thresholds_get(): @app.route('/api/health/thresholds', methods=['PUT']) -@require_auth +@require_admin_scope def api_health_thresholds_put(): """Save a partial threshold payload. Body shape mirrors DEFAULTS but the leaves are bare numbers, not metadata dicts. Sections not @@ -14453,7 +14502,7 @@ def api_health_thresholds_put(): @app.route('/api/health/thresholds/reset', methods=['POST']) -@require_auth +@require_admin_scope def api_health_thresholds_reset(): """Reset thresholds. ?section= resets one section, no parameter resets everything to recommended.""" @@ -14473,7 +14522,7 @@ def api_health_thresholds_reset(): @app.route('/api/health/acknowledge', methods=['POST']) -@require_auth +@require_admin_scope def api_health_acknowledge(): """Acknowledge/dismiss a health error by error_key. @@ -14502,7 +14551,7 @@ def api_health_acknowledge(): @app.route('/api/health/un-acknowledge', methods=['POST']) -@require_auth +@require_admin_scope def api_health_unacknowledge(): """Reverse a previous dismiss — re-enables the alert so it can fire again. @@ -20148,7 +20197,11 @@ def _borg_env_for(target: dict, extra: dict | None = None) -> dict: env['BORG_PASSPHRASE'] = pw ssh_key = target.get('ssh_key') or '' if ssh_key: - env['BORG_RSH'] = f'ssh -i {ssh_key} -o StrictHostKeyChecking=accept-new' + # IdentitiesOnly keeps ssh from offering root's default keys first: + # a server that only accepts the ProxMenux key can hit MaxAuthTries + # before it is ever tried. borg adds `-p ` from the ssh:// URL. + env['BORG_RSH'] = (f'ssh -i {ssh_key} -o IdentitiesOnly=yes ' + '-o StrictHostKeyChecking=accept-new') # Non-interactive: if borg would prompt about a relocated repo, take # the safe answer instead of hanging the request. env['BORG_RELOCATED_REPO_ACCESS_IS_OK'] = 'yes' diff --git a/AppImage/scripts/health_persistence.py b/AppImage/scripts/health_persistence.py index d83031f2..4fb13fc7 100644 --- a/AppImage/scripts/health_persistence.py +++ b/AppImage/scripts/health_persistence.py @@ -421,6 +421,22 @@ class HealthPersistence: ) ''') cursor.execute('CREATE INDEX IF NOT EXISTS idx_excluded_interface ON excluded_interfaces(interface_name)') + + # Disks the user wants left alone: no periodic SMART or temperature + # reads, so a drive can reach its own spin-down and stop cycling its + # heads. Keyed by a stable identity rather than the kernel name, which + # a USB drive can change (sda -> sdb) on every reconnection. + cursor.execute(''' + CREATE TABLE IF NOT EXISTS excluded_disks ( + id INTEGER PRIMARY KEY AUTOINCREMENT, + disk_key TEXT UNIQUE NOT NULL, + disk_name TEXT, + model TEXT, + serial TEXT, + excluded_at TEXT NOT NULL, + reason TEXT + ) + ''') conn.commit() @@ -430,7 +446,7 @@ class HealthPersistence: required_tables = {'errors', 'events', 'system_capabilities', 'user_settings', 'notification_history', 'notification_last_sent', 'notification_delivery_claims', 'disk_registry', 'disk_observations', - 'excluded_storages', 'excluded_interfaces'} + 'excluded_storages', 'excluded_interfaces', 'excluded_disks'} missing = required_tables - tables if missing: print(f"[HealthPersistence] WARNING: Missing tables after init: {missing}") @@ -3257,6 +3273,67 @@ class HealthPersistence: print(f"[HealthPersistence] Error removing interface exclusion: {e}") return False + # ------------------------------------------------------------------ + # Disk exclusions + # ------------------------------------------------------------------ + + def get_excluded_disks(self) -> List[Dict[str, Any]]: + """Every disk the user has excluded from periodic reads.""" + try: + with self._db_connection(row_factory=True) as conn: + cursor = conn.cursor() + cursor.execute(''' + SELECT disk_key, disk_name, model, serial, excluded_at, reason + FROM excluded_disks + ''') + return [dict(row) for row in cursor.fetchall()] + except Exception as e: + print(f"[HealthPersistence] Error getting excluded disks: {e}") + return [] + + def exclude_disk(self, disk_key: str, disk_name: str = None, model: str = None, + serial: str = None, reason: str = None) -> bool: + """Add a disk to the exclusion list, or refresh its display fields.""" + try: + with self._db_connection() as conn: + cursor = conn.cursor() + cursor.execute(''' + INSERT INTO excluded_disks + (disk_key, disk_name, model, serial, excluded_at, reason) + VALUES (?, ?, ?, ?, ?, ?) + ON CONFLICT(disk_key) DO UPDATE SET + disk_name = excluded.disk_name, + model = excluded.model, + serial = excluded.serial + ''', (disk_key, disk_name, model, serial, datetime.now().isoformat(), reason)) + conn.commit() + return True + except Exception as e: + print(f"[HealthPersistence] Error excluding disk: {e}") + return False + + def remove_disk_exclusion(self, disk_key: str) -> bool: + """Put a disk back under periodic reads.""" + try: + with self._db_connection() as conn: + cursor = conn.cursor() + cursor.execute('DELETE FROM excluded_disks WHERE disk_key = ?', (disk_key,)) + conn.commit() + return cursor.rowcount > 0 + except Exception as e: + print(f"[HealthPersistence] Error removing disk exclusion: {e}") + return False + + def get_excluded_disk_keys(self) -> set: + """Stable keys of the excluded disks (see disk_identity.disk_key).""" + try: + with self._db_connection() as conn: + cursor = conn.cursor() + cursor.execute('SELECT disk_key FROM excluded_disks') + return {row[0] for row in cursor.fetchall()} + except Exception: + return set() + def get_excluded_interface_names(self, check_type: str = 'health') -> set: """ Get set of interface names excluded for a specific check type. diff --git a/AppImage/scripts/lxc_apps.py b/AppImage/scripts/lxc_apps.py index 18ce86c5..117e077f 100644 --- a/AppImage/scripts/lxc_apps.py +++ b/AppImage/scripts/lxc_apps.py @@ -2622,6 +2622,7 @@ def annotate_delegated_apps(apps: list, docker_inventory: dict) -> None: # showing the version of an image it no longer runs. app['docker_available_version'] = None app['docker_update_available'] = None + app['docker_pinned'] = None link = resolve_docker_image_for_app(app, docker_inventory) app['docker_image_reference'] = link.get('image_reference') app['docker_binding_error'] = link.get('error') @@ -2633,6 +2634,7 @@ def annotate_delegated_apps(apps: list, docker_inventory: dict) -> None: continue app['docker_available_version'] = image.get('available_version') app['docker_update_available'] = image.get('update_available') + app['docker_pinned'] = image.get('pinned') break except Exception: pass @@ -2903,6 +2905,7 @@ def _docker_inventory_from_ct(vmid) -> dict: "architecture": str(inspected_image.get("Architecture") or ""), "variant": str(inspected_image.get("Variant") or ""), }, + "pinned": False, "available_version": None, "available_version_source": None, "update_available": None, @@ -2911,13 +2914,78 @@ def _docker_inventory_from_ct(vmid) -> dict: if len(images) >= _DOCKER_MAX_IMAGES: break + # A container pinned by digest runs exactly the image it names; a newer + # tag upstream does not move it, only an edit to its reference does. It is + # listed under that reference with its installed version, and is never + # compared with the registry nor offered an update. + pinned_groups: dict[str, list[dict]] = {} + for item in containers: + reference = str(item.get("image_reference") or item.get("image") or "").strip() + if "@" in reference: + pinned_groups.setdefault(reference, []).append(item) + for reference in sorted(pinned_groups): + if len(images) >= _DOCKER_MAX_IMAGES: + break + name, _, pinned_digest = reference.partition("@") + if not re.fullmatch(r"sha256:[0-9a-f]{64}", pinned_digest): + continue + final_component = name.rsplit("/", 1)[-1] + repository, tag = name.rsplit(":", 1) if ":" in final_component else (name, "") + parsed = _parse_docker_reference(repository, tag or pinned_digest) + if not parsed or reference in seen: + continue + seen.add(reference) + parsed = {**parsed, "tag": tag, "reference": reference} + group = pinned_groups[reference] + image_id = next((str(item.get("image_id")) for item in group if item.get("image_id")), "") + inspected_image = ( + inspected_images.get(image_id) + or inspected_images.get(image_id.removeprefix("sha256:")) + or {} + ) + installed_version, installed_version_source = _docker_version_from_image_inspect( + parsed, inspected_image, + ) + primary_compose = group[0].get("compose") or {} + display_meta = _docker_service_catalog_meta( + str(primary_compose.get("service") or ""), + str(group[0].get("name") or ""), + reference, + ) + images.append({ + **parsed, + "local_digest": pinned_digest, + "remote_digest": None, + "image_id": image_id, + "used_by": sorted({item["name"] for item in group}), + "update_targets": [], + "standalone_containers": [], + "display_name": display_meta.get("name"), + "logo_url": display_meta.get("logo_url"), + "installed_version": installed_version, + "installed_version_source": installed_version_source, + "platform": { + "os": str(inspected_image.get("Os") or ""), + "architecture": str(inspected_image.get("Architecture") or ""), + "variant": str(inspected_image.get("Variant") or ""), + }, + "pinned": True, + "available_version": None, + "available_version_source": None, + "update_available": None, + "error": None, + }) + def _check(item: dict) -> tuple[str, Optional[str], Optional[str]]: remote, error = _fetch_registry_manifest_digest(item) return item["reference"], remote, error if images: - with concurrent.futures.ThreadPoolExecutor(max_workers=min(4, len(images))) as pool: - results = list(pool.map(_check, images)) + checkable = [item for item in images if not item.get("pinned")] + results = [] + if checkable: + with concurrent.futures.ThreadPoolExecutor(max_workers=min(4, len(checkable))) as pool: + results = list(pool.map(_check, checkable)) by_ref = {ref: (digest, error) for ref, digest, error in results} for item in images: remote, remote_error = by_ref.get(item["reference"], (None, None)) diff --git a/AppImage/scripts/oci_manager.py b/AppImage/scripts/oci_manager.py index 4d004525..5d8624a1 100644 --- a/AppImage/scripts/oci_manager.py +++ b/AppImage/scripts/oci_manager.py @@ -40,9 +40,10 @@ CATALOG_FILE = os.path.join(OCI_BASE_DIR, "catalog.json") INSTALLED_FILE = os.path.join(OCI_BASE_DIR, "installed.json") INSTANCES_DIR = os.path.join(OCI_BASE_DIR, "instances") -# Source catalog from Scripts (bundled with ProxMenux) -SCRIPTS_CATALOG = "/usr/local/share/proxmenux/scripts/oci/catalog.json" -DEV_SCRIPTS_CATALOG = os.path.join(os.path.dirname(__file__), "..", "..", "Scripts", "oci", "catalog.json") +# Source catalog shipped with ProxMenux, inside the OCI engine +SCRIPTS_CATALOG = os.path.join(OCI_BASE_DIR, "engine", "addons", "secure-gateway.json") +LEGACY_SCRIPTS_CATALOG = "/usr/local/share/proxmenux/scripts/oci/catalog.json" +DEV_SCRIPTS_CATALOG = os.path.join(os.path.dirname(__file__), "..", "..", "oci", "addons", "secure-gateway.json") # Encryption key file ENCRYPTION_KEY_FILE = os.path.join(OCI_BASE_DIR, ".encryption_key") @@ -143,10 +144,10 @@ def ensure_oci_directories(): os.makedirs(INSTANCES_DIR, exist_ok=True) if not os.path.exists(CATALOG_FILE): - if os.path.exists(SCRIPTS_CATALOG): - shutil.copy2(SCRIPTS_CATALOG, CATALOG_FILE) - elif os.path.exists(DEV_SCRIPTS_CATALOG): - shutil.copy2(DEV_SCRIPTS_CATALOG, CATALOG_FILE) + for source in (SCRIPTS_CATALOG, LEGACY_SCRIPTS_CATALOG, DEV_SCRIPTS_CATALOG): + if os.path.exists(source): + shutil.copy2(source, CATALOG_FILE) + break if not os.path.exists(INSTALLED_FILE): with open(INSTALLED_FILE, 'w') as f: @@ -689,7 +690,7 @@ def load_catalog() -> Dict[str, Any]: """Load the OCI app catalog.""" ensure_oci_directories() - for path in [CATALOG_FILE, SCRIPTS_CATALOG, DEV_SCRIPTS_CATALOG]: + for path in [CATALOG_FILE, SCRIPTS_CATALOG, LEGACY_SCRIPTS_CATALOG, DEV_SCRIPTS_CATALOG]: if os.path.exists(path): try: with open(path, 'r') as f: diff --git a/install_proxmenux.sh b/install_proxmenux.sh index 87051211..96d74701 100755 --- a/install_proxmenux.sh +++ b/install_proxmenux.sh @@ -847,6 +847,15 @@ install_normal_version() { pmx_journal_context "install_proxmenux" "1.0" "install_proxmenux" pmx_record_install "dialog jq curl git" "1.0" fi + + # The OCI engine is replaced on every install; instance records and + # addon state stored next to it in $BASE_DIR/oci are preserved. + if [ -d "./oci" ]; then + rm -rf "$BASE_DIR/oci/engine" + mkdir -p "$BASE_DIR/oci/engine" + cp -r "./oci/"* "$BASE_DIR/oci/engine/" + find "$BASE_DIR/oci/engine" -type f -name '*.sh' -exec chmod +x {} + + fi chmod +x "$BASE_DIR/install_proxmenux.sh" msg_ok "Necessary files created." diff --git a/install_proxmenux_beta.sh b/install_proxmenux_beta.sh index 1c23c5ac..81699714 100644 --- a/install_proxmenux_beta.sh +++ b/install_proxmenux_beta.sh @@ -738,9 +738,13 @@ install_beta() { pmx_record_install "dialog jq curl git" "1.0" fi + # The OCI engine is replaced on every install; instance records and + # addon state stored next to it in $BASE_DIR/oci are preserved. if [ -d "./oci" ]; then - mkdir -p "$BASE_DIR/oci" - cp -r "./oci/"* "$BASE_DIR/oci/" 2>/dev/null || true + rm -rf "$BASE_DIR/oci/engine" + mkdir -p "$BASE_DIR/oci/engine" + cp -r "./oci/"* "$BASE_DIR/oci/engine/" + find "$BASE_DIR/oci/engine" -type f -name '*.sh' -exec chmod +x {} + fi chmod +x "$INSTALL_DIR/$MENU_SCRIPT" [ -f "$BASE_DIR/install_proxmenux.sh" ] && chmod +x "$BASE_DIR/install_proxmenux.sh" diff --git a/lang/de.json b/lang/de.json index 38ee0395..7f33e99c 100644 --- a/lang/de.json +++ b/lang/de.json @@ -7,6 +7,7 @@ "(common default on Debian/LXC: PermitRootLogin prohibit-password).": "(allgemeiner Standard unter Debian/LXC: PermitRootLogin prohibit-password).", "(disabled)": "(deaktiviert)", "(e.g.": "(z. B.", + "(empty)": "(leer)", "(for unprivileged LXCs)": "(für unprivilegierte LXCs)", "(if only privileged LXCs need write access)": "(wenn nur privilegierte LXCs Schreibzugriff benötigen)", "(make.log not found — DKMS may have failed before invoking make)": "(make.log nicht gefunden – DKMS ist möglicherweise vor dem Aufruf von make fehlgeschlagen)", @@ -19,6 +20,7 @@ "(recommended)": "(empfohlen)", "(same MAC — restored config adjusted automatically)": "(gleicher MAC – wiederhergestellte Konfiguration automatisch angepasst)", ")": ")", + "*Arr Suite": "*Arr Suite", "+ Add a path": "+ Fügen Sie einen Pfad hinzu", "+ Add new Borg target": "+ Neues Borg-Ziel hinzufügen", "+ Add new PBS manually": "+ Neues PBS manuell hinzufügen", @@ -35,39 +37,101 @@ "/var/lib/vz/dump (Proxmox default)": "/var/lib/vz/dump (Proxmox-Standard)", "1777 = sticky bit + rwx for all. No shared group needed.": "1777 = Sticky Bit + RWX für alle. Keine gemeinsame Gruppe erforderlich.", "====== PVE UPDATE COMPLETED ======": "====== PVE-UPDATE ABGESCHLOSSEN ======", + "A GTK Broadway web UI for libvirt and virt-manager.": "Ein GTK Broadway Web UI für libvirt und virt-manager.", + "A Personal Relationship Management tool to help you document your social life.": "Eine persönliche Beziehung Management-Tool, das Ihnen hilft, Ihr soziales Leben zu dokumentieren.", "A VirtIO ISO already exists. Do you want to overwrite it?": "Eine VirtIO-ISO ist bereits vorhanden. Möchten Sie es überschreiben?", "A ZFS pool with this name already exists.": "Ein ZFS-Pool mit diesem Namen ist bereits vorhanden.", "A ZFS pool with this name already exists:": "Ein ZFS-Pool mit diesem Namen existiert bereits:", + "A backup was modified": "Ein Backup wurde modifiziert", + "A command did not finish in time:": "Ein Befehl endete nicht rechtzeitig:", "A complete restore will:": "Eine vollständige Wiederherstellung führt zu Folgendem:", + "A concurrent change was detected; the container is not removed": "Eine gleichzeitige Veränderung wurde festgestellt; der Behälter wird nicht entfernt", + "A container mount has a source, backup or permission different from the saved record": "Eine Containerhalterung hat eine Quelle, ein Backup oder eine Berechtigung, die sich von dem gespeicherten Datensatz unterscheidet", + "A coordinated operation is pending. The whole previous stack will be recovered, not only the selected member. If the operation already finished, the cleanup of its markers is completed.": "Eine koordinierte operation steht aus. Der gesamte vorherige Stapel wird wiederhergestellt, nicht nur das ausgewählte Mitglied. Wenn die operation bereits abgeschlossen ist, ist die Reinigung ihrer Marker abgeschlossen.", + "A different host monitor include already exists; it is not overwritten:": "Ein anderer Host-Monitor ist bereits vorhanden; er wird nicht überschrieben:", + "A fancy monitoring tool": "Ein ausgefallenes Monitoring-Tool", + "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata.": "Ein kostenloses und Open-Source-übergreifendes, dokumentenorientiertes Datenbankprogramm. Als NoSQL-Datenbankprogramm klassifiziert, verwendet MongoDB JSON-ähnliche Dokumente mit Schemata.", + "A free reverse proxy for tunneling services (not self-hosted).": "Ein kostenloser Reverse-Proxy für Tunneldienste (nicht selbst gehostet).", + "A free, self-hostable news aggregator…": "Ein kostenloser, selbst-hostabler Nachrichten-Aggregator...", + "A full-featured, open-source AI chat interface": "Eine voll ausgestattete, open-source-ki-chat-schnittstelle.", "A gasket DKMS registration is still present:": "Eine gasket-DKMS-Registrierung ist noch vorhanden:", + "A host bind mount cannot be included in vzdump": "Ein Host-Bind-Mount kann nicht in vzdump enthalten sein", + "A host mount is not part of the journal; recovery blocked": "Ein Host-Mount ist nicht Teil des Journals; Recovery blockiert", "A host reboot is required after this change.": "Nach dieser Änderung ist ein Neustart des Hosts erforderlich.", "A host reboot is required before starting the VM. Reboot now?": "Vor dem Starten der VM ist ein Host-Neustart erforderlich. Jetzt neu starten?", "A job with this ID already exists.": "Ein Job mit dieser ID existiert bereits.", + "A journal already exists; review or recover it before trying again": "Eine Zeitschrift existiert bereits; überprüfen oder wiederherstellen, bevor Sie es erneut versuchen", "A keyfile is installed at:": "Eine Schlüsseldatei ist installiert unter:", "A legacy gasket-dkms package was found on this host, but no Coral M.2 / PCIe hardware is present.": "Auf diesem Host wurde ein veraltetes gasket-dkms-Paket gefunden, es ist jedoch keine Coral M.2/PCIe-Hardware vorhanden.", + "A managed rootfs and an unprivileged container are required": "Ein Managed Rootf und ein unprivilegierter Container sind required", + "A managed volume with backup enabled is required": "Ein verwaltetes Volume mit Backup ist required", + "A member VMID is in use by another guest or is on another node": "Ein Mitglieds-VMID wird von einem anderen Gast verwendet oder befindet sich auf einem anderen Knoten", + "A member configuration changed after the stack was checked": "Eine Mitgliedskonfiguration wurde geändert, nachdem der Stapel überprüft wurde", + "A member configuration changed during the preparation": "Eine Mitgliedskonfiguration wurde während der Vorbereitung geändert", + "A member did not pass its service check:": "Ein Mitglied hat seinen Service-Check nicht bestanden:", + "A member has a pending operation": "Ein Mitglied hat eine ausstehende operation", + "A member has no reproducible service check": "Ein Mitglied hat keine reproduzierbare Serviceprüfung", + "A member is missing before the replacement": "Ein Mitglied fehlt vor dem Ersatz", + "A member operation does not belong to the stack": "Ein Mitglied operation gehört nicht zum Stack", + "A member stopped:": "Ein Mitglied stoppte:", + "A member was modified after it was recovered": "Ein Mitglied wurde modifiziert, nachdem es wiederhergestellt wurde", + "A modern wiki and knowledge base for teams": "Ein modernes Wiki und Wissensbasis für Teams", "A new ProxMenux version is available:": "Eine neue ProxMenux-Version ist verfügbar:", "A new kernel is staged for the next boot:": "Ein neuer Kernel wird für den nächsten Start bereitgestellt:", "A newer version is available:": "Eine neuere Version ist verfügbar:", + "A pending operation exists for": "Eine ausstehende operation existiert für", + "A pending stack assembly already exists; it is not overwritten": "Eine ausstehende Stapelanordnung existiert bereits; sie wird nicht überschrieben", + "A previous NVIDIA refresh is pending review": "Eine frühere NVIDIA-Aktualisierung steht noch aus", "A previous VFIO passthrough configuration was detected for the following NVIDIA GPU(s):": "Für die folgenden NVIDIA-GPU(s) wurde eine frühere VFIO-Passthrough-Konfiguration erkannt:", + "A privacy-first, open-source platform for knowledge management and collaboration.": "Eine Privacy-First-Open-Source-Plattform für Wissensmanagement und Zusammenarbeit.", "A reboot is recommended before the GPU is guaranteed to stay on the native driver.": "Ein Neustart wird empfohlen, bevor die GPU garantiert auf dem nativen Treiber bleibt.", "A reboot is required after installation to load the new kernel modules.": "Nach der Installation ist ein Neustart erforderlich, um die neuen Kernelmodule zu laden.", "A reboot is required for VFIO binding to take effect. Do you want to restart now?": "Damit die VFIO-Bindung wirksam wird, ist ein Neustart erforderlich. Möchten Sie jetzt neu starten?", "A reboot is required to apply the new GPU mode. Do you want to restart now?": "Um den neuen GPU-Modus anzuwenden, ist ein Neustart erforderlich. Möchten Sie jetzt neu starten?", "A reboot is required to finish the restore.": "Um die Wiederherstellung abzuschließen, ist ein Neustart erforderlich.", "A reboot will be required to complete the restore.": "Ein Neustart ist erforderlich, um die Wiederherstellung abzuschließen.", + "A reproducible native startup is missing": "Ein reproduzierbares natives Startup fehlt", + "A rootfs adaptation is stored in persistent storage": "Eine Rootfs-Adaption wird im persistenten Speicher gespeichert", + "A self-hosted Bitwarden server": "Ein selbst gehosteter Bitwarden-Server", + "A self-hosted, goal-free habit tracking tool.": "Ein selbst gehostetes, zielfreies Habit-Tracking-Tool.", + "A self-improving AI agent with memory, skills, messaging, and a web dashboard.": "Ein sich selbst verbessernder KI-Agent mit Speicher, Fähigkeiten, Messaging und einem Web-Dashboard.", "A server reboot is recommended for all changes to take full effect.": "Damit alle Änderungen vollständig wirksam werden, wird ein Neustart des Servers empfohlen.", + "A shared directory was replaced during the installation": "Ein gemeinsames Verzeichnis wurde während der Installation ersetzt", + "A shared source does not match its recorded identity": "Eine freigegebene Quelle stimmt nicht mit ihrer aufgezeichneten Identität überein", + "A simple, open-source file sharing host.": "Ein einfacher, Open-Source-Dateifreigabe-Host.", + "A simple, private file server.": "Ein einfacher, privater Dateiserver.", + "A single matching image platform cannot be resolved": "Eine einzelne passende Bildplattform kann nicht aufgelöst werden", + "A single-platform OCI archive is required": "Ein OCI-Archiv mit einer einzigen Plattform ist required", + "A stack backup is missing; a partial restore is not allowed": "Ein Stapel-Backup fehlt; eine teilweise Wiederherstellung ist nicht erlaubt", + "A stack member has a different identity": "Ein Stapelelement hat eine andere Identität", "A system reboot is recommended to ensure all changes take effect.": "Um sicherzustellen, dass alle Änderungen wirksam werden, wird ein Systemneustart empfohlen.", + "A third party companion app available to Plex server owners to allow their users to request, review and discover content.": "Eine Begleit-App von Drittanbietern, die Plex-Serverbesitzern zur Verfügung steht, damit ihre Benutzer Inhalte anfordern, überprüfen und entdecken können.", + "A third-party client for self-hosted server and self-hosted server, remote access management interface, remote access to installed applications.": "Ein Client von Drittanbietern für selbst gehostete Server und selbst gehostete Server, Remote Access Management-Schnittstelle, Fernzugriff auf installierte Anwendungen.", + "A tmpfs mount is not part of the journal; recovery blocked": "Ein tmpfs-Mount ist nicht Teil des Journals; Recovery blockiert", + "A tmpfs mount overlaps another mount": "Ein tmpfs-Mount überlappt ein anderes Mount", + "A tunneling daemon by Cloudflare that safely exposes your web servers into the internet.": "Ein Tunnel-Daemon von Cloudflare, der Ihre Webserver sicher im Internet aussetzt.", + "A versatile file conversion tool that supports multiple formats.": "Ein vielseitiges Dateikonvertierungstool, das mehrere Formate unterstützt.", + "A web GUI client of Project V which supports VMess, VLESS, SS, SSR, Trojan, Tuic and Juicity protocols": "Ein Web-GUI-Client von Project V, der die Protokolle VMess, VLESS, SS, SSR, Trojan, Tuic und Juicity unterstützt", + "A web app to listen Youtube audio source.": "Eine Web-App zum Hören von YouTube-Audioquellen.", + "A web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes": "Eine Web-App zur Verwaltung Ihrer Zwei-Faktor-Authentifizierungskonten (2FA) und zur Generierung ihrer Sicherheitscodes", + "A web frontend for the motion daemon.": "Ein Web-Frontend für den Motion-Daemon.", + "A web-based file sharing and management protocol": "Ein webbasiertes Filesharing- und Managementprotokoll", + "A well-designed cross-platform ChatGPT UI.": "Eine gut gestaltete Cross-Plattform ChatGPT UI.", "ACL Status:": "ACL-Status:", "ACL permissions applied for local access for user:": "ACL-Berechtigungen für lokalen Zugriff für Benutzer angewendet:", "ADVANCED SETTINGS COMPLETE": "ERWEITERTE EINSTELLUNGEN ABGESCHLOSSEN", "ALL DATA ON": "ALLE DATEN EIN", "ALL DATA ON THIS DISK WILL BE PERMANENTLY LOST!": "ALLE DATEN AUF DIESER Diskette gehen dauerhaft verloren!", "ALL Utilities": "ALLE Dienstprogramme", + "ALLOWED_HOSTS cannot contain line breaks": "ALLOWED HOSTS kann keine Zeilenumbrüche enthalten", + "AList initial login": "AList Erstanmeldung", "AMD CPU detected": "AMD-CPU erkannt", "AMD CPU fixes applied successfully": "AMD-CPU-Korrekturen erfolgreich angewendet", "AMD GPU Tools installation completed!": "Die Installation der AMD GPU Tools ist abgeschlossen!", "AMD GPU passthrough configured.": "AMD GPU-Passthrough konfiguriert.", "AMD GPU(s) detected:": "Erkannte AMD-GPU(s):", + "AMD KFD device": "AMD KFD-Vorrichtung", + "AMD VA-API + OpenCL (official mod)": "AMD VA-API + OpenCL (offizieller Mod)", "AMD fixes have been successfully reverted": "AMD-Korrekturen wurden erfolgreich rückgängig gemacht", "AMD mesa drivers installed.": "AMD Mesa-Treiber installiert.", "AMD softdep configured": "AMD-Softdep konfiguriert", @@ -93,9 +157,21 @@ "About to restore": "Wird gerade wiederhergestellt", "Absolute directory path to use as backup target:": "Absoluter Verzeichnispfad zur Verwendung als Sicherungsziel:", "Absolute path to a file or directory you want backed up:": "Absoluter Pfad zu einer Datei oder einem Verzeichnis, die/das Sie sichern möchten:", + "Acceleration": "Beschleunigung", + "Acceleration configuration cancelled": "Beschleunigungskonfiguration abgesagt", + "Acceleration for CodeProject.AI": "Beschleunigung für CodeProject. AI", + "Acceleration for Immich smart recognition": "Beschleunigung für Immich smart recognition", + "Acceleration for Ollama": "Beschleunigung für Ollama", "Accept routes from other nodes?": "Routen von anderen Knoten akzeptieren?", + "Accept this host monitoring profile?": "Akzeptieren Sie dieses Host Monitoring Profil?", "Access Scope:": "Zugriffsbereich:", + "Access bridge": "Zugangsbrücke", + "Access bridge for Immich": "Access Bridge für Immich", + "Access bridge for Nextcloud": "Access Bridge für Nextcloud", + "Access bridge for Paperless": "Access Bridge für Paperless", + "Access bridge for Tandoor": "Access Bridge für Tandoor", "Access profile:": "Zugangsprofil:", + "Access token of the Jupyter Lab web interface": "Access-Token des Jupyter Lab Webinterfaces", "Account is not locked": "Das Konto ist nicht gesperrt", "Action cancelled due to previous xshok-proxmox modifications.": "Aktion aufgrund früherer xshok-proxmox-Änderungen abgebrochen.", "Action:": "Aktion:", @@ -105,6 +181,10 @@ "Active Connections": "Aktive Verbindungen", "Active exports:": "Aktive Exporte:", "Active session:": "Aktive Sitzung:", + "Actual device path on the host": "Tatsächlicher Gerätepfad auf dem Host", + "Adaptation file too large": "Anpassungsdatei zu groß", + "Adaptation file with unexpected permissions or owner": "Anpassungsdatei mit unerwarteten Berechtigungen oder Besitzer", + "Adblock & DNS": "Adblock & DNS", "Add Audio Passthrough": "Fügen Sie Audio-Passthrough hinzu", "Add CIFS storage:": "CIFS-Speicher hinzufügen:", "Add Controller or NVMe (PCI passthrough)": "Controller oder NVMe hinzufügen (PCI-Passthrough)", @@ -123,6 +203,9 @@ "Add PBS": "PBS hinzufügen", "Add Samba Share as Proxmox Storage": "Samba-Freigabe als Proxmox-Speicher hinzufügen", "Add Samba share as Proxmox Storage": "Samba-Freigabe als Proxmox-Speicher hinzufügen", + "Add a Coral PCIe/M.2 device?": "Hinzufügen eines Coral PCIe/M.2-Geräts?", + "Add a custom data path?": "Fügen Sie einen benutzerdefinierten Datenpfad hinzu?", + "Add an extra custom path": "Hinzufügen eines zusätzlichen benutzerdefinierten Pfades", "Add as IDE": "Als IDE hinzufügen", "Add as SATA": "Als SATA hinzufügen", "Add as SCSI": "Als SCSI hinzufügen", @@ -140,6 +223,7 @@ "Add import disk": "Importdatenträger hinzufügen", "Add latest Ceph support": "Neueste Ceph-Unterstützung hinzufügen", "Add new PVE 9 enterprise repository (deb822 format) (Only if using enterprise):": "Neues PVE 9-Unternehmens-Repository hinzufügen (deb822-Format) (nur bei Verwendung von Enterprise):", + "Add or change a device": "Hinzufügen oder Ändern eines Geräts", "Add physical disk to VM via": "Fügen Sie der VM eine physische Festplatte hinzu über", "Add share block in /etc/samba/smb.conf:": "Freigabeblock in /etc/samba/smb.conf hinzufügen:", "Add unprivileged flag to container configuration:": "Unprivilegiert-Flag zur Containerkonfiguration hinzufügen:", @@ -154,20 +238,37 @@ "Adding": "Hinzufügen", "Adding CIFS storage to Proxmox...": "CIFS-Speicher zu Proxmox hinzufügen...", "Adding QEMU Guest Agent support...": "QEMU Guest Agent-Unterstützung wird hinzugefügt...", + "Adding Radarr to Prowlarr...": "Hinzufügen von Radarr zu Prowlarr...", + "Adding Sonarr to Prowlarr...": "Hinzufügen von Sonarr zu Prowlarr...", "Adding disk using the generated command to the selected VM": "Hinzufügen einer Festplatte mithilfe des generierten Befehls zur ausgewählten VM", "Adding existing users to sharedfiles group...": "Vorhandene Benutzer werden zur Sharedfiles-Gruppe hinzugefügt...", "Adding iSCSI storage to Proxmox...": "iSCSI-Speicher zu Proxmox hinzufügen...", "Adding new share to smb.conf...": "Neue Freigabe zur smb.conf hinzufügen...", + "Adding peers later means raising PEERS in /etc/pve/lxc/.conf and restarting the container. The existing peer keys are kept.": "Das spätere Hinzufügen von Peers bedeutet, PEERS in /etc/pve/lxc/.conf zu erhöhen und den Container neu zu starten. Die vorhandenen Peer Keys werden beibehalten.", + "Adding the mount points...": "Hinzufügen der Mount Points...", "Adding this NVMe as a PCIe device (via 'Add Controller or NVMe PCIe to VM') gives better performance.": "Das Hinzufügen dieses NVMe als PCIe-Gerät (über „Controller oder NVMe PCIe zur VM hinzufügen“) führt zu einer besseren Leistung.", "Adding to /etc/fstab for permanent mounting...": "Hinzufügen zu /etc/fstab für dauerhaftes Mounten ...", + "Additional URL advertised by Plex (optional)": "Zusätzliche URL von Plex angekündigt (optional)", "Additional audio function(s) to be added": "Zusätzliche Audiofunktion(en) sollen hinzugefügt werden", + "Additional media/GPU GIDs, comma-separated": "Zusätzliche Medien/GPU-GIDs, kommagetrennt", + "Additional paths for": "Zusätzliche Pfade für", + "Address of the Compose file": "Adresse der Compose-Datei", + "Address to reach Pydio Cells (https://domain or https://IP:8080)": "Adresse bis Pydio Cells (https://domain oder https://IP:8080)", + "Address used to reach wallabag (http://IP or https://wallabag.example.com)": "Adresse, über die wallabag erreicht wurde (http://IP oder https://wallabag.example.com)", + "Addresses to update: ipv4, ipv6 or both (uses an external service)": "Zu aktualisierende Adressen: ipv4, ipv6 oder beides (verwendet einen externen Dienst)", + "Adguardhome Sync web interface": "Adguardhome Sync Web-Schnittstelle", + "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances.": "Adguardhome-sync ist ein Tool zum Synchronisieren der AdGuardHome-Konfiguration mit replizierten Instanzen.", "Adjust network/CIDR to your environment.": "Passen Sie Netzwerk/CIDR an Ihre Umgebung an.", "Adjust options if needed (vers=4,hard,timeo,...).": "Passen Sie die Optionen bei Bedarf an (vers=4,hard,timeo,...).", "Adjusting systemd-journald limits to match Log2RAM size...": "Anpassen der systemd-journald-Grenzwerte an die Log2RAM-Größe ...", "Adjusts journald log level if needed (Proxmox defaults may block auth logs)": "Passt die Journal-Protokollebene bei Bedarf an (Proxmox-Standardeinstellungen blockieren möglicherweise Authentifizierungsprotokolle)", + "Admin page": "Admin-Seite", + "Administrator email": "Administrator-E-Mail", + "Administrator password, at least 12 characters (empty = generated)": "Administrator-Passwort, mindestens 12 Zeichen (leer = generiert)", "Advanced": "Fortschrittlich", "Advanced Diagnostics": "Erweiterte Diagnose", "Advanced Network Diagnostics": "Erweiterte Netzwerkdiagnose", + "Advanced: every setting of the container": "Fortgeschritten: jede Einstellung des Containers", "Affected LXC containers": "Betroffene LXC-Container", "After completing GPU setup, start the VM manually when the host is ready.": "Nachdem Sie die GPU-Einrichtung abgeschlossen haben, starten Sie die VM manuell, wenn der Host bereit ist.", "After confirming, you will be asked to choose the NVIDIA driver version to install.": "Nach der Bestätigung werden Sie aufgefordert, die zu installierende NVIDIA-Treiberversion auszuwählen.", @@ -183,11 +284,15 @@ "After the reboot you can follow the post-restore work live from ProxMenux Monitor → Backups tab (estimated time, per-component status, log tail, rollback delta).": "Nach dem Neustart können Sie die Arbeit nach der Wiederherstellung live über ProxMenux Monitor → Registerkarte „Backups“ verfolgen (geschätzte Zeit, Status pro Komponente, Protokollende, Rollback-Delta).", "After the reboot, you will only be able to access the Proxmox host via:": "Nach dem Neustart können Sie nur noch auf den Proxmox-Host zugreifen über:", "After this LXC → VM switch, reboot the host so the new binding state is applied cleanly.": "Starten Sie nach diesem Wechsel von LXC → VM den Host neu, damit der neue Bindungsstatus sauber angewendet wird.", + "Airsonic Advanced web interface": "Airsonic Advanced Web-Schnittstelle", + "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room.": "Airsonic-advanced ist ein kostenloser, webbasierter Medienstreamer, der ubiquitious Zugang zu Ihrer Musik bietet. Verwenden Sie es, um Ihre Musik mit Freunden zu teilen oder Ihre eigene Musik während der Arbeit zu hören. Sie können zu mehreren Spielern gleichzeitig streamen, zum Beispiel zu einem Spieler in Ihrer Küche und einem anderen in Ihrem Wohnzimmer.", "Aliases added to .bashrc": "Aliase wurden zu .bashrc hinzugefügt", + "Alist Sync web interface": "Alist Sync Web Interface", "All": "Alle", "All Available Scripts": "Alle verfügbaren Skripte", "All GPUs Already Assigned": "Alle GPUs bereits zugewiesen", "All ProxMenux optimizations are up to date.": "Alle ProxMenux-Optimierungen sind auf dem neuesten Stand.", + "All applications": "Alle Anwendungen", "All block devices:": "Alle Blockgeräte:", "All changes applied. No reboot required.": "Alle Änderungen übernommen. Kein Neustart erforderlich.", "All changes are reversible using the ProxMenux uninstaller.": "Alle Änderungen können mit dem ProxMenux-Deinstallationsprogramm rückgängig gemacht werden.", @@ -195,43 +300,79 @@ "All detected GPUs are already assigned to this VM.": "Alle erkannten GPUs sind dieser VM bereits zugewiesen.", "All detected controllers/NVMe are already present in the selected VM.": "Alle erkannten Controller/NVMe sind bereits in der ausgewählten VM vorhanden.", "All disks may already be in use or mounted.": "Möglicherweise sind alle Datenträger bereits verwendet oder gemountet.", + "All images are downloaded and verified first, and native backups are taken with the stack stopped. Contracts are published after the whole set is checked. If anything fails, all members are recovered.": "Alle Bilder werden zuerst heruntergeladen und verifiziert, und native Backups werden mit gestopptem Stapel aufgenommen. Verträge werden veröffentlicht, nachdem das gesamte Set überprüft wurde. Wenn etwas fehlschlägt, werden alle Mitglieder wiederhergestellt.", "All images imported and configured successfully": "Alle Bilder wurden erfolgreich importiert und konfiguriert", "All imports failed": "Alle Importe sind fehlgeschlagen", + "All of them are removed.": "Alle werden entfernt.", "All partitions and metadata removed.": "Alle Partitionen und Metadaten entfernt.", "All physical interfaces from backup are present on target": "Alle physischen Schnittstellen aus dem Backup sind auf dem Ziel vorhanden", + "All stack members are updated together. Main CT:": "Alle Stack-Mitglieder werden gemeinsam aktualisiert. Haupt-CT:", "All types (images, backup, iso, vztmpl, snippets)": "Alle Typen (Images, Backup, ISO, Vztmpl, Snippets)", "All user-installed packages from the backup are present on this host": "Alle vom Benutzer installierten Pakete aus dem Backup sind auf diesem Host vorhanden", "All users with UID and GID": "Alle Benutzer mit UID und GID", "Allocate CPU Cores": "Weisen Sie CPU-Kerne zu", "Allocate RAM in MiB": "Weisen Sie RAM in MiB zu", + "Allowed hosts (comma separated; * allows access through the assigned IP)": "Zulässige Hosts (Komma getrennt; * ermöglicht den Zugriff über die zugewiesene IP)", "Already Mounted": "Bereits montiert", "Already configured": "Bereits konfiguriert", "Already installed — skipping": "Bereits installiert – wird übersprungen", + "Also add the /dev/srX optical device (recommended)": "Fügen Sie auch das /dev/srX optische Gerät hinzu (empfohlen)", "Also comment any remaining 'bookworm' entries in *.list if present.": "Kommentieren Sie auch alle verbleibenden „Bücherwurm“-Einträge in *.list, falls vorhanden.", "Also install the VirtIO network driver during setup to enable network access.": "Installieren Sie während des Setups auch den VirtIO-Netzwerktreiber, um den Netzwerkzugriff zu ermöglichen.", "Although VFIO can bind to this device, full passthrough to a VM is": "Obwohl sich VFIO an dieses Gerät binden kann, ist ein vollständiger Passthrough zu einer VM möglich", + "Altus is an Electron-based WhatsApp client with themes and multiple account support.": "Altus ist ein Electron-basierter WhatsApp-Client mit Themes und Unterstützung für mehrere Konten.", + "Ambiguous mount points in the container": "Mehrdeutige Befestigungspunkte im Behälter", + "Ambiguous or invalid environment variable": "Mehrdeutige oder ungültige Umgebungsvariable", "Amount of RAM in MiB (default: 4096)": "RAM-Größe in MiB (Standard: 4096)", + "An AI model used to generate images conditioned on text descriptions.": "Ein KI-Modell zur Erzeugung von Bildern, das auf Textbeschreibungen basiert.", "An AMD dedicated GPU has been detected without FLR support": "Es wurde eine dedizierte AMD-GPU ohne FLR-Unterstützung erkannt", "An AMD integrated GPU (APU) has been detected": "Eine integrierte AMD-GPU (APU) wurde erkannt", + "An Alist storage synchronization tool based on the Web interface.": "Ein Alist-Speichersynchronisierungstool basierend auf der Web-Schnittstelle.", + "An Industrial-Level Controllable and Efficient Zero-Shot Text-To-Speech System": "Ein industriell steuerbares und effizientes Zero-Shot-Text-to-Speech-System", "An Intel dedicated GPU has been detected without FLR support": "Es wurde eine dedizierte Intel-GPU ohne FLR-Unterstützung erkannt", + "An accelerated video generation framework that speeds up end-to-end diffusion while preserving video quality": "Ein beschleunigtes Videogenerierungs-Framework, das die End-to-End-Diffusion beschleunigt und gleichzeitig die Videoqualität bewahrt", + "An executable required by the adapter is missing in the new image": "Ein ausführbares required durch den Adapter fehlt im neuen Image", "An fstab entry already exists for:": "Es existiert bereits ein fstab-Eintrag für:", + "An image probe container was started externally": "Ein Bildsondenbehälter wurde extern gestartet", + "An include is not part of the journal; recovery blocked": "Ein Include ist nicht Teil des Journals; Recovery blockiert", + "An include was modified outside the journal; recovery blocked": "Ein Einschluss wurde außerhalb des Journals geändert; Recovery blockiert", + "An open source generative AI development platform for building AI Agents and LLM workflows": "Eine Open-Source-Plattform für die Entwicklung von KI-Agenten und LLM-Workflows", + "An operation of this installation has not finished; recover it from the management menu before removing it": "Eine operation dieser Installation ist noch nicht abgeschlossen; stellen Sie sie aus dem Managementmenü wieder her, bevor Sie sie entfernen", + "An update does not accept configuration changes": "Ein Update akzeptiert keine Konfigurationsänderungen", "Analysis Tools": "Analysetools", + "Analysis software that shows your internet speed for up to 30 days.": "Analysesoftware, die ihre internetgeschwindigkeit für bis zu 30 tage anzeigt.", "Analyze Bridge Configuration": "Analysieren Sie die Bridge-Konfiguration", "Analyze Network Configuration": "Analysieren Sie die Netzwerkkonfiguration", "Analyzing Bridge Configuration - READ ONLY MODE": "Analysieren der Bridge-Konfiguration – schreibgeschützter Modus", "Analyzing Network Configuration - READ ONLY MODE": "Analysieren der Netzwerkkonfiguration – schreibgeschützter Modus", "Analyzing selected disks...": "Ausgewählte Festplatten werden analysiert...", "Analyzing system for available PCIe storage devices...": "Analysesystem für verfügbare PCIe-Speichergeräte...", + "Another OCI operation is using the instance registry": "Eine andere OCI operation verwendet die Instanzregistrierung", + "Another OCI operation is using the instance registry. Wait for it to finish and open this menu again; no container is modified.": "Eine andere OCI operation verwendet die Instanzregistrierung. Warten Sie, bis es fertig ist und öffnen Sie dieses Menü erneut; kein Container wird geändert.", + "Another OCI operation is using the registry. This operation was not started.": "Eine weitere OCI operation verwendet die Registry. Diese operation wurde nicht gestartet.", + "Another instance uses": "Eine andere Instanz verwendet", + "Another stack operation is pending": "Ein weiterer Stack operation steht aus", + "Application": "Antragstellung", + "Application responding:": "Antragsantwort:", + "Application responding; checking its stability...": "Anwendung reagiert; Überprüfung seiner Stabilität...", + "Application suite: one independent LXC per selected application": "Anwendungssuite: eine unabhängige LXC pro ausgewählter Anwendung", + "Application:": "Anwendung:", + "Applications you can choose:": "Anwendungen, die Sie auswählen können:", "Apply": "Anwenden", "Apply AMD CPU fixes": "AMD-CPU-Korrekturen anwenden", "Apply Available Updates": "Verfügbare Updates anwenden", "Apply and restart services:": "Dienste anwenden und neu starten:", "Apply available updates": "Verfügbare Updates anwenden", "Apply boot/initramfs changes": "Übernehmen Sie Boot-/Initramfs-Änderungen", + "Apply configuration": "Konfiguration anwenden", "Apply fix now?": "Fix jetzt anwenden?", "Apply fix now? (The share will be briefly remounted)": "Fix jetzt anwenden? (Die Freigabe wird kurzzeitig wieder gemountet)", "Apply network optimizations": "Netzwerkoptimierungen anwenden", + "Apply optional security relaxation apparmor:rootlesskit": "Bewerben Sie optionale Sicherheitsentspannung Apparmor:rootlesskit", + "Apply optional security relaxation apparmor:unconfined": "Bewerben Sie optionale Sicherheitsentspannung Apparmor:unconfined", + "Apply optional security relaxation seccomp:unconfined": "Anwendung optionaler Sicherheitsentspannung seccomp:unconfined", "Apply read+write access for 'others' on the host directory?": "Lese- und Schreibzugriff für „Andere“ auf das Hostverzeichnis anwenden?", + "Apply the options from the current catalog template? Your data and configuration are kept.": "Wenden Sie die Optionen aus der aktuellen Katalogvorlage an? Ihre Daten und Konfiguration werden gespeichert.", "Applying AMD-specific fixes...": "Anwenden von AMD-spezifischen Korrekturen...", "Applying Changes": "Anwenden von Änderungen", "Applying Controller/NVMe passthrough to VM": "Anwenden von Controller/NVMe-Passthrough auf die VM", @@ -244,12 +385,21 @@ "Applying passthrough to CT": "Anwenden von Passthrough auf CT", "Applying safe paths and preparing pending restore": "Anwenden sicherer Pfade und Vorbereiten der ausstehenden Wiederherstellung", "Applying selected LXC switch action": "Anwenden der ausgewählten LXC-Schalteraktion", + "Applying the Jellyfin configuration:": "Anwendung der Jellyfin-Konfiguration:", + "Applying the LAN address to the application URLs...": "Anwenden der LAN-Adresse auf die Anwendung URLs...", + "Applying the initial Nextcloud settings...": "Anwendung der ersten Nextcloud-Einstellungen...", + "Applying the mount mode...": "Anwendung des Mount-Modus...", + "Apprise-api Takes advantage of Apprise through your network with a user-friendly API.": "Apprise-api Nutzt Apprise über Ihr Netzwerk mit einer benutzerfreundlichen API.", + "Architecture": "Architektur", + "Architecture:": "Architektur:", + "Architectures": "Architekturen", "Archive deleted.": "Archiv gelöscht.", "Archive extracted.": "Archiv extrahiert.", "Archive format": "Archivformat", "Archive ready": "Archiv bereit", "Archive size:": "Archivgröße:", "Archive:": "Archiv:", + "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers.": "Ardour ist eine Open-Source-Zusammenarbeit eines weltweiten Teams, das Musiker, Programmierer und professionelle Toningenieure umfasst.", "Are you absolutely sure?": "Bist du absolut sicher?", "Are you sure you want to continue?": "Sind Sie sicher, dass Sie fortfahren möchten?", "Are you sure you want to delete this export?": "Möchten Sie diesen Export wirklich löschen?", @@ -261,6 +411,7 @@ "Are you sure you want to unmount this NFS share?": "Sind Sie sicher, dass Sie die Bereitstellung dieser NFS-Freigabe aufheben möchten?", "Are you sure you want to unmount this Samba share?": "Sind Sie sicher, dass Sie die Bereitstellung dieser Samba-Freigabe aufheben möchten?", "Are you sure?": "Bist du sicher?", + "Arr suite: applications to install": "Arr Suite: Anwendungen zum Installieren", "As Proxmox storage": "Als Proxmox-Speicher", "As host fstab mount only": "Nur als Host-fstab-Mount", "Assign GPU PCI function to VM": "Weisen Sie der VM die GPU-PCI-Funktion zu", @@ -275,14 +426,19 @@ "Attach imported disk to VM": "Hängen Sie die importierte Festplatte an die VM an", "Attach to an existing PVE vzdump job (inherit schedule + retention)": "An einen vorhandenen PVE-vzdump-Job anhängen (Zeitplan + Aufbewahrung erben)", "Attached to PVE job:": "An PVE-Job angehängt:", + "Attaching the volumes...": "Beifügen der Volumina...", "Attempting automatic repair...": "Versuch einer automatischen Reparatur...", "Attempting passthrough with this GPU typically results in": "Ein Passthrough-Versuch mit dieser GPU führt normalerweise zu:", "Attention: Removing the subscription banner may cause issues in the web interface after a future update.": "Achtung: Das Entfernen des Abonnementbanners kann nach einem zukünftigen Update zu Problemen in der Weboberfläche führen.", + "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source.": "Audacity ist ein einfach zu bedienender, mehrspuriger Audio-Editor und Recorder. Entwickelt von einer Gruppe von Freiwilligen als Open Source.", + "Audio device directory": "Audiogeräteverzeichnis", + "Audiobookshelf is a self-hosted audiobook and podcast server.": "Audiobookshelf ist ein selbst gehosteter Hörbuch- und Podcast-Server.", "Audit completed. Press Enter to continue...": "Prüfung abgeschlossen. Drücken Sie die Eingabetaste, um fortzufahren...", "Audit socket disabled or not required": "Audit-Socket deaktiviert oder nicht erforderlich", "Auth key is required.": "Authentifizierungsschlüssel ist erforderlich.", "Auth:": "Authentifizierung:", "Authentication": "Authentifizierung", + "Authentication & Security": "Authentifizierung & Sicherheit", "Authentication Error": "Authentifizierungsfehler", "Authentication failed.": "Die Authentifizierung ist fehlgeschlagen.", "Authentication required:": "Authentifizierung erforderlich:", @@ -301,7 +457,12 @@ "Auto-sync was not enabled": "Die automatische Synchronisierung war nicht aktiviert", "Automated Post-Install Script": "Automatisiertes Post-Install-Skript", "Automated post-installation script": "Automatisiertes Nachinstallationsskript", + "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Automatic Video Library Manager für TV-Shows. Es schaut nach neuen episoden ihrer lieblingsshows, und wenn sie gepostet werden, macht es seine magie.", + "Automatic detection": "Automatische Erkennung", + "Automatic private network allocation requires a /24 subnet": "Automatische private Netzwerkzuweisung requires a /24 Subnetz", + "Automatic video library manager for TV Shows": "Automatischer Videobibliotheksmanager für TV-Shows", "Automatic/Unattended": "Automatisch/unbeaufsichtigt", + "Automation & Scheduling": "Automatisierung & Terminplanung", "Available": "Verfügbar", "Available Borg archives (newest first):": "Verfügbare Borg-Archive (neueste zuerst):", "Available Borg targets:": "Verfügbare Borg-Ziele:", @@ -322,17 +483,23 @@ "Available space in /mnt:": "Verfügbarer Speicherplatz in /mnt:", "Available storage information:": "Verfügbare Speicherinformationen:", "Available storage volumes:": "Verfügbare Speichervolumina:", + "Azahar is an open-source 3DS emulator based on Citra.": "Azahar ist ein Open-Source 3DS-Emulator auf Basis von Citra.", "BIOS TYPE": "BIOS-TYP", "BIOS Type": "BIOS-Typ", "BIOS from": "BIOS von", "BIOS: OVMF (UEFI)": "BIOS: OVMF (UEFI)", + "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications.": "BOINC ist eine Plattform für Hochdurchsatz-Computing in großem Maßstab (Tausende oder Millionen von Computern). Es kann für Freiwilligen-Computing (unter Verwendung von Consumer-Geräten) oder Grid-Computing (unter Verwendung von organisatorischen Ressourcen) verwendet werden. Es unterstützt virtualisierte, parallele und GPU-basierte Anwendungen.", "BRIDGE CONFIGURATION ANALYSIS": "BRÜCKENKONFIGURATIONSANALYSE", "BTRFS:": "BTRFS:", + "Baby Buddy web interface": "Baby Buddy Web-Schnittstelle", + "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work.": "Babybuddy ist ein Kumpel für Babys! Hilft Betreuern, Schlaf, Fütterungen, Windelwechsel, Bauchzeit und mehr zu verfolgen, um die Bedürfnisse des Babys zu erfahren und vorherzusagen, ohne (so viel) Arbeit zu erraten.", "Back to previous menu or Esc + Enter": "Zurück zum vorherigen Menü oder Esc + Enter", "Backed up and cleared": "Gesichert und gelöscht", "Backend": "Backend", "Backend:": "Backend:", + "Background archive extraction for Arr download queues. No web interface.": "Hintergrund-Archivextraktion für Arr-Download-Warteschlangen. Kein Webinterface.", "Backup — VM and CT backups": "Backup – VM- und CT-Backups", + "Backup & Recovery": "Backup & Recovery", "Backup Created": "Backup erstellt", "Backup ID (group name in PBS):": "Backup-ID (Gruppenname in PBS):", "Backup ID for this job:": "Backup-ID für diesen Job:", @@ -345,6 +512,7 @@ "Backup available at": "Backup verfügbar unter", "Backup completed successfully.": "Sicherung erfolgreich abgeschlossen.", "Backup completed:": "Sicherung abgeschlossen:", + "Backup created": "Backup erstellt", "Backup created:": "Backup erstellt:", "Backup declares unused NICs that are not on this host:": "Backup deklariert nicht verwendete Netzwerkkarten, die sich nicht auf diesem Host befinden:", "Backup destination is inside the backup": "Das Backup-Ziel liegt innerhalb des Backups", @@ -355,6 +523,7 @@ "Backup information": "Backup-Informationen", "Backup location": "Backup-Speicherort", "Backup metadata": "Metadaten sichern", + "Backup of the previous installation verified": "Backup der vorherigen Installation verifiziert", "Backup on newer kernel:": "Backup auf neuerem Kernel:", "Backup on older kernel:": "Backup auf älterem Kernel:", "Backup origin metadata:": "Metadaten des Backup-Ursprungs:", @@ -369,26 +538,42 @@ "Backup:": "Sicherung:", "Backups already on PBS were encrypted with the current key — downloading them will fail unless you first Download the current keyfile to keep a copy.": "Backups, die sich bereits auf PBS befinden, wurden mit dem aktuellen Schlüssel verschlüsselt – der Download schlägt fehl, es sei denn, Sie laden zuerst die aktuelle Schlüsseldatei herunter, um eine Kopie zu behalten.", "Backups already stored on PBS were encrypted with the current keyfile. After this action:": "Bereits auf PBS gespeicherte Backups wurden mit der aktuellen Schlüsseldatei verschlüsselt. Nach dieser Aktion:", + "Backups verified": "Backups verifiziert", + "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience.": "Bambu Studio ist eine Open-Source-, hochmoderne, funktionsreiche Slicing-Software. Es enthält projektbasierte Workflows, systematisch optimierte Schnittalgorithmen und eine benutzerfreundliche grafische Oberfläche, die den Benutzern ein unglaublich reibungsloses Druckerlebnis bietet.", "Bandwidth limit configured": "Bandbreitenbegrenzung konfiguriert", "Bandwidth test (iperf3)": "Bandbreitentest (iperf3)", "Bandwidth test completed successfully": "Bandbreitentest erfolgreich abgeschlossen", "Base VM created with ID": "Basis-VM mit ID erstellt", + "Base VMID": "Basis-VMID", + "Base VMID (empty = next free block)": "Basis VMID (leer = nächster freier Block)", + "Base VMID of Nextcloud (empty = next free block)": "Basis-VMID von Nextcloud (leer = nächster freier Block)", + "Base VMID of Paperless (empty = next free block)": "Basis-VMID von Paperless (leer = nächster freier Block)", + "Base VMID of Tandoor (empty = next free block)": "Basis-VMID von Tandoor (leer = nächster freier Block)", + "Base VMID of the server (empty = next free block)": "Basis-VMID des Servers (leer = nächster freier Block)", "Bash prompt path": "Pfadanzeige der Bash-Eingabeaufforderung", "Bashrc customization completed": "Bashrc-Anpassung abgeschlossen", "Basic Settings": "Grundeinstellungen", "Basic Utilities": "Grundlegende Dienstprogramme", + "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you.": "Bazarr ist eine Begleitanwendung für Sonarr und Radarr. Es kann Untertitel basierend auf Ihren requirements verwalten und herunterladen. Sie definieren Ihre Präferenzen nach TV-Show oder Film und Bazarr kümmert sich um alles für Sie.", + "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools.": "Beets ist ein Musikbibliotheksmanager und nicht zum größten Teil ein Musikplayer. Es enthält ein einfaches Player-Plugin und einen experimentellen Web-basierten Player, überlässt jedoch in der Regel die tatsächliche Tonwiedergabe spezialisierten Tools.", "Before making any changes, we'll create a safety backup.": "Bevor wir Änderungen vornehmen, erstellen wir ein Sicherheitsbackup.", "Beta (develop branch)": "Beta (Entwicklungszweig)", "Beta version:": "Betaversion:", "Binary not found in extracted content.": "Binärdatei im extrahierten Inhalt nicht gefunden.", "Bind mount added:": "Bind-Reittier hinzugefügt:", + "Bind mounts are not included in vzdump": "Bind Mounts sind nicht in vzdump enthalten", + "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services.": "Bitcoin Knots kann als Desktop-Client für regelmäßige Zahlungen oder als Full Node Server-Dienstprogramm für Händler und andere Zahlungsdienste verwendet werden.", "Blacklist nouveau driver": "Nouveau-Treiber auf die schwarze Liste setzen", "Blacklisting GPU host drivers...": "GPU-Hosttreiber werden auf die schwarze Liste gesetzt...", "Blacklisting nouveau driver...": "Nouveau-Treiber wird auf die schwarze Liste gesetzt...", + "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**": "Blender ist ein kostenloses und Open-Source-3D-Computergrafik-Software-Toolset, das zum Erstellen von Animationsfilmen, visuellen Effekten, Kunst, 3D-gedruckten Modellen, Bewegungsgrafiken, interaktiven 3D-Anwendungen, virtueller Realität und Computerspielen verwendet wird. **Dieses Bild unterstützt kein GPU-Rendering out of the box nur beschleunigtes Workspace-Erlebnis **", + "Blinko is an AI-powered card note-taking project. Designed for individuals who want to quickly capture and organize their fleeting thoughts. Blinko allows users to seamlessly jot down ideas the moment they strike, ensuring that no spark of creativity is lost.": "Blinko ist ein KI-gestütztes Kartennotizprojekt. Entwickelt für Personen, die quickly ihre flüchtigen Gedanken erfassen und organisieren möchten. Blinko ermöglicht es Benutzern, Ideen in dem Moment, in dem sie auftreffen, nahtlos aufzuschreiben, um sicherzustellen, dass kein Funke Kreativität verloren geht.", "Blocked GPU ID": "Blockierte GPU-ID", "Blocked GPU ID for VM Mode": "Blockierte GPU-ID für den VM-Modus", "Blocked device(s)": "Blockierte(s) Gerät(e)", "Blocked device(s):": "Blockierte(s) Gerät(e):", + "BookStack web interface": "BookStack Web-Schnittstelle", + "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease.": "Bookstack ist ein kostenloses und Open-Source-Wiki für die Erstellung schöner Dokumentation. Mit einem einfachen, aber leistungsstarken WYSIWYG-Editor können Teams mit Leichtigkeit detaillierte und nützliche Dokumentationen erstellen.", "Boot Disk": "Bootdiskette", "Boot artifacts regenerated — reboot the host to activate the merged config.": "Boot-Artefakte neu generiert – Starten Sie den Host neu, um die zusammengeführte Konfiguration zu aktivieren.", "Boot disk:": "Bootdiskette:", @@ -415,9 +600,13 @@ "Bridge:": "Brücke:", "Bridges analyzed": "Brücken analysiert", "Broken gasket-dkms package state recovered.": "Der Status des defekten „gasket-dkms“-Pakets wurde wiederhergestellt.", + "Browse Your Life in Images": "Durchsuchen Sie Ihr Leben in Bildern", "Browse manually (advanced)...": "Manuell durchsuchen (erweitert)...", + "Browsers & Web Desktops": "Browser & Web Desktops", "Build and install the gasket and apex kernel modules (DKMS)": "gasket- und apex-Kernelmodule erstellen und installieren (DKMS)", "Build dependencies installed.": "Build-Abhängigkeiten installiert.", + "Build your personal knowledge base with TriliumNext Notes": "Erstellen Sie Ihre persönliche Wissensbasis mit TriliumNext Notes", + "Business & ERP": "Business & ERP", "CHANGES APPLIED SUCCESSFULLY": "ÄNDERUNGEN WURDEN ERFOLGREICH ANGEWENDET", "CIFS Client Tools: AVAILABLE": "CIFS-Client-Tools: VERFÜGBAR", "CIFS Client Tools: NOT AVAILABLE - installing...": "CIFS-Client-Tools: NICHT VERFÜGBAR – Installation...", @@ -435,24 +624,35 @@ "CLUSTER UPGRADE NOTES:": "HINWEISE ZUM CLUSTER-UPGRADE:", "CONFIGURED INTERFACES": "Konfigurierte Schnittstellen", "CONFIRM FORMAT": "BESTÄTIGEN SIE DAS FORMAT", + "CPU": "CPU", "CPU Cores": "CPU-Kerne", "CPU MODEL": "CPU-MODELL", "CPU Model": "CPU-Modell", + "CPU cores": "CPU-Kerne", + "CPU priority": "CPU-Priorität", "CPU set to host,hidden=1,flags=+pcid": "CPU auf Host,hidden=1,flags=+pcid eingestellt", "CPU vendor (intel/amd):": "CPU-Anbieter (Intel/AMD):", "CRITICAL: The selected disk is referenced by a RUNNING VM or CT.": "KRITISCH: Die ausgewählte Festplatte wird von einer LAUFENDEN VM oder CT referenziert.", "CT": "CT", "CT started successfully.": "CT erfolgreich gestartet.", + "CUDA requires a working NVIDIA driver": "CUDA requires ein funktionierender NVIDIA Fahrer", + "CUDA requires the NVIDIA Container Toolkit on the host": "CUDA requires das NVIDIA Container Toolkit auf dem Host", + "Calculate all kinds of statistics from your (local) Emby or Jellyfin server": "Berechnen Sie alle Arten von Statistiken von Ihrem (lokalen) Emby- oder Jellyfin-Server", + "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts.": "Calibre ist ein leistungsstarker und einfach zu bedienender E-Book-Manager. Benutzer sagen, es ist hervorragend und ein must-have. Es ermöglicht Ihnen, fast alles zu tun, und es dauert einen Schritt über die normale E-Book-Software hinaus. Es ist auch völlig kostenlos und Open Source und ideal für Gelegenheitsbenutzer und Computerexperten.", + "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself.": "Calibre-web ist eine Web-App, die eine saubere Schnittstelle zum Durchsuchen, Lesen und Herunterladen von eBooks mit einer vorhandenen Calibre-Datenbank bietet. Es ist auch möglich, Google Drive zu integrieren und Metadaten und Ihre calibre-Bibliothek über die App selbst zu bearbeiten.", + "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases.": "Calligra ist eine Büro- und Grafiksuite von KDE. Es ist für Desktop-PCs, Tablet-Computer und Smartphones verfügbar. Es enthält Anwendungen für Textverarbeitung, Tabellenkalkulationen, Präsentation, Vektorgrafiken und Bearbeitungsdatenbanken.", "Cancel": "Stornieren", "Cancel restore": "Wiederherstellung abbrechen", "Cancel this setup": "Brechen Sie diese Einrichtung ab", "Cancelled by user or empty URL.": "Abgebrochen durch Benutzer oder leere URL.", "Cancelled by user.": "Vom Benutzer abgebrochen.", + "Cannot apply the Compose command:": "Kann den Befehl Compose nicht anwenden:", "Cannot connect to server": "Es kann keine Verbindung zum Server hergestellt werden", "Cannot continue": "Kann nicht fortgesetzt werden", "Cannot create:": "Kann nicht erstellt werden:", "Cannot detect filesystem on": "Dateisystem kann nicht erkannt werden", "Cannot find": "Kann nicht gefunden werden", + "Cannot identify the vendor of the device:": "Kann den Anbieter des Geräts nicht identifizieren:", "Cannot load backup library: lib_host_backup_common.sh": "Sicherungsbibliothek kann nicht geladen werden: lib_host_backup_common.sh", "Cannot proceed with invalid export path.": "Mit ungültigem Exportpfad kann nicht fortgefahren werden.", "Cannot proceed with invalid share name.": "Mit ungültigem Freigabenamen kann nicht fortgefahren werden.", @@ -460,7 +660,11 @@ "Cannot reach download.proxmox.com. Check network, proxy or DNS.": "Download.proxmox.com kann nicht erreicht werden. Überprüfen Sie Netzwerk, Proxy oder DNS.", "Cannot reach portal:": "Portal kann nicht erreicht werden:", "Cannot reach server": "Server ist nicht erreichbar", + "Cannot read": "kann nicht lesen", + "Cannot read the OCI archive:": "Kann das OCI-Archiv nicht lesen:", "Cannot validate credentials - no shares available for testing.": "Anmeldeinformationen können nicht validiert werden – keine Freigaben zum Testen verfügbar.", + "Cannot verify the reused disk:": "Kann die wiederverwendete Festplatte nicht überprüfen:", + "Capabilities cannot be kept and all dropped at the same time": "Fähigkeiten können nicht gehalten werden und alle gleichzeitig fallen gelassen werden", "Category": "Kategorie", "Caution: Maximum mode generates more heat.": "Achtung: Im Maximalmodus entsteht mehr Wärme.", "Ceph check skipped by user flag (--ignore-ceph-check)": "Ceph-Prüfung durch Benutzerflag übersprungen (--ignore-ceph-check)", @@ -487,14 +691,23 @@ "Ceph repository configured for PVE 9": "Ceph-Repository für PVE 9 konfiguriert", "Ceph repository signature verification failed; installation has been stopped": "Überprüfung der Ceph-Repository-Signatur fehlgeschlagen;Die Installation wurde gestoppt", "Ceph version OK:": "Ceph-Version OK:", + "Certificate errors are logged in /config/log/letsencrypt inside the container.": "Zertifikatsfehler werden in /config/log/letsencrypt im Container eingeloggt.", "Certificate fingerprint of the PBS server:": "Zertifikatsfingerabdruck des PBS-Servers:", + "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL": "Zertifikatsanbieter: leer für Let's Encrypt, zerossl für ZeroSSL", + "Change GPU acceleration?": "GPU-Beschleunigung ändern?", "Change Language": "Sprache ändern", "Change Release Channel": "Veröffentlichungskanal ändern", + "Change it after the first login.": "Ändern Sie es nach dem ersten Login.", + "Change or add an environment variable?": "Ändern oder Hinzufügen einer Umgebungsvariable?", + "Change the access network?": "Ändern Sie das Zugangsnetzwerk?", + "Changedetection.io provides free, open-source web page monitoring, notification and change detection.": "Changedetection.io bietet kostenlose Open-Source-Webseitenüberwachung, Benachrichtigung und Änderungserkennung.", "Changes applied. A system reboot is recommended for them to take full effect.": "Änderungen übernommen. Damit sie ihre volle Wirkung entfalten, wird ein Neustart des Systems empfohlen.", "Changes have been applied to the configuration file.": "Es wurden Änderungen an der Konfigurationsdatei vorgenommen.", "Changes will apply after reboot.": "Änderungen werden nach dem Neustart wirksam.", "Changing Release Channel": "Veröffentlichungskanal ändern", "Changing the machine type on an existing installed VM is not safe: it changes the chipset and PCI slot layout, which typically prevents the guest OS from booting.": "Das Ändern des Maschinentyps auf einer vorhandenen installierten VM ist nicht sicher: Es ändert den Chipsatz und das PCI-Steckplatz-Layout, was normalerweise dazu führt, dass das Gastbetriebssystem nicht startet.", + "Changing the rootfs or its storage requires a separate migration": "Ändern der Rootfs oder seiner Speicherung requires eine separate Migration", + "Changing the storage or size of a disk requires a migration; empty disks are not created": "Ändern des Speichers oder der Größe einer Festplatte requires eine Migration; leere Festplatten werden nicht erstellt", "Check": "Überprüfen", "Check BIOS/UEFI in Hardware > BIOS — must match what the original VM used": "Überprüfen Sie BIOS/UEFI unter Hardware > BIOS – es muss mit dem übereinstimmen, was die ursprüngliche VM verwendet hat", "Check Coral USB/M.2 detection": "Überprüfen Sie die Coral USB/M.2-Erkennung", @@ -520,6 +733,7 @@ "Check the service status manually if needed.": "Überprüfen Sie den Servicestatus bei Bedarf manuell.", "Checking MOTD configuration...": "MOTD-Konfiguration wird überprüft...", "Checking NVIDIA driver status with nvidia-smi": "Überprüfen des NVIDIA-Treiberstatus mit nvidia-smi", + "Checking OCI": "Überprüfung der OCI", "Checking VFIO modules...": "VFIO-Module werden überprüft...", "Checking VM virtual display model...": "Virtuelles Anzeigemodell der VM wird überprüft...", "Checking ZFS autotrim configuration...": "ZFS-Autotrim-Konfiguration wird überprüft...", @@ -531,7 +745,22 @@ "Checking if the server belongs to OVH...": "Es wird geprüft, ob der Server zu OVH gehört...", "Checking kernel headers and build tools...": "Kernel-Header und Build-Tools werden überprüft...", "Checking remaining interfaces": "Überprüfung der verbleibenden Schnittstellen", + "Checking that the container keeps running...": "Überprüfen, ob der Container weiter läuft...", "Checking that this version builds against the running kernel...": "Überprüfen, ob diese Version mit dem laufenden Kernel kompatibel ist ...", + "Checking the GPU of the machine learning container...": "Überprüfen der GPU des Machine Learning Containers...", + "Checking the container before recreating it...": "Überprüfen Sie den Container, bevor Sie ihn neu erstellen ...", + "Checking the container before the update...": "Überprüfen Sie den Container vor dem Update ...", + "Checking the device permissions for the application user...": "Überprüfung der Geräteberechtigungen für den Anwendungsbenutzer...", + "Checking the image compatibility:": "Prüfung der Bildkompatibilität:", + "Checking the image in the registry...": "Überprüfen Sie das Bild in der Registry ...", + "Checking the interrupted operation...": "Überprüfen Sie die unterbrochene operation ...", + "Checking the interrupted stack operation...": "Überprüfen Sie den unterbrochenen Stapel operation ...", + "Checking the new image without starting it:": "Überprüfen Sie das neue Bild, ohne es zu starten:", + "Checking the remote...": "Die Fernbedienung überprüfen...", + "Checking the restored installation": "Überprüfung der wiederhergestellten Installation", + "Checking the restored installation...": "Überprüfung der wiederhergestellten Installation...", + "Checking the stack before the update...": "Überprüfen Sie den Stack vor dem Update ...", + "Checking the updated stack...": "Überprüfen Sie den aktualisierten Stack...", "Checklist post-upgrade finished. Warnings:": "Checkliste nach dem Upgrade abgeschlossen. Warnungen:", "Checklist pre-check finished. Warnings:": "Checklisten-Vorprüfung abgeschlossen. Warnungen:", "Checks for LVM and storage issues": "Prüft auf LVM- und Speicherprobleme", @@ -588,6 +817,9 @@ "Choose the type of virtual system to install:": "Wählen Sie den Typ des zu installierenden virtuellen Systems:", "Choose what to do with the selected disk:": "Wählen Sie, was mit der ausgewählten Festplatte geschehen soll:", "Choose where to save the backup:": "Wählen Sie, wo das Backup gespeichert werden soll:", + "Chrome is the official web browser from Google, built to be fast, secure, and customizable.": "Chrome ist der offizielle Webbrowser von Google, der schnell, sicher und anpassbar ist.", + "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.": "Chromium ist ein Open-Source-Browser-Projekt, das darauf abzielt, eine sicherere, schnellere und stabilere Möglichkeit für alle Benutzer zu schaffen, das Web zu erleben.", + "Circular dependency:": "Zirkularabhängigkeit:", "Clean disk metadata": "Bereinigen Sie die Festplattenmetadaten", "Cleaned up": "Aufgeräumt", "Cleaning cached files...": "Zwischengespeicherte Dateien bereinigen...", @@ -611,21 +843,29 @@ "Clearing login credentials...": "Anmeldedaten werden gelöscht...", "Client (run a bandwidth test to a server)": "Client (führen Sie einen Bandbreitentest für einen Server durch)", "Client determines best version to use": "Der Kunde bestimmt die beste zu verwendende Version", + "Clients reach the VPN through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Clients erreichen das VPN über die öffentliche Adresse und den während der Installation angegebenen UDP-Port, so dass der Port an diesen Container weitergeleitet werden muss.", "Cloning Coral driver repository (feranick fork)...": "Klonen des Coral-Treiber-Repositorys (Feranick-Fork) ...", "Cloning Lynis from GitHub...": "Lynis von GitHub klonen...", "Cloning and applying NVIDIA patch (keylase/nvidia-patch)...": "Klonen und Anwenden des NVIDIA-Patches (keylase/nvidia-patch) ...", "Closed": "Geschlossen", + "Cloud storage synchronization and FUSE mounts": "Cloud Storage Synchronisation und FUSE-Mounts", "Cloud-Init Automated Installers": "Automatisierte Cloud-Init-Installationsprogramme", "Cluster certificates updated": "Clusterzertifikate aktualisiert", "Cluster configuration (advanced)": "Clusterkonfiguration (erweitert)", "Cluster data will be applied automatically at next boot.": "Clusterdaten werden beim nächsten Start automatisch angewendet.", "Cluster upgrade mode": "Cluster-Upgrade-Modus", + "Code-server is VS Code running on a remote server, accessible through the browser.": "Code-Server ist VS Code, der auf einem entfernten Server läuft und über den Browser zugänglich ist.", + "CodeProject.AI Server": "CodeProject. AI Server", "Command": "Befehl", + "Command override for an unknown service:": "Command Override für einen unbekannten Dienst:", "Commenting any residual Bookworm lines in *.list...": "Kommentieren aller verbleibenden Bookworm-Zeilen in *.list...", "Commenting legacy PVE 8 repository .list files (if any)...": "Kommentieren älterer PVE 8-Repository-.list-Dateien (falls vorhanden) ...", "Commenting legacy ceph.list (if present)...": "Kommentieren der alten ceph.list (falls vorhanden) ...", "Common Issues Check": "Überprüfen Sie häufige Probleme", + "Common root for the published views": "Gemeinsame Wurzel für die veröffentlichten Ansichten", + "Communication & Community": "Kommunikation & Community", "Community Scripts": "Community-Skripte", + "Community single-container Home Assistant OS image": "Einbehälter-Bild in der Gemeinschaft Home Assistant OS", "Compatibility check": "Kompatibilitätsprüfung", "Compatibility check — OK": "Kompatibilitätsprüfung – OK", "Compatibility check — issues detected": "Kompatibilitätsprüfung – Probleme erkannt", @@ -640,24 +880,31 @@ "Complete restore": "Vollständige Wiederherstellung", "Complete the DSM installation wizard": "Schließen Sie den DSM-Installationsassistenten ab", "Complete the ZimaOS installation wizard": "Schließen Sie den ZimaOS-Installationsassistenten ab", + "Complete the media server and Seerr accounts, the Bazarr providers and the SABnzbd Usenet credentials when they are selected.": "Füllen Sie den Medienserver und die Seerr-Konten, die Bazarr-Anbieter und die SABnzbd Usenet credentials aus, wenn sie ausgewählt sind.", + "Completed": "Abgeschlossen", "Completed Successfully with GPU passthrough configured!": "Erfolgreich abgeschlossen mit konfiguriertem GPU-Passthrough!", "Completed Successfully!": "Erfolgreich abgeschlossen!", "Completed with errors —": "Mit Fehlern abgeschlossen –", "Completed.": "Vollendet.", "Completed. Devices added to VM {vmid}: {count}.": "Abgeschlossen. Zur VM {vmid} hinzugefügte Geräte: {count}.", "Completed. Press Enter to return to menu...": "Vollendet. Drücken Sie die Eingabetaste, um zum Menü zurückzukehren...", + "Completing its final cleanup...": "Abschluss der endgültigen Bereinigung...", "Completing pending package configurations...": "Ausstehende Paketkonfigurationen werden abgeschlossen...", "Compliance checking (PCI-DSS, HIPAA, etc.)": "Konformitätsprüfung (PCI-DSS, HIPAA usw.)", "Component to uninstall manually (no --auto-uninstall yet):": "Komponente zum manuellen Deinstallieren (noch kein --auto-uninstall):", "Component was installed on the backup source but no matching hardware was found on this host.": "Die Komponente wurde auf der Backup-Quelle installiert, aber auf diesem Host wurde keine passende Hardware gefunden.", "Component:": "Komponente:", "Components to uninstall (manual for now):": "Zu deinstallierende Komponenten (vorerst manuell):", + "Compose capabilities validated in the LXC user namespace:": "Compose-Funktionen, die im LXC-Benutzernamensraum validiert wurden:", + "Compose file of the application": "Datei des Antrags erstellen", + "Compose file of this host": "Datei dieses Hosts erstellen", "Compressed size:": "Komprimierte Größe:", "Compressing": "Komprimieren", "Compression Tools": "Komprimierungswerkzeuge", "Concise output of logical volumes": "Übersichtliche Ausgabe logischer Volumes", "Concise output of physical volumes": "Übersichtliche Ausgabe physischer Datenträger", "Concise output of volume groups": "Übersichtliche Ausgabe von Volumengruppen", + "Concurrent change while restoring the start at boot setting": "Gleichzeitige Änderung beim Wiederherstellen des Starts bei der Booteinstellung", "Configuration Analysis": "Konfigurationsanalyse", "Configuration Menu": "Konfigurationsmenü", "Configuration Summary:": "Konfigurationszusammenfassung:", @@ -666,11 +913,13 @@ "Configuration can continue now and will be effective after reboot.": "Die Konfiguration kann jetzt fortgesetzt werden und wird nach dem Neustart wirksam.", "Configuration completed successfully!": "Konfiguration erfolgreich abgeschlossen!", "Configuration file for container": "Konfigurationsdatei für Container", + "Configuration files generated:": "Generierte Konfigurationsdateien:", "Configuration has been stopped due to high reset risk.": "Die Konfiguration wurde aufgrund eines hohen Reset-Risikos gestoppt.", "Configuration has been stopped to prevent an unusable VM state.": "Die Konfiguration wurde gestoppt, um einen unbrauchbaren VM-Status zu verhindern.", "Configuration has been stopped to prevent leaving the VM in an unusable state.": "Die Konfiguration wurde gestoppt, um zu verhindern, dass die VM in einem unbrauchbaren Zustand verbleibt.", "Configuration name:": "Konfigurationsname:", "Configuration sections that will be REMOVED": "Konfigurationsabschnitte, die ENTFERNT werden", + "Configuration size in GB": "Konfigurationsgröße in GB", "Configuration to be Removed": "Zu entfernende Konfiguration", "Configuration will continue now and be effective after reboot.": "Die Konfiguration wird jetzt fortgesetzt und ist nach dem Neustart wirksam.", "Configuration:": "Konfiguration:", @@ -713,6 +962,7 @@ "Configuring Proxmox jail...": "Proxmox-Jail wird konfiguriert...", "Configuring TCP optimizations...": "TCP-Optimierungen konfigurieren...", "Configuring TPM device": "TPM-Gerät konfigurieren", + "Configuring Unpackerr...": "Konfiguration von Unpackerr...", "Configuring VFIO modules...": "VFIO-Module konfigurieren...", "Configuring VM": "VM konfigurieren", "Configuring bandwidth limit for vzdump...": "Bandbreitenbegrenzung für vzdump konfigurieren...", @@ -728,8 +978,11 @@ "Configuring max FD limit / ulimit...": "Konfigurieren des maximalen FD-Limits/Ulimit...", "Configuring max user watches...": "Maximale Benutzerüberwachungen werden konfiguriert...", "Configuring pigz as a faster replacement for gzip...": "Pigz als schnelleren Ersatz für gzip konfigurieren ...", + "Configuring qBittorrent...": "Konfiguration von qBittorrent...", "Configuring snapshot schedules...": "Snapshot-Zeitpläne konfigurieren...", "Configuring system time settings...": "Konfigurieren der Systemzeiteinstellungen...", + "Configuring the Radarr root folder...": "Konfiguration des Radarr-Root-Ordners...", + "Configuring the Sonarr root folder...": "Konfiguration des Sonarr-Root-Ordners...", "Configuring vfio-pci binding...": "vfio-pci-Bindung wird konfiguriert...", "Confirm Borg passphrase": "Borg-Passphrase bestätigen", "Confirm Borg passphrase:": "Bestätigen Sie die Borg-Passphrase:", @@ -751,6 +1004,7 @@ "Confirm export": "Bestätigen Sie den Export", "Confirm password for": "Passwort bestätigen für", "Confirm recovery passphrase:": "Bestätigen Sie die Wiederherstellungspassphrase:", + "Confirm that host data is not reverted": "Bestätigen Sie, dass Hostdaten nicht zurückgesetzt werden", "Confirm the keyfile passphrase:": "Bestätigen Sie die Passphrase der Schlüsseldatei:", "Confirm the mount path is visible.": "Bestätigen Sie, dass der Mount-Pfad sichtbar ist.", "Confirm the password:": "Bestätigen Sie das Passwort:", @@ -762,7 +1016,11 @@ "Conflicting path included in backup:": "In der Sicherung enthaltener widersprüchlicher Pfad:", "Conflicting utilities removed": "Widersprüchliche Dienstprogramme entfernt", "Connect a Coral Accelerator and try again.": "Schließen Sie einen Coral Accelerator an und versuchen Sie es erneut.", + "Connect your devices and users together in your own secure virtual private network.": "Verbinden Sie Ihre Geräte und Benutzer in Ihrem eigenen sicheren virtuellen privaten Netzwerk.", + "Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.": "Verbinden Sie Ihre Geräte mit einem sicheren WireGuard®-basierten Overlay-Netzwerk mit SSO, MFA und granularen Zugriffskontrollen.", "Connected": "Verbunden", + "Connecting Radarr to qBittorrent...": "Radarr mit qBittorrent verbinden...", + "Connecting Sonarr to qBittorrent...": "Sonarr mit qBittorrent verbinden...", "Connecting to PBS and starting backup...": "Mit PBS verbinden und Backup starten...", "Connection Details:": "Verbindungsdetails:", "Connection Error": "Verbindungsfehler", @@ -774,6 +1032,7 @@ "Consider removing its configuration": "Erwägen Sie, die Konfiguration zu entfernen", "Consider security implications for production environments": "Berücksichtigen Sie Sicherheitsauswirkungen für Produktionsumgebungen", "Consider visiting the repository and supporting the project.": "Erwägen Sie einen Besuch im Repository und die Unterstützung des Projekts.", + "Console log:": "Konsolenprotokoll:", "Container": "Container", "Container — LXC root directories": "Container – LXC-Stammverzeichnisse", "Container ID": "Container-ID", @@ -783,30 +1042,50 @@ "Container Path": "Containerpfad", "Container Path:": "Containerpfad:", "Container Status": "Containerstatus", + "Container checked": "Container geprüft", "Container configuration not found": "Containerkonfiguration nicht gefunden", + "Container configured (not started):": "Container konfiguriert (nicht gestartet):", + "Container converted to privileged": "Container umgewandelt in Privileged", + "Container created:": "Container erstellt:", "Container did not become ready in time. Skipping driver installation.": "Container wurde nicht rechtzeitig fertig. Treiberinstallation wird übersprungen.", "Container did not start in time.": "Container wurde nicht rechtzeitig gestartet.", "Container distro": "Containerverteilung", "Container does not have apt-get available. Coral driver installation only supports Debian/Ubuntu containers.": "Für den Container ist apt-get nicht verfügbar. Die Coral-Treiberinstallation unterstützt nur Debian/Ubuntu-Container.", + "Container installed, but without a verifiable record for future updates.": "Container installiert, aber ohne überprüfbare Aufzeichnung für zukünftige Updates.", "Container is already stopped.": "Container ist bereits gestoppt.", "Container is running. Restart to apply changes?": "Container läuft. Neu starten, um die Änderungen zu übernehmen?", "Container is stopped. Start it now to verify the mount works?": "Container wird gestoppt. Jetzt starten, um zu überprüfen, ob die Halterung funktioniert?", + "Container kept with its data; the installation was not validated:": "Container mit seinen Daten aufbewahrt; die Anlage wurde nicht validiert:", "Container mount point:": "Container-Montagepunkt:", "Container must be stopped before conversion": "Der Container muss vor der Konvertierung gestoppt werden", + "Container prepared for the stack:": "Für den Stapel vorbereiteter Behälter:", + "Container recreated": "Container wieder hergestellt", + "Container removed:": "Container entfernt:", "Container restarted successfully": "Container wurde erfolgreich neu gestartet", + "Container running steadily": "Container läuft stetig", + "Container started": "Container gestartet", "Container started successfully": "Container wurde erfolgreich gestartet", "Container started successfully.": "Container wurde erfolgreich gestartet.", "Container started.": "Container gestartet.", + "Container stopped": "Container gestoppt", "Container stopped.": "Container gestoppt.", "Container successfully converted to privileged.": "Container wurde erfolgreich in privilegiert konvertiert.", "Container template— LXC templates": "Containervorlage – LXC-Vorlagen", + "Container volume": "Behältervolumen", + "Container volume (included in backups)": "Containervolumen (in Backups enthalten)", "Container will pick up the mount on next start": "Der Container holt das Reittier beim nächsten Start ab", "Container with ID": "Container mit ID", "Container:": "Container:", + "Containers & Docker": "Container & Docker", + "Containers returned to their previous state": "Container in ihren vorherigen Zustand zurückgekehrt", + "Containers that are removed:": "Entfernte Behälter:", + "Containers that will be created (one LXC per service, on a private network):": "Container, die erstellt werden (ein LXC pro Dienst, in einem privaten Netzwerk):", + "Containers:": "Container:", "Contains files": "Enthält Dateien", "Contains:": "Enthält:", "Content Types": "Inhaltstypen", "Content Types:": "Inhaltstypen:", + "Content collaboration platform": "Content Collaboration Plattform", "Content is usually images for VM block devices.": "Bei den Inhalten handelt es sich in der Regel um Bilder für VM-Blockgeräte.", "Content type is fixed to:": "Der Inhaltstyp ist festgelegt auf:", "Content:": "Inhalt:", @@ -817,10 +1096,12 @@ "Continue the Windows installation as usual.": "Setzen Sie die Windows-Installation wie gewohnt fort.", "Continue with Coral TPU configuration only?": "Nur mit Coral TPU-Konfiguration fortfahren?", "Continue with live apply now? SSH may disconnect immediately.": "Jetzt mit der Live-Bewerbung fortfahren? SSH wird möglicherweise sofort getrennt.", + "Continue with the experimental HAOS One profile?": "Weiter mit dem experimentellen HAOS One-Profil?", "Continue with the import?": "Mit dem Import fortfahren?", "Continue: Proceed with conversion": "Weiter: Fahren Sie mit der Konvertierung fort", "Continue?": "Weitermachen?", "Continuing with your selection.": "Fahren Sie mit Ihrer Auswahl fort.", + "Contradictory tmpfs options": "Widersprüchliche tmpfs Optionen", "Controller": "Regler", "Controller + NVMe": "Controller + NVMe", "Controller + NVMe assignment will be written now and become active after host reboot.": "Die Controller + NVMe-Zuweisung wird jetzt geschrieben und wird nach dem Neustart des Hosts aktiv.", @@ -849,7 +1130,11 @@ "Converting disk": "Konvertieren einer Festplatte", "Converting file ownership (this may take several minutes)...": "Dateieigentum wird umgewandelt (dies kann mehrere Minuten dauern)...", "Converting image using command:": "Bild mit Befehl konvertieren:", + "Converting the container to privileged...": "Konvertieren des Containers in privilegierte...", "Converts to deb822; keeps .list backups as .bak": "Konvertiert in deb822; Behält .list-Backups als .bak", + "Coordinated backups require zstd": "Koordinierte Backups require zstd", + "Cops by Sébastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server.": "Cops von Sébastien Lucas, jetzt von MikesPub gepflegt, steht für Calibre OPDS (und HTML) Php Server.", + "Copy a peer configuration to the host with: pct pull /config/peer1/peer1.conf peer1.conf": "Kopieren einer Peer-Konfiguration auf den Host mit: pct pull /config/peer1/peer1.conf peer1.conf", "Copy failed": "Kopieren fehlgeschlagen", "Copy that file offsite yourself, or download it from the Monitor.": "Kopieren Sie diese Datei selbst oder laden Sie sie vom Monitor herunter.", "Copy the correct keyfile to this host and rerun Restore — or pick an unencrypted backup.": "Kopieren Sie die richtige Schlüsseldatei auf diesen Host und führen Sie die Wiederherstellung erneut aus – oder wählen Sie ein unverschlüsseltes Backup aus.", @@ -864,6 +1149,7 @@ "Coral M.2 Apex configuration added - device ready": "Coral M.2 Apex-Konfiguration hinzugefügt – Gerät bereit", "Coral M.2 Apex configuration added - device will be available after reboot": "Coral M.2 Apex-Konfiguration hinzugefügt – Gerät ist nach dem Neustart verfügbar", "Coral M.2 Apex detected, configuring...": "Coral M.2 Apex erkannt, konfiguriert...", + "Coral PCIe/M.2 node (e.g. /dev/apex_0)": "Coral PCIe/M.2-Knoten (z. B. /dev/apex 0)", "Coral TPU Installation": "Coral-TPU-Installation", "Coral TPU Uninstall": "Coral TPU-Deinstallation", "Coral TPU device nodes detected with correct group (apex).": "Coral TPU-Geräteknoten wurden mit der richtigen Gruppe (Apex) erkannt.", @@ -876,19 +1162,33 @@ "Coral USB configured but device not currently connected": "Coral USB konfiguriert, aber das Gerät ist derzeit nicht angeschlossen", "Coral USB runtime installed. No reboot required.": "Coral USB-Runtime installiert. Kein Neustart erforderlich.", "Coral hardware configuration completed for container": "Coral-Hardwarekonfiguration für Container abgeschlossen", + "Coral is only offered for Frigate and CodeProject.AI": "Coral wird nur für Frigate und CodeProject angeboten. AI", "Coral kernel modules unloaded.": "Coral-Kernel-Module wurden entladen.", "Coral packages purged.": "Coral-Pakete vollständig entfernt.", "Coral uninstallation completed.": "Coral-Deinstallation abgeschlossen.", "Core Proxmox packages reinstalled successfully": "Kern-Proxmox-Pakete wurden erfolgreich neu installiert", + "Core is running, but not responding over HTTP on 80/8123": "Core läuft, reagiert aber nicht über HTTP auf 80/8123", + "Core is still on the initial installation page": "Core ist immer noch auf der ersten Installationsseite", "Core packages": "Kernpakete", + "Cores": "Kerne", + "Corrupted gzip layer": "Korrupte Gzip-Schicht", "Could not add": "Konnte nicht hinzugefügt werden", "Could not add disk": "Festplatte konnte nicht hinzugefügt werden", + "Could not add the device to the container:": "Konnte das Gerät nicht zum Container hinzufügen:", + "Could not add the mount point:": "Konnte den Mount Point nicht hinzufügen:", + "Could not apply the Compose extra hosts": "Konnte die Compose Extra Hosts nicht anwenden", + "Could not apply the Compose supplementary groups": "Konnte die Compose ergänzenden Gruppen nicht anwenden", + "Could not apply the Jellyfin configuration:": "Konnte die Jellyfin-Konfiguration nicht anwenden:", + "Could not apply the installer profile": "Konnte das Installer-Profil nicht anwenden", + "Could not apply the pre-start repair:": "Die Reparatur vor dem Start konnte nicht durchgeführt werden:", "Could not assign disk": "Datenträger konnte nicht zugewiesen werden", "Could not authorize the key via 'pct exec' on": "Der Schlüssel konnte nicht über „pct exec“ autorisiert werden", "Could not back up the existing auth.json": "Die vorhandene auth.json konnte nicht gesichert werden", "Could not change VM virtual display to vga: std": "Die virtuelle VM-Anzeige konnte nicht in vga: std geändert werden", + "Could not check the NVIDIA GPU": "Konnte die NVIDIA GPU nicht überprüfen", "Could not clone any gasket-driver repository. Check your internet connection and": "Es konnte kein gasket-driver-Repository geklont werden. Überprüfen Sie Ihre Internetverbindung und", "Could not configure IOMMU kernel parameters automatically. Configure manually and reboot.": "IOMMU-Kernelparameter konnten nicht automatisch konfiguriert werden. Manuell konfigurieren und neu starten.", + "Could not convert the OCI rootfs to privileged": "Konnte die OCI-Rootfs nicht in privilegierte umwandeln", "Could not copy the PVE keyfile into place. Check permissions on:": "Die PVE-Schlüsseldatei konnte nicht kopiert werden. Überprüfen Sie die Berechtigungen für:", "Could not copy the keyfile into place.": "Die Schlüsseldatei konnte nicht kopiert werden.", "Could not copy the keyfile into place. Check permissions on:": "Die Schlüsseldatei konnte nicht kopiert werden. Überprüfen Sie die Berechtigungen für:", @@ -898,6 +1198,9 @@ "Could not create or access directory:": "Verzeichnis konnte nicht erstellt oder darauf zugegriffen werden:", "Could not create temporary directory:": "Temporäres Verzeichnis konnte nicht erstellt werden:", "Could not create temporary working directory.": "Das temporäre Arbeitsverzeichnis konnte nicht erstellt werden.", + "Could not create the container:": "Konnte den Container nicht erstellen:", + "Could not create the initial administrator": "Konnte den ursprünglichen Administrator nicht erstellen", + "Could not create the service:": "Konnte den Dienst nicht erstellen:", "Could not detect apex major number from /proc/devices. Load the apex module first: modprobe apex": "Die Apex-Hauptnummer konnte nicht aus /proc/devices erkannt werden. Laden Sie zuerst das Apex-Modul: modprobe apex", "Could not detect the CIFS mount for this directory. Try accessing it manually.": "Der CIFS-Mount für dieses Verzeichnis konnte nicht erkannt werden. Versuchen Sie, manuell darauf zuzugreifen.", "Could not determine a valid ISO storage directory.": "Es konnte kein gültiges ISO-Speicherverzeichnis ermittelt werden.", @@ -907,7 +1210,9 @@ "Could not download recovery blob from PBS.": "Wiederherstellungsblob konnte nicht von PBS heruntergeladen werden.", "Could not download the NVIDIA Container Toolkit repository definition.": "Die NVIDIA Container Toolkit-Repository-Definition konnte nicht heruntergeladen werden.", "Could not download the NVIDIA Container Toolkit signing key.": "Der NVIDIA Container Toolkit-Signaturschlüssel konnte nicht heruntergeladen werden.", + "Could not download the image": "Das Bild konnte nicht heruntergeladen werden", "Could not download the installer.": "Das Installationsprogramm konnte nicht heruntergeladen werden.", + "Could not enable the privileged profile before the first start": "Das privilegierte Profil konnte vor dem ersten Start nicht aktiviert werden", "Could not export ZFS pool": "Der ZFS-Pool konnte nicht exportiert werden", "Could not extract from PBS.": "Konnte nicht aus PBS extrahiert werden.", "Could not fetch keylase/nvidia-patch supported list — patch reapply compatibility is not verified.": "Die Liste der unterstützten Keylase/Nvidia-Patches konnte nicht abgerufen werden – die Kompatibilität mit der erneuten Anwendung des Patches wurde nicht überprüft.", @@ -921,34 +1226,53 @@ "Could not install exFAT tools automatically.": "Die exFAT-Tools konnten nicht automatisch installiert werden.", "Could not install sshpass automatically (no internet?). Falling back to manual paste mode — you'll see the line to copy onto the server next.": "SSHPass konnte nicht automatisch installiert werden (kein Internet?).Wenn Sie auf den manuellen Einfügemodus zurückgreifen, sehen Sie als Nächstes die Zeile, die auf den Server kopiert werden soll.", "Could not install the NVIDIA Container Toolkit signing key.": "Der NVIDIA Container Toolkit-Signaturschlüssel konnte nicht installiert werden.", + "Could not install the required packages:": "Konnte die required-Pakete nicht installieren:", + "Could not install the stack startup hook": "Konnte den Stapelstarthaken nicht installieren", "Could not install vzdump hook in /etc/vzdump.conf": "Der vzdump-Hook konnte nicht in /etc/vzdump.conf installiert werden", "Could not load shared functions. Script cannot continue.": "Gemeinsam genutzte Funktionen konnten nicht geladen werden. Das Skript kann nicht fortgesetzt werden.", + "Could not load the host kernel module:": "Das Host-Kernel-Modul konnte nicht geladen werden:", "Could not locate imported disk in VM config.": "Der importierte Datenträger konnte in der VM-Konfiguration nicht gefunden werden.", "Could not mount": "Konnte nicht gemountet werden", "Could not mount ISO on device": "ISO konnte nicht auf dem Gerät gemountet werden", + "Could not mount the container filesystem:": "Konnte das Container-Dateisystem nicht einhängen:", + "Could not obtain an intact image after two attempts": "Konnte nach zwei Versuchen kein intaktes Bild erhalten", "Could not parse OVF file, or no disk image references found.": "Die OVF-Datei konnte nicht analysiert werden oder es wurden keine Disk-Image-Referenzen gefunden.", "Could not prepare on-boot restore service. Nothing new was scheduled.": "Der On-Boot-Wiederherstellungsdienst konnte nicht vorbereitet werden. Es war nichts Neues geplant.", + "Could not prepare the NVIDIA driver links": "Konnte die NVIDIA-Treiberlinks nicht vorbereiten", + "Could not prepare the file bind mount target:": "Konnte das File Bind Mount-Ziel nicht vorbereiten:", "Could not publish pending restore. Previous pending restore was kept.": "Ausstehende Wiederherstellung konnte nicht veröffentlicht werden. Die vorherige ausstehende Wiederherstellung wurde beibehalten.", "Could not push the key. Check the password and that": "Die Taste konnte nicht gedrückt werden. Überprüfen Sie das Passwort und so weiter", + "Could not query the image registry": "Konnte die Bildregistrierung nicht abfragen", "Could not read SMART data from": "Die SMART-Daten konnten nicht gelesen werden", "Could not read VM configuration.": "Die VM-Konfiguration konnte nicht gelesen werden.", + "Could not read the CUDA compute capability": "Konnte die CUDA-Rechenfähigkeit nicht lesen", + "Could not read the NVIDIA driver version": "Konnte die NVIDIA Treiberversion nicht lesen", "Could not remount automatically. Try manually or check credentials.": "Konnte nicht automatisch erneut bereitgestellt werden. Versuchen Sie es manuell oder überprüfen Sie die Anmeldeinformationen.", "Could not remove VM automatically. Run manually:": "VM konnte nicht automatisch entfernt werden. Manuell ausführen:", "Could not remove previous DKMS tree at": "Vorheriger DKMS-Baum konnte nicht entfernt werden", + "Could not reserve a private network for the stack": "Konnte kein privates Netzwerk für den Stack reservieren", + "Could not resolve the Compose user:": "Konnte den Compose-Benutzer nicht lösen:", + "Could not resolve the OCI manifest of the image:": "Konnte das OCI-Manifest des Bildes nicht auflösen:", + "Could not resolve the OCI manifest:": "Konnte das OCI-Manifest nicht lösen:", "Could not restart ProxMenux Monitor service.": "Der ProxMenux Monitor-Dienst konnte nicht neu gestartet werden.", "Could not restart the service — start it manually with systemctl start": "Der Dienst konnte nicht neu gestartet werden. Starten Sie ihn manuell mit systemctl start", "Could not retrieve versions list from NVIDIA. Please check your internet connection.": "Die Versionsliste konnte nicht von NVIDIA abgerufen werden. Bitte überprüfen Sie Ihre Internetverbindung.", + "Could not reuse the persistent disk:": "Konnte die persistente Festplatte nicht wiederverwenden:", "Could not run NVIDIA patch script. Please verify repository and driver version.": "Das NVIDIA-Patchskript konnte nicht ausgeführt werden. Bitte überprüfen Sie das Repository und die Treiberversion.", "Could not set VM virtual display to vga: std": "Die virtuelle VM-Anzeige konnte nicht auf vga: std gesetzt werden", "Could not set boot order for": "Die Startreihenfolge konnte nicht festgelegt werden", + "Could not set the container entrypoint": "Konnte den Container-Einstiegspunkt nicht einstellen", "Could not stage pending restore path:": "Ausstehender Wiederherstellungspfad konnte nicht bereitgestellt werden:", "Could not stage pending restore. Nothing new was scheduled.": "Die Wiederherstellung konnte nicht bereitgestellt werden. Es war nichts Neues geplant.", "Could not stop LXC": "LXC konnte nicht gestoppt werden", + "Could not translate the Compose command/entrypoint": "Konnte den Befehl Compose/Entrypoint nicht übersetzen", "Could not unload nouveau module (may be in use). The blacklist will take effect after reboot. Installation will continue but a reboot will be required.": "Das Nouveau-Modul konnte nicht entladen werden (möglicherweise wird es verwendet). Die Blacklist wird nach dem Neustart wirksam. Die Installation wird fortgesetzt, es ist jedoch ein Neustart erforderlich.", "Could not unmount": "Die Bereitstellung konnte nicht aufgehoben werden", + "Could not unmount the container filesystem:": "Konnte das Container-Dateisystem nicht unmounten:", "Could not unmount — disk may be busy. Removing fstab entry anyway.": "Die Bereitstellung konnte nicht aufgehoben werden – die Festplatte ist möglicherweise ausgelastet. Fstab-Eintrag trotzdem entfernen.", "Could not update config file.": "Die Konfigurationsdatei konnte nicht aktualisiert werden.", "Could not write to:": "Es konnte nicht geschrieben werden an:", + "Crafty Controller default login": "Crafty Controller Standard Login", "Create Directory": "Verzeichnis erstellen", "Create GPT and one partition:": "Erstellen Sie GPT und eine Partition:", "Create GPT partition": "Erstellen Sie eine GPT-Partition", @@ -971,6 +1295,7 @@ "Create a fresh GPT + ext4 partition and mount it?": "Eine neue GPT + ext4-Partition erstellen und mounten?", "Create a new dataset in a ZFS pool": "Erstellen Sie einen neuen Datensatz in einem ZFS-Pool", "Create a new group for isolation": "Erstellen Sie eine neue Gruppe zur Isolierung", + "Create and edit Matroska files from a browser": "Erstellen und Bearbeiten von Matroska-Dateien aus einem Browser", "Create credentials file (recommended):": "Anmeldeinformationsdatei erstellen (empfohlen):", "Create directory": "Verzeichnis erstellen", "Create export directory:": "Exportverzeichnis erstellen:", @@ -982,6 +1307,7 @@ "Create scheduled backup job": "Erstellen Sie einen geplanten Sicherungsauftrag", "Create share directory:": "Freigabeverzeichnis erstellen:", "Create shared directory:": "Freigegebenes Verzeichnis erstellen:", + "Create this LXC in privileged mode?": "Erstellen Sie diese LXC im privilegierten Modus?", "Created common remapped user": "Allgemeiner neu zugeordneter Benutzer erstellt", "Created directory on host:": "Erstelltes Verzeichnis auf Host:", "Created persistent names for": "Persistente Namen erstellt für", @@ -996,6 +1322,8 @@ "Creating UID remapping for unprivileged container compatibility...": "Erstellen einer UID-Neuzuordnung für Kompatibilität mit unprivilegierten Containern ...", "Creating VM with the above configuration": "Erstellen einer VM mit der obigen Konfiguration", "Creating VM...": "VM erstellen...", + "Creating a backup of": "Erstellen eines Backups von", + "Creating a backup of the container...": "Erstellen eines Backups des Containers...", "Creating backup of configuration file...": "Backup der Konfigurationsdatei wird erstellt...", "Creating backup of network interfaces configuration...": "Backup der Netzwerkschnittstellenkonfiguration wird erstellt...", "Creating compressed archive...": "Komprimiertes Archiv wird erstellt...", @@ -1005,6 +1333,11 @@ "Creating partition table and partition...": "Partitionstabelle und Partition erstellen...", "Creating partition...": "Partition erstellen...", "Creating pigz wrapper script...": "Pigz-Wrapper-Skript wird erstellt...", + "Creating the backup": "Erstellen des Backups", + "Creating the container...": "Erstellen des Containers...", + "Creating the initial administrator...": "Erstellen des ersten Administrators...", + "Creating the temporary data container": "Erstellen des temporären Datencontainers", + "Creative & Design": "Kreativ & Design", "Credentials are correct": "Die Anmeldedaten sind korrekt", "Credentials cleared. jwt_secret and API tokens preserved.": "Anmeldedaten gelöscht. jwt_secret und API-Token bleiben erhalten.", "Credentials file created securely.": "Anmeldeinformationsdatei sicher erstellt.", @@ -1014,6 +1347,8 @@ "Cross-host restore: guest IDs in backup overlap live IDs on target:": "Hostübergreifende Wiederherstellung: Gast-IDs im Backup überschneiden sich mit Live-IDs auf dem Ziel:", "Cross-kernel restore — kernel-tied paths merged, not copied": "Kernelübergreifende Wiederherstellung – Kernel-gebundene Pfade werden zusammengeführt, nicht kopiert", "Cross-kernel — paths hidden from picker": "Kernelübergreifend – Pfade, die vor der Auswahl verborgen sind", + "Cross-platform file sharing made easy.": "Plattformübergreifendes Filesharing leicht gemacht.", + "Cross-platform monitoring tool.": "Plattformübergreifendes Monitoring-Tool.", "Cross-version detected — safe restore mode": "Versionsübergreifend erkannt – sicherer Wiederherstellungsmodus", "Current": "Aktuell", "Current CIFS mounts:": "Aktuelle CIFS-Mounts:", @@ -1023,6 +1358,8 @@ "Current NFS client script supports privileged LXC only.": "Das aktuelle NFS-Client-Skript unterstützt nur privilegiertes LXC.", "Current NFS exports in CT": "Aktuelle NFS-Exporte in CT", "Current NFS mounts:": "Aktuelle NFS-Mounts:", + "Current NVIDIA inventory resolved: a refresh is required": "Aktuelles NVIDIA-Inventar behoben: ein Refresh ist required", + "Current NVIDIA inventory resolved: no refresh is required": "Aktuelles NVIDIA-Inventar behoben: kein Refresh ist required", "Current Network Configuration": "Aktuelle Netzwerkkonfiguration", "Current PVE Version": "Aktuelle PVE-Version", "Current ProxMenux host scripts register remote shares as Proxmox storages using pvesm.": "Aktuelle ProxMenux-Hostskripte registrieren Remote-Freigaben mithilfe von pvesm als Proxmox-Speicher.", @@ -1046,6 +1383,7 @@ "Current user": "Aktueller Benutzer", "Current user UID, GID and groups": "Aktuelle Benutzer-UID, GID und Gruppen", "Current version:": "Aktuelle Version:", + "Currently": "Momentan", "Currently Mounted:": "Derzeit montiert:", "Currently configured target:": "Derzeit konfiguriertes Ziel:", "Currently mounted:": "Derzeit montiert:", @@ -1066,6 +1404,7 @@ "Custom message added to MOTD": "Benutzerdefinierte Nachricht zu MOTD hinzugefügt", "Custom options": "Benutzerdefinierte Optionen", "Custom path": "Benutzerdefinierter Pfad", + "Custom path cancelled": "Abgebrochener Zollpfad", "Custom path...": "Benutzerdefinierter Pfad...", "Custom paths are included in BOTH default and custom backup profiles.": "Benutzerdefinierte Pfade sind SOWOHL in den Standard- als auch in den benutzerdefinierten Sicherungsprofilen enthalten.", "Custom paths currently saved: {count}.": "Derzeit gespeicherte benutzerdefinierte Pfade: {count}.", @@ -1078,6 +1417,8 @@ "Customization": "Anpassung", "Customize bashrc": "bashrc anpassen", "Customizing bashrc for root user...": "Anpassen von bashrc für Root-Benutzer ...", + "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite.": "DB Browser für SQLite ist ein qualitativ hochwertiges, visuelles Open-Source-Tool zum Erstellen, Entwerfen und Bearbeiten von Datenbankdateien, die mit SQLite kompatibel sind.", + "DHCP (automatic)": "DHCP (automatisch)", "DISABLED unless you enable it": "DEAKTIVIERT, es sei denn, Sie aktivieren es", "DKMS add failed. Check": "DKMS-Hinzufügen fehlgeschlagen. Überprüfen", "DKMS build failed.": "DKMS-Build ist fehlgeschlagen.", @@ -1090,15 +1431,34 @@ "DKMS registrations removed.": "DKMS-Registrierungen entfernt.", "DNS Resolution": "DNS-Auflösung", "DNS lookup for a domain": "DNS-Suche nach einer Domain", + "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)": "DNS-Plugin mit dns-Validierung (Cloudflare, duckdns, ovh...)", + "DNS server written in the client configurations": "DNS-Server in den Client-Konfigurationen geschrieben", + "DNS server written in the peer configurations (auto or an IP address)": "DNS-Server in den Peer-Konfigurationen geschrieben (Auto oder eine IP-Adresse)", + "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid.": "DOGWALK ist das lang erwartete zweite Spielprojekt des Blender Studios, das sich auf die Schaffung eines interaktiven Storytelling-Spielplatzes in mundgerechter Größe konzentriert. Spielen Sie als großer entzückender Hund und erkunden Sie den Winterwald mit einem kleinen Kind.", + "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games.": "DOSBox Staging ist eine moderne Fortsetzung von DOSBox, einem kostenlosen Open-Source-Emulator, der die Ausführung von MS-DOS-Software, insbesondere Videospielen, ermöglicht.", + "DVB device directory": "DVB-Geräteverzeichnis", + "Data": "Daten", + "Data location": "Datenstandort", "Data size:": "Datengröße:", + "Data that is deleted with them:": "Daten, die mit ihnen gelöscht werden:", + "Data volume size in GB": "Datenvolumengröße in GB", + "Data volumes protected": "Geschützte Datenmengen", "Data wipe complete.": "Datenlöschung abgeschlossen.", "Data wiped from": "Daten gelöscht von", + "Database management in a single PHP file": "Datenbankverwaltung in einer einzelnen PHP-Datei", + "Database server proposed on the login page (empty = typed at each login)": "Datenbankserver auf der Login-Seite vorgeschlagen (leer = bei jedem Login eingegeben)", + "Databases": "Datenbanken", "Datastore name:": "Datenspeichername:", + "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow.": "Davos ist ein FTP-Automatisierungstool, das bestimmte Host-Standorte regelmäßig nach neuen Dateien durchsucht. Es kann für verschiedene Zwecke konfiguriert werden, einschließlich des Abhörens bestimmter Dateien, die am Hoststandort erscheinen, bereit zum Herunterladen und dann Bewegen, wenn required. Es unterstützt auch Abschlussbenachrichtigungen sowie nachgelagerte API-Aufrufe, um den Workflow zu fördern.", + "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways.": "Ddclient ist ein Perl-Client, der verwendet wird, um dynamische DNS-Einträge für Konten bei Dynamic DNS Network Service Provider zu aktualisieren. Es wurde ursprünglich von Paul Burry geschrieben und ist jetzt hauptsächlich von wimpunk. Es hat die Möglichkeit, mehr als nur Dyndns zu aktualisieren und kann Ihre WAN-IPadadresse auf verschiedene Arten abrufen.", "Deactivate Monitor": "Monitor deaktivieren", "Deactivate ProxMenux Monitor": "Deaktivieren Sie den ProxMenux Monitor", "Debian repositories missing; creating default source file": "Debian-Repositorys fehlen; Erstellen einer Standardquelldatei", "Decompress backup manually": "Backup manuell dekomprimieren", "Decryption failed. The passphrase may be wrong, or the blob is corrupt. Try again?": "Die Entschlüsselung ist fehlgeschlagen. Möglicherweise ist die Passphrase falsch oder das Blob ist beschädigt. Versuchen Sie es erneut?", + "Dedicated container volume (included in backups)": "Dediziertes Containervolumen (in Backups enthalten)", + "Dedicated container volumes (included in backups)": "Dedizierte Container-Volumes (in Backups enthalten)", + "DeepSeek Harness “Everything is a Plugin“.": "DeepSeek Harness \"Alles ist ein Plugin\".", "Default ACLs applied for group inheritance.": "Für die Gruppenvererbung werden Standard-ACLs angewendet.", "Default Credentials": "Standardanmeldeinformationen", "Default Gateway": "Standard-Gateway", @@ -1110,10 +1470,12 @@ "Default journald configuration restored": "Standard-Journald-Konfiguration wiederhergestellt", "Default location is /mnt/. The share will be mounted here on the host with open permissions so an unprivileged LXC can bind-mount and write to it. For LXC access, bind-mount this path with the LXC Mount Manager.": "Der Standardspeicherort ist /mnt/. Die Freigabe wird hier auf dem Host mit offenen Berechtigungen gemountet, sodass ein unprivilegierter LXC sie binden, mounten und darauf schreiben kann. Für den LXC-Zugriff müssen Sie diesen Pfad mit dem LXC Mount Manager binden.", "Default location is /mnt/. The share will be mounted here on the host. Use this path in /etc/fstab. For LXC access, bind-mount this path with the LXC Mount Manager.": "Der Standardspeicherort ist /mnt/. Die Freigabe wird hier auf dem Host gemountet. Verwenden Sie diesen Pfad in /etc/fstab. Für den LXC-Zugriff müssen Sie diesen Pfad mit dem LXC Mount Manager binden.", + "Default login": "Standard-Login", "Default options": "Standardoptionen", "Default options read/write": "Standardoptionen Lesen/Schreiben", "Default will be used:": "Standard wird verwendet:", "Default:": "Standard:", + "Default: only what the application needs": "Standard: nur das, was die Anwendung braucht", "Delete Borg target": "Borg-Ziel löschen", "Delete Export": "Export löschen", "Delete Share": "Freigabe löschen", @@ -1122,7 +1484,10 @@ "Delete archive": "Archiv löschen", "Delete job": "Auftrag löschen", "Delete scheduled backup job?": "Geplanten Sicherungsauftrag löschen?", + "Delete the image to free the space?": "Löschen Sie das Bild, um den Raum freizugeben?", + "Delete the images to free the space?": "Löschen Sie die Bilder, um den Raum zu befreien?", "Delete this corrupt archive and pick another": "Löschen Sie dieses beschädigte Archiv und wählen Sie ein anderes aus", + "Deluge is a lightweight, Free Software, cross-platform BitTorrent client.": "Deluge ist ein leichter, Freie Software, Cross-Plattform BitTorrent Client.", "Dependencies installed successfully": "Abhängigkeiten erfolgreich installiert", "Deploy with this configuration?": "Mit dieser Konfiguration bereitstellen?", "Deploying Secure Gateway...": "Secure Gateway wird bereitgestellt...", @@ -1177,9 +1542,15 @@ "Device added": "Gerät hinzugefügt", "Device already present in target VM — existing hostpci entry reused": "Gerät ist bereits in der Ziel-VM vorhanden – vorhandener Hostpci-Eintrag wiederverwendet", "Device assignments will be written now and become active after reboot.": "Gerätezuordnungen werden jetzt geschrieben und sind nach dem Neustart aktiv.", + "Device configuration cancelled": "Gerätekonfiguration abgebrochen", "Device hostname": "Hostname des Geräts", + "Device node outside the supported profiles": "Geräteknoten außerhalb der unterstützten Profile", + "Device outside the supported profiles; NVIDIA and device trees require another profile": "Gerät außerhalb der unterstützten Profile; NVIDIA und Gerätebäume require ein weiteres Profil", "Device path mismatch. Format cancelled.": "Nicht übereinstimmender Gerätepfad. Formatierung abgebrochen.", + "Device permissions verified for the application user": "Geräteberechtigungen für den Anwendungsbenutzer verifiziert", "Device:": "Gerät:", + "Devices added to the container:": "Dem Behälter hinzugefügte Vorrichtungen:", + "Devices of the host it asks for:": "Geräte des Hosts, um den es bittet:", "Devices to add to VM": "Geräte, die zur VM hinzugefügt werden sollen", "Diff: current system vs backup (--- system +++ backup)": "Unterschied: aktuelles System vs. Backup (--- System +++ Backup)", "Different host. Backup from:": "Anderer Gastgeber. Backup von:", @@ -1196,6 +1567,8 @@ "Directory does not exist and was not created.": "Das Verzeichnis existiert nicht und wurde nicht erstellt.", "Directory does not exist:": "Verzeichnis existiert nicht:", "Directory error": "Verzeichnisfehler", + "Directory for the read-only view": "Verzeichnis für die Read-only-Ansicht", + "Directory for the read/write view": "Verzeichnis für die Lese-/Schreibansicht", "Directory not found": "Verzeichnis nicht gefunden", "Directory storage added successfully to Proxmox!": "Verzeichnisspeicher erfolgreich zu Proxmox hinzugefügt!", "Directory successfully.": "Verzeichnis erfolgreich.", @@ -1248,6 +1621,7 @@ "Disk path:": "Festplattenpfad:", "Disk safety revalidation failed.": "Die erneute Überprüfung der Festplattensicherheit ist fehlgeschlagen.", "Disk safety validation passed.": "Festplattensicherheitsvalidierung bestanden.", + "Disk too small for the common profile": "Disk zu klein für das gemeinsame Profil", "Disk unmounted from": "Datenträger nicht gemountet von", "Disk verified and accessible inside CT at": "Datenträger überprüft und im CT zugänglich unter", "Disk:": "Scheibe:", @@ -1261,6 +1635,10 @@ "Display physical volumes (LVM)": "Physische Volumes (LVM) anzeigen", "Display system summary in ASCII format": "Systemzusammenfassung im ASCII-Format anzeigen", "Display volume groups (LVM)": "Volumengruppen anzeigen (LVM)", + "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer.": "Gehen Sie nicht davon aus, dass Port 8123 nach dem Onboarding auf Home Assistant Core 2026.8 oder neuer aktiv bleibt.", + "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume.": "Behaupten Sie nicht, dass OCI-Image-Updates vor Ort validiert werden, bis Rootfs-Ersatz und Rollback getestet wurden, ohne das verwaltete /mnt / Datenvolumen zu verlieren.", + "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default.": "Aktivieren Sie nicht automatisch auf nicht unterstützten AMD integrierten GPUs. HSA-Überschreibungen sind manuelle Kompatibilitätsexperimente, kein validierter Standard.", + "Do not mount": "Nicht montieren", "Do not run the upgrade from the Web UI virtual console (it will disconnect)": "Führen Sie das Upgrade nicht über die virtuelle Konsole der Web-Benutzeroberfläche aus, da sonst die Verbindung unterbrochen wird.", "Do not start the VM until the system has been rebooted.": "Starten Sie die VM erst, wenn das System neu gestartet wurde.", "Do you want ProxMenux to stop it now?": "Möchten Sie, dass ProxMenux es jetzt stoppt?", @@ -1304,9 +1682,23 @@ "Do you want to update the existing export?": "Möchten Sie den vorhandenen Export aktualisieren?", "Do you want to update the existing share?": "Möchten Sie die vorhandene Freigabe aktualisieren?", "Do you want to view the selected backup before restoring?": "Möchten Sie das ausgewählte Backup vor der Wiederherstellung anzeigen?", + "Docker Mods are only offered for compatible LinuxServer images": "Docker Mods werden nur für kompatible LinuxServer Images angeboten", + "Docker Volume Backup": "Docker Volume Backup", + "Docker/CLI not available yet or no valid answer": "Docker/CLI noch nicht verfügbar oder keine gültige Antwort", + "Documents & Notes": "Dokumente & Notizen", + "Documents volume size in GB": "Dokumentenvolumen in GB", + "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki.": "Dokuwiki ist eine einfach zu bedienende und äußerst vielseitige Open-Source-Wiki-Software, die keine Datenbank requi ist. Es wird von den Benutzern für seine saubere und lesbare Syntax geliebt. Die einfache Wartung, Sicherung und Integration macht es zum Favoriten des Administrators. Integrierte Zugangskontrollen und Authentifizierungskonnektoren machen DokuWiki besonders nützlich im Unternehmenskontext und die große Anzahl von Plugins, die von der lebendigen Community beigetragen werden, ermöglichen eine breite Palette von Anwendungsfällen jenseits eines traditionellen Wikis.", + "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience.": "Mit Dolphin Emulator können Sie GameCube- und Wii-Spiele mit verschiedenen grafischen Verbesserungen spielen, und es stehen weitere Funktionen zur Verfügung, um Ihr Spielerlebnis zu verbessern.", + "Domain for the certificate (example.com)": "Domain für das Zertifikat (beispiel.com)", + "Doplarr is an *arr request bot for Discord.\"": "Doplarr ist ein *arr Request Bot für Discord.", + "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust.": "Doplarr_rs ist ein Discord-Bot für die Anforderung von Medien über *arr Backends, geschrieben in Rust.", + "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas.": "Double Commander ist ein kostenloser Cross-Plattform-Open-Source-Dateimanager mit zwei Panels nebeneinander. Es ist inspiriert von Total Commander und enthält einige neue Ideen.", + "Download Spotify music with album art and metadata": "Laden Sie Spotify Musik mit Album Art und Metadaten herunter", "Download failed for all attempted URLs": "Der Download ist für alle versuchten URLs fehlgeschlagen", + "Download its Compose file from an address": "Laden Sie die Compose-Datei von einer Adresse herunter", "Download keyfile": "Schlüsseldatei herunterladen", "Download latest VirtIO ISO automatically": "Laden Sie die neueste VirtIO-ISO automatisch herunter", + "Downloaded OCI images deleted:": "Heruntergeladene OCI-Bilder gelöscht:", "Downloaded amdgpu_top": "Amdgpu_top heruntergeladen", "Downloading": "Herunterladen", "Downloading Helper-Scripts logo...": "Helper-Scripts-Logo wird heruntergeladen...", @@ -1318,45 +1710,86 @@ "Downloading amdgpu_top": "Amdgpu_top wird heruntergeladen", "Downloading official installer...": "Offizielles Installationsprogramm wird heruntergeladen...", "Downloading pre-existing encrypted backups from this host will fail unless you kept a copy of the current key.": "Das Herunterladen bereits vorhandener verschlüsselter Backups von diesem Host schlägt fehl, es sei denn, Sie haben eine Kopie des aktuellen Schlüssels aufbewahrt.", + "Downloading the image:": "Herunterladen des Bildes:", "Downloading the latest Fastfetch release...": "Laden Sie die neueste Fastfetch-Version herunter...", "Driver blacklist entries removed": "Treiber-Blacklist-Einträge entfernt", "Driver blacklist removed for": "Treiber-Blacklist entfernt für", "Driver installed successfully. Press Enter to continue...": "Treiber erfolgreich installiert. Drücken Sie die Eingabetaste, um fortzufahren...", "Drivers :": "Treiber:", "Drivers compiled and installed via DKMS.": "Treiber über DKMS kompiliert und installiert.", + "Dry run completed; no changes were made.": "Trockenlauf abgeschlossen; es wurden keine Änderungen vorgenommen.", + "Dry run completed; no containers were created.": "Trockenlauf abgeschlossen; es wurden keine Container erstellt.", + "Dry run completed; the container and the mounts were not changed.": "Trockenlauf abgeschlossen; der Behälter und die Halterungen wurden nicht verändert.", + "DuckDNS subdomain without .duckdns.org (comma separated for several)": "DuckDNS Subdomain ohne .duckdns.org (Komma für mehrere getrennt)", + "DuckDNS token from your account at duckdns.org": "DuckDNS-Token von Ihrem Konto bei duckdns.org", + "DuckDNS updates the subdomain every 5 minutes. Without UPDATE_IP, DuckDNS itself detects the public IPv4 address of the request.": "DuckDNS aktualisiert die Subdomain alle 5 Minuten. Ohne UPDATE IP erkennt DuckDNS selbst die öffentliche IPv4-Adresse der Anfrage.", + "DuckStation is a PS1 Emulator aiming for the best accuracy and game support.": "DuckStation ist ein PS1-Emulator, der auf die beste accuracy- und Spielunterstützung abzielt.", + "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence.": "Duckdns ist ein kostenloser Dienst, der ein DNS (Subdomains von duckdns.org) auf eine IP Ihrer Wahl verweist. Der Dienst ist völlig kostenlos und require Reaktivierung oder Forenbeiträge, um seine Existenz zu erhalten.", "Dumping AMD GPU ROM BIOS via sysfs...": "Das AMD-GPU-ROM-BIOS wird über sysfs gelöscht ...", "Duplicate IP addresses found": "Doppelte IP-Adressen gefunden", "Duplicate parameters cleaned": "Doppelte Parameter bereinigt", + "Duplicate variable in the contract; review it before editing": "Duplizieren Sie die Variable im Vertrag; überprüfen Sie sie vor der Bearbeitung", + "Duplicated GPU device in the container": "Dupliziertes GPU-Gerät im Container", + "Duplicated NVIDIA devices": "Doppelte NVIDIA-Geräte", + "Duplicated VMID in the Proxmox inventory": "Dupliziertes VMID im Proxmox-Inventar", + "Duplicated native directive:": "Duplizierte native Direktive:", + "Duplicated native option": "Duplizierte native Option", + "Duplicated or invalid stack VMID": "Doppelter oder ungültiger Stack VMID", + "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others.": "Duplicati ist ein Backup-Client, der verschlüsselte, inkrementelle, komprimierte Backups sicher auf lokalem Speicher, Cloud-Speicherdiensten und Remote-Dateiservern speichert. Es funktioniert mit Standardprotokollen wie FTP, SSH, WebDAV sowie mit beliebten Diensten wie Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2 und vielen anderen.", + "Duplicati web interface (password only)": "Duplicati Webinterface (nur Passwort)", "Duration": "Dauer", "Duration:": "Dauer:", + "Dynamic NVIDIA is only validated for unprivileged containers. This profile uses static mounts and must be recreated after the host driver changes.": "Dynamic NVIDIA ist nur für unprivilegierte Container validiert. Dieses Profil verwendet statische Halterungen und muss nach dem Wechsel des Hosttreibers neu erstellt werden.", "EFI disk created and configured on": "EFI-Festplatte erstellt und konfiguriert auf", "EFI storage selection cancelled.": "EFI-Speicherauswahl abgebrochen.", "EFI storage selection failed or was cancelled. VM creation aborted.": "Die EFI-Speicherauswahl ist fehlgeschlagen oder wurde abgebrochen. VM-Erstellung wurde abgebrochen.", "EMERGENCY PROXMOX SYSTEM REPAIR": "NOTFALLREPARATUR DES PROXMOX-SYSTEMS", "ENABLED for restore": "Für die Wiederherstellung AKTIVIERT", "EXISTS": "EXISTIERT", + "Each /request command needs a backend: add a [[backends]] block in the same file with the url and api_key of your Sonarr, Radarr or Seerr instance, then restart the container.": "Jeder Befehl /request benötigt ein Backend: Fügen Sie einen Block [[Backends]] in derselben Datei mit der URL und dem api key Ihrer Sonarr-, Radarr- oder Seerr-Instanz hinzu und starten Sie dann den Container neu.", "Each LUN will appear as a block device assignable to VMs.": "Jede LUN wird als Blockgerät angezeigt, das VMs zugewiesen werden kann.", + "Each peer gets its configuration and its QR code inside the container: /config/peer1/peer1.conf and /config/peer1/peer1.png, or /config/peer_/peer_.conf when names were given.": "Jeder Peer erhält seine Konfiguration und seinen QR-Code im Container: /config/peer1/peer1.conf und /config/peer1/peer1.png oder /config/peer /peer .conf, wenn Namen angegeben wurden.", + "Ebook and audiobook collection manager for Usenet and BitTorrent users.": "Ebook und audiobook collection manager für usenet- und bittorrent-benutzer.", + "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind.": "Eden ist ein experimenteller Open-Source-Emulator für den Nintendo Switch, der auf Leistung und Stabilität ausgerichtet ist.", "Edge TPU runtime installed.": "Edge TPU-Laufzeit installiert.", "Edit raw CT configuration file": "Bearbeiten Sie die Roh-CT-Konfigurationsdatei", "Edit raw VM configuration file": "Bearbeiten Sie die Roh-VM-Konfigurationsdatei", "Edit the VM machine type to q35 and try again.": "Bearbeiten Sie den VM-Maschinentyp auf q35 und versuchen Sie es erneut.", + "Email address for certificate expiry notices (required by ZeroSSL)": "E-Mail-Adresse für Zertifikatsverfallsmeldungen (required by ZeroSSL)", + "Email address of the LibreDB Studio administrator": "E-Mail-Adresse des LibreDB Studio-Administrators", + "Email address of the NetBox admin account": "E-Mail-Adresse des NetBox Administratorkontos", + "Emby WebUI": "Emby WebUI", + "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server.": "Emby organisiert Video, Musik, Live-TV und Fotos aus persönlichen Medienbibliotheken und streamt sie auf Smart-TVs, Streaming-Boxen und mobile Geräte. Dieser Container ist als eigenständiger emby Media Server verpackt.", "Emergency Proxmox System Repair": "Notfallreparatur des Proxmox-Systems", "Emergency recovery:": "Notfallwiederherstellung:", + "Empowering the smart home": "Empowerment des Smart Home", "Empty": "Leer", + "Empty exec service check": "Leere Exec-Prüfung", + "Empty or duplicated NVIDIA identity": "Leere oder duplizierte NVIDIA-Identität", + "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes.": "EmulatorJS ist eine Docker-basierte Emulatoranwendung, die verschiedene operating-Systeme und Geräteumgebungen in Containern für Entwicklungs-, Test- und Lernzwecke simulieren kann.", "Enable": "Aktivieren", "Enable / disable job timer": "Job-Timer aktivieren/deaktivieren", "Enable High Availability services": "Hochverfügbarkeitsdienste aktivieren", "Enable IOMMU in GRUB or ZFS boot": "Aktivieren Sie IOMMU im GRUB- oder ZFS-Boot", "Enable IOMMU support if not enabled": "Aktivieren Sie die IOMMU-Unterstützung, falls diese nicht aktiviert ist", "Enable IOMMU, reboot the host, and try again.": "Aktivieren Sie IOMMU, starten Sie den Host neu und versuchen Sie es erneut.", + "Enable Intel/AMD VA-API video acceleration": "Intel/AMD VA-API Videobeschleunigung aktivieren", + "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping": "Aktivieren von NVIDIA Transcoding und HDR10/Dolby Vision to SDR Tone Mapping", "Enable Remote Desktop (RDP) before disabling the virtual display.": "Aktivieren Sie Remote Desktop (RDP), bevor Sie die virtuelle Anzeige deaktivieren.", "Enable SSD emulation for this disk?": "SSD-Emulation für diese Festplatte aktivieren?", "Enable TCP BBR/Fast Open control": "Aktivieren Sie die TCP-BBR/Fast-Open-Steuerung", + "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping": "Aktivieren von VA-API Transcoding und HDR10/Dolby Vision to SDR Tone Mapping", + "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin": "Aktivieren Sie VA-API, Hardware-Codierung und OpenCL-Tone-Mapping in Jellyfin", "Enable VFIO IOMMU support": "VFIO IOMMU-Unterstützung aktivieren", "Enable ZFS autotrim (SSD/NVMe pools)": "ZFS-Autotrim aktivieren (SSD/NVMe-Pools)", + "Enable a mount on an existing Rclone OCI container": "Aktivieren einer Halterung an einem vorhandenen Rclone OCI Container", + "Enable an optical drive for MakeMKV": "Aktivieren eines optischen Laufwerks für MakeMKV", "Enable auto-sync if /var/log exceeds 90% of its size?": "Automatische Synchronisierung aktivieren, wenn /var/log 90 % seiner Größe überschreitet?", "Enable fast reboots": "Schnelle Neustarts aktivieren", "Enable restart on kernel panic": "Neustart bei Kernel-Panic aktivieren", + "Enable the NVIDIA GPU requested by the image": "Aktivieren Sie die vom Bild angeforderte NVIDIA-GPU", + "Enable the NVIDIA GPU required by Open WebUI CUDA": "Aktivieren Sie die NVIDIA GPU required by Open WebUI CUDA", + "Enable this FUSE mount now and restart the CT?": "Aktivieren Sie diese FUSE-Halterung jetzt und starten Sie das CT neu?", "Enable/Disable job": "Job aktivieren/deaktivieren", "Enabled": "Ermöglicht", "Enabled (device pending — load apex module or reboot)": "Aktiviert (Gerät steht aus – Apex-Modul laden oder neu starten)", @@ -1401,6 +1834,7 @@ "Enter a name for the mount point (used as /mnt/):": "Geben Sie einen Namen für den Mount-Punkt ein (verwendet als /mnt/):", "Enter a name for the new virtual machine:": "Geben Sie einen Namen für die neue virtuelle Maschine ein:", "Enter a number, or write or paste a command:": "Geben Sie eine Zahl ein oder schreiben oder fügen Sie einen Befehl ein:", + "Enter a usable IPv4 address with its prefix, for example": "Geben Sie eine nutzbare IPv4-Adresse mit ihrem Präfix ein, zum Beispiel", "Enter backup file (.zst):": "Geben Sie die Sicherungsdatei (.zst) ein:", "Enter backup path (.tar.zst):": "Geben Sie den Sicherungspfad (.tar.zst) ein:", "Enter backup path (.vma.zst):": "Geben Sie den Sicherungspfad (.vma.zst) ein:", @@ -1489,6 +1923,7 @@ "Enter the number or type the interface name:": "Geben Sie die Nummer ein oder geben Sie den Schnittstellennamen ein:", "Enter the password for Samba user:": "Geben Sie das Passwort für den Samba-Benutzer ein:", "Enter the recovery passphrase set when the keyfile was created:": "Geben Sie die Wiederherstellungspassphrase ein, die beim Erstellen der Schlüsseldatei festgelegt wurde:", + "Enter the size in whole GB, for example": "Geben Sie die Größe in ganz GB ein, zum Beispiel", "Enter username for Samba server:": "Geben Sie den Benutzernamen für den Samba-Server ein:", "Enter username:": "Benutzernamen eingeben:", "Enterprise Proxmox Ceph repository disabled": "Enterprise Proxmox Ceph-Repository deaktiviert", @@ -1497,6 +1932,8 @@ "Enterprise repository returned 401 Unauthorized (no valid subscription). Switch to the no-subscription repository and retry?": "Das Unternehmens-Repository hat 401 Nicht autorisiert zurückgegeben (kein gültiges Abonnement). Zum Repository ohne Abonnement wechseln und es erneut versuchen?", "Enterprise repository unauthorized and fallback declined by user": "Unternehmens-Repository nicht autorisiert und Fallback vom Benutzer abgelehnt", "Entropy generation optimization removed": "Optimierung der Entropieerzeugung entfernt", + "Environment entry without an explicit value": "Umwelteintrag ohne expliziten Wert", + "Environment override for an unknown service:": "Environment Override für einen unbekannten Dienst:", "Equivalent manual flow of disk_host.sh: partition, format, mount, persist, register in Proxmox.": "Äquivalenter manueller Ablauf von disk_host.sh: Partitionieren, Formatieren, Mounten, Beibehalten, Registrieren in Proxmox.", "Equivalent manual flow of iscsi_host.sh.": "Äquivalenter manueller Ablauf von iscsi_host.sh.", "Equivalent manual flow used by Local Shared Manager.": "Äquivalenter manueller Ablauf, der von Local Shared Manager verwendet wird.", @@ -1512,12 +1949,16 @@ "Error: No write permissions in directory": "Fehler: Keine Schreibrechte im Verzeichnis", "Essential Proxmox packages installed": "Wichtige Proxmox-Pakete installiert", "Estimated required free space:": "Geschätzter erforderlicher freier Speicherplatz:", + "Etherpad admin page": "Etherpad Admin-Seite", "Every 12 hours": "Alle 12 Stunden", "Every 3 hours": "Alle 3 Stunden", "Every 6 hours": "Alle 6 Stunden", + "Every fail2ban jail ships disabled. Enable the ones you need in /config/fail2ban/jail.local, taking the ready-made jails in /config/fail2ban/jail.d/ as reference, then restart the container.": "Jedes fail2ban-Gefängnisschiff ist deaktiviert. Aktivieren Sie die benötigten in /config/fail2ban/jail.local, nehmen Sie die fertigen Gefängnisse in /config/fail2ban/jail.d/ als Referenz und starten Sie den Container neu.", "Every hour": "Stündlich", + "Every member of the stack is back to its previous installation.": "Jedes Mitglied des Stapels ist zurück zu seiner vorherigen Installation.", "Every path in this backup is kernel-tied: the restore applies these paths automatically via the safe-subset filter and re-merges the operator's tuning.": "Jeder Pfad in dieser Sicherung ist an den Kernel gebunden: Die Wiederherstellung wendet diese Pfade automatisch über den Safe-Subset-Filter an und führt die Optimierung des Operators erneut zusammen.", "Everything restorable in this backup will be restored": "Alles, was in diesem Backup wiederhergestellt werden kann, wird wiederhergestellt", + "Exact name of the remote": "Genauer Name der Fernbedienung", "Example output: rootfs: local-lvm:vm-114-disk-0,size=8G": "Beispielausgabe: rootfs: local-lvm:vm-114-disk-0,size=8G", "Example target: /dev/sdb": "Beispielziel: /dev/sdb", "Example: /dev/pve/vm-114-disk-0": "Beispiel: /dev/pve/vm-114-disk-0", @@ -1537,7 +1978,9 @@ "Execute destructive rollback?": "Destruktives Rollback ausführen?", "Executing destructive rollback (operator confirmed) ...": "Destruktives Rollback wird ausgeführt (Operator bestätigt) ...", "Executing:": "Ausführen:", + "Execution engine for Index-TTS": "Ausführungsmaschine für Index-TTS", "Existing Groups": "Bestehende Gruppen", + "Existing TLS certificate reused:": "Bestehendes TLS-Zertifikat wiederverwendet:", "Existing file, re-downloading...": "Vorhandene Datei, erneuter Download...", "Existing filesystem:": "Vorhandenes Dateisystem:", "Existing hostpci entries detected — they will be reused": "Vorhandene Hostpci-Einträge erkannt – sie werden wiederverwendet", @@ -1581,7 +2024,9 @@ "Extended Filesystem 4 (recommended)": "Erweitertes Dateisystem 4 (empfohlen)", "External ZFS ARC settings restored:": "Externe ZFS-ARC-Einstellungen wiederhergestellt:", "External ZFS configuration changed after the ProxMenux migration; current file and backup preserved:": "Die externe ZFS-Konfiguration wurde nach der ProxMenux-Migration geändert; aktuelle Datei und Sicherung wurden beibehalten:", + "External credential is empty or spans multiple lines": "Externes credential ist leer oder überspannt mehrere Zeilen", "External disk for backup": "Externe Festplatte zur Sicherung", + "External field not reserved:": "Externes Feld nicht reserviert:", "Extracting NVIDIA installer on host...": "NVIDIA-Installationsprogramm auf Host extrahieren...", "Extracting OVA archive...": "OVA-Archiv wird extrahiert...", "Extracting archive...": "Archiv wird extrahiert...", @@ -1592,7 +2037,9 @@ "Extraction failed. Check log:": "Die Extraktion ist fehlgeschlagen. Protokoll prüfen:", "Extraction successful": "Extraktion erfolgreich", "FAILED": "FEHLGESCHLAGEN", + "FFmpeg version the node uses (7 by default)": "FFmpeg-Version, die der Knoten verwendet (standardmäßig 7)", "FINAL CONFIRMATION — DATA WILL BE ERASED": "ENDGÜLTIGE BESTÄTIGUNG – DIE DATEN WERDEN GELÖSCHT", + "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface.": "FIleZilla Client ist ein schneller und zuverlässiger plattformübergreifender FTP-, FTPS- und SFTP-Client mit vielen nützlichen Funktionen und einer intuitiven grafischen Benutzeroberfläche.", "Fail2Ban - Intrusion Prevention": "Fail2Ban – Intrusion Prevention", "Fail2Ban Management": "Fail2Ban-Management", "Fail2Ban has been removed": "Fail2Ban wurde entfernt", @@ -1602,6 +2049,7 @@ "Fail2Ban is currently installed.": "Fail2Ban ist derzeit installiert.", "Fail2Ban is not installed on this system.": "Fail2Ban ist auf diesem System nicht installiert.", "Fail2Ban is running correctly": "Fail2Ban läuft ordnungsgemäß", + "Fail2ban is a daemon to ban hosts that cause multiple authentication errors.": "Fail2ban ist ein Daemon zum Verbot von Hosts, die mehrere Authentifizierungsfehler verursachen.", "Failed": "Fehlgeschlagen", "Failed to access log2ram directory": "Der Zugriff auf das log2ram-Verzeichnis ist fehlgeschlagen", "Failed to access share with provided credentials.": "Der Zugriff auf die Freigabe mit den angegebenen Anmeldeinformationen ist fehlgeschlagen.", @@ -1748,6 +2196,9 @@ "Failed. See log:": "Fehlgeschlagen. Siehe Protokoll:", "Falling back to each installer with --auto-reinstall...": "Zurückgreifen auf jedes Installationsprogramm mit --auto-reinstall...", "Falling back to manual paste mode.": "Zurück zum manuellen Einfügemodus.", + "Fast Usenet downloader with a SABnzbd-compatible API": "Schneller Usenet-Downloader mit SABnzbd-kompatibler API", + "Fast, modern web interface for qBittorrent": "Schnelles, modernes Webinterface für qBittorrent", + "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper.": "Faster-whisper ist eine Reimplementierung von OpenAIs Whisper-Modell mit CTranslate2, einer schnellen Inferenz-Engine für Transformer-Modelle. Dieser Container bietet einen Wyoming-Protokollserver für schnelleres Flüstern.", "Fastfetch Logo Selection": "Auswahl des Fastfetch-Logos", "Fastfetch configuration updated": "Fastfetch-Konfiguration aktualisiert", "Fastfetch download URL retrieved successfully.": "Fastfetch-Download-URL erfolgreich abgerufen.", @@ -1759,19 +2210,31 @@ "Fastfetch now displays: System optimised by: ProxMenux": "Fastfetch zeigt jetzt an: System optimiert von: ProxMenux", "Fastfetch removed from system": "Fastfetch wurde aus dem System entfernt", "Fastfetch will start automatically in the console": "Fastfetch wird automatisch in der Konsole gestartet", + "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application.": "Ferdium ist eine Desktop-App, mit der Sie organisieren können, wie Sie Ihre Lieblings-Apps verwenden, indem Sie sie in eine Anwendung integrieren.", "Fetching NVIDIA driver versions supported by your GPU...": "Von Ihrer GPU unterstützte NVIDIA-Treiberversionen werden abgerufen …", "Figurine installation and configuration completed successfully.": "Die Installation und Konfiguration der Figur wurde erfolgreich abgeschlossen.", "Figurine is not installed.": "Figur ist nicht installiert.", "Figurine removed from system": "Figur aus dem System entfernt", + "File bind mounts do not support spaces:": "File Bind Mounts unterstützen keine Spaces:", + "File processing made easy!": "Dateiverarbeitung leicht gemacht!", "File:": "Datei:", + "FileBrowser Quantum": "FileBrowser Quantum", + "FileBrowser Quantum (new installation)": "FileBrowser Quantum (Neuinstallation)", + "FileDrop is a free, open source file sharing service": "FileDrop ist ein kostenloser Open Source File Sharing Service", + "Files & Downloads": "Dateien & Downloads", + "Files volume size in GB": "Dateivolumengröße in GB", "Filesystem": "Dateisystem", "Filesystem Tools Required": "Dateisystem-Tools erforderlich", "Filesystem:": "Dateisystem:", "Final Confirmation": "Endgültige Bestätigung", + "Final cleanup of the stack operation completed": "Endgültige Bereinigung des Stacks operation abgeschlossen", "Final confirmation": "Endgültige Bestätigung", "Final storage health/status check": "Endgültige Überprüfung des Speicherzustands/-status", + "Finance & Budgeting": "Finanzen & Budgeting", "Find your device using https://finds.synology.com": "Finden Sie Ihr Gerät über https://finds.synology.com", "Fingerprint:": "Fingerabdruck:", + "Firefly, the easiest using of WireGuard VPN server, plus version of wg-easy.": "Firefly, die einfachste Verwendung von WireGuard VPN-Server, plus Version von wg-easy.", + "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards.": "Firefox Browser, auch bekannt als Mozilla Firefox oder einfach Firefox, ist ein kostenloser und Open-Source-Webbrowser, der von der Mozilla Foundation und ihrer Tochtergesellschaft, der Mozilla Corporation, entwickelt wurde. Firefox verwendet die Gecko-Layout-Engine zum Rendern von Webseiten, die aktuelle und erwartete Webstandards implementiert.", "Firewall allows port": "Firewall erlaubt Port", "Firewall settings": "Firewall-Einstellungen", "Firmware :": "Firmware:", @@ -1791,8 +2254,13 @@ "Fix systemd-boot meta-package conflict": "Beheben Sie den systemd-boot-Metapaketkonflikt", "Fix systemd-boot:": "Systemd-Boot reparieren:", "Fix: on the host, run": "Fix: Auf dem Host ausführen", + "FlexGet web interface": "FlexGet Web-Schnittstelle", + "Flexget is a multipurpose automation tool for all of your media.": "Flexget ist ein Mehrzweck-Automatisierungstool für alle Ihre Medien.", + "Flowise 3.0.1 and later create the administrator account from the web interface, the first time it is opened.": "Flowise 3.0.1 und später erstellen Sie das Administratorkonto von der Weboberfläche, wenn es zum ersten Mal geöffnet wird.", + "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast.": "Flycast ist ein Multi-Plattform Sega Dreamcast, Naomi, Naomi 2, und Atomiswave Emulator von Reicast abgeleitet.", "Folder Name": "Ordnername", "Folders in /mnt": "Ordner in /mnt", + "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics.": "Folding@home ist ein verteiltes Computerprojekt zur Simulation der Proteindynamik, einschließlich des Prozesses der Proteinfaltung und der Bewegungen von Proteinen, die an einer Vielzahl von Krankheiten beteiligt sind. Es bringt citizen-Wissenschaftler zusammen, die freiwillig Simulationen der Proteindynamik auf ihren PCs durchführen. Erkenntnisse aus diesen Daten helfen Wissenschaftlern, die Biologie besser zu verstehen, und bieten neue Möglichkeiten für die Entwicklung von Therapeutika.", "Follow post-restore progress live from ProxMenux Monitor → Backups tab after the reboot.": "Verfolgen Sie den Fortschritt nach der Wiederherstellung nach dem Neustart live über ProxMenux Monitor → Registerkarte „Backups“.", "For LVM - Create mount directory and mount:": "Für LVM – Mount-Verzeichnis erstellen und mounten:", "For ZFS, storage ID must start with a letter and use only letters, numbers, dot, dash, underscore or colon.": "Für ZFS muss die Speicher-ID mit einem Buchstaben beginnen und darf nur Buchstaben, Zahlen, Punkte, Bindestriche, Unterstriche oder Doppelpunkte enthalten.", @@ -1828,11 +2296,15 @@ "Formatting partition": "Partition formatieren", "Found": "Gefunden", "Found guest-accessible shares:": "Für Gäste zugängliche Freigaben gefunden:", + "Free and easy to use Minecraft server management tool.": "Kostenlos und einfach zu bedienen Minecraft Server-Management-Tool.", "Free public Proxmox repository enabled": "Kostenloses öffentliches Proxmox-Repository aktiviert", "Free space OK:": "Freier Speicherplatz OK:", "Free up disk space": "Geben Sie Speicherplatz frei", "Free:": "Frei:", + "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support.": "FreeCAD ist ein universeller parametrischer 3D-Computer-Aided Design (CAD)-Modellierer und eine BIM-Softwareanwendung mit Unterstützung der Finite-Elemente-Methode (FEM).", "French": "Französisch", + "Freshrss is a free, self-hostable aggregator for rss feeds.": "Freshrss ist ein kostenloser, selbstgehosteter Aggregator für rss-Feeds.", + "Frigate WebUI": "Frigate WebUI", "Full SMART Report": "Vollständiger SMART-Bericht", "Full SMART info and attributes": "Vollständige SMART-Informationen und -Attribute", "Full format — new GPT partition + filesystem": "Vollformat – neue GPT-Partition + Dateisystem", @@ -1845,6 +2317,7 @@ "Function Level Reset (FLR) not available": "Function Level Reset (FLR) nicht verfügbar", "GID already in use:": "GID bereits verwendet:", "GID in CT": "GID im CT", + "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable.": "GIMP ist ein kostenloser und Open-Source-Raster-Grafikeditor, der für Bildmanipulation (Retusche) und Bildbearbeitung, Freiformzeichnung, Transcodierung zwischen verschiedenen Bilddateiformaten und spezialisiertere Aufgaben verwendet wird. Es ist durch Plugins erweiterbar und skriptfähig.", "GPU": "GPU", "GPU -> VM Mode Detected": "GPU -> VM-Modus erkannt", "GPU Already Added": "GPU bereits hinzugefügt", @@ -1870,6 +2343,7 @@ "GPU already present in target VM — existing hostpci entry reused": "GPU bereits in der Ziel-VM vorhanden – vorhandener Hostpci-Eintrag wiederverwendet", "GPU audio added": "GPU-Audio hinzugefügt", "GPU audio already present in target VM — existing hostpci entry reused": "GPU-Audio ist bereits in der Ziel-VM vorhanden – vorhandener Hostpci-Eintrag wiederverwendet", + "GPU available for machine learning:": "GPU für Machine Learning verfügbar:", "GPU driver blacklisted": "GPU-Treiber auf der schwarzen Liste", "GPU guard hook will block concurrent start when another VM is already using this GPU": "Der GPU-Guard-Hook blockiert den gleichzeitigen Start, wenn eine andere VM diese GPU bereits verwendet", "GPU host driver blacklisted in /etc/modprobe.d/blacklist.conf": "GPU-Hosttreiber auf der schwarzen Liste in /etc/modprobe.d/blacklist.conf", @@ -1885,11 +2359,14 @@ "GPU passthrough to VMs requires IOMMU to be enabled in the kernel.": "GPU-Passthrough zu VMs erfordert die Aktivierung von IOMMU im Kernel.", "GPU passthrough was not applied.": "GPU-Passthrough wurde nicht angewendet.", "GPU passthrough was skipped (no compatible GPU detected).": "GPU-Passthrough wurde übersprungen (keine kompatible GPU erkannt).", + "GPU recognition uses 8 GB of RAM and a limit of 4 CPU equivalents. These resources were tested in the lab and are not a universal minimum. Compatibility depends on the GPU, the models and the kernel. NVIDIA uses the GPUs of the Toolkit inventory; Intel keeps the CPU topology.": "Die GPU-Erkennung verwendet 8 GB RAM und ein Limit von 4 CPU equivalenten. Diese Ressourcen wurden im Labor getestet und sind kein universelles Minimum. Die Kompatibilität hängt von der GPU, den Modellen und dem Kernel ab. NVIDIA verwendet die GPUs des Toolkit-Inventars; Intel behält die CPU-Topologie.", "GPU removed from VM": "GPU von VM entfernt", "GPU removed from VM config": "GPU aus VM-Konfiguration entfernt", + "GPU render device": "GPU-Renderingvorrichtung", "GPU switch complete: LXC mode prepared.": "GPU-Umstellung abgeschlossen: LXC-Modus vorbereitet.", "GPU switch complete: VM mode prepared.": "GPU-Umstellung abgeschlossen: VM-Modus vorbereitet.", "GPU switch mode completed. No reboot required.": "GPU-Umschaltmodus abgeschlossen. Kein Neustart erforderlich.", + "GPU verified:": "GPU verifiziert:", "GPU will be removed from source VM config": "Die GPU wird aus der Quell-VM-Konfiguration entfernt", "GPU will remain configured in source VM": "Die GPU bleibt in der Quell-VM konfiguriert", "GPU/TPU - Manual CLI Guide": "GPU/TPU – Manueller CLI-Leitfaden", @@ -1899,6 +2376,8 @@ "GRUB configuration updated": "GRUB-Konfiguration aktualisiert", "GRUB_CMDLINE_LINUX_DEFAULT not found in GRUB config": "GRUB_CMDLINE_LINUX_DEFAULT wurde in der GRUB-Konfiguration nicht gefunden", "GUI mode (if available)": "GUI-Modus (falls verfügbar)", + "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities.": "GZDoom ist ein funktionsorientierter Port für alle Doom-Engine-Spiele, basierend auf ZDoom, der einen OpenGL-Renderer und leistungsstarke Skriptfunktionen hinzufügt.", + "Gaming & Leisure": "Gaming & Leisure", "Gateway is not installed.": "Gateway ist nicht installiert.", "Gateway removed.": "Gateway entfernt.", "Gateway restarted.": "Gateway neu gestartet.", @@ -1908,19 +2387,32 @@ "Generate a new key and authorize it on the server automatically (recommended)": "Einen neuen Schlüssel generieren und automatisch auf dem Server autorisieren (empfohlen)", "Generate a new key, show me the line to paste manually": "Erzeugen Sie einen neuen Schlüssel und zeigen Sie mir die Zeile, die manuell eingefügt werden soll", "Generate a new keyfile": "Erzeugen Sie eine neue Schlüsseldatei", + "Generated Paperless administrator": "Generierter papierloser Administrator", + "Generated Tandoor administrator": "Tandoor-Administrator generiert", + "Generated administrator login": "Generierte Administrator-Login", "Generating OVF descriptor...": "OVF-Deskriptor wird generiert...", "Generating dkms.conf...": "dkms.conf wird generiert...", "Generating manifest...": "Manifest wird erstellt...", "Generating missing locale:": "Fehlendes Gebietsschema wird generiert:", + "Generic SCSI device associated with the drive (e.g. /dev/sg2)": "Generisches SCSI-Gerät, das dem Laufwerk zugeordnet ist (z. B. /dev/sg2)", "German": "Deutsch", "Get a list of all your containers:": "Erhalten Sie eine Liste aller Ihrer Container:", "Get the actual disk path:": "Ermitteln Sie den tatsächlichen Festplattenpfad:", "Get the container's storage information:": "Rufen Sie die Speicherinformationen des Containers ab:", + "Get up and running with large language models locally": "Aufstehen und Laufen mit großen Sprachmodellen lokal", "Git installed": "Git installiert", + "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality.": "GitQlient ist eine Multi-Plattform Git-Client ursprünglich forked von QGit. Heutzutage geht es über nur einen fork hinaus und fügt viele neue Funktionen hinzu.", + "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React.": "Github Desktop ist eine Open Source Electron-basierte GitHub App. Es ist in TypeScript geschrieben und verwendet React.", "Global settings and SSH jail configured": "Globale Einstellungen und SSH-Gefängnis konfiguriert", + "Gluetun/VPN not yet available: this suite does not route downloads through a VPN.": "Gluetun/VPN noch nicht verfügbar: Diese Suite führt keine Downloads über ein VPN weiter.", "Go to \"Manage custom paths\" and remove your custom entry that includes the destination": "Gehen Sie zu „Benutzerdefinierte Pfade verwalten“ und entfernen Sie Ihren benutzerdefinierten Eintrag, der das Ziel enthält", "Google only ships an official libedgetpu APT repository for Debian/Ubuntu. Hardware passthrough is already written to": "Google liefert nur ein offizielles libedgetpu APT-Repository für Debian/Ubuntu. Auf Hardware-Passthrough wurde bereits geschrieben", "Graceful shutdown timed out.": "Zeitüberschreitung beim ordnungsgemäßen Herunterfahren.", + "Grafana is a complete observability stack that allows you to monitor and analyze metrics, logs and traces. It allows you to query, visualize, alert on and understand your data no matter where it is stored.": "Grafana ist ein vollständiger Observability Stack, mit dem Sie Metriken, Protokolle und Traces überwachen und analysieren können. Es ermöglicht Ihnen, Ihre Daten abzufragen, zu visualisieren, zu warnen und zu verstehen, unabhängig davon, wo sie gespeichert sind.", + "Grafana web interface": "Grafana Web-Schnittstelle", + "Grav is a Fast, Simple, and Flexible, file-based Web-platform.": "Grav ist eine schnelle, einfache und flexible dateibasierte Web-Plattform.", + "Grocy (new installation; restored data keeps its credentials)": "Grocy (neue Installation; wiederhergestellte Daten behalten ihre credentials)", + "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility.": "Grocy ist ein ERP-System für Ihre Küche! Reduzieren Sie Lebensmittelabfälle und verwalten Sie Ihre Aufgaben mit diesem brillanten Dienstprogramm.", "Group": "Gruppe", "Group 'sharedfiles' already exists inside the CT": "Die Gruppe „sharedfiles“ existiert bereits im CT", "Group GID:": "Gruppen-GID:", @@ -1953,23 +2445,57 @@ "Guided Repair Available": "Geführte Reparatur verfügbar", "HA groups will be migrated to HA rules automatically": "HA-Gruppen werden automatisch zu HA-Regeln migriert", "HA services disabled (configs preserved)": "HA-Dienste deaktiviert (Konfigurationen bleiben erhalten)", + "HAOS One is a community image that runs Docker inside the container. The LXC stays unprivileged, but the inner AppArmor profiles may not be available. The first start downloads Home Assistant Core and its add-ons. If the check fails, the CT and /mnt/data are kept for diagnosis.": "HAOS One ist ein Community-Image, das Docker im Container ausführt. Der LXC bleibt unprivilegiert, aber die inneren AppArmor-Profile sind möglicherweise nicht verfügbar. Der erste Start lädt Home Assistant Core und seine Add-ons herunter. Wenn die Überprüfung fehlschlägt, werden die CT und / mnt / Daten zur Diagnose aufbewahrt.", + "HAOS One profile declined": "HAOS One-Profil rückläufig", + "HAOS One requires an unprivileged unmanaged LXC with nesting and keyctl, 2 cores, 2048 MB RAM, rootfs of at least 12 GB and /mnt/data of at least 16 GB on a container volume included in backups": "HAOS One requires ein unprivilegiertes unmanaged LXC mit Nesting und Keyctl, 2 Kernen, 2048 MB RAM, Rootfs von mindestens 12 GB und /mnt / Daten von mindestens 16 GB auf einem Containervolumen, das in Backups enthalten ist", + "HTTP service check without a saved URL": "HTTP Service Check ohne gespeicherte URL", + "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API.": "Habridge emuliert Philips Hue API zu anderen Home Automation Gateways wie einem Amazon Echo / Dot Gen 1 (Gen 2 hat Probleme bei der Erkennung von Ha-Bridge) oder anderen Systemen, die Philips Hue unterstützen. Die Bridge verarbeitet grundlegende Befehle wie Ein-, Aus- und Helligkeitsbefehle des Farbtonprotokolls. Diese Brücke kann die meisten Geräte mit einer bestimmten API steuern.", + "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs.": "HandBrake ist ein Open-Source-Tool, das von Freiwilligen entwickelt wurde, um Videos aus fast jedem Format in eine Auswahl moderner, weithin unterstützter Codecs zu konvertieren.", "Hardening SSH: setting MaxAuthTries to 3...": "SSH härten: MaxAuthTries auf 3 setzen ...", + "Hardware acceleration for Emby": "Hardware-Beschleunigung für Emby", + "Hardware acceleration for FileFlows": "Hardware-Beschleunigung für FileFlows", + "Hardware acceleration for Frigate": "Hardware-Beschleunigung für Frigate", + "Hardware acceleration for Jellyfin": "Hardware-Beschleunigung für Jellyfin", + "Hardware acceleration for Plex": "Hardware-Beschleunigung für Plex", + "Hardware acceleration for Roon Server": "Hardware-Beschleunigung für Roon Server", + "Hardware acceleration for Stremio": "Hardware-Beschleunigung für Stremio", + "Hardware acceleration for Tdarr": "Hardware-Beschleunigung für Tdarr", + "Hardware acceleration options:": "Hardware-Beschleunigungsoptionen:", "Hardware compatibility — these items will be skipped to keep the boot safe:": "Hardwarekompatibilität – diese Elemente werden übersprungen, um den Start zu gewährleisten:", "Hardware passthrough is already configured — the Coral device is visible inside the container as /dev/apex_0 (M.2) and/or /dev/bus/usb (USB).": "Hardware-Passthrough ist bereits konfiguriert – das Coral-Gerät ist im Container als /dev/apex_0 (M.2) und/oder /dev/bus/usb (USB) sichtbar.", "Hardware: GPUs and Coral-TPU": "Hardware: GPUs und Coral-TPU", + "Have a Private Social Space Hosted on Your Site": "Haben Sie einen privaten sozialen Raum auf Ihrer Website gehostet", "Have valid backups of all VMs and containers": "Verfügen Sie über gültige Backups aller VMs und Container", + "Health check failed:": "Gesundheitscheck fehlgeschlagen:", + "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface.": "Healthchecks ist ein Watchdog für Ihre Cron Jobs. Es ist ein Webserver, der auf Pings von Ihren Cron-Jobs hört, sowie eine Weboberfläche.", + "HedgeDoc gives you access to all your files wherever you are.": "HedgeDoc bietet Ihnen Zugriff auf alle Ihre Dateien, wo immer Sie sind.", + "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way.": "Heimdall ist eine Möglichkeit, all diese Links zu Ihren am häufigsten verwendeten Websites und Webanwendungen auf einfache Weise zu organisieren.", + "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking.": "Helium ist ein Chromium-basierter Webbrowser für Menschen mit Liebe. Privacy-first mit unvoreingenommenem Ad-Blocking.", "Help & Info (commands)": "Hilfe & Info (Befehle)", "Help & Information": "Hilfe und Informationen", "Help and Info": "Hilfe und Informationen", "Help and Info Commands": "Hilfe- und Infobefehle", "Helper-Scripts logo applied": "Helper-Scripts-Logo angewendet", + "Hermes WebUI": "Hermes WebUI", "Hidden for safety": "Aus Sicherheitsgründen versteckt", "Hidden:": "Versteckt:", "High Availability services have been enabled successfully": "Hochverfügbarkeitsdienste wurden erfolgreich aktiviert", "High Availability setup completed": "Hochverfügbarkeitseinrichtung abgeschlossen", + "High availability resources are not supported by this profile": "Hochverfügbarkeitsressourcen werden von diesem Profil nicht unterstützt", + "High availability resources are not supported for stacks": "Hochverfügbarkeitsressourcen werden für Stacks nicht unterstützt", "High risk confirmation": "Bestätigung mit hohem Risiko", "High-Risk GPU Power State": "GPU-Energiezustand mit hohem Risiko", + "Home Assistant": "Home Assistant", + "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server": "Home Assistant Core - Open-Source-Hausautomation, bei der lokale Kontrolle und Datenschutz an erster Stelle stehen. Angetrieben von einer weltweiten Gemeinschaft von Tüftlern und DIY-Enthusiasten. Perfekt zum Laufen auf einem Raspberry Pi oder einem lokalen Server", + "Home Assistant OS cannot be checked without an IP address": "Home Assistant OS kann ohne IP-Adresse nicht überprüft werden", + "Home Assistant OS did not pass the Supervisor, Core and Observer checks": "Home Assistant OS hat die Supervisor-, Core- und Beobachterprüfungen nicht bestanden", + "Home Assistant OS ready: Supervisor, Core and Observer running": "Home Assistant OS ready: Supervisor, Core und Observer laufen", + "Home Assistant OS was not started: its addresses will be known once Core is running.": "Home Assistant OS wurde nicht gestartet: seine Adressen werden bekannt sein, sobald Core ausgeführt wird.", + "Home Assistant Observer": "Home Assistant Beobachter", + "Home Automation systems": "Home Automation Systeme", "Home-Lab-Club logo applied": "Logo des Home-Lab-Clubs angebracht", + "HomeKit support for the impatient.": "HomeKit Unterstützung für Ungeduldige.", + "Homebridge UI": "Homebridge UI", "Host": "Gastgeber", "Host Backup → Borg": "Host-Backup → Borg", "Host Backup → Local archive": "Host-Backup → Lokales Archiv", @@ -1978,6 +2504,7 @@ "Host Config Backup": "Sicherung der Hostkonfiguration", "Host Config Backup / Restore": "Sicherung/Wiederherstellung der Host-Konfiguration", "Host Config Restore": "Wiederherstellung der Hostkonfiguration", + "Host DVB tuners": "Host DVB-Tuner", "Host Directory": "Hostverzeichnis", "Host Directory to LXC Mount Point": "Hostverzeichnis zum LXC-Mountpunkt", "Host Directory:": "Hostverzeichnis:", @@ -1985,18 +2512,37 @@ "Host GPU detected": "Host-GPU erkannt", "Host GPU is already bound to vfio-pci. Host reconfiguration/reboot should not be required for this VM-to-VM reassignment.": "Die Host-GPU ist bereits an vfio-pci gebunden. Für diese VM-zu-VM-Neuzuweisung sollte keine Host-Neukonfiguration/Neustart erforderlich sein.", "Host IP": "Host-IP", + "Host Management": "Host Management", "Host Mount Path": "Host-Mount-Pfad", "Host NFS/Samba as Proxmox Storage (pvesm)": "NFS/Samba als Proxmox-Speicher hosten (pvesm)", "Host Path": "Hostpfad", "Host Path:": "Hostpfad:", "Host Storage (NFS / Samba via Proxmox)": "Hostspeicher (NFS / Samba über Proxmox)", + "Host USB bus": "Host USB Bus", "Host VFIO config was already up to date — no reboot needed.": "Die Host-VFIO-Konfiguration war bereits auf dem neuesten Stand – kein Neustart erforderlich.", "Host VFIO configuration already up to date": "Host-VFIO-Konfiguration bereits auf dem neuesten Stand", "Host VFIO configuration changed (initramfs updated). Reboot required before starting the VM.": "Host-VFIO-Konfiguration geändert (initramfs aktualisiert). Vor dem Starten der VM ist ein Neustart erforderlich.", "Host VFIO configuration changed — reboot required before starting the VM.": "Host-VFIO-Konfiguration geändert – Neustart erforderlich, bevor die VM gestartet wird.", "Host already in VFIO mode — skipping host reconfiguration for VM reassignment": "Host bereits im VFIO-Modus – Host-Neukonfiguration für VM-Neuzuweisung wird übersprungen", + "Host audio devices": "Host-Audiogeräte", "Host backup attached to PVE job": "Host-Backup an PVE-Job angehängt", + "Host data is not restored by the backup; confirm it with --acknowledge-external-data": "Host-Daten werden nicht durch das Backup wiederhergestellt; bestätigen Sie es mit --acknowledge-external-data", + "Host device for /dev/kvm": "Host-Gerät für /dev/kvm", + "Host device for /dev/net/tun": "Host-Gerät für /dev/net/tun", + "Host device for /dev/ttyUSB0": "Host-Gerät für /dev/ttyUSB0", + "Host device for /dev/video10": "Host-Gerät für /dev/video10", + "Host device for /dev/video11": "Host-Gerät für /dev/video11", + "Host device for /dev/video12": "Host-Gerät für /dev/video12", + "Host device node": "Hostvorrichtungsknoten", + "Host directories are not included in the backup and are not reverted by a recovery.": "Host-Verzeichnisse sind nicht im Backup enthalten und werden nicht durch eine Wiederherstellung rückgängig gemacht.", + "Host directories are not included in the backups and are not reverted by a recovery.": "Host-Verzeichnisse sind nicht in den Backups enthalten und werden nicht durch eine Wiederherstellung rückgängig gemacht.", + "Host directories cannot be part of the vzdump backup": "Hostverzeichnisse können nicht Teil des vzdump-Backups sein", + "Host directories that are kept, with their content:": "Host-Verzeichnisse, die geführt werden, mit ihrem Inhalt:", + "Host directory": "Hostverzeichnis", + "Host directory (created if it does not exist)": "Host-Verzeichnis (erstellt, wenn es nicht existiert)", + "Host directory (not included in Proxmox backups)": "Hostverzeichnis (nicht in Proxmox-Backups enthalten)", "Host directory access for unprivileged containers has been prepared above": "Der Host-Verzeichniszugriff für unprivilegierte Container wurde oben vorbereitet", + "Host directory kept, with its content:": "Host-Verzeichnis mit seinem Inhalt:", "Host directory permissions updated — unprivileged containers can now access it": "Host-Verzeichnisberechtigungen aktualisiert – nicht privilegierte Container können jetzt darauf zugreifen", "Host directory:": "Hostverzeichnis:", "Host fstab CIFS Mounts:": "Host fstab CIFS-Mounts:", @@ -2008,7 +2554,14 @@ "Host fstab NFS mounts:": "Host-fstab-NFS-Mounts:", "Host fstab mounts (not registered as Proxmox storage):": "Host-fstab-Mounts (nicht als Proxmox-Speicher registriert):", "Host identity (hostname, hosts)": "Hostidentität (Hostname, Hosts)", + "Host kernel module loaded:": "Hostkernel-Modul geladen:", + "Host monitor configured: shared PID and network namespaces, LXCFS disabled in this container": "Host-Monitor konfiguriert: freigegebene PID und Netzwerk-Namespaces, LXCFS in diesem Container deaktiviert", + "Host monitor verified: PID and network namespaces and memory match the host": "Host-Monitor verifiziert: PID und Netzwerk-Namespaces und Speicher stimmen mit dem Host überein", + "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks.": "Host-Monitor: gemeinsame PID/Netzwerk und privilegierter Zugriff. Ein kompromittiertes Bild könnte Proxmox beeinflussen. Verwenden Sie nur in vertrauenswürdigen Netzwerken.", + "Host monitoring declined": "Host-Monitoring rückläufig", + "Host path for": "Host Path für", "Host permissions applied (o+rwx + default ACL) — unprivileged LXCs can read/write through bind-mounts": "Angewandte Host-Berechtigungen (o+rwx + Standard-ACL) – nicht privilegierte LXCs können über Bind-Mounts lesen/schreiben", + "Host system path": "Hostsystempfad", "Host write access confirmed.": "Host-Schreibzugriff bestätigt.", "Hostname": "Hostname", "Hot changes applied. No reboot needed for these paths.": "Heiße Änderungen angewendet. Für diese Pfade ist kein Neustart erforderlich.", @@ -2020,12 +2573,18 @@ "How do you want to select the Samba server?": "Wie möchten Sie den Samba-Server auswählen?", "How do you want to select the folder to export?": "Wie möchten Sie den zu exportierenden Ordner auswählen?", "How do you want to select the folder to share?": "Wie möchten Sie den Ordner zur Freigabe auswählen?", + "How is it installed?": "Wie wird es installiert?", + "How is the image described?": "Wie wird das Bild beschrieben?", "How to Access an LXC Terminal": "So greifen Sie auf ein LXC-Terminal zu", "How to Access an LXC Terminal from Proxmox Host": "So greifen Sie vom Proxmox-Host auf ein LXC-Terminal zu", "How to schedule": "So planen Sie", + "Htpcmanager is a front end for many htpc related applications.": "Htpcmanager ist ein Frontend für viele htpc-bezogene Anwendungen.", "I have read this": "Ich habe das gelesen", "I/O priority configured": "E/A-Priorität konfiguriert", "ID already in use. Please choose another.": "ID bereits verwendet. Bitte wählen Sie eine andere.", + "IGDB": "IGDB", + "IGDB Client ID": "IGDB-Kunden-ID", + "IGDB Client Secret": "IGDB-Kundengeheimnis", "IMPORTANT": "WICHTIG", "IMPORTANT NOTES:": "WICHTIGE HINWEISE:", "IMPORTANT PREREQUISITES:": "WICHTIGE VORAUSSETZUNGEN:", @@ -2062,7 +2621,14 @@ "IOMMU was configured during this wizard and a reboot is pending.": "IOMMU wurde während dieses Assistenten konfiguriert und ein Neustart steht aus.", "IOMMU/VFIO configuration reverted": "IOMMU/VFIO-Konfiguration wurde zurückgesetzt", "IP": "IP", + "IP address": "IP-Adresse", + "IP address and firewall of the host": "IP-Adresse und Firewall des Hosts", + "IP address of this container for the certificate (0.0.0.0 if unknown)": "IP-Adresse dieses Containers für das Zertifikat (0.0.0.0, falls unbekannt)", + "IP address:": "IP-Adresse:", "IP or hostname of the PVE node hosting the Borg server LXC:": "IP oder Hostname des PVE-Knotens, der den Borg-Server LXC hostet:", + "IPv4 address of the container": "IPv4-Adresse des Containers", + "IPv4 address of the containers": "IPv4-Adresse der Container", + "IPv4 gateway (empty = no outbound route)": "IPv4-Gateway (leer = keine ausgehende Route)", "ISO": "ISO", "ISO created successfully:": "ISO erfolgreich erstellt:", "ISO image — installation images": "ISO-Image – Installationsimages", @@ -2095,6 +2661,7 @@ "If this happens, you can restore the backup from the 'Subscription Banner Removal' option in 'Uninstall optimizations'.": "In diesem Fall können Sie die Sicherung über die Option „Entfernung des Abonnementbanners“ unter „Optimierungen deinstallieren“ wiederherstellen.", "If this node runs hyper-converged Ceph: ensure Ceph is 19.x (Squid) BEFORE upgrading PVE.": "Wenn dieser Knoten hyperkonvergentes Ceph ausführt: Stellen Sie sicher, dass Ceph 19.x (Squid) ist, BEVOR Sie PVE aktualisieren.", "If upgrade fails:": "Wenn das Upgrade fehlschlägt:", + "If you answer No, Glances is installed without privileges and monitors ONLY its own LXC, not Proxmox.": "Wenn Sie Nein antworten, wird Glances ohne Privilegien installiert und überwacht NUR seinen eigenen LXC, nicht Proxmox.", "If you are sure you want to use it, please remove the": "Wenn Sie sicher sind, dass Sie es verwenden möchten, entfernen Sie bitte das", "If you choose No, install": "Wenn Sie „Nein“ wählen, installieren Sie es", "If you continue, some adjustments may be duplicated or conflict with those already made by xshok.": "Wenn Sie fortfahren, werden möglicherweise einige Anpassungen dupliziert oder stehen in Konflikt mit den bereits von xshok vorgenommenen.", @@ -2104,11 +2671,30 @@ "If you want HDMI/analog audio inside the VM, select the audio controller(s) to pass through along with the GPU.": "Wenn Sie HDMI/analoges Audio innerhalb der VM wünschen, wählen Sie die Audio-Controller aus, die zusammen mit der GPU weitergeleitet werden sollen.", "If you want to use a physical monitor on the passthrough GPU:": "Wenn Sie einen physischen Monitor auf der Passthrough-GPU verwenden möchten:", "If your DHCP has a static reservation for the old MAC, update it.": "Wenn Ihr DHCP eine statische Reservierung für den alten MAC hat, aktualisieren Sie diese.", + "Image": "Bild", "Image Source Directory": "Bildquellenverzeichnis", + "Image cache": "Bild-Cache", + "Image compatibility restored:": "Bildkompatibilität wiederhergestellt:", + "Image compatibility verified:": "Verifizierte Bildkompatibilität:", "Image directory:": "Bildverzeichnis:", + "Image download failed:": "Bild-Download fehlgeschlagen:", + "Image downloaded": "Bild heruntergeladen", "Image file not found:": "Bilddatei nicht gefunden:", "Image imported:": "Bild importiert:", + "Image integrity verified": "Überprüfung der Integrität des Bildes", + "Image not allowed for the host monitor profile": "Bild nicht erlaubt für das Host-Monitor-Profil", + "Image reference (for example ghcr.io/user/application:latest)": "Bildreferenz (z. B. ghcr.io/user/application:latest)", + "Image that is not in the catalog": "Bild, das nicht im Katalog enthalten ist", + "Image:": "Bild:", "Images to import:": "Zu importierende Bilder:", + "Immich CUDA requires NVIDIA driver 545 or later": "Immich CUDA requires NVIDIA Treiber 545 oder höher", + "Immich GPU profile not validated": "Immich GPU-Profil nicht validiert", + "Immich configuration cancelled": "Immich-Konfiguration gestrichen", + "Immich device without a validated translation": "Immich-Gerät ohne validierte Übersetzung", + "Immich machine learning": "Immich Maschinelles Lernen", + "Immich requires CUDA compute capability 5.2 or later": "Immich requires CUDA Rechenfähigkeit 5.2 oder höher", + "Immich runtime without a validated translation": "Immich Laufzeit ohne validierte Übersetzung", + "Immich server": "Immich-Server", "Import — disk image imports": "Importieren – Disk-Image-Importe", "Import Disk Image to VM": "Disk-Image in VM importieren", "Import Disk to LXC": "Datenträger in LXC importieren", @@ -2149,24 +2735,58 @@ "Incompatible Reset Capability for Intel GPU": "Inkompatible Reset-Funktion für Intel-GPU", "Incompatible Reset Capability for Intel dGPU": "Inkompatible Reset-Funktion für Intel dGPU", "Incompatible archive": "Inkompatibles Archiv", + "Incompatible image platform": "Inkompatible Bildplattform", + "Incompatible instance directory": "Inkompatibles Instanzverzeichnis", + "Incompatible instance record": "Inkompatible Instanzdaten", + "Incompatible record": "Inkompatible Aufzeichnung", + "Incompatible stack assembly": "Inkompatible Stapelanordnung", "Incompatible version": "Inkompatible Version", + "Incomplete NVIDIA identity": "Unvollständige NVIDIA-Identität", + "Incomplete NVIDIA inventory": "Unvollständiges NVIDIA-Inventar", + "Incomplete Proxmox inventory": "Unvollständiges Proxmox-Inventar", + "Incomplete Proxmox inventory; recovery blocked": "Unvollständiges Proxmox-Inventar; Rückgewinnung blockiert", + "Incomplete container removed:": "Unvollständiger Behälter entfernt:", + "Incomplete dependency order": "Unvollständige Abhängigkeitsordnung", + "Incomplete file recipe or unknown paths": "Unvollständiges Dateirezept oder unbekannte Pfade", + "Incomplete gzip layer": "Unvollständige Gzip-Schicht", + "Incomplete or incompatible Proxmox inventory": "Unvollständiges oder inkompatibles Proxmox-Inventar", + "Incomplete primary network": "Unvollständiges Primärnetz", + "Incomplete stack order": "Unvollständiger Stapelauftrag", + "Incomplete stack removed": "Unvollständiger Stapel entfernt", + "Inconsistent adaptation profile and recipe": "Inkonsistentes Anpassungsprofil und Rezept", + "Inconsistent host monitor profile": "Inkonsistentes Hostmonitor-Profil", + "Inconsistent stack identity": "Inkonsistente Stapelidentität", + "Inconsistent stack membership for": "Inkonsistente Stack-Mitgliedschaft für", "Increase container RAM temporarily to": "Erhöhen Sie den Container-RAM vorübergehend auf", "Increase file and process limits for advanced workloads": "Erhöhen Sie die Datei- und Prozesslimits für erweiterte Workloads", "Increase various system limits": "Verschiedene Systemgrenzen erhöhen", "Increase vzdump backup speed": "Erhöhen Sie die Backup-Geschwindigkeit von vzdump", "Increasing maximum file system open files...": "Die maximale Anzahl geöffneter Dateien im Dateisystem wird erhöht...", "Increasing various system limits...": "Verschiedene Systemgrenzen erhöhen...", + "Independent LXC applications installed": "Unabhängige LXC-Anwendungen installiert", + "Independent LXCs: no main container or hookscript. Each one keeps its own Start with Proxmox setting.": "Unabhängige LXCs: kein Hauptcontainer oder Hookscript. Jeder behält seinen eigenen Start mit Proxmox-Einstellung.", + "Independent applications, without a main container.": "Unabhängige Anwendungen, ohne Hauptcontainer.", + "Indexers and quality profiles still need to be configured.": "Indexer und Qualitätsprofile müssen noch konfiguriert werden.", "Inherited retention:": "Geerbte Aufbewahrung:", "Inherited schedule:": "Geerbter Zeitplan:", + "Initial Nextcloud administrator": "Erster Nextcloud-Administrator", + "Initial Nextcloud settings applied": "Erste Nextcloud-Einstellungen", + "Initial Paperless-ngx administrator": "Erster Paperless-ngx-Administrator", + "Initial Tandoor administrator": "Initial Tandoor Administrator", + "Initial administrator created:": "Erster Administrator erstellt:", + "Initial administrator user": "Erster Administrator", "Initializing Borg repository if needed...": "Initialisierung des Borg-Repositorys bei Bedarf ...", "Initiator IQN is authorised on the target": "Der Initiator-IQN ist auf dem Ziel autorisiert", "Initiator IQN:": "Initiator-IQN:", + "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers.": "Inkscape ist professionelle Qualitätsvektor-Grafiksoftware, die auf Linux, Mac OS X und Windows Desktop-Computern läuft.", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN": "Erstellen Sie im LXC den Administrator: Konsole kimai:user:creat YOUR USERNAME YOUR EMAIL ROLE SUPER ADMIN", "Inspect disks before any action": "Überprüfen Sie die Datenträger vor jeder Aktion", "Inspect host device nodes": "Untersuchen Sie die Host-Geräteknoten", "Inspect passthrough/kernel events": "Überprüfen Sie Passthrough-/Kernel-Ereignisse", "Inspect storage config block:": "Überprüfen Sie den Speicherkonfigurationsblock:", "Inspection commands run directly. Template commands [T] require parameter substitution.": "Inspektionsbefehle werden direkt ausgeführt. Vorlagenbefehle [T] erfordern eine Parameterersetzung.", "Install": "Installieren", + "Install (experimental)": "Installieren (experimentell)", "Install ALL utilities": "Installieren Sie ALLE Dienstprogramme", "Install AMD GPU drivers inside the guest.": "Installieren Sie AMD-GPU-Treiber im Gast.", "Install CIFS client packages inside CT:": "Installieren Sie CIFS-Client-Pakete in CT:", @@ -2185,6 +2805,7 @@ "Install Samba inside CT:": "Installieren Sie Samba in CT:", "Install ZFS auto-snapshot": "ZFS-Auto-Snapshot installieren", "Install a version from the branch the kernel names.": "Installieren Sie eine Version aus dem Zweig der Kernelnamen.", + "Install an image that is not in the catalog": "Installieren Sie ein Bild, das sich nicht im Katalog befindet", "Install analysis tools": "Analysetools installieren", "Install and configure": "Installieren und konfigurieren", "Install and configure Fastfetch": "Fastfetch installieren und konfigurieren", @@ -2203,27 +2824,35 @@ "Install server packages inside CT:": "Installieren Sie Serverpakete in CT:", "Install terminal multiplexers": "Installieren Sie Terminal-Multiplexer", "Install the Edge TPU runtime (libedgetpu1-std)": "Installieren Sie die Edge TPU-Laufzeit (libedgetpu1-std).", + "Install this image?": "Installieren Sie dieses Bild?", "Install with Cloud-Init script": "Installation mit Cloud-Init-Skript", "Install with ISO from UUP Dump": "Mit ISO von UUP Dump installieren", + "Install with advanced settings": "Installieren mit erweiterten Einstellungen", + "Install with default settings": "Installieren mit Standardeinstellungen", "Install with personal ISO": "Mit persönlicher ISO installieren", + "Install with this configuration?": "Installieren Sie mit dieser Konfiguration?", "Install with traditional method": "Mit herkömmlicher Methode installieren", "Install with: apt-get install open-iscsi": "Installieren mit: apt-get install open-iscsi", "Install/Update Coral TPU on Host": "Coral TPU auf dem Host installieren/aktualisieren", "Install/Update NVIDIA Drivers (Host + LXC)": "NVIDIA-Treiber installieren/aktualisieren (Host + LXC)", "Installation Complete": "Installation abgeschlossen", + "Installation completed": "Installation abgeschlossen", "Installation completed.": "Installation abgeschlossen.", "Installation completed. Please reboot the server manually as soon as possible.": "Installation abgeschlossen. Bitte starten Sie den Server so schnell wie möglich manuell neu.", "Installation completed. Press Enter to continue...": "Installation abgeschlossen. Drücken Sie die Eingabetaste, um fortzufahren...", "Installation failed": "Die Installation ist fehlgeschlagen", "Installation finished but drivers are not loaded. A reboot may be required.": "Die Installation ist abgeschlossen, aber die Treiber sind nicht geladen. Möglicherweise ist ein Neustart erforderlich.", + "Installation incomplete. These containers and their data are kept:": "Installation unvollständig. Diese Container und ihre Daten werden aufbewahrt:", "Installation log:": "Installationsprotokoll:", "Installation summary": "Zusammenfassung der Installation", "Installed": "Installiert", "Installed at:": "Installiert unter:", "Installed components:": "Installierte Komponenten:", + "Installed:": "Installiert:", "Installer already downloaded and verified.": "Das Installationsprogramm wurde bereits heruntergeladen und überprüft.", "Installer copied to container.": "Installer in Container kopiert.", "Installer downloaded.": "Installer heruntergeladen.", + "Installer file not found:": "Installer-Datei nicht gefunden:", "Installer finished with errors.": "Installationsprogramm mit Fehlern abgeschlossen.", "Installer not found:": "Installationsprogramm nicht gefunden:", "Installing": "Installieren", @@ -2274,9 +2903,14 @@ "Installing pigz...": "Pigz wird installiert...", "Installing required dependencies...": "Erforderliche Abhängigkeiten werden installiert...", "Installing required package: git": "Erforderliches Paket installieren: git", + "Installing required packages...": "Installieren von required-Paketen...", "Installing required tools...": "Erforderliche Tools werden installiert...", "Installing selected utilities": "Ausgewählte Dienstprogramme installieren", "Installing system utilities...": "Systemdienstprogramme werden installiert...", + "Installing the new image": "Installieren des neuen Images", + "Installing the new image...": "Das neue Image installieren...", + "Installing the new image:": "Installieren des neuen Images:", + "Installing the stack startup hook...": "Installieren Sie den Stack Startup Hook ...", "Installing zfs-auto-snapshot package...": "ZFS-Auto-Snapshot-Paket wird installiert...", "Installs essential packages if missing": "Installiert wichtige Pakete, falls diese fehlen", "Insufficient Disk Space": "Nicht genügend Speicherplatz", @@ -2288,8 +2922,17 @@ "Intel CPU detected": "Intel-CPU erkannt", "Intel GPU Tools installation completed!": "Die Installation der Intel GPU Tools ist abgeschlossen!", "Intel GPU(s) detected:": "Erkannte Intel-GPU(s):", + "Intel VA-API + OpenCL (official mod)": "Intel VA-API + OpenCL (offizieller Mod)", "Intel VA-API drivers installed.": "Intel VA-API-Treiber installiert.", "Intel iGPU passthrough configured.": "Intel iGPU-Passthrough konfiguriert.", + "Intel render device for recognition": "Intel-Rendervorrichtung zur Erkennung", + "Intel/AMD (VA-API and QSV)": "Intel/AMD (VA-API und QSV)", + "Intel/AMD (VA-API)": "Intel/AMD (VA-API)", + "Intel/AMD (streaming rendering and encoding)": "Intel/AMD (Streaming Rendering und Codierung)", + "Intel/AMD VA-API": "Intel/AMD VA-API", + "Intel/AMD VA-API (no OpenCL mod)": "Intel/AMD VA-API (kein OpenCL-Mod)", + "Intel/AMD render node": "Intel/AMD Renderknoten", + "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters – building great software.": "IntelliJ IDEA hilft Ihnen, Code schneller zu schreiben, mit Tools, die mühsame Aufgaben eliminieren und Sie sich auf das Wesentliche konzentrieren können - das Erstellen großartiger Software.", "Interactive (guided, prompts visible)": "Interaktiv (geführt, Eingabeaufforderungen sichtbar)", "Interactive process viewer (press q to exit)": "Interaktiver Prozess-Viewer (zum Beenden q drücken)", "Interface": "Schnittstelle", @@ -2303,50 +2946,186 @@ "Interfaces to Remove": "Zu entfernende Schnittstellen", "Internal error: NVIDIA installer path is empty or file not found.": "Interner Fehler: Der NVIDIA-Installationspfad ist leer oder die Datei wurde nicht gefunden.", "Internal error: missing arguments in pmx_prepare_host_shared_dir": "Interner Fehler: fehlende Argumente in pmx_prepare_host_shared_dir", + "Internal subnet of the tunnel (change it only if it clashes)": "Internes Subnetz des Tunnels (ändern Sie es nur, wenn es kollidiert)", + "Interrupted operation": "Unterbrochene operation", + "Interrupted operation:": "Unterbrochene operation:", + "Interrupted stack operation found": "Unterbrochener Stapel operation gefunden", "Invalid 'proxmox-ve' candidate (not 9.x or none). Please verify your repository configuration and network, then retry.": "Ungültiger „proxmox-ve“-Kandidat (nicht 9.x oder keiner). Bitte überprüfen Sie Ihre Repository-Konfiguration und Ihr Netzwerk und versuchen Sie es dann erneut.", + "Invalid ALLOWED_HOSTS value": "Wert für ungültig ALLOWED HOSTs", + "Invalid Home Assistant OS check timeout": "Invalid Home Assistant OS Check Timeout", "Invalid ID": "Ungültige ID", + "Invalid Intel render path": "Ungültiger Intel-Renderpfad", + "Invalid Jellyfin path:": "Ungültige Jellyfin-Strecke:", + "Invalid MAC address:": "Ungültige MAC-Adresse:", + "Invalid NVIDIA destination": "Ungültiger NVIDIA-Bestimmungsort", + "Invalid NVIDIA device:": "Ungültiges NVIDIA-Gerät:", + "Invalid Nextcloud volume": "Ungültiges Volumen Nextcloud", + "Invalid OCI Entrypoint": "Ungültiger OCI Entrypoint", + "Invalid OCI digest": "Ungültiger OCI-Verdau", + "Invalid OCR language:": "Ungültige OCR-Sprache:", "Invalid Option": "Ungültige Option", "Invalid Path": "Ungültiger Pfad", + "Invalid Proxmox inventory": "Ungültiges Proxmox-Inventar", + "Invalid Python index:": "Invalid Python Index:", + "Invalid Python module:": "Ungültiges Python-Modul:", + "Invalid Python package:": "Ungültiges Python-Paket:", + "Invalid Python path in the repair:": "Ungültiger Python Pfad in der Reparatur:", + "Invalid Unpackerr variable": "Ungültige Variable Unpackerr", + "Invalid VFS cache mode": "Ungültiger VFS-Cache-Modus", "Invalid VMID": "Ungültige VMID", + "Invalid VMID or timeout": "Ungültige VMID oder Timeout", + "Invalid VMID:": "Ungültige VMID:", "Invalid ZFS pool name.": "Ungültiger ZFS-Poolname.", + "Invalid absolute mount path": "Ungültiger absoluter Halteweg", + "Invalid absolute path; avoid spaces, commas and relative segments": "Ungültiger absoluter Pfad; vermeiden Sie Leerzeichen, Kommas und relative Segmente", + "Invalid acceleration profile": "Ungültiges Beschleunigungsprofil", + "Invalid access address:": "Ungültige Zugangsadresse:", + "Invalid administrator email": "E-Mail des ungültigen Administrators", + "Invalid administrator user name": "Ungültiger Administrator Benutzername", + "Invalid base VMID": "Ungültige Basis VMID", + "Invalid check package:": "Ungültiges Kontrollpaket:", + "Invalid configuration path:": "Ungültiger Konfigurationspfad:", + "Invalid consume/export volumes": "Ungültige Verbrauchs-/Ausfuhrmengen", + "Invalid container path:": "Ungültiger Containerpfad:", + "Invalid credential file path:": "Ungültiger credential-Dateipfad:", + "Invalid declarative entrypoint": "Ungültiger deklarativer Eingangspunkt", + "Invalid declarative stop signal": "Ungültige Deklaration signal", + "Invalid declarative working directory": "Ungültiges deklaratives Arbeitsverzeichnis", + "Invalid device UID:": "UID des ungültigen Geräts:", + "Invalid device mode": "Ungültiger Gerätemodus", + "Invalid device mode:": "Ungültiger Gerätemodus:", + "Invalid device path:": "Ungültiger Gerätepfad:", + "Invalid device paths for": "Ungültige Gerätepfade für", "Invalid group name. Use letters, digits, underscore or hyphen, and start with a letter or underscore.": "Ungültiger Gruppenname. Verwenden Sie Buchstaben, Ziffern, Unterstrich oder Bindestrich und beginnen Sie mit einem Buchstaben oder Unterstrich.", + "Invalid health check": "Ungültige Gesundheitskontrolle", + "Invalid healthcheck path": "Ungültiger Gesundheitscheckpfad", + "Invalid healthcheck port": "Hafen für ungültige Gesundheitskontrollen", + "Invalid healthcheck request timeout": "Invalid Healthcheck Anfrage Timeout", + "Invalid healthcheck scheme": "Ungültiges Gesundheitschecksystem", + "Invalid healthcheck stability period": "Ungültiger Gesundheitscheck Stabilitätszeitraum", + "Invalid healthcheck timeout": "Ungültige healthcheck timeout", + "Invalid host kernel module name:": "Name des ungültigen Hostkernelmoduls:", + "Invalid host monitor PID": "PID für ungültige Host-Monitore", + "Invalid host path:": "Ungültiger Hostpfad:", + "Invalid image probe descriptor": "Beschreibung der ungültigen Bildsonde", "Invalid input": "Ungültige Eingabe", + "Invalid internal volume": "Ungültiges internes Volumen", + "Invalid list:": "Ungültige Liste:", + "Invalid machine learning CPU allocation:": "Ungültige CPU-Zuweisung für maschinelles Lernen:", + "Invalid machine learning resources": "Ungültige Machine Learning Ressourcen", + "Invalid main member or duplicated members": "Ungültiges Hauptmitglied oder duplizierte Mitglieder", + "Invalid media path": "Ungültiger Medienpfad", + "Invalid media volume": "Ungültiges Medienvolumen", + "Invalid mediafiles volume": "Volumen ungültiger Mediafiles", + "Invalid minimum version:": "Ungültige Mindestversion:", + "Invalid mount name": "Name des ungültigen Mounts", + "Invalid mount type": "Typ der ungültigen Halterung", "Invalid name": "Ungültiger Name", "Invalid name. Use only letters, numbers, hyphens and underscores.": "Ungültiger Name. Verwenden Sie nur Buchstaben, Zahlen, Bindestriche und Unterstriche.", + "Invalid native entrypoint": "Invalid native Entrypoint", + "Invalid octal permissions": "Ungültige Oktalgenehmigungen", "Invalid option": "Ungültige Option", "Invalid option, please try again.": "Ungültige Option, bitte versuchen Sie es erneut.", "Invalid option. Skipping.": "Ungültige Option. Überspringen.", + "Invalid or duplicated mount path": "Ungültiger oder duplizierter Halteweg", + "Invalid or duplicated network sysctl": "Ungültiges oder dupliziertes Netzwerk sysctl", "Invalid parameters for bind mount": "Ungültige Parameter für Bind Mount", + "Invalid path": "Ungültiger Pfad", + "Invalid path in the NVIDIA inventory": "Ungültiger Pfad im NVIDIA-Inventar", + "Invalid post-start timeout in the configuration:": "Ungültiges Timeout nach dem Start in der Konfiguration:", + "Invalid private bridge": "Ungültige Privatbrücke", + "Invalid private network": "Ungültiges privates Netzwerk", + "Invalid prlimit value": "Ungültiger Wert", + "Invalid process limits format": "Format für ungültige Prozessgrenzen", + "Invalid registry digest": "Verdauung im ungültigen Register", + "Invalid remote name": "Name der ungültigen Fernbedienung", + "Invalid remote path": "Ungültiger Fernpfad", + "Invalid repair version:": "Ungültige Reparaturversion:", + "Invalid resources": "Ungültige Mittel", + "Invalid restored volume path": "Ungültiger wiederhergestellter Volumenpfad", + "Invalid running state": "Invaliditätsstatus", + "Invalid security.unprivileged value:": "Invalid security.unprivilegierter Wert:", "Invalid selection": "Ungültige Auswahl", + "Invalid service alias": "Aliasname ungültiger Dienst", + "Invalid service check URL": "URL-Prüfung für ungültige Dienste", + "Invalid service check arguments": "Argumente für die Prüfung ungültiger Dienste", + "Invalid service check timeout": "Timeout für ungültige Service-Checks", + "Invalid shared path": "Ungültiger gemeinsamer Pfad", + "Invalid shutdown timeout": "Ungültige Abschaltung Timeout", "Invalid size. Please enter a number in MB (e.g., 128, 256, 512).": "Ungültige Größe. Bitte geben Sie eine Zahl in MB ein (z. B. 128, 256, 512).", + "Invalid stack contract": "Ungültiger Stapelvertrag", + "Invalid stack journal": "Invalid Stack Journal", + "Invalid stack members": "Ungültige Stapelmitglieder", + "Invalid stack name": "Name des ungültigen Stacks", + "Invalid stack operation": "Ungültiger Stapel operation", "Invalid storage ID. Use only letters, numbers, hyphens and underscores.": "Ungültige Speicher-ID. Verwenden Sie nur Buchstaben, Zahlen, Bindestriche und Unterstriche.", + "Invalid suite application": "Anwendung ungültiger Suiten", + "Invalid sysctl value:": "Ungültiger sysctl-Wert:", + "Invalid template storage": "Speicherung ungültiger Vorlagen", + "Invalid tmpfs options:": "Ungültige tmpfs Optionen:", + "Invalid tmpfs path:": "Ungültiger tmpfs-Pfad:", + "Invalid tmpfs size:": "Ungültige tmpfs Größe:", "Invalid username or password.": "Ungültiger Benutzername oder Passwort.", + "Invalid variable name": "Name der ungültigen Variablen", + "Invalid variable name:": "Name der ungültigen Variablen:", + "Invalid volume size": "Ungültige Volumengröße", + "Invalid volume size:": "Ungültige Volumengröße:", + "Invalid volume target": "Ungültiges Volumenziel", + "Is the value a password or secret?": "Ist der Wert ein Passwort oder ein Geheimnis?", "Issue": "Ausgabe", "Issues found": "Probleme gefunden", "Issues were found. Would you like to use the Guided Cleanup Assistant?": "Es wurden Probleme gefunden. Möchten Sie den Guided Cleanup Assistant verwenden?", "Issues were found. Would you like to use the Guided Repair Assistant?": "Es wurden Probleme gefunden. Möchten Sie den Guided Repair Assistant nutzen?", "It appears that you have already executed the xshok-proxmox post-install script on this system.": "Es scheint, dass Sie das Nachinstallationsskript xshok-proxmox bereits auf diesem System ausgeführt haben.", + "It asks for a system directory of the host:": "Es fragt nach einem Systemverzeichnis des Hosts:", + "It asks for capabilities or a relaxed confinement profile.": "Es fragt nach Fähigkeiten oder einem entspannten Einschlussprofil.", + "It asks to see the processes of the host.": "Es fordert, die Prozesse des Gastgebers zu sehen.", + "It cannot be removed on its own, because the application would stop working: continuing removes the whole application.": "Es kann nicht von selbst entfernt werden, weil die Anwendung nicht mehr funktioniert: Weiter entfernt die gesamte Anwendung.", + "It is created empty; existing data is not migrated automatically.": "Es wird leer erstellt; vorhandene Daten werden nicht automatisch migriert.", "It is recommended to create a backup before continuing.": "Es wird empfohlen, vor dem Fortfahren ein Backup zu erstellen.", "It is strongly recommended to create a backup of your container before proceeding with the conversion.": "Es wird dringend empfohlen, ein Backup Ihres Containers zu erstellen, bevor Sie mit der Konvertierung fortfahren.", + "It needs a privileged container, which is not isolated from the host.": "Es benötigt einen privilegierten Container, der nicht vom Host isoliert ist.", "It will be installed from the official GitHub repository.": "Es wird aus dem offiziellen GitHub-Repository installiert.", + "It works through the Docker engine of the host, and a native OCI container does not have one.": "Es funktioniert über die Docker-Engine des Hosts, und ein nativer OCI-Container hat keinen.", "Italian": "Italienisch", + "Its Compose file asks for privileged mode; the container is created unprivileged and that mode is only offered as an option.": "Die Compose-Datei fragt nach dem privilegierten Modus; der Container wird unprivilegiert erstellt und dieser Modus wird nur als Option angeboten.", + "Its final cleanup did not complete. Select the stack again in the OCI management menu to complete it.": "Seine endgültige Bereinigung wurde nicht abgeschlossen. Wählen Sie den Stack erneut im OCI-Verwaltungsmenü aus, um ihn abzuschließen.", + "Its labels are not applied: they are read by other Docker tools.": "Seine Etiketten werden nicht angewendet: Sie werden von anderen Docker-Tools gelesen.", "JC Channel logo applied": "JC Channel-Logo angebracht", + "JDownloader 2 with browser GUI and MyJDownloader support": "JDownloader 2 mit Browser GUI und MyJDownloader Unterstützung", + "JDownloader WebUI": "JDownloader WebUI", "JSON output for scripts": "JSON-Ausgabe für Skripte", + "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps.": "Jackett arbeitet als Proxy-Server: Er übersetzt Abfragen von Apps (Sonarr, SickRage, CouchPotato, Mylar usw.) in Tracker-Site-spezifische http-Abfragen, analysiert die HTML-Antwort und sendet dann Ergebnisse an die anfordernde Software zurück. Dies ermöglicht es, aktuelle Uploads (wie RSS) zu erhalten und Suchen durchzuführen. Jackett ist ein einziges Repository für gepflegte Indexer-Scraping- und Übersetzungslogik, das die Belastung anderer Apps beseitigt.", + "Jellyfin WebUI": "Jellyfin WebUI", + "Jellyfin configuration applied:": "Jellyfin-Konfiguration angewendet:", + "Jellyfin did not create encoding.xml before the timeout": "Jellyfin hat coding.xml nicht vor dem Timeout erstellt", + "Jellyfin has not created encoding.xml in any declared path": "Jellyfin hat coding.xml in keinem deklarierten Pfad erstellt", + "Jellyseerr is a free and open source software application for managing requests for your media library.": "Jellyseerr ist eine kostenlose Open-Source-Softwareanwendung zur Verwaltung von Anfragen für Ihre Medienbibliothek.", + "Jenkins Continuous Integration and Delivery server.": "Jenkins Continuous Integration und Delivery Server.", + "Jenkins unlock": "Jenkins entsperrt", "Job ID (letters, numbers, - _)": "Job-ID (Buchstaben, Zahlen, - _)", "Job ID:": "Job-ID:", "Job deleted:": "Job gelöscht:", "Job disabled:": "Job deaktiviert:", "Job enabled:": "Job aktiviert:", "Job selection returned empty id — aborting.": "Die Jobauswahl hat eine leere ID zurückgegeben – Abbruch.", + "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.": "Joplin ist eine kostenlose Open-Source-Notizenaufnahme- und To-Do-Anwendung, die eine große Anzahl von Notizen verarbeiten kann, die in Notebooks organisiert sind.", "Journald configuration adjusted to": "Journald-Konfiguration angepasst an", "Journald configuration is already optimized": "Die Journald-Konfiguration ist bereits optimiert", "Journald configuration updated and service restarted": "Journald-Konfiguration aktualisiert und Dienst neu gestartet", "Journald optimization completed": "Journald-Optimierung abgeschlossen", "Journald optimized - Max size: 64M": "Journald optimiert – Maximale Größe: 64 MB", + "Jupyter Lab (token only)": "Jupyter Lab (nur Token)", "KDF:": "KDF:", "KVM MSR options added to /etc/modprobe.d/kvm.conf": "KVM-MSR-Optionen zu /etc/modprobe.d/kvm.conf hinzugefügt", "KVM MSR options ensured in /etc/modprobe.d/kvm.conf": "KVM-MSR-Optionen werden in /etc/modprobe.d/kvm.conf sichergestellt", "KVM MSR options not present, nothing to revert": "KVM-MSR-Optionen sind nicht vorhanden, es kann nichts zurückgesetzt werden", + "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX ™ is a trademark of OffSec.": "Kali-linux ist eine Linux-Distribution für Advanced Penetration Testing, Ethical Hacking und Netzwerksicherheitsbewertungen. KALI LINUX TM ist eine Marke von OffSec.", + "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections.": "Kasm Workspaces ist eine docker Container-Streaming-Plattform für den browserbasierten Zugriff auf Desktops, Anwendungen und Webdienste. Kasm verwendet devops-fähige Containerized Desktop Infrastructure (CDI), um Einweg-docker-Container auf Abruf zu erstellen, die über den Webbrowser zugänglich sind. Beispiele für Anwendungsfälle sind Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS) und Open Source Intelligence (OSINT) Sammlungen.", + "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!": "Kavita ist ein schneller, funktionsreicher, plattformübergreifender Leseserver. Gebaut mit einem Fokus darauf, eine vollständige Lösung für alle Ihre Lesebedürfnisse zu sein. Richten Sie Ihren eigenen Server ein und teilen Sie Ihre Lesesammlung mit Ihren Freunden und Ihrer Familie!", + "Kavita is a free and open source web based Comic and Book Server.": "Kavita ist ein kostenloser und Open-Source-webbasierter Comic- und Buchserver.", + "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready.": "Kdenlive ist ein leistungsstarkes kostenloses und plattformübergreifendes Open-Source-Videobearbeitungsprogramm der KDE-Community. Feature reich und produktionsbereit.", + "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass).": "KeePassXC ist ein kostenloser und Open-Source-Passwort-Manager. Es begann als Community fork von KeePassX (selbst ein plattformübergreifender Port von KeePass).", "Keep GPU in LXC config (disable Start on boot)": "Behalten Sie die GPU in der LXC-Konfiguration bei (deaktivieren Sie „Start beim Booten“).", "Keep GPU in LXC config + disable Start on boot": "Behalten Sie die GPU in der LXC-Konfiguration bei und deaktivieren Sie „Start beim Booten“.", "Keep GPU in VM config (disable Start on boot)": "GPU in VM-Konfiguration belassen (Start beim Booten deaktivieren)", @@ -2356,6 +3135,7 @@ "Keep current version (N) if modified": "Bei Änderungen die aktuelle Version (N) beibehalten", "Keep in source VM(s) + disable onboot + add to target VM": "In Quell-VM(s) behalten + Onboot deaktivieren + zur Ziel-VM hinzufügen", "Keeping GPU in source VM config": "GPU in der Quell-VM-Konfiguration belassen", + "Keeping the settings changed in Proxmox:": "Die Einstellungen in Proxmox ändern:", "Kept sharedfiles group (has regular users assigned).": "Sharedfiles-Gruppe beibehalten (mit regulären Benutzern).", "Kernel and architecture info": "Kernel- und Architekturinformationen", "Kernel headers and build tools verified.": "Kernel-Header und Build-Tools überprüft.", @@ -2377,6 +3157,17 @@ "Keyfile recovery — pick source host": "Wiederherstellung der Schlüsseldatei – Quellhost auswählen", "Keyfile removed.": "Schlüsseldatei entfernt.", "Keyrings method failed; trying apt-key fallback": "Keyrings-Methode fehlgeschlagen; Ich versuche einen Apt-Key-Fallback", + "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite.": "KiCad - Eine Cross-Plattform und Open Source Electronics Design Automation Suite.", + "Kimai has no default account. Enter the container with: pct enter {main_vmid}": "Kimai hat kein Standardkonto. Geben Sie den Container ein mit: pct enter {main vmid}", + "Kimai is a professional grade time-tracking application, free and open-source.": "Kimai ist eine professionelle Time-Tracking-Anwendung, kostenlos und Open-Source.", + "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more.": "Kometa ist ein leistungsstarkes Tool, das Ihnen die vollständige Kontrolle über Ihre Medienbibliotheken gibt. Mit Kometa können Sie Ihre Anpassung auf die nächste Ebene bringen, mit granularer Kontrolle über Metadaten, Sammlungen, Overlays und vielem mehr.", + "Kometa reads its configuration from /config/config.yml and the container only ships /config/config.yml.template. Copy the template to config.yml, fill in the required Plex and TMDb connections, then restart the container.": "Kometa liest seine Konfiguration aus /config/config.yml und der Container liefert nur /config/config.yml.template. Kopieren Sie die Vorlage auf config.yml, füllen Sie die required Plex und TMDb-Verbindungen aus und starten Sie dann den Container neu.", + "Komga is a media server for your comics, mangas, BDs, magazines and eBooks.": "Komga ist ein Medienserver für Ihre Comics, Mangas, BDs, Magazine und eBooks.", + "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone.": "Krita ist ein professionelles kostenloses und Open-Source-Malprogramm. Es wird von Künstlern gemacht, die erschwingliche Kunstwerkzeuge für alle sehen wollen.", + "LAN access to the kept containers (stack configuration incomplete):": "LAN-Zugriff auf die aufbewahrten Container (Stack-Konfiguration unvollständig):", + "LAN address applied to the application URLs": "LAN-Adresse für die Anwendungs-URLs", + "LLM App Development Platform": "LLM App Entwicklungsplattform", + "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer.": "LM Studio kann lokale KI-Modelle wie gpt-oss, Llama, Gemma, Qwen und DeepSeek privat auf Ihrem Computer ausführen.", "LUNs appear as block devices assignable to VMs": "LUNs erscheinen als Blockgeräte, die VMs zugewiesen werden können", "LVM PV headers check completed": "Prüfung der LVM-PV-Header abgeschlossen", "LVM physical volume detected": "Physisches LVM-Volume erkannt", @@ -2393,18 +3184,27 @@ "LXC containers with NVIDIA passthrough:": "LXC-Container mit NVIDIA-Passthrough:", "LXC conversion from privileged to unprivileged completed successfully!": "LXC-Konvertierung von privilegiert zu unprivilegiert erfolgreich abgeschlossen!", "LXC conversion from unprivileged to privileged completed successfully!": "LXC-Konvertierung von unprivilegiert zu privilegiert erfolgreich abgeschlossen!", + "LXC entries outside the NVIDIA inventory of the journal": "LXC-Einträge außerhalb des NVIDIA-Inventars der Zeitschrift", + "LXC entries outside the selected acceleration profile": "LXC-Einträge außerhalb des ausgewählten Beschleunigungsprofils", + "LXC entry outside the read-only NVIDIA profile": "LXC-Eintrag außerhalb des Nur-Lese-NVIDIA-Profils", "LXC removed:": "LXC entfernt:", "LXC stopped": "LXC hat angehalten", "LXC update skipped by user.": "LXC-Update vom Benutzer übersprungen.", "LXCs to destroy:": "Zu zerstörende LXCs:", + "Lab interruption after installing the new container": "Laborunterbrechung nach Installation des neuen Containers", + "Lab interruption after protecting the data": "Laborunterbrechung nach dem Schutz der Daten", + "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models.": "Label Studio ist ein Open Source Data Labeling Tool. Sie können Datentypen wie Audio, Text, Bilder, Videos und Zeitreihen mit einer einfachen und einfachen Benutzeroberfläche beschriften und in verschiedene Modellformate exportieren. Es kann verwendet werden, um Rohdaten aufzubereiten oder vorhandene Trainingsdaten zu verbessern, um mehr accurate ML-Modelle zu erhalten.", "Label:": "Etikett:", "Language Change": "Sprachwechsel", "Language changed to": "Sprache geändert zu", + "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)": "Sprache/Local (z. B. es ES.UTF-8; Übersetzung jeder Anwendung ist nicht garantiert)", "Last 50 kernel log lines": "Letzte 50 Kernel-Protokollzeilen", "Last run:": "Letzte Ausführung:", "Last system boot time": "Letzte Systemstartzeit", "Latest version:": "Neueste Version:", "Launching GPU passthrough assistant for VM": "GPU-Passthrough-Assistent für VM wird gestartet", + "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork.": "Lazylibrarian ist ein Programm, um Autoren zu folgen und Metadaten für alle Ihre digitalen Lesebedürfnisse zu erfassen. Es verwendet eine combination von Goodreads Librarything und optional GoogleBooks als Quellen für Autoreninformationen und Buchinformationen. Dieser Container basiert auf dem DobyTang fork.", + "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user’s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012).": "Die Ldap-auth-Software dient zur Authentifizierung von Benutzern, die geschützte Ressourcen von Servern anfordern, die von nginx bereitgestellt werden. Es enthält einen Daemon (ldap-auth), der mit einem Authentifizierungsserver kommuniziert, und einen Webserver-Daemon, der ein Authentifizierungscookie basierend auf den credentials des Benutzers generiert. Die Daemons sind in Python für die Verwendung mit einem LDAP-Authentifizierungsserver (OpenLDAP oder Microsoft Windows Active Directory 2003 und 2012) geschrieben.", "Legacy PVE 8 .list files commented or not present": "Ältere PVE 8 .list-Dateien sind kommentiert oder nicht vorhanden", "Legacy ceph.list commented or not present": "Die alte ceph.list wurde kommentiert oder ist nicht vorhanden", "Legacy gasket-dkms cleanup could not be verified as complete.": "Die Bereinigung des veralteten gasket-dkms-Pakets konnte nicht als abgeschlossen verifiziert werden.", @@ -2412,12 +3212,25 @@ "Legacy network tools (e.g., ifconfig)": "Ältere Netzwerk-Tools (z. B. ifconfig)", "Legend:": "Legende:", "Let's review your current network configuration.": "Lassen Sie uns Ihre aktuelle Netzwerkkonfiguration überprüfen.", + "Liberate your videos and unleash infinite possibilities.": "Befreie deine Videos und entfessele unendliche Möglichkeiten.", + "Libraries: /data/media/movies, /data/media/series and /data/media/music. Select them in the media server.": "Bibliotheken: /data/media/movies, /data/media/series und /data/media/music. Wählen Sie diese im Media Server aus.", + "Library size in GB": "Bibliotheksgröße in GB", + "LibreDB Studio": "LibreDB Studio", + "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity.": "LibreOffice ist eine kostenlose und leistungsstarke Office-Suite und ein Nachfolger von OpenOffice.org (allgemein bekannt als OpenOffice). Die saubere Benutzeroberfläche und die funktionsreichen Tools helfen Ihnen, Ihre Kreativität zu entfalten und Ihre Produktivität zu steigern.", + "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM.": "LibreWolf ist eine benutzerdefinierte und unabhängige Version von Firefox mit den Hauptzielen Privatsphäre, Sicherheit und Benutzerfreiheit. LibreWolf zielt auch darauf ab, alle Telemetrie, Datenerfassung und Ärgernisse zu entfernen sowie Anti-Freiheits-Funktionen wie DRM zu deaktivieren.", + "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers.": "Librespeed ist ein sehr leichter Speedtest, der in Javascript implementiert ist und XMLHttpRequest und Web Workers verwendet.", + "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Lidarr ist ein Musiksammlungsmanager für Usenet- und BitTorrent-Benutzer. Es kann mehrere RSS-Feeds für neue Tracks von Ihren Lieblingskünstlern überwachen und sie greifen, sortieren und umbenennen. Es kann auch so konfiguriert werden, dass die Qualität der bereits heruntergeladenen Dateien automatisch aktualisiert wird, wenn ein besseres Qualitätsformat verfügbar ist.", + "Lightweight Docker management UI": "Leichtgewichtige Docker Management UI", "Likely cause: host directory permissions deny the container's mapped UID.": "Wahrscheinliche Ursache: Hostverzeichnisberechtigungen verweigern die zugeordnete UID des Containers.", "Limiting size and optimizing journald": "Begrenzung der Größe und Optimierung des Journals", "Limiting size and optimizing journald...": "Größe begrenzen und Journal optimieren...", + "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot.": "Limnoria Ein robuster, voll ausgestatteter und benutzerfreundlicher Python IRC-Bot mit vielen vorhandenen Plugins. Nachfolger des bekannten Supybot.", + "Limnoria joins no IRC network until its configuration file exists. Create it with the setup wizard from the Proxmox host: pct exec -- bash -c 'cd /config && limnoria-wizard'": "Limnoria schließt sich keinem IRC-Netzwerk an, bis seine Konfigurationsdatei existiert. Erstellen Sie es mit dem Setup-Assistenten aus dem Proxmox-Host: pct exec - bash -c 'cd /config & & limnoria-Wizard'", "Line to paste (single line, including \"command=...\" prefix):": "Einzufügende Zeile (einzelne Zeile, einschließlich „command=…“-Präfix):", "Linux Installation Options": "Linux-Installationsoptionen", "Linux/Mac path:": "Linux/Mac-Pfad:", + "LinuxServer Jellyfin with optional GPU passthrough": "LinuxServer Jellyfin mit optionalem GPU-Passthrough", + "LinuxServer MariaDB requires a user, database and password": "LinuxServer MariaDB requires ein Benutzer, Datenbank und Passwort", "List Available Disks": "Verfügbare Festplatten auflisten", "List IOMMU group mapping": "IOMMU-Gruppenzuordnung auflisten", "List NVMe devices": "NVMe-Geräte auflisten", @@ -2443,7 +3256,9 @@ "Listening on:": "Anhören:", "Listening ports:": "Abhörports:", "Listing relevant CT users and their mapped UID/GID on host...": "Auflistung relevanter CT-Benutzer und ihrer zugeordneten UID/GID auf dem Host ...", + "Load and verify the WireGuard module on the Proxmox host": "Laden und Verifizieren des WireGuard-Moduls auf dem Proxmox-Host", "Loading modules...": "Module werden geladen...", + "Loading the host kernel module:": "Laden des Hostkernel-Moduls:", "Local Disk Manager - Proxmox Host": "Lokaler Festplattenmanager – Proxmox-Host", "Local Disk Storages": "Lokale Festplattenspeicher", "Local Shared Directory on Host": "Lokales freigegebenes Verzeichnis auf dem Host", @@ -2454,6 +3269,7 @@ "Local keyfile is missing but a recovery copy was found in PBS.": "Die lokale Schlüsseldatei fehlt, aber in PBS wurde eine Wiederherstellungskopie gefunden.", "Local network only (192.168.0.0/16)": "Nur lokales Netzwerk (192.168.0.0/16)", "Local restore error log": "Fehlerprotokoll für die lokale Wiederherstellung", + "Local storage for PostgreSQL": "Lokale Speicherung für PostgreSQL", "Locale generated": "Gebietsschema generiert", "Location:": "Standort:", "Log": "Protokoll", @@ -2469,6 +3285,7 @@ "Logged-in users": "Angemeldete Benutzer", "Logrotate optimization completed": "Logrotate-Optimierung abgeschlossen", "Logrotate service restarted successfully": "Der Logrotate-Dienst wurde erfolgreich neu gestartet", + "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment.": "Lollypop ist ein leichter moderner Musikplayer, der hervorragend auf der GNOME-Desktopumgebung funktioniert.", "Long Test — Background": "Langer Test – Hintergrund", "Long self-test started on": "Langer Selbsttest begann am", "Long test — full scan, runs in background if closed": "Langer Test – vollständiger Scan, läuft im Hintergrund, wenn er geschlossen ist", @@ -2477,7 +3294,11 @@ "Lookup domain registration info": "Suchen Sie nach Domain-Registrierungsinformationen", "Low Container Memory": "Geringer Containerspeicher", "Low free space warning": "Warnung: Wenig freier Speicherplatz", + "Low-code programming for event-driven applications": "Low-Code-Programmierung für ereignisgesteuerte Anwendungen", "Low-power CPU platform": "CPU-Plattform mit geringem Stromverbrauch", + "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation": "Luanti (früher Minetest) ist eine Open-Source-Voxel-Spielerstellungsplattform mit einfachem Modding und Spielerstellung", + "Lucky web interface": "Lucky Web-Schnittstelle", + "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.": "Lychee ist ein kostenloses Fotomanagement-Tool, das auf Ihrem Server oder Webspace ausgeführt wird. Die Installation ist eine Frage von Sekunden. Hochladen, Verwalten und Teilen von Fotos wie aus einer nativen Anwendung. Lychee enthält alles, was Sie brauchen, und alle Ihre Fotos werden sicher gespeichert.", "Lynis - Security Audit": "Lynis – Sicherheitsaudit", "Lynis Management": "Lynis-Management", "Lynis command not found": "Lynis-Befehl nicht gefunden", @@ -2492,26 +3313,38 @@ "Lynis updated to version:": "Lynis wurde auf Version aktualisiert:", "Lynis version:": "Lynis-Version:", "Lynis was not installed from Git. Reinstalling...": "Lynis wurde nicht von Git installiert. Neuinstallation...", + "Lyrion Music Server is a streaming audio server for Squeezebox audio players.": "Lyrion Music Server ist ein Streaming-Audioserver für Squeezebox-Audioplayer.", "M.2 / PCIe devices:": "M.2 / PCIe-Geräte:", + "M3U proxy server": "M3U Proxy-Server", "MAC Address": "MAC-Adresse", + "MAC address": "MAC-Adresse", "MACHINE TYPE": "MASCHINENTYP", + "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers.": "MAME ist ein kostenloser und Open-Source-Emulator, der entwickelt wurde, um die Hardware von Arcade-Spielen, Videospielkonsolen, alten Computern und anderen Systemen in Software auf modernen PCs zu emulieren.", "MOTD configuration updated successfully": "MOTD-Konfiguration erfolgreich aktualisiert", "MOTD configuration was already up to date": "Die MOTD-Konfiguration war bereits auf dem neuesten Stand", "Machine Type": "Maschinentyp", + "Machine learning": "Maschinelles Lernen", + "Machine learning profile not implemented; it is not replaced by CPU:": "Machine Learning-Profil nicht implementiert; es wird nicht durch CPU ersetzt:", "Machine type: q35": "Maschinentyp: q35", "Machine: q35": "Maschine: q35", + "Main endpoint not yet defined": "Hauptendpunkt noch nicht definiert", "Major version differs:": "Hauptversion unterscheidet sich:", "Make sure IOMMU is properly enabled and the system has been rebooted after activation.": "Stellen Sie sicher, dass IOMMU ordnungsgemäß aktiviert ist und das System nach der Aktivierung neu gestartet wurde.", "Make sure there are no critical services running as they will be interrupted. Ensure your server can be safely rebooted.": "Stellen Sie sicher, dass keine kritischen Dienste ausgeführt werden, da diese unterbrochen werden. Stellen Sie sicher, dass Ihr Server sicher neu gestartet werden kann.", "Make sure you have SSH or Web UI access before rebooting.": "Stellen Sie vor dem Neustart sicher, dass Sie über SSH- oder Web-UI-Zugriff verfügen.", "Makefile missing in": "Makefile fehlt in", "Malformed repository entries cleaned": "Fehlerhafte Repository-Einträge wurden bereinigt", + "Manage OCI": "Verwaltung von OCI", + "Manage OCI stack": "Verwalten des OCI-Stacks", "Manage PBS encryption keyfile": "PBS-Verschlüsselungsschlüsseldatei verwalten", "Manage Secure Gateway": "Secure Gateway verwalten", "Manage and inspect VM disk images": "Verwalten und überprüfen Sie VM-Festplatten-Images", "Manage custom backup paths": "Benutzerdefinierte Sicherungspfade verwalten", "Manage custom paths (add / remove your folders)": "Benutzerdefinierte Pfade verwalten (Ordner hinzufügen/entfernen)", + "Manage installed OCI applications": "Verwalten installierter OCI-Anwendungen", "Manage local backup target": "Lokales Backup-Ziel verwalten", + "Managed disks must have backup enabled and a valid size": "Managed Disks müssen Backup aktiviert und eine gültige Größe haben", + "Managing Nginx proxy hosts with a simple, powerful interface.": "Verwalten von Nginx Proxy-Hosts mit einer einfachen, leistungsstarken Benutzeroberfläche.", "Manual CLI Guide (Disk and Storage Manager)": "Manueller CLI-Leitfaden (Disk and Storage Manager)", "Manual CLI Guide (GPU/TPU)": "Manueller CLI-Leitfaden (GPU/TPU)", "Manual Guide: Convert LXC Privileged to Unprivileged": "Manuelle Anleitung: Konvertieren Sie LXC Privileged in Unprivileged", @@ -2526,29 +3359,51 @@ "Manual review is required.": "Eine manuelle Überprüfung ist erforderlich.", "Manual steps recommended after import": "Nach dem Import werden manuelle Schritte empfohlen", "Manual upgrade guide step by step": "Manuelle Upgrade-Anleitung Schritt für Schritt", + "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing.": "Manyfold ist eine selbst gehostete Open-Source-Webanwendung zur Verwaltung einer Sammlung von 3D-Modellen, die sich insbesondere auf den 3D-Druck konzentriert.", "Mapped GID on host": "Zugeordnete GID auf dem Host", "Mapped UID on host": "Zugeordnete UID auf dem Host", + "Mariadb is one of the most popular database servers. Made by the original developers of MySQL.": "Mariadb ist einer der beliebtesten Datenbankserver. Hergestellt von den ursprünglichen Entwicklern von MySQL.", + "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..": "Mastodon ist ein kostenloser Open-Source-Sozialnetzwerkserver auf Basis von ActivityPub, auf dem Benutzer Freunden folgen und neue entdecken können.", "Max FD limit / ulimit configured": "Maximaler FD-Grenzwert / ulimit konfiguriert", "Max FS open files configuration created successfully": "Max. FS-Konfiguration für offene Dateien erfolgreich erstellt", "Max user watches configured": "Maximale Benutzerüberwachungen konfiguriert", "Maximum auto-repair attempts reached (3). Please review the log and run any remaining commands manually.": "Maximale Anzahl automatischer Reparaturversuche erreicht (3). Bitte überprüfen Sie das Protokoll und führen Sie alle verbleibenden Befehle manuell aus.", "May need to restart terminal": "Möglicherweise muss das Terminal neu gestartet werden", + "Media & Streaming": "Medien & Streaming", + "Media discovery and request management for Jellyfin, Plex and Emby.": "Media Discovery und Request Management für Jellyfin, Plex und Emby.", + "Media library transcoding and health checking, with an internal worker node.": "Medienbibliothek Transcodierung und Gesundheitsüberprüfung, mit einem internen Mitarbeiterknoten.", + "Media server": "Medienserver", + "Media server selection cancelled or invalid": "Medienserverauswahl abgebrochen oder ungültig", + "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well.": "MediaElch ist ein MediaManager für Kodi. Informationen über Filme, TV-Shows, Konzerte und Musik werden als nfo-Dateien gespeichert. Fanarts werden automatisch von fanart.tv heruntergeladen. Mit dem nfo-Generator kann MediaElch auch mit anderen MediaCentern verwendet werden.", + "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Medusa ist ein automatischer Video Library Manager für TV Shows. Es schaut nach neuen episoden ihrer lieblingsshows, und wenn sie gepostet werden, macht es seine magie.", + "Memory": "Speicher", + "Memory in MB": "Speicher in MB", "Memory optimization completed.": "Speicheroptimierung abgeschlossen.", "Memory optimizations removed": "Speicheroptimierungen entfernt", "Memory restored.": "Speicher wiederhergestellt.", "Memory settings optimized successfully": "Speichereinstellungen erfolgreich optimiert", "Memory:": "Erinnerung:", + "Memos is a lightweight, self-hosted memo hub. Open Source and Free forever.": "Memos ist ein leichter, selbst gehosteter Memo-Hub. Open Source und Free für immer.", + "Messaging & Queues": "Messaging & Queues", + "Messenger for the Decentralized Web": "Messenger für das dezentrale Web", "Method:": "Verfahren:", + "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium.": "Microsoft Edge ist ein plattformübergreifender Webbrowser, der von Microsoft entwickelt wurde und auf Chromium basiert.", "Migrate VMs away from node being upgraded": "Migrieren Sie VMs vom zu aktualisierenden Knoten weg", "Migrate away any guests that must keep running": "Migrieren Sie alle Gäste weg, die weiter ausgeführt werden müssen", "Migrated": "Migriert", "Migrated legacy ProxMenux NVIDIA blacklist state — module will reload after reboot": "Migrierter Legacy-ProxMenux-NVIDIA-Blacklist-Status – Modul wird nach dem Neustart neu geladen", + "MineOS web interface": "MineOS Web-Schnittstelle", + "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards.": "Minisatip ist eine Multi-Threaded-Satip-Server-Version 1.2, die unter Linux läuft und mit DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC und ISDB-T-Karten getestet wurde.", "Mirror URL not available for this script.": "Die Spiegel-URL ist für dieses Skript nicht verfügbar.", + "Miscellaneous": "Verschiedenes", "Missing": "Fehlen", + "Missing OCI metadata:": "Fehlende OCI Metadaten:", "Missing commands after installation:": "Fehlende Befehle nach der Installation:", "Missing dependency": "Fehlende Abhängigkeit", + "Missing native directive:": "Fehlende native Direktive:", "Missing on target:": "Ziel verfehlt:", "Missing or invalid parameter": "Fehlender oder ungültiger Parameter", + "Missing required command:": "fehlender Befehl required:", "Missing required parameter": "Fehlender erforderlicher Parameter", "Mixed GPU Modes": "Gemischte GPU-Modi", "Mixed current mode detected in selected GPU(s).": "Gemischter Strommodus in ausgewählten GPU(s) erkannt.", @@ -2556,15 +3411,20 @@ "Mode": "Modus", "Model": "Modell", "Modern resource monitor (press q to exit)": "Moderner Ressourcenmonitor (zum Beenden q drücken)", + "Modern, easy to use download automation for torrents and usenet.": "Moderne, einfach zu bedienende Download-Automatisierung für Torrents und Usenet.", "Modifying Fastfetch configuration...": "Fastfetch-Konfiguration wird geändert...", "Modules configuration updated.": "Modulkonfiguration aktualisiert.", "Modules loaded.": "Module geladen.", + "MongoDB 4.4, the last series that runs on a CPU without AVX.": "MongoDB 4.4, die letzte Serie, die auf einer CPU ohne AVX läuft.", + "Monica is an open source personal relationship management system, that lets you document your life.": "Monica ist ein Open Source Personal Relationship Management System, mit dem Sie Ihr Leben dokumentieren können.", "Monitor Activated": "Monitor aktiviert", "Monitor Deactivated": "Monitor deaktiviert", "Monitor URL": "Überwachen Sie die URL", "Monitor disk I/O usage (press q to exit)": "Überwachen Sie die E/A-Nutzung der Festplatte (drücken Sie q, um den Vorgang zu beenden)", "Monitor progress:": "Fortschritt überwachen:", + "Monitor, analyze, and alert on network performance.": "Überwachen, analysieren und alarmieren Sie die Netzwerkleistung.", "Monitoring": "Überwachung", + "Monitoring & Analytics": "Monitoring & Analytics", "Most common cause: the archive is corrupted (interrupted write, partial copy, or storage issue).": "Häufigste Ursache: Das Archiv ist beschädigt (unterbrochener Schreibvorgang, teilweises Kopieren oder Speicherproblem).", "Mount Added Successfully:": "Mount erfolgreich hinzugefügt:", "Mount CIFS share:": "CIFS-Freigabe bereitstellen:", @@ -2592,13 +3452,19 @@ "Mount Samba Share on Host": "Mounten Sie die Samba-Freigabe auf dem Host", "Mount USB disk?": "USB-Datenträger mounten?", "Mount a USB drive now": "Mounten Sie jetzt ein USB-Laufwerk", + "Mount activation cancelled": "Mount-Aktivierung aufgehoben", "Mount all datasets": "Hängen Sie alle Datensätze ein", "Mount already exists for this path in container": "Für diesen Pfad im Container ist bereits ein Mount vorhanden", "Mount and persist with UUID:": "Mounten und mit UUID beibehalten:", + "Mount configuration cancelled": "Mount-Konfiguration aufgehoben", "Mount failed": "Die Montage ist fehlgeschlagen", + "Mount mode applied": "Einbauart", + "Mount name": "Name des Mounts", + "Mount not authorized by the operation": "Mount nicht autorisiert durch operation", "Mount options:": "Montageoptionen:", "Mount path must be an absolute path starting with /": "Der Mount-Pfad muss ein absoluter Pfad sein, der mit / beginnt.", "Mount path:": "Mount-Pfad:", + "Mount paths must not overlap": "Montagebahnen dürfen sich nicht überlappen", "Mount point created": "Mountpunkt erstellt", "Mount point created.": "Mountpunkt erstellt.", "Mount point is visible but NOT writable from inside the container": "Der Einhängepunkt ist sichtbar, aber NICHT aus dem Container heraus beschreibbar", @@ -2607,11 +3473,14 @@ "Mount point ready:": "Mountpunkt bereit:", "Mount point removed successfully": "Der Mountpunkt wurde erfolgreich entfernt", "Mount point:": "Einhängepunkt:", + "Mount points added:": "Anbringungspunkte hinzugefügt:", + "Mount read-only": "Nur-Read-Only-Mount", "Mount shares on HOST first": "Mounten Sie zuerst Freigaben auf HOST", "Mount specific dataset": "Mounten Sie einen bestimmten Datensatz", "Mount status:": "Mount-Status:", "Mount this device and use it as the backup destination?": "Dieses Gerät mounten und als Backup-Ziel verwenden?", "Mount was busy — performed lazy unmount": "Mount war beschäftigt – träges Unmounten wurde durchgeführt", + "Mount your cloud drive on your home NAS": "Befestigen Sie Ihr Cloud-Laufwerk auf Ihrem NAS zu Hause", "Mounted": "Montiert", "Mounted ISO on device": "ISO auf dem Gerät installiert", "Mounted at": "Montiert bei", @@ -2626,8 +3495,17 @@ "Mounting here will hide existing files until unmounted.": "Beim Mounten hier werden vorhandene Dateien ausgeblendet, bis die Bereitstellung aufgehoben wird.", "Move that copy offsite (USB, password manager, another host). Delete it from this path when done.": "Verschieben Sie diese Kopie an einen anderen Standort (USB, Passwort-Manager, ein anderer Host).Löschen Sie es aus diesem Pfad, wenn Sie fertig sind.", "Move to target VM (remove from source VM config)": "Zur Ziel-VM verschieben (aus der Quell-VM-Konfiguration entfernen)", + "Moving the data volumes aside": "Verschieben der Datenmengen beiseite", + "Moving the data volumes aside...": "Verschieben der Datenmengen beiseite...", + "Multi-container application (experimental)": "Mehrbehälteranwendung (experimentell)", + "Multi-line variables are not supported": "Mehrzeilige Variablen werden nicht unterstützt", + "Multiple networks or external networks are not yet supported": "Mehrere Netzwerke oder externe Netzwerke werden noch nicht unterstützt", "Multiple recovery groups found in PBS. Pick the one that originally created the keyfile:": "In PBS wurden mehrere Wiederherstellungsgruppen gefunden. Wählen Sie diejenige aus, die ursprünglich die Schlüsseldatei erstellt hat:", "Multiple rootfs directories were found in this archive. Restore cannot continue automatically.": "In diesem Archiv wurden mehrere Rootfs-Verzeichnisse gefunden. Die Wiederherstellung kann nicht automatisch fortgesetzt werden.", + "Music Collection and Streaming Server": "Musiksammlung und Streaming Server", + "Music software that transforms your listening experience": "Musiksoftware, die Ihr Hörerlebnis verändert", + "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more.": "MySQL Workbench ist ein einheitliches visuelles Tool für Datenbankarchitekten, Entwickler und DBAs. MySQL Workbench bietet Datenmodellierung, SQL-Entwicklung und umfassende Verwaltungstools für Serverkonfiguration, Benutzerverwaltung, Backup und vieles mehr.", + "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL.": "Mylar3 ist ein automatisierter Comic Book Downloader (cbr/cbz) zur Verwendung mit NZB und in Python geschriebenen Torrents. Es unterstützt SABnzbd, NZBGET und viele Torrent-Clients zusätzlich zu DDL.", "NAS Systems": "NAS-Systeme", "NETWORK CONFIGURATION ANALYSIS": "NETZWERKKONFIGURATIONSANALYSE", "NFS Access Restricted": "NFS-Zugriff eingeschränkt", @@ -2691,24 +3569,33 @@ "NOT FOUND": "NICHT GEFUNDEN", "NOTE: The host directory and its contents will remain unchanged.": "HINWEIS: Das Hostverzeichnis und sein Inhalt bleiben unverändert.", "NVENC patch detected — list narrowed to versions supported by keylase/nvidia-patch.": "NVENC-Patch erkannt – Liste eingegrenzt auf Versionen, die von keylase/nvidia-patch unterstützt werden.", + "NVIDIA (CUDA)": "NVIDIEN (CUDA)", + "NVIDIA (CUDA; official GPU image)": "NVIDIA (CUDA; offizielles GPU-Bild)", + "NVIDIA (NVDEC/CUDA)": "NVIDIA (NVDEC/CUDA)", + "NVIDIA (NVENC/NVDEC)": "NVIDIA (NVENC/NVDEC)", "NVIDIA Actions": "NVIDIA-Aktionen", "NVIDIA CPU hiding already configured": "NVIDIA-CPU-Ausblendung bereits konfiguriert", "NVIDIA Container Toolkit": "NVIDIA Container Toolkit", + "NVIDIA Container Toolkit could not generate the runtime inventory": "NVIDIA Container Toolkit konnte das Laufzeitinventar nicht generieren", "NVIDIA Container Toolkit installed. GPU validation pending until the host restarts.": "NVIDIA Container Toolkit installiert. Die GPU-Validierung steht bis zum Neustart des Hosts aus.", "NVIDIA Container Toolkit is incomplete. Missing:": "NVIDIA Container Toolkit ist unvollständig. Fehlen:", "NVIDIA Container Toolkit is installed but its command line did not answer.": "NVIDIA Container Toolkit ist installiert, aber die Befehlszeile hat nicht geantwortet.", + "NVIDIA Container Toolkit is missing on the host (nvidia-container-cli)": "NVIDIA Container Toolkit fehlt auf dem Host (nvidia-container-cli)", "NVIDIA Container Toolkit verified against the running driver.": "NVIDIA Container Toolkit anhand des laufenden Treibers überprüft.", "NVIDIA DKMS entries removed.": "NVIDIA DKMS-Einträge entfernt.", "NVIDIA Driver Uninstall": "Deinstallation des NVIDIA-Treibers", "NVIDIA Driver Version": "NVIDIA-Treiberversion", "NVIDIA Drivers": "NVIDIA-Treiber", "NVIDIA Drivers Not Found": "NVIDIA-Treiber nicht gefunden", + "NVIDIA GPU / CUDA (Toolkit on the host)": "NVIDIA GPU / CUDA (Toolkit auf dem Host)", "NVIDIA GPU Driver Installation": "Installation des NVIDIA GPU-Treibers", "NVIDIA GPU passthrough configured.": "NVIDIA GPU-Passthrough konfiguriert.", + "NVIDIA GPU prepared:": "NVIDIA GPU vorbereitet:", "NVIDIA KVM args configured (kvm=off, vendor_id spoof)": "NVIDIA KVM-Argumente konfiguriert (kvm=off, Vendor_ID-Spoof)", "NVIDIA KVM hiding (cpu hidden=1)": "NVIDIA KVM versteckt (CPU versteckt=1)", "NVIDIA KVM hiding already configured": "NVIDIA KVM-Versteckung bereits konfiguriert", "NVIDIA Patch": "NVIDIA-Patch", + "NVIDIA device outside the expected native profile": "NVIDIA-Gerät außerhalb des erwarteten nativen Profils", "NVIDIA driver": "NVIDIA-Treiber", "NVIDIA driver installed successfully.": "NVIDIA-Treiber erfolgreich installiert.", "NVIDIA driver installed:": "NVIDIA-Treiber installiert:", @@ -2716,6 +3603,7 @@ "NVIDIA drivers are not installed or not loaded on this host.": "NVIDIA-Treiber sind auf diesem Host nicht installiert oder nicht geladen.", "NVIDIA host services disabled for VFIO mode": "NVIDIA-Hostdienste für VFIO-Modus deaktiviert", "NVIDIA host services/autoload already aligned for native mode": "NVIDIA-Hostdienste/Autoload sind bereits für den nativen Modus ausgerichtet", + "NVIDIA inside the container does not match the host driver or GPU": "NVIDIA im Container passt nicht zum Hosttreiber oder GPU", "NVIDIA install incomplete. Check log:": "NVIDIA-Installation unvollständig. Protokoll prüfen:", "NVIDIA installer downloaded successfully": "NVIDIA-Installationsprogramm erfolgreich heruntergeladen", "NVIDIA installer extracted.": "NVIDIA-Installationsprogramm extrahiert.", @@ -2724,29 +3612,50 @@ "NVIDIA installer returned error": "Das NVIDIA-Installationsprogramm hat einen Fehler zurückgegeben", "NVIDIA kernel modules unloaded successfully.": "NVIDIA-Kernelmodule wurden erfolgreich entladen.", "NVIDIA libs require approximately 1.5GB of free space.": "NVIDIA-Bibliotheken erfordern etwa 1,5 GB freien Speicherplatz.", + "NVIDIA mount with an unauthorized source or target": "NVIDIA-Halterung mit nicht autorisierter Quelle oder Ziel", "NVIDIA patch applied - check README for supported versions.": "NVIDIA-Patch angewendet – überprüfen Sie die README-Datei auf unterstützte Versionen.", "NVIDIA patch not applied.": "NVIDIA-Patch nicht angewendet.", "NVIDIA per-BDF VFIO binding configured": "NVIDIA pro-BDF-VFIO-Bindung konfiguriert", + "NVIDIA permissions or device nodes differ from the official inventory": "NVIDIA Berechtigungen oder Geräteknoten unterscheiden sich vom offiziellen Inventar", + "NVIDIA refresh validated; the container is stopped and its settings are kept": "NVIDIA update validiert; der Container wird angehalten und seine Einstellungen bleiben erhalten", + "NVIDIA runtime libraries or components are missing": "NVIDIA Runtime Libraries oder Komponenten fehlen", + "NVIDIA selection not supported by this profile": "NVIDIA Auswahl wird von diesem Profil nicht unterstützt", "NVIDIA services stopped and disabled.": "NVIDIA-Dienste wurden angehalten und deaktiviert.", "NVIDIA udev rules and persistence service installed.": "NVIDIA udev-Regeln und Persistenzdienst installiert.", "NVIDIA uninstallation steps completed.": "NVIDIA-Deinstallationsschritte abgeschlossen.", "NVIDIA uninstaller completed.": "NVIDIA-Deinstallationsprogramm abgeschlossen.", "NVIDIA update failed for LXC": "NVIDIA-Update für LXC fehlgeschlagen", "NVIDIA userspace libraries installed.": "NVIDIA-Userspace-Bibliotheken installiert.", + "NVML does not match the current host driver": "NVML stimmt nicht mit dem aktuellen Hosttreiber überein", "NVMe Disk Detected": "NVMe-Festplatte erkannt", "NVMe critical_warning is 0 (no critical warnings reported).": "NVMe Critical_warning ist 0 (keine kritischen Warnungen gemeldet).", + "NVMe health status: PASSED": "NVMe-Gesundheitsstatus: BESTANDEN", "NVMe health status: WARNING (critical_warning =": "NVMe-Gesundheitsstatus: WARNUNG (critical_warning =", "NVMe skipped (to add as PCIe use 'Add Controller or NVMe PCIe to VM'):": "NVMe übersprungen (zum Hinzufügen als PCIe verwenden Sie „Controller oder NVMe PCIe zur VM hinzufügen“):", "NVMe-specific SMART log": "NVMe-spezifisches SMART-Protokoll", + "NVR & Cameras": "NVR & Kameras", + "NVR with optional VA-API video acceleration and hardware object detectors": "NVR mit optionaler VA-API Videobeschleunigung und Hardwareobjektdetektoren", + "NZBGet web interface": "NZBGet Web-Schnittstelle", + "Name": "Name", + "Name for this application": "Name des Antrags", "Name for this target:": "Name für dieses Ziel:", + "Name of the PostgreSQL user created on the first start": "Name des PostgreSQL-Benutzers, der beim ersten Start erstellt wurde", + "Name of the database created on the first start": "Name der beim ersten Start erstellten Datenbank", + "Name of the internal worker node": "Name des internen Mitarbeiterknotens", + "Name of this wallabag instance, shown in the interface and in 2FA codes": "Name dieser wallabag-Instanz, angezeigt in der Schnittstelle und in 2FA-Codes", + "Name or part of the description of the application": "Name oder Teil der Beschreibung des Antrags", "Name:": "Name:", + "Named accounts need private mode. Stop the container, set public: false in /config/config.js, start it again and create each user with: pct exec -- env THELOUNGE_HOME=/config s6-setuidgid abc thelounge add ": "Benannte Konten benötigen einen privaten Modus. Stoppen Sie den Container, setzen Sie public: false in /config/config.js, starten Sie ihn erneut und erstellen Sie jeden Benutzer mit: pct exec -- env THELOUNGE HOME=/config s6-setuidgid abc thelounge add ", "Neither /etc/kernel/cmdline nor /etc/default/grub found.": "Weder /etc/kernel/cmdline noch /etc/default/grub gefunden.", "Nesting feature enabled": "Verschachtelungsfunktion aktiviert", "NetBIOS Service: RUNNING": "NetBIOS-Dienst: LÄUFT", "NetBIOS Service: STOPPED": "NetBIOS-Dienst: BEENDET", "NetBIOS port 139:": "NetBIOS-Port 139:", + "NetBox": "NetBox", + "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations.": "Netbox ist ein IP-Adressmanagement (IPAM) und ein Data Center Infrastructure Management (DCIM). Ursprünglich vom Netzwerk-Engineering-Team von DigitalOcean konzipiert, wurde NetBox speziell für die Bedürfnisse von Netzwerk- und Infrastrukturingenieuren entwickelt. Es soll als domänenspezifische Wahrheitsquelle für Netzwerk-operationen fungieren.", "Network": "Netzwerk", "Network :": "Netzwerk:", + "Network & Firewall": "Netzwerk & Firewall", "Network (interfaces, DNS)": "Netzwerk (Schnittstellen, DNS)", "Network Bridge": "Netzwerkbrücke", "Network Commands": "Netzwerkbefehle", @@ -2764,6 +3673,7 @@ "Network Restarted": "Netzwerk neu gestartet", "Network Tools": "Netzwerk-Tools", "Network access:": "Netzwerkzugriff:", + "Network bridge": "Netzbrücke", "Network configuration backed up": "Netzwerkkonfiguration gesichert", "Network configuration has been restored from backup.": "Die Netzwerkkonfiguration wurde aus der Sicherung wiederhergestellt.", "Network connection failed to": "Die Netzwerkverbindung konnte nicht hergestellt werden", @@ -2776,12 +3686,16 @@ "Network service restarted successfully": "Der Netzwerkdienst wurde erfolgreich neu gestartet", "Network service restarted successfully.": "Der Netzwerkdienst wurde erfolgreich neu gestartet.", "Network share mounting (NFS/Samba) requires a PRIVILEGED container.": "Für das Mounten von Netzwerkfreigaben (NFS/Samba) ist ein PRIVILEGED-Container erforderlich.", + "Network sysctls prepared:": "Netzwerk sysctls vorbereitet:", "Network throughput test (client/server)": "Netzwerkdurchsatztest (Client/Server)", + "Network-wide Ad Blocking": "Netzwerkweite Werbeblockierung", + "Network-wide ad and tracker blocking": "Netzwerkweite Werbe- und Trackerblockierung", "NetworkManager Detected": "NetworkManager erkannt", "NetworkManager has been removed successfully": "NetworkManager wurde erfolgreich entfernt", "NetworkManager is running (may cause conflicts)": "NetworkManager wird ausgeführt (kann zu Konflikten führen)", "NetworkManager is running, which may conflict with Proxmox.": "NetworkManager wird ausgeführt, was zu Konflikten mit Proxmox führen kann.", "NetworkManager not running": "NetworkManager läuft nicht", + "Networks the peers reach through the tunnel (0.0.0.0/0 = all traffic)": "Netzwerke, die die Peers durch den Tunnel erreichen (0.0.0.0/0 = aller Verkehr)", "New Folder in /mnt": "Neuer Ordner in /mnt", "New Group": "Neue Gruppe", "New Search": "Neue Suche", @@ -2789,14 +3703,26 @@ "New Virtual Machine": "Neue virtuelle Maschine", "New backup job": "Neuer Sicherungsauftrag", "New backups on this host will be unencrypted until a new keyfile is set up.": "Neue Backups auf diesem Host werden unverschlüsselt sein, bis eine neue Schlüsseldatei eingerichtet wird.", + "New image compatible:": "Neues Bild kompatibel:", + "New image installed": "Neues Bild installiert", + "New image installed, not verified yet": "Neues Bild installiert, noch nicht verifiziert", + "New image verified, not saved yet": "Neues Bild verifiziert, noch nicht gespeichert", "New kernel staged; rebuilding DKMS drivers:": "Neuer Kernel bereitgestellt;DKMS-Treiber neu erstellen:", "New mount options to apply:": "Neue Mount-Optionen zur Anwendung:", "New scheduled job (own timer + retention)": "Neuer geplanter Job (eigener Timer + Aufbewahrung)", + "New value for": "Neuer Wert für", "New version available": "Neue Version verfügbar", "New version:": "Neue Version:", "Next Step Required": "Nächster Schritt erforderlich", "Next Steps:": "Nächste Schritte:", "Next step: stop that VM first, then run": "Nächster Schritt: Stoppen Sie zuerst die VM und führen Sie sie dann aus", + "Nextcloud configuration cancelled": "Nextcloud-Konfiguration gestrichen", + "Nextcloud gives you access to all your files wherever you are.": "Nextcloud bietet Ihnen Zugriff auf alle Ihre Dateien, wo immer Sie sind.", + "Nextcloud volume size in GB": "Nextcloud Volumengröße in GB", + "Nextcloud with private PostgreSQL and Redis dependencies": "Nextcloud mit privaten PostgreSQL und Redis Abhängigkeiten", + "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server.": "Nginx ist ein HTTP-Webserver, Reverse-Proxy, Content-Cache, Load Balancer, TCP/UDP-Proxy-Server und Mail-Proxy-Server.", + "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.": "Nginx Webserver und Reverse Proxy mit PHP-Unterstützung und einem eingebauten Certbot-Client (Let's Encrypt). Es enthält auch fail2ban zur Intrusionsprävention.", + "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd.": "Ngircd ist ein kostenloser, tragbarer und leichter Internet Relay Chat Server für kleine oder private Netzwerke, der unter der GNU General Public License (GPL) entwickelt wurde. Es ist einfach zu konfigurieren, kann mit dynamischen IP-Adressen umgehen und unterstützt IPv6, SSL-geschützte Verbindungen sowie PAM für die Authentifizierung. Es ist von grund auf neu geschrieben und basiert nicht auf der ursprünglichen ircd.", "No": "NEIN", "No .ova or .ovf files found in:": "Keine .ova- oder .ovf-Dateien gefunden in:", "No .ovf descriptor found inside OVA.": "In OVA wurde kein .ovf-Deskriptor gefunden.", @@ -2814,6 +3740,7 @@ "No CTs available in the system.": "Im System sind keine CTs verfügbar.", "No Changes Needed": "Keine Änderungen erforderlich", "No Cleanup Needed": "Keine Reinigung erforderlich", + "No Compose file was given": "Keine Compose-Datei wurde angegeben", "No Controller/NVMe selected for now.": "Derzeit ist kein Controller/NVMe ausgewählt.", "No Coral Detected": "Kein Coral erkannt", "No Coral TPU device was found on this host (neither PCIe/M.2 nor USB).": "Auf diesem Host wurde kein Coral TPU-Gerät gefunden (weder PCIe/M.2 noch USB).", @@ -2825,6 +3752,7 @@ "No Exports": "Keine Exporte", "No Exports Found": "Keine Exporte gefunden", "No Folders": "Keine Ordner", + "No GPU (CPU)": "Keine GPU (CPU)", "No GPU Detected": "Keine GPU erkannt", "No GPU selected.": "Keine GPU ausgewählt.", "No GPU selected. Please select at least one GPU to continue.": "Keine GPU ausgewählt. Bitte wählen Sie mindestens eine GPU aus, um fortzufahren.", @@ -2832,12 +3760,15 @@ "No Guest Shares": "Keine Gastfreigaben", "No IP": "Keine IP", "No IP assigned": "Keine IP zugewiesen", + "No IPv4 address was detected after 30 seconds.": "Nach 30 Sekunden wurde keine IPv4-Adresse erkannt.", "No ISO file detected after UUP Dump process.": "Nach dem UUP-Dump-Vorgang wurde keine ISO-Datei erkannt.", "No ISO images found in Proxmox ISO storages.": "In Proxmox ISO-Speichern wurden keine ISO-Images gefunden.", "No ISO selected.": "Kein ISO ausgewählt.", "No ISO was generated.": "Es wurde keine ISO generiert.", "No Images Found": "Keine Bilder gefunden", "No Intel GPU detected on this system.": "Auf diesem System wurde keine Intel-GPU erkannt.", + "No LAN address was obtained": "Keine LAN-Adresse erhalten", + "No LAN address was obtained for the service:": "Für den Dienst wurde keine LAN-Adresse erhalten:", "No LXC containers available": "Keine LXC-Container verfügbar", "No LXC containers found": "Keine LXC-Container gefunden", "No LXC containers found on this system.": "Auf diesem System wurden keine LXC-Container gefunden.", @@ -2855,7 +3786,9 @@ "No NFS shares currently mounted.": "Derzeit sind keine NFS-Freigaben gemountet.", "No NVIDIA GPU detected on this system.": "Auf diesem System wurde keine NVIDIA-GPU erkannt.", "No NVIDIA GPU has been detected on this system. The installer will now exit.": "Auf diesem System wurde keine NVIDIA-GPU erkannt. Das Installationsprogramm wird nun beendet.", + "No NVIDIA GPU is available": "Keine NVIDIA GPU verfügbar", "No NVIDIA driver installed.": "Kein NVIDIA-Treiber installiert.", + "No OCI instances are registered.": "Es werden keine OCI-Instanzen registriert.", "No PBS keyfile is installed on this host and no automatic recovery was possible.": "Auf diesem Host ist keine PBS-Schlüsseldatei installiert und es war keine automatische Wiederherstellung möglich.", "No PVE vzdump job uses a": "Kein PVE-vzdump-Job verwendet a", "No PVs with old headers found.": "Keine PVs mit alten Headern gefunden.", @@ -2891,6 +3824,7 @@ "No Virtual Machines found on this system.": "Auf diesem System wurden keine virtuellen Maschinen gefunden.", "No ZFS pools detected. Skipping ZFS ARC optimization.": "Keine ZFS-Pools erkannt. Überspringen der ZFS ARC-Optimierung.", "No ZFS pools detected. Skipping ZFS autotrim.": "Keine ZFS-Pools erkannt. ZFS-Autotrim wird übersprungen.", + "No acceleration (CPU)": "Keine Beschleunigung (CPU)", "No accessible": "Nicht zugänglich", "No accessible NFS servers found.": "Es wurden keine zugänglichen NFS-Server gefunden.", "No accessible Samba servers found.": "Keine erreichbaren Samba-Server gefunden.", @@ -2900,11 +3834,13 @@ "No active session": "Keine aktive Sitzung", "No additional GPU can be added.": "Es kann keine zusätzliche GPU hinzugefügt werden.", "No additional device needs to be added.": "Es muss kein zusätzliches Gerät hinzugefügt werden.", + "No applications match": "Keine Übereinstimmung der Anwendungen", "No archives": "Keine Archive", "No archives found in this Borg repository.": "In diesem Borg-Repository wurden keine Archive gefunden.", "No available Controllers/NVMe devices were found.": "Es wurden keine verfügbaren Controller/NVMe-Geräte gefunden.", "No available disks found.": "Keine verfügbaren Datenträger gefunden.", "No backup found, logrotate configuration not changed": "Kein Backup gefunden, Logrotate-Konfiguration nicht geändert", + "No backup is scheduled: the rsnapshot lines in /config/crontabs/root are commented out. Uncomment or adjust the intervals you want, then restart the container.": "Es ist kein Backup geplant: Die rsnapshot Zeilen in /config/crontabs/root werden kommentiert. Decomment oder Anpassung der gewünschten Intervalle, dann starten Sie den Container neu.", "No backups": "Keine Backups", "No backups found": "Keine Backups gefunden", "No bridge configuration issues found": "Es wurden keine Probleme mit der Bridge-Konfiguration gefunden", @@ -2921,6 +3857,7 @@ "No compatible PVE jobs": "Keine kompatiblen PVE-Jobs", "No compatible disk images found in:": "Keine kompatiblen Disk-Images gefunden in:", "No configuration issues found": "Es wurden keine Konfigurationsprobleme gefunden", + "No container of the stack was modified.": "Es wurde kein Behälter des Stapels verändert.", "No container runtime available.": "Keine Containerlaufzeit verfügbar.", "No container selected. Exiting.": "Kein Container ausgewählt. Verlassen.", "No controller/NVMe selected.": "Kein Controller/NVMe ausgewählt.", @@ -2951,11 +3888,13 @@ "No folders found in /mnt. Please create a new folder.": "Keine Ordner in /mnt gefunden. Bitte erstellen Sie einen neuen Ordner.", "No folders found inside /mnt in the CT.": "Keine Ordner in /mnt im CT gefunden.", "No format-safe disks are available.": "Es sind keine formatsicheren Datenträger verfügbar.", + "No free ProxMenux private /24 network is available": "Kein kostenloses ProxMenux privates /24 Netzwerk verfügbar", "No gasket DKMS registrations remain.": "Es sind keine gasket-DKMS-Registrierungen mehr vorhanden.", "No group creation required — uses world-writable sticky bit permissions.": "Keine Gruppenerstellung erforderlich – verwendet weltweit beschreibbare Sticky-Bit-Berechtigungen.", "No host VFIO reconfiguration expected": "Keine Host-VFIO-Neukonfiguration erwartet", "No host VFIO/native binding changes were required.": "Es waren keine Host-VFIO/native Bindungsänderungen erforderlich.", "No host backups were found in this PBS repository:": "In diesem PBS-Repository wurden keine Host-Backups gefunden:", + "No host directory is used by this application.": "Es wird kein Hostverzeichnis von dieser Anwendung verwendet.", "No host reboot expected": "Kein Neustart des Hosts erwartet", "No host write access — server-side ACL or root_squash. Continuing anyway.": "Kein Host-Schreibzugriff – serverseitige ACL oder root_squash. Trotzdem weitermachen.", "No host write access — server-side ACL. Continuing anyway.": "Kein Host-Schreibzugriff – serverseitige ACL. Trotzdem weitermachen.", @@ -2964,6 +3903,7 @@ "No iSCSI storage configured.": "Kein iSCSI-Speicher konfiguriert.", "No iSCSI storage found in Proxmox.": "In Proxmox wurde kein iSCSI-Speicher gefunden.", "No iSCSI targets found on portal": "Im Portal wurden keine iSCSI-Ziele gefunden", + "No image was given": "Kein Bild wurde gegeben", "No import disks selected for now.": "Derzeit sind keine Importdatenträger ausgewählt.", "No importable disks available. System disks and protected disks are hidden.": "Keine importierbaren Datenträger verfügbar. Systemfestplatten und geschützte Festplatten werden ausgeblendet.", "No installation information available.": "Keine Installationsinformationen verfügbar.", @@ -2975,6 +3915,7 @@ "No mount point was specified.": "Es wurde kein Mountpunkt angegeben.", "No mount points found in any container": "In keinem Container wurden Mount-Punkte gefunden", "No mount points found in container": "Im Container wurden keine Mountpunkte gefunden", + "No name was given": "Kein Name wurde angegeben", "No network configuration backups found.": "Es wurden keine Sicherungen der Netzwerkkonfiguration gefunden.", "No network interfaces configured (besides loopback)": "Keine Netzwerkschnittstellen konfiguriert (außer Loopback)", "No new Controller/NVMe entries were added.": "Es wurden keine neuen Controller/NVMe-Einträge hinzugefügt.", @@ -2999,9 +3940,11 @@ "No scheduled backup jobs configured.": "Keine geplanten Sicherungsjobs konfiguriert.", "No scheduled backup jobs found.": "Keine geplanten Sicherungsjobs gefunden.", "No scripts found for:": "Keine Skripte gefunden für:", + "No security relaxation is required for the reviewed profile.": "Keine Sicherheitsentspannung ist required für das überprüfte Profil.", "No self-test history found for": "Kein Selbsttestverlauf gefunden für", "No self-test log available for": "Kein Selbsttestprotokoll verfügbar für", "No server IP or hostname provided.": "Keine Server-IP oder Hostname angegeben.", + "No shared media content.": "Keine geteilten Medieninhalte.", "No shared mount detected. Applying standard local access.": "Kein gemeinsamer Mount erkannt. Anwenden des standardmäßigen lokalen Zugriffs.", "No shares configured.": "Keine Freigaben konfiguriert.", "No shares found in smb.conf.": "In smb.conf wurden keine Freigaben gefunden.", @@ -3031,24 +3974,34 @@ "No valid mount points found": "Keine gültigen Mountpunkte gefunden", "No version in this branch is currently supported by keylase/nvidia-patch — the NVENC patch will not reapply after reinstall.": "Derzeit wird keine Version in diesem Zweig von keylase/nvidia-patch unterstützt – der NVENC-Patch wird nach der Neuinstallation nicht erneut angewendet.", "No virtual machines were found on this host.": "Auf diesem Host wurden keine virtuellen Maschinen gefunden.", + "No working NVIDIA GPU was found": "Keine funktionierende NVIDIA GPU gefunden", "No write permissions on:": "Keine Schreibrechte für:", "No, keep local only": "Nein, nur lokal behalten", "No-subscription repository present": "Kein Abonnement-Repository vorhanden", "No: the key stays only at": "Nein: Der Schlüssel bleibt nur bei", + "Node octal permissions (e.g. 0660)": "oktale Knotenberechtigungen (z. B. 0660)", "Non-Debian container detected": "Nicht-Debian-Container erkannt", "Non-free firmware warnings disabled": "Warnungen zu nicht kostenloser Firmware deaktiviert", "None": "Keiner", "Normalizing stable monitor service...": "Der stabile Monitordienst wird normalisiert...", "Not Mounted": "Nicht montiert", + "Not a JSON object:": "Kein JSON-Objekt:", "Not all platforms support Controller/NVMe passthrough reliably.": "Nicht alle Plattformen unterstützen zuverlässig Controller/NVMe-Passthrough.", + "Not all shared directories were verified": "Nicht alle freigegebenen Verzeichnisse wurden verifiziert", "Not an OVH server, skipping RTM installation": "Kein OVH-Server, die RTM-Installation wird übersprungen", "Not currently mounted": "Derzeit nicht gemountet", "Not currently mounted — skipping umount.": "Derzeit nicht gemountet – umount wird übersprungen.", + "Not enough free space for the backup": "Nicht genug freier Speicherplatz für das Backup", "Not found": "Nicht gefunden", + "Not found in the OCI archive:": "Nicht im OCI-Archiv gefunden:", "Not imported:": "Nicht importiert:", "Not mounted": "Nicht montiert", "Not portable:": "Nicht tragbar:", "Not registered as Proxmox storage — use 'LXC Mount Manager' to bind-mount": "Nicht als Proxmox-Speicher registriert – verwenden Sie „LXC Mount Manager“ zum Bind-Mount", + "Not required (access code only)": "Nicht required (nur Zugangscode)", + "Not required (password only)": "Nicht required (nur Passwort)", + "Not required (token only)": "Nicht required (nur Token)", + "Not yet verified by ProxMenux (beta)": "Noch nicht verifiziert durch ProxMenux (beta)", "Note: A system reboot will be required after enabling IOMMU.": "Hinweis: Nach der Aktivierung von IOMMU ist ein Systemneustart erforderlich.", "Note: this only works if the NFS server does NOT use 'all_squash' for root.": "Hinweis: Dies funktioniert nur, wenn der NFS-Server NICHT „all_squash“ als Root verwendet.", "Notes": "Notizen", @@ -3063,8 +4016,20 @@ "Nothing to schedule for reboot from selected paths.": "Für den Neustart von ausgewählten Pfaden ist nichts einzuplanen.", "Nouveau module is loaded, attempting to unload...": "Das Nouveau-Modul ist geladen und versucht zu entladen ...", "Number of CPU cores (default: 2)": "Anzahl der CPU-Kerne (Standard: 2)", + "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources.": "Nzbget ist ein Usenet-Downloader, der in C++ geschrieben und mit Blick auf die Leistung entwickelt wurde, um eine maximale Download-Geschwindigkeit mit sehr wenig Systemressourcen zu erreichen.", + "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra.": "Nzbhydra2 ist eine Meta-Suchanwendung für NZB-Indexer, der geistige Nachfolger von NZBmegasearcH und eine Weiterentwicklung der ursprünglichen Anwendung NZBHydra.", "OCI containers require Proxmox VE 9.1 or later.": "OCI-Container erfordern Proxmox VE 9.1 oder höher.", + "OCI management": "OCI-Verwaltung", + "OCI management could not be completed. Check the backend status; no additional cleanup has been authorized.": "Das OCI-Management konnte nicht abgeschlossen werden. Überprüfen Sie den Backend-Status; es wurde keine zusätzliche Bereinigung autorisiert.", + "OCI manager Apps (beta)": "OCI Manager Apps (Beta)", + "OCI manager Apps is a beta: if something does not work as expected, please report it on GitHub with the application name.": "OCI Manager Apps ist eine Beta: Wenn etwas nicht wie erwartet funktioniert, melden Sie es bitte auf GitHub mit dem Anwendungsnamen.", + "OCI metadata integrity mismatch": "Unstimmigkeiten bei den Metadaten", + "OCI metadata too large": "OCI-Metadaten zu groß", + "OCI stack management": "OCI-Stackmanagement", + "OCI verification failed:": "OCI-Überprüfung fehlgeschlagen:", + "OCR language (Tesseract code)": "OCR-Sprache (Tesseract-Code)", "OK": "OK", + "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms.": "ONLYOFFICE bietet eine vollständige Palette von Tools zum Erstellen, Bearbeiten und Zusammenarbeiten von Textdokumenten, Tabellenkalkulationen, Präsentationen, PDF-Formularen und regulären PDF-Dateien auf Web-, Desktop- und mobilen Plattformen.", "OR add new PVE 9 no-subscription repository:": "ODER neues PVE 9-Repository ohne Abonnement hinzufügen:", "OS hint:": "Hinweis zum Betriebssystem:", "OS release details": "Details zur Betriebssystemversion", @@ -3078,11 +4043,18 @@ "OVH RTM removed (Puppet artefacts may need manual cleanup)": "OVH RTM entfernt (Marionettenartefakte müssen möglicherweise manuell bereinigt werden)", "OVH server detected": "OVH-Server erkannt", "OVH server detection and RTM installation process completed": "OVH-Servererkennung und RTM-Installationsprozess abgeschlossen", + "Observer is not responding on port 4357": "Beobachter reagiert nicht auf Port 4357", + "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption.": "Obsidian ist eine Notiz-App, mit der Sie Ihre Notizen auf Ihrem Gerät erstellen, verknüpfen und organisieren können, mit Hunderten von Plugins und Themes, um Ihren Workflow anzupassen. Sie können Ihre Notizen auch online veröffentlichen, offline darauf zugreifen und sie sicher mit einer End-to-End-Verschlüsselung synchronisieren.", "Offer as exit node?": "Angebot als Exit-Knoten?", + "Official Emby Media Server image with optional VA-API or NVIDIA acceleration.": "Offizielles Emby Media Server Image mit optionaler VA-API oder NVIDIA Beschleunigung.", + "Official Jellyfin image with optional VA-API or NVIDIA acceleration.": "Offizielles Jellyfin Bild mit optionaler VA-API oder NVIDIA Beschleunigung.", "Official Linux Distributions": "Offizielle Linux-Distributionen", + "Official Plex Media Server image with optional hardware transcoding.": "Offizielles Plex Media Server Image mit optionaler Hardware-Transcodierung.", + "Official image": "Offizielles Bild", "Old debian.sources file removed to prevent duplication": "Alte debian.sources-Datei entfernt, um Duplikate zu verhindern", "Old memory configuration detected. Replacing with balanced optimization...": "Alte Speicherkonfiguration erkannt. Ersetzen durch ausgewogene Optimierung...", "Old time services removed successfully": "Alte Dienste erfolgreich entfernt", + "Ombi allows you to host your own Plex Request and user management system.": "Ombi ermöglicht es Ihnen, Ihr eigenes Plex Anfrage- und Benutzerverwaltungssystem zu hosten.", "On a privileged CT the mount options carry the only permissions.": "Bei einem privilegierten CT sind die Mount-Optionen die einzigen Berechtigungen.", "On some systems, when starting the VM the host may slow down for several minutes until it stabilizes, or freeze completely.": "Auf einigen Systemen kann es beim Starten der VM dazu kommen, dass der Host mehrere Minuten lang langsamer wird, bis er sich stabilisiert, oder vollständig einfriert.", "On the Borg server, append the following line to:": "Hängen Sie auf dem Borg-Server die folgende Zeile an:", @@ -3091,32 +4063,53 @@ "Once finished, re-run the script 'PVE 8 to 9 check' to verify that all issues.": "Wenn Sie fertig sind, führen Sie das Skript „PVE 8 to 9 check“ erneut aus, um zu überprüfen, ob alle Probleme vorliegen.", "Once installed, open the VirtIO ISO and run the installer to complete driver setup.": "Öffnen Sie nach der Installation die VirtIO-ISO und führen Sie das Installationsprogramm aus, um die Treibereinrichtung abzuschließen.", "One or more NVIDIA GPUs are currently configured for VM passthrough (vfio-pci):": "Eine oder mehrere NVIDIA-GPUs sind derzeit für VM-Passthrough (vfio-pci) konfiguriert:", + "Online retro games emulator": "Online Retro Spiele Emulator", + "Only a Docker Swarm uses these settings, so they are not applied:": "Nur ein Docker Swarm verwendet diese Einstellungen, so dass sie nicht angewendet werden:", "Only convert to privileged if absolutely necessary for your use case.": "Konvertieren Sie nur dann in privilegiert, wenn dies für Ihren Anwendungsfall unbedingt erforderlich ist.", "Only fully free disks are shown (not system-used and not referenced by VM/LXC).": "Es werden nur vollständig freie Festplatten angezeigt (nicht vom System verwendet und nicht von VM/LXC referenziert).", "Only if using enterprise subscription": "Nur bei Verwendung eines Unternehmensabonnements", "Only if using no-subscription repository": "Nur bei Verwendung eines Repositorys ohne Abonnement", "Only needed if you mounted the filesystem in step 6b": "Wird nur benötigt, wenn Sie das Dateisystem in Schritt 6b gemountet haben", + "Only one image at a time can be installed this way.": "Nur ein Bild auf einmal kann auf diese Weise installiert werden.", "Only removes storage definition, not remote data.": "Entfernt nur die Speicherdefinition, keine Remote-Daten.", "Only run this if you used LVM (step 6b):": "Führen Sie dies nur aus, wenn Sie LVM verwendet haben (Schritt 6b):", "Only the host backup hook is removed — PVE vzdump jobs targeting this storage stay intact.": "Nur der Host-Backup-Hook wird entfernt – PVE-vzdump-Jobs, die auf diesen Speicher abzielen, bleiben intakt.", + "Only the image reference, with no Compose file": "Nur die Bildreferenz, ohne Compose-Datei", "Open": "Offen", + "Open Source realtime backend in 1 file": "Open Source Echtzeit-Backend in 1 Datei", "Open rwx + default inheritance for new files": "Öffnen Sie rwx + Standardvererbung für neue Dateien", + "Open source chat UI for AI models": "Open-Source-Chat-Benutzeroberfläche für AI-Modelle", + "Open source home automation that puts local control and privacy first.": "Open-Source-Hausautomation, bei der lokale Kontrolle und Privatsphäre an erster Stelle stehen.", + "Open source, lightweight, native, supports (HTTP, BitTorrent, Magnet, etc.) for downloading.": "Open Source, lightweight, native, unterstützt (HTTP, BitTorrent, Magnet, etc.) zum Herunterladen.", "Open the VM console and wait for the installer to boot": "Öffnen Sie die VM-Konsole und warten Sie, bis das Installationsprogramm startet", "Open the VM console and wait for the loader to boot": "Öffnen Sie die VM-Konsole und warten Sie, bis der Loader startet", "Open the dashboard from this host on port 8008 to create a new admin account.": "Öffnen Sie das Dashboard von diesem Host auf Port 8008, um ein neues Administratorkonto zu erstellen.", "Open the dashboard to create a new admin account:": "Öffnen Sie das Dashboard, um ein neues Administratorkonto zu erstellen:", + "Open-source AI-powered coding assistant": "Open-Source AI-powered Coding Assistant", + "Open-source UI for building and debugging multi-agent and RAG applications": "Open-Source-Benutzeroberfläche zum Erstellen und Debuggen von Multi-Agenten- und RAG-Anwendungen", + "Open-source self-hosted SQL IDE.": "Open-Source selbst gehostete SQL IDE.", + "OpenClaw is a personal AI assistant you run on your own devices": "OpenClaw ist ein persönlicher KI-Assistent, den Sie auf Ihren eigenen Geräten ausführen", + "OpenList": "OpenList", + "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world.": "OpenShot Video Editor ist ein preisgekrönter kostenloser und Open-Source-Video-Editor für Linux, Mac und Windows und widmet sich der Bereitstellung hochwertiger Videobearbeitungs- und Animationslösungen für die Welt.", + "OpenVINO requires a CPU quota to keep the CPU topology": "OpenVINO requires eine CPU-Quote, um die CPU-Topologie beizubehalten", + "OpenVINO requires the render device of an Intel GPU": "OpenVINO requires das Rendergerät einer Intel GPU", "OpenVSwitch installation could not be verified": "Die OpenVSwitch-Installation konnte nicht überprüft werden", "OpenVSwitch installed successfully": "OpenVSwitch erfolgreich installiert", "OpenVSwitch is ready to use": "OpenVSwitch ist einsatzbereit", "OpenVSwitch removed": "OpenVSwitch entfernt", + "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server.": "Openssh-Server ist eine Sandbox-Umgebung, die ssh-Zugriff ermöglicht, ohne dem gesamten Server Schlüssel zu geben.", + "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser.": "Openvscode-Server bietet eine Version von VS Code, die einen Server auf einem entfernten Computer ausführt und den Zugriff über einen modernen Webbrowser ermöglicht.", + "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features.": "Opera ist ein Multi-Plattform-Webbrowser, der von seinem Namensgeber Opera entwickelt wurde. Der Browser basiert auf Chromium, unterscheidet sich jedoch von anderen Chromium-basierten Browsern (Chrome, Edge usw.) durch seine Benutzeroberfläche und andere Funktionen.", "Operation": "Betrieb", "Operation cancelled by user": "Vorgang vom Benutzer abgebrochen", "Operation cancelled by user to create backup.": "Der Vorgang wurde vom Benutzer abgebrochen, um ein Backup zu erstellen.", "Operation cancelled by user.": "Vorgang vom Benutzer abgebrochen.", + "Operation cancelled.": "Operation abgesagt.", "Operation cancelled. Cannot continue with an unprivileged container.": "Vorgang abgebrochen. Mit einem unprivilegierten Container kann nicht fortgefahren werden.", "Operation log": "Betriebsprotokoll", "Operator config re-applied via kernel-agnostic merge": "Operatorkonfiguration wurde über Kernel-agnostische Zusammenführung erneut angewendet", "Operator config that WILL be re-applied via kernel-agnostic merge": "Operatorkonfiguration, die über eine Kernel-agnostische Zusammenführung erneut angewendet wird", + "Optical block device (e.g. /dev/sr0)": "Optisches Blockgerät (z. B. /dev/sr0)", "Optimizations detected and ready to revert.": "Optimierungen erkannt und können wiederhergestellt werden.", "Optimize": "Optimieren", "Optimize Memory": "Speicher optimieren", @@ -3129,8 +4122,12 @@ "Optimizing network settings...": "Netzwerkeinstellungen optimieren...", "Optimizing vzdump backup speed...": "Optimierung der vzdump-Backup-Geschwindigkeit...", "Optional": "Optional", + "Optional GID of the plex group": "Optionale GID der plex-Gruppe", "Optional GPU Passthrough": "Optionaler GPU-Passthrough", + "Optional published URL for Jellyfin": "Optional veröffentlichte URL für Jellyfin", "Optional safety helper if you ever need to re-apply manually:": "Optionaler Sicherheitshelfer, falls Sie jemals manuell erneut anwenden müssen:", + "Optional token from https://www.plex.tv/claim": "Fakultativer Token von https://www.plex.tv/claim", + "Optional, not mounted by default": "Optional, nicht standardmäßig montiert", "Optional: Modernize repository sources:": "Optional: Repository-Quellen modernisieren:", "Optional: apply default ACL so new files inherit permissions:": "Optional: Standard-ACL anwenden, damit neue Dateien Berechtigungen erben:", "Optional: register this path as Proxmox dir storage:": "Optional: Registrieren Sie diesen Pfad als Proxmox-Verzeichnisspeicher:", @@ -3141,13 +4138,18 @@ "Or re-run this script and accept the 'apply host permissions' prompt.": "Oder führen Sie dieses Skript erneut aus und akzeptieren Sie die Eingabeaufforderung „Hostberechtigungen anwenden“.", "Or use ProxMenux update function": "Oder verwenden Sie die Update-Funktion von ProxMenux", "Or, if your terminal can't select text, copy it from:": "Oder, wenn Ihr Terminal keinen Text auswählen kann, kopieren Sie ihn von:", + "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community": "Orca Slicer ist ein Open Source Slicer für FDM-Drucker. OrcaSlicer ist fork von Bambu Studio, es war früher als BambuStudio-SoftFever bekannt, Bambu Studio ist forked von PrusaSlicer von Prusa Research, das von Slic3r von Alessandro Ranellucci und der RepRap-Community stammt.", "Original ZFS ARC config restored from .bak": "Ursprüngliche ZFS ARC-Konfiguration aus .bak wiederhergestellt", "Original bashrc restored": "Original-Bashrc restauriert", "Original logrotate configuration restored": "Ursprüngliche Logrotate-Konfiguration wiederhergestellt", + "Orphan stack contract archived:": "Orphan Stack Vertrag archiviert:", + "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.": "Oscam ist eine Open Source Conditional Access Module Software, die zum Entschlüsseln von DVB transmissions mit Chipkarten verwendet wird. Es ist sowohl ein Server als auch ein Client.", "Other Prebuilt Linux VMs": "Andere vorgefertigte Linux-VMs", "Output archive:": "Ausgabearchiv:", + "Overseerr is a request management and media discovery tool built to work with your existing Plex ecosystem.": "Overseerr ist ein Anforderungsmanagement- und Medienerkennungstool, das für die Arbeit mit Ihrem bestehenden Plex-Ökosystem entwickelt wurde.", "Owner:": "Eigentümer:", "Ownership set to root:sharedfiles with 2775 on:": "Eigentümerschaft auf root:sharedfiles mit 2775 gesetzt auf:", + "P2P bittorrent download": "P2P Bittorrent Download", "PAM limits configured": "PAM-Grenzwerte konfiguriert", "PBS API log rotation configured (hourly, size-based)": "PBS-API-Protokollrotation konfiguriert (stündlich, größenbasiert)", "PBS backup error log": "PBS-Backup-Fehlerprotokoll", @@ -3164,7 +4166,9 @@ "PCI reset method": "PCI-Reset-Methode", "PCIe GPU passthrough requires:": "PCIe-GPU-Passthrough erfordert:", "PCIe/M.2 gasket-dkms": "PCIe/M.2 gasket-dkms", + "PCSX2 is an open source PS2 Emulator.": "PCSX2 ist ein Open Source PS2 Emulator.", "POSIX ACLs applied (access + default for inheritance).": "POSIX-ACLs angewendet (Zugriff + Standard für Vererbung).", + "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability.": "PPSSPP ist ein kostenloser und Open-Source-SP-Emulator für Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series und Symbian mit Schwerpunkt auf Geschwindigkeit und Portabilität.", "PVE application manager updated": "PVE-Anwendungsmanager aktualisiert", "PVE cache regenerated": "PVE-Cache neu generiert", "PVE host (where the Borg LXC lives)": "PVE-Host (wo der Borg LXC lebt)", @@ -3179,17 +4183,28 @@ "Package update had issues, checking details...": "Bei der Paketaktualisierung gab es Probleme, beim Überprüfen der Details ...", "Packages from backup to install:": "Pakete vom Backup zur Installation:", "Packages installed: {count}.": "Installierte Pakete: {count}.", + "Packages to be upgraded": "Aufzurüstende Pakete", "Packages upgrade successfull": "Paketaktualisierung erfolgreich", "Packages upgraded": "Pakete aktualisiert", "Packages:": "Pakete:", "Packaging OVA file...": "OVA-Datei verpacken...", "Packing installer archive...": "Installationsarchiv packen...", + "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices.": "PairDrop ist eine großartige Alternative zu AirDrop, die auf allen Plattformen funktioniert. Senden Sie Bilder, Dokumente oder Text per Peer-to-Peer-Verbindung an Geräte im gleichen lokalen Netzwerk / WLAN oder an gekoppelte Geräte.", + "Paperless configuration cancelled": "Papierlose Konfiguration abgesagt", + "Paperless-ngx WebUI": "Paperless-ngx WebUI", "Parsing OVF descriptor...": "OVF-Deskriptor wird geparst...", "Partial VM removed": "Teilweise VM entfernt", "Partition": "Partition", "Partition created": "Partition erstellt", "Partition created:": "Partition erstellt:", "Partition table wiped": "Partitionstabelle gelöscht", + "Pass /dev/kvm to the LXC": "Pass /dev/kvm zum LXC", + "Pass /dev/net/tun to the LXC": "Pass /dev/net/tun zum LXC", + "Pass /dev/ttyUSB0 to the LXC": "Pass /dev/ttyUSB0 zum LXC", + "Pass /dev/video10 to the LXC": "Pass /dev/video10 zum LXC", + "Pass /dev/video11 to the LXC": "Pass /dev/video11 zum LXC", + "Pass /dev/video12 to the LXC": "Pass /dev/video12 zum LXC", + "Pass a host device to the LXC": "Übergeben Sie ein Host-Gerät an den LXC", "Passphrase used to unlock the imported keyfile (leave blank if the keyfile is unencrypted / kdf=none):": "Passphrase, die zum Entsperren der importierten Schlüsseldatei verwendet wird (leer lassen, wenn die Schlüsseldatei unverschlüsselt ist / kdf=none):", "Passphrases do not match.": "Passphrasen stimmen nicht überein.", "Passphrases do not match. Try again.": "Passphrasen stimmen nicht überein. Versuchen Sie es erneut.", @@ -3202,17 +4217,42 @@ "Password confirmation cannot be empty.": "Die Passwortbestätigung darf nicht leer sein.", "Password confirmation is required.": "Eine Passwortbestätigung ist erforderlich.", "Password for": "Passwort für", + "Password for aMule external connections (remote client)": "Passwort für aMule externe Verbindungen (Remote Client)", + "Password for the SSH login": "Passwort für den SSH Login", "Password for:": "Passwort für:", "Password is correct": "Das Passwort ist korrekt", + "Password of the AdGuard Home that receives the settings": "Passwort des AdGuard Home, das die Einstellungen erhält", + "Password of the Adguardhome Sync web interface": "Passwort des Adguardhome Sync Webinterfaces", + "Password of the Duplicati web interface": "Passwort des Duplicati Webinterfaces", + "Password of the Etherpad admin user": "Passwort des Etherpad-Admin-Benutzers", + "Password of the FlexGet web interface": "Passwort des FlexGet Webinterfaces", + "Password of the LibreDB Studio administrator": "Passwort des LibreDB Studio-Administrators", + "Password of the MineOS web interface user": "Kennwort des MineOS Web Interface User", + "Password of the NetBox admin account": "Passwort des NetBox Admin Accounts", + "Password of the OpenList admin user": "Passwort des OpenList-Admin-Benutzers", + "Password of the PhotoPrism admin user (at least 8 characters)": "Passwort des PhotoPrism-Admin-Benutzers (mindestens 8 Zeichen)", + "Password of the PostgreSQL user": "Passwort des PostgreSQL-Benutzers", + "Password of the SnapOtter admin user": "Passwort des SnapOtter-Admin-Benutzers", + "Password of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Passwort des veralteten Flowise-Anwendungs-Logins (nur von Flowise-Versionen vor 3.0.1) gelesen", + "Password of the main AdGuard Home": "Passwort des Haupt-AdGuard Home", "Password or API token secret:": "Passwort oder API-Token-Geheimnis:", + "Password or secret": "Passwort oder Geheimnis", "Password reset completed.": "Passwort-Reset abgeschlossen.", + "Password to access the aMule web interface": "Passwort für den Zugriff auf das aMule Webinterface", "Passwords do not match. Please try again.": "Passwörter stimmen nicht überein. Bitte versuchen Sie es erneut.", + "Paste it here and press Ctrl+D on an empty line.": "Fügen Sie es hier ein und drücken Sie Strg + D auf einer leeren Linie.", + "Paste its Compose file in the terminal": "Fügen Sie seine Compose-Datei in das Terminal ein", + "Paste its docker run command in the terminal": "Fügen Sie seinen docker-Laufbefehl in das Terminal ein", "Paste the UUP Dump URL here": "Fügen Sie hier die UUP-Dump-URL ein", "Patching source for kernel compatibility...": "Patch-Quelle für Kernel-Kompatibilität...", "Path does not exist.": "Pfad existiert nicht.", + "Path inside the container": "Weg innerhalb des Behälters", + "Path inside the container (e.g. /media-extra)": "Pfad innerhalb des Containers (z. B. /media-extra)", + "Path inside the remote (empty = root)": "Pfad innerhalb der Fernbedienung (leer = root)", "Path must be absolute (start with /)": "Der Pfad muss absolut sein (mit / beginnen)", "Path must be absolute (start with /).": "Der Pfad muss absolut sein (beginnen Sie mit /).", "Path not found": "Pfad nicht gefunden", + "Path of the Compose file": "Pfad der Compose-Datei", "Path:": "Weg:", "Paths applied:": "Angewandte Pfade:", "Paths included in backup": "Im Backup enthaltene Pfade", @@ -3220,6 +4260,10 @@ "Paths skipped:": "Übersprungene Pfade:", "Paths to back up:": "Zu sichernde Pfade:", "Paths:": "Pfade:", + "Peers reach the server through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Peers erreichen den Server über die öffentliche Adresse und den während der Installation angegebenen UDP-Port, so dass der Port an diesen Container weitergeleitet werden muss.", + "Peers to create: a number (3) or a list of names (phone,laptop)": "Peers zu erstellen: eine Zahl (3) oder eine Liste von Namen (Telefon, Laptop)", + "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration.": "Pelorus ist ein KI-Navigator für Selkies-basierte Linux-Desktops. Pelorus betreibt einen FastAPI-Server, der einem LLM-Agenten (Ollama, OpenAI-kompatibel oder Gemini) die Kontrolle über Maus-, Tastatur-, Screenshot- und Fensterverwaltung über das Pixelflux-Computer-Use-Backend, einen Linux-Zugänglichkeitsbaum (AT-SPI) und optionale KWin D-Bus-Integration gibt.", + "Pending components:": "Ausstehende Komponenten:", "Pending restore ID:": "Ausstehende Wiederherstellungs-ID:", "Pending restore dir:": "Ausstehendes Wiederherstellungsverzeichnis:", "Pending restore prepared. A reboot is required to complete it.": "Ausstehende Wiederherstellung vorbereitet. Zum Abschließen ist ein Neustart erforderlich.", @@ -3243,7 +4287,15 @@ "Permission error": "Berechtigungsfehler", "Permissions:": "Berechtigungen:", "Persist mount in CT /etc/fstab (optional):": "Mounten in CT /etc/fstab beibehalten (optional):", + "Persistence for": "Beharrlichkeit für", + "Persistence for the new path": "Beharrlichkeit für den neuen Weg", + "Persistent data:": "Dauerhafte Daten:", + "Persistent disk reused:": "Wiederverwendete Dauerscheiben:", "Persistent:": "Hartnäckig:", + "Personal finance management application": "Persönliche Finanzverwaltung Anwendung", + "Photo and video library with optional GPU transcoding and machine learning": "Foto- und Videobibliothek mit optionaler GPU-Transcodierung und maschinellem Lernen", + "PhotoPrism": "PhotoPrism", + "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB.": "Phpmyadmin ist ein in PHP geschriebenes kostenloses Software-Tool, das die Verwaltung von MySQL über das Web übernehmen soll. phpMyAdmin unterstützt eine breite Palette von operationen auf MySQL und MariaDB.", "Physical Function with": "Körperliche Funktion mit", "Physical interface": "Physische Schnittstelle", "Physical interfaces available": "Physikalische Schnittstellen verfügbar", @@ -3256,6 +4308,10 @@ "Pick a target to remove:": "Wählen Sie ein Ziel zum Entfernen aus:", "Pick an SSH private key (auto-detected on this host):": "Wählen Sie einen privaten SSH-Schlüssel (wird auf diesem Host automatisch erkannt):", "Pick an alternative way to authorize the new key:": "Wählen Sie eine alternative Möglichkeit zur Autorisierung des neuen Schlüssels:", + "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time.": "Pidgin ist ein Chat-Programm, mit dem Sie sich gleichzeitig in Konten in mehreren Chat-Netzwerken anmelden können. Dies bedeutet, dass sie mit freunden auf xmpp chatten und gleichzeitig in einem irc-kanal sitzen können.", + "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper.": "Piper ist ein schnelles, lokales neuronales Text-zu-Sprache-System, das gut klingt und für den Raspberry Pi 4 optimiert ist. Dieser Container bietet einen Wyoming-Protokollserver für Piper.", + "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures.": "Piwigo ist eine Fotogalerie-Software für das Web, die mit leistungsstarken Funktionen zur Veröffentlichung und Verwaltung Ihrer Bildersammlung ausgestattet ist.", + "Planka is an elegant open source project tracking tool.": "Planka ist ein elegantes Open Source Projekt-Tracking-Tool.", "Please check network connectivity.": "Bitte überprüfen Sie die Netzwerkkonnektivität.", "Please check permissions and try again.": "Bitte überprüfen Sie die Berechtigungen und versuchen Sie es erneut.", "Please check the installation.": "Bitte überprüfen Sie die Installation.", @@ -3273,6 +4329,10 @@ "Please select GPU(s) that are currently in the same mode and try again.": "Bitte wählen Sie GPU(s) aus, die sich derzeit im gleichen Modus befinden, und versuchen Sie es erneut.", "Please select a valid option": "Bitte wählen Sie eine gültige Option aus", "Please use an SSH session (Linux, macOS, Windows/PuTTY) or a physical console to perform the upgrade.": "Bitte verwenden Sie eine SSH-Sitzung (Linux, macOS, Windows/PuTTY) oder eine physische Konsole, um das Upgrade durchzuführen.", + "Plex WebUI": "Plex WebUI", + "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.": "Plex organisiert Videos, Musik und Fotos aus persönlichen Medienbibliotheken und streamt sie auf Smart-TVs, Streaming-Boxen und mobile Geräte. Dieser Container ist als eigenständiger Plex Media Server verpackt. Einfaches Design und umfangreiche Aktionen bedeuten, dass Dinge schneller erledigt werden.", + "PocketBase admin UI": "PocketBase Administrator UI", + "Podcast synchronization service": "Podcast Synchronisation", "Pool does not appear to use SSD/NVMe devices with discard support. Skipping ZFS autotrim for pool:": "Der Pool scheint keine SSD/NVMe-Geräte mit Discard-Unterstützung zu verwenden. ZFS-Autotrim für Pool überspringen:", "Pool exists": "Pool vorhanden", "Pool name matches but GUID differs (fresh ZFS install):": "Poolname stimmt überein, aber GUID unterscheidet sich (neue ZFS-Installation):", @@ -3283,12 +4343,21 @@ "Portal IP and port are correct": "Portal-IP und Port sind korrekt", "Portal is reachable": "Portal ist erreichbar", "Portal:": "Portal:", + "Ports": "Häfen", "Portuguese": "Portugiesisch", "Post-Installation Options": "Optionen nach der Installation", "Post-Installation Scripts": "Skripte nach der Installation", "Postfix configuration": "Postfix-Konfiguration", + "PostgreSQL": "PostgreSQL", + "PostgreSQL URL without an associated service:": "PostgreSQL URL ohne zugehörigen Dienst:", + "PostgreSQL creates the database named in POSTGRES_DB on the first start. The installer default is postgresql.": "PostgreSQL erstellt beim ersten Start die in POSTGRES DB genannte Datenbank. Der Installer ist standardmäßig postgresql.", + "PostgreSQL is an advanced, enterprise-class, and open-source relational database system. PostgreSQL supports both SQL (relational) and JSON (non-relational) querying.": "PostgreSQL ist ein fortschrittliches, Enterprise-Klasse und Open-Source relationale Datenbanksystem. PostgreSQL unterstützt sowohl SQL (relational) als auch JSON (non-relational) Abfragen.", + "PostgreSQL requires a password": "PostgreSQL requires ein Passwort", + "PostgreSQL volume size in GB": "PostgreSQL Volumengröße in GB", "Potential QEMU startup/assertion failures": "Potenzielle QEMU-Start-/Behauptungsfehler", "Power state D3cold/D0 transitions may be inaccessible": "Auf die Übergänge des Energiezustands D3cold/D0 kann möglicherweise nicht zugegriffen werden", + "Powerful OCR powered by DeepSeek AI": "Leistungsstarke OCR powered by DeepSeek AI", + "Powerful networking tool": "Leistungsstarkes Netzwerk-Tool", "Pre-check found": "Vorabprüfung gefunden", "Pre-configure destinations so you don't have to enter them every time you back up.": "Konfigurieren Sie Ziele vorab, damit Sie sie nicht bei jedem Backup erneut eingeben müssen.", "Pre-existing gasket-dkms package removed.": "Vorhandenes „gasket-dkms“-Paket entfernt.", @@ -3296,11 +4365,15 @@ "Pre-upgrade check FAILED: the simulation shows that 'proxmox-ve' would be REMOVED.\n This indicates a repository or dependency issue and upgrading now could break your Proxmox installation.": "Überprüfung vor dem Upgrade fehlgeschlagen: Die Simulation zeigt, dass „proxmox-ve“ ENTFERNT würde.\n Dies weist auf ein Repository- oder Abhängigkeitsproblem hin und ein Upgrade jetzt könnte Ihre Proxmox-Installation beschädigen.", "Pre-upgrade simulation failed. See log:": "Die Simulation vor dem Upgrade ist fehlgeschlagen. Siehe Protokoll:", "Pre-upgrade simulation passed: 'proxmox-ve' will be kept or upgraded safely.": "Simulation vor dem Upgrade bestanden: „proxmox-ve“ wird sicher beibehalten oder aktualisiert.", + "Prepared; the container was not modified yet": "Vorbereitet; der Container wurde noch nicht modifiziert", "Preparing Log2RAM configuration": "Vorbereiten der Log2RAM-Konfiguration", "Preparing files for backup...": "Dateien werden für die Sicherung vorbereitet...", "Preparing host mount...": "Host-Mount wird vorbereitet...", "Preparing pending restore (network-safe)": "Ausstehende Wiederherstellung vorbereiten (netzwerksicher)", "Preparing staging area...": "Bereitstellungsbereich wird vorbereitet...", + "Preparing the NVIDIA GPU...": "Vorbereitung der NVIDIA GPU...", + "Preparing the recreation...": "Vorbereitung der Erholung...", + "Preparing the update...": "Vorbereitung des Updates...", "Preserving logs to /var/log.hdd before unmounting...": "Protokolle werden vor dem Aufheben der Bereitstellung in /var/log.hdd beibehalten ...", "Press 'q' to exit": "Drücken Sie „q“, um den Vorgang zu beenden", "Press Ctrl+C to stop the server and return to menu.": "Drücken Sie Strg+C, um den Server zu stoppen und zum Menü zurückzukehren.", @@ -3316,6 +4389,7 @@ "Press Enter to return": "Drücken Sie die Eingabetaste, um zurückzukehren", "Press Enter to return to menu...": "Drücken Sie die Eingabetaste, um zum Menü zurückzukehren...", "Press Enter to return to the main menu...": "Drücken Sie die Eingabetaste, um zum Hauptmenü zurückzukehren...", + "Press Enter to return to the menu...": "Drücken Sie Enter, um zum Menü zurückzukehren ...", "Press Enter to return...": "Drücken Sie die Eingabetaste, um zurückzukehren...", "Press Enter when the line has been pasted on the server...": "Drücken Sie die Eingabetaste, wenn die Zeile auf dem Server eingefügt wurde ...", "Press OK to see the preview, then confirm": "Drücken Sie OK, um die Vorschau anzuzeigen, und bestätigen Sie dann", @@ -3325,9 +4399,20 @@ "Preview changes (diff)": "Vorschau der Änderungen (Unterschiede)", "Preview: changes that would be applied": "Vorschau: Änderungen, die angewendet würden", "Previous DKMS tree cleared.": "Vorheriger DKMS-Baum gelöscht.", + "Previous Rclone configuration restored": "Rclone-Konfiguration wiederhergestellt", "Previous installation cleaned": "Vorherige Installation gereinigt", "Previous installation removed": "Vorherige Installation entfernt", + "Previous installation restored": "Frühere Installation wiederhergestellt", "Previous shutdowns": "Frühere Abschaltungen", + "Primary GID for Emby": "Primäre GID für Emby", + "Privacy-first finance app with envelope budgeting and multi-device sync.": "Privacy-First Finance App mit Umschlag budgeting und Multi-Device-Sync.", + "Privacy-first, self-hosted PDF toolkit": "Privacy-First, selbst gehostetes PDF-Toolkit", + "Private installation record saved": "Private Installationsaufzeichnung gespeichert", + "Private network assigned automatically:": "Privates Netzwerk automatisch zugewiesen:", + "Private network of the application released:": "Privates Netzwerk der Anwendung freigegeben:", + "Private network of the application that is released:": "Privates Netzwerk der Anwendung, die freigegeben wird:", + "Private network:": "Privates Netzwerk:", + "Private personal knowledge management": "Privates persönliches Wissensmanagement", "Privileged": "Privilegiert", "Privileged Container": "Privilegierter Container", "Privileged Container Required": "Privilegierter Container erforderlich", @@ -3338,6 +4423,7 @@ "Privileged container — host root maps directly, no permission changes needed": "Privilegierter Container – Root-Maps direkt hosten, keine Berechtigungsänderungen erforderlich", "Privileged containers can access host devices directly": "Privilegierte Container können direkt auf Hostgeräte zugreifen", "Privileged containers have full root access to the host system!": "Privilegierte Container haben vollen Root-Zugriff auf das Hostsystem!", + "Privileged installation declined": "Privilegierte Installation abgelehnt", "Privileged: Full host access (less secure)": "Privilegiert: Vollständiger Hostzugriff (weniger sicher)", "Proceed": "Fortfahren", "Proceed with removal": "Fahren Sie mit der Entfernung fort", @@ -3346,11 +4432,15 @@ "Process may take several minutes depending on container size": "Der Vorgang kann je nach Behältergröße mehrere Minuten dauern", "Process may take several minutes for large containers": "Bei großen Behältern kann der Vorgang mehrere Minuten dauern", "Processes using NVIDIA:": "Prozesse mit NVIDIA:", + "Productivity & Workflows": "Produktivität & Workflows", "Profile": "Profil", "Profile:": "Profil:", + "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files.": "Projectsend ist eine selbst gehostete Anwendung, mit der Sie Dateien hochladen und bestimmten Clients zuweisen können, die Sie selbst erstellen. Sicher, privat und einfach. Nicht mehr abhängig von externen Diensten oder E-Mail, um diese Dateien zu senden.", "Proposed Changes": "Vorgeschlagene Änderungen", "Proposed ZFS ARC maximum:": "Vorgeschlagenes ZFS ARC-Maximum:", "Provided by newer version — skipping": "Wird von einer neueren Version bereitgestellt – wird übersprungen", + "Prowlarr does not offer the application schema:": "Prowlarr bietet das Anwendungsschema nicht an:", + "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all).": "Prowlarr ist ein Indexer-Manager / Proxy, der auf dem beliebten arr .net / reactjs-Basisstack zur Integration in Ihre verschiedenen PVR-Apps basiert. Prowlarr unterstützt sowohl Torrent Tracker als auch Usenet Indexer. Es integriert sich nahtlos in Sonarr, Radarr, Lidarr und Readarr und bietet eine vollständige Verwaltung Ihrer Indexer ohne App-Indexer-Setup required (wir machen alles).", "ProxMenux Information": "ProxMenux-Informationen", "ProxMenux Monitor": "ProxMenux Monitor", "ProxMenux Monitor Service Verification": "Überprüfung des ProxMenux Monitor-Dienstes", @@ -3364,10 +4454,12 @@ "ProxMenux Monitor protection": "ProxMenux Monitorschutz", "ProxMenux Monitor unit repaired and restarted": "ProxMenux Monitor-Einheit repariert und neu gestartet", "ProxMenux Monitor → Backups tab (live progress card with estimated time, logs, rollback delta)": "ProxMenux Monitor → Registerkarte „Backups“ (Live-Fortschrittskarte mit geschätzter Zeit, Protokollen, Rollback-Delta)", + "ProxMenux attaches directories, not single files, so this image cannot be installed yet.": "ProxMenux verbindet Verzeichnisse, nicht einzelne Dateien, so dass dieses Bild noch nicht installiert werden kann.", "ProxMenux can apply open permissions on this NFS directory from the host so the container can read and write:": "ProxMenux kann vom Host aus Öffnungsberechtigungen für dieses NFS-Verzeichnis anwenden, sodass der Container lesen und schreiben kann:", "ProxMenux can remount it with open permissions so any LXC can read and write.": "ProxMenux kann es mit offenen Berechtigungen erneut bereitstellen, sodass jeder LXC lesen und schreiben kann.", "ProxMenux cannot override NFS server-side permissions from the host.": "ProxMenux kann serverseitige NFS-Berechtigungen vom Host nicht überschreiben.", "ProxMenux customizations removed from bashrc": "ProxMenux-Anpassungen aus bashrc entfernt", + "ProxMenux does not give a container the system of its host.": "ProxMenux gibt einem Container nicht das System seines Hosts.", "ProxMenux does not validate the contents; any keyfile your PBS accepts is accepted here.": "ProxMenux validiert den Inhalt nicht;Jede von Ihrem PBS akzeptierte Schlüsseldatei wird hier akzeptiert.", "ProxMenux files:": "ProxMenux-Dateien:", "ProxMenux logo applied": "ProxMenux-Logo angewendet", @@ -3399,6 +4491,7 @@ "Proxmox repository configuration completed": "Konfiguration des Proxmox-Repositorys abgeschlossen", "Proxmox repository fixed (no-subscription, candidate is 9.x)": "Proxmox-Repository behoben (kein Abonnement, Kandidat ist 9.x)", "Proxmox status:": "Proxmox-Status:", + "Proxmox storage for the volume": "Proxmox Speicher für das Volumen", "Proxmox storages:": "Proxmox-Speicher:", "Proxmox system repair completed successfully!": "Proxmox-Systemreparatur erfolgreich abgeschlossen!", "Proxmox system repair completed with some issues.": "Die Reparatur des Proxmox-Systems wurde mit einigen Problemen abgeschlossen.", @@ -3408,10 +4501,21 @@ "Proxmox web interface: Datacenter > Storage > Add > SMB/CIFS": "Proxmox-Weboberfläche: Rechenzentrum > Speicher > Hinzufügen > SMB/CIFS", "Proxmox web interface: Datacenter > Storage > Add > ZFS": "Proxmox-Weboberfläche: Datencenter > Speicher > Hinzufügen > ZFS", "Proxmox web interface: Datacenter > Storage > Add > iSCSI": "Proxmox-Weboberfläche: Rechenzentrum > Speicher > Hinzufügen > iSCSI", + "Public UDP port clients connect to": "Öffentliche UDP Port Clients verbinden sich mit", + "Public UDP port peers connect to": "Öffentliche UDP-Port Peers verbinden sich mit", + "Public URL of phpMyAdmin when it is served behind a reverse proxy": "Öffentliche URL von phpMyAdmin, wenn sie hinter einem Reverse-Proxy bereitgestellt wird", + "Public address clients connect to (vpn.example.com or a public IP)": "Öffentliche Adress-Clients verbinden sich mit (vpn.example.com oder eine öffentliche IP)", + "Public address peers connect to, or auto to detect it (vpn.example.com)": "Public Adress Peers verbinden, oder Auto, um es zu erkennen (vpn.example.com)", "Pulling latest changes from GitHub...": "Aktuelle Änderungen von GitHub abrufen...", "Purge the gasket-dkms package": "gasket-dkms-Paket vollständig entfernen", "Purging gasket-dkms package...": "gasket-dkms-Paket wird vollständig entfernt ...", "Purging log2ram apt package...": "Log2ram-Apt-Paket wird gelöscht...", + "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.": "Pwndrop ist ein selbst einsetzbarer Dateihosting-Service zum Senden von roten Teaming-Nutzlasten oder zum sicheren Teilen Ihrer privaten Dateien über HTTP und WebDAV.", + "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more.": "PyCharm bietet Out-of-the-Box-Unterstützung für Python, Datenbanken, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI und mehr.", + "Pydio Cells needs an external MySQL or MariaDB database. The setup wizard asks for its address, database name and user on the first start.": "Pydio Cells benötigt eine externe MySQL- oder MariaDB-Datenbank. Der Setup-Assistent fragt beim ersten Start nach Adresse, Datenbankname und Benutzer.", + "Pydio Cells redirects to the address given in EXTERNALURL. If the container changes address, edit lxc.environment.runtime: EXTERNALURL and SERVER_IP in /etc/pve/lxc/.conf with the container stopped, and delete /config/keys/cert.crt to regenerate the certificate.": "Pydio Cells leitet an die in EXTERNALURL angegebene Adresse weiter. Wenn der Container die Adresse ändert, bearbeiten Sie lxc.environment.runtime: EXTERNALURL und SERVER IP in /etc/pve/lxc/.conf mit dem gestoppten Container und löschen Sie /config/keys/cert.crt, um das Zertifikat zu regenerieren.", + "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture.": "Pydio-cells ist die Nextgen File-Sharing-Plattform für Unternehmen. Es ist eine vollständige Neufassung des Pydio-Projekts mit der Go-Sprache nach einer Micro-Service-Architektur.", + "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat.": "QDirStat Qt-basierte Verzeichnisstatistik: KDirStat ohne KDE - vom Autor des ursprünglichen KDirStat.", "Quick health check (PASSED / FAILED)": "Schneller Gesundheitscheck (bestanden / nicht bestanden)", "Quick health status — overall SMART result + key attributes": "Schneller Gesundheitszustand – Gesamt-SMART-Ergebnis + Schlüsselattribute", "RAID Detected": "RAID erkannt", @@ -3425,9 +4529,26 @@ "RPC Bind Service: RUNNING": "RPC-Bindungsdienst: LÄUFT", "RPC Bind Service: STOPPED": "RPC-Bindungsdienst: BEENDET", "RPC Bind Service: STOPPED - starting...": "RPC-Bindungsdienst: GESTOPPT – startet...", + "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD.": "RPCS3 ist ein Multi-Plattform-Open-Source Sony PlayStation 3 Emulator und Debugger in C++ für Windows, Linux, macOS und FreeBSD geschrieben.", + "Radarr - A fork of Sonarr to work with movies à la Couchpotato.": "Radarr - Ein fork von Sonarr, um mit Filmen à la Couchpotato zu arbeiten.", + "Radarr added to Prowlarr": "Radarr wird zu Prowlarr hinzugefügt", + "Radarr connected to qBittorrent": "Radarr mit qBittorrent verbunden", + "Radarr root folder configured": "Radarr Wurzelordner konfiguriert", + "RagFlow is an open-source RAG engine based on deep document understanding.": "RagFlow ist eine Open-Source-RAG-Engine, die auf einem tiefen Dokumentenverständnis basiert.", + "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase.": "Raneto - ist eine Open-Source-Knowledgebase-Plattform, die statische Markdown-Dateien verwendet, um Ihre Knowledgebase zu betreiben.", + "Raneto web interface": "Raneto Web-Schnittstelle", + "RawTherapee is a free, cross-platform raw image processing program!": "RawTherapee ist ein kostenloses, plattformübergreifendes Rohbildverarbeitungsprogramm!", + "Rclone WebUI": "Rclone WebUI", + "Rclone mount": "Klonhalterung", + "Rclone mount active": "Rklonmontage aktiv", + "Rclone mount needs a privileged LXC with FUSE access. The container is dedicated to Rclone and its web UI must not be exposed to untrusted networks.": "Rclone Mount benötigt einen privilegierten LXC mit FUSE-Zugang. Der Container ist Rclone gewidmet und seine Web-Benutzeroberfläche darf nicht nicht vertrauenswürdigen Netzwerken ausgesetzt sein.", + "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network.": "Rclone Mount requires eine privilegierte LXC mit FUSE-Zugang. Verwenden Sie dieses Profil nur auf einem vertrauenswürdigen Knoten und Netzwerk.", + "Rclone mount requires a privileged container": "Rclone Mount requires ein privilegierter Container", "Re-enter the BORG REPOKEY passphrase to confirm:": "Geben Sie die BORG REPOKEY-Passphrase erneut ein, um zu bestätigen:", "Re-running pre-check after repairs...": "Nach der Reparatur wird die Vorkontrolle erneut durchgeführt...", "Reachable": "Erreichbar", + "Read its Compose file from a file of this host": "Lesen Sie die Compose-Datei aus einer Datei dieses Hosts", + "Read the link with pct console CTID on the Proxmox host, or from the Console panel of the container in the Proxmox web interface, then open the https://playit.gg/claim/ address it shows in a browser and sign in to playit.gg. Ctrl+a q leaves pct console.": "Lesen Sie den Link mit pct-Konsole CTID auf dem Proxmox-Host oder vom Konsolen-Panel des Containers in der Proxmox-Weboberfläche, öffnen Sie dann die https://playit.gg/claim/Adresse, die in einem Browser angezeigt wird, und melden Sie sich bei playit.gg an. Strg + a q verlässt pct Konsole.", "Read-Only": "Schreibgeschützt", "Read-Only access": "Nur lesender Zugriff", "Read-Write (universal)": "Lesen/Schreiben (universell)", @@ -3436,6 +4557,7 @@ "Read-only access (or no write permissions).": "Nur-Lese-Zugriff (oder keine Schreibberechtigungen).", "Read-only mount": "Schreibgeschützter Mount", "Read/Write (default)": "Lesen/Schreiben (Standard)", + "Read/write": "Lesen/Schreiben", "Read/write CPU model-specific registers": "CPU-modellspezifische Register lesen/schreiben", "Readable user table (UID, shell, etc.)": "Lesbare Benutzertabelle (UID, Shell usw.)", "Reading NVMe SMART data...": "NVMe SMART-Daten werden gelesen...", @@ -3443,7 +4565,9 @@ "Reading SMART data...": "SMART-Daten werden gelesen...", "Reading SMART self-test log...": "SMART-Selbsttestprotokoll wird gelesen...", "Reading full SMART report...": "Vollständigen SMART-Bericht lesen...", + "Real-time Performance Monitoring": "Echtzeit-Leistungsüberwachung", "Real-time bandwidth usage (press q to exit)": "Echtzeit-Bandbreitennutzung (zum Beenden q drücken)", + "Real-time collaborative document editor": "Echtzeit-Collaborative Document Editor", "Real-time network monitoring (press q to exit)": "Echtzeit-Netzwerküberwachung (zum Beenden q drücken)", "Real-time network usage (iftop)": "Netzwerknutzung in Echtzeit (iftop)", "Reason: Access denied": "Grund: Zugriff verweigert", @@ -3465,6 +4589,7 @@ "Recent Samba server": "Aktueller Samba-Server", "Recent logs:": "Aktuelle Protokolle:", "Recent test results:": "Aktuelle Testergebnisse:", + "Recognition profile not implemented": "Anerkennungsprofil nicht umgesetzt", "Recommendation: reformat the disk to ext4 for a robust setup — see docs.": "Empfehlung: Formatieren Sie die Festplatte für ein stabiles Setup auf ext4 neu – siehe Dokumentation.", "Recommendation: start with Complete restore.": "Empfehlung: Beginnen Sie mit der vollständigen Wiederherstellung.", "Recommendation: use 'Export to file' for these paths and apply manually during a maintenance window.": "Empfehlung: Verwenden Sie für diese Pfade „In Datei exportieren“ und wenden Sie sie während eines Wartungsfensters manuell an.", @@ -3476,17 +4601,36 @@ "Recommended: use GPU -> LXC mode for these devices.": "Empfohlen: Verwenden Sie für diese Geräte den GPU->LXC-Modus.", "Recommended: use GPU with LXC workloads instead of VM passthrough on this hardware.": "Empfohlen: Verwenden Sie auf dieser Hardware eine GPU mit LXC-Workloads anstelle von VM-Passthrough.", "Reconciled": "Versöhnt", + "Recover OCI": "OCI zur Rückgewinnung", + "Recover OCI stack": "OCI-Stack zur Wiederherstellung", + "Recover now?": "Jetzt erholen?", + "Recover or complete the operation?": "Wiederherstellen oder Vervollständigen der operation?", "Recover the keyfile using your recovery passphrase?": "Die Schlüsseldatei mit Ihrer Wiederherstellungspassphrase wiederherstellen?", + "Recover the previous installation": "Wiederherstellen der vorherigen Installation", "Recoverable:": "Wiederherstellbar:", + "Recovering the previous installation": "Wiederherstellen der vorherigen Installation", "Recovery blob upload failed — main backup is OK, but keyfile recovery from PBS will not be available for this backup.": "Hochladen des Wiederherstellungs-Blobs fehlgeschlagen – Hauptsicherung ist in Ordnung, aber die Wiederherstellung der Schlüsseldatei von PBS ist für diese Sicherung nicht verfügbar.", "Recovery blob:": "Wiederherstellungs-Blob:", + "Recovery completed. The container had not been modified yet.": "Wiedereinziehung abgeschlossen. Der Container wurde noch nicht verändert.", + "Recovery completed. The displaced disks and the backup are kept; nothing was deleted automatically.": "Wiedereinziehung abgeschlossen. Die verschobenen Festplatten und das Backup werden beibehalten; nichts wurde automatisch gelöscht.", "Recovery failed": "Die Wiederherstellung ist fehlgeschlagen", "Recovery passphrase": "Wiederherstellungspassphrase", "Recovery setup failed": "Die Wiederherstellungseinrichtung ist fehlgeschlagen", + "Recreate": "Recreated", + "Recreate OCI": "OCI neu erstellen", + "Recreate with these options?": "Recreate mit diesen Optionen?", + "Recreate: edit resources, network, paths and GPU": "Recreate: Ressourcen, Netzwerk, Pfade und GPU bearbeiten", + "Recreating requires a confirmed proposal": "Recreating requires ein bestätigter Vorschlag", + "Recreating the container...": "Den Container neu erstellen...", + "Recreating the container:": "Wiederherstellen des Containers:", + "Recreation completed. Data kept.": "Erholung abgeschlossen. Vorgehaltene Daten.", + "Recreation prepared": "Erholung vorbereitet", "Refresh APT index and verify repositories:": "APT-Index aktualisieren und Repositorys überprüfen:", "Refresh your browser (Ctrl+Shift+R) to see changes": "Aktualisieren Sie Ihren Browser (Strg+Umschalt+R), um die Änderungen anzuzeigen", "Refresh your browser to see changes (server restart may be required)": "Aktualisieren Sie Ihren Browser, um Änderungen zu sehen (möglicherweise ist ein Neustart des Servers erforderlich).", "Refreshing apt cache...": "Apt-Cache wird aktualisiert...", + "Refreshing the NVIDIA runtime...": "Erfrischung der NVIDIA Runtime...", + "Refusing an unexpected rootfs path:": "Ablehnung eines unerwarteten Rootfs-Pfades:", "Regenerating PVE package cache...": "Der PVE-Paket-Cache wird neu generiert...", "Regenerating boot artifacts for the merged kernel-agnostic changes...": "Boot-Artefakte für die zusammengeführten Kernel-agnostischen Änderungen werden neu generiert ...", "Regenerating certificates and restarting services...": "Zertifikate werden neu generiert und Dienste neu gestartet...", @@ -3502,6 +4646,7 @@ "Reinstalled Proxmox packages successfully": "Proxmox-Pakete erfolgreich neu installiert", "Reinstalling": "Neuinstallation", "Reinstalling core Proxmox packages...": "Kernpakete von Proxmox werden neu installiert...", + "Relative CPU priority (cpuunits)": "Relative CPU-Priorität (Cpuunits)", "Release Channel": "Release-Kanal", "Release channel set to Beta.": "Veröffentlichungskanal auf Beta eingestellt.", "Release channel set to Stable.": "Der Release-Kanal ist auf „Stabil“ eingestellt.", @@ -3511,8 +4656,12 @@ "Remapped Users:": "Neu zugeordnete Benutzer:", "Remapped users:": "Neu zugeordnete Benutzer:", "Reminder: You must install the QEMU Guest Agent inside the Windows VM": "Erinnerung: Sie müssen den QEMU-Gastagenten in der Windows-VM installieren", + "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported.": "Remmina ist ein Remote-Desktop-Client, der in GTK geschrieben ist und für Systemadministratoren und Reisende nützlich sein soll, die mit vielen Remote-Computern vor großen oder kleinen Bildschirmen arbeiten müssen. Remmina unterstützt mehrere Netzwerkprotokolle in einer integrierten und konsistenten Benutzeroberfläche. Derzeit werden RDP, VNC, SPICE, SSH und EXEC unterstützt.", + "Remote Access & VPN": "Remote Access und VPN", + "Remote dry run completed; no container was created.": "Ferntrockenlauf abgeschlossen; kein Container wurde erstellt.", "Remote repository path:": "Remote-Repository-Pfad:", "Remote server via SSH (recommended — off-host, dedup across machines)": "Remote-Server über SSH (empfohlen – Off-Host, maschinenübergreifende Deduplizierung)", + "Remote verified:": "Fernverifiziert:", "Remounting CIFS share with open permissions...": "CIFS-Freigabe wird mit offenen Berechtigungen erneut bereitgestellt ...", "Remove CIFS Mount": "Entfernen Sie den CIFS-Mount", "Remove CIFS Mount (pvesm or fstab)": "CIFS-Mount entfernen (pvesm oder fstab)", @@ -3540,6 +4689,7 @@ "Remove NFS fstab Mount": "Entfernen Sie den NFS-fstab-Mount", "Remove NFS fstab mount:": "Entfernen Sie den NFS-fstab-Mount:", "Remove NFS storage:": "NFS-Speicher entfernen:", + "Remove OCI": "OCI entfernen", "Remove Proxmox CIFS storage:": "Entfernen Sie den Proxmox CIFS-Speicher:", "Remove Proxmox NFS storage:": "Entfernen Sie den Proxmox NFS-Speicher:", "Remove Proxmox iSCSI storage:": "Entfernen Sie den Proxmox iSCSI-Speicher:", @@ -3551,6 +4701,7 @@ "Remove iSCSI storage definition:": "Entfernen Sie die iSCSI-Speicherdefinition:", "Remove invalid port": "Entfernen Sie den ungültigen Port", "Remove invalid port(s)": "Ungültige Port(s) entfernen", + "Remove it? The data of its containers cannot be recovered afterwards.": "Entfernen Sie es? Die Daten seiner Container können danach nicht wiederhergestellt werden.", "Remove keyfile from this host": "Schlüsseldatei von diesem Host entfernen", "Remove mount point:": "Mountpunkt entfernen:", "Remove obsolete systemd-boot meta-package": "Entfernen Sie das veraltete systemd-boot-Metapaket", @@ -3559,6 +4710,7 @@ "Remove subscription banner": "Abonnementbanner entfernen", "Remove the unprivileged flag from configuration:": "Entfernen Sie das Unprivileged-Flag aus der Konfiguration:", "Remove unused packages and their config": "Entfernen Sie nicht verwendete Pakete und deren Konfiguration", + "Remove: delete the application and its containers": "Entfernen: Löschen Sie die Anwendung und ihre Container", "Removed": "ENTFERNT", "Removed KVM MSR options from configuration": "KVM-MSR-Optionen aus der Konfiguration entfernt", "Removed Mount:": "Entfernte Halterung:", @@ -3609,6 +4761,9 @@ "Removing stale VFIO entries from vfio.conf...": "Veraltete VFIO-Einträge aus vfio.conf entfernen...", "Removing storage from Proxmox...": "Speicher aus Proxmox wird entfernt...", "Removing system limits optimizations...": "Systemlimitoptimierungen werden entfernt...", + "Removing the containers...": "Entfernen der Container...", + "Removing the incomplete stack...": "Entfernen des unvollständigen Stacks...", + "Removing the previous container": "Entfernen des vorherigen Containers", "Removing utilities installed by ProxMenux...": "Von ProxMenux installierte Dienstprogramme werden entfernt...", "Removing zfs-auto-snapshot...": "ZFS-Auto-Snapshot wird entfernt...", "Renamed": "Umbenannt", @@ -3616,6 +4771,7 @@ "Repair Complete": "Reparatur abgeschlossen", "Repair Options:": "Reparaturmöglichkeiten:", "Repairs and optimizes repositories": "Repariert und optimiert Repositorys", + "Repeat to confirm": "Wiederholen Sie die Bestätigung", "Replace": "Ersetzen", "Replace with the actual ID.": "Ersetzen Sie durch die tatsächliche ID.", "Replace with your actual container ID": "Ersetzen Sie durch Ihre tatsächliche Container-ID", @@ -3628,12 +4784,16 @@ "Repositories switched to no-subscription": "Repositorys wurden auf „Kein Abonnement“ umgestellt", "Repository ready.": "Repository bereit.", "Repository:": "Repository:", + "Request a staging certificate for testing: true or false": "Beantragen Sie ein Staging-Zertifikat für die Prüfung: true oder false", "Require reboot": "Neustart erforderlich", "Required command not found:": "Erforderlicher Befehl nicht gefunden:", "Required if using a VirtIO or SCSI disk.": "Erforderlich, wenn eine VirtIO- oder SCSI-Festplatte verwendet wird.", "Required install helpers not available.": "Erforderliche Installationshilfen nicht verfügbar.", + "Required new path cancelled": "Required neuer Pfad abgesagt", + "Required persistent paths cannot be removed": "Required persistente Pfade können nicht entfernt werden", "Requires acl package. Skip if setfacl is not available.": "Erfordert ein ACL-Paket. Überspringen, wenn setfacl nicht verfügbar ist.", "Requires authentication": "Erfordert Authentifizierung", + "Reserving a private network...": "Ein privates Netzwerk reservieren...", "Reset Capability Blocked": "Reset-Funktion blockiert", "Reset Capability Warning": "Warnung zum Zurücksetzen der Fähigkeit", "Reset Monitor Password": "Monitor-Passwort zurücksetzen", @@ -3641,7 +4801,9 @@ "Reset current storage selection": "Aktuelle Speicherauswahl zurücksetzen", "Resetting time synchronization...": "Zeitsynchronisierung wird zurückgesetzt...", "Residual Bookworm entries commented where applicable": "Verbleibende Bücherwurm-Einträge ggf. kommentiert", + "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes.": "Resilio-sync (ehemals BitTorrent Sync) verwendet das BitTorrent-Protokoll, um Dateien und Ordner zwischen allen Ihren Geräten zu synchronisieren. Es gibt sowohl kostenlose als auch kostenpflichtige Versionen, dieser Container unterstützt beide. Es gibt ein offizielles Synchronisierungsbild, aber wir haben dieses erstellt, da es die Benutzerzuordnung unterstützt, um Berechtigungen für Volumes zu vereinfachen.", "Resolve package conflicts": "Paketkonflikte lösen", + "Resources": "Ressourcen", "Restart Network": "Netzwerk neu starten", "Restart Network Service": "Starten Sie den Netzwerkdienst neu", "Restart Web UI proxy": "Starten Sie den Web-UI-Proxy neu", @@ -3673,8 +4835,11 @@ "Restore plan summary": "Zusammenfassung des Wiederherstellungsplans", "Restore source location": "Quellspeicherort wiederherstellen", "Restored config is on disk; reboot the host to apply.": "Die wiederhergestellte Konfiguration befindet sich auf der Festplatte. Starten Sie den Host neu, um ihn anzuwenden.", + "Restored installation checked": "Restaurierte Installation geprüft", "Restored original /bin/gzip": "Original /bin/gzip wiederhergestellt", "Restored original /etc/vzdump.conf from .bak": "Original /etc/vzdump.conf aus .bak wiederhergestellt", + "Restored:": "Restauriert:", + "Restoring": "Wiederherstellung", "Restoring APT language downloads...": "APT-Sprachdownloads werden wiederhergestellt...", "Restoring container memory to": "Containerspeicher wird wiederhergestellt", "Restoring default journald configuration...": "Standard-Journald-Konfiguration wird wiederhergestellt...", @@ -3682,15 +4847,23 @@ "Restoring original bashrc...": "Original-bashrc wird wiederhergestellt...", "Restoring original logrotate configuration...": "Die ursprüngliche Logrotate-Konfiguration wird wiederhergestellt...", "Restoring subscription banner...": "Abonnementbanner wird wiederhergestellt...", + "Restoring the backup": "Wiederherstellung des Backups", "Restoring the original rpcbind service state...": "Wiederherstellen des ursprünglichen Rpcbind-Dienststatus ...", + "Restoring the previous Rclone configuration...": "Wiederherstellen der vorherigen Rclone-Konfiguration...", + "Restoring the previous backup...": "Wiederherstellen des vorherigen Backups...", + "Restoring the previous state of the stack...": "Wiederherstellen des vorherigen Zustands des Stapels...", + "Restoring the stack records...": "Wiederherstellung der Stack Records...", "Results will be saved automatically to:": "Die Ergebnisse werden automatisch gespeichert unter:", "Results will be saved to:": "Die Ergebnisse werden gespeichert unter:", "Retention": "Zurückbehaltung", + "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface.": "RetroArch ist ein Frontend für Emulatoren, Game Engines und Media Player. Es ermöglicht Ihnen, klassische Spiele auf einer Vielzahl von Computern und Konsolen durch seine glatte grafische Oberfläche laufen.", "Return": "Zurückkehren", "Return to Main Menu": "Zurück zum Hauptmenü", "Return to Share Menu": "Zurück zum Teilen-Menü", "Return to main menu": "Zurück zum Hauptmenü", + "Returning the containers to their previous state...": "Die Container in ihren vorherigen Zustand zurückbringen...", "Reused the encryption key from the PVE storage entry.": "Der Verschlüsselungsschlüssel aus dem PVE-Speichereintrag wurde wiederverwendet.", + "Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container.": "Reverse Proxy Samples für andere Anwendungen befinden sich in /config/nginx/proxy confs im Container.", "Reverting AMD (Ryzen/EPYC) fixes...": "AMD (Ryzen/EPYC)-Korrekturen werden rückgängig gemacht...", "Reverting IOMMU/VFIO configuration...": "IOMMU/VFIO-Konfiguration wird zurückgesetzt...", "Reverting TCP BBR + Fast Open...": "TCP BBR + Fast Open wird zurückgesetzt...", @@ -3699,22 +4872,31 @@ "Reverting vzdump speed tuning...": "vzdump-Geschwindigkeitsoptimierung wird zurückgesetzt...", "Review passthrough config files": "Überprüfen Sie die Passthrough-Konfigurationsdateien", "Review what will be removed": "Überprüfen Sie, was entfernt wird", + "Rip DVD and Blu-ray media from a browser": "Rip DVD und Blu-ray Medien aus einem Browser", "Rollback: nothing to remove (host matches backup)": "Rollback: nichts zu entfernen (Host stimmt mit Backup überein)", + "Rolling back the incomplete container": "Zurückrollen des unvollständigen Behälters", + "RomM is a self-hosted ROM manager for managing and playing game collections.": "RomM ist ein selbst gehosteter ROM-Manager für die Verwaltung und das Spielen von Spielsammlungen.", "Root SSH keys/config": "Root-SSH-Schlüssel/Konfiguration", "Root inside container = root on host system": "Root im Container = Root auf dem Hostsystem", + "Root privileges are required": "Root Privilegien sind required", + "Root privileges on the Proxmox node are required": "Root-Rechte auf dem Proxmox-Knoten sind required", "Root shell/profile config": "Root-Shell-/Profilkonfiguration", "Root user on the PVE host (default 'root'):": "Root-Benutzer auf dem PVE-Host (Standard „root“):", + "Rootfs size in GB": "Rootfs Größe in GB", "Rotate the recovery passphrase": "Drehen Sie die Wiederherstellungspassphrase", "Routing Information": "Routing-Informationen", "Routing Table": "Routing-Tabelle", + "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required.": "Rsnapshot ist ein Dateisystem-Snapshot-Dienstprogramm, das auf rsync basiert. rsnapshot macht es einfach, periodische Snapshots von lokalen Maschinen und Remote-Maschinen über ssh zu erstellen. Der Code verwendet wann immer möglich ausgiebig Hardlinks, um den Speicherplatz required stark zu reduzieren.", "Run 'Mount NFS Share' to install NFS client automatically.": "Führen Sie „NFS-Freigabe bereitstellen“ aus, um den NFS-Client automatisch zu installieren.", "Run 'Mount Samba Share' to install CIFS client automatically.": "Führen Sie „Mount Samba Share“ aus, um den CIFS-Client automatisch zu installieren.", + "Run GGUF LLMs locally with GPU acceleration": "GGUF LLMs lokal mit GPU-Beschleunigung ausführen", "Run PVE 8 to 9": "Führen Sie PVE 8 bis 9 aus", "Run PVE 8 to 9 check": "Führen Sie den PVE 8 bis 9-Check durch", "Run \\\"Install NVIDIA Drivers on Host\\\" first so the installer is cached.": "Führen Sie zuerst „NVIDIA-Treiber auf Host installieren“ aus, damit das Installationsprogramm zwischengespeichert wird.", "Run a full security audit": "Führen Sie eine vollständige Sicherheitsüberprüfung durch", "Run a job now": "Führen Sie jetzt einen Job aus", "Run apt-get install -f to complete any pending package configurations": "Führen Sie apt-get install -f aus, um alle ausstehenden Paketkonfigurationen abzuschließen", + "Run as root on the Proxmox node; the registry contains private data": "Als root auf dem Proxmox-Knoten ausgeführt; die Registry enthält private Daten", "Run as server or client? [s/c]:": "Als Server oder Client ausführen? [sc]:", "Run checklist again to verify upgrade:": "Führen Sie die Checkliste erneut aus, um das Upgrade zu überprüfen:", "Run from console, or SSH inside tmux/screen": "Führen Sie es über die Konsole oder SSH in tmux/screen aus", @@ -3739,6 +4921,7 @@ "Running dkms autoinstall for kernel": "Ausführen der dkms-Autoinstallation für den Kernel", "Running kernel:": "Kernel ausführen:", "Running pre-upgrade simulation to verify 'proxmox-ve' will remain installed...": "Führen Sie eine Simulation vor dem Upgrade durch, um zu überprüfen, ob „proxmox-ve“ installiert bleibt ...", + "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration.": "RustDesk ist eine voll ausgestattete Open-Source-Fernbedienungsalternative für Selbsthosting und Sicherheit bei minimaler Konfiguration.", "SATA (standard - high compatibility)": "SATA (Standard – hohe Kompatibilität)", "SCSI (recommended for Linux and Windows)": "SCSI (empfohlen für Linux und Windows)", "SCSI (recommended for Linux)": "SCSI (empfohlen für Linux)", @@ -3755,6 +4938,7 @@ "SMB ports:": "SMB-Ports:", "SR-IOV Configuration Detected": "SR-IOV-Konfiguration erkannt", "SSD Emulation": "SSD-Emulation", + "SSH access": "SSH-Zugang", "SSH access (host + root)": "SSH-Zugriff (Host + Root)", "SSH auth logger service created and started": "SSH-Authentifizierungsprotokollierungsdienst erstellt und gestartet", "SSH hardening: MaxAuthTries set to 3 (Lynis recommendation)": "SSH-Härtung: MaxAuthTries auf 3 gesetzt (Lynis-Empfehlung)", @@ -3769,6 +4953,8 @@ "STEP 9: Cleanup (LVM only)": "SCHRITT 9: Bereinigung (nur LVM)", "STORAGE TYPE IDENTIFICATION:": "IDENTIFIZIERUNG DES SPEICHERTYPS:", "SUGGESTION FOR": "VORSCHLAG FÜR", + "SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.": "SWAG dient HTTPS auf Port 443. HTTP auf Port 80 ist deaktiviert in /config/nginx/site-confs/default.conf.", + "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction.": "Sabnzbd macht Usenet so einfach und schlank wie möglich, indem es alles automatisiert, was wir können. Alles, was Sie tun müssen, ist eine .nzb hinzuzufügen. SABnzbd übernimmt von dort aus, wo es automatisch heruntergeladen, verifiziert, repariert, extrahiert und mit null menschlicher Interaktion abgelegt wird.", "Safe design: no automatic ACL/ownership mutation on host or CT.": "Sicheres Design: keine automatische ACL-/Besitzmutation auf Host oder CT.", "Safe to apply now": "Jetzt sicher bewerben", "Safety Backup": "Sicherheits-Backup", @@ -3822,8 +5008,13 @@ "Same major series:": "Gleiche Hauptserie:", "Same major.minor:": "Gleiches Dur. Moll:", "Sanitizing NVIDIA host services for VFIO mode...": "Bereinigen der NVIDIA-Hostdienste für den VFIO-Modus ...", + "Save and classify articles. Read them later. Freely.": "Speichern und klassifizieren Sie Artikel. Lesen Sie sie später. Frei.", "Save the passphrase somewhere safe NOW, before continuing.": "Speichern Sie die Passphrase JETZT an einem sicheren Ort, bevor Sie fortfahren.", "Save this Borg target so you don't need to enter the details again?": "Dieses Borg-Ziel speichern, damit Sie die Details nicht erneut eingeben müssen?", + "Saved record removed": "Gespeicherter Datensatz entfernt", + "Saving the new configuration": "Speichern der neuen Konfiguration", + "Saving the new configuration...": "Speichern der neuen Konfiguration...", + "Saving the stack records...": "Speichern der Stack Records...", "Scan storage for new content": "Durchsuchen Sie den Speicher nach neuen Inhalten", "Scanning available physical disks...": "Verfügbare physische Festplatten werden gescannt...", "Scanning network for NFS servers...": "Netzwerk nach NFS-Servern durchsuchen...", @@ -3835,11 +5026,19 @@ "Scheduled backups and retention policies": "Geplante Backups und Aufbewahrungsrichtlinien", "Scheduled tasks (cron)": "Geplante Aufgaben (cron)", "Scheduler script not found:": "Scheduler-Skript nicht gefunden:", + "ScreenScraper": "ScreenScraper", + "ScreenScraper password": "ScreenScraper Passwort", + "ScreenScraper username": "ScreenScraper Benutzername", "Script Information": "Skriptinformationen", "Script not found:": "Skript nicht gefunden:", "Scripts in": "Skripte in", + "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator.": "ScummVM ist ein Programm, mit dem Sie bestimmte klassische grafische Abenteuer- und Rollenspiele ausführen können, sofern Sie bereits über deren Datendateien verfügen. Der clevere Teil dabei: ScummVM ersetzt nur die ausführbaren Dateien, die mit den Spielen ausgeliefert werden, so dass Sie sie auf Systemen spielen können, für die sie nie entwickelt wurden! ScummVM ist ein komplettes Umschreiben der ausführbaren Dateien dieser Spiele und kein Emulator.", + "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions—such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server.": "Sealskin ist eine selbst gehostete Client-Server-Plattform, mit der Benutzer leistungsstarke, containerisierte Desktop-Anwendungen ausführen können, die direkt in einen Webbrowser gestreamt werden. Es verwendet eine Browsererweiterung, um Benutzeraktionen abzufangen - wie das Klicken auf einen Link oder das Herunterladen einer Datei und leitet sie in eine sichere, isolierte Anwendungsumgebung um, die auf einem entfernten Server ausgeführt wird.", "Search Results for:": "Suchergebnisse für:", + "Search applications": "Suchanwendungen", + "Search results for:": "Suchergebnisse für:", "Search/Filter Scripts": "Such-/Filterskripte", + "Searchable document archive with OCR": "Durchsuchbares Dokumentenarchiv mit OCR", "Secure Disk Formatter": "Sicherer Festplattenformatierer", "Secure Gateway (Tailscale VPN)": "Secure Gateway (Tailscale VPN)", "Secure Gateway deployed successfully!": "Secure Gateway erfolgreich bereitgestellt!", @@ -3847,8 +5046,12 @@ "Security": "Sicherheit", "Security Updates": "Sicherheitsupdates", "Security Warning — read before applying": "Sicherheitswarnung – vor der Bewerbung lesen", + "Security directive outside the dynamic profile": "Sicherheitsrichtlinie außerhalb des dynamischen Profils", + "Security relaxation declined": "Sicherheitsentspannung zurückgegangen", "See": "Siehe", "See /tmp/proxmenux-mount.log for details.": "Weitere Informationen finden Sie unter /tmp/proxmenux-mount.log.", + "Seerr WebUI": "Seerr WebUI", + "Seerr/Bazarr connections, the SABnzbd client and the Lidarr profiles, root folder and client are configured manually in this version.": "Seerr/Bazarr-Verbindungen, der SABnzbd-Client und die Lidarr-Profile, Stammordner und Client werden in dieser Version manuell konfiguriert.", "Select": "Wählen", "Select Borg target": "Wählen Sie das Borg-Ziel aus", "Select CPU model": "Wählen Sie das CPU-Modell aus", @@ -3888,6 +5091,7 @@ "Select a Custom Logo": "Wählen Sie ein benutzerdefiniertes Logo", "Select a VirtIO ISO to use:": "Wählen Sie eine zu verwendende VirtIO-ISO aus:", "Select a category of useful commands:": "Wählen Sie eine Kategorie nützlicher Befehle aus:", + "Select a category or search for applications:": "Wählen Sie eine Kategorie oder suchen Sie nach Anwendungen:", "Select a category or search for scripts:": "Wählen Sie eine Kategorie oder suchen Sie nach Skripten:", "Select a custom ISO to use:": "Wählen Sie eine benutzerdefinierte ISO zur Verwendung aus:", "Select a job:": "Wählen Sie einen Job aus:", @@ -3897,6 +5101,7 @@ "Select a pre-configured Linux VM script to execute:": "Wählen Sie ein vorkonfiguriertes Linux-VM-Skript zur Ausführung aus:", "Select a script or action:": "Wählen Sie ein Skript oder eine Aktion aus:", "Select a share to delete:": "Wählen Sie eine Freigabe zum Löschen aus:", + "Select a specific Coral or USB node, not the whole /dev": "Wählen Sie einen bestimmten Coral- oder USB-Knoten, nicht den gesamten /dev", "Select access mode": "Wählen Sie den Zugriffsmodus", "Select an existing group": "Wählen Sie eine vorhandene Gruppe aus", "Select an existing group:": "Wählen Sie eine vorhandene Gruppe aus:", @@ -3907,6 +5112,7 @@ "Select archive": "Archiv auswählen", "Select archive to restore": "Wählen Sie das wiederherzustellende Archiv aus", "Select at least one path to continue.": "Wählen Sie mindestens einen Pfad aus, um fortzufahren.", + "Select at least one suite application": "Wählen Sie mindestens eine Suite-Anwendung aus", "Select authentication mode:": "Authentifizierungsmodus auswählen:", "Select authentication type:": "Wählen Sie den Authentifizierungstyp:", "Select available Controllers/NVMe to add:": "Wählen Sie die verfügbaren Controller/NVMe zum Hinzufügen aus:", @@ -4011,6 +5217,19 @@ "Selected optimizations have been uninstalled.": "Ausgewählte Optimierungen wurden deinstalliert.", "Selected paths produced no entries to apply.": "Ausgewählte Pfade ergaben keine anzuwendenden Einträge.", "Selected utilities installation completed": "Die Installation ausgewählter Dienstprogramme ist abgeschlossen", + "Selection": "Auswahl", + "Self-custodial Bitcoin Lightning wallet with integrated node and app connections.": "Bitcoin Lightning Wallet mit integrierten Knoten- und App-Verbindungen.", + "Self-hosted ZeroTier network controller with web UI for centralized management.": "Selbst gehosteter ZeroTier-Netzwerkcontroller mit Web-Benutzeroberfläche zur zentralen Verwaltung.", + "Self-hosted cloud data migration & sync manager": "Selbst gehostete Cloud Datenmigration & Sync Manager", + "Self-hosted collaborative bookmark manager to collect, read, annotate, and fully preserve what matters, all in one place.": "Selbst gehosteter kollaborativer Bookmark-Manager, um alles an einem Ort zu sammeln, zu lesen, zu kommentieren und vollständig zu bewahren, was wichtig ist.", + "Self-hosted file sharing with a modern web interface": "Self-Hosted File Sharing mit einem modernen Web-Interface", + "Self-hosted file toolkit for images, video, audio, PDFs, and files": "Selbst gehostetes Datei-Toolkit für Bilder, Video, Audio, PDFs und Dateien", + "Self-hosted internet archiving solution": "Selbst gehostete Internet-Archivierungslösung", + "Self-hosted recipe manager and meal planner": "Selbstgehosteter Rezeptmanager und Mahlzeitenplaner", + "Self-hosted software development service": "Entwicklung von selbst gehosteter Software", + "Self-signed TLS certificate created:": "Selbstsigniertes TLS-Zertifikat erstellt:", + "Selfhosted PDF manager, viewer and editor": "Selfhosted PDF Manager, Viewer und Editor", + "Selkies desktop and streaming acceleration": "Selkies Desktop und Streaming Beschleunigung", "Sending backup to Borg repository...": "Backup wird an das Borg-Repository gesendet...", "Sending backup to PBS...": "Backup an PBS senden...", "Server": "Server", @@ -4025,14 +5244,19 @@ "Server will listen on TCP port 5201.": "Der Server überwacht den TCP-Port 5201.", "Server:": "Server:", "Servers": "Server", + "Service": "Dienst", "Service Status": "Servicestatus", "Service is active and running": "Der Dienst ist aktiv und wird ausgeführt", "Service is inactive": "Der Dienst ist inaktiv", + "Service ready:": "Servicebereit:", + "Service responding:": "Service Response:", "Service restarted.": "Dienst neu gestartet.", "Service restarts:": "Dienst wird neu gestartet:", "Service stopped.": "Der Dienst wurde gestoppt.", + "Service:": "Service:", "Services failed": "Dienste sind fehlgeschlagen", "Services restarted": "Dienste neu gestartet", + "Services that depend on the main service are not yet supported": "Dienste, die vom Hauptdienst abhängen, werden noch nicht unterstützt", "Services:": "Leistungen:", "Set Display > Graphic card (VGA, SPICE or VirtIO) to match the guest": "Stellen Sie Anzeige > Grafikkarte (VGA, SPICE oder VirtIO) passend zum Gast ein", "Set Hostname": "Hostnamen festlegen", @@ -4077,13 +5301,26 @@ "Share:": "Aktie:", "Shared Directory Ready:": "Bereit für das freigegebene Verzeichnis:", "Shared Group": "Geteilte Gruppe", + "Shared directory created:": "Gemeinsames Verzeichnis erstellt:", + "Shared directory for consume and export": "Gemeinsames Verzeichnis für Konsum und Export", + "Shared directory for copy/sync operations": "Gemeinsames Verzeichnis für Copy/Sync operations", "Shared group: CONFIGURED": "Geteilte Gruppe: KONFIGURIERT", "Shared group: sharedfiles (GID:": "Freigegebene Gruppe: sharedfiles (GID:", + "Shared host content (not included in LXC backups):": "Gemeinsame Host-Inhalte (nicht in LXC-Backups enthalten):", + "Shared host data is not reverted by the backup. Continue?": "Geteilte Hostdaten werden durch das Backup nicht rückgängig gemacht. Weiter so?", + "Shared host data is not reverted by the backups. Continue?": "Geteilte Hostdaten werden durch die Backups nicht zurückgeführt. Weiter so?", + "Shared host directories (not included in Proxmox backups)": "Gemeinsame Host-Verzeichnisse (nicht in Proxmox-Backups enthalten)", + "Shared host directory": "Gemeinsames Hostverzeichnis", + "Shared host directory (not included in Proxmox backups)": "Gemeinsames Hostverzeichnis (nicht in Proxmox-Backups enthalten)", + "Shared host files are kept as they are; the backup does not restore their content.": "Geteilte Hostdateien werden so aufbewahrt, wie sie sind; das Backup stellt ihren Inhalt nicht wieder her.", + "Shared host media directory": "Gemeinsames Host-Medienverzeichnis", + "Shared memory size for the GPU workload in MB": "Gemeinsame Speichergröße für die GPU-Workload in MB", "Sharedfiles group already exists (GID: 101000)": "Die Sharedfiles-Gruppe existiert bereits (GID: 101000)", "Shares found:": "Gefundene Aktien:", "Shell user ulimit set": "Ulimit-Satz für Shell-Benutzer", "Short self-test started on": "Kurzer Selbsttest begann am", "Short test — ~2 minutes, basic surface check": "Kurzer Test – ca. 2 Minuten, grundlegende Oberflächenprüfung", + "Shotcut is a free, open source, cross-platform video editor.": "Shotcut ist ein kostenloser, plattformübergreifender Open Source Video-Editor.", "Should show 'unprivileged: 0' or no unprivileged line": "Sollte „unprivileged: 0“ oder keine unprivilegierte Zeile anzeigen", "Should show 'unprivileged: 1'": "Sollte „unprivilegiert: 1“ anzeigen", "Should show 'unprivileged: 1' if it's unprivileged": "Sollte „unprivileged: 1“ anzeigen, wenn es nicht privilegiert ist", @@ -4125,14 +5362,23 @@ "Show size of a directory": "Größe eines Verzeichnisses anzeigen", "Show standard exclude patterns": "Standard-Ausschlussmuster anzeigen", "Show status of all storage pools": "Status aller Speicherpools anzeigen", + "Show the QR code of a peer again with: pct exec -- /app/show-peer 1": "Zeigen Sie den QR-Code eines Peers erneut mit: pct exec -- /app/show-peer 1", "Show traffic statistics per interface": "Verkehrsstatistiken pro Schnittstelle anzeigen", "Show vzdump backup configuration": "vzdump-Sicherungskonfiguration anzeigen", "Shows status and type (nfs/cifs/dir/iscsi...).": "Zeigt Status und Typ an (nfs/cifs/dir/iscsi...).", "Shutdown timeout": "Zeitüberschreitung beim Herunterfahren", + "SiYuan access code": "SiYuan-Zugangscode", + "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more..": "SickGear bietet die Verwaltung von TV-Shows und / oder Anime, erkennt neue Episoden, verknüpft Downloader-Apps und mehr.", + "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private.": "Signal ist eine Messaging-App mit Privatsphäre im Kern. Es ist kostenlos und einfach zu bedienen, mit starker ende-zu-ende-verschlüsselung, die ihre kommunikation völlig privat hält.", "Signatures removed. Partition table preserved.": "Unterschriften entfernt. Partitionstabelle bleibt erhalten.", + "Simple and easy to use DDNS": "Einfach und einfach zu bedienen DDNS", "Single GPU Warning": "Warnung vor einer einzelnen GPU", "Single target found — selected automatically:": "Einzelnes Ziel gefunden – automatisch ausgewählt:", "Size": "Größe", + "Size in GB of": "Größe in GB von", + "Size of each consume/export volume in GB": "Größe jedes Verbrauchs-/Exportvolumens in GB", + "Size of the /dev/shm shared memory in MB": "Größe des /dev/shm Shared Memory in MB", + "Size of the Frigate temporary cache in MB": "Größe des Frigate temporären Cache in MB", "Size:": "Größe:", "Skip downloading additional languages": "Das Herunterladen zusätzlicher Sprachen überspringen", "Skip this device": "Überspringen Sie dieses Gerät", @@ -4142,6 +5388,7 @@ "Skip — leave as-is": "Überspringen – unverändert lassen", "Skipped (no disks of the pool are present on this host):": "Übersprungen (auf diesem Host sind keine Festplatten des Pools vorhanden):", "Skipped (some disks missing):": "Übersprungen (einige Festplatten fehlen):", + "Skipped because Jellyfin did not create encoding.xml:": "Überspringt, weil Jellyfin coding.xml nicht erstellt hat:", "Skipped device": "Übersprungenes Gerät", "Skipped to protect target system (would cascade-remove packages)": "Übersprungen, um das Zielsystem zu schützen (würde Pakete kaskadierend entfernen)", "Skipped, not in apt cache:": "Übersprungen, nicht im Apt-Cache:", @@ -4149,7 +5396,10 @@ "Skipping SR-IOV device": "SR-IOV-Gerät wird übersprungen", "Skipping installation.": "Installation überspringen.", "Skipping manual patches — feranick fork already supports this kernel.": "Manuelle Patches überspringen – Feranick Fork unterstützt diesen Kernel bereits.", + "Sleek podcast downloader with GPodder sync": "Sleek Podcast Downloader mit GPodder Sync", "Smart restore plan — hardware compatibility check": "Smart Restore Plan – Hardware-Kompatibilitätsprüfung", + "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis.": "Smokeping verfolgt Ihre Netzwerklatenz. Für ein vollständiges Beispiel, was diese Anwendung in der Lage ist, besuchen Sie UCDavis.", + "SnapOtter": "SnapOtter", "Snippets — hook scripts / config": "Snippets – Hook-Skripte/Konfiguration", "SoC-integrated GPU: tight coupling with other SoC components": "SoC-integrierte GPU: enge Kopplung mit anderen SoC-Komponenten", "Some DKMS removals reported errors; final verification will determine the result.": "Bei einigen DKMS-Entfernungen wurden Fehler gemeldet. Über das Ergebnis entscheidet die abschließende Prüfung.", @@ -4159,6 +5409,7 @@ "Some old time services could not be removed (not installed)": "Einige alte Dienste konnten nicht entfernt (nicht installiert) werden.", "Some operations failed — review messages above. Press Enter to continue...": "Einige Vorgänge sind fehlgeschlagen. Sehen Sie sich die Meldungen oben an. Drücken Sie die Eingabetaste, um fortzufahren...", "Some packages still need attention; review": "Einige Pakete erfordern noch Aufmerksamkeit;Rezension", + "Some projects publish a Dockerfile and not an image: it has to be built and published to a registry before it can be installed this way. An image of a private registry needs credentials, which are not supported yet.": "Einige Projekte veröffentlichen eine Docker-Datei und kein Bild: Sie muss erstellt und in einer Registry veröffentlicht werden, bevor sie auf diese Weise installiert werden kann. Ein Image eines privaten Registers benötigt credentials, die noch nicht unterstützt werden.", "Some repairs failed. Please fix manually and re-run the script.": "Einige Reparaturen schlugen fehl. Bitte beheben Sie den Fehler manuell und führen Sie das Skript erneut aus.", "Some repositories are not available, continuing with available ones...": "Einige Repositorys sind nicht verfügbar. Fahren Sie mit den verfügbaren fort ...", "Some selected GPUs are already configured in this container.": "Einige ausgewählte GPUs sind in diesem Container bereits konfiguriert.", @@ -4166,6 +5417,10 @@ "Some utility packages could not be removed; the remaining list has been preserved": "Einige Dienstprogrammpakete konnten nicht entfernt werden.die restliche Liste ist erhalten geblieben", "Something is already mounted at": "Etwas ist bereits montiert", "Something is already mounted at:": "Es ist bereits etwas montiert unter:", + "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Sonarr (früher NZBdrone) ist ein PVR für Usenet- und Bittorrent-Nutzer. Es kann mehrere RSS-Feeds für neue Episoden Ihrer Lieblingssendungen überwachen und sie erfassen, sortieren und umbenennen. Es kann auch so konfiguriert werden, dass die Qualität der bereits heruntergeladenen Dateien automatisch aktualisiert wird, wenn ein besseres Qualitätsformat verfügbar ist.", + "Sonarr added to Prowlarr": "Sonarr wird zu Prowlarr hinzugefügt", + "Sonarr connected to qBittorrent": "Sonarr mit qBittorrent verbunden", + "Sonarr root folder configured": "Sonarr Wurzelordner konfiguriert", "Source": "Quelle", "Source VM": "Quell-VM", "Source patched successfully.": "Quelle erfolgreich gepatcht.", @@ -4174,8 +5429,26 @@ "Spanish": "Spanisch", "Specific host (enter IP)": "Spezifischer Host (IP eingeben)", "Specific subnet (enter manually)": "Spezifisches Subnetz (manuell eingeben)", + "Speedtest Tracker web interface": "Speedtest Tracker Web-Schnittstelle", + "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service.": "Speedtest-Tracker ist eine selbst gehostete Internet-Performance-Tracking-Anwendung, die Speedtest-Checks gegen den Speedtest-Service von Ookla durchführt.", + "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium": "Spotube ist ein Open-Source-, plattformübergreifender Spotify-Client, der auf mehreren Plattformen mit Spotifys Daten-API und YouTube, Piped, kompatibel ist. Video oder JioSaavn als Audioquelle, wodurch Spotify Premium entfällt", "Stable (main branch)": "Stabil (Hauptzweig)", "Stable monitor service normalized.": "Stabiler Monitordienst normalisiert.", + "Stack": "Stapel", + "Stack adapter not recognized by the translator": "Stack-Adapter nicht vom Übersetzer erkannt", + "Stack backups are missing; a partial restore is not allowed": "Stack-Backups fehlen; eine teilweise Wiederherstellung ist nicht erlaubt", + "Stack checked:": "Stapel geprüft:", + "Stack members are missing; recreate them after verifying their volumes": "Stack-Mitglieder fehlen; erstellen Sie sie nach Überprüfung ihrer Volumina neu", + "Stack members are updated together with their stack": "Stack-Mitglieder werden zusammen mit ihrem Stack aktualisiert", + "Stack name": "Stackname", + "Stack records restored": "Stack Records wiederhergestellt", + "Stack records saved": "Speichern von Stack Records", + "Stack records saved; no container was reinstalled.": "Speichern von Stapeldatensätzen; kein Container wurde neu installiert.", + "Stack recovery completed; every member is back to its previous installation.": "Stack Recovery abgeschlossen; jedes Mitglied ist zurück zu seiner vorherigen Installation.", + "Stack startup hook installed": "Stack Starthaken installiert", + "Stack stopped": "Stack stoppt", + "Stack update completed. Data kept.": "Stack-Update abgeschlossen. Vorgehaltene Daten.", + "Stack:": "Stapel:", "Staging directory:": "Staging-Verzeichnis:", "Staging ready.": "Bühne bereit.", "Staging source:": "Staging-Quelle:", @@ -4183,11 +5456,13 @@ "Stale VFIO Config Detected": "Veraltete VFIO-Konfiguration erkannt", "Stale VFIO entries removed and initramfs rebuilt.": "Veraltete VFIO-Einträge entfernt und initramfs neu erstellt.", "Standard NAS (backup, iso, vztmpl)": "Standard-NAS (Backup, ISO, vztmpl)", + "Start": "Beginn", "Start VM": "Starten Sie die VM", "Start VM after creation": "Starten Sie die VM nach der Erstellung", "Start VM after creation?": "VM nach Erstellung starten?", "Start a container. Use the correct ": "Starten Sie einen Container. Verwenden Sie die richtige ", "Start a virtual machine. Use the correct ": "Starten Sie eine virtuelle Maschine. Verwenden Sie die richtige ", + "Start each LXC with Proxmox (no coordinated startup)": "Starten Sie jeden LXC mit Proxmox (kein koordiniertes Starten)", "Start long self-test (hours)": "Langer Selbsttest starten (Stunden)", "Start long test now?": "Jetzt Langtest starten?", "Start on boot already disabled for VM": "Beim Booten starten ist für die VM bereits deaktiviert", @@ -4199,11 +5474,16 @@ "Start scrub for a ZFS pool": "Starten Sie Scrub für einen ZFS-Pool", "Start short self-test (~2 min)": "Kurzen Selbsttest starten (~2 Min.)", "Start terminal multiplexer (recommended):": "Terminal-Multiplexer starten (empfohlen):", + "Start the LXC when finished to apply the selected configuration?": "Starten Sie die LXC, wenn Sie fertig sind, um die ausgewählte Konfiguration anzuwenden?", "Start the VM": "Starten Sie die VM", "Start the VM to begin Windows installation from the mounted ISO.": "Starten Sie die VM, um die Windows-Installation von der gemounteten ISO aus zu starten.", "Start the converted container:": "Starten Sie den konvertierten Container:", "Start the main system upgrade:": "Starten Sie das Hauptsystem-Upgrade:", + "Start the stack with Proxmox": "Starten Sie den Stack mit Proxmox", "Start uploading to PBS — sets a recovery passphrase": "Hochladen auf PBS starten – legt eine Wiederherstellungspassphrase fest", + "Start when finished": "Start nach Abschluss", + "Start with Proxmox": "Beginnen Sie mit Proxmox", + "Starting": "Beginn", "Starting Borg backup...": "Borg-Backup wird gestartet...", "Starting CT": "CT starten", "Starting LXC Privileged to Unprivileged conversion process...": "Der Konvertierungsprozess von LXC Privileged zu Unprivileged wird gestartet ...", @@ -4214,6 +5494,7 @@ "Starting ProxMenux update...": "ProxMenux-Update wird gestartet...", "Starting Proxmox storage integration...": "Proxmox-Speicherintegration wird gestartet...", "Starting Proxmox system repair...": "Proxmox-Systemreparatur wird gestartet...", + "Starting Rclone and waiting for the FUSE mount...": "Rclone starten und auf das FUSE-Mount warten...", "Starting SMART long self-test...": "Langer SMART-Selbsttest wird gestartet...", "Starting SMART short self-test...": "SMART-Kurzselbsttest wird gestartet...", "Starting container": "Startcontainer", @@ -4224,9 +5505,20 @@ "Starting installer...": "Installationsprogramm starten...", "Starting privileged container...": "Privilegierter Container wird gestartet...", "Starting rpcbind service...": "Rpcbind-Dienst wird gestartet...", + "Starting the container...": "Den Container starten...", + "Starting the main container and its dependencies...": "Starten des Hauptcontainers und seiner Abhängigkeiten...", + "Starting the service:": "Starten des Dienstes:", "Starting unprivileged container...": "Unprivilegierter Container wird gestartet...", + "Startup: coordinated by the stack startup hook": "Startup: Koordiniert durch den Stack Startup Hook", + "Startup: independent, without hookscript": "Startup: unabhängig, ohne Hookscript", + "Static IP": "Statisches IP", + "Static IPv4 address": "Statische IPv4-Adresse", + "Static IPv4 address for": "Statische IPv4-Adresse für", "Status": "Status", "Status:": "Status:", + "Steam is the ultimate destination for playing, discussing, and creating games.": "Steam ist das ultimative Ziel zum Spielen, Diskutieren und Erstellen von Spielen.", + "SteamGridDB": "SteamGridDB", + "SteamGridDB API key": "SteamGridDB API Schlüssel", "Step": "Schritt", "Step 2: Testing actual share access with guest...": "Schritt 2: Testen des tatsächlichen Freigabezugriffs mit Gast ...", "Steps that will run:": "Schritte, die ausgeführt werden:", @@ -4234,12 +5526,14 @@ "Stop it first and run this option again.": "Stoppen Sie es zuerst und führen Sie diese Option erneut aus.", "Stop the CT, unmount the disk on the HOST, and remount with:": "Stoppen Sie den CT, unmounten Sie die Festplatte auf dem HOST und mounten Sie sie erneut mit:", "Stop the VM/CT before formatting this disk.": "Stoppen Sie die VM/CT, bevor Sie diese Festplatte formatieren.", + "Stop the container before the NVIDIA refresh": "Stoppen Sie den Container, bevor Sie die NVIDIA aktualisieren", "Stop the container if it's running:": "Stoppen Sie den Container, wenn er ausgeführt wird:", "Stop them first and run this script again.": "Stoppen Sie sie zuerst und führen Sie dieses Skript erneut aus.", "Stop uploading to PBS": "Hochladen auf PBS beenden", "Stop uploading?": "Hochladen beenden?", "Stopped": "Angehalten", "Stopped and disabled": "Angehalten und deaktiviert", + "Stopped at:": "Halt bei:", "Stopping Coral kernel modules...": "Coral-Kernel-Module werden gestoppt...", "Stopping LXC": "LXC stoppen", "Stopping NFS services...": "NFS-Dienste werden gestoppt...", @@ -4251,6 +5545,8 @@ "Stopping gateway...": "Gateway wird gestoppt...", "Stopping the container before applying configuration...": "Stoppen Sie den Container, bevor Sie die Konfiguration anwenden ...", "Stopping the container before conversion...": "Stoppen des Containers vor der Konvertierung...", + "Stopping the container...": "Den Container stoppen...", + "Stopping the stack...": "Den Stack stoppen...", "Storage": "Lagerung", "Storage & Share Manager": "Speicher- und Freigabemanager", "Storage Added:": "Speicher hinzugefügt:", @@ -4263,21 +5559,40 @@ "Storage and Disks Commands": "Speicher- und Festplattenbefehle", "Storage controller: VirtIO SCSI": "Speichercontroller: VirtIO SCSI", "Storage disk identifier:": "Kennung der Speicherplatte:", + "Storage for Nextcloud files, configuration and data": "Speicherung für Nextcloud-Dateien, Konfiguration und Daten", + "Storage for Paperless data and documents": "Speicherung von papierlosen Daten und Dokumenten", + "Storage for Tandoor files": "Speicherung von Tandoor-Dateien", + "Storage for persistent data": "Speicherung von persistenten Daten", + "Storage for recipe images and files": "Speicherung von Rezeptbildern und -dateien", + "Storage for rootfs": "Lagerung für Rootfs", + "Storage for rootfs and private configuration": "Speicher für Rootfs und private Konfiguration", + "Storage for the Immich library": "Speicher für die Immich-Bibliothek", + "Storage for the Nextcloud data": "Speicherung der Nextcloud-Daten", + "Storage for the OCI image cache": "Speicher für den OCI Image Cache", + "Storage for the consume and export folders": "Speicherung für die Verbrauchs- und Exportordner", + "Storage for the persistent configuration": "Speicher für die persistente Konfiguration", "Storage is now available in Proxmox web interface under Datacenter > Storage": "Speicher ist jetzt in der Proxmox-Weboberfläche unter Datacenter > Speicher verfügbar", "Storage plan selection cancelled.": "Auswahl des Speicherplans abgebrochen.", "Storage plan selection failed or cancelled": "Die Auswahl des Speicherplans ist fehlgeschlagen oder wurde abgebrochen", + "Storage selection cancelled": "Speicherauswahl abgebrochen", "Storage:": "Lagerung:", "Stored Credentials:": "Gespeicherte Anmeldeinformationen:", "Stored credentials:": "Gespeicherte Zugangsdaten:", + "Stremio is a modern media center that gives you the freedom to watch everything you want.": "Stremio ist ein modernes Medienzentrum, das Ihnen die Freiheit gibt, alles zu sehen, was Sie wollen.", + "Subdomains for the certificate, comma separated (wildcard for *.domain)": "Subdomains für das Zertifikat, Komma getrennt (Wildcard für *.domain)", "Subnet": "Subnetz", "Subscription banner removal failed": "Das Entfernen des Abonnementbanners ist fehlgeschlagen", "Subscription banner removed successfully": "Das Abonnementbanner wurde erfolgreich entfernt", "Subscription banner restored successfully (desktop and mobile)": "Abonnementbanner erfolgreich wiederhergestellt (Desktop und Mobilgerät)", "Success": "Erfolg", "Successful": "Erfolgreich", + "Supervisor does not confirm healthy and supported yet": "Supervisor bestätigt nicht gesund und unterstützt noch", + "Supervisor reports no connectivity; retrying to get versions and install components": "Supervisor meldet keine Konnektivität; erneuter Versuch, Versionen zu erhalten und Komponenten zu installieren", "Supported formats: .img, .qcow2, .vmdk, .raw": "Unterstützte Formate: .img, .qcow2, .vmdk, .raw", + "Swap": "Swap", "Swap partition detected": "Swap-Partition erkannt", "Swappiness configuration created successfully": "Swappiness-Konfiguration erfolgreich erstellt", + "Swing Music is a beautifully designed, self-hosted music streaming server. Like a cooler Spotify ... but bring your own music.": "Swing Music ist ein wunderschön gestalteter, selbst gehosteter Musik-Streaming-Server. Wie ein cooler Spotify ... aber bringen Sie Ihre eigene Musik.", "Switch GPU Mode (VM <-> LXC)": "GPU-Modus wechseln (VM <-> LXC)", "Switch Mode": "Modus wechseln", "Switch Script Not Found": "Switch-Skript nicht gefunden", @@ -4287,13 +5602,21 @@ "Switching to": "Wechseln zu", "Switching to GPU -> LXC mode removes VFIO exclusivity.": "Durch den Wechsel in den GPU->LXC-Modus wird die VFIO-Exklusivität aufgehoben.", "Switching to GPU -> VM mode requires exclusive VFIO binding.": "Der Wechsel in den GPU -> VM-Modus erfordert eine exklusive VFIO-Bindung.", + "Symbolic link in a restored volume path": "Symbolische Verknüpfung in einem wiederhergestellten Volumenpfad", + "Symbolic link in the path of an adaptation": "Symbolische Verknüpfung im Weg einer Adaption", + "Symbolic link loop in the new image": "Symbolische Linkschleife im neuen Bild", + "Symbolic link outside the rootfs of the new image": "Symbolischer Link außerhalb der Rootfs des neuen Bildes", "Synchronize time automatically": "Zeit automatisch synchronisieren", + "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are.": "Synclounge ist ein Drittanbieter-Tool, mit dem Sie Plex synchron mit Ihren Freunden / Ihrer Familie ansehen können, wo auch immer Sie sind.", + "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet.": "Syncthing ersetzt proprietäre Sync- und Cloud-Dienste durch etwas Offenes, Vertrauenswürdiges und Dezentralisiertes. Ihre Daten sind Ihre Daten allein und Sie verdienen es zu wählen, wo sie gespeichert werden, ob sie mit Dritten geteilt werden und wie sie über das Internet übertragen werden.", + "Sysctl not namespaced or not valid:": "Sysctl nicht namespaced oder nicht gültig:", "System": "System", "System CLI Tools": "System-CLI-Tools", "System Disk Size (GB)": "Größe der Systemfestplatte (GB)", "System Update Information": "Informationen zur Systemaktualisierung", "System Utilities Installer": "Installationsprogramm für Systemdienstprogramme", "System disk is SSD or M.2. Proceeding with Log2RAM setup.": "Systemfestplatte ist SSD oder M.2. Fahren Sie mit der Einrichtung von Log2RAM fort.", + "System error:": "Systemfehler:", "System errors and logs": "Systemfehler und Protokolle", "System group apex already exists.": "Der Systemgruppen-Apex ist bereits vorhanden.", "System group apex created.": "Systemgruppen-Apex erstellt.", @@ -4304,6 +5627,7 @@ "System limits increase completed.": "Erhöhung der Systemlimits abgeschlossen.", "System limits optimizations removed": "Systemlimitoptimierungen entfernt", "System must be updated to latest PVE 8.4+ before starting": "Das System muss vor dem Start auf die neueste PVE 8.4+ aktualisiert werden", + "System path mounts are not yet supported": "Systempfadhalterungen werden noch nicht unterstützt", "System reboot required": "Systemneustart erforderlich", "System upgrade completed": "Systemaktualisierung abgeschlossen", "System uptime": "Systemverfügbarkeit", @@ -4318,6 +5642,11 @@ "TROUBLESHOOTING:": "FEHLERBEHEBUNG:", "TUI mode": "TUI-Modus", "TUI mode (requires root)": "TUI-Modus (erfordert Root)", + "Take control of your Minecraft servers.": "Übernehmen Sie die Kontrolle über Ihre Minecraft-Server.", + "Tandoor WebUI": "Tandoor WebUI", + "Tandoor configuration cancelled": "Tandoor-Konfiguration aufgehoben", + "Tandoor needs at least 1 GB for staticfiles and 4 GB for PostgreSQL": "Tandoor benötigt mindestens 1 GB für statische Dateien und 4 GB für PostgreSQL", + "Tandoor needs to complete its first start to create the initial administrator": "Tandoor muss seinen ersten Start abschließen, um den ursprünglichen Administrator zu erstellen", "Target IQN:": "Ziel-IQN:", "Target VM": "Ziel-VM", "Target VM validated": "Ziel-VM validiert", @@ -4327,6 +5656,12 @@ "Target mode": "Zielmodus", "Target server:": "Zielserver:", "Target:": "Ziel:", + "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server.": "Tautulli ist eine Python-basierte Webanwendung für Überwachung, Analyse und Benachrichtigungen für Plex Media Server.", + "Teable adopts a concise spreadsheet interface, yet creates powerful database applications": "Teable verwendet eine prägnante Tabellenkalkulationsoberfläche und erstellt leistungsstarke Datenbankanwendungen", + "Telegram is a cloud-based mobile and desktop messaging app.": "Telegram ist eine Cloud-basierte mobile und Desktop-Messaging-App.", + "Temporary data container:": "Temporäre Datencontainer:", + "Temporary login": "Temporäre Anmeldung", + "Temporary password retrieved": "Temporäres Passwort abgerufen", "Temporary working directory (if present):": "Temporäres Arbeitsverzeichnis (falls vorhanden):", "Terminal Multiplexers": "Terminal-Multiplexer", "Terminal multiplexer (Ctrl+b then d to detach, or type exit)": "Terminal-Multiplexer (Strg+B, dann D zum Trennen oder Exit eingeben)", @@ -4343,40 +5678,197 @@ "Testing comprehensive guest access to server": "Testen eines umfassenden Gastzugriffs auf den Server", "Testing connectivity to portal...": "Verbindung zum Portal wird getestet...", "Testing network connectivity...": "Netzwerkkonnektivität testen...", + "Text that new pads start with (empty = the text of the image)": "Text, mit dem neue Pads beginnen (leer = der Text des Bildes)", "Thank you for using ProxMenux. Goodbye!": "Vielen Dank, dass Sie ProxMenux verwenden. Auf Wiedersehen!", "That VM is currently stopped, so the GPU can be reassigned now.": "Diese VM ist derzeit gestoppt, sodass die GPU jetzt neu zugewiesen werden kann.", "That doesn't look like an SSH private key. Pick the private key file (no .pub extension, parseable by ssh-keygen).": "Das sieht nicht nach einem privaten SSH-Schlüssel aus. Wählen Sie die private Schlüsseldatei aus (keine .pub-Erweiterung, per ssh-keygen analysierbar).", + "The .conf files under /config/fail2ban are rewritten on every start. Keep customizations in the matching .local file, for example jail.local for jail.conf.": "Die .conf Dateien unter /config/fail2ban werden bei jedem Start neu geschrieben. Bewahren Sie Anpassungen in der passenden .local-Datei auf, z. B. jail.local für jail.conf.", + "The AppArmor/seccomp relaxation does not include the required consent": "Die AppArmor/seccomp Entspannung beinhaltet nicht die required Zustimmung", + "The Bookmark Everything App": "Die Bookmark Everything App", + "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile.": "Der Brave Browser ist ein schneller, privater und sicherer Webbrowser für PC, Mac und Mobilgeräte.", + "The CT already exists:": "Das CT existiert bereits:", + "The Compose file declares no service": "Die Compose-Datei erklärt keinen Dienst", + "The Compose file describes several images:": "Die Compose-Datei beschreibt mehrere Bilder:", + "The Compose file does not contain a Compose document": "Die Compose-Datei enthält kein Compose-Dokument", + "The Compose file is not valid YAML:": "Die Compose-Datei ist nicht gültig YAML:", + "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "Das Compose bietet eine optionale AppArmor- oder seccomp-Entspannung; es bleibt deaktiviert, es sei denn, der Benutzer wählt es aus. Fahren Sie nur fort, wenn Sie dem Image vertrauen und dieses Risiko akzeptieren.", + "The Compose value must be text or a list:": "Der Compose-Wert muss Text oder eine Liste sein:", + "The DRM node is not an Intel or AMD GPU; NVIDIA requires its library profile": "Der DRM-Knoten ist keine Intel- oder AMD-GPU; NVIDIA requires sein Bibliotheksprofil", + "The Entrypoint/Cmd combination is empty": "Die Entrypoint/Cmd combination ist leer", + "The FUSE publication helper was not found": "Der FUSE Publikationshelfer wurde nicht gefunden", + "The GPU evidence does not match the verified devices": "Der GPU-Beweis stimmt nicht mit den verifizierten Geräten überein", "The GPU has been moved out of VM": "Die GPU wurde aus der VM verschoben", + "The GPU identity or permissions changed; the container is not modified": "Die GPU-Identität oder Berechtigungen geändert; der Container wird nicht geändert", "The GPU is being detached from VM": "Die GPU wird von der VM getrennt", + "The GPU vendor differs from the requested profile": "Der GPU-Anbieter unterscheidet sich vom gewünschten Profil", + "The GPU vendor does not match the selected GPU profile:": "Der GPU-Anbieter stimmt nicht mit dem ausgewählten GPU-Profil überein:", + "The Immich CPU quota cannot be reproduced": "Die Immich CPU-Quote kann nicht reproduziert werden", + "The Immich library needs at least 8 GB": "Die Immich-Bibliothek benötigt mindestens 8 GB", + "The Immich startup was modified or cannot be reproduced": "Das Immich-Startup wurde modifiziert oder kann nicht reproduziert werden", + "The LXC has stopped": "Der LXC wurde gestoppt", + "The Lounge starts in public mode: anyone who reaches the address opens the client without logging in, and the IRC networks added are lost when the session ends.": "Die Lounge startet im öffentlichen Modus: Jeder, der die Adresse erreicht, öffnet den Client, ohne sich anzumelden, und die hinzugefügten IRC-Netzwerke gehen verloren, wenn die Sitzung endet.", + "The MAC address of the container cannot be kept": "Die MAC-Adresse des Containers kann nicht gespeichert werden", "The NVIDIA Container Toolkit repository definition was empty.": "Die NVIDIA Container Toolkit-Repository-Definition war leer.", "The NVIDIA Container Toolkit signing key could not be read.": "Der NVIDIA Container Toolkit-Signaturschlüssel konnte nicht gelesen werden.", + "The NVIDIA Container Toolkit version cannot be identified": "Die NVIDIA Container Toolkit Version kann nicht identifiziert werden", + "The NVIDIA destination cannot be replaced": "Die NVIDIA Destination kann nicht ersetzt werden", + "The NVIDIA destination escapes the rootfs": "Das NVIDIA-Ziel entkommt den Rootfs", "The NVIDIA driver is installed, but the Container Toolkit phase did not complete. GPU support for OCI containers is unavailable until it does.": "Der NVIDIA-Treiber ist installiert, aber die Container Toolkit-Phase wurde nicht abgeschlossen. Die GPU-Unterstützung für OCI-Container ist bis dahin nicht verfügbar.", + "The NVIDIA driver or inventory changed; the operation was stopped": "Der NVIDIA-Treiber oder -Inventar wurde geändert; die operation wurde gestoppt", + "The NVIDIA hook or environment differs from the declared one": "Der NVIDIA-Hook oder die Umgebung unterscheidet sich von dem deklarierten", + "The NVIDIA hook path does not belong to the installer": "Der NVIDIA-Hookpfad gehört nicht zum Installateur", "The NVIDIA installer needs at least": "Das NVIDIA-Installationsprogramm benötigt mindestens", + "The NVIDIA runtime is up to date; the container is not modified or started": "Die NVIDIA Laufzeit ist aktuell; der Container wird nicht geändert oder gestartet", + "The Nextcloud volume needs at least 8 GB": "Das Nextcloud-Volume benötigt mindestens 8 GB", + "The OCI archive contains no SHA-256 blobs": "Das OCI-Archiv enthält keine SHA-256 Blobs", + "The OCI archive does not contain exactly one manifest": "Das OCI-Archiv enthält nicht genau ein Manifest", + "The OCI archive does not exist or is empty:": "Das OCI-Archiv existiert nicht oder ist leer:", + "The OCI archive verifier was not found": "Der OCI-Archivverifikator wurde nicht gefunden", + "The OCI catalog is not installed. Update ProxMenux and try again.": "Der OCI-Katalog ist nicht installiert. Aktualisieren Sie ProxMenux und versuchen Sie es erneut.", + "The OCI engine is not installed. Update ProxMenux and try again.": "Der OCI-Motor ist nicht installiert. Aktualisieren Sie ProxMenux und versuchen Sie es erneut.", + "The OCI image storage was not kept": "Der OCI-Bildspeicher wurde nicht beibehalten", + "The OCR language must use Tesseract codes, for example eng or eng+spa": "Die OCR-Sprache muss Tesseract-Codes verwenden, z. B. eng oder eng+spa", + "The PATH of the new image is outside the reproducible profile": "Der PATH des neuen Bildes liegt außerhalb des reproduzierbaren Profils", + "The Paperless persistent volumes need at least 8 GB": "Die papierlosen persistenten Volumes benötigen mindestens 8 GB", + "The PostgreSQL volume needs at least 4 GB": "Das PostgreSQL-Volume benötigt mindestens 4 GB", + "The PostgreSQL volume needs at least 8 GB": "Das PostgreSQL-Volume benötigt mindestens 8 GB", "The Proxmox archive keyring is missing; Ceph installation cannot continue safely": "Der Archivschlüsselbund Proxmox fehlt;Die Ceph-Installation kann nicht sicher fortgesetzt werden", + "The Proxmox inventory and the local configurations differ": "Das Proxmox-Inventar und die lokalen Konfigurationen unterscheiden sich", + "The Rclone configuration needs at least 1 GB": "Die Rclone-Konfiguration benötigt mindestens 1 GB", + "The Rclone rootfs needs at least 2 GB": "Die Rclone Rootfs benötigen mindestens 2 GB", + "The Selkies profile requires a verified LinuxServer image": "Das Selkies Profil requires ein verifiziertes LinuxServer Image", + "The Tandoor files volume needs at least 2 GB": "Das Tandoor-Dateivolumen benötigt mindestens 2 GB", "The URL does not contain the required parameters (id, pack, edition).": "Die URL enthält nicht die erforderlichen Parameter (ID, Pack, Edition).", + "The USB number can change after reconnecting or rebooting. This profile does not remap it automatically or handle Coral USB re-enumeration. Do not share a dongle already used by another service.": "Die USB-Nummer kann sich nach dem Wiederanschließen oder Neustarten ändern. Dieses Profil ordnet es nicht automatisch neu oder verarbeitet Coral USB-Wiederaufzählung. Teilen Sie keinen Dongle, der bereits von einem anderen Dienst verwendet wurde.", + "The Unifi-controller software is a powerful, enterprise wireless software engine ideal for high-density client deployments requiring low latency and high uptime performance.": "Die Unifi-Controller-Software ist eine leistungsstarke, drahtlose Enterprise-Software-Engine, die sich ideal für Client-Bereitstellungen mit hoher Dichte requiring mit niedriger Latenz und hoher Betriebszeit eignet.", + "The VA-API device does not exist:": "Das VA-API-Gerät existiert nicht:", "The VM also has these audio devices assigned via PCI passthrough — typically added together with the GPU. Remove them too?": "Der VM werden diese Audiogeräte auch über PCI-Passthrough zugewiesen – normalerweise zusammen mit der GPU hinzugefügt. Auch entfernen?", "The VM guest will have exclusive access to the GPU.": "Der VM-Gast hat exklusiven Zugriff auf die GPU.", "The VM is powered on. Turn it off before adding disks.": "Die VM ist eingeschaltet. Schalten Sie es aus, bevor Sie Festplatten hinzufügen.", "The VM/LXC will lose access to this disk after formatting.": "Nach der Formatierung verliert die VM/LXC den Zugriff auf diese Festplatte.", + "The VMID belongs to another container now and is not touched:": "Der VMID gehört jetzt zu einem anderen Container und wird nicht berührt:", + "The VMID or its contract is already in use; it is not adopted": "Der VMID oder sein Vertrag ist bereits in Gebrauch; er wird nicht übernommen", + "The VMID was reused or its identity is unknown; the operation is blocked": "Die VMID wurde wiederverwendet oder ihre Identität ist unbekannt; die operation ist blockiert", + "The VMID was reused or the container is on another node; it is not overwritten": "Der VMID wurde wiederverwendet oder der Container befindet sich auf einem anderen Knoten; er wird nicht überschrieben", + "The VMID was taken during the installation:": "Die VMID wurde während der Installation aufgenommen:", + "The Valkey volume needs at least 1 GB": "Das Valkey-Volume benötigt mindestens 1 GB", + "The acceleration evidence differs from the verified inventory": "Der Beschleunigungsnachweis unterscheidet sich vom verifizierten Inventar", + "The acceleration profile does not support this architecture:": "Das Beschleunigungsprofil unterstützt diese Architektur nicht:", "The active kernel driver is not vfio-pci, but the entry in": "Der aktive Kernel-Treiber ist nicht vfio-pci, sondern der Eintrag in", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot, breaking the LXC passthrough about to be configured.": "Der aktive Kernel-Treiber ist nicht vfio-pci, aber der Eintrag bindet die GPU beim nächsten Neustart erneut an vfio-pci, wodurch der zu konfigurierende LXC-Passthrough unterbrochen wird.", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot.": "Der aktive Kernel-Treiber ist nicht vfio-pci, aber der Eintrag bindet die GPU beim nächsten Neustart erneut an vfio-pci.", + "The adaptation content was modified": "Der Adaptionsgehalt wurde modifiziert", + "The additional path hides a system directory": "Der zusätzliche Pfad verbirgt ein Systemverzeichnis", + "The address is already assigned on this host or cluster:": "Die Adresse ist bereits auf diesem Host oder Cluster zugewiesen:", + "The address must start with http:// or https://": "Die Adresse muss mit http:// oder https:// beginnen.", + "The administrator account, the public address and the UDP port are created on the first start, so the web interface opens directly on its login page.": "Das Administratorkonto, die öffentliche Adresse und der UDP-Port werden beim ersten Start erstellt, so dass sich das Webinterface direkt auf seiner Anmeldeseite öffnet.", + "The administrator email is not valid": "Die Administrator-E-Mail ist nicht gültig", + "The administrator user contains characters that are not allowed": "Der Administrator-Benutzer enthält Zeichen, die nicht erlaubt sind", + "The all-in-one AI application.": "Die All-in-One AI-Anwendung.", + "The application configuration needs a first start to complete.": "Die Anwendungskonfiguration muss einen ersten Start abschließen.", + "The application did not complete its initial setup:": "Die Anwendung hat ihre erste Einrichtung nicht abgeschlossen:", + "The application did not get an address on the access network:": "Die Anwendung hat keine Adresse im Zugangsnetz erhalten:", + "The application did not pass its HTTP check:": "Die Anwendung hat ihren HTTP-Check nicht bestanden:", + "The application did not respond in time:": "Der Antrag hat nicht rechtzeitig geantwortet:", + "The application stopped during its first start:": "Die Anwendung wurde während ihres ersten Starts gestoppt:", + "The application was removed": "Die Anwendung wurde entfernt", "The archive could not be extracted.": "Das Archiv konnte nicht extrahiert werden.", "The archive destination directory is INSIDE one of the paths you are about to back up. Writing the archive there would copy the backup into itself — producing a corrupted archive, or growing without limit until the disk fills up.": "Das Zielverzeichnis des Archivs befindet sich INNERHALB eines der Pfade, die Sie sichern möchten. Wenn Sie das Archiv dorthin schreiben, wird das Backup in sich selbst kopiert – was zu einem beschädigten Archiv führt oder unbegrenzt wächst, bis die Festplatte voll ist.", + "The backup could not be identified; the image is not replaced": "Das Backup konnte nicht identifiziert werden; das Bild wird nicht ersetzt", "The backup metadata was compared against this host. The following items will be SKIPPED to keep the boot safe:": "Die Backup-Metadaten wurden mit diesem Host verglichen. Die folgenden Elemente werden ÜBERSPRINGT, um die Sicherheit des Stiefels zu gewährleisten:", + "The backup of a member could not be identified": "Das Backup eines Mitglieds konnte nicht identifiziert werden", + "The backup was altered; recovery blocked": "Das Backup wurde geändert; Recovery blockiert", "The backup was taken on a different PVE or kernel major.minor. These paths will be SKIPPED to keep the boot safe:": "Das Backup wurde auf einem anderen PVE oder Kernel-Major. Minor erstellt. Diese Pfade werden ÜBERSPRINGT, um die Boot-Sicherheit zu gewährleisten:", + "The bind mount target escapes the rootfs:": "Das bind mount target entkommt den rootfs:", + "The block device does not exist:": "Das Blockgerät existiert nicht:", "The build could not be checked beforehand; continuing without that check.": "Der Build konnte vorher nicht überprüft werden;ohne diese Prüfung weitermachen.", + "The cached image does not match the current digest": "Das zwischengespeicherte Bild entspricht nicht dem aktuellen Digest", + "The cached image is damaged; it will be downloaded again.": "Das zwischengespeicherte Bild ist beschädigt; es wird erneut heruntergeladen.", + "The character device does not exist:": "Das Zeichengerät existiert nicht:", + "The command asks for a password that is not echoed. After creating the users, the web interface asks for a user name and a password.": "Der Befehl fragt nach einem Passwort, das nicht wiederholt wird. Nach dem Erstellen der Benutzer fragt die Weboberfläche nach einem Benutzernamen und einem Passwort.", + "The command does not name an image": "Der Befehl benennt kein Bild", + "The command reads its variables from a file; write them in the command or use a Compose file": "Der Befehl liest seine Variablen aus einer Datei; schreibe sie in den Befehl oder verwende eine Compose-Datei", + "The command runs the container as the user of the host; the container uses the user of its image instead.": "Der Befehl führt den Container als Benutzer des Hosts aus; der Container verwendet stattdessen den Benutzer seines Images.", + "The command uses options that cannot be translated:": "Der Befehl verwendet Optionen, die nicht übersetzt werden können:", + "The command works out a value by running another command:": "Der Befehl arbeitet einen Wert aus, indem er einen anderen Befehl ausführt:", "The compatibility check raised failures that may break the system after restore.": "Bei der Kompatibilitätsprüfung sind Fehler aufgetreten, die das System nach der Wiederherstellung beschädigen können.", + "The configuration changed after the backup was restored; the recovery is not confirmed": "Die Konfiguration wurde geändert, nachdem das Backup wiederhergestellt wurde; die Wiederherstellung wird nicht bestätigt", + "The configuration changed after the new container was validated": "Die Konfiguration wurde geändert, nachdem der neue Container validiert wurde", + "The configuration changed during the NVIDIA refresh": "Die Konfiguration wurde während der NVIDIA-Aktualisierung geändert", + "The configuration evidence does not match": "Der Konfigurationsnachweis stimmt nicht überein", + "The configuration must run as root on Proxmox VE": "Die Konfiguration muss als root auf Proxmox VE ausgeführt werden", + "The configuration of a new member changed after it was created": "Die Konfiguration eines neuen Mitglieds änderte sich, nachdem es erstellt wurde", + "The configuration stopped because of an unexpected error": "Die Konfiguration wurde wegen eines unerwarteten Fehlers gestoppt", + "The consume/export volumes need at least 1 GB": "Verbrauchs-/Exportvolumen benötigen mindestens 1 GB", + "The container could not be removed automatically:": "Der Container konnte nicht automatisch entfernt werden:", + "The container could not be started:": "Der Container konnte nicht gestartet werden:", + "The container creation does not match the prepared instance": "Die Containererstellung stimmt nicht mit der vorbereiteten Instanz überein", + "The container devices do not match the saved record": "Die Containergeräte stimmen nicht mit dem gespeicherten Datensatz überein", + "The container did not stop to update its persistent configuration:": "Der Container hat nicht angehalten, um seine persistente Konfiguration zu aktualisieren:", + "The container did not stop; its disks are not touched": "Der Container hat nicht angehalten; seine Scheiben werden nicht berührt", + "The container disks do not match the saved record": "Die Containerscheiben stimmen nicht mit dem gespeicherten Datensatz überein", + "The container does not exist:": "Der Container existiert nicht:", + "The container does not have the fuse=1 feature enabled": "Der Container hat die Funktion fuse=1 nicht aktiviert", + "The container does not need it any more; an update downloads the new version when there is one.": "Der Container benötigt ihn nicht mehr; ein Update lädt die neue Version herunter, wenn es eine gibt.", + "The container gets its own address and its own volumes, so the networks and volumes declared in the file are not used.": "Der Container erhält seine eigene Adresse und seine eigenen Volumes, so dass die in der Datei deklarierten Netzwerke und Volumes nicht verwendet werden.", + "The container has advanced Proxmox settings outside the supported profile": "Der Container verfügt über erweiterte Proxmox-Einstellungen außerhalb des unterstützten Profils", + "The container identity changed; the container is not replaced": "Die Containeridentität wurde geändert; der Container wird nicht ersetzt", + "The container identity does not match": "Die Containeridentität stimmt nicht überein", + "The container identity or configuration changed": "Container-Identität oder -Konfiguration geändert", "The container is currently stopped. Do you want to start it now to install the package?": "Der Container ist derzeit gestoppt. Möchten Sie es jetzt starten, um das Paket zu installieren?", + "The container is not modified because a host directory is not available:": "Der Container wird nicht geändert, da kein Hostverzeichnis verfügbar ist:", + "The container no longer exists:": "Der Container existiert nicht mehr:", + "The container of a member was replaced; the assembly is not resumed": "Der Container eines Mitglieds wurde ersetzt; die Montage wird nicht wieder aufgenommen", "The container should now start as privileged": "Der Container sollte nun als privilegiert starten", "The container should now start as unprivileged": "Der Container sollte nun als unprivilegiert starten", + "The container stopped after starting:": "Der Container wurde nach dem Start gestoppt:", + "The container stopped before publishing the mount": "Der Container stoppte vor der Veröffentlichung der Halterung", + "The container stopped before the GPU permissions were verified:": "Der Container wurde gestoppt, bevor die GPU-Berechtigungen verifiziert wurden:", + "The container stopped before the application responded:": "Der Container stoppte, bevor die Anwendung antwortete:", + "The container stopped:": "Der Container wurde gestoppt:", + "The container takes its time zone from Proxmox, so the time files of the host are not attached to it.": "Der Container nimmt seine Zeitzone von Proxmox, so dass die Zeitdateien des Hosts nicht an ihn angehängt sind.", + "The container was changed outside ProxMenux and an update would discard those changes:": "Der Container wurde außerhalb von ProxMenux geändert und ein Update würde diese Änderungen verwerfen:", + "The container was created from a downloaded OCI image": "Der Container wurde aus einem heruntergeladenen OCI-Image erstellt", + "The containers do not need them any more; an update downloads the new versions when there are any.": "Die Container brauchen sie nicht mehr; ein Update lädt die neuen Versionen herunter, wenn es welche gibt.", + "The containers were created from downloaded OCI images": "Die Container wurden aus heruntergeladenen OCI-Bildern erstellt", + "The coordinated backup was modified": "Das koordinierte Backup wurde modifiziert", "The current driver will be completely uninstalled before installing the new version. Continue?": "Der aktuelle Treiber wird vor der Installation der neuen Version vollständig deinstalliert. Weitermachen?", + "The current image of the saved channel will be checked and downloaded. Resources, paths and GPU are kept. The CT is stopped during the replacement and a native backup is created first.": "Das aktuelle Bild des gespeicherten Kanals wird überprüft und heruntergeladen. Ressourcen, Pfade und GPU werden beibehalten. Der CT wird während des Austauschs gestoppt und zuerst ein natives Backup erstellt.", + "The current record is missing for": "Der aktuelle Rekord fehlt für", + "The current template changes the image or identity; an explicit migration is required": "Die aktuelle Vorlage ändert das Bild oder die Identität; eine explizite Migration ist required", + "The current template requires a new persistent path:": "Die aktuelle Vorlage requires einen neuen persistenten Pfad:", + "The custom path cannot hide system directories": "Der benutzerdefinierte Pfad kann Systemverzeichnisse nicht verbergen", + "The custom path overlaps another mount": "Der benutzerdefinierte Pfad überlappt ein anderes Mount", + "The data and document volumes need at least 8 GB": "Die Daten- und Dokumentenvolumen benötigen mindestens 8 GB", + "The database server must accept connections from the IP address of this container, with a user that is not limited to localhost.": "Der Datenbankserver muss Verbindungen von der IP-Adresse dieses Containers mit einem Benutzer akzeptieren, der nicht auf localhost beschränkt ist.", + "The dedicated adapter still requires replaying its rootfs changes": "Der dedizierte Adapter requires wiederholt seine Rootfs-Änderungen", + "The dependency hook and the stack recipe differ": "Der Dependency Hook und das Stack-Rezept unterscheiden sich", + "The dependency hook was modified; review it before updating": "Der Dependency Hook wurde geändert; überprüfen Sie ihn vor der Aktualisierung", + "The developer-friendly cloud platform for building and running LLM agents for AI-native applications.": "Die entwicklerfreundliche Cloud-Plattform zum Erstellen und Ausführen von LLM-Agenten für AI-native Anwendungen.", + "The device directory does not exist:": "Das Geräteverzeichnis existiert nicht:", + "The device must keep its /dev path inside the LXC:": "Das Gerät muss seinen /dev-Pfad im LXC beibehalten:", + "The device must keep its native path without duplicates": "Das Gerät muss seinen nativen Pfad ohne Duplikate beibehalten", + "The directory contains no character devices:": "Das Verzeichnis enthält keine Zeichengeräte:", "The directory does not exist in the CT.": "Das Verzeichnis ist im CT nicht vorhanden.", "The disk": "Die Festplatte", + "The disk size cannot be reproduced": "Die Festplattengröße kann nicht reproduziert werden", + "The disk usage of the container could not be read": "Die Festplattennutzung des Containers konnte nicht gelesen werden", + "The domain must resolve to the public address of this network before the certificate can be issued.": "Die Domain muss sich auf die öffentliche Adresse dieses Netzwerks auflösen, bevor das Zertifikat ausgestellt werden kann.", + "The download client still needs to be configured.": "Der Download-Client muss noch konfiguriert werden.", + "The download stopped progressing; cancelling this attempt.": "Der Download hat aufgehört voranzukommen; diesen Versuch abzubrechen.", + "The downloaded image does not match its manifest": "Das heruntergeladene Bild stimmt nicht mit seinem Manifest überein", + "The downloaded image is corrupt:": "Das heruntergeladene Bild ist beschädigt:", "The dpkg package database is clean.": "Die dpkg-Paketdatenbank ist sauber.", "The driver installed but does not drive this GPU.": "Der Treiber ist installiert, treibt diese GPU jedoch nicht an.", + "The dynamic NVIDIA hook is missing": "Der dynamische NVIDIA-Hook fehlt", + "The dynamic NVIDIA hook is missing or duplicated": "Der dynamische NVIDIA-Hook fehlt oder dupliziert", + "The dynamic NVIDIA profile requires an unprivileged LXC": "Das dynamische NVIDIA Profil requires und unprivilegierte LXC", + "The dynamic profile does not support static driver mounts": "Das dynamische Profil unterstützt keine statischen Treiberhalterungen", "The file does not exist, is empty or is not readable.": "Die Datei existiert nicht, ist leer oder nicht lesbar.", + "The file does not exist:": "Die Datei existiert nicht:", + "The file is too large to be a Compose file": "Die Datei ist zu groß, um eine Compose-Datei zu sein", "The filesystem": "Das Dateisystem", + "The final cleanup did not complete:": "Die endgültige Bereinigung wurde nicht abgeschlossen:", "The following DKMS-managed drivers will now be rebuilt against it so they keep working after reboot:": "Die folgenden von DKMS verwalteten Treiber werden nun entsprechend neu erstellt, sodass sie nach dem Neustart weiterhin funktionieren:", "The following LXC containers have NVIDIA passthrough configured:": "Für die folgenden LXC-Container ist NVIDIA-Passthrough konfiguriert:", "The following backup paths are kernel-tied and are excluded from the picker to keep the target's boot safe. The operator's own tuning inside these paths (IOMMU cmdline, VFIO IDs, custom quirks) is merged back automatically via kernel-agnostic merge:": "Die folgenden Sicherungspfade sind an den Kernel gebunden und werden von der Auswahl ausgeschlossen, um den Start des Ziels zu gewährleisten. Die eigene Abstimmung des Betreibers innerhalb dieser Pfade (IOMMU-Cmdline, VFIO-IDs, benutzerdefinierte Macken) wird automatisch über die Kernel-agnostische Zusammenführung wieder zusammengeführt:", @@ -4390,17 +5882,99 @@ "The following selected device(s) are Physical Functions with active Virtual Functions:": "Bei den folgenden ausgewählten Geräten handelt es sich um physische Funktionen mit aktiven virtuellen Funktionen:", "The following selected device(s) are SR-IOV Virtual Functions (VFs):": "Die folgenden ausgewählten Geräte sind SR-IOV Virtual Functions (VFs):", "The fstab entry will still be removed; reboot or manual umount needed.": "Der fstab-Eintrag wird weiterhin entfernt; Neustart oder manuelles Umount erforderlich.", + "The gateway must be another usable address in the same subnet.": "Das Gateway muss eine andere nutzbare Adresse im selben Subnetz sein.", "The gateway should appear in your Tailscale admin console shortly.": "Das Gateway sollte in Kürze in Ihrer Tailscale-Administratorkonsole erscheinen.", + "The healthcheck cannot run without an IP address": "Der Healthcheck kann nicht ohne IP-Adresse laufen", + "The host NVIDIA driver is not responding correctly": "Der Host NVIDIA Fahrer reagiert nicht richtig", + "The host bind source does not exist:": "Die Host-Bind-Quelle existiert nicht:", + "The host bind source is not a regular file or directory:": "Die Host-Bind-Quelle ist keine reguläre Datei oder ein Verzeichnis:", + "The host directory changed before it was mounted": "Das Host-Verzeichnis wurde geändert, bevor es gemountet wurde", "The host directory may not be accessible from an unprivileged container.": "Auf das Hostverzeichnis kann von einem unprivilegierten Container aus möglicherweise nicht zugegriffen werden.", + "The host has no IPv4 address on the selected bridge": "Der Host hat keine IPv4-Adresse auf der ausgewählten Brücke", + "The host monitor does not see the real host memory": "Der Host-Monitor sieht den echten Host-Speicher nicht", + "The host monitor does not share this host namespace:": "Der Host-Monitor teilt diesen Host-Namespace nicht:", + "The host monitor needs consent for privileged access to the host": "Der Host-Monitor benötigt die Zustimmung für den privilegierten Zugriff auf den Host", + "The host monitor profile does not support another sysctl include": "Das Host-Monitor-Profil unterstützt kein weiteres sysctl include", + "The host monitor uses the host network, without DHCP or its own gateway": "Der Host-Monitor nutzt das Host-Netzwerk ohne DHCP oder eigenes Gateway", + "The host port is already in use:": "Der Host-Port wird bereits verwendet:", + "The identity of a member was replaced": "Die Identität eines Mitglieds wurde ersetzt", + "The image changes the user expected by the adapter": "Das Bild ändert den Benutzer, den der Adapter erwartet", + "The image could not be read from its registry:": "Das Bild konnte nicht aus seiner Registry gelesen werden:", + "The image declares data paths that are still stored in the rootfs": "Das Bild deklariert Datenpfade, die noch in den Rootfs gespeichert sind", + "The image did not grant the application user access to the devices; check its native init. Host permissions were not relaxed.": "Das Bild gewährte dem Anwendungsbenutzer keinen Zugriff auf die Geräte; Überprüfen Sie seine native Init. Host-Berechtigungen wurden nicht gelockert.", + "The image did not pass the integrity check": "Das Bild hat die Integritätsprüfung nicht bestanden", + "The image does not declare support for this architecture:": "Das Bild erklärt keine Unterstützung für diese Architektur:", + "The image download did not complete correctly; downloading it again...": "Der Bild-Download wurde nicht korrekt abgeschlossen; erneut herunterladen...", + "The image expects files that are given to it one by one:": "Das Bild erwartet Dateien, die ihm nacheinander gegeben werden:", + "The image is already up to date; nothing was changed.": "Das Bild ist bereits auf dem neuesten Stand; nichts wurde geändert.", + "The image is in its registry, for one architecture.": "Das Bild befindet sich in seiner Registrierung, für eine Architektur.", + "The image is in its registry.": "Das Bild befindet sich in seiner Registry.", + "The image is in its registry:": "Das Bild befindet sich in seiner Registrierung:", + "The image requests NVIDIA, but the host has no working NVIDIA driver": "Das Bild fordert NVIDIA an, aber der Host hat keinen funktionierenden NVIDIA-Treiber", + "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk.": "Das Bild fordert die Deaktivierung eines Teils der AppArmor- oder seccomp-Beschränkung auf. Fahren Sie nur fort, wenn Sie dem Image vertrauen und dieses Risiko akzeptieren.", + "The image requests disabling part of the AppArmor or seccomp confinement. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "Das Bild fordert die Deaktivierung eines Teils der AppArmor- oder seccomp-Beschränkung auf. Das Compose bietet eine optionale AppArmor- oder seccomp-Entspannung; es bleibt deaktiviert, es sei denn, der Benutzer wählt es aus. Fahren Sie nur fort, wenn Sie dem Image vertrauen und dieses Risiko akzeptieren.", + "The image was not found in its registry, or it is private:": "Das Bild wurde nicht in seiner Registrierung gefunden, oder es ist privat:", + "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged.": "Die importierte Compose verlangt privilegiert, aber die offizielle jlesage/handbrake Dokumentation require es nicht; ProxMenux hält die LXC unprivilegiert.", + "The imported OCI groups are not numeric": "Importierte OCI-Gruppen sind nicht numerisch", + "The imported OCI user or group is not numeric": "Der importierte OCI-Benutzer oder -Gruppe ist nicht numerisch", + "The initial user name and password stay written in /etc/pve/lxc/.conf as INIT_USERNAME and INIT_PASSWORD. They can be removed after the first login, with the container stopped.": "Der ursprüngliche Benutzername und das Passwort bleiben in /etc/pve/lxc/.conf als INIT USERNAME und INIT PASSWORD geschrieben. Sie können nach dem ersten Login entfernt werden, wenn der Container angehalten wird.", + "The installation asks which one to use for these paths.": "Die Installation fragt, welche für diese Pfade verwendet werden soll.", + "The installation ended with exit code": "Die Installation endete mit Exit-Code", "The installation requires a server restart to apply changes. Do you want to restart now?": "Die Installation erfordert einen Serverneustart, um die Änderungen zu übernehmen. Möchten Sie jetzt neu starten?", + "The installation runs on the Proxmox node itself, as root": "Die Installation läuft auf dem Proxmox-Knoten selbst, als root", + "The installation stopped because of an unexpected error": "Die Installation wurde wegen eines unerwarteten Fehlers gestoppt", "The installation/changes require a server restart to apply correctly. Do you want to reboot now?": "Die Installation/Änderungen erfordern einen Serverneustart, um korrekt angewendet zu werden. Möchten Sie jetzt neu starten?", + "The installer must run as root on Proxmox VE": "Der Installer muss als root auf Proxmox VE laufen", + "The instance changed while it was being edited; configure Recreate again": "Die Instanz wurde geändert, während sie bearbeitet wurde; konfigurieren Neu erstellen erneut", + "The instance does not use NVIDIA": "Die Instanz verwendet NVIDIA nicht", + "The instance has a pending operation": "Die Instanz hat eine ausstehende operation", + "The instance identity or status must be reviewed before updating.": "Die Instanzidentität oder der Status muss vor der Aktualisierung überprüft werden.", + "The instance is not ready to be updated": "Die Instanz ist nicht bereit für eine Aktualisierung", + "The instance is not ready; review its pending operation": "Die Instanz ist nicht bereit; überprüfen Sie die anhängige operation", + "The instance record operation did not complete; no container was modified.": "Der Instanzdatensatz operation wurde nicht abgeschlossen; kein Container wurde geändert.", + "The instance registry is not safe": "Die Instanzregistrierung ist nicht sicher", + "The journal belongs to another VMID": "Das Journal gehört zu einem anderen VMID", + "The journal belongs to another stack": "Das Journal gehört zu einem anderen Stapel", + "The journal has an incomplete recovery state": "Das Journal hat einen unvollständigen Wiederherstellungszustand", + "The kernel module is not active:": "Das Kernelmodul ist nicht aktiv:", "The kernel module of version": "Das Kernelmodul der Version", "The local envelope is dropped and future backups do not upload anything. Uploaded envelopes already on PBS stay intact and remain recoverable with their original passphrase.": "Der lokale Umschlag wird gelöscht und zukünftige Sicherungen laden nichts hoch. Bereits auf PBS hochgeladene Umschläge bleiben intakt und können mit ihrer ursprünglichen Passphrase wiederhergestellt werden.", "The long test runs directly on the disk hardware.": "Der Langzeittest läuft direkt auf der Festplatten-Hardware.", + "The main member must stop first and start last": "Hauptmitglied muss zuerst aufhören und zuletzt beginnen", + "The main member of the stack is missing": "Das Hauptelement des Stapels fehlt", + "The manifest does not match its digest": "Das Manifest passt nicht zu seinem Digest", + "The member journal belongs to another stack operation": "Das Member Journal gehört zu einem anderen Stack operation", + "The member journal is outside the registry": "Das Mitgliedsjournal befindet sich außerhalb der Registry", + "The mount evidence does not match the verified directories": "Der Mount-Beweis stimmt nicht mit den verifizierten Verzeichnissen überein", + "The mount source or options were not kept": "Die Mount-Quelle oder Optionen wurden nicht gehalten", + "The mounted source differs from the configured directory": "Die gespeicherte Quelle unterscheidet sich vom konfigurierten Verzeichnis", + "The mounts of the new container do not match the proposal": "Die Halterungen des neuen Containers entsprechen nicht dem Vorschlag", + "The native GPU permissions were not kept": "Die nativen GPU-Berechtigungen wurden nicht eingehalten", + "The native unprivileged idmap is required": "Die native unprivilegierte idmap ist required", "The new SSH key was installed and is now authorized on the server.\nKey file:": "Der neue SSH-Schlüssel wurde installiert und ist nun auf dem Server autorisiert.\nSchlüsseldatei:", "The new SSH key was pushed to the LXC via 'pct exec' on": "Der neue SSH-Schlüssel wurde über „pct exec“ an den LXC übertragen", + "The new Valkey volume contains unexpected data": "Das neue Valkey Volume enthält unerwartete Daten", + "The new container did not pass validation": "Der neue Container bestand die Validierung nicht", + "The new container is not authorized by the operation journal": "Der neue Container ist nicht durch das operation Journal autorisiert", + "The new image adds a symbolic link in a generated path": "Das neue Bild fügt einen symbolischen Link in einem generierten Pfad hinzu", + "The new image changes the PostgreSQL major version; the data must be migrated before updating": "Das neue Bild ändert die PostgreSQL Hauptversion; die Daten müssen vor der Aktualisierung migriert werden", + "The new image could not be installed": "Das neue Image konnte nicht installiert werden", + "The new image could not be installed:": "Das neue Image konnte nicht installiert werden:", + "The new image does not keep a required executable": "Das neue Image hält eine required nicht ausführbar", + "The new image requires additional persistent paths": "Das neue Bild requires zusätzliche persistente Pfade", + "The new image requires additional persistent paths; use Recreate": "Das neue Bild requires zusätzliche persistente Pfade; verwenden Recreate", "The new prompt will be used in new terminal sessions.": "Die neue Eingabeaufforderung wird in neuen Terminalsitzungen verwendet.", "The next visit to the dashboard will show the initial setup wizard.": "Beim nächsten Besuch des Dashboards wird der Ersteinrichtungsassistent angezeigt.", + "The observed inventory differs from the validated runtime": "Das beobachtete Inventar unterscheidet sich von der validierten Laufzeit", + "The official Tandoor startup executable is missing": "Die offizielle Tandoor Startup Executable fehlt", + "The official inventory contains no NVIDIA devices": "Das offizielle Inventar enthält keine NVIDIA Geräte", + "The official inventory contains no NVIDIA driver components": "Das offizielle Inventar enthält keine NVIDIA Treiberkomponenten", + "The official startup cannot be reproduced": "Das offizielle Startup kann nicht reproduziert werden", + "The official startup of the application is missing": "Der offizielle Start der Anwendung fehlt", + "The operation already finished; it is not restored automatically": "Die operation ist bereits fertig; sie wird nicht automatisch wiederhergestellt", + "The operation could not be completed": "Die operation konnte nicht abgeschlossen werden", + "The operation stopped halfway. Choose \"Recover\" for this container in the OCI management menu to restore the previous installation.": "Die operation blieb auf halbem Weg stehen. Wählen Sie \"Wiederherstellen\" für diesen Container im OCI-Verwaltungsmenü, um die vorherige Installation wiederherzustellen.", + "The operation was stopped because a shared directory changed its identity:": "Die operation wurde gestoppt, weil ein gemeinsames Verzeichnis seine Identität geändert hat:", "The original MOTD backup is unavailable; no changes were made": "Das ursprüngliche MOTD-Backup ist nicht verfügbar;Es wurden keine Änderungen vorgenommen", "The original MOTD configuration has been restored": "Die ursprüngliche MOTD-Konfiguration wurde wiederhergestellt", "The original MOTD state is unavailable; no changes were made": "Der ursprüngliche MOTD-Status ist nicht verfügbar. Es wurden keine Änderungen vorgenommen", @@ -4408,18 +5982,76 @@ "The original rpcbind state could not be restored completely": "Der ursprüngliche Rpcbind-Status konnte nicht vollständig wiederhergestellt werden", "The original rpcbind state is unavailable; no service state was changed": "Der ursprüngliche Rpcbind-Status ist nicht verfügbar. Es wurde kein Dienststatus geändert", "The package is currently in a broken state and is blocking apt updates on this system.": "Das Paket befindet sich derzeit in einem fehlerhaften Zustand und blockiert Apt-Updates auf diesem System.", + "The parent of an NVIDIA destination is not a directory": "Das Parent eines NVIDIA-Ziels ist kein Verzeichnis", + "The parent of the target is not a directory:": "Das übergeordnete Ziel ist kein Verzeichnis:", + "The password could not be retrieved automatically": "Das Passwort konnte nicht automatisch abgerufen werden", "The passwords do not match. Please try again.": "Die Passwörter stimmen nicht überein. Bitte versuchen Sie es erneut.", + "The path escapes the rootfs:": "Der Pfad entkommt den Roots:", + "The path must be absolute and normalized": "Der Pfad muss absolut und normalisiert sein", + "The path overlaps an existing mount": "Der Pfad überlappt eine bestehende Halterung", + "The persistent NVIDIA hook does not match the installer:": "Der persistente NVIDIA-Hook passt nicht zum Installer:", + "The persistent WebUI credentials were not found": "Die persistenten WebUI credentials wurden nicht gefunden", + "The physical NVIDIA selection changed": "Die physische NVIDIA-Auswahl hat sich geändert", + "The post-start configuration cannot be applied with the LXC stopped": "Die Post-Start-Konfiguration kann nicht angewendet werden, wenn der LXC gestoppt wird", + "The postgres user was not found in the image": "Der postgres-Benutzer wurde nicht im Bild gefunden", + "The prepared directory escapes the rootfs:": "Das vorbereitete Verzeichnis entgeht den Rootfs:", "The preselected VMID does not exist on this host:": "Die vorausgewählte VMID ist auf diesem Host nicht vorhanden:", + "The previous native backup will be restored. Shared host directories are not reverted. Displaced disks are kept.": "Das vorherige native Backup wird wiederhergestellt. Gemeinsame Host-Verzeichnisse werden nicht revertiert. Displaced Disks werden beibehalten.", + "The previous stack contract is not safe; review it before reusing it": "Der vorherige Stapelvertrag ist nicht sicher; überprüfen Sie ihn, bevor Sie ihn wiederverwenden", + "The previous stack contract is not valid; it is not archived automatically": "Der vorherige Stapelvertrag ist nicht gültig; er wird nicht automatisch archiviert", + "The previous stack contract still has containers or VMs:": "Der vorherige Stapelvertrag hat noch Container oder VMs:", + "The private address is already assigned to another container:": "Die Privatadresse ist bereits einem anderen Container zugeordnet:", + "The private bridge does not have the expected address:": "Die private Bridge hat nicht die erwartete Adresse:", + "The private journal has an unsafe owner or permissions": "Das private Journal hat einen unsicheren Besitzer oder Berechtigungen", + "The private network allocator was not found": "Der private Netzwerkzuweiser wurde nicht gefunden", + "The private network is still used by another container and is kept:": "Das private Netzwerk wird weiterhin von einem anderen Container genutzt und wird beibehalten:", + "The private network must be assigned automatically": "Das private Netzwerk muss automatisch zugewiesen werden", + "The privileged deployment does not include the required explicit consent": "Der privilegierte Einsatz beinhaltet nicht die ausdrückliche Zustimmung von required", + "The prlimit soft value exceeds the hard value": "Der prlimit Soft-Wert übersteigt den Hard-Wert", + "The proposal changes the identity of the instance": "Der Vorschlag ändert die Identität der Instanz", "The proposed ARC maximum is below Proxmox VE's pool-size guideline:": "Das vorgeschlagene ARC-Maximum liegt unter der Poolgrößenrichtlinie von Proxmox VE:", + "The published views must be inside the common root": "Die veröffentlichten Ansichten müssen sich innerhalb der gemeinsamen Wurzel befinden", + "The read-only view does not apply the expected protection": "Die Read-Only-Ansicht verwendet nicht den erwarteten Schutz", + "The read-only view was not published": "Die Read-Only-Ansicht wurde nicht veröffentlicht", + "The read/write view was not published": "Die Lese-/Schreibansicht wurde nicht veröffentlicht", + "The recipe requires configuration at startup; its coordinated replay is not available": "Das Rezept requires Konfiguration beim Start; seine koordinierte Wiederholung ist nicht verfügbar", + "The record belongs to another container": "Der Datensatz gehört zu einem anderen Container", + "The record does not belong to this operation": "Der Datensatz gehört nicht zu dieser operation", + "The record no longer belongs to this operation": "Der Datensatz gehört nicht mehr zu dieser operation", + "The record of a member was replaced; the assembly is not resumed": "Die Aufzeichnung eines Mitglieds wurde ersetzt; die Versammlung wird nicht wieder aufgenommen", + "The record or diagnosis could not be completed; no update was run.": "Die Aufzeichnung oder Diagnose konnte nicht abgeschlossen werden; kein Update wurde ausgeführt.", + "The recovery did not complete. Review the log and choose \"Recover\" again for this container in the OCI management menu.": "Die Rückforderung war nicht abgeschlossen. Überprüfen Sie das Protokoll und wählen Sie erneut \"Wiederherstellen\" für diesen Container im OCI-Verwaltungsmenü.", + "The remote does not exist; create and authorize it first in the WebUI:": "Die Fernbedienung existiert nicht; erstellen und autorisieren Sie sie zuerst in der WebUI:", + "The remote installer must run as root on Proxmox VE": "Der Remote-Installer muss als root auf Proxmox VE ausgeführt werden", + "The remote must already be created and authorized in the Rclone web UI. This operation restarts the CT and publishes two FUSE views on the host.": "Die Fernbedienung muss bereits im Rclone Web UI erstellt und autorisiert werden. Diese operation startet den CT neu und veröffentlicht zwei FUSE-Ansichten auf dem Host.", + "The remote path must be relative and cannot contain line breaks": "Der Fernpfad muss relativ sein und darf keine Linienumbrüche enthalten.", + "The removal could not be prepared:": "Die Entfernung konnte nicht vorbereitet werden:", + "The repair must preserve the image dependencies:": "Die Reparatur muss die Bildabhängigkeiten bewahren:", + "The requested VMID block is already in use": "Der angeforderte VMID-Block wird bereits verwendet", + "The requested machine learning GPU profile is not working; it is not replaced by CPU": "Das angeforderte Machine Learning-GPU-Profil funktioniert nicht; es wird nicht durch CPU ersetzt", + "The restored service did not pass its health check": "Der wiederhergestellte Service bestand seinen Gesundheitscheck nicht", + "The restored service stopped; the recovery is not confirmed": "Der wiederhergestellte Dienst wurde gestoppt; die Wiederherstellung wird nicht bestätigt", + "The reviewed Tandoor stack does not require a privileged LXC.": "Der überprüfte Tandoor-Stack requi ist kein privilegierter LXC.", + "The rootfs capture only belongs to the running installation": "Der Rootfs Capture gehört nur zur laufenden Installation", + "The rootfs is not managed by Proxmox": "Die Rootfs werden nicht von Proxmox verwaltet", + "The rootfs is not mounted": "Die Rootfs sind nicht montiert", "The same GPU cannot be used by two VMs at the same time.": "Die gleiche GPU kann nicht von zwei VMs gleichzeitig verwendet werden.", + "The same connection can be given as container variables instead of the file: UN_SONARR_0_URL and UN_SONARR_0_API_KEY, or the UN_RADARR_0_ equivalents.": "Die gleiche Verbindung kann als Containervariablen anstelle der Datei angegeben werden: UN SONARR 0 URL und UN SONARR 0 API KEY oder die UN RADARR 0 equivalents.", "The saved MOTD state is invalid; no changes were made": "Der gespeicherte MOTD-Status ist ungültig;Es wurden keine Änderungen vorgenommen", + "The saved OCI record is incomplete or has an unexpected format.": "Der gespeicherte OCI-Datensatz ist unvollständig oder hat ein unerwartetes Format.", + "The saved projection does not match the native evidence": "Die gespeicherte Projektion stimmt nicht mit dem nativen Beweis überein", + "The saved record was replaced for": "Der gespeicherte Datensatz wurde ersetzt für", "The saved utility package list is invalid; no packages were removed": "Die gespeicherte Liste der Dienstprogrammpakete ist ungültig. Es wurden keine Pakete entfernt", "The script clones the osx-proxmox.com repository and once the setup is complete, the server will automatically reboot.": "Das Skript klont das osx-proxmox.com-Repository und sobald die Einrichtung abgeschlossen ist, wird der Server automatisch neu gestartet.", "The script will continue to restore VM passthrough mode on the host and reuse existing hostpci entries.": "Das Skript stellt weiterhin den VM-Passthrough-Modus auf dem Host wieder her und verwendet vorhandene Hostpci-Einträge wieder.", "The script will preconfigure the selected GPU now and finalize hardware binding after reboot.": "Das Skript konfiguriert jetzt die ausgewählte GPU vor und schließt die Hardwarebindung nach dem Neustart ab.", "The selected AMD GPU does not report FLR reset support": "Die ausgewählte AMD-GPU meldet keine FLR-Reset-Unterstützung", "The selected AMD GPU is currently in power state D3cold": "Die ausgewählte AMD-GPU befindet sich derzeit im Energiezustand D3cold", + "The selected CT does not match its OCI record. Its configuration will not be modified or deleted.": "Das ausgewählte CT stimmt nicht mit seinem OCI-Record überein. Die Konfiguration wird nicht geändert oder gelöscht.", + "The selected GPU changed": "Die ausgewählte GPU hat sich geändert", "The selected GPU configuration already exists in this container.": "Die ausgewählte GPU-Konfiguration ist bereits in diesem Container vorhanden.", + "The selected GPU device does not exist:": "Das ausgewählte GPU-Gerät existiert nicht:", + "The selected GPU directory does not exist:": "Das ausgewählte GPU-Verzeichnis existiert nicht:", "The selected GPU has no dedicated .1 audio sibling function.": "Die ausgewählte GPU verfügt über keine dedizierte .1-Audio-Geschwisterfunktion.", "The selected GPU is already assigned to another VM that is currently running:": "Die ausgewählte GPU ist bereits einer anderen VM zugewiesen, die derzeit ausgeführt wird:", "The selected GPU is already assigned to this VM, but the host is not currently using vfio-pci for this device.": "Die ausgewählte GPU ist dieser VM bereits zugewiesen, aber der Host verwendet derzeit nicht vfio-pci für dieses Gerät.", @@ -4435,11 +6067,15 @@ "The selected Intel GPU does not expose a PCI reset interface": "Die ausgewählte Intel-GPU stellt keine PCI-Reset-Schnittstelle zur Verfügung", "The selected Intel GPU has non-FLR reset support and unknown subtype": "Die ausgewählte Intel-GPU verfügt über Nicht-FLR-Reset-Unterstützung und einen unbekannten Subtyp", "The selected Intel GPU is currently in power state D3cold": "Die ausgewählte Intel-GPU befindet sich derzeit im Energiezustand D3cold", + "The selected Intel render device does not exist:": "Das ausgewählte Intel-Rendergerät existiert nicht:", "The selected VM": "Die ausgewählte VM", "The selected VM is running.": "Die ausgewählte VM läuft.", "The selected base folder does not exist and could not be created:": "Der ausgewählte Basisordner existiert nicht und konnte nicht erstellt werden:", + "The selected configuration needs to start the LXC during the installation": "Die ausgewählte Konfiguration muss den LXC während der Installation starten", "The selected container is unprivileged. A privileged container is required for direct device passthrough.": "Der ausgewählte Container ist nicht privilegiert. Für den direkten Geräte-Passthrough ist ein privilegierter Container erforderlich.", "The selected device": "Das ausgewählte Gerät", + "The selected device is not a block device": "Das ausgewählte Gerät ist kein Blockgerät", + "The selected device is not a character device": "Das ausgewählte Gerät ist kein Zeichengerät", "The selected directory does not exist:": "Das ausgewählte Verzeichnis existiert nicht:", "The selected disk has an active swap partition. Aborting.": "Die ausgewählte Festplatte verfügt über eine aktive Swap-Partition. Abbruch.", "The selected disk is currently used by a RUNNING VM or CT. Stop it before formatting.": "Die ausgewählte Festplatte wird derzeit von einer LAUFENDEN VM oder CT verwendet. Stoppen Sie es vor dem Formatieren.", @@ -4447,25 +6083,76 @@ "The selected disk now contains a system-critical mount. Aborting.": "Der ausgewählte Datenträger enthält nun einen systemkritischen Mount. Abbruch.", "The selected path does not exist on this host:": "Der ausgewählte Pfad existiert auf diesem Host nicht:", "The selected path is not a valid directory:": "Der ausgewählte Pfad ist kein gültiges Verzeichnis:", + "The selected render device does not exist:": "Die ausgewählte Rendervorrichtung existiert nicht:", "The server connected you as guest instead of the specified user.": "Der Server hat Sie als Gast und nicht als angegebenen Benutzer verbunden.", "The server may not have accessible shares.": "Der Server verfügt möglicherweise nicht über zugängliche Freigaben.", "The server may require authentication for actual share access.": "Der Server erfordert möglicherweise eine Authentifizierung für den tatsächlichen Freigabezugriff.", "The server refused password authentication for": "Der Server hat die Passwortauthentifizierung abgelehnt", "The server rejected": "Der Server hat abgelehnt", + "The service builds its own image; only a published image can be installed": "Der Dienst erstellt ein eigenes Image; nur ein veröffentlichtes Image kann installiert werden", + "The service declares no image:": "Der Dienst erklärt kein Bild:", + "The setting has no final value:": "Die Einstellung hat keinen Endwert:", "The share already exists in smb.conf:": "Die Freigabe existiert bereits in smb.conf:", + "The shared destination is not a directory": "Das gemeinsame Ziel ist kein Verzeichnis", + "The shared directory points to a protected host path": "Das Shared Directory zeigt auf einen geschützten Hostpfad", + "The shared path exists but is not a directory:": "Der gemeinsame Pfad existiert, ist aber kein Verzeichnis:", + "The size of existing disks is not rounded": "Die Größe der vorhandenen Disks ist nicht gerundet", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk.": "Die Quelle Compose fordert privilegierte: true, aber dies beweist nicht, dass das Bild eine privilegierte LXC benötigt. ProxMenux verwendet standardmäßig einen unprivilegierten LXC und bietet den breiten Modus nur als Option an. Fahren Sie nur fort, wenn Sie dem Image vertrauen und dieses Risiko akzeptieren.", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. The Docker rootlesskit profile does not exist in LXC and will be replaced by AppArmor unconfined, which is less restrictive. Continue only if you trust the image and accept this risk.": "Die Quelle Compose fordert privilegierte: true, aber dies beweist nicht, dass das Bild eine privilegierte LXC benötigt. ProxMenux verwendet standardmäßig einen unprivilegierten LXC und bietet den breiten Modus nur als Option an. Das Compose bietet eine optionale AppArmor- oder seccomp-Entspannung; es bleibt deaktiviert, es sei denn, der Benutzer wählt es aus. Das Docker-Rootlesskit-Profil existiert nicht in LXC und wird durch AppArmor unconfined ersetzt, was weniger restriktiv ist. Fahren Sie nur fort, wenn Sie dem Image vertrauen und dieses Risiko akzeptieren.", "The source VM also has these audio devices, likely added together with the GPU. Remove them too?": "Die Quell-VM verfügt ebenfalls über diese Audiogeräte, wahrscheinlich zusammen mit der GPU hinzugefügt. Auch entfernen?", "The specified directory does not exist:": "Das angegebene Verzeichnis existiert nicht:", + "The stability period must be shorter than the healthcheck timeout": "Die Stabilitätsperiode muss kürzer sein als der Healthcheck-Timeout", + "The stack contains devices or directives without a translation": "Der Stack enthält Geräte oder Direktiven ohne Übersetzung", + "The stack does not have the expected native hook": "Der Stapel hat nicht den erwarteten nativen Haken", + "The stack journal is outside the registry": "Das Stack Journal befindet sich außerhalb der Registry", + "The stack member has no declared adaptation profile": "Stapelelement weist kein deklariertes Anpassungsprofil auf", + "The stack name only accepts lowercase letters, numbers and hyphens": "Der Stackname akzeptiert nur Kleinbuchstaben, Zahlen und Bindestriche", + "The stack needs member adaptations or a verification of missing volumes": "Der Stack benötigt Mitgliederanpassungen oder eine Überprüfung fehlender Volumen", + "The stack operation had already finished": "Der Stack operation war bereits fertig", + "The stack operation has not finished yet": "Der Stack operation ist noch nicht fertig", + "The stack operation stopped halfway. Select the stack again in the OCI management menu to recover it.": "Der Stack operation stoppte auf halbem Weg. Wählen Sie den Stack erneut im OCI-Verwaltungsmenü aus, um ihn wiederherzustellen.", + "The stack registry is incomplete; review the private contracts.": "Die Stack-Registrierung ist unvollständig; Überprüfen Sie die privaten Verträge.", + "The stack startup hook was not found": "Der Stapelstarthaken wurde nicht gefunden", + "The stack update was saved.": "Das Stack-Update wurde gespeichert.", + "The startup differs from the declared Nextcloud adapter": "Das Startup unterscheidet sich vom deklarierten Nextcloud Adapter", + "The startup differs from the declared adapter": "Das Startup unterscheidet sich vom deklarierten Adapter", + "The staticfiles volume needs at least 1 GB": "Das statische Dateivolumen benötigt mindestens 1 GB", "The storage has been removed and the disk unmounted.": "Der Speicher wurde entfernt und die Festplatte nicht bereitgestellt.", + "The sysctl content was modified outside the saved record": "Der sysctl-Inhalt wurde außerhalb des gespeicherten Datensatzes geändert", + "The sysctl include is a link:": "Das sysctl include ist ein Link:", + "The sysctl include is not a safe host file": "Das sysctl include ist keine sichere Host-Datei", + "The sysctl include is not restored over a symbolic link": "Das sysctl include wird nicht über einen symbolischen Link wiederhergestellt", + "The sysctl include is unknown or differs from the saved record": "Das sysctl include ist unbekannt oder unterscheidet sich vom gespeicherten Datensatz", + "The temporary password could not be retrieved.": "Das temporäre Passwort konnte nicht abgerufen werden.", "The test will continue even if you close this terminal.": "Der Test wird auch dann fortgesetzt, wenn Sie dieses Terminal schließen.", + "The tmpfs mounts of the container differ from the saved record": "Die tmpfs Halterungen des Containers unterscheiden sich vom gespeicherten Datensatz", + "The tmpfs path or size is outside the supported profile": "Der Pfad oder die Größe von tmpfs befindet sich außerhalb des unterstützten Profils", + "The translated recipe changed during the preparation": "Das übersetzte Rezept änderte sich während der Vorbereitung", + "The value contains an unsupported character": "Der Wert enthält ein nicht unterstütztes Zeichen", + "The values do not match. Enter them again.": "Die Werte stimmen nicht überein. Betreten Sie sie wieder.", + "The variable contains control characters:": "Die Variable enthält Steuerzeichen:", + "The variable contains line breaks:": "Die Variable enthält Zeilenumbrüche:", "The vfio.conf entries have been removed and initramfs rebuilt.": "Die vfio.conf-Einträge wurden entfernt und initramfs neu erstellt.", + "The web UI password must have at least 24 characters": "Das Web-UI-Passwort muss mindestens 24 Zeichen haben", + "The web UI user contains characters that are not allowed": "Der Web-UI-Benutzer enthält Zeichen, die nicht erlaubt sind", + "The web interface is served over plain HTTP on port 51821 (INSECURE=true). Keep it inside the local network or publish it through a reverse proxy with TLS.": "Das Webinterface wird über einfaches HTTP auf Port 51821 bedient (INSECURE=true). Behalten Sie es im lokalen Netzwerk oder veröffentlichen Sie es über einen Reverse-Proxy mit TLS.", + "The web interface uses a self-signed certificate, so the browser shows a warning the first time.": "Die Weboberfläche verwendet ein selbstsigniertes Zertifikat, sodass der Browser beim ersten Mal eine Warnung anzeigt.", + "The wizard writes a .conf file in /config. Restart the container afterwards so the bot starts with that configuration.": "Der Wizard schreibt eine .conf Datei in /config. Starten Sie den Container danach neu, sodass der Bot mit dieser Konfiguration beginnt.", + "The world's fastest framework for building websites": "Das weltweit schnellste Framework zum Erstellen von Websites", + "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server.": "Thelounge (ein fork von shoutIRC) ist ein Web-IRC-Client, den Sie auf Ihrem eigenen Server hosten.", "Then bind-mount to container": "Dann bind-mounten Sie es an den Container", "Then change the VM display to none (vga: none) when the guest is stable.": "Ändern Sie dann die VM-Anzeige auf „Keine“ (vga: none), wenn der Gast stabil ist.", "Then change the VM display to none (vga: none) when the system is stable.": "Ändern Sie dann die VM-Anzeige auf „Keine“ (vga: none), wenn das System stabil ist.", "Then run this option again:": "Führen Sie dann diese Option erneut aus:", "Then update /etc/fstab on the host with the same options.": "Aktualisieren Sie dann /etc/fstab auf dem Host mit denselben Optionen.", + "There are extra disks or bind mounts outside the journal; the rootfs is not replaced": "Es gibt zusätzliche Festplatten oder Bindehalterungen außerhalb des Journals; die Rootfs werden nicht ersetzt", + "There is no temporary container of this operation to keep the current disks": "Es gibt keinen temporären Container dieser operation, um die aktuellen Festplatten zu behalten", + "There is no verified backup; a modified container is not touched": "Es gibt kein verifiziertes Backup; ein modifizierter Container wird nicht berührt", + "These VMIDs are not free:": "Diese VMIDs sind nicht kostenlos:", "These are the changes that will be made": "Dies sind die Änderungen, die vorgenommen werden", "These interface configurations will be removed": "Diese Schnittstellenkonfigurationen werden entfernt", "These paths will not be restored live and will be extracted for manual recovery.": "Diese Pfade werden nicht live wiederhergestellt und zur manuellen Wiederherstellung extrahiert.", + "These values are asked during the installation:": "Diese Werte werden während der Installation abgefragt:", "This CIFS share is mounted with restrictive permissions.": "Diese CIFS-Freigabe wird mit restriktiven Berechtigungen gemountet.", "This GPU is considered incompatible with GPU passthrough to a VM in ProxMenux.": "Diese GPU gilt als inkompatibel mit GPU-Passthrough zu einer VM in ProxMenux.", "This NFS share is fully restricted — even the host root cannot write to it.": "Diese NFS-Freigabe ist vollständig eingeschränkt – selbst der Host-Root kann nicht darauf schreiben.", @@ -4477,6 +6164,8 @@ "This backup is encrypted.": "Dieses Backup ist verschlüsselt.", "This backup was taken on kernel": "Dieses Backup wurde im Kernel erstellt", "This cleanup will:": "Diese Bereinigung wird:", + "This container belongs to a stack; publish the whole stack": "Dieser Container gehört zu einem Stapel; veröffentlichen Sie den gesamten Stapel", + "This container belongs to a stack; recover the whole stack": "Dieser Behälter gehört zu einem Stapel; holen Sie den gesamten Stapel zurück", "This container does not have apt-get. NFS client installation only supports Debian/Ubuntu containers.": "Dieser Container verfügt nicht über apt-get. Die NFS-Client-Installation unterstützt nur Debian/Ubuntu-Container.", "This container does not have apt-get. Samba client installation only supports Debian/Ubuntu containers.": "Dieser Container verfügt nicht über apt-get. Die Samba-Client-Installation unterstützt nur Debian/Ubuntu-Container.", "This container has no GPU configured. Coral TPU works best alongside hardware video decoding (Quick Sync, VA-API, NVENC) for apps like Frigate.": "Für diesen Container ist keine GPU konfiguriert. Coral TPU funktioniert am besten zusammen mit der Hardware-Videodekodierung (Quick Sync, VA-API, NVENC) für Apps wie Frigate.", @@ -4486,15 +6175,21 @@ "This erases existing metadata.": "Dadurch werden vorhandene Metadaten gelöscht.", "This explicitly marks the container as privileged": "Dadurch wird der Container explizit als privilegiert gekennzeichnet", "This guarantees that device nodes are available before applying LXC GPU config.": "Dies garantiert, dass Geräteknoten verfügbar sind, bevor die LXC-GPU-Konfiguration angewendet wird.", + "This image cannot be installed as it is described:": "Dieses Bild kann nicht wie beschrieben installiert werden:", + "This image requires the host module": "Dieses Bild requires das Host-Modul", "This installation will:": "Diese Installation wird:", "This installer will:": "Dieses Installationsprogramm wird:", "This interface is configured but doesn't exist physically": "Diese Schnittstelle ist konfiguriert, aber physisch nicht vorhanden", + "This interface runs on the Proxmox node as root. Open proxmenux-oci.sh on the Proxmox host.": "Diese Schnittstelle läuft auf dem Proxmox-Knoten als root. Öffnen Sie proxmenux-oci.sh auf dem Proxmox-Host.", "This is IRREVERSIBLE.": "Das ist irreversibel.", "This is a destructive action": "Dies ist eine destruktive Aktion", "This is a simple configuration change": "Dies ist eine einfache Konfigurationsänderung", "This is an external community script maintained by": "Dies ist ein externes Community-Skript, das von verwaltet wird", "This is an external script that creates a macOS VM in Proxmox VE in just a few steps, whether you are using AMD or Intel hardware.": "Hierbei handelt es sich um ein externes Skript, das in wenigen Schritten eine macOS VM in Proxmox VE erstellt, egal ob Sie AMD- oder Intel-Hardware verwenden.", + "This is not a coordinated stack": "Dies ist kein koordinierter Stack", + "This is not a valid image reference:": "Dies ist keine gültige Bildreferenz:", "This is unexpected since credentials were validated.": "Dies ist unerwartet, da die Anmeldeinformationen validiert wurden.", + "This is what ProxMenux understood from the": "Dies hat ProxMenux aus dem", "This marks the container as unprivileged": "Dadurch wird der Container als nicht privilegiert markiert", "This may be normal for a fresh installation": "Dies kann bei einer Neuinstallation normal sein", "This may take a few minutes. Press OK to proceed.": "Dies kann einige Minuten dauern. Drücken Sie OK, um fortzufahren.", @@ -4503,12 +6198,14 @@ "This means Proxmox handles mount lifecycle natively (no manual /etc/fstab needed for NFS/CIFS host storages).": "Das bedeutet, dass Proxmox den Mount-Lebenszyklus nativ verwaltet (für NFS/CIFS-Hostspeicher ist kein manuelles /etc/fstab erforderlich).", "This means the credentials are incorrect.": "Dies bedeutet, dass die Anmeldeinformationen falsch sind.", "This might indicate network connectivity issues.": "Dies könnte auf Probleme mit der Netzwerkverbindung hinweisen.", + "This monitor uses a privileged LXC, shares processes and network with Proxmox and disables AppArmor in the CT. It uses the IP address and firewall of the host. A compromised image could affect the host; do not expose its web UI to the Internet.": "Dieser Monitor verwendet einen privilegierten LXC, teilt Prozesse und Netzwerke mit Proxmox und deaktiviert AppArmor im CT. Es verwendet die IP-Adresse und Firewall des Hosts. Ein kompromittiertes Bild könnte den Host beeinflussen; setzen Sie seine Web-Benutzeroberfläche nicht dem Internet aus.", "This operation may take several minutes and requires internet connectivity.": "Dieser Vorgang kann mehrere Minuten dauern und erfordert eine Internetverbindung.", "This package was installed by older versions of the ProxMenux Coral installer that placed the M.2 kernel driver on every system, including USB-only setups. It is not needed for Coral USB devices, which use libedgetpu1-std / libedgetpu1-max only.": "Dieses Paket wurde von älteren Versionen des ProxMenux Coral-Installationsprogramms installiert, das den M.2-Kernel-Treiber auf jedem System platzierte, einschließlich reiner USB-Setups. Es ist nicht für Coral USB-Geräte erforderlich, die nur libedgetpu1-std / libedgetpu1-max verwenden.", "This passphrase is the ONLY way to access encrypted Borg backups.": "Diese Passphrase ist die EINZIGE Möglichkeit, auf verschlüsselte Borg-Backups zuzugreifen.", "This path is already used as a mount point in this container.": "Dieser Pfad wird in diesem Container bereits als Mountpunkt verwendet.", "This path is not a registered mount point. Use it anyway?": "Dieser Pfad ist kein registrierter Mountpunkt. Trotzdem nutzen?", "This process changes file ownership inside the container": "Dieser Prozess ändert den Dateieigentum innerhalb des Containers", + "This profile only supports directory bind mounts": "Dieses Profil unterstützt nur Verzeichnisbindungshalterungen", "This release channel is already active.": "Dieser Release-Kanal ist bereits aktiv.", "This removes the 'unprivileged: 1' line from the config": "Dadurch wird die Zeile „unprivileged: 1“ aus der Konfiguration entfernt", "This removes the storage from Proxmox. The iSCSI target is not affected.": "Dadurch wird der Speicher von Proxmox entfernt. Das iSCSI-Ziel ist nicht betroffen.", @@ -4522,10 +6219,15 @@ "This session is running in the Monitor terminal. Running it from here would cut the connection mid-install and leave the switch in a broken state.": "Diese Sitzung wird im Monitor-Terminal ausgeführt. Wenn Sie es von hier aus ausführen, wird die Verbindung während der Installation unterbrochen und der Switch bleibt in einem defekten Zustand.", "This session is running in the Monitor terminal. Updating from here would restart the Monitor service and cut the connection mid-install, leaving the update in a broken state.": "Diese Sitzung wird im Monitor-Terminal ausgeführt. Eine Aktualisierung von hier aus würde den Monitor-Dienst neu starten und die Verbindung während der Installation unterbrechen, sodass das Update in einem fehlerhaften Zustand verbleibt.", "This shows the storage type and disk identifier": "Hier werden der Speichertyp und die Festplattenkennung angezeigt", + "This stack requires replaying specific rootfs adaptations. Coordinated updates are not yet enabled for it.": "Dieser Stapel requires Wiedergabe spezifischer Rootfs Anpassungen. Koordinierte Updates sind dafür noch nicht aktiviert.", "This state has a high probability of VM startup/reset failures.": "In diesem Zustand besteht eine hohe Wahrscheinlichkeit für VM-Start-/Reset-Fehler.", "This state indicates a high risk of passthrough failure due to": "Dieser Zustand weist auf ein hohes Risiko eines Passthrough-Fehlers hin", + "This template requests the host PID namespace, which has no validated safe LXC translation yet": "Diese Vorlage fordert den Host-PID-Namespace an, der noch keine validierte sichere LXC-Übersetzung hat.", "This tool is designed for systems with AMD GPUs.": "Dieses Tool ist für Systeme mit AMD-GPUs konzipiert.", "This tool is designed for systems with Intel GPUs.": "Dieses Tool ist für Systeme mit Intel-GPUs konzipiert.", + "This translator only supports the Nextcloud stack": "Dieser Übersetzer unterstützt nur die Nextcloud stack", + "This value is required.": "Dieser Wert ist required.", + "This variant requires the device": "Diese Variante requires das Gerät", "This version does not build against the running kernel.": "Diese Version baut nicht auf dem laufenden Kernel auf.", "This will RESET the ProxMenux Monitor login credentials on this host:": "Dadurch werden die Anmeldeinformationen von ProxMenux Monitor auf diesem Host ZURÜCKGESETZT:", "This will add the mount to /etc/fstab so it persists after reboot.": "Dadurch wird der Mount zu /etc/fstab hinzugefügt, sodass er nach dem Neustart bestehen bleibt.", @@ -4547,13 +6249,17 @@ "This will restart the network service and may cause a brief disconnection. Continue?": "Dadurch wird der Netzwerkdienst neu gestartet und es kann zu einer kurzen Unterbrechung der Verbindung kommen. Weitermachen?", "This will take time. Answer prompts carefully - see notes below.": "Das wird einige Zeit dauern. Beantworten Sie die Fragen sorgfältig – siehe Hinweise unten.", "This will upgrade this node to Proxmox VE 9 on Debian Trixie.": "Dadurch wird dieser Knoten auf Proxmox VE 9 unter Debian Trixie aktualisiert.", + "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client.": "Thunderbird ist ein kostenloser und Open-Source-Manager für persönliche Informationen, der hauptsächlich als E-Mail-Client mit Kalender und Kontaktbuch sowie als RSS-Feed-Reader, Chat-Client und Nachrichten-Client verwendet wird.", "Tick the paths to include in this backup. Press \"Add custom path\" to add a folder or file of your own to the list.": "Markieren Sie die Pfade, die in diese Sicherung einbezogen werden sollen. Klicken Sie auf „Benutzerdefinierten Pfad hinzufügen“, um der Liste einen eigenen Ordner oder eine eigene Datei hinzuzufügen.", "Tick the paths to remove (they will not be deleted from disk — only from this list):": "Markieren Sie die zu entfernenden Pfade (sie werden nicht von der Festplatte gelöscht, sondern nur aus dieser Liste):", + "Time is up; Home Assistant OS could not be confirmed as running": "Die Zeit ist abgelaufen; Home Assistant OS konnte nicht als ausgeführt bestätigt werden", "Time settings configured - Timezone:": "Konfigurierte Zeiteinstellungen – Zeitzone:", "Time synchronization reset to UTC": "Zeitsynchronisation auf UTC zurückgesetzt", + "Timezone": "Zeitzone", "Tip: Also mount the VirtIO ISO for drivers and guest agent installer": "Tipp: Mounten Sie auch die VirtIO-ISO für Treiber und Gast-Agent-Installationsprogramm", "Tip: You can install the QEMU Guest Agent inside the VM with:": "Tipp: Sie können den QEMU Guest Agent in der VM installieren mit:", "Tip: zfs set acltype=posixacl xattr=sa / enables full ACL support.": "Tipp: zfs set acltype=posixacl xattr=sa / aktiviert die vollständige ACL-Unterstützung.", + "Tmpfs size in MiB for": "Tmpfs Größe in MiB für", "To allow LXC write access, change the NFS export on the server to include:": "Um LXC-Schreibzugriff zu ermöglichen, ändern Sie den NFS-Export auf dem Server so, dass er Folgendes enthält:", "To apply it to the current shell now, run:": "Um sie jetzt auf die aktuelle Shell anzuwenden, führen Sie Folgendes aus:", "To assign VFs to VMs or LXCs, edit the configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Um VFs VMs oder LXCs zuzuweisen, bearbeiten Sie die Konfiguration manuell über die Proxmox-Weboberfläche. Die physische Funktion bleibt an den nativen Treiber gebunden.", @@ -4568,6 +6274,7 @@ "To pass SR-IOV Virtual Functions to a container, edit the LXC configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Um virtuelle SR-IOV-Funktionen an einen Container zu übergeben, bearbeiten Sie die LXC-Konfiguration manuell über die Proxmox-Weboberfläche. Die physische Funktion bleibt an den nativen Treiber gebunden.", "To remove partial VM:": "So entfernen Sie eine teilweise VM:", "To restore": "Zum Wiederherstellen", + "To restore it on another host, keep this file (not included in the vzdump backup):": "Um es auf einem anderen Host wiederherzustellen, behalten Sie diese Datei (nicht im vzdump-Backup enthalten):", "To revert changes:": "So machen Sie Änderungen rückgängig:", "To start the VM:": "So starten Sie die VM:", "To stop:": "Zum Stoppen:", @@ -4579,12 +6286,17 @@ "To use this share from an LXC, bind-mount it via:": "Um diese Freigabe von einem LXC aus zu verwenden, mounten Sie sie per Bind-Mount:", "Tool exit code:": "Tool-Exit-Code:", "Tool output:": "Werkzeugausgabe:", + "Tools": "Werkzeuge", "Top memory processes in CT": "Top-Gedächtnisprozesse in der CT", + "Top-level configs, secrets and other global options are not yet supported": "Top-Level-Konfigurationen, Geheimnisse und andere globale Optionen werden noch nicht unterstützt", + "Top-level volume options are not yet supported": "Top-Level-Volumenoptionen werden noch nicht unterstützt", "Total": "Gesamt", "Total members:": "Gesamtzahl der Mitglieder:", "Total routes": "Gesamtrouten", "Total size:": "Gesamtgröße:", + "Transaction log:": "Transaktionsprotokoll:", "Translation files:": "Übersetzungsdateien:", + "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, µTP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more.": "Transmission wurde für eine einfache und leistungsstarke Nutzung entwickelt. Transmission verfügt über die Funktionen, die Sie von einem BitTorrent-Client erwarten: Verschlüsselung, eine Web-Schnittstelle, Peer-Exchange, Magnet-Links, DHT, μTP, UPnP und NAT-PMP Port-Weiterleitung, Webseed-Unterstützung, Watch-Verzeichnisse, Tracker-Bearbeitung, globale und per-Torrent-Geschwindigkeitsbeschränkungen und mehr.", "Tried pvesm path and manual detection methods": "Versuchte den Pvesm-Pfad und manuelle Erkennungsmethoden", "Trust this certificate and save it for scheduled backups?": "Diesem Zertifikat vertrauen und es für geplante Sicherungen speichern?", "Try Again": "Versuchen Sie es erneut", @@ -4592,6 +6304,8 @@ "Try accessing": "Versuchen Sie, darauf zuzugreifen", "Try another archive": "Versuchen Sie es mit einem anderen Archiv", "Try automatic repair of detected issues": "Versuchen Sie, erkannte Probleme automatisch zu reparieren", + "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources.": "Tvheadend arbeitet als Proxy-Server: ist ein TV-Streaming-Server und Recorder für Linux, FreeBSD und Android, der DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP und HDHomeRun als Eingangsquellen unterstützt.", + "Twingate Connector for self-hosted server": "Twingate Connector für selbst gehosteten Server", "Two-factor authentication and backup codes will be removed.": "Zwei-Faktor-Authentifizierung und Backup-Codes werden entfernt.", "Type": "Typ", "Type the device path EXACTLY to confirm formatting:": "Geben Sie den Gerätepfad GENAU ein, um die Formatierung zu bestätigen:", @@ -4600,16 +6314,22 @@ "Type: attached to PVE storage": "Typ: An PVE-Speicher angeschlossen", "Typed value does not match selected disk. Operation cancelled.": "Der eingegebene Wert stimmt nicht mit der ausgewählten Festplatte überein. Vorgang abgebrochen.", "UID in CT": "UID im CT", + "UID of the plex user (also owner of the GPU device)": "UID des plex-Benutzers (auch Besitzer des GPU-Geräts)", + "UID that Emby runs as": "UID, dass Emby läuft als", "UPGRADE PROMPTS - RECOMMENDED ANSWERS:": "UPGRADE-AUFFORDERUNGEN – EMPFOHLENE ANTWORTEN:", + "UPS monitoring and power outage notification system": "UPS-Überwachungs- und Stromausfallmeldesystem", "USB Accelerators:": "USB-Beschleuniger:", + "USB bus directory": "USB-Busverzeichnis", "USB disk target": "USB-Festplattenziel", "USB drives mounted now:": "Jetzt gemountete USB-Laufwerke:", "USB libedgetpu1": "USB libedgetpu1", "UUP Dump script not found.": "UUP-Dump-Skript nicht gefunden.", "UUp Dump ISO creator Custom": "UUp Dump ISO-Ersteller Benutzerdefiniert", + "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer.": "Ubooquity ist ein kostenloser, leichter und benutzerfreundlicher Heimserver für Ihre Comics und E-Books. Verwenden Sie es, um von überall auf Ihre Dateien zuzugreifen, mit einem Tablet, einem E-Reader, einem Telefon oder einem Computer.", "Udev rules for Coral USB devices added and rules reloaded.": "Udev-Regeln für Coral USB-Geräte hinzugefügt und Regeln neu geladen.", "Udev rules for Coral USB devices already exist.": "Udev-Regeln für Coral USB-Geräte existieren bereits.", "Udev rules for Coral USB devices appended and rules reloaded.": "Udev-Regeln für Coral USB-Geräte angehängt und Regeln neu geladen.", + "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results.": "UltiMaker Cura ist eine kostenlose, benutzerfreundliche 3D-Drucksoftware, der Millionen von Benutzern vertrauen. Feinabstimmung Ihres 3D-Modells mit über 400 Einstellungen für die besten Schnitt- und Druckergebnisse.", "Umbrel OS installer script by Helper Scripts\n\nVisit the GitHub repo to learn more, contribute, or support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm": "Umbrel OS-Installationsskript von Helper Scripts\n\nBesuchen Sie das GitHub-Repo, um mehr zu erfahren, einen Beitrag zu leisten oder das Projekt zu unterstützen:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm", "Unable to detect Proxmox version": "Proxmox-Version konnte nicht erkannt werden", "Unable to detect Proxmox version.": "Proxmox-Version kann nicht erkannt werden.", @@ -4618,6 +6338,10 @@ "Unable to resolve system ZFS pool disks. Aborting.": "System-Pool-Festplatten ZFS können nicht aufgelöst werden. Abbruch.", "Unable to resolve system disk topology. Aborting.": "Die Topologie der Systemfestplatte kann nicht aufgelöst werden. Abbruch.", "Understand the security implications of privileged containers": "Verstehen Sie die Sicherheitsauswirkungen privilegierter Container", + "Unexpected Proxmox inventory; recovery blocked": "Unerwartetes Proxmox-Inventar; Erholung blockiert", + "Unexpected formatting directory in the new Valkey volume": "Unerwartetes Formatierungsverzeichnis im neuen Valkey-Volume", + "Ungoogled Chromium is Google Chromium, sans dependency on Google web services.": "Ungoogled Chromium ist Google Chromium, ohne Abhängigkeit von Google-Webdiensten.", + "Unified LLM Fine-Tuning with 100+ Models": "Unified LLM Fine-Tuning mit 100+ Modellen", "Uninstall Coral drivers and configuration": "Deinstallieren Sie Coral-Treiber und -Konfiguration", "Uninstall Fail2Ban": "Deinstallieren Sie Fail2Ban", "Uninstall Lynis": "Deinstallieren Sie Lynis", @@ -4647,6 +6371,10 @@ "Unknown CPU type. IOMMU might not be properly enabled.": "Unbekannter CPU-Typ. IOMMU ist möglicherweise nicht ordnungsgemäß aktiviert.", "Unknown CPU vendor. Cannot determine IOMMU parameter.": "Unbekannter CPU-Anbieter. IOMMU-Parameter kann nicht ermittelt werden.", "Unknown GPU": "Unbekannte GPU", + "Unknown adapter role": "Unbekannte Adapterrolle", + "Unknown credential service:": "Unbekannter credential Service:", + "Unknown dependency:": "Unbekannte Abhängigkeit:", + "Unknown host monitor": "Unbekannter Host-Monitor", "Unknown model": "Unbekanntes Modell", "Unknown size": "Unbekannte Größe", "Unknown storage controller": "Unbekannter Speichercontroller", @@ -4662,6 +6390,10 @@ "Unmounted:": "Unmontiert:", "Unmounting": "Absteigen", "Unmounting disk...": "Datenträger wird ausgehängt...", + "Unpackerr configured": "Unpackerr konfiguriert", + "Unpackerr has no web interface and extracts nothing until it is pointed at a Starr application. Uncomment the [sonarr.0] or [radarr.0] section in /config/unpackerr.conf inside the container, set its url and api_key, then restart the container.": "Unpackerr hat kein Webinterface und extrahiert nichts, bis es auf eine Starr-Anwendung gezeigt wird. Dekommentieren Sie den Abschnitt [sonarr.0] oder [radarr.0] in /conf/unpackerr.conf innerhalb des Containers, legen Sie die URL und den api key fest und starten Sie den Container neu.", + "Unpackerr requires Sonarr, Radarr or Lidarr in this suite": "Unpackerr requires Sonarr, Radarr oder Lidarr in dieser Suite", + "Unpackerr stopped during its first start": "Unpackerr wurde beim ersten Start gestoppt", "Unprivileged": "Unprivilegiert", "Unprivileged Container Access": "Unprivilegierter Containerzugriff", "Unprivileged container": "Unprivilegierter Container", @@ -4670,15 +6402,73 @@ "Unprivileged containers map their UIDs to high host UIDs (e.g. 100000+), which appear as 'others' on the host filesystem.": "Unprivilegierte Container ordnen ihre UIDs hohen Host-UIDs (z. B. 100000+) zu, die im Host-Dateisystem als „Andere“ angezeigt werden.", "Unprivileged: Limited access (more secure)": "Unprivilegiert: Begrenzter Zugriff (sicherer)", "Unreachable": "Unerreichbar", + "Unrecognized Immich adapter": "Nicht anerkannter Immich-Adapter", + "Unrecognized adaptation format": "Nicht erkanntes Anpassungsformat", + "Unrecognized adaptation recipe": "Nicht anerkanntes Anpassungsrezept", + "Unrecognized dependency order of the stack:": "Unerkannte Abhängigkeitsreihenfolge des Stapels:", + "Unrecognized host monitor profile": "Nicht erkanntes Host-Monitor-Profil", + "Unrecognized native configuration": "Nicht erkannte native Konfiguration", + "Unrecognized qBittorrent configuration format": "Nicht erkanntes qBittorrent-Konfigurationsformat", + "Unrecognized stack adapter or role": "Nicht erkannter Stapeladapter oder Rolle", + "Unrecognized stack adapter:": "Nicht erkannter Stapeladapter:", + "Unrecognized stack structure:": "Nicht erkannte Stapelstruktur:", + "Unrecognized volume definition": "Nicht anerkannte Volumendefinition", + "Unresolved variable:": "Unaufgelöste Variable:", + "Unsafe OCI archive path": "Unsicherer OCI-Archivpfad", + "Unsafe dependency contract": "Unsicherer Abhängigkeitsvertrag", + "Unsafe dependency hook contract": "Hook-Vertrag mit unsicherer Abhängigkeit", + "Unsafe instance directory": "Verzeichnis unsicherer Instanzen", + "Unsafe instance record": "Unsichere Instanzdaten", + "Unsafe journal or lock file": "Unsicheres Journal oder Sperrdatei", + "Unsafe private configuration path": "Unsicherer privater Konfigurationspfad", + "Unsafe qBittorrent configuration path": "Unsicherer qBittorrent Konfigurationspfad", + "Unsafe record": "Unsichere Aufzeichnung", + "Unsafe registry directory": "Unsicheres Registerverzeichnis", + "Unsafe registry lock": "Unsichere Registrierungssperre", + "Unsafe rootfs for the capture": "Unsichere Rootfs für den Fang", + "Unsafe stack assembly": "Unsichere Stapelanordnung", + "Unsafe volume path": "Unsicherer Volumenpfad", + "Unsupported CPU allocation mode:": "Nicht unterstützter CPU-Zuweisungsmodus:", + "Unsupported GID strategy:": "Nicht unterstützte GID-Strategie:", + "Unsupported NVIDIA mode:": "Nicht unterstützter NVIDIA-Modus:", + "Unsupported OCI digest:": "Nicht unterstützter OCI-Digest:", + "Unsupported OCI-LXC AppArmor profile:": "Nicht unterstütztes OCI-LXC AppArmor-Profil:", + "Unsupported OCI-LXC seccomp profile:": "Nicht unterstütztes OCI-LXC seccomp Profil:", "Unsupported Terminal": "Nicht unterstütztes Terminal", + "Unsupported architecture:": "Nicht unterstützte Architektur:", + "Unsupported backup compression": "Nicht unterstützte Backup-Komprimierung", + "Unsupported credential pattern:": "Nicht unterstütztes credential-Muster:", + "Unsupported declarative ostype:": "Nicht unterstützter deklarativer Ostype:", + "Unsupported device GID strategy": "Nicht unterstützte Geräte-GID-Strategie", + "Unsupported device type:": "Typ des nicht unterstützten Geräts:", + "Unsupported dynamic NVIDIA capabilities:": "Nicht unterstützte dynamische NVIDIA-Funktionen:", "Unsupported format. Only .ova and .ovf files are supported.": "Nicht unterstütztes Format. Es werden nur .ova- und .ovf-Dateien unterstützt.", + "Unsupported media storage mode:": "Nicht unterstützter Medienspeichermodus:", + "Unsupported mount type": "Typ der nicht unterstützten Halterung", + "Unsupported mount type:": "Typ der nicht unterstützten Halterung:", + "Unsupported native device type:": "Nicht unterstützter nativer Gerätetyp:", + "Unsupported operation": "Nicht unterstützte operation", "Unsupported output format:": "Nicht unterstütztes Ausgabeformat:", + "Unsupported post-start configuration:": "Nicht unterstützte Konfiguration nach dem Start:", + "Unsupported pre-start check:": "Nicht unterstützte Vorabprüfung:", + "Unsupported pre-start repair:": "Nicht unterstützte Reparatur vor dem Start:", + "Unsupported prlimit resource": "Nicht unterstützte Prilimit Ressource", + "Unsupported secret generator:": "Nicht unterstützter geheimer Generator:", + "Unsupported storage mode:": "Nicht unterstützter Speichermodus:", + "Unsupported tmpfs options": "Nicht unterstützte tmpfs Optionen", + "Unsupported volume options:": "Nicht unterstützte Volumenoptionen:", + "Untrusted or modified NVIDIA hook": "Nicht vertrauenswürdiger oder modifizierter NVIDIA-Hook", + "Unused image removed from the cache:": "Nicht verwendetes Bild aus dem Cache entfernt:", + "Unused images removed from the cache:": "Nicht verwendete Bilder aus dem Cache entfernt:", + "Update": "Aktualisierung", "Update Available": "Update verfügbar", "Update Ceph repository (Only if using Ceph):": "Ceph-Repository aktualisieren (nur bei Verwendung von Ceph):", "Update Debian repositories to Trixie:": "Debian-Repositories auf Trixie aktualisieren:", "Update Export": "Export aktualisieren", "Update Lynis to latest version": "Aktualisieren Sie Lynis auf die neueste Version", "Update NVIDIA in LXC Containers": "Aktualisieren Sie NVIDIA in LXC-Containern", + "Update OCI": "Aktualisierung OCI", + "Update OCI stack": "Aktualisierung des OCI-Stacks", "Update PVE enterprise repository (Only if using enterprise):": "PVE-Enterprise-Repository aktualisieren (nur bei Verwendung von Enterprise):", "Update Proxmox VE Appliance Manager": "Proxmox VE Appliance Manager aktualisieren", "Update Proxmox package lists": "Proxmox-Paketlisten aktualisieren", @@ -4687,15 +6477,26 @@ "Update and upgrade all system packages": "Aktualisieren und aktualisieren Sie alle Systempakete", "Update and upgrade system": "System aktualisieren und aktualisieren", "Update cancelled by user": "Update vom Benutzer abgebrochen", + "Update completed. Data kept.": "Update abgeschlossen. Vorgehaltene Daten.", "Update completed. Press Enter to continue...": "Aktualisierung abgeschlossen. Drücken Sie die Eingabetaste, um fortzufahren...", + "Update every container of the application": "Aktualisieren Sie jeden Container der Anwendung", "Update kernel to compatible version": "Aktualisieren Sie den Kernel auf eine kompatible Version", + "Update now?": "Update jetzt?", "Update package index:": "Paketindex aktualisieren:", + "Update prepared": "Update vorbereitet", "Update system to latest PVE 8.4+ (if not done already):": "Aktualisieren Sie das System auf die neueste PVE 8.4+ (falls noch nicht geschehen):", + "Update the image with the saved configuration": "Aktualisieren Sie das Bild mit der gespeicherten Konfiguration", + "Update the whole stack?": "Aktualisieren Sie den gesamten Stack?", "Updated": "Aktualisiert", "Updated sharedfiles group to GID: 101000": "Sharedfiles-Gruppe auf GID aktualisiert: 101000", + "Updated stack checked": "Aktualisierter Stapel geprüft", + "Updated:": "Aktualisiert:", "Updates all Proxmox and Debian packages": "Aktualisiert alle Proxmox- und Debian-Pakete", "Updates and Packages Commands": "Befehle für Updates und Pakete", + "Updates are not available yet for this application in this beta": "Updates sind für diese Anwendung in dieser Beta noch nicht verfügbar", + "Updates are not available yet in this beta for applications that use a privileged container or advanced LXC settings": "Updates sind in dieser Beta noch nicht verfügbar für Anwendungen, die einen privilegierten Container oder erweiterte LXC-Einstellungen verwenden", "Updates file is empty or unreadable.": "Die Aktualisierungsdatei ist leer oder nicht lesbar.", + "Updating": "Aktualisierung", "Updating APT package lists...": "APT-Paketlisten werden aktualisiert...", "Updating Debian Bookworm → Trixie in sources.list...": "Debian Bookworm wird aktualisiert → Trixie in resources.list...", "Updating Figurine binary...": "Figur-Binärdatei wird aktualisiert...", @@ -4727,6 +6528,7 @@ "Upload to PBS is currently: yes. Pick an action:": "Auf PBS hochladen ist derzeit: ja. Wählen Sie eine Aktion:", "Upload to PBS: enable, disable or rotate the recovery passphrase": "Auf PBS hochladen: Wiederherstellungspassphrase aktivieren, deaktivieren oder drehen", "Uptime and who is logged in": "Betriebszeit und wer angemeldet ist", + "Usage:": "Verwendung:", "Use \"Check test progress\" to see results.": "Verwenden Sie „Testfortschritt prüfen“, um die Ergebnisse anzuzeigen.", "Use 'Export to file' to save it and inspect manually.": "Verwenden Sie „In Datei exportieren“, um es zu speichern und manuell zu überprüfen.", "Use 'pct restore' / 'qmrestore' to recover their disks from your VM backups.": "Verwenden Sie „pct restart“ / „qmrestore“, um ihre Festplatten aus Ihren VM-Backups wiederherzustellen.", @@ -4769,6 +6571,12 @@ "User activity and uptime": "Benutzeraktivität und Betriebszeit", "User chose not to remove NetworkManager": "Der Benutzer hat sich dafür entschieden, NetworkManager nicht zu entfernen", "User chose to exit for manual backup creation.": "Der Benutzer hat sich für die manuelle Backup-Erstellung entschieden.", + "User name for the SSH login": "Benutzername für das SSH-Login", + "User name of the administrator of the web interface": "Benutzername des Administrators der Weboberfläche", + "User name of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Benutzername der veralteten Flowise-Anwendung (nur von Flowise-Versionen vor 3.0.1) gelesen", + "User of the AdGuard Home that receives the settings": "Benutzer des AdGuard Home, der die Einstellungen erhält", + "User of the main AdGuard Home": "Benutzer des Haupt AdGuard Home", + "User-friendly WebUI for LLMs (Formerly Ollama WebUI)": "Benutzerfreundliche WebUI für LLMs (früher Ollama WebUI)", "Username": "Benutzername", "Username (e.g. root@pam or user@pbs!token):": "Benutzername (z. B. root@pam oder user@pbs!token):", "Username and password": "Benutzername und Passwort", @@ -4782,6 +6590,8 @@ "Using advanced configuration": "Verwenden der erweiterten Konfiguration", "Using default Proxmox logo...": "Standardmäßiges Proxmox-Logo wird verwendet...", "Using existing encryption key:": "Verwendung des vorhandenen Verschlüsselungsschlüssels:", + "Using the image verified by the transaction": "Verwenden des durch die Transaktion verifizierten Bildes", + "Using the verified image from the cache": "Verwenden des verifizierten Bildes aus dem Cache", "Utilities": "Dienstprogramme", "Utilities Installation Menu": "Installationsmenü für Dienstprogramme", "Utilities Menu": "Menü „Dienstprogramme“.", @@ -4789,6 +6599,9 @@ "Utilities and Tools": "Dienstprogramme und Tools", "Utilities installation completed": "Die Installation der Dienstprogramme ist abgeschlossen", "Utilities installed by ProxMenux have been removed": "Von ProxMenux installierte Dienstprogramme wurden entfernt", + "VA-API driver": "VA-API-Fahrer", + "VA-API render device": "VA-API-Rendervorrichtung", + "VA-API video acceleration": "VA-API Videobeschleunigung", "VFIO device IDs removed from /etc/modprobe.d/vfio.conf": "VFIO-Geräte-IDs wurden aus /etc/modprobe.d/vfio.conf entfernt", "VFIO modules configured in /etc/modules": "In /etc/modules konfigurierte VFIO-Module", "VFIO modules configured.": "VFIO-Module konfiguriert.", @@ -4796,7 +6609,9 @@ "VFIO modules removed from /etc/modules": "VFIO-Module aus /etc/modules entfernt", "VFIO orphans cleared and initramfs rebuilt — next boot will free the GPU.": "VFIO-Waisen gelöscht und initramfs neu erstellt – beim nächsten Start wird die GPU freigegeben.", "VFIO orphans cleared but initramfs rebuild failed; check /var/log/proxmenux logs.": "VFIO-Waisen gelöscht, aber die Neuerstellung von initramfs ist fehlgeschlagen;Überprüfen Sie die /var/log/proxmenux-Protokolle.", + "VFS cache mode": "VFS-Cache-Modus", "VLAN": "VLAN", + "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices.": "VLC Medien Player ist ein kostenloser und Open-Source-übergreifender Multimedia-Player und -Framework, der eine zuverlässige Leistung auf mehreren Geräten bietet.", "VM": "VM", "VM Conflict Policy": "VM-Konfliktrichtlinie", "VM ID": "VM-ID", @@ -4824,17 +6639,28 @@ "VM started": "VM gestartet", "VM stopped": "VM gestoppt", "VM:": "VM:", + "VMID (empty = next free)": "VMID (leer = nächste frei)", "VMID in use": "VMID im Einsatz", "VMID must be a number.": "VMID muss eine Zahl sein.", "VMID of the Borg server LXC on": "VMID des Borg-Servers LXC auf", + "VMID of the Rclone OCI container": "VMID des Rclone-OCI-Containers", "VMs to destroy:": "Zu zerstörende VMs:", "VMs, LXCs, network, /etc/pve, users, cron, packages, drivers, ProxMenux state, etc.": "VMs, LXCs, Netzwerk, /etc/pve, Benutzer, Cron, Pakete, Treiber, ProxMenux-Status usw.", + "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server.": "VS Code ist eine integrierte Entwicklungsumgebung, die von Microsoft entwickelt wurde. Dieser Container führt die vollständige Desktop-Anwendung aus, für eine native Web-Version siehe Code Server.", + "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft’s editor VS Code.": "VSCodium ist eine Community-gesteuerte, frei lizenzierte Binärverteilung des Microsoft-Editors VS Code.", "Valid backups for all VMs/CTs": "Gültige Backups für alle VMs/CTs", "Validating Proxmox 9 repositories (checking 'proxmox-ve' candidate)...": "Validierung von Proxmox 9-Repositories (Prüfung des Kandidaten „proxmox-ve“) ...", "Validating credentials with server": "Anmeldeinformationen werden mit dem Server validiert", "Validating disk safety...": "Festplattensicherheit wird überprüft...", + "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)": "Validierungsmethode: http (Port 80 weitergeleitet) oder dns (DNS Provider Plugin)", + "Value for": "Wert für", + "Variable name": "Variable Bezeichnung", + "Variables": "Variablen", + "Variables the installation asks for:": "Variablen, die von der Anlage verlangt werden:", "Verbose pool status": "Ausführlicher Poolstatus", "Verification": "Überprüfung", + "Verified": "Geprüft", + "Verified by ProxMenux": "Verifiziert durch ProxMenux", "Verify IOMMU group for PCI device": "Überprüfen Sie die IOMMU-Gruppe für das PCI-Gerät", "Verify Options > OS Type — currently set to:": "Optionen überprüfen > Betriebssystemtyp – derzeit eingestellt auf:", "Verify PVE version (must be 8.4.1 or newer):": "Überprüfen Sie die PVE-Version (muss 8.4.1 oder neuer sein):", @@ -4850,12 +6676,16 @@ "Verifying Ceph packages availability...": "Verfügbarkeit von Ceph-Paketen überprüfen...", "Verifying all utilities status": "Überprüfen des Status aller Dienstprogramme", "Verifying disk accessibility in CT": "Überprüfung der Festplattenzugänglichkeit im CT", + "Verifying the backups...": "Überprüfung der Backups...", + "Verifying the image integrity...": "Überprüfung der Bildintegrität...", "Version": "Version", "Version Change Detected": "Versionsänderung erkannt", "Version info not available": "Versionsinformationen nicht verfügbar", "Version:": "Version:", "Version: Auto-negotiation (NFSv3/NFSv4)": "Version: Auto-Negotiation (NFSv3/NFSv4)", "Versions shown belong to maintained NVIDIA branches that list your GPU PCI ID and are new enough to build against the running kernel. DKMS compilation is the final validation. The recommended version keeps the current branch, or uses the NVIDIA Production Branch on a fresh install.": "Die angezeigten Versionen gehören zu gepflegten NVIDIA-Zweigen, die Ihre GPU-PCI-ID auflisten und neu genug sind, um auf dem laufenden Kernel zu erstellen. Die DKMS-Kompilierung ist die endgültige Validierung. Die empfohlene Version behält den aktuellen Zweig bei oder verwendet den NVIDIA Production Branch bei einer Neuinstallation.", + "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML.": "Videobeschleunigung und Objekterkennung sind unabhängige Entscheidungen; der Installer schreibt keine Kamera oder Detektor YAML.", + "Video transcoding acceleration": "Videotranscodierungsbeschleunigung", "View CIFS Mounts (pvesm + fstab)": "CIFS-Mounts anzeigen (pvesm + fstab)", "View Current Exports": "Aktuelle Exporte anzeigen", "View Current Mounts": "Aktuelle Reittiere anzeigen", @@ -4871,6 +6701,7 @@ "View raw VM configuration file": "Rohe VM-Konfigurationsdatei anzeigen", "View restore plan": "Wiederherstellungsplan anzeigen", "View self-test log": "Selbsttestprotokoll anzeigen", + "View status": "Sichtstatus", "VirtIO (advanced - high performance)": "VirtIO (fortgeschritten – hohe Leistung)", "VirtIO ISO not found after selection.": "VirtIO ISO wurde nach der Auswahl nicht gefunden.", "VirtIO ISO selection cancelled.": "VirtIO-ISO-Auswahl abgebrochen.", @@ -4886,10 +6717,19 @@ "Virtual display normalized to vga: std (compatibility)": "Virtuelle Anzeige normalisiert auf VGA: std (Kompatibilität)", "Virtual display set to": "Virtuelle Anzeige eingestellt auf", "Virtual interface (normal)": "Virtuelle Schnittstelle (normal)", + "Virtual whiteboard for sketching hand-drawn like diagrams": "Virtuelles Whiteboard zum Skizzieren von handgezeichneten Diagrammen", "Virtualization": "Virtualisierung", "Visit https://osx-proxmox.com for more information.": "Weitere Informationen finden Sie unter https://osx-proxmox.com.", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:": "Besuchen Sie die Website, um weitere Skripte zu entdecken, über die neuesten Updates auf dem Laufenden zu bleiben und das Projekt zu unterstützen:", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE": "Besuchen Sie die Website, um weitere Skripte zu entdecken, über die neuesten Updates auf dem Laufenden zu bleiben und das Projekt zu unterstützen:\n\nhttps://community-scripts.github.io/ProxmoxVE", + "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies.": "Vivaldi ist ein norwegischer Freeware-, Cross-Plattform-Webbrowser mit einem integrierten E-Mail-Client, der von Vivaldi Technologies entwickelt wurde.", + "Volume configuration cancelled": "Volumenkonfiguration abgesagt", + "Volume options are not yet supported": "Volumenoptionen werden noch nicht unterstützt", + "Volume size in GB": "Volumengröße in GB", + "Volumes attached": "Angehängte Volumen", + "Volumes prepared for the first start:": "Für den ersten Start vorbereitete Volumen:", + "Volumes shared between services are not yet supported": "Volumes, die zwischen Diensten geteilt werden, werden noch nicht unterstützt", + "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code.": "Vscodium-web ist eine Community-gesteuerte, frei lizenzierte Binärverteilung der Remote-Host-Webkomponente des Microsoft-Editors VS Code.", "Vulnerability detection": "Erkennung von Schwachstellen", "WARNING": "WARNUNG", "WARNING — This backup contains paths that are risky to restore on a running system:": "WARNUNG – Dieses Backup enthält Pfade, deren Wiederherstellung auf einem laufenden System riskant ist:", @@ -4912,15 +6752,41 @@ "WARNING: You are about to remove this Proxmox storage:": "ACHTUNG: Sie sind dabei, diesen Proxmox-Speicher zu entfernen:", "WARNING: You are about to remove this disk mount:": "WARNUNG: Sie sind dabei, diese Festplattenhalterung zu entfernen:", "WARNING: this will ERASE EVERYTHING on the disk.": "ACHTUNG: Dadurch wird ALLES auf der Festplatte GELÖSCHT.", + "WEB UI to manage WireGuard VPN.": "WEB UI zur Verwaltung von WireGuard VPN.", "WILL BE PERMANENTLY ERASED.": "WIRD DAUERHAFT GELÖSCHT.", + "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency.": "WPS Office ist eine leichte, funktionsreiche, umfassende Office-Suite mit hoher Kompatibilität. Als praktische und professionelle Office-Software können Sie mit WPS Office Dateien in Writer, Presentation, Spreadsheet und PDF bearbeiten, um Ihre Arbeitseffizienz zu verbessern.", "Wait for each node to complete before starting next": "Warten Sie, bis jeder Knoten abgeschlossen ist, bevor Sie mit dem nächsten beginnen", + "Waiting for Home Assistant OS...": "Warten auf Home Assistant OS...", + "Waiting for the FUSE mount:": "Warten auf das FUSE-Mount:", + "Waiting for the application to respond...": "Warten auf die Antwort des Antrags...", + "Waiting for the initial Jellyfin configuration...": "Warten auf die erste Jellyfin-Konfiguration...", + "Waiting for the network address...": "Warten auf die Netzwerkadresse...", + "Waiting for the password of the application...": "Warten auf das Passwort der Anwendung...", + "Waiting for the temporary password...": "Warten auf das temporäre Passwort...", "Warning": "Warnung", "Warning: Auth key should start with 'tskey-'": "Warnung: Der Authentifizierungsschlüssel sollte mit „tskey-“ beginnen.", "Warning: Disk Images on CIFS": "Warnung: Disk-Images auf CIFS", "Warning: Limited PCI Reset Support": "Warnung: Eingeschränkte PCI-Reset-Unterstützung", "Warning: both VMs have autostart enabled (onboot=1).": "Warnung: Auf beiden VMs ist der Autostart aktiviert (onboot=1).", "Warnings": "Warnungen", + "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents.": "WeKnora ist ein LLM-basiertes Framework, das für ein tiefes Dokumentenverständnis und semantisches Abrufen entwickelt wurde, insbesondere für den Umgang mit heterogenen Dokumenten von complex.", + "Web UI": "Web-UI", + "Web UI 1": "Web UI 1", + "Web UI 2": "Web UI 2", + "Web UI password": "Web UI Passwort", + "Web UI user": "Web-UI-Benutzer", + "Web access": "Webzugang", + "Web address of the AdGuard Home that receives the settings (e.g. http://192.168.1.3)": "Webadresse des AdGuard Home, der die Einstellungen erhält (z. B. http://192.168.1.3)", + "Web address of the main AdGuard Home, whose settings are copied (e.g. http://192.168.1.2)": "Webadresse des AdGuard Home, dessen Einstellungen kopiert sind (z. B. http://192.168.1.2)", + "Web interface to manage devices running Tasmota firmware.": "Web-Schnittstelle zur Verwaltung von Geräten mit Tasmota-Firmware.", + "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes).": "WebCord kann als ein Paket von Sicherheits- und Datenschutz-Härtungen, Discord-Features-Reimplementierungen, Electron / Chromium / Discord-Bugs-Workarounds, Stylesheets, interne Seiten und verpackte https://discord.com-Seite zusammengefasst werden, die so weit wie möglich mit ToS konform sind (oder die Änderungen, die es verletzen könnten, vor Discords Augen verbergen).", + "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels.": "Webgrabplus ist ein multi-site inkrementeller xmltv epg grabber. Es sammelt tv-programm-guide-daten von ausgewählten tvguide-seiten für ihre lieblingskanäle.", + "Webservers & Proxies": "Webserver & Proxies", "Website": "Webseite", + "Webstation is a web native emulation focused LXQt desktop based on Ubuntu.": "Webstation ist ein Web-nativer Emulations-fokussierter LXQt-Desktop auf Basis von Ubuntu.", + "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser.": "Webtop - Alpine, Ubuntu, Fedora und Arch-basierte Container mit vollständigen Desktop-Umgebungen in offiziell unterstützten Geschmacksrichtungen, die über jeden modernen Webbrowser zugänglich sind.", + "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent.": "Weixin (WeChat) ist eine von Tencent entwickelte Instant Messaging-, Social Media- und Mobile-Payment-App.", + "What cannot be translated:": "Was nicht übersetzt werden kann:", "What do you want to do?": "Was möchten Sie tun?", "What would you like to do?": "Was möchten Sie tun?", "When asked to select a disk, click Load Driver and load the VirtIO drivers.": "Wenn Sie aufgefordert werden, einen Datenträger auszuwählen, klicken Sie auf „Treiber laden“ und laden Sie die VirtIO-Treiber.", @@ -4932,28 +6798,46 @@ "Where do you want to mount the Samba share?": "Wo möchten Sie die Samba-Freigabe mounten?", "Where is the OVA/OVF file located?": "Wo befindet sich die OVA/OVF-Datei?", "Where to mount inside container?": "Wo im Container montieren?", + "Where to store": "Wo zu lagern", "While the server allows guest listing, no shares are actually accessible without authentication.": "Während der Server die Auflistung von Gästen zulässt, sind ohne Authentifizierung tatsächlich keine Freigaben zugänglich.", + "Wikijs A modern, lightweight and powerful wiki app built on NodeJS.": "Wikijs Eine moderne, leichte und leistungsstarke Wiki-App, die auf NodeJS basiert.", "Will be configured now": "Wird jetzt konfiguriert", "Windows Installation Options": "Windows-Installationsoptionen", "Windows path:": "Windows-Pfad:", + "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles.": "WineGUI ist ein benutzerfreundlicher Weinmanager, der ein grafisches Frontend zum Erstellen und Verwalten von Weinflaschen bietet.", "Wipe all — erase partitions + metadata": "Alles löschen – Partitionen und Metadaten löschen", "Wipe all — remove partitions + metadata": "Alles löschen – Partitionen und Metadaten entfernen", "Wipe old signatures and partition table (DESTRUCTIVE):": "Alte Signaturen und Partitionstabelle löschen (DESTRUKTIV):", "Wiping existing partition table...": "Vorhandene Partitionstabelle wird gelöscht...", "Wiping partitions and metadata...": "Partitionen und Metadaten löschen...", + "WireGuard Easy web interface": "WireGuard Easy Web-Schnittstelle", + "WireGuard® is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry.": "WireGuard® ist ein extrem einfaches, aber schnelles und modernes VPN, das modernste Kryptographie nutzt. Es zielt darauf ab, schneller, einfacher, schlanker und nützlicher als IPsec zu sein, während die massiven Kopfschmerzen vermieden werden. Es soll deutlich performanter sein als OpenVPN. WireGuard ist als Allzweck-VPN für den Betrieb auf eingebetteten Schnittstellen und Supercomputern konzipiert, die für viele verschiedene Umstände geeignet sind. Ursprünglich für den Linux-Kernel veröffentlicht, ist er jetzt plattformübergreifend (Windows, macOS, BSD, iOS, Android) und weit verbreitet einsetzbar. Es befindet sich derzeit in der entwicklung, aber es könnte bereits als die sicherste, einfachste und einfachste vpn-lösung in der branche angesehen werden.", "Wired NICs in backup missing on target:": "Kabelgebundene Netzwerkkarten im Backup fehlen auf dem Ziel:", + "Wireshark is the world’s foremost and widely-used network protocol analyzer. It lets you see what’s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998.": "Wireshark ist der weltweit führende und weit verbreitete Netzwerkprotokollanalysator. Es lässt Sie sehen, was in Ihrem Netzwerk auf einer mikroskopischen Ebene passiert und ist der De-facto- (und oft de jure-) Standard in vielen kommerziellen und gemeinnützigen Unternehmen, Regierungsbehörden und Bildungseinrichtungen. Die Entwicklung von Wireshark gedeiht dank der freiwilligen Beiträge von Netzwerkexperten auf der ganzen Welt und ist die Fortsetzung eines von Gerald Combs 1998 gestarteten Projekts.", + "With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopped.": "Bei der dns-Validierung benennt die DNSPLUGIN-Variable das Provider-Plugin. Die erweiterte Installation fragt danach; andernfalls fügen Sie die Zeile lxc.environment hinzu. Laufzeit: DNSPLUGIN= zu /etc/pve/lxc/.conf mit angehaltenem Container.", + "With dns validation, write the provider credentials in /config/dns-conf/.ini inside the container and restart it.": "Schreiben Sie mit der dns-Validierung den Provider credentials in /config/dns-conf/.ini in den Container und starten Sie ihn neu.", + "With http validation, port 80 of the router must be forwarded to port 80 of this container.": "Bei der http-Validierung muss Port 80 des Routers an Port 80 dieses Containers weitergeleitet werden.", "With warnings": "Mit Warnungen", "Without Function Level Reset (FLR), passthrough is not considered reliable": "Ohne Function Level Reset (FLR) gilt Passthrough nicht als zuverlässig", "Without a usable reset path, passthrough reliability is poor and VM": "Ohne einen nutzbaren Reset-Pfad ist die Passthrough-Zuverlässigkeit schlecht und VM", + "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom.": "Wolfenstein: Blade of Agony ist ein Story-basierter WWII-Shooter, inspiriert von Wolfenstein und Doom.", + "Workflow automation tool": "Workflow Automation Tool", "Working directory:": "Arbeitsverzeichnis:", "Works with LVM, ZFS, and BTRFS storage types": "Funktioniert mit LVM-, ZFS- und BTRFS-Speichertypen", + "Worth knowing before installing it:": "Wissenswert vor der Installation:", "Would you like to continue in passthrough-only mode? The libedgetpu APT install will be skipped, the Coral device will still be visible inside the container (e.g. /dev/apex_0), and you can install the runtime yourself or use an app container that bundles it (e.g. the Frigate Docker image).": "Möchten Sie im Nur-Passthrough-Modus fortfahren? Die Installation von libedgetpu APT wird übersprungen, das Coral-Gerät ist weiterhin im Container sichtbar (z. B. /dev/apex_0) und Sie können die Laufzeit selbst installieren oder einen App-Container verwenden, der sie bündelt (z. B. das Frigate Docker-Image).", "Would you like to see the current": "Möchten Sie den aktuellen Stand sehen?", "Write access confirmed for user:": "Schreibzugriff für Benutzer bestätigt:", "Write access confirmed.": "Schreibzugriff bestätigt.", "Write access test FAILED for user:": "Schreibzugriffstest für Benutzer fehlgeschlagen:", "Write access verified for user:": "Schreibzugriff für Benutzer bestätigt:", + "Write the value it produces instead.": "Schreibe stattdessen den Wert, den es produziert.", + "Wrong SHA-256 in": "Falsches SHA-256 in", + "Wrong inherited registry lock": "Falsche geerbte Registersperre", "Wrong passphrase": "Falsche Passphrase", + "Wrong size in": "Falsche Größe in", + "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support.": "Xbackbone ist ein einfacher, selbst gehosteter, leichter PHP-Dateimanager, der das Instant-Sharing-Tool ShareX und *NIX-Systeme unterstützt. Es unterstützt das Hochladen und Anzeigen von Bildern, GIF, Video, Code, formatiertem Text und Herunterladen und Hochladen von Dateien. Haben Sie auch eine Web-Benutzeroberfläche mit Multi-Benutzer-Management, Vergangenheit Uploads Geschichte und Such-Unterstützung.", + "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS.": "Yaak ist ein Desktop-API-Client zum Organisieren und Ausführen von REST-, GraphQL- und gRPC-Anfragen. Es basiert auf Tauri, Rust und ReactJS.", "Yes": "Ja", "Yes, upload": "Ja, hochladen", "Yes: set a recovery passphrase now; the encrypted key envelope is uploaded with every backup.": "Ja: Legen Sie jetzt eine Wiederherstellungspassphrase fest. Der verschlüsselte Schlüsselumschlag wird bei jedem Backup hochgeladen.", @@ -4984,6 +6868,9 @@ "You should now be able to access the Proxmox web interface.": "Sie sollten nun auf die Proxmox-Weboberfläche zugreifen können.", "You will need a Tailscale auth key from: https://login.tailscale.com/admin/settings/keys": "Sie benötigen einen Tailscale-Authentifizierungsschlüssel von: https://login.tailscale.com/admin/settings/keys", "Your Coral USB device and its runtime (libedgetpu1) will NOT be affected.": "Ihr Coral USB-Gerät und seine Laufzeit (libedgetpu1) sind NICHT betroffen.", + "Your machine learning Env work with Jupyter Lab": "Ihre Machine Learning Env arbeitet mit Jupyter Lab", + "Your next YouTube media manager": "Dein nächster YouTube Media Manager", + "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics.": "Your_spotify ist eine selbst gehostete Anwendung, die verfolgt, was Sie hören und bietet Ihnen ein Dashboard, um Statistiken darüber zu erkunden! Es besteht aus einem Webserver, der hin und wieder die Spotify-API abfragt, und einer Webanwendung, auf der Sie Ihre Statistiken erkunden können.", "ZFS ARC config removed (kernel defaults will apply on reboot)": "ZFS ARC-Konfiguration entfernt (Kernel-Standardeinstellungen gelten beim Neustart)", "ZFS ARC maximum configured:": "ZFS ARC maximal konfiguriert:", "ZFS ARC optimization completed": "ZFS ARC-Optimierung abgeschlossen", @@ -5011,9 +6898,17 @@ "ZFS storage added successfully to Proxmox!": "ZFS-Speicher erfolgreich zu Proxmox hinzugefügt!", "ZFS tools not found. Install zfsutils-linux and retry.": "ZFS-Tools nicht gefunden. Installieren Sie zfsutils-linux und versuchen Sie es erneut.", "ZFS:": "ZFS:", + "ZNC web interface": "ZNC Web-Schnittstelle", + "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design.": "Zen Browser ist eine kostenlose und Open-Source-fork von Mozilla Firefox mit einem Fokus auf Privatsphäre, Anpassbarkeit und Design.", "Zero all data — partition table preserved, data wiped": "Alle Daten auf Null setzen – Partitionstabelle bleibt erhalten, Daten werden gelöscht", "Zero all data — partition table preserved": "Alle Daten auf Null setzen – Partitionstabelle bleibt erhalten", "Zeroing partition": "Partition auf Null setzen", + "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC.": "Znc ist ein IRC Network Bouncer oder BNC. Es kann den client vom tatsächlichen irc-server und auch von ausgewählten kanälen trennen. Mehrere Clients von verschiedenen Standorten können sich gleichzeitig mit einem einzigen ZNC-Konto verbinden und erscheinen daher unter dem gleichen Spitznamen im IRC.", + "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research.": "Zotero ist ein kostenloses, benutzerfreundliches Tool, mit dem Sie Forschung sammeln, organisieren, kommentieren, zitieren und teilen können.", + "a device it asks for cannot be translated:": "Ein Gerät, um das es bittet, kann nicht übersetzt werden:", + "a value is required": "a Wert ist required", + "aMule WebUI (password only, no username)": "aMule WebUI (nur Passwort, kein Benutzername)", + "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule.": "aMule ist ein Multi-Plattform-Client für das ED2K-Dateifreigabenetzwerk und basiert auf dem Windows-Client eMule. aMule begann im August 2003 als fork von xMule, was ein fork von lMule ist.", "active VF(s)": "aktive VF(s)", "active VFs": "aktive VFs", "active Virtual Functions. Changing its driver binding would destroy every VF.": "aktive virtuelle Funktionen. Eine Änderung der Treiberbindung würde jedes VF zerstören.", @@ -5035,20 +6930,24 @@ "apex group still has members; left in place:": "Die Apex-Gruppe hat noch Mitglieder. an Ort und Stelle belassen:", "apex kernel module not loaded on host. Run \"Install Coral on Host\" first or the container will not see /dev/apex_0.": "Das Apex-Kernelmodul ist nicht auf dem Host geladen. Führen Sie zuerst „Install Coral on Host“ aus, sonst wird der Container /dev/apex_0 nicht sehen.", "appears to be part of a": "scheint Teil von a zu sein", + "apply requires the OCI archive of the resolved image": "requires das OCI-Archiv des aufgelösten Bildes anwenden", "applying minimal banner patch": "Anwenden eines minimalen Banner-Patches", "apt cache refreshed.": "Apt-Cache aktualisiert.", "apt-get exited": "apt-get exited", "apt-get update returned warnings. Continuing anyway; check": "apt-get update hat Warnungen zurückgegeben. Trotzdem weitermachen; überprüfen", "as": "als", + "assembling": "Montage", "automatically. Install it manually inside the container.": "automatisch. Installieren Sie es manuell im Container.", "automatically. Reboot LXC to fully release.": "automatisch. Starten Sie LXC neu, um es vollständig freizugeben.", "available for LXC bind-mounts via 'LXC Mount Manager'": "verfügbar für LXC-Bind-Mounts über „LXC Mount Manager“", "available in this same GPU and TPU menu.": "verfügbar im selben GPU- und TPU-Menü.", "backup at /etc/fstab.proxmenux.bak": "Backup unter /etc/fstab.proxmenux.bak", "ban": "Verbot", + "belongs to another OCI installation": "gehört zu einer anderen OCI-Anlage", "blocking issue(s).": "Blockierungsproblem(e).", "btrfs — Proxmox dir storage (snapshots, compression)": "btrfs – Proxmox-Verzeichnisspeicher (Snapshots, Komprimierung)", "btrfs — snapshots and compression": "btrfs – Snapshots und Komprimierung", + "budge is an open source 'budgeting with envelopes' personal finance app.": "budge ist eine Open Source 'budgeting mit Umschlägen' persönliche Finanz-App.", "builds against kernel": "Builds gegen den Kernel", "but it does not match the one used to create the backup. Replace it with the correct keyfile from the source host and retry.": "aber es stimmt nicht mit dem überein, das zum Erstellen der Sicherung verwendet wurde. Ersetzen Sie es durch die richtige Schlüsseldatei vom Quellhost und versuchen Sie es erneut.", "bytes": "Bytes", @@ -5056,29 +6955,52 @@ "chmod 1777 + setfacl o::rwx (applied on the NFS share from this host)": "chmod 1777 + setfacl o::rwx (auf die NFS-Freigabe von diesem Host angewendet)", "chmod failed — NFS server may be restricting changes from root": "chmod fehlgeschlagen – Der NFS-Server schränkt möglicherweise Änderungen vom Root aus ein", "chown/chmod failed — likely unprivileged CT against host bind mount. Falling back to ACL.": "chown/chmod fehlgeschlagen – wahrscheinlich unprivilegierter CT gegen Host-Bind-Mount. Zurückgreifen auf ACL.", + "containers": "Behälter", + "containers of": "Behälter von", "content:": "Inhalt:", + "copyparty web interface": "copyparty Web-Schnittstelle", "could not be compiled for kernel": "konnte nicht für den Kernel kompiliert werden", + "could not validate NVIDIA; exit code": "konnte NVIDIA nicht validieren; Exit-Code", + "cpuunits must be between 8 and 10000": "cpuunits müssen zwischen 8 und 10000 sein", + "custom": "Custom", + "custom dependency commands are not yet supported": "Custom Dependency Commands werden noch nicht unterstützt", + "custom path(s) saved.": "Benutzerdefinierte(r) Pfad(e) gespeichert.", + "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them.": "darktable ist eine Open-Source-Fotografie-Workflow-Anwendung und Rohentwickler. Ein virtueller Lichttisch und Dunkelkammer für Fotografen. Es verwaltet Ihre digitalen Negative in einer Datenbank, lässt Sie sie durch einen zoombaren Lichttisch anzeigen und ermöglicht es Ihnen, Rohbilder zu entwickeln und zu verbessern.", + "ddclient starts with the example configuration and updates nothing yet. Write your provider, login and domains in /config/ddclient.conf inside the container, then restart it.": "ddclient startet mit der Beispielkonfiguration und aktualisiert noch nichts. Schreiben Sie Ihren Provider, Login und Domains in /config/ddclient.conf in den Container und starten Sie ihn dann neu.", "default": "Standard", "delete the credentials file (if any)": "Löschen Sie die Anmeldeinformationsdatei (falls vorhanden).", "delete the matching line from /etc/fstab": "Löschen Sie die entsprechende Zeile aus /etc/fstab", "descriptor + VMDK files": "Deskriptor + VMDK-Dateien", + "device(s) added to VM": "Gerät(e) zur VM hinzugefügt", "devices": "Geräte", + "devices (dynamic runtime)": "Geräte (dynamische Laufzeit)", "did not become ready. Skipping.": "nicht fertig geworden. Überspringen.", + "digiKam: Professional Photo Management with the Power of Open Source": "digiKam: Professionelles Fotomanagement mit Open Source", "disk(s) added to CT": "Festplatte(n) zu CT hinzugefügt", "disk(s) added to VM": "Festplatte(n) zur VM hinzugefügt", + "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems.": "diskover ist ein Open-Source-Dateisystemindexer, der Elasticsearch verwendet, um Daten über heterogene Speichersysteme hinweg zu indizieren und zu verwalten.", "disks present": "Festplatten vorhanden", "dkms autoinstall did not activate:": "Die automatische Installation von dkms wurde nicht aktiviert:", "dkms.conf generated.": "dkms.conf generiert.", + "docker run command": "docker-Betriebsbefehl", + "docker run command of the application": "docker Run Command der Anwendung", "does not exist on this host. Path not added.": "existiert auf diesem Host nicht. Pfad nicht hinzugefügt.", "does not exist. Exiting.": "existiert nicht. Verlassen.", + "doplarr_rs starts from the example configuration and connects to nothing. Write the token of your Discord bot in discord_token in /config/config.toml inside the container.": "doplarr_rs beginnt mit der Beispielkonfiguration und verbindet sich mit nichts. Schreiben Sie das Token Ihres Discord-Bots in discord token in /config/config.toml in den Container.", + "downloaded Compose file": "Herunterladen der Compose-Datei", "dpkg still reports unfinished package work; review": "dpkg meldet immer noch unvollendete Paketarbeit;Rezension", + "driver components": "Treiberkomponenten", "driver:": "Treiber:", + "e.g.": "z. B.", + "empty = generate": "leer = erzeugen", "exFAT (portable: Windows/Linux/macOS)": "exFAT (tragbar: Windows/Linux/macOS)", "exFAT tools installed successfully.": "exFAT-Tools erfolgreich installiert.", "ext4 — Proxmox dir storage (recommended)": "ext4 – Proxmox-Verzeichnisspeicher (empfohlen)", "ext4 — recommended, most compatible": "ext4 – empfohlen, am kompatibelsten", "fail2ban-client could not communicate with the server": "fail2ban-client konnte nicht mit dem Server kommunizieren", "fail2ban-client successfully communicated with the server": "fail2ban-client hat erfolgreich mit dem Server kommuniziert", + "failed": "gescheitert", + "failed with exit code": "fehlgeschlagen mit Exit-Code", "failed:": "fehlgeschlagen:", "feranick fork unreachable. Falling back to google/gasket-driver...": "Der feranick-Fork ist nicht erreichbar. Es wird auf google/gasket-driver zurückgegriffen ...", "feranick/gasket-driver cloned (actively maintained, kernel 6.12+ ready).": "feranick/gasket-driver geklont (aktiv gepflegt, für Kernel 6.12+ vorbereitet).", @@ -5092,6 +7014,7 @@ "for this policy and may fail after first use or on subsequent VM starts.": "für diese Richtlinie und kann nach der ersten Verwendung oder bei nachfolgenden VM-Starts fehlschlagen.", "formatted as": "formatiert als", "found": "gefunden", + "free": "frei", "from Proxmox web interface (you will be asked)": "über die Proxmox-Weboberfläche (Sie werden gefragt)", "from container": "aus Container", "from the GPUs and Coral-TPU menu first, then run this option again.": "Wählen Sie zunächst das Menü „GPUs und Coral-TPU“ aus und führen Sie dann diese Option erneut aus.", @@ -5109,10 +7032,14 @@ "has a different MAC than the backup — update any DHCP static reservation": "Hat einen anderen MAC als das Backup – aktualisieren Sie alle statischen DHCP-Reservierungen", "has a new MAC": "hat einen neuen MAC", "has only": "hat nur", + "health and persistence profile not yet defined": "Gesundheits- und Persistenzprofil noch nicht definiert", + "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers.": "hiSHtory ist eine bessere Shell-Geschichte. Es speichert Ihre Shell-Historie im Kontext (in welchem Verzeichnis Sie den Befehl ausgeführt haben, ob er erfolgreich war oder nicht, wie lange er dauerte usw.). Dies wird alles lokal gespeichert und Ende-zu-Ende verschlüsselt für die Synchronisierung mit allen Ihren anderen Computern.", + "host directory": "Hostverzeichnis", "host fstab only (not registered as Proxmox storage)": "Nur Host-fstab (nicht als Proxmox-Speicher registriert)", "hostpci entries for all IOMMU group devices": "hostpci-Einträge für alle IOMMU-Gruppengeräte", "hostpci entries for selected GPU functions (full IOMMU group will be enforced after reboot)": "hostpci-Einträge für ausgewählte GPU-Funktionen (die vollständige IOMMU-Gruppe wird nach dem Neustart erzwungen)", "hour(s)": "Std)", + "https if the image serves TLS": "https, wenn das Bild TLS dient", "iSCSI Content Type": "iSCSI-Inhaltstyp", "iSCSI Daemon (iscsid): RUNNING": "iSCSI-Daemon (iscsid): LÄUFT", "iSCSI Daemon (iscsid): STOPPED": "iSCSI-Daemon (iscsid): GESTOPPT", @@ -5129,16 +7056,23 @@ "iSCSI storage provides raw block devices for VM disk images.": "iSCSI-Speicher stellt Rohblockgeräte für VM-Festplatten-Images bereit.", "iSCSI tools installed": "iSCSI-Tools installiert", "iftop usage": "iftop-Nutzung", + "image cache on": "Bild-Cache auf", + "image itself": "Bild selbst", "imported:": "importiert:", "in CT": "im CT", + "in backups": "in Backups", + "incompatible qBittorrent schema": "Inkompatibles qBittorrent-Schema", + "individual template is blocked": "Einzelne Vorlage wird blockiert", "initramfs updated": "initramfs aktualisiert", "initramfs updated.": "initramfs aktualisiert.", + "installed": "installiert", "installed but command not immediately available": "installiert, aber der Befehl ist nicht sofort verfügbar", "installed correctly and available": "korrekt installiert und verfügbar", "installed in CT": "im CT installiert", "installed inside CT": "im CT installiert", "installed successfully.": "erfolgreich installiert.", "installed.": "installiert.", + "installing": "Installation", "intel-gpu-tools installed successfully": "Intel-GPU-Tools erfolgreich installiert", "intel-gpu-tools is already installed:": "Intel-GPU-Tools ist bereits installiert:", "intel-gpu-tools is up to date": "Intel-GPU-Tools ist auf dem neuesten Stand", @@ -5169,7 +7103,11 @@ "is not configured as machine type q35.": "ist nicht als Maschinentyp q35 konfiguriert.", "is not in the patch.sh supported list. The patch may no-op or fail; review keylase/nvidia-patch README before continuing.": "ist nicht in der von patch.sh unterstützten Liste enthalten. Der Patch funktioniert möglicherweise nicht oder schlägt fehl. Lesen Sie die README-Datei zu keylase/nvidia-patch, bevor Sie fortfahren.", "is not supported by the official Google libedgetpu APT repository.": "wird vom offiziellen Google libedgetpu APT-Repository nicht unterstützt.", + "is one of the": "ist einer der", "is referenced in the following stopped VM(s)/CT(s):": "wird in den folgenden gestoppten VM(s)/CT(s) referenziert:", + "it asks for the network of the host; the container gets its own address instead": "es fragt nach dem Netzwerk des Hosts; der Container erhält stattdessen eine eigene Adresse", + "it publishes no other architecture": "Es veröffentlicht keine andere Architektur", + "it uses the Compose option": "Es verwendet die Compose-Option", "journald MaxLevelStore is adequate for auth logging": "„journald MaxLevelStore“ ist für die Authentifizierungsprotokollierung ausreichend", "journald drop-in created: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf": "Journald-Drop-In erstellt: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf", "journald log level restored": "Journald-Protokollebene wiederhergestellt", @@ -5193,26 +7131,41 @@ "kexec-tools installed successfully": "kexec-tools erfolgreich installiert", "kexec-tools is already installed": "kexec-tools ist bereits installiert", "kexec-tools is not installed or already removed.": "kexec-tools ist nicht installiert oder bereits entfernt.", + "layers": "Schichten", "legacy .link file(s) to the ProxMenux-managed format": "ältere .link-Dateien in das von ProxMenux verwaltete Format", "log2ram completely removed from system": "log2ram vollständig aus dem System entfernt", "manually inside the container before starting it.": "manuell in den Behälter hinein, bevor Sie ihn starten.", "manually inside the container.": "manuell in den Behälter einfüllen.", "maximum performance": "maximale Leistung", "may be closed — trying discovery anyway...": "möglicherweise geschlossen – versuchen Sie es trotzdem ...", + "melonDS aims at providing fast and accurate Nintendo DS emulation.": "melonDS zielt darauf ab, eine schnelle und accurate Nintendo DS-Emulation bereitzustellen.", + "members:": "Mitglieder:", + "minimum": "mindestens", "missing": "fehlt", "mkfs.btrfs not found. Install btrfs-progs and retry.": "mkfs.btrfs nicht gefunden. Installieren Sie btrfs-progs und versuchen Sie es erneut.", "more": "mehr", + "motionEye web interface": "motionEye Web-Schnittstelle", "mount.cifs command not found after installation.": "Der Befehl mount.cifs wurde nach der Installation nicht gefunden.", "mount.nfs command not found after installation.": "Der Befehl mount.nfs wurde nach der Installation nicht gefunden.", + "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone.": "mstream ist ein persönlicher Musikstreaming-Server. Sie können mStream verwenden, um Ihre Musik von Ihrem Heimcomputer auf jedes Gerät und überall zu streamen. Es gibt mobile Apps für Android und iPhone.", + "must contain a valid numeric UID for the GPU": "muss eine gültige numerische UID für die GPU enthalten", + "needed": "Notwendig", + "needs a privileged LXC": "braucht eine privilegierte LXC", + "needs a relaxed AppArmor or seccomp profile": "braucht ein entspanntes AppArmor- oder seccomp-Profil", + "needs stack review": "Needs Stack Überprüfung", "never": "nie", + "next free": "Nächster Free", + "next free block": "Nächster Free Block", "nftables not available - using iptables ban action": "nftables nicht verfügbar – iptables-Verbotsaktion wird verwendet", "no": "nein", "no (kdf=none, not needed)": "nein (kdf=none, nicht erforderlich)", "no (no escrow blob — set a recovery passphrase to enable recovery)": "nein (kein Escrow-Blob – legen Sie eine Wiederherstellungspassphrase fest, um die Wiederherstellung zu aktivieren)", + "no declarative value": "kein deklarativer Wert", "no passphrase": "keine Passphrase", "no password": "kein Passwort", "no_root_squash": "no_root_squash", "non-ProxMenux .tar archive(s) in this path": "Nicht-ProxMenux-.tar-Archive in diesem Pfad", + "not available yet": "noch nicht verfügbar", "not found.": "nicht gefunden.", "not installed": "nicht installiert", "not reliable on this hardware due to the following limitations": "Aufgrund der folgenden Einschränkungen ist die Funktion auf dieser Hardware nicht zuverlässig", @@ -5229,27 +7182,39 @@ "of free disk space.": "freien Speicherplatz.", "older firmware may increase passthrough instability": "Ältere Firmware kann die Passthrough-Instabilität erhöhen", "oldest driver offered:": "Ältester angebotener Treiber:", + "on": "am", "on SSD/NVMe pools that support discard": "auf SSD/NVMe-Pools, die das Verwerfen unterstützen", + "one of its services declares no image": "einer seiner Dienste erklärt kein Bild", + "one of its services is not written as a service": "einer seiner Dienste ist nicht als Dienst geschrieben", "openssl encryption failed.": "Die OpenSSL-Verschlüsselung ist fehlgeschlagen.", "openssl is not installed — cannot create recovery copy. Install openssl and retry.": "OpenSSL ist nicht installiert – Wiederherstellungskopie kann nicht erstellt werden. Installieren Sie OpenSSL und versuchen Sie es erneut.", + "optional": "fakultativ", + "optional dependencies are not yet supported": "Optionale Abhängigkeiten werden noch nicht unterstützt", "or format it manually using external tools.": "oder formatieren Sie es manuell mit externen Tools.", + "or none": "oder keine", "or use the ProxMenux LXC Mount Manager.": "oder verwenden Sie den ProxMenux LXC Mount Manager.", "orphan iface lines, no impact on restore": "Verwaiste Iface-Zeilen, keine Auswirkung auf die Wiederherstellung", "other .tar archive(s) — not ProxMenux host backups (e.g. PVE vzdump or unrelated tarballs).": "andere .tar-Archive – keine ProxMenux-Host-Backups (z. B. PVE vzdump oder nicht verwandte Tarballs).", "packages (this may take a few minutes)...": "Pakete (dies kann einige Minuten dauern)...", + "packages.": "Pakete.", "parent PF:": "Eltern-PF:", "partition(s). Partition table preserved.": "Partition(en). Partitionstabelle bleibt erhalten.", + "pasted Compose file": "Einfügen der Compose-Datei", "paths for next boot (/etc/pve, guests, drivers, ...)": "Pfade für den nächsten Start (/etc/pve, Gäste, Treiber, ...)", "pct exec authorization failed": "PCT-Exec-Autorisierung fehlgeschlagen", "pct push failed. Check log:": "PCT-Push fehlgeschlagen. Protokoll prüfen:", "pending (reboot required to enumerate full group)": "ausstehend (Neustart erforderlich, um die vollständige Gruppe aufzulisten)", + "phpMyAdmin is installed with arbitrary server connections enabled: the login page has a Server field where the address of the MySQL or MariaDB server is entered, together with its user and password.": "phpMyAdmin wird mit aktivierten beliebigen Serververbindungen installiert: Die Anmeldeseite hat ein Serverfeld, in dem die Adresse des MySQL- oder MariaDB-Servers zusammen mit seinem Benutzer und seinem Passwort eingegeben wird.", "pigz configuration completed": "Pigz-Konfiguration abgeschlossen", "pigz enabled in vzdump configuration": "pigz in der vzdump-Konfiguration aktiviert", "pigz installed successfully": "pigz erfolgreich installiert", "pigz removed": "Schweinchen entfernt", "pigz wrapper script created": "Pigz-Wrapper-Skript erstellt", + "playit.gg has to claim this agent before it forwards anything. The agent prints a one-time claim link on the container console and keeps it there until the link is opened.": "playit.gg muss diesen Agenten beanspruchen, bevor er etwas weiterleitet. Der Agent druckt einen einmaligen Claim-Link auf der Containerkonsole und behält ihn dort, bis der Link geöffnet ist.", "port": "Hafen", "portmapper/rpcbind has been disabled": "portmapper/rpcbind wurde deaktiviert", + "private network assigned automatically": "Privates Netzwerk automatisch zugewiesen", + "privileged LXC": "privilegierte LXC", "proxmox-backup-client reported:": "proxmox-backup-client berichtete:", "proxmox-boot-tool refreshed": "proxmox-boot-tool aktualisiert", "pve-enterprise.list update skipped (no change)": "pve-enterprise.list-Update übersprungen (keine Änderung)", @@ -5261,10 +7226,22 @@ "pvesm not found.": "pvesm nicht gefunden.", "pvesm path failed, trying manual detection...": "pvesm-Pfad fehlgeschlagen, manuelle Erkennung versucht ...", "pvesm status failed": "pvesm-Status fehlgeschlagen", + "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web.": "pyLoad ist ein Free- und Open Source-Download-Manager, der in Python geschrieben ist und extrem leicht, leicht erweiterbar und vollständig über das Web zu verwalten ist.", + "pyLoad web interface": "pyLoad Web Interface", + "qBittorrent WebUI password (user: admin)": "qBittorrent WebUI Passwort (Benutzer: admin)", + "qBittorrent already has a configuration; it is not overwritten": "qBittorrent hat bereits eine Konfiguration; es wird nicht überschrieben", + "qBittorrent configured": "qBittorrent konfiguriert", + "qBittorrent did not apply the category:": "qBittorrent hat die Kategorie nicht angewendet:", + "qBittorrent did not apply the download paths": "qBittorrent hat die Downloadpfade nicht angewendet", + "qBittorrent requires a non-empty password": "qBittorrent requires ein nicht leeres Passwort", + "qBittorrent: authenticated access to the preferences could not be verified": "qBittorrent: Der authentifizierte Zugriff auf die Präferenzen konnte nicht verifiziert werden", + "qBittorrent: invalid login response or missing session cookie": "qBittorrent: ungültige Anmeldeantwort oder fehlendes Sitzungscookie", "raw USB disk — no filesystem (will be FORMATTED)": "Raw-USB-Festplatte – kein Dateisystem (wird FORMATTIERT)", + "read-only": "Read-Only", "reboot-quick alias added": "reboot-quick-Alias ​​hinzugefügt", "reboot-quick alias is already configured": "reboot-quick Alias ​​ist bereits konfiguriert", "recommended": "empfohlen", + "recovering": "Rückgewinnung", "remapped users": "Benutzer neu zugeordnet", "remove the (now-empty) directory if possible": "Entfernen Sie nach Möglichkeit das (jetzt leere) Verzeichnis", "removed from Proxmox": "aus Proxmox entfernt", @@ -5280,11 +7257,14 @@ "rpcbind could not be disabled completely": "rpcbind konnte nicht vollständig deaktiviert werden", "rpcbind service and socket have been disabled and stopped": "rpcbind-Dienst und Socket wurden deaktiviert und gestoppt", "rpcbind units were not found; no changes were made": "rpcbind-Einheiten wurden nicht gefunden;Es wurden keine Änderungen vorgenommen", + "rsnapshot starts with the default configuration, which backs up /data into /.snapshots. Edit /config/rsnapshot.conf inside the container to set your own backup points, snapshot root and retention intervals.": "rsnapshot beginnt mit der Standardkonfiguration, die /data in /.snapshots sichert. Bearbeiten Sie /config/rsnapshot.conf im Container, um Ihre eigenen Backup-Punkte, Snapshot-Root und Retentionsintervalle festzulegen.", "running": "läuft", + "runs in": "läuft", "safe paths now (configs, packages, /etc, /root, ...)": "Jetzt sichere Pfade (Konfigurationen, Pakete, /etc, /root, ...)", "same MAC": "gleicher MAC", "seconds (default)": "Sekunden (Standard)", "see log:": "siehe Protokoll:", + "selected by default": "Standardmäßig ausgewählt", "selected path(s):": "ausgewählte(r) Pfad(e):", "server": "Server", "server IP or hostname:": "Server-IP oder Hostname:", @@ -5292,6 +7272,7 @@ "servers found on the network.": "im Netzwerk gefundene Server.", "servers found.": "Server gefunden.", "sha256sum not found. Cannot verify Borg binary.": "sha256sum nicht gefunden. Borg-Binärdatei kann nicht überprüft werden.", + "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++.": "shadPS4 ist ein früher PlayStation 4-Emulator für Windows, Linux und macOS, der in C++ geschrieben wurde.", "showmount command is not working properly.": "Der Befehl showmount funktioniert nicht ordnungsgemäß.", "showmount command not found after installation.": "Der Befehl „showmount“ wurde nach der Installation nicht gefunden.", "single portable archive": "einzelnes tragbares Archiv", @@ -5307,6 +7288,7 @@ "started successfully.": "erfolgreich gestartet.", "started.": "begonnen.", "startup/restart errors are likely.": "Start-/Neustartfehler sind wahrscheinlich.", + "staticfiles volume size in GB": "staticfiles Volumengröße in GB", "stop source VM first": "Stoppen Sie zuerst die Quell-VM", "stopped": "gestoppt", "storage yet.": "Speicher noch.", @@ -5316,9 +7298,16 @@ "suggested:": "empfohlen:", "switch_gpu_mode.sh was not found.": "switch_gpu_mode.sh wurde nicht gefunden.", "sysfs ROM dump failed — trying ACPI VFCT table...": "sysfs-ROM-Dump fehlgeschlagen – Versuch der ACPI-VFCT-Tabelle ...", + "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools.": "syslog-ng ermöglicht es Ihnen, Protokolle aus Ihrer gesamten Infrastruktur flexibel zu sammeln, zu analysieren, zu klassifizieren, neu zu schreiben und zu korrelieren und sie zu Protokollanalyse-Tools zu speichern oder zu leiten.", "systemctl restart networking failed:": "systemctl-Neustart des Netzwerks fehlgeschlagen:", "systemd OnCalendar expression": "systemd OnCalendar-Ausdruck", + "the API key was not generated on the first start": "Der API-Schlüssel wurde beim ersten Start nicht generiert", + "the container has its own address, so the port Docker published on the host is not needed": "der Container hat eine eigene Adresse, so dass der auf dem Host veröffentlichte Port Docker nicht benötigt wird", + "the qBittorrent schema is not available": "Das qBittorrent-Schema ist nicht verfügbar", + "this configuration needs the device": "Diese Konfiguration benötigt das Gerät", "this distribution": "diese Verteilung", + "tmpfs size in MB for": "tmpfs Größe in MB für", + "tmpfs size too small for": "tmpfs Größe zu klein für", "to": "Zu", "to CT": "zu CT", "to VM": "zu VM", @@ -5327,6 +7316,12 @@ "to sharedfiles group": "zur Sharedfiles-Gruppe", "total": "gesamt", "umount the path if currently mounted": "umount den Pfad, falls aktuell gemountet", + "unprivileged LXC": "unprivilegierte LXC", + "unsupported credential generator": "nicht unterstützter credential Generator", + "unsupported dependency condition": "nicht unterstützte Abhängigkeitsbedingung", + "unsupported external credential or boolean": "nicht unterstützte externe credential oder boolean", + "unsupported variable": "nicht unterstützte Variable", + "updating": "Aktualisierung", "updating NVIDIA userspace libs": "Aktualisieren der NVIDIA-Userspace-Bibliotheken", "user packages missing — will be installed automatically:": "Benutzerpakete fehlen – werden automatisch installiert:", "users": "Benutzer", @@ -5337,12 +7332,19 @@ "vfio-pci IDs configured": "vfio-pci-IDs konfiguriert", "vfio-pci IDs in /etc/modprobe.d/vfio.conf": "vfio-pci-IDs in /etc/modprobe.d/vfio.conf", "vzdump backup speed optimization completed": "vzdump-Backup-Geschwindigkeitsoptimierung abgeschlossen", + "wallabag builds its links from the address given during the installation. If it does not match the address of the container, edit lxc.environment.runtime: SYMFONY__ENV__DOMAIN_NAME in /etc/pve/lxc/.conf with the container stopped, and start it again.": "wallabag baut seine Links aus der während der Installation angegebenen Adresse auf. Wenn es nicht mit der Adresse des Containers übereinstimmt, bearbeiten Sie lxc.environment. Laufzeit: SYMFONY ENV DOMAIN NAME in /etc/pve/lxc/.conf mit angehaltenem Container und erneut starten.", + "wallabag listens on port 80 of the container and stores its data in SQLite.": "wallabag hört auf Port 80 des Containers und speichert seine Daten in SQLite.", + "wallabag web interface": "wallabag Web-Schnittstelle", "was": "war", "was installed, but the kernel reports:": "wurde installiert, aber der Kernel meldet:", + "when finished": "wenn fertig", "will rebind the GPU to vfio-pci on the next reboot, breaking the driver that is about to be installed.": "Bindet die GPU beim nächsten Neustart erneut an vfio-pci, wodurch der zu installierende Treiber beschädigt wird.", "wipefs failed on": "Wipefs sind fehlgeschlagen", "with": "mit", + "with Proxmox": "mit Proxmox", + "with prefix, e.g.": "mit Präfix, z. B.", "with the password you provided.": "mit dem von Ihnen angegebenen Passwort.", + "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems.": "xemu ist eine kostenlose Open-Source-Anwendung, die die ursprüngliche Microsoft Xbox-Spielkonsole emuliert und es Benutzern ermöglicht, ihre ursprünglichen Xbox-Spiele auf Windows-, macOS- und Linux-Systemen zu spielen.", "xfs — Proxmox dir storage (large files and VMs)": "xfs – Proxmox-Verzeichnisspeicher (große Dateien und VMs)", "xfs — better for large files": "xfs – besser für große Dateien", "years old": "Jahre alt", diff --git a/lang/es.json b/lang/es.json index cc01c999..02ef53e6 100644 --- a/lang/es.json +++ b/lang/es.json @@ -7,6 +7,7 @@ "(common default on Debian/LXC: PermitRootLogin prohibit-password).": "(valor predeterminado habitual en Debian/LXC: PermitRootLogin prohibit-password).", "(disabled)": "(deshabilitado)", "(e.g.": "(por ej.", + "(empty)": "(vacío)", "(for unprivileged LXCs)": "(para LXC sin privilegios)", "(if only privileged LXCs need write access)": "(si solo los LXC privilegiados necesitan acceso de escritura)", "(make.log not found — DKMS may have failed before invoking make)": "(make.log no encontrado; es posible que DKMS haya fallado antes de invocar make)", @@ -19,6 +20,7 @@ "(recommended)": "(recomendado)", "(same MAC — restored config adjusted automatically)": "(misma MAC: configuración restaurada ajustada automáticamente)", ")": ")", + "*Arr Suite": "*Arr Suite", "+ Add a path": "+ Agregar una ruta", "+ Add new Borg target": "+ Agregar nuevo objetivo Borg", "+ Add new PBS manually": "+ Agregar nuevo PBS manualmente", @@ -35,39 +37,101 @@ "/var/lib/vz/dump (Proxmox default)": "/var/lib/vz/dump (predeterminado de Proxmox)", "1777 = sticky bit + rwx for all. No shared group needed.": "1777 = sticky bit + rwx para todos. No se necesita un grupo compartido.", "====== PVE UPDATE COMPLETED ======": "====== ACTUALIZACIÓN PVE COMPLETADA ======", + "A Personal Relationship Management tool to help you document your social life.": "Una relación personal Herramienta de gestión para ayudarte a documentar tu vida social.", "A VirtIO ISO already exists. Do you want to overwrite it?": "Ya existe una ISO VirtIO. ¿Quieres sobrescribirla?", "A ZFS pool with this name already exists.": "Ya existe un grupo ZFS con este nombre.", "A ZFS pool with this name already exists:": "Ya existe un grupo ZFS con este nombre:", + "A backup was modified": "Un backup fue modificado", + "A command did not finish in time:": "Un comando no terminó en el tiempo:", "A complete restore will:": "Una restauración completa:", + "A concurrent change was detected; the container is not removed": "Se detectó un cambio simultáneo; el contenedor no se retira", + "A container mount has a source, backup or permission different from the saved record": "Un contenedor de montaje tiene una fuente, backup o permiso diferente del registro guardado", + "A coordinated operation is pending. The whole previous stack will be recovered, not only the selected member. If the operation already finished, the cleanup of its markers is completed.": "Está pendiente una operación coordinada. Toda la pila anterior se recuperará, no sólo el miembro seleccionado. Si la operación ya terminó, se completa la limpieza de sus marcadores.", + "A different host monitor include already exists; it is not overwritten:": "Un monitor de host diferente incluye ya existe; no está sobrescrito:", + "A fancy monitoring tool": "Una herramienta de monitoreo elegante", + "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata.": "Un programa de bases de datos de código abierto y libre. Clasificado como un programa de bases de datos NoSQL, MongoDB utiliza documentos similares a JSON con schemata.", + "A free reverse proxy for tunneling services (not self-hosted).": "Un proxy reverso libre para los servicios de túneles (no auto hospedado).", + "A free, self-hostable news aggregator…": "Un agregador de noticias libre y auto-hostable...", + "A full-featured, open-source AI chat interface": "Una interfaz de chat de código abierto y completo", "A gasket DKMS registration is still present:": "Todavía existe un registro de gasket en DKMS:", + "A host bind mount cannot be included in vzdump": "Un bind mount del host no se puede incluir en vzdump", + "A host mount is not part of the journal; recovery blocked": "Un montaje host no es parte de la revista; recuperación bloqueada", "A host reboot is required after this change.": "Es necesario reiniciar el host después de este cambio.", "A host reboot is required before starting the VM. Reboot now?": "Es necesario reiniciar el host antes de iniciar la VM. ¿Reiniciar ahora?", "A job with this ID already exists.": "Ya existe un trabajo con este ID.", + "A journal already exists; review or recover it before trying again": "Ya existe una revista; revisarla o recuperarla antes de intentarlo de nuevo", "A keyfile is installed at:": "un archivo de claves está instalado en:", "A legacy gasket-dkms package was found on this host, but no Coral M.2 / PCIe hardware is present.": "Se ha encontrado un paquete heredado gasket-dkms en este host, pero no hay ningún dispositivo Coral M.2/PCIe.", + "A managed rootfs and an unprivileged container are required": "Un rootf gestionado y un contenedor no privilegiado son necesarios", + "A managed volume with backup enabled is required": "Un volumen gestionado con backup habilitado es necesario", + "A member VMID is in use by another guest or is on another node": "Un miembro VMID está en uso por otro invitado o está en otro nodo", + "A member configuration changed after the stack was checked": "Una configuración de miembro cambió después de la comprobación de la pila", + "A member configuration changed during the preparation": "Una configuración de miembro cambió durante la preparación", + "A member did not pass its service check:": "Un miembro no aprobó su cheque de servicio:", + "A member has a pending operation": "Un miembro tiene una operación pendiente", + "A member has no reproducible service check": "Un miembro no tiene control de servicio reproducible", + "A member is missing before the replacement": "Falta un miembro antes de la sustitución", + "A member operation does not belong to the stack": "Una operación de miembro no pertenece a la pila", + "A member stopped:": "Un miembro se detuvo:", + "A member was modified after it was recovered": "Un miembro fue modificado después de su recuperación", + "A modern wiki and knowledge base for teams": "Una moderna wiki y base de conocimientos para los equipos", "A new ProxMenux version is available:": "Una nueva versión de ProxMenux está disponible:", "A new kernel is staged for the next boot:": "Se prepara un nuevo kernel para el siguiente arranque:", "A newer version is available:": "Hay una versión más nueva disponible:", + "A pending operation exists for": "Existe una operación pendiente", + "A pending stack assembly already exists; it is not overwritten": "Ya existe un montaje de pila pendiente; no está sobrescrito", + "A previous NVIDIA refresh is pending review": "Un refresco previo de NVIDIA está pendiente de revisión", "A previous VFIO passthrough configuration was detected for the following NVIDIA GPU(s):": "Se detectó una configuración de paso a través de VFIO anterior para las siguientes GPU NVIDIA:", + "A privacy-first, open-source platform for knowledge management and collaboration.": "Una plataforma de código abierto para la gestión del conocimiento y la colaboración.", "A reboot is recommended before the GPU is guaranteed to stay on the native driver.": "se recomienda reiniciar antes de garantizar que la GPU permanezca en el controlador nativo.", "A reboot is required after installation to load the new kernel modules.": "Es necesario reiniciar después de la instalación para cargar los nuevos módulos del kernel.", "A reboot is required for VFIO binding to take effect. Do you want to restart now?": "Es necesario reiniciar para que la vinculación de VFIO surta efecto. ¿Quieres reiniciar ahora?", "A reboot is required to apply the new GPU mode. Do you want to restart now?": "Es necesario reiniciar para aplicar el nuevo modo GPU. ¿Quieres reiniciar ahora?", "A reboot is required to finish the restore.": "es necesario reiniciar para finalizar la restauración.", "A reboot will be required to complete the restore.": "será necesario reiniciar para completar la restauración.", + "A reproducible native startup is missing": "Falta una startup nativa reproducible", + "A rootfs adaptation is stored in persistent storage": "Una adaptación de rootfs se almacena en almacenamiento persistente", + "A self-hosted Bitwarden server": "Un servidor Bitwarden auto hospedado", + "A self-hosted, goal-free habit tracking tool.": "Una herramienta de seguimiento de hábitos sin objetivos.", + "A self-improving AI agent with memory, skills, messaging, and a web dashboard.": "Un agente de IA auto-improbando con memoria, habilidades, mensajería y un panel web.", "A server reboot is recommended for all changes to take full effect.": "Se recomienda reiniciar el servidor para que todos los cambios surtan efecto.", + "A shared directory was replaced during the installation": "Un directorio compartido fue reemplazado durante la instalación", + "A shared source does not match its recorded identity": "Una fuente compartida no coincide con su identidad registrada", + "A simple, open-source file sharing host.": "Un host compartido de archivos de código abierto.", + "A simple, private file server.": "Un servidor de archivos simple y privado.", + "A single matching image platform cannot be resolved": "Una única plataforma de imagen que coincide no se puede resolver", + "A single-platform OCI archive is required": "Un archivo OCI de formato único es necesario", + "A stack backup is missing; a partial restore is not allowed": "Falta un backup de pila; no se permite una restauración parcial", + "A stack member has a different identity": "Un miembro de pila tiene una identidad diferente", "A system reboot is recommended to ensure all changes take effect.": "Se recomienda reiniciar el sistema para garantizar que todos los cambios surtan efecto.", + "A third party companion app available to Plex server owners to allow their users to request, review and discover content.": "Una aplicación compañera de terceros disponible para los propietarios de servidores Plex para permitir a sus usuarios solicitar, revisar y descubrir contenido.", + "A third-party client for self-hosted server and self-hosted server, remote access management interface, remote access to installed applications.": "Un cliente de terceros para servidor auto hospedado y servidor auto hospedado, interfaz de gestión de acceso remoto, acceso remoto a aplicaciones instaladas.", + "A tmpfs mount is not part of the journal; recovery blocked": "Un montaje de tmpfs no es parte de la revista; recuperación bloqueada", + "A tmpfs mount overlaps another mount": "Un montaje de tmpfs superpone otro montaje", + "A tunneling daemon by Cloudflare that safely exposes your web servers into the internet.": "Un daemon de túnel por Cloudflare que expone con seguridad sus servidores web en Internet.", + "A versatile file conversion tool that supports multiple formats.": "Una herramienta de conversión de archivos versátil que soporta múltiples formatos.", + "A web GUI client of Project V which supports VMess, VLESS, SS, SSR, Trojan, Tuic and Juicity protocols": "Un cliente web GUI del Proyecto V que soporta los protocolos VMess, VLESS, SS, SSR, Trojan, Tuic y Juicity", + "A web app to listen Youtube audio source.": "Una aplicación web para escuchar la fuente de audio de Youtube.", + "A web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes": "Una aplicación web para administrar sus cuentas de autenticación de dos factores (2FA) y generar sus códigos de seguridad", + "A web frontend for the motion daemon.": "Un frontend web para el daemon de movimiento.", + "A web-based file sharing and management protocol": "Un protocolo de intercambio de archivos y gestión basado en la web", + "A well-designed cross-platform ChatGPT UI.": "Un ChatGPT UI bien diseñado.", "ACL Status:": "Estado de ACL:", "ACL permissions applied for local access for user:": "Permisos ACL aplicados para el acceso local del usuario:", "ADVANCED SETTINGS COMPLETE": "CONFIGURACIÓN AVANZADA COMPLETA", + "AI / Coding & Dev-Tools": "AI / Coding " Dev-Tools", "ALL DATA ON": "TODOS LOS DATOS SOBRE", "ALL DATA ON THIS DISK WILL BE PERMANENTLY LOST!": "¡TODOS LOS DATOS DE ESTE DISCO SE PERDERÁN PERMANENTEMENTE!", "ALL Utilities": "TODAS las utilidades", + "ALLOWED_HOSTS cannot contain line breaks": "ALLOWED_HOSTS no puede contener saltos de línea", + "AList initial login": "Primera sesión de AList", "AMD CPU detected": "CPU AMD detectada", "AMD CPU fixes applied successfully": "Las correcciones de CPU AMD se aplicaron con éxito", "AMD GPU Tools installation completed!": "¡Se completó la instalación de las herramientas AMD GPU!", "AMD GPU passthrough configured.": "Paso a través de GPU AMD configurado.", "AMD GPU(s) detected:": "GPU AMD detectadas:", + "AMD KFD device": "dispositivo AMD KFD", + "AMD VA-API + OpenCL (official mod)": "AMD VA-API + OpenCL (modal oficial)", "AMD fixes have been successfully reverted": "Las correcciones de AMD se han revertido con éxito", "AMD mesa drivers installed.": "Controladores Mesa de AMD instalados.", "AMD softdep configured": "AMD softdep configurado", @@ -93,9 +157,21 @@ "About to restore": "A punto de restaurar", "Absolute directory path to use as backup target:": "Ruta absoluta del directorio para usar como destino de la copia de seguridad:", "Absolute path to a file or directory you want backed up:": "ruta absoluta a un archivo o directorio del que desea realizar una copia de seguridad:", + "Acceleration": "Aceleración", + "Acceleration configuration cancelled": "Configuración de aceleración cancelada", + "Acceleration for CodeProject.AI": "Aceleración para CodeProject. AI", + "Acceleration for Immich smart recognition": "Aceleración para el reconocimiento inteligente Immich", + "Acceleration for Ollama": "Aceleración para Ollama", "Accept routes from other nodes?": "¿Aceptar rutas de otros nodos?", + "Accept this host monitoring profile?": "¿Aceptar este perfil de monitorización del host?", "Access Scope:": "Ámbito de acceso:", + "Access bridge": "Puente de acceso", + "Access bridge for Immich": "Puente de acceso para Immich", + "Access bridge for Nextcloud": "Puente de acceso para Nextcloud", + "Access bridge for Paperless": "Puente de acceso para Paperless", + "Access bridge for Tandoor": "Puente de acceso para Tandoor", "Access profile:": "Perfil de acceso:", + "Access token of the Jupyter Lab web interface": "Acceso a la ficha de la interfaz web Jupyter Lab", "Account is not locked": "La cuenta no está bloqueada", "Action cancelled due to previous xshok-proxmox modifications.": "Acción cancelada debido a modificaciones anteriores de xshok-proxmox.", "Action:": "Acción:", @@ -105,6 +181,10 @@ "Active Connections": "Conexiones activas", "Active exports:": "Exportaciones activas:", "Active session:": "Sesión activa:", + "Actual device path on the host": "Vía de dispositivo real en el host", + "Adaptation file too large": "Archivo de adaptación demasiado grande", + "Adaptation file with unexpected permissions or owner": "Archivo de adaptación con permisos inesperados o propietario", + "Adblock & DNS": "Adblock " DNS", "Add Audio Passthrough": "Agregar transferencia de audio", "Add CIFS storage:": "Agregue almacenamiento CIFS:", "Add Controller or NVMe (PCI passthrough)": "Agregar controlador o NVMe (paso PCI)", @@ -123,6 +203,9 @@ "Add PBS": "Agregar PBS", "Add Samba Share as Proxmox Storage": "Agregar recurso compartido Samba como almacenamiento de Proxmox", "Add Samba share as Proxmox Storage": "Agregue el recurso compartido Samba como almacenamiento Proxmox", + "Add a Coral PCIe/M.2 device?": "¿Añada un dispositivo Coral PCIe/M.2?", + "Add a custom data path?": "¿Añadir una ruta de datos personalizada?", + "Add an extra custom path": "Añadir una ruta personalizada adicional", "Add as IDE": "Agregar como IDE", "Add as SATA": "Agregar como SATA", "Add as SCSI": "Agregar como SCSI", @@ -140,6 +223,7 @@ "Add import disk": "Agregar disco de importación", "Add latest Ceph support": "Añadir soporte para la última versión de Ceph", "Add new PVE 9 enterprise repository (deb822 format) (Only if using enterprise):": "Agregue un nuevo repositorio empresarial PVE 9 (formato deb822) (solo si usa Enterprise):", + "Add or change a device": "Agregar o cambiar un dispositivo", "Add physical disk to VM via": "Agregue el disco físico a la VM mediante", "Add share block in /etc/samba/smb.conf:": "Agregue el bloque para compartir en /etc/samba/smb.conf:", "Add unprivileged flag to container configuration:": "Agregar la opción de contenedor sin privilegios a su configuración:", @@ -154,20 +238,34 @@ "Adding": "Añadiendo", "Adding CIFS storage to Proxmox...": "Agregando almacenamiento CIFS a Proxmox...", "Adding QEMU Guest Agent support...": "Agregando soporte para el agente invitado QEMU...", + "Adding Radarr to Prowlarr...": "Añadiendo Radarr a Prowlarr...", + "Adding Sonarr to Prowlarr...": "Añadiendo Sonarr a Prowlarr...", "Adding disk using the generated command to the selected VM": "Agregar disco usando el comando generado a la VM seleccionada", "Adding existing users to sharedfiles group...": "Agregando usuarios existentes al grupo de archivos compartidos...", "Adding iSCSI storage to Proxmox...": "Agregando almacenamiento iSCSI a Proxmox...", "Adding new share to smb.conf...": "Agregando un nuevo recurso compartido a smb.conf...", + "Adding peers later means raising PEERS in /etc/pve/lxc/.conf and restarting the container. The existing peer keys are kept.": "Añadiendo pares más tarde significa elevar PEERS en /etc/pve/lxc/Seguido CTID confiar.conf y reiniciar el contenedor. Se guardan las llaves existentes.", + "Adding the mount points...": "Añadiendo los puntos de montaje...", "Adding this NVMe as a PCIe device (via 'Add Controller or NVMe PCIe to VM') gives better performance.": "Agregar este NVMe como dispositivo PCIe (a través de \"Agregar controlador o NVMe PCIe a VM\") proporciona un mejor rendimiento.", "Adding to /etc/fstab for permanent mounting...": "Agregando a /etc/fstab para montaje permanente...", + "Additional URL advertised by Plex (optional)": "URL adicional anunciado por Plex (opcional)", "Additional audio function(s) to be added": "Funciones de audio adicionales que se agregarán", + "Additional media/GPU GIDs, comma-separated": "GID de medios/GPU adicionales, separados por coma", + "Additional paths for": "Rutas adicionales para", + "Addresses to update: ipv4, ipv6 or both (uses an external service)": "Direcciones para actualizar: ipv4, ipv6 o ambos (utiliza un servicio externo)", + "Adguardhome Sync web interface": "Interfaz web Adguardhome Sync", + "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances.": "Adguardhome-sync es una herramienta para sincronizar AdGuardHome config a replicar instancias.", "Adjust network/CIDR to your environment.": "Ajuste la red/CIDR a su entorno.", "Adjust options if needed (vers=4,hard,timeo,...).": "Ajuste las opciones si es necesario (vers=4,hard,timeo,...).", "Adjusting systemd-journald limits to match Log2RAM size...": "Ajustando los límites de systemd-journald para que coincidan con el tamaño de Log2RAM...", "Adjusts journald log level if needed (Proxmox defaults may block auth logs)": "Ajusta el nivel de registro de journald si es necesario (los valores predeterminados de Proxmox pueden bloquear los registros de autenticación)", + "Admin page": "Página", + "Administrator email": "Correo del administrador", + "Administrator password, at least 12 characters (empty = generated)": "contraseña de administrador, al menos 12 caracteres (vacío = generado)", "Advanced": "Avanzado", "Advanced Diagnostics": "Diagnóstico de red", "Advanced Network Diagnostics": "Diagnóstico de red avanzado", + "Advanced: every setting of the container": "Avanzado: cada configuración del contenedor", "Affected LXC containers": "Contenedores LXC afectados", "After completing GPU setup, start the VM manually when the host is ready.": "Después de completar la configuración de la GPU, inicie la VM manualmente cuando el host esté listo.", "After confirming, you will be asked to choose the NVIDIA driver version to install.": "Después de confirmar, se le pedirá que elija la versión del controlador NVIDIA para instalar.", @@ -183,11 +281,15 @@ "After the reboot you can follow the post-restore work live from ProxMenux Monitor → Backups tab (estimated time, per-component status, log tail, rollback delta).": "Después del reinicio, puede seguir en tiempo real el trabajo posterior a la restauración desde ProxMenux Monitor → pestaña Copias de seguridad (tiempo estimado, estado por componente, últimas líneas del registro y cambios pendientes de revertir).", "After the reboot, you will only be able to access the Proxmox host via:": "Después del reinicio, solo podrá acceder al host Proxmox a través de:", "After this LXC → VM switch, reboot the host so the new binding state is applied cleanly.": "Después de este cambio LXC → VM, reinicie el host para que el nuevo estado de enlace se aplique limpiamente.", + "Airsonic Advanced web interface": "Interfaz web Airsonic Advanced", + "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room.": "Airsonic-advanced es un streamer de medios gratuito, basado en web, que proporciona acceso ubiquitious a su música. Úsalo para compartir tu música con tus amigos, o para escuchar tu propia música mientras trabajas. Usted puede transmitir a varios jugadores simultáneamente, por ejemplo a un jugador en su cocina y otro en su salón.", "Aliases added to .bashrc": "Alias ​​agregados a .bashrc", + "Alist Sync web interface": "Alist interfaz web Sync", "All": "Todos", "All Available Scripts": "Todos los scripts disponibles", "All GPUs Already Assigned": "Todas las GPU ya asignadas", "All ProxMenux optimizations are up to date.": "Todas las optimizaciones de ProxMenux están actualizadas.", + "All applications": "Todas las aplicaciones", "All block devices:": "Todos los dispositivos de bloque:", "All changes applied. No reboot required.": "Todos los cambios aplicados. No es necesario reiniciar.", "All changes are reversible using the ProxMenux uninstaller.": "Todos los cambios son reversibles utilizando el desinstalador ProxMenux.", @@ -195,43 +297,79 @@ "All detected GPUs are already assigned to this VM.": "Todas las GPU detectadas ya están asignadas a esta VM.", "All detected controllers/NVMe are already present in the selected VM.": "Todos los controladores/NVMe detectados ya están presentes en la VM seleccionada.", "All disks may already be in use or mounted.": "Es posible que todos los discos ya estén en uso o montados.", + "All images are downloaded and verified first, and native backups are taken with the stack stopped. Contracts are published after the whole set is checked. If anything fails, all members are recovered.": "Todas las imágenes se descargan y verifican primero, y los backups nativos se toman con la pila parada. Los contratos se publican después de que se revise todo el conjunto. Si algo falla, todos los miembros se recuperan.", "All images imported and configured successfully": "Todas las imágenes importadas y configuradas correctamente.", "All imports failed": "Todas las importaciones fallaron", + "All of them are removed.": "Todos son eliminados.", "All partitions and metadata removed.": "Se eliminaron todas las particiones y metadatos.", "All physical interfaces from backup are present on target": "Todas las interfaces físicas de la copia de seguridad están presentes en el objetivo", + "All stack members are updated together. Main CT:": "Todos los miembros de la pila se actualizan juntos. CT principal:", "All types (images, backup, iso, vztmpl, snippets)": "Todo tipo (imágenes, copias de seguridad, iso, vztmpl, fragmentos)", "All user-installed packages from the backup are present on this host": "todos los paquetes instalados por el usuario desde la copia de seguridad están presentes en este host", "All users with UID and GID": "Todos los usuarios con UID y GID", "Allocate CPU Cores": "Asignar núcleos de CPU", "Allocate RAM in MiB": "Asignar RAM en MiB", + "Allowed hosts (comma separated; * allows access through the assigned IP)": "Hosts permitidos (separados por comas; * permite el acceso a través de la IP asignada)", "Already Mounted": "Ya montado", "Already configured": "Ya configurado", "Already installed — skipping": "Ya instalado - omitiendo", + "Also add the /dev/srX optical device (recommended)": "También agregue el dispositivo óptico /dev/srX (recomendado)", "Also comment any remaining 'bookworm' entries in *.list if present.": "Comente también cualquier entrada de 'bookworm' que aún exista en los archivos *.list.", "Also install the VirtIO network driver during setup to enable network access.": "Instale también el controlador de red VirtIO durante la configuración para permitir el acceso a la red.", "Although VFIO can bind to this device, full passthrough to a VM is": "Aunque VFIO puede vincularse a este dispositivo, se requiere transferencia completa a una VM.", + "Altus is an Electron-based WhatsApp client with themes and multiple account support.": "Altus es un cliente de WhatsApp basado en electrones con temas y soporte de cuenta múltiple.", + "Ambiguous mount points in the container": "Puntos de montaje ambiguos en el contenedor", + "Ambiguous or invalid environment variable": "Variable de entorno ambiguo o inválido", "Amount of RAM in MiB (default: 4096)": "Cantidad de RAM en MiB (predeterminado: 4096)", + "An AI model used to generate images conditioned on text descriptions.": "Un modelo AI utilizado para generar imágenes condicionadas a descripciones de texto.", "An AMD dedicated GPU has been detected without FLR support": "Se ha detectado una GPU dedicada de AMD sin soporte FLR", "An AMD integrated GPU (APU) has been detected": "Se ha detectado una GPU (APU) integrada de AMD", + "An Alist storage synchronization tool based on the Web interface.": "Una herramienta de sincronización de almacenamiento Alist basado en la interfaz web.", + "An Industrial-Level Controllable and Efficient Zero-Shot Text-To-Speech System": "Un sistema de control de nivel industrial y eficiente de tipo cero", "An Intel dedicated GPU has been detected without FLR support": "Se ha detectado una GPU dedicada de Intel sin soporte FLR", + "An accelerated video generation framework that speeds up end-to-end diffusion while preserving video quality": "Un marco de generación de vídeo acelerado que acelera la difusión de extremo a extremo preservando la calidad de vídeo", + "An executable required by the adapter is missing in the new image": "Un ejecutable necesario para el adaptador falta en la nueva imagen", "An fstab entry already exists for:": "Ya existe una entrada fstab para:", + "An image probe container was started externally": "Un contenedor de sonda de imagen se inició externamente", + "An include is not part of the journal; recovery blocked": "Una inclusión no es parte de la revista; recuperación bloqueada", + "An include was modified outside the journal; recovery blocked": "Una incluye fue modificada fuera de la revista; recuperación bloqueada", + "An open source generative AI development platform for building AI Agents and LLM workflows": "Una plataforma de desarrollo de AI generativa de código abierto para la construcción de agentes AI y flujos de trabajo LLM", + "An operation of this installation has not finished; recover it from the management menu before removing it": "Una operación de esta instalación no ha terminado; recuperarla del menú de gestión antes de eliminarla", + "An update does not accept configuration changes": "Una actualización no acepta cambios de configuración", "Analysis Tools": "Herramientas de análisis", + "Analysis software that shows your internet speed for up to 30 days.": "Software de análisis que muestra su velocidad de Internet por hasta 30 días.", "Analyze Bridge Configuration": "Analizar la configuración del puente", "Analyze Network Configuration": "Analizar la configuración de la red", "Analyzing Bridge Configuration - READ ONLY MODE": "Analizando la configuración del puente — MODO DE SOLO LECTURA", "Analyzing Network Configuration - READ ONLY MODE": "Analizando la configuración de red — MODO DE SOLO LECTURA", "Analyzing selected disks...": "Analizando discos seleccionados...", "Analyzing system for available PCIe storage devices...": "Analizando el sistema para dispositivos de almacenamiento PCIe disponibles...", + "Another OCI operation is using the instance registry": "Otra operación OCI está utilizando el registro de instancias", + "Another OCI operation is using the instance registry. Wait for it to finish and open this menu again; no container is modified.": "Otra operación OCI está utilizando el registro de instancias. Espere a que termine y abra este menú de nuevo; no se modifica ningún contenedor.", + "Another OCI operation is using the registry. This operation was not started.": "Otro operación OCI está utilizando el registro. Esta operación no se inició.", + "Another instance uses": "Otro caso utiliza", + "Another stack operation is pending": "Otra pila operación está pendiente", + "Application": "Aplicación", + "Application responding:": "Solicitud de respuesta:", + "Application responding; checking its stability...": "Aplicación respondiendo; comprobando su estabilidad...", + "Application suite: one independent LXC per selected application": "Suite de aplicación: un LXC independiente por aplicación seleccionada", + "Application:": "Aplicación:", + "Applications you can choose:": "Aplicaciones que puede elegir:", "Apply": "Aplicar", "Apply AMD CPU fixes": "Aplicar correcciones para CPU AMD", "Apply Available Updates": "Aplicar actualizaciones disponibles", "Apply and restart services:": "Aplicar y reiniciar servicios:", "Apply available updates": "Aplicar actualizaciones disponibles", "Apply boot/initramfs changes": "Aplicar cambios de arranque/initramfs", + "Apply configuration": "Aplicar la configuración", "Apply fix now?": "¿Aplicar corrección ahora?", "Apply fix now? (The share will be briefly remounted)": "¿Aplicar la corrección ahora? (El recurso compartido se volverá a montar brevemente)", "Apply network optimizations": "Aplicar optimizaciones de red", + "Apply optional security relaxation apparmor:rootlesskit": "Apply opcional security relax apparmor:rootlesskit", + "Apply optional security relaxation apparmor:unconfined": "Apply opcional security relax apparmor:unconfined", + "Apply optional security relaxation seccomp:unconfined": "Aplicar seccomp de relajación de seguridad opcional:unconfined", "Apply read+write access for 'others' on the host directory?": "¿Aplicar acceso de lectura+escritura para 'otros' en el directorio de host?", + "Apply the options from the current catalog template? Your data and configuration are kept.": "¿Aplicar las opciones de la plantilla actual del catálogo? Sus datos y su configuración se mantienen.", "Applying AMD-specific fixes...": "Aplicando correcciones específicas de AMD...", "Applying Changes": "Aplicar cambios", "Applying Controller/NVMe passthrough to VM": "Aplicación del paso directo del controlador/NVMe a la VM", @@ -244,12 +382,21 @@ "Applying passthrough to CT": "Aplicar paso a CT", "Applying safe paths and preparing pending restore": "Aplicar rutas seguras y preparar la restauración pendiente", "Applying selected LXC switch action": "Aplicando la acción seleccionada para cambiar el modo del LXC", + "Applying the Jellyfin configuration:": "Aplicando la configuración Jellyfin:", + "Applying the LAN address to the application URLs...": "Aplicar la dirección LAN a las URL de la aplicación...", + "Applying the initial Nextcloud settings...": "Aplicando la configuración inicial de Nextcloud...", + "Applying the mount mode...": "Aplicando el modo de montaje...", + "Apprise-api Takes advantage of Apprise through your network with a user-friendly API.": "Apprise-api Aprovecha la aplicación a través de su red con una API fácil de usar.", + "Architecture": "Arquitectura", + "Architecture:": "Arquitectura:", + "Architectures": "Arquitecturas", "Archive deleted.": "Archivo eliminado.", "Archive extracted.": "Archivo extraído.", "Archive format": "Formato de archivo", "Archive ready": "Archivo listo", "Archive size:": "Tamaño del archivo:", "Archive:": "Archivo:", + "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers.": "Ardour es una fuente abierta y colaborativa de un equipo mundial, incluyendo músicos, programadores y ingenieros de grabación profesionales.", "Are you absolutely sure?": "¿Estás absolutamente seguro?", "Are you sure you want to continue?": "¿Estás seguro de que quieres continuar?", "Are you sure you want to delete this export?": "¿Está seguro de que desea eliminar esta exportación?", @@ -261,6 +408,7 @@ "Are you sure you want to unmount this NFS share?": "¿Está seguro de que desea desmontar este recurso compartido NFS?", "Are you sure you want to unmount this Samba share?": "¿Estás seguro de que quieres desmontar este recurso compartido de Samba?", "Are you sure?": "¿Está seguro?", + "Arr suite: applications to install": "Suite Arr: aplicaciones a instalar", "As Proxmox storage": "Como almacenamiento Proxmox", "As host fstab mount only": "Solo como montaje de host fstab", "Assign GPU PCI function to VM": "Asignar función PCI de GPU a VM", @@ -275,14 +423,19 @@ "Attach imported disk to VM": "Adjunte el disco importado a la VM", "Attach to an existing PVE vzdump job (inherit schedule + retention)": "Adjuntar a un trabajo PVE vzdump existente (heredar programación + retención)", "Attached to PVE job:": "Adjunto al trabajo PVE:", + "Attaching the volumes...": "Adjuntar los volúmenes...", "Attempting automatic repair...": "Intentando reparación automática...", "Attempting passthrough with this GPU typically results in": "Intentar la transferencia con esta GPU generalmente resulta en", "Attention: Removing the subscription banner may cause issues in the web interface after a future update.": "Atención: Eliminar el banner de suscripción puede causar problemas en la interfaz web después de una actualización futura.", + "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source.": "Audacity es un editor y grabador de audio de fácil uso. Desarrollado por un grupo de voluntarios como fuente abierta.", + "Audio device directory": "Directorio de dispositivos de audio", + "Audiobookshelf is a self-hosted audiobook and podcast server.": "Audiobookshelf es un servidor de audiolibros y podcast.", "Audit completed. Press Enter to continue...": "Auditoría completada. Presione Entrar para continuar...", "Audit socket disabled or not required": "Socket de auditoría deshabilitado o no requerido", "Auth key is required.": "Se requiere clave de autenticación.", "Auth:": "Autenticación:", "Authentication": "Autenticación", + "Authentication & Security": "Autenticación " Seguridad", "Authentication Error": "Error de autenticación", "Authentication failed.": "La autenticación falló.", "Authentication required:": "Se requiere autenticación:", @@ -301,7 +454,12 @@ "Auto-sync was not enabled": "La sincronización automática no estaba habilitada", "Automated Post-Install Script": "Script automático Post-Install", "Automated post-installation script": "Script automático Post-Install", + "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Administrador automático de Videoteca para programas de televisión. Observa nuevos episodios de tus programas favoritos, y cuando son publicados hace su magia.", + "Automatic detection": "Detección automática", + "Automatic private network allocation requires a /24 subnet": "Asignación automática de red privada requiere una subred /24", + "Automatic video library manager for TV Shows": "Gestor automático de la biblioteca de vídeo para TV Shows", "Automatic/Unattended": "Automático/desatendido", + "Automation & Scheduling": "Planificación de la automatización", "Available": "Disponible", "Available Borg archives (newest first):": "Archivos Borg disponibles (los más nuevos primero):", "Available Borg targets:": "Objetivos Borg disponibles:", @@ -322,17 +480,23 @@ "Available space in /mnt:": "Espacio disponible en /mnt:", "Available storage information:": "Información de almacenamiento disponible:", "Available storage volumes:": "Volúmenes de almacenamiento disponibles:", + "Azahar is an open-source 3DS emulator based on Citra.": "Azahar es un emulador de 3DS de código abierto basado en Citra.", "BIOS TYPE": "TIPO DE BIOS", "BIOS Type": "Tipo de BIOS", "BIOS from": "BIOS de", "BIOS: OVMF (UEFI)": "BIOS: OVMF (UEFI)", + "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications.": "BOINC es una plataforma para la computación de alto rendimiento a gran escala (miles o millones de computadoras). Se puede utilizar para el cálculo voluntario (utilizando dispositivos de consumo) o computación de redes (utilizando recursos de organización). Soporta aplicaciones virtualizadas, paralelas y basadas en GPU.", "BRIDGE CONFIGURATION ANALYSIS": "ANÁLISIS DE CONFIGURACIÓN DEL PUENTE", "BTRFS:": "BTRFS:", + "Baby Buddy web interface": "Baby Buddy interfaz web", + "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work.": "Babybuddy es un amigo para bebés! Ayuda a los cuidadores a rastrear el sueño, las alimentacións, los cambios en el pañal, el tiempo de estómago y más para aprender y predecir las necesidades del bebé sin (como mucho) adivinar el trabajo.", "Back to previous menu or Esc + Enter": "Volver al menú anterior o Esc + Enter", "Backed up and cleared": "Copia de seguridad y limpieza", "Backend": "backend", "Backend:": "Parte trasera:", + "Background archive extraction for Arr download queues. No web interface.": "Extracción de archivos de fondo para las colas de descarga Arr. No hay interfaz web.", "Backup — VM and CT backups": "Copia de seguridad: copias de seguridad de VM y CT", + "Backup & Recovery": "Recuperación", "Backup Created": "Copia de seguridad creada", "Backup ID (group name in PBS):": "ID del backup (nombre del grupo en PBS):", "Backup ID for this job:": "ID del backup para este trabajo:", @@ -345,6 +509,7 @@ "Backup available at": "Copia de seguridad disponible en", "Backup completed successfully.": "La copia de seguridad se completó correctamente.", "Backup completed:": "Copia de seguridad completada:", + "Backup created": "Backup creado", "Backup created:": "Copia de seguridad creada:", "Backup declares unused NICs that are not on this host:": "La copia de seguridad declara las NIC no utilizadas que no están en este host:", "Backup destination is inside the backup": "el destino de la copia de seguridad está dentro de la copia de seguridad", @@ -355,6 +520,7 @@ "Backup information": "Información de respaldo", "Backup location": "Ubicación de la copia de seguridad", "Backup metadata": "Metadatos de copia de seguridad", + "Backup of the previous installation verified": "Backup de la instalación anterior verificada", "Backup on newer kernel:": "Copia de seguridad en un kernel más nuevo:", "Backup on older kernel:": "Copia de seguridad en un kernel anterior:", "Backup origin metadata:": "Metadatos de origen de la copia de seguridad:", @@ -369,26 +535,42 @@ "Backup:": "Copia de seguridad:", "Backups already on PBS were encrypted with the current key — downloading them will fail unless you first Download the current keyfile to keep a copy.": "Las copias de seguridad que ya están en PBS se cifraron con la clave actual; la descarga fallará a menos que primero descargue el archivo de clave actual para conservar una copia.", "Backups already stored on PBS were encrypted with the current keyfile. After this action:": "las copias de seguridad ya almacenadas en PBS se cifraron con el archivo de claves actual. Después de esta acción:", + "Backups verified": "Backups verificados", + "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience.": "Bambu Studio es un software de corte de código abierto y rico en características. Contiene flujos de trabajo basados en proyectos, algoritmos de corte optimizados sistemáticamente, y una interfaz gráfica fácil de usar, aportando a los usuarios una experiencia de impresión increíblemente suave.", "Bandwidth limit configured": "Límite de ancho de banda configurado", "Bandwidth test (iperf3)": "Prueba de ancho de banda (iperf3)", "Bandwidth test completed successfully": "La prueba de ancho de banda se completó con éxito", "Base VM created with ID": "VM base creada con ID", + "Base VMID": "Base VMID", + "Base VMID (empty = next free block)": "Base VMID (vacío = siguiente bloque libre)", + "Base VMID of Nextcloud (empty = next free block)": "Base VMID de Nextcloud (vacío = siguiente bloque libre)", + "Base VMID of Paperless (empty = next free block)": "Base VMID de Paperless (vacío = siguiente bloque libre)", + "Base VMID of Tandoor (empty = next free block)": "Base VMID de Tandoor (vacío = siguiente bloque libre)", + "Base VMID of the server (empty = next free block)": "Base VMID del servidor (vacío = siguiente bloque libre)", "Bash prompt path": "Ruta del prompt de Bash", "Bashrc customization completed": "Personalización de Bashrc completada", "Basic Settings": "Ajustes básicos", "Basic Utilities": "Utilidades básicas", + "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you.": "Bazarr es una aplicación de acompañamiento para Sonarr y Radarr. Puede gestionar y descargar subtítulos basados en tus requirements. Usted define sus preferencias por programa de televisión o película y Bazarr se encarga de todo para usted.", + "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools.": "Beets es un gestor de bibliotecas de música y no, en su mayor parte, un reproductor de música. Incluye un plugin de reproductor simple y un reproductor web experimental, pero generalmente deja la reproducción de sonido real a herramientas especializadas.", "Before making any changes, we'll create a safety backup.": "Antes de realizar cualquier cambio, crearemos una copia de seguridad de seguridad.", "Beta (develop branch)": "Beta (rama de desarrollo)", "Beta version:": "Versión beta:", "Binary not found in extracted content.": "Binario no encontrado en el contenido extraído.", "Bind mount added:": "Montaje de enlace agregado:", + "Bind mounts are not included in vzdump": "Los bind mounts no están incluidos en vzdump", + "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services.": "Bitcoin Knots se puede utilizar como cliente de escritorio para pagos regulares o como un servidor de nodos completo para comerciantes y otros servicios de pago.", "Blacklist nouveau driver": "Poner el controlador nouveau en la lista negra", "Blacklisting GPU host drivers...": "Incluir en la lista negra los controladores del host de la GPU...", "Blacklisting nouveau driver...": "Poniendo el controlador nouveau en la lista negra...", + "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**": "Blender es un software gratuito y de código abierto para gráficos 3D utilizado para crear películas animadas, efectos visuales, arte, modelos impresos 3D, gráficos de movimiento, aplicaciones interactivas 3D, realidad virtual y juegos de computadora. **Esta imagen no admite la reproducción de GPU fuera de la caja sólo experiencia de trabajo acelerada**", + "Blinko is an AI-powered card note-taking project. Designed for individuals who want to quickly capture and organize their fleeting thoughts. Blinko allows users to seamlessly jot down ideas the moment they strike, ensuring that no spark of creativity is lost.": "Blinko es un proyecto de toma de notas con tarjeta de IA. Diseñado para individuos que quieren quickly capturar y organizar sus pensamientos fugaces. Blinko permite a los usuarios descifrar sin problemas las ideas en el momento en que golpean, asegurando que no se pierda ninguna chispa de creatividad.", "Blocked GPU ID": "ID de GPU bloqueada", "Blocked GPU ID for VM Mode": "ID de GPU bloqueada para el modo VM", "Blocked device(s)": "Dispositivo(s) bloqueado(s)", "Blocked device(s):": "Dispositivo(s) bloqueado(s):", + "BookStack web interface": "Interfaz web BookStack", + "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease.": "Bookstack es una fuente libre y abierta Wiki diseñada para crear una hermosa documentación. Con un editor WYSIWYG simple, pero potente, permite a los equipos crear documentación detallada y útil con facilidad.", "Boot Disk": "Disco de arranque", "Boot artifacts regenerated — reboot the host to activate the merged config.": "artefactos de arranque regenerados: reinicie el host para activar la configuración fusionada.", "Boot disk:": "Disco de arranque:", @@ -415,9 +597,13 @@ "Bridge:": "Puente:", "Bridges analyzed": "Puentes analizados", "Broken gasket-dkms package state recovered.": "Se ha recuperado el estado dañado del paquete gasket-dkms.", + "Browse Your Life in Images": "Explore su vida en imágenes", "Browse manually (advanced)...": "Navegar manualmente (avanzado)...", + "Browsers & Web Desktops": "Navegadores & Web Desktops", "Build and install the gasket and apex kernel modules (DKMS)": "Compilar e instalar los módulos del kernel gasket y apex (DKMS)", "Build dependencies installed.": "Construya dependencias instaladas.", + "Build your personal knowledge base with TriliumNext Notes": "Construya su base de conocimiento personal con Trilium", + "Business & ERP": "Business & ERP", "CHANGES APPLIED SUCCESSFULLY": "CAMBIOS APLICADOS EXITOSAMENTE", "CIFS Client Tools: AVAILABLE": "Herramientas de cliente CIFS: DISPONIBLES", "CIFS Client Tools: NOT AVAILABLE - installing...": "Herramientas de cliente CIFS: NO DISPONIBLES - instalando...", @@ -435,24 +621,35 @@ "CLUSTER UPGRADE NOTES:": "NOTAS DE ACTUALIZACIÓN DEL CLÚSTER:", "CONFIGURED INTERFACES": "INTERFACES CONFIGURADAS", "CONFIRM FORMAT": "CONFIRMAR FORMATO", + "CPU": "CPU", "CPU Cores": "Núcleos de CPU", "CPU MODEL": "MODELO DE CPU", "CPU Model": "Modelo de CPU", + "CPU cores": "Núcleos de CPU", + "CPU priority": "Prioridad de la CPU", "CPU set to host,hidden=1,flags=+pcid": "CPU configurada como host,hidden=1,flags=+pcid", "CPU vendor (intel/amd):": "Proveedor de CPU (Intel/AMD):", "CRITICAL: The selected disk is referenced by a RUNNING VM or CT.": "CRÍTICO: El disco seleccionado tiene referencia a una VM o CT EN EJECUCIÓN.", "CT": "LXC", "CT started successfully.": "El LXC se inició con éxito.", + "CUDA requires a working NVIDIA driver": "CUDA requires un controlador NVIDIA de trabajo", + "CUDA requires the NVIDIA Container Toolkit on the host": "CUDA requiere el NVIDIA Container Toolkit en el host", + "Calculate all kinds of statistics from your (local) Emby or Jellyfin server": "Calcular todo tipo de estadísticas de su servidor (local) Emby o Jellyfin", + "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts.": "Calibre es un poderoso y fácil de usar gestor de libros electrónicos. Los usuarios dicen que es excepcional y debe tener. Te permitirá hacer casi todo y lleva las cosas un paso más allá del software normal de libros electrónicos. También es completamente libre y de código abierto y excelente para usuarios casuales y expertos en informática.", + "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself.": "Calibre-web es una aplicación web que proporciona una interfaz limpia para navegar, leer y descargar eBooks utilizando una base de datos Calibre existente. También es posible integrar google drive y editar metadatos y su biblioteca calibre a través de la propia aplicación.", + "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases.": "Calligra es una oficina y una suite de arte gráfico por KDE. Está disponible para PCs de escritorio, computadoras de tableta y teléfonos inteligentes. Contiene aplicaciones para procesamiento de palabras, hojas de cálculo, presentación, gráficos vectoriales y bases de datos de edición.", "Cancel": "Cancelar", "Cancel restore": "Cancelar restauración", "Cancel this setup": "cancelar esta configuración", "Cancelled by user or empty URL.": "Cancelado por usuario o URL vacía.", "Cancelled by user.": "Cancelado por el usuario.", + "Cannot apply the Compose command:": "No puede aplicar el comando Compose:", "Cannot connect to server": "No se puede conectar al servidor", "Cannot continue": "no puedo continuar", "Cannot create:": "No se puede crear:", "Cannot detect filesystem on": "No se puede detectar el sistema de archivos en", "Cannot find": "no puedo encontrar", + "Cannot identify the vendor of the device:": "No se puede identificar el proveedor del dispositivo:", "Cannot load backup library: lib_host_backup_common.sh": "No se puede cargar la biblioteca de respaldo: lib_host_backup_common.sh", "Cannot proceed with invalid export path.": "No se puede continuar con una ruta de exportación no válida.", "Cannot proceed with invalid share name.": "No se puede continuar con un nombre compartido no válido.", @@ -460,7 +657,11 @@ "Cannot reach download.proxmox.com. Check network, proxy or DNS.": "No se puede acceder a download.proxmox.com. Verifique la red, proxy o DNS.", "Cannot reach portal:": "No se puede acceder al portal:", "Cannot reach server": "No puede alcanzar el servidor", + "Cannot read": "No puedo leer", + "Cannot read the OCI archive:": "No se puede leer el archivo OCI:", "Cannot validate credentials - no shares available for testing.": "No se pueden validar las credenciales: no hay recursos compartidos disponibles para realizar pruebas.", + "Cannot verify the reused disk:": "No se puede verificar el disco reutilizado:", + "Capabilities cannot be kept and all dropped at the same time": "No se pueden mantener las capacidades y todas se disminuyen al mismo tiempo", "Category": "Categoría", "Caution: Maximum mode generates more heat.": "Precaución: el modo máximo genera más calor.", "Ceph check skipped by user flag (--ignore-ceph-check)": "Comprobación de Ceph omitida por el indicador del usuario (--ignore-ceph-check)", @@ -487,14 +688,23 @@ "Ceph repository configured for PVE 9": "Repositorio Ceph configurado para PVE 9", "Ceph repository signature verification failed; installation has been stopped": "Error en la verificación de la firma del repositorio de Ceph;la instalación ha sido detenida", "Ceph version OK:": "Versión Ceph correcta:", + "Certificate errors are logged in /config/log/letsencrypt inside the container.": "Los errores de certificado se registran en /config/log/letsencrypt dentro del contenedor.", "Certificate fingerprint of the PBS server:": "Huella digital del certificado del servidor PBS:", + "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL": "Proveedor de certificados: vacío para Encriptar, cerossl para ZeroSSL", + "Change GPU acceleration?": "¿Cambiar la aceleración de GPU?", "Change Language": "Cambiar idioma", "Change Release Channel": "Cambiar canal de lanzamiento", + "Change it after the first login.": "Cámbialo después del primer inicio de sesión.", + "Change or add an environment variable?": "¿Cambiar o añadir una variable de entorno?", + "Change the access network?": "¿Cambiar la red de acceso?", + "Changedetection.io provides free, open-source web page monitoring, notification and change detection.": "Changedetection.io proporciona monitorización gratuita de páginas web de código abierto, notificación y detección de cambios.", "Changes applied. A system reboot is recommended for them to take full effect.": "Se aplicaron cambios. Se recomienda reiniciar el sistema para que surtan efecto completo.", "Changes have been applied to the configuration file.": "Se han aplicado cambios al archivo de configuración.", "Changes will apply after reboot.": "Los cambios se aplicarán después del reinicio.", "Changing Release Channel": "Cambiar el canal de lanzamiento", "Changing the machine type on an existing installed VM is not safe: it changes the chipset and PCI slot layout, which typically prevents the guest OS from booting.": "Cambiar el tipo de máquina en una VM instalada existente no es seguro: cambia el diseño del chipset y de la ranura PCI, lo que normalmente impide que el sistema operativo invitado se inicie.", + "Changing the rootfs or its storage requires a separate migration": "Cambiar los rootfs o su almacenamiento requiere una migración separada", + "Changing the storage or size of a disk requires a migration; empty disks are not created": "Cambiar el almacenamiento o el tamaño de un disco requiere una migración; los discos vacíos no se crean", "Check": "Controlar", "Check BIOS/UEFI in Hardware > BIOS — must match what the original VM used": "Verifique BIOS/UEFI en Hardware > BIOS: debe coincidir con lo que usó la VM original", "Check Coral USB/M.2 detection": "Comprobar la detección de Coral USB/M.2", @@ -520,6 +730,7 @@ "Check the service status manually if needed.": "Verifique el estado del servicio manualmente si es necesario.", "Checking MOTD configuration...": "Comprobando la configuración del MOTD...", "Checking NVIDIA driver status with nvidia-smi": "Comprobar el estado del controlador NVIDIA con nvidia-smi", + "Checking OCI": "Comprobando OCI", "Checking VFIO modules...": "Comprobando módulos VFIO...", "Checking VM virtual display model...": "Comprobando el modelo de pantalla virtual de VM...", "Checking ZFS autotrim configuration...": "Comprobando la configuración de recorte automático de ZFS...", @@ -531,7 +742,22 @@ "Checking if the server belongs to OVH...": "Comprobando si el servidor pertenece a OVH...", "Checking kernel headers and build tools...": "Comprobando los encabezados del kernel y las herramientas de compilación...", "Checking remaining interfaces": "Comprobando las interfaces restantes", + "Checking that the container keeps running...": "Comprobando que el contenedor sigue funcionando...", "Checking that this version builds against the running kernel...": "Comprobando que esta versión se compila con el kernel en ejecución...", + "Checking the GPU of the machine learning container...": "Comprobando la GPU del contenedor de aprendizaje automático...", + "Checking the container before recreating it...": "Revisando el contenedor antes de recrearlo...", + "Checking the container before the update...": "Revisando el contenedor antes de la actualización...", + "Checking the device permissions for the application user...": "Verificación de los permisos del dispositivo para el usuario de la aplicación...", + "Checking the image compatibility:": "Verificación de la compatibilidad de la imagen:", + "Checking the image in the registry...": "Revisando la imagen en el registro...", + "Checking the interrupted operation...": "Revisando la interrumpida operación...", + "Checking the interrupted stack operation...": "Revisando la pila interrumpida operación...", + "Checking the new image without starting it:": "Comprobando la nueva imagen sin comenzarla:", + "Checking the remote...": "Revisando el control remoto...", + "Checking the restored installation": "Comprobación de la instalación restaurada", + "Checking the restored installation...": "Revisando la instalación restaurada...", + "Checking the stack before the update...": "Revisando la pila antes de la actualización...", + "Checking the updated stack...": "Revisando la pila actualizada...", "Checklist post-upgrade finished. Warnings:": "Lista de verificación posterior a la actualización finalizada. Advertencias:", "Checklist pre-check finished. Warnings:": "Verificación previa de la lista de verificación finalizada. Advertencias:", "Checks for LVM and storage issues": "Comprueba si hay problemas de almacenamiento y LVM", @@ -588,6 +814,9 @@ "Choose the type of virtual system to install:": "Elige el tipo de sistema virtual a instalar:", "Choose what to do with the selected disk:": "Elige qué hacer con el disco seleccionado:", "Choose where to save the backup:": "Elige dónde guardar la copia de seguridad:", + "Chrome is the official web browser from Google, built to be fast, secure, and customizable.": "Chrome es el navegador web oficial de Google, construido para ser rápido, seguro y personalizable.", + "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.": "Chromium es un proyecto de navegador de código abierto que pretende construir una manera más segura, rápida y estable para que todos los usuarios experimenten la web.", + "Circular dependency:": "Dependencia circular:", "Clean disk metadata": "Limpiar metadatos del disco", "Cleaned up": "limpiado", "Cleaning cached files...": "Limpiando archivos en caché...", @@ -611,21 +840,29 @@ "Clearing login credentials...": "Borrando credenciales de inicio de sesión...", "Client (run a bandwidth test to a server)": "Cliente (ejecute una prueba de ancho de banda en un servidor)", "Client determines best version to use": "El cliente determina la mejor versión para usar", + "Clients reach the VPN through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Los clientes llegan a la VPN a través de la dirección pública y el puerto UDP dado durante la instalación, de modo que el puerto debe ser enviado a este contenedor.", "Cloning Coral driver repository (feranick fork)...": "Clonación del repositorio de controladores de Coral (fork feranick)...", "Cloning Lynis from GitHub...": "Clonando Lynis desde GitHub...", "Cloning and applying NVIDIA patch (keylase/nvidia-patch)...": "Clonación y aplicación del parche NVIDIA (keylase/nvidia-patch)...", "Closed": "Cerrado", + "Cloud storage synchronization and FUSE mounts": "Sincronización de almacenamiento en la nube y montajes FUSE", "Cloud-Init Automated Installers": "Instaladores automatizados de Cloud-Init", "Cluster certificates updated": "Certificados de clúster actualizados", "Cluster configuration (advanced)": "Configuración de clúster (avanzada)", "Cluster data will be applied automatically at next boot.": "los datos del clúster se aplicarán automáticamente en el próximo inicio.", "Cluster upgrade mode": "Modo de actualización del clúster", + "Code-server is VS Code running on a remote server, accessible through the browser.": "Code-server es el código VS que se ejecuta en un servidor remoto, accesible a través del navegador.", + "CodeProject.AI Server": "CodeProject. AI Server", "Command": "Dominio", + "Command override for an unknown service:": "Anulación de comando para un servicio desconocido:", "Commenting any residual Bookworm lines in *.list...": "Comentando cualquier línea residual de Bookworm en *.list...", "Commenting legacy PVE 8 repository .list files (if any)...": "Comentando archivos .list del repositorio PVE 8 heredado (si los hay)...", "Commenting legacy ceph.list (if present)...": "Comentando ceph.list heredado (si está presente)...", "Common Issues Check": "Verificación de problemas comunes", + "Common root for the published views": "Raíz común para las vistas publicadas", + "Communication & Community": "Comunicación y comunidad", "Community Scripts": "Scripts comunitarios", + "Community single-container Home Assistant OS image": "Comunidad Imagen de un solo contenedor Home Assistant OS", "Compatibility check": "verificación de compatibilidad", "Compatibility check — OK": "Verificación de compatibilidad - OK", "Compatibility check — issues detected": "verificación de compatibilidad: problemas detectados", @@ -640,24 +877,31 @@ "Complete restore": "restauración completa", "Complete the DSM installation wizard": "Complete el asistente de instalación de DSM", "Complete the ZimaOS installation wizard": "Complete el asistente de instalación de ZimaOS", + "Complete the media server and Seerr accounts, the Bazarr providers and the SABnzbd Usenet credentials when they are selected.": "Complete las cuentas del servidor multimedia y de Seerr, los proveedores de Bazarr y las credenciales de Usenet de SABnzbd cuando estén seleccionados.", + "Completed": "Completado", "Completed Successfully with GPU passthrough configured!": "¡Completado exitosamente con el paso a través de GPU configurado!", "Completed Successfully!": "¡Completado con éxito!", "Completed with errors —": "Completado con errores.", "Completed.": "Terminado.", "Completed. Devices added to VM {vmid}: {count}.": "Completado. Dispositivos agregados a la VM {vmid}: {count}.", "Completed. Press Enter to return to menu...": "Terminado. Presione Enter para regresar al menú...", + "Completing its final cleanup...": "Completando su limpieza final...", "Completing pending package configurations...": "Completando las configuraciones de paquetes pendientes...", "Compliance checking (PCI-DSS, HIPAA, etc.)": "Comprobación de cumplimiento (PCI-DSS, HIPAA, etc.)", "Component to uninstall manually (no --auto-uninstall yet):": "Componente para desinstalar manualmente (aún no hay desinstalación automática):", "Component was installed on the backup source but no matching hardware was found on this host.": "El componente se instaló en la fuente de respaldo, pero no se encontró hardware coincidente en este host.", "Component:": "Componente:", "Components to uninstall (manual for now):": "Componentes para desinstalar (manual por ahora):", + "Compose capabilities validated in the LXC user namespace:": "Configurar capacidades validadas en el espacio de nombres de usuario de LXC:", + "Compose file of the application": "Archivo Compose de la aplicación", + "Compose file of this host": "Archivo Compose de este host", "Compressed size:": "Tamaño comprimido:", "Compressing": "comprimir", "Compression Tools": "Herramientas de compresión", "Concise output of logical volumes": "Salida concisa de volúmenes lógicos", "Concise output of physical volumes": "Salida concisa de volúmenes físicos.", "Concise output of volume groups": "Salida concisa de grupos de volúmenes.", + "Concurrent change while restoring the start at boot setting": "Cambio simultáneo mientras se restablece el inicio en el ajuste de arranque", "Configuration Analysis": "Análisis de configuración", "Configuration Menu": "Menú de configuración", "Configuration Summary:": "Resumen de configuración:", @@ -666,11 +910,13 @@ "Configuration can continue now and will be effective after reboot.": "La configuración puede continuar ahora y será efectiva después del reinicio.", "Configuration completed successfully!": "¡La configuración se completó con éxito!", "Configuration file for container": "Archivo de configuración para contenedor", + "Configuration files generated:": "Archivos de configuración generados:", "Configuration has been stopped due to high reset risk.": "La configuración se ha detenido debido al alto riesgo de reinicio.", "Configuration has been stopped to prevent an unusable VM state.": "La configuración se ha detenido para evitar un estado de VM inutilizable.", "Configuration has been stopped to prevent leaving the VM in an unusable state.": "La configuración se ha detenido para evitar dejar la máquina virtual en un estado inutilizable.", "Configuration name:": "Nombre de configuración:", "Configuration sections that will be REMOVED": "Secciones de configuración que serán ELIMINADAS", + "Configuration size in GB": "Tamaño de configuración en GB", "Configuration to be Removed": "Configuración que se eliminará", "Configuration will continue now and be effective after reboot.": "La configuración continuará ahora y será efectiva después del reinicio.", "Configuration:": "Configuración:", @@ -713,6 +959,7 @@ "Configuring Proxmox jail...": "Configurando la cárcel de Proxmox...", "Configuring TCP optimizations...": "Configurando optimizaciones de TCP...", "Configuring TPM device": "Configurar el dispositivo TPM", + "Configuring Unpackerr...": "Configuración de Unpackerr...", "Configuring VFIO modules...": "Configurando módulos VFIO...", "Configuring VM": "Configurando la máquina virtual", "Configuring bandwidth limit for vzdump...": "Configurando el límite de ancho de banda para vzdump...", @@ -728,8 +975,11 @@ "Configuring max FD limit / ulimit...": "Configurando límite máximo de FD/ulimit...", "Configuring max user watches...": "Configurando el número máximo de visualizaciones de usuarios...", "Configuring pigz as a faster replacement for gzip...": "Configurando pigz como un reemplazo más rápido para gzip...", + "Configuring qBittorrent...": "Configuración de qBittorrent...", "Configuring snapshot schedules...": "Configurando programas de instantáneas...", "Configuring system time settings...": "Configurando los ajustes de hora del sistema...", + "Configuring the Radarr root folder...": "Configuración de la carpeta raíz Radarr...", + "Configuring the Sonarr root folder...": "Configuración de la carpeta raíz Sonarr...", "Configuring vfio-pci binding...": "Configurando el enlace vfio-pci...", "Confirm Borg passphrase": "Confirmar la frase de contraseña de Borg", "Confirm Borg passphrase:": "Confirmar la contraseña de Borg:", @@ -751,6 +1001,7 @@ "Confirm export": "Confirmar exportación", "Confirm password for": "Confirmar contraseña para", "Confirm recovery passphrase:": "Confirmar la contraseña de recuperación:", + "Confirm that host data is not reverted": "Confirme que los datos de host no se revierten", "Confirm the keyfile passphrase:": "confirme la frase de contraseña del archivo clave:", "Confirm the mount path is visible.": "Confirme que la ruta de montaje sea visible.", "Confirm the password:": "Confirme la contraseña:", @@ -762,7 +1013,11 @@ "Conflicting path included in backup:": "Ruta conflictiva incluida en la copia de seguridad:", "Conflicting utilities removed": "Se eliminaron las utilidades conflictivas", "Connect a Coral Accelerator and try again.": "Conecte un Coral Accelerator y vuelva a intentarlo.", + "Connect your devices and users together in your own secure virtual private network.": "Conecta tus dispositivos y usuarios juntos en tu propia red privada virtual segura.", + "Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.": "Conecte sus dispositivos en una red de superposición segura de WireGuard® con SSO, MFA y controles de acceso granular.", "Connected": "Conectado", + "Connecting Radarr to qBittorrent...": "Conexión de Radarr a qBittorrent...", + "Connecting Sonarr to qBittorrent...": "Conexión de Sonarr a qBittorrent...", "Connecting to PBS and starting backup...": "Conectándose a PBS e iniciando la copia de seguridad...", "Connection Details:": "Detalles de conexión:", "Connection Error": "Error de conexión", @@ -774,6 +1029,7 @@ "Consider removing its configuration": "Considere eliminar su configuración", "Consider security implications for production environments": "Considere las implicaciones de seguridad para los entornos de producción.", "Consider visiting the repository and supporting the project.": "considere visitar el repositorio y apoyar el proyecto.", + "Console log:": "Registro de consolas:", "Container": "Recipiente", "Container — LXC root directories": "Contenedor: directorios raíz de LXC", "Container ID": "ID del contenedor", @@ -783,30 +1039,46 @@ "Container Path": "Ruta del contenedor", "Container Path:": "Ruta del contenedor:", "Container Status": "Estado del contenedor", + "Container checked": "Control de contenedores", "Container configuration not found": "Configuración del contenedor no encontrada", + "Container configured (not started):": "Container configurado (no iniciado):", + "Container converted to privileged": "Container convertido a privilegiado", + "Container created:": "Container created:", "Container did not become ready in time. Skipping driver installation.": "El contenedor no estuvo listo a tiempo. Saltarse la instalación del controlador.", "Container did not start in time.": "El contenedor no arrancó a tiempo.", "Container distro": "distribución de contenedores", "Container does not have apt-get available. Coral driver installation only supports Debian/Ubuntu containers.": "El contenedor no tiene apt-get disponible. La instalación del controlador Coral solo admite contenedores Debian/Ubuntu.", + "Container installed, but without a verifiable record for future updates.": "Container instalado, pero sin un registro verificable para futuras actualizaciones.", "Container is already stopped.": "El contenedor ya está detenido.", "Container is running. Restart to apply changes?": "El contenedor está funcionando. ¿Reiniciar para aplicar cambios?", "Container is stopped. Start it now to verify the mount works?": "El contenedor está detenido. ¿Iniciarlo ahora para verificar que el soporte funciona?", + "Container kept with its data; the installation was not validated:": "Container se mantuvo con sus datos; la instalación no fue validada:", "Container mount point:": "Punto de montaje del contenedor:", "Container must be stopped before conversion": "El contenedor debe detenerse antes de la conversión.", + "Container prepared for the stack:": "Contenedor preparado para la pila:", + "Container recreated": "Container recreated", + "Container removed:": "Container removed:", "Container restarted successfully": "El contenedor se reinició correctamente", + "Container started": "Container started", "Container started successfully": "El contenedor se inició correctamente", "Container started successfully.": "El contenedor se inició correctamente.", "Container started.": "Contenedor iniciado.", + "Container stopped": "Container stopped", "Container stopped.": "El contenedor se detuvo.", "Container successfully converted to privileged.": "Contenedor convertido exitosamente a privilegiado.", "Container template— LXC templates": "Plantilla de contenedor: plantillas LXC", + "Container volume": "Volumen de contenedor", + "Container volume (included in backups)": "Volumen de contenedor (incluido en backups)", "Container will pick up the mount on next start": "El contenedor recogerá la montura en el próximo inicio.", "Container with ID": "Contenedor con identificación", "Container:": "Recipiente:", + "Containers & Docker": "Containers & Docker", + "Containers:": "Containers:", "Contains files": "Contiene archivos", "Contains:": "Contiene:", "Content Types": "Tipos de contenido", "Content Types:": "Tipos de contenido:", + "Content collaboration platform": "Plataforma de colaboración con contenidos", "Content is usually images for VM block devices.": "El contenido suele ser imágenes para dispositivos de bloque VM.", "Content type is fixed to:": "El tipo de contenido se fija en:", "Content:": "Contenido:", @@ -817,10 +1089,12 @@ "Continue the Windows installation as usual.": "Continúe la instalación de Windows como de costumbre.", "Continue with Coral TPU configuration only?": "¿Continuar solo con la configuración Coral TPU?", "Continue with live apply now? SSH may disconnect immediately.": "¿Continuar con la solicitud en vivo ahora? SSH puede desconectarse inmediatamente.", + "Continue with the experimental HAOS One profile?": "¿Continuar con el perfil experimental HAOS One?", "Continue with the import?": "¿Continuar con la importación?", "Continue: Proceed with conversion": "Continuar: continuar con la conversión", "Continue?": "¿Continuar?", "Continuing with your selection.": "Continuando con su selección.", + "Contradictory tmpfs options": "Opciones de tmpfs contradictorios", "Controller": "Controlador", "Controller + NVMe": "Controlador + NVMe", "Controller + NVMe assignment will be written now and become active after host reboot.": "La asignación de controlador + NVMe se escribirá ahora y se activará después de reiniciar el host.", @@ -849,7 +1123,11 @@ "Converting disk": "Convirtiendo disco", "Converting file ownership (this may take several minutes)...": "Convirtiendo la propiedad del archivo (esto puede tardar varios minutos)...", "Converting image using command:": "Convertir imagen usando el comando:", + "Converting the container to privileged...": "Convertir el contenedor en privilegiado...", "Converts to deb822; keeps .list backups as .bak": "Se convierte a deb822; mantiene las copias de seguridad .list como .bak", + "Coordinated backups require zstd": "Backups coordinados requieren zstd", + "Cops by Sébastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server.": "Cops de Sébastien Lucas, ahora mantenida por MikesPub, representa a Calibre OPDS (y HTML) Php Server.", + "Copy a peer configuration to the host with: pct pull /config/peer1/peer1.conf peer1.conf": "Copia una configuración de pares en el host con: pct pull /config/peer1/peer1.conf peer1.conf", "Copy failed": "Copia fallida", "Copy that file offsite yourself, or download it from the Monitor.": "copie ese archivo fuera del sitio usted mismo o descárguelo del Monitor.", "Copy the correct keyfile to this host and rerun Restore — or pick an unencrypted backup.": "copie el archivo de claves correcto en este host y vuelva a ejecutar Restaurar, o elija una copia de seguridad sin cifrar.", @@ -864,6 +1142,7 @@ "Coral M.2 Apex configuration added - device ready": "Configuración de Coral M.2 Apex agregada: dispositivo listo", "Coral M.2 Apex configuration added - device will be available after reboot": "Se agregó la configuración de Coral M.2 Apex: el dispositivo estará disponible después del reinicio", "Coral M.2 Apex detected, configuring...": "Coral M.2 Apex detectado, configurando...", + "Coral PCIe/M.2 node (e.g. /dev/apex_0)": "Nodo Coral PCIe/M.2 (por ejemplo, /dev/apex 0)", "Coral TPU Installation": "Instalación de TPU Coral", "Coral TPU Uninstall": "Desinstalación de Coral TPU", "Coral TPU device nodes detected with correct group (apex).": "Nodos del dispositivo Coral TPU detectados con el grupo correcto (ápice).", @@ -876,19 +1155,33 @@ "Coral USB configured but device not currently connected": "Coral USB configurado pero el dispositivo no está conectado actualmente", "Coral USB runtime installed. No reboot required.": "Tiempo de ejecución Coral USB instalado. No es necesario reiniciar.", "Coral hardware configuration completed for container": "Configuración de hardware Coral completada para contenedor", + "Coral is only offered for Frigate and CodeProject.AI": "Coral solo se ofrece para Frigate y CodeProject.AI", "Coral kernel modules unloaded.": "Módulos del kernel de Coral descargados.", "Coral packages purged.": "Paquetes de Coral purgados.", "Coral uninstallation completed.": "Se completó la desinstalación de Coral.", "Core Proxmox packages reinstalled successfully": "Paquetes Core Proxmox reinstalados exitosamente", + "Core is running, but not responding over HTTP on 80/8123": "Core está funcionando, pero no responde a HTTP en 80/8123", + "Core is still on the initial installation page": "Core sigue en la página de instalación inicial", "Core packages": "Paquetes principales", + "Cores": "Núcleos", + "Corrupted gzip layer": "Capa de gzip corregida", "Could not add": "No se pudo agregar", "Could not add disk": "No se pudo agregar el disco", + "Could not add the device to the container:": "No podía añadir el dispositivo al contenedor:", + "Could not add the mount point:": "No podía añadir el punto de montaje:", + "Could not apply the Compose extra hosts": "No podía aplicar los hosts adicionales Compose", + "Could not apply the Compose supplementary groups": "No podía aplicar los grupos complementarios de Compose", + "Could not apply the Jellyfin configuration:": "No podía aplicar la configuración Jellyfin:", + "Could not apply the installer profile": "No podía aplicar el perfil del instalador", + "Could not apply the pre-start repair:": "No se puede aplicar la reparación pre-start:", "Could not assign disk": "No se pudo asignar el disco", "Could not authorize the key via 'pct exec' on": "No se pudo autorizar la clave a través de 'pct exec' en", "Could not back up the existing auth.json": "No se pudo realizar una copia de seguridad del auth.json existente", "Could not change VM virtual display to vga: std": "No se pudo cambiar la pantalla virtual de VM a vga: estándar", + "Could not check the NVIDIA GPU": "No podía comprobar la GPU NVIDIA", "Could not clone any gasket-driver repository. Check your internet connection and": "No se pudo clonar ningún repositorio de gasket-driver. Compruebe la conexión a Internet y", "Could not configure IOMMU kernel parameters automatically. Configure manually and reboot.": "No se pudieron configurar los parámetros del kernel IOMMU automáticamente. Configure manualmente y reinicie.", + "Could not convert the OCI rootfs to privileged": "No podía convertir los rootfs OCI a privilegiados", "Could not copy the PVE keyfile into place. Check permissions on:": "No se pudo copiar el archivo de claves PVE en su lugar. Verifique los permisos en:", "Could not copy the keyfile into place.": "no se pudo copiar el archivo de claves en su lugar.", "Could not copy the keyfile into place. Check permissions on:": "no se pudo copiar el archivo de claves en su lugar. Verifique los permisos en:", @@ -898,6 +1191,9 @@ "Could not create or access directory:": "No se pudo crear o acceder al directorio:", "Could not create temporary directory:": "No se pudo crear el directorio temporal:", "Could not create temporary working directory.": "No se pudo crear un directorio de trabajo temporal.", + "Could not create the container:": "No podía crear el contenedor:", + "Could not create the initial administrator": "No podía crear el administrador inicial", + "Could not create the service:": "No podía crear el servicio:", "Could not detect apex major number from /proc/devices. Load the apex module first: modprobe apex": "No se pudo detectar el número principal del ápice desde /proc/devices. Cargue el módulo apex primero: modprobe apex", "Could not detect the CIFS mount for this directory. Try accessing it manually.": "No se pudo detectar el montaje CIFS para este directorio. Intente acceder manualmente.", "Could not determine a valid ISO storage directory.": "No se pudo determinar un directorio de almacenamiento ISO válido.", @@ -907,7 +1203,9 @@ "Could not download recovery blob from PBS.": "No se pudo descargar el blob de recuperación de PBS.", "Could not download the NVIDIA Container Toolkit repository definition.": "No se pudo descargar la definición del repositorio de NVIDIA Container Toolkit.", "Could not download the NVIDIA Container Toolkit signing key.": "No se pudo descargar la clave de firma de NVIDIA Container Toolkit.", + "Could not download the image": "No podía descargar la imagen", "Could not download the installer.": "No se pudo descargar el instalador.", + "Could not enable the privileged profile before the first start": "No podía permitir el perfil privilegiado antes del primer comienzo", "Could not export ZFS pool": "No se pudo exportar el grupo ZFS", "Could not extract from PBS.": "No se pudo extraer de PBS.", "Could not fetch keylase/nvidia-patch supported list — patch reapply compatibility is not verified.": "No se pudo recuperar la lista compatible con keylase/nvidia-patch: no se ha verificado la compatibilidad con la reaplicación del parche.", @@ -921,34 +1219,53 @@ "Could not install exFAT tools automatically.": "No se pudieron instalar las herramientas exFAT automáticamente.", "Could not install sshpass automatically (no internet?). Falling back to manual paste mode — you'll see the line to copy onto the server next.": "No se pudo instalar sshpass automáticamente (¿no hay Internet?).Volviendo al modo de pegado manual, verá la línea para copiar en el servidor a continuación.", "Could not install the NVIDIA Container Toolkit signing key.": "No se pudo instalar la clave de firma de NVIDIA Container Toolkit.", + "Could not install the required packages:": "No podía instalar los paquetes necesarios:", + "Could not install the stack startup hook": "No podía instalar el gancho de arranque de pila", "Could not install vzdump hook in /etc/vzdump.conf": "No se pudo instalar el gancho vzdump en /etc/vzdump.conf", "Could not load shared functions. Script cannot continue.": "No se pudieron cargar funciones compartidas. El guión no puede continuar.", + "Could not load the host kernel module:": "No podía cargar el módulo del kernel host:", "Could not locate imported disk in VM config.": "No se pudo ubicar el disco importado en la configuración de VM.", "Could not mount": "No se pudo montar", "Could not mount ISO on device": "No se pudo montar ISO en el dispositivo", + "Could not mount the container filesystem:": "No se pudo montar el sistema de archivos de contenedores:", + "Could not obtain an intact image after two attempts": "No podía obtener una imagen intacta después de dos intentos", "Could not parse OVF file, or no disk image references found.": "No se pudo analizar el archivo OVF o no se encontraron referencias de imágenes de disco.", "Could not prepare on-boot restore service. Nothing new was scheduled.": "No se pudo preparar el servicio de restauración en el arranque. No se ha programado nada nuevo.", + "Could not prepare the NVIDIA driver links": "No podía preparar los enlaces de controladores NVIDIA", + "Could not prepare the file bind mount target:": "No se pudo preparar el objetivo de montaje del archivo bind:", "Could not publish pending restore. Previous pending restore was kept.": "No se pudo publicar la restauración pendiente. Se mantiene la anterior.", "Could not push the key. Check the password and that": "No se pudo presionar la tecla. Verifique la contraseña y eso", + "Could not query the image registry": "No se puede consultar el registro de imagen", "Could not read SMART data from": "No se pudieron leer los datos SMART de", "Could not read VM configuration.": "No se pudo leer la configuración de la VM.", + "Could not read the CUDA compute capability": "No podía leer la capacidad de cálculo de CUDA", + "Could not read the NVIDIA driver version": "No podía leer la versión del controlador NVIDIA", "Could not remount automatically. Try manually or check credentials.": "No se pudo volver a montar automáticamente. Pruebe manualmente o verifique las credenciales.", "Could not remove VM automatically. Run manually:": "No se pudo eliminar la VM automáticamente. Ejecutar manualmente:", "Could not remove previous DKMS tree at": "No se pudo eliminar el árbol DKMS anterior en", + "Could not reserve a private network for the stack": "No podía reservar una red privada para la pila", + "Could not resolve the Compose user:": "No podía resolver el usuario de Compose:", + "Could not resolve the OCI manifest of the image:": "No podía resolver el manifiesto de la imagen de la OCI:", + "Could not resolve the OCI manifest:": "No podía resolver el manifiesto de la OCI:", "Could not restart ProxMenux Monitor service.": "No se pudo reiniciar el servicio ProxMenux Monitor.", "Could not restart the service — start it manually with systemctl start": "No se pudo reiniciar el servicio; inícielo manualmente con systemctl start", "Could not retrieve versions list from NVIDIA. Please check your internet connection.": "No se pudo recuperar la lista de versiones de NVIDIA. Por favor verifique su conexión a Internet.", + "Could not reuse the persistent disk:": "No podía reutilizar el disco persistente:", "Could not run NVIDIA patch script. Please verify repository and driver version.": "No se pudo ejecutar el script de parche de NVIDIA. Verifique el repositorio y la versión del controlador.", "Could not set VM virtual display to vga: std": "No se pudo configurar la pantalla virtual de VM en vga: estándar", "Could not set boot order for": "No se pudo establecer el orden de inicio para", + "Could not set the container entrypoint": "No podía establecer el punto de entrada del contenedor", "Could not stage pending restore path:": "No se pudo preparar la ruta de la restauración pendiente:", "Could not stage pending restore. Nothing new was scheduled.": "No se pudo preparar la restauración pendiente. No se ha programado nada nuevo.", "Could not stop LXC": "No se pudo detener LXC", + "Could not translate the Compose command/entrypoint": "No podía traducir el comando Compose/punto de entrada", "Could not unload nouveau module (may be in use). The blacklist will take effect after reboot. Installation will continue but a reboot will be required.": "No se pudo descargar el módulo nouveau (puede estar en uso). La lista negra entrará en vigor después del reinicio. La instalación continuará pero será necesario reiniciar.", "Could not unmount": "No se pudo desmontar", + "Could not unmount the container filesystem:": "No podía desmontar el sistema de archivos de contenedores:", "Could not unmount — disk may be busy. Removing fstab entry anyway.": "No se pudo desmontar: es posible que el disco esté ocupado. Eliminando la entrada fstab de todos modos.", "Could not update config file.": "No se pudo actualizar el archivo de configuración.", "Could not write to:": "No se pudo escribir a:", + "Crafty Controller default login": "Inicio predeterminado de Crafty Controller", "Create Directory": "Crear directorio", "Create GPT and one partition:": "Crea GPT y una partición:", "Create GPT partition": "Crear partición GPT", @@ -971,6 +1288,7 @@ "Create a fresh GPT + ext4 partition and mount it?": "¿Crear una nueva partición GPT + ext4 y montarla?", "Create a new dataset in a ZFS pool": "Crear un nuevo conjunto de datos en un grupo ZFS", "Create a new group for isolation": "Crear un nuevo grupo para aislamiento", + "Create and edit Matroska files from a browser": "Crear y editar archivos Matroska desde un navegador", "Create credentials file (recommended):": "Crear archivo de credenciales (recomendado):", "Create directory": "Crear directorio", "Create export directory:": "Crear directorio de exportación:", @@ -982,6 +1300,7 @@ "Create scheduled backup job": "Crear trabajo de copia de seguridad programado", "Create share directory:": "Crear directorio compartido:", "Create shared directory:": "Crear directorio compartido:", + "Create this LXC in privileged mode?": "¿Crear este LXC en modo privilegiado?", "Created common remapped user": "Usuario común reasignado creado", "Created directory on host:": "Directorio creado en el host:", "Created persistent names for": "Creó nombres persistentes para", @@ -996,6 +1315,8 @@ "Creating UID remapping for unprivileged container compatibility...": "Creando reasignación de UID para compatibilidad con contenedores sin privilegios...", "Creating VM with the above configuration": "Creando VM con la configuración anterior", "Creating VM...": "Creando máquina virtual...", + "Creating a backup of": "Crear un backup", + "Creating a backup of the container...": "Creando un backup del contenedor...", "Creating backup of configuration file...": "Creando copia de seguridad del archivo de configuración...", "Creating backup of network interfaces configuration...": "Creando copia de seguridad de la configuración de las interfaces de red...", "Creating compressed archive...": "Creando archivo comprimido...", @@ -1005,6 +1326,11 @@ "Creating partition table and partition...": "Creando tabla de particiones y partición...", "Creating partition...": "Creando partición...", "Creating pigz wrapper script...": "Creando script contenedor pigz...", + "Creating the backup": "Crear el backup", + "Creating the container...": "Creando el contenedor...", + "Creating the initial administrator...": "Crear el administrador inicial...", + "Creating the temporary data container": "Creación del contenedor de datos temporales", + "Creative & Design": "Diseño creativo", "Credentials are correct": "Las credenciales son correctas", "Credentials cleared. jwt_secret and API tokens preserved.": "Credenciales borradas. Se conservan los tokens jwt_secret y API.", "Credentials file created securely.": "Archivo de credenciales creado de forma segura.", @@ -1014,6 +1340,8 @@ "Cross-host restore: guest IDs in backup overlap live IDs on target:": "Restauración entre hosts: los ID de invitados en la copia de seguridad se superponen a los ID activos en el destino:", "Cross-kernel restore — kernel-tied paths merged, not copied": "restauración entre núcleos: rutas vinculadas al núcleo fusionadas, no copiadas", "Cross-kernel — paths hidden from picker": "Cross-kernel: rutas ocultas al selector", + "Cross-platform file sharing made easy.": "Intercambio de archivos multiplataforma hecho fácil.", + "Cross-platform monitoring tool.": "Herramienta de monitoreo multiplataforma.", "Cross-version detected — safe restore mode": "Se detectó una versión cruzada: modo de restauración segura", "Current": "Actual", "Current CIFS mounts:": "Montajes CIFS actuales:", @@ -1023,6 +1351,8 @@ "Current NFS client script supports privileged LXC only.": "La secuencia de comandos del cliente NFS actual solo admite LXC privilegiado.", "Current NFS exports in CT": "Exportaciones actuales de NFS en CT", "Current NFS mounts:": "Montajes NFS actuales:", + "Current NVIDIA inventory resolved: a refresh is required": "Actual inventario NVIDIA resuelto: un refresco es necesario", + "Current NVIDIA inventory resolved: no refresh is required": "Inventario NVIDIA actual resuelto: ningún refresco es necesario", "Current Network Configuration": "Configuración de red actual", "Current PVE Version": "Versión PVE actual", "Current ProxMenux host scripts register remote shares as Proxmox storages using pvesm.": "Los scripts de host ProxMenux actuales registran recursos compartidos remotos como almacenamientos en Proxmox utilizando pvesm.", @@ -1046,6 +1376,7 @@ "Current user": "Usuario actual", "Current user UID, GID and groups": "UID, GID y grupos del usuario actual", "Current version:": "Versión actual:", + "Currently": "actualmente", "Currently Mounted:": "Actualmente montado:", "Currently configured target:": "Destino actualmente configurado:", "Currently mounted:": "Actualmente montado:", @@ -1066,6 +1397,7 @@ "Custom message added to MOTD": "Mensaje personalizado agregado a MOTD", "Custom options": "Opciones personalizadas", "Custom path": "Ruta personalizada", + "Custom path cancelled": "Ruta personalizada cancelada", "Custom path...": "Ruta personalizada...", "Custom paths are included in BOTH default and custom backup profiles.": "Las rutas personalizadas se incluyen tanto en los perfiles de copia de seguridad predeterminados como en los personalizados.", "Custom paths currently saved: {count}.": "Rutas personalizadas guardadas actualmente: {count}.", @@ -1078,6 +1410,8 @@ "Customization": "Personalización", "Customize bashrc": "Personalizar bashrc", "Customizing bashrc for root user...": "Personalizando bashrc para usuario root...", + "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite.": "DB Browser for SQLite es una herramienta de alta calidad, visual y de código abierto para crear, diseñar y editar archivos de base compatibles con SQLite.", + "DHCP (automatic)": "DHCP (automático)", "DISABLED unless you enable it": "DESHABILITADO a menos que lo habilites", "DKMS add failed. Check": "Error al agregar DKMS. Controlar", "DKMS build failed.": "Error en la compilación de DKMS.", @@ -1090,15 +1424,34 @@ "DKMS registrations removed.": "Registros DKMS eliminados.", "DNS Resolution": "Resolución DNS", "DNS lookup for a domain": "Búsqueda de DNS para un dominio", + "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)": "plugin DNS utilizado con dns validation (cloudflare, duckdns, ovh...)", + "DNS server written in the client configurations": "Servidor DNS escrito en las configuraciones del cliente", + "DNS server written in the peer configurations (auto or an IP address)": "Servidor DNS escrito en las configuraciones de pares (auto o dirección IP)", + "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid.": "DOGWALK es el esperado proyecto de segundo juego de Blender Studio, centrado en la creación de un área de narración interactiva de tamaño de mordedura. Juega como un perro adorable grande y explora los bosques de invierno con un niño pequeño.", + "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games.": "DOSBox Staging es una continuación moderna de DOSBox un emulador libre y de código abierto que permite la ejecución de software MS-DOS, especialmente videojuegos.", + "DVB device directory": "Directorio de dispositivos DVB", + "Data": "Datos", + "Data location": "Ubicación de los datos", "Data size:": "Tamaño de datos:", + "Data that is deleted with them:": "Datos que se eliminan con ellos:", + "Data volume size in GB": "Tamaño del volumen de datos en GB", + "Data volumes protected": "Volumen de datos protegidos", "Data wipe complete.": "Borrado de datos completo.", "Data wiped from": "Datos borrados de", + "Database management in a single PHP file": "Gestión de bases de datos en un solo archivo PHP", + "Database server proposed on the login page (empty = typed at each login)": "Servidor de base propuesto en la página de inicio de sesión (vacío = escrito en cada login)", + "Databases": "Bases de datos", "Datastore name:": "Nombre del almacén de datos:", + "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow.": "Davos es una herramienta de automatización FTP que analiza periódicamente las ubicaciones de host para nuevos archivos. Puede configurarse para varios propósitos, incluyendo escuchar archivos específicos para aparecer en la ubicación del host, listo para descargar y luego mover, si necesario. También apoya las notificaciones de terminación, así como las llamadas API de abajostream, para promover el flujo de trabajo.", + "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways.": "Ddclient es un cliente Perl utilizado para actualizar las entradas dinámicas de DNS para cuentas en Dynamic DNS Network Service Provider. Fue originalmente escrito por Paul Burry y ahora es principalmente por wimpunk. Tiene la capacidad de actualizar más que solo dyndns y puede conseguir su WAN-ipaddress de algunas maneras diferentes.", "Deactivate Monitor": "Desactivar monitor", "Deactivate ProxMenux Monitor": "Desactivar ProxMenux Monitor", "Debian repositories missing; creating default source file": "Faltan repositorios de Debian; creando un archivo fuente predeterminado", "Decompress backup manually": "Descomprimir la copia de seguridad manualmente", "Decryption failed. The passphrase may be wrong, or the blob is corrupt. Try again?": "Falló el descifrado. La frase de contraseña puede ser incorrecta o el blob está dañado.¿Intentar otra vez?", + "Dedicated container volume (included in backups)": "Volumen de contenedor dedicado (incluido en backups)", + "Dedicated container volumes (included in backups)": "Volúmenes de contenedor dedicados (incluidos en backups)", + "DeepSeek Harness “Everything is a Plugin“.": "DeepSeek Harness “Todo es un Plugin”.", "Default ACLs applied for group inheritance.": "ACL predeterminadas aplicadas para la herencia de grupo.", "Default Credentials": "Credenciales predeterminadas", "Default Gateway": "Puerta de enlace predeterminada", @@ -1110,10 +1463,12 @@ "Default journald configuration restored": "Configuración de diario predeterminada restaurada", "Default location is /mnt/. The share will be mounted here on the host with open permissions so an unprivileged LXC can bind-mount and write to it. For LXC access, bind-mount this path with the LXC Mount Manager.": "La ubicación predeterminada es /mnt/. El recurso compartido se montará aquí en el host con permisos abiertos para que un LXC sin privilegios pueda vincularlo, montarlo y escribir en él. Para acceder a LXC, vincule esta ruta con LXC Mount Manager.", "Default location is /mnt/. The share will be mounted here on the host. Use this path in /etc/fstab. For LXC access, bind-mount this path with the LXC Mount Manager.": "La ubicación predeterminada es /mnt/. El recurso compartido se montará aquí en el host. Utilice esta ruta en /etc/fstab. Para acceder a LXC, vincule esta ruta con LXC Mount Manager.", + "Default login": "Acceso predeterminado", "Default options": "Opciones predeterminadas", "Default options read/write": "Opciones predeterminadas lectura/escritura", "Default will be used:": "Se utilizará el valor predeterminado:", "Default:": "Predeterminado:", + "Default: only what the application needs": "Por defecto: solo lo que la aplicación necesita", "Delete Borg target": "Eliminar objetivo Borg", "Delete Export": "Eliminar Exportar", "Delete Share": "Eliminar Compartir", @@ -1122,7 +1477,10 @@ "Delete archive": "Eliminar archivo", "Delete job": "Eliminar tarea de copia de seguridad", "Delete scheduled backup job?": "¿Eliminar la tarea de copia de seguridad programada?", + "Delete the image to free the space?": "¿Eliminar la imagen para liberar el espacio?", + "Delete the images to free the space?": "¿Eliminar las imágenes para liberar el espacio?", "Delete this corrupt archive and pick another": "elimine este archivo corrupto y elija otro", + "Deluge is a lightweight, Free Software, cross-platform BitTorrent client.": "Deluge es un cliente BitTorrent ligero, Software libre, multiplataforma.", "Dependencies installed successfully": "Dependencias instaladas exitosamente", "Deploy with this configuration?": "¿Implementar con esta configuración?", "Deploying Secure Gateway...": "Implementando Secure Gateway...", @@ -1177,9 +1535,15 @@ "Device added": "Dispositivo agregado", "Device already present in target VM — existing hostpci entry reused": "Dispositivo ya presente en la máquina virtual de destino: se reutiliza la entrada hostpci existente", "Device assignments will be written now and become active after reboot.": "Las asignaciones de dispositivos se escribirán ahora y se activarán después del reinicio.", + "Device configuration cancelled": "Configuración del dispositivo cancelada", "Device hostname": "Nombre de host del dispositivo", + "Device node outside the supported profiles": "Nodo de dispositivo fuera de los perfiles soportados", + "Device outside the supported profiles; NVIDIA and device trees require another profile": "Dispositivo fuera de los perfiles soportados; NVIDIA y árboles de dispositivos requieren otro perfil", "Device path mismatch. Format cancelled.": "la ruta del dispositivo no coincide. Formato cancelado.", + "Device permissions verified for the application user": "Autorizaciones de dispositivo verificadas para el usuario de la aplicación", "Device:": "Dispositivo:", + "Devices added to the container:": "Dispositivos añadidos al contenedor:", + "Devices of the host it asks for:": "Dispositivos del host que solicita:", "Devices to add to VM": "Dispositivos para agregar a VM", "Diff: current system vs backup (--- system +++ backup)": "Diferencia: sistema actual vs copia de seguridad (--- sistema +++ copia de seguridad)", "Different host. Backup from:": "Host diferente. Copia de seguridad procedente de:", @@ -1196,6 +1560,8 @@ "Directory does not exist and was not created.": "El directorio no existe y no fue creado.", "Directory does not exist:": "El directorio no existe:", "Directory error": "error de directorio", + "Directory for the read-only view": "Directorio para la vista de sólo lectura", + "Directory for the read/write view": "Directorio para la vista lectura/escritura", "Directory not found": "Directorio no encontrado", "Directory storage added successfully to Proxmox!": "¡Almacenamiento de directorio agregado exitosamente a Proxmox!", "Directory successfully.": "Directorio con éxito.", @@ -1248,6 +1614,7 @@ "Disk path:": "Ruta del disco:", "Disk safety revalidation failed.": "Error en la revalidación de seguridad del disco.", "Disk safety validation passed.": "Se pasó la validación de seguridad del disco.", + "Disk too small for the common profile": "Disk demasiado pequeño para el perfil común", "Disk unmounted from": "Disco desmontado de", "Disk verified and accessible inside CT at": "Disco verificado y accesible dentro de CT en", "Disk:": "Disco:", @@ -1261,6 +1628,10 @@ "Display physical volumes (LVM)": "Mostrar volúmenes físicos (LVM)", "Display system summary in ASCII format": "Mostrar resumen del sistema en formato ASCII", "Display volume groups (LVM)": "Mostrar grupos de volúmenes (LVM)", + "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer.": "No asuma el puerto 8123 permanece activo después de a bordo en Home Assistant Core 2026.8 o más reciente.", + "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume.": "No reclamar actualizaciones de imagen en el lugar OCI se validan hasta que los rootfs reemplazo y rollback han sido probados sin perder el volumen gestionado /mnt/data.", + "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default.": "No active automáticamente las GPUs integradas de AMD sin soporte. Los overrides HSA son experimentos de compatibilidad manual, no un defecto validado.", + "Do not mount": "No montar", "Do not run the upgrade from the Web UI virtual console (it will disconnect)": "No ejecute la actualización desde la consola virtual de la interfaz de usuario web (se desconectará)", "Do not start the VM until the system has been rebooted.": "No inicie la VM hasta que se haya reiniciado el sistema.", "Do you want ProxMenux to stop it now?": "¿Quieres que ProxMenux lo detenga ahora?", @@ -1304,9 +1675,23 @@ "Do you want to update the existing export?": "¿Quiere actualizar la exportación existente?", "Do you want to update the existing share?": "¿Quieres actualizar el recurso compartido existente?", "Do you want to view the selected backup before restoring?": "¿Quieres ver la copia de seguridad seleccionada antes de restaurar?", + "Docker Mods are only offered for compatible LinuxServer images": "Docker Mods solo se ofrecen para imágenes compatibles de LinuxServer", + "Docker Volume Backup": "Docker Volume Backup", + "Docker/CLI not available yet or no valid answer": "Docker/CLI aún no está disponible o no hay respuesta válida", + "Documents & Notes": "Documentos y notas", + "Documents volume size in GB": "Tamaño del volumen de documentos en GB", + "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki.": "Dokuwiki es un software de wiki de código abierto muy versátil que no requiere una base de datos. Es amado por los usuarios por su sintaxis limpia y legible. La facilidad de mantenimiento, backup e integración lo convierte en el favorito del administrador. Construidos en controles de acceso y conectores de autenticación hacen de DokuWiki especialmente útil en el contexto empresarial y el gran número de plugins aportados por su vibrante comunidad permiten una amplia gama de casos de uso más allá de un wiki tradicional.", + "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience.": "Dolphin Emulator le permite jugar juegos de GameCube y Wii con diversas mejoras gráficas y otras características están disponibles para mejorar su experiencia de juego.", + "Domain for the certificate (example.com)": "Dominio para el certificado (example.com)", + "Doplarr is an *arr request bot for Discord.\"": "Doplarrr es un *arr petición bot para discordia.\"", + "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust.": "Doplarr_rs es un bot de discordia para solicitar medios a través de *arr backends, escrito en Rust.", + "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas.": "Double Commander es un gestor de archivos de código abierto con dos paneles lado a lado. Está inspirado por Total Commander y cuenta con algunas ideas nuevas.", + "Download Spotify music with album art and metadata": "Descargar música de Spotify con el álbum art y metadata", "Download failed for all attempted URLs": "La descarga falló en todos los intentos de URL", + "Download its Compose file from an address": "Descargar su archivo Compose desde una dirección", "Download keyfile": "Descargar archivo clave", "Download latest VirtIO ISO automatically": "Descargue la última ISO de VirtIO automáticamente", + "Downloaded OCI images deleted:": "Imágenes OCI descargadas eliminadas:", "Downloaded amdgpu_top": "Descargado amdgpu_top", "Downloading": "Descargando", "Downloading Helper-Scripts logo...": "Descargando el logotipo de Helper-Scripts...", @@ -1318,45 +1703,86 @@ "Downloading amdgpu_top": "Descargando amdgpu_top", "Downloading official installer...": "Descargando el instalador oficial...", "Downloading pre-existing encrypted backups from this host will fail unless you kept a copy of the current key.": "la descarga de copias de seguridad cifradas preexistentes desde este host fallará a menos que conserve una copia de la clave actual.", + "Downloading the image:": "Descargar la imagen:", "Downloading the latest Fastfetch release...": "Descargando la última versión de Fastfetch...", "Driver blacklist entries removed": "Se eliminaron las entradas de la lista negra de controladores", "Driver blacklist removed for": "Lista negra de controladores eliminada para", "Driver installed successfully. Press Enter to continue...": "Controlador instalado correctamente. Presione Entrar para continuar...", "Drivers :": "Controladores:", "Drivers compiled and installed via DKMS.": "Controladores compilados e instalados mediante DKMS.", + "Dry run completed; no changes were made.": "Corriente seca completada; no se hicieron cambios.", + "Dry run completed; no containers were created.": "Correción seca completada; no se crearon contenedores.", + "Dry run completed; the container and the mounts were not changed.": "Correción seca completada; el contenedor y las monturas no se cambiaron.", + "DuckDNS subdomain without .duckdns.org (comma separated for several)": "Subdominio DuckDNS sin .duckdns.org (comma separado para varios)", + "DuckDNS token from your account at duckdns.org": "DuckDNS token desde tu cuenta en duckdns.org", + "DuckDNS updates the subdomain every 5 minutes. Without UPDATE_IP, DuckDNS itself detects the public IPv4 address of the request.": "DuckDNS actualiza el subdominio cada 5 minutos. Sin UPDATE IP, DuckDNS detecta la dirección IPv4 pública de la solicitud.", + "DuckStation is a PS1 Emulator aiming for the best accuracy and game support.": "DuckStation es un emulador PS1 que busca el mejor accuracy y soporte para juegos.", + "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence.": "Duckdns es un servicio gratuito que señalará un DNS (sub dominios de duckdns.org) a un IP de su elección. El servicio es totalmente gratuito, y no requiere reactivación o publicaciones de foro para mantener su existencia.", "Dumping AMD GPU ROM BIOS via sysfs...": "Volviendo la BIOS de la ROM de la GPU AMD a través de sysfs...", "Duplicate IP addresses found": "Se encontraron direcciones IP duplicadas", "Duplicate parameters cleaned": "Parámetros duplicados limpiados", + "Duplicate variable in the contract; review it before editing": "Variable duplicada en el contrato; revísalo antes de editar", + "Duplicated GPU device in the container": "Dispositivo GPU duplicado en el contenedor", + "Duplicated NVIDIA devices": "Dispositivos NVIDIA duplicados", + "Duplicated VMID in the Proxmox inventory": "VMID duplicado en el inventario de Proxmox", + "Duplicated native directive:": "Directiva nativa duplicada:", + "Duplicated native option": "Opción nativa duplicada", + "Duplicated or invalid stack VMID": "Montaje duplicado o inválido VMID", + "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others.": "Duplicati es un cliente de backup que almacena de forma segura backups cifradas, incrementales y comprimidas en almacenamiento local, servicios de almacenamiento en la nube y servidores de archivos remotos. Funciona con protocolos estándar como FTP, SSH, WebDAV y servicios populares como Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, y muchos otros.", + "Duplicati web interface (password only)": "Interfaz web Duplicati (sólo contraseña)", "Duration": "Duración", "Duration:": "Duración:", + "Dynamic NVIDIA is only validated for unprivileged containers. This profile uses static mounts and must be recreated after the host driver changes.": "La NVIDIA dinámica sólo es validada para contenedores no privilegiados. Este perfil utiliza montajes estáticos y debe recrearse después de que el controlador host cambie.", "EFI disk created and configured on": "Disco EFI creado y configurado en", "EFI storage selection cancelled.": "Se canceló la selección de almacenamiento EFI.", "EFI storage selection failed or was cancelled. VM creation aborted.": "La selección de almacenamiento EFI falló o se canceló. Se canceló la creación de la máquina virtual.", "EMERGENCY PROXMOX SYSTEM REPAIR": "REPARACIÓN DE EMERGENCIA SISTEMA PROXMOX", "ENABLED for restore": "HABILITADO para restaurar", "EXISTS": "EXISTE", + "Each /request command needs a backend: add a [[backends]] block in the same file with the url and api_key of your Sonarr, Radarr or Seerr instance, then restart the container.": "Cada comando /request necesita un backend: añadir un bloque [[backends]] en el mismo archivo con el url y api key de su instancia Sonarr, Radarr o Seerr y reiniciar el contenedor.", "Each LUN will appear as a block device assignable to VMs.": "Cada LUN aparecerá como un dispositivo de bloque asignable a las VM.", + "Each peer gets its configuration and its QR code inside the container: /config/peer1/peer1.conf and /config/peer1/peer1.png, or /config/peer_/peer_.conf when names were given.": "Cada par obtiene su configuración y su código QR dentro del contenedor: /config/peer1/peer1.conf y /config/peer1/peer1.png, o /config/peer Se indica el nombre de usuario/peer se indica el nombre de usuario.conf cuando se dieron nombres.", + "Ebook and audiobook collection manager for Usenet and BitTorrent users.": "Gestor de colección Ebook y audiobook para usuarios de Usenet y BitTorrent.", + "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind.": "Eden es un emulador experimental de código abierto para el Nintendo Switch, construido con rendimiento y estabilidad en mente.", "Edge TPU runtime installed.": "Tiempo de ejecución de Edge TPU instalado.", "Edit raw CT configuration file": "Editar archivo de configuración CT sin formato", "Edit raw VM configuration file": "Editar archivo de configuración de VM sin formato", "Edit the VM machine type to q35 and try again.": "Edite el tipo de máquina VM a q35 y vuelva a intentarlo.", + "Email address for certificate expiry notices (required by ZeroSSL)": "Dirección de correo electrónico para avisos de expiración de certificado (necesario para ZeroSSL)", + "Email address of the LibreDB Studio administrator": "Dirección de correo electrónico del administrador LibreDB Studio", + "Email address of the NetBox admin account": "Dirección de correo electrónico de la cuenta de administración NetBox", + "Emby WebUI": "Emby WebUI", + "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server.": "Emby organiza vídeo, música, TV en vivo y fotos de bibliotecas de medios personales y las transmite a televisores inteligentes, cajas de streaming y dispositivos móviles. Este contenedor se envasa como un servidor multimedia emby independiente.", "Emergency Proxmox System Repair": "Reparación de emergencia del sistema Proxmox", "Emergency recovery:": "Recuperación de emergencia:", + "Empowering the smart home": "Empoderando el hogar inteligente", "Empty": "Vacío", + "Empty exec service check": "Comprobación de servicio de exec", + "Empty or duplicated NVIDIA identity": "Identidad NVIDIA vacía o duplicada", + "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes.": "EmulatorJS es una aplicación emulador basada en Docker que puede simular varios sistemas operating y entornos de dispositivos dentro de contenedores para propósitos de desarrollo, pruebas y aprendizaje.", "Enable": "Permitir", "Enable / disable job timer": "Activar/desactivar el temporizador de copias", "Enable High Availability services": "Activar servicios de alta disponibilidad", "Enable IOMMU in GRUB or ZFS boot": "Habilite IOMMU en el arranque GRUB o ZFS", "Enable IOMMU support if not enabled": "Habilite la compatibilidad con IOMMU si no está habilitado", "Enable IOMMU, reboot the host, and try again.": "Habilite IOMMU, reinicie el host y vuelva a intentarlo.", + "Enable Intel/AMD VA-API video acceleration": "Activar la aceleración de vídeo de Intel/AMD VA-API", + "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping": "Activar la transcodificación NVIDIA y HDR10/Dolby Vision a la cartografía de tono SDR", "Enable Remote Desktop (RDP) before disabling the virtual display.": "Habilite el Escritorio remoto (RDP) antes de deshabilitar la pantalla virtual.", "Enable SSD emulation for this disk?": "¿Habilitar la emulación SSD para este disco?", "Enable TCP BBR/Fast Open control": "Activar control TCP BBR/Fast Open", + "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping": "Activar la transcodificación VA-API y HDR10/Dolby Vision a la cartografía de tono SDR", + "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin": "Activar VA-API, codificación de hardware y cartografía de tono OpenCL en Jellyfin", "Enable VFIO IOMMU support": "Activar soporte VFIO IOMMU", "Enable ZFS autotrim (SSD/NVMe pools)": "Activar ZFS autotrim (pools SSD/NVMe)", + "Enable a mount on an existing Rclone OCI container": "Activar un montaje en un contenedor Rclone OCI existente", + "Enable an optical drive for MakeMKV": "Permite una unidad óptica para MakeMKV", "Enable auto-sync if /var/log exceeds 90% of its size?": "¿Habilitar la sincronización automática si /var/log excede el 90% de su tamaño?", "Enable fast reboots": "Activar reinicios rápidos", "Enable restart on kernel panic": "Activar reinicio ante kernel panic", + "Enable the NVIDIA GPU requested by the image": "Activar la GPU NVIDIA solicitada por la imagen", + "Enable the NVIDIA GPU required by Open WebUI CUDA": "Activar la GPU NVIDIA necesario para Open WebUI CUDA", + "Enable this FUSE mount now and restart the CT?": "¿Habilitar este montaje FUSE ahora y reiniciar la CT?", "Enable/Disable job": "Activar/Desactivar trabajo", "Enabled": "Activado", "Enabled (device pending — load apex module or reboot)": "Habilitado (dispositivo pendiente: cargar el módulo Apex o reiniciar)", @@ -1401,6 +1827,7 @@ "Enter a name for the mount point (used as /mnt/):": "Ingrese un nombre para el punto de montaje (usado como /mnt/):", "Enter a name for the new virtual machine:": "Ingrese un nombre para la nueva máquina virtual:", "Enter a number, or write or paste a command:": "Ingrese un número, o escriba o pegue un comando:", + "Enter a usable IPv4 address with its prefix, for example": "Introduzca una dirección IPv4 usable con su prefijo, por ejemplo", "Enter backup file (.zst):": "Ingrese el archivo de respaldo (.zst):", "Enter backup path (.tar.zst):": "Ingrese la ruta de respaldo (.tar.zst):", "Enter backup path (.vma.zst):": "Ingrese la ruta de respaldo (.vma.zst):", @@ -1489,6 +1916,7 @@ "Enter the number or type the interface name:": "Ingrese el número o escriba el nombre de la interfaz:", "Enter the password for Samba user:": "Ingrese la contraseña para el usuario de Samba:", "Enter the recovery passphrase set when the keyfile was created:": "ingrese la frase de contraseña de recuperación establecida cuando se creó el archivo de claves:", + "Enter the size in whole GB, for example": "Introduzca el tamaño en GB enteros, por ejemplo", "Enter username for Samba server:": "Ingrese el nombre de usuario para el servidor Samba:", "Enter username:": "Introduzca nombre de usuario:", "Enterprise Proxmox Ceph repository disabled": "Repositorio Enterprise Proxmox Ceph deshabilitado", @@ -1497,6 +1925,8 @@ "Enterprise repository returned 401 Unauthorized (no valid subscription). Switch to the no-subscription repository and retry?": "El repositorio empresarial devolvió 401 No autorizado (sin suscripción válida). ¿Cambiar al repositorio sin suscripción y volver a intentarlo?", "Enterprise repository unauthorized and fallback declined by user": "Repositorio empresarial no autorizado y respaldo rechazado por el usuario", "Entropy generation optimization removed": "Se eliminó la optimización de la generación de entropía.", + "Environment entry without an explicit value": "Entrada de entorno sin un valor explícito", + "Environment override for an unknown service:": "Anulación de entorno para un servicio desconocido:", "Equivalent manual flow of disk_host.sh: partition, format, mount, persist, register in Proxmox.": "Flujo manual equivalente de disk_host.sh: particionar, formatear, montar, persistir, registrar en Proxmox.", "Equivalent manual flow of iscsi_host.sh.": "Flujo manual equivalente de iscsi_host.sh.", "Equivalent manual flow used by Local Shared Manager.": "Flujo manual equivalente utilizado por Local Shared Manager.", @@ -1512,12 +1942,16 @@ "Error: No write permissions in directory": "Error: no hay permisos de escritura en el directorio", "Essential Proxmox packages installed": "Paquetes esenciales de Proxmox instalados", "Estimated required free space:": "Espacio libre requerido estimado:", + "Etherpad admin page": "Página de administración Etherpad", "Every 12 hours": "Cada 12 horas", "Every 3 hours": "Cada 3 horas", "Every 6 hours": "Cada 6 horas", + "Every fail2ban jail ships disabled. Enable the ones you need in /config/fail2ban/jail.local, taking the ready-made jails in /config/fail2ban/jail.d/ as reference, then restart the container.": "Cada nave de prisión de fail2ban discapacitados. Habilitar los que necesites en /config/fail2ban/jail.local, tomando las cárceles listas en /config/fail2ban/jail.d/ como referencia, luego reiniciar el contenedor.", "Every hour": "Cada hora", + "Every member of the stack is back to its previous installation.": "Cada miembro de la pila está de vuelta a su instalación anterior.", "Every path in this backup is kernel-tied: the restore applies these paths automatically via the safe-subset filter and re-merges the operator's tuning.": "Cada ruta en esta copia de seguridad está vinculada al kernel: la restauración aplica estas rutas automáticamente a través del filtro de subconjunto seguro y vuelve a fusionar el ajuste del operador.", "Everything restorable in this backup will be restored": "Todo lo que se pueda restaurar en esta copia de seguridad será restaurado", + "Exact name of the remote": "Nombre exacto del remoto", "Example output: rootfs: local-lvm:vm-114-disk-0,size=8G": "Salida de ejemplo: rootfs: local-lvm:vm-114-disk-0,size=8G", "Example target: /dev/sdb": "Destino de ejemplo: /dev/sdb", "Example: /dev/pve/vm-114-disk-0": "Ejemplo: /dev/pve/vm-114-disk-0", @@ -1537,7 +1971,9 @@ "Execute destructive rollback?": "¿Ejecutar reversión destructiva?", "Executing destructive rollback (operator confirmed) ...": "Ejecutando reversión destructiva (confirmado por el operador)...", "Executing:": "Ejecutando:", + "Execution engine for Index-TTS": "Motor de ejecución para Index-TTS", "Existing Groups": "Grupos existentes", + "Existing TLS certificate reused:": "Certificado TLS existente reutilizado:", "Existing file, re-downloading...": "Archivo existente, volviendo a descargar...", "Existing filesystem:": "Sistema de archivos existente:", "Existing hostpci entries detected — they will be reused": "Se detectaron entradas de hostpci existentes: se reutilizarán", @@ -1581,7 +2017,9 @@ "Extended Filesystem 4 (recommended)": "Sistema de archivos extendido 4 (recomendado)", "External ZFS ARC settings restored:": "Configuración externa de ZFS ARC restaurada:", "External ZFS configuration changed after the ProxMenux migration; current file and backup preserved:": "La configuración externa de ZFS cambió después de la migración de ProxMenux; se conservaron el archivo actual y la copia de seguridad:", + "External credential is empty or spans multiple lines": "La credencial externa está vacía o abarca varias líneas", "External disk for backup": "Disco externo para copia de seguridad", + "External field not reserved:": "Campo externo no reservado:", "Extracting NVIDIA installer on host...": "Extrayendo el instalador de NVIDIA en el host...", "Extracting OVA archive...": "Extrayendo archivo OVA...", "Extracting archive...": "Extrayendo archivo...", @@ -1592,7 +2030,9 @@ "Extraction failed. Check log:": "La extracción falló. Registro de verificación:", "Extraction successful": "Extracción exitosa", "FAILED": "FALLIDO", + "FFmpeg version the node uses (7 by default)": "Versión FFmpeg el nodo utiliza (7 por defecto)", "FINAL CONFIRMATION — DATA WILL BE ERASED": "CONFIRMACIÓN FINAL — LOS DATOS SERÁN BORRADOS", + "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface.": "FIleZilla Client es un cliente de FTP, FTPS y SFTP de formato rápido y fiable con muchas características útiles y una interfaz de usuario gráfica intuitiva.", "Fail2Ban - Intrusion Prevention": "Fail2Ban - Prevención de intrusiones", "Fail2Ban Management": "Gestión de Fail2Ban", "Fail2Ban has been removed": "Fail2Ban ha sido eliminado", @@ -1602,6 +2042,7 @@ "Fail2Ban is currently installed.": "Fail2Ban está actualmente instalado.", "Fail2Ban is not installed on this system.": "Fail2Ban no está instalado en este sistema.", "Fail2Ban is running correctly": "Fail2Ban se está ejecutando correctamente", + "Fail2ban is a daemon to ban hosts that cause multiple authentication errors.": "Fail2ban es un daemon para prohibir los hosts que causan múltiples errores de autenticación.", "Failed": "Fallido", "Failed to access log2ram directory": "No se pudo acceder al directorio log2ram", "Failed to access share with provided credentials.": "No se pudo acceder al recurso compartido con las credenciales proporcionadas.", @@ -1748,6 +2189,9 @@ "Failed. See log:": "Fallido. Ver registro:", "Falling back to each installer with --auto-reinstall...": "recurrir a cada instalador con --auto-reinstall...", "Falling back to manual paste mode.": "volver al modo de pegado manual.", + "Fast Usenet downloader with a SABnzbd-compatible API": "Descarga rápida Usenet con una API compatible con SABnzbd", + "Fast, modern web interface for qBittorrent": "Interfaz web rápida y moderna para qBittorrent", + "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper.": "Más rápido es una reimplementación del modelo Whisper de OpenAI usando CTranslate2, que es un motor de inferencia rápida para los modelos Transformer. Este contenedor proporciona un servidor de protocolo de Wyoming para un usuario más rápido.", "Fastfetch Logo Selection": "Selección de logotipo de búsqueda rápida", "Fastfetch configuration updated": "Configuración Fastfetch actualizada", "Fastfetch download URL retrieved successfully.": "La URL de descarga de Fastfetch se recuperó correctamente.", @@ -1759,19 +2203,31 @@ "Fastfetch now displays: System optimised by: ProxMenux": "Fastfetch ahora muestra: Sistema optimizado por: ProxMenux", "Fastfetch removed from system": "Fastfetch eliminado del sistema", "Fastfetch will start automatically in the console": "Fastfetch se iniciará automáticamente en la consola", + "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application.": "Ferdium es una aplicación de escritorio que te ayuda a organizar cómo utilizas tus aplicaciones favoritas por combininglas en una sola aplicación.", "Fetching NVIDIA driver versions supported by your GPU...": "Obteniendo versiones del controlador NVIDIA compatibles con su GPU...", "Figurine installation and configuration completed successfully.": "La instalación y configuración deFigurine se completó con éxito.", "Figurine is not installed.": "Figurine no está instalado.", "Figurine removed from system": "Figurine desinstalado del sistema", + "File bind mounts do not support spaces:": "Las monturas de fijación de archivos no admiten espacios:", + "File processing made easy!": "El procesamiento de archivos se hizo fácil!", "File:": "Archivo:", + "FileBrowser Quantum": "FileBrowser Quantum", + "FileBrowser Quantum (new installation)": "FileBrowser Quantum (nueva instalación)", + "FileDrop is a free, open source file sharing service": "FileDrop es un servicio gratuito de intercambio de archivos de código abierto", + "Files & Downloads": "Descargas de archivos", + "Files volume size in GB": "Tamaño del volumen de archivos en GB", "Filesystem": "Sistema de archivos", "Filesystem Tools Required": "Herramientas del sistema de archivos necesarias", "Filesystem:": "Sistema de archivos:", "Final Confirmation": "Confirmación final", + "Final cleanup of the stack operation completed": "Limpieza final de la pila operación completado", "Final confirmation": "Confirmación final", "Final storage health/status check": "Comprobación final del estado/salud del almacenamiento", + "Finance & Budgeting": "Finanzas & Budgeting", "Find your device using https://finds.synology.com": "Encuentre su dispositivo usando https://finds.synology.com", "Fingerprint:": "Huella digital:", + "Firefly, the easiest using of WireGuard VPN server, plus version of wg-easy.": "Firefly, el uso más fácil del servidor WireGuard VPN, además de la versión de wg-easy.", + "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards.": "Firefox Browser, también conocido como Mozilla Firefox o simplemente Firefox, es un navegador web libre y de código abierto desarrollado por la Fundación Mozilla y su filial, Mozilla Corporation. Firefox utiliza el motor de diseño Gecko para renderizar páginas web, que implementa estándares web actuales y anticipados.", "Firewall allows port": "El cortafuegos permite el puerto", "Firewall settings": "Configuración del cortafuegos", "Firmware :": "Firmware:", @@ -1791,8 +2247,13 @@ "Fix systemd-boot meta-package conflict": "Solucionar el conflicto del metapaquete systemd-boot", "Fix systemd-boot:": "Arreglar systemd-boot:", "Fix: on the host, run": "Solución: en el host, ejecute", + "FlexGet web interface": "Interfaz web FlexGet", + "Flexget is a multipurpose automation tool for all of your media.": "Flexget es una herramienta de automatización multipropósito para todos sus medios.", + "Flowise 3.0.1 and later create the administrator account from the web interface, the first time it is opened.": "Flowise 3.0.1 y después crear la cuenta de administrador de la interfaz web, la primera vez que se abre.", + "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast.": "Flycast es un multiplataforma Sega Dreamcast, Naomi, Naomi 2, y el emulador de onda Atomis derivado del reicast.", "Folder Name": "Nombre de la carpeta", "Folders in /mnt": "Carpetas en /mnt", + "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics.": "Folding@home es un proyecto de computación distribuido para simular dinámicas de proteínas, incluyendo el proceso de plegado de proteínas y los movimientos de proteínas implicados en una variedad de enfermedades. Reúne a los científicos citizen que se ofrecen como voluntarios para realizar simulaciones de dinámicas de proteínas en sus computadoras personales. Las visiones de estos datos están ayudando a los científicos a comprender mejor la biología y brindando nuevas oportunidades para desarrollar la terapéutica.", "Follow post-restore progress live from ProxMenux Monitor → Backups tab after the reboot.": "siga el progreso posterior a la restauración en vivo desde la pestaña ProxMenux Monitor → Copias de seguridad después del reinicio.", "For LVM - Create mount directory and mount:": "Para LVM: cree el directorio de montaje y monte:", "For ZFS, storage ID must start with a letter and use only letters, numbers, dot, dash, underscore or colon.": "Para ZFS, el ID de almacenamiento debe comenzar con una letra y usar solo letras, números, punto, guión, guión bajo o dos puntos.", @@ -1828,11 +2289,15 @@ "Formatting partition": "Formatear partición", "Found": "Encontrado", "Found guest-accessible shares:": "Acciones encontradas accesibles para invitados:", + "Free and easy to use Minecraft server management tool.": "Herramienta de gestión de servidores Minecraft libre y fácil de usar.", "Free public Proxmox repository enabled": "Repositorio público gratuito de Proxmox habilitado", "Free space OK:": "Espacio libre Aceptar:", "Free up disk space": "Liberar espacio en disco", "Free:": "Gratis:", + "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support.": "FreeCAD es un modelador de diseño paramétrico 3D (CAD) de uso general y una aplicación de modelado de información de construcción (BIM) con soporte de elementos finitos (FEM).", "French": "Francés", + "Freshrss is a free, self-hostable aggregator for rss feeds.": "Freshrss es un agregador libre y auto-hostable para las fuentes de rss.", + "Frigate WebUI": "Frigate WebUI", "Full SMART Report": "Informe SMART completo", "Full SMART info and attributes": "Información y atributos SMART completos", "Full format — new GPT partition + filesystem": "Formato completo: nueva partición GPT + sistema de archivos", @@ -1845,6 +2310,7 @@ "Function Level Reset (FLR) not available": "Restablecimiento del nivel de función (FLR) no disponible", "GID already in use:": "GID ya en uso:", "GID in CT": "GID en TC", + "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable.": "GIMP es un editor gráfico de raster libre y de código abierto utilizado para la manipulación de imágenes (retouching) y edición de imágenes, dibujo de forma libre, transcodificación entre diferentes formatos de archivo de imagen y tareas más especializadas. Es extensible por medio de plugins, y scriptable.", "GPU": "GPU", "GPU -> VM Mode Detected": "GPU -> Modo VM detectado", "GPU Already Added": "GPU ya agregada", @@ -1870,6 +2336,7 @@ "GPU already present in target VM — existing hostpci entry reused": "GPU ya presente en la máquina virtual de destino: se reutiliza la entrada hostpci existente", "GPU audio added": "Audio GPU agregado", "GPU audio already present in target VM — existing hostpci entry reused": "El audio de la GPU ya está presente en la máquina virtual de destino: se reutiliza la entrada hostpci existente", + "GPU available for machine learning:": "GPU disponible para el aprendizaje automático:", "GPU driver blacklisted": "Controlador de GPU en lista negra", "GPU guard hook will block concurrent start when another VM is already using this GPU": "El gancho de protección de GPU bloqueará el inicio simultáneo cuando otra VM ya esté usando esta GPU", "GPU host driver blacklisted in /etc/modprobe.d/blacklist.conf": "Controlador de host de GPU incluido en la lista negra en /etc/modprobe.d/blacklist.conf", @@ -1885,11 +2352,14 @@ "GPU passthrough to VMs requires IOMMU to be enabled in the kernel.": "El paso de GPU a las máquinas virtuales requiere que IOMMU esté habilitado en el kernel.", "GPU passthrough was not applied.": "No se aplicó la transferencia de GPU.", "GPU passthrough was skipped (no compatible GPU detected).": "Se omitió el paso de GPU (no se detectó ninguna GPU compatible).", + "GPU recognition uses 8 GB of RAM and a limit of 4 CPU equivalents. These resources were tested in the lab and are not a universal minimum. Compatibility depends on the GPU, the models and the kernel. NVIDIA uses the GPUs of the Toolkit inventory; Intel keeps the CPU topology.": "El reconocimiento GPU utiliza 8 GB de RAM y un límite de 4 CPU equivalentes. Estos recursos se probaron en el laboratorio y no son un mínimo universal. La compatibilidad depende de la GPU, los modelos y el núcleo. NVIDIA utiliza las GPU del inventario de Toolkit; Intel mantiene la topología de la CPU.", "GPU removed from VM": "GPU eliminada de la VM", "GPU removed from VM config": "GPU eliminada de la configuración de VM", + "GPU render device": "GPU dispositivo de renderizado", "GPU switch complete: LXC mode prepared.": "Cambio de GPU completo: modo LXC preparado.", "GPU switch complete: VM mode prepared.": "Cambio de GPU completo: modo VM preparado.", "GPU switch mode completed. No reboot required.": "Modo de cambio de GPU completado. No es necesario reiniciar.", + "GPU verified:": "GPU verificado:", "GPU will be removed from source VM config": "La GPU se eliminará de la configuración de la VM de origen", "GPU will remain configured in source VM": "La GPU permanecerá configurada en la VM de origen", "GPU/TPU - Manual CLI Guide": "GPU/TPU - Guía CLI manual", @@ -1899,6 +2369,8 @@ "GRUB configuration updated": "Configuración de GRUB actualizada", "GRUB_CMDLINE_LINUX_DEFAULT not found in GRUB config": "GRUB_CMDLINE_LINUX_DEFAULT no se encuentra en la configuración de GRUB", "GUI mode (if available)": "Modo GUI (si está disponible)", + "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities.": "GZDoom es un puerto centrico característica para todos los juegos de motores Doom, basado en ZDoom, añadiendo un renderizador OpenGL y potentes capacidades de scripting.", + "Gaming & Leisure": "Gaming & Leisure", "Gateway is not installed.": "La puerta de enlace no está instalada.", "Gateway removed.": "Puerta de enlace eliminada.", "Gateway restarted.": "La puerta de enlace se reinició.", @@ -1908,19 +2380,32 @@ "Generate a new key and authorize it on the server automatically (recommended)": "genere una nueva clave y autorícela en el servidor automáticamente (recomendado)", "Generate a new key, show me the line to paste manually": "Genera una nueva clave, muéstrame la línea para pegar manualmente", "Generate a new keyfile": "generar un nuevo archivo de claves", + "Generated Paperless administrator": "Generado administrador sin papel", + "Generated Tandoor administrator": "Administrador de Tandoor Generado", + "Generated administrator login": "Acceso del administrador generado", "Generating OVF descriptor...": "Generando descriptor OVF...", "Generating dkms.conf...": "Generando dkms.conf...", "Generating manifest...": "Generando manifiesto...", "Generating missing locale:": "Generando configuración regional faltante:", + "Generic SCSI device associated with the drive (e.g. /dev/sg2)": "Dispositivo genérico SCSI asociado con la unidad (por ejemplo /dev/sg2)", "German": "Alemán", "Get a list of all your containers:": "Obtenga una lista de todos sus contenedores:", "Get the actual disk path:": "Obtenga la ruta real del disco:", "Get the container's storage information:": "Obtenga la información de almacenamiento del contenedor:", + "Get up and running with large language models locally": "Levántate y corre con grandes modelos de lenguaje local", "Git installed": "git instalado", + "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality.": "GitQlient es un multiplataforma Cliente Git originalmente forked de QGit. Hoy va más allá de sólo un fork y añade mucha nueva funcionalidad.", + "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React.": "Github Desktop es una aplicación GitHub de código abierto. Está escrito en TipoScript y utiliza React.", "Global settings and SSH jail configured": "Configuración global y cárcel SSH configurada", + "Gluetun/VPN not yet available: this suite does not route downloads through a VPN.": "Gluetun/VPN todavía no está disponible: esta suite no enruta las descargas a través de una VPN.", "Go to \"Manage custom paths\" and remove your custom entry that includes the destination": "vaya a \"Administrar rutas personalizadas\" y elimine la entrada personalizada que incluye el destino.", "Google only ships an official libedgetpu APT repository for Debian/Ubuntu. Hardware passthrough is already written to": "Google solo envía un repositorio APT oficial de libedgetpu para Debian/Ubuntu. La transferencia de hardware ya está escrita en", "Graceful shutdown timed out.": "Se agotó el tiempo de cierre elegante.", + "Grafana is a complete observability stack that allows you to monitor and analyze metrics, logs and traces. It allows you to query, visualize, alert on and understand your data no matter where it is stored.": "Grafana es un conjunto completo de observabilidad que permite monitorear y analizar métricas, registros y trazas. Le permite consultar, visualizar, alertar y comprender sus datos sin importar dónde se almacena.", + "Grafana web interface": "Interfaz web Grafana", + "Grav is a Fast, Simple, and Flexible, file-based Web-platform.": "Grav es una plataforma web rápida, sencilla y flexible basada en archivos.", + "Grocy (new installation; restored data keeps its credentials)": "Grocy (nueva instalación; datos restaurados mantiene su credentials)", + "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility.": "Grocy es un sistema ERP para su cocina! Corta los residuos de alimentos, y maneja tus tareas con esta utilidad brillante.", "Group": "Grupo", "Group 'sharedfiles' already exists inside the CT": "El grupo 'archivos compartidos' ya existe dentro del CT", "Group GID:": "GID de grupo:", @@ -1953,23 +2438,55 @@ "Guided Repair Available": "Reparación guiada disponible", "HA groups will be migrated to HA rules automatically": "Los grupos de HA se migrarán a reglas de HA automáticamente", "HA services disabled (configs preserved)": "Servicios HA deshabilitados (configuraciones preservadas)", + "HAOS One is a community image that runs Docker inside the container. The LXC stays unprivileged, but the inner AppArmor profiles may not be available. The first start downloads Home Assistant Core and its add-ons. If the check fails, the CT and /mnt/data are kept for diagnosis.": "HAOS One es una imagen comunitaria que ejecuta Docker dentro del contenedor. El LXC permanece sin privilegios, pero los perfiles de AppArmor internos pueden no estar disponibles. El primer inicio descarga Home Assistant Core y sus complementos. Si el cheque falla, la CT y /mnt/data se mantienen para el diagnóstico.", + "HAOS One profile declined": "Perfil HAOS One rechazado", + "HTTP service check without a saved URL": "Control de servicio HTTP sin una URL guardada", + "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API.": "Habridge emula Philips Hue API a otras pasarelas de automatización casera como un Amazon Echo/Dot Gen 1 (gen 2 tiene problemas descubriendo ha-bridge) u otros sistemas que apoyan Philips Hue. El puente maneja comandos básicos tales como On, Off y comandos de brillo del protocolo de hue. Este puente puede controlar la mayoría de los dispositivos que tienen una API distinta.", + "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs.": "HandBrake es una herramienta de código abierto, construida por voluntarios, para convertir vídeo de casi cualquier formato a una selección de codecs modernos y ampliamente apoyados.", "Hardening SSH: setting MaxAuthTries to 3...": "Endurecimiento de SSH: configuración de MaxAuthTries en 3...", + "Hardware acceleration for Emby": "aceleración de hardware para Emby", + "Hardware acceleration for FileFlows": "aceleración de hardware para FileFlows", + "Hardware acceleration for Frigate": "aceleración de hardware para Frigate", + "Hardware acceleration for Jellyfin": "aceleración de hardware para Jellyfin", + "Hardware acceleration for Plex": "aceleración de hardware para Plex", + "Hardware acceleration for Roon Server": "aceleración de hardware para Roon Server", + "Hardware acceleration for Stremio": "aceleración de hardware para Stremio", + "Hardware acceleration for Tdarr": "aceleración de hardware para Tdarr", + "Hardware acceleration options:": "Opciones de aceleración de hardware:", "Hardware compatibility — these items will be skipped to keep the boot safe:": "Compatibilidad de hardware: estos elementos se omitirán para mantener el arranque seguro:", "Hardware passthrough is already configured — the Coral device is visible inside the container as /dev/apex_0 (M.2) and/or /dev/bus/usb (USB).": "La transferencia de hardware ya está configurada: el dispositivo Coral es visible dentro del contenedor como /dev/apex_0 (M.2) y/o /dev/bus/usb (USB).", "Hardware: GPUs and Coral-TPU": "Hardware: GPU y Coral-TPU", + "Have a Private Social Space Hosted on Your Site": "Tener un espacio social privado acogido en su sitio", "Have valid backups of all VMs and containers": "Tener copias de seguridad válidas de todas las máquinas virtuales y contenedores", + "Health check failed:": "El cheque de salud falló:", + "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface.": "Healthchecks es un vigilante para sus trabajos de cron. Es un servidor web que escucha pings de tus trabajos de cron, además de una interfaz web.", + "HedgeDoc gives you access to all your files wherever you are.": "HedgeDoc te da acceso a todos tus archivos donde estés.", + "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way.": "Heimdall es una manera de organizar todos esos enlaces a sus sitios web y aplicaciones web más utilizados de una manera sencilla.", + "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking.": "Helium es un navegador web basado en Chromium hecho para personas, con amor. Privacidad primero con bloqueo de anuncios imparcial.", "Help & Info (commands)": "Ayuda e información (comandos)", "Help & Information": "Ayuda e información", "Help and Info": "Ayuda e información", "Help and Info Commands": "Comandos de ayuda e información", "Helper-Scripts logo applied": "Logotipo de Helper-Scripts aplicado", + "Hermes WebUI": "Hermes WebUI", "Hidden for safety": "Escondido por seguridad", "Hidden:": "Oculto:", "High Availability services have been enabled successfully": "Los servicios de alta disponibilidad se han habilitado correctamente", "High Availability setup completed": "Configuración de alta disponibilidad completada", + "High availability resources are not supported by this profile": "Este perfil no cuenta con recursos de alta disponibilidad", + "High availability resources are not supported for stacks": "No se admiten recursos de alta disponibilidad para pilas", "High risk confirmation": "Confirmación de alto riesgo", "High-Risk GPU Power State": "Estado de energía de la GPU de alto riesgo", + "Home Assistant": "Home Assistant", + "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server": "Home Assistant Core - Automatización de código abierto que pone el control local y la privacidad primero. Desarrollado por una comunidad mundial de tinkerers y entusiastas del DIY. Perfecto para funcionar en un Raspberry Pi o un servidor local", + "Home Assistant OS cannot be checked without an IP address": "Home Assistant OS no se puede verificar sin una dirección IP", + "Home Assistant OS did not pass the Supervisor, Core and Observer checks": "Home Assistant OS no pasó los controles del Supervisor, Core y Observer", + "Home Assistant OS ready: Supervisor, Core and Observer running": "Home Assistant OS listo: Supervisor, Core y Observador funcionando", + "Home Assistant OS was not started: its addresses will be known once Core is running.": "Home Assistant OS no se inició: sus direcciones serán conocidas una vez que Core esté funcionando.", + "Home Automation systems": "Home Sistemas de automatización", "Home-Lab-Club logo applied": "Logotipo de Home-Lab-Club aplicado", + "HomeKit support for the impatient.": "Soporte HomeKit para el impaciente.", + "Homebridge UI": "Homebridge UI", "Host": "Anfitrión", "Host Backup → Borg": "Copia de seguridad del host → Borg", "Host Backup → Local archive": "Copia de seguridad del host → Archivo local", @@ -1985,18 +2502,31 @@ "Host GPU detected": "GPU del host detectada", "Host GPU is already bound to vfio-pci. Host reconfiguration/reboot should not be required for this VM-to-VM reassignment.": "La GPU del host ya está vinculada a vfio-pci. No debería ser necesario reconfigurar/reiniciar el host para esta reasignación de VM a VM.", "Host IP": "IP del host", + "Host Management": "Host Management", "Host Mount Path": "Ruta de montaje del host", "Host NFS/Samba as Proxmox Storage (pvesm)": "Aloje NFS/Samba como almacenamiento en Proxmox (pvesm)", "Host Path": "Ruta del host", "Host Path:": "Ruta del host:", "Host Storage (NFS / Samba via Proxmox)": "Almacenamiento de host (NFS/Samba vía Proxmox)", + "Host USB bus": "Hoster autobús USB", "Host VFIO config was already up to date — no reboot needed.": "La configuración del host VFIO ya estaba actualizada; no es necesario reiniciar.", "Host VFIO configuration already up to date": "Configuración del host VFIO ya actualizada", "Host VFIO configuration changed (initramfs updated). Reboot required before starting the VM.": "La configuración de VFIO del host cambió (initramfs actualizado). Es necesario reiniciar antes de iniciar la máquina virtual.", "Host VFIO configuration changed — reboot required before starting the VM.": "La configuración de VFIO del host cambió: es necesario reiniciar antes de iniciar la máquina virtual.", "Host already in VFIO mode — skipping host reconfiguration for VM reassignment": "El host ya está en modo VFIO: omitir la reconfiguración del host para la reasignación de VM", + "Host audio devices": "Dispositivos de audio hosts", "Host backup attached to PVE job": "Copia de seguridad del host adjunta al trabajo PVE", + "Host data is not restored by the backup; confirm it with --acknowledge-external-data": "Los datos de host no son restaurados por el backup; confirme con --acknowledge-external-data", + "Host device node": "Nodo de dispositivo host", + "Host directories are not included in the backup and are not reverted by a recovery.": "Los directorios host no están incluidos en el backup y no son revertidos por una recuperación.", + "Host directories are not included in the backups and are not reverted by a recovery.": "Los directorios hosts no están incluidos en los backups y no son revertidos por una recuperación.", + "Host directories cannot be part of the vzdump backup": "Los directorios de host no pueden ser parte del backup de vzdump", + "Host directories that are kept, with their content:": "Directorios del host que se mantienen, con su contenido:", + "Host directory": "Directorio del host", + "Host directory (created if it does not exist)": "Directorio host (creado si no existe)", + "Host directory (not included in Proxmox backups)": "Directorio del host (no incluido en backups de Proxmox)", "Host directory access for unprivileged containers has been prepared above": "El acceso al directorio de host para contenedores sin privilegios se preparó anteriormente", + "Host directory kept, with its content:": "El directorio host se mantiene, con su contenido:", "Host directory permissions updated — unprivileged containers can now access it": "Permisos del directorio de host actualizados: los contenedores sin privilegios ahora pueden acceder a él", "Host directory:": "Directorio de host:", "Host fstab CIFS Mounts:": "Montajes CIFS del host fstab:", @@ -2008,7 +2538,14 @@ "Host fstab NFS mounts:": "Montajes NFS del host fstab:", "Host fstab mounts (not registered as Proxmox storage):": "Montajes de host fstab (no registrados como almacenamiento Proxmox):", "Host identity (hostname, hosts)": "Identidad del host (nombre de host, hosts)", + "Host kernel module loaded:": "Módulo host kernel cargado:", + "Host monitor configured: shared PID and network namespaces, LXCFS disabled in this container": "Monitor de host configurado: PID compartido y espacios de red, LXCFS deshabilitado en este contenedor", + "Host monitor verified: PID and network namespaces and memory match the host": "Monitor de host verificado: PID y espacio de nombres de red y memoria coinciden con el host", + "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks.": "Monitor del host: PID compartido/network y acceso privilegiado. Una imagen comprometida podría afectar a Proxmox. Úsalo sólo en redes de confianza.", + "Host monitoring declined": "Monitorización del host rechazada", + "Host path for": "Ruta del host para", "Host permissions applied (o+rwx + default ACL) — unprivileged LXCs can read/write through bind-mounts": "Permisos de host aplicados (o+rwx + ACL predeterminada): los LXC sin privilegios pueden leer/escribir a través de montajes vinculados", + "Host system path": "Ruta del sistema host", "Host write access confirmed.": "Acceso de escritura del host confirmado.", "Hostname": "Nombre de host", "Hot changes applied. No reboot needed for these paths.": "Se aplicaron cambios importantes. No es necesario reiniciar para estas rutas.", @@ -2020,12 +2557,17 @@ "How do you want to select the Samba server?": "¿Cómo desea seleccionar el servidor Samba?", "How do you want to select the folder to export?": "¿Cómo desea seleccionar la carpeta para exportar?", "How do you want to select the folder to share?": "¿Cómo desea seleccionar la carpeta para compartir?", + "How is it installed?": "¿Cómo se instala?", + "How is the image described?": "¿Cómo se describe la imagen?", "How to Access an LXC Terminal": "Cómo acceder a una terminal LXC", "How to Access an LXC Terminal from Proxmox Host": "Cómo acceder a una terminal LXC desde Proxmox Host", "How to schedule": "Cómo programar", + "Htpcmanager is a front end for many htpc related applications.": "Htpcmanager es un extremo frontal para muchas aplicaciones relacionadas con htpc.", "I have read this": "He leído esto", "I/O priority configured": "Prioridad de E/S configurada", "ID already in use. Please choose another.": "ID ya en uso. Por favor elige otro.", + "IGDB": "IGDB", + "IGDB Client ID": "IGDB ID de cliente", "IMPORTANT": "IMPORTANTE", "IMPORTANT NOTES:": "NOTAS IMPORTANTES:", "IMPORTANT PREREQUISITES:": "PRERREQUISITOS IMPORTANTES:", @@ -2062,7 +2604,14 @@ "IOMMU was configured during this wizard and a reboot is pending.": "IOMMU se configuró durante este asistente y hay un reinicio pendiente.", "IOMMU/VFIO configuration reverted": "Configuración de IOMMU/VFIO revertida", "IP": "IP", + "IP address": "Dirección IP", + "IP address and firewall of the host": "Dirección IP y cortafuegos del host", + "IP address of this container for the certificate (0.0.0.0 if unknown)": "Dirección IP de este contenedor para el certificado (0.0.0.0 si se desconoce)", + "IP address:": "Dirección IP:", "IP or hostname of the PVE node hosting the Borg server LXC:": "IP o nombre de host del nodo PVE que aloja el servidor Borg LXC:", + "IPv4 address of the container": "Dirección IPv4 del contenedor", + "IPv4 address of the containers": "Dirección IPv4 de los contenedores", + "IPv4 gateway (empty = no outbound route)": "Puerta de enlace IPv4 (vacío = sin ruta de salida)", "ISO": "ISO", "ISO created successfully:": "ISO creada con éxito:", "ISO image — installation images": "Imagen ISO: imágenes de instalación", @@ -2095,6 +2644,7 @@ "If this happens, you can restore the backup from the 'Subscription Banner Removal' option in 'Uninstall optimizations'.": "Si esto sucede, puede restaurar la copia de seguridad desde la opción 'Eliminación del banner de suscripción' en 'Optimizaciones de desinstalación'.", "If this node runs hyper-converged Ceph: ensure Ceph is 19.x (Squid) BEFORE upgrading PVE.": "Si este nodo ejecuta Ceph hiperconvergente: asegúrese de que Ceph sea 19.x (Squid) ANTES de actualizar PVE.", "If upgrade fails:": "Si la actualización falla:", + "If you answer No, Glances is installed without privileges and monitors ONLY its own LXC, not Proxmox.": "Si responde No, Glances se instala sin privilegios y monitoriza SOLO su propio LXC, no Proxmox.", "If you are sure you want to use it, please remove the": "Si está seguro de que desea utilizarlo, elimine el", "If you choose No, install": "Si elige No, instale", "If you continue, some adjustments may be duplicated or conflict with those already made by xshok.": "Si continúa, es posible que algunos ajustes se dupliquen o entren en conflicto con los que ya realizó xshok.", @@ -2104,11 +2654,29 @@ "If you want HDMI/analog audio inside the VM, select the audio controller(s) to pass through along with the GPU.": "Si desea audio HDMI/analógico dentro de la VM, seleccione los controladores de audio para pasar junto con la GPU.", "If you want to use a physical monitor on the passthrough GPU:": "Si desea utilizar un monitor físico en la GPU de paso:", "If your DHCP has a static reservation for the old MAC, update it.": "si su DHCP tiene una reserva estática para la MAC anterior, actualícela.", + "Image": "Imagen", "Image Source Directory": "Directorio de origen de imágenes", + "Image cache": "Caché de imágenes", + "Image compatibility restored:": "Compatibilidad de imagen restaurada:", + "Image compatibility verified:": "Compatibilidad de imagen verificada:", "Image directory:": "Directorio de imágenes:", + "Image download failed:": "Descarga de imagen falló:", + "Image downloaded": "Imagen descargada", "Image file not found:": "Archivo de imagen no encontrado:", "Image imported:": "Imagen importada:", + "Image integrity verified": "Verificación de la integridad de la imagen", + "Image not allowed for the host monitor profile": "Imagen no permitida para el perfil del monitor host", + "Image reference (for example ghcr.io/user/application:latest)": "Referencia de imagen (por ejemplo ghcr.io/user/application:latest)", + "Image that is not in the catalog": "Imagen que no está en el catálogo", + "Image:": "Imagen:", "Images to import:": "Imágenes para importar:", + "Immich CUDA requires NVIDIA driver 545 or later": "Immich CUDA requiere controlador NVIDIA 545 o posterior", + "Immich GPU profile not validated": "Perfil GPU Immich no validado", + "Immich configuration cancelled": "Configuración Immich cancelada", + "Immich device without a validated translation": "dispositivo Immich sin una traducción validada", + "Immich requires CUDA compute capability 5.2 or later": "Immich requiere CUDA capacidad de cálculo 5.2 o posterior", + "Immich runtime without a validated translation": "Immich tiempo de ejecución sin una traducción validada", + "Immich server": "Servidor Immich", "Import — disk image imports": "Importar: importaciones de imágenes de disco", "Import Disk Image to VM": "Importar imagen de disco a VM", "Import Disk to LXC": "Importar disco a LXC", @@ -2149,24 +2717,58 @@ "Incompatible Reset Capability for Intel GPU": "Capacidad de reinicio incompatible para GPU Intel", "Incompatible Reset Capability for Intel dGPU": "Capacidad de reinicio incompatible para Intel dGPU", "Incompatible archive": "Archivo incompatible", + "Incompatible image platform": "Plataforma de imagen incompatible", + "Incompatible instance directory": "Directorio de instancias incompatibles", + "Incompatible instance record": "Registro de instancia incompatible", + "Incompatible record": "Registro incompatible", + "Incompatible stack assembly": "Montaje de pila incompatible", "Incompatible version": "versión incompatible", + "Incomplete NVIDIA identity": "Identidad incompleta NVIDIA", + "Incomplete NVIDIA inventory": "Incompleto inventario de NVIDIA", + "Incomplete Proxmox inventory": "Incompleta Proxmox inventario", + "Incomplete Proxmox inventory; recovery blocked": "Incompleto Proxmox inventario; recuperación bloqueada", + "Incomplete container removed:": "Removido de contenedores incompletos:", + "Incomplete dependency order": "Orden de dependencia incompleta", + "Incomplete file recipe or unknown paths": "Receta de archivos incompleta o caminos desconocidos", + "Incomplete gzip layer": "Capa de gzip incompleta", + "Incomplete or incompatible Proxmox inventory": "Incompleto o incompatible Proxmox inventario", + "Incomplete primary network": "Red primaria incompleta", + "Incomplete stack order": "Orden de pila incompleta", + "Incomplete stack removed": "Montaje completo eliminado", + "Inconsistent adaptation profile and recipe": "Perfil de adaptación inconsistente y receta", + "Inconsistent host monitor profile": "Perfil de monitor de host inconsistente", + "Inconsistent stack identity": "Identidad de pila inconsistente", + "Inconsistent stack membership for": "Miembro de pila inconsistente para", "Increase container RAM temporarily to": "Aumente temporalmente la RAM del contenedor para", "Increase file and process limits for advanced workloads": "Aumente los límites de archivos y procesos para cargas de trabajo avanzadas", "Increase various system limits": "Aumentar varios límites del sistema", "Increase vzdump backup speed": "Aumentar velocidad de copias vzdump", "Increasing maximum file system open files...": "Aumentando el número máximo de archivos abiertos en el sistema de archivos...", "Increasing various system limits...": "Aumentando varios límites del sistema...", + "Independent LXC applications installed": "Aplicaciones LXC independientes instaladas", + "Independent LXCs: no main container or hookscript. Each one keeps its own Start with Proxmox setting.": "LXC independientes: sin contenedor principal ni hookscript. Cada uno mantiene su propio ajuste de Inicio con Proxmox.", + "Independent applications, without a main container.": "Aplicaciones independientes, sin un contenedor principal.", + "Indexers and quality profiles still need to be configured.": "Los índices y perfiles de calidad todavía necesitan ser configurados.", "Inherited retention:": "Retención heredada:", "Inherited schedule:": "Horario heredado:", + "Initial Nextcloud administrator": "Administrador inicial Nextcloud", + "Initial Nextcloud settings applied": "Ajustes iniciales Nextcloud aplicados", + "Initial Paperless-ngx administrator": "Administrador inicial Paperless-ngx", + "Initial Tandoor administrator": "Administrador inicial de Tandoor", + "Initial administrator created:": "Administrador inicial creado:", + "Initial administrator user": "Usuario administrador inicial", "Initializing Borg repository if needed...": "Inicializando el repositorio de Borg si es necesario...", "Initiator IQN is authorised on the target": "El iniciador IQN está autorizado en el objetivo.", "Initiator IQN:": "IQN del iniciador:", + "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers.": "Inkscape es un software de gráficos vectoriales de calidad profesional que funciona en Linux, Mac OS X y Windows computadoras de escritorio.", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN": "Dentro del LXC, crea el administrador: consola kimai:user:crear Your USERNAME Your EMAIL ROLE SUPER ADMIN", "Inspect disks before any action": "Inspeccionar los discos antes de cualquier acción.", "Inspect host device nodes": "Inspeccionar los nodos del dispositivo host", "Inspect passthrough/kernel events": "Inspeccionar eventos de transferencia/kernel", "Inspect storage config block:": "Inspeccionar el bloque de configuración de almacenamiento:", "Inspection commands run directly. Template commands [T] require parameter substitution.": "Los comandos de inspección se ejecutan directamente. Los comandos de plantilla [T] requieren la sustitución de parámetros.", "Install": "Instalar", + "Install (experimental)": "Instalar (experimental)", "Install ALL utilities": "Instalar TODAS las utilidades", "Install AMD GPU drivers inside the guest.": "Instale los controladores de GPU AMD dentro del invitado.", "Install CIFS client packages inside CT:": "Instale paquetes de cliente CIFS dentro de CT:", @@ -2185,6 +2787,7 @@ "Install Samba inside CT:": "Instale Samba dentro de CT:", "Install ZFS auto-snapshot": "Instalar ZFS auto-snapshot", "Install a version from the branch the kernel names.": "instale una versión de la rama de los nombres del kernel.", + "Install an image that is not in the catalog": "Instalar una imagen que no está en el catálogo", "Install analysis tools": "Instalar herramientas de análisis", "Install and configure": "Instalar y configurar", "Install and configure Fastfetch": "Instalar y configurar Fastfetch", @@ -2203,27 +2806,35 @@ "Install server packages inside CT:": "Instale paquetes de servidor dentro de CT:", "Install terminal multiplexers": "Instalar multiplexores de terminales", "Install the Edge TPU runtime (libedgetpu1-std)": "Instale el tiempo de ejecución de Edge TPU (libedgetpu1-std)", + "Install this image?": "¿Instalar esta imagen?", "Install with Cloud-Init script": "Instalar con el script Cloud-Init", "Install with ISO from UUP Dump": "Instalar con ISO desde UUP Dump", + "Install with advanced settings": "Instalar con configuración avanzada", + "Install with default settings": "Instalar con la configuración predeterminada", "Install with personal ISO": "Instalar con ISO personal", + "Install with this configuration?": "¿Instalar con esta configuración?", "Install with traditional method": "Instalar con método tradicional.", "Install with: apt-get install open-iscsi": "Instalar con: apt-get install open-iscsi", "Install/Update Coral TPU on Host": "Instalar/actualizar Coral TPU en el host", "Install/Update NVIDIA Drivers (Host + LXC)": "Instalar/actualizar controladores NVIDIA (Host + LXC)", "Installation Complete": "Instalación completa", + "Installation completed": "Instalación terminada", "Installation completed.": "Instalación completada.", "Installation completed. Please reboot the server manually as soon as possible.": "Instalación completada. Reinicie el servidor manualmente lo antes posible.", "Installation completed. Press Enter to continue...": "Instalación completada. Presione Entrar para continuar...", "Installation failed": "La instalación falló", "Installation finished but drivers are not loaded. A reboot may be required.": "La instalación finalizó pero los controladores no están cargados. Es posible que sea necesario reiniciar.", + "Installation incomplete. These containers and their data are kept:": "Instalación incompleta. Estos contenedores y sus datos se guardan:", "Installation log:": "Registro de instalación:", "Installation summary": "Resumen de instalación", "Installed": "Instalado", "Installed at:": "Instalado en:", "Installed components:": "Componentes instalados:", + "Installed:": "Instalado:", "Installer already downloaded and verified.": "Instalador ya descargado y verificado.", "Installer copied to container.": "Instalador copiado al contenedor.", "Installer downloaded.": "Instalador descargado.", + "Installer file not found:": "Archivo de Installer no encontrado:", "Installer finished with errors.": "El instalador terminó con errores.", "Installer not found:": "Instalador no encontrado:", "Installing": "Instalación", @@ -2274,9 +2885,14 @@ "Installing pigz...": "Instalando pigz...", "Installing required dependencies...": "Instalando las dependencias requeridas...", "Installing required package: git": "Instalación del paquete requerido: git", + "Installing required packages...": "Instalar paquetes necesarios...", "Installing required tools...": "Instalando las herramientas necesarias...", "Installing selected utilities": "Instalación de utilidades seleccionadas", "Installing system utilities...": "Instalando utilidades del sistema...", + "Installing the new image": "Instalación de la nueva imagen", + "Installing the new image...": "Instalar la nueva imagen...", + "Installing the new image:": "Instalar la nueva imagen:", + "Installing the stack startup hook...": "Instalar el gancho de arranque de la pila...", "Installing zfs-auto-snapshot package...": "Instalando el paquete zfs-auto-snapshot...", "Installs essential packages if missing": "Instala paquetes esenciales si faltan", "Insufficient Disk Space": "Espacio en disco insuficiente", @@ -2288,8 +2904,17 @@ "Intel CPU detected": "CPU Intel detectada", "Intel GPU Tools installation completed!": "¡Se completó la instalación de las herramientas Intel GPU!", "Intel GPU(s) detected:": "GPU Intel detectadas:", + "Intel VA-API + OpenCL (official mod)": "Intel VA-API + OpenCL (modal oficial)", "Intel VA-API drivers installed.": "Controladores Intel VA-API instalados.", "Intel iGPU passthrough configured.": "Paso a través de Intel iGPU configurado.", + "Intel render device for recognition": "Dispositivo de renderización Intel para reconocimiento", + "Intel/AMD (VA-API and QSV)": "Intel/AMD (VA-API y QSV)", + "Intel/AMD (VA-API)": "Intel/AMD (VA-API)", + "Intel/AMD (streaming rendering and encoding)": "Intel/AMD (reducción y codificación)", + "Intel/AMD VA-API": "Intel/AMD VA-API", + "Intel/AMD VA-API (no OpenCL mod)": "Intel/AMD VA-API (no OpenCL mod)", + "Intel/AMD render node": "Nodo de renderización Intel/AMD", + "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters – building great software.": "IntelliJ IDEA le ayuda a escribir código más rápido con herramientas que eliminan tareas tediosas y le permiten concentrarse en lo que importa – construir un gran software.", "Interactive (guided, prompts visible)": "Interactivo (guiado, indicaciones visibles)", "Interactive process viewer (press q to exit)": "Visor de procesos interactivo (presione q para salir)", "Interface": "Interfaz", @@ -2303,41 +2928,169 @@ "Interfaces to Remove": "Interfaces para eliminar", "Internal error: NVIDIA installer path is empty or file not found.": "Error interno: la ruta del instalador de NVIDIA está vacía o no se encuentra el archivo.", "Internal error: missing arguments in pmx_prepare_host_shared_dir": "Error interno: faltan argumentos en pmx_prepare_host_shared_dir", + "Internal subnet of the tunnel (change it only if it clashes)": "Subnet interno del túnel (cambiarlo sólo si choca)", + "Interrupted operation": "Operación interrumpida", + "Interrupted operation:": "Interrupted operación:", + "Interrupted stack operation found": "Montaje interrumpido operación encontrado", "Invalid 'proxmox-ve' candidate (not 9.x or none). Please verify your repository configuration and network, then retry.": "Candidato 'proxmox-ve' no válido (ni 9.x ni ninguno). Verifique la configuración y la red de su repositorio y luego vuelva a intentarlo.", + "Invalid ALLOWED_HOSTS value": "Valor inválido ALLOWED HOSTS", + "Invalid Home Assistant OS check timeout": "Inválido Home Assistant OS check timeout", "Invalid ID": "ID no válida", + "Invalid Intel render path": "Ruta de renderización Intel no válida", + "Invalid Jellyfin path:": "Camino inválido Jellyfin:", + "Invalid MAC address:": "Dirección MAC inválida:", + "Invalid NVIDIA destination": "Destino NVIDIA inválido", + "Invalid NVIDIA device:": "Dispositivo NVIDIA inválido:", + "Invalid Nextcloud volume": "Volumen inválido Nextcloud", + "Invalid OCI Entrypoint": "Punto de entrada OCI inválido", + "Invalid OCI digest": "Inválido OCI digest", + "Invalid OCR language:": "Idioma OCR inválido:", "Invalid Option": "Opción no válida", "Invalid Path": "Ruta no válida", + "Invalid Proxmox inventory": "Inválido Proxmox inventario", + "Invalid Python index:": "Índice de pitón inválido:", + "Invalid Python module:": "Módulo Python inválido:", + "Invalid Python package:": "Paquete de pitón inválido:", + "Invalid Python path in the repair:": "Camino de pitón inválido en la reparación:", + "Invalid Unpackerr variable": "Inválido Unpackerr variable", + "Invalid VFS cache mode": "Modo de caché VFS inválido", "Invalid VMID": "VMID no válido", + "Invalid VMID or timeout": "VMID inválido o timeout", + "Invalid VMID:": "VMID inválido:", "Invalid ZFS pool name.": "Nombre de grupo ZFS no válido.", + "Invalid absolute mount path": "Camino de montaje absoluto inválido", + "Invalid absolute path; avoid spaces, commas and relative segments": "Ruta absoluta no válida; evita espacios, comas y segmentos relativos", + "Invalid acceleration profile": "Perfil de aceleración inválido", + "Invalid access address:": "Dirección de acceso inválida:", + "Invalid administrator email": "Correo electrónico del administrador inválido", + "Invalid administrator user name": "Nombre del usuario del administrador inválido", + "Invalid base VMID": "Base inválida VMID", + "Invalid check package:": "Paquete de comprobación inválido:", + "Invalid configuration path:": "Vía de configuración inválida:", + "Invalid consume/export volumes": "Volumen de consumo/exportación inválidos", + "Invalid container path:": "Carril de contenedor inválido:", + "Invalid declarative entrypoint": "Punto de entrada declarativo inválido", + "Invalid declarative stop signal": "Parada declarativa inválida signal", + "Invalid declarative working directory": "Directorio de trabajo declarativo inválido", + "Invalid device UID:": "Dispositivo no válido UID:", + "Invalid device mode": "Modo de dispositivo inválido", + "Invalid device mode:": "Modo de dispositivo inválido:", + "Invalid device path:": "Camino del dispositivo inválido:", + "Invalid device paths for": "Rutas de dispositivo no válidas para", "Invalid group name. Use letters, digits, underscore or hyphen, and start with a letter or underscore.": "Nombre de grupo no válido. Utilice letras, dígitos, guiones bajos o guiones y comience con una letra o un guión bajo.", + "Invalid health check": "Control de salud inválido", + "Invalid healthcheck path": "Camino de control de salud inválido", + "Invalid healthcheck port": "Puerto de control de salud inválido", + "Invalid healthcheck request timeout": "Tiempo de solicitud de salud inválido", + "Invalid healthcheck scheme": "Plan de control de salud inválido", + "Invalid healthcheck stability period": "Período de estabilidad de control de salud inválido", + "Invalid healthcheck timeout": "Hora de salida de salud inválida", + "Invalid host kernel module name:": "Nombre del módulo de host inválido:", + "Invalid host monitor PID": "Monitor de host inválido PID", + "Invalid host path:": "Camino del host inválido:", + "Invalid image probe descriptor": "Descriptor de sonda de imagen inválida", "Invalid input": "Entrada no válida", + "Invalid internal volume": "Volumen interno inválido", + "Invalid list:": "Lista inválida:", + "Invalid machine learning CPU allocation:": "Aprendizaje de máquina inválida CPU:", + "Invalid machine learning resources": "Recursos de aprendizaje automático inválidos", + "Invalid main member or duplicated members": "Miembros principales inválidos o miembros duplicados", + "Invalid media path": "Camino de los medios inválidos", + "Invalid media volume": "Volumen de medios inválidos", + "Invalid mediafiles volume": "Volumen de los archivos multimedia inválidos", + "Invalid minimum version:": "Versión mínima válida:", + "Invalid mount name": "Nombre de montaje inválido", + "Invalid mount type": "Tipo de montaje inválido", "Invalid name": "Nombre no válido", "Invalid name. Use only letters, numbers, hyphens and underscores.": "Nombre no válido. Utilice únicamente letras, números, guiones y guiones bajos.", + "Invalid native entrypoint": "Punto de entrada nativo inválido", + "Invalid octal permissions": "Permisos octales no válidos", "Invalid option": "Opción no válida", "Invalid option, please try again.": "Opción no válida, inténtalo de nuevo.", "Invalid option. Skipping.": "Opción no válida. Salto a la comba.", + "Invalid or duplicated mount path": "Camino de montaje inválido o duplicado", + "Invalid or duplicated network sysctl": "Sistema de red inválido o duplicado", "Invalid parameters for bind mount": "Parámetros no válidos para montaje de enlace", + "Invalid path": "Ruta no válida", + "Invalid path in the NVIDIA inventory": "Camino inválido en el inventario de NVIDIA", + "Invalid post-start timeout in the configuration:": "Tiempo inválido post-start en la configuración:", + "Invalid private bridge": "Puente privado inválido", + "Invalid private network": "Red privada inválida", + "Invalid prlimit value": "Valor de primitivo inválido", + "Invalid process limits format": "Inválido límites de proceso formato", + "Invalid registry digest": "Registro inválido digest", + "Invalid remote name": "Nombre remoto inválido", + "Invalid remote path": "Camino remoto inválido", + "Invalid repair version:": "Versión de reparación inválida:", + "Invalid resources": "Recursos inválidos", + "Invalid restored volume path": "Camino de volumen restaurado inválido", + "Invalid running state": "Estado de funcionamiento inválido", + "Invalid security.unprivileged value:": "Seguridad inválida. valor no privilegiado:", "Invalid selection": "Selección no válida", + "Invalid service alias": "Servicios inválidos", + "Invalid service check URL": "Registro de servicio inválido URL", + "Invalid service check arguments": "Inválidos argumentos de verificación de servicios", + "Invalid service check timeout": "Hora de facturación de servicio inválido", + "Invalid shared path": "Ruta compartida no válida", + "Invalid shutdown timeout": "Hora de apagado inválido", "Invalid size. Please enter a number in MB (e.g., 128, 256, 512).": "Tamaño no válido. Ingrese un número en MB (por ejemplo, 128, 256, 512).", + "Invalid stack contract": "Contrato de pila inválido", + "Invalid stack journal": "Revista de pilas inválidas", + "Invalid stack members": "Miembros de pila inválidos", + "Invalid stack name": "Nombre de pila inválido", + "Invalid stack operation": "Apilación inválida operación", "Invalid storage ID. Use only letters, numbers, hyphens and underscores.": "ID de almacenamiento no válido. Utilice únicamente letras, números, guiones y guiones bajos.", + "Invalid suite application": "Aplicación de suite inválida", + "Invalid sysctl value:": "Valor sysctl inválido:", + "Invalid template storage": "Almacenamiento de plantillas inválidas", + "Invalid tmpfs options:": "Opciones de tmpfs inválidos:", + "Invalid tmpfs path:": "Camino de los tmpfs inválidos:", + "Invalid tmpfs size:": "tamaño de tmpfs inválido:", "Invalid username or password.": "Nombre de usuario o contraseña no válidos.", + "Invalid variable name": "Nombre de variable no válido", + "Invalid variable name:": "Nombre variable inválido:", + "Invalid volume size": "Tamaño del volumen inválido", + "Invalid volume size:": "Tamaño de volumen inválido:", + "Invalid volume target": "Destino de volumen no válido", + "IoT & Smart Home": "IoT & Smart Home", + "Is the value a password or secret?": "¿Es el valor una contraseña o secreto?", "Issue": "Asunto", "Issues found": "Problemas encontrados", "Issues were found. Would you like to use the Guided Cleanup Assistant?": "Se encontraron problemas. ¿Le gustaría utilizar el Asistente de limpieza guiada?", "Issues were found. Would you like to use the Guided Repair Assistant?": "Se encontraron problemas. ¿Le gustaría utilizar el Asistente de reparación guiada?", "It appears that you have already executed the xshok-proxmox post-install script on this system.": "Parece que ya ejecutó el script posterior a la instalación xshok-proxmox en este sistema.", + "It asks for a system directory of the host:": "Pide un directorio del sistema del host:", + "It asks for capabilities or a relaxed confinement profile.": "Pide capacidades o un perfil de confinamiento relajado.", + "It asks to see the processes of the host.": "Pide ver los procesos del host.", + "It cannot be removed on its own, because the application would stop working: continuing removes the whole application.": "No se puede eliminar por sí solo, porque la aplicación dejaría de funcionar: continuar elimina toda la aplicación.", + "It is created empty; existing data is not migrated automatically.": "Se crea vacía; los datos existentes no se migran automáticamente.", "It is recommended to create a backup before continuing.": "Se recomienda crear una copia de seguridad antes de continuar.", "It is strongly recommended to create a backup of your container before proceeding with the conversion.": "Se recomienda encarecidamente crear una copia de seguridad de su contenedor antes de continuar con la conversión.", + "It needs a privileged container, which is not isolated from the host.": "Necesita un contenedor privilegiado, que no está aislado del host.", "It will be installed from the official GitHub repository.": "Se instalará desde el repositorio oficial de GitHub.", + "It works through the Docker engine of the host, and a native OCI container does not have one.": "Funciona a través del motor Docker del host, y un contenedor OCI nativo no tiene uno.", "Italian": "italiano", + "Its Compose file asks for privileged mode; the container is created unprivileged and that mode is only offered as an option.": "Su archivo Compose pide un modo privilegiado; el contenedor se crea sin privilegios y ese modo sólo se ofrece como una opción.", + "Its final cleanup did not complete. Select the stack again in the OCI management menu to complete it.": "Su limpieza final no terminó. Seleccione la pila de nuevo en el menú de gestión OCI para completarla.", + "Its labels are not applied: they are read by other Docker tools.": "Sus etiquetas no se aplican: son leídas por otras herramientas Docker.", "JC Channel logo applied": "Logotipo de JC Channel aplicado", + "JDownloader 2 with browser GUI and MyJDownloader support": "JDownloader 2 con compatibilidad con el navegador GUI y MyJDownloader", + "JDownloader WebUI": "JDownloader WebUI", "JSON output for scripts": "Salida JSON para scripts", + "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps.": "Jackett funciona como un servidor proxy: traduce consultas de aplicaciones (Sonarr, SickRage, CouchPotato, Mylar, etc) en consultas http específicas para rastreadores, analiza la respuesta html, y luego envía resultados de vuelta al software que solicita. Esto permite obtener subidas recientes (como RSS) y realizar búsquedas. Jackett es un único repositorio de la lógica de traducción de indexador mantenido, eliminando la carga de otras aplicaciones.", + "Jellyfin WebUI": "Jellyfin WebUI", + "Jellyfin configuration applied:": "Configuración Jellyfin aplicada:", + "Jellyfin did not create encoding.xml before the timeout": "Jellyfin no creó encoding.xml antes del timeout", + "Jellyfin has not created encoding.xml in any declared path": "Jellyfin no ha creado encoding.xml en ningún camino declarado", + "Jellyseerr is a free and open source software application for managing requests for your media library.": "Jellyseerr es una aplicación de software libre y de código abierto para gestionar solicitudes para su biblioteca multimedia.", + "Jenkins unlock": "Jenkins desbloquea", "Job ID (letters, numbers, - _)": "ID de trabajo (letras, números, - _)", "Job ID:": "Identificación del trabajo:", "Job deleted:": "Trabajo eliminado:", "Job disabled:": "Trabajo deshabilitado:", "Job enabled:": "Trabajo habilitado:", "Job selection returned empty id — aborting.": "La selección de trabajo devolvió una identificación vacía: abortando.", + "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.": "Joplin es una aplicación gratuita y de código abierto, que puede manejar un gran número de notas organizadas en cuadernos.", "Journald configuration adjusted to": "Configuración de diario ajustada a", "Journald configuration is already optimized": "La configuración de Journald ya está optimizada", "Journald configuration updated and service restarted": "Configuración de diario actualizada y servicio reiniciado", @@ -2347,6 +3100,12 @@ "KVM MSR options added to /etc/modprobe.d/kvm.conf": "Opciones de KVM MSR agregadas a /etc/modprobe.d/kvm.conf", "KVM MSR options ensured in /etc/modprobe.d/kvm.conf": "Opciones de KVM MSR aseguradas en /etc/modprobe.d/kvm.conf", "KVM MSR options not present, nothing to revert": "Las opciones de KVM MSR no están presentes, no hay nada que revertir", + "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX ™ is a trademark of OffSec.": "Kali-linux - es una distribución avanzada de pruebas de penetración que se utiliza para pruebas de penetración, Hacking ético y evaluaciones de seguridad de red. KALI LINUX TM es una marca comercial de OffSec.", + "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections.": "Kasm Workspaces es una plataforma de streaming de contenedores docker para ofrecer acceso basado en el navegador a escritorios, aplicaciones y servicios web. Kasm utiliza la infraestructura de escritorio containerized (CDI) devops-enable para crear contenedores a pedido, desechables, docker que son accesibles a través del navegador web. Ejemplos de casos de uso incluyen aislamiento de navegador remoto (RBI), prevención de la pérdida de datos (DLP), escritorio como servicio (DaaS), servicios de acceso remoto seguro (RAS), y colecciones de inteligencia de código abierto (OSINT).", + "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!": "Kavita es un servidor de lectura de plataformas cruzadas rápido y rico. Construido con un enfoque para ser una solución completa para todas sus necesidades de lectura. ¡Configura tu propio servidor y comparte tu colección de lectura con tus amigos y familiares!", + "Kavita is a free and open source web based Comic and Book Server.": "Kavita es una web de código abierto y libre Comic y Book Server.", + "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready.": "Kdenlive es un potente programa de edición de vídeo de código abierto y libre realizado por la comunidad KDE. Característica rica y producción lista.", + "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass).": "KeePassXC es un gestor de contraseña gratuito y de código abierto. Comenzó como una comunidad fork de KeePassX (sólo un puerto multiplataforma de KeePass).", "Keep GPU in LXC config (disable Start on boot)": "Mantenga la GPU en la configuración LXC (deshabilite Inicio al arrancar)", "Keep GPU in LXC config + disable Start on boot": "Mantenga la GPU en la configuración LXC + deshabilite el inicio al arrancar", "Keep GPU in VM config (disable Start on boot)": "Mantenga la GPU en la configuración de VM (deshabilite Inicio al arrancar)", @@ -2356,6 +3115,7 @@ "Keep current version (N) if modified": "Mantener la versión actual (N) si se modifica", "Keep in source VM(s) + disable onboot + add to target VM": "Mantener en las VM de origen + desactivar el inicio + agregar a la VM de destino", "Keeping GPU in source VM config": "Mantener la GPU en la configuración de la VM de origen", + "Keeping the settings changed in Proxmox:": "Mantener la configuración cambiada en Proxmox:", "Kept sharedfiles group (has regular users assigned).": "Se mantiene el grupo de archivos compartidos (tiene usuarios habituales asignados).", "Kernel and architecture info": "Información sobre el kernel y la arquitectura", "Kernel headers and build tools verified.": "Encabezados del kernel y herramientas de compilación verificados.", @@ -2377,6 +3137,16 @@ "Keyfile recovery — pick source host": "Recuperación de archivos clave: elija el host de origen", "Keyfile removed.": "Archivo de claves eliminado.", "Keyrings method failed; trying apt-key fallback": "El método de llaveros falló; probando el respaldo de clave apta", + "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite.": "KiCad - Un Cross Platform y Open Source Electronics Design Automation Suite.", + "Kimai has no default account. Enter the container with: pct enter {main_vmid}": "Kimai no tiene una cuenta predeterminada. Introduzca el contenedor con: pct entrar {main vmid}", + "Kimai is a professional grade time-tracking application, free and open-source.": "Kimai es una aplicación profesional de seguimiento de tiempo, libre y de código abierto.", + "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more.": "Kometa es una poderosa herramienta diseñada para darle control completo sobre sus bibliotecas multimedia. Con Kometa, usted puede tomar su personalización al siguiente nivel, con control granular sobre metadatos, colecciones, overlays, y mucho más.", + "Kometa reads its configuration from /config/config.yml and the container only ships /config/config.yml.template. Copy the template to config.yml, fill in the required Plex and TMDb connections, then restart the container.": "Kometa lee su configuración desde /config/config.yml y el contenedor sólo barcos /config/config.yml.template. Copiar la plantilla para config.yml, rellenar las conexiones necesario Plex y TMDb, luego reiniciar el contenedor.", + "Komga is a media server for your comics, mangas, BDs, magazines and eBooks.": "Komga es un servidor multimedia para tus cómics, mangas, BDs, revistas y eBooks.", + "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone.": "Krita es un programa de pintura profesional GRATIS y de código abierto. Está hecho por artistas que quieren ver herramientas de arte asequibles para todos.", + "LAN access to the kept containers (stack configuration incomplete):": "Acceso LAN a los contenedores guardados (incompleto de configuración de almacenamiento):", + "LAN address applied to the application URLs": "Dirección LAN aplicada a las URL de la aplicación", + "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer.": "LM Studio puede ejecutar modelos locales de IA como gpt-oss, Llama, Gemma, Qwen y DeepSeek en privado en su computadora.", "LUNs appear as block devices assignable to VMs": "Los LUN aparecen como dispositivos de bloque asignables a VM", "LVM PV headers check completed": "Se completó la verificación de los encabezados fotovoltaicos de LVM", "LVM physical volume detected": "Volumen físico LVM detectado", @@ -2393,18 +3163,27 @@ "LXC containers with NVIDIA passthrough:": "Contenedores LXC con transferencia NVIDIA:", "LXC conversion from privileged to unprivileged completed successfully!": "¡La conversión de LXC de privilegiado a no privilegiado se completó con éxito!", "LXC conversion from unprivileged to privileged completed successfully!": "¡La conversión de LXC de no privilegiado a privilegiado se completó con éxito!", + "LXC entries outside the NVIDIA inventory of the journal": "LXC entradas fuera del inventario NVIDIA de la revista", + "LXC entries outside the selected acceleration profile": "LXC entradas fuera del perfil de aceleración seleccionado", + "LXC entry outside the read-only NVIDIA profile": "LXC entrada fuera del perfil de NVIDIA solo lectura", "LXC removed:": "LXC eliminado:", "LXC stopped": "LXC se detuvo", "LXC update skipped by user.": "Actualización de LXC omitida por el usuario.", "LXCs to destroy:": "LXC para destruir:", + "Lab interruption after installing the new container": "Interrupción de laboratorio después de instalar el nuevo contenedor", + "Lab interruption after protecting the data": "Interrupción de laboratorio después de proteger los datos", + "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models.": "Label Studio es una herramienta de etiquetado de datos de código abierto. Le permite etiquetar tipos de datos como audio, texto, imágenes, videos y series de tiempo con una interfaz de usuario sencilla y sencilla y exportar a varios formatos de modelo. Se puede utilizar para preparar datos brutos o mejorar los datos de entrenamiento existentes para obtener más modelos ML de accurate.", "Label:": "Etiqueta:", "Language Change": "Cambio de idioma", "Language changed to": "Idioma cambiado a", + "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)": "Idioma/local (por ejemplo es ES.UTF-8; traducción de cada aplicación no está garantizada)", "Last 50 kernel log lines": "Últimas 50 líneas de registro del kernel", "Last run:": "Última ejecución:", "Last system boot time": "Hora del último arranque del sistema", "Latest version:": "Última versión:", "Launching GPU passthrough assistant for VM": "Lanzamiento del asistente de transferencia de GPU para VM", + "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork.": "Lazylibrarian es un programa para seguir a los autores y tomar metadatos para todas sus necesidades de lectura digital. Utiliza un combination of Goodreads Librarything y opcionalmente GoogleBooks como fuentes para información de autor y información de libros. Este contenedor está basado en el DobyTang fork.", + "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user’s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012).": "El software Ldap-auth es para los usuarios que solicitan recursos protegidos de servidores proxiados por nginx. Incluye un daemon (sala-auth) que se comunica con un servidor de autenticación, y un daemon del servidor web que genera una cookie de autenticación basada en el credential del usuario. Los daemons están escritos en Python para su uso con un servidor de autenticación Lightweight Directory Access Protocol (LDAP) (OpenLDAP o Microsoft Windows Active Directory 2003 y 2012).", "Legacy PVE 8 .list files commented or not present": "Archivos .list de PVE 8 heredados comentados o no presentes", "Legacy ceph.list commented or not present": "Legacy ceph.list comentado o no presente", "Legacy gasket-dkms cleanup could not be verified as complete.": "No se ha podido verificar que la limpieza del paquete heredado gasket-dkms haya finalizado correctamente.", @@ -2412,12 +3191,25 @@ "Legacy network tools (e.g., ifconfig)": "Herramientas de red heredadas (por ejemplo, ifconfig)", "Legend:": "Leyenda:", "Let's review your current network configuration.": "Revisemos su configuración de red actual.", + "Liberate your videos and unleash infinite possibilities.": "Libera tus videos y desata infinitas posibilidades.", + "Libraries: /data/media/movies, /data/media/series and /data/media/music. Select them in the media server.": "Bibliotecas: /data/media/movies, /data/media/series y /data/media/music. Selecciónalas en el servidor multimedia.", + "Library size in GB": "Tamaño de la biblioteca en GB", + "LibreDB Studio": "LibreDB Studio", + "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity.": "LibreOffice es una suite de oficina libre y potente, y un sucesor de OpenOffice.org (comúnmente conocido como OpenOffice). Su interfaz limpia y herramientas ricas en características le ayudan a desatar su creatividad y mejorar su productividad.", + "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM.": "LibreWolf es una versión personalizada e independiente de Firefox, con los principales objetivos de privacidad, seguridad y libertad de usuario. LibreWolf también tiene como objetivo eliminar todas las telemetrías, la recopilación de datos y las molestias, así como desactivar las características antilibertad como DRM.", + "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers.": "Librespeed es un Speedtest muy ligero implementado en Javascript, usando XMLHttpRequest y Web Workers.", + "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Lidarr es un gestor de colección de música para usuarios de Usenet y BitTorrent. Puede monitorear múltiples feeds RSS para nuevas pistas de sus artistas favoritos y los agarrará, ordenará y renombrará. También se puede configurar para actualizar automáticamente la calidad de los archivos ya descargados cuando se dispone de un formato de mejor calidad.", + "Lightweight Docker management UI": "Gestión ligera Docker UI", "Likely cause: host directory permissions deny the container's mapped UID.": "Causa probable: los permisos del directorio del host niegan el UID asignado del contenedor.", "Limiting size and optimizing journald": "Limitar el tamaño y optimizar el diario", "Limiting size and optimizing journald...": "Limitar el tamaño y optimizar el diario...", + "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot.": "Limnoria Un robusto, completo y fácil de usar/programmer-friendly Python IRC bot, con muchos plugins existentes. Sucesor del conocido Supybot.", + "Limnoria joins no IRC network until its configuration file exists. Create it with the setup wizard from the Proxmox host: pct exec -- bash -c 'cd /config && limnoria-wizard'": "Limnoria no se une a ninguna red IRC hasta que exista su archivo de configuración. Crealo con el asistente de configuración del host Proxmox: pct exec ■CTID confiar -- bash -c 'cd /config ' limit limnoria-wizard'", "Line to paste (single line, including \"command=...\" prefix):": "Línea para pegar (una sola línea, incluido el prefijo \"comando=...\"):", "Linux Installation Options": "Opciones de instalación de Linux", "Linux/Mac path:": "Ruta Linux/Mac:", + "LinuxServer Jellyfin with optional GPU passthrough": "LinuxServer Jellyfin con paso de GPU opcional", + "LinuxServer MariaDB requires a user, database and password": "LinuxServer MariaDB requiere un usuario, base de datos y contraseña", "List Available Disks": "Listar discos disponibles", "List IOMMU group mapping": "Listar el mapeo del grupo IOMMU", "List NVMe devices": "Listar dispositivos NVMe", @@ -2443,7 +3235,9 @@ "Listening on:": "Escuchando en:", "Listening ports:": "Puertos de escucha:", "Listing relevant CT users and their mapped UID/GID on host...": "Listado de usuarios CT relevantes y su UID/GID asignado en el host...", + "Load and verify the WireGuard module on the Proxmox host": "Cargar y verificar el módulo WireGuard en el host Proxmox", "Loading modules...": "Cargando módulos...", + "Loading the host kernel module:": "Carga el módulo del kernel host:", "Local Disk Manager - Proxmox Host": "Administrador de discos locales - Proxmox Host", "Local Disk Storages": "Almacenamientos en disco local", "Local Shared Directory on Host": "Directorio compartido local en el host", @@ -2454,6 +3248,7 @@ "Local keyfile is missing but a recovery copy was found in PBS.": "falta el archivo de claves local, pero se encontró una copia de recuperación en PBS.", "Local network only (192.168.0.0/16)": "Sólo red local (192.168.0.0/16)", "Local restore error log": "Registro de errores de restauración local", + "Local storage for PostgreSQL": "Almacenamiento local para PostgreSQL", "Locale generated": "Configuración regional generada", "Location:": "Ubicación:", "Log": "Registro", @@ -2469,6 +3264,7 @@ "Logged-in users": "Usuarios registrados", "Logrotate optimization completed": "Optimización de logrotate completada", "Logrotate service restarted successfully": "El servicio Logrotate se reinició exitosamente", + "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment.": "Lollypop es un reproductor de música moderno ligero diseñado para trabajar excelentemente en el entorno de escritorio GNOME.", "Long Test — Background": "Prueba larga — en segundo plano", "Long self-test started on": "La autoprueba larga comenzó el", "Long test — full scan, runs in background if closed": "Prueba larga: análisis completo, se ejecuta en segundo plano si está cerrado", @@ -2477,7 +3273,11 @@ "Lookup domain registration info": "Buscar información de registro de dominio", "Low Container Memory": "Memoria de contenedor baja", "Low free space warning": "Advertencia de poco espacio libre", + "Low-code programming for event-driven applications": "Programación de código bajo para aplicaciones impulsadas por eventos", "Low-power CPU platform": "Plataforma de CPU de bajo consumo", + "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation": "Luanti (antes Minetest) es una plataforma de creación de juego de voxel de código abierto con la creación de juegos fáciles de modding y juego", + "Lucky web interface": "Interfaz web Lucky", + "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.": "Lychee es una herramienta gratuita de gestión de fotos, que se ejecuta en su servidor o espacio web. Instalar es cuestión de segundos. Subir, gestionar y compartir fotos como de una aplicación nativa. Lychee viene con todo lo que necesitas y todas tus fotos se guardan de forma segura.", "Lynis - Security Audit": "Lynis - Auditoría de seguridad", "Lynis Management": "Gestión Lynis", "Lynis command not found": "Comando Lynis no encontrado", @@ -2492,26 +3292,37 @@ "Lynis updated to version:": "Lynis actualizado a la versión:", "Lynis version:": "Versión Lynis:", "Lynis was not installed from Git. Reinstalling...": "Lynis no se instaló desde Git. Reinstalando...", + "Lyrion Music Server is a streaming audio server for Squeezebox audio players.": "Lyrion Music Server es un servidor de audio de streaming para reproductores de audio Squeezebox.", "M.2 / PCIe devices:": "Dispositivos M.2/PCIe:", + "M3U proxy server": "M3U servidor proxy", "MAC Address": "Dirección MAC", + "MAC address": "Dirección MAC", "MACHINE TYPE": "TIPO DE MÁQUINA", + "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers.": "MAME es un emulador de código abierto y gratuito diseñado para emular el hardware de juegos de arcade, consolas de videojuegos, computadoras antiguas y otros sistemas en software en computadoras personales modernas.", "MOTD configuration updated successfully": "Configuración de MOTD actualizada con éxito", "MOTD configuration was already up to date": "la configuración de MOTD ya estaba actualizada", "Machine Type": "Tipo de máquina", + "Machine learning": "Aprendizaje automático", + "Machine learning profile not implemented; it is not replaced by CPU:": "Perfil de aprendizaje automático no implementado; no es reemplazado por CPU:", "Machine type: q35": "Tipo de máquina: q35", "Machine: q35": "Máquina: q35", + "Main endpoint not yet defined": "Punto final principal aún no definido", "Major version differs:": "La versión principal difiere:", "Make sure IOMMU is properly enabled and the system has been rebooted after activation.": "Asegúrese de que IOMMU esté habilitado correctamente y que el sistema se haya reiniciado después de la activación.", "Make sure there are no critical services running as they will be interrupted. Ensure your server can be safely rebooted.": "Asegúrese de que no haya servicios críticos en ejecución, ya que se interrumpirán. Asegúrese de que su servidor pueda reiniciarse de forma segura.", "Make sure you have SSH or Web UI access before rebooting.": "Asegúrese de tener acceso SSH o UI web antes de reiniciar.", "Makefile missing in": "Falta el archivo Makefile", "Malformed repository entries cleaned": "Se limpiaron las entradas del repositorio con formato incorrecto", + "Manage OCI": "Gestionar OCI", "Manage PBS encryption keyfile": "administrar el archivo de claves de cifrado PBS", "Manage Secure Gateway": "Administrar Secure Gateway", "Manage and inspect VM disk images": "Administrar e inspeccionar imágenes de disco de VM", "Manage custom backup paths": "Configurar rutas de respaldo personalizadas", "Manage custom paths (add / remove your folders)": "Configurar rutas personalizadas (agreguar/eliminar carpetas)", + "Manage installed OCI applications": "Gestionar aplicaciones OCI instaladas", "Manage local backup target": "Configurar el destino de la copia de seguridad local", + "Managed disks must have backup enabled and a valid size": "Los discos gestionados deben tener habilitado backup y un tamaño válido", + "Managing Nginx proxy hosts with a simple, powerful interface.": "Gestión de hosts proxy Nginx con una interfaz sencilla y potente.", "Manual CLI Guide (Disk and Storage Manager)": "Comandos CLI manuales (Administrador de discos y almacenamiento)", "Manual CLI Guide (GPU/TPU)": "Comandos CLI manuales (GPU/TPU)", "Manual Guide: Convert LXC Privileged to Unprivileged": "Guía manual: convertir LXC privilegiado a no privilegiado", @@ -2526,29 +3337,49 @@ "Manual review is required.": "Se requiere una revisión manual.", "Manual steps recommended after import": "Pasos manuales recomendados después de la importación", "Manual upgrade guide step by step": "Guía de actualización manual paso a paso", + "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing.": "Manyfold es una aplicación web de código abierto para gestionar una colección de modelos 3D, especialmente centrada en la impresión 3D.", "Mapped GID on host": "GID asignado en el host", "Mapped UID on host": "UID asignado en el host", + "Mariadb is one of the most popular database servers. Made by the original developers of MySQL.": "Mariadb es uno de los servidores de bases de datos más populares. Hecho por los desarrolladores originales de MySQL.", + "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..": "Mastodon es un servidor de red social de código abierto basado en ActivityPub donde los usuarios pueden seguir amigos y descubrir nuevos..", "Max FD limit / ulimit configured": "Límite máximo de FD/ulimit configurado", "Max FS open files configuration created successfully": "Configuración de archivos abiertos de Max FS creada con éxito", "Max user watches configured": "Número máximo de relojes de usuario configurados", "Maximum auto-repair attempts reached (3). Please review the log and run any remaining commands manually.": "Se alcanzó el número máximo de intentos de reparación automática (3). Revise el registro y ejecute los comandos restantes manualmente.", "May need to restart terminal": "Puede que sea necesario reiniciar el terminal", + "Media & Streaming": "Media " Streaming", + "Media library transcoding and health checking, with an internal worker node.": "Transcodificación de la biblioteca de medios y control de salud, con un nodo de trabajador interno.", + "Media server": "Servidor multimedia", + "Media server selection cancelled or invalid": "Selección de servidor multimedia cancelada o no válida", + "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well.": "MediaElch es un MediaManager para Kodi. Información sobre películas, programas de televisión, conciertos y música se almacenan como archivos nfo. Los Fanarts se descargan automáticamente desde fanart.tv. Utilizando el generador nfo, MediaElch también se puede utilizar con otros MediaCenters.", + "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Medusa es un gestor automático de Videoteca para programas de televisión. Observa nuevos episodios de tus programas favoritos, y cuando son publicados hace su magia.", + "Memory": "Memoria", + "Memory in MB": "Memoria en MB", "Memory optimization completed.": "Optimización de la memoria completada.", "Memory optimizations removed": "Se eliminaron las optimizaciones de memoria.", "Memory restored.": "Memoria restaurada.", "Memory settings optimized successfully": "Configuración de memoria optimizada con éxito", "Memory:": "Memoria:", + "Memos is a lightweight, self-hosted memo hub. Open Source and Free forever.": "Memos es un centro de memo liviano y auto hospedado. Fuente Abierta y Libre para siempre.", + "Messaging & Queues": "Mensajes " Queues", "Method:": "Método:", + "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium.": "Microsoft Edge es un navegador web multiplataforma desarrollado por Microsoft y basado en Chromium.", "Migrate VMs away from node being upgraded": "Migrar las máquinas virtuales fuera del nodo que se está actualizando", "Migrate away any guests that must keep running": "Migrar cualquier invitado que deba seguir ejecutándose", "Migrated": "migrado", "Migrated legacy ProxMenux NVIDIA blacklist state — module will reload after reboot": "Estado de lista negra de NVIDIA ProxMenux heredado migrado: el módulo se recargará después del reinicio", + "MineOS web interface": "Interfaz web MineOS", + "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards.": "Minisatip es una versión de servidor de satip multitelecha 1.2 que funciona bajo Linux y fue probada con tarjetas DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC e ISDB-T.", "Mirror URL not available for this script.": "La URL reflejada no está disponible para este script.", + "Miscellaneous": "Varios", "Missing": "Desaparecido", + "Missing OCI metadata:": "Desapareciendo los metadatos de la OCI:", "Missing commands after installation:": "Comandos que faltan después de la instalación:", "Missing dependency": "Dependencia faltante", + "Missing native directive:": "Desapareciendo la directiva nativa:", "Missing on target:": "Falta en el objetivo:", "Missing or invalid parameter": "Parámetro faltante o no válido", + "Missing required command:": "Falta el comando necesario:", "Missing required parameter": "Falta el parámetro requerido", "Mixed GPU Modes": "Modos de GPU mixtos", "Mixed current mode detected in selected GPU(s).": "Modo de corriente mixta detectado en GPU seleccionadas.", @@ -2556,15 +3387,20 @@ "Mode": "Modo", "Model": "Modelo", "Modern resource monitor (press q to exit)": "Monitor de recursos moderno (presione q para salir)", + "Modern, easy to use download automation for torrents and usenet.": "Moderno, fácil de usar la automatización de descargas para torrents y usenet.", "Modifying Fastfetch configuration...": "Modificando la configuración de Fastfetch...", "Modules configuration updated.": "Configuración de módulos actualizada.", "Modules loaded.": "Módulos cargados.", + "MongoDB 4.4, the last series that runs on a CPU without AVX.": "MongoDB 4.4, la última serie que se ejecuta en una CPU sin AVX.", + "Monica is an open source personal relationship management system, that lets you document your life.": "Monica es un sistema de gestión de relaciones personales de código abierto que le permite documentar su vida.", "Monitor Activated": "Monitor activado", "Monitor Deactivated": "Monitor desactivado", "Monitor URL": "URL del monitor", "Monitor disk I/O usage (press q to exit)": "Monitorear el uso de E/S del disco (presione q para salir)", "Monitor progress:": "Supervisar el progreso:", + "Monitor, analyze, and alert on network performance.": "Monitorear, analizar y alertar sobre el rendimiento de la red.", "Monitoring": "Monitorización", + "Monitoring & Analytics": "Monitoring " Analytics", "Most common cause: the archive is corrupted (interrupted write, partial copy, or storage issue).": "causa más común: el archivo está dañado (escritura interrumpida, copia parcial o problema de almacenamiento).", "Mount Added Successfully:": "Montaje agregado con éxito:", "Mount CIFS share:": "Monte el recurso compartido CIFS:", @@ -2592,13 +3428,19 @@ "Mount Samba Share on Host": "Montar recurso compartido Samba en el host", "Mount USB disk?": "¿Montar disco USB?", "Mount a USB drive now": "Monte una unidad USB ahora", + "Mount activation cancelled": "Activación de montaje cancelada", "Mount all datasets": "Montar todos los conjuntos de datos", "Mount already exists for this path in container": "El montaje ya existe para esta ruta en el contenedor", "Mount and persist with UUID:": "Montar y persistir con UUID:", + "Mount configuration cancelled": "Configuración de montaje cancelada", "Mount failed": "Montaje fallido", + "Mount mode applied": "Modo de montaje aplicado", + "Mount name": "Nombre del montaje", + "Mount not authorized by the operation": "Montaje no autorizado por la operación", "Mount options:": "Opciones de montaje:", "Mount path must be an absolute path starting with /": "La ruta de montaje debe ser una ruta absoluta que comience con /", "Mount path:": "Ruta de montaje:", + "Mount paths must not overlap": "Los caminos del monte no deben sobreponerse", "Mount point created": "Punto de montaje creado", "Mount point created.": "Punto de montaje creado.", "Mount point is visible but NOT writable from inside the container": "El punto de montaje es visible pero NO se puede escribir desde el interior del contenedor.", @@ -2607,11 +3449,14 @@ "Mount point ready:": "Punto de montaje listo:", "Mount point removed successfully": "Punto de montaje eliminado correctamente", "Mount point:": "Punto de montaje:", + "Mount points added:": "Puntos de montaje añadidos:", + "Mount read-only": "Montaje solo lectura", "Mount shares on HOST first": "Montar acciones en HOST primero", "Mount specific dataset": "Montar conjunto de datos específico", "Mount status:": "Estado de montaje:", "Mount this device and use it as the backup destination?": "¿Montar este dispositivo y usarlo como destino de respaldo?", "Mount was busy — performed lazy unmount": "El montaje estaba ocupado: se realizó un desmontaje diferido", + "Mount your cloud drive on your home NAS": "Monta tu unidad de nube en tu NAS de origen", "Mounted": "Montado", "Mounted ISO on device": "ISO montado en el dispositivo", "Mounted at": "Montado en", @@ -2626,8 +3471,15 @@ "Mounting here will hide existing files until unmounted.": "Montar aquí ocultará los archivos existentes hasta que se desmonten.", "Move that copy offsite (USB, password manager, another host). Delete it from this path when done.": "mueva esa copia fuera del sitio (USB, administrador de contraseñas, otro host).Elimínelo de esta ruta cuando haya terminado.", "Move to target VM (remove from source VM config)": "Mover a la VM de destino (eliminar de la configuración de la VM de origen)", + "Moving the data volumes aside...": "Mover los volúmenes de datos a un lado...", + "Multi-container application (experimental)": "Aplicación multicontenedor (experimental)", + "Multi-line variables are not supported": "No se admiten variables multilíneas", + "Multiple networks or external networks are not yet supported": "Aún no se admiten múltiples redes o redes externas", "Multiple recovery groups found in PBS. Pick the one that originally created the keyfile:": "Múltiples grupos de recuperación encontrados en PBS. Elige el que creó originalmente el archivo de claves:", "Multiple rootfs directories were found in this archive. Restore cannot continue automatically.": "Se encontraron varios directorios rootfs en este archivo. La restauración no puede continuar automáticamente.", + "Music software that transforms your listening experience": "Software de música que transforma tu experiencia de escucha", + "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more.": "MySQL Workbench es una herramienta visual unificada para arquitectos de bases de datos, desarrolladores y DBAs. MySQL Workbench proporciona modelos de datos, desarrollo SQL y herramientas de administración integrales para la configuración del servidor, administración del usuario, backup y mucho más.", + "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL.": "Mylar3 es un descargador automatizado Comic Book (cbr/cbz) para uso con NZB y torrents escrito en python. Admite SABnzbd, NZBGET, y muchos clientes torrent además de DDL.", "NAS Systems": "Sistemas NAS", "NETWORK CONFIGURATION ANALYSIS": "ANÁLISIS DE CONFIGURACIÓN DE RED", "NFS Access Restricted": "Acceso NFS restringido", @@ -2691,24 +3543,33 @@ "NOT FOUND": "EXTRAVIADO", "NOTE: The host directory and its contents will remain unchanged.": "NOTA: El directorio del host y su contenido permanecerán sin cambios.", "NVENC patch detected — list narrowed to versions supported by keylase/nvidia-patch.": "Parche NVENC detectado: lista reducida a versiones compatibles con keylase/nvidia-patch.", + "NVIDIA (CUDA)": "NVIDIA (CUDA)", + "NVIDIA (CUDA; official GPU image)": "NVIDIA (CUDA; imagen oficial de la GPU)", + "NVIDIA (NVDEC/CUDA)": "NVIDIA (NVDEC/CUDA)", + "NVIDIA (NVENC/NVDEC)": "NVIDIA (NVENC/NVDEC)", "NVIDIA Actions": "Acciones de NVIDIA", "NVIDIA CPU hiding already configured": "Ocultación de CPU NVIDIA ya configurada", "NVIDIA Container Toolkit": "Kit de herramientas de contenedor NVIDIA", + "NVIDIA Container Toolkit could not generate the runtime inventory": "NVIDIA Container Toolkit no pudo generar el inventario de tiempo de ejecución", "NVIDIA Container Toolkit installed. GPU validation pending until the host restarts.": "NVIDIA Container Toolkit instalado. Validación de GPU pendiente hasta que se reinicie el host.", "NVIDIA Container Toolkit is incomplete. Missing:": "NVIDIA Container Toolkit está incompleto. Desaparecido:", "NVIDIA Container Toolkit is installed but its command line did not answer.": "NVIDIA Container Toolkit está instalado pero su línea de comando no respondió.", + "NVIDIA Container Toolkit is missing on the host (nvidia-container-cli)": "Falta el NVIDIA Container Toolkit en el host (nvidia-container-cli)", "NVIDIA Container Toolkit verified against the running driver.": "NVIDIA Container Toolkit verificado con el controlador en ejecución.", "NVIDIA DKMS entries removed.": "Se eliminaron las entradas de NVIDIA DKMS.", "NVIDIA Driver Uninstall": "Desinstalación del controlador NVIDIA", "NVIDIA Driver Version": "Versión del controlador NVIDIA", "NVIDIA Drivers": "Controladores NVIDIA", "NVIDIA Drivers Not Found": "Controladores NVIDIA no encontrados", + "NVIDIA GPU / CUDA (Toolkit on the host)": "NVIDIA GPU / CUDA (Toolkit en el host)", "NVIDIA GPU Driver Installation": "Instalación del controlador de GPU NVIDIA", "NVIDIA GPU passthrough configured.": "Paso a través de GPU NVIDIA configurado.", + "NVIDIA GPU prepared:": "GPU NVIDIA preparó:", "NVIDIA KVM args configured (kvm=off, vendor_id spoof)": "Argumentos de NVIDIA KVM configurados (kvm=off, spoof de seller_id)", "NVIDIA KVM hiding (cpu hidden=1)": "Ocultación de NVIDIA KVM (cpu oculta = 1)", "NVIDIA KVM hiding already configured": "Ocultación de NVIDIA KVM ya configurada", "NVIDIA Patch": "Parche NVIDIA", + "NVIDIA device outside the expected native profile": "dispositivo NVIDIA fuera del perfil nativo esperado", "NVIDIA driver": "controlador nvidia", "NVIDIA driver installed successfully.": "El controlador NVIDIA se instaló correctamente.", "NVIDIA driver installed:": "Controlador NVIDIA instalado:", @@ -2716,6 +3577,7 @@ "NVIDIA drivers are not installed or not loaded on this host.": "Los controladores NVIDIA no están instalados o no están cargados en este host.", "NVIDIA host services disabled for VFIO mode": "Servicios de host NVIDIA deshabilitados para el modo VFIO", "NVIDIA host services/autoload already aligned for native mode": "Servicios de host de NVIDIA/carga automática ya alineados para el modo nativo", + "NVIDIA inside the container does not match the host driver or GPU": "NVIDIA dentro del contenedor no coincide con el controlador host o GPU", "NVIDIA install incomplete. Check log:": "Instalación de NVIDIA incompleta. Registro de verificación:", "NVIDIA installer downloaded successfully": "El instalador de NVIDIA se descargó correctamente", "NVIDIA installer extracted.": "Instalador de NVIDIA extraído.", @@ -2724,29 +3586,50 @@ "NVIDIA installer returned error": "El instalador de NVIDIA devolvió un error", "NVIDIA kernel modules unloaded successfully.": "Los módulos del kernel de NVIDIA se descargaron correctamente.", "NVIDIA libs require approximately 1.5GB of free space.": "Las bibliotecas de NVIDIA requieren aproximadamente 1,5 GB de espacio libre.", + "NVIDIA mount with an unauthorized source or target": "Montaje NVIDIA con una fuente o objetivo no autorizados", "NVIDIA patch applied - check README for supported versions.": "Parche de NVIDIA aplicado: consulte README para conocer las versiones compatibles.", "NVIDIA patch not applied.": "Parche de NVIDIA no aplicado.", "NVIDIA per-BDF VFIO binding configured": "Enlace NVIDIA por BDF VFIO configurado", + "NVIDIA permissions or device nodes differ from the official inventory": "Los permisos o nodos de dispositivo NVIDIA difieren del inventario oficial", + "NVIDIA refresh validated; the container is stopped and its settings are kept": "NVIDIA refrescante validado; el contenedor se detiene y sus ajustes se mantienen", + "NVIDIA runtime libraries or components are missing": "Faltan bibliotecas o componentes de tiempo de ejecución de NVIDIA", + "NVIDIA selection not supported by this profile": "Selección NVIDIA no compatible con este perfil", "NVIDIA services stopped and disabled.": "Los servicios de NVIDIA se detuvieron y deshabilitaron.", "NVIDIA udev rules and persistence service installed.": "Reglas de NVIDIA udev y servicio de persistencia instalados.", "NVIDIA uninstallation steps completed.": "Pasos de desinstalación de NVIDIA completados.", "NVIDIA uninstaller completed.": "Desinstalador de NVIDIA completado.", "NVIDIA update failed for LXC": "La actualización de NVIDIA falló para LXC", "NVIDIA userspace libraries installed.": "Bibliotecas de espacio de usuario de NVIDIA instaladas.", + "NVML does not match the current host driver": "NVML no coincide con el controlador de host actual", "NVMe Disk Detected": "Disco NVMe detectado", "NVMe critical_warning is 0 (no critical warnings reported).": "NVMe critic_warning es 0 (no se reportan advertencias críticas).", + "NVMe health status: PASSED": "Estado de salud de NVMe: PASADO", "NVMe health status: WARNING (critical_warning =": "Estado de salud de NVMe: ADVERTENCIA (advertencia_crítica =", "NVMe skipped (to add as PCIe use 'Add Controller or NVMe PCIe to VM'):": "NVMe omitido (para agregar como PCIe use 'Agregar controlador o NVMe PCIe a VM'):", "NVMe-specific SMART log": "Registro SMART específico de NVMe", + "NVR & Cameras": "Cámaras NVR", + "NVR with optional VA-API video acceleration and hardware object detectors": "NVR con detectores opcionales de vídeo VA-API y detectores de objetos de hardware", + "NZBGet web interface": "Interfaz web NZBGet", + "Name": "Nombre", + "Name for this application": "Nombre de esta aplicación", "Name for this target:": "Nombre para este objetivo:", + "Name of the PostgreSQL user created on the first start": "Nombre del usuario PostgreSQL creado en el primer inicio", + "Name of the database created on the first start": "Nombre de la base de datos creada en el primer comienzo", + "Name of the internal worker node": "Nombre del nodo obrero interno", + "Name of this wallabag instance, shown in the interface and in 2FA codes": "Nombre de esta instancia wallabag, mostrado en la interfaz y en códigos 2FA", + "Name or part of the description of the application": "Nombre o parte de la descripción de la aplicación", "Name:": "Nombre:", + "Named accounts need private mode. Stop the container, set public: false in /config/config.js, start it again and create each user with: pct exec -- env THELOUNGE_HOME=/config s6-setuidgid abc thelounge add ": "Las cuentas con nombre necesitan modo privado. Detén el contenedor, pon public: false en /config/config.js, vuelve a arrancarlo y crea cada usuario con:", "Neither /etc/kernel/cmdline nor /etc/default/grub found.": "No se encontraron /etc/kernel/cmdline ni /etc/default/grub.", "Nesting feature enabled": "Función de anidamiento habilitada", "NetBIOS Service: RUNNING": "Servicio NetBIOS: EN EJECUCIÓN", "NetBIOS Service: STOPPED": "Servicio NetBIOS: DETENIDO", "NetBIOS port 139:": "Puerto NetBIOS 139:", + "NetBox": "NetBox", + "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations.": "Netbox es una herramienta de gestión de direcciones IP (IPAM) y gestión de infraestructuras del centro de datos (DCIM). Inicialmente concebido por el equipo de ingeniería de red en DigitalOcean, NetBox fue desarrollado específicamente para atender las necesidades de los ingenieros de red e infraestructura. Está destinado a funcionar como una fuente de verdad específica para la red operations.", "Network": "Red", "Network :": "Red :", + "Network & Firewall": "Red de cortafuegos", "Network (interfaces, DNS)": "Red (interfaces, DNS)", "Network Bridge": "Puente de red", "Network Commands": "Comandos de red", @@ -2764,6 +3647,7 @@ "Network Restarted": "Red reiniciada", "Network Tools": "Herramientas de red", "Network access:": "Acceso a la red:", + "Network bridge": "Puente de red", "Network configuration backed up": "Configuración de red respaldada", "Network configuration has been restored from backup.": "La configuración de red se ha restaurado desde la copia de seguridad.", "Network connection failed to": "La conexión de red no pudo", @@ -2776,12 +3660,16 @@ "Network service restarted successfully": "El servicio de red se reinició exitosamente", "Network service restarted successfully.": "El servicio de red se reinició exitosamente.", "Network share mounting (NFS/Samba) requires a PRIVILEGED container.": "El montaje de recursos compartidos de red (NFS/Samba) requiere un contenedor PRIVILEGED.", + "Network sysctls prepared:": "Red sysctls prepared:", "Network throughput test (client/server)": "Prueba de rendimiento de la red (cliente/servidor)", + "Network-wide Ad Blocking": "Bloqueo de anuncios en toda la red", + "Network-wide ad and tracker blocking": "Bloqueo de anuncios y rastreadores en toda la red", "NetworkManager Detected": "Administrador de red detectado", "NetworkManager has been removed successfully": "NetworkManager se ha eliminado correctamente", "NetworkManager is running (may cause conflicts)": "NetworkManager se está ejecutando (puede causar conflictos)", "NetworkManager is running, which may conflict with Proxmox.": "NetworkManager se está ejecutando, lo que puede entrar en conflicto con Proxmox.", "NetworkManager not running": "NetworkManager no se ejecuta", + "Networks the peers reach through the tunnel (0.0.0.0/0 = all traffic)": "Redes que los pares llegan a través del túnel (0.0.0.0/0 = todo el tráfico)", "New Folder in /mnt": "Nueva carpeta en /mnt", "New Group": "Nuevo grupo", "New Search": "Nueva búsqueda", @@ -2789,14 +3677,26 @@ "New Virtual Machine": "Nueva máquina virtual", "New backup job": "Nuevo trabajo de copia de seguridad", "New backups on this host will be unencrypted until a new keyfile is set up.": "Las nuevas copias de seguridad en este host no estarán cifradas hasta que se configure un nuevo archivo de claves.", + "New image compatible:": "Nueva imagen compatible:", + "New image installed": "Nueva imagen instalada", + "New image installed, not verified yet": "Nueva imagen instalada, aún no verificada", + "New image verified, not saved yet": "Nueva imagen verificada, no guardada aún", "New kernel staged; rebuilding DKMS drivers:": "Nuevo kernel preparado;Reconstrucción de controladores DKMS:", "New mount options to apply:": "Nuevas opciones de montaje para aplicar:", "New scheduled job (own timer + retention)": "Nuevo trabajo programado (temporizador propio + retención)", + "New value for": "Nuevo valor para", "New version available": "Nueva versión disponible", "New version:": "Nueva versión:", "Next Step Required": "Se requiere el siguiente paso", "Next Steps:": "Próximos pasos:", "Next step: stop that VM first, then run": "Siguiente paso: detenga esa VM primero y luego ejecútela", + "Nextcloud configuration cancelled": "Configuración Nextcloud cancelada", + "Nextcloud gives you access to all your files wherever you are.": "Nextcloud te da acceso a todos tus archivos donde estés.", + "Nextcloud volume size in GB": "Tamaño del volumen de Nextcloud en GB", + "Nextcloud with private PostgreSQL and Redis dependencies": "Nextcloud con dependencia privada PostgreSQL y Redis", + "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server.": "Nginx es un servidor web HTTP, proxy inverso, caché de contenido, balanceador de carga, servidor proxy TCP/UDP y servidor proxy de correo.", + "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.": "Nginx servidor web y proxy reverso con soporte de php y un cliente de Certbot incorporado (Encrypt). También contiene fail2ban para la prevención de la intrusión.", + "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd.": "Ngircd es un servidor gratuito, portátil y ligero de Internet Relay Chat para redes pequeñas o privadas, desarrollado bajo GNU General Public License (GPL). Es fácil de configurar, puede hacer frente a direcciones IP dinámicas y admite conexiones IPv6, SSL protegidas, así como PAM para la autenticación. Está escrito desde cero y no basado en el IRCd original.", "No": "No", "No .ova or .ovf files found in:": "No se encontraron archivos .ova o .ovf en:", "No .ovf descriptor found inside OVA.": "No se encontró ningún descriptor .ovf dentro de OVA.", @@ -2814,6 +3714,7 @@ "No CTs available in the system.": "No hay CT disponibles en el sistema.", "No Changes Needed": "No se necesitan cambios", "No Cleanup Needed": "No se necesita limpieza", + "No Compose file was given": "No se dio ningún archivo Compose", "No Controller/NVMe selected for now.": "No se ha seleccionado ningún controlador/NVMe por ahora.", "No Coral Detected": "No se ha detectado Coral", "No Coral TPU device was found on this host (neither PCIe/M.2 nor USB).": "No se encontró ningún dispositivo Coral TPU en este host (ni PCIe/M.2 ni USB).", @@ -2832,12 +3733,15 @@ "No Guest Shares": "No hay acciones para invitados", "No IP": "Sin IP", "No IP assigned": "Ninguna IP asignada", + "No IPv4 address was detected after 30 seconds.": "No se detectó dirección IPv4 después de 30 segundos.", "No ISO file detected after UUP Dump process.": "No se detectó ningún archivo ISO después del proceso de volcado UUP.", "No ISO images found in Proxmox ISO storages.": "No se encontraron imágenes ISO en los almacenamientos ISO de Proxmox.", "No ISO selected.": "No se seleccionó ningún ISO.", "No ISO was generated.": "No se generó ninguna ISO.", "No Images Found": "No se encontraron imágenes", "No Intel GPU detected on this system.": "No se detectó ninguna GPU Intel en este sistema.", + "No LAN address was obtained": "No se obtuvo dirección LAN", + "No LAN address was obtained for the service:": "No se obtuvo dirección LAN para el servicio:", "No LXC containers available": "No hay contenedores LXC disponibles", "No LXC containers found": "No se encontraron contenedores LXC", "No LXC containers found on this system.": "No se encontraron contenedores LXC en este sistema.", @@ -2855,7 +3759,9 @@ "No NFS shares currently mounted.": "Actualmente no hay acciones NFS montadas.", "No NVIDIA GPU detected on this system.": "No se detectó ninguna GPU NVIDIA en este sistema.", "No NVIDIA GPU has been detected on this system. The installer will now exit.": "No se ha detectado ninguna GPU NVIDIA en este sistema. El instalador ahora saldrá.", + "No NVIDIA GPU is available": "No hay GPU NVIDIA disponible", "No NVIDIA driver installed.": "No hay ningún controlador NVIDIA instalado.", + "No OCI instances are registered.": "No hay instancias OCI registradas.", "No PBS keyfile is installed on this host and no automatic recovery was possible.": "No hay ningún archivo de claves PBS instalado en este host y no fue posible la recuperación automática.", "No PVE vzdump job uses a": "Ningún trabajo PVE vzdump utiliza un", "No PVs with old headers found.": "No se encontraron PV con encabezados antiguos.", @@ -2891,6 +3797,7 @@ "No Virtual Machines found on this system.": "No se encontraron máquinas virtuales en este sistema.", "No ZFS pools detected. Skipping ZFS ARC optimization.": "No se detectaron grupos ZFS.Saltándose la optimización ZFS ARC.", "No ZFS pools detected. Skipping ZFS autotrim.": "No se detectaron grupos ZFS. Saltarse el recorte automático de ZFS.", + "No acceleration (CPU)": "Sin aceleración (CPU)", "No accessible": "No accesible", "No accessible NFS servers found.": "No se encontraron servidores NFS accesibles.", "No accessible Samba servers found.": "No se encontraron servidores Samba accesibles.", @@ -2900,11 +3807,13 @@ "No active session": "Ninguna sesión activa", "No additional GPU can be added.": "No se puede agregar ninguna GPU adicional.", "No additional device needs to be added.": "No es necesario agregar ningún dispositivo adicional.", + "No applications match": "Ninguna aplicación coincide", "No archives": "Sin archivos", "No archives found in this Borg repository.": "No se encontraron archivos en este repositorio Borg.", "No available Controllers/NVMe devices were found.": "No se encontraron controladores/dispositivos NVMe disponibles.", "No available disks found.": "No se encontraron discos disponibles.", "No backup found, logrotate configuration not changed": "No se encontró ninguna copia de seguridad, la configuración de logrotate no cambió", + "No backup is scheduled: the rsnapshot lines in /config/crontabs/root are commented out. Uncomment or adjust the intervals you want, then restart the container.": "No se programa ninguna backup: se comentan las líneas rsnapshot en /config/crontabs/root. Descomponer o ajustar los intervalos que desee, reiniciar el contenedor.", "No backups": "Sin copias de seguridad", "No backups found": "No se encontraron copias de seguridad", "No bridge configuration issues found": "No se encontraron problemas de configuración del puente", @@ -2921,6 +3830,7 @@ "No compatible PVE jobs": "No hay tareas PVE compatibles", "No compatible disk images found in:": "No se encontraron imágenes de disco compatibles en:", "No configuration issues found": "No se encontraron problemas de configuración", + "No container of the stack was modified.": "No se modificó ningún contenedor de la pila.", "No container runtime available.": "No hay tiempo de ejecución de contenedor disponible.", "No container selected. Exiting.": "No se seleccionó ningún contenedor. Saliendo.", "No controller/NVMe selected.": "No se seleccionó ningún controlador/NVMe.", @@ -2951,11 +3861,13 @@ "No folders found in /mnt. Please create a new folder.": "No se encontraron carpetas en /mnt. Por favor cree una nueva carpeta.", "No folders found inside /mnt in the CT.": "No se encontraron carpetas dentro de /mnt en el CT.", "No format-safe disks are available.": "No hay discos con formato seguro disponibles.", + "No free ProxMenux private /24 network is available": "No gratuito ProxMenux red privada /24 está disponible", "No gasket DKMS registrations remain.": "No quedan registros de gasket en DKMS.", "No group creation required — uses world-writable sticky bit permissions.": "No se requiere creación de grupos: utiliza permisos de bits adhesivos de escritura mundial.", "No host VFIO reconfiguration expected": "No se espera reconfiguración del VFIO del host", "No host VFIO/native binding changes were required.": "No se requirieron cambios de enlace nativo/VFIO del host.", "No host backups were found in this PBS repository:": "No se encontraron copias de seguridad del host en este repositorio de PBS:", + "No host directory is used by this application.": "Esta aplicación no utiliza ningún directorio host.", "No host reboot expected": "No se espera reiniciar el host", "No host write access — server-side ACL or root_squash. Continuing anyway.": "Sin acceso de escritura al host: ACL del lado del servidor o root_squash. Continuando de todos modos.", "No host write access — server-side ACL. Continuing anyway.": "Sin acceso de escritura al host: ACL del lado del servidor. Continuando de todos modos.", @@ -2964,6 +3876,7 @@ "No iSCSI storage configured.": "No hay almacenamiento iSCSI configurado.", "No iSCSI storage found in Proxmox.": "No se encontró almacenamiento iSCSI en Proxmox.", "No iSCSI targets found on portal": "No se encontraron objetivos iSCSI en el portal", + "No image was given": "No se dio ninguna imagen", "No import disks selected for now.": "No se han seleccionado discos de importación por ahora.", "No importable disks available. System disks and protected disks are hidden.": "No hay discos importables disponibles. Los discos del sistema y los discos protegidos están ocultos.", "No installation information available.": "No hay información de instalación disponible.", @@ -2975,6 +3888,7 @@ "No mount point was specified.": "No se especificó ningún punto de montaje.", "No mount points found in any container": "No se encontraron puntos de montaje en ningún contenedor.", "No mount points found in container": "No se encontraron puntos de montaje en el contenedor", + "No name was given": "No se dio nombre", "No network configuration backups found.": "No se encontraron copias de seguridad de la configuración de red.", "No network interfaces configured (besides loopback)": "No hay interfaces de red configuradas (aparte del loopback)", "No new Controller/NVMe entries were added.": "No se agregaron nuevas entradas de Controlador/NVMe.", @@ -2999,9 +3913,11 @@ "No scheduled backup jobs configured.": "No se han configurado trabajos de copia de seguridad programados.", "No scheduled backup jobs found.": "No se encontraron tareas de copia de seguridad programadas.", "No scripts found for:": "No se encontraron secuencias de comandos para:", + "No security relaxation is required for the reviewed profile.": "No hay relajación de seguridad es necesario para el perfil revisado.", "No self-test history found for": "No se encontró ningún historial de autoevaluación para", "No self-test log available for": "No hay ningún registro de autoprueba disponible para", "No server IP or hostname provided.": "No se proporcionó ninguna IP de servidor ni nombre de host.", + "No shared media content.": "No hay contenido multimedia compartido.", "No shared mount detected. Applying standard local access.": "No se detectó ningún montaje compartido. Aplicando acceso local estándar.", "No shares configured.": "No hay recursos compartidos configurados.", "No shares found in smb.conf.": "No se encontraron acciones en smb.conf.", @@ -3031,24 +3947,34 @@ "No valid mount points found": "No se encontraron puntos de montaje válidos", "No version in this branch is currently supported by keylase/nvidia-patch — the NVENC patch will not reapply after reinstall.": "Actualmente, keylase/nvidia-patch no admite ninguna versión de esta rama; el parche NVENC no se volverá a aplicar después de la reinstalación.", "No virtual machines were found on this host.": "No se encontraron máquinas virtuales en este host.", + "No working NVIDIA GPU was found": "No se encontró GPU NVIDIA trabajando", "No write permissions on:": "Sin permisos de escritura en:", "No, keep local only": "No, mantener solo local", "No-subscription repository present": "Repositorio sin suscripción presente", "No: the key stays only at": "No: la clave permanece solo en", + "Node octal permissions (e.g. 0660)": "Permisos octales del nodo (por ejemplo, 0660)", "Non-Debian container detected": "Se detectó un contenedor que no es Debian", "Non-free firmware warnings disabled": "Advertencias de firmware no libre deshabilitadas", "None": "Ninguno", "Normalizing stable monitor service...": "Normalizando el servicio de monitor estable...", "Not Mounted": "No montado", + "Not a JSON object:": "No es un objeto JSON:", "Not all platforms support Controller/NVMe passthrough reliably.": "No todas las plataformas admiten el paso a través de Controller/NVMe de manera confiable.", + "Not all shared directories were verified": "No todos los directorios compartidos fueron verificados", "Not an OVH server, skipping RTM installation": "No es un servidor OVH, se salta la instalación de RTM", "Not currently mounted": "Actualmente no montado", "Not currently mounted — skipping umount.": "Actualmente no montado: omitiendo el desmontaje.", + "Not enough free space for the backup": "No suficiente espacio libre para el backup", "Not found": "Extraviado", + "Not found in the OCI archive:": "No se encuentra en el archivo OCI:", "Not imported:": "No importado:", "Not mounted": "No montado", "Not portable:": "No portátil:", "Not registered as Proxmox storage — use 'LXC Mount Manager' to bind-mount": "No registrado como almacenamiento enProxmox: use 'LXC Mount Manager' para vincular el montaje", + "Not required (access code only)": "No necesario (código de acceso solamente)", + "Not required (password only)": "No necesario (sólo contraseña)", + "Not required (token only)": "No necesario (token only)", + "Not yet verified by ProxMenux (beta)": "Aún no ha sido verificada por ProxMenux (beta)", "Note: A system reboot will be required after enabling IOMMU.": "Nota: Será necesario reiniciar el sistema después de habilitar IOMMU.", "Note: this only works if the NFS server does NOT use 'all_squash' for root.": "Nota: esto sólo funciona si el servidor NFS NO usa 'all_squash' como root.", "Notes": "Notas", @@ -3063,8 +3989,18 @@ "Nothing to schedule for reboot from selected paths.": "No hay nada que programar para reiniciar desde las rutas seleccionadas.", "Nouveau module is loaded, attempting to unload...": "El módulo Nouveau está cargado, intentando descargarse...", "Number of CPU cores (default: 2)": "Número de núcleos de CPU (predeterminado: 2)", + "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources.": "Nzbget es un descargador de Usenet, escrito en C++ y diseñado con el rendimiento en mente para lograr la máxima velocidad de descarga utilizando muy pocos recursos del sistema.", + "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra.": "Nzbhydra2 es una meta aplicación de búsqueda para los indexadores NZB, el sucesor espiritual de NZBmegasearcH, y una evolución de la aplicación original NZBHydra.", "OCI containers require Proxmox VE 9.1 or later.": "Los contenedores OCI requieren Proxmox VE 9.1 o posterior.", + "OCI management": "Gestión OCI", + "OCI management could not be completed. Check the backend status; no additional cleanup has been authorized.": "La gestión OCI no pudo completarse. Comprueba el estado del backend; no se ha autorizado ninguna limpieza adicional.", + "OCI manager Apps is a beta: if something does not work as expected, please report it on GitHub with the application name.": "OCI manager Apps es una beta: si algo no funciona como esperabas, repórtalo en GitHub con el nombre de la aplicación.", + "OCI metadata integrity mismatch": "Desigualdad de la integridad de los metadatos de la OCI", + "OCI metadata too large": "Metadatos demasiado grandes", + "OCI stack management": "Gestión de pilas OCI", + "OCI verification failed:": "La verificación de la OCI falló:", "OK": "DE ACUERDO", + "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms.": "ONLYOFFICE ofrece una amplia gama de herramientas para crear, editar y colaborar en documentos de texto, hojas de cálculo, presentaciones, formularios PDF y archivos PDF regulares en plataformas web, de escritorio y móviles.", "OR add new PVE 9 no-subscription repository:": "O agregue un nuevo repositorio PVE 9 sin suscripción:", "OS hint:": "Sugerencia del sistema operativo:", "OS release details": "Detalles de la versión del sistema operativo", @@ -3078,11 +4014,18 @@ "OVH RTM removed (Puppet artefacts may need manual cleanup)": "OVH RTM eliminado (los artefactos de las marionetas pueden necesitar una limpieza manual)", "OVH server detected": "Servidor OVH detectado", "OVH server detection and RTM installation process completed": "Finalizado el proceso de detección del servidor OVH e instalación de RTM", + "Observer is not responding on port 4357": "El observador no responde en el puerto 4357", + "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption.": "Obsidian es una aplicación de toma de notas que te permite crear, vincular y organizar tus notas en tu dispositivo, con cientos de plugins y temas para personalizar tu flujo de trabajo. También puede publicar sus notas en línea, acceder a ellas sin conexión y sincronizarlas de forma segura con encriptación de extremo a extremo.", "Offer as exit node?": "¿Oferta como nodo de salida?", + "Official Emby Media Server image with optional VA-API or NVIDIA acceleration.": "Imagen oficial Emby Media Server con aceleración opcional VA-API o NVIDIA.", + "Official Jellyfin image with optional VA-API or NVIDIA acceleration.": "Imagen oficial Jellyfin con aceleración opcional VA-API o NVIDIA.", "Official Linux Distributions": "Distribuciones oficiales de Linux", + "Official Plex Media Server image with optional hardware transcoding.": "Imagen oficial Plex Media Server con transcodificación de hardware opcional.", + "Official image": "Imagen oficial", "Old debian.sources file removed to prevent duplication": "Se eliminó el antiguo archivo debian.sources para evitar la duplicación", "Old memory configuration detected. Replacing with balanced optimization...": "Se detectó una configuración de memoria antigua. Reemplazando con optimización equilibrada...", "Old time services removed successfully": "Servicios antiguos eliminados con éxito", + "Ombi allows you to host your own Plex Request and user management system.": "Ombi le permite albergar su propio sistema de solicitud y gestión de usuarios Plex.", "On a privileged CT the mount options carry the only permissions.": "En un CT privilegiado, las opciones de montaje tienen los únicos permisos.", "On some systems, when starting the VM the host may slow down for several minutes until it stabilizes, or freeze completely.": "En algunos sistemas, al iniciar la máquina virtual, el host puede ralentizarse durante varios minutos hasta que se estabilice o se congele por completo.", "On the Borg server, append the following line to:": "en el servidor Borg, agregue la siguiente línea a:", @@ -3091,32 +4034,53 @@ "Once finished, re-run the script 'PVE 8 to 9 check' to verify that all issues.": "Una vez terminado, vuelva a ejecutar el script 'PVE 8 to 9 check' para verificar que todos los problemas.", "Once installed, open the VirtIO ISO and run the installer to complete driver setup.": "Una vez instalado, abra VirtIO ISO y ejecute el instalador para completar la configuración del controlador.", "One or more NVIDIA GPUs are currently configured for VM passthrough (vfio-pci):": "Actualmente, una o más GPU NVIDIA están configuradas para el paso a través de VM (vfio-pci):", + "Online retro games emulator": "emulador de juegos retro en línea", + "Only a Docker Swarm uses these settings, so they are not applied:": "Solo un Docker Swarm utiliza estos ajustes, por lo que no se aplican:", "Only convert to privileged if absolutely necessary for your use case.": "Convierta a privilegiado solo si es absolutamente necesario para su caso de uso.", "Only fully free disks are shown (not system-used and not referenced by VM/LXC).": "Solo se muestran los discos completamente libres (no utilizados por el sistema y a los que VM/LXC no hace referencia).", "Only if using enterprise subscription": "Solo si usa una suscripción empresarial", "Only if using no-subscription repository": "Sólo si se utiliza un repositorio sin suscripción", "Only needed if you mounted the filesystem in step 6b": "Solo es necesario si montó el sistema de archivos en el paso 6b", + "Only one image at a time can be installed this way.": "Sólo una imagen a la vez se puede instalar de esta manera.", "Only removes storage definition, not remote data.": "Solo elimina la definición de almacenamiento, no los datos remotos.", "Only run this if you used LVM (step 6b):": "Ejecute esto solo si usó LVM (paso 6b):", "Only the host backup hook is removed — PVE vzdump jobs targeting this storage stay intact.": "solo se elimina el enlace de copia de seguridad del host; las tareas de PVE vzdump destinados a este almacenamiento permanecen intactos.", + "Only the image reference, with no Compose file": "Sólo la referencia de la imagen, sin archivo Compose", "Open": "Abierto", + "Open Source realtime backend in 1 file": "Open Source en tiempo real backend en 1 archivo", "Open rwx + default inheritance for new files": "Abra rwx + herencia predeterminada para archivos nuevos", + "Open source chat UI for AI models": "Chat de código abierto UI para modelos AI", + "Open source home automation that puts local control and privacy first.": "Automatización casera de código abierto que pone el control local y la privacidad primero.", + "Open source, lightweight, native, supports (HTTP, BitTorrent, Magnet, etc.) for downloading.": "Fuente abierta, ligero, nativo, soporta (HTTP, BitTorrent, Magnet, etc.) para descargar.", "Open the VM console and wait for the installer to boot": "Abra la consola VM y espere a que se inicie el instalador.", "Open the VM console and wait for the loader to boot": "Abra la consola VM y espere a que se inicie el cargador.", "Open the dashboard from this host on port 8008 to create a new admin account.": "Abra el panel de este host en el puerto 8008 para crear una nueva cuenta de administrador.", "Open the dashboard to create a new admin account:": "Abra el panel para crear una nueva cuenta de administrador:", + "Open-source AI-powered coding assistant": "Asistente de codificación de código abierto", + "Open-source UI for building and debugging multi-agent and RAG applications": "UI de código abierto para la construcción y depuración de aplicaciones multiagentes y RAG", + "Open-source self-hosted SQL IDE.": "SQL IDE de código abierto.", + "OpenClaw is a personal AI assistant you run on your own devices": "OpenClaw es un asistente personal de inteligencia artificial que ejecuta en sus propios dispositivos", + "OpenList": "OpenList", + "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world.": "OpenShot Video Editor es un galardonado editor de vídeo gratuito y de código abierto para Linux, Mac y Windows, y está dedicado a ofrecer soluciones de edición y animación de vídeo de alta calidad al mundo.", + "OpenVINO requires a CPU quota to keep the CPU topology": "OpenVINO requiere una cuota de CPU para mantener la topología de la CPU", + "OpenVINO requires the render device of an Intel GPU": "OpenVINO requiere el dispositivo renderizado de una GPU Intel", "OpenVSwitch installation could not be verified": "No se pudo verificar la instalación de OpenVSwitch", "OpenVSwitch installed successfully": "OpenVSwitch se instaló exitosamente", "OpenVSwitch is ready to use": "OpenVSwitch está listo para usar", "OpenVSwitch removed": "OpenVSwitch eliminado", + "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server.": "Openssh-servidor es un entorno de sandboxed que permite el acceso de ssh sin dar claves a todo el servidor.", + "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser.": "Openvscode-servidor proporciona una versión de código VS que ejecuta un servidor en una máquina remota y permite el acceso a través de un navegador web moderno.", + "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features.": "Opera es un navegador web multiplataforma desarrollado por su empresa de nombres Opera. El navegador está basado en Chromium, pero se distingue de otros navegadores basados en Chromium (Chrome, Edge, etc.) a través de su interfaz de usuario y otras características.", "Operation": "Operación", "Operation cancelled by user": "Operación cancelada por el usuario", "Operation cancelled by user to create backup.": "Operación cancelada por el usuario para crear copia de seguridad.", "Operation cancelled by user.": "Operación cancelada por el usuario.", + "Operation cancelled.": "Operación cancelada.", "Operation cancelled. Cannot continue with an unprivileged container.": "Operación cancelada. No se puede continuar con un contenedor sin privilegios.", "Operation log": "Registro de operaciones", "Operator config re-applied via kernel-agnostic merge": "La configuración del operador se volvió a aplicar mediante una fusión independiente del kernel", "Operator config that WILL be re-applied via kernel-agnostic merge": "Configuración del operador que se volverá a aplicar mediante una combinación independiente del kernel", + "Optical block device (e.g. /dev/sr0)": "Dispositivo de bloque óptico (por ejemplo /dev/sr0)", "Optimizations detected and ready to revert.": "Optimizaciones detectadas y listas para revertir.", "Optimize": "Optimizar", "Optimize Memory": "Optimizar memoria", @@ -3129,8 +4093,12 @@ "Optimizing network settings...": "Optimizando la configuración de red...", "Optimizing vzdump backup speed...": "Optimizando la velocidad de copia de seguridad de vzdump...", "Optional": "Opcional", + "Optional GID of the plex group": "GID opcional del grupo plex", "Optional GPU Passthrough": "Paso de GPU opcional", + "Optional published URL for Jellyfin": "URL publicada opcional para Jellyfin", "Optional safety helper if you ever need to re-apply manually:": "Ayudante de seguridad opcional si alguna vez necesita volver a aplicar manualmente:", + "Optional token from https://www.plex.tv/claim": "Opcional token from https://www.plex.tv/claim", + "Optional, not mounted by default": "Opcional, no montado por defecto", "Optional: Modernize repository sources:": "Opcional: Modernice las fuentes del repositorio:", "Optional: apply default ACL so new files inherit permissions:": "Opcional: aplique la ACL predeterminada para que los archivos nuevos hereden permisos:", "Optional: register this path as Proxmox dir storage:": "Opcional: registre esta ruta como almacenamiento de directorios de Proxmox:", @@ -3141,13 +4109,18 @@ "Or re-run this script and accept the 'apply host permissions' prompt.": "O vuelva a ejecutar este script y acepte el mensaje \"aplicar permisos de host\".", "Or use ProxMenux update function": "O utilice la función de actualización de ProxMenux", "Or, if your terminal can't select text, copy it from:": "O, si tu terminal no puede seleccionar texto, cópialo desde:", + "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community": "Orca Slicer es un rebanador de código abierto para impresoras FDM. OrcaSlicer es fork de Bambu Studio, anteriormente conocido como BambuStudio-SoftFever, Bambu Studio es forked de PrusaSlicer por Prusa Research, que es de Slic3r por Alessandro Ranellucci y la comunidad RepRap", "Original ZFS ARC config restored from .bak": "Configuración original de ZFS ARC restaurada desde .bak", "Original bashrc restored": "Bashrc original restaurado.", "Original logrotate configuration restored": "Configuración original de logrotate restaurada", + "Orphan stack contract archived:": "Contrato de pila de huérfano archivado:", + "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.": "Oscam es un software de módulos de acceso condicional de código abierto utilizado para descifrar transmissions DVB utilizando tarjetas inteligentes. Es un servidor y un cliente.", "Other Prebuilt Linux VMs": "Otras máquinas virtuales Linux prediseñadas", "Output archive:": "Archivo de salida:", + "Overseerr is a request management and media discovery tool built to work with your existing Plex ecosystem.": "Overseerr es una herramienta de gestión de solicitudes y descubrimiento de medios construida para trabajar con su ecosistema Plex existente.", "Owner:": "Dueño:", "Ownership set to root:sharedfiles with 2775 on:": "Propiedad establecida en root:sharedfiles con 2775 en:", + "P2P bittorrent download": "P2P bittorrent descarga", "PAM limits configured": "Límites PAM configurados", "PBS API log rotation configured (hourly, size-based)": "Rotación de registros de API de PBS configurada (por horas, según el tamaño)", "PBS backup error log": "Registro de errores de copia de seguridad de PBS", @@ -3164,7 +4137,9 @@ "PCI reset method": "Método de reinicio de PCI", "PCIe GPU passthrough requires:": "La transferencia de GPU PCIe requiere:", "PCIe/M.2 gasket-dkms": "gasket-dkms para PCIe/M.2", + "PCSX2 is an open source PS2 Emulator.": "PCSX2 es un emulador PS2 de código abierto.", "POSIX ACLs applied (access + default for inheritance).": "ACL POSIX aplicadas (acceso + valor predeterminado para herencia).", + "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability.": "PPSSPP es un emulador PSP gratuito y de código abierto para Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series y Symbian con un enfoque en velocidad y portabilidad.", "PVE application manager updated": "Administrador de aplicaciones PVE actualizado", "PVE cache regenerated": "Caché PVE regenerado", "PVE host (where the Borg LXC lives)": "Host PVE (donde se encuentra el LXC de Borg)", @@ -3179,17 +4154,28 @@ "Package update had issues, checking details...": "La actualización del paquete tuvo problemas, comprobando detalles...", "Packages from backup to install:": "Paquetes de copia de seguridad para instalar:", "Packages installed: {count}.": "Paquetes instalados: {count}.", + "Packages to be upgraded": "Paquetes a actualizar", "Packages upgrade successfull": "Actualización de paquetes exitosa", "Packages upgraded": "Paquetes actualizados", "Packages:": "Paquetes:", "Packaging OVA file...": "Embalaje archivo OVA...", "Packing installer archive...": "Empaquetando el archivo del instalador...", + "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices.": "PairDrop es una alternativa sublime a AirDrop que funciona en todas las plataformas. Envíe imágenes, documentos o texto a través de pares para conectarse a dispositivos en la misma red local/Wi-Fi o para dispositivos emparejados.", + "Paperless configuration cancelled": "Configuración de Paperless cancelada", + "Paperless-ngx WebUI": "Paperless-ngx WebUI", "Parsing OVF descriptor...": "Analizando el descriptor OVF...", "Partial VM removed": "Máquina virtual eliminada parcialmente", "Partition": "Dividir", "Partition created": "Partición creada", "Partition created:": "Partición creada:", "Partition table wiped": "Tabla de particiones limpiada", + "Pass /dev/kvm to the LXC": "Paso /dev/kvm al LXC", + "Pass /dev/net/tun to the LXC": "Paso /dev/net/tun al LXC", + "Pass /dev/ttyUSB0 to the LXC": "Paso /dev/ttyUSB0 al LXC", + "Pass /dev/video10 to the LXC": "Paso /dev/video10 al LXC", + "Pass /dev/video11 to the LXC": "Paso /dev/video11 al LXC", + "Pass /dev/video12 to the LXC": "Paso /dev/video12 al LXC", + "Pass a host device to the LXC": "Pase un dispositivo host al LXC", "Passphrase used to unlock the imported keyfile (leave blank if the keyfile is unencrypted / kdf=none):": "frase de contraseña utilizada para desbloquear el archivo de claves importado (déjelo en blanco si el archivo de claves no está cifrado/kdf=none):", "Passphrases do not match.": "Las frases de contraseña no coinciden.", "Passphrases do not match. Try again.": "Las frases de contraseña no coinciden. Intentar otra vez.", @@ -3202,14 +4188,37 @@ "Password confirmation cannot be empty.": "La confirmación de contraseña no puede estar vacía.", "Password confirmation is required.": "Se requiere confirmación de contraseña.", "Password for": "Contraseña para", + "Password for the SSH login": "Contraseña para el login SSH", "Password for:": "Contraseña para:", "Password is correct": "La contraseña es correcta", + "Password of the AdGuard Home that receives the settings": "Contraseña del AdGuard Home que recibe la configuración", + "Password of the Adguardhome Sync web interface": "Contraseña de la interfaz web Adguardhome Sync", + "Password of the Duplicati web interface": "Contraseña de la interfaz web Duplicati", + "Password of the Etherpad admin user": "Contraseña del usuario de admin Etherpad", + "Password of the FlexGet web interface": "Contraseña de la interfaz web FlexGet", + "Password of the LibreDB Studio administrator": "Contraseña del administrador LibreDB Studio", + "Password of the MineOS web interface user": "Contraseña del usuario de interfaz web MineOS", + "Password of the NetBox admin account": "Contraseña de la cuenta de administración NetBox", + "Password of the OpenList admin user": "Contraseña del usuario de admin OpenList", + "Password of the PhotoPrism admin user (at least 8 characters)": "Contraseña del usuario de PhotoPrism admin (al menos 8 caracteres)", + "Password of the PostgreSQL user": "Contraseña del usuario de PostgreSQL", + "Password of the SnapOtter admin user": "Contraseña del usuario de admin SnapOtter", + "Password of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Password of the deprecated Flowise application login (sólo leído por Flowise versiones antes de 3.0.1)", + "Password of the main AdGuard Home": "Contraseña del AdGuard Home principal", "Password or API token secret:": "Contraseña o token secreto de API:", + "Password or secret": "Contraseña o secreto", "Password reset completed.": "Restablecimiento de contraseña completado.", + "Password to access the aMule web interface": "Contraseña para acceder a la interfaz web aMule", "Passwords do not match. Please try again.": "Las contraseñas no coinciden. Por favor inténtalo de nuevo.", + "Paste it here and press Ctrl+D on an empty line.": "Pégalo aquí y pulsa Ctrl+D en una línea vacía.", + "Paste its Compose file in the terminal": "Pega su archivo Compose en la terminal", + "Paste its docker run command in the terminal": "Pega su comando docker run en la terminal", "Paste the UUP Dump URL here": "Pegue la URL del volcado UUP aquí", "Patching source for kernel compatibility...": "Fuente de parcheo para compatibilidad del kernel...", "Path does not exist.": "La ruta no existe.", + "Path inside the container": "Ruta dentro del contenedor", + "Path inside the container (e.g. /media-extra)": "Ruta dentro del contenedor (por ejemplo /media-extra)", + "Path inside the remote (empty = root)": "Ruta dentro del remoto (vacío = raíz)", "Path must be absolute (start with /)": "La ruta debe ser absoluta (comenzar con /)", "Path must be absolute (start with /).": "La ruta debe ser absoluta (comenzar con /).", "Path not found": "Ruta no encontrada", @@ -3220,6 +4229,9 @@ "Paths skipped:": "Rutas omitidas:", "Paths to back up:": "Rutas para realizar copias de seguridad:", "Paths:": "Rutas:", + "Peers reach the server through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Peers alcanza el servidor a través de la dirección pública y el puerto UDP dado durante la instalación, de modo que el puerto debe ser enviado a este contenedor.", + "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration.": "Pelorus es un navegador de IA para los escritorios Linux impulsados por Selkies. Pelorus ejecuta un servidor FastAPI que da un agente LLM (Ollama, OpenAI-compatible, o Gemini) control sobre el ratón, teclado, captura de pantalla y gestión de ventanas a través del backend de uso de computadora Pixelflux, un árbol de accesibilidad de Linux (AT-SPI), y la integración opcional KWin D-Bus.", + "Pending components:": "Componentes pendientes:", "Pending restore ID:": "ID de restauración pendiente:", "Pending restore dir:": "Directorio de restauración pendiente:", "Pending restore prepared. A reboot is required to complete it.": "Restauración pendiente preparada. Es necesario reiniciar para completarlo.", @@ -3243,7 +4255,15 @@ "Permission error": "error de permiso", "Permissions:": "Permisos:", "Persist mount in CT /etc/fstab (optional):": "Montaje persistente en CT /etc/fstab (opcional):", + "Persistence for": "Persistencia para", + "Persistence for the new path": "Persistencia para la nueva ruta", + "Persistent data:": "Datos persistentes:", + "Persistent disk reused:": "Disco persistente reutilizado:", "Persistent:": "Persistente:", + "Personal finance management application": "Aplicación de gestión de finanzas personales", + "Photo and video library with optional GPU transcoding and machine learning": "Foto y videoteca con transcodificación GPU opcional y aprendizaje automático", + "PhotoPrism": "PhotoPrism", + "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB.": "Phpmyadmin es una herramienta de software libre escrita en PHP, destinada a manejar la administración de MySQL sobre la Web. phpMyAdmin admite una amplia gama de operations en MySQL y MariaDB.", "Physical Function with": "Función física con", "Physical interface": "Interfaz física", "Physical interfaces available": "Interfaces físicas disponibles", @@ -3256,6 +4276,10 @@ "Pick a target to remove:": "elija un objetivo para eliminar:", "Pick an SSH private key (auto-detected on this host):": "elija una clave privada SSH (detectada automáticamente en este host):", "Pick an alternative way to authorize the new key:": "elija una forma alternativa de autorizar la nueva clave:", + "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time.": "Pidgin es un programa de chat que le permite iniciar sesión en cuentas en múltiples redes de chat simultáneamente. Esto significa que puede estar charlando con amigos en XMPP y sentado en un canal IRC al mismo tiempo.", + "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper.": "Piper es un texto neuronal rápido y local al sistema de habla que suena genial y está optimizado para el Raspberry Pi 4. Este contenedor proporciona un servidor de protocolo de Wyoming para Piper.", + "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures.": "Piwigo es un software de galería de fotos para la web que viene con potentes funciones para publicar y gestionar su colección de imágenes.", + "Planka is an elegant open source project tracking tool.": "Planka es una elegante herramienta de seguimiento de proyectos de código abierto.", "Please check network connectivity.": "Por favor verifique la conectividad de la red.", "Please check permissions and try again.": "Por favor verifique los permisos e inténtelo nuevamente.", "Please check the installation.": "Por favor verifique la instalación.", @@ -3273,6 +4297,9 @@ "Please select GPU(s) that are currently in the same mode and try again.": "Seleccione las GPU que se encuentran actualmente en el mismo modo e inténtelo de nuevo.", "Please select a valid option": "Por favor seleccione una opción válida", "Please use an SSH session (Linux, macOS, Windows/PuTTY) or a physical console to perform the upgrade.": "Utilice una sesión SSH (Linux, macOS, Windows/PuTTY) o una consola física para realizar la actualización.", + "Plex WebUI": "Plex WebUI", + "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.": "Plex organiza vídeo, música y fotos de bibliotecas de medios personales y los transmite a televisores inteligentes, cajas de streaming y dispositivos móviles. Este contenedor se envasa como un servidor multimedia Plex independiente. Diseño directo y acciones a granel significan hacer las cosas más rápido.", + "Podcast synchronization service": "Servicio de sincronización de podcast", "Pool does not appear to use SSD/NVMe devices with discard support. Skipping ZFS autotrim for pool:": "El grupo no parece utilizar dispositivos SSD/NVMe con soporte de descarte. Saltar el ajuste automático de ZFS para el grupo:", "Pool exists": "Pool existe", "Pool name matches but GUID differs (fresh ZFS install):": "el nombre del grupo coincide pero el GUID difiere (instalación nueva de ZFS):", @@ -3283,12 +4310,20 @@ "Portal IP and port are correct": "La IP y el puerto del portal son correctos", "Portal is reachable": "El portal es accesible", "Portal:": "Portal:", + "Ports": "Puertos", "Portuguese": "portugués", "Post-Installation Options": "Opciones Post-Install", "Post-Installation Scripts": "Scripts Post-Install", "Postfix configuration": "Configuración de sufijo", + "PostgreSQL": "PostgreSQL", + "PostgreSQL URL without an associated service:": "URL de PostgreSQL sin un servicio asociado:", + "PostgreSQL creates the database named in POSTGRES_DB on the first start. The installer default is postgresql.": "PostgreSQL crea la base de datos llamada en POSTGRES DB en el primer comienzo. El instalador predeterminado es postgresql.", + "PostgreSQL is an advanced, enterprise-class, and open-source relational database system. PostgreSQL supports both SQL (relational) and JSON (non-relational) querying.": "PostgreSQL es un sistema de bases de datos relacionales avanzado, de clase empresarial y de código abierto. PostgreSQL soporta tanto SQL (relacional) como JSON (no-relacional) querying.", + "PostgreSQL volume size in GB": "Tamaño del volumen de PostgreSQL en GB", "Potential QEMU startup/assertion failures": "Posibles fallos de inicio/afirmación de QEMU", "Power state D3cold/D0 transitions may be inaccessible": "Las transiciones del estado de energía D3cold/D0 pueden ser inaccesibles", + "Powerful OCR powered by DeepSeek AI": "Potente OCR alimentado por DeepSeek AI", + "Powerful networking tool": "Herramienta de redes potente", "Pre-check found": "Pre-comprobación encontrada", "Pre-configure destinations so you don't have to enter them every time you back up.": "preconfigure los destinos para que no tenga que ingresarlos cada vez que realice una copia de seguridad.", "Pre-existing gasket-dkms package removed.": "Se eliminó el paquete gasket-dkms preexistente.", @@ -3301,6 +4336,9 @@ "Preparing host mount...": "Preparando el montaje del host...", "Preparing pending restore (network-safe)": "Preparando restauración pendiente (segura para la red)", "Preparing staging area...": "Preparando el área de preparación...", + "Preparing the NVIDIA GPU...": "Preparando la GPU NVIDIA...", + "Preparing the recreation...": "Preparando la recreación...", + "Preparing the update...": "Preparando la actualización...", "Preserving logs to /var/log.hdd before unmounting...": "Preservando registros en /var/log.hdd antes de desmontar...", "Press 'q' to exit": "Presione 'q' para salir", "Press Ctrl+C to stop the server and return to menu.": "Presione Ctrl+C para detener el servidor y regresar al menú.", @@ -3316,6 +4354,7 @@ "Press Enter to return": "Presione Entrar para regresar", "Press Enter to return to menu...": "Presione Enter para regresar al menú...", "Press Enter to return to the main menu...": "Presione Enter para regresar al menú principal...", + "Press Enter to return to the menu...": "Pulse Enter para volver al menú...", "Press Enter to return...": "Presione Entrar para regresar...", "Press Enter when the line has been pasted on the server...": "presione Entrar cuando la línea se haya pegado en el servidor...", "Press OK to see the preview, then confirm": "Presione OK para ver la vista previa, luego confirme", @@ -3325,9 +4364,19 @@ "Preview changes (diff)": "Vista previa de cambios (diff)", "Preview: changes that would be applied": "Vista previa: cambios que se aplicarían", "Previous DKMS tree cleared.": "Se borró el árbol DKMS anterior.", + "Previous Rclone configuration restored": "Configuración Rclone anterior restaurada", "Previous installation cleaned": "Instalación anterior limpia", "Previous installation removed": "Instalación anterior eliminada", + "Previous installation restored": "Instalación anterior restaurada", "Previous shutdowns": "Paradas anteriores", + "Primary GID for Emby": "GID primario para Emby", + "Privacy-first finance app with envelope budgeting and multi-device sync.": "Aplicación de privacidad-primera aplicación financiera con sobre budgeting y sincronización multidispositivo.", + "Private installation record saved": "Registro de instalación privado guardado", + "Private network assigned automatically:": "Red privada asignada automáticamente:", + "Private network of the application released:": "Red privada de la aplicación liberada:", + "Private network of the application that is released:": "Red privada de la aplicación que se libera:", + "Private network:": "Red privada:", + "Private personal knowledge management": "Gestión privada de los conocimientos personales", "Privileged": "Privilegiado", "Privileged Container": "Contenedor privilegiado", "Privileged Container Required": "Se requiere contenedor privilegiado", @@ -3338,6 +4387,7 @@ "Privileged container — host root maps directly, no permission changes needed": "Contenedor privilegiado: aloja mapas raíz directamente, no se necesitan cambios de permisos", "Privileged containers can access host devices directly": "Los contenedores privilegiados pueden acceder a los dispositivos host directamente", "Privileged containers have full root access to the host system!": "¡Los contenedores privilegiados tienen acceso raíz completo al sistema host!", + "Privileged installation declined": "Instalación privilegiada rechazada", "Privileged: Full host access (less secure)": "Privilegiado: acceso completo al host (menos seguro)", "Proceed": "Proceder", "Proceed with removal": "Proceder con la eliminación", @@ -3346,11 +4396,15 @@ "Process may take several minutes depending on container size": "El proceso puede tardar varios minutos dependiendo del tamaño del contenedor.", "Process may take several minutes for large containers": "El proceso puede tardar varios minutos para contenedores grandes.", "Processes using NVIDIA:": "Procesos usando NVIDIA:", + "Productivity & Workflows": "Productividad " Workflows", "Profile": "Perfil", "Profile:": "Perfil:", + "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files.": "Projectsend es una aplicación autoalojada que le permite subir archivos y asignarlos a clientes específicos que usted crea. Seguro, privado y fácil. No más dependiendo de servicios externos o correo electrónico para enviar esos archivos.", "Proposed Changes": "Cambios propuestos", "Proposed ZFS ARC maximum:": "ZFS ARC máximo propuesto:", "Provided by newer version — skipping": "Proporcionado por una versión más reciente: omitir", + "Prowlarr does not offer the application schema:": "Prowlarr no ofrece el esquema de aplicación:", + "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all).": "Prowlarr es un gestor/proxy indexador construido en el popular arrr .net/reactjs base pila para integrarse con sus diversas aplicaciones PVR. Prowlarr soporta tanto los Trackers Torrent como los Indexers Usenet. Se integra perfectamente con Sonarr, Radarr, Lidarr, y Readarr ofreciendo una gestión completa de sus indexadores sin ninguna aplicación Configuración de indexadores necesario (lo hacemos todo).", "ProxMenux Information": "Información de ProxMenux", "ProxMenux Monitor": "ProxMenux Monitor", "ProxMenux Monitor Service Verification": "Verificación del servicio de ProxMenux Monitor", @@ -3364,10 +4418,12 @@ "ProxMenux Monitor protection": "Protección del ProxMenux Monitor", "ProxMenux Monitor unit repaired and restarted": "Unidad de ProxMenux Monitor reparada y reiniciada", "ProxMenux Monitor → Backups tab (live progress card with estimated time, logs, rollback delta)": "ProxMenux Monitor → pestaña Copias de seguridad (tarjeta de progreso en vivo con tiempo estimado, registros, delta de reversión)", + "ProxMenux attaches directories, not single files, so this image cannot be installed yet.": "ProxMenux adjunta directorios, no archivos individuales, por lo que esta imagen no se puede instalar todavía.", "ProxMenux can apply open permissions on this NFS directory from the host so the container can read and write:": "ProxMenux puede aplicar permisos de apertura en este directorio NFS desde el host para que el contenedor pueda leer y escribir:", "ProxMenux can remount it with open permissions so any LXC can read and write.": "ProxMenux puede volver a montarlo con permisos abiertos para que cualquier LXC pueda leer y escribir.", "ProxMenux cannot override NFS server-side permissions from the host.": "ProxMenux no puede anular los permisos del lado del servidor NFS del host.", "ProxMenux customizations removed from bashrc": "Personalizaciones de ProxMenux eliminadas de bashrc", + "ProxMenux does not give a container the system of its host.": "ProxMenux no le da a un contenedor el sistema de su host.", "ProxMenux does not validate the contents; any keyfile your PBS accepts is accepted here.": "ProxMenux no valida los contenidos;cualquier archivo clave que acepte su PBS se acepta aquí.", "ProxMenux files:": "Archivos ProxMenux:", "ProxMenux logo applied": "Logotipo de ProxMenux aplicado", @@ -3399,6 +4455,7 @@ "Proxmox repository configuration completed": "Configuración del repositorio Proxmox completada", "Proxmox repository fixed (no-subscription, candidate is 9.x)": "Repositorio de Proxmox arreglado (sin suscripción, el candidato es 9.x)", "Proxmox status:": "Estado de Proxmox:", + "Proxmox storage for the volume": "Almacenamiento Proxmox para el volumen", "Proxmox storages:": "Almacenamientos Proxmox:", "Proxmox system repair completed successfully!": "¡La reparación del sistema Proxmox se completó con éxito!", "Proxmox system repair completed with some issues.": "Reparación del sistema Proxmox completada con algunos problemas.", @@ -3408,16 +4465,27 @@ "Proxmox web interface: Datacenter > Storage > Add > SMB/CIFS": "Interfaz web de Proxmox: Centro de datos > Almacenamiento > Agregar > SMB/CIFS", "Proxmox web interface: Datacenter > Storage > Add > ZFS": "Interfaz web de Proxmox: Centro de datos > Almacenamiento > Agregar > ZFS", "Proxmox web interface: Datacenter > Storage > Add > iSCSI": "Interfaz web de Proxmox: Centro de datos > Almacenamiento > Agregar > iSCSI", + "Public UDP port clients connect to": "Público UDP port clients connect to", + "Public URL of phpMyAdmin when it is served behind a reverse proxy": "URL pública de phpMyAdmin cuando se sirve detrás de un proxy inverso", + "Public address clients connect to (vpn.example.com or a public IP)": "Los clientes de dirección pública se conectan a (vpn.example.com o IP pública)", + "Public address peers connect to, or auto to detect it (vpn.example.com)": "Los pares de direcciones públicas se conectan a, o auto para detectarlo (vpn.example.com)", "Pulling latest changes from GitHub...": "Sacando los últimos cambios de GitHub...", "Purge the gasket-dkms package": "Purgar el paquete gasket-dkms", "Purging gasket-dkms package...": "Purgando el paquete gasket-dkms...", "Purging log2ram apt package...": "Purgando el paquete log2ram apt...", + "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.": "Pwndrop es un servicio de hospedaje de archivos autodesplegable para enviar descargas de equipo rojo o compartir de forma segura sus archivos privados sobre HTTP y WebDAV.", + "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more.": "PyCharm ofrece soporte fuera de la caja para Python, bases de datos, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, y más.", + "Pydio Cells needs an external MySQL or MariaDB database. The setup wizard asks for its address, database name and user on the first start.": "Pydio Cells necesita una base de datos MySQL externa o MariaDB. El asistente de configuración pide su dirección, nombre de la base de datos y usuario en el primer comienzo.", + "Pydio Cells redirects to the address given in EXTERNALURL. If the container changes address, edit lxc.environment.runtime: EXTERNALURL and SERVER_IP in /etc/pve/lxc/.conf with the container stopped, and delete /config/keys/cert.crt to regenerate the certificate.": "Pydio Cells redirige a la dirección dada en EXTERNALURL. Si el contenedor cambia la dirección, edite lxc.environment.runtime: EXTERNALURL y SERVER IP en /etc/pve/lxc/Seguido CTID ratio.conf con el contenedor detenido, y elimine /config/keys/cert.crt para regenerar el certificado.", + "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture.": "Pydio-cells es la plataforma de intercambio de archivos de Nextgen para organizaciones. Es una reescritura completa del proyecto Pydio usando el lenguaje Go siguiendo una arquitectura de microservicio.", + "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat.": "QDirStat Estadísticas de directorios basadas en Qt: KDirStat sin ningún KDE -- del autor del original KDirStat.", "Quick health check (PASSED / FAILED)": "Chequeo de salud rápido (APROBADO / FALLADO)", "Quick health status — overall SMART result + key attributes": "Estado de salud rápido: resultado SMART general + atributos clave", "RAID Detected": "RAID detectado", "RAID member detected": "Miembro RAID detectado", "RAM Size": "Tamaño de RAM", "RAM and swap usage": "Uso de RAM y swap", + "RAM in MiB": "RAM en MiB", "REPAIR SUMMARY": "RESUMEN DE REPARACIÓN", "REQUIREMENTS:": "REQUISITOS:", "ROM dump not available — configuring without romfile.": "Volcado de ROM no disponible: configuración sin archivo rom.", @@ -3425,9 +4493,26 @@ "RPC Bind Service: RUNNING": "Servicio de enlace RPC: EN EJECUCIÓN", "RPC Bind Service: STOPPED": "Servicio de enlace RPC: DETENIDO", "RPC Bind Service: STOPPED - starting...": "Servicio de enlace RPC: DETENIDO - iniciando...", + "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD.": "RPCS3 es un emulador y depurador de código abierto multiplataforma Sony PlayStation 3 escrito en C++ para Windows, Linux, macOS y FreeBSD.", + "Radarr - A fork of Sonarr to work with movies à la Couchpotato.": "Radarr - Una fork de Sonarr para trabajar con películas a la Couchpotato.", + "Radarr added to Prowlarr": "Radarr añadido a Prowlarr", + "Radarr connected to qBittorrent": "Radarr conectado a qBittorrent", + "Radarr root folder configured": "Carpeta raíz Radarr configurada", + "RagFlow is an open-source RAG engine based on deep document understanding.": "RagFlow es un motor RAG de código abierto basado en la comprensión profunda de documentos.", + "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase.": "Raneto - es una plataforma de base de conocimientos de código abierto que utiliza archivos de marcación estática para alimentar su base de conocimientos.", + "Raneto web interface": "Interfaz web Raneto", + "RawTherapee is a free, cross-platform raw image processing program!": "RawTherapee es un programa gratuito de procesamiento de imágenes crudas multiplataforma!", + "Rclone WebUI": "Rclone WebUI", + "Rclone mount": "Montaje Rclone", + "Rclone mount active": "Montaje Rclone activo", + "Rclone mount needs a privileged LXC with FUSE access. The container is dedicated to Rclone and its web UI must not be exposed to untrusted networks.": "Rclone mount necesita un LXC privilegiado con acceso FUSE. El contenedor está dedicado a Rclone y su interfaz de usuario web no debe estar expuesto a redes no confiadas.", + "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network.": "Rclone mount requiere a privilegiada LXC con acceso FUSE. Utilice este perfil sólo en un nodo y red de confianza.", + "Rclone mount requires a privileged container": "Rclone mount requiere un contenedor privilegiado", "Re-enter the BORG REPOKEY passphrase to confirm:": "Vuelva a ingresar la frase de contraseña de BORG REPOKEY para confirmar:", "Re-running pre-check after repairs...": "Volviendo a ejecutar la verificación previa después de las reparaciones...", "Reachable": "Accesible", + "Read its Compose file from a file of this host": "Lea su archivo Compose desde un archivo de este host", + "Read the link with pct console CTID on the Proxmox host, or from the Console panel of the container in the Proxmox web interface, then open the https://playit.gg/claim/ address it shows in a browser and sign in to playit.gg. Ctrl+a q leaves pct console.": "Lea el enlace con la consola pct CTID en el host Proxmox, o desde el panel Console del contenedor en la interfaz web Proxmox, a continuación, abra la dirección https://playit.gg/claim/ que muestra en un navegador y regístrese para playit.gg. Ctrl+a q deja la consola pct.", "Read-Only": "Sólo lectura", "Read-Only access": "Acceso de sólo lectura", "Read-Write (universal)": "Lectura-Escritura (universal)", @@ -3436,6 +4521,7 @@ "Read-only access (or no write permissions).": "Acceso de solo lectura (o sin permisos de escritura).", "Read-only mount": "Montaje de solo lectura", "Read/Write (default)": "Lectura/Escritura (predeterminado)", + "Read/write": "Leer/escribir", "Read/write CPU model-specific registers": "Leer/escribir registros específicos del modelo de CPU", "Readable user table (UID, shell, etc.)": "Tabla de usuarios legible (UID, shell, etc.)", "Reading NVMe SMART data...": "Leyendo datos NVMe SMART...", @@ -3443,7 +4529,9 @@ "Reading SMART data...": "Leyendo datos SMART...", "Reading SMART self-test log...": "Leyendo el registro de autoprueba SMART...", "Reading full SMART report...": "Leyendo el informe SMART completo...", + "Real-time Performance Monitoring": "Supervisión del desempeño en tiempo real", "Real-time bandwidth usage (press q to exit)": "Uso de ancho de banda en tiempo real (presione q para salir)", + "Real-time collaborative document editor": "Editor de documentos colaborativos en tiempo real", "Real-time network monitoring (press q to exit)": "Monitoreo de red en tiempo real (presione q para salir)", "Real-time network usage (iftop)": "Uso de red en tiempo real (iftop)", "Reason: Access denied": "Razón: Acceso denegado", @@ -3465,6 +4553,7 @@ "Recent Samba server": "Servidor Samba reciente", "Recent logs:": "Registros recientes:", "Recent test results:": "Resultados de pruebas recientes:", + "Recognition profile not implemented": "Perfil de reconocimiento no implementado", "Recommendation: reformat the disk to ext4 for a robust setup — see docs.": "Recomendación: vuelva a formatear el disco a ext4 para una configuración sólida; consulte los documentos.", "Recommendation: start with Complete restore.": "Recomendación: comience con la restauración completa.", "Recommendation: use 'Export to file' for these paths and apply manually during a maintenance window.": "Recomendación: use 'Exportar a archivo' para estas rutas y aplíquelo manualmente durante una ventana de mantenimiento.", @@ -3476,17 +4565,35 @@ "Recommended: use GPU -> LXC mode for these devices.": "Recomendado: use GPU -> modo LXC para estos dispositivos.", "Recommended: use GPU with LXC workloads instead of VM passthrough on this hardware.": "Recomendado: use GPU con cargas de trabajo LXC en lugar de transferencia de VM en este hardware.", "Reconciled": "reconciliado", + "Recover OCI": "Recuperar OCI", + "Recover OCI stack": "Recuperar la pila OCI", + "Recover now?": "¿Recuperar ahora?", + "Recover or complete the operation?": "¿Recuperar o completar la operación?", "Recover the keyfile using your recovery passphrase?": "¿Recuperar el archivo clave usando su frase de contraseña de recuperación?", + "Recover the previous installation": "Recuperar la instalación anterior", "Recoverable:": "Recuperable:", + "Recovering the previous installation": "Recuperar la instalación anterior", "Recovery blob upload failed — main backup is OK, but keyfile recovery from PBS will not be available for this backup.": "Error en la carga del blob de recuperación: la copia de seguridad principal está bien, pero la recuperación del archivo clave de PBS no estará disponible para esta copia de seguridad.", "Recovery blob:": "blob de recuperación:", + "Recovery completed. The container had not been modified yet.": "Recuperación completada. El contenedor aún no había sido modificado.", + "Recovery completed. The displaced disks and the backup are kept; nothing was deleted automatically.": "Recuperación completada. Los discos desplazados y el backup se mantienen; nada fue eliminado automáticamente.", "Recovery failed": "La recuperación falló", "Recovery passphrase": "frase de contraseña de recuperación", "Recovery setup failed": "Error en la configuración de recuperación", + "Recreate": "Recrear", + "Recreate OCI": "Recrear OCI", + "Recreate with these options?": "¿Recrear con estas opciones?", + "Recreate: edit resources, network, paths and GPU": "Recrear: editar recursos, red, rutas y GPU", + "Recreating the container...": "Recreando el contenedor...", + "Recreating the container:": "Recreando el contenedor:", + "Recreation completed. Data kept.": "Recreación completada. Datos guardados.", + "Recreation prepared": "Recreación preparada", "Refresh APT index and verify repositories:": "Actualizar el índice APT y verificar los repositorios:", "Refresh your browser (Ctrl+Shift+R) to see changes": "Actualiza tu navegador (Ctrl+Shift+R) para ver los cambios", "Refresh your browser to see changes (server restart may be required)": "Actualice su navegador para ver los cambios (es posible que sea necesario reiniciar el servidor)", "Refreshing apt cache...": "Actualizando caché de apt...", + "Refreshing the NVIDIA runtime...": "Refrescando el tiempo de ejecución de NVIDIA...", + "Refusing an unexpected rootfs path:": "Refusing an inesperado rootfs path:", "Regenerating PVE package cache...": "Regenerando caché de paquetes PVE...", "Regenerating boot artifacts for the merged kernel-agnostic changes...": "Regenerando artefactos de arranque para los cambios fusionados independientes del kernel...", "Regenerating certificates and restarting services...": "Regenerando certificados y reiniciando servicios...", @@ -3502,6 +4609,7 @@ "Reinstalled Proxmox packages successfully": "Paquetes Proxmox reinstalados exitosamente", "Reinstalling": "reinstalar", "Reinstalling core Proxmox packages...": "Reinstalando los paquetes principales de Proxmox...", + "Relative CPU priority (cpuunits)": "Prioridad relativa de la CPU (cpuunits)", "Release Channel": "Canal de lanzamiento", "Release channel set to Beta.": "Canal de lanzamiento configurado en Beta.", "Release channel set to Stable.": "Canal de liberación configurado en Estable.", @@ -3511,8 +4619,12 @@ "Remapped Users:": "Usuarios reasignados:", "Remapped users:": "Usuarios reasignados:", "Reminder: You must install the QEMU Guest Agent inside the Windows VM": "Recordatorio: debe instalar el agente invitado QEMU dentro de la máquina virtual de Windows", + "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported.": "Remmina es un cliente de escritorio remoto escrito en GTK, con el objetivo de ser útil para administradores de sistemas y viajeros, que necesitan trabajar con un montón de computadoras remotas delante de pantallas grandes o pequeñas. Remmina admite múltiples protocolos de red, en una interfaz de usuario integrada y coherente. Actualmente se admiten RDP, VNC, SPICE, SSH y EXEC.", + "Remote Access & VPN": "Acceso remoto VPN", + "Remote dry run completed; no container was created.": "Corriente seca remota completada; no se creó ningún contenedor.", "Remote repository path:": "Ruta del repositorio remoto:", "Remote server via SSH (recommended — off-host, dedup across machines)": "servidor remoto a través de SSH (recomendado: fuera del host, desduplicación entre máquinas)", + "Remote verified:": "Comprobación remota:", "Remounting CIFS share with open permissions...": "Remontando el recurso compartido CIFS con permisos abiertos...", "Remove CIFS Mount": "Quitar montaje CIFS", "Remove CIFS Mount (pvesm or fstab)": "Quitar montaje CIFS (pvesm o fstab)", @@ -3540,6 +4652,7 @@ "Remove NFS fstab Mount": "Quitar el montaje fstab de NFS", "Remove NFS fstab mount:": "Quitar el montaje fstab de NFS:", "Remove NFS storage:": "Eliminar el almacenamiento NFS:", + "Remove OCI": "Eliminar OCI", "Remove Proxmox CIFS storage:": "Eliminar el almacenamiento CIFS de Proxmox:", "Remove Proxmox NFS storage:": "Eliminar el almacenamiento Proxmox NFS:", "Remove Proxmox iSCSI storage:": "Eliminar el almacenamiento iSCSI de Proxmox:", @@ -3551,6 +4664,7 @@ "Remove iSCSI storage definition:": "Eliminar la definición de almacenamiento iSCSI:", "Remove invalid port": "Eliminar puerto no válido", "Remove invalid port(s)": "Eliminar puertos no válidos", + "Remove it? The data of its containers cannot be recovered afterwards.": "¿Eliminarlo? Los datos de sus contenedores no se podrán recuperar después.", "Remove keyfile from this host": "eliminar el archivo de claves de este host", "Remove mount point:": "Eliminar punto de montaje:", "Remove obsolete systemd-boot meta-package": "Eliminar el metapaquete obsoleto systemd-boot", @@ -3559,6 +4673,7 @@ "Remove subscription banner": "Eliminar banner de suscripción", "Remove the unprivileged flag from configuration:": "Elimine la bandera sin privilegios de la configuración:", "Remove unused packages and their config": "Eliminar paquetes no utilizados y su configuración.", + "Remove: delete the application and its containers": "Eliminar: eliminar la aplicación y sus contenedores", "Removed": "Remoto", "Removed KVM MSR options from configuration": "Se eliminaron las opciones de KVM MSR de la configuración.", "Removed Mount:": "Montaje eliminado:", @@ -3609,6 +4724,9 @@ "Removing stale VFIO entries from vfio.conf...": "Eliminando entradas VFIO obsoletas de vfio.conf...", "Removing storage from Proxmox...": "Eliminando almacenamiento de Proxmox...", "Removing system limits optimizations...": "Eliminando optimizaciones de límites del sistema...", + "Removing the containers...": "Removiendo los contenedores...", + "Removing the incomplete stack...": "La eliminación de la pila incompleta...", + "Removing the previous container": "Remoción del contenedor anterior", "Removing utilities installed by ProxMenux...": "Eliminando utilidades instaladas por ProxMenux...", "Removing zfs-auto-snapshot...": "Eliminando zfs-auto-snapshot...", "Renamed": "Renombrado", @@ -3616,6 +4734,7 @@ "Repair Complete": "Reparación completa", "Repair Options:": "Opciones de reparación:", "Repairs and optimizes repositories": "Repara y optimiza repositorios", + "Repeat to confirm": "Repita para confirmar", "Replace": "Reemplazar", "Replace with the actual ID.": "Reemplace con el ID real.", "Replace with your actual container ID": "Reemplace con su ID de contenedor real", @@ -3628,12 +4747,16 @@ "Repositories switched to no-subscription": "Los repositorios cambiaron a sin suscripción", "Repository ready.": "Repositorio listo.", "Repository:": "Repositorio:", + "Request a staging certificate for testing: true or false": "Solicitar un certificado de estadificación para pruebas: verdaderas o falsas", "Require reboot": "Requerir reinicio", "Required command not found:": "Comando requerido no encontrado:", "Required if using a VirtIO or SCSI disk.": "Requerido si se utiliza un disco VirtIO o SCSI.", "Required install helpers not available.": "Los ayudantes de instalación necesarios no están disponibles.", + "Required new path cancelled": "Nueva ruta necesaria cancelada", + "Required persistent paths cannot be removed": "Las rutas persistentes necesarias no se pueden eliminar", "Requires acl package. Skip if setfacl is not available.": "Requiere paquete acl. Omita si setfacl no está disponible.", "Requires authentication": "Requiere autenticación", + "Reserving a private network...": "Reservando una red privada...", "Reset Capability Blocked": "Capacidad de reinicio bloqueada", "Reset Capability Warning": "Advertencia de capacidad de reinicio", "Reset Monitor Password": "Restablecer contraseña del monitor", @@ -3641,7 +4764,9 @@ "Reset current storage selection": "Restablecer la selección de almacenamiento actual", "Resetting time synchronization...": "Restableciendo la sincronización horaria...", "Residual Bookworm entries commented where applicable": "Entradas residuales de Bookworm comentadas cuando corresponda", + "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes.": "Resilio-sync (antes BitTorrent Sync) utiliza el protocolo BitTorrent para sincronizar archivos y carpetas entre todos sus dispositivos. Hay versiones gratuitas y pagadas, este contenedor soporta ambos. Hay una imagen oficial de sincronización, pero creamos ésta ya que soporta la asignación de usuarios para simplificar permisos para volúmenes.", "Resolve package conflicts": "Resolver conflictos de paquetes", + "Resources": "Recursos", "Restart Network": "Reiniciar la red", "Restart Network Service": "Reiniciar el servicio de red", "Restart Web UI proxy": "Reinicie el proxy de la interfaz de usuario web", @@ -3673,8 +4798,11 @@ "Restore plan summary": "Resumen del plan de restauración", "Restore source location": "Restaurar ubicación de origen", "Restored config is on disk; reboot the host to apply.": "La configuración restaurada está en el disco; reinicie el host para aplicar.", + "Restored installation checked": "Instalación restaurada", "Restored original /bin/gzip": "Restaurado original /bin/gzip", "Restored original /etc/vzdump.conf from .bak": "Restaurado /etc/vzdump.conf original desde .bak", + "Restored:": "Restaurado:", + "Restoring": "Restauración", "Restoring APT language downloads...": "Restaurando descargas del idioma APT...", "Restoring container memory to": "Restaurar la memoria del contenedor a", "Restoring default journald configuration...": "Restaurando la configuración predeterminada del diario...", @@ -3682,15 +4810,23 @@ "Restoring original bashrc...": "Restaurando bashrc original...", "Restoring original logrotate configuration...": "Restaurando la configuración original de logrotate...", "Restoring subscription banner...": "Restaurando el banner de suscripción...", + "Restoring the backup": "Restaurar el backup", "Restoring the original rpcbind service state...": "Restaurando el estado original del servicio rpcbind...", + "Restoring the previous Rclone configuration...": "Restaurar la configuración anterior de Rclone...", + "Restoring the previous backup...": "Restaurar el backup anterior...", + "Restoring the previous state of the stack...": "Restaurar el estado anterior de la pila...", + "Restoring the stack records...": "Restaurar los registros de la pila...", "Results will be saved automatically to:": "Los resultados se guardarán automáticamente en:", "Results will be saved to:": "Los resultados se guardarán en:", "Retention": "Retención", + "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface.": "RetroArch es un frontend para emuladores, motores de juego y jugadores de medios. Le permite ejecutar juegos clásicos en una amplia gama de computadoras y consolas a través de su interfaz gráfica slick.", "Return": "Volver", "Return to Main Menu": "Volver al menú principal", "Return to Share Menu": "Volver al menú Compartir", "Return to main menu": "Volver al menú principal", + "Returning the containers to their previous state...": "Devolviendo los contenedores a su estado anterior...", "Reused the encryption key from the PVE storage entry.": "reutilizó la clave de cifrado de la entrada de almacenamiento PVE.", + "Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container.": "Las muestras de proxy inversa para otras aplicaciones están en /config/nginx/proxy confs dentro del contenedor.", "Reverting AMD (Ryzen/EPYC) fixes...": "Revertir correcciones de AMD (Ryzen/EPYC)...", "Reverting IOMMU/VFIO configuration...": "Revirtiendo la configuración de IOMMU/VFIO...", "Reverting TCP BBR + Fast Open...": "Revertir TCP BBR + Apertura rápida...", @@ -3699,22 +4835,30 @@ "Reverting vzdump speed tuning...": "Revertir el ajuste de velocidad de vzdump...", "Review passthrough config files": "Revisar los archivos de configuración de paso a través", "Review what will be removed": "Revisa lo que se eliminará", + "Rip DVD and Blu-ray media from a browser": "Rip DVD y Blu-ray medios de un navegador", "Rollback: nothing to remove (host matches backup)": "Revertir: nada que eliminar (el host coincide con la copia de seguridad)", + "RomM is a self-hosted ROM manager for managing and playing game collections.": "RomM es un gestor de ROM auto hospedado para gestionar y jugar colecciones de juego.", "Root SSH keys/config": "Configuración/claves SSH raíz", "Root inside container = root on host system": "Raíz dentro del contenedor = raíz en el sistema host", + "Root privileges are required": "Los privilegios de raíz son necesarios", + "Root privileges on the Proxmox node are required": "Los privilegios de raíz en el nodo Proxmox son necesarios", "Root shell/profile config": "Configuración de perfil/shell raíz", "Root user on the PVE host (default 'root'):": "Usuario root en el host PVE ('root' predeterminado):", + "Rootfs size in GB": "Tamaño de los rootfs en GB", "Rotate the recovery passphrase": "rotar la frase de contraseña de recuperación", "Routing Information": "Información de ruta", "Routing Table": "Tabla de enrutamiento", + "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required.": "Rsnapshot es una utilidad instantánea del sistema de archivos basada en rsync. rsnapshot hace fácil hacer instantáneas periódicas de máquinas locales, y máquinas remotas sobre ssh. El código hace un uso amplio de enlaces duros siempre que sea posible, para reducir enormemente el espacio de disco necesario.", "Run 'Mount NFS Share' to install NFS client automatically.": "Ejecute «Montar recurso compartido NFS» para instalar automáticamente el cliente NFS.", "Run 'Mount Samba Share' to install CIFS client automatically.": "Ejecute «Montar recurso compartido Samba» para instalar automáticamente el cliente CIFS.", + "Run GGUF LLMs locally with GPU acceleration": "Ejecute GGUF LLMs localmente con aceleración GPU", "Run PVE 8 to 9": "Ejecuta PVE 8 a 9", "Run PVE 8 to 9 check": "Ejecute la verificación PVE 8 a 9", "Run \\\"Install NVIDIA Drivers on Host\\\" first so the installer is cached.": "Primero ejecute \\\"Instalar controladores NVIDIA en el host\\\" para que el instalador se almacene en caché.", "Run a full security audit": "Ejecute una auditoría de seguridad completa", "Run a job now": "Ejecute un trabajo ahora", "Run apt-get install -f to complete any pending package configurations": "Ejecutar apt-get install -f para completar las configuraciones de paquetes pendientes", + "Run as root on the Proxmox node; the registry contains private data": "Ejecutar como raíz en el nodo Proxmox; el registro contiene datos privados", "Run as server or client? [s/c]:": "¿Ejecutar como servidor o cliente? [Carolina del Sur]:", "Run checklist again to verify upgrade:": "Ejecute la lista de verificación nuevamente para verificar la actualización:", "Run from console, or SSH inside tmux/screen": "Ejecutar desde la consola o SSH dentro de tmux/screen", @@ -3739,6 +4883,7 @@ "Running dkms autoinstall for kernel": "Ejecutando la instalación automática de dkms para el kernel", "Running kernel:": "Kernel en ejecución:", "Running pre-upgrade simulation to verify 'proxmox-ve' will remain installed...": "Ejecutando una simulación previa a la actualización para verificar que 'proxmox-ve' permanecerá instalado...", + "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration.": "RustDesk es una alternativa de control remoto de código abierto con una configuración mínima.", "SATA (standard - high compatibility)": "SATA (estándar - alta compatibilidad)", "SCSI (recommended for Linux and Windows)": "SCSI (recomendado para Linux y Windows)", "SCSI (recommended for Linux)": "SCSI (recomendado para Linux)", @@ -3755,6 +4900,7 @@ "SMB ports:": "Puertos PYME:", "SR-IOV Configuration Detected": "Configuración SR-IOV detectada", "SSD Emulation": "Emulación de SSD", + "SSH access": "Acceso SSH", "SSH access (host + root)": "Acceso SSH (host + raíz)", "SSH auth logger service created and started": "Servicio de registro de autenticación SSH creado e iniciado", "SSH hardening: MaxAuthTries set to 3 (Lynis recommendation)": "Endurecimiento SSH: MaxAuthTries establecido en 3 (recomendación de Lynis)", @@ -3769,6 +4915,8 @@ "STEP 9: Cleanup (LVM only)": "PASO 9: Limpieza (solo LVM)", "STORAGE TYPE IDENTIFICATION:": "IDENTIFICACIÓN DEL TIPO DE ALMACENAMIENTO:", "SUGGESTION FOR": "SUGERENCIA PARA", + "SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.": "SWAG sirve HTTPS en el puerto 443. Plain HTTP en el puerto 80 está deshabilitado en /config/nginx/site-confs/default.conf.", + "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction.": "Sabnzbd hace Usenet tan simple y simplificado como sea posible automatizando todo lo que podamos. Todo lo que tienes que hacer es añadir un .nzb. SABnzbd se apodera de allí, donde se descargará automáticamente, verificará, reparará, extraerá y archivará con cero interacción humana.", "Safe design: no automatic ACL/ownership mutation on host or CT.": "Diseño seguro: sin mutación automática de ACL/propiedad en el host o CT.", "Safe to apply now": "Es seguro aplicar ahora", "Safety Backup": "Respaldo de seguridad", @@ -3822,8 +4970,13 @@ "Same major series:": "Misma serie principal:", "Same major.minor:": "Mismo mayor.menor:", "Sanitizing NVIDIA host services for VFIO mode...": "Desinfectando los servicios de host de NVIDIA para el modo VFIO...", + "Save and classify articles. Read them later. Freely.": "Guardar y clasificar artículos. Léelos más tarde. Libre.", "Save the passphrase somewhere safe NOW, before continuing.": "guarde la frase de contraseña en un lugar seguro AHORA, antes de continuar.", "Save this Borg target so you don't need to enter the details again?": "¿Guardar este objetivo Borg para no tener que volver a introducir los detalles?", + "Saved record removed": "Se elimina el registro guardado", + "Saving the new configuration": "Salvando la nueva configuración", + "Saving the new configuration...": "Salvando la nueva configuración...", + "Saving the stack records...": "Salvando los registros de la pila...", "Scan storage for new content": "Escanear el almacenamiento en busca de contenido nuevo", "Scanning available physical disks...": "Escaneando discos físicos disponibles...", "Scanning network for NFS servers...": "Escaneando la red en busca de servidores NFS...", @@ -3835,11 +4988,19 @@ "Scheduled backups and retention policies": "Tareas de copia de seguridad programadas y políticas de retención", "Scheduled tasks (cron)": "Tareas programadas (cron)", "Scheduler script not found:": "Script del programador no encontrado:", + "ScreenScraper": "ScreenScraper", + "ScreenScraper password": "Contraseña de ScreenScraper", + "ScreenScraper username": "Nombre de usuario de ScreenScraper", "Script Information": "Información del guión", "Script not found:": "Guión no encontrado:", "Scripts in": "Guiones en", + "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator.": "ScummVM es un programa que permite ejecutar ciertos juegos clásicos de aventura gráfica y juego de roles, siempre y cuando ya tenga sus archivos de datos. La parte inteligente sobre esto: ScummVM simplemente reemplaza a los ejecutables enviados por los juegos, lo que le permite jugar en sistemas para los cuales nunca fueron diseñados! ScummVM es una reescritura completa de estos juegos' ejecutables y no es un emulador.", + "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions—such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server.": "Sealskin es una plataforma cliente-servidor auto hospedado que permite a los usuarios ejecutar aplicaciones de escritorio potentes y containerizzatos transmitidos directamente a un navegador web. Utiliza una extensión del navegador para interceptar acciones de usuario, como hacer clic en un enlace o descargar un archivo y redirigirlos a un entorno de aplicación seguro y aislado que se ejecuta en un servidor remoto.", "Search Results for:": "Resultados de búsqueda para:", + "Search applications": "Buscar aplicaciones", + "Search results for:": "Resultados de la búsqueda para:", "Search/Filter Scripts": "Scripts de búsqueda/filtro", + "Searchable document archive with OCR": "Archivo de documentos de búsqueda con OCR", "Secure Disk Formatter": "Formateador de disco seguro", "Secure Gateway (Tailscale VPN)": "Secure Gateway (VPN Tailscale)", "Secure Gateway deployed successfully!": "¡Secure Gateway se implementó con éxito!", @@ -3847,8 +5008,12 @@ "Security": "Seguridad", "Security Updates": "Actualizaciones de seguridad", "Security Warning — read before applying": "Advertencia de seguridad: lea antes de aplicar", + "Security directive outside the dynamic profile": "Directiva de seguridad fuera del perfil dinámico", + "Security relaxation declined": "Relajación de seguridad rechazada", "See": "Ver", "See /tmp/proxmenux-mount.log for details.": "consulte /tmp/proxmenux-mount.log para obtener más detalles.", + "Seerr WebUI": "Seerr WebUI", + "Seerr/Bazarr connections, the SABnzbd client and the Lidarr profiles, root folder and client are configured manually in this version.": "Las conexiones Seerr/Bazarr, el cliente SABnzbd y los perfiles Lidarr, la carpeta raíz y el cliente se configuran manualmente en esta versión.", "Select": "Seleccionar", "Select Borg target": "Seleccionar objetivo Borg", "Select CPU model": "Seleccione el modelo de CPU", @@ -3888,6 +5053,7 @@ "Select a Custom Logo": "Seleccione un logotipo personalizado", "Select a VirtIO ISO to use:": "Seleccione una ISO de VirtIO para usar:", "Select a category of useful commands:": "Seleccione una categoría de comandos útiles:", + "Select a category or search for applications:": "Seleccione una categoría o busque aplicaciones:", "Select a category or search for scripts:": "Seleccione una categoría o busque scripts:", "Select a custom ISO to use:": "Seleccione una ISO personalizada para usar:", "Select a job:": "Seleccione un trabajo:", @@ -3897,6 +5063,7 @@ "Select a pre-configured Linux VM script to execute:": "Seleccione un script de VM Linux preconfigurado para ejecutar:", "Select a script or action:": "Seleccione un script o acción:", "Select a share to delete:": "Seleccione un recurso compartido para eliminar:", + "Select a specific Coral or USB node, not the whole /dev": "Seleccione un Coral específico o nodo USB, no todo /dev", "Select access mode": "Seleccionar modo de acceso", "Select an existing group": "Seleccione un grupo existente", "Select an existing group:": "Seleccione un grupo existente:", @@ -3907,6 +5074,7 @@ "Select archive": "Seleccionar archivo", "Select archive to restore": "Seleccione el archivo para restaurar", "Select at least one path to continue.": "seleccione al menos una ruta para continuar.", + "Select at least one suite application": "Seleccione al menos una aplicación de suite", "Select authentication mode:": "Seleccione el modo de autenticación:", "Select authentication type:": "Seleccione el tipo de autenticación:", "Select available Controllers/NVMe to add:": "Seleccione Controladores/NVMe disponibles para agregar:", @@ -4011,6 +5179,19 @@ "Selected optimizations have been uninstalled.": "Se han desinstalado las optimizaciones seleccionadas.", "Selected paths produced no entries to apply.": "Las rutas seleccionadas no generaron entradas para aplicar.", "Selected utilities installation completed": "Instalación de utilidades seleccionadas completada", + "Selection": "Selección", + "Self-custodial Bitcoin Lightning wallet with integrated node and app connections.": "Cartera de iluminación Bitcoin auto-custodial con conexiones integradas de nodo y aplicaciones.", + "Self-hosted ZeroTier network controller with web UI for centralized management.": "Controlador de red ZeroTier con interfaz de usuario web para la gestión centralizada.", + "Self-hosted cloud data migration & sync manager": "Gestor de sincronización de datos en la nube", + "Self-hosted collaborative bookmark manager to collect, read, annotate, and fully preserve what matters, all in one place.": "Gestor de marcadores colaborativos auto hospedados para recoger, leer, anotar y preservar plenamente lo que importa, todo en un solo lugar.", + "Self-hosted file sharing with a modern web interface": "Compartir archivos con una interfaz web moderna", + "Self-hosted file toolkit for images, video, audio, PDFs, and files": "Herramienta de archivo auto-hosted para imágenes, vídeo, audio, PDF y archivos", + "Self-hosted internet archiving solution": "Solución de archivo de Internet auto-hosted", + "Self-hosted recipe manager and meal planner": "Administrador de recetas y planificador de comidas", + "Self-hosted software development service": "Servicio de desarrollo de software autoapropiado", + "Self-signed TLS certificate created:": "Certificado TLS auto-firmado creado:", + "Selfhosted PDF manager, viewer and editor": "Administrador de PDF, visor y editor", + "Selkies desktop and streaming acceleration": "Selkies escritorio y aceleración de streaming", "Sending backup to Borg repository...": "Enviando copia de seguridad al repositorio Borg...", "Sending backup to PBS...": "Enviando copia de seguridad a PBS...", "Server": "Servidor", @@ -4025,14 +5206,19 @@ "Server will listen on TCP port 5201.": "El servidor escuchará en el puerto TCP 5201.", "Server:": "Servidor:", "Servers": "Servidores", + "Service": "Servicio", "Service Status": "Estado del servicio", "Service is active and running": "El servicio está activo y funcionando.", "Service is inactive": "El servicio está inactivo.", + "Service ready:": "Servicio listo:", + "Service responding:": "Servicio que responde:", "Service restarted.": "Servicio reiniciado.", "Service restarts:": "El servicio se reinicia:", "Service stopped.": "El servicio se detuvo.", + "Service:": "Servicio:", "Services failed": "Los servicios fallaron", "Services restarted": "Servicios reiniciados", + "Services that depend on the main service are not yet supported": "Los servicios que dependen del servicio principal aún no se admiten", "Services:": "Servicios:", "Set Display > Graphic card (VGA, SPICE or VirtIO) to match the guest": "Configure Pantalla > Tarjeta gráfica (VGA, SPICE o VirtIO) para que coincida con el invitado", "Set Hostname": "Establecer nombre de host", @@ -4077,13 +5263,26 @@ "Share:": "Compartir:", "Shared Directory Ready:": "Directorio compartido listo:", "Shared Group": "Grupo compartido", + "Shared directory created:": "Directorio compartido creado:", + "Shared directory for consume and export": "Directorio compartido para consumo y exportación", + "Shared directory for copy/sync operations": "Directorio compartido para operaciones de copia/sincronización", "Shared group: CONFIGURED": "Grupo compartido: CONFIGURADO", "Shared group: sharedfiles (GID:": "Grupo compartido: archivos compartidos (GID:", + "Shared host content (not included in LXC backups):": "Contenido de host compartido (no incluido en backups de LXC):", + "Shared host data is not reverted by the backup. Continue?": "Los datos de host compartidos no son revertidos por el backup. ¿Continúa?", + "Shared host data is not reverted by the backups. Continue?": "Los datos de host compartidos no son revertidos por los backups. ¿Continúa?", + "Shared host directories (not included in Proxmox backups)": "Directorios de host compartidos (no incluidos en backups de Proxmox)", + "Shared host directory": "Directorio compartido del host", + "Shared host directory (not included in Proxmox backups)": "Directorio de host compartido (no incluido en backups de Proxmox)", + "Shared host files are kept as they are; the backup does not restore their content.": "Los archivos de host compartidos se guardan como están; el backup no restaura su contenido.", + "Shared host media directory": "Directorio multimedia compartido del host", + "Shared memory size for the GPU workload in MB": "Tamaño de memoria compartido para el volumen de trabajo de GPU en MB", "Sharedfiles group already exists (GID: 101000)": "El grupo Sharedfiles ya existe (GID: 101000)", "Shares found:": "Acciones encontradas:", "Shell user ulimit set": "Conjunto de ulimit de usuario de Shell", "Short self-test started on": "Autotest breve iniciado el", "Short test — ~2 minutes, basic surface check": "Prueba corta: ~2 minutos, verificación básica de la superficie", + "Shotcut is a free, open source, cross-platform video editor.": "Shotcut es un editor de vídeo de código abierto y gratuito.", "Should show 'unprivileged: 0' or no unprivileged line": "Debería mostrar 'sin privilegios: 0' o ninguna línea sin privilegios", "Should show 'unprivileged: 1'": "Debería mostrar 'sin privilegios: 1'", "Should show 'unprivileged: 1' if it's unprivileged": "Debería mostrar 'sin privilegios: 1' si no tiene privilegios", @@ -4125,14 +5324,23 @@ "Show size of a directory": "Mostrar tamaño de un directorio", "Show standard exclude patterns": "Mostrar patrones de exclusión estándar", "Show status of all storage pools": "Mostrar el estado de todos los grupos de almacenamiento", + "Show the QR code of a peer again with: pct exec -- /app/show-peer 1": "Mostrar el código QR de un par de nuevo con: pct exec -- /app/show-peer 1", "Show traffic statistics per interface": "Mostrar estadísticas de tráfico por interfaz", "Show vzdump backup configuration": "Mostrar configuración de copia de seguridad de vzdump", "Shows status and type (nfs/cifs/dir/iscsi...).": "Muestra el estado y el tipo (nfs/cifs/dir/iscsi...).", "Shutdown timeout": "Tiempo de espera de apagado", + "SiYuan access code": "Código de acceso de SiYuan", + "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more..": "SickGear proporciona la gestión de programas de televisión y/o Anime, detecta nuevos episodios, enlaces aplicaciones de descargador, y más..", + "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private.": "Signal es una aplicación de mensajería con privacidad en su núcleo. Es libre y fácil de usar, con una fuerte encriptación de extremo a extremo que mantiene su comunicación completamente privada.", "Signatures removed. Partition table preserved.": "Firmas eliminadas. Se conserva la tabla de particiones.", + "Simple and easy to use DDNS": "DDNS simple y fácil de usar", "Single GPU Warning": "Advertencia de GPU única", "Single target found — selected automatically:": "Objetivo único encontrado: seleccionado automáticamente:", "Size": "Tamaño", + "Size in GB of": "Tamaño en GB de", + "Size of each consume/export volume in GB": "Tamaño de cada volumen de consumo/exportación en GB", + "Size of the /dev/shm shared memory in MB": "Tamaño de la memoria compartida /dev/shm en MB", + "Size of the Frigate temporary cache in MB": "Tamaño de la caché temporal Frigate en MB", "Size:": "Tamaño:", "Skip downloading additional languages": "Omitir la descarga de idiomas adicionales", "Skip this device": "Saltar este dispositivo", @@ -4142,6 +5350,7 @@ "Skip — leave as-is": "Saltar: dejar como está", "Skipped (no disks of the pool are present on this host):": "omitido (no hay discos del grupo presentes en este host):", "Skipped (some disks missing):": "omitido (faltan algunos discos):", + "Skipped because Jellyfin did not create encoding.xml:": "Saltar porque Jellyfin no creó encoding.xml:", "Skipped device": "Dispositivo omitido", "Skipped to protect target system (would cascade-remove packages)": "omitido para proteger el sistema de destino (eliminaría paquetes en cascada)", "Skipped, not in apt cache:": "omitido, no en caché apto:", @@ -4149,7 +5358,10 @@ "Skipping SR-IOV device": "Saltar el dispositivo SR-IOV", "Skipping installation.": "Saltarse la instalación.", "Skipping manual patches — feranick fork already supports this kernel.": "Saltarse parches manuales: feranick fork ya es compatible con este kernel.", + "Sleek podcast downloader with GPodder sync": "descargador de podcast Sleek con sincronización GPodder", "Smart restore plan — hardware compatibility check": "Plan de restauración inteligente: verificación de compatibilidad de hardware", + "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis.": "Smokeping mantiene un seguimiento de la latencia de su red. Para un ejemplo completo de lo que esta aplicación es capaz de visitar UCDavis.", + "SnapOtter": "SnapOtter", "Snippets — hook scripts / config": "Fragmentos: scripts de enlace/configuración", "SoC-integrated GPU: tight coupling with other SoC components": "GPU integrada en SoC: estrecho acoplamiento con otros componentes de SoC", "Some DKMS removals reported errors; final verification will determine the result.": "Algunas eliminaciones de DKMS han devuelto errores; la verificación final determinará el resultado.", @@ -4159,6 +5371,7 @@ "Some old time services could not be removed (not installed)": "Algunos servicios antiguos no se pudieron eliminar (no instalar)", "Some operations failed — review messages above. Press Enter to continue...": "Algunas operaciones fallaron: revise los mensajes anteriores. Presione Entrar para continuar...", "Some packages still need attention; review": "Algunos paquetes aún requieren atención; revise", + "Some projects publish a Dockerfile and not an image: it has to be built and published to a registry before it can be installed this way. An image of a private registry needs credentials, which are not supported yet.": "Algunos proyectos publican un Dockerfile y no una imagen: tiene que ser construido y publicado a un registro antes de que pueda instalarse de esta manera. Una imagen de un registro privado necesita credentials, que aún no son compatibles.", "Some repairs failed. Please fix manually and re-run the script.": "Algunas reparaciones fallaron. Corrija manualmente y vuelva a ejecutar el script.", "Some repositories are not available, continuing with available ones...": "Algunos repositorios no están disponibles, continuando con los disponibles...", "Some selected GPUs are already configured in this container.": "Algunas GPU seleccionadas ya están configuradas en este contenedor.", @@ -4166,6 +5379,10 @@ "Some utility packages could not be removed; the remaining list has been preserved": "algunos paquetes de utilidades no se pudieron eliminar;la lista restante se ha conservado", "Something is already mounted at": "Ya hay algo montado en", "Something is already mounted at:": "Ya hay algo montado en:", + "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Sonarr (antes NZBdrone) es un PVR para usuarios de utilidad y bittorrent. Puede monitorear múltiples feeds RSS para nuevos episodios de sus programas favoritos y los agarrará, ordenará y renombrará. También se puede configurar para actualizar automáticamente la calidad de los archivos ya descargados cuando se dispone de un formato de mejor calidad.", + "Sonarr added to Prowlarr": "Sonarr añadido a Prowlarr", + "Sonarr connected to qBittorrent": "Sonarr conectado a qBittorrent", + "Sonarr root folder configured": "Carpeta raíz Sonarr configurada", "Source": "Fuente", "Source VM": "Máquina virtual de origen", "Source patched successfully.": "Fuente parcheada exitosamente.", @@ -4174,8 +5391,26 @@ "Spanish": "Español", "Specific host (enter IP)": "Host específico (ingrese IP)", "Specific subnet (enter manually)": "Subred específica (ingresar manualmente)", + "Speedtest Tracker web interface": "Interfaz web Speedtest Tracker", + "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service.": "Speedtest-tracker es una aplicación de seguimiento de rendimiento de internet autoauspiciada que ejecuta cheques de velocidad contra el servicio Speedtest de Ookla.", + "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium": "Spotube es un cliente de código abierto, multiplataforma de Spotify compatible con múltiples plataformas utilizando API de datos de Spotify y YouTube, Piped. video o JioSaavn como fuente de audio, eliminando la necesidad de Spotify Premium", "Stable (main branch)": "Estable (rama principal)", "Stable monitor service normalized.": "Servicio de monitor estable normalizado.", + "Stack": "Pila", + "Stack adapter not recognized by the translator": "Adaptador Stack no reconocido por el traductor", + "Stack backups are missing; a partial restore is not allowed": "Faltan backups; no se permite una restauración parcial", + "Stack checked:": "Se ha comprobado:", + "Stack members are missing; recreate them after verifying their volumes": "Los miembros de Stack están desaparecidos; recrearlos después de verificar sus volúmenes", + "Stack members are updated together with their stack": "Los miembros de Stack se actualizan junto con su pila", + "Stack name": "Nombre de la pila", + "Stack records restored": "Registros recuperados", + "Stack records saved": "Registros guardados", + "Stack records saved; no container was reinstalled.": "Registros guardados; no se reinstaló ningún contenedor.", + "Stack recovery completed; every member is back to its previous installation.": "Recuperación de etapas completada; cada miembro está de vuelta a su instalación anterior.", + "Stack startup hook installed": "Gancho de arranque de Stack instalado", + "Stack stopped": "Stack paró", + "Stack update completed. Data kept.": "Actualización finalizada. Datos guardados.", + "Stack:": "Stack:", "Staging directory:": "Directorio temporal:", "Staging ready.": "Preparación completada.", "Staging source:": "Origen de la preparación:", @@ -4183,11 +5418,13 @@ "Stale VFIO Config Detected": "Se detectó configuración VFIO obsoleta", "Stale VFIO entries removed and initramfs rebuilt.": "Se eliminaron las entradas VFIO obsoletas y se reconstruyó initramfs.", "Standard NAS (backup, iso, vztmpl)": "NAS estándar (copia de seguridad, iso, vztmpl)", + "Start": "Inicio", "Start VM": "Iniciar máquina virtual", "Start VM after creation": "Iniciar VM después de la creación", "Start VM after creation?": "¿Iniciar VM después de la creación?", "Start a container. Use the correct ": "Inicie un contenedor. Utilice el correcto", "Start a virtual machine. Use the correct ": "Inicie una máquina virtual. Utilice el correcto", + "Start each LXC with Proxmox (no coordinated startup)": "Iniciar cada LXC con Proxmox (sin arranque coordinado)", "Start long self-test (hours)": "Iniciar autotest largo (horas)", "Start long test now?": "¿Iniciar una prueba larga ahora?", "Start on boot already disabled for VM": "Iniciar al arrancar ya está deshabilitado para VM", @@ -4199,11 +5436,16 @@ "Start scrub for a ZFS pool": "Iniciar limpieza para un grupo ZFS", "Start short self-test (~2 min)": "Iniciar una autoprueba breve (~2 min)", "Start terminal multiplexer (recommended):": "Iniciar multiplexor de terminal (recomendado):", + "Start the LXC when finished to apply the selected configuration?": "¿Iniciar el LXC al terminar para aplicar la configuración seleccionada?", "Start the VM": "Inicie la máquina virtual", "Start the VM to begin Windows installation from the mounted ISO.": "Inicie la VM para comenzar la instalación de Windows desde la ISO montada.", "Start the converted container:": "Inicie el contenedor convertido:", "Start the main system upgrade:": "Inicie la actualización principal del sistema:", + "Start the stack with Proxmox": "Iniciar la pila con Proxmox", "Start uploading to PBS — sets a recovery passphrase": "comience a cargar en PBS: establece una frase de contraseña de recuperación", + "Start when finished": "Iniciar al terminar", + "Start with Proxmox": "Iniciar con Proxmox", + "Starting": "Empezando", "Starting Borg backup...": "Iniciando copia de seguridad de Borg...", "Starting CT": "TC inicial", "Starting LXC Privileged to Unprivileged conversion process...": "Iniciando el proceso de conversión de LXC privilegiado a no privilegiado...", @@ -4214,6 +5456,7 @@ "Starting ProxMenux update...": "Iniciando actualización de ProxMenux...", "Starting Proxmox storage integration...": "Iniciando la integración del almacenamiento de Proxmox...", "Starting Proxmox system repair...": "Iniciando la reparación del sistema Proxmox...", + "Starting Rclone and waiting for the FUSE mount...": "Empezando Rclone y esperando el montaje FUSE...", "Starting SMART long self-test...": "Iniciando la autoprueba larga SMART...", "Starting SMART short self-test...": "Iniciando la autoprueba corta SMART...", "Starting container": "Contenedor inicial", @@ -4224,9 +5467,18 @@ "Starting installer...": "Iniciando el instalador...", "Starting privileged container...": "Iniciando contenedor privilegiado...", "Starting rpcbind service...": "Iniciando el servicio rpcbind...", + "Starting the container...": "Comenzando el contenedor...", + "Starting the main container and its dependencies...": "Comenzando el contenedor principal y sus dependencias...", + "Starting the service:": "Inicio del servicio:", "Starting unprivileged container...": "Iniciando contenedor sin privilegios...", + "Startup: coordinated by the stack startup hook": "Inicio: coordinado por el gancho de arranque de pila", + "Static IP": "IP estática", + "Static IPv4 address": "Dirección IPv4 estática", + "Static IPv4 address for": "Dirección IPv4 estática para", "Status": "Estado", "Status:": "Estado:", + "Steam is the ultimate destination for playing, discussing, and creating games.": "Steam es el destino final para jugar, discutir y crear juegos.", + "SteamGridDB": "SteamGridDB", "Step": "Paso", "Step 2: Testing actual share access with guest...": "Paso 2: Probar el acceso compartido real con los invitados...", "Steps that will run:": "Pasos que se ejecutarán:", @@ -4234,12 +5486,14 @@ "Stop it first and run this option again.": "Deténgalo primero y ejecute esta opción nuevamente.", "Stop the CT, unmount the disk on the HOST, and remount with:": "Detenga el CT, desmonte el disco en el HOST y vuelva a montarlo con:", "Stop the VM/CT before formatting this disk.": "Detenga el VM/CT antes de formatear este disco.", + "Stop the container before the NVIDIA refresh": "Detén el contenedor antes de la actualización de NVIDIA", "Stop the container if it's running:": "Detenga el contenedor si se está ejecutando:", "Stop them first and run this script again.": "Deténgalos primero y ejecute este script nuevamente.", "Stop uploading to PBS": "dejar de subir a PBS", "Stop uploading?": "¿Dejar de subir?", "Stopped": "Interrumpido", "Stopped and disabled": "Detenido y deshabilitado", + "Stopped at:": "Detuvo:", "Stopping Coral kernel modules...": "Deteniendo los módulos del kernel de Coral...", "Stopping LXC": "Detener LXC", "Stopping NFS services...": "Deteniendo los servicios NFS...", @@ -4251,6 +5505,8 @@ "Stopping gateway...": "Deteniendo la puerta de enlace...", "Stopping the container before applying configuration...": "Deteniendo el contenedor antes de aplicar la configuración...", "Stopping the container before conversion...": "Deteniendo el contenedor antes de la conversión...", + "Stopping the container...": "Deteniendo el contenedor...", + "Stopping the stack...": "Detener la pila...", "Storage": "Almacenamiento", "Storage & Share Manager": "Administrador de almacenamiento y recursos compartidos", "Storage Added:": "Almacenamiento agregado:", @@ -4263,21 +5519,41 @@ "Storage and Disks Commands": "Comandos de almacenamiento y discos", "Storage controller: VirtIO SCSI": "Controlador de almacenamiento: VirtIO SCSI", "Storage disk identifier:": "Identificador del disco de almacenamiento:", + "Storage for Nextcloud files, configuration and data": "Almacenamiento para archivos Nextcloud, configuración y datos", + "Storage for Paperless data and documents": "Almacenamiento para los datos y documentos de Paperless", + "Storage for Tandoor files": "Almacenamiento para archivos Tandoor", + "Storage for persistent data": "Almacenamiento para datos persistentes", + "Storage for recipe images and files": "Almacenamiento para imágenes y archivos de receta", + "Storage for rootfs": "Almacenamiento para rootfs", + "Storage for rootfs and private configuration": "Almacenamiento para rootfs y configuración privada", + "Storage for the Immich library": "Almacenamiento para la biblioteca Immich", + "Storage for the Nextcloud data": "Almacenamiento para los datos Nextcloud", + "Storage for the OCI image cache": "Almacenamiento para la caché de imágenes OCI", + "Storage for the consume and export folders": "Almacenamiento para las carpetas de consumo y exportación", + "Storage for the persistent configuration": "Almacenamiento para la configuración persistente", "Storage is now available in Proxmox web interface under Datacenter > Storage": "El almacenamiento ahora está disponible en la interfaz web de Proxmox en Centro de datos > Almacenamiento", "Storage plan selection cancelled.": "Se canceló la selección del plan de almacenamiento.", "Storage plan selection failed or cancelled": "La selección del plan de almacenamiento falló o se canceló", + "Storage selection cancelled": "Selección de almacenamiento cancelada", "Storage:": "Almacenamiento:", "Stored Credentials:": "Credenciales almacenadas:", "Stored credentials:": "Credenciales almacenadas:", + "Stremio is a modern media center that gives you the freedom to watch everything you want.": "Stremio es un moderno centro de medios que te da la libertad de ver todo lo que quieras.", + "Subdomains for the certificate, comma separated (wildcard for *.domain)": "Subdominios para el certificado, coma separado (wildcard para *.domain)", "Subnet": "Subred", "Subscription banner removal failed": "Error al eliminar el banner de suscripción", "Subscription banner removed successfully": "El banner de suscripción se eliminó correctamente", "Subscription banner restored successfully (desktop and mobile)": "El banner de suscripción se restauró correctamente (escritorio y móvil)", "Success": "Éxito", "Successful": "Exitoso", + "Supervisor does not confirm healthy and supported yet": "Supervisor no confirma sano y apoyado aún", + "Supervisor reports no connectivity; retrying to get versions and install components": "Supervisor no informa de conectividad; reintentar para obtener versiones e instalar componentes", "Supported formats: .img, .qcow2, .vmdk, .raw": "Formatos admitidos: .img, .qcow2, .vmdk, .raw", + "Swap": "Swap", + "Swap in MB": "Swap en MB", "Swap partition detected": "Partición swap detectada", "Swappiness configuration created successfully": "Configuración de swappiness creada correctamente", + "Swing Music is a beautifully designed, self-hosted music streaming server. Like a cooler Spotify ... but bring your own music.": "Swing Music es un servidor de streaming de música de diseño propio. Como un Spotify más fresco... pero trae tu propia música.", "Switch GPU Mode (VM <-> LXC)": "Cambiar el modo GPU (VM <-> LXC)", "Switch Mode": "Switch Mode", "Switch Script Not Found": "Script de cambio no encontrado", @@ -4287,13 +5563,21 @@ "Switching to": "Cambiando a", "Switching to GPU -> LXC mode removes VFIO exclusivity.": "Cambiar a GPU -> modo LXC elimina la exclusividad de VFIO.", "Switching to GPU -> VM mode requires exclusive VFIO binding.": "Cambiar a GPU -> modo VM requiere un enlace VFIO exclusivo.", + "Symbolic link in a restored volume path": "Enlace simbólico en una ruta de volumen restaurada", + "Symbolic link in the path of an adaptation": "Enlace simbólico en el camino de una adaptación", + "Symbolic link loop in the new image": "El bucle de enlace simbólico en la nueva imagen", + "Symbolic link outside the rootfs of the new image": "Enlace simbólico fuera de los rootfs de la nueva imagen", "Synchronize time automatically": "Sincronizar la hora automáticamente", + "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are.": "Synclounge es una herramienta de terceros que te permite ver Plex en sincronía con tus amigos/familia, donde estés.", + "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet.": "Syncthing reemplaza los servicios patentados de sincronización y nube con algo abierto, confiable y descentralizado. Sus datos son sólo sus datos y merece elegir dónde se almacena, si se comparte con algún tercero y cómo se transmite a través de Internet.", + "Sysctl not namespaced or not valid:": "Sysctl no namespaced or not valid:", "System": "Sistema", "System CLI Tools": "Herramientas CLI del sistema", "System Disk Size (GB)": "Tamaño del disco del sistema (GB)", "System Update Information": "Información de actualización del sistema", "System Utilities Installer": "Instalador de utilidades del sistema", "System disk is SSD or M.2. Proceeding with Log2RAM setup.": "El disco del sistema es SSD o M.2. Continuando con la configuración de Log2RAM.", + "System error:": "Error del sistema:", "System errors and logs": "Errores y registros del sistema", "System group apex already exists.": "El vértice del grupo del sistema ya existe.", "System group apex created.": "Vértice del grupo de sistemas creado.", @@ -4304,6 +5588,7 @@ "System limits increase completed.": "Aumento de los límites del sistema completado.", "System limits optimizations removed": "Se eliminaron las optimizaciones de los límites del sistema", "System must be updated to latest PVE 8.4+ before starting": "El sistema debe actualizarse a la última versión de PVE 8.4+ antes de comenzar.", + "System path mounts are not yet supported": "Los montajes de la ruta del sistema aún no están soportados", "System reboot required": "Es necesario reiniciar el sistema", "System upgrade completed": "Actualización del sistema completada", "System uptime": "Tiempo de actividad del sistema", @@ -4318,6 +5603,11 @@ "TROUBLESHOOTING:": "SOLUCIÓN DE PROBLEMAS:", "TUI mode": "modo TUI", "TUI mode (requires root)": "Modo TUI (requiere root)", + "Take control of your Minecraft servers.": "Tome el control de sus servidores Minecraft.", + "Tandoor WebUI": "Tandoor WebUI", + "Tandoor configuration cancelled": "Configuración de Tandoor cancelada", + "Tandoor needs at least 1 GB for staticfiles and 4 GB for PostgreSQL": "Tandoor necesita al menos 1 GB para ficheros estáticos y 4 GB para PostgreSQL", + "Tandoor needs to complete its first start to create the initial administrator": "Tandoor necesita completar su primer arranque para crear el administrador inicial", "Target IQN:": "IQN objetivo:", "Target VM": "Máquina virtual de destino", "Target VM validated": "VM de destino validada", @@ -4327,6 +5617,12 @@ "Target mode": "Modo objetivo", "Target server:": "Servidor de destino:", "Target:": "Objetivo:", + "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server.": "Tautulli es una aplicación web basada en python para monitoreo, análisis y notificaciones para Plex Media Server.", + "Teable adopts a concise spreadsheet interface, yet creates powerful database applications": "Teable adopta una interfaz de hoja de cálculo concisa, sin embargo crea potentes aplicaciones de bases de datos", + "Telegram is a cloud-based mobile and desktop messaging app.": "Telegram es una aplicación de mensajería móvil y de escritorio basada en la nube.", + "Temporary data container:": "contenedor de datos temporales:", + "Temporary login": "Acceso temporal", + "Temporary password retrieved": "Contraseña temporal recuperada", "Temporary working directory (if present):": "Directorio de trabajo temporal (si está presente):", "Terminal Multiplexers": "Multiplexores de terminales", "Terminal multiplexer (Ctrl+b then d to detach, or type exit)": "Multiplexor de terminal (Ctrl+b y luego d para desconectar, o escriba exit)", @@ -4343,40 +5639,197 @@ "Testing comprehensive guest access to server": "Probando el acceso integral de invitados al servidor", "Testing connectivity to portal...": "Probando la conectividad al portal...", "Testing network connectivity...": "Probando la conectividad de la red...", + "Text that new pads start with (empty = the text of the image)": "Texto que comienzan las nuevas almohadillas (vacío = texto de la imagen)", "Thank you for using ProxMenux. Goodbye!": "Gracias por utilizar ProxMenux. ¡Hasta pronto!", "That VM is currently stopped, so the GPU can be reassigned now.": "Esa VM está actualmente detenida, por lo que la GPU se puede reasignar ahora.", "That doesn't look like an SSH private key. Pick the private key file (no .pub extension, parseable by ssh-keygen).": "Eso no parece una clave privada SSH.Elige el archivo de clave privada (sin extensión .pub, analizable mediante ssh-keygen).", + "The .conf files under /config/fail2ban are rewritten on every start. Keep customizations in the matching .local file, for example jail.local for jail.conf.": "Los archivos .conf bajo /config/fail2ban son reescritos en cada inicio. Mantenga las personalizaciones en el archivo .local coincidente, por ejemplo la cárcel.local para jail.conf.", + "The AppArmor/seccomp relaxation does not include the required consent": "La relajación AppArmor/seccomp no incluye el consentimiento necesario", + "The Bookmark Everything App": "La aplicación Todo Marcador", + "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile.": "El navegador Brave es un navegador web rápido, privado y seguro para PC, Mac y móvil.", + "The CT already exists:": "El CT ya existe:", + "The Compose file declares no service": "El archivo Compose no declara servicio", + "The Compose file describes several images:": "El archivo Compose describe varias imágenes:", + "The Compose file does not contain a Compose document": "El archivo Compose no contiene un documento Compose", + "The Compose file is not valid YAML:": "El archivo Compose no es YAML válido:", + "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "El Compose ofrece una relajación opcional AppArmor o seccomp; se mantendrá deshabilitado a menos que el usuario lo seleccione. Continúe sólo si confía en la imagen y acepta este riesgo.", + "The Compose value must be text or a list:": "El valor Compose debe ser texto o lista:", + "The DRM node is not an Intel or AMD GPU; NVIDIA requires its library profile": "El nodo DRM no es una GPU Intel o AMD; NVIDIA requiere su perfil de biblioteca", + "The Entrypoint/Cmd combination is empty": "El punto de entrada/Cmd combination está vacío", + "The FUSE publication helper was not found": "El ayudante de publicación FUSE no fue encontrado", + "The GPU evidence does not match the verified devices": "La evidencia GPU no coincide con los dispositivos verificados", "The GPU has been moved out of VM": "La GPU se ha sacado de la VM", + "The GPU identity or permissions changed; the container is not modified": "La identidad o permisos de la GPU cambió; el contenedor no se modifica", "The GPU is being detached from VM": "La GPU se está desconectando de la VM", + "The GPU vendor differs from the requested profile": "El proveedor de GPU difiere del perfil solicitado", + "The GPU vendor does not match the selected GPU profile:": "El proveedor GPU no coincide con el perfil GPU seleccionado:", + "The Immich CPU quota cannot be reproduced": "La cuota de CPU Immich no se puede reproducir", + "The Immich library needs at least 8 GB": "La biblioteca Immich necesita al menos 8 GB", + "The Immich startup was modified or cannot be reproduced": "La startup Immich fue modificada o no se puede reproducir", + "The LXC has stopped": "El LXC ha parado", + "The Lounge starts in public mode: anyone who reaches the address opens the client without logging in, and the IRC networks added are lost when the session ends.": "El Salón comienza en modo público: cualquier persona que alcance la dirección abre al cliente sin iniciar sesión, y las redes IRC agregadas se pierden cuando termina la sesión.", + "The MAC address of the container cannot be kept": "La dirección MAC del contenedor no se puede mantener", "The NVIDIA Container Toolkit repository definition was empty.": "La definición del repositorio de NVIDIA Container Toolkit estaba vacía.", "The NVIDIA Container Toolkit signing key could not be read.": "No se pudo leer la clave de firma de NVIDIA Container Toolkit.", + "The NVIDIA Container Toolkit version cannot be identified": "No se puede identificar la versión de NVIDIA Container Toolkit", + "The NVIDIA destination cannot be replaced": "El destino NVIDIA no puede ser reemplazado", + "The NVIDIA destination escapes the rootfs": "El destino NVIDIA escapa a los rootfs", "The NVIDIA driver is installed, but the Container Toolkit phase did not complete. GPU support for OCI containers is unavailable until it does.": "El controlador NVIDIA está instalado, pero la fase del Container Toolkit no se completó. La compatibilidad con GPU para contenedores OCI no estará disponible hasta que lo haga.", + "The NVIDIA driver or inventory changed; the operation was stopped": "El controlador o inventario de NVIDIA cambió; la operación se detuvo", + "The NVIDIA hook or environment differs from the declared one": "El gancho o entorno NVIDIA difiere del declarado", + "The NVIDIA hook path does not belong to the installer": "La ruta de gancho NVIDIA no pertenece al instalador", "The NVIDIA installer needs at least": "El instalador de NVIDIA necesita al menos", + "The NVIDIA runtime is up to date; the container is not modified or started": "El tiempo de funcionamiento de NVIDIA está actualizado; el contenedor no se modifica o se inicia", + "The Nextcloud volume needs at least 8 GB": "El volumen de Nextcloud necesita al menos 8 GB", + "The OCI archive contains no SHA-256 blobs": "El archivo OCI no contiene bloques SHA-256", + "The OCI archive does not contain exactly one manifest": "El archivo OCI no contiene exactamente un manifiesto", + "The OCI archive does not exist or is empty:": "El archivo OCI no existe o está vacío:", + "The OCI archive verifier was not found": "El verificador de archivos OCI no fue encontrado", + "The OCI catalog is not installed. Update ProxMenux and try again.": "El catálogo OCI no está instalado. Actualice ProxMenux e inténtelo de nuevo.", + "The OCI engine is not installed. Update ProxMenux and try again.": "El motor OCI no está instalado. Actualice ProxMenux e inténtelo de nuevo.", + "The OCI image storage was not kept": "El almacenamiento de imágenes OCI no se mantuvo", + "The OCR language must use Tesseract codes, for example eng or eng+spa": "El lenguaje OCR debe utilizar códigos de Tesseract, por ejemplo eng o eng+spa", + "The PATH of the new image is outside the reproducible profile": "El PATH de la nueva imagen está fuera del perfil reproducible", + "The Paperless persistent volumes need at least 8 GB": "Los volúmenes persistentes de Paperless necesitan al menos 8 GB", + "The PostgreSQL volume needs at least 4 GB": "El volumen de PostgreSQL necesita al menos 4 GB", + "The PostgreSQL volume needs at least 8 GB": "El volumen de PostgreSQL necesita al menos 8 GB", "The Proxmox archive keyring is missing; Ceph installation cannot continue safely": "Falta el conjunto de claves de archivo Proxmox;La instalación de Ceph no puede continuar de forma segura", + "The Proxmox inventory and the local configurations differ": "El inventario de Proxmox y las configuraciones locales difieren", + "The Rclone configuration needs at least 1 GB": "La configuración Rclone necesita al menos 1 GB", + "The Rclone rootfs needs at least 2 GB": "El rootfs de Rclone necesita al menos 2 GB", + "The Selkies profile requires a verified LinuxServer image": "El perfil de Selkies requiere una imagen verificada LinuxServer", + "The Tandoor files volume needs at least 2 GB": "El volumen de archivos Tandoor necesita al menos 2 GB", "The URL does not contain the required parameters (id, pack, edition).": "La URL no contiene los parámetros requeridos (id, paquete, edición).", + "The USB number can change after reconnecting or rebooting. This profile does not remap it automatically or handle Coral USB re-enumeration. Do not share a dongle already used by another service.": "El número USB puede cambiar después de reconectarse o reiniciar. Este perfil no lo reasigna automáticamente ni gestiona Coral re-enumeración USB. No comparta un dongle ya utilizado por otro servicio.", + "The Unifi-controller software is a powerful, enterprise wireless software engine ideal for high-density client deployments requiring low latency and high uptime performance.": "El software Unifi-controller es un potente motor de software inalámbrico empresarial ideal para implementaciones cliente de alta densidad requiring de baja latencia y alto rendimiento de tiempo de funcionamiento.", + "The VA-API device does not exist:": "El dispositivo VA-API no existe:", "The VM also has these audio devices assigned via PCI passthrough — typically added together with the GPU. Remove them too?": "La VM también tiene estos dispositivos de audio asignados mediante transferencia PCI, que generalmente se agregan junto con la GPU. ¿Quitarlos también?", "The VM guest will have exclusive access to the GPU.": "El invitado de la VM tendrá acceso exclusivo a la GPU.", "The VM is powered on. Turn it off before adding disks.": "La máquina virtual está encendida. Apáguelo antes de agregar discos.", "The VM/LXC will lose access to this disk after formatting.": "El VM/LXC perderá el acceso a este disco después de formatear.", + "The VMID belongs to another container now and is not touched:": "El VMID pertenece a otro contenedor ahora y no se toca:", + "The VMID or its contract is already in use; it is not adopted": "El VMID o su contrato ya está en uso; no es adoptado", + "The VMID was reused or its identity is unknown; the operation is blocked": "El VMID fue reutilizado o su identidad es desconocida; la operación está bloqueada", + "The VMID was reused or the container is on another node; it is not overwritten": "El VMID fue reutilizado o el contenedor está en otro nodo; no está sobrescrito", + "The VMID was taken during the installation:": "El VMID fue tomado durante la instalación:", + "The Valkey volume needs at least 1 GB": "El volumen Valkey necesita al menos 1 GB", + "The acceleration evidence differs from the verified inventory": "Las pruebas de aceleración difieren del inventario verificado", + "The acceleration profile does not support this architecture:": "El perfil de aceleración no apoya esta arquitectura:", "The active kernel driver is not vfio-pci, but the entry in": "El controlador del kernel activo no es vfio-pci, sino la entrada en", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot, breaking the LXC passthrough about to be configured.": "El controlador del kernel activo no es vfio-pci, pero la entrada volverá a vincular la GPU a vfio-pci en el próximo reinicio, interrumpiendo el paso a través de LXC que está a punto de configurarse.", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot.": "el controlador del kernel activo no es vfio-pci, pero la entrada volverá a vincular la GPU a vfio-pci en el próximo reinicio.", + "The adaptation content was modified": "El contenido de adaptación fue modificado", + "The additional path hides a system directory": "El camino adicional esconde un directorio del sistema", + "The address is already assigned on this host or cluster:": "La dirección ya está asignada en este host o cluster:", + "The address must start with http:// or https://": "La dirección debe comenzar con http:// o https://", + "The administrator account, the public address and the UDP port are created on the first start, so the web interface opens directly on its login page.": "La cuenta de administrador, la dirección pública y el puerto UDP se crean en el primer comienzo, por lo que la interfaz web se abre directamente en su página de inicio de sesión.", + "The administrator email is not valid": "El correo electrónico del administrador no es válido", + "The administrator user contains characters that are not allowed": "El usuario administrador contiene caracteres que no se permiten", + "The all-in-one AI application.": "La aplicación de IA todo en uno.", + "The application configuration needs a first start to complete.": "La configuración de la aplicación necesita un primer arranque para completarse.", + "The application did not complete its initial setup:": "La aplicación no completó su configuración inicial:", + "The application did not get an address on the access network:": "La aplicación no obtuvo una dirección en la red de acceso:", + "The application did not pass its HTTP check:": "La aplicación no pasó su cheque HTTP:", + "The application did not respond in time:": "La aplicación no respondió a tiempo:", + "The application stopped during its first start:": "La aplicación se detuvo durante su primer comienzo:", + "The application was removed": "La solicitud fue eliminada", "The archive could not be extracted.": "No se pudo extraer el archivo.", "The archive destination directory is INSIDE one of the paths you are about to back up. Writing the archive there would copy the backup into itself — producing a corrupted archive, or growing without limit until the disk fills up.": "El directorio de destino del archivo está DENTRO de una de las rutas de las que está a punto de realizar una copia de seguridad. Escribir el archivo allí copiaría la copia de seguridad en sí mismo, lo que produciría un archivo corrupto o crecería sin límite hasta que el disco se llenara.", + "The backup could not be identified; the image is not replaced": "El backup no se pudo identificar; la imagen no es reemplazada", "The backup metadata was compared against this host. The following items will be SKIPPED to keep the boot safe:": "los metadatos de la copia de seguridad se compararon con este host. Se SALTARÁN los siguientes elementos para mantener el arranque seguro:", + "The backup of a member could not be identified": "No se pudo identificar el backup de un miembro", + "The backup was altered; recovery blocked": "El backup fue alterado; la recuperación bloqueada", "The backup was taken on a different PVE or kernel major.minor. These paths will be SKIPPED to keep the boot safe:": "La copia de seguridad se realizó en un PVE o kernel mayor.menor diferente. Estas rutas se SALTARÁN para mantener el arranque seguro:", + "The bind mount target escapes the rootfs:": "El objetivo de montaje enlazado escapa a los rootfs:", + "The block device does not exist:": "El dispositivo bloque no existe:", "The build could not be checked beforehand; continuing without that check.": "La compilación no se pudo verificar de antemano;continuar sin ese cheque.", + "The cached image does not match the current digest": "La imagen caché no coincide con el digesto actual", + "The cached image is damaged; it will be downloaded again.": "La imagen en caché está dañada; se descargará de nuevo.", + "The character device does not exist:": "El dispositivo de carácter no existe:", + "The command asks for a password that is not echoed. After creating the users, the web interface asks for a user name and a password.": "El comando pide una contraseña que no se hace eco. Después de crear los usuarios, la interfaz web pide un nombre de usuario y una contraseña.", + "The command does not name an image": "El comando no nombra ninguna imagen", + "The command reads its variables from a file; write them in the command or use a Compose file": "El comando lee sus variables de un archivo; escríbalas en el comando o utilice un archivo Compose", + "The command runs the container as the user of the host; the container uses the user of its image instead.": "El comando ejecuta el contenedor como el usuario del host; el contenedor utiliza el usuario de su imagen en su lugar.", + "The command uses options that cannot be translated:": "El comando utiliza opciones que no pueden traducirse:", + "The command works out a value by running another command:": "El comando obtiene un valor ejecutando otro comando:", "The compatibility check raised failures that may break the system after restore.": "La verificación de compatibilidad generó fallas que pueden dañar el sistema después de la restauración.", + "The configuration changed after the backup was restored; the recovery is not confirmed": "La configuración cambió después de la restauración del backup; la recuperación no se confirma", + "The configuration changed after the new container was validated": "La configuración cambió después de validar el nuevo contenedor", + "The configuration changed during the NVIDIA refresh": "La configuración cambió durante la actualización de NVIDIA", + "The configuration evidence does not match": "La evidencia de configuración no coincide", + "The configuration must run as root on Proxmox VE": "La configuración debe funcionar como root en Proxmox VE", + "The configuration of a new member changed after it was created": "La configuración de un nuevo miembro cambió después de su creación", + "The configuration stopped because of an unexpected error": "La configuración se detuvo debido a un error inesperado", + "The consume/export volumes need at least 1 GB": "Los volúmenes de consumo/exportación necesitan al menos 1 GB", + "The container could not be removed automatically:": "El contenedor no se puede retirar automáticamente:", + "The container could not be started:": "No se podía iniciar el contenedor:", + "The container creation does not match the prepared instance": "La creación de contenedores no coincide con la instancia preparada", + "The container devices do not match the saved record": "Los dispositivos de contenedores no coinciden con el registro guardado", + "The container did not stop to update its persistent configuration:": "El contenedor no se detuvo para actualizar su configuración persistente:", + "The container did not stop; its disks are not touched": "El contenedor no se detuvo; sus discos no se tocan", + "The container disks do not match the saved record": "Los discos de contenedores no coinciden con el disco guardado", + "The container does not exist:": "El contenedor no existe:", + "The container does not have the fuse=1 feature enabled": "El contenedor no tiene activada la función fuse=1", + "The container does not need it any more; an update downloads the new version when there is one.": "El contenedor ya no lo necesita; una actualización descarga la nueva versión cuando la hay.", + "The container gets its own address and its own volumes, so the networks and volumes declared in the file are not used.": "El contenedor obtiene su propia dirección y sus propios volúmenes, por lo que las redes y volúmenes declarados en el archivo no se utilizan.", + "The container has advanced Proxmox settings outside the supported profile": "El contenedor ha avanzado la configuración Proxmox fuera del perfil soportado", + "The container identity changed; the container is not replaced": "La identidad del contenedor cambió; el contenedor no es reemplazado", + "The container identity does not match": "La identidad del contenedor no coincide", + "The container identity or configuration changed": "La identidad o configuración del contenedor cambió", "The container is currently stopped. Do you want to start it now to install the package?": "El contenedor se encuentra actualmente detenido. ¿Quieres iniciarlo ahora para instalar el paquete?", + "The container is not modified because a host directory is not available:": "El contenedor no se modifica porque un directorio host no está disponible:", + "The container no longer exists:": "El contenedor ya no existe:", + "The container of a member was replaced; the assembly is not resumed": "El contenedor de un miembro fue reemplazado; la asamblea no se reanuda", "The container should now start as privileged": "El contenedor ahora debería comenzar como privilegiado.", "The container should now start as unprivileged": "El contenedor ahora debería comenzar sin privilegios.", + "The container stopped after starting:": "El contenedor se detuvo después de comenzar:", + "The container stopped before publishing the mount": "El contenedor se detuvo antes de publicar el montaje", + "The container stopped before the GPU permissions were verified:": "El contenedor se detuvo antes de que se verificaran los permisos de la GPU:", + "The container stopped before the application responded:": "El contenedor se detuvo antes de que la aplicación respondiera:", + "The container stopped:": "El contenedor se detuvo:", + "The container takes its time zone from Proxmox, so the time files of the host are not attached to it.": "El contenedor toma su zona horaria de Proxmox, por lo que los archivos de tiempo del host no se adjuntan a él.", + "The container was changed outside ProxMenux and an update would discard those changes:": "El contenedor fue cambiado fuera de ProxMenux y una actualización descartaría esos cambios:", + "The container was created from a downloaded OCI image": "El contenedor fue creado a partir de una imagen OCI descargada", + "The containers do not need them any more; an update downloads the new versions when there are any.": "Los contenedores ya no las necesitan; una actualización descarga las nuevas versiones cuando las hay.", + "The containers were created from downloaded OCI images": "Los contenedores fueron creados a partir de imágenes OCI descargadas", + "The coordinated backup was modified": "El backup coordinado fue modificada", "The current driver will be completely uninstalled before installing the new version. Continue?": "El controlador actual se desinstalará por completo antes de instalar la nueva versión. ¿Continuar?", + "The current image of the saved channel will be checked and downloaded. Resources, paths and GPU are kept. The CT is stopped during the replacement and a native backup is created first.": "La imagen actual del canal guardado será revisada y descargada. Se mantienen recursos, rutas y GPU. El CT se detiene durante el reemplazo y se crea primero un backup nativo.", + "The current record is missing for": "Falta el registro actual para", + "The current template changes the image or identity; an explicit migration is required": "La plantilla actual cambia la imagen o la identidad; es necesaria una migración explícita", + "The current template requires a new persistent path:": "La plantilla actual requiere una nueva ruta persistente:", + "The custom path cannot hide system directories": "La ruta personalizada no puede ocultar directorios del sistema", + "The custom path overlaps another mount": "La ruta personalizada se superpone a otro montaje", + "The data and document volumes need at least 8 GB": "Los volúmenes de datos y documentos necesitan al menos 8 GB", + "The database server must accept connections from the IP address of this container, with a user that is not limited to localhost.": "El servidor de bases de datos debe aceptar conexiones desde la dirección IP de este contenedor, con un usuario que no se limita a localhost.", + "The dedicated adapter still requires replaying its rootfs changes": "El adaptador dedicado todavía requiere replaying its rootfs changes", + "The dependency hook and the stack recipe differ": "El gancho de dependencia y la receta de pila difieren", + "The dependency hook was modified; review it before updating": "El gancho de dependencia fue modificado; revisarlo antes de actualizarlo", + "The developer-friendly cloud platform for building and running LLM agents for AI-native applications.": "La plataforma de nube amigable con el desarrollador para construir y ejecutar agentes LLM para aplicaciones nativas de AI.", + "The device directory does not exist:": "El directorio del dispositivo no existe:", + "The device must keep its /dev path inside the LXC:": "El dispositivo debe mantener su camino /dev dentro del LXC:", + "The device must keep its native path without duplicates": "El dispositivo debe mantener su ruta nativa sin duplicados", + "The directory contains no character devices:": "El directorio no contiene dispositivos de carácter:", "The directory does not exist in the CT.": "El directorio no existe en el CT.", "The disk": "el disco", + "The disk size cannot be reproduced": "El tamaño del disco no se puede reproducir", + "The disk usage of the container could not be read": "El uso del disco del contenedor no se podía leer", + "The domain must resolve to the public address of this network before the certificate can be issued.": "El dominio debe resolverse a la dirección pública de esta red antes de que se pueda expedir el certificado.", + "The download client still needs to be configured.": "El cliente de descarga todavía necesita ser configurado.", + "The download stopped progressing; cancelling this attempt.": "La descarga dejó de progresar; cancelando este intento.", + "The downloaded image does not match its manifest": "La imagen descargada no coincide con su manifiesto", + "The downloaded image is corrupt:": "La imagen descargada es corrupta:", "The dpkg package database is clean.": "La base de datos de paquetes de dpkg está limpia.", "The driver installed but does not drive this GPU.": "El controlador se instaló pero no controla esta GPU.", + "The dynamic NVIDIA hook is missing": "Falta el gancho dinámico NVIDIA", + "The dynamic NVIDIA hook is missing or duplicated": "El gancho dinámico NVIDIA está desaparecido o duplicado", + "The dynamic NVIDIA profile requires an unprivileged LXC": "El perfil dinámico NVIDIA requiere un LXC no privilegiado", + "The dynamic profile does not support static driver mounts": "El perfil dinámico no admite montajes de controlador estático", "The file does not exist, is empty or is not readable.": "El archivo no existe, está vacío o no es legible.", + "The file does not exist:": "El archivo no existe:", + "The file is too large to be a Compose file": "El archivo es demasiado grande para ser un archivo Compose", "The filesystem": "El sistema de archivos", + "The final cleanup did not complete:": "La limpieza final no terminó:", "The following DKMS-managed drivers will now be rebuilt against it so they keep working after reboot:": "Los siguientes controladores administrados por DKMS ahora se reconstruirán para que sigan funcionando después del reinicio:", "The following LXC containers have NVIDIA passthrough configured:": "Los siguientes contenedores LXC tienen configurado el paso a través de NVIDIA:", "The following backup paths are kernel-tied and are excluded from the picker to keep the target's boot safe. The operator's own tuning inside these paths (IOMMU cmdline, VFIO IDs, custom quirks) is merged back automatically via kernel-agnostic merge:": "las siguientes rutas de respaldo están vinculadas al kernel y se excluyen del selector para mantener seguro el arranque del destino. El propio ajuste del operador dentro de estas rutas (línea cmd de IOMMU, ID de VFIO, peculiaridades personalizadas) se fusiona automáticamente mediante una fusión independiente del kernel:", @@ -4390,17 +5843,99 @@ "The following selected device(s) are Physical Functions with active Virtual Functions:": "Los siguientes dispositivos seleccionados son funciones físicas con funciones virtuales activas:", "The following selected device(s) are SR-IOV Virtual Functions (VFs):": "Los siguientes dispositivos seleccionados son funciones virtuales (VF) SR-IOV:", "The fstab entry will still be removed; reboot or manual umount needed.": "La entrada fstab seguirá siendo eliminada; Es necesario reiniciar o desmontar manualmente.", + "The gateway must be another usable address in the same subnet.": "La puerta de enlace debe ser otra dirección utilizable de la misma subred.", "The gateway should appear in your Tailscale admin console shortly.": "La puerta de enlace debería aparecer en su consola de administración de Tailscale en breve.", + "The healthcheck cannot run without an IP address": "El control de salud no puede funcionar sin una dirección IP", + "The host NVIDIA driver is not responding correctly": "El controlador NVIDIA host no está respondiendo correctamente", + "The host bind source does not exist:": "La fuente de host bind no existe:", + "The host bind source is not a regular file or directory:": "La fuente host bind no es un archivo o directorio regular:", + "The host directory changed before it was mounted": "El directorio host cambió antes de montarlo", "The host directory may not be accessible from an unprivileged container.": "Es posible que no se pueda acceder al directorio del host desde un contenedor sin privilegios.", + "The host has no IPv4 address on the selected bridge": "El host no tiene dirección IPv4 en el puente seleccionado", + "The host monitor does not see the real host memory": "El monitor host no ve la memoria real del host", + "The host monitor does not share this host namespace:": "El monitor host no comparte este espacio de nombres de host:", + "The host monitor needs consent for privileged access to the host": "El monitor host necesita el consentimiento para el acceso privilegiado al host", + "The host monitor profile does not support another sysctl include": "El perfil de monitor host no soporta otro sísctl incluye", + "The host monitor uses the host network, without DHCP or its own gateway": "El monitor host utiliza la red host, sin DHCP o su propia puerta de entrada", + "The host port is already in use:": "El puerto host ya está en uso:", + "The identity of a member was replaced": "Se sustituyó la identidad de un miembro", + "The image changes the user expected by the adapter": "La imagen cambia el usuario esperado por el adaptador", + "The image could not be read from its registry:": "La imagen no se pudo leer desde su registro:", + "The image declares data paths that are still stored in the rootfs": "La imagen declara caminos de datos que aún están almacenados en los rootfs", + "The image did not grant the application user access to the devices; check its native init. Host permissions were not relaxed.": "La imagen no concedió el acceso del usuario de la aplicación a los dispositivos; comprobar su entrada nativa. Los permisos del host no se relajaron.", + "The image did not pass the integrity check": "La imagen no pasó el control de integridad", + "The image does not declare support for this architecture:": "La imagen no declara soporte para esta arquitectura:", + "The image download did not complete correctly; downloading it again...": "La descarga de la imagen no se completó correctamente; descargarlo de nuevo...", + "The image expects files that are given to it one by one:": "La imagen espera archivos que se le dan uno por uno:", + "The image is already up to date; nothing was changed.": "La imagen ya está actualizada; nada cambió.", + "The image is in its registry, for one architecture.": "La imagen está en su registro, para una arquitectura.", + "The image is in its registry.": "La imagen está en su registro.", + "The image is in its registry:": "La imagen está en su registro:", + "The image requests NVIDIA, but the host has no working NVIDIA driver": "La imagen solicita NVIDIA, pero el host no tiene ningún controlador NVIDIA trabajando", + "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk.": "La imagen solicita desactivar parte del AppArmor o confinamiento de seccomp. Continúe sólo si confía en la imagen y acepta este riesgo.", + "The image requests disabling part of the AppArmor or seccomp confinement. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "La imagen solicita desactivar parte del AppArmor o confinamiento de seccomp. El Compose ofrece una relajación opcional AppArmor o seccomp; se mantendrá deshabilitado a menos que el usuario lo seleccione. Continúe sólo si confía en la imagen y acepta este riesgo.", + "The image was not found in its registry, or it is private:": "La imagen no se encontró en su registro, o es privada:", + "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged.": "El Compose importado solicita privilegiado, pero la documentación oficial jlesage/handbrake no lo requiere; ProxMenux mantiene el LXC sin privilegios.", + "The imported OCI groups are not numeric": "Los grupos OCI importados no son numéricos", + "The imported OCI user or group is not numeric": "El usuario o grupo OCI importado no es numérico", + "The initial user name and password stay written in /etc/pve/lxc/.conf as INIT_USERNAME and INIT_PASSWORD. They can be removed after the first login, with the container stopped.": "El nombre de usuario inicial y la contraseña permanecen escritos en /etc/pve/lxc/según INIT USERNAME e INIT PASSWORD. Se pueden quitar después de la primera entrada, con el contenedor detenido.", + "The installation asks which one to use for these paths.": "La instalación pregunta cuál usar para estas rutas.", + "The installation ended with exit code": "La instalación terminó con código de salida", "The installation requires a server restart to apply changes. Do you want to restart now?": "La instalación requiere reiniciar el servidor para aplicar los cambios. ¿Quieres reiniciar ahora?", + "The installation runs on the Proxmox node itself, as root": "La instalación se ejecuta en el propio nodo Proxmox, como root", + "The installation stopped because of an unexpected error": "La instalación se detuvo debido a un error inesperado", "The installation/changes require a server restart to apply correctly. Do you want to reboot now?": "La instalación/los cambios requieren un reinicio del servidor para que se apliquen correctamente. ¿Quieres reiniciar ahora?", + "The installer must run as root on Proxmox VE": "El instalador debe funcionar como root en Proxmox VE", + "The instance changed while it was being edited; configure Recreate again": "El caso cambió mientras se estaba editando; configurar Recrear de nuevo", + "The instance does not use NVIDIA": "El caso no utiliza NVIDIA", + "The instance has a pending operation": "El caso tiene una operación pendiente", + "The instance identity or status must be reviewed before updating.": "La identidad o el estado de la instancia debe revisarse antes de actualizarse.", + "The instance is not ready to be updated": "El caso no está listo para ser actualizado", + "The instance is not ready; review its pending operation": "La instancia no está lista; revise su operación pendiente", + "The instance record operation did not complete; no container was modified.": "El registro de instancia operación no se completó; ningún contenedor fue modificado.", + "The instance registry is not safe": "El registro de instancias no es seguro", + "The journal belongs to another VMID": "El diario pertenece a otro VMID", + "The journal belongs to another stack": "El diario pertenece a otra pila", + "The journal has an incomplete recovery state": "La revista tiene un estado de recuperación incompleto", + "The kernel module is not active:": "El módulo del núcleo no está activo:", "The kernel module of version": "El módulo del kernel de la versión.", "The local envelope is dropped and future backups do not upload anything. Uploaded envelopes already on PBS stay intact and remain recoverable with their original passphrase.": "El sobre local se elimina y las copias de seguridad futuras no cargan nada. Los sobres cargados que ya están en PBS permanecen intactos y recuperables con su frase de contraseña original.", "The long test runs directly on the disk hardware.": "La prueba larga se ejecuta directamente en el hardware del disco.", + "The main member must stop first and start last": "El miembro principal debe parar primero y comenzar el último", + "The main member of the stack is missing": "Falta el miembro principal de la pila", + "The manifest does not match its digest": "El manifiesto no coincide con su digestión", + "The member journal belongs to another stack operation": "El diario miembro pertenece a otra pila operación", + "The member journal is outside the registry": "La revista miembro está fuera del registro", + "The mount evidence does not match the verified directories": "La evidencia de montaje no coincide con los directorios verificados", + "The mount source or options were not kept": "La fuente de montaje o las opciones no se guardaron", + "The mounted source differs from the configured directory": "La fuente montada difiere del directorio configurado", + "The mounts of the new container do not match the proposal": "Las monturas del nuevo contenedor no coinciden con la propuesta", + "The native GPU permissions were not kept": "Los permisos de GPU nativos no se conservaron", + "The native unprivileged idmap is required": "El idmap nativo no privilegiado es necesario", "The new SSH key was installed and is now authorized on the server.\nKey file:": "La nueva clave SSH se instaló y ahora está autorizada en el servidor.\nArchivo clave:", "The new SSH key was pushed to the LXC via 'pct exec' on": "La nueva clave SSH se envió al LXC a través de 'pct exec' en", + "The new Valkey volume contains unexpected data": "El nuevo volumen Valkey contiene datos inesperados", + "The new container did not pass validation": "El nuevo contenedor no aprobó la validación", + "The new container is not authorized by the operation journal": "El nuevo contenedor no está autorizado por la revista operación", + "The new image adds a symbolic link in a generated path": "La nueva imagen añade un vínculo simbólico en un camino generado", + "The new image changes the PostgreSQL major version; the data must be migrated before updating": "La nueva imagen cambia la versión principal de PostgreSQL; los datos deben ser migrados antes de actualizar", + "The new image could not be installed": "La nueva imagen no se puede instalar", + "The new image could not be installed:": "La nueva imagen no se puede instalar:", + "The new image does not keep a required executable": "La nueva imagen no mantiene un ejecutable necesario", + "The new image requires additional persistent paths": "La nueva imagen requiere caminos persistentes adicionales", + "The new image requires additional persistent paths; use Recreate": "La nueva imagen requiere caminos persistentes adicionales; uso Recrear", "The new prompt will be used in new terminal sessions.": "El nuevo prompt se usará en las nuevas sesiones de terminal.", "The next visit to the dashboard will show the initial setup wizard.": "La próxima visita al panel mostrará el asistente de configuración inicial.", + "The observed inventory differs from the validated runtime": "El inventario observado difiere del tiempo de funcionamiento validado", + "The official Tandoor startup executable is missing": "Falta el ejecutable oficial de arranque de Tandoor", + "The official inventory contains no NVIDIA devices": "El inventario oficial no contiene dispositivos NVIDIA", + "The official inventory contains no NVIDIA driver components": "El inventario oficial no contiene componentes de controlador NVIDIA", + "The official startup cannot be reproduced": "La startup oficial no puede reproducirse", + "The official startup of the application is missing": "Falta el inicio oficial de la aplicación", + "The operation already finished; it is not restored automatically": "La operación ya terminada; no se restaura automáticamente", + "The operation could not be completed": "La operación no pudo completarse", + "The operation stopped halfway. Choose \"Recover\" for this container in the OCI management menu to restore the previous installation.": "La operación se detuvo a mitad de camino. Elija \"Recover\" para este contenedor en el menú de gestión OCI para restaurar la instalación anterior.", + "The operation was stopped because a shared directory changed its identity:": "La operación se detuvo porque un directorio compartido cambió su identidad:", "The original MOTD backup is unavailable; no changes were made": "The original MOTD backup is unavailable;no se hicieron cambios", "The original MOTD configuration has been restored": "La configuración MOTD original ha sido restaurada", "The original MOTD state is unavailable; no changes were made": "el estado MOTD original no está disponible;no se hicieron cambios", @@ -4408,18 +5943,75 @@ "The original rpcbind state could not be restored completely": "El estado original de rpcbind no se pudo restaurar por completo", "The original rpcbind state is unavailable; no service state was changed": "el estado rpcbind original no está disponible;no se cambió ningún estado de servicio", "The package is currently in a broken state and is blocking apt updates on this system.": "El paquete está dañado y bloquea las actualizaciones de APT en este sistema.", + "The parent of an NVIDIA destination is not a directory": "El padre de un destino NVIDIA no es un directorio", + "The parent of the target is not a directory:": "El padre del objetivo no es un directorio:", + "The password could not be retrieved automatically": "La contraseña no se pudo recuperar automáticamente", "The passwords do not match. Please try again.": "Las contraseñas no coinciden. Por favor inténtalo de nuevo.", + "The path escapes the rootfs:": "El camino escapa a los rootfs:", + "The path must be absolute and normalized": "La ruta debe ser absoluta y estar normalizada", + "The path overlaps an existing mount": "La ruta se superpone a un montaje existente", + "The persistent NVIDIA hook does not match the installer:": "El gancho NVIDIA persistente no coincide con el instalador:", + "The persistent WebUI credentials were not found": "No se encontraron las persistentes credentiales WebUI", + "The physical NVIDIA selection changed": "La selección física de NVIDIA cambió", + "The post-start configuration cannot be applied with the LXC stopped": "La configuración post-start no se puede aplicar con el LXC detenido", + "The postgres user was not found in the image": "El usuario postgres no fue encontrado en la imagen", + "The prepared directory escapes the rootfs:": "El directorio preparado escapa a los rootfs:", "The preselected VMID does not exist on this host:": "El VMID preseleccionado no existe en este host:", + "The previous native backup will be restored. Shared host directories are not reverted. Displaced disks are kept.": "El backup nativo anterior será restaurado. Los directorios de host compartidos no son revertidos. Se guardan discos desplazados.", + "The previous stack contract is not safe; review it before reusing it": "El contrato de pila anterior no es seguro; revisarlo antes de reutilizarlo", + "The previous stack contract is not valid; it is not archived automatically": "El contrato de pila anterior no es válido; no se archiva automáticamente", + "The previous stack contract still has containers or VMs:": "El contrato de pila anterior todavía tiene contenedores o VMs:", + "The private address is already assigned to another container:": "La dirección privada ya está asignada a otro contenedor:", + "The private bridge does not have the expected address:": "El puente privado no tiene la dirección prevista:", + "The private journal has an unsafe owner or permissions": "La revista privada tiene un propietario inseguro o permisos", + "The private network allocator was not found": "El aleator de la red privada no fue encontrado", + "The private network is still used by another container and is kept:": "La red privada sigue siendo utilizada por otro contenedor y se mantiene:", + "The private network must be assigned automatically": "La red privada debe ser asignada automáticamente", + "The privileged deployment does not include the required explicit consent": "El despliegue privilegiado no incluye el consentimiento explícito necesario", + "The prlimit soft value exceeds the hard value": "El valor prlimit blando supera el valor duro", + "The proposal changes the identity of the instance": "La propuesta cambia la identidad de la instancia", "The proposed ARC maximum is below Proxmox VE's pool-size guideline:": "El máximo de ARC propuesto está por debajo de la pauta de tamaño de grupo de Proxmox VE:", + "The published views must be inside the common root": "Las opiniones publicadas deben estar dentro de la raíz común", + "The read-only view does not apply the expected protection": "La opinión de sólo lectura no aplica la protección esperada", + "The read-only view was not published": "La opinión de sólo lectura no fue publicada", + "The read/write view was not published": "La vista de lectura/escritura no se publicó", + "The recipe requires configuration at startup; its coordinated replay is not available": "La configuración de la receta requiere al inicio; su reproducción coordinada no está disponible", + "The record belongs to another container": "El registro pertenece a otro contenedor", + "The record does not belong to this operation": "El registro no pertenece a esta operación", + "The record no longer belongs to this operation": "El registro ya no pertenece a esta operación", + "The record of a member was replaced; the assembly is not resumed": "El registro de un miembro fue reemplazado; la asamblea no se reanuda", + "The record or diagnosis could not be completed; no update was run.": "El registro o el diagnóstico no se pudo completar; no se realizó ninguna actualización.", + "The recovery did not complete. Review the log and choose \"Recover\" again for this container in the OCI management menu.": "La recuperación no terminó. Revise el registro y elija \"Recover\" de nuevo para este contenedor en el menú de gestión OCI.", + "The remote does not exist; create and authorize it first in the WebUI:": "El remoto no existe; crear y autorizar primero en el WebUI:", + "The remote installer must run as root on Proxmox VE": "El instalador remoto debe funcionar como root en Proxmox VE", + "The remote must already be created and authorized in the Rclone web UI. This operation restarts the CT and publishes two FUSE views on the host.": "El remoto ya debe estar creado y autorizado en la interfaz web de Rclone. Esta operación reinicia el CT y publica dos puntos de vista FUSE sobre el host.", + "The remote path must be relative and cannot contain line breaks": "La ruta remota debe ser relativa y no puede contener saltos de línea", + "The repair must preserve the image dependencies:": "La reparación debe preservar las dependencias de la imagen:", + "The requested VMID block is already in use": "El bloque VMID solicitado ya está en uso", + "The requested machine learning GPU profile is not working; it is not replaced by CPU": "El perfil GPU de aprendizaje automático solicitado no funciona; no es reemplazado por CPU", + "The restored service did not pass its health check": "El servicio restaurado no aprobó su cheque de salud", + "The restored service stopped; the recovery is not confirmed": "El servicio restaurado se detuvo; la recuperación no se confirma", + "The reviewed Tandoor stack does not require a privileged LXC.": "La pila Tandoor revisada no requiere un privilegiado LXC.", + "The rootfs capture only belongs to the running installation": "La captura de rootfs sólo pertenece a la instalación de ejecución", + "The rootfs is not managed by Proxmox": "Los rootfs no son gestionados por Proxmox", + "The rootfs is not mounted": "Los rootfs no se montan", "The same GPU cannot be used by two VMs at the same time.": "Dos máquinas virtuales no pueden utilizar la misma GPU al mismo tiempo.", + "The same connection can be given as container variables instead of the file: UN_SONARR_0_URL and UN_SONARR_0_API_KEY, or the UN_RADARR_0_ equivalents.": "La misma conexión se puede administrar como variables contenedor en lugar del archivo: UN SONARR 0 URL y UN SONARR 0 API KEY, o UN RADARR 0 equivalents.", "The saved MOTD state is invalid; no changes were made": "el estado MOTD guardado no es válido;no se hicieron cambios", + "The saved OCI record is incomplete or has an unexpected format.": "El registro OCI guardado es incompleto o tiene un formato inesperado.", + "The saved projection does not match the native evidence": "La proyección salva no coincide con la evidencia nativa", + "The saved record was replaced for": "El registro guardado fue reemplazado por", "The saved utility package list is invalid; no packages were removed": "la lista de paquetes de utilidades guardada no es válida;no se eliminaron paquetes", "The script clones the osx-proxmox.com repository and once the setup is complete, the server will automatically reboot.": "El script clona el repositorio osx-proxmox.com y una vez que se completa la configuración, el servidor se reiniciará automáticamente.", "The script will continue to restore VM passthrough mode on the host and reuse existing hostpci entries.": "El script continuará restaurando el modo de paso a través de VM en el host y reutilizará las entradas hostpci existentes.", "The script will preconfigure the selected GPU now and finalize hardware binding after reboot.": "El script preconfigurará la GPU seleccionada ahora y finalizará el enlace del hardware después del reinicio.", "The selected AMD GPU does not report FLR reset support": "La GPU AMD seleccionada no informa compatibilidad con el restablecimiento de FLR", "The selected AMD GPU is currently in power state D3cold": "La GPU AMD seleccionada se encuentra actualmente en estado de energía D3cold", + "The selected CT does not match its OCI record. Its configuration will not be modified or deleted.": "El CT seleccionado no coincide con su registro OCI. Su configuración no será modificada ni eliminada.", + "The selected GPU changed": "La GPU seleccionada cambió", "The selected GPU configuration already exists in this container.": "La configuración de GPU seleccionada ya existe en este contenedor.", + "The selected GPU device does not exist:": "El dispositivo GPU seleccionado no existe:", + "The selected GPU directory does not exist:": "El directorio GPU seleccionado no existe:", "The selected GPU has no dedicated .1 audio sibling function.": "La GPU seleccionada no tiene una función hermana de audio .1 dedicada.", "The selected GPU is already assigned to another VM that is currently running:": "La GPU seleccionada ya está asignada a otra VM que se está ejecutando actualmente:", "The selected GPU is already assigned to this VM, but the host is not currently using vfio-pci for this device.": "La GPU seleccionada ya está asignada a esta VM, pero el host no utiliza actualmente vfio-pci para este dispositivo.", @@ -4435,11 +6027,15 @@ "The selected Intel GPU does not expose a PCI reset interface": "La GPU Intel seleccionada no expone una interfaz de reinicio PCI", "The selected Intel GPU has non-FLR reset support and unknown subtype": "La GPU Intel seleccionada tiene soporte de reinicio no FLR y subtipo desconocido", "The selected Intel GPU is currently in power state D3cold": "La GPU Intel seleccionada se encuentra actualmente en estado de energía D3cold", + "The selected Intel render device does not exist:": "El dispositivo de renderización Intel seleccionado no existe:", "The selected VM": "La máquina virtual seleccionada", "The selected VM is running.": "La VM seleccionada se está ejecutando.", "The selected base folder does not exist and could not be created:": "La carpeta base seleccionada no existe y no se pudo crear:", + "The selected configuration needs to start the LXC during the installation": "La configuración seleccionada debe iniciar el LXC durante la instalación", "The selected container is unprivileged. A privileged container is required for direct device passthrough.": "El contenedor seleccionado no tiene privilegios. Se requiere un contenedor privilegiado para el paso directo del dispositivo.", "The selected device": "El dispositivo seleccionado", + "The selected device is not a block device": "El dispositivo seleccionado no es un dispositivo de bloque", + "The selected device is not a character device": "El dispositivo seleccionado no es un dispositivo de carácter", "The selected directory does not exist:": "El directorio seleccionado no existe:", "The selected disk has an active swap partition. Aborting.": "El disco seleccionado tiene una partición swap activa. Se cancela la operación.", "The selected disk is currently used by a RUNNING VM or CT. Stop it before formatting.": "El disco seleccionado lo utiliza actualmente una VM o CT EN EJECUCIÓN. Deténgalo antes de formatear.", @@ -4447,25 +6043,76 @@ "The selected disk now contains a system-critical mount. Aborting.": "El disco seleccionado ahora contiene un montaje crítico para el sistema. Abortando.", "The selected path does not exist on this host:": "la ruta seleccionada no existe en este host:", "The selected path is not a valid directory:": "La ruta seleccionada no es un directorio válido:", + "The selected render device does not exist:": "El dispositivo de renderización seleccionado no existe:", "The server connected you as guest instead of the specified user.": "El servidor lo conectó como invitado en lugar del usuario especificado.", "The server may not have accessible shares.": "Es posible que el servidor no tenga recursos compartidos accesibles.", "The server may require authentication for actual share access.": "El servidor puede requerir autenticación para el acceso real al recurso compartido.", "The server refused password authentication for": "El servidor rechazó la autenticación de contraseña para", "The server rejected": "El servidor rechazó", + "The service builds its own image; only a published image can be installed": "El servicio construye su propia imagen; sólo se puede instalar una imagen publicada", + "The service declares no image:": "El servicio no declara imagen:", + "The setting has no final value:": "El ajuste no tiene valor final:", "The share already exists in smb.conf:": "El recurso compartido ya existe en smb.conf:", + "The shared destination is not a directory": "El destino compartido no es un directorio", + "The shared directory points to a protected host path": "El directorio compartido apunta a una ruta de host protegida", + "The shared path exists but is not a directory:": "El camino compartido existe pero no es un directorio:", + "The size of existing disks is not rounded": "El tamaño de los discos existentes no se redondea", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk.": "La fuente Compose pide privilegiado: verdadero, pero esto no prueba que la imagen necesita un LXC privilegiado. ProxMenux utilizará un LXC sin privilegios por defecto y ofrecerá el modo amplio sólo como opción. Continúe sólo si confía en la imagen y acepta este riesgo.", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. The Docker rootlesskit profile does not exist in LXC and will be replaced by AppArmor unconfined, which is less restrictive. Continue only if you trust the image and accept this risk.": "La fuente Compose pide privilegiado: verdadero, pero esto no prueba que la imagen necesita un LXC privilegiado. ProxMenux utilizará un LXC sin privilegios por defecto y ofrecerá el modo amplio sólo como opción. El Compose ofrece una relajación opcional AppArmor o seccomp; se mantendrá deshabilitado a menos que el usuario lo seleccione. El perfil de rootlesskit Docker no existe en LXC y será reemplazado por AppArmor no definido, que es menos restrictivo. Continúe sólo si confía en la imagen y acepta este riesgo.", "The source VM also has these audio devices, likely added together with the GPU. Remove them too?": "La máquina virtual de origen también tiene estos dispositivos de audio, probablemente agregados junto con la GPU. ¿Quitarlos también?", "The specified directory does not exist:": "El directorio especificado no existe:", + "The stability period must be shorter than the healthcheck timeout": "El período de estabilidad debe ser más corto que el tiempo de prueba de salud", + "The stack contains devices or directives without a translation": "La pila contiene dispositivos o directivas sin una traducción", + "The stack does not have the expected native hook": "La pila no tiene el gancho nativo esperado", + "The stack journal is outside the registry": "El diario de la pila está fuera del registro", + "The stack member has no declared adaptation profile": "El miembro de la pila no tiene perfil de adaptación declarado", + "The stack name only accepts lowercase letters, numbers and hyphens": "El nombre de la pila solo acepta letras minúsculas, números y guiones", + "The stack needs member adaptations or a verification of missing volumes": "La pila necesita adaptaciones de los miembros o una verificación de volúmenes perdidos", + "The stack operation had already finished": "La pila operación ya había terminado", + "The stack operation has not finished yet": "La pila operación no ha terminado todavía", + "The stack operation stopped halfway. Select the stack again in the OCI management menu to recover it.": "La pila operación se detuvo a mitad de camino. Seleccione la pila de nuevo en el menú de gestión de OCI para recuperarla.", + "The stack registry is incomplete; review the private contracts.": "El registro de pilas es incompleto; revisar los contratos privados.", + "The stack startup hook was not found": "El gancho de arranque de pila no fue encontrado", + "The stack update was saved.": "La actualización de la pila fue guardada.", + "The startup differs from the declared Nextcloud adapter": "La startup difiere del adaptador Nextcloud declarado", + "The startup differs from the declared adapter": "La startup difiere del adaptador declarado", + "The staticfiles volume needs at least 1 GB": "El volumen de los ficheros estáticos necesita al menos 1 GB", "The storage has been removed and the disk unmounted.": "Se eliminó el almacenamiento y se desmontó el disco.", + "The sysctl content was modified outside the saved record": "El contenido de sysctl fue modificado fuera del registro guardado", + "The sysctl include is a link:": "El sysctl incluye un enlace:", + "The sysctl include is not a safe host file": "El sysctl incluye no es un archivo host seguro", + "The sysctl include is not restored over a symbolic link": "El sysctl incluye no se restaura sobre un enlace simbólico", + "The sysctl include is unknown or differs from the saved record": "El sysctl incluye es desconocido o difiere del registro guardado", + "The temporary password could not be retrieved.": "La contraseña temporal no se puede recuperar.", "The test will continue even if you close this terminal.": "La prueba continuará incluso si cierra esta terminal.", + "The tmpfs mounts of the container differ from the saved record": "Los montajes tmpfs del contenedor difieren del registro guardado", + "The tmpfs path or size is outside the supported profile": "El camino o tamaño de tmpfs está fuera del perfil soportado", + "The translated recipe changed during the preparation": "La receta traducida cambió durante la preparación", + "The value contains an unsupported character": "El valor contiene un carácter no admitido", + "The values do not match. Enter them again.": "Los valores no coinciden. Vuelve a introducirlos.", + "The variable contains control characters:": "La variable contiene caracteres de control:", + "The variable contains line breaks:": "La variable contiene roturas de línea:", "The vfio.conf entries have been removed and initramfs rebuilt.": "Las entradas de vfio.conf se eliminaron y se reconstruyó initramfs.", + "The web UI password must have at least 24 characters": "La contraseña de la interfaz web debe tener al menos 24 caracteres", + "The web UI user contains characters that are not allowed": "El usuario de la interfaz web contiene caracteres no permitidos", + "The web interface is served over plain HTTP on port 51821 (INSECURE=true). Keep it inside the local network or publish it through a reverse proxy with TLS.": "La interfaz web se sirve sobre HTTP simple en el puerto 51821 (INSECURE=true). Mantenlo dentro de la red local o publicarlo a través de un proxy inverso con TLS.", + "The web interface uses a self-signed certificate, so the browser shows a warning the first time.": "La interfaz web utiliza un certificado auto-firmado, por lo que el navegador muestra una advertencia por primera vez.", + "The wizard writes a .conf file in /config. Restart the container afterwards so the bot starts with that configuration.": "El mago escribe un archivo .conf en /config. Reinicie el contenedor después para que el bot comience con esa configuración.", + "The world's fastest framework for building websites": "El marco más rápido del mundo para construir sitios web", + "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server.": "Thelounge (un fork de shoutIRC) es un cliente IRC web que alberga en su propio servidor.", "Then bind-mount to container": "Luego vincule el montaje al contenedor", "Then change the VM display to none (vga: none) when the guest is stable.": "Luego cambie la visualización de la VM a ninguno (vga: ninguno) cuando el invitado esté estable.", "Then change the VM display to none (vga: none) when the system is stable.": "Luego cambie la visualización de VM a ninguno (vga: ninguno) cuando el sistema esté estable.", "Then run this option again:": "Luego ejecute esta opción nuevamente:", "Then update /etc/fstab on the host with the same options.": "Luego actualice /etc/fstab en el host con las mismas opciones.", + "There are extra disks or bind mounts outside the journal; the rootfs is not replaced": "Hay discos extras o monturas bind fuera de la revista; los rootfs no es reemplazado", + "There is no temporary container of this operation to keep the current disks": "No hay contenedor temporal de esta operación para mantener los discos actuales", + "There is no verified backup; a modified container is not touched": "No hay backup verificado; un contenedor modificado no se toca", + "These VMIDs are not free:": "Estos VMID no son gratuitos:", "These are the changes that will be made": "Estos son los cambios que se harán", "These interface configurations will be removed": "Estas configuraciones de interfaz serán eliminadas.", "These paths will not be restored live and will be extracted for manual recovery.": "Estas rutas no se restaurarán en vivo y se extraerán para su recuperación manual.", + "These values are asked during the installation:": "Estos valores se preguntan durante la instalación:", "This CIFS share is mounted with restrictive permissions.": "Este recurso compartido CIFS está montado con permisos restrictivos.", "This GPU is considered incompatible with GPU passthrough to a VM in ProxMenux.": "Esta GPU se considera incompatible con el paso de GPU a una VM en ProxMenux.", "This NFS share is fully restricted — even the host root cannot write to it.": "Este recurso compartido NFS está completamente restringido: ni siquiera la raíz del host puede escribir en él.", @@ -4477,6 +6124,8 @@ "This backup is encrypted.": "esta copia de seguridad está cifrada.", "This backup was taken on kernel": "Esta copia de seguridad se realizó en el kernel", "This cleanup will:": "Esta limpieza realizará lo siguiente:", + "This container belongs to a stack; publish the whole stack": "Este contenedor pertenece a una pila; publicar toda la pila", + "This container belongs to a stack; recover the whole stack": "Este contenedor pertenece a una pila; recuperar toda la pila", "This container does not have apt-get. NFS client installation only supports Debian/Ubuntu containers.": "Este contenedor no tiene apt-get. La instalación del cliente NFS solo admite contenedores Debian/Ubuntu.", "This container does not have apt-get. Samba client installation only supports Debian/Ubuntu containers.": "Este contenedor no tiene apt-get. La instalación del cliente Samba solo admite contenedores Debian/Ubuntu.", "This container has no GPU configured. Coral TPU works best alongside hardware video decoding (Quick Sync, VA-API, NVENC) for apps like Frigate.": "Este contenedor no tiene GPU configurada. Coral TPU funciona mejor junto con la decodificación de video por hardware (Quick Sync, VA-API, NVENC) para aplicaciones como Frigate.", @@ -4486,15 +6135,21 @@ "This erases existing metadata.": "Esto borra los metadatos existentes.", "This explicitly marks the container as privileged": "Esto marca explícitamente el contenedor como privilegiado.", "This guarantees that device nodes are available before applying LXC GPU config.": "Esto garantiza que los nodos del dispositivo estén disponibles antes de aplicar la configuración de GPU LXC.", + "This image cannot be installed as it is described:": "Esta imagen no se puede instalar como se describe:", + "This image requires the host module": "Esta imagen requiere el módulo host", "This installation will:": "Esta instalación:", "This installer will:": "Este instalador:", "This interface is configured but doesn't exist physically": "Esta interfaz está configurada pero no existe físicamente.", + "This interface runs on the Proxmox node as root. Open proxmenux-oci.sh on the Proxmox host.": "Esta interfaz se ejecuta en el nodo Proxmox como root. Abre proxmenux-oci.sh en el host Proxmox.", "This is IRREVERSIBLE.": "Esto es IRREVERSIBLE.", "This is a destructive action": "Esta es una acción destructiva.", "This is a simple configuration change": "Este es un cambio de configuración simple.", "This is an external community script maintained by": "Este es un script externo mantenido por", "This is an external script that creates a macOS VM in Proxmox VE in just a few steps, whether you are using AMD or Intel hardware.": "Este es un script externo que crea una máquina virtual macOS en Proxmox VE en solo unos pocos pasos, ya sea que esté utilizando hardware AMD o Intel.", + "This is not a coordinated stack": "Esto no es una pila coordinada", + "This is not a valid image reference:": "Esta no es una referencia de imagen válida:", "This is unexpected since credentials were validated.": "Esto es inesperado ya que se validaron las credenciales.", + "This is what ProxMenux understood from the": "Esto es lo que ProxMenux entendió del", "This marks the container as unprivileged": "Esto marca el contenedor como sin privilegios.", "This may be normal for a fresh installation": "Esto puede ser normal para una instalación nueva.", "This may take a few minutes. Press OK to proceed.": "Esto puede tardar unos minutos. Presione Aceptar para continuar.", @@ -4503,12 +6158,14 @@ "This means Proxmox handles mount lifecycle natively (no manual /etc/fstab needed for NFS/CIFS host storages).": "Esto significa que Proxmox maneja el ciclo de vida del montaje de forma nativa (no se necesita /etc/fstab manual para almacenamientos de host NFS/CIFS).", "This means the credentials are incorrect.": "Esto significa que las credenciales son incorrectas.", "This might indicate network connectivity issues.": "Esto podría indicar problemas de conectividad de red.", + "This monitor uses a privileged LXC, shares processes and network with Proxmox and disables AppArmor in the CT. It uses the IP address and firewall of the host. A compromised image could affect the host; do not expose its web UI to the Internet.": "Este monitor utiliza un LXC privilegiado, comparte procesos y red con Proxmox y deshabilita AppArmor en el CT. Utiliza la dirección IP y el cortafuegos del host. Una imagen comprometida podría afectar al host; no exponga su interfaz de usuario web a Internet.", "This operation may take several minutes and requires internet connectivity.": "Esta operación puede tardar varios minutos y requiere conexión a Internet.", "This package was installed by older versions of the ProxMenux Coral installer that placed the M.2 kernel driver on every system, including USB-only setups. It is not needed for Coral USB devices, which use libedgetpu1-std / libedgetpu1-max only.": "Este paquete fue instalado por versiones antiguas del instalador de Coral de ProxMenux, que instalaban el controlador del kernel para Coral M.2 en todos los sistemas, incluidos aquellos que solo usaban Coral USB. No es necesario para los dispositivos Coral USB, que únicamente utilizan libedgetpu1-std o libedgetpu1-max.", "This passphrase is the ONLY way to access encrypted Borg backups.": "esta frase de contraseña es la ÚNICA forma de acceder a las copias de seguridad cifradas de Borg.", "This path is already used as a mount point in this container.": "Esta ruta ya se utiliza como punto de montaje en este contenedor.", "This path is not a registered mount point. Use it anyway?": "Esta ruta no es un punto de montaje registrado. ¿Usarlo de todos modos?", "This process changes file ownership inside the container": "Este proceso cambia la propiedad del archivo dentro del contenedor.", + "This profile only supports directory bind mounts": "Este perfil solo admite monturas de bind directorio", "This release channel is already active.": "Este canal de lanzamiento ya está activo.", "This removes the 'unprivileged: 1' line from the config": "Esto elimina la línea 'sin privilegios: 1' de la configuración", "This removes the storage from Proxmox. The iSCSI target is not affected.": "Esto elimina el almacenamiento de Proxmox. El destino iSCSI no se ve afectado.", @@ -4522,10 +6179,15 @@ "This session is running in the Monitor terminal. Running it from here would cut the connection mid-install and leave the switch in a broken state.": "esta sesión se ejecuta en la terminal Monitor. Ejecutarlo desde aquí cortaría la conexión durante la instalación y dejaría el conmutador en un estado roto.", "This session is running in the Monitor terminal. Updating from here would restart the Monitor service and cut the connection mid-install, leaving the update in a broken state.": "esta sesión se ejecuta en la terminal Monitor. La actualización desde aquí reiniciaría el servicio Monitor y cortaría la conexión durante la instalación, dejando la actualización en un estado roto.", "This shows the storage type and disk identifier": "Esto muestra el tipo de almacenamiento y el identificador del disco.", + "This stack requires replaying specific rootfs adaptations. Coordinated updates are not yet enabled for it.": "Esta pila requiere reaplicar adaptaciones específicas del rootfs. Las actualizaciones coordinadas aún no están habilitadas para ella.", "This state has a high probability of VM startup/reset failures.": "Este estado tiene una alta probabilidad de que se produzcan errores de inicio/reinicio de la máquina virtual.", "This state indicates a high risk of passthrough failure due to": "Este estado indica un alto riesgo de fallo de paso debido a", + "This template requests the host PID namespace, which has no validated safe LXC translation yet": "Esta plantilla solicita el espacio de nombres PID host, que no tiene ninguna traducción segura LXC validada todavía", "This tool is designed for systems with AMD GPUs.": "Esta herramienta está diseñada para sistemas con GPU AMD.", "This tool is designed for systems with Intel GPUs.": "Esta herramienta está diseñada para sistemas con GPU Intel.", + "This translator only supports the Nextcloud stack": "Este traductor solo admite el Nextcloud stack", + "This value is required.": "Este valor es necesario.", + "This variant requires the device": "Esta variante requiere el dispositivo", "This version does not build against the running kernel.": "esta versión no se basa en el kernel en ejecución.", "This will RESET the ProxMenux Monitor login credentials on this host:": "Esto RESTABLECERÁ las credenciales de inicio de sesión de ProxMenux Monitor en este host:", "This will add the mount to /etc/fstab so it persists after reboot.": "Esto agregará el montaje a /etc/fstab para que persista después del reinicio.", @@ -4547,13 +6209,17 @@ "This will restart the network service and may cause a brief disconnection. Continue?": "Esto reiniciará el servicio de red y puede provocar una breve desconexión. ¿Continuar?", "This will take time. Answer prompts carefully - see notes below.": "Esto llevará tiempo. Responda las indicaciones con atención; consulte las notas a continuación.", "This will upgrade this node to Proxmox VE 9 on Debian Trixie.": "Esto actualizará este nodo a Proxmox VE 9 en Debian Trixie.", + "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client.": "Thunderbird es un gestor de información personal gratuito y de código abierto que se utiliza principalmente como cliente de correo electrónico con un calendario y un libro de contactos, así como un lector de feeds RSS, cliente de chat y cliente de noticias.", "Tick the paths to include in this backup. Press \"Add custom path\" to add a folder or file of your own to the list.": "marque las rutas que desea incluir en esta copia de seguridad. Presione \"Agregar ruta personalizada\" para agregar una carpeta o archivo propio a la lista.", "Tick the paths to remove (they will not be deleted from disk — only from this list):": "marque las rutas a eliminar (no se eliminarán del disco, solo de esta lista):", + "Time is up; Home Assistant OS could not be confirmed as running": "El tiempo ha terminado; Home Assistant OS no puede ser confirmado como funcionamiento", "Time settings configured - Timezone:": "Configuración de hora configurada - Zona horaria:", "Time synchronization reset to UTC": "Restablecimiento de la sincronización horaria a UTC", + "Timezone": "Zona horaria", "Tip: Also mount the VirtIO ISO for drivers and guest agent installer": "Consejo: monte también VirtIO ISO para controladores y el instalador del agente invitado", "Tip: You can install the QEMU Guest Agent inside the VM with:": "Consejo: Puede instalar el Agente Invitado QEMU dentro de la VM con:", "Tip: zfs set acltype=posixacl xattr=sa / enables full ACL support.": "Consejo: zfs set acltype=posixacl xattr=sa / habilita la compatibilidad total con ACL.", + "Tmpfs size in MiB for": "Tamaño de tmpfs en MiB para", "To allow LXC write access, change the NFS export on the server to include:": "Para permitir el acceso de escritura a LXC, cambie la exportación NFS en el servidor para incluir:", "To apply it to the current shell now, run:": "Para aplicarlo ahora en la sesión actual, ejecute:", "To assign VFs to VMs or LXCs, edit the configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Para asignar VF a VM o LXC, edite la configuración manualmente a través de la interfaz web de Proxmox. La Función Física permanecerá ligada al controlador nativo.", @@ -4568,6 +6234,7 @@ "To pass SR-IOV Virtual Functions to a container, edit the LXC configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Para pasar funciones virtuales SR-IOV a un contenedor, edite la configuración de LXC manualmente a través de la interfaz web de Proxmox. La Función Física permanecerá ligada al controlador nativo.", "To remove partial VM:": "Para eliminar una máquina virtual parcial:", "To restore": "para restaurar", + "To restore it on another host, keep this file (not included in the vzdump backup):": "Para restaurarlo en otro host, mantenga este archivo (no incluido en el backup vzdump):", "To revert changes:": "Para revertir cambios:", "To start the VM:": "Para iniciar la máquina virtual:", "To stop:": "Para parar:", @@ -4579,12 +6246,17 @@ "To use this share from an LXC, bind-mount it via:": "Para usar este recurso compartido desde un LXC, móntelo mediante enlace:", "Tool exit code:": "Código de salida de la herramienta:", "Tool output:": "Salida de herramienta:", + "Tools": "Herramientas", "Top memory processes in CT": "Principales procesos de memoria en CT", + "Top-level configs, secrets and other global options are not yet supported": "Las opciones globales de nivel superior —configs, secrets y otras— aún no se admiten", + "Top-level volume options are not yet supported": "Todavía no se admiten opciones de volumen de alto nivel", "Total": "Total", "Total members:": "Total de miembros:", "Total routes": "Rutas totales", "Total size:": "Tamaño total:", + "Transaction log:": "Registro de transacciones:", "Translation files:": "Archivos de traducción:", + "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, µTP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more.": "Transmission está diseñado para un uso fácil y potente. Transmission tiene las características que desea de un cliente BitTorrent: cifrado, una interfaz web, intercambio de pares, enlaces magnéticos, DHT, μTP, UPnP y NAT-PMP, soporte web, directorios de reloj, edición de rastreadores, límites de velocidad globales y per-torrent, y más.", "Tried pvesm path and manual detection methods": "Ruta pvesm probada y métodos de detección manual", "Trust this certificate and save it for scheduled backups?": "¿Confiar en este certificado y guardarlo para copias de seguridad programadas?", "Try Again": "Intentar otra vez", @@ -4592,6 +6264,8 @@ "Try accessing": "Intenta acceder", "Try another archive": "Pruebe con otro archivo", "Try automatic repair of detected issues": "Pruebe la reparación automática de los problemas detectados", + "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources.": "Tvheadend funciona como servidor proxy: es un servidor de streaming de TV y registrador para Linux, FreeBSD y Android compatible con DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT confidencialIP y HDHomeRun como fuentes de entrada.", + "Twingate Connector for self-hosted server": "Conector Twingate para servidor auto hospedado", "Two-factor authentication and backup codes will be removed.": "Se eliminarán la autenticación de dos factores y los códigos de respaldo.", "Type": "Tipo", "Type the device path EXACTLY to confirm formatting:": "escriba la ruta del dispositivo EXACTAMENTE para confirmar el formato:", @@ -4600,16 +6274,22 @@ "Type: attached to PVE storage": "Tipo: adjunto al almacenamiento PVE", "Typed value does not match selected disk. Operation cancelled.": "El valor escrito no coincide con el disco seleccionado. Operación cancelada.", "UID in CT": "UID en TC", + "UID of the plex user (also owner of the GPU device)": "UID del usuario plex (también propietario del dispositivo GPU)", + "UID that Emby runs as": "UID que Emby funciona como", "UPGRADE PROMPTS - RECOMMENDED ANSWERS:": "INDICACIONES DE ACTUALIZACIÓN - RESPUESTAS RECOMENDADAS:", + "UPS monitoring and power outage notification system": "Sistema de notificación de seguimiento y salida de energía de UPS", "USB Accelerators:": "Aceleradores USB:", + "USB bus directory": "Directorio de autobuses USB", "USB disk target": "destino de disco USB", "USB drives mounted now:": "unidades USB montadas ahora:", "USB libedgetpu1": "USB libedgetpu1", "UUP Dump script not found.": "No se encontró el script de volcado UUP.", "UUp Dump ISO creator Custom": "UUp Dump Creador de ISO Personalizado", + "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer.": "Ubooquity es un servidor gratuito, ligero y fácil de usar para tus cómics y libros electrónicos. Úsalo para acceder a tus archivos desde cualquier lugar, con una tableta, un lector electrónico, un teléfono o una computadora.", "Udev rules for Coral USB devices added and rules reloaded.": "Se agregaron reglas de Udev para dispositivos Coral USB y se recargaron reglas.", "Udev rules for Coral USB devices already exist.": "Las reglas de Udev para dispositivos Coral USB ya existen.", "Udev rules for Coral USB devices appended and rules reloaded.": "Se agregaron reglas de Udev para dispositivos Coral USB y se recargaron reglas.", + "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results.": "UltiMaker Cura es un software de impresión 3D gratuito y fácil de usar confiable por millones de usuarios. Ajuste su modelo 3D con más de 400 ajustes para los mejores resultados de corte e impresión.", "Umbrel OS installer script by Helper Scripts\n\nVisit the GitHub repo to learn more, contribute, or support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm": "Script de instalación del sistema operativo Umbrel de Helper Scripts\n\nVisite el repositorio de GitHub para obtener más información, contribuir o apoyar el proyecto:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm", "Unable to detect Proxmox version": "No se puede detectar la versión de Proxmox", "Unable to detect Proxmox version.": "No se puede detectar la versión de Proxmox.", @@ -4618,6 +6298,9 @@ "Unable to resolve system ZFS pool disks. Aborting.": "No se pudieron resolver los discos del pool ZFS del sistema. Se cancela.", "Unable to resolve system disk topology. Aborting.": "No se pudo resolver la topología de discos del sistema. Se cancela.", "Understand the security implications of privileged containers": "Comprender las implicaciones de seguridad de los contenedores privilegiados", + "Unexpected Proxmox inventory; recovery blocked": "Inventario Proxmox inesperado; recuperación bloqueada", + "Unexpected formatting directory in the new Valkey volume": "directorio de formato inesperado en el nuevo volumen Valkey", + "Ungoogled Chromium is Google Chromium, sans dependency on Google web services.": "Ungoogled Chromium es Google Chromium, dependencia sans de los servicios web de Google.", "Uninstall Coral drivers and configuration": "Desinstalar los controladores y la configuración de Coral", "Uninstall Fail2Ban": "Desinstalar Fail2Ban", "Uninstall Lynis": "Desinstalar Lynis", @@ -4647,6 +6330,9 @@ "Unknown CPU type. IOMMU might not be properly enabled.": "Tipo de CPU desconocido. Es posible que IOMMU no esté habilitado correctamente.", "Unknown CPU vendor. Cannot determine IOMMU parameter.": "Proveedor de CPU desconocido. No se puede determinar el parámetro IOMMU.", "Unknown GPU": "GPU desconocida", + "Unknown adapter role": "Función de adaptador desconocido", + "Unknown dependency:": "Dependencia desconocida:", + "Unknown host monitor": "Monitor de host desconocido", "Unknown model": "Modelo desconocido", "Unknown size": "Tamaño desconocido", "Unknown storage controller": "Controlador de almacenamiento desconocido", @@ -4662,6 +6348,10 @@ "Unmounted:": "Desmontado:", "Unmounting": "Desmontaje", "Unmounting disk...": "Desmontando disco...", + "Unpackerr configured": "Unpackerr configurado", + "Unpackerr has no web interface and extracts nothing until it is pointed at a Starr application. Uncomment the [sonarr.0] or [radarr.0] section in /config/unpackerr.conf inside the container, set its url and api_key, then restart the container.": "Unpackerr no tiene interfaz web y no extrae nada hasta que se apunta a una aplicación Starr. Descomponer la sección [sonarr.0] o [radarr.0] en /config/unpackerr.conf dentro del contenedor, establecer su url y api key, luego reiniciar el recipiente.", + "Unpackerr requires Sonarr, Radarr or Lidarr in this suite": "Unpackerr requiere Sonarr, Radarr o Lidarr en esta suite", + "Unpackerr stopped during its first start": "Unpackerr se detuvo durante su primer inicio", "Unprivileged": "Sin privilegios", "Unprivileged Container Access": "Acceso a contenedores sin privilegios", "Unprivileged container": "Contenedor sin privilegios", @@ -4670,15 +6360,72 @@ "Unprivileged containers map their UIDs to high host UIDs (e.g. 100000+), which appear as 'others' on the host filesystem.": "Los contenedores sin privilegios asignan sus UID a UID de host altos (por ejemplo, 100000+), que aparecen como \"otros\" en el sistema de archivos del host.", "Unprivileged: Limited access (more secure)": "Sin privilegios: acceso limitado (más seguro)", "Unreachable": "Inalcanzable", + "Unrecognized Immich adapter": "Adaptador Immich no reconocido", + "Unrecognized adaptation format": "Formato de adaptación no reconocido", + "Unrecognized adaptation recipe": "Receta de adaptación no reconocida", + "Unrecognized dependency order of the stack:": "Orden de dependencia no reconocido de la pila:", + "Unrecognized host monitor profile": "Perfil de monitor de host no reconocido", + "Unrecognized native configuration": "Configuración nativa no reconocida", + "Unrecognized qBittorrent configuration format": "Formato de configuración de qBittorrent no reconocido", + "Unrecognized stack adapter or role": "Adaptador de pila no reconocido o papel", + "Unrecognized stack adapter:": "Adaptador de pila no reconocido:", + "Unrecognized stack structure:": "Estructura de pila no reconocida:", + "Unrecognized volume definition": "Definición de volumen no reconocida", + "Unresolved variable:": "Variable sin resolver:", + "Unsafe dependency contract": "Contrato de dependencia en condiciones de seguridad", + "Unsafe dependency hook contract": "Contrato de garantía de dependencia", + "Unsafe instance directory": "Directorio de instancias inseguras", + "Unsafe instance record": "Registro de casos peligrosos", + "Unsafe journal or lock file": "Diario inseguro o archivo de bloqueo", + "Unsafe private configuration path": "Vía de configuración privada insegura", + "Unsafe qBittorrent configuration path": "Vía de configuración segura qBittorrent", + "Unsafe record": "Registro inseguro", + "Unsafe registry directory": "Directorio de registros inseguros", + "Unsafe registry lock": "Cierre de registro inseguro", + "Unsafe rootfs for the capture": "rootfs inseguros para la captura", + "Unsafe stack assembly": "Montaje de pila inseguro", + "Unsafe volume path": "Vía de volumen inseguro", + "Unsupported CPU allocation mode:": "Modo de asignación de CPU no compatible:", + "Unsupported GID strategy:": "Estrategia GID sin apoyo:", + "Unsupported NVIDIA mode:": "Modo NVIDIA sin soporte:", + "Unsupported OCI digest:": "OCI sin soporte digestivo:", + "Unsupported OCI-LXC AppArmor profile:": "Perfil de AppArmor sin soporte:", + "Unsupported OCI-LXC seccomp profile:": "Perfil sin soporte OCI-LXC seccomp:", "Unsupported Terminal": "Terminal no compatible", + "Unsupported architecture:": "Arquitectura sin soporte:", + "Unsupported backup compression": "Compresión de backup sin soporte", + "Unsupported credential pattern:": "Patrón credential sin soporte:", + "Unsupported declarative ostype:": "Ostipo declarativo sin apoyo:", + "Unsupported device GID strategy": "Estrategia GID de dispositivo sin soporte", + "Unsupported device type:": "Tipo de dispositivo sin soporte:", + "Unsupported dynamic NVIDIA capabilities:": "Capacidades dinámicas de NVIDIA sin apoyo:", "Unsupported format. Only .ova and .ovf files are supported.": "Formato no compatible. Sólo se admiten archivos .ova y .ovf.", + "Unsupported media storage mode:": "Modo de almacenamiento multimedia sin soporte:", + "Unsupported mount type": "Tipo de montaje sin soporte", + "Unsupported mount type:": "Tipo de montaje sin soporte:", + "Unsupported native device type:": "Tipo de dispositivo nativo sin soporte:", + "Unsupported operation": "operación sin soporte", "Unsupported output format:": "Formato de salida no admitido:", + "Unsupported post-start configuration:": "Configuración sin soporte post-start:", + "Unsupported pre-start check:": "Comprobación sin soporte previo:", + "Unsupported pre-start repair:": "Reparación sin soporte previo al arranque:", + "Unsupported prlimit resource": "Recursos imprevistos sin apoyo", + "Unsupported secret generator:": "Generador de secretos no admitido:", + "Unsupported storage mode:": "Modo de almacenamiento sin soporte:", + "Unsupported tmpfs options": "Opciones de tmpfs sin soporte", + "Unsupported volume options:": "Opciones de volumen no admitidas:", + "Untrusted or modified NVIDIA hook": "Gancho NVIDIA sin confianza o modificado", + "Unused image removed from the cache:": "Imagen no utilizada extraída del caché:", + "Unused images removed from the cache:": "Imágenes no utilizadas eliminadas del caché:", + "Update": "Actualización", "Update Available": "Actualización disponible", "Update Ceph repository (Only if using Ceph):": "Actualice el repositorio de Ceph (solo si usa Ceph):", "Update Debian repositories to Trixie:": "Actualice los repositorios de Debian a Trixie:", "Update Export": "Actualizar Exportación", "Update Lynis to latest version": "Actualice Lynis a la última versión", "Update NVIDIA in LXC Containers": "Actualizar NVIDIA en contenedores LXC", + "Update OCI": "Actualizar OCI", + "Update OCI stack": "Actualizar la pila OCI", "Update PVE enterprise repository (Only if using enterprise):": "Actualice el repositorio empresarial PVE (solo si usa Enterprise):", "Update Proxmox VE Appliance Manager": "Actualizar Proxmox VE Appliance Manager", "Update Proxmox package lists": "Actualizar las listas de paquetes de Proxmox", @@ -4687,15 +6434,26 @@ "Update and upgrade all system packages": "Actualizar y actualizar todos los paquetes del sistema.", "Update and upgrade system": "Actualizar el sistema", "Update cancelled by user": "Actualización cancelada por el usuario", + "Update completed. Data kept.": "Actualización completada. Datos guardados.", "Update completed. Press Enter to continue...": "Actualización completada. Presione Entrar para continuar...", + "Update every container of the application": "Actualizar cada contenedor de la aplicación", "Update kernel to compatible version": "Actualizar el kernel a una versión compatible", + "Update now?": "¿Actualizar ahora?", "Update package index:": "Actualizar índice del paquete:", + "Update prepared": "Actualización preparada", "Update system to latest PVE 8.4+ (if not done already):": "Actualice el sistema a la última versión de PVE 8.4+ (si aún no lo ha hecho):", + "Update the image with the saved configuration": "Actualizar la imagen con la configuración guardada", + "Update the whole stack?": "¿Actualizar toda la pila?", "Updated": "Actualizado", "Updated sharedfiles group to GID: 101000": "Grupo de archivos compartidos actualizado a GID: 101000", + "Updated stack checked": "Se ha comprobado la pila actualizada", + "Updated:": "Actualizado:", "Updates all Proxmox and Debian packages": "Actualiza todos los paquetes de Proxmox y Debian.", "Updates and Packages Commands": "Comandos de actualizaciones y paquetes", + "Updates are not available yet for this application in this beta": "Aún no hay actualizaciones para esta aplicación en este beta", + "Updates are not available yet in this beta for applications that use a privileged container or advanced LXC settings": "Aún no se dispone de actualizaciones en esta beta para aplicaciones que utilizan un contenedor privilegiado o configuración avanzada LXC", "Updates file is empty or unreadable.": "El archivo de actualizaciones está vacío o es ilegible.", + "Updating": "Actualización", "Updating APT package lists...": "Actualizando listas de paquetes APT...", "Updating Debian Bookworm → Trixie in sources.list...": "Actualizando Debian Bookworm → Trixie en fuentes.list...", "Updating Figurine binary...": "Actualizando el binario de Figurine...", @@ -4727,6 +6485,7 @@ "Upload to PBS is currently: yes. Pick an action:": "Subir a PBS actualmente es: sí. Elige una acción:", "Upload to PBS: enable, disable or rotate the recovery passphrase": "cargar en PBS: habilitar, deshabilitar o rotar la frase de contraseña de recuperación", "Uptime and who is logged in": "Tiempo de actividad y quién ha iniciado sesión", + "Usage:": "Usage:", "Use \"Check test progress\" to see results.": "Utilice \"Verificar el progreso de la prueba\" para ver los resultados.", "Use 'Export to file' to save it and inspect manually.": "Utilice 'Exportar a archivo' para guardarlo e inspeccionarlo manualmente.", "Use 'pct restore' / 'qmrestore' to recover their disks from your VM backups.": "utilice 'pct restaurar' / 'qmrestore' para recuperar sus discos de las copias de seguridad de su VM.", @@ -4769,6 +6528,12 @@ "User activity and uptime": "Actividad del usuario y tiempo de actividad", "User chose not to remove NetworkManager": "El usuario decidió no eliminar NetworkManager", "User chose to exit for manual backup creation.": "El usuario eligió salir para la creación manual de la copia de seguridad.", + "User name for the SSH login": "Nombre de usuario para el login SSH", + "User name of the administrator of the web interface": "Nombre de usuario del administrador de la interfaz web", + "User name of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Nombre de usuario del login de aplicación Flowise deprecado (sólo leído por Flowise versiones antes de 3.0.1)", + "User of the AdGuard Home that receives the settings": "Usuario del AdGuard Home que recibe la configuración", + "User of the main AdGuard Home": "Usuario del AdGuard Home principal", + "User-friendly WebUI for LLMs (Formerly Ollama WebUI)": "WebUI fácil de usar para LLMs (Formerly Ollama WebUI)", "Username": "Nombre de usuario", "Username (e.g. root@pam or user@pbs!token):": "Nombre de usuario (por ejemplo, root@pam o usuario@pbs!token):", "Username and password": "Nombre de usuario y contraseña", @@ -4782,6 +6547,8 @@ "Using advanced configuration": "Usando configuración avanzada", "Using default Proxmox logo...": "Usando el logotipo predeterminado de Proxmox...", "Using existing encryption key:": "Usando la clave de cifrado existente:", + "Using the image verified by the transaction": "Utilizando la imagen verificada por la transacción", + "Using the verified image from the cache": "Utilizando la imagen verificada del cache", "Utilities": "Utilidades", "Utilities Installation Menu": "Menú de instalación de utilidades", "Utilities Menu": "Menú de utilidades", @@ -4789,6 +6556,9 @@ "Utilities and Tools": "Utilidades y herramientas", "Utilities installation completed": "Instalación de utilidades completada", "Utilities installed by ProxMenux have been removed": "Se han eliminado las utilidades instaladas por ProxMenux", + "VA-API driver": "Conductor VA-API", + "VA-API render device": "Dispositivo de renderización VA-API", + "VA-API video acceleration": "VA-API aceleración de vídeo", "VFIO device IDs removed from /etc/modprobe.d/vfio.conf": "ID de dispositivos VFIO eliminados de /etc/modprobe.d/vfio.conf", "VFIO modules configured in /etc/modules": "Módulos VFIO configurados en /etc/modules", "VFIO modules configured.": "Módulos VFIO configurados.", @@ -4796,7 +6566,9 @@ "VFIO modules removed from /etc/modules": "Módulos VFIO eliminados de /etc/modules", "VFIO orphans cleared and initramfs rebuilt — next boot will free the GPU.": "VFIO huérfano eliminado e initramfs reconstruido; el próximo arranque liberará la GPU.", "VFIO orphans cleared but initramfs rebuild failed; check /var/log/proxmenux logs.": "Los huérfanos de VFIO se borraron pero la reconstrucción de initramfs falló;verifique los registros de /var/log/proxmenux.", + "VFS cache mode": "Modo de caché VFS", "VLAN": "VLAN", + "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices.": "VLC Media Player es un reproductor multimedia de código abierto y gratuito que ofrece un rendimiento confiable en múltiples dispositivos.", "VM": "VM", "VM Conflict Policy": "Política de conflictos de máquinas virtuales", "VM ID": "ID de máquina virtual", @@ -4824,17 +6596,28 @@ "VM started": "VM iniciada", "VM stopped": "VM detenida", "VM:": "Máquina virtual:", + "VMID (empty = next free)": "VMID (vacío = siguiente libre)", "VMID in use": "VMID en uso", "VMID must be a number.": "VMID debe ser un número.", "VMID of the Borg server LXC on": "VMID del servidor Borg LXC en", + "VMID of the Rclone OCI container": "VMID del contenedor Rclone OCI", "VMs to destroy:": "VM para destruir:", "VMs, LXCs, network, /etc/pve, users, cron, packages, drivers, ProxMenux state, etc.": "VM, LXC, red, /etc/pve, usuarios, cron, paquetes, controladores, estado de ProxMenux, etc.", + "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server.": "VS Code es un entorno de desarrollo integrado desarrollado por Microsoft. Este contenedor ejecuta la aplicación completa de escritorio, para una versión nativa web ver Code Server.", + "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft’s editor VS Code.": "VSCodium es una distribución binaria impulsada por la comunidad, de libre licencia del editor VS Code de Microsoft.", "Valid backups for all VMs/CTs": "Copias de seguridad válidas para todas las VM/CT", "Validating Proxmox 9 repositories (checking 'proxmox-ve' candidate)...": "Validando repositorios de Proxmox 9 (marcando el candidato 'proxmox-ve')...", "Validating credentials with server": "Validar credenciales con el servidor", "Validating disk safety...": "Validando la seguridad del disco...", + "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)": "Método de validación: http (port 80 reenviado) o dns ( plugin del proveedor DNS)", + "Value for": "Valor para", + "Variable name": "Nombre de la variable", + "Variables": "Variables", + "Variables the installation asks for:": "Variables que pide la instalación:", "Verbose pool status": "Estado detallado del grupo", "Verification": "Verificación", + "Verified": "Verificado", + "Verified by ProxMenux": "Verificado por ProxMenux", "Verify IOMMU group for PCI device": "Verificar el grupo IOMMU para el dispositivo PCI", "Verify Options > OS Type — currently set to:": "Verificar opciones > Tipo de sistema operativo: actualmente configurado en:", "Verify PVE version (must be 8.4.1 or newer):": "Verifique la versión de PVE (debe ser 8.4.1 o más reciente):", @@ -4850,12 +6633,16 @@ "Verifying Ceph packages availability...": "Verificando la disponibilidad de los paquetes de Ceph...", "Verifying all utilities status": "Comprobando el estado de todas las utilidades", "Verifying disk accessibility in CT": "Verificación de la accesibilidad del disco en CT", + "Verifying the backups...": "Verificando los refuerzos...", + "Verifying the image integrity...": "Verificando la integridad de la imagen...", "Version": "Versión", "Version Change Detected": "Cambio de versión detectado", "Version info not available": "Información de versión no disponible", "Version:": "Versión:", "Version: Auto-negotiation (NFSv3/NFSv4)": "Versión: negociación automática (NFSv3/NFSv4)", "Versions shown belong to maintained NVIDIA branches that list your GPU PCI ID and are new enough to build against the running kernel. DKMS compilation is the final validation. The recommended version keeps the current branch, or uses the NVIDIA Production Branch on a fresh install.": "Las versiones mostradas pertenecen a ramas mantenidas de NVIDIA que enumeran su ID PCI de GPU y son lo suficientemente nuevas como para compilarse con el kernel en ejecución. La compilación DKMS es la validación final. La versión recomendada mantiene la rama actual o utiliza la rama de producción de NVIDIA en una instalación nueva.", + "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML.": "La aceleración de vídeo y la detección de objetos son opciones independientes; el instalador no escribe cámara o detector YAML.", + "Video transcoding acceleration": "Aceleración de transcodificación de vídeo", "View CIFS Mounts (pvesm + fstab)": "Ver montajes CIFS (pvesm + fstab)", "View Current Exports": "Ver exportaciones actuales", "View Current Mounts": "Ver montajes actuales", @@ -4871,6 +6658,7 @@ "View raw VM configuration file": "Ver el archivo de configuración de VM sin formato", "View restore plan": "Ver plan de restauración", "View self-test log": "Ver registro de autoprueba", + "View status": "Ver estado", "VirtIO (advanced - high performance)": "VirtIO (avanzado - alto rendimiento)", "VirtIO ISO not found after selection.": "VirtIO ISO no encontrado después de la selección.", "VirtIO ISO selection cancelled.": "Selección VirtIO ISO cancelada.", @@ -4886,10 +6674,19 @@ "Virtual display normalized to vga: std (compatibility)": "Pantalla virtual normalizada a vga: std (compatibilidad)", "Virtual display set to": "Pantalla virtual configurada en", "Virtual interface (normal)": "Interfaz virtual (normal)", + "Virtual whiteboard for sketching hand-drawn like diagrams": "Pizarra virtual para dibujar a mano como diagramas", "Virtualization": "Virtualización", "Visit https://osx-proxmox.com for more information.": "Visite https://osx-proxmox.com para obtener más información.", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:": "Visite el sitio web para descubrir más scripts, mantenerse actualizado con las últimas actualizaciones y respaldar el proyecto:", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE": "Visite el sitio web para descubrir más scripts, mantenerse actualizado con las últimas actualizaciones y respaldar el proyecto:\n\nhttps://community-scripts.github.io/ProxmoxVE", + "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies.": "Vivaldi es un freeware noruego, navegador web multiplataforma con un cliente de correo electrónico integrado desarrollado por Vivaldi Technologies.", + "Volume configuration cancelled": "Configuración de volumen cancelada", + "Volume options are not yet supported": "Todavía no se admiten opciones de volumen", + "Volume size in GB": "Tamaño del volumen en GB", + "Volumes attached": "Volumen adjunto", + "Volumes prepared for the first start:": "Volumen preparado para el primer comienzo:", + "Volumes shared between services are not yet supported": "Todavía no se admiten volúmenes compartidos entre los servicios", + "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code.": "Vscodium-web es una distribución binaria basada en la comunidad, con licencia gratuita del componente web host remoto del editor VS Code de Microsoft.", "Vulnerability detection": "Detección de vulnerabilidades", "WARNING": "ADVERTENCIA", "WARNING — This backup contains paths that are risky to restore on a running system:": "ADVERTENCIA: esta copia de seguridad contiene rutas cuya restauración es riesgosa en un sistema en ejecución:", @@ -4912,15 +6709,40 @@ "WARNING: You are about to remove this Proxmox storage:": "ADVERTENCIA: Está a punto de eliminar este almacenamiento de Proxmox:", "WARNING: You are about to remove this disk mount:": "ADVERTENCIA: Está a punto de quitar este soporte de disco:", "WARNING: this will ERASE EVERYTHING on the disk.": "ADVERTENCIA: esto BORRARÁ TODO lo que hay en el disco.", + "WEB UI to manage WireGuard VPN.": "WEB UI para administrar WireGuard VPN.", "WILL BE PERMANENTLY ERASED.": "SE BORRARÁN PERMANENTEMENTE.", + "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency.": "WPS Office es una suite de oficina amplia y ligera con alta compatibilidad. Como un práctico y profesional software de oficina, WPS Office le permite editar archivos en Writer, Presentation, Spreadsheet y PDF para mejorar su eficiencia de trabajo.", "Wait for each node to complete before starting next": "Espere a que se complete cada nodo antes de comenzar el siguiente", + "Waiting for Home Assistant OS...": "Esperando a Home Assistant OS...", + "Waiting for the FUSE mount:": "Esperando el montaje FUSE:", + "Waiting for the application to respond...": "Esperando que la aplicación responda...", + "Waiting for the initial Jellyfin configuration...": "Esperando la configuración inicial de Jellyfin...", + "Waiting for the network address...": "Esperando la dirección de la red...", + "Waiting for the password of the application...": "Esperando la contraseña de la aplicación...", + "Waiting for the temporary password...": "Esperando la contraseña temporal...", "Warning": "Advertencia", "Warning: Auth key should start with 'tskey-'": "Advertencia: la clave de autenticación debe comenzar con 'tskey-'", "Warning: Disk Images on CIFS": "Advertencia: imágenes de disco en CIFS", "Warning: Limited PCI Reset Support": "Advertencia: soporte limitado para reinicio de PCI", "Warning: both VMs have autostart enabled (onboot=1).": "Advertencia: ambas máquinas virtuales tienen el inicio automático habilitado (onboot=1).", "Warnings": "Advertencias", + "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents.": "WeKnora es un marco impulsado por LLM diseñado para la comprensión profunda de documentos y la recuperación semántica, especialmente para el manejo de complex, documentos heterogéneos.", + "Web UI": "Web UI", + "Web UI 1": "Web UI 1", + "Web UI 2": "Web UI 2", + "Web UI user": "Usuario de la interfaz web", + "Web access": "Acceso web", + "Web address of the AdGuard Home that receives the settings (e.g. http://192.168.1.3)": "Dirección web del AdGuard Home que recibe los ajustes (por ejemplo, http://192.168.1.3)", + "Web address of the main AdGuard Home, whose settings are copied (e.g. http://192.168.1.2)": "Dirección web del AdGuard Home principal, cuyos ajustes se copian (por ejemplo, http://192.168.1.2)", + "Web interface to manage devices running Tasmota firmware.": "Interfaz web para gestionar dispositivos que ejecutan el firmware de Tasmota.", + "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes).": "WebCord se puede resumir como un paquete de endurecimientos de seguridad y privacidad, Discord características reimplementaciones, Electron / Chromium / Discord bugs workarounds, hojas de estilo, páginas internas y envueltas https://discord.com página, diseñado para conformarse con ToS tanto como sea posible (o ocultar los cambios que podrían violarlo de los ojos de Discord).", + "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels.": "Webgrabplus es un multi-sitio incremental xmltv epg grabber. Recopila datos de guía de tv-program de sitios seleccionados de tvguide para sus canales favoritos.", + "Webservers & Proxies": "Webservers " Proxies", "Website": "Sitio web", + "Webstation is a web native emulation focused LXQt desktop based on Ubuntu.": "Webstation es una emulación nativa web centrada en el escritorio LXQt basado en Ubuntu.", + "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser.": "Webtop - Contenedores alpinos, Ubuntu, Fedora y Arch que contienen entornos completos de escritorio en sabores oficialmente compatibles accesibles a través de cualquier navegador web moderno.", + "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent.": "Weixin (WeChat) es una aplicación de mensajería instantánea, redes sociales y pago móvil desarrollada por Tencent.", + "What cannot be translated:": "Lo que no puede traducirse:", "What do you want to do?": "¿Qué es lo que quieres hacer?", "What would you like to do?": "¿Qué te gustaría hacer?", "When asked to select a disk, click Load Driver and load the VirtIO drivers.": "Cuando se le solicite seleccionar un disco, haga clic en Cargar controlador y cargue los controladores VirtIO.", @@ -4932,28 +6754,46 @@ "Where do you want to mount the Samba share?": "¿Dónde quieres montar el recurso compartido Samba?", "Where is the OVA/OVF file located?": "¿Dónde se encuentra el archivo OVA/OVF?", "Where to mount inside container?": "¿Dónde montarlo dentro del contenedor?", + "Where to store": "Dónde almacenar", "While the server allows guest listing, no shares are actually accessible without authentication.": "Si bien el servidor permite la lista de invitados, en realidad no se puede acceder a ningún recurso compartido sin autenticación.", + "Wikijs A modern, lightweight and powerful wiki app built on NodeJS.": "Wikijs Una moderna, ligera y potente aplicación wiki construida en NodeJS.", "Will be configured now": "Se configurará ahora", "Windows Installation Options": "Opciones de instalación de Windows", "Windows path:": "Ruta de Windows:", + "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles.": "WineGUI es un gestor de vino amigable con interfaz de usuario que proporciona un frontend gráfico para crear y gestionar botellas de vino.", "Wipe all — erase partitions + metadata": "Limpiar todo: borrar particiones + metadatos", "Wipe all — remove partitions + metadata": "Limpiar todo: eliminar particiones + metadatos", "Wipe old signatures and partition table (DESTRUCTIVE):": "Limpiar firmas antiguas y tabla de particiones (DESTRUCTIVO):", "Wiping existing partition table...": "Limpiando la tabla de particiones existente...", "Wiping partitions and metadata...": "Limpiando particiones y metadatos...", + "WireGuard Easy web interface": "Interfaz web WireGuard Easy", + "WireGuard® is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry.": "WireGuard® es un VPN extremadamente sencillo pero rápido y moderno que utiliza la criptografía de última generación. Su objetivo es ser más rápido, más simple, más inclinado y más útil que IPsec, evitando al mismo tiempo el dolor de cabeza masivo. Tiene la intención de ser considerablemente más performante que OpenVPN. WireGuard está diseñado como una VPN de propósito general para ejecutar en interfaces incrustadas y super ordenadores por igual, encajan para muchas circunstancias diferentes. Inicialmente lanzado para el kernel de Linux, ahora es multiplataforma (Windows, macOS, BSD, iOS, Android) y ampliamente implementable. Actualmente está en desarrollo pesado, pero ya podría considerarse como la solución VPN más segura, fácil de usar y más simple de la industria.", "Wired NICs in backup missing on target:": "Faltan NIC cableadas en la copia de seguridad en el objetivo:", + "Wireshark is the world’s foremost and widely-used network protocol analyzer. It lets you see what’s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998.": "Wireshark es el analizador de protocolo de red más importante y ampliamente utilizado del mundo. Le permite ver lo que está sucediendo en su red a nivel microscópico y es el estándar de facto (y a menudo de jure) en muchas empresas comerciales y sin fines de lucro, agencias gubernamentales e instituciones educativas. El desarrollo de Wireshark prospera gracias a las contribuciones voluntarias de expertos en redes en todo el mundo y es la continuación de un proyecto iniciado por Gerald Combs en 1998.", + "With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopped.": "Con dns validation, la variable DNSPLUGIN nombra el plugin del proveedor. La instalación avanzada lo pide; de lo contrario, agregue la línea lxc.environment. tiempo de ejecución: DNSPLUGIN= obedeciópluginilo a /etc/pve/lxc/ se hizo referencia aCTID ratio.conf con el contenedor detenido.", + "With dns validation, write the provider credentials in /config/dns-conf/.ini inside the container and restart it.": "Con la validación dns, escriba el proveedor credentials en /config/dns-conf/iereplugin Principe.ini dentro del contenedor y reiniciarlo.", + "With http validation, port 80 of the router must be forwarded to port 80 of this container.": "Con validación http, el puerto 80 del router debe ser enviado al puerto 80 de este contenedor.", "With warnings": "Con advertencias", "Without Function Level Reset (FLR), passthrough is not considered reliable": "Sin reinicio del nivel de función (FLR), el paso a través no se considera confiable", "Without a usable reset path, passthrough reliability is poor and VM": "Sin una ruta de reinicio utilizable, la confiabilidad del paso a través es pobre y la VM", + "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom.": "Wolfenstein: Blade of Agony es un tirador WWII inspirado en Wolfenstein y Doom.", + "Workflow automation tool": "Herramienta de automatización de flujos de trabajo", "Working directory:": "Directorio de trabajo:", "Works with LVM, ZFS, and BTRFS storage types": "Funciona con tipos de almacenamiento LVM, ZFS y BTRFS", + "Worth knowing before installing it:": "Conviene saberlo antes de instalarlo:", "Would you like to continue in passthrough-only mode? The libedgetpu APT install will be skipped, the Coral device will still be visible inside the container (e.g. /dev/apex_0), and you can install the runtime yourself or use an app container that bundles it (e.g. the Frigate Docker image).": "¿Le gustaría continuar en modo de solo paso? Se omitirá la instalación de libedgetpu APT, el dispositivo Coral seguirá siendo visible dentro del contenedor (por ejemplo, /dev/apex_0) y podrá instalar el tiempo de ejecución usted mismo o usar un contenedor de aplicaciones que lo incluya (por ejemplo, la imagen de Frigate Docker).", "Would you like to see the current": "¿Quieres ver la actualidad?", "Write access confirmed for user:": "Acceso de escritura confirmado para el usuario:", "Write access confirmed.": "Acceso de escritura confirmado.", "Write access test FAILED for user:": "La prueba de acceso de escritura FALLÓ para el usuario:", "Write access verified for user:": "Acceso de escritura verificado para el usuario:", + "Write the value it produces instead.": "Escribe el valor que produce en su lugar.", + "Wrong SHA-256 in": "SHA-256 equivocado en", + "Wrong inherited registry lock": "Cierre heredado del registro equivocado", "Wrong passphrase": "frase de contraseña incorrecta", + "Wrong size in": "Tamaño equivocado en", + "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support.": "Xbackbone es un gestor de archivos PHP simple, auto-alojado, ligero que soporta la herramienta de intercambio instantáneo ShareX y *NIX sistemas. Admite la carga y visualización de imágenes, GIF, vídeo, código, texto formateado y descarga y carga de archivos. También tiene una interfaz de usuario web con gestión multiusuario, pasado carga historia y soporte de búsqueda.", + "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS.": "Yaak es un cliente de API de escritorio para organizar y ejecutar solicitudes REST, GraphQL y gRPC. Está construido usando Tauri, Rust y ReactJS.", "Yes": "Sí", "Yes, upload": "Sí, subir", "Yes: set a recovery passphrase now; the encrypted key envelope is uploaded with every backup.": "Sí: establezca una contraseña de recuperación ahora;el sobre de la clave cifrada se carga con cada copia de seguridad.", @@ -4984,6 +6824,9 @@ "You should now be able to access the Proxmox web interface.": "Ahora debería poder acceder a la interfaz web de Proxmox.", "You will need a Tailscale auth key from: https://login.tailscale.com/admin/settings/keys": "Necesitará una clave de autenticación de Tailscale de: https://login.tailscale.com/admin/settings/keys", "Your Coral USB device and its runtime (libedgetpu1) will NOT be affected.": "El dispositivo Coral USB y su entorno de ejecución (libedgetpu1) NO se verán afectados.", + "Your machine learning Env work with Jupyter Lab": "Tu máquina de aprendizaje Env trabaja con Jupyter Lab", + "Your next YouTube media manager": "Su próximo director de medios de YouTube", + "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics.": "Your_spotify es una aplicación autoalojada que rastrea lo que escucha y le ofrece un panel para explorar estadísticas sobre él! Está compuesto por un servidor web que encuesta la API de Spotify de vez en cuando y una aplicación web en la que puede explorar sus estadísticas.", "ZFS ARC config removed (kernel defaults will apply on reboot)": "Se eliminó la configuración de ZFS ARC (los valores predeterminados del kernel se aplicarán al reiniciar)", "ZFS ARC maximum configured:": "ZFS ARC máximo configurado:", "ZFS ARC optimization completed": "Optimización ZFS ARC completada", @@ -5011,9 +6854,17 @@ "ZFS storage added successfully to Proxmox!": "¡Almacenamiento ZFS agregado exitosamente a Proxmox!", "ZFS tools not found. Install zfsutils-linux and retry.": "No se encontraron herramientas ZFS. Instale zfsutils-linux y vuelva a intentarlo.", "ZFS:": "ZFS:", + "ZNC web interface": "Interfaz web ZNC", + "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design.": "Zen Browser es un fork gratuito y de código abierto de Mozilla Firefox con un enfoque en privacidad, personalizabilidad y diseño.", "Zero all data — partition table preserved, data wiped": "Cero todos los datos: tabla de particiones preservada, datos borrados", "Zero all data — partition table preserved": "Cero todos los datos: se conserva la tabla de particiones", "Zeroing partition": "Partición de puesta a cero", + "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC.": "Znc es un rebote de red IRC o BNC. Puede separar al cliente del servidor IRC real, y también de canales seleccionados. Múltiples clientes de diferentes ubicaciones pueden conectarse a una sola cuenta ZNC simultáneamente y por lo tanto aparecen bajo el mismo apodo en IRC.", + "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research.": "Zotero es una herramienta gratuita, fácil de usar para ayudarle a recoger, organizar, anotar, citar y compartir la investigación.", + "a device it asks for cannot be translated:": "un dispositivo que solicita no se puede traducir:", + "a value is required": "se necesita un valor", + "aMule WebUI (password only, no username)": "aMule WebUI (sólo contraseña, sin nombre de usuario)", + "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule.": "aMule es un cliente multiplataforma para la red de intercambio de archivos ED2K y basado en el eMule cliente de ventanas. aMule comenzó en agosto de 2003, como un fork de xMule, que es un fork de lMule.", "active VF(s)": "FV activas", "active VFs": "FV activas", "active Virtual Functions. Changing its driver binding would destroy every VF.": "Funciones virtuales activas. Cambiar la vinculación del controlador destruiría todos los VF.", @@ -5035,20 +6886,24 @@ "apex group still has members; left in place:": "el grupo principal todavía tiene miembros; dejado en su lugar:", "apex kernel module not loaded on host. Run \"Install Coral on Host\" first or the container will not see /dev/apex_0.": "El módulo del kernel de Apex no está cargado en el host. Primero ejecute \"Instalar Coral en el host\" o el contenedor no verá /dev/apex_0.", "appears to be part of a": "parece ser parte de un", + "apply requires the OCI archive of the resolved image": "aplicar requiere el archivo OCI de la imagen resuelta", "applying minimal banner patch": "aplicando un parche de banner mínimo", "apt cache refreshed.": "caché apto actualizado.", "apt-get exited": "apt-salir", "apt-get update returned warnings. Continuing anyway; check": "apt-get update devolvió advertencias. Continuando de todos modos; controlar", "as": "como", + "assembling": "ensamblando", "automatically. Install it manually inside the container.": "automáticamente. Instálelo manualmente dentro del contenedor.", "automatically. Reboot LXC to fully release.": "automáticamente. Reinicie LXC para liberarlo por completo.", "available for LXC bind-mounts via 'LXC Mount Manager'": "disponible para montajes de enlace LXC a través de 'LXC Mount Manager'", "available in this same GPU and TPU menu.": "disponible en este mismo menú de GPU y TPU.", "backup at /etc/fstab.proxmenux.bak": "copia de seguridad en /etc/fstab.proxmenux.bak", "ban": "prohibición", + "belongs to another OCI installation": "pertenece a otra instalación OCI", "blocking issue(s).": "problema(s) de bloqueo.", "btrfs — Proxmox dir storage (snapshots, compression)": "btrfs: almacenamiento de directorios de Proxmox (instantáneas, compresión)", "btrfs — snapshots and compression": "btrfs: instantáneas y compresión", + "budge is an open source 'budgeting with envelopes' personal finance app.": "budge es una aplicación de financiación personal de código abierto 'budgeting con sobres'.", "builds against kernel": "se construye contra el kernel", "but it does not match the one used to create the backup. Replace it with the correct keyfile from the source host and retry.": "pero no coincide con el utilizado para crear la copia de seguridad. Reemplácelo con el archivo de claves correcto del host de origen y vuelva a intentarlo.", "bytes": "bytes", @@ -5056,29 +6911,52 @@ "chmod 1777 + setfacl o::rwx (applied on the NFS share from this host)": "chmod 1777 + setfacl o::rwx (aplicado en el recurso compartido NFS de este host)", "chmod failed — NFS server may be restricting changes from root": "chmod falló: el servidor NFS puede estar restringiendo los cambios desde la raíz", "chown/chmod failed — likely unprivileged CT against host bind mount. Falling back to ACL.": "chown/chmod falló: probablemente CT sin privilegios contra el montaje de enlace del host. Regresando a ACL.", + "containers": "contenedores", + "containers of": "contenedores de", "content:": "contenido:", + "copyparty web interface": "Interfaz web copyparty", "could not be compiled for kernel": "no se pudo compilar para el kernel", + "could not validate NVIDIA; exit code": "no puede validar NVIDIA; código de salida", + "cpuunits must be between 8 and 10000": "cpuunits debe ser entre 8 y 10000", + "custom": "personalizado", + "custom dependency commands are not yet supported": "los comandos de dependencia personalizados todavía no son compatibles", + "custom path(s) saved.": "rutas personalizadas guardadas.", + "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them.": "darktable es una aplicación de flujo de trabajo de fotografía de código abierto y desarrollador bruto. Un faro virtual y un cuarto oscuro para fotógrafos. Gestiona sus negativos digitales en una base de datos, permite visualizarlos a través de un faro zoomable y le permite desarrollar imágenes crudas y mejorarlas.", + "ddclient starts with the example configuration and updates nothing yet. Write your provider, login and domains in /config/ddclient.conf inside the container, then restart it.": "ddclient comienza con la configuración de ejemplo y no actualiza nada todavía. Escriba su proveedor, login y dominios en /config/ddclient.conf dentro del contenedor, luego reiniciarlo.", "default": "por defecto", "delete the credentials file (if any)": "eliminar el archivo de credenciales (si corresponde)", "delete the matching line from /etc/fstab": "elimine la línea coincidente de /etc/fstab", "descriptor + VMDK files": "descriptor + archivos VMDK", + "device(s) added to VM": "Dispositivo(s) agregado(s) a la VM", "devices": "dispositivos", + "devices (dynamic runtime)": "dispositivos (tiempo de ejecución dinamico)", "did not become ready. Skipping.": "no estuvo listo. Salto a la comba.", + "digiKam: Professional Photo Management with the Power of Open Source": "digiKam: Gestión de fotos profesionales con el poder de código abierto", "disk(s) added to CT": "disco(s) agregado(s) a CT", "disk(s) added to VM": "discos agregados a la VM", + "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems.": "diskover es un indexador de sistema de archivos de código abierto que utiliza Elasticsearch para indexar y gestionar datos a través de sistemas de almacenamiento heterogéneo.", "disks present": "discos presentes", "dkms autoinstall did not activate:": "la instalación automática de dkms no se activó:", "dkms.conf generated.": "dkms.conf generado.", + "docker run command": "comando docker run", + "docker run command of the application": "comando docker run de la aplicación", "does not exist on this host. Path not added.": "no existe en este host. Ruta no agregada.", "does not exist. Exiting.": "no existe. Saliendo.", + "doplarr_rs starts from the example configuration and connects to nothing. Write the token of your Discord bot in discord_token in /config/config.toml inside the container.": "doplarr_rs comienza desde la configuración de ejemplo y se conecta a nada. Escribe la ficha de tu bot Discord token en /config/config.toml dentro del contenedor.", + "downloaded Compose file": "archivo Compose descargado", "dpkg still reports unfinished package work; review": "dpkg todavía informa de tareas de paquetes sin finalizar; revise", + "driver components": "componentes del controlador", "driver:": "controlador:", + "e.g.": "por ejemplo", + "empty = generate": "vacío = generar", "exFAT (portable: Windows/Linux/macOS)": "exFAT (portátil: Windows/Linux/macOS)", "exFAT tools installed successfully.": "Herramientas exFAT instaladas correctamente.", "ext4 — Proxmox dir storage (recommended)": "ext4 — Almacenamiento de directorios de Proxmox (recomendado)", "ext4 — recommended, most compatible": "ext4: recomendado, más compatible", "fail2ban-client could not communicate with the server": "El cliente fail2ban no pudo comunicarse con el servidor.", "fail2ban-client successfully communicated with the server": "El cliente fail2ban se comunicó exitosamente con el servidor.", + "failed": "fallido", + "failed with exit code": "falló con código de salida", "failed:": "fallido:", "feranick fork unreachable. Falling back to google/gasket-driver...": "No se puede acceder al fork de feranick. Se usará google/gasket-driver como alternativa...", "feranick/gasket-driver cloned (actively maintained, kernel 6.12+ ready).": "feranick/gasket-driver clonado (mantenido activamente, kernel 6.12+ listo).", @@ -5092,6 +6970,7 @@ "for this policy and may fail after first use or on subsequent VM starts.": "para esta política y puede fallar después del primer uso o en inicios posteriores de la máquina virtual.", "formatted as": "formateado como", "found": "encontró", + "free": "libre", "from Proxmox web interface (you will be asked)": "desde la interfaz web de Proxmox (se le preguntará)", "from container": "del contenedor", "from the GPUs and Coral-TPU menu first, then run this option again.": "Primero desde el menú GPU y Coral-TPU, luego ejecute esta opción nuevamente.", @@ -5109,10 +6988,14 @@ "has a different MAC than the backup — update any DHCP static reservation": "tiene una MAC diferente a la de la copia de seguridad: actualice cualquier reserva estática de DHCP", "has a new MAC": "tiene una nueva MAC", "has only": "solo tiene", + "health and persistence profile not yet defined": "perfil de salud y persistencia aún no definido", + "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers.": "HiSHtory es una mejor historia de shell. Almacena su historia de la concha en contexto (cual directorio se ejecutó el comando, ya sea sucedió o falló, cuánto tiempo tomó, etc.). Todo esto está almacenado localmente y encriptado de extremo a extremo para sincronizar a todos los demás ordenadores.", + "host directory": "directorio host", "host fstab only (not registered as Proxmox storage)": "host fstab solamente (no registrado como almacenamiento en Proxmox)", "hostpci entries for all IOMMU group devices": "entradas hostpci para todos los dispositivos del grupo IOMMU", "hostpci entries for selected GPU functions (full IOMMU group will be enforced after reboot)": "Entradas de hostpci para funciones de GPU seleccionadas (el grupo IOMMU completo se aplicará después del reinicio)", "hour(s)": "horas)", + "https if the image serves TLS": "https si la imagen sirve TLS", "iSCSI Content Type": "Tipo de contenido iSCSI", "iSCSI Daemon (iscsid): RUNNING": "Demonio iSCSI (iscsid): EN EJECUCIÓN", "iSCSI Daemon (iscsid): STOPPED": "Demonio iSCSI (iscsid): DETENIDO", @@ -5129,16 +7012,22 @@ "iSCSI storage provides raw block devices for VM disk images.": "El almacenamiento iSCSI proporciona dispositivos de bloques sin formato para imágenes de disco de VM.", "iSCSI tools installed": "Herramientas iSCSI instaladas", "iftop usage": "uso de iftop", + "image cache on": "caché de imágenes en", + "image itself": "la propia imagen", "imported:": "importado:", "in CT": "en TC", + "in backups": "en backups", + "individual template is blocked": "la plantilla individual está bloqueada", "initramfs updated": "initramfs actualizado", "initramfs updated.": "initramfs actualizado.", + "installed": "instalado", "installed but command not immediately available": "instalado pero el comando no está disponible inmediatamente", "installed correctly and available": "instalado correctamente y disponible", "installed in CT": "instalado en TC", "installed inside CT": "instalado dentro de CT", "installed successfully.": "instalado exitosamente.", "installed.": "instalado.", + "installing": "instalando", "intel-gpu-tools installed successfully": "Intel-gpu-tools instalado correctamente", "intel-gpu-tools is already installed:": "Intel-gpu-tools ya está instalado:", "intel-gpu-tools is up to date": "Intel-gpu-tools está actualizado", @@ -5169,7 +7058,11 @@ "is not configured as machine type q35.": "no está configurado como tipo de máquina q35.", "is not in the patch.sh supported list. The patch may no-op or fail; review keylase/nvidia-patch README before continuing.": "no está en la lista compatible con patch.sh. Es posible que el parche no funcione o falle; revise el archivo README de keylase/nvidia-patch antes de continuar.", "is not supported by the official Google libedgetpu APT repository.": "no es compatible con el repositorio oficial de Google libedgetpu APT.", + "is one of the": "es uno de los", "is referenced in the following stopped VM(s)/CT(s):": "se hace referencia en las siguientes VM/CT detenidas:", + "it asks for the network of the host; the container gets its own address instead": "pide la red del host; el contenedor obtiene su propia dirección en su lugar", + "it publishes no other architecture": "no publica ninguna otra arquitectura", + "it uses the Compose option": "utiliza la opción Compose", "journald MaxLevelStore is adequate for auth logging": "journald MaxLevelStore es adecuado para el registro de autenticación", "journald drop-in created: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf": "drop-in de diario creado: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf", "journald log level restored": "Nivel de registro de journald restaurado", @@ -5193,26 +7086,41 @@ "kexec-tools installed successfully": "kexec-tools instalado correctamente", "kexec-tools is already installed": "kexec-tools ya está instalado", "kexec-tools is not installed or already removed.": "kexec-tools no está instalado o ya se ha eliminado.", + "layers": "capas", "legacy .link file(s) to the ProxMenux-managed format": "archivos .link heredados al formato administrado por ProxMenux", "log2ram completely removed from system": "log2ram completamente eliminado del sistema", "manually inside the container before starting it.": "manualmente dentro del contenedor antes de ponerlo en marcha.", "manually inside the container.": "manualmente dentro del contenedor.", "maximum performance": "máximo rendimiento", "may be closed — trying discovery anyway...": "puede estar cerrado; intentando el descubrimiento de todos modos...", + "melonDS aims at providing fast and accurate Nintendo DS emulation.": "melonDS pretende proporcionar una emulación rápida y accurate Nintendo DS.", + "members:": "miembros:", + "minimum": "mínimo", "missing": "desaparecido", "mkfs.btrfs not found. Install btrfs-progs and retry.": "mkfs.btrfs no encontrado. Instale btrfs-progs y vuelva a intentarlo.", "more": "más", + "motionEye web interface": "Interfaz web motionEye", "mount.cifs command not found after installation.": "El comando mount.cifs no se encuentra después de la instalación.", "mount.nfs command not found after installation.": "El comando mount.nfs no se encuentra después de la instalación.", + "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone.": "mstream es un servidor de streaming de música personal. Puede utilizar mStream para transmitir su música desde el ordenador de su casa a cualquier dispositivo, en cualquier lugar. Hay aplicaciones móviles disponibles para Android y iPhone.", + "must contain a valid numeric UID for the GPU": "debe contener un UID numérico válido para la GPU", + "needed": "necesario", + "needs a privileged LXC": "necesita un LXC privilegiado", + "needs a relaxed AppArmor or seccomp profile": "necesita un perfil de AppArmor o seccomp relajado", + "needs stack review": "necesita revisión de pila", "never": "nunca", + "next free": "siguiente libre", + "next free block": "siguiente bloque libre", "nftables not available - using iptables ban action": "nftables no disponible - usando la acción de prohibición de iptables", "no": "no", "no (kdf=none, not needed)": "no (kdf=ninguno, no es necesario)", "no (no escrow blob — set a recovery passphrase to enable recovery)": "no (sin blob de depósito en garantía: establezca una frase de contraseña de recuperación para habilitar la recuperación)", + "no declarative value": "sin valor declarativo", "no passphrase": "sin frase de contraseña", "no password": "sin contraseña", "no_root_squash": "no_root_squash", "non-ProxMenux .tar archive(s) in this path": "archivo(s) .tar que no son de ProxMenux en esta ruta", + "not available yet": "aún no disponible", "not found.": "extraviado.", "not installed": "no instalado", "not reliable on this hardware due to the following limitations": "No es confiable en este hardware debido a las siguientes limitaciones.", @@ -5229,27 +7137,39 @@ "of free disk space.": "de espacio libre en disco.", "older firmware may increase passthrough instability": "el firmware más antiguo puede aumentar la inestabilidad del paso", "oldest driver offered:": "controlador más antiguo ofrecido:", + "on": "en", "on SSD/NVMe pools that support discard": "en grupos de SSD/NVMe que admiten descarte", + "one of its services declares no image": "uno de sus servicios no declara imagen", + "one of its services is not written as a service": "uno de sus servicios no está escrito como servicio", "openssl encryption failed.": "falló el cifrado de openssl.", "openssl is not installed — cannot create recovery copy. Install openssl and retry.": "openssl no está instalado; no se puede crear una copia de recuperación. Instale openssl y vuelva a intentarlo.", + "optional": "opcional", + "optional dependencies are not yet supported": "las dependencias opcionales aún no se admiten", "or format it manually using external tools.": "o formatéelo manualmente utilizando herramientas externas.", + "or none": "o ninguno", "or use the ProxMenux LXC Mount Manager.": "o utilice el Administrador de montaje ProxMenux LXC.", "orphan iface lines, no impact on restore": "líneas de iface huérfanas, sin impacto en la restauración", "other .tar archive(s) — not ProxMenux host backups (e.g. PVE vzdump or unrelated tarballs).": "otros archivos .tar, no copias de seguridad del host ProxMenux (por ejemplo, PVE vzdump o archivos tar no relacionados).", "packages (this may take a few minutes)...": "paquetes (esto puede tardar unos minutos)...", + "packages.": "paquetes.", "parent PF:": "padre PF:", "partition(s). Partition table preserved.": "partición(es). Se conserva la tabla de particiones.", + "pasted Compose file": "archivo Compose pegado", "paths for next boot (/etc/pve, guests, drivers, ...)": "rutas para el próximo arranque (/etc/pve, invitados, controladores, ...)", "pct exec authorization failed": "error en la autorización ejecutiva de PCT", "pct push failed. Check log:": "Error al enviar el PCT. Registro de verificación:", "pending (reboot required to enumerate full group)": "pendiente (es necesario reiniciar para enumerar el grupo completo)", + "phpMyAdmin is installed with arbitrary server connections enabled: the login page has a Server field where the address of the MySQL or MariaDB server is entered, together with its user and password.": "phpMyAdmin se instala con conexiones de servidor arbitrarias habilitadas: la página de inicio de sesión tiene un campo Server donde se introduce la dirección del servidor MySQL o MariaDB, junto con su usuario y contraseña.", "pigz configuration completed": "configuración de pigz completada", "pigz enabled in vzdump configuration": "pigz habilitado en la configuración de vzdump", "pigz installed successfully": "pigz instalado exitosamente", "pigz removed": "cerdo eliminado", "pigz wrapper script created": "script contenedor pigz creado", + "playit.gg has to claim this agent before it forwards anything. The agent prints a one-time claim link on the container console and keeps it there until the link is opened.": "playit.gg tiene que reclamar a este agente antes de que avance cualquier cosa. El agente imprime un enlace de reclamación de una sola vez en la consola de contenedores y lo mantiene allí hasta que se abra el enlace.", "port": "puerto", "portmapper/rpcbind has been disabled": "portmapper/rpcbind ha sido deshabilitado", + "private network assigned automatically": "red privada asignada automáticamente", + "privileged LXC": "LXC privilegiado", "proxmox-backup-client reported:": "proxmox-backup-client informó:", "proxmox-boot-tool refreshed": "herramienta de arranque proxmox actualizada", "pve-enterprise.list update skipped (no change)": "Actualización de pve-enterprise.list omitida (sin cambios)", @@ -5261,10 +7181,22 @@ "pvesm not found.": "pvesm no encontrado.", "pvesm path failed, trying manual detection...": "La ruta pvesm falló, intentando la detección manual...", "pvesm status failed": "el estado de pvesm falló", + "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web.": "pyLoad es un gestor de descargas Free and Open Source escrito en Python y diseñado para ser extremadamente ligero, fácilmente extensible y totalmente manejable a través de web.", + "pyLoad web interface": "interfaz web de pyLoad", + "qBittorrent WebUI password (user: admin)": "contraseña de qBittorrent WebUI (usuario: admin)", + "qBittorrent already has a configuration; it is not overwritten": "qBittorrent ya tiene una configuración; no está sobrescrito", + "qBittorrent configured": "qBittorrent configurado", + "qBittorrent did not apply the category:": "qBittorrent no aplicó la categoría:", + "qBittorrent did not apply the download paths": "qBittorrent no aplica las rutas de descarga", + "qBittorrent requires a non-empty password": "qBittorrent requiere una contraseña no vacía", + "qBittorrent: authenticated access to the preferences could not be verified": "qBittorrent: no se puede verificar el acceso autenticado a las preferencias", + "qBittorrent: invalid login response or missing session cookie": "qBittorrent: respuesta de inicio de sesión inválida o cookie de sesión perdida", "raw USB disk — no filesystem (will be FORMATTED)": "disco USB sin formato: sin sistema de archivos (se FORMATEARÁ)", + "read-only": "solo lectura", "reboot-quick alias added": "alias de reinicio rápido agregado", "reboot-quick alias is already configured": "el alias de reinicio rápido ya está configurado", "recommended": "recomendado", + "recovering": "recuperando", "remapped users": "usuarios reasignados", "remove the (now-empty) directory if possible": "elimine el directorio (ahora vacío) si es posible", "removed from Proxmox": "eliminado de Proxmox", @@ -5280,11 +7212,14 @@ "rpcbind could not be disabled completely": "rpcbind no se pudo desactivar por completo", "rpcbind service and socket have been disabled and stopped": "el servicio rpcbind y el socket han sido deshabilitados y detenidos", "rpcbind units were not found; no changes were made": "no se encontraron unidades rpcbind;no se hicieron cambios", + "rsnapshot starts with the default configuration, which backs up /data into /.snapshots. Edit /config/rsnapshot.conf inside the container to set your own backup points, snapshot root and retention intervals.": "rsnapshot comienza con la configuración predeterminada, que respalda /data en /.snapshots. Editar /config/rsnapshot.conf dentro del contenedor para establecer sus propios puntos de backup, raíz instantánea y intervalos de retención.", "running": "correr", + "runs in": "se ejecuta en", "safe paths now (configs, packages, /etc, /root, ...)": "rutas seguras ahora (configuraciones, paquetes, /etc, /root, ...)", "same MAC": "misma MAC", "seconds (default)": "segundos (predeterminado)", "see log:": "ver registro:", + "selected by default": "seleccionado por defecto", "selected path(s):": "ruta(s) seleccionada(s):", "server": "servidor", "server IP or hostname:": "IP del servidor o nombre de host:", @@ -5292,6 +7227,7 @@ "servers found on the network.": "servidores encontrados en la red.", "servers found.": "servidores encontrados.", "sha256sum not found. Cannot verify Borg binary.": "sha256sum no encontrado. No se puede verificar el binario Borg.", + "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++.": "shadPS4 es un emulador de PlayStation 4 temprano para Windows, Linux y macOS escrito en C++.", "showmount command is not working properly.": "El comando showmount no funciona correctamente.", "showmount command not found after installation.": "El comando showmount no se encuentra después de la instalación.", "single portable archive": "archivo portátil único", @@ -5307,6 +7243,7 @@ "started successfully.": "comenzó exitosamente.", "started.": "comenzó.", "startup/restart errors are likely.": "Es probable que se produzcan errores de inicio/reinicio.", + "staticfiles volume size in GB": "tamaño del volumen de los ficheros estáticos en GB", "stop source VM first": "detener la VM de origen primero", "stopped": "interrumpido", "storage yet.": "almacenamiento todavía.", @@ -5316,9 +7253,16 @@ "suggested:": "sugerido:", "switch_gpu_mode.sh was not found.": "No se encontró switch_gpu_mode.sh.", "sysfs ROM dump failed — trying ACPI VFCT table...": "Error en el volcado de ROM de sysfs: al intentar la tabla ACPI VFCT...", + "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools.": "syslog-ng le permite recoger flexiblemente, parse, clasificar, reescribir y correlacionar los registros de toda su infraestructura y almacenar o encaminarlos a herramientas de análisis de registros.", "systemctl restart networking failed:": "El reinicio de red systemctl falló:", "systemd OnCalendar expression": "expresión systemd OnCalendar", + "the API key was not generated on the first start": "la clave de API no se generó en el primer comienzo", + "the container has its own address, so the port Docker published on the host is not needed": "el contenedor tiene su propia dirección, por lo que el puerto Docker publicado en el host no es necesario", + "the qBittorrent schema is not available": "el esquema qBittorrent no está disponible", + "this configuration needs the device": "esta configuración necesita el dispositivo", "this distribution": "esta distribución", + "tmpfs size in MB for": "tamaño de tmpfs en MB para", + "tmpfs size too small for": "tamaño de tmpfs demasiado pequeño para", "to": "a", "to CT": "a TC", "to VM": "a la máquina virtual", @@ -5327,6 +7271,12 @@ "to sharedfiles group": "al grupo de archivos compartidos", "total": "total", "umount the path if currently mounted": "desmontar la ruta si actualmente está montada", + "unprivileged LXC": "LXC sin privilegios", + "unsupported credential generator": "generador de credenciales no admitido", + "unsupported dependency condition": "condición de dependencia no admitida", + "unsupported external credential or boolean": "credencial externa o booleano no admitidos", + "unsupported variable": "variable no admitida", + "updating": "actualizando", "updating NVIDIA userspace libs": "actualizando las bibliotecas del espacio de usuario de NVIDIA", "user packages missing — will be installed automatically:": "faltan paquetes de usuario; se instalarán automáticamente:", "users": "usuarios", @@ -5337,12 +7287,19 @@ "vfio-pci IDs configured": "ID de vfio-pci configurados", "vfio-pci IDs in /etc/modprobe.d/vfio.conf": "ID de vfio-pci en /etc/modprobe.d/vfio.conf", "vzdump backup speed optimization completed": "Optimización de la velocidad de copia de seguridad de vzdump completada", + "wallabag builds its links from the address given during the installation. If it does not match the address of the container, edit lxc.environment.runtime: SYMFONY__ENV__DOMAIN_NAME in /etc/pve/lxc/.conf with the container stopped, and start it again.": "wallabag construye sus enlaces desde la dirección dada durante la instalación. Si no coincide con la dirección del contenedor, edite lxc.environment. tiempo de ejecución: SYMFONY DOMAIN NAME en /etc/pve/lxc/ se hizo referencia aCTID ratio.conf con el contenedor parado, y comenzar de nuevo.", + "wallabag listens on port 80 of the container and stores its data in SQLite.": "wallabag escucha en el puerto 80 del contenedor y almacena sus datos en SQLite.", + "wallabag web interface": "Interfaz web wallabag", "was": "era", "was installed, but the kernel reports:": "se instaló, pero el kernel informa:", + "when finished": "al terminar", "will rebind the GPU to vfio-pci on the next reboot, breaking the driver that is about to be installed.": "volverá a vincular la GPU a vfio-pci en el próximo reinicio, rompiendo el controlador que está a punto de instalarse.", "wipefs failed on": "los borrados fallaron", "with": "con", + "with Proxmox": "con Proxmox", + "with prefix, e.g.": "con prefijo, por ejemplo", "with the password you provided.": "con la contraseña que proporcionaste.", + "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems.": "xemu es una aplicación gratuita y de código abierto que emula la consola original de juego Microsoft Xbox, permitiendo a la gente jugar sus juegos originales de Xbox en sistemas Windows, macOS y Linux.", "xfs — Proxmox dir storage (large files and VMs)": "xfs: almacenamiento de directorios de Proxmox (archivos grandes y máquinas virtuales)", "xfs — better for large files": "xfs: mejor para archivos grandes", "years old": "años", diff --git a/lang/fr.json b/lang/fr.json index 421accce..942e1a77 100644 --- a/lang/fr.json +++ b/lang/fr.json @@ -7,6 +7,7 @@ "(common default on Debian/LXC: PermitRootLogin prohibit-password).": "(par défaut courant sur Debian/LXC : PermitRootLogin prohibit-password).", "(disabled)": "(désactivé)", "(e.g.": "(par ex.", + "(empty)": "(vide)", "(for unprivileged LXCs)": "(pour les LXC non privilégiés)", "(if only privileged LXCs need write access)": "(si seuls les LXC privilégiés ont besoin d'un accès en écriture)", "(make.log not found — DKMS may have failed before invoking make)": "(make.log introuvable — DKMS a peut-être échoué avant d'invoquer make)", @@ -19,6 +20,7 @@ "(recommended)": "(recommandé)", "(same MAC — restored config adjusted automatically)": "(même MAC – config restaurée ajustée automatiquement)", ")": ")", + "*Arr Suite": "*Arr Suite", "+ Add a path": "+ Ajouter un chemin", "+ Add new Borg target": "+ Ajouter une nouvelle cible Borg", "+ Add new PBS manually": "+ Ajouter un nouveau PBS manuellement", @@ -35,39 +37,102 @@ "/var/lib/vz/dump (Proxmox default)": "/var/lib/vz/dump (Proxmox par défaut)", "1777 = sticky bit + rwx for all. No shared group needed.": "1777 = bit collant + rwx pour tous. Aucun groupe partagé n’est nécessaire.", "====== PVE UPDATE COMPLETED ======": "====== MISE À JOUR PVE TERMINÉE ======", + "A GTK Broadway web UI for libvirt and virt-manager.": "Une interface web GTK Broadway pour libvirt et virt-manager.", + "A Personal Relationship Management tool to help you document your social life.": "Une relation personnelle Outil de gestion pour vous aider à documenter votre vie sociale.", "A VirtIO ISO already exists. Do you want to overwrite it?": "Un ISO VirtIO existe déjà. Voulez-vous l'écraser ?", "A ZFS pool with this name already exists.": "Un pool ZFS portant ce nom existe déjà.", "A ZFS pool with this name already exists:": "Un pool ZFS portant ce nom existe déjà :", + "A backup was modified": "Une sauvegarde a été modifiée", + "A command did not finish in time:": "Une commande n'a pas fini à temps :", "A complete restore will:": "Une restauration complète :", + "A concurrent change was detected; the container is not removed": "Un changement simultané a été détecté; le contenant n'est pas enlevé", + "A container mount has a source, backup or permission different from the saved record": "Un support conteneur a une source, une sauvegarde ou une permission différente de l'enregistrement enregistré", + "A coordinated operation is pending. The whole previous stack will be recovered, not only the selected member. If the operation already finished, the cleanup of its markers is completed.": "Une intervention coordonnée opera est en cours. Toute la pile précédente sera récupérée, pas seulement le membre sélectionné. Si la operation déjà terminée, le nettoyage de ses marqueurs est terminé.", + "A different host monitor include already exists; it is not overwritten:": "Un moniteur hôte différent inclut déjà existe; il n'est pas écrasé:", + "A fancy monitoring tool": "Un outil de surveillance sophistiqué", + "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata.": "Un programme de base de données libre et open-source axé sur les documents. Classée comme un programme de base de données NoSQL, MongoDB utilise des documents JSON avec des schémas.", + "A free reverse proxy for tunneling services (not self-hosted).": "Un proxy inverse gratuit pour les services de tunnelage (pas auto-organisé).", + "A free, self-hostable news aggregator…": "Un agrégateur de nouvelles libre et autonome...", + "A full-featured, open-source AI chat interface": "Une interface de chat d'IA entièrement adaptée et open-source", "A gasket DKMS registration is still present:": "Un enregistrement DKMS de gasket est toujours présent :", + "A host bind mount cannot be included in vzdump": "Une fixation hôte ne peut pas être incluse dans vzdump", + "A host mount is not part of the journal; recovery blocked": "Un support hôte ne fait pas partie du journal; récupération bloquée", "A host reboot is required after this change.": "Un redémarrage de l'hôte est requis après cette modification.", "A host reboot is required before starting the VM. Reboot now?": "Un redémarrage de l'hôte est requis avant de démarrer la VM. Redémarrer maintenant ?", "A job with this ID already exists.": "Une tâche avec cet ID existe déjà.", + "A journal already exists; review or recover it before trying again": "Un journal existe déjà; examiner ou récupérer avant d'essayer de nouveau", "A keyfile is installed at:": "Un fichier de clés est installé à :", "A legacy gasket-dkms package was found on this host, but no Coral M.2 / PCIe hardware is present.": "Un ancien paquet gasket-dkms a été trouvé sur cet hôte, mais aucun matériel Coral M.2/PCIe n'est présent.", + "A managed rootfs and an unprivileged container are required": "Un rootf géré et un conteneur non privilégié sont required", + "A managed volume with backup enabled is required": "Un volume géré avec sauvegarde activée est required", + "A member VMID is in use by another guest or is on another node": "Un membre VMID est utilisé par un autre invité ou est sur un autre noeud", + "A member configuration changed after the stack was checked": "Une configuration de membre a été modifiée après vérification de la pile", + "A member configuration changed during the preparation": "Une configuration de membre a changé pendant la préparation", + "A member did not pass its service check:": "Un membre n'a pas réussi sa vérification de service :", + "A member has a pending operation": "Un membre a une operation en attente", + "A member has no reproducible service check": "Un membre n'a pas de contrôle de service reproductible", + "A member is missing before the replacement": "Un membre est absent avant le remplacement", + "A member operation does not belong to the stack": "Un membre operation n'appartient pas à la pile", + "A member stopped:": "Un membre s'est arrêté :", + "A member was modified after it was recovered": "Un membre a été modifié après sa récupération", + "A modern wiki and knowledge base for teams": "Un wiki moderne et une base de connaissances pour les équipes", "A new ProxMenux version is available:": "Une nouvelle version de ProxMenux est disponible :", "A new kernel is staged for the next boot:": "Un nouveau noyau est préparé pour le prochain démarrage :", "A newer version is available:": "Une version plus récente est disponible :", + "A pending operation exists for": "Un opera en attente existe pour", + "A pending stack assembly already exists; it is not overwritten": "Une pile en attente existe déjà; elle n'est pas écrasée", + "A previous NVIDIA refresh is pending review": "Une mise à jour antérieure de la NVIDIA est en attente d'examen", "A previous VFIO passthrough configuration was detected for the following NVIDIA GPU(s):": "Une configuration de relais VFIO précédente a été détectée pour le(s) GPU NVIDIA suivant :", + "A privacy-first, open-source platform for knowledge management and collaboration.": "Une plate-forme de gestion et de collaboration des connaissances ouverte et axée sur la protection de la vie privée.", "A reboot is recommended before the GPU is guaranteed to stay on the native driver.": "Un redémarrage est recommandé avant que le GPU ne soit assuré de rester sur le pilote natif.", "A reboot is required after installation to load the new kernel modules.": "Un redémarrage est requis après l'installation pour charger les nouveaux modules du noyau.", "A reboot is required for VFIO binding to take effect. Do you want to restart now?": "Un redémarrage est requis pour que la liaison VFIO prenne effet. Voulez-vous redémarrer maintenant ?", "A reboot is required to apply the new GPU mode. Do you want to restart now?": "Un redémarrage est nécessaire pour appliquer le nouveau mode GPU. Voulez-vous redémarrer maintenant ?", "A reboot is required to finish the restore.": "Un redémarrage est nécessaire pour terminer la restauration.", "A reboot will be required to complete the restore.": "Un redémarrage sera nécessaire pour terminer la restauration.", + "A reproducible native startup is missing": "Une start-up native reproductible est manquante", + "A rootfs adaptation is stored in persistent storage": "Une adaptation des roofs est stockée dans un stockage persistant", + "A self-hosted Bitwarden server": "Un serveur Bitwarden auto-organisé", + "A self-hosted, goal-free habit tracking tool.": "Un outil de suivi de l'habitude autonome et sans but.", + "A self-improving AI agent with memory, skills, messaging, and a web dashboard.": "Un agent d'IA auto-améliorant avec mémoire, compétences, messagerie, et un tableau de bord web.", "A server reboot is recommended for all changes to take full effect.": "Un redémarrage du serveur est recommandé pour que toutes les modifications prennent pleinement effet.", + "A shared directory was replaced during the installation": "Un répertoire partagé a été remplacé pendant l'installation", + "A shared source does not match its recorded identity": "Une source partagée ne correspond pas à son identité enregistrée", + "A simple, open-source file sharing host.": "Un simple serveur de partage de fichiers open-source.", + "A simple, private file server.": "Un simple serveur de fichiers privé.", + "A single matching image platform cannot be resolved": "Une plateforme d'image unique ne peut être résolue", + "A single-platform OCI archive is required": "Une archive unique de l'OCI est required", + "A stack backup is missing; a partial restore is not allowed": "Une sauvegarde de la pile est manquante ; une restauration partielle n'est pas autorisée", + "A stack member has a different identity": "Un membre pile a une identité différente", "A system reboot is recommended to ensure all changes take effect.": "Un redémarrage du système est recommandé pour garantir que toutes les modifications prennent effet.", + "A third party companion app available to Plex server owners to allow their users to request, review and discover content.": "Une application complémentaire tierce disponible aux propriétaires de serveurs Plex pour permettre à leurs utilisateurs de demander, de revoir et de découvrir du contenu.", + "A third-party client for self-hosted server and self-hosted server, remote access management interface, remote access to installed applications.": "Un client tiers pour serveur autonome et serveur autonome, interface de gestion d'accès à distance, accès à distance aux applications installées.", + "A tmpfs mount is not part of the journal; recovery blocked": "Un montage tmpfs ne fait pas partie du journal; récupération bloquée", + "A tmpfs mount overlaps another mount": "Un montage tmpfs chevauche un autre montage", + "A tunneling daemon by Cloudflare that safely exposes your web servers into the internet.": "Un démon de tunnel par Cloudflare qui expose en toute sécurité vos serveurs web dans Internet.", + "A versatile file conversion tool that supports multiple formats.": "Un outil de conversion de fichiers polyvalent qui prend en charge plusieurs formats.", + "A web GUI client of Project V which supports VMess, VLESS, SS, SSR, Trojan, Tuic and Juicity protocols": "Un client web GUI du Projet V qui prend en charge les protocoles VMess, VLESS, SS, SSR, Trojan, Tuic et Juicity", + "A web app to listen Youtube audio source.": "Une application web pour écouter la source audio Youtube.", + "A web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes": "Une application web pour gérer vos comptes d'authentification à deux facteurs (2FA) et générer leurs codes de sécurité", + "A web frontend for the motion daemon.": "Une interface web pour le démon du mouvement.", + "A web-based file sharing and management protocol": "Un protocole de partage et de gestion de fichiers en ligne", + "A well-designed cross-platform ChatGPT UI.": "Une interface multiplateforme bien conçue.", "ACL Status:": "Statut de la liste de contrôle d'accès :", "ACL permissions applied for local access for user:": "Autorisations ACL appliquées pour l'accès local pour l'utilisateur :", "ADVANCED SETTINGS COMPLETE": "PARAMÈTRES AVANCÉS TERMINÉS", + "AI / Coding & Dev-Tools": "AI / Codage & Outils Dev", "ALL DATA ON": "TOUTES LES DONNÉES SUR", "ALL DATA ON THIS DISK WILL BE PERMANENTLY LOST!": "TOUTES LES DONNÉES SUR CE DISQUE SERONT PERMANENTES DÉFINITIVEMENT !", "ALL Utilities": "TOUS les utilitaires", + "ALLOWED_HOSTS cannot contain line breaks": "ALLOWED HOSTS ne peut pas contenir les ruptures de ligne", + "AList initial login": "Connexion initiale AList", "AMD CPU detected": "Processeur AMD détecté", "AMD CPU fixes applied successfully": "Correctifs du processeur AMD appliqués avec succès", "AMD GPU Tools installation completed!": "Installation des outils GPU AMD terminée !", "AMD GPU passthrough configured.": "Passthrough GPU AMD configuré.", "AMD GPU(s) detected:": "GPU(s) AMD détecté(s) :", + "AMD KFD device": "Dispositif AMD KFD", + "AMD VA-API + OpenCL (official mod)": "AMD VA-API + OpenCL (mod officiel)", "AMD fixes have been successfully reverted": "Les correctifs AMD ont été annulés avec succès", "AMD mesa drivers installed.": "Pilotes AMD mesa installés.", "AMD softdep configured": "AMD softdep configuré", @@ -93,9 +158,21 @@ "About to restore": "Sur le point de restaurer", "Absolute directory path to use as backup target:": "Chemin du répertoire absolu à utiliser comme cible de sauvegarde :", "Absolute path to a file or directory you want backed up:": "Chemin absolu vers un fichier ou un répertoire que vous souhaitez sauvegarder :", + "Acceleration": "Accélération", + "Acceleration configuration cancelled": "Configuration d'accélération annulée", + "Acceleration for CodeProject.AI": "Accélération pour CodeProject. AI", + "Acceleration for Immich smart recognition": "Accélération de la reconnaissance intelligente Immich", + "Acceleration for Ollama": "Accélération pour Ollama", "Accept routes from other nodes?": "Accepter les routes d'autres nœuds ?", + "Accept this host monitoring profile?": "Accepter ce profil de surveillance de l'hôte?", "Access Scope:": "Portée d'accès :", + "Access bridge": "Pont d'accès", + "Access bridge for Immich": "Pont d'accès pour Immich", + "Access bridge for Nextcloud": "Pont d'accès pour Nextcloud", + "Access bridge for Paperless": "Pont d'accès pour sans papier", + "Access bridge for Tandoor": "Pont d'accès pour Tandoor", "Access profile:": "Profil d'accès :", + "Access token of the Jupyter Lab web interface": "Jeton d'accès de l'interface web Jupyter Lab", "Account is not locked": "Le compte n'est pas verrouillé", "Action cancelled due to previous xshok-proxmox modifications.": "Action annulée en raison de modifications précédentes de xshok-proxmox.", "Action:": "Action:", @@ -105,6 +182,10 @@ "Active Connections": "Connexions actives", "Active exports:": "Exportations actives :", "Active session:": "Séance active :", + "Actual device path on the host": "Chemin réel du périphérique sur l'hôte", + "Adaptation file too large": "Dossier d'adaptation trop grand", + "Adaptation file with unexpected permissions or owner": "Fichier d'adaptation avec permissions inattendues ou propriétaire", + "Adblock & DNS": "Adblock & DNS", "Add Audio Passthrough": "Ajouter un relais audio", "Add CIFS storage:": "Ajoutez un stockage CIFS :", "Add Controller or NVMe (PCI passthrough)": "Ajouter un contrôleur ou NVMe (passthrough PCI)", @@ -123,6 +204,9 @@ "Add PBS": "Ajouter du PBS", "Add Samba Share as Proxmox Storage": "Ajouter le partage Samba comme stockage Proxmox", "Add Samba share as Proxmox Storage": "Ajouter le partage Samba en tant que stockage Proxmox", + "Add a Coral PCIe/M.2 device?": "Ajouter un périphérique Coral PCIe/M.2?", + "Add a custom data path?": "Ajouter un chemin de données personnalisé ?", + "Add an extra custom path": "Ajouter un chemin personnalisé supplémentaire", "Add as IDE": "Ajouter en tant qu'EDI", "Add as SATA": "Ajouter en tant que SATA", "Add as SCSI": "Ajouter en tant que SCSI", @@ -140,6 +224,7 @@ "Add import disk": "Ajouter un disque d'importation", "Add latest Ceph support": "ajouter la dernière prise en charge de Ceph", "Add new PVE 9 enterprise repository (deb822 format) (Only if using enterprise):": "Ajouter un nouveau référentiel d'entreprise PVE 9 (format deb822) (uniquement si vous utilisez Enterprise) :", + "Add or change a device": "Ajouter ou modifier un appareil", "Add physical disk to VM via": "Ajouter un disque physique à la VM via", "Add share block in /etc/samba/smb.conf:": "Ajoutez un bloc de partage dans /etc/samba/smb.conf :", "Add unprivileged flag to container configuration:": "Ajoutez un indicateur sans privilèges à la configuration du conteneur :", @@ -154,20 +239,37 @@ "Adding": "Ajout", "Adding CIFS storage to Proxmox...": "Ajout du stockage CIFS à Proxmox...", "Adding QEMU Guest Agent support...": "Ajout de la prise en charge de l'agent invité QEMU...", + "Adding Radarr to Prowlarr...": "Ajouter Radarr à Prowlarr...", + "Adding Sonarr to Prowlarr...": "Ajouter Sonarr à Prowlarr...", "Adding disk using the generated command to the selected VM": "Ajout d'un disque à l'aide de la commande générée à la VM sélectionnée", "Adding existing users to sharedfiles group...": "Ajout d'utilisateurs existants au groupe de fichiers partagés...", "Adding iSCSI storage to Proxmox...": "Ajout du stockage iSCSI à Proxmox...", "Adding new share to smb.conf...": "Ajout d'un nouveau partage à smb.conf...", + "Adding peers later means raising PEERS in /etc/pve/lxc/.conf and restarting the container. The existing peer keys are kept.": "Ajouter des pairs plus tard signifie élever PEERS dans /etc/pve/lxc/.conf et redémarrer le conteneur. Les clés existantes sont conservées.", + "Adding the mount points...": "Ajout des points de montage...", "Adding this NVMe as a PCIe device (via 'Add Controller or NVMe PCIe to VM') gives better performance.": "L'ajout de ce NVMe en tant que périphérique PCIe (via « Ajouter un contrôleur ou NVMe PCIe à la VM ») donne de meilleures performances.", "Adding to /etc/fstab for permanent mounting...": "Ajout à /etc/fstab pour un montage permanent...", + "Additional URL advertised by Plex (optional)": "URL supplémentaire annoncée par Plex (facultatif)", "Additional audio function(s) to be added": "Fonction(s) audio supplémentaire(s) à ajouter", + "Additional media/GPU GIDs, comma-separated": "Autres médias/GPU GID, séparés par des virgules", + "Additional paths for": "Voies supplémentaires pour", + "Address of the Compose file": "Adresse du fichier Composer", + "Address to reach Pydio Cells (https://domain or https://IP:8080)": "Adresse pour atteindre Pydio Cells (https://domaine ou https://IP:8080)", + "Address used to reach wallabag (http://IP or https://wallabag.example.com)": "Adresse utilisée pour atteindre wallabag (http://IP ou https://wallabag.exemple.com)", + "Addresses to update: ipv4, ipv6 or both (uses an external service)": "Adresses à mettre à jour: ipv4, ipv6 ou les deux (utilise un service externe)", + "Adguardhome Sync web interface": "Interface web Adguardhome Sync", + "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances.": "Adguardhome-sync est un outil pour synchroniser la configuration AdGuardHome pour reproduire des instances.", "Adjust network/CIDR to your environment.": "Ajustez le réseau/CIDR à votre environnement.", "Adjust options if needed (vers=4,hard,timeo,...).": "Ajustez les options si nécessaire (vers=4,hard,timeo,...).", "Adjusting systemd-journald limits to match Log2RAM size...": "Ajustement des limites du journal système pour correspondre à la taille de Log2RAM...", "Adjusts journald log level if needed (Proxmox defaults may block auth logs)": "Ajuste le niveau de journalisation du journal si nécessaire (les valeurs par défaut de Proxmox peuvent bloquer les journaux d'authentification)", + "Admin page": "Administrateur page", + "Administrator email": "Courriel de l'administrateur", + "Administrator password, at least 12 characters (empty = generated)": "Mot de passe administrateur, au moins 12 caractères (vide = généré)", "Advanced": "Avancé", "Advanced Diagnostics": "Diagnostic avancé", "Advanced Network Diagnostics": "Diagnostics réseau avancés", + "Advanced: every setting of the container": "Avancé : chaque réglage du conteneur", "Affected LXC containers": "Conteneurs LXC concernés", "After completing GPU setup, start the VM manually when the host is ready.": "Après avoir terminé la configuration du GPU, démarrez la VM manuellement lorsque l'hôte est prêt.", "After confirming, you will be asked to choose the NVIDIA driver version to install.": "Après confirmation, il vous sera demandé de choisir la version du pilote NVIDIA à installer.", @@ -183,11 +285,15 @@ "After the reboot you can follow the post-restore work live from ProxMenux Monitor → Backups tab (estimated time, per-component status, log tail, rollback delta).": "Après le redémarrage, vous pouvez suivre le travail post-restauration en direct depuis ProxMenux Monitor → onglet Sauvegardes (durée estimée, état par composant, queue du journal, delta de restauration).", "After the reboot, you will only be able to access the Proxmox host via:": "Après le redémarrage, vous ne pourrez accéder à l'hôte Proxmox que via :", "After this LXC → VM switch, reboot the host so the new binding state is applied cleanly.": "Après ce commutateur LXC → VM, redémarrez l'hôte afin que le nouvel état de liaison soit appliqué proprement.", + "Airsonic Advanced web interface": "Interface web Airsonic Advanced", + "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room.": "Airsonic-Advanced est un flux multimédia gratuit, basé sur le web, offrant un accès ubiquitious à votre musique. Utilisez-le pour partager votre musique avec des amis, ou pour écouter votre propre musique au travail. Vous pouvez diffuser simultanément vers plusieurs joueurs, par exemple vers un joueur dans votre cuisine et un autre dans votre salon.", "Aliases added to .bashrc": "Alias ​​ajoutés à .bashrc", + "Alist Sync web interface": "Alist Interface web Sync", "All": "Tous", "All Available Scripts": "Tous les scripts disponibles", "All GPUs Already Assigned": "Tous les GPU déjà attribués", "All ProxMenux optimizations are up to date.": "Toutes les optimisations de ProxMenux sont à jour.", + "All applications": "Toutes les demandes", "All block devices:": "Tous les appareils bloqués :", "All changes applied. No reboot required.": "Toutes les modifications ont été appliquées. Aucun redémarrage requis.", "All changes are reversible using the ProxMenux uninstaller.": "Toutes les modifications sont réversibles à l'aide du programme de désinstallation ProxMenux.", @@ -195,43 +301,79 @@ "All detected GPUs are already assigned to this VM.": "Tous les GPU détectés sont déjà attribués à cette VM.", "All detected controllers/NVMe are already present in the selected VM.": "Tous les contrôleurs/NVMe détectés sont déjà présents dans la VM sélectionnée.", "All disks may already be in use or mounted.": "Tous les disques sont peut-être déjà utilisés ou montés.", + "All images are downloaded and verified first, and native backups are taken with the stack stopped. Contracts are published after the whole set is checked. If anything fails, all members are recovered.": "Toutes les images sont téléchargées et vérifiées en premier, et les sauvegardes natives sont prises avec la pile arrêtée. Les contrats sont publiés après vérification de l'ensemble. Si quelque chose échoue, tous les membres sont récupérés.", "All images imported and configured successfully": "Toutes les images importées et configurées avec succès", "All imports failed": "Toutes les importations ont échoué", + "All of them are removed.": "Tous sont enlevés.", "All partitions and metadata removed.": "Toutes les partitions et métadonnées supprimées.", "All physical interfaces from backup are present on target": "Toutes les interfaces physiques de la sauvegarde sont présentes sur la cible", + "All stack members are updated together. Main CT:": "Tous les membres de pile sont mis à jour ensemble. Principale CT:", "All types (images, backup, iso, vztmpl, snippets)": "Tous types (images, sauvegarde, iso, vztmpl, snippets)", "All user-installed packages from the backup are present on this host": "Tous les packages installés par l'utilisateur à partir de la sauvegarde sont présents sur cet hôte", "All users with UID and GID": "Tous les utilisateurs avec UID et GID", "Allocate CPU Cores": "Allouer des cœurs de processeur", "Allocate RAM in MiB": "Allouer de la RAM en MiB", + "Allowed hosts (comma separated; * allows access through the assigned IP)": "Hôtes autorisés (comma séparé ; * permet l'accès via l'IP assigné)", "Already Mounted": "Déjà monté", "Already configured": "Déjà configuré", "Already installed — skipping": "Déjà installé – sauter", + "Also add the /dev/srX optical device (recommended)": "Ajoutez également le périphérique optique /dev/srX (recommandé)", "Also comment any remaining 'bookworm' entries in *.list if present.": "Commentez également toutes les entrées « bookworm » restantes dans *.list si elles sont présentes.", "Also install the VirtIO network driver during setup to enable network access.": "Installez également le pilote réseau VirtIO lors de l'installation pour activer l'accès au réseau.", "Although VFIO can bind to this device, full passthrough to a VM is": "Bien que VFIO puisse se lier à cet appareil, le relais complet vers une VM est", + "Altus is an Electron-based WhatsApp client with themes and multiple account support.": "Altus est un client de WhatsApp basé à Electron avec des thèmes et un support de compte multiple.", + "Ambiguous mount points in the container": "Points de montage ambigus dans le conteneur", + "Ambiguous or invalid environment variable": "Variable d'environnement ambulante ou invalide", "Amount of RAM in MiB (default: 4096)": "Quantité de RAM en MiB (par défaut : 4096)", + "An AI model used to generate images conditioned on text descriptions.": "Un modèle AI utilisé pour générer des images conditionnées par des descriptions de texte.", "An AMD dedicated GPU has been detected without FLR support": "Un GPU dédié AMD a été détecté sans prise en charge FLR", "An AMD integrated GPU (APU) has been detected": "Un GPU intégré (APU) AMD a été détecté", + "An Alist storage synchronization tool based on the Web interface.": "Un outil de synchronisation de stockage Alist basé sur l'interface Web.", + "An Industrial-Level Controllable and Efficient Zero-Shot Text-To-Speech System": "Un système de discussion texte-à-parler efficace et contrôlable au niveau industriel", "An Intel dedicated GPU has been detected without FLR support": "Un GPU dédié Intel a été détecté sans prise en charge FLR", + "An accelerated video generation framework that speeds up end-to-end diffusion while preserving video quality": "Un cadre de production vidéo accéléré qui accélère la diffusion de bout en bout tout en préservant la qualité vidéo", + "An executable required by the adapter is missing in the new image": "Une requi exécutable est manquante dans la nouvelle image", "An fstab entry already exists for:": "Une entrée fstab existe déjà pour :", + "An image probe container was started externally": "Un conteneur de sonde d'image a été lancé à l'extérieur", + "An include is not part of the journal; recovery blocked": "Une inclusion ne fait pas partie du journal; récupération bloquée", + "An include was modified outside the journal; recovery blocked": "Une inclusion a été modifiée en dehors du journal; récupération bloquée", + "An open source generative AI development platform for building AI Agents and LLM workflows": "Une plate-forme de développement de l'intelligence artificielle à source ouverte pour la construction d'agents d'intelligence artificielle et de flux de travail LLM", + "An operation of this installation has not finished; recover it from the management menu before removing it": "Un operation de cette installation n'a pas fini; récupérer du menu de gestion avant de le supprimer", + "An update does not accept configuration changes": "Une mise à jour n'accepte pas les modifications de configuration", "Analysis Tools": "Outils d'analyse", + "Analysis software that shows your internet speed for up to 30 days.": "Logiciel d'analyse qui montre votre vitesse Internet pendant jusqu'à 30 jours.", "Analyze Bridge Configuration": "Analyser la configuration du pont", "Analyze Network Configuration": "Analyser la configuration du réseau", "Analyzing Bridge Configuration - READ ONLY MODE": "Analyse de la configuration du pont - MODE LECTURE SEULE", "Analyzing Network Configuration - READ ONLY MODE": "Analyse de la configuration réseau - MODE LECTURE SEULE", "Analyzing selected disks...": "Analyse des disques sélectionnés...", "Analyzing system for available PCIe storage devices...": "Système d'analyse des périphériques de stockage PCIe disponibles...", + "Another OCI operation is using the instance registry": "Un autre OCI operation utilise le registre d'instance", + "Another OCI operation is using the instance registry. Wait for it to finish and open this menu again; no container is modified.": "Un autre OCI operation utilise le registre des instances. Attendez qu'il finisse et ouvrez à nouveau ce menu; aucun conteneur n'est modifié.", + "Another OCI operation is using the registry. This operation was not started.": "Un autre OCI operation utilise le registre. Ce opera n'a pas commencé.", + "Another instance uses": "Une autre instance utilise", + "Another stack operation is pending": "Une autre pile operation est en attente", + "Application": "Demande", + "Application responding:": "Réponse à la demande :", + "Application responding; checking its stability...": "Application répondant; contrôle de sa stabilité...", + "Application suite: one independent LXC per selected application": "Suite d'application : un LXC indépendant par application sélectionnée", + "Application:": "Demande :", + "Applications you can choose:": "Les applications que vous pouvez choisir:", "Apply": "Appliquer", "Apply AMD CPU fixes": "appliquer les correctifs du processeur AMD", "Apply Available Updates": "Appliquer les mises à jour disponibles", "Apply and restart services:": "Appliquer et redémarrer les services :", "Apply available updates": "appliquer les mises à jour disponibles", "Apply boot/initramfs changes": "Appliquer les modifications de démarrage/initramfs", + "Apply configuration": "Appliquer la configuration", "Apply fix now?": "Appliquer le correctif maintenant ?", "Apply fix now? (The share will be briefly remounted)": "Appliquer le correctif maintenant ? (Le partage sera brièvement remonté)", "Apply network optimizations": "appliquer les optimisations du réseau", + "Apply optional security relaxation apparmor:rootlesskit": "Appliquer l'apparmor de relaxation de sécurité optionnel:rootlesskit", + "Apply optional security relaxation apparmor:unconfined": "Appliquer l'apparmor de relaxation de sécurité optionnel:uncontinued", + "Apply optional security relaxation seccomp:unconfined": "Appliquer la relaxation de sécurité optionnelle seccomp:unconfined", "Apply read+write access for 'others' on the host directory?": "Appliquer un accès en lecture et en écriture aux « autres » sur le répertoire hôte ?", + "Apply the options from the current catalog template? Your data and configuration are kept.": "Appliquer les options du modèle de catalogue actuel? Vos données et configurations sont conservées.", "Applying AMD-specific fixes...": "Application de correctifs spécifiques à AMD...", "Applying Changes": "Application des modifications", "Applying Controller/NVMe passthrough to VM": "Application du relais Controller/NVMe à la VM", @@ -244,12 +386,21 @@ "Applying passthrough to CT": "Application du relais au CT", "Applying safe paths and preparing pending restore": "Application de chemins sécurisés et préparation de la restauration en attente", "Applying selected LXC switch action": "Application de l'action du commutateur LXC sélectionnée", + "Applying the Jellyfin configuration:": "Appliquer la configuration Jellyfin:", + "Applying the LAN address to the application URLs...": "Appliquer l'adresse LAN aux URLs de l'application...", + "Applying the initial Nextcloud settings...": "Appliquer les paramètres Nextcloud...", + "Applying the mount mode...": "Appliquer le mode montage...", + "Apprise-api Takes advantage of Apprise through your network with a user-friendly API.": "Apprise-api Profitez d'Apprise via votre réseau avec une API conviviale.", + "Architecture": "Architecture", + "Architecture:": "Architecture :", + "Architectures": "Architectures", "Archive deleted.": "Archive supprimée.", "Archive extracted.": "Archive extraite.", "Archive format": "Format d'archives", "Archive ready": "Archiver prêt", "Archive size:": "Taille des archives :", "Archive:": "Archive:", + "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers.": "Ardour est une équipe ouverte et collaborative de musiciens, de programmeurs et d'ingénieurs d'enregistrement professionnels.", "Are you absolutely sure?": "Etes-vous absolument sûr ?", "Are you sure you want to continue?": "Êtes-vous sûr de vouloir continuer ?", "Are you sure you want to delete this export?": "Êtes-vous sûr de vouloir supprimer cette exportation ?", @@ -261,6 +412,7 @@ "Are you sure you want to unmount this NFS share?": "Êtes-vous sûr de vouloir démonter ce partage NFS ?", "Are you sure you want to unmount this Samba share?": "Êtes-vous sûr de vouloir démonter ce partage Samba ?", "Are you sure?": "Es-tu sûr?", + "Arr suite: applications to install": "Arr suite: applications à installer", "As Proxmox storage": "Comme stockage Proxmox", "As host fstab mount only": "En tant qu'hôte, montage fstab uniquement", "Assign GPU PCI function to VM": "Attribuer la fonction GPU PCI à la VM", @@ -275,14 +427,19 @@ "Attach imported disk to VM": "Attacher le disque importé à la VM", "Attach to an existing PVE vzdump job (inherit schedule + retention)": "Attacher à une tâche vzdump PVE existante (hériter de la planification + rétention)", "Attached to PVE job:": "Attaché au travail PVE :", + "Attaching the volumes...": "Attacher les volumes...", "Attempting automatic repair...": "Tentative de réparation automatique...", "Attempting passthrough with this GPU typically results in": "Toute tentative de relais avec ce GPU entraîne généralement", "Attention: Removing the subscription banner may cause issues in the web interface after a future update.": "Attention : La suppression de la bannière d'abonnement peut entraîner des problèmes dans l'interface Web après une future mise à jour.", + "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source.": "Audacity est un éditeur et un enregistreur audio facile à utiliser. Développé par un groupe de volontaires comme source ouverte.", + "Audio device directory": "Répertoire des périphériques audio", + "Audiobookshelf is a self-hosted audiobook and podcast server.": "Audiobookshelf est un livre audio et un serveur podcast auto-organisé.", "Audit completed. Press Enter to continue...": "Vérification terminée. Appuyez sur Entrée pour continuer...", "Audit socket disabled or not required": "Socket d'audit désactivé ou non requis", "Auth key is required.": "La clé d'authentification est requise.", "Auth:": "Authentification :", "Authentication": "Authentification", + "Authentication & Security": "Authentification et sécurité", "Authentication Error": "Erreur d'authentification", "Authentication failed.": "L'authentification a échoué.", "Authentication required:": "Authentification requise :", @@ -301,7 +458,12 @@ "Auto-sync was not enabled": "La synchronisation automatique n'a pas été activée", "Automated Post-Install Script": "Script de post-installation automatisé", "Automated post-installation script": "Script de post-installation automatisé", + "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Gestionnaire automatique de bibliothèque vidéo pour les émissions de télévision. Il regarde de nouveaux épisodes de vos spectacles préférés, et quand ils sont affichés, il fait sa magie.", + "Automatic detection": "Détection automatique", + "Automatic private network allocation requires a /24 subnet": "Allocation de réseau privé automatique requires un sous-réseau /24", + "Automatic video library manager for TV Shows": "Gestionnaire automatique de bibliothèque vidéo pour TV Shows", "Automatic/Unattended": "Automatique/sans surveillance", + "Automation & Scheduling": "Automatisation et calendrier", "Available": "Disponible", "Available Borg archives (newest first):": "Archives Borg disponibles (les plus récentes en premier) :", "Available Borg targets:": "Cibles Borg disponibles :", @@ -322,17 +484,23 @@ "Available space in /mnt:": "Espace disponible en /mnt :", "Available storage information:": "Informations de stockage disponibles :", "Available storage volumes:": "Volumes de stockage disponibles :", + "Azahar is an open-source 3DS emulator based on Citra.": "Azahar est un émulateur 3DS open-source basé sur Citra.", "BIOS TYPE": "TYPE DE BIOS", "BIOS Type": "Type de BIOS", "BIOS from": "BIOS de", "BIOS: OVMF (UEFI)": "BIOS : OVMF (UEFI)", + "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications.": "BOINC est une plateforme de calcul à haut débit à grande échelle (en milliers ou en millions d'ordinateurs). Il peut être utilisé pour l'informatique bénévole (à l'aide d'appareils grand public) ou l'informatique par grille (à l'aide de ressources organisationnelles). Il prend en charge les applications virtualisées, parallèles et GPU.", "BRIDGE CONFIGURATION ANALYSIS": "ANALYSE DE LA CONFIGURATION DU PONT", "BTRFS:": "BTRFS :", + "Baby Buddy web interface": "Interface web Baby Buddy", + "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work.": "Babybuddy est un ami pour les bébés ! Aide les soignants à suivre le sommeil, l'alimentation, les changements de couches, le temps du ventre et plus encore pour apprendre et prédire les besoins du bébé sans (autant) le travail de supposition.", "Back to previous menu or Esc + Enter": "Retour au menu précédent ou Echap + Entrée", "Backed up and cleared": "Sauvegarde et effacement", "Backend": "Back-end", "Backend:": "Back-end :", + "Background archive extraction for Arr download queues. No web interface.": "Extraction des archives de fond pour les files de téléchargement Arr. Pas d'interface web.", "Backup — VM and CT backups": "Sauvegarde – Sauvegardes VM et CT", + "Backup & Recovery": "Sauvegarde et récupération", "Backup Created": "Sauvegarde créée", "Backup ID (group name in PBS):": "ID de sauvegarde (nom du groupe dans PBS) :", "Backup ID for this job:": "ID de sauvegarde pour ce travail :", @@ -345,6 +513,7 @@ "Backup available at": "Sauvegarde disponible sur", "Backup completed successfully.": "Sauvegarde terminée avec succès.", "Backup completed:": "Sauvegarde terminée :", + "Backup created": "Sauvegarde créée", "Backup created:": "Sauvegarde créée :", "Backup declares unused NICs that are not on this host:": "La sauvegarde déclare les cartes réseau inutilisées qui ne se trouvent pas sur cet hôte :", "Backup destination is inside the backup": "La destination de la sauvegarde se trouve à l'intérieur de la sauvegarde", @@ -355,6 +524,7 @@ "Backup information": "Informations de sauvegarde", "Backup location": "Emplacement de sauvegarde", "Backup metadata": "Métadonnées de sauvegarde", + "Backup of the previous installation verified": "Sauvegarde de l'installation précédente vérifiée", "Backup on newer kernel:": "Sauvegarde sur un noyau plus récent :", "Backup on older kernel:": "Sauvegarde sur un noyau plus ancien :", "Backup origin metadata:": "Métadonnées d'origine de la sauvegarde :", @@ -369,26 +539,42 @@ "Backup:": "Sauvegarde :", "Backups already on PBS were encrypted with the current key — downloading them will fail unless you first Download the current keyfile to keep a copy.": "Les sauvegardes déjà sur PBS ont été chiffrées avec la clé actuelle. Leur téléchargement échouera à moins que vous ne téléchargiez d'abord le fichier de clé actuel pour en conserver une copie.", "Backups already stored on PBS were encrypted with the current keyfile. After this action:": "les sauvegardes déjà stockées sur PBS ont été chiffrées avec le fichier de clés actuel. Après cette action :", + "Backups verified": "Sauvegardes vérifiés", + "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience.": "Bambu Studio est un logiciel de sciage ouvert, de pointe et riche en fonctionnalités. Il contient des workflows basés sur des projets, des algorithmes de coupe optimisés systématiquement, et une interface graphique facile à utiliser, apportant aux utilisateurs une expérience d'impression incroyablement fluide.", "Bandwidth limit configured": "Limite de bande passante configurée", "Bandwidth test (iperf3)": "Test de bande passante (iperf3)", "Bandwidth test completed successfully": "Test de bande passante terminé avec succès", "Base VM created with ID": "VM de base créée avec l'ID", + "Base VMID": "VMID de base", + "Base VMID (empty = next free block)": "VMID de base (vide = prochain bloc libre)", + "Base VMID of Nextcloud (empty = next free block)": "VMID de base de Nextcloud (vide = prochain bloc libre)", + "Base VMID of Paperless (empty = next free block)": "VMID de base sans papier (vide = prochain bloc libre)", + "Base VMID of Tandoor (empty = next free block)": "VMID de base de Tandoor (vide = prochain bloc libre)", + "Base VMID of the server (empty = next free block)": "Base VMID du serveur (vide = prochain bloc libre)", "Bash prompt path": "Chemin dans l’invite Bash", "Bashrc customization completed": "Personnalisation de Bashrc terminée", "Basic Settings": "Paramètres de base", "Basic Utilities": "Utilitaires de base", + "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you.": "Bazarr est une application compagnon pour Sonarr et Radarr. Il peut gérer et télécharger des sous-titres basés sur vos requirements. Vous définissez vos préférences par émission TV ou film et Bazarr prend soin de tout pour vous.", + "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools.": "Beets est un gestionnaire de bibliothèque musicale et non, pour la plupart, un lecteur de musique. Il inclut un simple plugin de lecteur et un lecteur Web expérimental, mais il laisse généralement la reproduction réelle du son à des outils spécialisés.", "Before making any changes, we'll create a safety backup.": "Avant d'apporter des modifications, nous créerons une sauvegarde de sécurité.", "Beta (develop branch)": "Bêta (branche de développement)", "Beta version:": "Version bêta :", "Binary not found in extracted content.": "Binaire introuvable dans le contenu extrait.", "Bind mount added:": "Support de liaison ajouté :", + "Bind mounts are not included in vzdump": "Les montages de bind ne sont pas inclus dans vzdump", + "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services.": "Bitcoin Knots peut être utilisé comme client de bureau pour les paiements réguliers ou comme utilitaire de serveur de nœud complet pour les marchands et autres services de paiement.", "Blacklist nouveau driver": "Nouveau pilote de liste noire", "Blacklisting GPU host drivers...": "Mise sur liste noire des pilotes hôtes GPU...", "Blacklisting nouveau driver...": "Nouveau pilote sur liste noire...", + "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**": "Blender est un logiciel 3D gratuit et open-source utilisé pour la création de films d'animation, d'effets visuels, d'art, de modèles imprimés 3D, de mouvements graphiques, d'applications 3D interactives, de réalité virtuelle et de jeux informatiques. **Cette image ne supporte pas le rendu GPU hors de la boîte seulement l'expérience d'espace de travail accélérée**", + "Blinko is an AI-powered card note-taking project. Designed for individuals who want to quickly capture and organize their fleeting thoughts. Blinko allows users to seamlessly jot down ideas the moment they strike, ensuring that no spark of creativity is lost.": "Blinko est un projet de prise de notes de carte alimenté par l'IA. Conçu pour les personnes qui veulent qui capter et organiser leurs pensées fugaces. Le Blinko permet aux utilisateurs de tirer des idées en douceur dès qu'ils frappent, garantissant qu'aucune étincelle de créativité n'est perdue.", "Blocked GPU ID": "ID GPU bloqué", "Blocked GPU ID for VM Mode": "ID GPU bloqué pour le mode VM", "Blocked device(s)": "Appareil(s) bloqué(s)", "Blocked device(s):": "Appareil(s) bloqué(s) :", + "BookStack web interface": "Interface web BookStack", + "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease.": "Bookstack est un Wiki libre et open source conçu pour créer une belle documentation. Doté d'un éditeur WYSIWYG simple mais puissant, il permet aux équipes de créer facilement une documentation détaillée et utile.", "Boot Disk": "Disque de démarrage", "Boot artifacts regenerated — reboot the host to activate the merged config.": "Artefacts de démarrage régénérés – redémarrez l'hôte pour activer la configuration fusionnée.", "Boot disk:": "Disque de démarrage :", @@ -415,9 +601,13 @@ "Bridge:": "Pont:", "Bridges analyzed": "Ponts analysés", "Broken gasket-dkms package state recovered.": "L'état défectueux du paquet gasket-dkms a été réparé.", + "Browse Your Life in Images": "Parcourez votre vie en images", "Browse manually (advanced)...": "Parcourir manuellement (avancé)...", + "Browsers & Web Desktops": "Navigateurs et bureaux Web", "Build and install the gasket and apex kernel modules (DKMS)": "Compiler et installer les modules noyau gasket et apex (DKMS)", "Build dependencies installed.": "Dépendances de build installées.", + "Build your personal knowledge base with TriliumNext Notes": "Construisez votre base de connaissances personnelles avec TriliumNext Notes", + "Business & ERP": "Affaires & ERP", "CHANGES APPLIED SUCCESSFULLY": "MODIFICATIONS APPLIQUÉES AVEC SUCCÈS", "CIFS Client Tools: AVAILABLE": "Outils clients CIFS : DISPONIBLES", "CIFS Client Tools: NOT AVAILABLE - installing...": "Outils client CIFS : NON DISPONIBLE - installation...", @@ -435,24 +625,35 @@ "CLUSTER UPGRADE NOTES:": "REMARQUES SUR LA MISE À NIVEAU DU CLUSTER :", "CONFIGURED INTERFACES": "INTERFACES CONFIGURÉES", "CONFIRM FORMAT": "CONFIRMER LE FORMAT", + "CPU": "CPU", "CPU Cores": "Cœurs de processeur", "CPU MODEL": "MODÈLE DE CPU", "CPU Model": "Modèle de processeur", + "CPU cores": "Noyaux CPU", + "CPU priority": "Priorité du CPU", "CPU set to host,hidden=1,flags=+pcid": "CPU défini sur hôte, caché = 1, flags = + pcid", "CPU vendor (intel/amd):": "Fournisseur de processeur (Intel/AMD) :", "CRITICAL: The selected disk is referenced by a RUNNING VM or CT.": "CRITIQUE : le disque sélectionné est référencé par une VM ou un CT en cours d'exécution.", "CT": "CT", "CT started successfully.": "CT a démarré avec succès.", + "CUDA requires a working NVIDIA driver": "CUDA requires un pilote NVIDIA fonctionnant", + "CUDA requires the NVIDIA Container Toolkit on the host": "CUDA requires la boîte à outils de conteneur NVIDIA sur l'hôte", + "Calculate all kinds of statistics from your (local) Emby or Jellyfin server": "Calculez toutes sortes de statistiques à partir de votre serveur (local) Emby ou Jellyfin", + "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts.": "Calibre est un gestionnaire de livres électroniques puissant et facile à utiliser. Les utilisateurs disent que c'est exceptionnel et indispensable. Il vous permettra de faire presque tout et il prend les choses un pas au-delà du logiciel e-book normal. Il est également entièrement gratuit et open source et idéal pour les utilisateurs occasionnels et les experts en informatique.", + "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself.": "Calibre-web est une application web offrant une interface propre pour la navigation, la lecture et le téléchargement de livres électroniques à l'aide d'une base de données existante Calibre. Il est également possible d'intégrer google drive et éditer des métadonnées et votre bibliothèque calibre via l'application elle-même.", + "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases.": "Calligra est une suite de bureau et d'art graphique de KDE. Il est disponible pour les ordinateurs de bureau, les tablettes et les smartphones. Il contient des applications pour le traitement de texte, les feuilles de calcul, la présentation, les graphiques vectoriels et l'édition des bases de données.", "Cancel": "Annuler", "Cancel restore": "Annuler la restauration", "Cancel this setup": "Annuler cette configuration", "Cancelled by user or empty URL.": "Annulé par l'utilisateur ou URL vide.", "Cancelled by user.": "Annulé par l'utilisateur.", + "Cannot apply the Compose command:": "Impossible d'appliquer la commande Composer :", "Cannot connect to server": "Impossible de se connecter au serveur", "Cannot continue": "Impossible de continuer", "Cannot create:": "Impossible de créer :", "Cannot detect filesystem on": "Impossible de détecter le système de fichiers sur", "Cannot find": "Impossible de trouver", + "Cannot identify the vendor of the device:": "Impossible d'identifier le fournisseur de l'appareil :", "Cannot load backup library: lib_host_backup_common.sh": "Impossible de charger la bibliothèque de sauvegarde : lib_host_backup_common.sh", "Cannot proceed with invalid export path.": "Impossible de poursuivre avec un chemin d'exportation non valide.", "Cannot proceed with invalid share name.": "Impossible de continuer avec un nom de partage invalide.", @@ -460,7 +661,11 @@ "Cannot reach download.proxmox.com. Check network, proxy or DNS.": "Impossible d'accéder à download.proxmox.com. Vérifiez le réseau, le proxy ou le DNS.", "Cannot reach portal:": "Impossible d'accéder au portail :", "Cannot reach server": "Ne peut pas atteindre le serveur", + "Cannot read": "Impossible de lire", + "Cannot read the OCI archive:": "Impossible de lire l'archive du BEC :", "Cannot validate credentials - no shares available for testing.": "Impossible de valider les informations d'identification - aucun partage disponible pour les tests.", + "Cannot verify the reused disk:": "Impossible de vérifier le disque réutilisé :", + "Capabilities cannot be kept and all dropped at the same time": "Les capacités ne peuvent être conservées et toutes abandonnées en même temps", "Category": "Catégorie", "Caution: Maximum mode generates more heat.": "Attention : le mode maximum génère plus de chaleur.", "Ceph check skipped by user flag (--ignore-ceph-check)": "Vérification Ceph ignorée par l'indicateur utilisateur (--ignore-ceph-check)", @@ -487,14 +692,23 @@ "Ceph repository configured for PVE 9": "Dépôt Ceph configuré pour PVE 9", "Ceph repository signature verification failed; installation has been stopped": "La vérification de la signature du référentiel Ceph a échoué ;l'installation a été arrêtée", "Ceph version OK:": "Version Ceph OK :", + "Certificate errors are logged in /config/log/letsencrypt inside the container.": "Les erreurs de certificat sont enregistrées dans /config/log/letsencrypt dans le conteneur.", "Certificate fingerprint of the PBS server:": "Empreinte digitale du certificat du serveur PBS :", + "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL": "Fournisseur de certificat: vide pour Let's Encrypt, zérossl pour ZeroSSL", + "Change GPU acceleration?": "Changer l'accélération GPU ?", "Change Language": "Changer de langue", "Change Release Channel": "Changer le canal de publication", + "Change it after the first login.": "Changez-le après la première connexion.", + "Change or add an environment variable?": "Changer ou ajouter une variable d'environnement?", + "Change the access network?": "Changer le réseau d'accès ?", + "Changedetection.io provides free, open-source web page monitoring, notification and change detection.": "Changedetection.io fournit gratuitement la surveillance, la notification et la détection de changement de page Web open-source.", "Changes applied. A system reboot is recommended for them to take full effect.": "Modifications appliquées. Un redémarrage du système est recommandé pour qu'ils prennent pleinement effet.", "Changes have been applied to the configuration file.": "Les modifications ont été appliquées au fichier de configuration.", "Changes will apply after reboot.": "Les modifications s'appliqueront après le redémarrage.", "Changing Release Channel": "Changer le canal de publication", "Changing the machine type on an existing installed VM is not safe: it changes the chipset and PCI slot layout, which typically prevents the guest OS from booting.": "Changer le type de machine sur une VM installée existante n'est pas sûr : cela modifie la disposition du chipset et des emplacements PCI, ce qui empêche généralement le système d'exploitation invité de démarrer.", + "Changing the rootfs or its storage requires a separate migration": "Modification des rootfs ou de leur stockage requires une migration séparée", + "Changing the storage or size of a disk requires a migration; empty disks are not created": "Modification du stockage ou de la taille d'un disque requires une migration; les disques vides ne sont pas créés", "Check": "Vérifier", "Check BIOS/UEFI in Hardware > BIOS — must match what the original VM used": "Vérifiez le BIOS/UEFI dans Matériel > BIOS : doit correspondre à ce que la VM d'origine a utilisée", "Check Coral USB/M.2 detection": "Vérifier la détection Coral USB/M.2", @@ -520,6 +734,7 @@ "Check the service status manually if needed.": "Vérifiez l'état du service manuellement si nécessaire.", "Checking MOTD configuration...": "Vérification de la configuration MOTD...", "Checking NVIDIA driver status with nvidia-smi": "Vérification de l'état du pilote NVIDIA avec nvidia-smi", + "Checking OCI": "Vérification du BEC", "Checking VFIO modules...": "Vérification des modules VFIO...", "Checking VM virtual display model...": "Vérification du modèle d'affichage virtuel de la VM...", "Checking ZFS autotrim configuration...": "Vérification de la configuration du découpage automatique ZFS...", @@ -531,7 +746,22 @@ "Checking if the server belongs to OVH...": "Vérifier si le serveur appartient à OVH...", "Checking kernel headers and build tools...": "Vérification des en-têtes du noyau et des outils de construction...", "Checking remaining interfaces": "Vérification des interfaces restantes", + "Checking that the container keeps running...": "Je vérifie que le conteneur continue de fonctionner...", "Checking that this version builds against the running kernel...": "Vérifier que cette version s'appuie sur le noyau en cours d'exécution...", + "Checking the GPU of the machine learning container...": "Vérifier le GPU du conteneur d'apprentissage...", + "Checking the container before recreating it...": "Vérifier le contenant avant de le recréer...", + "Checking the container before the update...": "Vérifier le conteneur avant la mise à jour...", + "Checking the device permissions for the application user...": "Vérification des autorisations de l'appareil pour l'utilisateur de l'application...", + "Checking the image compatibility:": "Vérification de la compatibilité de l'image :", + "Checking the image in the registry...": "Vérification de l'image dans le registre...", + "Checking the interrupted operation...": "Vérification de l'interruption du operation...", + "Checking the interrupted stack operation...": "Vérification de la pile interrompue operation...", + "Checking the new image without starting it:": "Vérifier la nouvelle image sans la démarrer :", + "Checking the remote...": "Vérification de la télécommande...", + "Checking the restored installation": "Vérification de l'installation restaurée", + "Checking the restored installation...": "Vérifier l'installation restaurée...", + "Checking the stack before the update...": "Vérification de la pile avant la mise à jour...", + "Checking the updated stack...": "Vérification de la pile mise à jour...", "Checklist post-upgrade finished. Warnings:": "Liste de contrôle après la mise à niveau terminée. Avertissements :", "Checklist pre-check finished. Warnings:": "Pré-vérification de la liste de contrôle terminée. Avertissements :", "Checks for LVM and storage issues": "Vérifie les problèmes de LVM et de stockage", @@ -588,6 +818,9 @@ "Choose the type of virtual system to install:": "Choisissez le type de système virtuel à installer :", "Choose what to do with the selected disk:": "Choisissez quoi faire avec le disque sélectionné :", "Choose where to save the backup:": "Choisissez où enregistrer la sauvegarde :", + "Chrome is the official web browser from Google, built to be fast, secure, and customizable.": "Chrome est le navigateur Web officiel de Google, construit pour être rapide, sécurisé et personnalisable.", + "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.": "Chromium est un projet de navigateur open-source qui vise à construire un moyen plus sûr, plus rapide et plus stable pour tous les utilisateurs d'expérimenter le web.", + "Circular dependency:": "Dépendance circulaire:", "Clean disk metadata": "Nettoyer les métadonnées du disque", "Cleaned up": "Nettoyé", "Cleaning cached files...": "Nettoyage des fichiers en cache...", @@ -611,21 +844,30 @@ "Clearing login credentials...": "Effacement des identifiants de connexion...", "Client (run a bandwidth test to a server)": "Client (exécuter un test de bande passante sur un serveur)", "Client determines best version to use": "Le client détermine la meilleure version à utiliser", + "Clients reach the VPN through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Les clients atteignent le VPN par l'adresse publique et le port UDP donné lors de l'installation, de sorte que le port doit être transmis à ce conteneur.", "Cloning Coral driver repository (feranick fork)...": "Clonage du référentiel de pilotes Coral (feranick fork)...", "Cloning Lynis from GitHub...": "Clonage de Lynis depuis GitHub...", "Cloning and applying NVIDIA patch (keylase/nvidia-patch)...": "Clonage et application du patch NVIDIA (keylase/nvidia-patch)...", "Closed": "Fermé", + "Cloud Database Manager.": "Gestionnaire de bases de données Cloud.", + "Cloud storage synchronization and FUSE mounts": "Synchronisation de stockage en nuage et montages FUSE", "Cloud-Init Automated Installers": "Installateurs automatisés Cloud-Init", "Cluster certificates updated": "Certificats de cluster mis à jour", "Cluster configuration (advanced)": "Configuration du cluster (avancé)", "Cluster data will be applied automatically at next boot.": "les données du cluster seront appliquées automatiquement au prochain démarrage.", "Cluster upgrade mode": "Mode de mise à niveau du cluster", + "Code-server is VS Code running on a remote server, accessible through the browser.": "Code-serveur est VS Code fonctionnant sur un serveur distant, accessible par le navigateur.", + "CodeProject.AI Server": "CodeProject. AI Server", "Command": "Commande", + "Command override for an unknown service:": "Dépassement de commande pour un service inconnu :", "Commenting any residual Bookworm lines in *.list...": "Commenter les lignes résiduelles de Bookworm dans *.list...", "Commenting legacy PVE 8 repository .list files (if any)...": "Commentaire des anciens fichiers .list du référentiel PVE 8 (le cas échéant)...", "Commenting legacy ceph.list (if present)...": "Commentaire de l'héritage ceph.list (si présent)...", "Common Issues Check": "Vérification des problèmes courants", + "Common root for the published views": "Source commune des vues publiées", + "Communication & Community": "Communication & Communauté", "Community Scripts": "Scripts communautaires", + "Community single-container Home Assistant OS image": "Image OS communautaire monoconteneur Home Assistant", "Compatibility check": "Vérification de compatibilité", "Compatibility check — OK": "Vérification de compatibilité - OK", "Compatibility check — issues detected": "Vérification de compatibilité : problèmes détectés", @@ -640,24 +882,31 @@ "Complete restore": "Restauration complète", "Complete the DSM installation wizard": "Terminez l'assistant d'installation de DSM", "Complete the ZimaOS installation wizard": "Terminez l'assistant d'installation de ZimaOS", + "Complete the media server and Seerr accounts, the Bazarr providers and the SABnzbd Usenet credentials when they are selected.": "Compléter le serveur multimédia et les comptes Seerr, les fournisseurs Bazarr et les clients utilisateurs SABnzbd lorsqu'ils sont sélectionnés.", + "Completed": "Achevé", "Completed Successfully with GPU passthrough configured!": "Terminé avec succès avec le passthrough GPU configuré !", "Completed Successfully!": "Terminé avec succès !", "Completed with errors —": "Complété avec des erreurs —", "Completed.": "Complété.", "Completed. Devices added to VM {vmid}: {count}.": "Terminé. Appareils ajoutés à la VM {vmid} : {count}.", "Completed. Press Enter to return to menu...": "Complété. Appuyez sur Entrée pour revenir au menu...", + "Completing its final cleanup...": "Compléter son nettoyage final...", "Completing pending package configurations...": "Finalisation des configurations de packages en attente...", "Compliance checking (PCI-DSS, HIPAA, etc.)": "Vérification de la conformité (PCI-DSS, HIPAA, etc.)", "Component to uninstall manually (no --auto-uninstall yet):": "Composant à désinstaller manuellement (pas encore de --auto-uninstall) :", "Component was installed on the backup source but no matching hardware was found on this host.": "Le composant a été installé sur la source de sauvegarde mais aucun matériel correspondant n'a été trouvé sur cet hôte.", "Component:": "Composant :", "Components to uninstall (manual for now):": "Composants à désinstaller (manuel pour l'instant) :", + "Compose capabilities validated in the LXC user namespace:": "Composez les capacités validées dans l'espace de noms d'utilisateur LXC :", + "Compose file of the application": "Composer le dossier de la demande", + "Compose file of this host": "Composez le fichier de cet hôte", "Compressed size:": "Taille compressée :", "Compressing": "Compression", "Compression Tools": "Outils de compression", "Concise output of logical volumes": "Sortie concise des volumes logiques", "Concise output of physical volumes": "Sortie concise des volumes physiques", "Concise output of volume groups": "Sortie concise des groupes de volumes", + "Concurrent change while restoring the start at boot setting": "Changement simultané lors de la restauration du démarrage au réglage du démarrage", "Configuration Analysis": "Analyse de configuration", "Configuration Menu": "Menu de configuration", "Configuration Summary:": "Résumé de la configuration :", @@ -666,11 +915,13 @@ "Configuration can continue now and will be effective after reboot.": "La configuration peut continuer maintenant et sera effective après le redémarrage.", "Configuration completed successfully!": "Configuration terminée avec succès !", "Configuration file for container": "Fichier de configuration pour le conteneur", + "Configuration files generated:": "Fichiers de configuration générés :", "Configuration has been stopped due to high reset risk.": "La configuration a été arrêtée en raison d'un risque élevé de réinitialisation.", "Configuration has been stopped to prevent an unusable VM state.": "La configuration a été arrêtée pour éviter un état de VM inutilisable.", "Configuration has been stopped to prevent leaving the VM in an unusable state.": "La configuration a été arrêtée pour éviter de laisser la VM dans un état inutilisable.", "Configuration name:": "Nom de la configuration :", "Configuration sections that will be REMOVED": "Sections de configuration qui seront SUPPRIMÉES", + "Configuration size in GB": "Taille de configuration en GB", "Configuration to be Removed": "Configuration à supprimer", "Configuration will continue now and be effective after reboot.": "La configuration va continuer maintenant et sera effective après le redémarrage.", "Configuration:": "Configuration:", @@ -713,6 +964,7 @@ "Configuring Proxmox jail...": "Configuration de la prison Proxmox...", "Configuring TCP optimizations...": "Configuration des optimisations TCP...", "Configuring TPM device": "Configuration du périphérique TPM", + "Configuring Unpackerr...": "Configuration de Unpackerr...", "Configuring VFIO modules...": "Configuration des modules VFIO...", "Configuring VM": "Configuration de la VM", "Configuring bandwidth limit for vzdump...": "Configuration de la limite de bande passante pour vzdump...", @@ -728,8 +980,11 @@ "Configuring max FD limit / ulimit...": "Configuration de la limite FD maximale / ulimit...", "Configuring max user watches...": "Configuration du nombre maximal de montres utilisateur...", "Configuring pigz as a faster replacement for gzip...": "Configuration de pigz comme remplacement plus rapide de gzip...", + "Configuring qBittorrent...": "Configuration de qBittorrent...", "Configuring snapshot schedules...": "Configuration des planifications d'instantanés...", "Configuring system time settings...": "Configuration des paramètres d'heure du système...", + "Configuring the Radarr root folder...": "Configuration du dossier racine Radarr...", + "Configuring the Sonarr root folder...": "Configuration du dossier racine Sonarr...", "Configuring vfio-pci binding...": "Configuration de la liaison vfio-pci...", "Confirm Borg passphrase": "Confirmer la phrase secrète Borg", "Confirm Borg passphrase:": "Confirmez la phrase secrète de Borg :", @@ -751,6 +1006,7 @@ "Confirm export": "Confirmer l'exportation", "Confirm password for": "Confirmer le mot de passe pour", "Confirm recovery passphrase:": "Confirmez la phrase secrète de récupération :", + "Confirm that host data is not reverted": "Confirmer que les données de l'hôte ne sont pas retournées", "Confirm the keyfile passphrase:": "Confirmez la phrase secrète du fichier clé :", "Confirm the mount path is visible.": "Confirmez que le chemin de montage est visible.", "Confirm the password:": "Confirmez le mot de passe :", @@ -762,7 +1018,11 @@ "Conflicting path included in backup:": "Chemin d'accès en conflit inclus dans la sauvegarde :", "Conflicting utilities removed": "Utilitaires en conflit supprimés", "Connect a Coral Accelerator and try again.": "Connectez un accélérateur Coral et réessayez.", + "Connect your devices and users together in your own secure virtual private network.": "Connectez vos appareils et utilisateurs ensemble dans votre propre réseau privé virtuel sécurisé.", + "Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.": "Connectez vos appareils à un réseau de superposition sécurisé basé sur WireGuard® avec des contrôles d'accès SSO, MFA et granulaires.", "Connected": "Connecté", + "Connecting Radarr to qBittorrent...": "Connexion Radarr à qBittorrent...", + "Connecting Sonarr to qBittorrent...": "Connexion Sonarr à qBittorrent...", "Connecting to PBS and starting backup...": "Connexion à PBS et démarrage de la sauvegarde...", "Connection Details:": "Détails de connexion :", "Connection Error": "Erreur de connexion", @@ -774,6 +1034,7 @@ "Consider removing its configuration": "Pensez à supprimer sa configuration", "Consider security implications for production environments": "Tenir compte des implications en matière de sécurité pour les environnements de production", "Consider visiting the repository and supporting the project.": "pensez à visiter le référentiel et à soutenir le projet.", + "Console log:": "Registre de la console & #160;:", "Container": "Récipient", "Container — LXC root directories": "Conteneur — Répertoires racine LXC", "Container ID": "ID du conteneur", @@ -783,30 +1044,50 @@ "Container Path": "Chemin du conteneur", "Container Path:": "Chemin du conteneur :", "Container Status": "Statut du conteneur", + "Container checked": "Conteneur vérifié", "Container configuration not found": "Configuration du conteneur introuvable", + "Container configured (not started):": "Conteneur configuré (non démarré):", + "Container converted to privileged": "Conteneur converti en privilégié", + "Container created:": "Conteneur créé & #160;:", "Container did not become ready in time. Skipping driver installation.": "Le conteneur n’est pas prêt à temps. Ignorer l'installation du pilote.", "Container did not start in time.": "Le conteneur n'a pas démarré à temps.", "Container distro": "Distribution de conteneurs", "Container does not have apt-get available. Coral driver installation only supports Debian/Ubuntu containers.": "Le conteneur n’a pas apt-get disponible. L'installation du pilote Coral prend uniquement en charge les conteneurs Debian/Ubuntu.", + "Container installed, but without a verifiable record for future updates.": "Conteneur installé, mais sans enregistrement vérifiable pour les mises à jour futures.", "Container is already stopped.": "Le conteneur est déjà arrêté.", "Container is running. Restart to apply changes?": "Le conteneur est en cours d'exécution. Redémarrer pour appliquer les modifications ?", "Container is stopped. Start it now to verify the mount works?": "Le conteneur est arrêté. Le démarrer maintenant pour vérifier que le montage fonctionne ?", + "Container kept with its data; the installation was not validated:": "Conteneur conservé avec ses données; l'installation n'a pas été validée:", "Container mount point:": "Point de montage du conteneur :", "Container must be stopped before conversion": "Le conteneur doit être arrêté avant la conversion", + "Container prepared for the stack:": "Récipient préparé pour la cheminée:", + "Container recreated": "Conteneur recréé", + "Container removed:": "Récipient enlevé:", "Container restarted successfully": "Le conteneur a redémarré avec succès", + "Container running steadily": "Conteneur fonctionnant régulièrement", + "Container started": "Conteneur démarré", "Container started successfully": "Le conteneur a démarré avec succès", "Container started successfully.": "Le conteneur a démarré avec succès.", "Container started.": "Le conteneur a démarré.", + "Container stopped": "Conteneur arrêté", "Container stopped.": "Conteneur arrêté.", "Container successfully converted to privileged.": "Conteneur converti avec succès en privilège.", "Container template— LXC templates": "Modèle de conteneur – Modèles LXC", + "Container volume": "Volume du conteneur", + "Container volume (included in backups)": "Volume des conteneurs (inclus dans les sauvegardes)", "Container will pick up the mount on next start": "Le conteneur récupérera la monture au prochain démarrage", "Container with ID": "Conteneur avec ID", "Container:": "Récipient:", + "Containers & Docker": "Conteneurs & Docker", + "Containers returned to their previous state": "Conteneurs retournés à leur état précédent", + "Containers that are removed:": "Conteneurs enlevés:", + "Containers that will be created (one LXC per service, on a private network):": "Conteneurs qui seront créés (un LXC par service, sur un réseau privé):", + "Containers:": "Conteneurs:", "Contains files": "Contient des fichiers", "Contains:": "Contient:", "Content Types": "Types de contenu", "Content Types:": "Types de contenu :", + "Content collaboration platform": "Plateforme de collaboration de contenu", "Content is usually images for VM block devices.": "Le contenu est généralement constitué d’images pour les périphériques de bloc VM.", "Content type is fixed to:": "Le type de contenu est fixé à :", "Content:": "Contenu:", @@ -817,10 +1098,12 @@ "Continue the Windows installation as usual.": "Continuez l'installation de Windows comme d'habitude.", "Continue with Coral TPU configuration only?": "Continuer avec la configuration Coral TPU uniquement ?", "Continue with live apply now? SSH may disconnect immediately.": "Continuer avec la candidature en direct maintenant ? SSH peut se déconnecter immédiatement.", + "Continue with the experimental HAOS One profile?": "Continuer avec le profil expérimental HAOS One?", "Continue with the import?": "Continuer l'importation ?", "Continue: Proceed with conversion": "Continuer : procéder à la conversion", "Continue?": "Continuer?", "Continuing with your selection.": "Poursuivez votre sélection.", + "Contradictory tmpfs options": "Options contradictoires tmpfs", "Controller": "Contrôleur", "Controller + NVMe": "Contrôleur + NVMe", "Controller + NVMe assignment will be written now and become active after host reboot.": "L'affectation Contrôleur + NVMe sera écrite maintenant et deviendra active après le redémarrage de l'hôte.", @@ -849,7 +1132,11 @@ "Converting disk": "Conversion de disque", "Converting file ownership (this may take several minutes)...": "Conversion de la propriété du fichier (cela peut prendre plusieurs minutes)...", "Converting image using command:": "Conversion d'image à l'aide de la commande :", + "Converting the container to privileged...": "Convertir le conteneur en...", "Converts to deb822; keeps .list backups as .bak": "Convertit en deb822 ; conserve les sauvegardes .list au format .bak", + "Coordinated backups require zstd": "Sauvegardes coordonnées require zstd", + "Cops by Sébastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server.": "Cops de Sébastien Lucas, maintenant maintenu par MikesPub, représente Calibre OPDS (and HTML) Php Server.", + "Copy a peer configuration to the host with: pct pull /config/peer1/peer1.conf peer1.conf": "Copier une configuration par les pairs dans l'hôte avec : pct pull /config/peer1/peer1.conf peer1.conf", "Copy failed": "échec de la copie", "Copy that file offsite yourself, or download it from the Monitor.": "copiez vous-même ce fichier hors site ou téléchargez-le depuis le moniteur.", "Copy the correct keyfile to this host and rerun Restore — or pick an unencrypted backup.": "copiez le fichier de clés correct sur cet hôte et réexécutez la restauration – ou choisissez une sauvegarde non cryptée.", @@ -864,6 +1151,7 @@ "Coral M.2 Apex configuration added - device ready": "Configuration Coral M.2 Apex ajoutée - appareil prêt", "Coral M.2 Apex configuration added - device will be available after reboot": "Configuration Coral M.2 Apex ajoutée - l'appareil sera disponible après le redémarrage", "Coral M.2 Apex detected, configuring...": "Coral M.2 Apex détecté, configuration...", + "Coral PCIe/M.2 node (e.g. /dev/apex_0)": "Coral PCIe/M.2 noeud (par exemple /dev/apex 0)", "Coral TPU Installation": "Installation du TPU Coral", "Coral TPU Uninstall": "Désinstallation de Coral TPU", "Coral TPU device nodes detected with correct group (apex).": "Nœuds de périphérique Coral TPU détectés avec le groupe correct (apex).", @@ -876,19 +1164,33 @@ "Coral USB configured but device not currently connected": "Coral USB configuré mais l'appareil n'est pas actuellement connecté", "Coral USB runtime installed. No reboot required.": "Le runtime Coral USB est installé. Aucun redémarrage requis.", "Coral hardware configuration completed for container": "Configuration matérielle Coral terminée pour le conteneur", + "Coral is only offered for Frigate and CodeProject.AI": "Coral est offert uniquement pour Frigate et CodeProject. AI", "Coral kernel modules unloaded.": "Modules noyau Coral déchargés.", "Coral packages purged.": "Paquets Coral purgés.", "Coral uninstallation completed.": "Désinstallation de Coral terminée.", "Core Proxmox packages reinstalled successfully": "Packages Core Proxmox réinstallés avec succès", + "Core is running, but not responding over HTTP on 80/8123": "Core fonctionne, mais ne répond pas par HTTP sur 80/8123", + "Core is still on the initial installation page": "Core est toujours sur la page d'installation initiale", "Core packages": "Forfaits de base", + "Cores": "Noyaux", + "Corrupted gzip layer": "Couche gzip corrompue", "Could not add": "Impossible d'ajouter", "Could not add disk": "Impossible d'ajouter un disque", + "Could not add the device to the container:": "Impossible d'ajouter l'appareil au conteneur :", + "Could not add the mount point:": "Impossible d'ajouter le point de montage :", + "Could not apply the Compose extra hosts": "Impossible d'appliquer les hôtes supplémentaires Compose", + "Could not apply the Compose supplementary groups": "Impossible d'appliquer les groupes supplémentaires Compose", + "Could not apply the Jellyfin configuration:": "Impossible d'appliquer la configuration Jellyfin :", + "Could not apply the installer profile": "Impossible d'appliquer le profil d'installation", + "Could not apply the pre-start repair:": "Impossible d'appliquer la réparation prédémarrage :", "Could not assign disk": "Impossible d'attribuer le disque", "Could not authorize the key via 'pct exec' on": "Impossible d'autoriser la clé via 'pct exec' sur", "Could not back up the existing auth.json": "Impossible de sauvegarder le auth.json existant", "Could not change VM virtual display to vga: std": "Impossible de changer l'affichage virtuel de la VM en VGA : std", + "Could not check the NVIDIA GPU": "Impossible de vérifier le GPU NVIDIA", "Could not clone any gasket-driver repository. Check your internet connection and": "Impossible de cloner un dépôt gasket-driver. Vérifiez votre connexion Internet et", "Could not configure IOMMU kernel parameters automatically. Configure manually and reboot.": "Impossible de configurer automatiquement les paramètres du noyau IOMMU. Configurez manuellement et redémarrez.", + "Could not convert the OCI rootfs to privileged": "Impossible de convertir les roofs de l'OCI en privilégiés", "Could not copy the PVE keyfile into place. Check permissions on:": "Impossible de copier le fichier de clés PVE.Vérifiez les autorisations sur :", "Could not copy the keyfile into place.": "Impossible de copier le fichier de clés.", "Could not copy the keyfile into place. Check permissions on:": "Impossible de copier le fichier de clés. Vérifiez les autorisations sur :", @@ -898,6 +1200,9 @@ "Could not create or access directory:": "Impossible de créer ou d'accéder au répertoire :", "Could not create temporary directory:": "Impossible de créer le répertoire temporaire :", "Could not create temporary working directory.": "Impossible de créer un répertoire de travail temporaire.", + "Could not create the container:": "Impossible de créer le conteneur :", + "Could not create the initial administrator": "Impossible de créer l'administrateur initial", + "Could not create the service:": "Impossible de créer le service :", "Could not detect apex major number from /proc/devices. Load the apex module first: modprobe apex": "Impossible de détecter le numéro majeur apex à partir de /proc/devices. Chargez d'abord le module apex : modprobe apex", "Could not detect the CIFS mount for this directory. Try accessing it manually.": "Impossible de détecter le montage CIFS pour ce répertoire. Essayez d'y accéder manuellement.", "Could not determine a valid ISO storage directory.": "Impossible de déterminer un répertoire de stockage ISO valide.", @@ -907,7 +1212,9 @@ "Could not download recovery blob from PBS.": "Impossible de télécharger le blob de récupération depuis PBS.", "Could not download the NVIDIA Container Toolkit repository definition.": "Impossible de télécharger la définition du référentiel NVIDIA Container Toolkit.", "Could not download the NVIDIA Container Toolkit signing key.": "Impossible de télécharger la clé de signature NVIDIA Container Toolkit.", + "Could not download the image": "Impossible de télécharger l'image", "Could not download the installer.": "Impossible de télécharger le programme d'installation.", + "Could not enable the privileged profile before the first start": "Impossible d'activer le profil privilégié avant le premier départ", "Could not export ZFS pool": "Impossible d'exporter le pool ZFS", "Could not extract from PBS.": "Impossible d'extraire du PBS.", "Could not fetch keylase/nvidia-patch supported list — patch reapply compatibility is not verified.": "Impossible de récupérer la liste des correctifs keylase/nvidia pris en charge : la compatibilité de la réapplication du correctif n'est pas vérifiée.", @@ -921,34 +1228,53 @@ "Could not install exFAT tools automatically.": "Impossible d'installer automatiquement les outils exFAT.", "Could not install sshpass automatically (no internet?). Falling back to manual paste mode — you'll see the line to copy onto the server next.": "Impossible d'installer sshpass automatiquement (pas d'Internet ?).En revenant au mode de collage manuel, vous verrez ensuite la ligne à copier sur le serveur.", "Could not install the NVIDIA Container Toolkit signing key.": "Impossible d'installer la clé de signature NVIDIA Container Toolkit.", + "Could not install the required packages:": "Impossible d'installer les paquets required :", + "Could not install the stack startup hook": "Impossible d'installer le crochet de démarrage de la pile", "Could not install vzdump hook in /etc/vzdump.conf": "Impossible d'installer le hook vzdump dans /etc/vzdump.conf", "Could not load shared functions. Script cannot continue.": "Impossible de charger les fonctions partagées. Le script ne peut pas continuer.", + "Could not load the host kernel module:": "Impossible de charger le module du noyau hôte :", "Could not locate imported disk in VM config.": "Impossible de localiser le disque importé dans la configuration de la VM.", "Could not mount": "Impossible de monter", "Could not mount ISO on device": "Impossible de monter l'ISO sur l'appareil", + "Could not mount the container filesystem:": "Impossible de monter le système de fichiers conteneur :", + "Could not obtain an intact image after two attempts": "Impossible d'obtenir une image intacte après deux tentatives", "Could not parse OVF file, or no disk image references found.": "Impossible d'analyser le fichier OVF ou aucune référence d'image disque n'a été trouvée.", "Could not prepare on-boot restore service. Nothing new was scheduled.": "Impossible de préparer le service de restauration au démarrage. Rien de nouveau n'était prévu.", + "Could not prepare the NVIDIA driver links": "Impossible de préparer les liens du pilote NVIDIA", + "Could not prepare the file bind mount target:": "Impossible de préparer le fichier lier la cible de montage :", "Could not publish pending restore. Previous pending restore was kept.": "Impossible de publier la restauration en attente. La restauration précédente en attente a été conservée.", "Could not push the key. Check the password and that": "Impossible d'appuyer sur la clé. Vérifiez le mot de passe et cela", + "Could not query the image registry": "Impossible d'interroger le registre d'images", "Could not read SMART data from": "Impossible de lire les données SMART de", "Could not read VM configuration.": "Impossible de lire la configuration de la VM.", + "Could not read the CUDA compute capability": "Impossible de lire la capacité de calcul CUDA", + "Could not read the NVIDIA driver version": "Impossible de lire la version du pilote NVIDIA", "Could not remount automatically. Try manually or check credentials.": "Impossible de remonter automatiquement. Essayez manuellement ou vérifiez les informations d'identification.", "Could not remove VM automatically. Run manually:": "Impossible de supprimer automatiquement la VM. Exécuter manuellement :", "Could not remove previous DKMS tree at": "Impossible de supprimer l'arborescence DKMS précédente à", + "Could not reserve a private network for the stack": "Impossible de réserver un réseau privé pour la pile", + "Could not resolve the Compose user:": "Impossible de résoudre l'utilisateur Composer :", + "Could not resolve the OCI manifest of the image:": "Impossible de résoudre le manifeste de l'image :", + "Could not resolve the OCI manifest:": "Impossible de résoudre le manifeste du BEC :", "Could not restart ProxMenux Monitor service.": "Impossible de redémarrer le service ProxMenux Monitor.", "Could not restart the service — start it manually with systemctl start": "Impossible de redémarrer le service - démarrez-le manuellement avec systemctl start", "Could not retrieve versions list from NVIDIA. Please check your internet connection.": "Impossible de récupérer la liste des versions de NVIDIA. Veuillez vérifier votre connexion Internet.", + "Could not reuse the persistent disk:": "Impossible de réutiliser le disque persistant :", "Could not run NVIDIA patch script. Please verify repository and driver version.": "Impossible d'exécuter le script de correctif NVIDIA. Veuillez vérifier le référentiel et la version du pilote.", "Could not set VM virtual display to vga: std": "Impossible de définir l'affichage virtuel de la VM sur VGA : std", "Could not set boot order for": "Impossible de définir l'ordre de démarrage pour", + "Could not set the container entrypoint": "Impossible de définir le point d'entrée du conteneur", "Could not stage pending restore path:": "Impossible de préparer le chemin de restauration en attente :", "Could not stage pending restore. Nothing new was scheduled.": "Impossible d’effectuer la restauration en attente. Rien de nouveau n'était prévu.", "Could not stop LXC": "Impossible d'arrêter LXC", + "Could not translate the Compose command/entrypoint": "Impossible de traduire la commande/point d'entrée Compose", "Could not unload nouveau module (may be in use). The blacklist will take effect after reboot. Installation will continue but a reboot will be required.": "Impossible de décharger le nouveau module (peut-être en cours d'utilisation). La liste noire prendra effet après le redémarrage. L'installation continuera mais un redémarrage sera nécessaire.", "Could not unmount": "Impossible de démonter", + "Could not unmount the container filesystem:": "Impossible de démonter le système de fichiers conteneur :", "Could not unmount — disk may be busy. Removing fstab entry anyway.": "Impossible de démonter : le disque est peut-être occupé. Suppression de l'entrée fstab de toute façon.", "Could not update config file.": "Impossible de mettre à jour le fichier de configuration.", "Could not write to:": "impossible d'écrire vers :", + "Crafty Controller default login": "Connexion par défaut du contrôleur Crafty", "Create Directory": "Créer un répertoire", "Create GPT and one partition:": "Créez GPT et une partition :", "Create GPT partition": "Créer une partition GPT", @@ -971,6 +1297,7 @@ "Create a fresh GPT + ext4 partition and mount it?": "Créer une nouvelle partition GPT + ext4 et la monter ?", "Create a new dataset in a ZFS pool": "Créer un nouvel ensemble de données dans un pool ZFS", "Create a new group for isolation": "Créer un nouveau groupe pour l'isolement", + "Create and edit Matroska files from a browser": "Créer et modifier des fichiers Matroska depuis un navigateur", "Create credentials file (recommended):": "Créer un fichier d'informations d'identification (recommandé) :", "Create directory": "Créer un répertoire", "Create export directory:": "Créer un répertoire d'exportation :", @@ -982,6 +1309,7 @@ "Create scheduled backup job": "Créer une tâche de sauvegarde planifiée", "Create share directory:": "Créer un répertoire de partage :", "Create shared directory:": "Créer un répertoire partagé :", + "Create this LXC in privileged mode?": "Créer ce LXC en mode privilégié ?", "Created common remapped user": "Création d'un utilisateur remappé commun", "Created directory on host:": "Répertoire créé sur l'hôte :", "Created persistent names for": "Création de noms persistants pour", @@ -996,6 +1324,8 @@ "Creating UID remapping for unprivileged container compatibility...": "Création d'un remappage UID pour une compatibilité de conteneurs non privilégiés...", "Creating VM with the above configuration": "Création d'une VM avec la configuration ci-dessus", "Creating VM...": "Création d'une VM...", + "Creating a backup of": "Créer une sauvegarde de", + "Creating a backup of the container...": "Création d'une sauvegarde du conteneur...", "Creating backup of configuration file...": "Création d'une sauvegarde du fichier de configuration...", "Creating backup of network interfaces configuration...": "Création d'une sauvegarde de la configuration des interfaces réseau...", "Creating compressed archive...": "Création d'une archive compressée...", @@ -1005,6 +1335,11 @@ "Creating partition table and partition...": "Création d'une table de partition et d'une partition...", "Creating partition...": "Création d'une partition...", "Creating pigz wrapper script...": "Création du script wrapper pigz...", + "Creating the backup": "Création de la sauvegarde", + "Creating the container...": "Créer le conteneur...", + "Creating the initial administrator...": "Création de l'administrateur initial...", + "Creating the temporary data container": "Création du conteneur temporaire de données", + "Creative & Design": "Création & Design", "Credentials are correct": "Les informations d'identification sont correctes", "Credentials cleared. jwt_secret and API tokens preserved.": "Informations d'identification effacées. Jwt_secret et jetons API préservés.", "Credentials file created securely.": "Fichier d’informations d’identification créé en toute sécurité.", @@ -1014,6 +1349,8 @@ "Cross-host restore: guest IDs in backup overlap live IDs on target:": "Restauration entre hôtes : les ID d'invité dans la sauvegarde chevauchent les ID actifs sur la cible :", "Cross-kernel restore — kernel-tied paths merged, not copied": "Restauration inter-noyau – chemins liés au noyau fusionnés, non copiés", "Cross-kernel — paths hidden from picker": "Cross-kernel – chemins cachés du sélecteur", + "Cross-platform file sharing made easy.": "Partage de fichiers multiplateforme rendu facile.", + "Cross-platform monitoring tool.": "Outil de surveillance multiplateforme.", "Cross-version detected — safe restore mode": "Version croisée détectée – mode de restauration sécurisé", "Current": "Actuel", "Current CIFS mounts:": "Montages CIFS actuels :", @@ -1023,6 +1360,8 @@ "Current NFS client script supports privileged LXC only.": "Le script client NFS actuel prend uniquement en charge LXC privilégié.", "Current NFS exports in CT": "Exportations NFS actuelles dans CT", "Current NFS mounts:": "Montages NFS actuels :", + "Current NVIDIA inventory resolved: a refresh is required": "L'inventaire actuel de NVIDIA résolu: un rafraîchissement est required", + "Current NVIDIA inventory resolved: no refresh is required": "L'inventaire actuel de NVIDIA résolu: aucun rafraîchissement n'est required", "Current Network Configuration": "Configuration réseau actuelle", "Current PVE Version": "Version PVE actuelle", "Current ProxMenux host scripts register remote shares as Proxmox storages using pvesm.": "Les scripts hôtes ProxMenux actuels enregistrent les partages distants en tant que stockages Proxmox à l'aide de pvesm.", @@ -1046,6 +1385,7 @@ "Current user": "Utilisateur actuel", "Current user UID, GID and groups": "UID, GID et groupes de l'utilisateur actuel", "Current version:": "Version actuelle :", + "Currently": "Actuellement", "Currently Mounted:": "Actuellement monté :", "Currently configured target:": "cible actuellement configurée :", "Currently mounted:": "Actuellement monté :", @@ -1066,6 +1406,7 @@ "Custom message added to MOTD": "Message personnalisé ajouté à MOTD", "Custom options": "Options personnalisées", "Custom path": "Chemin personnalisé", + "Custom path cancelled": "Chemin personnalisé annulé", "Custom path...": "Chemin personnalisé...", "Custom paths are included in BOTH default and custom backup profiles.": "Les chemins personnalisés sont inclus dans les profils de sauvegarde par défaut et personnalisés.", "Custom paths currently saved: {count}.": "Chemins personnalisés actuellement enregistrés : {count}.", @@ -1078,6 +1419,8 @@ "Customization": "Personnalisation", "Customize bashrc": "Personnaliser bashrc", "Customizing bashrc for root user...": "Personnalisation de bashrc pour l'utilisateur root...", + "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite.": "DB Browser for SQLite est un outil de haute qualité, visuel, open source pour créer, concevoir et éditer des fichiers de base de données compatibles avec SQLite.", + "DHCP (automatic)": "DHCP (automatique)", "DISABLED unless you enable it": "DÉSACTIVÉ sauf si vous l'activez", "DKMS add failed. Check": "L'ajout de DKMS a échoué. Vérifier", "DKMS build failed.": "La construction de DKMS a échoué.", @@ -1090,15 +1433,34 @@ "DKMS registrations removed.": "enregistrements DKMS supprimés.", "DNS Resolution": "Résolution DNS", "DNS lookup for a domain": "Recherche DNS pour un domaine", + "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)": "plugin DNS utilisé avec validation dns (cloudflare, duckdns, ovh...)", + "DNS server written in the client configurations": "Serveur DNS écrit dans les configurations du client", + "DNS server written in the peer configurations (auto or an IP address)": "Serveur DNS écrit dans les configurations par les pairs (auto ou adresse IP)", + "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid.": "DOGWALK est le deuxième projet de jeu de Blender Studio longtemps attendu, axé sur la création d'un terrain de conte interactif de taille bouchée. Jouer comme un grand chien adorable et explorer les bois d'hiver avec un petit enfant.", + "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games.": "DOSBox Staging est une suite moderne de DOSBox un émulateur libre et open-source qui permet l'exécution de logiciels MS-DOS, en particulier les jeux vidéo.", + "DVB device directory": "Répertoire des périphériques DVB", + "Data": "Données", + "Data location": "Emplacement des données", "Data size:": "Taille des données :", + "Data that is deleted with them:": "Données supprimées avec elles:", + "Data volume size in GB": "Volume des données en GB", + "Data volumes protected": "Volumes de données protégés", "Data wipe complete.": "Effacement des données terminé.", "Data wiped from": "Données effacées de", + "Database management in a single PHP file": "Gestion de la base de données dans un seul fichier PHP", + "Database server proposed on the login page (empty = typed at each login)": "Serveur de base de données proposé sur la page de connexion (vide = tapé à chaque connexion)", + "Databases": "Bases de données", "Datastore name:": "Nom de la banque de données :", + "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow.": "Davos est un outil d'automatisation FTP qui scanne périodiquement les emplacements de l'hôte pour les nouveaux fichiers. Il peut être configuré à diverses fins, y compris l'écoute de fichiers spécifiques à apparaître dans l'emplacement de l'hôte, prêt à être téléchargé puis déplacé, si required. Il prend également en charge les notifications d'achèvement ainsi que les appels d'API en aval, afin d'améliorer le flux de travail.", + "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways.": "Ddclient est un client Perl utilisé pour mettre à jour les entrées DNS dynamiques pour les comptes sur Dynamic DNS Network Service Provider. Il a été initialement écrit par Paul Burry et est maintenant principalement par wimpunk. Il a la capacité de mettre à jour plus que des dyndns et il peut récupérer votre adresse WAN de plusieurs façons différentes.", "Deactivate Monitor": "Désactiver le moniteur", "Deactivate ProxMenux Monitor": "Désactiver le ProxMenux Monitor", "Debian repositories missing; creating default source file": "Dépôts Debian manquants ; création du fichier source par défaut", "Decompress backup manually": "Décompresser la sauvegarde manuellement", "Decryption failed. The passphrase may be wrong, or the blob is corrupt. Try again?": "Le décryptage a échoué. La phrase secrète est peut-être erronée ou le blob est corrompu. Essayer à nouveau?", + "Dedicated container volume (included in backups)": "Volume du conteneur dédié (inclus dans les sauvegardes)", + "Dedicated container volumes (included in backups)": "Volumes de conteneurs dédiés (inclus dans les sauvegardes)", + "DeepSeek Harness “Everything is a Plugin“.": "Harnais DeepSeek Tout est un Plugin.", "Default ACLs applied for group inheritance.": "ACL par défaut appliquées pour l’héritage de groupe.", "Default Credentials": "Informations d'identification par défaut", "Default Gateway": "Passerelle par défaut", @@ -1110,10 +1472,12 @@ "Default journald configuration restored": "Configuration journald par défaut restaurée", "Default location is /mnt/. The share will be mounted here on the host with open permissions so an unprivileged LXC can bind-mount and write to it. For LXC access, bind-mount this path with the LXC Mount Manager.": "L'emplacement par défaut est /mnt/. Le partage sera monté ici sur l'hôte avec des autorisations ouvertes afin qu'un LXC non privilégié puisse y effectuer un montage en liaison et y écrire. Pour l'accès LXC, montez en liaison ce chemin avec le gestionnaire de montage LXC.", "Default location is /mnt/. The share will be mounted here on the host. Use this path in /etc/fstab. For LXC access, bind-mount this path with the LXC Mount Manager.": "L'emplacement par défaut est /mnt/. Le partage sera monté ici sur l'hôte. Utilisez ce chemin dans /etc/fstab. Pour l'accès LXC, montez en liaison ce chemin avec le gestionnaire de montage LXC.", + "Default login": "Connexion par défaut", "Default options": "Options par défaut", "Default options read/write": "Options par défaut lecture/écriture", "Default will be used:": "la valeur par défaut sera utilisée :", "Default:": "Par défaut :", + "Default: only what the application needs": "Par défaut : seulement ce dont l'application a besoin", "Delete Borg target": "Supprimer la cible Borg", "Delete Export": "Supprimer l'exportation", "Delete Share": "Supprimer le partage", @@ -1122,7 +1486,10 @@ "Delete archive": "Supprimer les archives", "Delete job": "Supprimer le travail", "Delete scheduled backup job?": "Supprimer la tâche de sauvegarde planifiée ?", + "Delete the image to free the space?": "Supprimer l'image pour libérer l'espace ?", + "Delete the images to free the space?": "Supprimer les images pour libérer l'espace ?", "Delete this corrupt archive and pick another": "Supprimez cette archive corrompue et choisissez-en une autre", + "Deluge is a lightweight, Free Software, cross-platform BitTorrent client.": "Deluge est un client BitTorrent léger, logiciel libre, multiplateforme.", "Dependencies installed successfully": "Dépendances installées avec succès", "Deploy with this configuration?": "Déployer avec cette configuration ?", "Deploying Secure Gateway...": "Déploiement de Secure Gateway...", @@ -1177,9 +1544,15 @@ "Device added": "Appareil ajouté", "Device already present in target VM — existing hostpci entry reused": "Périphérique déjà présent dans la VM cible — entrée hostpci existante réutilisée", "Device assignments will be written now and become active after reboot.": "Les affectations de périphériques seront écrites maintenant et deviendront actives après le redémarrage.", + "Device configuration cancelled": "Configuration du périphérique annulée", "Device hostname": "Nom d'hôte de l'appareil", + "Device node outside the supported profiles": "Noeud du périphérique en dehors des profils pris en charge", + "Device outside the supported profiles; NVIDIA and device trees require another profile": "Dispositif en dehors des profils pris en charge; NVIDIA et arbres d'appareils require un autre profil", "Device path mismatch. Format cancelled.": "Incohérence du chemin du périphérique. Format annulé.", + "Device permissions verified for the application user": "Autorisations du périphérique vérifiées pour l'utilisateur de l'application", "Device:": "Appareil:", + "Devices added to the container:": "Dispositifs ajoutés au réservoir:", + "Devices of the host it asks for:": "Dispositifs de l'hôte qu'il demande:", "Devices to add to VM": "Appareils à ajouter à la VM", "Diff: current system vs backup (--- system +++ backup)": "Diff : système actuel vs sauvegarde (--- système +++ sauvegarde)", "Different host. Backup from:": "Hôte différent. Sauvegarde depuis :", @@ -1196,6 +1569,8 @@ "Directory does not exist and was not created.": "Le répertoire n'existe pas et n'a pas été créé.", "Directory does not exist:": "Le répertoire n'existe pas :", "Directory error": "Erreur d'annuaire", + "Directory for the read-only view": "Répertoire pour la vue en lecture seule", + "Directory for the read/write view": "Répertoire pour la vue lecture/écriture", "Directory not found": "Répertoire introuvable", "Directory storage added successfully to Proxmox!": "Stockage d'annuaire ajouté avec succès à Proxmox !", "Directory successfully.": "Répertoire avec succès.", @@ -1248,6 +1623,7 @@ "Disk path:": "Chemin du disque :", "Disk safety revalidation failed.": "La revalidation de la sécurité du disque a échoué.", "Disk safety validation passed.": "Validation de la sécurité du disque réussie.", + "Disk too small for the common profile": "Disque trop petit pour le profil commun", "Disk unmounted from": "Disque démonté de", "Disk verified and accessible inside CT at": "Disque vérifié et accessible à l'intérieur de CT à", "Disk:": "Disque:", @@ -1261,6 +1637,10 @@ "Display physical volumes (LVM)": "Afficher les volumes physiques (LVM)", "Display system summary in ASCII format": "Afficher le résumé du système au format ASCII", "Display volume groups (LVM)": "Afficher les groupes de volumes (LVM)", + "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer.": "Ne présumez pas que le port 8123 reste actif après l'embarquement sur Home Assistant Core 2026.8 ou plus récent.", + "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume.": "Ne prétendez pas que les mises à jour d'image de l'OCI en place sont validées jusqu'à ce que le remplacement et le renversement des rootfs aient été testés sans perdre le volume de /mnt/data géré.", + "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default.": "Ne pas activer automatiquement les GPU intégrés AMD non pris en charge. Les dépassements HSA sont des expériences de compatibilité manuelle, pas une valeur par défaut validée.", + "Do not mount": "Ne pas monter", "Do not run the upgrade from the Web UI virtual console (it will disconnect)": "N'exécutez pas la mise à niveau à partir de la console virtuelle Web UI (elle se déconnectera)", "Do not start the VM until the system has been rebooted.": "Ne démarrez pas la VM tant que le système n'a pas été redémarré.", "Do you want ProxMenux to stop it now?": "Voulez-vous que ProxMenux l'arrête maintenant ?", @@ -1304,9 +1684,23 @@ "Do you want to update the existing export?": "Voulez-vous mettre à jour l’export existant ?", "Do you want to update the existing share?": "Voulez-vous mettre à jour le partage existant ?", "Do you want to view the selected backup before restoring?": "Voulez-vous afficher la sauvegarde sélectionnée avant de la restaurer ?", + "Docker Mods are only offered for compatible LinuxServer images": "Les mods Docker sont proposés uniquement pour les images LinuxServer compatibles", + "Docker Volume Backup": "Docker Volume Backup", + "Docker/CLI not available yet or no valid answer": "Docker/CLI pas encore disponible ou pas de réponse valide", + "Documents & Notes": "Documents et notes", + "Documents volume size in GB": "Volume des documents en GB", + "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki.": "Dokuwiki est un logiciel wiki Open Source simple à utiliser et très polyvalent qui ne require une base de données. Il est aimé par les utilisateurs pour sa syntaxe propre et lisible. La facilité de maintenance, de sauvegarde et d'intégration en fait le favori d'un administrateur. Construit dans les contrôles d'accès et les connecteurs d'authentification font DokuWiki particulièrement utile dans le contexte de l'entreprise et le grand nombre de plugins fournis par sa communauté dynamique permettent une large gamme de cas d'utilisation au-delà d'un wiki traditionnel.", + "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience.": "Dolphin Emulator vous permet de jouer à des jeux GameCube et Wii avec différentes améliorations graphiques et d'autres fonctionnalités sont disponibles pour améliorer votre expérience de jeu.", + "Domain for the certificate (example.com)": "Domaine pour le certificat (example.com)", + "Doplarr is an *arr request bot for Discord.\"": "Doplarr est un bot *arr request pour Discord.\"", + "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust.": "Doplarr_rs est un robot Discord pour demander des médias à travers *arr backends, écrit dans Rust.", + "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas.": "Double Commander est un gestionnaire de fichiers gratuit cross open source avec deux panneaux côte à côte. Il est inspiré par Total Commander et présente de nouvelles idées.", + "Download Spotify music with album art and metadata": "Télécharger Spotify musique avec album art et métadonnées", "Download failed for all attempted URLs": "Le téléchargement a échoué pour toutes les tentatives d'URL", + "Download its Compose file from an address": "Télécharger son fichier Composer depuis une adresse", "Download keyfile": "Télécharger le fichier clé", "Download latest VirtIO ISO automatically": "Téléchargez automatiquement la dernière version ISO de VirtIO", + "Downloaded OCI images deleted:": "Images téléchargées du BEC supprimées:", "Downloaded amdgpu_top": "Téléchargé amdgpu_top", "Downloading": "Téléchargement", "Downloading Helper-Scripts logo...": "Téléchargement du logo Helper-Scripts...", @@ -1318,45 +1712,86 @@ "Downloading amdgpu_top": "Téléchargement de amdgpu_top", "Downloading official installer...": "Téléchargement du programme d'installation officiel...", "Downloading pre-existing encrypted backups from this host will fail unless you kept a copy of the current key.": "Le téléchargement de sauvegardes chiffrées préexistantes à partir de cet hôte échouera à moins que vous ne conserviez une copie de la clé actuelle.", + "Downloading the image:": "Téléchargement de l'image :", "Downloading the latest Fastfetch release...": "Téléchargement de la dernière version de Fastfetch...", "Driver blacklist entries removed": "Entrées de la liste noire des pilotes supprimées", "Driver blacklist removed for": "Liste noire des pilotes supprimée pour", "Driver installed successfully. Press Enter to continue...": "Pilote installé avec succès. Appuyez sur Entrée pour continuer...", "Drivers :": "Pilotes :", "Drivers compiled and installed via DKMS.": "Pilotes compilés et installés via DKMS.", + "Dry run completed; no changes were made.": "Le parcours à sec est terminé; aucun changement n'a été apporté.", + "Dry run completed; no containers were created.": "Le parcours à sec est terminé; aucun conteneur n'a été créé.", + "Dry run completed; the container and the mounts were not changed.": "Le parcours à sec est terminé; le conteneur et les supports n'ont pas été changés.", + "DuckDNS subdomain without .duckdns.org (comma separated for several)": "DuckDNS sous-domaine sans .duckdns.org (comma séparé pour plusieurs)", + "DuckDNS token from your account at duckdns.org": "Jeton DuckDNS de votre compte sur duckdns.org", + "DuckDNS updates the subdomain every 5 minutes. Without UPDATE_IP, DuckDNS itself detects the public IPv4 address of the request.": "DuckDNS met à jour le sous-domaine toutes les 5 minutes. Sans mise à jour, DuckDNS détecte lui-même l'adresse IPv4 publique de la requête.", + "DuckStation is a PS1 Emulator aiming for the best accuracy and game support.": "DuckStation est un émulateur PS1 visant le meilleur accuracy et le meilleur support de jeu.", + "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence.": "Duckdns est un service gratuit qui dirigera un DNS (sous-domaines de duckdns.org) vers une IP de votre choix. Le service est entièrement gratuit, et ne require réactivation ou forum posts pour maintenir son existence.", "Dumping AMD GPU ROM BIOS via sysfs...": "Vidage du BIOS ROM GPU AMD via sysfs...", "Duplicate IP addresses found": "Adresses IP en double trouvées", "Duplicate parameters cleaned": "Paramètres en double nettoyés", + "Duplicate variable in the contract; review it before editing": "Variable dupliquée dans le contrat; l'examiner avant d'éditer", + "Duplicated GPU device in the container": "Dispositif GPU double dans le conteneur", + "Duplicated NVIDIA devices": "Dispositifs NVIDIA en double", + "Duplicated VMID in the Proxmox inventory": "VMID en double dans l'inventaire Proxmox", + "Duplicated native directive:": "Directive native dupliquée:", + "Duplicated native option": "Option native dupliquée", + "Duplicated or invalid stack VMID": "VMID de pile double ou invalide", + "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others.": "Duplicati est un client de sauvegarde qui stocke en toute sécurité des sauvegardes cryptées, progressives et compressées sur le stockage local, les services de stockage en nuage et les serveurs de fichiers distants. Il fonctionne avec des protocoles standard comme FTP, SSH, WebDAV ainsi que des services populaires comme Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, et beaucoup d'autres.", + "Duplicati web interface (password only)": "Interface web Duplicati (mot de passe seulement)", "Duration": "Durée", "Duration:": "Durée:", + "Dynamic NVIDIA is only validated for unprivileged containers. This profile uses static mounts and must be recreated after the host driver changes.": "Dynamic NVIDIA n'est validé que pour les conteneurs non privilégiés. Ce profil utilise des montures statiques et doit être recréé après que le pilote hôte change.", "EFI disk created and configured on": "Disque EFI créé et configuré sur", "EFI storage selection cancelled.": "Sélection de stockage EFI annulée.", "EFI storage selection failed or was cancelled. VM creation aborted.": "La sélection du stockage EFI a échoué ou a été annulée. Création de VM abandonnée.", "EMERGENCY PROXMOX SYSTEM REPAIR": "RÉPARATION D'URGENCE DU SYSTÈME PROXMOX", "ENABLED for restore": "ACTIVÉ pour la restauration", "EXISTS": "EXISTE", + "Each /request command needs a backend: add a [[backends]] block in the same file with the url and api_key of your Sonarr, Radarr or Seerr instance, then restart the container.": "Chaque commande /request a besoin d'un backend : ajoutez un bloc [[[backends]] dans le même fichier avec l'url et api key de votre instance Sonarr, Radarr ou Seerr, puis redémarrez le conteneur.", "Each LUN will appear as a block device assignable to VMs.": "Chaque LUN apparaîtra comme un périphérique bloc attribuable aux machines virtuelles.", + "Each peer gets its configuration and its QR code inside the container: /config/peer1/peer1.conf and /config/peer1/peer1.png, or /config/peer_/peer_.conf when names were given.": "Chaque pair obtient sa configuration et son code QR à l'intérieur du conteneur : /config/peer1/peer1.conf et /config/peer1/peer1.png, ou /config/peer /peer .conf lorsque les noms ont été donnés.", + "Ebook and audiobook collection manager for Usenet and BitTorrent users.": "Gestionnaire de collection de livres électroniques et audio pour utilisateurs Usenet et BitTorrent.", + "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind.": "Eden est un émulateur open source expérimental pour le commutateur Nintendo, construit avec des performances et une stabilité à l'esprit.", "Edge TPU runtime installed.": "Le runtime Edge TPU est installé.", "Edit raw CT configuration file": "Modifier le fichier de configuration CT brut", "Edit raw VM configuration file": "Modifier le fichier de configuration brut de la VM", "Edit the VM machine type to q35 and try again.": "Modifiez le type de machine virtuelle en q35 et réessayez.", + "Email address for certificate expiry notices (required by ZeroSSL)": "Adresse électronique des avis d'expiration du certificat (required by ZeroSSL)", + "Email address of the LibreDB Studio administrator": "Adresse électronique de l'administrateur LibreDB Studio", + "Email address of the NetBox admin account": "Adresse électronique du compte administrateur NetBox", + "Emby WebUI": "Emby WebUI", + "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server.": "Emby organise la vidéo, la musique, la télévision en direct et les photos des bibliothèques de médias personnels et les diffuse vers des téléviseurs intelligents, des boîtes de streaming et des appareils mobiles. Ce conteneur est emballé comme un serveur multimédia autonome emby.", "Emergency Proxmox System Repair": "Réparation d'urgence du système Proxmox", "Emergency recovery:": "Récupération d'urgence :", + "Empowering the smart home": "Autonomiser la maison intelligente", "Empty": "Vide", + "Empty exec service check": "Vérification du service exec vide", + "Empty or duplicated NVIDIA identity": "Identité NVIDIA vide ou dupliquée", + "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes.": "EmulatorJS est une application d'émulateur basée sur Docker qui peut simuler divers systèmes operating et environnements d'appareils dans des conteneurs pour le développement, les essais et l'apprentissage.", "Enable": "Activer", "Enable / disable job timer": "Activer/désactiver le minuteur de travail", "Enable High Availability services": "Activer les services de haute disponibilité", "Enable IOMMU in GRUB or ZFS boot": "Activer IOMMU au démarrage GRUB ou ZFS", "Enable IOMMU support if not enabled": "Activer la prise en charge IOMMU si elle n'est pas activée", "Enable IOMMU, reboot the host, and try again.": "Activez IOMMU, redémarrez l'hôte et réessayez.", + "Enable Intel/AMD VA-API video acceleration": "Activer l'accélération vidéo VA-API Intel/AMD", + "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping": "Activer le transcodage NVIDIA et HDR10/Dolby Vision pour la cartographie des tons SDR", "Enable Remote Desktop (RDP) before disabling the virtual display.": "Activez le Bureau à distance (RDP) avant de désactiver l'affichage virtuel.", "Enable SSD emulation for this disk?": "Activer l'émulation SSD pour ce disque ?", "Enable TCP BBR/Fast Open control": "Activer le contrôle TCP BBR/Fast Open", + "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping": "Activer le transcodage VA-API et HDR10/Dolby Vision pour la cartographie des tons SDR", + "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin": "Activer le VA-API, l'encodage matériel et la cartographie des tons OpenCL dans Jellyfin", "Enable VFIO IOMMU support": "Activer la prise en charge de VFIO IOMMU", "Enable ZFS autotrim (SSD/NVMe pools)": "Activer le réglage automatique ZFS (pools SSD/NVMe)", + "Enable a mount on an existing Rclone OCI container": "Activer un montage sur un conteneur existant Rclone OCI", + "Enable an optical drive for MakeMKV": "Activer un lecteur optique pour MakeMKV", "Enable auto-sync if /var/log exceeds 90% of its size?": "Activer la synchronisation automatique si /var/log dépasse 90 % de sa taille ?", "Enable fast reboots": "Activer les redémarrages rapides", "Enable restart on kernel panic": "Activer le redémarrage en cas de panique du noyau", + "Enable the NVIDIA GPU requested by the image": "Activer le GPU NVIDIA demandé par l'image", + "Enable the NVIDIA GPU required by Open WebUI CUDA": "Activer le processeur GPU NVIDIA required par Open WebUI CUDA", + "Enable this FUSE mount now and restart the CT?": "Activer ce montage FUSE maintenant et redémarrer le CT ?", "Enable/Disable job": "Activer/Désactiver le travail", "Enabled": "Activé", "Enabled (device pending — load apex module or reboot)": "Activé (périphérique en attente – charger le module apex ou redémarrer)", @@ -1401,6 +1836,7 @@ "Enter a name for the mount point (used as /mnt/):": "Entrez un nom pour le point de montage (utilisé comme /mnt/) :", "Enter a name for the new virtual machine:": "Entrez un nom pour la nouvelle machine virtuelle :", "Enter a number, or write or paste a command:": "Entrez un nombre, ou écrivez ou collez une commande :", + "Enter a usable IPv4 address with its prefix, for example": "Saisissez une adresse IPv4 utilisable avec son préfixe, par exemple", "Enter backup file (.zst):": "Entrez le fichier de sauvegarde (.zst) :", "Enter backup path (.tar.zst):": "Entrez le chemin de sauvegarde (.tar.zst) :", "Enter backup path (.vma.zst):": "Entrez le chemin de sauvegarde (.vma.zst) :", @@ -1489,6 +1925,7 @@ "Enter the number or type the interface name:": "Entrez le numéro ou tapez le nom de l'interface :", "Enter the password for Samba user:": "Entrez le mot de passe de l'utilisateur Samba :", "Enter the recovery passphrase set when the keyfile was created:": "Saisissez la phrase secrète de récupération définie lors de la création du fichier de clés :", + "Enter the size in whole GB, for example": "Saisissez la taille en Go entier, par exemple", "Enter username for Samba server:": "Entrez le nom d'utilisateur pour le serveur Samba :", "Enter username:": "Entrez le nom d'utilisateur :", "Enterprise Proxmox Ceph repository disabled": "Référentiel Enterprise Proxmox Ceph désactivé", @@ -1497,6 +1934,8 @@ "Enterprise repository returned 401 Unauthorized (no valid subscription). Switch to the no-subscription repository and retry?": "Le référentiel d'entreprise a renvoyé 401 non autorisé (pas d'abonnement valide). Passer au référentiel sans abonnement et réessayer ?", "Enterprise repository unauthorized and fallback declined by user": "Dépôt d'entreprise non autorisé et solution de secours refusée par l'utilisateur", "Entropy generation optimization removed": "Optimisation de la génération d'entropie supprimée", + "Environment entry without an explicit value": "Entrée environnement sans valeur explicite", + "Environment override for an unknown service:": "Dépassement de l'environnement pour un service inconnu :", "Equivalent manual flow of disk_host.sh: partition, format, mount, persist, register in Proxmox.": "Flux manuel équivalent de disk_host.sh : partitionner, formater, monter, persister, s'inscrire dans Proxmox.", "Equivalent manual flow of iscsi_host.sh.": "Flux manuel équivalent de iscsi_host.sh.", "Equivalent manual flow used by Local Shared Manager.": "Flux manuel équivalent utilisé par Local Shared Manager.", @@ -1512,12 +1951,16 @@ "Error: No write permissions in directory": "Erreur : aucune autorisation d'écriture dans le répertoire", "Essential Proxmox packages installed": "Packages Proxmox essentiels installés", "Estimated required free space:": "Espace libre requis estimé :", + "Etherpad admin page": "Etherpad page d'administration", "Every 12 hours": "Toutes les 12 heures", "Every 3 hours": "Toutes les 3 heures", "Every 6 hours": "Toutes les 6 heures", + "Every fail2ban jail ships disabled. Enable the ones you need in /config/fail2ban/jail.local, taking the ready-made jails in /config/fail2ban/jail.d/ as reference, then restart the container.": "Toutes les prisons de fail2ban sont désactivées. Activez ceux dont vous avez besoin dans /config/fail2ban/jail.local, en prenant les prisons prêtes à l'emploi dans /config/fail2ban/jail.d/ comme référence, puis redémarrez le conteneur.", "Every hour": "Toutes les heures", + "Every member of the stack is back to its previous installation.": "Chaque membre de la pile est de retour à son installation précédente.", "Every path in this backup is kernel-tied: the restore applies these paths automatically via the safe-subset filter and re-merges the operator's tuning.": "Chaque chemin de cette sauvegarde est lié au noyau : la restauration applique automatiquement ces chemins via le filtre de sous-ensemble sécurisé et fusionne à nouveau le réglage de l'opérateur.", "Everything restorable in this backup will be restored": "Tout ce qui peut être restauré dans cette sauvegarde sera restauré", + "Exact name of the remote": "Nom exact de la télécommande", "Example output: rootfs: local-lvm:vm-114-disk-0,size=8G": "Exemple de sortie : rootfs : local-lvm:vm-114-disk-0,size=8G", "Example target: /dev/sdb": "Exemple de cible : /dev/sdb", "Example: /dev/pve/vm-114-disk-0": "Exemple : /dev/pve/vm-114-disk-0", @@ -1537,7 +1980,9 @@ "Execute destructive rollback?": "Exécuter une restauration destructrice ?", "Executing destructive rollback (operator confirmed) ...": "Exécution d'une restauration destructrice (opérateur confirmé)...", "Executing:": "Exécution :", + "Execution engine for Index-TTS": "Moteur d'exécution pour Index-TTS", "Existing Groups": "Groupes existants", + "Existing TLS certificate reused:": "Certificat TLS existant réutilisé:", "Existing file, re-downloading...": "Fichier existant, retéléchargement...", "Existing filesystem:": "Système de fichiers existant :", "Existing hostpci entries detected — they will be reused": "Entrées hostpci existantes détectées : elles seront réutilisées", @@ -1581,7 +2026,9 @@ "Extended Filesystem 4 (recommended)": "Système de fichiers étendu 4 (recommandé)", "External ZFS ARC settings restored:": "Paramètres ZFS ARC externes restaurés :", "External ZFS configuration changed after the ProxMenux migration; current file and backup preserved:": "La configuration ZFS externe a changé après la migration ProxMenux ; le fichier actuel et sa sauvegarde ont été conservés :", + "External credential is empty or spans multiple lines": "Externe credential est vide ou couvre plusieurs lignes", "External disk for backup": "Disque externe pour la sauvegarde", + "External field not reserved:": "Champ externe non réservé:", "Extracting NVIDIA installer on host...": "Extraction du programme d'installation NVIDIA sur l'hôte...", "Extracting OVA archive...": "Extraction de l'archive OVA...", "Extracting archive...": "Extraction des archives...", @@ -1592,7 +2039,9 @@ "Extraction failed. Check log:": "L'extraction a échoué. Journal de vérification :", "Extraction successful": "Extraction réussie", "FAILED": "ÉCHOUÉ", + "FFmpeg version the node uses (7 by default)": "Version FFmpeg le noeud utilise (7 par défaut)", "FINAL CONFIRMATION — DATA WILL BE ERASED": "CONFIRMATION FINALE — LES DONNÉES SERONT EFFACÉES", + "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface.": "FIleZilla Client est un client FTP, FTPS et SFTP multiplateforme rapide et fiable avec de nombreuses fonctionnalités utiles et une interface utilisateur graphique intuitive.", "Fail2Ban - Intrusion Prevention": "Fail2Ban - Prévention des intrusions", "Fail2Ban Management": "Gestion Fail2Ban", "Fail2Ban has been removed": "Fail2Ban a été supprimé", @@ -1602,6 +2051,7 @@ "Fail2Ban is currently installed.": "Fail2Ban est actuellement installé.", "Fail2Ban is not installed on this system.": "Fail2Ban n'est pas installé sur ce système.", "Fail2Ban is running correctly": "Fail2Ban fonctionne correctement", + "Fail2ban is a daemon to ban hosts that cause multiple authentication errors.": "Fail2ban est un démon pour interdire les hôtes qui causent de multiples erreurs d'authentification.", "Failed": "Échoué", "Failed to access log2ram directory": "Échec de l'accès au répertoire log2ram", "Failed to access share with provided credentials.": "Échec de l'accès au partage avec les informations d'identification fournies.", @@ -1748,6 +2198,9 @@ "Failed. See log:": "Échoué. Voir le journal :", "Falling back to each installer with --auto-reinstall...": "Revenir à chaque installateur avec --auto-reinstall...", "Falling back to manual paste mode.": "Revenir au mode de collage manuel.", + "Fast Usenet downloader with a SABnzbd-compatible API": "Téléchargement rapide Usenet avec une API compatible SABnzbd", + "Fast, modern web interface for qBittorrent": "Interface web rapide et moderne pour qBittorrent", + "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper.": "Fast-whisper est une réimplémentation du modèle Whisper d'OpenAI en utilisant CTranslate2, qui est un moteur d'inférence rapide pour les modèles Transformers. Ce conteneur fournit un serveur de protocole de Wyoming pour un whisper plus rapide.", "Fastfetch Logo Selection": "Sélection de logos Fastfetch", "Fastfetch configuration updated": "Configuration Fastfetch mise à jour", "Fastfetch download URL retrieved successfully.": "URL de téléchargement Fastfetch récupérée avec succès.", @@ -1759,19 +2212,31 @@ "Fastfetch now displays: System optimised by: ProxMenux": "Fastfetch affiche désormais : Système optimisé par : ProxMenux", "Fastfetch removed from system": "Fastfetch supprimé du système", "Fastfetch will start automatically in the console": "Fastfetch démarrera automatiquement dans la console", + "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application.": "Ferdium est une application de bureau qui vous aide à organiser la façon dont vous utilisez vos applications préférées en utilisant combi en une seule application.", "Fetching NVIDIA driver versions supported by your GPU...": "Récupération des versions de pilotes NVIDIA prises en charge par votre GPU...", "Figurine installation and configuration completed successfully.": "Installation et configuration de la figurine terminées avec succès.", "Figurine is not installed.": "La figurine n'est pas installée.", "Figurine removed from system": "Figurine retirée du système", + "File bind mounts do not support spaces:": "Les fixations de fichiers ne supportent pas les espaces :", + "File processing made easy!": "Le traitement des fichiers est facile!", "File:": "Déposer:", + "FileBrowser Quantum": "FileBrowser Quantum", + "FileBrowser Quantum (new installation)": "FileBrowser Quantum (nouvelle installation)", + "FileDrop is a free, open source file sharing service": "FileDrop est un service gratuit de partage de fichiers open source", + "Files & Downloads": "Fichiers & téléchargements", + "Files volume size in GB": "Taille du volume des fichiers en GB", "Filesystem": "Système de fichiers", "Filesystem Tools Required": "Outils de système de fichiers requis", "Filesystem:": "Système de fichiers :", "Final Confirmation": "Confirmation finale", + "Final cleanup of the stack operation completed": "Nettoyage final de la pile operation terminée", "Final confirmation": "Confirmation finale", "Final storage health/status check": "Vérification finale de l’état/de l’état du stockage", + "Finance & Budgeting": "Finances & Budgeting", "Find your device using https://finds.synology.com": "Trouvez votre appareil en utilisant https://finds.synology.com", "Fingerprint:": "Empreinte digitale :", + "Firefly, the easiest using of WireGuard VPN server, plus version of wg-easy.": "Firefly, la plus simple utilisation du serveur VPN WireGuard, plus la version de wg-easy.", + "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards.": "Firefox Browser, également connu sous le nom de Mozilla Firefox ou simplement Firefox, est un navigateur web libre et open-source développé par la Fondation Mozilla et sa filiale, Mozilla Corporation. Le Firefox utilise le moteur de mise en page Gecko pour rendre des pages Web, qui implémente les normes Web actuelles et prévues.", "Firewall allows port": "Le pare-feu autorise le port", "Firewall settings": "Paramètres du pare-feu", "Firmware :": "Micrologiciel :", @@ -1791,8 +2256,13 @@ "Fix systemd-boot meta-package conflict": "Correction du conflit de méta-paquet systemd-boot", "Fix systemd-boot:": "Correction du démarrage système :", "Fix: on the host, run": "Correctif : sur l'hôte, exécutez", + "FlexGet web interface": "Interface web FlexGet", + "Flexget is a multipurpose automation tool for all of your media.": "Flexget est un outil d'automatisation polyvalent pour tous vos supports.", + "Flowise 3.0.1 and later create the administrator account from the web interface, the first time it is opened.": "Flowise 3.0.1 et plus tard créer le compte administrateur à partir de l'interface web, la première fois qu'il est ouvert.", + "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast.": "Flycast est un émulateur multiplateforme Sega Dreamcast, Naomi, Naomi 2 et Atomiswave dérivé de reicast.", "Folder Name": "Nom du dossier", "Folders in /mnt": "Dossiers dans /mnt", + "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics.": "Folding@home est un projet de calcul distribué pour simuler la dynamique des protéines, y compris le processus de repliement des protéines et les mouvements des protéines impliquées dans une variété de maladies. Il réunit des scientifiques citizen qui se portent volontaires pour exécuter des simulations de la dynamique des protéines sur leurs ordinateurs personnels. Les conclusions de ces données aident les scientifiques à mieux comprendre la biologie et offrent de nouvelles possibilités de développement thérapeutique.", "Follow post-restore progress live from ProxMenux Monitor → Backups tab after the reboot.": "suivez la progression post-restauration en direct depuis ProxMenux Monitor → onglet Sauvegardes après le redémarrage.", "For LVM - Create mount directory and mount:": "Pour LVM - Créez le répertoire de montage et montez :", "For ZFS, storage ID must start with a letter and use only letters, numbers, dot, dash, underscore or colon.": "Pour ZFS, l'ID de stockage doit commencer par une lettre et utiliser uniquement des lettres, des chiffres, des points, des tirets, des traits de soulignement ou des deux-points.", @@ -1828,11 +2298,15 @@ "Formatting partition": "Formatage d'une partition", "Found": "Trouvé", "Found guest-accessible shares:": "Partages trouvés accessibles aux invités :", + "Free and easy to use Minecraft server management tool.": "Outil de gestion de serveur Minecraft gratuit et facile à utiliser.", "Free public Proxmox repository enabled": "Dépôt public Proxmox gratuit activé", "Free space OK:": "Espace libre OK :", "Free up disk space": "Libérer de l'espace disque", "Free:": "Gratuit:", + "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support.": "Le FreeCAD est un modélisateur général de conception assistée par ordinateur (CAD) et un logiciel de modélisation de l'information sur le bâtiment (BIM) avec support de la méthode des éléments finis (FEM).", "French": "Français", + "Freshrss is a free, self-hostable aggregator for rss feeds.": "Freshrss est un agrégateur libre et autonome pour les flux rss.", + "Frigate WebUI": "Frigate WebUI", "Full SMART Report": "Rapport SMART complet", "Full SMART info and attributes": "Informations et attributs SMART complets", "Full format — new GPT partition + filesystem": "Format complet – nouvelle partition GPT + système de fichiers", @@ -1845,6 +2319,7 @@ "Function Level Reset (FLR) not available": "Réinitialisation du niveau de fonction (FLR) non disponible", "GID already in use:": "GID déjà utilisé :", "GID in CT": "GID en CT", + "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable.": "GIMP est un éditeur gratuit et open-source de graphiques raster utilisé pour la manipulation d'images (retouche) et l'édition d'images, le dessin libre, le codage entre différents formats de fichiers d'images et des tâches plus spécialisées. Il est extensible au moyen de plugins, et scriptable.", "GPU": "GPU", "GPU -> VM Mode Detected": "GPU -> Mode VM détecté", "GPU Already Added": "GPU déjà ajouté", @@ -1870,6 +2345,7 @@ "GPU already present in target VM — existing hostpci entry reused": "GPU déjà présent dans la VM cible – entrée hostpci existante réutilisée", "GPU audio added": "Audio GPU ajouté", "GPU audio already present in target VM — existing hostpci entry reused": "Audio GPU déjà présent dans la VM cible – entrée hostpci existante réutilisée", + "GPU available for machine learning:": "GPU disponible pour l'apprentissage automatique:", "GPU driver blacklisted": "Pilote GPU sur liste noire", "GPU guard hook will block concurrent start when another VM is already using this GPU": "Le crochet de protection du GPU bloquera le démarrage simultané lorsqu'une autre VM utilise déjà ce GPU", "GPU host driver blacklisted in /etc/modprobe.d/blacklist.conf": "Pilote hôte GPU sur liste noire dans /etc/modprobe.d/blacklist.conf", @@ -1885,11 +2361,14 @@ "GPU passthrough to VMs requires IOMMU to be enabled in the kernel.": "Le relais GPU vers les machines virtuelles nécessite que IOMMU soit activé dans le noyau.", "GPU passthrough was not applied.": "Le relais GPU n’a pas été appliqué.", "GPU passthrough was skipped (no compatible GPU detected).": "Le relais GPU a été ignoré (aucun GPU compatible détecté).", + "GPU recognition uses 8 GB of RAM and a limit of 4 CPU equivalents. These resources were tested in the lab and are not a universal minimum. Compatibility depends on the GPU, the models and the kernel. NVIDIA uses the GPUs of the Toolkit inventory; Intel keeps the CPU topology.": "La reconnaissance GPU utilise 8 Go de RAM et une limite de 4 CPU equivalents. Ces ressources ont été testées en laboratoire et ne constituent pas un minimum universel. La compatibilité dépend du GPU, des modèles et du noyau. NVIDIA utilise les GPU de l'inventaire Toolkit ; Intel garde la topologie du CPU.", "GPU removed from VM": "GPU supprimé de la VM", "GPU removed from VM config": "GPU supprimé de la configuration de la VM", + "GPU render device": "Dispositif de rendu GPU", "GPU switch complete: LXC mode prepared.": "Changement GPU terminé : mode LXC préparé.", "GPU switch complete: VM mode prepared.": "Changement de GPU terminé : mode VM préparé.", "GPU switch mode completed. No reboot required.": "Mode de changement de GPU terminé. Aucun redémarrage requis.", + "GPU verified:": "GPU vérifié :", "GPU will be removed from source VM config": "Le GPU sera supprimé de la configuration de la VM source", "GPU will remain configured in source VM": "Le GPU restera configuré dans la VM source", "GPU/TPU - Manual CLI Guide": "GPU/TPU - Guide CLI manuel", @@ -1899,6 +2378,8 @@ "GRUB configuration updated": "Configuration GRUB mise à jour", "GRUB_CMDLINE_LINUX_DEFAULT not found in GRUB config": "GRUB_CMDLINE_LINUX_DEFAULT introuvable dans la configuration GRUB", "GUI mode (if available)": "Mode GUI (si disponible)", + "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities.": "GZDoom est un port centré pour tous les jeux de moteurs Doom, basé sur ZDoom, ajoutant un rendu OpenGL et de puissantes capacités de script.", + "Gaming & Leisure": "Jeu & Leisure", "Gateway is not installed.": "La passerelle n'est pas installée.", "Gateway removed.": "Passerelle supprimée.", "Gateway restarted.": "La passerelle a redémarré.", @@ -1908,19 +2389,32 @@ "Generate a new key and authorize it on the server automatically (recommended)": "générer une nouvelle clé et l'autoriser automatiquement sur le serveur (recommandé)", "Generate a new key, show me the line to paste manually": "Générez une nouvelle clé, montrez-moi la ligne à coller manuellement", "Generate a new keyfile": "générer un nouveau fichier de clés", + "Generated Paperless administrator": "Administrateur sans papier généré", + "Generated Tandoor administrator": "Administrateur Tandoor généré", + "Generated administrator login": "Connexion de l'administrateur généré", "Generating OVF descriptor...": "Génération du descripteur OVF...", "Generating dkms.conf...": "Génération de dkms.conf...", "Generating manifest...": "Génération du manifeste...", "Generating missing locale:": "Génération des paramètres régionaux manquants :", + "Generic SCSI device associated with the drive (e.g. /dev/sg2)": "Dispositif SCSI générique associé au lecteur (p. ex. /dev/sg2)", "German": "Allemand", "Get a list of all your containers:": "Obtenez une liste de tous vos conteneurs :", "Get the actual disk path:": "Obtenez le chemin d'accès réel au disque :", "Get the container's storage information:": "Obtenez les informations de stockage du conteneur :", + "Get up and running with large language models locally": "Monter et fonctionner avec de grands modèles de langue localement", "Git installed": "Git installé", + "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality.": "GitQlient est une multiplateforme Client Git à l'origine fork de QGit. Aujourd'hui, il va au-delà d'un fork et ajoute beaucoup de nouvelles fonctionnalités.", + "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React.": "Github Desktop est une application GitHub à source ouverte. Il est écrit dans TypeScript et utilise React.", "Global settings and SSH jail configured": "Paramètres globaux et prison SSH configurés", + "Gluetun/VPN not yet available: this suite does not route downloads through a VPN.": "Gluetun/VPN n'est pas encore disponible : cette suite n'achemine pas les téléchargements via un VPN.", "Go to \"Manage custom paths\" and remove your custom entry that includes the destination": "Accédez à \"Gérer les chemins personnalisés\" et supprimez votre entrée personnalisée qui inclut la destination", "Google only ships an official libedgetpu APT repository for Debian/Ubuntu. Hardware passthrough is already written to": "Google fournit uniquement un référentiel officiel libedgetpu APT pour Debian/Ubuntu. Le relais matériel est déjà écrit dans", "Graceful shutdown timed out.": "L'arrêt progressif a expiré.", + "Grafana is a complete observability stack that allows you to monitor and analyze metrics, logs and traces. It allows you to query, visualize, alert on and understand your data no matter where it is stored.": "Grafana est une pile d'observation complète qui vous permet de surveiller et d'analyser les métriques, les journaux et les traces. Il vous permet d'interroger, de visualiser, d'alerter et de comprendre vos données, où qu'elles soient stockées.", + "Grafana web interface": "Interface web Grafana", + "Grav is a Fast, Simple, and Flexible, file-based Web-platform.": "Grav est une plateforme Web rapide, simple et flexible, basée sur des fichiers.", + "Grocy (new installation; restored data keeps its credentials)": "Grocy (nouvelle installation; les données restaurées conservent ses credentials)", + "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility.": "Grocy est un système ERP pour votre cuisine ! Réduire les déchets alimentaires et gérer vos tâches avec cette utilitaire brillante.", "Group": "Groupe", "Group 'sharedfiles' already exists inside the CT": "Le groupe « fichiers partagés » existe déjà dans le CT", "Group GID:": "GID du groupe :", @@ -1953,23 +2447,58 @@ "Guided Repair Available": "Réparation guidée disponible", "HA groups will be migrated to HA rules automatically": "Les groupes HA seront automatiquement migrés vers les règles HA.", "HA services disabled (configs preserved)": "Services HA désactivés (configurations préservées)", + "HAOS One is a community image that runs Docker inside the container. The LXC stays unprivileged, but the inner AppArmor profiles may not be available. The first start downloads Home Assistant Core and its add-ons. If the check fails, the CT and /mnt/data are kept for diagnosis.": "HAOS One est une image communautaire qui exécute Docker à l'intérieur du conteneur. Le LXC reste non privilégié, mais les profils internes de l'AppArmor peuvent ne pas être disponibles. Le premier démarrage télécharge Home Assistant Core et ses add-ons. Si la vérification échoue, l'EC et /mnt/data sont conservés pour diagnostic.", + "HAOS One profile declined": "Profil HAOS One décliné", + "HAOS One requires an unprivileged unmanaged LXC with nesting and keyctl, 2 cores, 2048 MB RAM, rootfs of at least 12 GB and /mnt/data of at least 16 GB on a container volume included in backups": "HAOS One requires un LXC non géré non privilégié avec nidation et keyctl, 2 carottes, 2048 MB RAM, rootfs d'au moins 12 Go et /mnt/data d'au moins 16 Go sur un volume de conteneur inclus dans les sauvegardes", + "HTML5 Network Speed Test Server.": "Serveur de test de vitesse réseau HTML5.", + "HTTP service check without a saved URL": "Contrôle du service HTTP sans URL enregistrée", + "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API.": "Habridge émule Philips Hue API à d'autres passerelles de domotique comme un Amazon Echo/Dot Gen 1 (gen 2 a des problèmes de découverte ha-bridge) ou d'autres systèmes qui prennent en charge Philips Hue. Le pont gère les commandes de base comme On, Off et les commandes de luminosité du protocole de teinte. Ce pont peut contrôler la plupart des appareils qui ont une API distincte.", + "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs.": "HandBrake est un outil open-source, construit par des bénévoles, pour convertir la vidéo de presque n'importe quel format en une sélection de codecs modernes et largement pris en charge.", "Hardening SSH: setting MaxAuthTries to 3...": "Renforcement de SSH : définition de MaxAuthTries sur 3...", + "Hardware acceleration for Emby": "Accélération matérielle pour Emby", + "Hardware acceleration for FileFlows": "Accélération matérielle pour FileFlows", + "Hardware acceleration for Frigate": "Accélération matérielle pour Frigate", + "Hardware acceleration for Jellyfin": "Accélération matérielle pour Jellyfin", + "Hardware acceleration for Plex": "Accélération matérielle pour Plex", + "Hardware acceleration for Roon Server": "Accélération matérielle pour Roon Server", + "Hardware acceleration for Stremio": "Accélération matérielle pour Stremio", + "Hardware acceleration for Tdarr": "Accélération matérielle pour Tdarr", + "Hardware acceleration options:": "Options d'accélération matérielle:", "Hardware compatibility — these items will be skipped to keep the boot safe:": "Compatibilité matérielle – ces éléments seront ignorés pour assurer la sécurité du démarrage :", "Hardware passthrough is already configured — the Coral device is visible inside the container as /dev/apex_0 (M.2) and/or /dev/bus/usb (USB).": "Le relais matériel est déjà configuré — le périphérique Coral est visible à l'intérieur du conteneur sous le nom /dev/apex_0 (M.2) et/ou /dev/bus/usb (USB).", "Hardware: GPUs and Coral-TPU": "Matériel : GPU et Coral-TPU", + "Have a Private Social Space Hosted on Your Site": "Avoir un espace social privé hébergé sur votre site", "Have valid backups of all VMs and containers": "Avoir des sauvegardes valides de toutes les VM et conteneurs", + "Health check failed:": "Le contrôle de santé a échoué :", + "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface.": "Healthchecks est un chien de garde pour vos emplois de cron. C'est un serveur web qui écoute les pings de vos jobs de cron, plus une interface web.", + "HedgeDoc gives you access to all your files wherever you are.": "HedgeDoc vous donne accès à tous vos fichiers où que vous soyez.", + "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way.": "Heimdall est un moyen simple d'organiser tous ces liens vers vos sites Web et applications web les plus utilisés.", + "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking.": "Helium est un navigateur web basé sur Chromium conçu pour les gens, avec amour. La vie privée d'abord avec un blocage publicitaire impartial.", "Help & Info (commands)": "Aide et informations (commandes)", "Help & Information": "Aide et informations", "Help and Info": "Aide et informations", "Help and Info Commands": "Commandes d'aide et d'informations", "Helper-Scripts logo applied": "Logo Helper-Scripts appliqué", + "Hermes WebUI": "Hermes WebUI", "Hidden for safety": "Caché pour plus de sécurité", "Hidden:": "Caché:", "High Availability services have been enabled successfully": "Les services haute disponibilité ont été activés avec succès", "High Availability setup completed": "Configuration de la haute disponibilité terminée", + "High availability resources are not supported by this profile": "Les ressources à forte disponibilité ne sont pas soutenues par ce profil", + "High availability resources are not supported for stacks": "Les ressources à forte disponibilité ne sont pas prises en charge pour les piles", "High risk confirmation": "Confirmation de risque élevé", "High-Risk GPU Power State": "État d'alimentation du GPU à haut risque", + "Home Assistant": "Home Assistant", + "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server": "Home Assistant Core - La domotique open source qui place le contrôle local et la confidentialité en premier. Propulsé par une communauté mondiale de bricoleurs et amateurs de bricolage. Parfait pour fonctionner sur un Raspberry Pi ou un serveur local", + "Home Assistant OS cannot be checked without an IP address": "Home Assistant OS ne peut pas être vérifié sans adresse IP", + "Home Assistant OS did not pass the Supervisor, Core and Observer checks": "Home Assistant OS n'a pas réussi les vérifications de superviseur, de base et d'observateur", + "Home Assistant OS ready: Supervisor, Core and Observer running": "Home Assistant OS prêt: Superviseur, Core et Observateur en marche", + "Home Assistant OS was not started: its addresses will be known once Core is running.": "Home Assistant OS n'a pas été démarré : ses adresses seront connues une fois Core lancé.", + "Home Assistant Observer": "Home Assistant Observateur", + "Home Automation systems": "Systèmes d'automatisation à domicile", "Home-Lab-Club logo applied": "Logo Home-Lab-Club appliqué", + "HomeKit support for the impatient.": "HomeKit soutien pour l'impatient.", + "Homebridge UI": "Homebridge UI", "Host": "Hôte", "Host Backup → Borg": "Sauvegarde de l'hôte → Borg", "Host Backup → Local archive": "Sauvegarde de l'hôte → Archive locale", @@ -1978,6 +2507,7 @@ "Host Config Backup": "Sauvegarde de la configuration de l'hôte", "Host Config Backup / Restore": "Sauvegarde/restauration de la configuration de l'hôte", "Host Config Restore": "Restauration de la configuration de l'hôte", + "Host DVB tuners": "Tuners DVB hôtes", "Host Directory": "Répertoire des hôtes", "Host Directory to LXC Mount Point": "Répertoire hôte vers le point de montage LXC", "Host Directory:": "Répertoire des hôtes :", @@ -1985,18 +2515,37 @@ "Host GPU detected": "GPU hôte détecté", "Host GPU is already bound to vfio-pci. Host reconfiguration/reboot should not be required for this VM-to-VM reassignment.": "Le GPU hôte est déjà lié à vfio-pci. La reconfiguration/redémarrage de l'hôte ne devrait pas être requis pour cette réaffectation de VM à VM.", "Host IP": "IP de l'hôte", + "Host Management": "Gestion de l'hôte", "Host Mount Path": "Chemin de montage de l'hôte", "Host NFS/Samba as Proxmox Storage (pvesm)": "Hébergez NFS/Samba en tant que stockage Proxmox (pvesm)", "Host Path": "Chemin d'accès de l'hôte", "Host Path:": "Chemin d'accès de l'hôte :", "Host Storage (NFS / Samba via Proxmox)": "Stockage hôte (NFS / Samba via Proxmox)", + "Host USB bus": "Bus USB hôte", "Host VFIO config was already up to date — no reboot needed.": "La configuration de l'hôte VFIO était déjà à jour – aucun redémarrage n'était nécessaire.", "Host VFIO configuration already up to date": "Configuration hôte VFIO déjà à jour", "Host VFIO configuration changed (initramfs updated). Reboot required before starting the VM.": "La configuration de l'hôte VFIO a été modifiée (initramfs mis à jour). Redémarrage requis avant de démarrer la VM.", "Host VFIO configuration changed — reboot required before starting the VM.": "La configuration de l'hôte VFIO a été modifiée : redémarrage requis avant de démarrer la VM.", "Host already in VFIO mode — skipping host reconfiguration for VM reassignment": "Hôte déjà en mode VFIO : ignorer la reconfiguration de l'hôte pour la réaffectation de la VM", + "Host audio devices": "Appareils audio d'accueil", "Host backup attached to PVE job": "Sauvegarde de l'hôte attachée au travail PVE", + "Host data is not restored by the backup; confirm it with --acknowledge-external-data": "Les données de l'hôte ne sont pas restaurées par la sauvegarde; confirmez-le avec --acknow-external-data", + "Host device for /dev/kvm": "Appareil d'accueil pour /dev/kvm", + "Host device for /dev/net/tun": "Appareil hôte pour /dev/net/tun", + "Host device for /dev/ttyUSB0": "Appareil hôte pour /dev/ttyUSB0", + "Host device for /dev/video10": "Appareil hôte pour /dev/video10", + "Host device for /dev/video11": "Appareil hôte pour /dev/video11", + "Host device for /dev/video12": "Appareil hôte pour /dev/video12", + "Host device node": "Noeud du périphérique hôte", + "Host directories are not included in the backup and are not reverted by a recovery.": "Les répertoires hôtes ne sont pas inclus dans la sauvegarde et ne sont pas retournés par une récupération.", + "Host directories are not included in the backups and are not reverted by a recovery.": "Les répertoires hôtes ne sont pas inclus dans les sauvegardes et ne sont pas retournés par une récupération.", + "Host directories cannot be part of the vzdump backup": "Les répertoires hôtes ne peuvent pas faire partie de la sauvegarde vzdump", + "Host directories that are kept, with their content:": "Les répertoires d'accueil qui sont conservés, avec leur contenu :", + "Host directory": "Répertoire de l'hôte", + "Host directory (created if it does not exist)": "Répertoire de l'hôte (créé s'il n'existe pas)", + "Host directory (not included in Proxmox backups)": "Répertoire hôte (non inclus dans les sauvegardes Proxmox)", "Host directory access for unprivileged containers has been prepared above": "L'accès au répertoire hôte pour les conteneurs non privilégiés a été préparé ci-dessus", + "Host directory kept, with its content:": "Répertoire de l'hôte tenu, avec son contenu :", "Host directory permissions updated — unprivileged containers can now access it": "Autorisations du répertoire hôte mises à jour : les conteneurs non privilégiés peuvent désormais y accéder", "Host directory:": "Répertoire hôte :", "Host fstab CIFS Mounts:": "Hôte des montages fstab CIFS :", @@ -2008,7 +2557,14 @@ "Host fstab NFS mounts:": "Hôte des montages fstab NFS :", "Host fstab mounts (not registered as Proxmox storage):": "Montages fstab de l'hôte (non enregistrés comme stockage Proxmox) :", "Host identity (hostname, hosts)": "Identité de l'hôte (nom d'hôte, hôtes)", + "Host kernel module loaded:": "Module du noyau de l'hôte chargé :", + "Host monitor configured: shared PID and network namespaces, LXCFS disabled in this container": "Moniteur d'hôte configuré : espaces de noms PID et réseau partagés, LXCFS désactivés dans ce conteneur", + "Host monitor verified: PID and network namespaces and memory match the host": "Moniteur d'hôte vérifié : les espaces de noms PID et réseau et la mémoire correspondent à l'hôte", + "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks.": "Moniteur hôte : PID/réseau partagé et accès privilégié. Une image compromise pourrait affecter Proxmox. Utiliser uniquement sur des réseaux de confiance.", + "Host monitoring declined": "La surveillance des hôtes a diminué", + "Host path for": "Chemin de l'hôte pour", "Host permissions applied (o+rwx + default ACL) — unprivileged LXCs can read/write through bind-mounts": "Autorisations d'hôte appliquées (o+rwx + ACL par défaut) — les LXC non privilégiés peuvent lire/écrire via les montages de liaison", + "Host system path": "Emplacement du système hôte", "Host write access confirmed.": "Accès en écriture de l'hôte confirmé.", "Hostname": "Nom d'hôte", "Hot changes applied. No reboot needed for these paths.": "Modifications à chaud appliquées. Aucun redémarrage n'est nécessaire pour ces chemins.", @@ -2020,12 +2576,17 @@ "How do you want to select the Samba server?": "Comment voulez-vous sélectionner le serveur Samba ?", "How do you want to select the folder to export?": "Comment voulez-vous sélectionner le dossier à exporter ?", "How do you want to select the folder to share?": "Comment voulez-vous sélectionner le dossier à partager ?", + "How is it installed?": "Comment est-il installé?", + "How is the image described?": "Comment l'image est-elle décrite?", "How to Access an LXC Terminal": "Comment accéder à un terminal LXC", "How to Access an LXC Terminal from Proxmox Host": "Comment accéder à un terminal LXC depuis l'hôte Proxmox", "How to schedule": "Comment planifier", + "Htpcmanager is a front end for many htpc related applications.": "Htpcmanager est une interface frontale pour de nombreuses applications liées à htpc.", "I have read this": "j'ai lu ceci", "I/O priority configured": "Priorité E/S configurée", "ID already in use. Please choose another.": "ID déjà utilisé. Veuillez en choisir un autre.", + "IGDB": "IGDB", + "IGDB Client ID": "ID client IGDB", "IMPORTANT": "IMPORTANT", "IMPORTANT NOTES:": "REMARQUES IMPORTANTES :", "IMPORTANT PREREQUISITES:": "PRÉREQUIS IMPORTANTS :", @@ -2062,7 +2623,14 @@ "IOMMU was configured during this wizard and a reboot is pending.": "IOMMU a été configuré lors de cet assistant et un redémarrage est en attente.", "IOMMU/VFIO configuration reverted": "Configuration IOMMU/VFIO inversée", "IP": "IP", + "IP address": "Adresse IP", + "IP address and firewall of the host": "Adresse IP et pare-feu de l'hôte", + "IP address of this container for the certificate (0.0.0.0 if unknown)": "Adresse IP de ce conteneur pour le certificat (0.0.0.0 si inconnu)", + "IP address:": "Adresse IP:", "IP or hostname of the PVE node hosting the Borg server LXC:": "IP ou nom d'hôte du nœud PVE hébergeant le serveur Borg LXC :", + "IPv4 address of the container": "Adresse IPv4 du conteneur", + "IPv4 address of the containers": "Adresse IPv4 des conteneurs", + "IPv4 gateway (empty = no outbound route)": "passerelle IPv4 (vide = pas d'itinéraire sortant)", "ISO": "OIN", "ISO created successfully:": "ISO créé avec succès :", "ISO image — installation images": "Image ISO – images d'installation", @@ -2095,6 +2663,7 @@ "If this happens, you can restore the backup from the 'Subscription Banner Removal' option in 'Uninstall optimizations'.": "Si cela se produit, vous pouvez restaurer la sauvegarde à partir de l'option « Suppression de la bannière d'abonnement » dans « Désinstaller les optimisations ».", "If this node runs hyper-converged Ceph: ensure Ceph is 19.x (Squid) BEFORE upgrading PVE.": "Si ce nœud exécute Ceph hyper-convergé : assurez-vous que Ceph est 19.x (Squid) AVANT de mettre à niveau PVE.", "If upgrade fails:": "Si la mise à niveau échoue :", + "If you answer No, Glances is installed without privileges and monitors ONLY its own LXC, not Proxmox.": "Si vous répondez Non, Glances est installé sans privilèges et surveille SEULEMENT ses propres LXC, pas Proxmox.", "If you are sure you want to use it, please remove the": "Si vous êtes sûr de vouloir l'utiliser, veuillez supprimer le", "If you choose No, install": "Si vous choisissez Non, installez", "If you continue, some adjustments may be duplicated or conflict with those already made by xshok.": "Si vous continuez, certains ajustements peuvent être dupliqués ou entrer en conflit avec ceux déjà effectués par xshok.", @@ -2104,11 +2673,30 @@ "If you want HDMI/analog audio inside the VM, select the audio controller(s) to pass through along with the GPU.": "Si vous souhaitez que l'audio HDMI/analogique soit intégré à la VM, sélectionnez le(s) contrôleur(s) audio à transmettre avec le GPU.", "If you want to use a physical monitor on the passthrough GPU:": "Si vous souhaitez utiliser un moniteur physique sur le GPU passthrough :", "If your DHCP has a static reservation for the old MAC, update it.": "Si votre DHCP a une réservation statique pour l'ancien MAC, mettez-la à jour.", + "Image": "Image", "Image Source Directory": "Répertoire des sources d'images", + "Image cache": "cache d'image", + "Image compatibility restored:": "Compatibilité de l'image restaurée :", + "Image compatibility verified:": "Compatibilité de l'image vérifiée :", "Image directory:": "Répertoire d'images :", + "Image download failed:": "Le téléchargement de l'image a échoué :", + "Image downloaded": "Image téléchargée", "Image file not found:": "Fichier image introuvable :", "Image imported:": "Image importée :", + "Image integrity verified": "Intégrité de l'image vérifiée", + "Image not allowed for the host monitor profile": "Image non autorisée pour le profil du moniteur hôte", + "Image reference (for example ghcr.io/user/application:latest)": "Référence de l'image (par exemple ghcr.io/user/application:latest)", + "Image that is not in the catalog": "Image ne figurant pas dans le catalogue", + "Image:": "Image & #160;:", "Images to import:": "Images à importer :", + "Immich CUDA requires NVIDIA driver 545 or later": "Immich CUDA requires pilote NVIDIA 545 ou plus", + "Immich GPU profile not validated": "Profil GPU Immich non validé", + "Immich configuration cancelled": "Configuration Immich annulée", + "Immich device without a validated translation": "Dispositif Immich sans traduction validée", + "Immich machine learning": "Immich apprentissage automatique", + "Immich requires CUDA compute capability 5.2 or later": "Immich requires CUDA capacité de calcul 5.2 ou ultérieure", + "Immich runtime without a validated translation": "Immich runtime sans traduction validée", + "Immich server": "Serveur Immich", "Import — disk image imports": "Importer – importations d'images disque", "Import Disk Image to VM": "Importer l'image disque vers la VM", "Import Disk to LXC": "Importer un disque vers LXC", @@ -2149,24 +2737,58 @@ "Incompatible Reset Capability for Intel GPU": "Capacité de réinitialisation incompatible pour le GPU Intel", "Incompatible Reset Capability for Intel dGPU": "Capacité de réinitialisation incompatible pour Intel dGPU", "Incompatible archive": "Archives incompatibles", + "Incompatible image platform": "Plateforme d'image incompatible", + "Incompatible instance directory": "Répertoire des instances incompatibles", + "Incompatible instance record": "Enregistrement d'instance incompatible", + "Incompatible record": "Enregistrement incompatible", + "Incompatible stack assembly": "Montage de la pile incompatible", "Incompatible version": "Version incompatible", + "Incomplete NVIDIA identity": "Identité incomplète NVIDIA", + "Incomplete NVIDIA inventory": "Inventaire incomplet de la NVIDIA", + "Incomplete Proxmox inventory": "Stock de Proxmox incomplet", + "Incomplete Proxmox inventory; recovery blocked": "Stock de Proxmox incomplet; récupération bloquée", + "Incomplete container removed:": "Contenant incomplet enlevé:", + "Incomplete dependency order": "Ordre de dépendance incomplet", + "Incomplete file recipe or unknown paths": "Recette de fichier incomplète ou chemins inconnus", + "Incomplete gzip layer": "Couche gzip incomplète", + "Incomplete or incompatible Proxmox inventory": "Stocks de Proxmox incomplets ou incompatibles", + "Incomplete primary network": "Réseau primaire incomplet", + "Incomplete stack order": "Ordre incomplet de la pile", + "Incomplete stack removed": "Pile incomplète enlevée", + "Inconsistent adaptation profile and recipe": "Profil et recette d'adaptation non cohérents", + "Inconsistent host monitor profile": "Profil de moniteur d'hôte non cohérent", + "Inconsistent stack identity": "Identité de la pile non cohérente", + "Inconsistent stack membership for": "Membres de pile non cohérents pour", "Increase container RAM temporarily to": "Augmentez temporairement la RAM du conteneur pour", "Increase file and process limits for advanced workloads": "Augmentez les limites de fichiers et de processus pour les charges de travail avancées", "Increase various system limits": "Augmenter diverses limites du système", "Increase vzdump backup speed": "Augmenter la vitesse de sauvegarde de vzdump", "Increasing maximum file system open files...": "Augmentation du nombre maximal de fichiers ouverts dans le système de fichiers...", "Increasing various system limits...": "Augmentation de diverses limites du système...", + "Independent LXC applications installed": "Application indépendante LXC installée", + "Independent LXCs: no main container or hookscript. Each one keeps its own Start with Proxmox setting.": "LXCs indépendants: pas de conteneur principal ou de hookscript. Chacun garde son propre réglage Commencer avec Proxmox.", + "Independent applications, without a main container.": "Applications indépendantes, sans conteneur principal.", + "Indexers and quality profiles still need to be configured.": "Les indexeurs et les profils de qualité doivent encore être configurés.", "Inherited retention:": "Rétention héritée :", "Inherited schedule:": "Horaire hérité :", + "Initial Nextcloud administrator": "Administrateur initial Nextcloud", + "Initial Nextcloud settings applied": "Paramètres Nextcloud initiaux appliqués", + "Initial Paperless-ngx administrator": "Administrateur initial Paperless-ngx", + "Initial Tandoor administrator": "Administrateur Tandoor initial", + "Initial administrator created:": "Administrateur initial créé :", + "Initial administrator user": "Administrateur initial", "Initializing Borg repository if needed...": "Initialisation du référentiel Borg si nécessaire...", "Initiator IQN is authorised on the target": "L'IQN initiateur est autorisé sur la cible", "Initiator IQN:": "IQN initiateur :", + "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers.": "Inkscape est un logiciel graphique vectoriel de qualité professionnelle qui fonctionne sur les ordinateurs de bureau Linux, Mac OS X et Windows.", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN": "À l'intérieur du LXC, créez l'administrateur: console kimai:utilisateur:créez VOTRE USERNAME VOTRE ROLE SUPER ADMIN", "Inspect disks before any action": "Inspecter les disques avant toute action", "Inspect host device nodes": "Inspecter les nœuds du périphérique hôte", "Inspect passthrough/kernel events": "Inspecter les événements de relais/noyau", "Inspect storage config block:": "Inspectez le bloc de configuration du stockage :", "Inspection commands run directly. Template commands [T] require parameter substitution.": "Les commandes d'inspection s'exécutent directement. Les commandes de modèle [T] nécessitent une substitution de paramètres.", "Install": "Installer", + "Install (experimental)": "Installation (expérimentale)", "Install ALL utilities": "Installez TOUS les utilitaires", "Install AMD GPU drivers inside the guest.": "Installez les pilotes GPU AMD dans l'invité.", "Install CIFS client packages inside CT:": "Installez les packages clients CIFS dans CT :", @@ -2185,6 +2807,7 @@ "Install Samba inside CT:": "Installez Samba dans CT :", "Install ZFS auto-snapshot": "Installer l'instantané automatique ZFS", "Install a version from the branch the kernel names.": "Installez une version à partir de la branche des noms de noyau.", + "Install an image that is not in the catalog": "Installez une image qui n'est pas dans le catalogue", "Install analysis tools": "Installer des outils d'analyse", "Install and configure": "Installer et configurer", "Install and configure Fastfetch": "Installer et configurer Fastfetch", @@ -2203,27 +2826,35 @@ "Install server packages inside CT:": "Installez les packages de serveur dans CT :", "Install terminal multiplexers": "Installer des multiplexeurs de terminaux", "Install the Edge TPU runtime (libedgetpu1-std)": "Installez le runtime Edge TPU (libedgetpu1-std)", + "Install this image?": "Installer cette image ?", "Install with Cloud-Init script": "Installer avec le script Cloud-Init", "Install with ISO from UUP Dump": "Installer avec ISO à partir de UUP Dump", + "Install with advanced settings": "Installer avec les paramètres avancés", + "Install with default settings": "Installer avec les paramètres par défaut", "Install with personal ISO": "Installer avec une ISO personnelle", + "Install with this configuration?": "Installer avec cette configuration ?", "Install with traditional method": "Installer avec la méthode traditionnelle", "Install with: apt-get install open-iscsi": "Installer avec : apt-get install open-iscsi", "Install/Update Coral TPU on Host": "Installer/mettre à jour Coral TPU sur l'hôte", "Install/Update NVIDIA Drivers (Host + LXC)": "Installer/mettre à jour les pilotes NVIDIA (hôte + LXC)", "Installation Complete": "Installation terminée", + "Installation completed": "Installation terminée", "Installation completed.": "Installation terminée.", "Installation completed. Please reboot the server manually as soon as possible.": "Installation terminée. Veuillez redémarrer le serveur manuellement dès que possible.", "Installation completed. Press Enter to continue...": "Installation terminée. Appuyez sur Entrée pour continuer...", "Installation failed": "L'installation a échoué", "Installation finished but drivers are not loaded. A reboot may be required.": "Installation terminée mais les pilotes ne sont pas chargés. Un redémarrage peut être nécessaire.", + "Installation incomplete. These containers and their data are kept:": "Installation incomplète. Ces conteneurs et leurs données sont conservés:", "Installation log:": "Journal d'installation :", "Installation summary": "Résumé de l'installation", "Installed": "Installé", "Installed at:": "Installé à :", "Installed components:": "Composants installés :", + "Installed:": "Installé:", "Installer already downloaded and verified.": "Installateur déjà téléchargé et vérifié.", "Installer copied to container.": "Programme d'installation copié dans le conteneur.", "Installer downloaded.": "Installateur téléchargé.", + "Installer file not found:": "Fichier installateur introuvable :", "Installer finished with errors.": "Le programme d'installation s'est terminé avec des erreurs.", "Installer not found:": "Installateur introuvable :", "Installing": "Installation", @@ -2274,9 +2905,14 @@ "Installing pigz...": "Installation de pigz...", "Installing required dependencies...": "Installation des dépendances requises...", "Installing required package: git": "Installation du package requis : git", + "Installing required packages...": "Installation de paquets required...", "Installing required tools...": "Installation des outils requis...", "Installing selected utilities": "Installation des utilitaires sélectionnés", "Installing system utilities...": "Installation des utilitaires système...", + "Installing the new image": "Installation de la nouvelle image", + "Installing the new image...": "Installer la nouvelle image...", + "Installing the new image:": "Installer la nouvelle image :", + "Installing the stack startup hook...": "Installation du crochet de démarrage de la pile...", "Installing zfs-auto-snapshot package...": "Installation du package zfs-auto-snapshot...", "Installs essential packages if missing": "Installe les packages essentiels s'ils sont manquants", "Insufficient Disk Space": "Espace disque insuffisant", @@ -2288,8 +2924,17 @@ "Intel CPU detected": "Processeur Intel détecté", "Intel GPU Tools installation completed!": "Installation des outils GPU Intel terminée !", "Intel GPU(s) detected:": "GPU Intel détecté(s) :", + "Intel VA-API + OpenCL (official mod)": "Intel VA-API + OpenCL (mod officiel)", "Intel VA-API drivers installed.": "Pilotes Intel VA-API installés.", "Intel iGPU passthrough configured.": "Passthrough Intel iGPU configuré.", + "Intel render device for recognition": "Dispositif de rendu Intel pour la reconnaissance", + "Intel/AMD (VA-API and QSV)": "Intel/AMD (VA-API et QSV)", + "Intel/AMD (VA-API)": "Intel/AMD (VA-API)", + "Intel/AMD (streaming rendering and encoding)": "Intel/AMD (formatage et encodage)", + "Intel/AMD VA-API": "Intel/AMD VA-API", + "Intel/AMD VA-API (no OpenCL mod)": "Intel/AMD VA-API (pas de mod OpenCL)", + "Intel/AMD render node": "Le nœud de rendu Intel/AMD", + "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters – building great software.": "IntelliJ IDEA vous aide à écrire plus rapidement du code avec des outils qui éliminent les tâches fastidieuses et vous permettent de vous concentrer sur ce qui compte – construire de grands logiciels.", "Interactive (guided, prompts visible)": "Interactif (guidé, invites visibles)", "Interactive process viewer (press q to exit)": "Visionneuse de processus interactive (appuyez sur q pour quitter)", "Interface": "Interface", @@ -2303,50 +2948,186 @@ "Interfaces to Remove": "Interfaces à supprimer", "Internal error: NVIDIA installer path is empty or file not found.": "Erreur interne : le chemin du programme d'installation NVIDIA est vide ou le fichier est introuvable.", "Internal error: missing arguments in pmx_prepare_host_shared_dir": "Erreur interne : arguments manquants dans pmx_prepare_host_shared_dir", + "Internal subnet of the tunnel (change it only if it clashes)": "Sous-réseau interne du tunnel (ne le changer que s'il s'agit d'affrontements)", + "Interrupted operation": "Interruption du opera", + "Interrupted operation:": "Interruption du opera:", + "Interrupted stack operation found": "Pile interrompue operation trouvée", "Invalid 'proxmox-ve' candidate (not 9.x or none). Please verify your repository configuration and network, then retry.": "Candidat 'proxmox-ve' invalide (pas 9.x ou aucun). Veuillez vérifier la configuration et le réseau de votre référentiel, puis réessayez.", + "Invalid ALLOWED_HOSTS value": "Valeur HÔTES INDÉSIRABLES", + "Invalid Home Assistant OS check timeout": "Non valide Home Assistant OS check timeout", "Invalid ID": "Pièce d'identité invalide", + "Invalid Intel render path": "Chemin de rendu Intel incorrect", + "Invalid Jellyfin path:": "Chemin Jellyfin non valide:", + "Invalid MAC address:": "Adresse MAC non valide:", + "Invalid NVIDIA destination": "Destination NVIDIA non valable", + "Invalid NVIDIA device:": "Dispositif NVIDIA non valide:", + "Invalid Nextcloud volume": "Volume de Nextcloud non valable", + "Invalid OCI Entrypoint": "Point d'entrée non valide de l'OCI", + "Invalid OCI digest": "Digest de l'OCI non valide", + "Invalid OCR language:": "Langue OCR non valide:", "Invalid Option": "Option invalide", "Invalid Path": "Chemin invalide", + "Invalid Proxmox inventory": "Stock de Proxmox non valide", + "Invalid Python index:": "Indice Python non valide :", + "Invalid Python module:": "Module Python non valide :", + "Invalid Python package:": "Python non valide :", + "Invalid Python path in the repair:": "Python chemin non valide dans la réparation:", + "Invalid Unpackerr variable": "Variable Unpackerr non valable", + "Invalid VFS cache mode": "Mode cache VFS non valide", "Invalid VMID": "IDVM invalide", + "Invalid VMID or timeout": "VMID ou timeout non valides", + "Invalid VMID:": "VMID non valide:", "Invalid ZFS pool name.": "Nom du pool ZFS non valide.", + "Invalid absolute mount path": "Chemin de montage absolu non valide", + "Invalid absolute path; avoid spaces, commas and relative segments": "Chemin absolu non valide; évitez les espaces, les virgules et les segments relatifs", + "Invalid acceleration profile": "Profil d'accélération non valide", + "Invalid access address:": "Adresse d'accès invalide:", + "Invalid administrator email": "Courriel administrateur non valide", + "Invalid administrator user name": "Nom d'utilisateur non valide", + "Invalid base VMID": "VMID de base non valide", + "Invalid check package:": "Dossier de contrôle non valide:", + "Invalid configuration path:": "Chemin de configuration non valide & #160;:", + "Invalid consume/export volumes": "Volumes de consommation/d'exportation non valides", + "Invalid container path:": "Voie du conteneur non valide:", + "Invalid credential file path:": "Chemin de fichier credential incorrect :", + "Invalid declarative entrypoint": "Point de déclaration non valide", + "Invalid declarative stop signal": "Arrêt déclaratif non valide signal", + "Invalid declarative working directory": "Répertoire de travail déclaratif non valide", + "Invalid device UID:": "UID du dispositif non valide:", + "Invalid device mode": "Mode périphérique non valide", + "Invalid device mode:": "Mode de l'appareil non valide:", + "Invalid device path:": "Chemin du périphérique non valide & #160;:", + "Invalid device paths for": "Chemins de périphérique non valides pour", "Invalid group name. Use letters, digits, underscore or hyphen, and start with a letter or underscore.": "Nom de groupe invalide. Utilisez des lettres, des chiffres, un trait de soulignement ou un trait d'union et commencez par une lettre ou un trait de soulignement.", + "Invalid health check": "Contrôle de santé non valide", + "Invalid healthcheck path": "Voie de contrôle de santé non valide", + "Invalid healthcheck port": "Port de bilan de santé non valide", + "Invalid healthcheck request timeout": "Délai de demande de contrôle de santé non valide", + "Invalid healthcheck scheme": "Régime de contrôle sanitaire non valable", + "Invalid healthcheck stability period": "Période de stabilité du bilan de santé non valide", + "Invalid healthcheck timeout": "Invalidité du délai de contrôle de santé", + "Invalid host kernel module name:": "Nom du module hôte non valide & #160;:", + "Invalid host monitor PID": "PID de moniteur d'hôte non valide", + "Invalid host path:": "Chemin de l'hôte non valide & #160;:", + "Invalid image probe descriptor": "Descripteur de la sonde d'image non valide", "Invalid input": "Entrée invalide", + "Invalid internal volume": "Volume interne non valable", + "Invalid list:": "Liste non valide:", + "Invalid machine learning CPU allocation:": "Allocation de CPU pour apprentissage automatique non valide:", + "Invalid machine learning resources": "Ressources d'apprentissage automatique non valides", + "Invalid main member or duplicated members": "Membres principaux ou membres en double non valides", + "Invalid media path": "Chemin des médias non valide", + "Invalid media volume": "Volume des médias non valide", + "Invalid mediafiles volume": "Volume des fichiers multimédias non valide", + "Invalid minimum version:": "Version minimale non valide:", + "Invalid mount name": "Nom de montage non valide", + "Invalid mount type": "Type de montage non valide", "Invalid name": "Nom invalide", "Invalid name. Use only letters, numbers, hyphens and underscores.": "Nom invalide. Utilisez uniquement des lettres, des chiffres, des traits d'union et des traits de soulignement.", + "Invalid native entrypoint": "Point d'entrée natif non valide", + "Invalid octal permissions": "Autorisations d'octal non valides", "Invalid option": "Option invalide", "Invalid option, please try again.": "Option non valide, veuillez réessayer.", "Invalid option. Skipping.": "Option invalide. Saut.", + "Invalid or duplicated mount path": "Chemin de montage incorrect ou dupliqué", + "Invalid or duplicated network sysctl": "Système réseau non valide ou dupliqué", "Invalid parameters for bind mount": "Paramètres non valides pour le montage de liaison", + "Invalid path": "Voie non valide", + "Invalid path in the NVIDIA inventory": "Voie non valable dans l'inventaire NVIDIA", + "Invalid post-start timeout in the configuration:": "Temps d'arrêt non valide après le démarrage dans la configuration:", + "Invalid private bridge": "Pont privé non valide", + "Invalid private network": "Réseau privé non valide", + "Invalid prlimit value": "Valeur limite non valable", + "Invalid process limits format": "Format des limites de processus non valides", + "Invalid registry digest": "Digest de registre non valide", + "Invalid remote name": "Nom distant non valide", + "Invalid remote path": "Voie distante non valide", + "Invalid repair version:": "Version de réparation non valide:", + "Invalid resources": "Ressources non valides", + "Invalid restored volume path": "Voie de volume restaurée non valide", + "Invalid running state": "État de fonctionnement non valide", + "Invalid security.unprivileged value:": "Valeur de sécurité non valide.", "Invalid selection": "Sélection invalide", + "Invalid service alias": "Alias de service non valide", + "Invalid service check URL": "URL de vérification de service non valide", + "Invalid service check arguments": "arguments de vérification de service non valides", + "Invalid service check timeout": "Temps d'arrêt du service non valide", + "Invalid shared path": "Voie partagée non valide", + "Invalid shutdown timeout": "Arrêt non valide", "Invalid size. Please enter a number in MB (e.g., 128, 256, 512).": "Taille invalide. Veuillez saisir un nombre en Mo (par exemple, 128, 256, 512).", + "Invalid stack contract": "Contrat de pile non valide", + "Invalid stack journal": "Journal de pile non valide", + "Invalid stack members": "Membres de pile non valides", + "Invalid stack name": "Nom de la pile non valide", + "Invalid stack operation": "Pile non valide operation", "Invalid storage ID. Use only letters, numbers, hyphens and underscores.": "ID de stockage invalide. Utilisez uniquement des lettres, des chiffres, des traits d'union et des traits de soulignement.", + "Invalid suite application": "Demande de suite non valide", + "Invalid sysctl value:": "Valeur sysctl non valable:", + "Invalid template storage": "Stockage de gabarit non valide", + "Invalid tmpfs options:": "Options non valides:", + "Invalid tmpfs path:": "Path tmpfs non valide :", + "Invalid tmpfs size:": "Taille de tmpfs non valable:", "Invalid username or password.": "Nom d'utilisateur ou mot de passe invalide.", + "Invalid variable name": "Nom de la variable non valide", + "Invalid variable name:": "Nom de la variable invalide & #160;:", + "Invalid volume size": "Volume non valide", + "Invalid volume size:": "Volume non valide:", + "Invalid volume target": "Cible de volume non valable", + "Is the value a password or secret?": "La valeur est-elle un mot de passe ou un secret ?", "Issue": "Problème", "Issues found": "Problèmes trouvés", "Issues were found. Would you like to use the Guided Cleanup Assistant?": "Des problèmes ont été trouvés. Souhaitez-vous utiliser l'assistant de nettoyage guidé ?", "Issues were found. Would you like to use the Guided Repair Assistant?": "Des problèmes ont été trouvés. Souhaitez-vous utiliser l'assistant de réparation guidé ?", "It appears that you have already executed the xshok-proxmox post-install script on this system.": "Il semble que vous ayez déjà exécuté le script de post-installation xshok-proxmox sur ce système.", + "It asks for a system directory of the host:": "Il demande un répertoire système de l'hôte:", + "It asks for capabilities or a relaxed confinement profile.": "Il demande des capacités ou un profil de confinement détendu.", + "It asks to see the processes of the host.": "Il demande de voir les processus de l'hôte.", + "It cannot be removed on its own, because the application would stop working: continuing removes the whole application.": "Il ne peut pas être retiré seul, car la demande cesserait de fonctionner: la poursuite supprime l'ensemble de la demande.", + "It is created empty; existing data is not migrated automatically.": "Il est créé vide ; les données existantes ne sont pas migrées automatiquement.", "It is recommended to create a backup before continuing.": "Il est recommandé de créer une sauvegarde avant de continuer.", "It is strongly recommended to create a backup of your container before proceeding with the conversion.": "Il est fortement recommandé de créer une sauvegarde de votre conteneur avant de procéder à la conversion.", + "It needs a privileged container, which is not isolated from the host.": "Il a besoin d'un conteneur privilégié, qui n'est pas isolé de l'hôte.", "It will be installed from the official GitHub repository.": "Il sera installé à partir du référentiel officiel GitHub.", + "It works through the Docker engine of the host, and a native OCI container does not have one.": "Il fonctionne à travers le moteur Docker de l'hôte, et un conteneur OCI natif n'en a pas.", "Italian": "italien", + "Its Compose file asks for privileged mode; the container is created unprivileged and that mode is only offered as an option.": "Son fichier Compose demande un mode privilégié ; le conteneur est créé non privilégié et ce mode n'est offert qu'en option.", + "Its final cleanup did not complete. Select the stack again in the OCI management menu to complete it.": "Son nettoyage final n'est pas terminé. Sélectionnez à nouveau la pile dans le menu de gestion du BEC pour la compléter.", + "Its labels are not applied: they are read by other Docker tools.": "Ses étiquettes ne sont pas appliquées : elles sont lues par d'autres outils Docker.", "JC Channel logo applied": "Logo JC Channel appliqué", + "JDownloader 2 with browser GUI and MyJDownloader support": "JDownloader 2 avec GUI navigateur et support MyJDownloader", + "JDownloader WebUI": "JDownloader WebUI", "JSON output for scripts": "Sortie JSON pour les scripts", + "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps.": "Jackett fonctionne comme un serveur proxy: il traduit les requêtes des applications (Sonarr, SickRage, CouchPotato, Mylar, etc) en requêtes http spécifiques au site tracker, analyse la réponse html, puis renvoie les résultats au logiciel demandeur. Cela permet d'obtenir des téléchargements récents (comme RSS) et d'effectuer des recherches. Jackett est un dépôt unique de la logique de grattage et de traduction de l'indexeur - en supprimant le fardeau des autres applications.", + "Jellyfin WebUI": "Jellyfin WebUI", + "Jellyfin configuration applied:": "Configuration Jellyfin appliquée:", + "Jellyfin did not create encoding.xml before the timeout": "Jellyfin n'a pas créé d'encodage.xml avant l'expiration du délai", + "Jellyfin has not created encoding.xml in any declared path": "Jellyfin n'a créé encoding.xml dans aucun chemin déclaré", + "Jellyseerr is a free and open source software application for managing requests for your media library.": "Jellyseerr est une application gratuite et open source pour la gestion des demandes pour votre médiathèque.", + "Jenkins Continuous Integration and Delivery server.": "Serveur d'intégration et de livraison continue Jenkins.", + "Jenkins unlock": "Jenkins déverrouiller", "Job ID (letters, numbers, - _)": "ID de travail (lettres, chiffres, - _)", "Job ID:": "Identifiant du travail :", "Job deleted:": "Tâche supprimée :", "Job disabled:": "Emploi désactivé :", "Job enabled:": "Tâche activée :", "Job selection returned empty id — aborting.": "La sélection de tâches a renvoyé un identifiant vide – abandon.", + "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.": "Joplin est une application gratuite et open source, qui peut gérer un grand nombre de notes organisées en cahiers.", "Journald configuration adjusted to": "Configuration du journal ajustée à", "Journald configuration is already optimized": "La configuration de Journald est déjà optimisée", "Journald configuration updated and service restarted": "Configuration journald mise à jour et service redémarré", "Journald optimization completed": "Optimisation du journal terminée", "Journald optimized - Max size: 64M": "Journal optimisé - Taille max : 64M", + "Jupyter Lab (token only)": "Jupyter Lab (jeton seulement)", "KDF:": "KDF :", "KVM MSR options added to /etc/modprobe.d/kvm.conf": "Options KVM MSR ajoutées à /etc/modprobe.d/kvm.conf", "KVM MSR options ensured in /etc/modprobe.d/kvm.conf": "Options KVM MSR assurées dans /etc/modprobe.d/kvm.conf", "KVM MSR options not present, nothing to revert": "Options KVM MSR non présentes, rien à annuler", + "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX ™ is a trademark of OffSec.": "Kali-linux - est une distribution Linux de test de pénétration avancée utilisée pour les tests de pénétration, le piratage éthique et les évaluations de sécurité réseau. KALI LINUX TM est une marque déposée de OffSec.", + "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections.": "Kasm Workspaces est une plate-forme de diffusion de conteneurs docker pour fournir un accès par navigateur aux ordinateurs de bureau, aux applications et aux services Web. Kasm utilise l'infrastructure de bureau containerized devops (CDI) pour créer sur demande, jetable, des conteneurs docker qui sont accessibles via le navigateur Web. Les exemples d'utilisation comprennent l'isolement du navigateur à distance (RBI), la prévention de la perte de données (DLP), le bureau en tant que service (DaaS), les services d'accès à distance sécurisé (RAS) et les collections Open Source Intelligence (OSINT).", + "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!": "Kavita est un serveur de lecture crossplateforme rapide, riche en fonctionnalités. Construit avec un focus pour être une solution complète pour tous vos besoins de lecture. Configurez votre propre serveur et partagez votre collection de lecture avec vos amis et votre famille !", + "Kavita is a free and open source web based Comic and Book Server.": "Kavita est un serveur Web gratuit et open source basé sur Comic et Book Server.", + "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready.": "Kdenlive est un puissant logiciel de montage vidéo libre et ouvert réalisé par la communauté KDE. Caractéristique riche et la production prête.", + "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass).": "KeePassXC est un gestionnaire de mots de passe libre et ouvert. Elle a commencé en tant que communauté fork de KeePassX (elle-même un port multiplateforme de KeePass).", "Keep GPU in LXC config (disable Start on boot)": "Conserver le GPU dans la configuration LXC (désactiver le démarrage au démarrage)", "Keep GPU in LXC config + disable Start on boot": "Conserver le GPU dans la configuration LXC + désactiver le démarrage au démarrage", "Keep GPU in VM config (disable Start on boot)": "Conserver le GPU dans la configuration de la VM (désactiver le démarrage au démarrage)", @@ -2356,6 +3137,7 @@ "Keep current version (N) if modified": "Conserver la version actuelle (N) si modifiée", "Keep in source VM(s) + disable onboot + add to target VM": "Conserver dans la ou les VM sources + désactiver le démarrage + ajouter à la VM cible", "Keeping GPU in source VM config": "Conserver le GPU dans la configuration de la VM source", + "Keeping the settings changed in Proxmox:": "Garder les paramètres modifiés dans Proxmox :", "Kept sharedfiles group (has regular users assigned).": "Groupe de fichiers partagés conservé (des utilisateurs réguliers sont attribués).", "Kernel and architecture info": "Informations sur le noyau et l'architecture", "Kernel headers and build tools verified.": "En-têtes du noyau et outils de build vérifiés.", @@ -2377,6 +3159,17 @@ "Keyfile recovery — pick source host": "Récupération du fichier de clés – choisissez l'hôte source", "Keyfile removed.": "fichier clé supprimé.", "Keyrings method failed; trying apt-key fallback": "La méthode des porte-clés a échoué ; essayer la solution de secours apt-key", + "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite.": "KiCad - Une plateforme croisée et une suite d'automatisation de conception électronique ouverte.", + "Kimai has no default account. Enter the container with: pct enter {main_vmid}": "Kimai n'a pas de compte par défaut. Saisissez le conteneur avec : pct entre {main vmid}", + "Kimai is a professional grade time-tracking application, free and open-source.": "Kimai est une application professionnelle de suivi du temps, libre et open-source.", + "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more.": "Kometa est un outil puissant conçu pour vous donner un contrôle complet sur vos bibliothèques multimédias. Avec Kometa, vous pouvez porter votre personnalisation au niveau suivant, avec un contrôle granulaire sur les métadonnées, les collections, les superpositions et bien plus encore.", + "Kometa reads its configuration from /config/config.yml and the container only ships /config/config.yml.template. Copy the template to config.yml, fill in the required Plex and TMDb connections, then restart the container.": "Kometa lit sa configuration à partir de /config/config.yml et le conteneur ne livre que /config/config.yml.template. Copiez le modèle pour config.yml, remplissez les connexions required Plex et TMDb, puis redémarrez le conteneur.", + "Komga is a media server for your comics, mangas, BDs, magazines and eBooks.": "Komga est un serveur multimédia pour vos BD, mangas, BD, magazines et eBooks.", + "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone.": "Krita est un programme professionnel de peinture libre et GRATUIT. Il est fait par des artistes qui veulent voir des outils d'art abordables pour tout le monde.", + "LAN access to the kept containers (stack configuration incomplete):": "Accès au réseau local des conteneurs gardés (configuration incomplète):", + "LAN address applied to the application URLs": "Adresse LAN appliquée aux URL de l'application", + "LLM App Development Platform": "Plateforme de développement de l'application LLM", + "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer.": "LM Studio peut exécuter des modèles d'IA locaux comme gpt-oss, Llama, Gemma, Qwen et DeepSeek en privé sur votre ordinateur.", "LUNs appear as block devices assignable to VMs": "Les LUN apparaissent sous forme de périphériques de bloc attribuables aux machines virtuelles", "LVM PV headers check completed": "Vérification des en-têtes PV LVM terminée", "LVM physical volume detected": "Volume physique LVM détecté", @@ -2393,18 +3186,27 @@ "LXC containers with NVIDIA passthrough:": "Conteneurs LXC avec relais NVIDIA :", "LXC conversion from privileged to unprivileged completed successfully!": "La conversion LXC de privilégié à non privilégié s'est terminée avec succès !", "LXC conversion from unprivileged to privileged completed successfully!": "Conversion LXC de non privilégié à privilégié terminée avec succès !", + "LXC entries outside the NVIDIA inventory of the journal": "LXC entrées à l'extérieur de l'inventaire NVIDIA de la revue", + "LXC entries outside the selected acceleration profile": "LXC entrées en dehors du profil d'accélération sélectionné", + "LXC entry outside the read-only NVIDIA profile": "LXC entrée en dehors du profil NVIDIA en lecture seule", "LXC removed:": "LXC supprimé :", "LXC stopped": "LXC arrêté", "LXC update skipped by user.": "Mise à jour LXC ignorée par l'utilisateur.", "LXCs to destroy:": "LXC à détruire :", + "Lab interruption after installing the new container": "Interruption de laboratoire après l'installation du nouveau conteneur", + "Lab interruption after protecting the data": "Interruption du laboratoire après protection des données", + "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models.": "Label Studio est un outil d'étiquetage de données open source. Il vous permet d'étiqueter des types de données comme audio, texte, images, vidéos et séries chronologiques avec une interface utilisateur simple et simple et d'exporter vers différents formats de modèles. Il peut être utilisé pour préparer des données brutes ou améliorer les données de formation existantes pour obtenir plus de modèles ML accurate.", "Label:": "Étiquette:", "Language Change": "Changement de langue", "Language changed to": "La langue a été modifiée en", + "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)": "Langue/locale (par exemple es ES.UTF-8; la traduction de chaque application n'est pas garantie)", "Last 50 kernel log lines": "50 dernières lignes de journal du noyau", "Last run:": "Dernière exécution :", "Last system boot time": "Heure du dernier démarrage du système", "Latest version:": "Dernière version :", "Launching GPU passthrough assistant for VM": "Lancement de l'assistant de passthrough GPU pour VM", + "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork.": "Lazylibrarian est un programme pour suivre les auteurs et saisir des métadonnées pour tous vos besoins de lecture numérique. Il utilise un combination de Goodreads Librarything et optionnellement GoogleBooks comme sources pour l'information de l'auteur et l'information de livre. Ce conteneur est basé sur le DobyTang fork.", + "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user’s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012).": "Le logiciel Ldap-auth est destiné à authentifier les utilisateurs qui demandent des ressources protégées à partir de serveurs approchés par nginx. Il comprend un démon (ldap-auth) qui communique avec un serveur d'authentification, et un démon de serveur web qui génère un cookie d'authentification basé sur l'utilisateur. Les démons sont écrits en Python pour utilisation avec un serveur d'authentification Lightweight Directory Access Protocol (LDAP) (OpenLDAP ou Microsoft Windows Active Directory 2003 et 2012).", "Legacy PVE 8 .list files commented or not present": "Fichiers .list hérités PVE 8 commentés ou non présents", "Legacy ceph.list commented or not present": "Ceph.list hérité commenté ou non présent", "Legacy gasket-dkms cleanup could not be verified as complete.": "Impossible de confirmer que le nettoyage de l'ancien paquet gasket-dkms est terminé.", @@ -2412,12 +3214,25 @@ "Legacy network tools (e.g., ifconfig)": "Outils réseau hérités (par exemple, ifconfig)", "Legend:": "Légende:", "Let's review your current network configuration.": "Passons en revue votre configuration réseau actuelle.", + "Liberate your videos and unleash infinite possibilities.": "Libérez vos vidéos et relâchez des possibilités infinies.", + "Libraries: /data/media/movies, /data/media/series and /data/media/music. Select them in the media server.": "Bibliothèques: /data/media/movies, /data/media/série et /data/media/music. Sélectionnez-les dans le serveur multimédia.", + "Library size in GB": "Taille de la bibliothèque en GB", + "LibreDB Studio": "LibreDB Studio", + "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity.": "LibreOffice est une suite de bureau gratuite et puissante, et un successeur à OpenOffice.org (connu sous le nom d'OpenOffice). Son interface propre et ses outils riches en fonctionnalités vous aident à libérer votre créativité et à améliorer votre productivité.", + "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM.": "LibreWolf est une version personnalisée et indépendante de Firefox, avec les principaux objectifs de confidentialité, de sécurité et de liberté des utilisateurs. LibreWolf vise également à supprimer toutes les caractéristiques de télémétrie, de collecte de données et d'ennuis, ainsi que les fonctionnalités anti-liberté invalidantes comme DRM.", + "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers.": "Librespeed est un Speedtest très léger implémenté dans Javascript, utilisant XMLHttpRequest et Web Workers.", + "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Lidarr est un gestionnaire de collection musicale pour les utilisateurs Usenet et BitTorrent. Il peut surveiller plusieurs flux RSS pour de nouvelles pistes de vos artistes préférés et les saisir, les trier et les renommer. Il peut également être configuré pour améliorer automatiquement la qualité des fichiers déjà téléchargés lorsqu'un format de meilleure qualité devient disponible.", + "Lightweight Docker management UI": "Gestion légère Docker UI", "Likely cause: host directory permissions deny the container's mapped UID.": "Cause probable : les autorisations du répertoire hôte refusent l'UID mappé du conteneur.", "Limiting size and optimizing journald": "Limiter la taille et optimiser journald", "Limiting size and optimizing journald...": "Limiter la taille et optimiser le journal...", + "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot.": "Limnoria Un robot Python IRC robuste, complet et convivial/programmeur, avec de nombreux plugins existants. Successeur du célèbre Supybot.", + "Limnoria joins no IRC network until its configuration file exists. Create it with the setup wizard from the Proxmox host: pct exec -- bash -c 'cd /config && limnoria-wizard'": "Limnoria ne rejoint aucun réseau IRC jusqu'à ce que son fichier de configuration existe. Créez-le avec l'assistant de configuration de l'hôte Proxmox : pct exec -- bash -c 'cd /config && limnoria-wizard'", "Line to paste (single line, including \"command=...\" prefix):": "Ligne à coller (une seule ligne, incluant le préfixe \"command=...\") :", "Linux Installation Options": "Options d'installation Linux", "Linux/Mac path:": "Chemin Linux/Mac :", + "LinuxServer Jellyfin with optional GPU passthrough": "LinuxServer Jellyfin avec passage GPU optionnel", + "LinuxServer MariaDB requires a user, database and password": "LinuxServer MariaDB requires un utilisateur, une base de données et un mot de passe", "List Available Disks": "Liste des disques disponibles", "List IOMMU group mapping": "Répertorier le mappage de groupe IOMMU", "List NVMe devices": "Répertorier les appareils NVMe", @@ -2443,7 +3258,9 @@ "Listening on:": "En écoute sur :", "Listening ports:": "Ports d'écoute :", "Listing relevant CT users and their mapped UID/GID on host...": "Liste des utilisateurs CT concernés et de leur UID/GID mappé sur l'hôte...", + "Load and verify the WireGuard module on the Proxmox host": "Charger et vérifier le module WireGuard sur l'hôte Proxmox", "Loading modules...": "Chargement des modules...", + "Loading the host kernel module:": "Chargement du module du noyau hôte & #160;:", "Local Disk Manager - Proxmox Host": "Gestionnaire de disque local - Hôte Proxmox", "Local Disk Storages": "Stockages sur disque local", "Local Shared Directory on Host": "Répertoire partagé local sur l'hôte", @@ -2454,6 +3271,7 @@ "Local keyfile is missing but a recovery copy was found in PBS.": "Le fichier de clé local est manquant mais une copie de récupération a été trouvée dans PBS.", "Local network only (192.168.0.0/16)": "Réseau local uniquement (192.168.0.0/16)", "Local restore error log": "Journal des erreurs de restauration locale", + "Local storage for PostgreSQL": "Stockage local pour PostgreSQL", "Locale generated": "Paramètres régionaux générés", "Location:": "Emplacement:", "Log": "Enregistrer", @@ -2469,6 +3287,7 @@ "Logged-in users": "Utilisateurs connectés", "Logrotate optimization completed": "Optimisation de la rotation terminée", "Logrotate service restarted successfully": "Le service Logrotate a redémarré avec succès", + "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment.": "Lollypop est un lecteur de musique moderne léger conçu pour fonctionner parfaitement sur l'environnement de bureau GNOME.", "Long Test — Background": "Test long — Contexte", "Long self-test started on": "Un autotest long a démarré le", "Long test — full scan, runs in background if closed": "Test long : analyse complète, s'exécute en arrière-plan si fermé", @@ -2477,7 +3296,11 @@ "Lookup domain registration info": "Rechercher des informations d'enregistrement de domaine", "Low Container Memory": "Mémoire de conteneur faible", "Low free space warning": "Avertissement d'espace libre faible", + "Low-code programming for event-driven applications": "Programmation à code bas pour les applications événementielles", "Low-power CPU platform": "Plateforme CPU basse consommation", + "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation": "Luanti (anciennement Minetest) est une plate-forme de création de jeux voxel open source avec un moudding facile et la création de jeux", + "Lucky web interface": "Interface web Lucky", + "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.": "Lychee est un outil de gestion de photos gratuit, qui fonctionne sur votre serveur ou votre espace web. L'installation est une question de secondes. Télécharger, gérer et partager des photos comme à partir d'une application native. Lychee est livré avec tout ce dont vous avez besoin et toutes vos photos sont stockées en toute sécurité.", "Lynis - Security Audit": "Lynis - Audit de sécurité", "Lynis Management": "Gestion Lynis", "Lynis command not found": "Commande Lynis introuvable", @@ -2492,26 +3315,38 @@ "Lynis updated to version:": "Lynis mis à jour vers la version :", "Lynis version:": "Version Lynis :", "Lynis was not installed from Git. Reinstalling...": "Lynis n'a pas été installé depuis Git. Réinstallation...", + "Lyrion Music Server is a streaming audio server for Squeezebox audio players.": "Lyrion Music Server est un serveur audio en streaming pour les lecteurs audio Squeezebox.", "M.2 / PCIe devices:": "Appareils M.2/PCIe :", + "M3U proxy server": "Serveur proxy M3U", "MAC Address": "Adresse MAC", + "MAC address": "Adresse MAC", "MACHINE TYPE": "TYPE DE MACHINE", + "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers.": "MAME est un émulateur libre et open-source conçu pour émuler le matériel des jeux d'arcade, consoles de jeux vidéo, anciens ordinateurs et autres systèmes dans les logiciels sur les ordinateurs personnels modernes.", "MOTD configuration updated successfully": "Configuration MOTD mise à jour avec succès", "MOTD configuration was already up to date": "La configuration MOTD était déjà à jour", "Machine Type": "Type de machine", + "Machine learning": "Apprentissage automatique", + "Machine learning profile not implemented; it is not replaced by CPU:": "Profil d'apprentissage automatique non implémenté; il n'est pas remplacé par CPU:", "Machine type: q35": "Type de machine : q35", "Machine: q35": "Appareil : q35", + "Main endpoint not yet defined": "Objectif principal non encore défini", "Major version differs:": "La version majeure diffère :", "Make sure IOMMU is properly enabled and the system has been rebooted after activation.": "Assurez-vous que IOMMU est correctement activé et que le système a été redémarré après l'activation.", "Make sure there are no critical services running as they will be interrupted. Ensure your server can be safely rebooted.": "Assurez-vous qu'aucun service critique n'est en cours d'exécution car ils seront interrompus. Assurez-vous que votre serveur peut être redémarré en toute sécurité.", "Make sure you have SSH or Web UI access before rebooting.": "Assurez-vous que vous disposez d'un accès SSH ou Web UI avant de redémarrer.", "Makefile missing in": "Makefile manquant dans", "Malformed repository entries cleaned": "Entrées de référentiel malformées nettoyées", + "Manage OCI": "Gérer le BEC", + "Manage OCI stack": "Gérer la pile OCI", "Manage PBS encryption keyfile": "Gérer le fichier de clés de chiffrement PBS", "Manage Secure Gateway": "Gérer Secure Gateway", "Manage and inspect VM disk images": "Gérer et inspecter les images de disque de VM", "Manage custom backup paths": "Gérer les chemins de sauvegarde personnalisés", "Manage custom paths (add / remove your folders)": "Gérer les chemins personnalisés (ajouter/supprimer vos dossiers)", + "Manage installed OCI applications": "Gérer les applications OCI installées", "Manage local backup target": "Gérer la cible de sauvegarde locale", + "Managed disks must have backup enabled and a valid size": "Les disques gérés doivent avoir une sauvegarde activée et une taille valide", + "Managing Nginx proxy hosts with a simple, powerful interface.": "Gestion des hôtes proxy Nginx avec une interface simple et puissante.", "Manual CLI Guide (Disk and Storage Manager)": "Guide CLI manuel (Gestionnaire de disques et de stockage)", "Manual CLI Guide (GPU/TPU)": "Guide CLI manuel (GPU/TPU)", "Manual Guide: Convert LXC Privileged to Unprivileged": "Guide manuel : Convertir LXC privilégié en non privilégié", @@ -2526,29 +3361,51 @@ "Manual review is required.": "une révision manuelle est requise.", "Manual steps recommended after import": "Étapes manuelles recommandées après l'importation", "Manual upgrade guide step by step": "Guide de mise à niveau manuelle étape par étape", + "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing.": "Manyfold est une application web ouverte, auto-organisée pour gérer une collection de modèles 3D, particulièrement axée sur l'impression 3D.", "Mapped GID on host": "GID mappé sur l'hôte", "Mapped UID on host": "UID mappé sur l'hôte", + "Mariadb is one of the most popular database servers. Made by the original developers of MySQL.": "Mariadb est l'un des serveurs de base de données les plus populaires. Réalisé par les développeurs originaux de MySQL.", + "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..": "Mastodon est un serveur de réseau social libre basé sur ActivitéPub où les utilisateurs peuvent suivre leurs amis et en découvrir de nouveaux.", "Max FD limit / ulimit configured": "Limite FD maximale / ulimit configurée", "Max FS open files configuration created successfully": "Configuration des fichiers ouverts Max FS créée avec succès", "Max user watches configured": "Nombre maximum de montres utilisateur configurées", "Maximum auto-repair attempts reached (3). Please review the log and run any remaining commands manually.": "Nombre maximal de tentatives de réparation automatique atteint (3). Veuillez consulter le journal et exécuter manuellement les commandes restantes.", "May need to restart terminal": "Il faudra peut-être redémarrer le terminal", + "Media & Streaming": "Médias & Streaming", + "Media discovery and request management for Jellyfin, Plex and Emby.": "Découverte des médias et gestion des demandes pour Jellyfin, Plex et Emby.", + "Media library transcoding and health checking, with an internal worker node.": "Transcodage de la médiathèque et contrôle de la santé, avec un noeud de travail interne.", + "Media server": "Serveur multimédia", + "Media server selection cancelled or invalid": "Sélection du serveur multimédia annulée ou invalide", + "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well.": "MediaElch est un MediaManager pour Kodi. Les informations sur les films, les émissions télévisées, les concerts et la musique sont stockées sous forme de fichiers nfo. Fanarts sont téléchargés automatiquement depuis fanart.tv. En utilisant le générateur nfo, MediaElch peut également être utilisé avec d'autres MediaCenters.", + "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Medusa est un gestionnaire automatique de bibliothèque vidéo pour les émissions de télévision. Il regarde de nouveaux épisodes de vos spectacles préférés, et quand ils sont affichés, il fait sa magie.", + "Memory": "Mémoire", + "Memory in MB": "Mémoire en MB", "Memory optimization completed.": "Optimisation de la mémoire terminée.", "Memory optimizations removed": "Optimisations de mémoire supprimées", "Memory restored.": "Mémoire restaurée.", "Memory settings optimized successfully": "Paramètres de mémoire optimisés avec succès", "Memory:": "Mémoire:", + "Memos is a lightweight, self-hosted memo hub. Open Source and Free forever.": "Memos est un centre de mémos léger et auto-organisé. Source ouverte et libre pour toujours.", + "Messaging & Queues": "Messagerie et requêtes", + "Messenger for the Decentralized Web": "Messager pour le Web décentralisé", "Method:": "Méthode:", + "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium.": "Microsoft Edge est un navigateur web multiplateforme développé par Microsoft et basé sur Chromium.", "Migrate VMs away from node being upgraded": "Migrer les VM hors du nœud en cours de mise à niveau", "Migrate away any guests that must keep running": "Migrez tous les invités qui doivent continuer à fonctionner", "Migrated": "Migré", "Migrated legacy ProxMenux NVIDIA blacklist state — module will reload after reboot": "État de la liste noire ProxMenux NVIDIA héritée migrée : le module se rechargera après le redémarrage", + "MineOS web interface": "Interface web MineOS", + "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards.": "Minisatip est une version de serveur satip multi-threaded 1.2 qui fonctionne sous Linux et qui a été testée avec des cartes DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC et ISDB-T.", "Mirror URL not available for this script.": "URL miroir non disponible pour ce script.", + "Miscellaneous": "Divers", "Missing": "Manquant", + "Missing OCI metadata:": "métadonnées manquantes du BEC:", "Missing commands after installation:": "Commandes manquantes après l'installation :", "Missing dependency": "Dépendance manquante", + "Missing native directive:": "Directive native manquante:", "Missing on target:": "Manquant la cible :", "Missing or invalid parameter": "Paramètre manquant ou invalide", + "Missing required command:": "Commande required manquante :", "Missing required parameter": "Paramètre obligatoire manquant", "Mixed GPU Modes": "Modes GPU mixtes", "Mixed current mode detected in selected GPU(s).": "Mode courant mixte détecté dans le(s) GPU sélectionné(s).", @@ -2556,15 +3413,20 @@ "Mode": "Mode", "Model": "Modèle", "Modern resource monitor (press q to exit)": "Moniteur de ressources moderne (appuyez sur q pour quitter)", + "Modern, easy to use download automation for torrents and usenet.": "Moderne, facile à utiliser automatisation de téléchargement pour torrents et usernet.", "Modifying Fastfetch configuration...": "Modification de la configuration de Fastfetch...", "Modules configuration updated.": "Configuration des modules mise à jour.", "Modules loaded.": "Modules chargés.", + "MongoDB 4.4, the last series that runs on a CPU without AVX.": "MongoDB 4.4, la dernière série qui fonctionne sur un processeur sans AVX.", + "Monica is an open source personal relationship management system, that lets you document your life.": "Monica est un système de gestion des relations personnelles open source qui vous permet de documenter votre vie.", "Monitor Activated": "Moniteur activé", "Monitor Deactivated": "Moniteur désactivé", "Monitor URL": "Surveiller l'URL", "Monitor disk I/O usage (press q to exit)": "Surveiller l'utilisation des E/S du disque (appuyez sur q pour quitter)", "Monitor progress:": "Surveiller les progrès :", + "Monitor, analyze, and alert on network performance.": "Surveiller, analyser et alerter les performances du réseau.", "Monitoring": "Surveillance", + "Monitoring & Analytics": "Surveillance et analyse", "Most common cause: the archive is corrupted (interrupted write, partial copy, or storage issue).": "Cause la plus courante : l'archive est corrompue (écriture interrompue, copie partielle ou problème de stockage).", "Mount Added Successfully:": "Montage ajouté avec succès :", "Mount CIFS share:": "Montez le partage CIFS :", @@ -2592,13 +3454,19 @@ "Mount Samba Share on Host": "Partager Mount Samba sur l'hôte", "Mount USB disk?": "Monter un disque USB ?", "Mount a USB drive now": "Montez une clé USB maintenant", + "Mount activation cancelled": "Activation du montage annulée", "Mount all datasets": "Monter tous les ensembles de données", "Mount already exists for this path in container": "Le support existe déjà pour ce chemin dans le conteneur", "Mount and persist with UUID:": "Montez et conservez avec l'UUID :", + "Mount configuration cancelled": "Configuration de montage annulée", "Mount failed": "Le montage a échoué", + "Mount mode applied": "Mode de montage appliqué", + "Mount name": "Nom du montage", + "Mount not authorized by the operation": "Montage non autorisé par la operation", "Mount options:": "Options de montage :", "Mount path must be an absolute path starting with /": "Le chemin de montage doit être un chemin absolu commençant par /", "Mount path:": "Chemin de montage :", + "Mount paths must not overlap": "Les chemins de montage ne doivent pas se chevaucher", "Mount point created": "Point de montage créé", "Mount point created.": "Point de montage créé.", "Mount point is visible but NOT writable from inside the container": "Le point de montage est visible mais NON accessible en écriture depuis l'intérieur du conteneur", @@ -2607,11 +3475,14 @@ "Mount point ready:": "Point de montage prêt :", "Mount point removed successfully": "Point de montage supprimé avec succès", "Mount point:": "Point de montage :", + "Mount points added:": "Points de montage ajoutés:", + "Mount read-only": "Monter en lecture seule", "Mount shares on HOST first": "Montez d'abord les partages sur HOST", "Mount specific dataset": "Monter un ensemble de données spécifique", "Mount status:": "Statut du montage :", "Mount this device and use it as the backup destination?": "Monter cet appareil et l'utiliser comme destination de sauvegarde ?", "Mount was busy — performed lazy unmount": "Mount était occupé – effectué un démontage paresseux", + "Mount your cloud drive on your home NAS": "Montez votre lecteur cloud sur votre NAS", "Mounted": "Monté", "Mounted ISO on device": "ISO monté sur l'appareil", "Mounted at": "Monté à", @@ -2626,8 +3497,17 @@ "Mounting here will hide existing files until unmounted.": "Le montage ici masquera les fichiers existants jusqu'à leur démontage.", "Move that copy offsite (USB, password manager, another host). Delete it from this path when done.": "déplacez cette copie hors site (USB, gestionnaire de mots de passe, un autre hôte).Supprimez-le de ce chemin une fois terminé.", "Move to target VM (remove from source VM config)": "Déplacer vers la VM cible (supprimer de la configuration de la VM source)", + "Moving the data volumes aside": "Déplacement des volumes de données", + "Moving the data volumes aside...": "Déplacer les volumes de données de côté...", + "Multi-container application (experimental)": "Application multiconteneurs (expérimentale)", + "Multi-line variables are not supported": "Les variables multilignes ne sont pas prises en charge", + "Multiple networks or external networks are not yet supported": "Plusieurs réseaux ou réseaux externes ne sont pas encore pris en charge", "Multiple recovery groups found in PBS. Pick the one that originally created the keyfile:": "Plusieurs groupes de récupération trouvés dans PBS. Choisissez celui qui a initialement créé le fichier de clés :", "Multiple rootfs directories were found in this archive. Restore cannot continue automatically.": "Plusieurs répertoires rootfs ont été trouvés dans cette archive. La restauration ne peut pas continuer automatiquement.", + "Music Collection and Streaming Server": "Collection de musique et serveur de streaming", + "Music software that transforms your listening experience": "Logiciel de musique qui transforme votre expérience d'écoute", + "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more.": "MySQL Workbench est un outil visuel unifié pour les architectes de bases de données, les développeurs et les DBA. MySQL Workbench fournit des outils de modélisation de données, de développement SQL et d'administration complète pour la configuration du serveur, l'administration des utilisateurs, la sauvegarde et bien plus encore.", + "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL.": "Mylar3 est un téléchargeur automatique de Comic Book (cbr/cbz) pour utilisation avec NZB et torrents écrits en python. Il prend en charge SABnzbd, NZBGET et de nombreux clients torrents en plus de DDL.", "NAS Systems": "Systèmes NAS", "NETWORK CONFIGURATION ANALYSIS": "ANALYSE DE LA CONFIGURATION DU RÉSEAU", "NFS Access Restricted": "Accès NFS restreint", @@ -2691,24 +3571,33 @@ "NOT FOUND": "NON TROUVÉ", "NOTE: The host directory and its contents will remain unchanged.": "REMARQUE : Le répertoire hôte et son contenu resteront inchangés.", "NVENC patch detected — list narrowed to versions supported by keylase/nvidia-patch.": "Correctif NVENC détecté — liste restreinte aux versions prises en charge par keylase/nvidia-patch.", + "NVIDIA (CUDA)": "NVIDIA (CUDA)", + "NVIDIA (CUDA; official GPU image)": "NVIDIA (CUDA; image officielle du GPU)", + "NVIDIA (NVDEC/CUDA)": "NVIDIA (NVDEC/CUDA)", + "NVIDIA (NVENC/NVDEC)": "NVIDIA (NVENC/NVDEC)", "NVIDIA Actions": "Actions NVIDIA", "NVIDIA CPU hiding already configured": "Le masquage du processeur NVIDIA est déjà configuré", "NVIDIA Container Toolkit": "Boîte à outils de conteneur NVIDIA", + "NVIDIA Container Toolkit could not generate the runtime inventory": "NVIDIA Container Toolkit n'a pas pu générer l'inventaire d'exécution", "NVIDIA Container Toolkit installed. GPU validation pending until the host restarts.": "NVIDIA Container Toolkit installé. Validation GPU en attente jusqu'au redémarrage de l'hôte.", "NVIDIA Container Toolkit is incomplete. Missing:": "NVIDIA Container Toolkit est incomplet. Manquant:", "NVIDIA Container Toolkit is installed but its command line did not answer.": "NVIDIA Container Toolkit est installé mais sa ligne de commande n'a pas répondu.", + "NVIDIA Container Toolkit is missing on the host (nvidia-container-cli)": "NVIDIA Container Toolkit est absent sur l'hôte (nvidia-container-cli)", "NVIDIA Container Toolkit verified against the running driver.": "NVIDIA Container Toolkit vérifié par rapport au pilote en cours d'exécution.", "NVIDIA DKMS entries removed.": "NVIDIA DKMS entries removed.", "NVIDIA Driver Uninstall": "Désinstallation du pilote NVIDIA", "NVIDIA Driver Version": "Version du pilote NVIDIA", "NVIDIA Drivers": "Pilotes NVIDIA", "NVIDIA Drivers Not Found": "Pilotes NVIDIA introuvables", + "NVIDIA GPU / CUDA (Toolkit on the host)": "NVIDIA GPU / CUDA (Boîte à outils sur l'hôte)", "NVIDIA GPU Driver Installation": "Installation du pilote GPU NVIDIA", "NVIDIA GPU passthrough configured.": "Passthrough GPU NVIDIA configuré.", + "NVIDIA GPU prepared:": "GPU NVIDIA préparé:", "NVIDIA KVM args configured (kvm=off, vendor_id spoof)": "Arguments NVIDIA KVM configurés (kvm=off, usurpation d'id_vendeur)", "NVIDIA KVM hiding (cpu hidden=1)": "Masquage NVIDIA KVM (cpu caché = 1)", "NVIDIA KVM hiding already configured": "Masquage NVIDIA KVM déjà configuré", "NVIDIA Patch": "Correctif NVIDIA", + "NVIDIA device outside the expected native profile": "Appareil NVIDIA en dehors du profil natif attendu", "NVIDIA driver": "Pilote NVIDIA", "NVIDIA driver installed successfully.": "Pilote NVIDIA installé avec succès.", "NVIDIA driver installed:": "Pilote NVIDIA installé :", @@ -2716,6 +3605,7 @@ "NVIDIA drivers are not installed or not loaded on this host.": "Les pilotes NVIDIA ne sont pas installés ou ne sont pas chargés sur cet hôte.", "NVIDIA host services disabled for VFIO mode": "Services hôte NVIDIA désactivés pour le mode VFIO", "NVIDIA host services/autoload already aligned for native mode": "Services d'hôte NVIDIA/chargement automatique déjà alignés pour le mode natif", + "NVIDIA inside the container does not match the host driver or GPU": "NVIDIA à l'intérieur du conteneur ne correspond pas au pilote hôte ou GPU", "NVIDIA install incomplete. Check log:": "Installation NVIDIA incomplète. Journal de vérification :", "NVIDIA installer downloaded successfully": "Le programme d'installation de NVIDIA a été téléchargé avec succès", "NVIDIA installer extracted.": "Programme d'installation NVIDIA extrait.", @@ -2724,29 +3614,50 @@ "NVIDIA installer returned error": "Le programme d'installation de NVIDIA a renvoyé une erreur", "NVIDIA kernel modules unloaded successfully.": "Les modules du noyau NVIDIA ont été déchargés avec succès.", "NVIDIA libs require approximately 1.5GB of free space.": "Les bibliothèques NVIDIA nécessitent environ 1,5 Go d'espace libre.", + "NVIDIA mount with an unauthorized source or target": "Montage NVIDIA avec une source ou une cible non autorisée", "NVIDIA patch applied - check README for supported versions.": "Patch NVIDIA appliqué - consultez le fichier README pour les versions prises en charge.", "NVIDIA patch not applied.": "Patch NVIDIA non appliqué.", "NVIDIA per-BDF VFIO binding configured": "Liaison NVIDIA par BDF VFIO configurée", + "NVIDIA permissions or device nodes differ from the official inventory": "Les permissions NVIDIA ou les nœuds de périphérique diffèrent de l'inventaire officiel", + "NVIDIA refresh validated; the container is stopped and its settings are kept": "NVIDIA rafraîchissement validé; le conteneur est arrêté et ses réglages sont conservés", + "NVIDIA runtime libraries or components are missing": "Les bibliothèques ou composants d'exécution NVIDIA manquent", + "NVIDIA selection not supported by this profile": "Sélection NVIDIA non prise en charge par ce profil", "NVIDIA services stopped and disabled.": "Services NVIDIA arrêtés et désactivés.", "NVIDIA udev rules and persistence service installed.": "Règles NVIDIA udev et service de persistance installés.", "NVIDIA uninstallation steps completed.": "Étapes de désinstallation de NVIDIA terminées.", "NVIDIA uninstaller completed.": "Le programme de désinstallation NVIDIA est terminé.", "NVIDIA update failed for LXC": "La mise à jour NVIDIA a échoué pour LXC", "NVIDIA userspace libraries installed.": "Bibliothèques d'espace utilisateur NVIDIA installées.", + "NVML does not match the current host driver": "NVML ne correspond pas au pilote hôte actuel", "NVMe Disk Detected": "Disque NVMe détecté", "NVMe critical_warning is 0 (no critical warnings reported).": "NVMe critic_warning est 0 (aucun avertissement critique signalé).", + "NVMe health status: PASSED": "État de santé NVMe : RÉUSSI", "NVMe health status: WARNING (critical_warning =": "État de santé NVMe : AVERTISSEMENT (critical_warning =", "NVMe skipped (to add as PCIe use 'Add Controller or NVMe PCIe to VM'):": "NVMe ignoré (pour ajouter en tant que PCIe, utilisez « Ajouter un contrôleur ou NVMe PCIe à la VM ») :", "NVMe-specific SMART log": "Journal SMART spécifique à NVMe", + "NVR & Cameras": "NVR & Caméras", + "NVR with optional VA-API video acceleration and hardware object detectors": "NVR avec accélération vidéo VA-API en option et détecteurs d'objets matériels", + "NZBGet web interface": "Interface web NZBGet", + "Name": "Dénomination", + "Name for this application": "Nom de la présente demande", "Name for this target:": "Nom de cette cible :", + "Name of the PostgreSQL user created on the first start": "Nom de l'utilisateur PostgreSQL créé au premier démarrage", + "Name of the database created on the first start": "Nom de la base de données créée au premier démarrage", + "Name of the internal worker node": "Nom du nœud du travailleur interne", + "Name of this wallabag instance, shown in the interface and in 2FA codes": "Nom de cette instance wallabag, affichée dans l'interface et dans les codes 2FA", + "Name or part of the description of the application": "Nom ou partie de la description de la demande", "Name:": "Nom:", + "Named accounts need private mode. Stop the container, set public: false in /config/config.js, start it again and create each user with: pct exec -- env THELOUNGE_HOME=/config s6-setuidgid abc thelounge add ": "Les comptes nommés nécessitent un mode privé. Arrêter le conteneur, définir public: false in /config/config.js, recommencer et créer chaque utilisateur avec: pct exec -- env THELOUNGE HOME=/config s6-setuidgid abc thelounge ajouter ", "Neither /etc/kernel/cmdline nor /etc/default/grub found.": "Ni /etc/kernel/cmdline ni /etc/default/grub n'ont été trouvés.", "Nesting feature enabled": "Fonction d'imbrication activée", "NetBIOS Service: RUNNING": "Service NetBIOS : EN EXÉCUTION", "NetBIOS Service: STOPPED": "Service NetBIOS : ARRÊTÉ", "NetBIOS port 139:": "Port NetBIOS 139 :", + "NetBox": "NetBox", + "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations.": "Netbox est un outil de gestion des adresses IP (IPAM) et de gestion de l'infrastructure des centres de données (DCIM). Initialement conçu par l'équipe d'ingénierie du réseau de DigitalOcean, NetBox a été développé spécifiquement pour répondre aux besoins des ingénieurs du réseau et de l'infrastructure. Il est destiné à fonctionner comme une source de vérité spécifique au domaine pour le réseau operations.", "Network": "Réseau", "Network :": "Réseau :", + "Network & Firewall": "Réseau & Pare-feu", "Network (interfaces, DNS)": "Réseau (interfaces, DNS)", "Network Bridge": "Pont réseau", "Network Commands": "Commandes réseau", @@ -2764,6 +3675,7 @@ "Network Restarted": "Réseau redémarré", "Network Tools": "Outils réseau", "Network access:": "Accès au réseau :", + "Network bridge": "Pont réseau", "Network configuration backed up": "Configuration réseau sauvegardée", "Network configuration has been restored from backup.": "La configuration réseau a été restaurée à partir de la sauvegarde.", "Network connection failed to": "La connexion réseau n'a pas réussi", @@ -2776,12 +3688,16 @@ "Network service restarted successfully": "Le service réseau a redémarré avec succès", "Network service restarted successfully.": "Le service réseau a redémarré avec succès.", "Network share mounting (NFS/Samba) requires a PRIVILEGED container.": "Le montage de partage réseau (NFS/Samba) nécessite un conteneur PRIVILEGED.", + "Network sysctls prepared:": "Systèmes de réseau préparés:", "Network throughput test (client/server)": "Test de débit réseau (client/serveur)", + "Network-wide Ad Blocking": "Blocage publicitaire à l'échelle du réseau", + "Network-wide ad and tracker blocking": "Blocage des publicités et des trackers à l'échelle du réseau", "NetworkManager Detected": "Gestionnaire de réseau détecté", "NetworkManager has been removed successfully": "NetworkManager a été supprimé avec succès", "NetworkManager is running (may cause conflicts)": "NetworkManager est en cours d'exécution (peut provoquer des conflits)", "NetworkManager is running, which may conflict with Proxmox.": "NetworkManager est en cours d'exécution, ce qui peut entrer en conflit avec Proxmox.", "NetworkManager not running": "NetworkManager ne fonctionne pas", + "Networks the peers reach through the tunnel (0.0.0.0/0 = all traffic)": "Réseaux que les pairs atteignent à travers le tunnel (0.0.0.0/0 = tout le trafic)", "New Folder in /mnt": "Nouveau dossier dans /mnt", "New Group": "Nouveau groupe", "New Search": "Nouvelle recherche", @@ -2789,14 +3705,26 @@ "New Virtual Machine": "Nouvelle machine virtuelle", "New backup job": "Nouveau travail de sauvegarde", "New backups on this host will be unencrypted until a new keyfile is set up.": "Les nouvelles sauvegardes sur cet hôte ne seront pas chiffrées jusqu'à ce qu'un nouveau fichier de clés soit configuré.", + "New image compatible:": "Nouvelle image compatible & #160;:", + "New image installed": "Nouvelle image installée", + "New image installed, not verified yet": "Nouvelle image installée, non encore vérifiée", + "New image verified, not saved yet": "Nouvelle image vérifiée, pas encore enregistrée", "New kernel staged; rebuilding DKMS drivers:": "Nouveau noyau mis en scène ;reconstruction des pilotes DKMS :", "New mount options to apply:": "Nouvelles options de montage à appliquer :", "New scheduled job (own timer + retention)": "Nouvelle tâche planifiée (propre minuterie + rétention)", + "New value for": "Nouvelle valeur pour", "New version available": "Nouvelle version disponible", "New version:": "Nouvelle version :", "Next Step Required": "Prochaine étape requise", "Next Steps:": "Prochaines étapes :", "Next step: stop that VM first, then run": "Étape suivante : arrêtez d'abord cette VM, puis exécutez", + "Nextcloud configuration cancelled": "Configuration Nextcloud annulée", + "Nextcloud gives you access to all your files wherever you are.": "Nextcloud vous donne accès à tous vos fichiers où que vous soyez.", + "Nextcloud volume size in GB": "Taille du volume Nextcloud en GB", + "Nextcloud with private PostgreSQL and Redis dependencies": "Nextcloud avec dépendances privées PostgreSQL et Redis", + "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server.": "Nginx est un serveur web HTTP, proxy inversé, cache de contenu, équilibreur de charge, serveur proxy TCP/UDP et serveur proxy de courrier.", + "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.": "Le serveur web Nginx et le proxy inverse avec le support php et un client Certbot intégré (Let's Encrypt). Il contient également fail2ban pour la prévention des intrusions.", + "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd.": "Ngircd est un serveur de clavardage Internet gratuit, portable et léger pour petits réseaux ou privés, développé sous la licence publique générale GNU (GPL). Il est facile à configurer, peut faire face à des adresses IP dynamiques, et prend en charge les connexions protégées par IPv6, ainsi que PAM pour l'authentification. Il est écrit à partir de zéro et non sur la base du CRId original.", "No": "Non", "No .ova or .ovf files found in:": "Aucun fichier .ova ou .ovf trouvé dans :", "No .ovf descriptor found inside OVA.": "Aucun descripteur .ovf trouvé dans OVA.", @@ -2814,6 +3742,7 @@ "No CTs available in the system.": "Aucun TC disponible dans le système.", "No Changes Needed": "Aucun changement nécessaire", "No Cleanup Needed": "Aucun nettoyage nécessaire", + "No Compose file was given": "Aucun fichier Compose n'a été donné", "No Controller/NVMe selected for now.": "Aucun contrôleur/NVMe sélectionné pour l'instant.", "No Coral Detected": "Aucun Coral détecté", "No Coral TPU device was found on this host (neither PCIe/M.2 nor USB).": "Aucun périphérique Coral TPU n'a été trouvé sur cet hôte (ni PCIe/M.2 ni USB).", @@ -2825,6 +3754,7 @@ "No Exports": "Aucune exportation", "No Exports Found": "Aucune exportation trouvée", "No Folders": "Aucun dossier", + "No GPU (CPU)": "Pas de GPU", "No GPU Detected": "Aucun GPU détecté", "No GPU selected.": "Aucun GPU sélectionné.", "No GPU selected. Please select at least one GPU to continue.": "Aucun GPU sélectionné. Veuillez sélectionner au moins un GPU pour continuer.", @@ -2832,12 +3762,15 @@ "No Guest Shares": "Aucun partage invité", "No IP": "Pas d'adresse IP", "No IP assigned": "Aucune adresse IP attribuée", + "No IPv4 address was detected after 30 seconds.": "Aucune adresse IPv4 n'a été détectée après 30 secondes.", "No ISO file detected after UUP Dump process.": "Aucun fichier ISO détecté après le processus de vidage UUP.", "No ISO images found in Proxmox ISO storages.": "Aucune image ISO trouvée dans les stockages ISO Proxmox.", "No ISO selected.": "Aucun ISO sélectionné.", "No ISO was generated.": "Aucun ISO n'a été généré.", "No Images Found": "Aucune image trouvée", "No Intel GPU detected on this system.": "Aucun GPU Intel détecté sur ce système.", + "No LAN address was obtained": "Aucune adresse du réseau local n'a été obtenue", + "No LAN address was obtained for the service:": "Aucune adresse LAN n'a été obtenue pour le service :", "No LXC containers available": "Aucun conteneur LXC disponible", "No LXC containers found": "Aucun conteneur LXC trouvé", "No LXC containers found on this system.": "Aucun conteneur LXC trouvé sur ce système.", @@ -2855,7 +3788,9 @@ "No NFS shares currently mounted.": "Aucun partage NFS actuellement monté.", "No NVIDIA GPU detected on this system.": "Aucun GPU NVIDIA détecté sur ce système.", "No NVIDIA GPU has been detected on this system. The installer will now exit.": "Aucun GPU NVIDIA n'a été détecté sur ce système. Le programme d'installation va maintenant se fermer.", + "No NVIDIA GPU is available": "Aucun GPU NVIDIA n'est disponible", "No NVIDIA driver installed.": "Aucun pilote NVIDIA installé.", + "No OCI instances are registered.": "Aucune instance du BEC n'est enregistrée.", "No PBS keyfile is installed on this host and no automatic recovery was possible.": "Aucun fichier de clé PBS n'est installé sur cet hôte et aucune récupération automatique n'a été possible.", "No PVE vzdump job uses a": "Aucune tâche vzdump PVE n'utilise un", "No PVs with old headers found.": "Aucun PV avec d'anciens en-têtes trouvé.", @@ -2891,6 +3826,7 @@ "No Virtual Machines found on this system.": "Aucune machine virtuelle trouvée sur ce système.", "No ZFS pools detected. Skipping ZFS ARC optimization.": "Aucun pool ZFS détecté. Ignorer l'optimisation ZFS ARC.", "No ZFS pools detected. Skipping ZFS autotrim.": "Aucun pool ZFS détecté. Ignorer le découpage automatique ZFS.", + "No acceleration (CPU)": "Aucune accélération (CPU)", "No accessible": "Non accessible", "No accessible NFS servers found.": "Aucun serveur NFS accessible trouvé.", "No accessible Samba servers found.": "Aucun serveur Samba accessible trouvé.", @@ -2900,11 +3836,13 @@ "No active session": "Aucune session active", "No additional GPU can be added.": "Aucun GPU supplémentaire ne peut être ajouté.", "No additional device needs to be added.": "Aucun appareil supplémentaire ne doit être ajouté.", + "No applications match": "Aucune demande ne correspond", "No archives": "Pas d'archives", "No archives found in this Borg repository.": "Aucune archive trouvée dans ce référentiel Borg.", "No available Controllers/NVMe devices were found.": "Aucun contrôleur/périphérique NVMe disponible n'a été trouvé.", "No available disks found.": "Aucun disque disponible trouvé.", "No backup found, logrotate configuration not changed": "Aucune sauvegarde trouvée, la configuration de la rotation n'a pas été modifiée", + "No backup is scheduled: the rsnapshot lines in /config/crontabs/root are commented out. Uncomment or adjust the intervals you want, then restart the container.": "Aucune sauvegarde n'est programmée : les lignes rsnapshot dans /config/crontabs/root sont commentées. Décommentez ou ajustez les intervalles que vous voulez, puis redémarrez le conteneur.", "No backups": "Aucune sauvegarde", "No backups found": "Aucune sauvegarde trouvée", "No bridge configuration issues found": "Aucun problème de configuration de pont trouvé", @@ -2921,6 +3859,7 @@ "No compatible PVE jobs": "Aucun travail PVE compatible", "No compatible disk images found in:": "Aucune image disque compatible trouvée dans :", "No configuration issues found": "Aucun problème de configuration trouvé", + "No container of the stack was modified.": "Aucun contenant de la pile n'a été modifié.", "No container runtime available.": "Aucun environnement d'exécution de conteneur disponible.", "No container selected. Exiting.": "Aucun conteneur sélectionné. Sortir.", "No controller/NVMe selected.": "Aucun contrôleur/NVMe sélectionné.", @@ -2951,11 +3890,13 @@ "No folders found in /mnt. Please create a new folder.": "Aucun dossier trouvé dans /mnt. Veuillez créer un nouveau dossier.", "No folders found inside /mnt in the CT.": "Aucun dossier trouvé dans /mnt dans le CT.", "No format-safe disks are available.": "Aucun disque au format sécurisé n'est disponible.", + "No free ProxMenux private /24 network is available": "Pas de réseau privé gratuit ProxMenux /24 est disponible", "No gasket DKMS registrations remain.": "Il ne reste aucun enregistrement DKMS de gasket.", "No group creation required — uses world-writable sticky bit permissions.": "Aucune création de groupe requise : utilise des autorisations de bit collant accessibles en écriture dans le monde entier.", "No host VFIO reconfiguration expected": "Aucune reconfiguration VFIO hôte attendue", "No host VFIO/native binding changes were required.": "Aucune modification de liaison VFIO/native de l’hôte n’a été requise.", "No host backups were found in this PBS repository:": "Aucune sauvegarde d'hôte n'a été trouvée dans ce référentiel PBS :", + "No host directory is used by this application.": "Aucun répertoire hôte n'est utilisé par cette application.", "No host reboot expected": "Aucun redémarrage de l'hôte n'est prévu", "No host write access — server-side ACL or root_squash. Continuing anyway.": "Aucun accès en écriture sur l'hôte : ACL côté serveur ou root_squash. On continue quand même.", "No host write access — server-side ACL. Continuing anyway.": "Aucun accès en écriture sur l'hôte – ACL côté serveur. On continue quand même.", @@ -2964,6 +3905,7 @@ "No iSCSI storage configured.": "Aucun stockage iSCSI configuré.", "No iSCSI storage found in Proxmox.": "Aucun stockage iSCSI trouvé dans Proxmox.", "No iSCSI targets found on portal": "Aucune cible iSCSI trouvée sur le portail", + "No image was given": "Aucune image n'a été donnée", "No import disks selected for now.": "Aucun disque d'importation sélectionné pour l'instant.", "No importable disks available. System disks and protected disks are hidden.": "Aucun disque importable disponible. Les disques système et les disques protégés sont masqués.", "No installation information available.": "Aucune information d'installation disponible.", @@ -2975,6 +3917,7 @@ "No mount point was specified.": "Aucun point de montage n'a été spécifié.", "No mount points found in any container": "Aucun point de montage trouvé dans aucun conteneur", "No mount points found in container": "Aucun point de montage trouvé dans le conteneur", + "No name was given": "Aucun nom n'a été donné", "No network configuration backups found.": "Aucune sauvegarde de configuration réseau trouvée.", "No network interfaces configured (besides loopback)": "Aucune interface réseau configurée (en dehors du bouclage)", "No new Controller/NVMe entries were added.": "Aucune nouvelle entrée Contrôleur/NVMe n’a été ajoutée.", @@ -2999,9 +3942,11 @@ "No scheduled backup jobs configured.": "Aucune tâche de sauvegarde planifiée configurée.", "No scheduled backup jobs found.": "Aucune tâche de sauvegarde planifiée trouvée.", "No scripts found for:": "Aucun script trouvé pour :", + "No security relaxation is required for the reviewed profile.": "Aucune relaxation de sécurité n'est required pour le profil examiné.", "No self-test history found for": "Aucun historique d'autotest trouvé pour", "No self-test log available for": "Aucun journal d'autotest disponible pour", "No server IP or hostname provided.": "Aucune adresse IP de serveur ou nom d'hôte fourni.", + "No shared media content.": "Pas de contenu multimédia partagé.", "No shared mount detected. Applying standard local access.": "Aucun montage partagé détecté. Application d'un accès local standard.", "No shares configured.": "Aucun partage configuré.", "No shares found in smb.conf.": "Aucun partage trouvé dans smb.conf.", @@ -3031,24 +3976,34 @@ "No valid mount points found": "Aucun point de montage valide trouvé", "No version in this branch is currently supported by keylase/nvidia-patch — the NVENC patch will not reapply after reinstall.": "Aucune version de cette branche n'est actuellement prise en charge par keylase/nvidia-patch — le correctif NVENC ne sera pas réappliqué après la réinstallation.", "No virtual machines were found on this host.": "Aucune machine virtuelle n'a été trouvée sur cet hôte.", + "No working NVIDIA GPU was found": "Aucun GPU NVIDIA n'a été trouvé", "No write permissions on:": "Aucune autorisation en écriture sur :", "No, keep local only": "Non, conserver uniquement les informations locales", "No-subscription repository present": "Référentiel sans abonnement présent", "No: the key stays only at": "Non : la clé reste uniquement à", + "Node octal permissions (e.g. 0660)": "Autorisations d'octal de nœud (par exemple 0660)", "Non-Debian container detected": "Conteneur non Debian détecté", "Non-free firmware warnings disabled": "Avertissements du micrologiciel non libre désactivés", "None": "Aucun", "Normalizing stable monitor service...": "Normalisation du service de surveillance stable...", "Not Mounted": "Non monté", + "Not a JSON object:": "Pas un objet JSON:", "Not all platforms support Controller/NVMe passthrough reliably.": "Toutes les plates-formes ne prennent pas en charge le relais Controller/NVMe de manière fiable.", + "Not all shared directories were verified": "Tous les répertoires partagés n'ont pas été vérifiés", "Not an OVH server, skipping RTM installation": "Pas un serveur OVH, sautant l'installation RTM", "Not currently mounted": "Non monté actuellement", "Not currently mounted — skipping umount.": "Non monté actuellement – ​​ignorer umount.", + "Not enough free space for the backup": "Pas assez d'espace libre pour la sauvegarde", "Not found": "Pas trouvé", + "Not found in the OCI archive:": "Non trouvé dans l'archive du BEC :", "Not imported:": "Non importé :", "Not mounted": "Non monté", "Not portable:": "Non portable :", "Not registered as Proxmox storage — use 'LXC Mount Manager' to bind-mount": "Non enregistré en tant que stockage Proxmox — utilisez « LXC Mount Manager » pour effectuer le montage en liaison", + "Not required (access code only)": "Pas de required (code d'accès seulement)", + "Not required (password only)": "Pas de required (mot de passe seulement)", + "Not required (token only)": "Pas de required", + "Not yet verified by ProxMenux (beta)": "Non encore vérifié par ProxMenux (beta)", "Note: A system reboot will be required after enabling IOMMU.": "Remarque : Un redémarrage du système sera requis après l'activation d'IOMMU.", "Note: this only works if the NFS server does NOT use 'all_squash' for root.": "Remarque : cela ne fonctionne que si le serveur NFS n'utilise PAS « all_squash » pour root.", "Notes": "Remarques", @@ -3063,8 +4018,20 @@ "Nothing to schedule for reboot from selected paths.": "Rien à planifier pour le redémarrage à partir des chemins sélectionnés.", "Nouveau module is loaded, attempting to unload...": "Le module Nouveau est chargé, tentative de déchargement...", "Number of CPU cores (default: 2)": "Nombre de cœurs de processeur (par défaut : 2)", + "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources.": "Nzbget est un téléchargeur usernet, écrit en C++ et conçu avec des performances en vue d'atteindre une vitesse de téléchargement maximale en utilisant très peu de ressources système.", + "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra.": "Nzbhydra2 est une application de recherche méta pour les indexeurs NZB, le successeur spirituel de NZBmegasearcH, et une évolution de l'application originale NZBHydra.", "OCI containers require Proxmox VE 9.1 or later.": "Les conteneurs OCI nécessitent Proxmox VE 9.1 ou version ultérieure.", + "OCI management": "Gestion du BEC", + "OCI management could not be completed. Check the backend status; no additional cleanup has been authorized.": "La gestion du BEC n'a pas pu être terminée. Vérifiez l'état du moteur; aucun nettoyage supplémentaire n'a été autorisé.", + "OCI manager Apps (beta)": "Gestionnaire du BEC Apps (beta)", + "OCI manager Apps is a beta: if something does not work as expected, please report it on GitHub with the application name.": "OCI manager Apps est une bêta : si quelque chose ne fonctionne pas comme prévu, veuillez le signaler sur GitHub avec le nom de l'application.", + "OCI metadata integrity mismatch": "Inadéquation de l'intégrité des métadonnées du BEC", + "OCI metadata too large": "Métadonnées du BEC trop grandes", + "OCI stack management": "Gestion des piles du BEC", + "OCI verification failed:": "La vérification du BEC a échoué :", + "OCR language (Tesseract code)": "Langue de l'OCR (code Tesseract)", "OK": "D'ACCORD", + "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms.": "ONLYOFFICE fournit une gamme complète d'outils pour créer, modifier et collaborer sur des documents texte, des feuilles de calcul, des présentations, des formulaires PDF et des fichiers PDF réguliers sur les plateformes Web, de bureau et mobiles.", "OR add new PVE 9 no-subscription repository:": "OU ajoutez un nouveau référentiel sans abonnement PVE 9 :", "OS hint:": "Astuce du système d'exploitation :", "OS release details": "Détails de la version du système d'exploitation", @@ -3078,11 +4045,18 @@ "OVH RTM removed (Puppet artefacts may need manual cleanup)": "OVH RTM supprimé (les artefacts de marionnettes peuvent nécessiter un nettoyage manuel)", "OVH server detected": "Serveur OVH détecté", "OVH server detection and RTM installation process completed": "Processus de détection du serveur OVH et d'installation de RTM terminé", + "Observer is not responding on port 4357": "L'observateur ne répond pas au port 4357", + "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption.": "Obsidian est une application de prise de notes qui vous permet de créer, de lier et d'organiser vos notes sur votre appareil, avec des centaines de plugins et de thèmes pour personnaliser votre workflow. Vous pouvez également publier vos notes en ligne, les accéder hors ligne et les synchroniser en toute sécurité avec le chiffrement de bout en bout.", "Offer as exit node?": "Proposer comme nœud de sortie ?", + "Official Emby Media Server image with optional VA-API or NVIDIA acceleration.": "Image officielle Emby Media Server avec accélération VA-API ou NVIDIA en option.", + "Official Jellyfin image with optional VA-API or NVIDIA acceleration.": "Image officielle Jellyfin avec accélération VA-API ou NVIDIA en option.", "Official Linux Distributions": "Distributions Linux officielles", + "Official Plex Media Server image with optional hardware transcoding.": "Image officielle Plex Media Server avec transcodage matériel en option.", + "Official image": "Image officielle", "Old debian.sources file removed to prevent duplication": "Ancien fichier debian.sources supprimé pour éviter la duplication", "Old memory configuration detected. Replacing with balanced optimization...": "Ancienne configuration de mémoire détectée. Remplacement par une optimisation équilibrée...", "Old time services removed successfully": "Les anciens services ont été supprimés avec succès", + "Ombi allows you to host your own Plex Request and user management system.": "Ombi vous permet d'accueillir votre propre système de demande et de gestion des utilisateurs Plex.", "On a privileged CT the mount options carry the only permissions.": "Sur un CT privilégié, les options de montage portent les seules autorisations.", "On some systems, when starting the VM the host may slow down for several minutes until it stabilizes, or freeze completely.": "Sur certains systèmes, lors du démarrage de la VM, l'hôte peut ralentir pendant plusieurs minutes jusqu'à ce qu'il se stabilise, ou se figer complètement.", "On the Borg server, append the following line to:": "Sur le serveur Borg, ajoutez la ligne suivante à :", @@ -3091,32 +4065,53 @@ "Once finished, re-run the script 'PVE 8 to 9 check' to verify that all issues.": "Une fois terminé, réexécutez le script « PVE 8 to 9 check » pour vérifier que tous les problèmes sont résolus.", "Once installed, open the VirtIO ISO and run the installer to complete driver setup.": "Une fois installé, ouvrez l'ISO VirtIO et exécutez le programme d'installation pour terminer la configuration du pilote.", "One or more NVIDIA GPUs are currently configured for VM passthrough (vfio-pci):": "Un ou plusieurs GPU NVIDIA sont actuellement configurés pour le relais de VM (vfio-pci) :", + "Online retro games emulator": "Jeux rétro en ligne émulateur", + "Only a Docker Swarm uses these settings, so they are not applied:": "Seul un Swarm Docker utilise ces paramètres, donc ils ne sont pas appliqués:", "Only convert to privileged if absolutely necessary for your use case.": "Ne convertissez en privilèges que si cela est absolument nécessaire pour votre cas d'utilisation.", "Only fully free disks are shown (not system-used and not referenced by VM/LXC).": "Seuls les disques entièrement libres sont affichés (non utilisés par le système et non référencés par VM/LXC).", "Only if using enterprise subscription": "Uniquement si vous utilisez un abonnement entreprise", "Only if using no-subscription repository": "Uniquement si vous utilisez un référentiel sans abonnement", "Only needed if you mounted the filesystem in step 6b": "Nécessaire uniquement si vous avez monté le système de fichiers à l'étape 6b", + "Only one image at a time can be installed this way.": "Une seule image à la fois peut être installée de cette façon.", "Only removes storage definition, not remote data.": "Supprime uniquement la définition de stockage, pas les données distantes.", "Only run this if you used LVM (step 6b):": "Exécutez-le uniquement si vous avez utilisé LVM (étape 6b) :", "Only the host backup hook is removed — PVE vzdump jobs targeting this storage stay intact.": "seul le hook de sauvegarde de l'hôte est supprimé – les tâches PVE vzdump ciblant ce stockage restent intactes.", + "Only the image reference, with no Compose file": "Seule la référence d'image, sans fichier Compose", "Open": "Ouvrir", + "Open Source realtime backend in 1 file": "Ouvrir le moteur en temps réel dans 1 fichier", "Open rwx + default inheritance for new files": "Ouvrir rwx + héritage par défaut pour les nouveaux fichiers", + "Open source chat UI for AI models": "Open source chat UI pour les modèles d'IA", + "Open source home automation that puts local control and privacy first.": "La domotique open source qui place le contrôle local et la confidentialité en premier.", + "Open source, lightweight, native, supports (HTTP, BitTorrent, Magnet, etc.) for downloading.": "Open source, léger, natif, supports (HTTP, BitTorrent, Magnet, etc.) pour le téléchargement.", "Open the VM console and wait for the installer to boot": "Ouvrez la console VM et attendez que le programme d'installation démarre", "Open the VM console and wait for the loader to boot": "Ouvrez la console VM et attendez que le chargeur démarre", "Open the dashboard from this host on port 8008 to create a new admin account.": "Ouvrez le tableau de bord de cet hôte sur le port 8008 pour créer un nouveau compte administrateur.", "Open the dashboard to create a new admin account:": "Ouvrez le tableau de bord pour créer un nouveau compte administrateur :", + "Open-source AI-powered coding assistant": "Assistant de codage à source ouverte", + "Open-source UI for building and debugging multi-agent and RAG applications": "UI open-source pour la construction et le débogage d'applications multi-agents et RAG", + "Open-source self-hosted SQL IDE.": "IDE SQL auto-organisé open-source.", + "OpenClaw is a personal AI assistant you run on your own devices": "OpenClaw est un assistant d'IA personnel que vous exécutez sur vos propres appareils", + "OpenList": "OpenList", + "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world.": "OpenShot Video Editor est un éditeur vidéo gratuit et open-source primé pour Linux, Mac et Windows, et est dédié à fournir des solutions d'édition vidéo et d'animation de haute qualité au monde.", + "OpenVINO requires a CPU quota to keep the CPU topology": "OpenVINO requires un quota CPU pour garder la topologie CPU", + "OpenVINO requires the render device of an Intel GPU": "OpenVINO requires le périphérique de rendu d'un GPU Intel", "OpenVSwitch installation could not be verified": "L'installation d'OpenVSwitch n'a pas pu être vérifiée", "OpenVSwitch installed successfully": "OpenVSwitch installé avec succès", "OpenVSwitch is ready to use": "OpenVSwitch est prêt à être utilisé", "OpenVSwitch removed": "OpenVSwitch supprimé", + "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server.": "Openssh-server est un environnement sandbox qui permet l'accès à ssh sans donner de clés à l'ensemble du serveur.", + "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser.": "Openvscode-server fournit une version de VS Code qui gère un serveur sur une machine distante et permet l'accès via un navigateur Web moderne.", + "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features.": "Opera est un navigateur web multiplateforme développé par sa société nominative Opera. Le navigateur est basé sur Chromium, mais se distingue des autres navigateurs basés sur Chromium (Chrome, Edge, etc.) par son interface utilisateur et d'autres fonctionnalités.", "Operation": "Opération", "Operation cancelled by user": "Opération annulée par l'utilisateur", "Operation cancelled by user to create backup.": "Opération annulée par l'utilisateur pour créer une sauvegarde.", "Operation cancelled by user.": "Opération annulée par l'utilisateur.", + "Operation cancelled.": "Operation annulée.", "Operation cancelled. Cannot continue with an unprivileged container.": "Opération annulée. Impossible de continuer avec un conteneur non privilégié.", "Operation log": "Journal des opérations", "Operator config re-applied via kernel-agnostic merge": "configuration de l'opérateur réappliquée via une fusion indépendante du noyau", "Operator config that WILL be re-applied via kernel-agnostic merge": "configuration de l'opérateur qui SERA réappliquée via une fusion indépendante du noyau", + "Optical block device (e.g. /dev/sr0)": "Dispositif de blocage optique (par exemple /dev/sr0)", "Optimizations detected and ready to revert.": "Optimisations détectées et prêtes à être annulées.", "Optimize": "Optimiser", "Optimize Memory": "optimiser la mémoire", @@ -3129,8 +4124,12 @@ "Optimizing network settings...": "Optimisation des paramètres réseau...", "Optimizing vzdump backup speed...": "Optimisation de la vitesse de sauvegarde de vzdump...", "Optional": "facultatif", + "Optional GID of the plex group": "GID facultatif du groupe plex", "Optional GPU Passthrough": "Passthrough GPU en option", + "Optional published URL for Jellyfin": "URL publiée en option pour Jellyfin", "Optional safety helper if you ever need to re-apply manually:": "Assistant de sécurité facultatif si jamais vous devez réappliquer manuellement :", + "Optional token from https://www.plex.tv/claim": "Jeton facultatif à partir de https://www.plex.tv/claim", + "Optional, not mounted by default": "Facultatif, non monté par défaut", "Optional: Modernize repository sources:": "Facultatif : Modernisez les sources du référentiel :", "Optional: apply default ACL so new files inherit permissions:": "Facultatif : appliquez l'ACL par défaut pour que les nouveaux fichiers héritent des autorisations :", "Optional: register this path as Proxmox dir storage:": "Facultatif : enregistrez ce chemin en tant que stockage du répertoire Proxmox :", @@ -3141,13 +4140,18 @@ "Or re-run this script and accept the 'apply host permissions' prompt.": "Ou réexécutez ce script et acceptez l'invite « appliquer les autorisations de l'hôte ».", "Or use ProxMenux update function": "Ou utilisez la fonction de mise à jour de ProxMenux", "Or, if your terminal can't select text, copy it from:": "Ou, si votre terminal ne peut pas sélectionner de texte, copiez-le depuis :", + "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community": "Orca Slicer est une trancheuse open source pour imprimantes FDM. OrcaSlicer est le fork de Bambu Studio, il était auparavant connu sous le nom de BambuStudio-SoftFever, Bambu Studio est le fork de PrusaSlicer par Prusa Research, qui est de Slic3r par Alessandro Rannellucci et la communauté RepRap", "Original ZFS ARC config restored from .bak": "Configuration ZFS ARC d'origine restaurée à partir de .bak", "Original bashrc restored": "Bashrc d'origine restauré", "Original logrotate configuration restored": "Configuration de rotation d'origine restaurée", + "Orphan stack contract archived:": "Contrat de pile d'orphelin archivé :", + "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.": "Oscam est un logiciel Open Source Conditional Access Module utilisé pour le décraquage des cartes à puce DVB transmissions. C'est un serveur et un client.", "Other Prebuilt Linux VMs": "Autres machines virtuelles Linux prédéfinies", "Output archive:": "Archives de sortie :", + "Overseerr is a request management and media discovery tool built to work with your existing Plex ecosystem.": "Overseerr est un outil de gestion des demandes et de découverte des médias conçu pour travailler avec votre écosystème Plex existant.", "Owner:": "Propriétaire:", "Ownership set to root:sharedfiles with 2775 on:": "Propriété définie sur root:sharedfiles avec 2775 sur :", + "P2P bittorrent download": "P2P bittorrent télécharger", "PAM limits configured": "Limites PAM configurées", "PBS API log rotation configured (hourly, size-based)": "rotation des journaux de l'API PBS configurée (horaire, basée sur la taille)", "PBS backup error log": "Journal des erreurs de sauvegarde PBS", @@ -3164,7 +4168,9 @@ "PCI reset method": "Méthode de réinitialisation PCI", "PCIe GPU passthrough requires:": "Le relais GPU PCIe nécessite :", "PCIe/M.2 gasket-dkms": "PCIe/M.2 gasket-dkms", + "PCSX2 is an open source PS2 Emulator.": "PCSX2 est un émulateur PS2 open source.", "POSIX ACLs applied (access + default for inheritance).": "ACL POSIX appliquées (accès + valeur par défaut pour l'héritage).", + "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability.": "PPSSPP est un émulateur PSP gratuit et open-source pour Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series et Symbian avec un accent sur la vitesse et la portabilité.", "PVE application manager updated": "Gestionnaire d'applications PVE mis à jour", "PVE cache regenerated": "Cache PVE régénéré", "PVE host (where the Borg LXC lives)": "hôte PVE (où vit le Borg LXC)", @@ -3179,17 +4185,28 @@ "Package update had issues, checking details...": "La mise à jour du package a rencontré des problèmes, vérification des détails...", "Packages from backup to install:": "Packages de la sauvegarde à installer :", "Packages installed: {count}.": "Packages installés : {count}.", + "Packages to be upgraded": "Les paquets à mettre à jour", "Packages upgrade successfull": "Mise à jour des packages réussie", "Packages upgraded": "Forfaits mis à niveau", "Packages:": "Forfaits :", "Packaging OVA file...": "Emballage du fichier OVA...", "Packing installer archive...": "Archive du programme d'installation de l'emballage...", + "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices.": "PairDrop est une sublime alternative à AirDrop qui fonctionne sur toutes les plateformes. Envoyez des images, des documents ou du texte via une connexion pair à des appareils du même réseau local/Wi-Fi ou à des appareils appariés.", + "Paperless configuration cancelled": "Configuration sans papier annulée", + "Paperless-ngx WebUI": "Paperless-ngx WebUI", "Parsing OVF descriptor...": "Analyse du descripteur OVF...", "Partial VM removed": "VM partielle supprimée", "Partition": "Partition", "Partition created": "Partition créée", "Partition created:": "Partition créée :", "Partition table wiped": "Table de partition effacée", + "Pass /dev/kvm to the LXC": "Passer /dev/kvm au LXC", + "Pass /dev/net/tun to the LXC": "Passer /dev/net/tun au LXC", + "Pass /dev/ttyUSB0 to the LXC": "Passer /dev/ttyUSB0 au LXC", + "Pass /dev/video10 to the LXC": "Passer /dev/video10 au LXC", + "Pass /dev/video11 to the LXC": "Passez /dev/video11 au LXC", + "Pass /dev/video12 to the LXC": "Passer /dev/video12 au LXC", + "Pass a host device to the LXC": "Passer un appareil hôte au LXC", "Passphrase used to unlock the imported keyfile (leave blank if the keyfile is unencrypted / kdf=none):": "Phrase secrète utilisée pour déverrouiller le fichier de clés importé (laisser vide si le fichier de clés n'est pas chiffré / kdf=aucun) :", "Passphrases do not match.": "Les phrases secrètes ne correspondent pas.", "Passphrases do not match. Try again.": "Les phrases secrètes ne correspondent pas. Essayer à nouveau.", @@ -3202,17 +4219,42 @@ "Password confirmation cannot be empty.": "La confirmation du mot de passe ne peut pas être vide.", "Password confirmation is required.": "Une confirmation du mot de passe est requise.", "Password for": "Mot de passe pour", + "Password for aMule external connections (remote client)": "Mot de passe pour les connexions externes aMule (client éloigné)", + "Password for the SSH login": "Mot de passe pour la connexion SSH", "Password for:": "Mot de passe pour :", "Password is correct": "Le mot de passe est correct", + "Password of the AdGuard Home that receives the settings": "Mot de passe du AdGuard Home qui reçoit les paramètres", + "Password of the Adguardhome Sync web interface": "Mot de passe de l'interface web Adguardhome Sync", + "Password of the Duplicati web interface": "Mot de passe de l'interface web Duplicati", + "Password of the Etherpad admin user": "Mot de passe de l'utilisateur administrateur Etherpad", + "Password of the FlexGet web interface": "Mot de passe de l'interface web FlexGet", + "Password of the LibreDB Studio administrator": "Mot de passe de l'administrateur LibreDB Studio", + "Password of the MineOS web interface user": "Mot de passe de l'utilisateur de l'interface web MineOS", + "Password of the NetBox admin account": "Mot de passe du compte admin NetBox", + "Password of the OpenList admin user": "Mot de passe de l'utilisateur administrateur OpenList", + "Password of the PhotoPrism admin user (at least 8 characters)": "Mot de passe de l'utilisateur administrateur PhotoPrism (au moins 8 caractères)", + "Password of the PostgreSQL user": "Mot de passe de l'utilisateur PostgreSQL", + "Password of the SnapOtter admin user": "Mot de passe de l'utilisateur administrateur SnapOtter", + "Password of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Mot de passe de l'application Flowise dépréciée (seulement lu par les versions Flowise avant 3.0.1)", + "Password of the main AdGuard Home": "Mot de passe du AdGuard Home principal", "Password or API token secret:": "Mot de passe ou secret du jeton API :", + "Password or secret": "Mot de passe ou secret", "Password reset completed.": "Réinitialisation du mot de passe terminée.", + "Password to access the aMule web interface": "Mot de passe pour accéder à l'interface web aMule", "Passwords do not match. Please try again.": "Les mots de passe ne correspondent pas. Veuillez réessayer.", + "Paste it here and press Ctrl+D on an empty line.": "Collez-le ici et appuyez sur Ctrl+D sur une ligne vide.", + "Paste its Compose file in the terminal": "Coller son fichier Composer dans le terminal", + "Paste its docker run command in the terminal": "Coller sa commande d'exécution docker dans le terminal", "Paste the UUP Dump URL here": "Collez l'URL de vidage UUP ici", "Patching source for kernel compatibility...": "Source de correctifs pour la compatibilité du noyau...", "Path does not exist.": "Le chemin n'existe pas.", + "Path inside the container": "Voie à l'intérieur du conteneur", + "Path inside the container (e.g. /media-extra)": "Voie à l'intérieur du conteneur (par exemple /media-extra)", + "Path inside the remote (empty = root)": "Chemin à l'intérieur de la télécommande (vide = racine)", "Path must be absolute (start with /)": "Le chemin doit être absolu (commencer par /)", "Path must be absolute (start with /).": "Le chemin doit être absolu (commencer par /).", "Path not found": "Chemin introuvable", + "Path of the Compose file": "Chemin du fichier Composer", "Path:": "Chemin:", "Paths applied:": "Chemins appliqués :", "Paths included in backup": "Chemins inclus dans la sauvegarde", @@ -3220,6 +4262,10 @@ "Paths skipped:": "Chemins ignorés :", "Paths to back up:": "Chemins à sauvegarder :", "Paths:": "Chemins :", + "Peers reach the server through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Les pairs atteignent le serveur par l'adresse publique et le port UDP donné pendant l'installation, de sorte que le port doit être transmis à ce conteneur.", + "Peers to create: a number (3) or a list of names (phone,laptop)": "Les pairs à créer : un nombre (3) ou une liste de noms (téléphone,ordinateur portable)", + "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration.": "Pelorus est un navigateur AI pour les bureaux Linux alimentés par Selkies. Pelorus gère un serveur FastAPI qui permet à un agent LLM (Ollama, compatible OpenAI ou Gemini) de contrôler la gestion de la souris, du clavier, de la capture d'écran et de la fenêtre via le moteur d'utilisation de Pixelflux, un arbre d'accessibilité Linux (AT-SPI) et une intégration optionnelle KWin D-Bus.", + "Pending components:": "Composantes en suspens", "Pending restore ID:": "ID de restauration en attente :", "Pending restore dir:": "Répertoire de restauration en attente :", "Pending restore prepared. A reboot is required to complete it.": "En attente de restauration préparée. Un redémarrage est nécessaire pour le terminer.", @@ -3243,7 +4289,15 @@ "Permission error": "Erreur d'autorisation", "Permissions:": "Autorisations :", "Persist mount in CT /etc/fstab (optional):": "Conserver le montage dans CT /etc/fstab (facultatif) :", + "Persistence for": "Persistance pour", + "Persistence for the new path": "Persistance pour le nouveau chemin", + "Persistent data:": "Données persistantes:", + "Persistent disk reused:": "Disque persistant réutilisé :", "Persistent:": "Persistant:", + "Personal finance management application": "Demande de gestion des finances personnelles", + "Photo and video library with optional GPU transcoding and machine learning": "Photothèque et vidéothèque avec transcodage GPU optionnel et apprentissage automatique", + "PhotoPrism": "PhotoPrism", + "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB.": "Phpmyadmin est un logiciel libre écrit en PHP, destiné à gérer l'administration de MySQL sur le Web. phpMyAdmin prend en charge une large gamme de operations sur MySQL et MariaDB.", "Physical Function with": "Fonction physique avec", "Physical interface": "Interface physique", "Physical interfaces available": "Interfaces physiques disponibles", @@ -3256,6 +4310,10 @@ "Pick a target to remove:": "Choisissez une cible à supprimer :", "Pick an SSH private key (auto-detected on this host):": "Choisissez une clé privée SSH (détectée automatiquement sur cet hôte) :", "Pick an alternative way to authorize the new key:": "Choisissez une autre manière d'autoriser la nouvelle clé :", + "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time.": "Pidgin est un programme de chat qui vous permet de vous connecter à des comptes sur plusieurs réseaux de chat simultanément. Cela signifie que vous pouvez discuter avec des amis sur XMPP et vous asseoir dans une chaîne IRC en même temps.", + "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper.": "Piper est un système de texte neural à la parole rapide et local qui sonne bien et est optimisé pour le Raspberry Pi 4. Ce conteneur fournit un serveur de protocole de Wyoming pour Piper.", + "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures.": "Piwigo est un logiciel de galerie de photos pour le web qui est livré avec des fonctionnalités puissantes pour publier et gérer votre collection d'images.", + "Planka is an elegant open source project tracking tool.": "Planka est un élégant outil de suivi de projet open source.", "Please check network connectivity.": "Veuillez vérifier la connectivité réseau.", "Please check permissions and try again.": "Veuillez vérifier les autorisations et réessayer.", "Please check the installation.": "Veuillez vérifier l'installation.", @@ -3273,6 +4331,10 @@ "Please select GPU(s) that are currently in the same mode and try again.": "Veuillez sélectionner le(s) GPU actuellement dans le même mode et réessayer.", "Please select a valid option": "Veuillez sélectionner une option valide", "Please use an SSH session (Linux, macOS, Windows/PuTTY) or a physical console to perform the upgrade.": "Veuillez utiliser une session SSH (Linux, macOS, Windows/PuTTY) ou une console physique pour effectuer la mise à niveau.", + "Plex WebUI": "Plex WebUI", + "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.": "Plex organise la vidéo, la musique et les photos des bibliothèques de médias personnels et les diffuse vers des téléviseurs intelligents, des boîtes de streaming et des appareils mobiles. Ce conteneur est emballé comme un serveur multimédia autonome Plex. La conception directe et les actions en vrac signifient faire les choses plus vite.", + "PocketBase admin UI": "PocketBase UI administrateur", + "Podcast synchronization service": "Service de synchronisation Podcast", "Pool does not appear to use SSD/NVMe devices with discard support. Skipping ZFS autotrim for pool:": "Le pool ne semble pas utiliser de périphériques SSD/NVMe prenant en charge la suppression. Ignorer le découpage automatique ZFS pour le pool :", "Pool exists": "La piscine existe", "Pool name matches but GUID differs (fresh ZFS install):": "le nom du pool correspond mais le GUID diffère (nouvelle installation de ZFS) :", @@ -3283,12 +4345,21 @@ "Portal IP and port are correct": "L'adresse IP et le port du portail sont corrects", "Portal is reachable": "Le portail est accessible", "Portal:": "Portail:", + "Ports": "Ports", "Portuguese": "portugais", "Post-Installation Options": "Options de post-installation", "Post-Installation Scripts": "Scripts de post-installation", "Postfix configuration": "Configuration de Postfix", + "PostgreSQL": "PostgreSQL", + "PostgreSQL URL without an associated service:": "URL PostgreSQL sans service associé:", + "PostgreSQL creates the database named in POSTGRES_DB on the first start. The installer default is postgresql.": "PostgreSQL crée la base de données nommée dans POSTGRES DB au premier démarrage. Par défaut, l'installation est postgresql.", + "PostgreSQL is an advanced, enterprise-class, and open-source relational database system. PostgreSQL supports both SQL (relational) and JSON (non-relational) querying.": "PostgreSQL est un système de base de données relationnelles avancé, de classe entreprise et open-source. PostgreSQL prend en charge les requêtes SQL (relational) et JSON (non-relational).", + "PostgreSQL requires a password": "PostgreSQL requires un mot de passe", + "PostgreSQL volume size in GB": "Taille du volume PostgreSQL en GB", "Potential QEMU startup/assertion failures": "Échecs potentiels de démarrage/d’assertion de QEMU", "Power state D3cold/D0 transitions may be inaccessible": "Les transitions de l'état d'alimentation D3cold/D0 peuvent être inaccessibles", + "Powerful OCR powered by DeepSeek AI": "Puissant OCR alimenté par DeepSeek AI", + "Powerful networking tool": "Outil puissant de mise en réseau", "Pre-check found": "Pré-vérification trouvée", "Pre-configure destinations so you don't have to enter them every time you back up.": "Préconfigurez les destinations afin de ne pas avoir à les saisir à chaque sauvegarde.", "Pre-existing gasket-dkms package removed.": "Le paquet gasket-dkms préexistant a été supprimé.", @@ -3296,11 +4367,15 @@ "Pre-upgrade check FAILED: the simulation shows that 'proxmox-ve' would be REMOVED.\n This indicates a repository or dependency issue and upgrading now could break your Proxmox installation.": "ÉCHEC de la vérification avant la mise à niveau : la simulation montre que « proxmox-ve » serait SUPPRIMÉ.\n Cela indique un problème de référentiel ou de dépendance et une mise à niveau maintenant pourrait interrompre votre installation Proxmox.", "Pre-upgrade simulation failed. See log:": "La simulation préalable à la mise à niveau a échoué. Voir le journal :", "Pre-upgrade simulation passed: 'proxmox-ve' will be kept or upgraded safely.": "Simulation de pré-mise à niveau réussie : « proxmox-ve » sera conservé ou mis à niveau en toute sécurité.", + "Prepared; the container was not modified yet": "Préparé; le contenant n'a pas encore été modifié", "Preparing Log2RAM configuration": "Préparation de la configuration de Log2RAM", "Preparing files for backup...": "Préparation des fichiers pour la sauvegarde...", "Preparing host mount...": "Préparation du montage sur l'hôte...", "Preparing pending restore (network-safe)": "Préparation de la restauration en attente (sécurisée sur le réseau)", "Preparing staging area...": "Préparation de la zone de préparation...", + "Preparing the NVIDIA GPU...": "Préparation du GPU NVIDIA...", + "Preparing the recreation...": "Préparer les loisirs...", + "Preparing the update...": "Préparation de la mise à jour...", "Preserving logs to /var/log.hdd before unmounting...": "Conserver les journaux dans /var/log.hdd avant de démonter...", "Press 'q' to exit": "Appuyez sur « q » pour quitter", "Press Ctrl+C to stop the server and return to menu.": "Appuyez sur Ctrl+C pour arrêter le serveur et revenir au menu.", @@ -3316,6 +4391,7 @@ "Press Enter to return": "Appuyez sur Entrée pour revenir", "Press Enter to return to menu...": "Appuyez sur Entrée pour revenir au menu...", "Press Enter to return to the main menu...": "Appuyez sur Entrée pour revenir au menu principal...", + "Press Enter to return to the menu...": "Appuyez sur Entrée pour revenir au menu...", "Press Enter to return...": "Appuyez sur Entrée pour revenir...", "Press Enter when the line has been pasted on the server...": "Appuyez sur Entrée lorsque la ligne a été collée sur le serveur...", "Press OK to see the preview, then confirm": "Appuyez sur OK pour voir l'aperçu, puis confirmez", @@ -3325,9 +4401,20 @@ "Preview changes (diff)": "Aperçu des modifications (diff)", "Preview: changes that would be applied": "Aperçu : modifications qui seraient appliquées", "Previous DKMS tree cleared.": "L’arborescence DKMS précédente a été effacée.", + "Previous Rclone configuration restored": "Configuration Rclone précédente restaurée", "Previous installation cleaned": "Installation précédente nettoyée", "Previous installation removed": "Installation précédente supprimée", + "Previous installation restored": "Installation précédente restaurée", "Previous shutdowns": "Arrêts précédents", + "Primary GID for Emby": "GID primaire pour Emby", + "Privacy-first finance app with envelope budgeting and multi-device sync.": "Privacy-first finance app avec enveloppe budgeting et synchronisation multi-appareils.", + "Privacy-first, self-hosted PDF toolkit": "Boîte à outils PDF pour la première fois en matière de protection de la vie privée", + "Private installation record saved": "Enregistrement d'installation privé enregistré", + "Private network assigned automatically:": "Réseau privé assigné automatiquement:", + "Private network of the application released:": "Réseau privé de la demande publiée:", + "Private network of the application that is released:": "Réseau privé de la demande qui est publiée:", + "Private network:": "Réseau privé:", + "Private personal knowledge management": "Gestion privée des connaissances personnelles", "Privileged": "Privilégié", "Privileged Container": "Conteneur privilégié", "Privileged Container Required": "Conteneur privilégié requis", @@ -3338,6 +4425,7 @@ "Privileged container — host root maps directly, no permission changes needed": "Conteneur privilégié : hébergez directement les mappages racines, aucune modification d'autorisation n'est nécessaire", "Privileged containers can access host devices directly": "Les conteneurs privilégiés peuvent accéder directement aux appareils hôtes", "Privileged containers have full root access to the host system!": "Les conteneurs privilégiés ont un accès root complet au système hôte !", + "Privileged installation declined": "Défaut d'installation privilégié", "Privileged: Full host access (less secure)": "Privilégié : accès complet à l'hôte (moins sécurisé)", "Proceed": "Procéder", "Proceed with removal": "Procéder à la suppression", @@ -3346,11 +4434,15 @@ "Process may take several minutes depending on container size": "Le processus peut prendre plusieurs minutes selon la taille du conteneur", "Process may take several minutes for large containers": "Le processus peut prendre plusieurs minutes pour les grands conteneurs", "Processes using NVIDIA:": "Processus utilisant NVIDIA :", + "Productivity & Workflows": "Productivité et flux de travail", "Profile": "Profil", "Profile:": "Profil :", + "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files.": "Projectsend est une application auto-portée qui vous permet de télécharger des fichiers et de les assigner à des clients spécifiques que vous créez vous-même. Sécurisée, privée et facile. Pas plus selon les services externes ou e-mail pour envoyer ces fichiers.", "Proposed Changes": "Modifications proposées", "Proposed ZFS ARC maximum:": "ZFS ARC maximum proposé :", "Provided by newer version — skipping": "fourni par une version plus récente – sauter", + "Prowlarr does not offer the application schema:": "Prowlarr n'offre pas le schéma d'application :", + "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all).": "Prowlarr est un gestionnaire d'indexeur/proxy construit sur la pile de base arr .net/réactjs populaire pour s'intégrer à vos différentes applications PVR. Prowlarr prend en charge à la fois Torrent Trackers et Usenet Indexers. Il s'intègre parfaitement avec Sonarr, Radarr, Lidarr et Readarr offrant une gestion complète de vos indexeurs sans aucune configuration par application.", "ProxMenux Information": "Informations sur ProxMenux", "ProxMenux Monitor": "ProxMenux Monitor", "ProxMenux Monitor Service Verification": "ProxMenux Monitor Vérification du service", @@ -3364,10 +4456,12 @@ "ProxMenux Monitor protection": "Protection du ProxMenux Monitor", "ProxMenux Monitor unit repaired and restarted": "Unité ProxMenux Monitor réparée et redémarrée", "ProxMenux Monitor → Backups tab (live progress card with estimated time, logs, rollback delta)": "ProxMenux Monitor → Onglet Sauvegardes (carte de progression en direct avec durée estimée, journaux, delta de restauration)", + "ProxMenux attaches directories, not single files, so this image cannot be installed yet.": "ProxMenux attache des répertoires, pas des fichiers uniques, donc cette image ne peut pas encore être installée.", "ProxMenux can apply open permissions on this NFS directory from the host so the container can read and write:": "ProxMenux peut appliquer des autorisations d'ouverture sur ce répertoire NFS depuis l'hôte afin que le conteneur puisse lire et écrire :", "ProxMenux can remount it with open permissions so any LXC can read and write.": "ProxMenux peut le remonter avec des autorisations ouvertes afin que n'importe quel LXC puisse lire et écrire.", "ProxMenux cannot override NFS server-side permissions from the host.": "ProxMenux ne peut pas remplacer les autorisations côté serveur NFS de l'hôte.", "ProxMenux customizations removed from bashrc": "Personnalisations de ProxMenux supprimées de bashrc", + "ProxMenux does not give a container the system of its host.": "ProxMenux ne donne pas à un conteneur le système de son hôte.", "ProxMenux does not validate the contents; any keyfile your PBS accepts is accepted here.": "ProxMenux ne valide pas le contenu ;tout fichier clé accepté par votre PBS est accepté ici.", "ProxMenux files:": "Fichiers ProxMenux :", "ProxMenux logo applied": "Logo ProxMenux appliqué", @@ -3399,6 +4493,7 @@ "Proxmox repository configuration completed": "Configuration du référentiel Proxmox terminée", "Proxmox repository fixed (no-subscription, candidate is 9.x)": "Dépôt Proxmox corrigé (sans abonnement, le candidat est 9.x)", "Proxmox status:": "Statut Proxmox :", + "Proxmox storage for the volume": "Stockage Proxmox pour le volume", "Proxmox storages:": "Stockages Proxmox :", "Proxmox system repair completed successfully!": "Réparation du système Proxmox terminée avec succès !", "Proxmox system repair completed with some issues.": "Réparation du système Proxmox terminée avec quelques problèmes.", @@ -3408,16 +4503,28 @@ "Proxmox web interface: Datacenter > Storage > Add > SMB/CIFS": "Interface web Proxmox : Datacenter > Stockage > Ajouter > SMB/CIFS", "Proxmox web interface: Datacenter > Storage > Add > ZFS": "Interface web Proxmox : Datacenter > Stockage > Ajouter > ZFS", "Proxmox web interface: Datacenter > Storage > Add > iSCSI": "Interface Web Proxmox : Datacenter > Stockage > Ajouter > iSCSI", + "Public UDP port clients connect to": "Les clients du port UDP public se connectent à", + "Public UDP port peers connect to": "Les pairs du port UDP public se connectent à", + "Public URL of phpMyAdmin when it is served behind a reverse proxy": "URL publique de phpMyAdmin quand elle est servie derrière un proxy inversé", + "Public address clients connect to (vpn.example.com or a public IP)": "Les clients d'adresses publiques se connectent à (vpn.example.com ou à un IP public)", + "Public address peers connect to, or auto to detect it (vpn.example.com)": "Pairs d'adresse publique se connectent, ou auto pour le détecter (vpn.example.com)", "Pulling latest changes from GitHub...": "Extraction des dernières modifications de GitHub...", "Purge the gasket-dkms package": "Purger le paquet gasket-dkms", "Purging gasket-dkms package...": "Purge du paquet gasket-dkms...", "Purging log2ram apt package...": "Purge du paquet log2ram apt...", + "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.": "Pwndrop est un service d'hébergement de fichiers autodéployable pour envoyer des équipes rouges ou partager vos fichiers privés en toute sécurité via HTTP et WebDAV.", + "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more.": "PyCharm offre une prise en charge hors de la boîte pour Python, bases de données, Jupyter, Git, Conde, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, et plus encore.", + "Pydio Cells needs an external MySQL or MariaDB database. The setup wizard asks for its address, database name and user on the first start.": "Pydio Cells a besoin d'une base de données externe MySQL ou MariaDB. L'assistant de configuration demande son adresse, son nom de base de données et son utilisateur au premier démarrage.", + "Pydio Cells redirects to the address given in EXTERNALURL. If the container changes address, edit lxc.environment.runtime: EXTERNALURL and SERVER_IP in /etc/pve/lxc/.conf with the container stopped, and delete /config/keys/cert.crt to regenerate the certificate.": "Pydio Cells redirige vers l'adresse indiquée dans EXTERNALURL. Si le conteneur change d'adresse, éditer lxc.environment.runtime: EXTERNALURL et SERVER IP dans /etc/pve/lxc/.conf avec le conteneur arrêté, et supprimer /config/keys/cert.crt pour régénérer le certificat.", + "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture.": "Pydio-cells est la plateforme de partage de fichiers nextgen pour les organisations. C'est une réécriture complète du projet Pydio en utilisant le langage Go suivant une architecture de micro-service.", + "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat.": "QDirStat Statistiques de répertoire basées sur Qt: KDirStat sans KDE -- de l'auteur de l'original KDirStat.", "Quick health check (PASSED / FAILED)": "Bilan de santé rapide (RÉUSSI / ÉCHEC)", "Quick health status — overall SMART result + key attributes": "État de santé rapide – résultat SMART global + attributs clés", "RAID Detected": "RAID détecté", "RAID member detected": "Membre RAID détecté", "RAM Size": "Taille de la RAM", "RAM and swap usage": "Utilisation de la RAM et du swap", + "RAM in MiB": "RAM en MIB", "REPAIR SUMMARY": "RÉSUMÉ DE LA RÉPARATION", "REQUIREMENTS:": "EXIGENCES:", "ROM dump not available — configuring without romfile.": "Dump ROM non disponible - configuration sans fichier rom.", @@ -3425,9 +4532,26 @@ "RPC Bind Service: RUNNING": "Service de liaison RPC : EN EXÉCUTION", "RPC Bind Service: STOPPED": "Service de liaison RPC : ARRÊTÉ", "RPC Bind Service: STOPPED - starting...": "Service de liaison RPC : ARRÊTÉ - démarrage...", + "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD.": "RPCS3 est un émulateur et un débogueur Sony PlayStation 3 multiplateforme, écrit en C++ pour Windows, Linux, macOS et FreeBSD.", + "Radarr - A fork of Sonarr to work with movies à la Couchpotato.": "Radarr - A fork de Sonarr pour travailler avec des films à la Couchpotato.", + "Radarr added to Prowlarr": "Radarr ajouté à Prowlarr", + "Radarr connected to qBittorrent": "Radarr connecté à qBittorrent", + "Radarr root folder configured": "Dossier racine Radarr configuré", + "RagFlow is an open-source RAG engine based on deep document understanding.": "RagFlow est un moteur RAG ouvert basé sur une compréhension approfondie des documents.", + "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase.": "Raneto - est une plateforme de base de connaissances open source qui utilise des fichiers de Markdown statiques pour alimenter votre base de connaissances.", + "Raneto web interface": "Interface web Raneto", + "RawTherapee is a free, cross-platform raw image processing program!": "RawTherapee est un programme de traitement d'image brut gratuit et multiplateforme!", + "Rclone WebUI": "Rclone WebUI", + "Rclone mount": "Montage à rouleaux", + "Rclone mount active": "Montage Rclone actif", + "Rclone mount needs a privileged LXC with FUSE access. The container is dedicated to Rclone and its web UI must not be exposed to untrusted networks.": "Le montage Rclone a besoin d'un LXC privilégié avec accès FUSE. Le conteneur est dédié à Rclone et son interface web ne doit pas être exposée à des réseaux non fiables.", + "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network.": "Rclone monture requires un LXC privilégié avec accès FUSE. Utilisez ce profil uniquement sur un nœud et un réseau de confiance.", + "Rclone mount requires a privileged container": "Rclone mount requires un conteneur privilégié", "Re-enter the BORG REPOKEY passphrase to confirm:": "saisissez à nouveau la phrase secrète BORG REPOKEY pour confirmer :", "Re-running pre-check after repairs...": "Nouvelle vérification préalable après réparation...", "Reachable": "Accessible", + "Read its Compose file from a file of this host": "Lire son fichier Composer à partir d'un fichier de cet hôte", + "Read the link with pct console CTID on the Proxmox host, or from the Console panel of the container in the Proxmox web interface, then open the https://playit.gg/claim/ address it shows in a browser and sign in to playit.gg. Ctrl+a q leaves pct console.": "Lisez le lien avec la console pct CTID sur l'hôte Proxmox, ou depuis le panneau Console du conteneur dans l'interface web Proxmox, puis ouvrez l'adresse https://playit.gg/claim/ qu'elle affiche dans un navigateur et connectez-vous à playit.gg. Ctrl+a q quitte la console pct.", "Read-Only": "Lecture seule", "Read-Only access": "Accès en lecture seule", "Read-Write (universal)": "Lecture-écriture (universel)", @@ -3436,6 +4560,7 @@ "Read-only access (or no write permissions).": "Accès en lecture seule (ou aucune autorisation en écriture).", "Read-only mount": "Montage en lecture seule", "Read/Write (default)": "Lecture/écriture (par défaut)", + "Read/write": "Lecture/écriture", "Read/write CPU model-specific registers": "Lecture/écriture de registres spécifiques au modèle de processeur", "Readable user table (UID, shell, etc.)": "Table utilisateur lisible (UID, shell, etc.)", "Reading NVMe SMART data...": "Lecture des données NVMe SMART...", @@ -3443,7 +4568,9 @@ "Reading SMART data...": "Lecture des données SMART...", "Reading SMART self-test log...": "Lecture du journal d'autotest SMART...", "Reading full SMART report...": "Lecture du rapport SMART complet...", + "Real-time Performance Monitoring": "Surveillance du rendement en temps réel", "Real-time bandwidth usage (press q to exit)": "Utilisation de la bande passante en temps réel (appuyez sur q pour quitter)", + "Real-time collaborative document editor": "Éditeur de document collaboratif en temps réel", "Real-time network monitoring (press q to exit)": "Surveillance du réseau en temps réel (appuyez sur q pour quitter)", "Real-time network usage (iftop)": "Utilisation du réseau en temps réel (iftop)", "Reason: Access denied": "Raison : Accès refusé", @@ -3465,6 +4592,7 @@ "Recent Samba server": "Serveur Samba récent", "Recent logs:": "Journaux récents :", "Recent test results:": "Résultats de tests récents :", + "Recognition profile not implemented": "Profil de reconnaissance non mis en œuvre", "Recommendation: reformat the disk to ext4 for a robust setup — see docs.": "Recommandation : reformatez le disque en ext4 pour une configuration robuste – voir la documentation.", "Recommendation: start with Complete restore.": "Recommandation : commencez par Restauration complète.", "Recommendation: use 'Export to file' for these paths and apply manually during a maintenance window.": "Recommandation : utilisez « Exporter vers un fichier » pour ces chemins et appliquez-le manuellement pendant une fenêtre de maintenance.", @@ -3476,17 +4604,36 @@ "Recommended: use GPU -> LXC mode for these devices.": "Recommandé : utilisez le mode GPU -> LXC pour ces appareils.", "Recommended: use GPU with LXC workloads instead of VM passthrough on this hardware.": "Recommandé : utilisez le GPU avec les charges de travail LXC au lieu du relais VM sur ce matériel.", "Reconciled": "Réconcilié", + "Recover OCI": "Récupérer le BEC", + "Recover OCI stack": "Récupérer la pile OCI", + "Recover now?": "Récupérer maintenant ?", + "Recover or complete the operation?": "Récupérer ou compléter la operation?", "Recover the keyfile using your recovery passphrase?": "Récupérer le fichier de clés à l'aide de votre phrase secrète de récupération ?", + "Recover the previous installation": "Récupérer l'installation précédente", "Recoverable:": "Récupérable :", + "Recovering the previous installation": "Récupération de l'installation précédente", "Recovery blob upload failed — main backup is OK, but keyfile recovery from PBS will not be available for this backup.": "Échec du téléchargement du blob de récupération – la sauvegarde principale est OK, mais la récupération du fichier de clé à partir de PBS ne sera pas disponible pour cette sauvegarde.", "Recovery blob:": "Blob de récupération :", + "Recovery completed. The container had not been modified yet.": "Récupération terminée. Le contenant n'avait pas encore été modifié.", + "Recovery completed. The displaced disks and the backup are kept; nothing was deleted automatically.": "Récupération terminée. Les disques déplacés et la sauvegarde sont conservés ; rien n'a été supprimé automatiquement.", "Recovery failed": "La récupération a échoué", "Recovery passphrase": "Phrase secrète de récupération", "Recovery setup failed": "La configuration de la récupération a échoué", + "Recreate": "Recréer", + "Recreate OCI": "Recréer le BEC", + "Recreate with these options?": "Recréer avec ces options ?", + "Recreate: edit resources, network, paths and GPU": "Recréer: éditer ressources, réseau, chemins et GPU", + "Recreating requires a confirmed proposal": "Recréer requires une proposition confirmée", + "Recreating the container...": "Recréer le conteneur...", + "Recreating the container:": "Recréation du réservoir:", + "Recreation completed. Data kept.": "Loisirs terminés. Données conservées.", + "Recreation prepared": "Loisirs préparés", "Refresh APT index and verify repositories:": "Actualisez l'index APT et vérifiez les référentiels :", "Refresh your browser (Ctrl+Shift+R) to see changes": "Actualisez votre navigateur (Ctrl+Shift+R) pour voir les modifications", "Refresh your browser to see changes (server restart may be required)": "Actualisez votre navigateur pour voir les modifications (un redémarrage du serveur peut être nécessaire)", "Refreshing apt cache...": "Actualisation du cache apt...", + "Refreshing the NVIDIA runtime...": "Rafraîchir l'exécution NVIDIA...", + "Refusing an unexpected rootfs path:": "Refuser un chemin inattendu de roofs :", "Regenerating PVE package cache...": "Régénération du cache des packages PVE...", "Regenerating boot artifacts for the merged kernel-agnostic changes...": "Régénération des artefacts de démarrage pour les modifications fusionnées indépendantes du noyau...", "Regenerating certificates and restarting services...": "Régénération des certificats et redémarrage des services...", @@ -3502,6 +4649,7 @@ "Reinstalled Proxmox packages successfully": "Packages Proxmox réinstallés avec succès", "Reinstalling": "Réinstallation", "Reinstalling core Proxmox packages...": "Réinstallation des packages Proxmox principaux...", + "Relative CPU priority (cpuunits)": "Priorité relative du CPU (cpuunits)", "Release Channel": "Canal de sortie", "Release channel set to Beta.": "Canal de sortie défini sur Bêta.", "Release channel set to Stable.": "Canal de sortie réglé sur Stable.", @@ -3511,8 +4659,12 @@ "Remapped Users:": "Utilisateurs remappés :", "Remapped users:": "Utilisateurs remappés :", "Reminder: You must install the QEMU Guest Agent inside the Windows VM": "Rappel : vous devez installer l'agent invité QEMU dans la VM Windows", + "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported.": "Remmina est un client de bureau à distance écrit en GTK, visant à être utile pour les administrateurs système et les voyageurs, qui ont besoin de travailler avec beaucoup d'ordinateurs distants devant les grands ou petits écrans. Remmina prend en charge plusieurs protocoles réseau, dans une interface utilisateur intégrée et cohérente. Actuellement, RDP, VNC, SPICE, SSH et EXEC sont pris en charge.", + "Remote Access & VPN": "Accès à distance et VPN", + "Remote dry run completed; no container was created.": "Un parcours sec à distance est terminé; aucun conteneur n'a été créé.", "Remote repository path:": "Chemin du référentiel distant :", "Remote server via SSH (recommended — off-host, dedup across machines)": "Serveur distant via SSH (recommandé – hors hôte, déduplication sur plusieurs machines)", + "Remote verified:": "Télévérifié:", "Remounting CIFS share with open permissions...": "Remontage du partage CIFS avec des autorisations ouvertes...", "Remove CIFS Mount": "Supprimer le support CIFS", "Remove CIFS Mount (pvesm or fstab)": "Supprimer le support CIFS (pvesm ou fstab)", @@ -3540,6 +4692,7 @@ "Remove NFS fstab Mount": "Supprimer le montage NFS fstab", "Remove NFS fstab mount:": "Supprimez le montage NFS fstab :", "Remove NFS storage:": "Supprimez le stockage NFS :", + "Remove OCI": "Supprimer le BEC", "Remove Proxmox CIFS storage:": "Supprimez le stockage Proxmox CIFS :", "Remove Proxmox NFS storage:": "Supprimez le stockage Proxmox NFS :", "Remove Proxmox iSCSI storage:": "Supprimez le stockage iSCSI Proxmox :", @@ -3551,6 +4704,7 @@ "Remove iSCSI storage definition:": "Supprimez la définition de stockage iSCSI :", "Remove invalid port": "Supprimer le port invalide", "Remove invalid port(s)": "Supprimer les ports invalides", + "Remove it? The data of its containers cannot be recovered afterwards.": "L'enlever ? Les données de ses conteneurs ne peuvent pas être récupérées par la suite.", "Remove keyfile from this host": "Supprimer le fichier de clés de cet hôte", "Remove mount point:": "Supprimer le point de montage :", "Remove obsolete systemd-boot meta-package": "Supprimer le méta-paquet systemd-boot obsolète", @@ -3559,6 +4713,7 @@ "Remove subscription banner": "Supprimer la bannière d'abonnement", "Remove the unprivileged flag from configuration:": "Supprimez l'indicateur sans privilèges de la configuration :", "Remove unused packages and their config": "Supprimer les packages inutilisés et leur configuration", + "Remove: delete the application and its containers": "Supprimer: supprimer l'application et ses conteneurs", "Removed": "Supprimé", "Removed KVM MSR options from configuration": "Options KVM MSR supprimées de la configuration", "Removed Mount:": "Support supprimé :", @@ -3609,6 +4764,9 @@ "Removing stale VFIO entries from vfio.conf...": "Suppression des entrées VFIO obsolètes de vfio.conf...", "Removing storage from Proxmox...": "Suppression du stockage de Proxmox...", "Removing system limits optimizations...": "La suppression des optimisations des limites du système...", + "Removing the containers...": "Enlever les conteneurs...", + "Removing the incomplete stack...": "Enlever la pile incomplète...", + "Removing the previous container": "Suppression du conteneur précédent", "Removing utilities installed by ProxMenux...": "Suppression des utilitaires installés par ProxMenux...", "Removing zfs-auto-snapshot...": "Suppression de zfs-auto-snapshot...", "Renamed": "Renommé", @@ -3616,6 +4774,7 @@ "Repair Complete": "Réparation terminée", "Repair Options:": "Options de réparation :", "Repairs and optimizes repositories": "Répare et optimise les référentiels", + "Repeat to confirm": "Répéter pour confirmer", "Replace": "Remplacer", "Replace with the actual ID.": "Remplacez par l'ID réel.", "Replace with your actual container ID": "Remplacez par votre ID de conteneur réel", @@ -3628,12 +4787,16 @@ "Repositories switched to no-subscription": "Les référentiels sont passés au sans abonnement", "Repository ready.": "Référentiel prêt.", "Repository:": "Dépôt:", + "Request a staging certificate for testing: true or false": "Demander un certificat de mise à l'essai : vrai ou faux", "Require reboot": "Nécessite un redémarrage", "Required command not found:": "Commande requise introuvable :", "Required if using a VirtIO or SCSI disk.": "Requis si vous utilisez un disque VirtIO ou SCSI.", "Required install helpers not available.": "Les aides à l'installation requises ne sont pas disponibles.", + "Required new path cancelled": "Required nouveau chemin annulé", + "Required persistent paths cannot be removed": "Les chemins persistants required ne peuvent pas être enlevés", "Requires acl package. Skip if setfacl is not available.": "Nécessite le package acl. Ignorer si setfacl n'est pas disponible.", "Requires authentication": "Nécessite une authentification", + "Reserving a private network...": "Réserver un réseau privé...", "Reset Capability Blocked": "Capacité de réinitialisation bloquée", "Reset Capability Warning": "Avertissement de capacité de réinitialisation", "Reset Monitor Password": "Réinitialiser le mot de passe du moniteur", @@ -3641,7 +4804,9 @@ "Reset current storage selection": "Réinitialiser la sélection de stockage actuelle", "Resetting time synchronization...": "Réinitialisation de la synchronisation de l'heure...", "Residual Bookworm entries commented where applicable": "Entrées résiduelles de Bookworm commentées le cas échéant", + "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes.": "Resilio-sync (anciennement BitTorrent Sync) utilise le protocole BitTorrent pour synchroniser les fichiers et les dossiers entre tous vos appareils. Il y a à la fois des versions gratuites et payantes, ce conteneur supporte les deux. Il y a une image de synchronisation officielle mais nous avons créé celle-ci car elle prend en charge la cartographie utilisateur pour simplifier les autorisations pour les volumes.", "Resolve package conflicts": "Résoudre les conflits de packages", + "Resources": "Ressources", "Restart Network": "Redémarrer le réseau", "Restart Network Service": "Redémarrer le service réseau", "Restart Web UI proxy": "Redémarrer le proxy de l'interface utilisateur Web", @@ -3673,8 +4838,11 @@ "Restore plan summary": "Résumé du plan de restauration", "Restore source location": "Restaurer l'emplacement source", "Restored config is on disk; reboot the host to apply.": "La configuration restaurée est sur le disque ; redémarrez l'hôte pour appliquer.", + "Restored installation checked": "Correction de l'installation", "Restored original /bin/gzip": "Original restauré /bin/gzip", "Restored original /etc/vzdump.conf from .bak": "/etc/vzdump.conf d'origine restauré à partir de .bak", + "Restored:": "Restauré :", + "Restoring": "Restauration", "Restoring APT language downloads...": "Restauration des téléchargements de langue APT...", "Restoring container memory to": "Restauration de la mémoire du conteneur sur", "Restoring default journald configuration...": "Restauration de la configuration journald par défaut...", @@ -3682,15 +4850,23 @@ "Restoring original bashrc...": "Restauration du bashrc d'origine...", "Restoring original logrotate configuration...": "Restauration de la configuration originale de la rotation des logs...", "Restoring subscription banner...": "Restauration de la bannière d'abonnement...", + "Restoring the backup": "Restaurer la sauvegarde", "Restoring the original rpcbind service state...": "Restauration de l'état d'origine du service rpcbind...", + "Restoring the previous Rclone configuration...": "Restaurer la configuration Rclone précédente...", + "Restoring the previous backup...": "Restaurer la sauvegarde précédente...", + "Restoring the previous state of the stack...": "Restaurer l'état précédent de la pile...", + "Restoring the stack records...": "Restaurer les enregistrements de la pile...", "Results will be saved automatically to:": "Les résultats seront automatiquement enregistrés dans :", "Results will be saved to:": "Les résultats seront enregistrés dans :", "Retention": "Rétention", + "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface.": "RetroArch est une interface pour les émulateurs, les moteurs de jeu et les joueurs multimédias. Il vous permet d'exécuter des jeux classiques sur une large gamme d'ordinateurs et de consoles grâce à son interface graphique slick.", "Return": "Retour", "Return to Main Menu": "Retour au menu principal", "Return to Share Menu": "Revenir au menu Partager", "Return to main menu": "Retour au menu principal", + "Returning the containers to their previous state...": "Retour des conteneurs dans leur état précédent...", "Reused the encryption key from the PVE storage entry.": "réutilisation de la clé de cryptage de l'entrée de stockage PVE.", + "Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container.": "Les échantillons proxy inversés pour d'autres applications sont dans /config/nginx/proxy confs à l'intérieur du conteneur.", "Reverting AMD (Ryzen/EPYC) fixes...": "Annulation des correctifs AMD (Ryzen/EPYC)...", "Reverting IOMMU/VFIO configuration...": "Rétablissement de la configuration IOMMU/VFIO...", "Reverting TCP BBR + Fast Open...": "Rétablissement de TCP BBR + ouverture rapide...", @@ -3699,22 +4875,31 @@ "Reverting vzdump speed tuning...": "Annulation du réglage de la vitesse de vzdump...", "Review passthrough config files": "Examiner les fichiers de configuration relais", "Review what will be removed": "Vérifiez ce qui sera supprimé", + "Rip DVD and Blu-ray media from a browser": "Rip DVD et Blu-ray médias à partir d'un navigateur", "Rollback: nothing to remove (host matches backup)": "Rollback : rien à supprimer (l'hôte correspond à la sauvegarde)", + "Rolling back the incomplete container": "Retourner le conteneur incomplet", + "RomM is a self-hosted ROM manager for managing and playing game collections.": "RomM est un gestionnaire autonome de ROM pour gérer et jouer des collections de jeux.", "Root SSH keys/config": "Clés/configuration SSH racine", "Root inside container = root on host system": "Racine à l'intérieur du conteneur = racine sur le système hôte", + "Root privileges are required": "Les privilèges de racine sont required", + "Root privileges on the Proxmox node are required": "Les privilèges de racine sur le noeud Proxmox sont required", "Root shell/profile config": "Configuration du shell/profil racine", "Root user on the PVE host (default 'root'):": "Utilisateur root sur l'hôte PVE ('root' par défaut) :", + "Rootfs size in GB": "Taille des racines en GB", "Rotate the recovery passphrase": "Faites pivoter la phrase secrète de récupération", "Routing Information": "Informations d'acheminement", "Routing Table": "Table de routage", + "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required.": "Rsnapshot est un utilitaire de snapshot système de fichiers basé sur rsync. rsnapshot facilite la réalisation d'instantanés périodiques de machines locales et de machines à distance sur ssh. Le code fait une large utilisation de liens durs chaque fois que possible, pour réduire considérablement l'espace disque required.", "Run 'Mount NFS Share' to install NFS client automatically.": "Exécutez « Monter le partage NFS » pour installer automatiquement le client NFS.", "Run 'Mount Samba Share' to install CIFS client automatically.": "Exécutez « Mount Samba Share » pour installer automatiquement le client CIFS.", + "Run GGUF LLMs locally with GPU acceleration": "Exécuter localement des LLM GGUF avec accélération GPU", "Run PVE 8 to 9": "Exécutez le PVE 8 à 9", "Run PVE 8 to 9 check": "Exécutez la vérification PVE 8 à 9", "Run \\\"Install NVIDIA Drivers on Host\\\" first so the installer is cached.": "Exécutez d'abord \\\"Installer les pilotes NVIDIA sur l'hôte\\\" pour que le programme d'installation soit mis en cache.", "Run a full security audit": "Exécutez un audit de sécurité complet", "Run a job now": "Exécutez un travail maintenant", "Run apt-get install -f to complete any pending package configurations": "Exécutez apt-get install -f pour terminer toutes les configurations de package en attente", + "Run as root on the Proxmox node; the registry contains private data": "Exécuter comme racine sur le noeud Proxmox; le registre contient des données privées", "Run as server or client? [s/c]:": "Exécuter en tant que serveur ou client ? [s/c] :", "Run checklist again to verify upgrade:": "Exécutez à nouveau la liste de contrôle pour vérifier la mise à niveau :", "Run from console, or SSH inside tmux/screen": "Exécuté depuis la console ou SSH dans tmux/screen", @@ -3739,6 +4924,7 @@ "Running dkms autoinstall for kernel": "Exécution de l'installation automatique de dkms pour le noyau", "Running kernel:": "Exécuter le noyau :", "Running pre-upgrade simulation to verify 'proxmox-ve' will remain installed...": "Exécution d'une simulation de pré-mise à niveau pour vérifier que « proxmox-ve » restera installé...", + "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration.": "RustDesk est une alternative à la télécommande open source pour l'auto-hébergement et la sécurité avec une configuration minimale.", "SATA (standard - high compatibility)": "SATA (standard - haute compatibilité)", "SCSI (recommended for Linux and Windows)": "SCSI (recommandé pour Linux et Windows)", "SCSI (recommended for Linux)": "SCSI (recommandé pour Linux)", @@ -3755,6 +4941,7 @@ "SMB ports:": "Ports PME :", "SR-IOV Configuration Detected": "Configuration SR-IOV détectée", "SSD Emulation": "Émulation SSD", + "SSH access": "Accès SSH", "SSH access (host + root)": "Accès SSH (hôte + root)", "SSH auth logger service created and started": "Service d'enregistrement d'authentification SSH créé et démarré", "SSH hardening: MaxAuthTries set to 3 (Lynis recommendation)": "Renforcement SSH : MaxAuthTries défini sur 3 (recommandation Lynis)", @@ -3769,6 +4956,8 @@ "STEP 9: Cleanup (LVM only)": "ÉTAPE 9 : Nettoyage (LVM uniquement)", "STORAGE TYPE IDENTIFICATION:": "IDENTIFICATION DU TYPE DE STOCKAGE :", "SUGGESTION FOR": "SUGGESTION POUR", + "SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.": "SWAG sert HTTPS sur le port 443. Un HTTP simple sur le port 80 est désactivé dans /config/nginx/site-confs/default.conf.", + "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction.": "Sabnzbd rend Usenet aussi simple et rationalisé que possible en automatisant tout ce que nous pouvons. Tout ce que vous avez à faire est d'ajouter un .nzb. SABnzbd prend la relève de là, où il sera automatiquement téléchargé, vérifié, réparé, extrait et rangé avec aucune interaction humaine.", "Safe design: no automatic ACL/ownership mutation on host or CT.": "Conception sécurisée : pas de mutation automatique d’ACL/propriété sur l’hôte ou le CT.", "Safe to apply now": "Postuler en toute sécurité maintenant", "Safety Backup": "Sauvegarde de sécurité", @@ -3822,8 +5011,13 @@ "Same major series:": "Même grande série :", "Same major.minor:": "Même majeur.mineur :", "Sanitizing NVIDIA host services for VFIO mode...": "Désinfection des services hôtes NVIDIA pour le mode VFIO...", + "Save and classify articles. Read them later. Freely.": "Enregistrer et classer les articles. Lisez-les plus tard. Gratuitement.", "Save the passphrase somewhere safe NOW, before continuing.": "Enregistrez la phrase secrète dans un endroit sûr MAINTENANT, avant de continuer.", "Save this Borg target so you don't need to enter the details again?": "Enregistrer cette cible Borg pour ne pas avoir à saisir à nouveau les détails ?", + "Saved record removed": "Enregistrement supprimé", + "Saving the new configuration": "Enregistrement de la nouvelle configuration", + "Saving the new configuration...": "Enregistrer la nouvelle configuration...", + "Saving the stack records...": "Enregistrer les enregistrements de la pile...", "Scan storage for new content": "Analyser le stockage pour trouver du nouveau contenu", "Scanning available physical disks...": "Analyse des disques physiques disponibles...", "Scanning network for NFS servers...": "Réseau d'analyse pour les serveurs NFS...", @@ -3835,11 +5029,19 @@ "Scheduled backups and retention policies": "Sauvegardes planifiées et politiques de conservation", "Scheduled tasks (cron)": "Tâches planifiées (cron)", "Scheduler script not found:": "Script du planificateur introuvable :", + "ScreenScraper": "Scrapeur d'écran", + "ScreenScraper password": "Mot de passe ScreenScraper", + "ScreenScraper username": "Nom d'utilisateur ScreenScraper", "Script Information": "Informations sur le script", "Script not found:": "Script introuvable :", "Scripts in": "Scripts dans", + "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator.": "ScummVM est un programme qui vous permet d'exécuter certaines aventures graphiques classiques et jeux de rôle, à condition que vous ayez déjà leurs fichiers de données. La partie intelligente à ce sujet: ScummVM remplace les exécutables livrés avec les jeux, vous permettant de les jouer sur des systèmes pour lesquels ils n'ont jamais été conçus! ScummVM est une réécriture complète des exécutables de ces jeux et n'est pas un émulateur.", + "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions—such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server.": "Sealskin est une plate-forme client-serveur auto-organisé qui permet aux utilisateurs d'exécuter des applications de bureau puissantes et containerizzato diffusées directement sur un navigateur Web. Il utilise une extension de navigateur pour intercepter les actions de l'utilisateur – comme cliquer sur un lien ou télécharger un fichier et les rediriger vers un environnement d'application sécurisé et isolé fonctionnant sur un serveur distant.", "Search Results for:": "Résultats de recherche pour :", + "Search applications": "Recherche des applications", + "Search results for:": "Résultats de recherche pour :", "Search/Filter Scripts": "Scripts de recherche/filtrage", + "Searchable document archive with OCR": "Archive documentaire consultable avec OCR", "Secure Disk Formatter": "Formateur de disque sécurisé", "Secure Gateway (Tailscale VPN)": "Secure Gateway (VPN Tailscale)", "Secure Gateway deployed successfully!": "Secure Gateway déployé avec succès !", @@ -3847,8 +5049,12 @@ "Security": "Sécurité", "Security Updates": "Mises à jour de sécurité", "Security Warning — read before applying": "Avertissement de sécurité – à lire avant de postuler", + "Security directive outside the dynamic profile": "Directive de sécurité en dehors du profil dynamique", + "Security relaxation declined": "La détente en matière de sécurité a diminué", "See": "Voir", "See /tmp/proxmenux-mount.log for details.": "Voir /tmp/proxmenux-mount.log pour plus de détails.", + "Seerr WebUI": "Seerr WebUI", + "Seerr/Bazarr connections, the SABnzbd client and the Lidarr profiles, root folder and client are configured manually in this version.": "Les connexions Seerr/Bazarr, le client SABnzbd et les profils Lidarr, le dossier racine et le client sont configurés manuellement dans cette version.", "Select": "Sélectionner", "Select Borg target": "Sélectionnez la cible Borg", "Select CPU model": "Sélectionnez le modèle de processeur", @@ -3888,6 +5094,7 @@ "Select a Custom Logo": "Sélectionnez un logo personnalisé", "Select a VirtIO ISO to use:": "Sélectionnez un ISO VirtIO à utiliser :", "Select a category of useful commands:": "Sélectionnez une catégorie de commandes utiles :", + "Select a category or search for applications:": "Sélectionnez une catégorie ou recherchez des applications :", "Select a category or search for scripts:": "Sélectionnez une catégorie ou recherchez des scripts :", "Select a custom ISO to use:": "Sélectionnez un ISO personnalisé à utiliser :", "Select a job:": "Sélectionnez un emploi :", @@ -3897,6 +5104,7 @@ "Select a pre-configured Linux VM script to execute:": "Sélectionnez un script de machine virtuelle Linux préconfiguré à exécuter :", "Select a script or action:": "Sélectionnez un script ou une action :", "Select a share to delete:": "Sélectionnez un partage à supprimer :", + "Select a specific Coral or USB node, not the whole /dev": "Sélectionnez un noeud spécifique Coral ou USB, pas l'ensemble /dev", "Select access mode": "Sélectionnez le mode d'accès", "Select an existing group": "Sélectionnez un groupe existant", "Select an existing group:": "Sélectionnez un groupe existant :", @@ -3907,6 +5115,7 @@ "Select archive": "Sélectionner les archives", "Select archive to restore": "Sélectionnez l'archive à restaurer", "Select at least one path to continue.": "sélectionnez au moins un chemin pour continuer.", + "Select at least one suite application": "Sélectionnez au moins une application suite", "Select authentication mode:": "Sélectionnez le mode d'authentification :", "Select authentication type:": "Sélectionnez le type d'authentification :", "Select available Controllers/NVMe to add:": "Sélectionnez les contrôleurs/NVMe disponibles à ajouter :", @@ -4011,6 +5220,19 @@ "Selected optimizations have been uninstalled.": "Les optimisations sélectionnées ont été désinstallées.", "Selected paths produced no entries to apply.": "les chemins sélectionnés n'ont produit aucune entrée à appliquer.", "Selected utilities installation completed": "Installation des utilitaires sélectionnés terminée", + "Selection": "Sélection", + "Self-custodial Bitcoin Lightning wallet with integrated node and app connections.": "Auto-custodial Bitcoin Lightning portefeuille avec nœud intégré et connexions app.", + "Self-hosted ZeroTier network controller with web UI for centralized management.": "Contrôleur réseau ZeroTier auto-organisé avec interface utilisateur web pour une gestion centralisée.", + "Self-hosted cloud data migration & sync manager": "Gestion de migration et de synchronisation de données en nuage auto-organisé", + "Self-hosted collaborative bookmark manager to collect, read, annotate, and fully preserve what matters, all in one place.": "Gestionnaire de signets collaboratifs auto-organisés pour recueillir, lire, annoter et préserver pleinement ce qui compte, le tout en un seul endroit.", + "Self-hosted file sharing with a modern web interface": "Partage de fichiers auto-organisé avec une interface web moderne", + "Self-hosted file toolkit for images, video, audio, PDFs, and files": "Boîte à outils de fichiers auto-organisé pour les images, vidéo, audio, PDF et fichiers", + "Self-hosted internet archiving solution": "Solution d'archivage internet auto-organisé", + "Self-hosted recipe manager and meal planner": "Gestionnaire de recettes et planificateur de repas", + "Self-hosted software development service": "Service de développement de logiciels autonomes", + "Self-signed TLS certificate created:": "Certificat TLS autosigné créé :", + "Selfhosted PDF manager, viewer and editor": "Gestionnaire, visionneur et éditeur de PDF auto-organisé", + "Selkies desktop and streaming acceleration": "Selkies bureau et l'accélération de streaming", "Sending backup to Borg repository...": "Envoi de la sauvegarde au référentiel Borg...", "Sending backup to PBS...": "Envoi de sauvegarde vers PBS...", "Server": "Serveur", @@ -4025,14 +5247,19 @@ "Server will listen on TCP port 5201.": "Le serveur écoutera sur le port TCP 5201.", "Server:": "Serveur:", "Servers": "Serveurs", + "Service": "Services", "Service Status": "Statut du service", "Service is active and running": "Le service est actif et en cours d'exécution", "Service is inactive": "Le service est inactif", + "Service ready:": "Service prêt:", + "Service responding:": "Réponse du service :", "Service restarted.": "Service redémarré.", "Service restarts:": "Le service redémarre :", "Service stopped.": "Service arrêté.", + "Service:": "Service:", "Services failed": "Les services ont échoué", "Services restarted": "Services redémarrés", + "Services that depend on the main service are not yet supported": "Les services qui dépendent du service principal ne sont pas encore pris en charge", "Services:": "Services:", "Set Display > Graphic card (VGA, SPICE or VirtIO) to match the guest": "Réglez Affichage > Carte graphique (VGA, SPICE ou VirtIO) pour correspondre à l'invité", "Set Hostname": "Définir le nom d'hôte", @@ -4077,13 +5304,26 @@ "Share:": "Partager:", "Shared Directory Ready:": "Répertoire partagé prêt :", "Shared Group": "Groupe partagé", + "Shared directory created:": "Répertoire partagé créé & #160;:", + "Shared directory for consume and export": "Répertoire partagé pour la consommation et l'exportation", + "Shared directory for copy/sync operations": "Répertoire partagé pour copier/sync operations", "Shared group: CONFIGURED": "Groupe partagé : CONFIGURÉ", "Shared group: sharedfiles (GID:": "Groupe partagé : fichiers partagés (GID :", + "Shared host content (not included in LXC backups):": "Contenu d'hôte partagé (non inclus dans les sauvegardes LXC):", + "Shared host data is not reverted by the backup. Continue?": "Les données d'hôte partagées ne sont pas retournées par la sauvegarde. Continuez ?", + "Shared host data is not reverted by the backups. Continue?": "Les données d'hôte partagées ne sont pas retournées par les sauvegardes. Continuez ?", + "Shared host directories (not included in Proxmox backups)": "Répertoires d'hôtes partagés (non inclus dans les sauvegardes Proxmox)", + "Shared host directory": "Répertoire d'hôte partagé", + "Shared host directory (not included in Proxmox backups)": "Répertoire d'hôte partagé (non inclus dans les sauvegardes Proxmox)", + "Shared host files are kept as they are; the backup does not restore their content.": "Les fichiers d'hôte partagés sont conservés tels quels ; la sauvegarde ne restaure pas leur contenu.", + "Shared host media directory": "Répertoire des médias hôtes partagés", + "Shared memory size for the GPU workload in MB": "Taille de mémoire partagée pour la charge de travail GPU en MB", "Sharedfiles group already exists (GID: 101000)": "Le groupe Sharedfiles existe déjà (GID : 101000)", "Shares found:": "Partages trouvés :", "Shell user ulimit set": "Ensemble ulimit utilisateur Shell", "Short self-test started on": "Court autotest démarré le", "Short test — ~2 minutes, basic surface check": "Test court — ~ 2 minutes, vérification de base de la surface", + "Shotcut is a free, open source, cross-platform video editor.": "Shotcut est un éditeur vidéo libre, open source, multiplateforme.", "Should show 'unprivileged: 0' or no unprivileged line": "Doit afficher « non privilégié : 0 » ou aucune ligne non privilégiée", "Should show 'unprivileged: 1'": "Doit afficher « non privilégié : 1 »", "Should show 'unprivileged: 1' if it's unprivileged": "Doit afficher « non privilégié : 1 » s'il n'est pas privilégié", @@ -4125,14 +5365,23 @@ "Show size of a directory": "Afficher la taille d'un répertoire", "Show standard exclude patterns": "Afficher les modèles d'exclusion standard", "Show status of all storage pools": "Afficher l'état de tous les pools de stockage", + "Show the QR code of a peer again with: pct exec -- /app/show-peer 1": "Afficher de nouveau le code QR d'un pair avec: pct exec -- /app/show-peer 1", "Show traffic statistics per interface": "Afficher les statistiques de trafic par interface", "Show vzdump backup configuration": "Afficher la configuration de sauvegarde vzdump", "Shows status and type (nfs/cifs/dir/iscsi...).": "Affiche l'état et le type (nfs/cifs/dir/iscsi...).", "Shutdown timeout": "Délai d'arrêt", + "SiYuan access code": "Code d'accès SiYuan", + "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more..": "SickGear assure la gestion d'émissions TV et/ou Anime, détecte de nouveaux épisodes, links downloader apps, etc.", + "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private.": "Signal est une application de messagerie avec la confidentialité à son cœur. Il est gratuit et facile à utiliser, avec un cryptage de bout en bout fort qui maintient votre communication complètement privée.", "Signatures removed. Partition table preserved.": "Signatures supprimées. Table de partition conservée.", + "Simple and easy to use DDNS": "Simple et facile à utiliser DDNS", "Single GPU Warning": "Avertissement sur un seul GPU", "Single target found — selected automatically:": "Cible unique trouvée — sélectionnée automatiquement :", "Size": "Taille", + "Size in GB of": "Taille en GB", + "Size of each consume/export volume in GB": "Taille de chaque consommation/exportation en GB", + "Size of the /dev/shm shared memory in MB": "Taille de la mémoire partagée /dev/shm en MB", + "Size of the Frigate temporary cache in MB": "Taille du cache temporaire Frigate en MB", "Size:": "Taille:", "Skip downloading additional languages": "ignorer le téléchargement de langues supplémentaires", "Skip this device": "Ignorer cet appareil", @@ -4142,6 +5391,7 @@ "Skip — leave as-is": "Sauter — laisser tel quel", "Skipped (no disks of the pool are present on this host):": "Ignoré (aucun disque du pool n’est présent sur cet hôte) :", "Skipped (some disks missing):": "Sauté (certains disques manquants) :", + "Skipped because Jellyfin did not create encoding.xml:": "Passé parce que Jellyfin n'a pas créé encoding.xml:", "Skipped device": "Appareil ignoré", "Skipped to protect target system (would cascade-remove packages)": "Ignoré pour protéger le système cible (supprimerait les packages en cascade)", "Skipped, not in apt cache:": "Ignoré, pas dans le cache apt :", @@ -4149,7 +5399,10 @@ "Skipping SR-IOV device": "Ignorer le périphérique SR-IOV", "Skipping installation.": "Sauter l'installation.", "Skipping manual patches — feranick fork already supports this kernel.": "Ignorer les correctifs manuels — feranick fork prend déjà en charge ce noyau.", + "Sleek podcast downloader with GPodder sync": "Téléchargeur de podcast Sleek avec synchronisation GPodder", "Smart restore plan — hardware compatibility check": "Plan de restauration intelligent – vérification de la compatibilité matérielle", + "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis.": "Smokeping suit votre latence réseau. Pour un exemple complet de ce que cette application est capable de visiter UCDavis.", + "SnapOtter": "SnapOtter", "Snippets — hook scripts / config": "Extraits - scripts de hook / configuration", "SoC-integrated GPU: tight coupling with other SoC components": "GPU intégré au SoC : couplage étroit avec d'autres composants du SoC", "Some DKMS removals reported errors; final verification will determine the result.": "Certaines suppressions de DKMS ont signalé des erreurs ;la vérification finale déterminera le résultat.", @@ -4159,6 +5412,7 @@ "Some old time services could not be removed (not installed)": "Certains anciens services n'ont pas pu être supprimés (non installés)", "Some operations failed — review messages above. Press Enter to continue...": "Certaines opérations ont échoué : consultez les messages ci-dessus. Appuyez sur Entrée pour continuer...", "Some packages still need attention; review": "Certains packages nécessitent encore une attention particulière ;revoir", + "Some projects publish a Dockerfile and not an image: it has to be built and published to a registry before it can be installed this way. An image of a private registry needs credentials, which are not supported yet.": "Certains projets publient un fichier Docker et non une image: il doit être construit et publié dans un registre avant de pouvoir être installé de cette façon. Une image d'un registre privé nécessite credentials, qui ne sont pas encore pris en charge.", "Some repairs failed. Please fix manually and re-run the script.": "Certaines réparations ont échoué. Veuillez corriger manuellement et réexécuter le script.", "Some repositories are not available, continuing with available ones...": "Certains référentiels ne sont pas disponibles, continuons avec ceux disponibles...", "Some selected GPUs are already configured in this container.": "Certains GPU sélectionnés sont déjà configurés dans ce conteneur.", @@ -4166,6 +5420,10 @@ "Some utility packages could not be removed; the remaining list has been preserved": "Certains packages utilitaires n'ont pas pu être supprimés ;the remaining list has been preserved", "Something is already mounted at": "Quelque chose est déjà monté sur", "Something is already mounted at:": "Quelque chose est déjà monté sur :", + "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Sonarr (anciennement NZBdrone) est un PVR pour les utilisateurs de usenet et de bittorrent. Il peut surveiller plusieurs flux RSS pour les nouveaux épisodes de vos spectacles préférés et va les saisir, les trier et les renommer. Il peut également être configuré pour améliorer automatiquement la qualité des fichiers déjà téléchargés lorsqu'un format de meilleure qualité devient disponible.", + "Sonarr added to Prowlarr": "Sonarr ajouté à Prowlarr", + "Sonarr connected to qBittorrent": "Sonarr connecté à qBittorrent", + "Sonarr root folder configured": "Dossier racine Sonarr configuré", "Source": "Source", "Source VM": "VM source", "Source patched successfully.": "Source corrigée avec succès.", @@ -4174,8 +5432,26 @@ "Spanish": "Espagnol", "Specific host (enter IP)": "Hôte spécifique (entrez IP)", "Specific subnet (enter manually)": "Sous-réseau spécifique (saisir manuellement)", + "Speedtest Tracker web interface": "Interface web Speedtest Tracker", + "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service.": "Speedtest-tracker est une application de suivi de performance internet auto-organisé qui effectue des contrôles de test de vitesse contre le service Speedtest d'Ookla.", + "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium": "Spotube est un client Spotify ouvert et multiplateforme compatible avec plusieurs plateformes utilisant l'API de données de Spotify et YouTube, Piped. vidéo ou JioSaavn comme source audio, éliminant le besoin de Spotify Premium", "Stable (main branch)": "Stable (branche principale)", "Stable monitor service normalized.": "Service de surveillance stable normalisé.", + "Stack": "Stack", + "Stack adapter not recognized by the translator": "Adaptateur empilé non reconnu par le traducteur", + "Stack backups are missing; a partial restore is not allowed": "Les sauvegardes sont manquantes ; une restauration partielle n'est pas autorisée", + "Stack checked:": "A vérifié :", + "Stack members are missing; recreate them after verifying their volumes": "Les membres sont manquants ; recréez-les après vérification de leurs volumes", + "Stack members are updated together with their stack": "Les membres Stack sont mis à jour avec leur pile", + "Stack name": "Nom de la pile", + "Stack records restored": "Dossiers des piles restaurés", + "Stack records saved": "Enregistrer les enregistrements", + "Stack records saved; no container was reinstalled.": "Enregistrements de paquets enregistrés; aucun conteneur n'a été réinstallé.", + "Stack recovery completed; every member is back to its previous installation.": "Récupération de la pile terminée; chaque membre est de retour à son installation précédente.", + "Stack startup hook installed": "Crochet de démarrage Stack installé", + "Stack stopped": "Stack arrêté", + "Stack update completed. Data kept.": "Mise à jour de la pile terminée. Données conservées.", + "Stack:": "Pioche :", "Staging directory:": "Répertoire intermédiaire :", "Staging ready.": "Mise en scène prête.", "Staging source:": "Source intermédiaire :", @@ -4183,11 +5459,13 @@ "Stale VFIO Config Detected": "configuration VFIO obsolète détectée", "Stale VFIO entries removed and initramfs rebuilt.": "entrées VFIO obsolètes supprimées et initramfs reconstruits.", "Standard NAS (backup, iso, vztmpl)": "NAS standard (sauvegarde, iso, vztmpl)", + "Start": "Démarrer", "Start VM": "Démarrer la machine virtuelle", "Start VM after creation": "Démarrer la VM après la création", "Start VM after creation?": "Démarrer la VM après la création ?", "Start a container. Use the correct ": "Démarrez un conteneur. Utilisez le bon ", "Start a virtual machine. Use the correct ": "Démarrez une machine virtuelle. Utilisez le bon ", + "Start each LXC with Proxmox (no coordinated startup)": "Démarrer chaque LXC avec Proxmox (pas de démarrage coordonné)", "Start long self-test (hours)": "Démarrer un autotest long (heures)", "Start long test now?": "Commencer un long test maintenant ?", "Start on boot already disabled for VM": "Démarrer au démarrage déjà désactivé pour la VM", @@ -4199,11 +5477,16 @@ "Start scrub for a ZFS pool": "Démarrer le nettoyage pour un pool ZFS", "Start short self-test (~2 min)": "Démarrer un court autotest (~ 2 min)", "Start terminal multiplexer (recommended):": "Démarrez le multiplexeur de terminal (recommandé) :", + "Start the LXC when finished to apply the selected configuration?": "Démarrer le LXC une fois terminé pour appliquer la configuration sélectionnée?", "Start the VM": "Démarrer la VM", "Start the VM to begin Windows installation from the mounted ISO.": "Démarrez la VM pour commencer l'installation de Windows à partir de l'ISO montée.", "Start the converted container:": "Démarrez le conteneur converti :", "Start the main system upgrade:": "Démarrez la mise à niveau principale du système :", + "Start the stack with Proxmox": "Démarrer la pile avec Proxmox", "Start uploading to PBS — sets a recovery passphrase": "Commencer le téléchargement sur PBS – définit une phrase secrète de récupération", + "Start when finished": "Commencer à la fin", + "Start with Proxmox": "Commencez par Proxmox", + "Starting": "Début", "Starting Borg backup...": "Démarrage de la sauvegarde Borg...", "Starting CT": "Démarrage du CT", "Starting LXC Privileged to Unprivileged conversion process...": "Démarrage du processus de conversion LXC privilégié en non privilégié...", @@ -4214,6 +5497,7 @@ "Starting ProxMenux update...": "Démarrage de la mise à jour de ProxMenux...", "Starting Proxmox storage integration...": "Démarrage de l'intégration du stockage Proxmox...", "Starting Proxmox system repair...": "Démarrage de la réparation du système Proxmox...", + "Starting Rclone and waiting for the FUSE mount...": "Démarrer Rclone et attendre le montage FUSE...", "Starting SMART long self-test...": "Démarrage de l'autotest long SMART...", "Starting SMART short self-test...": "Démarrage du court autotest SMART...", "Starting container": "Conteneur de démarrage", @@ -4224,9 +5508,20 @@ "Starting installer...": "Démarrage du programme d'installation...", "Starting privileged container...": "Démarrage du conteneur privilégié...", "Starting rpcbind service...": "Démarrage du service rpcbind...", + "Starting the container...": "Démarrage du conteneur...", + "Starting the main container and its dependencies...": "Commencer le conteneur principal et ses dépendances...", + "Starting the service:": "Début du service:", "Starting unprivileged container...": "Démarrage du conteneur sans privilèges...", + "Startup: coordinated by the stack startup hook": "Démarrage : coordonné par le crochet de démarrage de la pile", + "Startup: independent, without hookscript": "Démarrage : indépendant, sans hookscript", + "Static IP": "IP statique", + "Static IPv4 address": "Adresse IPv4 statique", + "Static IPv4 address for": "Adresse IPv4 statique pour", "Status": "Statut", "Status:": "Statut:", + "Steam is the ultimate destination for playing, discussing, and creating games.": "Steam est la destination ultime pour jouer, discuter et créer des jeux.", + "SteamGridDB": "SteamGridDB", + "SteamGridDB API key": "SteamGridDB API clé", "Step": "Étape", "Step 2: Testing actual share access with guest...": "Étape 2 : Test de l'accès réel au partage avec l'invité...", "Steps that will run:": "Étapes qui s'exécuteront :", @@ -4234,12 +5529,14 @@ "Stop it first and run this option again.": "Arrêtez-le d'abord et réexécutez cette option.", "Stop the CT, unmount the disk on the HOST, and remount with:": "Arrêtez le CT, démontez le disque sur le HOST et remontez avec :", "Stop the VM/CT before formatting this disk.": "Arrêtez la VM/CT avant de formater ce disque.", + "Stop the container before the NVIDIA refresh": "Arrêter le récipient avant le rafraîchissement NVIDIA", "Stop the container if it's running:": "Arrêtez le conteneur s'il est en cours d'exécution :", "Stop them first and run this script again.": "Arrêtez-les d'abord et exécutez à nouveau ce script.", "Stop uploading to PBS": "Arrêter de télécharger sur PBS", "Stop uploading?": "Arrêter le téléchargement ?", "Stopped": "Arrêté", "Stopped and disabled": "Arrêté et désactivé", + "Stopped at:": "Arrêt à:", "Stopping Coral kernel modules...": "Arrêt des modules du noyau Coral...", "Stopping LXC": "Arrêter LXC", "Stopping NFS services...": "Arrêt des services NFS...", @@ -4251,6 +5548,8 @@ "Stopping gateway...": "Arrêt de la passerelle...", "Stopping the container before applying configuration...": "Arrêt du conteneur avant d'appliquer la configuration...", "Stopping the container before conversion...": "Arrêt du conteneur avant la conversion...", + "Stopping the container...": "Arrêter le conteneur...", + "Stopping the stack...": "Arrêter la pile...", "Storage": "Stockage", "Storage & Share Manager": "Gestionnaire de stockage et de partage", "Storage Added:": "Stockage ajouté :", @@ -4263,21 +5562,41 @@ "Storage and Disks Commands": "Commandes de stockage et de disques", "Storage controller: VirtIO SCSI": "Contrôleur de stockage : VirtIO SCSI", "Storage disk identifier:": "Identifiant du disque de stockage :", + "Storage for Nextcloud files, configuration and data": "Stockage des fichiers, configuration et données Nextcloud", + "Storage for Paperless data and documents": "Stockage des données et documents sans papier", + "Storage for Tandoor files": "Stockage pour les fichiers Tandoor", + "Storage for persistent data": "Stockage pour données persistantes", + "Storage for recipe images and files": "Stockage d'images et de fichiers de recettes", + "Storage for rootfs": "Stockage pour roofs", + "Storage for rootfs and private configuration": "Stockage pour roofs et configuration privée", + "Storage for the Immich library": "Stockage pour la bibliothèque Immich", + "Storage for the Nextcloud data": "Stockage pour les données Nextcloud", + "Storage for the OCI image cache": "Stockage pour le cache d'image de l'OCI", + "Storage for the consume and export folders": "Stockage des dossiers de consommation et d'exportation", + "Storage for the persistent configuration": "Stockage pour la configuration persistante", "Storage is now available in Proxmox web interface under Datacenter > Storage": "Le stockage est désormais disponible dans l'interface Web Proxmox sous Datacenter > Stockage", "Storage plan selection cancelled.": "Sélection du plan de stockage annulée.", "Storage plan selection failed or cancelled": "La sélection du plan de stockage a échoué ou a été annulée", + "Storage selection cancelled": "Sélection de stockage annulée", "Storage:": "Stockage:", "Stored Credentials:": "Identifiants stockés :", "Stored credentials:": "Identifiants stockés :", + "Stremio is a modern media center that gives you the freedom to watch everything you want.": "Stremio est un centre de médias moderne qui vous donne la liberté de regarder tout ce que vous voulez.", + "Subdomains for the certificate, comma separated (wildcard for *.domain)": "Sous-domaines pour le certificat, virgule séparée (carte d'identification pour *.domaine)", "Subnet": "Sous-réseau", "Subscription banner removal failed": "Échec de la suppression de la bannière d'abonnement", "Subscription banner removed successfully": "La bannière d'abonnement a été supprimée avec succès", "Subscription banner restored successfully (desktop and mobile)": "Bannière d'abonnement restaurée avec succès (ordinateur et mobile)", "Success": "Succès", "Successful": "Réussi", + "Supervisor does not confirm healthy and supported yet": "Le superviseur ne confirme pas encore la santé et le soutien", + "Supervisor reports no connectivity; retrying to get versions and install components": "Superviseur ne signale aucune connectivité; réessayer pour obtenir des versions et installer des composants", "Supported formats: .img, .qcow2, .vmdk, .raw": "Formats pris en charge : .img, .qcow2, .vmdk, .raw", + "Swap": "Échange", + "Swap in MB": "Échange en MB", "Swap partition detected": "Partition swap détectée", "Swappiness configuration created successfully": "Configuration de swappiness créée avec succès", + "Swing Music is a beautifully designed, self-hosted music streaming server. Like a cooler Spotify ... but bring your own music.": "Swing Music est un serveur de streaming de musique parfaitement conçu et auto-organisé. Comme un Spotify plus cool... mais apportez votre propre musique.", "Switch GPU Mode (VM <-> LXC)": "Changer de mode GPU (VM <-> LXC)", "Switch Mode": "Changer de mode", "Switch Script Not Found": "Script de commutation introuvable", @@ -4287,13 +5606,21 @@ "Switching to": "Passer à", "Switching to GPU -> LXC mode removes VFIO exclusivity.": "Le passage au mode GPU -> LXC supprime l'exclusivité VFIO.", "Switching to GPU -> VM mode requires exclusive VFIO binding.": "Le passage au mode GPU -> VM nécessite une liaison VFIO exclusive.", + "Symbolic link in a restored volume path": "Lien symbolique dans un chemin de volume restauré", + "Symbolic link in the path of an adaptation": "Lien symbolique dans le chemin d'une adaptation", + "Symbolic link loop in the new image": "Boucle de lien symbolique dans la nouvelle image", + "Symbolic link outside the rootfs of the new image": "Lien symbolique en dehors des roofs de la nouvelle image", "Synchronize time automatically": "Synchroniser l'heure automatiquement", + "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are.": "Synclounge est un outil tiers qui vous permet de regarder Plex en synchronisation avec vos amis/familles, où que vous soyez.", + "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet.": "Syncthing remplace les services propriétaires de synchronisation et de cloud par quelque chose d'ouvert, fiable et décentralisé. Vos données sont vos seules données et vous méritez de choisir où elles sont stockées, si elles sont partagées avec un tiers et comment elles sont transmises sur Internet.", + "Sysctl not namespaced or not valid:": "Sysctl n'est pas espace ou n'est pas valide:", "System": "Système", "System CLI Tools": "Outils CLI système", "System Disk Size (GB)": "Taille du disque système (Go)", "System Update Information": "Informations sur la mise à jour du système", "System Utilities Installer": "Installateur des utilitaires système", "System disk is SSD or M.2. Proceeding with Log2RAM setup.": "Le disque système est SSD ou M.2. Poursuite de la configuration de Log2RAM.", + "System error:": "Erreur système & #160;:", "System errors and logs": "Erreurs système et journaux", "System group apex already exists.": "Le sommet du groupe système existe déjà.", "System group apex created.": "Sommet du groupe système créé.", @@ -4304,6 +5631,7 @@ "System limits increase completed.": "Augmentation des limites du système terminée.", "System limits optimizations removed": "Optimisations des limites du système supprimées", "System must be updated to latest PVE 8.4+ before starting": "Le système doit être mis à jour avec la dernière version PVE 8.4+ avant de démarrer", + "System path mounts are not yet supported": "Les montages du chemin système ne sont pas encore pris en charge", "System reboot required": "Redémarrage du système requis", "System upgrade completed": "Mise à niveau du système terminée", "System uptime": "Disponibilité du système", @@ -4318,6 +5646,11 @@ "TROUBLESHOOTING:": "DÉPANNAGE :", "TUI mode": "Mode TUI", "TUI mode (requires root)": "Mode TUI (nécessite root)", + "Take control of your Minecraft servers.": "Prenez le contrôle de vos serveurs Minecraft.", + "Tandoor WebUI": "Tandoor WebUI", + "Tandoor configuration cancelled": "Configuration Tandoor annulée", + "Tandoor needs at least 1 GB for staticfiles and 4 GB for PostgreSQL": "Tandoor a besoin d'au moins 1 Go pour les fichiers statiques et 4 Go pour PostgreSQL", + "Tandoor needs to complete its first start to create the initial administrator": "Tandoor doit terminer son premier démarrage pour créer l'administrateur initial", "Target IQN:": "IQN cible :", "Target VM": "VM cible", "Target VM validated": "VM cible validée", @@ -4327,6 +5660,12 @@ "Target mode": "Mode cible", "Target server:": "Serveur cible :", "Target:": "Cible:", + "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server.": "Tautulli est une application web basée sur le python pour la surveillance, l'analyse et les notifications pour Plex Media Server.", + "Teable adopts a concise spreadsheet interface, yet creates powerful database applications": "Teable adopte une interface de tableur concise, mais crée des applications de base de données puissantes", + "Telegram is a cloud-based mobile and desktop messaging app.": "Telegram est une application de messagerie mobile et de bureau basée sur le cloud.", + "Temporary data container:": "Conteneur de données temporaire:", + "Temporary login": "Connexion temporaire", + "Temporary password retrieved": "Mot de passe temporaire récupéré", "Temporary working directory (if present):": "Répertoire de travail temporaire (si présent) :", "Terminal Multiplexers": "Multiplexeurs de terminaux", "Terminal multiplexer (Ctrl+b then d to detach, or type exit)": "Multiplexeur de terminal (Ctrl+b puis d pour détacher, ou taper exit)", @@ -4343,40 +5682,197 @@ "Testing comprehensive guest access to server": "Test de l'accès invité complet au serveur", "Testing connectivity to portal...": "Test de la connectivité au portail...", "Testing network connectivity...": "Test de la connectivité réseau...", + "Text that new pads start with (empty = the text of the image)": "Texte qui commence par les nouveaux tampons (vide = le texte de l'image)", "Thank you for using ProxMenux. Goodbye!": "Merci d'utiliser ProxMenux. Au revoir!", "That VM is currently stopped, so the GPU can be reassigned now.": "Cette VM est actuellement arrêtée, le GPU peut donc être réaffecté maintenant.", "That doesn't look like an SSH private key. Pick the private key file (no .pub extension, parseable by ssh-keygen).": "Cela ne ressemble pas à une clé privée SSH.Choisissez le fichier de clé privée (pas d'extension .pub, analysable par ssh-keygen).", + "The .conf files under /config/fail2ban are rewritten on every start. Keep customizations in the matching .local file, for example jail.local for jail.conf.": "Les fichiers .conf sous /config/fail2ban sont réécrits à chaque démarrage. Gardez les personnalisations dans le fichier .local correspondant, par exemple prison.local pour prison.conf.", + "The AppArmor/seccomp relaxation does not include the required consent": "L'AppArmor/seccomp relaxation ne comprend pas le consentement required", + "The Bookmark Everything App": "L'application Tout Signet", + "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile.": "Le navigateur Brave est un navigateur Web rapide, privé et sécurisé pour PC, Mac et mobile.", + "The CT already exists:": "Le CT existe déjà:", + "The Compose file declares no service": "Le fichier Compose déclare aucun service", + "The Compose file describes several images:": "Le fichier Compose décrit plusieurs images :", + "The Compose file does not contain a Compose document": "Le fichier Compose ne contient pas de document Compose", + "The Compose file is not valid YAML:": "Le fichier Compose n'est pas valide YAML:", + "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "Le Compose offre une relaxation en option AppArmor ou seccomp ; il restera désactivé à moins que l'utilisateur le sélectionne. Continuez seulement si vous faites confiance à l'image et acceptez ce risque.", + "The Compose value must be text or a list:": "La valeur Compose doit être un texte ou une liste :", + "The DRM node is not an Intel or AMD GPU; NVIDIA requires its library profile": "Le noeud DRM n'est pas un GPU Intel ou AMD ; NVIDIA requires son profil de bibliothèque", + "The Entrypoint/Cmd combination is empty": "Le point d'entrée/Cmd combination est vide", + "The FUSE publication helper was not found": "L'aide à la publication FUSE n'a pas été trouvée", + "The GPU evidence does not match the verified devices": "La preuve GPU ne correspond pas aux appareils vérifiés", "The GPU has been moved out of VM": "Le GPU a été déplacé hors de la VM", + "The GPU identity or permissions changed; the container is not modified": "L'identité GPU ou les permissions ont changé; le conteneur n'est pas modifié", "The GPU is being detached from VM": "Le GPU est détaché de la VM", + "The GPU vendor differs from the requested profile": "Le fournisseur GPU diffère du profil demandé", + "The GPU vendor does not match the selected GPU profile:": "Le fournisseur GPU ne correspond pas au profil GPU sélectionné :", + "The Immich CPU quota cannot be reproduced": "Le quota de CPU Immich ne peut pas être reproduit", + "The Immich library needs at least 8 GB": "La bibliothèque Immich a besoin d'au moins 8 Go", + "The Immich startup was modified or cannot be reproduced": "Le démarrage de Immich a été modifié ou ne peut pas être reproduit", + "The LXC has stopped": "Le LXC est arrêté", + "The Lounge starts in public mode: anyone who reaches the address opens the client without logging in, and the IRC networks added are lost when the session ends.": "Le Lounge commence en mode public : quiconque atteint l'adresse ouvre le client sans se connecter, et les réseaux IRC ajoutés sont perdus à la fin de la session.", + "The MAC address of the container cannot be kept": "L'adresse MAC du conteneur ne peut pas être conservée", "The NVIDIA Container Toolkit repository definition was empty.": "La définition du référentiel NVIDIA Container Toolkit était vide.", "The NVIDIA Container Toolkit signing key could not be read.": "La clé de signature NVIDIA Container Toolkit n'a pas pu être lue.", + "The NVIDIA Container Toolkit version cannot be identified": "La version NVIDIA Container Toolkit ne peut pas être identifiée", + "The NVIDIA destination cannot be replaced": "La destination NVIDIA ne peut pas être remplacée", + "The NVIDIA destination escapes the rootfs": "La destination NVIDIA échappe aux roofs", "The NVIDIA driver is installed, but the Container Toolkit phase did not complete. GPU support for OCI containers is unavailable until it does.": "Le pilote NVIDIA est installé, mais la phase Container Toolkit n'est pas terminée. La prise en charge GPU pour les conteneurs OCI n'est pas disponible jusqu'à ce qu'elle le soit.", + "The NVIDIA driver or inventory changed; the operation was stopped": "Le pilote ou l'inventaire NVIDIA a changé; le operation a été arrêté", + "The NVIDIA hook or environment differs from the declared one": "Le crochet ou l'environnement NVIDIA diffère de celui déclaré", + "The NVIDIA hook path does not belong to the installer": "Le chemin de crochet NVIDIA n'appartient pas à l'installateur", "The NVIDIA installer needs at least": "Le programme d'installation de NVIDIA a besoin d'au moins", + "The NVIDIA runtime is up to date; the container is not modified or started": "L'exécution NVIDIA est à jour; le conteneur n'est ni modifié ni démarré.", + "The Nextcloud volume needs at least 8 GB": "Le volume Nextcloud nécessite au moins 8 Go", + "The OCI archive contains no SHA-256 blobs": "L'archive OCI ne contient pas de blobs SHA-256", + "The OCI archive does not contain exactly one manifest": "L'archive OCI ne contient pas exactement un manifeste", + "The OCI archive does not exist or is empty:": "L'archive du BEC n'existe pas ou est vide :", + "The OCI archive verifier was not found": "Le vérificateur des archives du BEC n'a pas été trouvé", + "The OCI catalog is not installed. Update ProxMenux and try again.": "Le catalogue OCI n'est pas installé. Mettre à jour ProxMenux et réessayer.", + "The OCI engine is not installed. Update ProxMenux and try again.": "Le moteur OCI n'est pas installé. Mettre à jour ProxMenux et réessayer.", + "The OCI image storage was not kept": "Le stockage d'images du BEC n'a pas été conservé", + "The OCR language must use Tesseract codes, for example eng or eng+spa": "Le langage OCR doit utiliser des codes Tesseract, par exemple eng ou eng+spa", + "The PATH of the new image is outside the reproducible profile": "Le PATH de la nouvelle image est en dehors du profil reproductible", + "The Paperless persistent volumes need at least 8 GB": "Les volumes persistants sans papier nécessitent au moins 8 Go", + "The PostgreSQL volume needs at least 4 GB": "Le volume PostgreSQL nécessite au moins 4 Go", + "The PostgreSQL volume needs at least 8 GB": "Le volume PostgreSQL nécessite au moins 8 Go", "The Proxmox archive keyring is missing; Ceph installation cannot continue safely": "Le trousseau de clés d'archive Proxmox est manquant ;L'installation de Ceph ne peut pas continuer en toute sécurité", + "The Proxmox inventory and the local configurations differ": "L'inventaire Proxmox et les configurations locales diffèrent", + "The Rclone configuration needs at least 1 GB": "La configuration Rclone nécessite au moins 1 Go", + "The Rclone rootfs needs at least 2 GB": "Les roofs Rclone ont besoin d'au moins 2 Go", + "The Selkies profile requires a verified LinuxServer image": "Le profil Selkies requires une image LinuxServer vérifiée", + "The Tandoor files volume needs at least 2 GB": "Le volume de fichiers Tandoor nécessite au moins 2 Go", "The URL does not contain the required parameters (id, pack, edition).": "L'URL ne contient pas les paramètres requis (id, pack, édition).", + "The USB number can change after reconnecting or rebooting. This profile does not remap it automatically or handle Coral USB re-enumeration. Do not share a dongle already used by another service.": "Le numéro USB peut changer après la reconnexion ou le redémarrage. Ce profil ne le remaprise pas automatiquement ou ne gère pas la réénumération USB Coral. Ne partagez pas un dongle déjà utilisé par un autre service.", + "The Unifi-controller software is a powerful, enterprise wireless software engine ideal for high-density client deployments requiring low latency and high uptime performance.": "Le logiciel Unifi-controller est un puissant moteur de logiciel sans fil d'entreprise idéal pour les déploiements clients haute densité requi avec faible latence et des performances de pointe.", + "The VA-API device does not exist:": "Le dispositif VA-API n'existe pas :", "The VM also has these audio devices assigned via PCI passthrough — typically added together with the GPU. Remove them too?": "La VM dispose également de ces périphériques audio attribués via un relais PCI, généralement ajoutés avec le GPU. Les supprimer aussi ?", "The VM guest will have exclusive access to the GPU.": "L'invité de la VM aura un accès exclusif au GPU.", "The VM is powered on. Turn it off before adding disks.": "La VM est sous tension. Éteignez-le avant d'ajouter des disques.", "The VM/LXC will lose access to this disk after formatting.": "La VM/LXC perdra l'accès à ce disque après le formatage.", + "The VMID belongs to another container now and is not touched:": "Le VMID appartient à un autre conteneur maintenant et n'est pas touché:", + "The VMID or its contract is already in use; it is not adopted": "Le VMID ou son contrat est déjà utilisé; il n'est pas adopté", + "The VMID was reused or its identity is unknown; the operation is blocked": "Le VMID a été réutilisé ou son identité est inconnue; la operation est bloquée", + "The VMID was reused or the container is on another node; it is not overwritten": "Le VMID a été réutilisé ou le conteneur est sur un autre noeud; il n'est pas écrasé", + "The VMID was taken during the installation:": "Le VMID a été pris pendant l'installation:", + "The Valkey volume needs at least 1 GB": "Le volume de Valkey nécessite au moins 1 Go", + "The acceleration evidence differs from the verified inventory": "Les preuves d'accélération diffèrent de l'inventaire vérifié", + "The acceleration profile does not support this architecture:": "Le profil d'accélération ne supporte pas cette architecture:", "The active kernel driver is not vfio-pci, but the entry in": "Le pilote du noyau actif n'est pas vfio-pci, mais l'entrée dans", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot, breaking the LXC passthrough about to be configured.": "Le pilote actif du noyau n'est pas vfio-pci, mais l'entrée reliera le GPU à vfio-pci au prochain redémarrage, interrompant ainsi le relais LXC sur le point d'être configuré.", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot.": "Le pilote du noyau actif n'est pas vfio-pci, mais l'entrée reliera le GPU à vfio-pci au prochain redémarrage.", + "The adaptation content was modified": "Le contenu de l'adaptation a été modifié", + "The additional path hides a system directory": "Le chemin supplémentaire masque un répertoire système", + "The address is already assigned on this host or cluster:": "L'adresse est déjà attribuée sur cet hôte ou ce cluster :", + "The address must start with http:// or https://": "L'adresse doit commencer par http:// ou https://", + "The administrator account, the public address and the UDP port are created on the first start, so the web interface opens directly on its login page.": "Le compte administrateur, l'adresse publique et le port UDP sont créés au premier démarrage, de sorte que l'interface web s'ouvre directement sur sa page de connexion.", + "The administrator email is not valid": "Le courriel de l'administrateur n'est pas valide", + "The administrator user contains characters that are not allowed": "L'utilisateur administrateur contient des caractères qui ne sont pas autorisés", + "The all-in-one AI application.": "L'application d'IA tout-en-un.", + "The application configuration needs a first start to complete.": "La configuration de l'application nécessite un premier démarrage à compléter.", + "The application did not complete its initial setup:": "L'application n'a pas terminé sa configuration initiale :", + "The application did not get an address on the access network:": "La demande n'a pas obtenu d'adresse sur le réseau d'accès :", + "The application did not pass its HTTP check:": "L'application n'a pas réussi sa vérification HTTP :", + "The application did not respond in time:": "La demande n'a pas répondu à temps :", + "The application stopped during its first start:": "L'application s'est arrêtée lors de son premier démarrage :", + "The application was removed": "La demande a été retirée", "The archive could not be extracted.": "L'archive n'a pas pu être extraite.", "The archive destination directory is INSIDE one of the paths you are about to back up. Writing the archive there would copy the backup into itself — producing a corrupted archive, or growing without limit until the disk fills up.": "Le répertoire de destination de l'archive se trouve À L'INTÉRIEUR de l'un des chemins que vous êtes sur le point de sauvegarder. Écrire l'archive là-bas copierait la sauvegarde sur elle-même, produisant une archive corrompue ou s'agrandissant sans limite jusqu'à ce que le disque se remplisse.", + "The backup could not be identified; the image is not replaced": "La sauvegarde n'a pas pu être identifiée; l'image n'est pas remplacée", "The backup metadata was compared against this host. The following items will be SKIPPED to keep the boot safe:": "les métadonnées de sauvegarde ont été comparées à cet hôte. Les éléments suivants seront SAUTÉS pour assurer la sécurité du démarrage :", + "The backup of a member could not be identified": "Le soutien d'un membre n'a pas pu être identifié", + "The backup was altered; recovery blocked": "La sauvegarde a été modifiée; récupération bloquée", "The backup was taken on a different PVE or kernel major.minor. These paths will be SKIPPED to keep the boot safe:": "La sauvegarde a été effectuée sur un autre PVE ou noyau major.minor. Ces chemins seront SAUTÉS pour assurer la sécurité du démarrage :", + "The bind mount target escapes the rootfs:": "La cible de montage de liaison échappe aux roofs:", + "The block device does not exist:": "Le dispositif de blocage n'existe pas :", "The build could not be checked beforehand; continuing without that check.": "La build n'a pas pu être vérifiée au préalable ;continuer sans cette vérification.", + "The cached image does not match the current digest": "L'image mise en cache ne correspond pas au digest actuel", + "The cached image is damaged; it will be downloaded again.": "L'image mise en cache est endommagée ; elle sera à nouveau téléchargée.", + "The character device does not exist:": "Le dispositif de caractère n'existe pas :", + "The command asks for a password that is not echoed. After creating the users, the web interface asks for a user name and a password.": "La commande demande un mot de passe qui n'est pas repris. Après la création des utilisateurs, l'interface web demande un nom d'utilisateur et un mot de passe.", + "The command does not name an image": "La commande ne nomme pas une image", + "The command reads its variables from a file; write them in the command or use a Compose file": "La commande lit ses variables à partir d'un fichier ; écrivez-les dans la commande ou utilisez un fichier Compose", + "The command runs the container as the user of the host; the container uses the user of its image instead.": "La commande lance le conteneur en tant qu'utilisateur de l'hôte; le conteneur utilise plutôt l'utilisateur de son image.", + "The command uses options that cannot be translated:": "La commande utilise des options qui ne peuvent pas être traduites :", + "The command works out a value by running another command:": "La commande fonctionne une valeur en exécutant une autre commande :", "The compatibility check raised failures that may break the system after restore.": "La vérification de compatibilité a généré des échecs susceptibles de casser le système après la restauration.", + "The configuration changed after the backup was restored; the recovery is not confirmed": "La configuration a changé après la restauration de la sauvegarde; la récupération n'est pas confirmée", + "The configuration changed after the new container was validated": "La configuration a changé après la validation du nouveau conteneur", + "The configuration changed during the NVIDIA refresh": "La configuration a changé lors du rafraîchissement NVIDIA", + "The configuration evidence does not match": "La preuve de configuration ne correspond pas", + "The configuration must run as root on Proxmox VE": "La configuration doit fonctionner comme racine sur Proxmox VE", + "The configuration of a new member changed after it was created": "La configuration d'un nouveau membre a changé après sa création", + "The configuration stopped because of an unexpected error": "La configuration s'est arrêtée en raison d'une erreur inattendue", + "The consume/export volumes need at least 1 GB": "Les volumes de consommation/exportation nécessitent au moins 1 Go", + "The container could not be removed automatically:": "Le conteneur n'a pas pu être enlevé automatiquement:", + "The container could not be started:": "Le conteneur n'a pas pu être démarré:", + "The container creation does not match the prepared instance": "La création du conteneur ne correspond pas à l'instance préparée", + "The container devices do not match the saved record": "Les périphériques de conteneur ne correspondent pas à l'enregistrement enregistré", + "The container did not stop to update its persistent configuration:": "Le conteneur ne s'est pas arrêté pour mettre à jour sa configuration persistante:", + "The container did not stop; its disks are not touched": "Le conteneur ne s'est pas arrêté; ses disques ne sont pas touchés", + "The container disks do not match the saved record": "Les disques de conteneur ne correspondent pas à l'enregistrement enregistré", + "The container does not exist:": "Le conteneur n'existe pas:", + "The container does not have the fuse=1 feature enabled": "Le conteneur n'a pas la fonction fusible=1 activée", + "The container does not need it any more; an update downloads the new version when there is one.": "Le conteneur n'en a plus besoin ; une mise à jour télécharge la nouvelle version quand il y en a une.", + "The container gets its own address and its own volumes, so the networks and volumes declared in the file are not used.": "Le conteneur obtient sa propre adresse et ses propres volumes, de sorte que les réseaux et les volumes déclarés dans le fichier ne sont pas utilisés.", + "The container has advanced Proxmox settings outside the supported profile": "Le conteneur a avancé les paramètres Proxmox en dehors du profil pris en charge", + "The container identity changed; the container is not replaced": "L'identité du conteneur a changé; le conteneur n'est pas remplacé", + "The container identity does not match": "L'identité du conteneur ne correspond pas", + "The container identity or configuration changed": "L'identité ou la configuration du conteneur a changé", "The container is currently stopped. Do you want to start it now to install the package?": "Le conteneur est actuellement arrêté. Voulez-vous le démarrer maintenant pour installer le package ?", + "The container is not modified because a host directory is not available:": "Le conteneur n'est pas modifié car un répertoire hôte n'est pas disponible :", + "The container no longer exists:": "Le conteneur n'existe plus:", + "The container of a member was replaced; the assembly is not resumed": "Le conteneur d'un membre a été remplacé; l'assemblée n'est pas reprise", "The container should now start as privileged": "Le conteneur devrait maintenant démarrer en tant que privilégié", "The container should now start as unprivileged": "Le conteneur devrait maintenant démarrer sans privilèges", + "The container stopped after starting:": "Le conteneur s'est arrêté après le début:", + "The container stopped before publishing the mount": "Le conteneur s'est arrêté avant la publication du montage", + "The container stopped before the GPU permissions were verified:": "Le conteneur s'est arrêté avant que les autorisations du GPU ne soient vérifiées :", + "The container stopped before the application responded:": "Le contenant s'est arrêté avant que la demande ne réponde :", + "The container stopped:": "Le réservoir s'est arrêté:", + "The container takes its time zone from Proxmox, so the time files of the host are not attached to it.": "Le conteneur prend son fuseau horaire de Proxmox, de sorte que les fichiers de temps de l'hôte ne lui sont pas attachés.", + "The container was changed outside ProxMenux and an update would discard those changes:": "Le contenant a été modifié à l'extérieur du ProxMenux et une mise à jour permettrait de rejeter ces changements :", + "The container was created from a downloaded OCI image": "Le conteneur a été créé à partir d'une image téléchargée du BEC", + "The containers do not need them any more; an update downloads the new versions when there are any.": "Les conteneurs n'en ont plus besoin ; une mise à jour télécharge les nouvelles versions quand il y en a.", + "The containers were created from downloaded OCI images": "Les conteneurs ont été créés à partir d'images téléchargées du BEC", + "The coordinated backup was modified": "La sauvegarde coordonnée a été modifiée", "The current driver will be completely uninstalled before installing the new version. Continue?": "Le pilote actuel sera complètement désinstallé avant d'installer la nouvelle version. Continuer?", + "The current image of the saved channel will be checked and downloaded. Resources, paths and GPU are kept. The CT is stopped during the replacement and a native backup is created first.": "L'image actuelle du canal sauvegardé sera vérifiée et téléchargée. Les ressources, les chemins et le GPU sont conservés. Le CT est arrêté pendant le remplacement et une sauvegarde native est créée en premier.", + "The current record is missing for": "L'enregistrement actuel manque pour", + "The current template changes the image or identity; an explicit migration is required": "Le modèle actuel modifie l'image ou l'identité; une migration explicite est required", + "The current template requires a new persistent path:": "Le modèle actuel requires un nouveau chemin persistant:", + "The custom path cannot hide system directories": "Le chemin personnalisé ne peut pas masquer les répertoires système", + "The custom path overlaps another mount": "Le chemin personnalisé chevauche un autre montage", + "The data and document volumes need at least 8 GB": "Les volumes de données et de documents nécessitent au moins 8 Go", + "The database server must accept connections from the IP address of this container, with a user that is not limited to localhost.": "Le serveur de base de données doit accepter les connexions à partir de l'adresse IP de ce conteneur, avec un utilisateur qui ne se limite pas à localhost.", + "The dedicated adapter still requires replaying its rootfs changes": "L'adaptateur dédié requires rejoue ses changements roofs", + "The dependency hook and the stack recipe differ": "Le crochet de dépendance et la recette de pile diffèrent", + "The dependency hook was modified; review it before updating": "Le crochet de dépendance a été modifié; l'examiner avant de mettre à jour", + "The developer-friendly cloud platform for building and running LLM agents for AI-native applications.": "La plate-forme cloud conviviale pour la construction et l'exploitation d'agents LLM pour les applications AI-native.", + "The device directory does not exist:": "Le répertoire des périphériques n'existe pas :", + "The device must keep its /dev path inside the LXC:": "L'appareil doit garder son chemin /dev à l'intérieur du LXC:", + "The device must keep its native path without duplicates": "L'appareil doit garder son chemin natif sans duplicata", + "The directory contains no character devices:": "Le répertoire ne contient aucun périphérique de caractère:", "The directory does not exist in the CT.": "Le répertoire n'existe pas dans le CT.", "The disk": "Le disque", + "The disk size cannot be reproduced": "La taille du disque ne peut pas être reproduite", + "The disk usage of the container could not be read": "L'utilisation du disque du conteneur n'a pas pu être lue", + "The domain must resolve to the public address of this network before the certificate can be issued.": "Le domaine doit se résoudre à l'adresse publique de ce réseau avant la délivrance du certificat.", + "The download client still needs to be configured.": "Le client de téléchargement doit encore être configuré.", + "The download stopped progressing; cancelling this attempt.": "Le téléchargement a cessé de progresser; annuler cette tentative.", + "The downloaded image does not match its manifest": "L'image téléchargée ne correspond pas à son manifeste", + "The downloaded image is corrupt:": "L'image téléchargée est corrompue :", "The dpkg package database is clean.": "La base de données du package dpkg est propre.", "The driver installed but does not drive this GPU.": "Le pilote est installé mais ne pilote pas ce GPU.", + "The dynamic NVIDIA hook is missing": "Le crochet dynamique NVIDIA manque", + "The dynamic NVIDIA hook is missing or duplicated": "Le crochet dynamique NVIDIA est manquant ou dupliqué", + "The dynamic NVIDIA profile requires an unprivileged LXC": "Le profil dynamique NVIDIA requires un LXC non privilégié", + "The dynamic profile does not support static driver mounts": "Le profil dynamique ne supporte pas les supports statiques du pilote", "The file does not exist, is empty or is not readable.": "Le fichier n'existe pas, est vide ou n'est pas lisible.", + "The file does not exist:": "Le fichier n'existe pas :", + "The file is too large to be a Compose file": "Le fichier est trop grand pour être un fichier Compose", "The filesystem": "Le système de fichiers", + "The final cleanup did not complete:": "Le nettoyage final n'a pas été terminé :", "The following DKMS-managed drivers will now be rebuilt against it so they keep working after reboot:": "Les pilotes gérés par DKMS suivants seront désormais reconstruits afin qu'ils continuent de fonctionner après le redémarrage :", "The following LXC containers have NVIDIA passthrough configured:": "Les conteneurs LXC suivants ont configuré le relais NVIDIA :", "The following backup paths are kernel-tied and are excluded from the picker to keep the target's boot safe. The operator's own tuning inside these paths (IOMMU cmdline, VFIO IDs, custom quirks) is merged back automatically via kernel-agnostic merge:": "Les chemins de sauvegarde suivants sont liés au noyau et sont exclus du sélecteur pour assurer la sécurité du démarrage de la cible. Les propres réglages de l'opérateur à l'intérieur de ces chemins (ligne de commande IOMMU, ID VFIO, bizarreries personnalisées) sont automatiquement fusionnés via une fusion indépendante du noyau :", @@ -4390,17 +5886,99 @@ "The following selected device(s) are Physical Functions with active Virtual Functions:": "Les appareils sélectionnés suivants sont des fonctions physiques avec des fonctions virtuelles actives :", "The following selected device(s) are SR-IOV Virtual Functions (VFs):": "Les périphériques sélectionnés suivants sont des fonctions virtuelles (VF) SR-IOV :", "The fstab entry will still be removed; reboot or manual umount needed.": "L'entrée fstab sera toujours supprimée ; redémarrage ou démontage manuel nécessaire.", + "The gateway must be another usable address in the same subnet.": "La passerelle doit être une autre adresse utilisable dans le même sous-net.", "The gateway should appear in your Tailscale admin console shortly.": "La passerelle devrait bientôt apparaître dans votre console d'administration Tailscale.", + "The healthcheck cannot run without an IP address": "Le contrôle de santé ne peut pas fonctionner sans adresse IP", + "The host NVIDIA driver is not responding correctly": "Le pilote NVIDIA hôte ne répond pas correctement", + "The host bind source does not exist:": "La source de liaison hôte n'existe pas:", + "The host bind source is not a regular file or directory:": "La source de liaison hôte n'est pas un fichier ou un répertoire régulier :", + "The host directory changed before it was mounted": "Le répertoire hôte a changé avant son montage", "The host directory may not be accessible from an unprivileged container.": "Le répertoire hôte peut ne pas être accessible à partir d'un conteneur non privilégié.", + "The host has no IPv4 address on the selected bridge": "L'hôte n'a pas d'adresse IPv4 sur le pont sélectionné", + "The host monitor does not see the real host memory": "Le moniteur hôte ne voit pas la mémoire de l'hôte réel", + "The host monitor does not share this host namespace:": "L'écran hôte ne partage pas cet espace de noms d'hôte :", + "The host monitor needs consent for privileged access to the host": "Le moniteur hôte a besoin d'un consentement pour un accès privilégié à l'hôte", + "The host monitor profile does not support another sysctl include": "Le profil du moniteur hôte ne prend pas en charge un autre système comprenant", + "The host monitor uses the host network, without DHCP or its own gateway": "Le moniteur hôte utilise le réseau hôte, sans DHCP ou sa propre passerelle", + "The host port is already in use:": "Le port hôte est déjà utilisé:", + "The identity of a member was replaced": "L'identité d'un membre a été remplacée", + "The image changes the user expected by the adapter": "L'image change l'utilisateur attendu par l'adaptateur", + "The image could not be read from its registry:": "L'image n'a pas pu être lue depuis son registre :", + "The image declares data paths that are still stored in the rootfs": "L'image déclare les chemins de données qui sont encore stockés dans les rootfs", + "The image did not grant the application user access to the devices; check its native init. Host permissions were not relaxed.": "L'image n'a pas permis à l'utilisateur de l'application d'accéder aux appareils; vérifiez son init natif. Les permissions de l'hôte n'étaient pas détendues.", + "The image did not pass the integrity check": "L'image n'a pas réussi la vérification d'intégrité", + "The image does not declare support for this architecture:": "L'image ne déclare pas le support de cette architecture :", + "The image download did not complete correctly; downloading it again...": "Le téléchargement de l'image ne s'est pas terminé correctement ; le téléchargement à nouveau...", + "The image expects files that are given to it one by one:": "L'image s'attend à ce que les fichiers qui lui sont donnés un par un:", + "The image is already up to date; nothing was changed.": "L'image est déjà à jour ; rien n'a été changé.", + "The image is in its registry, for one architecture.": "L'image est dans son registre, pour une architecture.", + "The image is in its registry.": "L'image est dans son registre.", + "The image is in its registry:": "L'image est dans son registre:", + "The image requests NVIDIA, but the host has no working NVIDIA driver": "L'image demande NVIDIA, mais l'hôte n'a pas de pilote NVIDIA fonctionnant", + "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk.": "L'image demande l'invalidation d'une partie de l'AppArmor ou du confinement de seccomp. Continuez seulement si vous faites confiance à l'image et acceptez ce risque.", + "The image requests disabling part of the AppArmor or seccomp confinement. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "L'image demande l'invalidation d'une partie de l'AppArmor ou du confinement de seccomp. Le Compose offre une relaxation en option AppArmor ou seccomp ; il restera désactivé à moins que l'utilisateur le sélectionne. Continuez seulement si vous faites confiance à l'image et acceptez ce risque.", + "The image was not found in its registry, or it is private:": "L'image n'a pas été trouvée dans son registre, ou elle est privée:", + "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged.": "Le Compose importé demande privilégié, mais la documentation officielle de jlesage/handbrake ne require; ProxMenux maintient le LXC non privilégié.", + "The imported OCI groups are not numeric": "Les groupes importés du BEC ne sont pas numériques", + "The imported OCI user or group is not numeric": "L'utilisateur ou le groupe importé du BEC n'est pas numérique", + "The initial user name and password stay written in /etc/pve/lxc/.conf as INIT_USERNAME and INIT_PASSWORD. They can be removed after the first login, with the container stopped.": "Le nom d'utilisateur initial et le mot de passe restent écrits dans /etc/pve/lxc/.conf comme INIT USERNAME et INIT PASSWORD. Ils peuvent être enlevés après la première connexion, le conteneur étant arrêté.", + "The installation asks which one to use for these paths.": "L'installation demande lequel utiliser pour ces chemins.", + "The installation ended with exit code": "L'installation s'est terminée avec le code de sortie", "The installation requires a server restart to apply changes. Do you want to restart now?": "L'installation nécessite un redémarrage du serveur pour appliquer les modifications. Voulez-vous redémarrer maintenant ?", + "The installation runs on the Proxmox node itself, as root": "L'installation fonctionne sur le nœud Proxmox lui-même, comme root", + "The installation stopped because of an unexpected error": "L'installation s'est arrêtée par une erreur inattendue", "The installation/changes require a server restart to apply correctly. Do you want to reboot now?": "L'installation/les modifications nécessitent un redémarrage du serveur pour s'appliquer correctement. Voulez-vous redémarrer maintenant ?", + "The installer must run as root on Proxmox VE": "L'installateur doit fonctionner comme root sur Proxmox VE", + "The instance changed while it was being edited; configure Recreate again": "L'instance a changé pendant qu'elle était en cours d'édition; configurer Recreate à nouveau", + "The instance does not use NVIDIA": "L'instance n'utilise pas NVIDIA", + "The instance has a pending operation": "L'instance a une operation en attente", + "The instance identity or status must be reviewed before updating.": "L'identité ou le statut de l'instance doit être revu avant la mise à jour.", + "The instance is not ready to be updated": "L'instance n'est pas prête à être mise à jour", + "The instance is not ready; review its pending operation": "L'instance n'est pas prête; examiner sa operation en attente", + "The instance record operation did not complete; no container was modified.": "L'enregistrement de l'instance operation n'a pas été terminé; aucun conteneur n'a été modifié.", + "The instance registry is not safe": "Le registre d'instance n'est pas sûr", + "The journal belongs to another VMID": "Le journal appartient à un autre VMID", + "The journal belongs to another stack": "Le journal appartient à une autre pile", + "The journal has an incomplete recovery state": "La revue a un état de récupération incomplet", + "The kernel module is not active:": "Le module noyau n'est pas actif:", "The kernel module of version": "Le module noyau de la version", "The local envelope is dropped and future backups do not upload anything. Uploaded envelopes already on PBS stay intact and remain recoverable with their original passphrase.": "L'enveloppe locale est supprimée et les futures sauvegardes ne téléchargent rien. Les enveloppes téléchargées déjà sur PBS restent intactes et restent récupérables avec leur phrase secrète d'origine.", "The long test runs directly on the disk hardware.": "Le test long s'exécute directement sur le matériel du disque.", + "The main member must stop first and start last": "Le membre principal doit s'arrêter en premier et commencer en dernier", + "The main member of the stack is missing": "Le membre principal de la pile est manquant", + "The manifest does not match its digest": "Le manifeste ne correspond pas à son digest", + "The member journal belongs to another stack operation": "Le journal membre appartient à une autre pile operation", + "The member journal is outside the registry": "Le journal membre est en dehors du registre", + "The mount evidence does not match the verified directories": "La preuve de montage ne correspond pas aux répertoires vérifiés", + "The mount source or options were not kept": "La source de montage ou les options n'ont pas été conservées", + "The mounted source differs from the configured directory": "La source montée diffère du répertoire configuré", + "The mounts of the new container do not match the proposal": "Les montages du nouveau conteneur ne correspondent pas à la proposition", + "The native GPU permissions were not kept": "Les permissions GPU natives n'ont pas été conservées", + "The native unprivileged idmap is required": "L'idmap natif non privilégié est required", "The new SSH key was installed and is now authorized on the server.\nKey file:": "La nouvelle clé SSH a été installée et est désormais autorisée sur le serveur.\nFichier clé :", "The new SSH key was pushed to the LXC via 'pct exec' on": "La nouvelle clé SSH a été transmise au LXC via 'pct exec' sur", + "The new Valkey volume contains unexpected data": "Le nouveau volume Valkey contient des données inattendues", + "The new container did not pass validation": "Le nouveau conteneur n'a pas réussi la validation", + "The new container is not authorized by the operation journal": "Le nouveau conteneur n'est pas autorisé par la revue operation", + "The new image adds a symbolic link in a generated path": "La nouvelle image ajoute un lien symbolique dans un chemin généré", + "The new image changes the PostgreSQL major version; the data must be migrated before updating": "La nouvelle image modifie la version majeure de PostgreSQL; les données doivent être migrées avant la mise à jour", + "The new image could not be installed": "La nouvelle image n'a pas pu être installée", + "The new image could not be installed:": "La nouvelle image n'a pas pu être installée :", + "The new image does not keep a required executable": "La nouvelle image ne conserve pas un exécutable required", + "The new image requires additional persistent paths": "La nouvelle image requires chemins persistants supplémentaires", + "The new image requires additional persistent paths; use Recreate": "La nouvelle image requires chemins persistants supplémentaires; utiliser Recreate", "The new prompt will be used in new terminal sessions.": "La nouvelle invite sera utilisée dans les nouvelles sessions de terminal.", "The next visit to the dashboard will show the initial setup wizard.": "La prochaine visite sur le tableau de bord affichera l'assistant de configuration initiale.", + "The observed inventory differs from the validated runtime": "L'inventaire observé diffère du temps d'exécution validé", + "The official Tandoor startup executable is missing": "La startup officielle Tandoor exécutable est manquante", + "The official inventory contains no NVIDIA devices": "L'inventaire officiel ne contient pas de dispositifs NVIDIA", + "The official inventory contains no NVIDIA driver components": "L'inventaire officiel ne contient pas de composants conducteurs NVIDIA", + "The official startup cannot be reproduced": "Le démarrage officiel ne peut pas être reproduit", + "The official startup of the application is missing": "Le démarrage officiel de l'application est manquant", + "The operation already finished; it is not restored automatically": "Le operation déjà fini; il n'est pas restauré automatiquement", + "The operation could not be completed": "Le operation n'a pas pu être terminé", + "The operation stopped halfway. Choose \"Recover\" for this container in the OCI management menu to restore the previous installation.": "Le operation s'est arrêté à mi-chemin. Choisissez « Recover » pour ce conteneur dans le menu de gestion OCI pour restaurer l'installation précédente.", + "The operation was stopped because a shared directory changed its identity:": "Le operation a été arrêté parce qu'un répertoire partagé a changé son identité:", "The original MOTD backup is unavailable; no changes were made": "La sauvegarde MOTD d'origine n'est pas disponible ;aucun changement n'a été apporté", "The original MOTD configuration has been restored": "La configuration MOTD d'origine a été restaurée", "The original MOTD state is unavailable; no changes were made": "l'état MOTD d'origine n'est pas disponible ;aucun changement n'a été apporté", @@ -4408,18 +5986,76 @@ "The original rpcbind state could not be restored completely": "L'état d'origine de rpcbind n'a pas pu être restauré complètement", "The original rpcbind state is unavailable; no service state was changed": "L'état rpcbind d'origine n'est pas disponible ;aucun état du service n'a été modifié", "The package is currently in a broken state and is blocking apt updates on this system.": "Le package est actuellement dans un état défectueux et bloque les mises à jour apt sur ce système.", + "The parent of an NVIDIA destination is not a directory": "Le parent d'une destination NVIDIA n'est pas un répertoire", + "The parent of the target is not a directory:": "Le parent de la cible n'est pas un répertoire :", + "The password could not be retrieved automatically": "Le mot de passe n'a pas pu être récupéré automatiquement", "The passwords do not match. Please try again.": "Les mots de passe ne correspondent pas. Veuillez réessayer.", + "The path escapes the rootfs:": "Le chemin échappe aux roofs :", + "The path must be absolute and normalized": "Le chemin doit être absolu et normalisé", + "The path overlaps an existing mount": "Le chemin chevauche un montage existant", + "The persistent NVIDIA hook does not match the installer:": "Le crochet NVIDIA persistant ne correspond pas à l'installateur:", + "The persistent WebUI credentials were not found": "Les credentials de WebUI persistants n'ont pas été trouvés", + "The physical NVIDIA selection changed": "La sélection physique NVIDIA a changé", + "The post-start configuration cannot be applied with the LXC stopped": "La configuration post-démarrage ne peut pas être appliquée avec le LXC stoppé", + "The postgres user was not found in the image": "L'utilisateur postgres n'a pas été trouvé dans l'image", + "The prepared directory escapes the rootfs:": "Le répertoire préparé échappe aux rootfs :", "The preselected VMID does not exist on this host:": "Le VMID présélectionné n'existe pas sur cet hôte :", + "The previous native backup will be restored. Shared host directories are not reverted. Displaced disks are kept.": "La sauvegarde native précédente sera restaurée. Les répertoires d'hôtes partagés ne sont pas retournés. Les disques déplacés sont conservés.", + "The previous stack contract is not safe; review it before reusing it": "Le précédent contrat de pile n'est pas sûr; l'examiner avant de le réutiliser", + "The previous stack contract is not valid; it is not archived automatically": "Le contrat précédent n'est pas valide; il n'est pas archivé automatiquement", + "The previous stack contract still has containers or VMs:": "Le contrat de pile précédent comporte toujours des conteneurs ou des VM :", + "The private address is already assigned to another container:": "L'adresse privée est déjà attribuée à un autre conteneur:", + "The private bridge does not have the expected address:": "Le pont privé n'a pas l'adresse prévue :", + "The private journal has an unsafe owner or permissions": "Le journal privé a un propriétaire dangereux ou des permissions", + "The private network allocator was not found": "L'allocateur du réseau privé n'a pas été trouvé", + "The private network is still used by another container and is kept:": "Le réseau privé est toujours utilisé par un autre conteneur et est conservé:", + "The private network must be assigned automatically": "Le réseau privé doit être assigné automatiquement", + "The privileged deployment does not include the required explicit consent": "Le déploiement privilégié n'inclut pas le consentement explicite required", + "The prlimit soft value exceeds the hard value": "La valeur souple prlimit dépasse la valeur dure", + "The proposal changes the identity of the instance": "La proposition modifie l'identité de l'instance", "The proposed ARC maximum is below Proxmox VE's pool-size guideline:": "L'ARC maximum proposé est inférieur à la directive relative à la taille du pool de Proxmox VE :", + "The published views must be inside the common root": "Les vues publiées doivent être à l'intérieur de la racine commune", + "The read-only view does not apply the expected protection": "La vue en lecture seule n'applique pas la protection attendue", + "The read-only view was not published": "La vue en lecture seule n'a pas été publiée", + "The read/write view was not published": "La vue lecture/écriture n'a pas été publiée", + "The recipe requires configuration at startup; its coordinated replay is not available": "La recette requires configuration au démarrage; son replay coordonné n'est pas disponible", + "The record belongs to another container": "L'enregistrement appartient à un autre conteneur", + "The record does not belong to this operation": "Le disque n'appartient pas à cette operation", + "The record no longer belongs to this operation": "Le record n'appartient plus à cette operation", + "The record of a member was replaced; the assembly is not resumed": "Le procès-verbal d'un membre a été remplacé; l'assemblée n'est pas reprise", + "The record or diagnosis could not be completed; no update was run.": "Le dossier ou le diagnostic n'a pu être complété; aucune mise à jour n'a été effectuée.", + "The recovery did not complete. Review the log and choose \"Recover\" again for this container in the OCI management menu.": "La récupération n'est pas terminée. Passez en revue le journal et choisissez « Recover » pour ce conteneur dans le menu de gestion du BEC.", + "The remote does not exist; create and authorize it first in the WebUI:": "La télécommande n'existe pas; créez et autorisez-la d'abord dans le WebUI:", + "The remote installer must run as root on Proxmox VE": "L'installateur distant doit fonctionner comme root sur Proxmox VE", + "The remote must already be created and authorized in the Rclone web UI. This operation restarts the CT and publishes two FUSE views on the host.": "La télécommande doit déjà être créée et autorisée dans l'interface web Rclone. Ce operation redémarre le CT et publie deux vues FUSE sur l'hôte.", + "The remote path must be relative and cannot contain line breaks": "Le chemin distant doit être relatif et ne peut contenir des ruptures de ligne", + "The removal could not be prepared:": "L'enlèvement n'a pas pu être préparé:", + "The repair must preserve the image dependencies:": "La réparation doit préserver les dépendances de l'image:", + "The requested VMID block is already in use": "Le bloc VMID demandé est déjà utilisé", + "The requested machine learning GPU profile is not working; it is not replaced by CPU": "Le profil GPU d'apprentissage automatique demandé ne fonctionne pas; il n'est pas remplacé par CPU", + "The restored service did not pass its health check": "Le service restauré n'a pas réussi son bilan de santé", + "The restored service stopped; the recovery is not confirmed": "Le service restauré s'est arrêté; la récupération n'est pas confirmée", + "The reviewed Tandoor stack does not require a privileged LXC.": "La pile Tandoor revue ne require un LXC privilégié.", + "The rootfs capture only belongs to the running installation": "La capture rootfs appartient uniquement à l'installation en cours d'exécution", + "The rootfs is not managed by Proxmox": "Les roofs ne sont pas gérés par Proxmox", + "The rootfs is not mounted": "Les roofs ne sont pas montés", "The same GPU cannot be used by two VMs at the same time.": "Le même GPU ne peut pas être utilisé par deux VM en même temps.", + "The same connection can be given as container variables instead of the file: UN_SONARR_0_URL and UN_SONARR_0_API_KEY, or the UN_RADARR_0_ equivalents.": "La même connexion peut être donnée comme variable de conteneur au lieu du fichier : UN SONARR 0 URL et UN SONARR 0 API KEY, ou les UN RADARR 0 equivalents.", "The saved MOTD state is invalid; no changes were made": "l'état MOTD enregistré n'est pas valide ;aucun changement n'a été apporté", + "The saved OCI record is incomplete or has an unexpected format.": "L'enregistrement enregistré du BEC est incomplet ou a un format inattendu.", + "The saved projection does not match the native evidence": "La projection enregistrée ne correspond pas à la preuve native", + "The saved record was replaced for": "L'enregistrement sauvegardé a été remplacé pour", "The saved utility package list is invalid; no packages were removed": "La liste des packages utilitaires enregistrés n'est pas valide ;aucun paquet n'a été supprimé", "The script clones the osx-proxmox.com repository and once the setup is complete, the server will automatically reboot.": "Le script clone le référentiel osx-proxmox.com et une fois la configuration terminée, le serveur redémarrera automatiquement.", "The script will continue to restore VM passthrough mode on the host and reuse existing hostpci entries.": "Le script continuera à restaurer le mode passthrough de la VM sur l'hôte et à réutiliser les entrées hostpci existantes.", "The script will preconfigure the selected GPU now and finalize hardware binding after reboot.": "Le script va préconfigurer le GPU sélectionné maintenant et finaliser la liaison matérielle après le redémarrage.", "The selected AMD GPU does not report FLR reset support": "Le GPU AMD sélectionné ne signale pas la prise en charge de la réinitialisation FLR", "The selected AMD GPU is currently in power state D3cold": "Le GPU AMD sélectionné est actuellement en état d'alimentation D3cold", + "The selected CT does not match its OCI record. Its configuration will not be modified or deleted.": "Le CT sélectionné ne correspond pas à son enregistrement OCI. Sa configuration ne sera ni modifiée ni supprimée.", + "The selected GPU changed": "Le GPU sélectionné a changé", "The selected GPU configuration already exists in this container.": "La configuration GPU sélectionnée existe déjà dans ce conteneur.", + "The selected GPU device does not exist:": "Le périphérique GPU sélectionné n'existe pas :", + "The selected GPU directory does not exist:": "Le répertoire GPU sélectionné n'existe pas :", "The selected GPU has no dedicated .1 audio sibling function.": "Le GPU sélectionné n’a pas de fonction de frère audio .1 dédiée.", "The selected GPU is already assigned to another VM that is currently running:": "Le GPU sélectionné est déjà attribué à une autre VM en cours d'exécution :", "The selected GPU is already assigned to this VM, but the host is not currently using vfio-pci for this device.": "Le GPU sélectionné est déjà attribué à cette VM, mais l'hôte n'utilise pas actuellement vfio-pci pour cet appareil.", @@ -4435,11 +6071,15 @@ "The selected Intel GPU does not expose a PCI reset interface": "Le GPU Intel sélectionné n'expose pas d'interface de réinitialisation PCI", "The selected Intel GPU has non-FLR reset support and unknown subtype": "Le GPU Intel sélectionné prend en charge la réinitialisation non FLR et sous-type inconnu", "The selected Intel GPU is currently in power state D3cold": "Le GPU Intel sélectionné est actuellement en état d'alimentation D3cold", + "The selected Intel render device does not exist:": "Le périphérique de rendu Intel sélectionné n'existe pas :", "The selected VM": "La VM sélectionnée", "The selected VM is running.": "La VM sélectionnée est en cours d'exécution.", "The selected base folder does not exist and could not be created:": "Le dossier de base sélectionné n'existe pas et n'a pas pu être créé :", + "The selected configuration needs to start the LXC during the installation": "La configuration sélectionnée doit démarrer le LXC pendant l'installation", "The selected container is unprivileged. A privileged container is required for direct device passthrough.": "Le conteneur sélectionné n'est pas privilégié. Un conteneur privilégié est requis pour le relais direct du périphérique.", "The selected device": "L'appareil sélectionné", + "The selected device is not a block device": "L'appareil sélectionné n'est pas un dispositif de blocage", + "The selected device is not a character device": "Le périphérique sélectionné n'est pas un périphérique de caractère", "The selected directory does not exist:": "Le répertoire sélectionné n'existe pas :", "The selected disk has an active swap partition. Aborting.": "Le disque sélectionné possède une partition swap active. Opération annulée.", "The selected disk is currently used by a RUNNING VM or CT. Stop it before formatting.": "Le disque sélectionné est actuellement utilisé par une VM ou CT en cours d'exécution. Arrêtez-le avant le formatage.", @@ -4447,25 +6087,76 @@ "The selected disk now contains a system-critical mount. Aborting.": "Le disque sélectionné contient désormais un montage critique pour le système. Avorter.", "The selected path does not exist on this host:": "Le chemin sélectionné n'existe pas sur cet hôte :", "The selected path is not a valid directory:": "Le chemin sélectionné n'est pas un répertoire valide :", + "The selected render device does not exist:": "Le périphérique de rendu sélectionné n'existe pas :", "The server connected you as guest instead of the specified user.": "Le serveur vous a connecté en tant qu'invité au lieu de l'utilisateur spécifié.", "The server may not have accessible shares.": "Le serveur n'a peut-être pas de partages accessibles.", "The server may require authentication for actual share access.": "Le serveur peut exiger une authentification pour l'accès réel au partage.", "The server refused password authentication for": "Le serveur a refusé l'authentification par mot de passe pour", "The server rejected": "Le serveur a rejeté", + "The service builds its own image; only a published image can be installed": "Le service construit sa propre image; seule une image publiée peut être installée", + "The service declares no image:": "Le service ne déclare aucune image:", + "The setting has no final value:": "Le réglage n'a pas de valeur finale:", "The share already exists in smb.conf:": "Le partage existe déjà dans smb.conf :", + "The shared destination is not a directory": "La destination partagée n'est pas un répertoire", + "The shared directory points to a protected host path": "Le répertoire partagé indique un chemin d'hôte protégé", + "The shared path exists but is not a directory:": "Le chemin partagé existe mais n'est pas un répertoire :", + "The size of existing disks is not rounded": "La taille des disques existants n'est pas arrondie", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk.": "La source Compose demande privilégié : vrai, mais cela ne prouve pas que l'image a besoin d'un LXC privilégié. ProxMenux utilisera un LXC par défaut et n'offrira le mode large qu'en option. Continuez seulement si vous faites confiance à l'image et acceptez ce risque.", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. The Docker rootlesskit profile does not exist in LXC and will be replaced by AppArmor unconfined, which is less restrictive. Continue only if you trust the image and accept this risk.": "La source Compose demande privilégié : vrai, mais cela ne prouve pas que l'image a besoin d'un LXC privilégié. ProxMenux utilisera un LXC par défaut et n'offrira le mode large qu'en option. Le Compose offre une relaxation en option AppArmor ou seccomp ; il restera désactivé à moins que l'utilisateur le sélectionne. Le profil Docker rootlesskit n'existe pas dans LXC et sera remplacé par AppArmor non confiné, ce qui est moins restrictif. Continuez seulement si vous faites confiance à l'image et acceptez ce risque.", "The source VM also has these audio devices, likely added together with the GPU. Remove them too?": "La VM source possède également ces périphériques audio, probablement ajoutés au GPU. Les supprimer aussi ?", "The specified directory does not exist:": "Le répertoire spécifié n'existe pas :", + "The stability period must be shorter than the healthcheck timeout": "La période de stabilité doit être plus courte que le délai de contrôle sanitaire", + "The stack contains devices or directives without a translation": "La pile contient des dispositifs ou des directives sans traduction", + "The stack does not have the expected native hook": "La pile n'a pas le crochet natif attendu", + "The stack journal is outside the registry": "La pile journal est à l'extérieur du registre", + "The stack member has no declared adaptation profile": "La pile n'a pas de profil d'adaptation déclaré", + "The stack name only accepts lowercase letters, numbers and hyphens": "Le nom de la pile accepte uniquement les lettres minuscules, les chiffres et les tirets", + "The stack needs member adaptations or a verification of missing volumes": "La pile nécessite des adaptations de membres ou une vérification des volumes manquants", + "The stack operation had already finished": "La pile operation avait déjà fini", + "The stack operation has not finished yet": "La pile operation n'a pas encore fini", + "The stack operation stopped halfway. Select the stack again in the OCI management menu to recover it.": "La pile operation s'est arrêtée à mi-chemin. Sélectionnez à nouveau la pile dans le menu de gestion de l'OCI pour la récupérer.", + "The stack registry is incomplete; review the private contracts.": "Le registre des piles est incomplet; il examine les contrats privés.", + "The stack startup hook was not found": "Le crochet de démarrage de pile n'a pas été trouvé", + "The stack update was saved.": "La mise à jour de la pile a été enregistrée.", + "The startup differs from the declared Nextcloud adapter": "Le démarrage diffère de l'adaptateur Nextcloud déclaré", + "The startup differs from the declared adapter": "Le démarrage diffère de l'adaptateur déclaré", + "The staticfiles volume needs at least 1 GB": "Le volume des fichiers statiques nécessite au moins 1 Go", "The storage has been removed and the disk unmounted.": "Le stockage a été supprimé et le disque démonté.", + "The sysctl content was modified outside the saved record": "Le contenu du sysctl a été modifié en dehors de l'enregistrement enregistré", + "The sysctl include is a link:": "Le système inclus est un lien:", + "The sysctl include is not a safe host file": "Le système inclus n'est pas un fichier hôte sûr", + "The sysctl include is not restored over a symbolic link": "Le sysctl inclus n'est pas restauré sur un lien symbolique", + "The sysctl include is unknown or differs from the saved record": "Le système inclut est inconnu ou diffère de l'enregistrement enregistré", + "The temporary password could not be retrieved.": "Le mot de passe temporaire n'a pas pu être récupéré.", "The test will continue even if you close this terminal.": "Le test continuera même si vous fermez ce terminal.", + "The tmpfs mounts of the container differ from the saved record": "Les supports tmpfs du conteneur diffèrent de l'enregistrement enregistré", + "The tmpfs path or size is outside the supported profile": "Le chemin ou la taille de tmpfs est en dehors du profil pris en charge", + "The translated recipe changed during the preparation": "La recette traduite a changé pendant la préparation", + "The value contains an unsupported character": "La valeur contient un caractère non pris en charge", + "The values do not match. Enter them again.": "Les valeurs ne correspondent pas. Entrez encore.", + "The variable contains control characters:": "La variable contient des caractères de contrôle :", + "The variable contains line breaks:": "La variable contient des ruptures de ligne:", "The vfio.conf entries have been removed and initramfs rebuilt.": "Les entrées vfio.conf ont été supprimées et initramfs reconstruit.", + "The web UI password must have at least 24 characters": "Le mot de passe web UI doit avoir au moins 24 caractères", + "The web UI user contains characters that are not allowed": "L'utilisateur Web UI contient des caractères qui ne sont pas autorisés", + "The web interface is served over plain HTTP on port 51821 (INSECURE=true). Keep it inside the local network or publish it through a reverse proxy with TLS.": "L'interface web est desservie par HTTP sur le port 51821 (INSECURE=true). Gardez-le à l'intérieur du réseau local ou publiez-le via un proxy inversé avec TLS.", + "The web interface uses a self-signed certificate, so the browser shows a warning the first time.": "L'interface web utilise un certificat autosigné, de sorte que le navigateur affiche un avertissement la première fois.", + "The wizard writes a .conf file in /config. Restart the container afterwards so the bot starts with that configuration.": "L'assistant écrit un fichier .conf dans /config. Redémarrez le conteneur après, donc le bot commence par cette configuration.", + "The world's fastest framework for building websites": "Le cadre de construction le plus rapide au monde", + "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server.": "Thelounge (un fork de crieIRC) est un client IRC web que vous hébergez sur votre propre serveur.", "Then bind-mount to container": "Puis liez le montage au conteneur", "Then change the VM display to none (vga: none) when the guest is stable.": "Modifiez ensuite l'affichage de la VM sur aucun (vga : aucun) lorsque l'invité est stable.", "Then change the VM display to none (vga: none) when the system is stable.": "Modifiez ensuite l'affichage de la VM sur aucun (vga : aucun) lorsque le système est stable.", "Then run this option again:": "Ensuite, réexécutez cette option :", "Then update /etc/fstab on the host with the same options.": "Mettez ensuite à jour /etc/fstab sur l'hôte avec les mêmes options.", + "There are extra disks or bind mounts outside the journal; the rootfs is not replaced": "Il y a des disques supplémentaires ou des fixations en dehors du journal; les rootfs ne sont pas remplacés", + "There is no temporary container of this operation to keep the current disks": "Il n'y a pas de conteneur temporaire de cette operation pour garder les disques actuels", + "There is no verified backup; a modified container is not touched": "Il n'y a pas de sauvegarde vérifiée; un conteneur modifié n'est pas touché", + "These VMIDs are not free:": "Ces VMID ne sont pas libres:", "These are the changes that will be made": "Ce sont les changements qui seront apportés", "These interface configurations will be removed": "Ces configurations d'interface seront supprimées", "These paths will not be restored live and will be extracted for manual recovery.": "Ces chemins ne seront pas restaurés en direct et seront extraits pour une récupération manuelle.", + "These values are asked during the installation:": "Ces valeurs sont demandées lors de l'installation:", "This CIFS share is mounted with restrictive permissions.": "Ce partage CIFS est monté avec des autorisations restrictives.", "This GPU is considered incompatible with GPU passthrough to a VM in ProxMenux.": "Ce GPU est considéré comme incompatible avec le relais GPU vers une VM dans ProxMenux.", "This NFS share is fully restricted — even the host root cannot write to it.": "Ce partage NFS est entièrement restreint : même la racine de l'hôte ne peut pas y écrire.", @@ -4477,6 +6168,8 @@ "This backup is encrypted.": "Cette sauvegarde est cryptée.", "This backup was taken on kernel": "Cette sauvegarde a été effectuée sur le noyau", "This cleanup will:": "Ce nettoyage :", + "This container belongs to a stack; publish the whole stack": "Ce conteneur appartient à une pile; publier la pile entière", + "This container belongs to a stack; recover the whole stack": "Ce conteneur appartient à une pile; récupérer toute la pile", "This container does not have apt-get. NFS client installation only supports Debian/Ubuntu containers.": "Ce conteneur n'a pas apt-get. L'installation du client NFS prend uniquement en charge les conteneurs Debian/Ubuntu.", "This container does not have apt-get. Samba client installation only supports Debian/Ubuntu containers.": "Ce conteneur n'a pas apt-get. L'installation du client Samba prend uniquement en charge les conteneurs Debian/Ubuntu.", "This container has no GPU configured. Coral TPU works best alongside hardware video decoding (Quick Sync, VA-API, NVENC) for apps like Frigate.": "Ce conteneur n'a aucun GPU configuré. Coral TPU fonctionne mieux avec le décodage vidéo matériel (Quick Sync, VA-API, NVENC) pour des applications comme Frigate.", @@ -4486,15 +6179,21 @@ "This erases existing metadata.": "Cela efface les métadonnées existantes.", "This explicitly marks the container as privileged": "Cela marque explicitement le conteneur comme privilégié", "This guarantees that device nodes are available before applying LXC GPU config.": "Cela garantit que les nœuds de périphérique sont disponibles avant d'appliquer la configuration GPU LXC.", + "This image cannot be installed as it is described:": "Cette image ne peut pas être installée comme elle est décrite :", + "This image requires the host module": "Cette image requirese le module hôte", "This installation will:": "Cette installation va :", "This installer will:": "Ce programme d'installation va :", "This interface is configured but doesn't exist physically": "Cette interface est configurée mais n'existe pas physiquement", + "This interface runs on the Proxmox node as root. Open proxmenux-oci.sh on the Proxmox host.": "Cette interface fonctionne sur le nœud Proxmox comme racine. Ouvrez proxmenux-oci.sh sur l'hôte Proxmox.", "This is IRREVERSIBLE.": "C’est IRRÉVERSIBLE.", "This is a destructive action": "Il s’agit d’une action destructrice", "This is a simple configuration change": "Il s'agit d'un simple changement de configuration", "This is an external community script maintained by": "Il s'agit d'un script de communauté externe maintenu par", "This is an external script that creates a macOS VM in Proxmox VE in just a few steps, whether you are using AMD or Intel hardware.": "Il s'agit d'un script externe qui crée une VM macOS dans Proxmox VE en quelques étapes seulement, que vous utilisiez du matériel AMD ou Intel.", + "This is not a coordinated stack": "Ce n'est pas une pile coordonnée", + "This is not a valid image reference:": "Ce n'est pas une référence d'image valide:", "This is unexpected since credentials were validated.": "C'est inattendu puisque les informations d'identification ont été validées.", + "This is what ProxMenux understood from the": "C'est ce que ProxMenux a compris de la", "This marks the container as unprivileged": "Cela marque le conteneur comme non privilégié", "This may be normal for a fresh installation": "Cela peut être normal pour une nouvelle installation", "This may take a few minutes. Press OK to proceed.": "Cela peut prendre quelques minutes. Appuyez sur OK pour continuer.", @@ -4503,12 +6202,14 @@ "This means Proxmox handles mount lifecycle natively (no manual /etc/fstab needed for NFS/CIFS host storages).": "Cela signifie que Proxmox gère le cycle de vie du montage de manière native (aucun /etc/fstab manuel n'est nécessaire pour les stockages hôtes NFS/CIFS).", "This means the credentials are incorrect.": "Cela signifie que les informations d'identification sont incorrectes.", "This might indicate network connectivity issues.": "Cela peut indiquer des problèmes de connectivité réseau.", + "This monitor uses a privileged LXC, shares processes and network with Proxmox and disables AppArmor in the CT. It uses the IP address and firewall of the host. A compromised image could affect the host; do not expose its web UI to the Internet.": "Ce moniteur utilise un LXC privilégié, partage les processus et le réseau avec Proxmox et désactive AppArmor dans le CT. Il utilise l'adresse IP et le pare-feu de l'hôte. Une image compromise pourrait affecter l'hôte; ne pas exposer son interface utilisateur Web à Internet.", "This operation may take several minutes and requires internet connectivity.": "Cette opération peut prendre plusieurs minutes et nécessite une connexion Internet.", "This package was installed by older versions of the ProxMenux Coral installer that placed the M.2 kernel driver on every system, including USB-only setups. It is not needed for Coral USB devices, which use libedgetpu1-std / libedgetpu1-max only.": "Ce package a été installé par les anciennes versions du programme d'installation de ProxMenux Coral qui plaçaient le pilote du noyau M.2 sur chaque système, y compris les configurations USB uniquement. Il n'est pas nécessaire pour les périphériques USB Coral, qui utilisent uniquement libedgetpu1-std / libedgetpu1-max.", "This passphrase is the ONLY way to access encrypted Borg backups.": "Cette phrase secrète est le SEUL moyen d'accéder aux sauvegardes Borg cryptées.", "This path is already used as a mount point in this container.": "Ce chemin est déjà utilisé comme point de montage dans ce conteneur.", "This path is not a registered mount point. Use it anyway?": "Ce chemin n'est pas un point de montage enregistré. L'utiliser quand même ?", "This process changes file ownership inside the container": "Ce processus modifie la propriété du fichier à l'intérieur du conteneur", + "This profile only supports directory bind mounts": "Ce profil ne prend en charge que les montages de liaison de répertoire", "This release channel is already active.": "Ce canal de publication est déjà actif.", "This removes the 'unprivileged: 1' line from the config": "Cela supprime la ligne « non privilégié : 1 » de la configuration.", "This removes the storage from Proxmox. The iSCSI target is not affected.": "Cela supprime le stockage de Proxmox. La cible iSCSI n'est pas affectée.", @@ -4522,10 +6223,15 @@ "This session is running in the Monitor terminal. Running it from here would cut the connection mid-install and leave the switch in a broken state.": "Cette session est en cours d'exécution dans le terminal Monitor. L’exécuter à partir d’ici couperait la connexion en cours d’installation et laisserait le commutateur dans un état cassé.", "This session is running in the Monitor terminal. Updating from here would restart the Monitor service and cut the connection mid-install, leaving the update in a broken state.": "Cette session est en cours d'exécution dans le terminal Monitor. La mise à jour à partir d'ici redémarrerait le service Monitor et couperait la connexion en cours d'installation, laissant la mise à jour dans un état interrompu.", "This shows the storage type and disk identifier": "Ceci montre le type de stockage et l'identifiant du disque", + "This stack requires replaying specific rootfs adaptations. Coordinated updates are not yet enabled for it.": "Cette pile requires rejoue des adaptations spécifiques rootfs. Les mises à jour coordonnées ne sont pas encore activées.", "This state has a high probability of VM startup/reset failures.": "Cet état présente une forte probabilité d’échecs de démarrage/réinitialisation de la VM.", "This state indicates a high risk of passthrough failure due to": "Cet état indique un risque élevé d'échec du relais en raison de", + "This template requests the host PID namespace, which has no validated safe LXC translation yet": "Ce modèle demande l'espace de noms PID hôte, qui n'a pas encore validé la traduction sûre LXC", "This tool is designed for systems with AMD GPUs.": "Cet outil est conçu pour les systèmes équipés de GPU AMD.", "This tool is designed for systems with Intel GPUs.": "Cet outil est conçu pour les systèmes équipés de GPU Intel.", + "This translator only supports the Nextcloud stack": "Ce traducteur prend uniquement en charge le Nextcloud stack", + "This value is required.": "Cette valeur est required.", + "This variant requires the device": "Cette variante requires l'appareil", "This version does not build against the running kernel.": "Cette version ne s'appuie pas sur le noyau en cours d'exécution.", "This will RESET the ProxMenux Monitor login credentials on this host:": "Cela réinitialisera les informations de connexion de ProxMenux Monitor sur cet hôte :", "This will add the mount to /etc/fstab so it persists after reboot.": "Cela ajoutera le montage à /etc/fstab afin qu'il persiste après le redémarrage.", @@ -4547,13 +6253,17 @@ "This will restart the network service and may cause a brief disconnection. Continue?": "Cela redémarrera le service réseau et pourrait provoquer une brève déconnexion. Continuer?", "This will take time. Answer prompts carefully - see notes below.": "Cela prendra du temps. Répondez attentivement aux invites - voir les notes ci-dessous.", "This will upgrade this node to Proxmox VE 9 on Debian Trixie.": "Cela mettra à niveau ce nœud vers Proxmox VE 9 sur Debian Trixie.", + "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client.": "Thunderbird est un gestionnaire de renseignements personnels libre et open source principalement utilisé comme client de messagerie électronique avec un agenda et un carnet de contact, ainsi qu'un lecteur de flux RSS, client de chat et client de nouvelles.", "Tick the paths to include in this backup. Press \"Add custom path\" to add a folder or file of your own to the list.": "Cochez les chemins à inclure dans cette sauvegarde. Appuyez sur \"Ajouter un chemin personnalisé\" pour ajouter votre propre dossier ou fichier à la liste.", "Tick the paths to remove (they will not be deleted from disk — only from this list):": "Cochez les chemins à supprimer (ils ne seront pas supprimés du disque — uniquement à partir de cette liste) :", + "Time is up; Home Assistant OS could not be confirmed as running": "Le temps est écoulé; Home Assistant OS n'a pas pu être confirmé comme fonctionnant", "Time settings configured - Timezone:": "Paramètres horaires configurés - Fuseau horaire :", "Time synchronization reset to UTC": "Synchronisation de l'heure réinitialisée sur UTC", + "Timezone": "Fuseau horaire", "Tip: Also mount the VirtIO ISO for drivers and guest agent installer": "Astuce : Montez également l'ISO VirtIO pour les pilotes et le programme d'installation de l'agent invité.", "Tip: You can install the QEMU Guest Agent inside the VM with:": "Astuce : Vous pouvez installer l'agent invité QEMU dans la VM avec :", "Tip: zfs set acltype=posixacl xattr=sa / enables full ACL support.": "Astuce : zfs set acltype=posixacl xattr=sa / active la prise en charge complète des ACL.", + "Tmpfs size in MiB for": "Taille Tmpfs en MiB pour", "To allow LXC write access, change the NFS export on the server to include:": "Pour autoriser l'accès en écriture LXC, modifiez l'exportation NFS sur le serveur pour inclure :", "To apply it to the current shell now, run:": "Pour l’appliquer maintenant à la session shell actuelle, exécutez :", "To assign VFs to VMs or LXCs, edit the configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Pour attribuer des VF aux VM ou LXC, modifiez la configuration manuellement via l'interface Web Proxmox. La fonction physique restera liée au pilote natif.", @@ -4568,6 +6278,7 @@ "To pass SR-IOV Virtual Functions to a container, edit the LXC configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Pour transmettre les fonctions virtuelles SR-IOV à un conteneur, modifiez la configuration LXC manuellement via l'interface Web Proxmox. La fonction physique restera liée au pilote natif.", "To remove partial VM:": "Pour supprimer une VM partielle :", "To restore": "Pour restaurer", + "To restore it on another host, keep this file (not included in the vzdump backup):": "Pour la restaurer sur un autre hôte, conservez ce fichier (non inclus dans la sauvegarde vzdump) :", "To revert changes:": "Pour annuler les modifications :", "To start the VM:": "Pour démarrer la VM :", "To stop:": "Pour arrêter :", @@ -4579,12 +6290,17 @@ "To use this share from an LXC, bind-mount it via:": "Pour utiliser ce partage à partir d'un LXC, montez-le via :", "Tool exit code:": "Code de sortie de l'outil :", "Tool output:": "Sortie de l'outil :", + "Tools": "Outils", "Top memory processes in CT": "Principaux processus de mémoire en CT", + "Top-level configs, secrets and other global options are not yet supported": "Configurations de haut niveau, secrets et autres options globales ne sont pas encore pris en charge", + "Top-level volume options are not yet supported": "Les options de volume de haut niveau ne sont pas encore prises en charge", "Total": "Total", "Total members:": "Nombre total de membres :", "Total routes": "Total des itinéraires", "Total size:": "Taille totale :", + "Transaction log:": "Registre des transactions & #160;:", "Translation files:": "Fichiers de traduction :", + "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, µTP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more.": "Transmission est conçu pour une utilisation facile et puissante. Transmission possède les fonctionnalités que vous souhaitez d'un client BitTorrent : cryptage, interface web, échange entre pairs, liens magnétiques, DHT, μTP, UPnP et le transfert de port NAT-PMP, support de webseed, répertoires de veille, édition de tracker, limites de vitesse globales et per-torrent, et plus encore.", "Tried pvesm path and manual detection methods": "Chemin pvesm essayé et méthodes de détection manuelle", "Trust this certificate and save it for scheduled backups?": "Faire confiance à ce certificat et l'enregistrer pour les sauvegardes planifiées ?", "Try Again": "Essayer à nouveau", @@ -4592,6 +6308,8 @@ "Try accessing": "Essayez d'accéder", "Try another archive": "Essayez une autre archive", "Try automatic repair of detected issues": "Essayez la réparation automatique des problèmes détectés", + "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources.": "Tvheadend fonctionne comme serveur proxy: est un serveur de streaming TV et enregistreur pour Linux, FreeBSD et Android prenant en charge DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP et HDHomeRun comme sources d'entrée.", + "Twingate Connector for self-hosted server": "Connecteur Twingate pour serveur autonome", "Two-factor authentication and backup codes will be removed.": "L'authentification à deux facteurs et les codes de sauvegarde seront supprimés.", "Type": "Taper", "Type the device path EXACTLY to confirm formatting:": "Tapez EXACTEMENT le chemin du périphérique pour confirmer le formatage :", @@ -4600,16 +6318,22 @@ "Type: attached to PVE storage": "Type : attaché au stockage PVE", "Typed value does not match selected disk. Operation cancelled.": "La valeur saisie ne correspond pas au disque sélectionné. Opération annulée.", "UID in CT": "UID dans CT", + "UID of the plex user (also owner of the GPU device)": "UID de l'utilisateur plex (également propriétaire du périphérique GPU)", + "UID that Emby runs as": "UID que Emby fonctionne comme", "UPGRADE PROMPTS - RECOMMENDED ANSWERS:": "INVITES DE MISE À NIVEAU – RÉPONSES RECOMMANDÉES :", + "UPS monitoring and power outage notification system": "Système de surveillance et de notification de panne d'électricité UPS", "USB Accelerators:": "Accélérateurs USB :", + "USB bus directory": "Répertoire de bus USB", "USB disk target": "cible du disque USB", "USB drives mounted now:": "Clés USB montées maintenant :", "USB libedgetpu1": "USB libedgetpu1", "UUP Dump script not found.": "Script de vidage UUP introuvable.", "UUp Dump ISO creator Custom": "UUp Dump Créateur ISO Personnalisé", + "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer.": "Ubooquity est un serveur à domicile gratuit, léger et facile à utiliser pour vos BD et ebooks. Utilisez-le pour accéder à vos fichiers de n'importe où, avec une tablette, un lecteur électronique, un téléphone ou un ordinateur.", "Udev rules for Coral USB devices added and rules reloaded.": "Règles Udev pour les périphériques USB Coral ajoutées et règles rechargées.", "Udev rules for Coral USB devices already exist.": "Les règles Udev pour les périphériques Coral USB existent déjà.", "Udev rules for Coral USB devices appended and rules reloaded.": "Règles Udev pour les périphériques USB Coral ajoutées et règles rechargées.", + "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results.": "UltiMaker Cura est un logiciel d'impression 3D gratuit, facile à utiliser et fiable par des millions d'utilisateurs. Finissez votre modèle 3D avec plus de 400 réglages pour obtenir les meilleurs résultats de coupe et d'impression.", "Umbrel OS installer script by Helper Scripts\n\nVisit the GitHub repo to learn more, contribute, or support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm": "Script d'installation du système d'exploitation Umbrel par Helper Scripts\n\nVisitez le dépôt GitHub pour en savoir plus, contribuer ou soutenir le projet :\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm", "Unable to detect Proxmox version": "Impossible de détecter la version de Proxmox", "Unable to detect Proxmox version.": "Impossible de détecter la version de Proxmox.", @@ -4618,6 +6342,10 @@ "Unable to resolve system ZFS pool disks. Aborting.": "Impossible de résoudre les disques du pool système ZFS.Avorter.", "Unable to resolve system disk topology. Aborting.": "Impossible de résoudre la topologie du disque système. Avorter.", "Understand the security implications of privileged containers": "Comprendre les implications de sécurité des conteneurs privilégiés", + "Unexpected Proxmox inventory; recovery blocked": "stocks imprévus Proxmox; récupération bloquée", + "Unexpected formatting directory in the new Valkey volume": "Répertoire de formatage inattendu dans le nouveau volume Valkey", + "Ungoogled Chromium is Google Chromium, sans dependency on Google web services.": "Ungoogled Chromium est Google Chromium, sans dépendance sur les services web de Google.", + "Unified LLM Fine-Tuning with 100+ Models": "Unified LLM Fine-Tuning avec plus de 100 modèles", "Uninstall Coral drivers and configuration": "Désinstaller les pilotes et la configuration Coral", "Uninstall Fail2Ban": "Désinstaller Fail2Ban", "Uninstall Lynis": "Désinstaller Lynis", @@ -4647,6 +6375,10 @@ "Unknown CPU type. IOMMU might not be properly enabled.": "Type de processeur inconnu. IOMMU n'est peut-être pas correctement activé.", "Unknown CPU vendor. Cannot determine IOMMU parameter.": "Fournisseur de processeur inconnu. Impossible de déterminer le paramètre IOMMU.", "Unknown GPU": "GPU inconnu", + "Unknown adapter role": "Rôle d'adaptateur inconnu", + "Unknown credential service:": "Service credential inconnu:", + "Unknown dependency:": "Dépendance inconnue:", + "Unknown host monitor": "Moniteur hôte inconnu", "Unknown model": "Modèle inconnu", "Unknown size": "Taille inconnue", "Unknown storage controller": "Contrôleur de stockage inconnu", @@ -4662,6 +6394,10 @@ "Unmounted:": "Démonté :", "Unmounting": "Démontage", "Unmounting disk...": "Démontage du disque...", + "Unpackerr configured": "MPXTERM000 configuré", + "Unpackerr has no web interface and extracts nothing until it is pointed at a Starr application. Uncomment the [sonarr.0] or [radarr.0] section in /config/unpackerr.conf inside the container, set its url and api_key, then restart the container.": "Unpackerr n'a pas d'interface web et n'extrait rien jusqu'à ce qu'il soit pointé sur une application Starr. Décommenter la section [sonarr.0] ou [radarr.0] dans /config/unpackerr.conf à l'intérieur du conteneur, mettre son url et api key, puis redémarrer le conteneur.", + "Unpackerr requires Sonarr, Radarr or Lidarr in this suite": "Unpackerr requires Sonarr, Radarr ou Lidarr dans cette suite", + "Unpackerr stopped during its first start": "Unpackerr s'est arrêté lors de son premier départ", "Unprivileged": "Sans privilège", "Unprivileged Container Access": "Accès aux conteneurs sans privilèges", "Unprivileged container": "Conteneur non privilégié", @@ -4670,15 +6406,73 @@ "Unprivileged containers map their UIDs to high host UIDs (e.g. 100000+), which appear as 'others' on the host filesystem.": "Les conteneurs non privilégiés mappent leurs UID sur des UID d'hôte élevés (par exemple 100 000+), qui apparaissent comme « autres » sur le système de fichiers hôte.", "Unprivileged: Limited access (more secure)": "Non privilégié : accès limité (plus sécurisé)", "Unreachable": "Injoignable", + "Unrecognized Immich adapter": "Adaptateur Immich non reconnu", + "Unrecognized adaptation format": "Format d'adaptation non reconnu", + "Unrecognized adaptation recipe": "Recette d'adaptation non reconnue", + "Unrecognized dependency order of the stack:": "Ordre de dépendance non reconnu de la pile:", + "Unrecognized host monitor profile": "Profil non reconnu du moniteur hôte", + "Unrecognized native configuration": "Configuration native non reconnue", + "Unrecognized qBittorrent configuration format": "Format de configuration qBittorrent non reconnu", + "Unrecognized stack adapter or role": "Adaptateur ou rôle de pile non reconnu", + "Unrecognized stack adapter:": "Adaptateur de pile non reconnu:", + "Unrecognized stack structure:": "Structure de la pile non reconnue:", + "Unrecognized volume definition": "Définition non reconnue du volume", + "Unresolved variable:": "Variable non résolue:", + "Unsafe OCI archive path": "Chemin d'archive de l'OCI non sûr", + "Unsafe dependency contract": "Contrat de dépendance non sûr", + "Unsafe dependency hook contract": "Contrat de crochet de dépendance non sûr", + "Unsafe instance directory": "Répertoire d'instances non sécurisées", + "Unsafe instance record": "Enregistrement d'instance non sûr", + "Unsafe journal or lock file": "Fichier de journal ou de verrouillage non sécurisé", + "Unsafe private configuration path": "Voie de configuration privée non sûre", + "Unsafe qBittorrent configuration path": "Path de configuration qBittorrent non sûr", + "Unsafe record": "Enregistrement non sûr", + "Unsafe registry directory": "Répertoire de registre non sûr", + "Unsafe registry lock": "Verrouillage du registre non sûr", + "Unsafe rootfs for the capture": "Des rootfs non sûrs pour la capture", + "Unsafe stack assembly": "Montage de la pile non sûr", + "Unsafe volume path": "Voie de volume non sûre", + "Unsupported CPU allocation mode:": "Mode d'allocation CPU non pris en charge:", + "Unsupported GID strategy:": "Stratégie GID non soutenue :", + "Unsupported NVIDIA mode:": "Mode NVIDIA non supporté:", + "Unsupported OCI digest:": "Digest du BEC non soutenu:", + "Unsupported OCI-LXC AppArmor profile:": "Profil OCI-LXC AppArmor non soutenu :", + "Unsupported OCI-LXC seccomp profile:": "Profil de seccomp OCI-LXC non pris en charge:", "Unsupported Terminal": "Terminal non pris en charge", + "Unsupported architecture:": "Architecture non supportée :", + "Unsupported backup compression": "compression de sauvegarde non prise en charge", + "Unsupported credential pattern:": "Modèle credential non pris en charge:", + "Unsupported declarative ostype:": "Ostype déclaratif non soutenu:", + "Unsupported device GID strategy": "Stratégie GID du périphérique non pris en charge", + "Unsupported device type:": "Type de périphérique non pris en charge:", + "Unsupported dynamic NVIDIA capabilities:": "Capacités NVIDIA dynamiques non soutenues:", "Unsupported format. Only .ova and .ovf files are supported.": "Format non pris en charge. Seuls les fichiers .ova et .ovf sont pris en charge.", + "Unsupported media storage mode:": "Mode de stockage multimédia non supporté:", + "Unsupported mount type": "Type de montage non supporté", + "Unsupported mount type:": "Type de montage non pris en charge:", + "Unsupported native device type:": "Type de périphérique natif non pris en charge:", + "Unsupported operation": "operation non prise en charge", "Unsupported output format:": "Format de sortie non pris en charge :", + "Unsupported post-start configuration:": "Configuration après le démarrage non prise en charge:", + "Unsupported pre-start check:": "Vérification prédémarrage non prise en charge :", + "Unsupported pre-start repair:": "Réparation prédémarrage non prise en charge:", + "Unsupported prlimit resource": "Ressources prlimit non prises en charge", + "Unsupported secret generator:": "Générateur secret non supporté:", + "Unsupported storage mode:": "Mode de stockage non supporté:", + "Unsupported tmpfs options": "Options tmpfs non prises en charge", + "Unsupported volume options:": "Options de volume non pris en charge:", + "Untrusted or modified NVIDIA hook": "Crochet NVIDIA non fiable ou modifié", + "Unused image removed from the cache:": "Image non utilisée retirée du cache :", + "Unused images removed from the cache:": "Images inutilisées supprimées du cache :", + "Update": "Mise à jour", "Update Available": "mise à jour disponible", "Update Ceph repository (Only if using Ceph):": "Mettre à jour le référentiel Ceph (uniquement si vous utilisez Ceph) :", "Update Debian repositories to Trixie:": "Mettez à jour les dépôts Debian vers Trixie :", "Update Export": "Mettre à jour l'exportation", "Update Lynis to latest version": "Mettre à jour Lynis vers la dernière version", "Update NVIDIA in LXC Containers": "Mettre à jour NVIDIA dans les conteneurs LXC", + "Update OCI": "Mettre à jour le BEC", + "Update OCI stack": "Mettre à jour la pile OCI", "Update PVE enterprise repository (Only if using enterprise):": "Mettre à jour le référentiel d'entreprise PVE (uniquement si vous utilisez l'entreprise) :", "Update Proxmox VE Appliance Manager": "Mettre à jour le gestionnaire d'appliances Proxmox VE", "Update Proxmox package lists": "Mettre à jour les listes de packages Proxmox", @@ -4687,15 +6481,26 @@ "Update and upgrade all system packages": "Mettre à jour et mettre à niveau tous les packages système", "Update and upgrade system": "Système de mise à jour et de mise à niveau", "Update cancelled by user": "Mise à jour annulée par l'utilisateur", + "Update completed. Data kept.": "Mise à jour terminée. Données conservées.", "Update completed. Press Enter to continue...": "Mise à jour terminée. Appuyez sur Entrée pour continuer...", + "Update every container of the application": "Mettre à jour chaque conteneur de l'application", "Update kernel to compatible version": "Mettre à jour le noyau vers une version compatible", + "Update now?": "Mise à jour ?", "Update package index:": "Index du package de mise à jour :", + "Update prepared": "Mise à jour préparée", "Update system to latest PVE 8.4+ (if not done already):": "Mettre à jour le système vers la dernière version PVE 8.4+ (si ce n'est déjà fait) :", + "Update the image with the saved configuration": "Mettre à jour l'image avec la configuration enregistrée", + "Update the whole stack?": "Mettre à jour toute la pile ?", "Updated": "Mis à jour", "Updated sharedfiles group to GID: 101000": "Groupe de fichiers partagés mis à jour vers GID : 101000", + "Updated stack checked": "Correction de la pile", + "Updated:": "Mise à jour :", "Updates all Proxmox and Debian packages": "Met à jour tous les packages Proxmox et Debian", "Updates and Packages Commands": "Commandes de mises à jour et de packages", + "Updates are not available yet for this application in this beta": "Les mises à jour ne sont pas encore disponibles pour cette application dans cette bêta", + "Updates are not available yet in this beta for applications that use a privileged container or advanced LXC settings": "Les mises à jour ne sont pas encore disponibles dans cette bêta pour les applications qui utilisent un conteneur privilégié ou des paramètres avancés LXC", "Updates file is empty or unreadable.": "Le fichier de mises à jour est vide ou illisible.", + "Updating": "Mise à jour", "Updating APT package lists...": "Mise à jour des listes de packages APT...", "Updating Debian Bookworm → Trixie in sources.list...": "Mise à jour de Debian Bookworm → Trixie dans sources.list...", "Updating Figurine binary...": "Mise à jour du binaire Figurine...", @@ -4727,6 +6532,7 @@ "Upload to PBS is currently: yes. Pick an action:": "Le téléchargement sur PBS est actuellement : oui. Choisissez une action :", "Upload to PBS: enable, disable or rotate the recovery passphrase": "Télécharger sur PBS : activer, désactiver ou alterner la phrase secrète de récupération", "Uptime and who is logged in": "Disponibilité et qui est connecté", + "Usage:": "Utilisation :", "Use \"Check test progress\" to see results.": "Utilisez « Vérifier la progression du test » pour voir les résultats.", "Use 'Export to file' to save it and inspect manually.": "Utilisez « Exporter vers un fichier » pour l'enregistrer et l'inspecter manuellement.", "Use 'pct restore' / 'qmrestore' to recover their disks from your VM backups.": "Utilisez « PCT Restore » / « qmrestore » pour récupérer leurs disques à partir des sauvegardes de votre VM.", @@ -4769,6 +6575,12 @@ "User activity and uptime": "Activité des utilisateurs et disponibilité", "User chose not to remove NetworkManager": "L'utilisateur a choisi de ne pas supprimer NetworkManager", "User chose to exit for manual backup creation.": "L'utilisateur a choisi de quitter pour la création manuelle d'une sauvegarde.", + "User name for the SSH login": "Nom d'utilisateur pour la connexion SSH", + "User name of the administrator of the web interface": "Nom d'utilisateur de l'administrateur de l'interface web", + "User name of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Nom d'utilisateur de l'application Flowise dépréciée (seulement lu par les versions Flowise avant 3.0.1)", + "User of the AdGuard Home that receives the settings": "Utilisateur du AdGuard Home qui reçoit les paramètres", + "User of the main AdGuard Home": "Utilisateur du principal AdGuard Home", + "User-friendly WebUI for LLMs (Formerly Ollama WebUI)": "WebUI convivial pour les LLM (anciennement Ollama WebUI)", "Username": "Nom d'utilisateur", "Username (e.g. root@pam or user@pbs!token):": "Nom d'utilisateur (par exemple root@pam ou user@pbs!token) :", "Username and password": "Nom d'utilisateur et mot de passe", @@ -4782,6 +6594,8 @@ "Using advanced configuration": "Utilisation de la configuration avancée", "Using default Proxmox logo...": "Utilisation du logo Proxmox par défaut...", "Using existing encryption key:": "Utilisation de la clé de chiffrement existante :", + "Using the image verified by the transaction": "Utilisation de l'image vérifiée par la transaction", + "Using the verified image from the cache": "Utilisation de l'image vérifiée à partir du cache", "Utilities": "Utilitaires", "Utilities Installation Menu": "Menu d'installation des utilitaires", "Utilities Menu": "Menu Utilitaires", @@ -4789,6 +6603,9 @@ "Utilities and Tools": "Utilitaires et outils", "Utilities installation completed": "Installation des utilitaires terminée", "Utilities installed by ProxMenux have been removed": "Les utilitaires installés par ProxMenux ont été supprimés", + "VA-API driver": "Pilote VA-API", + "VA-API render device": "Dispositif de rendu VA-API", + "VA-API video acceleration": "Accélération vidéo VA-API", "VFIO device IDs removed from /etc/modprobe.d/vfio.conf": "ID de périphérique VFIO supprimés de /etc/modprobe.d/vfio.conf", "VFIO modules configured in /etc/modules": "Modules VFIO configurés dans /etc/modules", "VFIO modules configured.": "Modules VFIO configurés.", @@ -4796,7 +6613,9 @@ "VFIO modules removed from /etc/modules": "Modules VFIO supprimés de /etc/modules", "VFIO orphans cleared and initramfs rebuilt — next boot will free the GPU.": "les orphelins VFIO effacés et initramfs reconstruits — le prochain démarrage libérera le GPU.", "VFIO orphans cleared but initramfs rebuild failed; check /var/log/proxmenux logs.": "les orphelins VFIO ont été effacés mais la reconstruction d'initramfs a échoué ;vérifiez les journaux /var/log/proxmenux.", + "VFS cache mode": "Mode cache VFS", "VLAN": "VLAN", + "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices.": "VLC Médias Le lecteur est un lecteur multimédia multiplateforme libre et ouvert qui offre des performances fiables sur plusieurs appareils.", "VM": "VM", "VM Conflict Policy": "Politique de conflit de VM", "VM ID": "ID de machine virtuelle", @@ -4824,17 +6643,29 @@ "VM started": "VM démarrée", "VM stopped": "VM arrêtée", "VM:": "Machine virtuelle :", + "VMID (empty = next free)": "VMID (vide = prochain libre)", "VMID in use": "VMID en cours d'utilisation", "VMID must be a number.": "VMID doit être un nombre.", "VMID of the Borg server LXC on": "VMID du serveur Borg LXC sur", + "VMID of the Rclone OCI container": "VMID du contenant Rclone OCI", "VMs to destroy:": "VM à détruire :", "VMs, LXCs, network, /etc/pve, users, cron, packages, drivers, ProxMenux state, etc.": "machines virtuelles, LXC, réseau, /etc/pve, utilisateurs, cron, packages, pilotes, état ProxMenux, etc.", + "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server.": "VS Code est un environnement de développement intégré développé par Microsoft. Ce conteneur exécute l'application de bureau complet, pour une version web native voir Code Server.", + "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft’s editor VS Code.": "VSCodium est une distribution binaire libre de MicrosoftS Editor VS Code, dirigée par la communauté.", "Valid backups for all VMs/CTs": "Sauvegardes valides pour toutes les VM/CT", "Validating Proxmox 9 repositories (checking 'proxmox-ve' candidate)...": "Validation des référentiels Proxmox 9 (vérification du candidat 'proxmox-ve')...", "Validating credentials with server": "Validation des informations d'identification avec le serveur", "Validating disk safety...": "Validation de la sécurité du disque...", + "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)": "Méthode de validation: http (port 80 transmis) ou dns (greffon fournisseur de DNS)", + "Value for": "Valeur pour", + "Variable name": "Nom variable", + "Variables": "Variables", + "Variables the installation asks for:": "Variables que l'installation demande:", + "Vaultwarden Web Vault": "Vaultwarden Courbe Web", "Verbose pool status": "État du pool détaillé", "Verification": "Vérification", + "Verified": "Vérifié", + "Verified by ProxMenux": "Vérifié par ProxMenux", "Verify IOMMU group for PCI device": "Vérifier le groupe IOMMU pour le périphérique PCI", "Verify Options > OS Type — currently set to:": "Vérifiez les options > Type de système d'exploitation – actuellement défini sur :", "Verify PVE version (must be 8.4.1 or newer):": "Vérifiez la version PVE (doit être 8.4.1 ou plus récente) :", @@ -4850,12 +6681,16 @@ "Verifying Ceph packages availability...": "Vérification de la disponibilité des packages Ceph...", "Verifying all utilities status": "Vérification de l'état de tous les utilitaires", "Verifying disk accessibility in CT": "Vérification de l'accessibilité du disque dans CT", + "Verifying the backups...": "Vérifier les sauvegardes...", + "Verifying the image integrity...": "Vérifier l'intégrité de l'image...", "Version": "Version", "Version Change Detected": "Changement de version détecté", "Version info not available": "Informations sur la version non disponibles", "Version:": "Version:", "Version: Auto-negotiation (NFSv3/NFSv4)": "Version : Auto-négociation (NFSv3/NFSv4)", "Versions shown belong to maintained NVIDIA branches that list your GPU PCI ID and are new enough to build against the running kernel. DKMS compilation is the final validation. The recommended version keeps the current branch, or uses the NVIDIA Production Branch on a fresh install.": "Les versions affichées appartiennent aux branches NVIDIA maintenues qui répertorient votre ID PCI GPU et sont suffisamment récentes pour être construites sur le noyau en cours d'exécution. La compilation DKMS est la validation finale. La version recommandée conserve la branche actuelle ou utilise la branche de production NVIDIA sur une nouvelle installation.", + "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML.": "L'accélération vidéo et la détection d'objets sont des choix indépendants; l'installateur n'écrit pas la caméra ou le détecteur YAML.", + "Video transcoding acceleration": "Accélération du transcodage vidéo", "View CIFS Mounts (pvesm + fstab)": "Afficher les montages CIFS (pvesm + fstab)", "View Current Exports": "Afficher les exportations actuelles", "View Current Mounts": "Afficher les montures actuelles", @@ -4871,6 +6706,7 @@ "View raw VM configuration file": "Afficher le fichier de configuration brut de la VM", "View restore plan": "Afficher le plan de restauration", "View self-test log": "Afficher le journal d'autotest", + "View status": "État de la vue", "VirtIO (advanced - high performance)": "VirtIO (avancé - hautes performances)", "VirtIO ISO not found after selection.": "VirtIO ISO introuvable après sélection.", "VirtIO ISO selection cancelled.": "Sélection ISO VirtIO annulée.", @@ -4886,10 +6722,19 @@ "Virtual display normalized to vga: std (compatibility)": "Affichage virtuel normalisé en VGA : std (compatibilité)", "Virtual display set to": "Affichage virtuel réglé sur", "Virtual interface (normal)": "Interface virtuelle (normale)", + "Virtual whiteboard for sketching hand-drawn like diagrams": "Tableau blanc virtuel pour dessiner à la main comme des diagrammes", "Virtualization": "Virtualisation", "Visit https://osx-proxmox.com for more information.": "Visitez https://osx-proxmox.com pour plus d'informations.", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:": "Visitez le site Web pour découvrir plus de scripts, rester informé des dernières mises à jour et soutenir le projet :", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE": "Visitez le site Web pour découvrir plus de scripts, rester informé des dernières mises à jour et soutenir le projet :\n\nhttps://community-scripts.github.io/ProxmoxVE", + "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies.": "Vivaldi est un logiciel libre norvégien, un navigateur web multiplateforme avec un client de messagerie intégré développé par Vivaldi Technologies.", + "Volume configuration cancelled": "Configuration du volume annulée", + "Volume options are not yet supported": "Les options de volume ne sont pas encore prises en charge", + "Volume size in GB": "Volume en GB", + "Volumes attached": "Volumes joints", + "Volumes prepared for the first start:": "Volumes préparés pour le premier départ:", + "Volumes shared between services are not yet supported": "Les volumes partagés entre les services ne sont pas encore pris en charge", + "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code.": "Vscodium-web est une distribution binaire librement autorisée par la communauté du composant web hôte distant de l'éditeur VS Code de Microsoft.", "Vulnerability detection": "Détection de vulnérabilité", "WARNING": "AVERTISSEMENT", "WARNING — This backup contains paths that are risky to restore on a running system:": "AVERTISSEMENT — Cette sauvegarde contient des chemins dont la restauration est risquée sur un système en cours d'exécution :", @@ -4912,15 +6757,41 @@ "WARNING: You are about to remove this Proxmox storage:": "AVERTISSEMENT : Vous êtes sur le point de supprimer ce stockage Proxmox :", "WARNING: You are about to remove this disk mount:": "AVERTISSEMENT : vous êtes sur le point de supprimer ce support de disque :", "WARNING: this will ERASE EVERYTHING on the disk.": "ATTENTION : cela effacera TOUT ce qui se trouve sur le disque.", + "WEB UI to manage WireGuard VPN.": "UI WEB pour gérer WireGuard VPN.", "WILL BE PERMANENTLY ERASED.": "SERA définitivement effacé.", + "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency.": "WPS Office est une suite de bureau complète légère et riche en fonctionnalités avec une grande compatibilité. Comme logiciel de bureau pratique et professionnel, WPS Office vous permet de modifier des fichiers dans Writer, Presentation, Spreadsheet et PDF pour améliorer votre efficacité de travail.", "Wait for each node to complete before starting next": "Attendez que chaque nœud soit terminé avant de commencer le suivant", + "Waiting for Home Assistant OS...": "En attente de Home Assistant OS...", + "Waiting for the FUSE mount:": "En attente du montage FUSE :", + "Waiting for the application to respond...": "Attendre que l'application réponde...", + "Waiting for the initial Jellyfin configuration...": "En attente de la configuration initiale Jellyfin...", + "Waiting for the network address...": "En attendant l'adresse du réseau...", + "Waiting for the password of the application...": "En attendant le mot de passe de l'application...", + "Waiting for the temporary password...": "En attendant le mot de passe temporaire...", "Warning": "Avertissement", "Warning: Auth key should start with 'tskey-'": "Attention : la clé d'authentification doit commencer par \"tskey-\"", "Warning: Disk Images on CIFS": "Avertissement : Images disque sur CIFS", "Warning: Limited PCI Reset Support": "Avertissement : prise en charge limitée de la réinitialisation PCI", "Warning: both VMs have autostart enabled (onboot=1).": "Attention : les deux machines virtuelles ont le démarrage automatique activé (onboot=1).", "Warnings": "Avertissements", + "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents.": "WeKnora est un cadre alimenté par LLM conçu pour la compréhension approfondie des documents et la récupération sémantique, en particulier pour la manipulation des documents hétérogènes complex.", + "Web UI": "UI Web", + "Web UI 1": "Aide-mémoire sur le Web 1", + "Web UI 2": "UI Web 2", + "Web UI password": "Mot de passe de l'interface utilisateur Web", + "Web UI user": "Utilisateur d'interface utilisateur Web", + "Web access": "Accès au Web", + "Web address of the AdGuard Home that receives the settings (e.g. http://192.168.1.3)": "Adresse Web du AdGuard Home qui reçoit les paramètres (p. ex. http://192.168.1.3)", + "Web address of the main AdGuard Home, whose settings are copied (e.g. http://192.168.1.2)": "Adresse Web du principal AdGuard Home, dont les paramètres sont copiés (par exemple http://192.168.1.2)", + "Web interface to manage devices running Tasmota firmware.": "Interface Web pour gérer les appareils utilisant le firmware Tasmota.", + "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes).": "WebCord peut être résumé comme un paquet de durcissements de sécurité et de confidentialité, les fonctionnalités Discord réimplémentations, Electron / Chromium / Discord bugs workarounds, les feuilles de style, les pages internes et la page https://discord.com enveloppée, conçue pour se conformer à ToS autant qu'il est possible (ou cacher les changements qui pourraient la violer des yeux de Discord).", + "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels.": "Webgrabplus est un accrocheur différentiel multisite xmltv egg. Il recueille les données du guide TV-programme à partir de sites sélectionnés pour vos chaînes préférées.", + "Webservers & Proxies": "Serveurs Web & Proxies", "Website": "Site web", + "Webstation is a web native emulation focused LXQt desktop based on Ubuntu.": "Webstation est un ordinateur de bureau LXQt basé sur Ubuntu.", + "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser.": "Webtop - conteneurs basés sur Alpine, Ubuntu, Fedora et Arch contenant des environnements de bureau complets dans des saveurs officiellement pris en charge accessibles via n'importe quel navigateur Web moderne.", + "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent.": "Weixin (WeChat) est une application de messagerie instantanée, de médias sociaux et de paiement mobile développée par Tencent.", + "What cannot be translated:": "Ce qui ne peut être traduit:", "What do you want to do?": "Qu'est-ce que vous voulez faire?", "What would you like to do?": "Qu'aimeriez-vous faire ?", "When asked to select a disk, click Load Driver and load the VirtIO drivers.": "Lorsqu'on vous demande de sélectionner un disque, cliquez sur Charger le pilote et chargez les pilotes VirtIO.", @@ -4932,28 +6803,46 @@ "Where do you want to mount the Samba share?": "Où souhaitez-vous monter le partage Samba ?", "Where is the OVA/OVF file located?": "Où se trouve le fichier OVA/OVF ?", "Where to mount inside container?": "Où monter à l’intérieur du conteneur ?", + "Where to store": "Où conserver", "While the server allows guest listing, no shares are actually accessible without authentication.": "Bien que le serveur autorise la liste des invités, aucun partage n'est réellement accessible sans authentification.", + "Wikijs A modern, lightweight and powerful wiki app built on NodeJS.": "Wikijs Une application wiki moderne, légère et puissante construite sur NodeJS.", "Will be configured now": "Sera configuré maintenant", "Windows Installation Options": "Options d'installation de Windows", "Windows path:": "Chemin Windows :", + "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles.": "WineGUI est un gestionnaire de vin convivial qui fournit une interface graphique pour créer et gérer des bouteilles de vin.", "Wipe all — erase partitions + metadata": "Effacer tout – effacer les partitions + les métadonnées", "Wipe all — remove partitions + metadata": "Effacer tout – supprimer les partitions + les métadonnées", "Wipe old signatures and partition table (DESTRUCTIVE):": "Effacez les anciennes signatures et la table de partition (DESTRUCTIVE) :", "Wiping existing partition table...": "Effacement de la table de partition existante...", "Wiping partitions and metadata...": "Effacement des partitions et des métadonnées...", + "WireGuard Easy web interface": "Interface web WireGuard Easy", + "WireGuard® is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry.": "WireGuard® est un VPN extrêmement simple mais moderne qui utilise une cryptographie ultramoderne. Il vise à être plus rapide, plus simple, plus maigre et plus utile que IPsec, tout en évitant les maux de tête massifs. Il a l'intention d'être beaucoup plus performant que OpenVPN. WireGuard est conçu comme un VPN à usage général pour fonctionner sur des interfaces intégrées et des super ordinateurs, adaptés à de nombreuses circonstances différentes. Initialement sorti pour le noyau Linux, il est désormais multiplateforme (Windows, macOS, BSD, iOS, Android) et largement déployable. Il est actuellement en développement, mais il pourrait déjà être considéré comme la solution VPN la plus sûre, la plus facile à utiliser et la plus simple de l'industrie.", "Wired NICs in backup missing on target:": "Cartes réseau filaires dans la sauvegarde manquantes sur la cible :", + "Wireshark is the world’s foremost and widely-used network protocol analyzer. It lets you see what’s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998.": "Wireshark est l'analyseur de protocole réseau le plus utilisé au monde. Il vous permet de voir ce qui se passe sur votre réseau au niveau microscopique et est la norme de facto (et souvent de jure) dans de nombreuses entreprises commerciales et sans but lucratif, agences gouvernementales et établissements d'enseignement. Le développement de Wireshark prospère grâce aux contributions volontaires d'experts en réseautage dans le monde entier et est la suite d'un projet lancé par Gerald Combs en 1998.", + "With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopped.": "Avec la validation dns, la variable DNSPLUGIN nomme le plugin fournisseur. L'installation avancée le demande; sinon ajouter la ligne lxc.environment. durée d'exécution: DNSPLUGIN= à /etc/pve/lxc/.conf avec le conteneur arrêté.", + "With dns validation, write the provider credentials in /config/dns-conf/.ini inside the container and restart it.": "Avec la validation dns, écrivez le fournisseur credentials dans /config/dns-conf/.ini à l'intérieur du conteneur et redémarrez-le.", + "With http validation, port 80 of the router must be forwarded to port 80 of this container.": "Avec la validation http, le port 80 du routeur doit être envoyé au port 80 de ce conteneur.", "With warnings": "Avec des avertissements", "Without Function Level Reset (FLR), passthrough is not considered reliable": "Sans réinitialisation du niveau de fonction (FLR), le relais n'est pas considéré comme fiable", "Without a usable reset path, passthrough reliability is poor and VM": "Sans chemin de réinitialisation utilisable, la fiabilité du relais est médiocre et la VM", + "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom.": "Wolfenstein: Blade of Agony est un jeu de tir inspiré par Wolfenstein et Doom.", + "Workflow automation tool": "Outil d'automatisation du flux de travail", "Working directory:": "Répertoire de travail :", "Works with LVM, ZFS, and BTRFS storage types": "Fonctionne avec les types de stockage LVM, ZFS et BTRFS", + "Worth knowing before installing it:": "Il faut savoir avant de l'installer :", "Would you like to continue in passthrough-only mode? The libedgetpu APT install will be skipped, the Coral device will still be visible inside the container (e.g. /dev/apex_0), and you can install the runtime yourself or use an app container that bundles it (e.g. the Frigate Docker image).": "Souhaitez-vous continuer en mode passthrough uniquement ? L'installation de libedgetpu APT sera ignorée, le périphérique Coral sera toujours visible à l'intérieur du conteneur (par exemple /dev/apex_0) et vous pourrez installer le runtime vous-même ou utiliser un conteneur d'application qui le regroupe (par exemple l'image Frigate Docker).", "Would you like to see the current": "Souhaitez-vous voir le courant", "Write access confirmed for user:": "Accès en écriture confirmé pour l'utilisateur :", "Write access confirmed.": "Accès en écriture confirmé.", "Write access test FAILED for user:": "ÉCHEC du test d'accès en écriture pour l'utilisateur :", "Write access verified for user:": "Accès en écriture vérifié pour l'utilisateur :", + "Write the value it produces instead.": "Écrivez plutôt la valeur qu'elle produit.", + "Wrong SHA-256 in": "Mauvais SHA-256 en", + "Wrong inherited registry lock": "Mauvais verrouillage du registre hérité", "Wrong passphrase": "Mauvaise phrase secrète", + "Wrong size in": "Mauvaise taille en", + "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support.": "Xbackbone est un gestionnaire de fichiers PHP simple, autonome et léger qui prend en charge l'outil de partage instantané ShareX et *NIX systèmes. Il prend en charge le téléchargement et l'affichage d'images, GIF, vidéo, code, texte formaté, et le téléchargement et le téléchargement de fichiers. Disposez également d'une interface utilisateur web avec gestion multi-utilisateurs, historique des téléchargements passés et support de recherche.", + "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS.": "Yaak est un client API de bureau pour l'organisation et l'exécution des requêtes REST, GraphQL et gRPC. Il est construit avec Tauri, Rust et ReactJS.", "Yes": "Oui", "Yes, upload": "Oui, télécharger", "Yes: set a recovery passphrase now; the encrypted key envelope is uploaded with every backup.": "Oui : définissez une phrase secrète de récupération maintenant ;l'enveloppe de clé cryptée est téléchargée à chaque sauvegarde.", @@ -4984,6 +6873,9 @@ "You should now be able to access the Proxmox web interface.": "Vous devriez maintenant pouvoir accéder à l'interface Web de Proxmox.", "You will need a Tailscale auth key from: https://login.tailscale.com/admin/settings/keys": "Vous aurez besoin d'une clé d'authentification Tailscale provenant de : https://login.tailscale.com/admin/settings/keys", "Your Coral USB device and its runtime (libedgetpu1) will NOT be affected.": "Votre périphérique USB Coral et son environnement d'exécution (libedgetpu1) ne seront PAS affectés.", + "Your machine learning Env work with Jupyter Lab": "Votre machine learning Env travaille avec Jupyter Lab", + "Your next YouTube media manager": "Votre prochain gestionnaire de médias YouTube", + "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics.": "Your_spotify est une application auto-hôte qui suit ce que vous écoutez et vous offre un tableau de bord pour explorer les statistiques à ce sujet! Il est composé d'un serveur web qui interroge l'API Spotify de temps en temps et d'une application web sur laquelle vous pouvez explorer vos statistiques.", "ZFS ARC config removed (kernel defaults will apply on reboot)": "Configuration ZFS ARC supprimée (les valeurs par défaut du noyau s'appliqueront au redémarrage)", "ZFS ARC maximum configured:": "ZFS ARC maximum configuré :", "ZFS ARC optimization completed": "Optimisation ZFS ARC terminée", @@ -5011,9 +6903,17 @@ "ZFS storage added successfully to Proxmox!": "Stockage ZFS ajouté avec succès à Proxmox !", "ZFS tools not found. Install zfsutils-linux and retry.": "Outils ZFS introuvables. Installez zfsutils-linux et réessayez.", "ZFS:": "ZFS :", + "ZNC web interface": "Interface web ZNC", + "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design.": "Zen Browser est un navigateur libre et open source fork de Mozilla Firefox avec un accent sur la confidentialité, la personnalisation et la conception.", "Zero all data — partition table preserved, data wiped": "Zéro toutes les données : table de partition préservée, données effacées", "Zero all data — partition table preserved": "Zéro toutes les données - table de partition préservée", "Zeroing partition": "Remise à zéro de la partition", + "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC.": "Znc est un videur réseau IRC ou BNC. Il peut détacher le client du serveur IRC réel, ainsi que des canaux sélectionnés. Plusieurs clients de différents emplacements peuvent se connecter simultanément à un seul compte ZNC et apparaissent donc sous le même surnom sur IRC.", + "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research.": "Zotero est un outil gratuit et facile à utiliser pour vous aider à collecter, organiser, annoter, citer et partager la recherche.", + "a device it asks for cannot be translated:": "un appareil qu'il demande ne peut pas être traduit:", + "a value is required": "une valeur est required", + "aMule WebUI (password only, no username)": "aMule WebUI (mot de passe seulement, aucun nom d'utilisateur)", + "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule.": "aMule est un client multiplateforme pour le réseau de partage de fichiers ED2K et basé sur le client eMule de Windows. Le aMule a commencé en août 2003 en tant que fork de xMule, qui est un fork de lMule.", "active VF(s)": "FV active(s)", "active VFs": "VF actives", "active Virtual Functions. Changing its driver binding would destroy every VF.": "Fonctions virtuelles actives. Changer la liaison de son pilote détruirait chaque VF.", @@ -5035,20 +6935,24 @@ "apex group still has members; left in place:": "le groupe faîtier compte toujours des membres ; laissé en place :", "apex kernel module not loaded on host. Run \"Install Coral on Host\" first or the container will not see /dev/apex_0.": "Le module du noyau apex n'est pas chargé sur l'hôte. Exécutez d'abord \"Installer Coral sur l'hôte\" ou le conteneur ne verra pas /dev/apex_0.", "appears to be part of a": "semble faire partie d'un", + "apply requires the OCI archive of the resolved image": "appliquer requires l'archive OCI de l'image résolue", "applying minimal banner patch": "application d'un patch de bannière minimal", "apt cache refreshed.": "cache apt actualisé.", "apt-get exited": "apt-sortir", "apt-get update returned warnings. Continuing anyway; check": "apt-get update a renvoyé des avertissements. On continue quand même ; vérifier", "as": "comme", + "assembling": "assemblage", "automatically. Install it manually inside the container.": "automatiquement. Installez-le manuellement à l'intérieur du conteneur.", "automatically. Reboot LXC to fully release.": "automatiquement. Redémarrez LXC pour le libérer complètement.", "available for LXC bind-mounts via 'LXC Mount Manager'": "disponible pour les montages liés LXC via 'LXC Mount Manager'", "available in this same GPU and TPU menu.": "disponible dans ce même menu GPU et TPU.", "backup at /etc/fstab.proxmenux.bak": "sauvegarde sur /etc/fstab.proxmenux.bak", "ban": "interdire", + "belongs to another OCI installation": "appartient à une autre installation OCI", "blocking issue(s).": "problème(s) bloquant(s).", "btrfs — Proxmox dir storage (snapshots, compression)": "btrfs — Stockage du répertoire Proxmox (instantanés, compression)", "btrfs — snapshots and compression": "btrfs — instantanés et compression", + "budge is an open source 'budgeting with envelopes' personal finance app.": "budge est une application de financement personnel \"budge avec enveloppes\".", "builds against kernel": "construit contre le noyau", "but it does not match the one used to create the backup. Replace it with the correct keyfile from the source host and retry.": "mais il ne correspond pas à celui utilisé pour créer la sauvegarde. Remplacez-le par le fichier de clés correct de l'hôte source et réessayez.", "bytes": "octets", @@ -5056,29 +6960,52 @@ "chmod 1777 + setfacl o::rwx (applied on the NFS share from this host)": "chmod 1777 + setfacl o::rwx (appliqué sur le partage NFS de cet hôte)", "chmod failed — NFS server may be restricting changes from root": "chmod a échoué — Le serveur NFS restreint peut-être les modifications depuis la racine", "chown/chmod failed — likely unprivileged CT against host bind mount. Falling back to ACL.": "chown/chmod a échoué - CT probablement non privilégié contre le montage de liaison de l'hôte. Revenir à ACL.", + "containers": "contenants", + "containers of": "contenants", "content:": "contenu:", + "copyparty web interface": "Interface web copyparty", "could not be compiled for kernel": "n'a pas pu être compilé pour le noyau", + "could not validate NVIDIA; exit code": "n'a pas pu valider NVIDIA; code de sortie", + "cpuunits must be between 8 and 10000": "cpuunits doivent être compris entre 8 et 10000", + "custom": "personnalisé", + "custom dependency commands are not yet supported": "commandes de dépendance personnalisées ne sont pas encore prises en charge", + "custom path(s) saved.": "chemin(s) personnalisé(s) enregistré(s).", + "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them.": "darktable est une application de travail de photographie open source et développeur brut. Un tableau lumineux virtuel et sombre pour les photographes. Il gère vos négatifs numériques dans une base de données, vous permet de les voir à travers un tableau lumineux zoomable et vous permet de développer des images brutes et de les améliorer.", + "ddclient starts with the example configuration and updates nothing yet. Write your provider, login and domains in /config/ddclient.conf inside the container, then restart it.": "ddclient commence par la configuration d'exemple et ne met à jour rien encore. Écrivez votre fournisseur, login et domaines dans /config/ddclient.conf dans le conteneur, puis redémarrez-le.", "default": "défaut", "delete the credentials file (if any)": "supprimer le fichier d'informations d'identification (le cas échéant)", "delete the matching line from /etc/fstab": "supprimez la ligne correspondante de /etc/fstab", "descriptor + VMDK files": "descripteur + fichiers VMDK", + "device(s) added to VM": "périphérique(s) ajouté(s) à la VM", "devices": "appareils", + "devices (dynamic runtime)": "dispositifs (temps d'exécution dynamique)", "did not become ready. Skipping.": "n'est pas devenu prêt. Saut.", + "digiKam: Professional Photo Management with the Power of Open Source": "digiKam: Gestion de photos professionnelles avec la puissance de l'Open Source", "disk(s) added to CT": "disque(s) ajouté(s) à CT", "disk(s) added to VM": "disque(s) ajouté(s) à la VM", + "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems.": "diskover est un indexeur de système de fichiers open source qui utilise Elasticsearch pour indexer et gérer les données dans des systèmes de stockage hétérogènes.", "disks present": "disques présents", "dkms autoinstall did not activate:": "l'installation automatique de dkms n'a pas été activée :", "dkms.conf generated.": "dkms.conf généré.", + "docker run command": "Commande d'exécution docker", + "docker run command of the application": "docker commande d'exécution de l'application", "does not exist on this host. Path not added.": "n'existe pas sur cet hôte. Chemin non ajouté.", "does not exist. Exiting.": "n'existe pas. Sortir.", + "doplarr_rs starts from the example configuration and connects to nothing. Write the token of your Discord bot in discord_token in /config/config.toml inside the container.": "doplarr_rs commence à partir de la configuration d'exemple et se connecte à rien. Écrivez le jeton de votre bot Discord dans discord token dans /config/config.toml à l'intérieur du conteneur.", + "downloaded Compose file": "Fichier Compose téléchargé", "dpkg still reports unfinished package work; review": "dpkg signale toujours le travail inachevé sur les packages ;revoir", + "driver components": "Composants du conducteur", "driver:": "pilote:", + "e.g.": "Par exemple", + "empty = generate": "vide = générer", "exFAT (portable: Windows/Linux/macOS)": "exFAT (portable : Windows/Linux/macOS)", "exFAT tools installed successfully.": "Outils exFAT installés avec succès.", "ext4 — Proxmox dir storage (recommended)": "ext4 — Stockage du répertoire Proxmox (recommandé)", "ext4 — recommended, most compatible": "ext4 — recommandé, le plus compatible", "fail2ban-client could not communicate with the server": "fail2ban-client n'a pas pu communiquer avec le serveur", "fail2ban-client successfully communicated with the server": "fail2ban-client a communiqué avec succès avec le serveur", + "failed": "échoué", + "failed with exit code": "échoué avec le code de sortie", "failed:": "échoué:", "feranick fork unreachable. Falling back to google/gasket-driver...": "Le fork feranick est inaccessible. Retour à google/gasket-driver...", "feranick/gasket-driver cloned (actively maintained, kernel 6.12+ ready).": "feranick/gasket-driver cloné (maintenu activement, noyau 6.12+ prêt).", @@ -5092,6 +7019,7 @@ "for this policy and may fail after first use or on subsequent VM starts.": "pour cette stratégie et peut échouer après la première utilisation ou lors des démarrages ultérieurs de la VM.", "formatted as": "formaté comme", "found": "trouvé", + "free": "gratuit", "from Proxmox web interface (you will be asked)": "depuis l'interface web de Proxmox (il vous sera demandé)", "from container": "du conteneur", "from the GPUs and Coral-TPU menu first, then run this option again.": "à partir du menu GPU et Coral-TPU, puis réexécutez cette option.", @@ -5102,6 +7030,7 @@ "gasket-dkms has been fully removed from this system.": "gasket-dkms a été entièrement supprimé de ce système.", "gasket-dkms is still reported by dpkg in state:": "gasket-dkms est toujours signalé par dpkg dans l'état :", "gawk installed": "bouche bée installé", + "go2rtc WebUI": "WebUI go2rtc", "google/gasket-driver cloned (fallback — will apply local patches).": "google/gasket-driver cloné (repli – appliquera les correctifs locaux).", "gpg not found; trying apt-key fallback": "gpg introuvable ; essayer la solution de secours apt-key", "gzip replaced with pigz wrapper successfully": "gzip remplacé avec succès par le wrapper pigz", @@ -5109,10 +7038,14 @@ "has a different MAC than the backup — update any DHCP static reservation": "a un MAC différent de celui de la sauvegarde – mettre à jour toute réservation statique DHCP", "has a new MAC": "a un nouveau MAC", "has only": "n'a que", + "health and persistence profile not yet defined": "profil de santé et de persistance non encore défini", + "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers.": "hiSHtory est une meilleure histoire de coquille. Il stocke l'historique de votre shell en contexte (dans quel répertoire vous avez lancé la commande, qu'elle ait réussi ou échoué, combien de temps cela a pris, etc.). Ceci est stocké localement et de bout en bout crypté pour la synchronisation à tous vos autres ordinateurs.", + "host directory": "répertoire hôte", "host fstab only (not registered as Proxmox storage)": "hôte fstab uniquement (non enregistré comme stockage Proxmox)", "hostpci entries for all IOMMU group devices": "entrées hostpci pour tous les périphériques du groupe IOMMU", "hostpci entries for selected GPU functions (full IOMMU group will be enforced after reboot)": "Entrées hostpci pour les fonctions GPU sélectionnées (le groupe IOMMU complet sera appliqué après le redémarrage)", "hour(s)": "heures)", + "https if the image serves TLS": "https si l'image sert TLS", "iSCSI Content Type": "Type de contenu iSCSI", "iSCSI Daemon (iscsid): RUNNING": "Démon iSCSI (iscsid) : EN COURS D'EXÉCUTION", "iSCSI Daemon (iscsid): STOPPED": "Démon iSCSI (iscsid) : ARRÊTÉ", @@ -5129,16 +7062,23 @@ "iSCSI storage provides raw block devices for VM disk images.": "Le stockage iSCSI fournit des périphériques de bloc bruts pour les images disque de VM.", "iSCSI tools installed": "Outils iSCSI installés", "iftop usage": "utilisation de l'iftop", + "image cache on": "cache d'image sur", + "image itself": "image elle-même", "imported:": "importé:", "in CT": "en CT", + "in backups": "dans les sauvegardes", + "incompatible qBittorrent schema": "Schéma qBittorrent incompatible", + "individual template is blocked": "modèle individuel est bloqué", "initramfs updated": "initramfs mis à jour", "initramfs updated.": "initramfs mis à jour.", + "installed": "installé", "installed but command not immediately available": "installé mais la commande n'est pas immédiatement disponible", "installed correctly and available": "installé correctement et disponible", "installed in CT": "installé en CT", "installed inside CT": "installé à l'intérieur du CT", "installed successfully.": "installé avec succès.", "installed.": "installé.", + "installing": "installation", "intel-gpu-tools installed successfully": "Intel-Gpu-Tools installé avec succès", "intel-gpu-tools is already installed:": "intel-gpu-tools est déjà installé :", "intel-gpu-tools is up to date": "Intel-Gpu-Tools est à jour", @@ -5169,7 +7109,11 @@ "is not configured as machine type q35.": "n'est pas configuré comme type de machine q35.", "is not in the patch.sh supported list. The patch may no-op or fail; review keylase/nvidia-patch README before continuing.": "n'est pas dans la liste des patch.sh pris en charge. Le correctif peut ne pas fonctionner ou échouer ; consultez le fichier README keylase/nvidia-patch avant de continuer.", "is not supported by the official Google libedgetpu APT repository.": "n'est pas pris en charge par le référentiel officiel Google libedgetpu APT.", + "is one of the": "est l'un des", "is referenced in the following stopped VM(s)/CT(s):": "est référencé dans les VM/CT arrêtés suivants :", + "it asks for the network of the host; the container gets its own address instead": "il demande le réseau de l'hôte; le conteneur obtient sa propre adresse à la place", + "it publishes no other architecture": "il ne publie aucune autre architecture", + "it uses the Compose option": "il utilise l'option Composer", "journald MaxLevelStore is adequate for auth logging": "journald MaxLevelStore est adéquat pour la journalisation d'authentification", "journald drop-in created: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf": "Journald drop-in créé : /etc/systemd/journald.conf.d/proxmenux-loglevel.conf", "journald log level restored": "niveau de journalisation restauré", @@ -5193,26 +7137,41 @@ "kexec-tools installed successfully": "kexec-tools installé avec succès", "kexec-tools is already installed": "kexec-tools est déjà installé", "kexec-tools is not installed or already removed.": "kexec-tools n'est pas installé ou déjà supprimé.", + "layers": "couches", "legacy .link file(s) to the ProxMenux-managed format": "les anciens fichiers .link au format géré par ProxMenux", "log2ram completely removed from system": "log2ram complètement supprimé du système", "manually inside the container before starting it.": "manuellement à l'intérieur du conteneur avant de le démarrer.", "manually inside the container.": "manuellement à l'intérieur du conteneur.", "maximum performance": "performances maximales", "may be closed — trying discovery anyway...": "peut être fermé — essayez quand même la découverte...", + "melonDS aims at providing fast and accurate Nintendo DS emulation.": "melonDS vise à fournir une émulation rapide et accurate Nintendo DS.", + "members:": "membres:", + "minimum": "minimum", "missing": "manquant", "mkfs.btrfs not found. Install btrfs-progs and retry.": "mkfs.btrfs introuvable. Installez btrfs-progs et réessayez.", "more": "plus", + "motionEye web interface": "Interface web motionEye", "mount.cifs command not found after installation.": "Commande mount.cifs introuvable après l'installation.", "mount.nfs command not found after installation.": "Commande mount.nfs introuvable après l'installation.", + "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone.": "mstream est un serveur de streaming de musique personnel. Vous pouvez utiliser mStream pour diffuser votre musique depuis votre ordinateur personnel vers n'importe quel appareil, n'importe où. Il existe des applications mobiles disponibles pour Android et iPhone.", + "must contain a valid numeric UID for the GPU": "doit contenir un UID numérique valide pour le GPU", + "needed": "nécessaire", + "needs a privileged LXC": "a besoin d'un LXC privilégié", + "needs a relaxed AppArmor or seccomp profile": "nécessite un profil AppArmor ou seccomp détendu", + "needs stack review": "examen de la pile des besoins", "never": "jamais", + "next free": "suivant gratuit", + "next free block": "prochain bloc libre", "nftables not available - using iptables ban action": "nftables non disponible - utilisation de l'action d'interdiction iptables", "no": "non", "no (kdf=none, not needed)": "non (kdf=aucun, pas nécessaire)", "no (no escrow blob — set a recovery passphrase to enable recovery)": "non (pas de blob de dépôt fiduciaire – définissez une phrase secrète de récupération pour activer la récupération)", + "no declarative value": "aucune valeur déclarative", "no passphrase": "pas de phrase secrète", "no password": "pas de mot de passe", "no_root_squash": "no_root_squash", "non-ProxMenux .tar archive(s) in this path": "Archive(s) .tar non-ProxMenux dans ce chemin", + "not available yet": "non encore disponible", "not found.": "pas trouvé.", "not installed": "non installé", "not reliable on this hardware due to the following limitations": "non fiable sur ce matériel en raison des limitations suivantes", @@ -5229,27 +7188,39 @@ "of free disk space.": "d'espace disque libre.", "older firmware may increase passthrough instability": "un firmware plus ancien peut augmenter l'instabilité du relais", "oldest driver offered:": "le pilote le plus ancien proposé :", + "on": "le", "on SSD/NVMe pools that support discard": "sur les pools SSD/NVMe prenant en charge la suppression", + "one of its services declares no image": "un de ses services déclare aucune image", + "one of its services is not written as a service": "un de ses services n'est pas écrit comme un service", "openssl encryption failed.": "Le cryptage openssl a échoué.", "openssl is not installed — cannot create recovery copy. Install openssl and retry.": "openssl n'est pas installé - impossible de créer une copie de récupération. Installez openssl et réessayez.", + "optional": "facultatif", + "optional dependencies are not yet supported": "les dépendances facultatives ne sont pas encore prises en charge", "or format it manually using external tools.": "ou formatez-le manuellement à l’aide d’outils externes.", + "or none": "ou aucun", "or use the ProxMenux LXC Mount Manager.": "ou utilisez le gestionnaire de montage ProxMenux LXC.", "orphan iface lines, no impact on restore": "lignes iface orphelines, aucun impact sur la restauration", "other .tar archive(s) — not ProxMenux host backups (e.g. PVE vzdump or unrelated tarballs).": "autres archives .tar - pas les sauvegardes de l'hôte ProxMenux (par exemple, vzdump PVE ou archives tar sans rapport).", "packages (this may take a few minutes)...": "packages (cela peut prendre quelques minutes)...", + "packages.": "paquets.", "parent PF:": "PF parent :", "partition(s). Partition table preserved.": "partition(s). Table de partition conservée.", + "pasted Compose file": "fichier Compose collé", "paths for next boot (/etc/pve, guests, drivers, ...)": "chemins pour le prochain démarrage (/etc/pve, invités, pilotes, ...)", "pct exec authorization failed": "échec de l'autorisation d'exécution PCT", "pct push failed. Check log:": "La poussée PCT a échoué. Journal de vérification :", "pending (reboot required to enumerate full group)": "en attente (redémarrage requis pour énumérer le groupe complet)", + "phpMyAdmin is installed with arbitrary server connections enabled: the login page has a Server field where the address of the MySQL or MariaDB server is entered, together with its user and password.": "phpMyAdmin est installé avec des connexions de serveur arbitraires activées : la page de connexion a un champ Serveur où l'adresse du serveur MySQL ou MariaDB est saisie, ainsi que son utilisateur et son mot de passe.", "pigz configuration completed": "configuration pigz terminée", "pigz enabled in vzdump configuration": "pigz activé dans la configuration de vzdump", "pigz installed successfully": "pigz installé avec succès", "pigz removed": "cochon supprimé", "pigz wrapper script created": "Script wrapper pigz créé", + "playit.gg has to claim this agent before it forwards anything. The agent prints a one-time claim link on the container console and keeps it there until the link is opened.": "playit.gg doit réclamer cet agent avant qu'il n'avance quoi que ce soit. L'agent imprime un lien de réclamation unique sur la console du conteneur et le garde là jusqu'à ce que le lien soit ouvert.", "port": "port", "portmapper/rpcbind has been disabled": "portmapper/rpcbind a été désactivé", + "private network assigned automatically": "réseau privé attribué automatiquement", + "privileged LXC": "privilégié LXC", "proxmox-backup-client reported:": "proxmox-backup-client a signalé :", "proxmox-boot-tool refreshed": "proxmox-boot-tool actualisé", "pve-enterprise.list update skipped (no change)": "Mise à jour de pve-enterprise.list ignorée (aucun changement)", @@ -5261,10 +7232,22 @@ "pvesm not found.": "pvesm introuvable.", "pvesm path failed, trying manual detection...": "Échec du chemin pvesm, tentative de détection manuelle...", "pvesm status failed": "le statut pvesm a échoué", + "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web.": "pyLoad est un gestionnaire de téléchargement gratuit et Open Source écrit en Python et conçu pour être extrêmement léger, facilement extensible et entièrement gérable via le web.", + "pyLoad web interface": "PyLoad interface web", + "qBittorrent WebUI password (user: admin)": "qBittorrent Mot de passe WebUI (utilisateur: admin)", + "qBittorrent already has a configuration; it is not overwritten": "qBittorrent a déjà une configuration; elle n'est pas écrasée", + "qBittorrent configured": "MPXTERM000 configuré", + "qBittorrent did not apply the category:": "qBittorrent n'a pas appliqué la catégorie :", + "qBittorrent did not apply the download paths": "qBittorrent n'a pas appliqué les chemins de téléchargement", + "qBittorrent requires a non-empty password": "qBittorrent requires un mot de passe non vide", + "qBittorrent: authenticated access to the preferences could not be verified": "qBittorrent: l'accès authentifié aux préférences n'a pas pu être vérifié", + "qBittorrent: invalid login response or missing session cookie": "qBittorrent: réponse de connexion invalide ou cookie de session manquant", "raw USB disk — no filesystem (will be FORMATTED)": "disque USB brut — pas de système de fichiers (sera FORMATÉ)", + "read-only": "en lecture seule", "reboot-quick alias added": "alias de redémarrage rapide ajouté", "reboot-quick alias is already configured": "l'alias de redémarrage rapide est déjà configuré", "recommended": "recommandé", + "recovering": "récupération", "remapped users": "utilisateurs remappés", "remove the (now-empty) directory if possible": "supprimez le répertoire (maintenant vide) si possible", "removed from Proxmox": "supprimé de Proxmox", @@ -5280,11 +7263,14 @@ "rpcbind could not be disabled completely": "rpcbind n'a pas pu être complètement désactivé", "rpcbind service and socket have been disabled and stopped": "le service et le socket rpcbind ont été désactivés et arrêtés", "rpcbind units were not found; no changes were made": "les unités rpcbind n'ont pas été trouvées ;aucun changement n'a été apporté", + "rsnapshot starts with the default configuration, which backs up /data into /.snapshots. Edit /config/rsnapshot.conf inside the container to set your own backup points, snapshot root and retention intervals.": "rsnapshot commence par la configuration par défaut, qui sauvegarde /data dans /.snapshots. Modifier /config/rsnapshot.conf à l'intérieur du conteneur pour définir vos propres points de sauvegarde, la racine d'instantané et les intervalles de rétention.", "running": "en cours d'exécution", + "runs in": "cours d'eau", "safe paths now (configs, packages, /etc, /root, ...)": "chemins sécurisés maintenant (configurations, packages, /etc, /root, ...)", "same MAC": "même MAC", "seconds (default)": "secondes (par défaut)", "see log:": "voir le journal :", + "selected by default": "sélectionné par défaut", "selected path(s):": "chemin(s) sélectionné(s) :", "server": "serveur", "server IP or hostname:": "IP du serveur ou nom d'hôte :", @@ -5292,6 +7278,7 @@ "servers found on the network.": "serveurs trouvés sur le réseau.", "servers found.": "serveurs trouvés.", "sha256sum not found. Cannot verify Borg binary.": "somme sha256 introuvable. Impossible de vérifier le binaire Borg.", + "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++.": "shadPS4 est un émulateur PlayStation 4 pour Windows, Linux et macOS écrit en C++.", "showmount command is not working properly.": "La commande showmount ne fonctionne pas correctement.", "showmount command not found after installation.": "Commande showmount introuvable après l'installation.", "single portable archive": "archive portable unique", @@ -5307,6 +7294,7 @@ "started successfully.": "démarré avec succès.", "started.": "commencé.", "startup/restart errors are likely.": "des erreurs de démarrage/redémarrage sont probables.", + "staticfiles volume size in GB": "taille du volume des fichiers statiques en GB", "stop source VM first": "arrêter d'abord la VM source", "stopped": "arrêté", "storage yet.": "stockage pour le moment.", @@ -5316,9 +7304,16 @@ "suggested:": "suggéré:", "switch_gpu_mode.sh was not found.": "switch_gpu_mode.sh n'a pas été trouvé.", "sysfs ROM dump failed — trying ACPI VFCT table...": "Échec du vidage de la ROM sysfs - tentative de la table ACPI VFCT...", + "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools.": "syslog-ng vous permet de collecter, d'analyser, de classer, de réécrire et de corréler les logs de toute votre infrastructure et de les stocker ou de les acheminer vers des outils d'analyse de log.", "systemctl restart networking failed:": "échec du redémarrage du réseau systemctl :", "systemd OnCalendar expression": "expression systemd OnCalendar", + "the API key was not generated on the first start": "la clé API n'a pas été générée au premier démarrage", + "the container has its own address, so the port Docker published on the host is not needed": "le conteneur a sa propre adresse, donc le port Docker publié sur l'hôte n'est pas nécessaire", + "the qBittorrent schema is not available": "le schéma qBittorrent n'est pas disponible", + "this configuration needs the device": "cette configuration nécessite le périphérique", "this distribution": "cette répartition", + "tmpfs size in MB for": "Tmpfs taille en MB pour", + "tmpfs size too small for": "tmpfs taille trop petite pour", "to": "à", "to CT": "au CT", "to VM": "vers la machine virtuelle", @@ -5327,6 +7322,12 @@ "to sharedfiles group": "au groupe de fichiers partagés", "total": "total", "umount the path if currently mounted": "démonter le chemin s'il est actuellement monté", + "unprivileged LXC": "LXC non privilégié", + "unsupported credential generator": "générateur credential non supporté", + "unsupported dependency condition": "état de dépendance non soutenu", + "unsupported external credential or boolean": "credential ou booléen", + "unsupported variable": "variable non prise en charge", + "updating": "mise à jour", "updating NVIDIA userspace libs": "mise à jour des bibliothèques d'espace utilisateur NVIDIA", "user packages missing — will be installed automatically:": "packages utilisateur manquants – seront installés automatiquement :", "users": "utilisateurs", @@ -5337,12 +7338,19 @@ "vfio-pci IDs configured": "ID vfio-pci configurés", "vfio-pci IDs in /etc/modprobe.d/vfio.conf": "ID vfio-pci dans /etc/modprobe.d/vfio.conf", "vzdump backup speed optimization completed": "Optimisation de la vitesse de sauvegarde de vzdump terminée", + "wallabag builds its links from the address given during the installation. If it does not match the address of the container, edit lxc.environment.runtime: SYMFONY__ENV__DOMAIN_NAME in /etc/pve/lxc/.conf with the container stopped, and start it again.": "wallabag construit ses liens à partir de l'adresse donnée pendant l'installation. S'il ne correspond pas à l'adresse du conteneur, modifier lxc.environnement. temps d'exécution: SYMFONY ENV DOMAIN NAME dans /etc/pve/lxc/.conf avec le conteneur arrêté, et recommencer.", + "wallabag listens on port 80 of the container and stores its data in SQLite.": "wallabag écoute sur le port 80 du conteneur et stocke ses données dans SQLite.", + "wallabag web interface": "Interface web wallabag", "was": "était", "was installed, but the kernel reports:": "a été installé, mais le noyau rapporte :", + "when finished": "à la fin", "will rebind the GPU to vfio-pci on the next reboot, breaking the driver that is about to be installed.": "reliera le GPU à vfio-pci au prochain redémarrage, cassant ainsi le pilote qui est sur le point d'être installé.", "wipefs failed on": "les wipefs ont échoué", "with": "avec", + "with Proxmox": "avec Proxmox", + "with prefix, e.g.": "avec préfixe, par exemple", "with the password you provided.": "Message technique pour Proxmox et l'informatique. Traduisez : avec le mot de passe que vous avez fourni.", + "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems.": "xemu est une application gratuite et open-source qui émule la console de jeu Microsoft Xbox originale, permettant aux utilisateurs de jouer à leurs jeux Xbox originaux sur Windows, macOS et Linux.", "xfs — Proxmox dir storage (large files and VMs)": "xfs — Stockage du répertoire Proxmox (fichiers volumineux et machines virtuelles)", "xfs — better for large files": "xfs – meilleur pour les gros fichiers", "years old": "ans", diff --git a/lang/it.json b/lang/it.json index 4e9d2605..56c467a9 100644 --- a/lang/it.json +++ b/lang/it.json @@ -7,6 +7,7 @@ "(common default on Debian/LXC: PermitRootLogin prohibit-password).": "(impostazione predefinita comune su Debian/LXC: PermitRootLogin proibisce-password).", "(disabled)": "(disabilitato)", "(e.g.": "(es.", + "(empty)": "(vuoto)", "(for unprivileged LXCs)": "(per LXC non privilegiati)", "(if only privileged LXCs need write access)": "(se solo gli LXC privilegiati necessitano dell'accesso in scrittura)", "(make.log not found — DKMS may have failed before invoking make)": "(make.log non trovato: DKMS potrebbe non essere riuscito prima di richiamare make)", @@ -19,6 +20,7 @@ "(recommended)": "(raccomandato)", "(same MAC — restored config adjusted automatically)": "(stesso MAC: configurazione ripristinata regolata automaticamente)", ")": ")", + "*Arr Suite": "*Arr Suite", "+ Add a path": "+ Aggiungi un percorso", "+ Add new Borg target": "+ Aggiungi un nuovo bersaglio Borg", "+ Add new PBS manually": "+ Aggiungi manualmente il nuovo PBS", @@ -35,39 +37,101 @@ "/var/lib/vz/dump (Proxmox default)": "/var/lib/vz/dump (predefinito di Proxmox)", "1777 = sticky bit + rwx for all. No shared group needed.": "1777 = bit adesivo + rwx per tutti. Non è necessario alcun gruppo condiviso.", "====== PVE UPDATE COMPLETED ======": "====== AGGIORNAMENTO PVE COMPLETATO ======", + "A GTK Broadway web UI for libvirt and virt-manager.": "Un web UI di GTK Broadway per libvirt e virt-manager.", + "A Personal Relationship Management tool to help you document your social life.": "Una relazione personale Strumento di gestione per aiutarti a documentare la tua vita sociale.", "A VirtIO ISO already exists. Do you want to overwrite it?": "Esiste già un ISO VirtIO. Vuoi sovrascriverlo?", "A ZFS pool with this name already exists.": "Esiste già un pool ZFS con questo nome.", "A ZFS pool with this name already exists:": "Esiste già un pool ZFS con questo nome:", + "A backup was modified": "Un backup è stato modificato", + "A command did not finish in time:": "Un comando non ha finito nel tempo:", "A complete restore will:": "Un ripristino completo:", + "A concurrent change was detected; the container is not removed": "È stato rilevato un cambiamento concomitante; il contenitore non viene rimosso", + "A container mount has a source, backup or permission different from the saved record": "Un supporto contenitore ha una fonte, un backup o un'autorizzazione diversa dal record salvato", + "A coordinated operation is pending. The whole previous stack will be recovered, not only the selected member. If the operation already finished, the cleanup of its markers is completed.": "Un operation coordinato è in attesa. L'intero stack precedente verrà recuperato, non solo il membro selezionato. Se il operation già finito, la pulizia dei suoi marcatori è completata.", + "A different host monitor include already exists; it is not overwritten:": "Un monitor host diverso include già esiste; non è sovrascritto:", + "A fancy monitoring tool": "Uno strumento di monitoraggio di fantasia", + "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata.": "Un programma di database gratuito e open source cross-platform. Classificato come un programma di database NoSQL, MongoDB utilizza documenti simili a JSON con schemata.", + "A free reverse proxy for tunneling services (not self-hosted).": "Un proxy inverso gratuito per i servizi di tunneling (non self-hosted).", + "A free, self-hostable news aggregator…": "Un aggregatore di notizie libero e ospitabile...", + "A full-featured, open-source AI chat interface": "Un'interfaccia di chat AI completa e open source", "A gasket DKMS registration is still present:": "È ancora presente una registrazione DKMS di gasket:", + "A host bind mount cannot be included in vzdump": "Un supporto legante host non può essere incluso in vzdump", + "A host mount is not part of the journal; recovery blocked": "Un supporto host non fa parte della rivista; il recupero bloccato", "A host reboot is required after this change.": "Dopo questa modifica è necessario il riavvio dell'host.", "A host reboot is required before starting the VM. Reboot now?": "È necessario il riavvio dell'host prima di avviare la VM. Riavviare adesso?", "A job with this ID already exists.": "Esiste già un lavoro con questo ID.", + "A journal already exists; review or recover it before trying again": "Un diario già esiste; rivedere o recuperarlo prima di provare di nuovo", "A keyfile is installed at:": "un file di chiavi è installato in:", "A legacy gasket-dkms package was found on this host, but no Coral M.2 / PCIe hardware is present.": "Su questo host è stato trovato un pacchetto gasket-dkms legacy, ma non è presente alcun hardware Coral M.2/PCIe.", + "A managed rootfs and an unprivileged container are required": "Un rootf gestito e un contenitore non privato sono required", + "A managed volume with backup enabled is required": "Un volume gestito con il backup abilitato è required", + "A member VMID is in use by another guest or is on another node": "Un VMID membro è in uso da un altro ospite o è su un altro nodo", + "A member configuration changed after the stack was checked": "Una configurazione dei membri cambiata dopo il controllo dello stack", + "A member configuration changed during the preparation": "Una configurazione dei membri è cambiata durante la preparazione", + "A member did not pass its service check:": "Un membro non ha superato il suo controllo di servizio:", + "A member has a pending operation": "Un membro ha un operation in sospeso", + "A member has no reproducible service check": "Un membro non ha un controllo del servizio riproducibile", + "A member is missing before the replacement": "Un membro manca prima della sostituzione", + "A member operation does not belong to the stack": "Un membro operation non appartiene allo stack", + "A member stopped:": "Un membro si è fermato:", + "A member was modified after it was recovered": "Un membro è stato modificato dopo il recupero", + "A modern wiki and knowledge base for teams": "Una moderna base wiki e conoscenze per i team", "A new ProxMenux version is available:": "È disponibile una nuova versione di ProxMenux:", "A new kernel is staged for the next boot:": "viene messo in scena un nuovo kernel per il prossimo avvio:", "A newer version is available:": "È disponibile una versione più recente:", + "A pending operation exists for": "Esiste una operation pendente", + "A pending stack assembly already exists; it is not overwritten": "Un assemblaggio di pila in sospeso esiste già; non è sovrascritto", + "A previous NVIDIA refresh is pending review": "Un precedente aggiornamento NVIDIA è in attesa di revisione", "A previous VFIO passthrough configuration was detected for the following NVIDIA GPU(s):": "è stata rilevata una configurazione passthrough VFIO precedente per le seguenti GPU NVIDIA:", + "A privacy-first, open-source platform for knowledge management and collaboration.": "Una piattaforma privacy-first, open-source per la gestione della conoscenza e la collaborazione.", "A reboot is recommended before the GPU is guaranteed to stay on the native driver.": "si consiglia un riavvio prima che sia garantito che la GPU rimanga sul driver nativo.", "A reboot is required after installation to load the new kernel modules.": "Dopo l'installazione è necessario un riavvio per caricare i nuovi moduli del kernel.", "A reboot is required for VFIO binding to take effect. Do you want to restart now?": "È necessario un riavvio affinché l'associazione VFIO abbia effetto. Vuoi riavviare adesso?", "A reboot is required to apply the new GPU mode. Do you want to restart now?": "È necessario un riavvio per applicare la nuova modalità GPU. Vuoi riavviare adesso?", "A reboot is required to finish the restore.": "È necessario un riavvio per completare il ripristino.", "A reboot will be required to complete the restore.": "sarà necessario un riavvio per completare il ripristino.", + "A reproducible native startup is missing": "Manca una startup riproducibile", + "A rootfs adaptation is stored in persistent storage": "Un adattamento rootfs viene memorizzato nella conservazione persistente", + "A self-hosted Bitwarden server": "Un server Bitwarden self-hosted", + "A self-hosted, goal-free habit tracking tool.": "Uno strumento di monitoraggio dell'abitudine senza scopo.", + "A self-improving AI agent with memory, skills, messaging, and a web dashboard.": "Un agente AI auto-migliorante con memoria, abilità, messaggistica e una dashboard web.", "A server reboot is recommended for all changes to take full effect.": "Si consiglia di riavviare il server affinché tutte le modifiche abbiano pieno effetto.", + "A shared directory was replaced during the installation": "Una directory condivisa è stata sostituita durante l'installazione", + "A shared source does not match its recorded identity": "Una fonte condivisa non corrisponde alla sua identità registrata", + "A simple, open-source file sharing host.": "Un semplice host di condivisione di file open source.", + "A simple, private file server.": "Un semplice server di file privato.", + "A single matching image platform cannot be resolved": "Non è possibile risolvere una singola piattaforma di immagine corrispondente", + "A single-platform OCI archive is required": "Un archivio OCI monopiattaforma è required", + "A stack backup is missing; a partial restore is not allowed": "Manca un backup stack; un ripristino parziale non è consentito", + "A stack member has a different identity": "Un membro dello stack ha una diversa identità", "A system reboot is recommended to ensure all changes take effect.": "Si consiglia di riavviare il sistema per garantire che tutte le modifiche abbiano effetto.", + "A third party companion app available to Plex server owners to allow their users to request, review and discover content.": "Un'app compagna di terze parti disponibile per i proprietari di server Plex per consentire ai propri utenti di richiedere, rivedere e scoprire contenuti.", + "A third-party client for self-hosted server and self-hosted server, remote access management interface, remote access to installed applications.": "Un client di terze parti per server self-hosted e server self-hosted, interfaccia di gestione dell'accesso remoto, accesso remoto alle applicazioni installate.", + "A tmpfs mount is not part of the journal; recovery blocked": "Un supporto tmpfs non fa parte della rivista; il recupero bloccato", + "A tmpfs mount overlaps another mount": "Un supporto tmpfs sovrappone un altro supporto", + "A tunneling daemon by Cloudflare that safely exposes your web servers into the internet.": "Un demone tunneling di Cloudflare che espone in modo sicuro i vostri server web in Internet.", + "A versatile file conversion tool that supports multiple formats.": "Uno strumento di conversione di file versatile che supporta più formati.", + "A web GUI client of Project V which supports VMess, VLESS, SS, SSR, Trojan, Tuic and Juicity protocols": "Un client web GUI di Project V che supporta i protocolli VMess, VLESS, SS, SSR, Trojan, Tuic e Juicity", + "A web app to listen Youtube audio source.": "Una web app per ascoltare Youtube sorgente audio.", + "A web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes": "Una web app per gestire i tuoi account di autenticazione a due fattori (2FA) e generare i loro codici di sicurezza", + "A web frontend for the motion daemon.": "Un frontend web per il demone del movimento.", + "A web-based file sharing and management protocol": "Un protocollo di condivisione e gestione dei file web-based", + "A well-designed cross-platform ChatGPT UI.": "Un'interfaccia ChatGPT UI ben progettata.", "ACL Status:": "Stato ACL:", "ACL permissions applied for local access for user:": "ACL permissions applied for local access for user:", "ADVANCED SETTINGS COMPLETE": "IMPOSTAZIONI AVANZATE COMPLETATE", "ALL DATA ON": "TUTTI I DATI SU", "ALL DATA ON THIS DISK WILL BE PERMANENTLY LOST!": "TUTTI I DATI SU QUESTO DISCO SARANNO PERDUTI PERMANENTEMENTE!", "ALL Utilities": "TUTTE le utenze", + "ALLOWED_HOSTS cannot contain line breaks": "ALLOWED HOSTS non può contenere interruzioni di linea", + "AList initial login": "login iniziale AList", "AMD CPU detected": "Rilevata CPU AMD", "AMD CPU fixes applied successfully": "Le correzioni della CPU AMD sono state applicate correttamente", "AMD GPU Tools installation completed!": "Installazione degli strumenti GPU AMD completata!", "AMD GPU passthrough configured.": "Passthrough GPU AMD configurato.", "AMD GPU(s) detected:": "GPU AMD rilevate:", + "AMD KFD device": "AMD KFD dispositivo", + "AMD VA-API + OpenCL (official mod)": "AMD VA-API + OpenCL (modifica ufficiale)", "AMD fixes have been successfully reverted": "Le correzioni AMD sono state ripristinate con successo", "AMD mesa drivers installed.": "Driver AMD Mesa installati.", "AMD softdep configured": "AMD softdep configurato", @@ -93,9 +157,21 @@ "About to restore": "In procinto di ripristinare", "Absolute directory path to use as backup target:": "percorso assoluto della directory da utilizzare come destinazione del backup:", "Absolute path to a file or directory you want backed up:": "Percorso assoluto di un file o di una directory di cui desideri eseguire il backup:", + "Acceleration": "Accelerazione", + "Acceleration configuration cancelled": "Cancellazione della configurazione di accelerazione", + "Acceleration for CodeProject.AI": "Accelerazione per CodeProject. AI", + "Acceleration for Immich smart recognition": "Accelerazione per il riconoscimento intelligente Immich", + "Acceleration for Ollama": "Accelerazione per Ollama", "Accept routes from other nodes?": "Accetti percorsi da altri nodi?", + "Accept this host monitoring profile?": "Accettare questo profilo di monitoraggio host?", "Access Scope:": "Ambito di accesso:", + "Access bridge": "Ponte di accesso", + "Access bridge for Immich": "Ponte di accesso per Immich", + "Access bridge for Nextcloud": "Ponte di accesso per Nextcloud", + "Access bridge for Paperless": "Ponte di accesso per Paperless", + "Access bridge for Tandoor": "Ponte di accesso per Tandoor", "Access profile:": "Profilo di accesso:", + "Access token of the Jupyter Lab web interface": "Token di accesso dell'interfaccia web di Jupyter Lab", "Account is not locked": "L'account non è bloccato", "Action cancelled due to previous xshok-proxmox modifications.": "Azione annullata a causa di precedenti modifiche a xshok-proxmox.", "Action:": "Azione:", @@ -105,6 +181,10 @@ "Active Connections": "Connessioni attive", "Active exports:": "Esportazioni attive:", "Active session:": "Sessione attiva:", + "Actual device path on the host": "Percorso effettivo del dispositivo sull'host", + "Adaptation file too large": "File di adattamento troppo grande", + "Adaptation file with unexpected permissions or owner": "File di adattamento con autorizzazioni inaspettate o proprietario", + "Adblock & DNS": "Adblock & DNS", "Add Audio Passthrough": "Aggiungi pass-through audio", "Add CIFS storage:": "Aggiungi spazio di archiviazione CIFS:", "Add Controller or NVMe (PCI passthrough)": "Aggiungi controller o NVMe (passthrough PCI)", @@ -123,6 +203,9 @@ "Add PBS": "Aggiungi PBS", "Add Samba Share as Proxmox Storage": "Aggiungi condivisione Samba come spazio di archiviazione Proxmox", "Add Samba share as Proxmox Storage": "Aggiungi la condivisione Samba come Proxmox Storage", + "Add a Coral PCIe/M.2 device?": "Aggiungi un dispositivo Coral PCIe/M.2?", + "Add a custom data path?": "Aggiungi un percorso dati personalizzato?", + "Add an extra custom path": "Aggiungi un percorso extra personalizzato", "Add as IDE": "Aggiungi come IDE", "Add as SATA": "Aggiungi come SATA", "Add as SCSI": "Aggiungi come SCSI", @@ -140,6 +223,7 @@ "Add import disk": "Aggiungi disco di importazione", "Add latest Ceph support": "aggiungi il supporto Ceph più recente", "Add new PVE 9 enterprise repository (deb822 format) (Only if using enterprise):": "Aggiungi il nuovo repository enterprise PVE 9 (formato deb822) (solo se utilizzi enterprise):", + "Add or change a device": "Aggiungere o modificare un dispositivo", "Add physical disk to VM via": "Aggiungi disco fisico alla VM tramite", "Add share block in /etc/samba/smb.conf:": "Aggiungi il blocco di condivisione in /etc/samba/smb.conf:", "Add unprivileged flag to container configuration:": "Aggiungi flag senza privilegi alla configurazione del contenitore:", @@ -154,20 +238,37 @@ "Adding": "Aggiunta", "Adding CIFS storage to Proxmox...": "Aggiunta dello spazio di archiviazione CIFS a Proxmox...", "Adding QEMU Guest Agent support...": "Aggiunta del supporto per l'agente guest QEMU...", + "Adding Radarr to Prowlarr...": "Aggiungere Radarr a Prowlarr...", + "Adding Sonarr to Prowlarr...": "Aggiungere Sonarr a Prowlarr...", "Adding disk using the generated command to the selected VM": "Aggiunta del disco utilizzando il comando generato alla VM selezionata", "Adding existing users to sharedfiles group...": "Aggiunta di utenti esistenti al gruppo sharedfiles...", "Adding iSCSI storage to Proxmox...": "Aggiunta di spazio di archiviazione iSCSI a Proxmox...", "Adding new share to smb.conf...": "Aggiunta di una nuova condivisione a smb.conf...", + "Adding peers later means raising PEERS in /etc/pve/lxc/.conf and restarting the container. The existing peer keys are kept.": "Aggiunta di coetanei in seguito significa sollevare PEERS in /etc/pve/lxc/δCTID>.conf e riavviare il contenitore. Le chiavi peer esistenti sono conservate.", + "Adding the mount points...": "Aggiungere i punti di fissaggio...", "Adding this NVMe as a PCIe device (via 'Add Controller or NVMe PCIe to VM') gives better performance.": "L'aggiunta di questo NVMe come dispositivo PCIe (tramite \"Aggiungi controller o NVMe PCIe alla VM\") offre prestazioni migliori.", "Adding to /etc/fstab for permanent mounting...": "Aggiunta a /etc/fstab per il montaggio permanente...", + "Additional URL advertised by Plex (optional)": "URL aggiuntivo pubblicizzato da Plex (opzionale)", "Additional audio function(s) to be added": "Ulteriori funzioni audio da aggiungere", + "Additional media/GPU GIDs, comma-separated": "Supporti aggiuntivi/GPU GID, separati da virgola", + "Additional paths for": "Altri percorsi per", + "Address of the Compose file": "Indirizzo del file Compose", + "Address to reach Pydio Cells (https://domain or https://IP:8080)": "Indirizzo per raggiungere Pydio Cells (https://domain o https://IP:80)", + "Address used to reach wallabag (http://IP or https://wallabag.example.com)": "Indirizzo utilizzato per raggiungere wallabag (http://IP o https://wallabag.example.com)", + "Addresses to update: ipv4, ipv6 or both (uses an external service)": "Indirizzi per l'aggiornamento: ipv4, ipv6 o entrambi (utilizza un servizio esterno)", + "Adguardhome Sync web interface": "Interfaccia web Adguardhome Sync", + "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances.": "Adguardhome-sync è uno strumento per sincronizzare AdGuardHome config per replicare le istanze.", "Adjust network/CIDR to your environment.": "Adatta la rete/CIDR al tuo ambiente.", "Adjust options if needed (vers=4,hard,timeo,...).": "Modifica le opzioni se necessario (vers=4,hard,timeo,...).", "Adjusting systemd-journald limits to match Log2RAM size...": "Regolazione dei limiti di systemd-journald in modo che corrispondano alle dimensioni di Log2RAM...", "Adjusts journald log level if needed (Proxmox defaults may block auth logs)": "Regola il livello di registro journald se necessario (le impostazioni predefinite di Proxmox potrebbero bloccare i registri di autenticazione)", + "Admin page": "Pagina iniziale", + "Administrator email": "E-mail amministratore", + "Administrator password, at least 12 characters (empty = generated)": "Password amministratore, almeno 12 caratteri (vuoto = generato)", "Advanced": "Avanzato", "Advanced Diagnostics": "Diagnostica avanzata", "Advanced Network Diagnostics": "Diagnostica di rete avanzata", + "Advanced: every setting of the container": "Avanzato: ogni impostazione del contenitore", "Affected LXC containers": "Contenitori LXC interessati", "After completing GPU setup, start the VM manually when the host is ready.": "Dopo aver completato la configurazione della GPU, avvia manualmente la VM quando l'host è pronto.", "After confirming, you will be asked to choose the NVIDIA driver version to install.": "Dopo la conferma, ti verrà chiesto di scegliere la versione del driver NVIDIA da installare.", @@ -183,11 +284,15 @@ "After the reboot you can follow the post-restore work live from ProxMenux Monitor → Backups tab (estimated time, per-component status, log tail, rollback delta).": "dopo il riavvio è possibile seguire in tempo reale il lavoro post-ripristino da ProxMenux Monitor → scheda Backup (tempo stimato, stato per componente, coda del registro, delta di rollback).", "After the reboot, you will only be able to access the Proxmox host via:": "Dopo il riavvio, potrai accedere all'host Proxmox solo tramite:", "After this LXC → VM switch, reboot the host so the new binding state is applied cleanly.": "Dopo questo passaggio LXC → VM, riavviare l'host in modo che il nuovo stato di associazione venga applicato in modo pulito.", + "Airsonic Advanced web interface": "Interfaccia web Airsonic Advanced", + "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room.": "Airsonic-advanced è un free, web-based media streamer, fornendo ubiquitious accesso alla vostra musica. Usalo per condividere la tua musica con gli amici, o per ascoltare la tua musica mentre lavori. È possibile trasmettere a più giocatori contemporaneamente, per esempio a un giocatore nella vostra cucina e un altro nel vostro soggiorno.", "Aliases added to .bashrc": "Alias ​​aggiunti a .bashrc", + "Alist Sync web interface": "Interfaccia web Alist Sync", "All": "Tutto", "All Available Scripts": "Tutti gli script disponibili", "All GPUs Already Assigned": "Tutte le GPU già assegnate", "All ProxMenux optimizations are up to date.": "Tutte le ottimizzazioni di ProxMenux sono aggiornate.", + "All applications": "Tutte le applicazioni", "All block devices:": "Tutti i dispositivi a blocchi:", "All changes applied. No reboot required.": "Tutte le modifiche sono state applicate. Nessun riavvio richiesto.", "All changes are reversible using the ProxMenux uninstaller.": "Tutte le modifiche sono reversibili utilizzando il programma di disinstallazione di ProxMenux.", @@ -195,43 +300,79 @@ "All detected GPUs are already assigned to this VM.": "Tutte le GPU rilevate sono già assegnate a questa VM.", "All detected controllers/NVMe are already present in the selected VM.": "Tutti i controller/NVMe rilevati sono già presenti nella VM selezionata.", "All disks may already be in use or mounted.": "Tutti i dischi potrebbero essere già in uso o montati.", + "All images are downloaded and verified first, and native backups are taken with the stack stopped. Contracts are published after the whole set is checked. If anything fails, all members are recovered.": "Tutte le immagini vengono scaricate e verificate prima, e i backup nativi vengono presi con lo stack interrotto. I contratti vengono pubblicati dopo la verifica dell'intero insieme. Se qualcosa fallisce, tutti i membri vengono recuperati.", "All images imported and configured successfully": "Tutte le immagini sono state importate e configurate correttamente", "All imports failed": "Tutte le importazioni sono fallite", + "All of them are removed.": "Tutti loro sono rimossi.", "All partitions and metadata removed.": "Tutte le partizioni e i metadati rimossi.", "All physical interfaces from backup are present on target": "Tutte le interfacce fisiche del backup sono presenti sulla destinazione", + "All stack members are updated together. Main CT:": "Tutti i membri dello stack sono aggiornati insieme. CT principale:", "All types (images, backup, iso, vztmpl, snippets)": "Tutti i tipi (immagini, backup, iso, vztmpl, snippet)", "All user-installed packages from the backup are present on this host": "Tutti i pacchetti installati dall'utente dal backup sono presenti su questo host", "All users with UID and GID": "Tutti gli utenti con UID e GID", "Allocate CPU Cores": "Assegnare i core della CPU", "Allocate RAM in MiB": "Assegna la RAM in MiB", + "Allowed hosts (comma separated; * allows access through the assigned IP)": "Host consentiti (comma separato; * consente l'accesso tramite l'IP assegnato)", "Already Mounted": "Già montato", "Already configured": "Già configurato", "Already installed — skipping": "già installato: saltato", + "Also add the /dev/srX optical device (recommended)": "Aggiungi anche il dispositivo ottico /dev/srX (consigliato)", "Also comment any remaining 'bookworm' entries in *.list if present.": "Commenta anche eventuali voci rimanenti di 'bookworm' in *.list, se presenti.", "Also install the VirtIO network driver during setup to enable network access.": "Installare anche il driver di rete VirtIO durante la configurazione per abilitare l'accesso alla rete.", "Although VFIO can bind to this device, full passthrough to a VM is": "Sebbene VFIO possa collegarsi a questo dispositivo, il passthrough completo a una VM lo è", + "Altus is an Electron-based WhatsApp client with themes and multiple account support.": "Altus è un client WhatsApp basato su Electron con temi e supporto di account multipli.", + "Ambiguous mount points in the container": "Punti di montaggio ambigui nel contenitore", + "Ambiguous or invalid environment variable": "Variazione ambientale ambigua o non valida", "Amount of RAM in MiB (default: 4096)": "Quantità di RAM in MiB (impostazione predefinita: 4096)", + "An AI model used to generate images conditioned on text descriptions.": "Un modello AI usato per generare immagini condizionate da descrizioni di testo.", "An AMD dedicated GPU has been detected without FLR support": "È stata rilevata una GPU dedicata AMD senza supporto FLR", "An AMD integrated GPU (APU) has been detected": "È stata rilevata una GPU integrata AMD (APU).", + "An Alist storage synchronization tool based on the Web interface.": "Uno strumento di sincronizzazione dello storage Alist basato sull'interfaccia Web.", + "An Industrial-Level Controllable and Efficient Zero-Shot Text-To-Speech System": "Un sistema di testo a velocità variabile industriale ed efficiente Zero-Shot", "An Intel dedicated GPU has been detected without FLR support": "È stata rilevata una GPU Intel dedicata senza supporto FLR", + "An accelerated video generation framework that speeds up end-to-end diffusion while preserving video quality": "Un framework di generazione video accelerato che velocizza la diffusione end-to-end preservando la qualità video", + "An executable required by the adapter is missing in the new image": "Un required eseguibile dall'adattatore manca nella nuova immagine", "An fstab entry already exists for:": "Esiste già una voce fstab per:", + "An image probe container was started externally": "Un contenitore di sonda di immagine è stato avviato esternamente", + "An include is not part of the journal; recovery blocked": "Un include non fa parte della rivista; il recupero bloccato", + "An include was modified outside the journal; recovery blocked": "Un include è stato modificato al di fuori della rivista; il recupero bloccato", + "An open source generative AI development platform for building AI Agents and LLM workflows": "Una piattaforma di sviluppo AI generativa open source per la costruzione di agenti AI e flussi di lavoro LLM", + "An operation of this installation has not finished; recover it from the management menu before removing it": "Un operation di questa installazione non è finito; recuperarlo dal menu di gestione prima di rimuoverlo", + "An update does not accept configuration changes": "Un aggiornamento non accetta modifiche di configurazione", "Analysis Tools": "Strumenti di analisi", + "Analysis software that shows your internet speed for up to 30 days.": "Software di analisi che mostra la velocità di internet fino a 30 giorni.", "Analyze Bridge Configuration": "Analizzare la configurazione del bridge", "Analyze Network Configuration": "Analizzare la configurazione di rete", "Analyzing Bridge Configuration - READ ONLY MODE": "Analisi della configurazione del bridge - MODALITÀ SOLA LETTURA", "Analyzing Network Configuration - READ ONLY MODE": "Analisi della configurazione di rete - MODALITÀ SOLA LETTURA", "Analyzing selected disks...": "Analisi dei dischi selezionati...", "Analyzing system for available PCIe storage devices...": "Analisi del sistema per i dispositivi di archiviazione PCIe disponibili...", + "Another OCI operation is using the instance registry": "Un'altra OCI operation utilizza il registro delle istanze", + "Another OCI operation is using the instance registry. Wait for it to finish and open this menu again; no container is modified.": "Un'altra OCI operation utilizza il registro delle istanze. Attendere che finisca e apra nuovamente questo menu; nessun contenitore viene modificato.", + "Another OCI operation is using the registry. This operation was not started.": "Un'altra OCI operation sta usando il registro. Questo operation non è stato avviato.", + "Another instance uses": "Un'altra istanza utilizza", + "Another stack operation is pending": "Un altro stack operation è in attesa", + "Application": "Applicazione", + "Application responding:": "Richiesta di risposta:", + "Application responding; checking its stability...": "Applicazione rispondente; controllare la sua stabilità...", + "Application suite: one independent LXC per selected application": "Suite di applicazione: un LXC indipendente per applicazione selezionata", + "Application:": "Applicazione:", + "Applications you can choose:": "Applicazioni che puoi scegliere:", "Apply": "Fare domanda a", "Apply AMD CPU fixes": "applica le correzioni della CPU AMD", "Apply Available Updates": "Applica gli aggiornamenti disponibili", "Apply and restart services:": "Applicare e riavviare i servizi:", "Apply available updates": "applica gli aggiornamenti disponibili", "Apply boot/initramfs changes": "Applica le modifiche boot/initramfs", + "Apply configuration": "Applicare la configurazione", "Apply fix now?": "Applicare la correzione adesso?", "Apply fix now? (The share will be briefly remounted)": "Applicare la correzione adesso? (La condivisione verrà brevemente rimontata)", "Apply network optimizations": "applica ottimizzazioni di rete", + "Apply optional security relaxation apparmor:rootlesskit": "Applicare apparmor di rilassamento della sicurezza opzionale:rootlesskit", + "Apply optional security relaxation apparmor:unconfined": "Applicare apparmor di rilassamento di sicurezza facoltativo:unconfined", + "Apply optional security relaxation seccomp:unconfined": "Applicare facoltativo sicurezza rilassamento seccomp:unconfined", "Apply read+write access for 'others' on the host directory?": "Applicare l'accesso in lettura+scrittura per \"altri\" nella directory host?", + "Apply the options from the current catalog template? Your data and configuration are kept.": "Applicare le opzioni dal modello di catalogo corrente? I dati e la configurazione sono conservati.", "Applying AMD-specific fixes...": "Applicazione delle correzioni specifiche di AMD...", "Applying Changes": "Applicazione delle modifiche", "Applying Controller/NVMe passthrough to VM": "Applicazione del passthrough Controller/NVMe alla VM", @@ -244,12 +385,21 @@ "Applying passthrough to CT": "Applicazione del passthrough a CT", "Applying safe paths and preparing pending restore": "Applicazione di percorsi sicuri e preparazione del ripristino in sospeso", "Applying selected LXC switch action": "Applicazione dell'azione di commutazione LXC selezionata", + "Applying the Jellyfin configuration:": "Applicando la configurazione Jellyfin:", + "Applying the LAN address to the application URLs...": "Applicare l'indirizzo LAN agli URL dell'applicazione...", + "Applying the initial Nextcloud settings...": "Applicare le impostazioni iniziali Nextcloud...", + "Applying the mount mode...": "Applicare la modalità di montaggio...", + "Apprise-api Takes advantage of Apprise through your network with a user-friendly API.": "Apprise-api Approfitta di Apprise attraverso la rete con un'API user-friendly.", + "Architecture": "Architettura", + "Architecture:": "Architettura:", + "Architectures": "Architettura", "Archive deleted.": "Archivio eliminato.", "Archive extracted.": "Archivio estratto.", "Archive format": "Formato dell'archivio", "Archive ready": "Archivio pronto", "Archive size:": "Dimensioni dell'archivio:", "Archive:": "Archivio:", + "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers.": "Ardour è uno sforzo aperto e collaborativo di un team di tutto il mondo, tra cui musicisti, programmatori e ingegneri di registrazione professionale.", "Are you absolutely sure?": "Ne sei assolutamente sicuro?", "Are you sure you want to continue?": "Sei sicuro di voler continuare?", "Are you sure you want to delete this export?": "Sei sicuro di voler eliminare questa esportazione?", @@ -261,6 +411,7 @@ "Are you sure you want to unmount this NFS share?": "Sei sicuro di voler smontare questa condivisione NFS?", "Are you sure you want to unmount this Samba share?": "Sei sicuro di voler smontare questa condivisione Samba?", "Are you sure?": "Sei sicuro?", + "Arr suite: applications to install": "Arr suite: applicazioni da installare", "As Proxmox storage": "Come spazio di archiviazione Proxmox", "As host fstab mount only": "Solo come host fstab montato", "Assign GPU PCI function to VM": "Assegna la funzione GPU PCI alla VM", @@ -275,14 +426,19 @@ "Attach imported disk to VM": "Allega il disco importato alla VM", "Attach to an existing PVE vzdump job (inherit schedule + retention)": "collega a un lavoro vzdump PVE esistente (pianificazione ereditaria + conservazione)", "Attached to PVE job:": "Allegato al lavoro PVE:", + "Attaching the volumes...": "Attaccare i volumi...", "Attempting automatic repair...": "Tentativo di riparazione automatica...", "Attempting passthrough with this GPU typically results in": "Il tentativo di passthrough con questa GPU in genere dà come risultato", "Attention: Removing the subscription banner may cause issues in the web interface after a future update.": "Attenzione: la rimozione del banner di abbonamento potrebbe causare problemi nell'interfaccia web dopo un futuro aggiornamento.", + "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source.": "Audacity è un editor e registratore audio multi-track facili da usare. Sviluppato da un gruppo di volontari come open source.", + "Audio device directory": "Directory del dispositivo audio", + "Audiobookshelf is a self-hosted audiobook and podcast server.": "Audiobookshelf è un audiobook self-hosted e un server podcast.", "Audit completed. Press Enter to continue...": "Verifica completata. Premi Invio per continuare...", "Audit socket disabled or not required": "socket di controllo disabilitato o non richiesto", "Auth key is required.": "È richiesta la chiave di autenticazione.", "Auth:": "Autenticazione:", "Authentication": "Autenticazione", + "Authentication & Security": "Autenticazione e sicurezza", "Authentication Error": "Errore di autenticazione", "Authentication failed.": "Autenticazione non riuscita.", "Authentication required:": "Autenticazione richiesta:", @@ -301,7 +457,12 @@ "Auto-sync was not enabled": "La sincronizzazione automatica non era abilitata", "Automated Post-Install Script": "Script post-installazione automatizzato", "Automated post-installation script": "script post-installazione automatizzato", + "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Gestione automatica della Videoteca per spettacoli televisivi. Osserva per nuovi episodi dei tuoi spettacoli preferiti, e quando sono pubblicati fa la sua magia.", + "Automatic detection": "Rilevamento automatico", + "Automatic private network allocation requires a /24 subnet": "Distribuzione automatica della rete privata requires a /24 subnet", + "Automatic video library manager for TV Shows": "Gestore automatico della libreria video per spettacoli televisivi", "Automatic/Unattended": "Automatico/non presidiato", + "Automation & Scheduling": "Automazione & Scheduling", "Available": "Disponibile", "Available Borg archives (newest first):": "Archivi Borg disponibili (prima il più recente):", "Available Borg targets:": "Obiettivi Borg disponibili:", @@ -322,17 +483,23 @@ "Available space in /mnt:": "Spazio disponibile in /mnt:", "Available storage information:": "Informazioni sullo spazio di archiviazione disponibile:", "Available storage volumes:": "Volumi di archiviazione disponibili:", + "Azahar is an open-source 3DS emulator based on Citra.": "Azahar è un emulatore 3DS open source basato su Citra.", "BIOS TYPE": "TIPO DI BIOS", "BIOS Type": "Tipo di BIOS", "BIOS from": "BIOS da", "BIOS: OVMF (UEFI)": "BIOS: OVMF (UEFI)", + "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications.": "BOINC è una piattaforma per il calcolo ad alta produttività su larga scala (migliaia o milioni di computer). Può essere utilizzato per il calcolo volontario (utilizzando dispositivi di consumo) o il calcolo della griglia (utilizzando risorse organizzative). Supporta applicazioni virtualizzate, parallele e GPU.", "BRIDGE CONFIGURATION ANALYSIS": "ANALISI DELLA CONFIGURAZIONE DEL PONTE", "BTRFS:": "BTRFS:", + "Baby Buddy web interface": "Interfaccia web Baby Buddy", + "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work.": "Babybuddy è un amico per i bambini! Aiuta i caregiver a monitorare il sonno, gli alimenti, i cambiamenti del pannolino, il tempo della pancia e altro ancora per conoscere e prevedere le esigenze del bambino senza (così tanto) indovinare il lavoro.", "Back to previous menu or Esc + Enter": "Torna al menu precedente o Esc + Invio", "Backed up and cleared": "Effettuato il backup e cancellato", "Backend": "Backend", "Backend:": "Backend:", + "Background archive extraction for Arr download queues. No web interface.": "Estrazione archivio di sfondo per Arr file di download. Nessuna interfaccia web.", "Backup — VM and CT backups": "Backup: backup di VM e CT", + "Backup & Recovery": "Backup & Recupero", "Backup Created": "Backup creato", "Backup ID (group name in PBS):": "ID backup (nome del gruppo in PBS):", "Backup ID for this job:": "ID di backup per questo lavoro:", @@ -345,6 +512,7 @@ "Backup available at": "Backup disponibile su", "Backup completed successfully.": "Backup completato con successo.", "Backup completed:": "Backup completato:", + "Backup created": "Backup creato", "Backup created:": "Backup creato:", "Backup declares unused NICs that are not on this host:": "Il backup dichiara le NIC inutilizzate che non si trovano su questo host:", "Backup destination is inside the backup": "La destinazione del backup è all'interno del backup", @@ -355,6 +523,7 @@ "Backup information": "Informazioni di backup", "Backup location": "Posizione di backup", "Backup metadata": "Metadati di backup", + "Backup of the previous installation verified": "Backup dell'installazione precedente verificata", "Backup on newer kernel:": "backup sul kernel più recente:", "Backup on older kernel:": "backup sul kernel precedente:", "Backup origin metadata:": "Metadati di origine del backup:", @@ -369,26 +538,42 @@ "Backup:": "Backup:", "Backups already on PBS were encrypted with the current key — downloading them will fail unless you first Download the current keyfile to keep a copy.": "i backup già presenti su PBS sono stati crittografati con la chiave corrente: il loro download fallirà a meno che non si scarichi prima il file di chiavi corrente per conservarne una copia.", "Backups already stored on PBS were encrypted with the current keyfile. After this action:": "i backup già archiviati su PBS sono stati crittografati con il file di chiavi corrente. Dopo questa azione:", + "Backups verified": "Backup verificati", + "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience.": "Bambu Studio è un software di taglio open source, all'avanguardia e ricco di funzionalità. Contiene flussi di lavoro basati su progetti, algoritmi di slicing ottimizzati sistematicamente, e un'interfaccia grafica facile da usare, portando agli utenti un'esperienza di stampa incredibilmente liscia.", "Bandwidth limit configured": "Limite di larghezza di banda configurato", "Bandwidth test (iperf3)": "test della larghezza di banda (iperf3)", "Bandwidth test completed successfully": "Test della larghezza di banda completato con successo", "Base VM created with ID": "VM di base creata con ID", + "Base VMID": "Base VMID", + "Base VMID (empty = next free block)": "Base VMID (vuoto = prossimo blocco gratuito)", + "Base VMID of Nextcloud (empty = next free block)": "Base VMID di Nextcloud (vuoto = prossimo blocco gratuito)", + "Base VMID of Paperless (empty = next free block)": "Base VMID di Paperless (vuoto = prossimo blocco gratuito)", + "Base VMID of Tandoor (empty = next free block)": "Base VMID di Tandoor (vuoto = prossimo blocco gratuito)", + "Base VMID of the server (empty = next free block)": "Base VMID del server (vuoto = prossimo blocco gratuito)", "Bash prompt path": "Percorso nel prompt Bash", "Bashrc customization completed": "Personalizzazione Bashrc completata", "Basic Settings": "Impostazioni di base", "Basic Utilities": "Utilità di base", + "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you.": "Bazarr è un'applicazione compagna di Sonarr e Radarr. Può gestire e scaricare i sottotitoli in base ai tuoi requirements. Definisci le tue preferenze per show TV o film e Bazarr si prende cura di tutto per te.", + "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools.": "Beets è un direttore della biblioteca musicale e non, per la maggior parte, un lettore musicale. Esso include un semplice plug-in del giocatore e un lettore sperimentale basato su Web, ma generalmente lascia la riproduzione del suono reale agli strumenti specializzati.", "Before making any changes, we'll create a safety backup.": "Prima di apportare qualsiasi modifica, creeremo un backup di sicurezza.", "Beta (develop branch)": "Beta (ramo di sviluppo)", "Beta version:": "Versione beta:", "Binary not found in extracted content.": "Binario non trovato nel contenuto estratto.", "Bind mount added:": "Aggiunto supporto di collegamento:", + "Bind mounts are not included in vzdump": "I supporti binari non sono inclusi in vzdump", + "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services.": "Bitcoin Knots può essere utilizzato come client desktop per i pagamenti regolari o come utilità server nodo completo per i commercianti e altri servizi di pagamento.", "Blacklist nouveau driver": "Nouveau driver nella lista nera", "Blacklisting GPU host drivers...": "Inserimento nella lista nera dei driver host GPU...", "Blacklisting nouveau driver...": "Nouveau driver nella lista nera...", + "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**": "Blender è un software per computer grafica 3D gratuito e open source utilizzato per la creazione di film animati, effetti visivi, arte, modelli stampati 3D, grafica del movimento, applicazioni 3D interattive, realtà virtuale e giochi per computer. **Questa immagine non supporta il rendering GPU dalla scatola solo un'esperienza di workspace accelerata**", + "Blinko is an AI-powered card note-taking project. Designed for individuals who want to quickly capture and organize their fleeting thoughts. Blinko allows users to seamlessly jot down ideas the moment they strike, ensuring that no spark of creativity is lost.": "Blinko è un progetto di note-taking per schede AI. Progettato per gli individui che vogliono quickly catturare e organizzare i loro pensieri fugace. Blinko consente agli utenti di scovare senza soluzione di continuità le idee nel momento in cui colpiscono, garantendo che nessuna scintilla di creatività è persa.", "Blocked GPU ID": "ID GPU bloccato", "Blocked GPU ID for VM Mode": "ID GPU bloccato per la modalità VM", "Blocked device(s)": "Dispositivo/i bloccato/i", "Blocked device(s):": "Dispositivi bloccati:", + "BookStack web interface": "Interfaccia web BookStack", + "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease.": "Bookstack è un Wiki gratuito e open source progettato per creare una bella documentazione. Con un semplice, ma potente editor WYSIWYG consente ai team di creare documentazione dettagliata e utile con facilità.", "Boot Disk": "Disco di avvio", "Boot artifacts regenerated — reboot the host to activate the merged config.": "artefatti di avvio rigenerati: riavvia l'host per attivare la configurazione unita.", "Boot disk:": "Disco di avvio:", @@ -415,9 +600,13 @@ "Bridge:": "Ponte:", "Bridges analyzed": "Ponti analizzati", "Broken gasket-dkms package state recovered.": "Lo stato danneggiato del pacchetto gasket-dkms è stato ripristinato.", + "Browse Your Life in Images": "Sfoglia la tua vita in immagini", "Browse manually (advanced)...": "Sfoglia manualmente (avanzato)...", + "Browsers & Web Desktops": "Browser & Web Desktops", "Build and install the gasket and apex kernel modules (DKMS)": "Compila e installa i moduli kernel gasket e apex (DKMS)", "Build dependencies installed.": "Costruisci dipendenze installate.", + "Build your personal knowledge base with TriliumNext Notes": "Costruire la vostra base di conoscenza personale con TriliumNext Notes", + "Business & ERP": "Affari & ERP", "CHANGES APPLIED SUCCESSFULLY": "MODIFICHE APPLICATE CON SUCCESSO", "CIFS Client Tools: AVAILABLE": "Strumenti client CIFS: DISPONIBILE", "CIFS Client Tools: NOT AVAILABLE - installing...": "Strumenti client CIFS: NON DISPONIBILE - installazione in corso...", @@ -435,24 +624,35 @@ "CLUSTER UPGRADE NOTES:": "NOTE SULL'AGGIORNAMENTO DEL CLUSTER:", "CONFIGURED INTERFACES": "INTERFACCE CONFIGURATE", "CONFIRM FORMAT": "CONFERMA FORMATO", + "CPU": "CPU", "CPU Cores": "Core della CPU", "CPU MODEL": "MODELLO CPU", "CPU Model": "Modello della CPU", + "CPU cores": "core della CPU", + "CPU priority": "Priorità della CPU", "CPU set to host,hidden=1,flags=+pcid": "CPU impostata su host,hidden=1,flags=+pcid", "CPU vendor (intel/amd):": "Fornitore della CPU (Intel/AMD):", "CRITICAL: The selected disk is referenced by a RUNNING VM or CT.": "CRITICO: al disco selezionato fa riferimento una VM o un CT IN ESECUZIONE.", "CT": "CT", "CT started successfully.": "CT è stato avviato correttamente.", + "CUDA requires a working NVIDIA driver": "CUDA requires un driver NVIDIA funzionante", + "CUDA requires the NVIDIA Container Toolkit on the host": "CUDA requires il NVIDIA Container Toolkit sul host", + "Calculate all kinds of statistics from your (local) Emby or Jellyfin server": "Calcola tutti i tipi di statistiche dal server (locale) Emby o Jellyfin", + "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts.": "Calibre è un potente e facile da usare e-book manager. Gli utenti dicono che è eccezionale e un must-have. Ti permetterà di fare quasi tutto e ci vuole un passo oltre il normale software e-book. E 'anche completamente gratuito e open source e grande sia per gli utenti casual e esperti di computer.", + "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself.": "Calibre-web è un'app web che fornisce un'interfaccia pulita per la navigazione, la lettura e il download di eBooks utilizzando un database Calibre esistente. È anche possibile integrare Google Drive e modificare metadati e la libreria calibre attraverso l'app stessa.", + "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases.": "Calligra è una suite per ufficio e grafica di KDE. È disponibile per PC desktop, tablet e smartphone. Contiene applicazioni per l'elaborazione di parole, fogli di calcolo, presentazione, grafica vettoriale e database di editing.", "Cancel": "Cancellare", "Cancel restore": "Annulla ripristino", "Cancel this setup": "annulla questa configurazione", "Cancelled by user or empty URL.": "Annullato dall'utente o URL vuoto.", "Cancelled by user.": "Annullato dall'utente.", + "Cannot apply the Compose command:": "Non è possibile applicare il comando Compose:", "Cannot connect to server": "Impossibile connettersi al server", "Cannot continue": "Impossibile continuare", "Cannot create:": "Impossibile creare:", "Cannot detect filesystem on": "Impossibile rilevare il file system attivo", "Cannot find": "Impossibile trovare", + "Cannot identify the vendor of the device:": "Non è possibile identificare il fornitore del dispositivo:", "Cannot load backup library: lib_host_backup_common.sh": "Impossibile caricare la libreria di backup: lib_host_backup_common.sh", "Cannot proceed with invalid export path.": "Impossibile procedere con un percorso di esportazione non valido.", "Cannot proceed with invalid share name.": "Impossibile procedere con un nome di condivisione non valido.", @@ -460,7 +660,11 @@ "Cannot reach download.proxmox.com. Check network, proxy or DNS.": "impossibile raggiungere download.proxmox.com. Controlla rete, proxy o DNS.", "Cannot reach portal:": "Impossibile raggiungere il portale:", "Cannot reach server": "Impossibile raggiungere il server", + "Cannot read": "Non riesco a leggere", + "Cannot read the OCI archive:": "Non è possibile leggere l'archivio OCI:", "Cannot validate credentials - no shares available for testing.": "Impossibile convalidare le credenziali: nessuna condivisione disponibile per il test.", + "Cannot verify the reused disk:": "Non è possibile verificare il disco riutilizzato:", + "Capabilities cannot be kept and all dropped at the same time": "Le capacità non possono essere mantenute e tutte cadute allo stesso tempo", "Category": "Categoria", "Caution: Maximum mode generates more heat.": "Attenzione: la modalità massima genera più calore.", "Ceph check skipped by user flag (--ignore-ceph-check)": "Controllo Ceph saltato dal flag utente (--ignore-ceph-check)", @@ -487,14 +691,23 @@ "Ceph repository configured for PVE 9": "Repository Ceph configurato per PVE 9", "Ceph repository signature verification failed; installation has been stopped": "verifica della firma del repository Ceph non riuscita;l'installazione è stata interrotta", "Ceph version OK:": "Versione Ceph OK:", + "Certificate errors are logged in /config/log/letsencrypt inside the container.": "Gli errori del certificato sono registrati in /config/log/letsencrypt all'interno del contenitore.", "Certificate fingerprint of the PBS server:": "impronta digitale del certificato del server PBS:", + "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL": "Fornitore di certificati: vuoto per Let's Encrypt, zerossl per ZeroSSL", + "Change GPU acceleration?": "Cambiare l'accelerazione GPU?", "Change Language": "Cambia lingua", "Change Release Channel": "Cambia canale di rilascio", + "Change it after the first login.": "Modificarlo dopo il primo login.", + "Change or add an environment variable?": "Cambiare o aggiungere una variabile di ambiente?", + "Change the access network?": "Cambiare la rete di accesso?", + "Changedetection.io provides free, open-source web page monitoring, notification and change detection.": "Changedetection.io fornisce il monitoraggio gratuito, la notifica e il rilevamento delle modifiche della pagina web open source.", "Changes applied. A system reboot is recommended for them to take full effect.": "Modifiche applicate. Si consiglia di riavviare il sistema affinché abbiano pieno effetto.", "Changes have been applied to the configuration file.": "Le modifiche sono state applicate al file di configurazione.", "Changes will apply after reboot.": "Le modifiche verranno applicate dopo il riavvio.", "Changing Release Channel": "Modifica del canale di rilascio", "Changing the machine type on an existing installed VM is not safe: it changes the chipset and PCI slot layout, which typically prevents the guest OS from booting.": "La modifica del tipo di macchina su una VM installata esistente non è sicura: modifica il chipset e il layout dello slot PCI, che in genere impedisce l'avvio del sistema operativo guest.", + "Changing the rootfs or its storage requires a separate migration": "Cambiare i rootf o il suo storage requires una migrazione separata", + "Changing the storage or size of a disk requires a migration; empty disks are not created": "Cambiare lo storage o la dimensione di un disco requires una migrazione; i dischi vuoti non vengono creati", "Check": "Controllo", "Check BIOS/UEFI in Hardware > BIOS — must match what the original VM used": "Controlla BIOS/UEFI in Hardware > BIOS: deve corrispondere a quello utilizzato dalla VM originale", "Check Coral USB/M.2 detection": "Controllare il rilevamento Coral USB/M.2", @@ -520,6 +733,7 @@ "Check the service status manually if needed.": "Controlla manualmente lo stato del servizio, se necessario.", "Checking MOTD configuration...": "Controllo della configurazione MOTD...", "Checking NVIDIA driver status with nvidia-smi": "Controllo dello stato del driver NVIDIA con nvidia-smi", + "Checking OCI": "Controllo OCI", "Checking VFIO modules...": "Controllo dei moduli VFIO...", "Checking VM virtual display model...": "Verifica del modello di visualizzazione virtuale della VM in corso...", "Checking ZFS autotrim configuration...": "Controllo della configurazione del taglio automatico ZFS in corso...", @@ -531,7 +745,22 @@ "Checking if the server belongs to OVH...": "Verifica se il server appartiene a OVH...", "Checking kernel headers and build tools...": "Controllo delle intestazioni del kernel e degli strumenti di compilazione in corso...", "Checking remaining interfaces": "Controllo delle interfacce rimanenti", + "Checking that the container keeps running...": "Controllare che il contenitore continui a funzionare...", "Checking that this version builds against the running kernel...": "controllo che questa versione venga compilata rispetto al kernel in esecuzione...", + "Checking the GPU of the machine learning container...": "Controllare la GPU del contenitore di machine learning...", + "Checking the container before recreating it...": "Controllare il contenitore prima di ricrearlo...", + "Checking the container before the update...": "Controllare il contenitore prima dell'aggiornamento...", + "Checking the device permissions for the application user...": "Controllare le autorizzazioni del dispositivo per l'utente dell'applicazione...", + "Checking the image compatibility:": "Controllare la compatibilità dell'immagine:", + "Checking the image in the registry...": "Controllare l'immagine nel registro...", + "Checking the interrupted operation...": "Controllare il operation interrotto...", + "Checking the interrupted stack operation...": "Controllare la pila interrotta operation...", + "Checking the new image without starting it:": "Controllare la nuova immagine senza avviarla:", + "Checking the remote...": "Controllare il telecomando...", + "Checking the restored installation": "Controllare l'installazione restaurata", + "Checking the restored installation...": "Controllare l'installazione restaurata...", + "Checking the stack before the update...": "Controllare lo stack prima dell'aggiornamento...", + "Checking the updated stack...": "Controllare lo stack aggiornato...", "Checklist post-upgrade finished. Warnings:": "Elenco di controllo post-aggiornamento terminato. Avvertenze:", "Checklist pre-check finished. Warnings:": "Controllo preliminare della lista di controllo terminato. Avvertenze:", "Checks for LVM and storage issues": "Verifica la presenza di problemi di LVM e di archiviazione", @@ -588,6 +817,9 @@ "Choose the type of virtual system to install:": "Scegli il tipo di sistema virtuale da installare:", "Choose what to do with the selected disk:": "Scegli cosa fare con il disco selezionato:", "Choose where to save the backup:": "Scegli dove salvare il backup:", + "Chrome is the official web browser from Google, built to be fast, secure, and customizable.": "Chrome è il browser web ufficiale di Google, costruito per essere veloce, sicuro e personalizzabile.", + "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.": "Chromium è un progetto di browser open source che mira a costruire un modo più sicuro, più veloce e più stabile per tutti gli utenti di sperimentare il web.", + "Circular dependency:": "Dipendenza circolare:", "Clean disk metadata": "Pulisci i metadati del disco", "Cleaned up": "Pulito", "Cleaning cached files...": "Pulizia dei file memorizzati nella cache...", @@ -611,21 +843,29 @@ "Clearing login credentials...": "Cancellazione delle credenziali di accesso...", "Client (run a bandwidth test to a server)": "Client (esegui un test della larghezza di banda su un server)", "Client determines best version to use": "Il client determina la versione migliore da utilizzare", + "Clients reach the VPN through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "I client raggiungono la VPN attraverso l'indirizzo pubblico e la porta UDP data durante l'installazione, in modo che la porta debba essere inoltrata a questo contenitore.", "Cloning Coral driver repository (feranick fork)...": "Clonazione del repository dei driver Coral (fork feranick)...", "Cloning Lynis from GitHub...": "Clonazione di Lynis da GitHub...", "Cloning and applying NVIDIA patch (keylase/nvidia-patch)...": "Clonazione e applicazione della patch NVIDIA (keylase/nvidia-patch)...", "Closed": "Chiuso", + "Cloud storage synchronization and FUSE mounts": "Sincronizzazione di storage cloud e supporti FUSE", "Cloud-Init Automated Installers": "Programmi di installazione automatizzati Cloud-Init", "Cluster certificates updated": "Certificati cluster aggiornati", "Cluster configuration (advanced)": "Configurazione cluster (avanzata)", "Cluster data will be applied automatically at next boot.": "i dati del cluster verranno applicati automaticamente al prossimo avvio.", "Cluster upgrade mode": "Modalità di aggiornamento del cluster", + "Code-server is VS Code running on a remote server, accessible through the browser.": "Code-server è VS Code in esecuzione su un server remoto, accessibile tramite il browser.", + "CodeProject.AI Server": "CodeProject. AI Server", "Command": "Comando", + "Command override for an unknown service:": "Comando override per un servizio sconosciuto:", "Commenting any residual Bookworm lines in *.list...": "Commentando eventuali righe residue di Bookworm in *.list...", "Commenting legacy PVE 8 repository .list files (if any)...": "Commento dei file .list del repository PVE 8 legacy (se presenti)...", "Commenting legacy ceph.list (if present)...": "Commento legacy ceph.list (se presente)...", "Common Issues Check": "Controllo dei problemi comuni", + "Common root for the published views": "Radice comune per le opinioni pubblicate", + "Communication & Community": "Comunicazione e Comunità", "Community Scripts": "Script di comunità", + "Community single-container Home Assistant OS image": "Immagine del sistema operativo Home Assistant", "Compatibility check": "Controllo di compatibilità", "Compatibility check — OK": "Controllo di compatibilità: OK", "Compatibility check — issues detected": "Controllo di compatibilità: problemi rilevati", @@ -640,24 +880,31 @@ "Complete restore": "Ripristino completo", "Complete the DSM installation wizard": "Completa la procedura guidata di installazione del DSM", "Complete the ZimaOS installation wizard": "Completa la procedura guidata di installazione di ZimaOS", + "Complete the media server and Seerr accounts, the Bazarr providers and the SABnzbd Usenet credentials when they are selected.": "Completare gli account server multimediali e Seerr, i provider Bazarr e i Creden Usenet edentials quando vengono selezionati.", + "Completed": "Completato", "Completed Successfully with GPU passthrough configured!": "Completato con successo con passthrough GPU configurato!", "Completed Successfully!": "Completato con successo!", "Completed with errors —": "Completato con errori —", "Completed.": "Completato.", "Completed. Devices added to VM {vmid}: {count}.": "completato. Dispositivi aggiunti alla VM {vmid}: {count}.", "Completed. Press Enter to return to menu...": "Completato. Premere Invio per tornare al menu...", + "Completing its final cleanup...": "Completa la sua pulizia finale...", "Completing pending package configurations...": "completamento delle configurazioni dei pacchetti in sospeso...", "Compliance checking (PCI-DSS, HIPAA, etc.)": "Controllo della conformità (PCI-DSS, HIPAA, ecc.)", "Component to uninstall manually (no --auto-uninstall yet):": "Componente da disinstallare manualmente (ancora no --auto-uninstall):", "Component was installed on the backup source but no matching hardware was found on this host.": "il componente è stato installato sull'origine del backup ma non è stato trovato hardware corrispondente su questo host.", "Component:": "Componente:", "Components to uninstall (manual for now):": "Componenti da disinstallare (manuale per ora):", + "Compose capabilities validated in the LXC user namespace:": "Compose funzionalità convalidate nello spazio nome utente LXC:", + "Compose file of the application": "Compila il file dell'applicazione", + "Compose file of this host": "Compila il file di questo host", "Compressed size:": "Dimensioni compresse:", "Compressing": "Compressione", "Compression Tools": "Strumenti di compressione", "Concise output of logical volumes": "Output conciso di volumi logici", "Concise output of physical volumes": "Output conciso di volumi fisici", "Concise output of volume groups": "Output conciso dei gruppi di volumi", + "Concurrent change while restoring the start at boot setting": "Cambiamento corrente durante il ripristino dell'avvio all'impostazione di avvio", "Configuration Analysis": "Analisi della configurazione", "Configuration Menu": "Menù di configurazione", "Configuration Summary:": "Riepilogo della configurazione:", @@ -666,11 +913,13 @@ "Configuration can continue now and will be effective after reboot.": "La configurazione può continuare ora e sarà effettiva dopo il riavvio.", "Configuration completed successfully!": "Configurazione completata con successo!", "Configuration file for container": "File di configurazione per il contenitore", + "Configuration files generated:": "File di configurazione generati:", "Configuration has been stopped due to high reset risk.": "La configurazione è stata interrotta a causa dell'elevato rischio di ripristino.", "Configuration has been stopped to prevent an unusable VM state.": "La configurazione è stata interrotta per impedire uno stato inutilizzabile della VM.", "Configuration has been stopped to prevent leaving the VM in an unusable state.": "La configurazione è stata interrotta per evitare di lasciare la VM in uno stato inutilizzabile.", "Configuration name:": "Nome della configurazione:", "Configuration sections that will be REMOVED": "Sezioni di configurazione che verranno rimosse", + "Configuration size in GB": "Dimensione di configurazione in GB", "Configuration to be Removed": "Configurazione da rimuovere", "Configuration will continue now and be effective after reboot.": "La configurazione continuerà ora e sarà effettiva dopo il riavvio.", "Configuration:": "Configurazione:", @@ -713,6 +962,7 @@ "Configuring Proxmox jail...": "Configurazione della prigione Proxmox in corso...", "Configuring TCP optimizations...": "Configurazione delle ottimizzazioni TCP...", "Configuring TPM device": "Configurazione del dispositivo TPM", + "Configuring Unpackerr...": "Configurare Unpackerr...", "Configuring VFIO modules...": "Configurazione dei moduli VFIO...", "Configuring VM": "Configurazione della macchina virtuale", "Configuring bandwidth limit for vzdump...": "Configurazione del limite di larghezza di banda per vzdump...", @@ -728,8 +978,11 @@ "Configuring max FD limit / ulimit...": "Configurazione del limite FD massimo/limite u...", "Configuring max user watches...": "Configurazione del numero massimo di orologi utente...", "Configuring pigz as a faster replacement for gzip...": "Configurazione di pigz come sostituto più veloce di gzip...", + "Configuring qBittorrent...": "Configurare qBittorrent...", "Configuring snapshot schedules...": "Configurazione delle pianificazioni delle istantanee...", "Configuring system time settings...": "Configurazione delle impostazioni dell'ora del sistema in corso...", + "Configuring the Radarr root folder...": "Configurazione della cartella radice Radarr...", + "Configuring the Sonarr root folder...": "Configurazione della cartella radice Sonarr...", "Configuring vfio-pci binding...": "Configurazione dell'associazione vfio-pci in corso...", "Confirm Borg passphrase": "conferma la passphrase Borg", "Confirm Borg passphrase:": "Conferma la passphrase Borg:", @@ -751,6 +1004,7 @@ "Confirm export": "Conferma l'esportazione", "Confirm password for": "Conferma la password per", "Confirm recovery passphrase:": "Conferma la passphrase di ripristino:", + "Confirm that host data is not reverted": "Confermare che i dati dell'host non vengono convertiti", "Confirm the keyfile passphrase:": "conferma la passphrase del file di chiavi:", "Confirm the mount path is visible.": "Confermare che il percorso di montaggio sia visibile.", "Confirm the password:": "Conferma la password:", @@ -762,7 +1016,11 @@ "Conflicting path included in backup:": "Percorso in conflitto incluso nel backup:", "Conflicting utilities removed": "Utilità in conflitto rimosse", "Connect a Coral Accelerator and try again.": "Collega un Coral Accelerator e riprova.", + "Connect your devices and users together in your own secure virtual private network.": "Collegare i dispositivi e gli utenti insieme nella propria rete privata sicura.", + "Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.": "Collegare i dispositivi in una rete di sovrapposizione WireGuard® sicura con i controlli di accesso SSO, MFA e granulare.", "Connected": "Collegato", + "Connecting Radarr to qBittorrent...": "Collegare Radarr a qBittorrent...", + "Connecting Sonarr to qBittorrent...": "Collegare Sonarr a qBittorrent...", "Connecting to PBS and starting backup...": "Connessione a PBS e avvio del backup in corso...", "Connection Details:": "Dettagli di connessione:", "Connection Error": "Errore di connessione", @@ -774,6 +1032,7 @@ "Consider removing its configuration": "Valuta la possibilità di rimuoverne la configurazione", "Consider security implications for production environments": "Considerare le implicazioni sulla sicurezza per gli ambienti di produzione", "Consider visiting the repository and supporting the project.": "valuta la possibilità di visitare il repository e sostenere il progetto.", + "Console log:": "Console log:", "Container": "Contenitore", "Container — LXC root directories": "Contenitore: directory root LXC", "Container ID": "ID contenitore", @@ -783,30 +1042,50 @@ "Container Path": "Percorso del contenitore", "Container Path:": "Percorso del contenitore:", "Container Status": "Stato del contenitore", + "Container checked": "Contenitore controllato", "Container configuration not found": "Configurazione del contenitore non trovata", + "Container configured (not started):": "Contenitore configurato (non avviato):", + "Container converted to privileged": "Contenitore convertito in privilegiato", + "Container created:": "Contenitore creato:", "Container did not become ready in time. Skipping driver installation.": "Il contenitore non è stato pronto in tempo. Saltare l'installazione del driver.", "Container did not start in time.": "Il contenitore non è stato avviato in tempo.", "Container distro": "Distribuzione contenitore", "Container does not have apt-get available. Coral driver installation only supports Debian/Ubuntu containers.": "Il contenitore non ha apt-get disponibile. L'installazione del driver Coral supporta solo i contenitori Debian/Ubuntu.", + "Container installed, but without a verifiable record for future updates.": "Contenitore installato, ma senza un record verificabile per aggiornamenti futuri.", "Container is already stopped.": "Il contenitore è già fermo.", "Container is running. Restart to apply changes?": "Il contenitore è in esecuzione. Riavviare per applicare le modifiche?", "Container is stopped. Start it now to verify the mount works?": "Il contenitore è fermo. Avviarlo ora per verificare che il montaggio funzioni?", + "Container kept with its data; the installation was not validated:": "Contenitore mantenuto con i suoi dati; l'installazione non è stata validata:", "Container mount point:": "Punto di montaggio del contenitore:", "Container must be stopped before conversion": "Il contenitore deve essere arrestato prima della conversione", + "Container prepared for the stack:": "Contenitore preparato per la pila:", + "Container recreated": "Contenitore recretato", + "Container removed:": "Contenitore rimosso:", "Container restarted successfully": "Il contenitore è stato riavviato correttamente", + "Container running steadily": "Contenitore in esecuzione costante", + "Container started": "Contenitore iniziato", "Container started successfully": "Il contenitore è stato avviato correttamente", "Container started successfully.": "Il contenitore è stato avviato correttamente.", "Container started.": "Il contenitore è stato avviato.", + "Container stopped": "Contenitore fermato", "Container stopped.": "Contenitore fermo.", "Container successfully converted to privileged.": "Contenitore convertito correttamente in privilegiato.", "Container template— LXC templates": "Modello contenitore: modelli LXC", + "Container volume": "Volume del contenitore", + "Container volume (included in backups)": "Volume contenitore (incluso nei backup)", "Container will pick up the mount on next start": "Il contenitore raccoglierà la montatura al prossimo avvio", "Container with ID": "Contenitore con ID", "Container:": "Contenitore:", + "Containers & Docker": "Contenitori & Docker", + "Containers returned to their previous state": "Contenitori tornati al loro stato precedente", + "Containers that are removed:": "Contenitori che vengono rimossi:", + "Containers that will be created (one LXC per service, on a private network):": "Contenitori che verranno creati (un LXC per servizio, su una rete privata):", + "Containers:": "Contenitori:", "Contains files": "Contiene file", "Contains:": "Contiene:", "Content Types": "Tipi di contenuto", "Content Types:": "Tipi di contenuto:", + "Content collaboration platform": "piattaforma di collaborazione dei contenuti", "Content is usually images for VM block devices.": "Il contenuto è solitamente costituito da immagini per i dispositivi a blocchi VM.", "Content type is fixed to:": "Il tipo di contenuto è fisso su:", "Content:": "Contenuto:", @@ -817,10 +1096,12 @@ "Continue the Windows installation as usual.": "Continua l'installazione di Windows come al solito.", "Continue with Coral TPU configuration only?": "Continuare solo con la configurazione Coral TPU?", "Continue with live apply now? SSH may disconnect immediately.": "Continuare con la candidatura dal vivo adesso? SSH potrebbe disconnettersi immediatamente.", + "Continue with the experimental HAOS One profile?": "Continuare con il profilo sperimentale HAOS One?", "Continue with the import?": "continuare con l'importazione?", "Continue: Proceed with conversion": "Continua: Procedi con la conversione", "Continue?": "Continuare?", "Continuing with your selection.": "Continuando con la selezione.", + "Contradictory tmpfs options": "Opzioni di tmpfs di contrasto", "Controller": "Controllore", "Controller + NVMe": "Controller + NVMe", "Controller + NVMe assignment will be written now and become active after host reboot.": "L'assegnazione Controller + NVMe verrà scritta ora e diventerà attiva dopo il riavvio dell'host.", @@ -849,7 +1130,11 @@ "Converting disk": "Conversione del disco", "Converting file ownership (this may take several minutes)...": "Conversione della proprietà del file (l'operazione potrebbe richiedere diversi minuti)...", "Converting image using command:": "Conversione dell'immagine utilizzando il comando:", + "Converting the container to privileged...": "Convertire il contenitore in...", "Converts to deb822; keeps .list backups as .bak": "Converte in deb822; mantiene i backup .list come .bak", + "Coordinated backups require zstd": "Backup coordinati require zstd", + "Cops by Sébastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server.": "Cops di Sébastien Lucas, ora mantenuto da MikesPub, sta per Calibre OPDS (e HTML) Php Server.", + "Copy a peer configuration to the host with: pct pull /config/peer1/peer1.conf peer1.conf": "Copiare una configurazione peer all'host con: pct pull /config/peer1/peer1.conf peer1.conf", "Copy failed": "copia non riuscita", "Copy that file offsite yourself, or download it from the Monitor.": "copia tu stesso il file fuori sede o scaricalo dal Monitor.", "Copy the correct keyfile to this host and rerun Restore — or pick an unencrypted backup.": "copia il file di chiavi corretto su questo host ed esegui nuovamente il ripristino oppure scegli un backup non crittografato.", @@ -864,6 +1149,7 @@ "Coral M.2 Apex configuration added - device ready": "Aggiunta configurazione Coral M.2 Apex: dispositivo pronto", "Coral M.2 Apex configuration added - device will be available after reboot": "Aggiunta configurazione Coral M.2 Apex: il dispositivo sarà disponibile dopo il riavvio", "Coral M.2 Apex detected, configuring...": "Rilevato Coral M.2 Apex, configurazione in corso...", + "Coral PCIe/M.2 node (e.g. /dev/apex_0)": "Coral PCIe/M.2 nodo (ad esempio /dev/apex 0)", "Coral TPU Installation": "Installazione TPU Coral", "Coral TPU Uninstall": "Disinstallazione di Coral TPU", "Coral TPU device nodes detected with correct group (apex).": "Nodi del dispositivo Coral TPU rilevati con il gruppo corretto (apice).", @@ -876,19 +1162,33 @@ "Coral USB configured but device not currently connected": "Coral USB configurato ma dispositivo attualmente non connesso", "Coral USB runtime installed. No reboot required.": "Runtime USB Coral installato. Nessun riavvio richiesto.", "Coral hardware configuration completed for container": "Configurazione hardware Coral completata per container", + "Coral is only offered for Frigate and CodeProject.AI": "Coral è offerto solo per Frigate e CodeProject. AI", "Coral kernel modules unloaded.": "Moduli del kernel Coral scaricati.", "Coral packages purged.": "Pacchetti Coral eliminati.", "Coral uninstallation completed.": "Disinstallazione di Coral completata.", "Core Proxmox packages reinstalled successfully": "I pacchetti Core Proxmox sono stati reinstallati correttamente", + "Core is running, but not responding over HTTP on 80/8123": "Core è in esecuzione, ma non risponde su HTTP su 80/8123", + "Core is still on the initial installation page": "Core è ancora sulla pagina iniziale di installazione", "Core packages": "Pacchetti principali", + "Cores": "Nuclei", + "Corrupted gzip layer": "Strato di gzip rotto", "Could not add": "Impossibile aggiungere", "Could not add disk": "Impossibile aggiungere il disco", + "Could not add the device to the container:": "Non è possibile aggiungere il dispositivo al contenitore:", + "Could not add the mount point:": "Non è possibile aggiungere il punto di montaggio:", + "Could not apply the Compose extra hosts": "Non potrebbe applicare il Compose host extra", + "Could not apply the Compose supplementary groups": "Non è possibile applicare i gruppi complementari Compose", + "Could not apply the Jellyfin configuration:": "Non è possibile applicare la configurazione Jellyfin:", + "Could not apply the installer profile": "Non potrebbe applicare il profilo dell'installatore", + "Could not apply the pre-start repair:": "Non poteva applicare la riparazione pre-start:", "Could not assign disk": "Impossibile assegnare il disco", "Could not authorize the key via 'pct exec' on": "Impossibile autorizzare la chiave tramite 'pct exec'", "Could not back up the existing auth.json": "Impossibile eseguire il backup del file auth.json esistente", "Could not change VM virtual display to vga: std": "Impossibile modificare la visualizzazione virtuale della VM in vga: std", + "Could not check the NVIDIA GPU": "Non poteva controllare la GPU NVIDIA", "Could not clone any gasket-driver repository. Check your internet connection and": "Impossibile clonare un repository gasket-driver. Controlla la connessione Internet e", "Could not configure IOMMU kernel parameters automatically. Configure manually and reboot.": "Impossibile configurare automaticamente i parametri del kernel IOMMU. Configura manualmente e riavvia.", + "Could not convert the OCI rootfs to privileged": "Non poteva convertire i rootf OCI a privilegiati", "Could not copy the PVE keyfile into place. Check permissions on:": "impossibile copiare il file di chiavi PVE nella sua posizione. Controlla i permessi su:", "Could not copy the keyfile into place.": "impossibile copiare il file di chiavi in ​​posizione.", "Could not copy the keyfile into place. Check permissions on:": "impossibile copiare il file di chiavi in ​​posizione. Controlla i permessi su:", @@ -898,6 +1198,9 @@ "Could not create or access directory:": "Impossibile creare o accedere alla directory:", "Could not create temporary directory:": "Impossibile creare la directory temporanea:", "Could not create temporary working directory.": "Impossibile creare la directory di lavoro temporanea.", + "Could not create the container:": "Non poteva creare il contenitore:", + "Could not create the initial administrator": "Non è possibile creare l'amministratore iniziale", + "Could not create the service:": "Non poteva creare il servizio:", "Could not detect apex major number from /proc/devices. Load the apex module first: modprobe apex": "Impossibile rilevare il numero principale dell'apice da /proc/devices. Caricare prima il modulo apex: modprobe apex", "Could not detect the CIFS mount for this directory. Try accessing it manually.": "Impossibile rilevare il montaggio CIFS per questa directory. Prova ad accedervi manualmente.", "Could not determine a valid ISO storage directory.": "Impossibile determinare una directory di archiviazione ISO valida.", @@ -907,7 +1210,9 @@ "Could not download recovery blob from PBS.": "Impossibile scaricare il BLOB di ripristino da PBS.", "Could not download the NVIDIA Container Toolkit repository definition.": "impossibile scaricare la definizione del repository NVIDIA Container Toolkit.", "Could not download the NVIDIA Container Toolkit signing key.": "impossibile scaricare la chiave di firma di NVIDIA Container Toolkit.", + "Could not download the image": "Non poteva scaricare l'immagine", "Could not download the installer.": "Impossibile scaricare il programma di installazione.", + "Could not enable the privileged profile before the first start": "Non poteva consentire il profilo privilegiato prima del primo inizio", "Could not export ZFS pool": "Impossibile esportare il pool ZFS", "Could not extract from PBS.": "Impossibile estrarre da PBS.", "Could not fetch keylase/nvidia-patch supported list — patch reapply compatibility is not verified.": "Impossibile recuperare l'elenco supportato da keylase/nvidia-patch: la compatibilità con la riapplicazione della patch non è stata verificata.", @@ -921,34 +1226,53 @@ "Could not install exFAT tools automatically.": "Impossibile installare automaticamente gli strumenti exFAT.", "Could not install sshpass automatically (no internet?). Falling back to manual paste mode — you'll see the line to copy onto the server next.": "Impossibile installare automaticamente sshpass (niente Internet?).Tornando alla modalità incolla manuale: successivamente vedrai la riga da copiare sul server.", "Could not install the NVIDIA Container Toolkit signing key.": "impossibile installare la chiave di firma di NVIDIA Container Toolkit.", + "Could not install the required packages:": "Non è possibile installare i pacchetti required:", + "Could not install the stack startup hook": "Non è possibile installare il gancio di avvio stack", "Could not install vzdump hook in /etc/vzdump.conf": "Impossibile installare l'hook vzdump in /etc/vzdump.conf", "Could not load shared functions. Script cannot continue.": "Impossibile caricare le funzioni condivise. Lo script non può continuare.", + "Could not load the host kernel module:": "Non poteva caricare il modulo del kernel host:", "Could not locate imported disk in VM config.": "Impossibile individuare il disco importato nella configurazione della VM.", "Could not mount": "Impossibile montare", "Could not mount ISO on device": "Impossibile montare l'ISO sul dispositivo", + "Could not mount the container filesystem:": "Non poteva montare il filesystem del contenitore:", + "Could not obtain an intact image after two attempts": "Non poteva ottenere un'immagine intatta dopo due tentativi", "Could not parse OVF file, or no disk image references found.": "Impossibile analizzare il file OVF o nessun riferimento all'immagine del disco trovato.", "Could not prepare on-boot restore service. Nothing new was scheduled.": "impossibile preparare il servizio di ripristino all'avvio. Non era previsto nulla di nuovo.", + "Could not prepare the NVIDIA driver links": "Non è possibile preparare i collegamenti del driver NVIDIA", + "Could not prepare the file bind mount target:": "Non poteva preparare il target di montaggio del file bind:", "Could not publish pending restore. Previous pending restore was kept.": "impossibile pubblicare il ripristino in sospeso. Il precedente ripristino in sospeso è stato mantenuto.", "Could not push the key. Check the password and that": "Impossibile premere la chiave. Controlla la password e quello", + "Could not query the image registry": "Non potrebbe query il registro di immagine", "Could not read SMART data from": "Impossibile leggere i dati SMART da", "Could not read VM configuration.": "Impossibile leggere la configurazione della VM.", + "Could not read the CUDA compute capability": "Non poteva leggere la capacità di calcolo CUDA", + "Could not read the NVIDIA driver version": "Non poteva leggere la versione del driver NVIDIA", "Could not remount automatically. Try manually or check credentials.": "Impossibile rimontare automaticamente. Prova manualmente o controlla le credenziali.", "Could not remove VM automatically. Run manually:": "Impossibile rimuovere la VM automaticamente. Esegui manualmente:", "Could not remove previous DKMS tree at": "Impossibile rimuovere l'albero DKMS precedente in", + "Could not reserve a private network for the stack": "Non poteva prenotare una rete privata per lo stack", + "Could not resolve the Compose user:": "Non è possibile risolvere l'utente Compose:", + "Could not resolve the OCI manifest of the image:": "Non poteva risolvere il manifesto OCI dell'immagine:", + "Could not resolve the OCI manifest:": "Non poteva risolvere il manifesto OCI:", "Could not restart ProxMenux Monitor service.": "Impossibile riavviare il servizio ProxMenux Monitor.", "Could not restart the service — start it manually with systemctl start": "Impossibile riavviare il servizio: avvialo manualmente con systemctl start", "Could not retrieve versions list from NVIDIA. Please check your internet connection.": "Impossibile recuperare l'elenco delle versioni da NVIDIA. Controlla la tua connessione Internet.", + "Could not reuse the persistent disk:": "Non poteva riutilizzare il disco persistente:", "Could not run NVIDIA patch script. Please verify repository and driver version.": "Impossibile eseguire lo script della patch NVIDIA. Verificare il repository e la versione del driver.", "Could not set VM virtual display to vga: std": "Impossibile impostare il display virtuale della VM su vga: std", "Could not set boot order for": "Impossibile impostare l'ordine di avvio per", + "Could not set the container entrypoint": "Non poteva impostare il punto di ingresso del contenitore", "Could not stage pending restore path:": "Impossibile organizzare il percorso di ripristino in sospeso:", "Could not stage pending restore. Nothing new was scheduled.": "impossibile eseguire il ripristino in sospeso. Non era previsto nulla di nuovo.", "Could not stop LXC": "Impossibile fermare LXC", + "Could not translate the Compose command/entrypoint": "Non poteva tradurre il comando Compose/entrypoint", "Could not unload nouveau module (may be in use). The blacklist will take effect after reboot. Installation will continue but a reboot will be required.": "Impossibile scaricare il modulo nouveau (potrebbe essere in uso). La lista nera avrà effetto dopo il riavvio. L'installazione continuerà ma sarà necessario un riavvio.", "Could not unmount": "Impossibile smontare", + "Could not unmount the container filesystem:": "Non poteva smontare il filesystem del contenitore:", "Could not unmount — disk may be busy. Removing fstab entry anyway.": "Impossibile smontare: il disco potrebbe essere occupato. Rimozione comunque della voce fstab.", "Could not update config file.": "Impossibile aggiornare il file di configurazione.", "Could not write to:": "Impossibile scrivere a:", + "Crafty Controller default login": "Crafty Controller login predefinito", "Create Directory": "Crea directory", "Create GPT and one partition:": "Crea GPT e una partizione:", "Create GPT partition": "Crea partizione GPT", @@ -971,6 +1295,7 @@ "Create a fresh GPT + ext4 partition and mount it?": "Creare una nuova partizione GPT + ext4 e montarla?", "Create a new dataset in a ZFS pool": "Crea un nuovo set di dati in un pool ZFS", "Create a new group for isolation": "Crea un nuovo gruppo per l'isolamento", + "Create and edit Matroska files from a browser": "Creare e modificare i file Matroska da un browser", "Create credentials file (recommended):": "Crea un file delle credenziali (consigliato):", "Create directory": "Crea rubrica", "Create export directory:": "Crea directory di esportazione:", @@ -982,6 +1307,7 @@ "Create scheduled backup job": "Crea un processo di backup pianificato", "Create share directory:": "Crea directory condivisa:", "Create shared directory:": "Crea directory condivisa:", + "Create this LXC in privileged mode?": "Creare questo LXC in modalità privilegiata?", "Created common remapped user": "Creato utente rimappato comune", "Created directory on host:": "Directory creata sull'host:", "Created persistent names for": "Creati nomi persistenti per", @@ -996,6 +1322,8 @@ "Creating UID remapping for unprivileged container compatibility...": "Creazione della rimappatura UID per la compatibilità del contenitore non privilegiato...", "Creating VM with the above configuration": "Creazione della VM con la configurazione precedente", "Creating VM...": "Creazione della macchina virtuale...", + "Creating a backup of": "Creazione di un backup", + "Creating a backup of the container...": "Creazione di un backup del contenitore...", "Creating backup of configuration file...": "Creazione del backup del file di configurazione in corso...", "Creating backup of network interfaces configuration...": "Creazione del backup della configurazione delle interfacce di rete in corso...", "Creating compressed archive...": "Creazione archivio compresso...", @@ -1005,6 +1333,11 @@ "Creating partition table and partition...": "Creazione della tabella delle partizioni e della partizione in corso...", "Creating partition...": "Creazione della partizione...", "Creating pigz wrapper script...": "Creazione dello script wrapper pigz in corso...", + "Creating the backup": "Creazione del backup", + "Creating the container...": "Creare il contenitore...", + "Creating the initial administrator...": "Creazione dell'amministratore iniziale...", + "Creating the temporary data container": "Creazione del contenitore dati temporaneo", + "Creative & Design": "Creativo e design", "Credentials are correct": "Le credenziali sono corrette", "Credentials cleared. jwt_secret and API tokens preserved.": "Credenziali cancellate. jwt_secret e token API conservati.", "Credentials file created securely.": "File delle credenziali creato in modo sicuro.", @@ -1014,6 +1347,8 @@ "Cross-host restore: guest IDs in backup overlap live IDs on target:": "Ripristino tra host: gli ID guest nel backup si sovrappongono agli ID live sulla destinazione:", "Cross-kernel restore — kernel-tied paths merged, not copied": "ripristino cross-kernel: percorsi collegati al kernel uniti, non copiati", "Cross-kernel — paths hidden from picker": "Cross-kernel: percorsi nascosti dal selettore", + "Cross-platform file sharing made easy.": "La condivisione di file cross-platform ha reso facile.", + "Cross-platform monitoring tool.": "Strumento di monitoraggio multipiattaforma.", "Cross-version detected — safe restore mode": "Rilevata versione incrociata: modalità di ripristino sicuro", "Current": "Attuale", "Current CIFS mounts:": "Supporti CIFS attuali:", @@ -1023,6 +1358,8 @@ "Current NFS client script supports privileged LXC only.": "Lo script client NFS corrente supporta solo LXC privilegiato.", "Current NFS exports in CT": "Attuali esportazioni NFS in CT", "Current NFS mounts:": "Supporti NFS attuali:", + "Current NVIDIA inventory resolved: a refresh is required": "Corrente inventario NVIDIA risolto: un aggiornamento è required", + "Current NVIDIA inventory resolved: no refresh is required": "L'inventario NVIDIA corrente risolto: nessun aggiornamento è required", "Current Network Configuration": "Configurazione di rete corrente", "Current PVE Version": "Versione PVE attuale", "Current ProxMenux host scripts register remote shares as Proxmox storages using pvesm.": "Gli attuali script host ProxMenux registrano le condivisioni remote come archivi Proxmox utilizzando pvesm.", @@ -1046,6 +1383,7 @@ "Current user": "Utente attuale", "Current user UID, GID and groups": "UID, GID e gruppi dell'utente corrente", "Current version:": "Versione attuale:", + "Currently": "Attualmente", "Currently Mounted:": "Attualmente montato:", "Currently configured target:": "destinazione attualmente configurata:", "Currently mounted:": "Attualmente montato:", @@ -1066,6 +1404,7 @@ "Custom message added to MOTD": "Messaggio personalizzato aggiunto a MOTD", "Custom options": "Opzioni personalizzate", "Custom path": "Percorso personalizzato", + "Custom path cancelled": "Percorso personalizzato annullato", "Custom path...": "Percorso personalizzato...", "Custom paths are included in BOTH default and custom backup profiles.": "I percorsi personalizzati sono inclusi SIA nei profili di backup predefiniti che in quelli personalizzati.", "Custom paths currently saved: {count}.": "percorsi personalizzati attualmente salvati: {count}.", @@ -1078,6 +1417,8 @@ "Customization": "personalizzazione", "Customize bashrc": "personalizza bashrc", "Customizing bashrc for root user...": "Personalizzazione bashrc per l'utente root...", + "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite.": "DB Browser per SQLite è uno strumento di alta qualità, visivo, open source per creare, progettare e modificare file di database compatibili con SQLite.", + "DHCP (automatic)": "DHCP (automatico)", "DISABLED unless you enable it": "DISABILITATO a meno che non lo abiliti", "DKMS add failed. Check": "Aggiunta DKMS non riuscita. Controllo", "DKMS build failed.": "Creazione DKMS non riuscita.", @@ -1090,15 +1431,34 @@ "DKMS registrations removed.": "registrazioni DKMS rimosse.", "DNS Resolution": "Risoluzione DNS", "DNS lookup for a domain": "Ricerca DNS per un dominio", + "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)": "Plugin DNS utilizzato con la convalida dei dns (cloudflare, duckdns, ovh...)", + "DNS server written in the client configurations": "Server DNS scritto nelle configurazioni client", + "DNS server written in the peer configurations (auto or an IP address)": "Server DNS scritto nelle configurazioni peer (auto o indirizzo IP)", + "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid.": "DOGWALK è il lungo progetto di seconda partita di Blender Studio, incentrato sulla creazione di un parco giochi di narrazione interattivo di dimensioni morsi. Gioca come un grande cane adorabile ed esplorare i boschi invernali con un bambino.", + "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games.": "DOSBox Staging è una continuazione moderna di DOSBox un emulatore gratuito e open source che consente l'esecuzione di software MS-DOS, in particolare videogiochi.", + "DVB device directory": "directory del dispositivo DVB", + "Data": "Dati", + "Data location": "Posizione dei dati", "Data size:": "Dimensione dei dati:", + "Data that is deleted with them:": "Dati che vengono cancellati con loro:", + "Data volume size in GB": "Dimensione del volume di dati in GB", + "Data volumes protected": "I volumi di dati protetti", "Data wipe complete.": "Cancellazione dei dati completata.", "Data wiped from": "Dati cancellati da", + "Database management in a single PHP file": "Gestione database in un unico file PHP", + "Database server proposed on the login page (empty = typed at each login)": "Server di database proposto nella pagina di login (vuoto = digitato ad ogni login)", + "Databases": "Databases", "Datastore name:": "Nome dell'archivio dati:", + "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow.": "Davos è uno strumento di automazione FTP che scansiona periodicamente le posizioni degli host date per i nuovi file. Può essere configurato per vari scopi, tra cui l'ascolto per i file specifici da visualizzare nella posizione dell'host, pronto per il download e quindi spostare, se required. Supporta anche le notifiche di completamento e le chiamate API a valle, per continuare il flusso di lavoro.", + "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways.": "Ddclient è un client Perl utilizzato per aggiornare le voci DNS dinamiche per gli account su Dynamic DNS Network Service Provider. Originariamente è stato scritto da Paul Burry ed è ora per lo più di wimpunk. Ha la capacità di aggiornare più di soli dyndns e può prendere il vostro WAN-ipaddress in pochi modi diversi.", "Deactivate Monitor": "Disattiva monitoraggio", "Deactivate ProxMenux Monitor": "Disattiva il ProxMenux Monitor", "Debian repositories missing; creating default source file": "Mancano i repository Debian; creazione del file sorgente predefinito", "Decompress backup manually": "Decomprimere manualmente il backup", "Decryption failed. The passphrase may be wrong, or the blob is corrupt. Try again?": "La decrittografia non è riuscita. La passphrase potrebbe essere errata oppure il BLOB è danneggiato. Riprova?", + "Dedicated container volume (included in backups)": "Volume contenitore dedicato (incluso nei backup)", + "Dedicated container volumes (included in backups)": "volumi di container dedicati (inclusi nei backup)", + "DeepSeek Harness “Everything is a Plugin“.": "DeepSeek Harness “Tutto è un Plugin“.", "Default ACLs applied for group inheritance.": "Gli ACL predefiniti hanno applicato l'ereditarietà del gruppo.", "Default Credentials": "Credenziali predefinite", "Default Gateway": "Gateway predefinito", @@ -1110,10 +1470,12 @@ "Default journald configuration restored": "Configurazione journal predefinita ripristinata", "Default location is /mnt/. The share will be mounted here on the host with open permissions so an unprivileged LXC can bind-mount and write to it. For LXC access, bind-mount this path with the LXC Mount Manager.": "La posizione predefinita è /mnt/. La condivisione verrà montata qui sull'host con autorizzazioni aperte in modo che un LXC non privilegiato possa eseguire il bind-mount e scrivere su di essa. Per l'accesso LXC, eseguire il bind-mount di questo percorso con LXC Mount Manager.", "Default location is /mnt/. The share will be mounted here on the host. Use this path in /etc/fstab. For LXC access, bind-mount this path with the LXC Mount Manager.": "La posizione predefinita è /mnt/. La condivisione verrà montata qui sull'host. Utilizzare questo percorso in /etc/fstab. Per l'accesso LXC, eseguire il bind-mount di questo percorso con LXC Mount Manager.", + "Default login": "Accesso predefinito", "Default options": "Opzioni predefinite", "Default options read/write": "Opzioni predefinite di lettura/scrittura", "Default will be used:": "Verrà utilizzato il valore predefinito:", "Default:": "Predefinito:", + "Default: only what the application needs": "Predefinito: solo ciò di cui l'applicazione ha bisogno", "Delete Borg target": "Elimina il bersaglio Borg", "Delete Export": "Elimina esportazione", "Delete Share": "Elimina condivisione", @@ -1122,7 +1484,10 @@ "Delete archive": "Elimina archivio", "Delete job": "Elimina lavoro", "Delete scheduled backup job?": "Eliminare il processo di backup pianificato?", + "Delete the image to free the space?": "Eliminare l'immagine per liberare lo spazio?", + "Delete the images to free the space?": "Eliminare le immagini per liberare lo spazio?", "Delete this corrupt archive and pick another": "Elimina questo archivio corrotto e scegline un altro", + "Deluge is a lightweight, Free Software, cross-platform BitTorrent client.": "Deluge è un client BitTorrent leggero e gratuito.", "Dependencies installed successfully": "Dipendenze installate correttamente", "Deploy with this configuration?": "Distribuire con questa configurazione?", "Deploying Secure Gateway...": "Distribuzione di Secure Gateway...", @@ -1177,9 +1542,15 @@ "Device added": "Dispositivo aggiunto", "Device already present in target VM — existing hostpci entry reused": "Dispositivo già presente nella VM di destinazione: voce hostpci esistente riutilizzata", "Device assignments will be written now and become active after reboot.": "Le assegnazioni dei dispositivi verranno scritte ora e diventeranno attive dopo il riavvio.", + "Device configuration cancelled": "Configurazione del dispositivo annullata", "Device hostname": "Nome host del dispositivo", + "Device node outside the supported profiles": "Nodo dispositivo al di fuori dei profili supportati", + "Device outside the supported profiles; NVIDIA and device trees require another profile": "Dispositivo al di fuori dei profili supportati; NVIDIA e alberi di dispositivo require un altro profilo", "Device path mismatch. Format cancelled.": "Mancata corrispondenza del percorso del dispositivo. Formato annullato.", + "Device permissions verified for the application user": "autorizzazioni del dispositivo verificate per l'utente dell'applicazione", "Device:": "Dispositivo:", + "Devices added to the container:": "Dispositivi aggiunti al contenitore:", + "Devices of the host it asks for:": "Dispositivi dell'host che chiede:", "Devices to add to VM": "Dispositivi da aggiungere alla VM", "Diff: current system vs backup (--- system +++ backup)": "Differenza: sistema attuale vs backup (--- sistema +++ backup)", "Different host. Backup from:": "Ospite diverso. Backup da:", @@ -1196,6 +1567,8 @@ "Directory does not exist and was not created.": "La directory non esiste e non è stata creata.", "Directory does not exist:": "La directory non esiste:", "Directory error": "Errore nella directory", + "Directory for the read-only view": "Directory per la visualizzazione di sola lettura", + "Directory for the read/write view": "Directory per la vista lettura/scrittura", "Directory not found": "Directory non trovata", "Directory storage added successfully to Proxmox!": "Archiviazione di directory aggiunta con successo a Proxmox!", "Directory successfully.": "Elenco con successo.", @@ -1248,6 +1621,7 @@ "Disk path:": "Percorso del disco:", "Disk safety revalidation failed.": "La riconvalida della sicurezza del disco non è riuscita.", "Disk safety validation passed.": "Convalida della sicurezza del disco superata.", + "Disk too small for the common profile": "Disco troppo piccolo per il profilo comune", "Disk unmounted from": "Disco smontato da", "Disk verified and accessible inside CT at": "Disco verificato e accessibile all'interno di CT all'indirizzo", "Disk:": "Disco:", @@ -1261,6 +1635,10 @@ "Display physical volumes (LVM)": "Visualizza volumi fisici (LVM)", "Display system summary in ASCII format": "Visualizza il riepilogo del sistema in formato ASCII", "Display volume groups (LVM)": "Visualizza gruppi di volumi (LVM)", + "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer.": "Non assumere la porta 8123 rimane attiva dopo l'imbarco su Home Assistant Core 2026.8 o più recente.", + "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume.": "Non rivendicare in-place gli aggiornamenti delle immagini OCI sono convalidati fino a quando rootfs sostituzione e rollback sono stati testati senza perdere il volume gestito /mnt/data.", + "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default.": "Non attivare automaticamente le GPU integrate AMD non supportate. Gli override HSA sono esperimenti di compatibilità manuale, non un default convalidato.", + "Do not mount": "Non montare", "Do not run the upgrade from the Web UI virtual console (it will disconnect)": "Non eseguire l'aggiornamento dalla console virtuale dell'interfaccia utente Web (si disconnetterà)", "Do not start the VM until the system has been rebooted.": "Non avviare la VM finché il sistema non è stato riavviato.", "Do you want ProxMenux to stop it now?": "Vuoi che ProxMenux lo interrompa adesso?", @@ -1304,9 +1682,23 @@ "Do you want to update the existing export?": "Vuoi aggiornare l'esportazione esistente?", "Do you want to update the existing share?": "Vuoi aggiornare la condivisione esistente?", "Do you want to view the selected backup before restoring?": "Vuoi visualizzare il backup selezionato prima del ripristino?", + "Docker Mods are only offered for compatible LinuxServer images": "I Mods Docker sono offerti solo per immagini LinuxServer compatibili", + "Docker Volume Backup": "Docker Volume Backup", + "Docker/CLI not available yet or no valid answer": "Docker/CLI non disponibile o nessuna risposta valida", + "Documents & Notes": "Documenti e note", + "Documents volume size in GB": "Dimensioni volume documenti in GB", + "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki.": "Dokuwiki è un software wiki Open Source semplice da usare e altamente versatile che non require un database. È amato dagli utenti per la sua sintassi pulita e leggibile. La facilità di manutenzione, backup e integrazione lo rende preferito da un amministratore. Costruito in controlli di accesso e connettori di autenticazione rendono DokuWiki particolarmente utile nel contesto aziendale e il gran numero di plugin che la sua vivace comunità consente una vasta gamma di casi di utilizzo oltre un wiki tradizionale.", + "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience.": "Dolphin Emulator consente di giocare giochi GameCube e Wii con vari miglioramenti grafici e altre funzionalità sono disponibili per migliorare la vostra esperienza di gioco.", + "Domain for the certificate (example.com)": "Dominio per il certificato (example.com)", + "Doplarr is an *arr request bot for Discord.\"": "Doplarr è un robot di richiesta *arr per Discord.\"", + "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust.": "Doplarr_rs è un bot Discord per la richiesta di supporti attraverso *arr backends, scritto in Rust.", + "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas.": "Double Commander è un free cross platform open source file manager con due pannelli laterali. È ispirato da Total Commander e presenta alcune nuove idee.", + "Download Spotify music with album art and metadata": "Scarica musica Spotify con album art e metadati", "Download failed for all attempted URLs": "Download non riuscito per tutti gli URL tentati", + "Download its Compose file from an address": "Scarica il file Compose da un indirizzo", "Download keyfile": "scarica il file chiave", "Download latest VirtIO ISO automatically": "Scarica automaticamente l'ultima ISO VirtIO", + "Downloaded OCI images deleted:": "Scaricate le immagini OCI cancellate:", "Downloaded amdgpu_top": "Scaricato amdgpu_top", "Downloading": "Download in corso", "Downloading Helper-Scripts logo...": "Download del logo degli script di supporto in corso...", @@ -1318,45 +1710,86 @@ "Downloading amdgpu_top": "Download di amdgpu_top", "Downloading official installer...": "Download del programma di installazione ufficiale in corso...", "Downloading pre-existing encrypted backups from this host will fail unless you kept a copy of the current key.": "il download di backup crittografati preesistenti da questo host fallirà a meno che tu non conservi una copia della chiave corrente.", + "Downloading the image:": "Scarica l'immagine:", "Downloading the latest Fastfetch release...": "Download dell'ultima versione di Fastfetch in corso...", "Driver blacklist entries removed": "Voci della lista nera dei driver rimosse", "Driver blacklist removed for": "Lista nera dei driver rimossa per", "Driver installed successfully. Press Enter to continue...": "Driver installato correttamente. Premi Invio per continuare...", "Drivers :": "Driver:", "Drivers compiled and installed via DKMS.": "Driver compilati e installati tramite DKMS.", + "Dry run completed; no changes were made.": "Eseguita a secco completata; non sono state apportate modifiche.", + "Dry run completed; no containers were created.": "Corsa a secco completata; non sono stati creati contenitori.", + "Dry run completed; the container and the mounts were not changed.": "Corsa a secco completata; il contenitore e i supporti non sono stati modificati.", + "DuckDNS subdomain without .duckdns.org (comma separated for several)": "Sottodominio DuckDNS senza .duckdns.org (comma separato per diversi)", + "DuckDNS token from your account at duckdns.org": "Token DuckDNS dal tuo account su duckdns.org", + "DuckDNS updates the subdomain every 5 minutes. Without UPDATE_IP, DuckDNS itself detects the public IPv4 address of the request.": "DuckDNS aggiorna il sottodominio ogni 5 minuti. Senza UPDATE IP, DuckDNS stesso rileva l'indirizzo IPv4 pubblico della richiesta.", + "DuckStation is a PS1 Emulator aiming for the best accuracy and game support.": "DuckStation è un Emulatore PS1 che mira al miglior supporto accuracy e game.", + "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence.": "Duckdns è un servizio gratuito che indicherà un DNS (sotto domini di duckdns.org) a un IP di vostra scelta. Il servizio è completamente gratuito, e non require riattivazione o post del forum per mantenere la sua esistenza.", "Dumping AMD GPU ROM BIOS via sysfs...": "Dumping del BIOS ROM della GPU AMD tramite sysfs...", "Duplicate IP addresses found": "Trovati indirizzi IP duplicati", "Duplicate parameters cleaned": "Parametri duplicati puliti", + "Duplicate variable in the contract; review it before editing": "Duplicare la variabile nel contratto; rivederla prima della modifica", + "Duplicated GPU device in the container": "Dispositivo GPU duplicato nel contenitore", + "Duplicated NVIDIA devices": "Dispositivi NVIDIA duplicati", + "Duplicated VMID in the Proxmox inventory": "VMID duplicato nell'inventario Proxmox", + "Duplicated native directive:": "Direttiva madre duplicata:", + "Duplicated native option": "Opzione nativa duplicata", + "Duplicated or invalid stack VMID": "VMID stack duplicato o non valido", + "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others.": "Duplicati è un client di backup che memorizza in modo sicuro backup crittografati, incrementali, compressi su storage locale, servizi di archiviazione cloud e server di file remoti. Funziona con protocolli standard come FTP, SSH, WebDAV e servizi popolari come Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, e molti altri.", + "Duplicati web interface (password only)": "Interfaccia web Duplicati (solo password)", "Duration": "Durata", "Duration:": "Durata:", + "Dynamic NVIDIA is only validated for unprivileged containers. This profile uses static mounts and must be recreated after the host driver changes.": "Dynamic NVIDIA è validato solo per contenitori non privati. Questo profilo utilizza supporti statici e deve essere ricreato dopo che il driver host cambia.", "EFI disk created and configured on": "Disco EFI creato e configurato su", "EFI storage selection cancelled.": "Selezione dell'archiviazione EFI annullata.", "EFI storage selection failed or was cancelled. VM creation aborted.": "La selezione dell'archivio EFI non è riuscita o è stata annullata. Creazione della VM interrotta.", "EMERGENCY PROXMOX SYSTEM REPAIR": "RIPARAZIONE DEL SISTEMA PROXMOX IN EMERGENZA", "ENABLED for restore": "ABILITATO per il ripristino", "EXISTS": "ESISTE", + "Each /request command needs a backend: add a [[backends]] block in the same file with the url and api_key of your Sonarr, Radarr or Seerr instance, then restart the container.": "Ogni comando /request ha bisogno di un backend: aggiungere un blocco [[backends]] nello stesso file con l'url e api key del Sonarr, Radarr o Seerr istanza, quindi riavviare il contenitore.", "Each LUN will appear as a block device assignable to VMs.": "Ogni LUN apparirà come un dispositivo a blocchi assegnabile alle VM.", + "Each peer gets its configuration and its QR code inside the container: /config/peer1/peer1.conf and /config/peer1/peer1.png, or /config/peer_/peer_.conf when names were given.": "Ogni peer ottiene la sua configurazione e il suo codice QR all'interno del contenitore: /config/peer1/peer1.conf e /config/peer1/peer1.png, or /config/peer ±name>/peer ±name>.conf quando i nomi sono stati dati.", + "Ebook and audiobook collection manager for Usenet and BitTorrent users.": "Ebook e gestore di raccolta audiobook per utenti Usenet e BitTorrent.", + "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind.": "Eden è un emulatore sperimentale open source per il Nintendo Switch, costruito con prestazioni e stabilità in mente.", "Edge TPU runtime installed.": "Runtime Edge TPU installato.", "Edit raw CT configuration file": "Modifica il file di configurazione CT grezzo", "Edit raw VM configuration file": "Modifica il file di configurazione grezzo della VM", "Edit the VM machine type to q35 and try again.": "Modifica il tipo di macchina VM su q35 e riprova.", + "Email address for certificate expiry notices (required by ZeroSSL)": "Indirizzo e-mail per le comunicazioni di scadenza del certificato (required by ZeroSSL)", + "Email address of the LibreDB Studio administrator": "Indirizzo e-mail dell'amministratore LibreDB Studio", + "Email address of the NetBox admin account": "Indirizzo e-mail dell'account amministratore NetBox", + "Emby WebUI": "Emby WebUI", + "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server.": "Emby organizza video, musica, TV dal vivo e foto da librerie di media personali e li trasmette a smart TV, scatole di streaming e dispositivi mobili. Questo contenitore è confezionato come server multimediale emby standalone.", "Emergency Proxmox System Repair": "Riparazione di emergenza del sistema Proxmox", "Emergency recovery:": "Recupero d'emergenza:", + "Empowering the smart home": "Migliorare la casa intelligente", "Empty": "Vuoto", + "Empty exec service check": "Controllo servizio exec vuoto", + "Empty or duplicated NVIDIA identity": "Identità NVIDIA vuota o duplicata", + "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes.": "EmulatorJS è un'applicazione emulatore basata su Docker che può simulare vari sistemi operating e ambienti di dispositivo all'interno di contenitori per lo sviluppo, il test e l'apprendimento.", "Enable": "Abilitare", "Enable / disable job timer": "Abilita/disabilita il timer del lavoro", "Enable High Availability services": "abilita i servizi ad alta disponibilità", "Enable IOMMU in GRUB or ZFS boot": "Abilita IOMMU nell'avvio GRUB o ZFS", "Enable IOMMU support if not enabled": "Abilita il supporto IOMMU se non abilitato", "Enable IOMMU, reboot the host, and try again.": "Abilita IOMMU, riavvia l'host e riprova.", + "Enable Intel/AMD VA-API video acceleration": "Attiva accelerazione video Intel/AMD VA-API", + "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping": "Abilitare NVIDIA transcodifica e HDR10/Dolby Vision alla mappatura del tono SDR", "Enable Remote Desktop (RDP) before disabling the virtual display.": "Abilita Desktop remoto (RDP) prima di disabilitare il display virtuale.", "Enable SSD emulation for this disk?": "Abilitare l'emulazione SSD per questo disco?", "Enable TCP BBR/Fast Open control": "abilita il controllo TCP BBR/Fast Open", + "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping": "Abilita trascodifica VA-API e HDR10/Dolby Vision alla mappatura del tono SDR", + "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin": "Abilita VA-API, codifica hardware e mappatura del tono OpenCL in Jellyfin", "Enable VFIO IOMMU support": "abilita il supporto VFIO IOMMU", "Enable ZFS autotrim (SSD/NVMe pools)": "abilita il taglio automatico ZFS (pool SSD/NVMe)", + "Enable a mount on an existing Rclone OCI container": "Abilitare un supporto su un contenitore Rclone OCI esistente", + "Enable an optical drive for MakeMKV": "Abilitare un'unità ottica per MakeMKV", "Enable auto-sync if /var/log exceeds 90% of its size?": "Abilitare la sincronizzazione automatica se /var/log supera il 90% delle sue dimensioni?", "Enable fast reboots": "abilita i riavvii rapidi", "Enable restart on kernel panic": "abilita il riavvio in caso di panico del kernel", + "Enable the NVIDIA GPU requested by the image": "Abilitare la GPU NVIDIA richiesta dall'immagine", + "Enable the NVIDIA GPU required by Open WebUI CUDA": "Abilitare la GPU NVIDIA required di Open WebUI CUDA", + "Enable this FUSE mount now and restart the CT?": "Abilitare questo supporto FUSE ora e riavviare la CT?", "Enable/Disable job": "Abilita/Disabilita lavoro", "Enabled": "Abilitato", "Enabled (device pending — load apex module or reboot)": "Abilitato (dispositivo in sospeso: carica il modulo apex o riavvia)", @@ -1401,6 +1834,7 @@ "Enter a name for the mount point (used as /mnt/):": "Inserisci un nome per il punto di montaggio (usato come /mnt/):", "Enter a name for the new virtual machine:": "Inserisci un nome per la nuova macchina virtuale:", "Enter a number, or write or paste a command:": "Inserisci un numero oppure scrivi o incolla un comando:", + "Enter a usable IPv4 address with its prefix, for example": "Inserisci un indirizzo IPv4 utilizzabile con il suo prefisso, ad esempio", "Enter backup file (.zst):": "Inserisci il file di backup (.zst):", "Enter backup path (.tar.zst):": "Inserisci il percorso di backup (.tar.zst):", "Enter backup path (.vma.zst):": "Inserisci il percorso di backup (.vma.zst):", @@ -1489,6 +1923,7 @@ "Enter the number or type the interface name:": "Inserisci il numero o digita il nome dell'interfaccia:", "Enter the password for Samba user:": "Inserisci la password per l'utente Samba:", "Enter the recovery passphrase set when the keyfile was created:": "Inserisci la passphrase di ripristino impostata al momento della creazione del file di chiavi:", + "Enter the size in whole GB, for example": "Inserisci le dimensioni in GB interi, ad esempio", "Enter username for Samba server:": "Inserisci il nome utente per il server Samba:", "Enter username:": "Inserisci il nome utente:", "Enterprise Proxmox Ceph repository disabled": "Repository Enterprise Proxmox Ceph disabilitato", @@ -1497,6 +1932,8 @@ "Enterprise repository returned 401 Unauthorized (no valid subscription). Switch to the no-subscription repository and retry?": "Il repository aziendale ha restituito 401 Non autorizzato (nessun abbonamento valido). Passare al repository senza abbonamento e riprovare?", "Enterprise repository unauthorized and fallback declined by user": "Repository aziendale non autorizzato e fallback rifiutato dall'utente", "Entropy generation optimization removed": "Ottimizzazione della generazione di entropia rimossa", + "Environment entry without an explicit value": "Entrata ambientale senza un valore esplicito", + "Environment override for an unknown service:": "Interruzione ambientale per un servizio sconosciuto:", "Equivalent manual flow of disk_host.sh: partition, format, mount, persist, register in Proxmox.": "Flusso manuale equivalente di disk_host.sh: partizione, formattazione, montaggio, persistenza, registrazione in Proxmox.", "Equivalent manual flow of iscsi_host.sh.": "Flusso manuale equivalente di iscsi_host.sh.", "Equivalent manual flow used by Local Shared Manager.": "Flusso manuale equivalente utilizzato dal Local Shared Manager.", @@ -1512,12 +1949,16 @@ "Error: No write permissions in directory": "Errore: nessuna autorizzazione di scrittura nella directory", "Essential Proxmox packages installed": "Pacchetti Proxmox essenziali installati", "Estimated required free space:": "Spazio libero richiesto stimato:", + "Etherpad admin page": "Pagina di amministrazione Etherpad", "Every 12 hours": "Ogni 12 ore", "Every 3 hours": "Ogni 3 ore", "Every 6 hours": "Ogni 6 ore", + "Every fail2ban jail ships disabled. Enable the ones you need in /config/fail2ban/jail.local, taking the ready-made jails in /config/fail2ban/jail.d/ as reference, then restart the container.": "Ogni prigione fail2ban è disattivata. Abilitare quelli di cui hai bisogno in /config/fail2ban/jail.local, prendendo le carceri preparate in /config/fail2ban/jail.d/ come riferimento, quindi riavviare il contenitore.", "Every hour": "Ogni ora", + "Every member of the stack is back to its previous installation.": "Ogni membro dello stack è tornato alla sua precedente installazione.", "Every path in this backup is kernel-tied: the restore applies these paths automatically via the safe-subset filter and re-merges the operator's tuning.": "ogni percorso in questo backup è legato al kernel: il ripristino applica questi percorsi automaticamente tramite il filtro del sottoinsieme sicuro e unisce nuovamente l'ottimizzazione dell'operatore.", "Everything restorable in this backup will be restored": "tutto ciò che è ripristinabile in questo backup verrà ripristinato", + "Exact name of the remote": "Nome esatto del telecomando", "Example output: rootfs: local-lvm:vm-114-disk-0,size=8G": "Output di esempio: rootfs: local-lvm:vm-114-disk-0,size=8G", "Example target: /dev/sdb": "Destinazione di esempio: /dev/sdb", "Example: /dev/pve/vm-114-disk-0": "Esempio: /dev/pve/vm-114-disk-0", @@ -1537,7 +1978,9 @@ "Execute destructive rollback?": "eseguire un rollback distruttivo?", "Executing destructive rollback (operator confirmed) ...": "Esecuzione di un rollback distruttivo (confermato dall'operatore) ...", "Executing:": "In esecuzione:", + "Execution engine for Index-TTS": "Motore di esecuzione per Index-TTS", "Existing Groups": "Gruppi esistenti", + "Existing TLS certificate reused:": "Certificato TLS esistente riutilizzato:", "Existing file, re-downloading...": "File esistente, nuovo download in corso...", "Existing filesystem:": "File system esistente:", "Existing hostpci entries detected — they will be reused": "Rilevate voci hostpci esistenti: verranno riutilizzate", @@ -1581,7 +2024,9 @@ "Extended Filesystem 4 (recommended)": "Filesystem esteso 4 (consigliato)", "External ZFS ARC settings restored:": "Impostazioni ZFS ARC esterne ripristinate:", "External ZFS configuration changed after the ProxMenux migration; current file and backup preserved:": "La configurazione ZFS esterna è cambiata dopo la migrazione ProxMenux; il file attuale e il backup sono stati conservati:", + "External credential is empty or spans multiple lines": "credential esterno è vuoto o abbraccia più linee", "External disk for backup": "Disco esterno per il backup", + "External field not reserved:": "Campo esterno non riservato:", "Extracting NVIDIA installer on host...": "Estrazione del programma di installazione NVIDIA sull'host in corso...", "Extracting OVA archive...": "Estrazione dell'archivio OVA...", "Extracting archive...": "Estrazione archivio...", @@ -1592,7 +2037,9 @@ "Extraction failed. Check log:": "Estrazione fallita. Controlla il registro:", "Extraction successful": "Estrazione riuscita", "FAILED": "FALLITO", + "FFmpeg version the node uses (7 by default)": "FFmpeg versione il nodo utilizza (7 per impostazione predefinita)", "FINAL CONFIRMATION — DATA WILL BE ERASED": "CONFERMA FINALE — I DATI VERRANNO CANCELLATI", + "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface.": "Il client FIleZilla è un client FTP, FTPS e SFTP veloce e affidabile con molte funzioni utili e un'interfaccia utente grafica intuitiva.", "Fail2Ban - Intrusion Prevention": "Fail2Ban - Prevenzione delle intrusioni", "Fail2Ban Management": "Gestione Fail2Ban", "Fail2Ban has been removed": "Fail2Ban è stato rimosso", @@ -1602,6 +2049,7 @@ "Fail2Ban is currently installed.": "Fail2Ban è attualmente installato.", "Fail2Ban is not installed on this system.": "Fail2Ban non è installato su questo sistema.", "Fail2Ban is running correctly": "Fail2Ban funziona correttamente", + "Fail2ban is a daemon to ban hosts that cause multiple authentication errors.": "Fail2ban è un daemon per vietare gli host che causano errori di autenticazione multipli.", "Failed": "Fallito", "Failed to access log2ram directory": "Impossibile accedere alla directory log2ram", "Failed to access share with provided credentials.": "Impossibile accedere alla condivisione con le credenziali fornite.", @@ -1748,6 +2196,9 @@ "Failed. See log:": "Fallito. Vedi registro:", "Falling back to each installer with --auto-reinstall...": "ricorrere a ciascun programma di installazione con --auto-reinstall...", "Falling back to manual paste mode.": "ritorno alla modalità incolla manuale.", + "Fast Usenet downloader with a SABnzbd-compatible API": "Downloader Fast Usenet con API compatibile SABnzbd", + "Fast, modern web interface for qBittorrent": "Interfaccia web veloce e moderna per qBittorrent", + "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper.": "Più veloce è una riimplementazione del modello Whisper di OpenAI utilizzando CTranslate2, che è un motore di inferenza veloce per i modelli Transformer. Questo contenitore fornisce un server di protocollo Wyoming per la più veloce-whisper.", "Fastfetch Logo Selection": "Selezione logo Fastfetch", "Fastfetch configuration updated": "Configurazione fastfetch aggiornata", "Fastfetch download URL retrieved successfully.": "URL di download Fastfetch recuperato correttamente.", @@ -1759,19 +2210,31 @@ "Fastfetch now displays: System optimised by: ProxMenux": "Fastfetch ora visualizza: Sistema ottimizzato da: ProxMenux", "Fastfetch removed from system": "Fastfetch rimosso dal sistema", "Fastfetch will start automatically in the console": "Fastfetch si avvierà automaticamente nella console", + "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application.": "Ferdium è un'applicazione desktop che ti aiuta a organizzare come utilizzare le tue applicazioni preferite da combining in una sola applicazione.", "Fetching NVIDIA driver versions supported by your GPU...": "Recupero delle versioni dei driver NVIDIA supportate dalla tua GPU...", "Figurine installation and configuration completed successfully.": "L'installazione e la configurazione della statuetta sono state completate con successo.", "Figurine is not installed.": "La statuetta non è installata.", "Figurine removed from system": "Statuetta rimossa dal sistema", + "File bind mounts do not support spaces:": "I supporti file bind non supportano gli spazi:", + "File processing made easy!": "L'elaborazione dei file è facile!", "File:": "File:", + "FileBrowser Quantum": "FileBrowser Quantum", + "FileBrowser Quantum (new installation)": "FileBrowser Quantum (nuova installazione)", + "FileDrop is a free, open source file sharing service": "FileDrop è un servizio di condivisione di file open source gratuito", + "Files & Downloads": "File e download", + "Files volume size in GB": "Dimensione del volume dei file in GB", "Filesystem": "File system", "Filesystem Tools Required": "Strumenti del file system obbligatori", "Filesystem:": "File system:", "Final Confirmation": "Conferma finale", + "Final cleanup of the stack operation completed": "Pulizia finale della pila operation completata", "Final confirmation": "Conferma finale", "Final storage health/status check": "Controllo finale dell'integrità/stato dell'archiviazione", + "Finance & Budgeting": "Finanza e Budgeting", "Find your device using https://finds.synology.com": "Trova il tuo dispositivo utilizzando https://finds.synology.com", "Fingerprint:": "Impronta digitale:", + "Firefly, the easiest using of WireGuard VPN server, plus version of wg-easy.": "Firefly, il più semplice utilizzo del server VPN WireGuard, oltre alla versione di wg-easy.", + "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards.": "Firefox Browser, noto anche come Mozilla Firefox o semplicemente Firefox, è un browser web gratuito e open source sviluppato dalla Mozilla Foundation e dalla sua controllata, Mozilla Corporation. Firefox utilizza il motore di layout Gecko per rendere le pagine web, che implementa gli standard web attuali e previsti.", "Firewall allows port": "Il firewall consente la porta", "Firewall settings": "Impostazioni del firewall", "Firmware :": "Firmware:", @@ -1791,8 +2254,13 @@ "Fix systemd-boot meta-package conflict": "Risolto il conflitto del metapacchetto systemd-boot", "Fix systemd-boot:": "Correggi l'avvio di systemd:", "Fix: on the host, run": "Correzione: sull'host, esegui", + "FlexGet web interface": "Interfaccia web FlexGet", + "Flexget is a multipurpose automation tool for all of your media.": "Flexget è uno strumento di automazione multiuso per tutti i tuoi supporti.", + "Flowise 3.0.1 and later create the administrator account from the web interface, the first time it is opened.": "Flowise 3.0.1 e successivamente creare l'account amministratore dall'interfaccia web, la prima volta che viene aperto.", + "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast.": "Flycast è un emulatore multi-piattaforma Sega Dreamcast, Naomi, Naomi 2 e Atomiswave derivato dal reicast.", "Folder Name": "Nome della cartella", "Folders in /mnt": "Cartelle in /mnt", + "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics.": "Folding@home è un progetto di calcolo distribuito per simulare le dinamiche proteiche, compreso il processo di piegatura delle proteine e i movimenti delle proteine implicati in una varietà di malattie. Esso riunisce scienziati citizen che si propongono di eseguire simulazioni di dinamiche proteiche sui loro personal computer. Le intuizioni di questi dati stanno aiutando gli scienziati a comprendere meglio la biologia e a fornire nuove opportunità per lo sviluppo di terapeutici.", "Follow post-restore progress live from ProxMenux Monitor → Backups tab after the reboot.": "segui l'avanzamento post-ripristino in tempo reale da ProxMenux Monitor → scheda Backup dopo il riavvio.", "For LVM - Create mount directory and mount:": "Per LVM: crea la directory di montaggio e monta:", "For ZFS, storage ID must start with a letter and use only letters, numbers, dot, dash, underscore or colon.": "Per ZFS, l'ID di archiviazione deve iniziare con una lettera e utilizzare solo lettere, numeri, punto, trattino, carattere di sottolineatura o due punti.", @@ -1828,11 +2296,15 @@ "Formatting partition": "Formattazione della partizione", "Found": "Trovato", "Found guest-accessible shares:": "Condivisioni accessibili agli ospiti trovate:", + "Free and easy to use Minecraft server management tool.": "Strumento di gestione server Minecraft gratuito e facile da usare.", "Free public Proxmox repository enabled": "Repository Proxmox pubblico gratuito abilitato", "Free space OK:": "Spazio libero OK:", "Free up disk space": "Liberare spazio su disco", "Free:": "Gratuito:", + "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support.": "FreeCAD è un modello di progettazione computerizzata 3D (CAD) parametrico generale e un'applicazione software per la modellazione delle informazioni di costruzione (BIM) con il supporto del metodo degli elementi finiti (FEM).", "French": "francese", + "Freshrss is a free, self-hostable aggregator for rss feeds.": "Freshrss è un aggregatore auto-hostable gratuito per feed rss.", + "Frigate WebUI": "Frigate WebUI", "Full SMART Report": "Rapporto SMART completo", "Full SMART info and attributes": "Informazioni e attributi SMART completi", "Full format — new GPT partition + filesystem": "Formato completo: nuova partizione GPT + filesystem", @@ -1845,6 +2317,7 @@ "Function Level Reset (FLR) not available": "Reset del livello di funzione (FLR) non disponibile", "GID already in use:": "GID già in uso:", "GID in CT": "GID nella TC", + "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable.": "GIMP è un editor grafico raster gratuito e open source utilizzato per la manipolazione delle immagini (retouching) e l'editing delle immagini, il disegno a forma libera, la transcodifica tra diversi formati di file di immagine e attività più specializzate. E 'estensibile per mezzo di plugin, e scriptable.", "GPU": "GPU", "GPU -> VM Mode Detected": "GPU -> Modalità VM rilevata", "GPU Already Added": "GPU già aggiunta", @@ -1870,6 +2343,7 @@ "GPU already present in target VM — existing hostpci entry reused": "GPU già presente nella VM di destinazione: voce hostpci esistente riutilizzata", "GPU audio added": "Aggiunto audio GPU", "GPU audio already present in target VM — existing hostpci entry reused": "Audio GPU già presente nella VM di destinazione: voce hostpci esistente riutilizzata", + "GPU available for machine learning:": "GPU disponibile per l'apprendimento automatico:", "GPU driver blacklisted": "Driver GPU nella lista nera", "GPU guard hook will block concurrent start when another VM is already using this GPU": "Il guard hook della GPU bloccherà l'avvio simultaneo quando un'altra VM sta già utilizzando questa GPU", "GPU host driver blacklisted in /etc/modprobe.d/blacklist.conf": "Driver host GPU inserito nella lista nera in /etc/modprobe.d/blacklist.conf", @@ -1885,11 +2359,14 @@ "GPU passthrough to VMs requires IOMMU to be enabled in the kernel.": "Il passthrough GPU alle macchine virtuali richiede che IOMMU sia abilitato nel kernel.", "GPU passthrough was not applied.": "Il passthrough GPU non è stato applicato.", "GPU passthrough was skipped (no compatible GPU detected).": "Il passthrough della GPU è stato saltato (nessuna GPU compatibile rilevata).", + "GPU recognition uses 8 GB of RAM and a limit of 4 CPU equivalents. These resources were tested in the lab and are not a universal minimum. Compatibility depends on the GPU, the models and the kernel. NVIDIA uses the GPUs of the Toolkit inventory; Intel keeps the CPU topology.": "Il riconoscimento GPU utilizza 8 GB di RAM e un limite di 4 CPU equivalents. Queste risorse sono state testate in laboratorio e non sono un minimo universale. La compatibilità dipende dalla GPU, dai modelli e dal kernel. NVIDIA utilizza le GPU dell'inventario Toolkit; Intel mantiene la topologia della CPU.", "GPU removed from VM": "GPU rimossa dalla VM", "GPU removed from VM config": "GPU rimossa dalla configurazione della VM", + "GPU render device": "Dispositivo di rendering GPU", "GPU switch complete: LXC mode prepared.": "Switch GPU completato: modalità LXC preparata.", "GPU switch complete: VM mode prepared.": "Switch GPU completato: modalità VM preparata.", "GPU switch mode completed. No reboot required.": "Modalità di cambio GPU completata. Nessun riavvio richiesto.", + "GPU verified:": "GPU verificato:", "GPU will be removed from source VM config": "La GPU verrà rimossa dalla configurazione della VM di origine", "GPU will remain configured in source VM": "La GPU rimarrà configurata nella VM di origine", "GPU/TPU - Manual CLI Guide": "GPU/TPU: guida CLI manuale", @@ -1899,6 +2376,8 @@ "GRUB configuration updated": "Configurazione GRUB aggiornata", "GRUB_CMDLINE_LINUX_DEFAULT not found in GRUB config": "GRUB_CMDLINE_LINUX_DEFAULT non trovato nella configurazione di GRUB", "GUI mode (if available)": "Modalità GUI (se disponibile)", + "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities.": "GZDoom è una porta centrica caratteristica per tutti i giochi del motore Doom, basata su ZDoom, aggiungendo un renderer OpenGL e potenti capacità di scripting.", + "Gaming & Leisure": "Gioco & Leisure", "Gateway is not installed.": "Il gateway non è installato.", "Gateway removed.": "Gateway rimosso.", "Gateway restarted.": "Il gateway è stato riavviato.", @@ -1908,19 +2387,32 @@ "Generate a new key and authorize it on the server automatically (recommended)": "genera una nuova chiave e la autorizza automaticamente sul server (consigliato)", "Generate a new key, show me the line to paste manually": "genera una nuova chiave, mostrami la riga da incollare manualmente", "Generate a new keyfile": "genera un nuovo file di chiavi", + "Generated Paperless administrator": "Amministratore Generato senza Carta", + "Generated Tandoor administrator": "Amministratore generato Tandoor", + "Generated administrator login": "Accesso all'amministratore generato", "Generating OVF descriptor...": "Generazione del descrittore OVF in corso...", "Generating dkms.conf...": "Generazione dkms.conf...", "Generating manifest...": "Generazione manifesto...", "Generating missing locale:": "Generazione della lingua mancante:", + "Generic SCSI device associated with the drive (e.g. /dev/sg2)": "Dispositivo SCSI generico associato all'unità (ad esempio /dev/sg2)", "German": "tedesco", "Get a list of all your containers:": "Ottieni un elenco di tutti i tuoi contenitori:", "Get the actual disk path:": "Ottieni il percorso effettivo del disco:", "Get the container's storage information:": "Ottieni le informazioni sullo spazio di archiviazione del contenitore:", + "Get up and running with large language models locally": "Alzati e correndo con modelli di lingua di grandi dimensioni localmente", "Git installed": "Git installato", + "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality.": "GitQlient è una multipiattaforma client Git originariamente forked da QGit. Al giorno d'oggi va oltre un fork e aggiunge un sacco di nuove funzionalità.", + "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React.": "Github Desktop è un'applicazione GitHub basata su elettroni a fonte aperta. È scritto in TypeScript e usa React.", "Global settings and SSH jail configured": "Impostazioni globali e jail SSH configurati", + "Gluetun/VPN not yet available: this suite does not route downloads through a VPN.": "Gluetun/VPN non ancora disponibile: questa suite non reindirizza i download tramite una VPN.", "Go to \"Manage custom paths\" and remove your custom entry that includes the destination": "Vai su \"Gestisci percorsi personalizzati\" e rimuovi la voce personalizzata che include la destinazione", "Google only ships an official libedgetpu APT repository for Debian/Ubuntu. Hardware passthrough is already written to": "Google fornisce solo un repository APT libedgetpu ufficiale per Debian/Ubuntu. Il passthrough hardware è già scritto", "Graceful shutdown timed out.": "Lo spegnimento ordinato è scaduto.", + "Grafana is a complete observability stack that allows you to monitor and analyze metrics, logs and traces. It allows you to query, visualize, alert on and understand your data no matter where it is stored.": "Grafana è uno stack di osservabilità completo che consente di monitorare e analizzare metriche, registri e tracce. Ti permette di interrogare, visualizzare, allertare e comprendere i tuoi dati indipendentemente da dove viene memorizzato.", + "Grafana web interface": "Interfaccia web Grafana", + "Grav is a Fast, Simple, and Flexible, file-based Web-platform.": "Grav è una piattaforma web veloce, semplice e flessibile, basata su file.", + "Grocy (new installation; restored data keeps its credentials)": "Grocy (nuova installazione; dati restaurati mantiene i suoi credentials)", + "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility.": "Grocy è un sistema ERP per la vostra cucina! Tagliare su rifiuti alimentari, e gestire le vostre faccende con questa brillante utility.", "Group": "Gruppo", "Group 'sharedfiles' already exists inside the CT": "Il gruppo \"file condivisi\" esiste già all'interno del CT", "Group GID:": "GID del gruppo:", @@ -1953,23 +2445,57 @@ "Guided Repair Available": "Riparazione guidata disponibile", "HA groups will be migrated to HA rules automatically": "I gruppi HA verranno migrati automaticamente alle regole HA", "HA services disabled (configs preserved)": "Servizi HA disabilitati (configurazioni conservate)", + "HAOS One is a community image that runs Docker inside the container. The LXC stays unprivileged, but the inner AppArmor profiles may not be available. The first start downloads Home Assistant Core and its add-ons. If the check fails, the CT and /mnt/data are kept for diagnosis.": "HAOS One è un'immagine comunitaria che gestisce Docker all'interno del contenitore. Il LXC rimane non privato, ma i profili interni AppArmor potrebbero non essere disponibili. Il primo avvio scarica Home Assistant Core e i suoi componenti aggiuntivi. Se il controllo fallisce, la CT e /mnt/data sono tenuti per la diagnosi.", + "HAOS One profile declined": "Profilo HAOS One declinato", + "HAOS One requires an unprivileged unmanaged LXC with nesting and keyctl, 2 cores, 2048 MB RAM, rootfs of at least 12 GB and /mnt/data of at least 16 GB on a container volume included in backups": "HAOS One requi è una LXC non gestita con nidificazione e keyctl, 2 core, 2048 MB RAM, rootf di almeno 12 GB e /mnt/dati di almeno 16 GB su un volume di container incluso in backup", + "HTTP service check without a saved URL": "Controllo del servizio HTTP senza un URL salvato", + "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API.": "Habridge emula Philips Hue API ad altri gateway di automazione domestica come un Amazon Echo/Dot Gen 1 (gen 2 ha problemi di scoperta ha-bridge) o altri sistemi che supportano Philips Hue. Il Bridge gestisce comandi di base come On, Off e comandi di luminosità del protocollo hue. Questo ponte può controllare la maggior parte dei dispositivi che hanno una API distinta.", + "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs.": "HandBrake è uno strumento open source, costruito da volontari, per convertire video da quasi qualsiasi formato in una selezione di codec moderni e ampiamente supportati.", "Hardening SSH: setting MaxAuthTries to 3...": "Rafforzamento di SSH: impostazione di MaxAuthTries su 3...", + "Hardware acceleration for Emby": "Accelerazione hardware per Emby", + "Hardware acceleration for FileFlows": "Accelerazione hardware per FileFlows", + "Hardware acceleration for Frigate": "Accelerazione hardware per Frigate", + "Hardware acceleration for Jellyfin": "Accelerazione hardware per Jellyfin", + "Hardware acceleration for Plex": "Accelerazione hardware per Plex", + "Hardware acceleration for Roon Server": "Accelerazione hardware per Roon Server", + "Hardware acceleration for Stremio": "Accelerazione hardware per Stremio", + "Hardware acceleration for Tdarr": "Accelerazione hardware per Tdarr", + "Hardware acceleration options:": "Opzioni di accelerazione hardware:", "Hardware compatibility — these items will be skipped to keep the boot safe:": "Compatibilità hardware: questi elementi verranno ignorati per mantenere l'avvio sicuro:", "Hardware passthrough is already configured — the Coral device is visible inside the container as /dev/apex_0 (M.2) and/or /dev/bus/usb (USB).": "Il passthrough hardware è già configurato: il dispositivo Coral è visibile all'interno del contenitore come /dev/apex_0 (M.2) e/o /dev/bus/usb (USB).", "Hardware: GPUs and Coral-TPU": "Hardware: GPU e Coral-TPU", + "Have a Private Social Space Hosted on Your Site": "Avere uno spazio sociale privato ospitato sul tuo sito", "Have valid backups of all VMs and containers": "Disporre di backup validi di tutte le macchine virtuali e i contenitori", + "Health check failed:": "Controllo sanitario fallito:", + "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface.": "Healthchecks è un cane da guardia per i vostri lavori di cron. Si tratta di un web server che ascolta per pings dai vostri lavori di cron, più un'interfaccia web.", + "HedgeDoc gives you access to all your files wherever you are.": "HedgeDoc ti dà accesso a tutti i tuoi file ovunque tu sia.", + "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way.": "Heimdall è un modo per organizzare tutti quei link ai siti web più utilizzati e applicazioni web in modo semplice.", + "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking.": "Helium è un browser web basato su Chromium fatto per le persone, con amore. Privacy-primo con ad-blocking imparziale.", "Help & Info (commands)": "Aiuto e informazioni (comandi)", "Help & Information": "Aiuto e informazioni", "Help and Info": "Aiuto e informazioni", "Help and Info Commands": "Comandi di aiuto e informazioni", "Helper-Scripts logo applied": "Logo Helper-Scripts applicato", + "Hermes WebUI": "Hermes WebUI", "Hidden for safety": "Nascosto per sicurezza", "Hidden:": "Nascosto:", "High Availability services have been enabled successfully": "I servizi ad alta disponibilità sono stati abilitati correttamente", "High Availability setup completed": "Configurazione dell'alta disponibilità completata", + "High availability resources are not supported by this profile": "Le risorse ad alta disponibilità non sono supportate da questo profilo", + "High availability resources are not supported for stacks": "Le risorse ad alta disponibilità non sono supportate per pile", "High risk confirmation": "Conferma ad alto rischio", "High-Risk GPU Power State": "Stato di alimentazione della GPU ad alto rischio", + "Home Assistant": "Home Assistant", + "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server": "Home Assistant Core - Automazione domestica open source che mette prima il controllo locale e la privacy. Alimentato da una comunità mondiale di amichevoli e appassionati di fai da te. Perfetto per funzionare su un Raspberry Pi o un server locale", + "Home Assistant OS cannot be checked without an IP address": "Il sistema operativo Home Assistant non può essere controllato senza un indirizzo IP", + "Home Assistant OS did not pass the Supervisor, Core and Observer checks": "Home Assistant OS non ha superato i controlli Supervisor, Core e Observer", + "Home Assistant OS ready: Supervisor, Core and Observer running": "Home Assistant OS pronto: Supervisore, Core e Osservatore in esecuzione", + "Home Assistant OS was not started: its addresses will be known once Core is running.": "Home Assistant OS non è stato avviato: i suoi indirizzi saranno noti una volta che Core è in esecuzione.", + "Home Assistant Observer": "Osservatore Home Assistant", + "Home Automation systems": "Home Sistemi di automazione", "Home-Lab-Club logo applied": "Logo Home-Lab-Club applicato", + "HomeKit support for the impatient.": "HomeKit supporto per l'impaziente.", + "Homebridge UI": "Homebridge UI", "Host": "Ospite", "Host Backup → Borg": "Backup dell'host → Borg", "Host Backup → Local archive": "Backup dell'host → Archivio locale", @@ -1978,6 +2504,7 @@ "Host Config Backup": "Backup della configurazione dell'host", "Host Config Backup / Restore": "Backup/ripristino della configurazione dell'host", "Host Config Restore": "Ripristino configurazione host", + "Host DVB tuners": "Tuner Host DVB", "Host Directory": "Directory dell'ospite", "Host Directory to LXC Mount Point": "Directory host per punto di montaggio LXC", "Host Directory:": "Directory host:", @@ -1985,6 +2512,7 @@ "Host GPU detected": "Rilevata GPU host", "Host GPU is already bound to vfio-pci. Host reconfiguration/reboot should not be required for this VM-to-VM reassignment.": "La GPU host è già associata a vfio-pci. La riconfigurazione/riavvio dell'host non dovrebbe essere necessario per questa riassegnazione da VM a VM.", "Host IP": "IP dell'ospite", + "Host Management": "Gestione host", "Host Mount Path": "Percorso di montaggio dell'host", "Host NFS/Samba as Proxmox Storage (pvesm)": "Ospita NFS/Samba come storage Proxmox (pvesm)", "Host Path": "Percorso dell'ospite", @@ -1995,8 +2523,25 @@ "Host VFIO configuration changed (initramfs updated). Reboot required before starting the VM.": "La configurazione dell'host VFIO è stata modificata (initramfs aggiornato). Riavvio richiesto prima di avviare la VM.", "Host VFIO configuration changed — reboot required before starting the VM.": "La configurazione VFIO dell'host è stata modificata: è necessario riavviare prima di avviare la VM.", "Host already in VFIO mode — skipping host reconfiguration for VM reassignment": "Host già in modalità VFIO: salta la riconfigurazione dell'host per la riassegnazione della VM", + "Host audio devices": "Dispositivi audio host", "Host backup attached to PVE job": "backup dell'host collegato al lavoro PVE", + "Host data is not restored by the backup; confirm it with --acknowledge-external-data": "I dati host non vengono ripristinati dal backup; confermarlo con --acknowledge-external-data", + "Host device for /dev/kvm": "Dispositivo host per /dev/kvm", + "Host device for /dev/net/tun": "Dispositivo host per /dev/net/tun", + "Host device for /dev/ttyUSB0": "Dispositivo host per /dev/ttyUSB0", + "Host device for /dev/video10": "Dispositivo host per /dev/video10", + "Host device for /dev/video11": "Dispositivo host per /dev/video11", + "Host device for /dev/video12": "Dispositivo host per /dev/video12", + "Host device node": "Nodo del dispositivo host", + "Host directories are not included in the backup and are not reverted by a recovery.": "Le directory ospitanti non sono incluse nel backup e non sono convertite da un recupero.", + "Host directories are not included in the backups and are not reverted by a recovery.": "Le directory ospitanti non sono incluse nei backup e non sono convertite da un recupero.", + "Host directories cannot be part of the vzdump backup": "Le directory ospitanti non possono far parte del backup vzdump", + "Host directories that are kept, with their content:": "Le directory ospitanti che vengono conservate, con il loro contenuto:", + "Host directory": "directory host", + "Host directory (created if it does not exist)": "directory host (creato se non esiste)", + "Host directory (not included in Proxmox backups)": "directory host (non inclusa nei backup Proxmox)", "Host directory access for unprivileged containers has been prepared above": "L'accesso alla directory host per i contenitori non privilegiati è stato preparato sopra", + "Host directory kept, with its content:": "directory host conservata, con il suo contenuto:", "Host directory permissions updated — unprivileged containers can now access it": "Autorizzazioni della directory host aggiornate: ora i contenitori non privilegiati possono accedervi", "Host directory:": "Directory host:", "Host fstab CIFS Mounts:": "Montaggi CIFS host fstab:", @@ -2008,7 +2553,14 @@ "Host fstab NFS mounts:": "Supporti NFS host fstab:", "Host fstab mounts (not registered as Proxmox storage):": "Montaggi host fstab (non registrato come spazio di archiviazione Proxmox):", "Host identity (hostname, hosts)": "Identità host (nome host, host)", + "Host kernel module loaded:": "Modulo del kernel host caricato:", + "Host monitor configured: shared PID and network namespaces, LXCFS disabled in this container": "Monitor host configurato: PID condiviso e namespace di rete, LXCFS disabilitato in questo contenitore", + "Host monitor verified: PID and network namespaces and memory match the host": "Monitor host verificato: PID e namespace di rete e la memoria corrispondono all'host", + "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks.": "Monitor host: rete PID condivisa e accesso privilegiato. Un'immagine compromessa potrebbe influenzare Proxmox. Utilizzare solo su reti di fiducia.", + "Host monitoring declined": "Monitoraggio host declinato", + "Host path for": "Percorso host per", "Host permissions applied (o+rwx + default ACL) — unprivileged LXCs can read/write through bind-mounts": "Autorizzazioni host applicate (o+rwx + ACL predefinito): gli LXC non privilegiati possono leggere/scrivere tramite montaggi bind", + "Host system path": "Percorso del sistema host", "Host write access confirmed.": "Accesso in scrittura dell'host confermato.", "Hostname": "Nome host", "Hot changes applied. No reboot needed for these paths.": "Sono state applicate modifiche importanti. Non è necessario il riavvio per questi percorsi.", @@ -2020,12 +2572,18 @@ "How do you want to select the Samba server?": "Come vuoi selezionare il server Samba?", "How do you want to select the folder to export?": "Come vuoi selezionare la cartella da esportare?", "How do you want to select the folder to share?": "Come vuoi selezionare la cartella da condividere?", + "How is it installed?": "Come è installato?", + "How is the image described?": "Come viene descritta l'immagine?", "How to Access an LXC Terminal": "Come accedere a un terminale LXC", "How to Access an LXC Terminal from Proxmox Host": "Come accedere a un terminale LXC dall'host Proxmox", "How to schedule": "Come pianificare", + "Htpcmanager is a front end for many htpc related applications.": "Htpcmanager è un front end per molte applicazioni relative a htpc.", "I have read this": "Ho letto questo", "I/O priority configured": "Priorità I/O configurata", "ID already in use. Please choose another.": "ID già in uso. Per favore scegline un altro.", + "IGDB": "IGDB", + "IGDB Client ID": "ID cliente IGDB", + "IGDB Client Secret": "Segreto cliente IGDB", "IMPORTANT": "IMPORTANTE", "IMPORTANT NOTES:": "NOTE IMPORTANTI:", "IMPORTANT PREREQUISITES:": "PREREQUISITI IMPORTANTI:", @@ -2062,7 +2620,14 @@ "IOMMU was configured during this wizard and a reboot is pending.": "IOMMU è stato configurato durante questa procedura guidata ed è in sospeso un riavvio.", "IOMMU/VFIO configuration reverted": "Configurazione IOMMU/VFIO ripristinata", "IP": "IP", + "IP address": "Indirizzo IP", + "IP address and firewall of the host": "Indirizzo IP e firewall dell'host", + "IP address of this container for the certificate (0.0.0.0 if unknown)": "Indirizzo IP di questo contenitore per il certificato (0.0.0.0 se sconosciuto)", + "IP address:": "Indirizzo IP:", "IP or hostname of the PVE node hosting the Borg server LXC:": "IP o nome host del nodo PVE che ospita il server Borg LXC:", + "IPv4 address of the container": "Indirizzo IPv4 del contenitore", + "IPv4 address of the containers": "Indirizzo IPv4 dei contenitori", + "IPv4 gateway (empty = no outbound route)": "gateway IPv4 (vuoto = nessun percorso in uscita)", "ISO": "ISO", "ISO created successfully:": "ISO creato con successo:", "ISO image — installation images": "Immagine ISO: immagini di installazione", @@ -2095,6 +2660,7 @@ "If this happens, you can restore the backup from the 'Subscription Banner Removal' option in 'Uninstall optimizations'.": "In questo caso, puoi ripristinare il backup dall'opzione \"Rimozione banner di abbonamento\" in \"Disinstalla ottimizzazioni\".", "If this node runs hyper-converged Ceph: ensure Ceph is 19.x (Squid) BEFORE upgrading PVE.": "Se questo nodo esegue Ceph iperconvergente: assicurati che Ceph sia 19.x (Squid) PRIMA di aggiornare PVE.", "If upgrade fails:": "Se l'aggiornamento fallisce:", + "If you answer No, Glances is installed without privileges and monitors ONLY its own LXC, not Proxmox.": "Se rispondete a No, Glances è installato senza privilegi e monitor SOLO il proprio LXC, non Proxmox.", "If you are sure you want to use it, please remove the": "Se sei sicuro di volerlo utilizzare, rimuovi il file", "If you choose No, install": "Se scegli No, installa", "If you continue, some adjustments may be duplicated or conflict with those already made by xshok.": "Se continui, alcune modifiche potrebbero essere duplicate o entrare in conflitto con quelle già apportate da xshok.", @@ -2104,11 +2670,29 @@ "If you want HDMI/analog audio inside the VM, select the audio controller(s) to pass through along with the GPU.": "Se desideri l'audio HDMI/analogico all'interno della VM, seleziona i controller audio da far passare insieme alla GPU.", "If you want to use a physical monitor on the passthrough GPU:": "Se desideri utilizzare un monitor fisico sulla GPU passthrough:", "If your DHCP has a static reservation for the old MAC, update it.": "se il tuo DHCP ha una prenotazione statica per il vecchio MAC, aggiornalo.", + "Image": "Immagine", "Image Source Directory": "Directory di origine delle immagini", + "Image cache": "cache immagine", + "Image compatibility restored:": "Compatibilità immagine ripristinata:", + "Image compatibility verified:": "Compatibilità immagine verificata:", "Image directory:": "Directory delle immagini:", + "Image download failed:": "Scarica immagine fallito:", + "Image downloaded": "Immagine scaricata", "Image file not found:": "File immagine non trovato:", "Image imported:": "Immagine importata:", + "Image integrity verified": "integrità immagine verificata", + "Image not allowed for the host monitor profile": "Immagine non consentita per il profilo del monitor host", + "Image reference (for example ghcr.io/user/application:latest)": "Riferimento immagine (ad esempio ghcr.io/utente/applicazione:più recente)", + "Image that is not in the catalog": "Immagine che non è nel catalogo", + "Image:": "Immagine:", "Images to import:": "Immagini da importare:", + "Immich CUDA requires NVIDIA driver 545 or later": "Immich CUDA requires NVIDIA driver 545 o versioni successive", + "Immich GPU profile not validated": "Profilo GPU Immich non convalidato", + "Immich configuration cancelled": "Cancellazione della configurazione Immich", + "Immich device without a validated translation": "Dispositivo Immich senza traduzione convalidata", + "Immich requires CUDA compute capability 5.2 or later": "Immich requires CUDA capacità di calcolo 5.2 o versioni successive", + "Immich runtime without a validated translation": "Tempo di esecuzione Immich senza traduzione convalidata", + "Immich server": "Server Immich", "Import — disk image imports": "Importa: importa immagini disco", "Import Disk Image to VM": "Importa immagine disco nella VM", "Import Disk to LXC": "Importa disco su LXC", @@ -2149,24 +2733,58 @@ "Incompatible Reset Capability for Intel GPU": "Funzionalità di ripristino incompatibile per GPU Intel", "Incompatible Reset Capability for Intel dGPU": "Funzionalità di ripristino incompatibile per Intel dGPU", "Incompatible archive": "Archivio incompatibile", + "Incompatible image platform": "Piattaforma immagine incompatibile", + "Incompatible instance directory": "Elenco delle istanze incompatibili", + "Incompatible instance record": "Registrazione di istanze incompatibili", + "Incompatible record": "Registrazione incompatibile", + "Incompatible stack assembly": "Montaggio a pila incompatibile", "Incompatible version": "versione incompatibile", + "Incomplete NVIDIA identity": "Identità NVIDIA incompleta", + "Incomplete NVIDIA inventory": "inventario NVIDIA incompleto", + "Incomplete Proxmox inventory": "inventario Proxmox incompleto", + "Incomplete Proxmox inventory; recovery blocked": "inventario Proxmox incompleto; il recupero bloccato", + "Incomplete container removed:": "Contenitore incompleto rimosso:", + "Incomplete dependency order": "Ordine di dipendenza incompleto", + "Incomplete file recipe or unknown paths": "Ricetta di file incompleto o sentieri sconosciuti", + "Incomplete gzip layer": "Strato gzip incompleto", + "Incomplete or incompatible Proxmox inventory": "inventario Proxmox incompleto o incompatibile", + "Incomplete primary network": "Rete primaria incompleta", + "Incomplete stack order": "Ordine stack incompleto", + "Incomplete stack removed": "stack incompleto rimosso", + "Inconsistent adaptation profile and recipe": "Profilo e ricetta di adattamento inconsistenti", + "Inconsistent host monitor profile": "Profilo del monitor host inconsistente", + "Inconsistent stack identity": "Identità dello stack inconsistente", + "Inconsistent stack membership for": "Affiliazione dello stack inconsistente", "Increase container RAM temporarily to": "Aumenta temporaneamente la RAM del contenitore a", "Increase file and process limits for advanced workloads": "Aumenta i limiti di file e processi per carichi di lavoro avanzati", "Increase various system limits": "Aumenta i vari limiti del sistema", "Increase vzdump backup speed": "aumenta la velocità di backup di vzdump", "Increasing maximum file system open files...": "Aumento del numero massimo di file aperti del file system...", "Increasing various system limits...": "Aumento dei vari limiti del sistema...", + "Independent LXC applications installed": "Applicazioni LXC indipendenti installate", + "Independent LXCs: no main container or hookscript. Each one keeps its own Start with Proxmox setting.": "LXC indipendenti: nessun contenitore principale o gancioscript. Ognuno mantiene il proprio Start con l'impostazione Proxmox.", + "Independent applications, without a main container.": "Applicazioni indipendenti, senza un contenitore principale.", + "Indexers and quality profiles still need to be configured.": "Gli indici e i profili di qualità devono ancora essere configurati.", "Inherited retention:": "Conservazione ereditata:", "Inherited schedule:": "pianificazione ereditata:", + "Initial Nextcloud administrator": "Amministratore iniziale Nextcloud", + "Initial Nextcloud settings applied": "Impostazioni iniziali Nextcloud applicate", + "Initial Paperless-ngx administrator": "Amministratore iniziale Paperless-ngx", + "Initial Tandoor administrator": "Amministratore di Tandoor iniziale", + "Initial administrator created:": "Amministratore iniziale creato:", + "Initial administrator user": "utente amministratore iniziale", "Initializing Borg repository if needed...": "Inizializzazione del repository Borg, se necessario...", "Initiator IQN is authorised on the target": "L'IQN dell'iniziatore è autorizzato sul target", "Initiator IQN:": "IQN dell'iniziatore:", + "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers.": "Inkscape è un software grafico vettoriale di qualità professionale che funziona su computer desktop Linux, Mac OS X e Windows.", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN": "All'interno del LXC, creare l'amministratore: console kimai:user:creare Your USERNAME Your EMAIL ROLE SUPER ADMIN", "Inspect disks before any action": "Ispezionare i dischi prima di qualsiasi azione", "Inspect host device nodes": "Ispezionare i nodi del dispositivo host", "Inspect passthrough/kernel events": "Ispezionare gli eventi passthrough/kernel", "Inspect storage config block:": "Esamina il blocco di configurazione dell'archiviazione:", "Inspection commands run directly. Template commands [T] require parameter substitution.": "I comandi di ispezione vengono eseguiti direttamente. I comandi modello [T] richiedono la sostituzione dei parametri.", "Install": "Installare", + "Install (experimental)": "Installazione (sperimentale)", "Install ALL utilities": "Installa TUTTE le utilità", "Install AMD GPU drivers inside the guest.": "Installa i driver GPU AMD all'interno del guest.", "Install CIFS client packages inside CT:": "Installa i pacchetti client CIFS all'interno di CT:", @@ -2185,6 +2803,7 @@ "Install Samba inside CT:": "Installa Samba all'interno di CT:", "Install ZFS auto-snapshot": "installa l'istantanea automatica ZFS", "Install a version from the branch the kernel names.": "installa una versione dal ramo indicato dai nomi del kernel.", + "Install an image that is not in the catalog": "Installare un'immagine che non è nel catalogo", "Install analysis tools": "Installa strumenti di analisi", "Install and configure": "Installa e configura", "Install and configure Fastfetch": "installa e configura Fastfetch", @@ -2203,27 +2822,35 @@ "Install server packages inside CT:": "Installa i pacchetti server all'interno di CT:", "Install terminal multiplexers": "Installare multiplexer terminali", "Install the Edge TPU runtime (libedgetpu1-std)": "Installa il runtime Edge TPU (libedgetpu1-std)", + "Install this image?": "Installare questa immagine?", "Install with Cloud-Init script": "Installa con lo script Cloud-Init", "Install with ISO from UUP Dump": "Installa con ISO da UUP Dump", + "Install with advanced settings": "Installare con impostazioni avanzate", + "Install with default settings": "Installare con impostazioni predefinite", "Install with personal ISO": "Installa con ISO personale", + "Install with this configuration?": "Installare con questa configurazione?", "Install with traditional method": "Installazione con metodo tradizionale", "Install with: apt-get install open-iscsi": "Installa con: apt-get install open-iscsi", "Install/Update Coral TPU on Host": "Installa/Aggiorna Coral TPU sull'host", "Install/Update NVIDIA Drivers (Host + LXC)": "Installa/Aggiorna i driver NVIDIA (Host + LXC)", "Installation Complete": "Installazione completata", + "Installation completed": "Installazione completata", "Installation completed.": "Installazione completata.", "Installation completed. Please reboot the server manually as soon as possible.": "Installazione completata. Riavviare manualmente il server il prima possibile.", "Installation completed. Press Enter to continue...": "Installazione completata. Premi Invio per continuare...", "Installation failed": "Installazione non riuscita", "Installation finished but drivers are not loaded. A reboot may be required.": "L'installazione è terminata ma i driver non sono caricati. Potrebbe essere necessario un riavvio.", + "Installation incomplete. These containers and their data are kept:": "Installazione incompleta. Questi contenitori e i loro dati sono conservati:", "Installation log:": "Registro di installazione:", "Installation summary": "Riepilogo dell'installazione", "Installed": "Installato", "Installed at:": "Installato presso:", "Installed components:": "Componenti installati:", + "Installed:": "Installato:", "Installer already downloaded and verified.": "Programma di installazione già scaricato e verificato.", "Installer copied to container.": "Programma di installazione copiato nel contenitore.", "Installer downloaded.": "Programma di installazione scaricato.", + "Installer file not found:": "File di installazione non trovato:", "Installer finished with errors.": "Programma di installazione terminato con errori.", "Installer not found:": "Programma di installazione non trovato:", "Installing": "Installazione", @@ -2274,9 +2901,14 @@ "Installing pigz...": "Installazione di Pigz...", "Installing required dependencies...": "Installazione delle dipendenze richieste...", "Installing required package: git": "Installazione del pacchetto richiesto: git", + "Installing required packages...": "Installazione di pacchetti required...", "Installing required tools...": "Installazione degli strumenti richiesti...", "Installing selected utilities": "Installazione delle utilità selezionate", "Installing system utilities...": "Installazione delle utilità di sistema...", + "Installing the new image": "Installazione della nuova immagine", + "Installing the new image...": "Installazione della nuova immagine...", + "Installing the new image:": "Installazione della nuova immagine:", + "Installing the stack startup hook...": "Installazione del gancio di avvio dello stack...", "Installing zfs-auto-snapshot package...": "Installazione del pacchetto zfs-auto-snapshot in corso...", "Installs essential packages if missing": "Installa i pacchetti essenziali se mancanti", "Insufficient Disk Space": "Spazio su disco insufficiente", @@ -2288,8 +2920,17 @@ "Intel CPU detected": "Rilevata CPU Intel", "Intel GPU Tools installation completed!": "Installazione degli strumenti GPU Intel completata!", "Intel GPU(s) detected:": "GPU Intel rilevate:", + "Intel VA-API + OpenCL (official mod)": "Intel VA-API + OpenCL (modalità ufficiale)", "Intel VA-API drivers installed.": "Driver Intel VA-API installati.", "Intel iGPU passthrough configured.": "Passthrough Intel iGPU configurato.", + "Intel render device for recognition": "Dispositivo di rendering Intel per il riconoscimento", + "Intel/AMD (VA-API and QSV)": "Intel/AMD (VA-API e QSV)", + "Intel/AMD (VA-API)": "Intel/AMD (VA-API)", + "Intel/AMD (streaming rendering and encoding)": "Intel/AMD (streaming rendering e codifica)", + "Intel/AMD VA-API": "Intel/AMD VA-API", + "Intel/AMD VA-API (no OpenCL mod)": "Intel/AMD VA-API (no OpenCL mod)", + "Intel/AMD render node": "Nodo di rendering Intel/AMD", + "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters – building great software.": "IntelliJ IDEA ti aiuta a scrivere codice più velocemente con strumenti che eliminano le attività noiose e ti permettono di concentrarti su ciò che conta – costruendo un grande software.", "Interactive (guided, prompts visible)": "Interattivo (guidato, istruzioni visibili)", "Interactive process viewer (press q to exit)": "Visualizzatore interattivo dei processi (premi q per uscire)", "Interface": "Interfaccia", @@ -2303,50 +2944,178 @@ "Interfaces to Remove": "Interfacce da rimuovere", "Internal error: NVIDIA installer path is empty or file not found.": "Errore interno: il percorso del programma di installazione NVIDIA è vuoto o il file non è stato trovato.", "Internal error: missing arguments in pmx_prepare_host_shared_dir": "Errore interno: argomenti mancanti in pmx_prepare_host_shared_dir", + "Internal subnet of the tunnel (change it only if it clashes)": "Sottorete interna del tunnel (cambiare solo se si scontra)", + "Interrupted operation": "operation interrotta", + "Interrupted operation:": "operation interrotta:", + "Interrupted stack operation found": "Pila interrotta operation trovata", "Invalid 'proxmox-ve' candidate (not 9.x or none). Please verify your repository configuration and network, then retry.": "Candidato 'proxmox-ve' non valido (non 9.xo nessuno). Verifica la configurazione e la rete del repository, quindi riprova.", + "Invalid ALLOWED_HOSTS value": "Valore non valido ALLOWED HOSTs", "Invalid ID": "ID non valido", + "Invalid Intel render path": "percorso di rendering Intel non valido", + "Invalid Jellyfin path:": "Invalid Jellyfin percorso:", + "Invalid MAC address:": "Indirizzo MAC non valido:", + "Invalid NVIDIA destination": "Destinazione NVIDIA non valida", + "Invalid NVIDIA device:": "Dispositivo NVIDIA non valido:", + "Invalid Nextcloud volume": "Volume non valido Nextcloud", + "Invalid OCI Entrypoint": "Invalid OCI", + "Invalid OCR language:": "Lingua OCR non valida:", "Invalid Option": "Opzione non valida", "Invalid Path": "Percorso non valido", + "Invalid Proxmox inventory": "inventario Proxmox non valido", + "Invalid Python module:": "Modulo Python non valido:", + "Invalid Python package:": "Pacchetto Python non valido:", + "Invalid Python path in the repair:": "Invalid Python percorso nella riparazione:", + "Invalid Unpackerr variable": "Invalid Unpackerr variabile", + "Invalid VFS cache mode": "Modalità cache VFS non valida", "Invalid VMID": "VMID non valido", + "Invalid VMID or timeout": "VMID non valido o timeout", + "Invalid VMID:": "Invalid VMID:", "Invalid ZFS pool name.": "Nome del pool ZFS non valido.", + "Invalid absolute mount path": "percorso di montaggio assoluto non valido", + "Invalid absolute path; avoid spaces, commas and relative segments": "percorso assoluto non valido; evitare spazi, virgole e segmenti relativi", + "Invalid acceleration profile": "Profilo di accelerazione non valido", + "Invalid access address:": "Indirizzo di accesso non valido:", + "Invalid administrator email": "E-mail di amministratore non valido", + "Invalid administrator user name": "Nome utente amministratore non valido", + "Invalid base VMID": "Base non valida VMID", + "Invalid check package:": "Pacchetto di controllo non valido:", + "Invalid configuration path:": "percorso di configurazione non valido:", + "Invalid consume/export volumes": "Quantità di consumo/esportazione non valide", + "Invalid container path:": "Percorso contenitore non valido:", + "Invalid credential file path:": "Invalid credential percorso di file:", + "Invalid declarative entrypoint": "N. di dichiarazione non valida", + "Invalid declarative stop signal": "Fermata dichiarativa non valida signal", + "Invalid declarative working directory": "Elenco di lavoro dichiarativo non valido", + "Invalid device UID:": "Dispositivo non valido UID:", + "Invalid device mode": "Modalità dispositivo non valido", + "Invalid device mode:": "Modalità dispositivo non valido:", + "Invalid device path:": "percorso del dispositivo non valido:", + "Invalid device paths for": "Percorsi di dispositivo non validi", "Invalid group name. Use letters, digits, underscore or hyphen, and start with a letter or underscore.": "Nome del gruppo non valido. Utilizza lettere, cifre, trattino basso o trattino e inizia con una lettera o un trattino basso.", + "Invalid health check": "Controllo sanitario non valido", + "Invalid healthcheck path": "percorso di controllo sanitario non valido", + "Invalid healthcheck port": "Invalid healthcheck porto", + "Invalid healthcheck request timeout": "Invalid healthcheck richiesta timeout", + "Invalid healthcheck scheme": "Programma di controllo sanitario non valido", + "Invalid healthcheck stability period": "Periodo di stabilità del controllo sanitario non valido", + "Invalid host kernel module name:": "Nome del modulo del kernel host non valido:", + "Invalid host monitor PID": "Monitor host non valido PID", + "Invalid host path:": "Percorso non valido:", + "Invalid image probe descriptor": "Descrittore dell'immagine non valida", "Invalid input": "Immissione non valida", + "Invalid internal volume": "Volume interno non valido", + "Invalid list:": "Elenco non valido:", + "Invalid machine learning CPU allocation:": "allocazione della CPU di apprendimento della macchina non valida:", + "Invalid machine learning resources": "Risorse di apprendimento delle macchine non valide", + "Invalid main member or duplicated members": "Membro principale non valido o membri duplicati", + "Invalid media path": "Sentiero dei media non valido", + "Invalid media volume": "Volume dei media non valido", + "Invalid minimum version:": "Versione minima non valida:", + "Invalid mount type": "Tipo di montaggio non valido", "Invalid name": "Nome non valido", "Invalid name. Use only letters, numbers, hyphens and underscores.": "Nome non valido. Utilizza solo lettere, numeri, trattini e trattini bassi.", + "Invalid native entrypoint": "Invalid nativo", + "Invalid octal permissions": "Permessi ottali non validi", "Invalid option": "Opzione non valida", "Invalid option, please try again.": "Opzione non valida, riprova.", "Invalid option. Skipping.": "Opzione non valida. Saltare.", + "Invalid or duplicated mount path": "percorso di montaggio non valido o duplicato", + "Invalid or duplicated network sysctl": "Sisctl di rete non valido o duplicato", "Invalid parameters for bind mount": "Parametri non validi per il montaggio del collegamento", + "Invalid path": "Percorso non valido", + "Invalid path in the NVIDIA inventory": "percorso non valido nell'inventario NVIDIA", + "Invalid post-start timeout in the configuration:": "Invalid post-start timeout nella configurazione:", + "Invalid private bridge": "Ponte privato non valido", + "Invalid private network": "Rete privata non valida", + "Invalid prlimit value": "Valore non valido", + "Invalid process limits format": "Formato dei limiti di processo non valido", + "Invalid registry digest": "Digerimento del registro non valido", + "Invalid remote name": "Nome remoto non valido", + "Invalid remote path": "percorso remoto non valido", + "Invalid repair version:": "Versione di riparazione non valida:", + "Invalid resources": "Risorse non valide", + "Invalid restored volume path": "percorso di volume non valido restaurato", + "Invalid running state": "Stato in esecuzione non valido", "Invalid selection": "Selezione non valida", + "Invalid service alias": "Servizio non valido alias", + "Invalid service check arguments": "Argomenti di controllo del servizio non valido", + "Invalid service check timeout": "Servizio non valido check timeout", + "Invalid shared path": "percorso condiviso non valido", + "Invalid shutdown timeout": "Tempo di chiusura non valido", "Invalid size. Please enter a number in MB (e.g., 128, 256, 512).": "Taglia non valida. Inserisci un numero in MB (ad esempio, 128, 256, 512).", + "Invalid stack contract": "Contratto di stack non valido", + "Invalid stack journal": "Diario di stack non valido", + "Invalid stack members": "Membri dello stack non validi", + "Invalid stack name": "Nome della pila non valida", + "Invalid stack operation": "Pila non valida operation", "Invalid storage ID. Use only letters, numbers, hyphens and underscores.": "ID di archiviazione non valido. Utilizza solo lettere, numeri, trattini e trattini bassi.", + "Invalid suite application": "Applicazione della suite non valida", + "Invalid sysctl value:": "Valore di sisctl non valido:", + "Invalid template storage": "Deposito di modelli non validi", + "Invalid tmpfs options:": "Invalid tmpfs opzioni:", + "Invalid tmpfs path:": "Invalid tmpfs percorso:", + "Invalid tmpfs size:": "Invalid tmpfs dimensione:", "Invalid username or password.": "Nome utente o password non validi.", + "Invalid variable name": "Nome variabile non valido", + "Invalid variable name:": "Nome variabile non valido:", + "Invalid volume size": "Dimensione del volume non valido", + "Invalid volume size:": "Dimensioni del volume non valido:", + "Invalid volume target": "Obiettivo del volume non valido", + "Is the value a password or secret?": "Il valore è una password o un segreto?", "Issue": "Problema", "Issues found": "Problemi rilevati", "Issues were found. Would you like to use the Guided Cleanup Assistant?": "Sono stati rilevati problemi. Desideri utilizzare l'Assistente di pulizia guidata?", "Issues were found. Would you like to use the Guided Repair Assistant?": "Sono stati rilevati problemi. Desideri utilizzare l'Assistente riparazione guidata?", "It appears that you have already executed the xshok-proxmox post-install script on this system.": "Sembra che tu abbia già eseguito lo script di post-installazione xshok-proxmox su questo sistema.", + "It asks for a system directory of the host:": "Richiede una directory di sistema dell'host:", + "It asks for capabilities or a relaxed confinement profile.": "Richiede capacità o un profilo di confinamento rilassato.", + "It asks to see the processes of the host.": "Chiede di vedere i processi dell'host.", + "It cannot be removed on its own, because the application would stop working: continuing removes the whole application.": "Non può essere rimosso da solo, perché l'applicazione smette di funzionare: continua a rimuovere l'intera applicazione.", + "It is created empty; existing data is not migrated automatically.": "Viene creato vuoto; i dati esistenti non vengono migrati automaticamente.", "It is recommended to create a backup before continuing.": "Si consiglia di creare un backup prima di continuare.", "It is strongly recommended to create a backup of your container before proceeding with the conversion.": "Si consiglia vivamente di creare un backup del proprio contenitore prima di procedere con la conversione.", + "It needs a privileged container, which is not isolated from the host.": "Ha bisogno di un contenitore privilegiato, che non è isolato dall'ospite.", "It will be installed from the official GitHub repository.": "Verrà installato dal repository GitHub ufficiale.", + "It works through the Docker engine of the host, and a native OCI container does not have one.": "Funziona attraverso il motore Docker dell'host, e un contenitore OCI nativo non ne ha uno.", "Italian": "Italiano", + "Its Compose file asks for privileged mode; the container is created unprivileged and that mode is only offered as an option.": "Il suo file Compose chiede modalità privilegiate; il contenitore viene creato non privato e tale modalità viene offerta solo come opzione.", + "Its final cleanup did not complete. Select the stack again in the OCI management menu to complete it.": "La sua pulizia finale non è stata completata. Selezionare nuovamente lo stack nel menu di gestione OCI per completarlo.", + "Its labels are not applied: they are read by other Docker tools.": "Le sue etichette non sono applicate: sono lette da altri strumenti Docker.", "JC Channel logo applied": "Logo JC Channel applicato", + "JDownloader 2 with browser GUI and MyJDownloader support": "JDownloader 2 con browser GUI e supporto MyJDownloader", + "JDownloader WebUI": "JDownloader WebUI", "JSON output for scripts": "Output JSON per gli script", + "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps.": "Jackett funziona come server proxy: traduce query da app (Sonarr, SickRage, CouchPotato, Mylar, ecc) in query http site-specific tracker, analizza la risposta html, quindi invia i risultati al software richiedente. Questo consente di ottenere carichi recenti (come RSS) e di eseguire ricerche. Jackett è un singolo repository di logiche di demolizione e traduzione dell'indicizzatore mantenuto - rimuovendo il peso da altre applicazioni.", + "Jellyfin WebUI": "Jellyfin WebUI", + "Jellyfin configuration applied:": "Jellyfin configurazione applicata:", + "Jellyfin did not create encoding.xml before the timeout": "Jellyfin non ha creato encoding.xml prima del timeout", + "Jellyfin has not created encoding.xml in any declared path": "Jellyfin non ha creato encoding.xml in qualsiasi percorso dichiarato", + "Jellyseerr is a free and open source software application for managing requests for your media library.": "Jellyseerr è un'applicazione software gratuita e open source per la gestione delle richieste per la tua libreria multimediale.", + "Jenkins Continuous Integration and Delivery server.": "Jenkins server di integrazione e consegna continua.", + "Jenkins unlock": "Jenkins sbloccare", "Job ID (letters, numbers, - _)": "ID lavoro (lettere, numeri, - _)", "Job ID:": "ID lavoro:", "Job deleted:": "Lavoro eliminato:", "Job disabled:": "Lavoro disabilitato:", "Job enabled:": "Lavoro abilitato:", "Job selection returned empty id — aborting.": "La selezione del lavoro ha restituito un ID vuoto: interruzione.", + "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.": "Joplin è un'applicazione gratuita e aperta, che può gestire un gran numero di note organizzate in notebook.", "Journald configuration adjusted to": "Configurazione journal adattata a", "Journald configuration is already optimized": "La configurazione journaled è già ottimizzata", "Journald configuration updated and service restarted": "Configurazione journal aggiornata e servizio riavviato", "Journald optimization completed": "Ottimizzazione del journal completata", "Journald optimized - Max size: 64M": "Ottimizzato per journal - Dimensione massima: 64M", + "Jupyter Lab (token only)": "Jupyter Lab (solo token)", "KDF:": "KDF:", "KVM MSR options added to /etc/modprobe.d/kvm.conf": "Opzioni KVM MSR aggiunte a /etc/modprobe.d/kvm.conf", "KVM MSR options ensured in /etc/modprobe.d/kvm.conf": "Opzioni KVM MSR garantite in /etc/modprobe.d/kvm.conf", "KVM MSR options not present, nothing to revert": "Opzioni KVM MSR non presenti, niente da ripristinare", + "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX ™ is a trademark of OffSec.": "Kali-linux - è una distribuzione Advanced Penetration Testing Linux utilizzata per Penetration Testing, Ethical Hacking e valutazioni di sicurezza di rete. KALI LINUX TM è un marchio di OffSec.", + "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections.": "Kasm Workspaces è una piattaforma di streaming container docker per offrire un accesso basato sul browser a desktop, applicazioni e servizi web. Kasm utilizza le infrastrutture desktop containerizzate (CDI) per creare contenitori docker on-demand, monouso, accessibili tramite browser web. Esempio di casi di utilizzo includono l'isolamento del browser remoto (RBI), la prevenzione della perdita di dati (DLP), il desktop come un servizio (DaaS), i servizi di accesso remoto sicuro (RAS), e le collezioni Open Source Intelligence (OSINT).", + "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!": "Kavita è un server di lettura veloce, ricco di funzionalità, cross platform. Costruito con un focus per essere una soluzione completa per tutte le vostre esigenze di lettura. Configura il tuo server e condividi la tua collezione di lettura con i tuoi amici e la tua famiglia!", + "Kavita is a free and open source web based Comic and Book Server.": "Kavita è un server Comic e Book basato su web gratuito e open source.", + "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready.": "Kdenlive è un potente programma di editing video cross-platform gratuito e open source realizzato dalla comunità KDE. Caratteristica ricca e la produzione pronta.", + "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass).": "KeePassXC è un gestore di password gratuito e open source. Ha iniziato come comunità fork di KeePassX (è un porto cross-platform di KeePass).", "Keep GPU in LXC config (disable Start on boot)": "Mantieni la GPU nella configurazione LXC (disabilita Avvia all'avvio)", "Keep GPU in LXC config + disable Start on boot": "Mantieni la GPU nella configurazione LXC + disabilita l'avvio all'avvio", "Keep GPU in VM config (disable Start on boot)": "Mantieni la GPU nella configurazione della VM (disabilita Avvia all'avvio)", @@ -2356,6 +3125,7 @@ "Keep current version (N) if modified": "Mantieni la versione corrente (N) se modificata", "Keep in source VM(s) + disable onboot + add to target VM": "Mantieni le VM di origine + disabilita l'avvio + aggiungi alla VM di destinazione", "Keeping GPU in source VM config": "Mantenere la GPU nella configurazione della VM di origine", + "Keeping the settings changed in Proxmox:": "Mantenere le impostazioni modificate in Proxmox:", "Kept sharedfiles group (has regular users assigned).": "Mantenuto il gruppo sharedfiles (ha utenti regolari assegnati).", "Kernel and architecture info": "Informazioni sul kernel e sull'architettura", "Kernel headers and build tools verified.": "Intestazioni del kernel e strumenti di creazione verificati.", @@ -2377,6 +3147,17 @@ "Keyfile recovery — pick source host": "Recupero file chiave: scegli l'host di origine", "Keyfile removed.": "file di chiavi rimosso.", "Keyrings method failed; trying apt-key fallback": "Il metodo dei portachiavi non è riuscito; provando il fallback con la chiave apt", + "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite.": "KiCad - A Cross Platform e Open Source Electronics Design Automation Suite.", + "Kimai has no default account. Enter the container with: pct enter {main_vmid}": "Kimai non ha un account predefinito. Inserisci il contenitore con: pct inserire {main vmid}", + "Kimai is a professional grade time-tracking application, free and open-source.": "Kimai è un'applicazione di tempo-tracking professionale di grado, libera e open-source.", + "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more.": "Kometa è un potente strumento progettato per darvi il controllo completo sulle librerie multimediali. Con Kometa, si può prendere la personalizzazione al livello successivo, con controllo granulare su metadati, collezioni, sovrapposizioni e molto altro.", + "Kometa reads its configuration from /config/config.yml and the container only ships /config/config.yml.template. Copy the template to config.yml, fill in the required Plex and TMDb connections, then restart the container.": "Kometa legge la sua configurazione da /config/config.yml e il contenitore solo navi /config/config.yml.template. Copiare il modello per config.yml, riempire le connessioni quired Plex e TMDb, quindi riavviare il contenitore.", + "Komga is a media server for your comics, mangas, BDs, magazines and eBooks.": "Komga è un server multimediale per i tuoi fumetti, mangas, BD, riviste ed eBook.", + "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone.": "Krita è un programma professionale di pittura GRATUITA e open source. È fatto da artisti che vogliono vedere strumenti di arte a prezzi accessibili per tutti.", + "LAN access to the kept containers (stack configuration incomplete):": "Accesso LAN ai container custoditi (configurazione incompleta):", + "LAN address applied to the application URLs": "Indirizzo LAN applicato agli URL dell'applicazione", + "LLM App Development Platform": "Piattaforma di sviluppo LLM App", + "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer.": "LM Studio può eseguire modelli AI locali come gpt-oss, Llama, Gemma, Qwen e DeepSeek in privato sul computer.", "LUNs appear as block devices assignable to VMs": "I LUN vengono visualizzati come dispositivi a blocchi assegnabili alle VM", "LVM PV headers check completed": "Controllo delle intestazioni PV LVM completato", "LVM physical volume detected": "Rilevato volume fisico LVM", @@ -2393,18 +3174,27 @@ "LXC containers with NVIDIA passthrough:": "Contenitori LXC con passthrough NVIDIA:", "LXC conversion from privileged to unprivileged completed successfully!": "Conversione LXC da privilegiato a non privilegiato completata con successo!", "LXC conversion from unprivileged to privileged completed successfully!": "Conversione LXC da non privilegiato a privilegiato completata con successo!", + "LXC entries outside the NVIDIA inventory of the journal": "LXC voci al di fuori dell'inventario NVIDIA della rivista", + "LXC entries outside the selected acceleration profile": "Le voci LXC fuori dal profilo di accelerazione selezionato", + "LXC entry outside the read-only NVIDIA profile": "Ingresso LXC al di fuori del profilo NVIDIA in sola lettura", "LXC removed:": "LXC rimosso:", "LXC stopped": "LXC si fermò", "LXC update skipped by user.": "Aggiornamento LXC saltato dall'utente.", "LXCs to destroy:": "LXC da distruggere:", + "Lab interruption after installing the new container": "Interruzione del laboratorio dopo l'installazione del nuovo contenitore", + "Lab interruption after protecting the data": "Interruzione del laboratorio dopo la protezione dei dati", + "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models.": "Label Studio è uno strumento di etichettatura dei dati open source. Consente di etichettare i tipi di dati come audio, testo, immagini, video e serie di tempo con un UI semplice e semplice ed esportare in vari formati di modello. Può essere utilizzato per preparare i dati grezzi o migliorare i dati di formazione esistenti per ottenere più modelli ML accurate.", "Label:": "Etichetta:", "Language Change": "Cambio di lingua", "Language changed to": "La lingua è cambiata in", + "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)": "Lingua/locale (ad esempio es ES.UTF-8; la traduzione di ogni applicazione non è garantita)", "Last 50 kernel log lines": "Ultime 50 righe di registro del kernel", "Last run:": "Ultima esecuzione:", "Last system boot time": "Ora dell'ultimo avvio del sistema", "Latest version:": "Ultima versione:", "Launching GPU passthrough assistant for VM": "Avvio dell'assistente passthrough GPU per VM", + "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork.": "Lazylibrarian è un programma per seguire gli autori e afferrare i metadati per tutte le vostre esigenze di lettura digitale. Esso utilizza un combination di Goodreads Librarything e opzionalmente GoogleBooks come fonti per l'autore info e informazioni di libro. Questo contenitore si basa sul DobyTang fork.", + "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user’s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012).": "Ldap-auth software è per l'autenticazione degli utenti che richiedono risorse protette da server predisposti da nginx. Include un demone (ldap-auth) che comunica con un server di autenticazione e un demone webserver che genera un cookie di autenticazione basato sul credentials dell'utente. I demoni sono scritti in Python per l'uso con un server di autenticazione Lightweight Directory Access Protocol (LDAP) (OpenLDAP o Microsoft Windows Active Directory 2003 e 2012).", "Legacy PVE 8 .list files commented or not present": "File legacy PVE 8 .list commentati o non presenti", "Legacy ceph.list commented or not present": "Ceph.list legacy commentato o non presente", "Legacy gasket-dkms cleanup could not be verified as complete.": "Non è stato possibile verificare che la pulizia del pacchetto gasket-dkms legacy sia stata completata.", @@ -2412,12 +3202,25 @@ "Legacy network tools (e.g., ifconfig)": "Strumenti di rete legacy (ad esempio ifconfig)", "Legend:": "Leggenda:", "Let's review your current network configuration.": "Rivediamo la tua attuale configurazione di rete.", + "Liberate your videos and unleash infinite possibilities.": "Libera i tuoi video e libera le tue infinite possibilità.", + "Libraries: /data/media/movies, /data/media/series and /data/media/music. Select them in the media server.": "Biblioteche: /data/media/movies, /data/media/series e /data/media/musica. Selezionarli nel server multimediale.", + "Library size in GB": "Dimensione della biblioteca in GB", + "LibreDB Studio": "LibreDB Studio", + "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity.": "LibreOffice è una suite per uffici gratuita e potente, e un successore di OpenOffice.org (comunemente noto come OpenOffice). La sua interfaccia pulita e gli strumenti ricchi di funzionalità ti aiutano a scatenare la tua creatività e migliorare la tua produttività.", + "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM.": "LibreWolf è una versione personalizzata e indipendente di Firefox, con gli obiettivi principali di privacy, sicurezza e libertà degli utenti. LibreWolf ha anche lo scopo di rimuovere tutte le telemetrie, la raccolta dei dati e le annoiazioni, oltre a disabilitare le funzioni anti-freedom come DRM.", + "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers.": "Librespeed è un Speedtest molto leggero implementato in Javascript, utilizzando XMLHttpRequest e Web Workers.", + "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Lidarr è un manager di raccolta musicale per utenti Usenet e BitTorrent. Può monitorare più feed RSS per nuove tracce dai tuoi artisti preferiti e li afferra, ordina e rinomina. Può anche essere configurato per aggiornare automaticamente la qualità dei file già scaricati quando un formato di qualità migliore diventa disponibile.", + "Lightweight Docker management UI": "Gestione leggera Docker UI", "Likely cause: host directory permissions deny the container's mapped UID.": "Causa probabile: le autorizzazioni della directory host negano l'UID mappato del contenitore.", "Limiting size and optimizing journald": "Limitare le dimensioni e ottimizzare journald", "Limiting size and optimizing journald...": "Limitazione delle dimensioni e ottimizzazione del journal...", + "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot.": "Limnoria Un robusto, completo e user/programmar-friendly Python IRC bot, con molti plugin esistenti. Successore del noto Supybot.", + "Limnoria joins no IRC network until its configuration file exists. Create it with the setup wizard from the Proxmox host: pct exec -- bash -c 'cd /config && limnoria-wizard'": "Limnoria non entra in rete IRC fino a quando il suo file di configurazione non esiste. Crealo con la procedura guidata di configurazione dell'host Proxmox: pct exec -- bash -c 'cd /config && limnoria-wizard'", "Line to paste (single line, including \"command=...\" prefix):": "Riga da incollare (riga singola, incluso il prefisso \"command=...\"):", "Linux Installation Options": "Opzioni di installazione di Linux", "Linux/Mac path:": "Percorso Linux/Mac:", + "LinuxServer Jellyfin with optional GPU passthrough": "LinuxServer Jellyfin con passthrough GPU opzionale", + "LinuxServer MariaDB requires a user, database and password": "LinuxServer MariaDB requires un utente, un database e una password", "List Available Disks": "Elenca i dischi disponibili", "List IOMMU group mapping": "Elenca la mappatura dei gruppi IOMMU", "List NVMe devices": "Elenca i dispositivi NVMe", @@ -2443,7 +3246,9 @@ "Listening on:": "Ascolto su:", "Listening ports:": "Porte di ascolto:", "Listing relevant CT users and their mapped UID/GID on host...": "Elenco degli utenti CT rilevanti e dei relativi UID/GID mappati sull'host...", + "Load and verify the WireGuard module on the Proxmox host": "Caricare e verificare il modulo WireGuard sull'host Proxmox", "Loading modules...": "Caricamento moduli...", + "Loading the host kernel module:": "Caricamento del modulo del kernel host:", "Local Disk Manager - Proxmox Host": "Gestione disco locale - Host Proxmox", "Local Disk Storages": "Archiviazioni su disco locale", "Local Shared Directory on Host": "Directory condivisa locale sull'host", @@ -2454,6 +3259,7 @@ "Local keyfile is missing but a recovery copy was found in PBS.": "Manca il file di chiavi locale ma è stata trovata una copia di ripristino in PBS.", "Local network only (192.168.0.0/16)": "Solo rete locale (192.168.0.0/16)", "Local restore error log": "Registro degli errori di ripristino locale", + "Local storage for PostgreSQL": "Stoccaggio locale per PostgreSQL", "Locale generated": "Locale generata", "Location:": "Posizione:", "Log": "Tronco d'albero", @@ -2469,6 +3275,7 @@ "Logged-in users": "Utenti registrati", "Logrotate optimization completed": "Ottimizzazione di Logrotate completata", "Logrotate service restarted successfully": "Il servizio Logrotate è stato riavviato correttamente", + "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment.": "Lollypop è un lettore musicale moderno leggero progettato per lavorare in modo eccellente sull'ambiente desktop GNOME.", "Long Test — Background": "Test lungo: contesto", "Long self-test started on": "È iniziato l'autotest lungo", "Long test — full scan, runs in background if closed": "Test lungo: scansione completa, viene eseguito in background se chiuso", @@ -2477,7 +3284,11 @@ "Lookup domain registration info": "Cerca informazioni sulla registrazione del dominio", "Low Container Memory": "Memoria contenitore insufficiente", "Low free space warning": "Avviso di spazio libero insufficiente", + "Low-code programming for event-driven applications": "Programmazione a basso codice per applicazioni basate su eventi", "Low-power CPU platform": "Piattaforma CPU a basso consumo", + "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation": "Luanti (precedentemente Minetest) è una piattaforma open source voxel game-creation con facile modding e creazione di giochi", + "Lucky web interface": "Interfaccia web Lucky", + "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.": "Lychee è uno strumento gratuito di gestione delle foto, che viene eseguito sul server o sul web-space. L'installazione è una questione di secondi. Caricare, gestire e condividere foto come da un'applicazione nativa. Lychee viene fornito con tutto il necessario e tutte le tue foto vengono memorizzate in modo sicuro.", "Lynis - Security Audit": "Lynis - Controllo della sicurezza", "Lynis Management": "Gestione Lynis", "Lynis command not found": "Comando Lynis non trovato", @@ -2492,26 +3303,38 @@ "Lynis updated to version:": "Lynis aggiornato alla versione:", "Lynis version:": "Versione Lynis:", "Lynis was not installed from Git. Reinstalling...": "Lynis non è stato installato da Git. Reinstallazione...", + "Lyrion Music Server is a streaming audio server for Squeezebox audio players.": "Lyrion Music Server è un server audio in streaming per i lettori audio Squeezebox.", "M.2 / PCIe devices:": "Dispositivi M.2/PCIe:", + "M3U proxy server": "Server proxy M3U", "MAC Address": "Indirizzo MAC", + "MAC address": "Indirizzo MAC", "MACHINE TYPE": "TIPO DI MACCHINA", + "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers.": "MAME è un emulatore gratuito e open source progettato per emulare l'hardware di giochi arcade, console di videogiochi, vecchi computer e altri sistemi in software su computer personali moderni.", "MOTD configuration updated successfully": "Configurazione MOTD aggiornata con successo", "MOTD configuration was already up to date": "la configurazione MOTD era già aggiornata", "Machine Type": "Tipo di macchina", + "Machine learning": "Apprendimento della macchina", + "Machine learning profile not implemented; it is not replaced by CPU:": "Profilo di apprendimento automatico non implementato; non è sostituito dalla CPU:", "Machine type: q35": "Tipo macchina: q35", "Machine: q35": "Macchina: q35", + "Main endpoint not yet defined": "Punto finale principale non ancora definito", "Major version differs:": "La versione principale differisce:", "Make sure IOMMU is properly enabled and the system has been rebooted after activation.": "Assicurati che IOMMU sia abilitato correttamente e che il sistema sia stato riavviato dopo l'attivazione.", "Make sure there are no critical services running as they will be interrupted. Ensure your server can be safely rebooted.": "Assicurati che non ci siano servizi critici in esecuzione poiché verranno interrotti. Assicurati che il tuo server possa essere riavviato in sicurezza.", "Make sure you have SSH or Web UI access before rebooting.": "Assicurati di avere accesso SSH o all'interfaccia utente Web prima di riavviare.", "Makefile missing in": "Makefile mancante", "Malformed repository entries cleaned": "Voci del repository non valide pulite", + "Manage OCI": "Gestione di OCI", + "Manage OCI stack": "Gestione dello stack OCI", "Manage PBS encryption keyfile": "gestisci il file di chiavi di crittografia PBS", "Manage Secure Gateway": "Gestisci Secure Gateway", "Manage and inspect VM disk images": "Gestisci e ispeziona le immagini del disco della VM", "Manage custom backup paths": "Gestisci percorsi di backup personalizzati", "Manage custom paths (add / remove your folders)": "Gestisci percorsi personalizzati (aggiungi/rimuovi le tue cartelle)", + "Manage installed OCI applications": "Gestione delle applicazioni OCI installate", "Manage local backup target": "gestisci la destinazione di backup locale", + "Managed disks must have backup enabled and a valid size": "I dischi gestiti devono avere il backup abilitato e una dimensione valida", + "Managing Nginx proxy hosts with a simple, powerful interface.": "Gestire host proxy Nginx con un'interfaccia semplice e potente.", "Manual CLI Guide (Disk and Storage Manager)": "Guida CLI manuale (Gestione dischi e archiviazione)", "Manual CLI Guide (GPU/TPU)": "Guida CLI manuale (GPU/TPU)", "Manual Guide: Convert LXC Privileged to Unprivileged": "Guida manuale: convertire LXC privilegiato in non privilegiato", @@ -2526,29 +3349,51 @@ "Manual review is required.": "è richiesta la revisione manuale.", "Manual steps recommended after import": "Passaggi manuali consigliati dopo l'importazione", "Manual upgrade guide step by step": "Guida all'aggiornamento manuale passo dopo passo", + "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing.": "Manyfold è un'applicazione web open source e self-hosted per la gestione di una collezione di modelli 3D, particolarmente focalizzata sulla stampa 3D.", "Mapped GID on host": "GID mappato sull'host", "Mapped UID on host": "UID mappato sull'host", + "Mariadb is one of the most popular database servers. Made by the original developers of MySQL.": "Mariadb è uno dei server di database più popolari. Realizzato dagli sviluppatori originali di MySQL.", + "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..": "Mastodon è un server di social network open source gratuito basato su ActivityPub dove gli utenti possono seguire gli amici e scoprire quelli nuovi..", "Max FD limit / ulimit configured": "Limite FD massimo/limite u configurato", "Max FS open files configuration created successfully": "Configurazione dei file aperti di Max FS creata correttamente", "Max user watches configured": "Numero massimo di orologi utente configurati", "Maximum auto-repair attempts reached (3). Please review the log and run any remaining commands manually.": "È stato raggiunto il numero massimo di tentativi di riparazione automatica (3). Esamina il registro ed esegui manualmente gli eventuali comandi rimanenti.", "May need to restart terminal": "Potrebbe essere necessario riavviare il terminale", + "Media & Streaming": "Media e streaming", + "Media discovery and request management for Jellyfin, Plex and Emby.": "Gestione della ricerca e della richiesta dei media per Jellyfin, Plex e Emby.", + "Media library transcoding and health checking, with an internal worker node.": "Media biblioteca transcodifica e controllo sanitario, con un nodo interno del lavoratore.", + "Media server": "Server dei media", + "Media server selection cancelled or invalid": "Selezione server media cancellata o non valida", + "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well.": "MediaElch è un MediaManager per Kodi. Le informazioni su Film, Spettacoli TV, Concerti e Musica sono memorizzate come file nfo. Fanarts viene scaricato automaticamente da fanart.tv. Utilizzando il generatore nfo, MediaElch può essere utilizzato anche con altri MediaCenter.", + "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Medusa è un Video Library Manager automatico per spettacoli televisivi. Osserva per nuovi episodi dei tuoi spettacoli preferiti, e quando sono pubblicati fa la sua magia.", + "Memory": "Memoria", + "Memory in MB": "Memoria in MB", "Memory optimization completed.": "Ottimizzazione della memoria completata.", "Memory optimizations removed": "Ottimizzazioni della memoria rimosse", "Memory restored.": "Memoria ripristinata.", "Memory settings optimized successfully": "Impostazioni di memoria ottimizzate con successo", "Memory:": "Memoria:", + "Memos is a lightweight, self-hosted memo hub. Open Source and Free forever.": "Memos è un hub memo leggero e self-hosted. Open Source e Free per sempre.", + "Messaging & Queues": "Messaging & Queues", + "Messenger for the Decentralized Web": "Messaggero per il Web decentrato", "Method:": "Metodo:", + "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium.": "Microsoft Edge è un browser web cross-platform sviluppato da Microsoft e basato su Chromium.", "Migrate VMs away from node being upgraded": "Migrare le VM dal nodo in fase di aggiornamento", "Migrate away any guests that must keep running": "Migrare tutti gli ospiti che devono continuare a funzionare", "Migrated": "Migrato", "Migrated legacy ProxMenux NVIDIA blacklist state — module will reload after reboot": "Stato della lista nera NVIDIA ProxMenux legacy migrato: il modulo verrà ricaricato dopo il riavvio", + "MineOS web interface": "Interfaccia web MineOS", + "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards.": "Minisatip è una versione di server satipi multi-threaded 1.2 che funziona sotto Linux ed è stato testato con schede DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC e ISDB-T.", "Mirror URL not available for this script.": "URL mirror non disponibile per questo script.", + "Miscellaneous": "Varie", "Missing": "Mancante", + "Missing OCI metadata:": "Metadati OCI mancanti:", "Missing commands after installation:": "Comandi mancanti dopo l'installazione:", "Missing dependency": "Dipendenza mancante", + "Missing native directive:": "Direttiva nativo mancante:", "Missing on target:": "Obiettivo mancato:", "Missing or invalid parameter": "Parametro mancante o non valido", + "Missing required command:": "Manca il comando required:", "Missing required parameter": "Parametro obbligatorio mancante", "Mixed GPU Modes": "Modalità GPU miste", "Mixed current mode detected in selected GPU(s).": "Modalità corrente mista rilevata nelle GPU selezionate.", @@ -2556,15 +3401,20 @@ "Mode": "Modalità", "Model": "Modello", "Modern resource monitor (press q to exit)": "Monitoraggio delle risorse moderne (premi q per uscire)", + "Modern, easy to use download automation for torrents and usenet.": "Moderno, facile da usare l'automazione download per torrent e usenet.", "Modifying Fastfetch configuration...": "Modifica della configurazione Fastfetch...", "Modules configuration updated.": "Configurazione dei moduli aggiornata.", "Modules loaded.": "Moduli caricati.", + "MongoDB 4.4, the last series that runs on a CPU without AVX.": "MongoDB 4.4, l'ultima serie che gira su una CPU senza AVX.", + "Monica is an open source personal relationship management system, that lets you document your life.": "Monica è un sistema di gestione delle relazioni personali open source che ti permette di documentare la tua vita.", "Monitor Activated": "Monitor attivato", "Monitor Deactivated": "Monitor disattivato", "Monitor URL": "Monitora l'URL", "Monitor disk I/O usage (press q to exit)": "Monitorare l'utilizzo dell'I/O del disco (premi q per uscire)", "Monitor progress:": "Monitorare i progressi:", + "Monitor, analyze, and alert on network performance.": "Monitora, analizza e segnala le prestazioni della rete.", "Monitoring": "monitoraggio", + "Monitoring & Analytics": "Monitoraggio e analisi", "Most common cause: the archive is corrupted (interrupted write, partial copy, or storage issue).": "Causa più comune: l'archivio è danneggiato (scrittura interrotta, copia parziale o problema di archiviazione).", "Mount Added Successfully:": "Montaggio aggiunto con successo:", "Mount CIFS share:": "Montare condivisione CIFS:", @@ -2592,13 +3442,19 @@ "Mount Samba Share on Host": "Monte Samba Condividi sull'host", "Mount USB disk?": "Montare il disco USB?", "Mount a USB drive now": "Monta ora un'unità USB", + "Mount activation cancelled": "Attivazione del montaggio annullata", "Mount all datasets": "Montare tutti i set di dati", "Mount already exists for this path in container": "Il montaggio esiste già per questo percorso nel contenitore", "Mount and persist with UUID:": "Montare e persistere con l'UUID:", + "Mount configuration cancelled": "Configurazione del montaggio annullata", "Mount failed": "Il montaggio non è riuscito", + "Mount mode applied": "Modalità di montaggio applicata", + "Mount name": "Nome di montaggio", + "Mount not authorized by the operation": "Montaggio non autorizzato dalla operation", "Mount options:": "Opzioni di montaggio:", "Mount path must be an absolute path starting with /": "Il percorso di montaggio deve essere un percorso assoluto che inizia con /", "Mount path:": "Percorso di montaggio:", + "Mount paths must not overlap": "I percorsi di montaggio non devono sovrapporsi", "Mount point created": "Punto di montaggio creato", "Mount point created.": "Punto di montaggio creato.", "Mount point is visible but NOT writable from inside the container": "Il punto di montaggio è visibile ma NON scrivibile dall'interno del contenitore", @@ -2607,11 +3463,14 @@ "Mount point ready:": "Punto di montaggio pronto:", "Mount point removed successfully": "Punto di montaggio rimosso correttamente", "Mount point:": "Punto di montaggio:", + "Mount points added:": "Punti di montaggio aggiunti:", + "Mount read-only": "Montaggio in sola lettura", "Mount shares on HOST first": "Montare prima le condivisioni su HOST", "Mount specific dataset": "Montare un set di dati specifico", "Mount status:": "Stato del montaggio:", "Mount this device and use it as the backup destination?": "Montare questo dispositivo e utilizzarlo come destinazione del backup?", "Mount was busy — performed lazy unmount": "Il montaggio era occupato: ha eseguito lo smontaggio pigro", + "Mount your cloud drive on your home NAS": "Montare l'unità cloud sul NAS domestico", "Mounted": "Montato", "Mounted ISO on device": "ISO montato sul dispositivo", "Mounted at": "Montato a", @@ -2626,8 +3485,17 @@ "Mounting here will hide existing files until unmounted.": "Il montaggio qui nasconderà i file esistenti finché non verranno smontati.", "Move that copy offsite (USB, password manager, another host). Delete it from this path when done.": "sposta la copia fuori sede (USB, gestore password, un altro host).Eliminalo da questo percorso una volta terminato.", "Move to target VM (remove from source VM config)": "Sposta nella VM di destinazione (rimuovi dalla configurazione della VM di origine)", + "Moving the data volumes aside": "Trasferire i volumi di dati da parte", + "Moving the data volumes aside...": "Spostare i volumi di dati da parte...", + "Multi-container application (experimental)": "Applicazione multicontainer (sperimentale)", + "Multi-line variables are not supported": "Le variabili multilinee non sono supportate", + "Multiple networks or external networks are not yet supported": "Le reti multiple o le reti esterne non sono ancora supportate", "Multiple recovery groups found in PBS. Pick the one that originally created the keyfile:": "Più gruppi di recupero trovati in PBS. Scegli quello che originariamente ha creato il file di chiavi:", "Multiple rootfs directories were found in this archive. Restore cannot continue automatically.": "In questo archivio sono state trovate più directory rootfs. Il ripristino non può continuare automaticamente.", + "Music Collection and Streaming Server": "Music Collection e Streaming Server", + "Music software that transforms your listening experience": "Software musicale che trasforma la tua esperienza di ascolto", + "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more.": "MySQL Workbench è uno strumento visivo unificato per architetti di database, sviluppatori e DBA. MySQL Workbench fornisce modelli di dati, sviluppo SQL e strumenti di amministrazione completi per la configurazione del server, l'amministrazione utente, il backup e molto altro ancora.", + "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL.": "Mylar3 è un scaricatore automatico Comic Book (cbr/cbz) da utilizzare con NZB e torrent scritti in pitone. Supporta SABnzbd, NZBGET, e molti client torrent oltre a DDL.", "NAS Systems": "Sistemi NAS", "NETWORK CONFIGURATION ANALYSIS": "ANALISI DELLA CONFIGURAZIONE DELLA RETE", "NFS Access Restricted": "Accesso NFS limitato", @@ -2691,24 +3559,33 @@ "NOT FOUND": "NON TROVATO", "NOTE: The host directory and its contents will remain unchanged.": "NOTA: la directory host e il suo contenuto rimarranno invariati.", "NVENC patch detected — list narrowed to versions supported by keylase/nvidia-patch.": "Rilevata patch NVENC: elenco ristretto alle versioni supportate da keylase/nvidia-patch.", + "NVIDIA (CUDA)": "NVIDIA (CUDA)", + "NVIDIA (CUDA; official GPU image)": "NVIDIA (CUDA; immagine ufficiale GPU)", + "NVIDIA (NVDEC/CUDA)": "NVIDIA (NVDEC/CUDA)", + "NVIDIA (NVENC/NVDEC)": "NVIDIA (NVENC/NVDEC)", "NVIDIA Actions": "Azioni NVIDIA", "NVIDIA CPU hiding already configured": "Nascondere la CPU NVIDIA già configurata", "NVIDIA Container Toolkit": "NVIDIA Container Toolkit", + "NVIDIA Container Toolkit could not generate the runtime inventory": "NVIDIA Container Toolkit non poteva generare l'inventario runtime", "NVIDIA Container Toolkit installed. GPU validation pending until the host restarts.": "NVIDIA Container Toolkit installato. Convalida GPU in sospeso fino al riavvio dell'host.", "NVIDIA Container Toolkit is incomplete. Missing:": "NVIDIA Container Toolkit è incompleto. Mancante:", "NVIDIA Container Toolkit is installed but its command line did not answer.": "NVIDIA Container Toolkit è installato ma la riga di comando non risponde.", + "NVIDIA Container Toolkit is missing on the host (nvidia-container-cli)": "NVIDIA Container Toolkit manca sull'host (nvidia-container-cli)", "NVIDIA Container Toolkit verified against the running driver.": "NVIDIA Container Toolkit verificato rispetto al driver in esecuzione.", "NVIDIA DKMS entries removed.": "Voci NVIDIA DKMS rimosse.", "NVIDIA Driver Uninstall": "Disinstallazione del driver NVIDIA", "NVIDIA Driver Version": "Versione del driver NVIDIA", "NVIDIA Drivers": "Driver NVIDIA", "NVIDIA Drivers Not Found": "Driver NVIDIA non trovati", + "NVIDIA GPU / CUDA (Toolkit on the host)": "NVIDIA GPU / CUDA (Toolkit sull'host)", "NVIDIA GPU Driver Installation": "Installazione del driver GPU NVIDIA", "NVIDIA GPU passthrough configured.": "Passthrough GPU NVIDIA configurato.", + "NVIDIA GPU prepared:": "GPU NVIDIA preparato:", "NVIDIA KVM args configured (kvm=off, vendor_id spoof)": "Argomenti NVIDIA KVM configurati (kvm=off, spoofing vendor_id)", "NVIDIA KVM hiding (cpu hidden=1)": "Nascondimento NVIDIA KVM (cpu nascosta=1)", "NVIDIA KVM hiding already configured": "Nascondiglio NVIDIA KVM già configurato", "NVIDIA Patch": "Patch NVIDIA", + "NVIDIA device outside the expected native profile": "dispositivo NVIDIA al di fuori del profilo nativo previsto", "NVIDIA driver": "Driver NVIDIA", "NVIDIA driver installed successfully.": "Driver NVIDIA installato correttamente.", "NVIDIA driver installed:": "Driver NVIDIA installato:", @@ -2716,6 +3593,7 @@ "NVIDIA drivers are not installed or not loaded on this host.": "I driver NVIDIA non sono installati o non caricati su questo host.", "NVIDIA host services disabled for VFIO mode": "Servizi host NVIDIA disabilitati per la modalità VFIO", "NVIDIA host services/autoload already aligned for native mode": "Servizi host/caricamento automatico NVIDIA già allineati per la modalità nativa", + "NVIDIA inside the container does not match the host driver or GPU": "NVIDIA all'interno del contenitore non corrisponde al driver host o GPU", "NVIDIA install incomplete. Check log:": "Installazione NVIDIA incompleta. Controlla il registro:", "NVIDIA installer downloaded successfully": "Il programma di installazione NVIDIA è stato scaricato correttamente", "NVIDIA installer extracted.": "Estratto il programma di installazione NVIDIA.", @@ -2724,29 +3602,50 @@ "NVIDIA installer returned error": "Il programma di installazione NVIDIA ha restituito un errore", "NVIDIA kernel modules unloaded successfully.": "I moduli del kernel NVIDIA sono stati scaricati correttamente.", "NVIDIA libs require approximately 1.5GB of free space.": "Le librerie NVIDIA richiedono circa 1,5 GB di spazio libero.", + "NVIDIA mount with an unauthorized source or target": "Supporto NVIDIA con una fonte non autorizzata o un obiettivo", "NVIDIA patch applied - check README for supported versions.": "Patch NVIDIA applicata: controlla README per le versioni supportate.", "NVIDIA patch not applied.": "Patch NVIDIA non applicata.", "NVIDIA per-BDF VFIO binding configured": "Associazione VFIO NVIDIA per-BDF configurata", + "NVIDIA permissions or device nodes differ from the official inventory": "Le autorizzazioni NVIDIA o i nodi del dispositivo differiscono dall'inventario ufficiale", + "NVIDIA refresh validated; the container is stopped and its settings are kept": "NVIDIA aggiornamento convalidato; il contenitore viene fermato e le sue impostazioni vengono mantenute", + "NVIDIA runtime libraries or components are missing": "Mancano librerie o componenti runtime NVIDIA", + "NVIDIA selection not supported by this profile": "Selezione NVIDIA non supportata da questo profilo", "NVIDIA services stopped and disabled.": "I servizi NVIDIA sono stati interrotti e disabilitati.", "NVIDIA udev rules and persistence service installed.": "Regole NVIDIA udev e servizio di persistenza installati.", "NVIDIA uninstallation steps completed.": "Passaggi di disinstallazione di NVIDIA completati.", "NVIDIA uninstaller completed.": "Programma di disinstallazione NVIDIA completato.", "NVIDIA update failed for LXC": "L'aggiornamento NVIDIA non è riuscito per LXC", "NVIDIA userspace libraries installed.": "Librerie dello spazio utente NVIDIA installate.", + "NVML does not match the current host driver": "NVML non corrisponde all'attuale driver host", "NVMe Disk Detected": "Rilevato disco NVMe", "NVMe critical_warning is 0 (no critical warnings reported).": "NVMe critical_warning è 0 (nessun avviso critico segnalato).", + "NVMe health status: PASSED": "Stato di salute NVMe: SUPERATO", "NVMe health status: WARNING (critical_warning =": "Stato di integrità NVMe: ATTENZIONE (critical_warning =", "NVMe skipped (to add as PCIe use 'Add Controller or NVMe PCIe to VM'):": "NVMe saltato (per aggiungere come PCIe utilizzare 'Aggiungi controller o NVMe PCIe alla VM'):", "NVMe-specific SMART log": "Log SMART specifico per NVMe", + "NVR & Cameras": "NVR e telecamere", + "NVR with optional VA-API video acceleration and hardware object detectors": "NVR con rilevatori di accelerazione video VA-API opzionali e oggetti hardware", + "NZBGet web interface": "Interfaccia web NZBGet", + "Name": "Nome", + "Name for this application": "Nome per questa applicazione", "Name for this target:": "Nome per questo obiettivo:", + "Name of the PostgreSQL user created on the first start": "Nome dell'utente PostgreSQL creato al primo avviamento", + "Name of the database created on the first start": "Nome del database creato al primo avviamento", + "Name of the internal worker node": "Nome del nodo interno del lavoratore", + "Name of this wallabag instance, shown in the interface and in 2FA codes": "Nome di questa istanza wallabag, mostrata nell'interfaccia e nei codici 2FA", + "Name or part of the description of the application": "Nome o parte della descrizione dell'applicazione", "Name:": "Nome:", + "Named accounts need private mode. Stop the container, set public: false in /config/config.js, start it again and create each user with: pct exec -- env THELOUNGE_HOME=/config s6-setuidgid abc thelounge add ": "I conti nominati hanno bisogno di modalità privata. Stop al contenitore, set public: false in /config/config.js, avviare di nuovo e creare ogni utente con: pct exec -- env THELOUNGE HOME=/config s6-setuidgid abc thelounge add ", "Neither /etc/kernel/cmdline nor /etc/default/grub found.": "Non sono stati trovati né /etc/kernel/cmdline né /etc/default/grub.", "Nesting feature enabled": "Funzionalità di annidamento abilitata", "NetBIOS Service: RUNNING": "Servizio NetBIOS: IN ESECUZIONE", "NetBIOS Service: STOPPED": "Servizio NetBIOS: ARRESTATO", "NetBIOS port 139:": "Porta NetBIOS 139:", + "NetBox": "NetBox", + "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations.": "Netbox è uno strumento di gestione degli indirizzi IP (IPAM) e di gestione delle infrastrutture dei data center (DCIM). Inizialmente concepito dal team di ingegneria di rete di DigitalOcean, NetBox è stato sviluppato specificamente per soddisfare le esigenze degli ingegneri della rete e delle infrastrutture. È destinato a funzionare come fonte di verità specifica di dominio per la rete operations.", "Network": "Rete", "Network :": "Rete :", + "Network & Firewall": "Rete e Firewall", "Network (interfaces, DNS)": "Rete (interfacce, DNS)", "Network Bridge": "Ponte di rete", "Network Commands": "Comandi di rete", @@ -2764,6 +3663,7 @@ "Network Restarted": "Rete riavviata", "Network Tools": "Strumenti di rete", "Network access:": "Accesso alla rete:", + "Network bridge": "Ponte di rete", "Network configuration backed up": "Backup della configurazione di rete", "Network configuration has been restored from backup.": "La configurazione di rete è stata ripristinata dal backup.", "Network connection failed to": "La connessione di rete non è riuscita", @@ -2776,12 +3676,16 @@ "Network service restarted successfully": "Il servizio di rete è stato riavviato correttamente", "Network service restarted successfully.": "Il servizio di rete è stato riavviato correttamente.", "Network share mounting (NFS/Samba) requires a PRIVILEGED container.": "Il montaggio della condivisione di rete (NFS/Samba) richiede un contenitore PRIVILEGED.", + "Network sysctls prepared:": "Sisctls di rete preparati:", "Network throughput test (client/server)": "Test di throughput della rete (client/server)", + "Network-wide Ad Blocking": "Blocco annuncio su scala di rete", + "Network-wide ad and tracker blocking": "Blocco ad e tracker su scala di rete", "NetworkManager Detected": "Rilevato gestore di rete", "NetworkManager has been removed successfully": "NetworkManager è stato rimosso con successo", "NetworkManager is running (may cause conflicts)": "NetworkManager è in esecuzione (potrebbe causare conflitti)", "NetworkManager is running, which may conflict with Proxmox.": "NetworkManager è in esecuzione, il che potrebbe entrare in conflitto con Proxmox.", "NetworkManager not running": "NetworkManager non in esecuzione", + "Networks the peers reach through the tunnel (0.0.0.0/0 = all traffic)": "Reti che i pari raggiungono attraverso il tunnel (0.0.0.0/0 = tutto il traffico)", "New Folder in /mnt": "Nuova cartella in /mnt", "New Group": "Nuovo gruppo", "New Search": "Nuova ricerca", @@ -2789,14 +3693,26 @@ "New Virtual Machine": "Nuova macchina virtuale", "New backup job": "Nuovo lavoro di backup", "New backups on this host will be unencrypted until a new keyfile is set up.": "i nuovi backup su questo host non saranno crittografati finché non verrà impostato un nuovo file di chiavi.", + "New image compatible:": "Nuova immagine compatibile:", + "New image installed": "Nuova immagine installata", + "New image installed, not verified yet": "Nuova immagine installata, non ancora verificata", + "New image verified, not saved yet": "Nuova immagine verificata, non ancora salvata", "New kernel staged; rebuilding DKMS drivers:": "nuovo kernel messo in scena;ricostruzione dei driver DKMS:", "New mount options to apply:": "Nuove opzioni di montaggio da applicare:", "New scheduled job (own timer + retention)": "Nuovo lavoro pianificato (timer personale + conservazione)", + "New value for": "Nuovo valore per", "New version available": "Nuova versione disponibile", "New version:": "Nuova versione:", "Next Step Required": "Passaggio successivo obbligatorio", "Next Steps:": "Passaggi successivi:", "Next step: stop that VM first, then run": "Passaggio successivo: arresta prima la VM, quindi eseguila", + "Nextcloud configuration cancelled": "Cancellazione della configurazione Nextcloud", + "Nextcloud gives you access to all your files wherever you are.": "Nextcloud ti dà accesso a tutti i tuoi file ovunque tu sia.", + "Nextcloud volume size in GB": "Dimensione del volume Nextcloud in GB", + "Nextcloud with private PostgreSQL and Redis dependencies": "Nextcloud con PostgreSQL privato e dipendenze Redis", + "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server.": "Nginx è un server web HTTP, proxy inverso, cache dei contenuti, bilanciatore di carico, server proxy TCP/UDP e server proxy di posta.", + "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.": "Webserver Nginx e proxy inverso con supporto php e un client Certbot integrato (Encrypt) . Contiene anche fail2ban per la prevenzione delle intrusioni.", + "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd.": "Ngircd è un server Internet Relay Chat gratuito, portatile e leggero per reti piccole o private, sviluppato sotto la GNU General Public License (GPL). È facile da configurare, può far fronte a indirizzi IP dinamici e supporta connessioni IPv6, SSL e PAM per l'autenticazione. È scritto da zero e non basato sull'IRCd originale.", "No": "NO", "No .ova or .ovf files found in:": "Nessun file .ova o .ovf trovato in:", "No .ovf descriptor found inside OVA.": "Nessun descrittore .ovf trovato in OVA.", @@ -2814,6 +3730,7 @@ "No CTs available in the system.": "Nessun CT disponibile nel sistema.", "No Changes Needed": "Nessuna modifica necessaria", "No Cleanup Needed": "Nessuna pulizia necessaria", + "No Compose file was given": "Nessun file Compose è stato dato", "No Controller/NVMe selected for now.": "Nessun controller/NVMe selezionato per ora.", "No Coral Detected": "Nessun Coral rilevato", "No Coral TPU device was found on this host (neither PCIe/M.2 nor USB).": "Nessun dispositivo Coral TPU è stato trovato su questo host (né PCIe/M.2 né USB).", @@ -2832,12 +3749,15 @@ "No Guest Shares": "Nessuna condivisione degli ospiti", "No IP": "Nessun IP", "No IP assigned": "Nessun IP assegnato", + "No IPv4 address was detected after 30 seconds.": "Nessun indirizzo IPv4 è stato rilevato dopo 30 secondi.", "No ISO file detected after UUP Dump process.": "Nessun file ISO rilevato dopo il processo di dump UUP.", "No ISO images found in Proxmox ISO storages.": "Nessuna immagine ISO trovata negli archivi ISO Proxmox.", "No ISO selected.": "Nessun ISO selezionato.", "No ISO was generated.": "Non è stata generata alcuna ISO.", "No Images Found": "Nessuna immagine trovata", "No Intel GPU detected on this system.": "Nessuna GPU Intel rilevata su questo sistema.", + "No LAN address was obtained": "Nessun indirizzo LAN è stato ottenuto", + "No LAN address was obtained for the service:": "Nessun indirizzo LAN è stato ottenuto per il servizio:", "No LXC containers available": "Nessun contenitore LXC disponibile", "No LXC containers found": "Nessun contenitore LXC trovato", "No LXC containers found on this system.": "Nessun contenitore LXC trovato su questo sistema.", @@ -2855,7 +3775,9 @@ "No NFS shares currently mounted.": "Nessuna condivisione NFS attualmente montata.", "No NVIDIA GPU detected on this system.": "Nessuna GPU NVIDIA rilevata su questo sistema.", "No NVIDIA GPU has been detected on this system. The installer will now exit.": "Nessuna GPU NVIDIA è stata rilevata su questo sistema. Il programma di installazione verrà ora chiuso.", + "No NVIDIA GPU is available": "No NVIDIA GPU è disponibile", "No NVIDIA driver installed.": "Nessun driver NVIDIA installato.", + "No OCI instances are registered.": "Nessuna istanza OCI è registrata.", "No PBS keyfile is installed on this host and no automatic recovery was possible.": "su questo host non è installato alcun file di chiavi PBS e non è stato possibile il ripristino automatico.", "No PVE vzdump job uses a": "nessun lavoro PVE vzdump utilizza a", "No PVs with old headers found.": "Nessun PV con intestazioni vecchie trovato.", @@ -2891,6 +3813,7 @@ "No Virtual Machines found on this system.": "Nessuna macchina virtuale trovata su questo sistema.", "No ZFS pools detected. Skipping ZFS ARC optimization.": "nessun pool ZFS rilevato. Saltare l'ottimizzazione ZFS ARC.", "No ZFS pools detected. Skipping ZFS autotrim.": "Nessun pool ZFS rilevato. Saltare l'autotrim ZFS.", + "No acceleration (CPU)": "Nessuna accelerazione (CPU)", "No accessible": "Non accessibile", "No accessible NFS servers found.": "Nessun server NFS accessibile trovato.", "No accessible Samba servers found.": "Nessun server Samba accessibile trovato.", @@ -2900,11 +3823,13 @@ "No active session": "Nessuna sessione attiva", "No additional GPU can be added.": "Non è possibile aggiungere alcuna GPU aggiuntiva.", "No additional device needs to be added.": "Non è necessario aggiungere alcun dispositivo aggiuntivo.", + "No applications match": "Nessuna corrispondenza delle applicazioni", "No archives": "Nessun archivio", "No archives found in this Borg repository.": "Nessun archivio trovato in questo repository Borg.", "No available Controllers/NVMe devices were found.": "Non è stato trovato alcun controller/dispositivo NVMe disponibile.", "No available disks found.": "Nessun disco disponibile trovato.", "No backup found, logrotate configuration not changed": "Nessun backup trovato, configurazione logrotate non modificata", + "No backup is scheduled: the rsnapshot lines in /config/crontabs/root are commented out. Uncomment or adjust the intervals you want, then restart the container.": "Nessun backup è programmato: le linee rsnapshot in /config/crontabs/root sono commentate. Scommentare o regolare gli intervalli che si desidera, quindi riavviare il contenitore.", "No backups": "nessun backup", "No backups found": "Nessun backup trovato", "No bridge configuration issues found": "Nessun problema di configurazione del bridge trovato", @@ -2921,6 +3846,7 @@ "No compatible PVE jobs": "Nessun lavoro PVE compatibile", "No compatible disk images found in:": "Nessuna immagine disco compatibile trovata in:", "No configuration issues found": "Nessun problema di configurazione trovato", + "No container of the stack was modified.": "Nessun contenitore dello stack è stato modificato.", "No container runtime available.": "Nessun runtime del contenitore disponibile.", "No container selected. Exiting.": "Nessun contenitore selezionato. In uscita.", "No controller/NVMe selected.": "Nessun controller/NVMe selezionato.", @@ -2951,11 +3877,13 @@ "No folders found in /mnt. Please create a new folder.": "Nessuna cartella trovata in /mnt. Per favore crea una nuova cartella.", "No folders found inside /mnt in the CT.": "Nessuna cartella trovata all'interno di /mnt nel CT.", "No format-safe disks are available.": "Non sono disponibili dischi formattati.", + "No free ProxMenux private /24 network is available": "Non è disponibile nessuna rete ProxMenux privata /24", "No gasket DKMS registrations remain.": "Non rimangono registrazioni DKMS di gasket.", "No group creation required — uses world-writable sticky bit permissions.": "Non è richiesta la creazione di gruppi: utilizza autorizzazioni sticky bit scrivibili da tutti.", "No host VFIO reconfiguration expected": "Non è prevista alcuna riconfigurazione VFIO dell'host", "No host VFIO/native binding changes were required.": "Non sono state necessarie modifiche al VFIO host/associazione nativa.", "No host backups were found in this PBS repository:": "non è stato trovato alcun backup dell'host in questo repository PBS:", + "No host directory is used by this application.": "Nessuna directory host viene utilizzata da questa applicazione.", "No host reboot expected": "Non è previsto il riavvio dell'host", "No host write access — server-side ACL or root_squash. Continuing anyway.": "Nessun accesso in scrittura sull'host: ACL lato server o root_squash. Continuando comunque.", "No host write access — server-side ACL. Continuing anyway.": "Nessun accesso in scrittura sull'host: ACL lato server. Continuando comunque.", @@ -2964,6 +3892,7 @@ "No iSCSI storage configured.": "Nessun archivio iSCSI configurato.", "No iSCSI storage found in Proxmox.": "Nessun archivio iSCSI trovato in Proxmox.", "No iSCSI targets found on portal": "Nessuna destinazione iSCSI trovata nel portale", + "No image was given": "Nessuna immagine è stata data", "No import disks selected for now.": "Nessun disco di importazione selezionato per ora.", "No importable disks available. System disks and protected disks are hidden.": "Nessun disco importabile disponibile. I dischi di sistema e i dischi protetti sono nascosti.", "No installation information available.": "Nessuna informazione di installazione disponibile.", @@ -2975,6 +3904,7 @@ "No mount point was specified.": "Non è stato specificato alcun punto di montaggio.", "No mount points found in any container": "Nessun punto di montaggio trovato in nessun contenitore", "No mount points found in container": "Nessun punto di montaggio trovato nel contenitore", + "No name was given": "Nessun nome è stato dato", "No network configuration backups found.": "Nessun backup della configurazione di rete trovato.", "No network interfaces configured (besides loopback)": "Nessuna interfaccia di rete configurata (a parte il loopback)", "No new Controller/NVMe entries were added.": "Non sono state aggiunte nuove voci Controller/NVMe.", @@ -2999,9 +3929,11 @@ "No scheduled backup jobs configured.": "nessun processo di backup pianificato configurato.", "No scheduled backup jobs found.": "Nessun processo di backup pianificato trovato.", "No scripts found for:": "Nessuno script trovato per:", + "No security relaxation is required for the reviewed profile.": "Nessun rilassamento di sicurezza è required per il profilo recensito.", "No self-test history found for": "Nessuna cronologia di autotest trovata per", "No self-test log available for": "Nessun registro di autotest disponibile per", "No server IP or hostname provided.": "Nessun IP del server o nome host fornito.", + "No shared media content.": "Nessun contenuto di media condiviso.", "No shared mount detected. Applying standard local access.": "Nessun montaggio condiviso rilevato. Applicazione dell'accesso locale standard.", "No shares configured.": "Nessuna condivisione configurata.", "No shares found in smb.conf.": "Nessuna condivisione trovata in smb.conf.", @@ -3031,24 +3963,34 @@ "No valid mount points found": "Nessun punto di montaggio valido trovato", "No version in this branch is currently supported by keylase/nvidia-patch — the NVENC patch will not reapply after reinstall.": "Nessuna versione in questo ramo è attualmente supportata da keylase/nvidia-patch: la patch NVENC non verrà riapplicata dopo la reinstallazione.", "No virtual machines were found on this host.": "Nessuna macchina virtuale trovata su questo host.", + "No working NVIDIA GPU was found": "Nessun lavoro NVIDIA GPU è stato trovato", "No write permissions on:": "Nessuna autorizzazione di scrittura su:", "No, keep local only": "No, mantieni solo locale", "No-subscription repository present": "Nessun repository di abbonamento presente", "No: the key stays only at": "No: la chiave rimane solo a", + "Node octal permissions (e.g. 0660)": "Nodo ottale autorizzazioni (es. 0660)", "Non-Debian container detected": "Rilevato contenitore non Debian", "Non-free firmware warnings disabled": "Avvisi firmware non liberi disabilitati", "None": "Nessuno", "Normalizing stable monitor service...": "Normalizzazione del servizio di monitoraggio stabile in corso...", "Not Mounted": "Non montato", + "Not a JSON object:": "Non un oggetto JSON:", "Not all platforms support Controller/NVMe passthrough reliably.": "Non tutte le piattaforme supportano il passthrough Controller/NVMe in modo affidabile.", + "Not all shared directories were verified": "Non tutte le directory condivise sono state verificate", "Not an OVH server, skipping RTM installation": "Non è un server OVH, salta l'installazione RTM", "Not currently mounted": "Attualmente non montato", "Not currently mounted — skipping umount.": "Attualmente non montato: salta lo smontaggio.", + "Not enough free space for the backup": "Non abbastanza spazio libero per il backup", "Not found": "Non trovato", + "Not found in the OCI archive:": "Non trovato nell'archivio OCI:", "Not imported:": "Non importato:", "Not mounted": "Non montato", "Not portable:": "Non portatile:", "Not registered as Proxmox storage — use 'LXC Mount Manager' to bind-mount": "Non registrato come storage Proxmox: utilizzare \"LXC Mount Manager\" per eseguire il bind-mount", + "Not required (access code only)": "Non required (solo codice di accesso)", + "Not required (password only)": "Non required (solo password)", + "Not required (token only)": "Non required (solo token)", + "Not yet verified by ProxMenux (beta)": "Non ancora verificato da ProxMenux (beta)", "Note: A system reboot will be required after enabling IOMMU.": "Nota: sarà necessario riavviare il sistema dopo aver abilitato IOMMU.", "Note: this only works if the NFS server does NOT use 'all_squash' for root.": "Nota: funziona solo se il server NFS NON utilizza 'all_squash' per root.", "Notes": "Note", @@ -3063,8 +4005,19 @@ "Nothing to schedule for reboot from selected paths.": "Niente da pianificare per il riavvio dai percorsi selezionati.", "Nouveau module is loaded, attempting to unload...": "Il modulo Nouveau è caricato, tentativo di scaricamento...", "Number of CPU cores (default: 2)": "Numero di core della CPU (impostazione predefinita: 2)", + "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources.": "Nzbget è un downloader usenet, scritto in C++ e progettato con le prestazioni in mente per raggiungere la massima velocità di download utilizzando pochissime risorse di sistema.", + "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra.": "Nzbhydra2 è un'applicazione di ricerca meta per gli indici NZB, il successore spirituale di NZBmegasearcH, e un'evoluzione dell'applicazione originale NZBHydra.", "OCI containers require Proxmox VE 9.1 or later.": "I contenitori OCI richiedono Proxmox VE 9.1 o versione successiva.", + "OCI management": "Gestione OCI", + "OCI management could not be completed. Check the backend status; no additional cleanup has been authorized.": "La gestione OCI non poteva essere completata. Controlla lo stato del backend; non è stata autorizzata alcuna pulizia aggiuntiva.", + "OCI manager Apps is a beta: if something does not work as expected, please report it on GitHub with the application name.": "OCI manager Apps è una beta: se qualcosa non funziona come previsto, si prega di segnalarlo su GitHub con il nome dell'applicazione.", + "OCI metadata integrity mismatch": "OCI metadati integrità mismatch", + "OCI metadata too large": "OCI metadati troppo grandi", + "OCI stack management": "Gestione dello stack OCI", + "OCI verification failed:": "La verifica OCI ha fallito:", + "OCR language (Tesseract code)": "Lingua OCR (Codice Tesseract)", "OK": "OK", + "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms.": "ONLYOFFICE fornisce una gamma completa di strumenti per creare, modificare e collaborare su documenti di testo, fogli di calcolo, presentazioni, moduli PDF e file PDF regolari su piattaforme web, desktop e mobili.", "OR add new PVE 9 no-subscription repository:": "OPPURE aggiungi un nuovo repository PVE 9 senza abbonamento:", "OS hint:": "Suggerimento del sistema operativo:", "OS release details": "Dettagli sulla versione del sistema operativo", @@ -3078,11 +4031,18 @@ "OVH RTM removed (Puppet artefacts may need manual cleanup)": "OVH RTM rimosso (gli artefatti dei pupazzi potrebbero richiedere una pulizia manuale)", "OVH server detected": "Rilevato server OVH", "OVH server detection and RTM installation process completed": "Processo di rilevamento dei server OVH e installazione RTM completato", + "Observer is not responding on port 4357": "L'osservatore non risponde al porto 4357", + "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption.": "Obsidian è un app che ti permette di creare, collegare e organizzare le tue note sul tuo dispositivo, con centinaia di plugin e temi per personalizzare il tuo flusso di lavoro. Puoi anche pubblicare le tue note online, accederle offline e sincronizzarle in modo sicuro con la crittografia end-to-end.", "Offer as exit node?": "Offrire come nodo di uscita?", + "Official Emby Media Server image with optional VA-API or NVIDIA acceleration.": "Immagine ufficiale del server multimediale Emby con accelerazione opzionale VA-API o NVIDIA.", + "Official Jellyfin image with optional VA-API or NVIDIA acceleration.": "Immagine ufficiale Jellyfin con accelerazione opzionale VA-API o NVIDIA.", "Official Linux Distributions": "Distribuzioni Linux ufficiali", + "Official Plex Media Server image with optional hardware transcoding.": "Immagine ufficiale del server multimediale Plex con transcodifica hardware opzionale.", + "Official image": "Immagine ufficiale", "Old debian.sources file removed to prevent duplication": "Il vecchio file debian.sources è stato rimosso per evitare duplicazioni", "Old memory configuration detected. Replacing with balanced optimization...": "Rilevata vecchia configurazione di memoria. Sostituzione con ottimizzazione bilanciata...", "Old time services removed successfully": "I vecchi servizi sono stati rimossi con successo", + "Ombi allows you to host your own Plex Request and user management system.": "Ombi consente di ospitare il proprio sistema di richiesta e gestione utente Plex.", "On a privileged CT the mount options carry the only permissions.": "Su un CT privilegiato le opzioni di montaggio hanno le uniche autorizzazioni.", "On some systems, when starting the VM the host may slow down for several minutes until it stabilizes, or freeze completely.": "Su alcuni sistemi, all'avvio della VM l'host potrebbe rallentare per diversi minuti fino a stabilizzarsi, o bloccarsi completamente.", "On the Borg server, append the following line to:": "Sul server Borg, aggiungi la seguente riga a:", @@ -3091,32 +4051,52 @@ "Once finished, re-run the script 'PVE 8 to 9 check' to verify that all issues.": "Una volta terminato, eseguire nuovamente lo script \"PVE 8 to 9 check\" per verificare che tutti i problemi siano corretti.", "Once installed, open the VirtIO ISO and run the installer to complete driver setup.": "Una volta installato, apri l'ISO VirtIO ed esegui il programma di installazione per completare la configurazione del driver.", "One or more NVIDIA GPUs are currently configured for VM passthrough (vfio-pci):": "Una o più GPU NVIDIA sono attualmente configurate per il passthrough VM (vfio-pci):", + "Online retro games emulator": "Emulatore di giochi retrò online", + "Only a Docker Swarm uses these settings, so they are not applied:": "Solo un Docker Swarm utilizza queste impostazioni, quindi non vengono applicate:", "Only convert to privileged if absolutely necessary for your use case.": "Converti in privilegiato solo se assolutamente necessario per il tuo caso d'uso.", "Only fully free disks are shown (not system-used and not referenced by VM/LXC).": "Vengono visualizzati solo i dischi completamente liberi (non utilizzati dal sistema e non referenziati da VM/LXC).", "Only if using enterprise subscription": "Solo se si utilizza l'abbonamento aziendale", "Only if using no-subscription repository": "Solo se si utilizza un repository senza abbonamento", "Only needed if you mounted the filesystem in step 6b": "Necessario solo se hai montato il filesystem nel passaggio 6b", + "Only one image at a time can be installed this way.": "Solo un'immagine alla volta può essere installata in questo modo.", "Only removes storage definition, not remote data.": "Rimuove solo la definizione di archiviazione, non i dati remoti.", "Only run this if you used LVM (step 6b):": "Eseguilo solo se hai utilizzato LVM (passaggio 6b):", "Only the host backup hook is removed — PVE vzdump jobs targeting this storage stay intact.": "viene rimosso solo l'hook di backup dell'host: i processi PVE vzdump destinati a questo storage rimangono intatti.", + "Only the image reference, with no Compose file": "Solo il riferimento dell'immagine, senza file Compose", "Open": "Aprire", + "Open Source realtime backend in 1 file": "Open Source backend in tempo reale in 1 file", "Open rwx + default inheritance for new files": "Apri rwx + ereditarietà predefinita per i nuovi file", + "Open source chat UI for AI models": "Open source chat UI per modelli AI", + "Open source home automation that puts local control and privacy first.": "Automazione domestica open source che mette il controllo locale e la privacy prima.", + "Open source, lightweight, native, supports (HTTP, BitTorrent, Magnet, etc.) for downloading.": "Open source, leggero, nativo, supporti (HTTP, BitTorrent, Magnet, ecc.) per il download.", "Open the VM console and wait for the installer to boot": "Apri la console della VM e attendi l'avvio del programma di installazione", "Open the VM console and wait for the loader to boot": "Apri la console della VM e attendi l'avvio del caricatore", "Open the dashboard from this host on port 8008 to create a new admin account.": "Apri la dashboard da questo host sulla porta 8008 per creare un nuovo account amministratore.", "Open the dashboard to create a new admin account:": "Apri la dashboard per creare un nuovo account amministratore:", + "Open-source AI-powered coding assistant": "Assistente di codifica AI-powered open source", + "Open-source UI for building and debugging multi-agent and RAG applications": "UI open source per la costruzione e il debug di applicazioni multi-agent e RAG", + "OpenClaw is a personal AI assistant you run on your own devices": "OpenClaw è un assistente personale AI che si esegue sui propri dispositivi", + "OpenList": "OpenList", + "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world.": "OpenShot Video Editor è un premiato editor video gratuito e open source per Linux, Mac e Windows, ed è dedicato a fornire soluzioni di video editing e animazione di alta qualità al mondo.", + "OpenVINO requires a CPU quota to keep the CPU topology": "OpenVINO requires una quota della CPU per mantenere la topologia della CPU", + "OpenVINO requires the render device of an Intel GPU": "OpenVINO requires il dispositivo di rendering di una GPU Intel", "OpenVSwitch installation could not be verified": "Impossibile verificare l'installazione di OpenVSwitch", "OpenVSwitch installed successfully": "OpenVSwitch installato correttamente", "OpenVSwitch is ready to use": "OpenVSwitch è pronto per l'uso", "OpenVSwitch removed": "OpenVSwitch rimosso", + "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server.": "Openssh-server è un ambiente sandbox che consente l'accesso a ssh senza dare le chiavi all'intero server.", + "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser.": "Openvscode-server fornisce una versione di VS Code che gestisce un server su una macchina remota e consente l'accesso tramite un browser web moderno.", + "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features.": "Opera è un browser web multi-piattaforma sviluppato dalla sua omonima azienda Opera. Il browser è basato su Chromium, ma si distingue da altri browser basati su Chromium (Chrome, Edge, ecc.) attraverso la sua interfaccia utente e altre funzionalità.", "Operation": "Operazione", "Operation cancelled by user": "Operazione annullata dall'utente", "Operation cancelled by user to create backup.": "Operazione annullata dall'utente per creare il backup.", "Operation cancelled by user.": "Operazione annullata dall'utente.", + "Operation cancelled.": "Operation annullato.", "Operation cancelled. Cannot continue with an unprivileged container.": "Operazione annullata. Impossibile continuare con un contenitore senza privilegi.", "Operation log": "Registro delle operazioni", "Operator config re-applied via kernel-agnostic merge": "configurazione dell'operatore riapplicata tramite unione indipendente dal kernel", "Operator config that WILL be re-applied via kernel-agnostic merge": "configurazione dell'operatore che verrà riapplicata tramite unione indipendente dal kernel", + "Optical block device (e.g. /dev/sr0)": "Dispositivo di blocco ottico (ad esempio /dev/sr0)", "Optimizations detected and ready to revert.": "Ottimizzazioni rilevate e pronte per essere ripristinate.", "Optimize": "Ottimizzare", "Optimize Memory": "ottimizza la memoria", @@ -3129,8 +4109,12 @@ "Optimizing network settings...": "Ottimizzazione delle impostazioni di rete...", "Optimizing vzdump backup speed...": "Ottimizzazione della velocità di backup di vzdump in corso...", "Optional": "facoltativo", + "Optional GID of the plex group": "GID opzionale del gruppo plex", "Optional GPU Passthrough": "Passthrough GPU opzionale", + "Optional published URL for Jellyfin": "URL pubblicato facoltativo per Jellyfin", "Optional safety helper if you ever need to re-apply manually:": "Assistente di sicurezza opzionale se hai bisogno di riapplicare manualmente:", + "Optional token from https://www.plex.tv/claim": "Token opzionale da https://www.plex.tv/claim", + "Optional, not mounted by default": "Opzionale, non montato per impostazione predefinita", "Optional: Modernize repository sources:": "Facoltativo: modernizzare le origini del repository:", "Optional: apply default ACL so new files inherit permissions:": "Facoltativo: applica l'ACL predefinito in modo che i nuovi file ereditino le autorizzazioni:", "Optional: register this path as Proxmox dir storage:": "Facoltativo: registrare questo percorso come archiviazione della directory Proxmox:", @@ -3141,13 +4125,18 @@ "Or re-run this script and accept the 'apply host permissions' prompt.": "Oppure esegui nuovamente questo script e accetta la richiesta \"applica autorizzazioni host\".", "Or use ProxMenux update function": "Oppure usa la funzione di aggiornamento di ProxMenux", "Or, if your terminal can't select text, copy it from:": "oppure, se il tuo terminale non può selezionare il testo, copialo da:", + "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community": "Orca Slicer è un affettatore open source per stampanti FDM. OrcaSlicer è fork di Bambu Studio, era precedentemente conosciuto come BambuStudio-SoftFever, Bambu Studio è forked da PrusaSlicer di Prusa Research, che è da Slic3r di Alessandro Ranellucci e la comunità RepRap", "Original ZFS ARC config restored from .bak": "Configurazione originale di ZFS ARC ripristinata da .bak", "Original bashrc restored": "Bashrc originale restaurato", "Original logrotate configuration restored": "Configurazione logrotate originale ripristinata", + "Orphan stack contract archived:": "Orphan stack contratto archiviato:", + "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.": "Oscam è un software Open Source Conditional Access Module utilizzato per descrambling DVB transmissions che utilizza smart card. E' sia un server che un client.", "Other Prebuilt Linux VMs": "Altre VM Linux predefinite", "Output archive:": "Archivio di output:", + "Overseerr is a request management and media discovery tool built to work with your existing Plex ecosystem.": "Overseerr è uno strumento di gestione delle richieste e di scoperta dei media costruito per lavorare con il vostro ecosistema Plex esistente.", "Owner:": "Proprietario:", "Ownership set to root:sharedfiles with 2775 on:": "Proprietà impostata su root:sharedfiles con 2775 su:", + "P2P bittorrent download": "P2P bittorrent scaricare", "PAM limits configured": "Limiti PAM configurati", "PBS API log rotation configured (hourly, size-based)": "rotazione del log API PBS configurata (oraria, in base alle dimensioni)", "PBS backup error log": "Registro degli errori del backup PBS", @@ -3164,7 +4153,9 @@ "PCI reset method": "Metodo di ripristino PCI", "PCIe GPU passthrough requires:": "Il passthrough GPU PCIe richiede:", "PCIe/M.2 gasket-dkms": "PCIe/M.2 gasket-dkms", + "PCSX2 is an open source PS2 Emulator.": "PCSX2 è un emulatore PS2 open source.", "POSIX ACLs applied (access + default for inheritance).": "ACL POSIX applicati (accesso + impostazione predefinita per ereditarietà).", + "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability.": "PPSSPP è un emulatore PSP gratuito e open source per Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series e Symbian con un focus sulla velocità e la portabilità.", "PVE application manager updated": "Gestore applicazioni PVE aggiornato", "PVE cache regenerated": "Cache PVE rigenerata", "PVE host (where the Borg LXC lives)": "host PVE (dove vive il Borg LXC)", @@ -3179,17 +4170,28 @@ "Package update had issues, checking details...": "L'aggiornamento del pacchetto presentava problemi, verifica dei dettagli...", "Packages from backup to install:": "pacchetti dal backup all'installazione:", "Packages installed: {count}.": "pacchetti installati: {count}.", + "Packages to be upgraded": "Pacchetti da aggiornare", "Packages upgrade successfull": "Aggiornamento dei pacchetti riuscito", "Packages upgraded": "Pacchetti aggiornati", "Packages:": "Pacchetti:", "Packaging OVA file...": "Confezione del file OVA...", "Packing installer archive...": "Compressione dell'archivio del programma di installazione...", + "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices.": "PairDrop è una sublime alternativa a AirDrop che funziona su tutte le piattaforme. Invia immagini, documenti o testo tramite connessione peer to peer a dispositivi nella stessa rete locale/Wi-Fi o a dispositivi abbinati.", + "Paperless configuration cancelled": "Configurazione senza carta cancellata", + "Paperless-ngx WebUI": "Paperless-ngx WebUI", "Parsing OVF descriptor...": "Analisi del descrittore OVF in corso...", "Partial VM removed": "VM parziale rimossa", "Partition": "Partizione", "Partition created": "Partizione creata", "Partition created:": "Partizione creata:", "Partition table wiped": "Tabella delle partizioni cancellata", + "Pass /dev/kvm to the LXC": "Passa /dev/kvm al LXC", + "Pass /dev/net/tun to the LXC": "Passare /dev/net/tun al LXC", + "Pass /dev/ttyUSB0 to the LXC": "Passa /dev/ttyUSB0 al LXC", + "Pass /dev/video10 to the LXC": "Passa /dev/video10 al LXC", + "Pass /dev/video11 to the LXC": "Passa /dev/video11 al LXC", + "Pass /dev/video12 to the LXC": "Passa /dev/video12 al LXC", + "Pass a host device to the LXC": "Passare un dispositivo host al LXC", "Passphrase used to unlock the imported keyfile (leave blank if the keyfile is unencrypted / kdf=none):": "passphrase utilizzata per sbloccare il file di chiavi importato (lascia vuoto se il file di chiavi non è crittografato / kdf=none):", "Passphrases do not match.": "Le passphrase non corrispondono.", "Passphrases do not match. Try again.": "Le passphrase non corrispondono. Riprova.", @@ -3202,17 +4204,42 @@ "Password confirmation cannot be empty.": "La conferma della password non può essere vuota.", "Password confirmation is required.": "È richiesta la conferma della password.", "Password for": "Parola d'ordine per", + "Password for aMule external connections (remote client)": "Password per connessioni esterne aMule (cliente di rimozione)", + "Password for the SSH login": "Password per il login SSH", "Password for:": "Password per:", "Password is correct": "La password è corretta", + "Password of the AdGuard Home that receives the settings": "Password del AdGuard Home che riceve le impostazioni", + "Password of the Adguardhome Sync web interface": "Password dell'interfaccia web Adguardhome Sync", + "Password of the Duplicati web interface": "Password dell'interfaccia web Duplicati", + "Password of the Etherpad admin user": "Password dell'utente amministratore Etherpad", + "Password of the FlexGet web interface": "Password dell'interfaccia web FlexGet", + "Password of the LibreDB Studio administrator": "Password dell'amministratore LibreDB Studio", + "Password of the MineOS web interface user": "Password dell'utente dell'interfaccia web MineOS", + "Password of the NetBox admin account": "Password dell'account amministratore NetBox", + "Password of the OpenList admin user": "Password dell'utente amministratore OpenList", + "Password of the PhotoPrism admin user (at least 8 characters)": "Password dell'utente di amministrazione PhotoPrism (almeno 8 caratteri)", + "Password of the PostgreSQL user": "Password dell'utente PostgreSQL", + "Password of the SnapOtter admin user": "Password dell'utente amministratore SnapOtter", + "Password of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Password del deprecato login applicazione Flowise (solo letto da versioni Flowise prima 3.0.1)", + "Password of the main AdGuard Home": "Password del AdGuard Home principale", "Password or API token secret:": "Segreto password o token API:", + "Password or secret": "Password o segreto", "Password reset completed.": "Reimpostazione della password completata.", + "Password to access the aMule web interface": "Password per accedere all'interfaccia web aMule", "Passwords do not match. Please try again.": "Le password non corrispondono. Per favore riprova.", + "Paste it here and press Ctrl+D on an empty line.": "Incolla qui e premi Ctrl+D su una linea vuota.", + "Paste its Compose file in the terminal": "Incolla il suo file Compose nel terminale", + "Paste its docker run command in the terminal": "Incolla il comando di esecuzione docker nel terminale", "Paste the UUP Dump URL here": "Incolla qui l'URL del dump UUP", "Patching source for kernel compatibility...": "Fonte di patch per la compatibilità del kernel...", "Path does not exist.": "Il percorso non esiste.", + "Path inside the container": "Percorso all'interno del contenitore", + "Path inside the container (e.g. /media-extra)": "Percorso all'interno del contenitore (ad esempio /media-extra)", + "Path inside the remote (empty = root)": "Percorso all'interno del telecomando (vuoto = radice)", "Path must be absolute (start with /)": "Il percorso deve essere assoluto (inizia con /)", "Path must be absolute (start with /).": "Il percorso deve essere assoluto (inizia con /).", "Path not found": "Percorso non trovato", + "Path of the Compose file": "Percorso del file Compose", "Path:": "Sentiero:", "Paths applied:": "Percorsi applicati:", "Paths included in backup": "Percorsi inclusi nel backup", @@ -3220,6 +4247,10 @@ "Paths skipped:": "Percorsi saltati:", "Paths to back up:": "Percorsi di cui eseguire il backup:", "Paths:": "Percorsi:", + "Peers reach the server through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "I pari raggiungono il server attraverso l'indirizzo pubblico e la porta UDP data durante l'installazione, in modo che la porta debba essere inoltrata a questo contenitore.", + "Peers to create: a number (3) or a list of names (phone,laptop)": "Peers per creare: un numero (3) o un elenco di nomi (telefono, laptop)", + "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration.": "Pelorus è un navigatore AI per desktop Linux alimentati da Selkies. Pelorus esegue un server FastAPI che fornisce un agente LLM (Ollama, compatibile con OpenAI o Gemini) il controllo sul mouse, sulla tastiera, sullo screenshot e sulla gestione delle finestre tramite il backend computer-use Pixelflux, un albero di accessibilità Linux (AT-SPI), e l'integrazione opzionale KWin D-Bus.", + "Pending components:": "Componenti in attesa:", "Pending restore ID:": "ID ripristino in sospeso:", "Pending restore dir:": "Dir ripristino in attesa:", "Pending restore prepared. A reboot is required to complete it.": "Ripristino in attesa preparato. Per completarlo è necessario un riavvio.", @@ -3243,7 +4274,15 @@ "Permission error": "Errore di autorizzazione", "Permissions:": "Autorizzazioni:", "Persist mount in CT /etc/fstab (optional):": "Persistenza del montaggio in CT /etc/fstab (opzionale):", + "Persistence for": "Persistenza per", + "Persistence for the new path": "Persistenza per il nuovo percorso", + "Persistent data:": "Dati persistenti:", + "Persistent disk reused:": "Disco persistente riutilizzato:", "Persistent:": "Persistente:", + "Personal finance management application": "Applicazione della gestione della finanza personale", + "Photo and video library with optional GPU transcoding and machine learning": "Libreria fotografica e video con transcodifica GPU opzionale e machine learning", + "PhotoPrism": "PhotoPrism", + "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB.": "Phpmyadmin è uno strumento software gratuito scritto in PHP, destinato a gestire l'amministrazione di MySQL sul Web. phpMyAdmin supporta una vasta gamma di operations su MySQL e MariaDB.", "Physical Function with": "Funzione fisica con", "Physical interface": "Interfaccia fisica", "Physical interfaces available": "Interfacce fisiche disponibili", @@ -3256,6 +4295,10 @@ "Pick a target to remove:": "Scegli un target da rimuovere:", "Pick an SSH private key (auto-detected on this host):": "scegli una chiave privata SSH (rilevata automaticamente su questo host):", "Pick an alternative way to authorize the new key:": "scegli un modo alternativo per autorizzare la nuova chiave:", + "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time.": "Pidgin è un programma di chat che consente di accedere ai conti su più reti di chat contemporaneamente. Ciò significa che è possibile chattare con gli amici su XMPP e sedersi in un canale IRC allo stesso tempo.", + "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper.": "Piper è un testo neurale veloce e locale al sistema vocale che suona grande ed è ottimizzato per il Raspberry Pi 4. Questo contenitore fornisce un server di protocollo Wyoming per Piper.", + "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures.": "Piwigo è un software di galleria fotografica per il web che viene fornito con caratteristiche potenti per pubblicare e gestire la vostra collezione di immagini.", + "Planka is an elegant open source project tracking tool.": "Planka è un elegante strumento di monitoraggio del progetto open source.", "Please check network connectivity.": "Controlla la connettività di rete.", "Please check permissions and try again.": "Controlla le autorizzazioni e riprova.", "Please check the installation.": "Si prega di verificare l'installazione.", @@ -3273,6 +4316,10 @@ "Please select GPU(s) that are currently in the same mode and try again.": "Seleziona le GPU che sono attualmente nella stessa modalità e riprova.", "Please select a valid option": "Seleziona un'opzione valida", "Please use an SSH session (Linux, macOS, Windows/PuTTY) or a physical console to perform the upgrade.": "Utilizza una sessione SSH (Linux, macOS, Windows/PuTTY) o una console fisica per eseguire l'aggiornamento.", + "Plex WebUI": "Plex WebUI", + "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.": "Plex organizza video, musica e foto da librerie di media personali e li trasmette a smart TV, caselle di streaming e dispositivi mobili. Questo contenitore è confezionato come server multimediale Plex standalone. Design dritto e le azioni di massa significa ottenere le cose fatte più velocemente.", + "PocketBase admin UI": "UI di amministrazione PocketBase", + "Podcast synchronization service": "Servizio di sincronizzazione Podcast", "Pool does not appear to use SSD/NVMe devices with discard support. Skipping ZFS autotrim for pool:": "Il pool non sembra utilizzare dispositivi SSD/NVMe con supporto di eliminazione. Saltare l'autotrim ZFS per il pool:", "Pool exists": "La piscina esiste", "Pool name matches but GUID differs (fresh ZFS install):": "il nome del pool corrisponde ma il GUID è diverso (nuova installazione ZFS):", @@ -3283,12 +4330,21 @@ "Portal IP and port are correct": "L'IP e la porta del portale sono corretti", "Portal is reachable": "Il portale è raggiungibile", "Portal:": "Portale:", + "Ports": "Porti", "Portuguese": "portoghese", "Post-Installation Options": "Opzioni post-installazione", "Post-Installation Scripts": "Script post-installazione", "Postfix configuration": "Configurazione suffissa", + "PostgreSQL": "PostgreSQL", + "PostgreSQL URL without an associated service:": "URL PostgreSQL senza un servizio associato:", + "PostgreSQL creates the database named in POSTGRES_DB on the first start. The installer default is postgresql.": "PostgreSQL crea il database chiamato in POSTGRES DB al primo avvio. L'impostazione predefinita è postgresql.", + "PostgreSQL is an advanced, enterprise-class, and open-source relational database system. PostgreSQL supports both SQL (relational) and JSON (non-relational) querying.": "PostgreSQL è un sistema di database relazionale avanzato, di classe enterprise e open source. PostgreSQL supporta sia querying SQL (relazionale) che JSON (non relazionale).", + "PostgreSQL requires a password": "PostgreSQL requires una password", + "PostgreSQL volume size in GB": "Dimensione del volume PostgreSQL in GB", "Potential QEMU startup/assertion failures": "Potenziali errori di avvio/asserzione di QEMU", "Power state D3cold/D0 transitions may be inaccessible": "Le transizioni dello stato di alimentazione D3freddo/D0 potrebbero essere inaccessibili", + "Powerful OCR powered by DeepSeek AI": "Potente OCR alimentato da DeepSeek AI", + "Powerful networking tool": "Potente strumento di networking", "Pre-check found": "Pre-controllo trovato", "Pre-configure destinations so you don't have to enter them every time you back up.": "Preconfigura le destinazioni in modo da non doverle inserire ogni volta che esegui il backup.", "Pre-existing gasket-dkms package removed.": "Pacchetto gasket-dkms preesistente rimosso.", @@ -3296,11 +4352,15 @@ "Pre-upgrade check FAILED: the simulation shows that 'proxmox-ve' would be REMOVED.\n This indicates a repository or dependency issue and upgrading now could break your Proxmox installation.": "Controllo pre-aggiornamento FALLITO: la simulazione mostra che 'proxmox-ve' verrebbe RIMOSSO.\n Ciò indica un problema di repository o dipendenza e l'aggiornamento ora potrebbe interrompere l'installazione di Proxmox.", "Pre-upgrade simulation failed. See log:": "Simulazione pre-aggiornamento non riuscita. Vedi registro:", "Pre-upgrade simulation passed: 'proxmox-ve' will be kept or upgraded safely.": "Simulazione pre-aggiornamento superata: 'proxmox-ve' verrà mantenuto o aggiornato in modo sicuro.", + "Prepared; the container was not modified yet": "Preparato; il contenitore non è stato ancora modificato", "Preparing Log2RAM configuration": "Preparazione della configurazione Log2RAM", "Preparing files for backup...": "Preparazione dei file per il backup...", "Preparing host mount...": "Preparazione del montaggio dell'host in corso...", "Preparing pending restore (network-safe)": "Preparazione del ripristino in sospeso (sicuro per la rete)", "Preparing staging area...": "Preparazione dell'area di sosta...", + "Preparing the NVIDIA GPU...": "Preparare la GPU NVIDIA...", + "Preparing the recreation...": "Preparare la ricreazione...", + "Preparing the update...": "Preparare l'aggiornamento...", "Preserving logs to /var/log.hdd before unmounting...": "Conservazione dei log su /var/log.hdd prima dello smontaggio...", "Press 'q' to exit": "Premere 'q' per uscire", "Press Ctrl+C to stop the server and return to menu.": "Premi Ctrl+C per arrestare il server e tornare al menu.", @@ -3316,6 +4376,7 @@ "Press Enter to return": "Premere Invio per tornare", "Press Enter to return to menu...": "Premere Invio per tornare al menu...", "Press Enter to return to the main menu...": "Premere Invio per tornare al menu principale...", + "Press Enter to return to the menu...": "Premere Invio per tornare al menu...", "Press Enter to return...": "Premi Invio per tornare...", "Press Enter when the line has been pasted on the server...": "premi Invio quando la riga è stata incollata sul server...", "Press OK to see the preview, then confirm": "Premere OK per vedere l'anteprima, quindi confermare", @@ -3325,9 +4386,19 @@ "Preview changes (diff)": "Anteprima modifiche (diff)", "Preview: changes that would be applied": "Anteprima: modifiche che verrebbero applicate", "Previous DKMS tree cleared.": "L'albero DKMS precedente è stato cancellato.", + "Previous Rclone configuration restored": "Precedente Configurazione Rclone ripristinata", "Previous installation cleaned": "Installazione precedente pulita", "Previous installation removed": "Installazione precedente rimossa", + "Previous installation restored": "Installazione precedente restaurata", "Previous shutdowns": "Arresti precedenti", + "Primary GID for Emby": "GID primario per Emby", + "Privacy-first finance app with envelope budgeting and multi-device sync.": "Privacy-primo app di finanza con busta budgeting e sincronizzazione multi-dispositivo.", + "Private installation record saved": "Registrazione di installazione privata salvata", + "Private network assigned automatically:": "Rete privata assegnata automaticamente:", + "Private network of the application released:": "Rete privata dell'applicazione rilasciata:", + "Private network of the application that is released:": "Rete privata dell'applicazione che viene rilasciato:", + "Private network:": "Rete privata:", + "Private personal knowledge management": "Gestione della conoscenza personale privata", "Privileged": "Privilegiato", "Privileged Container": "Contenitore privilegiato", "Privileged Container Required": "Contenitore privilegiato obbligatorio", @@ -3338,6 +4409,7 @@ "Privileged container — host root maps directly, no permission changes needed": "Contenitore privilegiato: ospita direttamente le mappe root, senza bisogno di modifiche alle autorizzazioni", "Privileged containers can access host devices directly": "I contenitori privilegiati possono accedere direttamente ai dispositivi host", "Privileged containers have full root access to the host system!": "I contenitori privilegiati hanno pieno accesso root al sistema host!", + "Privileged installation declined": "Installazione privilegiata declinata", "Privileged: Full host access (less secure)": "Privilegiato: accesso completo all'host (meno sicuro)", "Proceed": "Procedere", "Proceed with removal": "Procedere con la rimozione", @@ -3346,11 +4418,15 @@ "Process may take several minutes depending on container size": "Il processo potrebbe richiedere diversi minuti a seconda delle dimensioni del contenitore", "Process may take several minutes for large containers": "Il processo potrebbe richiedere diversi minuti per i contenitori di grandi dimensioni", "Processes using NVIDIA:": "Processi che utilizzano NVIDIA:", + "Productivity & Workflows": "Produttività e flussi di lavoro", "Profile": "Profilo", "Profile:": "Profilo:", + "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files.": "Projectsend è un'applicazione self-hosted che consente di caricare i file e assegnarli a specifici client che si creano da soli. Sicuro, privato e facile. Non più a seconda dei servizi esterni o e-mail per inviare quei file.", "Proposed Changes": "Modifiche proposte", "Proposed ZFS ARC maximum:": "ZFS ARC massimo proposto:", "Provided by newer version — skipping": "fornito dalla versione più recente: saltato", + "Prowlarr does not offer the application schema:": "Prowlarr non offre lo schema di applicazione:", + "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all).": "Prowlarr è un indicizzatore manager/proxy costruito sul popolare arr .net/reactjs stack base per integrare con le varie applicazioni PVR. Prowlarr supporta sia Torrent Trackers che Usenet Indexers. Si integra perfettamente con Sonarr, Radarr, Lidarr, e Readarr che offrono una gestione completa dei vostri indicizzatori senza per app Indice configurazione required (lo facciamo tutti).", "ProxMenux Information": "Informazioni su ProxMenux", "ProxMenux Monitor": "ProxMenux Monitor", "ProxMenux Monitor Service Verification": "Verifica del servizio ProxMenux Monitor", @@ -3364,10 +4440,12 @@ "ProxMenux Monitor protection": "Protezione del ProxMenux Monitor", "ProxMenux Monitor unit repaired and restarted": "Unità ProxMenux Monitor riparata e riavviata", "ProxMenux Monitor → Backups tab (live progress card with estimated time, logs, rollback delta)": "ProxMenux Monitor → scheda Backup (scheda di avanzamento in tempo reale con tempo stimato, registri, delta di rollback)", + "ProxMenux attaches directories, not single files, so this image cannot be installed yet.": "ProxMenux allega directory, non file singoli, quindi questa immagine non può essere ancora installata.", "ProxMenux can apply open permissions on this NFS directory from the host so the container can read and write:": "ProxMenux può applicare autorizzazioni di apertura su questa directory NFS dall'host in modo che il contenitore possa leggere e scrivere:", "ProxMenux can remount it with open permissions so any LXC can read and write.": "ProxMenux può rimontarlo con permessi aperti in modo che qualsiasi LXC possa leggere e scrivere.", "ProxMenux cannot override NFS server-side permissions from the host.": "ProxMenux non può sovrascrivere le autorizzazioni lato server NFS dall'host.", "ProxMenux customizations removed from bashrc": "Personalizzazioni ProxMenux rimosse da bashrc", + "ProxMenux does not give a container the system of its host.": "ProxMenux non dà a un contenitore il sistema del suo host.", "ProxMenux does not validate the contents; any keyfile your PBS accepts is accepted here.": "ProxMenux non convalida i contenuti;qualsiasi file di chiavi accettato dal PBS viene accettato qui.", "ProxMenux files:": "File ProxMenux:", "ProxMenux logo applied": "Logo ProxMenux applicato", @@ -3399,6 +4477,7 @@ "Proxmox repository configuration completed": "Configurazione del repository Proxmox completata", "Proxmox repository fixed (no-subscription, candidate is 9.x)": "Repository Proxmox corretto (nessuna sottoscrizione, il candidato è 9.x)", "Proxmox status:": "Stato di Proxmox:", + "Proxmox storage for the volume": "Proxmox storage per il volume", "Proxmox storages:": "Memorie Proxmox:", "Proxmox system repair completed successfully!": "Riparazione del sistema Proxmox completata con successo!", "Proxmox system repair completed with some issues.": "Riparazione del sistema Proxmox completata con alcuni problemi.", @@ -3408,10 +4487,21 @@ "Proxmox web interface: Datacenter > Storage > Add > SMB/CIFS": "Interfaccia web Proxmox: Datacenter > Archiviazione > Aggiungi > SMB/CIFS", "Proxmox web interface: Datacenter > Storage > Add > ZFS": "Interfaccia web Proxmox: Datacenter > Archiviazione > Aggiungi > ZFS", "Proxmox web interface: Datacenter > Storage > Add > iSCSI": "Interfaccia web Proxmox: Datacenter > Archiviazione > Aggiungi > iSCSI", + "Public UDP port clients connect to": "I clienti della porta UDP pubblici si collegano a", + "Public UDP port peers connect to": "I colleghi della porta UDP pubblici si connettono a", + "Public URL of phpMyAdmin when it is served behind a reverse proxy": "URL pubblico di phpMyAdmin quando viene servito dietro un proxy inverso", + "Public address clients connect to (vpn.example.com or a public IP)": "I client di indirizzo pubblico si connettono a (vpn.example.com o un IP pubblico)", + "Public address peers connect to, or auto to detect it (vpn.example.com)": "I colleghi di indirizzo pubblico si connettono a, o auto per rilevarlo (vpn.example.com)", "Pulling latest changes from GitHub...": "Estrazione delle ultime modifiche da GitHub...", "Purge the gasket-dkms package": "Elimina completamente il pacchetto gasket-dkms", "Purging gasket-dkms package...": "Eliminazione completa del pacchetto gasket-dkms...", "Purging log2ram apt package...": "Eliminazione del pacchetto apt log2ram in corso...", + "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.": "Pwndrop è un servizio di hosting di file auto-deployable per l'invio di payload di teaming rosso o la condivisione sicura dei file privati su HTTP e WebDAV.", + "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more.": "PyCharm offre supporto out-of-the-box per Python, banche dati, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, e altro ancora.", + "Pydio Cells needs an external MySQL or MariaDB database. The setup wizard asks for its address, database name and user on the first start.": "Pydio Cells ha bisogno di un database MySQL esterno o MariaDB. La procedura guidata di configurazione chiede il suo indirizzo, il nome del database e l'utente al primo avvio.", + "Pydio Cells redirects to the address given in EXTERNALURL. If the container changes address, edit lxc.environment.runtime: EXTERNALURL and SERVER_IP in /etc/pve/lxc/.conf with the container stopped, and delete /config/keys/cert.crt to regenerate the certificate.": "Pydio Cells reindirizza all'indirizzo indicato in EXTERNALURL. Se il contenitore cambia indirizzo, modifica lxc.environment.runtime: EXTERNALURL e SERVER IP in /etc/pve/lxc/∂.conf con il contenitore interrotto, ed eliminare /config/keys/cert.crt per rigenerare il certificato.", + "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture.": "Pydio-cells è la piattaforma di condivisione file di prossima generazione per le organizzazioni. Si tratta di una riscrittura completa del progetto Pydio utilizzando la lingua Go seguendo un'architettura micro-servizio.", + "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat.": "QDirStat Statistiche di directory basate su Qt: KDirStat senza KDE -- dall'autore del KDirStat originale.", "Quick health check (PASSED / FAILED)": "Controllo rapido dello stato (SUPERATO/FALLITO)", "Quick health status — overall SMART result + key attributes": "Stato di salute rapido: risultato SMART complessivo + attributi chiave", "RAID Detected": "RAID rilevato", @@ -3425,9 +4515,26 @@ "RPC Bind Service: RUNNING": "Servizio di associazione RPC: IN ESECUZIONE", "RPC Bind Service: STOPPED": "Servizio di associazione RPC: ARRESTATO", "RPC Bind Service: STOPPED - starting...": "Servizio di associazione RPC: ARRESTATO - avvio in corso...", + "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD.": "RPCS3 è un emulatore multi-piattaforma open-source Sony PlayStation 3 e debugger scritto in C++ per Windows, Linux, macOS e FreeBSD.", + "Radarr - A fork of Sonarr to work with movies à la Couchpotato.": "Radarr - A fork di Sonarr per lavorare con film à la Couchpotato.", + "Radarr added to Prowlarr": "Radarr aggiunto a Prowlarr", + "Radarr connected to qBittorrent": "Radarr collegato a qBittorrent", + "Radarr root folder configured": "cartella radice Radarr configurata", + "RagFlow is an open-source RAG engine based on deep document understanding.": "RagFlow è un motore RAG open source basato sulla profonda comprensione dei documenti.", + "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase.": "Raneto - è una piattaforma open source Knowledgebase che utilizza i file statici Markdown per alimentare la tua Knowledgebase.", + "Raneto web interface": "Interfaccia web Raneto", + "RawTherapee is a free, cross-platform raw image processing program!": "RawTherapee è un programma gratuito di elaborazione delle immagini crude cross-platform!", + "Rclone WebUI": "Rclone WebUI", + "Rclone mount": "Montaggio Rclone", + "Rclone mount active": "Supporto Rclone attivo", + "Rclone mount needs a privileged LXC with FUSE access. The container is dedicated to Rclone and its web UI must not be exposed to untrusted networks.": "Rclone mount ha bisogno di un LXC privilegiato con accesso FUSE. Il contenitore è dedicato a Rclone e la sua interfaccia web non deve essere esposta a reti non attendibili.", + "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network.": "Rclone mount requires un LXC privilegiato con accesso FUSE. Utilizzare questo profilo solo su un nodo e una rete di fiducia.", + "Rclone mount requires a privileged container": "Rclone mount requires un contenitore privilegiato", "Re-enter the BORG REPOKEY passphrase to confirm:": "Reinserisci la passphrase BORG REPOKEY per confermare:", "Re-running pre-check after repairs...": "Nuova esecuzione del controllo preliminare dopo la riparazione...", "Reachable": "Raggiungibile", + "Read its Compose file from a file of this host": "Leggi il suo file Compose da un file di questo host", + "Read the link with pct console CTID on the Proxmox host, or from the Console panel of the container in the Proxmox web interface, then open the https://playit.gg/claim/ address it shows in a browser and sign in to playit.gg. Ctrl+a q leaves pct console.": "Leggi il link con console PCt CTID sull'host Proxmox, o dal pannello Console del contenitore nell'interfaccia web Proxmox, quindi apri l'indirizzo https://playit.gg/claim/ che mostra in un browser e accedi a playit.gg. Ctrl+a q lascia console pct.", "Read-Only": "Sola lettura", "Read-Only access": "Accesso di sola lettura", "Read-Write (universal)": "Lettura-scrittura (universale)", @@ -3436,6 +4543,7 @@ "Read-only access (or no write permissions).": "Accesso di sola lettura (o nessuna autorizzazione di scrittura).", "Read-only mount": "Montaggio di sola lettura", "Read/Write (default)": "Lettura/Scrittura (impostazione predefinita)", + "Read/write": "Leggi/scrittura", "Read/write CPU model-specific registers": "Lettura/scrittura registri specifici del modello di CPU", "Readable user table (UID, shell, etc.)": "Tabella utente leggibile (UID, shell, ecc.)", "Reading NVMe SMART data...": "Lettura dei dati NVMe SMART...", @@ -3443,7 +4551,9 @@ "Reading SMART data...": "Lettura dei dati SMART...", "Reading SMART self-test log...": "Lettura del registro dell'autotest SMART...", "Reading full SMART report...": "Leggendo il rapporto SMART completo...", + "Real-time Performance Monitoring": "Monitoraggio delle prestazioni in tempo reale", "Real-time bandwidth usage (press q to exit)": "Utilizzo della larghezza di banda in tempo reale (premi q per uscire)", + "Real-time collaborative document editor": "Editor di documenti collaborativi in tempo reale", "Real-time network monitoring (press q to exit)": "Monitoraggio della rete in tempo reale (premi q per uscire)", "Real-time network usage (iftop)": "utilizzo della rete in tempo reale (iftop)", "Reason: Access denied": "Motivo: accesso negato", @@ -3465,6 +4575,7 @@ "Recent Samba server": "Server Samba recente", "Recent logs:": "Registri recenti:", "Recent test results:": "Risultati dei test recenti:", + "Recognition profile not implemented": "Profilo di riconoscimento non implementato", "Recommendation: reformat the disk to ext4 for a robust setup — see docs.": "Raccomandazione: riformattare il disco in ext4 per una configurazione solida: vedere la documentazione.", "Recommendation: start with Complete restore.": "Raccomandazione: iniziare con il ripristino completo.", "Recommendation: use 'Export to file' for these paths and apply manually during a maintenance window.": "Raccomandazione: utilizzare \"Esporta in file\" per questi percorsi e applicarli manualmente durante una finestra di manutenzione.", @@ -3476,17 +4587,36 @@ "Recommended: use GPU -> LXC mode for these devices.": "Consigliato: utilizzare GPU -> modalità LXC per questi dispositivi.", "Recommended: use GPU with LXC workloads instead of VM passthrough on this hardware.": "Consigliato: utilizzare la GPU con carichi di lavoro LXC invece del passthrough VM su questo hardware.", "Reconciled": "riconciliato", + "Recover OCI": "Recuperare OCI", + "Recover OCI stack": "Recuperare lo stack OCI", + "Recover now?": "Recuperare ora?", + "Recover or complete the operation?": "Recuperare o completare il operation?", "Recover the keyfile using your recovery passphrase?": "Recuperare il file di chiavi utilizzando la passphrase di ripristino?", + "Recover the previous installation": "Recuperare l'installazione precedente", "Recoverable:": "Recuperabile:", + "Recovering the previous installation": "Recuperare l'installazione precedente", "Recovery blob upload failed — main backup is OK, but keyfile recovery from PBS will not be available for this backup.": "caricamento del BLOB di ripristino non riuscito: il backup principale è OK, ma il ripristino del file di chiavi da PBS non sarà disponibile per questo backup.", "Recovery blob:": "BLOB di ripristino:", + "Recovery completed. The container had not been modified yet.": "Recupero completato. Il contenitore non era ancora stato modificato.", + "Recovery completed. The displaced disks and the backup are kept; nothing was deleted automatically.": "Recupero completato. I dischi spostati e il backup sono tenuti; nulla è stato cancellato automaticamente.", "Recovery failed": "Il ripristino non è riuscito", "Recovery passphrase": "Passphrase di ripristino", "Recovery setup failed": "La configurazione del ripristino non è riuscita", + "Recreate": "Ritiro", + "Recreate OCI": "Recrezione OCI", + "Recreate with these options?": "Ricreare con queste opzioni?", + "Recreate: edit resources, network, paths and GPU": "Ricreazione: modifica risorse, rete, percorsi e GPU", + "Recreating requires a confirmed proposal": "Ricreare requires una proposta confermata", + "Recreating the container...": "Ricreare il contenitore...", + "Recreating the container:": "Ricreazione del contenitore:", + "Recreation completed. Data kept.": "Ricreazione completata. Dati conservati.", + "Recreation prepared": "Ricreazione preparata", "Refresh APT index and verify repositories:": "Aggiorna l'indice APT e verifica i repository:", "Refresh your browser (Ctrl+Shift+R) to see changes": "Aggiorna il browser (Ctrl+Shift+R) per vedere le modifiche", "Refresh your browser to see changes (server restart may be required)": "Aggiorna il browser per vedere le modifiche (potrebbe essere necessario il riavvio del server)", "Refreshing apt cache...": "Aggiornamento della cache di apt in corso...", + "Refreshing the NVIDIA runtime...": "Rinfresco del runtime NVIDIA...", + "Refusing an unexpected rootfs path:": "Rifiutare un percorso di rootfs inaspettato:", "Regenerating PVE package cache...": "Rigenerazione della cache dei pacchetti PVE in corso...", "Regenerating boot artifacts for the merged kernel-agnostic changes...": "rigenerazione degli artefatti di avvio per le modifiche unite indipendenti dal kernel...", "Regenerating certificates and restarting services...": "Rigenerazione certificati e riavvio servizi...", @@ -3502,6 +4632,7 @@ "Reinstalled Proxmox packages successfully": "Pacchetti Proxmox reinstallati correttamente", "Reinstalling": "Reinstallazione", "Reinstalling core Proxmox packages...": "Reinstallazione dei pacchetti Proxmox principali in corso...", + "Relative CPU priority (cpuunits)": "Priorità relativa della CPU (cpuunits)", "Release Channel": "Canale di rilascio", "Release channel set to Beta.": "Canale di rilascio impostato su Beta.", "Release channel set to Stable.": "Canale di rilascio impostato su Stabile.", @@ -3511,8 +4642,12 @@ "Remapped Users:": "Utenti rimappati:", "Remapped users:": "Utenti rimappati:", "Reminder: You must install the QEMU Guest Agent inside the Windows VM": "Promemoria: è necessario installare l'agente guest QEMU all'interno della VM Windows", + "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported.": "Remmina è un client desktop remoto scritto in GTK, che mira ad essere utile per amministratori di sistema e viaggiatori, che hanno bisogno di lavorare con un sacco di computer remoti davanti a schermi grandi o piccoli. Remmina supporta più protocolli di rete, in un'interfaccia utente integrata e coerente. Attualmente sono supportati RDP, VNC, SPICE, SSH ed EXEC.", + "Remote Access & VPN": "Accesso remoto e VPN", + "Remote dry run completed; no container was created.": "Funzionamento a secco a distanza completato; nessun contenitore è stato creato.", "Remote repository path:": "Percorso del repository remoto:", "Remote server via SSH (recommended — off-host, dedup across machines)": "Server remoto tramite SSH (consigliato: fuori host, deduplicazione su più computer)", + "Remote verified:": "Verificato da remoto:", "Remounting CIFS share with open permissions...": "Rimontaggio della condivisione CIFS con autorizzazioni aperte in corso...", "Remove CIFS Mount": "Rimuovere il montaggio CIFS", "Remove CIFS Mount (pvesm or fstab)": "Rimuovere il montaggio CIFS (pvesm o fstab)", @@ -3540,6 +4675,7 @@ "Remove NFS fstab Mount": "Rimuovere il supporto NFS fstab", "Remove NFS fstab mount:": "Rimuovere il montaggio fstab NFS:", "Remove NFS storage:": "Rimuovere l'archiviazione NFS:", + "Remove OCI": "Rimuovi OCI", "Remove Proxmox CIFS storage:": "Rimuovere lo storage CIFS Proxmox:", "Remove Proxmox NFS storage:": "Rimuovere lo spazio di archiviazione NFS Proxmox:", "Remove Proxmox iSCSI storage:": "Rimuovere lo spazio di archiviazione iSCSI Proxmox:", @@ -3551,6 +4687,7 @@ "Remove iSCSI storage definition:": "Rimuovere la definizione di archiviazione iSCSI:", "Remove invalid port": "Rimuovi la porta non valida", "Remove invalid port(s)": "Rimuovi le porte non valide", + "Remove it? The data of its containers cannot be recovered afterwards.": "Rimozione? I dati dei suoi contenitori non possono essere recuperati dopo.", "Remove keyfile from this host": "rimuovi il file di chiavi da questo host", "Remove mount point:": "Rimuovi punto di montaggio:", "Remove obsolete systemd-boot meta-package": "Rimuovi il metapacchetto systemd-boot obsoleto", @@ -3559,6 +4696,7 @@ "Remove subscription banner": "rimuovi il banner di abbonamento", "Remove the unprivileged flag from configuration:": "Rimuovi il flag senza privilegi dalla configurazione:", "Remove unused packages and their config": "Rimuovi i pacchetti non utilizzati e la loro configurazione", + "Remove: delete the application and its containers": "Rimuovere: eliminare l'applicazione e i suoi contenitori", "Removed": "RIMOSSO", "Removed KVM MSR options from configuration": "Rimosse le opzioni KVM MSR dalla configurazione", "Removed Mount:": "Supporto rimosso:", @@ -3609,6 +4747,9 @@ "Removing stale VFIO entries from vfio.conf...": "rimozione delle voci VFIO obsolete da vfio.conf...", "Removing storage from Proxmox...": "Rimozione dello spazio di archiviazione da Proxmox in corso...", "Removing system limits optimizations...": "Rimozione delle ottimizzazioni dei limiti di sistema...", + "Removing the containers...": "Rimuovere i contenitori...", + "Removing the incomplete stack...": "Rimuovere lo stack incompleto...", + "Removing the previous container": "Rimozione del contenitore precedente", "Removing utilities installed by ProxMenux...": "rimozione delle utilità installate da ProxMenux...", "Removing zfs-auto-snapshot...": "Rimozione dell'istantanea automatica zfs in corso...", "Renamed": "rinominato", @@ -3616,6 +4757,7 @@ "Repair Complete": "Riparazione completata", "Repair Options:": "Opzioni di riparazione:", "Repairs and optimizes repositories": "Ripara e ottimizza i repository", + "Repeat to confirm": "Ripeto per confermare", "Replace": "Sostituire", "Replace with the actual ID.": "Sostituisci con l'ID effettivo.", "Replace with your actual container ID": "Sostituisci con il tuo ID contenitore effettivo", @@ -3628,12 +4770,16 @@ "Repositories switched to no-subscription": "I repository sono passati alla modalità senza abbonamento", "Repository ready.": "Archivio pronto.", "Repository:": "Deposito:", + "Request a staging certificate for testing: true or false": "Richiedi un certificato di allestimento per il test: vero o falso", "Require reboot": "Richiede il riavvio", "Required command not found:": "Comando richiesto non trovato:", "Required if using a VirtIO or SCSI disk.": "Necessario se si utilizza un disco VirtIO o SCSI.", "Required install helpers not available.": "Assistenti di installazione richiesti non disponibili.", + "Required new path cancelled": "Required nuovo percorso cancellato", + "Required persistent paths cannot be removed": "I percorsi persistenti Required non possono essere rimossi", "Requires acl package. Skip if setfacl is not available.": "Richiede il pacchetto ACL. Salta se setfacl non è disponibile.", "Requires authentication": "Richiede l'autenticazione", + "Reserving a private network...": "Conservare una rete privata...", "Reset Capability Blocked": "Funzionalità di ripristino bloccata", "Reset Capability Warning": "Reimposta avviso capacità", "Reset Monitor Password": "Reimposta la password del monitor", @@ -3641,7 +4787,9 @@ "Reset current storage selection": "Reimposta la selezione di archiviazione corrente", "Resetting time synchronization...": "Reimpostazione della sincronizzazione dell'ora...", "Residual Bookworm entries commented where applicable": "Voci residue dei Bookworm commentate dove applicabile", + "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes.": "Resilio-sync (ex BitTorrent Sync) utilizza il protocollo BitTorrent per sincronizzare file e cartelle tra tutti i dispositivi. Ci sono sia versioni gratuite e a pagamento, questo contenitore supporta entrambi. C'è un'immagine di sincronizzazione ufficiale, ma abbiamo creato questo in quanto supporta la mappatura dell'utente per semplificare le autorizzazioni per i volumi.", "Resolve package conflicts": "Risolvere i conflitti tra pacchetti", + "Resources": "Risorse", "Restart Network": "Riavvia la rete", "Restart Network Service": "Riavviare il servizio di rete", "Restart Web UI proxy": "Riavviare il proxy dell'interfaccia utente Web", @@ -3673,8 +4821,11 @@ "Restore plan summary": "Ripristina il riepilogo del piano", "Restore source location": "Ripristina la posizione di origine", "Restored config is on disk; reboot the host to apply.": "La configurazione ripristinata è su disco; riavviare l'host per applicare.", + "Restored installation checked": "Installazione ripristinata controllata", "Restored original /bin/gzip": "/bin/gzip originale ripristinato", "Restored original /etc/vzdump.conf from .bak": "/etc/vzdump.conf originale ripristinato da .bak", + "Restored:": "Restaurato:", + "Restoring": "Restauro", "Restoring APT language downloads...": "Ripristino dei download della lingua APT in corso...", "Restoring container memory to": "Ripristino della memoria del contenitore in", "Restoring default journald configuration...": "Ripristino della configurazione journald predefinita in corso...", @@ -3682,15 +4833,23 @@ "Restoring original bashrc...": "Ripristino bashrc originale...", "Restoring original logrotate configuration...": "Ripristino della configurazione originale di logrotate...", "Restoring subscription banner...": "Ripristino del banner di abbonamento in corso...", + "Restoring the backup": "Ripristinare il backup", "Restoring the original rpcbind service state...": "ripristino dello stato originale del servizio rpcbind...", + "Restoring the previous Rclone configuration...": "Ripristino della precedente configurazione Rclone...", + "Restoring the previous backup...": "Ripristino del backup precedente...", + "Restoring the previous state of the stack...": "Ripristino dello stato precedente dello stack...", + "Restoring the stack records...": "Ripristino dei record di stack...", "Results will be saved automatically to:": "I risultati verranno salvati automaticamente in:", "Results will be saved to:": "I risultati verranno salvati in:", "Retention": "Conservazione", + "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface.": "RetroArch è un frontend per emulatori, motori di gioco e lettori multimediali. Consente di eseguire giochi classici su una vasta gamma di computer e console attraverso la sua interfaccia grafica slick.", "Return": "Ritorno", "Return to Main Menu": "Ritorna al menu principale", "Return to Share Menu": "Torna al menu Condividi", "Return to main menu": "Ritorna al menu principale", + "Returning the containers to their previous state...": "Ritornare i contenitori al loro stato precedente...", "Reused the encryption key from the PVE storage entry.": "riutilizzata la chiave di crittografia dalla voce di archiviazione PVE.", + "Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container.": "I campioni di proxy per altre applicazioni sono in /config/nginx/proxy confs all'interno del contenitore.", "Reverting AMD (Ryzen/EPYC) fixes...": "Ripristino delle correzioni AMD (Ryzen/EPYC)...", "Reverting IOMMU/VFIO configuration...": "Ripristino della configurazione IOMMU/VFIO...", "Reverting TCP BBR + Fast Open...": "Ripristino TCP BBR + Apertura rapida...", @@ -3699,22 +4858,31 @@ "Reverting vzdump speed tuning...": "Ripristino della regolazione della velocità di vzdump in corso...", "Review passthrough config files": "Esaminare i file di configurazione passthrough", "Review what will be removed": "Controlla cosa verrà rimosso", + "Rip DVD and Blu-ray media from a browser": "Rip DVD e Blu-ray media da un browser", "Rollback: nothing to remove (host matches backup)": "Rollback: niente da rimuovere (l'host corrisponde al backup)", + "Rolling back the incomplete container": "Rotolando indietro il contenitore incompleto", + "RomM is a self-hosted ROM manager for managing and playing game collections.": "RomM è un manager ROM self-hosted per la gestione e la riproduzione di collezioni di giochi.", "Root SSH keys/config": "Chiavi/config. SSH root", "Root inside container = root on host system": "Root all'interno del contenitore = root sul sistema host", + "Root privileges are required": "I privilegi delle radici sono required", + "Root privileges on the Proxmox node are required": "I privilegi di radice sul nodo Proxmox sono required", "Root shell/profile config": "Configurazione della shell/profilo root", "Root user on the PVE host (default 'root'):": "Utente root sull'host PVE (default 'root'):", + "Rootfs size in GB": "Dimensioni Rootfs in GB", "Rotate the recovery passphrase": "ruota la passphrase di ripristino", "Routing Information": "Informazioni sul percorso", "Routing Table": "Tabella di instradamento", + "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required.": "Rsnapshot è un filesystem snapshot utility basato su rsync. rsnapshot rende facile effettuare istantanee periodiche di macchine locali e macchine remote su ssh. Il codice rende ampio uso di collegamenti duri ogni volta che possibile, per ridurre notevolmente lo spazio su disco required.", "Run 'Mount NFS Share' to install NFS client automatically.": "Eseguire \"Monta condivisione NFS\" per installare automaticamente il client NFS.", "Run 'Mount Samba Share' to install CIFS client automatically.": "Eseguire 'Mount Samba Share' per installare automaticamente il client CIFS.", + "Run GGUF LLMs locally with GPU acceleration": "Eseguire GGUF LLM localmente con accelerazione GPU", "Run PVE 8 to 9": "Esegui PVE da 8 a 9", "Run PVE 8 to 9 check": "Esegui il controllo PVE da 8 a 9", "Run \\\"Install NVIDIA Drivers on Host\\\" first so the installer is cached.": "Eseguire prima \\\"Installa driver NVIDIA sull'host\\\" in modo che il programma di installazione venga memorizzato nella cache.", "Run a full security audit": "Esegui un controllo di sicurezza completo", "Run a job now": "Esegui un lavoro adesso", "Run apt-get install -f to complete any pending package configurations": "esegui apt-get install -f per completare eventuali configurazioni di pacchetti in sospeso", + "Run as root on the Proxmox node; the registry contains private data": "Eseguire come root sul nodo Proxmox; il registro contiene dati privati", "Run as server or client? [s/c]:": "Eseguire come server o client? [s/c]:", "Run checklist again to verify upgrade:": "Esegui nuovamente l'elenco di controllo per verificare l'aggiornamento:", "Run from console, or SSH inside tmux/screen": "Esegui dalla console o SSH all'interno di tmux/screen", @@ -3739,6 +4907,7 @@ "Running dkms autoinstall for kernel": "esecuzione dell'installazione automatica di dkms per il kernel", "Running kernel:": "Kernel in esecuzione:", "Running pre-upgrade simulation to verify 'proxmox-ve' will remain installed...": "Esecuzione della simulazione pre-aggiornamento per verificare che 'proxmox-ve' rimanga installato...", + "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration.": "RustDesk è un'alternativa di controllo remoto open source completa per l'hosting e la sicurezza con una configurazione minima.", "SATA (standard - high compatibility)": "SATA (standard - alta compatibilità)", "SCSI (recommended for Linux and Windows)": "SCSI (consigliato per Linux e Windows)", "SCSI (recommended for Linux)": "SCSI (consigliato per Linux)", @@ -3755,6 +4924,7 @@ "SMB ports:": "Porte PMI:", "SR-IOV Configuration Detected": "Rilevata configurazione SR-IOV", "SSD Emulation": "Emulazione SSD", + "SSH access": "Accesso SSH", "SSH access (host + root)": "Accesso SSH (host + root)", "SSH auth logger service created and started": "Servizio di registrazione di autenticazione SSH creato e avviato", "SSH hardening: MaxAuthTries set to 3 (Lynis recommendation)": "Rafforzamento SSH: MaxAuthTries impostato su 3 (consiglio Lynis)", @@ -3769,6 +4939,8 @@ "STEP 9: Cleanup (LVM only)": "PASSO 9: Pulizia (solo LVM)", "STORAGE TYPE IDENTIFICATION:": "IDENTIFICAZIONE DEL TIPO DI STOCCAGGIO:", "SUGGESTION FOR": "CONSIGLIO PER", + "SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.": "SWAG serve HTTPS sulla porta 443. La piattaforma HTTP sulla porta 80 è disabilitata in /config/nginx/site-confs/default.conf.", + "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction.": "Sabnzbd rende Usenet il più semplice e semplificato possibile automatizzando tutto il possibile. Tutto quello che dovete fare è aggiungere un .nzb. SABnzbd prende il controllo da lì, dove verrà scaricato automaticamente, verificato, riparato, estratto e archiviato via con zero interazione umana.", "Safe design: no automatic ACL/ownership mutation on host or CT.": "Progettazione sicura: nessuna mutazione automatica dell'ACL/della proprietà sull'host o sul CT.", "Safe to apply now": "Sicuro da applicare ora", "Safety Backup": "Backup di sicurezza", @@ -3822,8 +4994,13 @@ "Same major series:": "Stessa serie principale:", "Same major.minor:": "Stesso major.minor:", "Sanitizing NVIDIA host services for VFIO mode...": "Disinfezione dei servizi host NVIDIA per la modalità VFIO in corso...", + "Save and classify articles. Read them later. Freely.": "Salvare e classificare gli articoli. Leggili più tardi. Libero.", "Save the passphrase somewhere safe NOW, before continuing.": "salva la passphrase in un posto sicuro ORA, prima di continuare.", "Save this Borg target so you don't need to enter the details again?": "Salvare questo target Borg in modo da non dover inserire nuovamente i dettagli?", + "Saved record removed": "Salvataggio del record rimosso", + "Saving the new configuration": "Salvataggio della nuova configurazione", + "Saving the new configuration...": "Salvare la nuova configurazione...", + "Saving the stack records...": "Salvare i record di stack...", "Scan storage for new content": "Scansione dello spazio di archiviazione per nuovi contenuti", "Scanning available physical disks...": "Scansione dei dischi fisici disponibili...", "Scanning network for NFS servers...": "Scansione della rete per server NFS...", @@ -3835,11 +5012,19 @@ "Scheduled backups and retention policies": "Backup pianificati e policy di conservazione", "Scheduled tasks (cron)": "Attività pianificate (cron)", "Scheduler script not found:": "Script dello scheduler non trovato:", + "ScreenScraper": "Screenscraper", + "ScreenScraper password": "ScreenScraper password", + "ScreenScraper username": "Nome utente ScreenScraper", "Script Information": "Informazioni sulla sceneggiatura", "Script not found:": "Script non trovato:", "Scripts in": "Script dentro", + "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator.": "ScummVM è un programma che consente di eseguire alcuni giochi di avventura grafica classica e di gioco di ruolo, a condizione che tu abbia già i loro file di dati. La parte intelligente di questo: ScummVM sostituisce solo gli eseguibili spediti con i giochi, permettendo di giocare su sistemi per i quali non sono mai stati progettati! ScummVM è una riscrittura completa degli eseguibili di questi giochi e non è un emulatore.", + "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions—such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server.": "Sealskin è una piattaforma self-hosted, client-server che consente agli utenti di eseguire applicazioni desktop potenti e containerizzati trasmessi direttamente a un browser web. Utilizza un'estensione del browser per intercettare le azioni degli utenti, come fare clic su un link o scaricare un file e reindirizzarli in un ambiente di applicazione sicuro e isolato in esecuzione su un server remoto.", "Search Results for:": "Risultati della ricerca per:", + "Search applications": "Applicazioni di ricerca", + "Search results for:": "Risultati ricerca per:", "Search/Filter Scripts": "Script di ricerca/filtro", + "Searchable document archive with OCR": "Archivio di documenti ricercabile con OCR", "Secure Disk Formatter": "Formattatore di dischi sicuro", "Secure Gateway (Tailscale VPN)": "Secure Gateway (VPN Tailscale)", "Secure Gateway deployed successfully!": "Secure Gateway distribuito con successo!", @@ -3847,8 +5032,12 @@ "Security": "Sicurezza", "Security Updates": "Aggiornamenti di sicurezza", "Security Warning — read before applying": "Avviso di sicurezza: leggere prima di presentare domanda", + "Security directive outside the dynamic profile": "Direttiva sulla sicurezza al di fuori del profilo dinamico", + "Security relaxation declined": "Riduzione del relax di sicurezza", "See": "vedi", "See /tmp/proxmenux-mount.log for details.": "Vedi /tmp/proxmenux-mount.log per i dettagli.", + "Seerr WebUI": "Seerr WebUI", + "Seerr/Bazarr connections, the SABnzbd client and the Lidarr profiles, root folder and client are configured manually in this version.": "Le connessioni Seerr/Bazarr, il client SABnzbd e i profili Lidarr, la cartella root e il client sono configurati manualmente in questa versione.", "Select": "Selezionare", "Select Borg target": "Seleziona il bersaglio Borg", "Select CPU model": "Seleziona il modello della CPU", @@ -3888,6 +5077,7 @@ "Select a Custom Logo": "Seleziona un logo personalizzato", "Select a VirtIO ISO to use:": "Seleziona un ISO VirtIO da utilizzare:", "Select a category of useful commands:": "Seleziona una categoria di comandi utili:", + "Select a category or search for applications:": "Seleziona una categoria o ricerca per le applicazioni:", "Select a category or search for scripts:": "Seleziona una categoria o cerca gli script:", "Select a custom ISO to use:": "Seleziona un ISO personalizzato da utilizzare:", "Select a job:": "Seleziona un lavoro:", @@ -3897,6 +5087,7 @@ "Select a pre-configured Linux VM script to execute:": "Seleziona uno script VM Linux preconfigurato da eseguire:", "Select a script or action:": "Seleziona uno script o un'azione:", "Select a share to delete:": "Seleziona una condivisione da eliminare:", + "Select a specific Coral or USB node, not the whole /dev": "Selezionare uno specifico nodo Coral o USB, non l'intero /dev", "Select access mode": "Seleziona la modalità di accesso", "Select an existing group": "Seleziona un gruppo esistente", "Select an existing group:": "Seleziona un gruppo esistente:", @@ -3907,6 +5098,7 @@ "Select archive": "Seleziona archivio", "Select archive to restore": "Seleziona l'archivio da ripristinare", "Select at least one path to continue.": "seleziona almeno un percorso per continuare.", + "Select at least one suite application": "Selezionare almeno un'applicazione suite", "Select authentication mode:": "Seleziona la modalità di autenticazione:", "Select authentication type:": "Seleziona il tipo di autenticazione:", "Select available Controllers/NVMe to add:": "Seleziona i controller/NVMe disponibili da aggiungere:", @@ -4011,6 +5203,19 @@ "Selected optimizations have been uninstalled.": "Le ottimizzazioni selezionate sono state disinstallate.", "Selected paths produced no entries to apply.": "i percorsi selezionati non hanno prodotto voci da applicare.", "Selected utilities installation completed": "Installazione delle utilità selezionate completata", + "Selection": "Selezione", + "Self-custodial Bitcoin Lightning wallet with integrated node and app connections.": "Portafoglio self-custodial Bitcoin Lightning con nodo integrato e connessioni app.", + "Self-hosted ZeroTier network controller with web UI for centralized management.": "Controller di rete ZeroTier con interfaccia utente web per la gestione centralizzata.", + "Self-hosted cloud data migration & sync manager": "migrazione di dati cloud self-hosted & sync manager", + "Self-hosted collaborative bookmark manager to collect, read, annotate, and fully preserve what matters, all in one place.": "Self-hosted bookmark manager collaborativo per raccogliere, leggere, annotare e preservare pienamente ciò che conta, tutto in un unico luogo.", + "Self-hosted file sharing with a modern web interface": "condivisione di file con un'interfaccia web moderna", + "Self-hosted file toolkit for images, video, audio, PDFs, and files": "Toolkit di file self-hosted per immagini, video, audio, PDF e file", + "Self-hosted internet archiving solution": "Soluzione di archiviazione internet self-hosting", + "Self-hosted recipe manager and meal planner": "Gestore di ricette self-hosted e pianificatore di pasti", + "Self-hosted software development service": "Servizio di sviluppo software self-hosting", + "Self-signed TLS certificate created:": "Certificato TLS autofirmato creato:", + "Selfhosted PDF manager, viewer and editor": "Gestore, spettatore ed editor PDF", + "Selkies desktop and streaming acceleration": "Selkies accelerazione desktop e streaming", "Sending backup to Borg repository...": "invio del backup al repository Borg...", "Sending backup to PBS...": "Invio del backup a PBS...", "Server": "Server", @@ -4025,14 +5230,19 @@ "Server will listen on TCP port 5201.": "Il server ascolterà sulla porta TCP 5201.", "Server:": "Server:", "Servers": "Server", + "Service": "Servizio", "Service Status": "Stato del servizio", "Service is active and running": "Il servizio è attivo e funzionante", "Service is inactive": "Il servizio è inattivo", + "Service ready:": "Servizio pronto:", + "Service responding:": "Servizio di assistenza:", "Service restarted.": "Il servizio è stato riavviato.", "Service restarts:": "Il servizio riparte:", "Service stopped.": "Il servizio è stato interrotto.", + "Service:": "Servizio:", "Services failed": "I servizi sono falliti", "Services restarted": "I servizi sono riavviati", + "Services that depend on the main service are not yet supported": "I servizi che dipendono dal servizio principale non sono ancora supportati", "Services:": "Servizi:", "Set Display > Graphic card (VGA, SPICE or VirtIO) to match the guest": "Imposta Display > Scheda grafica (VGA, SPICE o VirtIO) in modo che corrisponda al guest", "Set Hostname": "Imposta il nome host", @@ -4077,13 +5287,26 @@ "Share:": "Condividere:", "Shared Directory Ready:": "Directory condivisa pronta:", "Shared Group": "Gruppo condiviso", + "Shared directory created:": "directory condivisa creata:", + "Shared directory for consume and export": "Directory condivisa per consumare ed esportare", + "Shared directory for copy/sync operations": "Directory condivisa per copia/sync operations", "Shared group: CONFIGURED": "Gruppo condiviso: CONFIGURATO", "Shared group: sharedfiles (GID:": "Gruppo condiviso: file condivisi (GID:", + "Shared host content (not included in LXC backups):": "Contenuto host condiviso (non incluso nei backup LXC):", + "Shared host data is not reverted by the backup. Continue?": "I dati host condivisi non vengono ripristinati dal backup. Continua?", + "Shared host data is not reverted by the backups. Continue?": "I dati host condivisi non vengono convertiti dai backup. Continua?", + "Shared host directories (not included in Proxmox backups)": "directory host condivise (non incluse nei backup Proxmox)", + "Shared host directory": "directory host condivisa", + "Shared host directory (not included in Proxmox backups)": "directory host condivisa (non inclusa nei backup Proxmox)", + "Shared host files are kept as they are; the backup does not restore their content.": "I file host condivisi vengono conservati come sono; il backup non ripristina il loro contenuto.", + "Shared host media directory": "Directory media host condivisa", + "Shared memory size for the GPU workload in MB": "Dimensione della memoria condivisa per il carico di lavoro GPU in MB", "Sharedfiles group already exists (GID: 101000)": "Il gruppo Sharedfiles esiste già (GID: 101000)", "Shares found:": "Azioni trovate:", "Shell user ulimit set": "Set ulimit utente shell", "Short self-test started on": "È iniziato il breve test automatico", "Short test — ~2 minutes, basic surface check": "Test breve: circa 2 minuti, controllo di base della superficie", + "Shotcut is a free, open source, cross-platform video editor.": "Shotcut è un editor video free, open source, cross-platform.", "Should show 'unprivileged: 0' or no unprivileged line": "Dovrebbe mostrare \"non privilegiato: 0\" o nessuna linea non privilegiata", "Should show 'unprivileged: 1'": "Dovrebbe mostrare \"non privilegiato: 1\"", "Should show 'unprivileged: 1' if it's unprivileged": "Dovrebbe mostrare \"non privilegiato: 1\" se non è privilegiato", @@ -4125,14 +5348,23 @@ "Show size of a directory": "Mostra la dimensione di una directory", "Show standard exclude patterns": "Mostra modelli di esclusione standard", "Show status of all storage pools": "Mostra lo stato di tutti gli storage pool", + "Show the QR code of a peer again with: pct exec -- /app/show-peer 1": "Mostra di nuovo il codice QR di un peer con: pct exec -- /app/show-peer 1", "Show traffic statistics per interface": "Mostra le statistiche del traffico per interfaccia", "Show vzdump backup configuration": "Mostra la configurazione del backup vzdump", "Shows status and type (nfs/cifs/dir/iscsi...).": "Mostra lo stato e il tipo (nfs/cifs/dir/iscsi...).", "Shutdown timeout": "Timeout di spegnimento", + "SiYuan access code": "Codice di accesso SiYuan", + "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more..": "SickGear fornisce la gestione di programmi TV e/o Anime, rileva nuovi episodi, link downloader applicazioni, e altro ancora..", + "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private.": "Signal è un'applicazione di messaggistica con privacy al suo core. È gratuito e facile da usare, con una forte crittografia end-to-end che mantiene la comunicazione completamente privata.", "Signatures removed. Partition table preserved.": "Firme rimosse. Tabella delle partizioni conservata.", + "Simple and easy to use DDNS": "Semplice e facile da usare DDNS", "Single GPU Warning": "Avviso GPU singola", "Single target found — selected automatically:": "Target singolo trovato - selezionato automaticamente:", "Size": "Misurare", + "Size in GB of": "Dimensione in GB di", + "Size of each consume/export volume in GB": "Dimensione di ogni volume di consumo/esportazione in GB", + "Size of the /dev/shm shared memory in MB": "Dimensione della memoria condivisa /dev/shm in MB", + "Size of the Frigate temporary cache in MB": "Dimensione della cache temporanea Frigate in MB", "Size:": "Misurare:", "Skip downloading additional languages": "salta il download di lingue aggiuntive", "Skip this device": "Salta questo dispositivo", @@ -4142,6 +5374,7 @@ "Skip — leave as-is": "Salta: lascia così com'è", "Skipped (no disks of the pool are present on this host):": "Messaggio tecnico per Proxmox e IT.Traduzione: saltato (nessun disco del pool è presente su questo host):", "Skipped (some disks missing):": "saltato (alcuni dischi mancanti):", + "Skipped because Jellyfin did not create encoding.xml:": "Skipped perché Jellyfin non ha creato encoding.xml:", "Skipped device": "Dispositivo saltato", "Skipped to protect target system (would cascade-remove packages)": "Messaggio tecnico per Proxmox e IT.Traduzione: saltato per proteggere il sistema di destinazione (rimuoverebbe i pacchetti a cascata)", "Skipped, not in apt cache:": "Saltato, non nella cache di apt:", @@ -4149,7 +5382,10 @@ "Skipping SR-IOV device": "Saltare il dispositivo SR-IOV", "Skipping installation.": "Saltare l'installazione.", "Skipping manual patches — feranick fork already supports this kernel.": "Saltare le patch manuali: il fork feranick supporta già questo kernel.", + "Sleek podcast downloader with GPodder sync": "Sleek podcast downloader con sincronizzazione GPodder", "Smart restore plan — hardware compatibility check": "Piano di ripristino intelligente: verifica della compatibilità hardware", + "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis.": "Smokeping tiene traccia della latenza della rete. Per un esempio completo di ciò che questa applicazione è in grado di visitare UCDavis.", + "SnapOtter": "SnapOtter", "Snippets — hook scripts / config": "Snippet: script di hook/config", "SoC-integrated GPU: tight coupling with other SoC components": "GPU integrata nel SoC: stretto accoppiamento con altri componenti SoC", "Some DKMS removals reported errors; final verification will determine the result.": "alcune rimozioni DKMS hanno riportato errori;la verifica finale determinerà il risultato.", @@ -4159,6 +5395,7 @@ "Some old time services could not be removed (not installed)": "Impossibile rimuovere alcuni servizi obsoleti (non installati)", "Some operations failed — review messages above. Press Enter to continue...": "Alcune operazioni non sono riuscite: rivedi i messaggi sopra. Premi Invio per continuare...", "Some packages still need attention; review": "alcuni pacchetti necessitano ancora di attenzione;revisione", + "Some projects publish a Dockerfile and not an image: it has to be built and published to a registry before it can be installed this way. An image of a private registry needs credentials, which are not supported yet.": "Alcuni progetti pubblicano un Dockerfile e non un'immagine: deve essere costruito e pubblicato su un registro prima che possa essere installato in questo modo. Un'immagine di un registro privato ha bisogno di credentials, che non sono ancora supportati.", "Some repairs failed. Please fix manually and re-run the script.": "Alcune riparazioni sono fallite. Correggi manualmente ed esegui nuovamente lo script.", "Some repositories are not available, continuing with available ones...": "Alcuni repository non sono disponibili, continuando con quelli disponibili...", "Some selected GPUs are already configured in this container.": "Alcune GPU selezionate sono già configurate in questo contenitore.", @@ -4166,6 +5403,10 @@ "Some utility packages could not be removed; the remaining list has been preserved": "non è stato possibile rimuovere alcuni pacchetti di utilità;l'elenco rimanente è stato conservato", "Something is already mounted at": "Qualcosa è già montato su", "Something is already mounted at:": "Qualcosa è già montato in:", + "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Sonarr (ex NZBdrone) è un PVR per utenti usenet e bittorrent. Può monitorare più feed RSS per nuovi episodi dei tuoi spettacoli preferiti e li afferra, ordina e rinomina. Può anche essere configurato per aggiornare automaticamente la qualità dei file già scaricati quando un formato di qualità migliore diventa disponibile.", + "Sonarr added to Prowlarr": "Sonarr aggiunto a Prowlarr", + "Sonarr connected to qBittorrent": "Sonarr collegato a qBittorrent", + "Sonarr root folder configured": "cartella radice Sonarr configurata", "Source": "Fonte", "Source VM": "Macchina virtuale di origine", "Source patched successfully.": "La sorgente è stata patchata correttamente.", @@ -4174,8 +5415,26 @@ "Spanish": "spagnolo", "Specific host (enter IP)": "Host specifico (inserire IP)", "Specific subnet (enter manually)": "Sottorete specifica (immettere manualmente)", + "Speedtest Tracker web interface": "Interfaccia web Speedtest Tracker", + "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service.": "Speedtest-tracker è un'applicazione di monitoraggio delle prestazioni internet self-hosted che esegue controlli più veloci contro il servizio Speedtest di Ookla.", + "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium": "Spotube è un client open source, multipiattaforma Spotify compatibile su più piattaforme utilizzando le API dati di Spotify e YouTube, Piped. video o JioSaavn come fonte audio, eliminando la necessità di Spotify Premium", "Stable (main branch)": "Stabile (ramo principale)", "Stable monitor service normalized.": "Servizio di monitoraggio stabile normalizzato.", + "Stack": "Stack", + "Stack adapter not recognized by the translator": "Adattatore Stack non riconosciuto dal traduttore", + "Stack backups are missing; a partial restore is not allowed": "Mancano i backup dello stack; non è consentito un ripristino parziale", + "Stack checked:": "Stack controllato:", + "Stack members are missing; recreate them after verifying their volumes": "Mancano i membri dello Stack; li ricreano dopo aver verificato i loro volumi", + "Stack members are updated together with their stack": "I membri dello Stack vengono aggiornati insieme al loro stack", + "Stack name": "Nome di stack", + "Stack records restored": "Stack record ripristinato", + "Stack records saved": "Registrazioni di Stack salvati", + "Stack records saved; no container was reinstalled.": "Registrati memorizzati; nessun contenitore è stato reinstallato.", + "Stack recovery completed; every member is back to its previous installation.": "Ripristino dello stack completato; ogni membro è tornato alla sua precedente installazione.", + "Stack startup hook installed": "Installazione del gancio di avvio Stack", + "Stack stopped": "Stack si è fermato", + "Stack update completed. Data kept.": "Aggiornamento Stack completato. Dati conservati.", + "Stack:": "Stack:", "Staging directory:": "Directory di staging:", "Staging ready.": "Allestimento pronto.", "Staging source:": "Fonte di stadiazione:", @@ -4183,11 +5442,13 @@ "Stale VFIO Config Detected": "Rilevata configurazione VFIO obsoleta", "Stale VFIO entries removed and initramfs rebuilt.": "voci VFIO obsolete rimosse e initramfs ricostruito.", "Standard NAS (backup, iso, vztmpl)": "NAS standard (backup, iso, vztmpl)", + "Start": "Inizio", "Start VM": "Avvia la VM", "Start VM after creation": "Avvia la VM dopo la creazione", "Start VM after creation?": "Avviare la VM dopo la creazione?", "Start a container. Use the correct ": "Avvia un contenitore. Utilizzare il corretto", "Start a virtual machine. Use the correct ": "Avvia una macchina virtuale. Utilizzare il corretto", + "Start each LXC with Proxmox (no coordinated startup)": "Avviare ogni LXC con Proxmox (senza avvio coordinato)", "Start long self-test (hours)": "Avvia autotest lungo (ore)", "Start long test now?": "Iniziare un test lungo adesso?", "Start on boot already disabled for VM": "Avvia all'avvio già disabilitato per la VM", @@ -4199,11 +5460,16 @@ "Start scrub for a ZFS pool": "Avvia lo scrubbing per un pool ZFS", "Start short self-test (~2 min)": "Avvia un breve test automatico (~2 minuti)", "Start terminal multiplexer (recommended):": "Avviare il multiplexer terminale (consigliato):", + "Start the LXC when finished to apply the selected configuration?": "Avviare il LXC quando finito per applicare la configurazione selezionata?", "Start the VM": "Avvia la VM", "Start the VM to begin Windows installation from the mounted ISO.": "Avvia la VM per iniziare l'installazione di Windows dall'ISO montato.", "Start the converted container:": "Avvia il contenitore convertito:", "Start the main system upgrade:": "Avvia l'aggiornamento del sistema principale:", + "Start the stack with Proxmox": "Avviare lo stack con Proxmox", "Start uploading to PBS — sets a recovery passphrase": "avvia il caricamento su PBS: imposta una passphrase di ripristino", + "Start when finished": "Iniziare quando finito", + "Start with Proxmox": "Inizia con Proxmox", + "Starting": "Inizio", "Starting Borg backup...": "Avvio del backup Borg...", "Starting CT": "Inizio TAC", "Starting LXC Privileged to Unprivileged conversion process...": "Avvio del processo di conversione da LXC Privileged a Unprivileged...", @@ -4214,6 +5480,7 @@ "Starting ProxMenux update...": "Avvio dell'aggiornamento di ProxMenux...", "Starting Proxmox storage integration...": "Avvio dell'integrazione dello storage Proxmox in corso...", "Starting Proxmox system repair...": "Avvio della riparazione del sistema Proxmox in corso...", + "Starting Rclone and waiting for the FUSE mount...": "Avvio di Rclone e in attesa del montaggio FUSE...", "Starting SMART long self-test...": "Avvio dell'autotest lungo SMART...", "Starting SMART short self-test...": "Avvio dell'autotest breve SMART...", "Starting container": "Contenitore di partenza", @@ -4224,9 +5491,20 @@ "Starting installer...": "Avvio del programma di installazione...", "Starting privileged container...": "Avvio del contenitore privilegiato...", "Starting rpcbind service...": "Avvio del servizio rpcbind in corso...", + "Starting the container...": "Avviare il contenitore...", + "Starting the main container and its dependencies...": "Avviare il contenitore principale e le sue dipendenze...", + "Starting the service:": "Avvio del servizio:", "Starting unprivileged container...": "Avvio del contenitore non privilegiato...", + "Startup: coordinated by the stack startup hook": "Startup: coordinato dal gancio di avvio stack", + "Startup: independent, without hookscript": "Startup: indipendente, senza hookscript", + "Static IP": "IP statico", + "Static IPv4 address": "Indirizzo IPv4 statico", + "Static IPv4 address for": "Indirizzo IPv4 statico per", "Status": "Stato", "Status:": "Stato:", + "Steam is the ultimate destination for playing, discussing, and creating games.": "Steam è la destinazione finale per giocare, discutere e creare giochi.", + "SteamGridDB": "SteamGridDB", + "SteamGridDB API key": "Chiave API SteamGridDB", "Step": "Fare un passo", "Step 2: Testing actual share access with guest...": "Passaggio 2: testare l'effettivo accesso alla condivisione con l'ospite...", "Steps that will run:": "Passaggi che verranno eseguiti:", @@ -4234,12 +5512,14 @@ "Stop it first and run this option again.": "Interrompilo prima ed esegui nuovamente questa opzione.", "Stop the CT, unmount the disk on the HOST, and remount with:": "Arrestare il CT, smontare il disco sull'HOST e rimontarlo con:", "Stop the VM/CT before formatting this disk.": "Arrestare il VM/CT prima di formattare questo disco.", + "Stop the container before the NVIDIA refresh": "Fermare il contenitore prima del rinfresco NVIDIA", "Stop the container if it's running:": "Arresta il contenitore se è in esecuzione:", "Stop them first and run this script again.": "Prima fermali ed esegui nuovamente questo script.", "Stop uploading to PBS": "interrompi il caricamento su PBS", "Stop uploading?": "interrompi il caricamento?", "Stopped": "Fermato", "Stopped and disabled": "Fermato e disabilitato", + "Stopped at:": "Stopped at:", "Stopping Coral kernel modules...": "Arresto dei moduli del kernel Coral...", "Stopping LXC": "Arresto dell'LXC", "Stopping NFS services...": "Arresto dei servizi NFS in corso...", @@ -4251,6 +5531,8 @@ "Stopping gateway...": "Arresto del gateway...", "Stopping the container before applying configuration...": "Arresto del contenitore prima di applicare la configurazione...", "Stopping the container before conversion...": "Arresto del contenitore prima della conversione...", + "Stopping the container...": "Fermare il contenitore...", + "Stopping the stack...": "Fermare la pila...", "Storage": "Magazzinaggio", "Storage & Share Manager": "Gestore archiviazione e condivisione", "Storage Added:": "Spazio di archiviazione aggiunto:", @@ -4263,21 +5545,41 @@ "Storage and Disks Commands": "Comandi di archiviazione e dischi", "Storage controller: VirtIO SCSI": "Controller di archiviazione: VirtIO SCSI", "Storage disk identifier:": "Identificatore del disco di archiviazione:", + "Storage for Nextcloud files, configuration and data": "Storage per file, configurazione e dati Nextcloud", + "Storage for Paperless data and documents": "Stoccaggio di dati e documenti senza carta", + "Storage for Tandoor files": "Stoccaggio per i file Tandoor", + "Storage for persistent data": "Conservazione dei dati persistenti", + "Storage for recipe images and files": "Archiviazione per immagini e file di ricetta", + "Storage for rootfs": "Conservazione per rootf", + "Storage for rootfs and private configuration": "Storage per rootf e configurazione privata", + "Storage for the Immich library": "Archiviazione per la libreria Immich", + "Storage for the Nextcloud data": "Conservazione dei dati Nextcloud", + "Storage for the OCI image cache": "Memorizzazione della cache dell'immagine OCI", + "Storage for the consume and export folders": "Conservazione per le cartelle di consumo ed esportazione", + "Storage for the persistent configuration": "Conservazione per la configurazione persistente", "Storage is now available in Proxmox web interface under Datacenter > Storage": "Lo spazio di archiviazione è ora disponibile nell'interfaccia web di Proxmox in Datacenter > Archiviazione", "Storage plan selection cancelled.": "Selezione del piano di archiviazione annullata.", "Storage plan selection failed or cancelled": "La selezione del piano di archiviazione non è riuscita o è stata annullata", + "Storage selection cancelled": "Selezione di stoccaggio annullata", "Storage:": "Magazzinaggio:", "Stored Credentials:": "Credenziali archiviate:", "Stored credentials:": "Credenziali archiviate:", + "Stremio is a modern media center that gives you the freedom to watch everything you want.": "Stremio è un moderno centro multimediale che ti dà la libertà di guardare tutto quello che vuoi.", + "Subdomains for the certificate, comma separated (wildcard for *.domain)": "Sottodomini per il certificato, virgola separata (wildcard per *.domain)", "Subnet": "Sottorete", "Subscription banner removal failed": "rimozione del banner di iscrizione non riuscita", "Subscription banner removed successfully": "Banner di abbonamento rimosso con successo", "Subscription banner restored successfully (desktop and mobile)": "Banner di abbonamento ripristinato correttamente (desktop e mobile)", "Success": "Successo", "Successful": "Riuscito", + "Supervisor does not confirm healthy and supported yet": "Il supervisore non conferma sano e sostenuto ancora", + "Supervisor reports no connectivity; retrying to get versions and install components": "Il supervisore non segnala alcuna connettività; riprova per ottenere versioni e installare componenti", "Supported formats: .img, .qcow2, .vmdk, .raw": "Formati supportati: .img, .qcow2, .vmdk, .raw", + "Swap": "Scambio", + "Swap in MB": "Scambio di MB", "Swap partition detected": "Partizione di swap rilevata", "Swappiness configuration created successfully": "Configurazione Swappiness creata con successo", + "Swing Music is a beautifully designed, self-hosted music streaming server. Like a cooler Spotify ... but bring your own music.": "Swing Music è un server di streaming di musica con un design accattivante. Come un Spotify più cool... ma porta la tua musica.", "Switch GPU Mode (VM <-> LXC)": "Cambia modalità GPU (VM <-> LXC)", "Switch Mode": "Cambia modalità", "Switch Script Not Found": "Script del cambio non trovato", @@ -4287,13 +5589,21 @@ "Switching to": "passaggio a", "Switching to GPU -> LXC mode removes VFIO exclusivity.": "Il passaggio a GPU -> modalità LXC rimuove l'esclusività VFIO.", "Switching to GPU -> VM mode requires exclusive VFIO binding.": "Il passaggio alla modalità GPU -> VM richiede l'associazione VFIO esclusiva.", + "Symbolic link in a restored volume path": "Link simbolico in un percorso di volume restaurato", + "Symbolic link in the path of an adaptation": "Link simbolico nel percorso di un adattamento", + "Symbolic link loop in the new image": "Ciclo di collegamento simbolico nella nuova immagine", + "Symbolic link outside the rootfs of the new image": "Link simbolico al di fuori dei rootf della nuova immagine", "Synchronize time automatically": "sincronizza l'ora automaticamente", + "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are.": "Synclounge è uno strumento di terze parti che ti permette di guardare Plex in sintonia con i tuoi amici/famiglia, ovunque tu sia.", + "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet.": "Syncthing sostituisce i servizi di sincronizzazione proprietaria e cloud con qualcosa di aperto, affidabile e decentralizzato. I tuoi dati sono i tuoi dati da soli e ti meriti di scegliere dove viene memorizzato, se viene condiviso con terzi e come viene trasmesso su Internet.", + "Sysctl not namespaced or not valid:": "Sysctl non namespaced o non valido:", "System": "Sistema", "System CLI Tools": "Strumenti della CLI di sistema", "System Disk Size (GB)": "Dimensioni del disco di sistema (GB)", "System Update Information": "Informazioni sull'aggiornamento del sistema", "System Utilities Installer": "Programma di installazione delle utilità di sistema", "System disk is SSD or M.2. Proceeding with Log2RAM setup.": "Il disco di sistema è SSD o M.2. Procedere con la configurazione di Log2RAM.", + "System error:": "Errore di sistema:", "System errors and logs": "Errori e registri di sistema", "System group apex already exists.": "L'apice del gruppo di sistemi esiste già.", "System group apex created.": "Apice del gruppo di sistema creato.", @@ -4304,6 +5614,7 @@ "System limits increase completed.": "Aumento dei limiti di sistema completato.", "System limits optimizations removed": "Ottimizzazioni dei limiti di sistema rimosse", "System must be updated to latest PVE 8.4+ before starting": "Il sistema deve essere aggiornato all'ultima versione PVE 8.4+ prima di iniziare", + "System path mounts are not yet supported": "I supporti del percorso di sistema non sono ancora supportati", "System reboot required": "È necessario il riavvio del sistema", "System upgrade completed": "Aggiornamento del sistema completato", "System uptime": "Tempo di attività del sistema", @@ -4318,6 +5629,11 @@ "TROUBLESHOOTING:": "RISOLUZIONE DEI PROBLEMI:", "TUI mode": "Modalità TUI", "TUI mode (requires root)": "Modalità TUI (richiede root)", + "Take control of your Minecraft servers.": "Prendi il controllo dei tuoi server Minecraft.", + "Tandoor WebUI": "WebUI di Tandoor", + "Tandoor configuration cancelled": "Configurazione Tandoor cancellata", + "Tandoor needs at least 1 GB for staticfiles and 4 GB for PostgreSQL": "Tandoor ha bisogno di almeno 1 GB per i file statici e 4 GB per PostgreSQL", + "Tandoor needs to complete its first start to create the initial administrator": "Tandoor deve completare il suo primo avvio per creare l'amministratore iniziale", "Target IQN:": "IQN target:", "Target VM": "VM di destinazione", "Target VM validated": "VM di destinazione convalidata", @@ -4327,6 +5643,12 @@ "Target mode": "Modalità bersaglio", "Target server:": "Server di destinazione:", "Target:": "Bersaglio:", + "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server.": "Tautulli è un'applicazione web basata su pitone per il monitoraggio, l'analisi e le notifiche per Plex Media Server.", + "Teable adopts a concise spreadsheet interface, yet creates powerful database applications": "Teable adotta un'interfaccia del foglio di calcolo conciso, ma crea potenti applicazioni del database", + "Telegram is a cloud-based mobile and desktop messaging app.": "Telegram è un'app di messaggistica mobile e desktop basata su cloud.", + "Temporary data container:": "Contenitore di dati temporaneo:", + "Temporary login": "Accesso temporaneo", + "Temporary password retrieved": "Password temporanea recuperata", "Temporary working directory (if present):": "Directory di lavoro temporanea (se presente):", "Terminal Multiplexers": "Multiplexer terminali", "Terminal multiplexer (Ctrl+b then d to detach, or type exit)": "Multiplexer terminale (Ctrl+b poi d per scollegare o digitare exit)", @@ -4343,40 +5665,197 @@ "Testing comprehensive guest access to server": "Test dell'accesso ospite completo al server", "Testing connectivity to portal...": "Test della connettività al portale...", "Testing network connectivity...": "Test della connettività di rete in corso...", + "Text that new pads start with (empty = the text of the image)": "Testo che i nuovi pad iniziano con (vuoto = testo dell'immagine)", "Thank you for using ProxMenux. Goodbye!": "Grazie per aver utilizzato ProxMenux. Arrivederci!", "That VM is currently stopped, so the GPU can be reassigned now.": "La VM è attualmente arrestata, quindi la GPU può essere riassegnata ora.", "That doesn't look like an SSH private key. Pick the private key file (no .pub extension, parseable by ssh-keygen).": "non sembra una chiave privata SSH.Scegli il file della chiave privata (nessuna estensione .pub, analizzabile da ssh-keygen).", + "The .conf files under /config/fail2ban are rewritten on every start. Keep customizations in the matching .local file, for example jail.local for jail.conf.": "I file .conf sotto /config/fail2ban vengono riscritti in ogni inizio. Tenere personalizzazione nel file corrispondente .local, per esempio jail.local per jail.conf.", + "The AppArmor/seccomp relaxation does not include the required consent": "Il relax AppArmor/seccomp non include il consenso required", + "The Bookmark Everything App": "Il Segnalibro Tutto App", + "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile.": "Il browser Brave è un browser web veloce, privato e sicuro per PC, Mac e mobile.", + "The CT already exists:": "La CT esiste già:", + "The Compose file declares no service": "Il file Compose non dichiara alcun servizio", + "The Compose file describes several images:": "Il file Compose descrive diverse immagini:", + "The Compose file does not contain a Compose document": "Il file Compose non contiene un documento Compose", + "The Compose file is not valid YAML:": "Il file Compose non è valido YAML:", + "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "Il Compose offre un rilassamento opzionale AppArmor o seccomp; rimarrà disabilitato a meno che l'utente non lo selezioni. Continua solo se ti fidi dell'immagine e accetti questo rischio.", + "The Compose value must be text or a list:": "Il valore Compose deve essere testo o elenco:", + "The DRM node is not an Intel or AMD GPU; NVIDIA requires its library profile": "Il nodo DRM non è una GPU Intel o AMD; NVIDIA requires il suo profilo di libreria", + "The Entrypoint/Cmd combination is empty": "Il punto di ingresso/Cmd combination è vuoto", + "The FUSE publication helper was not found": "L'aiutante di pubblicazione FUSE non è stato trovato", + "The GPU evidence does not match the verified devices": "Le prove della GPU non corrispondono ai dispositivi verificati", "The GPU has been moved out of VM": "La GPU è stata spostata fuori dalla VM", + "The GPU identity or permissions changed; the container is not modified": "L'identità o le autorizzazioni GPU cambiate; il contenitore non viene modificato", "The GPU is being detached from VM": "La GPU viene scollegata dalla VM", + "The GPU vendor differs from the requested profile": "Il fornitore GPU differisce dal profilo richiesto", + "The GPU vendor does not match the selected GPU profile:": "Il fornitore GPU non corrisponde al profilo GPU selezionato:", + "The Immich CPU quota cannot be reproduced": "La quota Immich CPU non può essere riprodotta", + "The Immich library needs at least 8 GB": "La libreria Immich ha bisogno di almeno 8 GB", + "The Immich startup was modified or cannot be reproduced": "L'avvio Immich è stato modificato o non può essere riprodotto", + "The LXC has stopped": "Il LXC si è fermato", + "The Lounge starts in public mode: anyone who reaches the address opens the client without logging in, and the IRC networks added are lost when the session ends.": "Il Lounge inizia in modalità pubblica: chiunque raggiunga l'indirizzo apre il client senza accedere, e le reti IRC aggiunte sono perse quando la sessione termina.", + "The MAC address of the container cannot be kept": "L'indirizzo MAC del contenitore non può essere mantenuto", "The NVIDIA Container Toolkit repository definition was empty.": "la definizione del repository NVIDIA Container Toolkit era vuota.", "The NVIDIA Container Toolkit signing key could not be read.": "non è stato possibile leggere la chiave di firma di NVIDIA Container Toolkit.", + "The NVIDIA Container Toolkit version cannot be identified": "La versione NVIDIA Container Toolkit non può essere identificata", + "The NVIDIA destination cannot be replaced": "La destinazione NVIDIA non può essere sostituita", + "The NVIDIA destination escapes the rootfs": "La destinazione NVIDIA sfugge ai rootf", "The NVIDIA driver is installed, but the Container Toolkit phase did not complete. GPU support for OCI containers is unavailable until it does.": "il driver NVIDIA è installato, ma la fase Container Toolkit non è stata completata. Il supporto GPU per i contenitori OCI non sarà disponibile finché non lo sarà.", + "The NVIDIA driver or inventory changed; the operation was stopped": "Il driver o l'inventario NVIDIA sono cambiati; il operation è stato interrotto", + "The NVIDIA hook or environment differs from the declared one": "Il gancio o l'ambiente NVIDIA differisce da quello dichiarato", + "The NVIDIA hook path does not belong to the installer": "Il percorso di aggancio NVIDIA non appartiene al programma di installazione", "The NVIDIA installer needs at least": "Il programma di installazione NVIDIA ha bisogno di almeno", + "The NVIDIA runtime is up to date; the container is not modified or started": "Il runtime NVIDIA è aggiornato; il contenitore non è modificato o avviato", + "The Nextcloud volume needs at least 8 GB": "Il volume Nextcloud richiede almeno 8 GB", + "The OCI archive contains no SHA-256 blobs": "L'archivio OCI non contiene alcun Blobs SHA-256", + "The OCI archive does not contain exactly one manifest": "L'archivio OCI non contiene esattamente un manifesto", + "The OCI archive does not exist or is empty:": "L'archivio OCI non esiste o non è vuoto:", + "The OCI archive verifier was not found": "Il verificatore dell'archivio OCI non è stato trovato", + "The OCI catalog is not installed. Update ProxMenux and try again.": "Il catalogo OCI non è installato. Aggiorna ProxMenux e riprova.", + "The OCI engine is not installed. Update ProxMenux and try again.": "Il motore OCI non è installato. Aggiorna ProxMenux e riprova.", + "The OCI image storage was not kept": "La memorizzazione delle immagini OCI non è stata mantenuta", + "The OCR language must use Tesseract codes, for example eng or eng+spa": "La lingua OCR deve utilizzare i codici Tesseract, ad esempio l'ing o l'ing+spa", + "The PATH of the new image is outside the reproducible profile": "Il PATH della nuova immagine è al di fuori del profilo riproducibile", + "The Paperless persistent volumes need at least 8 GB": "I volumi persistenti senza carta hanno bisogno di almeno 8 GB", + "The PostgreSQL volume needs at least 4 GB": "Il volume PostgreSQL ha bisogno di almeno 4 GB", + "The PostgreSQL volume needs at least 8 GB": "Il volume PostgreSQL richiede almeno 8 GB", "The Proxmox archive keyring is missing; Ceph installation cannot continue safely": "manca il portachiavi dell'archivio Proxmox;L'installazione di Ceph non può continuare in sicurezza", + "The Proxmox inventory and the local configurations differ": "L'inventario Proxmox e le configurazioni locali differiscono", + "The Rclone configuration needs at least 1 GB": "La configurazione Rclone richiede almeno 1 GB", + "The Rclone rootfs needs at least 2 GB": "I rootf Rclone hanno bisogno di almeno 2 GB", + "The Selkies profile requires a verified LinuxServer image": "Il profilo Selkies requires un'immagine LinuxServer verificata", + "The Tandoor files volume needs at least 2 GB": "Il volume dei file Tandoor ha bisogno di almeno 2 GB", "The URL does not contain the required parameters (id, pack, edition).": "L'URL non contiene i parametri richiesti (id, pack, edizione).", + "The USB number can change after reconnecting or rebooting. This profile does not remap it automatically or handle Coral USB re-enumeration. Do not share a dongle already used by another service.": "Il numero USB può cambiare dopo il ricollegamento o il riavvio. Questo profilo non lo rimappa automaticamente o gestisce la rienumerazione USB Coral. Non condividere un dongle già usato da un altro servizio.", + "The Unifi-controller software is a powerful, enterprise wireless software engine ideal for high-density client deployments requiring low latency and high uptime performance.": "Il software Unifi-controller è un potente motore software wireless aziendale ideale per le implementazioni client ad alta densità requiring bassa latenza e alte prestazioni di uptime.", + "The VA-API device does not exist:": "Il dispositivo VA-API non esiste:", "The VM also has these audio devices assigned via PCI passthrough — typically added together with the GPU. Remove them too?": "Alla VM questi dispositivi audio vengono assegnati anche tramite passthrough PCI, in genere aggiunti insieme alla GPU. Eliminare anche quelli?", "The VM guest will have exclusive access to the GPU.": "L'ospite della VM avrà accesso esclusivo alla GPU.", "The VM is powered on. Turn it off before adding disks.": "La VM è accesa. Spegnerlo prima di aggiungere dischi.", "The VM/LXC will lose access to this disk after formatting.": "La VM/LXC perderà l'accesso a questo disco dopo la formattazione.", + "The VMID belongs to another container now and is not touched:": "Il VMID appartiene ad un altro container ora e non è toccato:", + "The VMID or its contract is already in use; it is not adopted": "Il VMID o il suo contratto è già in uso; non è adottato", + "The VMID was reused or its identity is unknown; the operation is blocked": "Il VMID è stato riutilizzato o la sua identità è sconosciuta; il operation è bloccato", + "The VMID was reused or the container is on another node; it is not overwritten": "Il VMID è stato riutilizzato o il contenitore è su un altro nodo; non è sovrascritto", + "The VMID was taken during the installation:": "Il VMID è stato preso durante l'installazione:", + "The Valkey volume needs at least 1 GB": "Il volume Valkey ha bisogno di almeno 1 GB", + "The acceleration evidence differs from the verified inventory": "Le prove di accelerazione differiscono dall'inventario verificato", + "The acceleration profile does not support this architecture:": "Il profilo di accelerazione non supporta questa architettura:", "The active kernel driver is not vfio-pci, but the entry in": "il driver del kernel attivo non è vfio-pci, ma la voce in", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot, breaking the LXC passthrough about to be configured.": "il driver del kernel attivo non è vfio-pci, ma la voce ricollegherà la GPU a vfio-pci al prossimo riavvio, interrompendo il passthrough LXC che sta per essere configurato.", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot.": "il driver del kernel attivo non è vfio-pci, ma la voce ricollegherà la GPU a vfio-pci al prossimo riavvio.", + "The adaptation content was modified": "Il contenuto di adattamento è stato modificato", + "The additional path hides a system directory": "Il percorso aggiuntivo nasconde una directory di sistema", + "The address is already assigned on this host or cluster:": "L'indirizzo è già assegnato su questo host o cluster:", + "The address must start with http:// or https://": "L'indirizzo deve iniziare con http:// o http://", + "The administrator account, the public address and the UDP port are created on the first start, so the web interface opens directly on its login page.": "L'account amministratore, l'indirizzo pubblico e la porta UDP sono creati al primo avvio, quindi l'interfaccia web si apre direttamente sulla sua pagina di login.", + "The administrator email is not valid": "L'email dell'amministratore non è valida", + "The administrator user contains characters that are not allowed": "L'utente amministratore contiene caratteri non consentiti", + "The all-in-one AI application.": "L'applicazione AI all-in-one.", + "The application configuration needs a first start to complete.": "La configurazione dell'applicazione ha bisogno di un primo avvio da completare.", + "The application did not complete its initial setup:": "L'applicazione non ha completato la sua configurazione iniziale:", + "The application did not get an address on the access network:": "L'applicazione non ha ottenuto un indirizzo sulla rete di accesso:", + "The application did not pass its HTTP check:": "L'applicazione non ha superato il suo controllo HTTP:", + "The application did not respond in time:": "La domanda non ha risposto in tempo:", + "The application stopped during its first start:": "L'applicazione si è fermata durante il suo primo inizio:", + "The application was removed": "L'applicazione è stata rimossa", "The archive could not be extracted.": "Impossibile estrarre l'archivio.", "The archive destination directory is INSIDE one of the paths you are about to back up. Writing the archive there would copy the backup into itself — producing a corrupted archive, or growing without limit until the disk fills up.": "La directory di destinazione dell'archivio è ALL'INTERNO di uno dei percorsi di cui stai per eseguire il backup. Scrivere l'archivio lì copierebbe il backup su se stesso, producendo un archivio danneggiato o crescendo senza limiti finché il disco non si riempie.", + "The backup could not be identified; the image is not replaced": "Il backup non potrebbe essere identificato; l'immagine non è sostituita", "The backup metadata was compared against this host. The following items will be SKIPPED to keep the boot safe:": "i metadati di backup sono stati confrontati con questo host. I seguenti elementi verranno SALTATI per mantenere lo stivale sicuro:", + "The backup of a member could not be identified": "Il backup di un membro non potrebbe essere identificato", + "The backup was altered; recovery blocked": "Il backup è stato modificato; il recupero bloccato", "The backup was taken on a different PVE or kernel major.minor. These paths will be SKIPPED to keep the boot safe:": "il backup è stato eseguito su un PVE o kernel major.minor diverso. Questi percorsi verranno SALTATI per mantenere l'avvio sicuro:", + "The bind mount target escapes the rootfs:": "Il bersaglio del supporto del legante sfugge ai rootf:", + "The block device does not exist:": "Il dispositivo di blocco non esiste:", "The build could not be checked beforehand; continuing without that check.": "non è stato possibile controllare in anticipo la build;continuando senza quel controllo.", + "The cached image does not match the current digest": "L'immagine memorizzata nella cache non corrisponde al digestivo corrente", + "The cached image is damaged; it will be downloaded again.": "L'immagine cache è danneggiata; verrà scaricata di nuovo.", + "The character device does not exist:": "Il dispositivo di carattere non esiste:", + "The command asks for a password that is not echoed. After creating the users, the web interface asks for a user name and a password.": "Il comando richiede una password che non viene riecheggiata. Dopo aver creato gli utenti, l'interfaccia web richiede un nome utente e una password.", + "The command does not name an image": "Il comando non nomina un'immagine", + "The command reads its variables from a file; write them in the command or use a Compose file": "Il comando legge le sue variabili da un file; scrivile nel comando o usa un file Compose", + "The command runs the container as the user of the host; the container uses the user of its image instead.": "Il comando esegue il contenitore come utente dell'host; il contenitore utilizza invece l'utente della sua immagine.", + "The command uses options that cannot be translated:": "Il comando utilizza opzioni che non possono essere tradotte:", + "The command works out a value by running another command:": "Il comando esegue un valore eseguendo un altro comando:", "The compatibility check raised failures that may break the system after restore.": "Il controllo di compatibilità ha rilevato errori che potrebbero danneggiare il sistema dopo il ripristino.", + "The configuration changed after the backup was restored; the recovery is not confirmed": "La configurazione è cambiata dopo il ripristino del backup; il recupero non è confermato", + "The configuration changed after the new container was validated": "La configurazione è cambiata dopo la convalida del nuovo contenitore", + "The configuration changed during the NVIDIA refresh": "La configurazione è cambiata durante il aggiornamento NVIDIA", + "The configuration evidence does not match": "Le prove di configurazione non corrispondono", + "The configuration must run as root on Proxmox VE": "La configurazione deve essere eseguita come root su Proxmox VE", + "The configuration of a new member changed after it was created": "La configurazione di un nuovo membro cambiato dopo che è stato creato", + "The configuration stopped because of an unexpected error": "La configurazione si è fermata a causa di un errore inaspettato", + "The consume/export volumes need at least 1 GB": "I volumi di consumo/esportazione devono almeno 1 GB", + "The container could not be removed automatically:": "Il contenitore non può essere rimosso automaticamente:", + "The container could not be started:": "Il contenitore non poteva essere avviato:", + "The container creation does not match the prepared instance": "La creazione del contenitore non corrisponde all'istanza preparata", + "The container devices do not match the saved record": "I dispositivi dei container non corrispondono al record salvato", + "The container did not stop to update its persistent configuration:": "Il contenitore non si è fermato per aggiornare la sua configurazione persistente:", + "The container did not stop; its disks are not touched": "Il contenitore non si è fermato; i suoi dischi non sono toccati", + "The container disks do not match the saved record": "I dischi dei container non corrispondono al record salvato", + "The container does not exist:": "Il contenitore non esiste:", + "The container does not have the fuse=1 feature enabled": "Il contenitore non ha la funzione fuse=1 abilitata", + "The container does not need it any more; an update downloads the new version when there is one.": "Il contenitore non ne ha più bisogno; un aggiornamento scarica la nuova versione quando c'è uno.", + "The container gets its own address and its own volumes, so the networks and volumes declared in the file are not used.": "Il contenitore ottiene il proprio indirizzo e i propri volumi, quindi le reti e i volumi dichiarati nel file non vengono utilizzati.", + "The container has advanced Proxmox settings outside the supported profile": "Il contenitore ha impostazioni Proxmox avanzate al di fuori del profilo supportato", + "The container identity changed; the container is not replaced": "L'identità del contenitore è cambiata; il contenitore non è sostituito", + "The container identity does not match": "L'identità del contenitore non corrisponde", + "The container identity or configuration changed": "Modificata l'identità o la configurazione del contenitore", "The container is currently stopped. Do you want to start it now to install the package?": "Il contenitore è attualmente fermo. Vuoi avviarlo adesso per installare il pacchetto?", + "The container is not modified because a host directory is not available:": "Il contenitore non è modificato perché una directory host non è disponibile:", + "The container no longer exists:": "Il contenitore non esiste più:", + "The container of a member was replaced; the assembly is not resumed": "Il contenitore di un membro è stato sostituito; l'assemblaggio non è ripreso", "The container should now start as privileged": "Il contenitore ora dovrebbe iniziare come privilegiato", "The container should now start as unprivileged": "Il contenitore ora dovrebbe iniziare come senza privilegi", + "The container stopped after starting:": "Il contenitore si è fermato dopo l'avvio:", + "The container stopped before publishing the mount": "Il contenitore si è fermato prima di pubblicare il supporto", + "The container stopped before the GPU permissions were verified:": "Il contenitore si è fermato prima che le autorizzazioni GPU fossero verificate:", + "The container stopped before the application responded:": "Il contenitore si è fermato prima dell'applicazione ha risposto:", + "The container stopped:": "Il contenitore si è fermato:", + "The container takes its time zone from Proxmox, so the time files of the host are not attached to it.": "Il contenitore prende il suo fuso orario da Proxmox, quindi i file temporali dell'host non sono attaccati ad esso.", + "The container was changed outside ProxMenux and an update would discard those changes:": "Il contenitore è stato cambiato al di fuori di ProxMenux e un aggiornamento scarterà tali modifiche:", + "The container was created from a downloaded OCI image": "Il contenitore è stato creato da un'immagine OCI scaricata", + "The containers do not need them any more; an update downloads the new versions when there are any.": "I contenitori non ne hanno più bisogno; un aggiornamento scarica le nuove versioni quando ci sono.", + "The containers were created from downloaded OCI images": "I contenitori sono stati creati da immagini OCI scaricate", + "The coordinated backup was modified": "Il backup coordinato è stato modificato", "The current driver will be completely uninstalled before installing the new version. Continue?": "Il driver corrente verrà completamente disinstallato prima di installare la nuova versione. Continuare?", + "The current image of the saved channel will be checked and downloaded. Resources, paths and GPU are kept. The CT is stopped during the replacement and a native backup is created first.": "L'immagine corrente del canale salvato verrà controllata e scaricata. Risorse, percorsi e GPU sono tenuti. La CT viene fermata durante la sostituzione e viene creato un backup nativo prima.", + "The current record is missing for": "L'attuale record manca per", + "The current template changes the image or identity; an explicit migration is required": "Il modello attuale cambia immagine o identità; una migrazione esplicita è required", + "The current template requires a new persistent path:": "Il modello attuale requires un nuovo percorso persistente:", + "The custom path cannot hide system directories": "Il percorso personalizzato non può nascondere directory di sistema", + "The custom path overlaps another mount": "Il percorso personalizzato sovrappone un altro supporto", + "The data and document volumes need at least 8 GB": "I volumi di dati e documenti hanno bisogno di almeno 8 GB", + "The database server must accept connections from the IP address of this container, with a user that is not limited to localhost.": "Il server del database deve accettare le connessioni dall'indirizzo IP di questo contenitore, con un utente che non è limitato a localhost.", + "The dedicated adapter still requires replaying its rootfs changes": "L'adattatore dedicato ancora requires rigiocare le sue modifiche rootfs", + "The dependency hook and the stack recipe differ": "Il gancio di dipendenza e la ricetta dello stack differiscono", + "The dependency hook was modified; review it before updating": "Il gancio di dipendenza è stato modificato; rivederlo prima dell'aggiornamento", + "The developer-friendly cloud platform for building and running LLM agents for AI-native applications.": "La piattaforma cloud per la costruzione e l'esecuzione di agenti LLM per applicazioni AI-native.", + "The device directory does not exist:": "La directory del dispositivo non esiste:", + "The device must keep its /dev path inside the LXC:": "Il dispositivo deve mantenere il suo percorso /dev all'interno del LXC:", + "The device must keep its native path without duplicates": "Il dispositivo deve mantenere il suo percorso nativo senza duplicati", + "The directory contains no character devices:": "La directory non contiene dispositivi di carattere:", "The directory does not exist in the CT.": "La directory non esiste nel CT.", "The disk": "Il disco", + "The disk size cannot be reproduced": "Il formato del disco non può essere riprodotto", + "The disk usage of the container could not be read": "L'uso del disco del contenitore non poteva essere letto", + "The domain must resolve to the public address of this network before the certificate can be issued.": "Il dominio deve essere risolto all'indirizzo pubblico di questa rete prima che il certificato possa essere rilasciato.", + "The download client still needs to be configured.": "Il client di download deve ancora essere configurato.", + "The download stopped progressing; cancelling this attempt.": "Il download ha smesso di progredire; cancellando questo tentativo.", + "The downloaded image does not match its manifest": "L'immagine scaricata non corrisponde al suo manifesto", + "The downloaded image is corrupt:": "L'immagine scaricata è corrotta:", "The dpkg package database is clean.": "il database dei pacchetti dpkg è pulito.", "The driver installed but does not drive this GPU.": "il driver è installato ma non gestisce questa GPU.", + "The dynamic NVIDIA hook is missing": "Manca il gancio dinamico NVIDIA", + "The dynamic NVIDIA hook is missing or duplicated": "Il gancio dinamico NVIDIA manca o duplicato", + "The dynamic NVIDIA profile requires an unprivileged LXC": "Il profilo dinamico NVIDIA requires un LXC non privato", + "The dynamic profile does not support static driver mounts": "Il profilo dinamico non supporta i supporti driver statici", "The file does not exist, is empty or is not readable.": "il file non esiste, è vuoto o non è leggibile.", + "The file does not exist:": "Il file non esiste:", + "The file is too large to be a Compose file": "Il file è troppo grande per essere un file Compose", "The filesystem": "Il file system", + "The final cleanup did not complete:": "La pulizia finale non è stata completata:", "The following DKMS-managed drivers will now be rebuilt against it so they keep working after reboot:": "i seguenti driver gestiti da DKMS verranno ora ricostruiti in modo che continuino a funzionare dopo il riavvio:", "The following LXC containers have NVIDIA passthrough configured:": "I seguenti contenitori LXC hanno il passthrough NVIDIA configurato:", "The following backup paths are kernel-tied and are excluded from the picker to keep the target's boot safe. The operator's own tuning inside these paths (IOMMU cmdline, VFIO IDs, custom quirks) is merged back automatically via kernel-agnostic merge:": "i seguenti percorsi di backup sono legati al kernel e sono esclusi dal selettore per mantenere sicuro l'avvio della destinazione. L'ottimizzazione dell'operatore all'interno di questi percorsi (linea cmd IOMMU, ID VFIO, stranezze personalizzate) viene riunita automaticamente tramite unione indipendente dal kernel:", @@ -4390,17 +5869,99 @@ "The following selected device(s) are Physical Functions with active Virtual Functions:": "I seguenti dispositivi selezionati sono funzioni fisiche con funzioni virtuali attive:", "The following selected device(s) are SR-IOV Virtual Functions (VFs):": "I seguenti dispositivi selezionati sono funzioni virtuali SR-IOV (VF):", "The fstab entry will still be removed; reboot or manual umount needed.": "La voce fstab verrà comunque rimossa; è necessario riavviare o eseguire lo smontaggio manuale.", + "The gateway must be another usable address in the same subnet.": "Il gateway deve essere un altro indirizzo utilizzabile nella stessa sottorete.", "The gateway should appear in your Tailscale admin console shortly.": "Il gateway dovrebbe apparire a breve nella tua console di amministrazione Tailscale.", + "The healthcheck cannot run without an IP address": "Il controllo sanitario non può essere eseguito senza un indirizzo IP", + "The host NVIDIA driver is not responding correctly": "Il driver NVIDIA non risponde correttamente", + "The host bind source does not exist:": "La fonte di legame host non esiste:", + "The host bind source is not a regular file or directory:": "La fonte di legame host non è un file o una directory regolari:", + "The host directory changed before it was mounted": "La directory host cambiò prima che fosse montata", "The host directory may not be accessible from an unprivileged container.": "La directory host potrebbe non essere accessibile da un contenitore non privilegiato.", + "The host has no IPv4 address on the selected bridge": "L'host non ha indirizzo IPv4 sul ponte selezionato", + "The host monitor does not see the real host memory": "Il monitor host non vede la vera memoria host", + "The host monitor does not share this host namespace:": "Il monitor host non condivide questo namespace host:", + "The host monitor needs consent for privileged access to the host": "Il monitor host ha bisogno del consenso per l'accesso privilegiato all'host", + "The host monitor profile does not support another sysctl include": "Il profilo del monitor host non supporta un altro sysctl include", + "The host monitor uses the host network, without DHCP or its own gateway": "Il monitor host utilizza la rete host, senza DHCP o il proprio gateway", + "The host port is already in use:": "Il porto host è già in uso:", + "The identity of a member was replaced": "L'identità di un membro è stata sostituita", + "The image changes the user expected by the adapter": "L'immagine cambia l'utente previsto dall'adattatore", + "The image could not be read from its registry:": "L'immagine non poteva essere letta dal suo registro:", + "The image declares data paths that are still stored in the rootfs": "L'immagine dichiara percorsi di dati che sono ancora memorizzati nei rootfs", + "The image did not grant the application user access to the devices; check its native init. Host permissions were not relaxed.": "L'immagine non ha concesso l'accesso dell'utente dell'applicazione ai dispositivi; controlla il suo init nativo. Le autorizzazioni ospitanti non erano rilassate.", + "The image did not pass the integrity check": "L'immagine non ha superato il controllo dell'integrità", + "The image does not declare support for this architecture:": "L'immagine non dichiara supporto per questa architettura:", + "The image download did not complete correctly; downloading it again...": "Il download dell'immagine non è stato completato correttamente; scaricarlo di nuovo...", + "The image expects files that are given to it one by one:": "L'immagine prevede file che gli vengono dati uno per uno:", + "The image is already up to date; nothing was changed.": "L'immagine è già aggiornata; nulla è stato cambiato.", + "The image is in its registry, for one architecture.": "L'immagine è nel suo registro, per un'architettura.", + "The image is in its registry.": "L'immagine è nel suo registro.", + "The image is in its registry:": "L'immagine è nel suo registro:", + "The image requests NVIDIA, but the host has no working NVIDIA driver": "L'immagine richiede NVIDIA, ma l'host non ha un driver NVIDIA funzionante", + "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk.": "L'immagine richiede di disabilitare parte del confinamento AppArmor o seccomp. Continua solo se ti fidi dell'immagine e accetti questo rischio.", + "The image requests disabling part of the AppArmor or seccomp confinement. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "L'immagine richiede di disabilitare parte del confinamento AppArmor o seccomp. Il Compose offre un rilassamento opzionale AppArmor o seccomp; rimarrà disabilitato a meno che l'utente non lo selezioni. Continua solo se ti fidi dell'immagine e accetti questo rischio.", + "The image was not found in its registry, or it is private:": "L'immagine non è stata trovata nel suo registro, o è privata:", + "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged.": "Il Compose importato richiede privilegiato, ma la documentazione ufficiale jlesage/handbrake non lo require; ProxMenux mantiene il LXC non privato.", + "The imported OCI groups are not numeric": "I gruppi OCI importati non sono numerici", + "The imported OCI user or group is not numeric": "L'utente o il gruppo OCI importati non è numerico", + "The initial user name and password stay written in /etc/pve/lxc/.conf as INIT_USERNAME and INIT_PASSWORD. They can be removed after the first login, with the container stopped.": "Il nome utente iniziale e la password rimangono scritti in /etc/pve/lxc/δCTID>.conf come INIT USERNAME e INIT PASSWORD. Possono essere rimossi dopo il primo login, con il contenitore fermato.", + "The installation asks which one to use for these paths.": "L'installazione chiede quale utilizzare per questi percorsi.", + "The installation ended with exit code": "L'installazione è terminata con il codice di uscita", "The installation requires a server restart to apply changes. Do you want to restart now?": "L'installazione richiede il riavvio del server per applicare le modifiche. Vuoi riavviare adesso?", + "The installation runs on the Proxmox node itself, as root": "L'installazione funziona sul nodo Proxmox stesso, come radice", + "The installation stopped because of an unexpected error": "L'installazione si è fermata a causa di un errore inaspettato", "The installation/changes require a server restart to apply correctly. Do you want to reboot now?": "L'installazione/modifiche richiedono il riavvio del server per essere applicate correttamente. Vuoi riavviare adesso?", + "The installer must run as root on Proxmox VE": "L'installatore deve essere eseguito come root su Proxmox VE", + "The instance changed while it was being edited; configure Recreate again": "L'istanza è cambiata mentre veniva modificata; configurare nuovamente Recreate", + "The instance does not use NVIDIA": "L'istanza non utilizza NVIDIA", + "The instance has a pending operation": "L'istanza ha un operation in sospeso", + "The instance identity or status must be reviewed before updating.": "L'identità o lo stato dell'istanza devono essere esaminati prima dell'aggiornamento.", + "The instance is not ready to be updated": "L'istanza non è pronta ad essere aggiornata", + "The instance is not ready; review its pending operation": "L'istanza non è pronta; rivedere la sua operation", + "The instance record operation did not complete; no container was modified.": "Il record di istanza operation non è stato completato; nessun contenitore è stato modificato.", + "The instance registry is not safe": "Il registro delle istanze non è sicuro", + "The journal belongs to another VMID": "Il diario appartiene ad un altro VMID", + "The journal belongs to another stack": "Il diario appartiene ad un altro stack", + "The journal has an incomplete recovery state": "La rivista ha uno stato di recupero incompleto", + "The kernel module is not active:": "Il modulo del kernel non è attivo:", "The kernel module of version": "il modulo del kernel della versione", "The local envelope is dropped and future backups do not upload anything. Uploaded envelopes already on PBS stay intact and remain recoverable with their original passphrase.": "la busta locale viene eliminata e i backup futuri non caricano nulla. Le buste caricate già su PBS rimangono intatte e recuperabili con la loro passphrase originale.", "The long test runs directly on the disk hardware.": "Il test lungo viene eseguito direttamente sull'hardware del disco.", + "The main member must stop first and start last": "Il membro principale deve fermarsi prima e iniziare l'ultima", + "The main member of the stack is missing": "Manca il principale membro dello stack", + "The manifest does not match its digest": "Il manifesto non corrisponde al suo digestivo", + "The member journal belongs to another stack operation": "Il diario membro appartiene ad un altro stack operation", + "The member journal is outside the registry": "Il diario dei membri è fuori dal registro", + "The mount evidence does not match the verified directories": "Le prove di montaggio non corrispondono alle directory verificate", + "The mount source or options were not kept": "La sorgente di montaggio o le opzioni non sono state conservate", + "The mounted source differs from the configured directory": "La sorgente montata differisce dalla directory configurata", + "The mounts of the new container do not match the proposal": "I supporti del nuovo contenitore non corrispondono alla proposta", + "The native GPU permissions were not kept": "Le autorizzazioni GPU native non sono state mantenute", + "The native unprivileged idmap is required": "Il nativo idmap non privato è required", "The new SSH key was installed and is now authorized on the server.\nKey file:": "La nuova chiave SSH è stata installata ed è ora autorizzata sul server.\nFascicolo chiave:", "The new SSH key was pushed to the LXC via 'pct exec' on": "la nuova chiave SSH è stata inviata all'LXC tramite 'pct exec'", + "The new Valkey volume contains unexpected data": "Il nuovo volume Valkey contiene dati inaspettati", + "The new container did not pass validation": "Il nuovo contenitore non ha superato la validazione", + "The new container is not authorized by the operation journal": "Il nuovo contenitore non è autorizzato dalla rivista operation", + "The new image adds a symbolic link in a generated path": "La nuova immagine aggiunge un link simbolico in un percorso generato", + "The new image changes the PostgreSQL major version; the data must be migrated before updating": "La nuova immagine cambia la versione principale PostgreSQL; i dati devono essere migrati prima dell'aggiornamento", + "The new image could not be installed": "La nuova immagine non poteva essere installata", + "The new image could not be installed:": "La nuova immagine non poteva essere installata:", + "The new image does not keep a required executable": "La nuova immagine non conserva un eseguibile required", + "The new image requires additional persistent paths": "La nuova immagine requires ulteriori percorsi persistenti", + "The new image requires additional persistent paths; use Recreate": "La nuova immagine requires ulteriori percorsi persistenti; utilizzare Recreate", "The new prompt will be used in new terminal sessions.": "Il nuovo prompt verrà usato nelle nuove sessioni del terminale.", "The next visit to the dashboard will show the initial setup wizard.": "La successiva visita alla dashboard mostrerà la procedura guidata di configurazione iniziale.", + "The observed inventory differs from the validated runtime": "L'inventario osservato differisce dal runtime convalidato", + "The official Tandoor startup executable is missing": "Manca l'eseguibile ufficiale di avvio Tandoor", + "The official inventory contains no NVIDIA devices": "L'inventario ufficiale non contiene dispositivi NVIDIA", + "The official inventory contains no NVIDIA driver components": "L'inventario ufficiale non contiene componenti driver NVIDIA", + "The official startup cannot be reproduced": "L'avvio ufficiale non può essere riprodotto", + "The official startup of the application is missing": "Manca l'avvio ufficiale dell'applicazione", + "The operation already finished; it is not restored automatically": "Il operation già finito; non viene ripristinato automaticamente", + "The operation could not be completed": "Il operation non poteva essere completato", + "The operation stopped halfway. Choose \"Recover\" for this container in the OCI management menu to restore the previous installation.": "La operation si è fermata a metà strada. Scegliere \"Recuperare\" per questo contenitore nel menu di gestione OCI per ripristinare l'installazione precedente.", + "The operation was stopped because a shared directory changed its identity:": "La operation è stata fermata perché una directory condivisa ha cambiato la sua identità:", "The original MOTD backup is unavailable; no changes were made": "il backup MOTD originale non è disponibile;non sono state apportate modifiche", "The original MOTD configuration has been restored": "La configurazione MOTD originale è stata ripristinata", "The original MOTD state is unavailable; no changes were made": "lo stato MOTD originale non è disponibile;non sono state apportate modifiche", @@ -4408,18 +5969,76 @@ "The original rpcbind state could not be restored completely": "non è stato possibile ripristinare completamente lo stato originale di rpcbind", "The original rpcbind state is unavailable; no service state was changed": "lo stato originale di rpcbind non è disponibile;nessuno stato del servizio è stato modificato", "The package is currently in a broken state and is blocking apt updates on this system.": "il pacchetto è attualmente in uno stato non funzionante e sta bloccando gli aggiornamenti apt su questo sistema.", + "The parent of an NVIDIA destination is not a directory": "Il genitore di una destinazione NVIDIA non è una directory", + "The parent of the target is not a directory:": "Il genitore dell'obiettivo non è una directory:", + "The password could not be retrieved automatically": "La password non potrebbe essere recuperata automaticamente", "The passwords do not match. Please try again.": "Le password non corrispondono. Per favore riprova.", + "The path escapes the rootfs:": "Il sentiero sfugge ai rootf:", + "The path must be absolute and normalized": "Il percorso deve essere assoluto e normalizzato", + "The path overlaps an existing mount": "Il percorso si sovrappone a un supporto esistente", + "The persistent NVIDIA hook does not match the installer:": "Il gancio NVIDIA persistente non corrisponde al programma di installazione:", + "The persistent WebUI credentials were not found": "I persistenti WebUI credentials non sono stati trovati", + "The physical NVIDIA selection changed": "La selezione fisica NVIDIA è cambiata", + "The post-start configuration cannot be applied with the LXC stopped": "La configurazione post-start non può essere applicata con il LXC fermato", + "The postgres user was not found in the image": "L'utente postgres non è stato trovato nell'immagine", + "The prepared directory escapes the rootfs:": "La directory preparata sfugge ai rootf:", "The preselected VMID does not exist on this host:": "Il VMID preselezionato non esiste su questo host:", + "The previous native backup will be restored. Shared host directories are not reverted. Displaced disks are kept.": "Il backup nativo precedente verrà ripristinato. Le directory degli host condivisi non vengono rimosse. I dischi staccati sono tenuti.", + "The previous stack contract is not safe; review it before reusing it": "Il precedente contratto stack non è sicuro; rivederlo prima di riutilizzarlo", + "The previous stack contract is not valid; it is not archived automatically": "Il precedente contratto stack non è valido; non viene archiviato automaticamente", + "The previous stack contract still has containers or VMs:": "Il precedente contratto stack ha ancora container o VM:", + "The private address is already assigned to another container:": "L'indirizzo privato è già assegnato ad un altro contenitore:", + "The private bridge does not have the expected address:": "Il ponte privato non ha l'indirizzo previsto:", + "The private journal has an unsafe owner or permissions": "Il diario privato ha un proprietario o autorizzazioni non sicuri", + "The private network allocator was not found": "L'allocatore della rete privata non è stato trovato", + "The private network is still used by another container and is kept:": "La rete privata è ancora utilizzata da un altro contenitore ed è conservata:", + "The private network must be assigned automatically": "La rete privata deve essere assegnata automaticamente", + "The privileged deployment does not include the required explicit consent": "La distribuzione privilegiata non include il consenso esplicito required", + "The prlimit soft value exceeds the hard value": "Il valore morbido prilimit supera il valore duro", + "The proposal changes the identity of the instance": "La proposta modifica l'identità dell'istanza", "The proposed ARC maximum is below Proxmox VE's pool-size guideline:": "il massimo ARC proposto è inferiore alle Proxmox linee guida VE sulle dimensioni della piscina:", + "The published views must be inside the common root": "Le opinioni pubblicate devono essere all'interno della radice comune", + "The read-only view does not apply the expected protection": "La vista di sola lettura non applica la protezione prevista", + "The read-only view was not published": "La visione di sola lettura non è stata pubblicata", + "The read/write view was not published": "La vista lettura/scrittura non è stata pubblicata", + "The recipe requires configuration at startup; its coordinated replay is not available": "La ricetta requires configurazione all'avvio; la sua ripetizione coordinata non è disponibile", + "The record belongs to another container": "Il record appartiene ad un altro container", + "The record does not belong to this operation": "Il record non appartiene a questo operation", + "The record no longer belongs to this operation": "Il record non appartiene più a questo operation", + "The record of a member was replaced; the assembly is not resumed": "Il registro di un membro è stato sostituito; l'assemblea non è ripresa", + "The record or diagnosis could not be completed; no update was run.": "Il record o la diagnosi non potrebbero essere completati; nessun aggiornamento è stato eseguito.", + "The recovery did not complete. Review the log and choose \"Recover\" again for this container in the OCI management menu.": "Il recupero non è completo. Rivedere il registro e scegliere \"Recuperare\" di nuovo per questo contenitore nel menu di gestione OCI.", + "The remote does not exist; create and authorize it first in the WebUI:": "Il telecomando non esiste; crea e autorizza prima nel WebUI:", + "The remote installer must run as root on Proxmox VE": "L'installatore remoto deve essere eseguito come root su Proxmox VE", + "The remote must already be created and authorized in the Rclone web UI. This operation restarts the CT and publishes two FUSE views on the host.": "Il telecomando deve già essere creato e autorizzato nell'interfaccia web Rclone. Questo operation riavvia la CT e pubblica due visualizzazioni FUSE sull'host.", + "The remote path must be relative and cannot contain line breaks": "Il percorso remoto deve essere relativo e non può contenere interruzioni di linea", + "The removal could not be prepared:": "La rimozione non poteva essere preparata:", + "The repair must preserve the image dependencies:": "La riparazione deve preservare le dipendenze dell'immagine:", + "The requested VMID block is already in use": "Il blocco VMID richiesto è già in uso", + "The requested machine learning GPU profile is not working; it is not replaced by CPU": "Il profilo di GPU di apprendimento della macchina richiesta non funziona; non è sostituito dalla CPU", + "The restored service did not pass its health check": "Il servizio restaurato non ha superato il suo controllo sanitario", + "The restored service stopped; the recovery is not confirmed": "Il servizio restaurato si è fermato; il recupero non è confermato", + "The reviewed Tandoor stack does not require a privileged LXC.": "Lo stack Tandoor recensito non require un LXC privilegiato.", + "The rootfs capture only belongs to the running installation": "La cattura dei rootf appartiene solo all'installazione in esecuzione", + "The rootfs is not managed by Proxmox": "I rootf non sono gestiti da Proxmox", + "The rootfs is not mounted": "I rootf non sono montati", "The same GPU cannot be used by two VMs at the same time.": "La stessa GPU non può essere utilizzata da due VM contemporaneamente.", + "The same connection can be given as container variables instead of the file: UN_SONARR_0_URL and UN_SONARR_0_API_KEY, or the UN_RADARR_0_ equivalents.": "La stessa connessione può essere data come variabili di contenitore al posto del file: UN SONARR 0 URL e UN SONARR 0 API KEY, o UN RADARR 0 equivalents.", "The saved MOTD state is invalid; no changes were made": "lo stato MOTD salvato non è valido;non sono state apportate modifiche", + "The saved OCI record is incomplete or has an unexpected format.": "Il record OCI salvato è incompleto o ha un formato inaspettato.", + "The saved projection does not match the native evidence": "La proiezione salvata non corrisponde alle prove native", + "The saved record was replaced for": "Il record salvato è stato sostituito per", "The saved utility package list is invalid; no packages were removed": "l'elenco dei pacchetti di utilità salvati non è valido;nessun pacchetto è stato rimosso", "The script clones the osx-proxmox.com repository and once the setup is complete, the server will automatically reboot.": "Lo script clona il repository osx-proxmox.com e una volta completata la configurazione, il server si riavvierà automaticamente.", "The script will continue to restore VM passthrough mode on the host and reuse existing hostpci entries.": "Lo script continuerà a ripristinare la modalità passthrough della VM sull'host e a riutilizzare le voci hostpci esistenti.", "The script will preconfigure the selected GPU now and finalize hardware binding after reboot.": "Lo script preconfigurerà ora la GPU selezionata e finalizzerà il collegamento hardware dopo il riavvio.", "The selected AMD GPU does not report FLR reset support": "La GPU AMD selezionata non riporta il supporto per il ripristino FLR", "The selected AMD GPU is currently in power state D3cold": "La GPU AMD selezionata è attualmente nello stato di alimentazione D3cold", + "The selected CT does not match its OCI record. Its configuration will not be modified or deleted.": "La TAC selezionata non corrisponde al suo record OCI. La sua configurazione non verrà modificata o cancellata.", + "The selected GPU changed": "La GPU selezionata è cambiata", "The selected GPU configuration already exists in this container.": "La configurazione GPU selezionata esiste già in questo contenitore.", + "The selected GPU device does not exist:": "Il dispositivo GPU selezionato non esiste:", + "The selected GPU directory does not exist:": "La directory GPU selezionata non esiste:", "The selected GPU has no dedicated .1 audio sibling function.": "La GPU selezionata non dispone di una funzione di pari livello audio .1 dedicata.", "The selected GPU is already assigned to another VM that is currently running:": "La GPU selezionata è già assegnata a un'altra VM attualmente in esecuzione:", "The selected GPU is already assigned to this VM, but the host is not currently using vfio-pci for this device.": "La GPU selezionata è già assegnata a questa VM, ma l'host attualmente non utilizza vfio-pci per questo dispositivo.", @@ -4435,11 +6054,15 @@ "The selected Intel GPU does not expose a PCI reset interface": "La GPU Intel selezionata non espone un'interfaccia di ripristino PCI", "The selected Intel GPU has non-FLR reset support and unknown subtype": "La GPU Intel selezionata ha il supporto per il ripristino non FLR e un sottotipo sconosciuto", "The selected Intel GPU is currently in power state D3cold": "La GPU Intel selezionata è attualmente nello stato di alimentazione D3cold", + "The selected Intel render device does not exist:": "Il dispositivo di rendering Intel selezionato non esiste:", "The selected VM": "La VM selezionata", "The selected VM is running.": "La VM selezionata è in esecuzione.", "The selected base folder does not exist and could not be created:": "La cartella di base selezionata non esiste e non può essere creata:", + "The selected configuration needs to start the LXC during the installation": "La configurazione selezionata deve avviare il LXC durante l'installazione", "The selected container is unprivileged. A privileged container is required for direct device passthrough.": "Il contenitore selezionato non è privilegiato. È richiesto un contenitore privilegiato per il passthrough diretto del dispositivo.", "The selected device": "Il dispositivo selezionato", + "The selected device is not a block device": "Il dispositivo selezionato non è un dispositivo di blocco", + "The selected device is not a character device": "Il dispositivo selezionato non è un dispositivo di carattere", "The selected directory does not exist:": "La directory selezionata non esiste:", "The selected disk has an active swap partition. Aborting.": "Il disco selezionato ha una partizione di swap attiva. Interruzione.", "The selected disk is currently used by a RUNNING VM or CT. Stop it before formatting.": "Il disco selezionato è attualmente utilizzato da una VM o CT IN ESECUZIONE. Interrompilo prima della formattazione.", @@ -4447,25 +6070,76 @@ "The selected disk now contains a system-critical mount. Aborting.": "Il disco selezionato ora contiene un montaggio critico per il sistema. Interruzione.", "The selected path does not exist on this host:": "il percorso selezionato non esiste su questo host:", "The selected path is not a valid directory:": "Il percorso selezionato non è una directory valida:", + "The selected render device does not exist:": "Il dispositivo di rendering selezionato non esiste:", "The server connected you as guest instead of the specified user.": "Il server ti ha connesso come ospite invece dell'utente specificato.", "The server may not have accessible shares.": "Il server potrebbe non avere condivisioni accessibili.", "The server may require authentication for actual share access.": "Il server potrebbe richiedere l'autenticazione per l'effettivo accesso alla condivisione.", "The server refused password authentication for": "il server ha rifiutato l'autenticazione della password per", "The server rejected": "il server ha rifiutato", + "The service builds its own image; only a published image can be installed": "Il servizio costruisce la propria immagine; solo un'immagine pubblicata può essere installata", + "The service declares no image:": "Il servizio non dichiara alcuna immagine:", + "The setting has no final value:": "L'impostazione non ha valore finale:", "The share already exists in smb.conf:": "La condivisione esiste già in smb.conf:", + "The shared destination is not a directory": "La destinazione condivisa non è una directory", + "The shared directory points to a protected host path": "La directory condivisa indica un percorso host protetto", + "The shared path exists but is not a directory:": "Il percorso condiviso esiste ma non è una directory:", + "The size of existing disks is not rounded": "La dimensione dei dischi esistenti non è arrotondata", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk.": "La fonte Compose richiede privilegi: vero, ma questo non dimostra che l'immagine ha bisogno di un LXC privilegiato. ProxMenux utilizzerà un LXC non privato per impostazione predefinita e offrirà l'ampia modalità solo come opzione. Continua solo se ti fidi dell'immagine e accetti questo rischio.", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. The Docker rootlesskit profile does not exist in LXC and will be replaced by AppArmor unconfined, which is less restrictive. Continue only if you trust the image and accept this risk.": "La fonte Compose richiede privilegi: vero, ma questo non dimostra che l'immagine ha bisogno di un LXC privilegiato. ProxMenux utilizzerà un LXC non privato per impostazione predefinita e offrirà l'ampia modalità solo come opzione. Il Compose offre un rilassamento opzionale AppArmor o seccomp; rimarrà disabilitato a meno che l'utente non lo selezioni. Il profilo di Docker rootlesskit non esiste in LXC e sarà sostituito da AppArmor non Confined, che è meno restrittivo. Continua solo se ti fidi dell'immagine e accetti questo rischio.", "The source VM also has these audio devices, likely added together with the GPU. Remove them too?": "Anche la VM di origine dispone di questi dispositivi audio, probabilmente aggiunti insieme alla GPU. Eliminare anche quelli?", "The specified directory does not exist:": "La directory specificata non esiste:", + "The stability period must be shorter than the healthcheck timeout": "Il periodo di stabilità deve essere più breve del timeout del controllo sanitario", + "The stack contains devices or directives without a translation": "Lo stack contiene dispositivi o direttive senza traduzione", + "The stack does not have the expected native hook": "Lo stack non ha il gancio nativo previsto", + "The stack journal is outside the registry": "Il diario dello stack è fuori dal registro", + "The stack member has no declared adaptation profile": "Il membro dello stack non ha un profilo di adattamento dichiarato", + "The stack name only accepts lowercase letters, numbers and hyphens": "Il nome della pila accetta solo lettere minuscole, numeri e trattini", + "The stack needs member adaptations or a verification of missing volumes": "Lo stack ha bisogno di adattamenti dei membri o di una verifica dei volumi mancanti", + "The stack operation had already finished": "La pila operation aveva già finito", + "The stack operation has not finished yet": "La pila operation non ha ancora finito", + "The stack operation stopped halfway. Select the stack again in the OCI management menu to recover it.": "La pila operation si è fermata a metà strada. Selezionare nuovamente lo stack nel menu di gestione OCI per recuperarlo.", + "The stack registry is incomplete; review the private contracts.": "Il registro di stack è incompleto; rivedere i contratti privati.", + "The stack startup hook was not found": "Il gancio di avvio stack non è stato trovato", + "The stack update was saved.": "L'aggiornamento stack è stato salvato.", + "The startup differs from the declared Nextcloud adapter": "L'avvio differisce dall'adattatore Nextcloud dichiarato", + "The startup differs from the declared adapter": "L'avvio differisce dall'adattatore dichiarato", + "The staticfiles volume needs at least 1 GB": "Il volume dei file statici richiede almeno 1 GB", "The storage has been removed and the disk unmounted.": "La memoria è stata rimossa e il disco smontato.", + "The sysctl content was modified outside the saved record": "Il contenuto di sysctl è stato modificato al di fuori del record salvato", + "The sysctl include is a link:": "Il sysctl include un link:", + "The sysctl include is not a safe host file": "Il sysctl include non è un file host sicuro", + "The sysctl include is not restored over a symbolic link": "Il sysctl include non è ripristinato su un link simbolico", + "The sysctl include is unknown or differs from the saved record": "Il sysctl include è sconosciuto o differisce dal record salvato", + "The temporary password could not be retrieved.": "La password temporanea non poteva essere recuperata.", "The test will continue even if you close this terminal.": "Il test continuerà anche se chiudi questo terminale.", + "The tmpfs mounts of the container differ from the saved record": "I supporti tmpf del contenitore differiscono dal record salvato", + "The tmpfs path or size is outside the supported profile": "Il percorso o la dimensione tmpfs è al di fuori del profilo supportato", + "The translated recipe changed during the preparation": "La ricetta tradotta è cambiata durante la preparazione", + "The value contains an unsupported character": "Il valore contiene un carattere non supportato", + "The values do not match. Enter them again.": "I valori non corrispondono. Inserirli di nuovo.", + "The variable contains control characters:": "La variabile contiene caratteri di controllo:", + "The variable contains line breaks:": "La variabile contiene interruzioni di riga:", "The vfio.conf entries have been removed and initramfs rebuilt.": "le voci vfio.conf sono state rimosse e initramfs è stato ricostruito.", + "The web UI password must have at least 24 characters": "La password web UI deve avere almeno 24 caratteri", + "The web UI user contains characters that are not allowed": "L'utente web UI contiene caratteri che non sono ammessi", + "The web interface is served over plain HTTP on port 51821 (INSECURE=true). Keep it inside the local network or publish it through a reverse proxy with TLS.": "L'interfaccia web è servita su HTTP normale sulla porta 51821 (INSECURE=true). Mantenerlo all'interno della rete locale o pubblicarlo attraverso un proxy inverso con TLS.", + "The web interface uses a self-signed certificate, so the browser shows a warning the first time.": "L'interfaccia web utilizza un certificato autofirmato, quindi il browser mostra un avviso la prima volta.", + "The wizard writes a .conf file in /config. Restart the container afterwards so the bot starts with that configuration.": "Il wizard scrive un file .conf in /config. Riavviare il contenitore in seguito così il bot inizia con quella configurazione.", + "The world's fastest framework for building websites": "Il quadro più veloce del mondo per la costruzione di siti web", + "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server.": "Thelounge (a fork di urlaIRC) è un client web IRC che si ospita sul proprio server.", "Then bind-mount to container": "Quindi associare il montaggio al contenitore", "Then change the VM display to none (vga: none) when the guest is stable.": "Quindi modifica la visualizzazione della VM su none (vga: none) quando il guest è stabile.", "Then change the VM display to none (vga: none) when the system is stable.": "Quindi modificare la visualizzazione della VM su none (vga: none) quando il sistema è stabile.", "Then run this option again:": "Quindi esegui nuovamente questa opzione:", "Then update /etc/fstab on the host with the same options.": "Quindi aggiorna /etc/fstab sull'host con le stesse opzioni.", + "There are extra disks or bind mounts outside the journal; the rootfs is not replaced": "Ci sono dischi extra o supporti di legatura al di fuori della rivista; i rootf non sono sostituiti", + "There is no temporary container of this operation to keep the current disks": "Non c'è un contenitore temporaneo di questa operation per mantenere i dischi attuali", + "There is no verified backup; a modified container is not touched": "Non c'è nessun backup verificato; un contenitore modificato non viene toccato", + "These VMIDs are not free:": "Questi VMID non sono gratuiti:", "These are the changes that will be made": "Queste sono le modifiche che verranno apportate", "These interface configurations will be removed": "Queste configurazioni dell'interfaccia verranno rimosse", "These paths will not be restored live and will be extracted for manual recovery.": "Questi percorsi non verranno ripristinati in tempo reale e verranno estratti per il ripristino manuale.", + "These values are asked during the installation:": "Questi valori vengono richiesti durante l'installazione:", "This CIFS share is mounted with restrictive permissions.": "Questa condivisione CIFS è montata con autorizzazioni restrittive.", "This GPU is considered incompatible with GPU passthrough to a VM in ProxMenux.": "Questa GPU è considerata incompatibile con il passthrough GPU a una VM in ProxMenux.", "This NFS share is fully restricted — even the host root cannot write to it.": "Questa condivisione NFS è completamente limitata: anche l'host root non può scrivervi.", @@ -4477,6 +6151,8 @@ "This backup is encrypted.": "questo backup è crittografato.", "This backup was taken on kernel": "questo backup è stato eseguito sul kernel", "This cleanup will:": "questa pulizia:", + "This container belongs to a stack; publish the whole stack": "Questo contenitore appartiene a uno stack; pubblicare l'intero stack", + "This container belongs to a stack; recover the whole stack": "Questo contenitore appartiene a uno stack; recuperare l'intero stack", "This container does not have apt-get. NFS client installation only supports Debian/Ubuntu containers.": "Questo contenitore non ha apt-get. L'installazione del client NFS supporta solo i contenitori Debian/Ubuntu.", "This container does not have apt-get. Samba client installation only supports Debian/Ubuntu containers.": "Questo contenitore non ha apt-get. L'installazione del client Samba supporta solo i contenitori Debian/Ubuntu.", "This container has no GPU configured. Coral TPU works best alongside hardware video decoding (Quick Sync, VA-API, NVENC) for apps like Frigate.": "Questo contenitore non ha GPU configurata. Coral TPU funziona meglio insieme alla decodifica video hardware (Quick Sync, VA-API, NVENC) per app come Frigate.", @@ -4486,15 +6162,21 @@ "This erases existing metadata.": "Ciò cancella i metadati esistenti.", "This explicitly marks the container as privileged": "Ciò contrassegna esplicitamente il contenitore come privilegiato", "This guarantees that device nodes are available before applying LXC GPU config.": "Ciò garantisce che i nodi del dispositivo siano disponibili prima di applicare la configurazione della GPU LXC.", + "This image cannot be installed as it is described:": "Questa immagine non può essere installata come descritto:", + "This image requires the host module": "Questa immagine requires il modulo host", "This installation will:": "Questa installazione:", "This installer will:": "Questo programma di installazione:", "This interface is configured but doesn't exist physically": "Questa interfaccia è configurata ma non esiste fisicamente", + "This interface runs on the Proxmox node as root. Open proxmenux-oci.sh on the Proxmox host.": "Questa interfaccia funziona sul nodo Proxmox come root. Aprire proxmenux-oci.sh sull'host Proxmox.", "This is IRREVERSIBLE.": "questo è IRREVERSIBILE.", "This is a destructive action": "Questa è un'azione distruttiva", "This is a simple configuration change": "Si tratta di una semplice modifica della configurazione", "This is an external community script maintained by": "questo è uno script di una comunità esterna gestito da", "This is an external script that creates a macOS VM in Proxmox VE in just a few steps, whether you are using AMD or Intel hardware.": "Si tratta di uno script esterno che crea in pochi passaggi una VM macOS in Proxmox VE, sia che utilizzi hardware AMD o Intel.", + "This is not a coordinated stack": "Questo non è uno stack coordinato", + "This is not a valid image reference:": "Questo non è un riferimento di immagine valido:", "This is unexpected since credentials were validated.": "Ciò è inaspettato poiché le credenziali sono state convalidate.", + "This is what ProxMenux understood from the": "Questo è ciò che ProxMenux ha capito dal", "This marks the container as unprivileged": "Ciò contrassegna il contenitore come non privilegiato", "This may be normal for a fresh installation": "Questo potrebbe essere normale per una nuova installazione", "This may take a few minutes. Press OK to proceed.": "l'operazione potrebbe richiedere alcuni minuti. Premere OK per procedere.", @@ -4503,12 +6185,14 @@ "This means Proxmox handles mount lifecycle natively (no manual /etc/fstab needed for NFS/CIFS host storages).": "Ciò significa che Proxmox gestisce il ciclo di vita del montaggio in modo nativo (non è necessario il manuale /etc/fstab per gli archivi host NFS/CIFS).", "This means the credentials are incorrect.": "Ciò significa che le credenziali non sono corrette.", "This might indicate network connectivity issues.": "Ciò potrebbe indicare problemi di connettività di rete.", + "This monitor uses a privileged LXC, shares processes and network with Proxmox and disables AppArmor in the CT. It uses the IP address and firewall of the host. A compromised image could affect the host; do not expose its web UI to the Internet.": "Questo monitor utilizza un LXC privilegiato, condivide i processi e la rete con Proxmox e disabilita AppArmor nella CT. Utilizza l'indirizzo IP e il firewall dell'host. Un'immagine compromessa potrebbe influenzare l'host; non esporre il suo web UI a Internet.", "This operation may take several minutes and requires internet connectivity.": "Questa operazione potrebbe richiedere diversi minuti e richiede la connettività Internet.", "This package was installed by older versions of the ProxMenux Coral installer that placed the M.2 kernel driver on every system, including USB-only setups. It is not needed for Coral USB devices, which use libedgetpu1-std / libedgetpu1-max only.": "questo pacchetto è stato installato dalle versioni precedenti del programma di installazione ProxMenux Coral che posizionava il driver del kernel M.2 su ogni sistema, comprese le configurazioni solo USB.Non è necessario per i dispositivi USB Coral, che utilizzano solo libedgetpu1-std / libedgetpu1-max.", "This passphrase is the ONLY way to access encrypted Borg backups.": "questa passphrase è l'UNICO modo per accedere ai backup Borg crittografati.", "This path is already used as a mount point in this container.": "Questo percorso è già utilizzato come punto di montaggio in questo contenitore.", "This path is not a registered mount point. Use it anyway?": "Questo percorso non è un punto di montaggio registrato. Usarlo comunque?", "This process changes file ownership inside the container": "Questo processo modifica la proprietà del file all'interno del contenitore", + "This profile only supports directory bind mounts": "Questo profilo supporta solo i supporti delle directory", "This release channel is already active.": "Questo canale di rilascio è già attivo.", "This removes the 'unprivileged: 1' line from the config": "Ciò rimuove la riga \"non privilegiata: 1\" dal file config", "This removes the storage from Proxmox. The iSCSI target is not affected.": "Ciò rimuove lo spazio di archiviazione da Proxmox. La destinazione iSCSI non è interessata.", @@ -4522,10 +6206,15 @@ "This session is running in the Monitor terminal. Running it from here would cut the connection mid-install and leave the switch in a broken state.": "questa sessione è in esecuzione nel terminale Monitor. Eseguirlo da qui interromperebbe la connessione a metà installazione e lascerebbe l'interruttore in uno stato interrotto.", "This session is running in the Monitor terminal. Updating from here would restart the Monitor service and cut the connection mid-install, leaving the update in a broken state.": "questa sessione è in esecuzione nel terminale Monitor. L'aggiornamento da qui riavvierebbe il servizio Monitor e interromperebbe la connessione durante l'installazione, lasciando l'aggiornamento in uno stato interrotto.", "This shows the storage type and disk identifier": "Mostra il tipo di archiviazione e l'identificatore del disco", + "This stack requires replaying specific rootfs adaptations. Coordinated updates are not yet enabled for it.": "Questo stack requires rigioca specifici adattamenti rootfs. Gli aggiornamenti coordinati non sono ancora abilitati per esso.", "This state has a high probability of VM startup/reset failures.": "Questo stato ha un'alta probabilità di errori di avvio/reimpostazione della VM.", "This state indicates a high risk of passthrough failure due to": "Questo stato indica un rischio elevato di errore passthrough dovuto a", + "This template requests the host PID namespace, which has no validated safe LXC translation yet": "Questo modello richiede il namespace PID host, che non ha ancora validato la traduzione sicura LXC", "This tool is designed for systems with AMD GPUs.": "Questo strumento è progettato per sistemi con GPU AMD.", "This tool is designed for systems with Intel GPUs.": "Questo strumento è progettato per sistemi con GPU Intel.", + "This translator only supports the Nextcloud stack": "Questo traduttore supporta solo Nextcloud stack", + "This value is required.": "Questo valore è required.", + "This variant requires the device": "Questa variante requires il dispositivo", "This version does not build against the running kernel.": "questa versione non si basa sul kernel in esecuzione.", "This will RESET the ProxMenux Monitor login credentials on this host:": "Ciò RIPRISTINERÀ le credenziali di accesso di ProxMenux Monitor su questo host:", "This will add the mount to /etc/fstab so it persists after reboot.": "Questo aggiungerà il montaggio a /etc/fstab in modo che persista dopo il riavvio.", @@ -4547,13 +6236,17 @@ "This will restart the network service and may cause a brief disconnection. Continue?": "Ciò riavvierà il servizio di rete e potrebbe causare una breve disconnessione. Continuare?", "This will take time. Answer prompts carefully - see notes below.": "Ci vorrà del tempo. Rispondi attentamente alle richieste: vedi le note di seguito.", "This will upgrade this node to Proxmox VE 9 on Debian Trixie.": "Ciò aggiornerà questo nodo a Proxmox VE 9 su Debian Trixie.", + "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client.": "Thunderbird è un gestore di informazioni personali gratuito e open source utilizzato principalmente come client di posta elettronica con un calendario e una cartella di contatti, nonché un lettore di feed RSS, client di chat e client di notizie.", "Tick the paths to include in this backup. Press \"Add custom path\" to add a folder or file of your own to the list.": "Spunta i percorsi da includere in questo backup. Premi \"Aggiungi percorso personalizzato\" per aggiungere una cartella o un file all'elenco.", "Tick the paths to remove (they will not be deleted from disk — only from this list):": "Seleziona i percorsi da rimuovere (non verranno eliminati dal disco, solo da questo elenco):", + "Time is up; Home Assistant OS could not be confirmed as running": "Tempo scaduto; Home Assistant OS non poteva essere confermato come in esecuzione", "Time settings configured - Timezone:": "Impostazioni dell'ora configurate - Fuso orario:", "Time synchronization reset to UTC": "La sincronizzazione dell'ora è stata reimpostata su UTC", + "Timezone": "Tempo", "Tip: Also mount the VirtIO ISO for drivers and guest agent installer": "Suggerimento: montare anche l'ISO VirtIO per i driver e il programma di installazione dell'agente guest", "Tip: You can install the QEMU Guest Agent inside the VM with:": "Suggerimento: puoi installare QEMU Guest Agent all'interno della VM con:", "Tip: zfs set acltype=posixacl xattr=sa / enables full ACL support.": "Suggerimento: zfs set acltype=posixacl xattr=sa / abilita il supporto ACL completo.", + "Tmpfs size in MiB for": "Tmpfs misura in MiB per", "To allow LXC write access, change the NFS export on the server to include:": "Per consentire l'accesso in scrittura LXC, modificare l'esportazione NFS sul server per includere:", "To apply it to the current shell now, run:": "Per applicarlo ora alla sessione shell corrente, esegui:", "To assign VFs to VMs or LXCs, edit the configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Per assegnare VF a VM o LXC, modificare manualmente la configurazione tramite l'interfaccia web Proxmox. La Funzione Fisica resterà vincolata al pilota nativo.", @@ -4568,6 +6261,7 @@ "To pass SR-IOV Virtual Functions to a container, edit the LXC configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Per passare le funzioni virtuali SR-IOV a un contenitore, modificare manualmente la configurazione LXC tramite l'interfaccia web Proxmox. La Funzione Fisica resterà vincolata al pilota nativo.", "To remove partial VM:": "Per rimuovere la VM parziale:", "To restore": "Per ripristinare", + "To restore it on another host, keep this file (not included in the vzdump backup):": "Per ripristinarlo su un altro host, tenere questo file (non incluso nel backup vzdump):", "To revert changes:": "Per annullare le modifiche:", "To start the VM:": "Per avviare la VM:", "To stop:": "Per interrompere:", @@ -4579,12 +6273,17 @@ "To use this share from an LXC, bind-mount it via:": "Per utilizzare questa condivisione da un LXC, esegui il bind-mount tramite:", "Tool exit code:": "Codice di uscita dello strumento:", "Tool output:": "Uscita dello strumento:", + "Tools": "Strumenti", "Top memory processes in CT": "Principali processi di memoria in CT", + "Top-level configs, secrets and other global options are not yet supported": "Le configurazioni di livello superiore, i segreti e altre opzioni globali non sono ancora supportate", + "Top-level volume options are not yet supported": "Le opzioni di volume di primo livello non sono ancora supportate", "Total": "Totale", "Total members:": "Membri totali:", "Total routes": "Percorsi totali", "Total size:": "Dimensione totale:", + "Transaction log:": "Registro delle transazioni:", "Translation files:": "File di traduzione:", + "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, µTP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more.": "Transmission è progettato per un uso facile e potente. Transmission ha le caratteristiche che si desidera da un client BitTorrent: crittografia, un'interfaccia web, scambio peer, collegamenti magneti, DHT, μTP, UPnP e porta NAT-PMP in avanti, supporto webseed, directory di orologi, tracker editing, limiti di velocità globali e per-torrent, e altro ancora.", "Tried pvesm path and manual detection methods": "Ho provato il percorso pvesm e i metodi di rilevamento manuale", "Trust this certificate and save it for scheduled backups?": "considerare attendibile questo certificato e salvarlo per i backup pianificati?", "Try Again": "Riprova", @@ -4592,6 +6291,8 @@ "Try accessing": "Prova ad accedere", "Try another archive": "Prova un altro archivio", "Try automatic repair of detected issues": "Prova la riparazione automatica dei problemi rilevati", + "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources.": "Tvheadend funziona come server proxy: è un server di streaming TV e registratore per Linux, FreeBSD e Android che supporta DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP e HDHomeRun come sorgenti di ingresso.", + "Twingate Connector for self-hosted server": "Connettore Twingate per server self-hosting", "Two-factor authentication and backup codes will be removed.": "L'autenticazione a due fattori e i codici di backup verranno rimossi.", "Type": "Tipo", "Type the device path EXACTLY to confirm formatting:": "Digitare ESATTAMENTE il percorso del dispositivo per confermare la formattazione:", @@ -4600,16 +6301,22 @@ "Type: attached to PVE storage": "Tipo: allegato allo storage PVE", "Typed value does not match selected disk. Operation cancelled.": "Il valore digitato non corrisponde al disco selezionato. Operazione annullata.", "UID in CT": "UID nel CT", + "UID of the plex user (also owner of the GPU device)": "UID dell'utente plex (anche proprietario del dispositivo GPU)", + "UID that Emby runs as": "UID che Emby funziona come", "UPGRADE PROMPTS - RECOMMENDED ANSWERS:": "RICHIESTE DI AGGIORNAMENTO - RISPOSTE CONSIGLIATE:", + "UPS monitoring and power outage notification system": "Sistema di notifica UPS di monitoraggio e di interruzione di corrente", "USB Accelerators:": "Acceleratori USB:", + "USB bus directory": "directory bus USB", "USB disk target": "destinazione del disco USB", "USB drives mounted now:": "unità USB montate ora:", "USB libedgetpu1": "USB libedgetpu1", "UUP Dump script not found.": "Script UUP Dump non trovato.", "UUp Dump ISO creator Custom": "UUp Dump Creatore ISO Personalizzato", + "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer.": "Ubooquity è un home server gratuito, leggero e facile da usare per i tuoi fumetti ed ebook. Utilizzare per accedere ai file da qualsiasi luogo, con un tablet, un e-reader, un telefono o un computer.", "Udev rules for Coral USB devices added and rules reloaded.": "Aggiunte regole Udev per i dispositivi USB Coral e ricaricate.", "Udev rules for Coral USB devices already exist.": "Esistono già regole Udev per i dispositivi USB Coral.", "Udev rules for Coral USB devices appended and rules reloaded.": "Aggiunte regole Udev per i dispositivi USB Coral e ricaricate.", + "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results.": "UltiMaker Cura è un software di stampa 3D gratuito e facile da usare affidabile da milioni di utenti. Affina il tuo modello 3D con 400+ impostazioni per i migliori risultati di stampa e stampa.", "Umbrel OS installer script by Helper Scripts\n\nVisit the GitHub repo to learn more, contribute, or support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm": "Script di installazione del sistema operativo Umbrel di Helper Scripts\n\nVisita il repository GitHub per saperne di più, contribuire o supportare il progetto:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm", "Unable to detect Proxmox version": "impossibile rilevare la versione di Proxmox", "Unable to detect Proxmox version.": "Impossibile rilevare la versione di Proxmox.", @@ -4618,6 +6325,10 @@ "Unable to resolve system ZFS pool disks. Aborting.": "Messaggio tecnico per Proxmox e IT.Traduzione: impossibile risolvere i dischi del pool di sistema ZFS.Interruzione.", "Unable to resolve system disk topology. Aborting.": "impossibile risolvere la topologia del disco di sistema. Interruzione.", "Understand the security implications of privileged containers": "Comprendere le implicazioni sulla sicurezza dei contenitori privilegiati", + "Unexpected Proxmox inventory; recovery blocked": "inventario Proxmox inaspettato; bloccato di recupero", + "Unexpected formatting directory in the new Valkey volume": "directory di formattazione inaspettata nel nuovo volume Valkey", + "Ungoogled Chromium is Google Chromium, sans dependency on Google web services.": "Ungoogled Chromium è Google Chromium, sans dipendenza dai servizi web di Google.", + "Unified LLM Fine-Tuning with 100+ Models": "Fine-Tuning LLM unificato con 100+ Modelli", "Uninstall Coral drivers and configuration": "Disinstallare i driver e la configurazione Coral", "Uninstall Fail2Ban": "Disinstallare Fail2Ban", "Uninstall Lynis": "Disinstallare Lynis", @@ -4647,6 +6358,10 @@ "Unknown CPU type. IOMMU might not be properly enabled.": "Tipo di CPU sconosciuto. IOMMU potrebbe non essere abilitato correttamente.", "Unknown CPU vendor. Cannot determine IOMMU parameter.": "Fornitore di CPU sconosciuto. Impossibile determinare il parametro IOMMU.", "Unknown GPU": "GPU sconosciuta", + "Unknown adapter role": "ruolo dell'adattatore sconosciuto", + "Unknown credential service:": "Servizio credential sconosciuto:", + "Unknown dependency:": "Dipendenza sconosciuta:", + "Unknown host monitor": "Monitor host sconosciuto", "Unknown model": "Modello sconosciuto", "Unknown size": "Dimensioni sconosciute", "Unknown storage controller": "Controller di archiviazione sconosciuto", @@ -4662,6 +6377,10 @@ "Unmounted:": "Non montato:", "Unmounting": "Smontaggio", "Unmounting disk...": "Smontaggio disco...", + "Unpackerr configured": "Unpackerr configurato", + "Unpackerr has no web interface and extracts nothing until it is pointed at a Starr application. Uncomment the [sonarr.0] or [radarr.0] section in /config/unpackerr.conf inside the container, set its url and api_key, then restart the container.": "Unpackerr non ha interfaccia web e non estrae nulla fino a quando non è indicato in un'applicazione Starr. Scomporre la sezione [sonarr.0] o [radarr.0] in /config/unpackerr.conf all'interno del contenitore, impostare la sua URL e api key, quindi riavviare il contenitore.", + "Unpackerr requires Sonarr, Radarr or Lidarr in this suite": "Unpackerr requires Sonarr, Radarr o Lidarr in questa suite", + "Unpackerr stopped during its first start": "Unpackerr si è fermato durante il suo primo inizio", "Unprivileged": "Senza privilegi", "Unprivileged Container Access": "Accesso al contenitore non privilegiato", "Unprivileged container": "Contenitore non privilegiato", @@ -4670,15 +6389,73 @@ "Unprivileged containers map their UIDs to high host UIDs (e.g. 100000+), which appear as 'others' on the host filesystem.": "I contenitori non privilegiati mappano i loro UID su UID host elevati (ad esempio 100000+), che appaiono come \"altri\" sul filesystem host.", "Unprivileged: Limited access (more secure)": "Non privilegiato: accesso limitato (più sicuro)", "Unreachable": "Irraggiungibile", + "Unrecognized Immich adapter": "Adattatore Immich non riconosciuto", + "Unrecognized adaptation format": "Formato di adattamento non riconosciuto", + "Unrecognized adaptation recipe": "Ricetta di adattamento non riconosciuta", + "Unrecognized dependency order of the stack:": "Ordine di dipendenza non riconosciuto dello stack:", + "Unrecognized host monitor profile": "Profilo del monitor host non riconosciuto", + "Unrecognized native configuration": "Configurazione nativa non riconosciuta", + "Unrecognized qBittorrent configuration format": "Formato di configurazione qBittorrent non riconosciuto", + "Unrecognized stack adapter or role": "Adattatore di stack non riconosciuto o ruolo", + "Unrecognized stack adapter:": "Adattatore di pila non riconosciuto:", + "Unrecognized stack structure:": "Struttura impilabile non riconosciuta:", + "Unrecognized volume definition": "Definizione del volume non riconosciuta", + "Unresolved variable:": "Variazione non risolta:", + "Unsafe OCI archive path": "percorso di archivio OCI", + "Unsafe dependency contract": "Contratto di dipendenza non sicuro", + "Unsafe dependency hook contract": "Contratto di gancio di dipendenza non sicuro", + "Unsafe instance directory": "Directory delle istanze pericolose", + "Unsafe instance record": "Registrazione delle istanze pericolose", + "Unsafe journal or lock file": "Diario non sicuro o file di blocco", + "Unsafe private configuration path": "Percorso di configurazione privata", + "Unsafe qBittorrent configuration path": "percorso di configurazione qBittorrent non sicuro", + "Unsafe record": "Registrazione non sicura", + "Unsafe registry directory": "Directory di registro non sicura", + "Unsafe registry lock": "Blocco del registro non sicuro", + "Unsafe rootfs for the capture": "Radici non sicuri per la cattura", + "Unsafe stack assembly": "Montaggio a pila non sicuro", + "Unsafe volume path": "Percorso di volume non sicuro", + "Unsupported CPU allocation mode:": "Modalità di allocazione CPU non supportata:", + "Unsupported GID strategy:": "Strategia GID non supportata:", + "Unsupported NVIDIA mode:": "Modalità NVIDIA non supportata:", + "Unsupported OCI digest:": "Non supportato OCI digest:", + "Unsupported OCI-LXC AppArmor profile:": "Profilo OCI-LXC AppArmor non supportato:", + "Unsupported OCI-LXC seccomp profile:": "Profilo OCI-LXC seccomp non supportato:", "Unsupported Terminal": "Terminale non supportato", + "Unsupported architecture:": "Architettura non supportata:", + "Unsupported backup compression": "compressione di backup non supportata", + "Unsupported credential pattern:": "Modello credential non supportato:", + "Unsupported declarative ostype:": "Ostipo dichiarativo non supportato:", + "Unsupported device GID strategy": "Strategia GID del dispositivo non supportata", + "Unsupported device type:": "Tipo di dispositivo non supportato:", + "Unsupported dynamic NVIDIA capabilities:": "Capacità NVIDIA dinamiche non supportate:", "Unsupported format. Only .ova and .ovf files are supported.": "Formato non supportato. Sono supportati solo i file .ova e .ovf.", + "Unsupported media storage mode:": "Modalità di memorizzazione multimediale non supportato:", + "Unsupported mount type": "Tipo di montaggio non supportato", + "Unsupported mount type:": "Tipo di montaggio non supportato:", + "Unsupported native device type:": "Tipo di dispositivo nativo non supportato:", + "Unsupported operation": "operation non supportato", "Unsupported output format:": "Formato di output non supportato:", + "Unsupported post-start configuration:": "Configurazione post-start non supportata:", + "Unsupported pre-start check:": "Controllo pre-start non supportato:", + "Unsupported pre-start repair:": "Riparazione pre-start non supportata:", + "Unsupported prlimit resource": "Risorse prilimite non supportate", + "Unsupported secret generator:": "Generatore segreto non supportato:", + "Unsupported storage mode:": "Modalità di archiviazione non supportata:", + "Unsupported tmpfs options": "Opzioni tmpfs non supportate", + "Unsupported volume options:": "Opzioni di volume non supportate:", + "Untrusted or modified NVIDIA hook": "gancio NVIDIA non fidato o modificato", + "Unused image removed from the cache:": "Immagine non utilizzata rimossa dalla cache:", + "Unused images removed from the cache:": "Immagini non utilizzate rimosse dalla cache:", + "Update": "Aggiornamento", "Update Available": "aggiornamento disponibile", "Update Ceph repository (Only if using Ceph):": "Aggiorna repository Ceph (solo se si utilizza Ceph):", "Update Debian repositories to Trixie:": "Aggiorna i repository Debian a Trixie:", "Update Export": "Aggiorna esportazione", "Update Lynis to latest version": "Aggiorna Lynis all'ultima versione", "Update NVIDIA in LXC Containers": "Aggiorna NVIDIA nei contenitori LXC", + "Update OCI": "Aggiornamento OCI", + "Update OCI stack": "Aggiornare lo stack OCI", "Update PVE enterprise repository (Only if using enterprise):": "Aggiorna repository aziendale PVE (solo se si utilizza enterprise):", "Update Proxmox VE Appliance Manager": "Aggiorna Proxmox VE Appliance Manager", "Update Proxmox package lists": "Aggiorna gli elenchi dei pacchetti Proxmox", @@ -4687,15 +6464,26 @@ "Update and upgrade all system packages": "Aggiorna e aggiorna tutti i pacchetti di sistema", "Update and upgrade system": "aggiornamento e aggiornamento del sistema", "Update cancelled by user": "Aggiornamento annullato dall'utente", + "Update completed. Data kept.": "Aggiornamento completato. Dati conservati.", "Update completed. Press Enter to continue...": "Aggiornamento completato. Premi Invio per continuare...", + "Update every container of the application": "Aggiorna ogni contenitore dell'applicazione", "Update kernel to compatible version": "Aggiorna il kernel alla versione compatibile", + "Update now?": "Aggiornamento?", "Update package index:": "Aggiorna l'indice del pacchetto:", + "Update prepared": "Aggiornamento preparato", "Update system to latest PVE 8.4+ (if not done already):": "Aggiorna il sistema all'ultimo PVE 8.4+ (se non lo hai già fatto):", + "Update the image with the saved configuration": "Aggiornare l'immagine con la configurazione salvata", + "Update the whole stack?": "Aggiornare l'intero stack?", "Updated": "Aggiornato", "Updated sharedfiles group to GID: 101000": "Gruppo sharedfiles aggiornato a GID: 101000", + "Updated stack checked": "Aggiornato stack controllato", + "Updated:": "Aggiornato:", "Updates all Proxmox and Debian packages": "Aggiorna tutti i pacchetti Proxmox e Debian", "Updates and Packages Commands": "Comandi per aggiornamenti e pacchetti", + "Updates are not available yet for this application in this beta": "Gli aggiornamenti non sono ancora disponibili per questa applicazione in questa beta", + "Updates are not available yet in this beta for applications that use a privileged container or advanced LXC settings": "Gli aggiornamenti non sono ancora disponibili in questa beta per applicazioni che utilizzano un contenitore privilegiato o impostazioni LXC avanzate", "Updates file is empty or unreadable.": "Il file degli aggiornamenti è vuoto o illeggibile.", + "Updating": "Aggiornamento", "Updating APT package lists...": "Aggiornamento degli elenchi di pacchetti APT in corso...", "Updating Debian Bookworm → Trixie in sources.list...": "Aggiornamento di Debian Bookworm → Trixie nel file source.list...", "Updating Figurine binary...": "Aggiornamento del binario Figurine in corso...", @@ -4727,6 +6515,7 @@ "Upload to PBS is currently: yes. Pick an action:": "Il caricamento su PBS è attualmente: sì. Scegli un'azione:", "Upload to PBS: enable, disable or rotate the recovery passphrase": "Carica su PBS: abilita, disabilita o ruota la passphrase di ripristino", "Uptime and who is logged in": "Uptime e chi ha effettuato l'accesso", + "Usage:": "Utilizzo:", "Use \"Check test progress\" to see results.": "Utilizza \"Controlla l'avanzamento del test\" per visualizzare i risultati.", "Use 'Export to file' to save it and inspect manually.": "Utilizza \"Esporta su file\" per salvarlo e controllarlo manualmente.", "Use 'pct restore' / 'qmrestore' to recover their disks from your VM backups.": "Utilizza 'pct Restore' / 'qmrestore' per ripristinare i loro dischi dai backup della tua VM.", @@ -4769,6 +6558,12 @@ "User activity and uptime": "Attività dell'utente e tempo di attività", "User chose not to remove NetworkManager": "L'utente ha scelto di non rimuovere NetworkManager", "User chose to exit for manual backup creation.": "L'utente ha scelto di uscire per la creazione manuale del backup.", + "User name for the SSH login": "Nome utente per il login SSH", + "User name of the administrator of the web interface": "Nome utente dell'amministratore dell'interfaccia web", + "User name of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Nome utente del login di applicazione Flowise deprecato (solo letto da versioni Flowise prima di 3.0.1)", + "User of the AdGuard Home that receives the settings": "Utente del AdGuard Home che riceve le impostazioni", + "User of the main AdGuard Home": "Utente del principale AdGuard Home", + "User-friendly WebUI for LLMs (Formerly Ollama WebUI)": "WebUI facile da usare per LLM (ex Ollama WebUI)", "Username": "Nome utente", "Username (e.g. root@pam or user@pbs!token):": "Nome utente (ad esempio root@pam o utente@pbs!token):", "Username and password": "Nome utente e password", @@ -4782,6 +6577,8 @@ "Using advanced configuration": "Utilizzando la configurazione avanzata", "Using default Proxmox logo...": "Utilizzo del logo Proxmox predefinito...", "Using existing encryption key:": "Utilizzando la chiave di crittografia esistente:", + "Using the image verified by the transaction": "Utilizzo dell'immagine verificata dalla transazione", + "Using the verified image from the cache": "Utilizzo dell'immagine verificata dalla cache", "Utilities": "Utilità", "Utilities Installation Menu": "Menu di installazione delle utilità", "Utilities Menu": "Menù Utilità", @@ -4789,6 +6586,9 @@ "Utilities and Tools": "Utilità e strumenti", "Utilities installation completed": "Installazione delle utilità completata", "Utilities installed by ProxMenux have been removed": "le utilità installate da ProxMenux sono state rimosse", + "VA-API driver": "Driver VA-API", + "VA-API render device": "Dispositivo di rendering VA-API", + "VA-API video acceleration": "Accelerazione video VA-API", "VFIO device IDs removed from /etc/modprobe.d/vfio.conf": "ID dispositivo VFIO rimossi da /etc/modprobe.d/vfio.conf", "VFIO modules configured in /etc/modules": "Moduli VFIO configurati in /etc/modules", "VFIO modules configured.": "Moduli VFIO configurati.", @@ -4796,7 +6596,9 @@ "VFIO modules removed from /etc/modules": "Moduli VFIO rimossi da /etc/modules", "VFIO orphans cleared and initramfs rebuilt — next boot will free the GPU.": "gli orfani VFIO sono stati cancellati e initramfs ricostruito: il prossimo avvio libererà la GPU.", "VFIO orphans cleared but initramfs rebuild failed; check /var/log/proxmenux logs.": "gli orfani VFIO sono stati cancellati ma la ricostruzione di initramfs non è riuscita;controlla i log /var/log/proxmenux.", + "VFS cache mode": "Modalità cache VFS", "VLAN": "VLAN", + "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices.": "Media VLC Il giocatore è un lettore multimediale multipiattaforma gratuito e open source che offre prestazioni affidabili su più dispositivi.", "VM": "VM", "VM Conflict Policy": "Politica sui conflitti delle VM", "VM ID": "ID della macchina virtuale", @@ -4824,17 +6626,28 @@ "VM started": "La VM è stata avviata", "VM stopped": "La macchina virtuale si è arrestata", "VM:": "MV:", + "VMID (empty = next free)": "VMID (vuoto = prossimo libero)", "VMID in use": "VMID in uso", "VMID must be a number.": "VMID deve essere un numero.", "VMID of the Borg server LXC on": "VMID del server Borg LXC attivo", + "VMID of the Rclone OCI container": "VMID del contenitore Rclone OCI", "VMs to destroy:": "VM da distruggere:", "VMs, LXCs, network, /etc/pve, users, cron, packages, drivers, ProxMenux state, etc.": "VM, LXC, rete, /etc/pve, utenti, cron, pacchetti, driver, stato ProxMenux, ecc.", + "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server.": "VS Code è un ambiente di sviluppo integrato sviluppato da Microsoft. Questo contenitore esegue l'applicazione desktop completa, per una versione web nativo vedere Code Server.", + "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft’s editor VS Code.": "VSCodium è una distribuzione binaria basata sulla comunità, liberamente licenza del codice VS redattore di Microsoft.", "Valid backups for all VMs/CTs": "Backup validi per tutte le VM/CT", "Validating Proxmox 9 repositories (checking 'proxmox-ve' candidate)...": "Convalida dei repository Proxmox 9 (controllo del candidato \"proxmox-ve\")...", "Validating credentials with server": "Convalida delle credenziali con il server", "Validating disk safety...": "Convalida della sicurezza del disco in corso...", + "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)": "Metodo di convalida: http (port 80 inoltrato) o dns (DNS provider plugin)", + "Value for": "Valore per", + "Variable name": "Nome variabile", + "Variables": "Variabili", + "Variables the installation asks for:": "Variabili l'installazione richiede:", "Verbose pool status": "Stato del pool dettagliato", "Verification": "Verifica", + "Verified": "Verificato", + "Verified by ProxMenux": "Verificato da ProxMenux", "Verify IOMMU group for PCI device": "Verificare il gruppo IOMMU per il dispositivo PCI", "Verify Options > OS Type — currently set to:": "Verifica opzioni > Tipo sistema operativo: attualmente impostato su:", "Verify PVE version (must be 8.4.1 or newer):": "Verifica la versione PVE (deve essere 8.4.1 o successiva):", @@ -4850,12 +6663,16 @@ "Verifying Ceph packages availability...": "Verifica della disponibilità dei pacchetti Ceph in corso...", "Verifying all utilities status": "Verifica dello stato di tutte le utenze", "Verifying disk accessibility in CT": "Verifica dell'accessibilità del disco in CT", + "Verifying the backups...": "Verificare i backup...", + "Verifying the image integrity...": "Verifica dell'integrità dell'immagine...", "Version": "Versione", "Version Change Detected": "Rilevata modifica della versione", "Version info not available": "Informazioni sulla versione non disponibili", "Version:": "Versione:", "Version: Auto-negotiation (NFSv3/NFSv4)": "Versione: negoziazione automatica (NFSv3/NFSv4)", "Versions shown belong to maintained NVIDIA branches that list your GPU PCI ID and are new enough to build against the running kernel. DKMS compilation is the final validation. The recommended version keeps the current branch, or uses the NVIDIA Production Branch on a fresh install.": "le versioni mostrate appartengono ai rami NVIDIA mantenuti che elencano l'ID PCI della GPU e sono sufficientemente nuove per essere costruite con il kernel in esecuzione. La compilazione DKMS è la convalida finale. La versione consigliata mantiene il ramo corrente o utilizza NVIDIA Production Branch in una nuova installazione.", + "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML.": "L'accelerazione video e il rilevamento degli oggetti sono scelte indipendenti; l'installatore non scrive fotocamera o rilevatore YAML.", + "Video transcoding acceleration": "Accelerazione di transcodifica video", "View CIFS Mounts (pvesm + fstab)": "Visualizza montaggi CIFS (pvesm + fstab)", "View Current Exports": "Visualizza le esportazioni correnti", "View Current Mounts": "Visualizza i supporti attuali", @@ -4871,6 +6688,7 @@ "View raw VM configuration file": "Visualizza il file di configurazione della VM non elaborato", "View restore plan": "Visualizza il piano di ripristino", "View self-test log": "Visualizza il registro dell'autotest", + "View status": "Visualizza stato", "VirtIO (advanced - high performance)": "VirtIO (avanzato - alte prestazioni)", "VirtIO ISO not found after selection.": "ISO VirtIO non trovato dopo la selezione.", "VirtIO ISO selection cancelled.": "Selezione ISO VirtIO annullata.", @@ -4886,10 +6704,19 @@ "Virtual display normalized to vga: std (compatibility)": "Display virtuale normalizzato su VGA: std (compatibilità)", "Virtual display set to": "Display virtuale impostato su", "Virtual interface (normal)": "Interfaccia virtuale (normale)", + "Virtual whiteboard for sketching hand-drawn like diagrams": "Lavagna virtuale per schizzare a mano come diagrammi", "Virtualization": "virtualizzazione", "Visit https://osx-proxmox.com for more information.": "Visita https://osx-proxmox.com per ulteriori informazioni.", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:": "Visita il sito web per scoprire altri script, rimanere aggiornato con gli ultimi aggiornamenti e supportare il progetto:", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE": "Visita il sito web per scoprire altri script, rimanere aggiornato con gli ultimi aggiornamenti e supportare il progetto:\n\nhttps://community-scripts.github.io/ProxmoxVE", + "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies.": "Vivaldi è un freeware norvegese, browser web cross-platform con un client di posta elettronica integrato sviluppato da Vivaldi Technologies.", + "Volume configuration cancelled": "Cancellazione della configurazione del volume", + "Volume options are not yet supported": "Le opzioni di volume non sono ancora supportate", + "Volume size in GB": "Dimensione del volume in GB", + "Volumes attached": "Volume allegato", + "Volumes prepared for the first start:": "Volumes preparato per il primo inizio:", + "Volumes shared between services are not yet supported": "I volumi condivisi tra i servizi non sono ancora supportati", + "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code.": "Vscodium-web è una distribuzione binaria guidata da comunità, liberamente licenza del componente web host remoto del codice VS dell'editor di Microsoft.", "Vulnerability detection": "Rilevamento delle vulnerabilità", "WARNING": "AVVERTIMENTO", "WARNING — This backup contains paths that are risky to restore on a running system:": "ATTENZIONE: questo backup contiene percorsi rischiosi da ripristinare su un sistema in esecuzione:", @@ -4912,15 +6739,39 @@ "WARNING: You are about to remove this Proxmox storage:": "ATTENZIONE: stai per rimuovere questo spazio di archiviazione Proxmox:", "WARNING: You are about to remove this disk mount:": "ATTENZIONE: stai per rimuovere questo montaggio del disco:", "WARNING: this will ERASE EVERYTHING on the disk.": "ATTENZIONE: questo CANCELLERA' TUTTO il disco.", + "WEB UI to manage WireGuard VPN.": "WEB UI per gestire WireGuard VPN.", "WILL BE PERMANENTLY ERASED.": "VERRÀ CANCELLATO PERMANENTEMENTE.", + "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency.": "WPS Office è una suite da ufficio completa leggera e ricca di funzionalità con alta compatibilità. Come pratico e professionale software per ufficio, WPS Office consente di modificare i file in Writer, Presentation, Spreadsheet e PDF per migliorare l'efficienza del lavoro.", "Wait for each node to complete before starting next": "Attendi il completamento di ciascun nodo prima di iniziare il successivo", + "Waiting for Home Assistant OS...": "In attesa di Home Assistant OS...", + "Waiting for the FUSE mount:": "In attesa del montaggio FUSE:", + "Waiting for the application to respond...": "In attesa che la domanda risponda...", + "Waiting for the initial Jellyfin configuration...": "In attesa della configurazione iniziale Jellyfin...", + "Waiting for the network address...": "In attesa dell'indirizzo di rete...", + "Waiting for the password of the application...": "In attesa della password dell'applicazione...", + "Waiting for the temporary password...": "Attendere la password temporanea...", "Warning": "Avvertimento", "Warning: Auth key should start with 'tskey-'": "Avviso: la chiave di autenticazione deve iniziare con \"tskey-\"", "Warning: Disk Images on CIFS": "Avvertenza: immagini disco su CIFS", "Warning: Limited PCI Reset Support": "Avvertenza: supporto limitato per il ripristino PCI", "Warning: both VMs have autostart enabled (onboot=1).": "Attenzione: entrambe le VM hanno l'avvio automatico abilitato (onboot=1).", "Warnings": "Avvertenze", + "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents.": "WeKnora è una struttura alimentata a LLM progettata per la comprensione profonda dei documenti e il recupero semantico, in particolare per la gestione dei documenti complex, eterogenei.", + "Web UI": "Web UI", + "Web UI 1": "Web UI 1", + "Web UI 2": "Web UI 2", + "Web UI user": "Web UI utente", + "Web access": "Accesso al Web", + "Web address of the AdGuard Home that receives the settings (e.g. http://192.168.1.3)": "Indirizzo Web del AdGuard Home che riceve le impostazioni (ad esempio http://192.168.1.3)", + "Web address of the main AdGuard Home, whose settings are copied (e.g. http://192.168.1.2)": "Indirizzo web del principale AdGuard Home, le cui impostazioni sono copiate (ad esempio http://192.168.1.2)", + "Web interface to manage devices running Tasmota firmware.": "Interfaccia web per gestire i dispositivi che eseguono il firmware Tasmota.", + "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes).": "WebCord può essere riassunto come un pacchetto di indurzioni di sicurezza e privacy, Discord caratteristiche reimplement, Electron / Chromium / Discord bugs workarounds, stylesheets, pagine interne e avvolto https://discord.com pagina, progettato per conformarsi con ToS quanto è possibile (o nascondere le modifiche che potrebbero violarlo dagli occhi di Discord).", + "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels.": "Webgrabplus è un manubrio multi-sito incrementale xmltv epg. Raccoglie i dati della guida tv-programma da siti di guida selezionati per i tuoi canali preferiti.", + "Webservers & Proxies": "Webservers & Proxies", "Website": "Sito web", + "Webstation is a web native emulation focused LXQt desktop based on Ubuntu.": "Webstation è un desktop LXQt basato su Ubuntu.", + "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser.": "Webtop - contenitori Alpine, Ubuntu, Fedora e Arch, contenenti ambienti desktop completi in gusti ufficialmente supportati accessibili tramite qualsiasi browser web moderno.", + "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent.": "Weixin (WeChat) è un'applicazione di messaggistica istantanea, social media e pagamento mobile sviluppata da Tencent.", "What do you want to do?": "Cosa vuoi fare?", "What would you like to do?": "Cosa ti piacerebbe fare?", "When asked to select a disk, click Load Driver and load the VirtIO drivers.": "Quando viene richiesto di selezionare un disco, fare clic su Carica driver e caricare i driver VirtIO.", @@ -4932,28 +6783,46 @@ "Where do you want to mount the Samba share?": "Dove vuoi montare la condivisione Samba?", "Where is the OVA/OVF file located?": "Dove si trova il file OVA/OVF?", "Where to mount inside container?": "Dove montare all'interno del contenitore?", + "Where to store": "Dove conservare", "While the server allows guest listing, no shares are actually accessible without authentication.": "Sebbene il server consenta l'elenco degli ospiti, nessuna condivisione è effettivamente accessibile senza autenticazione.", + "Wikijs A modern, lightweight and powerful wiki app built on NodeJS.": "Wikijs Una moderna, leggera e potente applicazione wiki costruita su NodeJS.", "Will be configured now": "Verrà configurato ora", "Windows Installation Options": "Opzioni di installazione di Windows", "Windows path:": "Percorso di Windows:", + "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles.": "WineGUI è un Wine manager di interfaccia utente che fornisce un frontend grafico per la creazione e la gestione di bottiglie di vino.", "Wipe all — erase partitions + metadata": "Cancella tutto: cancella partizioni + metadati", "Wipe all — remove partitions + metadata": "Cancella tutto: rimuovi partizioni + metadati", "Wipe old signatures and partition table (DESTRUCTIVE):": "Cancella le vecchie firme e la tabella delle partizioni (DISTRUTTIVO):", "Wiping existing partition table...": "Cancellazione della tabella delle partizioni esistente...", "Wiping partitions and metadata...": "Cancellazione di partizioni e metadati in corso...", + "WireGuard Easy web interface": "Interfaccia web WireGuard Easy", + "WireGuard® is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry.": "WireGuard® è una VPN estremamente semplice ma veloce e moderna che utilizza la crittografia all'avanguardia. Esso mira ad essere più veloce, più semplice, più snella, e più utile di IPsec, evitando il mal di testa massiccio. Si intende essere molto più performante di OpenVPN. WireGuard è progettato come una VPN di scopo generale per l'esecuzione su interfacce embedded e super computer allo stesso modo, adatto per molte circostanze diverse. Inizialmente rilasciato per il kernel Linux, è ora cross-platform (Windows, macOS, BSD, iOS, Android) e ampiamente implementabile. Attualmente è in forte sviluppo, ma già potrebbe essere considerato come la soluzione VPN più sicura, più facile da usare e più semplice del settore.", "Wired NICs in backup missing on target:": "Schede NIC cablate nel backup mancanti sulla destinazione:", + "Wireshark is the world’s foremost and widely-used network protocol analyzer. It lets you see what’s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998.": "Wireshark è il principale e ampiamente utilizzato analizzatore di protocollo di rete. Ti permette di vedere cosa sta accadendo sulla tua rete a livello microscopico ed è lo standard de facto (e spesso de jure) in molte imprese commerciali e non-profit, agenzie governative e istituzioni educative. Lo sviluppo di Wireshark prospera grazie ai contributi volontari di esperti di networking in tutto il mondo ed è la continuazione di un progetto avviato da Gerald Combs nel 1998.", + "With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopped.": "Con la convalida di dns, la variabile DNSPLUGIN nomina il plugin del provider. L'installazione avanzata lo richiede; altrimenti aggiungere la linea lxc.environment. runtime: DNSPLUGIN= a /etc/pve/lxc/δCTID>.conf con il contenitore interrotto.", + "With dns validation, write the provider credentials in /config/dns-conf/.ini inside the container and restart it.": "Con la validazione di dns, scrivere il credentials del fornitore in /config/dns-conf/δplugin>.ini all'interno del contenitore e riavviarlo.", + "With http validation, port 80 of the router must be forwarded to port 80 of this container.": "Con la convalida http, la porta 80 del router deve essere inoltrata alla porta 80 di questo contenitore.", "With warnings": "Con avvertimenti", "Without Function Level Reset (FLR), passthrough is not considered reliable": "Senza Function Level Reset (FLR), il passthrough non è considerato affidabile", "Without a usable reset path, passthrough reliability is poor and VM": "Senza un percorso di ripristino utilizzabile, l'affidabilità passthrough è scarsa e VM", + "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom.": "Wolfenstein: Blade of Agony è uno sparatutto della seconda guerra mondiale ispirato a Wolfenstein e Doom.", + "Workflow automation tool": "Strumento di automazione del flusso di lavoro", "Working directory:": "Directory di lavoro:", "Works with LVM, ZFS, and BTRFS storage types": "Funziona con i tipi di archiviazione LVM, ZFS e BTRFS", + "Worth knowing before installing it:": "Vale la pena sapere prima di installarlo:", "Would you like to continue in passthrough-only mode? The libedgetpu APT install will be skipped, the Coral device will still be visible inside the container (e.g. /dev/apex_0), and you can install the runtime yourself or use an app container that bundles it (e.g. the Frigate Docker image).": "Vuoi continuare in modalità solo passthrough? L'installazione di APT libedgetpu verrà saltata, il dispositivo Coral sarà ancora visibile all'interno del contenitore (ad esempio /dev/apex_0) e potrai installare tu stesso il runtime o utilizzare un contenitore dell'app che lo raggruppa (ad esempio l'immagine Frigate Docker).", "Would you like to see the current": "Ti piacerebbe vedere la corrente", "Write access confirmed for user:": "Accesso in scrittura confermato per l'utente:", "Write access confirmed.": "Accesso in scrittura confermato.", "Write access test FAILED for user:": "Test di accesso in scrittura NON FALLITO per l'utente:", "Write access verified for user:": "Accesso in scrittura verificato per l'utente:", + "Write the value it produces instead.": "Scrivere il valore che produce invece.", + "Wrong SHA-256 in": "Sbagliato SHA-256 in", + "Wrong inherited registry lock": "Wrong ereditato blocco del registro", "Wrong passphrase": "Passphrase errata", + "Wrong size in": "Dimensioni sbagliato in", + "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support.": "Xbackbone è un semplice, self-hosted, leggero file manager PHP che supporta i sistemi di condivisione istantanea ShareX e *NIX. Supporta il caricamento e la visualizzazione di immagini, GIF, video, codice, testo formattato, e il download di file e caricamento. Hanno anche un web UI con gestione multi utente, passato carica storia e supporto di ricerca.", + "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS.": "Yaak è un client API desktop per l'organizzazione e l'esecuzione delle richieste REST, GraphQL e gRPC. E' costruito usando Tauri, Rust e ReactJS.", "Yes": "SÌ", "Yes, upload": "Sì, carica", "Yes: set a recovery passphrase now; the encrypted key envelope is uploaded with every backup.": "Sì: imposta subito una passphrase di ripristino;la busta della chiave crittografata viene caricata ad ogni backup.", @@ -4984,6 +6853,9 @@ "You should now be able to access the Proxmox web interface.": "Ora dovresti essere in grado di accedere all'interfaccia web di Proxmox.", "You will need a Tailscale auth key from: https://login.tailscale.com/admin/settings/keys": "Avrai bisogno di una chiave di autenticazione Tailscale da: https://login.tailscale.com/admin/settings/keys", "Your Coral USB device and its runtime (libedgetpu1) will NOT be affected.": "Il dispositivo USB Coral e il relativo runtime (libedgetpu1) NON saranno interessati.", + "Your machine learning Env work with Jupyter Lab": "Il tuo machine learning Env lavora con Jupyter Lab", + "Your next YouTube media manager": "Il prossimo responsabile dei media di YouTube", + "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics.": "Your_spotify è un'applicazione self-hosted che traccia quello che ascolti e ti offre un cruscotto per esplorare le statistiche su di esso! Si compone di un web server che sonda l'API Spotify ogni tanto e un'applicazione web su cui è possibile esplorare le statistiche.", "ZFS ARC config removed (kernel defaults will apply on reboot)": "Configurazione ZFS ARC rimossa (le impostazioni predefinite del kernel verranno applicate al riavvio)", "ZFS ARC maximum configured:": "ZFS ARC massimo configurato:", "ZFS ARC optimization completed": "Ottimizzazione ZFS ARC completata", @@ -5011,9 +6883,17 @@ "ZFS storage added successfully to Proxmox!": "Lo storage ZFS è stato aggiunto con successo a Proxmox!", "ZFS tools not found. Install zfsutils-linux and retry.": "Strumenti ZFS non trovati. Installa zfsutils-linux e riprova.", "ZFS:": "ZFS:", + "ZNC web interface": "Interfaccia web ZNC", + "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design.": "Zen Browser è un fork gratuito e open source di Mozilla Firefox con un focus sulla privacy, la personalizzazione e il design.", "Zero all data — partition table preserved, data wiped": "Azzera tutti i dati: tabella delle partizioni conservata, dati cancellati", "Zero all data — partition table preserved": "Azzera tutti i dati: tabella delle partizioni conservata", "Zeroing partition": "Azzeramento della partizione", + "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC.": "Znc è un buttafuori di rete IRC o BNC. Può staccare il client dal server IRC effettivo, e anche da canali selezionati. Molti client provenienti da diverse posizioni possono connettersi a un singolo account ZNC contemporaneamente e quindi appaiono sotto lo stesso soprannome di IRC.", + "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research.": "Zotero è uno strumento gratuito, facile da usare per aiutarti a raccogliere, organizzare, annotare, citare e condividere la ricerca.", + "a device it asks for cannot be translated:": "un dispositivo che chiede non può essere tradotto:", + "a value is required": "un valore è required", + "aMule WebUI (password only, no username)": "aMule WebUI (solo password, nessun nome utente)", + "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule.": "aMule è un client multi-piattaforma per la rete di condivisione di file ED2K e basato su Windows client eMule. aMule ha iniziato nell'agosto 2003, come fork di xMule, che è un fork di lMule.", "active VF(s)": "FV attive", "active VFs": "VF attive", "active Virtual Functions. Changing its driver binding would destroy every VF.": "funzioni virtuali attive. La modifica del collegamento del driver distruggerebbe ogni VF.", @@ -5035,20 +6915,24 @@ "apex group still has members; left in place:": "il gruppo apicale ha ancora membri; lasciato sul posto:", "apex kernel module not loaded on host. Run \"Install Coral on Host\" first or the container will not see /dev/apex_0.": "Modulo del kernel apex non caricato sull'host. Eseguire prima \"Install Coral on Host\" altrimenti il ​​contenitore non vedrà /dev/apex_0.", "appears to be part of a": "sembra far parte di a", + "apply requires the OCI archive of the resolved image": "applicare requires l'archivio OCI dell'immagine risolta", "applying minimal banner patch": "applicando una patch minima per il banner", "apt cache refreshed.": "cache apt aggiornata.", "apt-get exited": "apt-esci", "apt-get update returned warnings. Continuing anyway; check": "apt-get update ha restituito avvisi. Continuando comunque; controllo", "as": "COME", + "assembling": "montaggio", "automatically. Install it manually inside the container.": "automaticamente. Installalo manualmente all'interno del contenitore.", "automatically. Reboot LXC to fully release.": "automaticamente. Riavviare LXC per il rilascio completo.", "available for LXC bind-mounts via 'LXC Mount Manager'": "disponibile per i supporti LXC tramite 'LXC Mount Manager'", "available in this same GPU and TPU menu.": "disponibile nello stesso menu GPU e TPU.", "backup at /etc/fstab.proxmenux.bak": "backup su /etc/fstab.proxmenux.bak", "ban": "divieto", + "belongs to another OCI installation": "appartiene a un'altra installazione OCI", "blocking issue(s).": "problemi di blocco.", "btrfs — Proxmox dir storage (snapshots, compression)": "btrfs — Archiviazione delle directory Proxmox (istantanee, compressione)", "btrfs — snapshots and compression": "btrfs: istantanee e compressione", + "budge is an open source 'budgeting with envelopes' personal finance app.": "budge è una fonte aperta 'budgeting con buste' personal finance app.", "builds against kernel": "si basa sul kernel", "but it does not match the one used to create the backup. Replace it with the correct keyfile from the source host and retry.": "ma non corrisponde a quello utilizzato per creare il backup. Sostituirlo con il file di chiavi corretto dall'host di origine e riprovare.", "bytes": "byte", @@ -5056,29 +6940,52 @@ "chmod 1777 + setfacl o::rwx (applied on the NFS share from this host)": "chmod 1777 + setfacl o::rwx (applicato alla condivisione NFS da questo host)", "chmod failed — NFS server may be restricting changes from root": "chmod non riuscito: il server NFS potrebbe limitare le modifiche da root", "chown/chmod failed — likely unprivileged CT against host bind mount. Falling back to ACL.": "chown/chmod non è riuscito: probabilmente CT non privilegiato contro il montaggio del collegamento dell'host. Ritornando all'ACL.", + "containers": "contenitori", + "containers of": "contenitori di", "content:": "contenuto:", + "copyparty web interface": "Interfaccia web copyparty", "could not be compiled for kernel": "non può essere compilato per il kernel", + "could not validate NVIDIA; exit code": "non poteva convalidare NVIDIA; codice di uscita", + "cpuunits must be between 8 and 10000": "i cpuunits devono essere tra 8 e 10000", + "custom": "personalizzato", + "custom dependency commands are not yet supported": "comandi di dipendenza personalizzati non sono ancora supportati", + "custom path(s) saved.": "percorsi personalizzati salvati.", + "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them.": "darktable è un'applicazione di flusso di lavoro di fotografia open source e sviluppatore raw. Un lighttable virtuale e darkroom per i fotografi. Gestisce i negativi digitali in un database, consente di visualizzarli attraverso un lighttable zoomabile e consente di sviluppare immagini crude e migliorarle.", + "ddclient starts with the example configuration and updates nothing yet. Write your provider, login and domains in /config/ddclient.conf inside the container, then restart it.": "ddclient inizia con la configurazione dell'esempio e non aggiorna ancora nulla. Scrivi il tuo provider, login e domini in /config/ddclient.conf all'interno del contenitore, quindi riavvialo.", "default": "predefinito", "delete the credentials file (if any)": "eliminare il file delle credenziali (se presente)", "delete the matching line from /etc/fstab": "elimina la riga corrispondente da /etc/fstab", "descriptor + VMDK files": "descrittore + file VMDK", + "device(s) added to VM": "dispositivi aggiunti alla VM", "devices": "dispositivi", + "devices (dynamic runtime)": "dispositivi (velocità dinamica)", "did not become ready. Skipping.": "non è diventato pronto. Saltare.", + "digiKam: Professional Photo Management with the Power of Open Source": "digiKam: Gestione Foto Professionale con la Potenza di Open Source", "disk(s) added to CT": "disco(i) aggiunto(i) a CT", "disk(s) added to VM": "disco/i aggiunto/i alla VM", + "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems.": "diskover è un indice di file system open source che utilizza Elasticsearch per indicizzare e gestire i dati attraverso sistemi di archiviazione eterogenei.", "disks present": "dischi presenti", "dkms autoinstall did not activate:": "l'installazione automatica di dkms non è stata attivata:", "dkms.conf generated.": "dkms.conf generato.", + "docker run command": "comando di esecuzione docker", + "docker run command of the application": "Comando di esecuzione docker dell'applicazione", "does not exist on this host. Path not added.": "non esiste su questo host. Percorso non aggiunto.", "does not exist. Exiting.": "non esiste. In uscita.", + "doplarr_rs starts from the example configuration and connects to nothing. Write the token of your Discord bot in discord_token in /config/config.toml inside the container.": "doplarr_rs parte dalla configurazione di esempio e si collega a nulla. Scrivi il token del tuo bot Discord in discord token in /config/config.toml all'interno del contenitore.", + "downloaded Compose file": "Scaricare il file Compose", "dpkg still reports unfinished package work; review": "dpkg segnala ancora il lavoro del pacchetto incompleto;revisione", + "driver components": "componenti driver", "driver:": "driver:", + "e.g.": "ad es.", + "empty = generate": "vuoto = generare", "exFAT (portable: Windows/Linux/macOS)": "exFAT (portatile: Windows/Linux/macOS)", "exFAT tools installed successfully.": "Strumenti exFAT installati correttamente.", "ext4 — Proxmox dir storage (recommended)": "ext4: archiviazione della directory Proxmox (consigliato)", "ext4 — recommended, most compatible": "ext4: consigliato, più compatibile", "fail2ban-client could not communicate with the server": "fail2ban-client non è riuscito a comunicare con il server", "fail2ban-client successfully communicated with the server": "fail2ban-client ha comunicato con successo con il server", + "failed": "fallito", + "failed with exit code": "non riuscito con codice di uscita", "failed:": "fallito:", "feranick fork unreachable. Falling back to google/gasket-driver...": "Il fork feranick non è raggiungibile. Ripiego su google/gasket-driver...", "feranick/gasket-driver cloned (actively maintained, kernel 6.12+ ready).": "feranick/gasket-driver clonato (mantenuto attivamente, kernel 6.12+ pronto).", @@ -5092,6 +6999,7 @@ "for this policy and may fail after first use or on subsequent VM starts.": "per questa policy e potrebbe non riuscire dopo il primo utilizzo o ai successivi avvii della VM.", "formatted as": "formattato come", "found": "trovato", + "free": "gratis", "from Proxmox web interface (you will be asked)": "dall'interfaccia web di Proxmox (ti verrà chiesto)", "from container": "dal contenitore", "from the GPUs and Coral-TPU menu first, then run this option again.": "prima dal menu GPU e Coral-TPU, quindi esegui nuovamente questa opzione.", @@ -5102,6 +7010,7 @@ "gasket-dkms has been fully removed from this system.": "gasket-dkms è stato completamente rimosso dal sistema.", "gasket-dkms is still reported by dpkg in state:": "gasket-dkms è ancora riportato da dpkg nello stato:", "gawk installed": "gawk installato", + "go2rtc WebUI": "Go2rtc WebUI", "google/gasket-driver cloned (fallback — will apply local patches).": "google/gasket-driver clonato (fallback: applicherà le patch locali).", "gpg not found; trying apt-key fallback": "gpg non trovato; provando il fallback con la chiave apt", "gzip replaced with pigz wrapper successfully": "gzip sostituito con successo con il wrapper pigz", @@ -5109,10 +7018,14 @@ "has a different MAC than the backup — update any DHCP static reservation": "ha un MAC diverso da quello del backup: aggiorna qualsiasi prenotazione statica DHCP", "has a new MAC": "ha un nuovo MAC", "has only": "ha solo", + "health and persistence profile not yet defined": "profilo di salute e persistenza non ancora definito", + "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers.": "hiSHtory è una storia di shell migliore. Memorizza la cronologia della shell in contesto (che directory ha eseguito il comando, se è riuscito o fallito, quanto tempo ci è voluto, ecc). Questo è tutto memorizzato localmente e end-to-end crittografato per la sincronizzazione a tutti gli altri computer.", + "host directory": "directory host", "host fstab only (not registered as Proxmox storage)": "solo host fstab (non registrato come archivio Proxmox)", "hostpci entries for all IOMMU group devices": "voci hostpci per tutti i dispositivi del gruppo IOMMU", "hostpci entries for selected GPU functions (full IOMMU group will be enforced after reboot)": "voci hostpci per le funzioni GPU selezionate (il gruppo IOMMU completo verrà applicato dopo il riavvio)", "hour(s)": "ore)", + "https if the image serves TLS": "https se l'immagine serve TLS", "iSCSI Content Type": "Tipo di contenuto iSCSI", "iSCSI Daemon (iscsid): RUNNING": "Demone iSCSI (iscsid): IN ESECUZIONE", "iSCSI Daemon (iscsid): STOPPED": "Demone iSCSI (iscsid): ARRESTATO", @@ -5129,16 +7042,23 @@ "iSCSI storage provides raw block devices for VM disk images.": "Lo storage iSCSI fornisce dispositivi a blocchi grezzi per le immagini del disco della VM.", "iSCSI tools installed": "Strumenti iSCSI installati", "iftop usage": "utilizzo iftop", + "image cache on": "cache immagine su", + "image itself": "immagine stessa", "imported:": "importato:", "in CT": "nella CT", + "in backups": "in backup", + "incompatible qBittorrent schema": "schema qBittorrent incompatibile", + "individual template is blocked": "singolo modello è bloccato", "initramfs updated": "initramfs aggiornato", "initramfs updated.": "initramfs aggiornato.", + "installed": "installato", "installed but command not immediately available": "installato ma comando non immediatamente disponibile", "installed correctly and available": "installato correttamente e disponibile", "installed in CT": "installato in CT", "installed inside CT": "installato all'interno del CT", "installed successfully.": "installato con successo.", "installed.": "installato.", + "installing": "installazione", "intel-gpu-tools installed successfully": "intel-gpu-tools installato correttamente", "intel-gpu-tools is already installed:": "intel-gpu-tools è già installato:", "intel-gpu-tools is up to date": "intel-gpu-tools è aggiornato", @@ -5169,7 +7089,11 @@ "is not configured as machine type q35.": "non è configurato come tipo macchina q35.", "is not in the patch.sh supported list. The patch may no-op or fail; review keylase/nvidia-patch README before continuing.": "non è nell'elenco supportato da patch.sh. La patch potrebbe non funzionare o fallire; rivedere il README di keylase/nvidia-patch prima di continuare.", "is not supported by the official Google libedgetpu APT repository.": "non è supportato dal repository APT ufficiale di Google libedgetpu.", + "is one of the": "è uno dei", "is referenced in the following stopped VM(s)/CT(s):": "viene fatto riferimento nelle seguenti VM/CT arrestati:", + "it asks for the network of the host; the container gets its own address instead": "chiede la rete dell'host; il contenitore ottiene invece il proprio indirizzo", + "it publishes no other architecture": "non pubblica altra architettura", + "it uses the Compose option": "utilizza l'opzione Compose", "journald MaxLevelStore is adequate for auth logging": "journald MaxLevelStore è adeguato per la registrazione di autenticazione", "journald drop-in created: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf": "drop-in journald creato: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf", "journald log level restored": "livello di registro journald ripristinato", @@ -5193,26 +7117,41 @@ "kexec-tools installed successfully": "kexec-tools è stato installato correttamente", "kexec-tools is already installed": "kexec-tools è già installato", "kexec-tools is not installed or already removed.": "kexec-tools non è installato o è già stato rimosso.", + "layers": "strati di strati", "legacy .link file(s) to the ProxMenux-managed format": "file .link legacy nel formato gestito da ProxMenux", "log2ram completely removed from system": "log2ram completamente rimosso dal sistema", "manually inside the container before starting it.": "manualmente all'interno del contenitore prima di avviarlo.", "manually inside the container.": "manualmente all'interno del contenitore.", "maximum performance": "massime prestazioni", "may be closed — trying discovery anyway...": "potrebbe essere chiuso: prova comunque la scoperta...", + "melonDS aims at providing fast and accurate Nintendo DS emulation.": "melonDS mira a fornire emulazione rapida e accurate Nintendo DS.", + "members:": "membri:", + "minimum": "minimo", "missing": "mancante", "mkfs.btrfs not found. Install btrfs-progs and retry.": "mkfs.btrfs non trovato. Installa btrfs-progs e riprova.", "more": "Di più", + "motionEye web interface": "Interfaccia web motionEye", "mount.cifs command not found after installation.": "Comando mount.cifs non trovato dopo l'installazione.", "mount.nfs command not found after installation.": "Comando mount.nfs non trovato dopo l'installazione.", + "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone.": "mstream è un server di streaming musicale personale. È possibile utilizzare mStream per trasmettere la musica dal computer di casa a qualsiasi dispositivo, ovunque. Ci sono applicazioni mobili disponibili sia per Android che per iPhone.", + "must contain a valid numeric UID for the GPU": "deve contenere un UID numerico valido per la GPU", + "needed": "necessario", + "needs a privileged LXC": "ha bisogno di un LXC privilegiato", + "needs a relaxed AppArmor or seccomp profile": "ha bisogno di un profilo AppArmor o asciugamp rilassato", + "needs stack review": "bisogno di stack recensione", "never": "mai", + "next free": "prossimo libero", + "next free block": "prossimo blocco libero", "nftables not available - using iptables ban action": "nftables non disponibile: utilizzo dell'azione di divieto di iptables", "no": "no", "no (kdf=none, not needed)": "no (kdf=none, non necessario)", "no (no escrow blob — set a recovery passphrase to enable recovery)": "no (nessun blob di deposito a garanzia: imposta una passphrase di ripristino per abilitare il ripristino)", + "no declarative value": "nessun valore dichiarativo", "no passphrase": "nessuna passphrase", "no password": "nessuna password", "no_root_squash": "no_root_zucca", "non-ProxMenux .tar archive(s) in this path": "archivi .tar non ProxMenux in questo percorso", + "not available yet": "non disponibile", "not found.": "non trovato.", "not installed": "non installato", "not reliable on this hardware due to the following limitations": "non affidabile su questo hardware a causa delle seguenti limitazioni", @@ -5229,27 +7168,39 @@ "of free disk space.": "di spazio libero su disco.", "older firmware may increase passthrough instability": "il firmware precedente può aumentare l'instabilità del passthrough", "oldest driver offered:": "driver più vecchio offerto:", + "on": "su", "on SSD/NVMe pools that support discard": "su pool SSD/NVMe che supportano l'eliminazione", + "one of its services declares no image": "uno dei suoi servizi non dichiara immagine", + "one of its services is not written as a service": "uno dei suoi servizi non è scritto come servizio", "openssl encryption failed.": "La crittografia openssl non è riuscita.", "openssl is not installed — cannot create recovery copy. Install openssl and retry.": "openssl non è installato: impossibile creare una copia di ripristino. Installa openssl e riprova.", + "optional": "opzionale", + "optional dependencies are not yet supported": "le dipendenze facoltative non sono ancora supportate", "or format it manually using external tools.": "oppure formattarlo manualmente utilizzando strumenti esterni.", + "or none": "o nessuno", "or use the ProxMenux LXC Mount Manager.": "oppure utilizzare ProxMenux LXC Mount Manager.", "orphan iface lines, no impact on restore": "Linee iface orfane, nessun impatto sul ripristino", "other .tar archive(s) — not ProxMenux host backups (e.g. PVE vzdump or unrelated tarballs).": "altri archivi .tar — non backup dell'host ProxMenux (ad esempio PVE vzdump o tarball non correlati).", "packages (this may take a few minutes)...": "pacchetti (l'operazione potrebbe richiedere alcuni minuti)...", + "packages.": "pacchetti.", "parent PF:": "PF genitore:", "partition(s). Partition table preserved.": "partizione(i). Tabella delle partizioni conservata.", + "pasted Compose file": "file incollato Compose", "paths for next boot (/etc/pve, guests, drivers, ...)": "percorsi per l'avvio successivo (/etc/pve, guest, driver, ...)", "pct exec authorization failed": "autorizzazione pct exec non riuscita", "pct push failed. Check log:": "PCT push non riuscito. Controlla il registro:", "pending (reboot required to enumerate full group)": "in sospeso (riavvio necessario per enumerare il gruppo completo)", + "phpMyAdmin is installed with arbitrary server connections enabled: the login page has a Server field where the address of the MySQL or MariaDB server is entered, together with its user and password.": "phpMyAdmin è installato con connessioni server arbitrarie abilitate: la pagina di login ha un campo Server in cui è inserito l'indirizzo del server MySQL o MariaDB, insieme all'utente e alla password.", "pigz configuration completed": "configurazione pigz completata", "pigz enabled in vzdump configuration": "pigz abilitato nella configurazione vzdump", "pigz installed successfully": "pigz installato con successo", "pigz removed": "maiale rimosso", "pigz wrapper script created": "Script wrapper pigz creato", + "playit.gg has to claim this agent before it forwards anything. The agent prints a one-time claim link on the container console and keeps it there until the link is opened.": "playit.gg deve rivendicare questo agente prima di inoltrare nulla. L'agente stampa un collegamento di rivendicazione una volta sulla console del contenitore e la tiene lì fino all'apertura del collegamento.", "port": "porta", "portmapper/rpcbind has been disabled": "portmapper/rpcbind è stato disabilitato", + "private network assigned automatically": "rete privata assegnata automaticamente", + "privileged LXC": "LXC privilegiato", "proxmox-backup-client reported:": "proxmox-backup-client segnalato:", "proxmox-boot-tool refreshed": "proxmox-boot-tool aggiornato", "pve-enterprise.list update skipped (no change)": "Aggiornamento pve-enterprise.list saltato (nessuna modifica)", @@ -5261,10 +7212,22 @@ "pvesm not found.": "pvesm non trovato.", "pvesm path failed, trying manual detection...": "Percorso pvesm non riuscito, tentativo di rilevamento manuale...", "pvesm status failed": "stato pvesm non riuscito", + "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web.": "pyLoad è un free and Open Source download manager scritto in Python e progettato per essere estremamente leggero, facilmente estensibile e completamente gestibile via web.", + "pyLoad web interface": "interfaccia web pyLoad", + "qBittorrent WebUI password (user: admin)": "qBittorrent password WebUI (utente: admin)", + "qBittorrent already has a configuration; it is not overwritten": "qBittorrent ha già una configurazione; non è sovrascritto", + "qBittorrent configured": "qBittorrent configurato", + "qBittorrent did not apply the category:": "qBittorrent non ha applicato la categoria:", + "qBittorrent did not apply the download paths": "qBittorrent non ha applicato i percorsi di download", + "qBittorrent requires a non-empty password": "qBittorrent requi è una password non vuota", + "qBittorrent: authenticated access to the preferences could not be verified": "qBittorrent: l'accesso autenticato alle preferenze non poteva essere verificato", + "qBittorrent: invalid login response or missing session cookie": "qBittorrent: risposta di login non valida o cookie di sessione mancante", "raw USB disk — no filesystem (will be FORMATTED)": "Disco USB grezzo: nessun file system (verrà FORMATTATO)", + "read-only": "sola lettura", "reboot-quick alias added": "Aggiunto alias riavvio rapido", "reboot-quick alias is already configured": "l'alias di riavvio rapido è già configurato", "recommended": "raccomandato", + "recovering": "recupero", "remapped users": "utenti rimappati", "remove the (now-empty) directory if possible": "rimuovere la directory (ora vuota) se possibile", "removed from Proxmox": "rimosso da Proxmox", @@ -5280,11 +7243,14 @@ "rpcbind could not be disabled completely": "rpcbind could not be disabled completely", "rpcbind service and socket have been disabled and stopped": "il servizio e il socket rpcbind sono stati disabilitati e interrotti", "rpcbind units were not found; no changes were made": "le unità rpcbind non sono state trovate;non sono state apportate modifiche", + "rsnapshot starts with the default configuration, which backs up /data into /.snapshots. Edit /config/rsnapshot.conf inside the container to set your own backup points, snapshot root and retention intervals.": "rsnapshot inizia con la configurazione predefinita, che viene eseguito il backup /data in /.snapshots. Modifica /config/rsnapshot.conf all'interno del contenitore per impostare i propri punti di backup, root snapshot e intervalli di ritenzione.", "running": "corsa", + "runs in": "corre", "safe paths now (configs, packages, /etc, /root, ...)": "percorsi sicuri ora (configurazioni, pacchetti, /etc, /root, ...)", "same MAC": "stesso MAC", "seconds (default)": "secondi (predefinito)", "see log:": "vedi registro:", + "selected by default": "selezionato per impostazione predefinita", "selected path(s):": "percorso/i selezionato/i:", "server": "server", "server IP or hostname:": "IP del server o nome host:", @@ -5292,6 +7258,7 @@ "servers found on the network.": "server trovati sulla rete.", "servers found.": "server trovati.", "sha256sum not found. Cannot verify Borg binary.": "sha256sum non trovato. Impossibile verificare il binario Borg.", + "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++.": "shadPS4 è un primo emulatore PlayStation 4 per Windows, Linux e macOS scritto in C++.", "showmount command is not working properly.": "il comando showmount non funziona correttamente.", "showmount command not found after installation.": "Comando showmount non trovato dopo l'installazione.", "single portable archive": "unico archivio portatile", @@ -5307,6 +7274,7 @@ "started successfully.": "iniziato con successo.", "started.": "iniziato.", "startup/restart errors are likely.": "sono probabili errori di avvio/riavvio.", + "staticfiles volume size in GB": "dimensione del volume staticfiles in GB", "stop source VM first": "arrestare prima la VM di origine", "stopped": "fermato", "storage yet.": "ancora spazio di archiviazione.", @@ -5316,9 +7284,16 @@ "suggested:": "suggerito:", "switch_gpu_mode.sh was not found.": "switch_gpu_mode.sh non è stato trovato.", "sysfs ROM dump failed — trying ACPI VFCT table...": "Il dump della ROM sysfs non è riuscito: provo la tabella ACPI VFCT...", + "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools.": "syslog-ng consente di raccogliere, parse, classificare, riscrivere e correlare i log da tutta la vostra infrastruttura e memorizzarli o indirizzarli agli strumenti di analisi del registro.", "systemctl restart networking failed:": "systemctl riavvio della rete non riuscito:", "systemd OnCalendar expression": "espressione systemd OnCalendar", + "the API key was not generated on the first start": "la chiave API non è stata generata al primo avvio", + "the container has its own address, so the port Docker published on the host is not needed": "il container ha un proprio indirizzo, quindi la porta Docker pubblicata sull'host non è necessaria", + "the qBittorrent schema is not available": "lo schema qBittorrent non è disponibile", + "this configuration needs the device": "questa configurazione ha bisogno del dispositivo", "this distribution": "questa distribuzione", + "tmpfs size in MB for": "tmpfs dimensione in MB per", + "tmpfs size too small for": "tmpfs dimensione troppo piccola per", "to": "A", "to CT": "alla TC", "to VM": "a VM", @@ -5327,6 +7302,12 @@ "to sharedfiles group": "al gruppo sharedfiles", "total": "totale", "umount the path if currently mounted": "smontare il percorso se attualmente montato", + "unprivileged LXC": "LXC non privato", + "unsupported credential generator": "generatore credential non supportato", + "unsupported dependency condition": "condizione di dipendenza non supportata", + "unsupported external credential or boolean": "credential o boolean esterno non supportato", + "unsupported variable": "variabile non supportata", + "updating": "aggiornamento", "updating NVIDIA userspace libs": "aggiornamento delle librerie dello spazio utente NVIDIA", "user packages missing — will be installed automatically:": "pacchetti utente mancanti: verranno installati automaticamente:", "users": "utenti", @@ -5337,12 +7318,19 @@ "vfio-pci IDs configured": "ID vfio-pci configurati", "vfio-pci IDs in /etc/modprobe.d/vfio.conf": "ID vfio-pci in /etc/modprobe.d/vfio.conf", "vzdump backup speed optimization completed": "Ottimizzazione della velocità di backup di vzdump completata", + "wallabag builds its links from the address given during the installation. If it does not match the address of the container, edit lxc.environment.runtime: SYMFONY__ENV__DOMAIN_NAME in /etc/pve/lxc/.conf with the container stopped, and start it again.": "wallabag costruisce i suoi collegamenti dall'indirizzo indicato durante l'installazione. Se non corrisponde all'indirizzo del contenitore, modificare lxc.environment. runtime: SYMFONY ENV DOMAIN NAME in /etc/pve/lxc/δCTID>.conf con il contenitore fermato, e ricominciare.", + "wallabag listens on port 80 of the container and stores its data in SQLite.": "wallabag ascolta la porta 80 del contenitore e memorizza i suoi dati in SQLite.", + "wallabag web interface": "Interfaccia web wallabag", "was": "era", "was installed, but the kernel reports:": "è stato installato, ma il kernel riporta:", + "when finished": "quando finito", "will rebind the GPU to vfio-pci on the next reboot, breaking the driver that is about to be installed.": "ricollegherà la GPU a vfio-pci al prossimo riavvio, rompendo il driver che sta per essere installato.", "wipefs failed on": "wipefs non è riuscito", "with": "con", + "with Proxmox": "con Proxmox", + "with prefix, e.g.": "con prefisso, ad esempio.", "with the password you provided.": "con la password che hai fornito.", + "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems.": "xemu è un'applicazione gratuita e open source che emula la console di gioco Microsoft Xbox originale, consentendo alle persone di giocare i loro giochi Xbox originali su sistemi Windows, macOS e Linux.", "xfs — Proxmox dir storage (large files and VMs)": "xfs: archiviazione di directory Proxmox (file di grandi dimensioni e VM)", "xfs — better for large files": "xfs: migliore per file di grandi dimensioni", "years old": "anni", diff --git a/lang/pt.json b/lang/pt.json index ab219190..ba3ce882 100644 --- a/lang/pt.json +++ b/lang/pt.json @@ -7,6 +7,7 @@ "(common default on Debian/LXC: PermitRootLogin prohibit-password).": "(padrão comum no Debian/LXC: PermitRootLogin proíbe-senha).", "(disabled)": "(desativado)", "(e.g.": "(por ex.", + "(empty)": "(vazio)", "(for unprivileged LXCs)": "(para LXCs sem privilégios)", "(if only privileged LXCs need write access)": "(se apenas LXCs privilegiados precisarem de acesso de gravação)", "(make.log not found — DKMS may have failed before invoking make)": "(make.log não encontrado — DKMS pode ter falhado antes de invocar make)", @@ -19,6 +20,7 @@ "(recommended)": "(recomendado)", "(same MAC — restored config adjusted automatically)": "(mesmo MAC - configuração restaurada ajustada automaticamente)", ")": ")", + "*Arr Suite": "* Arr Suite", "+ Add a path": "+ Adicione um caminho", "+ Add new Borg target": "+ Adicionar novo alvo Borg", "+ Add new PBS manually": "+ Adicione novo PBS manualmente", @@ -35,39 +37,102 @@ "/var/lib/vz/dump (Proxmox default)": "/var/lib/vz/dump (padrão Proxmox)", "1777 = sticky bit + rwx for all. No shared group needed.": "1777 = sticky bit + rwx para todos. Nenhum grupo compartilhado é necessário.", "====== PVE UPDATE COMPLETED ======": "====== ATUALIZAÇÃO PVE CONCLUÍDA ======", + "A GTK Broadway web UI for libvirt and virt-manager.": "Um GTK Broadway web UI para libvirt e virt-manager.", + "A Personal Relationship Management tool to help you document your social life.": "Uma relação pessoal Ferramenta de gerenciamento para ajudá-lo a documentar sua vida social.", "A VirtIO ISO already exists. Do you want to overwrite it?": "Já existe uma ISO do VirtIO. Você quer sobrescrevê-lo?", "A ZFS pool with this name already exists.": "Já existe um pool ZFS com esse nome.", "A ZFS pool with this name already exists:": "Já existe um pool ZFS com este nome:", + "A backup was modified": "Uma cópia de segurança foi modificada", + "A command did not finish in time:": "Um comando não terminou a tempo:", "A complete restore will:": "Uma restauração completa irá:", + "A concurrent change was detected; the container is not removed": "Foi detectada uma alteração simultânea; o recipiente não é removido", + "A container mount has a source, backup or permission different from the saved record": "Uma montagem de container tem uma fonte, cópia de segurança ou permissão diferente do registro salvo", + "A coordinated operation is pending. The whole previous stack will be recovered, not only the selected member. If the operation already finished, the cleanup of its markers is completed.": "Está pendente uma operation coordenada. Toda a pilha anterior será recuperada, não só o membro selecionado. Se a operation já tiver terminado, a limpeza dos seus marcadores é concluída.", + "A different host monitor include already exists; it is not overwritten:": "Já existe um monitor de máquina diferente; não é substituído:", + "A fancy monitoring tool": "Uma ferramenta de monitorização elegante", + "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata.": "Um programa de banco de dados livre e de código aberto orientado a documentos. Classificado como um programa de banco de dados NoSQL, o MongoDB usa documentos tipo JSON com esquemata.", + "A free reverse proxy for tunneling services (not self-hosted).": "Um proxy reverso gratuito para serviços de túnel (não self-hosted).", + "A free, self-hostable news aggregator…": "Um agregador de notícias gratuito e auto-hospedeiro...", + "A full-featured, open-source AI chat interface": "Uma interface de bate-papo de IA de código aberto completa", "A gasket DKMS registration is still present:": "Ainda existe um registo DKMS de gasket:", + "A host bind mount cannot be included in vzdump": "Uma montagem de ligação da máquina não pode ser incluída no vzdump", + "A host mount is not part of the journal; recovery blocked": "Uma montagem da máquina não faz parte da revista; a recuperação foi bloqueada", "A host reboot is required after this change.": "Uma reinicialização do host é necessária após essa alteração.", "A host reboot is required before starting the VM. Reboot now?": "É necessária uma reinicialização do host antes de iniciar a VM. Reiniciar agora?", "A job with this ID already exists.": "Já existe um trabalho com este ID.", + "A journal already exists; review or recover it before trying again": "Já existe uma revista; reveja ou recupere- a antes de tentar novamente", "A keyfile is installed at:": "Um arquivo-chave está instalado em:", "A legacy gasket-dkms package was found on this host, but no Coral M.2 / PCIe hardware is present.": "Foi encontrado neste host um pacote gasket-dkms legado, mas não existe hardware Coral M.2/PCIe.", + "A managed rootfs and an unprivileged container are required": "Um rootfs gerenciado e um recipiente sem privilégios são required", + "A managed volume with backup enabled is required": "Um volume gerenciado com backup habilitado é required", + "A member VMID is in use by another guest or is on another node": "Um membro VMID está em uso por outro hóspede ou está em outro nó", + "A member configuration changed after the stack was checked": "Uma configuração de membro foi alterada após a pilha ter sido verificada", + "A member configuration changed during the preparation": "A configuração de um membro foi alterada durante a preparação", + "A member did not pass its service check:": "Um membro não passou em sua verificação de serviço:", + "A member has a pending operation": "Um membro tem uma operation pendente", + "A member has no reproducible service check": "Um membro não tem verificação de serviço reprodutível", + "A member is missing before the replacement": "Falta um membro antes da substituição", + "A member operation does not belong to the stack": "Um membro operation não pertence à pilha", + "A member stopped:": "Um membro parou:", + "A member was modified after it was recovered": "Um membro foi modificado após a sua recuperação", + "A modern wiki and knowledge base for teams": "Um wiki moderno e base de conhecimento para equipes", "A new ProxMenux version is available:": "Uma nova versão do ProxMenux está disponível:", "A new kernel is staged for the next boot:": "Um novo kernel está preparado para a próxima inicialização:", "A newer version is available:": "Uma versão mais recente está disponível:", + "A pending operation exists for": "Existe uma operation pendente para", + "A pending stack assembly already exists; it is not overwritten": "Já existe um conjunto de pilha pendente; não é substituído", + "A previous NVIDIA refresh is pending review": "Uma atualização anterior do NVIDIA está pendente revisão", "A previous VFIO passthrough configuration was detected for the following NVIDIA GPU(s):": "Uma configuração de passagem VFIO anterior foi detectada para as seguintes GPUs NVIDIA:", + "A privacy-first, open-source platform for knowledge management and collaboration.": "Uma plataforma de privacidade-primeiro, open-source para gestão de conhecimento e colaboração.", "A reboot is recommended before the GPU is guaranteed to stay on the native driver.": "Recomenda-se uma reinicialização antes que a GPU permaneça no driver nativo.", "A reboot is required after installation to load the new kernel modules.": "Uma reinicialização é necessária após a instalação para carregar os novos módulos do kernel.", "A reboot is required for VFIO binding to take effect. Do you want to restart now?": "É necessária uma reinicialização para que a ligação VFIO entre em vigor. Quer reiniciar agora?", "A reboot is required to apply the new GPU mode. Do you want to restart now?": "É necessária uma reinicialização para aplicar o novo modo GPU. Quer reiniciar agora?", "A reboot is required to finish the restore.": "Uma reinicialização é necessária para concluir a restauração.", "A reboot will be required to complete the restore.": "Será necessária uma reinicialização para concluir a restauração.", + "A reproducible native startup is missing": "Falta uma inicialização nativa reprodutível", + "A rootfs adaptation is stored in persistent storage": "Uma adaptação rootfs é armazenada em armazenamento persistente", + "A self-hosted Bitwarden server": "Um servidor Bitwarden auto- hospedado", + "A self-hosted, goal-free habit tracking tool.": "Uma ferramenta de rastreamento de hábitos auto-alojada e livre de objetivos.", + "A self-improving AI agent with memory, skills, messaging, and a web dashboard.": "Um agente de IA auto-melhorando com memória, habilidades, mensagens e um painel web.", "A server reboot is recommended for all changes to take full effect.": "Uma reinicialização do servidor é recomendada para que todas as alterações tenham efeito total.", + "A shared directory was replaced during the installation": "Um diretório compartilhado foi substituído durante a instalação", + "A shared source does not match its recorded identity": "Uma fonte partilhada não corresponde à sua identidade gravada", + "A simple, open-source file sharing host.": "Uma máquina de partilha de ficheiros simples e de código aberto.", + "A simple, private file server.": "Um simples servidor de ficheiros privado.", + "A single matching image platform cannot be resolved": "Não é possível resolver uma única plataforma de imagem correspondente", + "A single-platform OCI archive is required": "Um arquivo OCI de plataforma única é required", + "A stack backup is missing; a partial restore is not allowed": "Falta uma cópia de segurança da pilha; uma restauração parcial não é permitida", + "A stack member has a different identity": "Um membro da pilha tem uma identidade diferente", "A system reboot is recommended to ensure all changes take effect.": "Recomenda-se uma reinicialização do sistema para garantir que todas as alterações tenham efeito.", + "A third party companion app available to Plex server owners to allow their users to request, review and discover content.": "Um aplicativo companheiro de terceiros disponível para proprietários de servidores Plex para permitir que seus usuários solicitem, revejam e descubram conteúdo.", + "A third-party client for self-hosted server and self-hosted server, remote access management interface, remote access to installed applications.": "Um cliente de terceiros para servidor self-hosted e servidor self-hosted, interface de gerenciamento de acesso remoto, acesso remoto às aplicações instaladas.", + "A tmpfs mount is not part of the journal; recovery blocked": "Uma montagem do tmpfs não faz parte da revista; a recuperação foi bloqueada", + "A tmpfs mount overlaps another mount": "Um monte tmpfs sobrepõe- se a outro monte", + "A tunneling daemon by Cloudflare that safely exposes your web servers into the internet.": "Um daemon de túneis pela Cloudflare que expõe com segurança seus servidores web na internet.", + "A versatile file conversion tool that supports multiple formats.": "Uma ferramenta versátil de conversão de arquivos que suporta vários formatos.", + "A web GUI client of Project V which supports VMess, VLESS, SS, SSR, Trojan, Tuic and Juicity protocols": "Um cliente web GUI do Projeto V que suporta protocolos VMess, VLESS, SS, SS, SSR, Trojan, Tuic e Juicity", + "A web app to listen Youtube audio source.": "Uma aplicação Web para ouvir a fonte de áudio do Youtube.", + "A web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes": "Um aplicativo web para gerenciar suas contas de autenticação de dois fatores (2FA) e gerar seus códigos de segurança", + "A web frontend for the motion daemon.": "Uma interface Web para o servidor de movimento.", + "A web-based file sharing and management protocol": "Um protocolo de compartilhamento e gerenciamento de arquivos baseado na web", + "A well-designed cross-platform ChatGPT UI.": "Um ChatGPT UI bem desenhado.", "ACL Status:": "Status da ACL:", "ACL permissions applied for local access for user:": "Permissões ACL aplicadas para acesso local do usuário:", "ADVANCED SETTINGS COMPLETE": "CONFIGURAÇÕES AVANÇADAS CONCLUÍDAS", + "AI / Coding & Dev-Tools": "IA / Codificação & Ferramentas Dev", "ALL DATA ON": "TODOS OS DADOS EM", "ALL DATA ON THIS DISK WILL BE PERMANENTLY LOST!": "TODOS OS DADOS NESTE DISCO SERÃO PERMANENTEMENTE PERDIDOS!", "ALL Utilities": "TODOS os utilitários", + "ALLOWED_HOSTS cannot contain line breaks": "Allowed hosts não pode conter quebras de linha", + "AList initial login": "Login inicial do AList", "AMD CPU detected": "CPU AMD detectada", "AMD CPU fixes applied successfully": "Correções de CPU AMD aplicadas com sucesso", "AMD GPU Tools installation completed!": "Instalação das ferramentas AMD GPU concluída!", "AMD GPU passthrough configured.": "Passagem de GPU AMD configurada.", "AMD GPU(s) detected:": "GPU(s) AMD detectada(s):", + "AMD KFD device": "Dispositivo AMD KFD", + "AMD VA-API + OpenCL (official mod)": "AMD VA-API + OpenCL (mod oficial)", "AMD fixes have been successfully reverted": "As correções da AMD foram revertidas com sucesso", "AMD mesa drivers installed.": "Drivers AMD mesa instalados.", "AMD softdep configured": "Softdep AMD configurado", @@ -93,9 +158,21 @@ "About to restore": "Prestes a restaurar", "Absolute directory path to use as backup target:": "caminho absoluto do diretório para usar como destino de backup:", "Absolute path to a file or directory you want backed up:": "Caminho absoluto para um arquivo ou diretório do qual deseja fazer backup:", + "Acceleration": "Aceleração", + "Acceleration configuration cancelled": "Configuração da aceleração cancelada", + "Acceleration for CodeProject.AI": "Aceleração para o Projeto de Código. IA", + "Acceleration for Immich smart recognition": "Aceleração para reconhecimento inteligente Immich", + "Acceleration for Ollama": "Aceleração para Ollama", "Accept routes from other nodes?": "Aceita rotas de outros nós?", + "Accept this host monitoring profile?": "Aceita este perfil de monitorização da máquina?", "Access Scope:": "Escopo de acesso:", + "Access bridge": "Ponte de acesso", + "Access bridge for Immich": "Ponte de acesso para Immich", + "Access bridge for Nextcloud": "Ponte de acesso para Nextcloud", + "Access bridge for Paperless": "Ponte de acesso para Paperless", + "Access bridge for Tandoor": "Ponte de acesso para Tandoor", "Access profile:": "Perfil de acesso:", + "Access token of the Jupyter Lab web interface": "Token de acesso da interface web Jupyter Lab", "Account is not locked": "A conta não está bloqueada", "Action cancelled due to previous xshok-proxmox modifications.": "Ação cancelada devido a modificações anteriores do xshok-proxmox.", "Action:": "Ação:", @@ -105,6 +182,10 @@ "Active Connections": "Conexões Ativas", "Active exports:": "Exportações ativas:", "Active session:": "Sessão ativa:", + "Actual device path on the host": "Localização real do dispositivo na máquina", + "Adaptation file too large": "Arquivo de adaptação muito grande", + "Adaptation file with unexpected permissions or owner": "Arquivo de adaptação com permissões inesperadas ou proprietário", + "Adblock & DNS": "Adblock & DNS", "Add Audio Passthrough": "Adicionar passagem de áudio", "Add CIFS storage:": "Adicione armazenamento CIFS:", "Add Controller or NVMe (PCI passthrough)": "Adicionar controlador ou NVMe (passagem PCI)", @@ -123,6 +204,9 @@ "Add PBS": "Adicionar PBS", "Add Samba Share as Proxmox Storage": "Adicionar compartilhamento Samba como armazenamento Proxmox", "Add Samba share as Proxmox Storage": "Adicionar compartilhamento Samba como armazenamento Proxmox", + "Add a Coral PCIe/M.2 device?": "Adicionar um dispositivo Coral PCIe/M.2?", + "Add a custom data path?": "Adicionar um caminho de dados personalizado?", + "Add an extra custom path": "Adicionar um caminho personalizado extra", "Add as IDE": "Adicionar como IDE", "Add as SATA": "Adicionar como SATA", "Add as SCSI": "Adicionar como SCSI", @@ -140,6 +224,7 @@ "Add import disk": "Adicionar disco de importação", "Add latest Ceph support": "Adicionar suporte Ceph mais recente", "Add new PVE 9 enterprise repository (deb822 format) (Only if using enterprise):": "Adicione novo repositório corporativo PVE 9 (formato deb822) (somente se estiver usando corporativo):", + "Add or change a device": "Adicionar ou alterar um dispositivo", "Add physical disk to VM via": "Adicione disco físico à VM via", "Add share block in /etc/samba/smb.conf:": "Adicione bloco de compartilhamento em /etc/samba/smb.conf:", "Add unprivileged flag to container configuration:": "Adicione sinalizador sem privilégios à configuração do contêiner:", @@ -154,20 +239,37 @@ "Adding": "Adicionando", "Adding CIFS storage to Proxmox...": "Adicionando armazenamento CIFS ao Proxmox...", "Adding QEMU Guest Agent support...": "Adicionando suporte ao agente convidado QEMU...", + "Adding Radarr to Prowlarr...": "Adicionando Radarr ao Prowlarr...", + "Adding Sonarr to Prowlarr...": "Adicionando Sonarr ao Prowlarr...", "Adding disk using the generated command to the selected VM": "Adicionando disco usando o comando gerado à VM selecionada", "Adding existing users to sharedfiles group...": "Adicionando usuários existentes ao grupo sharedfiles...", "Adding iSCSI storage to Proxmox...": "Adicionando armazenamento iSCSI ao Proxmox...", "Adding new share to smb.conf...": "Adicionando novo compartilhamento ao smb.conf...", + "Adding peers later means raising PEERS in /etc/pve/lxc/.conf and restarting the container. The existing peer keys are kept.": "Adicionar pares mais tarde significa levantar PEERS em /etc/pve/lxc/.conf e reiniciar o recipiente. As chaves interpares existentes são mantidas.", + "Adding the mount points...": "Adicionando os pontos de montagem...", "Adding this NVMe as a PCIe device (via 'Add Controller or NVMe PCIe to VM') gives better performance.": "Adicionar este NVMe como um dispositivo PCIe (via 'Adicionar controlador ou NVMe PCIe à VM') oferece melhor desempenho.", "Adding to /etc/fstab for permanent mounting...": "Adicionando ao /etc/fstab para montagem permanente...", + "Additional URL advertised by Plex (optional)": "URL adicional anunciado pelo Plex (opcional)", "Additional audio function(s) to be added": "Funções de áudio adicionais a serem adicionadas", + "Additional media/GPU GIDs, comma-separated": "GIDs adicionais/GPU, separados por vírgulas", + "Additional paths for": "Caminhos adicionais para", + "Address of the Compose file": "Endereço do ficheiro Compor", + "Address to reach Pydio Cells (https://domain or https://IP:8080)": "Endereço para chegar a Pydio Cells (https://domínio ou https://IP:8080)", + "Address used to reach wallabag (http://IP or https://wallabag.example.com)": "Endereço utilizado para chegar ao wallabag (http://IP ou https://wallabag.example.com)", + "Addresses to update: ipv4, ipv6 or both (uses an external service)": "Endereços a atualizar: ipv4, ipv6 ou ambos (usa um serviço externo)", + "Adguardhome Sync web interface": "Interface Web Adguardhome Sync", + "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances.": "Adguardhome-sync é uma ferramenta para sincronizar a configuração do AdGuardHome para reproduzir instâncias.", "Adjust network/CIDR to your environment.": "Ajuste a rede/CIDR ao seu ambiente.", "Adjust options if needed (vers=4,hard,timeo,...).": "Ajuste as opções se necessário (vers=4,hard,timeo,...).", "Adjusting systemd-journald limits to match Log2RAM size...": "Ajustando os limites do systemd-journald para corresponder ao tamanho do Log2RAM...", "Adjusts journald log level if needed (Proxmox defaults may block auth logs)": "Ajusta o nível de log do diário, se necessário (os padrões do Proxmox podem bloquear logs de autenticação)", + "Admin page": "Página de administração", + "Administrator email": "E- mail do administrador", + "Administrator password, at least 12 characters (empty = generated)": "Senha do administrador, pelo menos 12 caracteres (vazio = gerado)", "Advanced": "Avançado", "Advanced Diagnostics": "Diagnóstico Avançado", "Advanced Network Diagnostics": "Diagnóstico avançado de rede", + "Advanced: every setting of the container": "Avançado: cada configuração do recipiente", "Affected LXC containers": "Contêineres LXC afetados", "After completing GPU setup, start the VM manually when the host is ready.": "Depois de concluir a configuração da GPU, inicie a VM manualmente quando o host estiver pronto.", "After confirming, you will be asked to choose the NVIDIA driver version to install.": "Após a confirmação, você será solicitado a escolher a versão do driver NVIDIA para instalar.", @@ -183,11 +285,15 @@ "After the reboot you can follow the post-restore work live from ProxMenux Monitor → Backups tab (estimated time, per-component status, log tail, rollback delta).": "Após a reinicialização, você pode acompanhar o trabalho pós-restauração ao vivo no ProxMenux Monitor → guia Backups (tempo estimado, status por componente, cauda do log, delta de reversão).", "After the reboot, you will only be able to access the Proxmox host via:": "Após a reinicialização, você só poderá acessar o host Proxmox via:", "After this LXC → VM switch, reboot the host so the new binding state is applied cleanly.": "Após esta opção LXC → VM, reinicialize o host para que o novo estado de ligação seja aplicado de forma limpa.", + "Airsonic Advanced web interface": "Interface Web Airsonic Advanced", + "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room.": "Airsonic-avanced é uma transmissão de mídia gratuita, baseada na web, proporcionando ubiquitious acesso à sua música. Use-o para compartilhar sua música com amigos, ou para ouvir sua própria música durante o trabalho. Você pode transmitir para vários jogadores simultaneamente, por exemplo para um jogador na sua cozinha e outro na sua sala de estar.", "Aliases added to .bashrc": "Aliases adicionados a .bashrc", + "Alist Sync web interface": "Interface Web de sincronização Alist", "All": "Todos", "All Available Scripts": "Todos os scripts disponíveis", "All GPUs Already Assigned": "Todas as GPUs já atribuídas", "All ProxMenux optimizations are up to date.": "Todas as otimizações do ProxMenux estão atualizadas.", + "All applications": "Todos os pedidos", "All block devices:": "Todos os dispositivos de bloco:", "All changes applied. No reboot required.": "Todas as alterações aplicadas. Não é necessária reinicialização.", "All changes are reversible using the ProxMenux uninstaller.": "Todas as alterações são reversíveis usando o desinstalador ProxMenux.", @@ -195,43 +301,79 @@ "All detected GPUs are already assigned to this VM.": "Todas as GPUs detectadas já estão atribuídas a esta VM.", "All detected controllers/NVMe are already present in the selected VM.": "Todos os controladores/NVMe detectados já estão presentes na VM selecionada.", "All disks may already be in use or mounted.": "Todos os discos podem já estar em uso ou montados.", + "All images are downloaded and verified first, and native backups are taken with the stack stopped. Contracts are published after the whole set is checked. If anything fails, all members are recovered.": "Todas as imagens são baixadas e verificadas primeiro, e backups nativos são feitos com a pilha parada. Os contratos são publicados após a verificação de todo o conjunto. Se alguma coisa falhar, todos os membros são recuperados.", "All images imported and configured successfully": "Todas as imagens importadas e configuradas com sucesso", "All imports failed": "Todas as importações falharam", + "All of them are removed.": "Todos eles foram removidos.", "All partitions and metadata removed.": "Todas as partições e metadados removidos.", "All physical interfaces from backup are present on target": "Todas as interfaces físicas do backup estão presentes no destino", + "All stack members are updated together. Main CT:": "Todos os membros da pilha são atualizados juntos. CT principal:", "All types (images, backup, iso, vztmpl, snippets)": "Todos os tipos (imagens, backup, iso, vztmpl, snippets)", "All user-installed packages from the backup are present on this host": "Todos os pacotes instalados pelo usuário do backup estão presentes neste host", "All users with UID and GID": "Todos os usuários com UID e GID", "Allocate CPU Cores": "Alocar núcleos de CPU", "Allocate RAM in MiB": "Alocar RAM em MiB", + "Allowed hosts (comma separated; * allows access through the assigned IP)": "Hosts permitidas (separados por vírgula; * permite o acesso através do IP atribuído)", "Already Mounted": "Já montado", "Already configured": "Já configurado", "Already installed — skipping": "Já instalado – pulando", + "Also add the /dev/srX optical device (recommended)": "Adicione também o dispositivo óptico /dev/srX (recomendado)", "Also comment any remaining 'bookworm' entries in *.list if present.": "Comente também quaisquer entradas restantes de 'bookworm' em *.list, se houver.", "Also install the VirtIO network driver during setup to enable network access.": "Instale também o driver de rede VirtIO durante a configuração para habilitar o acesso à rede.", "Although VFIO can bind to this device, full passthrough to a VM is": "Embora o VFIO possa se vincular a este dispositivo, a passagem completa para uma VM é", + "Altus is an Electron-based WhatsApp client with themes and multiple account support.": "Altus é um cliente WhatsApp baseado em Electron com temas e suporte a múltiplas contas.", + "Ambiguous mount points in the container": "Pontos de montagem ambíguos no recipiente", + "Ambiguous or invalid environment variable": "Variável de ambiente ambígua ou inválida", "Amount of RAM in MiB (default: 4096)": "Quantidade de RAM em MiB (padrão: 4096)", + "An AI model used to generate images conditioned on text descriptions.": "Um modelo de IA usado para gerar imagens condicionadas em descrições de texto.", "An AMD dedicated GPU has been detected without FLR support": "Uma GPU dedicada AMD foi detectada sem suporte FLR", "An AMD integrated GPU (APU) has been detected": "Uma GPU integrada AMD (APU) foi detectada", + "An Alist storage synchronization tool based on the Web interface.": "Uma ferramenta de sincronização de armazenamento Alist baseada na interface Web.", + "An Industrial-Level Controllable and Efficient Zero-Shot Text-To-Speech System": "Um Sistema de Texto-A-Shot Controlável e Eficiente de Nível Industrial", "An Intel dedicated GPU has been detected without FLR support": "Uma GPU dedicada Intel foi detectada sem suporte FLR", + "An accelerated video generation framework that speeds up end-to-end diffusion while preserving video quality": "Um framework acelerado de geração de vídeo que acelera a difusão de ponta a ponta, preservando a qualidade de vídeo", + "An executable required by the adapter is missing in the new image": "Falta um executável required pelo adaptador na nova imagem", "An fstab entry already exists for:": "Já existe uma entrada fstab para:", + "An image probe container was started externally": "Foi iniciado um recipiente de sonda de imagem externamente", + "An include is not part of the journal; recovery blocked": "Uma inclusão não faz parte da revista; recuperação bloqueada", + "An include was modified outside the journal; recovery blocked": "Uma inclusão foi modificada fora da revista; recuperação bloqueada", + "An open source generative AI development platform for building AI Agents and LLM workflows": "Uma plataforma de desenvolvimento de IA geradora de código aberto para a construção de fluxos de trabalho AI Agents e LLM", + "An operation of this installation has not finished; recover it from the management menu before removing it": "Uma operation desta instalação não terminou; recuperá-la do menu de gestão antes de removê-la", + "An update does not accept configuration changes": "Uma atualização não aceita alterações de configuração", "Analysis Tools": "Ferramentas de análise", + "Analysis software that shows your internet speed for up to 30 days.": "Software de análise que mostra a sua velocidade de internet por até 30 dias.", "Analyze Bridge Configuration": "Analisar configuração da ponte", "Analyze Network Configuration": "Analisar configuração de rede", "Analyzing Bridge Configuration - READ ONLY MODE": "Analisando a configuração da ponte - MODO SOMENTE LEITURA", "Analyzing Network Configuration - READ ONLY MODE": "Analisando a configuração da rede - MODO SOMENTE LEITURA", "Analyzing selected disks...": "Analisando discos selecionados...", "Analyzing system for available PCIe storage devices...": "Analisando sistema para dispositivos de armazenamento PCIe disponíveis...", + "Another OCI operation is using the instance registry": "Outra OCI operation está usando o registro de instância", + "Another OCI operation is using the instance registry. Wait for it to finish and open this menu again; no container is modified.": "Outra OCI operation está usando o registro de instância. Espere que termine e abra este menu novamente; nenhum recipiente é modificado.", + "Another OCI operation is using the registry. This operation was not started.": "Outra OCI operation está usando o registro. Esta operation não foi iniciada.", + "Another instance uses": "Outra instância usa", + "Another stack operation is pending": "Outra pilha operation está pendente", + "Application": "Aplicação", + "Application responding:": "Aplicação que responde:", + "Application responding; checking its stability...": "Aplicação respondendo; verificando sua estabilidade...", + "Application suite: one independent LXC per selected application": "Pacote de aplicativos: um LXC independente por aplicativo selecionado", + "Application:": "Aplicação:", + "Applications you can choose:": "Aplicações que você pode escolher:", "Apply": "Aplicar", "Apply AMD CPU fixes": "Aplicar correções de CPU AMD", "Apply Available Updates": "Aplicar atualizações disponíveis", "Apply and restart services:": "Aplique e reinicie os serviços:", "Apply available updates": "Aplicar atualizações disponíveis", "Apply boot/initramfs changes": "Aplicar alterações de boot/initramfs", + "Apply configuration": "Aplicar configuração", "Apply fix now?": "Aplicar correção agora?", "Apply fix now? (The share will be briefly remounted)": "Aplicar correção agora? (A ação será brevemente remontada)", "Apply network optimizations": "aplicar otimizações de rede", + "Apply optional security relaxation apparmor:rootlesskit": "Aplicar o apparmor de relaxamento de segurança opcional:rootlesskit", + "Apply optional security relaxation apparmor:unconfined": "Aplicar o apparmor de relaxamento de segurança opcional:unconfined", + "Apply optional security relaxation seccomp:unconfined": "Aplicar seccomp de relaxamento de segurança opcional:unconfined", "Apply read+write access for 'others' on the host directory?": "Aplicar acesso de leitura + gravação para 'outros' no diretório host?", + "Apply the options from the current catalog template? Your data and configuration are kept.": "Aplicar as opções do modelo de catálogo atual? Seus dados e configuração são mantidos.", "Applying AMD-specific fixes...": "Aplicando correções específicas da AMD...", "Applying Changes": "Aplicando alterações", "Applying Controller/NVMe passthrough to VM": "Aplicando passagem de controlador/NVMe à VM", @@ -244,12 +386,21 @@ "Applying passthrough to CT": "Aplicando passagem ao CT", "Applying safe paths and preparing pending restore": "Aplicando caminhos seguros e preparando restauração pendente", "Applying selected LXC switch action": "Aplicando ação de switch LXC selecionada", + "Applying the Jellyfin configuration:": "Aplicando a configuração Jellyfin:", + "Applying the LAN address to the application URLs...": "Aplicando o endereço LAN aos URLs da aplicação...", + "Applying the initial Nextcloud settings...": "Aplicando as configurações iniciais do Nextcloud...", + "Applying the mount mode...": "Aplicando o modo de montagem...", + "Apprise-api Takes advantage of Apprise through your network with a user-friendly API.": "Aparecer- api Aproveite o apprise através de sua rede com uma API amigável.", + "Architecture": "Arquitetura", + "Architecture:": "Arquitetura:", + "Architectures": "Arquiteturas", "Archive deleted.": "Arquivo excluído.", "Archive extracted.": "Arquivo extraído.", "Archive format": "Formato de arquivo", "Archive ready": "Arquivo pronto", "Archive size:": "Tamanho do arquivo:", "Archive:": "Arquivo:", + "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers.": "O Ardour é um esforço colaborativo aberto de uma equipe mundial, incluindo músicos, programadores e engenheiros profissionais de gravação.", "Are you absolutely sure?": "Você tem certeza absoluta?", "Are you sure you want to continue?": "Tem certeza de que deseja continuar?", "Are you sure you want to delete this export?": "Tem certeza de que deseja excluir esta exportação?", @@ -261,6 +412,7 @@ "Are you sure you want to unmount this NFS share?": "Tem certeza de que deseja desmontar este compartilhamento NFS?", "Are you sure you want to unmount this Samba share?": "Tem certeza de que deseja desmontar este compartilhamento do Samba?", "Are you sure?": "Tem certeza?", + "Arr suite: applications to install": "Arr suite: aplicações a instalar", "As Proxmox storage": "Como armazenamento Proxmox", "As host fstab mount only": "Apenas como host fstab mount", "Assign GPU PCI function to VM": "Atribuir função GPU PCI à VM", @@ -275,14 +427,19 @@ "Attach imported disk to VM": "Anexe o disco importado à VM", "Attach to an existing PVE vzdump job (inherit schedule + retention)": "anexar a um trabalho PVE vzdump existente (herdar cronograma + retenção)", "Attached to PVE job:": "Anexado ao trabalho PVE:", + "Attaching the volumes...": "A anexar os volumes...", "Attempting automatic repair...": "Tentando reparo automático...", "Attempting passthrough with this GPU typically results in": "A tentativa de passagem com esta GPU normalmente resulta em", "Attention: Removing the subscription banner may cause issues in the web interface after a future update.": "Atenção: A remoção do banner de assinatura pode causar problemas na interface web após uma atualização futura.", + "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source.": "Audacity é um editor e gravador de áudio de várias faixas fácil de usar. Desenvolvido por um grupo de voluntários como código aberto.", + "Audio device directory": "Directório do dispositivo de áudio", + "Audiobookshelf is a self-hosted audiobook and podcast server.": "Audiobookshelf é um servidor de áudio e podcast self-hosted.", "Audit completed. Press Enter to continue...": "Auditoria concluída. Pressione Enter para continuar...", "Audit socket disabled or not required": "soquete de auditoria desabilitado ou não necessário", "Auth key is required.": "A chave de autenticação é obrigatória.", "Auth:": "Autenticação:", "Authentication": "Autenticação", + "Authentication & Security": "Autenticação e Segurança", "Authentication Error": "Erro de autenticação", "Authentication failed.": "Falha na autenticação.", "Authentication required:": "Autenticação necessária:", @@ -301,7 +458,12 @@ "Auto-sync was not enabled": "A sincronização automática não foi ativada", "Automated Post-Install Script": "Script pós-instalação automatizado", "Automated post-installation script": "script de pós-instalação automatizado", + "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Gestor de Biblioteca de Vídeo Automático para Programas de TV. Ele assiste a novos episódios de seus programas favoritos, e quando eles são postados ele faz sua mágica.", + "Automatic detection": "Detecção automática", + "Automatic private network allocation requires a /24 subnet": "Alocação automática de rede privada requires a /24 subnet", + "Automatic video library manager for TV Shows": "Gerenciador automático de bibliotecas de vídeo para programas de TV", "Automatic/Unattended": "Automático/Autônomo", + "Automation & Scheduling": "Programação de Automação", "Available": "Disponível", "Available Borg archives (newest first):": "Arquivos Borg disponíveis (os mais recentes primeiro):", "Available Borg targets:": "Alvos Borg disponíveis:", @@ -322,17 +484,23 @@ "Available space in /mnt:": "Espaço disponível em /mnt:", "Available storage information:": "Informações de armazenamento disponíveis:", "Available storage volumes:": "Volumes de armazenamento disponíveis:", + "Azahar is an open-source 3DS emulator based on Citra.": "Azahar é um emulador 3DS de código aberto baseado no Citra.", "BIOS TYPE": "TIPO DE BIOS", "BIOS Type": "Tipo de BIOS", "BIOS from": "BIOS de", "BIOS: OVMF (UEFI)": "BIOS: OVMF (UEFI)", + "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications.": "BOINC é uma plataforma para computação de alto rendimento em grande escala (milhares ou milhões de computadores). Ele pode ser usado para computação voluntária (usando dispositivos de consumo) ou computação em grade (usando recursos organizacionais). Ele suporta aplicativos virtualizados, paralelos e baseados em GPU.", "BRIDGE CONFIGURATION ANALYSIS": "ANÁLISE DE CONFIGURAÇÃO DE PONTE", "BTRFS:": "BTRFS:", + "Baby Buddy web interface": "Interface web Baby Buddy", + "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work.": "Babybuddy é um amigo para bebês! Ajuda os cuidadores a rastrear sono, alimentação, mudança de fraldas, tempo de barriga e muito mais para aprender e prever as necessidades do bebê sem (tanto) adivinhar trabalho.", "Back to previous menu or Esc + Enter": "Voltar ao menu anterior ou Esc + Enter", "Backed up and cleared": "Backup e limpeza", "Backend": "Back-end", "Backend:": "Back-end:", + "Background archive extraction for Arr download queues. No web interface.": "Extração de arquivo de fundo para as filas de download do Arr. Sem interface web.", "Backup — VM and CT backups": "Backup – backups de VM e CT", + "Backup & Recovery": "Backup & Recuperação", "Backup Created": "Backup criado", "Backup ID (group name in PBS):": "ID de backup (nome do grupo no PBS):", "Backup ID for this job:": "ID de backup para este trabalho:", @@ -345,6 +513,7 @@ "Backup available at": "Backup disponível em", "Backup completed successfully.": "Backup concluído com sucesso.", "Backup completed:": "Backup concluído:", + "Backup created": "Cópia de segurança criada", "Backup created:": "Backup criado:", "Backup declares unused NICs that are not on this host:": "O backup declara NICs não utilizados que não estão neste host:", "Backup destination is inside the backup": "O destino do backup está dentro do backup", @@ -355,6 +524,7 @@ "Backup information": "Informações de backup", "Backup location": "Local de backup", "Backup metadata": "Metadados de backup", + "Backup of the previous installation verified": "Cópia de segurança da instalação anterior verificada", "Backup on newer kernel:": "Backup no kernel mais recente:", "Backup on older kernel:": "Backup no kernel mais antigo:", "Backup origin metadata:": "Metadados de origem do backup:", @@ -369,26 +539,42 @@ "Backup:": "Backup:", "Backups already on PBS were encrypted with the current key — downloading them will fail unless you first Download the current keyfile to keep a copy.": "Os backups já no PBS foram criptografados com a chave atual – o download deles falhará, a menos que você primeiro baixe o arquivo de chave atual para manter uma cópia.", "Backups already stored on PBS were encrypted with the current keyfile. After this action:": "Os backups já armazenados no PBS foram criptografados com o arquivo-chave atual. Após esta ação:", + "Backups verified": "Cópias de segurança verificadas", + "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience.": "O Bambu Studio é um software de corte aberto, de ponta, rico em recursos. Ele contém fluxos de trabalho baseados em projetos, algoritmos de corte sistematicamente otimizados e uma interface gráfica fácil de usar, trazendo aos usuários uma experiência de impressão incrivelmente suave.", "Bandwidth limit configured": "Limite de largura de banda configurado", "Bandwidth test (iperf3)": "teste de largura de banda (iperf3)", "Bandwidth test completed successfully": "Teste de largura de banda concluído com sucesso", "Base VM created with ID": "VM base criada com ID", + "Base VMID": "VMID base", + "Base VMID (empty = next free block)": "VMID base (vazio = próximo bloco livre)", + "Base VMID of Nextcloud (empty = next free block)": "VMID base de Nextcloud (vazio = próximo bloco livre)", + "Base VMID of Paperless (empty = next free block)": "VMID base de Paperless (vazio = próximo bloco livre)", + "Base VMID of Tandoor (empty = next free block)": "VMID base de Tandoor (vazio = próximo bloco livre)", + "Base VMID of the server (empty = next free block)": "VMID base do servidor (vazio = próximo bloco livre)", "Bash prompt path": "Caminho no prompt do Bash", "Bashrc customization completed": "Personalização do Bashrc concluída", "Basic Settings": "configurações básicas", "Basic Utilities": "Utilitários básicos", + "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you.": "Bazarr é uma aplicação complementar para Sonarr e Radarr. Ele pode gerenciar e baixar legendas com base em seus requirements. Você define suas preferências por programa de TV ou filme e o Bazarr cuida de tudo para você.", + "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools.": "Beets é um gestor de biblioteca de música e não, na sua maioria, um leitor de música. Ele inclui um simples plugin de jogador e um jogador experimental baseado na Web, mas geralmente deixa a reprodução de som real para ferramentas especializadas.", "Before making any changes, we'll create a safety backup.": "Antes de fazer qualquer alteração, criaremos um backup de segurança.", "Beta (develop branch)": "Beta (ramo de desenvolvimento)", "Beta version:": "Versão beta:", "Binary not found in extracted content.": "Binário não encontrado no conteúdo extraído.", "Bind mount added:": "Montagem de ligação adicionada:", + "Bind mounts are not included in vzdump": "As montagens de ligação não estão incluídas no vzdump", + "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services.": "Bitcoin Knots pode ser usado como um cliente desktop para pagamentos regulares ou como um utilitário servidor de nó completo para comerciantes e outros serviços de pagamento.", "Blacklist nouveau driver": "Colocar o driver nouveau na lista negra", "Blacklisting GPU host drivers...": "Colocando drivers de host de GPU na lista negra...", "Blacklisting nouveau driver...": "Colocando o driver nouveau na lista negra...", + "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**": "O Blender é um conjunto de ferramentas gratuitas e open-source de software de computação gráfica 3D usado para criar filmes animados, efeitos visuais, arte, modelos impressos em 3D, gráficos de movimento, aplicações 3D interativas, realidade virtual e jogos de computador. **Esta imagem não suporta renderização GPU fora da caixa apenas experiência de espaço de trabalho acelerada**", + "Blinko is an AI-powered card note-taking project. Designed for individuals who want to quickly capture and organize their fleeting thoughts. Blinko allows users to seamlessly jot down ideas the moment they strike, ensuring that no spark of creativity is lost.": "Blinko é um projeto de anotação de cartões movidos por IA. Projetado para indivíduos que querem capturar e organizar seus pensamentos fugazes. O Blinko permite que os usuários anotem perfeitamente as ideias no momento em que elas atingem, garantindo que nenhuma faísca de criatividade seja perdida.", "Blocked GPU ID": "ID da GPU bloqueada", "Blocked GPU ID for VM Mode": "ID de GPU bloqueado para modo VM", "Blocked device(s)": "Dispositivo(s) bloqueado(s)", "Blocked device(s):": "Dispositivo(s) bloqueado(s):", + "BookStack web interface": "Interface Web BookStack", + "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease.": "Bookstack é um Wiki livre e de código aberto projetado para criar documentação bonita. Com um editor WYSIWYG simples, mas poderoso, permite que as equipes criem documentação detalhada e útil com facilidade.", "Boot Disk": "Disco de inicialização", "Boot artifacts regenerated — reboot the host to activate the merged config.": "Artefatos de inicialização regenerados – reinicie o host para ativar a configuração mesclada.", "Boot disk:": "Disco de inicialização:", @@ -415,9 +601,13 @@ "Bridge:": "Ponte:", "Bridges analyzed": "Pontes analisadas", "Broken gasket-dkms package state recovered.": "O estado danificado do pacote gasket-dkms foi recuperado.", + "Browse Your Life in Images": "Navegue por sua vida em imagens", "Browse manually (advanced)...": "Navegar manualmente (avançado)...", + "Browsers & Web Desktops": "Navegadores e Ecrãs Web", "Build and install the gasket and apex kernel modules (DKMS)": "Compilar e instalar os módulos de kernel gasket e apex (DKMS)", "Build dependencies installed.": "Construa dependências instaladas.", + "Build your personal knowledge base with TriliumNext Notes": "Crie sua base de conhecimento pessoal com TriliumPróximos Notas", + "Business & ERP": "Negócios & ERP", "CHANGES APPLIED SUCCESSFULLY": "ALTERAÇÕES APLICADAS COM SUCESSO", "CIFS Client Tools: AVAILABLE": "Ferramentas de cliente CIFS: DISPONÍVEIS", "CIFS Client Tools: NOT AVAILABLE - installing...": "Ferramentas cliente CIFS: NÃO DISPONÍVEIS - instalando...", @@ -435,24 +625,35 @@ "CLUSTER UPGRADE NOTES:": "NOTAS DE ATUALIZAÇÃO DO CLUSTER:", "CONFIGURED INTERFACES": "INTERFACES CONFIGURADAS", "CONFIRM FORMAT": "CONFIRMAR FORMATO", + "CPU": "CPU", "CPU Cores": "Núcleos de CPU", "CPU MODEL": "MODELO DE CPU", "CPU Model": "Modelo de CPU", + "CPU cores": "Núcleos de CPU", + "CPU priority": "Prioridade da CPU", "CPU set to host,hidden=1,flags=+pcid": "CPU definida como host, oculto=1,flags=+pcid", "CPU vendor (intel/amd):": "Fornecedor de CPU (Intel/AMD):", "CRITICAL: The selected disk is referenced by a RUNNING VM or CT.": "CRÍTICO: O disco selecionado é referenciado por uma VM ou CT em RUNNING.", "CT": "TC", "CT started successfully.": "CT iniciado com sucesso.", + "CUDA requires a working NVIDIA driver": "CUDA requires um driver NVIDIA funcionando", + "CUDA requires the NVIDIA Container Toolkit on the host": "CUDA requires o kit de ferramentas do recipiente NVIDIA no host", + "Calculate all kinds of statistics from your (local) Emby or Jellyfin server": "Calcular todos os tipos de estatísticas do seu servidor Emby ou Jellyfin (local)", + "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts.": "Calibre é um gerenciador de e-book poderoso e fácil de usar. Os usuários dizem que é excelente e uma obrigação. Ele permitirá que você faça quase tudo e leva as coisas um passo além do software de e-book normal. Também é completamente livre e de código aberto e ótimo para usuários casuais e especialistas em informática.", + "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself.": "Calibre-web é um aplicativo web que oferece uma interface limpa para navegação, leitura e download de eBooks usando um banco de dados existente de Calibre. Também é possível integrar o Google Drive e editar metadados e sua biblioteca calibre através do próprio aplicativo.", + "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases.": "Calligra é uma suite de arte gráfica e de escritório do KDE. Está disponível para computadores desktop, tablets e smartphones. Ele contém aplicativos para processamento de texto, planilhas, apresentação, gráficos vetoriais e bancos de dados de edição.", "Cancel": "Cancelar", "Cancel restore": "Cancelar restauração", "Cancel this setup": "cancelar esta configuração", "Cancelled by user or empty URL.": "Cancelado pelo usuário ou URL vazio.", "Cancelled by user.": "Cancelado pelo usuário.", + "Cannot apply the Compose command:": "Não é possível aplicar o comando Compose:", "Cannot connect to server": "Não é possível conectar ao servidor", "Cannot continue": "Não é possível continuar", "Cannot create:": "Não é possível criar:", "Cannot detect filesystem on": "Não é possível detectar o sistema de arquivos em", "Cannot find": "Não foi possível encontrar", + "Cannot identify the vendor of the device:": "Não é possível identificar o fornecedor do dispositivo:", "Cannot load backup library: lib_host_backup_common.sh": "Não é possível carregar a biblioteca de backup: lib_host_backup_common.sh", "Cannot proceed with invalid export path.": "Não é possível prosseguir com caminho de exportação inválido.", "Cannot proceed with invalid share name.": "Não é possível continuar com um nome de compartilhamento inválido.", @@ -460,7 +661,11 @@ "Cannot reach download.proxmox.com. Check network, proxy or DNS.": "Não é possível acessar download.proxmox.com. Verifique a rede, proxy ou DNS.", "Cannot reach portal:": "Não é possível acessar o portal:", "Cannot reach server": "Sem contato com o servidor", + "Cannot read": "Não foi possível ler", + "Cannot read the OCI archive:": "Não foi possível ler o arquivo OCI:", "Cannot validate credentials - no shares available for testing.": "Não é possível validar credenciais – não há compartilhamentos disponíveis para teste.", + "Cannot verify the reused disk:": "Não foi possível verificar o disco reutilizado:", + "Capabilities cannot be kept and all dropped at the same time": "Capacidades não podem ser mantidas e todas retiradas ao mesmo tempo", "Category": "Categoria", "Caution: Maximum mode generates more heat.": "Cuidado: O modo máximo gera mais calor.", "Ceph check skipped by user flag (--ignore-ceph-check)": "Verificação do Ceph ignorada pelo sinalizador do usuário (--ignore-ceph-check)", @@ -487,14 +692,23 @@ "Ceph repository configured for PVE 9": "Repositório Ceph configurado para PVE 9", "Ceph repository signature verification failed; installation has been stopped": "falha na verificação da assinatura do repositório Ceph;a instalação foi interrompida", "Ceph version OK:": "Versão do Ceph OK:", + "Certificate errors are logged in /config/log/letsencrypt inside the container.": "Os erros do certificado são logados em /config/log/letsencrypt dentro do recipiente.", "Certificate fingerprint of the PBS server:": "Impressão digital do certificado do servidor PBS:", + "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL": "Fornecedor de certificado: vazio para Vamos criptografar, zerossl para ZeroSSL", + "Change GPU acceleration?": "Mudar a aceleração da GPU?", "Change Language": "Alterar idioma", "Change Release Channel": "Alterar canal de lançamento", + "Change it after the first login.": "Altere- o após o primeiro login.", + "Change or add an environment variable?": "Mudar ou adicionar uma variável de ambiente?", + "Change the access network?": "Mudar a rede de acesso?", + "Changedetection.io provides free, open-source web page monitoring, notification and change detection.": "O Changedetection.io oferece monitoramento gratuito de página de código aberto, notificação e detecção de alterações.", "Changes applied. A system reboot is recommended for them to take full effect.": "Alterações aplicadas. Recomenda-se uma reinicialização do sistema para que tenham efeito total.", "Changes have been applied to the configuration file.": "As alterações foram aplicadas ao arquivo de configuração.", "Changes will apply after reboot.": "As alterações serão aplicadas após a reinicialização.", "Changing Release Channel": "Alterando o canal de lançamento", "Changing the machine type on an existing installed VM is not safe: it changes the chipset and PCI slot layout, which typically prevents the guest OS from booting.": "Alterar o tipo de máquina em uma VM instalada existente não é seguro: isso altera o layout do chipset e do slot PCI, o que normalmente impede a inicialização do sistema operacional convidado.", + "Changing the rootfs or its storage requires a separate migration": "Alterando os rootfs ou seu requires de armazenamento uma migração separada", + "Changing the storage or size of a disk requires a migration; empty disks are not created": "A alteração do tamanho ou armazenamento de um disco requires uma migração; discos vazios não são criados", "Check": "Verificar", "Check BIOS/UEFI in Hardware > BIOS — must match what the original VM used": "Verifique BIOS/UEFI em Hardware > BIOS — deve corresponder ao que a VM original usou", "Check Coral USB/M.2 detection": "Verifique a detecção Coral USB/M.2", @@ -520,6 +734,7 @@ "Check the service status manually if needed.": "Verifique o status do serviço manualmente, se necessário.", "Checking MOTD configuration...": "Verificando a configuração do MOTD...", "Checking NVIDIA driver status with nvidia-smi": "Verificando o status do driver NVIDIA com nvidia-smi", + "Checking OCI": "Verificando OCI", "Checking VFIO modules...": "Verificando módulos VFIO...", "Checking VM virtual display model...": "Verificando o modelo de exibição virtual da VM...", "Checking ZFS autotrim configuration...": "Verificando a configuração do ajuste automático do ZFS...", @@ -531,7 +746,22 @@ "Checking if the server belongs to OVH...": "Verificando se o servidor pertence à OVH...", "Checking kernel headers and build tools...": "Verificando cabeçalhos do kernel e ferramentas de construção...", "Checking remaining interfaces": "Verificando interfaces restantes", + "Checking that the container keeps running...": "A verificar se o contentor continua a funcionar...", "Checking that this version builds against the running kernel...": "Verificando se esta versão é construída no kernel em execução...", + "Checking the GPU of the machine learning container...": "Verificando a GPU do recipiente de aprendizado de máquina...", + "Checking the container before recreating it...": "Verificando o recipiente antes de recriar...", + "Checking the container before the update...": "A verificar o contentor antes da actualização...", + "Checking the device permissions for the application user...": "Verificando as permissões do dispositivo para o usuário da aplicação...", + "Checking the image compatibility:": "Verificando a compatibilidade da imagem:", + "Checking the image in the registry...": "Verificando a imagem no registro...", + "Checking the interrupted operation...": "A verificar a operation interrompida...", + "Checking the interrupted stack operation...": "Verificando a pilha interrompida operation...", + "Checking the new image without starting it:": "Verificando a nova imagem sem iniciar:", + "Checking the remote...": "A verificar o comando...", + "Checking the restored installation": "Verificando a instalação restaurada", + "Checking the restored installation...": "Verificando a instalação restaurada...", + "Checking the stack before the update...": "Verificando a pilha antes da atualização...", + "Checking the updated stack...": "Verificando a pilha atualizada...", "Checklist post-upgrade finished. Warnings:": "Lista de verificação pós-atualização concluída. Avisos:", "Checklist pre-check finished. Warnings:": "Pré-verificação da lista de verificação concluída. Avisos:", "Checks for LVM and storage issues": "Verifica problemas de LVM e armazenamento", @@ -588,6 +818,9 @@ "Choose the type of virtual system to install:": "Escolha o tipo de sistema virtual a ser instalado:", "Choose what to do with the selected disk:": "Escolha o que fazer com o disco selecionado:", "Choose where to save the backup:": "Escolha onde salvar o backup:", + "Chrome is the official web browser from Google, built to be fast, secure, and customizable.": "Chrome é o navegador oficial do Google, construído para ser rápido, seguro e personalizável.", + "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.": "Chromium é um projeto de navegador de código aberto que visa construir uma maneira mais segura, rápida e estável para todos os usuários experimentarem a web.", + "Circular dependency:": "Dependência circular:", "Clean disk metadata": "Limpar metadados do disco", "Cleaned up": "Limpo", "Cleaning cached files...": "Limpando arquivos em cache...", @@ -611,21 +844,30 @@ "Clearing login credentials...": "Limpando credenciais de login...", "Client (run a bandwidth test to a server)": "Cliente (execute um teste de largura de banda em um servidor)", "Client determines best version to use": "O cliente determina a melhor versão a ser usada", + "Clients reach the VPN through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Os clientes chegam à VPN através do endereço público e da porta UDP fornecida durante a instalação, de modo que a porta deve ser encaminhada para este recipiente.", "Cloning Coral driver repository (feranick fork)...": "Clonando repositório de driver Coral (feranick fork)...", "Cloning Lynis from GitHub...": "Clonando Lynis do GitHub...", "Cloning and applying NVIDIA patch (keylase/nvidia-patch)...": "Clonando e aplicando patch NVIDIA (keylase/nvidia-patch)...", "Closed": "Fechado", + "Cloud Database Manager.": "Gerenciador de banco de dados em nuvem.", + "Cloud storage synchronization and FUSE mounts": "Sincronização de armazenamento em nuvem e montagem FUSE", "Cloud-Init Automated Installers": "Instaladores automatizados Cloud-Init", "Cluster certificates updated": "Certificados de cluster atualizados", "Cluster configuration (advanced)": "Configuração de cluster (avançado)", "Cluster data will be applied automatically at next boot.": "os dados do cluster serão aplicados automaticamente na próxima inicialização.", "Cluster upgrade mode": "Modo de atualização de cluster", + "Code-server is VS Code running on a remote server, accessible through the browser.": "O servidor de código é VS Code em execução em um servidor remoto, acessível através do navegador.", + "CodeProject.AI Server": "CodeProject. AI Server", "Command": "Comando", + "Command override for an unknown service:": "Sobreposição de comandos para um serviço desconhecido:", "Commenting any residual Bookworm lines in *.list...": "Comentando quaisquer linhas residuais do Bookworm em *.list...", "Commenting legacy PVE 8 repository .list files (if any)...": "Comentando arquivos .list do repositório PVE 8 legado (se houver)...", "Commenting legacy ceph.list (if present)...": "Comentando legado ceph.list (se presente)...", "Common Issues Check": "Verificação de problemas comuns", + "Common root for the published views": "Raiz comum das opiniões publicadas", + "Communication & Community": "Comunicação & Comunidade", "Community Scripts": "Scripts da comunidade", + "Community single-container Home Assistant OS image": "Imagem do sistema operacional Home Assistant para um único recipiente comunitário", "Compatibility check": "Verificação de compatibilidade", "Compatibility check — OK": "Verificação de compatibilidade – OK", "Compatibility check — issues detected": "Verificação de compatibilidade – problemas detectados", @@ -640,24 +882,31 @@ "Complete restore": "Restauração completa", "Complete the DSM installation wizard": "Conclua o assistente de instalação do DSM", "Complete the ZimaOS installation wizard": "Conclua o assistente de instalação do ZimaOS", + "Complete the media server and Seerr accounts, the Bazarr providers and the SABnzbd Usenet credentials when they are selected.": "Complete o servidor de mídia e contas Seerr, os provedores Bazarr e o SABnzbd Usenet credentials quando forem selecionados.", + "Completed": "Concluído", "Completed Successfully with GPU passthrough configured!": "Concluído com sucesso com passagem de GPU configurada!", "Completed Successfully!": "Concluído com sucesso!", "Completed with errors —": "Concluído com erros -", "Completed.": "Concluído.", "Completed. Devices added to VM {vmid}: {count}.": "Concluído. Dispositivos adicionados à VM {vmid}: {count}.", "Completed. Press Enter to return to menu...": "Concluído. Pressione Enter para retornar ao menu...", + "Completing its final cleanup...": "Completando sua limpeza final...", "Completing pending package configurations...": "Concluindo configurações de pacotes pendentes...", "Compliance checking (PCI-DSS, HIPAA, etc.)": "Verificação de conformidade (PCI-DSS, HIPAA, etc.)", "Component to uninstall manually (no --auto-uninstall yet):": "Componente a ser desinstalado manualmente (ainda sem --auto-uninstall):", "Component was installed on the backup source but no matching hardware was found on this host.": "O componente foi instalado na origem do backup, mas nenhum hardware correspondente foi encontrado neste host.", "Component:": "Componente:", "Components to uninstall (manual for now):": "Componentes a serem desinstalados (manual por enquanto):", + "Compose capabilities validated in the LXC user namespace:": "Compor capacidades validadas no espaço de nomes de utilizador LXC:", + "Compose file of the application": "Compor o ficheiro da aplicação", + "Compose file of this host": "Compor o ficheiro desta máquina", "Compressed size:": "Tamanho compactado:", "Compressing": "Comprimindo", "Compression Tools": "Ferramentas de compressão", "Concise output of logical volumes": "Saída concisa de volumes lógicos", "Concise output of physical volumes": "Saída concisa de volumes físicos", "Concise output of volume groups": "Saída concisa de grupos de volumes", + "Concurrent change while restoring the start at boot setting": "Alteração simultânea ao restaurar o início na configuração de arranque", "Configuration Analysis": "Análise de configuração", "Configuration Menu": "Menu de configuração", "Configuration Summary:": "Resumo da configuração:", @@ -666,11 +915,13 @@ "Configuration can continue now and will be effective after reboot.": "A configuração pode continuar agora e entrará em vigor após a reinicialização.", "Configuration completed successfully!": "Configuração concluída com sucesso!", "Configuration file for container": "Arquivo de configuração para contêiner", + "Configuration files generated:": "Arquivos de configuração gerados:", "Configuration has been stopped due to high reset risk.": "A configuração foi interrompida devido ao alto risco de reinicialização.", "Configuration has been stopped to prevent an unusable VM state.": "A configuração foi interrompida para evitar um estado de VM inutilizável.", "Configuration has been stopped to prevent leaving the VM in an unusable state.": "A configuração foi interrompida para evitar deixar a VM em estado inutilizável.", "Configuration name:": "Nome da configuração:", "Configuration sections that will be REMOVED": "Seções de configuração que serão REMOVIDAS", + "Configuration size in GB": "Tamanho da configuração em GB", "Configuration to be Removed": "Configuração a ser removida", "Configuration will continue now and be effective after reboot.": "A configuração continuará agora e entrará em vigor após a reinicialização.", "Configuration:": "Configuração:", @@ -713,6 +964,7 @@ "Configuring Proxmox jail...": "Configurando a prisão do Proxmox...", "Configuring TCP optimizations...": "Configurando otimizações de TCP...", "Configuring TPM device": "Configurando o dispositivo TPM", + "Configuring Unpackerr...": "Configurando o Unpackerr...", "Configuring VFIO modules...": "Configurando módulos VFIO...", "Configuring VM": "Configurando VM", "Configuring bandwidth limit for vzdump...": "Configurando limite de largura de banda para vzdump...", @@ -728,8 +980,11 @@ "Configuring max FD limit / ulimit...": "Configurando limite máximo de FD/ulimit...", "Configuring max user watches...": "Configurando o máximo de relógios de usuários...", "Configuring pigz as a faster replacement for gzip...": "Configurando o pigz como um substituto mais rápido para o gzip...", + "Configuring qBittorrent...": "Configurando o qBittorrent...", "Configuring snapshot schedules...": "Configurando programações de snapshots...", "Configuring system time settings...": "Configurando as configurações de hora do sistema...", + "Configuring the Radarr root folder...": "A configurar a pasta raiz do Radarr...", + "Configuring the Sonarr root folder...": "A configurar a pasta raiz do Sonarr...", "Configuring vfio-pci binding...": "Configurando a ligação vfio-pci...", "Confirm Borg passphrase": "Confirme a senha Borg", "Confirm Borg passphrase:": "Confirme a senha Borg:", @@ -751,6 +1006,7 @@ "Confirm export": "Confirmar exportação", "Confirm password for": "Confirme a senha para", "Confirm recovery passphrase:": "Confirme a senha de recuperação:", + "Confirm that host data is not reverted": "Confirmar que os dados da máquina não são revertidos", "Confirm the keyfile passphrase:": "Confirme a senha do arquivo-chave:", "Confirm the mount path is visible.": "Confirme se o caminho de montagem está visível.", "Confirm the password:": "Confirme a senha:", @@ -762,7 +1018,11 @@ "Conflicting path included in backup:": "Caminho conflitante incluído no backup:", "Conflicting utilities removed": "Utilitários conflitantes removidos", "Connect a Coral Accelerator and try again.": "Conecte um Coral Accelerator e tente novamente.", + "Connect your devices and users together in your own secure virtual private network.": "Conecte seus dispositivos e usuários em sua própria rede privada virtual segura.", + "Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.": "Conecte seus dispositivos a uma rede segura de sobreposição WireGuard® com controles de acesso SSO, MFA e granular.", "Connected": "Conectado", + "Connecting Radarr to qBittorrent...": "Ligando Radarr ao qBittorrent...", + "Connecting Sonarr to qBittorrent...": "Ligando Sonarr ao qBittorrent...", "Connecting to PBS and starting backup...": "Conectando ao PBS e iniciando o backup...", "Connection Details:": "Detalhes de conexão:", "Connection Error": "Erro de conexão", @@ -774,6 +1034,7 @@ "Consider removing its configuration": "Considere remover sua configuração", "Consider security implications for production environments": "Considere as implicações de segurança para ambientes de produção", "Consider visiting the repository and supporting the project.": "Considere visitar o repositório e apoiar o projeto.", + "Console log:": "Registo da consola:", "Container": "Recipiente", "Container — LXC root directories": "Container - diretórios raiz LXC", "Container ID": "ID do contêiner", @@ -783,30 +1044,50 @@ "Container Path": "Caminho do contêiner", "Container Path:": "Caminho do contêiner:", "Container Status": "Status do contêiner", + "Container checked": "Container verificado", "Container configuration not found": "Configuração do contêiner não encontrada", + "Container configured (not started):": "Container configurado (não iniciado):", + "Container converted to privileged": "Container convertido em privilegiado", + "Container created:": "Container criado:", "Container did not become ready in time. Skipping driver installation.": "O contêiner não ficou pronto a tempo. Ignorando a instalação do driver.", "Container did not start in time.": "O contêiner não começou a tempo.", "Container distro": "Distribuição de contêiner", "Container does not have apt-get available. Coral driver installation only supports Debian/Ubuntu containers.": "O contêiner não tem o apt-get disponível. A instalação do driver Coral suporta apenas contêineres Debian/Ubuntu.", + "Container installed, but without a verifiable record for future updates.": "Container instalado, mas sem um registro verificável para futuras atualizações.", "Container is already stopped.": "O contêiner já está parado.", "Container is running. Restart to apply changes?": "O contêiner está em execução. Reiniciar para aplicar as alterações?", "Container is stopped. Start it now to verify the mount works?": "O contêiner está parado. Iniciá-lo agora para verificar se a montagem funciona?", + "Container kept with its data; the installation was not validated:": "Container mantido com seus dados; a instalação não foi validada:", "Container mount point:": "Ponto de montagem do contêiner:", "Container must be stopped before conversion": "O contêiner deve ser parado antes da conversão", + "Container prepared for the stack:": "Container preparado para a pilha:", + "Container recreated": "Container recriado", + "Container removed:": "Container removido:", "Container restarted successfully": "Contêiner reiniciado com sucesso", + "Container running steadily": "Container em funcionamento constante", + "Container started": "Container iniciado", "Container started successfully": "Contêiner iniciado com sucesso", "Container started successfully.": "O contêiner foi iniciado com sucesso.", "Container started.": "Contêiner iniciado.", + "Container stopped": "Container parado", "Container stopped.": "Contêiner parado.", "Container successfully converted to privileged.": "Contêiner convertido com sucesso em privilegiado.", "Container template— LXC templates": "Modelo de contêiner - modelos LXC", + "Container volume": "Volume do recipiente", + "Container volume (included in backups)": "Volume do recipiente (incluído em backups)", "Container will pick up the mount on next start": "O contêiner pegará a montagem na próxima partida", "Container with ID": "Contêiner com ID", "Container:": "Recipiente:", + "Containers & Docker": "Containers e Docker", + "Containers returned to their previous state": "Os contentores voltaram ao seu estado anterior", + "Containers that are removed:": "Recipientes que são removidos:", + "Containers that will be created (one LXC per service, on a private network):": "Containers que serão criados (um LXC por serviço, em uma rede privada):", + "Containers:": "Contentores:", "Contains files": "Contém arquivos", "Contains:": "Contém:", "Content Types": "Tipos de conteúdo", "Content Types:": "Tipos de conteúdo:", + "Content collaboration platform": "Plataforma de colaboração de conteúdo", "Content is usually images for VM block devices.": "O conteúdo geralmente consiste em imagens para dispositivos de bloco VM.", "Content type is fixed to:": "O tipo de conteúdo é fixado em:", "Content:": "Contente:", @@ -817,10 +1098,12 @@ "Continue the Windows installation as usual.": "Continue a instalação do Windows normalmente.", "Continue with Coral TPU configuration only?": "Continuar apenas com a configuração do Coral TPU?", "Continue with live apply now? SSH may disconnect immediately.": "Continuar com a inscrição ao vivo agora? O SSH pode ser desconectado imediatamente.", + "Continue with the experimental HAOS One profile?": "Continuar com o perfil experimental HAOS One?", "Continue with the import?": "Continuar com a importação?", "Continue: Proceed with conversion": "Continuar: Prossiga com a conversão", "Continue?": "Continuar?", "Continuing with your selection.": "Continuando com sua seleção.", + "Contradictory tmpfs options": "Opções contradictory tmpfs", "Controller": "Controlador", "Controller + NVMe": "Controlador + NVMe", "Controller + NVMe assignment will be written now and become active after host reboot.": "A atribuição de controlador + NVMe será gravada agora e se tornará ativa após a reinicialização do host.", @@ -849,7 +1132,11 @@ "Converting disk": "Convertendo disco", "Converting file ownership (this may take several minutes)...": "Convertendo a propriedade do arquivo (isso pode levar alguns minutos)...", "Converting image using command:": "Convertendo imagem usando o comando:", + "Converting the container to privileged...": "Convertendo o contentor para...", "Converts to deb822; keeps .list backups as .bak": "Converte para deb822; mantém backups .list como .bak", + "Coordinated backups require zstd": "Backups coordenados require zstd", + "Cops by Sébastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server.": "Cops por Sébastien Lucas, agora mantido por MikesPub, significa Calibre OPDS (e HTML) Php Server.", + "Copy a peer configuration to the host with: pct pull /config/peer1/peer1.conf peer1.conf": "Copiar uma configuração por pares para a máquina com: pct pull /config/peer1/peer1.conf peer1.conf", "Copy failed": "Falha na cópia", "Copy that file offsite yourself, or download it from the Monitor.": "Copie você mesmo esse arquivo fora do local ou baixe-o do Monitor.", "Copy the correct keyfile to this host and rerun Restore — or pick an unencrypted backup.": "Copie o arquivo-chave correto para este host e execute novamente a Restauração – ou escolha um backup não criptografado.", @@ -864,6 +1151,7 @@ "Coral M.2 Apex configuration added - device ready": "Configuração Coral M.2 Apex adicionada - dispositivo pronto", "Coral M.2 Apex configuration added - device will be available after reboot": "Configuração Coral M.2 Apex adicionada - o dispositivo estará disponível após a reinicialização", "Coral M.2 Apex detected, configuring...": "Coral M.2 Apex detectado, configurando...", + "Coral PCIe/M.2 node (e.g. /dev/apex_0)": "Nó Coral PCIe/M.2 (por exemplo, /dev/apex 0)", "Coral TPU Installation": "Instalação Coral TPU", "Coral TPU Uninstall": "Desinstalação do Coral TPU", "Coral TPU device nodes detected with correct group (apex).": "Nós do dispositivo Coral TPU detectados com o grupo correto (apex).", @@ -876,19 +1164,33 @@ "Coral USB configured but device not currently connected": "Coral USB configurado, mas o dispositivo não está conectado no momento", "Coral USB runtime installed. No reboot required.": "Tempo de execução Coral USB instalado. Não é necessária reinicialização.", "Coral hardware configuration completed for container": "Configuração de hardware Coral concluída para contêiner", + "Coral is only offered for Frigate and CodeProject.AI": "Coral é oferecido apenas para Frigate e CodeProject. IA", "Coral kernel modules unloaded.": "Módulos do kernel Coral descarregados.", "Coral packages purged.": "Pacotes Coral eliminados.", "Coral uninstallation completed.": "Desinstalação do Coral concluída.", "Core Proxmox packages reinstalled successfully": "Pacotes principais do Proxmox reinstalados com sucesso", + "Core is running, but not responding over HTTP on 80/8123": "O núcleo está em execução, mas não está respondendo sobre HTTP em 80/8123", + "Core is still on the initial installation page": "O núcleo ainda está na página de instalação inicial", "Core packages": "Pacotes principais", + "Cores": "Cores", + "Corrupted gzip layer": "Camada gzip corrompida", "Could not add": "Não foi possível adicionar", "Could not add disk": "Não foi possível adicionar o disco", + "Could not add the device to the container:": "Não foi possível adicionar o dispositivo ao recipiente:", + "Could not add the mount point:": "Não foi possível adicionar o ponto de montagem:", + "Could not apply the Compose extra hosts": "Não foi possível aplicar as máquinas extras", + "Could not apply the Compose supplementary groups": "Não foi possível aplicar os grupos complementares Compose", + "Could not apply the Jellyfin configuration:": "Não foi possível aplicar a configuração do Jellyfin:", + "Could not apply the installer profile": "Não foi possível aplicar o perfil do instalador", + "Could not apply the pre-start repair:": "Não foi possível aplicar o reparo pré-inicial:", "Could not assign disk": "Não foi possível atribuir o disco", "Could not authorize the key via 'pct exec' on": "Não foi possível autorizar a chave via 'pct exec' em", "Could not back up the existing auth.json": "Não foi possível fazer backup do auth.json existente", "Could not change VM virtual display to vga: std": "Não foi possível alterar a exibição virtual da VM para vga: std", + "Could not check the NVIDIA GPU": "Não foi possível verificar a GPU NVIDIA", "Could not clone any gasket-driver repository. Check your internet connection and": "Não foi possível clonar um repositório gasket-driver. Verifique a ligação à Internet e", "Could not configure IOMMU kernel parameters automatically. Configure manually and reboot.": "Não foi possível configurar os parâmetros do kernel IOMMU automaticamente. Configure manualmente e reinicie.", + "Could not convert the OCI rootfs to privileged": "Não foi possível converter os rootfs do OCI para privilegiado", "Could not copy the PVE keyfile into place. Check permissions on:": "Não foi possível copiar o arquivo-chave PVE no lugar. Verifique as permissões em:", "Could not copy the keyfile into place.": "Não foi possível copiar o arquivo-chave no lugar.", "Could not copy the keyfile into place. Check permissions on:": "Não foi possível copiar o arquivo-chave no lugar. Verifique as permissões em:", @@ -898,6 +1200,9 @@ "Could not create or access directory:": "Não foi possível criar ou acessar o diretório:", "Could not create temporary directory:": "Não foi possível criar o diretório temporário:", "Could not create temporary working directory.": "Não foi possível criar um diretório de trabalho temporário.", + "Could not create the container:": "Não foi possível criar o recipiente:", + "Could not create the initial administrator": "Não foi possível criar o administrador inicial", + "Could not create the service:": "Não foi possível criar o serviço:", "Could not detect apex major number from /proc/devices. Load the apex module first: modprobe apex": "Não foi possível detectar o número principal do ápice em /proc/devices. Carregue o módulo apex primeiro: modprobe apex", "Could not detect the CIFS mount for this directory. Try accessing it manually.": "Não foi possível detectar a montagem CIFS para este diretório. Tente acessá-lo manualmente.", "Could not determine a valid ISO storage directory.": "Não foi possível determinar um diretório de armazenamento ISO válido.", @@ -907,7 +1212,9 @@ "Could not download recovery blob from PBS.": "Não foi possível baixar o blob de recuperação do PBS.", "Could not download the NVIDIA Container Toolkit repository definition.": "não foi possível baixar a definição do repositório NVIDIA Container Toolkit.", "Could not download the NVIDIA Container Toolkit signing key.": "Não foi possível baixar a chave de assinatura do NVIDIA Container Toolkit.", + "Could not download the image": "Não foi possível baixar a imagem", "Could not download the installer.": "Não foi possível baixar o instalador.", + "Could not enable the privileged profile before the first start": "Não foi possível habilitar o perfil privilegiado antes do primeiro início", "Could not export ZFS pool": "Não foi possível exportar o pool ZFS", "Could not extract from PBS.": "Não foi possível extrair do PBS.", "Could not fetch keylase/nvidia-patch supported list — patch reapply compatibility is not verified.": "Não foi possível buscar a lista compatível com keylase/nvidia-patch — a compatibilidade de reaplicação do patch não foi verificada.", @@ -921,34 +1228,53 @@ "Could not install exFAT tools automatically.": "Não foi possível instalar as ferramentas exFAT automaticamente.", "Could not install sshpass automatically (no internet?). Falling back to manual paste mode — you'll see the line to copy onto the server next.": "Não foi possível instalar o sshpass automaticamente (sem internet?).Voltando ao modo de colagem manual - você verá a próxima linha para copiar no servidor.", "Could not install the NVIDIA Container Toolkit signing key.": "Não foi possível instalar a chave de assinatura do NVIDIA Container Toolkit.", + "Could not install the required packages:": "Não foi possível instalar os pacotes required:", + "Could not install the stack startup hook": "Não foi possível instalar o gancho de inicialização da pilha", "Could not install vzdump hook in /etc/vzdump.conf": "Não foi possível instalar o gancho vzdump em /etc/vzdump.conf", "Could not load shared functions. Script cannot continue.": "Não foi possível carregar funções compartilhadas. O script não pode continuar.", + "Could not load the host kernel module:": "Não foi possível ler o módulo do kernel da máquina:", "Could not locate imported disk in VM config.": "Não foi possível localizar o disco importado na configuração da VM.", "Could not mount": "Não foi possível montar", "Could not mount ISO on device": "Não foi possível montar o ISO no dispositivo", + "Could not mount the container filesystem:": "Não foi possível montar o sistema de ficheiros do contentor:", + "Could not obtain an intact image after two attempts": "Não foi possível obter uma imagem intacta após duas tentativas", "Could not parse OVF file, or no disk image references found.": "Não foi possível analisar o arquivo OVF ou nenhuma referência de imagem de disco foi encontrada.", "Could not prepare on-boot restore service. Nothing new was scheduled.": "Não foi possível preparar o serviço de restauração na inicialização. Nada de novo foi programado.", + "Could not prepare the NVIDIA driver links": "Não foi possível preparar os links do driver NVIDIA", + "Could not prepare the file bind mount target:": "Não foi possível preparar o ficheiro de ligação ao alvo de montagem:", "Could not publish pending restore. Previous pending restore was kept.": "não foi possível publicar a restauração pendente. A restauração pendente anterior foi mantida.", "Could not push the key. Check the password and that": "Não foi possível pressionar a chave. Verifique a senha e isso", + "Could not query the image registry": "Não foi possível consultar o registro de imagem", "Could not read SMART data from": "Não foi possível ler os dados SMART de", "Could not read VM configuration.": "Não foi possível ler a configuração da VM.", + "Could not read the CUDA compute capability": "Não foi possível ler a capacidade de computação do CUDA", + "Could not read the NVIDIA driver version": "Não foi possível ler a versão do driver NVIDIA", "Could not remount automatically. Try manually or check credentials.": "Não foi possível remontar automaticamente. Tente manualmente ou verifique as credenciais.", "Could not remove VM automatically. Run manually:": "Não foi possível remover a VM automaticamente. Execute manualmente:", "Could not remove previous DKMS tree at": "Não foi possível remover a árvore DKMS anterior em", + "Could not reserve a private network for the stack": "Não foi possível reservar uma rede privada para a pilha", + "Could not resolve the Compose user:": "Não foi possível resolver o usuário Compose:", + "Could not resolve the OCI manifest of the image:": "Não foi possível resolver o manifesto OCI da imagem:", + "Could not resolve the OCI manifest:": "Não foi possível resolver o manifesto OCI:", "Could not restart ProxMenux Monitor service.": "Não foi possível reiniciar o serviço ProxMenux Monitor.", "Could not restart the service — start it manually with systemctl start": "Não foi possível reiniciar o serviço – inicie-o manualmente com systemctl start", "Could not retrieve versions list from NVIDIA. Please check your internet connection.": "Não foi possível recuperar a lista de versões da NVIDIA. Verifique sua conexão com a Internet.", + "Could not reuse the persistent disk:": "Não foi possível reutilizar o disco persistente:", "Could not run NVIDIA patch script. Please verify repository and driver version.": "Não foi possível executar o script de patch da NVIDIA. Verifique o repositório e a versão do driver.", "Could not set VM virtual display to vga: std": "Não foi possível definir a exibição virtual da VM como vga: std", "Could not set boot order for": "Não foi possível definir a ordem de inicialização para", + "Could not set the container entrypoint": "Não foi possível definir o ponto de entrada do recipiente", "Could not stage pending restore path:": "Não foi possível preparar o caminho de restauração pendente:", "Could not stage pending restore. Nothing new was scheduled.": "não foi possível preparar a restauração pendente. Nada de novo foi programado.", "Could not stop LXC": "Não foi possível parar o LXC", + "Could not translate the Compose command/entrypoint": "Não foi possível traduzir o comando/ponto de entrada Compose", "Could not unload nouveau module (may be in use). The blacklist will take effect after reboot. Installation will continue but a reboot will be required.": "Não foi possível descarregar o módulo nouveau (pode estar em uso). A lista negra entrará em vigor após a reinicialização. A instalação continuará, mas será necessária uma reinicialização.", "Could not unmount": "Não foi possível desmontar", + "Could not unmount the container filesystem:": "Não foi possível desmontar o sistema de arquivos do recipiente:", "Could not unmount — disk may be busy. Removing fstab entry anyway.": "Não foi possível desmontar — o disco pode estar ocupado. Removendo a entrada fstab de qualquer maneira.", "Could not update config file.": "Não foi possível atualizar o arquivo de configuração.", "Could not write to:": "Não foi possível escrever para:", + "Crafty Controller default login": "Login padrão do controlador Crafty", "Create Directory": "Criar diretório", "Create GPT and one partition:": "Crie GPT e uma partição:", "Create GPT partition": "Criar partição GPT", @@ -971,6 +1297,7 @@ "Create a fresh GPT + ext4 partition and mount it?": "Criar uma nova partição GPT + ext4 e montá-la?", "Create a new dataset in a ZFS pool": "Crie um novo conjunto de dados em um pool ZFS", "Create a new group for isolation": "Crie um novo grupo para isolamento", + "Create and edit Matroska files from a browser": "Criar e editar arquivos Matroska a partir de um navegador", "Create credentials file (recommended):": "Crie um arquivo de credenciais (recomendado):", "Create directory": "Criar diretório", "Create export directory:": "Crie o diretório de exportação:", @@ -982,6 +1309,7 @@ "Create scheduled backup job": "Criar tarefa de backup agendada", "Create share directory:": "Crie um diretório de compartilhamento:", "Create shared directory:": "Crie um diretório compartilhado:", + "Create this LXC in privileged mode?": "Criar este LXC em modo privilegiado?", "Created common remapped user": "Usuário remapeado comum criado", "Created directory on host:": "Diretório criado no host:", "Created persistent names for": "Nomes persistentes criados para", @@ -996,6 +1324,8 @@ "Creating UID remapping for unprivileged container compatibility...": "Criando remapeamento de UID para compatibilidade de contêiner sem privilégios...", "Creating VM with the above configuration": "Criando VM com a configuração acima", "Creating VM...": "Criando VM...", + "Creating a backup of": "Criar uma cópia de segurança de", + "Creating a backup of the container...": "Criando um backup do recipiente...", "Creating backup of configuration file...": "Criando backup do arquivo de configuração...", "Creating backup of network interfaces configuration...": "Criando backup da configuração das interfaces de rede...", "Creating compressed archive...": "Criando arquivo compactado...", @@ -1005,6 +1335,11 @@ "Creating partition table and partition...": "Criando tabela de partição e partição...", "Creating partition...": "Criando partição...", "Creating pigz wrapper script...": "Criando script wrapper pigz...", + "Creating the backup": "Criando o backup", + "Creating the container...": "A criar o contentor...", + "Creating the initial administrator...": "Criando o administrador inicial...", + "Creating the temporary data container": "Criando o recipiente de dados temporário", + "Creative & Design": "Desenho Criativo", "Credentials are correct": "As credenciais estão corretas", "Credentials cleared. jwt_secret and API tokens preserved.": "Credenciais apagadas. jwt_secret e tokens de API preservados.", "Credentials file created securely.": "Arquivo de credenciais criado com segurança.", @@ -1014,6 +1349,8 @@ "Cross-host restore: guest IDs in backup overlap live IDs on target:": "Restauração entre hosts: os IDs de convidados no backup se sobrepõem aos Live IDs no destino:", "Cross-kernel restore — kernel-tied paths merged, not copied": "Restauração entre kernels – caminhos vinculados ao kernel mesclados, não copiados", "Cross-kernel — paths hidden from picker": "Cross-kernel – caminhos ocultos do seletor", + "Cross-platform file sharing made easy.": "O compartilhamento de arquivos entre plataformas tornou-se fácil.", + "Cross-platform monitoring tool.": "Ferramenta de monitorização multiplataforma.", "Cross-version detected — safe restore mode": "Versão cruzada detectada – modo de restauração seguro", "Current": "Atual", "Current CIFS mounts:": "Montagens CIFS atuais:", @@ -1023,6 +1360,8 @@ "Current NFS client script supports privileged LXC only.": "O script do cliente NFS atual suporta apenas LXC privilegiado.", "Current NFS exports in CT": "Exportações atuais de NFS em CT", "Current NFS mounts:": "Montagens NFS atuais:", + "Current NVIDIA inventory resolved: a refresh is required": "Inventário NVIDIA atual resolvido: uma atualização é required", + "Current NVIDIA inventory resolved: no refresh is required": "Inventário NVIDIA atual resolvido: nenhuma atualização é required", "Current Network Configuration": "Configuração de rede atual", "Current PVE Version": "Versão atual do PVE", "Current ProxMenux host scripts register remote shares as Proxmox storages using pvesm.": "Os scripts atuais do host ProxMenux registram compartilhamentos remotos como armazenamentos Proxmox usando pvesm.", @@ -1046,6 +1385,7 @@ "Current user": "Usuário atual", "Current user UID, GID and groups": "UID, GID e grupos do usuário atual", "Current version:": "Versão atual:", + "Currently": "Atualmente", "Currently Mounted:": "Atualmente montado:", "Currently configured target:": "destino atualmente configurado:", "Currently mounted:": "Atualmente montado:", @@ -1066,6 +1406,7 @@ "Custom message added to MOTD": "Mensagem personalizada adicionada ao MOTD", "Custom options": "Opções personalizadas", "Custom path": "Caminho personalizado", + "Custom path cancelled": "Caminho personalizado cancelado", "Custom path...": "Caminho personalizado...", "Custom paths are included in BOTH default and custom backup profiles.": "Os caminhos personalizados estão incluídos em AMBOS os perfis de backup padrão e personalizados.", "Custom paths currently saved: {count}.": "caminhos personalizados salvos atualmente: {count}.", @@ -1078,6 +1419,8 @@ "Customization": "Personalização", "Customize bashrc": "Personalizar bashrc", "Customizing bashrc for root user...": "Personalizando o bashrc para usuário root...", + "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite.": "DB Browser for SQLite é uma ferramenta de alta qualidade, visual, código aberto para criar, projetar e editar arquivos de banco de dados compatíveis com SQLite.", + "DHCP (automatic)": "DHCP (automático)", "DISABLED unless you enable it": "DESATIVADO, a menos que você o habilite", "DKMS add failed. Check": "Falha na adição do DKMS. Verificar", "DKMS build failed.": "Falha na compilação do DKMS.", @@ -1090,15 +1433,34 @@ "DKMS registrations removed.": "registros DKMS removidos.", "DNS Resolution": "Resolução DNS", "DNS lookup for a domain": "Pesquisa de DNS para um domínio", + "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)": "Plug-in de DNS usado com validação de dns (nuvem, duckdns, ovh...)", + "DNS server written in the client configurations": "Servidor de DNS escrito nas configurações do cliente", + "DNS server written in the peer configurations (auto or an IP address)": "Servidor de DNS escrito nas configurações dos pares (automático ou endereço IP)", + "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid.": "DOGWALK é o tão esperado segundo projeto de jogo do Blender Studio, focado na criação de um playground interativo para contar histórias. Jogue como um grande cão adorável e explorar a floresta de inverno com uma criança.", + "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games.": "DOSBox Staging é uma continuação moderna do DOSBox um emulador livre e de código aberto que permite a execução de software MS-DOS, especialmente jogos de vídeo.", + "DVB device directory": "Directório do dispositivo DVB", + "Data": "Dados", + "Data location": "Localização dos dados", "Data size:": "Tamanho dos dados:", + "Data that is deleted with them:": "Dados que são suprimidos com eles:", + "Data volume size in GB": "Tamanho do volume de dados em GB", + "Data volumes protected": "Volumes de dados protegidos", "Data wipe complete.": "Limpeza de dados concluída.", "Data wiped from": "Dados apagados de", + "Database management in a single PHP file": "Gerenciamento de banco de dados em um único arquivo PHP", + "Database server proposed on the login page (empty = typed at each login)": "Servidor de banco de dados proposto na página de login (vazio = digitado em cada login)", + "Databases": "Bases de dados", "Datastore name:": "Nome do armazenamento de dados:", + "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow.": "Davos é uma ferramenta de automação FTP que periodicamente verifica locais de host para novos arquivos. Ele pode ser configurado para vários propósitos, incluindo ouvir arquivos específicos para aparecer no local do host, pronto para que ele baixe e então se mova, se required. Ele também suporta notificações de conclusão, bem como chamadas de API a jusante, para promover o fluxo de trabalho.", + "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways.": "Ddclient é um cliente Perl usado para atualizar entradas DNS dinâmicas para contas no DNS Network Service Provider dinâmico. Foi originalmente escrito por Paul Burry e agora é principalmente por wimpunk. Ele tem a capacidade de atualizar mais do que apenas dyndns e ele pode obter o seu WAN-ipaddress de algumas maneiras diferentes.", "Deactivate Monitor": "Desativar monitor", "Deactivate ProxMenux Monitor": "Desativar ProxMenux Monitor", "Debian repositories missing; creating default source file": "Repositórios Debian ausentes; criando arquivo fonte padrão", "Decompress backup manually": "Descompacte o backup manualmente", "Decryption failed. The passphrase may be wrong, or the blob is corrupt. Try again?": "A descriptografia falhou. A senha pode estar errada ou o blob está corrompido. Tentar novamente?", + "Dedicated container volume (included in backups)": "Volume dedicado do recipiente (incluído em backups)", + "Dedicated container volumes (included in backups)": "Volumes de contentores dedicados (incluídos em cópias de segurança)", + "DeepSeek Harness “Everything is a Plugin“.": "DeepSeek Harness “Tudo é um Plugin“.", "Default ACLs applied for group inheritance.": "ACLs padrão aplicadas para herança de grupo.", "Default Credentials": "Credenciais padrão", "Default Gateway": "Gateway padrão", @@ -1110,10 +1472,12 @@ "Default journald configuration restored": "Configuração padrão do diário restaurada", "Default location is /mnt/. The share will be mounted here on the host with open permissions so an unprivileged LXC can bind-mount and write to it. For LXC access, bind-mount this path with the LXC Mount Manager.": "O local padrão é /mnt/. O compartilhamento será montado aqui no host com permissões abertas para que um LXC sem privilégios possa montar e gravar nele. Para acesso LXC, monte este caminho com o LXC Mount Manager.", "Default location is /mnt/. The share will be mounted here on the host. Use this path in /etc/fstab. For LXC access, bind-mount this path with the LXC Mount Manager.": "O local padrão é /mnt/. O compartilhamento será montado aqui no host. Use este caminho em /etc/fstab. Para acesso LXC, monte este caminho com o LXC Mount Manager.", + "Default login": "Utilizador por omissão", "Default options": "Opções padrão", "Default options read/write": "Opções padrão leitura/gravação", "Default will be used:": "O padrão será usado:", "Default:": "Padrão:", + "Default: only what the application needs": "Padrão: somente o que a aplicação precisa", "Delete Borg target": "Excluir alvo Borg", "Delete Export": "Excluir exportação", "Delete Share": "Excluir compartilhamento", @@ -1122,7 +1486,10 @@ "Delete archive": "Excluir arquivo", "Delete job": "Excluir trabalho", "Delete scheduled backup job?": "Excluir tarefa de backup agendada?", + "Delete the image to free the space?": "Apagar a imagem para libertar o espaço?", + "Delete the images to free the space?": "Apagar as imagens para libertar o espaço?", "Delete this corrupt archive and pick another": "Exclua este arquivo corrompido e escolha outro", + "Deluge is a lightweight, Free Software, cross-platform BitTorrent client.": "Deluge é um leve, Software Livre, cliente BitTorrent multiplataforma.", "Dependencies installed successfully": "Dependências instaladas com sucesso", "Deploy with this configuration?": "Implantar com esta configuração?", "Deploying Secure Gateway...": "Implantando Secure Gateway...", @@ -1177,9 +1544,15 @@ "Device added": "Dispositivo adicionado", "Device already present in target VM — existing hostpci entry reused": "Dispositivo já presente na VM de destino – entrada hostpci existente reutilizada", "Device assignments will be written now and become active after reboot.": "As atribuições de dispositivos serão gravadas agora e ficarão ativas após a reinicialização.", + "Device configuration cancelled": "Configuração do dispositivo cancelada", "Device hostname": "Nome de host do dispositivo", + "Device node outside the supported profiles": "Nó do dispositivo fora dos perfis suportados", + "Device outside the supported profiles; NVIDIA and device trees require another profile": "Dispositivo fora dos perfis suportados; NVIDIA e árvores de dispositivos require outro perfil", "Device path mismatch. Format cancelled.": "Incompatibilidade de caminho do dispositivo. Formato cancelado.", + "Device permissions verified for the application user": "Permissões do dispositivo verificadas para o utilizador da aplicação", "Device:": "Dispositivo:", + "Devices added to the container:": "Dispositivos adicionados ao recipiente:", + "Devices of the host it asks for:": "Dispositivos da máquina que pede:", "Devices to add to VM": "Dispositivos para adicionar à VM", "Diff: current system vs backup (--- system +++ backup)": "Diferença: sistema atual vs backup (--- backup do sistema +++)", "Different host. Backup from:": "Anfitrião diferente. Backup de:", @@ -1196,6 +1569,8 @@ "Directory does not exist and was not created.": "O diretório não existe e não foi criado.", "Directory does not exist:": "O diretório não existe:", "Directory error": "Erro de diretório", + "Directory for the read-only view": "Diretório para a visão somente de leitura", + "Directory for the read/write view": "Diretório para a visão de leitura/escrita", "Directory not found": "Diretório não encontrado", "Directory storage added successfully to Proxmox!": "Armazenamento de diretório adicionado com sucesso ao Proxmox!", "Directory successfully.": "Diretório com sucesso.", @@ -1248,6 +1623,7 @@ "Disk path:": "Caminho do disco:", "Disk safety revalidation failed.": "Falha na revalidação da segurança do disco.", "Disk safety validation passed.": "A validação de segurança do disco foi aprovada.", + "Disk too small for the common profile": "Disco muito pequeno para o perfil comum", "Disk unmounted from": "Disco desmontado de", "Disk verified and accessible inside CT at": "Disco verificado e acessível dentro do CT em", "Disk:": "Disco:", @@ -1261,6 +1637,10 @@ "Display physical volumes (LVM)": "Exibir volumes físicos (LVM)", "Display system summary in ASCII format": "Exibir resumo do sistema em formato ASCII", "Display volume groups (LVM)": "Exibir grupos de volumes (LVM)", + "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer.": "Não assuma que a porta 8123 permanece ativa após a integração no núcleo Home Assistant 2026.8 ou mais recente.", + "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume.": "Não reclame que as atualizações de imagem OCI no local são validadas até que a substituição e rollback do rootfs tenham sido testadas sem perder o volume gerenciado /mnt/data.", + "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default.": "Não habilite automaticamente em GPUs integradas AMD não suportadas. Os sobreposições HSA são experimentos de compatibilidade manual, não um padrão validado.", + "Do not mount": "Não montar", "Do not run the upgrade from the Web UI virtual console (it will disconnect)": "Não execute a atualização no console virtual da Web UI (ele será desconectado)", "Do not start the VM until the system has been rebooted.": "Não inicie a VM até que o sistema seja reinicializado.", "Do you want ProxMenux to stop it now?": "Você quer que o ProxMenux pare com isso agora?", @@ -1304,9 +1684,23 @@ "Do you want to update the existing export?": "Deseja atualizar a exportação existente?", "Do you want to update the existing share?": "Deseja atualizar o compartilhamento existente?", "Do you want to view the selected backup before restoring?": "Deseja visualizar o backup selecionado antes de restaurá-lo?", + "Docker Mods are only offered for compatible LinuxServer images": "Docker Mods são oferecidos apenas para imagens LinuxServer compatíveis", + "Docker Volume Backup": "Docker Volume Backup", + "Docker/CLI not available yet or no valid answer": "Docker/CLI ainda não disponível ou nenhuma resposta válida", + "Documents & Notes": "Documentos e Notas", + "Documents volume size in GB": "Tamanho do volume de documentos em GB", + "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki.": "Dokuwiki é um software wiki de código aberto muito simples de usar e altamente versátil que não require um banco de dados. É amado pelos usuários por sua sintaxe limpa e legível. A facilidade de manutenção, backup e integração o torna o favorito do administrador. Conectados em controles de acesso e conectores de autenticação tornam o DokuWiki especialmente útil no contexto empresarial e o grande número de plugins contribuídos por sua comunidade vibrante permitem uma ampla gama de casos de uso além de uma wiki tradicional.", + "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience.": "O Emulador Dolphin permite que você jogue jogos GameCube e Wii com várias melhorias gráficas e outros recursos estão disponíveis para melhorar sua experiência de jogo.", + "Domain for the certificate (example.com)": "Domínio para o certificado (exemplo.com)", + "Doplarr is an *arr request bot for Discord.\"": "Doplarr é um bot *arr request para Discord.\"", + "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust.": "Doplarr_rs é um bot Discord para solicitar mídia através de backends *arr, escrito em Rust.", + "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas.": "Double Commander é um gerenciador de arquivos de código aberto livre plataforma cruzada com dois painéis lado a lado. Ele é inspirado pelo Comandante Total e apresenta algumas novas ideias.", + "Download Spotify music with album art and metadata": "Baixar música Spotify com arte de álbum e metadados", "Download failed for all attempted URLs": "Falha no download de todas as tentativas de URL", + "Download its Compose file from an address": "Baixe seu arquivo Compose de um endereço", "Download keyfile": "Baixar arquivo-chave", "Download latest VirtIO ISO automatically": "Baixe o VirtIO ISO mais recente automaticamente", + "Downloaded OCI images deleted:": "Imagens OCI transferidas suprimidas:", "Downloaded amdgpu_top": "baixado amdgpu_top", "Downloading": "Baixando", "Downloading Helper-Scripts logo...": "Baixando o logotipo do Helper-Scripts...", @@ -1318,45 +1712,86 @@ "Downloading amdgpu_top": "Baixando amdgpu_top", "Downloading official installer...": "Baixando o instalador oficial...", "Downloading pre-existing encrypted backups from this host will fail unless you kept a copy of the current key.": "O download de backups criptografados pré-existentes deste host falhará, a menos que você mantenha uma cópia da chave atual.", + "Downloading the image:": "Baixando a imagem:", "Downloading the latest Fastfetch release...": "Baixando a versão mais recente do Fastfetch...", "Driver blacklist entries removed": "Entradas da lista negra de drivers removidas", "Driver blacklist removed for": "Lista negra de drivers removida para", "Driver installed successfully. Press Enter to continue...": "Driver instalado com sucesso. Pressione Enter para continuar...", "Drivers :": "Drivers:", "Drivers compiled and installed via DKMS.": "Drivers compilados e instalados via DKMS.", + "Dry run completed; no changes were made.": "O ensaio foi concluído; não foram feitas alterações.", + "Dry run completed; no containers were created.": "Correr a seco concluído; nenhum recipiente foi criado.", + "Dry run completed; the container and the mounts were not changed.": "A corrida a seco foi concluída; o recipiente e as montagens não foram alteradas.", + "DuckDNS subdomain without .duckdns.org (comma separated for several)": "Subdomínio DuckDNS sem .duckdns.org (comma separado para vários)", + "DuckDNS token from your account at duckdns.org": "DuckDNS token da sua conta em duckdns.org", + "DuckDNS updates the subdomain every 5 minutes. Without UPDATE_IP, DuckDNS itself detects the public IPv4 address of the request.": "DuckDNS atualiza o subdomínio a cada 5 minutos. Sem UPDATE IP, o próprio DuckDNS detecta o endereço IPv4 público da solicitação.", + "DuckStation is a PS1 Emulator aiming for the best accuracy and game support.": "DuckStation é um emulador PS1 que visa o melhor accuracy e suporte a jogos.", + "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence.": "Duckdns é um serviço gratuito que irá apontar um DNS (subdomínios do duckdns.org) para um IP de sua escolha. O serviço é completamente gratuito, e não require reativação ou posts de fórum para manter sua existência.", "Dumping AMD GPU ROM BIOS via sysfs...": "Despejando BIOS da ROM da GPU AMD via sysfs...", "Duplicate IP addresses found": "Endereços IP duplicados encontrados", "Duplicate parameters cleaned": "Parâmetros duplicados limpos", + "Duplicate variable in the contract; review it before editing": "Duplicar a variável no contrato; revê- a antes de editar", + "Duplicated GPU device in the container": "Dispositivo GPU duplicado no recipiente", + "Duplicated NVIDIA devices": "Dispositivos NVIDIA duplicados", + "Duplicated VMID in the Proxmox inventory": "VMID duplicado no inventário Proxmox", + "Duplicated native directive:": "Directiva nativa duplicada:", + "Duplicated native option": "Opção nativa duplicada", + "Duplicated or invalid stack VMID": "VMID de pilha duplicada ou inválida", + "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others.": "Duplicati é um cliente de backup que armazena com segurança backups criptografados, incrementais e compactados em armazenamento local, serviços de armazenamento em nuvem e servidores de arquivos remotos. Ele funciona com protocolos padrão como FTP, SSH, WebDAV, bem como serviços populares como Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2 e muitos outros.", + "Duplicati web interface (password only)": "Interface Web Duplicati (somente palavra-passe)", "Duration": "Duração", "Duration:": "Duração:", + "Dynamic NVIDIA is only validated for unprivileged containers. This profile uses static mounts and must be recreated after the host driver changes.": "A NVIDIA dinâmica só é validada para recipientes não privilegiados. Este perfil usa montagens estáticas e deve ser recriado após as mudanças do driver.", "EFI disk created and configured on": "Disco EFI criado e configurado em", "EFI storage selection cancelled.": "Seleção de armazenamento EFI cancelada.", "EFI storage selection failed or was cancelled. VM creation aborted.": "A seleção de armazenamento EFI falhou ou foi cancelada. Criação de VM abortada.", "EMERGENCY PROXMOX SYSTEM REPAIR": "REPARO DE EMERGÊNCIA DO SISTEMA PROXMOX", "ENABLED for restore": "HABILITADO para restauração", "EXISTS": "EXISTE", + "Each /request command needs a backend: add a [[backends]] block in the same file with the url and api_key of your Sonarr, Radarr or Seerr instance, then restart the container.": "Cada comando /request precisa de uma infra-estrutura: adicionar um bloco [[backends]] no mesmo arquivo com o url e api key do seu Sonarr, Radarr ou Seerr instância, em seguida, reiniciar o recipiente.", "Each LUN will appear as a block device assignable to VMs.": "Cada LUN aparecerá como um dispositivo de bloco atribuível às VMs.", + "Each peer gets its configuration and its QR code inside the container: /config/peer1/peer1.conf and /config/peer1/peer1.png, or /config/peer_/peer_.conf when names were given.": "Cada peer obtém sua configuração e seu código QR dentro do recipiente: /config/peer1/peer1.conf e /config/peer1/peer1.png, ou /config/peer /peer .conf quando os nomes foram dados.", + "Ebook and audiobook collection manager for Usenet and BitTorrent users.": "Gerenciador de coleção de ebooks e audiolivros para usuários Usenet e BitTorrent.", + "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind.": "Eden é um emulador experimental de código aberto para o Nintendo Switch, construído com desempenho e estabilidade em mente.", "Edge TPU runtime installed.": "Tempo de execução do Edge TPU instalado.", "Edit raw CT configuration file": "Editar arquivo de configuração CT bruto", "Edit raw VM configuration file": "Editar arquivo de configuração bruto da VM", "Edit the VM machine type to q35 and try again.": "Edite o tipo de máquina VM para q35 e tente novamente.", + "Email address for certificate expiry notices (required by ZeroSSL)": "Endereço de e-mail para os avisos de validade do certificado (required by ZeroSSL)", + "Email address of the LibreDB Studio administrator": "Endereço de e-mail do administrador LibreDB Studio", + "Email address of the NetBox admin account": "Endereço de e-mail da conta de administrador NetBox", + "Emby WebUI": "Emby WebUI", + "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server.": "Emby organiza vídeo, música, TV ao vivo e fotos de bibliotecas de mídia pessoal e os transmite para televisões inteligentes, caixas de streaming e dispositivos móveis. Este recipiente é embalado como um servidor de mídia emby independente.", "Emergency Proxmox System Repair": "Reparo de emergência do sistema Proxmox", "Emergency recovery:": "Recuperação de emergência:", + "Empowering the smart home": "Empoderar o lar inteligente", "Empty": "Vazio", + "Empty exec service check": "Verificação do serviço executivo vazio", + "Empty or duplicated NVIDIA identity": "Identidade NVIDIA vazia ou duplicada", + "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes.": "EmulatorJS é uma aplicação emuladora baseada em Docker que pode simular vários sistemas e ambientes de dispositivos de opera dentro de recipientes para fins de desenvolvimento, teste e aprendizagem.", "Enable": "Habilitar", "Enable / disable job timer": "Ativar/desativar temporizador de trabalho", "Enable High Availability services": "Habilitar serviços de alta disponibilidade", "Enable IOMMU in GRUB or ZFS boot": "Habilite IOMMU na inicialização GRUB ou ZFS", "Enable IOMMU support if not enabled": "Habilite o suporte IOMMU se não estiver habilitado", "Enable IOMMU, reboot the host, and try again.": "Habilite o IOMMU, reinicie o host e tente novamente.", + "Enable Intel/AMD VA-API video acceleration": "Activar a aceleração de vídeo Intel/AMD VA-API", + "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping": "Habilitar transcodificação NVIDIA e HDR10/Dolby Vision para mapeamento de tom SDR", "Enable Remote Desktop (RDP) before disabling the virtual display.": "Habilite a Área de Trabalho Remota (RDP) antes de desabilitar a exibição virtual.", "Enable SSD emulation for this disk?": "Ativar emulação SSD para este disco?", "Enable TCP BBR/Fast Open control": "Habilitar controle TCP BBR/Fast Open", + "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping": "Habilitar transcodificação VA-API e HDR10/Dolby Vision para mapeamento de tom SDR", + "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin": "Habilitar VA-API, codificação de hardware e mapeamento de tom OpenCL em Jellyfin", "Enable VFIO IOMMU support": "Habilitar suporte VFIO IOMMU", "Enable ZFS autotrim (SSD/NVMe pools)": "Habilitar ajuste automático ZFS (pools SSD/NVMe)", + "Enable a mount on an existing Rclone OCI container": "Activar uma montagem num contentor Rclone OCI existente", + "Enable an optical drive for MakeMKV": "Activar uma unidade óptica para MakeMKV", "Enable auto-sync if /var/log exceeds 90% of its size?": "Ativar a sincronização automática se /var/log exceder 90% do seu tamanho?", "Enable fast reboots": "Habilite reinicializações rápidas", "Enable restart on kernel panic": "Habilite a reinicialização no kernel panic", + "Enable the NVIDIA GPU requested by the image": "Activar a GPU NVIDIA solicitada pela imagem", + "Enable the NVIDIA GPU required by Open WebUI CUDA": "Activar a required da GPU NVIDIA por Open WebUI CUDA", + "Enable this FUSE mount now and restart the CT?": "Activar esta montagem FUSE e reiniciar o CT?", "Enable/Disable job": "Habilitar/Desabilitar trabalho", "Enabled": "Habilitado", "Enabled (device pending — load apex module or reboot)": "Ativado (dispositivo pendente – carregar módulo apex ou reinicializar)", @@ -1401,6 +1836,7 @@ "Enter a name for the mount point (used as /mnt/):": "Insira um nome para o ponto de montagem (usado como /mnt/):", "Enter a name for the new virtual machine:": "Insira um nome para a nova máquina virtual:", "Enter a number, or write or paste a command:": "Digite um número ou escreva ou cole um comando:", + "Enter a usable IPv4 address with its prefix, for example": "Digite um endereço IPv4 utilizável com seu prefixo, por exemplo", "Enter backup file (.zst):": "Insira o arquivo de backup (.zst):", "Enter backup path (.tar.zst):": "Insira o caminho de backup (.tar.zst):", "Enter backup path (.vma.zst):": "Insira o caminho de backup (.vma.zst):", @@ -1489,6 +1925,7 @@ "Enter the number or type the interface name:": "Digite o número ou digite o nome da interface:", "Enter the password for Samba user:": "Digite a senha do usuário Samba:", "Enter the recovery passphrase set when the keyfile was created:": "Insira a senha de recuperação definida quando o arquivo-chave foi criado:", + "Enter the size in whole GB, for example": "Digite o tamanho em GB inteiro, por exemplo", "Enter username for Samba server:": "Digite o nome de usuário do servidor Samba:", "Enter username:": "Digite o nome de usuário:", "Enterprise Proxmox Ceph repository disabled": "Repositório Enterprise Proxmox Ceph desativado", @@ -1497,6 +1934,8 @@ "Enterprise repository returned 401 Unauthorized (no valid subscription). Switch to the no-subscription repository and retry?": "O repositório corporativo retornou 401 Não autorizado (sem assinatura válida). Mudar para o repositório sem assinatura e tentar novamente?", "Enterprise repository unauthorized and fallback declined by user": "Repositório corporativo não autorizado e substituto recusado pelo usuário", "Entropy generation optimization removed": "Otimização de geração de entropia removida", + "Environment entry without an explicit value": "Entrada do ambiente sem um valor explícito", + "Environment override for an unknown service:": "Sobreposição do ambiente para um serviço desconhecido:", "Equivalent manual flow of disk_host.sh: partition, format, mount, persist, register in Proxmox.": "Fluxo manual equivalente a disk_host.sh: particionar, formatar, montar, persistir, registrar no Proxmox.", "Equivalent manual flow of iscsi_host.sh.": "Fluxo manual equivalente de iscsi_host.sh.", "Equivalent manual flow used by Local Shared Manager.": "Fluxo manual equivalente usado pelo Local Shared Manager.", @@ -1512,12 +1951,16 @@ "Error: No write permissions in directory": "Erro: Sem permissões de gravação no diretório", "Essential Proxmox packages installed": "Pacotes essenciais do Proxmox instalados", "Estimated required free space:": "Espaço livre necessário estimado:", + "Etherpad admin page": "Página de administração do Etherpad", "Every 12 hours": "A cada 12 horas", "Every 3 hours": "A cada 3 horas", "Every 6 hours": "A cada 6 horas", + "Every fail2ban jail ships disabled. Enable the ones you need in /config/fail2ban/jail.local, taking the ready-made jails in /config/fail2ban/jail.d/ as reference, then restart the container.": "Todas as naves de prisão fail2ban desactivadas. Habilite os que você precisa em /config/fail2ban/jail.local, levando as cadeias prontas em /config/fail2ban/jail.d/ como referência, em seguida, reinicie o recipiente.", "Every hour": "A cada hora", + "Every member of the stack is back to its previous installation.": "Cada membro da pilha está de volta à sua instalação anterior.", "Every path in this backup is kernel-tied: the restore applies these paths automatically via the safe-subset filter and re-merges the operator's tuning.": "Cada caminho neste backup está vinculado ao kernel: a restauração aplica esses caminhos automaticamente por meio do filtro de subconjunto seguro e mescla novamente o ajuste do operador.", "Everything restorable in this backup will be restored": "tudo o que for restaurável neste backup será restaurado", + "Exact name of the remote": "Nome exato do remoto", "Example output: rootfs: local-lvm:vm-114-disk-0,size=8G": "Exemplo de saída: rootfs: local-lvm:vm-114-disk-0,size=8G", "Example target: /dev/sdb": "Destino de exemplo: /dev/sdb", "Example: /dev/pve/vm-114-disk-0": "Exemplo: /dev/pve/vm-114-disk-0", @@ -1537,7 +1980,9 @@ "Execute destructive rollback?": "Executar reversão destrutiva?", "Executing destructive rollback (operator confirmed) ...": "Executando reversão destrutiva (operador confirmado) ...", "Executing:": "Executando:", + "Execution engine for Index-TTS": "Motor de execução para Index-TTS", "Existing Groups": "Grupos Existentes", + "Existing TLS certificate reused:": "Certificado TLS existente reutilizado:", "Existing file, re-downloading...": "Arquivo existente, baixando novamente...", "Existing filesystem:": "Sistema de arquivos existente:", "Existing hostpci entries detected — they will be reused": "Entradas hostpci existentes detectadas – elas serão reutilizadas", @@ -1581,7 +2026,9 @@ "Extended Filesystem 4 (recommended)": "Sistema de arquivos estendido 4 (recomendado)", "External ZFS ARC settings restored:": "Configurações ZFS ARC externas restauradas:", "External ZFS configuration changed after the ProxMenux migration; current file and backup preserved:": "A configuração ZFS externa foi alterada após a migração do ProxMenux; o ficheiro atual e a cópia de segurança foram preservados:", + "External credential is empty or spans multiple lines": "O credential externo está vazio ou abrange várias linhas", "External disk for backup": "Disco externo para backup", + "External field not reserved:": "Campo externo não reservado:", "Extracting NVIDIA installer on host...": "Extraindo o instalador NVIDIA no host...", "Extracting OVA archive...": "Extraindo arquivo OVA...", "Extracting archive...": "Extraindo arquivo...", @@ -1592,7 +2039,9 @@ "Extraction failed. Check log:": "Falha na extração. Verifique o registro:", "Extraction successful": "Extração bem-sucedida", "FAILED": "FRACASSADO", + "FFmpeg version the node uses (7 by default)": "Versão FFmpeg que o nó usa (7 por padrão)", "FINAL CONFIRMATION — DATA WILL BE ERASED": "CONFIRMAÇÃO FINAL — OS DADOS SERÃO APAGADOS", + "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface.": "FIleZilla Client é um FTP multiplataforma rápida e confiável, FTPS e SFTP cliente com muitos recursos úteis e uma interface gráfica intuitiva do usuário.", "Fail2Ban - Intrusion Prevention": "Fail2Ban - Prevenção de Intrusões", "Fail2Ban Management": "Gerenciamento Fail2Ban", "Fail2Ban has been removed": "Fail2Ban foi removido", @@ -1602,6 +2051,7 @@ "Fail2Ban is currently installed.": "Fail2Ban está instalado atualmente.", "Fail2Ban is not installed on this system.": "Fail2Ban não está instalado neste sistema.", "Fail2Ban is running correctly": "Fail2Ban está funcionando corretamente", + "Fail2ban is a daemon to ban hosts that cause multiple authentication errors.": "Fail2ban é um servidor para banir hosts que causam múltiplos erros de autenticação.", "Failed": "Fracassado", "Failed to access log2ram directory": "Falha ao acessar o diretório log2ram", "Failed to access share with provided credentials.": "Falha ao acessar o compartilhamento com as credenciais fornecidas.", @@ -1748,6 +2198,9 @@ "Failed. See log:": "Fracassado. Veja registro:", "Falling back to each installer with --auto-reinstall...": "recorrendo a cada instalador com --auto-reinstall...", "Falling back to manual paste mode.": "voltando ao modo de colagem manual.", + "Fast Usenet downloader with a SABnzbd-compatible API": "Baixer Fast Usenet com uma API compatível com SABnzbd", + "Fast, modern web interface for qBittorrent": "Interface web rápida e moderna para qBittorrent", + "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper.": "O sussurro mais rápido é uma reimplementação do modelo Whisper da OpenAI usando o CTranslate2, que é um motor de inferência rápido para modelos Transformer. Este contentor fornece um servidor de protocolo Wyoming para um sussurro mais rápido.", "Fastfetch Logo Selection": "Seleção de logotipo Fastfetch", "Fastfetch configuration updated": "Configuração do Fastfetch atualizada", "Fastfetch download URL retrieved successfully.": "URL de download do Fastfetch recuperado com sucesso.", @@ -1759,19 +2212,31 @@ "Fastfetch now displays: System optimised by: ProxMenux": "Fastfetch agora exibe: Sistema otimizado por: ProxMenux", "Fastfetch removed from system": "Fastfetch removido do sistema", "Fastfetch will start automatically in the console": "Fastfetch será iniciado automaticamente no console", + "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application.": "Ferdium é um aplicativo de desktop que ajuda você a organizar como você usa seus aplicativos favoritos pelo combi colocando-os em um aplicativo.", "Fetching NVIDIA driver versions supported by your GPU...": "Buscando versões de driver NVIDIA suportadas por sua GPU...", "Figurine installation and configuration completed successfully.": "Instalação e configuração da estatueta concluídas com sucesso.", "Figurine is not installed.": "A estatueta não está instalada.", "Figurine removed from system": "Estatueta removida do sistema", + "File bind mounts do not support spaces:": "Os arquivos de montagem não suportam espaços:", + "File processing made easy!": "Processamento de arquivo feito fácil!", "File:": "Arquivo:", + "FileBrowser Quantum": "FileBrowser Quantum", + "FileBrowser Quantum (new installation)": "FileBrowser Quantum (nova instalação)", + "FileDrop is a free, open source file sharing service": "FileDrop é um serviço de compartilhamento de arquivos livre e aberto", + "Files & Downloads": "Ficheiros e Transferências", + "Files volume size in GB": "Tamanho do volume dos arquivos em GB", "Filesystem": "Sistema de arquivos", "Filesystem Tools Required": "Ferramentas de sistema de arquivos necessárias", "Filesystem:": "Sistema de arquivos:", "Final Confirmation": "Confirmação Final", + "Final cleanup of the stack operation completed": "Limpeza final da pilha operation concluída", "Final confirmation": "Confirmação final", "Final storage health/status check": "Verificação final de integridade/status do armazenamento", + "Finance & Budgeting": "Finanças & Budgeting", "Find your device using https://finds.synology.com": "Encontre o seu dispositivo usando https://finds.synology.com", "Fingerprint:": "Impressão digital:", + "Firefly, the easiest using of WireGuard VPN server, plus version of wg-easy.": "Firefly, o mais fácil de usar o servidor VPN WireGuard, além da versão do wg-fácil.", + "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards.": "Firefox Browser, também conhecido como Mozilla Firefox ou simplesmente Firefox, é um navegador web livre e de código aberto desenvolvido pela Mozilla Foundation e sua subsidiária, a Mozilla Corporation. Firefox usa o mecanismo de layout Gecko para renderizar páginas web, que implementa padrões web atuais e antecipados.", "Firewall allows port": "Firewall permite porta", "Firewall settings": "Configurações de firewall", "Firmware :": "Firmware:", @@ -1791,8 +2256,13 @@ "Fix systemd-boot meta-package conflict": "Corrigir conflito de meta-pacote systemd-boot", "Fix systemd-boot:": "Corrija a inicialização do systemd:", "Fix: on the host, run": "Correção: no host, execute", + "FlexGet web interface": "Interface Web FlexGet", + "Flexget is a multipurpose automation tool for all of your media.": "Flexget é uma ferramenta de automação multiuso para todos os seus meios.", + "Flowise 3.0.1 and later create the administrator account from the web interface, the first time it is opened.": "Flowise 3.0.1 e depois criar a conta de administrador a partir da interface web, a primeira vez que é aberto.", + "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast.": "Flycast é um emulador multiplataforma Sega Dreamcast, Naomi, Naomi 2 e Atomiswave derivado do reicast.", "Folder Name": "Nome da pasta", "Folders in /mnt": "Pastas em /mnt", + "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics.": "Folding@home é um projeto de computação distribuída para simular a dinâmica proteica, incluindo o processo de dobramento proteico e os movimentos de proteínas implicadas em uma variedade de doenças. Ele reúne cientistas citizen que se voluntariam para executar simulações de dinâmica de proteínas em seus computadores pessoais. A análise destes dados está a ajudar os cientistas a compreender melhor a biologia e a proporcionar novas oportunidades de desenvolvimento terapêutico.", "Follow post-restore progress live from ProxMenux Monitor → Backups tab after the reboot.": "Acompanhe o progresso pós-restauração ao vivo no ProxMenux Monitor → guia Backups após a reinicialização.", "For LVM - Create mount directory and mount:": "Para LVM - Crie o diretório de montagem e monte:", "For ZFS, storage ID must start with a letter and use only letters, numbers, dot, dash, underscore or colon.": "Para ZFS, o ID de armazenamento deve começar com uma letra e usar apenas letras, números, ponto, traço, sublinhado ou dois pontos.", @@ -1828,11 +2298,15 @@ "Formatting partition": "Formatando partição", "Found": "Encontrado", "Found guest-accessible shares:": "Compartilhamentos acessíveis para convidados encontrados:", + "Free and easy to use Minecraft server management tool.": "Ferramenta de gerenciamento de servidores Minecraft gratuita e fácil de usar.", "Free public Proxmox repository enabled": "Repositório Proxmox público gratuito habilitado", "Free space OK:": "Espaço livre OK:", "Free up disk space": "Libere espaço em disco", "Free:": "Livre:", + "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support.": "FreeCAD é um modelador paramétrico paramétrico de projeto 3D assistido por computador (CAD) e um software de modelagem de informações de construção (BIM) com suporte ao método de elementos finitos (FEM).", "French": "Francês", + "Freshrss is a free, self-hostable aggregator for rss feeds.": "Freshrss é um agregador livre e auto-hostável para feeds rss.", + "Frigate WebUI": "Frigate WebUI", "Full SMART Report": "Relatório SMART completo", "Full SMART info and attributes": "Informações e atributos SMART completos", "Full format — new GPT partition + filesystem": "Formato completo – nova partição GPT + sistema de arquivos", @@ -1845,6 +2319,7 @@ "Function Level Reset (FLR) not available": "Redefinição de nível de função (FLR) não disponível", "GID already in use:": "GID já em uso:", "GID in CT": "GID em TC", + "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable.": "GIMP é um editor gráfico raster livre e de código aberto usado para manipulação de imagem (retoque) e edição de imagem, desenho de forma livre, transcodificação entre diferentes formatos de arquivos de imagem e tarefas mais especializadas. É extensível por meio de plugins, e scriptable.", "GPU": "GPU", "GPU -> VM Mode Detected": "GPU -> Modo VM detectado", "GPU Already Added": "GPU já adicionada", @@ -1870,6 +2345,7 @@ "GPU already present in target VM — existing hostpci entry reused": "GPU já presente na VM de destino – entrada hostpci existente reutilizada", "GPU audio added": "Áudio GPU adicionado", "GPU audio already present in target VM — existing hostpci entry reused": "Áudio da GPU já presente na VM de destino – entrada hostpci existente reutilizada", + "GPU available for machine learning:": "GPU disponível para aprendizado de máquina:", "GPU driver blacklisted": "Driver de GPU na lista negra", "GPU guard hook will block concurrent start when another VM is already using this GPU": "O gancho de proteção da GPU bloqueará o início simultâneo quando outra VM já estiver usando esta GPU", "GPU host driver blacklisted in /etc/modprobe.d/blacklist.conf": "Driver host GPU na lista negra em /etc/modprobe.d/blacklist.conf", @@ -1885,11 +2361,14 @@ "GPU passthrough to VMs requires IOMMU to be enabled in the kernel.": "A passagem de GPU para VMs requer que o IOMMU esteja habilitado no kernel.", "GPU passthrough was not applied.": "A passagem de GPU não foi aplicada.", "GPU passthrough was skipped (no compatible GPU detected).": "A passagem da GPU foi ignorada (nenhuma GPU compatível detectada).", + "GPU recognition uses 8 GB of RAM and a limit of 4 CPU equivalents. These resources were tested in the lab and are not a universal minimum. Compatibility depends on the GPU, the models and the kernel. NVIDIA uses the GPUs of the Toolkit inventory; Intel keeps the CPU topology.": "O reconhecimento da GPU usa 8 GB de RAM e um limite de 4 CPU equivalentes. Esses recursos foram testados no laboratório e não são um mínimo universal. A compatibilidade depende da GPU, dos modelos e do kernel. NVIDIA usa as GPUs do inventário Toolkit; Intel mantém a topologia da CPU.", "GPU removed from VM": "GPU removida da VM", "GPU removed from VM config": "GPU removida da configuração da VM", + "GPU render device": "Dispositivo de renderização GPU", "GPU switch complete: LXC mode prepared.": "Troca de GPU concluída: modo LXC preparado.", "GPU switch complete: VM mode prepared.": "Troca de GPU concluída: modo VM preparado.", "GPU switch mode completed. No reboot required.": "Modo de troca de GPU concluído. Não é necessária reinicialização.", + "GPU verified:": "GPU verificado:", "GPU will be removed from source VM config": "A GPU será removida da configuração da VM de origem", "GPU will remain configured in source VM": "A GPU permanecerá configurada na VM de origem", "GPU/TPU - Manual CLI Guide": "GPU/TPU - Guia CLI manual", @@ -1899,6 +2378,8 @@ "GRUB configuration updated": "Configuração do GRUB atualizada", "GRUB_CMDLINE_LINUX_DEFAULT not found in GRUB config": "GRUB_CMDLINE_LINUX_DEFAULT não encontrado na configuração do GRUB", "GUI mode (if available)": "Modo GUI (se disponível)", + "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities.": "GZDoom é uma porta centrada em recursos para todos os jogos do Doom Engine, baseado no ZDoom, adicionando um renderizador OpenGL e recursos de script poderosos.", + "Gaming & Leisure": "Jogos & Leisure", "Gateway is not installed.": "O gateway não está instalado.", "Gateway removed.": "Gateway removido.", "Gateway restarted.": "Gateway reiniciado.", @@ -1908,19 +2389,32 @@ "Generate a new key and authorize it on the server automatically (recommended)": "Gere uma nova chave e autorize-a automaticamente no servidor (recomendado)", "Generate a new key, show me the line to paste manually": "Gere uma nova chave, mostre-me a linha para colar manualmente", "Generate a new keyfile": "Gere um novo arquivo-chave", + "Generated Paperless administrator": "Administrador Gerado sem Papel", + "Generated Tandoor administrator": "Gerado o administrador Tandoor", + "Generated administrator login": "Gerou o login do administrador", "Generating OVF descriptor...": "Gerando descritor OVF...", "Generating dkms.conf...": "Gerando dkms.conf...", "Generating manifest...": "Gerando manifesto...", "Generating missing locale:": "Gerando localidade ausente:", + "Generic SCSI device associated with the drive (e.g. /dev/sg2)": "Dispositivo SCSI genérico associado à unidade (por exemplo, /dev/sg2)", "German": "Alemão", "Get a list of all your containers:": "Obtenha uma lista de todos os seus contêineres:", "Get the actual disk path:": "Obtenha o caminho real do disco:", "Get the container's storage information:": "Obtenha as informações de armazenamento do contêiner:", + "Get up and running with large language models locally": "Começar a funcionar com modelos de linguagem grandes localmente", "Git installed": "Git instalado", + "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality.": "GitQlient é uma multi-plataforma Cliente Git originalmente forked do QGit. Hoje em dia vai além de apenas um fork e adiciona um monte de novas funcionalidades.", + "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React.": "Github Desktop é uma aplicação GitHub baseada em electrões de código aberto. É escrito em TypeScript e usa React.", "Global settings and SSH jail configured": "Configurações globais e prisão SSH configuradas", + "Gluetun/VPN not yet available: this suite does not route downloads through a VPN.": "Gluetun/VPN ainda não está disponível: este pacote não encaminha downloads através de uma VPN.", "Go to \"Manage custom paths\" and remove your custom entry that includes the destination": "Vá para \"Gerenciar caminhos personalizados\" e remova sua entrada personalizada que inclui o destino", "Google only ships an official libedgetpu APT repository for Debian/Ubuntu. Hardware passthrough is already written to": "O Google envia apenas um repositório oficial libedgetpu APT para Debian/Ubuntu. A passagem de hardware já está gravada em", "Graceful shutdown timed out.": "O desligamento normal expirou.", + "Grafana is a complete observability stack that allows you to monitor and analyze metrics, logs and traces. It allows you to query, visualize, alert on and understand your data no matter where it is stored.": "Grafana é uma pilha de observação completa que permite monitorar e analisar métricas, registros e traços. Ele permite que você consulte, visualize, alerte e entenda seus dados, não importa onde esteja armazenado.", + "Grafana web interface": "Interface Web Grafana", + "Grav is a Fast, Simple, and Flexible, file-based Web-platform.": "Grav é uma plataforma web rápida, simples e flexível.", + "Grocy (new installation; restored data keeps its credentials)": "Grocy (nova instalação; dados restaurados mantêm seus credentials)", + "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility.": "Grocy é um sistema ERP para sua cozinha! Reduza o desperdício de comida, e gerencie suas tarefas com esta utilidade brilhante.", "Group": "Grupo", "Group 'sharedfiles' already exists inside the CT": "O grupo ‘sharedfiles’ já existe dentro do CT", "Group GID:": "GID do grupo:", @@ -1953,23 +2447,58 @@ "Guided Repair Available": "Reparo guiado disponível", "HA groups will be migrated to HA rules automatically": "Os grupos de HA serão migrados para regras de HA automaticamente", "HA services disabled (configs preserved)": "Serviços HA desativados (configurações preservadas)", + "HAOS One is a community image that runs Docker inside the container. The LXC stays unprivileged, but the inner AppArmor profiles may not be available. The first start downloads Home Assistant Core and its add-ons. If the check fails, the CT and /mnt/data are kept for diagnosis.": "HAOS One é uma imagem comunitária que executa Docker dentro do recipiente. O LXC permanece sem privilégios, mas os perfis internos do AppArmor podem não estar disponíveis. O primeiro início baixa o Home Assistant Core e seus add-ons. Se a verificação falhar, a TC e /mnt/dados são mantidos para diagnóstico.", + "HAOS One profile declined": "O perfil do HAOS One diminuiu", + "HAOS One requires an unprivileged unmanaged LXC with nesting and keyctl, 2 cores, 2048 MB RAM, rootfs of at least 12 GB and /mnt/data of at least 16 GB on a container volume included in backups": "HAOS One requires um LXC não privilegiado não gerido com nidificação e keyctl, 2 núcleos, 2048 MB RAM, rootfs de pelo menos 12 GB e /mnt/dados de pelo menos 16 GB em um volume de recipiente incluído em backups", + "HTML5 Network Speed Test Server.": "Servidor de Teste de Velocidade de Rede HTML5.", + "HTTP service check without a saved URL": "Verificação de serviço HTTP sem um URL salvo", + "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API.": "Habridge emula Philips Hue API para outros gateways de automação doméstica, como um Amazon Echo/Dot Gen 1 (gen 2 tem problemas descobrindo ha-bridge) ou outros sistemas que suportam Philips Hue. A Ponte lida com comandos básicos como comandos On, Off e brilho do protocolo de matiz. Esta ponte pode controlar a maioria dos dispositivos que têm uma API distinta.", + "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs.": "HandBrake é uma ferramenta de código aberto, construída por voluntários, para converter vídeo de quase qualquer formato para uma seleção de codecs modernos e amplamente suportados.", "Hardening SSH: setting MaxAuthTries to 3...": "Endurecimento SSH: configurando MaxAuthTries para 3...", + "Hardware acceleration for Emby": "Aceleração de hardware para Emby", + "Hardware acceleration for FileFlows": "Aceleração de hardware para FileFlows", + "Hardware acceleration for Frigate": "Aceleração de hardware para Frigate", + "Hardware acceleration for Jellyfin": "Aceleração de hardware para Jellyfin", + "Hardware acceleration for Plex": "Aceleração de hardware para Plex", + "Hardware acceleration for Roon Server": "Aceleração de hardware para Roon Server", + "Hardware acceleration for Stremio": "Aceleração de hardware para Stremio", + "Hardware acceleration for Tdarr": "Aceleração de hardware para Tdarr", + "Hardware acceleration options:": "Opções de aceleração do hardware:", "Hardware compatibility — these items will be skipped to keep the boot safe:": "Compatibilidade de hardware — estes itens serão ignorados para manter a inicialização segura:", "Hardware passthrough is already configured — the Coral device is visible inside the container as /dev/apex_0 (M.2) and/or /dev/bus/usb (USB).": "A passagem de hardware já está configurada — o dispositivo Coral é visível dentro do contêiner como /dev/apex_0 (M.2) e/ou /dev/bus/usb (USB).", "Hardware: GPUs and Coral-TPU": "Hardware: GPUs e Coral-TPU", + "Have a Private Social Space Hosted on Your Site": "Ter um espaço social privado hospedado em seu site", "Have valid backups of all VMs and containers": "Tenha backups válidos de todas as VMs e contêineres", + "Health check failed:": "Verificação de saúde falhou:", + "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface.": "Healthchecks é um cão de guarda para seus trabalhos de cron. É um servidor web que ouve pings de seus trabalhos de cron, além de uma interface web.", + "HedgeDoc gives you access to all your files wherever you are.": "O HedgeDoc dá-lhe acesso a todos os seus ficheiros onde quer que esteja.", + "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way.": "Heimdall é uma forma de organizar todos esses links para os seus sites mais usados e aplicações web de uma forma simples.", + "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking.": "Helium é um navegador baseado em Chromium feito para pessoas, com amor. Privacy-primeiro com ad-bloqueamento imparcial.", "Help & Info (commands)": "Ajuda e informações (comandos)", "Help & Information": "Ajuda e informações", "Help and Info": "Ajuda e informações", "Help and Info Commands": "Comandos de ajuda e informações", "Helper-Scripts logo applied": "Logotipo Helper-Scripts aplicado", + "Hermes WebUI": "Hermes WebUI", "Hidden for safety": "Escondido por segurança", "Hidden:": "Escondido:", "High Availability services have been enabled successfully": "Os serviços de alta disponibilidade foram ativados com sucesso", "High Availability setup completed": "Configuração de alta disponibilidade concluída", + "High availability resources are not supported by this profile": "Recursos de alta disponibilidade não são suportados por este perfil", + "High availability resources are not supported for stacks": "Recursos de alta disponibilidade não são suportados para pilhas", "High risk confirmation": "Confirmação de alto risco", "High-Risk GPU Power State": "Estado de energia da GPU de alto risco", + "Home Assistant": "Home Assistant", + "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server": "Home Assistant Core - Automação de origem aberta que coloca o controle local e a privacidade em primeiro lugar. Alimentado por uma comunidade mundial de tinkerers e entusiastas de DIY. Perfeito para executar em um Pi Framboesa ou um servidor local", + "Home Assistant OS cannot be checked without an IP address": "O sistema operacional Home Assistant não pode ser verificado sem um endereço IP", + "Home Assistant OS did not pass the Supervisor, Core and Observer checks": "O Home Assistant OS não passou nas verificações Supervisor, Núcleo e Observador", + "Home Assistant OS ready: Supervisor, Core and Observer running": "Home Assistant OS pronto: Supervisor, Núcleo e Observador em execução", + "Home Assistant OS was not started: its addresses will be known once Core is running.": "O sistema operacional Home Assistant não foi iniciado: seus endereços serão conhecidos quando o Core estiver em execução.", + "Home Assistant Observer": "Observador Home Assistant", + "Home Automation systems": "Sistemas de automação residencial", "Home-Lab-Club logo applied": "Logotipo Home-Lab-Club aplicado", + "HomeKit support for the impatient.": "HomeKit apoio para os impacientes.", + "Homebridge UI": "Homebridge UI", "Host": "Hospedar", "Host Backup → Borg": "Backup de host → Borg", "Host Backup → Local archive": "Backup do host → Arquivo local", @@ -1978,6 +2507,7 @@ "Host Config Backup": "Backup de configuração do host", "Host Config Backup / Restore": "Backup/restauração de configuração do host", "Host Config Restore": "Restauração de configuração do host", + "Host DVB tuners": "Afinadores DVB da máquina", "Host Directory": "Diretório de host", "Host Directory to LXC Mount Point": "Diretório de host para ponto de montagem LXC", "Host Directory:": "Diretório de host:", @@ -1985,18 +2515,37 @@ "Host GPU detected": "GPU host detectada", "Host GPU is already bound to vfio-pci. Host reconfiguration/reboot should not be required for this VM-to-VM reassignment.": "A GPU host já está vinculada ao vfio-pci. A reconfiguração/reinicialização do host não deve ser necessária para esta reatribuição de VM para VM.", "Host IP": "IP do host", + "Host Management": "Gestão da Máquina", "Host Mount Path": "Caminho de montagem do host", "Host NFS/Samba as Proxmox Storage (pvesm)": "Hospedar NFS/Samba como armazenamento Proxmox (pvesm)", "Host Path": "Caminho do host", "Host Path:": "Caminho do host:", "Host Storage (NFS / Samba via Proxmox)": "Armazenamento de host (NFS/Samba via Proxmox)", + "Host USB bus": "Barramento USB da máquina", "Host VFIO config was already up to date — no reboot needed.": "A configuração do Host VFIO já estava atualizada – não é necessária reinicialização.", "Host VFIO configuration already up to date": "Configuração do host VFIO já atualizada", "Host VFIO configuration changed (initramfs updated). Reboot required before starting the VM.": "Configuração do host VFIO alterada (initramfs atualizado). Reinicialização necessária antes de iniciar a VM.", "Host VFIO configuration changed — reboot required before starting the VM.": "Configuração do host VFIO alterada — reinicialização necessária antes de iniciar a VM.", "Host already in VFIO mode — skipping host reconfiguration for VM reassignment": "Host já no modo VFIO — ignorando a reconfiguração do host para reatribuição de VM", + "Host audio devices": "Dispositivos de áudio da máquina", "Host backup attached to PVE job": "Backup do host anexado ao trabalho PVE", + "Host data is not restored by the backup; confirm it with --acknowledge-external-data": "Os dados da máquina não são restaurados pelo backup; confirme- o com -- acknowledge- external- data", + "Host device for /dev/kvm": "Dispositivo de máquina para /dev/kvm", + "Host device for /dev/net/tun": "Dispositivo de máquina para /dev/net/tun", + "Host device for /dev/ttyUSB0": "Dispositivo da máquina para /dev/ttyUSB0", + "Host device for /dev/video10": "Dispositivo de máquina para /dev/video10", + "Host device for /dev/video11": "Dispositivo de máquina para /dev/video11", + "Host device for /dev/video12": "Dispositivo de máquina para /dev/video12", + "Host device node": "Nó do dispositivo da máquina", + "Host directories are not included in the backup and are not reverted by a recovery.": "Diretórios host não estão incluídos no backup e não são revertidas por uma recuperação.", + "Host directories are not included in the backups and are not reverted by a recovery.": "Diretórios host não estão incluídos nos backups e não são revertidas por uma recuperação.", + "Host directories cannot be part of the vzdump backup": "As pastas da máquina não podem fazer parte do backup do vzdump", + "Host directories that are kept, with their content:": "Directórios de máquinas que são mantidos, com o seu conteúdo:", + "Host directory": "Pasta da máquina", + "Host directory (created if it does not exist)": "Pasta da máquina (criada se não existir)", + "Host directory (not included in Proxmox backups)": "Diretório da máquina (não incluído nos backups do Proxmox)", "Host directory access for unprivileged containers has been prepared above": "O acesso ao diretório de host para contêineres sem privilégios foi preparado acima", + "Host directory kept, with its content:": "Diretório da máquina mantido, com seu conteúdo:", "Host directory permissions updated — unprivileged containers can now access it": "Permissões do diretório de host atualizadas – contêineres sem privilégios agora podem acessá-lo", "Host directory:": "Diretório de host:", "Host fstab CIFS Mounts:": "Host fstab montagens CIFS:", @@ -2008,7 +2557,14 @@ "Host fstab NFS mounts:": "Host fstab montagens NFS:", "Host fstab mounts (not registered as Proxmox storage):": "Host fstab montagens (não registradas como armazenamento Proxmox):", "Host identity (hostname, hosts)": "Identidade do host (nome do host, hosts)", + "Host kernel module loaded:": "Módulo do kernel da máquina carregado:", + "Host monitor configured: shared PID and network namespaces, LXCFS disabled in this container": "Monitor de máquina configurado: espaços de nomes compartilhados PID e rede, LXCFS desabilitados neste recipiente", + "Host monitor verified: PID and network namespaces and memory match the host": "Monitor da máquina verificado: os espaços de nomes de rede e de rede e a memória correspondem à máquina", + "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks.": "Monitor de host: PID/rede compartilhada e acesso privilegiado. Uma imagem comprometida pode afetar o Proxmox. Use apenas em redes confiáveis.", + "Host monitoring declined": "Monitoramento da máquina recusado", + "Host path for": "Localização da máquina para", "Host permissions applied (o+rwx + default ACL) — unprivileged LXCs can read/write through bind-mounts": "Permissões de host aplicadas (o+rwx + ACL padrão) — LXCs sem privilégios podem ler/gravar por meio de montagens de ligação", + "Host system path": "Localização do sistema da máquina", "Host write access confirmed.": "Acesso de gravação do host confirmado.", "Hostname": "Nome do host", "Hot changes applied. No reboot needed for these paths.": "Mudanças importantes aplicadas. Não é necessária reinicialização para esses caminhos.", @@ -2020,12 +2576,18 @@ "How do you want to select the Samba server?": "Como você deseja selecionar o servidor Samba?", "How do you want to select the folder to export?": "Como você deseja selecionar a pasta para exportar?", "How do you want to select the folder to share?": "Como você deseja selecionar a pasta para compartilhar?", + "How is it installed?": "Como é instalado?", + "How is the image described?": "Como se descreve a imagem?", "How to Access an LXC Terminal": "Como acessar um terminal LXC", "How to Access an LXC Terminal from Proxmox Host": "Como acessar um terminal LXC do Proxmox Host", "How to schedule": "Como agendar", + "Htpcmanager is a front end for many htpc related applications.": "Htpcmanager é uma interface para muitas aplicações relacionadas com htpc.", "I have read this": "eu li isso", "I/O priority configured": "Prioridade de E/S configurada", "ID already in use. Please choose another.": "ID já em uso. Por favor escolha outro.", + "IGDB": "IGDB", + "IGDB Client ID": "ID do Cliente do IGDB", + "IGDB Client Secret": "Segredo do Cliente do IGDB", "IMPORTANT": "IMPORTANTE", "IMPORTANT NOTES:": "NOTAS IMPORTANTES:", "IMPORTANT PREREQUISITES:": "PRÉ-REQUISITOS IMPORTANTES:", @@ -2062,7 +2624,14 @@ "IOMMU was configured during this wizard and a reboot is pending.": "O IOMMU foi configurado durante este assistente e uma reinicialização está pendente.", "IOMMU/VFIO configuration reverted": "Configuração IOMMU/VFIO revertida", "IP": "PI", + "IP address": "Endereço IP", + "IP address and firewall of the host": "Endereço IP e firewall do host", + "IP address of this container for the certificate (0.0.0.0 if unknown)": "Endereço IP deste recipiente para o certificado (0.0.0.0 se desconhecido)", + "IP address:": "Endereço IP:", "IP or hostname of the PVE node hosting the Borg server LXC:": "IP ou nome do host do nó PVE que hospeda o servidor Borg LXC:", + "IPv4 address of the container": "Endereço IPv4 do recipiente", + "IPv4 address of the containers": "Endereço IPv4 dos contentores", + "IPv4 gateway (empty = no outbound route)": "Gateway IPv4 (vazio = nenhuma rota de saída)", "ISO": "ISO", "ISO created successfully:": "ISO criado com sucesso:", "ISO image — installation images": "Imagem ISO – imagens de instalação", @@ -2095,6 +2664,7 @@ "If this happens, you can restore the backup from the 'Subscription Banner Removal' option in 'Uninstall optimizations'.": "Se isso acontecer, você pode restaurar o backup a partir da opção ‘Remoção de Banner de Assinatura’ em ‘Otimizações de desinstalação’.", "If this node runs hyper-converged Ceph: ensure Ceph is 19.x (Squid) BEFORE upgrading PVE.": "Se este nó executar o Ceph hiperconvergente: certifique-se de que o Ceph seja 19.x (Squid) ANTES de atualizar o PVE.", "If upgrade fails:": "Se a atualização falhar:", + "If you answer No, Glances is installed without privileges and monitors ONLY its own LXC, not Proxmox.": "Se responder Não, o Glances é instalado sem privilégios e monitora SOMENTE o seu próprio LXC, não o Proxmox.", "If you are sure you want to use it, please remove the": "Se você tem certeza de que deseja usá-lo, remova o", "If you choose No, install": "Se você escolher Não, instale", "If you continue, some adjustments may be duplicated or conflict with those already made by xshok.": "Se você continuar, alguns ajustes poderão ser duplicados ou entrar em conflito com aqueles já feitos pelo xshok.", @@ -2104,11 +2674,29 @@ "If you want HDMI/analog audio inside the VM, select the audio controller(s) to pass through along with the GPU.": "Se você deseja áudio HDMI/analógico dentro da VM, selecione o(s) controlador(es) de áudio para passar junto com a GPU.", "If you want to use a physical monitor on the passthrough GPU:": "Se você quiser usar um monitor físico na GPU de passagem:", "If your DHCP has a static reservation for the old MAC, update it.": "Se o seu DHCP tiver uma reserva estática para o MAC antigo, atualize-o.", + "Image": "Imagem", "Image Source Directory": "Diretório de origem da imagem", + "Image cache": "Cache de imagens", + "Image compatibility restored:": "Compatibilidade da imagem restaurada:", + "Image compatibility verified:": "Compatibilidade da imagem verificada:", "Image directory:": "Diretório de imagens:", + "Image download failed:": "A transferência da imagem falhou:", + "Image downloaded": "Imagem transferida", "Image file not found:": "Arquivo de imagem não encontrado:", "Image imported:": "Imagem importada:", + "Image integrity verified": "Integridade da imagem verificada", + "Image not allowed for the host monitor profile": "Imagem não permitida para o perfil do monitor da máquina", + "Image reference (for example ghcr.io/user/application:latest)": "Referência da imagem (por exemplo ghcr.io/usuário/aplicação:latest)", + "Image that is not in the catalog": "Imagem que não está no catálogo", + "Image:": "Imagem:", "Images to import:": "Imagens para importar:", + "Immich CUDA requires NVIDIA driver 545 or later": "Immich CUDA requires NVIDIA driver 545 ou posterior", + "Immich GPU profile not validated": "Perfil Immich GPU não validado", + "Immich configuration cancelled": "Configuração do Immich cancelada", + "Immich device without a validated translation": "Dispositivo Immich sem tradução validada", + "Immich requires CUDA compute capability 5.2 or later": "Immich requires Capacidade de computação CUDA 5.2 ou posterior", + "Immich runtime without a validated translation": "Immich runtime sem uma tradução validada", + "Immich server": "Servidor Immich", "Import — disk image imports": "Importar — importações de imagens de disco", "Import Disk Image to VM": "Importar imagem de disco para VM", "Import Disk to LXC": "Importar disco para LXC", @@ -2149,24 +2737,58 @@ "Incompatible Reset Capability for Intel GPU": "Capacidade de reinicialização incompatível para GPU Intel", "Incompatible Reset Capability for Intel dGPU": "Capacidade de reinicialização incompatível para Intel dGPU", "Incompatible archive": "Arquivo incompatível", + "Incompatible image platform": "Plataforma de imagem incompatível", + "Incompatible instance directory": "Directório de instância incompatível", + "Incompatible instance record": "Registo de instância incompatível", + "Incompatible record": "Registo incompatível", + "Incompatible stack assembly": "Montagem de pilha incompatível", "Incompatible version": "versão incompatível", + "Incomplete NVIDIA identity": "Identidade NVIDIA incompleta", + "Incomplete NVIDIA inventory": "Inventário NVIDIA incompleto", + "Incomplete Proxmox inventory": "Inventário Proxmox incompleto", + "Incomplete Proxmox inventory; recovery blocked": "Incompleto inventário Proxmox; recuperação bloqueada", + "Incomplete container removed:": "Recipiente incompleto removido:", + "Incomplete dependency order": "Ordem de dependência incompleta", + "Incomplete file recipe or unknown paths": "Receita de arquivo incompleta ou caminhos desconhecidos", + "Incomplete gzip layer": "Camada gzip incompleta", + "Incomplete or incompatible Proxmox inventory": "Inventário Proxmox incompleto ou incompatível", + "Incomplete primary network": "Rede primária incompleta", + "Incomplete stack order": "Ordem da pilha incompleta", + "Incomplete stack removed": "Pilha incompleta removida", + "Inconsistent adaptation profile and recipe": "Perfil e receita de adaptação inconsistentes", + "Inconsistent host monitor profile": "Perfil inconsistente do monitor da máquina", + "Inconsistent stack identity": "Identidade da pilha inconsistente", + "Inconsistent stack membership for": "Membro da pilha inconsistente para", "Increase container RAM temporarily to": "Aumente temporariamente a RAM do contêiner para", "Increase file and process limits for advanced workloads": "Aumente os limites de arquivos e processos para cargas de trabalho avançadas", "Increase various system limits": "Aumentar vários limites do sistema", "Increase vzdump backup speed": "Aumentar a velocidade de backup do vzdump", "Increasing maximum file system open files...": "Aumentando o máximo de arquivos abertos do sistema de arquivos...", "Increasing various system limits...": "Aumentando vários limites do sistema...", + "Independent LXC applications installed": "Aplicações independentes LXC instaladas", + "Independent LXCs: no main container or hookscript. Each one keeps its own Start with Proxmox setting.": "LXCs independentes: nenhum recipiente principal ou gancho. Cada um mantém a sua própria configuração Iniciar com Proxmox.", + "Independent applications, without a main container.": "Aplicações independentes, sem um recipiente principal.", + "Indexers and quality profiles still need to be configured.": "Os indexadores e os perfis de qualidade ainda precisam ser configurados.", "Inherited retention:": "retenção herdada:", "Inherited schedule:": "Cronograma herdado:", + "Initial Nextcloud administrator": "Administrador inicial do Nextcloud", + "Initial Nextcloud settings applied": "Configurações iniciais do Nextcloud aplicadas", + "Initial Paperless-ngx administrator": "Administrador inicial do Paperless-ngx", + "Initial Tandoor administrator": "Administrador inicial Tandoor", + "Initial administrator created:": "Administrador inicial criado:", + "Initial administrator user": "Utilizador de administrador inicial", "Initializing Borg repository if needed...": "Inicializando o repositório Borg, se necessário...", "Initiator IQN is authorised on the target": "O iniciador IQN está autorizado no alvo", "Initiator IQN:": "IQN do iniciador:", + "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers.": "Inkscape é um software gráfico vetorial de qualidade profissional que funciona em computadores desktop Linux, Mac OS X e Windows.", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN": "Dentro do LXC, crie o administrador: console kimai:user:create Your USERNAME Your EMAIL ROLE SUPER ADMIN", "Inspect disks before any action": "Inspecione os discos antes de qualquer ação", "Inspect host device nodes": "Inspecione os nós do dispositivo host", "Inspect passthrough/kernel events": "Inspecionar eventos de passagem/kernel", "Inspect storage config block:": "Inspecione o bloco de configuração de armazenamento:", "Inspection commands run directly. Template commands [T] require parameter substitution.": "Os comandos de inspeção são executados diretamente. Comandos de modelo [T] requerem substituição de parâmetro.", "Install": "Instalar", + "Install (experimental)": "Instalar (experimental)", "Install ALL utilities": "Instale TODOS os utilitários", "Install AMD GPU drivers inside the guest.": "Instale os drivers da GPU AMD dentro do convidado.", "Install CIFS client packages inside CT:": "Instale os pacotes do cliente CIFS dentro do CT:", @@ -2185,6 +2807,7 @@ "Install Samba inside CT:": "Instale o Samba dentro do CT:", "Install ZFS auto-snapshot": "Instale o instantâneo automático do ZFS", "Install a version from the branch the kernel names.": "Instale uma versão da ramificação dos nomes do kernel.", + "Install an image that is not in the catalog": "Instalar uma imagem que não está no catálogo", "Install analysis tools": "Instale ferramentas de análise", "Install and configure": "Instalar e configurar", "Install and configure Fastfetch": "Instalar e configurar o Fastfetch", @@ -2203,27 +2826,35 @@ "Install server packages inside CT:": "Instale pacotes de servidores dentro do CT:", "Install terminal multiplexers": "Instale multiplexadores de terminal", "Install the Edge TPU runtime (libedgetpu1-std)": "Instale o tempo de execução do Edge TPU (libedgetpu1-std)", + "Install this image?": "Instalar esta imagem?", "Install with Cloud-Init script": "Instalar com script Cloud-Init", "Install with ISO from UUP Dump": "Instalar com ISO do UUP Dump", + "Install with advanced settings": "Instalar com configurações avançadas", + "Install with default settings": "Instalar com as configurações padrão", "Install with personal ISO": "Instalar com ISO pessoal", + "Install with this configuration?": "Instalar com esta configuração?", "Install with traditional method": "Instale com método tradicional", "Install with: apt-get install open-iscsi": "Instale com: apt-get install open-iscsi", "Install/Update Coral TPU on Host": "Instalar/atualizar Coral TPU no host", "Install/Update NVIDIA Drivers (Host + LXC)": "Instalar/atualizar drivers NVIDIA (Host + LXC)", "Installation Complete": "Instalação concluída", + "Installation completed": "Instalação concluída", "Installation completed.": "Instalação concluída.", "Installation completed. Please reboot the server manually as soon as possible.": "Instalação concluída. Reinicie o servidor manualmente o mais rápido possível.", "Installation completed. Press Enter to continue...": "Instalação concluída. Pressione Enter para continuar...", "Installation failed": "Falha na instalação", "Installation finished but drivers are not loaded. A reboot may be required.": "A instalação foi concluída, mas os drivers não foram carregados. Uma reinicialização pode ser necessária.", + "Installation incomplete. These containers and their data are kept:": "Instalação incompleta. Estes contentores e os seus dados são conservados:", "Installation log:": "Registro de instalação:", "Installation summary": "Resumo da instalação", "Installed": "Instalado", "Installed at:": "Instalado em:", "Installed components:": "Componentes instalados:", + "Installed:": "Instalado:", "Installer already downloaded and verified.": "Instalador já baixado e verificado.", "Installer copied to container.": "Instalador copiado para contêiner.", "Installer downloaded.": "Instalador baixado.", + "Installer file not found:": "Ficheiro de instalação não encontrado:", "Installer finished with errors.": "O instalador terminou com erros.", "Installer not found:": "Instalador não encontrado:", "Installing": "Instalando", @@ -2274,9 +2905,14 @@ "Installing pigz...": "Instalando o pigz...", "Installing required dependencies...": "Instalando dependências necessárias...", "Installing required package: git": "Instalando o pacote necessário: git", + "Installing required packages...": "Instalando pacotes required...", "Installing required tools...": "Instalando as ferramentas necessárias...", "Installing selected utilities": "Instalando utilitários selecionados", "Installing system utilities...": "Instalando utilitários do sistema...", + "Installing the new image": "Instalando a nova imagem", + "Installing the new image...": "Instalando a nova imagem...", + "Installing the new image:": "Instalando a nova imagem:", + "Installing the stack startup hook...": "Instalando o gancho inicial da pilha...", "Installing zfs-auto-snapshot package...": "Instalando o pacote zfs-auto-snapshot...", "Installs essential packages if missing": "Instala pacotes essenciais se estiverem faltando", "Insufficient Disk Space": "Espaço em disco insuficiente", @@ -2288,8 +2924,17 @@ "Intel CPU detected": "CPU Intel detectada", "Intel GPU Tools installation completed!": "Instalação das ferramentas Intel GPU concluída!", "Intel GPU(s) detected:": "GPU(s) Intel detectada(s):", + "Intel VA-API + OpenCL (official mod)": "Intel VA-API + OpenCL (mod oficial)", "Intel VA-API drivers installed.": "Drivers Intel VA-API instalados.", "Intel iGPU passthrough configured.": "Passagem Intel iGPU configurada.", + "Intel render device for recognition": "Dispositivo de renderização Intel para reconhecimento", + "Intel/AMD (VA-API and QSV)": "Intel/AMD (VA-API e QSV)", + "Intel/AMD (VA-API)": "Intel/AMD (VA-API)", + "Intel/AMD (streaming rendering and encoding)": "Intel/AMD (transmissão e codificação)", + "Intel/AMD VA-API": "Intel/AMD VA-API", + "Intel/AMD VA-API (no OpenCL mod)": "Intel/AMD VA-API (sem OpenCL mod)", + "Intel/AMD render node": "Nó de renderização Intel/AMD", + "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters – building great software.": "IntelliJ IDEA ajuda você a escrever código mais rápido com ferramentas que eliminam tarefas tediosas e permitem que você se concentre no que importa – construindo ótimo software.", "Interactive (guided, prompts visible)": "Interativo (guiado, avisos visíveis)", "Interactive process viewer (press q to exit)": "Visualizador de processo interativo (pressione q para sair)", "Interface": "Interface", @@ -2303,50 +2948,186 @@ "Interfaces to Remove": "Interfaces para remover", "Internal error: NVIDIA installer path is empty or file not found.": "Erro interno: o caminho do instalador NVIDIA está vazio ou o arquivo não foi encontrado.", "Internal error: missing arguments in pmx_prepare_host_shared_dir": "Erro interno: argumentos ausentes em pmx_prepare_host_shared_dir", + "Internal subnet of the tunnel (change it only if it clashes)": "Subrede interna do túnel (altere-o apenas se colidir)", + "Interrupted operation": "operation interrompido", + "Interrupted operation:": "operation interrompida:", + "Interrupted stack operation found": "Pilha interrompida operation encontrada", "Invalid 'proxmox-ve' candidate (not 9.x or none). Please verify your repository configuration and network, then retry.": "Candidato 'proxmox-ve' inválido (não 9.x ou nenhum). Verifique a configuração e a rede do seu repositório e tente novamente.", + "Invalid ALLOWED_HOSTS value": "Valor Allowed hosts inválido", + "Invalid Home Assistant OS check timeout": "Tempo de verificação do sistema operacional Home Assistant inválido", "Invalid ID": "ID inválido", + "Invalid Intel render path": "Caminho de renderização Intel inválido", + "Invalid Jellyfin path:": "Caminho Jellyfin inválido:", + "Invalid MAC address:": "Endereço MAC inválido:", + "Invalid NVIDIA destination": "Destino NVIDIA inválido", + "Invalid NVIDIA device:": "Dispositivo NVIDIA inválido:", + "Invalid Nextcloud volume": "Volume Nextcloud inválido", + "Invalid OCI Entrypoint": "Ponto de Entrada OCI inválido", + "Invalid OCI digest": "Digestão OCI inválida", + "Invalid OCR language:": "Língua OCR inválida:", "Invalid Option": "Opção inválida", "Invalid Path": "Caminho inválido", + "Invalid Proxmox inventory": "Inventário Proxmox inválido", + "Invalid Python index:": "Índice Python inválido:", + "Invalid Python module:": "Módulo Python inválido:", + "Invalid Python package:": "Pacote Python inválido:", + "Invalid Python path in the repair:": "Caminho Python inválido na reparação:", + "Invalid Unpackerr variable": "Variável Unpackerr inválida", + "Invalid VFS cache mode": "Modo de cache VFS inválido", "Invalid VMID": "IDVM inválido", + "Invalid VMID or timeout": "VMID ou tempo limite inválidos", + "Invalid VMID:": "VMID inválido:", "Invalid ZFS pool name.": "Nome de pool ZFS inválido.", + "Invalid absolute mount path": "Caminho de montagem absoluto inválido", + "Invalid absolute path; avoid spaces, commas and relative segments": "Caminho absoluto inválido; evite espaços, vírgulas e segmentos relativos", + "Invalid acceleration profile": "Perfil de aceleração inválido", + "Invalid access address:": "Endereço de acesso inválido:", + "Invalid administrator email": "E- mail de administrador inválido", + "Invalid administrator user name": "Nome de usuário do administrador inválido", + "Invalid base VMID": "VMID base inválida", + "Invalid check package:": "Pacote de verificação inválido:", + "Invalid configuration path:": "Caminho de configuração inválido:", + "Invalid consume/export volumes": "Volumes de consumo/exportação inválidos", + "Invalid container path:": "Localização do contentor inválida:", + "Invalid credential file path:": "Caminho do arquivo credential inválido:", + "Invalid declarative entrypoint": "Ponto de entrada declarativo inválido", + "Invalid declarative stop signal": "Parada declarativa inválida signal", + "Invalid declarative working directory": "Pasta de trabalho declarativa inválida", + "Invalid device UID:": "UID do dispositivo inválido:", + "Invalid device mode": "Modo de dispositivo inválido", + "Invalid device mode:": "Modo do dispositivo inválido:", + "Invalid device path:": "Caminho inválido do dispositivo:", + "Invalid device paths for": "Caminhos de dispositivos inválidos para", "Invalid group name. Use letters, digits, underscore or hyphen, and start with a letter or underscore.": "Nome de grupo inválido. Use letras, dígitos, sublinhado ou hífen e comece com uma letra ou sublinhado.", + "Invalid health check": "Verificação de saúde inválida", + "Invalid healthcheck path": "Caminho de verificação de saúde inválido", + "Invalid healthcheck port": "Porta de verificação de saúde inválida", + "Invalid healthcheck request timeout": "Tempo limite de verificação de saúde inválido", + "Invalid healthcheck scheme": "Esquema de verificação de saúde inválido", + "Invalid healthcheck stability period": "Período de estabilidade de verificação de saúde inválido", + "Invalid healthcheck timeout": "Tempo limite de verificação de saúde inválido", + "Invalid host kernel module name:": "Nome do módulo do kernel da máquina inválido:", + "Invalid host monitor PID": "PID da máquina inválida", + "Invalid host path:": "Caminho da máquina inválido:", + "Invalid image probe descriptor": "descritor de sonda de imagem inválido", "Invalid input": "Entrada inválida", + "Invalid internal volume": "Volume interno inválido", + "Invalid list:": "Lista inválida:", + "Invalid machine learning CPU allocation:": "Alocação de CPU de aprendizado de máquina inválida:", + "Invalid machine learning resources": "Recursos de aprendizagem de máquina inválidos", + "Invalid main member or duplicated members": "Membro principal inválido ou membros duplicados", + "Invalid media path": "Caminho de mídia inválido", + "Invalid media volume": "Volume de mídia inválido", + "Invalid mediafiles volume": "Volume de ficheiros multimédia inválidos", + "Invalid minimum version:": "Versão mínima inválida:", + "Invalid mount name": "Nome de montagem inválido", + "Invalid mount type": "Tipo de montagem inválido", "Invalid name": "Nome inválido", "Invalid name. Use only letters, numbers, hyphens and underscores.": "Nome inválido. Use apenas letras, números, hífens e sublinhados.", + "Invalid native entrypoint": "Ponto de entrada nativo inválido", + "Invalid octal permissions": "Permissões octal inválidas", "Invalid option": "Opção inválida", "Invalid option, please try again.": "Opção inválida. Tente novamente.", "Invalid option. Skipping.": "Opção inválida. Pulando.", + "Invalid or duplicated mount path": "Caminho de montagem inválido ou duplicado", + "Invalid or duplicated network sysctl": "Sistema de rede inválido ou duplicado", "Invalid parameters for bind mount": "Parâmetros inválidos para montagem vinculada", + "Invalid path": "Caminho inválido", + "Invalid path in the NVIDIA inventory": "Caminho inválido no inventário NVIDIA", + "Invalid post-start timeout in the configuration:": "Tempo- limite pós- início inválido na configuração:", + "Invalid private bridge": "Ponte privada inválida", + "Invalid private network": "Rede privada inválida", + "Invalid prlimit value": "Valor do prlimit inválido", + "Invalid process limits format": "Formato de limites de processo inválido", + "Invalid registry digest": "Digest de registro inválido", + "Invalid remote name": "Nome remoto inválido", + "Invalid remote path": "Caminho remoto inválido", + "Invalid repair version:": "Versão de reparação inválida:", + "Invalid resources": "Recursos inválidos", + "Invalid restored volume path": "Caminho de volume restaurado inválido", + "Invalid running state": "Estado de execução inválido", + "Invalid security.unprivileged value:": "Título inválido. Valor não privilegiado:", "Invalid selection": "Seleção inválida", + "Invalid service alias": "Apelido de serviço inválido", + "Invalid service check URL": "URL de verificação de serviço inválido", + "Invalid service check arguments": "Argumentos de verificação de serviço inválidos", + "Invalid service check timeout": "Tempo limite de verificação do serviço inválido", + "Invalid shared path": "Caminho partilhado inválido", + "Invalid shutdown timeout": "Tempo de encerramento inválido", "Invalid size. Please enter a number in MB (e.g., 128, 256, 512).": "Tamanho inválido. Insira um número em MB (por exemplo, 128, 256, 512).", + "Invalid stack contract": "Contrato de pilha inválido", + "Invalid stack journal": "Diário de pilha inválido", + "Invalid stack members": "Membros inválidos da pilha", + "Invalid stack name": "Nome da pilha inválido", + "Invalid stack operation": "Pilha inválida operation", "Invalid storage ID. Use only letters, numbers, hyphens and underscores.": "ID de armazenamento inválido. Use apenas letras, números, hífens e sublinhados.", + "Invalid suite application": "Aplicativo de suite inválido", + "Invalid sysctl value:": "Valor do sysctl inválido:", + "Invalid template storage": "Armazenamento de modelos inválido", + "Invalid tmpfs options:": "Opções de tmpfs inválidas:", + "Invalid tmpfs path:": "Caminho do tmpfs inválido:", + "Invalid tmpfs size:": "Tamanho do tmpfs inválido:", "Invalid username or password.": "Nome de usuário ou senha inválidos.", + "Invalid variable name": "Nome da variável inválida", + "Invalid variable name:": "Nome da variável inválida:", + "Invalid volume size": "Tamanho de volume inválido", + "Invalid volume size:": "Tamanho de volume inválido:", + "Invalid volume target": "Alvo de volume inválido", + "Is the value a password or secret?": "O valor é uma senha ou segredo?", "Issue": "Emitir", "Issues found": "Problemas encontrados", "Issues were found. Would you like to use the Guided Cleanup Assistant?": "Problemas foram encontrados. Gostaria de usar o Assistente de limpeza guiada?", "Issues were found. Would you like to use the Guided Repair Assistant?": "Problemas foram encontrados. Gostaria de usar o Assistente de reparo guiado?", "It appears that you have already executed the xshok-proxmox post-install script on this system.": "Parece que você já executou o script pós-instalação xshok-proxmox neste sistema.", + "It asks for a system directory of the host:": "Ele pede um diretório de sistema da máquina:", + "It asks for capabilities or a relaxed confinement profile.": "Pede capacidades ou um perfil de confinamento relaxado.", + "It asks to see the processes of the host.": "Ele pede para ver os processos do host.", + "It cannot be removed on its own, because the application would stop working: continuing removes the whole application.": "Ele não pode ser removido por conta própria, porque o aplicativo iria parar de funcionar: continuando remove todo o aplicativo.", + "It is created empty; existing data is not migrated automatically.": "Ele é criado em branco; os dados existentes não são migrados automaticamente.", "It is recommended to create a backup before continuing.": "Recomenda-se criar um backup antes de continuar.", "It is strongly recommended to create a backup of your container before proceeding with the conversion.": "É altamente recomendável criar um backup do seu contêiner antes de prosseguir com a conversão.", + "It needs a privileged container, which is not isolated from the host.": "Precisa de um recipiente privilegiado, que não seja isolado do hospedeiro.", "It will be installed from the official GitHub repository.": "Ele será instalado a partir do repositório oficial do GitHub.", + "It works through the Docker engine of the host, and a native OCI container does not have one.": "Funciona através do motor Docker do hospedeiro, e um recipiente OCI nativo não tem um.", "Italian": "italiano", + "Its Compose file asks for privileged mode; the container is created unprivileged and that mode is only offered as an option.": "Seu arquivo Compose pede modo privilegiado; o recipiente é criado sem privilégios e esse modo só é oferecido como opção.", + "Its final cleanup did not complete. Select the stack again in the OCI management menu to complete it.": "Sua limpeza final não terminou. Selecione novamente a pilha no menu de gerenciamento OCI para completá-la.", + "Its labels are not applied: they are read by other Docker tools.": "Suas etiquetas não são aplicadas: são lidas por outras ferramentas Docker.", "JC Channel logo applied": "Logotipo do canal JC aplicado", + "JDownloader 2 with browser GUI and MyJDownloader support": "JDownloader 2 com suporte a interface gráfica do navegador e MyJDownloader", + "JDownloader WebUI": "JDownloader WebUI", "JSON output for scripts": "Saída JSON para scripts", + "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps.": "O Jackett funciona como um servidor proxy: traduz consultas de aplicativos (Sonarr, SickRage, CouchPotato, Mylar, etc) em consultas http específicas do site do rastreador, analisa a resposta html e envia os resultados de volta para o software solicitante. Isso permite obter uploads recentes (como RSS) e realizar pesquisas. O Jackett é um único repositório de lógica de raspagem & tradução de indexadores mantidos - removendo a carga de outros aplicativos.", + "Jellyfin WebUI": "Jellyfin WebUI", + "Jellyfin configuration applied:": "Configuração Jellyfin aplicada:", + "Jellyfin did not create encoding.xml before the timeout": "Jellyfin não criou coding.xml antes do tempo limite", + "Jellyfin has not created encoding.xml in any declared path": "Jellyfin não criou coding.xml em qualquer caminho declarado", + "Jellyseerr is a free and open source software application for managing requests for your media library.": "Jellyseerr é um aplicativo de software gratuito e de código aberto para gerenciar pedidos para sua biblioteca de mídia.", + "Jenkins Continuous Integration and Delivery server.": "Servidor de Integração e Entrega Contínua Jenkins.", + "Jenkins unlock": "Jenkins desbloquear", "Job ID (letters, numbers, - _)": "ID do trabalho (letras, números, - _)", "Job ID:": "ID do trabalho:", "Job deleted:": "Trabalho excluído:", "Job disabled:": "Trabalho desativado:", "Job enabled:": "Trabalho habilitado:", "Job selection returned empty id — aborting.": "A seleção do trabalho retornou um ID vazio – anulado.", + "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.": "O Joplin é um aplicativo gratuito de notas de código aberto, que pode lidar com um grande número de notas organizadas em notebooks.", "Journald configuration adjusted to": "Configuração do diário ajustada para", "Journald configuration is already optimized": "A configuração do Journald já está otimizada", "Journald configuration updated and service restarted": "Configuração do Journald atualizada e serviço reiniciado", "Journald optimization completed": "Otimização do diário concluída", "Journald optimized - Max size: 64M": "Diário otimizado - Tamanho máximo: 64M", + "Jupyter Lab (token only)": "Laboratório Jupyter (apenas por token)", "KDF:": "KDF:", "KVM MSR options added to /etc/modprobe.d/kvm.conf": "Opções KVM MSR adicionadas a /etc/modprobe.d/kvm.conf", "KVM MSR options ensured in /etc/modprobe.d/kvm.conf": "Opções KVM MSR garantidas em /etc/modprobe.d/kvm.conf", "KVM MSR options not present, nothing to revert": "Opções KVM MSR não presentes, nada para reverter", + "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX ™ is a trademark of OffSec.": "Kali-linux - é uma distribuição Linux Advanced Penetration Testing usada para testes de penetração, hacking ético e avaliações de segurança de rede. KALI LINUX TM é uma marca comercial da OffSec.", + "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections.": "Kasm Workspaces é uma plataforma de streaming de container docker para fornecer acesso baseado em navegador a desktops, aplicativos e serviços web. O Kasm utiliza a infraestrutura de Desktop Containerizada habilitada para devops (CDI) para criar containers sob demanda, descartáveis e docker acessíveis via navegador web. Exemplos de casos de uso incluem isolamento de navegador remoto (RBI), prevenção de perda de dados (DLP), desktop como um serviço (DaaS), serviços de acesso remoto seguro (RAS) e coleções de inteligência de código aberto (OSINT).", + "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!": "Kavita é um servidor de leitura rápido, rico em recursos, de plataforma cruzada. Construído com foco para ser uma solução completa para todas as suas necessidades de leitura. Configure seu próprio servidor e compartilhe sua coleção de leitura com seus amigos e familiares!", + "Kavita is a free and open source web based Comic and Book Server.": "Kavita é um Comic and Book Server gratuito e de código aberto.", + "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready.": "Kdenlive é um poderoso programa de edição de vídeo livre e de código aberto feito pela comunidade do KDE. Característica rica e produção pronta.", + "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass).": "KeePassXC é um gerenciador de senhas livre e de código aberto. Começou como uma comunidade fork de KeePassX (sendo uma porta multi-plataforma de KeePass).", "Keep GPU in LXC config (disable Start on boot)": "Mantenha a GPU na configuração LXC (desative Iniciar na inicialização)", "Keep GPU in LXC config + disable Start on boot": "Mantenha a GPU na configuração LXC + desative Iniciar na inicialização", "Keep GPU in VM config (disable Start on boot)": "Mantenha a GPU na configuração da VM (desative Iniciar na inicialização)", @@ -2356,6 +3137,7 @@ "Keep current version (N) if modified": "Manter a versão atual (N) se modificada", "Keep in source VM(s) + disable onboot + add to target VM": "Manter na(s) VM(s) de origem + desativar onboot + adicionar à VM de destino", "Keeping GPU in source VM config": "Mantendo a GPU na configuração da VM de origem", + "Keeping the settings changed in Proxmox:": "Manter as configurações alteradas em Proxmox:", "Kept sharedfiles group (has regular users assigned).": "Manteve o grupo sharedfiles (tem usuários regulares atribuídos).", "Kernel and architecture info": "Informações sobre kernel e arquitetura", "Kernel headers and build tools verified.": "Cabeçalhos de kernel e ferramentas de construção verificadas.", @@ -2377,6 +3159,17 @@ "Keyfile recovery — pick source host": "Recuperação de arquivo-chave – escolha o host de origem", "Keyfile removed.": "arquivo-chave removido.", "Keyrings method failed; trying apt-key fallback": "O método dos chaveiros falhou; tentando substituto do apt-key", + "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite.": "KiCad - Uma plataforma cruzada e Open Source Electronics Design Automation Suite.", + "Kimai has no default account. Enter the container with: pct enter {main_vmid}": "Kimai não tem conta padrão. Digite o recipiente com: pct enter {main vmid}", + "Kimai is a professional grade time-tracking application, free and open-source.": "Kimai é um aplicativo de rastreamento de tempo profissional, gratuito e de código aberto.", + "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more.": "Kometa é uma ferramenta poderosa projetada para lhe dar controle completo sobre suas bibliotecas de mídia. Com o Kometa, você pode levar sua personalização para o próximo nível, com controle granular sobre metadados, coleções, sobreposições e muito mais.", + "Kometa reads its configuration from /config/config.yml and the container only ships /config/config.yml.template. Copy the template to config.yml, fill in the required Plex and TMDb connections, then restart the container.": "Kometa lê a sua configuração a partir de /config/config.yml e o recipiente apenas navios /config/config.yml.template. Copie o modelo para config.yml, preencha o requi vermelho Plex e conexões TMDb, em seguida, reinicie o recipiente.", + "Komga is a media server for your comics, mangas, BDs, magazines and eBooks.": "Komga é um servidor de mídia para seus quadrinhos, mangás, BDs, revistas e eBooks.", + "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone.": "Krita é um programa de pintura livre e livre profissional. É feito por artistas que querem ver ferramentas de arte acessíveis para todos.", + "LAN access to the kept containers (stack configuration incomplete):": "Acesso LAN aos recipientes mantidos (configuração incompleta):", + "LAN address applied to the application URLs": "Endereço LAN aplicado aos URLs da aplicação", + "LLM App Development Platform": "Plataforma de Desenvolvimento de Aplicações LLM", + "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer.": "LM Studio pode executar modelos de IA locais como gpt-oss, Llama, Gemma, Qwen e DeepSeek em particular em seu computador.", "LUNs appear as block devices assignable to VMs": "LUNs aparecem como dispositivos de bloco atribuíveis a VMs", "LVM PV headers check completed": "Verificação dos cabeçalhos LVM PV concluída", "LVM physical volume detected": "Volume físico LVM detectado", @@ -2393,18 +3186,27 @@ "LXC containers with NVIDIA passthrough:": "Contêineres LXC com passagem NVIDIA:", "LXC conversion from privileged to unprivileged completed successfully!": "Conversão LXC de privilegiado para não privilegiado concluída com sucesso!", "LXC conversion from unprivileged to privileged completed successfully!": "Conversão LXC de não privilegiado para privilegiado concluída com sucesso!", + "LXC entries outside the NVIDIA inventory of the journal": "LXC inscrições fora do inventário NVIDIA da revista", + "LXC entries outside the selected acceleration profile": "Entradas LXC fora do perfil de aceleração seleccionado", + "LXC entry outside the read-only NVIDIA profile": "Entrada LXC fora do perfil NVIDIA apenas para leitura", "LXC removed:": "LXC removido:", "LXC stopped": "LXC parou", "LXC update skipped by user.": "Atualização do LXC ignorada pelo usuário.", "LXCs to destroy:": "LXCs para destruir:", + "Lab interruption after installing the new container": "Interrupção do laboratório após instalar o novo recipiente", + "Lab interruption after protecting the data": "Interrupção do laboratório após proteger os dados", + "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models.": "Label Studio é uma ferramenta de rotulagem de dados de código aberto. Permite rotular tipos de dados como áudio, texto, imagens, vídeos e séries temporais com uma interface simples e direta e exportar para vários formatos de modelo. Ele pode ser usado para preparar dados brutos ou melhorar dados de treinamento existentes para obter mais modelos ML accurate.", "Label:": "Rótulo:", "Language Change": "Mudança de idioma", "Language changed to": "Idioma alterado para", + "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)": "Língua/locale (por exemplo, es ES.UTF-8; a tradução de cada pedido não é garantida)", "Last 50 kernel log lines": "Últimas 50 linhas de log do kernel", "Last run:": "Última execução:", "Last system boot time": "Hora da última inicialização do sistema", "Latest version:": "Versão mais recente:", "Launching GPU passthrough assistant for VM": "Lançamento do assistente de passagem de GPU para VM", + "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork.": "Lazylibrarian é um programa para seguir autores e obter metadados para todas as suas necessidades de leitura digital. Ele usa um combination of Goodreads Librarything e opcionalmente GoogleBooks como fontes para informações de autor e livro. Este recipiente é baseado no DobyTang fork.", + "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user’s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012).": "O software Ldap-auth é para autenticar usuários que solicitam recursos protegidos de servidores proxiados pelo nginx. Ele inclui um daemon (ldap-auth) que se comunica com um servidor de autenticação, e um daemon servidor web que gera um cookie de autenticação baseado no credentials do usuário. Os daemons são escritos em Python para uso com um servidor de autenticação Lightweight Directory Access Protocol (LDAP) (OpenLDAP ou Microsoft Windows Active Directory 2003 e 2012).", "Legacy PVE 8 .list files commented or not present": "Arquivos .list PVE 8 legados comentados ou não presentes", "Legacy ceph.list commented or not present": "Ceph.list legado comentado ou não presente", "Legacy gasket-dkms cleanup could not be verified as complete.": "Não foi possível confirmar a conclusão da limpeza do pacote gasket-dkms legado.", @@ -2412,12 +3214,25 @@ "Legacy network tools (e.g., ifconfig)": "Ferramentas de rede legadas (por exemplo, ifconfig)", "Legend:": "Lenda:", "Let's review your current network configuration.": "Vamos revisar sua configuração de rede atual.", + "Liberate your videos and unleash infinite possibilities.": "Liberte seus vídeos e solte infinitas possibilidades.", + "Libraries: /data/media/movies, /data/media/series and /data/media/music. Select them in the media server.": "Bibliotecas: /data/media/movies, /data/media/series e /data/media/music. Selecione-os no servidor de mídia.", + "Library size in GB": "Tamanho da biblioteca em GB", + "LibreDB Studio": "LibreDB Studio", + "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity.": "LibreOffice é uma suíte de escritório livre e poderosa, e um sucessor do OpenOffice.org (comummente conhecido como OpenOffice). Sua interface limpa e ferramentas ricas em recursos ajudam você a liberar sua criatividade e aumentar sua produtividade.", + "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM.": "LibreWolf é uma versão personalizada e independente do Firefox, com os principais objetivos de privacidade, segurança e liberdade de usuário. LibreWolf também tem como objetivo remover todas as telemetrias, coleta de dados e aborrecimentos, bem como desativar recursos anti-liberdade como DRM.", + "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers.": "Librespeed é um Speedtest muito leve implementado em Javascript, usando XMLHttpRequest e Web Workers.", + "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Lidarr é um gerenciador de coleção de música para usuários Usenet e BitTorrent. Ele pode monitorar vários feeds RSS para novas faixas de seus artistas favoritos e vai agarrar, classificar e renomeá-los. Ele também pode ser configurado para atualizar automaticamente a qualidade dos arquivos já baixados quando um formato de melhor qualidade fica disponível.", + "Lightweight Docker management UI": "IU de gestão Docker leve", "Likely cause: host directory permissions deny the container's mapped UID.": "Causa provável: as permissões do diretório host negam o UID mapeado do contêiner.", "Limiting size and optimizing journald": "Limitando o tamanho e otimizando o diário", "Limiting size and optimizing journald...": "Limitando o tamanho e otimizando o diário...", + "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot.": "Limnoria Um bot Python IRC robusto, completo e amigável ao usuário/programador, com muitos plugins existentes. Sucessor do conhecido Supybot.", + "Limnoria joins no IRC network until its configuration file exists. Create it with the setup wizard from the Proxmox host: pct exec -- bash -c 'cd /config && limnoria-wizard'": "Limnoria não se junta a nenhuma rede IRC até que seu arquivo de configuração exista. Crie- o com o assistente de configuração a partir da máquina Proxmox: pct exec -- bash - c 'cd /config && limnoria- wizard'", "Line to paste (single line, including \"command=...\" prefix):": "Linha a ser colada (linha única, incluindo o prefixo \"command=...\"):", "Linux Installation Options": "Opções de instalação do Linux", "Linux/Mac path:": "Caminho Linux/Mac:", + "LinuxServer Jellyfin with optional GPU passthrough": "LinuxServer Jellyfin com passagem opcional de GPU", + "LinuxServer MariaDB requires a user, database and password": "LinuxServer MariaDB requires um usuário, banco de dados e senha", "List Available Disks": "Listar discos disponíveis", "List IOMMU group mapping": "Listar mapeamento de grupo IOMMU", "List NVMe devices": "Listar dispositivos NVMe", @@ -2443,7 +3258,9 @@ "Listening on:": "Ouvindo em:", "Listening ports:": "Portas de escuta:", "Listing relevant CT users and their mapped UID/GID on host...": "Listando usuários CT relevantes e seu UID/GID mapeado no host...", + "Load and verify the WireGuard module on the Proxmox host": "Carregar e verificar o módulo WireGuard na máquina Proxmox", "Loading modules...": "Carregando módulos...", + "Loading the host kernel module:": "Carregando o módulo do kernel da máquina:", "Local Disk Manager - Proxmox Host": "Gerenciador de disco local - Host Proxmox", "Local Disk Storages": "Armazenamentos em disco local", "Local Shared Directory on Host": "Diretório compartilhado local no host", @@ -2454,6 +3271,7 @@ "Local keyfile is missing but a recovery copy was found in PBS.": "O arquivo-chave local está faltando, mas uma cópia de recuperação foi encontrada no PBS.", "Local network only (192.168.0.0/16)": "Somente rede local (192.168.0.0/16)", "Local restore error log": "Log de erros de restauração local", + "Local storage for PostgreSQL": "Armazenamento local para PostgreSQL", "Locale generated": "Local gerado", "Location:": "Localização:", "Log": "Registro", @@ -2469,6 +3287,7 @@ "Logged-in users": "Usuários logados", "Logrotate optimization completed": "Otimização do Logrotate concluída", "Logrotate service restarted successfully": "Serviço Logrotate reiniciado com sucesso", + "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment.": "Lollypop é um player de música moderna leve projetado para trabalhar de forma excelente no ambiente de trabalho GNOME.", "Long Test — Background": "Teste Longo - Antecedentes", "Long self-test started on": "Autoteste longo iniciado em", "Long test — full scan, runs in background if closed": "Teste longo – verificação completa, executado em segundo plano se fechado", @@ -2477,7 +3296,11 @@ "Lookup domain registration info": "Pesquisar informações de registro de domínio", "Low Container Memory": "Memória baixa do contêiner", "Low free space warning": "Aviso de pouco espaço livre", + "Low-code programming for event-driven applications": "Programação de código baixo para aplicações orientadas para eventos", "Low-power CPU platform": "Plataforma de CPU de baixo consumo", + "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation": "Luanti (anteriormente Minetest) é uma plataforma de criação de jogos voxel de código aberto com fácil modding e criação de jogos", + "Lucky web interface": "Interface Web Lucky", + "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.": "Lychee é uma ferramenta gratuita de gerenciamento de fotos, que é executada em seu servidor ou espaço web. Instalar é uma questão de segundos. Envie, gerencie e compartilhe fotos como de uma aplicação nativa. Lychee vem com tudo que você precisa e todas as suas fotos são armazenadas com segurança.", "Lynis - Security Audit": "Lynis - Auditoria de Segurança", "Lynis Management": "Gestão Lynis", "Lynis command not found": "Comando Lynis não encontrado", @@ -2492,26 +3315,38 @@ "Lynis updated to version:": "Lynis atualizado para a versão:", "Lynis version:": "Versão Lynis:", "Lynis was not installed from Git. Reinstalling...": "Lynis não foi instalado a partir do Git. Reinstalando...", + "Lyrion Music Server is a streaming audio server for Squeezebox audio players.": "Lyrion Music Server é um servidor de áudio de streaming para leitores de áudio Squeezebox.", "M.2 / PCIe devices:": "Dispositivos M.2/PCIe:", + "M3U proxy server": "Servidor proxy M3U", "MAC Address": "Endereço MAC", + "MAC address": "Endereço MAC", "MACHINE TYPE": "TIPO DE MÁQUINA", + "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers.": "MAME é um emulador livre e de código aberto projetado para emular o hardware de jogos de arcade, consoles de jogos de vídeo, computadores antigos e outros sistemas em software em computadores pessoais modernos.", "MOTD configuration updated successfully": "Configuração MOTD atualizada com sucesso", "MOTD configuration was already up to date": "a configuração do MOTD já estava atualizada", "Machine Type": "Tipo de máquina", + "Machine learning": "Aprendizagem de máquina", + "Machine learning profile not implemented; it is not replaced by CPU:": "Perfil de aprendizagem de máquina não implementado; não é substituído por CPU:", "Machine type: q35": "Tipo de máquina: q35", "Machine: q35": "Máquina: q35", + "Main endpoint not yet defined": "Endpoint principal ainda não definido", "Major version differs:": "A versão principal é diferente:", "Make sure IOMMU is properly enabled and the system has been rebooted after activation.": "Certifique-se de que o IOMMU esteja habilitado corretamente e que o sistema tenha sido reinicializado após a ativação.", "Make sure there are no critical services running as they will be interrupted. Ensure your server can be safely rebooted.": "Certifique-se de que não haja serviços críticos em execução, pois eles serão interrompidos. Certifique-se de que seu servidor possa ser reinicializado com segurança.", "Make sure you have SSH or Web UI access before rebooting.": "Certifique-se de ter acesso SSH ou Web UI antes de reiniciar.", "Makefile missing in": "Makefile faltando em", "Malformed repository entries cleaned": "Entradas de repositório malformadas limpas", + "Manage OCI": "Gerenciar OCI", + "Manage OCI stack": "Gerenciar a pilha OCI", "Manage PBS encryption keyfile": "Gerenciar arquivo de chave de criptografia PBS", "Manage Secure Gateway": "Gerenciar Secure Gateway", "Manage and inspect VM disk images": "Gerenciar e inspecionar imagens de disco de VM", "Manage custom backup paths": "Gerencie caminhos de backup personalizados", "Manage custom paths (add / remove your folders)": "Gerencie caminhos personalizados (adicione/remova suas pastas)", + "Manage installed OCI applications": "Gerenciar aplicativos OCI instalados", "Manage local backup target": "Gerenciar destino de backup local", + "Managed disks must have backup enabled and a valid size": "Os discos gerenciados devem ter backup ativado e um tamanho válido", + "Managing Nginx proxy hosts with a simple, powerful interface.": "Gerenciando hosts proxy Nginx com uma interface simples e poderosa.", "Manual CLI Guide (Disk and Storage Manager)": "Guia CLI manual (Gerenciador de disco e armazenamento)", "Manual CLI Guide (GPU/TPU)": "Guia CLI manual (GPU/TPU)", "Manual Guide: Convert LXC Privileged to Unprivileged": "Guia manual: converter LXC privilegiado em não privilegiado", @@ -2526,29 +3361,51 @@ "Manual review is required.": "a revisão manual é necessária.", "Manual steps recommended after import": "Etapas manuais recomendadas após a importação", "Manual upgrade guide step by step": "Guia de atualização manual passo a passo", + "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing.": "Manyfold é um aplicativo web de código aberto e auto-hospedado para gerenciar uma coleção de modelos 3D, particularmente focado na impressão 3D.", "Mapped GID on host": "GID mapeado no host", "Mapped UID on host": "UID mapeado no host", + "Mariadb is one of the most popular database servers. Made by the original developers of MySQL.": "Mariadb é um dos servidores de banco de dados mais populares. Feito pelos desenvolvedores originais do MySQL.", + "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..": "Mastodon é um servidor de rede social livre e de código aberto baseado no ActivityPub onde os usuários podem seguir amigos e descobrir novos..", "Max FD limit / ulimit configured": "Limite máximo de FD/ulimit configurado", "Max FS open files configuration created successfully": "Configuração de arquivos abertos Max FS criada com sucesso", "Max user watches configured": "Máximo de visualizações do usuário configuradas", "Maximum auto-repair attempts reached (3). Please review the log and run any remaining commands manually.": "Máximo de tentativas de reparo automático atingido (3). Revise o log e execute quaisquer comandos restantes manualmente.", "May need to restart terminal": "Pode ser necessário reiniciar o terminal", + "Media & Streaming": "& Streaming de Mídia", + "Media discovery and request management for Jellyfin, Plex and Emby.": "Gerenciamento de descoberta e solicitação de mídia para Jellyfin, Plex e Emby.", + "Media library transcoding and health checking, with an internal worker node.": "Transcodificação da biblioteca de mídia e verificação de saúde, com um nó de trabalhador interno.", + "Media server": "Servidor de mídia", + "Media server selection cancelled or invalid": "Selecção do servidor de mídia cancelada ou inválida", + "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well.": "MediaElch é um MediaManager para Kodi. Informações sobre filmes, programas de TV, concertos e música são armazenados como arquivos nfo. Fanarts são baixados automaticamente de fanart.tv. Usando o gerador nfo, MediaElch pode ser usado com outros MediaCenters também.", + "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Medusa é um gerenciador automático de bibliotecas de vídeo para programas de TV. Ele assiste a novos episódios de seus programas favoritos, e quando eles são postados ele faz sua mágica.", + "Memory": "Memória", + "Memory in MB": "Memória em MB", "Memory optimization completed.": "Otimização de memória concluída.", "Memory optimizations removed": "Otimizações de memória removidas", "Memory restored.": "Memória restaurada.", "Memory settings optimized successfully": "Configurações de memória otimizadas com sucesso", "Memory:": "Memória:", + "Memos is a lightweight, self-hosted memo hub. Open Source and Free forever.": "Memos é um hub de memorando leve e auto-hospedado. Código Aberto e Livre para sempre.", + "Messaging & Queues": "Mensagens & Filas", + "Messenger for the Decentralized Web": "Mensageiro para a Web Descentralizada", "Method:": "Método:", + "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium.": "Microsoft Edge é um navegador web multiplataforma desenvolvido pela Microsoft e baseado em Chromium.", "Migrate VMs away from node being upgraded": "Migrar VMs para fora do nó que está sendo atualizado", "Migrate away any guests that must keep running": "Migre todos os convidados que precisam continuar em execução", "Migrated": "Migrado", "Migrated legacy ProxMenux NVIDIA blacklist state — module will reload after reboot": "Estado de lista negra legado ProxMenux NVIDIA migrado – o módulo será recarregado após a reinicialização", + "MineOS web interface": "Interface Web MineOS", + "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards.": "Minisatip é um servidor de satip multi-threaded versão 1.2 que é executado sob Linux e foi testado com placas DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC e ISDB-T.", "Mirror URL not available for this script.": "URL espelhado não disponível para este script.", + "Miscellaneous": "Diversos", "Missing": "Ausente", + "Missing OCI metadata:": "Faltam metadados OCI:", "Missing commands after installation:": "Comandos ausentes após a instalação:", "Missing dependency": "Dependência ausente", + "Missing native directive:": "Directiva nativa em falta:", "Missing on target:": "Faltando no alvo:", "Missing or invalid parameter": "Parâmetro ausente ou inválido", + "Missing required command:": "Falta o comando required:", "Missing required parameter": "Parâmetro obrigatório ausente", "Mixed GPU Modes": "Modos GPU mistos", "Mixed current mode detected in selected GPU(s).": "Modo atual misto detectado em GPU(s) selecionada(s).", @@ -2556,15 +3413,20 @@ "Mode": "Modo", "Model": "Modelo", "Modern resource monitor (press q to exit)": "Monitor de recursos moderno (pressione q para sair)", + "Modern, easy to use download automation for torrents and usenet.": "Moderno, fácil de usar automação de download para torrentes e usenet.", "Modifying Fastfetch configuration...": "Modificando a configuração do Fastfetch...", "Modules configuration updated.": "Configuração dos módulos atualizada.", "Modules loaded.": "Módulos carregados.", + "MongoDB 4.4, the last series that runs on a CPU without AVX.": "MongoDB 4.4, a última série que roda em uma CPU sem AVX.", + "Monica is an open source personal relationship management system, that lets you document your life.": "Monica é um sistema de gerenciamento de relacionamento pessoal de código aberto, que permite documentar sua vida.", "Monitor Activated": "Monitor ativado", "Monitor Deactivated": "Monitor desativado", "Monitor URL": "Monitorar URL", "Monitor disk I/O usage (press q to exit)": "Monitore o uso de E/S do disco (pressione q para sair)", "Monitor progress:": "Monitore o progresso:", + "Monitor, analyze, and alert on network performance.": "Monitorar, analisar e alertar sobre o desempenho da rede.", "Monitoring": "Monitoramento", + "Monitoring & Analytics": "Monitoramento e Análise", "Most common cause: the archive is corrupted (interrupted write, partial copy, or storage issue).": "Causa mais comum: o arquivo está corrompido (gravação interrompida, cópia parcial ou problema de armazenamento).", "Mount Added Successfully:": "Montagem adicionada com sucesso:", "Mount CIFS share:": "Monte o compartilhamento CIFS:", @@ -2592,13 +3454,19 @@ "Mount Samba Share on Host": "Monte o compartilhamento do Samba no host", "Mount USB disk?": "Montar disco USB?", "Mount a USB drive now": "Monte uma unidade USB agora", + "Mount activation cancelled": "Ativação da montagem cancelada", "Mount all datasets": "Monte todos os conjuntos de dados", "Mount already exists for this path in container": "A montagem já existe para este caminho no contêiner", "Mount and persist with UUID:": "Monte e persista com UUID:", + "Mount configuration cancelled": "Configuração da montagem cancelada", "Mount failed": "Falha na montagem", + "Mount mode applied": "Modo de montagem aplicado", + "Mount name": "Nome da montagem", + "Mount not authorized by the operation": "Montagem não autorizada pela operation", "Mount options:": "Opções de montagem:", "Mount path must be an absolute path starting with /": "O caminho de montagem deve ser um caminho absoluto começando com /", "Mount path:": "Caminho de montagem:", + "Mount paths must not overlap": "Os caminhos de montagem não devem sobrepor-se", "Mount point created": "Ponto de montagem criado", "Mount point created.": "Ponto de montagem criado.", "Mount point is visible but NOT writable from inside the container": "O ponto de montagem é visível, mas NÃO pode ser gravado de dentro do contêiner", @@ -2607,11 +3475,14 @@ "Mount point ready:": "Ponto de montagem pronto:", "Mount point removed successfully": "Ponto de montagem removido com sucesso", "Mount point:": "Ponto de montagem:", + "Mount points added:": "Pontos de montagem adicionados:", + "Mount read-only": "Montar somente leitura", "Mount shares on HOST first": "Monte compartilhamentos no HOST primeiro", "Mount specific dataset": "Monte conjunto de dados específico", "Mount status:": "Status da montagem:", "Mount this device and use it as the backup destination?": "Montar este dispositivo e usá-lo como destino de backup?", "Mount was busy — performed lazy unmount": "A montagem estava ocupada - executou a desmontagem preguiçosa", + "Mount your cloud drive on your home NAS": "Monte sua unidade de nuvem em seu NAS casa", "Mounted": "Montado", "Mounted ISO on device": "ISO montado no dispositivo", "Mounted at": "Montado em", @@ -2626,8 +3497,17 @@ "Mounting here will hide existing files until unmounted.": "A montagem aqui ocultará os arquivos existentes até serem desmontados.", "Move that copy offsite (USB, password manager, another host). Delete it from this path when done.": "Mova essa cópia para fora do local (USB, gerenciador de senhas, outro host).Exclua-o deste caminho quando terminar.", "Move to target VM (remove from source VM config)": "Mover para a VM de destino (remover da configuração da VM de origem)", + "Moving the data volumes aside": "Removendo os volumes de dados", + "Moving the data volumes aside...": "Mudando os volumes de dados de lado...", + "Multi-container application (experimental)": "Aplicação multi-contentor (experimental)", + "Multi-line variables are not supported": "Variáveis de várias linhas não são suportadas", + "Multiple networks or external networks are not yet supported": "Várias redes ou redes externas ainda não são suportadas", "Multiple recovery groups found in PBS. Pick the one that originally created the keyfile:": "Vários grupos de recuperação encontrados no PBS. Escolha aquele que originalmente criou o arquivo-chave:", "Multiple rootfs directories were found in this archive. Restore cannot continue automatically.": "Vários diretórios rootfs foram encontrados neste arquivo. A restauração não pode continuar automaticamente.", + "Music Collection and Streaming Server": "Servidor de Coleção e Streaming de Música", + "Music software that transforms your listening experience": "Software de música que transforma sua experiência de audição", + "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more.": "MySQL Workbench é uma ferramenta visual unificada para arquitetos de banco de dados, desenvolvedores e DBAs. O MySQL Workbench fornece modelagem de dados, desenvolvimento SQL e ferramentas de administração abrangentes para configuração de servidor, administração de usuários, backup e muito mais.", + "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL.": "Mylar3 é um download automático de Comic Book (cbr/cbz) para uso com NZB e torrents escritos em python. Ele suporta SABnzbd, NZBGET, e muitos clientes torrent além de DDL.", "NAS Systems": "Sistemas NAS", "NETWORK CONFIGURATION ANALYSIS": "ANÁLISE DE CONFIGURAÇÃO DE REDE", "NFS Access Restricted": "Acesso NFS restrito", @@ -2691,24 +3571,33 @@ "NOT FOUND": "NÃO ENCONTRADO", "NOTE: The host directory and its contents will remain unchanged.": "NOTA: O diretório host e seu conteúdo permanecerão inalterados.", "NVENC patch detected — list narrowed to versions supported by keylase/nvidia-patch.": "Patch NVENC detectado — lista reduzida às versões suportadas por keylase/nvidia-patch.", + "NVIDIA (CUDA)": "NVIDIA (CUDA)", + "NVIDIA (CUDA; official GPU image)": "NVIDIA (CUDA; imagem oficial da GPU)", + "NVIDIA (NVDEC/CUDA)": "NVIDIA (NVDEC/CUDA)", + "NVIDIA (NVENC/NVDEC)": "NVIDIA (NVENC/NVDEC)", "NVIDIA Actions": "Ações NVIDIA", "NVIDIA CPU hiding already configured": "Ocultação de CPU NVIDIA já configurada", "NVIDIA Container Toolkit": "NVIDIA Container Toolkit", + "NVIDIA Container Toolkit could not generate the runtime inventory": "NVIDIA Container Toolkit não pôde gerar o inventário em tempo de execução", "NVIDIA Container Toolkit installed. GPU validation pending until the host restarts.": "NVIDIA Container Toolkit instalado. Validação de GPU pendente até que o host seja reiniciado.", "NVIDIA Container Toolkit is incomplete. Missing:": "NVIDIA Container Toolkit está incompleto. Ausente:", "NVIDIA Container Toolkit is installed but its command line did not answer.": "NVIDIA Container Toolkit está instalado, mas sua linha de comando não respondeu.", + "NVIDIA Container Toolkit is missing on the host (nvidia-container-cli)": "NVIDIA Container Toolkit está faltando na máquina (nvidia-container-cli)", "NVIDIA Container Toolkit verified against the running driver.": "NVIDIA Container Toolkit verificado em relação ao driver em execução.", "NVIDIA DKMS entries removed.": "Entradas NVIDIA DKMS removidas.", "NVIDIA Driver Uninstall": "Desinstalação do driver NVIDIA", "NVIDIA Driver Version": "Versão do driver NVIDIA", "NVIDIA Drivers": "Controladores NVIDIA", "NVIDIA Drivers Not Found": "Drivers NVIDIA não encontrados", + "NVIDIA GPU / CUDA (Toolkit on the host)": "NVIDIA GPU / CUDA (Toolkit na máquina)", "NVIDIA GPU Driver Installation": "Instalação do driver da GPU NVIDIA", "NVIDIA GPU passthrough configured.": "Passagem de GPU NVIDIA configurada.", + "NVIDIA GPU prepared:": "NVIDIA GPU preparada:", "NVIDIA KVM args configured (kvm=off, vendor_id spoof)": "Argumentos NVIDIA KVM configurados (kvm=off, vendor_id spoof)", "NVIDIA KVM hiding (cpu hidden=1)": "Ocultação NVIDIA KVM (cpu oculta = 1)", "NVIDIA KVM hiding already configured": "Ocultação NVIDIA KVM já configurada", "NVIDIA Patch": "Atualização NVIDIA", + "NVIDIA device outside the expected native profile": "Dispositivo NVIDIA fora do perfil nativo esperado", "NVIDIA driver": "Controlador NVIDIA", "NVIDIA driver installed successfully.": "Driver NVIDIA instalado com sucesso.", "NVIDIA driver installed:": "Driver NVIDIA instalado:", @@ -2716,6 +3605,7 @@ "NVIDIA drivers are not installed or not loaded on this host.": "Os drivers NVIDIA não estão instalados ou não carregados neste host.", "NVIDIA host services disabled for VFIO mode": "Serviços de host NVIDIA desativados para modo VFIO", "NVIDIA host services/autoload already aligned for native mode": "Serviços de host/autoload NVIDIA já alinhados para o modo nativo", + "NVIDIA inside the container does not match the host driver or GPU": "NVIDIA dentro do recipiente não corresponde ao driver da máquina ou GPU", "NVIDIA install incomplete. Check log:": "Instalação da NVIDIA incompleta. Verifique o registro:", "NVIDIA installer downloaded successfully": "Instalador NVIDIA baixado com sucesso", "NVIDIA installer extracted.": "Instalador NVIDIA extraído.", @@ -2724,29 +3614,50 @@ "NVIDIA installer returned error": "O instalador NVIDIA retornou erro", "NVIDIA kernel modules unloaded successfully.": "Módulos do kernel NVIDIA descarregados com sucesso.", "NVIDIA libs require approximately 1.5GB of free space.": "As bibliotecas NVIDIA requerem aproximadamente 1,5 GB de espaço livre.", + "NVIDIA mount with an unauthorized source or target": "Montagem NVIDIA com uma fonte ou alvo não autorizado", "NVIDIA patch applied - check README for supported versions.": "Patch NVIDIA aplicado - verifique o README para versões suportadas.", "NVIDIA patch not applied.": "Patch NVIDIA não aplicado.", "NVIDIA per-BDF VFIO binding configured": "Ligação NVIDIA per-BDF VFIO configurada", + "NVIDIA permissions or device nodes differ from the official inventory": "As permissões ou nós do dispositivo NVIDIA diferem do inventário oficial", + "NVIDIA refresh validated; the container is stopped and its settings are kept": "Atualizar NVIDIA validado; o recipiente é parado e suas configurações são mantidas", + "NVIDIA runtime libraries or components are missing": "Faltam bibliotecas ou componentes em tempo de execução NVIDIA", + "NVIDIA selection not supported by this profile": "Seleção NVIDIA não suportada por este perfil", "NVIDIA services stopped and disabled.": "Os serviços NVIDIA foram interrompidos e desativados.", "NVIDIA udev rules and persistence service installed.": "Regras NVIDIA udev e serviço de persistência instalados.", "NVIDIA uninstallation steps completed.": "Etapas de desinstalação da NVIDIA concluídas.", "NVIDIA uninstaller completed.": "Desinstalador da NVIDIA concluído.", "NVIDIA update failed for LXC": "A atualização da NVIDIA falhou para LXC", "NVIDIA userspace libraries installed.": "Bibliotecas de espaço de usuário NVIDIA instaladas.", + "NVML does not match the current host driver": "O NVML não corresponde ao driver da máquina atual", "NVMe Disk Detected": "Disco NVMe detectado", "NVMe critical_warning is 0 (no critical warnings reported).": "NVMe critic_warning é 0 (nenhum aviso crítico relatado).", + "NVMe health status: PASSED": "Status de integridade do NVMe: APROVADO", "NVMe health status: WARNING (critical_warning =": "Status de integridade do NVMe: AVISO (critical_warning =", "NVMe skipped (to add as PCIe use 'Add Controller or NVMe PCIe to VM'):": "NVMe ignorado (para adicionar como PCIe, use 'Adicionar controlador ou NVMe PCIe à VM'):", "NVMe-specific SMART log": "Registro SMART específico do NVMe", + "NVR & Cameras": "Câmeras NVR", + "NVR with optional VA-API video acceleration and hardware object detectors": "NVR com aceleração de vídeo VA-API opcional e detectores de objetos de hardware", + "NZBGet web interface": "Interface Web NZBGet", + "Name": "Nome", + "Name for this application": "Nome para este aplicativo", "Name for this target:": "Nome para este alvo:", + "Name of the PostgreSQL user created on the first start": "Nome do usuário PostgreSQL criado no primeiro início", + "Name of the database created on the first start": "Nome da base de dados criada no primeiro início", + "Name of the internal worker node": "Nome do nó do trabalhador interno", + "Name of this wallabag instance, shown in the interface and in 2FA codes": "Nome desta instância wallabag, mostrado na interface e em códigos 2FA", + "Name or part of the description of the application": "Nome ou parte da descrição do pedido", "Name:": "Nome:", + "Named accounts need private mode. Stop the container, set public: false in /config/config.js, start it again and create each user with: pct exec -- env THELOUNGE_HOME=/config s6-setuidgid abc thelounge add ": "Contas nomeadas precisam de modo privado. Pare o contêiner, defina público: false in /config/config.js, inicie-o novamente e crie cada usuário com: pct exec -- env THELOUNGE HOME=/config s6-setuidgid abc thelounge add ", "Neither /etc/kernel/cmdline nor /etc/default/grub found.": "Nem /etc/kernel/cmdline nem /etc/default/grub foram encontrados.", "Nesting feature enabled": "Recurso de aninhamento ativado", "NetBIOS Service: RUNNING": "Serviço NetBIOS: EM EXECUÇÃO", "NetBIOS Service: STOPPED": "Serviço NetBIOS: PARADO", "NetBIOS port 139:": "Porta NetBIOS 139:", + "NetBox": "NetBox", + "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations.": "Netbox é uma ferramenta de gerenciamento de endereços IP (IPAM) e gerenciamento de infraestrutura de data center (DCIM). Inicialmente concebido pela equipe de engenharia de rede da DigitalOcean, o NetBox foi desenvolvido especificamente para atender às necessidades dos engenheiros de rede e infraestrutura. Pretende-se funcionar como uma fonte específica de domínio de verdade para a rede operations.", "Network": "Rede", "Network :": "Rede :", + "Network & Firewall": "Rede e Firewall", "Network (interfaces, DNS)": "Rede (interfaces, DNS)", "Network Bridge": "Ponte de rede", "Network Commands": "Comandos de rede", @@ -2764,6 +3675,7 @@ "Network Restarted": "Rede reiniciada", "Network Tools": "Ferramentas de rede", "Network access:": "Acesso à rede:", + "Network bridge": "Ponte de rede", "Network configuration backed up": "Configuração de rede com backup", "Network configuration has been restored from backup.": "A configuração de rede foi restaurada do backup.", "Network connection failed to": "Falha na conexão de rede", @@ -2776,12 +3688,16 @@ "Network service restarted successfully": "Serviço de rede reiniciado com sucesso", "Network service restarted successfully.": "Serviço de rede reiniciado com sucesso.", "Network share mounting (NFS/Samba) requires a PRIVILEGED container.": "A montagem de compartilhamento de rede (NFS/Samba) requer um contêiner PRIVILEGADO.", + "Network sysctls prepared:": "Sistemas de rede preparados:", "Network throughput test (client/server)": "Teste de rendimento de rede (cliente/servidor)", + "Network-wide Ad Blocking": "Bloqueamento de anúncios em toda a rede", + "Network-wide ad and tracker blocking": "Bloqueio de anúncios e rastreadores de rede", "NetworkManager Detected": "NetworkManager detectado", "NetworkManager has been removed successfully": "NetworkManager foi removido com sucesso", "NetworkManager is running (may cause conflicts)": "NetworkManager está em execução (pode causar conflitos)", "NetworkManager is running, which may conflict with Proxmox.": "O NetworkManager está em execução, o que pode entrar em conflito com o Proxmox.", "NetworkManager not running": "NetworkManager não está em execução", + "Networks the peers reach through the tunnel (0.0.0.0/0 = all traffic)": "Redes que os pares alcançam através do túnel (0.0.0.0/0 = todo o tráfego)", "New Folder in /mnt": "Nova pasta em /mnt", "New Group": "Novo grupo", "New Search": "Nova pesquisa", @@ -2789,14 +3705,26 @@ "New Virtual Machine": "Nova máquina virtual", "New backup job": "Nova tarefa de backup", "New backups on this host will be unencrypted until a new keyfile is set up.": "Novos backups neste host serão descriptografados até que um novo arquivo-chave seja configurado.", + "New image compatible:": "Nova imagem compatível:", + "New image installed": "Nova imagem instalada", + "New image installed, not verified yet": "Nova imagem instalada, ainda não verificada", + "New image verified, not saved yet": "Nova imagem verificada, ainda não salva", "New kernel staged; rebuilding DKMS drivers:": "Novo kernel testado;reconstruindo drivers DKMS:", "New mount options to apply:": "Novas opções de montagem para aplicar:", "New scheduled job (own timer + retention)": "Novo trabalho agendado (cronômetro próprio + retenção)", + "New value for": "Novo valor para", "New version available": "Nova versão disponível", "New version:": "Nova versão:", "Next Step Required": "Próxima etapa obrigatória", "Next Steps:": "Próximas etapas:", "Next step: stop that VM first, then run": "Próxima etapa: pare a VM primeiro e depois execute", + "Nextcloud configuration cancelled": "Configuração do Nextcloud cancelada", + "Nextcloud gives you access to all your files wherever you are.": "O Nextcloud dá-lhe acesso a todos os seus ficheiros onde quer que esteja.", + "Nextcloud volume size in GB": "Tamanho do volume Nextcloud em GB", + "Nextcloud with private PostgreSQL and Redis dependencies": "Nextcloud com dependências privadas PostgreSQL e Redes", + "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server.": "O Nginx é um servidor web HTTP, proxy reverso, cache de conteúdo, balanceador de carga, servidor proxy TCP/UDP e servidor proxy de e-mail.", + "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.": "Servidor web Nginx e proxy reverso com suporte php e um cliente Certbot (Vamos Criptografar). Contém também fail2ban para prevenção de intrusões.", + "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd.": "O Ngircd é um servidor de bate-papo gratuito, portátil e leve para redes pequenas ou privadas, desenvolvido sob a GNU General Public License (GPL). É fácil de configurar, pode lidar com endereços IP dinâmicos, e suporta conexões protegidas por SSL IPv6, bem como PAM para autenticação. É escrito do zero e não baseado no IRCd original.", "No": "Não", "No .ova or .ovf files found in:": "Nenhum arquivo .ova ou .ovf encontrado em:", "No .ovf descriptor found inside OVA.": "Nenhum descritor .ovf encontrado dentro do OVA.", @@ -2814,6 +3742,7 @@ "No CTs available in the system.": "Não há CTs disponíveis no sistema.", "No Changes Needed": "Nenhuma alteração necessária", "No Cleanup Needed": "Nenhuma limpeza necessária", + "No Compose file was given": "Não foi indicado nenhum ficheiro Compose", "No Controller/NVMe selected for now.": "Nenhum controlador/NVMe selecionado no momento.", "No Coral Detected": "Nenhum Coral detetado", "No Coral TPU device was found on this host (neither PCIe/M.2 nor USB).": "Nenhum dispositivo Coral TPU foi encontrado neste host (nem PCIe/M.2 nem USB).", @@ -2825,6 +3754,7 @@ "No Exports": "Sem exportações", "No Exports Found": "Nenhuma exportação encontrada", "No Folders": "Sem pastas", + "No GPU (CPU)": "Sem GPU (CPU)", "No GPU Detected": "Nenhuma GPU detectada", "No GPU selected.": "Nenhuma GPU selecionada.", "No GPU selected. Please select at least one GPU to continue.": "Nenhuma GPU selecionada. Selecione pelo menos uma GPU para continuar.", @@ -2832,12 +3762,15 @@ "No Guest Shares": "Sem compartilhamentos de convidados", "No IP": "Sem IP", "No IP assigned": "Nenhum IP atribuído", + "No IPv4 address was detected after 30 seconds.": "Nenhum endereço IPv4 foi detectado após 30 segundos.", "No ISO file detected after UUP Dump process.": "Nenhum arquivo ISO detectado após o processo UUP Dump.", "No ISO images found in Proxmox ISO storages.": "Nenhuma imagem ISO encontrada nos armazenamentos ISO do Proxmox.", "No ISO selected.": "Nenhum ISO selecionado.", "No ISO was generated.": "Nenhum ISO foi gerado.", "No Images Found": "Nenhuma imagem encontrada", "No Intel GPU detected on this system.": "Nenhuma GPU Intel detectada neste sistema.", + "No LAN address was obtained": "Nenhum endereço LAN foi obtido", + "No LAN address was obtained for the service:": "Nenhum endereço LAN foi obtido para o serviço:", "No LXC containers available": "Nenhum contêiner LXC disponível", "No LXC containers found": "Nenhum contêiner LXC encontrado", "No LXC containers found on this system.": "Nenhum contêiner LXC encontrado neste sistema.", @@ -2855,7 +3788,9 @@ "No NFS shares currently mounted.": "Nenhum compartilhamento NFS montado atualmente.", "No NVIDIA GPU detected on this system.": "Nenhuma GPU NVIDIA detectada neste sistema.", "No NVIDIA GPU has been detected on this system. The installer will now exit.": "Nenhuma GPU NVIDIA foi detectada neste sistema. O instalador será encerrado agora.", + "No NVIDIA GPU is available": "Nenhuma GPU NVIDIA está disponível", "No NVIDIA driver installed.": "Nenhum driver NVIDIA instalado.", + "No OCI instances are registered.": "Não estão registadas instâncias OCI.", "No PBS keyfile is installed on this host and no automatic recovery was possible.": "Nenhum arquivo-chave PBS está instalado neste host e nenhuma recuperação automática foi possível.", "No PVE vzdump job uses a": "Nenhum trabalho PVE vzdump usa um", "No PVs with old headers found.": "Nenhum PV com cabeçalhos antigos encontrados.", @@ -2891,6 +3826,7 @@ "No Virtual Machines found on this system.": "Nenhuma máquina virtual encontrada neste sistema.", "No ZFS pools detected. Skipping ZFS ARC optimization.": "Nenhum pool ZFS detectado. Ignorando a otimização do ZFS ARC.", "No ZFS pools detected. Skipping ZFS autotrim.": "Nenhum pool ZFS detectado. Ignorando o ajuste automático do ZFS.", + "No acceleration (CPU)": "Sem aceleração (CPU)", "No accessible": "Não acessível", "No accessible NFS servers found.": "Nenhum servidor NFS acessível encontrado.", "No accessible Samba servers found.": "Nenhum servidor Samba acessível encontrado.", @@ -2900,11 +3836,13 @@ "No active session": "Nenhuma sessão ativa", "No additional GPU can be added.": "Nenhuma GPU adicional pode ser adicionada.", "No additional device needs to be added.": "Nenhum dispositivo adicional precisa ser adicionado.", + "No applications match": "Nenhuma aplicação corresponde", "No archives": "Sem arquivos", "No archives found in this Borg repository.": "Nenhum arquivo encontrado neste repositório Borg.", "No available Controllers/NVMe devices were found.": "Nenhum controlador/dispositivo NVMe disponível foi encontrado.", "No available disks found.": "Nenhum disco disponível encontrado.", "No backup found, logrotate configuration not changed": "Nenhum backup encontrado, configuração do logrotate não alterada", + "No backup is scheduled: the rsnapshot lines in /config/crontabs/root are commented out. Uncomment or adjust the intervals you want, then restart the container.": "Nenhum backup está agendado: as linhas rsnapshot em /config/crontabs/root são comentadas. Descomentar ou ajustar os intervalos desejados, em seguida, reiniciar o recipiente.", "No backups": "sem backups", "No backups found": "Nenhum backup encontrado", "No bridge configuration issues found": "Nenhum problema de configuração de ponte encontrado", @@ -2921,6 +3859,7 @@ "No compatible PVE jobs": "Nenhum trabalho PVE compatível", "No compatible disk images found in:": "Nenhuma imagem de disco compatível encontrada em:", "No configuration issues found": "Nenhum problema de configuração encontrado", + "No container of the stack was modified.": "Nenhum recipiente da pilha foi modificado.", "No container runtime available.": "Nenhum tempo de execução do contêiner disponível.", "No container selected. Exiting.": "Nenhum contêiner selecionado. Saindo.", "No controller/NVMe selected.": "Nenhum controlador/NVMe selecionado.", @@ -2951,11 +3890,13 @@ "No folders found in /mnt. Please create a new folder.": "Nenhuma pasta encontrada em /mnt. Por favor, crie uma nova pasta.", "No folders found inside /mnt in the CT.": "Nenhuma pasta encontrada dentro de /mnt no CT.", "No format-safe disks are available.": "Nenhum disco de formato seguro está disponível.", + "No free ProxMenux private /24 network is available": "Nenhuma rede privada ProxMenux livre 24 está disponível", "No gasket DKMS registrations remain.": "Não restam registos DKMS de gasket.", "No group creation required — uses world-writable sticky bit permissions.": "Não é necessária a criação de grupos — usa permissões de sticky bit graváveis ​​mundialmente.", "No host VFIO reconfiguration expected": "Nenhuma reconfiguração VFIO do host é esperada", "No host VFIO/native binding changes were required.": "Nenhuma alteração de ligação VFIO/nativa do host foi necessária.", "No host backups were found in this PBS repository:": "Nenhum backup de host foi encontrado neste repositório PBS:", + "No host directory is used by this application.": "Nenhuma pasta host é usada por esta aplicação.", "No host reboot expected": "Nenhuma reinicialização do host é esperada", "No host write access — server-side ACL or root_squash. Continuing anyway.": "Sem acesso de gravação no host — ACL do lado do servidor ou root_squash. Continuando de qualquer maneira.", "No host write access — server-side ACL. Continuing anyway.": "Sem acesso de gravação no host — ACL do lado do servidor. Continuando de qualquer maneira.", @@ -2964,6 +3905,7 @@ "No iSCSI storage configured.": "Nenhum armazenamento iSCSI configurado.", "No iSCSI storage found in Proxmox.": "Nenhum armazenamento iSCSI encontrado no Proxmox.", "No iSCSI targets found on portal": "Nenhum destino iSCSI encontrado no portal", + "No image was given": "Nenhuma imagem foi dada", "No import disks selected for now.": "Nenhum disco de importação selecionado no momento.", "No importable disks available. System disks and protected disks are hidden.": "Nenhum disco importável disponível. Os discos do sistema e os discos protegidos ficam ocultos.", "No installation information available.": "Nenhuma informação de instalação disponível.", @@ -2975,6 +3917,7 @@ "No mount point was specified.": "Nenhum ponto de montagem foi especificado.", "No mount points found in any container": "Nenhum ponto de montagem encontrado em nenhum contêiner", "No mount points found in container": "Nenhum ponto de montagem encontrado no contêiner", + "No name was given": "Nenhum nome foi dado", "No network configuration backups found.": "Nenhum backup de configuração de rede encontrado.", "No network interfaces configured (besides loopback)": "Nenhuma interface de rede configurada (além de loopback)", "No new Controller/NVMe entries were added.": "Nenhuma nova entrada de Controlador/NVMe foi adicionada.", @@ -2999,9 +3942,11 @@ "No scheduled backup jobs configured.": "Nenhuma tarefa de backup agendada configurada.", "No scheduled backup jobs found.": "Nenhum trabalho de backup agendado foi encontrado.", "No scripts found for:": "Nenhum script encontrado para:", + "No security relaxation is required for the reviewed profile.": "Nenhum relaxamento de segurança é required para o perfil revisado.", "No self-test history found for": "Nenhum histórico de autoteste encontrado para", "No self-test log available for": "Nenhum registro de autoteste disponível para", "No server IP or hostname provided.": "Nenhum IP do servidor ou nome de host fornecido.", + "No shared media content.": "Sem conteúdo de mídia compartilhado.", "No shared mount detected. Applying standard local access.": "Nenhuma montagem compartilhada detectada. Aplicando acesso local padrão.", "No shares configured.": "Nenhum compartilhamento configurado.", "No shares found in smb.conf.": "Nenhum compartilhamento encontrado em smb.conf.", @@ -3031,24 +3976,34 @@ "No valid mount points found": "Nenhum ponto de montagem válido encontrado", "No version in this branch is currently supported by keylase/nvidia-patch — the NVENC patch will not reapply after reinstall.": "Nenhuma versão nesta ramificação é atualmente suportada por keylase/nvidia-patch — o patch NVENC não será reaplicado após a reinstalação.", "No virtual machines were found on this host.": "Nenhuma máquina virtual foi encontrada neste host.", + "No working NVIDIA GPU was found": "Não foi encontrada nenhuma GPU NVIDIA funcional", "No write permissions on:": "Sem permissões de gravação em:", "No, keep local only": "Não, mantenha apenas local", "No-subscription repository present": "Repositório sem assinatura presente", "No: the key stays only at": "Não: a chave fica apenas em", + "Node octal permissions (e.g. 0660)": "Permissões octais do nó (por exemplo, 0660)", "Non-Debian container detected": "Contêiner não-Debian detectado", "Non-free firmware warnings disabled": "Avisos de firmware não-livre desativados", "None": "Nenhum", "Normalizing stable monitor service...": "Normalizando serviço de monitor estável...", "Not Mounted": "Não montado", + "Not a JSON object:": "Não é um objecto JSON:", "Not all platforms support Controller/NVMe passthrough reliably.": "Nem todas as plataformas oferecem suporte à passagem de controlador/NVMe de maneira confiável.", + "Not all shared directories were verified": "Nem todos os diretórios compartilhados foram verificados", "Not an OVH server, skipping RTM installation": "Não é um servidor OVH, ignorando a instalação do RTM", "Not currently mounted": "Atualmente não montado", "Not currently mounted — skipping umount.": "Atualmente não montado – ignorando umount.", + "Not enough free space for the backup": "Não há espaço livre suficiente para o backup", "Not found": "Não encontrado", + "Not found in the OCI archive:": "Não encontrado no arquivo OCI:", "Not imported:": "Não importado:", "Not mounted": "Não montado", "Not portable:": "Não portátil:", "Not registered as Proxmox storage — use 'LXC Mount Manager' to bind-mount": "Não registrado como armazenamento Proxmox - use 'LXC Mount Manager' para vincular a montagem", + "Not required (access code only)": "Não é required (apenas código de acesso)", + "Not required (password only)": "Não é required (somente palavra-passe)", + "Not required (token only)": "Não é required (apenas por token)", + "Not yet verified by ProxMenux (beta)": "Ainda não verificado pelo ProxMenux (beta)", "Note: A system reboot will be required after enabling IOMMU.": "Nota: Será necessária uma reinicialização do sistema após ativar o IOMMU.", "Note: this only works if the NFS server does NOT use 'all_squash' for root.": "Nota: isso só funciona se o servidor NFS NÃO usar 'all_squash' para root.", "Notes": "Notas", @@ -3063,8 +4018,20 @@ "Nothing to schedule for reboot from selected paths.": "Nada para agendar a reinicialização dos caminhos selecionados.", "Nouveau module is loaded, attempting to unload...": "O módulo Nouveau está carregado, tentando descarregar...", "Number of CPU cores (default: 2)": "Número de núcleos de CPU (padrão: 2)", + "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources.": "Nzbget é um downloader usenet, escrito em C++ e projetado com o desempenho em mente para alcançar a velocidade máxima de download usando muito poucos recursos do sistema.", + "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra.": "Nzbhydra2 é uma aplicação de pesquisa meta para indexadores NZB, o sucessor espiritual para NZBmegasearcH, e uma evolução da aplicação original NZBHydra.", "OCI containers require Proxmox VE 9.1 or later.": "Os contêineres OCI requerem Proxmox VE 9.1 ou posterior.", + "OCI management": "Gestão de OCI", + "OCI management could not be completed. Check the backend status; no additional cleanup has been authorized.": "A gestão do OCI não pôde ser concluída. Verifique o estado da infra- estrutura; nenhuma limpeza adicional foi autorizada.", + "OCI manager Apps (beta)": "Apps do gestor de OCI (beta)", + "OCI manager Apps is a beta: if something does not work as expected, please report it on GitHub with the application name.": "Gerenciador de OCI Apps é um beta: se algo não funcionar como esperado, por favor, relate no GitHub com o nome da aplicação.", + "OCI metadata integrity mismatch": "Incompatibilidade da integridade dos metadados OCI", + "OCI metadata too large": "Metadados OCI demasiado grandes", + "OCI stack management": "Gestão de pilhas OCI", + "OCI verification failed:": "A verificação do OCI falhou:", + "OCR language (Tesseract code)": "Língua OCR (código Tesseract)", "OK": "OK", + "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms.": "ONLYOFFICE fornece uma gama completa de ferramentas para criar, editar e colaborar em documentos de texto, planilhas, apresentações, formulários PDF e arquivos PDF regulares em plataformas web, desktop e móveis.", "OR add new PVE 9 no-subscription repository:": "OU adicione novo repositório PVE 9 sem assinatura:", "OS hint:": "Dica do sistema operacional:", "OS release details": "Detalhes da versão do sistema operacional", @@ -3078,11 +4045,18 @@ "OVH RTM removed (Puppet artefacts may need manual cleanup)": "OVH RTM removido (artefatos de marionetes podem precisar de limpeza manual)", "OVH server detected": "Servidor OVH detectado", "OVH server detection and RTM installation process completed": "Processo de detecção do servidor OVH e instalação RTM concluído", + "Observer is not responding on port 4357": "Observador não está respondendo na porta 4357", + "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption.": "Obsidian é um aplicativo de anotações que permite criar, vincular e organizar suas notas em seu dispositivo, com centenas de plugins e temas para personalizar seu fluxo de trabalho. Você também pode publicar suas notas online, acessá-las offline e sincronizá-las com segurança com criptografia de ponta a ponta.", "Offer as exit node?": "Oferecer como nó de saída?", + "Official Emby Media Server image with optional VA-API or NVIDIA acceleration.": "Imagem oficial do servidor de mídia Emby com aceleração opcional VA-API ou NVIDIA.", + "Official Jellyfin image with optional VA-API or NVIDIA acceleration.": "Imagem Jellyfin oficial com aceleração opcional VA-API ou NVIDIA.", "Official Linux Distributions": "Distribuições oficiais do Linux", + "Official Plex Media Server image with optional hardware transcoding.": "Imagem oficial do servidor de mídia Plex com transcodificação de hardware opcional.", + "Official image": "Imagem oficial", "Old debian.sources file removed to prevent duplication": "Arquivo debian.sources antigo removido para evitar duplicação", "Old memory configuration detected. Replacing with balanced optimization...": "Configuração de memória antiga detectada. Substituindo por otimização balanceada...", "Old time services removed successfully": "Serviços antigos removidos com sucesso", + "Ombi allows you to host your own Plex Request and user management system.": "Ombi permite que você hospede seu próprio sistema de pedido de Plex e gerenciamento de usuários.", "On a privileged CT the mount options carry the only permissions.": "Em um CT privilegiado, as opções de montagem possuem as únicas permissões.", "On some systems, when starting the VM the host may slow down for several minutes until it stabilizes, or freeze completely.": "Em alguns sistemas, ao iniciar a VM, o host pode ficar lento por vários minutos até se estabilizar ou congelar completamente.", "On the Borg server, append the following line to:": "No servidor Borg, anexe a seguinte linha a:", @@ -3091,32 +4065,53 @@ "Once finished, re-run the script 'PVE 8 to 9 check' to verify that all issues.": "Quando terminar, execute novamente o script 'PVE 8 to 9 check' para verificar todos os problemas.", "Once installed, open the VirtIO ISO and run the installer to complete driver setup.": "Depois de instalado, abra o VirtIO ISO e execute o instalador para concluir a configuração do driver.", "One or more NVIDIA GPUs are currently configured for VM passthrough (vfio-pci):": "Uma ou mais GPUs NVIDIA estão atualmente configuradas para passagem de VM (vfio-pci):", + "Online retro games emulator": "Emulador de jogos retro online", + "Only a Docker Swarm uses these settings, so they are not applied:": "Apenas um Swarm Docker usa estas configurações, então elas não são aplicadas:", "Only convert to privileged if absolutely necessary for your use case.": "Converta para privilegiado apenas se for absolutamente necessário para o seu caso de uso.", "Only fully free disks are shown (not system-used and not referenced by VM/LXC).": "Somente discos totalmente livres são mostrados (não usados ​​pelo sistema e não referenciados pelo VM/LXC).", "Only if using enterprise subscription": "Somente se estiver usando assinatura corporativa", "Only if using no-subscription repository": "Somente se estiver usando repositório sem assinatura", "Only needed if you mounted the filesystem in step 6b": "Necessário apenas se você montou o sistema de arquivos na etapa 6b", + "Only one image at a time can be installed this way.": "Só uma imagem de cada vez pode ser instalada desta forma.", "Only removes storage definition, not remote data.": "Remove apenas a definição de armazenamento, não os dados remotos.", "Only run this if you used LVM (step 6b):": "Execute isso apenas se você usou LVM (etapa 6b):", "Only the host backup hook is removed — PVE vzdump jobs targeting this storage stay intact.": "apenas o gancho de backup do host é removido – as tarefas PVE vzdump direcionadas a esse armazenamento permanecem intactas.", + "Only the image reference, with no Compose file": "Apenas a referência da imagem, sem composição do ficheiro", "Open": "Abrir", + "Open Source realtime backend in 1 file": "Abrir a infra- estrutura em tempo real em 1 ficheiro", "Open rwx + default inheritance for new files": "Abra rwx + herança padrão para novos arquivos", + "Open source chat UI for AI models": "Interface de chat de código aberto para modelos de IA", + "Open source home automation that puts local control and privacy first.": "Automação de casa de código aberto que coloca o controle local e privacidade em primeiro lugar.", + "Open source, lightweight, native, supports (HTTP, BitTorrent, Magnet, etc.) for downloading.": "Código aberto, leve, nativo, suporta (HTTP, BitTorrent, Magnet, etc.) para download.", "Open the VM console and wait for the installer to boot": "Abra o console da VM e espere o instalador inicializar", "Open the VM console and wait for the loader to boot": "Abra o console da VM e espere o carregador inicializar", "Open the dashboard from this host on port 8008 to create a new admin account.": "Abra o painel deste host na porta 8008 para criar uma nova conta de administrador.", "Open the dashboard to create a new admin account:": "Abra o painel para criar uma nova conta de administrador:", + "Open-source AI-powered coding assistant": "Assistente de codificação com código aberto", + "Open-source UI for building and debugging multi-agent and RAG applications": "UI de código aberto para a construção e depuração de aplicações multi-agente e RAG", + "Open-source self-hosted SQL IDE.": "SQL IDE self-hosted do código aberto.", + "OpenClaw is a personal AI assistant you run on your own devices": "OpenClaw é um assistente pessoal de IA que você executa em seus próprios dispositivos", + "OpenList": "OpenList", + "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world.": "O OpenShot Video Editor é um premiado editor de vídeo gratuito e de código aberto para Linux, Mac e Windows, e é dedicado a fornecer soluções de edição e animação de vídeo de alta qualidade para o mundo.", + "OpenVINO requires a CPU quota to keep the CPU topology": "OpenVINO requires uma quota de CPU para manter a topologia da CPU", + "OpenVINO requires the render device of an Intel GPU": "OpenVINO requires o dispositivo de renderização de uma GPU Intel", "OpenVSwitch installation could not be verified": "A instalação do OpenVSwitch não pôde ser verificada", "OpenVSwitch installed successfully": "OpenVSwitch instalado com sucesso", "OpenVSwitch is ready to use": "OpenVSwitch está pronto para uso", "OpenVSwitch removed": "OpenVSwitch removido", + "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server.": "Openssh-server é um ambiente sandboxed que permite o acesso ssh sem dar chaves para todo o servidor.", + "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser.": "O Openvscode-server fornece uma versão do VS Code que executa um servidor em uma máquina remota e permite o acesso através de um navegador web moderno.", + "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features.": "Opera é um navegador web multi-plataforma desenvolvido pela sua empresa homônimo Opera. O navegador é baseado em Chromium, mas se distingue de outros navegadores baseados em Chromium (Chrome, Edge, etc.) através de sua interface de usuário e outros recursos.", "Operation": "Operação", "Operation cancelled by user": "Operação cancelada pelo usuário", "Operation cancelled by user to create backup.": "Operação cancelada pelo usuário para criar backup.", "Operation cancelled by user.": "Operação cancelada pelo usuário.", + "Operation cancelled.": "Operation cancelada.", "Operation cancelled. Cannot continue with an unprivileged container.": "Operação cancelada. Não é possível continuar com um contêiner sem privilégios.", "Operation log": "Registro de operação", "Operator config re-applied via kernel-agnostic merge": "configuração do operador reaplicada por meio de mesclagem independente de kernel", "Operator config that WILL be re-applied via kernel-agnostic merge": "configuração do operador que SERÁ reaplicada por meio de mesclagem independente de kernel", + "Optical block device (e.g. /dev/sr0)": "Dispositivo de bloqueio óptico (por exemplo, /dev/sr0)", "Optimizations detected and ready to revert.": "Otimizações detectadas e prontas para serem revertidas.", "Optimize": "Otimizar", "Optimize Memory": "Otimizar Memória", @@ -3129,8 +4124,12 @@ "Optimizing network settings...": "Otimizando configurações de rede...", "Optimizing vzdump backup speed...": "Otimizando a velocidade de backup do vzdump...", "Optional": "Opcional", + "Optional GID of the plex group": "GID opcional do grupo plex", "Optional GPU Passthrough": "Passagem de GPU opcional", + "Optional published URL for Jellyfin": "URL opcional publicado para Jellyfin", "Optional safety helper if you ever need to re-apply manually:": "Auxiliar de segurança opcional se você precisar se inscrever novamente manualmente:", + "Optional token from https://www.plex.tv/claim": "Token opcional de https://www.plex.tv/claim", + "Optional, not mounted by default": "Opcional, não montado por padrão", "Optional: Modernize repository sources:": "Opcional: Modernize as fontes do repositório:", "Optional: apply default ACL so new files inherit permissions:": "Opcional: aplique a ACL padrão para que novos arquivos herdem permissões:", "Optional: register this path as Proxmox dir storage:": "Opcional: registre este caminho como armazenamento dir Proxmox:", @@ -3141,13 +4140,18 @@ "Or re-run this script and accept the 'apply host permissions' prompt.": "Ou execute novamente este script e aceite o prompt 'aplicar permissões de host'.", "Or use ProxMenux update function": "Ou use a função de atualização do ProxMenux", "Or, if your terminal can't select text, copy it from:": "Ou, se o seu terminal não conseguir selecionar texto, copie-o de:", + "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community": "Orca Slicer é um cortador de código aberto para impressoras FDM. OrcaSlicer é fork do Bambu Studio, era anteriormente conhecido como BambuStudio-SoftFever, Bambu Studio é fork da PrusaSlicer pela Prusa Research, que é da Slic3r pela Alessandro Ranellucci e da comunidade RepRap", "Original ZFS ARC config restored from .bak": "Configuração original do ZFS ARC restaurada de .bak", "Original bashrc restored": "Bashrc original restaurado", "Original logrotate configuration restored": "Configuração original do logrotate restaurada", + "Orphan stack contract archived:": "Contrato de pilha órfã arquivado:", + "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.": "Oscam é um software de módulo de acesso condicional de código aberto usado para descodificar DVB transmissions usando cartões inteligentes. É um servidor e um cliente.", "Other Prebuilt Linux VMs": "Outras VMs Linux pré-construídas", "Output archive:": "Arquivo de saída:", + "Overseerr is a request management and media discovery tool built to work with your existing Plex ecosystem.": "Overseerr é uma ferramenta de gerenciamento de pedidos e descoberta de mídia construída para trabalhar com seu ecossistema Plex existente.", "Owner:": "Proprietário:", "Ownership set to root:sharedfiles with 2775 on:": "Propriedade definida como root:sharedfiles com 2775 em:", + "P2P bittorrent download": "Transferência de bits P2P", "PAM limits configured": "Limites PAM configurados", "PBS API log rotation configured (hourly, size-based)": "rotação de log da API PBS configurada (por hora, com base no tamanho)", "PBS backup error log": "Log de erros de backup do PBS", @@ -3164,7 +4168,9 @@ "PCI reset method": "Método de redefinição PCI", "PCIe GPU passthrough requires:": "A passagem de GPU PCIe requer:", "PCIe/M.2 gasket-dkms": "PCIe/M.2 gasket-dkms", + "PCSX2 is an open source PS2 Emulator.": "PCSX2 é um emulador PS2 de código aberto.", "POSIX ACLs applied (access + default for inheritance).": "ACLs POSIX aplicadas (acesso + padrão para herança).", + "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability.": "PPSSPP é um emulador PSP gratuito e de código aberto para Windows, MacOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series e Symbian com um foco na velocidade e portabilidade.", "PVE application manager updated": "Gerenciador de aplicativos PVE atualizado", "PVE cache regenerated": "Cache PVE regenerado", "PVE host (where the Borg LXC lives)": "Host PVE (onde mora o Borg LXC)", @@ -3179,17 +4185,28 @@ "Package update had issues, checking details...": "A atualização do pacote teve problemas, verificando detalhes...", "Packages from backup to install:": "Pacotes do backup para instalação:", "Packages installed: {count}.": "Pacotes instalados: {count}.", + "Packages to be upgraded": "Pacotes a actualizar", "Packages upgrade successfull": "Atualização de pacotes bem-sucedida", "Packages upgraded": "Pacotes atualizados", "Packages:": "Pacotes:", "Packaging OVA file...": "Empacotando arquivo OVA...", "Packing installer archive...": "Empacotando o arquivo do instalador...", + "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices.": "PairDrop é uma alternativa sublime para AirDrop que funciona em todas as plataformas. Envie imagens, documentos ou texto via peer para conexão por pares a dispositivos na mesma rede local/Wi-Fi ou para dispositivos pareados.", + "Paperless configuration cancelled": "Configuração sem papel cancelada", + "Paperless-ngx WebUI": "Paperless-ngx WebUI", "Parsing OVF descriptor...": "Analisando descritor OVF...", "Partial VM removed": "VM parcial removida", "Partition": "Partição", "Partition created": "Partição criada", "Partition created:": "Partição criada:", "Partition table wiped": "Tabela de partição apagada", + "Pass /dev/kvm to the LXC": "Passar /dev/kvm para o LXC", + "Pass /dev/net/tun to the LXC": "Passe /dev/net/tun para o LXC", + "Pass /dev/ttyUSB0 to the LXC": "Passar /dev/ttyUSB0 para o LXC", + "Pass /dev/video10 to the LXC": "Passe /dev/video10 para o LXC", + "Pass /dev/video11 to the LXC": "Passe /dev/video11 para o LXC", + "Pass /dev/video12 to the LXC": "Passe /dev/video12 para o LXC", + "Pass a host device to the LXC": "Passe um dispositivo da máquina para o LXC", "Passphrase used to unlock the imported keyfile (leave blank if the keyfile is unencrypted / kdf=none):": "Senha usada para desbloquear o arquivo-chave importado (deixe em branco se o arquivo-chave não estiver criptografado / kdf=none):", "Passphrases do not match.": "As senhas não correspondem.", "Passphrases do not match. Try again.": "As senhas não correspondem. Tente novamente.", @@ -3202,17 +4219,42 @@ "Password confirmation cannot be empty.": "A confirmação da senha não pode ficar vazia.", "Password confirmation is required.": "A confirmação da senha é necessária.", "Password for": "Senha para", + "Password for aMule external connections (remote client)": "Senha para conexões externas aMule (cliente remoto)", + "Password for the SSH login": "Senha para o login do SSH", "Password for:": "Senha para:", "Password is correct": "A senha está correta", + "Password of the AdGuard Home that receives the settings": "Senha do AdGuard Home que recebe as configurações", + "Password of the Adguardhome Sync web interface": "Senha da interface Web Adguardhome Sync", + "Password of the Duplicati web interface": "Senha da interface Web Duplicati", + "Password of the Etherpad admin user": "Senha do usuário administrador do Etherpad", + "Password of the FlexGet web interface": "Senha da interface Web FlexGet", + "Password of the LibreDB Studio administrator": "Senha do administrador do LibreDB Studio", + "Password of the MineOS web interface user": "Senha do utilizador da interface Web MineOS", + "Password of the NetBox admin account": "Senha da conta de administração NetBox", + "Password of the OpenList admin user": "Senha do usuário administrador do OpenList", + "Password of the PhotoPrism admin user (at least 8 characters)": "Senha do usuário administrador do PhotoPrism (pelo menos 8 caracteres)", + "Password of the PostgreSQL user": "Senha do utilizador do PostgreSQL", + "Password of the SnapOtter admin user": "Senha do usuário administrador do SnapOtter", + "Password of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Senha do login do aplicativo Flowise obsoleto (apenas lido pelas versões do Flowise antes de 3.0.1)", + "Password of the main AdGuard Home": "Senha do AdGuard Home principal", "Password or API token secret:": "Senha ou token secreto da API:", + "Password or secret": "Senha ou segredo", "Password reset completed.": "Redefinição de senha concluída.", + "Password to access the aMule web interface": "Senha para acessar a interface web aMule", "Passwords do not match. Please try again.": "As senhas não coincidem. Por favor, tente novamente.", + "Paste it here and press Ctrl+D on an empty line.": "Colar aqui e pressionar Ctrl+D em uma linha vazia.", + "Paste its Compose file in the terminal": "Colar o seu ficheiro Compor no terminal", + "Paste its docker run command in the terminal": "Colar seu comando de execução docker no terminal", "Paste the UUP Dump URL here": "Cole o URL de despejo UUP aqui", "Patching source for kernel compatibility...": "Fonte de patch para compatibilidade do kernel...", "Path does not exist.": "Caminho não existe.", + "Path inside the container": "Localização dentro do recipiente", + "Path inside the container (e.g. /media-extra)": "Localização dentro do recipiente (por exemplo /media-extra)", + "Path inside the remote (empty = root)": "Localização dentro do comando (vazio = raiz)", "Path must be absolute (start with /)": "O caminho deve ser absoluto (comece com /)", "Path must be absolute (start with /).": "O caminho deve ser absoluto (começar com /).", "Path not found": "Caminho não encontrado", + "Path of the Compose file": "Localização do ficheiro Compor", "Path:": "Caminho:", "Paths applied:": "Caminhos aplicados:", "Paths included in backup": "Caminhos incluídos no backup", @@ -3220,6 +4262,10 @@ "Paths skipped:": "Caminhos ignorados:", "Paths to back up:": "Caminhos para fazer backup:", "Paths:": "Caminhos:", + "Peers reach the server through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Os pares chegam ao servidor através do endereço público e da porta UDP fornecida durante a instalação, de modo que a porta deve ser encaminhada para este recipiente.", + "Peers to create: a number (3) or a list of names (phone,laptop)": "Pares a criar: um número (3) ou uma lista de nomes (telefone, laptop)", + "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration.": "Pelorus é um navegador de IA para desktops Linux movidos por Selkies. O Pelorus executa um servidor FastAPI que fornece um agente LLM (Ollama, OpenAI-compatível, ou Gemini) controle sobre mouse, teclado, captura de tela e gerenciamento de janelas através da infraestrutura de uso de computador Pixelflux, uma árvore de acessibilidade Linux (AT-SPI) e integração opcional do KWin D-Bus.", + "Pending components:": "Componentes pendentes:", "Pending restore ID:": "ID de restauração pendente:", "Pending restore dir:": "Diretório de restauração pendente:", "Pending restore prepared. A reboot is required to complete it.": "Restauração pendente preparada. Uma reinicialização é necessária para concluí-lo.", @@ -3243,7 +4289,15 @@ "Permission error": "Erro de permissão", "Permissions:": "Permissões:", "Persist mount in CT /etc/fstab (optional):": "Persista a montagem em CT /etc/fstab (opcional):", + "Persistence for": "Persistência para", + "Persistence for the new path": "Persistência para o novo caminho", + "Persistent data:": "Dados persistentes:", + "Persistent disk reused:": "Disco persistente reutilizado:", "Persistent:": "Persistente:", + "Personal finance management application": "Aplicação de gestão de finanças pessoais", + "Photo and video library with optional GPU transcoding and machine learning": "Biblioteca de fotos e vídeos com transcodificação GPU opcional e aprendizado de máquina", + "PhotoPrism": "PhotoPrism", + "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB.": "Phpmyadmin é uma ferramenta de software livre escrita em PHP, destinada a lidar com a administração do MySQL através da Web. phpMyAdmin suporta uma ampla gama de operations no MySQL e MariaDB.", "Physical Function with": "Função Física com", "Physical interface": "Interface física", "Physical interfaces available": "Interfaces físicas disponíveis", @@ -3256,6 +4310,10 @@ "Pick a target to remove:": "Escolha um alvo para remover:", "Pick an SSH private key (auto-detected on this host):": "Escolha uma chave privada SSH (detectada automaticamente neste host):", "Pick an alternative way to authorize the new key:": "Escolha uma forma alternativa de autorizar a nova chave:", + "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time.": "Pidgin é um programa de chat que permite que você entre em contas em várias redes de chat simultaneamente. Isso significa que você pode estar conversando com amigos no XMPP e sentado em um canal IRC ao mesmo tempo.", + "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper.": "Piper é um rápido, texto neural local para o sistema de fala que soa ótimo e é otimizado para a framboesa Pi 4. Este recipiente fornece um servidor de protocolo Wyoming para Piper.", + "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures.": "Piwigo é um software de galeria de fotos para a web que vem com recursos poderosos para publicar e gerenciar sua coleção de imagens.", + "Planka is an elegant open source project tracking tool.": "Planka é uma elegante ferramenta de monitoramento de projetos de código aberto.", "Please check network connectivity.": "Verifique a conectividade da rede.", "Please check permissions and try again.": "Verifique as permissões e tente novamente.", "Please check the installation.": "Por favor, verifique a instalação.", @@ -3273,6 +4331,10 @@ "Please select GPU(s) that are currently in the same mode and try again.": "Selecione GPU(s) que estão atualmente no mesmo modo e tente novamente.", "Please select a valid option": "Selecione uma opção válida", "Please use an SSH session (Linux, macOS, Windows/PuTTY) or a physical console to perform the upgrade.": "Use uma sessão SSH (Linux, macOS, Windows/PuTTY) ou um console físico para realizar a atualização.", + "Plex WebUI": "Plex WebUI", + "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.": "Plex organiza vídeo, música e fotos de bibliotecas de mídia pessoal e os transmite para televisões inteligentes, caixas de streaming e dispositivos móveis. Este recipiente é embalado como um servidor de mídia Plex independente. Design direto e ações em massa significam fazer as coisas mais rápido.", + "PocketBase admin UI": "IU de administração do PocketBase", + "Podcast synchronization service": "Serviço de sincronização de podcasts", "Pool does not appear to use SSD/NVMe devices with discard support. Skipping ZFS autotrim for pool:": "O pool não parece usar dispositivos SSD/NVMe com suporte para descarte. Ignorando o ajuste automático do ZFS para pool:", "Pool exists": "O pool existe", "Pool name matches but GUID differs (fresh ZFS install):": "o nome do pool corresponde, mas o GUID é diferente (nova instalação do ZFS):", @@ -3283,12 +4345,21 @@ "Portal IP and port are correct": "O IP e a porta do portal estão corretos", "Portal is reachable": "O portal está acessível", "Portal:": "Portal:", + "Ports": "Portos", "Portuguese": "Português", "Post-Installation Options": "Opções pós-instalação", "Post-Installation Scripts": "Scripts pós-instalação", "Postfix configuration": "Configuração Postfix", + "PostgreSQL": "PostgreSQL", + "PostgreSQL URL without an associated service:": "URL do PostgreSQL sem um serviço associado:", + "PostgreSQL creates the database named in POSTGRES_DB on the first start. The installer default is postgresql.": "PostgreSQL cria o banco de dados nomeado em POSTGRES DB no primeiro início. O instalador do programa é chamado geralmente de postgresql.", + "PostgreSQL is an advanced, enterprise-class, and open-source relational database system. PostgreSQL supports both SQL (relational) and JSON (non-relational) querying.": "PostgreSQL é um sistema de banco de dados relacional avançado, de classe empresarial e de código aberto. O PostgreSQL suporta consultas SQL (relacionais) e JSON (não relacionais).", + "PostgreSQL requires a password": "PostgreSQL requires uma senha", + "PostgreSQL volume size in GB": "Tamanho do volume PostgreSQL em GB", "Potential QEMU startup/assertion failures": "Possíveis falhas de inicialização/afirmação do QEMU", "Power state D3cold/D0 transitions may be inaccessible": "As transições do estado de energia D3cold/D0 podem estar inacessíveis", + "Powerful OCR powered by DeepSeek AI": "Poderoso OCR alimentado por AI DeepSeek", + "Powerful networking tool": "Ferramenta de rede poderosa", "Pre-check found": "Pré-verificação encontrada", "Pre-configure destinations so you don't have to enter them every time you back up.": "Pré-configure destinos para que você não precise inseri-los sempre que fizer backup.", "Pre-existing gasket-dkms package removed.": "Pacote gasket-dkms preexistente removido.", @@ -3296,11 +4367,15 @@ "Pre-upgrade check FAILED: the simulation shows that 'proxmox-ve' would be REMOVED.\n This indicates a repository or dependency issue and upgrading now could break your Proxmox installation.": "Verificação de pré-atualização FALHOU: a simulação mostra que 'proxmox-ve' seria REMOVIDO.\n Isso indica um problema de repositório ou dependência e a atualização agora pode interromper a instalação do Proxmox.", "Pre-upgrade simulation failed. See log:": "Falha na simulação de pré-atualização. Veja registro:", "Pre-upgrade simulation passed: 'proxmox-ve' will be kept or upgraded safely.": "Simulação de pré-atualização aprovada: 'proxmox-ve' será mantido ou atualizado com segurança.", + "Prepared; the container was not modified yet": "Preparado; o recipiente ainda não foi modificado", "Preparing Log2RAM configuration": "Preparando a configuração do Log2RAM", "Preparing files for backup...": "Preparando arquivos para backup...", "Preparing host mount...": "Preparando montagem do host...", "Preparing pending restore (network-safe)": "Preparando restauração pendente (seguro para rede)", "Preparing staging area...": "Preparando área de preparação...", + "Preparing the NVIDIA GPU...": "Preparando a GPU NVIDIA...", + "Preparing the recreation...": "Preparando a recreação...", + "Preparing the update...": "Preparando a atualização...", "Preserving logs to /var/log.hdd before unmounting...": "Preservando logs em /var/log.hdd antes de desmontar...", "Press 'q' to exit": "Pressione 'q' para sair", "Press Ctrl+C to stop the server and return to menu.": "Pressione Ctrl+C para parar o servidor e retornar ao menu.", @@ -3316,6 +4391,7 @@ "Press Enter to return": "Pressione Enter para retornar", "Press Enter to return to menu...": "Pressione Enter para retornar ao menu...", "Press Enter to return to the main menu...": "Pressione Enter para retornar ao menu principal...", + "Press Enter to return to the menu...": "Pressione Enter para retornar ao menu...", "Press Enter to return...": "Pressione Enter para retornar...", "Press Enter when the line has been pasted on the server...": "Pressione Enter quando a linha for colada no servidor...", "Press OK to see the preview, then confirm": "Pressione OK para ver a visualização e confirme", @@ -3325,9 +4401,20 @@ "Preview changes (diff)": "Visualizar alterações (diferenças)", "Preview: changes that would be applied": "Pré-visualização: alterações que seriam aplicadas", "Previous DKMS tree cleared.": "Árvore DKMS anterior limpa.", + "Previous Rclone configuration restored": "Configuração anterior do Rclone restaurada", "Previous installation cleaned": "Instalação anterior limpa", "Previous installation removed": "Instalação anterior removida", + "Previous installation restored": "Instalação anterior restaurada", "Previous shutdowns": "Paralisações anteriores", + "Primary GID for Emby": "GID primário para Emby", + "Privacy-first finance app with envelope budgeting and multi-device sync.": "App Privacy-first finance com envelope budgeting e sincronização multidispositivo.", + "Privacy-first, self-hosted PDF toolkit": "Privacy-primeiro, auto-hosted PDF toolkit", + "Private installation record saved": "Gravação de instalação privada salva", + "Private network assigned automatically:": "Rede privada atribuída automaticamente:", + "Private network of the application released:": "Rede privada do aplicativo lançado:", + "Private network of the application that is released:": "Rede privada do aplicativo que é lançado:", + "Private network:": "Rede privada:", + "Private personal knowledge management": "Gestão privada do conhecimento pessoal", "Privileged": "Privilegiado", "Privileged Container": "Contêiner Privilegiado", "Privileged Container Required": "Requer contêiner privilegiado", @@ -3338,6 +4425,7 @@ "Privileged container — host root maps directly, no permission changes needed": "Contêiner privilegiado — hospede mapas raiz diretamente, sem necessidade de alterações de permissão", "Privileged containers can access host devices directly": "Contêineres privilegiados podem acessar dispositivos host diretamente", "Privileged containers have full root access to the host system!": "Contêineres privilegiados têm acesso root total ao sistema host!", + "Privileged installation declined": "Instalação privada declinou", "Privileged: Full host access (less secure)": "Privilegiado: acesso total ao host (menos seguro)", "Proceed": "Prosseguir", "Proceed with removal": "Prossiga com a remoção", @@ -3346,11 +4434,15 @@ "Process may take several minutes depending on container size": "O processo pode levar vários minutos dependendo do tamanho do recipiente", "Process may take several minutes for large containers": "O processo pode levar vários minutos para contêineres grandes", "Processes using NVIDIA:": "Processos usando NVIDIA:", + "Productivity & Workflows": "Produtividade e fluxos de trabalho", "Profile": "Perfil", "Profile:": "Perfil:", + "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files.": "Projectsend é uma aplicação auto-hospedada que permite fazer upload de arquivos e atribuí-los a clientes específicos que você mesmo cria. Seguro, privado e fácil. Não mais dependendo de serviços externos ou e-mail para enviar esses arquivos.", "Proposed Changes": "Mudanças propostas", "Proposed ZFS ARC maximum:": "Máximo de ZFS ARC proposto:", "Provided by newer version — skipping": "Fornecido pela versão mais recente — ignorando", + "Prowlarr does not offer the application schema:": "Prowlarr não oferece o esquema de aplicação:", + "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all).": "Prowlarr é um gerenciador/proxy indexador construído na popular pilha base arr .net/reactjs para integrar com seus vários aplicativos PVR. O Prowlarr suporta Rastreadores Torrent e Indexadores Usenet. Integra-se perfeitamente com Sonarr, Radarr, Lidarr e Readarr oferecendo gerenciamento completo de seus indexadores sem cada aplicativo Configuração do indexador required (nós fazemos tudo).", "ProxMenux Information": "Informações do ProxMenux", "ProxMenux Monitor": "ProxMenux Monitor", "ProxMenux Monitor Service Verification": "Verificação de serviço do ProxMenux Monitor", @@ -3364,10 +4456,12 @@ "ProxMenux Monitor protection": "Proteção do ProxMenux Monitor", "ProxMenux Monitor unit repaired and restarted": "Unidade ProxMenux Monitor reparada e reiniciada", "ProxMenux Monitor → Backups tab (live progress card with estimated time, logs, rollback delta)": "ProxMenux Monitor → guia Backups (cartão de progresso ao vivo com tempo estimado, logs, delta de reversão)", + "ProxMenux attaches directories, not single files, so this image cannot be installed yet.": "ProxMenux atribui diretórios, não arquivos únicos, então esta imagem ainda não pode ser instalada.", "ProxMenux can apply open permissions on this NFS directory from the host so the container can read and write:": "ProxMenux pode aplicar permissões abertas neste diretório NFS do host para que o contêiner possa ler e escrever:", "ProxMenux can remount it with open permissions so any LXC can read and write.": "ProxMenux pode remontá-lo com permissões abertas para que qualquer LXC possa ler e escrever.", "ProxMenux cannot override NFS server-side permissions from the host.": "ProxMenux não pode substituir as permissões do servidor NFS do host.", "ProxMenux customizations removed from bashrc": "Personalizações do ProxMenux removidas do bashrc", + "ProxMenux does not give a container the system of its host.": "ProxMenux não dá a um recipiente o sistema de seu host.", "ProxMenux does not validate the contents; any keyfile your PBS accepts is accepted here.": "ProxMenux não valida o conteúdo;qualquer arquivo-chave que seu PBS aceita é aceito aqui.", "ProxMenux files:": "Arquivos ProxMenux:", "ProxMenux logo applied": "Logotipo ProxMenux aplicado", @@ -3399,6 +4493,7 @@ "Proxmox repository configuration completed": "Configuração do repositório Proxmox concluída", "Proxmox repository fixed (no-subscription, candidate is 9.x)": "Repositório Proxmox corrigido (sem assinatura, o candidato é 9.x)", "Proxmox status:": "Status do Proxmox:", + "Proxmox storage for the volume": "Armazenamento Proxmox para o volume", "Proxmox storages:": "Armazenamentos Proxmox:", "Proxmox system repair completed successfully!": "Reparo do sistema Proxmox concluído com sucesso!", "Proxmox system repair completed with some issues.": "Reparo do sistema Proxmox concluído com alguns problemas.", @@ -3408,16 +4503,28 @@ "Proxmox web interface: Datacenter > Storage > Add > SMB/CIFS": "Interface web Proxmox: Datacenter > Armazenamento > Adicionar > SMB/CIFS", "Proxmox web interface: Datacenter > Storage > Add > ZFS": "Interface web Proxmox: Datacenter > Armazenamento > Adicionar > ZFS", "Proxmox web interface: Datacenter > Storage > Add > iSCSI": "Interface web Proxmox: Datacenter > Armazenamento > Adicionar > iSCSI", + "Public UDP port clients connect to": "Clientes públicos de porta UDP se conectam", + "Public UDP port peers connect to": "Os pares públicos de portas UDP se conectam", + "Public URL of phpMyAdmin when it is served behind a reverse proxy": "URL público do phpMyAdmin quando é servido por trás de um proxy reverso", + "Public address clients connect to (vpn.example.com or a public IP)": "Clientes de endereço público (vpn.example.com ou IP público)", + "Public address peers connect to, or auto to detect it (vpn.example.com)": "Os pares de endereços públicos se conectam ou se autopara detectá-lo (vpn.example.com)", "Pulling latest changes from GitHub...": "Extraindo as alterações mais recentes do GitHub...", "Purge the gasket-dkms package": "Remover completamente o pacote gasket-dkms", "Purging gasket-dkms package...": "A remover completamente o pacote gasket-dkms...", "Purging log2ram apt package...": "Expurgando pacote log2ram apt...", + "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.": "Pwndrop é um serviço de hospedagem de arquivos auto-implantável para enviar cargas de trabalho de equipes vermelhas ou compartilhar seus arquivos privados com segurança por HTTP e WebDAV.", + "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more.": "O PyCharm oferece suporte para Python, bases de dados, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI e muito mais.", + "Pydio Cells needs an external MySQL or MariaDB database. The setup wizard asks for its address, database name and user on the first start.": "Pydio Cells precisa de um banco de dados externo MySQL ou MariaDB. O assistente de configuração pede o seu endereço, nome do banco de dados e usuário no primeiro início.", + "Pydio Cells redirects to the address given in EXTERNALURL. If the container changes address, edit lxc.environment.runtime: EXTERNALURL and SERVER_IP in /etc/pve/lxc/.conf with the container stopped, and delete /config/keys/cert.crt to regenerate the certificate.": "Pydio Cells redireciona para o endereço indicado em EXTERNALURL. Se o recipiente mudar de endereço, edite lxc.environment.runtime: EXTERNALURL e SERVER IP em /etc/pve/lxc/.conf com o recipiente parado, e apague /config/keys/cert.crt para regenerar o certificado.", + "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture.": "Pydio-cells é a plataforma de compartilhamento de arquivos do nextgen para organizações. É uma reescrita completa do projeto Pydio usando a linguagem Go seguindo uma arquitetura de micro-serviço.", + "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat.": "QDirStat Estatísticas de pastas baseadas em Qt: KDirStat sem qualquer KDE -- do autor do KDirStat original.", "Quick health check (PASSED / FAILED)": "Verificação rápida de integridade (APROVADO/FALHA)", "Quick health status — overall SMART result + key attributes": "Status de saúde rápido – resultado SMART geral + atributos principais", "RAID Detected": "RAID detectado", "RAID member detected": "Membro RAID detectado", "RAM Size": "Tamanho da RAM", "RAM and swap usage": "RAM e uso de swap", + "RAM in MiB": "RAM em MiB", "REPAIR SUMMARY": "RESUMO DO REPARO", "REQUIREMENTS:": "REQUISITOS:", "ROM dump not available — configuring without romfile.": "Despejo de ROM não disponível — configurando sem romfile.", @@ -3425,9 +4532,26 @@ "RPC Bind Service: RUNNING": "Serviço de ligação RPC: EM EXECUÇÃO", "RPC Bind Service: STOPPED": "Serviço de ligação RPC: PARADO", "RPC Bind Service: STOPPED - starting...": "Serviço de ligação RPC: PARADO - iniciando...", + "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD.": "RPCS3 é um emulador de código aberto multiplataforma Sony PlayStation 3 escrito em C++ para Windows, Linux, macOS e FreeBSD.", + "Radarr - A fork of Sonarr to work with movies à la Couchpotato.": "Radarr - Um fork de Sonarr para trabalhar com filmes à la Couchpotato.", + "Radarr added to Prowlarr": "Radarr adicionado ao Prowlarr", + "Radarr connected to qBittorrent": "Radarr ligado ao qBittorrent", + "Radarr root folder configured": "Pasta raiz do Radarr configurada", + "RagFlow is an open-source RAG engine based on deep document understanding.": "RagFlow é um motor RAG de código aberto baseado no entendimento profundo do documento.", + "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase.": "Raneto - é uma plataforma de base de conhecimento de código aberto que usa arquivos Markdown estáticos para alimentar sua base de conhecimento.", + "Raneto web interface": "Interface Web Raneto", + "RawTherapee is a free, cross-platform raw image processing program!": "RawTherapee é um programa de processamento de imagem bruto livre e multiplataforma!", + "Rclone WebUI": "Rclone WebUI", + "Rclone mount": "Montagem Rclone", + "Rclone mount active": "Montagem Rclone ativa", + "Rclone mount needs a privileged LXC with FUSE access. The container is dedicated to Rclone and its web UI must not be exposed to untrusted networks.": "A montagem Rclone precisa de um LXC privilegiado com acesso FUSE. O contêiner é dedicado à Rclone e sua interface web não deve ser exposta a redes não confiáveis.", + "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network.": "Rclone mount requires um LXC privilegiado com acesso FUSE. Use este perfil apenas em um nó e rede confiáveis.", + "Rclone mount requires a privileged container": "Rclone mount requires um recipiente privilegiado", "Re-enter the BORG REPOKEY passphrase to confirm:": "Digite novamente a senha do BORG REPOKEY para confirmar:", "Re-running pre-check after repairs...": "Executando novamente a pré-verificação após os reparos...", "Reachable": "Acessível", + "Read its Compose file from a file of this host": "Leia seu arquivo Compor de um arquivo desta máquina", + "Read the link with pct console CTID on the Proxmox host, or from the Console panel of the container in the Proxmox web interface, then open the https://playit.gg/claim/ address it shows in a browser and sign in to playit.gg. Ctrl+a q leaves pct console.": "Leia o link com o PCT console CTID no host Proxmox, ou a partir do painel Console do recipiente na interface web Proxmox, em seguida, abra o https://playit.gg/claim/ endereço que ele mostra em um navegador e entre para playit.gg. Ctrl+a q deixa o console pct.", "Read-Only": "Somente leitura", "Read-Only access": "Acesso somente leitura", "Read-Write (universal)": "Leitura-Escrita (universal)", @@ -3436,6 +4560,7 @@ "Read-only access (or no write permissions).": "Acesso somente leitura (ou sem permissões de gravação).", "Read-only mount": "Montagem somente leitura", "Read/Write (default)": "Ler/gravar (padrão)", + "Read/write": "Ler/Escrever", "Read/write CPU model-specific registers": "Ler/gravar registros específicos do modelo de CPU", "Readable user table (UID, shell, etc.)": "Tabela de usuário legível (UID, shell, etc.)", "Reading NVMe SMART data...": "Lendo dados SMART do NVMe...", @@ -3443,7 +4568,9 @@ "Reading SMART data...": "Lendo dados SMART...", "Reading SMART self-test log...": "Lendo o registro de autoteste SMART...", "Reading full SMART report...": "Lendo o relatório SMART completo...", + "Real-time Performance Monitoring": "Monitoramento de desempenho em tempo real", "Real-time bandwidth usage (press q to exit)": "Uso de largura de banda em tempo real (pressione q para sair)", + "Real-time collaborative document editor": "Editor de documentos colaborativos em tempo real", "Real-time network monitoring (press q to exit)": "Monitoramento de rede em tempo real (pressione q para sair)", "Real-time network usage (iftop)": "uso de rede em tempo real (iftop)", "Reason: Access denied": "Motivo: acesso negado", @@ -3465,6 +4592,7 @@ "Recent Samba server": "Servidor Samba recente", "Recent logs:": "Registros recentes:", "Recent test results:": "Resultados de testes recentes:", + "Recognition profile not implemented": "Perfil de reconhecimento não implementado", "Recommendation: reformat the disk to ext4 for a robust setup — see docs.": "Recomendação: reformate o disco para ext4 para uma configuração robusta – consulte a documentação.", "Recommendation: start with Complete restore.": "Recomendação: comece com a restauração completa.", "Recommendation: use 'Export to file' for these paths and apply manually during a maintenance window.": "Recomendação: use 'Exportar para arquivo' para esses caminhos e aplique manualmente durante uma janela de manutenção.", @@ -3476,17 +4604,36 @@ "Recommended: use GPU -> LXC mode for these devices.": "Recomendado: use o modo GPU -> LXC para esses dispositivos.", "Recommended: use GPU with LXC workloads instead of VM passthrough on this hardware.": "Recomendado: use GPU com cargas de trabalho LXC em vez de passagem de VM neste hardware.", "Reconciled": "Reconciliado", + "Recover OCI": "Recuperar OCI", + "Recover OCI stack": "Recuperar pilha OCI", + "Recover now?": "Recuperar agora?", + "Recover or complete the operation?": "Recuperar ou completar o operation?", "Recover the keyfile using your recovery passphrase?": "Recuperar o arquivo-chave usando sua senha de recuperação?", + "Recover the previous installation": "Recuperar a instalação anterior", "Recoverable:": "Recuperável:", + "Recovering the previous installation": "Recuperar a instalação anterior", "Recovery blob upload failed — main backup is OK, but keyfile recovery from PBS will not be available for this backup.": "falha no upload do blob de recuperação – o backup principal está OK, mas a recuperação do arquivo-chave do PBS não estará disponível para este backup.", "Recovery blob:": "blob de recuperação:", + "Recovery completed. The container had not been modified yet.": "Recuperação concluída. O recipiente ainda não tinha sido modificado.", + "Recovery completed. The displaced disks and the backup are kept; nothing was deleted automatically.": "Recuperação concluída. Os discos deslocados e o backup são mantidos; nada foi excluído automaticamente.", "Recovery failed": "Falha na recuperação", "Recovery passphrase": "Senha de recuperação", "Recovery setup failed": "Falha na configuração de recuperação", + "Recreate": "Recriar", + "Recreate OCI": "Recriar OCI", + "Recreate with these options?": "Recriar com estas opções?", + "Recreate: edit resources, network, paths and GPU": "Recriar: editar recursos, rede, caminhos e GPU", + "Recreating requires a confirmed proposal": "Recreando requires uma proposta confirmada", + "Recreating the container...": "Recrear o contentor...", + "Recreating the container:": "Recrear o recipiente:", + "Recreation completed. Data kept.": "Recreação concluída. Dados guardados.", + "Recreation prepared": "Recreação preparada", "Refresh APT index and verify repositories:": "Atualize o índice APT e verifique os repositórios:", "Refresh your browser (Ctrl+Shift+R) to see changes": "Atualize seu navegador (Ctrl+Shift+R) para ver as alterações", "Refresh your browser to see changes (server restart may be required)": "Atualize seu navegador para ver as alterações (pode ser necessário reiniciar o servidor)", "Refreshing apt cache...": "Atualizando o cache do apt...", + "Refreshing the NVIDIA runtime...": "Atualizando o tempo de execução NVIDIA...", + "Refusing an unexpected rootfs path:": "Recusando um caminho inesperado do rootfs:", "Regenerating PVE package cache...": "Regenerando cache de pacotes PVE...", "Regenerating boot artifacts for the merged kernel-agnostic changes...": "Regenerando artefatos de inicialização para as alterações independentes do kernel mescladas...", "Regenerating certificates and restarting services...": "Gerando novamente certificados e reiniciando serviços...", @@ -3502,6 +4649,7 @@ "Reinstalled Proxmox packages successfully": "Pacotes Proxmox reinstalados com sucesso", "Reinstalling": "Reinstalando", "Reinstalling core Proxmox packages...": "Reinstalando pacotes principais do Proxmox...", + "Relative CPU priority (cpuunits)": "Prioridade relativa da CPU (cpuunits)", "Release Channel": "Canal de lançamento", "Release channel set to Beta.": "Canal de lançamento definido como Beta.", "Release channel set to Stable.": "Canal de lançamento definido como Estável.", @@ -3511,8 +4659,12 @@ "Remapped Users:": "Usuários remapeados:", "Remapped users:": "Usuários remapeados:", "Reminder: You must install the QEMU Guest Agent inside the Windows VM": "Lembrete: você deve instalar o agente convidado QEMU dentro da VM do Windows", + "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported.": "Remmina é um cliente de desktop remoto escrito em GTK, visando ser útil para administradores de sistema e viajantes, que precisam trabalhar com muitos computadores remotos na frente de telas grandes ou minúsculas. Remmina suporta vários protocolos de rede, em uma interface de usuário integrada e consistente. Atualmente RDP, VNC, SPICE, SSH e EXEC são suportados.", + "Remote Access & VPN": "Acesso remoto & VPN", + "Remote dry run completed; no container was created.": "Execução seca remota concluída; nenhum recipiente foi criado.", "Remote repository path:": "Caminho do repositório remoto:", "Remote server via SSH (recommended — off-host, dedup across machines)": "Servidor remoto via SSH (recomendado — fora do host, desduplicação entre máquinas)", + "Remote verified:": "Verificado remotamente:", "Remounting CIFS share with open permissions...": "Remontando o compartilhamento CIFS com permissões abertas...", "Remove CIFS Mount": "Remover montagem CIFS", "Remove CIFS Mount (pvesm or fstab)": "Remover montagem CIFS (pvesm ou fstab)", @@ -3540,6 +4692,7 @@ "Remove NFS fstab Mount": "Remover montagem fstab do NFS", "Remove NFS fstab mount:": "Remova a montagem fstab do NFS:", "Remove NFS storage:": "Remova o armazenamento NFS:", + "Remove OCI": "Remover OCI", "Remove Proxmox CIFS storage:": "Remova o armazenamento Proxmox CIFS:", "Remove Proxmox NFS storage:": "Remova o armazenamento Proxmox NFS:", "Remove Proxmox iSCSI storage:": "Remova o armazenamento iSCSI Proxmox:", @@ -3551,6 +4704,7 @@ "Remove iSCSI storage definition:": "Remova a definição de armazenamento iSCSI:", "Remove invalid port": "Remover porta inválida", "Remove invalid port(s)": "Remover portas inválidas", + "Remove it? The data of its containers cannot be recovered afterwards.": "Remover? Os dados dos seus contentores não podem ser recuperados posteriormente.", "Remove keyfile from this host": "Remover arquivo-chave deste host", "Remove mount point:": "Remover ponto de montagem:", "Remove obsolete systemd-boot meta-package": "Remover meta-pacote obsoleto systemd-boot", @@ -3559,6 +4713,7 @@ "Remove subscription banner": "Remover banner de assinatura", "Remove the unprivileged flag from configuration:": "Remova o sinalizador sem privilégios da configuração:", "Remove unused packages and their config": "Remova pacotes não utilizados e suas configurações", + "Remove: delete the application and its containers": "Remover: apagar o aplicativo e seus recipientes", "Removed": "Removido", "Removed KVM MSR options from configuration": "Opções KVM MSR removidas da configuração", "Removed Mount:": "Montagem removida:", @@ -3609,6 +4764,9 @@ "Removing stale VFIO entries from vfio.conf...": "Removendo entradas VFIO obsoletas do vfio.conf...", "Removing storage from Proxmox...": "Removendo armazenamento do Proxmox...", "Removing system limits optimizations...": "Removendo otimizações de limites do sistema...", + "Removing the containers...": "Removendo os contentores...", + "Removing the incomplete stack...": "Removendo a pilha incompleta...", + "Removing the previous container": "Removendo o recipiente anterior", "Removing utilities installed by ProxMenux...": "Removendo utilitários instalados por ProxMenux...", "Removing zfs-auto-snapshot...": "Removendo instantâneo zfs-auto...", "Renamed": "Renomeado", @@ -3616,6 +4774,7 @@ "Repair Complete": "Reparo concluído", "Repair Options:": "Opções de reparo:", "Repairs and optimizes repositories": "Repara e otimiza repositórios", + "Repeat to confirm": "Repetir para confirmar", "Replace": "Substituir", "Replace with the actual ID.": "Substitua pelo ID real.", "Replace with your actual container ID": "Substitua pelo ID real do contêiner", @@ -3628,12 +4787,16 @@ "Repositories switched to no-subscription": "Repositórios alterados para sem assinatura", "Repository ready.": "Repositório pronto.", "Repository:": "Repositório:", + "Request a staging certificate for testing: true or false": "Solicitar um certificado de estadiamento para testes: verdadeiro ou falso", "Require reboot": "Exigir reinicialização", "Required command not found:": "Comando necessário não encontrado:", "Required if using a VirtIO or SCSI disk.": "Obrigatório se estiver usando um disco VirtIO ou SCSI.", "Required install helpers not available.": "Auxiliares de instalação necessários não disponíveis.", + "Required new path cancelled": "Novo caminho do required cancelado", + "Required persistent paths cannot be removed": "Os caminhos persistentes do Required não podem ser removidos", "Requires acl package. Skip if setfacl is not available.": "Requer pacote acl. Ignore se setfacl não estiver disponível.", "Requires authentication": "Requer autenticação", + "Reserving a private network...": "Reservando uma rede privada...", "Reset Capability Blocked": "Capacidade de redefinição bloqueada", "Reset Capability Warning": "Aviso de capacidade de redefinição", "Reset Monitor Password": "Redefinir senha do monitor", @@ -3641,7 +4804,9 @@ "Reset current storage selection": "Redefinir a seleção de armazenamento atual", "Resetting time synchronization...": "Redefinindo a sincronização de horário...", "Residual Bookworm entries commented where applicable": "Entradas residuais do Bookworm comentadas quando aplicável", + "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes.": "Resilio-sync (anteriormente BitTorrent Sync) usa o protocolo BitTorrent para sincronizar arquivos e pastas entre todos os seus dispositivos. Existem versões gratuitas e pagas, este recipiente suporta ambas. Há uma imagem de sincronização oficial, mas nós criamos este como ele suporta o mapeamento do usuário para simplificar permissões para volumes.", "Resolve package conflicts": "Resolver conflitos de pacotes", + "Resources": "Recursos", "Restart Network": "Reiniciar rede", "Restart Network Service": "Reinicie o serviço de rede", "Restart Web UI proxy": "Reinicie o proxy da IU da Web", @@ -3673,8 +4838,11 @@ "Restore plan summary": "Resumo do plano de restauração", "Restore source location": "Restaurar local de origem", "Restored config is on disk; reboot the host to apply.": "A configuração restaurada está no disco; reinicie o host para aplicar.", + "Restored installation checked": "Instalação restaurada verificada", "Restored original /bin/gzip": "Original restaurado /bin/gzip", "Restored original /etc/vzdump.conf from .bak": "/etc/vzdump.conf original restaurado de .bak", + "Restored:": "Restaurado:", + "Restoring": "Restauração", "Restoring APT language downloads...": "Restaurando downloads de idiomas APT...", "Restoring container memory to": "Restaurando a memória do contêiner para", "Restoring default journald configuration...": "Restaurando a configuração padrão do journald...", @@ -3682,15 +4850,23 @@ "Restoring original bashrc...": "Restaurando o bashrc original...", "Restoring original logrotate configuration...": "Restaurando a configuração original do logrotate...", "Restoring subscription banner...": "Restaurando banner de assinatura...", + "Restoring the backup": "Restaurando o backup", "Restoring the original rpcbind service state...": "Restaurando o estado original do serviço rpcbind...", + "Restoring the previous Rclone configuration...": "Restaurando a configuração anterior do Rclone...", + "Restoring the previous backup...": "Restaurando o backup anterior...", + "Restoring the previous state of the stack...": "Restaurando o estado anterior da pilha...", + "Restoring the stack records...": "Restabelecer os registos da pilha...", "Results will be saved automatically to:": "Os resultados serão salvos automaticamente em:", "Results will be saved to:": "Os resultados serão salvos em:", "Retention": "Retenção", + "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface.": "RetroArch é uma interface para emuladores, motores de jogo e media players. Ele permite que você execute jogos clássicos em uma ampla gama de computadores e consoles através de sua interface gráfica liso.", "Return": "Retornar", "Return to Main Menu": "Retornar ao menu principal", "Return to Share Menu": "Retornar ao menu Compartilhar", "Return to main menu": "Voltar ao menu principal", + "Returning the containers to their previous state...": "Devolvendo os contentores ao seu estado anterior...", "Reused the encryption key from the PVE storage entry.": "Reutilizou a chave de criptografia da entrada de armazenamento PVE.", + "Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container.": "Amostras de proxy reversas para outras aplicações estão em /config/nginx/proxy confs dentro do recipiente.", "Reverting AMD (Ryzen/EPYC) fixes...": "Revertendo correções AMD (Ryzen/EPYC)...", "Reverting IOMMU/VFIO configuration...": "Revertendo a configuração IOMMU/VFIO...", "Reverting TCP BBR + Fast Open...": "Revertendo TCP BBR + abertura rápida...", @@ -3699,22 +4875,31 @@ "Reverting vzdump speed tuning...": "Revertendo o ajuste de velocidade do vzdump...", "Review passthrough config files": "Revise os arquivos de configuração de passagem", "Review what will be removed": "Revise o que será removido", + "Rip DVD and Blu-ray media from a browser": "Extrair mídia de DVD e Blu-ray de um navegador", "Rollback: nothing to remove (host matches backup)": "Rollback: nada para remover (host corresponde ao backup)", + "Rolling back the incomplete container": "Rebobinando o recipiente incompleto", + "RomM is a self-hosted ROM manager for managing and playing game collections.": "RomM é um gerenciador de ROM auto-hospedado para gerenciar e jogar coleções de jogos.", "Root SSH keys/config": "Chaves/configuração SSH raiz", "Root inside container = root on host system": "Raiz dentro do contêiner = raiz no sistema host", + "Root privileges are required": "Privilégios raiz são required", + "Root privileges on the Proxmox node are required": "Privilégios raiz no nó Proxmox são required", "Root shell/profile config": "Configuração de shell/perfil raiz", "Root user on the PVE host (default 'root'):": "Usuário root no host PVE (padrão 'root'):", + "Rootfs size in GB": "Tamanho do Rootfs em GB", "Rotate the recovery passphrase": "gire a senha de recuperação", "Routing Information": "Informações de roteamento", "Routing Table": "Tabela de roteamento", + "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required.": "Rsnapshot é um utilitário de instantâneo do sistema de arquivos baseado em rsync. O rsnapshot torna mais fácil fazer instantâneos periódicos de máquinas locais e máquinas remotas sobre o ssh. O código faz uso extensivo de links rígidos sempre que possível, para reduzir muito o espaço em disco requi vermelho.", "Run 'Mount NFS Share' to install NFS client automatically.": "Execute 'Mount NFS Share' para instalar o cliente NFS automaticamente.", "Run 'Mount Samba Share' to install CIFS client automatically.": "Execute 'Mount Samba Share' para instalar o cliente CIFS automaticamente.", + "Run GGUF LLMs locally with GPU acceleration": "Executar GGUF LLMs localmente com aceleração GPU", "Run PVE 8 to 9": "Execute PVE 8 a 9", "Run PVE 8 to 9 check": "Execute a verificação PVE 8 a 9", "Run \\\"Install NVIDIA Drivers on Host\\\" first so the installer is cached.": "Execute \"Instalar drivers NVIDIA no host\" primeiro para que o instalador seja armazenado em cache.", "Run a full security audit": "Execute uma auditoria de segurança completa", "Run a job now": "Execute um trabalho agora", "Run apt-get install -f to complete any pending package configurations": "Execute apt-get install -f para completar quaisquer configurações de pacote pendentes", + "Run as root on the Proxmox node; the registry contains private data": "Executar como root no nó Proxmox; o registro contém dados privados", "Run as server or client? [s/c]:": "Executar como servidor ou cliente? [s/c]:", "Run checklist again to verify upgrade:": "Execute a lista de verificação novamente para verificar a atualização:", "Run from console, or SSH inside tmux/screen": "Execute a partir do console ou SSH dentro do tmux/screen", @@ -3739,6 +4924,7 @@ "Running dkms autoinstall for kernel": "Executando a instalação automática do dkms para o kernel", "Running kernel:": "Kernel em execução:", "Running pre-upgrade simulation to verify 'proxmox-ve' will remain installed...": "Executando simulação de pré-atualização para verificar se o 'proxmox-ve' permanecerá instalado...", + "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration.": "RustDesk é uma alternativa completa de controle remoto de código aberto para auto-alojamento e segurança com configuração mínima.", "SATA (standard - high compatibility)": "SATA (padrão - alta compatibilidade)", "SCSI (recommended for Linux and Windows)": "SCSI (recomendado para Linux e Windows)", "SCSI (recommended for Linux)": "SCSI (recomendado para Linux)", @@ -3755,6 +4941,7 @@ "SMB ports:": "Portas SMB:", "SR-IOV Configuration Detected": "Configuração SR-IOV detectada", "SSD Emulation": "Emulação SSD", + "SSH access": "Acesso SSH", "SSH access (host + root)": "Acesso SSH (host + root)", "SSH auth logger service created and started": "Serviço de registrador de autenticação SSH criado e iniciado", "SSH hardening: MaxAuthTries set to 3 (Lynis recommendation)": "Proteção SSH: MaxAuthTries definido como 3 (recomendação Lynis)", @@ -3769,6 +4956,8 @@ "STEP 9: Cleanup (LVM only)": "PASSO 9: Limpeza (somente LVM)", "STORAGE TYPE IDENTIFICATION:": "IDENTIFICAÇÃO DO TIPO DE ARMAZENAMENTO:", "SUGGESTION FOR": "SUGESTÃO PARA", + "SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.": "SWAG serve HTTPS na porta 443. HTTP simples na porta 80 está desativado em /config/nginx/site-confs/default.conf.", + "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction.": "Sabnzbd torna a Usenet tão simples e simplificada quanto possível automatizando tudo o que pudermos. Tudo o que você tem que fazer é adicionar um .nzb. SABnzbd assume a partir daí, onde será automaticamente baixado, verificado, reparado, extraído e arquivado com zero interação humana.", "Safe design: no automatic ACL/ownership mutation on host or CT.": "Design seguro: sem mutação automática de ACL/propriedade no host ou CT.", "Safe to apply now": "É seguro aplicar agora", "Safety Backup": "Backup de segurança", @@ -3822,8 +5011,13 @@ "Same major series:": "Mesma série principal:", "Same major.minor:": "Mesmo maior.menor:", "Sanitizing NVIDIA host services for VFIO mode...": "Sanitizando serviços de host NVIDIA para modo VFIO...", + "Save and classify articles. Read them later. Freely.": "Salvar e classificar artigos. Lê-os depois. Livremente.", "Save the passphrase somewhere safe NOW, before continuing.": "Salve a senha em algum lugar seguro AGORA, antes de continuar.", "Save this Borg target so you don't need to enter the details again?": "Salvar este alvo Borg para não precisar inserir os detalhes novamente?", + "Saved record removed": "Gravação salva removida", + "Saving the new configuration": "Salvando a nova configuração", + "Saving the new configuration...": "A gravar a nova configuração...", + "Saving the stack records...": "A salvar os registos da pilha...", "Scan storage for new content": "Verifique o armazenamento em busca de novo conteúdo", "Scanning available physical disks...": "Verificando discos físicos disponíveis...", "Scanning network for NFS servers...": "Verificando a rede em busca de servidores NFS...", @@ -3835,11 +5029,19 @@ "Scheduled backups and retention policies": "Backups agendados e políticas de retenção", "Scheduled tasks (cron)": "Tarefas agendadas (cron)", "Scheduler script not found:": "Script do agendador não encontrado:", + "ScreenScraper": "ScreenScraper", + "ScreenScraper password": "Senha do ScreenScraper", + "ScreenScraper username": "Nome de usuário ScreenScraper", "Script Information": "Informações do roteiro", "Script not found:": "Script não encontrado:", "Scripts in": "Scripts em", + "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator.": "ScummVM é um programa que permite que você execute certos jogos clássicos de aventura gráfica e RPG, desde que você já tenha seus arquivos de dados. A parte inteligente sobre isso: ScummVM apenas substitui os executáveis enviados com os jogos, permitindo que você jogá-los em sistemas para os quais eles nunca foram projetados! ScummVM é uma reescrita completa dos executáveis desses jogos e não é um emulador.", + "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions—such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server.": "Sealskin é uma plataforma auto-hospedada, cliente-servidor que permite aos usuários executar aplicativos de desktop poderosos e containerizados transmitidos diretamente para um navegador web. Ele usa uma extensão do navegador para interceptar ações do usuário, como clicar em um link ou baixar um arquivo e redirecioná-los para um ambiente de aplicação seguro e isolado rodando em um servidor remoto.", "Search Results for:": "Resultados da pesquisa para:", + "Search applications": "Aplicações de pesquisa", + "Search results for:": "Resultados da pesquisa para:", "Search/Filter Scripts": "Scripts de pesquisa/filtro", + "Searchable document archive with OCR": "Arquivo de documentos pesquisável com OCR", "Secure Disk Formatter": "Formatador de disco seguro", "Secure Gateway (Tailscale VPN)": "Secure Gateway (VPN Tailscale)", "Secure Gateway deployed successfully!": "Secure Gateway implantado com sucesso!", @@ -3847,8 +5049,12 @@ "Security": "Segurança", "Security Updates": "Atualizações de segurança", "Security Warning — read before applying": "Aviso de segurança – leia antes de aplicar", + "Security directive outside the dynamic profile": "Diretiva de segurança fora do perfil dinâmico", + "Security relaxation declined": "Relaxamento de segurança diminuído", "See": "Ver", "See /tmp/proxmenux-mount.log for details.": "Consulte /tmp/proxmenux-mount.log para obter detalhes.", + "Seerr WebUI": "Seerr WebUI", + "Seerr/Bazarr connections, the SABnzbd client and the Lidarr profiles, root folder and client are configured manually in this version.": "As conexões Seerr/Bazarr, o cliente SABnzbd e os perfis Lidarr, pasta raiz e cliente são configurados manualmente nesta versão.", "Select": "Selecione", "Select Borg target": "Selecione o alvo Borg", "Select CPU model": "Selecione o modelo da CPU", @@ -3888,6 +5094,7 @@ "Select a Custom Logo": "Selecione um logotipo personalizado", "Select a VirtIO ISO to use:": "Selecione um VirtIO ISO para usar:", "Select a category of useful commands:": "Selecione uma categoria de comandos úteis:", + "Select a category or search for applications:": "Selecione uma categoria ou pesquisa por aplicativos:", "Select a category or search for scripts:": "Selecione uma categoria ou pesquise scripts:", "Select a custom ISO to use:": "Selecione um ISO personalizado para usar:", "Select a job:": "Selecione um trabalho:", @@ -3897,6 +5104,7 @@ "Select a pre-configured Linux VM script to execute:": "Selecione um script de VM Linux pré-configurado para executar:", "Select a script or action:": "Selecione um script ou ação:", "Select a share to delete:": "Selecione um compartilhamento para excluir:", + "Select a specific Coral or USB node, not the whole /dev": "Selecione um nó Coral ou USB específico, não o /dev inteiro", "Select access mode": "Selecione o modo de acesso", "Select an existing group": "Selecione um grupo existente", "Select an existing group:": "Selecione um grupo existente:", @@ -3907,6 +5115,7 @@ "Select archive": "Selecione o arquivo", "Select archive to restore": "Selecione o arquivo para restaurar", "Select at least one path to continue.": "Selecione pelo menos um caminho para continuar.", + "Select at least one suite application": "Selecione pelo menos um aplicativo de suíte", "Select authentication mode:": "Selecione o modo de autenticação:", "Select authentication type:": "Selecione o tipo de autenticação:", "Select available Controllers/NVMe to add:": "Selecione controladores/NVMe disponíveis para adicionar:", @@ -4011,6 +5220,19 @@ "Selected optimizations have been uninstalled.": "As otimizações selecionadas foram desinstaladas.", "Selected paths produced no entries to apply.": "Os caminhos selecionados não produziram entradas a serem aplicadas.", "Selected utilities installation completed": "Instalação de utilitários selecionados concluída", + "Selection": "Selecção", + "Self-custodial Bitcoin Lightning wallet with integrated node and app connections.": "Carteira Bitcoin Lightning com nó integrado e conexões de aplicativo.", + "Self-hosted ZeroTier network controller with web UI for centralized management.": "Controlador de rede ZeroTier self-hosted com interface web para gerenciamento centralizado.", + "Self-hosted cloud data migration & sync manager": "Gerenciador de migração e sincronização de dados em nuvem hospedada automaticamente", + "Self-hosted collaborative bookmark manager to collect, read, annotate, and fully preserve what matters, all in one place.": "Gerenciador de favoritos colaborativo para coletar, ler, anotar e preservar totalmente o que importa, tudo em um só lugar.", + "Self-hosted file sharing with a modern web interface": "Partilha de ficheiros auto- hospedados com uma interface Web moderna", + "Self-hosted file toolkit for images, video, audio, PDFs, and files": "Kit de ferramentas de arquivo auto hospedado para imagens, vídeo, áudio, PDFs e arquivos", + "Self-hosted internet archiving solution": "Solução de arquivamento de internet self-hosted", + "Self-hosted recipe manager and meal planner": "Gestor de receitas e organizador de refeições", + "Self-hosted software development service": "Serviço de desenvolvimento de software self-hosted", + "Self-signed TLS certificate created:": "Certificado TLS auto- assinado criado:", + "Selfhosted PDF manager, viewer and editor": "Gerenciador de PDF, visualizador e editor selfhosted", + "Selkies desktop and streaming acceleration": "Aceleração da área de trabalho e da transmissão", "Sending backup to Borg repository...": "Enviando backup para o repositório Borg...", "Sending backup to PBS...": "Enviando backup para PBS...", "Server": "Servidor", @@ -4025,14 +5247,19 @@ "Server will listen on TCP port 5201.": "O servidor escutará na porta TCP 5201.", "Server:": "Servidor:", "Servers": "Servidores", + "Service": "Serviço", "Service Status": "Status do serviço", "Service is active and running": "O serviço está ativo e em execução", "Service is inactive": "O serviço está inativo", + "Service ready:": "Serviço pronto:", + "Service responding:": "Serviço que responde:", "Service restarted.": "Serviço reiniciado.", "Service restarts:": "O serviço é reiniciado:", "Service stopped.": "Serviço parado.", + "Service:": "Serviço:", "Services failed": "Falha nos serviços", "Services restarted": "Serviços reiniciados", + "Services that depend on the main service are not yet supported": "Serviços que dependem do serviço principal ainda não são suportados", "Services:": "Serviços:", "Set Display > Graphic card (VGA, SPICE or VirtIO) to match the guest": "Defina Display> Placa gráfica (VGA, SPICE ou VirtIO) para corresponder ao convidado", "Set Hostname": "Definir nome do host", @@ -4077,13 +5304,26 @@ "Share:": "Compartilhar:", "Shared Directory Ready:": "Diretório compartilhado pronto:", "Shared Group": "Grupo Compartilhado", + "Shared directory created:": "Directório partilhado criado:", + "Shared directory for consume and export": "Diretório compartilhado para consumir e exportar", + "Shared directory for copy/sync operations": "Diretório compartilhado para copiar/sincronizar operations", "Shared group: CONFIGURED": "Grupo compartilhado: CONFIGURADO", "Shared group: sharedfiles (GID:": "Grupo compartilhado: arquivos compartilhados (GID:", + "Shared host content (not included in LXC backups):": "Conteúdo da máquina compartilhada (não incluído em backups do LXC):", + "Shared host data is not reverted by the backup. Continue?": "Os dados da máquina partilhada não são revertidos pelo backup. Continuar?", + "Shared host data is not reverted by the backups. Continue?": "Os dados da máquina partilhada não são revertidos pelos backups. Continuar?", + "Shared host directories (not included in Proxmox backups)": "Pastas de máquinas partilhadas (não incluídas nas cópias de segurança do Proxmox)", + "Shared host directory": "Directório da máquina partilhada", + "Shared host directory (not included in Proxmox backups)": "Directório da máquina partilhada (não incluído nos backups do Proxmox)", + "Shared host files are kept as they are; the backup does not restore their content.": "Os arquivos de host compartilhados são mantidos como são; o backup não restaura seu conteúdo.", + "Shared host media directory": "Diretório de mídia da máquina compartilhada", + "Shared memory size for the GPU workload in MB": "Tamanho da memória compartilhada para a carga de trabalho da GPU em MB", "Sharedfiles group already exists (GID: 101000)": "O grupo Sharedfiles já existe (GID: 101000)", "Shares found:": "Ações encontradas:", "Shell user ulimit set": "Conjunto de limites de usuário do Shell", "Short self-test started on": "Autoteste curto iniciado em", "Short test — ~2 minutes, basic surface check": "Teste curto — aproximadamente 2 minutos, verificação básica da superfície", + "Shotcut is a free, open source, cross-platform video editor.": "Shotcut é um editor de vídeo livre, de código aberto, multi-plataforma.", "Should show 'unprivileged: 0' or no unprivileged line": "Deve mostrar 'sem privilégios: 0' ou nenhuma linha sem privilégios", "Should show 'unprivileged: 1'": "Deve mostrar 'sem privilégios: 1'", "Should show 'unprivileged: 1' if it's unprivileged": "Deve mostrar 'sem privilégios: 1' se não tiver privilégios", @@ -4125,14 +5365,23 @@ "Show size of a directory": "Mostrar tamanho de um diretório", "Show standard exclude patterns": "Mostrar padrões de exclusão padrão", "Show status of all storage pools": "Mostrar o status de todos os pools de armazenamento", + "Show the QR code of a peer again with: pct exec -- /app/show-peer 1": "Mostrar o código QR de um par novamente com: pct exec -- /app/show-peer 1", "Show traffic statistics per interface": "Mostrar estatísticas de tráfego por interface", "Show vzdump backup configuration": "Mostrar configuração de backup do vzdump", "Shows status and type (nfs/cifs/dir/iscsi...).": "Mostra status e tipo (nfs/cifs/dir/iscsi...).", "Shutdown timeout": "Tempo limite de desligamento", + "SiYuan access code": "Código de acesso SiYuan", + "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more..": "O SickGear oferece gerenciamento de programas de TV e/ou Anime, detecta novos episódios, links para aplicativos de download e muito mais..", + "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private.": "Signal é um aplicativo de mensagens com privacidade em seu núcleo. É livre e fácil de usar, com criptografia de ponta a ponta forte que mantém sua comunicação completamente privada.", "Signatures removed. Partition table preserved.": "Assinaturas removidas. Tabela de partição preservada.", + "Simple and easy to use DDNS": "Simples e fácil de usar DDNS", "Single GPU Warning": "Aviso de GPU única", "Single target found — selected automatically:": "Único alvo encontrado — selecionado automaticamente:", "Size": "Tamanho", + "Size in GB of": "Tamanho em GB de", + "Size of each consume/export volume in GB": "Tamanho de cada volume de consumo/exportação em GB", + "Size of the /dev/shm shared memory in MB": "Tamanho da memória partilhada /dev/shm em MB", + "Size of the Frigate temporary cache in MB": "Tamanho da cache temporária Frigate em MB", "Size:": "Tamanho:", "Skip downloading additional languages": "ignorar o download de idiomas adicionais", "Skip this device": "Ignorar este dispositivo", @@ -4142,6 +5391,7 @@ "Skip — leave as-is": "Pular – deixe como está", "Skipped (no disks of the pool are present on this host):": "Ignorado (nenhum disco do pool está presente neste host):", "Skipped (some disks missing):": "Ignorado (alguns discos faltando):", + "Skipped because Jellyfin did not create encoding.xml:": "Pular porque Jellyfin não criou coding.xml:", "Skipped device": "Dispositivo ignorado", "Skipped to protect target system (would cascade-remove packages)": "Ignorado para proteger o sistema de destino (removeria pacotes em cascata)", "Skipped, not in apt cache:": "Ignorado, não no cache do apt:", @@ -4149,7 +5399,10 @@ "Skipping SR-IOV device": "Ignorando dispositivo SR-IOV", "Skipping installation.": "Ignorando a instalação.", "Skipping manual patches — feranick fork already supports this kernel.": "Ignorando patches manuais – feranick fork já suporta este kernel.", + "Sleek podcast downloader with GPodder sync": "Baixador de podcast elegante com sincronização GPodder", "Smart restore plan — hardware compatibility check": "Plano de restauração inteligente – verificação de compatibilidade de hardware", + "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis.": "Smokeping acompanha a latência da sua rede. Para um exemplo completo do que esta aplicação é capaz de visitar UCDavis.", + "SnapOtter": "SnapOtter", "Snippets — hook scripts / config": "Snippets – scripts/configuração de gancho", "SoC-integrated GPU: tight coupling with other SoC components": "GPU integrada ao SoC: forte acoplamento com outros componentes do SoC", "Some DKMS removals reported errors; final verification will determine the result.": "Algumas remoções de DKMS relataram erros;a verificação final determinará o resultado.", @@ -4159,6 +5412,7 @@ "Some old time services could not be removed (not installed)": "Alguns serviços antigos não puderam ser removidos (não instalados)", "Some operations failed — review messages above. Press Enter to continue...": "Algumas operações falharam — revise as mensagens acima. Pressione Enter para continuar...", "Some packages still need attention; review": "Mensagem técnica para Proxmox e TI.Traduza: Alguns pacotes ainda precisam de atenção;análise", + "Some projects publish a Dockerfile and not an image: it has to be built and published to a registry before it can be installed this way. An image of a private registry needs credentials, which are not supported yet.": "Alguns projetos publicam um arquivo Docker e não uma imagem: ele tem que ser construído e publicado em um registro antes que ele possa ser instalado desta forma. Uma imagem de um registro privado precisa de credentials, que ainda não são suportados.", "Some repairs failed. Please fix manually and re-run the script.": "Alguns reparos falharam. Corrija manualmente e execute novamente o script.", "Some repositories are not available, continuing with available ones...": "Alguns repositórios não estão disponíveis, continuando com os disponíveis...", "Some selected GPUs are already configured in this container.": "Algumas GPUs selecionadas já estão configuradas neste contêiner.", @@ -4166,6 +5420,10 @@ "Some utility packages could not be removed; the remaining list has been preserved": "Alguns pacotes de utilitários não puderam ser removidos;a lista restante foi preservada", "Something is already mounted at": "Algo já está montado em", "Something is already mounted at:": "Algo já está montado em:", + "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Sonarr (anteriormente NZBdrone) é um PVR para usuários usenet e bittorrent. Ele pode monitorar vários feeds RSS para novos episódios de seus programas favoritos e vai agarrar, classificar e renomeá-los. Ele também pode ser configurado para atualizar automaticamente a qualidade dos arquivos já baixados quando um formato de melhor qualidade fica disponível.", + "Sonarr added to Prowlarr": "Sonarr adicionado ao Prowlarr", + "Sonarr connected to qBittorrent": "Sonarr ligado ao qBittorrent", + "Sonarr root folder configured": "Pasta raiz do Sonarr configurada", "Source": "Fonte", "Source VM": "VM de origem", "Source patched successfully.": "Fonte corrigida com sucesso.", @@ -4174,8 +5432,26 @@ "Spanish": "Espanhol", "Specific host (enter IP)": "Host específico (insira o IP)", "Specific subnet (enter manually)": "Sub-rede específica (inserir manualmente)", + "Speedtest Tracker web interface": "Interface Web Speedtest Tracker", + "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service.": "Speedtest-tracker é um aplicativo de rastreamento de desempenho da internet que executa verificações de velocidade contra o serviço Speedtest da Ookla.", + "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium": "Spotube é um cliente Spotify de código aberto, multi-plataforma compatível em várias plataformas utilizando a API de dados do Spotify e YouTube, Piped. vídeo ou JioSaavn como uma fonte de áudio, eliminando a necessidade de Spotify Premium", "Stable (main branch)": "Estável (ramo principal)", "Stable monitor service normalized.": "Serviço de monitor estável normalizado.", + "Stack": "Pilha", + "Stack adapter not recognized by the translator": "Adaptador de pilha não reconhecido pelo tradutor", + "Stack backups are missing; a partial restore is not allowed": "Faltam cópias de segurança das pilhas; uma restauração parcial não é permitida", + "Stack checked:": "Pilha marcada:", + "Stack members are missing; recreate them after verifying their volumes": "Faltam membros da pilha; recria- os após verificar os seus volumes", + "Stack members are updated together with their stack": "Os membros da pilha são atualizados junto com sua pilha", + "Stack name": "Nome da pilha", + "Stack records restored": "Gravações de pilhas restauradas", + "Stack records saved": "Gravações de pilhas salvas", + "Stack records saved; no container was reinstalled.": "Os registos da pilha foram salvos; nenhum contentor foi reinstalado.", + "Stack recovery completed; every member is back to its previous installation.": "Stack recuperação concluída; cada membro está de volta à sua instalação anterior.", + "Stack startup hook installed": "Gancho de inicialização da pilha instalado", + "Stack stopped": "Pilha parada", + "Stack update completed. Data kept.": "A actualização da pilha foi concluída. Dados guardados.", + "Stack:": "Pilha:", "Staging directory:": "Diretório de teste:", "Staging ready.": "Preparação pronta.", "Staging source:": "Fonte de teste:", @@ -4183,11 +5459,13 @@ "Stale VFIO Config Detected": "Configuração VFIO obsoleta detectada", "Stale VFIO entries removed and initramfs rebuilt.": "entradas VFIO obsoletas removidas e initramfs reconstruído.", "Standard NAS (backup, iso, vztmpl)": "NAS padrão (backup, iso, vztmpl)", + "Start": "Iniciar", "Start VM": "Iniciar VM", "Start VM after creation": "Inicie a VM após a criação", "Start VM after creation?": "Iniciar VM após a criação?", "Start a container. Use the correct ": "Inicie um contêiner. Use o correto", "Start a virtual machine. Use the correct ": "Inicie uma máquina virtual. Use o correto", + "Start each LXC with Proxmox (no coordinated startup)": "Iniciar cada LXC com Proxmox (sem arranque coordenado)", "Start long self-test (hours)": "Iniciar um autoteste longo (horas)", "Start long test now?": "Iniciar um teste longo agora?", "Start on boot already disabled for VM": "Iniciar na inicialização já desabilitado para VM", @@ -4199,11 +5477,16 @@ "Start scrub for a ZFS pool": "Iniciar a limpeza de um pool ZFS", "Start short self-test (~2 min)": "Inicie um autoteste curto (~2 min)", "Start terminal multiplexer (recommended):": "Inicie o multiplexador de terminal (recomendado):", + "Start the LXC when finished to apply the selected configuration?": "Iniciar o LXC quando terminar de aplicar a configuração selecionada?", "Start the VM": "Inicie a VM", "Start the VM to begin Windows installation from the mounted ISO.": "Inicie a VM para iniciar a instalação do Windows a partir do ISO montado.", "Start the converted container:": "Inicie o contêiner convertido:", "Start the main system upgrade:": "Inicie a atualização principal do sistema:", + "Start the stack with Proxmox": "Iniciar a pilha com Proxmox", "Start uploading to PBS — sets a recovery passphrase": "comece a enviar para o PBS – define uma senha de recuperação", + "Start when finished": "Iniciar quando terminar", + "Start with Proxmox": "Iniciar com Proxmox", + "Starting": "Início", "Starting Borg backup...": "Iniciando backup do Borg...", "Starting CT": "Iniciando TC", "Starting LXC Privileged to Unprivileged conversion process...": "Iniciando o processo de conversão LXC privilegiado para não privilegiado...", @@ -4214,6 +5497,7 @@ "Starting ProxMenux update...": "Iniciando atualização do ProxMenux...", "Starting Proxmox storage integration...": "Iniciando a integração do armazenamento Proxmox...", "Starting Proxmox system repair...": "Iniciando o reparo do sistema Proxmox...", + "Starting Rclone and waiting for the FUSE mount...": "A iniciar o Rclone e à espera da montagem FUSE...", "Starting SMART long self-test...": "Iniciando o autoteste longo SMART...", "Starting SMART short self-test...": "Iniciando o autoteste curto SMART...", "Starting container": "Iniciando contêiner", @@ -4224,9 +5508,20 @@ "Starting installer...": "Iniciando o instalador...", "Starting privileged container...": "Iniciando contêiner privilegiado...", "Starting rpcbind service...": "Iniciando o serviço rpcbind...", + "Starting the container...": "A iniciar o contentor...", + "Starting the main container and its dependencies...": "A iniciar o contentor principal e as suas dependências...", + "Starting the service:": "Iniciando o serviço:", "Starting unprivileged container...": "Iniciando contêiner sem privilégios...", + "Startup: coordinated by the stack startup hook": "Inicialização: coordenada pelo gancho de arranque da pilha", + "Startup: independent, without hookscript": "Inicialização: independente, sem hookscript", + "Static IP": "IP estático", + "Static IPv4 address": "Endereço IPv4 estático", + "Static IPv4 address for": "Endereço IPv4 estático para", "Status": "Status", "Status:": "Status:", + "Steam is the ultimate destination for playing, discussing, and creating games.": "Steam é o destino final para jogar, discutir e criar jogos.", + "SteamGridDB": "SteamGridDB", + "SteamGridDB API key": "Chave de API SteamGridDB", "Step": "Etapa", "Step 2: Testing actual share access with guest...": "Etapa 2: Testando o acesso real ao compartilhamento com convidados...", "Steps that will run:": "Etapas que serão executadas:", @@ -4234,12 +5529,14 @@ "Stop it first and run this option again.": "Pare primeiro e execute esta opção novamente.", "Stop the CT, unmount the disk on the HOST, and remount with:": "Pare o CT, desmonte o disco no HOST e remonte com:", "Stop the VM/CT before formatting this disk.": "Pare a VM/CT antes de formatar este disco.", + "Stop the container before the NVIDIA refresh": "Pare o recipiente antes da atualização do NVIDIA", "Stop the container if it's running:": "Pare o contêiner se ele estiver em execução:", "Stop them first and run this script again.": "Pare-os primeiro e execute este script novamente.", "Stop uploading to PBS": "Pare de fazer upload para PBS", "Stop uploading?": "Parar de enviar?", "Stopped": "Parou", "Stopped and disabled": "Parado e desabilitado", + "Stopped at:": "Parado em:", "Stopping Coral kernel modules...": "Parando módulos do kernel Coral...", "Stopping LXC": "Parando LXC", "Stopping NFS services...": "Parando serviços NFS...", @@ -4251,6 +5548,8 @@ "Stopping gateway...": "Parando o gateway...", "Stopping the container before applying configuration...": "Parando o contêiner antes de aplicar a configuração...", "Stopping the container before conversion...": "Parando o contêiner antes da conversão...", + "Stopping the container...": "Parar o contentor...", + "Stopping the stack...": "Parar a pilha...", "Storage": "Armazenar", "Storage & Share Manager": "Gerenciador de armazenamento e compartilhamento", "Storage Added:": "Armazenamento adicionado:", @@ -4263,21 +5562,41 @@ "Storage and Disks Commands": "Comandos de armazenamento e discos", "Storage controller: VirtIO SCSI": "Controlador de armazenamento: VirtIO SCSI", "Storage disk identifier:": "Identificador do disco de armazenamento:", + "Storage for Nextcloud files, configuration and data": "Armazenamento para arquivos, configurações e dados Nextcloud", + "Storage for Paperless data and documents": "Armazenamento para dados e documentos sem papel", + "Storage for Tandoor files": "Armazenamento para arquivos Tandoor", + "Storage for persistent data": "Armazenamento para dados persistentes", + "Storage for recipe images and files": "Armazenamento para imagens de receita e arquivos", + "Storage for rootfs": "Armazenamento para rootfs", + "Storage for rootfs and private configuration": "Armazenamento para rootfs e configuração privada", + "Storage for the Immich library": "Armazenamento para a biblioteca Immich", + "Storage for the Nextcloud data": "Armazenamento para os dados Nextcloud", + "Storage for the OCI image cache": "Armazenamento para a cache de imagens OCI", + "Storage for the consume and export folders": "Armazenamento para as pastas de consumo e exportação", + "Storage for the persistent configuration": "Armazenamento para a configuração persistente", "Storage is now available in Proxmox web interface under Datacenter > Storage": "O armazenamento agora está disponível na interface web do Proxmox em Datacenter > Armazenamento", "Storage plan selection cancelled.": "Seleção do plano de armazenamento cancelada.", "Storage plan selection failed or cancelled": "A seleção do plano de armazenamento falhou ou foi cancelada", + "Storage selection cancelled": "Selecção do armazenamento cancelada", "Storage:": "Armazenar:", "Stored Credentials:": "Credenciais armazenadas:", "Stored credentials:": "Credenciais armazenadas:", + "Stremio is a modern media center that gives you the freedom to watch everything you want.": "Stremio é um centro de mídia moderno que lhe dá a liberdade de assistir tudo o que você quer.", + "Subdomains for the certificate, comma separated (wildcard for *.domain)": "Subdomínios para o certificado, vírgula separada (wildcard for *. domain)", "Subnet": "Sub-rede", "Subscription banner removal failed": "Mensagem técnica para Proxmox e TI.Tradução: falha na remoção do banner de assinatura", "Subscription banner removed successfully": "Banner de assinatura removido com sucesso", "Subscription banner restored successfully (desktop and mobile)": "Banner de assinatura restaurado com sucesso (desktop e celular)", "Success": "Sucesso", "Successful": "Bem-sucedido", + "Supervisor does not confirm healthy and supported yet": "Supervisor ainda não confirma saudável e apoiado", + "Supervisor reports no connectivity; retrying to get versions and install components": "Supervisor não relata conectividade; tentando novamente obter versões e instalar componentes", "Supported formats: .img, .qcow2, .vmdk, .raw": "Formatos suportados: .img, .qcow2, .vmdk, .raw", + "Swap": "Trocar", + "Swap in MB": "Trocar em MB", "Swap partition detected": "Partição swap detectada", "Swappiness configuration created successfully": "Configuração de swappiness criada com sucesso", + "Swing Music is a beautifully designed, self-hosted music streaming server. Like a cooler Spotify ... but bring your own music.": "O Swing Music é um servidor de streaming de música muito bem projetado e self-hosted. Como um Spotify mais fresco... mas traz a tua própria música.", "Switch GPU Mode (VM <-> LXC)": "Alternar modo GPU (VM <-> LXC)", "Switch Mode": "Alterar modo", "Switch Script Not Found": "Alternar script não encontrado", @@ -4287,13 +5606,21 @@ "Switching to": "Mudando para", "Switching to GPU -> LXC mode removes VFIO exclusivity.": "Mudar para GPU -> modo LXC remove a exclusividade VFIO.", "Switching to GPU -> VM mode requires exclusive VFIO binding.": "Mudar para o modo GPU -> VM requer ligação VFIO exclusiva.", + "Symbolic link in a restored volume path": "Ligação simbólica num caminho de volume restaurado", + "Symbolic link in the path of an adaptation": "Ligação simbólica no caminho de uma adaptação", + "Symbolic link loop in the new image": "Ciclo de ligação simbólica na nova imagem", + "Symbolic link outside the rootfs of the new image": "Ligação simbólica fora dos rootfs da nova imagem", "Synchronize time automatically": "sincronizar a hora automaticamente", + "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are.": "Synclounge é uma ferramenta de terceiros que permite que você assista Plex em sincronia com seus amigos/família, onde quer que você esteja.", + "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet.": "O Syncthing substitui serviços de sincronização e nuvem proprietários por algo aberto, confiável e descentralizado. Seus dados são apenas seus dados e você merece escolher onde são armazenados, se forem compartilhados com algum terceiro e como são transmitidos pela Internet.", + "Sysctl not namespaced or not valid:": "Sysctl não espaçado ou não válido:", "System": "Sistema", "System CLI Tools": "Ferramentas CLI do sistema", "System Disk Size (GB)": "Tamanho do disco do sistema (GB)", "System Update Information": "Informações de atualização do sistema", "System Utilities Installer": "Instalador de utilitários de sistema", "System disk is SSD or M.2. Proceeding with Log2RAM setup.": "O disco do sistema é SSD ou M.2. Continuando com a configuração do Log2RAM.", + "System error:": "Erro do sistema:", "System errors and logs": "Erros e registros do sistema", "System group apex already exists.": "O ápice do grupo de sistemas já existe.", "System group apex created.": "Apex do grupo de sistemas criado.", @@ -4304,6 +5631,7 @@ "System limits increase completed.": "Aumento dos limites do sistema concluído.", "System limits optimizations removed": "Otimizações de limites do sistema removidas", "System must be updated to latest PVE 8.4+ before starting": "O sistema deve ser atualizado para o PVE 8.4+ mais recente antes de iniciar", + "System path mounts are not yet supported": "As montagens do caminho do sistema ainda não são suportadas", "System reboot required": "Reinicialização do sistema necessária", "System upgrade completed": "Atualização do sistema concluída", "System uptime": "Tempo de atividade do sistema", @@ -4318,6 +5646,11 @@ "TROUBLESHOOTING:": "SOLUÇÃO DE PROBLEMAS:", "TUI mode": "Modo TUI", "TUI mode (requires root)": "Modo TUI (requer root)", + "Take control of your Minecraft servers.": "Assuma o controle dos seus servidores Minecraft.", + "Tandoor WebUI": "Tandoor WebUI", + "Tandoor configuration cancelled": "Configuração Tandoor cancelada", + "Tandoor needs at least 1 GB for staticfiles and 4 GB for PostgreSQL": "Tandoor precisa de pelo menos 1 GB para arquivos estáticos e 4 GB para PostgreSQL", + "Tandoor needs to complete its first start to create the initial administrator": "Tandoor precisa completar seu primeiro começo para criar o administrador inicial", "Target IQN:": "IQN alvo:", "Target VM": "VM de destino", "Target VM validated": "VM de destino validada", @@ -4327,6 +5660,12 @@ "Target mode": "Modo alvo", "Target server:": "Servidor de destino:", "Target:": "Alvo:", + "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server.": "Tautulli é um aplicativo web baseado em python para monitoramento, análise e notificações para Plex Media Server.", + "Teable adopts a concise spreadsheet interface, yet creates powerful database applications": "Teable adota uma interface de planilha concisa, mas cria poderosas aplicações de banco de dados", + "Telegram is a cloud-based mobile and desktop messaging app.": "Telegram é um aplicativo de mensagens móveis e desktop baseado em nuvem.", + "Temporary data container:": "Recipiente temporário de dados:", + "Temporary login": "Login temporário", + "Temporary password retrieved": "Senha temporária obtida", "Temporary working directory (if present):": "Diretório de trabalho temporário (se presente):", "Terminal Multiplexers": "Multiplexadores de terminais", "Terminal multiplexer (Ctrl+b then d to detach, or type exit)": "Multiplexador de terminal (Ctrl+b e depois d para desconectar ou digite exit)", @@ -4343,40 +5682,197 @@ "Testing comprehensive guest access to server": "Testando o acesso abrangente de convidados ao servidor", "Testing connectivity to portal...": "Testando conectividade com o portal...", "Testing network connectivity...": "Testando conectividade de rede...", + "Text that new pads start with (empty = the text of the image)": "Texto com o qual começam os novos blocos (vazio = o texto da imagem)", "Thank you for using ProxMenux. Goodbye!": "Obrigado por usar o ProxMenux. Adeus!", "That VM is currently stopped, so the GPU can be reassigned now.": "Essa VM está atualmente parada, então a GPU pode ser reatribuída agora.", "That doesn't look like an SSH private key. Pick the private key file (no .pub extension, parseable by ssh-keygen).": "Isso não se parece com uma chave privada SSH.Escolha o arquivo de chave privada (sem extensão .pub, analisável por ssh-keygen).", + "The .conf files under /config/fail2ban are rewritten on every start. Keep customizations in the matching .local file, for example jail.local for jail.conf.": "Os arquivos .conf em /config/fail2ban são reescritos em cada início. Mantenha personalizações no arquivo .local correspondente, por exemplo, jail.local para jail.conf.", + "The AppArmor/seccomp relaxation does not include the required consent": "O relaxamento AppArmor/seccomp não inclui o consentimento required", + "The Bookmark Everything App": "A aplicação Tudo do Favorito", + "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile.": "O navegador Brave é um navegador web rápido, privado e seguro para PC, Mac e móvel.", + "The CT already exists:": "O CT já existe:", + "The Compose file declares no service": "O arquivo Compose não declara nenhum serviço", + "The Compose file describes several images:": "O arquivo Compose descreve várias imagens:", + "The Compose file does not contain a Compose document": "O arquivo Compose não contém um documento Compose", + "The Compose file is not valid YAML:": "O arquivo Compose não é válido YAML:", + "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "O Compose oferece um relaxamento opcional AppArmor ou seccomp; ele ficará desativado a menos que o usuário o selecione. Continue apenas se você confiar na imagem e aceitar este risco.", + "The Compose value must be text or a list:": "O valor Compose deve ser texto ou uma lista:", + "The DRM node is not an Intel or AMD GPU; NVIDIA requires its library profile": "O nó DRM não é uma GPU Intel ou AMD; NVIDIA requires seu perfil de biblioteca", + "The Entrypoint/Cmd combination is empty": "O ponto de entrada / Cmd combination está vazio", + "The FUSE publication helper was not found": "Não foi encontrado o auxiliar de publicação do FUSE", + "The GPU evidence does not match the verified devices": "A evidência da GPU não corresponde aos dispositivos verificados", "The GPU has been moved out of VM": "A GPU foi removida da VM", + "The GPU identity or permissions changed; the container is not modified": "A identidade ou permissões da GPU foram alteradas; o recipiente não foi modificado", "The GPU is being detached from VM": "A GPU está sendo desconectada da VM", + "The GPU vendor differs from the requested profile": "O fornecedor da GPU difere do perfil solicitado", + "The GPU vendor does not match the selected GPU profile:": "O fornecedor da GPU não corresponde ao perfil da GPU seleccionado:", + "The Immich CPU quota cannot be reproduced": "A quota de CPU Immich não pode ser reproduzida", + "The Immich library needs at least 8 GB": "A biblioteca Immich precisa de pelo menos 8 GB", + "The Immich startup was modified or cannot be reproduced": "A inicialização do Immich foi modificada ou não pode ser reproduzida", + "The LXC has stopped": "O LXC parou", + "The Lounge starts in public mode: anyone who reaches the address opens the client without logging in, and the IRC networks added are lost when the session ends.": "O Lounge começa em modo público: qualquer pessoa que chegar ao endereço abre o cliente sem fazer login, e as redes de IRC adicionadas são perdidas quando a sessão termina.", + "The MAC address of the container cannot be kept": "O endereço MAC do recipiente não pode ser conservado", "The NVIDIA Container Toolkit repository definition was empty.": "a definição do repositório NVIDIA Container Toolkit estava vazia.", "The NVIDIA Container Toolkit signing key could not be read.": "A chave de assinatura do NVIDIA Container Toolkit não pôde ser lida.", + "The NVIDIA Container Toolkit version cannot be identified": "A versão do kit de ferramentas do recipiente NVIDIA não pode ser identificada", + "The NVIDIA destination cannot be replaced": "O destino NVIDIA não pode ser substituído", + "The NVIDIA destination escapes the rootfs": "O destino NVIDIA escapa dos rootfs", "The NVIDIA driver is installed, but the Container Toolkit phase did not complete. GPU support for OCI containers is unavailable until it does.": "O driver NVIDIA está instalado, mas a fase do Container Toolkit não foi concluída. O suporte de GPU para contêineres OCI estará indisponível até que isso aconteça.", + "The NVIDIA driver or inventory changed; the operation was stopped": "O driver ou inventário NVIDIA mudou; o operation foi interrompido", + "The NVIDIA hook or environment differs from the declared one": "O gancho ou ambiente NVIDIA difere do declarado", + "The NVIDIA hook path does not belong to the installer": "O caminho do gancho NVIDIA não pertence ao instalador", "The NVIDIA installer needs at least": "O instalador NVIDIA precisa de pelo menos", + "The NVIDIA runtime is up to date; the container is not modified or started": "O tempo de execução NVIDIA está atualizado; o recipiente não é modificado ou iniciado", + "The Nextcloud volume needs at least 8 GB": "O volume Nextcloud precisa de pelo menos 8 GB", + "The OCI archive contains no SHA-256 blobs": "O arquivo OCI não contém bolhas SHA-256", + "The OCI archive does not contain exactly one manifest": "O arquivo OCI não contém exatamente um manifesto", + "The OCI archive does not exist or is empty:": "O arquivo OCI não existe ou está vazio:", + "The OCI archive verifier was not found": "O verificador de arquivos OCI não foi encontrado", + "The OCI catalog is not installed. Update ProxMenux and try again.": "O catálogo OCI não está instalado. Atualizar ProxMenux e tentar novamente.", + "The OCI engine is not installed. Update ProxMenux and try again.": "O motor OCI não está instalado. Atualizar ProxMenux e tentar novamente.", + "The OCI image storage was not kept": "O armazenamento de imagens OCI não foi mantido", + "The OCR language must use Tesseract codes, for example eng or eng+spa": "A linguagem OCR deve usar códigos Tesseract, por exemplo eng ou eng+spa", + "The PATH of the new image is outside the reproducible profile": "O PATH da nova imagem está fora do perfil reprodutível", + "The Paperless persistent volumes need at least 8 GB": "Os volumes persistentes sem papel precisam de pelo menos 8 GB", + "The PostgreSQL volume needs at least 4 GB": "O volume PostgreSQL precisa de pelo menos 4 GB", + "The PostgreSQL volume needs at least 8 GB": "O volume PostgreSQL precisa de pelo menos 8 GB", "The Proxmox archive keyring is missing; Ceph installation cannot continue safely": "O chaveiro de arquivo Proxmox está faltando;A instalação do Ceph não pode continuar com segurança", + "The Proxmox inventory and the local configurations differ": "O inventário Proxmox e as configurações locais diferem", + "The Rclone configuration needs at least 1 GB": "A configuração Rclone precisa de pelo menos 1 GB", + "The Rclone rootfs needs at least 2 GB": "O Rclone rootfs precisa de pelo menos 2 GB", + "The Selkies profile requires a verified LinuxServer image": "O perfil de Selkies requires uma imagem LinuxServer verificada", + "The Tandoor files volume needs at least 2 GB": "O volume de arquivos Tandoor precisa de pelo menos 2 GB", "The URL does not contain the required parameters (id, pack, edition).": "A URL não contém os parâmetros necessários (id, pack, edição).", + "The USB number can change after reconnecting or rebooting. This profile does not remap it automatically or handle Coral USB re-enumeration. Do not share a dongle already used by another service.": "O número USB pode mudar após reconectar ou reiniciar. Este perfil não remapeá-lo automaticamente ou lidar com a re-enumeração Coral USB. Não partilhe um dongle já utilizado por outro serviço.", + "The Unifi-controller software is a powerful, enterprise wireless software engine ideal for high-density client deployments requiring low latency and high uptime performance.": "O software Unifique-controlador é um poderoso motor de software sem fio empresarial ideal para implantações de clientes de alta densidade requi com baixa latência e alto desempenho de uptime.", + "The VA-API device does not exist:": "O dispositivo VA-API não existe:", "The VM also has these audio devices assigned via PCI passthrough — typically added together with the GPU. Remove them too?": "A VM também possui esses dispositivos de áudio atribuídos por meio de passagem PCI — normalmente adicionados junto com a GPU. Remova-os também?", "The VM guest will have exclusive access to the GPU.": "O convidado da VM terá acesso exclusivo à GPU.", "The VM is powered on. Turn it off before adding disks.": "A VM está ligada. Desligue-o antes de adicionar discos.", "The VM/LXC will lose access to this disk after formatting.": "O VM/LXC perderá acesso a este disco após a formatação.", + "The VMID belongs to another container now and is not touched:": "O VMID pertence a outro recipiente agora e não é tocado:", + "The VMID or its contract is already in use; it is not adopted": "O VMID ou seu contrato já está em uso; não é adotado", + "The VMID was reused or its identity is unknown; the operation is blocked": "O VMID foi reutilizado ou sua identidade é desconhecida; o operation está bloqueado", + "The VMID was reused or the container is on another node; it is not overwritten": "O VMID foi reutilizado ou o recipiente está noutro nó; não é substituído", + "The VMID was taken during the installation:": "O VMID foi tomado durante a instalação:", + "The Valkey volume needs at least 1 GB": "O volume Valkey precisa de pelo menos 1 GB", + "The acceleration evidence differs from the verified inventory": "A evidência de aceleração difere do inventário verificado", + "The acceleration profile does not support this architecture:": "O perfil de aceleração não suporta esta arquitetura:", "The active kernel driver is not vfio-pci, but the entry in": "O driver do kernel ativo não é vfio-pci, mas a entrada em", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot, breaking the LXC passthrough about to be configured.": "O driver do kernel ativo não é vfio-pci, mas a entrada irá religar a GPU ao vfio-pci na próxima reinicialização, interrompendo a passagem LXC prestes a ser configurada.", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot.": "O driver do kernel ativo não é vfio-pci, mas a entrada irá religar a GPU ao vfio-pci na próxima reinicialização.", + "The adaptation content was modified": "O conteúdo da adaptação foi modificado", + "The additional path hides a system directory": "O caminho adicional esconde uma pasta do sistema", + "The address is already assigned on this host or cluster:": "O endereço já está atribuído neste host ou cluster:", + "The address must start with http:// or https://": "O endereço deve começar por http:// ou https://", + "The administrator account, the public address and the UDP port are created on the first start, so the web interface opens directly on its login page.": "A conta de administrador, o endereço público e a porta UDP são criados no primeiro início, então a interface web abre diretamente em sua página de login.", + "The administrator email is not valid": "O e- mail do administrador não é válido", + "The administrator user contains characters that are not allowed": "O usuário administrador contém caracteres que não são permitidos", + "The all-in-one AI application.": "A aplicação de IA tudo-em-um.", + "The application configuration needs a first start to complete.": "A configuração do aplicativo precisa de um primeiro começo para completar.", + "The application did not complete its initial setup:": "A aplicação não completou a sua configuração inicial:", + "The application did not get an address on the access network:": "A aplicação não obteve um endereço na rede de acesso:", + "The application did not pass its HTTP check:": "A aplicação não passou na sua verificação HTTP:", + "The application did not respond in time:": "O pedido não respondeu a tempo:", + "The application stopped during its first start:": "A aplicação parou durante o seu primeiro início:", + "The application was removed": "O aplicativo foi removido", "The archive could not be extracted.": "O arquivo não pôde ser extraído.", "The archive destination directory is INSIDE one of the paths you are about to back up. Writing the archive there would copy the backup into itself — producing a corrupted archive, or growing without limit until the disk fills up.": "O diretório de destino do arquivo está DENTRO de um dos caminhos dos quais você está prestes a fazer backup. Escrever o arquivo ali copiaria o backup para si mesmo – produzindo um arquivo corrompido ou crescendo sem limites até que o disco ficasse cheio.", + "The backup could not be identified; the image is not replaced": "A cópia de segurança não pôde ser identificada; a imagem não foi substituída", "The backup metadata was compared against this host. The following items will be SKIPPED to keep the boot safe:": "os metadados de backup foram comparados com este host. Os seguintes itens serão IGNORADOS para manter a inicialização segura:", + "The backup of a member could not be identified": "Não foi possível identificar o backup de um membro", + "The backup was altered; recovery blocked": "O backup foi alterado; recuperação bloqueada", "The backup was taken on a different PVE or kernel major.minor. These paths will be SKIPPED to keep the boot safe:": "O backup foi feito em um PVE ou kernel major.minor diferente. Esses caminhos serão SKIPPED para manter a inicialização segura:", + "The bind mount target escapes the rootfs:": "O alvo de montagem de ligação escapa aos rootfs:", + "The block device does not exist:": "O dispositivo de bloqueio não existe:", "The build could not be checked beforehand; continuing without that check.": "A compilação não pôde ser verificada antecipadamente;continuando sem essa verificação.", + "The cached image does not match the current digest": "A imagem em cache não corresponde à digest atual", + "The cached image is damaged; it will be downloaded again.": "A imagem em cache está danificada; será transferida novamente.", + "The character device does not exist:": "O dispositivo de caracteres não existe:", + "The command asks for a password that is not echoed. After creating the users, the web interface asks for a user name and a password.": "O comando pede uma senha que não seja ecoada. Depois de criar os usuários, a interface web pede um nome de usuário e uma senha.", + "The command does not name an image": "O comando não nomeia uma imagem", + "The command reads its variables from a file; write them in the command or use a Compose file": "O comando lê as suas variáveis a partir de um ficheiro; escreva- as no comando ou use um ficheiro Compor", + "The command runs the container as the user of the host; the container uses the user of its image instead.": "O comando executa o recipiente como o usuário da máquina; o recipiente usa o usuário de sua imagem em vez disso.", + "The command uses options that cannot be translated:": "O comando usa opções que não podem ser traduzidas:", + "The command works out a value by running another command:": "O comando executa um valor executando outro comando:", "The compatibility check raised failures that may break the system after restore.": "A verificação de compatibilidade levantou falhas que podem danificar o sistema após a restauração.", + "The configuration changed after the backup was restored; the recovery is not confirmed": "A configuração mudou depois que o backup foi restaurado; a recuperação não é confirmada", + "The configuration changed after the new container was validated": "A configuração foi alterada após a validação do novo recipiente", + "The configuration changed during the NVIDIA refresh": "A configuração mudou durante a atualização do NVIDIA", + "The configuration evidence does not match": "A evidência de configuração não corresponde", + "The configuration must run as root on Proxmox VE": "A configuração deve ser executada como root no Proxmox VE", + "The configuration of a new member changed after it was created": "A configuração de um novo membro mudou depois de ter sido criado", + "The configuration stopped because of an unexpected error": "A configuração parou devido a um erro inesperado", + "The consume/export volumes need at least 1 GB": "Os volumes de consumo/exportação necessitam de pelo menos 1 GB", + "The container could not be removed automatically:": "O recipiente não pôde ser removido automaticamente:", + "The container could not be started:": "Não foi possível iniciar o recipiente:", + "The container creation does not match the prepared instance": "A criação do recipiente não corresponde à instância preparada", + "The container devices do not match the saved record": "Os dispositivos do contentor não correspondem ao registo gravado", + "The container did not stop to update its persistent configuration:": "O recipiente não parou para atualizar sua configuração persistente:", + "The container did not stop; its disks are not touched": "O recipiente não parou; os seus discos não são tocados", + "The container disks do not match the saved record": "Os discos do contentor não correspondem ao registo gravado", + "The container does not exist:": "O recipiente não existe:", + "The container does not have the fuse=1 feature enabled": "O recipiente não tem a funcionalidade fusível=1 activada", + "The container does not need it any more; an update downloads the new version when there is one.": "O recipiente não precisa mais dele; uma atualização baixa a nova versão quando há uma.", + "The container gets its own address and its own volumes, so the networks and volumes declared in the file are not used.": "O contêiner recebe seu próprio endereço e seus próprios volumes, de modo que as redes e volumes declarados no arquivo não são usados.", + "The container has advanced Proxmox settings outside the supported profile": "O recipiente tem configurações avançadas Proxmox fora do perfil suportado", + "The container identity changed; the container is not replaced": "A identidade do contentor foi alterada; o contentor não é substituído", + "The container identity does not match": "A identidade do contentor não corresponde", + "The container identity or configuration changed": "A identidade ou configuração do contentor foi alterada", "The container is currently stopped. Do you want to start it now to install the package?": "O contêiner está atualmente parado. Deseja iniciá-lo agora para instalar o pacote?", + "The container is not modified because a host directory is not available:": "O recipiente não é modificado porque não está disponível uma pasta de máquinas:", + "The container no longer exists:": "O recipiente já não existe:", + "The container of a member was replaced; the assembly is not resumed": "O recipiente de um membro foi substituído; a montagem não é retomada", "The container should now start as privileged": "O contêiner agora deve começar como privilegiado", "The container should now start as unprivileged": "O contêiner agora deve começar como sem privilégios", + "The container stopped after starting:": "O recipiente parou após iniciar:", + "The container stopped before publishing the mount": "O recipiente parou antes de publicar a montagem", + "The container stopped before the GPU permissions were verified:": "O recipiente parou antes das permissões da GPU serem verificadas:", + "The container stopped before the application responded:": "O recipiente parou antes da aplicação responder:", + "The container stopped:": "O recipiente parou:", + "The container takes its time zone from Proxmox, so the time files of the host are not attached to it.": "O recipiente toma seu fuso horário de Proxmox, para que os arquivos de tempo do host não são anexados a ele.", + "The container was changed outside ProxMenux and an update would discard those changes:": "O recipiente foi alterado fora do ProxMenux e uma atualização descartaria essas alterações:", + "The container was created from a downloaded OCI image": "O recipiente foi criado a partir de uma imagem OCI descarregada", + "The containers do not need them any more; an update downloads the new versions when there are any.": "Os recipientes não precisam mais deles; uma atualização baixa as novas versões quando existem.", + "The containers were created from downloaded OCI images": "Os recipientes foram criados a partir de imagens OCI descarregadas", + "The coordinated backup was modified": "O backup coordenado foi modificado", "The current driver will be completely uninstalled before installing the new version. Continue?": "O driver atual será completamente desinstalado antes de instalar a nova versão. Continuar?", + "The current image of the saved channel will be checked and downloaded. Resources, paths and GPU are kept. The CT is stopped during the replacement and a native backup is created first.": "A imagem atual do canal salvo será verificada e baixada. Recursos, caminhos e GPU são mantidos. O CT é interrompido durante a substituição e um backup nativo é criado primeiro.", + "The current record is missing for": "Falta o registro atual para", + "The current template changes the image or identity; an explicit migration is required": "O modelo atual muda a imagem ou identidade; uma migração explícita é required", + "The current template requires a new persistent path:": "O modelo atual requires um novo caminho persistente:", + "The custom path cannot hide system directories": "O caminho personalizado não pode ocultar diretórios do sistema", + "The custom path overlaps another mount": "O caminho personalizado sobrepõe- se a outro monte", + "The data and document volumes need at least 8 GB": "Os volumes de dados e documentos precisam de pelo menos 8 GB", + "The database server must accept connections from the IP address of this container, with a user that is not limited to localhost.": "O servidor de banco de dados deve aceitar conexões a partir do endereço IP deste recipiente, com um usuário que não está limitado a localhost.", + "The dedicated adapter still requires replaying its rootfs changes": "O adaptador dedicado ainda requires repetindo suas mudanças rootfs", + "The dependency hook and the stack recipe differ": "O gancho de dependência e a receita da pilha diferem", + "The dependency hook was modified; review it before updating": "O gancho de dependência foi modificado; revisá-lo antes de atualizar", + "The developer-friendly cloud platform for building and running LLM agents for AI-native applications.": "A plataforma de nuvem amigável ao desenvolvedor para a construção e execução de agentes LLM para aplicações nativas de IA.", + "The device directory does not exist:": "O diretório do dispositivo não existe:", + "The device must keep its /dev path inside the LXC:": "O dispositivo deve manter o seu caminho /dev dentro do LXC:", + "The device must keep its native path without duplicates": "O dispositivo deve manter o seu caminho nativo sem duplicatas", + "The directory contains no character devices:": "A pasta não contém dispositivos de caracteres:", "The directory does not exist in the CT.": "O diretório não existe no CT.", "The disk": "O disco", + "The disk size cannot be reproduced": "O tamanho do disco não pode ser reproduzido", + "The disk usage of the container could not be read": "Não foi possível ler o uso do disco do recipiente", + "The domain must resolve to the public address of this network before the certificate can be issued.": "O domínio deve ser resolvido para o endereço público desta rede antes que o certificado possa ser emitido.", + "The download client still needs to be configured.": "O cliente de download ainda precisa ser configurado.", + "The download stopped progressing; cancelling this attempt.": "O download parou de progredir; cancelando esta tentativa.", + "The downloaded image does not match its manifest": "A imagem transferida não corresponde ao seu manifesto", + "The downloaded image is corrupt:": "A imagem baixada está corrompida:", "The dpkg package database is clean.": "O banco de dados do pacote dpkg está limpo.", "The driver installed but does not drive this GPU.": "O driver foi instalado, mas não aciona esta GPU.", + "The dynamic NVIDIA hook is missing": "Falta o gancho NVIDIA dinâmico", + "The dynamic NVIDIA hook is missing or duplicated": "O gancho NVIDIA dinâmico está faltando ou duplicado", + "The dynamic NVIDIA profile requires an unprivileged LXC": "O perfil NVIDIA dinâmico requires um LXC sem privilégios", + "The dynamic profile does not support static driver mounts": "O perfil dinâmico não suporta montagens estáticas do driver", "The file does not exist, is empty or is not readable.": "O arquivo não existe, está vazio ou não é legível.", + "The file does not exist:": "O arquivo não existe:", + "The file is too large to be a Compose file": "O arquivo é muito grande para ser um arquivo Compose", "The filesystem": "O sistema de arquivos", + "The final cleanup did not complete:": "A limpeza final não completou:", "The following DKMS-managed drivers will now be rebuilt against it so they keep working after reboot:": "Os seguintes drivers gerenciados pelo DKMS agora serão reconstruídos para que continuem funcionando após a reinicialização:", "The following LXC containers have NVIDIA passthrough configured:": "Os seguintes contêineres LXC têm passagem NVIDIA configurada:", "The following backup paths are kernel-tied and are excluded from the picker to keep the target's boot safe. The operator's own tuning inside these paths (IOMMU cmdline, VFIO IDs, custom quirks) is merged back automatically via kernel-agnostic merge:": "Os seguintes caminhos de backup estão vinculados ao kernel e são excluídos do seletor para manter a inicialização do destino segura. O próprio ajuste do operador dentro desses caminhos (cmdline IOMMU, IDs VFIO, peculiaridades personalizadas) é mesclado automaticamente por meio de mesclagem independente de kernel:", @@ -4390,17 +5886,99 @@ "The following selected device(s) are Physical Functions with active Virtual Functions:": "Os seguintes dispositivos selecionados são funções físicas com funções virtuais ativas:", "The following selected device(s) are SR-IOV Virtual Functions (VFs):": "The following selected device(s) are SR-IOV Virtual Functions (VFs):", "The fstab entry will still be removed; reboot or manual umount needed.": "A entrada fstab ainda será removida; reinicialização ou desmontagem manual necessária.", + "The gateway must be another usable address in the same subnet.": "O gateway deve ser outro endereço utilizável na mesma subrede.", "The gateway should appear in your Tailscale admin console shortly.": "O gateway deve aparecer em seu console de administração Tailscale em breve.", + "The healthcheck cannot run without an IP address": "A verificação de saúde não pode ser executada sem um endereço IP", + "The host NVIDIA driver is not responding correctly": "O driver NVIDIA da máquina não está respondendo corretamente", + "The host bind source does not exist:": "O código de ligação da máquina não existe:", + "The host bind source is not a regular file or directory:": "O código de ligação da máquina não é um ficheiro ou directório regular:", + "The host directory changed before it was mounted": "A pasta da máquina mudou antes de ser montada", "The host directory may not be accessible from an unprivileged container.": "O diretório host pode não estar acessível a partir de um contêiner sem privilégios.", + "The host has no IPv4 address on the selected bridge": "A máquina não tem endereço IPv4 na ponte seleccionada", + "The host monitor does not see the real host memory": "O monitor da máquina não vê a memória verdadeira da máquina", + "The host monitor does not share this host namespace:": "O monitor da máquina não compartilha este espaço de nomes da máquina:", + "The host monitor needs consent for privileged access to the host": "O monitor do host precisa de consentimento para acesso privilegiado ao host", + "The host monitor profile does not support another sysctl include": "O perfil do monitor da máquina não suporta outro sysctl include", + "The host monitor uses the host network, without DHCP or its own gateway": "O monitor host usa a rede host, sem DHCP ou seu próprio gateway", + "The host port is already in use:": "A porta da máquina já está em uso:", + "The identity of a member was replaced": "A identidade de um membro foi substituída", + "The image changes the user expected by the adapter": "A imagem muda o usuário esperado pelo adaptador", + "The image could not be read from its registry:": "Não foi possível ler a imagem do seu registo:", + "The image declares data paths that are still stored in the rootfs": "A imagem declara os caminhos de dados que ainda estão armazenados nos rootfs", + "The image did not grant the application user access to the devices; check its native init. Host permissions were not relaxed.": "A imagem não concedeu ao usuário do aplicativo acesso aos dispositivos; verifique seu init nativo. As permissões do anfitrião não foram relaxadas.", + "The image did not pass the integrity check": "A imagem não passou na verificação de integridade", + "The image does not declare support for this architecture:": "A imagem não declara suporte para esta arquitetura:", + "The image download did not complete correctly; downloading it again...": "A transferência da imagem não terminou correctamente; transferi- la novamente...", + "The image expects files that are given to it one by one:": "A imagem espera arquivos que lhe são dados um por um:", + "The image is already up to date; nothing was changed.": "A imagem já está atualizada; nada mudou.", + "The image is in its registry, for one architecture.": "A imagem está em seu registro, para uma arquitetura.", + "The image is in its registry.": "A imagem está no seu registo.", + "The image is in its registry:": "A imagem está em seu registro:", + "The image requests NVIDIA, but the host has no working NVIDIA driver": "A imagem solicita NVIDIA, mas a máquina não tem driver NVIDIA funcionando", + "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk.": "A imagem solicita desativar parte do confinamento AppArmor ou seccomp. Continue apenas se você confiar na imagem e aceitar este risco.", + "The image requests disabling part of the AppArmor or seccomp confinement. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "A imagem solicita desativar parte do confinamento AppArmor ou seccomp. O Compose oferece um relaxamento opcional AppArmor ou seccomp; ele ficará desativado a menos que o usuário o selecione. Continue apenas se você confiar na imagem e aceitar este risco.", + "The image was not found in its registry, or it is private:": "A imagem não foi encontrada em seu registro, ou é privada:", + "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged.": "Os pedidos Compose importados são privilegiados, mas a documentação oficial jlesage/handbrake não require-lo; ProxMenux mantém o LXC sem privilégios.", + "The imported OCI groups are not numeric": "Os grupos OCI importados não são numéricos", + "The imported OCI user or group is not numeric": "O usuário ou grupo OCI importado não é numérico", + "The initial user name and password stay written in /etc/pve/lxc/.conf as INIT_USERNAME and INIT_PASSWORD. They can be removed after the first login, with the container stopped.": "O nome de usuário inicial e senha permanecem escritos em /etc/pve/lxc/.conf como INIT USERNAME e INIT PASSWORD. Eles podem ser removidos após o primeiro login, com o recipiente parado.", + "The installation asks which one to use for these paths.": "A instalação pergunta qual usar para estes caminhos.", + "The installation ended with exit code": "A instalação terminou com o código de saída", "The installation requires a server restart to apply changes. Do you want to restart now?": "A instalação requer a reinicialização do servidor para aplicar as alterações. Quer reiniciar agora?", + "The installation runs on the Proxmox node itself, as root": "A instalação é executada no próprio nó Proxmox, como root", + "The installation stopped because of an unexpected error": "A instalação parou devido a um erro inesperado", "The installation/changes require a server restart to apply correctly. Do you want to reboot now?": "A instalação/alterações requerem a reinicialização do servidor para serem aplicadas corretamente. Você quer reiniciar agora?", + "The installer must run as root on Proxmox VE": "O instalador deve correr como root no Proxmox VE", + "The instance changed while it was being edited; configure Recreate again": "A instância mudou enquanto ela estava sendo editada; configure Recrear novamente", + "The instance does not use NVIDIA": "A instância não utiliza NVIDIA", + "The instance has a pending operation": "A instância tem uma operation pendente", + "The instance identity or status must be reviewed before updating.": "A identidade ou o estado da instância devem ser revistos antes da atualização.", + "The instance is not ready to be updated": "A instância não está pronta para ser atualizada", + "The instance is not ready; review its pending operation": "A instância não está pronta; reveja sua operation pendente", + "The instance record operation did not complete; no container was modified.": "O registro de instância operation não completou; nenhum recipiente foi modificado.", + "The instance registry is not safe": "O registro de instância não é seguro", + "The journal belongs to another VMID": "A revista pertence a outro VMID", + "The journal belongs to another stack": "O diário pertence a outra pilha", + "The journal has an incomplete recovery state": "A revista tem um estado de recuperação incompleto", + "The kernel module is not active:": "O módulo do kernel não está ativo:", "The kernel module of version": "O módulo do kernel da versão", "The local envelope is dropped and future backups do not upload anything. Uploaded envelopes already on PBS stay intact and remain recoverable with their original passphrase.": "O envelope local é eliminado e os backups futuros não carregam nada. Os envelopes carregados já no PBS permanecem intactos e podem ser recuperados com sua senha original.", "The long test runs directly on the disk hardware.": "O teste longo é executado diretamente no hardware do disco.", + "The main member must stop first and start last": "O membro principal deve parar primeiro e começar por último", + "The main member of the stack is missing": "Falta o membro principal da pilha", + "The manifest does not match its digest": "O manifesto não corresponde à sua digest", + "The member journal belongs to another stack operation": "O diário membro pertence a outra pilha operation", + "The member journal is outside the registry": "O periódico membro está fora do registro", + "The mount evidence does not match the verified directories": "A evidência de montagem não corresponde às pastas verificadas", + "The mount source or options were not kept": "A fonte de montagem ou as opções não foram mantidas", + "The mounted source differs from the configured directory": "A fonte montada difere da pasta configurada", + "The mounts of the new container do not match the proposal": "As montagens do novo recipiente não correspondem à proposta", + "The native GPU permissions were not kept": "As permissões da GPU nativa não foram mantidas", + "The native unprivileged idmap is required": "O idmap nativo não privilegiado é required", "The new SSH key was installed and is now authorized on the server.\nKey file:": "A nova chave SSH foi instalada e agora está autorizada no servidor.\nArquivo chave:", "The new SSH key was pushed to the LXC via 'pct exec' on": "A nova chave SSH foi enviada para o LXC via 'pct exec' em", + "The new Valkey volume contains unexpected data": "O novo volume do Valkey contém dados inesperados", + "The new container did not pass validation": "O novo recipiente não passou na validação", + "The new container is not authorized by the operation journal": "O novo recipiente não é autorizado pela revista operation", + "The new image adds a symbolic link in a generated path": "A nova imagem adiciona um link simbólico em um caminho gerado", + "The new image changes the PostgreSQL major version; the data must be migrated before updating": "A nova imagem muda a versão principal do PostgreSQL; os dados devem ser migrados antes de atualizar", + "The new image could not be installed": "Não foi possível instalar a nova imagem", + "The new image could not be installed:": "A nova imagem não pôde ser instalada:", + "The new image does not keep a required executable": "A nova imagem não mantém um executável required", + "The new image requires additional persistent paths": "O novo requires caminhos persistentes adicionais", + "The new image requires additional persistent paths; use Recreate": "A nova imagem requires caminhos persistentes adicionais; use Recrear", "The new prompt will be used in new terminal sessions.": "O novo prompt será usado em novas sessões do terminal.", "The next visit to the dashboard will show the initial setup wizard.": "A próxima visita ao painel mostrará o assistente de configuração inicial.", + "The observed inventory differs from the validated runtime": "O inventário observado difere do tempo de execução validado", + "The official Tandoor startup executable is missing": "Falta o executável oficial de inicialização Tandoor", + "The official inventory contains no NVIDIA devices": "O inventário oficial não contém dispositivos NVIDIA", + "The official inventory contains no NVIDIA driver components": "O inventário oficial não contém componentes do driver NVIDIA", + "The official startup cannot be reproduced": "A inicialização oficial não pode ser reproduzida", + "The official startup of the application is missing": "Falta a inicialização oficial da aplicação", + "The operation already finished; it is not restored automatically": "A operation já terminou; não é restaurada automaticamente", + "The operation could not be completed": "A operation não pôde ser completada", + "The operation stopped halfway. Choose \"Recover\" for this container in the OCI management menu to restore the previous installation.": "A operation parou a meio caminho. Escolha \"Recover\" para este recipiente no menu de gerenciamento OCI para restaurar a instalação anterior.", + "The operation was stopped because a shared directory changed its identity:": "A operation foi interrompida porque um diretório compartilhado mudou sua identidade:", "The original MOTD backup is unavailable; no changes were made": "O backup MOTD original não está disponível;nenhuma alteração foi feita", "The original MOTD configuration has been restored": "A configuração original do MOTD foi restaurada", "The original MOTD state is unavailable; no changes were made": "O estado MOTD original não está disponível;nenhuma alteração foi feita", @@ -4408,18 +5986,76 @@ "The original rpcbind state could not be restored completely": "O estado original do rpcbind não pôde ser restaurado completamente", "The original rpcbind state is unavailable; no service state was changed": "O estado rpcbind original não está disponível;nenhum estado de serviço foi alterado", "The package is currently in a broken state and is blocking apt updates on this system.": "O pacote está atualmente quebrado e está bloqueando atualizações do apt neste sistema.", + "The parent of an NVIDIA destination is not a directory": "O pai de um destino NVIDIA não é um diretório", + "The parent of the target is not a directory:": "O pai do alvo não é uma pasta:", + "The password could not be retrieved automatically": "A senha não pôde ser obtida automaticamente", "The passwords do not match. Please try again.": "As senhas não coincidem. Por favor, tente novamente.", + "The path escapes the rootfs:": "O caminho escapa aos rootfs:", + "The path must be absolute and normalized": "O caminho deve ser absoluto e normalizado", + "The path overlaps an existing mount": "O caminho sobrepõe- se a uma montagem existente", + "The persistent NVIDIA hook does not match the installer:": "O gancho NVIDIA persistente não corresponde ao instalador:", + "The persistent WebUI credentials were not found": "Os persistentes credentials não foram encontrados", + "The physical NVIDIA selection changed": "A seleção física de NVIDIA mudou", + "The post-start configuration cannot be applied with the LXC stopped": "A configuração pós- arranque não pode ser aplicada com o LXC parado", + "The postgres user was not found in the image": "O usuário do postgres não foi encontrado na imagem", + "The prepared directory escapes the rootfs:": "O diretório preparado escapa aos rootfs:", "The preselected VMID does not exist on this host:": "O VMID pré-selecionado não existe neste host:", + "The previous native backup will be restored. Shared host directories are not reverted. Displaced disks are kept.": "O backup nativo anterior será restaurado. As pastas da máquina partilhada não são revertidas. Os discos deslocados são mantidos.", + "The previous stack contract is not safe; review it before reusing it": "O contrato de pilha anterior não é seguro; reveja-o antes de reutilizá-lo", + "The previous stack contract is not valid; it is not archived automatically": "O contrato de pilha anterior não é válido; não é arquivado automaticamente", + "The previous stack contract still has containers or VMs:": "O contrato de pilha anterior ainda tem contêineres ou VMs:", + "The private address is already assigned to another container:": "O endereço privado já está atribuído a outro contentor:", + "The private bridge does not have the expected address:": "A ponte privada não tem o endereço esperado:", + "The private journal has an unsafe owner or permissions": "A revista privada tem um proprietário inseguro ou permissões", + "The private network allocator was not found": "O alocador de rede privada não foi encontrado", + "The private network is still used by another container and is kept:": "A rede privada ainda é utilizada por outro recipiente e é mantida:", + "The private network must be assigned automatically": "A rede privada deve ser atribuída automaticamente", + "The privileged deployment does not include the required explicit consent": "A implantação privilegiada não inclui o consentimento explícito required", + "The prlimit soft value exceeds the hard value": "O valor suave do prlimit excede o valor duro", + "The proposal changes the identity of the instance": "A proposta altera a identidade da instância", "The proposed ARC maximum is below Proxmox VE's pool-size guideline:": "O máximo ARC proposto está abaixo da diretriz de tamanho do pool de Proxmox VE:", + "The published views must be inside the common root": "As visualizações publicadas devem estar dentro da raiz comum", + "The read-only view does not apply the expected protection": "A visão somente leitura não aplica a proteção esperada", + "The read-only view was not published": "A visão somente leitura não foi publicada", + "The read/write view was not published": "A visão de leitura/escrita não foi publicada", + "The recipe requires configuration at startup; its coordinated replay is not available": "A configuração da receita requires na inicialização; sua repetição coordenada não está disponível", + "The record belongs to another container": "O registro pertence a outro recipiente", + "The record does not belong to this operation": "O registro não pertence a esta operation", + "The record no longer belongs to this operation": "O registro já não pertence a esta operation", + "The record of a member was replaced; the assembly is not resumed": "O registro de um membro foi substituído; a assembléia não é retomada", + "The record or diagnosis could not be completed; no update was run.": "O registro ou diagnóstico não pôde ser concluído; nenhuma atualização foi realizada.", + "The recovery did not complete. Review the log and choose \"Recover\" again for this container in the OCI management menu.": "A recuperação não terminou. Reveja o log e escolha \"Recover\" novamente para este recipiente no menu de gerenciamento OCI.", + "The remote does not exist; create and authorize it first in the WebUI:": "O remoto não existe; crie e autorize-o primeiro na WebUI:", + "The remote installer must run as root on Proxmox VE": "O instalador remoto deve correr como root no Proxmox VE", + "The remote must already be created and authorized in the Rclone web UI. This operation restarts the CT and publishes two FUSE views on the host.": "O controle remoto já deve ser criado e autorizado na interface web Rclone. Esta operation reinicia o CT e publica duas visualizações FUSE no host.", + "The remote path must be relative and cannot contain line breaks": "O caminho remoto deve ser relativo e não pode conter quebras de linha", + "The removal could not be prepared:": "A remoção não pôde ser preparada:", + "The repair must preserve the image dependencies:": "O reparo deve preservar as dependências da imagem:", + "The requested VMID block is already in use": "O bloco VMID solicitado já está em uso", + "The requested machine learning GPU profile is not working; it is not replaced by CPU": "O perfil de aprendizado de máquina solicitado GPU não está funcionando; não é substituído por CPU", + "The restored service did not pass its health check": "O serviço restaurado não passou no seu exame de saúde", + "The restored service stopped; the recovery is not confirmed": "O serviço restaurado parou; a recuperação não é confirmada", + "The reviewed Tandoor stack does not require a privileged LXC.": "A pilha Tandoor revisada não require um LXC privilegiado.", + "The rootfs capture only belongs to the running installation": "A captura do rootfs só pertence à instalação em execução", + "The rootfs is not managed by Proxmox": "O rootfs não é gerido pelo Proxmox", + "The rootfs is not mounted": "O rootfs não está montado", "The same GPU cannot be used by two VMs at the same time.": "A mesma GPU não pode ser usada por duas VMs ao mesmo tempo.", + "The same connection can be given as container variables instead of the file: UN_SONARR_0_URL and UN_SONARR_0_API_KEY, or the UN_RADARR_0_ equivalents.": "A mesma conexão pode ser dada como variáveis de container em vez do arquivo: UN SONARR 0 URL e UN SONARR 0 API KEY, ou o UN RADARR 0 equivalentes.", "The saved MOTD state is invalid; no changes were made": "O estado MOTD salvo é inválido;nenhuma alteração foi feita", + "The saved OCI record is incomplete or has an unexpected format.": "O registro OCI salvo está incompleto ou tem um formato inesperado.", + "The saved projection does not match the native evidence": "A projeção salva não corresponde à evidência nativa", + "The saved record was replaced for": "O registro salvo foi substituído por", "The saved utility package list is invalid; no packages were removed": "A lista de pacotes de utilitários salvos é inválida;nenhum pacote foi removido", "The script clones the osx-proxmox.com repository and once the setup is complete, the server will automatically reboot.": "O script clona o repositório osx-proxmox.com e assim que a configuração for concluída, o servidor será reinicializado automaticamente.", "The script will continue to restore VM passthrough mode on the host and reuse existing hostpci entries.": "O script continuará a restaurar o modo de passagem da VM no host e a reutilizar as entradas hostpci existentes.", "The script will preconfigure the selected GPU now and finalize hardware binding after reboot.": "O script irá pré-configurar a GPU selecionada agora e finalizará a ligação do hardware após a reinicialização.", "The selected AMD GPU does not report FLR reset support": "A GPU AMD selecionada não relata suporte para redefinição de FLR", "The selected AMD GPU is currently in power state D3cold": "A GPU AMD selecionada está atualmente no estado de energia D3cold", + "The selected CT does not match its OCI record. Its configuration will not be modified or deleted.": "A TC selecionada não corresponde ao seu registro OCI. Sua configuração não será modificada ou excluída.", + "The selected GPU changed": "A GPU selecionada mudou", "The selected GPU configuration already exists in this container.": "A configuração de GPU selecionada já existe neste contêiner.", + "The selected GPU device does not exist:": "O dispositivo GPU selecionado não existe:", + "The selected GPU directory does not exist:": "O diretório GPU selecionado não existe:", "The selected GPU has no dedicated .1 audio sibling function.": "A GPU selecionada não possui função de irmão de áudio .1 dedicada.", "The selected GPU is already assigned to another VM that is currently running:": "A GPU selecionada já está atribuída a outra VM em execução:", "The selected GPU is already assigned to this VM, but the host is not currently using vfio-pci for this device.": "A GPU selecionada já está atribuída a esta VM, mas o host não está usando atualmente vfio-pci para este dispositivo.", @@ -4435,11 +6071,15 @@ "The selected Intel GPU does not expose a PCI reset interface": "A GPU Intel selecionada não expõe uma interface de redefinição PCI", "The selected Intel GPU has non-FLR reset support and unknown subtype": "A GPU Intel selecionada tem suporte para redefinição não FLR e subtipo desconhecido", "The selected Intel GPU is currently in power state D3cold": "A GPU Intel selecionada está atualmente no estado de energia D3cold", + "The selected Intel render device does not exist:": "O dispositivo de renderização Intel selecionado não existe:", "The selected VM": "A VM selecionada", "The selected VM is running.": "A VM selecionada está em execução.", "The selected base folder does not exist and could not be created:": "A pasta base selecionada não existe e não pôde ser criada:", + "The selected configuration needs to start the LXC during the installation": "A configuração selecionada precisa iniciar o LXC durante a instalação", "The selected container is unprivileged. A privileged container is required for direct device passthrough.": "O contêiner selecionado não tem privilégios. Um contêiner privilegiado é necessário para passagem direta do dispositivo.", "The selected device": "O dispositivo selecionado", + "The selected device is not a block device": "O dispositivo selecionado não é um dispositivo de bloqueio", + "The selected device is not a character device": "O dispositivo selecionado não é um dispositivo de caracteres", "The selected directory does not exist:": "O diretório selecionado não existe:", "The selected disk has an active swap partition. Aborting.": "O disco selecionado possui uma partição swap ativa. Abortando.", "The selected disk is currently used by a RUNNING VM or CT. Stop it before formatting.": "O disco selecionado é usado atualmente por uma VM ou CT em RUNNING. Pare antes de formatar.", @@ -4447,25 +6087,76 @@ "The selected disk now contains a system-critical mount. Aborting.": "O disco selecionado agora contém uma montagem crítica do sistema. Abortando.", "The selected path does not exist on this host:": "O caminho selecionado não existe neste host:", "The selected path is not a valid directory:": "O caminho selecionado não é um diretório válido:", + "The selected render device does not exist:": "O dispositivo de renderização selecionado não existe:", "The server connected you as guest instead of the specified user.": "O servidor conectou você como convidado em vez do usuário especificado.", "The server may not have accessible shares.": "O servidor pode não ter compartilhamentos acessíveis.", "The server may require authentication for actual share access.": "O servidor pode exigir autenticação para acesso real ao compartilhamento.", "The server refused password authentication for": "O servidor recusou a autenticação por senha para", "The server rejected": "O servidor rejeitou", + "The service builds its own image; only a published image can be installed": "O serviço constrói sua própria imagem; somente uma imagem publicada pode ser instalada", + "The service declares no image:": "O serviço não declara imagem:", + "The setting has no final value:": "A configuração não tem valor final:", "The share already exists in smb.conf:": "O compartilhamento já existe em smb.conf:", + "The shared destination is not a directory": "O destino compartilhado não é um diretório", + "The shared directory points to a protected host path": "A pasta partilhada aponta para uma localização protegida da máquina", + "The shared path exists but is not a directory:": "O caminho compartilhado existe mas não é um diretório:", + "The size of existing disks is not rounded": "O tamanho dos discos existentes não é arredondado", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk.": "A fonte Compõe pedidos privilegiados: true, mas isso não prova que a imagem precisa de um LXC privilegiado. ProxMenux usará um LXC sem privilégios por padrão e oferecerá o modo amplo apenas como opção. Continue apenas se você confiar na imagem e aceitar este risco.", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. The Docker rootlesskit profile does not exist in LXC and will be replaced by AppArmor unconfined, which is less restrictive. Continue only if you trust the image and accept this risk.": "A fonte Compõe pedidos privilegiados: true, mas isso não prova que a imagem precisa de um LXC privilegiado. ProxMenux usará um LXC sem privilégios por padrão e oferecerá o modo amplo apenas como opção. O Compose oferece um relaxamento opcional AppArmor ou seccomp; ele ficará desativado a menos que o usuário o selecione. O perfil Docker rootlesskit não existe em LXC e será substituído por AppArmor sem confinar, o que é menos restritivo. Continue apenas se você confiar na imagem e aceitar este risco.", "The source VM also has these audio devices, likely added together with the GPU. Remove them too?": "A VM de origem também possui esses dispositivos de áudio, provavelmente adicionados junto com a GPU. Remova-os também?", "The specified directory does not exist:": "O diretório especificado não existe:", + "The stability period must be shorter than the healthcheck timeout": "O período de estabilidade deve ser mais curto do que o tempo de verificação de saúde", + "The stack contains devices or directives without a translation": "A pilha contém dispositivos ou diretivas sem tradução", + "The stack does not have the expected native hook": "A pilha não tem o gancho nativo esperado", + "The stack journal is outside the registry": "O diário de pilha está fora do registro", + "The stack member has no declared adaptation profile": "O membro da pilha não tem perfil de adaptação declarado", + "The stack name only accepts lowercase letters, numbers and hyphens": "O nome da pilha só aceita letras minúsculas, números e hífens", + "The stack needs member adaptations or a verification of missing volumes": "A pilha precisa de adaptações de membros ou uma verificação dos volumes em falta", + "The stack operation had already finished": "A pilha operation já tinha terminado", + "The stack operation has not finished yet": "A pilha operation ainda não terminou", + "The stack operation stopped halfway. Select the stack again in the OCI management menu to recover it.": "A pilha operation parou a meio caminho. Selecione a pilha novamente no menu de gerenciamento OCI para recuperá-lo.", + "The stack registry is incomplete; review the private contracts.": "O registro da pilha está incompleto; revise os contratos privados.", + "The stack startup hook was not found": "O gancho de inicialização da pilha não foi encontrado", + "The stack update was saved.": "A atualização da pilha foi salva.", + "The startup differs from the declared Nextcloud adapter": "A inicialização difere do adaptador Nextcloud declarado", + "The startup differs from the declared adapter": "A inicialização difere do adaptador declarado", + "The staticfiles volume needs at least 1 GB": "O volume de ficheiros estáticos necessita de pelo menos 1 GB", "The storage has been removed and the disk unmounted.": "O armazenamento foi removido e o disco desmontado.", + "The sysctl content was modified outside the saved record": "O conteúdo do sysctl foi modificado fora do registro salvo", + "The sysctl include is a link:": "O sysctl inclui um link:", + "The sysctl include is not a safe host file": "A inclusão do sysctl não é um ficheiro de máquina seguro", + "The sysctl include is not restored over a symbolic link": "A inclusão do sysctl não é restaurada sobre um link simbólico", + "The sysctl include is unknown or differs from the saved record": "A inclusão do sysctl é desconhecida ou difere do registro salvo", + "The temporary password could not be retrieved.": "Não foi possível obter a senha temporária.", "The test will continue even if you close this terminal.": "O teste continuará mesmo se você fechar este terminal.", + "The tmpfs mounts of the container differ from the saved record": "As montagens tmpfs do recipiente diferem do registo gravado", + "The tmpfs path or size is outside the supported profile": "O caminho ou tamanho do tmpfs está fora do perfil suportado", + "The translated recipe changed during the preparation": "A receita traduzida mudou durante a preparação", + "The value contains an unsupported character": "O valor contém um caracter não suportado", + "The values do not match. Enter them again.": "Os valores não correspondem. Entra outra vez.", + "The variable contains control characters:": "A variável contém caracteres de controle:", + "The variable contains line breaks:": "A variável contém quebras de linha:", "The vfio.conf entries have been removed and initramfs rebuilt.": "As entradas vfio.conf foram removidas e o initramfs reconstruído.", + "The web UI password must have at least 24 characters": "A senha da interface web deve ter pelo menos 24 caracteres", + "The web UI user contains characters that are not allowed": "O usuário de interface web contém caracteres que não são permitidos", + "The web interface is served over plain HTTP on port 51821 (INSECURE=true). Keep it inside the local network or publish it through a reverse proxy with TLS.": "A interface web é servida sobre HTTP simples na porta 51821 (INSECURE=true). Mantenha-o dentro da rede local ou publique-o através de um proxy reverso com TLS.", + "The web interface uses a self-signed certificate, so the browser shows a warning the first time.": "A interface web usa um certificado auto-assinado, então o navegador mostra um aviso na primeira vez.", + "The wizard writes a .conf file in /config. Restart the container afterwards so the bot starts with that configuration.": "O assistente escreve um arquivo .conf em /conf. Reinicie o recipiente depois para que o bot comece com essa configuração.", + "The world's fastest framework for building websites": "A estrutura mais rápida do mundo para construir sites", + "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server.": "Thelounge (um fork de shoutIRC) é um cliente de IRC web que você hospeda em seu próprio servidor.", "Then bind-mount to container": "Em seguida, ligue a montagem ao contêiner", "Then change the VM display to none (vga: none) when the guest is stable.": "Em seguida, altere a exibição da VM para nenhum (vga: nenhum) quando o convidado estiver estável.", "Then change the VM display to none (vga: none) when the system is stable.": "Em seguida, altere a exibição da VM para nenhum (vga: nenhum) quando o sistema estiver estável.", "Then run this option again:": "Em seguida, execute esta opção novamente:", "Then update /etc/fstab on the host with the same options.": "Em seguida, atualize /etc/fstab no host com as mesmas opções.", + "There are extra disks or bind mounts outside the journal; the rootfs is not replaced": "Existem discos extras ou montagens de ligação fora do diário; o rootfs não é substituído", + "There is no temporary container of this operation to keep the current disks": "Não existe nenhum recipiente temporário deste operation para manter os discos atuais", + "There is no verified backup; a modified container is not touched": "Não existe backup verificado; um recipiente modificado não é tocado", + "These VMIDs are not free:": "Estes VMIDs não são gratuitos:", "These are the changes that will be made": "Estas são as mudanças que serão feitas", "These interface configurations will be removed": "Essas configurações de interface serão removidas", "These paths will not be restored live and will be extracted for manual recovery.": "Esses caminhos não serão restaurados ao vivo e serão extraídos para recuperação manual.", + "These values are asked during the installation:": "Estes valores são questionados durante a instalação:", "This CIFS share is mounted with restrictive permissions.": "Este compartilhamento CIFS é montado com permissões restritivas.", "This GPU is considered incompatible with GPU passthrough to a VM in ProxMenux.": "Esta GPU é considerada incompatível com a passagem de GPU para uma VM no ProxMenux.", "This NFS share is fully restricted — even the host root cannot write to it.": "Este compartilhamento NFS é totalmente restrito — até mesmo o host root não pode gravar nele.", @@ -4477,6 +6168,8 @@ "This backup is encrypted.": "Este backup está criptografado.", "This backup was taken on kernel": "Este backup foi feito no kernel", "This cleanup will:": "Esta limpeza irá:", + "This container belongs to a stack; publish the whole stack": "Este recipiente pertence a uma pilha; publique a pilha inteira", + "This container belongs to a stack; recover the whole stack": "Este recipiente pertence a uma pilha; recuperar a pilha inteira", "This container does not have apt-get. NFS client installation only supports Debian/Ubuntu containers.": "Este contêiner não possui o apt-get. A instalação do cliente NFS suporta apenas contêineres Debian/Ubuntu.", "This container does not have apt-get. Samba client installation only supports Debian/Ubuntu containers.": "Este contêiner não possui o apt-get. A instalação do cliente Samba suporta apenas contêineres Debian/Ubuntu.", "This container has no GPU configured. Coral TPU works best alongside hardware video decoding (Quick Sync, VA-API, NVENC) for apps like Frigate.": "Este contêiner não tem GPU configurada. Coral TPU funciona melhor com decodificação de vídeo de hardware (Quick Sync, VA-API, NVENC) para aplicativos como Frigate.", @@ -4486,15 +6179,21 @@ "This erases existing metadata.": "Isso apaga os metadados existentes.", "This explicitly marks the container as privileged": "Isso marca explicitamente o contêiner como privilegiado", "This guarantees that device nodes are available before applying LXC GPU config.": "Isso garante que os nós do dispositivo estejam disponíveis antes de aplicar a configuração da GPU LXC.", + "This image cannot be installed as it is described:": "Esta imagem não pode ser instalada como está descrita:", + "This image requires the host module": "Esta imagem requires o módulo da máquina", "This installation will:": "Esta instalação irá:", "This installer will:": "Este instalador irá:", "This interface is configured but doesn't exist physically": "Esta interface está configurada, mas não existe fisicamente", + "This interface runs on the Proxmox node as root. Open proxmenux-oci.sh on the Proxmox host.": "Esta interface é executada no nó Proxmox como root. Abra proxmenux-oci.sh no host Proxmox.", "This is IRREVERSIBLE.": "Mensagem técnica para Proxmox e TI.Traduza: Isso é IRREVERSÍVEL.", "This is a destructive action": "Esta é uma ação destrutiva", "This is a simple configuration change": "Esta é uma simples mudança de configuração", "This is an external community script maintained by": "Este é um script da comunidade externa mantido por", "This is an external script that creates a macOS VM in Proxmox VE in just a few steps, whether you are using AMD or Intel hardware.": "Este é um script externo que cria uma VM macOS no Proxmox VE em apenas algumas etapas, esteja você usando hardware AMD ou Intel.", + "This is not a coordinated stack": "Esta não é uma pilha coordenada", + "This is not a valid image reference:": "Esta não é uma referência de imagem válida:", "This is unexpected since credentials were validated.": "Isto é inesperado, uma vez que as credenciais foram validadas.", + "This is what ProxMenux understood from the": "Isto é o que ProxMenux entendeu a partir do", "This marks the container as unprivileged": "Isso marca o contêiner como sem privilégios", "This may be normal for a fresh installation": "Isso pode ser normal para uma nova instalação", "This may take a few minutes. Press OK to proceed.": "Isso pode levar alguns minutos. Pressione OK para continuar.", @@ -4503,12 +6202,14 @@ "This means Proxmox handles mount lifecycle natively (no manual /etc/fstab needed for NFS/CIFS host storages).": "Isso significa que o Proxmox lida com o ciclo de vida da montagem nativamente (não é necessário /etc/fstab manual para armazenamentos de host NFS/CIFS).", "This means the credentials are incorrect.": "Isso significa que as credenciais estão incorretas.", "This might indicate network connectivity issues.": "Isso pode indicar problemas de conectividade de rede.", + "This monitor uses a privileged LXC, shares processes and network with Proxmox and disables AppArmor in the CT. It uses the IP address and firewall of the host. A compromised image could affect the host; do not expose its web UI to the Internet.": "Este monitor usa um LXC privilegiado, compartilha processos e rede com Proxmox e desativa AppArmor no CT. Ele usa o endereço IP e firewall do host. Uma imagem comprometida poderia afetar o host; não expor sua interface web para a Internet.", "This operation may take several minutes and requires internet connectivity.": "Esta operação pode demorar vários minutos e requer conectividade com a Internet.", "This package was installed by older versions of the ProxMenux Coral installer that placed the M.2 kernel driver on every system, including USB-only setups. It is not needed for Coral USB devices, which use libedgetpu1-std / libedgetpu1-max only.": "Este pacote foi instalado por versões mais antigas do instalador ProxMenux Coral que colocava o driver do kernel M.2 em todos os sistemas, incluindo configurações somente USB.Não é necessário para dispositivos Coral USB, que usam apenas libedgetpu1-std / libedgetpu1-max.", "This passphrase is the ONLY way to access encrypted Borg backups.": "Esta senha é a ÚNICA maneira de acessar backups criptografados do Borg.", "This path is already used as a mount point in this container.": "Este caminho já é usado como ponto de montagem neste contêiner.", "This path is not a registered mount point. Use it anyway?": "Este caminho não é um ponto de montagem registrado. Usar mesmo assim?", "This process changes file ownership inside the container": "Este processo altera a propriedade do arquivo dentro do contêiner", + "This profile only supports directory bind mounts": "Este perfil só suporta montagens de ligação de pastas", "This release channel is already active.": "Este canal de lançamento já está ativo.", "This removes the 'unprivileged: 1' line from the config": "Isso remove a linha ‘unprivileged: 1’ da configuração", "This removes the storage from Proxmox. The iSCSI target is not affected.": "Isso remove o armazenamento do Proxmox. O destino iSCSI não é afetado.", @@ -4522,10 +6223,15 @@ "This session is running in the Monitor terminal. Running it from here would cut the connection mid-install and leave the switch in a broken state.": "Esta sessão está sendo executada no terminal Monitor. Executá-lo a partir daqui cortaria a conexão no meio da instalação e deixaria o switch quebrado.", "This session is running in the Monitor terminal. Updating from here would restart the Monitor service and cut the connection mid-install, leaving the update in a broken state.": "Esta sessão está sendo executada no terminal Monitor. A atualização a partir daqui reiniciaria o serviço Monitor e cortaria a conexão no meio da instalação, deixando a atualização em um estado interrompido.", "This shows the storage type and disk identifier": "Isso mostra o tipo de armazenamento e o identificador do disco", + "This stack requires replaying specific rootfs adaptations. Coordinated updates are not yet enabled for it.": "Esta pilha requires replaying adaptações rootfs específicas. As atualizações coordenadas ainda não estão habilitadas para ele.", "This state has a high probability of VM startup/reset failures.": "Este estado tem uma alta probabilidade de falhas de inicialização/redefinição da VM.", "This state indicates a high risk of passthrough failure due to": "Este estado indica um alto risco de falha de passagem devido a", + "This template requests the host PID namespace, which has no validated safe LXC translation yet": "Este modelo solicita o espaço de nomes PID da máquina, que ainda não possui uma tradução segura validada para o LXC", "This tool is designed for systems with AMD GPUs.": "Esta ferramenta foi projetada para sistemas com GPUs AMD.", "This tool is designed for systems with Intel GPUs.": "Esta ferramenta foi projetada para sistemas com GPUs Intel.", + "This translator only supports the Nextcloud stack": "Este tradutor só suporta o Nextcloud stack", + "This value is required.": "Este valor é required.", + "This variant requires the device": "Esta variante requires o dispositivo", "This version does not build against the running kernel.": "Esta versão não é construída no kernel em execução.", "This will RESET the ProxMenux Monitor login credentials on this host:": "Isso irá REINICIAR as credenciais de login do ProxMenux Monitor neste host:", "This will add the mount to /etc/fstab so it persists after reboot.": "Isso adicionará a montagem ao /etc/fstab para que persista após a reinicialização.", @@ -4547,13 +6253,17 @@ "This will restart the network service and may cause a brief disconnection. Continue?": "Isto reiniciará o serviço de rede e poderá causar uma breve desconexão. Continuar?", "This will take time. Answer prompts carefully - see notes below.": "Isso levará tempo. Responda às solicitações com cuidado - veja as notas abaixo.", "This will upgrade this node to Proxmox VE 9 on Debian Trixie.": "Isto irá atualizar este nó para Proxmox VE 9 no Debian Trixie.", + "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client.": "Thunderbird é um gerenciador de informações pessoais livre e de código aberto usado principalmente como um cliente de e-mail com um calendário e livro de contatos, bem como um leitor de feed RSS, cliente de chat e cliente de notícias.", "Tick the paths to include in this backup. Press \"Add custom path\" to add a folder or file of your own to the list.": "Assinale os caminhos a incluir neste backup. Pressione \"Adicionar caminho personalizado\" para adicionar uma pasta ou arquivo à lista.", "Tick the paths to remove (they will not be deleted from disk — only from this list):": "Marque os caminhos a serem removidos (eles não serão excluídos do disco — apenas desta lista):", + "Time is up; Home Assistant OS could not be confirmed as running": "Acabou o tempo; o sistema operacional Home Assistant não pôde ser confirmado como em execução", "Time settings configured - Timezone:": "Configurações de horário configuradas - Fuso horário:", "Time synchronization reset to UTC": "Sincronização de horário redefinida para UTC", + "Timezone": "Fuso horário", "Tip: Also mount the VirtIO ISO for drivers and guest agent installer": "Dica: monte também o VirtIO ISO para drivers e instalador de agente convidado", "Tip: You can install the QEMU Guest Agent inside the VM with:": "Dica: você pode instalar o agente convidado QEMU dentro da VM com:", "Tip: zfs set acltype=posixacl xattr=sa / enables full ACL support.": "Dica: zfs set acltype=posixacl xattr=sa / permite suporte completo a ACL.", + "Tmpfs size in MiB for": "Tamanho do Tmpfs em MiB para", "To allow LXC write access, change the NFS export on the server to include:": "Para permitir o acesso de gravação LXC, altere a exportação NFS no servidor para incluir:", "To apply it to the current shell now, run:": "Para aplicá-lo agora à sessão shell atual, execute:", "To assign VFs to VMs or LXCs, edit the configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Para atribuir VFs a VMs ou LXCs, edite a configuração manualmente por meio da interface web do Proxmox. A Função Física permanecerá vinculada ao driver nativo.", @@ -4568,6 +6278,7 @@ "To pass SR-IOV Virtual Functions to a container, edit the LXC configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Para passar funções virtuais SR-IOV para um contêiner, edite a configuração LXC manualmente por meio da interface da web do Proxmox. A Função Física permanecerá vinculada ao driver nativo.", "To remove partial VM:": "Para remover VM parcial:", "To restore": "Para restaurar", + "To restore it on another host, keep this file (not included in the vzdump backup):": "Para restaurá-lo em outra máquina, mantenha este arquivo (não incluído no backup vzdump):", "To revert changes:": "Para reverter alterações:", "To start the VM:": "Para iniciar a VM:", "To stop:": "Para parar:", @@ -4579,12 +6290,17 @@ "To use this share from an LXC, bind-mount it via:": "Para usar este compartilhamento de um LXC, monte-o por meio de:", "Tool exit code:": "Código de saída da ferramenta:", "Tool output:": "Saída da ferramenta:", + "Tools": "Ferramentas", "Top memory processes in CT": "Principais processos de memória em CT", + "Top-level configs, secrets and other global options are not yet supported": "Configurações de topo, segredos e outras opções globais ainda não são suportadas", + "Top-level volume options are not yet supported": "As opções de volume de topo ainda não são suportadas", "Total": "Total", "Total members:": "Total de membros:", "Total routes": "Rotas totais", "Total size:": "Tamanho total:", + "Transaction log:": "Registo de transacções:", "Translation files:": "Arquivos de tradução:", + "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, µTP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more.": "Transmission é projetado para uso fácil e poderoso. Transmission tem os recursos que você deseja de um cliente BitTorrent: criptografia, uma interface web, troca de pares, links magnéticos, DHT, μTP, encaminhamento de portas UPnP e NAT-PMP, suporte a webseed, diretórios de relógio, edição de rastreadores, limites de velocidade globais e per-torrent, e muito mais.", "Tried pvesm path and manual detection methods": "Tentei caminho pvesm e métodos de detecção manual", "Trust this certificate and save it for scheduled backups?": "Confiar neste certificado e salvá-lo para backups agendados?", "Try Again": "Tente novamente", @@ -4592,6 +6308,8 @@ "Try accessing": "Tente acessar", "Try another archive": "Tente outro arquivo", "Try automatic repair of detected issues": "Experimente o reparo automático dos problemas detectados", + "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources.": "Tvheadend funciona como um servidor proxy: é um servidor de streaming de TV para Linux, FreeBSD e Android que suporta DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP e HDHomeRun como fontes de entrada.", + "Twingate Connector for self-hosted server": "Conector Twingate para servidor auto- hospedado", "Two-factor authentication and backup codes will be removed.": "A autenticação de dois fatores e os códigos de backup serão removidos.", "Type": "Tipo", "Type the device path EXACTLY to confirm formatting:": "Digite EXATAMENTE o caminho do dispositivo para confirmar a formatação:", @@ -4600,16 +6318,22 @@ "Type: attached to PVE storage": "Tipo: anexado ao armazenamento PVE", "Typed value does not match selected disk. Operation cancelled.": "O valor digitado não corresponde ao disco selecionado. Operação cancelada.", "UID in CT": "UID em CT", + "UID of the plex user (also owner of the GPU device)": "UID do usuário plex (também proprietário do dispositivo GPU)", + "UID that Emby runs as": "UID que o Emby funciona como", "UPGRADE PROMPTS - RECOMMENDED ANSWERS:": "PROMPTS DE ATUALIZAÇÃO - RESPOSTAS RECOMENDADAS:", + "UPS monitoring and power outage notification system": "Sistema de notificação de perda de energia e monitorização UPS", "USB Accelerators:": "Aceleradores USB:", + "USB bus directory": "Directório do barramento USB", "USB disk target": "destino de disco USB", "USB drives mounted now:": "unidades USB montadas agora:", "USB libedgetpu1": "USB libedgetpu1", "UUP Dump script not found.": "Script de despejo UUP não encontrado.", "UUp Dump ISO creator Custom": "Criador UUp Dump ISO personalizado", + "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer.": "Ubooquity é um servidor doméstico gratuito, leve e fácil de usar para seus quadrinhos e ebooks. Use-o para acessar seus arquivos de qualquer lugar, com um tablet, um e-leitor, um telefone ou um computador.", "Udev rules for Coral USB devices added and rules reloaded.": "Regras Udev para dispositivos USB Coral adicionadas e regras recarregadas.", "Udev rules for Coral USB devices already exist.": "As regras do Udev para dispositivos USB Coral já existem.", "Udev rules for Coral USB devices appended and rules reloaded.": "Regras Udev para dispositivos Coral USB anexadas e regras recarregadas.", + "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results.": "UltiMaker Cura é software de impressão 3D gratuito e fácil de usar confiável por milhões de usuários. Ajuste o seu modelo 3D com mais de 400 configurações para obter os melhores resultados de corte e impressão.", "Umbrel OS installer script by Helper Scripts\n\nVisit the GitHub repo to learn more, contribute, or support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm": "Script de instalação do Umbrel OS por Helper Scripts\n\nVisite o repositório GitHub para saber mais, contribuir ou apoiar o projeto:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm", "Unable to detect Proxmox version": "Não foi possível detectar a versão do Proxmox", "Unable to detect Proxmox version.": "Não foi possível detectar a versão do Proxmox.", @@ -4618,6 +6342,10 @@ "Unable to resolve system ZFS pool disks. Aborting.": "Não foi possível resolver os discos do pool ZFS do sistema. Abortando.", "Unable to resolve system disk topology. Aborting.": "Não é possível resolver a topologia do disco do sistema. Abortando.", "Understand the security implications of privileged containers": "Entenda as implicações de segurança de contêineres privilegiados", + "Unexpected Proxmox inventory; recovery blocked": "Inesperado inventário Proxmox; recuperação bloqueada", + "Unexpected formatting directory in the new Valkey volume": "Directório de formatação inesperado no novo volume Valkey", + "Ungoogled Chromium is Google Chromium, sans dependency on Google web services.": "Ungoogled Chromium é o Google Chromium, sem dependência de serviços web do Google.", + "Unified LLM Fine-Tuning with 100+ Models": "Unified LLM Fine-Tuning com mais de 100 modelos", "Uninstall Coral drivers and configuration": "Desinstale os drivers e configuração do Coral", "Uninstall Fail2Ban": "Desinstalar Fail2Ban", "Uninstall Lynis": "Desinstalar Lynis", @@ -4647,6 +6375,10 @@ "Unknown CPU type. IOMMU might not be properly enabled.": "Tipo de CPU desconhecido. O IOMMU pode não estar habilitado corretamente.", "Unknown CPU vendor. Cannot determine IOMMU parameter.": "Fornecedor de CPU desconhecido. Não é possível determinar o parâmetro IOMMU.", "Unknown GPU": "GPU desconhecida", + "Unknown adapter role": "Papel do adaptador desconhecido", + "Unknown credential service:": "Serviço credential desconhecido:", + "Unknown dependency:": "Dependência desconhecida:", + "Unknown host monitor": "Monitor da máquina desconhecido", "Unknown model": "Modelo desconhecido", "Unknown size": "Tamanho desconhecido", "Unknown storage controller": "Controlador de armazenamento desconhecido", @@ -4662,6 +6394,10 @@ "Unmounted:": "Desmontado:", "Unmounting": "Desmontando", "Unmounting disk...": "Desmontando disco...", + "Unpackerr configured": "Unpackerr configurado", + "Unpackerr has no web interface and extracts nothing until it is pointed at a Starr application. Uncomment the [sonarr.0] or [radarr.0] section in /config/unpackerr.conf inside the container, set its url and api_key, then restart the container.": "Unpackerr não tem interface web e não extrai nada até ser apontado para uma aplicação Starr. Descomente a seção [sonarr.0] ou [radarr.0] em /config/unpackerr.conf dentro do recipiente, defina seu url e api key e reinicie o recipiente.", + "Unpackerr requires Sonarr, Radarr or Lidarr in this suite": "Unpackerr requires Sonarr, Radarr ou Lidarr nesta suite", + "Unpackerr stopped during its first start": "Unpackerr parou durante o seu primeiro início", "Unprivileged": "Sem privilégios", "Unprivileged Container Access": "Acesso a contêineres sem privilégios", "Unprivileged container": "Contêiner sem privilégios", @@ -4670,15 +6406,73 @@ "Unprivileged containers map their UIDs to high host UIDs (e.g. 100000+), which appear as 'others' on the host filesystem.": "Contêineres sem privilégios mapeiam seus UIDs para UIDs de host altos (por exemplo, 100.000+), que aparecem como 'outros' no sistema de arquivos do host.", "Unprivileged: Limited access (more secure)": "Sem privilégios: acesso limitado (mais seguro)", "Unreachable": "Inacessível", + "Unrecognized Immich adapter": "Adaptador Immich não reconhecido", + "Unrecognized adaptation format": "Formato de adaptação não reconhecido", + "Unrecognized adaptation recipe": "Receita de adaptação não reconhecida", + "Unrecognized dependency order of the stack:": "Ordem de dependência não reconhecida da pilha:", + "Unrecognized host monitor profile": "Perfil do monitor da máquina não reconhecido", + "Unrecognized native configuration": "Configuração nativa não reconhecida", + "Unrecognized qBittorrent configuration format": "Formato de configuração qBittorrent não reconhecido", + "Unrecognized stack adapter or role": "Adaptador ou função de pilha não reconhecido", + "Unrecognized stack adapter:": "Adaptador de pilha não reconhecido:", + "Unrecognized stack structure:": "Estrutura de pilha não reconhecida:", + "Unrecognized volume definition": "Definição de volume não reconhecida", + "Unresolved variable:": "Variável não resolvida:", + "Unsafe OCI archive path": "Caminho de arquivo OCI inseguro", + "Unsafe dependency contract": "Contrato de dependência inseguro", + "Unsafe dependency hook contract": "Contrato de gancho de dependência inseguro", + "Unsafe instance directory": "Directório de instância inseguro", + "Unsafe instance record": "Registo de instância inseguro", + "Unsafe journal or lock file": "Ficheiro de bloqueio ou diário inseguro", + "Unsafe private configuration path": "Caminho de configuração privado inseguro", + "Unsafe qBittorrent configuration path": "Caminho de configuração não seguro do qBittorrent", + "Unsafe record": "Registo inseguro", + "Unsafe registry directory": "Diretório de registro inseguro", + "Unsafe registry lock": "Bloqueio de registo inseguro", + "Unsafe rootfs for the capture": "Rootfs inseguros para a captura", + "Unsafe stack assembly": "Montagem da pilha insegura", + "Unsafe volume path": "Caminho de volume inseguro", + "Unsupported CPU allocation mode:": "Modo de alocação de CPU não suportado:", + "Unsupported GID strategy:": "Estratégia GID não suportada:", + "Unsupported NVIDIA mode:": "Modo NVIDIA não suportado:", + "Unsupported OCI digest:": "Digerir OCI não suportado:", + "Unsupported OCI-LXC AppArmor profile:": "Perfil do AppArmor OCI-LXC não suportado:", + "Unsupported OCI-LXC seccomp profile:": "Perfil OCI-LXC seccomp não suportado:", "Unsupported Terminal": "Terminal não suportado", + "Unsupported architecture:": "Arquitetura não suportada:", + "Unsupported backup compression": "Compressão de backup não suportada", + "Unsupported credential pattern:": "Padrão credential não suportado:", + "Unsupported declarative ostype:": "Ostipo declarativo não suportado:", + "Unsupported device GID strategy": "Estratégia GID do dispositivo não suportado", + "Unsupported device type:": "Tipo de dispositivo não suportado:", + "Unsupported dynamic NVIDIA capabilities:": "Capacidades NVIDIA dinâmicas não suportadas:", "Unsupported format. Only .ova and .ovf files are supported.": "Formato não suportado. Somente arquivos .ova e .ovf são suportados.", + "Unsupported media storage mode:": "Modo de armazenamento de mídia não suportado:", + "Unsupported mount type": "Tipo de montagem não suportado", + "Unsupported mount type:": "Tipo de montagem não suportado:", + "Unsupported native device type:": "Tipo de dispositivo nativo não suportado:", + "Unsupported operation": "operation não suportado", "Unsupported output format:": "Formato de saída não suportado:", + "Unsupported post-start configuration:": "Configuração pós- arranque não suportada:", + "Unsupported pre-start check:": "Verificação prévia não suportada:", + "Unsupported pre-start repair:": "Reparação pré-inicial não suportada:", + "Unsupported prlimit resource": "Recurso de prlimit não suportado", + "Unsupported secret generator:": "Gerador secreto não suportado:", + "Unsupported storage mode:": "Modo de armazenamento não suportado:", + "Unsupported tmpfs options": "Opções de tmpfs não suportadas", + "Unsupported volume options:": "Opções de volume não suportadas:", + "Untrusted or modified NVIDIA hook": "Gancho NVIDIA não confiável ou modificado", + "Unused image removed from the cache:": "Imagem não usada removida da cache:", + "Unused images removed from the cache:": "Imagens não usadas removidas da cache:", + "Update": "Atualizar", "Update Available": "atualização disponível", "Update Ceph repository (Only if using Ceph):": "Atualize o repositório do Ceph (somente se estiver usando o Ceph):", "Update Debian repositories to Trixie:": "Atualize os repositórios Debian para Trixie:", "Update Export": "Atualizar exportação", "Update Lynis to latest version": "Atualize Lynis para a versão mais recente", "Update NVIDIA in LXC Containers": "Atualizar NVIDIA em contêineres LXC", + "Update OCI": "Actualizar OCI", + "Update OCI stack": "Actualizar a pilha OCI", "Update PVE enterprise repository (Only if using enterprise):": "Atualize o repositório corporativo PVE (somente se estiver usando corporativo):", "Update Proxmox VE Appliance Manager": "Atualizar Proxmox VE Appliance Manager", "Update Proxmox package lists": "Atualizar listas de pacotes Proxmox", @@ -4687,15 +6481,26 @@ "Update and upgrade all system packages": "Atualize e atualize todos os pacotes do sistema", "Update and upgrade system": "Atualizar e atualizar o sistema", "Update cancelled by user": "Atualização cancelada pelo usuário", + "Update completed. Data kept.": "Actualização concluída. Dados guardados.", "Update completed. Press Enter to continue...": "Atualização concluída. Pressione Enter para continuar...", + "Update every container of the application": "Atualizar cada recipiente do aplicativo", "Update kernel to compatible version": "Atualize o kernel para uma versão compatível", + "Update now?": "Actualizar agora?", "Update package index:": "Atualizar índice do pacote:", + "Update prepared": "Actualização preparada", "Update system to latest PVE 8.4+ (if not done already):": "Atualize o sistema para o PVE 8.4+ mais recente (se ainda não tiver feito):", + "Update the image with the saved configuration": "Atualizar a imagem com a configuração salva", + "Update the whole stack?": "Atualizar toda a pilha?", "Updated": "Atualizado", "Updated sharedfiles group to GID: 101000": "Grupo de arquivos compartilhados atualizado para GID: 101000", + "Updated stack checked": "Stack atualizado verificado", + "Updated:": "Actualizado:", "Updates all Proxmox and Debian packages": "Atualiza todos os pacotes Proxmox e Debian", "Updates and Packages Commands": "Comandos de atualizações e pacotes", + "Updates are not available yet for this application in this beta": "As atualizações ainda não estão disponíveis para esta aplicação neste beta", + "Updates are not available yet in this beta for applications that use a privileged container or advanced LXC settings": "Atualizações ainda não estão disponíveis neste beta para aplicações que usam um recipiente privilegiado ou configurações LXC avançadas", "Updates file is empty or unreadable.": "O arquivo de atualizações está vazio ou ilegível.", + "Updating": "Actualização", "Updating APT package lists...": "Atualizando listas de pacotes APT...", "Updating Debian Bookworm → Trixie in sources.list...": "Atualizando Debian Bookworm → Trixie em fontes.list...", "Updating Figurine binary...": "Atualizando o binário da estatueta...", @@ -4727,6 +6532,7 @@ "Upload to PBS is currently: yes. Pick an action:": "O upload para PBS é atualmente: sim. Escolha uma ação:", "Upload to PBS: enable, disable or rotate the recovery passphrase": "Carregar para PBS: ativar, desativar ou alternar a senha de recuperação", "Uptime and who is logged in": "Tempo de atividade e quem está logado", + "Usage:": "Uso:", "Use \"Check test progress\" to see results.": "Use \"Verificar o progresso do teste\" para ver os resultados.", "Use 'Export to file' to save it and inspect manually.": "Use 'Exportar para arquivo' para salvá-lo e inspecionar manualmente.", "Use 'pct restore' / 'qmrestore' to recover their disks from your VM backups.": "Use 'pct restore' / 'qmrestore' para recuperar seus discos de seus backups de VM.", @@ -4769,6 +6575,12 @@ "User activity and uptime": "Atividade do usuário e tempo de atividade", "User chose not to remove NetworkManager": "O usuário optou por não remover o NetworkManager", "User chose to exit for manual backup creation.": "O usuário optou por sair para a criação manual de backup.", + "User name for the SSH login": "Nome do usuário para o login do SSH", + "User name of the administrator of the web interface": "Nome do usuário do administrador da interface web", + "User name of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Nome de usuário do login de aplicativo Flowise obsoleto (apenas lido pelas versões Flowise antes de 3.0.1)", + "User of the AdGuard Home that receives the settings": "Usuário do AdGuard Home que recebe as configurações", + "User of the main AdGuard Home": "Usuário do AdGuard Home principal", + "User-friendly WebUI for LLMs (Formerly Ollama WebUI)": "WebUI amigável para LLMs (formerly Ollama WebUI)", "Username": "Nome de usuário", "Username (e.g. root@pam or user@pbs!token):": "Nome de usuário (por exemplo, root@pam ou user@pbs!token):", "Username and password": "Nome de usuário e senha", @@ -4782,6 +6594,8 @@ "Using advanced configuration": "Usando configuração avançada", "Using default Proxmox logo...": "Usando o logotipo padrão do Proxmox...", "Using existing encryption key:": "Usando a chave de criptografia existente:", + "Using the image verified by the transaction": "Usando a imagem verificada pela transação", + "Using the verified image from the cache": "Usando a imagem verificada da cache", "Utilities": "Utilitários", "Utilities Installation Menu": "Menu de instalação de utilitários", "Utilities Menu": "Menu Utilitários", @@ -4789,6 +6603,9 @@ "Utilities and Tools": "Utilitários e ferramentas", "Utilities installation completed": "Instalação de utilitários concluída", "Utilities installed by ProxMenux have been removed": "Utilitários instalados por ProxMenux foram removidos", + "VA-API driver": "Motorista VA-API", + "VA-API render device": "Dispositivo de renderização VA-API", + "VA-API video acceleration": "Aceleração de vídeo VA-API", "VFIO device IDs removed from /etc/modprobe.d/vfio.conf": "IDs de dispositivos VFIO removidos de /etc/modprobe.d/vfio.conf", "VFIO modules configured in /etc/modules": "Módulos VFIO configurados em /etc/modules", "VFIO modules configured.": "Módulos VFIO configurados.", @@ -4796,7 +6613,9 @@ "VFIO modules removed from /etc/modules": "Módulos VFIO removidos de /etc/modules", "VFIO orphans cleared and initramfs rebuilt — next boot will free the GPU.": "órfãos VFIO limpos e initramfs reconstruídos – a próxima inicialização irá liberar a GPU.", "VFIO orphans cleared but initramfs rebuild failed; check /var/log/proxmenux logs.": "órfãos VFIO eliminados, mas a reconstrução do initramfs falhou;verifique os logs /var/log/proxmenux.", + "VFS cache mode": "Modo de cache VFS", "VLAN": "VLAN", + "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices.": "Mídia VLC O Player é um player multiplataforma multiplataforma gratuito e aberto que oferece desempenho confiável em vários dispositivos.", "VM": "VM", "VM Conflict Policy": "Política de conflitos de VM", "VM ID": "ID da VM", @@ -4824,17 +6643,29 @@ "VM started": "VM iniciada", "VM stopped": "VM parada", "VM:": "VM:", + "VMID (empty = next free)": "VMID (vazio = livre seguinte)", "VMID in use": "VMID em uso", "VMID must be a number.": "VMID deve ser um número.", "VMID of the Borg server LXC on": "VMID do servidor Borg LXC em", + "VMID of the Rclone OCI container": "VMID do recipiente Rclone OCI", "VMs to destroy:": "VMs para destruir:", "VMs, LXCs, network, /etc/pve, users, cron, packages, drivers, ProxMenux state, etc.": "VMs, LXCs, rede, /etc/pve, usuários, cron, pacotes, drivers, estado ProxMenux, etc.", + "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server.": "VS Code é um ambiente de desenvolvimento integrado desenvolvido pela Microsoft. Este recipiente executa o aplicativo de desktop completo, para uma versão nativa da web ver Code Server.", + "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft’s editor VS Code.": "VSCodium é uma distribuição binária baseada na comunidade do editor VS Code da Microsoft.", "Valid backups for all VMs/CTs": "Backups válidos para todas as VMs/CTs", "Validating Proxmox 9 repositories (checking 'proxmox-ve' candidate)...": "Validando repositórios Proxmox 9 (verificando o candidato 'proxmox-ve')...", "Validating credentials with server": "Validando credenciais com servidor", "Validating disk safety...": "Validando a segurança do disco...", + "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)": "Método de validação: http (porta 80 enviada) ou dns (plugin de provedor DNS)", + "Value for": "Valor para", + "Variable name": "Nome da variável", + "Variables": "Variáveis", + "Variables the installation asks for:": "Variáveis que a instalação solicita:", + "Vaultwarden Web Vault": "Vault Web Vaultwarden", "Verbose pool status": "Status detalhado do pool", "Verification": "Verificação", + "Verified": "Verificado", + "Verified by ProxMenux": "Verificado por ProxMenux", "Verify IOMMU group for PCI device": "Verifique o grupo IOMMU para dispositivo PCI", "Verify Options > OS Type — currently set to:": "Verifique Opções > Tipo de SO — atualmente definido como:", "Verify PVE version (must be 8.4.1 or newer):": "Verifique a versão do PVE (deve ser 8.4.1 ou mais recente):", @@ -4850,12 +6681,16 @@ "Verifying Ceph packages availability...": "Verificando a disponibilidade dos pacotes do Ceph...", "Verifying all utilities status": "Verificando o status de todos os utilitários", "Verifying disk accessibility in CT": "Verificando a acessibilidade do disco no CT", + "Verifying the backups...": "Verificando os backups...", + "Verifying the image integrity...": "Verificando a integridade da imagem...", "Version": "Versão", "Version Change Detected": "Alteração de versão detectada", "Version info not available": "Informações da versão não disponíveis", "Version:": "Versão:", "Version: Auto-negotiation (NFSv3/NFSv4)": "Versão: Negociação automática (NFSv3/NFSv4)", "Versions shown belong to maintained NVIDIA branches that list your GPU PCI ID and are new enough to build against the running kernel. DKMS compilation is the final validation. The recommended version keeps the current branch, or uses the NVIDIA Production Branch on a fresh install.": "As versões mostradas pertencem a ramificações NVIDIA mantidas que listam seu ID PCI da GPU e são novas o suficiente para serem construídas no kernel em execução. A compilação DKMS é a validação final. A versão recomendada mantém a ramificação atual ou usa a ramificação de produção NVIDIA em uma nova instalação.", + "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML.": "Aceleração de vídeo e detecção de objetos são escolhas independentes; o instalador não grava câmera ou detector YAML.", + "Video transcoding acceleration": "Aceleração da transcodificação de vídeo", "View CIFS Mounts (pvesm + fstab)": "Ver montagens CIFS (pvesm + fstab)", "View Current Exports": "Ver exportações atuais", "View Current Mounts": "Ver montagens atuais", @@ -4871,6 +6706,7 @@ "View raw VM configuration file": "Ver arquivo de configuração bruto da VM", "View restore plan": "Ver plano de restauração", "View self-test log": "Ver registro de autoteste", + "View status": "Ver o estado", "VirtIO (advanced - high performance)": "VirtIO (avançado - alto desempenho)", "VirtIO ISO not found after selection.": "VirtIO ISO não encontrado após a seleção.", "VirtIO ISO selection cancelled.": "Seleção ISO do VirtIO cancelada.", @@ -4886,10 +6722,19 @@ "Virtual display normalized to vga: std (compatibility)": "Display virtual normalizado para vga: std (compatibilidade)", "Virtual display set to": "Exibição virtual definida como", "Virtual interface (normal)": "Interface virtual (normal)", + "Virtual whiteboard for sketching hand-drawn like diagrams": "Quadro branco virtual para desenhar diagramas desenhados à mão", "Virtualization": "Virtualização", "Visit https://osx-proxmox.com for more information.": "Visite https://osx-proxmox.com para obter mais informações.", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:": "Visite o site para descobrir mais scripts, ficar atualizado com as atualizações mais recentes e apoiar o projeto:", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE": "Visite o site para descobrir mais scripts, ficar atualizado com as atualizações mais recentes e apoiar o projeto:\n\nhttps://community-scripts.github.io/ProxmoxVE", + "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies.": "O Vivaldi é um navegador de web cross-platform norueguês desenvolvido pela Vivaldi Technologies.", + "Volume configuration cancelled": "Configuração do volume cancelada", + "Volume options are not yet supported": "As opções de volume ainda não são suportadas", + "Volume size in GB": "Tamanho do volume em GB", + "Volumes attached": "Volumes anexados", + "Volumes prepared for the first start:": "Volumes preparados para o primeiro início:", + "Volumes shared between services are not yet supported": "Volumes compartilhados entre serviços ainda não são suportados", + "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code.": "Vscodium-web é uma distribuição binária baseada na comunidade do componente web do editor VS Code da Microsoft.", "Vulnerability detection": "Detecção de vulnerabilidade", "WARNING": "AVISO", "WARNING — This backup contains paths that are risky to restore on a running system:": "AVISO — Este backup contém caminhos que são arriscados para restauração em um sistema em execução:", @@ -4912,15 +6757,41 @@ "WARNING: You are about to remove this Proxmox storage:": "AVISO: você está prestes a remover este armazenamento Proxmox:", "WARNING: You are about to remove this disk mount:": "AVISO: você está prestes a remover esta montagem de disco:", "WARNING: this will ERASE EVERYTHING on the disk.": "AVISO: isso APAGARÁ TUDO do disco.", + "WEB UI to manage WireGuard VPN.": "WEB UI para gerenciar WireGuard VPN.", "WILL BE PERMANENTLY ERASED.": "SERÁ APAGADO PERMANENTEMENTE.", + "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency.": "WPS Office é uma suíte de escritório abrangente leve e rica em recursos com alta compatibilidade. Como um software de escritório prático e profissional, WPS Office permite que você edite arquivos em Writer, Apresentação, Planilha e PDF para melhorar sua eficiência de trabalho.", "Wait for each node to complete before starting next": "Aguarde a conclusão de cada nó antes de iniciar o próximo", + "Waiting for Home Assistant OS...": "À espera do SO Home Assistant...", + "Waiting for the FUSE mount:": "À espera da montagem FUSE:", + "Waiting for the application to respond...": "À espera que a aplicação responda...", + "Waiting for the initial Jellyfin configuration...": "À espera da configuração inicial do Jellyfin...", + "Waiting for the network address...": "À espera do endereço da rede...", + "Waiting for the password of the application...": "À espera da senha da aplicação...", + "Waiting for the temporary password...": "À espera da senha temporária...", "Warning": "Aviso", "Warning: Auth key should start with 'tskey-'": "Aviso: a chave de autenticação deve começar com 'tskey-'", "Warning: Disk Images on CIFS": "Aviso: imagens de disco no CIFS", "Warning: Limited PCI Reset Support": "Aviso: suporte limitado para redefinição de PCI", "Warning: both VMs have autostart enabled (onboot=1).": "Aviso: ambas as VMs têm inicialização automática habilitada (onboot=1).", "Warnings": "Avisos", + "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents.": "WeKnora é um framework alimentado por LLM projetado para compreensão de documentos profundos e recuperação semântica, especialmente para lidar complex, documentos heterogêneos.", + "Web UI": "UI Web", + "Web UI 1": "UI Web 1", + "Web UI 2": "UI Web 2", + "Web UI password": "Senha da interface Web", + "Web UI user": "Utilizador de interface Web", + "Web access": "Acesso à Internet", + "Web address of the AdGuard Home that receives the settings (e.g. http://192.168.1.3)": "Endereço Web do AdGuard Home que recebe as definições (por exemplo, http://192.168.1.3)", + "Web address of the main AdGuard Home, whose settings are copied (e.g. http://192.168.1.2)": "Endereço Web do AdGuard Home principal, cujas configurações são copiadas (por exemplo, http://192.168.1.2)", + "Web interface to manage devices running Tasmota firmware.": "Interface Web para gerenciar dispositivos rodando firmware Tasmota.", + "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes).": "WebCord pode ser resumido como um pacote de endurecimentos de segurança e privacidade, recursos de discórdia reimplementações, Electron / Chromium / Erros de discórdia workarounds, stylesheets, páginas internas e página envolto https://discord.com, projetado para se conformar com ToS tanto quanto possível (ou ocultar as alterações que podem violá-lo dos olhos da Discord).", + "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels.": "Webgrabplus é um multi-site incremental xmltv epg grabber. Ele coleta dados de guias de tv-programa de sites selecionados para seus canais favoritos.", + "Webservers & Proxies": "Servidores Web & Proxies", "Website": "Site", + "Webstation is a web native emulation focused LXQt desktop based on Ubuntu.": "Webstation é um ambiente de trabalho LXQt baseado no Ubuntu.", + "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser.": "Webtop - Embalagens baseadas em Alpine, Ubuntu, Fedora e Arch contendo ambientes de desktop completos em sabores oficialmente suportados acessíveis através de qualquer navegador moderno.", + "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent.": "Weixin (WeChat) é uma mensagem instantânea, mídias sociais e aplicativo de pagamento móvel desenvolvido pela Tencent.", + "What cannot be translated:": "O que não pode ser traduzido:", "What do you want to do?": "O que você quer fazer?", "What would you like to do?": "O que você gostaria de fazer?", "When asked to select a disk, click Load Driver and load the VirtIO drivers.": "Quando solicitado a selecionar um disco, clique em Carregar driver e carregue os drivers VirtIO.", @@ -4932,28 +6803,46 @@ "Where do you want to mount the Samba share?": "Onde você deseja montar o compartilhamento do Samba?", "Where is the OVA/OVF file located?": "Onde está localizado o arquivo OVA/OVF?", "Where to mount inside container?": "Onde montar dentro do container?", + "Where to store": "Onde conservar", "While the server allows guest listing, no shares are actually accessible without authentication.": "Embora o servidor permita a listagem de convidados, nenhum compartilhamento é realmente acessível sem autenticação.", + "Wikijs A modern, lightweight and powerful wiki app built on NodeJS.": "Wikijs Um aplicativo wiki moderno, leve e poderoso construído no NodeJS.", "Will be configured now": "Será configurado agora", "Windows Installation Options": "Opções de instalação do Windows", "Windows path:": "Caminho do Windows:", + "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles.": "WineGUI é um gerenciador de vinhos amigável de interface de usuário que fornece uma interface gráfica para a criação e gestão de garrafas de vinho.", "Wipe all — erase partitions + metadata": "Limpe tudo – apague partições + metadados", "Wipe all — remove partitions + metadata": "Limpe tudo – remova partições + metadados", "Wipe old signatures and partition table (DESTRUCTIVE):": "Limpe assinaturas antigas e tabela de partições (DESTRUTIVO):", "Wiping existing partition table...": "Limpando tabela de partição existente...", "Wiping partitions and metadata...": "Limpando partições e metadados...", + "WireGuard Easy web interface": "Interface Web WireGuard Easy", + "WireGuard® is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry.": "WireGuard® é uma VPN extremamente simples, mas rápida e moderna, que utiliza criptografia de última geração. Pretende ser mais rápido, mais simples, mais magro e mais útil do que o IPsec, evitando ao mesmo tempo a enorme dor de cabeça. Pretende ser consideravelmente mais performante do que o OpenVPN. WireGuard é projetado como uma VPN de propósito geral para execução em interfaces incorporadas e super computadores, apto para muitas circunstâncias diferentes. Inicialmente lançado para o kernel Linux, ele agora é multi-plataforma (Windows, macOS, BSD, iOS, Android) e amplamente implantável. Ele está atualmente em desenvolvimento pesado, mas já pode ser considerado como a solução VPN mais segura, mais fácil de usar e mais simples no setor.", "Wired NICs in backup missing on target:": "NICs com fio no backup ausentes no destino:", + "Wireshark is the world’s foremost and widely-used network protocol analyzer. It lets you see what’s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998.": "Wireshark é o principal e amplamente utilizado analisador de protocolos de rede do mundo. Ele permite que você veja o que está acontecendo em sua rede em um nível microscópico e é o padrão de fato (e muitas vezes de jure) em muitas empresas comerciais e sem fins lucrativos, agências governamentais e instituições educacionais. O desenvolvimento do Wireshark prospera graças às contribuições voluntárias de especialistas em redes em todo o mundo e é a continuação de um projeto iniciado por Gerald Combs em 1998.", + "With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopped.": "Com validação dns, as variáveis DNSPLUGIN nomeiam o plugin provedor. A instalação avançada pede; caso contrário, adicione a linha lxc.environment. tempo de execução: DNSPLUGIN= para /etc/pve/lxc/.conf com o recipiente parado.", + "With dns validation, write the provider credentials in /config/dns-conf/.ini inside the container and restart it.": "Com validação dns, escreva o provedor credentials em /config/dns-conf/.ini dentro do recipiente e reinicie-o.", + "With http validation, port 80 of the router must be forwarded to port 80 of this container.": "Com a validação http, a porta 80 do roteador deve ser encaminhada para a porta 80 deste recipiente.", "With warnings": "Com avisos", "Without Function Level Reset (FLR), passthrough is not considered reliable": "Sem a redefinição do nível de função (FLR), o passthrough não é considerado confiável", "Without a usable reset path, passthrough reliability is poor and VM": "Sem um caminho de redefinição utilizável, a confiabilidade da passagem é baixa e a VM", + "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom.": "Wolfenstein: Blade of Agony é um atirador inspirado em Wolfenstein e Doom.", + "Workflow automation tool": "Ferramenta de automação de fluxo de trabalho", "Working directory:": "Diretório de trabalho:", "Works with LVM, ZFS, and BTRFS storage types": "Funciona com tipos de armazenamento LVM, ZFS e BTRFS", + "Worth knowing before installing it:": "Vale a pena saber antes de instalá-lo:", "Would you like to continue in passthrough-only mode? The libedgetpu APT install will be skipped, the Coral device will still be visible inside the container (e.g. /dev/apex_0), and you can install the runtime yourself or use an app container that bundles it (e.g. the Frigate Docker image).": "Gostaria de continuar no modo somente passagem? A instalação do libedgetpu APT será ignorada, o dispositivo Coral ainda estará visível dentro do contêiner (por exemplo, /dev/apex_0) e você mesmo pode instalar o tempo de execução ou usar um contêiner de aplicativo que o agrupe (por exemplo, a imagem Frigate Docker).", "Would you like to see the current": "Você gostaria de ver o atual", "Write access confirmed for user:": "Acesso de gravação confirmado para o usuário:", "Write access confirmed.": "Acesso de gravação confirmado.", "Write access test FAILED for user:": "Teste de acesso de gravação FALHOU para o usuário:", "Write access verified for user:": "Acesso de gravação verificado para o usuário:", + "Write the value it produces instead.": "Escreva o valor que produz.", + "Wrong SHA-256 in": "SHA-256 errado dentro", + "Wrong inherited registry lock": "Bloqueio de registo herdado errado", "Wrong passphrase": "Senha errada", + "Wrong size in": "Tamanho errado em", + "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support.": "Xbackbone é um gerenciador de arquivos PHP simples e leve que suporta a ferramenta de compartilhamento instantâneo ShareX e *NIX systems. Ele suporta upload e exibição de imagens, GIF, vídeo, código, texto formatado, e download de arquivos e upload. Também tem uma interface web com gerenciamento multi usuário, passado uploads histórico e suporte de pesquisa.", + "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS.": "Yaak é um cliente de API desktop para organizar e executar solicitações REST, GraphQL e gRPC. Foi construído usando Tauri, Rust e ReactJS.", "Yes": "Sim", "Yes, upload": "Sim, fazer upload", "Yes: set a recovery passphrase now; the encrypted key envelope is uploaded with every backup.": "Sim: defina uma senha de recuperação agora;o envelope da chave criptografada é carregado com cada backup.", @@ -4984,6 +6873,9 @@ "You should now be able to access the Proxmox web interface.": "Agora você deve conseguir acessar a interface da web do Proxmox.", "You will need a Tailscale auth key from: https://login.tailscale.com/admin/settings/keys": "Você precisará de uma chave de autenticação Tailscale de: https://login.tailscale.com/admin/settings/keys", "Your Coral USB device and its runtime (libedgetpu1) will NOT be affected.": "Seu dispositivo Coral USB e seu tempo de execução (libedgetpu1) NÃO serão afetados.", + "Your machine learning Env work with Jupyter Lab": "O seu Env de aprendizagem de máquina trabalha com o Jupyter Lab", + "Your next YouTube media manager": "Seu próximo gerenciador de mídia do YouTube", + "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics.": "Your_spotify é uma aplicação auto-anfitriã que rastreia o que você ouve e oferece um painel para explorar estatísticas sobre isso! É composto por um servidor web que pesquisa a API do Spotify de vez em quando e uma aplicação web na qual você pode explorar suas estatísticas.", "ZFS ARC config removed (kernel defaults will apply on reboot)": "Configuração do ZFS ARC removida (os padrões do kernel serão aplicados na reinicialização)", "ZFS ARC maximum configured:": "máximo do ZFS ARC configurado:", "ZFS ARC optimization completed": "Otimização ZFS ARC concluída", @@ -5011,9 +6903,17 @@ "ZFS storage added successfully to Proxmox!": "Armazenamento ZFS adicionado com sucesso ao Proxmox!", "ZFS tools not found. Install zfsutils-linux and retry.": "Ferramentas ZFS não encontradas. Instale zfsutils-linux e tente novamente.", "ZFS:": "ZFS:", + "ZNC web interface": "Interface Web ZNC", + "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design.": "Zen Browser é um fork livre e de código aberto da Mozilla Firefox com foco em privacidade, personalização e design.", "Zero all data — partition table preserved, data wiped": "Zerar todos os dados – tabela de partição preservada, dados apagados", "Zero all data — partition table preserved": "Zerar todos os dados – tabela de partição preservada", "Zeroing partition": "Zerando partição", + "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC.": "Znc é um segurança de rede IRC ou BNC. Ele pode desconectar o cliente do servidor IRC real, e também de canais selecionados. Vários clientes de diferentes locais podem se conectar a uma única conta ZNC simultaneamente e, portanto, aparecer sob o mesmo apelido no IRC.", + "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research.": "Zotero é uma ferramenta gratuita e fácil de usar para ajudá-lo a coletar, organizar, anotar, citar e compartilhar pesquisas.", + "a device it asks for cannot be translated:": "um dispositivo que solicita não pode ser traduzido:", + "a value is required": "um valor é required", + "aMule WebUI (password only, no username)": "aMule WebUI (somente senha, sem nome de utilizador)", + "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule.": "aMule é um cliente multi-plataforma para a rede de compartilhamento de arquivos ED2K e baseado no eMule cliente Windows. aMule começou em agosto de 2003, como um fork de xMule, que é um fork de lMule.", "active VF(s)": "FV ativa(s)", "active VFs": "FVs ativas", "active Virtual Functions. Changing its driver binding would destroy every VF.": "Funções virtuais ativas. Alterar a ligação do driver destruiria todos os VF.", @@ -5035,20 +6935,24 @@ "apex group still has members; left in place:": "o grupo apex ainda tem membros; deixado no lugar:", "apex kernel module not loaded on host. Run \"Install Coral on Host\" first or the container will not see /dev/apex_0.": "módulo do kernel apex não carregado no host. Execute \"Install Coral on Host\" primeiro ou o contêiner não verá /dev/apex_0.", "appears to be part of a": "parece fazer parte de um", + "apply requires the OCI archive of the resolved image": "aplicar o requires no arquivo OCI da imagem resolvida", "applying minimal banner patch": "aplicando patch mínimo de banner", "apt cache refreshed.": "cache do apt atualizado.", "apt-get exited": "apt-get saiu", "apt-get update returned warnings. Continuing anyway; check": "apt-get update retornou avisos. Continuando de qualquer maneira; verificar", "as": "como", + "assembling": "montagem", "automatically. Install it manually inside the container.": "automaticamente. Instale-o manualmente dentro do contêiner.", "automatically. Reboot LXC to fully release.": "automaticamente. Reinicie o LXC para liberar completamente.", "available for LXC bind-mounts via 'LXC Mount Manager'": "disponível para montagens vinculadas LXC via 'LXC Mount Manager'", "available in this same GPU and TPU menu.": "disponível neste mesmo menu GPU e TPU.", "backup at /etc/fstab.proxmenux.bak": "backup em /etc/fstab.proxmenux.bak", "ban": "proibir", + "belongs to another OCI installation": "pertence a outra instalação OCI", "blocking issue(s).": "problema(s) de bloqueio.", "btrfs — Proxmox dir storage (snapshots, compression)": "btrfs — Armazenamento de diretório Proxmox (instantâneos, compactação)", "btrfs — snapshots and compression": "btrfs — instantâneos e compactação", + "budge is an open source 'budgeting with envelopes' personal finance app.": "budge é um aplicativo de finanças pessoais de código aberto 'budge com envelopes'.", "builds against kernel": "compilações contra o kernel", "but it does not match the one used to create the backup. Replace it with the correct keyfile from the source host and retry.": "Mensagem técnica para Proxmox e TI.Traduza: mas não corresponde ao usado para criar o backup. Substitua-o pelo arquivo-chave correto do host de origem e tente novamente.", "bytes": "bytes", @@ -5056,29 +6960,52 @@ "chmod 1777 + setfacl o::rwx (applied on the NFS share from this host)": "chmod 1777 + setfacl o::rwx (aplicado no compartilhamento NFS deste host)", "chmod failed — NFS server may be restricting changes from root": "chmod falhou — O servidor NFS pode estar restringindo alterações do root", "chown/chmod failed — likely unprivileged CT against host bind mount. Falling back to ACL.": "chown/chmod falhou — provavelmente CT sem privilégios contra montagem de ligação do host. Voltando ao ACL.", + "containers": "recipientes", + "containers of": "Contentores de", "content:": "contente:", + "copyparty web interface": "Interface Web copyparty", "could not be compiled for kernel": "não foi possível compilar para o kernel", + "could not validate NVIDIA; exit code": "não foi possível validar o NVIDIA; código de saída", + "cpuunits must be between 8 and 10000": "cpuunidades devem estar entre 8 e 10000", + "custom": "personalizado", + "custom dependency commands are not yet supported": "comandos de dependência personalizados ainda não são suportados", + "custom path(s) saved.": "caminhos personalizados salvos.", + "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them.": "darktable é um aplicativo de fluxo de trabalho de fotografia de código aberto e desenvolvedor bruto. Um lighttable virtual e quarto escuro para fotógrafos. Ele gerencia seus negativos digitais em um banco de dados, permite que você os visualize através de um lighttable zoomable e permite que você desenvolva imagens brutas e melhore-os.", + "ddclient starts with the example configuration and updates nothing yet. Write your provider, login and domains in /config/ddclient.conf inside the container, then restart it.": "ddclient começa com a configuração de exemplo e ainda não atualiza nada. Escreva o seu provedor, login e domínios em /config/ddclient.conf dentro do recipiente, em seguida, reinicie-o.", "default": "padrão", "delete the credentials file (if any)": "exclua o arquivo de credenciais (se houver)", "delete the matching line from /etc/fstab": "exclua a linha correspondente de /etc/fstab", "descriptor + VMDK files": "descritor + arquivos VMDK", + "device(s) added to VM": "dispositivos adicionados à VM", "devices": "dispositivos", + "devices (dynamic runtime)": "dispositivos (tempo de execução dinâmico)", "did not become ready. Skipping.": "não ficou pronto. Pulando.", + "digiKam: Professional Photo Management with the Power of Open Source": "digiKam: Gestão Fotográfica Profissional com o Poder de Código Aberto", "disk(s) added to CT": "disco(s) adicionado(s) ao CT", "disk(s) added to VM": "disco(s) adicionado(s) à VM", + "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems.": "diskover é um indexador de sistema de arquivos de código aberto que usa a Elasticsearch para indexar e gerenciar dados em sistemas de armazenamento heterogêneos.", "disks present": "discos presentes", "dkms autoinstall did not activate:": "a instalação automática do dkms não foi ativada:", "dkms.conf generated.": "dkms.conf gerado.", + "docker run command": "Comando de execução do docker", + "docker run command of the application": "docker executar o comando da aplicação", "does not exist on this host. Path not added.": "não existe neste host. Caminho não adicionado.", "does not exist. Exiting.": "não existe. Saindo.", + "doplarr_rs starts from the example configuration and connects to nothing. Write the token of your Discord bot in discord_token in /config/config.toml inside the container.": "doplarr_rs começa a partir da configuração do exemplo e se conecta a nada. Escreva o token do seu bot Discord em discord token em /config/config.toml dentro do recipiente.", + "downloaded Compose file": "arquivo Compose baixado", "dpkg still reports unfinished package work; review": "dpkg ainda relata trabalho de pacote inacabado;análise", + "driver components": "componentes do condutor", "driver:": "driver:", + "e.g.": "Por exemplo:", + "empty = generate": "vazio = gerar", "exFAT (portable: Windows/Linux/macOS)": "exFAT (portátil: Windows/Linux/macOS)", "exFAT tools installed successfully.": "Ferramentas exFAT instaladas com sucesso.", "ext4 — Proxmox dir storage (recommended)": "ext4 — Armazenamento de diretório Proxmox (recomendado)", "ext4 — recommended, most compatible": "ext4 — recomendado, mais compatível", "fail2ban-client could not communicate with the server": "fail2ban-client não conseguiu se comunicar com o servidor", "fail2ban-client successfully communicated with the server": "fail2ban-client se comunicou com sucesso com o servidor", + "failed": "falhou", + "failed with exit code": "falhou com o código de saída", "failed:": "fracassado:", "feranick fork unreachable. Falling back to google/gasket-driver...": "O fork feranick está inacessível. A usar google/gasket-driver como alternativa...", "feranick/gasket-driver cloned (actively maintained, kernel 6.12+ ready).": "feranick/gasket-driver clonado (mantido ativamente, kernel 6.12+ pronto).", @@ -5092,6 +7019,7 @@ "for this policy and may fail after first use or on subsequent VM starts.": "para esta política e pode falhar após o primeiro uso ou em inícios subsequentes da VM.", "formatted as": "formatado como", "found": "encontrado", + "free": "livre", "from Proxmox web interface (you will be asked)": "da interface da web do Proxmox (será solicitado)", "from container": "do contêiner", "from the GPUs and Coral-TPU menu first, then run this option again.": "primeiro no menu GPUs e Coral-TPU e, em seguida, execute esta opção novamente.", @@ -5109,10 +7037,14 @@ "has a different MAC than the backup — update any DHCP static reservation": "tem um MAC diferente do backup – atualize qualquer reserva estática de DHCP", "has a new MAC": "tem um novo MAC", "has only": "tem apenas", + "health and persistence profile not yet defined": "perfil de saúde e persistência ainda não definido", + "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers.": "hiSHtory é uma história melhor. Ele armazena seu histórico de shell no contexto (em que diretório você executou o comando, se ele foi bem sucedido ou falhou, quanto tempo levou, etc). Isto é tudo armazenado localmente e de ponta a ponta criptografado para sincronização para todos os seus outros computadores.", + "host directory": "pasta da máquina", "host fstab only (not registered as Proxmox storage)": "host fstab apenas (não registrado como armazenamento Proxmox)", "hostpci entries for all IOMMU group devices": "entradas hostpci para todos os dispositivos do grupo IOMMU", "hostpci entries for selected GPU functions (full IOMMU group will be enforced after reboot)": "entradas hostpci para funções GPU selecionadas (o grupo IOMMU completo será aplicado após a reinicialização)", "hour(s)": "horas)", + "https if the image serves TLS": "https se a imagem serve TLS", "iSCSI Content Type": "Tipo de conteúdo iSCSI", "iSCSI Daemon (iscsid): RUNNING": "Daemon iSCSI (iscsid): EM EXECUÇÃO", "iSCSI Daemon (iscsid): STOPPED": "Daemon iSCSI (iscsid): PARADO", @@ -5129,16 +7061,23 @@ "iSCSI storage provides raw block devices for VM disk images.": "O armazenamento iSCSI fornece dispositivos de bloco brutos para imagens de disco de VM.", "iSCSI tools installed": "Ferramentas iSCSI instaladas", "iftop usage": "uso iftop", + "image cache on": "'cache' de imagens ligado", + "image itself": "imagem em si", "imported:": "importado:", "in CT": "em tomografia computadorizada", + "in backups": "em backups", + "incompatible qBittorrent schema": "esquema de qBittorrent incompatível", + "individual template is blocked": "o modelo individual está bloqueado", "initramfs updated": "initramfs atualizado", "initramfs updated.": "initramfs atualizado.", + "installed": "instalado", "installed but command not immediately available": "instalado, mas o comando não está imediatamente disponível", "installed correctly and available": "instalado corretamente e disponível", "installed in CT": "instalado em CT", "installed inside CT": "instalado dentro do CT", "installed successfully.": "instalado com sucesso.", "installed.": "instalado.", + "installing": "instalar", "intel-gpu-tools installed successfully": "ferramentas intel-gpu instaladas com sucesso", "intel-gpu-tools is already installed:": "intel-gpu-tools já está instalado:", "intel-gpu-tools is up to date": "intel-gpu-tools está atualizado", @@ -5169,7 +7108,11 @@ "is not configured as machine type q35.": "não está configurado como tipo de máquina q35.", "is not in the patch.sh supported list. The patch may no-op or fail; review keylase/nvidia-patch README before continuing.": "não está na lista de suporte do patch.sh. O patch pode não funcionar ou falhar; revise o README keylase/nvidia-patch antes de continuar.", "is not supported by the official Google libedgetpu APT repository.": "não é compatível com o repositório APT oficial do Google libedgetpu.", + "is one of the": "é um dos", "is referenced in the following stopped VM(s)/CT(s):": "é referenciado nas seguintes VM(s)/CT(s) interrompidas:", + "it asks for the network of the host; the container gets its own address instead": "ele pede a rede do host; o recipiente recebe seu próprio endereço", + "it publishes no other architecture": "não publica nenhuma outra arquitetura", + "it uses the Compose option": "usa a opção Compose", "journald MaxLevelStore is adequate for auth logging": "journald MaxLevelStore é adequado para registro de autenticação", "journald drop-in created: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf": "Drop-in do journald criado: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf", "journald log level restored": "nível de log do journald restaurado", @@ -5193,26 +7136,41 @@ "kexec-tools installed successfully": "kexec-tools instalado com sucesso", "kexec-tools is already installed": "kexec-tools já está instalado", "kexec-tools is not installed or already removed.": "kexec-tools não está instalado ou já foi removido.", + "layers": "camadas", "legacy .link file(s) to the ProxMenux-managed format": "arquivo(s) .link herdado(s) para o formato gerenciado pelo ProxMenux", "log2ram completely removed from system": "log2ram completamente removido do sistema", "manually inside the container before starting it.": "manualmente dentro do contêiner antes de iniciá-lo.", "manually inside the container.": "manualmente dentro do contêiner.", "maximum performance": "desempenho máximo", "may be closed — trying discovery anyway...": "pode estar fechado - tentando a descoberta de qualquer maneira...", + "melonDS aims at providing fast and accurate Nintendo DS emulation.": "melonDS visa fornecer emulação rápida e accurate Nintendo DS.", + "members:": "membros:", + "minimum": "mínimo", "missing": "faltando", "mkfs.btrfs not found. Install btrfs-progs and retry.": "mkfs.btrfs não encontrado. Instale o btrfs-progs e tente novamente.", "more": "mais", + "motionEye web interface": "Interface Web motionEye", "mount.cifs command not found after installation.": "Comando mount.cifs não encontrado após a instalação.", "mount.nfs command not found after installation.": "Comando mount.nfs não encontrado após a instalação.", + "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone.": "mstream é um servidor de streaming de música pessoal. Você pode usar o mStream para transmitir sua música do seu computador doméstico para qualquer dispositivo, em qualquer lugar. Existem aplicativos móveis disponíveis para Android e iPhone.", + "must contain a valid numeric UID for the GPU": "deve conter um UID numérico válido para a GPU", + "needed": "necessário", + "needs a privileged LXC": "precisa de um LXC privilegiado", + "needs a relaxed AppArmor or seccomp profile": "precisa de um perfil de AppArmor ou seccomp relaxado", + "needs stack review": "precisa de revisão da pilha", "never": "nunca", + "next free": "livre seguinte", + "next free block": "próximo bloco livre", "nftables not available - using iptables ban action": "nftables não disponível - usando a ação de proibição do iptables", "no": "não", "no (kdf=none, not needed)": "não (kdf = nenhum, não é necessário)", "no (no escrow blob — set a recovery passphrase to enable recovery)": "não (sem blob de garantia – defina uma senha de recuperação para permitir a recuperação)", + "no declarative value": "sem valor declarativo", "no passphrase": "sem senha", "no password": "sem senha", "no_root_squash": "sem_root_squash", "non-ProxMenux .tar archive(s) in this path": "arquivo(s) .tar não-ProxMenux neste caminho", + "not available yet": "não disponível ainda", "not found.": "não encontrado.", "not installed": "não instalado", "not reliable on this hardware due to the following limitations": "não é confiável neste hardware devido às seguintes limitações", @@ -5229,27 +7187,39 @@ "of free disk space.": "de espaço livre em disco.", "older firmware may increase passthrough instability": "firmware mais antigo pode aumentar a instabilidade de passagem", "oldest driver offered:": "driver mais antigo oferecido:", + "on": "ligado", "on SSD/NVMe pools that support discard": "em pools SSD/NVMe que suportam descarte", + "one of its services declares no image": "um de seus serviços declara nenhuma imagem", + "one of its services is not written as a service": "um dos seus serviços não é escrito como serviço", "openssl encryption failed.": "A criptografia do openssl falhou.", "openssl is not installed — cannot create recovery copy. Install openssl and retry.": "openssl não está instalado — não é possível criar uma cópia de recuperação. Instale o openssl e tente novamente.", + "optional": "opcional", + "optional dependencies are not yet supported": "dependências opcionais ainda não são suportadas", "or format it manually using external tools.": "ou formate-o manualmente usando ferramentas externas.", + "or none": "ou nenhum", "or use the ProxMenux LXC Mount Manager.": "ou use o ProxMenux LXC Mount Manager.", "orphan iface lines, no impact on restore": "linhas iface órfãs, sem impacto na restauração", "other .tar archive(s) — not ProxMenux host backups (e.g. PVE vzdump or unrelated tarballs).": "outros arquivos .tar — não backups de host ProxMenux (por exemplo, PVE vzdump ou tarballs não relacionados).", "packages (this may take a few minutes)...": "pacotes (isso pode levar alguns minutos)...", + "packages.": "pacotes.", "parent PF:": "pai PF:", "partition(s). Partition table preserved.": "partição(ões). Tabela de partição preservada.", + "pasted Compose file": "arquivo Compose colado", "paths for next boot (/etc/pve, guests, drivers, ...)": "caminhos para a próxima inicialização (/etc/pve, convidados, drivers, ...)", "pct exec authorization failed": "falha na autorização pct exec", "pct push failed. Check log:": "pct push falhou. Verifique o registro:", "pending (reboot required to enumerate full group)": "pendente (reinicialização necessária para enumerar o grupo completo)", + "phpMyAdmin is installed with arbitrary server connections enabled: the login page has a Server field where the address of the MySQL or MariaDB server is entered, together with its user and password.": "phpMyAdmin é instalado com conexões de servidor arbitrárias habilitadas: a página de login tem um campo de servidor onde o endereço do servidor MySQL ou MariaDB é inserido, juntamente com seu usuário e senha.", "pigz configuration completed": "configuração do pigz concluída", "pigz enabled in vzdump configuration": "pigz habilitado na configuração do vzdump", "pigz installed successfully": "pigz instalado com sucesso", "pigz removed": "porco removido", "pigz wrapper script created": "script de wrapper pigz criado", + "playit.gg has to claim this agent before it forwards anything. The agent prints a one-time claim link on the container console and keeps it there until the link is opened.": "playit.gg tem que reivindicar este agente antes que ele avance com qualquer coisa. O agente imprime um link de reivindicação única no console do contêiner e o mantém lá até que o link seja aberto.", "port": "porta", "portmapper/rpcbind has been disabled": "portmapper/rpcbind foi desativado", + "private network assigned automatically": "rede privada atribuída automaticamente", + "privileged LXC": "LXC privilegiado", "proxmox-backup-client reported:": "proxmox-backup-client relatado:", "proxmox-boot-tool refreshed": "ferramenta proxmox-boot atualizada", "pve-enterprise.list update skipped (no change)": "Atualização de pve-enterprise.list ignorada (sem alteração)", @@ -5261,10 +7231,22 @@ "pvesm not found.": "pvesm não encontrado.", "pvesm path failed, trying manual detection...": "caminho pvesm falhou, tentando detecção manual...", "pvesm status failed": "status pvesm falhou", + "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web.": "pyLoad é um gerenciador de download livre e Open Source escrito em Python e projetado para ser extremamente leve, facilmente extensível e totalmente gerenciável via web.", + "pyLoad web interface": "interface web pyLoad", + "qBittorrent WebUI password (user: admin)": "Senha do WebUI do qBittorrent (utilizador: administrador)", + "qBittorrent already has a configuration; it is not overwritten": "O qBittorrent já tem uma configuração; não é sobrescrito", + "qBittorrent configured": "qBittorrent configurado", + "qBittorrent did not apply the category:": "qBittorrent não aplicava a categoria:", + "qBittorrent did not apply the download paths": "qBittorrent não aplicaram os caminhos de transferência", + "qBittorrent requires a non-empty password": "qBittorrent requires uma senha não vazia", + "qBittorrent: authenticated access to the preferences could not be verified": "qBittorrent: não foi possível verificar o acesso autenticado às preferências", + "qBittorrent: invalid login response or missing session cookie": "qBittorrent: resposta de login inválida ou cookie de sessão ausente", "raw USB disk — no filesystem (will be FORMATTED)": "disco USB bruto - sem sistema de arquivos (será FORMATADO)", + "read-only": "somente leitura", "reboot-quick alias added": "alias de reinicialização rápida adicionado", "reboot-quick alias is already configured": "o alias de reinicialização rápida já está configurado", "recommended": "recomendado", + "recovering": "recuperação", "remapped users": "usuários remapeados", "remove the (now-empty) directory if possible": "remova o diretório (agora vazio), se possível", "removed from Proxmox": "removido do Proxmox", @@ -5280,11 +7262,14 @@ "rpcbind could not be disabled completely": "rpcbind não pôde ser desativado completamente", "rpcbind service and socket have been disabled and stopped": "o serviço rpcbind e o soquete foram desativados e parados", "rpcbind units were not found; no changes were made": "unidades rpcbind não foram encontradas;nenhuma alteração foi feita", + "rsnapshot starts with the default configuration, which backs up /data into /.snapshots. Edit /config/rsnapshot.conf inside the container to set your own backup points, snapshot root and retention intervals.": "rsnapshot começa com a configuração padrão, que faz backup /data em /.snapshots. Edit /config/rsnapshot.conf dentro do recipiente para definir seus próprios pontos de backup, instantâneo raiz e intervalos de retenção.", "running": "correndo", + "runs in": "corre para dentro", "safe paths now (configs, packages, /etc, /root, ...)": "caminhos seguros agora (configs, pacotes, /etc, /root, ...)", "same MAC": "mesmo MAC", "seconds (default)": "segundos (padrão)", "see log:": "veja o log:", + "selected by default": "selecionado por padrão", "selected path(s):": "caminho(s) selecionado(s):", "server": "servidor", "server IP or hostname:": "IP do servidor ou nome do host:", @@ -5292,6 +7277,7 @@ "servers found on the network.": "servidores encontrados na rede.", "servers found.": "servidores encontrados.", "sha256sum not found. Cannot verify Borg binary.": "sha256sum não encontrado. Não é possível verificar o binário Borg.", + "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++.": "shadPS4 é um emulador para Windows, Linux e macOS escrito em C++.", "showmount command is not working properly.": "O comando showmount não está funcionando corretamente.", "showmount command not found after installation.": "Comando showmount não encontrado após a instalação.", "single portable archive": "arquivo portátil único", @@ -5307,6 +7293,7 @@ "started successfully.": "iniciado com sucesso.", "started.": "iniciado.", "startup/restart errors are likely.": "erros de inicialização/reinicialização são prováveis.", + "staticfiles volume size in GB": "tamanho do volume de ficheiros estáticos em GB", "stop source VM first": "pare a VM de origem primeiro", "stopped": "parou", "storage yet.": "armazenamento ainda.", @@ -5316,9 +7303,16 @@ "suggested:": "sugerido:", "switch_gpu_mode.sh was not found.": "switch_gpu_mode.sh não foi encontrado.", "sysfs ROM dump failed — trying ACPI VFCT table...": "Falha no despejo de ROM do sysfs - tentando tabela ACPI VFCT...", + "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools.": "o syslog-ng permite coletar, analisar, classificar, reescrever e correlacionar logs de toda sua infraestrutura e armazená-los ou roteá-los para ferramentas de análise de log.", "systemctl restart networking failed:": "falha na reinicialização da rede do systemctl:", "systemd OnCalendar expression": "Expressão Systemd OnCalendar", + "the API key was not generated on the first start": "a tecla API não foi gerada no primeiro início", + "the container has its own address, so the port Docker published on the host is not needed": "o recipiente tem seu próprio endereço, então a porta Docker publicada no host não é necessária", + "the qBittorrent schema is not available": "o esquema qBittorrent não está disponível", + "this configuration needs the device": "esta configuração necessita do dispositivo", "this distribution": "esta distribuição", + "tmpfs size in MB for": "tamanho tmpfs em MB para", + "tmpfs size too small for": "tamanho tmpfs demasiado pequeno para", "to": "para", "to CT": "para TC", "to VM": "para VM", @@ -5327,6 +7321,12 @@ "to sharedfiles group": "para o grupo de arquivos compartilhados", "total": "total", "umount the path if currently mounted": "desmontar o caminho se estiver montado atualmente", + "unprivileged LXC": "LXC sem privilégios", + "unsupported credential generator": "gerador credential não suportado", + "unsupported dependency condition": "condição de dependência não suportada", + "unsupported external credential or boolean": "credential ou booleano não suportado", + "unsupported variable": "variável não suportada", + "updating": "atualização", "updating NVIDIA userspace libs": "atualizando bibliotecas de espaço de usuário NVIDIA", "user packages missing — will be installed automatically:": "pacotes de usuário ausentes — serão instalados automaticamente:", "users": "Usuários", @@ -5337,12 +7337,19 @@ "vfio-pci IDs configured": "IDs vfio-pci configurados", "vfio-pci IDs in /etc/modprobe.d/vfio.conf": "IDs vfio-pci em /etc/modprobe.d/vfio.conf", "vzdump backup speed optimization completed": "otimização da velocidade de backup do vzdump concluída", + "wallabag builds its links from the address given during the installation. If it does not match the address of the container, edit lxc.environment.runtime: SYMFONY__ENV__DOMAIN_NAME in /etc/pve/lxc/.conf with the container stopped, and start it again.": "wallabag constrói seus links a partir do endereço fornecido durante a instalação. Se não corresponder ao endereço do recipiente, edite lxc.environment. tempo de execução: SYMFONY ENV DOMAIN NAME em /etc/pve/lxc/.conf com o recipiente parado, e inicie-o novamente.", + "wallabag listens on port 80 of the container and stores its data in SQLite.": "wallabag escuta na porta 80 do recipiente e armazena seus dados em SQLite.", + "wallabag web interface": "Interface Web wallabag", "was": "era", "was installed, but the kernel reports:": "foi instalado, mas o kernel informa:", + "when finished": "quando terminado", "will rebind the GPU to vfio-pci on the next reboot, breaking the driver that is about to be installed.": "irá religar a GPU ao vfio-pci na próxima reinicialização, quebrando o driver que está prestes a ser instalado.", "wipefs failed on": "Wipefs falhou em", "with": "com", + "with Proxmox": "com Proxmox", + "with prefix, e.g.": "com prefixo, por exemplo.", "with the password you provided.": "com a senha que você forneceu.", + "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems.": "xemu é um aplicativo livre e de código aberto que emula o console original do jogo Microsoft Xbox, permitindo que as pessoas joguem seus jogos originais Xbox em sistemas Windows, macOS e Linux.", "xfs — Proxmox dir storage (large files and VMs)": "xfs — Armazenamento em diretório Proxmox (arquivos grandes e VMs)", "xfs — better for large files": "xfs — melhor para arquivos grandes", "years old": "anos", diff --git a/lang/sk.json b/lang/sk.json index dba25c9a..17fdb783 100644 --- a/lang/sk.json +++ b/lang/sk.json @@ -7,6 +7,7 @@ "(common default on Debian/LXC: PermitRootLogin prohibit-password).": "(bežné predvolené nastavenie na Debian/LXC: PermitRootLogin prohibit-password).", "(disabled)": "(vypnuté)", "(e.g.": "(napr.", + "(empty)": "(prázdne)", "(for unprivileged LXCs)": "(pre neprivilegované LXC)", "(if only privileged LXCs need write access)": "(ak zápis potrebujú iba privilegované LXC)", "(make.log not found — DKMS may have failed before invoking make)": "(make.log sa nenašiel - DKMS mohlo zlyhať ešte pred spustením make)", @@ -19,6 +20,7 @@ "(recommended)": "(odporúčané)", "(same MAC — restored config adjusted automatically)": "(rovnaká MAC - obnovené nastavenie bolo upravené automaticky)", ")": ")", + "*Arr Suite": "*Arr Suite", "+ Add a path": "+ Pridať cestu", "+ Add new Borg target": "+ Pridať nový Borg cieľ", "+ Add new PBS manually": "+ Pridať nové PBS ručne", @@ -35,39 +37,101 @@ "/var/lib/vz/dump (Proxmox default)": "/var/lib/vz/dump (predvolené v Proxmoxe)", "1777 = sticky bit + rwx for all. No shared group needed.": "1777 = sticky bit + rwx pre všetkých. Zdieľaná skupina nie je potrebná.", "====== PVE UPDATE COMPLETED ======": "====== AKTUALIZÁCIA PVE DOKONČENÁ ======", + "A GTK Broadway web UI for libvirt and virt-manager.": "GTK Broadway web UI pre libvirt a virt-manager.", + "A Personal Relationship Management tool to help you document your social life.": "Osobný vzťah Nástroj riadenia, ktorý vám pomôže zdokumentovať váš spoločenský život.", "A VirtIO ISO already exists. Do you want to overwrite it?": "VirtIO ISO už existuje. Chcete ho prepísať?", "A ZFS pool with this name already exists.": "ZFS pool s týmto názvom už existuje.", "A ZFS pool with this name already exists:": "ZFS pool s týmto názvom už existuje:", + "A backup was modified": "Posily boli upravené", + "A command did not finish in time:": "Príkaz neskončil včas:", "A complete restore will:": "Úplná obnova vykoná:", + "A concurrent change was detected; the container is not removed": "Bola zistená súbežná zmena; obal sa neodstraňuje", + "A container mount has a source, backup or permission different from the saved record": "Montáž kontajnera má zdroj, zálohu alebo povolenie odlišné od uloženého záznamu", + "A coordinated operation is pending. The whole previous stack will be recovered, not only the selected member. If the operation already finished, the cleanup of its markers is completed.": "Koordinovaná operation čaká. Celý predchádzajúci stack bude obnovený, nielen vybraný člen. Ak už operation skončil, vyčistenie jeho markerov je ukončené.", + "A different host monitor include already exists; it is not overwritten:": "Iný hostiteľský monitor už existuje; nie je prepísaný:", + "A fancy monitoring tool": "Nádherný monitorovací nástroj", + "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata.": "zadarmo a open-source cross-platform dokument-orientovaný databázový program. Utajené ako NoSQL databázový program, MongoDB používa JSON-like dokumenty so schémou.", + "A free reverse proxy for tunneling services (not self-hosted).": "Voľný spätný proxy pre tunelovanie služby (nie je self-hosted).", + "A free, self-hostable news aggregator…": "Slobodný agregácia správ...", + "A full-featured, open-source AI chat interface": "Full-featured, open-source AI chat rozhranie", "A gasket DKMS registration is still present:": "Stále existuje registrácia gasket DKMS:", + "A host bind mount cannot be included in vzdump": "Pripojenie hostiteľa nemôže byť súčasťou vzdumpu", + "A host mount is not part of the journal; recovery blocked": "@ info: tooltip", "A host reboot is required after this change.": "Po tejto zmene je potrebný reštart hosta.", "A host reboot is required before starting the VM. Reboot now?": "Pred spustením VM je potrebný reštart servera. Reštartovať teraz?", "A job with this ID already exists.": "Úloha s týmto ID už existuje.", + "A journal already exists; review or recover it before trying again": "Časopis už existuje; recenzia alebo obnoviť pred pokusom opäť", "A keyfile is installed at:": "Keyfile je nainštalovaný v:", "A legacy gasket-dkms package was found on this host, but no Coral M.2 / PCIe hardware is present.": "Na tomto hostiteľovi sa našiel starý balík gasket-dkms, ale nie je prítomný žiadny hardvér Coral M.2 / PCIe.", + "A managed rootfs and an unprivileged container are required": "Riadené rootfs a neprivilegovaný kontajner sú required", + "A managed volume with backup enabled is required": "Riadený objem so zapnutou zálohou je required", + "A member VMID is in use by another guest or is on another node": "Člen VMID používa iný hosť alebo je na inom uzle", + "A member configuration changed after the stack was checked": "Konfigurácia člena sa zmenila po kontrole zásobníka", + "A member configuration changed during the preparation": "Konfigurácia člena sa počas prípravy zmenila", + "A member did not pass its service check:": "Člen neprešiel servisnou kontrolou:", + "A member has a pending operation": "Člen čaká na operation", + "A member has no reproducible service check": "Člen nemá reprodukovateľnú servisnú kontrolu", + "A member is missing before the replacement": "Člen je nezvestný pred nahradením", + "A member operation does not belong to the stack": "Člen operation nepatrí do stohu", + "A member stopped:": "Člen zastavil:", + "A member was modified after it was recovered": "Člen bol zmenený po tom, čo bol obnovený", + "A modern wiki and knowledge base for teams": "Moderná wiki a vedomostná základňa pre tímy", "A new ProxMenux version is available:": "Je dostupná nová verzia ProxMenux:", "A new kernel is staged for the next boot:": "Na najbližší štart je pripravený nový kernel:", "A newer version is available:": "Je dostupná novšia verzia:", + "A pending operation exists for": "Čaká na operation existuje", + "A pending stack assembly already exists; it is not overwritten": "Nevyriešená zostava stohov už existuje; nie je prepísaná", + "A previous NVIDIA refresh is pending review": "Predchádzajúce obnovovanie NVIDIA čaká na preskúmanie", "A previous VFIO passthrough configuration was detected for the following NVIDIA GPU(s):": "Pre nasledujúce GPU NVIDIA bola zistená predchádzajúca konfigurácia priechodu VFIO:", + "A privacy-first, open-source platform for knowledge management and collaboration.": "Platforma pre riadenie znalostí a spoluprácu na prvom mieste ochrany súkromia s otvoreným zdrojom.", "A reboot is recommended before the GPU is guaranteed to stay on the native driver.": "Pred zaručením, že GPU zostane na natívnom ovládači, sa odporúča reštartovať.", "A reboot is required after installation to load the new kernel modules.": "Po inštalácii je potrebný reštart, aby sa načítali nové kernel moduly.", "A reboot is required for VFIO binding to take effect. Do you want to restart now?": "Na uplatnenie VFIO naviazania je potrebný reštart. Chcete reštartovať teraz?", "A reboot is required to apply the new GPU mode. Do you want to restart now?": "Na použitie nového režimu GPU je potrebný reštart. Chcete reštartovať teraz?", "A reboot is required to finish the restore.": "Na dokončenie obnovy je potrebný reštart.", "A reboot will be required to complete the restore.": "Na dokončenie obnovy bude potrebný reštart.", + "A reproducible native startup is missing": "Chýba reprodukovateľný prirodzený štart", + "A rootfs adaptation is stored in persistent storage": "Adaptácia korienkov sa skladuje v trvalom sklade", + "A self-hosted Bitwarden server": "Self-hosted Bitwarden server", + "A self-hosted, goal-free habit tracking tool.": "Sebestačný, bezcieľový nástroj na sledovanie zvyku.", + "A self-improving AI agent with memory, skills, messaging, and a web dashboard.": "Self-zlepšenie AI agenta s pamäťou, zručnosti, správy, a webová palubná doska.", "A server reboot is recommended for all changes to take full effect.": "Odporúča sa reštart servera, aby sa všetky zmeny naplno prejavili.", + "A shared directory was replaced during the installation": "Počas inštalácie bol vymenený zdieľaný adresár", + "A shared source does not match its recorded identity": "Spoločný zdroj nezodpovedá jeho zaznamenanej identite", + "A simple, open-source file sharing host.": "Jednoduchý, open-source súbor zdieľanie hostiteľa.", + "A simple, private file server.": "Jednoduchý súkromný súborový server.", + "A single matching image platform cannot be resolved": "Jedinú zodpovedajúcu obrazovú platformu nie je možné vyriešiť", + "A single-platform OCI archive is required": "Jednoplatformový OCI archív je required", + "A stack backup is missing; a partial restore is not allowed": "Chýba záloha stohu; čiastočná obnova nie je povolená", + "A stack member has a different identity": "Člen stohu má inú identitu", "A system reboot is recommended to ensure all changes take effect.": "Odporúča sa reštart systému, aby sa všetky zmeny bezpečne prejavili.", + "A third party companion app available to Plex server owners to allow their users to request, review and discover content.": "Aplikácia tretej strany pre majiteľov serverov Plex, ktorá umožňuje ich používateľom požadovať, skúmať a objavovať obsah.", + "A third-party client for self-hosted server and self-hosted server, remote access management interface, remote access to installed applications.": "Klient tretej strany pre self-hosted server a self-hosted server, vzdialený prístup k nainštalovaným aplikáciám.", + "A tmpfs mount is not part of the journal; recovery blocked": "A tmpfs mount nie je súčasťou časopisu; zotavenie blokované", + "A tmpfs mount overlaps another mount": "Pripojenie tmpfs sa prekrýva s inou montážou", + "A tunneling daemon by Cloudflare that safely exposes your web servers into the internet.": "Tunelový démon Cloudflare, ktorý bezpečne vystavuje vaše webové servery na internet.", + "A versatile file conversion tool that supports multiple formats.": "Univerzálny nástroj na konverziu súborov, ktorý podporuje viacero formátov.", + "A web GUI client of Project V which supports VMess, VLESS, SS, SSR, Trojan, Tuic and Juicity protocols": "Webový GUI klient projektu V, ktorý podporuje protokoly VMess, VLESS, SS, SSR, Trojan, Tuic a Juicity", + "A web app to listen Youtube audio source.": "Webová aplikácia na počúvanie zdroja zvuku Youtube.", + "A web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes": "Webová aplikácia na správu vašich dvoch autentifikácií (2FA) a generovanie ich bezpečnostných kódov", + "A web frontend for the motion daemon.": "Web frontend pre filmový démon.", + "A web-based file sharing and management protocol": "Webový protokol zdieľania a správy súborov", + "A well-designed cross-platform ChatGPT UI.": "Dobre navrhnutý cross-platform ChatGPT UI.", "ACL Status:": "Stav ACL:", "ACL permissions applied for local access for user:": "ACL oprávnenia boli nastavené pre lokálny prístup používateľa:", "ADVANCED SETTINGS COMPLETE": "POKROČILÉ NASTAVENIA SÚ HOTOVÉ", "ALL DATA ON": "VŠETKY DÁTA NA", "ALL DATA ON THIS DISK WILL BE PERMANENTLY LOST!": "VŠETKY DÁTA NA TOMTO DISKU BUDÚ NATRVALO STRATENÉ!", "ALL Utilities": "VŠETKY nástroje", + "ALLOWED_HOSTS cannot contain line breaks": "UDELENÉ HOSTS nemôžu obsahovať prestávky na čiare", + "AList initial login": "AList začiatočné prihlásenie", "AMD CPU detected": "Zistený AMD procesor", "AMD CPU fixes applied successfully": "Opravy pre AMD procesor boli úspešne použité", "AMD GPU Tools installation completed!": "Inštalácia nástrojov pre AMD GPU je hotová!", "AMD GPU passthrough configured.": "AMD GPU passthrough je nastavený.", "AMD GPU(s) detected:": "Nájdené AMD GPU:", + "AMD KFD device": "Zariadenie AMD KFD", + "AMD VA-API + OpenCL (official mod)": "AMD VA-API + OpenCL (oficiálny mod)", "AMD fixes have been successfully reverted": "Opravy pre AMD boli úspešne vrátené späť", "AMD mesa drivers installed.": "AMD mesa ovládače nainštalované.", "AMD softdep configured": "AMD softdep je nastavený", @@ -93,9 +157,21 @@ "About to restore": "Chystá sa obnova", "Absolute directory path to use as backup target:": "Absolútna cesta k priečinku, ktorý sa má použiť ako cieľ záloh:", "Absolute path to a file or directory you want backed up:": "Absolútna cesta k súboru alebo priečinku, ktorý chcete zálohovať:", + "Acceleration": "Zrýchlenie", + "Acceleration configuration cancelled": "Konfigurácia zrýchlenia zrušená", + "Acceleration for CodeProject.AI": "Zrýchlenie pre CodeProject. AI", + "Acceleration for Immich smart recognition": "Zrýchlenie pre Immich inteligentné uznanie", + "Acceleration for Ollama": "Zrýchlenie pre Ollama", "Accept routes from other nodes?": "Prijímať trasy z iných uzlov?", + "Accept this host monitoring profile?": "Prijmite tento monitorovací profil hostiteľa?", "Access Scope:": "Rozsah prístupu:", + "Access bridge": "Prístupový mostík", + "Access bridge for Immich": "Prístupový mostík pre Immich", + "Access bridge for Nextcloud": "Prístupový mostík pre Nextcloud", + "Access bridge for Paperless": "Prístupový mostík pre bezpapierové", + "Access bridge for Tandoor": "Prístupový mostík pre Tandoor", "Access profile:": "Profil prístupu:", + "Access token of the Jupyter Lab web interface": "Prístupový token webového rozhrania Jupyter Lab", "Account is not locked": "Účet nie je zamknutý", "Action cancelled due to previous xshok-proxmox modifications.": "Akcia bola zrušená, pretože v systéme už sú úpravy z xshok-proxmox.", "Action:": "Akcia:", @@ -105,6 +181,10 @@ "Active Connections": "Aktívne pripojenia", "Active exports:": "Aktívne exporty:", "Active session:": "Aktívna relácia:", + "Actual device path on the host": "Skutočná dráha zariadenia na hostiteľovi", + "Adaptation file too large": "Adaptačný súbor príliš veľký", + "Adaptation file with unexpected permissions or owner": "Adaptačný súbor s neočakávanými oprávneniami alebo majiteľom", + "Adblock & DNS": "Adblock & DNS", "Add Audio Passthrough": "Pridať audio passthrough", "Add CIFS storage:": "Pridať CIFS úložisko:", "Add Controller or NVMe (PCI passthrough)": "Pridať radič alebo NVMe (priame priradenie cez PCI)", @@ -123,6 +203,9 @@ "Add PBS": "Pridať PBS", "Add Samba Share as Proxmox Storage": "Pridať Samba zdieľanie ako úložisko Proxmoxu", "Add Samba share as Proxmox Storage": "Pridať Samba zdieľanie ako úložisko Proxmoxu", + "Add a Coral PCIe/M.2 device?": "Pridať zariadenie Coral PCIe/M.2?", + "Add a custom data path?": "Pridať vlastnú dátovú cestu?", + "Add an extra custom path": "Pridať extra vlastnú cestu", "Add as IDE": "Pridať ako IDE", "Add as SATA": "Pridať ako SATA", "Add as SCSI": "Pridať ako SCSI", @@ -140,6 +223,7 @@ "Add import disk": "Pridať importovaný disk", "Add latest Ceph support": "Pridať najnovšiu podporu Ceph", "Add new PVE 9 enterprise repository (deb822 format) (Only if using enterprise):": "Pridajte nový PVE 9 enterprise repozitár (formát deb822) (iba ak používate enterprise):", + "Add or change a device": "Pridať alebo zmeniť zariadenie", "Add physical disk to VM via": "Pridať fyzický disk do VM cez", "Add share block in /etc/samba/smb.conf:": "Pridať blok zdieľania do /etc/samba/smb.conf:", "Add unprivileged flag to container configuration:": "Pridať príznak neprivilegovaného kontajnera do nastavenia:", @@ -154,20 +238,37 @@ "Adding": "Pridávam", "Adding CIFS storage to Proxmox...": "Pridávam CIFS úložisko do Proxmoxu...", "Adding QEMU Guest Agent support...": "Pridávam podporu QEMU Guest Agent...", + "Adding Radarr to Prowlarr...": "Pridanie Radarr do Prowlarr...", + "Adding Sonarr to Prowlarr...": "Pridanie Sonarr do Prowlarr...", "Adding disk using the generated command to the selected VM": "Pridávam disk do vybranej VM pomocou vygenerovaného príkazu", "Adding existing users to sharedfiles group...": "Pridávam existujúcich používateľov do skupiny sharedfiles...", "Adding iSCSI storage to Proxmox...": "Pridávam iSCSI úložisko do Proxmoxu...", "Adding new share to smb.conf...": "Pridávam nové zdieľanie do smb.conf...", + "Adding peers later means raising PEERS in /etc/pve/lxc/.conf and restarting the container. The existing peer keys are kept.": "Pridanie peerov neskôr znamená zvýšenie PEERS v /etc/pve/lxc/.conf a obnovenie kontajnera. Existujúce kľúče peer sú zachované.", + "Adding the mount points...": "Pridanie bodov pripojenia...", "Adding this NVMe as a PCIe device (via 'Add Controller or NVMe PCIe to VM') gives better performance.": "Pridanie tohto NVMe ako PCIe zariadenia (cez 'Pridať radič alebo NVMe PCIe do VM') dáva lepší výkon.", "Adding to /etc/fstab for permanent mounting...": "Pridávam do /etc/fstab pre trvalé pripojenie...", + "Additional URL advertised by Plex (optional)": "Ďalšie URL inzerované Plex (voliteľné)", "Additional audio function(s) to be added": "Pridajú sa ďalšie audio funkcie", + "Additional media/GPU GIDs, comma-separated": "Dodatočné médiá/GPU GID, čiarovo oddelené", + "Additional paths for": "Ďalšie cesty pre", + "Address of the Compose file": "Adresa súboru", + "Address to reach Pydio Cells (https://domain or https://IP:8080)": "Adresa na oslovenie Pydio Cells (https://domain alebo https://IP:8080)", + "Address used to reach wallabag (http://IP or https://wallabag.example.com)": "Adresa použitá na dosiahnutie wallabag (http://IP alebo https://wallabag.example.com)", + "Addresses to update: ipv4, ipv6 or both (uses an external service)": "Adresy na aktualizáciu: ipv4, ipv6 alebo oboje (používa externú službu)", + "Adguardhome Sync web interface": "Webové rozhranie Adguardhome Sync", + "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances.": "Adguardhome-sync je nástroj na synchronizáciu adGuardHome config na opakovanie inštancií.", "Adjust network/CIDR to your environment.": "Upravte sieť/CIDR podľa svojho prostredia.", "Adjust options if needed (vers=4,hard,timeo,...).": "Podľa potreby upravte možnosti (vers=4,hard,timeo,...).", "Adjusting systemd-journald limits to match Log2RAM size...": "Upravujem limity systemd-journald podľa veľkosti Log2RAM...", "Adjusts journald log level if needed (Proxmox defaults may block auth logs)": "Podľa potreby upraví úroveň logovania journald (predvolené Proxmox nastavenie môže blokovať záznamy prihlásení)", + "Admin page": "Admin stránka", + "Administrator email": "Administrátorský mail", + "Administrator password, at least 12 characters (empty = generated)": "Heslo správcu, minimálne 12 znakov (prázdne = generované)", "Advanced": "Pokročilé", "Advanced Diagnostics": "Pokročilá diagnostika", "Advanced Network Diagnostics": "Pokročilá diagnostika siete", + "Advanced: every setting of the container": "Pokročilé: každé nastavenie kontajnera", "Affected LXC containers": "Dotknuté LXC kontajnery", "After completing GPU setup, start the VM manually when the host is ready.": "Po dokončení nastavenia GPU spustite VM ručne, keď bude server pripravený.", "After confirming, you will be asked to choose the NVIDIA driver version to install.": "Po potvrdení si vyberiete verziu ovládača NVIDIA, ktorú chcete nainštalovať.", @@ -183,11 +284,15 @@ "After the reboot you can follow the post-restore work live from ProxMenux Monitor → Backups tab (estimated time, per-component status, log tail, rollback delta).": "Po reštarte môžete práce po obnove sledovať naživo v ProxMenux Monitor → karta Backups (odhad času, stav súčastí, koniec záznamu, rozdiel rollbacku).", "After the reboot, you will only be able to access the Proxmox host via:": "Po reštarte sa k Proxmox hostovi dostanete iba cez:", "After this LXC → VM switch, reboot the host so the new binding state is applied cleanly.": "Po tomto prepnutí LXC → VM reštartujte host, aby sa nové naviazanie použilo čisto.", + "Airsonic Advanced web interface": "Webové rozhranie Airsonic Advanced", + "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room.": "Airsonic-pokročilé je zadarmo, web-založené mediálne streamer, poskytuje ubiquitious prístup k vašej hudbe. Pomocou neho zdieľať hudbu s priateľmi, alebo počúvať svoju vlastnú hudbu v práci. Môžete prúdiť do viacerých hráčov súčasne, napríklad do jedného hráča v kuchyni a ďalšie vo vašej obývacej izbe.", "Aliases added to .bashrc": "Aliasy boli pridané do .bashrc", + "Alist Sync web interface": "Alist Sync webové rozhranie", "All": "Všetky", "All Available Scripts": "Všetky dostupné skripty", "All GPUs Already Assigned": "Všetky GPU už sú priradené", "All ProxMenux optimizations are up to date.": "Všetky optimalizácie ProxMenux sú aktuálne.", + "All applications": "Všetky žiadosti", "All block devices:": "Všetky blokové zariadenia:", "All changes applied. No reboot required.": "Všetky zmeny boli použité. Reštart nie je potrebný.", "All changes are reversible using the ProxMenux uninstaller.": "Všetky zmeny sa dajú vrátiť späť cez odinštalátor ProxMenux.", @@ -195,43 +300,79 @@ "All detected GPUs are already assigned to this VM.": "Všetky zistené GPU už sú priradené tejto VM.", "All detected controllers/NVMe are already present in the selected VM.": "Všetky zistené Controller/NVMe zariadenia už sú vo vybranej VM pridané.", "All disks may already be in use or mounted.": "Všetky disky sa už možno používajú alebo sú pripojené.", + "All images are downloaded and verified first, and native backups are taken with the stack stopped. Contracts are published after the whole set is checked. If anything fails, all members are recovered.": "Všetky obrázky sú stiahnuté a overené prvý, a natívne zálohy sú prijaté s stack zastavil. Zmluvy sa uverejňujú po kontrole celej sady. Ak niečo zlyhá, všetci členovia sú späť.", "All images imported and configured successfully": "Všetky obrazy boli úspešne importované a nastavené", "All imports failed": "Všetky importy zlyhali", + "All of them are removed.": "Všetky sú odstránené.", "All partitions and metadata removed.": "Všetky oddiely a metadáta boli odstránené.", "All physical interfaces from backup are present on target": "Všetky fyzické rozhrania zo zálohy sú na cieli prítomné", + "All stack members are updated together. Main CT:": "Všetky stack členov sú aktualizované spoločne. Hlavné CT:", "All types (images, backup, iso, vztmpl, snippets)": "Všetky typy (images, backup, iso, vztmpl, snippets)", "All user-installed packages from the backup are present on this host": "Všetky používateľom nainštalované balíky zo zálohy sú na tomto hostovi prítomné", "All users with UID and GID": "Všetci používatelia s UID a GID", "Allocate CPU Cores": "Prideliť CPU jadrá", "Allocate RAM in MiB": "Prideliť RAM v MiB", + "Allowed hosts (comma separated; * allows access through the assigned IP)": "Povolené hostiteľov (koma oddelené; * umožňuje prístup cez pridelený IP)", "Already Mounted": "Už je pripojené", "Already configured": "Už nastavené", "Already installed — skipping": "Už nainštalované - preskakujem", + "Also add the /dev/srX optical device (recommended)": "Tiež pridať /dev / srX optické zariadenie (odporúčané)", "Also comment any remaining 'bookworm' entries in *.list if present.": "Zakomentujte aj všetky zostávajúce položky 'bookworm' v *.list, ak existujú.", "Also install the VirtIO network driver during setup to enable network access.": "Počas inštalácie nainštalujte aj sieťový ovládač VirtIO, aby fungoval prístup k sieti.", "Although VFIO can bind to this device, full passthrough to a VM is": "Aj keď sa VFIO vie na toto zariadenie naviazať, úplný passthrough do VM je", + "Altus is an Electron-based WhatsApp client with themes and multiple account support.": "Altus je Electron-based WhatsApp klient s témami a viacerými podporou účtu.", + "Ambiguous mount points in the container": "Ambiciózne body upevnenia v kontajneri", + "Ambiguous or invalid environment variable": "Ambiciózna alebo neplatná premenná prostredia", "Amount of RAM in MiB (default: 4096)": "Množstvo RAM v MiB (predvolené: 4096)", + "An AI model used to generate images conditioned on text descriptions.": "Model AI používaný na generovanie obrázkov podmienených textovými popismi.", "An AMD dedicated GPU has been detected without FLR support": "Bola zistená dedikovaná AMD GPU bez podpory FLR", "An AMD integrated GPU (APU) has been detected": "Bola zistená integrovaná AMD GPU (APU)", + "An Alist storage synchronization tool based on the Web interface.": "Nástroj na synchronizáciu pamäte Alist založený na webovom rozhraní.", + "An Industrial-Level Controllable and Efficient Zero-Shot Text-To-Speech System": "Priemyselná úroveň ovládateľná a efektívna zero-Shot Text-To-Speech System", "An Intel dedicated GPU has been detected without FLR support": "Bola zistená dedikovaná Intel GPU bez podpory FLR", + "An accelerated video generation framework that speeds up end-to-end diffusion while preserving video quality": "Zrýchlený rámec tvorby videa, ktorý urýchľuje šírenie do konca a zároveň zachováva kvalitu videa", + "An executable required by the adapter is missing in the new image": "V novom obrázku chýba spustiteľný requi.", "An fstab entry already exists for:": "Záznam vo fstab už existuje pre:", + "An image probe container was started externally": "Externe bola spustená obrazová sonda", + "An include is not part of the journal; recovery blocked": "Zahrnutie nie je súčasťou časopisu; obnova zablokovaná", + "An include was modified outside the journal; recovery blocked": "Zahrnutie bolo upravené mimo časopisu; regenerácia zablokovaná", + "An open source generative AI development platform for building AI Agents and LLM workflows": "Open source roding AI developing platform for building AI Agents and LLM workflows", + "An operation of this installation has not finished; recover it from the management menu before removing it": "operation tohto zariadenia ešte nie je dokončená; obnoviť ho z menu riadenia pred jeho odstránením", + "An update does not accept configuration changes": "Aktualizácia neprijíma zmeny konfigurácie", "Analysis Tools": "Analytické nástroje", + "Analysis software that shows your internet speed for up to 30 days.": "Analyzačný softvér, ktorý ukazuje rýchlosť internetu až 30 dní.", "Analyze Bridge Configuration": "Analyzovať nastavenie bridge", "Analyze Network Configuration": "Analyzovať nastavenie siete", "Analyzing Bridge Configuration - READ ONLY MODE": "Analyzujem nastavenie bridge - režim iba na čítanie", "Analyzing Network Configuration - READ ONLY MODE": "Analyzujem nastavenie siete - režim iba na čítanie", "Analyzing selected disks...": "Analyzujem vybrané disky...", "Analyzing system for available PCIe storage devices...": "Analyzujem systém a hľadám dostupné PCIe úložiskové zariadenia...", + "Another OCI operation is using the instance registry": "Ďalšia OCI operation používa inštančný register", + "Another OCI operation is using the instance registry. Wait for it to finish and open this menu again; no container is modified.": "Ďalšia OCI operation používa inštančný register. Počkajte, kým to dokončíte a znovu otvoríte toto menu; žiadna nádoba nie je upravená.", + "Another OCI operation is using the registry. This operation was not started.": "Ďalšia OCI operation používa register. Táto operation sa nezačala.", + "Another instance uses": "Iný prípad použitia", + "Another stack operation is pending": "Ďalší zásobník operation čaká", + "Application": "Uplatňovanie", + "Application responding:": "Aplikácia odpovedá:", + "Application responding; checking its stability...": "Aplikácia reaguje; kontrola jej stability...", + "Application suite: one independent LXC per selected application": "Application suite: jeden nezávislý LXC na vybranú aplikáciu", + "Application:": "Použitie:", + "Applications you can choose:": "Aplikácie si môžete vybrať:", "Apply": "Použiť", "Apply AMD CPU fixes": "Použiť opravy pre AMD procesory", "Apply Available Updates": "Nainštalovať dostupné aktualizácie", "Apply and restart services:": "Použiť zmeny a reštartovať služby:", "Apply available updates": "Nainštalovať dostupné aktualizácie", "Apply boot/initramfs changes": "Použiť zmeny boot/initramfs", + "Apply configuration": "Použiť nastavenie", "Apply fix now?": "Použiť opravu teraz?", "Apply fix now? (The share will be briefly remounted)": "Použiť opravu teraz? (zdieľanie sa na chvíľu znovu pripojí)", "Apply network optimizations": "Použiť sieťové optimalizácie", + "Apply optional security relaxation apparmor:rootlesskit": "Aplikovať voliteľný bezpečnostný relaxačný apartor:rootlesskit", + "Apply optional security relaxation apparmor:unconfined": "Aplikovať voliteľný bezpečnostný relaxačný apparmor:nekonfigurované", + "Apply optional security relaxation seccomp:unconfined": "Aplikovať voliteľné bezpečnostné relaxačné seccomp:unconfined", "Apply read+write access for 'others' on the host directory?": "Nastaviť pre 'others' čítanie aj zápis na priečinku hosta?", + "Apply the options from the current catalog template? Your data and configuration are kept.": "Aplikovať možnosti z aktuálnej katalógovej šablóny? Vaše dáta a konfigurácia sú uchovávané.", "Applying AMD-specific fixes...": "Používam opravy špecifické pre AMD...", "Applying Changes": "Používam zmeny", "Applying Controller/NVMe passthrough to VM": "Používam priame priradenie Controller/NVMe do VM", @@ -244,12 +385,21 @@ "Applying passthrough to CT": "Používam priame priradenie do CT", "Applying safe paths and preparing pending restore": "Používam bezpečné cesty a pripravujem čakajúcu obnovu", "Applying selected LXC switch action": "Používam vybranú akciu prepnutia LXC", + "Applying the Jellyfin configuration:": "Použitie konfigurácie Jellyfin:", + "Applying the LAN address to the application URLs...": "Aplikovať adresu LAN na URL aplikácie...", + "Applying the initial Nextcloud settings...": "Aplikácia prvých nastavení Nextcloud...", + "Applying the mount mode...": "Aplikácia režimu pripojenia...", + "Apprise-api Takes advantage of Apprise through your network with a user-friendly API.": "Apprese-api Využíva aplikáciu Apprise prostredníctvom vašej siete s užívateľsky prívetivým API.", + "Architecture": "Architektúra", + "Architecture:": "Architektúra:", + "Architectures": "Architektúry", "Archive deleted.": "Archív bol vymazaný.", "Archive extracted.": "Archív rozbalený.", "Archive format": "Formát archívu", "Archive ready": "Archív pripravený", "Archive size:": "Veľkosť archívu:", "Archive:": "Archív:", + "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers.": "Ardour je otvorený zdroj spolupráce celosvetového tímu vrátane hudobníkov, programátorov a profesionálnych nahrávacích inžinierov.", "Are you absolutely sure?": "Ste si úplne istý?", "Are you sure you want to continue?": "Naozaj chcete pokračovať?", "Are you sure you want to delete this export?": "Naozaj chcete vymazať tento export?", @@ -261,6 +411,7 @@ "Are you sure you want to unmount this NFS share?": "Naozaj chcete odpojiť toto NFS zdieľanie?", "Are you sure you want to unmount this Samba share?": "Naozaj chcete odpojiť toto Samba zdieľanie?", "Are you sure?": "Ste si istý?", + "Arr suite: applications to install": "Arr suite: aplikácie na inštaláciu", "As Proxmox storage": "Ako úložisko Proxmoxu", "As host fstab mount only": "Iba ako mount v host fstab", "Assign GPU PCI function to VM": "Priradiť PCI funkciu GPU k VM", @@ -275,14 +426,19 @@ "Attach imported disk to VM": "Pripojiť importovaný disk k VM", "Attach to an existing PVE vzdump job (inherit schedule + retention)": "Pripojiť k existujúcej PVE vzdump úlohe (prevezme plán + uchovávanie)", "Attached to PVE job:": "Pripojené k PVE úlohe:", + "Attaching the volumes...": "Pripájam zväzky...", "Attempting automatic repair...": "Skúšam automatickú opravu...", "Attempting passthrough with this GPU typically results in": "Pokus o passthrough s touto GPU zvyčajne vedie k", "Attention: Removing the subscription banner may cause issues in the web interface after a future update.": "Upozornenie: odstránenie hlásenia o predplatnom môže po budúcej aktualizácii spôsobiť problém vo webovom rozhraní.", + "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source.": "Audacity je ľahko použiteľný, multi-track audio editor a rekordér. Vyvinutá skupinou dobrovoľníkov ako open source.", + "Audio device directory": "Adresár audio zariadenia", + "Audiobookshelf is a self-hosted audiobook and podcast server.": "Audiobookshelf je samoobsluha audioknihy a podcast server.", "Audit completed. Press Enter to continue...": "Audit dokončený. Pokračujte stlačením Enter...", "Audit socket disabled or not required": "Zásuvka auditu je zakázaná alebo sa nevyžaduje", "Auth key is required.": "Auth key je povinný.", "Auth:": "Prihlásenie:", "Authentication": "Prihlásenie", + "Authentication & Security": "Overenie a bezpečnosť", "Authentication Error": "Chyba prihlásenia", "Authentication failed.": "Prihlásenie zlyhalo.", "Authentication required:": "Vyžaduje prihlásenie:", @@ -301,7 +457,12 @@ "Auto-sync was not enabled": "Automatická synchronizácia nebola zapnutá", "Automated Post-Install Script": "Automatický skript po inštalácii", "Automated post-installation script": "Automatický skript po inštalácii", + "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Automatický správca videoknižnice pre televízne programy. Sleduje nové epizódy vašich obľúbených šou, a keď sú zverejnené to robí jeho mágiu.", + "Automatic detection": "Automatická detekcia", + "Automatic private network allocation requires a /24 subnet": "Automatické pridelenie súkromných sietí requires a /24 subnet", + "Automatic video library manager for TV Shows": "Automatický správca video knižnice pre TV Shows", "Automatic/Unattended": "Automaticky/bez zásahu", + "Automation & Scheduling": "Automatizácia a plánovanie", "Available": "Dostupné", "Available Borg archives (newest first):": "Dostupné Borg archívy (najnovšie prvé):", "Available Borg targets:": "Dostupné Borg ciele:", @@ -322,17 +483,23 @@ "Available space in /mnt:": "Dostupné miesto v /mnt:", "Available storage information:": "Dostupné informácie o úložiskách:", "Available storage volumes:": "Dostupné úložiská:", + "Azahar is an open-source 3DS emulator based on Citra.": "Azahar je open-source 3DS emulátor založený na Citra.", "BIOS TYPE": "TYP BIOSU", "BIOS Type": "Typ BIOSu", "BIOS from": "BIOS z", "BIOS: OVMF (UEFI)": "BIOS: OVMF (UEFI)", + "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications.": "BOINC je platforma pre vysokovýkonnú výpočtovú techniku vo veľkom meradle (v tisícoch alebo miliónoch počítačov). Môže byť použitý pre dobrovoľnú výpočtovú techniku (pomocou spotrebiteľských zariadení) alebo grid computing (pomocou organizačných zdrojov). Podporuje virtualizované, paralelné a GPU-založené aplikácie.", "BRIDGE CONFIGURATION ANALYSIS": "ANALÝZA NASTAVENIA BRIDGE", "BTRFS:": "BTRFS:", + "Baby Buddy web interface": "Webové rozhranie Baby Buddy", + "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work.": "Babybuddy je kamarát pre deti! Pomáha opatrovateľom sledovať spánok, kŕmenie, zmeny plienky, čas bruška a ďalšie učiť sa a predvídať potreby dieťaťa bez (tak veľa) hádať prácu.", "Back to previous menu or Esc + Enter": "Späť do predchádzajúceho menu alebo Esc + Enter", "Backed up and cleared": "Zálohovaná a vyčistená", "Backend": "Backend", "Backend:": "Backend:", + "Background archive extraction for Arr download queues. No web interface.": "Extrakcia archívu pozadia pre Arr download fronty. Žiadne webové rozhranie.", "Backup — VM and CT backups": "Backup — zálohy VM a CT", + "Backup & Recovery": "Záloha a obnova", "Backup Created": "Záloha bola vytvorená", "Backup ID (group name in PBS):": "ID zálohy (názov skupiny v PBS):", "Backup ID for this job:": "ID zálohy pre túto úlohu:", @@ -345,6 +512,7 @@ "Backup available at": "Záloha je dostupná tu", "Backup completed successfully.": "Záloha bola úspešne dokončená.", "Backup completed:": "Záloha dokončená:", + "Backup created": "Vytvorená záloha", "Backup created:": "Záloha vytvorená:", "Backup declares unused NICs that are not on this host:": "Záloha uvádza nepoužité sieťové karty, ktoré na tomto hostovi nie sú:", "Backup destination is inside the backup": "Cieľ zálohy je vnútri zálohovanej cesty", @@ -355,6 +523,7 @@ "Backup information": "Informácie o zálohe", "Backup location": "Umiestnenie zálohy", "Backup metadata": "Metadáta zálohy", + "Backup of the previous installation verified": "Zálohovanie predchádzajúcej inštalácie overené", "Backup on newer kernel:": "Záloha na novšom kerneli:", "Backup on older kernel:": "Záloha na staršom kerneli:", "Backup origin metadata:": "Metadáta pôvodu zálohy:", @@ -369,26 +538,42 @@ "Backup:": "Záloha:", "Backups already on PBS were encrypted with the current key — downloading them will fail unless you first Download the current keyfile to keep a copy.": "Zálohy, ktoré už sú v PBS, boli zašifrované aktuálnym kľúčom - ich stiahnutie zlyhá, ak si najprv nestiahnete a neodložíte aktuálny keyfile.", "Backups already stored on PBS were encrypted with the current keyfile. After this action:": "Zálohy, ktoré sú už uložené v PBS, boli zašifrované aktuálnym keyfile. Po tejto akcii:", + "Backups verified": "Potvrdené zálohy", + "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience.": "Bambu Studio je open-source, špičkový, funkcie-bohaté krájanie softvér. Obsahuje projektové pracovné postupy, systematicky optimalizované algoritmy krájania a ľahko použiteľné grafické rozhranie, ktoré používateľom prináša neuveriteľne hladký zážitok z tlače.", "Bandwidth limit configured": "Limit priepustnosti je nastavený", "Bandwidth test (iperf3)": "Test priepustnosti (iperf3)", "Bandwidth test completed successfully": "Test priepustnosti bol úspešne dokončený", "Base VM created with ID": "Základná VM bola vytvorená s ID", + "Base VMID": "Základné VMID", + "Base VMID (empty = next free block)": "Základné VMID (prázdne = ďalší voľný blok)", + "Base VMID of Nextcloud (empty = next free block)": "Základné VMID Nextcloud (prázdne = ďalší voľný blok)", + "Base VMID of Paperless (empty = next free block)": "Základné VMID bezpapierové (prázdne = ďalší voľný blok)", + "Base VMID of Tandoor (empty = next free block)": "Základné VMID Tandooru (prázdne = ďalší voľný blok)", + "Base VMID of the server (empty = next free block)": "Základné VMID servera (prázdne = ďalší voľný blok)", "Bash prompt path": "Cesta v príkazovom riadku Bash", "Bashrc customization completed": "Úprava bashrc je dokončená", "Basic Settings": "Základné nastavenia", "Basic Utilities": "Základné nástroje", + "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you.": "Bazarr je sprievodná aplikácia na Sonarr a Radarr. To môže spravovať a stiahnuť titulky na základe requirements. Definujete svoje preferencie pomocou TV show alebo filmu a Bazarr sa postará o všetko pre vás.", + "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools.": "Beets je manažérom hudobnej knižnice a väčšinou nie hudobným prehrávačom. To zahŕňa jednoduchý prehrávač plugin a experimentálny webový prehrávač, ale všeobecne ponecháva skutočný zvuk-reprodukciu špecializovaných nástrojov.", "Before making any changes, we'll create a safety backup.": "Pred akoukoľvek zmenou vytvoríme bezpečnostnú zálohu.", "Beta (develop branch)": "Beta (vetva develop)", "Beta version:": "Beta verzia:", "Binary not found in extracted content.": "V rozbalenom obsahu sa nenašiel spustiteľný súbor.", "Bind mount added:": "Bind mount pridaný:", + "Bind mounts are not included in vzdump": "Vzadump nie sú zahrnuté svorníky", + "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services.": "Bitcoin Knots môže byť použitý ako desktop klient pre pravidelné platby alebo ako kompletný uzol server nástroj pre obchodníkov a iné platobné služby.", "Blacklist nouveau driver": "Pridá ovládač nouveau na blacklist", "Blacklisting GPU host drivers...": "Pridávam host ovládače GPU na blacklist...", "Blacklisting nouveau driver...": "Pridávam ovládač nouveau na blacklist...", + "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**": "Blender je bezplatný a open-source 3D počítačový grafický softvérový súbor používaný na vytváranie animovaných filmov, vizuálnych efektov, umenia, 3D tlačených modelov, pohybovej grafiky, interaktívnych 3D aplikácií, virtuálnej reality a počítačových hier. **Tento obrázok nepodporuje GPU vykresľovanie z krabice iba zrýchlený zážitok z pracovného priestoru", + "Blinko is an AI-powered card note-taking project. Designed for individuals who want to quickly capture and organize their fleeting thoughts. Blinko allows users to seamlessly jot down ideas the moment they strike, ensuring that no spark of creativity is lost.": "Blinko je projekt, ktorý berie na vedomie karty s umelým pohonom. Určené pre jednotlivcov, ktorí chcú quickly zachytiť a organizovať svoje letmé myšlienky. Blinko umožňuje používateľom bezproblémovo zatĺkať nápady v okamihu, keď udrú, takže žiadna iskra tvorivosti nie je stratená.", "Blocked GPU ID": "Blokované ID GPU", "Blocked GPU ID for VM Mode": "Blokované ID GPU pre VM režim", "Blocked device(s)": "Blokované zariadenia", "Blocked device(s):": "Blokované zariadenia:", + "BookStack web interface": "Webové rozhranie BookStack", + "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease.": "Bookstack je bezplatný a open source Wiki navrhnutý pre vytvorenie krásnej dokumentácie. Vďaka jednoduchému, ale výkonnému WYSIWYG editoru umožňuje tímom jednoducho vytvárať podrobnú a užitočnú dokumentáciu.", "Boot Disk": "Bootovací disk", "Boot artifacts regenerated — reboot the host to activate the merged config.": "Boot súbory boli znovu vytvorené - reštartujte host, aby sa zlúčené nastavenie aktivovalo.", "Boot disk:": "Boot disk:", @@ -415,9 +600,13 @@ "Bridge:": "Bridge:", "Bridges analyzed": "Skontrolované bridge rozhrania", "Broken gasket-dkms package state recovered.": "Poškodený stav balíka gasket-dkms bol opravený.", + "Browse Your Life in Images": "Prehliadajte svoj život v obrazoch", "Browse manually (advanced)...": "Vybrať ručne (pokročilé)...", + "Browsers & Web Desktops": "Prehliadače a webové plochy", "Build and install the gasket and apex kernel modules (DKMS)": "Zostaví a nainštaluje kernel moduly gasket a apex (DKMS)", "Build dependencies installed.": "Závislosti na zostavenie boli nainštalované.", + "Build your personal knowledge base with TriliumNext Notes": "Budujte si osobné znalosti základne s TriliumNext Poznámky", + "Business & ERP": "Obchod a ERP", "CHANGES APPLIED SUCCESSFULLY": "ZMENY BOLI ÚSPEŠNE POUŽITÉ", "CIFS Client Tools: AVAILABLE": "Nástroje CIFS klienta: DOSTUPNÉ", "CIFS Client Tools: NOT AVAILABLE - installing...": "Nástroje CIFS klienta: NEDOSTUPNÉ - inštalujem...", @@ -435,24 +624,34 @@ "CLUSTER UPGRADE NOTES:": "POZNÁMKY K AKTUALIZÁCII KLASTRA:", "CONFIGURED INTERFACES": "NASTAVENÉ ROZHRANIA", "CONFIRM FORMAT": "POTVRDENIE FORMÁTOVANIA", + "CPU": "CPU", "CPU Cores": "CPU jadrá", "CPU MODEL": "MODEL CPU", "CPU Model": "Model CPU", + "CPU cores": "Jadro procesora", + "CPU priority": "Priorita procesora", "CPU set to host,hidden=1,flags=+pcid": "CPU nastavené na host,hidden=1,flags=+pcid", "CPU vendor (intel/amd):": "Výrobca CPU (intel/amd):", "CRITICAL: The selected disk is referenced by a RUNNING VM or CT.": "KRITICKÉ: vybraný disk používa BEŽIACA VM alebo CT.", "CT": "CT", "CT started successfully.": "CT bol úspešne spustený.", + "CUDA requires a working NVIDIA driver": "CUDA requires pracovný ovládač NVIDIA", + "Calculate all kinds of statistics from your (local) Emby or Jellyfin server": "Vypočítajte všetky druhy štatistík z vášho (miestneho) servera Emby alebo Jellyfin", + "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts.": "Calibre je výkonný a ľahko použiteľný e-kniha manažér. Užívatelia hovoria, že je vynikajúci a musí mať. To vám umožní robiť takmer všetko a to trvá veci krok za normálne e-knihy softvér. Je to tiež úplne zadarmo a otvorený zdroj a skvelé ako pre príležitostných užívateľov a počítačových odborníkov.", + "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself.": "Calibre-web je webová aplikácia poskytujúca čisté rozhranie pre prehliadanie, čítanie a sťahovanie elektronických kníh pomocou existujúcej databázy Calibre. Je tiež možné integrovať Google disk a upraviť metaúdaje a knižnicu calibre prostredníctvom samotnej aplikácie.", + "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases.": "Calligra je kancelársky a grafický apartmán KDE. Je k dispozícii pre stolové počítače, tabletové počítače a smartphony. Obsahuje aplikácie na spracovanie slov, tabuľky, prezentáciu, vektorovú grafiku a editačné databázy.", "Cancel": "Zrušiť", "Cancel restore": "Zrušiť obnovu", "Cancel this setup": "Zrušiť toto nastavenie", "Cancelled by user or empty URL.": "Zrušené používateľom alebo prázdna URL.", "Cancelled by user.": "Zrušené používateľom.", + "Cannot apply the Compose command:": "Nie je možné použiť príkaz Compose:", "Cannot connect to server": "Nedá sa pripojiť k serveru", "Cannot continue": "Nedá sa pokračovať", "Cannot create:": "Nedá sa vytvoriť:", "Cannot detect filesystem on": "Nedá sa zistiť súborový systém na", "Cannot find": "Nedá sa nájsť", + "Cannot identify the vendor of the device:": "Nie je možné identifikovať predajcu zariadenia:", "Cannot load backup library: lib_host_backup_common.sh": "Nepodarilo sa načítať knižnicu zálohovania: lib_host_backup_common.sh", "Cannot proceed with invalid export path.": "Nedá sa pokračovať s neplatnou cestou exportu.", "Cannot proceed with invalid share name.": "Nedá sa pokračovať s neplatným názvom zdieľania.", @@ -460,7 +659,11 @@ "Cannot reach download.proxmox.com. Check network, proxy or DNS.": "Nedá sa dosiahnuť download.proxmox.com. Skontrolujte sieť, proxy alebo DNS.", "Cannot reach portal:": "Portál nie je dostupný:", "Cannot reach server": "Server nie je dostupný", + "Cannot read": "Nedá sa čítať", + "Cannot read the OCI archive:": "Nepodarilo sa prečítať archív OCI:", "Cannot validate credentials - no shares available for testing.": "Prihlasovacie údaje sa nedajú overiť - nie sú dostupné žiadne zdieľania na test.", + "Cannot verify the reused disk:": "Nie je možné overiť znovu použitý disk:", + "Capabilities cannot be kept and all dropped at the same time": "Nie je možné udržať si schopnosti a zároveň ich znížiť.", "Category": "Kategória", "Caution: Maximum mode generates more heat.": "Pozor: maximálny režim vytvára viac tepla.", "Ceph check skipped by user flag (--ignore-ceph-check)": "Kontrola Ceph preskočená používateľskou voľbou (--ignore-ceph-check)", @@ -487,14 +690,23 @@ "Ceph repository configured for PVE 9": "Repozitár Ceph je nastavený pre PVE 9", "Ceph repository signature verification failed; installation has been stopped": "Overenie podpisu úložiska Ceph zlyhalo;inštalácia bola zastavená", "Ceph version OK:": "Verzia Ceph je v poriadku:", + "Certificate errors are logged in /config/log/letsencrypt inside the container.": "Chyba certifikátu je prihlásená /config/log/letecrypt vo vnútri kontajnera.", "Certificate fingerprint of the PBS server:": "Odtlačok certifikátu PBS servera:", + "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL": "Poskytovateľ certifikátu: prázdny pre šifrovanie, nulassl pre ZeroSSL", + "Change GPU acceleration?": "Zmeniť zrýchlenie GPU?", "Change Language": "Zmeniť jazyk", "Change Release Channel": "Zmeniť vetvu vydania", + "Change it after the first login.": "Zmeňte ho po prvom prihlásení.", + "Change or add an environment variable?": "Zmeniť alebo pridať premennú prostredia?", + "Change the access network?": "Zmeniť prístupovú sieť?", + "Changedetection.io provides free, open-source web page monitoring, notification and change detection.": "Changedetection.io poskytuje bezplatné, open-source webové stránky monitorovanie, oznamovanie a detekciu zmien.", "Changes applied. A system reboot is recommended for them to take full effect.": "Zmeny boli použité. Odporúča sa reštart systému, aby sa prejavili naplno.", "Changes have been applied to the configuration file.": "Zmeny boli zapísané do konfiguračného súboru.", "Changes will apply after reboot.": "Zmeny sa prejavia po reštarte.", "Changing Release Channel": "Mením vetvu vydania", "Changing the machine type on an existing installed VM is not safe: it changes the chipset and PCI slot layout, which typically prevents the guest OS from booting.": "Meniť typ stroja na už nainštalovanej VM nie je bezpečné: zmení sa chipset a rozloženie PCI slotov, čo často zabráni štartu hosťovského OS.", + "Changing the rootfs or its storage requires a separate migration": "Zmena rootfs alebo jeho skladovanie requires samostatnú migráciu", + "Changing the storage or size of a disk requires a migration; empty disks are not created": "Zmena úložiska alebo veľkosti disku requires migrácie; prázdne disky nie sú vytvorené", "Check": "Skontrolujte", "Check BIOS/UEFI in Hardware > BIOS — must match what the original VM used": "Skontrolujte BIOS/UEFI v Hardware > BIOS - musí sedieť s tým, čo používala pôvodná VM", "Check Coral USB/M.2 detection": "Skontrolovať detekciu Coral USB/M.2", @@ -520,6 +732,7 @@ "Check the service status manually if needed.": "V prípade potreby skontrolujte stav služieb ručne.", "Checking MOTD configuration...": "Kontrolujem nastavenie MOTD...", "Checking NVIDIA driver status with nvidia-smi": "Kontrolujem stav ovládača NVIDIA pomocou nvidia-smi", + "Checking OCI": "Kontrola OCI", "Checking VFIO modules...": "Kontrolujem VFIO moduly...", "Checking VM virtual display model...": "Kontrolujem model virtuálneho zobrazenia VM...", "Checking ZFS autotrim configuration...": "Kontrolujem nastavenie ZFS autotrim...", @@ -531,7 +744,22 @@ "Checking if the server belongs to OVH...": "Kontrolujem, či server patrí pod OVH...", "Checking kernel headers and build tools...": "Kontrolujem kernel headers a nástroje na zostavenie...", "Checking remaining interfaces": "Kontrolujem zostávajúce rozhrania", + "Checking that the container keeps running...": "Kontrola, či kontajner beží...", "Checking that this version builds against the running kernel...": "Kontroluje sa, či sa táto verzia zostavuje so spusteným jadrom...", + "Checking the GPU of the machine learning container...": "Kontrola GPU kontajnera strojového učenia...", + "Checking the container before recreating it...": "Kontrola kontajnera pred obnovením...", + "Checking the container before the update...": "Kontrola kontajnera pred aktualizáciou...", + "Checking the device permissions for the application user...": "Kontrola oprávnení zariadenia pre užívateľa aplikácie...", + "Checking the image compatibility:": "Kontrola kompatibility obrázku:", + "Checking the image in the registry...": "Kontrola obrazu v registri...", + "Checking the interrupted operation...": "Kontrola prerušenia operation...", + "Checking the interrupted stack operation...": "Kontrola prerušeného zásobníka operation...", + "Checking the new image without starting it:": "Kontrola nového obrázku bez jeho spustenia:", + "Checking the remote...": "Kontrolujem ovládač...", + "Checking the restored installation": "Kontrola obnovenej inštalácie", + "Checking the restored installation...": "Kontrola obnovenej inštalácie...", + "Checking the stack before the update...": "Kontrola zásobníka pred aktualizáciou...", + "Checking the updated stack...": "Kontrolujem aktualizovaný stack...", "Checklist post-upgrade finished. Warnings:": "Kontrola po aktualizácii dokončená. Varovania:", "Checklist pre-check finished. Warnings:": "Predbežná kontrola dokončená. Varovania:", "Checks for LVM and storage issues": "Skontroluje problémy s LVM a úložiskami", @@ -588,6 +816,9 @@ "Choose the type of virtual system to install:": "Vyberte, aký typ VM chcete vytvoriť:", "Choose what to do with the selected disk:": "Vyberte, čo sa má urobiť s vybraným diskom:", "Choose where to save the backup:": "Vyberte, kam uložiť zálohu:", + "Chrome is the official web browser from Google, built to be fast, secure, and customizable.": "Chrome je oficiálny webový prehliadač z Google, postavený tak, aby bol rýchly, bezpečný a prispôsobiteľný.", + "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.": "Chromium je open-source prehliadač projekt, ktorého cieľom je vybudovať bezpečnejší, rýchlejší a stabilnejší spôsob, ako pre všetkých užívateľov zažiť web.", + "Circular dependency:": "Okružná závislosť:", "Clean disk metadata": "Vyčistiť metadáta disku", "Cleaned up": "Vyčistená", "Cleaning cached files...": "Čistím uložené dočasné súbory...", @@ -611,21 +842,30 @@ "Clearing login credentials...": "Mažem prihlasovacie údaje...", "Client (run a bandwidth test to a server)": "Klient (spustí test priepustnosti voči serveru)", "Client determines best version to use": "Klient si vyberie najvhodnejšiu verziu", + "Clients reach the VPN through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Klienti sa dostanú k VPN prostredníctvom verejnej adresy a portu UDP daného počas inštalácie, takže port musí byť odoslaný do tohto kontajnera.", "Cloning Coral driver repository (feranick fork)...": "Klonujem repozitár ovládača Coral (feranick fork)...", "Cloning Lynis from GitHub...": "Klonujem Lynis z GitHubu...", "Cloning and applying NVIDIA patch (keylase/nvidia-patch)...": "Klonujem a používam NVIDIA patch (keylase/nvidia-patch)...", "Closed": "Zatvorené", + "Cloud Database Manager.": "Správca databázy cloud.", + "Cloud storage synchronization and FUSE mounts": "Synchronizácia cloudového úložiska a pripojenia FUSE", "Cloud-Init Automated Installers": "Automatické inštalátory cez Cloud-Init", "Cluster certificates updated": "Certifikáty klastra aktualizované", "Cluster configuration (advanced)": "Nastavenie klastra (pokročilé)", "Cluster data will be applied automatically at next boot.": "Dáta klastra sa použijú automaticky pri ďalšom štarte.", "Cluster upgrade mode": "Režim aktualizácie klastra", + "Code-server is VS Code running on a remote server, accessible through the browser.": "Kód server je VS kód beží na vzdialenom serveri, prístupný cez prehliadač.", + "CodeProject.AI Server": "CodeProject. AI Server", "Command": "Príkaz", + "Command override for an unknown service:": "Prepísať príkaz pre neznámu službu:", "Commenting any residual Bookworm lines in *.list...": "Komentujem zostávajúce riadky Bookworm v *.list...", "Commenting legacy PVE 8 repository .list files (if any)...": "Komentujem staré .list súbory repozitárov PVE 8 (ak existujú)...", "Commenting legacy ceph.list (if present)...": "Komentujem starý ceph.list (ak existuje)...", "Common Issues Check": "Kontrola bežných problémov", + "Common root for the published views": "Spoločný koreň uverejnených názorov", + "Communication & Community": "Komunikácia a Spoločenstvo", "Community Scripts": "Komunitné skripty", + "Community single-container Home Assistant OS image": "Jednoduchý kontajner Spoločenstva Home Assistant OS image", "Compatibility check": "Kontrola kompatibility", "Compatibility check — OK": "Kontrola kompatibility - OK", "Compatibility check — issues detected": "Kontrola kompatibility - zistené problémy", @@ -640,24 +880,31 @@ "Complete restore": "Úplná obnova", "Complete the DSM installation wizard": "Dokončite sprievodcu inštaláciou DSM", "Complete the ZimaOS installation wizard": "Dokončite sprievodcu inštaláciou ZimaOS", + "Complete the media server and Seerr accounts, the Bazarr providers and the SABnzbd Usenet credentials when they are selected.": "Dokončiť mediálny server a Seerr účtov, poskytovatelia Bazarr a SABnzbd Usenet credentials, keď sú vybraní.", + "Completed": "Dokončené", "Completed Successfully with GPU passthrough configured!": "Úspešne dokončené aj s nastaveným priamym priradením GPU.", "Completed Successfully!": "Úspešne dokončené.", "Completed with errors —": "Dokončené s chybami -", "Completed.": "Dokončené.", "Completed. Devices added to VM {vmid}: {count}.": "Dokončené. Zariadenia pridané do VM {vmid}: {count}.", "Completed. Press Enter to return to menu...": "Dokončené. Stlačte Enter pre návrat do menu...", + "Completing its final cleanup...": "Dokončiť záverečné čistenie...", "Completing pending package configurations...": "Dokončenie čakajúcich konfigurácií balíka...", "Compliance checking (PCI-DSS, HIPAA, etc.)": "kontroly súladu (PCI-DSS, HIPAA atď.)", "Component to uninstall manually (no --auto-uninstall yet):": "Súčasť na ručné odinštalovanie (zatiaľ bez --auto-uninstall):", "Component was installed on the backup source but no matching hardware was found on this host.": "Súčasť bola nainštalovaná na zdrojovom hostovi zálohy, ale na tomto hostovi sa nenašiel zodpovedajúci hardvér.", "Component:": "Súčasť:", "Components to uninstall (manual for now):": "Súčasti na odinštalovanie (zatiaľ ručne):", + "Compose capabilities validated in the LXC user namespace:": "Skladanie schopností validovaných v LXC užívateľskom priestore:", + "Compose file of the application": "Zostaviť súbor žiadosti", + "Compose file of this host": "Zostaviť súbor tohto hostiteľa", "Compressed size:": "Veľkosť po kompresii:", "Compressing": "Komprimujem", "Compression Tools": "Kompresné nástroje", "Concise output of logical volumes": "Stručný výpis logických zväzkov", "Concise output of physical volumes": "Stručný výpis fyzických zväzkov", "Concise output of volume groups": "Stručný výpis skupín zväzkov", + "Concurrent change while restoring the start at boot setting": "Súčasná zmena pri obnovení štartu pri štarte", "Configuration Analysis": "Analýza nastavenia", "Configuration Menu": "Nastavenia", "Configuration Summary:": "Zhrnutie nastavenia:", @@ -666,11 +913,13 @@ "Configuration can continue now and will be effective after reboot.": "V nastavení môžete pokračovať teraz, prejaví sa po reštarte.", "Configuration completed successfully!": "Nastavenie bolo úspešne dokončené.", "Configuration file for container": "Konfiguračný súbor pre kontajner", + "Configuration files generated:": "Konfiguračné súbory generované:", "Configuration has been stopped due to high reset risk.": "Nastavenie bolo zastavené pre vysoké riziko resetu.", "Configuration has been stopped to prevent an unusable VM state.": "Nastavenie bolo zastavené, aby VM nezostala v nepoužiteľnom stave.", "Configuration has been stopped to prevent leaving the VM in an unusable state.": "Nastavenie bolo zastavené, aby sa VM neponechala v nepoužiteľnom stave.", "Configuration name:": "Názov nastavenia:", "Configuration sections that will be REMOVED": "Časti nastavenia, ktoré sa ODSTRÁNIA", + "Configuration size in GB": "Veľkosť konfigurácie v GB", "Configuration to be Removed": "Nastavenie na odstránenie", "Configuration will continue now and be effective after reboot.": "Nastavenie bude teraz pokračovať a prejaví sa po reštarte.", "Configuration:": "Konfigurácia:", @@ -713,6 +962,7 @@ "Configuring Proxmox jail...": "Nastavujem Proxmox jail...", "Configuring TCP optimizations...": "Nastavujem TCP optimalizácie...", "Configuring TPM device": "Nastavujem TPM zariadenie", + "Configuring Unpackerr...": "Nastavujem Unpackerr...", "Configuring VFIO modules...": "Nastavujem VFIO moduly...", "Configuring VM": "Nastavujem VM", "Configuring bandwidth limit for vzdump...": "Nastavujem limit priepustnosti pre vzdump...", @@ -728,8 +978,11 @@ "Configuring max FD limit / ulimit...": "Nastavujem maximálny FD limit / ulimit...", "Configuring max user watches...": "Nastavujem maximálny počet user watches...", "Configuring pigz as a faster replacement for gzip...": "Nastavujem pigz ako rýchlejšiu náhradu za gzip...", + "Configuring qBittorrent...": "Nastavujem qBittorrent...", "Configuring snapshot schedules...": "Nastavujem plán snapshotov...", "Configuring system time settings...": "Nastavujem systémový čas...", + "Configuring the Radarr root folder...": "Nastavujem koreňový priečinok Radarr...", + "Configuring the Sonarr root folder...": "Nastavujem koreňový priečinok Sonarr...", "Configuring vfio-pci binding...": "Nastavujem vfio-pci naviazanie...", "Confirm Borg passphrase": "Potvrďte Borg frázu", "Confirm Borg passphrase:": "Potvrďte Borg frázu:", @@ -751,6 +1004,7 @@ "Confirm export": "Potvrdiť export", "Confirm password for": "Potvrďte heslo pre", "Confirm recovery passphrase:": "Potvrďte obnovovaciu frázu:", + "Confirm that host data is not reverted": "Potvrďte, že údaje hostiteľa nie sú vrátené", "Confirm the keyfile passphrase:": "Potvrďte frázu keyfile:", "Confirm the mount path is visible.": "Overte, že cesta pripojenia je viditeľná.", "Confirm the password:": "Potvrďte heslo:", @@ -762,7 +1016,11 @@ "Conflicting path included in backup:": "Konfliktná cesta zahrnutá v zálohe:", "Conflicting utilities removed": "Konfliktné nástroje odstránené", "Connect a Coral Accelerator and try again.": "Pripojte Coral Accelerator a skúste to znova.", + "Connect your devices and users together in your own secure virtual private network.": "Spojte svoje zariadenia a užívateľov vo vlastnej zabezpečenej virtuálnej súkromnej sieti.", + "Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.": "Pripojte svoje zariadenia do zabezpečenej prekryvnej siete založenej na WireGuard® s ovládacími prvkami SSO, MFA a granulovaného prístupu.", "Connected": "Pripojené", + "Connecting Radarr to qBittorrent...": "Pripojenie Radarr k qBittorrent...", + "Connecting Sonarr to qBittorrent...": "Pripojenie Sonarr k qBittorrent...", "Connecting to PBS and starting backup...": "Pripájam sa k PBS a spúšťam zálohovanie...", "Connection Details:": "Detaily pripojenia:", "Connection Error": "Chyba pripojenia", @@ -774,6 +1032,7 @@ "Consider removing its configuration": "Zvážte odstránenie jeho nastavenia", "Consider security implications for production environments": "V produkčnom prostredí zvážte bezpečnostné dôsledky", "Consider visiting the repository and supporting the project.": "Zvážte návštevu repozitára a podporu projektu.", + "Console log:": "Konzolový log:", "Container": "Kontajner", "Container — LXC root directories": "Kontajner — root priečinky LXC", "Container ID": "ID kontajnera", @@ -783,30 +1042,50 @@ "Container Path": "Cesta v kontajneri", "Container Path:": "Cesta v kontajneri:", "Container Status": "Stav kontajnera", + "Container checked": "Skontrolovaný kontajner", "Container configuration not found": "Nastavenie kontajnera sa nenašlo", + "Container configured (not started):": "Kontajner nastavený (nezačína sa):", + "Container converted to privileged": "Kontajner prevedený na privilegovaný", + "Container created:": "Vytvorený kontajner:", "Container did not become ready in time. Skipping driver installation.": "Kontajner nebol včas pripravený. Inštaláciu ovládača preskakujem.", "Container did not start in time.": "Kontajner sa nestihol spustiť.", "Container distro": "Distribúcia kontajnera", "Container does not have apt-get available. Coral driver installation only supports Debian/Ubuntu containers.": "Kontajner nemá dostupný apt-get. Inštalácia ovládača Coral podporuje iba Debian/Ubuntu kontajnery.", + "Container installed, but without a verifiable record for future updates.": "Kontajner nainštalovaný, ale bez overiteľného záznamu pre budúce aktualizácie.", "Container is already stopped.": "Kontajner už je zastavený.", "Container is running. Restart to apply changes?": "Kontajner beží. Reštartovať ho, aby sa zmeny prejavili?", "Container is stopped. Start it now to verify the mount works?": "Kontajner je zastavený. Spustiť ho teraz a overiť, či mount funguje?", + "Container kept with its data; the installation was not validated:": "Kontajner uchovávaný so svojimi údajmi; zariadenie nebolo potvrdené:", "Container mount point:": "Mount point v kontajneri:", "Container must be stopped before conversion": "Kontajner musí byť pred prevodom zastavený", + "Container prepared for the stack:": "Nádoba pripravená na zásobník:", + "Container recreated": "Zrekonštruovaný kontajner", + "Container removed:": "Odstránený kontajner:", "Container restarted successfully": "Kontajner bol úspešne reštartovaný", + "Container running steadily": "Kontajner beží plynule", + "Container started": "Spustiť kontajner", "Container started successfully": "Kontajner bol úspešne spustený", "Container started successfully.": "Kontajner bol úspešne spustený.", "Container started.": "Kontajner je spustený.", + "Container stopped": "Kontajner zastavený", "Container stopped.": "Kontajner bol zastavený.", "Container successfully converted to privileged.": "Kontajner bol úspešne zmenený na privilegovaný.", "Container template— LXC templates": "Šablóna kontajnera— LXC šablóny", + "Container volume": "Objem kontajnera", + "Container volume (included in backups)": "Objem kontajnera (zahrnutý v zálohách)", "Container will pick up the mount on next start": "Kontajner načíta mount pri ďalšom štarte", "Container with ID": "Kontajner s ID", "Container:": "Kontajner:", + "Containers & Docker": "Kontajnery a Docker", + "Containers returned to their previous state": "Kontajnery sa vrátili do predchádzajúceho stavu", + "Containers that are removed:": "Nádoby, ktoré sú odstránené:", + "Containers that will be created (one LXC per service, on a private network):": "Kontajnery, ktoré budú vytvorené (jeden LXC na službu, na súkromnej sieti):", + "Containers:": "Obaly:", "Contains files": "Obsahuje súbory", "Contains:": "Obsahuje:", "Content Types": "Typy obsahu", "Content Types:": "Typy obsahu:", + "Content collaboration platform": "Platforma spolupráce v oblasti obsahu", "Content is usually images for VM block devices.": "Obsah je zvyčajne images pre blokové zariadenia VM.", "Content type is fixed to:": "Typ obsahu je pevne nastavený na:", "Content:": "Obsah:", @@ -817,10 +1096,12 @@ "Continue the Windows installation as usual.": "Pokračujte v inštalácii Windowsu bežným spôsobom.", "Continue with Coral TPU configuration only?": "Pokračovať iba s nastavením Coral TPU?", "Continue with live apply now? SSH may disconnect immediately.": "Pokračovať použitím za behu teraz? SSH sa môže okamžite odpojiť.", + "Continue with the experimental HAOS One profile?": "Pokračovať s experimentálnym profilom HAOS One?", "Continue with the import?": "Pokračovať v importe?", "Continue: Proceed with conversion": "Pokračovať: spustiť prevod", "Continue?": "Pokračovať?", "Continuing with your selection.": "Pokračujem s vaším výberom.", + "Contradictory tmpfs options": "Možnosti kontrastných tmpfs", "Controller": "Controller", "Controller + NVMe": "Controller + NVMe", "Controller + NVMe assignment will be written now and become active after host reboot.": "Priradenie Controller + NVMe sa teraz zapíše a aktivuje sa po reštarte servera.", @@ -849,7 +1130,11 @@ "Converting disk": "Konvertujem disk", "Converting file ownership (this may take several minutes)...": "Mením vlastníctvo súborov (môže to trvať niekoľko minút)...", "Converting image using command:": "Konvertujem obraz pomocou príkazu:", + "Converting the container to privileged...": "Konverzia kontajnera na privilegovaný...", "Converts to deb822; keeps .list backups as .bak": "Prevedie na deb822; zálohy .list ponechá ako .bak", + "Coordinated backups require zstd": "Koordinované zálohy require zstd", + "Cops by Sébastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server.": "Cops by Sébastien Lucas, teraz udržiavané MikesPub, znamená Calibre OPDS (a HTML) Php Server.", + "Copy a peer configuration to the host with: pct pull /config/peer1/peer1.conf peer1.conf": "Kopírovať konfiguráciu peer k hostiteľovi s: pct pull < CTID > /config/peer1/peer1.conf peer1.conf", "Copy failed": "Kopírovanie zlyhalo", "Copy that file offsite yourself, or download it from the Monitor.": "Skopírujte si tento súbor mimo servera sami alebo ho stiahnite z Monitoru.", "Copy the correct keyfile to this host and rerun Restore — or pick an unencrypted backup.": "Skopírujte správny keyfile na tento host a spustite obnovu znova - alebo vyberte nešifrovanú zálohu.", @@ -864,6 +1149,7 @@ "Coral M.2 Apex configuration added - device ready": "Nastavenie Coral M.2 Apex bolo pridané - zariadenie je pripravené", "Coral M.2 Apex configuration added - device will be available after reboot": "Nastavenie Coral M.2 Apex bolo pridané - zariadenie bude dostupné po reštarte", "Coral M.2 Apex detected, configuring...": "Našiel sa Coral M.2 Apex, nastavujem...", + "Coral PCIe/M.2 node (e.g. /dev/apex_0)": "Coral PCIe/M.2 uzly (napr. /dev/apex 0)", "Coral TPU Installation": "Inštalácia Coral TPU", "Coral TPU Uninstall": "Odinštalovanie Coral TPU", "Coral TPU device nodes detected with correct group (apex).": "Uzly zariadenia Coral TPU sa našli so správnou skupinou (apex).", @@ -876,19 +1162,33 @@ "Coral USB configured but device not currently connected": "Coral USB je nastavený, ale zariadenie momentálne nie je pripojené", "Coral USB runtime installed. No reboot required.": "Coral USB runtime bol nainštalovaný. Reštart nie je potrebný.", "Coral hardware configuration completed for container": "Nastavenie Coral hardvéru bolo dokončené pre kontajner", + "Coral is only offered for Frigate and CodeProject.AI": "Coral je ponúkaná len pre Frigate a CodeProject. AI", "Coral kernel modules unloaded.": "Kernel moduly Coral boli uvoľnené.", "Coral packages purged.": "Balíky Coral boli úplne odstránené.", "Coral uninstallation completed.": "Odinštalovanie Coral je hotové.", "Core Proxmox packages reinstalled successfully": "Základné balíky Proxmoxu boli úspešne preinštalované", + "Core is running, but not responding over HTTP on 80/8123": "Jadro beží, ale neodpovedá cez HTTP na 80/8123", + "Core is still on the initial installation page": "Jadro je stále na úvodnej inštalačnej stránke", "Core packages": "Základné balíky", + "Cores": "Jadro", + "Corrupted gzip layer": "Vrstvená vrstva gzipu", "Could not add": "Nepodarilo sa pridať", "Could not add disk": "Disk sa nepodarilo pridať", + "Could not add the device to the container:": "Nepodarilo sa pridať zariadenie do kontajnera:", + "Could not add the mount point:": "Nepodarilo sa pridať bod pripojenia:", + "Could not apply the Compose extra hosts": "Nepodarilo sa použiť extra hostiteľov", + "Could not apply the Compose supplementary groups": "Nepodarilo sa použiť zostavu doplnkových skupín", + "Could not apply the Jellyfin configuration:": "Nepodarilo sa použiť konfiguráciu Jellyfin:", + "Could not apply the installer profile": "Nepodarilo sa použiť profil inštalátora", + "Could not apply the pre-start repair:": "Nepodarilo sa použiť predštartovaciu opravu:", "Could not assign disk": "Disk sa nepodarilo priradiť", "Could not authorize the key via 'pct exec' on": "Kľúč sa nepodarilo autorizovať cez 'pct exec' na", "Could not back up the existing auth.json": "Existujúci auth.json sa nepodarilo zálohovať", "Could not change VM virtual display to vga: std": "Virtuálne zobrazenie VM sa nepodarilo zmeniť na vga: std", + "Could not check the NVIDIA GPU": "Nepodarilo sa skontrolovať GPU NVIDIA", "Could not clone any gasket-driver repository. Check your internet connection and": "Nepodarilo sa naklonovať žiadny repozitár gasket-driver. Skontrolujte internetové pripojenie a", "Could not configure IOMMU kernel parameters automatically. Configure manually and reboot.": "Parametre kernelu pre IOMMU sa nepodarilo nastaviť automaticky. Nastavte ich ručne a reštartujte.", + "Could not convert the OCI rootfs to privileged": "Nepodarilo sa previesť OCI rootfs na privilegované", "Could not copy the PVE keyfile into place. Check permissions on:": "PVE keyfile sa nepodarilo skopírovať na správne miesto. Skontrolujte oprávnenia na:", "Could not copy the keyfile into place.": "Keyfile sa nepodarilo skopírovať na správne miesto.", "Could not copy the keyfile into place. Check permissions on:": "Keyfile sa nepodarilo skopírovať na správne miesto. Skontrolujte oprávnenia na:", @@ -898,6 +1198,9 @@ "Could not create or access directory:": "Priečinok sa nepodarilo vytvoriť alebo otvoriť:", "Could not create temporary directory:": "Dočasný priečinok sa nepodarilo vytvoriť:", "Could not create temporary working directory.": "Dočasný pracovný priečinok sa nepodarilo vytvoriť.", + "Could not create the container:": "Nepodarilo sa vytvoriť kontajner:", + "Could not create the initial administrator": "Nepodarilo sa vytvoriť začiatočného správcu", + "Could not create the service:": "Nepodarilo sa vytvoriť službu:", "Could not detect apex major number from /proc/devices. Load the apex module first: modprobe apex": "Nepodarilo sa zistiť major číslo apex z /proc/devices. Najprv načítajte modul apex: modprobe apex", "Could not detect the CIFS mount for this directory. Try accessing it manually.": "Pre tento priečinok sa nepodarilo zistiť CIFS mount. Skúste ho otvoriť ručne.", "Could not determine a valid ISO storage directory.": "Nepodarilo sa určiť platný priečinok pre ISO úložisko.", @@ -907,7 +1210,9 @@ "Could not download recovery blob from PBS.": "Nepodarilo sa stiahnuť obnovovací balíček z PBS.", "Could not download the NVIDIA Container Toolkit repository definition.": "Nepodarilo sa stiahnuť definíciu úložiska NVIDIA Container Toolkit.", "Could not download the NVIDIA Container Toolkit signing key.": "Nepodarilo sa stiahnuť podpisový kľúč NVIDIA Container Toolkit.", + "Could not download the image": "Nepodarilo sa stiahnuť obrázok", "Could not download the installer.": "Inštalátor sa nepodarilo stiahnuť.", + "Could not enable the privileged profile before the first start": "Nepodarilo sa povoliť privilegovaný profil pred prvým začiatkom", "Could not export ZFS pool": "ZFS pool sa nepodarilo exportovať", "Could not extract from PBS.": "Nepodarilo sa rozbaliť dáta z PBS.", "Could not fetch keylase/nvidia-patch supported list — patch reapply compatibility is not verified.": "Nepodarilo sa načítať zoznam podporovaných verzií pre keylase/nvidia-patch - kompatibilita opätovného použitia patchu nie je overená.", @@ -921,34 +1226,53 @@ "Could not install exFAT tools automatically.": "Nástroje exFAT sa nepodarilo nainštalovať automaticky.", "Could not install sshpass automatically (no internet?). Falling back to manual paste mode — you'll see the line to copy onto the server next.": "sshpass sa nepodarilo nainštalovať automaticky (bez internetu?). Prepínam na ručné vloženie - hneď uvidíte riadok, ktorý treba skopírovať na server.", "Could not install the NVIDIA Container Toolkit signing key.": "Nepodarilo sa nainštalovať podpisový kľúč NVIDIA Container Toolkit.", + "Could not install the required packages:": "Nepodarilo sa nainštalovať required balíčky:", + "Could not install the stack startup hook": "Nepodarilo sa nainštalovať stack štartovací hák", "Could not install vzdump hook in /etc/vzdump.conf": "Nepodarilo sa nainštalovať vzdump hook do /etc/vzdump.conf", "Could not load shared functions. Script cannot continue.": "Nepodarilo sa načítať zdieľané funkcie. Skript nemôže pokračovať.", + "Could not load the host kernel module:": "Nepodarilo sa načítať modul hostiteľského jadra:", "Could not locate imported disk in VM config.": "Importovaný disk sa nepodarilo nájsť v nastavení VM.", "Could not mount": "Nepodarilo sa pripojiť", "Could not mount ISO on device": "ISO sa nepodarilo pripojiť k zariadeniu", + "Could not mount the container filesystem:": "Nepodarilo sa pripojiť súborový systém kontajnera:", + "Could not obtain an intact image after two attempts": "Nepodarilo sa získať neporušený obraz po dvoch pokusoch", "Could not parse OVF file, or no disk image references found.": "OVF súbor sa nepodarilo spracovať alebo neobsahuje odkazy na diskové obrazy.", "Could not prepare on-boot restore service. Nothing new was scheduled.": "Nepodarilo sa pripraviť službu obnovenia pri spustení. Nič nové nebolo naplánované.", + "Could not prepare the NVIDIA driver links": "Nepodarilo sa pripraviť odkazy na ovládač NVIDIA", + "Could not prepare the file bind mount target:": "Nepodarilo sa pripraviť cieľ pripojenia súboru:", "Could not publish pending restore. Previous pending restore was kept.": "Nepodarilo sa zverejniť čakajúce obnovenie. Predchádzajúce čakajúce obnovenie bolo zachované.", "Could not push the key. Check the password and that": "Kľúč sa nepodarilo odoslať. Skontrolujte heslo a to, že", + "Could not query the image registry": "Nepodarilo sa nájsť obrazový register", "Could not read SMART data from": "SMART dáta sa nepodarilo prečítať z", "Could not read VM configuration.": "Nastavenie VM sa nepodarilo prečítať.", + "Could not read the CUDA compute capability": "Nepodarilo sa prečítať výpočtovú schopnosť CUDA", + "Could not read the NVIDIA driver version": "Nepodarilo sa prečítať verziu ovládača NVIDIA", "Could not remount automatically. Try manually or check credentials.": "Automatické znovupripojenie zlyhalo. Skúste to ručne alebo skontrolujte prihlasovacie údaje.", "Could not remove VM automatically. Run manually:": "VM sa nepodarilo odstrániť automaticky. Spustite ručne:", "Could not remove previous DKMS tree at": "Nepodarilo sa odstrániť predchádzajúci DKMS strom v", + "Could not reserve a private network for the stack": "Nepodarilo sa rezervovať súkromnú sieť pre stack", + "Could not resolve the Compose user:": "Nepodarilo sa vyriešiť používateľa Compose:", + "Could not resolve the OCI manifest of the image:": "Nepodarilo sa vyriešiť OCI manifest obrazu:", + "Could not resolve the OCI manifest:": "Nepodarilo sa vyriešiť manifest OCI:", "Could not restart ProxMenux Monitor service.": "Službu ProxMenux Monitor sa nepodarilo reštartovať.", "Could not restart the service — start it manually with systemctl start": "Službu sa nepodarilo reštartovať — spustite ju ručne cez systemctl start", "Could not retrieve versions list from NVIDIA. Please check your internet connection.": "Nepodarilo sa načítať zoznam verzií od NVIDIA. Skontrolujte internetové pripojenie.", + "Could not reuse the persistent disk:": "Nepodarilo sa znovu použiť trvalý disk:", "Could not run NVIDIA patch script. Please verify repository and driver version.": "NVIDIA patch skript sa nepodarilo spustiť. Skontrolujte repozitár a verziu ovládača.", "Could not set VM virtual display to vga: std": "Virtuálne zobrazenie VM sa nepodarilo nastaviť na vga: std", "Could not set boot order for": "Poradie bootovania sa nepodarilo nastaviť pre", + "Could not set the container entrypoint": "Nepodarilo sa nastaviť vstupný bod kontajnera", "Could not stage pending restore path:": "Nepodarilo sa pripraviť cestu obnovenia:", "Could not stage pending restore. Nothing new was scheduled.": "Nepodarilo sa pripraviť čakajúce obnovenie. Nič nové nebolo naplánované.", "Could not stop LXC": "LXC sa nepodarilo zastaviť", + "Could not translate the Compose command/entrypoint": "Nepodarilo sa preložiť príkaz/bod vstupu", "Could not unload nouveau module (may be in use). The blacklist will take effect after reboot. Installation will continue but a reboot will be required.": "Modul nouveau sa nepodarilo uvoľniť (možno sa práve používa). Blacklist sa prejaví po reštarte. Inštalácia bude pokračovať, ale reštart bude potrebný.", "Could not unmount": "Nepodarilo sa odpojiť", + "Could not unmount the container filesystem:": "Nepodarilo sa odpojiť súborový systém kontajnera:", "Could not unmount — disk may be busy. Removing fstab entry anyway.": "Nepodarilo sa odpojiť - disk sa možno používa. Záznam z fstab aj tak odstraňujem.", "Could not update config file.": "Konfiguračný súbor sa nepodarilo aktualizovať.", "Could not write to:": "Nepodarilo sa zapísať do:", + "Crafty Controller default login": "Crafty Controller predvolené prihlásenie", "Create Directory": "Vytvoriť priečinok", "Create GPT and one partition:": "Vytvoriť GPT a jeden oddiel:", "Create GPT partition": "Vytvoriť GPT oddiel", @@ -971,6 +1295,7 @@ "Create a fresh GPT + ext4 partition and mount it?": "Vytvoriť nový GPT + ext4 oddiel a pripojiť ho?", "Create a new dataset in a ZFS pool": "Vytvoriť nový dataset v ZFS poole", "Create a new group for isolation": "Vytvoriť novú skupinu na oddelený prístup", + "Create and edit Matroska files from a browser": "Vytvorenie a úprava Matroska súborov z prehliadača", "Create credentials file (recommended):": "Vytvoriť súbor s prihlasovacími údajmi (odporúčané):", "Create directory": "Vytvoriť priečinok", "Create export directory:": "Vytvoriť exportovaný priečinok:", @@ -982,6 +1307,7 @@ "Create scheduled backup job": "Vytvoriť naplánovanú úlohu zálohy", "Create share directory:": "Vytvoriť zdieľaný priečinok:", "Create shared directory:": "Vytvoriť zdieľaný priečinok:", + "Create this LXC in privileged mode?": "Vytvoriť tento LXC v privilegovanom režime?", "Created common remapped user": "Vytvorený spoločný remapovaný používateľ", "Created directory on host:": "Priečinok vytvorený na hoste:", "Created persistent names for": "Vytvorené trvalé názvy pre", @@ -996,6 +1322,8 @@ "Creating UID remapping for unprivileged container compatibility...": "Vytváram UID remapovanie pre kompatibilitu s neprivilegovanými kontajnermi...", "Creating VM with the above configuration": "Vytváram VM s uvedeným nastavením", "Creating VM...": "Vytváram VM...", + "Creating a backup of": "Vytvorenie zálohy", + "Creating a backup of the container...": "Vytvorenie zálohy kontajnera...", "Creating backup of configuration file...": "Vytváram zálohu konfiguračného súboru...", "Creating backup of network interfaces configuration...": "Vytváram zálohu nastavenia sieťových rozhraní...", "Creating compressed archive...": "Vytváram komprimovaný archív...", @@ -1005,6 +1333,11 @@ "Creating partition table and partition...": "Vytváram tabuľku oddielov a oddiel...", "Creating partition...": "Vytváram oddiel...", "Creating pigz wrapper script...": "Vytváram wrapper skript pre pigz...", + "Creating the backup": "Vytvorenie zálohy", + "Creating the container...": "Vytváram kontajner...", + "Creating the initial administrator...": "Vytvorenie počiatočného správcu...", + "Creating the temporary data container": "Vytvorenie dočasného dátového kontajnera", + "Creative & Design": "Creative & Design", "Credentials are correct": "Prihlasovacie údaje sú správne", "Credentials cleared. jwt_secret and API tokens preserved.": "Prihlasovacie údaje sú vymazané. jwt_secret a API tokeny zostali zachované.", "Credentials file created securely.": "Súbor s prihlasovacími údajmi bol bezpečne vytvorený.", @@ -1014,6 +1347,8 @@ "Cross-host restore: guest IDs in backup overlap live IDs on target:": "Obnova medzi hostami: ID hostí zo zálohy sa prekrývajú so živými ID na cieli:", "Cross-kernel restore — kernel-tied paths merged, not copied": "Obnova medzi kernelmi - cesty viazané na kernel boli zlúčené, nie skopírované", "Cross-kernel — paths hidden from picker": "Rozdielny kernel - cesty skryté vo výbere", + "Cross-platform file sharing made easy.": "Cross-platform súboru zdieľanie jednoduché.", + "Cross-platform monitoring tool.": "Monitorovací nástroj s viacerými platformami.", "Cross-version detected — safe restore mode": "Zistená rozdielna verzia - bezpečný režim obnovy", "Current": "Aktuálne", "Current CIFS mounts:": "Aktuálne CIFS pripojenia:", @@ -1023,6 +1358,8 @@ "Current NFS client script supports privileged LXC only.": "Aktuálny skript NFS klienta podporuje iba privilegovaný LXC.", "Current NFS exports in CT": "Aktuálne NFS exporty v CT", "Current NFS mounts:": "Aktuálne NFS pripojenia:", + "Current NVIDIA inventory resolved: a refresh is required": "Aktuálne NVIDIA inventár vyriešený: obnovovanie je required", + "Current NVIDIA inventory resolved: no refresh is required": "Aktuálne NVIDIA inventár vyriešený: žiadne obnovenie je required", "Current Network Configuration": "Aktuálne nastavenie siete", "Current PVE Version": "Aktuálna verzia PVE", "Current ProxMenux host scripts register remote shares as Proxmox storages using pvesm.": "Aktuálne host skripty ProxMenux registrujú vzdialené zdieľania ako úložiská Proxmoxu pomocou pvesm.", @@ -1046,6 +1383,7 @@ "Current user": "Aktuálny používateľ", "Current user UID, GID and groups": "UID, GID a skupiny aktuálneho používateľa", "Current version:": "Aktuálna verzia:", + "Currently": "Aktuálne", "Currently Mounted:": "Aktuálne pripojené:", "Currently configured target:": "Aktuálne nastavený cieľ:", "Currently mounted:": "Aktuálne pripojené:", @@ -1066,6 +1404,7 @@ "Custom message added to MOTD": "Vlastná správa bola pridaná do MOTD", "Custom options": "Vlastné možnosti", "Custom path": "Vlastná cesta", + "Custom path cancelled": "Vlastná cesta zrušená", "Custom path...": "Vlastná cesta...", "Custom paths are included in BOTH default and custom backup profiles.": "Vlastné cesty sú zahrnuté v predvolenom aj vlastnom profile zálohy.", "Custom paths currently saved: {count}.": "Aktuálne uložené vlastné cesty: {count}.", @@ -1078,6 +1417,8 @@ "Customization": "Prispôsobenie", "Customize bashrc": "Prispôsobiť bashrc", "Customizing bashrc for root user...": "Upravujem bashrc pre používateľa root...", + "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite.": "DB prehliadač pre SQLite je vysoko kvalitný, vizuálny, open source nástroj na vytváranie, navrhovanie a úpravu databázových súborov kompatibilných so SQLite.", + "DHCP (automatic)": "DHCP (automatické)", "DISABLED unless you enable it": "VYPNUTÉ, kým to nezapnete", "DKMS add failed. Check": "Pridanie do DKMS zlyhalo. Skontrolujte", "DKMS build failed.": "DKMS zostavenie zlyhalo.", @@ -1090,15 +1431,34 @@ "DKMS registrations removed.": "registrácie DKMS boli odstránené.", "DNS Resolution": "Preklad DNS", "DNS lookup for a domain": "DNS vyhľadanie domény", + "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)": "DNS plugin použitý s dns validácia (cloudflare, duckdns, ovh...)", + "DNS server written in the client configurations": "DNS server napísaný v klientskych konfiguráciách", + "DNS server written in the peer configurations (auto or an IP address)": "DNS server napísaný v peer konfiguráciách (auto alebo IP adresa)", + "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid.": "DOGWALK je Blender Štúdio dlho očakávaný druhý herný projekt, zameraný na vytvorenie uhryznutie-veľké interaktívne rozprávanie príbehov ihrisko. Hrať ako veľký rozkošný pes a preskúmať zimné lesy s malým dieťaťom.", + "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games.": "DOSBox Staging je moderné pokračovanie DOSBoxu zadarmo a open-source emulátor, ktorý umožňuje realizáciu MS-DOS softvéru, najmä videohry.", + "DVB device directory": "Adresár zariadení DVB", + "Data": "Údaje", + "Data location": "Umiestnenie údajov", "Data size:": "Veľkosť dát:", + "Data that is deleted with them:": "Údaje, ktoré sa spolu s nimi vypúšťajú:", + "Data volume size in GB": "Veľkosť dátového objemu v GB", + "Data volumes protected": "Chránené objemy údajov", "Data wipe complete.": "Vymazanie dát je dokončené.", "Data wiped from": "Dáta boli vymazané z", + "Database management in a single PHP file": "Správa databáz v jednom PHP súbore", + "Database server proposed on the login page (empty = typed at each login)": "Databázový server navrhnutý na prihlasovacej stránke (prázdne = zadané pri každom prihlásení)", + "Databases": "Databázy", "Datastore name:": "Názov datastore:", + "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow.": "Davos je nástroj na automatizáciu FTP, ktorý pravidelne skenuje ubytovacie miesta pre nové súbory. To môže byť nakonfigurovaný pre rôzne účely, vrátane počúvania pre konkrétne súbory sa objaví v mieste hostiteľa, pripravený na stiahnutie a potom presunúť, ak required. Podporuje aj oznámenia o dokončení, ako aj následné výzvy týkajúce sa API na podporu pracovného postupu.", + "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways.": "Ddclient je Perl klient používaný na aktualizáciu dynamických položiek DNS pre účty na Dynamic DNS Network Service Provider. Pôvodne bol napísaný Paulom Burrym a teraz je väčšinou zbabelý. Má schopnosť aktualizovať viac ako len dyndns a môže priniesť WAN-ipaddress niekoľkými rôznymi spôsobmi.", "Deactivate Monitor": "Vypnúť Monitor", "Deactivate ProxMenux Monitor": "Vypnúť ProxMenux Monitor", "Debian repositories missing; creating default source file": "Debian repozitáre chýbajú; vytváram predvolený zdrojový súbor", "Decompress backup manually": "Ručne rozbaliť zálohu", "Decryption failed. The passphrase may be wrong, or the blob is corrupt. Try again?": "Dešifrovanie zlyhalo. Fráza môže byť nesprávna alebo je balíček poškodený. Skúsiť znova?", + "Dedicated container volume (included in backups)": "Dedikovaný objem kontajnera (zahrnutý do zálohy)", + "Dedicated container volumes (included in backups)": "Vyhradené objemy kontajnerov (zahrnuté do záloh)", + "DeepSeek Harness “Everything is a Plugin“.": "DeepSeek Harness, všetko je Plugin.", "Default ACLs applied for group inheritance.": "Predvolené ACL boli použité pre dedenie skupiny.", "Default Credentials": "Predvolené prihlasovacie údaje", "Default Gateway": "Predvolená brána", @@ -1110,10 +1470,12 @@ "Default journald configuration restored": "Predvolené nastavenie journald bolo obnovené", "Default location is /mnt/. The share will be mounted here on the host with open permissions so an unprivileged LXC can bind-mount and write to it. For LXC access, bind-mount this path with the LXC Mount Manager.": "Predvolené umiestnenie je /mnt/. Zdieľanie sa na hostovi pripojí sem s otvorenými oprávneniami, aby ho neprivilegovaný LXC mohol pripojiť ako bind mount a zapisovať doň. Pre prístup z LXC pripojte túto cestu cez Správcu LXC mountov ako bind mount.", "Default location is /mnt/. The share will be mounted here on the host. Use this path in /etc/fstab. For LXC access, bind-mount this path with the LXC Mount Manager.": "Predvolené umiestnenie je /mnt/. Zdieľanie sa na hostovi pripojí sem. Túto cestu použite v /etc/fstab. Pre prístup z LXC pripojte túto cestu cez Správcu LXC mountov ako bind mount.", + "Default login": "Štandardné prihlásenie", "Default options": "Predvolené možnosti", "Default options read/write": "Predvolené možnosti čítanie/zápis", "Default will be used:": "Použije sa predvolené:", "Default:": "Predvolené:", + "Default: only what the application needs": "Štandardne: len to, čo aplikácia potrebuje", "Delete Borg target": "Vymazať Borg cieľ", "Delete Export": "Vymazať export", "Delete Share": "Vymazať zdieľanie", @@ -1122,7 +1484,10 @@ "Delete archive": "Vymazať archív", "Delete job": "Vymazať úlohu", "Delete scheduled backup job?": "Vymazať naplánovanú úlohu zálohy?", + "Delete the image to free the space?": "Odstrániť obrázok na voľné miesto?", + "Delete the images to free the space?": "Odstrániť obrázky na voľné miesto?", "Delete this corrupt archive and pick another": "Vymazať tento poškodený archív a vybrať iný", + "Deluge is a lightweight, Free Software, cross-platform BitTorrent client.": "Deluge je ľahký, Free Software, cross-platform BitTorrent klient.", "Dependencies installed successfully": "Závislosti boli úspešne nainštalované", "Deploy with this configuration?": "Nasadiť s týmto nastavením?", "Deploying Secure Gateway...": "Nasadzuje sa Secure Gateway...", @@ -1177,9 +1542,15 @@ "Device added": "Zariadenie pridané", "Device already present in target VM — existing hostpci entry reused": "Zariadenie už je v cieľovej VM - existujúca hostpci položka sa použila znova", "Device assignments will be written now and become active after reboot.": "Priradenia zariadení sa zapíšu teraz a aktivujú sa po reštarte.", + "Device configuration cancelled": "Konfigurácia zariadenia zrušená", "Device hostname": "Hostname zariadenia", + "Device node outside the supported profiles": "Uzol zariadenia mimo podporovaných profilov", + "Device outside the supported profiles; NVIDIA and device trees require another profile": "Zariadenie mimo podporovaných profilov; NVIDIA a zariadenia stromy require iný profil", "Device path mismatch. Format cancelled.": "Cesta zariadenia nesedí. Formátovanie zrušené.", + "Device permissions verified for the application user": "Práva zariadenia overené pre užívateľa aplikácie", "Device:": "Zariadenie:", + "Devices added to the container:": "Zariadenia pridané do kontajnera:", + "Devices of the host it asks for:": "Zariadenia hostiteľa, o ktoré žiada:", "Devices to add to VM": "Zariadenia na pridanie do VM", "Diff: current system vs backup (--- system +++ backup)": "Rozdiel: aktuálny systém vs záloha (--- systém +++ záloha)", "Different host. Backup from:": "Iný host. Záloha z:", @@ -1196,6 +1567,8 @@ "Directory does not exist and was not created.": "Priečinok neexistuje a nebol vytvorený.", "Directory does not exist:": "Priečinok neexistuje:", "Directory error": "Chyba priečinka", + "Directory for the read-only view": "Adresár pre zobrazenie len na čítanie", + "Directory for the read/write view": "Adresár pre zobrazenie čítania/písania", "Directory not found": "Priečinok sa nenašiel", "Directory storage added successfully to Proxmox!": "Priečinkové úložisko bolo úspešne pridané do Proxmoxu!", "Directory successfully.": "Priečinok je pripravený.", @@ -1248,6 +1621,7 @@ "Disk path:": "Cesta k disku:", "Disk safety revalidation failed.": "Opätovná bezpečnostná kontrola disku zlyhala.", "Disk safety validation passed.": "Bezpečnostná kontrola disku prešla.", + "Disk too small for the common profile": "Disk príliš malý pre spoločný profil", "Disk unmounted from": "Disk odpojený z", "Disk verified and accessible inside CT at": "Disk bol overený a je dostupný v CT na", "Disk:": "Disk:", @@ -1261,6 +1635,10 @@ "Display physical volumes (LVM)": "Zobraziť fyzické zväzky (LVM)", "Display system summary in ASCII format": "Zobraziť stručný prehľad systému v termináli", "Display volume groups (LVM)": "Zobraziť skupiny zväzkov (LVM)", + "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer.": "Nepredpokladajte, že port 8123 zostane aktívny po nalodení na Home Assistant Core 2026.8 alebo novšie.", + "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume.": "Nevyhlasujte, že aktualizácie obrazu OCI sú validované na mieste, kým sa neotestujú rootfs náhrada a rollback bez straty riadeného /mnt/data objemu.", + "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default.": "Nepovoľovať automaticky na nepodporovaných integrovaných GPU AMD. HSA sú manuálne kompatibilné experimenty, nie validované predvolené.", + "Do not mount": "Nepripojiť", "Do not run the upgrade from the Web UI virtual console (it will disconnect)": "Nespúšťajte aktualizáciu z virtuálnej konzoly vo webovom rozhraní (odpojí sa)", "Do not start the VM until the system has been rebooted.": "VM nespúšťajte, kým sa systém nereštartuje.", "Do you want ProxMenux to stop it now?": "Chcete, aby ju ProxMenux teraz zastavil?", @@ -1304,9 +1682,23 @@ "Do you want to update the existing export?": "Chcete aktualizovať existujúci export?", "Do you want to update the existing share?": "Chcete aktualizovať existujúce zdieľanie?", "Do you want to view the selected backup before restoring?": "Chcete si vybranú zálohu pred obnovou pozrieť?", + "Docker Mods are only offered for compatible LinuxServer images": "Docker Mods sú ponúkané len pre kompatibilné LinuxServer obrázky", + "Docker Volume Backup": "Docker Volume Backup", + "Docker/CLI not available yet or no valid answer": "Docker/CLI ešte nie je k dispozícii alebo nie je platná odpoveď", + "Documents & Notes": "Dokumenty a poznámky", + "Documents volume size in GB": "Veľkosť objemu dokumentov v GB", + "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki.": "Dokuwiki je jednoduché použitie a vysoko univerzálny softvér Open Source wiki, ktorý nerequire databázu. Používatelia ho milujú pre jeho čistú a čitateľnú syntax. Jednoduchosť údržby, zálohovania a integrácie z neho robí administrátora obľúbeným. Postavený v prístupových a autentifikačných konektorov, aby DokuWiki obzvlášť užitočné v podnikovom kontexte a veľký počet pluginov, ktoré prispeli jeho pulzujúce komunity umožňujú širokú škálu prípadov použitia mimo tradičné wiki.", + "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience.": "Dolphin Emulator vám umožní hrať hryCube a Wii hry s rôznymi grafickými vylepšeniami a ďalšie funkcie sú k dispozícii pre zlepšenie herné skúsenosti.", + "Domain for the certificate (example.com)": "Doména pre osvedčenie (príklad.com)", + "Doplarr is an *arr request bot for Discord.\"": "Doplarr je robot pre Discord.", + "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust.": "Doplarr_rs je robot Discord pre žiadanie médií cez arr backends, napísané v Rust.", + "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas.": "Double Commander je free cross platform open source správca súborov s dvoma panelmi vedľa seba. Je inšpirovaný Total Commander a obsahuje niektoré nové nápady.", + "Download Spotify music with album art and metadata": "Stiahnuť Spotify hudbu s albumom a metadátami", "Download failed for all attempted URLs": "Sťahovanie zlyhalo zo všetkých vyskúšaných adries", + "Download its Compose file from an address": "Stiahnuť súbor z adresy", "Download keyfile": "Stiahnuť keyfile", "Download latest VirtIO ISO automatically": "Stiahnuť najnovšie VirtIO ISO automaticky", + "Downloaded OCI images deleted:": "Stiahnuté obrázky OCI odstránené:", "Downloaded amdgpu_top": "amdgpu_top bol stiahnutý", "Downloading": "Sťahujem", "Downloading Helper-Scripts logo...": "Sťahujem logo Helper-Scripts...", @@ -1318,45 +1710,86 @@ "Downloading amdgpu_top": "Sťahujem amdgpu_top", "Downloading official installer...": "Sťahujem oficiálny inštalátor...", "Downloading pre-existing encrypted backups from this host will fail unless you kept a copy of the current key.": "Stiahnutie už existujúcich šifrovaných záloh z tohto hosta zlyhá, ak ste si nenechali kópiu aktuálneho kľúča.", + "Downloading the image:": "Sťahovanie obrázku:", "Downloading the latest Fastfetch release...": "Sťahujem najnovšiu verziu Fastfetch...", "Driver blacklist entries removed": "Záznamy v blackliste ovládačov boli odstránené", "Driver blacklist removed for": "Blacklist ovládača odstránený pre", "Driver installed successfully. Press Enter to continue...": "Ovládač bol úspešne nainštalovaný. Stlačte Enter na pokračovanie...", "Drivers :": "Ovládače :", "Drivers compiled and installed via DKMS.": "Ovládače boli skompilované a nainštalované cez DKMS.", + "Dry run completed; no changes were made.": "Suchý beh dokončený; neboli vykonané žiadne zmeny.", + "Dry run completed; no containers were created.": "Suchý beh dokončený; neboli vytvorené žiadne kontajnery.", + "Dry run completed; the container and the mounts were not changed.": "Suchý chod dokončený; kontajner a držiaky neboli zmenené.", + "DuckDNS subdomain without .duckdns.org (comma separated for several)": "DuckDNS subdoména bez .duckdns.org (koma oddelené pre niekoľko)", + "DuckDNS token from your account at duckdns.org": "DuckDNS token z vášho účtu na duckdns.org", + "DuckDNS updates the subdomain every 5 minutes. Without UPDATE_IP, DuckDNS itself detects the public IPv4 address of the request.": "DuckDNS aktualizuje subdoménu každých 5 minút. Bez UPDATE IP samotná DuckDNS detekuje verejnú IPv4 adresu žiadosti.", + "DuckStation is a PS1 Emulator aiming for the best accuracy and game support.": "DuckStation je PS1 Emulátor zameraný na najlepšie accuracy a hernú podporu.", + "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence.": "Duckdns je bezplatná služba, ktorá bude ukazovať DNS (pod domény duckdns.org) na IP podľa vášho výberu. Služba je úplne zadarmo, a nie je require reaktivácia alebo fóra príspevky udržať jeho existenciu.", "Dumping AMD GPU ROM BIOS via sysfs...": "Vytváram dump AMD GPU ROM BIOS cez sysfs...", "Duplicate IP addresses found": "Našli sa duplicitné IP adresy", "Duplicate parameters cleaned": "Duplicitné parametre sú vyčistené", + "Duplicate variable in the contract; review it before editing": "Duplikovať premenné v zmluve; preskúmať pred úpravou", + "Duplicated GPU device in the container": "Duplikované GPU zariadenie v kontajneri", + "Duplicated NVIDIA devices": "Duplikované zariadenia NVIDIA", + "Duplicated VMID in the Proxmox inventory": "Duplikované VMID v inventári Proxmox", + "Duplicated native directive:": "Duplikát natívne smernice:", + "Duplicated native option": "Duplikované natívne možnosti", + "Duplicated or invalid stack VMID": "Duplikované alebo neplatné stoh VMID", + "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others.": "Duplicati je záložný klient, ktorý bezpečne ukladá šifrované, prírastkové, stlačené zálohy na lokálne úložisko, cloudové úložné služby a vzdialené súborové servery. Funguje so štandardnými protokolmi ako FTP, SSH, WebDAV, rovnako ako populárne služby ako Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, a mnoho ďalších.", + "Duplicati web interface (password only)": "Duplicati webové rozhranie (iba heslo)", "Duration": "Trvanie", "Duration:": "Trvanie:", + "Dynamic NVIDIA is only validated for unprivileged containers. This profile uses static mounts and must be recreated after the host driver changes.": "Dynamická NVIDIA je validovaná len pre neprivilegované kontajnery. Tento profil používa statické pripojenia a musí byť znovu vytvorený po zmene hostiteľského vodiča.", "EFI disk created and configured on": "EFI disk bol vytvorený a nastavený na", "EFI storage selection cancelled.": "Výber úložiska pre EFI bol zrušený.", "EFI storage selection failed or was cancelled. VM creation aborted.": "Výber úložiska pre EFI zlyhal alebo bol zrušený. Vytvorenie VM bolo prerušené.", "EMERGENCY PROXMOX SYSTEM REPAIR": "NÚDZOVÁ OPRAVA SYSTÉMU PROXMOX", "ENABLED for restore": "ZAPNUTÉ pre obnovu", "EXISTS": "EXISTUJE", + "Each /request command needs a backend: add a [[backends]] block in the same file with the url and api_key of your Sonarr, Radarr or Seerr instance, then restart the container.": "Každý príkaz / žiadosť potrebuje backend: pridať [[[backends]]] blok v rovnakom súbore s url a api key vášho Sonarr, Radarr alebo Seerr inštancie, potom reštartujte kontajner.", "Each LUN will appear as a block device assignable to VMs.": "Každý LUN sa zobrazí ako blokové zariadenie, ktoré sa dá priradiť k VM.", + "Each peer gets its configuration and its QR code inside the container: /config/peer1/peer1.conf and /config/peer1/peer1.png, or /config/peer_/peer_.conf when names were given.": "Každý peer dostane svoju konfiguráciu a QR kód vnútri kontajnera: /config/peer1/peer1.conf a /config/peer1/peer1.png, alebo /config/peer /peer .conf pri uvedení mien.", + "Ebook and audiobook collection manager for Usenet and BitTorrent users.": "Ebook a audioknihy správca zberu pre užívateľov Usenet a BitTorrent.", + "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind.": "Eden je experimentálny open-source emulátor pre Nintendo Switch, postavený s výkonom a stabilitou na mysli.", "Edge TPU runtime installed.": "Edge TPU runtime bol nainštalovaný.", "Edit raw CT configuration file": "Upraviť konfiguračný súbor CT", "Edit raw VM configuration file": "Upraviť konfiguračný súbor VM", "Edit the VM machine type to q35 and try again.": "Zmeňte typ stroja VM na q35 a skúste to znova.", + "Email address for certificate expiry notices (required by ZeroSSL)": "E-mailová adresa pre oznámenia o uplynutí platnosti certifikátu (required by ZeroSSL)", + "Email address of the LibreDB Studio administrator": "E-mailová adresa správcu LibreDB Studio", + "Email address of the NetBox admin account": "E-mailová adresa admin účtu NetBox", + "Emby WebUI": "Emby WebUI", + "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server.": "Emby organizuje video, hudbu, živú televíziu a fotografie z osobných mediálnych knižníc a prenáša ich do inteligentných televízorov, streamovacích skríň a mobilných zariadení. Tento kontajner je balený ako samostatný emby Media Server.", "Emergency Proxmox System Repair": "Núdzová oprava systému Proxmox", "Emergency recovery:": "Núdzová obnova:", + "Empowering the smart home": "Posilnenie inteligentného domova", "Empty": "Prázdny", + "Empty exec service check": "Prázdna kontrola exec služby", + "Empty or duplicated NVIDIA identity": "Prázdna alebo duplikovaná identita NVIDIA", + "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes.": "EmulatorJS je aplikácia Docker založená na emulátore, ktorá simuluje rôzne operatingové systémy a prostredia zariadení v kontajneroch pre vývoj, testovanie a učenie.", "Enable": "Zapnúť", "Enable / disable job timer": "Zapnúť / vypnúť timer úlohy", "Enable High Availability services": "Zapnúť služby High Availability", "Enable IOMMU in GRUB or ZFS boot": "Zapnúť IOMMU v GRUB alebo ZFS bootovaní", "Enable IOMMU support if not enabled": "Zapne podporu IOMMU, ak ešte nie je zapnutá", "Enable IOMMU, reboot the host, and try again.": "Zapnite IOMMU, reštartujte server a skúste to znova.", + "Enable Intel/AMD VA-API video acceleration": "Povoliť video zrýchlenie Intel/AMD VA-API", + "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping": "Povoliť transkódovanie NVIDIA a HDR10/Dolby Vision do mapovania SDR tónu", "Enable Remote Desktop (RDP) before disabling the virtual display.": "Pred vypnutím virtuálneho zobrazenia zapnite Vzdialenú plochu (RDP).", "Enable SSD emulation for this disk?": "Zapnúť pre tento disk emuláciu SSD?", "Enable TCP BBR/Fast Open control": "Zapnúť TCP BBR/Fast Open", + "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping": "Povoliť transkódovanie VA-API a HDR10/Dolby Vision do mapovania tónu SDR", + "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin": "Povoliť VA-API, kódovanie hardvéru a mapovanie OpenCL tónu v Jellyfin", "Enable VFIO IOMMU support": "Zapnúť podporu VFIO/IOMMU", "Enable ZFS autotrim (SSD/NVMe pools)": "Zapnúť ZFS autotrim (SSD/NVMe pooly)", + "Enable a mount on an existing Rclone OCI container": "Povoliť montáž na existujúci Rclone OCI kontajner", + "Enable an optical drive for MakeMKV": "Povoliť optický pohon pre MakeMKV", "Enable auto-sync if /var/log exceeds 90% of its size?": "Zapnúť automatickú synchronizáciu, keď /var/log presiahne 90 % svojej veľkosti?", "Enable fast reboots": "Zapnúť rýchle reštarty", "Enable restart on kernel panic": "Zapnúť reštart pri kernel panic", + "Enable the NVIDIA GPU requested by the image": "Povoliť NVIDIA GPU požadovanú obrázkom", + "Enable the NVIDIA GPU required by Open WebUI CUDA": "Povoliť NVIDIA GPU required by Open WebUI CUDA", + "Enable this FUSE mount now and restart the CT?": "Povoliť túto FUSE pripojiť teraz a reštartovať CT?", "Enable/Disable job": "Zapnúť/vypnúť úlohu", "Enabled": "Zapnuté", "Enabled (device pending — load apex module or reboot)": "Zapnuté (zariadenie čaká - načítajte modul apex alebo reštartujte)", @@ -1401,6 +1834,7 @@ "Enter a name for the mount point (used as /mnt/):": "Zadajte názov mount pointu (použije sa ako /mnt/):", "Enter a name for the new virtual machine:": "Zadajte názov novej virtuálnej mašiny:", "Enter a number, or write or paste a command:": "Zadajte číslo alebo napíšte či vložte príkaz:", + "Enter a usable IPv4 address with its prefix, for example": "Zadajte použiteľnú IPv4 adresu s predponou, napríklad", "Enter backup file (.zst):": "Zadajte súbor zálohy (.zst):", "Enter backup path (.tar.zst):": "Zadajte cestu k zálohe (.tar.zst):", "Enter backup path (.vma.zst):": "Zadajte cestu k zálohe (.vma.zst):", @@ -1489,6 +1923,7 @@ "Enter the number or type the interface name:": "Zadajte číslo alebo napíšte názov rozhrania:", "Enter the password for Samba user:": "Zadajte heslo pre Samba používateľa:", "Enter the recovery passphrase set when the keyfile was created:": "Zadajte obnovovaciu frázu nastavenú pri vytvorení keyfile:", + "Enter the size in whole GB, for example": "Zadajte veľkosť v celej GB, napríklad", "Enter username for Samba server:": "Zadajte používateľské meno pre Samba server:", "Enter username:": "Zadajte používateľské meno:", "Enterprise Proxmox Ceph repository disabled": "Enterprise Proxmox Ceph repozitár vypnutý", @@ -1497,6 +1932,8 @@ "Enterprise repository returned 401 Unauthorized (no valid subscription). Switch to the no-subscription repository and retry?": "Enterprise repozitár vrátil 401 Unauthorized (žiadne platné predplatné). Prepnúť na no-subscription repozitár a skúsiť znova?", "Enterprise repository unauthorized and fallback declined by user": "Enterprise repozitár nie je autorizovaný a používateľ odmietol náhradné riešenie", "Entropy generation optimization removed": "Optimalizácia generovania entropie bola odstránená", + "Environment entry without an explicit value": "Vstup do životného prostredia bez explicitnej hodnoty", + "Environment override for an unknown service:": "Prostredie prepísať pre neznámu službu:", "Equivalent manual flow of disk_host.sh: partition, format, mount, persist, register in Proxmox.": "Rovnaký ručný postup ako v disk_host.sh: rozdeliť, formátovať, pripojiť, uložiť natrvalo a zaregistrovať v Proxmoxe.", "Equivalent manual flow of iscsi_host.sh.": "Rovnaký ručný postup ako v iscsi_host.sh.", "Equivalent manual flow used by Local Shared Manager.": "Rovnaký ručný postup používa aj správca lokálneho zdieľania.", @@ -1512,12 +1949,16 @@ "Error: No write permissions in directory": "Chyba: v priečinku nie je oprávnenie na zápis", "Essential Proxmox packages installed": "Základné Proxmox balíky nainštalované", "Estimated required free space:": "Odhad potrebného voľného miesta:", + "Etherpad admin page": "Etherpad admin stránka", "Every 12 hours": "Každých 12 hodín", "Every 3 hours": "Každé 3 hodiny", "Every 6 hours": "Každých 6 hodín", + "Every fail2ban jail ships disabled. Enable the ones you need in /config/fail2ban/jail.local, taking the ready-made jails in /config/fail2ban/jail.d/ as reference, then restart the container.": "Každá fail2ban väzenská loď je vypnutá. Povoliť tie, ktoré potrebujete v /config/fail2ban/jail.local, pričom ready-made väzenia v /config/fail2ban/jail.d/ ako odkaz, potom reštartujte kontajner.", "Every hour": "Každú hodinu", + "Every member of the stack is back to its previous installation.": "Každý člen zásobníka je späť do svojej predchádzajúcej inštalácie.", "Every path in this backup is kernel-tied: the restore applies these paths automatically via the safe-subset filter and re-merges the operator's tuning.": "Každá cesta v tejto zálohe je viazaná na kernel: obnova tieto cesty použije automaticky cez filter bezpečnej podmnožiny a znovu zlúči vlastné ladenie správcu.", "Everything restorable in this backup will be restored": "Všetko obnoviteľné z tejto zálohy sa obnoví", + "Exact name of the remote": "Presný názov ovládača", "Example output: rootfs: local-lvm:vm-114-disk-0,size=8G": "Príklad výstupu: rootfs: local-lvm:vm-114-disk-0,size=8G", "Example target: /dev/sdb": "Príklad cieľa: /dev/sdb", "Example: /dev/pve/vm-114-disk-0": "Príklad: /dev/pve/vm-114-disk-0", @@ -1537,7 +1978,9 @@ "Execute destructive rollback?": "Vykonať deštruktívny rollback?", "Executing destructive rollback (operator confirmed) ...": "Vykonávam deštruktívny rollback (správca potvrdil) ...", "Executing:": "Spúšťam:", + "Execution engine for Index-TTS": "Vykonávací motor pre Index-TTS", "Existing Groups": "Existujúce skupiny", + "Existing TLS certificate reused:": "Existujúce osvedčenie TLS opätovne použité:", "Existing file, re-downloading...": "Súbor už existuje, sťahujem ho znova...", "Existing filesystem:": "Existujúci súborový systém:", "Existing hostpci entries detected — they will be reused": "Zistené existujúce hostpci položky - použijú sa znova", @@ -1581,7 +2024,9 @@ "Extended Filesystem 4 (recommended)": "Extended Filesystem 4 (odporúčané)", "External ZFS ARC settings restored:": "Externé nastavenia ZFS ARC boli obnovené:", "External ZFS configuration changed after the ProxMenux migration; current file and backup preserved:": "Externá konfigurácia ZFS sa po migrácii ProxMenux zmenila; aktuálny súbor aj záloha zostali zachované:", + "External credential is empty or spans multiple lines": "Externý credential je prázdny alebo rozpätie viacerých liniek", "External disk for backup": "Externý disk na zálohu", + "External field not reserved:": "Vonkajšie pole nie je vyhradené:", "Extracting NVIDIA installer on host...": "Rozbaľujem NVIDIA inštalátor na hostovi...", "Extracting OVA archive...": "Rozbaľujem OVA archív...", "Extracting archive...": "Rozbaľujem archív...", @@ -1592,7 +2037,9 @@ "Extraction failed. Check log:": "Rozbalenie zlyhalo. Skontrolujte záznam:", "Extraction successful": "Rozbalenie bolo úspešné", "FAILED": "ZLYHALO", + "FFmpeg version the node uses (7 by default)": "FFmpeg verzia uzol používa (7 predvolene)", "FINAL CONFIRMATION — DATA WILL BE ERASED": "POSLEDNÉ POTVRDENIE — DÁTA SA VYMAŽÚ", + "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface.": "FIleZilla Client je rýchly a spoľahlivý cross-platform FTP, FTPS a SFTP klient s množstvom užitočných funkcií a intuitívne grafické užívateľské rozhranie.", "Fail2Ban - Intrusion Prevention": "Fail2Ban - ochrana prihlasovania", "Fail2Ban Management": "Správa Fail2Ban", "Fail2Ban has been removed": "Fail2Ban bol odstránený", @@ -1602,6 +2049,7 @@ "Fail2Ban is currently installed.": "Fail2Ban je aktuálne nainštalovaný.", "Fail2Ban is not installed on this system.": "Fail2Ban nie je na tomto systéme nainštalovaný.", "Fail2Ban is running correctly": "Fail2Ban beží správne", + "Fail2ban is a daemon to ban hosts that cause multiple authentication errors.": "Fail2ban je démon zakázať hostiteľov, ktoré spôsobujú viac autentifikačných chýb.", "Failed": "Zlyhalo", "Failed to access log2ram directory": "Nepodarilo sa otvoriť priečinok log2ram", "Failed to access share with provided credentials.": "Nepodarilo sa pripojiť k zdieľaniu so zadanými prihlasovacími údajmi.", @@ -1748,6 +2196,9 @@ "Failed. See log:": "Zlyhalo. Pozrite záznam:", "Falling back to each installer with --auto-reinstall...": "Prepínam na jednotlivé inštalátory s --auto-reinstall...", "Falling back to manual paste mode.": "Prepínam na ručné vloženie.", + "Fast Usenet downloader with a SABnzbd-compatible API": "Fast Usenet downloader s SABnzbd kompatibilným API", + "Fast, modern web interface for qBittorrent": "Rýchle, moderné webové rozhranie pre qBittorrent", + "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper.": "Rýchlejšie-whisper je reimplementácia modelu Whisper OpenAI pomocou CTranslate2, ktorý je rýchlym vyvodzovacím motorom pre modely Transformer. Tento kontajner poskytuje Wyoming protokol server pre rýchlejšie-šepkať.", "Fastfetch Logo Selection": "Výber loga pre Fastfetch", "Fastfetch configuration updated": "Nastavenie Fastfetch bolo aktualizované", "Fastfetch download URL retrieved successfully.": "Adresa na stiahnutie Fastfetch bola úspešne získaná.", @@ -1759,19 +2210,31 @@ "Fastfetch now displays: System optimised by: ProxMenux": "Fastfetch teraz zobrazuje: Systém optimalizoval: ProxMenux", "Fastfetch removed from system": "Fastfetch bol odstránený zo systému", "Fastfetch will start automatically in the console": "Fastfetch sa bude v konzole spúšťať automaticky", + "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application.": "Ferdium je desktopová aplikácia, ktorá vám pomôže zorganizovať, ako používate svoje obľúbené aplikácie pomocou combi.", "Fetching NVIDIA driver versions supported by your GPU...": "Načítavam verzie ovládača NVIDIA podporované vaším GPU...", "Figurine installation and configuration completed successfully.": "Inštalácia a nastavenie Figurine boli úspešne dokončené.", "Figurine is not installed.": "Figurine nie je nainštalovaný.", "Figurine removed from system": "Figurine bol odstránený zo systému", + "File bind mounts do not support spaces:": "Pripojenie súborov nepodporuje medzery:", + "File processing made easy!": "Spracovanie súborov bolo jednoduché!", "File:": "Súbor:", + "FileBrowser Quantum": "FileBrowser Quantum", + "FileBrowser Quantum (new installation)": "FileBrowser Quantum (nová inštalácia)", + "FileDrop is a free, open source file sharing service": "FileDrop je bezplatná služba zdieľania súborov s otvoreným zdrojom", + "Files & Downloads": "Súbory a sťahovania", + "Files volume size in GB": "Veľkosť hlasitosti súborov v GB", "Filesystem": "Súborový systém", "Filesystem Tools Required": "Sú potrebné nástroje pre súborový systém", "Filesystem:": "Súborový systém:", "Final Confirmation": "Posledné potvrdenie", + "Final cleanup of the stack operation completed": "Konečné vyčistenie stohu operation dokončené", "Final confirmation": "Posledné potvrdenie", "Final storage health/status check": "Záverečná kontrola stavu úložiska", + "Finance & Budgeting": "Finance & Budgeting", "Find your device using https://finds.synology.com": "Zariadenie nájdete cez https://finds.synology.com", "Fingerprint:": "Odtlačok:", + "Firefly, the easiest using of WireGuard VPN server, plus version of wg-easy.": "Firefly, najjednoduchšie používanie WireGuard VPN servera, plus verzia wg-ľahké.", + "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards.": "Firefox Browser, tiež známy ako Mozilla Firefox alebo jednoducho Firefox, je zadarmo a open-source webový prehliadač vyvinutý Mozilla nadácie a jej dcérskej spoločnosti, Mozilla Corporation. Firefox používa Gecko dispozičný motor na vytvorenie webových stránok, ktoré implementujú aktuálne a predpokladané webové štandardy.", "Firewall allows port": "Firewall povoľuje port", "Firewall settings": "Nastavenia firewallu", "Firmware :": "Firmware :", @@ -1791,8 +2254,13 @@ "Fix systemd-boot meta-package conflict": "Opraviť konflikt meta-balíka systemd-boot", "Fix systemd-boot:": "Opraviť systemd-boot:", "Fix: on the host, run": "Oprava: na hostovi spustite", + "FlexGet web interface": "Webové rozhranie FlexGet", + "Flexget is a multipurpose automation tool for all of your media.": "Flexget je viacúčelový automatizačný nástroj pre všetky vaše médiá.", + "Flowise 3.0.1 and later create the administrator account from the web interface, the first time it is opened.": "Flowise 3.0.1 a neskôr vytvoriť správca účtu z webového rozhrania, prvýkrát je otvorený.", + "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast.": "Flycast je multiplatforma Sega Dreamcast, Naomi, Naomi 2, a atomiswave emulátor odvodený z reicastu.", "Folder Name": "Názov priečinka", "Folders in /mnt": "Priečinky v /mnt", + "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics.": "Folding@home je distribuovaný počítačový projekt na simuláciu dynamiky bielkovín, vrátane procesu skladania bielkovín a pohybu proteínov, ktoré sa podieľajú na rôznych chorobách. To spája citizen vedci, ktorí dobrovoľne spustiť simulácie proteínovej dynamiky na svojich osobných počítačoch. Pohľady z týchto údajov pomáhajú vedcom lepšie pochopiť biológiu a poskytujú nové príležitosti na rozvoj terapií.", "Follow post-restore progress live from ProxMenux Monitor → Backups tab after the reboot.": "Po reštarte sledujte priebeh po obnove naživo v ProxMenux Monitor → karta Backups.", "For LVM - Create mount directory and mount:": "Pre LVM - vytvoriť priečinok a pripojiť súborový systém:", "For ZFS, storage ID must start with a letter and use only letters, numbers, dot, dash, underscore or colon.": "Pri ZFS musí ID úložiska začínať písmenom a môže obsahovať iba písmená, čísla, bodku, pomlčku, podčiarkovník alebo dvojbodku.", @@ -1828,11 +2296,15 @@ "Formatting partition": "Formátujem oddiel", "Found": "Nájdené", "Found guest-accessible shares:": "Nájdené zdieľania dostupné pre hosťa:", + "Free and easy to use Minecraft server management tool.": "Bezplatný a ľahko použiteľný nástroj na správu serverov Minecraft.", "Free public Proxmox repository enabled": "Bezplatný verejný Proxmox repozitár zapnutý", "Free space OK:": "Voľné miesto je v poriadku:", "Free up disk space": "Uvoľniť miesto na disku", "Free:": "Voľné:", + "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support.": "FreeCAD je všeobecné parametrická 3D modelka s počítačovou podporou (CAD) a softvérová aplikácia so stavebným informačným modelovaním (BIM) s podporou konečnej elementovej metódy (FEM).", "French": "Francúzština", + "Freshrss is a free, self-hostable aggregator for rss feeds.": "Freshrss je voľný, self-hostinný aggregátor pre RSS kanály.", + "Frigate WebUI": "Frigate WebUI", "Full SMART Report": "Úplná SMART správa", "Full SMART info and attributes": "Úplné SMART informácie a atribúty", "Full format — new GPT partition + filesystem": "Úplné formátovanie - nový GPT oddiel + súborový systém", @@ -1845,6 +2317,7 @@ "Function Level Reset (FLR) not available": "Function Level Reset (FLR) nie je dostupný", "GID already in use:": "GID sa už používa:", "GID in CT": "GID v CT", + "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable.": "GIMP je bezplatný a open-source rastrový editor, ktorý sa používa na manipuláciu s obrázkami (retušovanie) a úpravu obrázkov, kreslenie voľných foriem, transkódovanie medzi rôznymi formátmi obrazových súborov a ďalšie špecializované úlohy. Je rozšíriteľný pomocou pluginu, a skriptovateľné.", "GPU": "GPU", "GPU -> VM Mode Detected": "Zistený režim GPU -> VM", "GPU Already Added": "GPU už je pridaná", @@ -1870,6 +2343,7 @@ "GPU already present in target VM — existing hostpci entry reused": "GPU už je v cieľovej VM - existujúca hostpci položka sa použila znova", "GPU audio added": "GPU audio pridané", "GPU audio already present in target VM — existing hostpci entry reused": "GPU audio už je v cieľovej VM - existujúca hostpci položka sa použila znova", + "GPU available for machine learning:": "GPU k dispozícii pre strojové učenie:", "GPU driver blacklisted": "Ovládač GPU pridaný na blacklist", "GPU guard hook will block concurrent start when another VM is already using this GPU": "GPU guard hook zablokuje súbežný štart, keď inú VM už táto GPU používa", "GPU host driver blacklisted in /etc/modprobe.d/blacklist.conf": "Host ovládač GPU pridaný na blacklist v /etc/modprobe.d/blacklist.conf", @@ -1885,11 +2359,14 @@ "GPU passthrough to VMs requires IOMMU to be enabled in the kernel.": "GPU passthrough do VM vyžaduje, aby bolo IOMMU zapnuté v kerneli.", "GPU passthrough was not applied.": "Priame priradenie GPU nebolo použité.", "GPU passthrough was skipped (no compatible GPU detected).": "Priame priradenie GPU bolo preskočené (nenašla sa vhodná GPU).", + "GPU recognition uses 8 GB of RAM and a limit of 4 CPU equivalents. These resources were tested in the lab and are not a universal minimum. Compatibility depends on the GPU, the models and the kernel. NVIDIA uses the GPUs of the Toolkit inventory; Intel keeps the CPU topology.": "Rozpoznávanie GPU používa 8 GB RAM a limit 4 CPU equivalentných. Tieto zdroje boli testované v laboratóriu a nie sú univerzálne minimum. Kompatibilita závisí od GPU, modelov a jadra. NVIDIA používa GPU inventára Toolkit; Intel udržuje topológiu CPU.", "GPU removed from VM": "GPU odstránená z VM", "GPU removed from VM config": "GPU bola odstránená z nastavenia VM", + "GPU render device": "GPU zariadenie", "GPU switch complete: LXC mode prepared.": "Prepnutie GPU je hotové: LXC režim je pripravený.", "GPU switch complete: VM mode prepared.": "Prepnutie GPU je hotové: VM režim je pripravený.", "GPU switch mode completed. No reboot required.": "Režim GPU bol prepnutý. Reštart nie je potrebný.", + "GPU verified:": "GPU overené:", "GPU will be removed from source VM config": "GPU sa odstráni z nastavenia zdrojovej VM", "GPU will remain configured in source VM": "GPU zostane nastavená v zdrojovej VM", "GPU/TPU - Manual CLI Guide": "GPU/TPU - ručný CLI sprievodca", @@ -1899,6 +2376,8 @@ "GRUB configuration updated": "Nastavenie GRUB bolo aktualizované", "GRUB_CMDLINE_LINUX_DEFAULT not found in GRUB config": "GRUB_CMDLINE_LINUX_DEFAULT sa v nastavení GRUB nenašlo", "GUI mode (if available)": "Grafický režim (ak je dostupný)", + "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities.": "GZDoom je funkcia centrický port pre všetky hry Doom motora, založené na ZDoom, pridanie OpenGL kresbu a mocné skriptovanie schopnosti.", + "Gaming & Leisure": "Herné a leisure", "Gateway is not installed.": "Brána nie je nainštalovaná.", "Gateway removed.": "Brána odstránená.", "Gateway restarted.": "Brána reštartovaná.", @@ -1908,19 +2387,32 @@ "Generate a new key and authorize it on the server automatically (recommended)": "Vygenerovať nový kľúč a automaticky ho autorizovať na serveri (odporúčané)", "Generate a new key, show me the line to paste manually": "Vygenerovať nový kľúč a zobraziť riadok na ručné vloženie", "Generate a new keyfile": "Vygenerovať nový keyfile", + "Generated Paperless administrator": "Generovaný administrátor bez dokumentov", + "Generated Tandoor administrator": "Name", + "Generated administrator login": "Prihlásenie generovaného správcu", "Generating OVF descriptor...": "Vytváram OVF popisovač...", "Generating dkms.conf...": "Vytváram dkms.conf...", "Generating manifest...": "Vytváram manifest...", "Generating missing locale:": "Vytváram chýbajúce locale:", + "Generic SCSI device associated with the drive (e.g. /dev/sg2)": "Generické zariadenie SCSI spojené s pohonom (napr. /dev/sg2)", "German": "Nemčina", "Get a list of all your containers:": "Zobraziť zoznam všetkých kontajnerov:", "Get the actual disk path:": "Zistiť skutočnú cestu k disku:", "Get the container's storage information:": "Zistiť informácie o úložisku kontajnera:", + "Get up and running with large language models locally": "Vstaňte a bežte s veľkými jazykovými modelmi lokálne", "Git installed": "Git nainštalovaný", + "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality.": "GitQlient je multiplatforma Git klient pôvodne fork od QGit. V súčasnej dobe ide nad rámec len fork a pridáva veľa nových funkcií.", + "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React.": "Github Desktop je open source Electron-based app GitHub. Je napísaný v TypeScript a používa React.", "Global settings and SSH jail configured": "Globálne nastavenia a SSH jail sú nastavené", + "Gluetun/VPN not yet available: this suite does not route downloads through a VPN.": "Gluetun/VPN zatiaľ nie je k dispozícii: tento suite nie je trasa sťahovania cez VPN.", "Go to \"Manage custom paths\" and remove your custom entry that includes the destination": "Prejdite do \"Spravovať vlastné cesty\" a odstráňte vlastnú položku, ktorá obsahuje cieľ", "Google only ships an official libedgetpu APT repository for Debian/Ubuntu. Hardware passthrough is already written to": "Google poskytuje oficiálny libedgetpu APT repozitár iba pre Debian/Ubuntu. Hardvérový passthrough už je zapísaný do", "Graceful shutdown timed out.": "Korektné vypnutie nestihlo dobehnúť.", + "Grafana is a complete observability stack that allows you to monitor and analyze metrics, logs and traces. It allows you to query, visualize, alert on and understand your data no matter where it is stored.": "Grafana je kompletný sledovateľnosť zásobníka, ktorý umožňuje sledovať a analyzovať metriky, protokoly a stopy. Umožňuje vyhľadávať, vizualizovať, upozorniť a porozumieť vašim údajom bez ohľadu na to, kde sú uložené.", + "Grafana web interface": "Webové rozhranie Grafana", + "Grav is a Fast, Simple, and Flexible, file-based Web-platform.": "Grav je rýchla, jednoduchá a flexibilná webová platforma na báze súborov.", + "Grocy (new installation; restored data keeps its credentials)": "Grocy (nová inštalácia; obnovené dáta udržuje svoje CRMXTERM001tials)", + "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility.": "Grocy je ERP systém pre vašu kuchyňu! Znížte plytvanie potravinami a spravte si prácu s týmto skvelým prínosom.", "Group": "Skupina", "Group 'sharedfiles' already exists inside the CT": "Skupina 'sharedfiles' už existuje vo vnútri CT", "Group GID:": "GID skupiny:", @@ -1953,23 +2445,57 @@ "Guided Repair Available": "Dostupná oprava so sprievodcom", "HA groups will be migrated to HA rules automatically": "HA skupiny sa automaticky prevedú na HA pravidlá", "HA services disabled (configs preserved)": "HA služby boli vypnuté (nastavenia zostali zachované)", + "HAOS One is a community image that runs Docker inside the container. The LXC stays unprivileged, but the inner AppArmor profiles may not be available. The first start downloads Home Assistant Core and its add-ons. If the check fails, the CT and /mnt/data are kept for diagnosis.": "HAOS One je obraz spoločenstva, ktorý prevádzkuje Docker vnútri kontajnera. LXC zostáva neprivilegovaný, ale vnútorné profily AppArmor nemusí byť k dispozícii. Prvý štart stiahne Home Assistant jadro a jeho doplnky. Ak kontrola zlyhá, CT a / mnt/ dáta sa uchovávajú na určenie diagnózy.", + "HAOS One profile declined": "Profil HAOS One klesol", + "HAOS One requires an unprivileged unmanaged LXC with nesting and keyctl, 2 cores, 2048 MB RAM, rootfs of at least 12 GB and /mnt/data of at least 16 GB on a container volume included in backups": "HAOS One requires an unprivileged unmanaged LXC with nestering and keyctl, 2 cores, 2048 MB RAM, rootfs najmenej 12 GB a /mnt/data najmenej 16 GB on a container volume included in backions", + "HTTP service check without a saved URL": "Kontrola služby HTTP bez uloženého URL", + "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API.": "Habridge napodobňuje Philipsa Spoločnosť Amazon tvrdí, že spoločnosť LuxOpCo by mala mať prístup k webovým stránkam spoločnosti LuxOpCo. Most riadi základné príkazy, ako je On, Off a jas príkazy protokolu odtieňov. Tento most môže ovládať väčšinu zariadení, ktoré majú odlišné API.", + "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs.": "HandBrake je open-source nástroj, postavený dobrovoľníkmi, pre konverziu video z takmer akéhokoľvek formátu na výber moderných, široko podporovaných kodekov.", "Hardening SSH: setting MaxAuthTries to 3...": "Spevňujem SSH: nastavujem MaxAuthTries na 3...", + "Hardware acceleration for Emby": "Zrýchlenie hardvéru pre Emby", + "Hardware acceleration for FileFlows": "Zrýchlenie hardvéru pre FileFlows", + "Hardware acceleration for Frigate": "Zrýchlenie hardvéru pre Frigate", + "Hardware acceleration for Jellyfin": "Zrýchlenie hardvéru pre Jellyfin", + "Hardware acceleration for Plex": "Zrýchlenie hardvéru pre Plex", + "Hardware acceleration for Roon Server": "Zrýchlenie hardvéru pre Roon Server", + "Hardware acceleration for Stremio": "Zrýchlenie hardvéru pre Stremio", + "Hardware acceleration for Tdarr": "Zrýchlenie hardvéru pre Tdarr", + "Hardware acceleration options:": "Možnosti zrýchlenia hardvéru:", "Hardware compatibility — these items will be skipped to keep the boot safe:": "Kompatibilita hardvéru - tieto položky sa preskočia, aby zostal štart bezpečný:", "Hardware passthrough is already configured — the Coral device is visible inside the container as /dev/apex_0 (M.2) and/or /dev/bus/usb (USB).": "Hardvérový passthrough už je nastavený - Coral zariadenie je v kontajneri viditeľné ako /dev/apex_0 (M.2) a/alebo /dev/bus/usb (USB).", "Hardware: GPUs and Coral-TPU": "Hardvér: grafické karty a Coral TPU", + "Have a Private Social Space Hosted on Your Site": "Majte na svojej stránke vlastný sociálny priestor", "Have valid backups of all VMs and containers": "Majte platné zálohy všetkých VM a kontajnerov", + "Health check failed:": "Kontrola stavu zlyhala:", + "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface.": "Healthchecks je strážny pes pre vaše Cron pracovných miest. Je to webový server, ktorý počúva na ping z vašich Cron jobs, plus webové rozhranie.", + "HedgeDoc gives you access to all your files wherever you are.": "HedgeDoc vám umožní prístup ku všetkým súborom kdekoľvek ste.", + "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way.": "Heimdall je spôsob, ako zorganizovať všetky tieto odkazy na vaše najpoužívanejšie webové stránky a webové aplikácie jednoduchým spôsobom.", + "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking.": "Helium je Chromium-založený webový prehliadač vyrobený pre ľudí, s láskou. Privacy-first with unsised ad-blocking.", "Help & Info (commands)": "Pomoc a informácie (príkazy)", "Help & Information": "Pomoc a informácie", "Help and Info": "Pomoc a informácie", "Help and Info Commands": "Pomocné a informačné príkazy", "Helper-Scripts logo applied": "Logo Helper-Scripts bolo použité", + "Hermes WebUI": "Hermes WebUI", "Hidden for safety": "Skryté kvôli bezpečnosti", "Hidden:": "Skryté:", "High Availability services have been enabled successfully": "Služby High Availability boli úspešne zapnuté", "High Availability setup completed": "Nastavenie High Availability je dokončené", + "High availability resources are not supported by this profile": "Tento profil nepodporuje vysoko dostupné zdroje", + "High availability resources are not supported for stacks": "Vysoká dostupnosť zdrojov nie sú podporované pre stohy", "High risk confirmation": "Potvrdenie vysokého rizika", "High-Risk GPU Power State": "Rizikový stav napájania GPU", + "Home Assistant": "Home Assistant", + "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server": "Home Assistant Core - Open source domácej automatizácie, ktorá kladie miestne ovládanie a súkromie ako prvý. Poháňané celosvetovou komunitou drotárov a domácich nadšencov. Ideálne pre beh na Malinová Pi alebo miestny server", + "Home Assistant OS cannot be checked without an IP address": "Home Assistant OS nemožno skontrolovať bez IP adresy", + "Home Assistant OS did not pass the Supervisor, Core and Observer checks": "Home Assistant OS neprešiel dozorcom, základnými a pozorovateľmi", + "Home Assistant OS ready: Supervisor, Core and Observer running": "Home Assistant OS pripravený: Supervízor, jadro a pozorovateľ beží", + "Home Assistant OS was not started: its addresses will be known once Core is running.": "Home Assistant OS sa nezačalo: jeho adresy budú známe po spustení Core.", + "Home Assistant Observer": "Home Assistant Pozorovateľ", + "Home Automation systems": "Systémy domácej automatizácie", "Home-Lab-Club logo applied": "Logo Home-Lab-Club bolo použité", + "HomeKit support for the impatient.": "Podpora HomeKit pre netrpezlivých.", + "Homebridge UI": "Homebridge UI", "Host": "Host", "Host Backup → Borg": "Záloha hosta → Borg", "Host Backup → Local archive": "Záloha hosta → lokálny archív", @@ -1978,6 +2504,7 @@ "Host Config Backup": "Záloha nastavení hosta", "Host Config Backup / Restore": "Záloha / obnova nastavení hosta", "Host Config Restore": "Obnova nastavení hosta", + "Host DVB tuners": "Hostiteľské DVB tunery", "Host Directory": "Priečinok hosta", "Host Directory to LXC Mount Point": "Priečinok hosta ako mount point v LXC", "Host Directory:": "Priečinok hosta:", @@ -1985,18 +2512,37 @@ "Host GPU detected": "Na hoste sa našla GPU", "Host GPU is already bound to vfio-pci. Host reconfiguration/reboot should not be required for this VM-to-VM reassignment.": "GPU na hostovi už je naviazaná na vfio-pci. Pri tomto presune VM-to-VM by nemalo byť potrebné meniť hosta ani reštartovať.", "Host IP": "IP hosta", + "Host Management": "Správa hostiteľov", "Host Mount Path": "Cesta mountu na hostovi", "Host NFS/Samba as Proxmox Storage (pvesm)": "Host NFS/Samba ako úložisko Proxmoxu (pvesm)", "Host Path": "Cesta na hostovi", "Host Path:": "Cesta na hostovi:", "Host Storage (NFS / Samba via Proxmox)": "Úložisko na serveri (NFS / Samba cez Proxmox)", + "Host USB bus": "Host USB autobus", "Host VFIO config was already up to date — no reboot needed.": "VFIO nastavenie hosta už bolo aktuálne - reštart nie je potrebný.", "Host VFIO configuration already up to date": "VFIO nastavenie hosta je už aktuálne", "Host VFIO configuration changed (initramfs updated). Reboot required before starting the VM.": "Nastavenie VFIO na serveri sa zmenilo (initramfs bol aktualizovaný). Pred spustením VM je potrebný reštart.", "Host VFIO configuration changed — reboot required before starting the VM.": "VFIO nastavenie hosta sa zmenilo - pred spustením VM je potrebný reštart.", "Host already in VFIO mode — skipping host reconfiguration for VM reassignment": "Host už je vo VFIO režime - zmena hosta sa pri presune medzi VM preskakuje", + "Host audio devices": "Hostiteľské audio zariadenia", "Host backup attached to PVE job": "Záloha hosta bola pripojená k PVE úlohe", + "Host data is not restored by the backup; confirm it with --acknowledge-external-data": "Údaje o hostiteľovi nie sú obnovené zálohou; potvrďte ich -- acnown-external-data", + "Host device for /dev/kvm": "Hostiteľské zariadenie pre /dev/kvm", + "Host device for /dev/net/tun": "Hostiteľské zariadenie pre /dev/net/tun", + "Host device for /dev/ttyUSB0": "Hostiteľské zariadenie pre /dev/ttyUSB0", + "Host device for /dev/video10": "Hostiteľské zariadenie pre /dev/video10", + "Host device for /dev/video11": "Hostiteľské zariadenie pre /dev/video11", + "Host device for /dev/video12": "Hostiteľské zariadenie pre /dev/video12", + "Host device node": "Uzol hostiteľského zariadenia", + "Host directories are not included in the backup and are not reverted by a recovery.": "Hostiteľské adresáre nie sú zahrnuté do zálohy a nie sú vrátené zotavením.", + "Host directories are not included in the backups and are not reverted by a recovery.": "Hostiteľské adresáre nie sú zahrnuté v zálohách a nie sú vrátené zotavením.", + "Host directories cannot be part of the vzdump backup": "Hostiteľské adresáre nemôžu byť súčasťou zálohy", + "Host directories that are kept, with their content:": "Hostiteľské adresáre, ktoré sú uchovávané, s ich obsahom:", + "Host directory": "Adresár hostiteľov", + "Host directory (created if it does not exist)": "Adresár hostiteľa (vytvorený, ak neexistuje)", + "Host directory (not included in Proxmox backups)": "Hostiteľský adresár (nie je súčasťou záloh Proxmox)", "Host directory access for unprivileged containers has been prepared above": "Prístup k priečinku hosta pre neprivilegované kontajnery bol pripravený vyššie", + "Host directory kept, with its content:": "Hostiteľský adresár s obsahom:", "Host directory permissions updated — unprivileged containers can now access it": "Oprávnenia priečinka na hostovi boli upravené - neprivilegované kontajnery k nemu teraz môžu pristupovať", "Host directory:": "Priečinok hosta:", "Host fstab CIFS Mounts:": "CIFS mounty v host fstab:", @@ -2008,7 +2554,14 @@ "Host fstab NFS mounts:": "NFS mounty v host fstab:", "Host fstab mounts (not registered as Proxmox storage):": "Mounty v host fstab (nie sú zaregistrované ako úložisko Proxmoxu):", "Host identity (hostname, hosts)": "Identita hosta (hostname, hosts)", + "Host kernel module loaded:": "Načítaný modul jadra hostiteľa:", + "Host monitor configured: shared PID and network namespaces, LXCFS disabled in this container": "Konfigurovaný monitor hostiteľa: zdieľané PID a sieťové priestory, LXCFS vypnuté v tomto kontajneri", + "Host monitor verified: PID and network namespaces and memory match the host": "Monitor hostiteľa overený: PID a sieťové názvy a pamäť zodpovedajú hostiteľovi", + "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks.": "Monitor hostiteľa: spoločná PID/sieť a privilegovaný prístup. Kompromisný obraz by mohol ovplyvniť Proxmox. Používajte len na dôveryhodných sieťach.", + "Host monitoring declined": "Monitorovanie hostiteľa sa znížilo", + "Host path for": "Hostiteľ cesta pre", "Host permissions applied (o+rwx + default ACL) — unprivileged LXCs can read/write through bind-mounts": "Oprávnenia hosta boli nastavené (o+rwx + predvolené ACL) - neprivilegované LXC môžu čítať/zapisovať cez bind mounty", + "Host system path": "Cesta k hostiteľskému systému", "Host write access confirmed.": "Zápis z hosta je potvrdený.", "Hostname": "Názov servera", "Hot changes applied. No reboot needed for these paths.": "Zmeny boli použité za behu. Pre tieto cesty nie je potrebný reštart.", @@ -2020,12 +2573,18 @@ "How do you want to select the Samba server?": "Ako chcete vybrať Samba server?", "How do you want to select the folder to export?": "Ako chcete vybrať priečinok na export?", "How do you want to select the folder to share?": "Ako chcete vybrať priečinok na zdieľanie?", + "How is it installed?": "Ako je nainštalovaný?", + "How is the image described?": "Ako je opísaný obraz?", "How to Access an LXC Terminal": "Ako otvoriť terminál LXC", "How to Access an LXC Terminal from Proxmox Host": "Ako otvoriť terminál LXC kontajnera z Proxmox servera", "How to schedule": "Spôsob plánovania", + "Htpcmanager is a front end for many htpc related applications.": "Htpcmanager je front end pre mnoho htpc súvisiacich aplikácií.", "I have read this": "Prečítal som si to", "I/O priority configured": "I/O priorita je nastavená", "ID already in use. Please choose another.": "Toto ID sa už používa. Vyberte iné.", + "IGDB": "IGDB", + "IGDB Client ID": "ID klienta IGDB", + "IGDB Client Secret": "IGDB klient tajomstvo", "IMPORTANT": "DÔLEŽITÉ", "IMPORTANT NOTES:": "DÔLEŽITÉ POZNÁMKY:", "IMPORTANT PREREQUISITES:": "DÔLEŽITÉ PREDPOKLADY:", @@ -2062,7 +2621,14 @@ "IOMMU was configured during this wizard and a reboot is pending.": "IOMMU bolo nastavené počas tohto sprievodcu a čaká sa na reštart.", "IOMMU/VFIO configuration reverted": "Nastavenie IOMMU/VFIO bolo vrátené späť", "IP": "IP", + "IP address": "IP adresa", + "IP address and firewall of the host": "IP adresa a firewall hostiteľa", + "IP address of this container for the certificate (0.0.0.0 if unknown)": "IP adresa tohto kontajnera pre osvedčenie (0,0.0, ak nie je známe)", + "IP address:": "IP adresa:", "IP or hostname of the PVE node hosting the Borg server LXC:": "IP alebo hostname PVE uzla, na ktorom beží Borg server LXC:", + "IPv4 address of the container": "IPv4 adresa kontajnera", + "IPv4 address of the containers": "IPv4 adresa kontajnerov", + "IPv4 gateway (empty = no outbound route)": "Vstupná brána IPv4 (prázdna = žiadna úniková cesta)", "ISO": "ISO", "ISO created successfully:": "ISO bolo úspešne vytvorené:", "ISO image — installation images": "ISO obraz — inštalačné obrazy", @@ -2095,6 +2661,7 @@ "If this happens, you can restore the backup from the 'Subscription Banner Removal' option in 'Uninstall optimizations'.": "Ak sa to stane, zálohu môžete obnoviť cez možnosť 'Subscription Banner Removal' v časti 'Uninstall optimizations'.", "If this node runs hyper-converged Ceph: ensure Ceph is 19.x (Squid) BEFORE upgrading PVE.": "Ak tento uzol používa hyper-konvergovaný Ceph: pred aktualizáciou PVE overte, že Ceph je 19.x (Squid).", "If upgrade fails:": "Ak aktualizácia zlyhá:", + "If you answer No, Glances is installed without privileges and monitors ONLY its own LXC, not Proxmox.": "Ak odpoviete nie, Glances je nainštalovaný bez oprávnení a monitoruje IBA svoje vlastné LXC, nie Proxmox.", "If you are sure you want to use it, please remove the": "Ak ste si istý, že ho chcete použiť, odstráňte", "If you choose No, install": "Ak vyberiete Nie, nainštalujte", "If you continue, some adjustments may be duplicated or conflict with those already made by xshok.": "Ak budete pokračovať, niektoré úpravy sa môžu zdvojiť alebo byť v konflikte s tým, čo už urobil xshok.", @@ -2104,11 +2671,30 @@ "If you want HDMI/analog audio inside the VM, select the audio controller(s) to pass through along with the GPU.": "Ak chcete mať vo VM HDMI/analógový zvuk, vyberte aj audio radiče, ktoré sa majú priradiť spolu s GPU.", "If you want to use a physical monitor on the passthrough GPU:": "Ak chcete použiť fyzický monitor na priamo priradenej GPU:", "If your DHCP has a static reservation for the old MAC, update it.": "Ak máte v DHCP statickú rezerváciu pre starú MAC adresu, aktualizujte ju.", + "Image": "Obrázok", "Image Source Directory": "Zdrojový priečinok obrazov", + "Image cache": "Comment", + "Image compatibility restored:": "Kompatibilita s obrázkom obnovená:", + "Image compatibility verified:": "Kompatibilita s obrázkom overená:", "Image directory:": "Priečinok s obrazmi:", + "Image download failed:": "Sťahovanie obrázku zlyhalo:", + "Image downloaded": "Stiahnutý obrázok", "Image file not found:": "Súbor obrazu sa nenašiel:", "Image imported:": "Obraz importovaný:", + "Image integrity verified": "Potvrdená integrita obrázku", + "Image not allowed for the host monitor profile": "Obrázok nie je povolený pre profil monitora hostiteľa", + "Image reference (for example ghcr.io/user/application:latest)": "Odkaz na obrázok (napríklad ghcr.io/user/aplikácia:posledná)", + "Image that is not in the catalog": "Obrázok, ktorý nie je v katalógu", + "Image:": "Obrázok:", "Images to import:": "Obrazy na import:", + "Immich CUDA requires NVIDIA driver 545 or later": "Immich CUDA requires NVIDIA ovládač 545 alebo neskôr", + "Immich GPU profile not validated": "Immich GPU profil nie je validovaný", + "Immich configuration cancelled": "Konfigurácia Immich zrušená", + "Immich device without a validated translation": "Zariadenie Immich bez overeného prekladu", + "Immich machine learning": "Immich strojové učenie", + "Immich requires CUDA compute capability 5.2 or later": "Immich requires CUDA výpočtová schopnosť 5.2 alebo neskôr", + "Immich runtime without a validated translation": "Immich spustiť bez overeného prekladu", + "Immich server": "Server Immich", "Import — disk image imports": "Import — import diskových obrazov", "Import Disk Image to VM": "Importovať obraz disku do VM", "Import Disk to LXC": "Importovať disk do LXC", @@ -2149,24 +2735,58 @@ "Incompatible Reset Capability for Intel GPU": "Intel GPU nemá vhodnú možnosť resetu", "Incompatible Reset Capability for Intel dGPU": "Nekompatibilná reset schopnosť pre Intel dGPU", "Incompatible archive": "Nekompatibilný archív", + "Incompatible image platform": "Nekompatibilná obrazová platforma", + "Incompatible instance directory": "Nekompatibilný inštančný adresár", + "Incompatible instance record": "Nekompatibilný záznam o inštancii", + "Incompatible record": "Nekompatibilný záznam", + "Incompatible stack assembly": "Nekompatibilná súprava stohov", "Incompatible version": "Nekompatibilná verzia", + "Incomplete NVIDIA identity": "Neúplná identita NVIDIA", + "Incomplete NVIDIA inventory": "Neúplný inventár NVIDIA", + "Incomplete Proxmox inventory": "Neúplný inventár Proxmox", + "Incomplete Proxmox inventory; recovery blocked": "Neúplný inventár Proxmox; blokovaná obnova", + "Incomplete container removed:": "Neúplná odstránená nádoba:", + "Incomplete dependency order": "Neúplné poradie závislosti", + "Incomplete file recipe or unknown paths": "Neúplný súbor recept alebo neznáme cesty", + "Incomplete gzip layer": "Neúplná vrstva gzipu", + "Incomplete or incompatible Proxmox inventory": "Neúplný alebo nezlučiteľný súpis Proxmox", + "Incomplete primary network": "Neúplná primárna sieť", + "Incomplete stack order": "Neúplné poradie stohu", + "Incomplete stack removed": "Neúplný zásobník odstránený", + "Inconsistent adaptation profile and recipe": "Nekonzistentný adaptačný profil a recept", + "Inconsistent host monitor profile": "Profil nekonzistentného monitora hostiteľa", + "Inconsistent stack identity": "Nejednotná identita stohu", + "Inconsistent stack membership for": "Nekonzistentný stack členstvo pre", "Increase container RAM temporarily to": "Dočasne zvýšte RAM kontajnera na", "Increase file and process limits for advanced workloads": "Zvýšiť limity súborov a procesov pre náročnejšie použitie", "Increase various system limits": "Zvýšiť systémové limity", "Increase vzdump backup speed": "Zvýšiť rýchlosť záloh vzdump", "Increasing maximum file system open files...": "Zvyšujem maximálny počet otvorených súborov v systéme...", "Increasing various system limits...": "Zvyšujem rôzne systémové limity...", + "Independent LXC applications installed": "Inštalované nezávislé aplikácie LXC", + "Independent LXCs: no main container or hookscript. Each one keeps its own Start with Proxmox setting.": "Nezávislé LXCs: žiadny hlavný kontajner alebo hákový skript. Každý si ponechá svoj vlastný štart s nastavením Proxmox.", + "Independent applications, without a main container.": "Nezávislé aplikácie bez hlavného kontajnera.", + "Indexers and quality profiles still need to be configured.": "Indexery a kvalitné profily ešte treba nakonfigurovať.", "Inherited retention:": "Prevzaté uchovávanie:", "Inherited schedule:": "Prevzatý plán:", + "Initial Nextcloud administrator": "Počiatočný správca Nextcloud", + "Initial Nextcloud settings applied": "Použité počiatočné nastavenia Nextcloud", + "Initial Paperless-ngx administrator": "Počiatočný správca Paperless-ngx", + "Initial Tandoor administrator": "Počiatočný správca Tandoor", + "Initial administrator created:": "Pôvodný správca vytvorený:", + "Initial administrator user": "Počiatočný užívateľ správcu", "Initializing Borg repository if needed...": "Pripravujem Borg repozitár, ak je to potrebné...", "Initiator IQN is authorised on the target": "IQN iniciátora je na targete povolené", "Initiator IQN:": "IQN iniciátora:", + "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers.": "Inkscape je profesionálne kvalitný vektorový grafický softvér, ktorý beží na počítačoch Linux, Mac OS X a Windows.", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN": "Vnútri LXC, vytvoriť administrátor: konzola kimai:používateľ:vytvorte VAŠE VYUŽITE VAŠE EMAIL ROLE SUPER ADMIN", "Inspect disks before any action": "Skontrolovať disky pred akoukoľvek akciou", "Inspect host device nodes": "Skontrolovať device nodes na hostovi", "Inspect passthrough/kernel events": "Skontrolovať passthrough/kernel udalosti", "Inspect storage config block:": "Skontrolovať blok nastavenia úložiska:", "Inspection commands run directly. Template commands [T] require parameter substitution.": "Kontrolné príkazy sa spúšťajú priamo. Šablónové príkazy [T] vyžadujú doplnenie parametrov.", "Install": "Nainštalovať", + "Install (experimental)": "Inštalovať (experimentálne)", "Install ALL utilities": "Nainštalovať VŠETKY nástroje", "Install AMD GPU drivers inside the guest.": "Vo vnútri hosťa nainštalujte AMD GPU ovládače.", "Install CIFS client packages inside CT:": "Nainštalovať balíky CIFS klienta vo vnútri CT:", @@ -2185,6 +2805,7 @@ "Install Samba inside CT:": "Nainštalovať Sambu vo vnútri CT:", "Install ZFS auto-snapshot": "Nainštalovať ZFS auto-snapshot", "Install a version from the branch the kernel names.": "Nainštalujte verziu z vetvy s názvami jadra.", + "Install an image that is not in the catalog": "Inštalovať obrázok, ktorý nie je v katalógu", "Install analysis tools": "Nainštalovať analytické nástroje", "Install and configure": "Nainštalovať a nastaviť", "Install and configure Fastfetch": "Nainštalovať a nastaviť Fastfetch", @@ -2203,27 +2824,35 @@ "Install server packages inside CT:": "Nainštalovať serverové balíky vo vnútri CT:", "Install terminal multiplexers": "Nainštalovať terminálové multiplexery", "Install the Edge TPU runtime (libedgetpu1-std)": "Nainštaluje Edge TPU runtime (libedgetpu1-std)", + "Install this image?": "Nainštalovať tento obrázok?", "Install with Cloud-Init script": "Inštalovať cez Cloud-Init skript", "Install with ISO from UUP Dump": "Inštalovať z ISO cez UUP Dump", + "Install with advanced settings": "Inštalovať s pokročilým nastavením", + "Install with default settings": "Inštalovať so štandardnými nastaveniami", "Install with personal ISO": "Inštalovať z vlastného ISO", + "Install with this configuration?": "Nainštalovať s touto konfiguráciou?", "Install with traditional method": "Inštalovať tradičným spôsobom", "Install with: apt-get install open-iscsi": "Nainštalujte cez: apt-get install open-iscsi", "Install/Update Coral TPU on Host": "Nainštalovať/aktualizovať Coral TPU na serveri", "Install/Update NVIDIA Drivers (Host + LXC)": "Nainštalovať/aktualizovať NVIDIA ovládače (server + LXC)", "Installation Complete": "Inštalácia dokončená", + "Installation completed": "Inštalácia dokončená", "Installation completed.": "Inštalácia je dokončená.", "Installation completed. Please reboot the server manually as soon as possible.": "Inštalácia je dokončená. Čo najskôr ručne reštartujte server.", "Installation completed. Press Enter to continue...": "Inštalácia je dokončená. Pokračujte stlačením Enter...", "Installation failed": "Inštalácia zlyhala", "Installation finished but drivers are not loaded. A reboot may be required.": "Inštalácia sa dokončila, ale ovládače nie sú načítané. Možno bude potrebný reštart.", + "Installation incomplete. These containers and their data are kept:": "Inštalácia neúplná. Tieto nádoby a ich údaje sa uchovávajú:", "Installation log:": "Záznam inštalácie:", "Installation summary": "Zhrnutie inštalácie", "Installed": "Nainštalované", "Installed at:": "Nainštalované v:", "Installed components:": "Nainštalované súčasti:", + "Installed:": "Nainštalované:", "Installer already downloaded and verified.": "Inštalátor už je stiahnutý a overený.", "Installer copied to container.": "Inštalátor skopírovaný do kontajnera.", "Installer downloaded.": "Inštalátor bol stiahnutý.", + "Installer file not found:": "Súbor Inštalátora nenájdený:", "Installer finished with errors.": "Inštalátor skončil s chybami.", "Installer not found:": "Inštalátor sa nenašiel:", "Installing": "Inštalujem", @@ -2274,9 +2903,14 @@ "Installing pigz...": "Inštalujem pigz...", "Installing required dependencies...": "Inštalujem potrebné závislosti...", "Installing required package: git": "Inštalujem potrebný balík: git", + "Installing required packages...": "Inštalujem required balíčky...", "Installing required tools...": "Inštalujem potrebné nástroje...", "Installing selected utilities": "Inštalujem vybrané nástroje", "Installing system utilities...": "Inštalujem systémové nástroje...", + "Installing the new image": "Inštalácia nového obrázku", + "Installing the new image...": "Inštalujem nový obrázok...", + "Installing the new image:": "Inštalácia nového obrázku:", + "Installing the stack startup hook...": "Inštalácia stack startup...", "Installing zfs-auto-snapshot package...": "Inštalujem balík zfs-auto-snapshot...", "Installs essential packages if missing": "Nainštaluje chýbajúce základné balíky", "Insufficient Disk Space": "Nedostatok miesta na disku", @@ -2288,8 +2922,17 @@ "Intel CPU detected": "Zistený Intel procesor", "Intel GPU Tools installation completed!": "Inštalácia Intel GPU Tools je dokončená.", "Intel GPU(s) detected:": "Nájdené Intel GPU:", + "Intel VA-API + OpenCL (official mod)": "Intel VA-API + OpenCL (oficiálny mod)", "Intel VA-API drivers installed.": "Intel VA-API ovládače nainštalované.", "Intel iGPU passthrough configured.": "Intel iGPU passthrough je nastavený.", + "Intel render device for recognition": "Zariadenie na rozpoznávanie informácií", + "Intel/AMD (VA-API and QSV)": "Intel/AMD (VA-API a QSV)", + "Intel/AMD (VA-API)": "Intel/AMD (VA-API)", + "Intel/AMD (streaming rendering and encoding)": "Intel/AMD (prevádzanie a kódovanie)", + "Intel/AMD VA-API": "Intel/AMD VA-API", + "Intel/AMD VA-API (no OpenCL mod)": "Intel/AMD VA-API (bez OpenCL mod)", + "Intel/AMD render node": "Uzol Intel/AMD", + "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters – building great software.": "IntelliJ IDEA vám pomôže napísať kód rýchlejšie s nástrojmi, ktoré eliminujú únavné úlohy a umožní vám sústrediť sa na to, čo je dôležité", "Interactive (guided, prompts visible)": "Interaktívne (sprievodca, otázky viditeľné)", "Interactive process viewer (press q to exit)": "Interaktívny prehliadač procesov (ukončíte klávesom q)", "Interface": "Rozhranie", @@ -2303,50 +2946,186 @@ "Interfaces to Remove": "Rozhrania na odstránenie", "Internal error: NVIDIA installer path is empty or file not found.": "Vnútorná chyba: cesta k NVIDIA inštalátoru je prázdna alebo sa súbor nenašiel.", "Internal error: missing arguments in pmx_prepare_host_shared_dir": "Vnútorná chyba: chýbajú argumenty v pmx_prepare_host_shared_dir", + "Internal subnet of the tunnel (change it only if it clashes)": "Interný podsieť tunela (zmeniť ho, len ak sa zrazí)", + "Interrupted operation": "Prerušená operation", + "Interrupted operation:": "Prerušená operation:", + "Interrupted stack operation found": "Prerušený zásobník operation nájdený", "Invalid 'proxmox-ve' candidate (not 9.x or none). Please verify your repository configuration and network, then retry.": "Neplatný kandidát 'proxmox-ve' (nie je 9.x alebo chýba). Skontrolujte nastavenie repozitárov a sieť, potom skúste znova.", + "Invalid ALLOWED_HOSTS value": "Neplatná hodnota UDELENÁ HOSTS", + "Invalid Home Assistant OS check timeout": "Neplatný čas odhlásenia Home Assistant OS", "Invalid ID": "Neplatné ID", + "Invalid Intel render path": "Neplatná cesta k zobrazeniu informácií", + "Invalid Jellyfin path:": "Neplatná cesta Jellyfin:", + "Invalid MAC address:": "Neplatná adresa MAC:", + "Invalid NVIDIA destination": "Neplatné miesto určenia NVIDIA", + "Invalid NVIDIA device:": "Neplatné NVIDIA zariadenie:", + "Invalid Nextcloud volume": "Neplatný objem Nextcloud", + "Invalid OCI Entrypoint": "Neplatný vstupný bod OCI", + "Invalid OCI digest": "Neplatná digescia OCI", + "Invalid OCR language:": "Neplatný jazyk OCR:", "Invalid Option": "Neplatná možnosť", "Invalid Path": "Neplatná cesta", + "Invalid Proxmox inventory": "Neplatný inventár Proxmox", + "Invalid Python index:": "Neplatný Python index:", + "Invalid Python module:": "Neplatný modul Python:", + "Invalid Python package:": "Neplatný Python balík:", + "Invalid Python path in the repair:": "Neplatná cesta Python v oprave:", + "Invalid Unpackerr variable": "Neplatná premenná Unpackerr", + "Invalid VFS cache mode": "Neplatný režim vyrovnávacej pamäte VFS", "Invalid VMID": "Neplatné VMID", + "Invalid VMID or timeout": "Neplatný VMID alebo časový limit", + "Invalid VMID:": "Neplatný VMID:", "Invalid ZFS pool name.": "Neplatný názov ZFS poolu.", + "Invalid absolute mount path": "Neplatná absolútna pripojovacia dráha", + "Invalid absolute path; avoid spaces, commas and relative segments": "Neplatná absolútna cesta; vyhnúť sa medzerám, čiarkam a relatívnym segmentom", + "Invalid acceleration profile": "Neplatný profil zrýchlenia", + "Invalid access address:": "Neplatná adresa prístupu:", + "Invalid administrator email": "Neplatný administrátorský mail", + "Invalid administrator user name": "Neplatné meno správcu", + "Invalid base VMID": "Neplatná základňa VMID", + "Invalid check package:": "Neplatný kontrolný balík:", + "Invalid configuration path:": "Neplatná konfiguračná dráha:", + "Invalid consume/export volumes": "Neplatné objemy spotreby/vývozu", + "Invalid container path:": "Neplatná trasa kontajnera:", + "Invalid credential file path:": "Neplatná cesta k credential súboru:", + "Invalid declarative entrypoint": "Neplatný deklaratívny vstupný bod", + "Invalid declarative stop signal": "Neplatná deklaratívna zastávka signal", + "Invalid declarative working directory": "Neplatný deklaratívny pracovný adresár", + "Invalid device UID:": "Neplatné UID zariadenie:", + "Invalid device mode": "Neplatný režim zariadenia", + "Invalid device mode:": "Neplatný režim zariadenia:", + "Invalid device path:": "Neplatná cesta zariadenia:", + "Invalid device paths for": "Neplatné cesty zariadenia pre", "Invalid group name. Use letters, digits, underscore or hyphen, and start with a letter or underscore.": "Neplatný názov skupiny. Použite písmená, čísla, podčiarkovník alebo pomlčku a začnite písmenom alebo podčiarkovníkom.", + "Invalid health check": "Neplatná kontrola zdravotného stavu", + "Invalid healthcheck path": "Neplatná cesta kontroly zdravotného stavu", + "Invalid healthcheck port": "Neplatný port na kontrolu zdravotného stavu", + "Invalid healthcheck request timeout": "Neplatná lehota na kontrolu zdravotného stavu", + "Invalid healthcheck scheme": "Neplatná schéma kontroly zdravotného stavu", + "Invalid healthcheck stability period": "Neplatná doba stability zdravotného poistenia", + "Invalid healthcheck timeout": "Neplatná lehota na kontrolu zdravotného stavu", + "Invalid host kernel module name:": "Neplatné meno modulu jadra hostiteľa:", + "Invalid host monitor PID": "Neplatný monitor hostiteľa PID", + "Invalid host path:": "Neplatná cesta k hostiteľovi:", + "Invalid image probe descriptor": "Neplatný deskriptor obrazovej sondy", "Invalid input": "Neplatný vstup", + "Invalid internal volume": "Neplatný vnútorný objem", + "Invalid list:": "Neplatný zoznam:", + "Invalid machine learning CPU allocation:": "Neplatné pridelenie CPU pre strojové učenie:", + "Invalid machine learning resources": "Neplatné zdroje strojového učenia", + "Invalid main member or duplicated members": "Neplatný hlavný člen alebo duplikovaný člen", + "Invalid media path": "Neplatná mediálna cesta", + "Invalid media volume": "Neplatný objem média", + "Invalid mediafiles volume": "Neplatný objem súborov médií", + "Invalid minimum version:": "Neplatná minimálna verzia:", + "Invalid mount name": "Neplatné meno pripojenia", + "Invalid mount type": "Neplatný typ pripojenia", "Invalid name": "Neplatný názov", "Invalid name. Use only letters, numbers, hyphens and underscores.": "Neplatný názov. Použite iba písmená, čísla, pomlčky a podčiarkovníky.", + "Invalid native entrypoint": "Neplatný domáci vstupný bod", + "Invalid octal permissions": "Neplatné oktálne práva", "Invalid option": "Neplatná voľba", "Invalid option, please try again.": "Neplatná možnosť, skúste to znova.", "Invalid option. Skipping.": "Neplatná možnosť. Preskakujem.", + "Invalid or duplicated mount path": "Neplatná alebo zdvojená cesta pripojenia", + "Invalid or duplicated network sysctl": "Neplatný alebo duplicitný sieťový sysctl", "Invalid parameters for bind mount": "Neplatné parametre pre bind mount", + "Invalid path": "Neplatná cesta", + "Invalid path in the NVIDIA inventory": "Neplatná cesta v inventári NVIDIA", + "Invalid post-start timeout in the configuration:": "Neplatný čas po štarte v konfigurácii:", + "Invalid private bridge": "Neplatný súkromný most", + "Invalid private network": "Neplatná súkromná sieť", + "Invalid prlimit value": "Neplatná hodnota prlimitu", + "Invalid process limits format": "Neplatný formát obmedzení procesu", + "Invalid registry digest": "Neplatné trávenie registra", + "Invalid remote name": "Neplatné vzdialené meno", + "Invalid remote path": "Neplatná vzdialená cesta", + "Invalid repair version:": "Neplatná verzia opravy:", + "Invalid resources": "Neplatné zdroje", + "Invalid restored volume path": "Neplatná cesta obnoveného objemu", + "Invalid running state": "Neplatný jazdný stav", + "Invalid security.unprivileged value:": "Neplatné zabezpečenie.neprivilegovaná hodnota:", "Invalid selection": "Neplatný výber", + "Invalid service alias": "Neplatný alias služby", + "Invalid service check URL": "Neplatné URL služby", + "Invalid service check arguments": "Neplatné kontrolné argumenty služby", + "Invalid service check timeout": "Neplatný čas odhlásenia služby", + "Invalid shared path": "Neplatná spoločná cesta", + "Invalid shutdown timeout": "Neplatný čas vypnutia", "Invalid size. Please enter a number in MB (e.g., 128, 256, 512).": "Neplatná veľkosť. Zadajte číslo v MB (napr. 128, 256, 512).", + "Invalid stack contract": "Neplatná zmluva o zásobníku", + "Invalid stack journal": "Neplatný zásobník", + "Invalid stack members": "Neplatní členovia stohu", + "Invalid stack name": "Neplatný názov stohu", + "Invalid stack operation": "Neplatný zásobník operation", "Invalid storage ID. Use only letters, numbers, hyphens and underscores.": "Neplatné ID úložiska. Použite iba písmená, čísla, pomlčky a podčiarkovníky.", + "Invalid suite application": "Neplatná aplikácia", + "Invalid sysctl value:": "Neplatná sysctl hodnota:", + "Invalid template storage": "Neplatná pamäť šablóny", + "Invalid tmpfs options:": "Neplatné možnosti tmpfs:", + "Invalid tmpfs path:": "Neplatná cesta tmpfs:", + "Invalid tmpfs size:": "Neplatná veľkosť tmpfs:", "Invalid username or password.": "Nesprávne meno používateľa alebo heslo.", + "Invalid variable name": "Neplatný názov premennej", + "Invalid variable name:": "Neplatný názov premennej:", + "Invalid volume size": "Neplatná veľkosť objemu", + "Invalid volume size:": "Neplatná veľkosť hlasitosti:", + "Invalid volume target": "Neplatný cieľ objemu", + "Is the value a password or secret?": "Je hodnota heslo alebo tajomstvo?", "Issue": "Problém", "Issues found": "Nájdené problémy", "Issues were found. Would you like to use the Guided Cleanup Assistant?": "Našli sa problémy. Chcete použiť sprievodcu čistením?", "Issues were found. Would you like to use the Guided Repair Assistant?": "Našli sa problémy. Chcete použiť sprievodcu opravou?", "It appears that you have already executed the xshok-proxmox post-install script on this system.": "Vyzerá to, že na tomto systéme už bol spustený post-install skript xshok-proxmox.", + "It asks for a system directory of the host:": "Žiada o systémový adresár hostiteľa:", + "It asks for capabilities or a relaxed confinement profile.": "Žiada o schopnosti alebo uvoľnený profil väzníc.", + "It asks to see the processes of the host.": "Žiada vidieť procesy hostiteľa.", + "It cannot be removed on its own, because the application would stop working: continuing removes the whole application.": "Nemôže sa odstrániť samostatne, pretože žiadosť by prestala fungovať: pokračuje v odstraňovaní celej aplikácie.", + "It is created empty; existing data is not migrated automatically.": "Vytvára sa prázdny; existujúce údaje sa automaticky neprenášajú.", "It is recommended to create a backup before continuing.": "Pred pokračovaním sa odporúča vytvoriť zálohu.", "It is strongly recommended to create a backup of your container before proceeding with the conversion.": "Pred prevodom sa dôrazne odporúča vytvoriť zálohu kontajnera.", + "It needs a privileged container, which is not isolated from the host.": "Potrebuje privilegovaný kontajner, ktorý nie je izolovaný od hostiteľa.", "It will be installed from the official GitHub repository.": "Nainštaluje sa z oficiálneho GitHub repozitára.", + "It works through the Docker engine of the host, and a native OCI container does not have one.": "Funguje prostredníctvom Docker motora hostiteľa, a natívne OCI kontajner nemá jeden.", "Italian": "Taliančina", + "Its Compose file asks for privileged mode; the container is created unprivileged and that mode is only offered as an option.": "Jeho súbor Compose požaduje privilegovaný režim; kontajner je vytvorený neprivilegovaný a tento režim je ponúkaný len ako možnosť.", + "Its final cleanup did not complete. Select the stack again in the OCI management menu to complete it.": "Jeho konečné vyčistenie sa nedokončilo. Vyberte zásobník znovu v menu správy OCI pre jeho dokončenie.", + "Its labels are not applied: they are read by other Docker tools.": "Nepoužijú sa jej označenia: čítajú ich iné nástroje Docker.", "JC Channel logo applied": "Logo JC Channel bolo použité", + "JDownloader 2 with browser GUI and MyJDownloader support": "JDownloader 2 s podporou prehliadača a MyJDownloader", + "JDownloader WebUI": "JDownloader WebUI", "JSON output for scripts": "JSON výstup pre skripty", + "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps.": "Jackett funguje ako proxy server: prekladá otázky z aplikácií (Sonarr, SickRage, CouchPotato, Mylar, atď) do tracker-site-specific http dotazov, analyzuje html odpoveď, potom pošle výsledky späť do žiadajúceho softvéru. To umožňuje získať najnovšie nahrávanie (ako RSS) a vykonávanie vyhľadávania. Jackett je jediný úložisko udržiavaného indexer škrabanie a preklad logiky - odstránenie záťaže z iných aplikácií.", + "Jellyfin WebUI": "Jellyfin WebUI", + "Jellyfin configuration applied:": "Použitá konfigurácia Jellyfin:", + "Jellyfin did not create encoding.xml before the timeout": "Jellyfin nevytvoril kódovanie.xml pred prestávkou", + "Jellyfin has not created encoding.xml in any declared path": "Jellyfin nevytvoril kódovanie.xml v žiadnej deklarovanej ceste", + "Jellyseerr is a free and open source software application for managing requests for your media library.": "Jellyseerr je bezplatná a open source softvérová aplikácia pre správu žiadostí o mediálnu knižnicu.", + "Jenkins Continuous Integration and Delivery server.": "Jenkins Nepretržitá integrácia a doručovací server.", + "Jenkins unlock": "Jenkins odomknúť", "Job ID (letters, numbers, - _)": "ID úlohy (písmená, čísla, - _)", "Job ID:": "ID úlohy:", "Job deleted:": "Úloha vymazaná:", "Job disabled:": "Úloha vypnutá:", "Job enabled:": "Úloha zapnutá:", "Job selection returned empty id — aborting.": "Výber úlohy vrátil prázdne ID - prerušujem.", + "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.": "Joplin je bezplatná, open source note, pričom a to-do aplikácie, ktoré dokážu zvládnuť veľký počet poznámok usporiadaných do notebookov.", "Journald configuration adjusted to": "Nastavenie journald bolo upravené na", "Journald configuration is already optimized": "Nastavenie journald už je optimalizované", "Journald configuration updated and service restarted": "Nastavenie journald bolo aktualizované a služba reštartovaná", "Journald optimization completed": "Optimalizácia journald je dokončená", "Journald optimized - Max size: 64M": "Journald je optimalizovaný - maximálna veľkosť: 64M", + "Jupyter Lab (token only)": "Jupyter Lab (iba token)", "KDF:": "KDF:", "KVM MSR options added to /etc/modprobe.d/kvm.conf": "Možnosti KVM MSR boli pridané do /etc/modprobe.d/kvm.conf", "KVM MSR options ensured in /etc/modprobe.d/kvm.conf": "Možnosti KVM MSR sú zaistené v /etc/modprobe.d/kvm.conf", "KVM MSR options not present, nothing to revert": "Možnosti KVM MSR nie sú prítomné, nie je čo vracať späť", + "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX ™ is a trademark of OffSec.": "Kali-linux - je Advanced Penetration Testing Linux distribúcia používaná pre Penetration Testing, Ethical Hacking a posúdenie bezpečnosti siete. KALI LINUX TM je ochranná známka OffSec.", + "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections.": "Kasm Workspaces je docker kontajner streaming platforma pre poskytovanie prístupu prehliadača na desktopy, aplikácie a webové služby. Kasm používa devops-povolený Containerized Desktop Infrastructure (CDI) vytvoriť na požiadanie, jednorazové, docker kontajnery, ktoré sú prístupné prostredníctvom webového prehliadača. Príkladom prípadov použitia je izolácia diaľkového prehliadača (RBI), prevencia straty dát (DLP), zbierka Desktop ako služba (DaaS), Secure Remote Access Services (RAS) a Open Source Intelligence (OSINT).", + "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!": "Kavita je rýchly, funkcie bohatý, cross platform čítanie servera. Postavený so zameraním na to, že úplné riešenie pre všetky vaše potreby čítania. Nastavte si vlastný server a podeľte sa o kolekciu čítania so svojimi priateľmi a rodinou!", + "Kavita is a free and open source web based Comic and Book Server.": "Kavita je zadarmo a open source web based Comic and Book Server.", + "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready.": "Kdenlive je výkonný voľný a otvorený zdroj multiplatformový program na úpravu videa vytvorený komunitou KDE. Motív bohatý a výroba pripravený.", + "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass).": "KeePassXC je bezplatný a open-source správca hesiel. Začalo sa to ako komunita fork z KeePassX (samotne ako cross-platform port KeePass).", "Keep GPU in LXC config (disable Start on boot)": "Ponechať GPU v nastavení LXC (vypnúť štart pri boote)", "Keep GPU in LXC config + disable Start on boot": "Ponechať GPU v nastavení LXC + vypnúť štart pri boote", "Keep GPU in VM config (disable Start on boot)": "Ponechať GPU v nastavení VM (vypnúť štart pri boote)", @@ -2356,6 +3135,7 @@ "Keep current version (N) if modified": "Ponechať aktuálnu verziu (N), ak bola upravená", "Keep in source VM(s) + disable onboot + add to target VM": "Ponechať v pôvodných VM + vypnúť onboot + pridať do cieľovej VM", "Keeping GPU in source VM config": "Ponechávam GPU v nastavení zdrojovej VM", + "Keeping the settings changed in Proxmox:": "Udržiavanie nastavenia v Proxmox:", "Kept sharedfiles group (has regular users assigned).": "Skupina sharedfiles zostala zachovaná (má priradených bežných používateľov).", "Kernel and architecture info": "Informácie o jadre a architektúre", "Kernel headers and build tools verified.": "Kernel headers a nástroje na zostavenie sú v poriadku.", @@ -2377,6 +3157,16 @@ "Keyfile recovery — pick source host": "Obnova keyfile - vyberte zdrojový host", "Keyfile removed.": "Keyfile odstránený.", "Keyrings method failed; trying apt-key fallback": "Metóda keyrings zlyhala; skúšam náhradný apt-key postup", + "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite.": "KiCad - Cross Platform a Open Source Electronics Design Automation Suite.", + "Kimai has no default account. Enter the container with: pct enter {main_vmid}": "Kimai nemá predvolený účet. Zadajte kontajner s: pct zadajte {main vmid}", + "Kimai is a professional grade time-tracking application, free and open-source.": "Kimai je profesionálna časová aplikácia, zadarmo a open-source.", + "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more.": "Kometa je výkonný nástroj navrhnutý tak, aby vám plnú kontrolu nad vaše mediálne knižnice. S Kometa, môžete vziať svoje prispôsobenie na ďalšiu úroveň, s granulovanou kontrolou nad metaúdaje, zbierky, prekrývanie, a oveľa viac.", + "Kometa reads its configuration from /config/config.yml and the container only ships /config/config.yml.template. Copy the template to config.yml, fill in the required Plex and TMDb connections, then restart the container.": "Kometa číta svoju konfiguráciu z /config/config.yml a kontajner iba lode /config/config.yml.templát. Skopírujte šablónu pre config.yml, vyplňte required Plex a TMDb pripojenia, potom reštartujte kontajner.", + "Komga is a media server for your comics, mangas, BDs, magazines and eBooks.": "Komga je mediálny server pre vaše komiksy, mangasy, BD, časopisy a eBooks.", + "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone.": "Krita je profesionálny zadarmo a open source maliarsky program. Je vyrobený umelcami, ktorí chcú vidieť dostupné umelecké nástroje pre každého.", + "LAN access to the kept containers (stack configuration incomplete):": "Prístup LAN k uloženým kontajnerom (konfigurácia koša neúplná):", + "LAN address applied to the application URLs": "LAN adresa použitá na URL aplikácie", + "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer.": "LM Studio môže spustiť miestne modely AI ako Gpt-oss, Llama, Gemma, Qwen, a DeepSeek súkromne na vašom počítači.", "LUNs appear as block devices assignable to VMs": "LUNy sa zobrazia ako blokové zariadenia priraditeľné k VM", "LVM PV headers check completed": "Kontrola LVM PV hlavičiek dokončená", "LVM physical volume detected": "Zistený fyzický zväzok LVM", @@ -2393,18 +3183,27 @@ "LXC containers with NVIDIA passthrough:": "LXC kontajnery s NVIDIA passthrough:", "LXC conversion from privileged to unprivileged completed successfully!": "Konverzia LXC z privilegovaného na neprivilegovaný kontajner bola úspešne dokončená.", "LXC conversion from unprivileged to privileged completed successfully!": "Konverzia LXC z neprivilegovaného na privilegovaný kontajner bola úspešne dokončená.", + "LXC entries outside the NVIDIA inventory of the journal": "LXC položiek mimo NVIDIA súpis časopisu", + "LXC entries outside the selected acceleration profile": "LXC položiek mimo zvoleného akceleračného profilu", + "LXC entry outside the read-only NVIDIA profile": "LXC vstup mimo profilu NVIDIA iba na čítanie", "LXC removed:": "LXC odstránený:", "LXC stopped": "LXC zastavený", "LXC update skipped by user.": "Aktualizácia LXC bola preskočená používateľom.", "LXCs to destroy:": "LXC na zničenie:", + "Lab interruption after installing the new container": "Prerušenie laboratória po inštalácii nového kontajnera", + "Lab interruption after protecting the data": "Prerušenie laboratória po ochrane údajov", + "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models.": "Label Studio je open source nástroj na označovanie dát. Umožňuje označiť dátové typy ako audio, text, obrázky, videá a časové rady jednoduchým a jednoduchým UI a exportovať do rôznych formátov modelu. Môže sa použiť na prípravu nespracovaných údajov alebo zlepšenie existujúcich údajov o odbornej príprave s cieľom získať viac modelov accurate ML.", "Label:": "Štítok:", "Language Change": "Zmena jazyka", "Language changed to": "Jazyk bol zmenený na", + "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)": "Jazyk/lokál (napr. es ES.UTF-8; preklad každej aplikácie nie je zaručený)", "Last 50 kernel log lines": "Posledných 50 riadkov logu jadra", "Last run:": "Posledné spustenie:", "Last system boot time": "Čas posledného štartu systému", "Latest version:": "Najnovšia verzia:", "Launching GPU passthrough assistant for VM": "Spúšťam sprievodcu priamym priradením GPU pre VM", + "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork.": "Lazylibrarian je program sledovať autorov a chytiť metaúdaje pre všetky vaše potreby digitálneho čítania. Používa combination of Goodreads Librarything a voliteľne GoogleBooks ako zdroje pre autora info a book info. Tento kontajner je založený na DobyTang fork.", + "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user’s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012).": "Software Llap-auth je určený pre autentifikáciu užívateľov, ktorí žiadajú chránené zdroje zo serverov proxied by nginx. Obsahuje démon (ldap-auth), ktorý komunikuje s autentifikačným serverom, a webserver démon, ktorý generuje autentifikačný cookie na základe užívateľa credentials. Démoni sú napísané v Python pre použitie s ľahkou Directory Access Protocol (LDAP) autentifikačný server (OpenLDAP alebo Microsoft Windows Active Directory 2003 a 2012).", "Legacy PVE 8 .list files commented or not present": "Staré .list súbory PVE 8 boli zakomentované alebo neexistujú", "Legacy ceph.list commented or not present": "Starý ceph.list bol zakomentovaný alebo neexistuje", "Legacy gasket-dkms cleanup could not be verified as complete.": "Dokončenie čistenia staršieho balíka gasket-dkms nebolo možné overiť.", @@ -2412,12 +3211,25 @@ "Legacy network tools (e.g., ifconfig)": "Staršie sieťové nástroje (napr. ifconfig)", "Legend:": "Vysvetlivky:", "Let's review your current network configuration.": "Pozrime si aktuálne nastavenie siete.", + "Liberate your videos and unleash infinite possibilities.": "Uvoľnite svoje videá a uvoľnite nekonečné možnosti.", + "Libraries: /data/media/movies, /data/media/series and /data/media/music. Select them in the media server.": "Knižnice: /data/media/mobiles, /data/media/series a /data/media/music. Vyberte ich na mediálnom serveri.", + "Library size in GB": "Veľkosť knižnice v GB", + "LibreDB Studio": "LibreDB Studio", + "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity.": "LibreOffice je bezplatný a výkonný kancelársky apartmán a nástupca OpenOffice.org (bežne známy ako OpenOffice). Jeho čisté rozhranie a funkcie bohaté nástroje vám pomôžu uvoľniť vašu kreativitu a zvýšiť vašu produktivitu.", + "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM.": "LibreWolf je vlastná a nezávislá verzia Firefox, s primárnymi cieľmi súkromia, bezpečnosti a užívateľskej slobody. Cieľom LibreWolf je tiež odstrániť všetky telemetriu, zber dát a otravy, ako aj znemožniť protislobodnosť funkcií ako DRM.", + "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers.": "Librespeed je veľmi ľahký Speedtest implementovaný v Javascripte, pomocou XMLHttpRequest a Web Workers.", + "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Lidarr je manažérom hudobných kolekcií pre užívateľov Usenet a BitTorrent. To môže sledovať viac RSS kanálov pre nové stopy od svojich obľúbených umelcov a bude chytiť, triediť a premenovať ich. Môže byť tiež nakonfigurovaný tak, aby automaticky upgrade kvality súborov už stiahnutých, keď je k dispozícii kvalitnejší formát.", + "Lightweight Docker management UI": "Ľahké Docker Management UI", "Likely cause: host directory permissions deny the container's mapped UID.": "Pravdepodobná príčina: oprávnenia priečinka na hostovi nepovoľujú namapované UID kontajnera.", "Limiting size and optimizing journald": "Obmedzujem veľkosť a optimalizujem journald", "Limiting size and optimizing journald...": "Obmedzujem veľkosť a optimalizujem journald...", + "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot.": "Limnoria Robustný, full-featured, a užívateľsky / programátor-friendly Python IRC robot, s mnohými existujúcimi modulmi. Nástupca známeho Supybota.", + "Limnoria joins no IRC network until its configuration file exists. Create it with the setup wizard from the Proxmox host: pct exec -- bash -c 'cd /config && limnoria-wizard'": "Limnoria sa pripája k žiadnej sieti IRC, kým neexistuje jej konfiguračný súbor. Vytvorte ho pomocou sprievodcu nastavením z Proxmox hostiteľa: pct exec -- bash -c 'cd /config && limnoria-wizard'", "Line to paste (single line, including \"command=...\" prefix):": "Riadok na vloženie (jeden riadok vrátane predpony \"command=...\"):", "Linux Installation Options": "Možnosti inštalácie Linuxu", "Linux/Mac path:": "Cesta pre Linux/Mac:", + "LinuxServer Jellyfin with optional GPU passthrough": "LinuxServer Jellyfin s voliteľným GPU priechodom", + "LinuxServer MariaDB requires a user, database and password": "LinuxServer MariaDB requires a user, databáza a heslo", "List Available Disks": "Zobraziť dostupné disky", "List IOMMU group mapping": "Zobraziť mapovanie IOMMU skupín", "List NVMe devices": "Zobraziť NVMe zariadenia", @@ -2443,7 +3255,9 @@ "Listening on:": "Počúva na:", "Listening ports:": "Počúvajúce porty:", "Listing relevant CT users and their mapped UID/GID on host...": "Zobrazujem relevantných používateľov CT a ich namapované UID/GID na hostovi...", + "Load and verify the WireGuard module on the Proxmox host": "Načítať a overiť WireGuard modul na Proxmox hostiteľa", "Loading modules...": "Načítavam moduly...", + "Loading the host kernel module:": "Načítavam modul hostiteľského jadra:", "Local Disk Manager - Proxmox Host": "Správca lokálnych diskov - Proxmox host", "Local Disk Storages": "Lokálne diskové úložiská", "Local Shared Directory on Host": "Lokálny zdieľaný priečinok na serveri", @@ -2454,6 +3268,7 @@ "Local keyfile is missing but a recovery copy was found in PBS.": "Lokálny keyfile chýba, ale v PBS sa našla obnovovacia kópia.", "Local network only (192.168.0.0/16)": "Iba lokálna sieť (192.168.0.0/16)", "Local restore error log": "Záznam chyby lokálnej obnovy", + "Local storage for PostgreSQL": "Lokálne skladovanie pre PostgreSQL", "Locale generated": "Locale bolo vytvorené", "Location:": "Umiestnenie:", "Log": "Záznam", @@ -2469,6 +3284,7 @@ "Logged-in users": "Prihlásení používatelia", "Logrotate optimization completed": "Optimalizácia logrotate je dokončená", "Logrotate service restarted successfully": "Služba logrotate bola úspešne reštartovaná", + "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment.": "Lollypop je ľahký moderný hudobný prehrávač navrhnutý tak, aby pracoval vynikajúco na GNOME desktop prostredí.", "Long Test — Background": "Dlhý test - na pozadí", "Long self-test started on": "Dlhý samo-test bol spustený na", "Long test — full scan, runs in background if closed": "Dlhý test - úplná kontrola, beží na pozadí aj po zatvorení", @@ -2477,7 +3293,11 @@ "Lookup domain registration info": "Vyhľadať registračné informácie domény", "Low Container Memory": "Málo pamäte v kontajneri", "Low free space warning": "Upozornenie na málo voľného miesta", + "Low-code programming for event-driven applications": "Nízkokódové programovanie pre aplikácie riadené udalosťami", "Low-power CPU platform": "Úsporná CPU platforma", + "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation": "Luanti (predtým Minetest) je open source voxel-creation platforma s jednoduchým moding a tvorba hry", + "Lucky web interface": "Webové rozhranie Lucky", + "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.": "Lychee je bezplatný nástroj na správu fotografií, ktorý beží na vašom serveri alebo webovom priestore. Inštalácia je otázka sekúnd. Nahrajte, spravujte a zdieľajte fotografie ako z natívnej aplikácie. Lychee prichádza so všetkým, čo potrebujete a všetky vaše fotografie sú uložené bezpečne.", "Lynis - Security Audit": "Lynis - bezpečnostná kontrola", "Lynis Management": "Správa Lynis", "Lynis command not found": "Príkaz Lynis sa nenašiel", @@ -2492,26 +3312,38 @@ "Lynis updated to version:": "Lynis aktualizovaný na verziu:", "Lynis version:": "Verzia Lynis:", "Lynis was not installed from Git. Reinstalling...": "Lynis nebol nainštalovaný z Gitu. Preinštalovávam...", + "Lyrion Music Server is a streaming audio server for Squeezebox audio players.": "Lyrion Music Server je streaming audio server pre Squeezebox audio prehrávače.", "M.2 / PCIe devices:": "M.2 / PCIe zariadenia:", + "M3U proxy server": "M3U proxy server", "MAC Address": "MAC adresa", + "MAC address": "Adresa MAC", "MACHINE TYPE": "TYP STROJA", + "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers.": "MAME je bezplatný a open-source emulátor určený na napodobnenie hardvéru arkádových hier, herných konzol, starých počítačov a ďalších systémov v softvéri na moderných osobných počítačoch.", "MOTD configuration updated successfully": "Nastavenie MOTD bolo úspešne aktualizované", "MOTD configuration was already up to date": "Konfigurácia MOTD už bola aktuálna", "Machine Type": "Typ stroja", + "Machine learning": "Strojové učenie", + "Machine learning profile not implemented; it is not replaced by CPU:": "Strojový vzdelávací profil nie je implementovaný; nie je nahradený CPU:", "Machine type: q35": "Typ stroja: q35", "Machine: q35": "Stroj: q35", + "Main endpoint not yet defined": "Hlavný cieľ zatiaľ nedefinovaný", "Major version differs:": "Hlavná verzia sa líši:", "Make sure IOMMU is properly enabled and the system has been rebooted after activation.": "Uistite sa, že IOMMU je správne zapnuté a systém bol po aktivácii reštartovaný.", "Make sure there are no critical services running as they will be interrupted. Ensure your server can be safely rebooted.": "Uistite sa, že nebežia dôležité služby, pretože budú prerušené. Server reštartujte iba vtedy, keď je to bezpečné.", "Make sure you have SSH or Web UI access before rebooting.": "Pred reštartom sa uistite, že máte prístup cez SSH alebo webové rozhranie.", "Makefile missing in": "Makefile chýba v", "Malformed repository entries cleaned": "Poškodené položky repozitárov vyčistené", + "Manage OCI": "Správa OCI", + "Manage OCI stack": "Spravovať stack OCI", "Manage PBS encryption keyfile": "Spravovať šifrovací keyfile pre PBS", "Manage Secure Gateway": "Spravovať Secure Gateway", "Manage and inspect VM disk images": "Spravovať a kontrolovať diskové obrazy VM", "Manage custom backup paths": "Spravovať vlastné cesty zálohy", "Manage custom paths (add / remove your folders)": "Spravovať vlastné cesty (pridať / odstrániť priečinky)", + "Manage installed OCI applications": "Spravovať nainštalované aplikácie OCI", "Manage local backup target": "Spravovať lokálny cieľ záloh", + "Managed disks must have backup enabled and a valid size": "Spravované disky musia mať zapnuté zálohovanie a platnú veľkosť", + "Managing Nginx proxy hosts with a simple, powerful interface.": "Správa Nginx proxy hostiteľov s jednoduchým, výkonným rozhraním.", "Manual CLI Guide (Disk and Storage Manager)": "Ručný návod v termináli (disky a úložiská)", "Manual CLI Guide (GPU/TPU)": "Ručný návod v termináli (GPU/TPU)", "Manual Guide: Convert LXC Privileged to Unprivileged": "Ručný návod: prevod LXC z privilegovaného na neprivilegovaný", @@ -2526,29 +3358,51 @@ "Manual review is required.": "Vyžaduje sa manuálna kontrola.", "Manual steps recommended after import": "Odporúčané ručné kroky po importe", "Manual upgrade guide step by step": "Ručný sprievodca aktualizáciou krok za krokom", + "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing.": "Manyfold je open source, self-hosted webová aplikácia pre správu kolekcie 3D modelov, najmä zamerané na 3D tlač.", "Mapped GID on host": "GID namapované na serveri", "Mapped UID on host": "UID namapované na serveri", + "Mariadb is one of the most popular database servers. Made by the original developers of MySQL.": "Mariadb je jedným z najpopulárnejších databázových serverov. Vyrobený pôvodnými vývojármi MySQL.", + "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..": "Mastodon je bezplatný, open-source server sociálnej siete založený na ActivityPub, kde používatelia môžu sledovať priateľov a objavovať nové..", "Max FD limit / ulimit configured": "Maximálny FD limit / ulimit je nastavený", "Max FS open files configuration created successfully": "Nastavenie maximálneho počtu otvorených súborov bolo úspešne vytvorené", "Max user watches configured": "Maximálny počet user watches je nastavený", "Maximum auto-repair attempts reached (3). Please review the log and run any remaining commands manually.": "Bol dosiahnutý maximálny počet automatických opráv (3). Skontrolujte záznam a zostávajúce príkazy spustite ručne.", "May need to restart terminal": "Možno bude potrebné reštartovať terminál", + "Media & Streaming": "Media & Streaming", + "Media discovery and request management for Jellyfin, Plex and Emby.": "Mediálny prieskum a správa požiadaviek pre Jellyfin, Plex a Emby.", + "Media library transcoding and health checking, with an internal worker node.": "Média knižnica transkódovanie a zdravotná kontrola, s interným uzol pracovníka.", + "Media server": "Mediálny server", + "Media server selection cancelled or invalid": "Výber mediálneho servera zrušený alebo neplatný", + "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well.": "MediaElch je MediaManager pre Kodi. Informácie o filmoch, TV Shows, koncertoch a hudbe sú uložené ako nfo súbory. Fanarty sa automaticky sťahujú z fanart.tv. Pomocou nFo generátora, MediaElch môžu byť použité s inými MediaCenters rovnako.", + "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Medusa je automatický manažér videoknižnice pre TV show. Sleduje nové epizódy vašich obľúbených šou, a keď sú zverejnené to robí jeho mágiu.", + "Memory": "Pamäť", + "Memory in MB": "Pamäť v MB", "Memory optimization completed.": "Optimalizácia pamäte je dokončená.", "Memory optimizations removed": "Optimalizácie pamäte boli odstránené", "Memory restored.": "Pamäť obnovená.", "Memory settings optimized successfully": "Nastavenie pamäte bolo úspešne optimalizované", "Memory:": "Pamäť:", + "Memos is a lightweight, self-hosted memo hub. Open Source and Free forever.": "Memos je ľahký, self-hosted memo centrum. Open Source a Free navždy.", + "Messaging & Queues": "Správy a fronty", + "Messenger for the Decentralized Web": "Posol pre decentralizovaný web", "Method:": "Spôsob:", + "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium.": "Microsoft Edge je cross-platform webový prehliadač vyvinutý spoločnosťou Microsoft a založený na Chromium.", "Migrate VMs away from node being upgraded": "Presuňte VM mimo uzol, ktorý sa aktualizuje", "Migrate away any guests that must keep running": "Presuňte mimo uzla všetkých hostí, ktorí musia zostať bežať", "Migrated": "Migrované", "Migrated legacy ProxMenux NVIDIA blacklist state — module will reload after reboot": "Starý stav ProxMenux NVIDIA blacklistu bol migrovaný - modul sa znovu načíta po reštarte", + "MineOS web interface": "Webové rozhranie MineOS", + "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards.": "Minisatip je viacväzbová satipová verzia 1.2, ktorá beží pod Linuxom a bola testovaná pomocou DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC a ISDB-T kariet.", "Mirror URL not available for this script.": "Záložná adresa pre tento skript nie je dostupná.", + "Miscellaneous": "Rôzne", "Missing": "Chýba", + "Missing OCI metadata:": "Chýbajúce metaúdaje OCI:", "Missing commands after installation:": "Po inštalácii stále chýbajú tieto príkazy:", "Missing dependency": "Chýbajúca závislosť", + "Missing native directive:": "Chýbajúce domáce smernice:", "Missing on target:": "Chýba na cieli:", "Missing or invalid parameter": "Parameter chýba alebo je neplatný", + "Missing required command:": "Chýba required príkaz:", "Missing required parameter": "Chýba povinný parameter", "Mixed GPU Modes": "Rôzne režimy GPU", "Mixed current mode detected in selected GPU(s).": "Vybrané GPU sú v rôznych aktuálnych režimoch.", @@ -2556,15 +3410,20 @@ "Mode": "Režim", "Model": "Model", "Modern resource monitor (press q to exit)": "Moderný monitor zdrojov (ukončíte klávesom q)", + "Modern, easy to use download automation for torrents and usenet.": "Moderná, ľahko ovládateľná automatizácia sťahovania pre torrenty a usenet.", "Modifying Fastfetch configuration...": "Upravujem nastavenie Fastfetch...", "Modules configuration updated.": "Nastavenie modulov bolo aktualizované.", "Modules loaded.": "Moduly boli načítané.", + "MongoDB 4.4, the last series that runs on a CPU without AVX.": "MongoDB 4.4, posledná séria beží na CPU bez AVX.", + "Monica is an open source personal relationship management system, that lets you document your life.": "Monica je open source systém riadenia osobných vzťahov, ktorý vám umožní dokumentovať svoj život.", "Monitor Activated": "Monitor je zapnutý", "Monitor Deactivated": "Monitor je vypnutý", "Monitor URL": "Adresa Monitora", "Monitor disk I/O usage (press q to exit)": "Sledovať využitie diskového I/O (ukončíte klávesom q)", "Monitor progress:": "Sledovanie priebehu:", + "Monitor, analyze, and alert on network performance.": "Monitorovať, analyzovať a upozorniť na výkonnosť siete.", "Monitoring": "Monitorovanie", + "Monitoring & Analytics": "Monitorovanie a analýza", "Most common cause: the archive is corrupted (interrupted write, partial copy, or storage issue).": "Najčastejšia príčina: archív je poškodený (prerušený zápis, neúplná kópia alebo problém s úložiskom).", "Mount Added Successfully:": "Mount bol úspešne pridaný:", "Mount CIFS share:": "Pripojiť CIFS zdieľanie:", @@ -2592,13 +3451,19 @@ "Mount Samba Share on Host": "Pripojiť Samba zdieľanie na hostovi", "Mount USB disk?": "Pripojiť USB disk?", "Mount a USB drive now": "Pripojiť USB disk teraz", + "Mount activation cancelled": "Aktivácia montáže zrušená", "Mount all datasets": "Pripojiť všetky datasety", "Mount already exists for this path in container": "Pre túto cestu už v kontajneri mount existuje", "Mount and persist with UUID:": "Pripojiť a uložiť natrvalo pomocou UUID:", + "Mount configuration cancelled": "Konfigurácia montáže zrušená", "Mount failed": "Pripojenie zlyhalo", + "Mount mode applied": "Použitý režim montáže", + "Mount name": "Názov pripojenia", + "Mount not authorized by the operation": "Pripojiť nie je povolené operation", "Mount options:": "Možnosti pripojenia:", "Mount path must be an absolute path starting with /": "Cesta pripojenia musí byť absolútna a začínať znakom /", "Mount path:": "Cesta pripojenia:", + "Mount paths must not overlap": "Pripojiť cesty sa nesmú prekrývať", "Mount point created": "Mount point bol vytvorený", "Mount point created.": "Mount point bol vytvorený.", "Mount point is visible but NOT writable from inside the container": "Mount point je viditeľný, ale zvnútra kontajnera NIE JE zapisovateľný", @@ -2607,11 +3472,14 @@ "Mount point ready:": "Mount point je pripravený:", "Mount point removed successfully": "Mount point bol úspešne odstránený", "Mount point:": "Mount point:", + "Mount points added:": "Pridanie bodov pripojenia:", + "Mount read-only": "Pripojiť iba na čítanie", "Mount shares on HOST first": "Najprv pripojiť zdieľania na HOSTE", "Mount specific dataset": "Pripojiť konkrétny dataset", "Mount status:": "Stav pripojenia:", "Mount this device and use it as the backup destination?": "Pripojiť toto zariadenie a použiť ho ako cieľ záloh?", "Mount was busy — performed lazy unmount": "Mount sa používal - vykonalo sa oneskorené odpojenie (lazy unmount)", + "Mount your cloud drive on your home NAS": "Namontujte svoju cloudovú jazdu na váš domov NAS", "Mounted": "Pripojené", "Mounted ISO on device": "ISO bolo pripojené k zariadeniu", "Mounted at": "Pripojené v", @@ -2626,8 +3494,17 @@ "Mounting here will hide existing files until unmounted.": "Pripojenie do tohto priečinka dočasne skryje existujúce súbory, kým zdieľanie neodpojíte.", "Move that copy offsite (USB, password manager, another host). Delete it from this path when done.": "Presuňte túto kópiu mimo servera (USB, správca hesiel, iný host). Po dokončení ju z tejto cesty odstráňte.", "Move to target VM (remove from source VM config)": "Presunúť do cieľovej VM (odstrániť zo zdrojovej VM)", + "Moving the data volumes aside": "Presun dátových objemov bokom", + "Moving the data volumes aside...": "Presunúť dáta nabok...", + "Multi-container application (experimental)": "Použitie viacerých kontajnerov (experimentálne)", + "Multi-line variables are not supported": "Multi-line premenné nie sú podporované", + "Multiple networks or external networks are not yet supported": "Viaceré siete alebo externé siete zatiaľ nie sú podporované", "Multiple recovery groups found in PBS. Pick the one that originally created the keyfile:": "V PBS sa našlo viac obnovovacích skupín. Vyberte tú, ktorá pôvodne vytvorila keyfile:", "Multiple rootfs directories were found in this archive. Restore cannot continue automatically.": "V tomto archíve sa našlo viac priečinkov rootfs. Automatická obnova nemôže pokračovať.", + "Music Collection and Streaming Server": "Zber hudby a streamovanie servera", + "Music software that transforms your listening experience": "Hudobný softvér, ktorý mení vaše počúvanie", + "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more.": "MySQL Workbench je jednotný vizuálny nástroj pre databázových architektov, vývojárov a DBA. MySQL Workbench poskytuje dátové modelovanie, vývoj SQL a komplexné nástroje správy pre konfiguráciu serverov, správu užívateľov, zálohovanie a oveľa viac.", + "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL.": "Mylar3 je automatický downloader Comic Book (cbr/cbz) pre použitie s NZB a torrenty napísané v pythone. Podporuje SABnzbd, NZBGET, a mnoho torrentových klientov okrem DDL.", "NAS Systems": "NAS systémy", "NETWORK CONFIGURATION ANALYSIS": "ANALÝZA NASTAVENIA SIETE", "NFS Access Restricted": "NFS prístup je obmedzený", @@ -2691,24 +3568,33 @@ "NOT FOUND": "NENÁJDENÉ", "NOTE: The host directory and its contents will remain unchanged.": "POZNÁMKA: priečinok na hostovi ani jeho obsah sa nezmenia.", "NVENC patch detected — list narrowed to versions supported by keylase/nvidia-patch.": "Zistil sa NVENC patch - zoznam je zúžený na verzie podporované cez keylase/nvidia-patch.", + "NVIDIA (CUDA)": "NVIDIA (CUDA)", + "NVIDIA (CUDA; official GPU image)": "NVIDIA (CUDA; oficiálny obraz GPU)", + "NVIDIA (NVDEC/CUDA)": "NVIDIA (NVDEC/CUDA)", + "NVIDIA (NVENC/NVDEC)": "NVIDIA (NVENC/NVDEC)", "NVIDIA Actions": "Akcie pre NVIDIA", "NVIDIA CPU hiding already configured": "NVIDIA CPU skrytie už je nastavené", "NVIDIA Container Toolkit": "NVIDIA Container Toolkit", + "NVIDIA Container Toolkit could not generate the runtime inventory": "NVIDIA Container Toolkit nemohol vygenerovať časový inventár", "NVIDIA Container Toolkit installed. GPU validation pending until the host restarts.": "Nainštalovaná súprava NVIDIA Container Toolkit. Čaká sa na overenie GPU, kým sa hostiteľ nereštartuje.", "NVIDIA Container Toolkit is incomplete. Missing:": "NVIDIA Container Toolkit je neúplná. Chýba:", "NVIDIA Container Toolkit is installed but its command line did not answer.": "NVIDIA Container Toolkit je nainštalovaný, ale jeho príkazový riadok neodpovedá.", + "NVIDIA Container Toolkit is missing on the host (nvidia-container-cli)": "NVIDIA Kontajner Toolkit chýba na hostiteľa (nvidia-container-cli)", "NVIDIA Container Toolkit verified against the running driver.": "Súprava NVIDIA Container Toolkit overená voči spustenému ovládaču.", "NVIDIA DKMS entries removed.": "NVIDIA DKMS záznamy boli odstránené.", "NVIDIA Driver Uninstall": "Odinštalovanie ovládača NVIDIA", "NVIDIA Driver Version": "Verzia ovládača NVIDIA", "NVIDIA Drivers": "Ovládače NVIDIA", "NVIDIA Drivers Not Found": "NVIDIA ovládače sa nenašli", + "NVIDIA GPU / CUDA (Toolkit on the host)": "NVIDIA GPU / CUDA (Toolkit na hostiteľa)", "NVIDIA GPU Driver Installation": "Inštalácia ovládača NVIDIA GPU", "NVIDIA GPU passthrough configured.": "NVIDIA GPU passthrough je nastavený.", + "NVIDIA GPU prepared:": "NVIDIA GPU pripravený:", "NVIDIA KVM args configured (kvm=off, vendor_id spoof)": "NVIDIA KVM argumenty nastavené (kvm=off, vendor_id spoof)", "NVIDIA KVM hiding (cpu hidden=1)": "NVIDIA KVM skrytie (cpu hidden=1)", "NVIDIA KVM hiding already configured": "NVIDIA KVM skrytie už je nastavené", "NVIDIA Patch": "NVIDIA patch", + "NVIDIA device outside the expected native profile": "Zariadenie NVIDIA mimo očakávaného prirodzeného profilu", "NVIDIA driver": "Ovládač NVIDIA", "NVIDIA driver installed successfully.": "Ovládač NVIDIA bol úspešne nainštalovaný.", "NVIDIA driver installed:": "Ovládač NVIDIA nainštalovaný:", @@ -2716,6 +3602,7 @@ "NVIDIA drivers are not installed or not loaded on this host.": "NVIDIA ovládače nie sú na tomto hostovi nainštalované alebo načítané.", "NVIDIA host services disabled for VFIO mode": "NVIDIA služby hosta vypnuté pre VFIO režim", "NVIDIA host services/autoload already aligned for native mode": "Služby/autoload NVIDIA na hoste už sú pripravené pre natívny režim", + "NVIDIA inside the container does not match the host driver or GPU": "NVIDIA vo vnútri kontajnera nezodpovedá hostiteľovi alebo GPU", "NVIDIA install incomplete. Check log:": "NVIDIA inštalácia nie je kompletná. Skontrolujte záznam:", "NVIDIA installer downloaded successfully": "NVIDIA inštalátor bol úspešne stiahnutý", "NVIDIA installer extracted.": "NVIDIA inštalátor rozbalený.", @@ -2724,29 +3611,50 @@ "NVIDIA installer returned error": "NVIDIA inštalátor vrátil chybu", "NVIDIA kernel modules unloaded successfully.": "Kernel moduly NVIDIA boli úspešne uvoľnené.", "NVIDIA libs require approximately 1.5GB of free space.": "NVIDIA knižnice vyžadujú približne 1,5 GB voľného miesta.", + "NVIDIA mount with an unauthorized source or target": "Pripojenie NVIDIA s neoprávneným zdrojom alebo cieľom", "NVIDIA patch applied - check README for supported versions.": "NVIDIA patch bol použitý - podporované verzie nájdete v README.", "NVIDIA patch not applied.": "NVIDIA patch nebol použitý.", "NVIDIA per-BDF VFIO binding configured": "NVIDIA VFIO naviazanie podľa BDF nastavené", + "NVIDIA permissions or device nodes differ from the official inventory": "Povolenie NVIDIA alebo uzly zariadení sa líšia od oficiálneho inventára", + "NVIDIA refresh validated; the container is stopped and its settings are kept": "NVIDIA obnovenie potvrdené; kontajner je zastavený a jeho nastavenia sú zachované", + "NVIDIA runtime libraries or components are missing": "NVIDIA runtime knižnice alebo komponenty chýbajú", + "NVIDIA selection not supported by this profile": "Výber NVIDIA nie je podporovaný týmto profilom", "NVIDIA services stopped and disabled.": "NVIDIA služby boli zastavené a vypnuté.", "NVIDIA udev rules and persistence service installed.": "NVIDIA udev pravidlá a persistence služba boli nainštalované.", "NVIDIA uninstallation steps completed.": "Kroky na odinštalovanie NVIDIA sú dokončené.", "NVIDIA uninstaller completed.": "NVIDIA odinštalovanie je dokončené.", "NVIDIA update failed for LXC": "Aktualizácia NVIDIA zlyhala pre LXC", "NVIDIA userspace libraries installed.": "NVIDIA userspace knižnice nainštalované.", + "NVML does not match the current host driver": "NVML nezodpovedá aktuálnemu hostiteľskému vodičovi", "NVMe Disk Detected": "Zistený NVMe disk", "NVMe critical_warning is 0 (no critical warnings reported).": "Kritické varovanie NVMe je 0 (žiadne kritické varovania nie sú hlásené).", + "NVMe health status: PASSED": "Stav NVMe: V PORIADKU", "NVMe health status: WARNING (critical_warning =": "Stav NVMe: UPOZORNENIE (critical_warning =", "NVMe skipped (to add as PCIe use 'Add Controller or NVMe PCIe to VM'):": "NVMe preskočené (ak ho chcete pridať ako PCIe, použite 'Pridať radič alebo NVMe PCIe do VM'):", "NVMe-specific SMART log": "SMART záznam špecifický pre NVMe", + "NVR & Cameras": "NVR & kamery", + "NVR with optional VA-API video acceleration and hardware object detectors": "NVR s voliteľným video zrýchlením VA-API a detektormi hardvérových objektov", + "NZBGet web interface": "Webové rozhranie NZBGet", + "Name": "Názov", + "Name for this application": "Názov tejto aplikácie", "Name for this target:": "Názov tohto cieľa:", + "Name of the PostgreSQL user created on the first start": "Názov užívateľa PostgreSQL vytvoreného pri prvom štarte", + "Name of the database created on the first start": "Názov databázy vytvorenej pri prvom štarte", + "Name of the internal worker node": "Názov vnútorného uzol pracovníka", + "Name of this wallabag instance, shown in the interface and in 2FA codes": "Názov tejto inštancie wallabag, zobrazený v rozhraní a v kódoch 2FA", + "Name or part of the description of the application": "Názov alebo časť opisu žiadosti", "Name:": "Názov:", + "Named accounts need private mode. Stop the container, set public: false in /config/config.js, start it again and create each user with: pct exec -- env THELOUNGE_HOME=/config s6-setuidgid abc thelounge add ": "Menované účty potrebujú súkromný režim. Zastaviť kontajner, nastaviť verejnosť: false in /config/config.js, začať znova a vytvoriť každého užívateľa s: pct exec < CTID> -- env THELOUNGE HOME=/config s6-setuid abc thelounge pridať ", "Neither /etc/kernel/cmdline nor /etc/default/grub found.": "Nenašiel sa /etc/kernel/cmdline ani /etc/default/grub.", "Nesting feature enabled": "Funkcia nesting bola zapnutá", "NetBIOS Service: RUNNING": "Služba NetBIOS: BEŽÍ", "NetBIOS Service: STOPPED": "Služba NetBIOS: ZASTAVENÁ", "NetBIOS port 139:": "NetBIOS port 139:", + "NetBox": "NetBox", + "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations.": "Netbox je nástroj riadenia IP adresy (IPAM) a riadenia infraštruktúry dátových centier (DCIM). Pôvodne koncipovaný sieťovým tímom v DigitalOcean, bol NetBox vyvinutý špeciálne pre potreby sieťových a infraštruktúrnych inžinierov. Je určený na fungovanie ako doménový špecifický zdroj pravdy pre siete operations.", "Network": "Sieť", "Network :": "Sieť :", + "Network & Firewall": "Sieťový & firewall", "Network (interfaces, DNS)": "Sieť (rozhrania, DNS)", "Network Bridge": "Sieťový bridge", "Network Commands": "Sieťové príkazy", @@ -2764,6 +3672,7 @@ "Network Restarted": "Sieť bola reštartovaná", "Network Tools": "Sieťové nástroje", "Network access:": "Sieťový prístup:", + "Network bridge": "Sieťový most", "Network configuration backed up": "Nastavenie siete bolo zálohované", "Network configuration has been restored from backup.": "Nastavenie siete bolo obnovené zo zálohy.", "Network connection failed to": "Sieťové pripojenie zlyhalo k", @@ -2776,12 +3685,16 @@ "Network service restarted successfully": "Sieťová služba bola úspešne reštartovaná", "Network service restarted successfully.": "Sieťová služba bola úspešne reštartovaná.", "Network share mounting (NFS/Samba) requires a PRIVILEGED container.": "Pripojenie sieťového zdieľania (NFS/Samba) vyžaduje PRIVILEGOVANÝ kontajner.", + "Network sysctls prepared:": "Sieťové sysktly pripravené:", "Network throughput test (client/server)": "Test sieťovej priepustnosti (klient/server)", + "Network-wide Ad Blocking": "Blokovanie reklamy v celej sieti", + "Network-wide ad and tracker blocking": "Blokovanie reklamy a trackerov v celej sieti", "NetworkManager Detected": "Zistený NetworkManager", "NetworkManager has been removed successfully": "NetworkManager bol úspešne odstránený", "NetworkManager is running (may cause conflicts)": "NetworkManager beží (môže spôsobovať konflikty)", "NetworkManager is running, which may conflict with Proxmox.": "NetworkManager beží a môže byť v konflikte s Proxmoxom.", "NetworkManager not running": "NetworkManager nebeží", + "Networks the peers reach through the tunnel (0.0.0.0/0 = all traffic)": "Siete, ktoré rovesníci dosahujú tunelom (0,0.0.0/0 = všetka doprava)", "New Folder in /mnt": "Nový priečinok v /mnt", "New Group": "Nová skupina", "New Search": "Nové hľadanie", @@ -2789,14 +3702,26 @@ "New Virtual Machine": "Nová virtuálna mašina", "New backup job": "Nová úloha zálohy", "New backups on this host will be unencrypted until a new keyfile is set up.": "Nové zálohy na tomto hostovi budú nešifrované, kým nenastavíte nový keyfile.", + "New image compatible:": "Nový obrázok kompatibilný:", + "New image installed": "Inštalovaný nový obrázok", + "New image installed, not verified yet": "Nainštalovaný nový obrázok, zatiaľ neoverený", + "New image verified, not saved yet": "Nový obrázok overený, zatiaľ neuložený", "New kernel staged; rebuilding DKMS drivers:": "Nový kernel je pripravený; znovu zostavujem DKMS ovládače:", "New mount options to apply:": "Nové možnosti pripojenia, ktoré sa použijú:", "New scheduled job (own timer + retention)": "Nová naplánovaná úloha (vlastný timer + uchovávanie)", + "New value for": "Nová hodnota pre", "New version available": "Dostupná nová verzia", "New version:": "Nová verzia:", "Next Step Required": "Je potrebný ďalší krok", "Next Steps:": "Ďalšie kroky:", "Next step: stop that VM first, then run": "Ďalší krok: najprv zastavte tú VM, potom spustite", + "Nextcloud configuration cancelled": "Konfigurácia Nextcloud zrušená", + "Nextcloud gives you access to all your files wherever you are.": "Nextcloud vám umožní prístup ku všetkým súborom kdekoľvek ste.", + "Nextcloud volume size in GB": "Nextcloud veľkosť objemu v GB", + "Nextcloud with private PostgreSQL and Redis dependencies": "Nextcloud s súkromnými PostgreSQL a Redis závislé", + "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server.": "Nginx je webový server HTTP, reverzný proxy, vyrovnávacia pamäť obsahu, načítací balander, proxy server TCP/UDP a proxy server pošty.", + "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.": "Nginx webserver a reverzný proxy s php podporou a vstavaný Certbot (Let's Encrypt) klient. Obsahuje aj fail2ban na prevenciu vniknutia.", + "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd.": "Ngircd je bezplatný, prenosný a ľahký internetový server Relay Chat pre malé alebo súkromné siete, vyvinutý podľa GNU General Public License (GPL). Je ľahko konfigurovateľný, dokáže sa vyrovnať s dynamickými IP adresami a podporuje pripojenie chránené IPv6, SSL, ako aj PAM pre autentifikáciu. Je napísaný od nuly a nie je založený na pôvodnom IRCd.", "No": "Nie", "No .ova or .ovf files found in:": "V tomto priečinku sa nenašli žiadne .ova ani .ovf súbory:", "No .ovf descriptor found inside OVA.": "V OVA sa nenašiel žiadny .ovf popisovač.", @@ -2814,6 +3739,7 @@ "No CTs available in the system.": "V systéme nie sú dostupné žiadne CT.", "No Changes Needed": "Nie sú potrebné žiadne zmeny", "No Cleanup Needed": "Čistenie nie je potrebné", + "No Compose file was given": "Nebol zadaný žiadny súbor", "No Controller/NVMe selected for now.": "Zatiaľ nie je vybraný žiadny Controller/NVMe.", "No Coral Detected": "Coral sa nenašiel", "No Coral TPU device was found on this host (neither PCIe/M.2 nor USB).": "Na tomto hoste sa nenašlo žiadne Coral TPU zariadenie (ani PCIe/M.2, ani USB).", @@ -2825,6 +3751,7 @@ "No Exports": "Žiadne exporty", "No Exports Found": "Nenašli sa žiadne exporty", "No Folders": "Žiadne priečinky", + "No GPU (CPU)": "Bez GPU (CPU)", "No GPU Detected": "GPU sa nenašla", "No GPU selected.": "Nebola vybraná žiadna GPU.", "No GPU selected. Please select at least one GPU to continue.": "Nie je vybraná žiadna GPU. Pre pokračovanie vyberte aspoň jednu GPU.", @@ -2832,12 +3759,15 @@ "No Guest Shares": "Žiadne hosťovské zdieľania", "No IP": "Bez IP", "No IP assigned": "IP adresa nie je priradená", + "No IPv4 address was detected after 30 seconds.": "Po 30 sekundách nebola zistená žiadna IPv4.", "No ISO file detected after UUP Dump process.": "Po procese UUP Dump sa nenašiel žiadny ISO súbor.", "No ISO images found in Proxmox ISO storages.": "V ISO úložiskách Proxmoxu sa nenašli žiadne ISO obrazy.", "No ISO selected.": "Nebolo vybrané žiadne ISO.", "No ISO was generated.": "Nebolo vytvorené žiadne ISO.", "No Images Found": "Nenašli sa žiadne obrazy", "No Intel GPU detected on this system.": "V tomto systéme sa nenašla žiadna Intel GPU.", + "No LAN address was obtained": "Nebola získaná adresa LAN", + "No LAN address was obtained for the service:": "Pre službu nebola získaná žiadna adresa LAN:", "No LXC containers available": "Nie sú dostupné žiadne LXC kontajnery", "No LXC containers found": "Nenašli sa žiadne LXC kontajnery", "No LXC containers found on this system.": "V systéme sa nenašli žiadne LXC kontajnery.", @@ -2855,7 +3785,9 @@ "No NFS shares currently mounted.": "Momentálne nie sú pripojené žiadne NFS zdieľania.", "No NVIDIA GPU detected on this system.": "V systéme nebola zistená žiadna NVIDIA GPU.", "No NVIDIA GPU has been detected on this system. The installer will now exit.": "V systéme nebola zistená žiadna NVIDIA GPU. Inštalátor sa teraz ukončí.", + "No NVIDIA GPU is available": "Nie je k dispozícii NVIDIA GPU", "No NVIDIA driver installed.": "Nie je nainštalovaný žiadny NVIDIA ovládač.", + "No OCI instances are registered.": "Žiadne prípady OCI nie sú registrované.", "No PBS keyfile is installed on this host and no automatic recovery was possible.": "Na tomto hostovi nie je nainštalovaný žiadny PBS keyfile a automatická obnova nebola možná.", "No PVE vzdump job uses a": "Žiadna PVE vzdump úloha nepoužíva", "No PVs with old headers found.": "Nenašli sa žiadne PV so starými hlavičkami.", @@ -2891,6 +3823,7 @@ "No Virtual Machines found on this system.": "V tomto systéme sa nenašli žiadne virtuálne stroje.", "No ZFS pools detected. Skipping ZFS ARC optimization.": "Nenašli sa žiadne ZFS pooly. Optimalizácia ZFS ARC sa preskočí.", "No ZFS pools detected. Skipping ZFS autotrim.": "Nenašli sa žiadne ZFS pooly. ZFS autotrim sa preskočí.", + "No acceleration (CPU)": "Žiadne zrýchlenie (CPU)", "No accessible": "Nič dostupné", "No accessible NFS servers found.": "Nenašli sa žiadne dostupné NFS servery.", "No accessible Samba servers found.": "Nenašli sa dostupné Samba servery.", @@ -2900,11 +3833,13 @@ "No active session": "Žiadna aktívna relácia", "No additional GPU can be added.": "Nie je možné pridať ďalšiu GPU.", "No additional device needs to be added.": "Netreba pridávať žiadne ďalšie zariadenie.", + "No applications match": "Žiadna zhoda aplikácií", "No archives": "Žiadne archívy", "No archives found in this Borg repository.": "V tomto Borg repozitári sa nenašli žiadne archívy.", "No available Controllers/NVMe devices were found.": "Nenašli sa žiadne dostupné Controller/NVMe zariadenia.", "No available disks found.": "Nenašli sa žiadne dostupné disky.", "No backup found, logrotate configuration not changed": "Nenašla sa žiadna záloha, nastavenie logrotate sa nemenilo", + "No backup is scheduled: the rsnapshot lines in /config/crontabs/root are commented out. Uncomment or adjust the intervals you want, then restart the container.": "Nie je naplánovaná žiadna záloha: linky rsnapshot v /config/crontabs/root sú komentované. Odpojte alebo nastavte intervaly, ktoré chcete, potom reštartujte kontajner.", "No backups": "Žiadne zálohy", "No backups found": "Nenašli sa žiadne zálohy", "No bridge configuration issues found": "V nastavení bridge sa nenašli problémy", @@ -2921,6 +3856,7 @@ "No compatible PVE jobs": "Žiadne kompatibilné PVE úlohy", "No compatible disk images found in:": "Nenašli sa kompatibilné diskové obrazy v:", "No configuration issues found": "V nastavení sa nenašli problémy", + "No container of the stack was modified.": "Žiadna nádoba zásobníka nebola upravená.", "No container runtime available.": "Nie je dostupný žiadny runtime pre kontajnery.", "No container selected. Exiting.": "Nebol vybraný žiadny kontajner. Ukončujem.", "No controller/NVMe selected.": "Nebol vybraný žiadny Controller/NVMe.", @@ -2951,11 +3887,13 @@ "No folders found in /mnt. Please create a new folder.": "V /mnt sa nenašli žiadne priečinky. Vytvorte nový priečinok.", "No folders found inside /mnt in the CT.": "V kontajneri sa v /mnt nenašli žiadne priečinky.", "No format-safe disks are available.": "Nie sú dostupné žiadne disky vhodné na bezpečné formátovanie.", + "No free ProxMenux private /24 network is available": "Nie je k dispozícii žiadna bezplatná sieť ProxMenux private /24", "No gasket DKMS registrations remain.": "Nezostávajú žiadne registrácie gasket DKMS.", "No group creation required — uses world-writable sticky bit permissions.": "Nie je potrebné vytvárať skupinu - používa sa zápis pre všetkých so sticky bitom.", "No host VFIO reconfiguration expected": "Neočakáva sa zmena VFIO nastavenia hosta", "No host VFIO/native binding changes were required.": "Nebolo potrebné meniť VFIO ani natívne priradenie na serveri.", "No host backups were found in this PBS repository:": "V tomto PBS repozitári sa nenašli žiadne zálohy hosta:", + "No host directory is used by this application.": "Táto aplikácia nepoužíva žiadny adresár hostiteľov.", "No host reboot expected": "Neočakáva sa reštart hosta", "No host write access — server-side ACL or root_squash. Continuing anyway.": "Host nemá právo zápisu - ACL na serveri alebo root_squash. Aj tak pokračujem.", "No host write access — server-side ACL. Continuing anyway.": "Server nemá právo zápisu. Pravdepodobne to blokuje ACL na druhej strane. Pokračujem.", @@ -2964,6 +3902,7 @@ "No iSCSI storage configured.": "Nie je nastavené žiadne iSCSI úložisko.", "No iSCSI storage found in Proxmox.": "V Proxmoxe sa nenašlo žiadne iSCSI úložisko.", "No iSCSI targets found on portal": "Na portáli sa nenašli žiadne iSCSI targety", + "No image was given": "Nebol predložený žiadny obrázok", "No import disks selected for now.": "Zatiaľ nie sú vybrané žiadne disky na import.", "No importable disks available. System disks and protected disks are hidden.": "Nie sú dostupné žiadne disky na import. Systémové a chránené disky sú skryté.", "No installation information available.": "Nie sú dostupné informácie o inštalácii.", @@ -2975,6 +3914,7 @@ "No mount point was specified.": "Nebol zadaný bod pripojenia.", "No mount points found in any container": "V žiadnom kontajneri sa nenašli mount pointy", "No mount points found in container": "V kontajneri sa nenašli mount pointy", + "No name was given": "Nebol uvedený žiadny názov", "No network configuration backups found.": "Nenašli sa žiadne zálohy sieťového nastavenia.", "No network interfaces configured (besides loopback)": "Nie sú nastavené žiadne sieťové rozhrania okrem loopback", "No new Controller/NVMe entries were added.": "Neboli pridané žiadne nové položky Controller/NVMe.", @@ -2999,9 +3939,11 @@ "No scheduled backup jobs configured.": "Nie sú nastavené žiadne naplánované úlohy záloh.", "No scheduled backup jobs found.": "Nenašli sa žiadne naplánované úlohy zálohy.", "No scripts found for:": "Nenašli sa žiadne skripty pre:", + "No security relaxation is required for the reviewed profile.": "Žiadny bezpečnostný relax je required pre preskúmaný profil.", "No self-test history found for": "Nenašla sa história samo-testov pre", "No self-test log available for": "Nie je dostupný log samo-testu pre", "No server IP or hostname provided.": "Nebola zadaná IP adresa ani názov servera.", + "No shared media content.": "Žiadny spoločný mediálny obsah.", "No shared mount detected. Applying standard local access.": "Nenašlo sa zdieľané pripojenie. Nastavujem bežný lokálny prístup.", "No shares configured.": "Nie sú nastavené žiadne zdieľania.", "No shares found in smb.conf.": "V smb.conf sa nenašli žiadne zdieľania.", @@ -3031,24 +3973,34 @@ "No valid mount points found": "Nenašli sa žiadne platné mount pointy", "No version in this branch is currently supported by keylase/nvidia-patch — the NVENC patch will not reapply after reinstall.": "Žiadna verzia v tejto vetve momentálne nie je podporovaná cez keylase/nvidia-patch - NVENC patch sa po preinštalovaní znovu nepoužije.", "No virtual machines were found on this host.": "Na tomto hostovi sa nenašli žiadne virtuálne stroje.", + "No working NVIDIA GPU was found": "Nebola nájdená žiadna funkčná NVIDIA GPU", "No write permissions on:": "Chýba oprávnenie na zápis do:", "No, keep local only": "Nie, ponechať iba lokálne", "No-subscription repository present": "No-subscription repozitár existuje", "No: the key stays only at": "Nie: kľúč zostane iba v", + "Node octal permissions (e.g. 0660)": "Oktálne povolenia uzla (napr. 0660)", "Non-Debian container detected": "Zistil sa kontajner, ktorý nie je Debian/Ubuntu", "Non-free firmware warnings disabled": "Upozornenia na non-free firmware vypnuté", "None": "Žiadne", "Normalizing stable monitor service...": "Upravujem službu Monitora pre stabilnú verziu...", "Not Mounted": "Nepripojené", + "Not a JSON object:": "Nie objekt JSON:", "Not all platforms support Controller/NVMe passthrough reliably.": "Nie všetky platformy podporujú priame priradenie Controller/NVMe spoľahlivo.", + "Not all shared directories were verified": "Nie všetky zdieľané adresáre boli overené", "Not an OVH server, skipping RTM installation": "Toto nie je OVH server, inštalácia RTM sa preskočí", "Not currently mounted": "Momentálne nepripojené", "Not currently mounted — skipping umount.": "Nie je pripojené, odpojenie preskakujem.", + "Not enough free space for the backup": "Nedostatok voľného priestoru pre zálohu", "Not found": "Nenájdené", + "Not found in the OCI archive:": "Nenájdené v archíve OCI:", "Not imported:": "Neimportované:", "Not mounted": "Nepripojené", "Not portable:": "Neprenáša sa:", "Not registered as Proxmox storage — use 'LXC Mount Manager' to bind-mount": "Nie je zaregistrované ako úložisko Proxmoxu - použite 'Správca LXC mountov' na bind mount", + "Not required (access code only)": "Nie je required (len prístupový kód)", + "Not required (password only)": "Nie je required (len heslo)", + "Not required (token only)": "Nie je required (iba token)", + "Not yet verified by ProxMenux (beta)": "Zatiaľ overené ProxMenux (beta)", "Note: A system reboot will be required after enabling IOMMU.": "Poznámka: po zapnutí IOMMU bude potrebný reštart systému.", "Note: this only works if the NFS server does NOT use 'all_squash' for root.": "Poznámka: funguje to iba vtedy, ak NFS server NEPOUŽÍVA 'all_squash' pre root.", "Notes": "Poznámky", @@ -3063,8 +4015,20 @@ "Nothing to schedule for reboot from selected paths.": "Z vybraných ciest nie je čo naplánovať na reštart.", "Nouveau module is loaded, attempting to unload...": "Modul Nouveau je načítaný, skúšam ho odpojiť...", "Number of CPU cores (default: 2)": "Počet CPU jadier (predvolené: 2)", + "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources.": "Nzbget je usenet downloader, napísaný v C++ a navrhnutý s výkonom na dosiahnutie maximálnej rýchlosti sťahovania pomocou veľmi málo systémových zdrojov.", + "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra.": "Nzbhydra2 je meta vyhľadávacia aplikácia pre NZB indexers, duchovný nástupca NZBmegasearcH, a vývoj pôvodnej aplikácie NZBHydra.", "OCI containers require Proxmox VE 9.1 or later.": "OCI kontajnery vyžadujú Proxmox VE 9.1 alebo novší.", + "OCI management": "Riadenie OCI", + "OCI management could not be completed. Check the backend status; no additional cleanup has been authorized.": "Riadenie OCI nebolo možné dokončiť. Skontrolujte stav backendu; žiadne dodatočné vyčistenie nebolo povolené.", + "OCI manager Apps (beta)": "Aplikácie pre správcu OCI (beta)", + "OCI manager Apps is a beta: if something does not work as expected, please report it on GitHub with the application name.": "OCI manažér Apps je beta: ak niečo nefunguje tak, ako sa očakávalo, nahláste to na GitHub s názvom aplikácie.", + "OCI metadata integrity mismatch": "Nepomer integrity metaúdajov OCI", + "OCI metadata too large": "Metaúdaje OCI príliš veľké", + "OCI stack management": "Riadenie stohu OCI", + "OCI verification failed:": "Overenie OCI zlyhalo:", + "OCR language (Tesseract code)": "Jazyk OCR (kód Tesseract)", "OK": "OK", + "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms.": "ONLYOFFICE poskytuje celý rad nástrojov na tvorbu, úpravu a spoluprácu na textových dokumentoch, tabuľkách, prezentáciách, PDF formulároch a pravidelných PDF súboroch na webových, stolových a mobilných platformách.", "OR add new PVE 9 no-subscription repository:": "ALEBO pridajte nový PVE 9 no-subscription repozitár:", "OS hint:": "Odhad OS:", "OS release details": "Podrobnosti o vydaní systému", @@ -3078,11 +4042,18 @@ "OVH RTM removed (Puppet artefacts may need manual cleanup)": "OVH RTM bol odstránený (Puppet súbory môže byť potrebné vyčistiť ručne)", "OVH server detected": "Zistený OVH server", "OVH server detection and RTM installation process completed": "Kontrola OVH servera a inštalácia RTM sú dokončené", + "Observer is not responding on port 4357": "Pozorovateľ nereaguje na prístav 4357", + "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption.": "Obsidian je note-prijímajúce aplikácie, ktoré vám umožní vytvoriť, odkaz, a usporiadať poznámky na vašom zariadení, so stovkami pluginov a tém prispôsobiť svoje pracovné postupy. Môžete tiež zverejniť svoje poznámky on-line, prístup je offline, a synchronizovať ich bezpečne s end-to-end šifrovanie.", "Offer as exit node?": "Ponúknuť ako exit node?", + "Official Emby Media Server image with optional VA-API or NVIDIA acceleration.": "Oficiálny obraz Emby Media Server s voliteľným zrýchlením VA-API alebo NVIDIA.", + "Official Jellyfin image with optional VA-API or NVIDIA acceleration.": "Oficiálny obraz Jellyfin s voliteľným zrýchlením VA-API alebo NVIDIA.", "Official Linux Distributions": "Oficiálne Linux distribúcie", + "Official Plex Media Server image with optional hardware transcoding.": "Oficiálny obraz Plex Media Server s voliteľným transkódovaním hardvéru.", + "Official image": "Oficiálny obrázok", "Old debian.sources file removed to prevent duplication": "Starý debian.sources súbor odstránený, aby nevznikla duplicita", "Old memory configuration detected. Replacing with balanced optimization...": "Našlo sa staršie nastavenie pamäte. Nahrádzam ho vyváženou optimalizáciou...", "Old time services removed successfully": "Staré časové služby boli úspešne odstránené", + "Ombi allows you to host your own Plex Request and user management system.": "Ombi vám umožní hostiť svoj vlastný Plex Žiadosť a systém správy užívateľov.", "On a privileged CT the mount options carry the only permissions.": "Pri privilegovanom CT určujú oprávnenia hlavne samotné možnosti pripojenia.", "On some systems, when starting the VM the host may slow down for several minutes until it stabilizes, or freeze completely.": "Na niektorých systémoch môže server pri štarte VM na niekoľko minút výrazne spomaliť, kým sa ustáli, alebo úplne zamrznúť.", "On the Borg server, append the following line to:": "Na Borg serveri pridajte nasledujúci riadok do:", @@ -3091,32 +4062,52 @@ "Once finished, re-run the script 'PVE 8 to 9 check' to verify that all issues.": "Po dokončení spustite skript 'PVE 8 to 9 check' znova, aby ste overili všetky problémy.", "Once installed, open the VirtIO ISO and run the installer to complete driver setup.": "Po nainštalovaní otvorte VirtIO ISO a spustite inštalátor na dokončenie ovládačov.", "One or more NVIDIA GPUs are currently configured for VM passthrough (vfio-pci):": "Jedna alebo viac NVIDIA GPU je aktuálne nastavených na VM passthrough (vfio-pci):", + "Online retro games emulator": "Online retro hry emulátor", + "Only a Docker Swarm uses these settings, so they are not applied:": "Tieto nastavenia používa len roj Docker, takže sa nepoužívajú:", "Only convert to privileged if absolutely necessary for your use case.": "Na privilegovaný kontajner prevádzajte iba vtedy, keď je to naozaj potrebné.", "Only fully free disks are shown (not system-used and not referenced by VM/LXC).": "Zobrazujú sa iba úplne voľné disky (nepoužíva ich systém a nie sú uvedené v nastavení VM/LXC).", "Only if using enterprise subscription": "Iba ak používate enterprise predplatné", "Only if using no-subscription repository": "Iba ak používate no-subscription repozitár", "Only needed if you mounted the filesystem in step 6b": "Potrebné iba vtedy, ak ste pripojili súborový systém v kroku 6b", + "Only one image at a time can be installed this way.": "Takto je možné nainštalovať iba jeden obrázok naraz.", "Only removes storage definition, not remote data.": "Odstráni iba definíciu úložiska, nie vzdialené dáta.", "Only run this if you used LVM (step 6b):": "Spustite iba vtedy, ak ste použili LVM (krok 6b):", "Only the host backup hook is removed — PVE vzdump jobs targeting this storage stay intact.": "Odstráni sa iba hook zálohy hosta - PVE vzdump úlohy smerujúce na toto úložisko zostanú zachované.", + "Only the image reference, with no Compose file": "Iba odkaz na obrázok bez súboru", "Open": "Otvorené", + "Open Source realtime backend in 1 file": "Open Source realtime backend v 1 súbore", "Open rwx + default inheritance for new files": "Otvorené rwx + predvolené dedenie pre nové súbory", + "Open source chat UI for AI models": "Open source chat UI pre modely AI", + "Open source home automation that puts local control and privacy first.": "Open source domácej automatizácie, ktorá dáva miestne ovládanie a súkromie na prvé miesto.", + "Open source, lightweight, native, supports (HTTP, BitTorrent, Magnet, etc.) for downloading.": "Otvorený zdroj, ľahký, natívne, podpora (HTTP, BitTorrent, Magnet, atď) pre stiahnutie.", "Open the VM console and wait for the installer to boot": "Otvorte konzolu VM a počkajte, kým sa spustí inštalátor", "Open the VM console and wait for the loader to boot": "Otvorte konzolu VM a počkajte, kým sa spustí loader", "Open the dashboard from this host on port 8008 to create a new admin account.": "Otvorte dashboard z tohto servera na porte 8008 a vytvorte nový admin účet.", "Open the dashboard to create a new admin account:": "Otvorte dashboard a vytvorte nový admin účet:", + "Open-source AI-powered coding assistant": "Open-source AI-poháňaný asistent kódovania", + "Open-source UI for building and debugging multi-agent and RAG applications": "Open-source UI pre stavebné a ladiace multi-agent a RAG aplikácie", + "OpenClaw is a personal AI assistant you run on your own devices": "OpenClaw je osobný asistent AI, ktorý beží na svoje vlastné zariadenia", + "OpenList": "OpenList", + "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world.": "OpenShot Video Editor je ocenený bezplatný a open-source video editor pre Linux, Mac a Windows a je venovaný poskytovaniu kvalitných riešení pre editáciu videa a animácie svetu.", + "OpenVINO requires a CPU quota to keep the CPU topology": "OpenVINO requires a CPU kvóta pre udržanie topológie procesora", + "OpenVINO requires the render device of an Intel GPU": "OpenVINO requires zariadenie Intel GPU", "OpenVSwitch installation could not be verified": "Inštaláciu OpenVSwitch sa nepodarilo overiť", "OpenVSwitch installed successfully": "OpenVSwitch bol úspešne nainštalovaný", "OpenVSwitch is ready to use": "OpenVSwitch je pripravený na použitie", "OpenVSwitch removed": "OpenVSwitch bol odstránený", + "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server.": "Openssh-server je pieskové prostredie, ktoré umožňuje prístup ssh bez toho, aby dal kľúče na celý server.", + "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser.": "Openvscode-server poskytuje verziu VS kódu, ktorý prevádzkuje server na vzdialenom počítači a umožňuje prístup prostredníctvom moderného webového prehliadača.", + "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features.": "Opera je multiplatformový webový prehliadač vyvinutý jeho namesake spoločnosťou Opera. Prehliadač je založený na Chromium, ale odlišuje sa od ostatných prehliadačov založených na Chromium (Chrome, Edge, atď.) prostredníctvom svojho používateľského rozhrania a ďalších funkcií.", "Operation": "Operácia", "Operation cancelled by user": "Operácia bola zrušená používateľom", "Operation cancelled by user to create backup.": "Operácia bola zrušená používateľom kvôli vytvoreniu zálohy.", "Operation cancelled by user.": "Operácia zrušená používateľom.", + "Operation cancelled.": "Operation zrušený.", "Operation cancelled. Cannot continue with an unprivileged container.": "Operácia bola zrušená. S neprivilegovaným kontajnerom sa nedá pokračovať.", "Operation log": "Záznam operácie", "Operator config re-applied via kernel-agnostic merge": "Vlastné nastavenie správcu bolo znovu použité cez zlúčenie nezávislé od kernelu", "Operator config that WILL be re-applied via kernel-agnostic merge": "Vlastné nastavenie správcu, ktoré SA znovu použije cez zlúčenie nezávislé od kernelu", + "Optical block device (e.g. /dev/sr0)": "Optické blokovacie zariadenie (napr. /dev/sr0)", "Optimizations detected and ready to revert.": "Optimalizácie boli nájdené a sú pripravené na vrátenie späť.", "Optimize": "Optimalizovať", "Optimize Memory": "Optimalizovať pamäť", @@ -3129,8 +4120,12 @@ "Optimizing network settings...": "Optimalizujem nastavenie siete...", "Optimizing vzdump backup speed...": "Optimalizujem rýchlosť záloh vzdump...", "Optional": "Voliteľné", + "Optional GID of the plex group": "Nepovinné GID skupiny plex", "Optional GPU Passthrough": "Voliteľné priame priradenie GPU", + "Optional published URL for Jellyfin": "Voliteľné URL pre Jellyfin", "Optional safety helper if you ever need to re-apply manually:": "Voliteľná bezpečnostná pomôcka, ak by ste to niekedy potrebovali použiť ručne znova:", + "Optional token from https://www.plex.tv/claim": "Voliteľný token z https://www.plex.tv/claim", + "Optional, not mounted by default": "Nepovinné, štandardne nemontované", "Optional: Modernize repository sources:": "Voliteľné: modernizovať zdroje repozitárov:", "Optional: apply default ACL so new files inherit permissions:": "Voliteľné: nastaviť predvolené ACL, aby nové súbory zdedili oprávnenia:", "Optional: register this path as Proxmox dir storage:": "Voliteľné: zaregistrovať túto cestu ako Proxmox dir úložisko:", @@ -3141,13 +4136,18 @@ "Or re-run this script and accept the 'apply host permissions' prompt.": "Alebo spustite tento skript znova a potvrďte výzvu na úpravu oprávnení hosta.", "Or use ProxMenux update function": "Alebo použite funkciu aktualizácie v ProxMenux", "Or, if your terminal can't select text, copy it from:": "Alebo ak váš terminál nevie označiť text, skopírujte ho z:", + "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community": "Orca Slicer je open source krájač pre FDM tlačiarne. OrcaSlicer je fork z Bambu Studio, to bolo predtým známe ako BambuStudio-SoftFever, Bambu Studio je forked z PrusaSlicer od Prusa Research, ktorý je z Slic3r od Alessandro Ranellucci a RepRap komunity", "Original ZFS ARC config restored from .bak": "Pôvodné nastavenie ZFS ARC bolo obnovené zo súboru .bak", "Original bashrc restored": "Pôvodný bashrc bol obnovený", "Original logrotate configuration restored": "Pôvodné nastavenie logrotate bolo obnovené", + "Orphan stack contract archived:": "@ info: whatsthis", + "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.": "Oscam je softvér Open Source Conditional Access Module používaný pre descrambling DVB transmissions pomocou inteligentných kariet. Je to server aj klient.", "Other Prebuilt Linux VMs": "Ďalšie pripravené Linux VM", "Output archive:": "Výstupný archív:", + "Overseerr is a request management and media discovery tool built to work with your existing Plex ecosystem.": "Overseerr je nástroj na riadenie žiadostí a vyhľadávanie médií postavený na prácu s existujúcim ekosystémom Plex.", "Owner:": "Vlastník:", "Ownership set to root:sharedfiles with 2775 on:": "Vlastník nastavený na root:sharedfiles s oprávnením 2775 na:", + "P2P bittorrent download": "P2P bittorrent stiahnuť", "PAM limits configured": "Limity PAM sú nastavené", "PBS API log rotation configured (hourly, size-based)": "Rotácia logov PBS API je nastavená (každú hodinu, podľa veľkosti)", "PBS backup error log": "Záznam chyby zálohy do PBS", @@ -3164,7 +4164,9 @@ "PCI reset method": "metóda PCI resetu", "PCIe GPU passthrough requires:": "PCIe GPU passthrough vyžaduje:", "PCIe/M.2 gasket-dkms": "PCIe/M.2 gasket-dkms", + "PCSX2 is an open source PS2 Emulator.": "PCSX2 je open source PS2 Emulátor.", "POSIX ACLs applied (access + default for inheritance).": "POSIX ACL boli použité (prístup aj predvolené dedenie).", + "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability.": "PPSSPP je voľný a open-source PSP emulátor pre Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series a Symbian so zameraním na rýchlosť a prenosnosť.", "PVE application manager updated": "Správca aplikácií PVE bol aktualizovaný", "PVE cache regenerated": "PVE cache bola znovu vytvorená", "PVE host (where the Borg LXC lives)": "PVE host (kde beží Borg LXC)", @@ -3179,17 +4181,28 @@ "Package update had issues, checking details...": "Pri aktualizácii balíkov nastali problémy, kontrolujem podrobnosti...", "Packages from backup to install:": "Balíky zo zálohy na inštaláciu:", "Packages installed: {count}.": "Nainštalované balíky: {count}.", + "Packages to be upgraded": "Balíky, ktoré sa majú aktualizovať", "Packages upgrade successfull": "Aktualizácia balíkov bola úspešná", "Packages upgraded": "Aktualizované balíky", "Packages:": "Balíky:", "Packaging OVA file...": "Balím OVA súbor...", "Packing installer archive...": "Balím archív inštalátora...", + "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices.": "PairDrop je skvelá alternatíva k AirDrop, ktorá pracuje na všetkých platformách. Poslať obrázky, dokumenty alebo text prostredníctvom peer-to-peer pripojenie k zariadeniam v rovnakej miestnej sieti/Wi-Fi alebo spárované zariadenia.", + "Paperless configuration cancelled": "Bezpapierová konfigurácia zrušená", + "Paperless-ngx WebUI": "Paperless-ngx WebUI", "Parsing OVF descriptor...": "Čítam OVF popisovač...", "Partial VM removed": "Čiastočná VM odstránená", "Partition": "Oddiel", "Partition created": "Oddiel bol vytvorený", "Partition created:": "Oddiel vytvorený:", "Partition table wiped": "Tabuľka oddielov bola vymazaná", + "Pass /dev/kvm to the LXC": "prejsť /dev/kvm na LXC", + "Pass /dev/net/tun to the LXC": "priepust /dev/net/tun na LXC", + "Pass /dev/ttyUSB0 to the LXC": "prejsť /dev/ttyUSB0 na LXC", + "Pass /dev/video10 to the LXC": "Prešiel /dev/video10 na LXC", + "Pass /dev/video11 to the LXC": "Prešiel /dev/video11 na LXC", + "Pass /dev/video12 to the LXC": "Prechod /dev/video12 na LXC", + "Pass a host device to the LXC": "Posuňte hostiteľské zariadenie na LXC", "Passphrase used to unlock the imported keyfile (leave blank if the keyfile is unencrypted / kdf=none):": "Fráza na odomknutie importovaného keyfile (nechajte prázdne, ak keyfile nie je šifrovaný / kdf=none):", "Passphrases do not match.": "Frázy sa nezhodujú.", "Passphrases do not match. Try again.": "Frázy sa nezhodujú. Skúste to znova.", @@ -3202,17 +4215,42 @@ "Password confirmation cannot be empty.": "Potvrdenie hesla nesmie byť prázdne.", "Password confirmation is required.": "Potvrdenie hesla je povinné.", "Password for": "Heslo pre", + "Password for aMule external connections (remote client)": "Heslo pre aMule externé pripojenia (diaľkový klient)", + "Password for the SSH login": "Heslo pre prihlásenie SSH", "Password for:": "Heslo pre:", "Password is correct": "Heslo je správne", + "Password of the AdGuard Home that receives the settings": "Heslo AdGuard Home, ktoré prijíma nastavenia", + "Password of the Adguardhome Sync web interface": "Heslo webového rozhrania Adguardhome Sync", + "Password of the Duplicati web interface": "Heslo webového rozhrania Duplicati", + "Password of the Etherpad admin user": "Heslo užívateľa Etherpad admin", + "Password of the FlexGet web interface": "Heslo webového rozhrania FlexGet", + "Password of the LibreDB Studio administrator": "Heslo správcu LibreDB Studio", + "Password of the MineOS web interface user": "Heslo používateľa webového rozhrania MineOS", + "Password of the NetBox admin account": "Heslo admin účtu NetBox", + "Password of the OpenList admin user": "Heslo užívateľa OpenList admin", + "Password of the PhotoPrism admin user (at least 8 characters)": "Heslo PhotoPrism admin užívateľa (aspoň 8 znakov)", + "Password of the PostgreSQL user": "Heslo používateľa PostgreSQL", + "Password of the SnapOtter admin user": "Heslo užívateľa SnapOtter admin", + "Password of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Heslo depreciovaného prihlasovacieho protokolu aplikácie Flowise (čítané iba verziami Flowise pred 3.0.1)", + "Password of the main AdGuard Home": "Heslo hlavného AdGuard Home", "Password or API token secret:": "Heslo alebo tajná časť API tokenu:", + "Password or secret": "Heslo alebo tajomstvo", "Password reset completed.": "Obnova hesla je dokončená.", + "Password to access the aMule web interface": "Heslo pre prístup k webovému rozhraniu aMule", "Passwords do not match. Please try again.": "Heslá sa nezhodujú. Skúste to znova.", + "Paste it here and press Ctrl+D on an empty line.": "Vložte ho sem a stlačte Ctrl+D na prázdne riadky.", + "Paste its Compose file in the terminal": "Vložiť súbor do terminálu", + "Paste its docker run command in the terminal": "Vložte jeho docker spustiť príkaz v termináli", "Paste the UUP Dump URL here": "Sem vložte UUP Dump URL", "Patching source for kernel compatibility...": "Upravujem zdrojový kód kvôli kompatibilite s kernelom...", "Path does not exist.": "Cesta neexistuje.", + "Path inside the container": "Cesta vnútri kontajnera", + "Path inside the container (e.g. /media-extra)": "Cesta vnútri kontajnera (napr. /media-extra)", + "Path inside the remote (empty = root)": "Cesta vnútri diaľkového (prázdne = koreň)", "Path must be absolute (start with /)": "Cesta musí byť absolútna (začínať znakom /)", "Path must be absolute (start with /).": "Cesta musí byť absolútna (začínať znakom /).", "Path not found": "Cesta sa nenašla", + "Path of the Compose file": "Cesta ku súboru", "Path:": "Cesta:", "Paths applied:": "Použité cesty:", "Paths included in backup": "Cesty zahrnuté v zálohe", @@ -3220,6 +4258,10 @@ "Paths skipped:": "Preskočené cesty:", "Paths to back up:": "Cesty na zálohovanie:", "Paths:": "Cesty:", + "Peers reach the server through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Peers dosiahnuť server prostredníctvom verejnej adresy a UDP port daný počas inštalácie, tak, aby port musí byť odoslaný do tohto kontajnera.", + "Peers to create: a number (3) or a list of names (phone,laptop)": "Peers vytvoriť: číslo (3) alebo zoznam mien (telefón,laptop)", + "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration.": "Pelorus je navigátor UI pre Linuxové plochy poháňané Selkiesom. Pelorus spustí FastAPI server, ktorý dáva LLM agenta (Ollama, OpenAI-kompatibilný, alebo Gemini) kontrolu nad myšou, klávesnice, screenshot, a správu okien cez Pixelflux počítač-použitie backend, Linux prístupnosť strom (AT-SPI), a voliteľné KWin D-Bus integrácie.", + "Pending components:": "Trvalé komponenty:", "Pending restore ID:": "ID čakajúcej obnovy:", "Pending restore dir:": "Priečinok čakajúcej obnovy:", "Pending restore prepared. A reboot is required to complete it.": "Čakajúca obnova je pripravená. Na jej dokončenie je potrebný reštart.", @@ -3243,7 +4285,15 @@ "Permission error": "Chyba oprávnení", "Permissions:": "Oprávnenia:", "Persist mount in CT /etc/fstab (optional):": "Uložiť pripojenie v CT /etc/fstab (voliteľné):", + "Persistence for": "Pretrvávanie", + "Persistence for the new path": "Pretrvávanie novej cesty", + "Persistent data:": "Trvalé údaje:", + "Persistent disk reused:": "Trvalý disk opätovne použitý:", "Persistent:": "Trvalé:", + "Personal finance management application": "Aplikácia na správu osobných financií", + "Photo and video library with optional GPU transcoding and machine learning": "Foto a video knižnica s voliteľným GPU transkódovanie a strojové učenie", + "PhotoPrism": "PhotoPrism", + "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB.": "Phpmyadmin je bezplatný softvérový nástroj napísaný v PHP, určený na zvládnutie správy MySQL cez web. phpMyAdmin podporuje širokú škálu operations na MySQL a MariaDB.", "Physical Function with": "Fyzická funkcia s", "Physical interface": "Fyzické rozhranie", "Physical interfaces available": "Dostupné fyzické rozhrania", @@ -3256,6 +4306,10 @@ "Pick a target to remove:": "Vyberte cieľ na odstránenie:", "Pick an SSH private key (auto-detected on this host):": "Vyberte súkromný SSH kľúč (automaticky nájdený na tomto hostovi):", "Pick an alternative way to authorize the new key:": "Vyberte iný spôsob autorizácie nového kľúča:", + "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time.": "Pidgin je program chatu, ktorý vám umožňuje prihlásiť sa do účtov na viacerých chatových sieťach súčasne. To znamená, že môžete chatovať s priateľmi na XMPP a zároveň sedieť v IRC kanáli.", + "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper.": "Piper je rýchly, miestny nervový text do rečového systému, ktorý znie skvele a je optimalizovaný pre Malina Pi 4. Tento kontajner poskytuje Wyoming protokol server pre Piper.", + "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures.": "Piwigo je softvér fotogalérie pre web, ktorý prichádza s výkonnými funkciami publikovať a spravovať vašu zbierku obrázkov.", + "Planka is an elegant open source project tracking tool.": "Planka je elegantný open source nástroj na sledovanie projektov.", "Please check network connectivity.": "Skontrolujte sieťové pripojenie.", "Please check permissions and try again.": "Skontrolujte oprávnenia a skúste to znova.", "Please check the installation.": "Skontrolujte inštaláciu.", @@ -3273,6 +4327,9 @@ "Please select GPU(s) that are currently in the same mode and try again.": "Vyberte GPU, ktoré sú teraz v rovnakom režime, a skúste to znova.", "Please select a valid option": "Vyberte platnú možnosť", "Please use an SSH session (Linux, macOS, Windows/PuTTY) or a physical console to perform the upgrade.": "Na aktualizáciu použite SSH reláciu (Linux, macOS, Windows/PuTTY) alebo fyzickú konzolu.", + "Plex WebUI": "Plex WebUI", + "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.": "Plex organizuje video, hudbu a fotografie z osobných mediálnych knižníc a vysiela ich do smart TV, streaming boxov a mobilných zariadení. Tento kontajner je balený ako samostatný Plex Media Server. Straightforward dizajn a hromadný akcie znamená dostať veci robiť rýchlejšie.", + "Podcast synchronization service": "Služba synchronizácie podcastov", "Pool does not appear to use SSD/NVMe devices with discard support. Skipping ZFS autotrim for pool:": "Pool pravdepodobne nepoužíva SSD/NVMe zariadenia s podporou discard. ZFS autotrim sa preskočí pre pool:", "Pool exists": "Pool už existuje", "Pool name matches but GUID differs (fresh ZFS install):": "Názov poolu sedí, ale GUID je iné (čerstvá ZFS inštalácia):", @@ -3283,12 +4340,21 @@ "Portal IP and port are correct": "IP adresa portálu a port sú správne", "Portal is reachable": "Portál je dostupný", "Portal:": "Portál:", + "Ports": "Porty", "Portuguese": "Portugalčina", "Post-Installation Options": "Možnosti po inštalácii", "Post-Installation Scripts": "Skripty po inštalácii", "Postfix configuration": "Nastavenie Postfixu", + "PostgreSQL": "PostgreSQL", + "PostgreSQL URL without an associated service:": "PostgreSQL URL bez súvisiacej služby:", + "PostgreSQL creates the database named in POSTGRES_DB on the first start. The installer default is postgresql.": "PostgreSQL vytvára databázu pomenovanú v POSTGRES DB na prvom začiatku. Štandardný inštalátor je postgresql.", + "PostgreSQL is an advanced, enterprise-class, and open-source relational database system. PostgreSQL supports both SQL (relational) and JSON (non-relational) querying.": "PostgreSQL je moderný, podnikový a open-source relačný databázový systém. PostgreSQL podporuje ako SQL (relatívne) tak JSON (nerelatívne) dotazovanie.", + "PostgreSQL requires a password": "PostgreSQL requires heslo", + "PostgreSQL volume size in GB": "PostgreSQL veľkosť objemu v GB", "Potential QEMU startup/assertion failures": "možné zlyhania štartu alebo assertion chyby QEMU", "Power state D3cold/D0 transitions may be inaccessible": "prechody napájacích stavov D3cold/D0 nemusia byť dostupné", + "Powerful OCR powered by DeepSeek AI": "Výkonný OCR poháňaný DeepSeek AI", + "Powerful networking tool": "Silný sieťový nástroj", "Pre-check found": "Predbežná kontrola našla", "Pre-configure destinations so you don't have to enter them every time you back up.": "Nastavte si ciele vopred, aby ste ich nemuseli zadávať pri každej zálohe.", "Pre-existing gasket-dkms package removed.": "Existujúci balík gasket-dkms bol odstránený.", @@ -3296,11 +4362,15 @@ "Pre-upgrade check FAILED: the simulation shows that 'proxmox-ve' would be REMOVED.\n This indicates a repository or dependency issue and upgrading now could break your Proxmox installation.": "Kontrola pred aktualizáciou ZLYHALA: simulácia ukazuje, že balík 'proxmox-ve' by bol ODSTRÁNENÝ.\n To naznačuje problém s repozitárom alebo závislosťami a aktualizácia by teraz mohla poškodiť inštaláciu Proxmoxu.", "Pre-upgrade simulation failed. See log:": "Simulácia pred inováciou zlyhala. Pozri denník:", "Pre-upgrade simulation passed: 'proxmox-ve' will be kept or upgraded safely.": "Simulácia pred aktualizáciou prešla: 'proxmox-ve' zostane zachované alebo sa bezpečne aktualizuje.", + "Prepared; the container was not modified yet": "Pripravené; obal ešte nebol upravený", "Preparing Log2RAM configuration": "Pripravujem nastavenie Log2RAM", "Preparing files for backup...": "Pripravujem súbory na zálohu...", "Preparing host mount...": "Pripravujem mount na hostovi...", "Preparing pending restore (network-safe)": "Pripravujem čakajúcu obnovu (bezpečnejšie pre sieť)", "Preparing staging area...": "Pripravujem pracovný priestor...", + "Preparing the NVIDIA GPU...": "Príprava NVIDIA GPU...", + "Preparing the recreation...": "Príprava rekreácie...", + "Preparing the update...": "Príprava aktualizácie...", "Preserving logs to /var/log.hdd before unmounting...": "Pred odpojením zachovávam logy do /var/log.hdd...", "Press 'q' to exit": "Stlačte 'q' na ukončenie", "Press Ctrl+C to stop the server and return to menu.": "Server zastavíte stlačením Ctrl+C a vrátite sa do menu.", @@ -3316,6 +4386,7 @@ "Press Enter to return": "Stlačte Enter pre návrat", "Press Enter to return to menu...": "Stlačte Enter pre návrat do menu...", "Press Enter to return to the main menu...": "Stlačte Enter pre návrat do hlavného menu...", + "Press Enter to return to the menu...": "Stlačte Enter pre návrat do menu...", "Press Enter to return...": "Stlačte Enter pre návrat...", "Press Enter when the line has been pasted on the server...": "Po vložení riadka na server stlačte Enter...", "Press OK to see the preview, then confirm": "Stlačte OK na zobrazenie náhľadu a potom akciu potvrďte", @@ -3325,9 +4396,19 @@ "Preview changes (diff)": "Náhľad zmien (diff)", "Preview: changes that would be applied": "Náhľad: zmeny, ktoré by sa použili", "Previous DKMS tree cleared.": "Predchádzajúci DKMS strom bol vyčistený.", + "Previous Rclone configuration restored": "Predchádzajúca konfigurácia Rclonu obnovená", "Previous installation cleaned": "Predchádzajúca inštalácia je vyčistená", "Previous installation removed": "Predchádzajúca inštalácia odstránená", + "Previous installation restored": "Predchádzajúca inštalácia obnovená", "Previous shutdowns": "Predchádzajúce vypnutia", + "Primary GID for Emby": "Primárne GID pre Emby", + "Privacy-first finance app with envelope budgeting and multi-device sync.": "Privacy-first finance app s obálkou budgeting a multi-device synchronizácia.", + "Private installation record saved": "Uložené súkromné záznamy o inštalácii", + "Private network assigned automatically:": "Privátne siete pridelené automaticky:", + "Private network of the application released:": "Súkromná sieť uvoľnenej žiadosti:", + "Private network of the application that is released:": "Súkromná sieť uvoľnenej aplikácie:", + "Private network:": "Súkromná sieť:", + "Private personal knowledge management": "Súkromné riadenie osobných znalostí", "Privileged": "Privilegovaný", "Privileged Container": "Privilegovaný kontajner", "Privileged Container Required": "Vyžaduje sa privilegovaný kontajner", @@ -3338,6 +4419,7 @@ "Privileged container — host root maps directly, no permission changes needed": "Privilegovaný kontajner - root hosta sa mapuje priamo, nie sú potrebné zmeny oprávnení", "Privileged containers can access host devices directly": "Privilegované kontajnery môžu priamo pristupovať k zariadeniam servera", "Privileged containers have full root access to the host system!": "Privilegované kontajnery majú plný root prístup k hostiteľskému systému!", + "Privileged installation declined": "Privilegovaná inštalácia odmietla", "Privileged: Full host access (less secure)": "Privilegovaný: plný prístup k serveru (menej bezpečné)", "Proceed": "Pokračovať", "Proceed with removal": "Pokračovať v odstránení", @@ -3346,11 +4428,15 @@ "Process may take several minutes depending on container size": "Proces môže trvať niekoľko minút podľa veľkosti kontajnera", "Process may take several minutes for large containers": "Pri veľkých kontajneroch môže proces trvať niekoľko minút", "Processes using NVIDIA:": "Procesy používajúce NVIDIA:", + "Productivity & Workflows": "Produktivita a pracovné toky", "Profile": "Profil", "Profile:": "Profil:", + "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files.": "Projectsend je aplikácia self-hosted, ktorá vám umožní nahrávať súbory a priradiť ich konkrétnym klientom, ktoré vytvoríte sami. Bezpečné, súkromné a jednoduché. Už nie je závislá od externých služieb alebo e-mailu, ktorý by tieto súbory posielal.", "Proposed Changes": "Navrhované zmeny", "Proposed ZFS ARC maximum:": "Navrhované maximum ZFS ARC:", "Provided by newer version — skipping": "Poskytuje novšia verzia - preskakujem", + "Prowlarr does not offer the application schema:": "Prowlarr neponúka schému aplikácie:", + "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all).": "Prowlarr je indexátor manažér/proxy postavený na populárnej arr .net / Reactjs base stack integrovať s rôznymi PVR aplikácie. Prowlarr podporuje ako Torrent Trackers a Usenet Indexers. To integruje bezproblémovo s Sonarr, Radarr, Lidarr, a Readarr ponúka kompletné riadenie vašich indexerov bez na app Indexer nastavenie required (robíme to všetko).", "ProxMenux Information": "Informácie o ProxMenux", "ProxMenux Monitor": "ProxMenux Monitor", "ProxMenux Monitor Service Verification": "Kontrola služby ProxMenux Monitor", @@ -3364,10 +4450,12 @@ "ProxMenux Monitor protection": "ochranou ProxMenux Monitoru", "ProxMenux Monitor unit repaired and restarted": "Jednotka ProxMenux Monitor bola opravená a reštartovaná", "ProxMenux Monitor → Backups tab (live progress card with estimated time, logs, rollback delta)": "ProxMenux Monitor → karta Backups (živý priebeh s odhadom času, záznamami a rozdielom rollbacku)", + "ProxMenux attaches directories, not single files, so this image cannot be installed yet.": "ProxMenux pripája adresáre, nie jednotlivé súbory, takže tento obrázok ešte nie je možné nainštalovať.", "ProxMenux can apply open permissions on this NFS directory from the host so the container can read and write:": "ProxMenux môže na hostovi nastaviť otvorené oprávnenia pre tento NFS priečinok, aby kontajner mohol čítať aj zapisovať:", "ProxMenux can remount it with open permissions so any LXC can read and write.": "ProxMenux ho môže znovu pripojiť s otvorenými oprávneniami, aby každý LXC mohol čítať aj zapisovať.", "ProxMenux cannot override NFS server-side permissions from the host.": "ProxMenux nevie z hosta prepísať oprávnenia nastavené na NFS serveri.", "ProxMenux customizations removed from bashrc": "Úpravy ProxMenux boli odstránené z bashrc", + "ProxMenux does not give a container the system of its host.": "ProxMenux nedáva kontajner systém svojho hostiteľa.", "ProxMenux does not validate the contents; any keyfile your PBS accepts is accepted here.": "ProxMenux nekontroluje obsah; prijme sa každý keyfile, ktorý prijme vaše PBS.", "ProxMenux files:": "Súbory ProxMenux:", "ProxMenux logo applied": "Logo ProxMenux bolo použité", @@ -3399,6 +4487,7 @@ "Proxmox repository configuration completed": "Nastavenie repozitárov Proxmoxu je dokončené", "Proxmox repository fixed (no-subscription, candidate is 9.x)": "Proxmox repozitár opravený (no-subscription, kandidát je 9.x)", "Proxmox status:": "Stav Proxmoxu:", + "Proxmox storage for the volume": "Uskladnenie Proxmox pre objem", "Proxmox storages:": "Úložiská Proxmoxu:", "Proxmox system repair completed successfully!": "Oprava systému Proxmox bola úspešne dokončená.", "Proxmox system repair completed with some issues.": "Oprava systému Proxmox bola dokončená, ale s niektorými problémami.", @@ -3408,16 +4497,28 @@ "Proxmox web interface: Datacenter > Storage > Add > SMB/CIFS": "Webové rozhranie Proxmoxu: Datacenter > Storage > Add > SMB/CIFS", "Proxmox web interface: Datacenter > Storage > Add > ZFS": "Webové rozhranie Proxmoxu: Datacenter > Storage > Add > ZFS", "Proxmox web interface: Datacenter > Storage > Add > iSCSI": "Webové rozhranie Proxmoxu: Datacenter > Storage > Add > iSCSI", + "Public UDP port clients connect to": "Verejné UDP port klienti pripojiť k", + "Public UDP port peers connect to": "Verejné UDP portové rovesníci pripojiť k", + "Public URL of phpMyAdmin when it is served behind a reverse proxy": "Verejné URL phpMyAdmin, keď sa podáva za reverzným proxy", + "Public address clients connect to (vpn.example.com or a public IP)": "Klienti verejnej adresy sa pripájajú k (vpn.example.com alebo verejné IP)", + "Public address peers connect to, or auto to detect it (vpn.example.com)": "Verejná adresa peers pripojiť, alebo auto na detekciu (vpn.example.com)", "Pulling latest changes from GitHub...": "Sťahujem najnovšie zmeny z GitHubu...", "Purge the gasket-dkms package": "Úplne odstrániť balík gasket-dkms", "Purging gasket-dkms package...": "Balík gasket-dkms sa úplne odstraňuje...", "Purging log2ram apt package...": "Úplne odstraňujem balík log2ram cez APT...", + "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.": "Pwndrop je samozamestnávateľná serverová hostingová služba pre odosielanie červeného spojovacieho užitočného zaťaženia alebo bezpečné zdieľanie vašich súkromných súborov cez HTTP a WebDAV.", + "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more.": "PyCharm ponúka mimo-of-the-box podporu pre Python, databázy, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI a ďalšie.", + "Pydio Cells needs an external MySQL or MariaDB database. The setup wizard asks for its address, database name and user on the first start.": "Pydio Cells potrebuje externú MySQL alebo MariaDB databázu. Sprievodca nastavením žiada o svoju adresu, meno databázy a užívateľa pri prvom štarte.", + "Pydio Cells redirects to the address given in EXTERNALURL. If the container changes address, edit lxc.environment.runtime: EXTERNALURL and SERVER_IP in /etc/pve/lxc/.conf with the container stopped, and delete /config/keys/cert.crt to regenerate the certificate.": "Pydio Cells presmeruje na adresu uvedenú v EXTERNURL. Ak kontajner zmení adresu, upravte lxc.environment.runtime: EXTERNURL a SERVER IP v /etc/pve/lxc/.conf s kontajnerom zastavil, a odstráňte /config/keys/cert.crt pre regeneráciu certifikátu.", + "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture.": "Pydio-bunky je platforma pre zdieľanie súborov pre organizácie. Je to úplný prepis projektu Pydio pomocou jazyka Go podľa architektúry mikroslužieb.", + "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat.": "QDirStat Štatistika adresára založená na Qt: KDirStat bez KDE -- od autora pôvodného KDirStat.", "Quick health check (PASSED / FAILED)": "Rýchla kontrola stavu (PASSED / FAILED)", "Quick health status — overall SMART result + key attributes": "Rýchly stav zdravia - celkový SMART výsledok + hlavné údaje", "RAID Detected": "Zistený RAID", "RAID member detected": "Zistený člen RAID", "RAM Size": "Veľkosť RAM", "RAM and swap usage": "Využitie RAM a swapu", + "RAM in MiB": "RAM v MiB", "REPAIR SUMMARY": "ZHRNUTIE OPRAVY", "REQUIREMENTS:": "POŽIADAVKY:", "ROM dump not available — configuring without romfile.": "ROM dump nie je dostupný - nastavujem bez romfile.", @@ -3425,9 +4526,26 @@ "RPC Bind Service: RUNNING": "Služba RPC Bind: BEŽÍ", "RPC Bind Service: STOPPED": "Služba RPC Bind: ZASTAVENÁ", "RPC Bind Service: STOPPED - starting...": "Služba RPC Bind: ZASTAVENÁ - spúšťam...", + "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD.": "RPCS3 je multi-platforma open-source Sony PlayStation 3 emulátor a debugger napísaný v C++ pre Windows, Linux, macOS a FreeBSD.", + "Radarr - A fork of Sonarr to work with movies à la Couchpotato.": "Radarr - A fork Sonarr pracovať s filmami à la Couchpotato.", + "Radarr added to Prowlarr": "Radarr pridaný do Prowlarr", + "Radarr connected to qBittorrent": "Radarr napojený na qBittorrent", + "Radarr root folder configured": "Konfigurovaný koreňový priečinok Radarr", + "RagFlow is an open-source RAG engine based on deep document understanding.": "RagFlow je open-source motor RAG založený na hlbokom porozumení dokumentov.", + "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase.": "Raneto - je open source Knowledgebase platforma, ktorá používa statické Markdown súbory pre napájanie znalostnej základne.", + "Raneto web interface": "Webové rozhranie Raneto", + "RawTherapee is a free, cross-platform raw image processing program!": "RawTherapee je zadarmo, cross-platform surový program spracovania obrazu!", + "Rclone WebUI": "Rclone WebUI", + "Rclone mount": "Prípojka Rclón", + "Rclone mount active": "Comment", + "Rclone mount needs a privileged LXC with FUSE access. The container is dedicated to Rclone and its web UI must not be exposed to untrusted networks.": "Rclone mount potrebuje privilegovaný LXC s FUSE prístupom. Kontajner je určený Rclone a jeho webové UI nesmie byť vystavený nedôveryhodným sieťam.", + "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network.": "Rclon mount requires privilegovaný LXC s FUSE prístupom. Použite tento profil len na dôveryhodnom uzle a sieti.", + "Rclone mount requires a privileged container": "Rclon mount requires privilegovaný kontajner", "Re-enter the BORG REPOKEY passphrase to confirm:": "Zadajte BORG REPOKEY frázu znova na potvrdenie:", "Re-running pre-check after repairs...": "Spúšťam predbežnú kontrolu znova po opravách...", "Reachable": "Dostupné", + "Read its Compose file from a file of this host": "Prečítajte si jeho súbor zo súboru tohto hostiteľa", + "Read the link with pct console CTID on the Proxmox host, or from the Console panel of the container in the Proxmox web interface, then open the https://playit.gg/claim/ address it shows in a browser and sign in to playit.gg. Ctrl+a q leaves pct console.": "Prečítajte si odkaz s pct konzolou CTID na Proxmox hostiteľa, alebo z panelu konzoly kontajnera vo webovom rozhraní Proxmox, potom otvorte https://playit.gg/claim/ adresu, ktorú zobrazí v prehliadači a prihláste sa na playit.gg. Ctrl+a q opustí pct konzolu.", "Read-Only": "Iba na čítanie", "Read-Only access": "Prístup iba na čítanie", "Read-Write (universal)": "Čítanie/zápis (univerzálne)", @@ -3436,6 +4554,7 @@ "Read-only access (or no write permissions).": "Prístup iba na čítanie (alebo chýba oprávnenie na zápis).", "Read-only mount": "Pripojiť iba na čítanie", "Read/Write (default)": "Čítanie/zápis (predvolené)", + "Read/write": "Čítať/písať", "Read/write CPU model-specific registers": "Čítať/zapisovať modelovo špecifické registre CPU", "Readable user table (UID, shell, etc.)": "Prehľadná tabuľka používateľov (UID, shell a pod.)", "Reading NVMe SMART data...": "Čítam NVMe SMART dáta...", @@ -3443,7 +4562,9 @@ "Reading SMART data...": "Čítam SMART dáta...", "Reading SMART self-test log...": "Čítam log SMART samo-testu...", "Reading full SMART report...": "Čítam úplnú SMART správu...", + "Real-time Performance Monitoring": "Monitorovanie výkonnosti v reálnom čase", "Real-time bandwidth usage (press q to exit)": "Využitie priepustnosti v reálnom čase (ukončíte klávesom q)", + "Real-time collaborative document editor": "Kolektívne editor dokumentov v reálnom čase", "Real-time network monitoring (press q to exit)": "Sieťový monitoring v reálnom čase (ukončíte klávesom q)", "Real-time network usage (iftop)": "Sieťová prevádzka v reálnom čase (iftop)", "Reason: Access denied": "Dôvod: Prístup zamietnutý", @@ -3465,6 +4586,7 @@ "Recent Samba server": "Posledný Samba server", "Recent logs:": "Posledné záznamy:", "Recent test results:": "Posledné výsledky testov:", + "Recognition profile not implemented": "Neimplementovaný profil uznávania", "Recommendation: reformat the disk to ext4 for a robust setup — see docs.": "Odporúčanie: pre spoľahlivejšie nastavenie preformátujte disk na ext4 - pozrite dokumentáciu.", "Recommendation: start with Complete restore.": "Odporúčanie: začnite úplnou obnovou.", "Recommendation: use 'Export to file' for these paths and apply manually during a maintenance window.": "Odporúčanie: pre tieto cesty použite 'Exportovať do súboru' a zmeny vykonajte ručne počas servisného okna.", @@ -3476,17 +4598,36 @@ "Recommended: use GPU -> LXC mode for these devices.": "Odporúčanie: pre tieto zariadenia použite režim GPU -> LXC.", "Recommended: use GPU with LXC workloads instead of VM passthrough on this hardware.": "Odporúčané: na tomto hardvéri používajte GPU radšej s LXC workloadmi namiesto VM passthrough.", "Reconciled": "Upravené", + "Recover OCI": "Obnoviť OCI", + "Recover OCI stack": "Obnoviť zásobník OCI", + "Recover now?": "Obnoviť teraz?", + "Recover or complete the operation?": "Obnoviť alebo dokončiť operation?", "Recover the keyfile using your recovery passphrase?": "Obnoviť keyfile pomocou obnovovacej frázy?", + "Recover the previous installation": "Obnoviť predchádzajúce zariadenie", "Recoverable:": "Obnoviteľné:", + "Recovering the previous installation": "Obnovenie predchádzajúceho zariadenia", "Recovery blob upload failed — main backup is OK, but keyfile recovery from PBS will not be available for this backup.": "Nahratie obnovovacieho balíčka zlyhalo - hlavná záloha je v poriadku, ale obnova keyfile z PBS pre túto zálohu nebude dostupná.", "Recovery blob:": "Obnovovací balíček:", + "Recovery completed. The container had not been modified yet.": "Vymáhanie ukončené. Obal ešte nebol upravený.", + "Recovery completed. The displaced disks and the backup are kept; nothing was deleted automatically.": "Vymáhanie ukončené. Posunuté disky a záloha sú uchovávané; nič nebolo automaticky vymazané.", "Recovery failed": "Obnova zlyhala", "Recovery passphrase": "Obnovovacia fráza", "Recovery setup failed": "Nastavenie obnovy zlyhalo", + "Recreate": "Obnoviť", + "Recreate OCI": "Obnoviť OCI", + "Recreate with these options?": "Obnoviť tieto možnosti?", + "Recreate: edit resources, network, paths and GPU": "Obnoviť: editovať zdroje, sieť, cesty a GPU", + "Recreating requires a confirmed proposal": "Obnovenie requires potvrdený návrh", + "Recreating the container...": "Obnovenie kontajnera...", + "Recreating the container:": "Obnovenie nádoby:", + "Recreation completed. Data kept.": "Rekreácia dokončená. Údaje uchovávané.", + "Recreation prepared": "Pripravené rekreácie", "Refresh APT index and verify repositories:": "Obnovte APT index a overte repozitáre:", "Refresh your browser (Ctrl+Shift+R) to see changes": "Obnovte prehliadač (Ctrl+Shift+R), aby ste videli zmeny", "Refresh your browser to see changes (server restart may be required)": "Obnovte stránku v prehliadači, aby ste videli zmeny (môže byť potrebný reštart servera)", "Refreshing apt cache...": "Obnovujem apt cache...", + "Refreshing the NVIDIA runtime...": "Obnovenie prevádzky NVIDIA...", + "Refusing an unexpected rootfs path:": "Odmietnutie nečakanej cesty ku koreňom:", "Regenerating PVE package cache...": "Znovu vytváram cache PVE balíkov...", "Regenerating boot artifacts for the merged kernel-agnostic changes...": "Znovu vytváram boot súbory pre zlúčené zmeny nezávislé od kernelu...", "Regenerating certificates and restarting services...": "Znovu generujem certifikáty a reštartujem služby...", @@ -3502,6 +4643,7 @@ "Reinstalled Proxmox packages successfully": "Balíky Proxmoxu boli úspešne preinštalované", "Reinstalling": "Preinštalovávam", "Reinstalling core Proxmox packages...": "Preinštalovávam základné balíky Proxmoxu...", + "Relative CPU priority (cpuunits)": "Relatívna priorita procesora (cpu jednotky)", "Release Channel": "Vetva vydania", "Release channel set to Beta.": "Vetva vydania je nastavená na Beta.", "Release channel set to Stable.": "Vetva vydania je nastavená na stabilnú verziu.", @@ -3511,8 +4653,12 @@ "Remapped Users:": "Remapovaní používatelia:", "Remapped users:": "Remapovaní používatelia:", "Reminder: You must install the QEMU Guest Agent inside the Windows VM": "Pripomienka: QEMU Guest Agent musíte nainštalovať aj priamo vo Windows VM", + "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported.": "Remmina je vzdialený desktopový klient napísaný v GTK, ktorého cieľom je byť užitočný pre správcov systémov a cestujúcich, ktorí musia pracovať s množstvom vzdialených počítačov pred veľkými alebo malými obrazovkami. Remmina podporuje viaceré sieťové protokoly v integrovanom a konzistentnom užívateľskom rozhraní. V súčasnosti sú podporované programy RDP, VNC, SPICE, SSH a EXEC.", + "Remote Access & VPN": "Vzdialený prístup a VPN", + "Remote dry run completed; no container was created.": "Diaľkový suchý beh dokončený; nebola vytvorená žiadna nádoba.", "Remote repository path:": "Vzdialená cesta repozitára:", "Remote server via SSH (recommended — off-host, dedup across machines)": "Vzdialený server cez SSH (odporúčané - mimo hosta, deduplikácia medzi strojmi)", + "Remote verified:": "Diaľkové overenie:", "Remounting CIFS share with open permissions...": "Znovu pripájam CIFS zdieľanie s otvorenými oprávneniami...", "Remove CIFS Mount": "Odstrániť CIFS mount", "Remove CIFS Mount (pvesm or fstab)": "Odstrániť CIFS mount (pvesm alebo fstab)", @@ -3540,6 +4686,7 @@ "Remove NFS fstab Mount": "Odstrániť NFS mount z fstab", "Remove NFS fstab mount:": "Odstrániť NFS mount z fstab:", "Remove NFS storage:": "Odstrániť NFS úložisko:", + "Remove OCI": "Odstrániť OCI", "Remove Proxmox CIFS storage:": "Odstrániť CIFS úložisko z Proxmoxu:", "Remove Proxmox NFS storage:": "Odstrániť NFS úložisko z Proxmoxu:", "Remove Proxmox iSCSI storage:": "Odstrániť iSCSI úložisko z Proxmoxu:", @@ -3551,6 +4698,7 @@ "Remove iSCSI storage definition:": "Odstrániť definíciu iSCSI úložiska:", "Remove invalid port": "Odstrániť neplatný port", "Remove invalid port(s)": "Odstrániť neplatné porty", + "Remove it? The data of its containers cannot be recovered afterwards.": "Odstrániť? Údaje o jeho nádobách sa potom nedajú získať.", "Remove keyfile from this host": "Odstrániť keyfile z tohto hosta", "Remove mount point:": "Odstrániť mount point:", "Remove obsolete systemd-boot meta-package": "Odstrániť zastaraný meta-balík systemd-boot", @@ -3559,6 +4707,7 @@ "Remove subscription banner": "Odstrániť hlásenie o predplatnom", "Remove the unprivileged flag from configuration:": "Odstrániť príznak neprivilegovaného kontajnera z nastavenia:", "Remove unused packages and their config": "Odstrániť nepoužívané balíky aj ich nastavenia", + "Remove: delete the application and its containers": "Odstrániť: odstrániť aplikáciu a jej obaly", "Removed": "Odstránené", "Removed KVM MSR options from configuration": "Možnosti KVM MSR boli odstránené z nastavenia", "Removed Mount:": "Odstránený mount:", @@ -3609,6 +4758,9 @@ "Removing stale VFIO entries from vfio.conf...": "Odstraňovanie zastaraných záznamov VFIO z vfio.conf...", "Removing storage from Proxmox...": "Odstraňujem úložisko z Proxmoxu...", "Removing system limits optimizations...": "Odstraňujem optimalizácie systémových limitov...", + "Removing the containers...": "Odstránenie kontajnerov...", + "Removing the incomplete stack...": "Odstránenie neúplného zásobníka...", + "Removing the previous container": "Odstránenie predchádzajúceho kontajnera", "Removing utilities installed by ProxMenux...": "Odstraňujú sa pomôcky nainštalované používateľom ProxMenux...", "Removing zfs-auto-snapshot...": "Odstraňujem zfs-auto-snapshot...", "Renamed": "Premenované", @@ -3616,6 +4768,7 @@ "Repair Complete": "Oprava je dokončená", "Repair Options:": "Možnosti opravy:", "Repairs and optimizes repositories": "Opraví a optimalizuje repozitáre", + "Repeat to confirm": "Opakujte na potvrdenie", "Replace": "Nahradiť", "Replace with the actual ID.": "Nahraďte skutočným ID kontajnera.", "Replace with your actual container ID": "Nahraďte skutočným ID kontajnera", @@ -3628,12 +4781,16 @@ "Repositories switched to no-subscription": "Repozitáre prepnuté na no-subscription", "Repository ready.": "Repozitár je pripravený.", "Repository:": "Repozitár:", + "Request a staging certificate for testing: true or false": "Vyžiada si osvedčenie o intenzite na testovanie: pravdivé alebo nepravdivé", "Require reboot": "Vyžaduje reštart", "Required command not found:": "Požadovaný príkaz sa nenašiel:", "Required if using a VirtIO or SCSI disk.": "Vyžaduje sa pri použití VirtIO alebo SCSI disku.", "Required install helpers not available.": "Potrební pomocníci na inštaláciu nie sú dostupní.", + "Required new path cancelled": "Required nová cesta zrušená", + "Required persistent paths cannot be removed": "Required perzistentné cesty nemožno odstrániť", "Requires acl package. Skip if setfacl is not available.": "Vyžaduje balík acl. Preskočte, ak setfacl nie je dostupný.", "Requires authentication": "Vyžaduje prihlásenie", + "Reserving a private network...": "Zachovanie súkromnej siete...", "Reset Capability Blocked": "Reset zariadenia nie je použiteľný", "Reset Capability Warning": "Upozornenie na reset schopnosť", "Reset Monitor Password": "Obnoviť heslo Monitora", @@ -3641,7 +4798,9 @@ "Reset current storage selection": "Vynulovať aktuálny výber úložiska", "Resetting time synchronization...": "Resetujem synchronizáciu času...", "Residual Bookworm entries commented where applicable": "Zostávajúce položky Bookworm boli zakomentované, kde to bolo potrebné", + "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes.": "Resilio-sync (predtým BitTorrent Sync) používa protokol BitTorrent na synchronizáciu súborov a priečinkov medzi všetkými zariadeniami. Existujú ako zadarmo a platená verzia, tento kontajner podporuje oboje. Existuje oficiálna synchronizácia obrazu, ale my sme vytvorili tento, pretože podporuje mapovanie užívateľa na zjednodušenie oprávnení pre objemy.", "Resolve package conflicts": "Vyriešiť konflikty balíkov", + "Resources": "Zdroje", "Restart Network": "Reštartovať sieť", "Restart Network Service": "Reštartovať sieťovú službu", "Restart Web UI proxy": "Reštartovať proxy webového rozhrania", @@ -3673,8 +4832,11 @@ "Restore plan summary": "Zhrnutie plánu obnovy", "Restore source location": "Umiestnenie zdroja obnovy", "Restored config is on disk; reboot the host to apply.": "Obnovené nastavenie je uložené na disku; aby sa použilo, reštartujte server.", + "Restored installation checked": "Obnovená inštalácia skontrolovaná", "Restored original /bin/gzip": "Pôvodný /bin/gzip bol obnovený", "Restored original /etc/vzdump.conf from .bak": "Pôvodný /etc/vzdump.conf bol obnovený zo súboru .bak", + "Restored:": "Obnovené:", + "Restoring": "Obnovenie", "Restoring APT language downloads...": "Obnovujem sťahovanie jazykov cez APT...", "Restoring container memory to": "Obnovujem pamäť kontajnera na", "Restoring default journald configuration...": "Obnovujem predvolené nastavenie journald...", @@ -3682,15 +4844,23 @@ "Restoring original bashrc...": "Obnovujem pôvodný bashrc...", "Restoring original logrotate configuration...": "Obnovujem pôvodné nastavenie logrotate...", "Restoring subscription banner...": "Obnovujem hlásenie o predplatnom...", + "Restoring the backup": "Obnovenie zálohy", "Restoring the original rpcbind service state...": "Obnovenie pôvodného stavu služby rpcbind...", + "Restoring the previous Rclone configuration...": "Obnovenie predchádzajúcej konfigurácie Rclone...", + "Restoring the previous backup...": "Obnovenie predchádzajúcej zálohy...", + "Restoring the previous state of the stack...": "Obnovenie predchádzajúceho stavu stohu...", + "Restoring the stack records...": "Obnovenie záznamov...", "Results will be saved automatically to:": "Výsledky sa automaticky uložia do:", "Results will be saved to:": "Výsledky sa uložia do:", "Retention": "Uchovávanie", + "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface.": "RetroArch je frontend pre emulátory, herné motory a prehrávače médií. Umožňuje spustiť klasické hry na širokej škále počítačov a konzol prostredníctvom svojho klik grafického rozhrania.", "Return": "Späť", "Return to Main Menu": "Späť do hlavného menu", "Return to Share Menu": "Späť do menu zdieľania", "Return to main menu": "Späť do hlavného menu", + "Returning the containers to their previous state...": "Vraciam kontajnery do ich predchádzajúceho stavu...", "Reused the encryption key from the PVE storage entry.": "Použil sa šifrovací kľúč z položky PVE úložiska.", + "Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container.": "Reverzné proxy vzorky pre iné aplikácie sú v /config/nginx/proxy confs vnútri kontajnera.", "Reverting AMD (Ryzen/EPYC) fixes...": "Vraciam späť opravy pre AMD (Ryzen/EPYC)...", "Reverting IOMMU/VFIO configuration...": "Vraciam späť nastavenie IOMMU/VFIO...", "Reverting TCP BBR + Fast Open...": "Vraciam späť TCP BBR + Fast Open...", @@ -3699,22 +4869,31 @@ "Reverting vzdump speed tuning...": "Vraciam späť ladenie rýchlosti vzdump...", "Review passthrough config files": "Skontrolovať konfiguračné súbory passthrough", "Review what will be removed": "Skontrolujte, čo sa odstráni", + "Rip DVD and Blu-ray media from a browser": "Rip DVD a Blu-ray médiá z prehliadača", "Rollback: nothing to remove (host matches backup)": "Rollback: nie je čo odstrániť (host zodpovedá zálohe)", + "Rolling back the incomplete container": "Zatáčanie nedokončenej nádoby", + "RomM is a self-hosted ROM manager for managing and playing game collections.": "RomM je self-hosted ROM manažér pre správu a hranie zbierky hier.", "Root SSH keys/config": "SSH kľúče/nastavenie roota", "Root inside container = root on host system": "Root v kontajneri = root na hostiteľskom systéme", + "Root privileges are required": "Koreňové práva sú required", + "Root privileges on the Proxmox node are required": "Koreňové práva na Proxmox uzla sú required", "Root shell/profile config": "Nastavenie shellu/profilu roota", "Root user on the PVE host (default 'root'):": "Root používateľ na PVE hostovi (predvolené 'root'):", + "Rootfs size in GB": "Rootfs veľkosť v GB", "Rotate the recovery passphrase": "Zmeniť obnovovaciu frázu", "Routing Information": "Informácie o smerovaní", "Routing Table": "Smerovacia tabuľka", + "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required.": "Rsnapshot je nástroj pre snímky súborového systému založený na rync. rsnapshot uľahčuje vytváranie pravidelných snímok lokálnych strojov a diaľkových strojov nad ssh. Kód robí rozsiahle použitie tvrdých odkazov vždy, keď je to možné, výrazne znížiť miesto na disku required.", "Run 'Mount NFS Share' to install NFS client automatically.": "Spustite 'Pripojiť NFS zdieľanie', aby sa NFS klient nainštaloval automaticky.", "Run 'Mount Samba Share' to install CIFS client automatically.": "Spustite 'Pripojiť Samba zdieľanie', aby sa CIFS klient nainštaloval automaticky.", + "Run GGUF LLMs locally with GPU acceleration": "Spustiť GGUF LLM lokálne s GPU zrýchlenia", "Run PVE 8 to 9": "Spustiť PVE 8 na 9", "Run PVE 8 to 9 check": "Spustiť kontrolu PVE 8 na 9", "Run \\\"Install NVIDIA Drivers on Host\\\" first so the installer is cached.": "Najprv spustite \\\"Nainštalovať NVIDIA ovládače na hostovi\\\", aby sa inštalátor uložil do cache.", "Run a full security audit": "Spustiť úplnú bezpečnostnú kontrolu", "Run a job now": "Spustiť úlohu teraz", "Run apt-get install -f to complete any pending package configurations": "Spustite apt-get install -f na dokončenie všetkých čakajúcich konfigurácií balíkov", + "Run as root on the Proxmox node; the registry contains private data": "Spustiť ako koreň na uzle Proxmox; register obsahuje súkromné údaje", "Run as server or client? [s/c]:": "Spustiť ako server alebo klient? [s/c]:", "Run checklist again to verify upgrade:": "Spustite kontrolný zoznam znova na overenie aktualizácie:", "Run from console, or SSH inside tmux/screen": "Spustiť z konzoly alebo cez SSH vo vnútri tmux/screen", @@ -3739,6 +4918,7 @@ "Running dkms autoinstall for kernel": "Spúšťam dkms autoinstall pre kernel", "Running kernel:": "Spustené jadro:", "Running pre-upgrade simulation to verify 'proxmox-ve' will remain installed...": "Spúšťam simuláciu pred aktualizáciou, aby sa overilo, že 'proxmox-ve' zostane nainštalované...", + "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration.": "RustDesk je plne funkčné open source diaľkové ovládanie alternatívu pre self-hosting a bezpečnosť s minimálnou konfiguráciou.", "SATA (standard - high compatibility)": "SATA (štandard - vysoká kompatibilita)", "SCSI (recommended for Linux and Windows)": "SCSI (odporúčané pre Linux a Windows)", "SCSI (recommended for Linux)": "SCSI (odporúčané pre Linux)", @@ -3755,6 +4935,7 @@ "SMB ports:": "SMB porty:", "SR-IOV Configuration Detected": "Zistené nastavenie SR-IOV", "SSD Emulation": "Emulácia SSD", + "SSH access": "Prístup SSH", "SSH access (host + root)": "SSH prístup (host + root)", "SSH auth logger service created and started": "Služba na logovanie SSH prihlásení bola vytvorená a spustená", "SSH hardening: MaxAuthTries set to 3 (Lynis recommendation)": "Spevnenie SSH: MaxAuthTries nastavené na 3 (odporúčanie Lynis)", @@ -3769,6 +4950,8 @@ "STEP 9: Cleanup (LVM only)": "KROK 9: čistenie (iba LVM)", "STORAGE TYPE IDENTIFICATION:": "ROZPOZNANIE TYPU ÚLOŽISKA:", "SUGGESTION FOR": "NÁVRH PRE", + "SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.": "SWAG slúži HTTPS na porte 443. Plain HTTP na porte 80 je vypnutý v /config/nginx/site-confs/default.conf.", + "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction.": "Sabnzbd robí Usenet tak jednoduché a efektívne, ako je to možné automatizáciou všetko, čo môžeme. Všetko, čo musíte urobiť, je pridať .nzb. SABnzbd preberá odtiaľ, kde bude automaticky stiahnutá, overená, opravená, extrahovaná a podaná preč s nulovou ľudskou interakciou.", "Safe design: no automatic ACL/ownership mutation on host or CT.": "Bezpečný návrh: bez automatickej zmeny ACL alebo vlastníctva na hostovi či v CT.", "Safe to apply now": "Bezpečné použiť teraz", "Safety Backup": "Bezpečnostná záloha", @@ -3822,8 +5005,13 @@ "Same major series:": "Rovnaká hlavná séria:", "Same major.minor:": "Rovnaké major.minor:", "Sanitizing NVIDIA host services for VFIO mode...": "Upravujem NVIDIA služby hosta pre VFIO režim...", + "Save and classify articles. Read them later. Freely.": "Uložiť a klasifikovať články. Prečítajte si ich neskôr. Slobodne.", "Save the passphrase somewhere safe NOW, before continuing.": "Uložte si frázu TERAZ na bezpečné miesto, ešte pred pokračovaním.", "Save this Borg target so you don't need to enter the details again?": "Uložiť tento Borg cieľ, aby ste údaje nemuseli zadávať znova?", + "Saved record removed": "Uložený záznam odstránený", + "Saving the new configuration": "Ukladanie novej konfigurácie", + "Saving the new configuration...": "Ukladanie novej konfigurácie...", + "Saving the stack records...": "Ukladám zásobníky...", "Scan storage for new content": "Vyhľadať nový obsah v úložisku", "Scanning available physical disks...": "Hľadám dostupné fyzické disky...", "Scanning network for NFS servers...": "Prehľadávam sieť a hľadám NFS servery...", @@ -3835,11 +5023,19 @@ "Scheduled backups and retention policies": "Naplánované zálohy a pravidlá uchovávania", "Scheduled tasks (cron)": "Naplánované úlohy (cron)", "Scheduler script not found:": "Skript plánovača sa nenašiel:", + "ScreenScraper": "ScreenScraper", + "ScreenScraper password": "Heslo ScreenScrapera", + "ScreenScraper username": "Užívateľské meno screenScrapera", "Script Information": "Informácie o skripte", "Script not found:": "Skript sa nenašiel:", "Scripts in": "Skripty v kategórii", + "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator.": "ScummVM je program, ktorý vám umožní spustiť určité klasické grafické dobrodružstvo a hranie rolí za predpokladu, že už máte ich dátové súbory. Inteligentná časť o tom: ScummVM práve nahrádza spustiteľné materiály dodávané s hrami, čo vám umožní hrať je na systémoch, pre ktoré neboli nikdy navrhnuté! ScummVM je kompletný prepis týchto hier 'spustiteľné a nie je emulátor.", + "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions—such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server.": "Sealskin je self-hosted, klient-server platforma, ktorá umožňuje užívateľom spustiť výkonné, kontajnerové desktopové aplikácie streamované priamo do webového prehliadača. Používa rozšírenie prehliadača na zachytenie užívateľských akcií, ako je kliknutie na odkaz alebo stiahnutie súboru a presmeruje ich na bezpečné, izolované aplikačné prostredie bežiace na vzdialenom serveri.", "Search Results for:": "Výsledky hľadania pre:", + "Search applications": "Hľadať aplikácie", + "Search results for:": "Výsledky vyhľadávania pre:", "Search/Filter Scripts": "Hľadať/filtrovať skripty", + "Searchable document archive with OCR": "Vyhľadávateľný archív dokumentov s OCR", "Secure Disk Formatter": "Bezpečné formátovanie disku", "Secure Gateway (Tailscale VPN)": "Secure Gateway (Tailscale VPN)", "Secure Gateway deployed successfully!": "Secure Gateway úspešne nasadené!", @@ -3847,8 +5043,12 @@ "Security": "Bezpečnosť", "Security Updates": "Bezpečnostné aktualizácie", "Security Warning — read before applying": "Bezpečnostné upozornenie - prečítajte pred použitím", + "Security directive outside the dynamic profile": "Bezpečnostná smernica mimo dynamického profilu", + "Security relaxation declined": "Uvoľnenie zabezpečenia sa znížilo", "See": "Pozrite", "See /tmp/proxmenux-mount.log for details.": "Podrobnosti nájdete v /tmp/proxmenux-mount.log.", + "Seerr WebUI": "Seerr WebUI", + "Seerr/Bazarr connections, the SABnzbd client and the Lidarr profiles, root folder and client are configured manually in this version.": "Pripojenie Seerr/Bazarr, klient SABnzbd a profily Lidarr, koreňový priečinok a klient sú v tejto verzii nastavené ručne.", "Select": "Vybrať", "Select Borg target": "Vyberte Borg cieľ", "Select CPU model": "Vyberte model CPU", @@ -3888,6 +5088,7 @@ "Select a Custom Logo": "Vyberte vlastné logo", "Select a VirtIO ISO to use:": "Vyberte VirtIO ISO, ktoré sa má použiť:", "Select a category of useful commands:": "Vyberte kategóriu užitočných príkazov:", + "Select a category or search for applications:": "Vyberte kategóriu alebo hľadanie aplikácií:", "Select a category or search for scripts:": "Vyberte kategóriu alebo vyhľadajte skripty:", "Select a custom ISO to use:": "Vyberte vlastné ISO, ktoré sa má použiť:", "Select a job:": "Vyberte úlohu:", @@ -3897,6 +5098,7 @@ "Select a pre-configured Linux VM script to execute:": "Vyberte pripravený skript pre Linux VM, ktorý sa má spustiť:", "Select a script or action:": "Vyberte skript alebo akciu:", "Select a share to delete:": "Vyberte zdieľanie na vymazanie:", + "Select a specific Coral or USB node, not the whole /dev": "Vyberte špecifický Coral alebo USB uzol, nie celý /dev", "Select access mode": "Vyberte režim prístupu", "Select an existing group": "Vybrať existujúcu skupinu", "Select an existing group:": "Vyberte existujúcu skupinu:", @@ -3907,6 +5109,7 @@ "Select archive": "Vyberte archív", "Select archive to restore": "Vyberte archív na obnovu", "Select at least one path to continue.": "Pre pokračovanie vyberte aspoň jednu cestu.", + "Select at least one suite application": "Vyberte aspoň jednu aplikáciu suite", "Select authentication mode:": "Vyberte spôsob prihlásenia:", "Select authentication type:": "Vyberte typ prihlásenia:", "Select available Controllers/NVMe to add:": "Vyberte dostupné Controllery/NVMe na pridanie:", @@ -4011,6 +5214,19 @@ "Selected optimizations have been uninstalled.": "Vybrané optimalizácie boli odinštalované.", "Selected paths produced no entries to apply.": "Vybrané cesty nevytvorili žiadne položky na použitie.", "Selected utilities installation completed": "Inštalácia vybraných nástrojov je dokončená", + "Selection": "Výber", + "Self-custodial Bitcoin Lightning wallet with integrated node and app connections.": "Samoobsluha Bitcoin Lightning peňaženka s integrovaným uzlom a pripojenie aplikácií.", + "Self-hosted ZeroTier network controller with web UI for centralized management.": "Samo-hostiteľom ZeroTier sieťový regulátor s web UI pre centralizované riadenie.", + "Self-hosted cloud data migration & sync manager": "Self-hosted cloud dát Migrácia a synchronizácia manažéra", + "Self-hosted collaborative bookmark manager to collect, read, annotate, and fully preserve what matters, all in one place.": "Self-hosted kolaboratívne záložky manažér zbierať, čítať, anotovať, a plne zachovať to, na čom záleží, všetko na jednom mieste.", + "Self-hosted file sharing with a modern web interface": "Samoobsluha zdieľania súborov s moderným webovým rozhraním", + "Self-hosted file toolkit for images, video, audio, PDFs, and files": "Súborový súbor s vlastným hostovaním pre obrázky, video, audio, PDF a súbory", + "Self-hosted internet archiving solution": "Samoobslužné riešenie archivácie internetu", + "Self-hosted recipe manager and meal planner": "Self-hosted recept manažér a jedlo plánovač", + "Self-hosted software development service": "Služba na vývoj softvéru s vlastným hostovaním", + "Self-signed TLS certificate created:": "Vytvorený samopodpísaný certifikát TLS:", + "Selfhosted PDF manager, viewer and editor": "Selfhosted PDF manažér, prehliadač a editor", + "Selkies desktop and streaming acceleration": "Selkies plocha a streamovanie zrýchlenie", "Sending backup to Borg repository...": "Odosielam zálohu do Borg repozitára...", "Sending backup to PBS...": "Odosielam zálohu do PBS...", "Server": "Server", @@ -4025,14 +5241,19 @@ "Server will listen on TCP port 5201.": "Server bude počúvať na TCP porte 5201.", "Server:": "Server:", "Servers": "Servery", + "Service": "Služba", "Service Status": "Stav služby", "Service is active and running": "Služba je aktívna a beží", "Service is inactive": "Služba nie je aktívna", + "Service ready:": "Pripravená služba:", + "Service responding:": "Služba odpovedá:", "Service restarted.": "Služba bola reštartovaná.", "Service restarts:": "Reštarty služieb:", "Service stopped.": "Služba je zastavená.", + "Service:": "Služba:", "Services failed": "Služby zlyhali", "Services restarted": "Služby reštartované", + "Services that depend on the main service are not yet supported": "Služby, ktoré závisia od hlavnej služby, zatiaľ nie sú podporované", "Services:": "Služby:", "Set Display > Graphic card (VGA, SPICE or VirtIO) to match the guest": "Nastavte Display > Graphic card (VGA, SPICE alebo VirtIO) podľa hosťa", "Set Hostname": "Zadať názov VM", @@ -4077,13 +5298,26 @@ "Share:": "Zdieľanie:", "Shared Directory Ready:": "Zdieľaný priečinok je pripravený:", "Shared Group": "Zdieľaná skupina", + "Shared directory created:": "Vytvorený zdieľaný adresár:", + "Shared directory for consume and export": "Zdieľaný adresár pre spotrebu a export", + "Shared directory for copy/sync operations": "Zdieľaný adresár pre kopírovanie/sync operations", "Shared group: CONFIGURED": "Zdieľaná skupina: NASTAVENÁ", "Shared group: sharedfiles (GID:": "Zdieľaná skupina: sharedfiles (GID:", + "Shared host content (not included in LXC backups):": "Zdieľaný obsah hostiteľa (nezahrnutý do záloh LXC):", + "Shared host data is not reverted by the backup. Continue?": "Zdieľané dáta hostiteľa nie sú vrátené zálohou. Pokračovať?", + "Shared host data is not reverted by the backups. Continue?": "Zdieľané dáta hostiteľa nie sú vrátené zálohami. Pokračovať?", + "Shared host directories (not included in Proxmox backups)": "Zdieľané adresáre hostiteľov (nezahrnuté do záloh Proxmox)", + "Shared host directory": "Zdieľaný adresár hostiteľov", + "Shared host directory (not included in Proxmox backups)": "Zdieľaný adresár host (nie je súčasťou záloh Proxmox)", + "Shared host files are kept as they are; the backup does not restore their content.": "Zdieľané hostiteľské súbory sú uchovávané ako sú; záloha neobnovuje ich obsah.", + "Shared host media directory": "Zdieľaný adresár médií pre hostiteľov", + "Shared memory size for the GPU workload in MB": "Zdieľaná veľkosť pamäte pre pracovné zaťaženie GPU v MB", "Sharedfiles group already exists (GID: 101000)": "Skupina sharedfiles už existuje (GID: 101000)", "Shares found:": "Nájdené zdieľania:", "Shell user ulimit set": "ulimit pre používateľa shellu je nastavený", "Short self-test started on": "Krátky samo-test bol spustený na", "Short test — ~2 minutes, basic surface check": "Krátky test - približne 2 minúty, základná kontrola povrchu", + "Shotcut is a free, open source, cross-platform video editor.": "Shotcut je bezplatný, otvorený zdroj, multiplatformový video editor.", "Should show 'unprivileged: 0' or no unprivileged line": "Malo by sa zobraziť 'unprivileged: 0' alebo žiadny riadok unprivileged", "Should show 'unprivileged: 1'": "Malo by sa zobraziť 'unprivileged: 1'", "Should show 'unprivileged: 1' if it's unprivileged": "Ak je kontajner neprivilegovaný, malo by sa zobraziť 'unprivileged: 1'", @@ -4125,14 +5359,23 @@ "Show size of a directory": "Zobraziť veľkosť priečinka", "Show standard exclude patterns": "Zobraziť štandardné vylučovacie vzory", "Show status of all storage pools": "Zobraziť stav všetkých úložísk", + "Show the QR code of a peer again with: pct exec -- /app/show-peer 1": "Zobraziť QR kód peera znovu s: pct exec < CTID > -- /app/show-peer 1", "Show traffic statistics per interface": "Zobraziť štatistiky prenosu podľa rozhrania", "Show vzdump backup configuration": "Zobraziť nastavenie vzdump záloh", "Shows status and type (nfs/cifs/dir/iscsi...).": "Zobrazí stav a typ (nfs/cifs/dir/iscsi...).", "Shutdown timeout": "Čas na vypnutie vypršal", + "SiYuan access code": "Prístupový kód SiYuan", + "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more..": "SickGear poskytuje správu televíznych relácií a / alebo Anime, detekuje nové epizódy, odkazy aplikácie pre downloader, a ďalšie..", + "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private.": "Signal je aplikácia správ s ochranou súkromia v jej jadre. Je zadarmo a ľahko použiteľný, so silným end-to-end šifrovaním, ktoré udržuje vašu komunikáciu úplne súkromnú.", "Signatures removed. Partition table preserved.": "Podpisy boli odstránené. Tabuľka oddielov zostala zachovaná.", + "Simple and easy to use DDNS": "Jednoduché a jednoduché použitie DDNS", "Single GPU Warning": "Upozornenie na jednu GPU", "Single target found — selected automatically:": "Našiel sa jeden target - vybraný automaticky:", "Size": "Veľkosť", + "Size in GB of": "Veľkosť v GB", + "Size of each consume/export volume in GB": "Veľkosť každého spotrebovaného/vývozného objemu v GB", + "Size of the /dev/shm shared memory in MB": "Veľkosť zdieľanej pamäte /dev/shm v MB", + "Size of the Frigate temporary cache in MB": "Veľkosť Frigate dočasnej vyrovnávacej pamäte v MB", "Size:": "Veľkosť:", "Skip downloading additional languages": "Nesťahovať ďalšie jazyky", "Skip this device": "Preskočiť toto zariadenie", @@ -4142,6 +5385,7 @@ "Skip — leave as-is": "Preskočiť - nechať bez zmeny", "Skipped (no disks of the pool are present on this host):": "Preskočené (na tomto hostovi nie sú prítomné žiadne disky poolu):", "Skipped (some disks missing):": "Preskočené (niektoré disky chýbajú):", + "Skipped because Jellyfin did not create encoding.xml:": "Preskočené, pretože Jellyfin nevytvoril kódovanie.xml:", "Skipped device": "Zariadenie bolo preskočené", "Skipped to protect target system (would cascade-remove packages)": "Preskočené na ochranu cieľového systému (odstránilo by to ďalšie balíky)", "Skipped, not in apt cache:": "Preskočené, nie je v apt cache:", @@ -4149,7 +5393,10 @@ "Skipping SR-IOV device": "Preskakujem SR-IOV zariadenie", "Skipping installation.": "Inštalácia sa preskakuje.", "Skipping manual patches — feranick fork already supports this kernel.": "Ručné záplaty preskakujem - fork feranick už tento kernel podporuje.", + "Sleek podcast downloader with GPodder sync": "Sleek podcast downloader s GPodder synchronizácia", "Smart restore plan — hardware compatibility check": "Inteligentný plán obnovy - kontrola kompatibility hardvéru", + "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis.": "Smokeping sleduje latenciu vašej siete. Úplný príklad toho, čo je táto aplikácia schopná navštíviť UCDavis.", + "SnapOtter": "SnapOtter", "Snippets — hook scripts / config": "Snippets — hook skripty / konfigurácia", "SoC-integrated GPU: tight coupling with other SoC components": "GPU integrovaná v SoC: úzke prepojenie s ďalšími súčasťami SoC", "Some DKMS removals reported errors; final verification will determine the result.": "Niektoré odstránenia DKMS hlásili chyby;konečné overenie určí výsledok.", @@ -4159,6 +5406,7 @@ "Some old time services could not be removed (not installed)": "Niektoré staré časové služby sa nepodarilo odstrániť (nie sú nainštalované)", "Some operations failed — review messages above. Press Enter to continue...": "Niektoré operácie zlyhali - pozrite si hlásenia vyššie. Pokračujte stlačením Enter...", "Some packages still need attention; review": "Niektoré balíky si stále vyžadujú pozornosť;recenzia", + "Some projects publish a Dockerfile and not an image: it has to be built and published to a registry before it can be installed this way. An image of a private registry needs credentials, which are not supported yet.": "Niektoré projekty publikujú súbor Docker, a nie obraz: musí byť postavený a zverejnený do registra predtým, než môže byť nainštalovaný týmto spôsobom. Obraz súkromného registra potrebuje credentials, ktoré ešte nie sú podporované.", "Some repairs failed. Please fix manually and re-run the script.": "Niektoré opravy zlyhali. Opravte ich ručne a spustite skript znova.", "Some repositories are not available, continuing with available ones...": "Niektoré repozitáre nie sú dostupné, pokračujem s dostupnými...", "Some selected GPUs are already configured in this container.": "Niektoré vybrané GPU už sú v tomto kontajneri nastavené.", @@ -4166,6 +5414,10 @@ "Some utility packages could not be removed; the remaining list has been preserved": "Niektoré balíky nástrojov nebolo možné odstrániť;zostávajúci zoznam sa zachoval", "Something is already mounted at": "Niečo už je pripojené v", "Something is already mounted at:": "Niečo už je pripojené v:", + "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Sonarr (predtým NZBdrone) je PVR pre užívateľov usenet a bittorrent. To môže sledovať viac RSS kanálov pre nové epizódy vašich obľúbených show a bude chytiť, triediť a premenovať ich. Môže byť tiež nakonfigurovaný tak, aby automaticky upgrade kvality súborov už stiahnutých, keď je k dispozícii kvalitnejší formát.", + "Sonarr added to Prowlarr": "Sonarr pridaný do Prowlarr", + "Sonarr connected to qBittorrent": "Sonarr napojený na qBittorrent", + "Sonarr root folder configured": "Konfigurovaný koreňový priečinok Sonarr", "Source": "Zdroj", "Source VM": "Zdrojová VM", "Source patched successfully.": "Zdrojový kód bol úspešne upravený.", @@ -4174,8 +5426,26 @@ "Spanish": "Španielčina", "Specific host (enter IP)": "Konkrétny host (zadať IP)", "Specific subnet (enter manually)": "Konkrétna podsieť (zadať ručne)", + "Speedtest Tracker web interface": "Webové rozhranie Speedtest Tracker", + "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service.": "Speedtest-tracker je self-hosted internetové sledovanie výkonu aplikácie, ktorá beží rýchlostnú kontrolu proti Ookla je Speedtest služby.", + "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium": "Spotube je open source, cross-platform Spotify klient kompatibilný vo viacerých platformách využívajúce dáta spoločnosti Spotify API a YouTube, Piped. video alebo JioSaavn ako audio zdroj, odstránenie potreby Spotify Premium", "Stable (main branch)": "Stabilná verzia (vetva main)", "Stable monitor service normalized.": "Služba Monitora pre stabilnú verziu je upravená.", + "Stack": "Stack", + "Stack adapter not recognized by the translator": "Stack adaptér nerozpoznal prekladateľ", + "Stack backups are missing; a partial restore is not allowed": "Chýbajú zálohy, čiastočná obnova nie je povolená.", + "Stack checked:": "Stack skontrolovaný:", + "Stack members are missing; recreate them after verifying their volumes": "Chýbajú členovia Stack; znovu ich vytvoriť po overení ich objemov", + "Stack members are updated together with their stack": "Členovia Stack sú aktualizované spolu s ich stack", + "Stack name": "Názov zásobníka", + "Stack records restored": "Stack záznamy obnovené", + "Stack records saved": "Uložené Stack záznamy", + "Stack records saved; no container was reinstalled.": "Stack záznamy uložené; žiadny kontajner bol znovu nainštalovaný.", + "Stack recovery completed; every member is back to its previous installation.": "Stack recovery dokončené; každý člen je späť do svojej predchádzajúcej inštalácie.", + "Stack startup hook installed": "Nainštalovaný štartovací hák Stack", + "Stack stopped": "Stack zastavil", + "Stack update completed. Data kept.": "Aktualizácia Stack dokončená. Údaje uchovávané.", + "Stack:": "Stack:", "Staging directory:": "Prípravný priečinok:", "Staging ready.": "Prípravný priečinok je pripravený.", "Staging source:": "Zdroj prípravy:", @@ -4183,11 +5453,13 @@ "Stale VFIO Config Detected": "Zistila sa zastaraná konfigurácia VFIO", "Stale VFIO entries removed and initramfs rebuilt.": "Zastarané záznamy VFIO boli odstránené a initramfs prestavané.", "Standard NAS (backup, iso, vztmpl)": "Štandardné NAS (backup, iso, vztmpl)", + "Start": "Začiatok", "Start VM": "Spustiť VM", "Start VM after creation": "Spustiť VM po vytvorení", "Start VM after creation?": "Spustiť VM po vytvorení?", "Start a container. Use the correct ": "Spustiť kontajner. Použite správne ", "Start a virtual machine. Use the correct ": "Spustiť VM. Použite správne ", + "Start each LXC with Proxmox (no coordinated startup)": "Začnite každý LXC s Proxmox (bez koordinovaného štartu)", "Start long self-test (hours)": "Spustiť dlhý samotest (hodiny)", "Start long test now?": "Spustiť dlhý test teraz?", "Start on boot already disabled for VM": "Štart pri boote je už pre VM vypnutý", @@ -4199,11 +5471,16 @@ "Start scrub for a ZFS pool": "Spustiť scrub pre ZFS pool", "Start short self-test (~2 min)": "Spustiť krátky samotest (~2 min)", "Start terminal multiplexer (recommended):": "Spustite terminálový multiplexer (odporúčané):", + "Start the LXC when finished to apply the selected configuration?": "Spustiť LXC po dokončení pre použitie zvolenej konfigurácie?", "Start the VM": "Spustiť VM", "Start the VM to begin Windows installation from the mounted ISO.": "Spustite VM a začnite inštaláciu Windowsu z pripojeného ISO.", "Start the converted container:": "Spustiť prevedený kontajner:", "Start the main system upgrade:": "Spustite hlavnú aktualizáciu systému:", + "Start the stack with Proxmox": "Spustiť zásobník s Proxmox", "Start uploading to PBS — sets a recovery passphrase": "Spustiť nahrávanie do PBS - nastaví obnovovaciu frázu", + "Start when finished": "Spustiť po dokončení", + "Start with Proxmox": "Začnite s Proxmox", + "Starting": "Začiatok", "Starting Borg backup...": "Spúšťam Borg zálohu...", "Starting CT": "Spúšťam CT", "Starting LXC Privileged to Unprivileged conversion process...": "Spúšťam prevod LXC z privilegovaného na neprivilegovaný...", @@ -4214,6 +5491,7 @@ "Starting ProxMenux update...": "Spúšťam aktualizáciu ProxMenux...", "Starting Proxmox storage integration...": "Spúšťam integráciu s úložiskom Proxmoxu...", "Starting Proxmox system repair...": "Spúšťam opravu systému Proxmox...", + "Starting Rclone and waiting for the FUSE mount...": "Štart Rclone a čakanie na FUSE...", "Starting SMART long self-test...": "Spúšťam dlhý SMART samo-test...", "Starting SMART short self-test...": "Spúšťam krátky SMART samo-test...", "Starting container": "Spúšťam kontajner", @@ -4224,9 +5502,20 @@ "Starting installer...": "Spúšťam inštalátor...", "Starting privileged container...": "Spúšťam privilegovaný kontajner...", "Starting rpcbind service...": "Spúšťam službu rpcbind...", + "Starting the container...": "Spúšťam kontajner...", + "Starting the main container and its dependencies...": "Spustenie hlavného kontajnera a jeho závislosti...", + "Starting the service:": "Spustenie služby:", "Starting unprivileged container...": "Spúšťam neprivilegovaný kontajner...", + "Startup: coordinated by the stack startup hook": "Štartovanie: koordinované stack štartovacím hákom", + "Startup: independent, without hookscript": "Spustenie: nezávislé, bez skriptu", + "Static IP": "Statické IP", + "Static IPv4 address": "Statická IPv4 adresa", + "Static IPv4 address for": "Statická IPv4 adresa pre", "Status": "Stav", "Status:": "Stav:", + "Steam is the ultimate destination for playing, discussing, and creating games.": "Steam je konečným cieľom pre hranie, diskusie, a vytváranie hier.", + "SteamGridDB": "SteamGridDB", + "SteamGridDB API key": "Kľúč SteamGridDB API", "Step": "Krok", "Step 2: Testing actual share access with guest...": "Krok 2: Testujem skutočný prístup k zdieľaniu ako hosť...", "Steps that will run:": "Kroky, ktoré sa vykonajú:", @@ -4234,12 +5523,14 @@ "Stop it first and run this option again.": "Najprv ju zastavte a potom túto možnosť spustite znova.", "Stop the CT, unmount the disk on the HOST, and remount with:": "Zastavte CT, odpojte disk na HOSTE a pripojte ho znova pomocou:", "Stop the VM/CT before formatting this disk.": "Pred formátovaním tohto disku zastavte VM/CT.", + "Stop the container before the NVIDIA refresh": "Zastavte nádobu pred obnovou NVIDIA", "Stop the container if it's running:": "Ak kontajner beží, zastavte ho:", "Stop them first and run this script again.": "Najprv ich zastavte a potom spustite skript znova.", "Stop uploading to PBS": "Zastaviť nahrávanie do PBS", "Stop uploading?": "Zastaviť nahrávanie?", "Stopped": "Zastavený", "Stopped and disabled": "Zastavené a vypnuté", + "Stopped at:": "Zastavené v:", "Stopping Coral kernel modules...": "Zastavujem kernel moduly Coral...", "Stopping LXC": "Zastavujem LXC", "Stopping NFS services...": "Zastavujem NFS služby...", @@ -4251,6 +5542,8 @@ "Stopping gateway...": "Zastavujem bránu...", "Stopping the container before applying configuration...": "Pred použitím nastavenia zastavujem kontajner...", "Stopping the container before conversion...": "Pred prevodom zastavujem kontajner...", + "Stopping the container...": "Zastavujem kontajner...", + "Stopping the stack...": "Zastavujem kopu...", "Storage": "Úložisko", "Storage & Share Manager": "Úložiská a zdieľanie", "Storage Added:": "Úložisko bolo pridané:", @@ -4263,21 +5556,41 @@ "Storage and Disks Commands": "Príkazy pre úložiská a disky", "Storage controller: VirtIO SCSI": "Radič úložiska: VirtIO SCSI", "Storage disk identifier:": "Identifikátor disku v úložisku:", + "Storage for Nextcloud files, configuration and data": "Úložisko pre Nextcloud súborov, konfigurácie a dát", + "Storage for Paperless data and documents": "Úložisko pre údaje a dokumenty bez dokumentov", + "Storage for Tandoor files": "Úložisko pre súbory Tandoor", + "Storage for persistent data": "Skladovanie trvalých údajov", + "Storage for recipe images and files": "Skladovanie pre recepty a súbory", + "Storage for rootfs": "Skladovanie pre rootfs", + "Storage for rootfs and private configuration": "Skladovanie pre rootfs a súkromné konfigurácie", + "Storage for the Immich library": "Sklad pre knižnicu Immich", + "Storage for the Nextcloud data": "Skladovanie údajov Nextcloud", + "Storage for the OCI image cache": "Úložisko pre vyrovnávaciu pamäť obrazu OCI", + "Storage for the consume and export folders": "Skladovanie pre konzumné a exportné priečinky", + "Storage for the persistent configuration": "Skladovanie pre trvalú konfiguráciu", "Storage is now available in Proxmox web interface under Datacenter > Storage": "Úložisko je teraz dostupné vo webovom rozhraní Proxmoxu v časti Datacenter > Storage", "Storage plan selection cancelled.": "Výber plánu úložiska bol zrušený.", "Storage plan selection failed or cancelled": "Výber plánu úložiska zlyhal alebo bol zrušený", + "Storage selection cancelled": "Výber úložiska zrušený", "Storage:": "Úložisko:", "Stored Credentials:": "Uložené prihlasovacie údaje:", "Stored credentials:": "Uložené prihlasovacie údaje:", + "Stremio is a modern media center that gives you the freedom to watch everything you want.": "Stremio je moderné mediálne centrum, ktoré vám dáva slobodu sledovať všetko, čo chcete.", + "Subdomains for the certificate, comma separated (wildcard for *.domain)": "Subdomény pre osvedčenie, čiarka oddelené (divoká karta pre *.doména)", "Subnet": "Podsieť", "Subscription banner removal failed": "Odstránenie bannera odberu zlyhalo", "Subscription banner removed successfully": "Banner predplatného bol úspešne odstránený", "Subscription banner restored successfully (desktop and mobile)": "Hlásenie o predplatnom bolo úspešne obnovené (desktop aj mobil)", "Success": "Úspech", "Successful": "Úspešné", + "Supervisor does not confirm healthy and supported yet": "Dozorca zatiaľ nepotvrdil zdravie a podporu", + "Supervisor reports no connectivity; retrying to get versions and install components": "Supervízor nenahlási žiadnu konektivitu; znovu sa snaží získať verzie a inštalovať komponenty", "Supported formats: .img, .qcow2, .vmdk, .raw": "Podporované formáty: .img, .qcow2, .vmdk, .raw", + "Swap": "Swap", + "Swap in MB": "Swap v MB", "Swap partition detected": "Zistený swap oddiel", "Swappiness configuration created successfully": "Nastavenie swappiness bolo úspešne vytvorené", + "Swing Music is a beautifully designed, self-hosted music streaming server. Like a cooler Spotify ... but bring your own music.": "Swing Music je krásne navrhnutý, self-hosted hudobný streaming server. Ako cooler Spotify ... ale priniesť si vlastnú hudbu.", "Switch GPU Mode (VM <-> LXC)": "Prepnúť režim GPU (VM <-> LXC)", "Switch Mode": "Zmena režimu", "Switch Script Not Found": "Skript na prepnutie sa nenašiel", @@ -4287,13 +5600,21 @@ "Switching to": "Prepnutie na", "Switching to GPU -> LXC mode removes VFIO exclusivity.": "Prepnutie do režimu GPU -> LXC odstráni výhradné použitie VFIO.", "Switching to GPU -> VM mode requires exclusive VFIO binding.": "Prepnutie do režimu GPU -> VM vyžaduje výhradné VFIO naviazanie.", + "Symbolic link in a restored volume path": "Symbolické spojenie v obnovenej ceste zväzku", + "Symbolic link in the path of an adaptation": "Symbolický odkaz na ceste adaptácie", + "Symbolic link loop in the new image": "Symbolická slučka na novom obrázku", + "Symbolic link outside the rootfs of the new image": "Symbolický odkaz mimo rootfs nového obrázku", "Synchronize time automatically": "Automaticky synchronizovať čas", + "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are.": "Synclounge je nástroj tretej strany, ktorý umožňuje sledovať Plex v synchronizácii so svojimi priateľmi / rodinou, kdekoľvek ste.", + "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet.": "Syncthing nahrádza proprietárnu synchronizáciu a cloudové služby niečím otvoreným, dôveryhodným a decentralizovaným. Vaše údaje sú len vaše údaje a zaslúžite si vybrať, kde sú uložené, ak sú zdieľané s nejakou treťou stranou a ako sa prenášajú cez internet.", + "Sysctl not namespaced or not valid:": "Sysctl nie je menovaný alebo neplatný:", "System": "Systém", "System CLI Tools": "Systémové CLI nástroje", "System Disk Size (GB)": "Veľkosť systémového disku (GB)", "System Update Information": "Informácie o aktualizácii systému", "System Utilities Installer": "Inštalátor systémových nástrojov", "System disk is SSD or M.2. Proceeding with Log2RAM setup.": "Systémový disk je SSD alebo M.2. Pokračujem v nastavení Log2RAM.", + "System error:": "Chyba systému:", "System errors and logs": "Systémové chyby a logy", "System group apex already exists.": "Systémová skupina apex už existuje.", "System group apex created.": "Systémová skupina apex bola vytvorená.", @@ -4304,6 +5625,7 @@ "System limits increase completed.": "Zvýšenie systémových limitov je dokončené.", "System limits optimizations removed": "Optimalizácie systémových limitov boli odstránené", "System must be updated to latest PVE 8.4+ before starting": "Pred začiatkom musí byť systém aktualizovaný na najnovšie PVE 8.4+", + "System path mounts are not yet supported": "Pripojenie systémovej cesty ešte nie je podporované", "System reboot required": "Vyžaduje sa reštart systému", "System upgrade completed": "Aktualizácia systému je dokončená", "System uptime": "Doba behu systému", @@ -4318,6 +5640,11 @@ "TROUBLESHOOTING:": "RIEŠENIE PROBLÉMOV:", "TUI mode": "TUI režim", "TUI mode (requires root)": "TUI režim (vyžaduje root)", + "Take control of your Minecraft servers.": "Prevezmite kontrolu nad svojimi servermi Minecraft.", + "Tandoor WebUI": "Tandoor WebUI", + "Tandoor configuration cancelled": "Konfigurácia tandooru zrušená", + "Tandoor needs at least 1 GB for staticfiles and 4 GB for PostgreSQL": "Tandoor potrebuje aspoň 1 GB pre statické súbory a 4 GB pre PostgreSQL", + "Tandoor needs to complete its first start to create the initial administrator": "Tandoor potrebuje dokončiť svoj prvý štart na vytvorenie pôvodného správcu", "Target IQN:": "IQN targetu:", "Target VM": "Cieľová VM", "Target VM validated": "Cieľová VM bola overená", @@ -4327,6 +5654,12 @@ "Target mode": "Cieľový režim", "Target server:": "Cieľový server:", "Target:": "Target:", + "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server.": "Tautulli je webová aplikácia založená na pythone pre monitorovanie, analýzu a oznámenia pre Plex Media Server.", + "Teable adopts a concise spreadsheet interface, yet creates powerful database applications": "Teable prijíma stručné tabuľkové rozhranie, ale vytvára výkonné databázové aplikácie", + "Telegram is a cloud-based mobile and desktop messaging app.": "Telegram je mobilná a desktopová aplikácia na báze cloudových správ.", + "Temporary data container:": "Dočasný dátový kontajner:", + "Temporary login": "Dočasné prihlásenie", + "Temporary password retrieved": "Dočasné obnovenie hesla", "Temporary working directory (if present):": "Dočasný pracovný priečinok (ak existuje):", "Terminal Multiplexers": "Terminálové multiplexery", "Terminal multiplexer (Ctrl+b then d to detach, or type exit)": "Terminálový multiplexer (Ctrl+b potom d na odpojenie, alebo napíšte exit)", @@ -4343,40 +5676,196 @@ "Testing comprehensive guest access to server": "Testujem podrobne prístup hosťa k serveru", "Testing connectivity to portal...": "Testujem pripojenie k portálu...", "Testing network connectivity...": "Testujem sieťové pripojenie...", + "Text that new pads start with (empty = the text of the image)": "Text, s ktorým začínajú nové podložky (prázdne = text obrázku)", "Thank you for using ProxMenux. Goodbye!": "Ďakujeme, že používate ProxMenux. Dovidenia!", "That VM is currently stopped, so the GPU can be reassigned now.": "Tá VM je momentálne zastavená, takže GPU sa teraz dá presunúť.", "That doesn't look like an SSH private key. Pick the private key file (no .pub extension, parseable by ssh-keygen).": "Toto nevyzerá ako súkromný SSH kľúč. Vyberte súbor súkromného kľúča (bez prípony .pub, čitateľný cez ssh-keygen).", + "The .conf files under /config/fail2ban are rewritten on every start. Keep customizations in the matching .local file, for example jail.local for jail.conf.": "Súbory .conf pod /config/fail2ban sú prepísané na každom začiatku. Udržujte prispôsobenie v zodpovedajúcom .lokálnom súbore, napríklad vo väzení.lokálne pre väzenie.conf.", + "The AppArmor/seccomp relaxation does not include the required consent": "AppArmor/seccomp relaxácia nezahŕňa súhlas required", + "The Bookmark Everything App": "Záložka Všetko App", + "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile.": "Prehliadač Brave je rýchly, súkromný a bezpečný webový prehliadač pre PC, Mac a mobil.", + "The CT already exists:": "CT už existuje:", + "The Compose file declares no service": "Zostaviť súbor deklaruje žiadnu službu", + "The Compose file describes several images:": "Skladací súbor popisuje niekoľko obrázkov:", + "The Compose file does not contain a Compose document": "Skladací súbor neobsahuje dokument", + "The Compose file is not valid YAML:": "Skladací súbor nie je platný", + "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "Skladba ponúka voliteľnú AppArmor alebo seccomp relaxáciu; zostane vypnutá, ak si ju užívateľ nevyberie. Pokračujte len vtedy, ak dôverujete obrazu a prijmete toto riziko.", + "The Compose value must be text or a list:": "Kompozitná hodnota musí byť text alebo zoznam:", + "The DRM node is not an Intel or AMD GPU; NVIDIA requires its library profile": "DRM uzol nie je Intel ani AMD GPU; NVIDIA requires svoj profil knižnice", + "The Entrypoint/Cmd combination is empty": "Vstupný bod/Cmd combination je prázdny", + "The FUSE publication helper was not found": "Pomocník FUSE nebol nájdený", + "The GPU evidence does not match the verified devices": "Dôkazy GPU nezodpovedajú overeným zariadeniam", "The GPU has been moved out of VM": "GPU bola presunutá mimo VM", + "The GPU identity or permissions changed; the container is not modified": "Identita alebo povolenia GPU sa zmenili; kontajner sa nemení", "The GPU is being detached from VM": "GPU sa odpája z VM", + "The GPU vendor differs from the requested profile": "Predajca GPU sa líši od požadovaného profilu", + "The GPU vendor does not match the selected GPU profile:": "Dodávateľ GPU nezodpovedá zvolenému profilu GPU:", + "The Immich CPU quota cannot be reproduced": "Kvóta Immich CPU nemôže byť reprodukovaná", + "The Immich library needs at least 8 GB": "Knižnica Immich potrebuje aspoň 8 GB", + "The Immich startup was modified or cannot be reproduced": "Spustenie Immich bolo upravené alebo nemožno reprodukovať", + "The LXC has stopped": "LXC zastavil", + "The Lounge starts in public mode: anyone who reaches the address opens the client without logging in, and the IRC networks added are lost when the session ends.": "Lounge začína vo verejnom režime: každý, kto dosiahne adresu otvorí klienta bez prihlásenia, a IRC siete pridané sú stratené po skončení sedenia.", + "The MAC address of the container cannot be kept": "Adresa MAC kontajnera sa nemôže uchovávať", "The NVIDIA Container Toolkit repository definition was empty.": "Definícia úložiska NVIDIA Container Toolkit bola prázdna.", "The NVIDIA Container Toolkit signing key could not be read.": "Nepodarilo sa prečítať podpisový kľúč súpravy NVIDIA Container Toolkit.", + "The NVIDIA Container Toolkit version cannot be identified": "Verzia NVIDIA Container Toolkit sa nedá identifikovať", + "The NVIDIA destination cannot be replaced": "Miesto určenia NVIDIA nemožno nahradiť", + "The NVIDIA destination escapes the rootfs": "Cieľ NVIDIA unikne koreňom", "The NVIDIA driver is installed, but the Container Toolkit phase did not complete. GPU support for OCI containers is unavailable until it does.": "Ovládač NVIDIA je nainštalovaný, ale fáza Container Toolkit sa nedokončila. Podpora GPU pre kontajnery OCI nie je k dispozícii, kým sa nestane.", + "The NVIDIA driver or inventory changed; the operation was stopped": "Ovládač NVIDIA alebo inventár sa zmenili; operation bol zastavený", + "The NVIDIA hook or environment differs from the declared one": "Háčik alebo prostredie NVIDIA sa líši od deklarovaného", + "The NVIDIA hook path does not belong to the installer": "Cesta k háku NVIDIA nepatrí inštalátorovi", "The NVIDIA installer needs at least": "NVIDIA inštalátor potrebuje aspoň", + "The NVIDIA runtime is up to date; the container is not modified or started": "Runtime NVIDIA je aktuálny; kontajner nie je upravený ani spustený", + "The Nextcloud volume needs at least 8 GB": "Objem Nextcloud potrebuje najmenej 8 GB", + "The OCI archive contains no SHA-256 blobs": "Archív OCI neobsahuje žiadne SHA-256 blobs", + "The OCI archive does not contain exactly one manifest": "Archív OCI neobsahuje presne jeden manifest", + "The OCI archive does not exist or is empty:": "Archív OCI neexistuje alebo je prázdny:", + "The OCI archive verifier was not found": "Archívový overovateľ OCI nebol nájdený", + "The OCI catalog is not installed. Update ProxMenux and try again.": "Katalóg OCI nie je nainštalovaný. Aktualizovať ProxMenux a skúste to znova.", + "The OCI engine is not installed. Update ProxMenux and try again.": "Motor OCI nie je nainštalovaný. Aktualizovať ProxMenux a skúste to znova.", + "The OCI image storage was not kept": "Uskladnenie obrazu OCI nebolo uchované", + "The OCR language must use Tesseract codes, for example eng or eng+spa": "Jazyk OCR musí používať kódy Tesseract, napríklad eng alebo eng+spa", + "The PATH of the new image is outside the reproducible profile": "PATH nového obrázku je mimo reprodukovateľného profilu", + "The Paperless persistent volumes need at least 8 GB": "Trvalé objemy bez dokumentov potrebujú najmenej 8 GB", + "The PostgreSQL volume needs at least 4 GB": "Objem PostgreSQL potrebuje najmenej 4 GB", + "The PostgreSQL volume needs at least 8 GB": "Objem PostgreSQL potrebuje najmenej 8 GB", "The Proxmox archive keyring is missing; Ceph installation cannot continue safely": "Chýba zväzok kľúčov archívu Proxmox;Inštalácia Ceph nemôže bezpečne pokračovať", + "The Proxmox inventory and the local configurations differ": "Súpis Proxmox a miestne konfigurácie sa líšia", + "The Rclone configuration needs at least 1 GB": "Konfigurácia Rklonu potrebuje aspoň 1 GB", + "The Rclone rootfs needs at least 2 GB": "Rclone rootfs potrebuje aspoň 2 GB", + "The Selkies profile requires a verified LinuxServer image": "Profil Selkies requires a overený obraz LinuxServer", + "The Tandoor files volume needs at least 2 GB": "Objem súborov Tandoor potrebuje aspoň 2 GB", "The URL does not contain the required parameters (id, pack, edition).": "URL neobsahuje potrebné parametre (id, pack, edition).", + "The USB number can change after reconnecting or rebooting. This profile does not remap it automatically or handle Coral USB re-enumeration. Do not share a dongle already used by another service.": "Číslo USB sa môže zmeniť po opätovnom pripojení alebo reštarte. Tento profil nie je automaticky premapovať alebo spracovať Coral USB re-enumeration. Nezdieľajte šišku, ktorú už používa iná služba.", + "The Unifi-controller software is a powerful, enterprise wireless software engine ideal for high-density client deployments requiring low latency and high uptime performance.": "Softvér Unifi-controller je výkonný, podnikový bezdrôtový softvérový motor ideálny pre zavedenie klientov s vysokou hustotou requiring nízka latencia a vysoký výkon v čase.", + "The VA-API device does not exist:": "Zariadenie VA-API neexistuje:", "The VM also has these audio devices assigned via PCI passthrough — typically added together with the GPU. Remove them too?": "VM má cez PCI passthrough priradené aj tieto audio zariadenia - zvyčajne sa pridávajú spolu s GPU. Odstrániť aj tie?", "The VM guest will have exclusive access to the GPU.": "Hosťovská VM bude mať výhradný prístup ku GPU.", "The VM is powered on. Turn it off before adding disks.": "VM je zapnutá. Pred pridaním diskov ju vypnite.", "The VM/LXC will lose access to this disk after formatting.": "VM/LXC po formátovaní stratí prístup k tomuto disku.", + "The VMID belongs to another container now and is not touched:": "VMID teraz patrí do inej nádoby a nedotýka sa:", + "The VMID or its contract is already in use; it is not adopted": "VMID alebo jeho zmluva sa už používa; nie je prijatá", + "The VMID was reused or its identity is unknown; the operation is blocked": "VMID bol opätovne použitý alebo jeho identita nie je známa; operation je zablokovaný", + "The VMID was reused or the container is on another node; it is not overwritten": "VMID bol opätovne použitý alebo kontajner je na inom uzle; nie je prepísaný", + "The VMID was taken during the installation:": "VMID bol vykonaný počas inštalácie:", + "The Valkey volume needs at least 1 GB": "Objem Valkey potrebuje aspoň 1 GB", + "The acceleration evidence differs from the verified inventory": "Dôkazy zrýchlenia sa líšia od overeného súpisu", + "The acceleration profile does not support this architecture:": "Profil zrýchlenia nepodporuje túto architektúru:", "The active kernel driver is not vfio-pci, but the entry in": "Aktívny ovládač jadra nie je vfio-pci, ale položka in", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot, breaking the LXC passthrough about to be configured.": "Aktívny ovládač jadra nie je vfio-pci, ale táto položka pri ďalšom reštarte znova naviaže GPU na vfio-pci, čím sa preruší prechod LXC, ktorý sa má konfigurovať.", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot.": "Aktívny ovládač jadra nie je vfio-pci, ale táto položka pri ďalšom reštarte znova pripojí GPU k vfio-pci.", + "The adaptation content was modified": "Obsah úpravy bol upravený", + "The additional path hides a system directory": "Ďalšia cesta skrýva systémový adresár", + "The address is already assigned on this host or cluster:": "Adresa je už priradená na tohto hostiteľa alebo klastra:", + "The address must start with http:// or https://": "Adresa musí začať na http:// alebo https://", + "The administrator account, the public address and the UDP port are created on the first start, so the web interface opens directly on its login page.": "Správca účtu, verejná adresa a UDP port sú vytvorené na prvom začiatku, takže webové rozhranie sa otvorí priamo na prihlasovacej stránke.", + "The administrator email is not valid": "Správca e-mail nie je platný", + "The administrator user contains characters that are not allowed": "Užívateľ správcu obsahuje znaky, ktoré nie sú povolené", + "The all-in-one AI application.": "Aplikácia UI.", + "The application configuration needs a first start to complete.": "Konfigurácia aplikácie potrebuje prvý štart na dokončenie.", + "The application did not complete its initial setup:": "Žiadosť nevyplnila svoje pôvodné nastavenie:", + "The application did not get an address on the access network:": "Aplikácia nedostala adresu v prístupovej sieti:", + "The application did not pass its HTTP check:": "Aplikácia neprešla kontrolou HTTP:", + "The application did not respond in time:": "Žiadosť neodpovedala včas:", + "The application stopped during its first start:": "Aplikácia sa zastavila počas prvého začiatku:", + "The application was removed": "Žiadosť bola stiahnutá", "The archive could not be extracted.": "Archív sa nepodarilo rozbaliť.", "The archive destination directory is INSIDE one of the paths you are about to back up. Writing the archive there would copy the backup into itself — producing a corrupted archive, or growing without limit until the disk fills up.": "Cieľový priečinok archívu je VNÚTRI jednej z ciest, ktoré sa chystáte zálohovať. Zápis archívu na toto miesto by zálohu kopíroval samu do seba - vznikol by poškodený archív alebo by rástol, kým sa disk nezaplní.", + "The backup could not be identified; the image is not replaced": "Zálohovanie nebolo možné identifikovať; obrázok nie je nahradený", "The backup metadata was compared against this host. The following items will be SKIPPED to keep the boot safe:": "Metadáta zálohy boli porovnané s týmto hostom. Nasledujúce položky sa PRESKOČIA, aby zostal štart bezpečný:", + "The backup of a member could not be identified": "Zálohu člena nebolo možné identifikovať", + "The backup was altered; recovery blocked": "Záloha bola zmenená; obnova zablokovaná", "The backup was taken on a different PVE or kernel major.minor. These paths will be SKIPPED to keep the boot safe:": "Záloha bola vytvorená na inom PVE alebo inom major.minor kerneli. Tieto cesty sa PRESKOČIA, aby zostal štart bezpečný:", + "The bind mount target escapes the rootfs:": "Záväzná pripojiť cieľ unikne koreňom:", + "The block device does not exist:": "Blokovacie zariadenie neexistuje:", "The build could not be checked beforehand; continuing without that check.": "Zostavenie nebolo možné vopred skontrolovať;pokračovanie bez tejto kontroly.", + "The cached image does not match the current digest": "Comment", + "The cached image is damaged; it will be downloaded again.": "Comment", + "The character device does not exist:": "Znakové zariadenie neexistuje:", + "The command asks for a password that is not echoed. After creating the users, the web interface asks for a user name and a password.": "Príkaz vyžaduje heslo, ktoré nie je ozvene. Po vytvorení užívateľov, webové rozhranie žiada o užívateľské meno a heslo.", + "The command does not name an image": "Príkaz nepomenuje obrázok", + "The command reads its variables from a file; write them in the command or use a Compose file": "Príkaz číta svoje premenné zo súboru; zapíšte ich do príkazu alebo použite súbor", + "The command runs the container as the user of the host; the container uses the user of its image instead.": "Príkaz spustí kontajner ako užívateľ hostiteľa; kontajner používa užívateľa svojho obrazu miesto.", + "The command works out a value by running another command:": "Príkaz vytvorí hodnotu spustením iného príkazu:", "The compatibility check raised failures that may break the system after restore.": "Kontrola kompatibility našla zlyhania, ktoré môžu po obnove poškodiť systém.", + "The configuration changed after the backup was restored; the recovery is not confirmed": "Konfigurácia zmenená po obnovení zálohy; obnova nie je potvrdená", + "The configuration changed after the new container was validated": "Konfigurácia zmenená po overení nového kontajnera", + "The configuration changed during the NVIDIA refresh": "Konfigurácia sa zmenila počas obnovovania NVIDIA", + "The configuration evidence does not match": "Konfiguračný dôkaz nezodpovedá", + "The configuration must run as root on Proxmox VE": "Konfigurácia musí bežať ako koreň na Proxmox VE", + "The configuration of a new member changed after it was created": "Nastavenie nového člena sa zmenilo po jeho vytvorení", + "The configuration stopped because of an unexpected error": "Konfigurácia sa zastavila kvôli neočakávanej chybe", + "The consume/export volumes need at least 1 GB": "Objem spotreby/vývozu potrebuje najmenej 1 GB", + "The container could not be removed automatically:": "Nádoba sa nedala automaticky odstrániť:", + "The container could not be started:": "Nádoba nemohla byť spustená:", + "The container creation does not match the prepared instance": "Vytvorenie kontajnera nezodpovedá pripravenej inštancii", + "The container devices do not match the saved record": "Zariadenie kontajnera nezodpovedá uloženému záznamu", + "The container did not stop to update its persistent configuration:": "Kontajner neprestal aktualizovať svoju pretrvávajúcu konfiguráciu:", + "The container did not stop; its disks are not touched": "Kontajner sa nezastavil; jeho disky nie sú dotknuté", + "The container disks do not match the saved record": "disky kontajnera nezodpovedajú uloženému záznamu", + "The container does not exist:": "Nádoba neexistuje:", + "The container does not have the fuse=1 feature enabled": "Kontajner nemá poistky = 1 zapnuté", + "The container does not need it any more; an update downloads the new version when there is one.": "Kontajner už nepotrebuje; aktualizácia si stiahne novú verziu, keď je.", + "The container gets its own address and its own volumes, so the networks and volumes declared in the file are not used.": "Kontajner dostane svoju vlastnú adresu a svoje vlastné objemy, takže siete a objemy deklarované v súbore nie sú použité.", + "The container has advanced Proxmox settings outside the supported profile": "Kontajner má pokročilé nastavenia Proxmox mimo podporovaného profilu", + "The container identity changed; the container is not replaced": "Označenie kontajnera sa zmenilo; kontajner sa nenahrádza.", + "The container identity does not match": "Identita kontajnera nezodpovedá", + "The container identity or configuration changed": "Zmena identity alebo konfigurácie kontajnera", "The container is currently stopped. Do you want to start it now to install the package?": "Kontajner je momentálne zastavený. Chcete ho teraz spustiť, aby sa balík nainštaloval?", + "The container is not modified because a host directory is not available:": "Kontajner nie je modifikovaný, pretože adresár hostiteľa nie je k dispozícii:", + "The container no longer exists:": "Obal už neexistuje:", + "The container of a member was replaced; the assembly is not resumed": "Zásobník člena bol nahradený; zhromaždenie sa neobnovuje", "The container should now start as privileged": "Kontajner by sa teraz mal spustiť ako privilegovaný", "The container should now start as unprivileged": "Kontajner by sa teraz mal spustiť ako neprivilegovaný", + "The container stopped after starting:": "Nádoba sa zastavila po začatí:", + "The container stopped before publishing the mount": "Kontajner sa zastavil pred zverejnením vrchu", + "The container stopped before the GPU permissions were verified:": "Kontajner sa zastavil pred overením povolení GPU:", + "The container stopped before the application responded:": "Nádobka sa pred podaním žiadosti zastavila:", + "The container stopped:": "Kontajner sa zastavil:", + "The container takes its time zone from Proxmox, so the time files of the host are not attached to it.": "Kontajner trvá časové pásmo od Proxmox, takže časové súbory hostiteľa nie sú pripojené k nemu.", + "The container was changed outside ProxMenux and an update would discard those changes:": "Kontajner bol zmenený mimo ProxMenux a aktualizácia by sa zbaviť týchto zmien:", + "The container was created from a downloaded OCI image": "Kontajner bol vytvorený zo stiahnutého obrázku OCI", + "The containers do not need them any more; an update downloads the new versions when there are any.": "Kontajnery ich už nepotrebujú; aktualizácia stiahne nové verzie, ak nejaké existujú.", + "The containers were created from downloaded OCI images": "Kontajnery boli vytvorené zo stiahnutých obrázkov OCI", + "The coordinated backup was modified": "Koordinovaná záloha bola zmenená", "The current driver will be completely uninstalled before installing the new version. Continue?": "Aktuálny ovládač sa pred inštaláciou novej verzie úplne odinštaluje. Pokračovať?", + "The current image of the saved channel will be checked and downloaded. Resources, paths and GPU are kept. The CT is stopped during the replacement and a native backup is created first.": "Aktuálny obraz uloženého kanála bude skontrolovaný a stiahnutý. Zdroje, cesty a GPU sú udržiavané. CT je zastavený počas výmeny a natívne zálohovanie je vytvorené ako prvé.", + "The current record is missing for": "Aktuálny záznam chýba", + "The current template changes the image or identity; an explicit migration is required": "Aktuálna šablóna mení obraz alebo identitu; explicitná migrácia je required", + "The current template requires a new persistent path:": "Aktuálna šablóna requires novú pretrvávajúcu cestu:", + "The custom path cannot hide system directories": "Vlastná cesta nemôže skryť systémové adresáre", + "The custom path overlaps another mount": "Vlastná cesta sa prekrýva s inou montážou", + "The data and document volumes need at least 8 GB": "Údaje a objemy dokumentov potrebujú najmenej 8 GB", + "The database server must accept connections from the IP address of this container, with a user that is not limited to localhost.": "Databázový server musí prijímať pripojenia z IP adresy tohto kontajnera s užívateľom, ktorý nie je obmedzený na localhost.", + "The dedicated adapter still requires replaying its rootfs changes": "Špecializovaný adaptér stále requires prehráva svoje rootfs zmeny", + "The dependency hook and the stack recipe differ": "Závislosť hák a stack recept sa líšia", + "The dependency hook was modified; review it before updating": "Závislosť hák bol upravený, prehodnocovať pred aktualizáciou", + "The developer-friendly cloud platform for building and running LLM agents for AI-native applications.": "Developer-friendly cloud platforma pre budovanie a prevádzku LLM agentov pre AI-natívne aplikácie.", + "The device directory does not exist:": "Adresár zariadenia neexistuje:", + "The device must keep its /dev path inside the LXC:": "Zariadenie musí udržať svoju / Dev cestu vnútri LXC:", + "The device must keep its native path without duplicates": "Zariadenie musí udržiavať svoju pôvodnú cestu bez duplikátov", + "The directory contains no character devices:": "Adresár neobsahuje žiadne znaky zariadenia:", "The directory does not exist in the CT.": "Priečinok v CT neexistuje.", "The disk": "Disk", + "The disk size cannot be reproduced": "Veľkosť disku nie je možné reprodukovať", + "The disk usage of the container could not be read": "Použitie disku kontajnera nebolo možné prečítať", + "The domain must resolve to the public address of this network before the certificate can be issued.": "Doména musí pred vydaním certifikátu vyriešiť verejnú adresu tejto siete.", + "The download client still needs to be configured.": "Stiahnuť klienta ešte treba nakonfigurovať.", + "The download stopped progressing; cancelling this attempt.": "Sťahovanie zastavilo postup, zrušilo tento pokus.", + "The downloaded image does not match its manifest": "Stiahnutý obrázok nezodpovedá jeho manifestu", + "The downloaded image is corrupt:": "Stiahnutý obrázok je poškodený:", "The dpkg package database is clean.": "Databáza balíkov dpkg je čistá.", "The driver installed but does not drive this GPU.": "Ovládač nainštalovaný, ale nepoháňa tento GPU.", + "The dynamic NVIDIA hook is missing": "Dynamický NVIDIA hák chýba", + "The dynamic NVIDIA hook is missing or duplicated": "Dynamický NVIDIA hák chýba alebo sa zdvojí", + "The dynamic NVIDIA profile requires an unprivileged LXC": "Dynamický profil NVIDIA requires a unprivileged LXC", + "The dynamic profile does not support static driver mounts": "Dynamický profil nepodporuje statické zapojenia vodiča", "The file does not exist, is empty or is not readable.": "Súbor neexistuje, je prázdny alebo sa nedá čítať.", + "The file does not exist:": "Súbor neexistuje:", + "The file is too large to be a Compose file": "Súbor je príliš veľký na to, aby bol súbor skladať", "The filesystem": "Súborový systém", + "The final cleanup did not complete:": "Konečné vyčistenie nedokončilo:", "The following DKMS-managed drivers will now be rebuilt against it so they keep working after reboot:": "Nasledujúce ovládače spravované cez DKMS sa teraz znovu zostavia pre nový kernel, aby fungovali aj po reštarte:", "The following LXC containers have NVIDIA passthrough configured:": "Tieto LXC kontajnery majú nastavený NVIDIA passthrough:", "The following backup paths are kernel-tied and are excluded from the picker to keep the target's boot safe. The operator's own tuning inside these paths (IOMMU cmdline, VFIO IDs, custom quirks) is merged back automatically via kernel-agnostic merge:": "Nasledujúce cesty zálohy sú viazané na kernel a sú vylúčené z výberu, aby zostal štart cieľa bezpečný. Vlastné ladenie správcu v týchto cestách (IOMMU cmdline, VFIO ID, vlastné úpravy) sa automaticky znovu zlúči spôsobom nezávislým od kernelu:", @@ -4390,17 +5879,99 @@ "The following selected device(s) are Physical Functions with active Virtual Functions:": "Tieto vybrané zariadenia sú Physical Functions s aktívnymi Virtual Functions:", "The following selected device(s) are SR-IOV Virtual Functions (VFs):": "Tieto vybrané zariadenia sú SR-IOV Virtual Functions (VF):", "The fstab entry will still be removed; reboot or manual umount needed.": "Záznam vo fstab sa aj tak odstráni; bude potrebný reštart alebo ručné odpojenie.", + "The gateway must be another usable address in the same subnet.": "Vstupnou bránou musí byť ďalšia použiteľná adresa v tej istej podsiete.", "The gateway should appear in your Tailscale admin console shortly.": "Brána by sa čoskoro mala objaviť v Tailscale administrácii.", + "The healthcheck cannot run without an IP address": "Kontrola zdravotného stavu nemôže prebiehať bez IP adresy", + "The host NVIDIA driver is not responding correctly": "Hostiteľ ovládač NVIDIA nereaguje správne", + "The host bind source does not exist:": "Zdroj hostiteľskej väzby neexistuje:", + "The host bind source is not a regular file or directory:": "Zdroj odkazu hostiteľa nie je bežný súbor alebo adresár:", + "The host directory changed before it was mounted": "Adresár hostiteľa sa zmenil predtým, ako bol pripojený", "The host directory may not be accessible from an unprivileged container.": "Priečinok na hostovi nemusí byť dostupný z neprivilegovaného kontajnera.", + "The host has no IPv4 address on the selected bridge": "Hostiteľ nemá IPv4 adresu na vybranom moste", + "The host monitor does not see the real host memory": "Monitor hostiteľa nevidí skutočnú pamäť hostiteľa", + "The host monitor does not share this host namespace:": "Monitor hostiteľa nezdieľa tento menový priestor hostiteľa:", + "The host monitor needs consent for privileged access to the host": "Hostiteľský monitor potrebuje súhlas na privilegovaný prístup k hostiteľovi", + "The host monitor profile does not support another sysctl include": "Profil monitora hostiteľa nepodporuje ďalšie sysctl patrí", + "The host monitor uses the host network, without DHCP or its own gateway": "Hostiteľský monitor využíva hostiteľskú sieť bez DHCP alebo vlastnej brány", + "The host port is already in use:": "Hostiteľský port sa už používa:", + "The identity of a member was replaced": "Identita člena bola nahradená", + "The image changes the user expected by the adapter": "Obrázok mení používateľa očakávaný adaptérom", + "The image could not be read from its registry:": "Obrázok sa nepodarilo prečítať z jeho registra:", + "The image declares data paths that are still stored in the rootfs": "Obrázok deklaruje dátové cesty, ktoré sú stále uložené v rootfs", + "The image did not grant the application user access to the devices; check its native init. Host permissions were not relaxed.": "Obrázok neumožňoval používateľovi aplikácie prístup k zariadeniam; skontrolujte jeho rodený init. Povolenie hostiteľa nebolo uvoľnené.", + "The image did not pass the integrity check": "Obrázok neprešiel kontrolou integrity", + "The image does not declare support for this architecture:": "Obraz nevyhlasuje podporu tejto architektúry:", + "The image download did not complete correctly; downloading it again...": "Sťahovanie obrázku nebolo správne dokončené; sťahovanie...", + "The image expects files that are given to it one by one:": "Obrázok očakáva súbory, ktoré sú mu dané jeden po druhom:", + "The image is already up to date; nothing was changed.": "Obraz je už aktuálny, nič sa nezmenilo.", + "The image is in its registry, for one architecture.": "Obraz je vo svojom registri, pre jednu architektúru.", + "The image is in its registry.": "Obrázok je v jeho registri.", + "The image is in its registry:": "Obrázok je vo svojom registri:", + "The image requests NVIDIA, but the host has no working NVIDIA driver": "Obrázok požaduje NVIDIA, ale hostiteľ nemá žiadny funkčný ovládač NVIDIA", + "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk.": "Obraz si vyžaduje vypnutie časti AppArmor alebo seccomp väzenia. Pokračujte len vtedy, ak dôverujete obrazu a prijmete toto riziko.", + "The image requests disabling part of the AppArmor or seccomp confinement. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "Obraz si vyžaduje vypnutie časti AppArmor alebo seccomp väzenia. Skladba ponúka voliteľnú AppArmor alebo seccomp relaxáciu; zostane vypnutá, ak si ju užívateľ nevyberie. Pokračujte len vtedy, ak dôverujete obrazu a prijmete toto riziko.", + "The image was not found in its registry, or it is private:": "Obrázok nebol nájdený v jeho registri, alebo je súkromný:", + "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged.": "Dovážané kompozície žiadosti privilegované, ale oficiálna jlesage/handbrake dokumentácia nie je require to; ProxMenux udržuje LXC neprivilegované.", + "The imported OCI groups are not numeric": "Dovezené skupiny OCI nie sú číselné", + "The imported OCI user or group is not numeric": "Dovážaný užívateľ alebo skupina OCI nie je numerická", + "The initial user name and password stay written in /etc/pve/lxc/.conf as INIT_USERNAME and INIT_PASSWORD. They can be removed after the first login, with the container stopped.": "Počiatočné užívateľské meno a heslo zostávajú zapísané v /etc/pve/lxc/.conf ako INIT USERNAME a INIT PASSWORD. Môžu byť odstránené po prvom prihlásení, pričom kontajner sa zastaví.", + "The installation asks which one to use for these paths.": "Inštalácia žiada, ktorý z nich sa má použiť pre tieto cesty.", + "The installation ended with exit code": "Inštalácia skončila kódom výstupu", "The installation requires a server restart to apply changes. Do you want to restart now?": "Na použitie zmien je po inštalácii potrebný reštart servera. Chcete reštartovať teraz?", + "The installation runs on the Proxmox node itself, as root": "Inštalácia beží na Proxmox uzol sám, ako koreň", + "The installation stopped because of an unexpected error": "Inštalácia zastavená kvôli neočakávanej chybe", "The installation/changes require a server restart to apply correctly. Do you want to reboot now?": "Aby sa inštalácia alebo zmeny správne použili, server treba reštartovať. Chcete reštartovať teraz?", + "The installer must run as root on Proxmox VE": "Inštalatér musí spustiť ako koreň na Proxmox VE", + "The instance changed while it was being edited; configure Recreate again": "Inštancia sa zmenila počas editácie; znovu nakonfigurujte Recreate", + "The instance does not use NVIDIA": "Tento prípad nepoužíva NVIDIU", + "The instance has a pending operation": "Inštancia má prebiehajúci operation", + "The instance identity or status must be reviewed before updating.": "Pred aktualizáciou sa musí preskúmať totožnosť alebo status prípadu.", + "The instance is not ready to be updated": "Prípad nie je pripravený na aktualizáciu", + "The instance is not ready; review its pending operation": "Inštancia nie je pripravená; preskúma svoju očakávanú operation", + "The instance record operation did not complete; no container was modified.": "Záznam o inštancii operation sa nedokončil; žiadna nádoba nebola zmenená.", + "The instance registry is not safe": "Inštančný register nie je bezpečný", + "The journal belongs to another VMID": "Časopis patrí inému VMIDu.", + "The journal belongs to another stack": "Časopis patrí inému stohu", + "The journal has an incomplete recovery state": "Časopis má neúplný stav obnovy", + "The kernel module is not active:": "Modul jadra nie je aktívny:", "The kernel module of version": "Modul jadra verzie", "The local envelope is dropped and future backups do not upload anything. Uploaded envelopes already on PBS stay intact and remain recoverable with their original passphrase.": "Lokálna obálka sa zahodí a budúce zálohy už nič nenahrajú. Obálky, ktoré už sú v PBS, zostanú zachované a budú obnoviteľné pôvodnou frázou.", "The long test runs directly on the disk hardware.": "Dlhý test beží priamo na hardvéri disku.", + "The main member must stop first and start last": "Hlavný člen sa musí zastaviť prvý a začať posledný", + "The main member of the stack is missing": "Hlavný člen zásobníka chýba", + "The manifest does not match its digest": "Manifest nezodpovedá jeho tráveniu", + "The member journal belongs to another stack operation": "Členský časopis patrí do ďalšieho stohu operation", + "The member journal is outside the registry": "Členský časopis je mimo registra", + "The mount evidence does not match the verified directories": "Pripojiť dôkazy nezodpovedá overených adresárov", + "The mount source or options were not kept": "Zdroj alebo možnosti pripojenia neboli zachované", + "The mounted source differs from the configured directory": "Inštalovaný zdroj sa líši od nakonfigurovaného adresára", + "The mounts of the new container do not match the proposal": "Montáže nového kontajnera nezodpovedajú návrhu", + "The native GPU permissions were not kept": "Natívne povolenia GPU neboli ponechané", + "The native unprivileged idmap is required": "Natívne neprivilegované idmapa je required", "The new SSH key was installed and is now authorized on the server.\nKey file:": "Nový SSH kľúč bol nainštalovaný a je teraz povolený na serveri.\nSúbor kľúča:", "The new SSH key was pushed to the LXC via 'pct exec' on": "Nový SSH kľúč bol odoslaný do LXC cez 'pct exec' na", + "The new Valkey volume contains unexpected data": "Nový Valkey objem obsahuje neočakávané dáta", + "The new container did not pass validation": "Nová nádoba neprešla validáciou", + "The new container is not authorized by the operation journal": "Nový kontajner nie je povolený časopisom operation", + "The new image adds a symbolic link in a generated path": "Nový obrázok pridáva symbolické spojenie na generovanej ceste", + "The new image changes the PostgreSQL major version; the data must be migrated before updating": "Nový obrázok mení PostgreSQL hlavnú verziu; údaje musia byť premiestnené pred aktualizáciou", + "The new image could not be installed": "Nový obrázok nemohol byť nainštalovaný", + "The new image could not be installed:": "Nový obrázok sa nepodarilo nainštalovať:", + "The new image does not keep a required executable": "Nový obrázok neudržuje spustiteľný required", + "The new image requires additional persistent paths": "Nový obrázok requires ďalšie pretrvávajúce cesty", + "The new image requires additional persistent paths; use Recreate": "Nový obrázok requires ďalšie pretrvávajúce cesty; používať Recreate", "The new prompt will be used in new terminal sessions.": "Nový príkazový riadok sa použije v nových reláciách terminálu.", "The next visit to the dashboard will show the initial setup wizard.": "Pri ďalšom otvorení dashboardu sa zobrazí úvodný sprievodca nastavením.", + "The observed inventory differs from the validated runtime": "Pozorovaný inventár sa líši od overeného času", + "The official Tandoor startup executable is missing": "Oficiálny spúšťač Tandoor chýba", + "The official inventory contains no NVIDIA devices": "Oficiálny inventár neobsahuje žiadne zariadenia NVIDIA", + "The official inventory contains no NVIDIA driver components": "Oficiálny inventár neobsahuje žiadne komponenty ovládača NVIDIA", + "The official startup cannot be reproduced": "Oficiálny štart nie je možné reprodukovať", + "The official startup of the application is missing": "Chýba oficiálny začiatok aplikácie", + "The operation already finished; it is not restored automatically": "operation už skončil; nie je automaticky obnovená", + "The operation could not be completed": "operation nebolo možné dokončiť", + "The operation stopped halfway. Choose \"Recover\" for this container in the OCI management menu to restore the previous installation.": "operation zastavil v polovici cesty. Vyberte \"Recover\" pre tento kontajner v menu správy OCI pre obnovenie predchádzajúcej inštalácie.", + "The operation was stopped because a shared directory changed its identity:": "operation bol zastavený, pretože zdieľaný adresár zmenil svoju identitu:", "The original MOTD backup is unavailable; no changes were made": "Pôvodná záloha MOTD nie je k dispozícii;neboli vykonané žiadne zmeny", "The original MOTD configuration has been restored": "Pôvodná konfigurácia MOTD bola obnovená", "The original MOTD state is unavailable; no changes were made": "Pôvodný stav MOTD nie je k dispozícii;neboli vykonané žiadne zmeny", @@ -4408,18 +5979,76 @@ "The original rpcbind state could not be restored completely": "Pôvodný stav rpcbind nebolo možné úplne obnoviť", "The original rpcbind state is unavailable; no service state was changed": "Pôvodný stav rpcbind nie je k dispozícii;žiadny servisný stav sa nezmenil", "The package is currently in a broken state and is blocking apt updates on this system.": "Balík je momentálne v nefunkčnom stave a blokuje aktualizácie apt v tomto systéme.", + "The parent of an NVIDIA destination is not a directory": "Materská destinácia NVIDIA nie je adresár", + "The parent of the target is not a directory:": "Materský cieľ nie je adresár:", + "The password could not be retrieved automatically": "Heslo nebolo možné získať automaticky", "The passwords do not match. Please try again.": "Heslá sa nezhodujú. Skúste to znova.", + "The path escapes the rootfs:": "Cesta uniká koreňom:", + "The path must be absolute and normalized": "Cesta musí byť absolútna a normalizovaná", + "The path overlaps an existing mount": "Trasa sa prekrýva s existujúcou montážou", + "The persistent NVIDIA hook does not match the installer:": "Trvalý NVIDIA hák nezodpovedá inštalátorovi:", + "The persistent WebUI credentials were not found": "Trvalé WebUI credentials neboli nájdené", + "The physical NVIDIA selection changed": "Fyzický výber NVIDIA sa zmenil", + "The post-start configuration cannot be applied with the LXC stopped": "Konfigurácia po štarte sa nedá použiť s zastavením LXC.", + "The postgres user was not found in the image": "Užívateľ postgres nebol nájdený v obrázku", + "The prepared directory escapes the rootfs:": "Pripravený adresár unikne koreňom:", "The preselected VMID does not exist on this host:": "Predvybrané VMID na tomto hostovi neexistuje:", + "The previous native backup will be restored. Shared host directories are not reverted. Displaced disks are kept.": "Predchádzajúce domáce zálohy budú obnovené. Spoločné adresáre sa nevrátia. Zadržiavajú sa vypustené disky.", + "The previous stack contract is not safe; review it before reusing it": "Predchádzajúca stack zmluva nie je bezpečná; pred opätovným použitím ju preskúmajte", + "The previous stack contract is not valid; it is not archived automatically": "Predchádzajúca zmluva nie je platná; nie je automaticky archivovaná", + "The previous stack contract still has containers or VMs:": "Predchádzajúca stack zmluva má stále kontajnery alebo VM:", + "The private address is already assigned to another container:": "Súkromná adresa je už pridelená k inému kontajneru:", + "The private bridge does not have the expected address:": "Súkromný most nemá očakávanú adresu:", + "The private journal has an unsafe owner or permissions": "Súkromný časopis má nebezpečného majiteľa alebo povolenia", + "The private network allocator was not found": "Private Network alocator nebol nájdený", + "The private network is still used by another container and is kept:": "Súkromná sieť sa stále používa v inej nádobe a udržiava sa:", + "The private network must be assigned automatically": "Súkromná sieť musí byť automaticky pridelená", + "The privileged deployment does not include the required explicit consent": "Privilegované nasadenie nezahŕňa required výslovný súhlas", + "The prlimit soft value exceeds the hard value": "Prlimit soft hodnota presahuje tvrdú hodnotu", + "The proposal changes the identity of the instance": "Návrh mení totožnosť inštancie", "The proposed ARC maximum is below Proxmox VE's pool-size guideline:": "Navrhované maximum ARC je nižšie ako smernica Proxmox VE pre veľkosť bazéna:", + "The published views must be inside the common root": "Publikované názory musia byť vo vnútri spoločného koreňa", + "The read-only view does not apply the expected protection": "Pohľad len na čítanie neuplatňuje očakávanú ochranu", + "The read-only view was not published": "Zobrazenie nebolo zverejnené", + "The read/write view was not published": "Pohľad na čítanie/ zápis nebol zverejnený", + "The recipe requires configuration at startup; its coordinated replay is not available": "Recept requires konfigurácie pri štarte; jeho koordinovaný opakovaný záznam nie je k dispozícii", + "The record belongs to another container": "Záznam patrí do inej nádoby", + "The record does not belong to this operation": "Záznam nepatrí k tomuto operation", + "The record no longer belongs to this operation": "Záznam už nepatrí k tomuto operation", + "The record of a member was replaced; the assembly is not resumed": "Záznam o členovi bol nahradený; zhromaždenie sa neobnovuje", + "The record or diagnosis could not be completed; no update was run.": "Záznam alebo diagnóza nemohla byť dokončená; žiadna aktualizácia nebola spustená.", + "The recovery did not complete. Review the log and choose \"Recover\" again for this container in the OCI management menu.": "Uzdravenie sa nedokončilo. Skontrolujte log a vyberte \"Recover\" znovu pre tento kontajner v menu OCI management.", + "The remote does not exist; create and authorize it first in the WebUI:": "Vzdialenosť neexistuje; vytvoriť a schváliť ju ako prvý na WebUI:", + "The remote installer must run as root on Proxmox VE": "Diaľkový inštalátor musí bežať ako koreň na Proxmox VE", + "The remote must already be created and authorized in the Rclone web UI. This operation restarts the CT and publishes two FUSE views on the host.": "Vzdialený musí byť už vytvorený a schválený v Rclone web UI. Tento operation reštartuje CT a zverejňuje dva pohľady FUSE na hostiteľa.", + "The remote path must be relative and cannot contain line breaks": "Diaľková dráha musí byť relatívna a nesmie obsahovať prestávky na priamke", + "The removal could not be prepared:": "Odstránenie nebolo možné pripraviť:", + "The repair must preserve the image dependencies:": "Oprava musí zachovať závislosť obrazu:", + "The requested VMID block is already in use": "Požadovaný blok VMID sa už používa", + "The requested machine learning GPU profile is not working; it is not replaced by CPU": "Požadovaný profil strojového učenia sa GPU nefunguje; nie je nahradený CPU", + "The restored service did not pass its health check": "Obnovená služba neprešla kontrolou stavu", + "The restored service stopped; the recovery is not confirmed": "Obnovená služba sa zastavila; obnova sa nepotvrdila", + "The reviewed Tandoor stack does not require a privileged LXC.": "Preskúmaný Tandoor stack require privilegovaný LXC.", + "The rootfs capture only belongs to the running installation": "Rootfs capture patrí len do bežiacej inštalácie", + "The rootfs is not managed by Proxmox": "Rootfs nie je riadený Proxmox", + "The rootfs is not mounted": "Korene nie sú namontované", "The same GPU cannot be used by two VMs at the same time.": "Rovnakú GPU nemôžu používať dve VM naraz.", + "The same connection can be given as container variables instead of the file: UN_SONARR_0_URL and UN_SONARR_0_API_KEY, or the UN_RADARR_0_ equivalents.": "Rovnaké spojenie možno uviesť ako kontajnerové premenné namiesto súboru: UN SONARR 0 URL a UN SONARR 0 API KEY, alebo UN RADARR 0 equivalents.", "The saved MOTD state is invalid; no changes were made": "Uložený stav MOTD je neplatný;neboli vykonané žiadne zmeny", + "The saved OCI record is incomplete or has an unexpected format.": "Uložený záznam OCI je neúplný alebo má neočakávaný formát.", + "The saved projection does not match the native evidence": "Uložená projekcia nezodpovedá natívnemu dôkazu", + "The saved record was replaced for": "Uložené záznamy boli nahradené pre", "The saved utility package list is invalid; no packages were removed": "Uložený zoznam balíkov nástrojov je neplatný;neboli odstránené žiadne balíky", "The script clones the osx-proxmox.com repository and once the setup is complete, the server will automatically reboot.": "Skript naklonuje repozitár osx-proxmox.com a po dokončení nastavenia sa server automaticky reštartuje.", "The script will continue to restore VM passthrough mode on the host and reuse existing hostpci entries.": "Skript bude pokračovať obnovením VM passthrough režimu na hostovi a znovu použije existujúce hostpci položky.", "The script will preconfigure the selected GPU now and finalize hardware binding after reboot.": "Skript teraz prednastaví vybranú GPU a po reštarte dokončí hardvérové naviazanie.", "The selected AMD GPU does not report FLR reset support": "Vybraná AMD GPU nehlási podporu FLR resetu", "The selected AMD GPU is currently in power state D3cold": "Vybraná AMD GPU je aktuálne v napájacom stave D3cold", + "The selected CT does not match its OCI record. Its configuration will not be modified or deleted.": "Vybrané CT nezodpovedá jeho záznamu OCI. Jeho konfigurácia nebude zmenená ani vymazaná.", + "The selected GPU changed": "Zmenený vybraný GPU", "The selected GPU configuration already exists in this container.": "Vybrané nastavenie GPU už v tomto kontajneri existuje.", + "The selected GPU device does not exist:": "Vybrané GPU zariadenie neexistuje:", + "The selected GPU directory does not exist:": "Vybraný adresár GPU neexistuje:", "The selected GPU has no dedicated .1 audio sibling function.": "Vybraná GPU nemá samostatnú .1 audio sesterskú funkciu.", "The selected GPU is already assigned to another VM that is currently running:": "Vybraná GPU je už priradená inej VM, ktorá práve beží:", "The selected GPU is already assigned to this VM, but the host is not currently using vfio-pci for this device.": "Vybraná GPU je už priradená tejto VM, ale host pre toto zariadenie momentálne nepoužíva vfio-pci.", @@ -4435,11 +6064,15 @@ "The selected Intel GPU does not expose a PCI reset interface": "Vybraná Intel GPU neposkytuje PCI reset rozhranie", "The selected Intel GPU has non-FLR reset support and unknown subtype": "Vybraná Intel GPU má reset podporu mimo FLR a neznámy podtyp", "The selected Intel GPU is currently in power state D3cold": "Vybraná Intel GPU je aktuálne v napájacom stave D3cold", + "The selected Intel render device does not exist:": "Vybrané zariadenie Intel render neexistuje:", "The selected VM": "Vybraná VM", "The selected VM is running.": "Vybraná VM beží.", "The selected base folder does not exist and could not be created:": "Vybraný základný priečinok neexistuje a nepodarilo sa ho vytvoriť:", + "The selected configuration needs to start the LXC during the installation": "Vybraná konfigurácia musí spustiť LXC počas inštalácie", "The selected container is unprivileged. A privileged container is required for direct device passthrough.": "Vybraný kontajner je neprivilegovaný. Na priame priradenie zariadenia je potrebný privilegovaný kontajner.", "The selected device": "Vybrané zariadenie", + "The selected device is not a block device": "Vybrané zariadenie nie je blokovacie zariadenie", + "The selected device is not a character device": "Vybrané zariadenie nie je charakterové zariadenie", "The selected directory does not exist:": "Vybraný priečinok neexistuje:", "The selected disk has an active swap partition. Aborting.": "Vybraný disk má aktívny swap oddiel. Akcia sa ruší.", "The selected disk is currently used by a RUNNING VM or CT. Stop it before formatting.": "Vybraný disk práve používa BEŽIACA VM alebo CT. Pred formátovaním ju zastavte.", @@ -4447,25 +6080,76 @@ "The selected disk now contains a system-critical mount. Aborting.": "Vybraný disk teraz obsahuje systémovo kritické pripojenie. Akcia sa ruší.", "The selected path does not exist on this host:": "Vybraná cesta na tomto hostovi neexistuje:", "The selected path is not a valid directory:": "Vybraná cesta nie je platný priečinok:", + "The selected render device does not exist:": "Vybrané vykresľovacie zariadenie neexistuje:", "The server connected you as guest instead of the specified user.": "Server vás pripojil ako hosťa namiesto zadaného používateľa.", "The server may not have accessible shares.": "Server možno nemá dostupné zdieľania.", "The server may require authentication for actual share access.": "Server môže vyžadovať prihlásenie pre samotný prístup k zdieľaniu.", "The server refused password authentication for": "Server odmietol prihlásenie heslom pre", "The server rejected": "Server odmietol", + "The service builds its own image; only a published image can be installed": "Služba buduje svoj vlastný obraz; môže byť nainštalovaný iba zverejnený obrázok", + "The service declares no image:": "Služba neprehlasuje žiadny obrázok:", + "The setting has no final value:": "Nastavenie nemá žiadnu konečnú hodnotu:", "The share already exists in smb.conf:": "Zdieľanie už existuje v smb.conf:", + "The shared destination is not a directory": "Zdieľaná destinácia nie je adresár", + "The shared directory points to a protected host path": "Zdieľaný adresár ukazuje na chránenú cestu hostiteľa", + "The shared path exists but is not a directory:": "Spoločná cesta existuje, ale nie je adresárom:", + "The size of existing disks is not rounded": "Veľkosť existujúcich diskov nie je zaokrúhlená", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk.": "Zdroj tvoria požiadavky privilegované: pravda, ale to nedokazuje, že obraz potrebuje privilegovaný LXC. ProxMenux štandardne použije neprivilegovaný LXC a ponúkne široký režim len ako možnosť. Pokračujte len vtedy, ak dôverujete obrazu a prijmete toto riziko.", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. The Docker rootlesskit profile does not exist in LXC and will be replaced by AppArmor unconfined, which is less restrictive. Continue only if you trust the image and accept this risk.": "Zdroj tvoria požiadavky privilegované: pravda, ale to nedokazuje, že obraz potrebuje privilegovaný LXC. ProxMenux štandardne použije neprivilegovaný LXC a ponúkne široký režim len ako možnosť. Skladba ponúka voliteľnú AppArmor alebo seccomp relaxáciu; zostane vypnutá, ak si ju užívateľ nevyberie. Profil Docker rootlesskit neexistuje v LXC a nahradí ho AppArmor unconfined, čo je menej obmedzujúce. Pokračujte len vtedy, ak dôverujete obrazu a prijmete toto riziko.", "The source VM also has these audio devices, likely added together with the GPU. Remove them too?": "Zdrojová VM má aj tieto audio zariadenia, pravdepodobne pridané spolu s GPU. Odstrániť aj tie?", "The specified directory does not exist:": "Zadaný priečinok neexistuje:", + "The stability period must be shorter than the healthcheck timeout": "Obdobie stability musí byť kratšie ako časový limit pre kontrolu zdravotného stavu.", + "The stack contains devices or directives without a translation": "Stock obsahuje zariadenia alebo smernice bez prekladu", + "The stack does not have the expected native hook": "Stack nemá očakávaný materinský hák", + "The stack journal is outside the registry": "Denník je mimo registra.", + "The stack member has no declared adaptation profile": "Stack člen nemá deklarovaný adaptačný profil", + "The stack name only accepts lowercase letters, numbers and hyphens": "Názov stohu prijíma len malé písmená, čísla a pomlčky", + "The stack needs member adaptations or a verification of missing volumes": "Stack potrebuje členské úpravy alebo overenie chýbajúcich objemov", + "The stack operation had already finished": "Stack operation už skončil", + "The stack operation has not finished yet": "Stack operation ešte neskončil", + "The stack operation stopped halfway. Select the stack again in the OCI management menu to recover it.": "Stack operation zastavil v polovici cesty. Vyberte zásobník znova v menu OCI pre správu obnoviť.", + "The stack registry is incomplete; review the private contracts.": "Register stoh je neúplný; preskúma súkromné zmluvy.", + "The stack startup hook was not found": "Stack startup hák nebol nájdený", + "The stack update was saved.": "Aktualizácia stohu bola uložená.", + "The startup differs from the declared Nextcloud adapter": "Spustenie sa líši od deklarovaného Nextcloud adaptéra", + "The startup differs from the declared adapter": "Spustenie sa líši od deklarovaného adaptéra", + "The staticfiles volume needs at least 1 GB": "Objem statických súborov potrebuje aspoň 1 GB", "The storage has been removed and the disk unmounted.": "Úložisko bolo odstránené a disk odpojený.", + "The sysctl content was modified outside the saved record": "Obsah sysctl bol upravený mimo uloženého záznamu", + "The sysctl include is a link:": "Sysctl patrí je odkaz:", + "The sysctl include is not a safe host file": "Sysctl patrí nie je bezpečný hostiteľský súbor", + "The sysctl include is not restored over a symbolic link": "Sysctl patrí nie je obnovený cez symbolické spojenie", + "The sysctl include is unknown or differs from the saved record": "Sysctl patrí nie je známe alebo sa líši od uloženého záznamu", + "The temporary password could not be retrieved.": "Dočasné heslo nebolo možné získať späť.", "The test will continue even if you close this terminal.": "Test bude pokračovať aj po zatvorení tohto terminálu.", + "The tmpfs mounts of the container differ from the saved record": "Tmpfs držiaky kontajnera sa líšia od uloženého záznamu", + "The tmpfs path or size is outside the supported profile": "Tmpfs cesta alebo veľkosť je mimo podporovaný profil", + "The translated recipe changed during the preparation": "Preložený recept sa počas prípravy zmenil", + "The value contains an unsupported character": "Hodnota obsahuje nepodporovaný znak", + "The values do not match. Enter them again.": "Hodnoty sa nezhodujú. Zadajte ich znova.", + "The variable contains control characters:": "Premenná obsahuje kontrolné znaky:", + "The variable contains line breaks:": "Premenná obsahuje prestávky na riadku:", "The vfio.conf entries have been removed and initramfs rebuilt.": "Položky vfio.conf boli odstránené a initramfs prebudované.", + "The web UI password must have at least 24 characters": "Webové UI heslo musí mať aspoň 24 znakov", + "The web UI user contains characters that are not allowed": "Webový užívateľ UI obsahuje znaky, ktoré nie sú povolené", + "The web interface is served over plain HTTP on port 51821 (INSECURE=true). Keep it inside the local network or publish it through a reverse proxy with TLS.": "Webové rozhranie sa podáva cez obyčajný HTTP na porte 51821 (INSECURE=true). Držte ho v miestnej sieti alebo ho publikujte prostredníctvom reverzného proxy s TLS.", + "The web interface uses a self-signed certificate, so the browser shows a warning the first time.": "Webové rozhranie používa samopodpísaný certifikát, takže prehliadač prvýkrát zobrazí varovanie.", + "The wizard writes a .conf file in /config. Restart the container afterwards so the bot starts with that configuration.": "Čarodejník píše súbor .conf v /config. Potom znovu spustite kontajner, takže robot začne s touto konfiguráciou.", + "The world's fastest framework for building websites": "Najrýchlejší rámec na svete pre vytváranie webových stránok", + "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server.": "Thelounge (fork screamIRC) je webový IRC klient, ktorý hosťujete na svojom vlastnom serveri.", "Then bind-mount to container": "Potom pripojiť do kontajnera cez bind mount", "Then change the VM display to none (vga: none) when the guest is stable.": "Keď bude VM stabilná, zmeňte jej display na none (vga: none).", "Then change the VM display to none (vga: none) when the system is stable.": "Keď bude systém stabilný, zmeňte display VM na none (vga: none).", "Then run this option again:": "Potom túto možnosť spustite znova:", "Then update /etc/fstab on the host with the same options.": "Potom aktualizujte /etc/fstab na hoste s rovnakými možnosťami.", + "There are extra disks or bind mounts outside the journal; the rootfs is not replaced": "Tam sú ďalšie disky alebo pripojiť mimo denníka; rootfs nie je nahradený", + "There is no temporary container of this operation to keep the current disks": "Neexistuje žiadny dočasný kontajner tohto operation udržať aktuálne disky", + "There is no verified backup; a modified container is not touched": "Neexistuje žiadna overená záloha; modifikovaný kontajner sa nedotýka", + "These VMIDs are not free:": "Tieto VMID nie sú zadarmo:", "These are the changes that will be made": "Tieto zmeny sa vykonajú", "These interface configurations will be removed": "Tieto nastavenia rozhraní sa odstránia", "These paths will not be restored live and will be extracted for manual recovery.": "Tieto cesty sa neobnovia za behu a rozbalia sa na ručnú obnovu.", + "These values are asked during the installation:": "Tieto hodnoty sa požadujú počas inštalácie:", "This CIFS share is mounted with restrictive permissions.": "Toto CIFS zdieľanie je pripojené s obmedzujúcimi oprávneniami.", "This GPU is considered incompatible with GPU passthrough to a VM in ProxMenux.": "Táto GPU sa v ProxMenux považuje za nekompatibilnú s GPU passthrough do VM.", "This NFS share is fully restricted — even the host root cannot write to it.": "Toto NFS zdieľanie je úplne obmedzené - ani root na hostovi doň nevie zapisovať.", @@ -4477,6 +6161,8 @@ "This backup is encrypted.": "Táto záloha je šifrovaná.", "This backup was taken on kernel": "Táto záloha bola vytvorená na kerneli", "This cleanup will:": "Toto čistenie:", + "This container belongs to a stack; publish the whole stack": "Tento kontajner patrí do stohu; publikovať celý zásobník", + "This container belongs to a stack; recover the whole stack": "Tento kontajner patrí do stohu; obnoviť celý zásobník", "This container does not have apt-get. NFS client installation only supports Debian/Ubuntu containers.": "Tento kontajner nemá apt-get. Inštalácia NFS klienta je podporovaná iba v Debian/Ubuntu kontajneroch.", "This container does not have apt-get. Samba client installation only supports Debian/Ubuntu containers.": "Tento kontajner nemá apt-get. Inštalácia Samba klienta je podporovaná iba v Debian/Ubuntu kontajneroch.", "This container has no GPU configured. Coral TPU works best alongside hardware video decoding (Quick Sync, VA-API, NVENC) for apps like Frigate.": "Tento kontajner nemá nastavenú GPU. Coral TPU funguje najlepšie spolu s hardvérovým dekódovaním videa (Quick Sync, VA-API, NVENC) v aplikáciách ako Frigate.", @@ -4486,15 +6172,21 @@ "This erases existing metadata.": "Týmto sa vymažú existujúce metadáta.", "This explicitly marks the container as privileged": "Týmto sa kontajner výslovne označí ako privilegovaný", "This guarantees that device nodes are available before applying LXC GPU config.": "Tým sa zabezpečí, že device nodes budú dostupné ešte pred použitím GPU nastavenia pre LXC.", + "This image cannot be installed as it is described:": "Tento obrázok nie je možné nainštalovať, ako je popísané:", + "This image requires the host module": "Tento obrázok requires hostiteľský modul", "This installation will:": "Táto inštalácia urobí toto:", "This installer will:": "Tento inštalátor urobí toto:", "This interface is configured but doesn't exist physically": "Toto rozhranie je nastavené, ale fyzicky neexistuje", + "This interface runs on the Proxmox node as root. Open proxmenux-oci.sh on the Proxmox host.": "Toto rozhranie beží na uzle Proxmox ako koreň. Otvorte proxmenux-oci.sh na hostiteľovi Proxmox.", "This is IRREVERSIBLE.": "Toto je NEVRATNÉ.", "This is a destructive action": "Toto je deštruktívna akcia", "This is a simple configuration change": "Ide o jednoduchú zmenu nastavenia", "This is an external community script maintained by": "Toto je externý komunitný skript, ktorý spravuje", "This is an external script that creates a macOS VM in Proxmox VE in just a few steps, whether you are using AMD or Intel hardware.": "Toto je externý skript, ktorý v Proxmox VE vytvorí VM s macOS v niekoľkých krokoch. Funguje na AMD aj Intel hardvéri.", + "This is not a coordinated stack": "Toto nie je koordinovaný stack", + "This is not a valid image reference:": "Toto nie je platný odkaz na obrázok:", "This is unexpected since credentials were validated.": "Toto je nečakané, pretože prihlasovacie údaje už boli overené.", + "This is what ProxMenux understood from the": "To je to, čo ProxMenux pochopil z", "This marks the container as unprivileged": "Týmto sa kontajner označí ako neprivilegovaný", "This may be normal for a fresh installation": "Pri čerstvej inštalácii to môže byť normálne", "This may take a few minutes. Press OK to proceed.": "Môže to trvať niekoľko minút. Pokračujte stlačením OK.", @@ -4503,12 +6195,14 @@ "This means Proxmox handles mount lifecycle natively (no manual /etc/fstab needed for NFS/CIFS host storages).": "To znamená, že Proxmox sa o pripojenie stará priamo; pre NFS/CIFS úložiská na hostovi netreba ručne upravovať /etc/fstab.", "This means the credentials are incorrect.": "To znamená, že prihlasovacie údaje nie sú správne.", "This might indicate network connectivity issues.": "Môže to znamenať problém so sieťovým pripojením.", + "This monitor uses a privileged LXC, shares processes and network with Proxmox and disables AppArmor in the CT. It uses the IP address and firewall of the host. A compromised image could affect the host; do not expose its web UI to the Internet.": "Tento monitor používa privilegovaný LXC, zdieľa procesy a sieť s Proxmox a vypne AppArmor v CT. Používa IP adresu a firewall hostiteľa. Kompromitovaný obraz by mohol mať vplyv na hostiteľa; nevystavujte svoje webové UI internetu.", "This operation may take several minutes and requires internet connectivity.": "Táto operácia môže trvať niekoľko minút a vyžaduje pripojenie na internet.", "This package was installed by older versions of the ProxMenux Coral installer that placed the M.2 kernel driver on every system, including USB-only setups. It is not needed for Coral USB devices, which use libedgetpu1-std / libedgetpu1-max only.": "Tento balík bol nainštalovaný staršími verziami inštalačného programu ProxMenux Coral, ktorý umiestnil ovládač jadra M.2 na každý systém, vrátane nastavení iba cez USB.Nie je potrebný pre zariadenia Coral USB, ktoré používajú iba libedgetpu1-std / libedgetpu1-max.", "This passphrase is the ONLY way to access encrypted Borg backups.": "Táto fráza je JEDINÝ spôsob, ako sa dostať k šifrovaným Borg zálohám.", "This path is already used as a mount point in this container.": "Táto cesta už je v tomto kontajneri použitá ako mount point.", "This path is not a registered mount point. Use it anyway?": "Táto cesta nie je registrovaný mount point. Použiť ju aj tak?", "This process changes file ownership inside the container": "Tento proces mení vlastníctvo súborov vo vnútri kontajnera", + "This profile only supports directory bind mounts": "Tento profil podporuje iba pripojenie priečinkov", "This release channel is already active.": "Táto vetva vydania je už aktívna.", "This removes the 'unprivileged: 1' line from the config": "Týmto sa z nastavenia odstráni riadok 'unprivileged: 1'", "This removes the storage from Proxmox. The iSCSI target is not affected.": "Týmto sa úložisko odstráni z Proxmoxu. iSCSI target sa nezmení.", @@ -4522,10 +6216,15 @@ "This session is running in the Monitor terminal. Running it from here would cut the connection mid-install and leave the switch in a broken state.": "Táto relácia beží v termináli Monitora. Ak by sa to spustilo odtiaľto, pripojenie sa počas inštalácie preruší a prepnutie môže zostať v zlom stave.", "This session is running in the Monitor terminal. Updating from here would restart the Monitor service and cut the connection mid-install, leaving the update in a broken state.": "Táto relácia beží v termináli Monitor. Aktualizácia odtiaľto by reštartovala službu Monitor a prerušila spojenie uprostred inštalácie, čo by mohlo nechať aktualizáciu v poškodenom stave.", "This shows the storage type and disk identifier": "Týmto sa zobrazí typ úložiska a identifikátor disku", + "This stack requires replaying specific rootfs adaptations. Coordinated updates are not yet enabled for it.": "Tento zásobník requires prehráva špecifické korektúry. Koordinované aktualizácie pre ňu zatiaľ nie sú povolené.", "This state has a high probability of VM startup/reset failures.": "Tento stav má vysokú pravdepodobnosť zlyhania štartu alebo resetu VM.", "This state indicates a high risk of passthrough failure due to": "Tento stav znamená vysoké riziko zlyhania passthrough pre", + "This template requests the host PID namespace, which has no validated safe LXC translation yet": "Táto šablóna vyžaduje PID formát hostiteľa, ktorý zatiaľ nemá overený bezpečný LXC preklad", "This tool is designed for systems with AMD GPUs.": "Tento nástroj je určený pre systémy s AMD GPU.", "This tool is designed for systems with Intel GPUs.": "Tento nástroj je určený pre systémy s Intel GPU.", + "This translator only supports the Nextcloud stack": "Tento prekladateľ podporuje iba Nextcloud stack", + "This value is required.": "Táto hodnota je required.", + "This variant requires the device": "Tento variant requires zariadenie", "This version does not build against the running kernel.": "Táto verzia nie je postavená proti bežiacemu jadru.", "This will RESET the ProxMenux Monitor login credentials on this host:": "Týmto sa vynulujú prihlasovacie údaje do ProxMenux Monitora na tomto serveri:", "This will add the mount to /etc/fstab so it persists after reboot.": "Týmto sa pripojenie pridá do /etc/fstab, takže zostane aj po reštarte.", @@ -4547,13 +6246,17 @@ "This will restart the network service and may cause a brief disconnection. Continue?": "Reštartuje sa sieťová služba a môže dôjsť ku krátkemu odpojeniu. Pokračovať?", "This will take time. Answer prompts carefully - see notes below.": "Bude to chvíľu trvať. Na otázky odpovedajte opatrne - pozrite poznámky nižšie.", "This will upgrade this node to Proxmox VE 9 on Debian Trixie.": "Týmto sa tento uzol aktualizuje na Proxmox VE 9 na Debiane Trixie.", + "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client.": "Thunderbird je bezplatný a open-source personal information manager používaný predovšetkým ako e-mailový klient s kalendárom a kontaktnou knihou, rovnako ako RSS feed čítačka, chat klient, a novinky klient.", "Tick the paths to include in this backup. Press \"Add custom path\" to add a folder or file of your own to the list.": "Označte cesty, ktoré chcete zahrnúť do tejto zálohy. Stlačte \"Pridať vlastnú cestu\", ak chcete do zoznamu pridať vlastný priečinok alebo súbor.", "Tick the paths to remove (they will not be deleted from disk — only from this list):": "Označte cesty na odstránenie (z disku sa nevymažú - odstránia sa iba z tohto zoznamu):", + "Time is up; Home Assistant OS could not be confirmed as running": "Čas vypršal; Home Assistant OS nebolo možné potvrdiť ako bežiace", "Time settings configured - Timezone:": "Nastavenie času je dokončené - časové pásmo:", "Time synchronization reset to UTC": "Synchronizácia času bola resetovaná na UTC", + "Timezone": "Časové pásmo", "Tip: Also mount the VirtIO ISO for drivers and guest agent installer": "Tip: pripojte aj VirtIO ISO s ovládačmi a inštalátorom guest agenta", "Tip: You can install the QEMU Guest Agent inside the VM with:": "Tip: QEMU Guest Agent môžete vo VM nainštalovať pomocou:", "Tip: zfs set acltype=posixacl xattr=sa / enables full ACL support.": "Tip: zfs set acltype=posixacl xattr=sa / zapne plnú podporu ACL.", + "Tmpfs size in MiB for": "Veľkosť Tmpfs v MiB pre", "To allow LXC write access, change the NFS export on the server to include:": "Aby LXC mohol zapisovať, upravte NFS export na serveri tak, aby obsahoval:", "To apply it to the current shell now, run:": "Ak ho chcete použiť v aktuálnej relácii shellu, spustite:", "To assign VFs to VMs or LXCs, edit the configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Ak chcete priradiť VF do VM alebo LXC, upravte nastavenie ručne cez webové rozhranie Proxmoxu. Physical Function zostane naviazaná na natívny ovládač.", @@ -4568,6 +6271,7 @@ "To pass SR-IOV Virtual Functions to a container, edit the LXC configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "Ak chcete priradiť SR-IOV Virtual Functions do kontajnera, upravte nastavenie LXC ručne cez webové rozhranie Proxmoxu. Physical Function zostane naviazaná na natívny ovládač.", "To remove partial VM:": "Na odstránenie čiastočnej VM:", "To restore": "Na obnovu použite", + "To restore it on another host, keep this file (not included in the vzdump backup):": "Ak chcete obnoviť na inom hostiteľa, ponechajte tento súbor (nie je súčasťou zálohy vzdump):", "To revert changes:": "Ako vrátiť zmeny späť:", "To start the VM:": "Na spustenie VM:", "To stop:": "Zastavenie:", @@ -4579,12 +6283,17 @@ "To use this share from an LXC, bind-mount it via:": "Ak chcete toto zdieľanie používať z LXC, pripojte ho ako bind mount cez:", "Tool exit code:": "Návratový kód nástroja:", "Tool output:": "Výstup nástroja:", + "Tools": "Nástroje", "Top memory processes in CT": "Procesy s najväčšou spotrebou pamäte v CT", + "Top-level configs, secrets and other global options are not yet supported": "Najlepšie konfigy, tajomstvá a iné globálne možnosti zatiaľ nie sú podporované", + "Top-level volume options are not yet supported": "Najvyššie možnosti objemu zatiaľ nie sú podporované", "Total": "Spolu", "Total members:": "Počet členov:", "Total routes": "Počet trás", "Total size:": "Celková veľkosť:", + "Transaction log:": "Záznam transakcií:", "Translation files:": "Prekladové súbory:", + "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, µTP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more.": "Transmission je určený pre jednoduché, výkonné použitie. Transmission má funkcie, ktoré chcete od BitTorrent klienta: šifrovanie, webové rozhranie, peer exchange, magnet odkazy, DHT, μTP, UPnP a NAT-PMP port forwarding, podpora webových seedov, sledovať adresáre, tracker editovanie, globálne a per-torrent rýchlostné limity, a ďalšie.", "Tried pvesm path and manual detection methods": "Skúšal sa pvesm path aj ručné hľadanie", "Trust this certificate and save it for scheduled backups?": "Dôverovať tomuto certifikátu a uložiť ho pre naplánované zálohy?", "Try Again": "Skúsiť znova", @@ -4592,6 +6301,8 @@ "Try accessing": "Skúste otvoriť", "Try another archive": "Skúsiť iný archív", "Try automatic repair of detected issues": "Skúsiť automatickú opravu zistených problémov", + "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources.": "Tvheadend funguje ako proxy server: je televízny streamovací server a záznamník pre Linux, FreeBSD a Android podporujúci DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP a HDHomeRun ako vstupné zdroje.", + "Twingate Connector for self-hosted server": "Twingate Connector pre self-hosted server", "Two-factor authentication and backup codes will be removed.": "Dvojfaktorové overenie a záložné kódy sa odstránia.", "Type": "Typ", "Type the device path EXACTLY to confirm formatting:": "Na potvrdenie formátovania zadajte PRESNÚ cestu zariadenia:", @@ -4600,16 +6311,22 @@ "Type: attached to PVE storage": "Typ: pripojené k PVE úložisku", "Typed value does not match selected disk. Operation cancelled.": "Zadaná hodnota sa nezhoduje s vybraným diskom. Operácia bola zrušená.", "UID in CT": "UID v CT", + "UID of the plex user (also owner of the GPU device)": "UID používateľa plex (tiež majiteľ zariadenia GPU)", + "UID that Emby runs as": "UID, že Emby beží ako", "UPGRADE PROMPTS - RECOMMENDED ANSWERS:": "OTÁZKY PRI AKTUALIZÁCII - ODPORÚČANÉ ODPOVEDE:", + "UPS monitoring and power outage notification system": "Systém monitorovania UPS a oznamovania výpadku napájania", "USB Accelerators:": "USB akcelerátory:", + "USB bus directory": "Adresár USB zbernice", "USB disk target": "Cieľ na USB disku", "USB drives mounted now:": "Aktuálne pripojené USB disky:", "USB libedgetpu1": "USB libedgetpu1", "UUP Dump script not found.": "Skript UUP Dump sa nenašiel.", "UUp Dump ISO creator Custom": "Vlastný tvorca ISO cez UUP Dump", + "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer.": "Ubooquity je bezplatný, ľahký a ľahko použiteľný domáci server pre vaše komiksy a ebooky. Použite ho na prístup k súborom odkiaľkoľvek, s tabletom, e-čítačkou, telefónom alebo počítačom.", "Udev rules for Coral USB devices added and rules reloaded.": "Udev pravidlá pre Coral USB zariadenia boli pridané a znovu načítané.", "Udev rules for Coral USB devices already exist.": "Udev pravidlá pre Coral USB zariadenia už existujú.", "Udev rules for Coral USB devices appended and rules reloaded.": "Udev pravidlá pre Coral USB zariadenia boli doplnené a znovu načítané.", + "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results.": "UltiMaker Cura je bezplatný, ľahko použiteľný 3D tlačový softvér dôveryhodný miliónom užívateľov. Vyrovnajte svoj 3D model s nastavením 400+ pre najlepšie výsledky krájania a tlače.", "Umbrel OS installer script by Helper Scripts\n\nVisit the GitHub repo to learn more, contribute, or support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm": "Inštalačný skript Umbrel OS od Helper Scripts\n\nNavštívte GitHub repozitár, kde nájdete viac informácií, môžete prispieť alebo podporiť projekt:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm", "Unable to detect Proxmox version": "Nepodarilo sa zistiť verziu Proxmoxu", "Unable to detect Proxmox version.": "Nepodarilo sa zistiť verziu Proxmoxu.", @@ -4618,6 +6335,10 @@ "Unable to resolve system ZFS pool disks. Aborting.": "Nepodarilo sa vyriešiť systémové disky ZFS fondu. Prerušuje sa.", "Unable to resolve system disk topology. Aborting.": "Nepodarilo sa vyriešiť topológiu systémového disku. Prerušuje sa.", "Understand the security implications of privileged containers": "Uistite sa, že rozumiete bezpečnostným dôsledkom privilegovaných kontajnerov", + "Unexpected Proxmox inventory; recovery blocked": "Neočakávaný inventár Proxmox; zablokovaná obnova", + "Unexpected formatting directory in the new Valkey volume": "Neočakávaný formátovanie adresára v novom hlasitosti Valkey", + "Ungoogled Chromium is Google Chromium, sans dependency on Google web services.": "Ungoogled Chromium je Google Chromium, sans závislosti na webových služieb Google.", + "Unified LLM Fine-Tuning with 100+ Models": "Unified LLM Fine-Tuning s 100+ Models", "Uninstall Coral drivers and configuration": "Odinštalovať ovládače a nastavenie Coral", "Uninstall Fail2Ban": "Odinštalovať Fail2Ban", "Uninstall Lynis": "Odinštalovať Lynis", @@ -4647,6 +6368,10 @@ "Unknown CPU type. IOMMU might not be properly enabled.": "Neznámy typ procesora. IOMMU nemusí byť správne zapnuté.", "Unknown CPU vendor. Cannot determine IOMMU parameter.": "Neznámy výrobca CPU. Parameter IOMMU sa nedá určiť.", "Unknown GPU": "Neznáma GPU", + "Unknown adapter role": "Neznáma úloha adaptéra", + "Unknown credential service:": "Neznámy credential servis:", + "Unknown dependency:": "Neznáma závislosť:", + "Unknown host monitor": "Neznámy monitor hostiteľa", "Unknown model": "Neznámy model", "Unknown size": "Neznáma veľkosť", "Unknown storage controller": "Neznámy storage controller", @@ -4662,6 +6387,10 @@ "Unmounted:": "Odpojené:", "Unmounting": "Odpájam", "Unmounting disk...": "Odpájam disk...", + "Unpackerr configured": "Konfigurovaný Unpackerr", + "Unpackerr has no web interface and extracts nothing until it is pointed at a Starr application. Uncomment the [sonarr.0] or [radarr.0] section in /config/unpackerr.conf inside the container, set its url and api_key, then restart the container.": "Unpackerr nemá webové rozhranie a nič nevyberá, kým nie je namierená na Starr aplikáciu. Odpojte časť [sonarr.0] alebo [radarr.0] v časti /config/unpackerr.conf vo vnútri kontajnera, nastavte jeho url a api key, potom znovu reštartujte kontajner.", + "Unpackerr requires Sonarr, Radarr or Lidarr in this suite": "Unpackerr requires Sonarr, Radarr alebo Lidarr v tomto súbore", + "Unpackerr stopped during its first start": "Unpackerr zastavil počas svojho prvého štartu", "Unprivileged": "Neprivilegovaný", "Unprivileged Container Access": "Prístup neprivilegovaného kontajnera", "Unprivileged container": "Neprivilegovaný kontajner", @@ -4670,15 +6399,73 @@ "Unprivileged containers map their UIDs to high host UIDs (e.g. 100000+), which appear as 'others' on the host filesystem.": "Neprivilegované kontajnery mapujú svoje UID na vysoké UID hosta (napr. 100000+), ktoré sa na súborovom systéme hosta zobrazujú ako 'others'.", "Unprivileged: Limited access (more secure)": "Neprivilegovaný: obmedzený prístup (bezpečnejšie)", "Unreachable": "Nedostupné", + "Unrecognized Immich adapter": "Nerozpoznaný adaptér Immich", + "Unrecognized adaptation format": "Nerozpoznaný formát adaptácie", + "Unrecognized adaptation recipe": "Nerozpoznaný adaptačný recept", + "Unrecognized dependency order of the stack:": "Nerozpoznané poradie závislosti stohu:", + "Unrecognized host monitor profile": "Nerozpoznaný profil monitora hostiteľa", + "Unrecognized native configuration": "Nerozpoznaná natívna konfigurácia", + "Unrecognized qBittorrent configuration format": "Nerozpoznaný formát konfigurácie qBittorrent", + "Unrecognized stack adapter or role": "Nerozpoznaný stack adaptér alebo role", + "Unrecognized stack adapter:": "Nerozpoznaný zásobník adaptér:", + "Unrecognized stack structure:": "Nerozpoznaná štruktúra stohu:", + "Unrecognized volume definition": "Nerozpoznaná definícia objemu", + "Unresolved variable:": "Nevyriešená premenná:", + "Unsafe OCI archive path": "Nebezpečná cesta k archívu OCI", + "Unsafe dependency contract": "Zmluva o neistej závislosti", + "Unsafe dependency hook contract": "Zmluva o nebezpečnom háku", + "Unsafe instance directory": "Nebezpečný priečinok inštancie", + "Unsafe instance record": "Nebezpečný záznam o udalosti", + "Unsafe journal or lock file": "Nebezpečný súbor denníka alebo zámku", + "Unsafe private configuration path": "Nebezpečná konfiguračná dráha", + "Unsafe qBittorrent configuration path": "Nebezpečná konfiguračná dráha qBittorrent", + "Unsafe record": "Nebezpečný záznam", + "Unsafe registry directory": "Nebezpečný adresár registrov", + "Unsafe registry lock": "Nebezpečný zámok registra", + "Unsafe rootfs for the capture": "Nebezpečné rootfs pre zachytenie", + "Unsafe stack assembly": "Nebezpečná montáž zásobníka", + "Unsafe volume path": "Nebezpečná trasa objemu", + "Unsupported CPU allocation mode:": "Nepodporovaný režim prideľovania CPU:", + "Unsupported GID strategy:": "Nepodporovaná stratégia GID:", + "Unsupported NVIDIA mode:": "Nepodporovaný režim NVIDIA:", + "Unsupported OCI digest:": "Nepodporovaná digescia OCI:", + "Unsupported OCI-LXC AppArmor profile:": "Nepodporovaný profil OCI-LXC AppArmor:", + "Unsupported OCI-LXC seccomp profile:": "Nepodporovaný profil OCI-LXC seccomp:", "Unsupported Terminal": "Nepodporovaný terminál", + "Unsupported architecture:": "Nepodporovaná architektúra:", + "Unsupported backup compression": "Nepodporovaná kompresia zálohy", + "Unsupported credential pattern:": "Nepodporovaný credential vzor:", + "Unsupported declarative ostype:": "Nepodporovaný deklaratívny typ os:", + "Unsupported device GID strategy": "Stratégia GID nepodporovaného zariadenia", + "Unsupported device type:": "Nepodporovaný typ zariadenia:", + "Unsupported dynamic NVIDIA capabilities:": "Nepodporované dynamické schopnosti NVIDIA:", "Unsupported format. Only .ova and .ovf files are supported.": "Nepodporovaný formát. Podporované sú iba .ova a .ovf súbory.", + "Unsupported media storage mode:": "Nepodporovaný režim pamäťového média:", + "Unsupported mount type": "Nepodporovaný typ pripojenia", + "Unsupported mount type:": "Nepodporovaný typ pripojenia:", + "Unsupported native device type:": "Nepodporovaný natívne typ zariadenia:", + "Unsupported operation": "Nepodporovaná operation", "Unsupported output format:": "Nepodporovaný výstupný formát:", + "Unsupported post-start configuration:": "Nepodporovaná konfigurácia po štarte:", + "Unsupported pre-start check:": "Nepodporovaná kontrola pred začiatkom:", + "Unsupported pre-start repair:": "Nepodporovaná oprava pred štartom:", + "Unsupported prlimit resource": "Nepodporovaný prlimit zdroj", + "Unsupported secret generator:": "Nepodporovaný tajný generátor:", + "Unsupported storage mode:": "Nepodporovaný režim skladovania:", + "Unsupported tmpfs options": "Nepodporované možnosti tmpfs", + "Unsupported volume options:": "Nepodporované možnosti objemu:", + "Untrusted or modified NVIDIA hook": "Nespoľahlivý alebo modifikovaný háčik NVIDIA", + "Unused image removed from the cache:": "Nevyužitý obrázok odstránený z vyrovnávacej pamäte:", + "Unused images removed from the cache:": "Nepoužité obrázky odstránené z vyrovnávacej pamäte:", + "Update": "Aktualizácia", "Update Available": "Dostupná aktualizácia", "Update Ceph repository (Only if using Ceph):": "Aktualizujte Ceph repozitár (iba ak používate Ceph):", "Update Debian repositories to Trixie:": "Aktualizujte Debian repozitáre na Trixie:", "Update Export": "Aktualizovať export", "Update Lynis to latest version": "Aktualizovať Lynis na najnovšiu verziu", "Update NVIDIA in LXC Containers": "Aktualizovať NVIDIA v LXC kontajneroch", + "Update OCI": "Aktualizovať OCI", + "Update OCI stack": "Aktualizovať OCI stack", "Update PVE enterprise repository (Only if using enterprise):": "Aktualizujte PVE enterprise repozitár (iba ak používate enterprise):", "Update Proxmox VE Appliance Manager": "Aktualizovať správcu aplikácií Proxmox VE", "Update Proxmox package lists": "Aktualizovať zoznamy Proxmox balíkov", @@ -4687,15 +6474,26 @@ "Update and upgrade all system packages": "Aktualizovať všetky systémové balíky", "Update and upgrade system": "Aktualizovať systém", "Update cancelled by user": "Aktualizácia zrušená používateľom", + "Update completed. Data kept.": "Aktualizácia dokončená. Údaje uchovávané.", "Update completed. Press Enter to continue...": "Aktualizácia dokončená. Pokračujte stlačením Enter...", + "Update every container of the application": "Aktualizovať každý kontajner aplikácie", "Update kernel to compatible version": "Aktualizovať kernel na kompatibilnú verziu", + "Update now?": "Aktualizácia?", "Update package index:": "Aktualizujte index balíkov:", + "Update prepared": "Aktualizácia", "Update system to latest PVE 8.4+ (if not done already):": "Aktualizujte systém na najnovšie PVE 8.4+ (ak to ešte nie je hotové):", + "Update the image with the saved configuration": "Aktualizovať obrázok pomocou uloženej konfigurácie", + "Update the whole stack?": "Aktualizovať celú kopu?", "Updated": "Aktualizované", "Updated sharedfiles group to GID: 101000": "Skupina sharedfiles bola aktualizovaná na GID: 101000", + "Updated stack checked": "Aktualizovaný stack", + "Updated:": "Aktualizované:", "Updates all Proxmox and Debian packages": "Aktualizuje všetky balíky Proxmoxu a Debianu", "Updates and Packages Commands": "Príkazy pre aktualizácie a balíky", + "Updates are not available yet for this application in this beta": "Aktualizácie zatiaľ nie sú k dispozícii pre túto aplikáciu v tejto beta", + "Updates are not available yet in this beta for applications that use a privileged container or advanced LXC settings": "Aktualizácie zatiaľ nie sú k dispozícii v tomto beta pre aplikácie, ktoré používajú privilegovaný kontajner alebo pokročilé nastavenia LXC", "Updates file is empty or unreadable.": "Súbor s aktualizáciami je prázdny alebo sa nedá prečítať.", + "Updating": "Aktualizácia", "Updating APT package lists...": "Aktualizujem zoznamy APT balíkov...", "Updating Debian Bookworm → Trixie in sources.list...": "Aktualizujem Debian Bookworm → Trixie v sources.list...", "Updating Figurine binary...": "Aktualizujem spustiteľný súbor Figurine...", @@ -4727,6 +6525,7 @@ "Upload to PBS is currently: yes. Pick an action:": "Nahrávanie do PBS je teraz: áno. Vyberte akciu:", "Upload to PBS: enable, disable or rotate the recovery passphrase": "Nahrávanie do PBS: zapnúť, vypnúť alebo zmeniť obnovovaciu frázu", "Uptime and who is logged in": "Doba behu systému a prihlásení používatelia", + "Usage:": "Použitie:", "Use \"Check test progress\" to see results.": "Výsledky zobrazíte cez možnosť \"Skontrolovať priebeh testu\".", "Use 'Export to file' to save it and inspect manually.": "Použite 'Exportovať do súboru', uložte ho a skontrolujte ručne.", "Use 'pct restore' / 'qmrestore' to recover their disks from your VM backups.": "Na obnovu ich diskov zo záloh VM použite 'pct restore' / 'qmrestore'.", @@ -4769,6 +6568,12 @@ "User activity and uptime": "Aktivita používateľov a doba behu systému", "User chose not to remove NetworkManager": "Používateľ sa rozhodol NetworkManager neodstraňovať", "User chose to exit for manual backup creation.": "Používateľ ukončil akciu, aby mohol ručne vytvoriť zálohu.", + "User name for the SSH login": "Užívateľské meno pre prihlásenie SSH", + "User name of the administrator of the web interface": "Užívateľské meno správcu webového rozhrania", + "User name of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Užívateľské meno depreciovaného prihlasovacieho protokolu aplikácie Flowise (prečítané iba verziami Flowise pred 3.0.1)", + "User of the AdGuard Home that receives the settings": "Užívateľ AdGuard Home, ktorý prijíma nastavenia", + "User of the main AdGuard Home": "Užívateľ hlavného AdGuard Home", + "User-friendly WebUI for LLMs (Formerly Ollama WebUI)": "Užívateľsky prívetivé WebUI pre LLM (predovšetkým Ollama WebUI)", "Username": "Používateľské meno", "Username (e.g. root@pam or user@pbs!token):": "Používateľské meno (napr. root@pam alebo user@pbs!token):", "Username and password": "Meno a heslo", @@ -4782,6 +6587,8 @@ "Using advanced configuration": "Používa sa pokročilé nastavenie", "Using default Proxmox logo...": "Používam predvolené logo Proxmoxu...", "Using existing encryption key:": "Používa sa existujúci šifrovací kľúč:", + "Using the image verified by the transaction": "Použitie obrázku overené transakcie", + "Using the verified image from the cache": "Použitie overeného obrazu z vyrovnávacej pamäte", "Utilities": "Nástroje", "Utilities Installation Menu": "Menu inštalácie nástrojov", "Utilities Menu": "Menu nástrojov", @@ -4789,6 +6596,9 @@ "Utilities and Tools": "Nástroje", "Utilities installation completed": "Inštalácia nástrojov je dokončená", "Utilities installed by ProxMenux have been removed": "Pomôcky nainštalované používateľom ProxMenux boli odstránené", + "VA-API driver": "Vodič VA-API", + "VA-API render device": "VA-API vykresľovacie zariadenie", + "VA-API video acceleration": "VA-API video zrýchlenie", "VFIO device IDs removed from /etc/modprobe.d/vfio.conf": "ID VFIO zariadení boli odstránené z /etc/modprobe.d/vfio.conf", "VFIO modules configured in /etc/modules": "VFIO moduly nastavené v /etc/modules", "VFIO modules configured.": "VFIO moduly sú nastavené.", @@ -4796,7 +6606,9 @@ "VFIO modules removed from /etc/modules": "VFIO moduly boli odstránené z /etc/modules", "VFIO orphans cleared and initramfs rebuilt — next boot will free the GPU.": "Osirelé VFIO väzby boli vyčistené a initramfs znovu vytvorený - pri ďalšom štarte sa GPU uvoľní.", "VFIO orphans cleared but initramfs rebuild failed; check /var/log/proxmenux logs.": "Osirelé VFIO väzby boli vyčistené, ale znovuvytvorenie initramfs zlyhalo; skontrolujte záznamy v /var/log/proxmenux.", + "VFS cache mode": "Režim vyrovnávacej pamäte VFS", "VLAN": "VLAN", + "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices.": "VLC Médiá Hráč je voľný a otvorený zdroj multimediálneho prehrávača a rámca, ktorý poskytuje spoľahlivý výkon vo viacerých zariadeniach.", "VM": "VM", "VM Conflict Policy": "Riešenie konfliktu VM", "VM ID": "ID VM", @@ -4824,17 +6636,28 @@ "VM started": "VM bola spustená", "VM stopped": "VM bola zastavená", "VM:": "VM:", + "VMID (empty = next free)": "VMID (prázdne = ďalšie voľné)", "VMID in use": "VMID sa už používa", "VMID must be a number.": "VMID musí byť číslo.", "VMID of the Borg server LXC on": "VMID Borg server LXC na", + "VMID of the Rclone OCI container": "VMID nádoby Rclone OCI", "VMs to destroy:": "VM na zničenie:", "VMs, LXCs, network, /etc/pve, users, cron, packages, drivers, ProxMenux state, etc.": "VM, LXC, sieť, /etc/pve, používatelia, cron, balíky, ovládače, stav ProxMenux atď.", + "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server.": "VS Code je integrované vývojové prostredie vyvinuté spoločnosťou Microsoft. Tento kontajner spúšťa plnú desktopovú aplikáciu, pre web natívne verziu pozri Code Server.", + "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft’s editor VS Code.": "VSCodium je komunita-riadený, voľne licencované binárne distribúcie Microsoft a editor VS Kód.", "Valid backups for all VMs/CTs": "Platné zálohy všetkých VM/CT", "Validating Proxmox 9 repositories (checking 'proxmox-ve' candidate)...": "Overujem Proxmox 9 repozitáre (kontrolujem kandidáta 'proxmox-ve')...", "Validating credentials with server": "Overujem prihlasovacie údaje na serveri", "Validating disk safety...": "Overujem bezpečnosť disku...", + "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)": "Validačná metóda: http (port 80 expedované) alebo dns (DNS modul poskytovateľa)", + "Value for": "Hodnota", + "Variable name": "Názov premennej", + "Variables": "Premenné", + "Variables the installation asks for:": "Premenné, ktoré požaduje inštalácia:", "Verbose pool status": "Podrobný stav poolu", "Verification": "Overenie", + "Verified": "Overené", + "Verified by ProxMenux": "Overené ProxMenux", "Verify IOMMU group for PCI device": "Overiť IOMMU skupinu PCI zariadenia", "Verify Options > OS Type — currently set to:": "Overte Options > OS Type - aktuálne nastavené na:", "Verify PVE version (must be 8.4.1 or newer):": "Overte verziu PVE (musí byť 8.4.1 alebo novšia):", @@ -4850,12 +6673,16 @@ "Verifying Ceph packages availability...": "Overujem dostupnosť balíkov Ceph...", "Verifying all utilities status": "Overujem stav všetkých nástrojov", "Verifying disk accessibility in CT": "Overujem dostupnosť disku v CT", + "Verifying the backups...": "Overujem zálohy...", + "Verifying the image integrity...": "Overuje integritu obrazu...", "Version": "Verzia", "Version Change Detected": "Zistená zmena verzie", "Version info not available": "Informácie o verzii nie sú dostupné", "Version:": "Verzia:", "Version: Auto-negotiation (NFSv3/NFSv4)": "Verzia: automatické dohodnutie (NFSv3/NFSv4)", "Versions shown belong to maintained NVIDIA branches that list your GPU PCI ID and are new enough to build against the running kernel. DKMS compilation is the final validation. The recommended version keeps the current branch, or uses the NVIDIA Production Branch on a fresh install.": "Zobrazené verzie patria do udržiavaných pobočiek NVIDIA, ktoré uvádzajú vaše ID PCI GPU a sú dostatočne nové na to, aby sa dali postaviť proti bežiacemu jadru. Kompilácia DKMS je konečným overením. Odporúčaná verzia ponecháva aktuálnu vetvu alebo používa NVIDIA Production Branch pri novej inštalácii.", + "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML.": "Video zrýchlenie a detekcia objektu sú nezávislé voľby; inštalátor nepíše fotoaparát alebo detektor YAML.", + "Video transcoding acceleration": "Zrýchlenie priepustnosti videa", "View CIFS Mounts (pvesm + fstab)": "Zobraziť CIFS mounty (pvesm + fstab)", "View Current Exports": "Zobraziť aktuálne exporty", "View Current Mounts": "Zobraziť aktuálne pripojenia", @@ -4871,6 +6698,7 @@ "View raw VM configuration file": "Zobraziť konfiguračný súbor VM", "View restore plan": "Zobraziť plán obnovy", "View self-test log": "Zobraziť log samo-testu", + "View status": "Stav zobrazenia", "VirtIO (advanced - high performance)": "VirtIO (pokročilé - vysoký výkon)", "VirtIO ISO not found after selection.": "Po výbere sa VirtIO ISO nenašlo.", "VirtIO ISO selection cancelled.": "Výber VirtIO ISO bol zrušený.", @@ -4886,10 +6714,19 @@ "Virtual display normalized to vga: std (compatibility)": "Virtuálne zobrazenie zjednotené na vga: std (kompatibilita)", "Virtual display set to": "Virtuálne zobrazenie nastavené na", "Virtual interface (normal)": "Virtuálne rozhranie (bežné)", + "Virtual whiteboard for sketching hand-drawn like diagrams": "Virtuálna tabuľa na kreslenie ručne kreslených diagramov", "Virtualization": "Virtualizácia", "Visit https://osx-proxmox.com for more information.": "Viac informácií nájdete na https://osx-proxmox.com.", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:": "Navštívte web, kde nájdete ďalšie skripty, novinky a môžete podporiť projekt:", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE": "Navštívte web, kde nájdete ďalšie skripty, novinky a môžete podporiť projekt:\n\nhttps://community-scripts.github.io/ProxmoxVE", + "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies.": "Vivaldi je nórsky freeware, cross-platform webový prehliadač s vstavaným e-mailovým klientom vyvinutým Vivaldi Technologies.", + "Volume configuration cancelled": "Konfigurácia hlasitosti zrušená", + "Volume options are not yet supported": "Možnosti objemu zatiaľ nie sú podporované", + "Volume size in GB": "Veľkosť objemu v GB", + "Volumes attached": "Pripojené objemy", + "Volumes prepared for the first start:": "Objemy pripravené na prvý začiatok:", + "Volumes shared between services are not yet supported": "Objemy zdieľané medzi službami zatiaľ nie sú podporované", + "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code.": "Vscodium-web je komunitne riadený, voľne licencovaná binárna distribúcia vzdialenej webovej zložky Microsoft editor VS Code.", "Vulnerability detection": "hľadania zraniteľností", "WARNING": "UPOZORNENIE", "WARNING — This backup contains paths that are risky to restore on a running system:": "UPOZORNENIE - táto záloha obsahuje cesty, ktoré je rizikové obnovovať na bežiacom systéme:", @@ -4912,15 +6749,40 @@ "WARNING: You are about to remove this Proxmox storage:": "UPOZORNENIE: Chystáte sa odstrániť toto úložisko Proxmoxu:", "WARNING: You are about to remove this disk mount:": "UPOZORNENIE: Chystáte sa odstrániť tento diskový mount:", "WARNING: this will ERASE EVERYTHING on the disk.": "UPOZORNENIE: týmto sa VYMAŽE VŠETKO na disku.", + "WEB UI to manage WireGuard VPN.": "WEB UI pre správu WireGuard VPN.", "WILL BE PERMANENTLY ERASED.": "BUDÚ NATRVALO VYMAZANÉ.", + "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency.": "WPS Office je ľahký, vybavený komplexný kancelársky apartmán s vysokou kompatibilitou. Ako praktický a profesionálny kancelársky softvér vám WPS Office umožňuje upravovať súbory v programe Writer, Prezentácia, Spreadsheet, a PDF pre zlepšenie vašej pracovnej efektívnosti.", "Wait for each node to complete before starting next": "Pred začiatkom ďalšieho uzla počkajte, kým aktuálny skončí", + "Waiting for Home Assistant OS...": "Čakám na Home Assistant OS...", + "Waiting for the FUSE mount:": "Čakám na FUSE mount:", + "Waiting for the application to respond...": "Čakanie na odpoveď aplikácie...", + "Waiting for the initial Jellyfin configuration...": "Čakám na počiatočnú konfiguráciu Jellyfin...", + "Waiting for the network address...": "Čakám na sieťovú adresu...", + "Waiting for the password of the application...": "Čakám na heslo aplikácie...", + "Waiting for the temporary password...": "Čakám na dočasné heslo...", "Warning": "Upozornenie", "Warning: Auth key should start with 'tskey-'": "Upozornenie: Auth key by mal začínať na 'tskey-'", "Warning: Disk Images on CIFS": "Upozornenie: obrazy diskov na CIFS", "Warning: Limited PCI Reset Support": "Upozornenie: obmedzená podpora PCI resetu", "Warning: both VMs have autostart enabled (onboot=1).": "Upozornenie: obe VM majú zapnutý autostart (onboot=1).", "Warnings": "Upozornenia", + "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents.": "WeKnora je LLM-poháňaný rámec určený pre hlboké pochopenie dokumentov a sémantické vyhľadávanie, najmä pre manipuláciu complex, heterogénne dokumenty.", + "Web UI": "Web UI", + "Web UI 1": "Web UI 1", + "Web UI 2": "Web UI 2", + "Web UI password": "Webové UI heslo", + "Web UI user": "Web UI užívateľ", + "Web access": "Prístup na internet", + "Web address of the AdGuard Home that receives the settings (e.g. http://192.168.1.3)": "Webová adresa AdGuard Home, ktorá prijíma nastavenia (napr. http://192.168.1.3)", + "Web address of the main AdGuard Home, whose settings are copied (e.g. http://192.168.1.2)": "Webová adresa hlavného AdGuard Home, ktorého nastavenia sú kopírované (napr. http://192.168.1.2)", + "Web interface to manage devices running Tasmota firmware.": "Webové rozhranie pre správu zariadení bežiacich na Tasmota firmware.", + "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes).": "WebCord možno zhrnúť ako balík bezpečnostných a súkromia kalenie, Discord funkcie reimplementácie, Electron / Chromium / Discord chyby práce, štýlové listy, vnútorné stránky a zabalené https://discord.com stránky, navrhnutý tak, aby zodpovedali ToS tak, ako je to možné (alebo skryť zmeny, ktoré by mohli porušovať z očí Discord).", + "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels.": "Webgrabplus je multi-site prírastkové xmltv epg grabber. Zhromažďuje tv-program sprievodcu dátami z vybraných tvguide stránok pre vaše obľúbené kanály.", + "Webservers & Proxies": "Webservers a Proxies", "Website": "Webová stránka", + "Webstation is a web native emulation focused LXQt desktop based on Ubuntu.": "Webstation je webová natívne emulácia zameraná LXQt plocha na základe Ubuntu.", + "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser.": "Webtop - Alpine, Ubuntu, Fedora, a Arch založené kontajnery obsahujúce plné pracovné prostredie v oficiálne podporovaných príchutiach prístupných cez akýkoľvek moderný webový prehliadač.", + "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent.": "Weixin (WeChat) je okamžité správy, sociálne médiá, a mobilné platobné aplikácie vyvinuté Tencent.", "What do you want to do?": "Čo chcete urobiť?", "What would you like to do?": "Čo chcete urobiť?", "When asked to select a disk, click Load Driver and load the VirtIO drivers.": "Keď sa zobrazí výber disku, kliknite na Load Driver a načítajte VirtIO ovládače.", @@ -4932,28 +6794,46 @@ "Where do you want to mount the Samba share?": "Kam chcete pripojiť Samba zdieľanie?", "Where is the OVA/OVF file located?": "Kde sa nachádza OVA/OVF súbor?", "Where to mount inside container?": "Kam sa má pripojiť vo vnútri kontajnera?", + "Where to store": "Kde uchovávať", "While the server allows guest listing, no shares are actually accessible without authentication.": "Server síce dovolí hosťovi zobraziť zoznam, ale bez prihlásenia nie je dostupné žiadne zdieľanie.", + "Wikijs A modern, lightweight and powerful wiki app built on NodeJS.": "Wikijs Moderná, ľahká a výkonná wiki aplikácia postavená na NodeJS.", "Will be configured now": "Nastaví sa teraz", "Windows Installation Options": "Možnosti inštalácie Windowsu", "Windows path:": "Cesta pre Windows:", + "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles.": "WineGUI je užívateľsky ústretový Wine manager, ktorý poskytuje grafický frontend pre vytváranie a správu fliaš vína.", "Wipe all — erase partitions + metadata": "Vymazať všetko - odstrániť oddiely + metadáta", "Wipe all — remove partitions + metadata": "Vymazať všetko - odstrániť oddiely + metadáta", "Wipe old signatures and partition table (DESTRUCTIVE):": "Vymazať staré podpisy a tabuľku oddielov (DEŠTRUKTÍVNE):", "Wiping existing partition table...": "Vymazávam existujúcu tabuľku oddielov...", "Wiping partitions and metadata...": "Vymazávam oddiely a metadáta...", + "WireGuard Easy web interface": "Webové rozhranie WireGuard Easy", + "WireGuard® is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry.": "WireGuard® je extrémne jednoduchá, ale rýchla a moderná VPN, ktorá využíva najmodernejšiu kryptografiu. Jeho cieľom je byť rýchlejší, jednoduchší, štíhlejší a užitočnejší ako IPsec, pričom sa vyhýba masívnej bolesti hlavy. Má v úmysle byť výrazne výkonnejší ako OpenVPN. WireGuard je navrhnutý ako všeobecný účel VPN pre prevádzku na vstavaných rozhraniach a super počítačoch podobne, vhodný pre mnoho rôznych okolností. Spočiatku sa vydáva pre jadro Linuxu, je teraz cross-platform (Windows, macOS, BSD, iOS, Android) a široko rozmiestnený. To je v súčasnosti v ťažkom vývoji, ale už to môže byť považované za najbezpečnejšie, najjednoduchšie použitie, a najjednoduchšie riešenie VPN v priemysle.", "Wired NICs in backup missing on target:": "Káblové sieťové karty zo zálohy chýbajú na cieli:", + "Wireshark is the world’s foremost and widely-used network protocol analyzer. It lets you see what’s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998.": "Wireshark je prvoradý a široko používaný sieťový protokol analyzátor. Umožňuje vidieť, čo sa deje na vašej sieti na mikroskopickej úrovni a je de facto (a často de jure) štandard v mnohých komerčných a neziskových podnikoch, vládnych agentúr a vzdelávacích inštitúcií. Rozvoj Wireshark sa darí vďaka dobrovoľným príspevkom odborníkov na vytváranie sietí po celom svete a je pokračovaním projektu, ktorý začal Gerald Combs v roku 1998.", + "With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopped.": "Pri validácii dns, DNSPLUGIN premenná názvy poskytovateľa plugin. Pokročilá inštalácia si to vyžaduje; inak pridajte linku lxc.environment. čas: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopd.", + "With dns validation, write the provider credentials in /config/dns-conf/.ini inside the container and restart it.": "S validáciou dns, napíšte poskytovateľa credentials v /config/dns-conf/.ini vnútri kontajnera a reštartujte ho.", + "With http validation, port 80 of the router must be forwarded to port 80 of this container.": "Pri validácii http sa port 80 routeru musí zaslať do prístavu 80 tohto kontajnera.", "With warnings": "S upozorneniami", "Without Function Level Reset (FLR), passthrough is not considered reliable": "Bez Function Level Reset (FLR) sa passthrough nepovažuje za spoľahlivý", "Without a usable reset path, passthrough reliability is poor and VM": "Bez použiteľnej reset cesty je spoľahlivosť passthrough nízka a VM", + "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom.": "Wolfenstein: Blade of Agony je príbeh-riadený WWII strelec inšpirovaný Wolfenstein a Doom.", + "Workflow automation tool": "Nástroj na automatizáciu pracovného toku", "Working directory:": "Pracovný priečinok:", "Works with LVM, ZFS, and BTRFS storage types": "Funguje s typmi úložísk LVM, ZFS a BTRFS", + "Worth knowing before installing it:": "Stojí za to vedieť pred inštaláciou:", "Would you like to continue in passthrough-only mode? The libedgetpu APT install will be skipped, the Coral device will still be visible inside the container (e.g. /dev/apex_0), and you can install the runtime yourself or use an app container that bundles it (e.g. the Frigate Docker image).": "Chcete pokračovať iba v režime passthrough? Inštalácia libedgetpu cez APT sa preskočí, Coral zariadenie bude v kontajneri stále viditeľné (napr. /dev/apex_0) a runtime si môžete doinštalovať sami alebo použiť aplikačný kontajner, ktorý ho už obsahuje (napr. Docker obraz Frigate).", "Would you like to see the current": "Chcete zobraziť aktuálny", "Write access confirmed for user:": "Zápis potvrdený pre používateľa:", "Write access confirmed.": "Zápis je potvrdený.", "Write access test FAILED for user:": "Test zápisu ZLYHAL pre používateľa:", "Write access verified for user:": "Prístup na zápis bol overený pre používateľa:", + "Write the value it produces instead.": "Napíšte namiesto toho hodnotu, ktorú vytvára.", + "Wrong SHA-256 in": "Nesprávne SHA-256 v", + "Wrong inherited registry lock": "Nesprávny zdedený register", "Wrong passphrase": "Nesprávna fráza", + "Wrong size in": "Nesprávna veľkosť", + "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support.": "Xbackbone je jednoduchý, self-hosted, ľahký PHP správca súborov, ktoré podporujú nástroj okamžité zdieľanie ShareX a *NIX systémy. Podporuje nahrávanie a zobrazovanie obrázkov, GIF, video, kód, formátovaný text a sťahovanie a nahrávanie súborov. Tiež majú webové UI s multi užívateľským manažmentom, minulé nahráva históriu a podporu vyhľadávania.", + "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS.": "Yaak je desktopový API klient pre organizovanie a vykonávanie REST, GraphQL, a gRPC požiadavky. Je postavený pomocou Tauri, Rust a ReactJS.", "Yes": "Áno", "Yes, upload": "Áno, nahrať", "Yes: set a recovery passphrase now; the encrypted key envelope is uploaded with every backup.": "Áno: teraz nastavte obnovovaciu frázu; šifrovaná obálka kľúča sa nahrá pri každej zálohe.", @@ -4984,6 +6864,9 @@ "You should now be able to access the Proxmox web interface.": "Teraz by ste mali mať prístup k webovému rozhraniu Proxmoxu.", "You will need a Tailscale auth key from: https://login.tailscale.com/admin/settings/keys": "Budete potrebovať Tailscale auth key z: https://login.tailscale.com/admin/settings/keys", "Your Coral USB device and its runtime (libedgetpu1) will NOT be affected.": "Vaše zariadenie Coral USB a jeho runtime (libedgetpu1) NEBUDÚ ovplyvnené.", + "Your machine learning Env work with Jupyter Lab": "Vaše strojové učenie Env práce s Jupyter Lab", + "Your next YouTube media manager": "Váš ďalší manažér médií YouTube", + "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics.": "Your_spotify je self-hosted aplikácie, ktorá sleduje to, čo počúvate a ponúka palubnú dosku preskúmať štatistiky o tom! Skladá sa z webového servera, ktorý skúma API Spotify sem tam a tam a webovej aplikácie, na ktorej môžete preskúmať svoje štatistiky.", "ZFS ARC config removed (kernel defaults will apply on reboot)": "Nastavenie ZFS ARC bolo odstránené (predvolené hodnoty kernelu sa použijú po reštarte)", "ZFS ARC maximum configured:": "Maximálna veľkosť ZFS ARC je nastavená na:", "ZFS ARC optimization completed": "Optimalizácia ZFS ARC je dokončená", @@ -5011,9 +6894,16 @@ "ZFS storage added successfully to Proxmox!": "ZFS úložisko bolo úspešne pridané do Proxmoxu!", "ZFS tools not found. Install zfsutils-linux and retry.": "Nástroje ZFS sa nenašli. Nainštalujte zfsutils-linux a skúste to znova.", "ZFS:": "ZFS:", + "ZNC web interface": "Webové rozhranie ZNC", + "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design.": "Zen Browser je bezplatný a open-source fork Mozilla Firefox so zameraním na súkromie, prispôsobiteľnosť a dizajn.", "Zero all data — partition table preserved, data wiped": "Vynulovať všetky dáta - tabuľka oddielov zostane, dáta sa vymažú", "Zero all data — partition table preserved": "Vynulovať všetky dáta - tabuľka oddielov zostane", "Zeroing partition": "Nulujem oddiel", + "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC.": "Znc je vyhadzovač siete IRC alebo BNC. Môže odpojiť klienta od aktuálneho IRC servera, ako aj od vybraných kanálov. Viacerí klienti z rôznych miest sa môžu pripojiť na jeden ZNC účet súčasne, a preto sa objaví pod rovnakou prezývkou na IRC.", + "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research.": "Zotero je bezplatný, ľahko použiteľný nástroj, ktorý vám pomôže zhromažďovať, organizovať, anotovať, citovať a zdieľať výskum.", + "a value is required": "hodnota je required", + "aMule WebUI (password only, no username)": "aMule WebUI (iba heslo, žiadne užívateľské meno)", + "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule.": "aMule je multiplatformový klient pre sieť zdieľania súborov ED2K a založený na eMule klienta okien. aMule začal v auguste 2003, ako fork xMule, čo je fork lMule.", "active VF(s)": "aktívne VF", "active VFs": "aktívnymi VF", "active Virtual Functions. Changing its driver binding would destroy every VF.": "aktívnymi Virtual Functions. Zmena naviazania ovládača by zrušila každú VF.", @@ -5035,20 +6925,24 @@ "apex group still has members; left in place:": "Skupina apex stále má členov, preto zostáva ponechaná:", "apex kernel module not loaded on host. Run \"Install Coral on Host\" first or the container will not see /dev/apex_0.": "Kernel modul apex nie je na hoste načítaný. Najprv spustite \"Install Coral on Host\", inak kontajner neuvidí /dev/apex_0.", "appears to be part of a": "vyzerá, že je súčasťou", + "apply requires the OCI archive of the resolved image": "aplikovať requires archív OCI vyriešeného obrazu", "applying minimal banner patch": "používam minimálnu úpravu bannera", "apt cache refreshed.": "apt cache bola obnovená.", "apt-get exited": "apt-get skončil", "apt-get update returned warnings. Continuing anyway; check": "apt-get update vrátil varovania. Pokračujem ďalej; skontrolujte", "as": "ako", + "assembling": "montáž", "automatically. Install it manually inside the container.": "automaticky. Nainštalujte ho ručne vo vnútri kontajnera.", "automatically. Reboot LXC to fully release.": "automaticky. Pre úplné uvoľnenie reštartujte LXC.", "available for LXC bind-mounts via 'LXC Mount Manager'": "dostupné pre LXC bind mounty cez 'Správca LXC mountov'", "available in this same GPU and TPU menu.": "dostupnej v tomto istom GPU a TPU menu.", "backup at /etc/fstab.proxmenux.bak": "záloha v /etc/fstab.proxmenux.bak", "ban": "zákaz", + "belongs to another OCI installation": "patrí do iného zariadenia OCI", "blocking issue(s).": "blokujúcich problémov.", "btrfs — Proxmox dir storage (snapshots, compression)": "btrfs — Proxmox dir úložisko (snapshoty, kompresia)", "btrfs — snapshots and compression": "btrfs - snapshoty a kompresia", + "budge is an open source 'budgeting with envelopes' personal finance app.": "budge je otvorený zdroj \"budgeting s obálkami\" aplikácie osobného financovania.", "builds against kernel": "stavia proti jadru", "but it does not match the one used to create the backup. Replace it with the correct keyfile from the source host and retry.": "ale nezhoduje sa s tým, ktorý bol použitý pri vytvorení zálohy. Nahraďte ho správnym keyfile zo zdrojového hosta a skúste to znova.", "bytes": "bajtov", @@ -5056,29 +6950,52 @@ "chmod 1777 + setfacl o::rwx (applied on the NFS share from this host)": "chmod 1777 + setfacl o::rwx (použité na NFS zdieľaní z tohto hosta)", "chmod failed — NFS server may be restricting changes from root": "chmod zlyhal - NFS server môže obmedzovať zmeny od roota", "chown/chmod failed — likely unprivileged CT against host bind mount. Falling back to ACL.": "chown/chmod zlyhalo - pravdepodobne ide o neprivilegovaný CT nad bind mountom z hosta. Skúšam náhradné riešenie cez ACL.", + "containers": "kontajnery", + "containers of": "nádob", "content:": "obsah:", + "copyparty web interface": "Webové rozhranie copyparty", "could not be compiled for kernel": "nepodarilo sa skompilovať pre jadro", + "could not validate NVIDIA; exit code": "nemohol potvrdiť NVIDIA; kód výstupu", + "cpuunits must be between 8 and 10000": "cpujednotky musia byť od 8 do 10000", + "custom": "zvyk", + "custom dependency commands are not yet supported": "Vlastné príkazy závislosti ešte nie sú podporované", + "custom path(s) saved.": "uložených vlastných ciest.", + "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them.": "darktable je aplikácia fotografií s otvoreným zdrojom a surový vývojár. Virtuálna svetelná a tmavá miestnosť pre fotografov. Spravuje vaše digitálne negatíva v databáze, umožňuje vám ich prezerať pomocou zoomovateľného svetelného zariadenia a umožňuje vám vyvinúť surové obrázky a zlepšiť ich.", + "ddclient starts with the example configuration and updates nothing yet. Write your provider, login and domains in /config/ddclient.conf inside the container, then restart it.": "ddclient začína s konfiguráciou príkladu a ešte nič neaktualizuje. Napíšte svojho poskytovateľa, prihlásenie a domény do /config/ddclient.conf vnútri kontajnera a potom ho reštartujte.", "default": "predvolené", "delete the credentials file (if any)": "vymazať súbor s prihlasovacími údajmi (ak existuje)", "delete the matching line from /etc/fstab": "odstrániť zodpovedajúci riadok z /etc/fstab", "descriptor + VMDK files": "popisovač + VMDK súbory", + "device(s) added to VM": "zariadení pridaných do VM", "devices": "zariadenia", + "devices (dynamic runtime)": "zariadenia (dynamický čas chodu)", "did not become ready. Skipping.": "nebol pripravený. Preskakujem.", + "digiKam: Professional Photo Management with the Power of Open Source": "digiKam: Profesionálny Photo Management s výkonom otvoreného zdroja", "disk(s) added to CT": "diskov pridaných do CT", "disk(s) added to VM": "diskov pridaných do VM", + "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems.": "diskover je indexátor open source súborového systému, ktorý používa Elasticsearch na indexovanie a správu dát v rámci heterogénnych pamäťových systémov.", "disks present": "disky prítomné", "dkms autoinstall did not activate:": "dkms autoinstall sa neaktivoval:", "dkms.conf generated.": "dkms.conf bol vytvorený.", + "docker run command": "docker spustiť príkaz", + "docker run command of the application": "docker spustiť príkaz aplikácie", "does not exist on this host. Path not added.": "na tomto hostovi neexistuje. Cesta nebola pridaná.", "does not exist. Exiting.": "neexistuje. Končím.", + "doplarr_rs starts from the example configuration and connects to nothing. Write the token of your Discord bot in discord_token in /config/config.toml inside the container.": "doplarr_rs začína od konfigurácie príkladu a spája sa s ničím. Napíšte token svojho Discord bot v discord token v /config/config.toml vnútri kontajnera.", + "downloaded Compose file": "stiahnutý súbor", "dpkg still reports unfinished package work; review": "dpkg stále hlási nedokončenú prácu s balíkom;recenzia", + "driver components": "komponenty vodiča", "driver:": "ovládač:", + "e.g.": "napr.", + "empty = generate": "prázdne = generovať", "exFAT (portable: Windows/Linux/macOS)": "exFAT (prenosné: Windows/Linux/macOS)", "exFAT tools installed successfully.": "Nástroje exFAT boli úspešne nainštalované.", "ext4 — Proxmox dir storage (recommended)": "ext4 — Proxmox dir úložisko (odporúčané)", "ext4 — recommended, most compatible": "ext4 - odporúčané, najkompatibilnejšie", "fail2ban-client could not communicate with the server": "fail2ban-client nedokázal komunikovať so serverom", "fail2ban-client successfully communicated with the server": "fail2ban-client úspešne komunikoval so serverom", + "failed": "zlyhalo", + "failed with exit code": "zlyhal s výstupným kódom", "failed:": "zlyhalo:", "feranick fork unreachable. Falling back to google/gasket-driver...": "Fork feranick nie je dostupný. Skúšam náhradný google/gasket-driver...", "feranick/gasket-driver cloned (actively maintained, kernel 6.12+ ready).": "feranick/gasket-driver bol naklonovaný (aktívne udržiavaný, pripravený pre kernel 6.12+).", @@ -5092,6 +7009,7 @@ "for this policy and may fail after first use or on subsequent VM starts.": "podľa týchto pravidiel a môže zlyhať po prvom použití alebo pri ďalších štartoch VM.", "formatted as": "naformátované ako", "found": "nájdené", + "free": "bez cla", "from Proxmox web interface (you will be asked)": "z webového rozhrania Proxmoxu (ešte sa vás opýta)", "from container": "z kontajnera", "from the GPUs and Coral-TPU menu first, then run this option again.": "z menu GPU a Coral-TPU a potom túto voľbu spustite znova.", @@ -5102,6 +7020,7 @@ "gasket-dkms has been fully removed from this system.": "gasket-dkms bol z tohto systému úplne odstránený.", "gasket-dkms is still reported by dpkg in state:": "dpkg stále hlási gasket-dkms v stave:", "gawk installed": "gawk je nainštalovaný", + "go2rtc WebUI": "Go2rtc WebUI", "google/gasket-driver cloned (fallback — will apply local patches).": "google/gasket-driver bol naklonovaný (náhradná možnosť - použijú sa lokálne záplaty).", "gpg not found; trying apt-key fallback": "gpg sa nenašiel; skúšam náhradný apt-key postup", "gzip replaced with pigz wrapper successfully": "gzip bol úspešne nahradený wrapperom pigz", @@ -5109,10 +7028,14 @@ "has a different MAC than the backup — update any DHCP static reservation": "má inú MAC než v zálohe - aktualizujte prípadnú statickú rezerváciu v DHCP", "has a new MAC": "má novú MAC", "has only": "má iba", + "health and persistence profile not yet defined": "profil zdravia a pretrvávania, zatiaľ nedefinovaný", + "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers.": "HISHtory je lepšia história mušlí. Ukladá históriu vášho shellu v kontexte (v akom adresári ste spustili príkaz, či sa to podarilo alebo zlyhalo, ako dlho to trvalo, atď). Toto všetko je uložené lokálne a end-to-end zašifrované pre synchronizáciu so všetkými ostatnými počítačmi.", + "host directory": "adresár host", "host fstab only (not registered as Proxmox storage)": "iba host fstab (nie je zaregistrované ako úložisko Proxmoxu)", "hostpci entries for all IOMMU group devices": "hostpci položky pre všetky zariadenia IOMMU skupiny", "hostpci entries for selected GPU functions (full IOMMU group will be enforced after reboot)": "hostpci položky pre vybrané funkcie GPU (celá IOMMU skupina sa vynúti po reštarte)", "hour(s)": "hod.", + "https if the image serves TLS": "https, ak obrázok slúži TLS", "iSCSI Content Type": "Typ obsahu iSCSI", "iSCSI Daemon (iscsid): RUNNING": "iSCSI služba (iscsid): BEŽÍ", "iSCSI Daemon (iscsid): STOPPED": "iSCSI služba (iscsid): ZASTAVENÁ", @@ -5129,16 +7052,23 @@ "iSCSI storage provides raw block devices for VM disk images.": "iSCSI úložisko poskytuje surové blokové zariadenia pre disky virtuálnych strojov.", "iSCSI tools installed": "iSCSI nástroje sú nainštalované", "iftop usage": "Použitie iftop", + "image cache on": "Comment", + "image itself": "samotný obrázok", "imported:": "importované:", "in CT": "v CT", + "in backups": "v zálohách", + "incompatible qBittorrent schema": "nekompatibilná schéma qBittorrent", + "individual template is blocked": "individuálna šablóna je zablokovaná", "initramfs updated": "initramfs aktualizovaný", "initramfs updated.": "initramfs bol aktualizovaný.", + "installed": "nainštalovaný", "installed but command not immediately available": "nainštalované, ale príkaz nie je hneď dostupný", "installed correctly and available": "nainštalované správne a dostupné", "installed in CT": "nainštalované v CT", "installed inside CT": "nainštalovaný vo vnútri CT", "installed successfully.": "úspešne nainštalovaný.", "installed.": "nainštalovaný.", + "installing": "inštalácia", "intel-gpu-tools installed successfully": "intel-gpu-tools bol úspešne nainštalovaný", "intel-gpu-tools is already installed:": "intel-gpu-tools už je nainštalovaný:", "intel-gpu-tools is up to date": "intel-gpu-tools je aktuálny", @@ -5169,7 +7099,11 @@ "is not configured as machine type q35.": "nie je nastavená ako typ stroja q35.", "is not in the patch.sh supported list. The patch may no-op or fail; review keylase/nvidia-patch README before continuing.": "nie je v zozname podporovanom patch.sh. Patch nemusí spraviť nič alebo môže zlyhať; pred pokračovaním si pozrite README pre keylase/nvidia-patch.", "is not supported by the official Google libedgetpu APT repository.": "nie je podporovaná oficiálnym Google libedgetpu APT repozitárom.", + "is one of the": "je jedným z", "is referenced in the following stopped VM(s)/CT(s):": "je uvedený v týchto zastavených VM/CT:", + "it asks for the network of the host; the container gets its own address instead": "žiada o sieť hostiteľa; kontajner dostane namiesto toho svoju vlastnú adresu", + "it publishes no other architecture": "nepublikuje žiadnu inú architektúru", + "it uses the Compose option": "používa možnosť Compose", "journald MaxLevelStore is adequate for auth logging": "journald MaxLevelStore je vhodný na logovanie prihlásení", "journald drop-in created: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf": "journald drop-in vytvorený: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf", "journald log level restored": "Úroveň logovania journald bola obnovená", @@ -5193,26 +7127,41 @@ "kexec-tools installed successfully": "kexec-tools boli úspešne nainštalované", "kexec-tools is already installed": "kexec-tools je už nainštalovaný", "kexec-tools is not installed or already removed.": "kexec-tools nie je nainštalovaný alebo už bol odstránený.", + "layers": "vrstvy", "legacy .link file(s) to the ProxMenux-managed format": "staršie .link súbory do formátu spravovaného ProxMenuxom", "log2ram completely removed from system": "log2ram bol úplne odstránený zo systému", "manually inside the container before starting it.": "ručne vo vnútri kontajnera pred jeho spustením.", "manually inside the container.": "ručne vo vnútri kontajnera.", "maximum performance": "maximálny výkon", "may be closed — trying discovery anyway...": "môže byť zatvorený - aj tak skúšam vyhľadanie...", + "melonDS aims at providing fast and accurate Nintendo DS emulation.": "Cieľom melonDS je poskytovať rýchle a accurate Nintendo DS emulácia.", + "members:": "členovia:", + "minimum": "minimálna", "missing": "chýba", "mkfs.btrfs not found. Install btrfs-progs and retry.": "mkfs.btrfs sa nenašiel. Nainštalujte btrfs-progs a skúste to znova.", "more": "ďalších", + "motionEye web interface": "Webové rozhranie motionEye", "mount.cifs command not found after installation.": "Príkaz mount.cifs sa po inštalácii nenašiel.", "mount.nfs command not found after installation.": "Príkaz mount.nfs sa po inštalácii nenašiel.", + "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone.": "mstream je osobný hudobný streamovací server. Môžete použiť mStream na streamovanie hudby z vášho domáceho počítača do akéhokoľvek zariadenia, kdekoľvek. K dispozícii sú mobilné aplikácie pre Android aj iPhone.", + "must contain a valid numeric UID for the GPU": "musí obsahovať platné číselné UID pre GPU", + "needed": "potrebné", + "needs a privileged LXC": "potrebuje privilegovanú LXC", + "needs a relaxed AppArmor or seccomp profile": "potrebuje uvoľnený AppArmor alebo seccomp profil", + "needs stack review": "Potreby stack review", "never": "nikdy", + "next free": "next free", + "next free block": "ďalší voľný blok", "nftables not available - using iptables ban action": "nftables nie je dostupné - používam zákaz cez iptables", "no": "nie", "no (kdf=none, not needed)": "nie (kdf=none, nie je potrebná)", "no (no escrow blob — set a recovery passphrase to enable recovery)": "nie (chýba balíček v úschove - nastavte obnovovaciu frázu, aby bola obnova možná)", + "no declarative value": "žiadna deklaratívna hodnota", "no passphrase": "bez frázy", "no password": "bez hesla", "no_root_squash": "no_root_squash", "non-ProxMenux .tar archive(s) in this path": "non-ProxMenux .tar archívy v tejto ceste", + "not available yet": "zatiaľ nedostupné", "not found.": "sa nenašiel.", "not installed": "nie je nainštalované", "not reliable on this hardware due to the following limitations": "na tomto hardvéri nespoľahlivý pre tieto obmedzenia", @@ -5229,27 +7178,39 @@ "of free disk space.": "voľného miesta na disku.", "older firmware may increase passthrough instability": "starší firmvér môže zvýšiť nestabilitu priameho priradenia", "oldest driver offered:": "najstarší ponúkaný ovládač:", + "on": "o", "on SSD/NVMe pools that support discard": "na SSD/NVMe pooloch, ktoré podporujú discard", + "one of its services declares no image": "jedna zo svojich služieb neprehlasuje žiadny obraz", + "one of its services is not written as a service": "jedna z jej služieb nie je napísaná ako služba", "openssl encryption failed.": "Šifrovanie cez openssl zlyhalo.", "openssl is not installed — cannot create recovery copy. Install openssl and retry.": "openssl nie je nainštalovaný - nedá sa vytvoriť obnovovacia kópia. Nainštalujte openssl a skúste to znova.", + "optional": "nepovinné", + "optional dependencies are not yet supported": "nepovinné závislosti zatiaľ nie sú podporované", "or format it manually using external tools.": "alebo ho naformátujte ručne pomocou externých nástrojov.", + "or none": "alebo žiadne", "or use the ProxMenux LXC Mount Manager.": "alebo použite Správcu LXC mountov v ProxMenux.", "orphan iface lines, no impact on restore": "osirelé iface riadky, bez vplyvu na obnovu", "other .tar archive(s) — not ProxMenux host backups (e.g. PVE vzdump or unrelated tarballs).": "iné .tar archívy - nie sú to ProxMenux zálohy hosta (napr. PVE vzdump alebo nesúvisiace tar archívy).", "packages (this may take a few minutes)...": "balíkov (môže to trvať pár minút)...", + "packages.": "balíkov.", "parent PF:": "rodičovská PF:", "partition(s). Partition table preserved.": "oddielov. Tabuľka oddielov zostala zachovaná.", + "pasted Compose file": "vložený súbor", "paths for next boot (/etc/pve, guests, drivers, ...)": "cesty na najbližší štart (/etc/pve, hostia, ovládače, ...)", "pct exec authorization failed": "Autorizácia cez pct exec zlyhala", "pct push failed. Check log:": "pct push zlyhalo. Skontrolujte záznam:", "pending (reboot required to enumerate full group)": "čaká (na zistenie celej skupiny je potrebný reštart)", + "phpMyAdmin is installed with arbitrary server connections enabled: the login page has a Server field where the address of the MySQL or MariaDB server is entered, together with its user and password.": "phpMyAdmin je nainštalovaný so zapnutými ľubovoľnými pripojeniami servera: prihlasovacia stránka má pole servera, kde je zadaná adresa servera MySQL alebo MariaDB, spolu s jeho užívateľom a heslom.", "pigz configuration completed": "Nastavenie pigz je dokončené", "pigz enabled in vzdump configuration": "pigz je zapnutý v nastavení vzdump", "pigz installed successfully": "pigz bol úspešne nainštalovaný", "pigz removed": "pigz bol odstránený", "pigz wrapper script created": "Wrapper skript pre pigz bol vytvorený", + "playit.gg has to claim this agent before it forwards anything. The agent prints a one-time claim link on the container console and keeps it there until the link is opened.": "playit.gg musí žiadať tohto agenta pred tým, než niečo postúpi. Agent vytlačí jednorázový reklamačný odkaz na konzolu kontajnera a nechá ho tam až do otvorenia odkazu.", "port": "port", "portmapper/rpcbind has been disabled": "portmapper/rpcbind bol zakázaný", + "private network assigned automatically": "privátne siete pridelené automaticky", + "privileged LXC": "Privilegované LXC", "proxmox-backup-client reported:": "proxmox-backup-client oznámil:", "proxmox-boot-tool refreshed": "proxmox-boot-tool bol obnovený", "pve-enterprise.list update skipped (no change)": "Aktualizácia pve-enterprise.list preskočená (bez zmeny)", @@ -5261,10 +7222,22 @@ "pvesm not found.": "pvesm sa nenašiel.", "pvesm path failed, trying manual detection...": "pvesm path zlyhal, skúšam ručné zistenie...", "pvesm status failed": "pvesm status zlyhal", + "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web.": "pyLoad je Free and Open Source manažér download napísaný v Pythone a navrhnutý tak, aby bol veľmi ľahký, ľahko rozšíriteľný a plne zvládnuteľný cez web.", + "pyLoad web interface": "webové rozhranie pyLoad", + "qBittorrent WebUI password (user: admin)": "qBittorrent WebUI heslo (používateľ: admin)", + "qBittorrent already has a configuration; it is not overwritten": "qBittorrent už má konfiguráciu; nie je prepísaná", + "qBittorrent configured": "Konfigurovaný qBittorrent", + "qBittorrent did not apply the category:": "qBittorrent neuplatnila kategóriu:", + "qBittorrent did not apply the download paths": "qBittorrent nepoužila cesty na stiahnutie", + "qBittorrent requires a non-empty password": "qBittorrent requires a non-prázdne heslo", + "qBittorrent: authenticated access to the preferences could not be verified": "qBittorrent: nemohol sa overiť overený prístup k preferenciám", + "qBittorrent: invalid login response or missing session cookie": "qBittorrent: neplatná odpoveď prihlásenia alebo chýbajúci súbor cookie sedenia", "raw USB disk — no filesystem (will be FORMATTED)": "surový USB disk - bez súborového systému (bude NAformátovaný)", + "read-only": "iba na čítanie", "reboot-quick alias added": "Alias reboot-quick bol pridaný", "reboot-quick alias is already configured": "alias rýchleho reštartu je už nakonfigurovaný", "recommended": "odporúčané", + "recovering": "zotavenie", "remapped users": "remapovanými používateľmi", "remove the (now-empty) directory if possible": "odstrániť teraz prázdny priečinok, ak to bude možné", "removed from Proxmox": "odstránené z Proxmoxu", @@ -5280,11 +7253,14 @@ "rpcbind could not be disabled completely": "rpcbind nebolo možné úplne vypnúť", "rpcbind service and socket have been disabled and stopped": "Služba rpcbind a socket boli deaktivované a zastavené", "rpcbind units were not found; no changes were made": "jednotky rpcbind neboli nájdené;neboli vykonané žiadne zmeny", + "rsnapshot starts with the default configuration, which backs up /data into /.snapshots. Edit /config/rsnapshot.conf inside the container to set your own backup points, snapshot root and retention intervals.": "rsnapshot začína štandardnou konfiguráciou, ktorá zálohuje / dáta do /.snapshots. Upraviť /config/rsnapshot.conf vnútri kontajnera nastaviť svoje vlastné záložné body, snímky koreňov a intervaly uchovávania.", "running": "beží", + "runs in": "beží v", "safe paths now (configs, packages, /etc, /root, ...)": "bezpečné cesty teraz (nastavenia, balíky, /etc, /root, ...)", "same MAC": "rovnaká MAC", "seconds (default)": "sekúnd (predvolené)", "see log:": "pozrite záznam:", + "selected by default": "vybrané štandardne", "selected path(s):": "vybraných ciest:", "server": "server", "server IP or hostname:": "IP adresa alebo názov servera:", @@ -5292,6 +7268,7 @@ "servers found on the network.": "serverov sa našlo v sieti.", "servers found.": "serverov sa našlo.", "sha256sum not found. Cannot verify Borg binary.": "sha256sum sa nenašiel. Borg binárku nie je možné overiť.", + "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++.": "shadPS4 je skorý emulátor PlayStation 4 pre Windows, Linux a macOS napísaný v C++.", "showmount command is not working properly.": "Príkaz showmount nefunguje správne.", "showmount command not found after installation.": "Príkaz showmount sa po inštalácii nenašiel.", "single portable archive": "jeden prenosný archív", @@ -5307,6 +7284,7 @@ "started successfully.": "úspešne spustený.", "started.": "spustený.", "startup/restart errors are likely.": "pravdepodobne narazí na chyby štartu/reštartu.", + "staticfiles volume size in GB": "veľkosť statických súborov v GB", "stop source VM first": "najprv zastavte zdrojovú VM", "stopped": "zastavené", "storage yet.": "úložisko zatiaľ.", @@ -5316,9 +7294,16 @@ "suggested:": "navrhované:", "switch_gpu_mode.sh was not found.": "switch_gpu_mode.sh sa nenašiel.", "sysfs ROM dump failed — trying ACPI VFCT table...": "sysfs ROM dump zlyhal - skúšam ACPI VFCT tabuľku...", + "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools.": "syslog-ng umožňuje flexibilne zbierať, spracovať, klasifikovať, prepísať a korelovať protokoly z celej vašej infraštruktúry a ukladať alebo smerovať ich do log analytické nástroje.", "systemctl restart networking failed:": "systemctl restart networking zlyhal:", "systemd OnCalendar expression": "systemd OnCalendar výraz", + "the API key was not generated on the first start": "kľúč API nebol vytvorený pri prvom štarte", + "the container has its own address, so the port Docker published on the host is not needed": "kontajner má svoju vlastnú adresu, takže port Docker zverejnené na hostiteľa nie je potrebné", + "the qBittorrent schema is not available": "schéma qBittorrent nie je k dispozícii", + "this configuration needs the device": "táto konfigurácia potrebuje zariadenie", "this distribution": "túto distribúciu", + "tmpfs size in MB for": "tmpfs veľkosť v MB pre", + "tmpfs size too small for": "tmpfs veľkosť príliš malá pre", "to": "na", "to CT": "do CT", "to VM": "do VM", @@ -5327,6 +7312,12 @@ "to sharedfiles group": "do skupiny sharedfiles", "total": "spolu", "umount the path if currently mounted": "odpojiť cestu, ak je práve pripojená", + "unprivileged LXC": "LXC unprivileged", + "unsupported credential generator": "nepodporovaný credential generátor", + "unsupported dependency condition": "stav bez podpory závislosti", + "unsupported external credential or boolean": "nepodporované externé credential alebo boolean", + "unsupported variable": "nepodporovaná premenná", + "updating": "aktualizácia", "updating NVIDIA userspace libs": "aktualizujem používateľské NVIDIA knižnice", "user packages missing — will be installed automatically:": "používateľských balíkov chýba - nainštalujú sa automaticky:", "users": "používateľov", @@ -5337,12 +7328,19 @@ "vfio-pci IDs configured": "vfio-pci ID nastavené", "vfio-pci IDs in /etc/modprobe.d/vfio.conf": "vfio-pci ID v /etc/modprobe.d/vfio.conf", "vzdump backup speed optimization completed": "Optimalizácia rýchlosti záloh vzdump je dokončená", + "wallabag builds its links from the address given during the installation. If it does not match the address of the container, edit lxc.environment.runtime: SYMFONY__ENV__DOMAIN_NAME in /etc/pve/lxc/.conf with the container stopped, and start it again.": "wallabag buduje svoje odkazy z adresy uvedenej počas inštalácie. Ak nezodpovedá adrese kontajnera, upravte prostredie lxc. čas: SYMFONY ENV DOMAIN NAME in /etc/pve/lxc/ .conf s kontajnerom zastavil, a začať znova.", + "wallabag listens on port 80 of the container and stores its data in SQLite.": "wallabag počúva port 80 kontajnera a ukladá svoje údaje v SQLite.", + "wallabag web interface": "Webové rozhranie wallabag", "was": "bolo", "was installed, but the kernel reports:": "bol nainštalovaný, ale jadro hlási:", + "when finished": "po dokončení", "will rebind the GPU to vfio-pci on the next reboot, breaking the driver that is about to be installed.": "pri ďalšom reštarte znova naviaže GPU na vfio-pci, čím sa preruší ovládač, ktorý sa má nainštalovať.", "wipefs failed on": "wipefs zlyhalo na", "with": "za", + "with Proxmox": "s Proxmox", + "with prefix, e.g.": "s predponou, napr.", "with the password you provided.": "s heslom, ktoré ste zadali.", + "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems.": "xemu je bezplatná a open-source aplikácia, ktorá napodobňuje originálnu konzolu Microsoft Xbox, ktorá umožňuje ľuďom hrať svoje pôvodné Xbox hry na systémoch Windows, macOS a Linux.", "xfs — Proxmox dir storage (large files and VMs)": "xfs — Proxmox dir úložisko (veľké súbory a VM)", "xfs — better for large files": "xfs - lepšie pre veľké súbory", "years old": "rokov starý", diff --git a/lang/sv.json b/lang/sv.json index b3fb4ffa..e4052f42 100644 --- a/lang/sv.json +++ b/lang/sv.json @@ -7,6 +7,7 @@ "(common default on Debian/LXC: PermitRootLogin prohibit-password).": "(vanlig standard på Debian/LXC: PermitRootLogin prohibit-password).", "(disabled)": "(inaktiverad)", "(e.g.": "(till exempel.", + "(empty)": "(Töm)", "(for unprivileged LXCs)": "(för oprivilegierade LXC)", "(if only privileged LXCs need write access)": "(om bara privilegierade LXC:er behöver skrivåtkomst)", "(make.log not found — DKMS may have failed before invoking make)": "(make.log hittades inte – DKMS kan ha misslyckats innan make.", @@ -19,6 +20,7 @@ "(recommended)": "(rekommenderad)", "(same MAC — restored config adjusted automatically)": "(samma MAC — återställd konfiguration justeras automatiskt)", ")": ")", + "*Arr Suite": "Arr Suite", "+ Add a path": "+ Lägg till en sökväg", "+ Add new Borg target": "+ Lägg till nytt Borgmål", "+ Add new PBS manually": "+ Lägg till ny PBS manuellt", @@ -35,39 +37,101 @@ "/var/lib/vz/dump (Proxmox default)": "/var/lib/vz/dump (Proxmox standard)", "1777 = sticky bit + rwx for all. No shared group needed.": "1777 = sticky bit + rwx för alla. Ingen delad grupp behövs.", "====== PVE UPDATE COMPLETED ======": "====== PVE UPPDATERING AVSLUTAD ======", + "A GTK Broadway web UI for libvirt and virt-manager.": "En GTK Broadway webb UI för libvirt och virt-manager.", + "A Personal Relationship Management tool to help you document your social life.": "Ett personligt förhållande Management verktyg för att hjälpa dig att dokumentera ditt sociala liv.", "A VirtIO ISO already exists. Do you want to overwrite it?": "En VirtIO ISO finns redan. Vill du skriva över det?", "A ZFS pool with this name already exists.": "En ZFS-pool med detta namn finns redan.", "A ZFS pool with this name already exists:": "En ZFS-pool med detta namn finns redan:", + "A backup was modified": "En backup modifierades", + "A command did not finish in time:": "Ett kommando avslutades inte i tid:", "A complete restore will:": "En fullständig återställning kommer att:", + "A concurrent change was detected; the container is not removed": "En samtidig förändring upptäcktes; behållaren avlägsnas inte", + "A container mount has a source, backup or permission different from the saved record": "En containerfäste har en källa, backup eller tillstånd som skiljer sig från den sparade posten", + "A coordinated operation is pending. The whole previous stack will be recovered, not only the selected member. If the operation already finished, the cleanup of its markers is completed.": "En samordnad operation väntas. Hela den tidigare stacken kommer att återställas, inte bara den valda medlemmen. Om operation redan är klar, är rengöringen av dess markörer klar.", + "A different host monitor include already exists; it is not overwritten:": "En annan värdmonitor inkluderar redan existerar; den är inte överskriven:", + "A fancy monitoring tool": "Ett snyggt övervakningsverktyg", + "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata.": "En gratis och öppen källkod plattform dokumentorienterat databasprogram. Klassificerat som ett NoSQL-databasprogram använder MongoDB JSON-liknande dokument med schemata.", + "A free reverse proxy for tunneling services (not self-hosted).": "En fri omvänd proxy för tunneltjänster (inte egenvärderad).", + "A free, self-hostable news aggregator…": "En fri, självvärd nyhetsaggregator...", + "A full-featured, open-source AI chat interface": "En fullfjädrad, öppen källkod AI chatt gränssnitt", "A gasket DKMS registration is still present:": "En gasket DKMS-registrering finns fortfarande:", + "A host bind mount cannot be included in vzdump": "En värdbindning kan inte inkluderas i vzdump", + "A host mount is not part of the journal; recovery blocked": "En värdfäste är inte en del av tidskriften; återhämtning blockerad", "A host reboot is required after this change.": "En omstart av värddatorn krävs efter denna ändring.", "A host reboot is required before starting the VM. Reboot now?": "En omstart av värddatorn krävs innan den virtuella datorn startas. Starta om nu?", "A job with this ID already exists.": "Ett jobb med detta ID finns redan.", + "A journal already exists; review or recover it before trying again": "En tidskrift finns redan; granska eller återhämta den innan du försöker igen", "A keyfile is installed at:": "En nyckelfil är installerad på:", "A legacy gasket-dkms package was found on this host, but no Coral M.2 / PCIe hardware is present.": "Ett äldre gasket-dkms-paket hittades på denna värd, men ingen Coral M.2/PCIe-hårdvara finns.", + "A managed rootfs and an unprivileged container are required": "En förvaltad rötter och en oprivilegierad behållare är required", + "A managed volume with backup enabled is required": "En hanterad volym med backup aktiverad är required", + "A member VMID is in use by another guest or is on another node": "En medlem VMID används av en annan gäst eller är på en annan nod", + "A member configuration changed after the stack was checked": "En medlemskonfiguration ändrades efter att stacken kontrollerades", + "A member configuration changed during the preparation": "En medlemskonfiguration ändrades under förberedelsen", + "A member did not pass its service check:": "En medlem passerade inte sin servicekontroll:", + "A member has a pending operation": "En medlem har en pågående operation", + "A member has no reproducible service check": "En medlem har ingen reproducerbar servicekontroll", + "A member is missing before the replacement": "En medlem saknas innan ersättningen", + "A member operation does not belong to the stack": "En medlem operation hör inte till stacken", + "A member stopped:": "En medlem slutade:", + "A member was modified after it was recovered": "En medlem ändrades efter att den återhämtats", + "A modern wiki and knowledge base for teams": "En modern wiki och kunskapsbas för lag", "A new ProxMenux version is available:": "En ny ProxMenux-version är tillgänglig:", "A new kernel is staged for the next boot:": "En ny kärna är iscensatt för nästa uppstart:", "A newer version is available:": "En nyare version finns tillgänglig:", + "A pending operation exists for": "En väntande operation finns för", + "A pending stack assembly already exists; it is not overwritten": "En väntande stack församling existerar redan; den är inte överskriven", + "A previous NVIDIA refresh is pending review": "En tidigare NVIDIA-uppdatering väntas granska", "A previous VFIO passthrough configuration was detected for the following NVIDIA GPU(s):": "En tidigare VFIO-passthrough-konfiguration upptäcktes för följande NVIDIA-GPU:er:", + "A privacy-first, open-source platform for knowledge management and collaboration.": "En sekretess-först, open-source plattform för kunskapshantering och samarbete.", "A reboot is recommended before the GPU is guaranteed to stay on the native driver.": "En omstart rekommenderas innan GPU:n garanterat stannar kvar på den inbyggda drivrutinen.", "A reboot is required after installation to load the new kernel modules.": "En omstart krävs efter installationen för att ladda de nya kärnmodulerna.", "A reboot is required for VFIO binding to take effect. Do you want to restart now?": "En omstart krävs för att VFIO-bindning ska träda i kraft. Vill du starta om nu?", "A reboot is required to apply the new GPU mode. Do you want to restart now?": "En omstart krävs för att tillämpa det nya GPU-läget. Vill du starta om nu?", "A reboot is required to finish the restore.": "En omstart krävs för att slutföra återställningen.", "A reboot will be required to complete the restore.": "En omstart kommer att krävas för att slutföra återställningen.", + "A reproducible native startup is missing": "En reproducerbar infödd start saknas", + "A rootfs adaptation is stored in persistent storage": "En rootfs anpassning lagras i ihållande lagring", + "A self-hosted Bitwarden server": "En själv värd Bitwarden server", + "A self-hosted, goal-free habit tracking tool.": "En självhäftad, målfri vana spårningsverktyg.", + "A self-improving AI agent with memory, skills, messaging, and a web dashboard.": "En självförbättrande AI-agent med minne, färdigheter, meddelanden och en webbdashboard.", "A server reboot is recommended for all changes to take full effect.": "En omstart av servern rekommenderas för att alla ändringar ska få full effekt.", + "A shared directory was replaced during the installation": "En delad katalog ersattes under installationen", + "A shared source does not match its recorded identity": "En delad källa matchar inte sin registrerade identitet", + "A simple, open-source file sharing host.": "En enkel, öppen källkod fildelning värd.", + "A simple, private file server.": "En enkel, privat filserver.", + "A single matching image platform cannot be resolved": "En enda matchande bildplattform kan inte lösas", + "A single-platform OCI archive is required": "En enda plattform OCI arkiv är required", + "A stack backup is missing; a partial restore is not allowed": "En stack backup saknas; en partiell återställning är inte tillåten", + "A stack member has a different identity": "En stackmedlem har en annan identitet", "A system reboot is recommended to ensure all changes take effect.": "En omstart av systemet rekommenderas för att säkerställa att alla ändringar träder i kraft.", + "A third party companion app available to Plex server owners to allow their users to request, review and discover content.": "En tredjeparts följeslagare app tillgänglig för Plex serverägare att låta sina användare begära, granska och upptäcka innehåll.", + "A third-party client for self-hosted server and self-hosted server, remote access management interface, remote access to installed applications.": "En tredjepartsklient för egen värd server och egen värd server, fjärråtkomsthantering gränssnitt, fjärråtkomst till installerade applikationer.", + "A tmpfs mount is not part of the journal; recovery blocked": "En tmpfs montering är inte en del av tidskriften; återhämtning blockerad", + "A tmpfs mount overlaps another mount": "En tmpfs montering överlappar en annan montering", + "A tunneling daemon by Cloudflare that safely exposes your web servers into the internet.": "En tunneldemon av Cloudflare som säkert avslöjar dina webbservrar på internet.", + "A versatile file conversion tool that supports multiple formats.": "Ett mångsidigt filkonverteringsverktyg som stöder flera format.", + "A web GUI client of Project V which supports VMess, VLESS, SS, SSR, Trojan, Tuic and Juicity protocols": "En webb GUI klient av Project V som stöder VMess, VLESS, SS, SSR, Trojan, Tuic och Juicity protokoll", + "A web app to listen Youtube audio source.": "En webbapp för att lyssna Youtube ljudkälla.", + "A web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes": "En webbapp för att hantera dina tvåfaktorautentisering (2FA) konton och generera sina säkerhetskoder", + "A web frontend for the motion daemon.": "En webbfrontend för motion daemon.", + "A web-based file sharing and management protocol": "En webbaserad fildelning och managementprotokoll", + "A well-designed cross-platform ChatGPT UI.": "En väldesignad plattform ChatGPT UI.", "ACL Status:": "ACL-status:", "ACL permissions applied for local access for user:": "ACL-behörigheter tillämpas för lokal åtkomst för användare:", "ADVANCED SETTINGS COMPLETE": "AVANCERADE INSTÄLLNINGAR KLARA", "ALL DATA ON": "ALLA DATA PÅ", "ALL DATA ON THIS DISK WILL BE PERMANENTLY LOST!": "ALLA DATA PÅ DEN HÄR DISKEN KOMMER ATT FÖRLORAS PERMANENT!", "ALL Utilities": "ALLA Utilities", + "ALLOWED_HOSTS cannot contain line breaks": "ALLOWED HOSTS kan inte innehålla radbrytningar", + "AList initial login": "AList initial inloggning", "AMD CPU detected": "AMD CPU upptäckt", "AMD CPU fixes applied successfully": "AMD CPU-fixar har använts", "AMD GPU Tools installation completed!": "Installationen av AMD GPU Tools är klar!", "AMD GPU passthrough configured.": "AMD GPU-genomföring har konfigurerats.", "AMD GPU(s) detected:": "AMD GPU(s) upptäckt:", + "AMD KFD device": "AMD KFD-enhet", + "AMD VA-API + OpenCL (official mod)": "AMD VA-API + OpenCL (officiell mod)", "AMD fixes have been successfully reverted": "AMD-korrigeringar har återställts", "AMD mesa drivers installed.": "AMD mesa-drivrutiner installerade.", "AMD softdep configured": "AMD softdep konfigurerad", @@ -93,9 +157,21 @@ "About to restore": "På väg att återställa", "Absolute directory path to use as backup target:": "Absolut katalogsökväg att använda som mål för säkerhetskopiering:", "Absolute path to a file or directory you want backed up:": "Absolut sökväg till en fil eller katalog som du vill säkerhetskopiera:", + "Acceleration": "Acceleration", + "Acceleration configuration cancelled": "Acceleration konfiguration inställd", + "Acceleration for CodeProject.AI": "Acceleration för CodeProject. AI", + "Acceleration for Immich smart recognition": "Acceleration för Immich smart erkännande", + "Acceleration for Ollama": "Acceleration för Ollama", "Accept routes from other nodes?": "Acceptera rutter från andra noder?", + "Accept this host monitoring profile?": "Acceptera denna värdövervakningsprofil?", "Access Scope:": "Åtkomstomfång:", + "Access bridge": "Tillgång bridge", + "Access bridge for Immich": "Tillgångsbro för Immich", + "Access bridge for Nextcloud": "Tillgångsbro för Nextcloud", + "Access bridge for Paperless": "Tillgångsbro för papperslös", + "Access bridge for Tandoor": "Tillgångsbro för Tandoor", "Access profile:": "Åtkomstprofil:", + "Access token of the Jupyter Lab web interface": "Tillgångstoken av Jupyter Labs webbgränssnitt", "Account is not locked": "Kontot är inte låst", "Action cancelled due to previous xshok-proxmox modifications.": "Åtgärden avbröts på grund av tidigare xshok-proxmox-modifieringar.", "Action:": "Åtgärd:", @@ -105,6 +181,10 @@ "Active Connections": "Aktiva anslutningar", "Active exports:": "Aktiv export:", "Active session:": "Aktiv session:", + "Actual device path on the host": "Verklig enhetsväg på värden", + "Adaptation file too large": "Anpassningsfil för stor", + "Adaptation file with unexpected permissions or owner": "Anpassningsfil med oväntade behörigheter eller ägare", + "Adblock & DNS": "Adblock och DNS", "Add Audio Passthrough": "Lägg till Audio Passthrough", "Add CIFS storage:": "Lägg till CIFS-lagring:", "Add Controller or NVMe (PCI passthrough)": "Lägg till styrenhet eller NVMe (PCI passthrough)", @@ -123,6 +203,9 @@ "Add PBS": "Lägg till PBS", "Add Samba Share as Proxmox Storage": "Lägg till Samba-delning som Proxmox-lagring", "Add Samba share as Proxmox Storage": "Lägg till Samba-andel som Proxmox Storage", + "Add a Coral PCIe/M.2 device?": "Lägg till en Coral PCIe/M.2-enhet?", + "Add a custom data path?": "Lägg till en anpassad dataväg?", + "Add an extra custom path": "Lägg till en extra anpassad väg", "Add as IDE": "Lägg till som IDE", "Add as SATA": "Lägg till som SATA", "Add as SCSI": "Lägg till som SCSI", @@ -140,6 +223,7 @@ "Add import disk": "Lägg till importdisk", "Add latest Ceph support": "Lägg till senaste Ceph-stödet", "Add new PVE 9 enterprise repository (deb822 format) (Only if using enterprise):": "Lägg till nytt PVE 9-företagsarkiv (deb822-format) (endast om du använder företag):", + "Add or change a device": "Lägg till eller ändra en enhet", "Add physical disk to VM via": "Lägg till fysisk disk till VM via", "Add share block in /etc/samba/smb.conf:": "Lägg till delningsblock i /etc/samba/smb.conf:", "Add unprivileged flag to container configuration:": "Lägg till oprivilegierad flagga till behållarkonfigurationen:", @@ -154,20 +238,37 @@ "Adding": "Lägger till", "Adding CIFS storage to Proxmox...": "Lägger till CIFS-lagring till Proxmox...", "Adding QEMU Guest Agent support...": "Lägger till stöd för QEMU Guest Agent...", + "Adding Radarr to Prowlarr...": "Lägga till Radarr till Prowlarr", + "Adding Sonarr to Prowlarr...": "Lägga till Sonarr till Prowlarr", "Adding disk using the generated command to the selected VM": "Lägger till disk med det genererade kommandot till den valda virtuella datorn", "Adding existing users to sharedfiles group...": "Lägger till befintliga användare i gruppen sharedfiles...", "Adding iSCSI storage to Proxmox...": "Lägger till iSCSI-lagring till Proxmox...", "Adding new share to smb.conf...": "Lägger till ny delning till smb.conf...", + "Adding peers later means raising PEERS in /etc/pve/lxc/.conf and restarting the container. The existing peer keys are kept.": "Lägga till kamrater senare innebär att höja PEERS i /etc/pve/lxc/.conf och starta om behållaren. De befintliga peer-nycklarna hålls.", + "Adding the mount points...": "Lägga till monteringspunkterna...", "Adding this NVMe as a PCIe device (via 'Add Controller or NVMe PCIe to VM') gives better performance.": "Att lägga till denna NVMe som en PCIe-enhet (via \"Add Controller or NVMe PCIe to VM\") ger bättre prestanda.", "Adding to /etc/fstab for permanent mounting...": "Lägger till i /etc/fstab för permanent montering...", + "Additional URL advertised by Plex (optional)": "Ytterligare URL annonserad av Plex (tillval)", "Additional audio function(s) to be added": "Ytterligare ljudfunktion(er) ska läggas till", + "Additional media/GPU GIDs, comma-separated": "Ytterligare media/GPU GID, comma-separerade", + "Additional paths for": "Ytterligare vägar för", + "Address of the Compose file": "Adress för Compose-filen", + "Address to reach Pydio Cells (https://domain or https://IP:8080)": "Adress för att nå Pydio Cells (https://domain eller https://IP:8080)", + "Address used to reach wallabag (http://IP or https://wallabag.example.com)": "Adress som används för att nå wallabag (http://IP eller https://wallabag.example.com)", + "Addresses to update: ipv4, ipv6 or both (uses an external service)": "Adresser till uppdatering: ipv4, ipv6 eller båda (använder en extern tjänst)", + "Adguardhome Sync web interface": "Adguardhome Sync webbgränssnitt", + "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances.": "Adguardhome-sync är ett verktyg för att synkronisera AdGuardHome config till replika instanser.", "Adjust network/CIDR to your environment.": "Anpassa nätverk/CIDR till din miljö.", "Adjust options if needed (vers=4,hard,timeo,...).": "Justera alternativ om det behövs (vers=4, hård, timeo,...).", "Adjusting systemd-journald limits to match Log2RAM size...": "Justerar systemjournaliserade gränser för att matcha Log2RAM-storleken...", "Adjusts journald log level if needed (Proxmox defaults may block auth logs)": "Justerar nivån för journalad logg om det behövs (Proxmox standardinställningar kan blockera autentiseringsloggar)", + "Admin page": "Admin sida", + "Administrator email": "Administratörs e-post", + "Administrator password, at least 12 characters (empty = generated)": "Administratörslösenord, minst 12 tecken (tom = genererad)", "Advanced": "Avancerad", "Advanced Diagnostics": "Avancerad diagnostik", "Advanced Network Diagnostics": "Avancerad nätverksdiagnostik", + "Advanced: every setting of the container": "Avancerad: varje inställning av behållaren", "Affected LXC containers": "Berörda LXC-behållare", "After completing GPU setup, start the VM manually when the host is ready.": "När du har slutfört GPU-installationen startar du den virtuella datorn manuellt när värden är klar.", "After confirming, you will be asked to choose the NVIDIA driver version to install.": "Efter bekräftelse kommer du att bli ombedd att välja NVIDIA-drivrutinsversionen att installera.", @@ -183,11 +284,15 @@ "After the reboot you can follow the post-restore work live from ProxMenux Monitor → Backups tab (estimated time, per-component status, log tail, rollback delta).": "Efter omstarten kan du följa arbetet efter återställningen live från ProxMenux Monitor → Fliken Säkerhetskopiering (uppskattad tid, status per komponent, loggens slut, återställningsskillnad).", "After the reboot, you will only be able to access the Proxmox host via:": "Efter omstarten kommer du bara att kunna komma åt Proxmox-värden via:", "After this LXC → VM switch, reboot the host so the new binding state is applied cleanly.": "Efter denna LXC → VM-switch, starta om värden så att det nya bindningsläget tillämpas korrekt.", + "Airsonic Advanced web interface": "Airsonic Advanced webbgränssnitt", + "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room.": "Airsonic-advanced är en gratis, webbaserad media streamer, som ger ubiquitious tillgång till din musik. Använd den för att dela din musik med vänner, eller för att lyssna på din egen musik på jobbet. Du kan strömma till flera spelare samtidigt, till exempel till en spelare i ditt kök och en annan i ditt vardagsrum.", "Aliases added to .bashrc": "Alias ​​har lagts till i .bashrc", + "Alist Sync web interface": "Alist Sync webbgränssnitt", "All": "Alla", "All Available Scripts": "Alla tillgängliga skript", "All GPUs Already Assigned": "Alla GPU:er redan tilldelade", "All ProxMenux optimizations are up to date.": "Alla ProxMenux-optimeringar är uppdaterade.", + "All applications": "Alla applikationer", "All block devices:": "Alla blockerade enheter:", "All changes applied. No reboot required.": "Alla ändringar tillämpades. Ingen omstart krävs.", "All changes are reversible using the ProxMenux uninstaller.": "Alla ändringar är reversibla med avinstallationsprogrammet ProxMenux.", @@ -195,43 +300,79 @@ "All detected GPUs are already assigned to this VM.": "Alla upptäckta GPU:er är redan tilldelade den här virtuella datorn.", "All detected controllers/NVMe are already present in the selected VM.": "Alla upptäckta kontroller/NVMe finns redan i den valda virtuella datorn.", "All disks may already be in use or mounted.": "Alla diskar kanske redan används eller är monterade.", + "All images are downloaded and verified first, and native backups are taken with the stack stopped. Contracts are published after the whole set is checked. If anything fails, all members are recovered.": "Alla bilder laddas ner och verifieras först, och infödda säkerhetskopior tas med stacken stoppas. Kontrakt publiceras efter att hela uppsättningen kontrolleras. Om något misslyckas återhämtas alla medlemmar.", "All images imported and configured successfully": "Alla bilder har importerats och konfigurerats", "All imports failed": "Alla importer misslyckades", + "All of them are removed.": "Alla är borttagna.", "All partitions and metadata removed.": "Alla partitioner och metadata har tagits bort.", "All physical interfaces from backup are present on target": "Alla fysiska gränssnitt från säkerhetskopia finns på målet", + "All stack members are updated together. Main CT:": "Alla stackmedlemmar uppdateras tillsammans. Huvud CT:", "All types (images, backup, iso, vztmpl, snippets)": "Alla typer (bilder, säkerhetskopiering, iso, vztmpl, utdrag)", "All user-installed packages from the backup are present on this host": "Alla användarinstallerade paket från säkerhetskopian finns på denna värd", "All users with UID and GID": "Alla användare med UID och GID", "Allocate CPU Cores": "Tilldela CPU-kärnor", "Allocate RAM in MiB": "Tilldela RAM i MiB", + "Allowed hosts (comma separated; * allows access through the assigned IP)": "Tillåtna värdar (komma separerade; * tillåter åtkomst via den tilldelade IP)", "Already Mounted": "Redan monterad", "Already configured": "Redan konfigurerad", "Already installed — skipping": "Redan installerat — hoppar över", + "Also add the /dev/srX optical device (recommended)": "Lägg även till /dev/srX optisk enhet (rekommenderad)", "Also comment any remaining 'bookworm' entries in *.list if present.": "Kommentera även eventuella återstående \"Bookworm\"-poster i *.list om sådana finns.", "Also install the VirtIO network driver during setup to enable network access.": "Installera även VirtIO-nätverksdrivrutinen under installationen för att möjliggöra nätverksåtkomst.", "Although VFIO can bind to this device, full passthrough to a VM is": "Även om VFIO kan binda till den här enheten, är full passthrough till en virtuell dator", + "Altus is an Electron-based WhatsApp client with themes and multiple account support.": "Altus är en Electron-baserad WhatsApp-klient med teman och flera kontosupport.", + "Ambiguous mount points in the container": "tvetydiga monteringspunkter i behållaren", + "Ambiguous or invalid environment variable": "tvetydiga eller ogiltiga miljövariabel", "Amount of RAM in MiB (default: 4096)": "Mängd RAM i MiB (standard: 4096)", + "An AI model used to generate images conditioned on text descriptions.": "En AI-modell som används för att generera bilder som är konditionerade på textbeskrivningar.", "An AMD dedicated GPU has been detected without FLR support": "En AMD-dedikerad GPU har upptäckts utan FLR-stöd", "An AMD integrated GPU (APU) has been detected": "En AMD integrerad GPU (APU) har upptäckts", + "An Alist storage synchronization tool based on the Web interface.": "Ett Alist lagringssynkroniseringsverktyg baserat på webbgränssnittet.", + "An Industrial-Level Controllable and Efficient Zero-Shot Text-To-Speech System": "En industriell nivå kontrollerbar och effektiv noll-shot text-till-talsystem", "An Intel dedicated GPU has been detected without FLR support": "En dedikerad Intel GPU har upptäckts utan FLR-stöd", + "An accelerated video generation framework that speeds up end-to-end diffusion while preserving video quality": "En accelererad videogenereringsram som påskyndar end-to-end diffusion samtidigt som videokvaliteten bevaras", + "An executable required by the adapter is missing in the new image": "En körbar required av adaptern saknas i den nya bilden", "An fstab entry already exists for:": "En fstab-post finns redan för:", + "An image probe container was started externally": "En bildsond behållare startades externt", + "An include is not part of the journal; recovery blocked": "Ett inkluderar är inte en del av tidskriften; återhämtning blockerad", + "An include was modified outside the journal; recovery blocked": "Ett inkluderar ändrades utanför tidskriften; återhämtning blockerad", + "An open source generative AI development platform for building AI Agents and LLM workflows": "En öppen källkod generativ AI-utvecklingsplattform för att bygga AI-agenter och LLM-arbetsflöden", + "An operation of this installation has not finished; recover it from the management menu before removing it": "En operation av denna installation har inte slutförts; återhämta den från förvaltningsmenyn innan du tar bort den.", + "An update does not accept configuration changes": "En uppdatering accepterar inte konfigurationsändringar", "Analysis Tools": "Analysverktyg", + "Analysis software that shows your internet speed for up to 30 days.": "Analysprogramvara som visar din internethastighet i upp till 30 dagar.", "Analyze Bridge Configuration": "Analysera bryggkonfiguration", "Analyze Network Configuration": "Analysera nätverkskonfiguration", "Analyzing Bridge Configuration - READ ONLY MODE": "Analysera bryggkonfiguration - LÄGE ENDAST LÄS", "Analyzing Network Configuration - READ ONLY MODE": "Analysera nätverkskonfiguration - LÄGE ENDAST läs", "Analyzing selected disks...": "Analyserar valda diskar...", "Analyzing system for available PCIe storage devices...": "Analyserar system för tillgängliga PCIe-lagringsenheter...", + "Another OCI operation is using the instance registry": "En annan OCI operation använder instansregistret", + "Another OCI operation is using the instance registry. Wait for it to finish and open this menu again; no container is modified.": "En annan OCI operation använder instansregistret. Vänta på att den ska slutföra och öppna den här menyn igen; ingen behållare modifieras.", + "Another OCI operation is using the registry. This operation was not started.": "En annan OCI operation använder registret. Denna operation startades inte.", + "Another instance uses": "Ett annat exempel använder", + "Another stack operation is pending": "En annan stack operation väntar", + "Application": "Ansökan", + "Application responding:": "Ansökan svarar:", + "Application responding; checking its stability...": "Ansökan svarar; kontrollera dess stabilitet...", + "Application suite: one independent LXC per selected application": "Applikationspaket: en oberoende LXC per vald ansökan", + "Application:": "Ansökan:", + "Applications you can choose:": "Ansökningar du kan välja:", "Apply": "Tillämpas", "Apply AMD CPU fixes": "Tillämpa AMD CPU-fixar", "Apply Available Updates": "Tillämpa tillgängliga uppdateringar", "Apply and restart services:": "Tillämpa och starta om tjänster:", "Apply available updates": "Tillämpa tillgängliga uppdateringar", "Apply boot/initramfs changes": "Tillämpa boot/initramfs ändringar", + "Apply configuration": "Applicera konfiguration", "Apply fix now?": "Tillämpa fix nu?", "Apply fix now? (The share will be briefly remounted)": "Tillämpa fix nu? (Andelen kommer att återmonteras kort)", "Apply network optimizations": "Tillämpa nätverksoptimeringar", + "Apply optional security relaxation apparmor:rootlesskit": "Applicera valfri säkerhetsavslappning apparmor:rootlesskit", + "Apply optional security relaxation apparmor:unconfined": "Applicera valfri säkerhetsavslappning apparmor:obegränsad", + "Apply optional security relaxation seccomp:unconfined": "Applicera valfri säkerhetsavslappning seccomp:obegränsad", "Apply read+write access for 'others' on the host directory?": "Tillämpa läs+skrivbehörighet för \"andra\" på värdkatalogen?", + "Apply the options from the current catalog template? Your data and configuration are kept.": "Applicera alternativen från den aktuella katalogmallen? Din data och konfiguration hålls.", "Applying AMD-specific fixes...": "Tillämpar AMD-specifika korrigeringar...", "Applying Changes": "Tillämpa ändringar", "Applying Controller/NVMe passthrough to VM": "Tillämpar styrenhets-/NVMe-passthrough på VM", @@ -244,12 +385,21 @@ "Applying passthrough to CT": "Tillämpa passthrough till CT", "Applying safe paths and preparing pending restore": "Tillämpa säkra vägar och förbereda väntande återställning", "Applying selected LXC switch action": "Tillämpar vald LXC-omkopplaråtgärd", + "Applying the Jellyfin configuration:": "Applicera Jellyfin-konfigurationen:", + "Applying the LAN address to the application URLs...": "Applicera LAN-adressen till applikationsadresserna...", + "Applying the initial Nextcloud settings...": "Tillämpa de första Nextcloud-inställningarna...", + "Applying the mount mode...": "Applicera monteringsläget...", + "Apprise-api Takes advantage of Apprise through your network with a user-friendly API.": "Apprise-api Dra nytta av Apprise genom ditt nätverk med ett användarvänligt API.", + "Architecture": "Arkitektur", + "Architecture:": "Arkitektur:", + "Architectures": "Architectures", "Archive deleted.": "Arkiv raderat.", "Archive extracted.": "Arkiv utdraget.", "Archive format": "Arkivformat", "Archive ready": "Arkiv klar", "Archive size:": "Arkivstorlek:", "Archive:": "Arkiv:", + "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers.": "Ardour är en öppen källkod, samarbetsinsats av ett globalt team inklusive musiker, programmerare och professionella inspelningsingenjörer.", "Are you absolutely sure?": "Är du helt säker?", "Are you sure you want to continue?": "Är du säker på att du vill fortsätta?", "Are you sure you want to delete this export?": "Är du säker på att du vill ta bort denna export?", @@ -261,6 +411,7 @@ "Are you sure you want to unmount this NFS share?": "Är du säker på att du vill avmontera denna NFS-resurs?", "Are you sure you want to unmount this Samba share?": "Är du säker på att du vill avmontera denna Samba-delning?", "Are you sure?": "Är du säker?", + "Arr suite: applications to install": "Arr suite: program för att installera", "As Proxmox storage": "Som Proxmox-lagring", "As host fstab mount only": "Endast som värd fstab-montering", "Assign GPU PCI function to VM": "Tilldela GPU PCI-funktion till VM", @@ -275,14 +426,18 @@ "Attach imported disk to VM": "Bifoga importerad disk till VM", "Attach to an existing PVE vzdump job (inherit schedule + retention)": "Bifoga till ett befintligt PVE vzdump-jobb (ärv schema + retention)", "Attached to PVE job:": "Bifogat till PVE-jobb:", + "Attaching the volumes...": "Bifoga volymerna...", "Attempting automatic repair...": "Försöker automatisk reparation...", "Attempting passthrough with this GPU typically results in": "Försök att passera med denna GPU resulterar vanligtvis i", "Attention: Removing the subscription banner may cause issues in the web interface after a future update.": "Observera: Att ta bort prenumerationsbannern kan orsaka problem i webbgränssnittet efter en framtida uppdatering.", + "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source.": "Audacity är en lättanvänd, multi-track ljudredigerare och inspelare. Utvecklad av en grupp frivilliga som öppen källkod.", + "Audiobookshelf is a self-hosted audiobook and podcast server.": "Audiobookshelf är en själv värd ljudbok och podcast server.", "Audit completed. Press Enter to continue...": "Revision avslutad. Tryck på Enter för att fortsätta...", "Audit socket disabled or not required": "Granskningsuttaget inaktiverat eller inte nödvändigt", "Auth key is required.": "Auth-nyckel krävs.", "Auth:": "Auth:", "Authentication": "Autentisering", + "Authentication & Security": "Autentisering och säkerhet", "Authentication Error": "Autentiseringsfel", "Authentication failed.": "Autentiseringen misslyckades.", "Authentication required:": "Autentisering krävs:", @@ -301,7 +456,12 @@ "Auto-sync was not enabled": "Automatisk synkronisering var inte aktiverad", "Automated Post-Install Script": "Automatiserat efterinstallationsskript", "Automated post-installation script": "Automatiserat skript efter installation", + "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Automatisk videobibliotekschef för TV-program. Den tittar på nya avsnitt av dina favoritprogram, och när de publiceras gör den sin magi.", + "Automatic detection": "Automatisk upptäckt", + "Automatic private network allocation requires a /24 subnet": "Automatisk privat nätverksallokering requires a /24 subnet", + "Automatic video library manager for TV Shows": "Automatisk videobibliotekschef för TV-program", "Automatic/Unattended": "Automatisk/Obevakad", + "Automation & Scheduling": "Automatisering och schemaläggning", "Available": "Tillgänglig", "Available Borg archives (newest first):": "Tillgängliga Borg-arkiv (nyaste först):", "Available Borg targets:": "Tillgängliga Borg-mål:", @@ -322,17 +482,23 @@ "Available space in /mnt:": "Tillgängligt utrymme i /mnt:", "Available storage information:": "Tillgänglig lagringsinformation:", "Available storage volumes:": "Tillgängliga lagringsvolymer:", + "Azahar is an open-source 3DS emulator based on Citra.": "Azahar är en open-source 3DS emulator baserad på Citra.", "BIOS TYPE": "BIOS TYP", "BIOS Type": "BIOS-typ", "BIOS from": "BIOS från", "BIOS: OVMF (UEFI)": "BIOS: OVMF (UEFI)", + "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications.": "BOINC är en plattform för hög genomströmning av datorer i stor skala (tusentals eller miljontals datorer). Den kan användas för volontärbehandling (med hjälp av konsumentenheter) eller nätbehandling (med hjälp av organisatoriska resurser). Den stöder virtualiserade, parallella och GPU-baserade applikationer.", "BRIDGE CONFIGURATION ANALYSIS": "BROKONFIGURATIONSANALYS", "BTRFS:": "BTRFS:", + "Baby Buddy web interface": "Baby Buddy webbgränssnitt", + "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work.": "Babybuddy är en kompis för spädbarn! Hjälper vårdgivare spåra sömn, matningar, blöja förändringar, mage tid och mer att lära sig om och förutsäga barnets behov utan (så mycket) gissning arbete.", "Back to previous menu or Esc + Enter": "Tillbaka till föregående meny eller Esc + Enter", "Backed up and cleared": "Säkerhetskopierade och rensade", "Backend": "Backend", "Backend:": "Backend:", + "Background archive extraction for Arr download queues. No web interface.": "Bakgrund arkiv extraktion för Arr nedladdning köer. Inget webbgränssnitt.", "Backup — VM and CT backups": "Säkerhetskopiering — VM- och CT-säkerhetskopior", + "Backup & Recovery": "Backup & Recovery", "Backup Created": "Säkerhetskopiering skapad", "Backup ID (group name in PBS):": "Säkerhetskopierings-ID (gruppnamn i PBS):", "Backup ID for this job:": "Säkerhetskopierings-ID för detta jobb:", @@ -345,6 +511,7 @@ "Backup available at": "Säkerhetskopiering tillgänglig på", "Backup completed successfully.": "Säkerhetskopieringen har slutförts.", "Backup completed:": "Säkerhetskopiering slutförd:", + "Backup created": "Backup skapad", "Backup created:": "Säkerhetskopiering skapad:", "Backup declares unused NICs that are not on this host:": "Säkerhetskopia förklarar oanvända nätverkskort som inte finns på denna värd:", "Backup destination is inside the backup": "Säkerhetskopieringsdestinationen finns i säkerhetskopian", @@ -355,6 +522,7 @@ "Backup information": "Säkerhetskopia information", "Backup location": "Säkerhetskopieringsplats", "Backup metadata": "Säkerhetskopiera metadata", + "Backup of the previous installation verified": "Säkerhetskopiering av den tidigare installationen verifierad", "Backup on newer kernel:": "Säkerhetskopiering på nyare kärna:", "Backup on older kernel:": "Säkerhetskopiering på äldre kärna:", "Backup origin metadata:": "Metadata för säkerhetskopiering:", @@ -369,26 +537,42 @@ "Backup:": "Säkerhetskopiering:", "Backups already on PBS were encrypted with the current key — downloading them will fail unless you first Download the current keyfile to keep a copy.": "Säkerhetskopieringar som redan fanns på PBS var krypterade med den aktuella nyckeln — nedladdningen misslyckas om du inte först laddar ner den aktuella nyckelfilen för att behålla en kopia.", "Backups already stored on PBS were encrypted with the current keyfile. After this action:": "Säkerhetskopieringar som redan lagrats på PBS krypterades med den aktuella nyckelfilen. Efter denna åtgärd:", + "Backups verified": "Backups verifierad", + "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience.": "Bambu Studio är en open-source, cutting-edge, funktionsrik skivprogramvara. Den innehåller projektbaserade arbetsflöden, systematiskt optimerade skivningsalgoritmer och ett lättanvänt grafiskt gränssnitt, vilket ger användarna en otroligt smidig utskriftsupplevelse.", "Bandwidth limit configured": "Bandbreddsgräns konfigurerad", "Bandwidth test (iperf3)": "Bandbreddstest (iperf3)", "Bandwidth test completed successfully": "Bandbreddstestet slutförts framgångsrikt", "Base VM created with ID": "Bas-VM skapad med ID", + "Base VMID": "Base VMID", + "Base VMID (empty = next free block)": "Bas VMID (tomt = nästa fri block)", + "Base VMID of Nextcloud (empty = next free block)": "Bas VMID av Nextcloud (tom = nästa fri block)", + "Base VMID of Paperless (empty = next free block)": "Bas VMID av papperslös (tom = nästa fri block)", + "Base VMID of Tandoor (empty = next free block)": "Bas VMID av Tandoor (tom = nästa fri block)", + "Base VMID of the server (empty = next free block)": "Bas VMID på servern (tomma = nästa gratis block)", "Bash prompt path": "Sökväg i Bash-prompten", "Bashrc customization completed": "Bashrc-anpassning slutförd", "Basic Settings": "Grundinställningar", "Basic Utilities": "Grundläggande verktyg", + "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you.": "Bazarr är en följeslagare till Sonarr och Radarr. Det kan hantera och ladda ner undertexter baserat på dina requirements. Du definierar dina preferenser av TV-program eller film och Bazarr tar hand om allt för dig.", + "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools.": "Beets är en musikbibliotekschef och inte, för det mesta, en musikspelare. Det inkluderar en enkel spelarplugin och en experimentell webbaserad spelare, men det lämnar i allmänhet faktisk ljudreproduktion till specialiserade verktyg.", "Before making any changes, we'll create a safety backup.": "Innan vi gör några ändringar skapar vi en säkerhetskopia.", "Beta (develop branch)": "Beta (utveckla gren)", "Beta version:": "Betaversion:", "Binary not found in extracted content.": "Binärt hittades inte i extraherat innehåll.", "Bind mount added:": "Bindfäste har lagts till:", + "Bind mounts are not included in vzdump": "Bind montage ingår inte i vzdump", + "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services.": "Bitcoin Knots kan användas som en stationär klient för vanliga betalningar eller som en fullständig nod server verktyg för handlare och andra betalningstjänster.", "Blacklist nouveau driver": "Svartlista nouveau drivrutinen", "Blacklisting GPU host drivers...": "Svartar GPU-värddrivrutiner...", "Blacklisting nouveau driver...": "Blacklistar nouveau-drivrutinen...", + "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**": "Blender är en fri och öppen källkod 3D-datorgrafikprogramvara som används för att skapa animerade filmer, visuella effekter, konst, 3D-printade modeller, rörelsegrafik, interaktiva 3D-program, virtuell verklighet och datorspel. **Denna bild stöder inte GPU-återgivning ur lådan utan endast accelererad arbetsyta******", + "Blinko is an AI-powered card note-taking project. Designed for individuals who want to quickly capture and organize their fleeting thoughts. Blinko allows users to seamlessly jot down ideas the moment they strike, ensuring that no spark of creativity is lost.": "Blinko är ett AI-drivet kort noteringsprojekt. Designad för personer som vill qui fånga och organisera sina flyktiga tankar. Blinko gör det möjligt för användare att sömlöst jot ner idéer i det ögonblick de slår, så att ingen gnista av kreativitet går förlorad.", "Blocked GPU ID": "Blockerat GPU-ID", "Blocked GPU ID for VM Mode": "Blockerat GPU-ID för VM-läge", "Blocked device(s)": "Blockerade enheter", "Blocked device(s):": "Blockerade enheter:", + "BookStack web interface": "BookStack webbgränssnitt", + "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease.": "Bookstack är en gratis och öppen källkod Wiki utformad för att skapa vacker dokumentation. Med en enkel, men kraftfull WYSIWYG-redigerare gör det möjligt för team att skapa detaljerad och användbar dokumentation med lätthet.", "Boot Disk": "Startskiva", "Boot artifacts regenerated — reboot the host to activate the merged config.": "Startartefakter återskapade — starta om värden för att aktivera den sammanslagna konfigurationen.", "Boot disk:": "Startskiva:", @@ -415,9 +599,13 @@ "Bridge:": "Bro:", "Bridges analyzed": "Broar analyserade", "Broken gasket-dkms package state recovered.": "Det trasiga pakettillståndet för gasket-dkms återställdes.", + "Browse Your Life in Images": "Bläddra i ditt liv i bilder", "Browse manually (advanced)...": "Bläddra manuellt (avancerat)...", + "Browsers & Web Desktops": "Webbläsare & Web Desktops", "Build and install the gasket and apex kernel modules (DKMS)": "Bygg och installera kärnmodulerna gasket och apex (DKMS)", "Build dependencies installed.": "Byggberoenden installerade.", + "Build your personal knowledge base with TriliumNext Notes": "Bygg din personliga kunskapsbas med TriliumNext Notes", + "Business & ERP": "Business & ERP", "CHANGES APPLIED SUCCESSFULLY": "ÄNDRINGAR HAR TILLÄMPATS", "CIFS Client Tools: AVAILABLE": "CIFS-klientverktyg: TILLGÄNGLIGT", "CIFS Client Tools: NOT AVAILABLE - installing...": "CIFS-klientverktyg: EJ TILLGÄNGLIGT - installerar...", @@ -435,24 +623,35 @@ "CLUSTER UPGRADE NOTES:": "ANMÄRKNINGAR FÖR KLUSTERUPPGRADERING:", "CONFIGURED INTERFACES": "KONFIGURERADE GRÄNSSNITT", "CONFIRM FORMAT": "BEKRÄFTA FORMAT", + "CPU": "CPU", "CPU Cores": "CPU-kärnor", "CPU MODEL": "CPU MODELL", "CPU Model": "CPU modell", + "CPU cores": "CPU kärnor", + "CPU priority": "CPU-prioritet", "CPU set to host,hidden=1,flags=+pcid": "CPU inställd på host,hidden=1,flags=+pcid", "CPU vendor (intel/amd):": "CPU-leverantör (intel/amd):", "CRITICAL: The selected disk is referenced by a RUNNING VM or CT.": "KRITISKT: Den valda disken refereras av en RUNNING VM eller CT.", "CT": "CT", "CT started successfully.": "CT startade framgångsrikt.", + "CUDA requires a working NVIDIA driver": "CUDA requires en fungerande NVIDIA-förare", + "CUDA requires the NVIDIA Container Toolkit on the host": "CUDA requires NVIDIA Container Toolkit på värden", + "Calculate all kinds of statistics from your (local) Emby or Jellyfin server": "Beräkna alla typer av statistik från din (lokal) Emby eller Jellyfin-server", + "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts.": "Calibre är en kraftfull och enkel att använda e-bokschef. Användare säger att det är enastående och ett måste. Det låter dig göra nästan allt och det tar saker ett steg bortom normal e-bok programvara. Det är också helt gratis och öppen källkod och bra för både tillfälliga användare och datorexperter.", + "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself.": "Calibre-web är en webbapp som ger ett rent gränssnitt för att surfa, läsa och ladda ner e-böcker med en befintlig Calibre-databas. Det är också möjligt att integrera Google Drive och redigera metadata och ditt calibre-bibliotek genom själva appen.", + "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases.": "Calligra är ett kontor och grafisk konstsvit av KDE. Det är tillgängligt för stationära datorer, surfplattor och smartphones. Den innehåller applikationer för ordbehandling, kalkylblad, presentation, vektorgrafik och redigeringsdatabaser.", "Cancel": "Avbryt", "Cancel restore": "Avbryt återställning", "Cancel this setup": "Avbryt denna inställning", "Cancelled by user or empty URL.": "Avbruten av användare eller tom URL.", "Cancelled by user.": "Avbruten av användaren.", + "Cannot apply the Compose command:": "Kan inte tillämpa kommandot Compose:", "Cannot connect to server": "Kan inte ansluta till servern", "Cannot continue": "Kan inte fortsätta", "Cannot create:": "Kan inte skapa:", "Cannot detect filesystem on": "Kan inte identifiera filsystemet på", "Cannot find": "Kan inte hitta", + "Cannot identify the vendor of the device:": "Kan inte identifiera leverantören av enheten:", "Cannot load backup library: lib_host_backup_common.sh": "Det går inte att ladda säkerhetskopia-biblioteket: lib_host_backup_common.sh", "Cannot proceed with invalid export path.": "Kan inte fortsätta med ogiltig exportsökväg.", "Cannot proceed with invalid share name.": "Kan inte fortsätta med ogiltigt delningsnamn.", @@ -460,7 +659,11 @@ "Cannot reach download.proxmox.com. Check network, proxy or DNS.": "Kan inte nå download.proxmox.com. Kontrollera nätverk, proxy eller DNS.", "Cannot reach portal:": "Kan inte nå portalen:", "Cannot reach server": "Kan inte nå servern", + "Cannot read": "Kan inte läsa", + "Cannot read the OCI archive:": "Kan inte läsa OCI-arkivet:", "Cannot validate credentials - no shares available for testing.": "Kan inte validera autentiseringsuppgifter - inga delningar tillgängliga för testning.", + "Cannot verify the reused disk:": "Kan inte verifiera den återanvända disken:", + "Capabilities cannot be kept and all dropped at the same time": "Förmågor kan inte hållas och alla tappas samtidigt", "Category": "Kategori", "Caution: Maximum mode generates more heat.": "Varning: Maximalt läge genererar mer värme.", "Ceph check skipped by user flag (--ignore-ceph-check)": "Ceph-kontroll hoppas över av användarflaggan (--ignore-ceph-check)", @@ -487,14 +690,23 @@ "Ceph repository configured for PVE 9": "Ceph arkiv konfigurerat för PVE 9", "Ceph repository signature verification failed; installation has been stopped": "Ceph repository signaturverifiering misslyckades;installationen har stoppats", "Ceph version OK:": "Ceph version OK:", + "Certificate errors are logged in /config/log/letsencrypt inside the container.": "Certifikatfel loggas in /config/log/letsencrypt inuti behållaren.", "Certificate fingerprint of the PBS server:": "Certifikatfingeravtryck för PBS-servern:", + "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL": "Certifikatleverantör: tomt för Let's Encrypt, nollsl för ZeroSSL", + "Change GPU acceleration?": "Ändra GPU acceleration?", "Change Language": "Byt språk", "Change Release Channel": "Ändra releasekanal", + "Change it after the first login.": "Ändra den efter den första inloggningen.", + "Change or add an environment variable?": "Ändra eller lägg till en miljövariabel?", + "Change the access network?": "Ändra åtkomstnätet?", + "Changedetection.io provides free, open-source web page monitoring, notification and change detection.": "Changedetection.io ger gratis, öppen källkod webbsida övervakning, anmälan och förändringsdetektering.", "Changes applied. A system reboot is recommended for them to take full effect.": "Ändringar tillämpade. En omstart av systemet rekommenderas för att de ska få full effekt.", "Changes have been applied to the configuration file.": "Ändringar har tillämpats på konfigurationsfilen.", "Changes will apply after reboot.": "Ändringar kommer att gälla efter omstart.", "Changing Release Channel": "Ändra release-kanal", "Changing the machine type on an existing installed VM is not safe: it changes the chipset and PCI slot layout, which typically prevents the guest OS from booting.": "Det är inte säkert att ändra maskintyp på en befintlig installerad virtuell dator: det ändrar chipset och PCI-kortplatslayout, vilket vanligtvis förhindrar att gästoperativsystemet startar.", + "Changing the rootfs or its storage requires a separate migration": "Ändra rötterna eller dess lagring requires en separat migration", + "Changing the storage or size of a disk requires a migration; empty disks are not created": "Ändra lagring eller storlek på en disk requires en migrering; tomma diskar skapas inte", "Check": "Kontrollera", "Check BIOS/UEFI in Hardware > BIOS — must match what the original VM used": "Kontrollera BIOS/UEFI i Maskinvara > BIOS — måste matcha vad den ursprungliga virtuella datorn använde", "Check Coral USB/M.2 detection": "Kontrollera Coral USB/M.2-detektering", @@ -520,6 +732,7 @@ "Check the service status manually if needed.": "Kontrollera servicestatus manuellt vid behov.", "Checking MOTD configuration...": "Kontrollerar MOTD-konfiguration...", "Checking NVIDIA driver status with nvidia-smi": "Kontrollerar NVIDIA-drivrutinsstatus med nvidia-smi", + "Checking OCI": "Kontrollera OCI", "Checking VFIO modules...": "Kontrollerar VFIO-moduler...", "Checking VM virtual display model...": "Kontrollerar virtuell virtuell skärmmodell...", "Checking ZFS autotrim configuration...": "Kontrollerar ZFS autotrim-konfiguration...", @@ -531,7 +744,22 @@ "Checking if the server belongs to OVH...": "Kontrollerar om servern tillhör OVH...", "Checking kernel headers and build tools...": "Kontrollerar kärnrubriker och byggverktyg...", "Checking remaining interfaces": "Kontrollerar återstående gränssnitt", + "Checking that the container keeps running...": "Kontrollera att behållaren håller igång...", "Checking that this version builds against the running kernel...": "Kontrollera att den här versionen bygger mot den körande kärnan...", + "Checking the GPU of the machine learning container...": "Kontrollera GPU av maskininlärningsbehållaren...", + "Checking the container before recreating it...": "Kontrollera behållaren innan du återskapar den...", + "Checking the container before the update...": "Kontrollera behållaren innan uppdateringen...", + "Checking the device permissions for the application user...": "Kontrollera enhetens behörigheter för applikationsanvändaren...", + "Checking the image compatibility:": "Kontrollera bildkompatibiliteten:", + "Checking the image in the registry...": "Kolla bilden i registret...", + "Checking the interrupted operation...": "Kontrollera den avbrutna operation", + "Checking the interrupted stack operation...": "Kontrollera den avbrutna stacken operation...", + "Checking the new image without starting it:": "Kontrollera den nya bilden utan att starta den:", + "Checking the remote...": "Kontrollera fjärrkontrollen...", + "Checking the restored installation": "Kontrollera den återställda installationen", + "Checking the restored installation...": "Kontrollera den restaurerade installationen...", + "Checking the stack before the update...": "Kontrollera stacken innan uppdateringen...", + "Checking the updated stack...": "Kontrollera den uppdaterade stacken...", "Checklist post-upgrade finished. Warnings:": "Checklista efter uppgradering avslutad. Varningar:", "Checklist pre-check finished. Warnings:": "Checklista förhandskontroll avslutad. Varningar:", "Checks for LVM and storage issues": "Kontrollerar LVM och lagringsproblem", @@ -588,6 +816,9 @@ "Choose the type of virtual system to install:": "Välj vilken typ av virtuellt system som ska installeras:", "Choose what to do with the selected disk:": "Välj vad du ska göra med den valda disken:", "Choose where to save the backup:": "Välj var du vill spara säkerhetskopian:", + "Chrome is the official web browser from Google, built to be fast, secure, and customizable.": "Chrome är den officiella webbläsaren från Google, byggd för att vara snabb, säker och anpassningsbar.", + "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.": "Chromium är ett open-source webbläsarprojekt som syftar till att bygga ett säkrare, snabbare och mer stabilt sätt för alla användare att uppleva webben.", + "Circular dependency:": "Cirkulärt beroende:", "Clean disk metadata": "Rensa diskmetadata", "Cleaned up": "Rensat", "Cleaning cached files...": "Rensar cachade filer...", @@ -611,21 +842,29 @@ "Clearing login credentials...": "Rensar inloggningsuppgifter...", "Client (run a bandwidth test to a server)": "Klient (kör ett bandbreddstest till en server)", "Client determines best version to use": "Klienten bestämmer den bästa versionen att använda", + "Clients reach the VPN through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Kunderna når VPN via den offentliga adressen och UDP-porten som ges under installationen, så att porten måste vidarebefordras till denna behållare.", "Cloning Coral driver repository (feranick fork)...": "Cloning Coral drivrutinförråd (feranick gaffel)...", "Cloning Lynis from GitHub...": "Klonar Lynis från GitHub...", "Cloning and applying NVIDIA patch (keylase/nvidia-patch)...": "Kloning och applicering av NVIDIA-patch (keylase/nvidia-patch)...", "Closed": "Stängd", + "Cloud storage synchronization and FUSE mounts": "Cloud storage synkronisering och FUSE monteringar", "Cloud-Init Automated Installers": "Cloud-Init automatiserade installationsprogram", "Cluster certificates updated": "Klustercertifikat uppdaterade", "Cluster configuration (advanced)": "Klusterkonfiguration (avancerat)", "Cluster data will be applied automatically at next boot.": "Klusterdata kommer att tillämpas automatiskt vid nästa uppstart.", "Cluster upgrade mode": "Klusteruppgraderingsläge", + "Code-server is VS Code running on a remote server, accessible through the browser.": "Kod-server är VS-kod som körs på en fjärrserver, tillgänglig via webbläsaren.", + "CodeProject.AI Server": "CodeProject. AI Server", "Command": "Kommando", + "Command override for an unknown service:": "Kommando åsidosätter en okänd tjänst:", "Commenting any residual Bookworm lines in *.list...": "Kommenterar eventuella återstående Bookworm-rader i *.list...", "Commenting legacy PVE 8 repository .list files (if any)...": "Kommenterar äldre PVE 8-arkiv .list-filer (om några)...", "Commenting legacy ceph.list (if present)...": "Kommenterar äldre ceph.list (om sådan finns)...", "Common Issues Check": "Kolla vanliga problem", + "Common root for the published views": "Gemensam rot för de publicerade vyerna", + "Communication & Community": "Kommunikation och gemenskap", "Community Scripts": "Gemenskapsskript", + "Community single-container Home Assistant OS image": "Community single-container Home Assistant OS bild", "Compatibility check": "Kompatibilitetskontroll", "Compatibility check — OK": "Kompatibilitetskontroll — OK", "Compatibility check — issues detected": "Kompatibilitetskontroll — problem upptäckts", @@ -640,24 +879,31 @@ "Complete restore": "Fullständig återställning", "Complete the DSM installation wizard": "Slutför installationsguiden för DSM", "Complete the ZimaOS installation wizard": "Slutför installationsguiden för ZimaOS", + "Complete the media server and Seerr accounts, the Bazarr providers and the SABnzbd Usenet credentials when they are selected.": "Fyll i mediaservern och Seerr-konton, Bazarr-leverantörerna och SABnzbd Usenet-credentials när de väljs.", + "Completed": "Fullbordad", "Completed Successfully with GPU passthrough configured!": "Slutfört framgångsrikt med GPU-genomkoppling konfigurerad!", "Completed Successfully!": "Avslutad framgångsrikt!", "Completed with errors —": "Kompletterad med fel —", "Completed.": "Avslutad.", "Completed. Devices added to VM {vmid}: {count}.": "Klar. Enheter som har lagts till VM {vmid}: {count}.", "Completed. Press Enter to return to menu...": "Avslutad. Tryck på Enter för att återgå till menyn...", + "Completing its final cleanup...": "Slutför sin sista rengöring...", "Completing pending package configurations...": "Slutför väntande paketkonfigurationer...", "Compliance checking (PCI-DSS, HIPAA, etc.)": "Överensstämmelsekontroll (PCI-DSS, HIPAA, etc.)", "Component to uninstall manually (no --auto-uninstall yet):": "Komponent att avinstallera manuellt (ingen --auto-uninstall ännu):", "Component was installed on the backup source but no matching hardware was found on this host.": "Komponenten installerades på säkerhetskopian men ingen matchande maskinvara hittades på denna värd.", "Component:": "Komponent:", "Components to uninstall (manual for now):": "Komponenter att avinstallera (manual för tillfället):", + "Compose capabilities validated in the LXC user namespace:": "Komponera funktioner som valideras i LXC användarnamnrymden:", + "Compose file of the application": "Komponera fil för programmet", + "Compose file of this host": "Komponera filen för denna värd", "Compressed size:": "Komprimerad storlek:", "Compressing": "Komprimerar", "Compression Tools": "Kompressionsverktyg", "Concise output of logical volumes": "Kortfattad utdata av logiska volymer", "Concise output of physical volumes": "Kortfattad utdata av fysiska volymer", "Concise output of volume groups": "Kortfattad utdata av volymgrupper", + "Concurrent change while restoring the start at boot setting": "Samtidig förändring medan du återställer starten vid startinställningen", "Configuration Analysis": "Konfigurationsanalys", "Configuration Menu": "Konfigurationsmeny", "Configuration Summary:": "Konfigurationssammanfattning:", @@ -666,11 +912,13 @@ "Configuration can continue now and will be effective after reboot.": "Konfigurationen kan fortsätta nu och kommer att träda i kraft efter omstart.", "Configuration completed successfully!": "Konfigurationen slutfördes framgångsrikt!", "Configuration file for container": "Konfigurationsfil för behållare", + "Configuration files generated:": "Konfigurationsfiler som genereras:", "Configuration has been stopped due to high reset risk.": "Konfigurationen har stoppats på grund av hög återställningsrisk.", "Configuration has been stopped to prevent an unusable VM state.": "Konfigurationen har stoppats för att förhindra ett oanvändbart VM-tillstånd.", "Configuration has been stopped to prevent leaving the VM in an unusable state.": "Konfigurationen har stoppats för att förhindra att den virtuella datorn lämnas i ett oanvändbart tillstånd.", "Configuration name:": "Konfigurationsnamn:", "Configuration sections that will be REMOVED": "Konfigurationssektioner som kommer att tas bort", + "Configuration size in GB": "Konfigurationsstorlek i GB", "Configuration to be Removed": "Konfiguration som ska tas bort", "Configuration will continue now and be effective after reboot.": "Konfigurationen fortsätter nu och träder i kraft efter omstart.", "Configuration:": "Konfiguration:", @@ -713,6 +961,7 @@ "Configuring Proxmox jail...": "Konfigurerar Proxmox jail...", "Configuring TCP optimizations...": "Konfigurerar TCP-optimeringar...", "Configuring TPM device": "Konfigurerar TPM-enhet", + "Configuring Unpackerr...": "Konfigurera Unpackerr...", "Configuring VFIO modules...": "Konfigurerar VFIO-moduler...", "Configuring VM": "Konfigurerar VM", "Configuring bandwidth limit for vzdump...": "Konfigurerar bandbreddsgräns för vzdump...", @@ -728,8 +977,11 @@ "Configuring max FD limit / ulimit...": "Konfigurerar max FD limit / ulimit...", "Configuring max user watches...": "Konfigurerar max antal användares klockor...", "Configuring pigz as a faster replacement for gzip...": "Konfigurerar pigz som en snabbare ersättning för gzip...", + "Configuring qBittorrent...": "Konfigurera qBittorrent...", "Configuring snapshot schedules...": "Konfigurerar ögonblicksbildscheman...", "Configuring system time settings...": "Konfigurerar systemtidsinställningar...", + "Configuring the Radarr root folder...": "Konfigurera Radarr rotmapp...", + "Configuring the Sonarr root folder...": "Konfigurera Sonarr rotmapp...", "Configuring vfio-pci binding...": "Konfigurerar vfio-pci-bindning...", "Confirm Borg passphrase": "Bekräfta Borg lösenfras", "Confirm Borg passphrase:": "Bekräfta Borg lösenfras:", @@ -751,6 +1003,7 @@ "Confirm export": "Bekräfta export", "Confirm password for": "Bekräfta lösenord för", "Confirm recovery passphrase:": "Bekräfta återställningslösenord:", + "Confirm that host data is not reverted": "Bekräfta att värddata inte återställs", "Confirm the keyfile passphrase:": "Bekräfta nyckelfilens lösenfras:", "Confirm the mount path is visible.": "Kontrollera att monteringsvägen är synlig.", "Confirm the password:": "Bekräfta lösenordet:", @@ -762,7 +1015,11 @@ "Conflicting path included in backup:": "Motstridig sökväg som ingår i säkerhetskopieringen:", "Conflicting utilities removed": "Motstridiga verktyg har tagits bort", "Connect a Coral Accelerator and try again.": "Anslut en Coral Accelerator och försök igen.", + "Connect your devices and users together in your own secure virtual private network.": "Anslut dina enheter och användare tillsammans i ditt eget säkra virtuella privata nätverk.", + "Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.": "Anslut dina enheter till ett säkert WireGuard®-baserat överläggsnätverk med SSO, MFA och granulära åtkomstkontroller.", "Connected": "Ansluten", + "Connecting Radarr to qBittorrent...": "Anslut Radarr till qBittorrent", + "Connecting Sonarr to qBittorrent...": "Anslut Sonarr till qBittorrent", "Connecting to PBS and starting backup...": "Ansluter till PBS och startar säkerhetskopiering...", "Connection Details:": "Anslutningsinformation:", "Connection Error": "Anslutningsfel", @@ -774,6 +1031,7 @@ "Consider removing its configuration": "Överväg att ta bort dess konfiguration", "Consider security implications for production environments": "Tänk på säkerhetsimplikationer för produktionsmiljöer", "Consider visiting the repository and supporting the project.": "Överväg att besöka arkivet och stödja projektet.", + "Console log:": "Konsollogg:", "Container": "Behållare", "Container — LXC root directories": "Behållare — LXC-rotkataloger", "Container ID": "Behållar-ID", @@ -783,30 +1041,50 @@ "Container Path": "Containerväg", "Container Path:": "Behållarväg:", "Container Status": "Behållarstatus", + "Container checked": "Container kontrollerad", "Container configuration not found": "Behållarkonfigurationen hittades inte", + "Container configured (not started):": "Container konfigurerad (inte startad):", + "Container converted to privileged": "Container konverterade till privilegierad", + "Container created:": "Container skapade:", "Container did not become ready in time. Skipping driver installation.": "Containern blev inte klar i tid. Hoppa över installation av drivrutiner.", "Container did not start in time.": "Containern startade inte i tid.", "Container distro": "Container distro", "Container does not have apt-get available. Coral driver installation only supports Debian/Ubuntu containers.": "Container har inte apt-get tillgänglig. Coral-drivrutininstallation stöder endast Debian/Ubuntu-behållare.", + "Container installed, but without a verifiable record for future updates.": "Container installerad, men utan verifierbar post för framtida uppdateringar.", "Container is already stopped.": "Behållaren är redan stoppad.", "Container is running. Restart to apply changes?": "Container körs. Starta om för att tillämpa ändringar?", "Container is stopped. Start it now to verify the mount works?": "Behållaren är stoppad. Starta den nu för att kontrollera att monteringen fungerar?", + "Container kept with its data; the installation was not validated:": "Behållare hålls med sina uppgifter; installationen validerades inte:", "Container mount point:": "Behållarmonteringspunkt:", "Container must be stopped before conversion": "Behållaren måste stoppas före konvertering", + "Container prepared for the stack:": "Container förberedd för stacken:", + "Container recreated": "Container återskapad", + "Container removed:": "Container bort:", "Container restarted successfully": "Behållaren har startats om", + "Container running steadily": "Container kör stadigt", + "Container started": "Container startade", "Container started successfully": "Behållaren startade framgångsrikt", "Container started successfully.": "Behållaren startade framgångsrikt.", "Container started.": "Behållaren startade.", + "Container stopped": "Container stannade", "Container stopped.": "Containern stannade.", "Container successfully converted to privileged.": "Behållaren har konverterats till privilegierad.", "Container template— LXC templates": "Behållarmall— LXC-mallar", + "Container volume": "Containervolymen", + "Container volume (included in backups)": "Containervolym (ingår i backuper)", "Container will pick up the mount on next start": "Containern hämtar monteringen vid nästa start", "Container with ID": "Container med ID", "Container:": "Behållare:", + "Containers & Docker": "Containers och Docker", + "Containers returned to their previous state": "Containers återvände till sin tidigare stat", + "Containers that are removed:": "Behållare som tas bort:", + "Containers that will be created (one LXC per service, on a private network):": "Behållare som kommer att skapas (en LXC per tjänst, på ett privat nätverk):", + "Containers:": "Behållare:", "Contains files": "Innehåller filer", "Contains:": "Innehåller:", "Content Types": "Innehållstyper", "Content Types:": "Innehållstyper:", + "Content collaboration platform": "Content samarbetsplattform", "Content is usually images for VM block devices.": "Innehåll är vanligtvis bilder för VM-blockenheter.", "Content type is fixed to:": "Innehållstypen är fixerad till:", "Content:": "Innehåll:", @@ -817,10 +1095,12 @@ "Continue the Windows installation as usual.": "Fortsätt installationen av Windows som vanligt.", "Continue with Coral TPU configuration only?": "Fortsätt endast med Coral TPU-konfiguration?", "Continue with live apply now? SSH may disconnect immediately.": "Fortsätt med liveansökan nu? SSH kan kopplas ur omedelbart.", + "Continue with the experimental HAOS One profile?": "Fortsätt med experimentell HAOS One-profil?", "Continue with the import?": "Fortsätta med importen?", "Continue: Proceed with conversion": "Fortsätt: Fortsätt med konverteringen", "Continue?": "Fortsätta?", "Continuing with your selection.": "Fortsätter med ditt val.", + "Contradictory tmpfs options": "motsägelsefulla tmpfs alternativ", "Controller": "Kontroller", "Controller + NVMe": "Styrenhet + NVMe", "Controller + NVMe assignment will be written now and become active after host reboot.": "Tilldelningen av styrenhet + NVMe skrivs nu och aktiveras efter omstart av värden.", @@ -849,7 +1129,11 @@ "Converting disk": "Konverterar disk", "Converting file ownership (this may take several minutes)...": "Konverterar filägande (detta kan ta flera minuter)...", "Converting image using command:": "Konvertera bild med kommandot:", + "Converting the container to privileged...": "Konvertera behållaren till privilegierad...", "Converts to deb822; keeps .list backups as .bak": "Konverterar till deb822; behåller .list-säkerhetskopior som .bak", + "Coordinated backups require zstd": "Samordnade backups require zstd", + "Cops by Sébastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server.": "Cops av Sébastien Lucas, som nu underhålls av MikesPub, står för Calibre OPDS (och HTML) Php Server.", + "Copy a peer configuration to the host with: pct pull /config/peer1/peer1.conf peer1.conf": "Kopiera en peer konfiguration till värden med: pct pull /config/peer1/peer1.conf peer1.conf", "Copy failed": "Kopieringen misslyckades", "Copy that file offsite yourself, or download it from the Monitor.": "Kopiera filen utanför platsen själv, eller ladda ner den från monitorn.", "Copy the correct keyfile to this host and rerun Restore — or pick an unencrypted backup.": "Kopiera rätt nyckelfil till denna värd och kör Restore igen - eller välj en okrypterad säkerhetskopia.", @@ -864,6 +1148,7 @@ "Coral M.2 Apex configuration added - device ready": "Coral M.2 Apex-konfiguration har lagts till - enheten är klar", "Coral M.2 Apex configuration added - device will be available after reboot": "Coral M.2 Apex-konfiguration tillagd - enheten kommer att vara tillgänglig efter omstart", "Coral M.2 Apex detected, configuring...": "Coral M.2 Apex upptäcktes, konfigurerar...", + "Coral PCIe/M.2 node (e.g. /dev/apex_0)": "Coral PCIe/M.2 nod (t.ex. /dev/apex 0)", "Coral TPU Installation": "Coral TPU installation", "Coral TPU Uninstall": "Avinstallera Coral TPU", "Coral TPU device nodes detected with correct group (apex).": "Coral TPU-enhetsnoder upptäckts med korrekt grupp (apex).", @@ -876,19 +1161,33 @@ "Coral USB configured but device not currently connected": "Coral USB konfigurerad men enheten är inte ansluten för närvarande", "Coral USB runtime installed. No reboot required.": "Coral USB runtime installerad. Ingen omstart krävs.", "Coral hardware configuration completed for container": "Coral-maskinvarukonfiguration slutförd för behållaren", + "Coral is only offered for Frigate and CodeProject.AI": "Coral erbjuds endast för Frigate och CodeProject. AI", "Coral kernel modules unloaded.": "Coral kernel moduler urladdade.", "Coral packages purged.": "Coral-paket rensade.", "Coral uninstallation completed.": "Coral avinstallation slutförd.", "Core Proxmox packages reinstalled successfully": "Core Proxmox-paket har installerats om", + "Core is running, but not responding over HTTP on 80/8123": "Kärnan körs, men svarar inte över HTTP på 80/8123", + "Core is still on the initial installation page": "Kärnan finns fortfarande på den första installationssidan", "Core packages": "Kärnpaket", + "Cores": "Cores", + "Corrupted gzip layer": "Korrupt gzip lager", "Could not add": "Kunde inte lägga till", "Could not add disk": "Det gick inte att lägga till disk", + "Could not add the device to the container:": "Kunde inte lägga till enheten i behållaren:", + "Could not add the mount point:": "Kunde inte lägga till monteringspunkten:", + "Could not apply the Compose extra hosts": "Kunde inte tillämpa Compose extra värdar", + "Could not apply the Compose supplementary groups": "Kan inte tillämpa kompletterande grupper", + "Could not apply the Jellyfin configuration:": "Kan inte tillämpa Jellyfin-konfigurationen:", + "Could not apply the installer profile": "Kan inte tillämpa installationsprofilen", + "Could not apply the pre-start repair:": "Kan inte tillämpa förskottsreparationen:", "Could not assign disk": "Det gick inte att tilldela disk", "Could not authorize the key via 'pct exec' on": "Kunde inte auktorisera nyckeln via 'pct exec' på", "Could not back up the existing auth.json": "Det gick inte att säkerhetskopiera den befintliga auth.json", "Could not change VM virtual display to vga: std": "Det gick inte att ändra virtuell skärm till vga: std", + "Could not check the NVIDIA GPU": "Kan inte kontrollera NVIDIA GPU", "Could not clone any gasket-driver repository. Check your internet connection and": "Kunde inte klona något gasket-driver-arkiv. Kontrollera internetanslutningen och", "Could not configure IOMMU kernel parameters automatically. Configure manually and reboot.": "Kunde inte konfigurera IOMMU kärnparametrar automatiskt. Konfigurera manuellt och starta om.", + "Could not convert the OCI rootfs to privileged": "Kunde inte konvertera OCI rootfs till privilegierad", "Could not copy the PVE keyfile into place. Check permissions on:": "Det gick inte att kopiera PVE-nyckelfilen på plats. Kontrollera behörigheter på:", "Could not copy the keyfile into place.": "Kunde inte kopiera nyckelfilen på plats.", "Could not copy the keyfile into place. Check permissions on:": "Kunde inte kopiera nyckelfilen på plats. Kontrollera behörigheter på:", @@ -898,6 +1197,9 @@ "Could not create or access directory:": "Kunde inte skapa eller komma åt katalogen:", "Could not create temporary directory:": "Kunde inte skapa en tillfällig katalog:", "Could not create temporary working directory.": "Det gick inte att skapa en tillfällig arbetskatalog.", + "Could not create the container:": "Kunde inte skapa behållaren:", + "Could not create the initial administrator": "Kan inte skapa den första administratören", + "Could not create the service:": "Kunde inte skapa tjänsten:", "Could not detect apex major number from /proc/devices. Load the apex module first: modprobe apex": "Kunde inte detektera apex major-nummer från /proc/devices. Ladda apexmodulen först: modprobe apex", "Could not detect the CIFS mount for this directory. Try accessing it manually.": "Kunde inte detektera CIFS-monteringen för den här katalogen. Försök att komma åt det manuellt.", "Could not determine a valid ISO storage directory.": "Det gick inte att fastställa en giltig ISO-lagringskatalog.", @@ -907,7 +1209,9 @@ "Could not download recovery blob from PBS.": "Det gick inte att ladda ned återställningsblobb från PBS.", "Could not download the NVIDIA Container Toolkit repository definition.": "Det gick inte att ladda ned definitionen av NVIDIA Container Toolkit-förvaret.", "Could not download the NVIDIA Container Toolkit signing key.": "Det gick inte att ladda ner NVIDIA Container Toolkit-signeringsnyckeln.", + "Could not download the image": "Kunde inte ladda ner bilden", "Could not download the installer.": "Det gick inte att ladda ner installationsprogrammet.", + "Could not enable the privileged profile before the first start": "Kan inte aktivera den privilegierade profilen innan den första starten", "Could not export ZFS pool": "Det gick inte att exportera ZFS-poolen", "Could not extract from PBS.": "Det gick inte att extrahera från PBS.", "Could not fetch keylase/nvidia-patch supported list — patch reapply compatibility is not verified.": "Det gick inte att hämta keylase/nvidia-patch-stödd lista — kompatibilitet med återanvändning av patch är inte verifierad.", @@ -921,34 +1225,53 @@ "Could not install exFAT tools automatically.": "Kunde inte installera exFAT-verktyg automatiskt.", "Could not install sshpass automatically (no internet?). Falling back to manual paste mode — you'll see the line to copy onto the server next.": "Kunde inte installera sshpass automatiskt (inget internet?). Går du tillbaka till manuellt inklistrat läge - du kommer att se raden för att kopiera till servern härnäst.", "Could not install the NVIDIA Container Toolkit signing key.": "Det gick inte att installera NVIDIA Container Toolkit-signeringsnyckeln.", + "Could not install the required packages:": "Kan inte installera required-paketen:", + "Could not install the stack startup hook": "Kunde inte installera stack start hook", "Could not install vzdump hook in /etc/vzdump.conf": "Kunde inte installera vzdump hook i /etc/vzdump.conf", "Could not load shared functions. Script cannot continue.": "Det gick inte att ladda delade funktioner. Skriptet kan inte fortsätta.", + "Could not load the host kernel module:": "Kan inte ladda värdkärnans modul:", "Could not locate imported disk in VM config.": "Kunde inte hitta importerad disk i VM-konfiguration.", "Could not mount": "Kunde inte montera", "Could not mount ISO on device": "Det gick inte att montera ISO på enheten", + "Could not mount the container filesystem:": "Kunde inte montera containerfilsystemet:", + "Could not obtain an intact image after two attempts": "Kan inte få en intakt bild efter två försök", "Could not parse OVF file, or no disk image references found.": "Det gick inte att analysera OVF-filen eller så hittades inga referenser till diskbilden.", "Could not prepare on-boot restore service. Nothing new was scheduled.": "Kunde inte förbereda återställningstjänst vid uppstart. Inget nytt var inplanerat.", + "Could not prepare the NVIDIA driver links": "Kan inte förbereda NVIDIA-förarlänkar", + "Could not prepare the file bind mount target:": "Kunde inte förbereda filbindningsmålet:", "Could not publish pending restore. Previous pending restore was kept.": "Kunde inte publicera väntande återställning. Tidigare pågående återställning behölls.", "Could not push the key. Check the password and that": "Kunde inte trycka på nyckeln. Kolla lösenordet och så", + "Could not query the image registry": "Kunde inte fråga bildregistret", "Could not read SMART data from": "Det gick inte att läsa SMART-data från", "Could not read VM configuration.": "Det gick inte att läsa VM-konfigurationen.", + "Could not read the CUDA compute capability": "Kunde inte läsa CUDA-beräkningsförmågan", + "Could not read the NVIDIA driver version": "Kan inte läsa NVIDIA-förarversionen", "Could not remount automatically. Try manually or check credentials.": "Kunde inte montera om automatiskt. Försök manuellt eller kontrollera autentiseringsuppgifterna.", "Could not remove VM automatically. Run manually:": "Det gick inte att ta bort VM automatiskt. Kör manuellt:", "Could not remove previous DKMS tree at": "Det gick inte att ta bort tidigare DKMS-träd kl", + "Could not reserve a private network for the stack": "Kunde inte reservera ett privat nätverk för stacken", + "Could not resolve the Compose user:": "Kunde inte lösa Compose-användaren:", + "Could not resolve the OCI manifest of the image:": "Kunde inte lösa OCI-manifestet av bilden:", + "Could not resolve the OCI manifest:": "Kunde inte lösa OCI-manifestet:", "Could not restart ProxMenux Monitor service.": "Kunde inte starta om tjänsten ProxMenux Monitor.", "Could not restart the service — start it manually with systemctl start": "Kunde inte starta om tjänsten — starta den manuellt med systemctl start", "Could not retrieve versions list from NVIDIA. Please check your internet connection.": "Det gick inte att hämta versionslistan från NVIDIA. Kontrollera din internetanslutning.", + "Could not reuse the persistent disk:": "Kunde inte återanvända den ihållande disken:", "Could not run NVIDIA patch script. Please verify repository and driver version.": "Kunde inte köra NVIDIA patch script. Vänligen verifiera arkivet och drivrutinsversionen.", "Could not set VM virtual display to vga: std": "Det gick inte att ställa in virtuell skärm på vga: std", "Could not set boot order for": "Det gick inte att ställa in startordning för", + "Could not set the container entrypoint": "Kan inte ställa in behållarens ingångspunkt", "Could not stage pending restore path:": "Kunde inte scenen väntande återställningssökväg:", "Could not stage pending restore. Nothing new was scheduled.": "Kunde inte scenen väntande återställning. Inget nytt var inplanerat.", "Could not stop LXC": "Kunde inte stoppa LXC", + "Could not translate the Compose command/entrypoint": "Kunde inte översätta kommandot Compose/entrypoint", "Could not unload nouveau module (may be in use). The blacklist will take effect after reboot. Installation will continue but a reboot will be required.": "Kunde inte ladda ner nouveau-modulen (kan vara i bruk). Svartlistan träder i kraft efter omstart. Installationen kommer att fortsätta men en omstart kommer att krävas.", "Could not unmount": "Det gick inte att avmontera", + "Could not unmount the container filesystem:": "Kunde inte ta bort containerfilsystemet:", "Could not unmount — disk may be busy. Removing fstab entry anyway.": "Det gick inte att avmontera — disken kan vara upptagen. Tar bort fstab-posten ändå.", "Could not update config file.": "Kunde inte uppdatera konfigurationsfilen.", "Could not write to:": "Kunde inte skriva till:", + "Crafty Controller default login": "Crafty Controller standard inloggning", "Create Directory": "Skapa katalog", "Create GPT and one partition:": "Skapa GPT och en partition:", "Create GPT partition": "Skapa GPT-partition", @@ -971,6 +1294,7 @@ "Create a fresh GPT + ext4 partition and mount it?": "Skapa en ny GPT + ext4-partition och montera den?", "Create a new dataset in a ZFS pool": "Skapa en ny datauppsättning i en ZFS-pool", "Create a new group for isolation": "Skapa en ny grupp för isolering", + "Create and edit Matroska files from a browser": "Skapa och redigera Matroska-filer från en webbläsare", "Create credentials file (recommended):": "Skapa autentiseringsfil (rekommenderas):", "Create directory": "Skapa katalog", "Create export directory:": "Skapa exportkatalog:", @@ -982,6 +1306,7 @@ "Create scheduled backup job": "Skapa schemalagt säkerhetskopieringsjobb", "Create share directory:": "Skapa delningskatalog:", "Create shared directory:": "Skapa delad katalog:", + "Create this LXC in privileged mode?": "Skapa denna LXC i privilegierat läge?", "Created common remapped user": "Skapat gemensam ommappad användare", "Created directory on host:": "Skapat katalog på värd:", "Created persistent names for": "Skapat beständiga namn för", @@ -996,6 +1321,8 @@ "Creating UID remapping for unprivileged container compatibility...": "Skapar UID-ommappning för oprivilegierad containerkompatibilitet...", "Creating VM with the above configuration": "Skapar VM med ovanstående konfiguration", "Creating VM...": "Skapar VM...", + "Creating a backup of": "Skapa en backup av", + "Creating a backup of the container...": "Skapa en backup av behållaren...", "Creating backup of configuration file...": "Skapar säkerhetskopia av konfigurationsfil...", "Creating backup of network interfaces configuration...": "Skapar säkerhetskopia av nätverksgränssnittskonfiguration...", "Creating compressed archive...": "Skapar komprimerat arkiv...", @@ -1005,6 +1332,11 @@ "Creating partition table and partition...": "Skapar partitionstabell och partition...", "Creating partition...": "Skapar partition...", "Creating pigz wrapper script...": "Skapar pigz wrapper-skript...", + "Creating the backup": "Skapa backup", + "Creating the container...": "Skapa behållaren...", + "Creating the initial administrator...": "Skapa den första administratören...", + "Creating the temporary data container": "Skapa den tillfälliga databehållaren", + "Creative & Design": "Kreativ och design", "Credentials are correct": "Inloggningsuppgifterna är korrekta", "Credentials cleared. jwt_secret and API tokens preserved.": "Autentiseringsuppgifter rensade. jwt_secret och API-tokens bevarade.", "Credentials file created securely.": "Autentiseringsfil skapad på ett säkert sätt.", @@ -1014,6 +1346,8 @@ "Cross-host restore: guest IDs in backup overlap live IDs on target:": "Cross-host-återställning: gäst-ID:n i säkerhetskopia överlappar live-ID:n på målet:", "Cross-kernel restore — kernel-tied paths merged, not copied": "Korskärnåterställning — kärnbundna sökvägar sammanslagna, inte kopierade", "Cross-kernel — paths hidden from picker": "Cross-kernel — vägar dolda från väljaren", + "Cross-platform file sharing made easy.": "Cross-platform fildelning gjorde lätt.", + "Cross-platform monitoring tool.": "Cross-platform övervakningsverktyg.", "Cross-version detected — safe restore mode": "Korsversion upptäckt – säkert återställningsläge", "Current": "Nuvarande", "Current CIFS mounts:": "Aktuella CIFS-fästen:", @@ -1023,6 +1357,8 @@ "Current NFS client script supports privileged LXC only.": "Nuvarande NFS-klientskript stöder endast privilegierad LXC.", "Current NFS exports in CT": "Aktuell NFS-export i CT", "Current NFS mounts:": "Aktuella NFS-fästen:", + "Current NVIDIA inventory resolved: a refresh is required": "Nuvarande NVIDIA inventering löst: en uppfriskning är required", + "Current NVIDIA inventory resolved: no refresh is required": "Nuvarande NVIDIA inventering löst: ingen uppfriskning är required", "Current Network Configuration": "Aktuell nätverkskonfiguration", "Current PVE Version": "Aktuell PVE-version", "Current ProxMenux host scripts register remote shares as Proxmox storages using pvesm.": "Aktuella ProxMenux-värdskript registrerar fjärrresurser som Proxmox-lagringar med hjälp av pvesm.", @@ -1046,6 +1382,7 @@ "Current user": "Nuvarande användare", "Current user UID, GID and groups": "Aktuell användar-UID, GID och grupper", "Current version:": "Aktuell version:", + "Currently": "För närvarande", "Currently Mounted:": "För närvarande monterad:", "Currently configured target:": "För närvarande konfigurerat mål:", "Currently mounted:": "För närvarande monterad:", @@ -1066,6 +1403,7 @@ "Custom message added to MOTD": "Anpassat meddelande har lagts till i MOTD", "Custom options": "Anpassade alternativ", "Custom path": "Anpassad sökväg", + "Custom path cancelled": "Anpassad väg inställd", "Custom path...": "Anpassad sökväg...", "Custom paths are included in BOTH default and custom backup profiles.": "Anpassade sökvägar ingår i BÅDE standard- och anpassade säkerhetskopieringsprofiler.", "Custom paths currently saved: {count}.": "Anpassade sökvägar sparade för närvarande: {count}.", @@ -1078,6 +1416,8 @@ "Customization": "Anpassning", "Customize bashrc": "Anpassa bashrc", "Customizing bashrc for root user...": "Anpassar bashrc för root-användare...", + "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite.": "DB Browser för SQLite är ett högkvalitativt, visuellt, open source-verktyg för att skapa, designa och redigera databasfiler som är kompatibla med SQLite.", + "DHCP (automatic)": "DHCP (automatisk)", "DISABLED unless you enable it": "INAKTIVERAD om du inte aktiverar det", "DKMS add failed. Check": "DKMS-tillägg misslyckades. Kontrollera", "DKMS build failed.": "DKMS-bygget misslyckades.", @@ -1090,15 +1430,34 @@ "DKMS registrations removed.": "DKMS-registreringar har tagits bort.", "DNS Resolution": "DNS-upplösning", "DNS lookup for a domain": "DNS-sökning för en domän", + "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)": "DNS plugin används med dns validering (cloudflare, duckdns, ovh...)", + "DNS server written in the client configurations": "DNS-server skriven i klientkonfigurationerna", + "DNS server written in the peer configurations (auto or an IP address)": "DNS-server skriven i peer-konfigurationerna (auto eller en IP-adress)", + "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid.": "DOGWALK är Blender Studios efterlängtade andra spelprojekt, fokuserat på att skapa en bitformad interaktiv berättande lekplats. Spela som en stor bedårande hund och utforska vinterträ med lite barn.", + "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games.": "DOSBox Staging är en modern fortsättning av DOSBox en fri och öppen källkod emulator som möjliggör utförande av MS-DOS programvara, särskilt videospel.", + "DVB device directory": "DVB-enhetskatalog", + "Data": "Datadatadata data", + "Data location": "Data plats", "Data size:": "Datastorlek:", + "Data that is deleted with them:": "Data som raderas med dem:", + "Data volume size in GB": "Datavolymstorlek i GB", + "Data volumes protected": "Data volymer skyddade", "Data wipe complete.": "Datarensning klar.", "Data wiped from": "Data raderas från", + "Database management in a single PHP file": "Databashantering i en enda PHP-fil", + "Database server proposed on the login page (empty = typed at each login)": "Databasserver föreslagen på inloggningssidan (tom = skriven vid varje inloggning)", + "Databases": "Databaser", "Datastore name:": "Datastore namn:", + "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow.": "Davos är ett FTP-automationsverktyg som regelbundet skannar givna värdplatser för nya filer. Det kan konfigureras för olika ändamål, inklusive att lyssna på specifika filer som ska visas på värdplatsen, redo för att ladda ner och sedan flytta, om required. Det stöder också slutförande aviseringar samt nedströms API-samtal, för att främja arbetsflödet.", + "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways.": "Ddclient är en Perl-klient som används för att uppdatera dynamiska DNS-poster för konton på Dynamic DNS Network Service Provider. Det skrevs ursprungligen av Paul Burry och är nu mestadels av wimpunk. Det har förmågan att uppdatera mer än bara dyndner och det kan hämta din WAN-ipaddress på några olika sätt.", "Deactivate Monitor": "Inaktivera monitor", "Deactivate ProxMenux Monitor": "Inaktivera ProxMenux Monitor", "Debian repositories missing; creating default source file": "Debianförråd saknas; skapa standardkällfil", "Decompress backup manually": "Dekomprimera säkerhetskopia manuellt", "Decryption failed. The passphrase may be wrong, or the blob is corrupt. Try again?": "Dekrypteringen misslyckades. Lösenfrasen kan vara fel eller så är blubben korrupt. Försök igen?", + "Dedicated container volume (included in backups)": "Dedikerad behållarvolym (ingår i säkerhetskopior)", + "Dedicated container volumes (included in backups)": "Dedikerade behållarvolymer (ingår i säkerhetskopior)", + "DeepSeek Harness “Everything is a Plugin“.": "DeepSeek Harness ”Allt är en plugin”.", "Default ACLs applied for group inheritance.": "Standard ACL:er tillämpas för grupparv.", "Default Credentials": "Standardinloggningsuppgifter", "Default Gateway": "Standardgateway", @@ -1110,10 +1469,12 @@ "Default journald configuration restored": "Standard journalkonfiguration återställd", "Default location is /mnt/. The share will be mounted here on the host with open permissions so an unprivileged LXC can bind-mount and write to it. For LXC access, bind-mount this path with the LXC Mount Manager.": "Standardplatsen är /mnt/. Delingen kommer att monteras här på värden med öppna behörigheter så att en oprivilegierad LXC kan bind-mounta och skriva till den. För LXC-åtkomst, bind-montera den här sökvägen med LXC Mount Manager.", "Default location is /mnt/. The share will be mounted here on the host. Use this path in /etc/fstab. For LXC access, bind-mount this path with the LXC Mount Manager.": "Standardplatsen är /mnt/. Delen kommer att monteras här på värden. Använd denna sökväg i /etc/fstab. För LXC-åtkomst, bind-montera den här sökvägen med LXC Mount Manager.", + "Default login": "Standard inloggning", "Default options": "Standardalternativ", "Default options read/write": "Standardalternativ läs/skriv", "Default will be used:": "Standard kommer att användas:", "Default:": "Standard:", + "Default: only what the application needs": "Standard: endast vad programmet behöver", "Delete Borg target": "Ta bort Borgmål", "Delete Export": "Ta bort export", "Delete Share": "Ta bort delning", @@ -1122,7 +1483,10 @@ "Delete archive": "Ta bort arkiv", "Delete job": "Ta bort jobb", "Delete scheduled backup job?": "Ta bort schemalagt säkerhetskopieringsjobb?", + "Delete the image to free the space?": "Ta bort bilden för att frigöra utrymmet?", + "Delete the images to free the space?": "Ta bort bilderna för att frigöra utrymmet?", "Delete this corrupt archive and pick another": "Ta bort detta korrupta arkiv och välj ett annat", + "Deluge is a lightweight, Free Software, cross-platform BitTorrent client.": "Deluge är en lätt, fri programvara, tvärplattform BitTorrent-klient.", "Dependencies installed successfully": "Beroenden har installerats framgångsrikt", "Deploy with this configuration?": "Installera med den här konfigurationen?", "Deploying Secure Gateway...": "Implementerar Secure Gateway...", @@ -1177,9 +1541,15 @@ "Device added": "Enhet har lagts till", "Device already present in target VM — existing hostpci entry reused": "Enhet som redan finns i mål-VM — befintlig hostpci-post återanvänds", "Device assignments will be written now and become active after reboot.": "Enhetstilldelningar skrivs nu och blir aktiva efter omstart.", + "Device configuration cancelled": "Enhetskonfiguration inställd", "Device hostname": "Enhetens värdnamn", + "Device node outside the supported profiles": "Enhetsnoden utanför de stödda profilerna", + "Device outside the supported profiles; NVIDIA and device trees require another profile": "Enhet utanför de stödda profilerna; NVIDIA och enhetsträd require en annan profil", "Device path mismatch. Format cancelled.": "Enhetens sökväg matchar inte. Formatet avbröts.", + "Device permissions verified for the application user": "Enhetsbehörigheter som verifierats för användaren", "Device:": "Anordning:", + "Devices added to the container:": "Enheter som läggs till i behållaren:", + "Devices of the host it asks for:": "Enheter i värden som den begär:", "Devices to add to VM": "Enheter att lägga till i VM", "Diff: current system vs backup (--- system +++ backup)": "Diff: nuvarande system vs säkerhetskopia (--- system +++ säkerhetskopia)", "Different host. Backup from:": "Annorlunda värd. Säkerhetskopiering från:", @@ -1196,6 +1566,8 @@ "Directory does not exist and was not created.": "Katalogen finns inte och skapades inte.", "Directory does not exist:": "Katalogen finns inte:", "Directory error": "Katalogfel", + "Directory for the read-only view": "Directory för den läsbara vyn", + "Directory for the read/write view": "Directory för läs/skriv vy", "Directory not found": "Katalog hittades inte", "Directory storage added successfully to Proxmox!": "Kataloglagring har lagts till i Proxmox!", "Directory successfully.": "Katalog lyckades.", @@ -1248,6 +1620,7 @@ "Disk path:": "Diskväg:", "Disk safety revalidation failed.": "Omvalidering av disksäkerhet misslyckades.", "Disk safety validation passed.": "Disksäkerhetsvalidering godkänd.", + "Disk too small for the common profile": "Disk för liten för den gemensamma profilen", "Disk unmounted from": "Disk avmonterad från", "Disk verified and accessible inside CT at": "Disk verifierad och tillgänglig inuti CT kl", "Disk:": "Disk:", @@ -1261,6 +1634,10 @@ "Display physical volumes (LVM)": "Visa fysiska volymer (LVM)", "Display system summary in ASCII format": "Visa systemsammanfattning i ASCII-format", "Display volume groups (LVM)": "Displayvolymgrupper (LVM)", + "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer.": "Anta inte att port 8123 förblir aktiv efter ombordstigning på Home Assistant Core 2026.8 eller nyare.", + "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume.": "Påstå inte att OCI-bilduppdateringar på plats valideras tills rootfs-ersättning och rullning har testats utan att förlora den hanterade /mnt / datavolymen.", + "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default.": "aktivera inte automatiskt på ostödda AMD integrerade GPU. HSA-överskridanden är manuella kompatibilitetsexperiment, inte en validerad standard.", + "Do not mount": "Inte montera", "Do not run the upgrade from the Web UI virtual console (it will disconnect)": "Kör inte uppgraderingen från den virtuella webbgränssnittskonsolen (den kopplas från)", "Do not start the VM until the system has been rebooted.": "Starta inte den virtuella datorn förrän systemet har startat om.", "Do you want ProxMenux to stop it now?": "Vill du att ProxMenux ska stoppa det nu?", @@ -1304,9 +1681,23 @@ "Do you want to update the existing export?": "Vill du uppdatera den befintliga exporten?", "Do you want to update the existing share?": "Vill du uppdatera den befintliga andelen?", "Do you want to view the selected backup before restoring?": "Vill du se den valda säkerhetskopian innan du återställer?", + "Docker Mods are only offered for compatible LinuxServer images": "Docker Mods erbjuds endast för kompatibla LinuxServer-bilder", + "Docker Volume Backup": "Docker Volume Backup", + "Docker/CLI not available yet or no valid answer": "Docker/CLI är inte tillgängligt än eller inget giltigt svar", + "Documents & Notes": "Dokument och anteckningar", + "Documents volume size in GB": "Dokumentvolymstorlek i GB", + "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki.": "Dokuwiki är en enkel att använda och mycket mångsidig Open Source wiki programvara som inte require en databas. Det är älskat av användare för sin rena och läsbara syntax. Enkelt underhåll, backup och integration gör det till en administratörs favorit. Byggd i åtkomstkontroller och autentiseringskontakter gör DokuWiki särskilt användbart i företagssammanhang och det stora antalet plugins som bidragits av dess livliga samhälle möjliggör ett brett spektrum av användningsfall utöver en traditionell wiki.", + "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience.": "Dolphin Emulator låter dig spela GameCube och Wii-spel med olika grafiska förbättringar och andra funktioner är tillgängliga för att förbättra din spelupplevelse.", + "Domain for the certificate (example.com)": "Domän för certifikatet (example.com)", + "Doplarr is an *arr request bot for Discord.\"": "Doplarr är en \"arr request bot for Discord\".", + "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust.": "Doplarr_rs är en Discord bot för att begära media genom *arr backends, skriven i Rust.", + "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas.": "Double Commander är en gratis plattform öppen källkod filhanterare med två paneler sida vid sida. Den är inspirerad av Total Commander och har några nya idéer.", + "Download Spotify music with album art and metadata": "Ladda ner Spotify musik med albumkonst och metadata", "Download failed for all attempted URLs": "Nedladdningen misslyckades för alla försök till webbadresser", + "Download its Compose file from an address": "Ladda ner sin Compose-fil från en adress", "Download keyfile": "Ladda ner nyckelfil", "Download latest VirtIO ISO automatically": "Ladda ner senaste VirtIO ISO automatiskt", + "Downloaded OCI images deleted:": "Nedladdade OCI-bilder raderade:", "Downloaded amdgpu_top": "Laddade ner amdgpu_top", "Downloading": "Laddar ner", "Downloading Helper-Scripts logo...": "Laddar ned Helper-Scripts logotyp...", @@ -1318,45 +1709,86 @@ "Downloading amdgpu_top": "Laddar ner amdgpu_top", "Downloading official installer...": "Laddar ned det officiella installationsprogrammet...", "Downloading pre-existing encrypted backups from this host will fail unless you kept a copy of the current key.": "Nedladdning av redan existerande krypterade säkerhetskopior från denna värd kommer att misslyckas om du inte behåller en kopia av den aktuella nyckeln.", + "Downloading the image:": "Ladda ner bilden:", "Downloading the latest Fastfetch release...": "Laddar ner den senaste Fastfetch-versionen...", "Driver blacklist entries removed": "Drivrutinens svartlistade poster har tagits bort", "Driver blacklist removed for": "Svartlista för drivrutiner har tagits bort för", "Driver installed successfully. Press Enter to continue...": "Drivrutinen installerades framgångsrikt. Tryck på Enter för att fortsätta...", "Drivers :": "Drivrutiner:", "Drivers compiled and installed via DKMS.": "Drivrutiner kompilerade och installerade via DKMS.", + "Dry run completed; no changes were made.": "Torr kör slutförd; inga förändringar gjordes.", + "Dry run completed; no containers were created.": "Torr kör färdig; inga behållare skapades.", + "Dry run completed; the container and the mounts were not changed.": "Torr kör slutfördes; behållaren och fästen ändrades inte.", + "DuckDNS subdomain without .duckdns.org (comma separated for several)": "DuckDNS underdomän utan .duckdns.org (komma separerad för flera)", + "DuckDNS token from your account at duckdns.org": "DuckDNS token från ditt konto på duckdns.org", + "DuckDNS updates the subdomain every 5 minutes. Without UPDATE_IP, DuckDNS itself detects the public IPv4 address of the request.": "DuckDNS uppdaterar underdomänen var femte minut. Utan UPDATE IP upptäcker DuckDNS själv den offentliga IPv4-adressen för begäran.", + "DuckStation is a PS1 Emulator aiming for the best accuracy and game support.": "DuckStation är en PS1 Emulator som syftar till bästa accuracy och spelstöd.", + "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence.": "Duckdns är en gratis tjänst som kommer att peka en DNS (sub domäner av duckdns.org) till en IP av ditt val. Tjänsten är helt gratis, och require reaktivering eller forumposter för att behålla sin existens.", "Dumping AMD GPU ROM BIOS via sysfs...": "Dumpar AMD GPU ROM BIOS via sysfs...", "Duplicate IP addresses found": "Dubbletter av IP-adresser hittades", "Duplicate parameters cleaned": "Duplikatparametrar rensade", + "Duplicate variable in the contract; review it before editing": "Duplicera variabel i kontraktet; granska det innan du redigerar", + "Duplicated GPU device in the container": "Duplicerad GPU-enhet i behållaren", + "Duplicated NVIDIA devices": "Duplicerade NVIDIA-enheter", + "Duplicated VMID in the Proxmox inventory": "Duplicerad VMID i Proxmox inventeringen", + "Duplicated native directive:": "Duplicerat inhemskt direktiv:", + "Duplicated native option": "Duplicerat inhemskt alternativ", + "Duplicated or invalid stack VMID": "Duplicerad eller ogiltig stack VMID", + "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others.": "Duplicati är en backup-klient som säkert lagrar krypterade, inkrementella, komprimerade säkerhetskopior på lokal lagring, molnlagringstjänster och fjärrfilservrar. Det fungerar med standardprotokoll som FTP, SSH, WebDAV samt populära tjänster som Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2 och många andra.", + "Duplicati web interface (password only)": "Duplicati webbgränssnitt (endast lösenord)", "Duration": "Varaktighet", "Duration:": "Varaktighet:", + "Dynamic NVIDIA is only validated for unprivileged containers. This profile uses static mounts and must be recreated after the host driver changes.": "Dynamisk NVIDIA valideras endast för oprivilegierade behållare. Denna profil använder statiska fästen och måste återskapas efter att värdföraren ändras.", "EFI disk created and configured on": "EFI-disk skapad och konfigurerad på", "EFI storage selection cancelled.": "Val av EFI-lagring avbröts.", "EFI storage selection failed or was cancelled. VM creation aborted.": "Val av EFI-lagring misslyckades eller avbröts. VM-skapandet avbröts.", "EMERGENCY PROXMOX SYSTEM REPAIR": "NÖDREPARATION AV PROXMOX-SYSTEM", "ENABLED for restore": "AKTIVERAD för återställning", "EXISTS": "FINNS", + "Each /request command needs a backend: add a [[backends]] block in the same file with the url and api_key of your Sonarr, Radarr or Seerr instance, then restart the container.": "Varje / begäran kommandot behöver en backend: lägga till en [backends] block i samma fil med url och api key av din Sonarr, Radarr eller Seerr instans, sedan starta om behållaren.", "Each LUN will appear as a block device assignable to VMs.": "Varje LUN kommer att visas som en blockenhet som kan tilldelas virtuella datorer.", + "Each peer gets its configuration and its QR code inside the container: /config/peer1/peer1.conf and /config/peer1/peer1.png, or /config/peer_/peer_.conf when names were given.": "Varje peer får sin konfiguration och sin QR-kod inuti behållaren: /config/peer1/peer1.conf och/config/peer1/peer1.png eller/config/peer /peer .conf när namnen gavs.", + "Ebook and audiobook collection manager for Usenet and BitTorrent users.": "Ebook och ljudbok samlingschef för Usenet och BitTorrent användare.", + "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind.": "Eden är en experimentell open-source emulator för Nintendo Switch, byggd med prestanda och stabilitet i åtanke.", "Edge TPU runtime installed.": "Edge TPU runtime installerad.", "Edit raw CT configuration file": "Redigera rå CT-konfigurationsfil", "Edit raw VM configuration file": "Redigera rå VM-konfigurationsfil", "Edit the VM machine type to q35 and try again.": "Redigera VM-maskintypen till q35 och försök igen.", + "Email address for certificate expiry notices (required by ZeroSSL)": "E-postadress för certifikatutgångsmeddelanden (required av ZeroSSL)", + "Email address of the LibreDB Studio administrator": "E-postadress till LibreDB Studio-administratören", + "Email address of the NetBox admin account": "E-postadress för NetBox administratörskonto", + "Emby WebUI": "Emby WebUI", + "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server.": "Emby organiserar video, musik, live-TV och bilder från personliga mediebibliotek och strömmar dem till smarta TV-apparater, streamingboxar och mobila enheter. Denna behållare är förpackad som en fristående emby Media Server.", "Emergency Proxmox System Repair": "Akut reparation av Proxmox-system", "Emergency recovery:": "Nödåterställning:", + "Empowering the smart home": "Att stärka det smarta hemmet", "Empty": "Tömma", + "Empty exec service check": "Tom exec service check", + "Empty or duplicated NVIDIA identity": "Tomma eller duplicerade NVIDIA-identitet", + "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes.": "EmulatorJS är en Docker-baserad emulatorapplikation som kan simulera olika operating system och enhetsmiljöer inom behållare för utveckling, testning och inlärningsändamål.", "Enable": "Aktivera", "Enable / disable job timer": "Aktivera/inaktivera jobbtimer", "Enable High Availability services": "Aktivera tjänster med hög tillgänglighet", "Enable IOMMU in GRUB or ZFS boot": "Aktivera IOMMU i GRUB- eller ZFS-start", "Enable IOMMU support if not enabled": "Aktivera IOMMU-stöd om det inte är aktiverat", "Enable IOMMU, reboot the host, and try again.": "Aktivera IOMMU, starta om värden och försök igen.", + "Enable Intel/AMD VA-API video acceleration": "Aktivera Intel/AMD VA-API video acceleration", + "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping": "Aktivera NVIDIA-överkodning och HDR10/Dolby Vision till SDR-tonkartläggning", "Enable Remote Desktop (RDP) before disabling the virtual display.": "Aktivera Remote Desktop (RDP) innan du inaktiverar den virtuella skärmen.", "Enable SSD emulation for this disk?": "Vill du aktivera SSD-emulering för den här disken?", "Enable TCP BBR/Fast Open control": "Aktivera TCP BBR/Fast Open-kontroll", + "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping": "Aktivera VA-API-transkodning och HDR10/Dolby Vision till SDR-tonkartläggning", + "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin": "Aktivera VA-API, hårdvarukodning och OpenCL tonkartläggning i Jellyfin", "Enable VFIO IOMMU support": "Aktivera VFIO IOMMU-stöd", "Enable ZFS autotrim (SSD/NVMe pools)": "Aktivera ZFS autotrim (SSD/NVMe-pooler)", + "Enable a mount on an existing Rclone OCI container": "Möjliggöra en montering på en befintlig Rclone OCI behållare", + "Enable an optical drive for MakeMKV": "Aktivera en optisk enhet för MakeMKV", "Enable auto-sync if /var/log exceeds 90% of its size?": "Aktivera automatisk synkronisering om /var/log överstiger 90 % av storleken?", "Enable fast reboots": "Aktivera snabba omstarter", "Enable restart on kernel panic": "Aktivera omstart vid kernel panic", + "Enable the NVIDIA GPU requested by the image": "Aktivera NVIDIA GPU begärd av bilden", + "Enable the NVIDIA GPU required by Open WebUI CUDA": "Möjliggöra NVIDIA GPU required av Open WebUI CUDA", + "Enable this FUSE mount now and restart the CT?": "Möjliggör denna FUSE-fäste nu och startar om CT?", "Enable/Disable job": "Aktivera/inaktivera jobb", "Enabled": "Aktiverad", "Enabled (device pending — load apex module or reboot)": "Aktiverad (enhet väntar - ladda apexmodul eller starta om)", @@ -1401,6 +1833,7 @@ "Enter a name for the mount point (used as /mnt/):": "Ange ett namn för monteringspunkten (används som /mnt/):", "Enter a name for the new virtual machine:": "Ange ett namn för den nya virtuella maskinen:", "Enter a number, or write or paste a command:": "Ange ett nummer, eller skriv eller klistra in ett kommando:", + "Enter a usable IPv4 address with its prefix, for example": "Ange en användbar IPv4-adress med dess prefix, till exempel", "Enter backup file (.zst):": "Ange backupfil (.zst):", "Enter backup path (.tar.zst):": "Ange backupsökväg (.tar.zst):", "Enter backup path (.vma.zst):": "Ange backupsökväg (.vma.zst):", @@ -1489,6 +1922,7 @@ "Enter the number or type the interface name:": "Ange numret eller skriv gränssnittets namn:", "Enter the password for Samba user:": "Ange lösenordet för Samba-användare:", "Enter the recovery passphrase set when the keyfile was created:": "Ange återställningslösenordet som angavs när nyckelfilen skapades:", + "Enter the size in whole GB, for example": "Ange storleken i hela GB, till exempel", "Enter username for Samba server:": "Ange användarnamn för Samba-servern:", "Enter username:": "Ange användarnamn:", "Enterprise Proxmox Ceph repository disabled": "Enterprise Proxmox Ceph arkiv inaktiverat", @@ -1497,6 +1931,8 @@ "Enterprise repository returned 401 Unauthorized (no valid subscription). Switch to the no-subscription repository and retry?": "Enterprise arkiv returnerade 401 Unauthorized (ingen giltig prenumeration). Byt till arkivet utan prenumeration och försök igen?", "Enterprise repository unauthorized and fallback declined by user": "Enterprise arkiv obehörigt och reserv avvisad av användaren", "Entropy generation optimization removed": "Entropigenereringsoptimering har tagits bort", + "Environment entry without an explicit value": "Miljöinträde utan uttryckligt värde", + "Environment override for an unknown service:": "Miljööverskridande för en okänd tjänst:", "Equivalent manual flow of disk_host.sh: partition, format, mount, persist, register in Proxmox.": "Motsvarande manuellt flöde av disk_host.sh: partition, format, mount, persist, registrera i Proxmox.", "Equivalent manual flow of iscsi_host.sh.": "Motsvarande manuellt flöde av iscsi_host.sh.", "Equivalent manual flow used by Local Shared Manager.": "Motsvarande manuellt flöde som används av Local Shared Manager.", @@ -1512,12 +1948,16 @@ "Error: No write permissions in directory": "Fel: Inga skrivbehörigheter i katalogen", "Essential Proxmox packages installed": "Viktiga Proxmox-paket installerade", "Estimated required free space:": "Beräknat ledigt utrymme:", + "Etherpad admin page": "Etherpad admin sida", "Every 12 hours": "Var 12:e timme", "Every 3 hours": "Var 3:e timme", "Every 6 hours": "Var 6:e ​​timme", + "Every fail2ban jail ships disabled. Enable the ones you need in /config/fail2ban/jail.local, taking the ready-made jails in /config/fail2ban/jail.d/ as reference, then restart the container.": "Varje fail2ban fängslade fartyg. Möjliggöra de du behöver i /config / fail2ban /jail.local, ta de färdiga fängelserna i /config / fail2ban /jail.d / som referens, sedan starta om behållaren.", "Every hour": "Varje timme", + "Every member of the stack is back to its previous installation.": "Varje medlem av stacken är tillbaka till sin tidigare installation.", "Every path in this backup is kernel-tied: the restore applies these paths automatically via the safe-subset filter and re-merges the operator's tuning.": "Varje sökväg i denna säkerhetskopia är kärnbunden: återställningen tillämpar dessa sökvägar automatiskt via filtret för säker delmängd och slår samman operatörens inställning.", "Everything restorable in this backup will be restored": "Allt som går att återställa i denna säkerhetskopia kommer att återställas", + "Exact name of the remote": "Exakt namn på fjärrkontrollen", "Example output: rootfs: local-lvm:vm-114-disk-0,size=8G": "Exempelutgång: rootfs: local-lvm:vm-114-disk-0,size=8G", "Example target: /dev/sdb": "Exempelmål: /dev/sdb", "Example: /dev/pve/vm-114-disk-0": "Exempel: /dev/pve/vm-114-disk-0", @@ -1537,7 +1977,9 @@ "Execute destructive rollback?": "Utföra destruktiv återställning?", "Executing destructive rollback (operator confirmed) ...": "Utför destruktiv återställning (operatör bekräftad) ...", "Executing:": "Utför:", + "Execution engine for Index-TTS": "Exekveringsmotor för Index-TTS", "Existing Groups": "Befintliga grupper", + "Existing TLS certificate reused:": "Befintligt TLS-certifikat återanvänds:", "Existing file, re-downloading...": "Befintlig fil, laddar ned igen...", "Existing filesystem:": "Befintligt filsystem:", "Existing hostpci entries detected — they will be reused": "Befintliga hostpci-poster har upptäckts – de kommer att återanvändas", @@ -1581,7 +2023,9 @@ "Extended Filesystem 4 (recommended)": "Utökat filsystem 4 (rekommenderas)", "External ZFS ARC settings restored:": "Externa ZFS ARC-inställningar återställdes:", "External ZFS configuration changed after the ProxMenux migration; current file and backup preserved:": "Den externa ZFS-konfigurationen ändrades efter ProxMenux-migreringen; aktuell fil och säkerhetskopia bevarades:", + "External credential is empty or spans multiple lines": "Extern credential är tom eller spänner över flera linjer", "External disk for backup": "Extern disk för säkerhetskopiering", + "External field not reserved:": "Externa fält som inte är reserverade:", "Extracting NVIDIA installer on host...": "Extraherar NVIDIA-installationsprogram på värd...", "Extracting OVA archive...": "Extraherar OVA-arkiv...", "Extracting archive...": "Extraherar arkiv...", @@ -1592,7 +2036,9 @@ "Extraction failed. Check log:": "Extrahering misslyckades. Kontrollera logg:", "Extraction successful": "Utvinningen lyckades", "FAILED": "MISLYCKADES", + "FFmpeg version the node uses (7 by default)": "FFmpeg version noden använder (7 som standard)", "FINAL CONFIRMATION — DATA WILL BE ERASED": "SLUTLIG BEKRÄFTELSE — DATA KOMMER ATT RADERAS", + "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface.": "FIleZilla Kund är en snabb och pålitlig plattform FTP, FTPS och SFTP-klient med massor av användbara funktioner och ett intuitivt grafiskt användargränssnitt.", "Fail2Ban - Intrusion Prevention": "Fail2Ban - Intrångsskydd", "Fail2Ban Management": "Fail2Ban-hantering", "Fail2Ban has been removed": "Fail2Ban har tagits bort", @@ -1602,6 +2048,7 @@ "Fail2Ban is currently installed.": "Fail2Ban är för närvarande installerat.", "Fail2Ban is not installed on this system.": "Fail2Ban är inte installerat på detta system.", "Fail2Ban is running correctly": "Fail2Ban körs korrekt", + "Fail2ban is a daemon to ban hosts that cause multiple authentication errors.": "Fail2ban är en daemon att förbjuda värdar som orsakar flera autentiseringsfel.", "Failed": "Misslyckades", "Failed to access log2ram directory": "Det gick inte att komma åt log2ram-katalogen", "Failed to access share with provided credentials.": "Det gick inte att komma åt delningen med angivna autentiseringsuppgifter.", @@ -1748,6 +2195,9 @@ "Failed. See log:": "Misslyckades. Se logg:", "Falling back to each installer with --auto-reinstall...": "Faller tillbaka till varje installationsprogram med --auto-reinstall...", "Falling back to manual paste mode.": "Går tillbaka till manuellt klistra-läge.", + "Fast Usenet downloader with a SABnzbd-compatible API": "Fast Usenet downloader med en SABnzbd-kompatibel API", + "Fast, modern web interface for qBittorrent": "Snabbt, modernt webbgränssnitt för qBittorrent", + "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper.": "Faster-whisper är en ombyggnad av OpenAI: s Whisper modell med CTranslate2, som är en snabb inferens motor för Transformer modeller. Denna behållare ger en Wyoming-protokollserver för snabbare viskning.", "Fastfetch Logo Selection": "Fastfetch Logo Selection", "Fastfetch configuration updated": "Fastfetch-konfigurationen uppdaterad", "Fastfetch download URL retrieved successfully.": "Fastfetch-nedladdnings-URL har hämtats.", @@ -1759,19 +2209,31 @@ "Fastfetch now displays: System optimised by: ProxMenux": "Fastfetch visar nu: System optimerat av: ProxMenux", "Fastfetch removed from system": "Fastfetch togs bort från systemet", "Fastfetch will start automatically in the console": "Fastfetch startar automatiskt i konsolen", + "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application.": "Ferdium är en skrivbordsapp som hjälper dig att organisera hur du använder dina favoritappar genom combining dem i en applikation.", "Fetching NVIDIA driver versions supported by your GPU...": "Hämtar NVIDIA-drivrutinsversioner som stöds av din GPU...", "Figurine installation and configuration completed successfully.": "Figurinstallation och konfiguration har slutförts framgångsrikt.", "Figurine is not installed.": "Figuren är inte installerad.", "Figurine removed from system": "Figuren borttagen från systemet", + "File bind mounts do not support spaces:": "Filbindande fästen stöder inte utrymmen:", + "File processing made easy!": "Filbehandling gjorde lätt!", "File:": "Fil:", + "FileBrowser Quantum": "FileBrowser Quantum", + "FileBrowser Quantum (new installation)": "FileBrowser Quantum (ny installation)", + "FileDrop is a free, open source file sharing service": "FileDrop är en gratis öppen källkod fildelningstjänst", + "Files & Downloads": "Filer och nedladdningar", + "Files volume size in GB": "Filer volymstorlek i GB", "Filesystem": "Filsystem", "Filesystem Tools Required": "Filsystemsverktyg krävs", "Filesystem:": "Filsystem:", "Final Confirmation": "Slutlig bekräftelse", + "Final cleanup of the stack operation completed": "Slutlig rensning av stapeln operation färdigställd", "Final confirmation": "Slutlig bekräftelse", "Final storage health/status check": "Slutlig lagringsstatus/statuskontroll", + "Finance & Budgeting": "Finans & Budgeting", "Find your device using https://finds.synology.com": "Hitta din enhet med https://finds.synology.com", "Fingerprint:": "Fingeravtryck:", + "Firefly, the easiest using of WireGuard VPN server, plus version of wg-easy.": "Firefly, den enklaste användningen av WireGuard VPN-server, plus version av wg-easy.", + "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards.": "Firefox Browser, även känd som Mozilla Firefox eller helt enkelt Firefox, är en fri och öppen källkod webbläsare utvecklad av Mozilla Foundation och dess dotterbolag, Mozilla Corporation. Firefox använder Gecko-layoutmotorn för att göra webbsidor, som implementerar aktuella och förväntade webbstandarder.", "Firewall allows port": "Brandväggen tillåter port", "Firewall settings": "Brandväggsinställningar", "Firmware :": "Firmware:", @@ -1791,8 +2253,13 @@ "Fix systemd-boot meta-package conflict": "Åtgärda systemd-boot-metapaketkonflikt", "Fix systemd-boot:": "Fixa systemd-boot:", "Fix: on the host, run": "Fix: på värden, kör", + "FlexGet web interface": "FlexGet webbgränssnitt", + "Flexget is a multipurpose automation tool for all of your media.": "Flexget är ett multifunktionsautomationsverktyg för alla dina medier.", + "Flowise 3.0.1 and later create the administrator account from the web interface, the first time it is opened.": "Flowise 3.0.1 och senare skapa administratörskontot från webbgränssnittet, första gången det öppnas.", + "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast.": "Flycast är en multiplattform Sega Dreamcast, Naomi, Naomi 2 och Atomiswave emulator härrör från reicast.", "Folder Name": "Mappnamn", "Folders in /mnt": "Mappar i /mnt", + "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics.": "Folding@home är ett distribuerat datorprojekt för att simulera proteindynamik, inklusive processen av proteinvikt och rörelser av proteiner som är inblandade i en mängd olika sjukdomar. Det sammanför Citizen forskare som frivilligt kör simuleringar av proteindynamik på sina datorer. Insikter från dessa data hjälper forskare att bättre förstå biologi och ger nya möjligheter att utveckla terapeutik.", "Follow post-restore progress live from ProxMenux Monitor → Backups tab after the reboot.": "Följ förloppet efter återställning live från ProxMenux Monitor → Fliken Säkerhetskopiering efter omstarten.", "For LVM - Create mount directory and mount:": "För LVM - Skapa monteringskatalog och montera:", "For ZFS, storage ID must start with a letter and use only letters, numbers, dot, dash, underscore or colon.": "För ZFS måste lagrings-ID börja med en bokstav och endast använda bokstäver, siffror, prick, bindestreck, understreck eller kolon.", @@ -1828,11 +2295,15 @@ "Formatting partition": "Formatera partition", "Found": "Hittade", "Found guest-accessible shares:": "Hittade gästtillgängliga delningar:", + "Free and easy to use Minecraft server management tool.": "Gratis och lätt att använda Minecraft server management verktyg.", "Free public Proxmox repository enabled": "Ledigt offentligt Proxmox-förråd aktiverat", "Free space OK:": "Ledigt utrymme OK:", "Free up disk space": "Frigör diskutrymme", "Free:": "Ledigt:", + "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support.": "FreeCAD är en allmänt ändamål parametrisk 3D-datorstödd design (CAD) modeller och en byggnadsinformation modellering (BIM) program med finit element metod (FEM) stöd.", "French": "franska", + "Freshrss is a free, self-hostable aggregator for rss feeds.": "Freshrss är en fri, självvärd aggregator för rss feeds.", + "Frigate WebUI": "Frigate WebUI", "Full SMART Report": "Fullständig SMART-rapport", "Full SMART info and attributes": "Fullständig SMART-information och attribut", "Full format — new GPT partition + filesystem": "Fullformat — ny GPT-partition + filsystem", @@ -1845,6 +2316,7 @@ "Function Level Reset (FLR) not available": "Funktionsnivååterställning (FLR) inte tillgänglig", "GID already in use:": "GID som redan används:", "GID in CT": "GID i CT", + "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable.": "GIMP är en fri och öppen källkod raster grafik redaktör som används för bild manipulation (retouching) och bildredigering, fri form ritning, transkodning mellan olika bildfilformat och mer specialiserade uppgifter. Det är utsträckt med hjälp av plugins och skriptable.", "GPU": "GPU", "GPU -> VM Mode Detected": "GPU -> VM-läge upptäckt", "GPU Already Added": "GPU redan tillagd", @@ -1870,6 +2342,7 @@ "GPU already present in target VM — existing hostpci entry reused": "GPU finns redan i mål-VM — befintlig hostpci-post återanvänds", "GPU audio added": "GPU-ljud har lagts till", "GPU audio already present in target VM — existing hostpci entry reused": "GPU-ljud finns redan i mål-VM — befintlig hostpci-post återanvänds", + "GPU available for machine learning:": "GPU tillgänglig för maskininlärning:", "GPU driver blacklisted": "GPU-drivrutin svartlistad", "GPU guard hook will block concurrent start when another VM is already using this GPU": "GPU guard hook kommer att blockera samtidig start när en annan virtuell dator redan använder denna GPU", "GPU host driver blacklisted in /etc/modprobe.d/blacklist.conf": "GPU-värddrivrutin svartlistad i /etc/modprobe.d/blacklist.conf", @@ -1885,11 +2358,14 @@ "GPU passthrough to VMs requires IOMMU to be enabled in the kernel.": "GPU-genomföring till virtuella datorer kräver att IOMMU är aktiverat i kärnan.", "GPU passthrough was not applied.": "GPU-genomföring tillämpades inte.", "GPU passthrough was skipped (no compatible GPU detected).": "GPU-genomföring hoppades över (ingen kompatibel GPU upptäcktes).", + "GPU recognition uses 8 GB of RAM and a limit of 4 CPU equivalents. These resources were tested in the lab and are not a universal minimum. Compatibility depends on the GPU, the models and the kernel. NVIDIA uses the GPUs of the Toolkit inventory; Intel keeps the CPU topology.": "GPU-igenkänning använder 8 GB RAM och en gräns på 4 CPU equivalents. Dessa resurser testades i labbet och är inte ett universellt minimum. Kompatibilitet beror på GPU, modellerna och kärnan. NVIDIA använder GPU: er i Toolkit inventeringen; Intel håller CPU topologi.", "GPU removed from VM": "GPU borttagen från VM", "GPU removed from VM config": "GPU togs bort från VM-konfigurationen", + "GPU render device": "GPU render enhet", "GPU switch complete: LXC mode prepared.": "GPU-omkopplare klar: LXC-läge förberett.", "GPU switch complete: VM mode prepared.": "GPU-switch klar: VM-läge förberett.", "GPU switch mode completed. No reboot required.": "GPU-växlingsläge slutfört. Ingen omstart krävs.", + "GPU verified:": "GPU verifierad:", "GPU will be removed from source VM config": "GPU kommer att tas bort från källans VM-konfiguration", "GPU will remain configured in source VM": "GPU kommer att förbli konfigurerad i käll-VM", "GPU/TPU - Manual CLI Guide": "GPU/TPU - Manuell CLI-guide", @@ -1899,6 +2375,8 @@ "GRUB configuration updated": "GRUB-konfigurationen uppdaterad", "GRUB_CMDLINE_LINUX_DEFAULT not found in GRUB config": "GRUB_CMDLINE_LINUX_DEFAULT hittades inte i GRUB-konfigurationen", "GUI mode (if available)": "GUI-läge (om tillgängligt)", + "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities.": "GZDoom är en funktion centric port för alla Doom motorspel, baserat på ZDoom, lägga till en OpenGL renderer och kraftfulla skriptfunktioner.", + "Gaming & Leisure": "Spel och Leisure", "Gateway is not installed.": "Gateway är inte installerad.", "Gateway removed.": "Gateway har tagits bort.", "Gateway restarted.": "Gateway startade om.", @@ -1908,19 +2386,32 @@ "Generate a new key and authorize it on the server automatically (recommended)": "Generera en ny nyckel och auktorisera den på servern automatiskt (rekommenderas)", "Generate a new key, show me the line to paste manually": "Skapa en ny nyckel, visa mig raden för att klistra in manuellt", "Generate a new keyfile": "Skapa en ny nyckelfil", + "Generated Paperless administrator": "Genererad papperslös administratör", + "Generated Tandoor administrator": "Genererad Tandoor administratör", + "Generated administrator login": "Genererad administratörsinloggning", "Generating OVF descriptor...": "Genererar OVF-beskrivning...", "Generating dkms.conf...": "Genererar dkms.conf...", "Generating manifest...": "Genererar manifest...", "Generating missing locale:": "Skapar saknad språk:", + "Generic SCSI device associated with the drive (e.g. /dev/sg2)": "Generisk SCSI-enhet i samband med enheten (t.ex. /dev/sg2)", "German": "tyska", "Get a list of all your containers:": "Få en lista över alla dina behållare:", "Get the actual disk path:": "Hämta den faktiska diskvägen:", "Get the container's storage information:": "Hämta behållarens lagringsinformation:", + "Get up and running with large language models locally": "Kom igång med stora språkmodeller lokalt", "Git installed": "Git installerat", + "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality.": "GitQlient är en multiplattform Git klient ursprungligen forked från QGit. Numera går det bortom bara en fork och lägger till en hel del ny funktionalitet.", + "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React.": "Github Desktop är en öppen källkod Electron-baserad GitHub app. Den är skriven i TypeScript och använder React.", "Global settings and SSH jail configured": "Globala inställningar och SSH-fängelse konfigurerade", + "Gluetun/VPN not yet available: this suite does not route downloads through a VPN.": "Gluetun/VPN är ännu inte tillgänglig: denna svit går inte nedladdningar via en VPN.", "Go to \"Manage custom paths\" and remove your custom entry that includes the destination": "Gå till \"Hantera anpassade sökvägar\" och ta bort din anpassade post som inkluderar destinationen", "Google only ships an official libedgetpu APT repository for Debian/Ubuntu. Hardware passthrough is already written to": "Google skickar bara ett officiellt libedgetpu APT-förråd för Debian/Ubuntu. Hardware passthrough är redan skriven till", "Graceful shutdown timed out.": "Graciös avstängning tog timeout.", + "Grafana is a complete observability stack that allows you to monitor and analyze metrics, logs and traces. It allows you to query, visualize, alert on and understand your data no matter where it is stored.": "Grafana är en komplett observerbarhetsstack som låter dig övervaka och analysera mätvärden, loggar och spår. Det låter dig fråga, visualisera, varna och förstå dina data oavsett var den lagras.", + "Grafana web interface": "Grafana webbgränssnitt", + "Grav is a Fast, Simple, and Flexible, file-based Web-platform.": "Grav är en snabb, enkel och flexibel, filbaserad webbplattform.", + "Grocy (new installation; restored data keeps its credentials)": "Grocy (ny installation; återställda data håller sina credentials)", + "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility.": "Grocy är ett ERP-system för ditt kök! Skär ner på matavfall och hantera dina sysslor med detta briljanta verktyg.", "Group": "Grupp", "Group 'sharedfiles' already exists inside the CT": "Gruppen \"delade filer\" finns redan i CT", "Group GID:": "Grupp GID:", @@ -1953,23 +2444,56 @@ "Guided Repair Available": "Guidad reparation tillgänglig", "HA groups will be migrated to HA rules automatically": "HA-grupper kommer att migreras till HA-regler automatiskt", "HA services disabled (configs preserved)": "HA-tjänster inaktiverade (konfigurationer bevarade)", + "HAOS One is a community image that runs Docker inside the container. The LXC stays unprivileged, but the inner AppArmor profiles may not be available. The first start downloads Home Assistant Core and its add-ons. If the check fails, the CT and /mnt/data are kept for diagnosis.": "HAOS One är en gemenskapsbild som kör Docker inuti behållaren. LXC är oprivilegierad, men de inre AppArmor-profilerna kanske inte är tillgängliga. Den första starten hämtar Home Assistant Core och dess tillägg. Om kontrollen misslyckas, CT och /mnt / data hålls för diagnos.", + "HAOS One profile declined": "HAOS One-profilen minskade", + "HAOS One requires an unprivileged unmanaged LXC with nesting and keyctl, 2 cores, 2048 MB RAM, rootfs of at least 12 GB and /mnt/data of at least 16 GB on a container volume included in backups": "HAOS One requires en oprivilegierad ohanterad LXC med häckning och keyctl, 2 kärnor, 2048 MB RAM, rötter på minst 12 GB och /mnt / data på minst 16 GB på en behållarvolym som ingår i backups", + "HTTP service check without a saved URL": "HTTP service check utan sparad URL", + "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API.": "Habridge emulerar Philips Hue API till andra hemautomatiseringsgateways som Amazon Echo / Dot Gen 1 (gen 2 har problem med att upptäcka ha-bro) eller andra system som stöder Philips Hue. Bron hanterar grundläggande kommandon som On, Off och ljusstyrka kommandon av nyansprotokollet. Denna bro kan styra de flesta enheter som har ett tydligt API.", + "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs.": "HandBrake är ett open-source verktyg, byggt av volontärer, för att konvertera video från nästan alla format till ett urval av moderna, allmänt stödda codecs.", "Hardening SSH: setting MaxAuthTries to 3...": "Härdar SSH: ställ in MaxAuthTries på 3...", + "Hardware acceleration for Emby": "Hårdvaruacceleration för Emby", + "Hardware acceleration for FileFlows": "Hårdvaruacceleration för FileFlows", + "Hardware acceleration for Frigate": "Hårdvaruacceleration för Frigate", + "Hardware acceleration for Jellyfin": "Hårdvaruacceleration för Jellyfin", + "Hardware acceleration for Plex": "Hårdvaruacceleration för Plex", + "Hardware acceleration for Roon Server": "Hårdvaruacceleration för Roon Server", + "Hardware acceleration for Stremio": "Hårdvaruacceleration för Stremio", + "Hardware acceleration for Tdarr": "Hårdvaruacceleration för Tdarr", + "Hardware acceleration options:": "Hårdvaruaccelerationsalternativ:", "Hardware compatibility — these items will be skipped to keep the boot safe:": "Hårdvarukompatibilitet - dessa objekt hoppas över för att hålla uppstarten säker:", "Hardware passthrough is already configured — the Coral device is visible inside the container as /dev/apex_0 (M.2) and/or /dev/bus/usb (USB).": "Hårdvaruöverföring är redan konfigurerad — Coral-enheten är synlig inuti behållaren som /dev/apex_0 (M.2) och/eller /dev/bus/usb (USB).", "Hardware: GPUs and Coral-TPU": "Hårdvara: GPU:er och Coral-TPU", + "Have a Private Social Space Hosted on Your Site": "Ha ett privat socialt utrymme på din webbplats", "Have valid backups of all VMs and containers": "Ha giltiga säkerhetskopior av alla virtuella datorer och behållare", + "Health check failed:": "Hälsokontroll misslyckades:", + "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface.": "Healthchecks är en vakthund för dina cron jobb. Det är en webbserver som lyssnar på pings från dina cronjobb, plus ett webbgränssnitt.", + "HedgeDoc gives you access to all your files wherever you are.": "HedgeDoc ger dig tillgång till alla dina filer var du än är.", + "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way.": "Heimdall är ett sätt att organisera alla länkar till dina mest använda webbplatser och webbapplikationer på ett enkelt sätt.", + "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking.": "Helium är en Chromium-baserad webbläsare gjord för människor, med kärlek. Privacy-först med opartisk annonsblockering.", "Help & Info (commands)": "Hjälp och info (kommandon)", "Help & Information": "Hjälp & information", "Help and Info": "Hjälp och info", "Help and Info Commands": "Hjälp- och infokommandon", "Helper-Scripts logo applied": "Helper-Scripts logotyp applicerad", + "Hermes WebUI": "Hermes WebUI", "Hidden for safety": "Gömd för säkerhets skull", "Hidden:": "Dold:", "High Availability services have been enabled successfully": "Hög tillgänglighetstjänster har aktiverats framgångsrikt", "High Availability setup completed": "Inställningen av hög tillgänglighet har slutförts", + "High availability resources are not supported by this profile": "Höga tillgänglighetsresurser stöds inte av denna profil", + "High availability resources are not supported for stacks": "Hög tillgänglighetsresurser stöds inte för staplar", "High risk confirmation": "Hög risk bekräftelse", "High-Risk GPU Power State": "Högrisk GPU Power State", + "Home Assistant": "Home Assistant", + "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server": "Home Assistant Core - Öppen källkod hemautomation som sätter lokal kontroll och integritet först. Drivs av en världsomspännande gemenskap av tinkerers och DIY-entusiaster. Perfekt att köra på en Raspberry Pi eller en lokal server", + "Home Assistant OS cannot be checked without an IP address": "Home Assistant OS kan inte kontrolleras utan en IP-adress", + "Home Assistant OS did not pass the Supervisor, Core and Observer checks": "Home Assistant OS passerade inte Supervisor, Core och Observer kontroller", + "Home Assistant OS ready: Supervisor, Core and Observer running": "Home Assistant OS redo: Supervisor, Core och Observer körning", + "Home Assistant OS was not started: its addresses will be known once Core is running.": "Home Assistant OS startades inte: dess adresser kommer att kallas när Core körs.", + "Home Automation systems": "Home Automation System", "Home-Lab-Club logo applied": "Home-Lab-Club logotyp applicerad", + "HomeKit support for the impatient.": "HomeKit stöd för otåligheten.", + "Homebridge UI": "Homebridge UI", "Host": "Värd", "Host Backup → Borg": "Värdbackup → Borg", "Host Backup → Local archive": "Värdbackup → Lokalt arkiv", @@ -1978,6 +2502,7 @@ "Host Config Backup": "Säkerhetskopia av värdkonfiguration", "Host Config Backup / Restore": "Säkerhetskopiera/återställa värdkonfiguration", "Host Config Restore": "Återställ värdkonfiguration", + "Host DVB tuners": "Värd DVB tuners", "Host Directory": "Värdkatalog", "Host Directory to LXC Mount Point": "Värdkatalog till LXC Mount Point", "Host Directory:": "Värdkatalog:", @@ -1985,18 +2510,37 @@ "Host GPU detected": "Värd GPU upptäckt", "Host GPU is already bound to vfio-pci. Host reconfiguration/reboot should not be required for this VM-to-VM reassignment.": "Värd-GPU är redan bunden till vfio-pci. Värd omkonfiguration/omstart bör inte krävas för denna VM-till-VM-omtilldelning.", "Host IP": "Värd IP", + "Host Management": "Host Management", "Host Mount Path": "Värdmonteringssökväg", "Host NFS/Samba as Proxmox Storage (pvesm)": "NFS/Samba på värden som Proxmox-lagring (pvesm)", "Host Path": "Värdsökväg", "Host Path:": "Värdsökväg:", "Host Storage (NFS / Samba via Proxmox)": "Värdlagring (NFS / Samba via Proxmox)", + "Host USB bus": "Värd USB buss", "Host VFIO config was already up to date — no reboot needed.": "Värd VFIO-konfigurationen var redan uppdaterad — ingen omstart behövs.", "Host VFIO configuration already up to date": "Värd VFIO-konfigurationen är redan uppdaterad", "Host VFIO configuration changed (initramfs updated). Reboot required before starting the VM.": "Värd VFIO-konfiguration ändrad (initramfs uppdaterade). Omstart krävs innan den virtuella datorn startas.", "Host VFIO configuration changed — reboot required before starting the VM.": "Värd VFIO-konfiguration ändrad — omstart krävs innan den virtuella datorn startas.", "Host already in VFIO mode — skipping host reconfiguration for VM reassignment": "Värd redan i VFIO-läge — hoppar över värdomkonfiguration för VM-omtilldelning", + "Host audio devices": "Värd ljudenheter", "Host backup attached to PVE job": "Värdsäkerhetskopia kopplad till PVE-jobb", + "Host data is not restored by the backup; confirm it with --acknowledge-external-data": "Värddata återställs inte av säkerhetskopieringen; bekräftar den med -acknowledge-extern data", + "Host device for /dev/kvm": "Värd enhet för /dev/kvm", + "Host device for /dev/net/tun": "Värd enhet för /dev/nett/tun", + "Host device for /dev/ttyUSB0": "Värd enhet för /dev/ttyUSB0", + "Host device for /dev/video10": "Värd enhet för /dev/video10", + "Host device for /dev/video11": "Värd enhet för /dev/video11", + "Host device for /dev/video12": "Värd enhet för /dev/video12", + "Host device node": "Värd enhet nod", + "Host directories are not included in the backup and are not reverted by a recovery.": "Värdkataloger ingår inte i backupen och återställs inte av en återhämtning.", + "Host directories are not included in the backups and are not reverted by a recovery.": "Värdkataloger ingår inte i säkerhetskopiorna och återställs inte av en återhämtning.", + "Host directories cannot be part of the vzdump backup": "Värdkataloger kan inte vara en del av vzdump backup", + "Host directories that are kept, with their content:": "Värdkataloger som hålls, med deras innehåll:", + "Host directory": "Värd katalog", + "Host directory (created if it does not exist)": "Värdkatalog (skapad om den inte existerar)", + "Host directory (not included in Proxmox backups)": "Värdkatalog (ingår inte i Proxmox säkerhetskopior)", "Host directory access for unprivileged containers has been prepared above": "Värdkatalogåtkomst för oprivilegierade behållare har förberetts ovan", + "Host directory kept, with its content:": "Värdkatalogen hålls, med innehållet:", "Host directory permissions updated — unprivileged containers can now access it": "Värdkatalogbehörigheter uppdaterade – oprivilegierade behållare kan nu komma åt den", "Host directory:": "Värdkatalog:", "Host fstab CIFS Mounts:": "Värdens CIFS-monteringar i fstab:", @@ -2008,7 +2552,14 @@ "Host fstab NFS mounts:": "Värdens NFS-monteringar i fstab:", "Host fstab mounts (not registered as Proxmox storage):": "Host fstab-fästen (ej registrerad som Proxmox-lagring):", "Host identity (hostname, hosts)": "Värdidentitet (värdnamn, värdar)", + "Host kernel module loaded:": "Värd kärnmodul laddad:", + "Host monitor configured: shared PID and network namespaces, LXCFS disabled in this container": "Värdmonitor konfigurerad: delade PID och nätverksnamn, LXCFS inaktiverad i denna behållare", + "Host monitor verified: PID and network namespaces and memory match the host": "Värdmonitor verifierad: PID och nätverksnamn och minne matchar värden", + "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks.": "Värdmonitor: delad PID/nätverk och privilegierad åtkomst. En kompromissad bild kan påverka Proxmox. Använd endast på betrodda nätverk.", + "Host monitoring declined": "Värdövervakning minskade", + "Host path for": "Värd väg för", "Host permissions applied (o+rwx + default ACL) — unprivileged LXCs can read/write through bind-mounts": "Värdbehörigheter tillämpas (o+rwx + standard-ACL) – oprivilegierade LXC:er kan läsa/skriva genom bind-mounts", + "Host system path": "Värd systemväg", "Host write access confirmed.": "Värd skrivåtkomst bekräftad.", "Hostname": "Värdnamn", "Hot changes applied. No reboot needed for these paths.": "Heta ändringar tillämpas. Ingen omstart behövs för dessa vägar.", @@ -2020,12 +2571,16 @@ "How do you want to select the Samba server?": "Hur vill du välja Samba-servern?", "How do you want to select the folder to export?": "Hur vill du välja mappen som ska exporteras?", "How do you want to select the folder to share?": "Hur vill du välja mappen att dela?", + "How is it installed?": "Hur är det installerat?", + "How is the image described?": "Hur beskrivs bilden?", "How to Access an LXC Terminal": "Hur man kommer åt en LXC-terminal", "How to Access an LXC Terminal from Proxmox Host": "Så öppnar du en LXC-terminal från Proxmox-värden", "How to schedule": "Hur man schemalägger", + "Htpcmanager is a front end for many htpc related applications.": "Htpcmanager är en frontend för många htpc-relaterade applikationer.", "I have read this": "Jag har läst detta", "I/O priority configured": "I/O-prioritet konfigurerad", "ID already in use. Please choose another.": "ID används redan. Välj en annan.", + "IGDB": "IGDB", "IMPORTANT": "VIKTIG", "IMPORTANT NOTES:": "VIKTIGA ANMÄRKNINGAR:", "IMPORTANT PREREQUISITES:": "VIKTIGA FÖRUTSÄTTNINGAR:", @@ -2062,7 +2617,14 @@ "IOMMU was configured during this wizard and a reboot is pending.": "IOMMU konfigurerades under den här guiden och en omstart väntar.", "IOMMU/VFIO configuration reverted": "IOMMU/VFIO-konfigurationen återställd", "IP": "IP", + "IP address": "IP-adress", + "IP address and firewall of the host": "IP-adress och brandvägg av värden", + "IP address of this container for the certificate (0.0.0.0 if unknown)": "IP-adress för denna behållare för certifikatet (0.0.0.0 om det är okänt)", + "IP address:": "IP-adress:", "IP or hostname of the PVE node hosting the Borg server LXC:": "IP eller värdnamn för PVE-noden som är värd för Borg-servern LXC:", + "IPv4 address of the container": "IPv4 adress för behållaren", + "IPv4 address of the containers": "IPv4-adress för behållarna", + "IPv4 gateway (empty = no outbound route)": "IPv4 gateway (tom = ingen utgående väg)", "ISO": "ISO", "ISO created successfully:": "ISO skapades framgångsrikt:", "ISO image — installation images": "ISO-bild — installationsbilder", @@ -2095,6 +2657,7 @@ "If this happens, you can restore the backup from the 'Subscription Banner Removal' option in 'Uninstall optimizations'.": "Om detta händer kan du återställa säkerhetskopian från alternativet \"Ta bort prenumerationsbanner\" i \"Avinstallera optimeringar\".", "If this node runs hyper-converged Ceph: ensure Ceph is 19.x (Squid) BEFORE upgrading PVE.": "Om denna nod kör hyperkonvergerad Ceph: se till att Ceph är 19.x (Squid) INNAN du uppgraderar PVE.", "If upgrade fails:": "Om uppgraderingen misslyckas:", + "If you answer No, Glances is installed without privileges and monitors ONLY its own LXC, not Proxmox.": "Om du svarar nej installeras Glances utan privilegier och övervakar ENDAST sin egen LXC, inte Proxmox.", "If you are sure you want to use it, please remove the": "Om du är säker på att du vill använda den, vänligen ta bort", "If you choose No, install": "Om du väljer Nej, installera", "If you continue, some adjustments may be duplicated or conflict with those already made by xshok.": "Om du fortsätter kan vissa justeringar dupliceras eller komma i konflikt med de som redan gjorts av xshok.", @@ -2104,11 +2667,30 @@ "If you want HDMI/analog audio inside the VM, select the audio controller(s) to pass through along with the GPU.": "Om du vill ha HDMI/analogt ljud inuti VM:n, välj ljudkontrollerna som ska passera tillsammans med GPU:n.", "If you want to use a physical monitor on the passthrough GPU:": "Om du vill använda en fysisk bildskärm på passthrough-GPU:n:", "If your DHCP has a static reservation for the old MAC, update it.": "Om din DHCP har en statisk reservation för den gamla MAC, uppdatera den.", + "Image": "Bild", "Image Source Directory": "Bildkällkatalog", + "Image cache": "Bild cache", + "Image compatibility restored:": "Bildkompatibilitet återställd:", + "Image compatibility verified:": "Bildkompatibilitet verifierad:", "Image directory:": "Bildkatalog:", + "Image download failed:": "Bildnedladdning misslyckades:", + "Image downloaded": "Bild nedladdad", "Image file not found:": "Bildfilen hittades inte:", "Image imported:": "Bild importerad:", + "Image integrity verified": "Bildintegritet verifierad", + "Image not allowed for the host monitor profile": "Bild som inte är tillåten för värdmonitorprofilen", + "Image reference (for example ghcr.io/user/application:latest)": "Bildreferens (till exempel ghcr.io/user/application:latest)", + "Image that is not in the catalog": "Bild som inte finns i katalogen", + "Image:": "Bild:", "Images to import:": "Bilder att importera:", + "Immich CUDA requires NVIDIA driver 545 or later": "Immich CUDA requires NVIDIA-förare 545 eller senare", + "Immich GPU profile not validated": "Immich GPU-profil som inte valideras", + "Immich configuration cancelled": "Immich konfiguration annullerad", + "Immich device without a validated translation": "Immich-enhet utan validerad översättning", + "Immich machine learning": "Immich maskininlärning", + "Immich requires CUDA compute capability 5.2 or later": "Immich requires CUDA beräknar kapacitet 5,2 eller senare", + "Immich runtime without a validated translation": "Immich runtime utan validerad översättning", + "Immich server": "Immich server", "Import — disk image imports": "Importera — import av diskavbildningar", "Import Disk Image to VM": "Importera diskavbildning till virtuell dator", "Import Disk to LXC": "Importera disk till LXC", @@ -2149,24 +2731,58 @@ "Incompatible Reset Capability for Intel GPU": "Inkompatibel återställningsförmåga för Intel GPU", "Incompatible Reset Capability for Intel dGPU": "Inkompatibel återställningskapacitet för Intel dGPU", "Incompatible archive": "Inkompatibelt arkiv", + "Incompatible image platform": "Inkompatibel bildplattform", + "Incompatible instance directory": "Inkompatibel instans katalog", + "Incompatible instance record": "Inkompatibelt rekord", + "Incompatible record": "Inkompatibelt rekord", + "Incompatible stack assembly": "Inkompatibel stack montering", "Incompatible version": "Inkompatibel version", + "Incomplete NVIDIA identity": "Ofullständig NVIDIA-identitet", + "Incomplete NVIDIA inventory": "Ofullständig NVIDIA-inventering", + "Incomplete Proxmox inventory": "Ofullständig Proxmox inventering", + "Incomplete Proxmox inventory; recovery blocked": "Ofullständig Proxmox inventering; återhämtning blockerad", + "Incomplete container removed:": "Ofullständig behållare borttagen:", + "Incomplete dependency order": "Ofullständig beroendeorder", + "Incomplete file recipe or unknown paths": "Ofullständiga recept eller okända vägar", + "Incomplete gzip layer": "Ofullständigt gzip lager", + "Incomplete or incompatible Proxmox inventory": "Ofullständig eller oförenlig Proxmox inventering", + "Incomplete primary network": "Ofullständigt primärnätverk", + "Incomplete stack order": "Ofullständig stack order", + "Incomplete stack removed": "Ofullständig stack bort", + "Inconsistent adaptation profile and recipe": "Inkonsekvent anpassningsprofil och recept", + "Inconsistent host monitor profile": "Inkonsekvent värd monitor profil", + "Inconsistent stack identity": "Inkonsekvent stack identitet", + "Inconsistent stack membership for": "Inkonsekvent stack medlemskap för", "Increase container RAM temporarily to": "Öka behållarens RAM tillfälligt till", "Increase file and process limits for advanced workloads": "Öka fil- och processgränserna för avancerade arbetsbelastningar", "Increase various system limits": "Öka olika systemgränser", "Increase vzdump backup speed": "Öka vzdump säkerhetskopia hastighet", "Increasing maximum file system open files...": "Ökar maximalt antal öppna filer i filsystemet...", "Increasing various system limits...": "Ökar olika systemgränser...", + "Independent LXC applications installed": "Oberoende LXC-program installerade", + "Independent LXCs: no main container or hookscript. Each one keeps its own Start with Proxmox setting.": "Oberoende LXCs: ingen huvudbehållare eller hookscript. Var och en håller sin egen start med Proxmox inställning.", + "Independent applications, without a main container.": "Oberoende applikationer, utan huvudbehållare.", + "Indexers and quality profiles still need to be configured.": "Indexers och kvalitetsprofiler behöver fortfarande konfigureras.", "Inherited retention:": "Ärvd retention:", "Inherited schedule:": "Ärvt schema:", + "Initial Nextcloud administrator": "Initial Nextcloud administratör", + "Initial Nextcloud settings applied": "Initial Nextcloud inställningar tillämpas", + "Initial Paperless-ngx administrator": "Initial Paperless-ngx administratör", + "Initial Tandoor administrator": "Initial Tandoor administratör", + "Initial administrator created:": "Initial administratör skapad:", + "Initial administrator user": "Initial administratör användare", "Initializing Borg repository if needed...": "Initierar Borg-arkivet om det behövs...", "Initiator IQN is authorised on the target": "Initiator IQN är auktoriserad på målet", "Initiator IQN:": "Initiativtagare IQN:", + "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers.": "Inkscape är professionell kvalitet vektor grafik programvara som körs på Linux, Mac OS X och Windows stationära datorer.", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN": "Inuti LXC, skapa administratören: konsol kimai:user: skapa ditt USERNAME YOUR EMAIL ROLE SUPER ADMIN", "Inspect disks before any action": "Inspektera diskar innan någon åtgärd", "Inspect host device nodes": "Inspektera värdenhetsnoder", "Inspect passthrough/kernel events": "Inspektera passthrough/kärnhändelser", "Inspect storage config block:": "Inspektera lagringskonfigurationsblocket:", "Inspection commands run directly. Template commands [T] require parameter substitution.": "Inspektionskommandon körs direkt. Mallkommandon [T] kräver parameterbyte.", "Install": "Installera", + "Install (experimental)": "Installera (experimentell)", "Install ALL utilities": "Installera ALLA verktyg", "Install AMD GPU drivers inside the guest.": "Installera AMD GPU-drivrutiner i gästen.", "Install CIFS client packages inside CT:": "Installera CIFS-klientpaket inuti CT:", @@ -2185,6 +2801,7 @@ "Install Samba inside CT:": "Installera Samba inuti CT:", "Install ZFS auto-snapshot": "Installera ZFS auto-snapshot", "Install a version from the branch the kernel names.": "Installera en version från grenen kärnan namnger.", + "Install an image that is not in the catalog": "Installera en bild som inte finns i katalogen", "Install analysis tools": "Installera analysverktyg", "Install and configure": "Installera och konfigurera", "Install and configure Fastfetch": "Installera och konfigurera Fastfetch", @@ -2203,27 +2820,35 @@ "Install server packages inside CT:": "Installera serverpaket inuti CT:", "Install terminal multiplexers": "Installera terminalmultiplexer", "Install the Edge TPU runtime (libedgetpu1-std)": "Installera Edge TPU runtime (libedgetpu1-std)", + "Install this image?": "Installera den här bilden?", "Install with Cloud-Init script": "Installera med Cloud-Init-skript", "Install with ISO from UUP Dump": "Installera med ISO från UUP Dump", + "Install with advanced settings": "Installera med avancerade inställningar", + "Install with default settings": "Installera med standardinställningar", "Install with personal ISO": "Installera med personlig ISO", + "Install with this configuration?": "Installera med denna konfiguration?", "Install with traditional method": "Installera med traditionell metod", "Install with: apt-get install open-iscsi": "Installera med: apt-get install open-iscsi", "Install/Update Coral TPU on Host": "Installera/uppdatera Coral TPU på värd", "Install/Update NVIDIA Drivers (Host + LXC)": "Installera/uppdatera NVIDIA-drivrutiner (värd + LXC)", "Installation Complete": "Installationen är klar", + "Installation completed": "Installation färdig", "Installation completed.": "Installationen är klar.", "Installation completed. Please reboot the server manually as soon as possible.": "Installationen är klar. Vänligen starta om servern manuellt så snart som möjligt.", "Installation completed. Press Enter to continue...": "Installationen är klar. Tryck på Enter för att fortsätta...", "Installation failed": "Installationen misslyckades", "Installation finished but drivers are not loaded. A reboot may be required.": "Installationen är klar men drivrutinerna är inte laddade. En omstart kan krävas.", + "Installation incomplete. These containers and their data are kept:": "Installation ofullständig. Dessa behållare och deras data hålls:", "Installation log:": "Installationslogg:", "Installation summary": "Sammanfattning av installationen", "Installed": "Installerad", "Installed at:": "Installerad på:", "Installed components:": "Installerade komponenter:", + "Installed:": "Installerat:", "Installer already downloaded and verified.": "Installationsprogrammet har redan laddats ner och verifierats.", "Installer copied to container.": "Installatören kopierad till behållaren.", "Installer downloaded.": "Installationsprogrammet nedladdat.", + "Installer file not found:": "Installationsfilen hittades inte:", "Installer finished with errors.": "Installatören är klar med fel.", "Installer not found:": "Installationsprogrammet hittades inte:", "Installing": "Installerar", @@ -2274,9 +2899,14 @@ "Installing pigz...": "Installerar pigz...", "Installing required dependencies...": "Installerar nödvändiga beroenden...", "Installing required package: git": "Installerar det nödvändiga paketet: git", + "Installing required packages...": "Installera required paket...", "Installing required tools...": "Installerar nödvändiga verktyg...", "Installing selected utilities": "Installerar utvalda verktyg", "Installing system utilities...": "Installerar systemverktyg...", + "Installing the new image": "Installera den nya bilden", + "Installing the new image...": "Installera den nya bilden...", + "Installing the new image:": "Installera den nya bilden:", + "Installing the stack startup hook...": "Installera stack start hook...", "Installing zfs-auto-snapshot package...": "Installerar paketet zfs-auto-snapshot...", "Installs essential packages if missing": "Installerar viktiga paket om de saknas", "Insufficient Disk Space": "Otillräckligt diskutrymme", @@ -2288,8 +2918,16 @@ "Intel CPU detected": "Intel CPU upptäckt", "Intel GPU Tools installation completed!": "Installationen av Intel GPU Tools slutförd!", "Intel GPU(s) detected:": "Intel GPU(s) upptäckt:", + "Intel VA-API + OpenCL (official mod)": "Intel VA-API + OpenCL (officiell mod)", "Intel VA-API drivers installed.": "Intel VA-API-drivrutiner installerade.", "Intel iGPU passthrough configured.": "Intel iGPU-passthrough konfigurerad.", + "Intel render device for recognition": "Intel render enhet för erkännande", + "Intel/AMD (VA-API and QSV)": "Intel/AMD (VA-API och QSV)", + "Intel/AMD (VA-API)": "Intel/AMD (VA-API)", + "Intel/AMD VA-API": "Intel/AMD VA-API", + "Intel/AMD VA-API (no OpenCL mod)": "Intel/AMD VA-API (ingen OpenCL-mod)", + "Intel/AMD render node": "Intel/AMD gör nod", + "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters – building great software.": "IntelliJ IDEA hjälper dig att skriva kod snabbare med verktyg som eliminerar tråkiga uppgifter och låter dig fokusera på vad som är viktigt - bygga bra programvara.", "Interactive (guided, prompts visible)": "Interaktiv (guidad, uppmaningar synliga)", "Interactive process viewer (press q to exit)": "Interaktiv processvisare (tryck på q för att avsluta)", "Interface": "Gränssnitt", @@ -2303,50 +2941,179 @@ "Interfaces to Remove": "Gränssnitt att ta bort", "Internal error: NVIDIA installer path is empty or file not found.": "Internt fel: NVIDIAs installationssökväg är tom eller filen hittades inte.", "Internal error: missing arguments in pmx_prepare_host_shared_dir": "Internt fel: saknade argument i pmx_prepare_host_shared_dir", + "Internal subnet of the tunnel (change it only if it clashes)": "Internt undernät av tunneln (ändra det bara om det sammandras)", + "Interrupted operation": "Avbruten operation", + "Interrupted operation:": "Avbruten operation:", + "Interrupted stack operation found": "Avbruten stack operation hittades", "Invalid 'proxmox-ve' candidate (not 9.x or none). Please verify your repository configuration and network, then retry.": "Ogiltig 'proxmox-ve'-kandidat (inte 9.x eller ingen). Verifiera din arkivkonfiguration och ditt nätverk och försök sedan igen.", + "Invalid ALLOWED_HOSTS value": "Invalid ALLOWED HOSTS värde", + "Invalid Home Assistant OS check timeout": "Ogiltig Home Assistant OS check timeout", "Invalid ID": "Ogiltigt ID", + "Invalid Intel render path": "Invalid Intel render bana", + "Invalid Jellyfin path:": "Invalid Jellyfin väg:", + "Invalid MAC address:": "Ogiltig MAC-adress:", + "Invalid NVIDIA device:": "Invalid NVIDIA-enhet:", + "Invalid Nextcloud volume": "Ogiltig Nextcloud volym", + "Invalid OCI Entrypoint": "Ogiltig OCI Entrypoint", + "Invalid OCI digest": "Ovalid OCI digest", + "Invalid OCR language:": "Ogiltigt OCR-språk:", "Invalid Option": "Ogiltigt alternativ", "Invalid Path": "Ogiltig sökväg", + "Invalid Proxmox inventory": "Invalid Proxmox inventering", + "Invalid Python module:": "Invalid Python modul:", + "Invalid Python package:": "Invalid Python-paket:", + "Invalid Python path in the repair:": "Invalid Python väg i reparationen:", + "Invalid Unpackerr variable": "Invalid Unpackerr variabel", + "Invalid VFS cache mode": "Ogiltig VFS cache läge", "Invalid VMID": "Ogiltigt VMID", + "Invalid VMID or timeout": "Ogiltig VMID eller timeout", + "Invalid VMID:": "Ogiltig VMID:", "Invalid ZFS pool name.": "Ogiltigt ZFS-poolnamn.", + "Invalid absolute mount path": "Ogiltig absolut monteringsväg", + "Invalid absolute path; avoid spaces, commas and relative segments": "Ogiltig absolut väg; undvika utrymmen, kommatecken och relativa segment", + "Invalid acceleration profile": "Invalid accelerationsprofil", + "Invalid access address:": "Ogiltig åtkomstadress:", + "Invalid administrator email": "Invalid administratör e-post", + "Invalid administrator user name": "Invalid administratör användarnamn", + "Invalid base VMID": "Ogiltig bas VMID", + "Invalid check package:": "Ogiltigt checkpaket:", + "Invalid configuration path:": "Ogiltig konfigurationsväg:", + "Invalid consume/export volumes": "Ogiltiga konsum/exportvolymer", + "Invalid container path:": "Invalid containerväg:", + "Invalid credential file path:": "Invalid credential filväg:", + "Invalid declarative entrypoint": "Invalid deklarativ ingång", + "Invalid declarative stop signal": "Invalid deklarativ stopp signal", + "Invalid declarative working directory": "Ogiltig deklarativ arbetskatalog", + "Invalid device UID:": "Ogiltig enhet UID:", + "Invalid device mode": "Invalid enhet läge", + "Invalid device mode:": "Invalid enhet läge:", + "Invalid device path:": "Invalid enhetsväg:", + "Invalid device paths for": "Invalid enhet vägar för", "Invalid group name. Use letters, digits, underscore or hyphen, and start with a letter or underscore.": "Ogiltigt gruppnamn. Använd bokstäver, siffror, understreck eller bindestreck och börja med en bokstav eller understreck.", + "Invalid health check": "Ogiltig hälsokontroll", + "Invalid healthcheck path": "Ogiltig hälsokontrollväg", + "Invalid healthcheck port": "Invalid Healthcheck Port", + "Invalid healthcheck request timeout": "Ogiltig hälsokontroll begär timeout", + "Invalid healthcheck scheme": "Invalid Healthcheck System", + "Invalid healthcheck stability period": "Ogiltig hälsokontroll stabilitetsperiod", + "Invalid healthcheck timeout": "Invalid Healthcheck timeout", + "Invalid host kernel module name:": "Invalid värd kernel modul namn:", + "Invalid host monitor PID": "Invalid värd monitor PID", + "Invalid host path:": "Invalid värdväg:", "Invalid input": "Ogiltig inmatning", + "Invalid internal volume": "Invalid intern volym", + "Invalid list:": "Invalid lista:", + "Invalid machine learning CPU allocation:": "Ogiltig maskininlärning CPU tilldelning:", + "Invalid machine learning resources": "Invalid maskininlärningsresurser", + "Invalid main member or duplicated members": "Ogiltig huvudmedlem eller duplicerade medlemmar", + "Invalid media path": "Invalid Media Path", + "Invalid media volume": "Invalid Media Volym", + "Invalid mediafiles volume": "Invalid Mediafiles volym", + "Invalid minimum version:": "Ogiltig minimiversion:", + "Invalid mount name": "Invalid Mount Namn", + "Invalid mount type": "Ogiltig montering typ", "Invalid name": "Ogiltigt namn", "Invalid name. Use only letters, numbers, hyphens and underscores.": "Ogiltigt namn. Använd endast bokstäver, siffror, bindestreck och understreck.", + "Invalid octal permissions": "Ogiltiga okta tillstånd", "Invalid option": "Ogiltigt alternativ", "Invalid option, please try again.": "Ogiltigt alternativ, försök igen.", "Invalid option. Skipping.": "Ogiltigt alternativ. Hoppa över.", + "Invalid or duplicated mount path": "Ogiltig eller duplicerad monteringsväg", + "Invalid or duplicated network sysctl": "Invalid eller duplicerad nätverkssysctl", "Invalid parameters for bind mount": "Ogiltiga parametrar för bindningsmontering", + "Invalid path": "Invalid väg", + "Invalid path in the NVIDIA inventory": "Ogiltig väg i NVIDIA inventering", + "Invalid post-start timeout in the configuration:": "Invalid post-start timeout i konfigurationen:", + "Invalid private bridge": "Invalid privat bro", + "Invalid private network": "Ogiltigt privat nätverk", + "Invalid prlimit value": "Invalid prlimit värde", + "Invalid process limits format": "Ogiltig process begränsar format", + "Invalid registry digest": "Invalid register digest", + "Invalid remote name": "Ogiltigt fjärrnamn", + "Invalid remote path": "Invalid fjärrväg", + "Invalid repair version:": "Ogiltig reparationsversion:", + "Invalid resources": "Ogiltiga resurser", + "Invalid restored volume path": "Invalid återställd volymväg", + "Invalid running state": "Ogiltig körstatus", + "Invalid security.unprivileged value:": "Invalid security.oprivileged value:", "Invalid selection": "Ogiltigt val", + "Invalid service alias": "Ogiltig service alias", + "Invalid service check URL": "Ogiltig service check URL", + "Invalid service check arguments": "Invalid service check argument", + "Invalid service check timeout": "Ogiltig service check timeout", + "Invalid shared path": "Invalid delad väg", "Invalid size. Please enter a number in MB (e.g., 128, 256, 512).": "Ogiltig storlek. Ange ett nummer i MB (t.ex. 128, 256, 512).", + "Invalid stack contract": "Invalid stack kontrakt", + "Invalid stack members": "Ogiltiga stackmedlemmar", + "Invalid stack name": "Invalid stack namn", + "Invalid stack operation": "Ogiltig stack operation", "Invalid storage ID. Use only letters, numbers, hyphens and underscores.": "Ogiltigt lagrings-ID. Använd endast bokstäver, siffror, bindestreck och understreck.", + "Invalid suite application": "Invalid suite applikation", + "Invalid sysctl value:": "Invalid sysctl värde:", + "Invalid template storage": "Invalid mall lagring", + "Invalid tmpfs options:": "Ogiltiga tmpfs alternativ:", + "Invalid tmpfs path:": "Invalid tmpfs väg:", + "Invalid tmpfs size:": "Invalid tmpfs storlek:", "Invalid username or password.": "Ogiltigt användarnamn eller lösenord.", + "Invalid variable name": "Invalid Variabel Namn", + "Invalid variable name:": "Invalid variabelnamn:", + "Invalid volume size": "Invalid volymstorlek", + "Invalid volume size:": "Ogiltig volymstorlek:", + "Invalid volume target": "Ogiltigt volymmål", + "Is the value a password or secret?": "Är värdet ett lösenord eller en hemlighet?", "Issue": "Utfärda", "Issues found": "Problem hittades", "Issues were found. Would you like to use the Guided Cleanup Assistant?": "Problem hittades. Vill du använda Guided Cleanup Assistant?", "Issues were found. Would you like to use the Guided Repair Assistant?": "Problem hittades. Vill du använda den guidade reparationsassistenten?", "It appears that you have already executed the xshok-proxmox post-install script on this system.": "Det verkar som om du redan har kört xshok-proxmox efterinstallationsskriptet på det här systemet.", + "It asks for a system directory of the host:": "Det begär en systemkatalog över värden:", + "It asks for capabilities or a relaxed confinement profile.": "Det ber om kapacitet eller en avslappnad förlossningsprofil.", + "It asks to see the processes of the host.": "Det ber om att se värdens processer.", + "It cannot be removed on its own, because the application would stop working: continuing removes the whole application.": "Det kan inte tas bort på egen hand, eftersom ansökan skulle sluta fungera: fortsätter att ta bort hela ansökan.", + "It is created empty; existing data is not migrated automatically.": "Den skapas tom; befintliga data migreras inte automatiskt.", "It is recommended to create a backup before continuing.": "Vi rekommenderar att du skapar en säkerhetskopia innan du fortsätter.", "It is strongly recommended to create a backup of your container before proceeding with the conversion.": "Det rekommenderas starkt att skapa en säkerhetskopia av din behållare innan du fortsätter med konverteringen.", + "It needs a privileged container, which is not isolated from the host.": "Den behöver en privilegierad behållare, som inte isoleras från värden.", "It will be installed from the official GitHub repository.": "Det kommer att installeras från det officiella GitHub-förrådet.", + "It works through the Docker engine of the host, and a native OCI container does not have one.": "Det fungerar genom Docker-motorn i värden, och en infödd OCI-behållare har inte en.", "Italian": "italienska", + "Its Compose file asks for privileged mode; the container is created unprivileged and that mode is only offered as an option.": "Dess Compose-fil ber om privilegierat läge; behållaren skapas oprivilegierad och det läget erbjuds endast som ett alternativ.", + "Its final cleanup did not complete. Select the stack again in the OCI management menu to complete it.": "Dess slutliga rengöring slutfördes inte. Välj stacken igen i OCI-hanteringsmenyn för att slutföra den.", + "Its labels are not applied: they are read by other Docker tools.": "Etiketterna tillämpas inte: de läses av andra Docker-verktyg.", "JC Channel logo applied": "JC Channel-logotyp applicerad", + "JDownloader 2 with browser GUI and MyJDownloader support": "JDownloader 2 med webbläsare GUI och MyJDownloader stöd", + "JDownloader WebUI": "JDownloader WebUI", "JSON output for scripts": "JSON-utgång för skript", + "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps.": "Jackett fungerar som en proxyserver: det översätter frågor från appar (Sonarr, SickRage, CouchPotato, Mylar, etc) till tracker-site-specifika http-frågor, parses html svar, sedan skickar resultat tillbaka till den begärda programvaran. Detta gör det möjligt att få nya uppladdningar (som RSS) och utföra sökningar. Jackett är en enda förvaring av underhållen indexerskrapning och översättningslogik - ta bort bördan från andra appar.", + "Jellyfin WebUI": "Jellyfin WebUI", + "Jellyfin configuration applied:": "Jellyfin-konfiguration tillämpad:", + "Jellyfin did not create encoding.xml before the timeout": "Jellyfin skapade inte encoding.xml före timeout", + "Jellyfin has not created encoding.xml in any declared path": "Jellyfin har inte skapat kodning.xml i någon förklarad väg", + "Jellyseerr is a free and open source software application for managing requests for your media library.": "Jellyseerr är en fri och öppen källkod program för hantering av förfrågningar för ditt mediebibliotek.", + "Jenkins unlock": "Jenkins låser upp", "Job ID (letters, numbers, - _)": "Jobb-ID (bokstäver, siffror, - _)", "Job ID:": "Jobb-ID:", "Job deleted:": "Jobbet raderat:", "Job disabled:": "Jobb inaktiverat:", "Job enabled:": "Jobb aktiverat:", "Job selection returned empty id — aborting.": "Jobbval returnerade tomt id — avbryter.", + "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.": "Joplin är en gratis, öppen källkod notering tar och att göra ansökan, som kan hantera ett stort antal anteckningar organiserade i anteckningsböcker.", "Journald configuration adjusted to": "Journalkonfiguration justerad till", "Journald configuration is already optimized": "Journalkonfigurationen är redan optimerad", "Journald configuration updated and service restarted": "Journalkonfigurationen uppdaterad och tjänsten startade om", "Journald optimization completed": "Journaloptimering slutförd", "Journald optimized - Max size: 64M": "Journaloptimerad - Maxstorlek: 64M", + "Jupyter Lab (token only)": "Jupyter Lab (endast token)", "KDF:": "KDF:", "KVM MSR options added to /etc/modprobe.d/kvm.conf": "KVM MSR-alternativ har lagts till i /etc/modprobe.d/kvm.conf", "KVM MSR options ensured in /etc/modprobe.d/kvm.conf": "KVM MSR-alternativ säkerställda i /etc/modprobe.d/kvm.conf", "KVM MSR options not present, nothing to revert": "KVM MSR-alternativ finns inte, inget att återställa", + "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX ™ is a trademark of OffSec.": "Kali-linux - är en Advanced Penetration Testing Linux-distribution som används för Penetration Testing, Ethical Hacking och nätverkssäkerhetsbedömningar. KALI LINUX TM är ett varumärke av OffSec.", + "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections.": "Kasm Workspaces är en docker container streaming plattform för att leverera webbläsarbaserad tillgång till skrivbord, applikationer och webbtjänster. Kasm använder devops-aktiverade Containerized Desktop Infrastructure (CDI) för att skapa on-demand, disponibel, docker behållare som är tillgängliga via webbläsare. Exempel användningsfall inkluderar fjärr webbläsare Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS) och Open Source Intelligence (OSINT) samlingar.", + "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!": "Kavita är en snabb, funktion rik, cross plattform läsning server. Byggd med fokus för att vara en hel lösning för alla dina läsbehov. Ställ in din egen server och dela din läskollektion med dina vänner och familj!", + "Kavita is a free and open source web based Comic and Book Server.": "Kavita är en gratis och öppen källkod webbaserad Comic and Book Server.", + "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready.": "Kdenlive är ett kraftfullt gratis och öppen källkod cross-platform video redigering program gjord av KDE gemenskapen. Funktionen rik och produktion redo.", + "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass).": "KeePassXC är en gratis och öppen källkod lösenordshanterare. Det började som en gemenskap fork av KeePassX (själv en plattformsport av KeePass).", "Keep GPU in LXC config (disable Start on boot)": "Behåll GPU i LXC-konfiguration (avaktivera Start vid start)", "Keep GPU in LXC config + disable Start on boot": "Behåll GPU i LXC config + inaktivera Start vid uppstart", "Keep GPU in VM config (disable Start on boot)": "Behåll GPU i VM-konfiguration (avaktivera Start vid uppstart)", @@ -2356,6 +3123,7 @@ "Keep current version (N) if modified": "Behåll aktuell version (N) om den ändras", "Keep in source VM(s) + disable onboot + add to target VM": "Behåll i käll-VM:er + inaktivera onboot + lägg till mål-VM", "Keeping GPU in source VM config": "Behåller GPU i käll-VM-konfigurationen", + "Keeping the settings changed in Proxmox:": "Att hålla inställningarna ändrade i Proxmox:", "Kept sharedfiles group (has regular users assigned).": "Kept sharedfiles group (har tilldelade vanliga användare).", "Kernel and architecture info": "Information om kärnor och arkitektur", "Kernel headers and build tools verified.": "Kärnrubriker och byggverktyg verifierade.", @@ -2377,6 +3145,16 @@ "Keyfile recovery — pick source host": "Nyckelfilsåterställning — välj källvärd", "Keyfile removed.": "Nyckelfilen har tagits bort.", "Keyrings method failed; trying apt-key fallback": "Nyckelringsmetoden misslyckades; försöker apt-key fallback", + "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite.": "KiCad - En Cross Platform och Open Source Electronics Design Automation Suite.", + "Kimai has no default account. Enter the container with: pct enter {main_vmid}": "Kimai har inget standardkonto. Ange behållaren med: pct enter {main vmid}", + "Kimai is a professional grade time-tracking application, free and open-source.": "Kimai är en professionell tidsspårningsapplikation, fri och öppen källkod.", + "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more.": "Kometa är ett kraftfullt verktyg för att ge dig fullständig kontroll över dina mediebibliotek. Med Kometa kan du ta din anpassning till nästa nivå, med granulär kontroll över metadata, samlingar, överlagringar och mycket mer.", + "Kometa reads its configuration from /config/config.yml and the container only ships /config/config.yml.template. Copy the template to config.yml, fill in the required Plex and TMDb connections, then restart the container.": "Kometa läser sin konfiguration från /config/config.yml och behållaren endast fartyg /config/config.yml.template. Kopiera mallen till config.yml, fyll i required Plex och TMDb-anslutningar och starta sedan om behållaren.", + "Komga is a media server for your comics, mangas, BDs, magazines and eBooks.": "Komga är en mediaserver för dina serier, mangas, BD, tidskrifter och e-böcker.", + "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone.": "Krita är ett professionellt gratis och öppen källkod målning program. Den är gjord av konstnärer som vill se prisvärda konstverktyg för alla.", + "LAN access to the kept containers (stack configuration incomplete):": "LAN tillgång till de bevarade behållarna (stack konfiguration ofullständig):", + "LAN address applied to the application URLs": "LAN-adress tillämpad på ansökningsadresserna", + "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer.": "LM Studio kan köra lokala AI-modeller som gpt-oss, Llama, Gemma, Qwen och DeepSeek privat på din dator.", "LUNs appear as block devices assignable to VMs": "LUN:er visas som blockenheter som kan tilldelas virtuella datorer", "LVM PV headers check completed": "Kontroll av LVM PV-huvuden slutförd", "LVM physical volume detected": "LVM fysisk volym upptäckt", @@ -2393,18 +3171,27 @@ "LXC containers with NVIDIA passthrough:": "LXC-behållare med NVIDIA-passthrough:", "LXC conversion from privileged to unprivileged completed successfully!": "LXC-konvertering från privilegierad till oprivilegierad slutförd framgångsrikt!", "LXC conversion from unprivileged to privileged completed successfully!": "LXC-konvertering från oprivilegierad till privilegierad slutförd framgångsrikt!", + "LXC entries outside the NVIDIA inventory of the journal": "LXC poster utanför NVIDIA inventering av tidskriften", + "LXC entries outside the selected acceleration profile": "LXC poster utanför den valda accelerationsprofilen", + "LXC entry outside the read-only NVIDIA profile": "LXC inträde utanför den lättlästa NVIDIA-profilen", "LXC removed:": "LXC bort:", "LXC stopped": "LXC stannade", "LXC update skipped by user.": "LXC-uppdatering hoppades över av användare.", "LXCs to destroy:": "LXC att förstöra:", + "Lab interruption after installing the new container": "Lab avbrott efter installation av den nya behållaren", + "Lab interruption after protecting the data": "Labbavbrott efter att ha skyddat data", + "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models.": "Label Studio är ett open source-datamärkningsverktyg. Det låter dig märka datatyper som ljud, text, bilder, videor och tidsserier med ett enkelt och enkelt UI och exportera till olika modellformat. Det kan användas för att förbereda rådata eller förbättra befintliga träningsdata för att få mer accurate ML-modeller.", "Label:": "Märka:", "Language Change": "Språkbyte", "Language changed to": "Språket ändrades till", + "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)": "Språk/lokal (t.ex. es ES.UTF-8; översättning av varje ansökan garanteras inte)", "Last 50 kernel log lines": "Senaste 50 kärnloggraderna", "Last run:": "Senaste körningen:", "Last system boot time": "Sista systemstarttid", "Latest version:": "Senaste versionen:", "Launching GPU passthrough assistant for VM": "Lanserar GPU-passthrough-assistent för virtuella datorer", + "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork.": "Lazylibrarian är ett program för att följa författare och ta tag i metadata för alla dina digitala läsbehov. Den använder en combination av Goodreads Librarything och valfritt GoogleBooks som källor för författare info och bok info. Denna behållare är baserad på DobyTang fork.", + "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user’s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012).": "Ldap-auth-programvaran är för att autentisera användare som begär skyddade resurser från servrar som är uppkopplade av nginx. Den innehåller en daemon (ldap-auth) som kommunicerar med en autentiseringsserver och en webserver-daemon som genererar en autentiseringscookie baserat på användarens credentials. Daemonerna är skrivna i Python för användning med en Lightweight Directory Access Protocol (LDAP) autentiseringsserver (OpenLDAP eller Microsoft Windows Active Directory 2003 och 2012).", "Legacy PVE 8 .list files commented or not present": "Äldre PVE 8 .list-filer kommenterade eller saknas", "Legacy ceph.list commented or not present": "Legacy ceph.list kommenterade eller inte närvarande", "Legacy gasket-dkms cleanup could not be verified as complete.": "Rensningen av det äldre gasket-dkms-paketet kunde inte verifieras som slutförd.", @@ -2412,12 +3199,25 @@ "Legacy network tools (e.g., ifconfig)": "Äldre nätverksverktyg (t.ex. ifconfig)", "Legend:": "Legend:", "Let's review your current network configuration.": "Låt oss granska din nuvarande nätverkskonfiguration.", + "Liberate your videos and unleash infinite possibilities.": "Befria dina videor och frigöra oändliga möjligheter.", + "Libraries: /data/media/movies, /data/media/series and /data/media/music. Select them in the media server.": "Bibliotek: /data/media/filmer,/data/media/serie och/data/media/musik. Välj dem i mediaservern.", + "Library size in GB": "Bibliotekets storlek i GB", + "LibreDB Studio": "LibreDB Studio", + "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity.": "LibreOffice är en fri och kraftfull kontorssvit och en efterträdare till OpenOffice.org (vanligen känd som OpenOffice). Dess rena gränssnitt och funktionsrika verktyg hjälper dig att frigöra din kreativitet och förbättra din produktivitet.", + "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM.": "LibreWolf är en anpassad och oberoende version av Firefox, med de primära målen för integritet, säkerhet och användarfrihet. LibreWolf syftar också till att ta bort alla telemetri, datainsamling och irritationer, samt inaktivera anti-frihet funktioner som DRM.", + "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers.": "Librespeed är en mycket lätt Speedtest implementerad i Javascript, med XMLHttpRequest och Web Workers.", + "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Lidarr är en musiksamlingschef för Usenet och BitTorrent-användare. Det kan övervaka flera RSS-flöden för nya spår från dina favoritartister och kommer att ta tag i, sortera och byta namn på dem. Det kan också konfigureras för att automatiskt uppgradera kvaliteten på filer som redan laddats ner när ett bättre kvalitetsformat blir tillgängligt.", + "Lightweight Docker management UI": "Lätt Docker ledning UI", "Likely cause: host directory permissions deny the container's mapped UID.": "Trolig orsak: värdkatalogbehörigheter nekar behållarens mappade UID.", "Limiting size and optimizing journald": "Begränsning av storlek och optimering av journal", "Limiting size and optimizing journald...": "Begränsar storlek och optimerar journal...", + "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot.": "Limnoria En robust, fullfjädrad och användarvänlig Python IRC bot, med många befintliga plugins. Framgång för den välkända Supybot.", + "Limnoria joins no IRC network until its configuration file exists. Create it with the setup wizard from the Proxmox host: pct exec -- bash -c 'cd /config && limnoria-wizard'": "Limnoria går med i inget IRC-nätverk tills dess konfigurationsfil finns. Skapa den med installationsguiden från Proxmox-värden: pct exec - bash -c \"cd /config & & & & limnoria-wizard\"", "Line to paste (single line, including \"command=...\" prefix):": "Rad att klistra in (en rad, inklusive \"command=...\" prefix):", "Linux Installation Options": "Linux installationsalternativ", "Linux/Mac path:": "Linux/Mac sökväg:", + "LinuxServer Jellyfin with optional GPU passthrough": "LinuxServer Jellyfin med valfri GPU genomgång", + "LinuxServer MariaDB requires a user, database and password": "LinuxServer MariaDB requires en användare, databas och lösenord", "List Available Disks": "Lista tillgängliga diskar", "List IOMMU group mapping": "Lista IOMMU-gruppkartläggning", "List NVMe devices": "Lista NVMe-enheter", @@ -2443,7 +3243,9 @@ "Listening on:": "Lyssnar på:", "Listening ports:": "Lyssningsportar:", "Listing relevant CT users and their mapped UID/GID on host...": "Listar relevanta CT-användare och deras mappade UID/GID på värd...", + "Load and verify the WireGuard module on the Proxmox host": "Ladda och verifiera WireGuard modulen på Proxmox värd", "Loading modules...": "Laddar moduler...", + "Loading the host kernel module:": "Loading the host kernel modul:", "Local Disk Manager - Proxmox Host": "Lokal diskhanterare – Proxmox-värd", "Local Disk Storages": "Lokala disklagringar", "Local Shared Directory on Host": "Lokal delad katalog på värd", @@ -2454,6 +3256,7 @@ "Local keyfile is missing but a recovery copy was found in PBS.": "Lokal nyckelfil saknas men en återställningskopia hittades i PBS.", "Local network only (192.168.0.0/16)": "Endast lokalt nätverk (192.168.0.0/16)", "Local restore error log": "Lokal återställningsfellogg", + "Local storage for PostgreSQL": "Lokal lagring för PostgreSQL", "Locale generated": "Språk genererad", "Location:": "Plats:", "Log": "Logga", @@ -2469,6 +3272,7 @@ "Logged-in users": "Inloggade användare", "Logrotate optimization completed": "Logrotate-optimering slutförd", "Logrotate service restarted successfully": "Logrotate-tjänsten startades om", + "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment.": "Lollypop är en lätt modern musikspelare utformad för att fungera utmärkt på GNOME-skrivbordsmiljön.", "Long Test — Background": "Långt test — Bakgrund", "Long self-test started on": "Långt självtest började", "Long test — full scan, runs in background if closed": "Långt test — full scan, körs i bakgrunden om den stängs", @@ -2477,7 +3281,11 @@ "Lookup domain registration info": "Sök information om domänregistrering", "Low Container Memory": "Lågt behållareminne", "Low free space warning": "Varning för lite ledigt utrymme", + "Low-code programming for event-driven applications": "Lågkodsprogrammering för evenemangsdrivna applikationer", "Low-power CPU platform": "CPU-plattform med låg effekt", + "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation": "Luanti (tidigare Minetest) är en öppen källkod voxel spelskapande plattform med enkel modding och spelskapande", + "Lucky web interface": "Lucky webbgränssnitt", + "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.": "Lychee är ett gratis fotohanteringsverktyg som körs på din server eller webbutrymme. Installation är en fråga om sekunder. Ladda upp, hantera och dela bilder som från en inbyggd applikation. Lychee kommer med allt du behöver och alla dina bilder lagras säkert.", "Lynis - Security Audit": "Lynis - Säkerhetsrevision", "Lynis Management": "Lynis Management", "Lynis command not found": "Lynis-kommandot hittades inte", @@ -2492,26 +3300,38 @@ "Lynis updated to version:": "Lynis uppdaterad till version:", "Lynis version:": "Lynis version:", "Lynis was not installed from Git. Reinstalling...": "Lynis installerades inte från Git. Installerar om...", + "Lyrion Music Server is a streaming audio server for Squeezebox audio players.": "Lyrion Music Server är en strömmande ljudserver för Squeezebox ljudspelare.", "M.2 / PCIe devices:": "M.2/PCIe-enheter:", + "M3U proxy server": "M3U proxy server", "MAC Address": "MAC-adress", + "MAC address": "MAC-adress", "MACHINE TYPE": "MASKINTYP", + "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers.": "MAME är en fri och öppen källkod emulator utformad för att efterlikna hårdvaran av arkadspel, videospel konsoler, gamla datorer och andra system i programvara på moderna datorer.", "MOTD configuration updated successfully": "MOTD-konfigurationen har uppdaterats", "MOTD configuration was already up to date": "MOTD-konfigurationen var redan uppdaterad", "Machine Type": "Maskintyp", + "Machine learning": "maskininlärning", + "Machine learning profile not implemented; it is not replaced by CPU:": "Maskininlärningsprofil som inte genomförs; den ersätts inte av CPU:", "Machine type: q35": "Maskintyp: q35", "Machine: q35": "Maskin: q35", + "Main endpoint not yet defined": "Huvud endpoint ännu inte definierad", "Major version differs:": "Huvudversionen skiljer sig:", "Make sure IOMMU is properly enabled and the system has been rebooted after activation.": "Se till att IOMMU är korrekt aktiverat och att systemet har startats om efter aktivering.", "Make sure there are no critical services running as they will be interrupted. Ensure your server can be safely rebooted.": "Se till att det inte finns några viktiga tjänster som körs eftersom de kommer att avbrytas. Se till att din server säkert kan startas om.", "Make sure you have SSH or Web UI access before rebooting.": "Se till att du har tillgång till SSH eller webbgränssnitt innan du startar om.", "Makefile missing in": "Makefil saknas i", "Malformed repository entries cleaned": "Felformade arkivsposter rensade", + "Manage OCI": "Hantera OCI", + "Manage OCI stack": "Hantera OCI stack", "Manage PBS encryption keyfile": "Hantera PBS-krypteringsnyckelfil", "Manage Secure Gateway": "Hantera Secure Gateway", "Manage and inspect VM disk images": "Hantera och inspektera VM-diskavbildningar", "Manage custom backup paths": "Hantera anpassade säkerhetskopieringsvägar", "Manage custom paths (add / remove your folders)": "Hantera anpassade sökvägar (lägg till / ta bort dina mappar)", + "Manage installed OCI applications": "Hantera installerade OCI-program", "Manage local backup target": "Hantera lokalt mål för säkerhetskopiering", + "Managed disks must have backup enabled and a valid size": "Hanterade diskar måste ha backup aktiverad och en giltig storlek", + "Managing Nginx proxy hosts with a simple, powerful interface.": "Hantera Nginx proxy värdar med ett enkelt, kraftfullt gränssnitt.", "Manual CLI Guide (Disk and Storage Manager)": "Manuell CLI-guide (disk- och lagringshanterare)", "Manual CLI Guide (GPU/TPU)": "Manuell CLI-guide (GPU/TPU)", "Manual Guide: Convert LXC Privileged to Unprivileged": "Manuell guide: Konvertera LXC Privileged till Unprivileged", @@ -2526,29 +3346,50 @@ "Manual review is required.": "Manuell granskning krävs.", "Manual steps recommended after import": "Manuella steg rekommenderas efter import", "Manual upgrade guide step by step": "Manuell uppgraderingsguide steg för steg", + "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing.": "Manyfold är en öppen källkod, självvärd webbapplikation för att hantera en samling av 3D-modeller, särskilt fokuserad på 3D-utskrift.", "Mapped GID on host": "Mappad GID på värd", "Mapped UID on host": "Mappat UID på värd", + "Mariadb is one of the most popular database servers. Made by the original developers of MySQL.": "Mariadb är en av de mest populära databasservrarna. Tillverkad av de ursprungliga utvecklarna av MySQL.", + "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..": "Mastodon är en gratis, öppen källkod sociala nätverksserver baserad på ActivityPub där användare kan följa vänner och upptäcka nya.", "Max FD limit / ulimit configured": "Max FD-gräns / ulimit konfigurerad", "Max FS open files configuration created successfully": "Max FS öppna filer konfiguration skapad framgångsrikt", "Max user watches configured": "Max användarklockor har konfigurerats", "Maximum auto-repair attempts reached (3). Please review the log and run any remaining commands manually.": "Maximalt antal autoreparationsförsök har uppnåtts (3). Granska loggen och kör eventuella återstående kommandon manuellt.", "May need to restart terminal": "Kan behöva starta om terminalen", + "Media & Streaming": "Media & Streaming", + "Media discovery and request management for Jellyfin, Plex and Emby.": "Media discovery och request management för Jellyfin, Plex och Emby.", + "Media library transcoding and health checking, with an internal worker node.": "Mediebiblioteksöverkodning och hälsokontroll, med en intern arbetstagarnod.", + "Media server": "Media server", + "Media server selection cancelled or invalid": "Mediaserverval annullerat eller ogiltigt", + "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well.": "MediaElch är en MediaManager för Kodi. Information om filmer, TV-program, konserter och musik lagras som nfo-filer. Fanarts hämtas automatiskt från fanart.tv. Med hjälp av nfo-generatorn kan MediaElch också användas med andra MediaCenters.", + "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.": "Medusa är en automatisk Video Library Manager för TV-program. Den tittar på nya avsnitt av dina favoritprogram, och när de publiceras gör den sin magi.", + "Memory": "Minne", + "Memory in MB": "Minne i MB", "Memory optimization completed.": "Minnesoptimering slutförd.", "Memory optimizations removed": "Minnesoptimeringar har tagits bort", "Memory restored.": "Minnet återställt.", "Memory settings optimized successfully": "Minnesinställningarna har optimerats", "Memory:": "Minne:", + "Memos is a lightweight, self-hosted memo hub. Open Source and Free forever.": "Memos är en lätt, självhäftad memo hub. Open Source och gratis för alltid.", + "Messaging & Queues": "Messaging & Queues", + "Messenger for the Decentralized Web": "Messenger för den decentraliserade webben", "Method:": "Metod:", + "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium.": "Microsoft Edge är en plattformswebbläsare som utvecklats av Microsoft och baserat på Chromium.", "Migrate VMs away from node being upgraded": "Migrera virtuella datorer bort från noden som uppgraderas", "Migrate away any guests that must keep running": "Migrera bort alla gäster som måste fortsätta springa", "Migrated": "Migrerade", "Migrated legacy ProxMenux NVIDIA blacklist state — module will reload after reboot": "Migrerat äldre ProxMenux NVIDIA-svartlistatillstånd — modulen laddas om efter omstart", + "MineOS web interface": "MineOS webbgränssnitt", + "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards.": "Minisatip är en multi-threaded satip server version 1.2 som körs under Linux och det testades med DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC och ISDB-T-kort.", "Mirror URL not available for this script.": "Mirror URL inte tillgänglig för det här skriptet.", + "Miscellaneous": "Miscellan", "Missing": "Saknad", "Missing commands after installation:": "Saknade kommandon efter installation:", "Missing dependency": "Saknat beroende", + "Missing native directive:": "Missing native direktiv:", "Missing on target:": "Saknas på mål:", "Missing or invalid parameter": "Saknas eller ogiltig parameter", + "Missing required command:": "Missing required kommando:", "Missing required parameter": "Erforderlig parameter saknas", "Mixed GPU Modes": "Blandade GPU-lägen", "Mixed current mode detected in selected GPU(s).": "Blandat nuvarande läge upptäckts i valda GPU(er).", @@ -2556,15 +3397,20 @@ "Mode": "Läge", "Model": "Modell", "Modern resource monitor (press q to exit)": "Modern resursmonitor (tryck på q för att avsluta)", + "Modern, easy to use download automation for torrents and usenet.": "Modern, lätt att använda nedladdningsautomation för torrents och Usenet.", "Modifying Fastfetch configuration...": "Ändrar Fastfetch-konfiguration...", "Modules configuration updated.": "Modulkonfigurationen uppdaterad.", "Modules loaded.": "Moduler laddade.", + "MongoDB 4.4, the last series that runs on a CPU without AVX.": "MongoDB 4.4, den sista serien som körs på en CPU utan AVX.", + "Monica is an open source personal relationship management system, that lets you document your life.": "Monica är ett open source personlighetshanteringssystem som låter dig dokumentera ditt liv.", "Monitor Activated": "Monitor aktiverad", "Monitor Deactivated": "Monitor avaktiverad", "Monitor URL": "Övervaka URL", "Monitor disk I/O usage (press q to exit)": "Övervaka disk I/O-användning (tryck på q för att avsluta)", "Monitor progress:": "Övervaka framsteg:", + "Monitor, analyze, and alert on network performance.": "Övervaka, analysera och varna på nätverksprestanda.", "Monitoring": "Övervakning", + "Monitoring & Analytics": "Övervakning och analys", "Most common cause: the archive is corrupted (interrupted write, partial copy, or storage issue).": "Vanligaste orsaken: arkivet är skadat (avbruten skrivning, delvis kopiering eller lagringsproblem).", "Mount Added Successfully:": "Montering har lagts till:", "Mount CIFS share:": "Montera CIFS-andel:", @@ -2592,13 +3438,19 @@ "Mount Samba Share on Host": "Montera Samba-delning på värden", "Mount USB disk?": "Montera USB-disk?", "Mount a USB drive now": "Montera en USB-enhet nu", + "Mount activation cancelled": "Mount aktivering avbruten", "Mount all datasets": "Montera alla datauppsättningar", "Mount already exists for this path in container": "Montering finns redan för den här sökvägen i behållaren", "Mount and persist with UUID:": "Montera och bestå med UUID:", + "Mount configuration cancelled": "Mount konfiguration inställd", "Mount failed": "Monteringen misslyckades", + "Mount mode applied": "Mount läge tillämpat", + "Mount name": "Mount namn", + "Mount not authorized by the operation": "Mount som inte godkänts av operation", "Mount options:": "Monteringsalternativ:", "Mount path must be an absolute path starting with /": "Monteringsväg måste vara en absolut väg som börjar med /", "Mount path:": "Monteringsväg:", + "Mount paths must not overlap": "Mount vägar får inte överlappa", "Mount point created": "Monteringspunkt skapad", "Mount point created.": "Monteringspunkt skapad.", "Mount point is visible but NOT writable from inside the container": "Monteringspunkten är synlig men INTE skrivbar inifrån behållaren", @@ -2607,11 +3459,13 @@ "Mount point ready:": "Monteringspunkt redo:", "Mount point removed successfully": "Monteringspunkten har tagits bort", "Mount point:": "Monteringspunkt:", + "Mount points added:": "Mount poäng tillsatt:", "Mount shares on HOST first": "Montera andelar på HOST först", "Mount specific dataset": "Montera specifik datauppsättning", "Mount status:": "Monteringsstatus:", "Mount this device and use it as the backup destination?": "Vill du montera den här enheten och använda den som destination för säkerhetskopiering?", "Mount was busy — performed lazy unmount": "Mount var upptagen — utförde lata avmontering", + "Mount your cloud drive on your home NAS": "Montera din molndrivning på ditt hem NAS", "Mounted": "Monterad", "Mounted ISO on device": "Monterad ISO på enheten", "Mounted at": "Monteras vid", @@ -2626,8 +3480,17 @@ "Mounting here will hide existing files until unmounted.": "Montering här kommer att dölja befintliga filer tills de avmonteras.", "Move that copy offsite (USB, password manager, another host). Delete it from this path when done.": "Flytta kopian från platsen (USB, lösenordshanterare, en annan värd). Ta bort den från den här sökvägen när du är klar.", "Move to target VM (remove from source VM config)": "Flytta till mål-VM (ta bort från käll-VM-konfiguration)", + "Moving the data volumes aside": "Flytta datavolymerna åt sidan", + "Moving the data volumes aside...": "Flytta datavolymerna åt sidan...", + "Multi-container application (experimental)": "Multicontainer-applikation (experimentell)", + "Multi-line variables are not supported": "Multi-line variabler stöds inte", + "Multiple networks or external networks are not yet supported": "Flera nätverk eller externa nätverk stöds ännu inte", "Multiple recovery groups found in PBS. Pick the one that originally created the keyfile:": "Flera återställningsgrupper hittades i PBS. Välj den som ursprungligen skapade nyckelfilen:", "Multiple rootfs directories were found in this archive. Restore cannot continue automatically.": "Flera rootfs-kataloger hittades i detta arkiv. Återställningen kan inte fortsätta automatiskt.", + "Music Collection and Streaming Server": "Music Collection och Streaming Server", + "Music software that transforms your listening experience": "Musikprogramvara som omvandlar din lyssnarupplevelse", + "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more.": "MySQL Workbench är ett enhetligt visuellt verktyg för databasarkitekter, utvecklare och DBA. MySQL Workbench tillhandahåller datamodellering, SQL-utveckling och omfattande administrationsverktyg för serverkonfiguration, användaradministration, backup och mycket mer.", + "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL.": "Mylar3 är en automatiserad Comic Book downloader (cbr/cbz) för användning med NZB och torrenter skrivna i python. Den stöder SABnzbd, NZBGET och många torrentklienter utöver DDL.", "NAS Systems": "NAS-system", "NETWORK CONFIGURATION ANALYSIS": "NÄTVERKSKONFIGURATIONSANALYS", "NFS Access Restricted": "NFS-åtkomst begränsad", @@ -2691,24 +3554,33 @@ "NOT FOUND": "HITTADE INTE", "NOTE: The host directory and its contents will remain unchanged.": "OBS: Värdkatalogen och dess innehåll förblir oförändrade.", "NVENC patch detected — list narrowed to versions supported by keylase/nvidia-patch.": "NVENC-patch upptäckt — listan minskad till versioner som stöds av keylase/nvidia-patch.", + "NVIDIA (CUDA)": "NVIDIA (CUDA)", + "NVIDIA (CUDA; official GPU image)": "NVIDIA (CUDA, officiell GPU-bild)", + "NVIDIA (NVDEC/CUDA)": "NVIDIA (NVDEC/CUDA)", + "NVIDIA (NVENC/NVDEC)": "NVIDIA (NVENC/NVDEC)", "NVIDIA Actions": "NVIDIA-åtgärder", "NVIDIA CPU hiding already configured": "NVIDIA CPU-döljning har redan konfigurerats", "NVIDIA Container Toolkit": "NVIDIA Container Toolkit", + "NVIDIA Container Toolkit could not generate the runtime inventory": "NVIDIA Container Toolkit kunde inte generera runtime inventering", "NVIDIA Container Toolkit installed. GPU validation pending until the host restarts.": "NVIDIA Container Toolkit installerat. GPU-validering väntar tills värden startar om.", "NVIDIA Container Toolkit is incomplete. Missing:": "NVIDIA Container Toolkit är ofullständig. Saknad:", "NVIDIA Container Toolkit is installed but its command line did not answer.": "NVIDIA Container Toolkit är installerat men dess kommandorad svarade inte.", + "NVIDIA Container Toolkit is missing on the host (nvidia-container-cli)": "NVIDIA Container Toolkit saknas på värden (nvidia-container-cli)", "NVIDIA Container Toolkit verified against the running driver.": "NVIDIA Container Toolkit har verifierats mot drivrutinen som körs.", "NVIDIA DKMS entries removed.": "NVIDIA DKMS-poster har tagits bort.", "NVIDIA Driver Uninstall": "Avinstallera NVIDIA-drivrutinen", "NVIDIA Driver Version": "NVIDIA drivrutinsversion", "NVIDIA Drivers": "NVIDIA-drivrutiner", "NVIDIA Drivers Not Found": "NVIDIA-drivrutiner hittades inte", + "NVIDIA GPU / CUDA (Toolkit on the host)": "NVIDIA GPU / CUDA (Toolkit på värden)", "NVIDIA GPU Driver Installation": "NVIDIA GPU-drivrutininstallation", "NVIDIA GPU passthrough configured.": "NVIDIA GPU-genomföring har konfigurerats.", + "NVIDIA GPU prepared:": "NVIDIA GPU förberedd:", "NVIDIA KVM args configured (kvm=off, vendor_id spoof)": "NVIDIA KVM-arg konfigurerade (kvm=off, vendor_id spoof)", "NVIDIA KVM hiding (cpu hidden=1)": "NVIDIA KVM döljer (cpu dold=1)", "NVIDIA KVM hiding already configured": "NVIDIA KVM-döljning redan konfigurerad", "NVIDIA Patch": "NVIDIA-patch", + "NVIDIA device outside the expected native profile": "NVIDIA-enhet utanför den förväntade inhemska profilen", "NVIDIA driver": "NVIDIA-drivrutinen", "NVIDIA driver installed successfully.": "NVIDIA-drivrutinen har installerats.", "NVIDIA driver installed:": "NVIDIA-drivrutin installerad:", @@ -2716,6 +3588,7 @@ "NVIDIA drivers are not installed or not loaded on this host.": "NVIDIA-drivrutiner är inte installerade eller laddade inte på denna värd.", "NVIDIA host services disabled for VFIO mode": "NVIDIA-värdtjänster inaktiverade för VFIO-läge", "NVIDIA host services/autoload already aligned for native mode": "NVIDIA-värdtjänster/autoload redan justerad för inbyggt läge", + "NVIDIA inside the container does not match the host driver or GPU": "NVIDIA inuti behållaren matchar inte värdföraren eller GPU", "NVIDIA install incomplete. Check log:": "NVIDIA-installationen är ofullständig. Kontrollera logg:", "NVIDIA installer downloaded successfully": "NVIDIA-installationsprogrammet har laddats ned", "NVIDIA installer extracted.": "NVIDIA-installationsprogrammet extraherades.", @@ -2724,29 +3597,50 @@ "NVIDIA installer returned error": "NVIDIA-installationsprogrammet returnerade fel", "NVIDIA kernel modules unloaded successfully.": "NVIDIA-kärnmoduler har lossats.", "NVIDIA libs require approximately 1.5GB of free space.": "NVIDIA libs kräver ungefär 1,5 GB ledigt utrymme.", + "NVIDIA mount with an unauthorized source or target": "NVIDIA montering med en obehörig källa eller mål", "NVIDIA patch applied - check README for supported versions.": "NVIDIA-patch tillämpad - kontrollera README för versioner som stöds.", "NVIDIA patch not applied.": "NVIDIA-patch har inte tillämpats.", "NVIDIA per-BDF VFIO binding configured": "NVIDIA per-BDF VFIO-bindning konfigurerad", + "NVIDIA permissions or device nodes differ from the official inventory": "NVIDIA-behörigheter eller enhetsnoder skiljer sig från den officiella inventeringen", + "NVIDIA refresh validated; the container is stopped and its settings are kept": "NVIDIA uppdatering valideras; behållaren stoppas och dess inställningar hålls", + "NVIDIA runtime libraries or components are missing": "NVIDIA runtime bibliotek eller komponenter saknas", + "NVIDIA selection not supported by this profile": "NVIDIA-val som inte stöds av denna profil", "NVIDIA services stopped and disabled.": "NVIDIA-tjänster stoppades och inaktiverades.", "NVIDIA udev rules and persistence service installed.": "NVIDIAs udev-regler och persistenstjänst installerad.", "NVIDIA uninstallation steps completed.": "Avinstallationsstegen för NVIDIA har slutförts.", "NVIDIA uninstaller completed.": "Avinstallationsprogrammet för NVIDIA slutfört.", "NVIDIA update failed for LXC": "NVIDIA-uppdatering misslyckades för LXC", "NVIDIA userspace libraries installed.": "NVIDIA-användarutrymmesbibliotek installerade.", + "NVML does not match the current host driver": "NVML matchar inte den nuvarande värdföraren", "NVMe Disk Detected": "NVMe-disk upptäckt", "NVMe critical_warning is 0 (no critical warnings reported).": "NVMe critical_warning är 0 (inga kritiska varningar har rapporterats).", + "NVMe health status: PASSED": "NVMe hälsostatus: Godkänd", "NVMe health status: WARNING (critical_warning =": "NVMe hälsostatus: VARNING (critical_warning =", "NVMe skipped (to add as PCIe use 'Add Controller or NVMe PCIe to VM'):": "NVMe hoppade över (för att lägga till som PCIe använd 'Lägg till styrenhet eller NVMe PCIe till VM'):", "NVMe-specific SMART log": "NVMe-specifik SMART-logg", + "NVR & Cameras": "NVR & Kameror", + "NVR with optional VA-API video acceleration and hardware object detectors": "NVR med valfri VA-API videoacceleration och hårdvaruobjektdetektorer", + "NZBGet web interface": "NZBGet webbgränssnitt", + "Name": "Namnnamn", + "Name for this application": "Namn för denna ansökan", "Name for this target:": "Namn på detta mål:", + "Name of the PostgreSQL user created on the first start": "Namnet på PostgreSQL-användaren som skapats i första början", + "Name of the database created on the first start": "Namnet på databasen som skapats i första början", + "Name of the internal worker node": "Namn på den interna arbetarnoden", + "Name of this wallabag instance, shown in the interface and in 2FA codes": "Namn på denna wallabag instans, visas i gränssnittet och i 2FA-koder", + "Name or part of the description of the application": "Namn eller del av beskrivningen av ansökan", "Name:": "Namn:", + "Named accounts need private mode. Stop the container, set public: false in /config/config.js, start it again and create each user with: pct exec -- env THELOUNGE_HOME=/config s6-setuidgid abc thelounge add ": "Namngivna konton behöver privat läge. Stoppa behållaren, ställ in offentligt: falskt i /config/config.js, starta den igen och skapa varje användare med: pct exec - env THELOUNGE HOME=/config s6-setuidgid abc thelounge addera ", "Neither /etc/kernel/cmdline nor /etc/default/grub found.": "Varken /etc/kernel/cmdline eller /etc/default/grub hittades.", "Nesting feature enabled": "Kapningsfunktionen aktiverad", "NetBIOS Service: RUNNING": "NetBIOS-tjänst: KÖR", "NetBIOS Service: STOPPED": "NetBIOS-tjänst: STOPPAT", "NetBIOS port 139:": "NetBIOS-port 139:", + "NetBox": "NetBox", + "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations.": "Netbox är ett IP-adresshantering (IPAM) och datacenter infrastrukturhantering (DCIM) verktyg. Initialt utformad av nätverksteknikteamet på DigitalOcean, utvecklades NetBox specifikt för att tillgodose behoven hos nätverks- och infrastrukturingenjörer. Den är avsedd att fungera som en domänspecifik källa till sanning för operations.", "Network": "Nätverk", "Network :": "Nätverk:", + "Network & Firewall": "Network & Firewall", "Network (interfaces, DNS)": "Nätverk (gränssnitt, DNS)", "Network Bridge": "Nätverksbrygga", "Network Commands": "Nätverkskommandon", @@ -2764,6 +3658,7 @@ "Network Restarted": "Nätverket har startat om", "Network Tools": "Nätverksverktyg", "Network access:": "Nätverksåtkomst:", + "Network bridge": "Nätverksbro", "Network configuration backed up": "Nätverkskonfiguration säkerhetskopierad", "Network configuration has been restored from backup.": "Nätverkskonfigurationen har återställts från säkerhetskopian.", "Network connection failed to": "Det gick inte att ansluta till nätverket", @@ -2776,12 +3671,16 @@ "Network service restarted successfully": "Nätverkstjänsten har startat om", "Network service restarted successfully.": "Nätverkstjänsten har startat om.", "Network share mounting (NFS/Samba) requires a PRIVILEGED container.": "Nätverksdelningsmontering (NFS/Samba) kräver en PRIVILEGERAD behållare.", + "Network sysctls prepared:": "Nätverkssysktil förberedda:", "Network throughput test (client/server)": "Test av nätverksgenomströmning (klient/server)", + "Network-wide Ad Blocking": "Nätverksövergripande annonsblockering", + "Network-wide ad and tracker blocking": "Nätverksövergripande annons och tracker blockering", "NetworkManager Detected": "NetworkManager upptäckt", "NetworkManager has been removed successfully": "NetworkManager har tagits bort", "NetworkManager is running (may cause conflicts)": "NetworkManager körs (kan orsaka konflikter)", "NetworkManager is running, which may conflict with Proxmox.": "NetworkManager körs, vilket kan komma i konflikt med Proxmox.", "NetworkManager not running": "NetworkManager körs inte", + "Networks the peers reach through the tunnel (0.0.0.0/0 = all traffic)": "Nätverk som kamraterna når genom tunneln (0.0.0.0/0 = all trafik)", "New Folder in /mnt": "Ny mapp i /mnt", "New Group": "Ny grupp", "New Search": "Ny sökning", @@ -2789,14 +3688,26 @@ "New Virtual Machine": "Ny virtuell maskin", "New backup job": "Nytt säkerhetskopia jobb", "New backups on this host will be unencrypted until a new keyfile is set up.": "Nya säkerhetskopior på denna värd kommer att vara okrypterade tills en ny nyckelfil ställs in.", + "New image compatible:": "Ny bildkompatibel:", + "New image installed": "Ny bild installerad", + "New image installed, not verified yet": "Ny bild installerad, inte verifierad ännu", + "New image verified, not saved yet": "Ny bild verifierad, inte sparad ännu", "New kernel staged; rebuilding DKMS drivers:": "Ny kärna iscensatt; bygga om DKMS-drivrutiner:", "New mount options to apply:": "Nya monteringsalternativ att tillämpa:", "New scheduled job (own timer + retention)": "Nytt schemalagt jobb (egen timer + retention)", + "New value for": "Nytt värde för", "New version available": "Ny version tillgänglig", "New version:": "Ny version:", "Next Step Required": "Nästa steg krävs", "Next Steps:": "Nästa steg:", "Next step: stop that VM first, then run": "Nästa steg: stoppa den virtuella datorn först och kör sedan", + "Nextcloud configuration cancelled": "Nextcloud konfiguration annullerad", + "Nextcloud gives you access to all your files wherever you are.": "Nextcloud ger dig tillgång till alla dina filer var du än är.", + "Nextcloud volume size in GB": "Nextcloud volymstorlek i GB", + "Nextcloud with private PostgreSQL and Redis dependencies": "Nextcloud med privata PostgreSQL och Redis beroenden", + "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server.": "Nginx är en HTTP-webbserver, omvänd proxy, content cache, load balancer, TCP / UDP proxyserver och mail proxyserver.", + "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.": "Nginx webbserver och omvänd proxy med php stöd och en inbyggd Certbot (Let's Encrypt) klient. Den innehåller också fail2ban för intrångsförebyggande.", + "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd.": "Ngircd är en gratis, portabel och lätt Internet Relay Chat-server för små eller privata nätverk, utvecklad under GNU General Public License (GPL). Det är lätt att konfigurera, kan hantera dynamiska IP-adresser och stöder IPv6, SSL-skyddade anslutningar samt PAM för autentisering. Det är skrivet från början och inte baserat på den ursprungliga IRCd.", "No": "Inga", "No .ova or .ovf files found in:": "Inga .ova- eller .ovf-filer hittades i:", "No .ovf descriptor found inside OVA.": "Ingen .ovf-beskrivning hittades i OVA.", @@ -2814,6 +3725,7 @@ "No CTs available in the system.": "Inga datortomografier tillgängliga i systemet.", "No Changes Needed": "Inga ändringar behövs", "No Cleanup Needed": "Ingen rengöring behövs", + "No Compose file was given": "Ingen Compose-fil gavs", "No Controller/NVMe selected for now.": "Ingen styrenhet/NVMe har valts för tillfället.", "No Coral Detected": "Ingen Coral upptäckt", "No Coral TPU device was found on this host (neither PCIe/M.2 nor USB).": "Ingen Coral TPU-enhet hittades på denna värd (varken PCIe/M.2 eller USB).", @@ -2825,6 +3737,7 @@ "No Exports": "Ingen export", "No Exports Found": "Ingen export hittades", "No Folders": "Inga mappar", + "No GPU (CPU)": "Ingen GPU (CPU)", "No GPU Detected": "Ingen GPU upptäckt", "No GPU selected.": "Ingen GPU har valts.", "No GPU selected. Please select at least one GPU to continue.": "Ingen GPU har valts. Välj minst en GPU för att fortsätta.", @@ -2832,12 +3745,15 @@ "No Guest Shares": "Inga gästandelar", "No IP": "Ingen IP", "No IP assigned": "Ingen IP tilldelad", + "No IPv4 address was detected after 30 seconds.": "Ingen IPv4-adress upptäcktes efter 30 sekunder.", "No ISO file detected after UUP Dump process.": "Ingen ISO-fil upptäcktes efter UUP Dump-processen.", "No ISO images found in Proxmox ISO storages.": "Inga ISO-bilder hittades i Proxmox ISO-lagringar.", "No ISO selected.": "Ingen ISO vald.", "No ISO was generated.": "Ingen ISO genererades.", "No Images Found": "Inga bilder hittades", "No Intel GPU detected on this system.": "Ingen Intel GPU upptäckt på detta system.", + "No LAN address was obtained": "Ingen LAN-adress erhölls", + "No LAN address was obtained for the service:": "Ingen LAN-adress erhölls för tjänsten:", "No LXC containers available": "Inga LXC-behållare tillgängliga", "No LXC containers found": "Inga LXC-behållare hittades", "No LXC containers found on this system.": "Inga LXC-behållare hittades på detta system.", @@ -2855,7 +3771,9 @@ "No NFS shares currently mounted.": "Inga NFS-resurser är för närvarande monterade.", "No NVIDIA GPU detected on this system.": "Ingen NVIDIA GPU upptäckt på detta system.", "No NVIDIA GPU has been detected on this system. The installer will now exit.": "Ingen NVIDIA GPU har upptäckts på det här systemet. Installationsprogrammet avslutas nu.", + "No NVIDIA GPU is available": "Ingen NVIDIA GPU är tillgänglig", "No NVIDIA driver installed.": "Ingen NVIDIA-drivrutin installerad.", + "No OCI instances are registered.": "Inga OCI-instanser registreras.", "No PBS keyfile is installed on this host and no automatic recovery was possible.": "Ingen PBS-nyckelfil är installerad på denna värd och ingen automatisk återställning var möjlig.", "No PVE vzdump job uses a": "Inget PVE vzdump-jobb använder en", "No PVs with old headers found.": "Inga PV:er med gamla rubriker hittades.", @@ -2891,6 +3809,7 @@ "No Virtual Machines found on this system.": "Inga virtuella maskiner hittades på detta system.", "No ZFS pools detected. Skipping ZFS ARC optimization.": "Inga ZFS-pooler upptäcktes. Hoppa över ZFS ARC-optimering.", "No ZFS pools detected. Skipping ZFS autotrim.": "Inga ZFS-pooler upptäcktes. Hoppa över ZFS autotrim.", + "No acceleration (CPU)": "Ingen acceleration (CPU)", "No accessible": "Ingen tillgänglig", "No accessible NFS servers found.": "Inga tillgängliga NFS-servrar hittades.", "No accessible Samba servers found.": "Inga tillgängliga Samba-servrar hittades.", @@ -2900,11 +3819,13 @@ "No active session": "Ingen aktiv session", "No additional GPU can be added.": "Ingen ytterligare GPU kan läggas till.", "No additional device needs to be added.": "Ingen ytterligare enhet behöver läggas till.", + "No applications match": "Inga applikationer matchar", "No archives": "Inga arkiv", "No archives found in this Borg repository.": "Inga arkiv hittades i detta Borg-förråd.", "No available Controllers/NVMe devices were found.": "Inga tillgängliga kontroller/NVMe-enheter hittades.", "No available disks found.": "Inga tillgängliga diskar hittades.", "No backup found, logrotate configuration not changed": "Ingen säkerhetskopia hittades, logrotate-konfigurationen har inte ändrats", + "No backup is scheduled: the rsnapshot lines in /config/crontabs/root are commented out. Uncomment or adjust the intervals you want, then restart the container.": "Ingen säkerhetskopia är schemalagd: rsnapshot-linjerna i /config /crontabs / rot kommenteras. Kommentera eller justera de intervaller du vill, starta sedan om behållaren.", "No backups": "Inga säkerhetskopior", "No backups found": "Inga säkerhetskopior hittades", "No bridge configuration issues found": "Inga problem med bryggkonfiguration hittades", @@ -2921,6 +3842,7 @@ "No compatible PVE jobs": "Inga kompatibla PVE-jobb", "No compatible disk images found in:": "Inga kompatibla diskbilder hittades i:", "No configuration issues found": "Inga konfigurationsproblem hittades", + "No container of the stack was modified.": "Ingen behållare av stacken modifierades.", "No container runtime available.": "Ingen containerkörning tillgänglig.", "No container selected. Exiting.": "Ingen behållare har valts. Avslutar.", "No controller/NVMe selected.": "Ingen styrenhet/NVMe har valts.", @@ -2951,11 +3873,13 @@ "No folders found in /mnt. Please create a new folder.": "Inga mappar hittades i /mnt. Skapa en ny mapp.", "No folders found inside /mnt in the CT.": "Inga mappar hittades inuti /mnt i CT.", "No format-safe disks are available.": "Inga formatsäkra diskar är tillgängliga.", + "No free ProxMenux private /24 network is available": "Inget gratis ProxMenux privat /24 nätverk är tillgängligt", "No gasket DKMS registrations remain.": "Inga gasket DKMS-registreringar finns kvar.", "No group creation required — uses world-writable sticky bit permissions.": "Inget gruppskapande krävs – använder världsskrivbara sticky bit-behörigheter.", "No host VFIO reconfiguration expected": "Ingen värd VFIO-omkonfiguration förväntas", "No host VFIO/native binding changes were required.": "Inga värd VFIO/native bindningsändringar krävdes.", "No host backups were found in this PBS repository:": "Inga värdsäkerhetskopior hittades i detta PBS-förråd:", + "No host directory is used by this application.": "Ingen värdkatalog används av denna ansökan.", "No host reboot expected": "Ingen värdstart förväntas", "No host write access — server-side ACL or root_squash. Continuing anyway.": "Ingen skrivåtkomst från värden – ACL på serversidan eller root_squash. Fortsätter ändå.", "No host write access — server-side ACL. Continuing anyway.": "Ingen värdskrivåtkomst — ACL på serversidan. Fortsätter i alla fall.", @@ -2964,6 +3888,7 @@ "No iSCSI storage configured.": "Ingen iSCSI-lagring konfigurerad.", "No iSCSI storage found in Proxmox.": "Ingen iSCSI-lagring hittades i Proxmox.", "No iSCSI targets found on portal": "Inga iSCSI-mål hittades på portalen", + "No image was given": "Ingen bild gavs", "No import disks selected for now.": "Inga importdiskar har valts för tillfället.", "No importable disks available. System disks and protected disks are hidden.": "Inga importerbara diskar tillgängliga. Systemdiskar och skyddade diskar är dolda.", "No installation information available.": "Ingen installationsinformation tillgänglig.", @@ -2975,6 +3900,7 @@ "No mount point was specified.": "Ingen monteringspunkt angavs.", "No mount points found in any container": "Inga monteringspunkter hittades i någon behållare", "No mount points found in container": "Inga monteringspunkter hittades i behållaren", + "No name was given": "Inget namn gavs", "No network configuration backups found.": "Inga säkerhetskopior av nätverkskonfiguration hittades.", "No network interfaces configured (besides loopback)": "Inga nätverksgränssnitt konfigurerade (förutom loopback)", "No new Controller/NVMe entries were added.": "Inga nya kontroller/NVMe-poster har lagts till.", @@ -2999,9 +3925,11 @@ "No scheduled backup jobs configured.": "Inga schemalagda säkerhetskopieringsjobb har konfigurerats.", "No scheduled backup jobs found.": "Inga schemalagda säkerhetskopieringsjobb hittades.", "No scripts found for:": "Inga skript hittades för:", + "No security relaxation is required for the reviewed profile.": "Ingen säkerhetsavslappning är required för den granskade profilen.", "No self-test history found for": "Ingen självtesthistorik hittades för", "No self-test log available for": "Ingen självtestlogg tillgänglig för", "No server IP or hostname provided.": "Ingen server-IP eller värdnamn har angetts.", + "No shared media content.": "Inget delat medieinnehåll.", "No shared mount detected. Applying standard local access.": "Inget delat fäste upptäcktes. Använder standard lokal åtkomst.", "No shares configured.": "Inga delningar har konfigurerats.", "No shares found in smb.conf.": "Inga aktier hittades i smb.conf.", @@ -3031,24 +3959,34 @@ "No valid mount points found": "Inga giltiga monteringspunkter hittades", "No version in this branch is currently supported by keylase/nvidia-patch — the NVENC patch will not reapply after reinstall.": "Ingen version i den här grenen stöds för närvarande av keylase/nvidia-patch — NVENC-patchen kommer inte att tillämpas igen efter ominstallation.", "No virtual machines were found on this host.": "Inga virtuella maskiner hittades på denna värd.", + "No working NVIDIA GPU was found": "Ingen fungerande NVIDIA GPU hittades", "No write permissions on:": "Inga skrivbehörigheter på:", "No, keep local only": "Nej, behåll endast lokalt", "No-subscription repository present": "Förvar utan prenumeration finns", "No: the key stays only at": "Nej: nyckeln stannar endast kl", + "Node octal permissions (e.g. 0660)": "Nod octal behörigheter (t.ex. 0660)", "Non-Debian container detected": "Icke-Debian-behållare upptäcktes", "Non-free firmware warnings disabled": "Varningar för icke-fri firmware inaktiverade", "None": "Ingen", "Normalizing stable monitor service...": "Normaliserar stabil monitortjänst...", "Not Mounted": "Ej monterad", + "Not a JSON object:": "Inte ett JSON-objekt:", "Not all platforms support Controller/NVMe passthrough reliably.": "Alla plattformar stöder inte styrenhets-/NVMe-passthrough på ett tillförlitligt sätt.", + "Not all shared directories were verified": "Inte alla delade kataloger verifierades", "Not an OVH server, skipping RTM installation": "Inte en OVH-server, hoppar över RTM-installation", "Not currently mounted": "Ej monterad just nu", "Not currently mounted — skipping umount.": "Ej monterad för närvarande — hoppar över umount.", + "Not enough free space for the backup": "Inte tillräckligt med ledigt utrymme för backup", "Not found": "Hittade inte", + "Not found in the OCI archive:": "Finns inte i OCI-arkivet:", "Not imported:": "Ej importerad:", "Not mounted": "Ej monterad", "Not portable:": "Ej bärbar:", "Not registered as Proxmox storage — use 'LXC Mount Manager' to bind-mount": "Inte registrerad som Proxmox-lagring — använd 'LXC Mount Manager' för att binda-montera", + "Not required (access code only)": "Inte required (endast åtkomstkod)", + "Not required (password only)": "Inte required (endast lösenord)", + "Not required (token only)": "Inte required (token only)", + "Not yet verified by ProxMenux (beta)": "Ännu inte verifierad av ProxMenux (beta)", "Note: A system reboot will be required after enabling IOMMU.": "Obs: En omstart av systemet kommer att krävas efter att IOMMU har aktiverats.", "Note: this only works if the NFS server does NOT use 'all_squash' for root.": "Notera: detta fungerar bara om NFS-servern INTE använder 'all_squash' för root.", "Notes": "Anteckningar", @@ -3063,8 +4001,19 @@ "Nothing to schedule for reboot from selected paths.": "Inget att schemalägga för omstart från valda vägar.", "Nouveau module is loaded, attempting to unload...": "Nouveau-modulen laddas, försöker ladda ur...", "Number of CPU cores (default: 2)": "Antal CPU-kärnor (standard: 2)", + "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources.": "Nzbget är en Usenet downloader, skriven i C++ och utformad med prestanda i åtanke för att uppnå maximal nedladdningshastighet genom att använda mycket små systemresurser.", + "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra.": "Nzbhydra2 är en meta sökapplikation för NZB-indexers, den andliga efterträdaren till NZBmegasearcH, och en utveckling av den ursprungliga applikationen NZBHydra.", "OCI containers require Proxmox VE 9.1 or later.": "OCI-behållare kräver Proxmox VE 9.1 eller senare.", + "OCI management": "OCI management", + "OCI management could not be completed. Check the backend status; no additional cleanup has been authorized.": "OCI-hanteringen kunde inte slutföras. Kontrollera backend status; ingen ytterligare rengöring har godkänts.", + "OCI manager Apps (beta)": "OCI Manager Apps (beta)", + "OCI manager Apps is a beta: if something does not work as expected, please report it on GitHub with the application name.": "OCI Manager Apps är en beta: om något inte fungerar som förväntat, vänligen rapportera det på GitHub med applikationsnamnet.", + "OCI metadata integrity mismatch": "OCI metadata integritet mismatch", + "OCI metadata too large": "OCI metadata för stor", + "OCI verification failed:": "OCI-verifiering misslyckades:", + "OCR language (Tesseract code)": "OCR-språk (Tesseract code)", "OK": "OK", + "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms.": "ONLYOFFICE ger ett komplett utbud av verktyg för att skapa, redigera och samarbeta på textdokument, kalkylblad, presentationer, PDF-formulär och vanliga PDF-filer på webb-, skrivbords- och mobilplattformar.", "OR add new PVE 9 no-subscription repository:": "ELLER lägg till nytt PVE 9-förråd utan prenumeration:", "OS hint:": "OS-tips:", "OS release details": "OS release detaljer", @@ -3078,11 +4027,18 @@ "OVH RTM removed (Puppet artefacts may need manual cleanup)": "OVH RTM har tagits bort (Puppet artefakter kan behöva manuell rengöring)", "OVH server detected": "OVH-server upptäckt", "OVH server detection and RTM installation process completed": "OVH-serverdetektering och RTM-installation har slutförts", + "Observer is not responding on port 4357": "Observer svarar inte på port 4357", + "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption.": "Obsidian är en noterande app som låter dig skapa, länka och organisera dina anteckningar på din enhet, med hundratals plugins och teman för att anpassa ditt arbetsflöde. Du kan också publicera dina anteckningar online, komma åt dem offline och synkronisera dem säkert med end-to-end-kryptering.", "Offer as exit node?": "Erbjuda som utgångsnod?", + "Official Emby Media Server image with optional VA-API or NVIDIA acceleration.": "Officiell Emby Media Server-bild med valfri VA-API eller NVIDIA-acceleration.", + "Official Jellyfin image with optional VA-API or NVIDIA acceleration.": "Officiell Jellyfin-bild med valfri VA-API eller NVIDIA-acceleration.", "Official Linux Distributions": "Officiella Linux-distributioner", + "Official Plex Media Server image with optional hardware transcoding.": "Officiell Plex Media Server-bild med valfri hårdvaruöverföring.", + "Official image": "Officiell bild", "Old debian.sources file removed to prevent duplication": "Den gamla debian.sources-filen togs bort för att förhindra dubbelarbete", "Old memory configuration detected. Replacing with balanced optimization...": "Gammal minneskonfiguration upptäcktes. Ersätt med balanserad optimering...", "Old time services removed successfully": "Gamla tjänster har tagits bort", + "Ombi allows you to host your own Plex Request and user management system.": "Ombi gör att du kan vara värd för din egen Plex Request and user management system.", "On a privileged CT the mount options carry the only permissions.": "På en privilegierad CT har monteringsalternativen de enda behörigheterna.", "On some systems, when starting the VM the host may slow down for several minutes until it stabilizes, or freeze completely.": "På vissa system, när den virtuella datorn startas, kan värden sakta ner i flera minuter tills den stabiliseras, eller frysa helt.", "On the Borg server, append the following line to:": "På Borg-servern, lägg till följande rad till:", @@ -3091,32 +4047,53 @@ "Once finished, re-run the script 'PVE 8 to 9 check' to verify that all issues.": "När du är klar, kör skriptet 'PVE 8 till 9 check' igen för att verifiera att alla problem.", "Once installed, open the VirtIO ISO and run the installer to complete driver setup.": "När det är installerat, öppna VirtIO ISO och kör installationsprogrammet för att slutföra drivrutinsinstallationen.", "One or more NVIDIA GPUs are currently configured for VM passthrough (vfio-pci):": "En eller flera NVIDIA GPU:er är för närvarande konfigurerade för VM-passthrough (vfio-pci):", + "Online retro games emulator": "Online retro spel emulator", + "Only a Docker Swarm uses these settings, so they are not applied:": "Endast en Docker Swarm använder dessa inställningar, så de tillämpas inte:", "Only convert to privileged if absolutely necessary for your use case.": "Konvertera endast till privilegierad om det är absolut nödvändigt för ditt användningsfall.", "Only fully free disks are shown (not system-used and not referenced by VM/LXC).": "Endast helt lediga diskar visas (inte systemanvända och inte refererade av VM/LXC).", "Only if using enterprise subscription": "Endast om du använder företagsabonnemang", "Only if using no-subscription repository": "Endast om du använder ett arkiv utan prenumeration", "Only needed if you mounted the filesystem in step 6b": "Behövs endast om du monterade filsystemet i steg 6b", + "Only one image at a time can be installed this way.": "Endast en bild i taget kan installeras på detta sätt.", "Only removes storage definition, not remote data.": "Tar bara bort lagringsdefinition, inte fjärrdata.", "Only run this if you used LVM (step 6b):": "Kör bara detta om du använde LVM (steg 6b):", "Only the host backup hook is removed — PVE vzdump jobs targeting this storage stay intact.": "Endast värdbackuphaken tas bort – PVE vzdump-jobb som riktar sig till denna lagring förblir intakta.", + "Only the image reference, with no Compose file": "Endast bildreferensen, utan Compose-fil", "Open": "Öppna", + "Open Source realtime backend in 1 file": "Open Source realtime backend i 1 fil", "Open rwx + default inheritance for new files": "Öppna rwx + standardarv för nya filer", + "Open source chat UI for AI models": "Open source chat UI för AI-modeller", + "Open source home automation that puts local control and privacy first.": "Öppen källkod hemautomation som sätter lokal kontroll och integritet först.", + "Open source, lightweight, native, supports (HTTP, BitTorrent, Magnet, etc.) for downloading.": "Öppen källa, lätt, infödd, stöder (HTTP, BitTorrent, Magnet, etc.) för nedladdning.", "Open the VM console and wait for the installer to boot": "Öppna VM-konsolen och vänta tills installationsprogrammet startar", "Open the VM console and wait for the loader to boot": "Öppna VM-konsolen och vänta på att laddaren startar", "Open the dashboard from this host on port 8008 to create a new admin account.": "Öppna instrumentpanelen från denna värd på port 8008 för att skapa ett nytt administratörskonto.", "Open the dashboard to create a new admin account:": "Öppna instrumentpanelen för att skapa ett nytt administratörskonto:", + "Open-source AI-powered coding assistant": "Open-source AI-driven kodningsassistent", + "Open-source UI for building and debugging multi-agent and RAG applications": "Open-source UI för att bygga och debugga multi-agent- och RAG-applikationer", + "Open-source self-hosted SQL IDE.": "Open-source självvärd SQL IDE.", + "OpenClaw is a personal AI assistant you run on your own devices": "OpenClaw är en personlig AI-assistent du kör på dina egna enheter", + "OpenList": "OpenList", + "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world.": "OpenShot Video Editor är en prisbelönt gratis och open-source videoredigerare för Linux, Mac och Windows, och är dedikerad till att leverera högkvalitativa videoredigerings- och animationslösningar till världen.", + "OpenVINO requires a CPU quota to keep the CPU topology": "OpenVINO requires en CPU kvot för att hålla CPU topologi", + "OpenVINO requires the render device of an Intel GPU": "OpenVINO requires render-enheten av en Intel GPU", "OpenVSwitch installation could not be verified": "OpenVSwitch-installationen kunde inte verifieras", "OpenVSwitch installed successfully": "OpenVSwitch har installerats", "OpenVSwitch is ready to use": "OpenVSwitch är redo att användas", "OpenVSwitch removed": "OpenVSwitch togs bort", + "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server.": "Openssh-server är en sandboxad miljö som tillåter ssh åtkomst utan att ge nycklar till hela servern.", + "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser.": "Openvscode-server ger en version av VS-kod som kör en server på en fjärrmaskin och tillåter åtkomst via en modern webbläsare.", + "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features.": "Opera är en multiplattformswebbläsare utvecklad av sitt namneföretag Opera. Webbläsaren är baserad på Chromium, men skiljer sig från andra Chromium-baserade webbläsare (Chrome, Edge, etc.) genom sitt användargränssnitt och andra funktioner.", "Operation": "Drift", "Operation cancelled by user": "Åtgärden avbröts av användaren", "Operation cancelled by user to create backup.": "Åtgärden avbröts av användaren för att skapa säkerhetskopia.", "Operation cancelled by user.": "Åtgärden avbröts av användaren.", + "Operation cancelled.": "Operation avbryts.", "Operation cancelled. Cannot continue with an unprivileged container.": "Åtgärden avbröts. Kan inte fortsätta med en oprivilegierad behållare.", "Operation log": "Driftlogg", "Operator config re-applied via kernel-agnostic merge": "Operatörskonfiguration tillämpas på nytt via kernel-agnostic merge", "Operator config that WILL be re-applied via kernel-agnostic merge": "Operatörskonfiguration som KOMMER att appliceras på nytt via kernel-agnostic merge", + "Optical block device (e.g. /dev/sr0)": "Optisk blockenhet (t.ex. /dev/sr0)", "Optimizations detected and ready to revert.": "Optimering har upptäckts och redo att återställas.", "Optimize": "Optimera", "Optimize Memory": "Optimera minnet", @@ -3129,8 +4106,12 @@ "Optimizing network settings...": "Optimerar nätverksinställningar...", "Optimizing vzdump backup speed...": "Optimerar vzdump säkerhetskopieringshastighet...", "Optional": "Frivillig", + "Optional GID of the plex group": "Valfri GID för plex-gruppen", "Optional GPU Passthrough": "Valfri GPU-genomföring", + "Optional published URL for Jellyfin": "Valfri publicerad URL för Jellyfin", "Optional safety helper if you ever need to re-apply manually:": "Valfri säkerhetshjälp om du någonsin behöver återansöka manuellt:", + "Optional token from https://www.plex.tv/claim": "Valfri token från https://www.plex.tv/claim", + "Optional, not mounted by default": "Valfri, inte monterad som standard", "Optional: Modernize repository sources:": "Valfritt: Modernisera arkivskällor:", "Optional: apply default ACL so new files inherit permissions:": "Valfritt: tillämpa standard ACL så att nya filer ärver behörigheter:", "Optional: register this path as Proxmox dir storage:": "Valfritt: registrera den här sökvägen som Proxmox dir-lagring:", @@ -3141,13 +4122,18 @@ "Or re-run this script and accept the 'apply host permissions' prompt.": "Eller kör det här skriptet igen och acceptera prompten \"använd värdbehörigheter\".", "Or use ProxMenux update function": "Eller använd ProxMenux uppdateringsfunktion", "Or, if your terminal can't select text, copy it from:": "Eller, om din terminal inte kan välja text, kopiera den från:", + "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community": "Orca Slicer är en öppen källkodsskiva för FDM-skrivare. OrcaSlicer är fork av Bambu Studio, det var tidigare känt som BambuStudio-SoftFever, Bambu Studio är forked från PrusaSlicer av Prusa Research, som är från Slic3r av Alessandro Ranellucci och RepRap gemenskap", "Original ZFS ARC config restored from .bak": "Original ZFS ARC-konfiguration återställd från .bak", "Original bashrc restored": "Original bashrc återställd", "Original logrotate configuration restored": "Ursprunglig logrotate-konfiguration återställd", + "Orphan stack contract archived:": "Orphan stack kontrakt arkiverad:", + "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.": "Oscam är en Open Source Conditional Access Module programvara som används för att descrambling DVB transmissions med hjälp av smarta kort. Det är både en server och en klient.", "Other Prebuilt Linux VMs": "Andra förbyggda virtuella Linux-datorer", "Output archive:": "Utdataarkiv:", + "Overseerr is a request management and media discovery tool built to work with your existing Plex ecosystem.": "Overseerr är ett verktyg för hantering och medieupptäckt för att arbeta med ditt befintliga Plex-ekosystem.", "Owner:": "Ägare:", "Ownership set to root:sharedfiles with 2775 on:": "Ägarskap inställt på root:sharedfiles med 2775 på:", + "P2P bittorrent download": "P2P bittorrent nedladdning", "PAM limits configured": "PAM-gränser konfigurerade", "PBS API log rotation configured (hourly, size-based)": "PBS API-loggrotation konfigurerad (timme, storleksbaserad)", "PBS backup error log": "PBS säkerhetskopia fellogg", @@ -3164,7 +4150,9 @@ "PCI reset method": "PCI-återställningsmetod", "PCIe GPU passthrough requires:": "PCIe GPU-genomföring kräver:", "PCIe/M.2 gasket-dkms": "PCIe/M.2 gasket-dkms", + "PCSX2 is an open source PS2 Emulator.": "PCSX2 är en öppen källkod PS2 Emulator.", "POSIX ACLs applied (access + default for inheritance).": "POSIX ACL:er tillämpas (åtkomst + standard för arv).", + "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability.": "PPSSPP är en fri och öppen källkod PSP emulator för Windows, MacOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series och Symbian med fokus på hastighet och portabilitet.", "PVE application manager updated": "PVE-applikationshanteraren uppdaterad", "PVE cache regenerated": "PVE-cache regenererad", "PVE host (where the Borg LXC lives)": "PVE-värd (där Borg LXC bor)", @@ -3179,17 +4167,28 @@ "Package update had issues, checking details...": "Paketuppdateringen hade problem, kontrollerade detaljer...", "Packages from backup to install:": "Paket från säkerhetskopia till installation:", "Packages installed: {count}.": "Paket installerade: {count}.", + "Packages to be upgraded": "Paket som ska uppgraderas", "Packages upgrade successfull": "Paketuppgraderingen lyckades", "Packages upgraded": "Paketen har uppgraderats", "Packages:": "Paket:", "Packaging OVA file...": "Förpackning av OVA-fil...", "Packing installer archive...": "Packar installationsarkiv...", + "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices.": "PairDrop är ett sublimt alternativ till AirDrop som fungerar på alla plattformar. Skicka bilder, dokument eller text via peer till peer-anslutning till enheter i samma lokala nätverk / Wi-Fi eller till parade enheter.", + "Paperless configuration cancelled": "Papperslös konfiguration inställd", + "Paperless-ngx WebUI": "Paperless-ngx WebUI", "Parsing OVF descriptor...": "Parsar OVF-beskrivning...", "Partial VM removed": "Partiell VM har tagits bort", "Partition": "Dela", "Partition created": "Partition skapad", "Partition created:": "Partition skapad:", "Partition table wiped": "Skiljebord torkat", + "Pass /dev/kvm to the LXC": "Pass /dev/kvm till LXC", + "Pass /dev/net/tun to the LXC": "Pass /dev/netto/tun till LXC", + "Pass /dev/ttyUSB0 to the LXC": "Pass /dev/ttyUSB0 till LXC", + "Pass /dev/video10 to the LXC": "Pass /dev/video10 till LXC", + "Pass /dev/video11 to the LXC": "Pass /dev/video11 till LXC", + "Pass /dev/video12 to the LXC": "Pass /dev/video12 till LXC", + "Pass a host device to the LXC": "Passera en värdenhet till LXC", "Passphrase used to unlock the imported keyfile (leave blank if the keyfile is unencrypted / kdf=none):": "Lösenfras som används för att låsa upp den importerade nyckelfilen (lämna tomt om nyckelfilen är okrypterad / kdf=ingen):", "Passphrases do not match.": "Lösenfraser matchar inte.", "Passphrases do not match. Try again.": "Lösenfraser matchar inte. Försök igen.", @@ -3202,17 +4201,42 @@ "Password confirmation cannot be empty.": "Lösenordsbekräftelsen kan inte vara tom.", "Password confirmation is required.": "Lösenordsbekräftelse krävs.", "Password for": "Lösenord för", + "Password for aMule external connections (remote client)": "Lösenord för aMule externa anslutningar (fjärrklient)", + "Password for the SSH login": "Lösenord för SSH inloggning", "Password for:": "Lösenord för:", "Password is correct": "Lösenordet är korrekt", + "Password of the AdGuard Home that receives the settings": "Lösenord för AdGuard Home som tar emot inställningarna", + "Password of the Adguardhome Sync web interface": "Lösenord för Adguardhome Sync webbgränssnitt", + "Password of the Duplicati web interface": "Lösenord för Duplicati webbgränssnitt", + "Password of the Etherpad admin user": "Lösenord för Etherpad admin användaren", + "Password of the FlexGet web interface": "Lösenord för FlexGet webbgränssnitt", + "Password of the LibreDB Studio administrator": "Lösenord för LibreDB Studio-administratören", + "Password of the MineOS web interface user": "Lösenord för MineOS webbgränssnitt användare", + "Password of the NetBox admin account": "Lösenord för NetBox admin konto", + "Password of the OpenList admin user": "Lösenord för OpenList admin användaren", + "Password of the PhotoPrism admin user (at least 8 characters)": "Lösenord för PhotoPrism-administratören (minst 8 tecken)", + "Password of the PostgreSQL user": "Lösenord för PostgreSQL-användaren", + "Password of the SnapOtter admin user": "Lösenord för SnapOtter admin användaren", + "Password of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Lösenordet för inloggningen Flowise (läs endast av Flowise-versioner före 3.0.1)", + "Password of the main AdGuard Home": "Lösenordet för AdGuard Home", "Password or API token secret:": "Lösenord eller API-token hemlighet:", + "Password or secret": "Lösenord eller hemlighet", "Password reset completed.": "Lösenordsåterställning slutförd.", + "Password to access the aMule web interface": "Lösenord för att komma åt aMule webbgränssnitt", "Passwords do not match. Please try again.": "Lösenord stämmer inte överens. Försök igen.", + "Paste it here and press Ctrl+D on an empty line.": "Klistra här och tryck på Ctrl+D på en tom linje.", + "Paste its Compose file in the terminal": "Klistra på sin komponeringsfil i terminalen", + "Paste its docker run command in the terminal": "Klistra på docker körkommandot i terminalen", "Paste the UUP Dump URL here": "Klistra in in UUP Dump URL här", "Patching source for kernel compatibility...": "Lappar källa för kärnkompatibilitet...", "Path does not exist.": "Vägen finns inte.", + "Path inside the container": "Vägen inuti behållaren", + "Path inside the container (e.g. /media-extra)": "Vägen inuti behållaren (t.ex. /media-extra)", + "Path inside the remote (empty = root)": "Vägen inuti fjärrkontrollen (tom = rot)", "Path must be absolute (start with /)": "Sökväg måste vara absolut (börja med /)", "Path must be absolute (start with /).": "Sökväg måste vara absolut (börja med /).", "Path not found": "Sökväg hittades inte", + "Path of the Compose file": "Path of the Compose filen", "Path:": "Väg:", "Paths applied:": "Tillämpade sökvägar:", "Paths included in backup": "Sökvägar som ingår i säkerhetskopia", @@ -3220,6 +4244,10 @@ "Paths skipped:": "Öppningsvägar:", "Paths to back up:": "Sökvägar att säkerhetskopiera:", "Paths:": "Sökvägar:", + "Peers reach the server through the public address and the UDP port given during the installation, so that port must be forwarded to this container.": "Peers når servern via den offentliga adressen och UDP-porten som ges under installationen, så att porten måste vidarebefordras till denna behållare.", + "Peers to create: a number (3) or a list of names (phone,laptop)": "Kamrater att skapa: ett nummer (3) eller en lista med namn (telefon,laptop)", + "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration.": "Pelorus är en AI-navigator för Selkies-drivna Linux-skrivbord. Pelorus kör en FastAPI-server som ger en LLM-agent (Ollama, OpenAI-kompatibel eller Gemini) kontroll över mus, tangentbord, skärmdump och fönsterhantering via Pixelflux datoranvändning backend, ett Linux tillgänglighetsträd (AT-SPI), och valfri KWin D-Bus integration.", + "Pending components:": "I väntan på komponenter:", "Pending restore ID:": "Väntande återställnings-ID:", "Pending restore dir:": "Väntar på återställningskatalog:", "Pending restore prepared. A reboot is required to complete it.": "Väntar på återställning förberedd. En omstart krävs för att slutföra det.", @@ -3243,7 +4271,15 @@ "Permission error": "Tillståndsfel", "Permissions:": "Behörigheter:", "Persist mount in CT /etc/fstab (optional):": "Fortsatt montering i CT /etc/fstab (valfritt):", + "Persistence for": "Persistens för", + "Persistence for the new path": "Persistens för den nya vägen", + "Persistent data:": "Persistenta data:", + "Persistent disk reused:": "Persistent disk återanvänd:", "Persistent:": "Beständig:", + "Personal finance management application": "Personlig ekonomi management ansökan", + "Photo and video library with optional GPU transcoding and machine learning": "Foto- och videobibliotek med valfri GPU-överkodning och maskininlärning", + "PhotoPrism": "PhotoPrism", + "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB.": "Phpmyadmin är ett gratis mjukvaruverktyg skrivet i PHP, avsedd att hantera administrationen av MySQL över webben. phpMyAdmin stöder ett brett utbud av operations på MySQL och MariaDB.", "Physical Function with": "Fysisk funktion med", "Physical interface": "Fysiskt gränssnitt", "Physical interfaces available": "Fysiska gränssnitt tillgängliga", @@ -3256,6 +4292,10 @@ "Pick a target to remove:": "Välj ett mål att ta bort:", "Pick an SSH private key (auto-detected on this host):": "Välj en privat SSH-nyckel (upptäcks automatiskt på denna värd):", "Pick an alternative way to authorize the new key:": "Välj ett alternativt sätt att auktorisera den nya nyckeln:", + "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time.": "Pidgin är ett chattprogram som låter dig logga in på konton på flera chattnätverk samtidigt. Detta innebär att du kan chatta med vänner på XMPP och sitta i en IRC-kanal samtidigt.", + "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper.": "Piper är en snabb, lokal neural text till talsystem som låter bra och är optimerad för Raspberry Pi 4. Denna behållare ger en Wyoming-protokollserver för Piper.", + "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures.": "Piwigo är en fotogalleri programvara för webben som kommer med kraftfulla funktioner för att publicera och hantera din samling av bilder.", + "Planka is an elegant open source project tracking tool.": "Planka är ett elegant open source-projekt spårningsverktyg.", "Please check network connectivity.": "Kontrollera nätverksanslutningen.", "Please check permissions and try again.": "Kontrollera behörigheterna och försök igen.", "Please check the installation.": "Please check the installation.", @@ -3273,6 +4313,9 @@ "Please select GPU(s) that are currently in the same mode and try again.": "Välj GPU(er) som för närvarande är i samma läge och försök igen.", "Please select a valid option": "Välj ett giltigt alternativ", "Please use an SSH session (Linux, macOS, Windows/PuTTY) or a physical console to perform the upgrade.": "Använd en SSH-session (Linux, macOS, Windows/PuTTY) eller en fysisk konsol för att utföra uppgraderingen.", + "Plex WebUI": "Plex WebUI", + "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.": "Plex organiserar video, musik och bilder från personliga mediebibliotek och strömmar dem till smarta TV-apparater, strömmande lådor och mobila enheter. Denna behållare är förpackad som en fristående Plex Media Server. Straightforward design och bulk åtgärder innebär att få saker gjort snabbare.", + "Podcast synchronization service": "Podcast synkroniseringstjänst", "Pool does not appear to use SSD/NVMe devices with discard support. Skipping ZFS autotrim for pool:": "Pool verkar inte använda SSD/NVMe-enheter med kasseringsstöd. Hoppa över ZFS autotrim för pool:", "Pool exists": "Pool finns", "Pool name matches but GUID differs (fresh ZFS install):": "Poolnamn matchar men GUID skiljer sig (ny ZFS-installation):", @@ -3283,12 +4326,21 @@ "Portal IP and port are correct": "Portal IP och port är korrekta", "Portal is reachable": "Portalen är tillgänglig", "Portal:": "Portal:", + "Ports": "Hamnar", "Portuguese": "portugisiska", "Post-Installation Options": "Alternativ efter installation", "Post-Installation Scripts": "Skript efter installation", "Postfix configuration": "Postfix-konfiguration", + "PostgreSQL": "PostgreSQL", + "PostgreSQL URL without an associated service:": "PostgreSQL URL utan tillhörande tjänst:", + "PostgreSQL creates the database named in POSTGRES_DB on the first start. The installer default is postgresql.": "PostgreSQL skapar databasen som heter POSTGRES DB i början. Installationsstandarden är postgresql.", + "PostgreSQL is an advanced, enterprise-class, and open-source relational database system. PostgreSQL supports both SQL (relational) and JSON (non-relational) querying.": "PostgreSQL är ett avancerat, företagsklass och open-source relational databassystem. PostgreSQL stöder både SQL (relational) och JSON (icke-relationell) fråga.", + "PostgreSQL requires a password": "PostgreSQL requires ett lösenord", + "PostgreSQL volume size in GB": "PostgreSQL volymstorlek i GB", "Potential QEMU startup/assertion failures": "Potentiella QEMU-start-/påståendefel", "Power state D3cold/D0 transitions may be inaccessible": "Strömtillstånd D3cold/D0-övergångar kan vara otillgängliga", + "Powerful OCR powered by DeepSeek AI": "Kraftfull OCR drivs av DeepSeek AI", + "Powerful networking tool": "Kraftfullt nätverksverktyg", "Pre-check found": "Förhandskontroll hittades", "Pre-configure destinations so you don't have to enter them every time you back up.": "Förkonfigurera destinationer så att du inte behöver ange dem varje gång du säkerhetskopierar.", "Pre-existing gasket-dkms package removed.": "Det befintliga gasket-dkms-paketet har tagits bort.", @@ -3296,11 +4348,15 @@ "Pre-upgrade check FAILED: the simulation shows that 'proxmox-ve' would be REMOVED.\n This indicates a repository or dependency issue and upgrading now could break your Proxmox installation.": "Kontroll före uppgraderingen MISSLYCKades: simuleringen visar att \"proxmox-ve\" skulle tas bort.\n Detta indikerar ett arkiv eller beroendeproblem och uppgradering nu kan bryta din Proxmox-installation.", "Pre-upgrade simulation failed. See log:": "Simulering av föruppgradering misslyckades. Se logg:", "Pre-upgrade simulation passed: 'proxmox-ve' will be kept or upgraded safely.": "Simulering före uppgradering godkänd: 'proxmox-ve' kommer att bevaras eller uppgraderas säkert.", + "Prepared; the container was not modified yet": "Förberedd; behållaren modifierades ännu inte", "Preparing Log2RAM configuration": "Förbereder Log2RAM-konfiguration", "Preparing files for backup...": "Förbereder filer för säkerhetskopiering...", "Preparing host mount...": "Förbereder värdfäste...", "Preparing pending restore (network-safe)": "Förbereder väntande återställning (nätverkssäker)", "Preparing staging area...": "Förbereder uppställningsområde...", + "Preparing the NVIDIA GPU...": "Förbered NVIDIA GPU...", + "Preparing the recreation...": "Förbereda rekreationen...", + "Preparing the update...": "Förbereda uppdateringen...", "Preserving logs to /var/log.hdd before unmounting...": "Sparar loggar till /var/log.hdd innan avmontering...", "Press 'q' to exit": "Tryck på 'q' för att avsluta", "Press Ctrl+C to stop the server and return to menu.": "Tryck på Ctrl+C för att stoppa servern och återgå till menyn.", @@ -3316,6 +4372,7 @@ "Press Enter to return": "Tryck på Enter för att gå tillbaka", "Press Enter to return to menu...": "Tryck på Enter för att återgå till menyn...", "Press Enter to return to the main menu...": "Tryck på Enter för att återgå till huvudmenyn...", + "Press Enter to return to the menu...": "Tryck på Enter för att återvända till menyn...", "Press Enter to return...": "Tryck på Enter för att gå tillbaka...", "Press Enter when the line has been pasted on the server...": "Tryck på Enter när raden har klistrats in på servern...", "Press OK to see the preview, then confirm": "Tryck på OK för att se förhandsgranskningen och bekräfta sedan", @@ -3325,9 +4382,20 @@ "Preview changes (diff)": "Förhandsgranska ändringar (diff)", "Preview: changes that would be applied": "Förhandsgranskning: ändringar som skulle tillämpas", "Previous DKMS tree cleared.": "Tidigare DKMS-träd har rensats.", + "Previous Rclone configuration restored": "Rclone konfiguration återställd", "Previous installation cleaned": "Tidigare installation rengjord", "Previous installation removed": "Tidigare installation har tagits bort", + "Previous installation restored": "Föregående installation restaurerad", "Previous shutdowns": "Tidigare avstängningar", + "Primary GID for Emby": "Primärt GID för Emby", + "Privacy-first finance app with envelope budgeting and multi-device sync.": "Privacy-first finans app med kuvert budgeting och multi-device sync.", + "Privacy-first, self-hosted PDF toolkit": "Privacy-first, självhäftad PDF-verktyg", + "Private installation record saved": "Privat installationsrekord sparad", + "Private network assigned automatically:": "Privat nätverk tilldelas automatiskt:", + "Private network of the application released:": "Privat nätverk av programmet som släppts:", + "Private network of the application that is released:": "Privat nätverk av programmet som släpps:", + "Private network:": "Privat nätverk:", + "Private personal knowledge management": "Privat personlig kunskapshantering", "Privileged": "Privilegierad", "Privileged Container": "Privilegerad container", "Privileged Container Required": "Privilegerad behållare krävs", @@ -3338,6 +4406,7 @@ "Privileged container — host root maps directly, no permission changes needed": "Privilegerad behållare - värd rotkartor direkt, inga behörighetsändringar behövs", "Privileged containers can access host devices directly": "Privilegerade behållare kan komma åt värdenheter direkt", "Privileged containers have full root access to the host system!": "Privilegerade behållare har full root-åtkomst till värdsystemet!", + "Privileged installation declined": "Privilegierad installation minskade", "Privileged: Full host access (less secure)": "Privilegerad: Full värdåtkomst (mindre säker)", "Proceed": "Fortsätta", "Proceed with removal": "Fortsätt med borttagning", @@ -3346,11 +4415,15 @@ "Process may take several minutes depending on container size": "Processen kan ta flera minuter beroende på behållarens storlek", "Process may take several minutes for large containers": "Processen kan ta flera minuter för stora behållare", "Processes using NVIDIA:": "Processer som använder NVIDIA:", + "Productivity & Workflows": "Produktivitet och arbetsflöden", "Profile": "Profil", "Profile:": "Profil:", + "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files.": "Projectsend är en självhäftad applikation som låter dig ladda upp filer och tilldela dem till specifika kunder som du skapar själv. Säker, privat och lätt. Inte mer beroende på externa tjänster eller e-post för att skicka dessa filer.", "Proposed Changes": "Föreslagna ändringar", "Proposed ZFS ARC maximum:": "Föreslagen ZFS ARC maximum:", "Provided by newer version — skipping": "Tillhandahålls av nyare version — hoppar över", + "Prowlarr does not offer the application schema:": "Prowlarr erbjuder inte ansökningsschemat:", + "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all).": "Prowlarr är en indexer manager / proxy byggd på den populära arr .net / reactjs bas stack för att integrera med dina olika PVR-appar. Prowlarr stöder både Torrent Trackers och Usenet Indexers. Det integreras sömlöst med Sonarr, Radarr, Lidarr och Readarr som erbjuder fullständig hantering av dina indexerare utan per app Indexer setup required (vi gör allt).", "ProxMenux Information": "ProxMenux information", "ProxMenux Monitor": "ProxMenux Monitor", "ProxMenux Monitor Service Verification": "ProxMenux Monitor Service Verification", @@ -3364,10 +4437,12 @@ "ProxMenux Monitor protection": "ProxMenux Monitor skydd", "ProxMenux Monitor unit repaired and restarted": "ProxMenux Monitor-enhet reparerad och omstartad", "ProxMenux Monitor → Backups tab (live progress card with estimated time, logs, rollback delta)": "ProxMenux Monitor → Fliken Säkerhetskopiering (live-förloppskort med beräknad tid, loggar, rollback-delta)", + "ProxMenux attaches directories, not single files, so this image cannot be installed yet.": "ProxMenux fäster kataloger, inte enstaka filer, så denna bild kan inte installeras ännu.", "ProxMenux can apply open permissions on this NFS directory from the host so the container can read and write:": "ProxMenux kan tillämpa öppna behörigheter på denna NFS-katalog från värden så att behållaren kan läsa och skriva:", "ProxMenux can remount it with open permissions so any LXC can read and write.": "ProxMenux kan montera om den med öppna behörigheter så att alla LXC kan läsa och skriva.", "ProxMenux cannot override NFS server-side permissions from the host.": "ProxMenux kan inte åsidosätta NFS-serversidans behörigheter från värden.", "ProxMenux customizations removed from bashrc": "ProxMenux-anpassningar har tagits bort från bashrc", + "ProxMenux does not give a container the system of its host.": "ProxMenux ger inte en behållare systemet för dess värd.", "ProxMenux does not validate the contents; any keyfile your PBS accepts is accepted here.": "ProxMenux validerar inte innehållet; alla nyckelfiler som din PBS accepterar accepteras här.", "ProxMenux files:": "ProxMenux filer:", "ProxMenux logo applied": "ProxMenux-logotyp applicerad", @@ -3399,6 +4474,7 @@ "Proxmox repository configuration completed": "Konfigurationen av Proxmox-arkivet har slutförts", "Proxmox repository fixed (no-subscription, candidate is 9.x)": "Proxmox arkiv fast (ingen prenumeration, kandidat är 9.x)", "Proxmox status:": "Proxmox status:", + "Proxmox storage for the volume": "Proxmox lagring för volymen", "Proxmox storages:": "Proxmox förråd:", "Proxmox system repair completed successfully!": "Reparationen av Proxmox-systemet har slutförts framgångsrikt!", "Proxmox system repair completed with some issues.": "Proxmox-systemreparation slutförd med några problem.", @@ -3408,16 +4484,28 @@ "Proxmox web interface: Datacenter > Storage > Add > SMB/CIFS": "Proxmox webbgränssnitt: Datacenter > Lagring > Lägg till > SMB/CIFS", "Proxmox web interface: Datacenter > Storage > Add > ZFS": "Proxmox webbgränssnitt: Datacenter > Lagring > Lägg till > ZFS", "Proxmox web interface: Datacenter > Storage > Add > iSCSI": "Proxmox webbgränssnitt: Datacenter > Lagring > Lägg till > iSCSI", + "Public UDP port clients connect to": "Offentliga UDP-portklienter ansluter till", + "Public UDP port peers connect to": "Offentliga UDP-portpeers ansluter till", + "Public URL of phpMyAdmin when it is served behind a reverse proxy": "Public URL av phpMyAdmin när den serveras bakom en omvänd proxy", + "Public address clients connect to (vpn.example.com or a public IP)": "Offentliga adressklienter ansluter till (vpn.example.com eller en offentlig IP)", + "Public address peers connect to, or auto to detect it (vpn.example.com)": "Offentliga adresspeers ansluter till, eller auto för att upptäcka det (vpn.example.com)", "Pulling latest changes from GitHub...": "Hämtar senaste ändringarna från GitHub...", "Purge the gasket-dkms package": "Ta bort gasket-dkms-paketet helt", "Purging gasket-dkms package...": "Tar bort gasket-dkms-paketet helt...", "Purging log2ram apt package...": "Rensar log2ram apt-paket...", + "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.": "Pwndrop är en självutnyttjande fil värdtjänst för att skicka ut röda lager nyttolast eller säkert dela dina privata filer över HTTP och WebDAV.", + "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more.": "PyCharm erbjuder out-of-the-box stöd för Python, databaser, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI och mer.", + "Pydio Cells needs an external MySQL or MariaDB database. The setup wizard asks for its address, database name and user on the first start.": "Pydio Cells behöver en extern MySQL- eller MariaDB-databas. Inställningsguiden ber om sin adress, databasnamn och användare i första början.", + "Pydio Cells redirects to the address given in EXTERNALURL. If the container changes address, edit lxc.environment.runtime: EXTERNALURL and SERVER_IP in /etc/pve/lxc/.conf with the container stopped, and delete /config/keys/cert.crt to regenerate the certificate.": "Pydio Cells omdirigerar till den adress som ges i EXTERNALURL. Om behållaren ändrar adress, redigera lxc.environment.runtime: EXTERNALURL och SERVER IP i /etc/pve/lxc/.conf med behållaren stannade, och ta bort /config/keys/cert.crt för att regenerera certifikatet.", + "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture.": "Pydio-celler är nästagen fildelningsplattform för organisationer. Det är en fullständig omskrivning av Pydio-projektet med Go-språket efter en mikroservicearkitektur.", + "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat.": "QDirStat Qt-baserad katalogstatistik: KDirStat utan KDE – från författaren till den ursprungliga KDirStat.", "Quick health check (PASSED / FAILED)": "Snabb hälsokontroll (GODKÄND / MISLYCKAD)", "Quick health status — overall SMART result + key attributes": "Snabb hälsostatus — övergripande SMART-resultat + nyckelattribut", "RAID Detected": "RAID upptäckt", "RAID member detected": "RAID-medlem upptäcktes", "RAM Size": "RAM-storlek", "RAM and swap usage": "Användning av RAM och swap", + "RAM in MiB": "RAM i MiB", "REPAIR SUMMARY": "REPARATION SAMMANFATTNING", "REQUIREMENTS:": "KRAV:", "ROM dump not available — configuring without romfile.": "ROM-dump inte tillgänglig — konfigureras utan romfil.", @@ -3425,9 +4513,26 @@ "RPC Bind Service: RUNNING": "RPC Bind Service: KÖR", "RPC Bind Service: STOPPED": "RPC-bindningstjänst: STOPPAD", "RPC Bind Service: STOPPED - starting...": "RPC-bindningstjänst: STOPPAD - börjar...", + "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD.": "RPCS3 är en multiplattform öppen källkod Sony PlayStation 3 emulator och debugger skriven i C ++ för Windows, Linux, macOS och FreeBSD.", + "Radarr - A fork of Sonarr to work with movies à la Couchpotato.": "Radarr - fork av Sonarr för att arbeta med filmer à la Couchpotato.", + "Radarr added to Prowlarr": "Radarr tillsatt till Prowlarr", + "Radarr connected to qBittorrent": "Radarr ansluten till qBittorrent", + "Radarr root folder configured": "Radarr rotmapp konfigurerad", + "RagFlow is an open-source RAG engine based on deep document understanding.": "RagFlow är en öppen källkod RAG motor baserad på djup dokument förståelse.", + "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase.": "Raneto - är en öppen källkod Knowledgebase-plattform som använder statiska Markdown-filer för att driva din Knowledgebase.", + "Raneto web interface": "Raneto webbgränssnitt", + "RawTherapee is a free, cross-platform raw image processing program!": "RawTherapee är ett gratis, korsplattformsprogram för rå bildbehandling!", + "Rclone WebUI": "Rclone WebUI", + "Rclone mount": "Rclone montering", + "Rclone mount active": "Rclone montering aktiv", + "Rclone mount needs a privileged LXC with FUSE access. The container is dedicated to Rclone and its web UI must not be exposed to untrusted networks.": "Rclone montering behöver en privilegierad LXC med FUSE tillgång. Behållaren är dedikerad till Rclone och dess webb-UI får inte utsättas för opålitliga nätverk.", + "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network.": "Rclone montering requires en privilegierad LXC med FUSE tillgång. Använd denna profil endast på en betrodd nod och nätverk.", + "Rclone mount requires a privileged container": "Rclone montering requires en privilegierad behållare", "Re-enter the BORG REPOKEY passphrase to confirm:": "Ange BORG REPOKEY-lösenordsfrasen igen för att bekräfta:", "Re-running pre-check after repairs...": "Kör förkontroll igen efter reparationer...", "Reachable": "Kan nåbar", + "Read its Compose file from a file of this host": "Läs dess Compose-fil från en fil av denna värd", + "Read the link with pct console CTID on the Proxmox host, or from the Console panel of the container in the Proxmox web interface, then open the https://playit.gg/claim/ address it shows in a browser and sign in to playit.gg. Ctrl+a q leaves pct console.": "Läs länken med pct console CTID på Proxmox-värden, eller från Console-panelen i behållaren i Proxmox-webbgränssnittet, öppna sedan https://playit.gg/claim/adressen visas i en webbläsare och logga in för att spelait.gg. Ctrl+a q lämnar pct konsol.", "Read-Only": "Skrivskyddad", "Read-Only access": "Skrivskyddad åtkomst", "Read-Write (universal)": "Läs-skriv (universell)", @@ -3436,6 +4541,7 @@ "Read-only access (or no write permissions).": "Skrivskyddad åtkomst (eller inga skrivbehörigheter).", "Read-only mount": "Endast läsfäste", "Read/Write (default)": "Läs/skriv (standard)", + "Read/write": "Läs/skriv", "Read/write CPU model-specific registers": "Läs/skriv CPU-modellspecifika register", "Readable user table (UID, shell, etc.)": "Läsbar användartabell (UID, skal, etc.)", "Reading NVMe SMART data...": "Läser NVMe SMART-data...", @@ -3444,6 +4550,7 @@ "Reading SMART self-test log...": "Läser SMART självtestlogg...", "Reading full SMART report...": "Läser hela SMART-rapporten...", "Real-time bandwidth usage (press q to exit)": "Användning av bandbredd i realtid (tryck på q för att avsluta)", + "Real-time collaborative document editor": "Realtidssamverkan dokument redaktör", "Real-time network monitoring (press q to exit)": "Nätverksövervakning i realtid (tryck på q för att avsluta)", "Real-time network usage (iftop)": "Nätverksanvändning i realtid (iftop)", "Reason: Access denied": "Anledning: Åtkomst nekad", @@ -3465,6 +4572,7 @@ "Recent Samba server": "Senaste Samba-servern", "Recent logs:": "Senaste loggar:", "Recent test results:": "Senaste testresultat:", + "Recognition profile not implemented": "Erkännandeprofil inte genomförd", "Recommendation: reformat the disk to ext4 for a robust setup — see docs.": "Rekommendation: formatera om disken till ext4 för en robust installation — se dokument.", "Recommendation: start with Complete restore.": "Rekommendation: börja med Komplett återställning.", "Recommendation: use 'Export to file' for these paths and apply manually during a maintenance window.": "Rekommendation: använd 'Exportera till fil' för dessa sökvägar och använd manuellt under ett underhållsfönster.", @@ -3476,17 +4584,36 @@ "Recommended: use GPU -> LXC mode for these devices.": "Rekommenderas: använd GPU -> LXC-läge för dessa enheter.", "Recommended: use GPU with LXC workloads instead of VM passthrough on this hardware.": "Rekommenderas: använd GPU med LXC-arbetsbelastningar istället för VM-passthrough på den här hårdvaran.", "Reconciled": "Försonad", + "Recover OCI": "Återställ OCI", + "Recover OCI stack": "Återställ OCI stack", + "Recover now?": "Återställ nu?", + "Recover or complete the operation?": "Återställ eller slutföra operation?", "Recover the keyfile using your recovery passphrase?": "Återställa nyckelfilen med din återställningslösenfras?", + "Recover the previous installation": "Återställ den tidigare installationen", "Recoverable:": "Återvinningsbar:", + "Recovering the previous installation": "Återställ den tidigare installationen", "Recovery blob upload failed — main backup is OK, but keyfile recovery from PBS will not be available for this backup.": "Uppladdning av återställningsblobb misslyckades – huvudsäkerhetskopieringen är OK, men nyckelfilsåterställning från PBS kommer inte att vara tillgänglig för denna säkerhetskopia.", "Recovery blob:": "Återhämtningsblobb:", + "Recovery completed. The container had not been modified yet.": "Återhämtning slutförd. Behållaren hade inte ändrats ännu.", + "Recovery completed. The displaced disks and the backup are kept; nothing was deleted automatically.": "Återhämtning slutförd. De förskjutna diskarna och backupen hålls; ingenting raderades automatiskt.", "Recovery failed": "Återställningen misslyckades", "Recovery passphrase": "Återställningslösenfras", "Recovery setup failed": "Återställningskonfigurationen misslyckades", + "Recreate": "Återskapa", + "Recreate OCI": "Återskapa OCI", + "Recreate with these options?": "Återskapa med dessa alternativ?", + "Recreate: edit resources, network, paths and GPU": "Redigera: redigera resurser, nätverk, vägar och GPU", + "Recreating requires a confirmed proposal": "Återskapa requires ett bekräftat förslag", + "Recreating the container...": "Återskapa behållaren...", + "Recreating the container:": "Återskapa behållaren:", + "Recreation completed. Data kept.": "Recreation slutförd. Data hålls.", + "Recreation prepared": "Rekreation förberedd", "Refresh APT index and verify repositories:": "Uppdatera APT-index och verifiera förråd:", "Refresh your browser (Ctrl+Shift+R) to see changes": "Uppdatera din webbläsare (Ctrl+Skift+R) för att se ändringar", "Refresh your browser to see changes (server restart may be required)": "Uppdatera din webbläsare för att se ändringar (serverns omstart kan krävas)", "Refreshing apt cache...": "Uppdaterar apt cache...", + "Refreshing the NVIDIA runtime...": "Uppfriskande NVIDIA runtime...", + "Refusing an unexpected rootfs path:": "Vägrar en oväntad rootfs väg:", "Regenerating PVE package cache...": "Återskapar PVE-paketcache...", "Regenerating boot artifacts for the merged kernel-agnostic changes...": "Regenererar startartefakter för de sammanslagna kärnagnostiska ändringarna...", "Regenerating certificates and restarting services...": "Återskapar certifikat och startar om tjänster...", @@ -3502,6 +4629,7 @@ "Reinstalled Proxmox packages successfully": "Ominstallerade Proxmox-paket framgångsrikt", "Reinstalling": "Installerar om", "Reinstalling core Proxmox packages...": "Installerar om kärn-Proxmox-paket...", + "Relative CPU priority (cpuunits)": "Relativ CPU-prioritet (cpuunits)", "Release Channel": "Släpp kanal", "Release channel set to Beta.": "Släppkanalen inställd på Beta.", "Release channel set to Stable.": "Släppkanalen inställd på Stabil.", @@ -3511,8 +4639,12 @@ "Remapped Users:": "Ommappade användare:", "Remapped users:": "Ommappade användare:", "Reminder: You must install the QEMU Guest Agent inside the Windows VM": "Påminnelse: Du måste installera QEMU Guest Agent i Windows VM", + "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported.": "Remmina är en fjärrskrivbordskund skriven i GTK, som syftar till att vara användbar för systemadministratörer och resenärer, som behöver arbeta med massor av fjärrdatorer framför antingen stora eller små skärmar. Remmina stöder flera nätverksprotokoll, i ett integrerat och konsekvent användargränssnitt. För närvarande stöds RDP, VNC, SPICE, SSH och EXEC.", + "Remote Access & VPN": "Fjärråtkomst och VPN", + "Remote dry run completed; no container was created.": "Fjärrtorkning slutförd; ingen behållare skapades.", "Remote repository path:": "Sökväg till fjärrarkiv:", "Remote server via SSH (recommended — off-host, dedup across machines)": "Fjärrserver via SSH (rekommenderas - utanför värddatorn, dedup över maskiner)", + "Remote verified:": "Fjärrkontrollerad:", "Remounting CIFS share with open permissions...": "Återmonterar CIFS-resurs med öppna behörigheter...", "Remove CIFS Mount": "Ta bort CIFS-monteringen", "Remove CIFS Mount (pvesm or fstab)": "Ta bort CIFS-monteringen (pvesm eller fstab)", @@ -3540,6 +4672,7 @@ "Remove NFS fstab Mount": "Ta bort NFS fstab-monteringen", "Remove NFS fstab mount:": "Ta bort NFS fstab-fäste:", "Remove NFS storage:": "Ta bort NFS-lagring:", + "Remove OCI": "Ta bort OCI", "Remove Proxmox CIFS storage:": "Ta bort Proxmox CIFS-lagring:", "Remove Proxmox NFS storage:": "Ta bort Proxmox NFS-lagring:", "Remove Proxmox iSCSI storage:": "Ta bort Proxmox iSCSI-lagring:", @@ -3551,6 +4684,7 @@ "Remove iSCSI storage definition:": "Ta bort iSCSI-lagringsdefinition:", "Remove invalid port": "Ta bort ogiltig port", "Remove invalid port(s)": "Ta bort ogiltiga port(ar)", + "Remove it? The data of its containers cannot be recovered afterwards.": "Ta bort det? Uppgifterna för dess behållare kan inte återvinnas efteråt.", "Remove keyfile from this host": "Ta bort nyckelfil från denna värd", "Remove mount point:": "Ta bort monteringspunkten:", "Remove obsolete systemd-boot meta-package": "Ta bort föråldrat systemd-boot-metapaket", @@ -3559,6 +4693,7 @@ "Remove subscription banner": "Ta bort prenumerationsbanner", "Remove the unprivileged flag from configuration:": "Ta bort den oprivilegierade flaggan från konfigurationen:", "Remove unused packages and their config": "Ta bort oanvända paket och deras konfiguration", + "Remove: delete the application and its containers": "Ta bort: ta bort programmet och dess behållare", "Removed": "Borttagen", "Removed KVM MSR options from configuration": "Tog bort KVM MSR-alternativ från konfigurationen", "Removed Mount:": "Borttaget fäste:", @@ -3609,6 +4744,9 @@ "Removing stale VFIO entries from vfio.conf...": "Ta bort inaktuella VFIO-poster från vfio.conf...", "Removing storage from Proxmox...": "Tar bort lagring från Proxmox...", "Removing system limits optimizations...": "Att ta bort systemet begränsar optimeringar...", + "Removing the containers...": "Ta bort behållarna...", + "Removing the incomplete stack...": "Ta bort den ofullständiga stacken...", + "Removing the previous container": "Ta bort den tidigare behållaren", "Removing utilities installed by ProxMenux...": "Tar bort verktyg installerade av ProxMenux...", "Removing zfs-auto-snapshot...": "Tar bort zfs-auto-snapshot...", "Renamed": "Omdöpt", @@ -3616,6 +4754,7 @@ "Repair Complete": "Reparation slutförd", "Repair Options:": "Reparationsalternativ:", "Repairs and optimizes repositories": "Reparerar och optimerar förråd", + "Repeat to confirm": "Upprepa för att bekräfta", "Replace": "Ersätta", "Replace with the actual ID.": "Ersätt med det faktiska ID:t.", "Replace with your actual container ID": "Ersätt med ditt faktiska container-ID", @@ -3628,12 +4767,16 @@ "Repositories switched to no-subscription": "Lagren bytte till ingen prenumeration", "Repository ready.": "Förvaret klart.", "Repository:": "Förvar:", + "Request a staging certificate for testing: true or false": "Begär ett staging-certifikat för testning: sant eller falskt", "Require reboot": "Kräv omstart", "Required command not found:": "Det obligatoriska kommandot hittades inte:", "Required if using a VirtIO or SCSI disk.": "Krävs om du använder en VirtIO- eller SCSI-disk.", "Required install helpers not available.": "Nödvändiga installationshjälpare är inte tillgängliga.", + "Required new path cancelled": "Required ny väg inställd", + "Required persistent paths cannot be removed": "Required ihållande vägar kan inte tas bort", "Requires acl package. Skip if setfacl is not available.": "Kräver acl-paket. Hoppa över om setfacl inte är tillgängligt.", "Requires authentication": "Kräver autentisering", + "Reserving a private network...": "Återställ ett privat nätverk...", "Reset Capability Blocked": "Återställ kapacitet blockerad", "Reset Capability Warning": "Varning för återställning av kapacitet", "Reset Monitor Password": "Återställ monitorlösenord", @@ -3641,7 +4784,9 @@ "Reset current storage selection": "Återställ aktuellt lagringsval", "Resetting time synchronization...": "Återställer tidssynkroniseringen...", "Residual Bookworm entries commented where applicable": "Resterande bokmalsposter kommenterade där tillämpligt", + "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes.": "Resilio-sync (tidigare BitTorrent Sync) använder BitTorrent-protokollet för att synkronisera filer och mappar mellan alla dina enheter. Det finns både gratis och betalda versioner, denna behållare stöder båda. Det finns en officiell synkroniseringsbild men vi skapade den här eftersom den stöder användarkartläggning för att förenkla behörigheter för volymer.", "Resolve package conflicts": "Lös paketkonflikter", + "Resources": "Resurser", "Restart Network": "Starta om nätverket", "Restart Network Service": "Starta om nätverkstjänsten", "Restart Web UI proxy": "Starta om proxy för webbgränssnittet", @@ -3673,8 +4818,11 @@ "Restore plan summary": "Sammanfattning av återställningsplan", "Restore source location": "Återställ källplats", "Restored config is on disk; reboot the host to apply.": "Återställd konfiguration finns på disken; starta om värden för att tillämpa.", + "Restored installation checked": "Återställd installation kontrollerad", "Restored original /bin/gzip": "Återställd original /bin/gzip", "Restored original /etc/vzdump.conf from .bak": "Återställd original /etc/vzdump.conf från .bak", + "Restored:": "Återställd:", + "Restoring": "Återställande", "Restoring APT language downloads...": "Återställer APT-språknedladdningar...", "Restoring container memory to": "Återställer containerminne till", "Restoring default journald configuration...": "Återställer standard journalkonfiguration...", @@ -3682,15 +4830,23 @@ "Restoring original bashrc...": "Återställer original bashrc...", "Restoring original logrotate configuration...": "Återställer den ursprungliga logrotate-konfigurationen...", "Restoring subscription banner...": "Återställer prenumerationsbanner...", + "Restoring the backup": "Återställ backup", "Restoring the original rpcbind service state...": "Återställer det ursprungliga rpcbind-tjänsttillståndet...", + "Restoring the previous Rclone configuration...": "Återställ den tidigare Rclone-konfigurationen...", + "Restoring the previous backup...": "Återställ den tidigare backup...", + "Restoring the previous state of the stack...": "Återställ det tidigare tillståndet i stacken...", + "Restoring the stack records...": "Återställ stack-posterna...", "Results will be saved automatically to:": "Resultaten sparas automatiskt till:", "Results will be saved to:": "Resultaten kommer att sparas till:", "Retention": "Retention", + "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface.": "RetroArch är en frontend för emulatorer, spelmotorer och mediaspelare. Det gör att du kan köra klassiska spel på ett brett spektrum av datorer och konsoler genom sitt slicka grafiska gränssnitt.", "Return": "Återvända", "Return to Main Menu": "Återgå till huvudmenyn", "Return to Share Menu": "Återgå till Dela-menyn", "Return to main menu": "Återgå till huvudmenyn", + "Returning the containers to their previous state...": "Återlämna behållarna till deras tidigare tillstånd...", "Reused the encryption key from the PVE storage entry.": "Återanvände krypteringsnyckeln från PVE-lagringsposten.", + "Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container.": "Omvänd proxyprover för andra applikationer finns i /config/nginx/proxy confs inuti behållaren.", "Reverting AMD (Ryzen/EPYC) fixes...": "Återställer AMD (Ryzen/EPYC)-fixar...", "Reverting IOMMU/VFIO configuration...": "Återställer IOMMU/VFIO-konfiguration...", "Reverting TCP BBR + Fast Open...": "Återställer TCP BBR + Snabböppning...", @@ -3699,22 +4855,31 @@ "Reverting vzdump speed tuning...": "Återställer vzdump-hastighetsinställning...", "Review passthrough config files": "Granska passthrough-konfigurationsfiler", "Review what will be removed": "Granska vad som kommer att tas bort", + "Rip DVD and Blu-ray media from a browser": "Rip DVD och Blu-ray media från en webbläsare", "Rollback: nothing to remove (host matches backup)": "Återställning: inget att ta bort (värden matchar säkerhetskopiering)", + "Rolling back the incomplete container": "Rulla tillbaka den ofullständiga behållaren", + "RomM is a self-hosted ROM manager for managing and playing game collections.": "RomM är en självvärd ROM-chef för att hantera och spela spelsamlingar.", "Root SSH keys/config": "Root SSH-nycklar/config", "Root inside container = root on host system": "Rot inuti behållare = rot på värdsystem", + "Root privileges are required": "Rotprivilegier är required", + "Root privileges on the Proxmox node are required": "Rot privilegier på Proxmox nod är required", "Root shell/profile config": "Rotskal/profilkonfiguration", "Root user on the PVE host (default 'root'):": "Rotanvändare på PVE-värden (standard 'root'):", + "Rootfs size in GB": "Rootfs storlek i GB", "Rotate the recovery passphrase": "Vrid återställningslösenfrasen", "Routing Information": "Routningsinformation", "Routing Table": "Rutttabell", + "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required.": "Rsnapshot är ett filsystem snapshot verktyg baserat på rsync. rsnapshot gör det enkelt att göra periodiska ögonblicksbilder av lokala maskiner och fjärrmaskiner över ssh. Koden gör omfattande användning av hårda länkar när det är möjligt, för att kraftigt minska diskutrymmet required.", "Run 'Mount NFS Share' to install NFS client automatically.": "Kör \"Montera NFS-delning\" för att installera NFS-klienten automatiskt.", "Run 'Mount Samba Share' to install CIFS client automatically.": "Kör \"Montera Samba-delning\" för att installera CIFS-klienten automatiskt.", + "Run GGUF LLMs locally with GPU acceleration": "Kör GGUF LLMs lokalt med GPU acceleration", "Run PVE 8 to 9": "Kör PVE 8 till 9", "Run PVE 8 to 9 check": "Kör PVE 8 till 9-kontroll", "Run \\\"Install NVIDIA Drivers on Host\\\" first so the installer is cached.": "Kör \\\"Installera NVIDIA-drivrutiner på värd\\\" först så att installationsprogrammet cachelagras.", "Run a full security audit": "Kör en fullständig säkerhetsgranskning", "Run a job now": "Kör ett jobb nu", "Run apt-get install -f to complete any pending package configurations": "Kör apt-get install -f för att slutföra eventuella väntande paketkonfigurationer", + "Run as root on the Proxmox node; the registry contains private data": "Kör som rot på Proxmox-noden; registret innehåller privata data", "Run as server or client? [s/c]:": "Köra som server eller klient? [s/c]:", "Run checklist again to verify upgrade:": "Kör checklistan igen för att verifiera uppgraderingen:", "Run from console, or SSH inside tmux/screen": "Kör från konsolen, eller SSH inuti tmux/skärm", @@ -3739,6 +4904,7 @@ "Running dkms autoinstall for kernel": "Kör dkms autoinstall för kärnan", "Running kernel:": "Kör kärnan:", "Running pre-upgrade simulation to verify 'proxmox-ve' will remain installed...": "Kör simulering före uppgradering för att verifiera att \"proxmox-ve\" förblir installerad...", + "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration.": "RustDesk är en fullfjädrad öppen källkod fjärrkontroll alternativ för självvärdering och säkerhet med minimal konfiguration.", "SATA (standard - high compatibility)": "SATA (standard - hög kompatibilitet)", "SCSI (recommended for Linux and Windows)": "SCSI (rekommenderas för Linux och Windows)", "SCSI (recommended for Linux)": "SCSI (rekommenderas för Linux)", @@ -3755,6 +4921,7 @@ "SMB ports:": "SMB-portar:", "SR-IOV Configuration Detected": "SR-IOV-konfiguration upptäckt", "SSD Emulation": "SSD-emulering", + "SSH access": "SSH tillgång", "SSH access (host + root)": "SSH-åtkomst (värd + rot)", "SSH auth logger service created and started": "SSH-authloggertjänst skapad och startade", "SSH hardening: MaxAuthTries set to 3 (Lynis recommendation)": "SSH-härdning: MaxAuthTries inställd på 3 (Lynis rekommendation)", @@ -3769,6 +4936,8 @@ "STEP 9: Cleanup (LVM only)": "STEG 9: Rensning (endast LVM)", "STORAGE TYPE IDENTIFICATION:": "IDENTIFIKATION AV FÖRVARINGSTYP:", "SUGGESTION FOR": "FÖRSLAG PÅ", + "SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.": "SWAG serverar HTTPS på port 443. Plain HTTP på port 80 är inaktiverad i /config/nginx/site-confs/default.conf.", + "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction.": "Sabnzbd gör Usenet så enkelt och effektiviserat som möjligt genom att automatisera allt vi kan. Allt du behöver göra är att lägga till en .nzb. SABnzbd tar över därifrån, där det automatiskt hämtas, verifieras, repareras, extraheras och lämnas in med noll mänsklig interaktion.", "Safe design: no automatic ACL/ownership mutation on host or CT.": "Säker design: ingen automatisk ACL/ägandemutation på värd eller CT.", "Safe to apply now": "Säkert att ansöka nu", "Safety Backup": "Säkerhetsbackup", @@ -3822,8 +4991,13 @@ "Same major series:": "Samma stora serie:", "Same major.minor:": "Samma major.moll:", "Sanitizing NVIDIA host services for VFIO mode...": "Sanerar NVIDIA-värdtjänster för VFIO-läge...", + "Save and classify articles. Read them later. Freely.": "Spara och klassificera artiklar. Läs dem senare. Fritt.", "Save the passphrase somewhere safe NOW, before continuing.": "Spara lösenfrasen någonstans säkert NU, innan du fortsätter.", "Save this Borg target so you don't need to enter the details again?": "Spara detta Borgmål så att du inte behöver ange detaljerna igen?", + "Saved record removed": "Saved Record bort", + "Saving the new configuration": "Spara den nya konfigurationen", + "Saving the new configuration...": "Spara den nya konfigurationen...", + "Saving the stack records...": "Spara staplarna...", "Scan storage for new content": "Skanna lagring efter nytt innehåll", "Scanning available physical disks...": "Skannar tillgängliga fysiska diskar...", "Scanning network for NFS servers...": "Skannar nätverk efter NFS-servrar...", @@ -3835,11 +5009,19 @@ "Scheduled backups and retention policies": "Schemalagda säkerhetskopieringar och lagringspolicyer", "Scheduled tasks (cron)": "Schemalagda uppgifter (cron)", "Scheduler script not found:": "Schemaläggarens skript hittades inte:", + "ScreenScraper": "ScreenScraper", + "ScreenScraper password": "ScreenScraper lösenord", + "ScreenScraper username": "ScreenScraper användarnamn", "Script Information": "Skriptinformation", "Script not found:": "Skriptet hittades inte:", "Scripts in": "Skript i", + "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator.": "ScummVM är ett program som låter dig köra vissa klassiska grafiska äventyr och rollspel, förutsatt att du redan har sina datafiler. Den smarta delen om detta: ScummVM ersätter just de körbara som levereras med spelen, så att du kan spela dem på system för vilka de aldrig designades! ScummVM är en komplett omskrivning av dessa spel körbara och är inte en emulator.", + "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions—such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server.": "Sealskin är en självhäftad, klient-server plattform som gör det möjligt för användare att köra kraftfulla, containeriserade stationära program strömmade direkt till en webbläsare. Den använder en webbläsartillägg för att avlyssna användaråtgärder - till exempel att klicka på en länk eller ladda ner en fil och omdirigerar dem till en säker, isolerad applikationsmiljö som körs på en fjärrserver.", "Search Results for:": "Sökresultat för:", + "Search applications": "Sök applikationer", + "Search results for:": "Sökresultat för:", "Search/Filter Scripts": "Sök/filtrera skript", + "Searchable document archive with OCR": "Sökbart dokumentarkiv med OCR", "Secure Disk Formatter": "Säker diskformaterare", "Secure Gateway (Tailscale VPN)": "Secure Gateway (Tailscale VPN)", "Secure Gateway deployed successfully!": "Secure Gateway har implementerats framgångsrikt!", @@ -3847,8 +5029,12 @@ "Security": "Säkerhet", "Security Updates": "Säkerhetsuppdateringar", "Security Warning — read before applying": "Säkerhetsvarning – läs innan du ansöker", + "Security directive outside the dynamic profile": "Säkerhetsdirektiv utanför den dynamiska profilen", + "Security relaxation declined": "Säkerhetsavslappning minskade", "See": "Se", "See /tmp/proxmenux-mount.log for details.": "Se /tmp/proxmenux-mount.log för detaljer.", + "Seerr WebUI": "Seerr WebUI", + "Seerr/Bazarr connections, the SABnzbd client and the Lidarr profiles, root folder and client are configured manually in this version.": "Seerr/Bazarr-anslutningar, SABnzbd-klienten och Lidarr-profilerna, rotmappen och klienten konfigureras manuellt i den här versionen.", "Select": "Välja", "Select Borg target": "Välj Borgmål", "Select CPU model": "Välj CPU-modell", @@ -3888,6 +5074,7 @@ "Select a Custom Logo": "Välj en anpassad logotyp", "Select a VirtIO ISO to use:": "Välj en VirtIO ISO att använda:", "Select a category of useful commands:": "Välj en kategori med användbara kommandon:", + "Select a category or search for applications:": "Välj en kategori eller sök efter applikationer:", "Select a category or search for scripts:": "Välj en kategori eller sök efter skript:", "Select a custom ISO to use:": "Välj en anpassad ISO att använda:", "Select a job:": "Välj ett jobb:", @@ -3897,6 +5084,7 @@ "Select a pre-configured Linux VM script to execute:": "Välj ett förkonfigurerat Linux VM-skript att köra:", "Select a script or action:": "Välj ett skript eller en åtgärd:", "Select a share to delete:": "Välj en delning att radera:", + "Select a specific Coral or USB node, not the whole /dev": "Välj en specifik Coral eller USB-nod, inte hela/dev", "Select access mode": "Välj åtkomstläge", "Select an existing group": "Välj en befintlig grupp", "Select an existing group:": "Välj en befintlig grupp:", @@ -3907,6 +5095,7 @@ "Select archive": "Välj arkiv", "Select archive to restore": "Välj arkiv för att återställa", "Select at least one path to continue.": "Välj minst en väg för att fortsätta.", + "Select at least one suite application": "Välj minst ett svitprogram", "Select authentication mode:": "Välj autentiseringsläge:", "Select authentication type:": "Välj autentiseringstyp:", "Select available Controllers/NVMe to add:": "Välj tillgängliga kontroller/NVMe att lägga till:", @@ -4011,6 +5200,18 @@ "Selected optimizations have been uninstalled.": "Valda optimeringar har avinstallerats.", "Selected paths produced no entries to apply.": "Utvalda sökvägar gav inga poster att tillämpa.", "Selected utilities installation completed": "Installationen av valda verktyg har slutförts", + "Selection": "Urval", + "Self-custodial Bitcoin Lightning wallet with integrated node and app connections.": "Självhäktande Bitcoin Lightning plånbok med integrerade nod- och appanslutningar.", + "Self-hosted ZeroTier network controller with web UI for centralized management.": "Self-hosted ZeroTier nätverkskontroller med webb-UI för centraliserad förvaltning.", + "Self-hosted collaborative bookmark manager to collect, read, annotate, and fully preserve what matters, all in one place.": "Self-hosted collaborative bookmark manager för att samla, läsa, notera och helt bevara vad som är viktigt, allt på ett ställe.", + "Self-hosted file sharing with a modern web interface": "Självhäftad fildelning med ett modernt webbgränssnitt", + "Self-hosted file toolkit for images, video, audio, PDFs, and files": "Självvärd filverktyg för bilder, video, ljud, PDF-filer och filer", + "Self-hosted internet archiving solution": "Självhäftad internetarkiveringslösning", + "Self-hosted recipe manager and meal planner": "Självvärd receptchef och måltidsplanerare", + "Self-hosted software development service": "Självvärd programvara utvecklingstjänst", + "Self-signed TLS certificate created:": "Självsignerat TLS-certifikat skapat:", + "Selfhosted PDF manager, viewer and editor": "Selfhosted PDF manager, tittare och redaktör", + "Selkies desktop and streaming acceleration": "Selkies skrivbord och streaming acceleration", "Sending backup to Borg repository...": "Skickar säkerhetskopia till Borg-arkivet...", "Sending backup to PBS...": "Skickar säkerhetskopia till PBS...", "Server": "Server", @@ -4025,14 +5226,19 @@ "Server will listen on TCP port 5201.": "Servern lyssnar på TCP-port 5201.", "Server:": "Server:", "Servers": "Servrar", + "Service": "Serviceservice", "Service Status": "Servicestatus", "Service is active and running": "Tjänsten är aktiv och igång", "Service is inactive": "Tjänsten är inaktiv", + "Service ready:": "Service redo:", + "Service responding:": "Service svarar:", "Service restarted.": "Tjänsten startade om.", "Service restarts:": "Tjänsten startar om:", "Service stopped.": "Service stoppad.", + "Service:": "Service:", "Services failed": "Tjänsterna misslyckades", "Services restarted": "Tjänsterna startade om", + "Services that depend on the main service are not yet supported": "Tjänster som är beroende av huvudtjänsten stöds ännu inte", "Services:": "Tjänster:", "Set Display > Graphic card (VGA, SPICE or VirtIO) to match the guest": "Ställ in Display > Grafikkort (VGA, SPICE eller VirtIO) för att matcha gästen", "Set Hostname": "Ange värdnamn", @@ -4077,13 +5283,26 @@ "Share:": "Dela:", "Shared Directory Ready:": "Redo för delad katalog:", "Shared Group": "Delad grupp", + "Shared directory created:": "Delad katalog skapad:", + "Shared directory for consume and export": "Delad katalog för konsumering och export", + "Shared directory for copy/sync operations": "Delad katalog för kopia/synkronisera operations", "Shared group: CONFIGURED": "Delad grupp: KONFIGURERAD", "Shared group: sharedfiles (GID:": "Delad grupp: sharedfiles (GID:", + "Shared host content (not included in LXC backups):": "Delat värdinnehåll (ingår inte i LXC säkerhetskopior):", + "Shared host data is not reverted by the backup. Continue?": "Delade värddata återställs inte av backupen. Fortsätt?", + "Shared host data is not reverted by the backups. Continue?": "Delade värddata återställs inte av säkerhetskopiorna. Fortsätt?", + "Shared host directories (not included in Proxmox backups)": "Delade värdkataloger (ingår inte i Proxmox säkerhetskopior)", + "Shared host directory": "Delad värdkatalog", + "Shared host directory (not included in Proxmox backups)": "Delad värdkatalog (ingår inte i Proxmox säkerhetskopior)", + "Shared host files are kept as they are; the backup does not restore their content.": "Delade värdfiler hålls som de är; backupen återställer inte deras innehåll.", + "Shared host media directory": "Delad värd media katalog", + "Shared memory size for the GPU workload in MB": "Delad minnesstorlek för GPU-arbetsbelastningen i MB", "Sharedfiles group already exists (GID: 101000)": "Sharedfiles-gruppen finns redan (GID: 101000)", "Shares found:": "Hittade andelar:", "Shell user ulimit set": "ulimit har ställts in för skal användaren", "Short self-test started on": "Kort självtest började på", "Short test — ~2 minutes, basic surface check": "Kort test - ~2 minuter, grundläggande ytkontroll", + "Shotcut is a free, open source, cross-platform video editor.": "Shotcut är en fri, öppen källkod, tvärplattform videoredigerare.", "Should show 'unprivileged: 0' or no unprivileged line": "Bör visa 'oprivilegierad: 0' eller ingen oprivilegierad rad", "Should show 'unprivileged: 1'": "Bör visa \"oprivilegierad: 1\"", "Should show 'unprivileged: 1' if it's unprivileged": "Bör visa \"oprivilegierad: 1\" om den är oprivilegierad", @@ -4125,14 +5344,23 @@ "Show size of a directory": "Visa storleken på en katalog", "Show standard exclude patterns": "Visa standardexkluderingsmönster", "Show status of all storage pools": "Visa status för alla lagringspooler", + "Show the QR code of a peer again with: pct exec -- /app/show-peer 1": "Visa QR-koden för en peer igen med: pct exec /app/show-peer 1", "Show traffic statistics per interface": "Visa trafikstatistik per gränssnitt", "Show vzdump backup configuration": "Visa vzdump säkerhetskopia-konfiguration", "Shows status and type (nfs/cifs/dir/iscsi...).": "Visar status och typ (nfs/cifs/dir/iscsi...).", "Shutdown timeout": "Timeout för avstängning", + "SiYuan access code": "SiYuan åtkomstkod", + "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more..": "SickGear tillhandahåller hantering av TV-program och / eller Anime, det upptäcker nya episoder, länkar nedladdningsprogram och mer.", + "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private.": "Signal är en meddelandeapp med integritet i kärnan. Det är gratis och lätt att använda, med stark end-to-end-kryptering som håller din kommunikation helt privat.", "Signatures removed. Partition table preserved.": "Signaturer har tagits bort. Partitionstabell bevarad.", + "Simple and easy to use DDNS": "Enkelt och enkelt att använda DDNS", "Single GPU Warning": "Varning för enkel GPU", "Single target found — selected automatically:": "Enstaka mål hittades — väljs automatiskt:", "Size": "Storlek", + "Size in GB of": "Storlek i GB av", + "Size of each consume/export volume in GB": "Storlek på varje konsum/exportvolym i GB", + "Size of the /dev/shm shared memory in MB": "Storlek på /dev/shm delat minne i MB", + "Size of the Frigate temporary cache in MB": "Storlek på Frigate tillfällig cache i MB", "Size:": "Storlek:", "Skip downloading additional languages": "Hoppa över nedladdning av ytterligare språk", "Skip this device": "Hoppa över den här enheten", @@ -4142,6 +5370,7 @@ "Skip — leave as-is": "Hoppa över — lämna som det är", "Skipped (no disks of the pool are present on this host):": "Hoppat över (inga diskar från poolen finns på denna värd):", "Skipped (some disks missing):": "Hoppade över (några diskar saknas):", + "Skipped because Jellyfin did not create encoding.xml:": "Skippad eftersom Jellyfin inte skapade kodning.xml:", "Skipped device": "Överhoppad enhet", "Skipped to protect target system (would cascade-remove packages)": "Hoppade över för att skydda målsystemet (skulle kaskad-ta bort paket)", "Skipped, not in apt cache:": "Hoppat över, inte i apt cache:", @@ -4149,7 +5378,10 @@ "Skipping SR-IOV device": "Hoppa över SR-IOV-enhet", "Skipping installation.": "Hoppa över installationen.", "Skipping manual patches — feranick fork already supports this kernel.": "Hoppa över manuella patchar — feranick fork stöder redan denna kärna.", + "Sleek podcast downloader with GPodder sync": "Sleek podcast downloader med GPodder sync", "Smart restore plan — hardware compatibility check": "Smart återställningsplan — kontroll av hårdvarukompatibilitet", + "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis.": "Smokeping håller reda på din nätverks latens. För ett fullständigt exempel på vad denna ansökan kan besöka UCDavis.", + "SnapOtter": "SnapOtter", "Snippets — hook scripts / config": "Snippets — krokskript / config", "SoC-integrated GPU: tight coupling with other SoC components": "SoC-integrerad GPU: tät koppling med andra SoC-komponenter", "Some DKMS removals reported errors; final verification will determine the result.": "Vissa DKMS-borttagningar rapporterade fel;slutlig verifiering kommer att avgöra resultatet.", @@ -4159,6 +5391,7 @@ "Some old time services could not be removed (not installed)": "Vissa gamla tjänster kunde inte tas bort (inte installerade)", "Some operations failed — review messages above. Press Enter to continue...": "Vissa operationer misslyckades – granska meddelanden ovan. Tryck på Enter för att fortsätta...", "Some packages still need attention; review": "Vissa paket behöver fortfarande uppmärksamhet;recension", + "Some projects publish a Dockerfile and not an image: it has to be built and published to a registry before it can be installed this way. An image of a private registry needs credentials, which are not supported yet.": "Vissa projekt publicerar en Dockerfil och inte en bild: den måste byggas och publiceras i ett register innan den kan installeras på detta sätt. En bild av ett privat register behöver credentials, som inte stöds ännu.", "Some repairs failed. Please fix manually and re-run the script.": "Vissa reparationer misslyckades. Vänligen fixa manuellt och kör skriptet igen.", "Some repositories are not available, continuing with available ones...": "Vissa förråd är inte tillgängliga, fortsätter med tillgängliga...", "Some selected GPUs are already configured in this container.": "Vissa valda GPU:er är redan konfigurerade i den här behållaren.", @@ -4166,6 +5399,10 @@ "Some utility packages could not be removed; the remaining list has been preserved": "Vissa verktygspaket kunde inte tas bort;the remaining list has been preserved", "Something is already mounted at": "Något är redan monterat på", "Something is already mounted at:": "Något är redan monterat på:", + "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.": "Sonarr (tidigare NZBdrone) är en PVR för Usenet och bittorrent användare. Det kan övervaka flera RSS-flöden för nya episoder av dina favoritprogram och kommer att ta tag i, sortera och byta namn på dem. Det kan också konfigureras för att automatiskt uppgradera kvaliteten på filer som redan laddats ner när ett bättre kvalitetsformat blir tillgängligt.", + "Sonarr added to Prowlarr": "Sonarr tillsatt till Prowlarr", + "Sonarr connected to qBittorrent": "Sonarr ansluten till qBittorrent", + "Sonarr root folder configured": "Sonarr rotmapp konfigurerad", "Source": "Källa", "Source VM": "Källa VM", "Source patched successfully.": "Källan har korrigerats.", @@ -4174,8 +5411,26 @@ "Spanish": "spanska", "Specific host (enter IP)": "Specifik värd (ange IP)", "Specific subnet (enter manually)": "Specifikt subnät (skriv in manuellt)", + "Speedtest Tracker web interface": "Speedtest Tracker webbgränssnitt", + "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service.": "Speedtest-tracker är en självhäftad internetprestationsspårningsapplikation som kör snabbaste kontroller mot Ooklas Speedtest-tjänst.", + "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium": "Spotube är en öppen källkod, plattform Spotify klient kompatibel över flera plattformar som använder Spotifys data API och YouTube, Piped. video eller JioSaavn som ljudkälla, vilket eliminerar behovet av Spotify Premium", "Stable (main branch)": "Stabil (huvudgren)", "Stable monitor service normalized.": "Stabil monitortjänst normaliserad.", + "Stack": "Stack", + "Stack adapter not recognized by the translator": "Stack adapter inte erkänd av översättaren", + "Stack backups are missing; a partial restore is not allowed": "Stack backups saknas; en partiell återställning är inte tillåtet", + "Stack checked:": "Stack kontrolleras:", + "Stack members are missing; recreate them after verifying their volumes": "Stack medlemmar saknas; återskapa dem efter att ha verifierat sina volymer", + "Stack members are updated together with their stack": "Stack medlemmar uppdateras tillsammans med sin stack", + "Stack name": "Stack namn", + "Stack records restored": "Stack Records återställd", + "Stack records saved": "Stack Records sparade", + "Stack records saved; no container was reinstalled.": "Stack poster sparade; ingen behållare installerades.", + "Stack recovery completed; every member is back to its previous installation.": "Stack återhämtning slutförd; varje medlem är tillbaka till sin tidigare installation.", + "Stack startup hook installed": "Stack start hook installerad", + "Stack stopped": "Stack stannade", + "Stack update completed. Data kept.": "Stack update slutförd. Data hålls.", + "Stack:": "Stack:", "Staging directory:": "Staging katalog:", "Staging ready.": "Iscensättning klar.", "Staging source:": "Iscensättningskälla:", @@ -4183,11 +5438,13 @@ "Stale VFIO Config Detected": "Inaktuell VFIO-konfiguration upptäckt", "Stale VFIO entries removed and initramfs rebuilt.": "Inaktuella VFIO-poster togs bort och initramfs byggdes om.", "Standard NAS (backup, iso, vztmpl)": "Standard NAS (säkerhetskopiering, iso, vztmpl)", + "Start": "Börja", "Start VM": "Starta VM", "Start VM after creation": "Starta VM efter skapandet", "Start VM after creation?": "Starta VM efter skapandet?", "Start a container. Use the correct ": "Starta en container. Använd rätt ", "Start a virtual machine. Use the correct ": "Starta en virtuell maskin. Använd rätt ", + "Start each LXC with Proxmox (no coordinated startup)": "Starta varje LXC med Proxmox (ingen samordnad start)", "Start long self-test (hours)": "Starta ett långt självtest (timmar)", "Start long test now?": "Börja långtest nu?", "Start on boot already disabled for VM": "Start vid start är redan inaktiverat för virtuell dator", @@ -4199,11 +5456,16 @@ "Start scrub for a ZFS pool": "Börja skrubba för en ZFS-pool", "Start short self-test (~2 min)": "Starta kort självtest (~2 min)", "Start terminal multiplexer (recommended):": "Starta terminalmultiplexer (rekommenderas):", + "Start the LXC when finished to apply the selected configuration?": "Starta LXC när du är klar för att tillämpa den valda konfigurationen?", "Start the VM": "Starta VM", "Start the VM to begin Windows installation from the mounted ISO.": "Starta den virtuella datorn för att påbörja Windows-installationen från den monterade ISO.", "Start the converted container:": "Starta den konverterade behållaren:", "Start the main system upgrade:": "Starta huvudsystemuppgraderingen:", + "Start the stack with Proxmox": "Börja stapeln med Proxmox", "Start uploading to PBS — sets a recovery passphrase": "Börja ladda upp till PBS — ställer in en återställningslösenfras", + "Start when finished": "Börja när du är färdig", + "Start with Proxmox": "Börja med Proxmox", + "Starting": "Börja", "Starting Borg backup...": "Startar Borg-säkerhetskopiering...", "Starting CT": "Startar CT", "Starting LXC Privileged to Unprivileged conversion process...": "Startar konverteringsprocessen för LXC Privileged to Unprivileged...", @@ -4214,6 +5476,7 @@ "Starting ProxMenux update...": "Startar ProxMenux-uppdatering...", "Starting Proxmox storage integration...": "Startar Proxmox-lagringsintegration...", "Starting Proxmox system repair...": "Startar reparation av Proxmox-system...", + "Starting Rclone and waiting for the FUSE mount...": "Starta Rclone och vänta på FUSE montering", "Starting SMART long self-test...": "Startar SMART långt självtest...", "Starting SMART short self-test...": "Startar SMART kort självtest...", "Starting container": "Startbehållare", @@ -4224,9 +5487,20 @@ "Starting installer...": "Startar installationsprogrammet...", "Starting privileged container...": "Startar privilegierad behållare...", "Starting rpcbind service...": "Startar rpcbind-tjänst...", + "Starting the container...": "Börja behållaren...", + "Starting the main container and its dependencies...": "Starta huvudbehållaren och dess beroende...", + "Starting the service:": "Starta tjänsten:", "Starting unprivileged container...": "Startar oprivilegierad behållare...", + "Startup: coordinated by the stack startup hook": "Startup: koordinerad av stack start hook", + "Startup: independent, without hookscript": "Startup: oberoende, utan hookscript", + "Static IP": "Statisk IP", + "Static IPv4 address": "Statisk IPv4-adress", + "Static IPv4 address for": "Statisk IPv4-adress för", "Status": "Status", "Status:": "Status:", + "Steam is the ultimate destination for playing, discussing, and creating games.": "Steam är den ultimata destinationen för att spela, diskutera och skapa spel.", + "SteamGridDB": "SteamGridDB", + "SteamGridDB API key": "SteamGridDB API nyckel", "Step": "Steg", "Step 2: Testing actual share access with guest...": "Steg 2: Testar faktisk delningsåtkomst med gäst...", "Steps that will run:": "Steg som kommer att köras:", @@ -4234,12 +5508,14 @@ "Stop it first and run this option again.": "Stoppa det först och kör det här alternativet igen.", "Stop the CT, unmount the disk on the HOST, and remount with:": "Stoppa CT, avmontera disken på HOST och montera om med:", "Stop the VM/CT before formatting this disk.": "Stoppa VM/CT innan du formaterar denna disk.", + "Stop the container before the NVIDIA refresh": "Stoppa behållaren innan NVIDIA-uppdateringen", "Stop the container if it's running:": "Stoppa behållaren om den är igång:", "Stop them first and run this script again.": "Stoppa dem först och kör det här skriptet igen.", "Stop uploading to PBS": "Sluta ladda upp till PBS", "Stop uploading?": "Vill du sluta ladda upp?", "Stopped": "Stoppad", "Stopped and disabled": "Stoppad och inaktiverad", + "Stopped at:": "Stannade på:", "Stopping Coral kernel modules...": "Stoppar Coral kernel-moduler...", "Stopping LXC": "Stoppar LXC", "Stopping NFS services...": "Stoppar NFS-tjänster...", @@ -4251,6 +5527,8 @@ "Stopping gateway...": "Stoppar gateway...", "Stopping the container before applying configuration...": "Stoppar behållaren innan konfiguration tillämpas...", "Stopping the container before conversion...": "Stoppar behållaren före konvertering...", + "Stopping the container...": "Stoppa behållaren...", + "Stopping the stack...": "Stoppa stacken...", "Storage": "Lagring", "Storage & Share Manager": "Lagrings- och delningshanterare", "Storage Added:": "Lagring tillagd:", @@ -4263,21 +5541,41 @@ "Storage and Disks Commands": "Lagrings- och diskkommandon", "Storage controller: VirtIO SCSI": "Lagringskontroller: VirtIO SCSI", "Storage disk identifier:": "Lagringsdiskidentifierare:", + "Storage for Nextcloud files, configuration and data": "Lagring för Nextcloud filer, konfiguration och data", + "Storage for Paperless data and documents": "Lagring för papperslösa data och dokument", + "Storage for Tandoor files": "Lagring för Tandoor filer", + "Storage for persistent data": "Lagring för ihållande data", + "Storage for recipe images and files": "Lagring för receptbilder och filer", + "Storage for rootfs": "Lagring för rootfs", + "Storage for rootfs and private configuration": "Lagring för rootfs och privat konfiguration", + "Storage for the Immich library": "Lagring för Immich bibliotek", + "Storage for the Nextcloud data": "Lagring för Nextcloud-data", + "Storage for the OCI image cache": "Lagring för OCI bild cache", + "Storage for the consume and export folders": "Lagring för konsument- och exportmapparna", + "Storage for the persistent configuration": "Lagring för den ihållande konfigurationen", "Storage is now available in Proxmox web interface under Datacenter > Storage": "Lagring är nu tillgängligt i Proxmox webbgränssnitt under Datacenter > Lagring", "Storage plan selection cancelled.": "Val av lagringsplan avbröts.", "Storage plan selection failed or cancelled": "Val av lagringsplan misslyckades eller avbröts", + "Storage selection cancelled": "Lagringsval avbokat", "Storage:": "Lagring:", "Stored Credentials:": "Lagrade inloggningsuppgifter:", "Stored credentials:": "Lagrade autentiseringsuppgifter:", + "Stremio is a modern media center that gives you the freedom to watch everything you want.": "Stremio är ett modernt mediacenter som ger dig friheten att titta på allt du vill ha.", + "Subdomains for the certificate, comma separated (wildcard for *.domain)": "Underdomäner för certifikatet, komma separerade (wildcard för *.domain)", "Subnet": "Subnät", "Subscription banner removal failed": "Borttagning av prenumerationsbanner misslyckades", "Subscription banner removed successfully": "Prenumerationsbannern har tagits bort", "Subscription banner restored successfully (desktop and mobile)": "Prenumerationsbannern har återställts (dator och mobil)", "Success": "Framgång", "Successful": "Framgångsrik", + "Supervisor does not confirm healthy and supported yet": "Handledaren bekräftar inte hälsosam och stödd ännu", + "Supervisor reports no connectivity; retrying to get versions and install components": "Övervakaren rapporterar ingen anslutning; att försöka få versioner och installera komponenter", "Supported formats: .img, .qcow2, .vmdk, .raw": "Format som stöds: .img, .qcow2, .vmdk, .raw", + "Swap": "Swap", + "Swap in MB": "Swap i MB", "Swap partition detected": "Swap-partition upptäckt", "Swappiness configuration created successfully": "Swappiness-konfigurationen har skapats", + "Swing Music is a beautifully designed, self-hosted music streaming server. Like a cooler Spotify ... but bring your own music.": "Swing Music är en vackert utformad, självhäftad musikströmningsserver. Som en coolare Spotify ... men ta med din egen musik.", "Switch GPU Mode (VM <-> LXC)": "Byt GPU-läge (VM <-> LXC)", "Switch Mode": "Växla läge", "Switch Script Not Found": "Växlingsskriptet hittades inte", @@ -4287,13 +5585,21 @@ "Switching to": "Byter till", "Switching to GPU -> LXC mode removes VFIO exclusivity.": "Att byta till GPU -> LXC-läge tar bort VFIO-exklusiviteten.", "Switching to GPU -> VM mode requires exclusive VFIO binding.": "Att byta till GPU -> VM-läge kräver exklusiv VFIO-bindning.", + "Symbolic link in a restored volume path": "Symbolisk länk i en återställd volymväg", + "Symbolic link in the path of an adaptation": "Symbolisk länk i vägen för en anpassning", + "Symbolic link loop in the new image": "Symbolisk länkslinga i den nya bilden", + "Symbolic link outside the rootfs of the new image": "Symbolisk länk utanför rötterna av den nya bilden", "Synchronize time automatically": "Synkronisera tiden automatiskt", + "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are.": "Synclounge är ett tredjepartsverktyg som låter dig titta på Plex i synkronisera med dina vänner/familj, var du än är.", + "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet.": "Syncthing ersätter egen synkronisering och molntjänster med något öppet, pålitligt och decentraliserat. Dina uppgifter är dina uppgifter ensam och du förtjänar att välja var de lagras, om de delas med någon tredje part och hur de överförs via Internet.", + "Sysctl not namespaced or not valid:": "Sysctl inte namnspaced eller inte giltig:", "System": "System", "System CLI Tools": "System CLI-verktyg", "System Disk Size (GB)": "Systemdiskstorlek (GB)", "System Update Information": "Systemuppdateringsinformation", "System Utilities Installer": "Installationsprogram för systemverktyg", "System disk is SSD or M.2. Proceeding with Log2RAM setup.": "Systemdisken är SSD eller M.2. Fortsätter med inställningen av Log2RAM.", + "System error:": "Systemfel:", "System errors and logs": "Systemfel och loggar", "System group apex already exists.": "Systemgrupps apex finns redan.", "System group apex created.": "Systemgruppsapex skapad.", @@ -4304,6 +5610,7 @@ "System limits increase completed.": "Systemgränshöjningen är klar.", "System limits optimizations removed": "Systembegränsningar har tagits bort", "System must be updated to latest PVE 8.4+ before starting": "Systemet måste uppdateras till senaste PVE 8.4+ innan start", + "System path mounts are not yet supported": "Systemvägfästen stöds ännu inte", "System reboot required": "Systemet måste startas om", "System upgrade completed": "Systemuppgraderingen slutförd", "System uptime": "Systemuppetid", @@ -4318,6 +5625,11 @@ "TROUBLESHOOTING:": "FELSÖKNING:", "TUI mode": "TUI-läge", "TUI mode (requires root)": "TUI-läge (kräver root)", + "Take control of your Minecraft servers.": "Ta kontroll över dina Minecraft-servrar.", + "Tandoor WebUI": "Tandoor WebUI", + "Tandoor configuration cancelled": "Tandoor konfiguration inställd", + "Tandoor needs at least 1 GB for staticfiles and 4 GB for PostgreSQL": "Tandoor behöver minst 1 GB för statikfiler och 4 GB för PostgreSQL", + "Tandoor needs to complete its first start to create the initial administrator": "Tandoor måste slutföra sin första start för att skapa den första administratören", "Target IQN:": "Mål-IQN:", "Target VM": "Mål VM", "Target VM validated": "Mål-VM validerad", @@ -4327,6 +5639,12 @@ "Target mode": "Målläge", "Target server:": "Målserver:", "Target:": "Mål:", + "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server.": "Tautulli är en pythonbaserad webbapplikation för övervakning, analys och meddelanden för Plex Media Server.", + "Teable adopts a concise spreadsheet interface, yet creates powerful database applications": "Teable antar ett koncis kalkylblad gränssnitt, men skapar kraftfulla databasapplikationer", + "Telegram is a cloud-based mobile and desktop messaging app.": "Telegram är en molnbaserad mobil- och skrivbordsmeddelandeapp.", + "Temporary data container:": "Tillfällig databehållare:", + "Temporary login": "Tillfällig inloggning", + "Temporary password retrieved": "Tillfälligt lösenord hämtat", "Temporary working directory (if present):": "Tillfällig arbetskatalog (om sådan finns):", "Terminal Multiplexers": "Terminal multiplexorer", "Terminal multiplexer (Ctrl+b then d to detach, or type exit)": "Terminalmultiplexer (Ctrl+b sedan d för att koppla bort, eller skriv exit)", @@ -4343,40 +5661,197 @@ "Testing comprehensive guest access to server": "Testar omfattande gäståtkomst till servern", "Testing connectivity to portal...": "Testar anslutning till portal...", "Testing network connectivity...": "Testar nätverksanslutning...", + "Text that new pads start with (empty = the text of the image)": "Text som nya kuddar börjar med (tomma = bildtexten)", "Thank you for using ProxMenux. Goodbye!": "Tack för att du använder ProxMenux. Adjö!", "That VM is currently stopped, so the GPU can be reassigned now.": "Den virtuella datorn är för närvarande stoppad, så GPU:n kan tilldelas om nu.", "That doesn't look like an SSH private key. Pick the private key file (no .pub extension, parseable by ssh-keygen).": "Det ser inte ut som en privat SSH-nyckel. Välj den privata nyckelfilen (ingen .pub-tillägg, kan analyseras med ssh-keygen).", + "The .conf files under /config/fail2ban are rewritten on every start. Keep customizations in the matching .local file, for example jail.local for jail.conf.": ".conf-filerna under/config/fail2ban skrivs om varje start. Håll anpassningar i matchande .local-filen, till exempel fängelse.local för jail.conf.", + "The AppArmor/seccomp relaxation does not include the required consent": "AppArmor/seccomp relaxation inkluderar inte required samtycke", + "The Bookmark Everything App": "Bokmärket allt App", + "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile.": "Brave-webbläsaren är en snabb, privat och säker webbläsare för PC, Mac och mobil.", + "The CT already exists:": "CT finns redan:", + "The Compose file declares no service": "Compose-filen förklarar ingen tjänst", + "The Compose file describes several images:": "Compose-filen beskriver flera bilder:", + "The Compose file does not contain a Compose document": "Compose-filen innehåller inte ett komponeringsdokument", + "The Compose file is not valid YAML:": "Compose-filen är inte giltig YAML:", + "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "Komponera erbjuder en valfri AppArmor eller seccomp avslappning; det kommer att vara inaktiverat om inte användaren väljer det. Fortsätt bara om du litar på bilden och accepterar denna risk.", + "The Compose value must be text or a list:": "Komponeringsvärdet måste vara text eller en lista:", + "The DRM node is not an Intel or AMD GPU; NVIDIA requires its library profile": "DRM-noden är inte en Intel eller AMD GPU; NVIDIA requires sin biblioteksprofil", + "The Entrypoint/Cmd combination is empty": "Entrypoint/Cmd combination är tom", + "The FUSE publication helper was not found": "FUSE publiceringshjälparen hittades inte", + "The GPU evidence does not match the verified devices": "GPU-beviset matchar inte de verifierade enheterna", "The GPU has been moved out of VM": "GPU:n har flyttats från VM", + "The GPU identity or permissions changed; the container is not modified": "GPU-identiteten eller behörigheterna ändras; behållaren ändras inte", "The GPU is being detached from VM": "GPU:n kopplas bort från VM", + "The GPU vendor differs from the requested profile": "GPU-leverantören skiljer sig från den begärda profilen", + "The GPU vendor does not match the selected GPU profile:": "GPU-leverantören matchar inte den valda GPU-profilen:", + "The Immich CPU quota cannot be reproduced": "Immich CPU kvot kan inte reproduceras", + "The Immich library needs at least 8 GB": "Biblioteket Immich behöver minst 8 GB", + "The Immich startup was modified or cannot be reproduced": "Immich startades eller kan inte reproduceras", + "The LXC has stopped": "LXC har slutat", + "The Lounge starts in public mode: anyone who reaches the address opens the client without logging in, and the IRC networks added are lost when the session ends.": "Loungen börjar i offentligt läge: alla som når adressen öppnar klienten utan att logga in, och IRC-nätverken går förlorade när sessionen slutar.", + "The MAC address of the container cannot be kept": "MAC-adressen till behållaren kan inte hållas", "The NVIDIA Container Toolkit repository definition was empty.": "NVIDIA Container Toolkit-förvarets definition var tom.", "The NVIDIA Container Toolkit signing key could not be read.": "NVIDIA Container Toolkit-signeringsnyckeln kunde inte läsas.", + "The NVIDIA Container Toolkit version cannot be identified": "NVIDIA Container Toolkit kan inte identifieras", + "The NVIDIA destination cannot be replaced": "NVIDIA-destinationen kan inte ersättas", + "The NVIDIA destination escapes the rootfs": "NVIDIA-destinationen flyr från rötterna", "The NVIDIA driver is installed, but the Container Toolkit phase did not complete. GPU support for OCI containers is unavailable until it does.": "NVIDIA-drivrutinen är installerad, men Container Toolkit-fasen slutfördes inte. GPU-stöd för OCI-behållare är inte tillgängligt förrän det gör det.", + "The NVIDIA driver or inventory changed; the operation was stopped": "NVIDIA-föraren eller lagret ändrades; operation stoppades.", + "The NVIDIA hook or environment differs from the declared one": "NVIDIA-kroken eller miljön skiljer sig från den deklarerade", + "The NVIDIA hook path does not belong to the installer": "NVIDIA-hookbanan hör inte till installatören", "The NVIDIA installer needs at least": "NVIDIA-installationsprogrammet behöver minst", + "The NVIDIA runtime is up to date; the container is not modified or started": "NVIDIA runtime är uppdaterad; behållaren är inte modifierad eller startad", + "The Nextcloud volume needs at least 8 GB": "Nextcloud-volymen behöver minst 8 GB", + "The OCI archive contains no SHA-256 blobs": "OCI-arkivet innehåller inga SHA-256 blobs", + "The OCI archive does not contain exactly one manifest": "OCI-arkivet innehåller inte exakt ett manifest.", + "The OCI archive does not exist or is empty:": "OCI-arkivet existerar inte eller är tomt:", + "The OCI archive verifier was not found": "OCI-arkivkontrollen hittades inte", + "The OCI catalog is not installed. Update ProxMenux and try again.": "OCI-katalogen är inte installerad. Uppdatera ProxMenux och försök igen.", + "The OCI engine is not installed. Update ProxMenux and try again.": "OCI-motorn är inte installerad. Uppdatera ProxMenux och försök igen.", + "The OCI image storage was not kept": "OCI-bildlagringen hölls inte", + "The OCR language must use Tesseract codes, for example eng or eng+spa": "OCR-språket måste använda Tesseract-koder, till exempel eng eller eng+spa", + "The PATH of the new image is outside the reproducible profile": "Den nya bildens PATH ligger utanför den reproducerbara profilen.", + "The Paperless persistent volumes need at least 8 GB": "De papperslösa ihållande volymerna behöver minst 8 GB", + "The PostgreSQL volume needs at least 4 GB": "PostgreSQL-volymen behöver minst 4 GB", + "The PostgreSQL volume needs at least 8 GB": "PostgreSQL-volymen behöver minst 8 GB", "The Proxmox archive keyring is missing; Ceph installation cannot continue safely": "Proxmox arkivnyckelringen saknas;Ceph-installationen kan inte fortsätta på ett säkert sätt", + "The Proxmox inventory and the local configurations differ": "Proxmox-inventeringen och de lokala konfigurationerna skiljer sig åt", + "The Rclone configuration needs at least 1 GB": "Rclone-konfigurationen behöver minst 1 GB", + "The Rclone rootfs needs at least 2 GB": "Rclone rootfs behöver minst 2 GB", + "The Selkies profile requires a verified LinuxServer image": "Selkies profil requires en verifierad LinuxServer bild", + "The Tandoor files volume needs at least 2 GB": "Tandoor filer volymen behöver minst 2 GB", "The URL does not contain the required parameters (id, pack, edition).": "URL:en innehåller inte de nödvändiga parametrarna (id, pack, edition).", + "The USB number can change after reconnecting or rebooting. This profile does not remap it automatically or handle Coral USB re-enumeration. Do not share a dongle already used by another service.": "USB-numret kan ändras efter återanslutning eller omstart. Denna profil remap det inte automatiskt eller hantera Coral USB-omräkning. Dela inte en dongel som redan används av en annan tjänst.", + "The Unifi-controller software is a powerful, enterprise wireless software engine ideal for high-density client deployments requiring low latency and high uptime performance.": "Unifi-controller-programvaran är en kraftfull, företags trådlös mjukvarumotor idealisk för hög densitetsklientdistributioner requiring låg latens och hög upptidsprestanda.", + "The VA-API device does not exist:": "VA-API-enheten finns inte:", "The VM also has these audio devices assigned via PCI passthrough — typically added together with the GPU. Remove them too?": "Den virtuella datorn har också dessa ljudenheter tilldelade via PCI-passthrough - vanligtvis läggs till tillsammans med GPU:n. Ta bort dem också?", "The VM guest will have exclusive access to the GPU.": "VM-gästen kommer att ha exklusiv tillgång till GPU:n.", "The VM is powered on. Turn it off before adding disks.": "Den virtuella datorn är påslagen. Stäng av den innan du lägger till diskar.", "The VM/LXC will lose access to this disk after formatting.": "VM/LXC kommer att förlora åtkomst till denna disk efter formatering.", + "The VMID belongs to another container now and is not touched:": "VMID tillhör en annan behållare nu och är inte rörd:", + "The VMID or its contract is already in use; it is not adopted": "VMID eller dess kontrakt används redan; det antas inte", + "The VMID was reused or its identity is unknown; the operation is blocked": "VMID återanvändes eller dess identitet är okänd; operation blockeras.", + "The VMID was reused or the container is on another node; it is not overwritten": "VMID återanvändes eller behållaren är på en annan nod; den är inte överskriven.", + "The VMID was taken during the installation:": "VMID togs under installationen:", + "The Valkey volume needs at least 1 GB": "Valkey-volymen behöver minst 1 GB", + "The acceleration evidence differs from the verified inventory": "Accelerationsbeviset skiljer sig från den verifierade inventeringen", + "The acceleration profile does not support this architecture:": "Accelerationsprofilen stöder inte denna arkitektur:", "The active kernel driver is not vfio-pci, but the entry in": "Den aktiva kärndrivrutinen är inte vfio-pci, utan posten i", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot, breaking the LXC passthrough about to be configured.": "Den aktiva kärndrivrutinen är inte vfio-pci, men posten kommer att binda om GPU:n till vfio-pci vid nästa omstart, vilket bryter LXC-passthrough som ska konfigureras.", "The active kernel driver is not vfio-pci, but the entry will rebind the GPU to vfio-pci on the next reboot.": "Den aktiva kärndrivrutinen är inte vfio-pci, men posten kommer att binda om GPU:n till vfio-pci vid nästa omstart.", + "The adaptation content was modified": "Anpassningsinnehållet ändrades", + "The additional path hides a system directory": "Den extra vägen döljer en systemkatalog", + "The address is already assigned on this host or cluster:": "Adressen är redan tilldelad på denna värd eller kluster:", + "The address must start with http:// or https://": "Adressen måste börja med https:// eller https://", + "The administrator account, the public address and the UDP port are created on the first start, so the web interface opens directly on its login page.": "Administratörskontot, den offentliga adressen och UDP-porten skapas i första början, så webbgränssnittet öppnar direkt på sin inloggningssida.", + "The administrator email is not valid": "Administratörens e-post är inte giltigt", + "The administrator user contains characters that are not allowed": "Administratörsanvändaren innehåller tecken som inte är tillåtna", + "The all-in-one AI application.": "All-in-one AI-applikationen.", + "The application configuration needs a first start to complete.": "Applikationskonfigurationen behöver en första start för att slutföra.", + "The application did not complete its initial setup:": "Ansökan slutförde inte sin första installation:", + "The application did not get an address on the access network:": "Ansökan fick inte en adress på åtkomstnätet:", + "The application did not pass its HTTP check:": "Ansökan passerade inte HTTP-kontrollen:", + "The application did not respond in time:": "Ansökan svarade inte i tid:", + "The application stopped during its first start:": "Ansökan slutade under sin första start:", + "The application was removed": "Ansökan togs bort", "The archive could not be extracted.": "Arkivet kunde inte extraheras.", "The archive destination directory is INSIDE one of the paths you are about to back up. Writing the archive there would copy the backup into itself — producing a corrupted archive, or growing without limit until the disk fills up.": "Arkivdestinationskatalogen är INNE i en av sökvägarna du ska säkerhetskopiera. Att skriva arkivet där skulle kopiera säkerhetskopian in i sig själv - producera ett skadat arkiv, eller växa utan begränsning tills disken fylls upp.", + "The backup could not be identified; the image is not replaced": "Säkerhetskopian kunde inte identifieras; bilden ersätts inte", "The backup metadata was compared against this host. The following items will be SKIPPED to keep the boot safe:": "Säkerhetskopieringsmetadata jämfördes med denna värd. Följande artiklar HOPPAS över för att hålla uppstarten säker:", + "The backup of a member could not be identified": "En medlems säkerhetskopia kunde inte identifieras", + "The backup was altered; recovery blocked": "Backupen ändrades; återhämtning blockerad", "The backup was taken on a different PVE or kernel major.minor. These paths will be SKIPPED to keep the boot safe:": "Säkerhetskopieringen togs på en annan PVE eller kernel major.minor. Dessa sökvägar HOPPAS över för att hålla uppstarten säker:", + "The bind mount target escapes the rootfs:": "Det bindande monteringsmålet flyr rötterna:", + "The block device does not exist:": "Blockenheten finns inte:", "The build could not be checked beforehand; continuing without that check.": "Bygget kunde inte kontrolleras i förväg;fortsätter utan den kontrollen.", + "The cached image does not match the current digest": "Den cachade bilden matchar inte den nuvarande smältningen", + "The cached image is damaged; it will be downloaded again.": "Den cachade bilden är skadad; den kommer att laddas ner igen.", + "The character device does not exist:": "Karaktärenheten existerar inte:", + "The command asks for a password that is not echoed. After creating the users, the web interface asks for a user name and a password.": "Kommandot begär ett lösenord som inte echoed. Efter att ha skapat användarna ber webbgränssnittet om ett användarnamn och ett lösenord.", + "The command does not name an image": "Kommandot heter inte en bild", + "The command reads its variables from a file; write them in the command or use a Compose file": "Kommandot läser dess variabler från en fil; skriv dem i kommandot eller använd en Compose-fil", + "The command runs the container as the user of the host; the container uses the user of its image instead.": "Kommandot kör behållaren som användaren av värden; behållaren använder användaren av dess bild istället.", + "The command uses options that cannot be translated:": "Kommandot använder alternativ som inte kan översättas:", + "The command works out a value by running another command:": "Kommandot fungerar ut ett värde genom att köra ett annat kommando:", "The compatibility check raised failures that may break the system after restore.": "Kompatibilitetskontrollen ledde till fel som kan bryta systemet efter återställning.", + "The configuration changed after the backup was restored; the recovery is not confirmed": "Konfigurationen ändrades efter säkerhetskopian återställdes; återhämtningen bekräftas inte", + "The configuration changed after the new container was validated": "Konfigurationen ändrades efter att den nya behållaren validerades", + "The configuration changed during the NVIDIA refresh": "Konfigurationen ändrades under NVIDIA-uppdateringen", + "The configuration evidence does not match": "Konfigurationsbeviset matchar inte", + "The configuration must run as root on Proxmox VE": "Konfigurationen måste köras som rot på Proxmox VE", + "The configuration of a new member changed after it was created": "Konfigurationen av en ny medlem ändrades efter att den skapades", + "The configuration stopped because of an unexpected error": "Konfigurationen stannade på grund av ett oväntat fel", + "The consume/export volumes need at least 1 GB": "Förbruknings-/exportvolymerna behöver minst 1 GB", + "The container could not be removed automatically:": "Behållaren kunde inte tas bort automatiskt:", + "The container could not be started:": "Behållaren kunde inte startas:", + "The container creation does not match the prepared instance": "Behållarens skapelse matchar inte den förberedda instansen", + "The container devices do not match the saved record": "Container-enheterna matchar inte det sparade rekordet", + "The container did not stop to update its persistent configuration:": "Behållaren slutade inte uppdatera sin ihållande konfiguration:", + "The container did not stop; its disks are not touched": "Behållaren slutade inte; dess diskar rörs inte", + "The container disks do not match the saved record": "Containerskivorna matchar inte den sparade posten", + "The container does not exist:": "Behållaren finns inte:", + "The container does not have the fuse=1 feature enabled": "Behållaren har inte säkring = 1 funktion aktiverad", + "The container does not need it any more; an update downloads the new version when there is one.": "Behållaren behöver det inte längre; en uppdatering hämtar den nya versionen när det finns en.", + "The container gets its own address and its own volumes, so the networks and volumes declared in the file are not used.": "Behållaren får sin egen adress och sina egna volymer, så de nätverk och volymer som anges i filen används inte.", + "The container has advanced Proxmox settings outside the supported profile": "Behållaren har avancerade Proxmox-inställningar utanför den stödda profilen", + "The container identity changed; the container is not replaced": "Behållarens identitet ändras; behållaren ersätts inte", + "The container identity does not match": "Innehållarens identitet matchar inte", + "The container identity or configuration changed": "Container identitet eller konfiguration ändras", "The container is currently stopped. Do you want to start it now to install the package?": "Containern är för närvarande stoppad. Vill du starta det nu för att installera paketet?", + "The container is not modified because a host directory is not available:": "Behållaren ändras inte eftersom en värdkatalog inte är tillgänglig:", + "The container no longer exists:": "Behållaren finns inte längre:", + "The container of a member was replaced; the assembly is not resumed": "En medlems behållare ersattes; församlingen återupptas inte.", "The container should now start as privileged": "Behållaren bör nu starta som privilegierad", "The container should now start as unprivileged": "Behållaren bör nu starta som oprivilegierad", + "The container stopped after starting:": "Behållaren stannade efter start:", + "The container stopped before publishing the mount": "Behållaren stannade innan du publicerade montern", + "The container stopped before the GPU permissions were verified:": "Behållaren stannade innan GPU-behörigheterna verifierades:", + "The container stopped before the application responded:": "Behållaren stannade innan ansökan svarade:", + "The container stopped:": "Behållaren stannade:", + "The container takes its time zone from Proxmox, so the time files of the host are not attached to it.": "Behållaren tar sin tidszon från Proxmox, så tidsfilerna på värden är inte fästa på den.", + "The container was changed outside ProxMenux and an update would discard those changes:": "Behållaren ändrades utanför ProxMenux och en uppdatering skulle kassera dessa ändringar:", + "The container was created from a downloaded OCI image": "Behållaren skapades från en nedladdad OCI-bild", + "The containers do not need them any more; an update downloads the new versions when there are any.": "Behållarna behöver dem inte längre; en uppdatering laddar ner de nya versionerna när det finns några.", + "The containers were created from downloaded OCI images": "Behållarna skapades från nedladdade OCI-bilder", + "The coordinated backup was modified": "Den samordnade backupen modifierades", "The current driver will be completely uninstalled before installing the new version. Continue?": "Den aktuella drivrutinen kommer att avinstalleras helt innan den nya versionen installeras. Fortsätta?", + "The current image of the saved channel will be checked and downloaded. Resources, paths and GPU are kept. The CT is stopped during the replacement and a native backup is created first.": "Den aktuella bilden av den sparade kanalen kontrolleras och laddas ner. Resurser, vägar och GPU hålls. CT stoppas under ersättningen och en infödd säkerhetskopia skapas först.", + "The current record is missing for": "Nuvarande rekord saknas för", + "The current template changes the image or identity; an explicit migration is required": "Den aktuella mallen ändrar bilden eller identiteten; en explicit migration är required.", + "The current template requires a new persistent path:": "Den nuvarande mallen requires en ny ihållande väg:", + "The custom path cannot hide system directories": "Den anpassade vägen kan inte dölja systemkataloger", + "The custom path overlaps another mount": "Den anpassade vägen överlappar ett annat berg", + "The data and document volumes need at least 8 GB": "Data- och dokumentvolymerna behöver minst 8 GB", + "The database server must accept connections from the IP address of this container, with a user that is not limited to localhost.": "Databasservern måste acceptera anslutningar från IP-adressen till denna behållare, med en användare som inte är begränsad till localhost.", + "The dedicated adapter still requires replaying its rootfs changes": "Den dedikerade adaptern fortfarande requires spela sina rootfs förändringar", + "The dependency hook and the stack recipe differ": "Beroende krok och stack receptet skiljer sig", + "The dependency hook was modified; review it before updating": "Beroendekroken ändrades; granska den innan du uppdaterar", + "The developer-friendly cloud platform for building and running LLM agents for AI-native applications.": "Den utvecklarvänliga molnplattformen för att bygga och driva LLM-agenter för AI-inhemska applikationer.", + "The device directory does not exist:": "Enhetskatalogen finns inte:", + "The device must keep its /dev path inside the LXC:": "Enheten måste hålla sin / Dev-väg inuti LXC:", + "The device must keep its native path without duplicates": "Enheten måste hålla sin infödda väg utan dubbletter", + "The directory contains no character devices:": "Katalogen innehåller inga teckenenheter:", "The directory does not exist in the CT.": "Katalogen finns inte i CT.", "The disk": "Disken", + "The disk size cannot be reproduced": "Skivstorleken kan inte reproduceras", + "The disk usage of the container could not be read": "Diskens användning av behållaren kunde inte läsas", + "The domain must resolve to the public address of this network before the certificate can be issued.": "Domänen måste lösa den offentliga adressen till detta nätverk innan certifikatet kan utfärdas.", + "The download client still needs to be configured.": "Nedladdningskunden behöver fortfarande konfigureras.", + "The download stopped progressing; cancelling this attempt.": "Nedladdningen slutade utvecklas; avbryta detta försök.", + "The downloaded image does not match its manifest": "Den nedladdade bilden matchar inte dess manifest", + "The downloaded image is corrupt:": "Den nedladdade bilden är korrupt:", "The dpkg package database is clean.": "Paketdatabasen för dpkg är ren.", "The driver installed but does not drive this GPU.": "Drivrutinen installerad men driver inte denna GPU.", + "The dynamic NVIDIA hook is missing": "Den dynamiska NVIDIA-hooken saknas", + "The dynamic NVIDIA hook is missing or duplicated": "Den dynamiska NVIDIA-kroken saknas eller dupliceras", + "The dynamic NVIDIA profile requires an unprivileged LXC": "Den dynamiska NVIDIA-profilen requires en oprivilegierad LXC", + "The dynamic profile does not support static driver mounts": "Den dynamiska profilen stöder inte statiska drivrutiner", "The file does not exist, is empty or is not readable.": "Filen finns inte, är tom eller är inte läsbar.", + "The file does not exist:": "Filen finns inte:", + "The file is too large to be a Compose file": "Filen är för stor för att vara en komponeringsfil", "The filesystem": "Filsystemet", + "The final cleanup did not complete:": "Den slutliga rengöringen slutfördes inte:", "The following DKMS-managed drivers will now be rebuilt against it so they keep working after reboot:": "Följande DKMS-hanterade drivrutiner kommer nu att byggas om mot det så att de fortsätter att fungera efter omstart:", "The following LXC containers have NVIDIA passthrough configured:": "Följande LXC-behållare har NVIDIA-passthrough konfigurerad:", "The following backup paths are kernel-tied and are excluded from the picker to keep the target's boot safe. The operator's own tuning inside these paths (IOMMU cmdline, VFIO IDs, custom quirks) is merged back automatically via kernel-agnostic merge:": "Följande säkerhetskopieringsvägar är kärnbundna och exkluderas från väljaren för att hålla målets start säker. Operatörens egen inställning inom dessa banor (IOMMU cmdline, VFIO ID:n, anpassade quirks) slås tillbaka automatiskt via kärnagnostisk sammanfogning:", @@ -4390,17 +5865,99 @@ "The following selected device(s) are Physical Functions with active Virtual Functions:": "Följande valda enhet(er) är fysiska funktioner med aktiva virtuella funktioner:", "The following selected device(s) are SR-IOV Virtual Functions (VFs):": "Följande valda enhet(er) är virtuella SR-IOV-funktioner (VF):", "The fstab entry will still be removed; reboot or manual umount needed.": "fstab-posten kommer fortfarande att tas bort; omstart eller manuell avmontering behövs.", + "The gateway must be another usable address in the same subnet.": "Porten måste vara en annan användbar adress i samma undernät.", "The gateway should appear in your Tailscale admin console shortly.": "Gatewayen bör snart visas i din Tailscale-administratörskonsol.", + "The healthcheck cannot run without an IP address": "Hälsokontrollen kan inte köras utan en IP-adress", + "The host NVIDIA driver is not responding correctly": "Värd NVIDIA-föraren svarar inte korrekt", + "The host bind source does not exist:": "Värdbindningskällan finns inte:", + "The host bind source is not a regular file or directory:": "Värdbindningskällan är inte en vanlig fil eller katalog:", + "The host directory changed before it was mounted": "Värdkatalogen ändrades innan den monterades", "The host directory may not be accessible from an unprivileged container.": "Värdkatalogen kanske inte är tillgänglig från en oprivilegierad behållare.", + "The host has no IPv4 address on the selected bridge": "Värden har ingen IPv4-adress på den valda bron", + "The host monitor does not see the real host memory": "Värdskärmen ser inte det verkliga värdminnet", + "The host monitor does not share this host namespace:": "Värdskärmen delar inte detta värdnamnsutrymme:", + "The host monitor needs consent for privileged access to the host": "Värdkontrollen behöver samtycke för privilegierad åtkomst till värden", + "The host monitor profile does not support another sysctl include": "Värdmonitorprofilen stöder inte en annan sysctl inkluderar", + "The host monitor uses the host network, without DHCP or its own gateway": "Värdmonitorn använder värdnätverket, utan DHCP eller egen gateway", + "The host port is already in use:": "Värdporten är redan i bruk:", + "The identity of a member was replaced": "En medlems identitet ersattes", + "The image changes the user expected by the adapter": "Bilden ändrar användaren som förväntas av adaptern", + "The image could not be read from its registry:": "Bilden kunde inte läsas från dess register:", + "The image declares data paths that are still stored in the rootfs": "Bilden förklarar datavägar som fortfarande lagras i rötterna", + "The image did not grant the application user access to the devices; check its native init. Host permissions were not relaxed.": "Bilden gav inte applikationsanvändaren tillgång till enheterna; kontrollera dess inhemska init. Värdbehörigheter var inte avslappnade.", + "The image did not pass the integrity check": "Bilden passerade inte integritetskontrollen", + "The image does not declare support for this architecture:": "Bilden förklarar inte stöd för denna arkitektur:", + "The image download did not complete correctly; downloading it again...": "Bildnedladdningen slutfördes inte korrekt; ladda ner den igen...", + "The image expects files that are given to it one by one:": "Bilden förväntar sig filer som ges till den en efter en:", + "The image is already up to date; nothing was changed.": "Bilden är redan uppdaterad; ingenting ändrades.", + "The image is in its registry, for one architecture.": "Bilden finns i dess register, för en arkitektur.", + "The image is in its registry.": "Bilden finns i dess register.", + "The image is in its registry:": "Bilden finns i dess register:", + "The image requests NVIDIA, but the host has no working NVIDIA driver": "Bilden begär NVIDIA, men värden har ingen fungerande NVIDIA-förare", + "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk.": "Bilden begär inaktivering av en del av AppArmor eller seccomp confinement. Fortsätt bara om du litar på bilden och accepterar denna risk.", + "The image requests disabling part of the AppArmor or seccomp confinement. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk.": "Bilden begär inaktivering av en del av AppArmor eller seccomp confinement. Komponera erbjuder en valfri AppArmor eller seccomp avslappning; det kommer att vara inaktiverat om inte användaren väljer det. Fortsätt bara om du litar på bilden och accepterar denna risk.", + "The image was not found in its registry, or it is private:": "Bilden hittades inte i dess register, eller det är privat:", + "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged.": "Den importerade Komponera förfrågningar privilegierade, men den officiella jlesage / handbrake dokumentation inte require det; ProxMenux håller LXC oprivilegierad.", + "The imported OCI groups are not numeric": "De importerade OCI-grupperna är inte numeriska", + "The imported OCI user or group is not numeric": "Den importerade OCI-användaren eller gruppen är inte numerisk", + "The initial user name and password stay written in /etc/pve/lxc/.conf as INIT_USERNAME and INIT_PASSWORD. They can be removed after the first login, with the container stopped.": "Det första användarnamnet och lösenordet förblir skrivet i /etc/pve/lxc/.conf som INIT USERNAME och INIT PASSWORD. De kan tas bort efter den första inloggningen, med behållaren stannade.", + "The installation asks which one to use for these paths.": "Installationen frågar vilken som ska användas för dessa vägar.", + "The installation ended with exit code": "Installationen slutade med exitkod", "The installation requires a server restart to apply changes. Do you want to restart now?": "Installationen kräver en omstart av servern för att tillämpa ändringar. Vill du starta om nu?", + "The installation runs on the Proxmox node itself, as root": "Installationen körs på Proxmox-noden själv, som rot", + "The installation stopped because of an unexpected error": "Installationen stannade på grund av ett oväntat fel", "The installation/changes require a server restart to apply correctly. Do you want to reboot now?": "Installationen/ändringarna kräver en omstart av servern för att tillämpas korrekt. Vill du starta om nu?", + "The installer must run as root on Proxmox VE": "Installatören måste köras som rot på Proxmox VE", + "The instance changed while it was being edited; configure Recreate again": "Instansen ändrades medan den redigerades; konfigurera återskapa igen", + "The instance does not use NVIDIA": "Instansen använder inte NVIDIA", + "The instance has a pending operation": "Instansen har en väntande operation", + "The instance identity or status must be reviewed before updating.": "Instansidentitet eller status måste granskas innan du uppdaterar.", + "The instance is not ready to be updated": "Instansen är inte redo att uppdateras", + "The instance is not ready; review its pending operation": "Instansen är inte klar; granska dess pågående operation", + "The instance record operation did not complete; no container was modified.": "Instansrekordet operation slutfördes inte; ingen behållare ändrades.", + "The instance registry is not safe": "Instansregistret är inte säkert", + "The journal belongs to another VMID": "Tidskriften tillhör en annan VMID", + "The journal belongs to another stack": "Tidskriften tillhör en annan stack", + "The journal has an incomplete recovery state": "Tidskriften har en ofullständig återhämtning stat", + "The kernel module is not active:": "Kernelmodulen är inte aktiv:", "The kernel module of version": "Kärnmodulen i versionen", "The local envelope is dropped and future backups do not upload anything. Uploaded envelopes already on PBS stay intact and remain recoverable with their original passphrase.": "Det lokala kuvertet tappas och framtida säkerhetskopior laddar inte upp någonting. Uppladdade kuvert som redan finns på PBS förblir intakta och kan återställas med sin ursprungliga lösenfras.", "The long test runs directly on the disk hardware.": "Det långa testet körs direkt på hårdvaran på hårddisken.", + "The main member must stop first and start last": "Huvudmedlemmen måste stanna först och börja senast", + "The main member of the stack is missing": "Huvudmedlemmen i stacken saknas", + "The manifest does not match its digest": "manifestet matchar inte sin smälta", + "The member journal belongs to another stack operation": "Medlemstidskriften tillhör en annan stack operation", + "The member journal is outside the registry": "Medlemstidskriften är utanför registret", + "The mount evidence does not match the verified directories": "Mount bevis matchar inte de verifierade katalogerna", + "The mount source or options were not kept": "Mount-källan eller alternativen förvarades inte", + "The mounted source differs from the configured directory": "Den monterade källan skiljer sig från den konfigurerade katalogen", + "The mounts of the new container do not match the proposal": "Den nya behållarens fästen matchar inte förslaget", + "The native GPU permissions were not kept": "De inhemska GPU-behörigheterna förvarades inte", + "The native unprivileged idmap is required": "Den infödda oprivilegierade idmap är required", "The new SSH key was installed and is now authorized on the server.\nKey file:": "Den nya SSH-nyckeln installerades och är nu auktoriserad på servern.\nNyckelfil:", "The new SSH key was pushed to the LXC via 'pct exec' on": "Den nya SSH-nyckeln trycktes till LXC via 'pct exec' på", + "The new Valkey volume contains unexpected data": "Den nya Valkey-volymen innehåller oväntade data", + "The new container did not pass validation": "Den nya behållaren godkände inte validering", + "The new container is not authorized by the operation journal": "Den nya behållaren är inte auktoriserad av tidskriften operation", + "The new image adds a symbolic link in a generated path": "Den nya bilden lägger till en symbolisk länk i en genererad väg", + "The new image changes the PostgreSQL major version; the data must be migrated before updating": "Den nya bilden ändrar PostgreSQL-versionen; data måste migreras innan de uppdateras.", + "The new image could not be installed": "Den nya bilden kunde inte installeras", + "The new image could not be installed:": "Den nya bilden kunde inte installeras:", + "The new image does not keep a required executable": "Den nya bilden håller inte en required körbar", + "The new image requires additional persistent paths": "Den nya bilden requires ytterligare bestående vägar", + "The new image requires additional persistent paths; use Recreate": "Den nya bilden requires ytterligare ihållande vägar; använd Återskapa", "The new prompt will be used in new terminal sessions.": "Den nya prompten används i nya terminalsessioner.", "The next visit to the dashboard will show the initial setup wizard.": "Nästa besök på instrumentpanelen visar den första installationsguiden.", + "The observed inventory differs from the validated runtime": "Den observerade inventeringen skiljer sig från den validerade runtime", + "The official Tandoor startup executable is missing": "Den officiella Tandoor start körbar saknas", + "The official inventory contains no NVIDIA devices": "Den officiella inventeringen innehåller inga NVIDIA-enheter", + "The official inventory contains no NVIDIA driver components": "Den officiella inventeringen innehåller inga NVIDIA-komponenter", + "The official startup cannot be reproduced": "Den officiella starten kan inte reproduceras", + "The official startup of the application is missing": "Den officiella starten av ansökan saknas", + "The operation already finished; it is not restored automatically": "operationen är redan färdig; den återställs inte automatiskt", + "The operation could not be completed": "operationen kunde inte slutföras", + "The operation stopped halfway. Choose \"Recover\" for this container in the OCI management menu to restore the previous installation.": "operationen stannade halvvägs. Välj \"Recover\" för denna behållare i OCI-hanteringsmenyn för att återställa den tidigare installationen.", + "The operation was stopped because a shared directory changed its identity:": "operationen stoppades eftersom en delad katalog ändrade sin identitet:", "The original MOTD backup is unavailable; no changes were made": "Den ursprungliga MOTD-backupen är inte tillgänglig;inga ändringar gjordes", "The original MOTD configuration has been restored": "Den ursprungliga MOTD-konfigurationen har återställts", "The original MOTD state is unavailable; no changes were made": "Det ursprungliga MOTD-tillståndet är inte tillgängligt;inga ändringar gjordes", @@ -4408,18 +5965,76 @@ "The original rpcbind state could not be restored completely": "Det ursprungliga rpcbind-tillståndet kunde inte återställas helt", "The original rpcbind state is unavailable; no service state was changed": "Det ursprungliga rpcbind-tillståndet är inte tillgängligt;inget serviceläge ändrades", "The package is currently in a broken state and is blocking apt updates on this system.": "Paketet är för närvarande i ett trasigt tillstånd och blockerar lämpliga uppdateringar på det här systemet.", + "The parent of an NVIDIA destination is not a directory": "Förälder till en NVIDIA destination är inte en katalog", + "The parent of the target is not a directory:": "Målets förälder är inte en katalog:", + "The password could not be retrieved automatically": "Lösenordet kunde inte hämtas automatiskt", "The passwords do not match. Please try again.": "Lösenorden stämmer inte överens. Försök igen.", + "The path escapes the rootfs:": "Vägen rymmer rötterna:", + "The path must be absolute and normalized": "Vägen måste vara absolut och normaliserad", + "The path overlaps an existing mount": "Vägen överlappar ett befintligt berg", + "The persistent NVIDIA hook does not match the installer:": "Den ihållande NVIDIA-kroken matchar inte installationsprogrammet:", + "The persistent WebUI credentials were not found": "Den ihållande WebUI credentials hittades inte", + "The physical NVIDIA selection changed": "Det fysiska NVIDIA-valet ändrades", + "The post-start configuration cannot be applied with the LXC stopped": "Konfigurationen efter start kan inte tillämpas med LXC stoppas.", + "The postgres user was not found in the image": "Postgres-användaren hittades inte i bilden", + "The prepared directory escapes the rootfs:": "Den förberedda katalogen flyr rötterna:", "The preselected VMID does not exist on this host:": "Det förvalda VMID:t finns inte på denna värd:", + "The previous native backup will be restored. Shared host directories are not reverted. Displaced disks are kept.": "Den tidigare infödda backupen kommer att återställas. Delade värdkataloger återställs inte. Fördrivna diskar hålls.", + "The previous stack contract is not safe; review it before reusing it": "Det tidigare stackkontraktet är inte säkert; granska det innan du återanvänder det", + "The previous stack contract is not valid; it is not archived automatically": "Det tidigare stackkontraktet är inte giltigt; det arkiveras inte automatiskt", + "The previous stack contract still has containers or VMs:": "Det tidigare stackkontraktet har fortfarande behållare eller VM:er:", + "The private address is already assigned to another container:": "Den privata adressen är redan tilldelad till en annan behållare:", + "The private bridge does not have the expected address:": "Den privata bron har inte den förväntade adressen:", + "The private journal has an unsafe owner or permissions": "Den privata tidskriften har en osäker ägare eller tillstånd", + "The private network allocator was not found": "Den privata nätverksallokatorn hittades inte", + "The private network is still used by another container and is kept:": "Det privata nätverket används fortfarande av en annan behållare och hålls:", + "The private network must be assigned automatically": "Det privata nätverket måste tilldelas automatiskt", + "The privileged deployment does not include the required explicit consent": "Den privilegierade utplaceringen omfattar inte det required explicit samtycke.", + "The prlimit soft value exceeds the hard value": "Prlimit mjukt värde överstiger det hårda värdet", + "The proposal changes the identity of the instance": "Förslaget ändrar instansens identitet", "The proposed ARC maximum is below Proxmox VE's pool-size guideline:": "Det föreslagna ARC-maximumet ligger under Proxmox VE:s riktlinjer för poolstorlek:", + "The published views must be inside the common root": "Den publicerade synen måste vara inne i den gemensamma roten", + "The read-only view does not apply the expected protection": "Den lätta utsikten gäller inte det förväntade skyddet", + "The read-only view was not published": "Den lätta utsikten publicerades inte", + "The read/write view was not published": "Den läs/skrivna vyn publicerades inte", + "The recipe requires configuration at startup; its coordinated replay is not available": "Receptet requires konfiguration vid start; dess koordinerade replay är inte tillgänglig", + "The record belongs to another container": "Skivan tillhör en annan behållare", + "The record does not belong to this operation": "Skivan tillhör inte denna operation", + "The record no longer belongs to this operation": "Skivan tillhör inte längre denna operation", + "The record of a member was replaced; the assembly is not resumed": "En medlems rekord ersattes; församlingen återupptas inte.", + "The record or diagnosis could not be completed; no update was run.": "Rekordet eller diagnosen kunde inte slutföras; ingen uppdatering kördes.", + "The recovery did not complete. Review the log and choose \"Recover\" again for this container in the OCI management menu.": "Återhämtningen slutfördes inte. Granska loggen och välj \"Recover\" igen för den här behållaren i OCI-hanteringsmenyn.", + "The remote does not exist; create and authorize it first in the WebUI:": "Fjärrkontrollen finns inte; skapa och godkänna den först i WebUI:", + "The remote installer must run as root on Proxmox VE": "Fjärrinstallatören måste köras som rot på Proxmox VE", + "The remote must already be created and authorized in the Rclone web UI. This operation restarts the CT and publishes two FUSE views on the host.": "Fjärrkontrollen måste redan skapas och auktoriseras i Rclone webb-UI. Denna operation startar om CT och publicerar två FUSE-vyer på värden.", + "The remote path must be relative and cannot contain line breaks": "Den avlägsna vägen måste vara relativ och kan inte innehålla linjeavbrott", + "The removal could not be prepared:": "Avlägsnandet kunde inte förberedas:", + "The repair must preserve the image dependencies:": "Reparationen måste bevara bildberoenden:", + "The requested VMID block is already in use": "Det begärda VMID-blocket används redan", + "The requested machine learning GPU profile is not working; it is not replaced by CPU": "Den begärda maskininlärningen GPU-profilen fungerar inte; den ersätts inte av CPU.", + "The restored service did not pass its health check": "Den återställda tjänsten passerade inte hälsokontrollen", + "The restored service stopped; the recovery is not confirmed": "Den återställda tjänsten stannade; återhämtningen bekräftas inte", + "The reviewed Tandoor stack does not require a privileged LXC.": "Den granskade Tandoor stack inte require en privilegierad LXC.", + "The rootfs capture only belongs to the running installation": "Rotfarna fångar bara tillhör den löpande installationen", + "The rootfs is not managed by Proxmox": "Rötterna hanteras inte av Proxmox", + "The rootfs is not mounted": "Rötterna är inte monterade", "The same GPU cannot be used by two VMs at the same time.": "Samma GPU kan inte användas av två virtuella datorer samtidigt.", + "The same connection can be given as container variables instead of the file: UN_SONARR_0_URL and UN_SONARR_0_API_KEY, or the UN_RADARR_0_ equivalents.": "Samma anslutning kan ges som containervariabler i stället för filen: UN SONARR 0 URL och UN SONARR 0 API KEY, eller UN RADARR 0 equivalents.", "The saved MOTD state is invalid; no changes were made": "Det sparade MOTD-tillståndet är ogiltigt;inga ändringar gjordes", + "The saved OCI record is incomplete or has an unexpected format.": "Den sparade OCI-posten är ofullständig eller har ett oväntat format.", + "The saved projection does not match the native evidence": "Den sparade projektionen matchar inte de infödda bevisen", + "The saved record was replaced for": "Det sparade rekordet ersattes för", "The saved utility package list is invalid; no packages were removed": "Listan över sparade verktygspaket är ogiltig;inga paket togs bort", "The script clones the osx-proxmox.com repository and once the setup is complete, the server will automatically reboot.": "Skriptet klonar osx-proxmox.com-arkivet och när installationen är klar kommer servern automatiskt att starta om.", "The script will continue to restore VM passthrough mode on the host and reuse existing hostpci entries.": "Skriptet kommer att fortsätta att återställa VM-passthrough-läge på värden och återanvända befintliga hostpci-poster.", "The script will preconfigure the selected GPU now and finalize hardware binding after reboot.": "Skriptet kommer att förkonfigurera den valda GPU:n nu och slutföra hårdvarubindning efter omstart.", "The selected AMD GPU does not report FLR reset support": "Den valda AMD GPU:n rapporterar inte stöd för FLR-återställning", "The selected AMD GPU is currently in power state D3cold": "Den valda AMD GPU:n är för närvarande i strömtillstånd D3cold", + "The selected CT does not match its OCI record. Its configuration will not be modified or deleted.": "Den valda CT matchar inte OCI-posten. Dess konfiguration kommer inte att ändras eller tas bort.", + "The selected GPU changed": "Den valda GPU ändras", "The selected GPU configuration already exists in this container.": "Den valda GPU-konfigurationen finns redan i den här behållaren.", + "The selected GPU device does not exist:": "Den valda GPU-enheten finns inte:", + "The selected GPU directory does not exist:": "Den valda GPU-katalogen finns inte:", "The selected GPU has no dedicated .1 audio sibling function.": "Den valda grafikprocessorn har ingen dedikerad .1-ljudsyskonfunktion.", "The selected GPU is already assigned to another VM that is currently running:": "Den valda GPU:n är redan tilldelad till en annan virtuell dator som körs för närvarande:", "The selected GPU is already assigned to this VM, but the host is not currently using vfio-pci for this device.": "Den valda GPU:n är redan tilldelad till denna virtuella dator, men värden använder för närvarande inte vfio-pci för den här enheten.", @@ -4435,11 +6050,15 @@ "The selected Intel GPU does not expose a PCI reset interface": "Den valda Intel GPU:n exponerar inte ett PCI-återställningsgränssnitt", "The selected Intel GPU has non-FLR reset support and unknown subtype": "Den valda Intel GPU:n har stöd för icke-FLR-återställning och okänd undertyp", "The selected Intel GPU is currently in power state D3cold": "Den valda Intel GPU:n är för närvarande i strömtillstånd D3cold", + "The selected Intel render device does not exist:": "Den valda Intel render-enheten finns inte:", "The selected VM": "Den valda virtuella datorn", "The selected VM is running.": "Den valda virtuella datorn körs.", "The selected base folder does not exist and could not be created:": "Den valda basmappen finns inte och kunde inte skapas:", + "The selected configuration needs to start the LXC during the installation": "Den valda konfigurationen måste starta LXC under installationen", "The selected container is unprivileged. A privileged container is required for direct device passthrough.": "Den valda behållaren är oprivilegierad. En privilegierad behållare krävs för direkt enhetsgenomföring.", "The selected device": "Den valda enheten", + "The selected device is not a block device": "Den valda enheten är inte en blockenhet", + "The selected device is not a character device": "Den valda enheten är inte en karaktär enhet", "The selected directory does not exist:": "Den valda katalogen finns inte:", "The selected disk has an active swap partition. Aborting.": "Den valda disken har en aktiv swap-partition. Åtgärden avbryts.", "The selected disk is currently used by a RUNNING VM or CT. Stop it before formatting.": "Den valda disken används för närvarande av en RUNNING VM eller CT. Stoppa det innan du formaterar.", @@ -4447,25 +6066,76 @@ "The selected disk now contains a system-critical mount. Aborting.": "Den valda disken innehåller nu en systemkritisk montering. Avbryter.", "The selected path does not exist on this host:": "Den valda sökvägen finns inte på denna värd:", "The selected path is not a valid directory:": "Den valda sökvägen är inte en giltig katalog:", + "The selected render device does not exist:": "Den valda render-enheten finns inte:", "The server connected you as guest instead of the specified user.": "Servern kopplade dig som gäst istället för den angivna användaren.", "The server may not have accessible shares.": "Servern kanske inte har tillgängliga resurser.", "The server may require authentication for actual share access.": "Servern kan kräva autentisering för faktisk delningsåtkomst.", "The server refused password authentication for": "Servern vägrade lösenordsautentisering för", "The server rejected": "Servern avvisades", + "The service builds its own image; only a published image can be installed": "Tjänsten bygger sin egen bild; endast en publicerad bild kan installeras.", + "The service declares no image:": "Tjänsten förklarar ingen bild:", + "The setting has no final value:": "Inställningen har inget slutvärde:", "The share already exists in smb.conf:": "Delningen finns redan i smb.conf:", + "The shared destination is not a directory": "Den delade destinationen är inte en katalog", + "The shared directory points to a protected host path": "Den delade katalogen pekar på en skyddad värdväg", + "The shared path exists but is not a directory:": "Den gemensamma vägen finns men är inte en katalog:", + "The size of existing disks is not rounded": "Storleken på befintliga diskar är inte avrundad", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk.": "Källan Komponera förfrågningar privilegierade: sant, men detta bevisar inte att bilden behöver en privilegierad LXC. ProxMenux kommer att använda en oprivilegierad LXC som standard och kommer att erbjuda det breda läget endast som ett alternativ. Fortsätt bara om du litar på bilden och accepterar denna risk.", + "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. The Docker rootlesskit profile does not exist in LXC and will be replaced by AppArmor unconfined, which is less restrictive. Continue only if you trust the image and accept this risk.": "Källan Komponera förfrågningar privilegierade: sant, men detta bevisar inte att bilden behöver en privilegierad LXC. ProxMenux kommer att använda en oprivilegierad LXC som standard och kommer att erbjuda det breda läget endast som ett alternativ. Komponera erbjuder en valfri AppArmor eller seccomp avslappning; det kommer att vara inaktiverat om inte användaren väljer det. Docker rootlesskit-profilen finns inte i LXC och kommer att ersättas av AppArmor obunden, vilket är mindre restriktivt. Fortsätt bara om du litar på bilden och accepterar denna risk.", "The source VM also has these audio devices, likely added together with the GPU. Remove them too?": "Käll-VM har också dessa ljudenheter, troligen läggs ihop med GPU:n. Ta bort dem också?", "The specified directory does not exist:": "Den angivna katalogen finns inte:", + "The stability period must be shorter than the healthcheck timeout": "Stabilitetsperioden måste vara kortare än hälsokontrollens timeout", + "The stack contains devices or directives without a translation": "Stacken innehåller enheter eller direktiv utan översättning", + "The stack does not have the expected native hook": "Stacken har inte den förväntade infödda kroken", + "The stack journal is outside the registry": "Stack journal är utanför registret", + "The stack member has no declared adaptation profile": "Stackmedlemmen har ingen deklarerad anpassningsprofil", + "The stack name only accepts lowercase letters, numbers and hyphens": "Stacknamnet accepterar endast bokstäver, siffror och hyphens", + "The stack needs member adaptations or a verification of missing volumes": "Stacken behöver medlemsanpassningar eller en verifiering av saknade volymer", + "The stack operation had already finished": "Stacken operation hade redan avslutats", + "The stack operation has not finished yet": "Stacken operation har ännu inte avslutats", + "The stack operation stopped halfway. Select the stack again in the OCI management menu to recover it.": "Stacken operation stannade halvvägs. Välj stacken igen i OCI-hanteringsmenyn för att återställa den.", + "The stack registry is incomplete; review the private contracts.": "Stackregistret är ofullständigt; granska privata kontrakt.", + "The stack startup hook was not found": "Stack Startup Hook hittades inte", + "The stack update was saved.": "Stackuppdateringen sparades.", + "The startup differs from the declared Nextcloud adapter": "Starten skiljer sig från den deklarerade Nextcloud-adaptern", + "The startup differs from the declared adapter": "Starten skiljer sig från den deklarerade adaptern", + "The staticfiles volume needs at least 1 GB": "Statikfilvolymen behöver minst 1 GB", "The storage has been removed and the disk unmounted.": "Lagringen har tagits bort och disken har avmonterats.", + "The sysctl content was modified outside the saved record": "Sysctl-innehållet ändrades utanför den sparade posten", + "The sysctl include is a link:": "Sysctl är en länk:", + "The sysctl include is not a safe host file": "Sysctl inkluderar inte en säker värdfil", + "The sysctl include is not restored over a symbolic link": "Sysctl inkluderar inte återställs över en symbolisk länk", + "The sysctl include is unknown or differs from the saved record": "Sysctl inkluderar är okänt eller skiljer sig från det sparade rekordet", + "The temporary password could not be retrieved.": "Det tillfälliga lösenordet kunde inte hämtas.", "The test will continue even if you close this terminal.": "Testet fortsätter även om du stänger denna terminal.", + "The tmpfs mounts of the container differ from the saved record": "Tmpfs montage av behållaren skiljer sig från den sparade rekordet", + "The tmpfs path or size is outside the supported profile": "Tmpfs-banan eller storleken ligger utanför den stödda profilen", + "The translated recipe changed during the preparation": "Det översatta receptet ändrades under förberedelsen", + "The value contains an unsupported character": "Värdet innehåller en ostödd karaktär", + "The values do not match. Enter them again.": "Värdena matchar inte. Ange dem igen.", + "The variable contains control characters:": "Variabeln innehåller kontrollkaraktärer:", + "The variable contains line breaks:": "Variabeln innehåller radbrytningar:", "The vfio.conf entries have been removed and initramfs rebuilt.": "vfio.conf-posterna har tagits bort och initramfs har byggts om.", + "The web UI password must have at least 24 characters": "Web UI-lösenordet måste ha minst 24 tecken", + "The web UI user contains characters that are not allowed": "Web UI-användaren innehåller tecken som inte är tillåtna", + "The web interface is served over plain HTTP on port 51821 (INSECURE=true). Keep it inside the local network or publish it through a reverse proxy with TLS.": "Webbgränssnittet serveras över vanligt HTTP på port 51821 (INSECURE=true). Håll det inne i det lokala nätverket eller publicera det genom en omvänd proxy med TLS.", + "The web interface uses a self-signed certificate, so the browser shows a warning the first time.": "Webbgränssnittet använder ett självsignerat certifikat, så webbläsaren visar en varning första gången.", + "The wizard writes a .conf file in /config. Restart the container afterwards so the bot starts with that configuration.": "Trollkarlen skriver en .conf-fil i /config. Starta behållaren efteråt så bot börjar med den konfigurationen.", + "The world's fastest framework for building websites": "Världens snabbaste ram för att bygga webbplatser", + "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server.": "Thelounge (en fork av shoutIRC) är en web IRC-klient som du är värd på din egen server.", "Then bind-mount to container": "Bind-montera sedan till behållaren", "Then change the VM display to none (vga: none) when the guest is stable.": "Ändra sedan VM-skärmen till ingen (vga: ingen) när gästen är stabil.", "Then change the VM display to none (vga: none) when the system is stable.": "Ändra sedan VM-skärmen till ingen (vga: ingen) när systemet är stabilt.", "Then run this option again:": "Kör sedan det här alternativet igen:", "Then update /etc/fstab on the host with the same options.": "Then update /etc/fstab on the host with the same options.", + "There are extra disks or bind mounts outside the journal; the rootfs is not replaced": "Det finns extra diskar eller binda fästen utanför tidskriften; rootfs ersätts inte", + "There is no temporary container of this operation to keep the current disks": "Det finns ingen tillfällig behållare av denna operation för att hålla de aktuella diskarna", + "There is no verified backup; a modified container is not touched": "Det finns ingen verifierad backup; en modifierad behållare är inte rörd", + "These VMIDs are not free:": "Dessa VMID är inte gratis:", "These are the changes that will be made": "Det är dessa ändringar som kommer att göras", "These interface configurations will be removed": "Dessa gränssnittskonfigurationer kommer att tas bort", "These paths will not be restored live and will be extracted for manual recovery.": "Dessa sökvägar kommer inte att återställas live och kommer att extraheras för manuell återställning.", + "These values are asked during the installation:": "Dessa värden tillfrågas under installationen:", "This CIFS share is mounted with restrictive permissions.": "Denna CIFS-andel är monterad med restriktiva behörigheter.", "This GPU is considered incompatible with GPU passthrough to a VM in ProxMenux.": "Denna GPU anses vara inkompatibel med GPU-genomföring till en virtuell dator i ProxMenux.", "This NFS share is fully restricted — even the host root cannot write to it.": "Denna NFS-resurs är helt begränsad — även värdroten kan inte skriva till den.", @@ -4477,6 +6147,8 @@ "This backup is encrypted.": "Denna säkerhetskopia är krypterad.", "This backup was taken on kernel": "Denna säkerhetskopia togs på kärnan", "This cleanup will:": "Denna rensning kommer:", + "This container belongs to a stack; publish the whole stack": "Denna behållare tillhör en stack; publicera hela stacken", + "This container belongs to a stack; recover the whole stack": "Denna behållare tillhör en stack; återhämta hela stacken", "This container does not have apt-get. NFS client installation only supports Debian/Ubuntu containers.": "Den här behållaren har inte apt-get. NFS-klientinstallation stöder endast Debian/Ubuntu-behållare.", "This container does not have apt-get. Samba client installation only supports Debian/Ubuntu containers.": "Den här behållaren har inte apt-get. Samba-klientinstallationen stöder endast Debian/Ubuntu-behållare.", "This container has no GPU configured. Coral TPU works best alongside hardware video decoding (Quick Sync, VA-API, NVENC) for apps like Frigate.": "Den här behållaren har ingen GPU konfigurerad. Coral TPU fungerar bäst tillsammans med hårdvaruvideoavkodning (Quick Sync, VA-API, NVENC) för appar som Frigate.", @@ -4486,15 +6158,21 @@ "This erases existing metadata.": "Detta raderar befintlig metadata.", "This explicitly marks the container as privileged": "Detta markerar uttryckligen behållaren som privilegierad", "This guarantees that device nodes are available before applying LXC GPU config.": "Detta garanterar att enhetsnoder är tillgängliga innan du använder LXC GPU-konfiguration.", + "This image cannot be installed as it is described:": "Denna bild kan inte installeras eftersom den beskrivs:", + "This image requires the host module": "Denna bild requires värdmodulen", "This installation will:": "Denna installation kommer att:", "This installer will:": "Detta installationsprogram kommer att:", "This interface is configured but doesn't exist physically": "Detta gränssnitt är konfigurerat men existerar inte fysiskt", + "This interface runs on the Proxmox node as root. Open proxmenux-oci.sh on the Proxmox host.": "Detta gränssnitt körs på Proxmox-noden som rot. Öppna proxmenux-oci.sh på Proxmox-värden.", "This is IRREVERSIBLE.": "Detta är IRREVERSIBELT.", "This is a destructive action": "Detta är en destruktiv handling", "This is a simple configuration change": "Detta är en enkel konfigurationsändring", "This is an external community script maintained by": "Detta är ett externt community-skript som underhålls av", "This is an external script that creates a macOS VM in Proxmox VE in just a few steps, whether you are using AMD or Intel hardware.": "Detta är ett externt skript som skapar en macOS VM i Proxmox VE med bara några få steg, oavsett om du använder AMD- eller Intel-hårdvara.", + "This is not a coordinated stack": "Detta är inte en koordinerad stack", + "This is not a valid image reference:": "Detta är inte en giltig bildreferens:", "This is unexpected since credentials were validated.": "Detta är oväntat eftersom autentiseringsuppgifterna validerades.", + "This is what ProxMenux understood from the": "Detta är vad ProxMenux förstod från", "This marks the container as unprivileged": "Detta markerar behållaren som oprivilegierad", "This may be normal for a fresh installation": "Detta kan vara normalt för en ny installation", "This may take a few minutes. Press OK to proceed.": "Detta kan ta några minuter. Tryck på OK för att fortsätta.", @@ -4503,12 +6181,14 @@ "This means Proxmox handles mount lifecycle natively (no manual /etc/fstab needed for NFS/CIFS host storages).": "Detta innebär att Proxmox hanterar monteringslivscykeln naturligt (ingen manuell /etc/fstab behövs för NFS/CIFS-värdlagringar).", "This means the credentials are incorrect.": "Det betyder att inloggningsuppgifterna är felaktiga.", "This might indicate network connectivity issues.": "Detta kan tyda på problem med nätverksanslutning.", + "This monitor uses a privileged LXC, shares processes and network with Proxmox and disables AppArmor in the CT. It uses the IP address and firewall of the host. A compromised image could affect the host; do not expose its web UI to the Internet.": "Denna bildskärm använder en privilegierad LXC, delar processer och nätverk med Proxmox och inaktiverar AppArmor i CT. Den använder IP-adressen och brandväggen i värden. En kompromissad bild kan påverka värden; exponera inte sitt webb-UI på Internet.", "This operation may take several minutes and requires internet connectivity.": "Denna operation kan ta flera minuter och kräver internetanslutning.", "This package was installed by older versions of the ProxMenux Coral installer that placed the M.2 kernel driver on every system, including USB-only setups. It is not needed for Coral USB devices, which use libedgetpu1-std / libedgetpu1-max only.": "Det här paketet installerades av äldre versioner av ProxMenux Coral-installationsprogrammet som placerade M.2-kärndrivrutinen på alla system, inklusive inställningar för endast USB.Det behövs inte för Coral USB-enheter, som endast använder libedgetpu1-std / libedgetpu1-max.", "This passphrase is the ONLY way to access encrypted Borg backups.": "Denna lösenfras är det ENDA sättet att komma åt krypterade Borg-säkerhetskopior.", "This path is already used as a mount point in this container.": "Den här sökvägen används redan som monteringspunkt i den här behållaren.", "This path is not a registered mount point. Use it anyway?": "Denna väg är inte en registrerad monteringspunkt. Använd den ändå?", "This process changes file ownership inside the container": "Denna process ändrar filägande inuti behållaren", + "This profile only supports directory bind mounts": "Denna profil stöder endast katalogbindning", "This release channel is already active.": "Den här releasekanalen är redan aktiv.", "This removes the 'unprivileged: 1' line from the config": "Detta tar bort raden 'oprivilegierad: 1' från konfigurationen", "This removes the storage from Proxmox. The iSCSI target is not affected.": "Detta tar bort lagringen från Proxmox. iSCSI-målet påverkas inte.", @@ -4522,10 +6202,15 @@ "This session is running in the Monitor terminal. Running it from here would cut the connection mid-install and leave the switch in a broken state.": "Den här sessionen körs i Monitor-terminalen. Om du kör den härifrån bryts anslutningen mitt under installationen och läget förblir felaktigt.", "This session is running in the Monitor terminal. Updating from here would restart the Monitor service and cut the connection mid-install, leaving the update in a broken state.": "Denna session körs i Monitor-terminalen. Uppdatering härifrån skulle starta om Monitor-tjänsten och bryta anslutningen mitt i installationen, vilket lämnar uppdateringen i ett trasigt tillstånd.", "This shows the storage type and disk identifier": "Detta visar lagringstyp och diskidentifierare", + "This stack requires replaying specific rootfs adaptations. Coordinated updates are not yet enabled for it.": "Denna stack requires spela specifika rootfs anpassningar. Koordinerade uppdateringar är ännu inte aktiverade för det.", "This state has a high probability of VM startup/reset failures.": "Detta tillstånd har en hög sannolikhet för VM-start/återställningsfel.", "This state indicates a high risk of passthrough failure due to": "Detta tillstånd indikerar hög risk för passthrough-fel pga", + "This template requests the host PID namespace, which has no validated safe LXC translation yet": "Denna mall begär värd PID-namnrymden, som inte har någon validerad säker LXC-översättning ännu", "This tool is designed for systems with AMD GPUs.": "Det här verktyget är designat för system med AMD GPU:er.", "This tool is designed for systems with Intel GPUs.": "Det här verktyget är designat för system med Intel GPU:er.", + "This translator only supports the Nextcloud stack": "Denna översättare stöder endast Nextcloud stack", + "This value is required.": "Detta värde är required.", + "This variant requires the device": "Denna variant requires enheten", "This version does not build against the running kernel.": "Denna version bygger inte mot den körande kärnan.", "This will RESET the ProxMenux Monitor login credentials on this host:": "Detta återställer inloggningsuppgifterna för ProxMenux Monitor på denna värd:", "This will add the mount to /etc/fstab so it persists after reboot.": "Detta kommer att lägga till monteringen till /etc/fstab så att den kvarstår efter omstart.", @@ -4547,13 +6232,17 @@ "This will restart the network service and may cause a brief disconnection. Continue?": "Detta kommer att starta om nätverkstjänsten och kan orsaka en kort frånkoppling. Fortsätta?", "This will take time. Answer prompts carefully - see notes below.": "Detta kommer att ta tid. Besvara uppmaningarna noggrant - se anteckningarna nedan.", "This will upgrade this node to Proxmox VE 9 on Debian Trixie.": "Detta kommer att uppgradera denna nod till Proxmox VE 9 på Debian Trixie.", + "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client.": "Thunderbird är en gratis och öppen källkod personlig informationshanterare främst används som en e-postklient med en kalender och kontaktbok, samt en RSS feed läsare, chattklient och nyhetskund.", "Tick the paths to include in this backup. Press \"Add custom path\" to add a folder or file of your own to the list.": "Markera sökvägarna som ska inkluderas i denna säkerhetskopia. Tryck på \"Lägg till anpassad sökväg\" för att lägga till en egen mapp eller fil till listan.", "Tick the paths to remove (they will not be deleted from disk — only from this list):": "Markera sökvägarna som ska tas bort (de kommer inte att raderas från disken - bara från den här listan):", + "Time is up; Home Assistant OS could not be confirmed as running": "Tid är upp; Home Assistant OS kunde inte bekräftas som körning", "Time settings configured - Timezone:": "Tidsinställningar konfigurerade - Tidszon:", "Time synchronization reset to UTC": "Tidssynkronisering återställd till UTC", + "Timezone": "Timezone", "Tip: Also mount the VirtIO ISO for drivers and guest agent installer": "Tips: Montera även VirtIO ISO för drivrutiner och gästagentinstallatör", "Tip: You can install the QEMU Guest Agent inside the VM with:": "Tips: Du kan installera QEMU Guest Agent inuti den virtuella datorn med:", "Tip: zfs set acltype=posixacl xattr=sa / enables full ACL support.": "Tips: zfs set acltype=posixacl xattr=sa / möjliggör fullt ACL-stöd.", + "Tmpfs size in MiB for": "Tmpfs storlek i MiB för", "To allow LXC write access, change the NFS export on the server to include:": "För att tillåta LXC-skrivåtkomst, ändra NFS-exporten på servern så att den inkluderar:", "To apply it to the current shell now, run:": "För att använda den i den aktuella shellsessionen nu, kör:", "To assign VFs to VMs or LXCs, edit the configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "För att tilldela VF:er till virtuella datorer eller LXC:er, redigera konfigurationen manuellt via Proxmox webbgränssnitt. Den fysiska funktionen förblir bunden till den ursprungliga drivrutinen.", @@ -4568,6 +6257,7 @@ "To pass SR-IOV Virtual Functions to a container, edit the LXC configuration manually via the Proxmox web interface. The Physical Function will remain bound to the native driver.": "För att skicka SR-IOV virtuella funktioner till en behållare, redigera LXC-konfigurationen manuellt via Proxmox webbgränssnitt. Den fysiska funktionen förblir bunden till den ursprungliga drivrutinen.", "To remove partial VM:": "Så här tar du bort partiell virtuell dator:", "To restore": "Att återställa", + "To restore it on another host, keep this file (not included in the vzdump backup):": "För att återställa den på en annan värd, hålla den här filen (ingår inte i vzdump-backupen):", "To revert changes:": "Så här återställer du ändringar:", "To start the VM:": "Så här startar du VM:n:", "To stop:": "För att stoppa:", @@ -4579,12 +6269,17 @@ "To use this share from an LXC, bind-mount it via:": "För att använda denna del från en LXC, bind-montera den via:", "Tool exit code:": "Verktygsutgångskod:", "Tool output:": "Verktygsutgång:", + "Tools": "Verktyg", "Top memory processes in CT": "Topp minnesprocesser i CT", + "Top-level configs, secrets and other global options are not yet supported": "Toppnivåkonfigs, hemligheter och andra globala alternativ stöds ännu inte", + "Top-level volume options are not yet supported": "Toppnivå volymalternativ stöds ännu inte", "Total": "Total", "Total members:": "Totalt antal medlemmar:", "Total routes": "Totalt antal rutter", "Total size:": "Total storlek:", + "Transaction log:": "Transaktionslogg:", "Translation files:": "Översättningsfiler:", + "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, µTP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more.": "Transmission är utformad för enkel, kraftfull användning. Transmission har de funktioner du vill ha från en BitTorrent-klient: kryptering, ett webbgränssnitt, peer-utbyte, magnetlänkar, DHT, μTP, UPnP och NAT-PMP-port vidarebefordran, webseed support, watch kataloger, tracker redigering, globala och per-torrent hastighet gränser, och mer.", "Tried pvesm path and manual detection methods": "Testade pvesm-väg och manuella detekteringsmetoder", "Trust this certificate and save it for scheduled backups?": "Lita på det här certifikatet och spara det för schemalagda säkerhetskopieringar?", "Try Again": "Försök igen", @@ -4592,6 +6287,8 @@ "Try accessing": "Försök komma åt", "Try another archive": "Försök med ett annat arkiv", "Try automatic repair of detected issues": "Prova automatisk reparation av upptäckta problem", + "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources.": "Tvheadend fungerar som en proxyserver: är en TV-streamingserver och inspelare för Linux, FreeBSD och Android som stöder DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP och HDHomeRun som ingångskällor.", + "Twingate Connector for self-hosted server": "Twingate Anslutning för egen värd server", "Two-factor authentication and backup codes will be removed.": "Tvåfaktorsautentisering och reservkoder kommer att tas bort.", "Type": "Typ", "Type the device path EXACTLY to confirm formatting:": "Skriv enhetssökvägen EXAKT för att bekräfta formateringen:", @@ -4600,16 +6297,22 @@ "Type: attached to PVE storage": "Typ: kopplad till PVE-lagring", "Typed value does not match selected disk. Operation cancelled.": "Det angivna värdet matchar inte den valda disken. Åtgärden avbröts.", "UID in CT": "UID i CT", + "UID of the plex user (also owner of the GPU device)": "UID för plex-användaren (även ägare av GPU-enheten)", + "UID that Emby runs as": "UID som Emby körs som", "UPGRADE PROMPTS - RECOMMENDED ANSWERS:": "UPPGRADERINGSUPPGIFTER - REKOMMENDERADE SVAR:", + "UPS monitoring and power outage notification system": "UPS övervaknings- och strömavbrottsmeddelandesystem", "USB Accelerators:": "USB-acceleratorer:", + "USB bus directory": "USB buss katalog", "USB disk target": "USB-diskmål", "USB drives mounted now:": "USB-enheter monterade nu:", "USB libedgetpu1": "USB libedgetpu1", "UUP Dump script not found.": "UUP Dump-skript hittades inte.", "UUp Dump ISO creator Custom": "UUp Dump ISO-skapare Anpassad", + "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer.": "Ubooquity är en gratis, lätt och lättanvänd hemserver för dina serier och e-böcker. Använd den för att komma åt dina filer var som helst, med en surfplatta, en e-läsare, en telefon eller en dator.", "Udev rules for Coral USB devices added and rules reloaded.": "Udev-regler för Coral USB-enheter har lagts till och regler har laddats om.", "Udev rules for Coral USB devices already exist.": "Udev-regler för Coral USB-enheter finns redan.", "Udev rules for Coral USB devices appended and rules reloaded.": "Udev-regler för Coral USB-enheter har lagts till och regler har laddats om.", + "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results.": "UltiMaker Cura är gratis, lätt att använda 3D-utskriftsprogram som litas av miljontals användare. Finjustera din 3D-modell med 400 + inställningar för bästa skiv- och utskriftsresultat.", "Umbrel OS installer script by Helper Scripts\n\nVisit the GitHub repo to learn more, contribute, or support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm": "Umbrel OS installationsskript av Helper Scripts\n\nBesök GitHub-repo för att lära dig mer, bidra eller stödja projektet:\n\nhttps://community-scripts.github.io/ProxmoxVE/scripts?id=umbrel-os-vm", "Unable to detect Proxmox version": "Det gick inte att upptäcka Proxmox-versionen", "Unable to detect Proxmox version.": "Det gick inte att upptäcka Proxmox-versionen.", @@ -4618,6 +6321,10 @@ "Unable to resolve system ZFS pool disks. Aborting.": "Det går inte att lösa system ZFS pooldiskar. Avbryter.", "Unable to resolve system disk topology. Aborting.": "Det gick inte att lösa systemdisktopologin. Avbryter.", "Understand the security implications of privileged containers": "Förstå säkerhetskonsekvenserna av privilegierade containrar", + "Unexpected Proxmox inventory; recovery blocked": "Oväntad Proxmox inventering; återhämtning blockerad", + "Unexpected formatting directory in the new Valkey volume": "Oväntad formateringskatalog i den nya Valkey-volymen", + "Ungoogled Chromium is Google Chromium, sans dependency on Google web services.": "Ungoogled Chromium är Google Chromium, sans beroende av Googles webbtjänster.", + "Unified LLM Fine-Tuning with 100+ Models": "Unified LLM Fine-Tuning med 100+ modeller", "Uninstall Coral drivers and configuration": "Avinstallera Coral drivrutiner och konfiguration", "Uninstall Fail2Ban": "Avinstallera Fail2Ban", "Uninstall Lynis": "Avinstallera Lynis", @@ -4647,6 +6354,10 @@ "Unknown CPU type. IOMMU might not be properly enabled.": "Okänd CPU-typ. IOMMU kanske inte är korrekt aktiverad.", "Unknown CPU vendor. Cannot determine IOMMU parameter.": "Okänd CPU-leverantör. Kan inte bestämma IOMMU-parametern.", "Unknown GPU": "Okänd GPU", + "Unknown adapter role": "Okänd adapterroll", + "Unknown credential service:": "Okänd credential service:", + "Unknown dependency:": "Okänt beroende:", + "Unknown host monitor": "Okänd värdmonitor", "Unknown model": "Okänd modell", "Unknown size": "Okänd storlek", "Unknown storage controller": "Okänd lagringskontroller", @@ -4662,6 +6373,10 @@ "Unmounted:": "Omonterad:", "Unmounting": "Avmontering", "Unmounting disk...": "Avmonterar disk...", + "Unpackerr configured": "Unpackerr konfigurerad", + "Unpackerr has no web interface and extracts nothing until it is pointed at a Starr application. Uncomment the [sonarr.0] or [radarr.0] section in /config/unpackerr.conf inside the container, set its url and api_key, then restart the container.": "Unpackerr har inget webbgränssnitt och extraherar ingenting tills det pekar på en Starr-applikation. Kommentera [sonarr.0] eller [radarr.0] sektionen i /config / unpackerr.conf inuti behållaren, ställa in sin url och api key, sedan starta om behållaren.", + "Unpackerr requires Sonarr, Radarr or Lidarr in this suite": "Unpackerr requires Sonarr, Radarr eller Lidarr i denna svit", + "Unpackerr stopped during its first start": "Unpackerr stannade under sin första start", "Unprivileged": "Oprivilegierad", "Unprivileged Container Access": "Oprivilegierad containeråtkomst", "Unprivileged container": "Oprivilegierad behållare", @@ -4670,15 +6385,69 @@ "Unprivileged containers map their UIDs to high host UIDs (e.g. 100000+), which appear as 'others' on the host filesystem.": "Oprivilegierade behållare mappar sina UID till höga värd-UID (t.ex. 100 000+), som visas som \"andra\" i värdfilsystemet.", "Unprivileged: Limited access (more secure)": "Oprivilegierad: Begränsad åtkomst (säkrare)", "Unreachable": "Otillgänglig", + "Unrecognized Immich adapter": "Okänd Immich adapter", + "Unrecognized adaptation format": "Unrecognized anpassningsformat", + "Unrecognized adaptation recipe": "Okänd anpassning recept", + "Unrecognized dependency order of the stack:": "Okänd beroendeordning av stacken:", + "Unrecognized host monitor profile": "Unrecognized värd monitor profil", + "Unrecognized native configuration": "Unrecognized infödd konfiguration", + "Unrecognized qBittorrent configuration format": "Unrecognized qBittorrent konfigurationsformat", + "Unrecognized stack adapter or role": "Okänd stack adapter eller roll", + "Unrecognized stack adapter:": "Okänd stack adapter:", + "Unrecognized stack structure:": "Okänd stackstruktur:", + "Unrecognized volume definition": "Unrecognized volymdefinition", + "Unresolved variable:": "Olöst variabel:", + "Unsafe OCI archive path": "Osäkra OCI arkiv väg", + "Unsafe dependency contract": "Osäkert beroendeavtal", + "Unsafe dependency hook contract": "Osäkert beroende hook kontrakt", + "Unsafe instance directory": "Unsafe instans katalog", + "Unsafe instance record": "Unsafe instans rekord", + "Unsafe journal or lock file": "Osäker tidskrift eller låsfil", + "Unsafe private configuration path": "Osäkra privata konfigurationsvägar", + "Unsafe qBittorrent configuration path": "Osäker qBittorrent konfigurationsväg", + "Unsafe record": "Osäker rekord", + "Unsafe registry directory": "Osäker registerkatalog", + "Unsafe registry lock": "Osäkra register lås", + "Unsafe rootfs for the capture": "Osäkra rötter för fångsten", + "Unsafe stack assembly": "Osäker stack montering", + "Unsafe volume path": "Osäker volymväg", + "Unsupported CPU allocation mode:": "Unsupported CPU-allokeringsläge:", + "Unsupported GID strategy:": "Ostödd GID-strategi:", + "Unsupported NVIDIA mode:": "Unsupported NVIDIA läge:", + "Unsupported OCI digest:": "Osupporterad OCI smält:", + "Unsupported OCI-LXC AppArmor profile:": "Ostödd OCI-LXC AppArmor-profil:", + "Unsupported OCI-LXC seccomp profile:": "Unsupported OCI-LXC seccomp profil:", "Unsupported Terminal": "Terminal som inte stöds", + "Unsupported architecture:": "Ostödd arkitektur:", + "Unsupported backup compression": "Unsupported backup komprimering", + "Unsupported credential pattern:": "Unsupported credential mönster:", + "Unsupported declarative ostype:": "Ostödd deklarativ ostyp:", + "Unsupported device GID strategy": "Ostödd enhet GID-strategi", + "Unsupported device type:": "Ostödd enhetstyp:", + "Unsupported dynamic NVIDIA capabilities:": "Ostödd dynamisk NVIDIA-kapacitet:", "Unsupported format. Only .ova and .ovf files are supported.": "Format som inte stöds. Endast .ova- och .ovf-filer stöds.", + "Unsupported mount type": "Unsupported Mount Typ", + "Unsupported mount type:": "Unsupported Mount Typ:", + "Unsupported operation": "Unsupported operation", "Unsupported output format:": "Utdataformat som inte stöds:", + "Unsupported post-start configuration:": "Unsupported post-start konfiguration:", + "Unsupported pre-start repair:": "Unsupported pre-start reparation:", + "Unsupported secret generator:": "Ostödd hemlig generator:", + "Unsupported storage mode:": "Ostödd lagringsläge:", + "Unsupported tmpfs options": "Ostödda tmpfs alternativ", + "Unsupported volume options:": "Ostödda volymalternativ:", + "Untrusted or modified NVIDIA hook": "Untrusted eller modifierad NVIDIA hook", + "Unused image removed from the cache:": "Oanvänd bild bort från cache:", + "Unused images removed from the cache:": "Oanvända bilder som tagits bort från cache:", + "Update": "Uppdatering", "Update Available": "Uppdatering tillgänglig", "Update Ceph repository (Only if using Ceph):": "Uppdatera Ceph arkiv (endast om du använder Ceph):", "Update Debian repositories to Trixie:": "Uppdatera Debians arkiv till Trixie:", "Update Export": "Uppdatera export", "Update Lynis to latest version": "Uppdatera Lynis till senaste versionen", "Update NVIDIA in LXC Containers": "Uppdatera NVIDIA i LXC-behållare", + "Update OCI": "Uppdatering OCI", + "Update OCI stack": "Uppdatera OCI stack", "Update PVE enterprise repository (Only if using enterprise):": "Uppdatera Proxmox VE:s företagsarkiv (endast om du använder företagsabonnemang):", "Update Proxmox VE Appliance Manager": "Uppdatera Proxmox VE Appliance Manager", "Update Proxmox package lists": "Uppdatera Proxmox-paketlistor", @@ -4687,15 +6456,26 @@ "Update and upgrade all system packages": "Uppdatera och uppgradera alla systempaket", "Update and upgrade system": "Uppdatera och uppgradera systemet", "Update cancelled by user": "Uppdateringen avbröts av användaren", + "Update completed. Data kept.": "Uppdatering färdig. Data hålls.", "Update completed. Press Enter to continue...": "Uppdatering slutförd. Tryck på Enter för att fortsätta...", + "Update every container of the application": "Uppdatera varje behållare av programmet", "Update kernel to compatible version": "Uppdatera kärnan till kompatibel version", + "Update now?": "Uppdatera nu?", "Update package index:": "Uppdatera paketindex:", + "Update prepared": "Uppdatering förberedd", "Update system to latest PVE 8.4+ (if not done already):": "Uppdatera systemet till senaste PVE 8.4+ (om det inte redan är gjort):", + "Update the image with the saved configuration": "Uppdatera bilden med sparad konfiguration", + "Update the whole stack?": "Uppdatera hela stacken?", "Updated": "Uppdaterad", "Updated sharedfiles group to GID: 101000": "Uppdaterad sharedfiles-grupp till GID: 101000", + "Updated stack checked": "Uppdaterad stack kontrollerad", + "Updated:": "Uppdaterad:", "Updates all Proxmox and Debian packages": "Uppdaterar alla Proxmox- och Debianpaket", "Updates and Packages Commands": "Uppdateringar och paketkommandon", + "Updates are not available yet for this application in this beta": "Uppdateringar är inte tillgängliga ännu för denna ansökan i denna beta", + "Updates are not available yet in this beta for applications that use a privileged container or advanced LXC settings": "Uppdateringar finns ännu inte i denna beta för applikationer som använder en privilegierad behållare eller avancerad LXC-inställningar.", "Updates file is empty or unreadable.": "Uppdateringsfilen är tom eller oläsbar.", + "Updating": "Uppdatering", "Updating APT package lists...": "Uppdaterar APT-paketlistor...", "Updating Debian Bookworm → Trixie in sources.list...": "Uppdaterar Debian Bookworm → Trixie i sources.list...", "Updating Figurine binary...": "Uppdaterar binär figur...", @@ -4727,6 +6507,7 @@ "Upload to PBS is currently: yes. Pick an action:": "Uppladdning till PBS är för närvarande: ja. Välj en åtgärd:", "Upload to PBS: enable, disable or rotate the recovery passphrase": "Ladda upp till PBS: aktivera, inaktivera eller rotera återställningslösenordet", "Uptime and who is logged in": "Upptid och vem som är inloggad", + "Usage:": "Användning:", "Use \"Check test progress\" to see results.": "Använd \"Kontrollera testförlopp\" för att se resultat.", "Use 'Export to file' to save it and inspect manually.": "Använd \"Exportera till fil\" för att spara den och inspektera manuellt.", "Use 'pct restore' / 'qmrestore' to recover their disks from your VM backups.": "Använd 'pct restore' / 'qmrestore' för att återställa sina diskar från dina VM-säkerhetskopior.", @@ -4769,6 +6550,12 @@ "User activity and uptime": "Användaraktivitet och drifttid", "User chose not to remove NetworkManager": "Användaren valde att inte ta bort NetworkManager", "User chose to exit for manual backup creation.": "Användaren valde att avsluta för att skapa manuell säkerhetskopia.", + "User name for the SSH login": "Användarnamn för SSH inloggning", + "User name of the administrator of the web interface": "Användarnamn för administratören av webbgränssnittet", + "User name of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)": "Användarnamnet på den avskrivna Flowise-applikationsinloggningen (läs endast av Flowise-versioner före 3.0.1)", + "User of the AdGuard Home that receives the settings": "Användare av AdGuard Home som tar emot inställningarna", + "User of the main AdGuard Home": "Användare av AdGuard Home", + "User-friendly WebUI for LLMs (Formerly Ollama WebUI)": "Användarvänlig WebUI för LLMs (tidigare Ollama WebUI)", "Username": "Användarnamn", "Username (e.g. root@pam or user@pbs!token):": "Användarnamn (t.ex. root@pam eller user@pbs!token):", "Username and password": "Användarnamn och lösenord", @@ -4782,6 +6569,8 @@ "Using advanced configuration": "Använder avancerad konfiguration", "Using default Proxmox logo...": "Använder standard Proxmox-logotyp...", "Using existing encryption key:": "Använda befintlig krypteringsnyckel:", + "Using the image verified by the transaction": "Använda bilden verifierad av transaktionen", + "Using the verified image from the cache": "Använda den verifierade bilden från cache", "Utilities": "Verktyg", "Utilities Installation Menu": "Utilities Installationsmeny", "Utilities Menu": "Verktygsmeny", @@ -4789,6 +6578,9 @@ "Utilities and Tools": "Verktyg och verktyg", "Utilities installation completed": "Installationen av verktyg är klar", "Utilities installed by ProxMenux have been removed": "Verktyg som installerats av ProxMenux har tagits bort", + "VA-API driver": "VA-API förare", + "VA-API render device": "VA-API render enhet", + "VA-API video acceleration": "VA-API videoacceleration", "VFIO device IDs removed from /etc/modprobe.d/vfio.conf": "VFIO-enhets-ID:n borttagna från /etc/modprobe.d/vfio.conf", "VFIO modules configured in /etc/modules": "VFIO-moduler konfigurerade i /etc/modules", "VFIO modules configured.": "VFIO-moduler konfigurerade.", @@ -4797,6 +6589,7 @@ "VFIO orphans cleared and initramfs rebuilt — next boot will free the GPU.": "VFIO föräldralösa enheter rensades och initramfs återuppbyggda — nästa uppstart kommer att frigöra GPU:n.", "VFIO orphans cleared but initramfs rebuild failed; check /var/log/proxmenux logs.": "VFIO föräldralösa enheter rensades men återuppbyggnaden av initramfs misslyckades; kontrollera /var/log/proxmenux loggar.", "VLAN": "VLAN", + "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices.": "VLC media Spelare är en fri och öppen källkod multimediaspelare och ram som levererar pålitlig prestanda över flera enheter.", "VM": "VM", "VM Conflict Policy": "VM-konfliktpolicy", "VM ID": "VM ID", @@ -4824,17 +6617,28 @@ "VM started": "VM startade", "VM stopped": "VM stannade", "VM:": "VM:", + "VMID (empty = next free)": "VMID (tom = nästa gratis)", "VMID in use": "VMID används", "VMID must be a number.": "VMID måste vara ett nummer.", "VMID of the Borg server LXC on": "VMID för Borg-servern LXC på", + "VMID of the Rclone OCI container": "VMID för Rclone OCI container", "VMs to destroy:": "virtuella datorer att förstöra:", "VMs, LXCs, network, /etc/pve, users, cron, packages, drivers, ProxMenux state, etc.": "VM, LXC, nätverk, /etc/pve, användare, cron, paket, drivrutiner, ProxMenux-tillstånd, etc.", + "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server.": "VS Code är en integrerad utvecklingsmiljö som utvecklats av Microsoft. Denna behållare kör hela skrivbordsapplikationen, för en webbinbyggd version se Code Server.", + "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft’s editor VS Code.": "VSCodium är en gemenskapsdriven, fritt licensierad binär distribution av Microsofts redaktör VS-kod.", "Valid backups for all VMs/CTs": "Giltiga säkerhetskopior för alla virtuella datorer/CT:er", "Validating Proxmox 9 repositories (checking 'proxmox-ve' candidate)...": "Validerar Proxmox 9-förråd (kontrollerar 'proxmox-ve'-kandidat)...", "Validating credentials with server": "Validerar autentiseringsuppgifter med server", "Validating disk safety...": "Validerar disksäkerhet...", + "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)": "Valideringsmetod: http (port 80 forwarded) eller dns (DNS-leverantörsplugin)", + "Value for": "Värde för", + "Variable name": "Variabelt namn", + "Variables": "Variables", + "Variables the installation asks for:": "Variabler som installationen begär:", "Verbose pool status": "Utförlig poolstatus", "Verification": "Kontroll", + "Verified": "Verifierad", + "Verified by ProxMenux": "Verifierad av ProxMenux", "Verify IOMMU group for PCI device": "Verifiera IOMMU-gruppen för PCI-enhet", "Verify Options > OS Type — currently set to:": "Verifiera alternativ > OS-typ — för närvarande inställd på:", "Verify PVE version (must be 8.4.1 or newer):": "Verifiera PVE-version (måste vara 8.4.1 eller nyare):", @@ -4850,12 +6654,16 @@ "Verifying Ceph packages availability...": "Verifierar tillgängligheten av Ceph-paket...", "Verifying all utilities status": "Verifierar alla verktygs status", "Verifying disk accessibility in CT": "Verifierar disktillgänglighet i CT", + "Verifying the backups...": "Verifiera backups...", + "Verifying the image integrity...": "Verifiera bildintegriteten...", "Version": "Version", "Version Change Detected": "Versionsändring upptäckt", "Version info not available": "Versionsinformation är inte tillgänglig", "Version:": "Version:", "Version: Auto-negotiation (NFSv3/NFSv4)": "Version: Auto-negotiation (NFSv3/NFSv4)", "Versions shown belong to maintained NVIDIA branches that list your GPU PCI ID and are new enough to build against the running kernel. DKMS compilation is the final validation. The recommended version keeps the current branch, or uses the NVIDIA Production Branch on a fresh install.": "Versioner som visas tillhör underhållna NVIDIA-grenar som listar ditt GPU PCI-ID och är tillräckligt nya för att bygga mot den körande kärnan. DKMS kompilering är den slutliga valideringen. Den rekommenderade versionen behåller den aktuella grenen eller använder NVIDIA Production Branch på en nyinstallation.", + "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML.": "Videoacceleration och objektdetektering är oberoende val; installatören skriver inte kamera eller detektor YAML.", + "Video transcoding acceleration": "Videoöverskridande acceleration", "View CIFS Mounts (pvesm + fstab)": "Visa CIFS-fästen (pvesm + fstab)", "View Current Exports": "Visa aktuell export", "View Current Mounts": "Visa aktuella monteringar", @@ -4871,6 +6679,7 @@ "View raw VM configuration file": "Visa rå VM-konfigurationsfil", "View restore plan": "Visa återställningsplan", "View self-test log": "Se självtestlogg", + "View status": "Visa status", "VirtIO (advanced - high performance)": "VirtIO (avancerat - hög prestanda)", "VirtIO ISO not found after selection.": "VirtIO ISO hittades inte efter val.", "VirtIO ISO selection cancelled.": "VirtIO ISO-val avbröts.", @@ -4886,10 +6695,19 @@ "Virtual display normalized to vga: std (compatibility)": "Virtuell skärm normaliserad till vga: std (kompatibilitet)", "Virtual display set to": "Virtuell skärm inställd på", "Virtual interface (normal)": "Virtuellt gränssnitt (normalt)", + "Virtual whiteboard for sketching hand-drawn like diagrams": "Virtuell whiteboard för att skissa handritade som diagram", "Virtualization": "Virtualisering", "Visit https://osx-proxmox.com for more information.": "Besök https://osx-proxmox.com för mer information.", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:": "Besök webbplatsen för att upptäcka fler skript, hålla dig uppdaterad med de senaste uppdateringarna och stödja projektet:", "Visit the website to discover more scripts, stay updated with the latest updates, and support the project:\n\nhttps://community-scripts.github.io/ProxmoxVE": "Besök webbplatsen för att upptäcka fler skript, hålla dig uppdaterad med de senaste uppdateringarna och stödja projektet:\n\nhttps://community-scripts.github.io/ProxmoxVE", + "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies.": "Vivaldi är en norsk freeware, cross-platform webbläsare med en inbyggd e-postklient som utvecklats av Vivaldi Technologies.", + "Volume configuration cancelled": "Volymkonfiguration inställd", + "Volume options are not yet supported": "Volymalternativ stöds ännu inte", + "Volume size in GB": "Volymstorlek i GB", + "Volumes attached": "Volymer fästa", + "Volumes prepared for the first start:": "Volymer förberedda för första början:", + "Volumes shared between services are not yet supported": "Volymer som delas mellan tjänster stöds ännu inte", + "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code.": "Vscodium-web är en community-driven, fritt licensierad binär distribution av den avlägsna webbkomponenten i Microsofts redaktör VS-kod.", "Vulnerability detection": "Sårbarhetsdetektering", "WARNING": "VARNING", "WARNING — This backup contains paths that are risky to restore on a running system:": "VARNING — Denna säkerhetskopia innehåller sökvägar som är riskabla att återställa på ett körande system:", @@ -4912,15 +6730,41 @@ "WARNING: You are about to remove this Proxmox storage:": "VARNING: Du är på väg att ta bort denna Proxmox-lagring:", "WARNING: You are about to remove this disk mount:": "VARNING: Du håller på att ta bort det här skivmonteringen:", "WARNING: this will ERASE EVERYTHING on the disk.": "VARNING: detta raderar ALLT på disken.", + "WEB UI to manage WireGuard VPN.": "WEB UI hanterar WireGuard VPN.", "WILL BE PERMANENTLY ERASED.": "KOMMER ATT RADERAS PERMANENT.", + "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency.": "WPS Office är en lätt, funktionsrik omfattande kontorsvit med hög kompatibilitet. Som en praktisk och professionell kontorsprogramvara tillåter WPS Office dig att redigera filer i Writer, Presentation, Spreadsheet och PDF för att förbättra din arbetseffektivitet.", "Wait for each node to complete before starting next": "Vänta tills varje nod är klar innan du börjar nästa", + "Waiting for Home Assistant OS...": "Väntar på Home Assistant OS", + "Waiting for the FUSE mount:": "Väntar på FUSE Mount:", + "Waiting for the application to respond...": "Väntar på att ansökan ska svara...", + "Waiting for the initial Jellyfin configuration...": "Väntar på den ursprungliga Jellyfin-konfigurationen.", + "Waiting for the network address...": "Väntar på nätverksadressen...", + "Waiting for the password of the application...": "Väntar på lösenordet för programmet...", + "Waiting for the temporary password...": "Väntar på det tillfälliga lösenordet...", "Warning": "Varning", "Warning: Auth key should start with 'tskey-'": "Varning: Auth key bör börja med 'tskey-'", "Warning: Disk Images on CIFS": "Varning: Diskbilder på CIFS", "Warning: Limited PCI Reset Support": "Varning: Begränsat stöd för PCI-återställning", "Warning: both VMs have autostart enabled (onboot=1).": "Varning: båda virtuella datorerna har autostart aktiverad (onboot=1).", "Warnings": "Varningar", + "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents.": "WeKnora är en LLM-driven ram utformad för djup dokumentförståelse och semantisk hämtning, särskilt för hantering av complex, heterogena dokument.", + "Web UI": "Web UI", + "Web UI 1": "Web UI 1", + "Web UI 2": "Web UI 2", + "Web UI password": "Web UI lösenord", + "Web UI user": "Web UI-användare", + "Web access": "Web access", + "Web address of the AdGuard Home that receives the settings (e.g. http://192.168.1.3)": "Webbadress för AdGuard Home som tar emot inställningarna (t.ex. http://192.168.1.3)", + "Web address of the main AdGuard Home, whose settings are copied (e.g. http://192.168.1.2)": "Webbadressen för AdGuard Home, vars inställningar kopieras (t.ex. http://192.168.1.2)", + "Web interface to manage devices running Tasmota firmware.": "Webbgränssnitt för att hantera enheter som kör Tasmota firmware.", + "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes).": "WebCord kan sammanfattas som ett paket av säkerhets- och sekretesshärdningar, Discord-funktioner reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, interna sidor och wrapped https://discord.com sida, utformad för att överensstämma med ToS så mycket som möjligt (eller dölja de förändringar som kan bryta mot det från Discords ögon).", + "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels.": "Webgrabplus är en multi-site inkrementell xmltv epg grabber. Det samlar in tv-programguide data från utvalda tvguide webbplatser för dina favoritkanaler.", + "Webservers & Proxies": "Webservers & Proxies", "Website": "Webbplats", + "Webstation is a web native emulation focused LXQt desktop based on Ubuntu.": "Webstation är en web inhemsk emulering fokuserad LXQt skrivbord baserat på Ubuntu.", + "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser.": "Webtop - Alpine, Ubuntu, Fedora och Arch-baserade behållare som innehåller fullständiga skrivbordsmiljöer i officiellt stödda smaker tillgängliga via alla moderna webbläsare.", + "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent.": "Weixin (WeChat) är en snabbmeddelande, sociala medier och mobil betalning app utvecklad av Tencent.", + "What cannot be translated:": "Vad som inte kan översättas:", "What do you want to do?": "Vad vill du göra?", "What would you like to do?": "Vad skulle du vilja göra?", "When asked to select a disk, click Load Driver and load the VirtIO drivers.": "När du uppmanas att välja en disk klickar du på Ladda drivrutin och laddar VirtIO-drivrutinerna.", @@ -4932,28 +6776,46 @@ "Where do you want to mount the Samba share?": "Var vill du montera Samba-delen?", "Where is the OVA/OVF file located?": "Var finns OVA/OVF-filen?", "Where to mount inside container?": "Var ska man montera inuti behållaren?", + "Where to store": "Var att lagra", "While the server allows guest listing, no shares are actually accessible without authentication.": "Medan servern tillåter gästlistning är inga delningar faktiskt tillgängliga utan autentisering.", + "Wikijs A modern, lightweight and powerful wiki app built on NodeJS.": "Wikijs En modern, lätt och kraftfull wiki app byggd på NodeJS.", "Will be configured now": "Kommer att konfigureras nu", "Windows Installation Options": "Windows installationsalternativ", "Windows path:": "Windows sökväg:", + "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles.": "WineGUI är en användargränssnittsvänlig Wine Manager som ger en grafisk frontend för att skapa och hantera vinflaskor.", "Wipe all — erase partitions + metadata": "Rensa alla — radera partitioner + metadata", "Wipe all — remove partitions + metadata": "Rensa alla — ta bort partitioner + metadata", "Wipe old signatures and partition table (DESTRUCTIVE):": "Torka gamla signaturer och partitionstabell (DESTRUKTIV):", "Wiping existing partition table...": "Rensar befintlig partitionstabell...", "Wiping partitions and metadata...": "Rensar partitioner och metadata...", + "WireGuard Easy web interface": "WireGuard Easy webbgränssnitt", + "WireGuard® is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry.": "WireGuard® är en extremt enkel men ändå snabb och modern VPN som använder toppmodern kryptografi. Det syftar till att vara snabbare, enklare, smalare och mer användbar än IPsec, samtidigt som man undviker den massiva huvudvärken. Det avser att vara betydligt mer performant än OpenVPN. WireGuard är utformad som ett allmänt ändamål VPN för att köra på inbyggda gränssnitt och superdatorer lika, passar för många olika omständigheter. Initialt släppt för Linux-kärnan är det nu cross-platform (Windows, macOS, BSD, iOS, Android) och allmänt distribuerbar. Det är för närvarande under tung utveckling, men redan kan det anses vara den säkraste, enklaste att använda och enklaste VPN-lösningen i branschen.", "Wired NICs in backup missing on target:": "Trådbundna nätverkskort i säkerhetskopia saknas på målet:", + "Wireshark is the world’s foremost and widely-used network protocol analyzer. It lets you see what’s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998.": "Wireshark är världens främsta och allmänt använda nätverksprotokollanalysator. Det låter dig se vad som händer på ditt nätverk på en mikroskopisk nivå och är de facto (och ofta de jure) standard över många kommersiella och ideella företag, myndigheter och utbildningsinstitutioner. Wireshark utveckling frodas tack vare de frivilliga bidragen från nätverksexperter runt om i världen och är fortsättningen av ett projekt som startades av Gerald Combs 1998.", + "With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopped.": "Med dns validering, DNSPLUGIN variabel namn leverantör plugin. Den avancerade installationen ber om det, annars lägg till linjen lxc.miljö. runtime: DNSPLUGIN till /etc/pve/lxc/.conf med behållaren stannade.", + "With dns validation, write the provider credentials in /config/dns-conf/.ini inside the container and restart it.": "Med dns validering, skriv leverantören credentials i /config/dns-conf/.ini inuti behållaren och starta om den.", + "With http validation, port 80 of the router must be forwarded to port 80 of this container.": "Med http validering måste port 80 av routern vidarebefordras till port 80 av denna behållare.", "With warnings": "Med varningar", "Without Function Level Reset (FLR), passthrough is not considered reliable": "Utan funktionsnivååterställning (FLR) anses passthrough inte vara tillförlitlig", "Without a usable reset path, passthrough reliability is poor and VM": "Utan en användbar återställningsväg är tillförlitligheten för genomkoppling dålig och VM", + "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom.": "Wolfenstein: Blade of Agony är en story-driven WWII skytt inspirerad av Wolfenstein och Doom.", + "Workflow automation tool": "Workflow automation verktyg", "Working directory:": "Arbetskatalog:", "Works with LVM, ZFS, and BTRFS storage types": "Fungerar med LVM, ZFS och BTRFS lagringstyper", + "Worth knowing before installing it:": "Värt att veta innan du installerar den:", "Would you like to continue in passthrough-only mode? The libedgetpu APT install will be skipped, the Coral device will still be visible inside the container (e.g. /dev/apex_0), and you can install the runtime yourself or use an app container that bundles it (e.g. the Frigate Docker image).": "Vill du fortsätta i endast passthrough-läge? Installationen av libedgetpu via APT hoppas över, Coral-enheten förblir synlig i behållaren (t.ex. /dev/apex_0), och du kan installera runtime-miljön själv eller använda en appbehållare som inkluderar den (t.ex. Docker-avbildningen för Frigate).", "Would you like to see the current": "Vill du se strömmen", "Write access confirmed for user:": "Skrivåtkomst bekräftad för användare:", "Write access confirmed.": "Skrivåtkomst bekräftad.", "Write access test FAILED for user:": "Skrivåtkomsttestet MISSLYCKades för användare:", "Write access verified for user:": "Skrivåtkomst verifierad för användare:", + "Write the value it produces instead.": "Skriv värdet den producerar istället.", + "Wrong SHA-256 in": "Fel SHA-256 i", + "Wrong inherited registry lock": "Fel ärvt registerlås", "Wrong passphrase": "Fel lösenfras", + "Wrong size in": "Fel storlek i", + "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support.": "Xbackbone är en enkel, självhäftad, lätt PHP filhanterare som stöder omedelbar delning verktyg ShareX och * NIX system. Det stöder uppladdning och visning av bilder, GIF, video, kod, formaterad text och filnedladdning och uppladdning. Också ha ett webb-UI med multianvändarhantering, tidigare uppladdningar historia och sökstöd.", + "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS.": "Yaak är en stationär API-klient för att organisera och genomföra REST, GraphQL och gRPC-förfrågningar. Den är byggd med Tauri, Rust och ReactJS.", "Yes": "Ja", "Yes, upload": "Ja, ladda upp", "Yes: set a recovery passphrase now; the encrypted key envelope is uploaded with every backup.": "Ja: ställ in en återställningslösenfras nu; det krypterade nyckelkuvertet laddas upp med varje säkerhetskopia.", @@ -4984,6 +6846,9 @@ "You should now be able to access the Proxmox web interface.": "Du bör nu kunna komma åt Proxmox webbgränssnitt.", "You will need a Tailscale auth key from: https://login.tailscale.com/admin/settings/keys": "Du behöver en Tailscale-autentiseringsnyckel från: https://login.tailscale.com/admin/settings/keys", "Your Coral USB device and its runtime (libedgetpu1) will NOT be affected.": "Din Coral USB-enhet och dess körtid (libedgetpu1) kommer INTE att påverkas.", + "Your machine learning Env work with Jupyter Lab": "Din maskininlärning Env arbetar med Jupyter Lab", + "Your next YouTube media manager": "Din nästa YouTube Media Manager", + "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics.": "Your_spotify är en egen värd program som spårar vad du lyssnar och erbjuder dig en instrumentpanel för att utforska statistik om det! Den består av en webbserver som undersöker Spotify API då och då och en webbapplikation där du kan utforska din statistik.", "ZFS ARC config removed (kernel defaults will apply on reboot)": "ZFS ARC-konfigurationen togs bort (kärnans standardinställningar gäller vid omstart)", "ZFS ARC maximum configured:": "ZFS ARC maximalt konfigurerat:", "ZFS ARC optimization completed": "ZFS ARC-optimering slutförd", @@ -5011,9 +6876,17 @@ "ZFS storage added successfully to Proxmox!": "ZFS-lagring lades till Proxmox!", "ZFS tools not found. Install zfsutils-linux and retry.": "ZFS-verktyg hittades inte. Installera zfsutils-linux och försök igen.", "ZFS:": "ZFS:", + "ZNC web interface": "ZNC webbgränssnitt", + "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design.": "Zen Browser är en gratis och öppen källkod fork av Mozilla Firefox med fokus på integritet, anpassningsförmåga och design.", "Zero all data — partition table preserved, data wiped": "Noll alla data – partitionstabellen bevarad, data raderas", "Zero all data — partition table preserved": "Noll alla data – partitionstabellen bevarad", "Zeroing partition": "Nollställ partition", + "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC.": "Znc är en IRC nätverk bouncer eller BNC. Det kan lossa klienten från den faktiska IRC-servern och även från valda kanaler. Flera kunder från olika platser kan ansluta till ett enda ZNC-konto samtidigt och visas därför under samma smeknamn på IRC.", + "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research.": "Zotero är ett gratis, lättanvänt verktyg för att hjälpa dig att samla, organisera, annotera, citera och dela forskning.", + "a device it asks for cannot be translated:": "En enhet som den begär kan inte översättas:", + "a value is required": "Ett värde är required", + "aMule WebUI (password only, no username)": "aMule WebUI (lösenord, inget användarnamn)", + "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule.": "aMule är en multiplattformskund för ED2K-fildelningsnätverket och baserat på windowsklienten eMule. aMule startade i augusti 2003, som en fork av xMule, som är en fork av lMule.", "active VF(s)": "aktiva VF(s)", "active VFs": "aktiva VF:er", "active Virtual Functions. Changing its driver binding would destroy every VF.": "aktiva virtuella funktioner. Att ändra dess drivrutinsbindning skulle förstöra varje VF.", @@ -5035,20 +6908,24 @@ "apex group still has members; left in place:": "apex-gruppen har fortfarande medlemmar; kvar på plats:", "apex kernel module not loaded on host. Run \"Install Coral on Host\" first or the container will not see /dev/apex_0.": "apex-kärnmodulen är inte laddad på värden. Kör \"Installera Coral på värden\" först, annars ser behållaren inte /dev/apex_0.", "appears to be part of a": "verkar vara en del av en", + "apply requires the OCI archive of the resolved image": "tillämpa requires OCI-arkivet på den lösta bilden", "applying minimal banner patch": "tillämpa minimal banner patch", "apt cache refreshed.": "apt cache uppdaterad.", "apt-get exited": "apt-get exited", "apt-get update returned warnings. Continuing anyway; check": "apt-get update returnerade varningar. Fortsätter ändå; kontrollera", "as": "som", + "assembling": "montering", "automatically. Install it manually inside the container.": "automatiskt. Installera den manuellt inuti behållaren.", "automatically. Reboot LXC to fully release.": "automatiskt. Starta om LXC för att släppa helt.", "available for LXC bind-mounts via 'LXC Mount Manager'": "tillgänglig för LXC bind-mounts via \"LXC Mount Manager\"", "available in this same GPU and TPU menu.": "tillgänglig i samma GPU- och TPU-meny.", "backup at /etc/fstab.proxmenux.bak": "säkerhetskopia på /etc/fstab.proxmenux.bak", "ban": "förbjuda", + "belongs to another OCI installation": "tillhör en annan OCI-installation", "blocking issue(s).": "blockeringsproblem.", "btrfs — Proxmox dir storage (snapshots, compression)": "btrfs — Proxmox dir-lagring (ögonblicksbilder, komprimering)", "btrfs — snapshots and compression": "btrfs — ögonblicksbilder och komprimering", + "budge is an open source 'budgeting with envelopes' personal finance app.": "budge är en öppen källkod \"budgeting med kuvert\" personlig finans app.", "builds against kernel": "bygger mot kärnan", "but it does not match the one used to create the backup. Replace it with the correct keyfile from the source host and retry.": "men den matchar inte den som användes för att skapa säkerhetskopian. Ersätt den med rätt nyckelfil från källvärden och försök igen.", "bytes": "bytes", @@ -5056,29 +6933,52 @@ "chmod 1777 + setfacl o::rwx (applied on the NFS share from this host)": "chmod 1777 + setfacl o::rwx (tillämpas på NFS-andelen från denna värd)", "chmod failed — NFS server may be restricting changes from root": "chmod misslyckades — NFS-servern kan begränsa ändringar från root", "chown/chmod failed — likely unprivileged CT against host bind mount. Falling back to ACL.": "chown/chmod misslyckades — sannolikt oprivilegierad CT mot värdbindningsmontering. Faller tillbaka till ACL.", + "containers": "behållare", + "containers of": "behållare av", "content:": "innehåll:", + "copyparty web interface": "copyparty webbgränssnitt", "could not be compiled for kernel": "kunde inte kompileras för kärnan", + "could not validate NVIDIA; exit code": "kan inte validera NVIDIA; exitkod", + "cpuunits must be between 8 and 10000": "cpuunits måste vara mellan 8 och 10000", + "custom": "anpassade", + "custom dependency commands are not yet supported": "Anpassade beroendekommandon stöds ännu inte", + "custom path(s) saved.": "anpassade sökvägar har sparats.", + "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them.": "darktable är en öppen källkod fotografering arbetsflöde ansökan och rå utvecklare. Ett virtuellt ljusbord och mörkrum för fotografer. Den hanterar dina digitala negativ i en databas, låter dig se dem genom en zoombar lighttable och gör att du kan utveckla råa bilder och förbättra dem.", + "ddclient starts with the example configuration and updates nothing yet. Write your provider, login and domains in /config/ddclient.conf inside the container, then restart it.": "ddclient börjar med exemplet konfiguration och uppdaterar ingenting ännu. Skriv din leverantör, inloggning och domäner i /config/ddclient.conf inuti behållaren och starta om den.", "default": "standard", "delete the credentials file (if any)": "radera autentiseringsfilen (om någon)", "delete the matching line from /etc/fstab": "ta bort den matchande raden från /etc/fstab", "descriptor + VMDK files": "descriptor + VMDK-filer", + "device(s) added to VM": "enhet(er) har lagts till i VM", "devices": "enheter", + "devices (dynamic runtime)": "enheter (dynamisk runtime)", "did not become ready. Skipping.": "blev inte redo. Hoppa över.", + "digiKam: Professional Photo Management with the Power of Open Source": "digiKam: Professionell fotohantering med kraften i öppen källkod", "disk(s) added to CT": "disk(ar) har lagts till i CT", "disk(s) added to VM": "disk(ar) har lagts till VM", + "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems.": "diskover är en öppen källkod filsystem indexer som använder Elasticsearch för att indexera och hantera data över heterogena lagringssystem.", "disks present": "diskar finns", "dkms autoinstall did not activate:": "dkms autoinstall aktiverades inte:", "dkms.conf generated.": "dkms.conf genereras.", + "docker run command": "docker kör kommando", + "docker run command of the application": "docker kör kommando av ansökan", "does not exist on this host. Path not added.": "finns inte på denna värd. Sökväg har inte lagts till.", "does not exist. Exiting.": "finns inte. Avslutar.", + "doplarr_rs starts from the example configuration and connects to nothing. Write the token of your Discord bot in discord_token in /config/config.toml inside the container.": "doplarr_rs startar från exemplet konfiguration och ansluter till ingenting. Skriv token av din Discord bot i discord token i /config/config.toml inuti behållaren.", + "downloaded Compose file": "Ladda ner Compose-fil", "dpkg still reports unfinished package work; review": "dpkg rapporterar fortfarande oavslutat paketarbete;recension", + "driver components": "Förarkomponenter", "driver:": "drivrutin:", + "e.g.": "t.ex.", + "empty = generate": "Tom = generera", "exFAT (portable: Windows/Linux/macOS)": "exFAT (bärbar: Windows/Linux/macOS)", "exFAT tools installed successfully.": "exFAT-verktyg installerade framgångsrikt.", "ext4 — Proxmox dir storage (recommended)": "ext4 — Proxmox dir-lagring (rekommenderas)", "ext4 — recommended, most compatible": "ext4 — rekommenderas, mest kompatibel", "fail2ban-client could not communicate with the server": "fail2ban-client kunde inte kommunicera med servern", "fail2ban-client successfully communicated with the server": "fail2ban-klient kommunicerade med servern", + "failed": "Misslyckades", + "failed with exit code": "Misslyckades med exit code", "failed:": "misslyckades:", "feranick fork unreachable. Falling back to google/gasket-driver...": "feranick-forken kan inte nås. Faller tillbaka på google/gasket-driver...", "feranick/gasket-driver cloned (actively maintained, kernel 6.12+ ready).": "feranick/gasket-driver klonad (aktivt underhållen, kärna 6.12+ redo).", @@ -5092,6 +6992,7 @@ "for this policy and may fail after first use or on subsequent VM starts.": "för denna policy och kan misslyckas efter första användning eller vid efterföljande VM-starter.", "formatted as": "formaterad som", "found": "hittade", + "free": "Gratis gratis", "from Proxmox web interface (you will be asked)": "från Proxmox webbgränssnitt (du kommer att bli tillfrågad)", "from container": "från container", "from the GPUs and Coral-TPU menu first, then run this option again.": "från GPU:er och Coral-TPU-menyn först, kör sedan det här alternativet igen.", @@ -5102,6 +7003,7 @@ "gasket-dkms has been fully removed from this system.": "gasket-dkms har tagits bort helt från detta system.", "gasket-dkms is still reported by dpkg in state:": "gasket-dkms rapporteras fortfarande av dpkg i tillstånd:", "gawk installed": "gawk installerad", + "go2rtc WebUI": "Go2rtc WebUI", "google/gasket-driver cloned (fallback — will apply local patches).": "google/gasket-driver cloned (reserv — kommer att tillämpa lokala patchar).", "gpg not found; trying apt-key fallback": "gpg hittades inte; försöker apt-key fallback", "gzip replaced with pigz wrapper successfully": "gzip ersattes med pigz wrapper framgångsrikt", @@ -5109,10 +7011,14 @@ "has a different MAC than the backup — update any DHCP static reservation": "har en annan MAC än säkerhetskopian — uppdatera alla statiska DHCP-reservationer", "has a new MAC": "har en ny MAC", "has only": "har bara", + "health and persistence profile not yet defined": "hälsa och uthållighetsprofil ännu inte definierad", + "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers.": "HiSHtory är en bättre skalhistoria. Det lagrar din skalhistoria i sitt sammanhang (vilken katalog du körde kommandot i, oavsett om det lyckades eller misslyckades, hur lång tid det tog, etc.). Detta lagras lokalt och end-to-end krypterad för att synkronisera till alla dina andra datorer.", + "host directory": "värd katalog", "host fstab only (not registered as Proxmox storage)": "host endast fstab (ej registrerad som Proxmox-lagring)", "hostpci entries for all IOMMU group devices": "hostpci-poster för alla IOMMU-gruppenheter", "hostpci entries for selected GPU functions (full IOMMU group will be enforced after reboot)": "hostpci-poster för utvalda GPU-funktioner (full IOMMU-grupp kommer att tillämpas efter omstart)", "hour(s)": "timme(r)", + "https if the image serves TLS": "https om bilden tjänar TLS", "iSCSI Content Type": "iSCSI-innehållstyp", "iSCSI Daemon (iscsid): RUNNING": "iSCSI Daemon (iscsid): KÖR", "iSCSI Daemon (iscsid): STOPPED": "iSCSI Daemon (iscsid): STOPPAT", @@ -5129,16 +7035,23 @@ "iSCSI storage provides raw block devices for VM disk images.": "iSCSI-lagring tillhandahåller råblockenheter för VM-diskavbildningar.", "iSCSI tools installed": "iSCSI-verktyg installerade", "iftop usage": "iftop användning", + "image cache on": "bild cache på", + "image itself": "bild själv", "imported:": "importerade:", "in CT": "i CT", + "in backups": "i backups", + "incompatible qBittorrent schema": "Inkompatibelt qBittorrent schema", + "individual template is blocked": "Enskild mall är blockerad", "initramfs updated": "initramfs uppdaterad", "initramfs updated.": "initramfs uppdaterad.", + "installed": "installerad", "installed but command not immediately available": "installerat men kommandot är inte tillgängligt omedelbart", "installed correctly and available": "installerad korrekt och tillgänglig", "installed in CT": "installerad i CT", "installed inside CT": "installerad inuti CT", "installed successfully.": "installerat framgångsrikt.", "installed.": "installerad.", + "installing": "Installera", "intel-gpu-tools installed successfully": "intel-gpu-tools installerades framgångsrikt", "intel-gpu-tools is already installed:": "intel-gpu-tools är redan installerat:", "intel-gpu-tools is up to date": "intel-gpu-tools är uppdaterad", @@ -5169,7 +7082,11 @@ "is not configured as machine type q35.": "är inte konfigurerad som maskintyp q35.", "is not in the patch.sh supported list. The patch may no-op or fail; review keylase/nvidia-patch README before continuing.": "finns inte i listan som stöds av patch.sh. Patchen kanske inte fungerar eller misslyckas; granska keylase/nvidia-patch README innan du fortsätter.", "is not supported by the official Google libedgetpu APT repository.": "stöds inte av det officiella Google libedgetpu APT-förrådet.", + "is one of the": "är en av", "is referenced in the following stopped VM(s)/CT(s):": "refereras till i följande stoppade VM(ar)/CT(er):", + "it asks for the network of the host; the container gets its own address instead": "ber om nätverket av värden; behållaren får sin egen adress istället", + "it publishes no other architecture": "publicerar ingen annan arkitektur", + "it uses the Compose option": "Den använder alternativet Compose", "journald MaxLevelStore is adequate for auth logging": "journald MaxLevelStore är tillräcklig för autentiseringsloggning", "journald drop-in created: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf": "journald drop-in skapad: /etc/systemd/journald.conf.d/proxmenux-loglevel.conf", "journald log level restored": "loggad loggnivå återställd", @@ -5193,26 +7110,41 @@ "kexec-tools installed successfully": "kexec-tools installerades framgångsrikt", "kexec-tools is already installed": "kexec-tools är redan installerat", "kexec-tools is not installed or already removed.": "kexec-tools är inte installerat eller redan borttaget.", + "layers": "Lager", "legacy .link file(s) to the ProxMenux-managed format": "äldre .link-fil(er) till det ProxMenux-hanterade formatet", "log2ram completely removed from system": "log2ram helt borttagen från systemet", "manually inside the container before starting it.": "manuellt inuti behållaren innan du startar den.", "manually inside the container.": "manuellt inuti behållaren.", "maximum performance": "maximal prestanda", "may be closed — trying discovery anyway...": "kan vara stängd — försöker hitta ändå...", + "melonDS aims at providing fast and accurate Nintendo DS emulation.": "melonDS syftar till att ge snabb och accurate Nintendo DS emulering.", + "members:": "medlemmar:", + "minimum": "minimum minimum", "missing": "saknad", "mkfs.btrfs not found. Install btrfs-progs and retry.": "mkfs.btrfs hittades inte. Installera btrfs-progs och försök igen.", "more": "mer", + "motionEye web interface": "motionEye webbgränssnitt", "mount.cifs command not found after installation.": "mount.cifs-kommandot hittades inte efter installationen.", "mount.nfs command not found after installation.": "mount.nfs-kommandot hittades inte efter installationen.", + "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone.": "mstream är en personlig musikströmningsserver. Du kan använda mStream för att strömma din musik från din hemdator till vilken enhet som helst. Det finns mobilappar tillgängliga för både Android och iPhone.", + "must contain a valid numeric UID for the GPU": "måste innehålla ett giltigt numeriskt UID för GPU", + "needed": "behövs", + "needs a privileged LXC": "behöver en privilegierad LXC", + "needs a relaxed AppArmor or seccomp profile": "behöver en avslappnad AppArmor eller seccomp-profil", + "needs stack review": "behov stack review", "never": "aldrig", + "next free": "Nästa gratis", + "next free block": "Nästa fria block", "nftables not available - using iptables ban action": "nftables inte tillgängliga - använder iptables förbudsåtgärd", "no": "inga", "no (kdf=none, not needed)": "nej (kdf=ingen, behövs inte)", "no (no escrow blob — set a recovery passphrase to enable recovery)": "nej (ingen escrow blob – ställ in en återställningslösenfras för att aktivera återställning)", + "no declarative value": "Inget deklarativt värde", "no passphrase": "ingen lösenfras", "no password": "inget lösenord", "no_root_squash": "no_root_squash", "non-ProxMenux .tar archive(s) in this path": "icke-ProxMenux .tar-arkiv(er) i den här sökvägen", + "not available yet": "Inte tillgänglig ännu", "not found.": "hittades inte.", "not installed": "inte installerat", "not reliable on this hardware due to the following limitations": "inte tillförlitlig på denna hårdvara på grund av följande begränsningar", @@ -5229,27 +7161,39 @@ "of free disk space.": "ledigt diskutrymme.", "older firmware may increase passthrough instability": "äldre firmware kan öka passthrough-instabiliteten", "oldest driver offered:": "äldsta drivrutin som erbjuds:", + "on": "på", "on SSD/NVMe pools that support discard": "på SSD/NVMe-pooler som stöder kassering", + "one of its services declares no image": "En av dess tjänster förklarar ingen bild", + "one of its services is not written as a service": "En av dess tjänster är inte skriven som en tjänst", "openssl encryption failed.": "openssl-kryptering misslyckades.", "openssl is not installed — cannot create recovery copy. Install openssl and retry.": "openssl är inte installerat — kan inte skapa återställningskopia. Installera openssl och försök igen.", + "optional": "Valfritt", + "optional dependencies are not yet supported": "valfria beroenden stöds ännu inte", "or format it manually using external tools.": "eller formatera det manuellt med hjälp av externa verktyg.", + "or none": "eller ingen", "or use the ProxMenux LXC Mount Manager.": "eller använd ProxMenux LXC Mount Manager.", "orphan iface lines, no impact on restore": "föräldralösa iface-linjer, ingen inverkan på återställning", "other .tar archive(s) — not ProxMenux host backups (e.g. PVE vzdump or unrelated tarballs).": "andra .tar-arkiv – inte ProxMenux-värdsäkerhetskopior (t.ex. PVE vzdump eller orelaterade tarballs).", "packages (this may take a few minutes)...": "paket (detta kan ta några minuter)...", + "packages.": "paket.", "parent PF:": "förälder PF:", "partition(s). Partition table preserved.": "partition(er). Partitionstabell bevarad.", + "pasted Compose file": "Tidigare Compose Fil", "paths for next boot (/etc/pve, guests, drivers, ...)": "sökvägar för nästa start (/etc/pve, gäster, drivrutin, ...)", "pct exec authorization failed": "pct exec auktorisering misslyckades", "pct push failed. Check log:": "pct push misslyckades. Kontrollera logg:", "pending (reboot required to enumerate full group)": "väntar (omstart krävs för att räkna upp hela gruppen)", + "phpMyAdmin is installed with arbitrary server connections enabled: the login page has a Server field where the address of the MySQL or MariaDB server is entered, together with its user and password.": "phpMyAdmin installeras med godtyckliga serveranslutningar aktiverade: inloggningssidan har ett serverfält där adressen till MySQL eller MariaDB-servern är inmatad, tillsammans med dess användare och lösenord.", "pigz configuration completed": "pigz-konfigurationen är klar", "pigz enabled in vzdump configuration": "pigz aktiverad i vzdump-konfiguration", "pigz installed successfully": "pigz installerades framgångsrikt", "pigz removed": "pigz borttagen", "pigz wrapper script created": "pigz wrapper-skript skapat", + "playit.gg has to claim this agent before it forwards anything. The agent prints a one-time claim link on the container console and keeps it there until the link is opened.": "playit.gg måste hävda denna agent innan den vidarebefordrar någonting. Agenten skriver ut en engångsregellänk på containerkonsolen och håller den där tills länken öppnas.", "port": "hamn", "portmapper/rpcbind has been disabled": "portmapper/rpcbind har inaktiverats", + "private network assigned automatically": "privat nätverk som tilldelats automatiskt", + "privileged LXC": "privilegierad LXC", "proxmox-backup-client reported:": "proxmox-säkerhetskopia-client rapporterade:", "proxmox-boot-tool refreshed": "proxmox-boot-tool uppdaterad", "pve-enterprise.list update skipped (no change)": "pve-enterprise.list-uppdateringen hoppade över (ingen förändring)", @@ -5261,10 +7205,22 @@ "pvesm not found.": "pvesm hittades inte.", "pvesm path failed, trying manual detection...": "pvesm sökväg misslyckades, försöker manuell upptäckt...", "pvesm status failed": "pvesm-status misslyckades", + "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web.": "pyLoad är en gratis och öppen källkod nedladdningshanterare skriven i Python och utformad för att vara extremt lätt, lättföränderlig och fullt hanterbar via webben.", + "pyLoad web interface": "PyLoad webbgränssnitt", + "qBittorrent WebUI password (user: admin)": "qBittorrent WebUI lösenord (användare: admin)", + "qBittorrent already has a configuration; it is not overwritten": "qBittorrent har redan en konfiguration; den är inte överskriven", + "qBittorrent configured": "qBittorrent konfigurerad", + "qBittorrent did not apply the category:": "qBittorrent tillämpade inte kategorin:", + "qBittorrent did not apply the download paths": "qBittorrent tillämpade inte nedladdningsvägarna", + "qBittorrent requires a non-empty password": "qBittorrent requires ett icke-tomt lösenord", + "qBittorrent: authenticated access to the preferences could not be verified": "qBittorrent: Autentiserad åtkomst till preferenserna kan inte verifieras", + "qBittorrent: invalid login response or missing session cookie": "qBittorrent: ogiltigt inloggningssvar eller saknad session cookie", "raw USB disk — no filesystem (will be FORMATTED)": "rå USB-disk — inget filsystem (kommer att formateras)", + "read-only": "Read-only", "reboot-quick alias added": "omstart-snabb alias lagt till", "reboot-quick alias is already configured": "omstart-snabb-alias är redan konfigurerat", "recommended": "rekommenderad", + "recovering": "Återhämtning", "remapped users": "ommappade användare", "remove the (now-empty) directory if possible": "ta bort den (nu tomma) katalogen om möjligt", "removed from Proxmox": "borttagen från Proxmox", @@ -5280,11 +7236,14 @@ "rpcbind could not be disabled completely": "rpcbind kunde inte inaktiveras helt", "rpcbind service and socket have been disabled and stopped": "rpcbind-tjänsten och socket har inaktiverats och stoppats", "rpcbind units were not found; no changes were made": "rpcbind-enheter hittades inte;inga ändringar gjordes", + "rsnapshot starts with the default configuration, which backs up /data into /.snapshots. Edit /config/rsnapshot.conf inside the container to set your own backup points, snapshot root and retention intervals.": "rsnapshot börjar med standardkonfigurationen, som backar upp / data i /.snapshots. Redigera /config / rsnapshot.conf inuti behållaren för att ställa in dina egna backuppunkter, snapshot root och retention intervaller.", "running": "spring", + "runs in": "springs in", "safe paths now (configs, packages, /etc, /root, ...)": "säkra sökvägar nu (konfigurationer, paket, /etc, /root, ...)", "same MAC": "samma MAC", "seconds (default)": "sekunder (standard)", "see log:": "se logg:", + "selected by default": "valt som standard", "selected path(s):": "valda sökvägar:", "server": "server", "server IP or hostname:": "server-IP eller värdnamn:", @@ -5292,6 +7251,7 @@ "servers found on the network.": "servrar som finns på nätverket.", "servers found.": "servrar hittades.", "sha256sum not found. Cannot verify Borg binary.": "sha256summen hittades inte. Kan inte verifiera Borg binär.", + "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++.": "shadPS4 är en tidig PlayStation 4 emulator för Windows, Linux och macOS skriven i C++.", "showmount command is not working properly.": "showmount-kommandot fungerar inte korrekt.", "showmount command not found after installation.": "showmount-kommandot hittades inte efter installationen.", "single portable archive": "enda bärbart arkiv", @@ -5307,6 +7267,7 @@ "started successfully.": "började framgångsrikt.", "started.": "startade.", "startup/restart errors are likely.": "start-/omstartsfel är troliga.", + "staticfiles volume size in GB": "Staticfiles volymstorlek i GB", "stop source VM first": "stoppa käll-VM först", "stopped": "stannade", "storage yet.": "lagring ännu.", @@ -5316,9 +7277,16 @@ "suggested:": "föreslog:", "switch_gpu_mode.sh was not found.": "switch_gpu_mode.sh hittades inte.", "sysfs ROM dump failed — trying ACPI VFCT table...": "sysfs ROM-dump misslyckades — försöker ACPI VFCT-tabell...", + "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools.": "syslog-ng låter dig flexibelt samla in, analysera, klassificera, skriva och korrelera loggar från hela din infrastruktur och lagra eller dirigera dem för att logga analysverktyg.", "systemctl restart networking failed:": "systemctl omstart av nätverk misslyckades:", "systemd OnCalendar expression": "systemd OnCalendar-uttryck", + "the API key was not generated on the first start": "API-nyckeln genererades inte i första början", + "the container has its own address, so the port Docker published on the host is not needed": "behållaren har sin egen adress, så porten Docker som publiceras på värden behövs inte", + "the qBittorrent schema is not available": "qBittorrent schemat är inte tillgängligt", + "this configuration needs the device": "Denna konfiguration behöver enheten", "this distribution": "denna fördelning", + "tmpfs size in MB for": "Tmpfs storlek i MB för", + "tmpfs size too small for": "Tmpfs storlek för liten för", "to": "till", "to CT": "till CT", "to VM": "till VM", @@ -5327,6 +7295,12 @@ "to sharedfiles group": "till sharedfiles-gruppen", "total": "total", "umount the path if currently mounted": "ommontera sökvägen om den för närvarande är monterad", + "unprivileged LXC": "Oprivilegierad LXC", + "unsupported credential generator": "ostödd credential generator", + "unsupported dependency condition": "ostödda beroendeförhållanden", + "unsupported external credential or boolean": "ostödd extern credential eller boolean", + "unsupported variable": "Ostödd variabel", + "updating": "Uppdatering", "updating NVIDIA userspace libs": "uppdaterar NVIDIA userspace libs", "user packages missing — will be installed automatically:": "användarpaket saknas — kommer att installeras automatiskt:", "users": "användare", @@ -5337,12 +7311,19 @@ "vfio-pci IDs configured": "vfio-pci ID:n konfigurerade", "vfio-pci IDs in /etc/modprobe.d/vfio.conf": "vfio-pci ID i /etc/modprobe.d/vfio.conf", "vzdump backup speed optimization completed": "Optimeringen av vzdump-säkerhetskopieringen har slutförts", + "wallabag builds its links from the address given during the installation. If it does not match the address of the container, edit lxc.environment.runtime: SYMFONY__ENV__DOMAIN_NAME in /etc/pve/lxc/.conf with the container stopped, and start it again.": "wallabag bygger sina länkar från den adress som ges under installationen. Om den inte matchar behållarens adress, redigera lxc.environment. runtime: SYMFONY ENV DOMAIN NAME in /etc/pve/lxc/.conf with the container stopped, and start it again.", + "wallabag listens on port 80 of the container and stores its data in SQLite.": "wallabag lyssnar på port 80 av behållaren och lagrar sina data i SQLite.", + "wallabag web interface": "wallabag webbgränssnitt", "was": "var", "was installed, but the kernel reports:": "installerades, men kärnan rapporterar:", + "when finished": "När den är färdig", "will rebind the GPU to vfio-pci on the next reboot, breaking the driver that is about to be installed.": "kommer att binda om GPU:n till vfio-pci vid nästa omstart, vilket bryter drivrutinen som är på väg att installeras.", "wipefs failed on": "wipefs misslyckades", "with": "med", + "with Proxmox": "med Proxmox", + "with prefix, e.g.": "med prefix, t.ex.", "with the password you provided.": "med lösenordet du angav.", + "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems.": "xemu är en fri och öppen källkod som emulerar den ursprungliga Microsoft Xbox spelkonsolen, så att människor kan spela sina ursprungliga Xbox-spel på Windows, MacOS och Linux-system.", "xfs — Proxmox dir storage (large files and VMs)": "xfs — Proxmox dir-lagring (stora filer och virtuella datorer)", "xfs — better for large files": "xfs — bättre för stora filer", "years old": "år gammal", diff --git a/oci/PACKAGE-CONTENTS.md b/oci/PACKAGE-CONTENTS.md new file mode 100644 index 00000000..9eb884e1 --- /dev/null +++ b/oci/PACKAGE-CONTENTS.md @@ -0,0 +1,13 @@ +# ProxMenux OCI package + +Runtime distribution only: + +- `proxmenux-oci.sh`: installer entry point. +- `catalog/`: index, application templates, curated definitions and overlays. +- `src/`: menu and deployment orchestrator. +- `remote/`: native Proxmox OCI/LXC installation and lifecycle helpers. +- `schemas/`: catalog schema. +- `requirements.txt`: Python dependencies. +- `README.md`: operational documentation. + +Development-only tests, virtual environments, laboratory evidence, caches and legacy root-level `*-oci.json` files are intentionally excluded. diff --git a/oci/README.md b/oci/README.md new file mode 100644 index 00000000..4c4871e3 --- /dev/null +++ b/oci/README.md @@ -0,0 +1,484 @@ +# ProxMenux OCI laboratory + +Prototype that converts official image documentation and discovered Docker +Compose definitions into one ProxMenux JSON template per distribution or +deployment profile, then optionally installs reviewed images as native Proxmox +VE OCI LXC containers. + +This repository is a laboratory. Generated templates are not considered +compatible merely because conversion succeeded. + +## Design + +- `catalog/index.json` is the lightweight application listing. +- `catalog/apps/.json` is the canonical template for one image. +- `schemas/oci-template.schema.json` validates generated templates. +- `container_contract` preserves the official Compose contract and source text. +- `catalog_ui` contains neutral store metadata and attributes each image to its + actual image repository or publisher. +- `first_run` records detected web endpoints, documented default credentials, + and supported methods for recovering credentials generated at runtime. +- `proxmox` contains only native OCI/LXC translation and documented adaptations. +- A multi-image application remains one catalog entry and one user-facing + installation. Its `compose_stack` creates one native OCI LXC per service, + allocates a private network automatically and orchestrates dependencies. +- Discovery catalogs are never recorded as image authors or repositories in + public templates. +- Imported store text keeps only `en_US` and `es_ES`; when Spanish is missing, + `es_ES` falls back to English instead of retaining unused source locales. +- Distributions and deployment profiles remain separate entries. For example, + `nextcloud` is the LinuxServer image, `nextcloud-official` is the official + single-image deployment and `nextcloud-stack` is the laboratory-derived + Nextcloud, PostgreSQL and Redis profile. The name `nextcloud-aio` is reserved + for the distinct upstream All-in-One project. +- Hardware choices share one application image: LinuxServer `jellyfin` offers + CPU, VA-API, AMD/OpenCL, Intel/OpenCL and NVIDIA in its installer profile. + OpenCL choices use official LinuxServer mods, not separate image variants. + See [Jellyfin GPU laboratory](docs/jellyfin-gpu-lab.md) for tested capabilities, + native OCI device permissions and the distinction between VA-API, OpenCL + and Vulkan tone mapping. +- Curated laboratory profiles can replace a duplicate discovery identifier. + `jdownloader` uses the maintained JDownloader 2 image from jlesage and + replaces the less clear discovered name `jdownloader2`; these are not two + different generations of JDownloader. +- The curated `frigate` profile replaces the generic discovered deployment and + preserves the AMD VA-API and OpenVINO CPU choices. The installer keeps the + official rolling `stable` image intact; package substitutions require a + separate validation on stable hardware and are not enabled automatically. +- The curated `paperless-ngx` profile translates the official PostgreSQL + Compose into three native LXCs: Paperless-ngx, PostgreSQL and Valkey. Private + state uses backed-up Proxmox volumes, while `consume` and `export` can use + either managed volumes or host directories shared with scanners and other + applications. +- The curated `rclone` profile uses a two-phase workflow. Installation starts + the official authenticated WebUI so the user can create and authorize a + private remote. The separate `rclone-mount` action then validates that remote, + enables the official FUSE mount and publishes distinct read/write and + recursively read-only paths for other native LXCs. + +## Catalog maintenance + +The catalog is generated rather than written by hand. `proxmenux-oci.sh` is the +tool that produces and inspects it, and it is what a contributor adding an +application runs: + +```bash +./proxmenux-oci.sh sync +./proxmenux-oci.sh list --filter sonarr +./proxmenux-oci.sh generate sonarr +./proxmenux-oci.sh show sonarr +GITHUB_TOKEN=github_pat_xxx ./proxmenux-oci.sh generate-all +``` + +`generate` writes one application's template from its published recipe; `show` +prints what the installation would create, which is the fastest way to see +whether a translation came out right before installing anything. + +On Debian and Proxmox the launcher reuses the distribution packages +`python3-yaml` and `python3-jsonschema` when they are present, so nothing is +installed into the system Python. Where they are absent, install them with APT +before generating the catalog. + +`GITHUB_TOKEN` is optional and only raises the public API rate limit, which the +full `generate-all` pass reaches. Never commit a token; `.env` files are +ignored. + +## Safety boundary + +Automatic installation is allowed only when every Compose behavior has a +reviewed and tested native Proxmox translation. Multi-image applications are +modeled as one installation; generic stacks remain blocked until their native +multi-LXC orchestrator is implemented and validated, while curated Immich, +Nextcloud and Paperless-ngx stacks have dedicated orchestrators. Privileged +mode and relaxed AppArmor/seccomp profiles require an explicit high-risk +confirmation. Security requirements are classified by capability instead of +assuming that every Compose `privileged: true` is an image requirement: + +- `requires_privileged_lxc` is reserved for a reviewed profile whose native + LXC adaptation has proved that broad privilege is necessary. +- `optional_privileged_lxc` records an upstream compatibility request. The + installer keeps the LXC unprivileged by default and offers the broader mode + only after explicit confirmation. +- GPU, USB and serial hardware are passed as individual Proxmox devices and do + not imply a privileged LXC. +- Required Compose AppArmor/seccomp relaxations need explicit confirmation. + Relaxations marked `#optional` remain disabled by default and are offered as + individual compatibility choices instead of being labeled as mandatory. +- `pid: host` is tracked separately as host PID namespace access. It remains + blocked until a safe native LXC translation is validated; it must never be + mislabeled as ordinary GPU access or silently promoted to privileged mode. + +Before creating an LXC, the tool prints a redacted deployment plan and requires +the exact confirmation `INSTALAR`. Remote credentials are handled by normal SSH; +they are never placed in a template or command argument. + +Image downloads run in a pseudo-terminal when `script` is available, allowing +Skopeo layer progress to remain visible. The final result lists the detected IP, +one complete URL per documented web endpoint, and any public default login from +the upstream LinuxServer `Application Setup` section. Non-web service ports are +not presented as browser URLs. Public default passwords should be changed after +the first login. + +Some images do not publish a static password. For example, qBittorrent prints a +temporary password for `admin` during startup. When this behavior is explicitly +documented upstream, the installer enables a short-lived native LXC console log +for the first boot, extracts the password, removes the log and its temporary +configuration, and prints the credential in the terminal. The generated secret +is never written back to the reusable catalog JSON or to Proxmox metadata. + +When run as root directly on a Proxmox node, destination `auto` selects local +execution and does not open an SSH connection back to the same node. Outside +Proxmox, specify `root@` using `--host` or the interactive prompt; +the installer never assumes a laboratory address. + +## Native Proxmox behavior + +Proxmox VE 9 imports OCI `Entrypoint`, `Cmd`, `Env`, `User`, `WorkingDir` and +`StopSignal` when `pct create` extracts the OCI archive. The installer preserves +that behavior and only overlays values explicitly present in Compose. + +Proxmox VE 9.2 cannot extract the tested OCI archive directly as a privileged +LXC. When a reviewed profile explicitly requires privileges, the installer +imports it with the standard unprivileged idmap, converts ownership before the +first start while preserving extended attributes, and only then switches the +native LXC configuration to privileged mode. This conversion is never applied +without the user's high-risk confirmation. + +Compose `stop_grace_period` is recorded as the timeout for ProxMenux-managed +`pct shutdown` operations. It is not mapped to Proxmox `startup.down`, because +that field controls sequencing between guests rather than the CT stop timeout. + +Persistent paths can be installed as: + +- Proxmox-managed `mpN` volumes with the image's original container path and + `backup=1` by default. +- Existing host bind mounts for data intentionally shared with other LXCs. +- Omitted mounts only when LinuxServer marks them optional. + +When a host bind is selected, the installer proposes +`/mnt/oci-shared//`. Missing data directories are created +automatically with ownership mapped for the unprivileged LXC; existing +directories are never re-owned. System files and runtime sockets are excluded +from automatic creation. + +Hardware devices keep their host path and obtain their numeric GID directly +from the selected host device; ProxMenux does not assume fixed `video` or +`render` group IDs. NVIDIA profiles additionally require a working host driver +and NVIDIA Container Toolkit. At installation time, `nvidia-container-cli` +supplies the current device, binary, firmware and driver-library inventory; +ProxMenux translates it to native Proxmox `devN` entries and read-only LXC file +mounts, including the compatibility links expected by the image. No driver +version or library list is hardcoded in the template. + +Compose `network_mode: host` means the network namespace of the dedicated LXC, +not the Proxmox host network. `bridge` and `default` use the same native LXC +model because no Docker NAT layer exists. Recognized `cap_add` values are +checked against the LXC capability model instead of using `lxc.cap.keep`, which +would accidentally remove other capabilities. WireGuard images that request +`SYS_MODULE` preload and verify the `wireguard` kernel module on the Proxmox +host while keeping the LXC unprivileged. + +Namespaced IPv4/IPv6 Compose sysctls are written to an LXC include profile in +`/etc/pve/lxc/.proxmenux-sysctls`; this is required because Proxmox 9.2 +does not accept arbitrary network sysctl keys directly in the managed CT +configuration. The profile is stored on the Proxmox cluster filesystem and is +removed on a failed installation. Cross-host backup/restore validation remains +pending, like the versioned NVIDIA host-driver mounts. + +`seccomp:unconfined` uses a valid empty LXC denylist profile, never `/dev/null`. +`apparmor:unconfined` is applied with its native LXC directive, and +`no-new-privileges` maps to `lxc.no_new_privs`. Docker's `label:disable` and +logging drivers remain source metadata because the native LXC runtime has no +Docker SELinux label or Docker log object. Compose supplementary groups are +resolved from the image's `/etc/group` and applied through `lxc.init.groups`. + +The current laboratory implementation records versioned NVIDIA driver paths in +the LXC configuration. After updating the NVIDIA host driver, those mounts must +be regenerated before affected LXCs are started. Automatic profile refresh is +part of the future update lifecycle and is not yet implemented. + +For multi-image applications, users choose only normal deployment values such +as storage destinations, frontend network and shared data paths. ProxMenux must +reserve all VMIDs atomically, create the dependency network, assign internal +addresses and service aliases, generate shared secrets, create every LXC and +start dependencies in health-checked order. Private configuration and database +paths use Proxmox-managed volumes with backup enabled; only intentionally shared +user data uses host bind mounts. + +Validated multi-LXC installers attach an official Proxmox hookscript to the +main LXC. ProxMenux only creates this lifecycle configuration during +installation; no ProxMenux daemon remains running. On every later `pre-start`, +Proxmox starts any stopped dependency in declared order and waits for its +healthcheck before allowing the main LXC to start. Stopping the main LXC does +not implicitly stop its dependencies, so a restart cannot interrupt a database +or cache before the application has shut down. + +Host bind paths selected by the user are created when missing and need an +independent backup policy; no shared path is created unless `host-bind` was +chosen. The default LXC is unprivileged and uses an 8 GB thin-provisioned +rootfs. + +## Validation lifecycle + +Generated templates start as `generated-unvalidated`. Promotion requires: + +1. Clean installation. +2. Application health check. +3. Restart persistence. +4. Proxmox backup and restore. +5. Image replacement with persistent volumes preserved. +6. Review of every platform adaptation and unsupported feature. + +The mini changelog comes from the LinuxServer README `Versions` section. At +installation, the architecture-specific registry digest and image labels are +recorded back into the local app JSON for future update comparisons. + +## Generic multi-LXC installer + +The generic stack compiler now handles an application with official PostgreSQL +and Redis/Valkey dependencies. It reuses `install_oci.sh` for image verification +and native OCI import. Docmost and Blinko are the first eligible catalog entries; +real installation and restart validation of this new driver remain pending. +Each other stack records its unresolved semantics in `proxmox.generic_stack_review`. + +The compiler resolves generated secrets once per stack and binds PostgreSQL URL +credentials to the named database service. The installer allocates a private +network, writes service aliases, creates data volumes with the image's initial +files and ownership, and registers the Proxmox dependency hook before starting +the main LXC. It replaces example localhost public URLs with the assigned LAN IP +after a successful first boot and performs a graceful restart to apply them. +Using a stable DHCP lease or a domain is necessary if that address later changes. +For the rolling official PostgreSQL image, legacy `/var/lib/postgresql/data` +mounts become `/var/lib/postgresql`, preserving its versioned data directory. + +Allocation is serialized among ProxMenux installers on the node; native `pct` +creation checks still arbitrate collisions with concurrent external operations. +A failed generic stack keeps completed LXCs and their volumes for diagnosis. +After a partial failure, inspect these resources before starting a new install. +No claim of atomic cross-cluster allocation or coordinated backup is made. +The hook snippet and `/etc/pve/priv/proxmenux-stack-.json` are host artifacts; +back them up separately and remap VMIDs/recreate the bridge when restoring a +whole stack on another host. A normal LXC backup alone does not package these +host artifacts. This restoration workflow is still pending validation. + +### Suite Arr (selectable media stack) + +The `suite-arr` catalog entry offers Prowlarr, Sonarr, Radarr, qBittorrent, +Lidarr, Bazarr, SABnzbd, Seerr and Unpackerr. The first four are checked by +default. A separate single-choice menu offers Jellyfin (default), Plex, Emby +or no media server. Only selected services are created. +It reuses individual image templates, including the official Seerr and Unpackerr +images. Each `/config` (Seerr: `/app/config`) is a separate managed Proxmox volume +with backup enabled. Media applications share a user-selected host directory at +`/data`; media is not included +in container backups. New media directories receive mapped UID/GID 1000 ownership; +existing directories and their permissions are not recursively changed. + +Web applications have LAN access and a private address for inter-service APIs. +Unpackerr has only a private address and no WebUI. Its initial start is deferred +until the selected Arr apps have generated API keys, then official `UN_*` +environment variables are persisted in its LXC config. Subsequent starts are independent and controlled by Proxmox onboot on each LXC. +Save the LXC configuration alongside application-volume backups. +The installer reads generated API keys, creates media root folders, and connects +selected Sonarr/Radarr instances to Prowlarr using its API schema. It does not +patch application binaries, add indexers, download content, disable authentication, +or install a VPN. First-login Arr authentication, indexers and quality profiles +still require user configuration. If qBittorrent is not selected, the download +client also needs manual configuration. + +The shared tree is `downloads/{tv,movies,music,incomplete,usenet,usenet-incomplete}` +and `media/{movies,series,music}`. Subtitles reside beside their media files. +SABnzbd's new persistent config sets both incomplete and complete download paths +under `/data`; no download content defaults to the container rootfs. +Jellyfin retains its 4 cores, 4096 MB RAM, 16 GB config volume and hardware selector. +Other media servers retain their image's hardware options. Accounts/library setup, +Seerr and Bazarr connections, Lidarr profiles/root folder/download client, SABnzbd +Usenet credentials/client connections and subtitle providers still require user +configuration. These integrations are not claimed as automatic. Gluetun/VPN is +explicitly deferred, not installed or advertised as protecting traffic. + +Seerr preserves the upstream non-root image user. Its documented security settings +map to `lxc.no_new_privs: 1` and `lxc.cap.keep: none` after clearing inherited drop +entries. All-capability removal is incompatible with requested additional capabilities. + +With qBittorrent selected, the user chooses the password for `admin`. The installer +copies the image's own default configuration into its new `/config` volume and +sets the upstream PBKDF2-SHA512 password hash; existing config is never overwritten. +No image files are patched. The API configures `/data/downloads/`, its `incomplete` +subdirectory, and selected `tv`/`movies` categories. Sonarr/Radarr download clients +are tested before saving. All apps use the same paths, with no remote path mappings. +Login accepts the legacy HTTP 200/`Ok.`/`SID` response or the qBittorrent 5.2 +HTTP 204/empty-body/`QBT_SID_` response. A protected preferences request must +also succeed before any settings are changed. The password is masked in deployment +previews and returned in the final terminal credentials; protect terminal output. +It is stored hashed in qBittorrent and by the Arr apps in their private databases. + +Suite Arr has no primary container, dependency hook or lifecycle contract. The +installer starts each selected application once to perform initial setup; that +one-time sequence does not couple future starts or stops. The user's onboot +choice is applied to each LXC individually. True dependent stacks (Immich, +Nextcloud and generic multi-image stacks) retain their existing hook lifecycle. +Failure preserves created containers/data. The suite remains unvalidated by a +complete real installation; tests cover compilation, independent startup and APIs. + +### Common dependency profiles + +The generic stack compiler also supports official `mariadb`, `mongo` and +`getmeili/meilisearch` dependencies. It uses MariaDB's bundled +`healthcheck.sh --connect --innodb_initialized`, MongoDB's `mongosh` ping, and +Meilisearch's `/health` endpoint. Missing implicit data volumes are materialized +as backed-up Proxmox volumes at their official paths; dependencies stay on the +private network with no LAN interface. The Proxmox host can still reach them. + +Per-stack `stack_environment_overrides` and `stack_generators` in catalog overlays +correct imported metadata without editing upstream images. Monica gets a 32-byte +base64 application key and a boolean random-root-password switch. Linkwarden gets +boolean credential login and a storage path matching its persisted volume. +Petio's setup should use MongoDB host `mongo`, port `27017`; Plex credentials remain +user-provided. No third-party API credentials are fabricated. + +These profiles enable `monica-official`, `petio` and `linkwarden` as installable, +not runtime-validated. Latest image tags remain selected; compatibility between +current upstream releases, initial application setup and restart/restore need +real laboratory testing. In particular, current MongoDB images require compatible +CPU instructions. Profiles do not grant LAN access to database services, enable +unattended upgrades or promise that a new database major version can reuse an old +data directory without migration. + +### RomM and optional external credentials + +RomM now uses the common MariaDB profile and binds `DB_PASSWD` to the same +installation-generated value as `MARIADB_PASSWORD`. Root credentials remain +independent. The overlay declares optional IGDB, ScreenScraper and SteamGridDB +credential groups via `stack_optional_environment`. They are requested only if +selected; skipped providers have no fabricated credentials. Entered secrets are +preserved literally (including dollar signs) and hidden in deployment summaries. +All five RomM data/configuration volumes default to backed-up private storage; +users may explicitly select shared host directories. + +RomM remains installable without runtime validation. The hook starts dependencies +before the main application but does not implement Compose's propagation of an +explicit dependency restart to RomM. Upstream latest versions, first-run setup +and restart/restore behavior still need real installation testing. + +### Teable and authenticated Redis + +Teable uses three OCI LXC services: the app, PostgreSQL and Redis. The overlay +replaces the malformed imported Redis argument with a reviewed three-argument +`redis-server --requirepass` command, preserving the image entrypoint. The Redis +server password, `REDISCLI_AUTH` and Teable's Redis URI share one generated value. +Only this explicit authenticated Redis command profile is accepted; arbitrary +custom dependency commands remain blocked. + +Redis healthchecks now require an exact `PONG` response. The hook does not embed +the password: the authenticated check obtains `REDISCLI_AUTH` inside the LXC. +Credentials remain readable to administrators in native runtime configuration. +A Compose internal network's `name` is treated as a label, not a fixed Proxmox +bridge name; external networks and custom IPAM remain unsupported by this driver. +Teable is installable but not yet runtime-validated; tests include a fake Redis CLI +that returns authentication errors with exit code zero, plus successful PONG. + +### LinuxServer multi-image definitions and Kimai + +The README converter now retains the full Compose stack instead of only the main +image and dependency names. Translation blockers remain until the generic driver +supports the full stack. Kimai reuses LinuxServer's own MariaDB image and its +/config persistence. Its generated database password matches DATABASE_URL; +readiness executes an authenticated SELECT 1 rather than merely checking a port. +The app uses Doctrine's automatic server-version detection and allows IPv4 host +names for the initial LAN deployment. Configure a specific domain when adding a +reverse proxy. Completion prints upstream instructions for creating the first +administrator inside the Kimai LXC; no default account is invented. + +Kimai is installable but runtime-unvalidated. Diskover remains blocked: its +upstream example includes an Elasticsearch dependency and a privileged helper +changing host vm.max_map_count. Host kernel settings and Elasticsearch version +compatibility need separate review, not silent removal of these requirements. + +### HAOS One native OCI profile + +The community image `qweritos/haos-one:latest` is installable with the laboratory +adaptation: unprivileged LXC, `ostype=unmanaged`, `nesting=1`, `keyctl=1`, and a +managed `/mnt/data` volume included in Proxmox backups (32 GB default, 16 GB +minimum). The image's entrypoint, command and stop signal remain imported from +OCI metadata. No Docker daemon or compatibility proxy is installed by ProxMenux; +the nested runtime belongs to the image itself. + +The installer asks for explicit acknowledgement of the experimental profile and +its inner AppArmor limitations. First boot may pull several images. A bounded +20-minute check reports progress and requires healthy/supported Supervisor, the +real Core container rather than the landing page, running CLI/DNS/audio/multicast/ +Observer containers, and working Core and Observer HTTP endpoints. The final +Core URL is detected on port 80 or 8123 instead of assumed. A first-boot failure +preserves the LXC, data and root-only console log for diagnosis; it never reports +success. If starting is declined, no unverified URL is printed. + +This installer path and the rolling latest image remain runtime-unvalidated. +The historical lab evidence stays in the template; it is not a guarantee for +new releases. Full backup restore, outer-image replacement, USB and multicast +discovery still need explicit tests. See the upstream project: +https://github.com/qweritos/haos-one + +### Native Compose resource limits + +`mem_limit` now supplies the editable Proxmox RAM default (MiB rounded upwards, +minimum 16 MiB). A conflicting `deploy.resources.limits.memory` remains blocked +for review. Swap is still an independent Proxmox setting, not a claim of exact +Docker swap defaults. `ulimits` maps soft/hard values to native `lxc.prlimit.*`; +`-1` becomes `unlimited`. Invalid resource names, malformed values, duplicate +remote entries and soft limits greater than hard limits are rejected. The +installation summary shows these limits, including per-service stack limits. + +No host sysctls, service-manager limits or privileges are silently changed to +make a requested limit succeed. LXC/kernel restrictions still apply. In +particular `nproc` is per real UID, not per container, and is not a replacement +for a cgroup PID limit. Reference: https://linuxcontainers.org/lxc/manpages/man5/lxc.container.conf.5.html + +Diskover and RagFlow no longer carry the generic mem_limit/ulimits translation +blockers, but remain unavailable for automatic installation until their other +dependencies, healthchecks and host requirements are adapted. Diskover retains +Elasticsearch 7.17.22 in `original_compose`; the normalized candidate follows the +catalog's `latest` policy. Compatibility and tag availability therefore require +review before promotion, not an unverified Elasticsearch upgrade. The full Compose is now preserved in the active JSON, +as it already is when regenerating from the LinuxServer README. + +### Host monitors: experimental native profile + +Glances offers an isolated alternative when host access is declined: an +unprivileged LXC with its own IP, default AppArmor, no host mounts, and no extra +capabilities. It monitors only itself, not Proxmox. The final summary states this +scope explicitly. `GLANCES_OPT=-w` remains automatic in either mode. Netdata's +host profile still requires acceptance; this fallback applies only to Glances. + +Glances and Netdata have an installable `host_monitor` profile, tested on amd64 +Proxmox 9.2.18 on 2026-09-14. Both expose host CPU/RAM/process metrics and survive +a shutdown/start cycle. Netdata also exposes LXC cgroup charts and preserves its +registry identity in a managed volume. Observed image digests and versions are +recorded in each template; rolling tags and arm64 are not universally validated. + +The profile uses a privileged LXC, explicitly inherits host PID and +network namespaces, and uses unconfined AppArmor. It requires informed consent; +a compromised monitor could affect the host. Its endpoint uses the host IP and +host firewall, with a port-conflict check before image download. Do not expose +these unauthenticated dashboards to untrusted networks. + +Only the monitor's LXCFS mount hook is cleared, to avoid reporting container +CPU/RAM limits as host metrics. Proxmox pre-start/autodev/post-stop hooks are +retained. No Docker socket or host root filesystem is mounted. Netdata's native +`/host` paths receive read-only proc/sys/identity mounts, and its three private +data directories remain managed volumes included in backup. Full filesystem, +SMART, Docker inventory and GPU monitoring are not implied by this profile. +The host cgroup mount is explicitly bound read-only below `/host/sys/fs/cgroup`. +CPU consumption is bounded with `cpulimit` rather than a restricted CPU affinity, +so the monitor sees the host's real processor count. + +Proxmox does not accept `lxc.namespace.share.*` directly in CT configuration. +The installer uses supported `lxc.include` referencing the static companion +`/etc/pve/lxc/proxmenux-host-monitor`. This file persists across host reboots but +is NOT included in a CT vzdump. Preserve/recreate it when restoring on another +host, in addition to restoring managed volumes. Full restore/image replacement +have not been tested. No custom supervisor or image entrypoint is introduced. + +DeepSeek OCR remains deferred at the user's request: registry inspection on +2026-09-14 found only `v2.2.0` for both IceWhaleTech images and no `latest` tag. +No fixed-version exception or deployment has been introduced. diff --git a/oci/catalog.json b/oci/addons/secure-gateway.json similarity index 100% rename from oci/catalog.json rename to oci/addons/secure-gateway.json diff --git a/oci/catalog/apps/2fauth.json b/oci/catalog/apps/2fauth.json new file mode 100644 index 00000000..83c327d3 --- /dev/null +++ b/oci/catalog/apps/2fauth.json @@ -0,0 +1,423 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-2fauth", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "2FAuth" + }, + "tagline": { + "en_US": "A web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes" + }, + "description": { + "en_US": "2FAuth is a web based self-hosted alternative to One Time Passcode (OTP) generators like Google Authenticator, designed for both mobile and desktop." + }, + "category": "security", + "category_label": "Authentication & Security", + "author": "Bubka", + "developer": "Bubka", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://2fauth.app", + "documentation": null, + "repository": "https://hub.docker.com/r/2fauth/2fauth", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/2fauth/2fauth", + "revision": "c253dbe602c2b09b665826316933397082a2c126ddb3f312cc5783558b38932e", + "image_repository_url": "https://hub.docker.com/r/2fauth/2fauth", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "c253dbe602c2b09b665826316933397082a2c126ddb3f312cc5783558b38932e", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "2fauth", + "container_name": "2fauth", + "image": { + "reference": "2fauth/2fauth:latest", + "registry": "docker.io", + "repository": "2fauth/2fauth", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "APP_KEY", + "example": "${GENERATED_APP_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/2fauth", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: 2fauth\nservices:\n 2fauth:\n image: 2fauth/2fauth:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 8000\n published: '8000'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /2fauth\n environment:\n APP_KEY: ${GENERATED_APP_KEY}\n container_name: 2fauth\n" + }, + "compose_stack": { + "project_name": "2fauth", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "2fauth", + "service_count": 1, + "services": [ + { + "name": "2fauth", + "image": "2fauth/2fauth:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "2fauth/2fauth:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8000, + "published": "8000", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/2fauth" + } + ], + "environment": { + "APP_KEY": "${GENERATED_APP_KEY}" + }, + "container_name": "2fauth" + } + } + ], + "top_level": { + "name": "2fauth" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "2fauth-volume-0", + "service": "2fauth", + "container_path": "/2fauth", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "2fauth" + ], + "stop_order": [ + "2fauth" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "app-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "2fauth", + "environment_variable": "APP_KEY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/actualbudget.json b/oci/catalog/apps/actualbudget.json new file mode 100644 index 00000000..4bd58527 --- /dev/null +++ b/oci/catalog/apps/actualbudget.json @@ -0,0 +1,400 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-actualbudget", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Actual Budget" + }, + "tagline": { + "en_US": "Privacy-first finance app with envelope budgeting and multi-device sync." + }, + "description": { + "en_US": "Actual Budget is a fast, privacy-focused finance management app using local-first envelope budgeting, ensuring full control over data. Its intuitive interface supports offline use, with multi-device sync and optional end-to-end encryption, delivering a secure, efficient financial management experience, ideal for users seeking clear financial oversight.\n\nThe app's core features include envelope budgeting based on real income, rapid transaction handling, and intuitive financial reporting. It helps users track spending and monitor monthly savings clearly, with a streamlined transaction editor for quick categorization, split transactions, and transfers. Built-in net worth and cash flow reports provide financial insights, and a custom report engine allows tailored reports for specific needs. Undo and redo functionality ensures users can easily correct mistakes, maintaining operational flexibility.\n\nIt integrates bank accounts via goCardless (EU/UK) or SimpleFIN (US/Canada), supports multi-device syncing for data privacy, and enables importing transaction data from YNAB4, nYNAB, and QIF, OFX, QFX, CAMT.053, CSV files, simplifying migration of existing financial records. Community documentation enhances usability, and the app's simple operation and high flexibility deliver a modern finance management solution.\n\n**Key Features:**\n- Privacy-focused personal finance management\n- Envelope budgeting methodology\n- Multi-device synchronization\n- End-to-end encryption support\n- Local data ownership\n- Fast and responsive interface\n- Open source and self-hosted\n- Bank account synchronization\n- Detailed financial reporting\n- Budget tracking and analysis\n\n**Learn More:**\n- [Actual Budget Official Website](https://actualbudget.org)\n- [Actual Budget GitHub Repository](https://github.com/actualbudget/actual)\n- [Actual Budget Docker Image](https://hub.docker.com/r/actualbudget/actual-server)\n" + }, + "category": "finance", + "category_label": "Finance & Budgeting", + "author": "ActualBudget", + "developer": "ActualBudget", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5006, + "path": "/" + }, + "website": "https://actualbudget.org", + "documentation": null, + "repository": "https://hub.docker.com/r/actualbudget/actual-server", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/actualbudget/actual-server", + "revision": "4a2a6ebc056da1fc016fbe7937484ca6c670fc056450e4d676ee663bf9962bb1", + "image_repository_url": "https://hub.docker.com/r/actualbudget/actual-server", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "4a2a6ebc056da1fc016fbe7937484ca6c670fc056450e4d676ee663bf9962bb1", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "actualbudget", + "container_name": "actualbudget", + "image": { + "reference": "actualbudget/actual-server:latest", + "registry": "docker.io", + "repository": "actualbudget/actual-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5006, + "published_example": 15006, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: actualbudget\nservices:\n actualbudget:\n image: actualbudget/actual-server:latest\n container_name: actualbudget\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /data\n ports:\n - target: 5006\n published: '15006'\n protocol: tcp\n" + }, + "compose_stack": { + "project_name": "actualbudget", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "actualbudget", + "service_count": 1, + "services": [ + { + "name": "actualbudget", + "image": "actualbudget/actual-server:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "actualbudget/actual-server:latest", + "container_name": "actualbudget", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/data" + } + ], + "ports": [ + { + "target": 5006, + "published": "15006", + "protocol": "tcp" + } + ] + } + } + ], + "top_level": { + "name": "actualbudget" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "actualbudget-volume-0", + "service": "actualbudget", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for actualbudget:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "actualbudget" + ], + "stop_order": [ + "actualbudget" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5006, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/adguard-home.json b/oci/catalog/apps/adguard-home.json new file mode 100644 index 00000000..aa28859f --- /dev/null +++ b/oci/catalog/apps/adguard-home.json @@ -0,0 +1,481 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-adguard-home", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "AdGuard Home" + }, + "tagline": { + "en_US": "Network-wide ad and tracker blocking" + }, + "description": { + "en_US": "Difference from Traditional Ad Blockers. Unlike traditional ad-blocking plugins that work only on individual devices, AdGuard Home offers a network-wide solution. By setting it up, you can block ads and trackers across all your home devices without needing to install any additional software on each device. This means comprehensive protection with minimal effort.\n\nHow AdGuard Home Works and How to Use It. AdGuard Home functions as a DNS server that reroutes tracking domains to a \"black hole,\" effectively preventing your devices from connecting to these servers. This blocks ads and trackers not only on your computer but also on your smartphone and smart home devices. To start using AdGuard Home, deploy it on your device, then change the DNS address assigned by DHCP on your router to the IP address of your AdGuard Home server.\n\nBenefits of Deploying AdGuard Home on self-hosted server Private Cloud. Deploying AdGuard Home on a self-hosted server device simplifies network-wide ad and tracker blocking, providing a seamless and secure browsing experience for all your home devices. With self-hosted server, you gain the flexibility to monitor network activity and create custom filtering rules tailored to your needs.\n" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "AdguardTeam", + "developer": "AdguardTeam", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://adguard.com/en/adguard-home/overview.html", + "documentation": null, + "repository": "https://hub.docker.com/r/adguard/adguardhome", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/adguard/adguardhome", + "revision": "f867788b8d2a98c367f6160bc3ae3ce515c037665242005c627bea1269aca62f", + "image_repository_url": "https://hub.docker.com/r/adguard/adguardhome", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "f867788b8d2a98c367f6160bc3ae3ce515c037665242005c627bea1269aca62f", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "adguard-home", + "container_name": "adguard-home", + "image": { + "reference": "adguard/adguardhome:latest", + "registry": "docker.io", + "repository": "adguard/adguardhome", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt/adguardhome/work", + "compose_source_example": "/DATA/AppData/$AppID/opt/adguardhome/work", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/opt/adguardhome/conf", + "compose_source_example": "/DATA/AppData/$AppID/opt/adguardhome/conf", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 53, + "published_example": 53, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 53, + "published_example": 53, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3000, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 853, + "published_example": 853, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 784, + "published_example": 784, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: adguard-home\nservices:\n adguard-home:\n image: adguard/adguardhome:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 53\n published: '53'\n protocol: tcp\n - target: 53\n published: '53'\n protocol: udp\n - target: 3000\n published: '3001'\n protocol: tcp\n - target: 853\n published: '853'\n protocol: tcp\n - target: 784\n published: '784'\n protocol: udp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/opt/adguardhome/work\n target: /opt/adguardhome/work\n - type: bind\n source: /DATA/AppData/$AppID/opt/adguardhome/conf\n target: /opt/adguardhome/conf\n container_name: adguard-home\n" + }, + "compose_stack": { + "project_name": "adguard-home", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "adguard-home", + "service_count": 1, + "services": [ + { + "name": "adguard-home", + "image": "adguard/adguardhome:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "adguard/adguardhome:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 53, + "published": "53", + "protocol": "tcp" + }, + { + "target": 53, + "published": "53", + "protocol": "udp" + }, + { + "target": 3000, + "published": "3001", + "protocol": "tcp" + }, + { + "target": 853, + "published": "853", + "protocol": "tcp" + }, + { + "target": 784, + "published": "784", + "protocol": "udp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/opt/adguardhome/work", + "target": "/opt/adguardhome/work" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/opt/adguardhome/conf", + "target": "/opt/adguardhome/conf" + } + ], + "container_name": "adguard-home" + } + } + ], + "top_level": { + "name": "adguard-home" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "adguard-home-volume-0", + "service": "adguard-home", + "container_path": "/opt/adguardhome/work", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "adguard-home-volume-1", + "service": "adguard-home", + "container_path": "/opt/adguardhome/conf", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "adguard-home" + ], + "stop_order": [ + "adguard-home" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/adguardhome-sync.json b/oci/catalog/apps/adguardhome-sync.json new file mode 100644 index 00000000..34665858 --- /dev/null +++ b/oci/catalog/apps/adguardhome-sync.json @@ -0,0 +1,248 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-adguardhome-sync", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Adguardhome Sync" + }, + "tagline": { + "en_US": "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances." + }, + "description": { + "en_US": "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances." + }, + "category": "adblock", + "category_label": "Adblock & DNS", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/adguardhome-sync-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/adguardhome-sync-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://github.com/bakito/adguardhome-sync/", + "documentation": "https://docs.linuxserver.io/images/docker-adguardhome-sync/", + "repository": "https://github.com/linuxserver/docker-adguardhome-sync", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-17", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-24", + "note": "Rebase to Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-adguardhome-sync", + "default_branch": "main", + "revision": "f5979684c0e61370b8f93425f984f6ea629c6dbd", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-adguardhome-sync/f5979684c0e61370b8f93425f984f6ea629c6dbd/README.md", + "readme_pushed_at": "2026-09-09T11:38:18Z", + "compose_sha256": "c8d84ce623aa48c468a5bcdfc3d20298e3a41cf9091895ef5eda65db776437fa", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "adguardhome-sync", + "container_name": "adguardhome-sync", + "image": { + "reference": "lscr.io/linuxserver/adguardhome-sync:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/adguardhome-sync", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CONFIGFILE", + "example": "/config/adguardhome-sync.yaml", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/adguardhome-sync/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n adguardhome-sync:\n image: lscr.io/linuxserver/adguardhome-sync:latest\n container_name: adguardhome-sync\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - CONFIGFILE=/config/adguardhome-sync.yaml #optional\n volumes:\n - /path/to/adguardhome-sync/config:/config\n ports:\n - 8080:8080\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/adminer.json b/oci/catalog/apps/adminer.json new file mode 100644 index 00000000..8c7afdcb --- /dev/null +++ b/oci/catalog/apps/adminer.json @@ -0,0 +1,360 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-adminer", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Adminer" + }, + "tagline": { + "en_US": "Database management in a single PHP file" + }, + "description": { + "en_US": "Adminer (formerly phpMinAdmin) is a full-featured database management tool written in PHP. Conversely to phpMyAdmin, it consist of a single file ready to deploy to the target server. Adminer is available for MySQL, PostgreSQL, SQLite, MS SQL, Oracle, Firebird, SimpleDB, Elasticsearch and MongoDB." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Jakub Vr\u00e1na", + "developer": "Jakub Vr\u00e1na", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://www.adminer.org", + "documentation": null, + "repository": "https://hub.docker.com/_/adminer", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/_/adminer", + "revision": "6c8ba52b744a2eccfafdf13e5e6bd0bd7c35423bcc033b0ffb122d90f39766e6", + "image_repository_url": "https://hub.docker.com/_/adminer", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "6c8ba52b744a2eccfafdf13e5e6bd0bd7c35423bcc033b0ffb122d90f39766e6", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "adminer", + "container_name": "adminer", + "image": { + "reference": "adminer:latest", + "registry": "docker.io", + "repository": "adminer", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: adminer\nservices:\n adminer:\n image: adminer:latest\n deploy:\n resources:\n reservations:\n memory: 32M\n restart: unless-stopped\n ports:\n - 8080:8080\n container_name: adminer\n" + }, + "compose_stack": { + "project_name": "adminer", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "adminer", + "service_count": 1, + "services": [ + { + "name": "adminer", + "image": "adminer:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "adminer:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "32M" + } + } + }, + "restart": "unless-stopped", + "ports": [ + "8080:8080" + ], + "container_name": "adminer" + } + } + ], + "top_level": { + "name": "adminer" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "adminer" + ], + "stop_order": [ + "adminer" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/airsonic-advanced.json b/oci/catalog/apps/airsonic-advanced.json new file mode 100644 index 00000000..d705be13 --- /dev/null +++ b/oci/catalog/apps/airsonic-advanced.json @@ -0,0 +1,431 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-airsonic-advanced", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Airsonic Advanced" + }, + "tagline": { + "en_US": "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room." + }, + "description": { + "en_US": "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/airsonic-advanced-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/airsonic-advanced-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 4040, + "path": "/" + }, + "website": "https://github.com/kagemomiji/airsonic-advanced", + "documentation": "https://docs.linuxserver.io/images/docker-airsonic-advanced/", + "repository": "https://github.com/linuxserver/docker-airsonic-advanced", + "tips": [], + "mini_changelog": [ + { + "date": "2024-12-21", + "note": "Rebase to Alpine 3.21. Switch upstream to track https://github.com/kagemomiji/airsonic-advanced." + }, + { + "date": "2024-05-24", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-05-30", + "note": "Rebase to Alpine 3.18." + }, + { + "date": "2023-02-11", + "note": "Rebase to Alpine 3.17." + } + ], + "display_version": null, + "updated_at": "2024-12-21" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-airsonic-advanced", + "default_branch": "master", + "revision": "6f1c44cca22385d01b5f95eae6fb34e48bbcd6db", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-airsonic-advanced/6f1c44cca22385d01b5f95eae6fb34e48bbcd6db/README.md", + "readme_pushed_at": "2026-09-12T12:53:04Z", + "compose_sha256": "00bd8daac79ebd1b2d47b34c2e8c5917bd8631116e61e320c057eee69de42931", + "generated_at": "2026-09-13T15:35:39+00:00" + }, + "container_contract": { + "service_name": "airsonic-advanced", + "container_name": "airsonic-advanced", + "image": { + "reference": "lscr.io/linuxserver/airsonic-advanced:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/airsonic-advanced", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CONTEXT_PATH", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "JAVA_OPTS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/airsonic-advanced/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/music", + "compose_source_example": "/path/to/music", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/playlists", + "compose_source_example": "/path/to/playlists", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/podcasts", + "compose_source_example": "/path/to/podcasts", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-4", + "container_path": "/media", + "compose_source_example": "/path/to/other media", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 4040, + "published_example": 4040, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n airsonic-advanced:\n image: lscr.io/linuxserver/airsonic-advanced:latest\n container_name: airsonic-advanced\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - CONTEXT_PATH= #optional\n - JAVA_OPTS= #optional\n volumes:\n - /path/to/airsonic-advanced/config:/config\n - /path/to/music:/music\n - /path/to/playlists:/playlists\n - /path/to/podcasts:/podcasts\n - /path/to/other media:/media #optional\n ports:\n - 4040:4040\n devices:\n - /dev/snd:/dev/snd #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 4040, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "dev-snd", + "kind": "character-device-tree", + "purpose": "audio", + "enable_prompt": "Host audio devices", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Audio device directory", + "host_path_default": "/dev/snd", + "container_path": "/dev/snd", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/snd:/dev/snd" + } + ] + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/albyhub.json b/oci/catalog/apps/albyhub.json new file mode 100644 index 00000000..106dab88 --- /dev/null +++ b/oci/catalog/apps/albyhub.json @@ -0,0 +1,463 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-albyhub", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Alby Hub \u2728" + }, + "tagline": { + "en_US": "Self-custodial Bitcoin Lightning wallet with integrated node and app connections." + }, + "description": { + "en_US": "Alby Hub is an open-source, self-custodial Bitcoin Lightning wallet, with the easiest-to-use Lightning Network node for everyone.\nWhether you're an individual, creator, or developer, Alby Hub is your centre for seamless Bitcoin payments.\nEffortlessly connect to a variety of apps like the Alby Browser Extension or Alby Go mobile app, create sub-wallets for family and friends, and take full control of your funds\u2014all within an intuitive interface and developer-ready APIs.\n\n**USEFUL LINKS**\n- [Source Repository](https://github.com/getAlby/hub)\n- [Support](https://support.getalby.com/)\n- [Marketing Site](https://albyhub.com/)\n- [Community of users and developers](https://discord.getalby.com)\n- [Feedback Board, feature requests, bug reports[(https://feedback.getalby.com)\n" + }, + "category": "finance", + "category_label": "Finance & Budgeting", + "author": "getalby", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://albyhub.com/", + "documentation": null, + "repository": "https://ghcr.io/getalby/hub", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "getalby", + "repository": "https://ghcr.io/getalby/hub", + "revision": "146ef47a306af88e45232c40da9d35e293b48de644664cf85de6c0ae2ad97ef1", + "image_repository_url": "https://ghcr.io/getalby/hub", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "146ef47a306af88e45232c40da9d35e293b48de644664cf85de6c0ae2ad97ef1", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "albyhub", + "container_name": "albyhub", + "image": { + "reference": "ghcr.io/getalby/hub:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/getalby/hub", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "UMASK", + "example": "002", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WORK_DIR", + "example": "/data/albyhub", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOG_EVENTS", + "example": "True", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 58000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "on-failure", + "stop_grace_period": "1m", + "original_compose": "name: albyhub\nservices:\n albyhub:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n UMASK: '002'\n WORK_DIR: /data/albyhub\n LOG_EVENTS: true\n command: []\n container_name: albyhub\n image: ghcr.io/getalby/hub:latest\n deploy:\n resources:\n reservations:\n memory: 1024M\n labels:\n icon: https://cdn.jsdelivr.net/gh/getAlby/hub@master/frontend/public/icon-512.png\n ports:\n - target: 8080\n published: '58000'\n protocol: tcp\n restart: on-failure\n stop_grace_period: 1m\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "albyhub", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "albyhub", + "service_count": 1, + "services": [ + { + "name": "albyhub", + "image": "ghcr.io/getalby/hub:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ", + "UMASK": "002", + "WORK_DIR": "/data/albyhub", + "LOG_EVENTS": true + }, + "command": [], + "container_name": "albyhub", + "image": "ghcr.io/getalby/hub:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + }, + "labels": { + "icon": "https://cdn.jsdelivr.net/gh/getAlby/hub@master/frontend/public/icon-512.png" + }, + "ports": [ + { + "target": 8080, + "published": "58000", + "protocol": "tcp" + } + ], + "restart": "on-failure", + "stop_grace_period": "1m", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "albyhub" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "albyhub-volume-0", + "service": "albyhub", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for albyhub:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "albyhub" + ], + "stop_order": [ + "albyhub" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 60 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/alist-sync.json b/oci/catalog/apps/alist-sync.json new file mode 100644 index 00000000..899df607 --- /dev/null +++ b/oci/catalog/apps/alist-sync.json @@ -0,0 +1,400 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-alist-sync", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Alist-Sync" + }, + "tagline": { + "en_US": "An Alist storage synchronization tool based on the Web interface." + }, + "description": { + "en_US": "Alist-Sync is a storage synchronization tool based on the Web interface. It can achieve data synchronization and mutual backup among multiple network disks, and also has practical functions such as multi-task management, scheduled synchronization and difference handling.\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "xjxjin", + "developer": "xjxjin", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 52441, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/xjxjin/alist-sync", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "xjxjin", + "repository": "https://hub.docker.com/r/xjxjin/alist-sync", + "revision": "d618977fd6400e8a25474aa77fae63474e399b77d0d55aaf8d76ec752572b771", + "image_repository_url": "https://hub.docker.com/r/xjxjin/alist-sync", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "d618977fd6400e8a25474aa77fae63474e399b77d0d55aaf8d76ec752572b771", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "alist-sync", + "container_name": "alist-sync", + "image": { + "reference": "xjxjin/alist-sync:latest", + "registry": "docker.io", + "repository": "xjxjin/alist-sync", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Asia/Shanghai", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 52441, + "published_example": 52441, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: alist-sync\nservices:\n alist-sync:\n image: xjxjin/alist-sync:latest\n container_name: alist-sync\n restart: unless-stopped\n ports:\n - 52441:52441\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /app/data\n environment:\n - TZ=Asia/Shanghai\n" + }, + "compose_stack": { + "project_name": "alist-sync", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "alist-sync", + "service_count": 1, + "services": [ + { + "name": "alist-sync", + "image": "xjxjin/alist-sync:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "xjxjin/alist-sync:latest", + "container_name": "alist-sync", + "restart": "unless-stopped", + "ports": [ + "52441:52441" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/app/data" + } + ], + "environment": [ + "TZ=Asia/Shanghai" + ] + } + } + ], + "top_level": { + "name": "alist-sync" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "alist-sync-volume-0", + "service": "alist-sync", + "container_path": "/app/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "alist-sync" + ], + "stop_order": [ + "alist-sync" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 52441, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/alist.json b/oci/catalog/apps/alist.json new file mode 100644 index 00000000..280ccdbb --- /dev/null +++ b/oci/catalog/apps/alist.json @@ -0,0 +1,401 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-alist", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Alist" + }, + "tagline": { + "en_US": "Mount your cloud drive on your home NAS" + }, + "description": { + "en_US": "Alist transforms how you manage and access your files at home, whether on your TV, phone, or any other device. Unlike traditional cloud storage, Alist offers a unified experience across multiple platforms, making it a breeze to keep your media and documents at your fingertips.\n\nWith features like easy installation, support for multiple storage providers (local, Aliyundrive, Onedrive, Google Drive), WebDAV support, dark mode, protected routes with password authentication, file previews for videos, audio, office files, PDFs, code, images, package and batch downloads, single sign-on, offline torrent downloads, file encryption, and additional tools like a text editor and Cloudflare workers proxy, Alist ensures a seamless and secure file management experience.\n\nDeploying Alist on private cloud devices like self-hosted server brings unmatched convenience with multi-device access, ensuring your files are always within reach and secure, no matter where you are.\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Xhofe", + "developer": "Xhofe", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5244, + "path": "/" + }, + "website": "https://alistgo.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/xhofe/alist", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "xhofe", + "repository": "https://hub.docker.com/r/xhofe/alist", + "revision": "fd43f0109fc409601d387e19033e2a96bcb6721e679aecddf551963c77585526", + "image_repository_url": "https://hub.docker.com/r/xhofe/alist", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "fd43f0109fc409601d387e19033e2a96bcb6721e679aecddf551963c77585526", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "alist", + "container_name": "alist", + "image": { + "reference": "xhofe/alist:latest", + "registry": "docker.io", + "repository": "xhofe/alist", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt/alist/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5244, + "published_example": 5244, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: alist\nservices:\n alist:\n image: xhofe/alist:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 5244\n published: '5244'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /opt/alist/data\n container_name: alist\n" + }, + "compose_stack": { + "project_name": "alist", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "alist", + "service_count": 1, + "services": [ + { + "name": "alist", + "image": "xhofe/alist:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "xhofe/alist:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 5244, + "published": "5244", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/opt/alist/data" + } + ], + "container_name": "alist" + } + } + ], + "top_level": { + "name": "alist" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "alist-volume-0", + "service": "alist", + "container_path": "/opt/alist/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "alist" + ], + "stop_order": [ + "alist" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5244, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/altus.json b/oci/catalog/apps/altus.json new file mode 100644 index 00000000..5c49f227 --- /dev/null +++ b/oci/catalog/apps/altus.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-altus", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Altus" + }, + "tagline": { + "en_US": "Altus is an Electron-based WhatsApp client with themes and multiple account support." + }, + "description": { + "en_US": "Altus is an Electron-based WhatsApp client with themes and multiple account support." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/altus-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/altus-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/amanharwara/altus", + "documentation": "https://docs.linuxserver.io/images/docker-altus/", + "repository": "https://github.com/linuxserver/docker-altus", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-altus", + "default_branch": "master", + "revision": "20affcb2e851b1243d54e496be9b97544dec2114", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-altus/20affcb2e851b1243d54e496be9b97544dec2114/README.md", + "readme_pushed_at": "2026-09-12T08:16:57Z", + "compose_sha256": "9f6f18c489939a4c28dc2d9027f13a9b00941765c0cb116600391eb2533af2f9", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "altus", + "container_name": "altus", + "image": { + "reference": "lscr.io/linuxserver/altus:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/altus", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/altus/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n altus:\n image: lscr.io/linuxserver/altus:latest\n container_name: altus\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/altus/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-altus/master/Dockerfile", + "dockerfile_sha256": "c6e3ffa939d03cece6f29c8d30127ca78ec10c67840d714042f725c09b82f701", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/amule.json b/oci/catalog/apps/amule.json new file mode 100644 index 00000000..fa3df805 --- /dev/null +++ b/oci/catalog/apps/amule.json @@ -0,0 +1,465 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "image-amule", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "aMule" + }, + "tagline": { + "en_US": "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule." + }, + "description": { + "en_US": "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "ngosang", + "developer": "ngosang", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 4711, + "path": "/" + }, + "website": "https://github.com/amule-org/amule", + "documentation": "https://github.com/ngosang/docker-amule", + "repository": "https://github.com/ngosang/docker-amule", + "tips": [ + "Configuration stays on a private managed Proxmox volume with backup enabled. Downloads may use a managed volume or an explicitly selected host directory.", + "Completed files use /downloads/incoming; incomplete files use /downloads/temp. Keeping both under one mount preserves moves on the same filesystem.", + "GUI_PWD and WEBUI_PWD are required upstream passwords, not built-in credentials. The web login requests no username.", + "Optional MOD variables are upstream features, not LinuxServer mods. They are not enabled automatically by this template.", + "Do not expose HTTP port 4711 or External Connections port 4712 directly to the Internet. Router port forwarding is a separate user action; this installer does not change the router." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-18" + }, + "source": { + "provider": "ngosang", + "repository": "https://github.com/ngosang/docker-amule", + "default_branch": "master", + "revision": "356d94c46b8e1d02eac35ca23875d15fc01864d8", + "readme_raw_url": "https://raw.githubusercontent.com/ngosang/docker-amule/356d94c46b8e1d02eac35ca23875d15fc01864d8/README.md", + "readme_pushed_at": "2026-09-18", + "compose_sha256": "c491822b91bc3e0e8af1e63f3e3cf5f1659185688afc7d9510034924662a51e6", + "generated_at": "2026-09-18T20:05:19+00:00" + }, + "container_contract": { + "service_name": "amule", + "container_name": "amule", + "image": { + "reference": "ngosang/amule:latest", + "registry": "docker.io", + "repository": "ngosang/amule", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "TZ", + "example": "Europe/London", + "required": true, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "GUI_PWD", + "example": "", + "required": true, + "sensitive": true, + "source": "upstream-compose", + "prompt": "Password for aMule external connections (remote client)" + }, + { + "name": "WEBUI_PWD", + "example": "", + "required": true, + "sensitive": true, + "source": "upstream-compose", + "prompt": "Password to access the aMule web interface" + }, + { + "name": "MOD_AUTO_RESTART_ENABLED", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "MOD_AUTO_RESTART_CRON", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "MOD_AUTO_SHARE_ENABLED", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "MOD_AUTO_SHARE_DIRECTORIES", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/home/amule/.aMule", + "compose_source_example": "", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 4711, + "published_example": 4711, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4712, + "published_example": 4712, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4662, + "published_example": 4662, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4665, + "published_example": 4665, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4672, + "published_example": 4672, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n amule:\n image: ngosang/amule\n container_name: amule\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Europe/London\n - GUI_PWD=\n - WEBUI_PWD=\n - MOD_AUTO_RESTART_ENABLED=true\n - MOD_AUTO_RESTART_CRON=0 6 * * *\n - MOD_AUTO_SHARE_ENABLED=false\n - MOD_AUTO_SHARE_DIRECTORIES=/downloads/incoming;/my_movies\n ports:\n - \"4711:4711\" # Web UI and REST API (amuleapi)\n - \"4712:4712\" # External connections (amuleapi, amulegui, amulecmd)\n - \"4662:4662\" # ED2K client-to-client TCP (required for High ID)\n - \"4665:4665/udp\" # ED2K server UDP (global searches, TCP port +3)\n - \"4672:4672/udp\" # Extended eMule protocol and Kademlia UDP\n volumes:\n - :/home/amule/.aMule\n - :/downloads\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 4711, + "path": "/", + "source": "upstream-documentation" + } + ], + "credentials": [ + { + "label": "aMule WebUI (password only, no username)", + "type": "configured-or-installer-generated", + "username": "Not required (password only)", + "password": null, + "password_environment": "WEBUI_PWD", + "change_required": false, + "source": "https://github.com/ngosang/docker-amule" + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "device_requests": [], + "startup_healthcheck": { + "scheme": "http", + "port": 4711, + "path": "/", + "timeout_seconds": 600, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "mem_limit", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "ulimits", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Reviewed official single-image mapping. Validated on amd64: clean install, authenticated web login, same-digest recreation and interrupted-candidate recovery with managed configuration and downloads. Cross-release migration, arm64 runtime and P2P downloads not tested." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "authenticated_login": "passed-after-recovery-amd64", + "restart_persistence": "passed-through-recreation-amd64", + "backup_restore": "passed-managed-configuration-and-downloads-amd64", + "update_preserves_data": "passed-same-digest-recreation-amd64", + "cross_release_upgrade": "not-tested", + "p2p_download": "not-tested", + "evidence": "docs/lab/new-images-validation-20260918.json" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/anaconda3.json b/oci/catalog/apps/anaconda3.json new file mode 100644 index 00000000..dadf1989 --- /dev/null +++ b/oci/catalog/apps/anaconda3.json @@ -0,0 +1,434 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-anaconda3", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Anaconda3" + }, + "tagline": { + "en_US": "Your machine learning Env work with Jupyter Lab" + }, + "description": { + "en_US": "Your machine learning Env work with Jupyter Lab" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "LisonEvf", + "developer": "LisonEvf", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8888, + "path": "/" + }, + "website": "https://www.anaconda.com", + "documentation": null, + "repository": "https://hub.docker.com/r/continuumio/anaconda3", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "continuumio", + "repository": "https://hub.docker.com/r/continuumio/anaconda3", + "revision": "cca7243066069a6d33c7856ee6d424878e3a549edb6cdac57b1d2d4546407f80", + "image_repository_url": "https://hub.docker.com/r/continuumio/anaconda3", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "cca7243066069a6d33c7856ee6d424878e3a549edb6cdac57b1d2d4546407f80", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "anaconda3", + "container_name": "anaconda3", + "image": { + "reference": "continuumio/anaconda3:latest", + "registry": "docker.io", + "repository": "continuumio/anaconda3", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "LANG", + "example": "C.UTF-8", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LC_ALL", + "example": "C.UTF-8", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PATH", + "example": "/opt/conda/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt/notebooks", + "compose_source_example": "/DATA/AppData/$AppID/notebooks", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8888, + "published_example": 8888, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: anaconda3\nservices:\n anaconda3:\n container_name: anaconda3\n image: continuumio/anaconda3:latest\n network_mode: bridge\n restart: unless-stopped\n environment:\n - LANG=C.UTF-8\n - LC_ALL=C.UTF-8\n - PATH=/opt/conda/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\n ports:\n - target: 8888\n published: '8888'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/notebooks\n target: /opt/notebooks\n command:\n - /bin/bash\n - -c\n - conda install -c conda-forge jupyterlab -y --quiet && jupyter lab --notebook-dir=/opt/notebooks\n --ip='*' --port=8888 --no-browser --allow-root\n" + }, + "compose_stack": { + "project_name": "anaconda3", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "anaconda3", + "service_count": 1, + "services": [ + { + "name": "anaconda3", + "image": "continuumio/anaconda3:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "anaconda3", + "image": "continuumio/anaconda3:latest", + "network_mode": "bridge", + "restart": "unless-stopped", + "environment": [ + "LANG=C.UTF-8", + "LC_ALL=C.UTF-8", + "PATH=/opt/conda/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" + ], + "ports": [ + { + "target": 8888, + "published": "8888", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/notebooks", + "target": "/opt/notebooks" + } + ], + "command": [ + "/bin/bash", + "-c", + "conda install -c conda-forge jupyterlab -y --quiet && jupyter lab --notebook-dir=/opt/notebooks --ip='*' --port=8888 --no-browser --allow-root" + ] + } + } + ], + "top_level": { + "name": "anaconda3" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "anaconda3-volume-0", + "service": "anaconda3", + "container_path": "/opt/notebooks", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "anaconda3" + ], + "stop_order": [ + "anaconda3" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8888, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "/bin/bash", + "-c", + "conda install -c conda-forge jupyterlab -y --quiet && jupyter lab --notebook-dir=/opt/notebooks --ip='*' --port=8888 --no-browser --allow-root" + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/anythingllm.json b/oci/catalog/apps/anythingllm.json new file mode 100644 index 00000000..b94e938f --- /dev/null +++ b/oci/catalog/apps/anythingllm.json @@ -0,0 +1,441 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-anythingllm", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "AnythingLLM" + }, + "tagline": { + "en_US": "The all-in-one AI application." + }, + "description": { + "en_US": "AnythingLLM is the easiest to use, all-in-one AI application that can do RAG, AI Agents, and much more with no code or infrastructure headaches." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Mintplex Labs", + "developer": "Mintplex Labs", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3001, + "path": "/" + }, + "website": "https://anythingllm.com", + "documentation": null, + "repository": "https://hub.docker.com/r/mintplexlabs/anythingllm", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "mintplexlabs", + "repository": "https://hub.docker.com/r/mintplexlabs/anythingllm", + "revision": "a810590b730bb60cbf75b8f76200c971f5f61cf2545aa237422d6bf4f1e55633", + "image_repository_url": "https://hub.docker.com/r/mintplexlabs/anythingllm", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "a810590b730bb60cbf75b8f76200c971f5f61cf2545aa237422d6bf4f1e55633", + "generated_at": "2026-09-13T15:47:45+00:00" + }, + "container_contract": { + "service_name": "anythingllm", + "container_name": "anythingllm", + "image": { + "reference": "mintplexlabs/anythingllm:latest", + "registry": "docker.io", + "repository": "mintplexlabs/anythingllm", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "STORAGE_DIR", + "example": "/app/server/storage", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/server/storage", + "compose_source_example": "/DATA/AppData/anythingllm/storage", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3001, + "published_example": 3051, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "version: '3.8'\nname: anythingllm\nservices:\n anythingllm:\n image: mintplexlabs/anythingllm:latest\n container_name: anythingllm\n ports:\n - target: 3001\n published: 3051\n protocol: tcp\n cap_add:\n - SYS_ADMIN\n volumes:\n - type: bind\n source: /DATA/AppData/anythingllm/storage\n target: /app/server/storage\n environment:\n - STORAGE_DIR=/app/server/storage\n restart: always\n extra_hosts:\n - host.docker.internal:host-gateway\n" + }, + "compose_stack": { + "project_name": "anythingllm", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "anythingllm", + "service_count": 1, + "services": [ + { + "name": "anythingllm", + "image": "mintplexlabs/anythingllm:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "mintplexlabs/anythingllm:latest", + "container_name": "anythingllm", + "ports": [ + { + "target": 3001, + "published": 3051, + "protocol": "tcp" + } + ], + "cap_add": [ + "SYS_ADMIN" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/anythingllm/storage", + "target": "/app/server/storage" + } + ], + "environment": [ + "STORAGE_DIR=/app/server/storage" + ], + "restart": "always", + "extra_hosts": [ + "host.docker.internal:host-gateway" + ] + } + } + ], + "top_level": { + "version": "3.8", + "name": "anythingllm" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "anythingllm-volume-0", + "service": "anythingllm", + "container_path": "/app/server/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "anythingllm" + ], + "stop_order": [ + "anythingllm" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3001, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "extra_hosts": [ + { + "hostname": "host.docker.internal", + "address": "host-gateway" + } + ], + "security": { + "required_capabilities": [ + "SYS_ADMIN" + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/apprise-api.json b/oci/catalog/apps/apprise-api.json new file mode 100644 index 00000000..183fd9f2 --- /dev/null +++ b/oci/catalog/apps/apprise-api.json @@ -0,0 +1,265 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-apprise-api", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Apprise Api" + }, + "tagline": { + "en_US": "Apprise-api Takes advantage of Apprise through your network with a user-friendly API." + }, + "description": { + "en_US": "Apprise-api Takes advantage of Apprise through your network with a user-friendly API." + }, + "category": "messaging", + "category_label": "Messaging & Queues", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/apprise-api-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/apprise-api-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://github.com/caronc/apprise-api", + "documentation": "https://docs.linuxserver.io/images/docker-apprise-api/", + "repository": "https://github.com/linuxserver/docker-apprise-api", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-24", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-24", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-07-10", + "note": "Rebase to Alpine 3.18." + } + ], + "display_version": null, + "updated_at": "2025-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-apprise-api", + "default_branch": "main", + "revision": "ea905a7e0229ebf4bc05f3189950ae580ba630bb", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-apprise-api/ea905a7e0229ebf4bc05f3189950ae580ba630bb/README.md", + "readme_pushed_at": "2026-09-07T15:41:13Z", + "compose_sha256": "edc366d773c0251a031d811302c84c97eb9efd9b468ee03bac804de06082dc88", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "apprise-api", + "container_name": "apprise-api", + "image": { + "reference": "lscr.io/linuxserver/apprise-api:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/apprise-api", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APPRISE_ATTACH_SIZE", + "example": "0", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/apprise-api/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/attachments", + "compose_source_example": "/path/to/apprise-api/attachments", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n apprise-api:\n image: lscr.io/linuxserver/apprise-api:latest\n container_name: apprise-api\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - APPRISE_ATTACH_SIZE=0 #optional\n volumes:\n - /path/to/apprise-api/config:/config\n - /path/to/apprise-api/attachments:/attachments #optional\n ports:\n - 8000:8000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/archivebox.json b/oci/catalog/apps/archivebox.json new file mode 100644 index 00000000..0aaaabd1 --- /dev/null +++ b/oci/catalog/apps/archivebox.json @@ -0,0 +1,747 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-archivebox", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "ArchiveBox" + }, + "tagline": { + "en_US": "Self-hosted internet archiving solution" + }, + "description": { + "en_US": "ArchiveBox is a powerful, self-hosted internet archiving solution that allows you to create your own personal archive of web pages, PDFs, videos, and more. It functions as a personal internet archive, saving content in multiple formats for long-term preservation.\n\nThe system consists of multiple components:\n- **ArchiveBox**: The main application providing the web interface and archiving capabilities\n- **Sonic**: A fast search backend for full-text search across archived content\n- **ArchiveBox Scheduler**: A background service for scheduled archiving tasks\n- **NoVNC**: A web-based VNC client for browser-based archiving\n\n**Key Features:**\n- Save web pages in multiple formats (HTML, PDF, screenshots, etc.)\n- Full-text search across all archived content\n- Scheduled archiving of websites and RSS feeds\n- Browser-based archiving with NoVNC\n- User authentication and access control\n- Extract and save media files (videos, audio, PDFs, etc.)\n\n**Learn More:**\n- [ArchiveBox Official Website](https://archivebox.io)\n- [ArchiveBox GitHub Repository](https://github.com/ArchiveBox/ArchiveBox)\n- [ArchiveBox Documentation](https://github.com/ArchiveBox/ArchiveBox/wiki)\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "ArchiveBox", + "developer": "ArchiveBox", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://archivebox.io", + "documentation": null, + "repository": "https://hub.docker.com/r/archivebox/archivebox", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/archivebox/archivebox", + "revision": "e27286fc551a27ebc617239ccf45d9f2e741c213adeed4f9fc37df676c1cf27c", + "image_repository_url": "https://hub.docker.com/r/archivebox/archivebox", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "e27286fc551a27ebc617239ccf45d9f2e741c213adeed4f9fc37df676c1cf27c", + "generated_at": "2026-09-13T15:48:20+00:00" + }, + "container_contract": { + "service_name": "archivebox", + "container_name": "archivebox", + "image": { + "reference": "archivebox/archivebox:latest", + "registry": "docker.io", + "repository": "archivebox/archivebox", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ADMIN_USERNAME", + "example": "archivebox", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ADMIN_PASSWORD", + "example": "${GENERATED_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "ALLOWED_HOSTS", + "example": "*", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CSRF_TRUSTED_ORIGINS", + "example": "*", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLIC_INDEX", + "example": "True", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLIC_SNAPSHOTS", + "example": "True", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLIC_ADD_VIEW", + "example": "False", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SEARCH_BACKEND_ENGINE", + "example": "sonic", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SEARCH_BACKEND_HOST_NAME", + "example": "archivebox_sonic", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SEARCH_BACKEND_PASSWORD", + "example": "${GENERATED_SEARCH_BACKEND_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 18010, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "archivebox_scheduler", + "image": "archivebox/archivebox:latest" + }, + { + "name": "archivebox_sonic", + "image": "archivebox/sonic:latest" + }, + { + "name": "archivebox_novnc", + "image": "theasp/novnc:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: archivebox\nservices:\n archivebox:\n image: archivebox/archivebox:latest\n container_name: archivebox\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - archivebox_network\n depends_on:\n - archivebox_sonic\n ports:\n - target: 8000\n published: '18010'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n environment:\n - ADMIN_USERNAME=archivebox\n - ADMIN_PASSWORD=${GENERATED_ADMIN_PASSWORD}\n - ALLOWED_HOSTS=*\n - CSRF_TRUSTED_ORIGINS=*\n - PUBLIC_INDEX=True\n - PUBLIC_SNAPSHOTS=True\n - PUBLIC_ADD_VIEW=False\n - SEARCH_BACKEND_ENGINE=sonic\n - SEARCH_BACKEND_HOST_NAME=archivebox_sonic\n - SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}\n healthcheck:\n test:\n - CMD\n - wget\n - --no-verbose\n - --tries=1\n - --spider\n - http://localhost:8000\n interval: 1m\n timeout: 3s\n archivebox_scheduler:\n image: archivebox/archivebox:latest\n container_name: archivebox_scheduler\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - archivebox_network\n depends_on:\n - archivebox_sonic\n command:\n - schedule\n - --foreground\n - --update\n - --every=day\n environment:\n - TIMEOUT=120\n - SEARCH_BACKEND_ENGINE=sonic\n - SEARCH_BACKEND_HOST_NAME=archivebox_sonic\n - SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n archivebox_sonic:\n image: archivebox/sonic:latest\n container_name: archivebox_sonic\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - archivebox_network\n expose:\n - 1491\n environment:\n - SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data/sonic\n target: /var/lib/sonic/store\n archivebox_novnc:\n image: theasp/novnc:latest\n container_name: archivebox_novnc\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - archivebox_network\n ports:\n - target: 8080\n published: '18082'\n protocol: tcp\n environment:\n - DISPLAY_WIDTH=1920\n - DISPLAY_HEIGHT=1080\n - RUN_XTERM=no\nnetworks:\n archivebox_network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "archivebox", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "archivebox", + "service_count": 4, + "services": [ + { + "name": "archivebox_novnc", + "image": "theasp/novnc:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "theasp/novnc:latest", + "container_name": "archivebox_novnc", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "restart": "unless-stopped", + "networks": [ + "archivebox_network" + ], + "ports": [ + { + "target": 8080, + "published": "18082", + "protocol": "tcp" + } + ], + "environment": [ + "DISPLAY_WIDTH=1920", + "DISPLAY_HEIGHT=1080", + "RUN_XTERM=no" + ] + } + }, + { + "name": "archivebox_sonic", + "image": "archivebox/sonic:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "archivebox/sonic:latest", + "container_name": "archivebox_sonic", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "restart": "unless-stopped", + "networks": [ + "archivebox_network" + ], + "expose": [ + 1491 + ], + "environment": [ + "SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data/sonic", + "target": "/var/lib/sonic/store" + } + ] + } + }, + { + "name": "archivebox_scheduler", + "image": "archivebox/archivebox:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [ + "archivebox_sonic" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "archivebox/archivebox:latest", + "container_name": "archivebox_scheduler", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "restart": "unless-stopped", + "networks": [ + "archivebox_network" + ], + "depends_on": [ + "archivebox_sonic" + ], + "command": [ + "schedule", + "--foreground", + "--update", + "--every=day" + ], + "environment": [ + "TIMEOUT=120", + "SEARCH_BACKEND_ENGINE=sonic", + "SEARCH_BACKEND_HOST_NAME=archivebox_sonic", + "SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ] + } + }, + { + "name": "archivebox", + "image": "archivebox/archivebox:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "archivebox_sonic" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "archivebox/archivebox:latest", + "container_name": "archivebox", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "restart": "unless-stopped", + "networks": [ + "archivebox_network" + ], + "depends_on": [ + "archivebox_sonic" + ], + "ports": [ + { + "target": 8000, + "published": "18010", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "environment": [ + "ADMIN_USERNAME=archivebox", + "ADMIN_PASSWORD=${GENERATED_ADMIN_PASSWORD}", + "ALLOWED_HOSTS=*", + "CSRF_TRUSTED_ORIGINS=*", + "PUBLIC_INDEX=True", + "PUBLIC_SNAPSHOTS=True", + "PUBLIC_ADD_VIEW=False", + "SEARCH_BACKEND_ENGINE=sonic", + "SEARCH_BACKEND_HOST_NAME=archivebox_sonic", + "SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}" + ], + "healthcheck": { + "test": [ + "CMD", + "wget", + "--no-verbose", + "--tries=1", + "--spider", + "http://localhost:8000" + ], + "interval": "1m", + "timeout": "3s" + } + } + } + ], + "top_level": { + "name": "archivebox", + "networks": { + "archivebox_network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "archivebox-volume-0", + "service": "archivebox", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for archivebox:/data" + }, + { + "id": "archivebox-scheduler-volume-0", + "service": "archivebox_scheduler", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for archivebox_scheduler:/data" + }, + { + "id": "archivebox-sonic-volume-0", + "service": "archivebox_sonic", + "container_path": "/var/lib/sonic/store", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 4, + "start_order": [ + "archivebox_novnc", + "archivebox_sonic", + "archivebox_scheduler", + "archivebox" + ], + "stop_order": [ + "archivebox", + "archivebox_scheduler", + "archivebox_sonic", + "archivebox_novnc" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "archivebox", + "environment_variable": "ADMIN_PASSWORD" + } + ] + }, + { + "id": "search-backend-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "archivebox", + "environment_variable": "SEARCH_BACKEND_PASSWORD" + }, + { + "service": "archivebox_scheduler", + "environment_variable": "SEARCH_BACKEND_PASSWORD" + }, + { + "service": "archivebox_sonic", + "environment_variable": "SEARCH_BACKEND_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "startup_healthcheck": { + "type": "http", + "scheme": "http", + "port": 8000, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 3, + "stability_seconds": 0, + "verify_tls": true, + "required": true, + "source": "compose-healthcheck" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "pending-per-application" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "archivebox_novnc: perfil de salud y persistencia pendiente", + "archivebox_scheduler: perfil de salud y persistencia pendiente", + "archivebox_sonic: perfil de salud y persistencia pendiente", + "volumen compartido entre servicios pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:archivebox_scheduler:compose-key:depends_on", + "service:archivebox_sonic:compose-key:expose", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ardour.json b/oci/catalog/apps/ardour.json new file mode 100644 index 00000000..cf289f04 --- /dev/null +++ b/oci/catalog/apps/ardour.json @@ -0,0 +1,369 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ardour", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ardour" + }, + "tagline": { + "en_US": "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers." + }, + "description": { + "en_US": "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ardour-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ardour-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://ardour.org/", + "documentation": "https://docs.linuxserver.io/images/docker-ardour/", + "repository": "https://github.com/linuxserver/docker-ardour", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-04-10", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ardour", + "default_branch": "master", + "revision": "2898fb09d627ed1399438ed0bc3efc7db4d685bb", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ardour/2898fb09d627ed1399438ed0bc3efc7db4d685bb/README.md", + "readme_pushed_at": "2026-06-25T16:52:13Z", + "compose_sha256": "68999431889fb890df586871ef191da31793aabfd0a9a5198f70e481dc6d672a", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "ardour", + "container_name": "ardour", + "image": { + "reference": "lscr.io/linuxserver/ardour:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ardour", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ardour:\n image: lscr.io/linuxserver/ardour:latest\n container_name: ardour\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-ardour/master/Dockerfile", + "dockerfile_sha256": "9446e3b76e6b52a395a1641520f5306eae58f9b5f0d167ff3827f132af63e5b2", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/audacity.json b/oci/catalog/apps/audacity.json new file mode 100644 index 00000000..8946046f --- /dev/null +++ b/oci/catalog/apps/audacity.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-audacity", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Audacity" + }, + "tagline": { + "en_US": "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source." + }, + "description": { + "en_US": "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/audacity-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/audacity-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.audacityteam.org/", + "documentation": "https://docs.linuxserver.io/images/docker-audacity/", + "repository": "https://github.com/linuxserver/docker-audacity", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-29", + "note": "Rebase to resolute." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-10-31", + "note": "Fix artifact name." + } + ], + "display_version": null, + "updated_at": "2026-04-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-audacity", + "default_branch": "main", + "revision": "d4dd141287260983154a2e9e6e4371ee35962ac1", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-audacity/d4dd141287260983154a2e9e6e4371ee35962ac1/README.md", + "readme_pushed_at": "2026-09-08T09:28:27Z", + "compose_sha256": "b01ce49ed7c4754968665fc392170d1d917f04146fa95b9b8c61e7e7053d300b", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "audacity", + "container_name": "audacity", + "image": { + "reference": "lscr.io/linuxserver/audacity:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/audacity", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/audacity/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n audacity:\n image: lscr.io/linuxserver/audacity:latest\n container_name: audacity\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/audacity/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-audacity/master/Dockerfile", + "dockerfile_sha256": "3feef0cf6583765091dae20ab79c21095c9a651e9d8b0f8edd05b3154c12584f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/audiobookshelf.json b/oci/catalog/apps/audiobookshelf.json new file mode 100644 index 00000000..6096ed41 --- /dev/null +++ b/oci/catalog/apps/audiobookshelf.json @@ -0,0 +1,476 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-audiobookshelf", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Audiobookshelf" + }, + "tagline": { + "en_US": "Audiobookshelf is a self-hosted audiobook and podcast server." + }, + "description": { + "en_US": "Audiobookshelf is a self-hosted media server designed for managing and streaming audiobooks, podcasts, and e-books, offering a secure and flexible solution for personal media libraries. Its lightweight architecture and intuitive Web interface (available as a Progressive Web App, PWA) enable seamless access from any browser, while beta Android and iOS apps support offline listening, catering to privacy-focused media enthusiasts.\n\nThe app supports on-the-fly streaming of all audio formats and provides robust management tools, including automatic metadata and cover art fetching from multiple sources, bulk drag-and-drop uploads for books and podcasts, and chapter editing with lookup via the Audnexus API. Users can search and subscribe to podcasts with auto-downloading episodes or manage content via open RSS feeds. It supports multi-user access with custom permissions, ensuring individual playback progress syncs across devices. Additionally, it offers audio tools (like merging files into m4b or embedding metadata) and experimental e-book support (epub, pdf, cbr, cbz), with the ability to send e-books to devices like Kindle.\n\nIt automatically detects library updates, eliminating manual rescans, and includes daily automated backups to safeguard metadata. Chromecast support (on Web and Android apps) enhances streaming capabilities, while an active community provides support documentation for continuous improvements. Whether for personal collections or family sharing, the app's intuitive interface and versatile features deliver a modern media management platform, meeting diverse needs.\n\n**Key Features:**\n- Multi-user support w/ custom permissions\n- Keeps progress per user and syncs across devices\n- Lookup and apply metadata and cover art from several providers\n- Audiobook chapter editor w/ chapter lookup\n- Audiobook tools: Embed metadata in audio files & merge multiple audio files to a single m4b\n- Search and add podcasts to download episodes w/ auto-download\n- Open RSS feeds for audiobooks and podcast episodes\n- Backups with automated backup scheduling\n- Basic ebook support and ereader (epub, pdf, cbr, cbz) + send to device (i.e. Kindle)\n\n**Learn More:**\n- [Audiobookshelf Official Website](https://audiobookshelf.org)\n- [Audiobookshelf GitHub Repository](https://github.com/advplyr/audiobookshelf)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "advplyr", + "developer": "advplyr", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://audiobookshelf.org", + "documentation": null, + "repository": "https://ghcr.io/advplyr/audiobookshelf", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "advplyr", + "repository": "https://ghcr.io/advplyr/audiobookshelf", + "revision": "9d718efdc366f5df43bbc93cf4de5854828553bb3321addaf7b2d084202ef220", + "image_repository_url": "https://ghcr.io/advplyr/audiobookshelf", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "9d718efdc366f5df43bbc93cf4de5854828553bb3321addaf7b2d084202ef220", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "audiobookshelf", + "container_name": "audiobookshelf", + "image": { + "reference": "ghcr.io/advplyr/audiobookshelf:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/advplyr/audiobookshelf", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/audiobooks", + "compose_source_example": "/DATA/Media/Audiobooks", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/podcasts", + "compose_source_example": "/DATA/Media/Podcasts", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-3", + "container_path": "/metadata", + "compose_source_example": "/DATA/AppData/$AppID/metadata", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 13378, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: audiobookshelf\nservices:\n audiobookshelf:\n image: ghcr.io/advplyr/audiobookshelf:latest\n container_name: audiobookshelf\n deploy:\n resources:\n reservations:\n memory: 64M\n restart: unless-stopped\n volumes:\n - /DATA/Media/Audiobooks:/audiobooks\n - /DATA/Media/Podcasts:/podcasts\n - /DATA/AppData/$AppID/config:/config\n - /DATA/AppData/$AppID/metadata:/metadata\n ports:\n - 13378:80\n" + }, + "compose_stack": { + "project_name": "audiobookshelf", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "audiobookshelf", + "service_count": 1, + "services": [ + { + "name": "audiobookshelf", + "image": "ghcr.io/advplyr/audiobookshelf:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/advplyr/audiobookshelf:latest", + "container_name": "audiobookshelf", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "restart": "unless-stopped", + "volumes": [ + "/DATA/Media/Audiobooks:/audiobooks", + "/DATA/Media/Podcasts:/podcasts", + "/DATA/AppData/$AppID/config:/config", + "/DATA/AppData/$AppID/metadata:/metadata" + ], + "ports": [ + "13378:80" + ] + } + } + ], + "top_level": { + "name": "audiobookshelf" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "audiobookshelf-volume-0", + "service": "audiobookshelf", + "container_path": "/audiobooks", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "audiobookshelf-volume-1", + "service": "audiobookshelf", + "container_path": "/podcasts", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "audiobookshelf-volume-2", + "service": "audiobookshelf", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "audiobookshelf-volume-3", + "service": "audiobookshelf", + "container_path": "/metadata", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "audiobookshelf" + ], + "stop_order": [ + "audiobookshelf" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/autobrr.json b/oci/catalog/apps/autobrr.json new file mode 100644 index 00000000..5df54d99 --- /dev/null +++ b/oci/catalog/apps/autobrr.json @@ -0,0 +1,405 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-autobrr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Autobrr" + }, + "tagline": { + "en_US": "Modern, easy to use download automation for torrents and usenet." + }, + "description": { + "en_US": "Autobrr is the modern download automation tool for torrents and usenet. With inspiration and ideas from tools like trackarr, autodl-irssi and flexget we built one tool that can do it all, and then some." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "Autobrr Team", + "developer": "Autobrr Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 7474, + "path": "/" + }, + "website": "https://autobrr.com", + "documentation": null, + "repository": "https://ghcr.io/autobrr/autobrr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/autobrr/autobrr", + "revision": "d33fd5e67068324754ca3a0f1345efc2893dabe5fb06c65ada9910b9254fb4b7", + "image_repository_url": "https://ghcr.io/autobrr/autobrr", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "d33fd5e67068324754ca3a0f1345efc2893dabe5fb06c65ada9910b9254fb4b7", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "autobrr", + "container_name": "autobrr", + "image": { + "reference": "ghcr.io/autobrr/autobrr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/autobrr/autobrr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 7474, + "published_example": 7474, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: autobrr\nservices:\n autobrr:\n container_name: autobrr\n image: ghcr.io/autobrr/autobrr:latest\n network_mode: bridge\n restart: unless-stopped\n environment:\n TZ: $TZ\n ports:\n - target: 7474\n published: '7474'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n" + }, + "compose_stack": { + "project_name": "autobrr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "autobrr", + "service_count": 1, + "services": [ + { + "name": "autobrr", + "image": "ghcr.io/autobrr/autobrr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "autobrr", + "image": "ghcr.io/autobrr/autobrr:latest", + "network_mode": "bridge", + "restart": "unless-stopped", + "environment": { + "TZ": "$TZ" + }, + "ports": [ + { + "target": 7474, + "published": "7474", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + } + ] + } + } + ], + "top_level": { + "name": "autobrr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "autobrr-volume-0", + "service": "autobrr", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "autobrr" + ], + "stop_order": [ + "autobrr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7474, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/azahar.json b/oci/catalog/apps/azahar.json new file mode 100644 index 00000000..c60dc9d5 --- /dev/null +++ b/oci/catalog/apps/azahar.json @@ -0,0 +1,264 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-azahar", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Azahar" + }, + "tagline": { + "en_US": "Azahar is an open-source 3DS emulator based on Citra." + }, + "description": { + "en_US": "Azahar is an open-source 3DS emulator based on Citra." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/azahar-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/azahar-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://azahar-emu.org/", + "documentation": "https://docs.linuxserver.io/images/docker-azahar/", + "repository": "https://github.com/linuxserver/docker-azahar", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-11-29", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-03-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-azahar", + "default_branch": "master", + "revision": "1f07417fbd6757438809cbaaf834961708799842", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-azahar/1f07417fbd6757438809cbaaf834961708799842/README.md", + "readme_pushed_at": "2026-09-12T04:47:01Z", + "compose_sha256": "c1db41560f28bb74cf13239c12b31d5983ad42f669b64579887c8b43ded40bdb", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "azahar", + "container_name": "azahar", + "image": { + "reference": "lscr.io/linuxserver/azahar:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/azahar", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n azahar:\n image: lscr.io/linuxserver/azahar:latest\n container_name: azahar\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/babybuddy.json b/oci/catalog/apps/babybuddy.json new file mode 100644 index 00000000..3c0f7acd --- /dev/null +++ b/oci/catalog/apps/babybuddy.json @@ -0,0 +1,248 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-babybuddy", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Babybuddy" + }, + "tagline": { + "en_US": "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work." + }, + "description": { + "en_US": "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/babybuddy-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/babybuddy-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://github.com/babybuddy/babybuddy", + "documentation": "https://docs.linuxserver.io/images/docker-babybuddy/", + "repository": "https://github.com/linuxserver/docker-babybuddy", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-21", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-06-30", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19 with php 8.3." + }, + { + "date": "2023-07-05", + "note": "Add standard HTTP/HTTPS listen ports 80 and 443, keeping 8000 for backwards compatibility." + } + ], + "display_version": null, + "updated_at": "2026-07-21" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-babybuddy", + "default_branch": "main", + "revision": "8743066585b4d5e07385ff33371ec56f6ca5988a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-babybuddy/8743066585b4d5e07385ff33371ec56f6ca5988a/README.md", + "readme_pushed_at": "2026-09-12T14:25:14Z", + "compose_sha256": "2918bb204dae64bf4f514de2bfa19f51424c94f19445478aca3a13c60fcb64ef", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "babybuddy", + "container_name": "babybuddy", + "image": { + "reference": "lscr.io/linuxserver/babybuddy:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/babybuddy", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CSRF_TRUSTED_ORIGINS", + "example": "http://127.0.0.1:8000,https://babybuddy.domain.com", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/babybuddy/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n babybuddy:\n image: lscr.io/linuxserver/babybuddy:latest\n container_name: babybuddy\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - CSRF_TRUSTED_ORIGINS=http://127.0.0.1:8000,https://babybuddy.domain.com\n volumes:\n - /path/to/babybuddy/config:/config\n ports:\n - 8000:8000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/bambustudio.json b/oci/catalog/apps/bambustudio.json new file mode 100644 index 00000000..c1779463 --- /dev/null +++ b/oci/catalog/apps/bambustudio.json @@ -0,0 +1,279 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-bambustudio", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Bambustudio" + }, + "tagline": { + "en_US": "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience." + }, + "description": { + "en_US": "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bambustudio-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bambustudio-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://bambulab.com/en/download/studio", + "documentation": "https://docs.linuxserver.io/images/docker-bambustudio/", + "repository": "https://github.com/linuxserver/docker-bambustudio", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-29", + "note": "Rebase to resolute." + }, + { + "date": "2026-04-11", + "note": "Ingest from pre-release, make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-31", + "note": "Update AppImage ingestion." + }, + { + "date": "2025-08-14", + "note": "Rebase to Ubuntu Noble to ingest approved appimage." + } + ], + "display_version": null, + "updated_at": "2026-04-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-bambustudio", + "default_branch": "master", + "revision": "3d3bba442d60a77c4165b7023530aa9a94618d83", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-bambustudio/3d3bba442d60a77c4165b7023530aa9a94618d83/README.md", + "readme_pushed_at": "2026-09-12T09:25:40Z", + "compose_sha256": "0e5ff6cd158cab73096ed4c4ddebb4795a78ba2ed9d776c568b5caad4a008659", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "bambustudio", + "container_name": "bambustudio", + "image": { + "reference": "lscr.io/linuxserver/bambustudio:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/bambustudio", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DARK_MODE", + "example": "true", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/bambustudio/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n bambustudio:\n image: lscr.io/linuxserver/bambustudio:latest\n container_name: bambustudio\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DARK_MODE=true #optional\n volumes:\n - /path/to/bambustudio/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/bazarr.json b/oci/catalog/apps/bazarr.json new file mode 100644 index 00000000..e9d824ac --- /dev/null +++ b/oci/catalog/apps/bazarr.json @@ -0,0 +1,275 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-bazarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Bazarr" + }, + "tagline": { + "en_US": "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you." + }, + "description": { + "en_US": "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bazarr-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bazarr-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6767, + "path": "/" + }, + "website": "https://www.bazarr.media/", + "documentation": "https://docs.linuxserver.io/images/docker-bazarr/", + "repository": "https://github.com/linuxserver/docker-bazarr", + "tips": [], + "mini_changelog": [ + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-24", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-24", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2025-12-28" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-bazarr", + "default_branch": "master", + "revision": "2154b521ffbee2deaece8abb9684fb3c275825a9", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-bazarr/2154b521ffbee2deaece8abb9684fb3c275825a9/README.md", + "readme_pushed_at": "2026-09-09T14:47:26Z", + "compose_sha256": "3734d559f54c05209e16a08310439640bd13c410b4efc8ea903e72f5760bf6ae", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "bazarr", + "container_name": "bazarr", + "image": { + "reference": "lscr.io/linuxserver/bazarr:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/bazarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/bazarr/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/movies", + "compose_source_example": "/path/to/movies", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/tv", + "compose_source_example": "/path/to/tv", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 6767, + "published_example": 6767, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n bazarr:\n image: lscr.io/linuxserver/bazarr:latest\n container_name: bazarr\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/bazarr/config:/config\n - /path/to/movies:/movies #optional\n - /path/to/tv:/tv #optional\n ports:\n - 6767:6767\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6767, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/beaverhabittracker.json b/oci/catalog/apps/beaverhabittracker.json new file mode 100644 index 00000000..cf2c523e --- /dev/null +++ b/oci/catalog/apps/beaverhabittracker.json @@ -0,0 +1,444 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-beaverhabittracker", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "BeaverHabitTracker" + }, + "tagline": { + "en_US": "A self-hosted, goal-free habit tracking tool." + }, + "description": { + "en_US": "Beaver Habit Tracker is a self-hosted habit tracking tool designed for users who want to effortlessly monitor daily behaviors without the stress of goal-setting. Its intuitive Web interface offers a pressure-free tracking experience, ideal for those focused on behavior observation and personal growth.\n\nThe tool's core features include goal-free habit tracking and a minimalist interface. It allows users to log multiple habits easily, without focusing on streaks or targets, and provides simple visualizations to understand behavior patterns. Users can add daily notes to record specific activities or reflections, with a smooth, low-effort interface.\n\nIt uses a self-hosted approach, ensuring data privacy and full control, with a lightweight, efficient design requiring minimal server resources. Users can manually reorder habits for an optimized experience. The tool's stress-free observation and intuitive operation help users gradually improve habits, delivering a modern habit management solution.\n\n**Key Features:**\n- Goal-free habit tracking focused on awareness, not achievement\n- Clean, minimalist interface for effortless daily logging\n- Lightweight and efficient, requiring minimal server resources\n- Simple visualizations to understand behavior patterns\n- Daily notes for recording activities or reflections\n\n**Learn More:**\n- [Beaver Habit Tracker Official Website](https://beaverhabits.com/)\n- [Beaver Habit Tracker GitHub](https://github.com/daya0576/beaverhabits)\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "daya0576", + "developer": "daya0576", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://beaverhabits.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/daya0576/beaverhabits", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "daya0576", + "repository": "https://hub.docker.com/r/daya0576/beaverhabits", + "revision": "5f7669fb9cdd5e2af81fea312b3747b782866673efa53c37096b54b64e6edb79", + "image_repository_url": "https://hub.docker.com/r/daya0576/beaverhabits", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "5f7669fb9cdd5e2af81fea312b3747b782866673efa53c37096b54b64e6edb79", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "beaverhabittracker", + "container_name": "beaverhabittracker", + "image": { + "reference": "daya0576/beaverhabits:latest", + "registry": "docker.io", + "repository": "daya0576/beaverhabits", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "HABITS_STORAGE", + "example": "USER_DISK", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TRUSTED_LOCAL_EMAIL", + "example": "your@email.com", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "INDEX_HABIT_DATE_COLUMNS", + "example": "5", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ENABLE_IOS_STANDALONE", + "example": "True", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/.user", + "compose_source_example": "/DATA/AppData/$AppID/", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 15580, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: beaverhabittracker\nservices:\n beaverhabittracker:\n image: daya0576/beaverhabits:latest\n container_name: beaverhabittracker\n deploy:\n resources:\n limits:\n memory: 128M\n reservations:\n memory: 128M\n restart: unless-stopped\n user: 1000:1000\n ports:\n - target: 8080\n published: '15580'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/\n target: /app/.user\n environment:\n HABITS_STORAGE: USER_DISK\n TRUSTED_LOCAL_EMAIL: your@email.com\n INDEX_HABIT_DATE_COLUMNS: 5\n ENABLE_IOS_STANDALONE: true\n" + }, + "compose_stack": { + "project_name": "beaverhabittracker", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "beaverhabittracker", + "service_count": 1, + "services": [ + { + "name": "beaverhabittracker", + "image": "daya0576/beaverhabits:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "daya0576/beaverhabits:latest", + "container_name": "beaverhabittracker", + "deploy": { + "resources": { + "limits": { + "memory": "128M" + }, + "reservations": { + "memory": "128M" + } + } + }, + "restart": "unless-stopped", + "user": "1000:1000", + "ports": [ + { + "target": 8080, + "published": "15580", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/", + "target": "/app/.user" + } + ], + "environment": { + "HABITS_STORAGE": "USER_DISK", + "TRUSTED_LOCAL_EMAIL": "your@email.com", + "INDEX_HABIT_DATE_COLUMNS": 5, + "ENABLE_IOS_STANDALONE": true + } + } + } + ], + "top_level": { + "name": "beaverhabittracker" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "beaverhabittracker-volume-0", + "service": "beaverhabittracker", + "container_path": "/app/.user", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "beaverhabittracker" + ], + "stop_order": [ + "beaverhabittracker" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "user": "1000:1000" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/beets.json b/oci/catalog/apps/beets.json new file mode 100644 index 00000000..7ee06065 --- /dev/null +++ b/oci/catalog/apps/beets.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-beets", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Beets" + }, + "tagline": { + "en_US": "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools." + }, + "description": { + "en_US": "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/beets-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/beets-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8337, + "path": "/" + }, + "website": "http://beets.io/", + "documentation": "https://docs.linuxserver.io/images/docker-beets/", + "repository": "https://github.com/linuxserver/docker-beets", + "tips": [], + "mini_changelog": [ + { + "date": "2026-02-01", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-01-27", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-10-01", + "note": "Add packages required for Discogs plugin." + }, + { + "date": "2024-08-28", + "note": "Rebase to Alpine 3.20, switch from Pillow to Imagemagick." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2026-02-01" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-beets", + "default_branch": "master", + "revision": "c39f8f901aa1caddaaad6265801e853c57fc85f3", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-beets/c39f8f901aa1caddaaad6265801e853c57fc85f3/README.md", + "readme_pushed_at": "2026-09-12T11:36:37Z", + "compose_sha256": "ba0e36161687eb34fb5a33a9f7a2762c52d84f527e856141cfafcfc1c95f07a4", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "beets", + "container_name": "beets", + "image": { + "reference": "lscr.io/linuxserver/beets:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/beets", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/beets/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/music", + "compose_source_example": "/path/to/music/library", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/path/to/ingest", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8337, + "published_example": 8337, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n beets:\n image: lscr.io/linuxserver/beets:latest\n container_name: beets\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/beets/config:/config\n - /path/to/music/library:/music\n - /path/to/ingest:/downloads\n ports:\n - 8337:8337\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8337, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/bentopdf.json b/oci/catalog/apps/bentopdf.json new file mode 100644 index 00000000..862771af --- /dev/null +++ b/oci/catalog/apps/bentopdf.json @@ -0,0 +1,418 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-bentopdf", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "BentoPDF" + }, + "tagline": { + "en_US": "Privacy-first, self-hosted PDF toolkit" + }, + "description": { + "en_US": "**Your PDFs never leave your device.** BentoPDF is a privacy-first PDF toolkit that runs entirely in your browser. Every merge, split, conversion, and edit happens locally on your machine \u2014 no file is ever uploaded to a server. More than 50 tools are bundled into one clean, fast, ad-free interface.\n\n**One app for every PDF job.** Organize and edit your documents (merge, split, reorder, rotate, crop, watermark, page numbers, redaction, annotations and forms), convert to and from PDF (images, Word, Excel, PowerPoint, EPUB, Markdown and more), run OCR, and secure your files with compression, encryption, digital signatures, and metadata cleanup.\n\n**Made for your private cloud.** Self-hosting BentoPDF on a private cloud device like self-hosted server gives your whole household or team a single, ad-free PDF workshop on hardware you control \u2014 fast over the local network, with your documents staying private by design.\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "BentoPDF", + "developer": "BentoPDF", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://bentopdf.com", + "documentation": null, + "repository": "https://ghcr.io/alam00000/bentopdf-simple", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "alam00000", + "repository": "https://ghcr.io/alam00000/bentopdf-simple", + "revision": "96324c7dd23e8982ccdab09487f254e7ffaec5b9f9a143530ed8732e053d366d", + "image_repository_url": "https://ghcr.io/alam00000/bentopdf-simple", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "96324c7dd23e8982ccdab09487f254e7ffaec5b9f9a143530ed8732e053d366d", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "bentopdf", + "container_name": "bentopdf", + "image": { + "reference": "ghcr.io/alam00000/bentopdf-simple:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/alam00000/bentopdf-simple", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DISABLE_IPV6", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 8080, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: bentopdf\nservices:\n bentopdf:\n container_name: bentopdf\n image: ghcr.io/alam00000/bentopdf-simple:latest\n network_mode: bridge\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 64M\n ports:\n - target: 8080\n published: '3000'\n protocol: tcp\n environment:\n PUID: $PUID\n PGID: $PGID\n DISABLE_IPV6: 'false'\n healthcheck:\n test:\n - CMD\n - wget\n - --spider\n - -q\n - http://localhost:8080\n interval: 30s\n timeout: 10s\n retries: 3\n" + }, + "compose_stack": { + "project_name": "bentopdf", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "bentopdf", + "service_count": 1, + "services": [ + { + "name": "bentopdf", + "image": "ghcr.io/alam00000/bentopdf-simple:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "bentopdf", + "image": "ghcr.io/alam00000/bentopdf-simple:latest", + "network_mode": "bridge", + "restart": "unless-stopped", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "ports": [ + { + "target": 8080, + "published": "3000", + "protocol": "tcp" + } + ], + "environment": { + "PUID": "$PUID", + "PGID": "$PGID", + "DISABLE_IPV6": "false" + }, + "healthcheck": { + "test": [ + "CMD", + "wget", + "--spider", + "-q", + "http://localhost:8080" + ], + "interval": "30s", + "timeout": "10s", + "retries": 3 + } + } + } + ], + "top_level": { + "name": "bentopdf" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "bentopdf" + ], + "stop_order": [ + "bentopdf" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "startup_healthcheck": { + "type": "http", + "scheme": "http", + "port": 8080, + "path": "/", + "timeout_seconds": 90, + "request_timeout_seconds": 10, + "stability_seconds": 0, + "verify_tls": true, + "required": true, + "source": "compose-healthcheck" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "pending-per-application" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/bitcoin-knots.json b/oci/catalog/apps/bitcoin-knots.json new file mode 100644 index 00000000..2ac7e2eb --- /dev/null +++ b/oci/catalog/apps/bitcoin-knots.json @@ -0,0 +1,247 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-bitcoin-knots", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Bitcoin Knots" + }, + "tagline": { + "en_US": "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services." + }, + "description": { + "en_US": "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bitcoin-knots-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bitcoin-knots-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://bitcoinknots.org/", + "documentation": "https://docs.linuxserver.io/images/docker-bitcoin-knots/", + "repository": "https://github.com/linuxserver/docker-bitcoin-knots", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-01-02", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-09", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-bitcoin-knots", + "default_branch": "master", + "revision": "99c701f2f45d30332f4373da61890f929d28fc1b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-bitcoin-knots/99c701f2f45d30332f4373da61890f929d28fc1b/README.md", + "readme_pushed_at": "2026-09-07T22:37:03Z", + "compose_sha256": "82c572ab0c919634609abe1d9a4c583ed8fea6e0f2800f7deb9863241a03951e", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "bitcoin-knots", + "container_name": "bitcoin-knots", + "image": { + "reference": "lscr.io/linuxserver/bitcoin-knots:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/bitcoin-knots", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/bitcoin-knots/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8333, + "published_example": 8333, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n bitcoin-knots:\n image: lscr.io/linuxserver/bitcoin-knots:latest\n container_name: bitcoin-knots\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/bitcoin-knots/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n - 8333:8333\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/blade-of-agony.json b/oci/catalog/apps/blade-of-agony.json new file mode 100644 index 00000000..0c3731cf --- /dev/null +++ b/oci/catalog/apps/blade-of-agony.json @@ -0,0 +1,256 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-blade-of-agony", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Blade Of Agony" + }, + "tagline": { + "en_US": "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom." + }, + "description": { + "en_US": "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/blade-of-agony-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/blade-of-agony-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://boa.realm667.com/", + "documentation": "https://docs.linuxserver.io/images/docker-blade-of-agony/", + "repository": "https://github.com/linuxserver/docker-blade-of-agony", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-26", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-26" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-blade-of-agony", + "default_branch": "master", + "revision": "ecd3048e450ae26d4da48c7cf90d4b4cb7a3bd9e", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-blade-of-agony/ecd3048e450ae26d4da48c7cf90d4b4cb7a3bd9e/README.md", + "readme_pushed_at": "2026-09-10T20:27:01Z", + "compose_sha256": "23ee58f6f420b01cfb66258159b7441ce268b7b23a4e18dfc65729480c35314e", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "blade-of-agony", + "container_name": "blade-of-agony", + "image": { + "reference": "lscr.io/linuxserver/blade-of-agony:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/blade-of-agony", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n blade-of-agony:\n image: lscr.io/linuxserver/blade-of-agony:latest\n container_name: blade-of-agony\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/blender.json b/oci/catalog/apps/blender.json new file mode 100644 index 00000000..21d6ac41 --- /dev/null +++ b/oci/catalog/apps/blender.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-blender", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Blender" + }, + "tagline": { + "en_US": "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**" + }, + "description": { + "en_US": "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/blender-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/blender-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.blender.org/", + "documentation": "https://docs.linuxserver.io/images/docker-blender/", + "repository": "https://github.com/linuxserver/docker-blender", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to resolute." + }, + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-27", + "note": "Add wayland init logic." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-08-19", + "note": "Rebase to noble." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-blender", + "default_branch": "master", + "revision": "4b6aa4535da82e95ac2c337ebfc8888ed277c47a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-blender/4b6aa4535da82e95ac2c337ebfc8888ed277c47a/README.md", + "readme_pushed_at": "2026-09-10T18:27:11Z", + "compose_sha256": "30f4f98e9d9e1cd1a51dd3f8f6a0f0b3306126dd75ab60124700a47b5dd764dd", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "blender", + "container_name": "blender", + "image": { + "reference": "lscr.io/linuxserver/blender:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/blender", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/blender/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n blender:\n image: lscr.io/linuxserver/blender:latest\n container_name: blender\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/blender/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-blender/master/Dockerfile", + "dockerfile_sha256": "c8595b28e544bd2e573052b84a494cff4a2a17c201f10828fe1065b1453a2e68", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/blinko.json b/oci/catalog/apps/blinko.json new file mode 100644 index 00000000..19185ee5 --- /dev/null +++ b/oci/catalog/apps/blinko.json @@ -0,0 +1,581 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-blinko", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Blinko" + }, + "tagline": { + "en_US": "Blinko is an AI-powered card note-taking project. Designed for individuals who want to quickly capture and organize their fleeting thoughts. Blinko allows users to seamlessly jot down ideas the moment they strike, ensuring that no spark of creativity is lost." + }, + "description": { + "en_US": "Blinko is an open-source personal knowledge management and information recording platform, focused on providing users with a lightweight, efficient, and scalable note-taking and knowledge organization experience. Through modular design and a modern technology stack, it enables users to quickly capture ideas, organize knowledge, and build their own information system.\n\nThe project emphasizes simplicity and customizability, supporting flexible combinations of various content types (text, tags, links, etc.), while its clear structured design helps users efficiently retrieve and connect information. Blinko also provides excellent extensibility, making it easy for developers to customize and enhance functionality according to their needs.\n\nIn practical use, Blinko balances usability and functionality, offering a smooth experience for daily note-taking, knowledge accumulation, or project document management - an ideal knowledge tool for long-term personal growth.\n\n**Main features:**\n\n- Lightweight note system for quick content recording and editing\n- Tags and structured organization to improve information retrieval efficiency\n- Support for multiple content types (text, links, etc.)\n- Extensible architecture for custom functionality and plugin development\n- Clean interface design focused on content rather than complex operations\n\n**Learn more:**\n\n- [Blinko GitHub](https://github.com/blinkospace/blinko)\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "blinkospace", + "developer": "blinkospace", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 1111, + "path": "/" + }, + "website": "https://blinko.space/", + "documentation": null, + "repository": "https://hub.docker.com/r/blinkospace/blinko", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/blinkospace/blinko", + "revision": "84db2960a2d3880221937ab78a0b98c2a189c23b2b95b853507bea4397cad767", + "image_repository_url": "https://hub.docker.com/r/blinkospace/blinko", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "84db2960a2d3880221937ab78a0b98c2a189c23b2b95b853507bea4397cad767", + "generated_at": "2026-09-13T15:48:20+00:00" + }, + "container_contract": { + "service_name": "blinko", + "container_name": "blinko", + "image": { + "reference": "blinkospace/blinko:latest", + "registry": "docker.io", + "repository": "blinkospace/blinko", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "NODE_ENV", + "example": "production", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_URL", + "example": "http://localhost:1111", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXT_PUBLIC_BASE_URL", + "example": "http://localhost:1111", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_SECRET", + "example": "${GENERATED_NEXTAUTH_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "DATABASE_URL", + "example": "postgresql://postgres:JWD9bxUR7Um9PaGg7FQZ@blinko-postgres:5432/postgres", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/.blinko", + "compose_source_example": "/DATA/AppData/$AppID/blinko_data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 1111, + "published_example": 1111, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "blinko-postgres", + "image": "postgres:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: blinko\nservices:\n blinko:\n image: blinkospace/blinko:latest\n container_name: blinko\n restart: unless-stopped\n networks:\n - blinko-net\n depends_on:\n blinko-postgres:\n condition: service_healthy\n ports:\n - target: 1111\n published: '1111'\n protocol: tcp\n environment:\n NODE_ENV: production\n NEXTAUTH_URL: http://localhost:1111\n NEXT_PUBLIC_BASE_URL: http://localhost:1111\n NEXTAUTH_SECRET: ${GENERATED_NEXTAUTH_SECRET}\n DATABASE_URL: postgresql://postgres:JWD9bxUR7Um9PaGg7FQZ@blinko-postgres:5432/postgres\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/blinko_data\n target: /app/.blinko\n logging:\n options:\n max-size: 10m\n max-file: '3'\n deploy:\n resources:\n reservations:\n memory: 512m\n blinko-postgres:\n image: postgres:latest\n container_name: blinko-postgres\n restart: unless-stopped\n environment:\n POSTGRES_DB: postgres\n POSTGRES_USER: postgres\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n TZ: $TZ\n networks:\n - blinko-net\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/postgres_data\n target: /var/lib/postgresql/data\n deploy:\n resources:\n reservations:\n memory: 256m\n healthcheck:\n test:\n - CMD\n - pg_isready\n - -U\n - postgres\n - -d\n - postgres\n interval: 5s\n timeout: 10s\n retries: 5\nnetworks:\n blinko-net:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "blinko", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "blinko", + "service_count": 2, + "services": [ + { + "name": "blinko-postgres", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:latest", + "container_name": "blinko-postgres", + "restart": "unless-stopped", + "environment": { + "POSTGRES_DB": "postgres", + "POSTGRES_USER": "postgres", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "TZ": "$TZ" + }, + "networks": [ + "blinko-net" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/postgres_data", + "target": "/var/lib/postgresql/data" + } + ], + "deploy": { + "resources": { + "reservations": { + "memory": "256m" + } + } + }, + "healthcheck": { + "test": [ + "CMD", + "pg_isready", + "-U", + "postgres", + "-d", + "postgres" + ], + "interval": "5s", + "timeout": "10s", + "retries": 5 + } + } + }, + { + "name": "blinko", + "image": "blinkospace/blinko:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "blinko-postgres" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "blinkospace/blinko:latest", + "container_name": "blinko", + "restart": "unless-stopped", + "networks": [ + "blinko-net" + ], + "depends_on": { + "blinko-postgres": { + "condition": "service_healthy" + } + }, + "ports": [ + { + "target": 1111, + "published": "1111", + "protocol": "tcp" + } + ], + "environment": { + "NODE_ENV": "production", + "NEXTAUTH_URL": "http://localhost:1111", + "NEXT_PUBLIC_BASE_URL": "http://localhost:1111", + "NEXTAUTH_SECRET": "${GENERATED_NEXTAUTH_SECRET}", + "DATABASE_URL": "postgresql://postgres:JWD9bxUR7Um9PaGg7FQZ@blinko-postgres:5432/postgres" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/blinko_data", + "target": "/app/.blinko" + } + ], + "logging": { + "options": { + "max-size": "10m", + "max-file": "3" + } + }, + "deploy": { + "resources": { + "reservations": { + "memory": "512m" + } + } + } + } + } + ], + "top_level": { + "name": "blinko", + "networks": { + "blinko-net": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "blinko-volume-0", + "service": "blinko", + "container_path": "/app/.blinko", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "blinko-postgres-volume-0", + "service": "blinko-postgres", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "blinko-postgres", + "blinko" + ], + "stop_order": [ + "blinko", + "blinko-postgres" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "nextauth-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "blinko", + "environment_variable": "NEXTAUTH_SECRET" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "blinko-postgres", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 1111, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/boinc.json b/oci/catalog/apps/boinc.json new file mode 100644 index 00000000..24874f4d --- /dev/null +++ b/oci/catalog/apps/boinc.json @@ -0,0 +1,421 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-boinc", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Boinc" + }, + "tagline": { + "en_US": "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications." + }, + "description": { + "en_US": "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/boinc-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/boinc-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 8181, + "path": "/" + }, + "website": "https://boinc.berkeley.edu/", + "documentation": "https://docs.linuxserver.io/images/docker-boinc/", + "repository": "https://github.com/linuxserver/docker-boinc", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to resolute, make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-07", + "note": "Rebase to selkies. Breaking change: HTTPS is now required. Use port 8181 with HTTPS for direct access. Reverse proxies can connect to 8080 over http as long as it's served over HTTPS to the user." + }, + { + "date": "2024-08-19", + "note": "Rebase to noble." + }, + { + "date": "2024-02-10", + "note": "Update Readme with new env vars and ingest proper PWA icon." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-boinc", + "default_branch": "master", + "revision": "22ffe9988684021b9a1c5a254ef176d1c2dae3f9", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-boinc/22ffe9988684021b9a1c5a254ef176d1c2dae3f9/README.md", + "readme_pushed_at": "2026-09-08T15:56:45Z", + "compose_sha256": "ff70b5f9e428a6f9cc16db75d2d50a71cd3b99f11c28dc342cbd8c693eb8784e", + "generated_at": "2026-09-13T15:35:41+00:00" + }, + "container_contract": { + "service_name": "boinc", + "container_name": "boinc", + "image": { + "reference": "lscr.io/linuxserver/boinc:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/boinc", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/boinc/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8181, + "published_example": 8181, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n boinc:\n image: lscr.io/linuxserver/boinc:latest\n container_name: boinc\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - PASSWORD= #optional\n volumes:\n - /path/to/boinc/config:/config\n ports:\n - 8080:8080\n - 8181:8181\n devices:\n - /dev/dri:/dev/dri #optional\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 8181, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "enable_prompt": "VA-API video acceleration", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/dri:/dev/dri" + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + }, + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-boinc/master/Dockerfile", + "dockerfile_sha256": "dde889004f5e40e783d2aacc615dda55ae7fe0eac713423595bcb2fbd4b5c5bd", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/bookstack.json b/oci/catalog/apps/bookstack.json new file mode 100644 index 00000000..271b5266 --- /dev/null +++ b/oci/catalog/apps/bookstack.json @@ -0,0 +1,297 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-bookstack", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Bookstack" + }, + "tagline": { + "en_US": "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease." + }, + "description": { + "en_US": "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease." + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bookstack-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bookstack-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://codeberg.org/bookstack/bookstack", + "documentation": "https://docs.linuxserver.io/images/docker-bookstack/", + "repository": "https://github.com/linuxserver/docker-bookstack", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-05", + "note": "Run the async queue worker as the PUID/PGID-managed abc user." + }, + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-04-29", + "note": "Switch to pulling releases from [Codeberg](https://codeberg.org/bookstack/bookstack)." + }, + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + } + ], + "display_version": null, + "updated_at": "2026-08-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-bookstack", + "default_branch": "master", + "revision": "b36da9cac7b506f71fa1acc55528d6923db5b471", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-bookstack/b36da9cac7b506f71fa1acc55528d6923db5b471/README.md", + "readme_pushed_at": "2026-09-07T21:32:19Z", + "compose_sha256": "b0be2e3cba70b0ef414aeb81040f3bfbf970eaac0a8458103ab93c1859162498", + "generated_at": "2026-09-12T14:37:23+00:00" + }, + "container_contract": { + "service_name": "bookstack", + "container_name": "bookstack", + "image": { + "reference": "lscr.io/linuxserver/bookstack:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/bookstack", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_KEY", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "3306", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USERNAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_DATABASE", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "QUEUE_CONNECTION", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/bookstack/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 6875, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n bookstack:\n image: lscr.io/linuxserver/bookstack:latest\n container_name: bookstack\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - APP_URL=\n - APP_KEY=\n - DB_HOST=\n - DB_PORT=3306\n - DB_USERNAME=\n - DB_PASSWORD=\n - DB_DATABASE=\n - QUEUE_CONNECTION= #optional\n volumes:\n - /path/to/bookstack/config:/config\n ports:\n - 6875:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/brave.json b/oci/catalog/apps/brave.json new file mode 100644 index 00000000..086b3717 --- /dev/null +++ b/oci/catalog/apps/brave.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-brave", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Brave" + }, + "tagline": { + "en_US": "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile." + }, + "description": { + "en_US": "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/brave-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/brave-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://brave.com/", + "documentation": "https://docs.linuxserver.io/images/docker-brave/", + "repository": "https://github.com/linuxserver/docker-brave", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-20", + "note": "Added Brave Origin as origin tag." + }, + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-06-06", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-04-20" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-brave", + "default_branch": "master", + "revision": "f7b34939eb09b1a1414a70067e2eb57599e84f84", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-brave/f7b34939eb09b1a1414a70067e2eb57599e84f84/README.md", + "readme_pushed_at": "2026-09-11T17:22:56Z", + "compose_sha256": "0ac179828ccab3a0dfc105088fd5ab86652bfb5e25c406afe6d5083725da5f69", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "brave", + "container_name": "brave", + "image": { + "reference": "lscr.io/linuxserver/brave:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/brave", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n brave:\n image: lscr.io/linuxserver/brave:latest\n container_name: brave\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/budge.json b/oci/catalog/apps/budge.json new file mode 100644 index 00000000..7b3d73e3 --- /dev/null +++ b/oci/catalog/apps/budge.json @@ -0,0 +1,248 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-budge", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Budge" + }, + "tagline": { + "en_US": "budge is an open source 'budgeting with envelopes' personal finance app." + }, + "description": { + "en_US": "budge is an open source 'budgeting with envelopes' personal finance app." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/budge-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/budge-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/linuxserver/budge", + "documentation": "https://docs.linuxserver.io/images/docker-budge/", + "repository": "https://github.com/linuxserver/docker-budge", + "tips": [], + "mini_changelog": [ + { + "date": "2024-06-06", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-03-06", + "note": "Existing users should update: site-confs/default.conf - Cleanup default site conf." + }, + { + "date": "2024-03-06", + "note": "Rebase to Alpine 3.19 with php 8.3." + }, + { + "date": "2023-05-25", + "note": "Rebase to Alpine 3.18, deprecate armhf." + }, + { + "date": "2023-04-13", + "note": "Move ssl.conf include to default.conf." + } + ], + "display_version": null, + "updated_at": "2024-06-06" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-budge", + "default_branch": "main", + "revision": "6dc66fab7df7b12c131a0f13781051f6c3980b94", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-budge/6dc66fab7df7b12c131a0f13781051f6c3980b94/README.md", + "readme_pushed_at": "2026-06-28T06:11:17Z", + "compose_sha256": "1f0b8db2a184d63d095b475291c723a1a701b649589b726745c3780916dcffdd", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "budge", + "container_name": "budge", + "image": { + "reference": "lscr.io/linuxserver/budge:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/budge", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/budge/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n budge:\n image: lscr.io/linuxserver/budge:latest\n container_name: budge\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/budge/config:/config\n ports:\n - 80:80\n - 443:443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/calibre-web.json b/oci/catalog/apps/calibre-web.json new file mode 100644 index 00000000..47a7a93a --- /dev/null +++ b/oci/catalog/apps/calibre-web.json @@ -0,0 +1,279 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-calibre-web", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Calibre Web" + }, + "tagline": { + "en_US": "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself." + }, + "description": { + "en_US": "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calibre-web-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calibre-web-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8083, + "path": "/" + }, + "website": "https://github.com/janeczku/calibre-web", + "documentation": "https://docs.linuxserver.io/images/docker-calibre-web/", + "repository": "https://github.com/linuxserver/docker-calibre-web", + "tips": [], + "mini_changelog": [ + { + "date": "2025-10-28", + "note": "Add libxfixes3 and libasound2t64 to support epub to pdf conversion; also set --no-sandbox for qtwebengine." + }, + { + "date": "2025-01-07", + "note": "Set kepubify path by default." + }, + { + "date": "2024-12-05", + "note": "Rebase to noble." + }, + { + "date": "2024-08-26", + "note": "Add new dep, xdg-utils." + }, + { + "date": "2024-07-07", + "note": "Add new dep, libmagic1." + } + ], + "display_version": null, + "updated_at": "2025-10-28" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-calibre-web", + "default_branch": "master", + "revision": "6cf8ca68f272f1e5ffd1b673e9194a89e0162385", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-calibre-web/6cf8ca68f272f1e5ffd1b673e9194a89e0162385/README.md", + "readme_pushed_at": "2026-09-06T04:54:26Z", + "compose_sha256": "02a0710202f82692e0caaf389fd7c0bf0490ea54645130d5dc750067364e8079", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "calibre-web", + "container_name": "calibre-web", + "image": { + "reference": "lscr.io/linuxserver/calibre-web:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/calibre-web", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DOCKER_MODS", + "example": "linuxserver/mods:universal-calibre", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "OAUTHLIB_RELAX_TOKEN_SCOPE", + "example": "1", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/calibre-web/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/books", + "compose_source_example": "/path/to/calibre/library", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8083, + "published_example": 8083, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n calibre-web:\n image: lscr.io/linuxserver/calibre-web:latest\n container_name: calibre-web\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DOCKER_MODS=linuxserver/mods:universal-calibre #optional\n - OAUTHLIB_RELAX_TOKEN_SCOPE=1 #optional\n volumes:\n - /path/to/calibre-web/data:/config\n - /path/to/calibre/library:/books\n ports:\n - 8083:8083\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8083, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [ + { + "label": "Default login", + "username": "admin", + "password": "admin123", + "change_required": true, + "source": "linuxserver-readme-application-setup" + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/calibre.json b/oci/catalog/apps/calibre.json new file mode 100644 index 00000000..c2f3b40b --- /dev/null +++ b/oci/catalog/apps/calibre.json @@ -0,0 +1,522 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-calibre", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Calibre" + }, + "tagline": { + "en_US": "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts." + }, + "description": { + "en_US": "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calibre-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calibre-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 8181, + "path": "/" + }, + "website": "https://calibre-ebook.com/", + "documentation": "https://docs.linuxserver.io/images/docker-calibre/", + "repository": "https://github.com/linuxserver/docker-calibre", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to resolute." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-26", + "note": "Rebase to selkies. Breaking Change: HTTPS is now required. Either use a reverse proxy with SSL cert or direct connect to port 8181 with HTTPS." + }, + { + "date": "2024-08-19", + "note": "Rebase to noble." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-calibre", + "default_branch": "master", + "revision": "98221d60545c9fe8e48ab7fe228a5128516afe06", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-calibre/98221d60545c9fe8e48ab7fe228a5128516afe06/README.md", + "readme_pushed_at": "2026-09-09T12:02:26Z", + "compose_sha256": "e1fd4775d52a4f4dd89e7d54f800a43df01fc1ef886c48c5f2dc9725d88012a4", + "generated_at": "2026-09-13T17:20:15+00:00" + }, + "container_contract": { + "service_name": "calibre", + "container_name": "calibre", + "image": { + "reference": "lscr.io/linuxserver/calibre:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/calibre", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "CLI_ARGS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/calibre/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8181, + "published_example": 8181, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8081, + "published_example": 8081, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n calibre:\n image: lscr.io/linuxserver/calibre:latest\n container_name: calibre\n security_opt:\n - seccomp:unconfined #optional\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - PASSWORD= #optional\n - CLI_ARGS= #optional\n volumes:\n - /path/to/calibre/config:/config\n ports:\n - 8080:8080\n - 8181:8181\n - 8081:8081\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 8181, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "security": { + "optional_relaxations": [ + { + "id": "seccomp-unconfined", + "enable_prompt": "Apply optional security relaxation seccomp:unconfined", + "enabled_default": false, + "options": { + "seccomp_profile": "unconfined" + } + } + ] + }, + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-calibre/master/Dockerfile", + "dockerfile_sha256": "796c5ec2f20a2f4d6e7a58b3f5a0f6b171276301aee42a0ca81e9610128b5730", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": true, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": true, + "risk_level": "high", + "confirmation_required": false, + "warning": "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/calligra.json b/oci/catalog/apps/calligra.json new file mode 100644 index 00000000..3166d71c --- /dev/null +++ b/oci/catalog/apps/calligra.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-calligra", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Calligra" + }, + "tagline": { + "en_US": "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases." + }, + "description": { + "en_US": "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calligra-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calligra-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://calligra.org/", + "documentation": "https://docs.linuxserver.io/images/docker-calligra/", + "repository": "https://github.com/linuxserver/docker-calligra", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-30", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-02-10", + "note": "Update Readme with new env vars and ingest proper PWA icon." + } + ], + "display_version": null, + "updated_at": "2026-03-30" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-calligra", + "default_branch": "master", + "revision": "23fceaf96061494ab6e5fa051a45c427c63e4e37", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-calligra/23fceaf96061494ab6e5fa051a45c427c63e4e37/README.md", + "readme_pushed_at": "2026-09-10T14:06:16Z", + "compose_sha256": "3601c4ff56d52d7b2170968241ecfe3fa59e07692d5a637e102e010b09258b01", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "calligra", + "container_name": "calligra", + "image": { + "reference": "lscr.io/linuxserver/calligra:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/calligra", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n calligra:\n image: lscr.io/linuxserver/calligra:latest\n container_name: calligra\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-calligra/master/Dockerfile", + "dockerfile_sha256": "01cf24c40c88e48b5329fcf6fe5d95e74312ea327a11cb7c3ca6dd1fb24c4cb9", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/changedetection.io.json b/oci/catalog/apps/changedetection.io.json new file mode 100644 index 00000000..89ed87df --- /dev/null +++ b/oci/catalog/apps/changedetection.io.json @@ -0,0 +1,255 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-changedetection-io", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Changedetection.Io" + }, + "tagline": { + "en_US": "Changedetection.io provides free, open-source web page monitoring, notification and change detection." + }, + "description": { + "en_US": "Changedetection.io provides free, open-source web page monitoring, notification and change detection." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/changedetection.io-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/changedetection.io-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5000, + "path": "/" + }, + "website": "https://github.com/dgtlmoon/changedetection.io", + "documentation": "https://docs.linuxserver.io/images/docker-changedetection.io/", + "repository": "https://github.com/linuxserver/docker-changedetection.io", + "tips": [], + "mini_changelog": [ + { + "date": "2026-02-18", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-19", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-09", + "note": "Build Playwright from source because Microsoft's build and packaging process is awful." + } + ], + "display_version": null, + "updated_at": "2026-02-18" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-changedetection.io", + "default_branch": "main", + "revision": "dfd70e0e7be8f0e5fa49a2d01c4e59fee3543cd0", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-changedetection.io/dfd70e0e7be8f0e5fa49a2d01c4e59fee3543cd0/README.md", + "readme_pushed_at": "2026-09-10T10:18:30Z", + "compose_sha256": "441c4f6be9216566c29c73618c56d3e1a442dcf1cb45fab4b1d0f55eadadd825", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "changedetection", + "container_name": "changedetection", + "image": { + "reference": "lscr.io/linuxserver/changedetection.io:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/changedetection.io", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "BASE_URL", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PLAYWRIGHT_DRIVER_URL", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/changedetection/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 5000, + "published_example": 5000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n changedetection:\n image: lscr.io/linuxserver/changedetection.io:latest\n container_name: changedetection\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - BASE_URL= #optional\n - PLAYWRIGHT_DRIVER_URL= #optional\n volumes:\n - /path/to/changedetection/config:/config\n ports:\n - 5000:5000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/chatbot-ui.json b/oci/catalog/apps/chatbot-ui.json new file mode 100644 index 00000000..bb2d27e6 --- /dev/null +++ b/oci/catalog/apps/chatbot-ui.json @@ -0,0 +1,385 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-chatbot-ui", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Chatbot UI" + }, + "tagline": { + "en_US": "Open source chat UI for AI models" + }, + "description": { + "en_US": "Chatbot UI is an open source chat UI for AI models." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Mckay Wrigley", + "developer": "Mckay Wrigley", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://www.chatbotui.com", + "documentation": null, + "repository": "https://ghcr.io/mckaywrigley/chatbot-ui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "mckaywrigley", + "repository": "https://ghcr.io/mckaywrigley/chatbot-ui", + "revision": "48fafac56d17a021d929ffeba51168ad56dfab1d9093b28a1d9c4d6478c72746", + "image_repository_url": "https://ghcr.io/mckaywrigley/chatbot-ui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "48fafac56d17a021d929ffeba51168ad56dfab1d9093b28a1d9c4d6478c72746", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "chatbot-ui", + "container_name": "chatbot-ui", + "image": { + "reference": "ghcr.io/mckaywrigley/chatbot-ui:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/mckaywrigley/chatbot-ui", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 3000, + "published_example": 3080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: chatbot-ui\nservices:\n chatbot-ui:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n image: ghcr.io/mckaywrigley/chatbot-ui:latest\n network_mode: bridge\n ports:\n - target: 3000\n published: '3080'\n protocol: tcp\n restart: unless-stopped\n container_name: chatbot-ui\n" + }, + "compose_stack": { + "project_name": "chatbot-ui", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "chatbot-ui", + "service_count": 1, + "services": [ + { + "name": "chatbot-ui", + "image": "ghcr.io/mckaywrigley/chatbot-ui:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "image": "ghcr.io/mckaywrigley/chatbot-ui:latest", + "network_mode": "bridge", + "ports": [ + { + "target": 3000, + "published": "3080", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "container_name": "chatbot-ui" + } + } + ], + "top_level": { + "name": "chatbot-ui" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "chatbot-ui" + ], + "stop_order": [ + "chatbot-ui" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/chatgpt-next-web.json b/oci/catalog/apps/chatgpt-next-web.json new file mode 100644 index 00000000..50b8179e --- /dev/null +++ b/oci/catalog/apps/chatgpt-next-web.json @@ -0,0 +1,416 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-chatgpt-next-web", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "ChatGPT Next Web" + }, + "tagline": { + "en_US": "A well-designed cross-platform ChatGPT UI." + }, + "description": { + "en_US": "An intelligent chat application based on ChatGPT, supports fast deployment, Markdown, beautiful UI, fluid response, privacy and security, and allows customization of preset roles for quick creation, sharing, and debugging of personalized conversations." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Yidadaa", + "developer": "Yidadaa", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://nextchat.club", + "documentation": null, + "repository": "https://hub.docker.com/r/yidadaa/chatgpt-next-web", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "yidadaa", + "repository": "https://hub.docker.com/r/yidadaa/chatgpt-next-web", + "revision": "d27148d56629c341835e1833824f2340d4a13e915a929f0f6ee432b4a2e31194", + "image_repository_url": "https://hub.docker.com/r/yidadaa/chatgpt-next-web", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "d27148d56629c341835e1833824f2340d4a13e915a929f0f6ee432b4a2e31194", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "chatgpt-next-web", + "container_name": "chatgpt-next-web", + "image": { + "reference": "yidadaa/chatgpt-next-web:latest", + "registry": "docker.io", + "repository": "yidadaa/chatgpt-next-web", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CODE", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PROXY_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BASE_URL", + "example": "https://api.openai.com", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: chatgpt-next-web\nservices:\n chatgpt-next-web:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n CODE: ''\n PROXY_URL: ''\n BASE_URL: https://api.openai.com\n image: yidadaa/chatgpt-next-web:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 3000\n published: '3000'\n protocol: tcp\n restart: unless-stopped\n container_name: chatgpt-next-web\n" + }, + "compose_stack": { + "project_name": "chatgpt-next-web", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "chatgpt-next-web", + "service_count": 1, + "services": [ + { + "name": "chatgpt-next-web", + "image": "yidadaa/chatgpt-next-web:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ", + "CODE": "", + "PROXY_URL": "", + "BASE_URL": "https://api.openai.com" + }, + "image": "yidadaa/chatgpt-next-web:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 3000, + "published": "3000", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "container_name": "chatgpt-next-web" + } + } + ], + "top_level": { + "name": "chatgpt-next-web" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "chatgpt-next-web" + ], + "stop_order": [ + "chatgpt-next-web" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/chrome.json b/oci/catalog/apps/chrome.json new file mode 100644 index 00000000..d4aaf69b --- /dev/null +++ b/oci/catalog/apps/chrome.json @@ -0,0 +1,280 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-chrome", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Chrome" + }, + "tagline": { + "en_US": "Chrome is the official web browser from Google, built to be fast, secure, and customizable." + }, + "description": { + "en_US": "Chrome is the official web browser from Google, built to be fast, secure, and customizable." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/chrome-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/chrome-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.google.com/chrome/", + "documentation": "https://docs.linuxserver.io/images/docker-chrome/", + "repository": "https://github.com/linuxserver/docker-chrome", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-27", + "note": "Add aarch64 support." + }, + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-09-02", + "note": "Revert graceful shutdown script to rely on the baseimage fix." + } + ], + "display_version": null, + "updated_at": "2026-07-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-chrome", + "default_branch": "master", + "revision": "0ca44c4169138d8d0f4abf2cb97595b6b360d471", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-chrome/0ca44c4169138d8d0f4abf2cb97595b6b360d471/README.md", + "readme_pushed_at": "2026-09-09T00:55:14Z", + "compose_sha256": "a3e7b9f8e1868c875558ffb5c3f41734bb9cc5c8585a776b847b52bad5c2d369", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "chrome", + "container_name": "chrome", + "image": { + "reference": "lscr.io/linuxserver/chrome:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/chrome", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CHROME_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n chrome:\n image: lscr.io/linuxserver/chrome:latest\n container_name: chrome\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - CHROME_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/chromium.json b/oci/catalog/apps/chromium.json new file mode 100644 index 00000000..06c8b93d --- /dev/null +++ b/oci/catalog/apps/chromium.json @@ -0,0 +1,280 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-chromium", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Chromium" + }, + "tagline": { + "en_US": "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web." + }, + "description": { + "en_US": "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/chromium-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/chromium-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.chromium.org/chromium-projects/", + "documentation": "https://docs.linuxserver.io/images/docker-chromium/", + "repository": "https://github.com/linuxserver/docker-chromium", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-04", + "note": "Deprecate Kasm branch." + }, + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-01", + "note": "Add Kasm branch." + } + ], + "display_version": null, + "updated_at": "2026-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-chromium", + "default_branch": "master", + "revision": "dd4df02a9614d2107ae303a77b5e309c5ceee12d", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-chromium/dd4df02a9614d2107ae303a77b5e309c5ceee12d/README.md", + "readme_pushed_at": "2026-09-09T14:32:01Z", + "compose_sha256": "25230baee43f5718a8571dfcc45149623d11568325068f1b3c456cc0e1d65bdb", + "generated_at": "2026-09-12T14:37:24+00:00" + }, + "container_contract": { + "service_name": "chromium", + "container_name": "chromium", + "image": { + "reference": "lscr.io/linuxserver/chromium:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/chromium", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CHROME_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/chromium/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n chromium:\n image: lscr.io/linuxserver/chromium:latest\n container_name: chromium\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - CHROME_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/chromium/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/cloudbeaver.json b/oci/catalog/apps/cloudbeaver.json new file mode 100644 index 00000000..a2547e44 --- /dev/null +++ b/oci/catalog/apps/cloudbeaver.json @@ -0,0 +1,403 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-cloudbeaver", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "CloudBeaver" + }, + "tagline": { + "en_US": "Cloud Database Manager." + }, + "description": { + "en_US": "CloudBeaver is a web-based database GUI tool which provides rich web interface. You can use it to manage PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, DB2, Firebird, H2, Trino." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "dbeaver", + "developer": "dbeaver", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8978, + "path": "/" + }, + "website": "https://dbeaver.com/download/cloudbeaver/", + "documentation": null, + "repository": "https://hub.docker.com/r/dbeaver/cloudbeaver", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/dbeaver/cloudbeaver", + "revision": "d227261123f35eaf91ba08a9383415670a97a16d7e4e59699bbb4690d538bfb9", + "image_repository_url": "https://hub.docker.com/r/dbeaver/cloudbeaver", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "d227261123f35eaf91ba08a9383415670a97a16d7e4e59699bbb4690d538bfb9", + "generated_at": "2026-09-13T15:34:57+00:00" + }, + "container_contract": { + "service_name": "cloudbeaver", + "container_name": "cloudbeaver", + "image": { + "reference": "dbeaver/cloudbeaver:latest", + "registry": "docker.io", + "repository": "dbeaver/cloudbeaver", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt/cloudbeaver/workspace", + "compose_source_example": "/DATA/AppData/$AppID/workspace", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8978, + "published_example": 8978, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "version: '3.7'\nname: cloudbeaver\nservices:\n cloudbeaver:\n container_name: cloudbeaver\n deploy:\n resources:\n reservations:\n memory: 256M\n image: dbeaver/cloudbeaver:latest\n ports:\n - target: 8978\n published: '8978'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/workspace\n target: /opt/cloudbeaver/workspace\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "cloudbeaver", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "cloudbeaver", + "service_count": 1, + "services": [ + { + "name": "cloudbeaver", + "image": "dbeaver/cloudbeaver:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "cloudbeaver", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "image": "dbeaver/cloudbeaver:latest", + "ports": [ + { + "target": 8978, + "published": "8978", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/workspace", + "target": "/opt/cloudbeaver/workspace" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "version": "3.7", + "name": "cloudbeaver" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "cloudbeaver-volume-0", + "service": "cloudbeaver", + "container_path": "/opt/cloudbeaver/workspace", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "cloudbeaver" + ], + "stop_order": [ + "cloudbeaver" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8978, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/cloudflared.json b/oci/catalog/apps/cloudflared.json new file mode 100644 index 00000000..5786da3a --- /dev/null +++ b/oci/catalog/apps/cloudflared.json @@ -0,0 +1,394 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-cloudflared", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Cloudflared" + }, + "tagline": { + "en_US": "A tunneling daemon by Cloudflare that safely exposes your web servers into the internet." + }, + "description": { + "en_US": "Cloudflare Tunnel offers an easy way to expose web servers securely to the internet, without opening up firewall ports and configuring ACLs. Cloudflare Tunnel also ensures requests route through Cloudflare before reaching the web server, so you can be sure attack traffic is stopped with Cloudflare\u2019s WAF and Unmetered DDoS mitigation, and authenticated with Access if you\u2019ve enabled those features for your account.\n\nThe software provides a seamless way to securely expose web servers to the internet without configuring firewall ports or access control lists (ACLs). All requests are routed through Cloudflare before reaching your web server, leveraging Cloudflare\u2019s Web Application Firewall (WAF) and unmetered DDoS mitigation to block attack traffic, with optional authentication via Cloudflare Access if enabled. With its intuitive Web interface and efficient tunnel management, this tool is the perfect solution for securely deploying web services.\n\n**Discover How to Connect self-hosted server to Cloudflare Tunnel**\nIntegrating self-hosted server with Cloudflare Tunnel allows you to securely expose local services to the internet without opening firewall ports, enabling seamless remote access. Below are two practical resources to guide you through the setup process:\n1. [**Cloudflare Official Tutorial**](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/get-started/create-remote-tunnel/): \n This tutorial provides detailed steps for creating and managing a Cloudflare Tunnel.\n2. [**Phiptech Practical Guide**](https://phiptech.com/how-to-setup-cloudflare-tunnel-and-expose-your-local-service-or-application/): \n This guide offers a concise, step-by-step walkthrough for setting up Cloudflare Tunnel on local devices like self-hosted server, with practical examples to help users easily expose services to the public internet.\n" + }, + "category": "web", + "category_label": "Webservers & Proxies", + "author": "Cloudflare Inc.", + "developer": "Cloudflare Inc.", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 14333, + "path": "/" + }, + "website": "https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/get-started/create-remote-tunnel/", + "documentation": null, + "repository": "https://hub.docker.com/r/wisdomsky/cloudflared-web", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "wisdomsky", + "repository": "https://hub.docker.com/r/wisdomsky/cloudflared-web", + "revision": "47fa44796989402418ef8b7b862a52ebd8ec3f098437c9dbc84bbdd9dea072eb", + "image_repository_url": "https://hub.docker.com/r/wisdomsky/cloudflared-web", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "47fa44796989402418ef8b7b862a52ebd8ec3f098437c9dbc84bbdd9dea072eb", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "cloudflared", + "container_name": "cloudflared", + "image": { + "reference": "wisdomsky/cloudflared-web:latest", + "registry": "docker.io", + "repository": "wisdomsky/cloudflared-web", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/cloudflared-cloudflared/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 14333, + "published_example": 14333, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: cloudflared\nservices:\n cloudflared:\n image: wisdomsky/cloudflared-web:latest\n restart: unless-stopped\n network_mode: host\n ports:\n - target: 14333\n published: '14333'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/cloudflared-cloudflared/config\n target: /config\n container_name: cloudflared\n" + }, + "compose_stack": { + "project_name": "cloudflared", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "cloudflared", + "service_count": 1, + "services": [ + { + "name": "cloudflared", + "image": "wisdomsky/cloudflared-web:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "wisdomsky/cloudflared-web:latest", + "restart": "unless-stopped", + "network_mode": "host", + "ports": [ + { + "target": 14333, + "published": "14333", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/cloudflared-cloudflared/config", + "target": "/config" + } + ], + "container_name": "cloudflared" + } + } + ], + "top_level": { + "name": "cloudflared" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "cloudflared-volume-0", + "service": "cloudflared", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "cloudflared" + ], + "stop_order": [ + "cloudflared" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 14333, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/clumoove.json b/oci/catalog/apps/clumoove.json new file mode 100644 index 00000000..2b8e1100 --- /dev/null +++ b/oci/catalog/apps/clumoove.json @@ -0,0 +1,662 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-clumoove", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "Clumoove" + }, + "tagline": { + "en_US": "Self-hosted cloud data migration & sync manager" + }, + "description": { + "en_US": "Clumoove is a modern, self-hosted cloud data migration and synchronization platform for files, calendars, and contacts.\n\nEasily connect, transfer, and synchronize data between cloud storage providers including Nextcloud, Google Drive, Dropbox, OneDrive, HiDrive, S3, WebDAV, SMB, SFTP, FTP, Immich, Seafile, Koofr, MEGA, and local storage.\n\nKey Features:\n- Zero-disk streaming transfers (no local temporary storage retention during migration)\n- Multi-threaded background migrations and cron-based synchronization schedules\n- Robust 3-way hash integrity verification & flexible conflict resolution\n- Integrated cloud file manager with multi-format previews and thumbnails\n- Multi-channel notification delivery (Gotify, ntfy, Telegram, Discord, Email)\n- Enterprise-grade security with AES-256-GCM encryption, TOTP 2FA, and audit logging\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Marcel Meyer", + "developer": "Marcel Meyer", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://clumoove.com", + "documentation": null, + "repository": "https://ghcr.io/xxroxxerxx/clumoove-frontend", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "xxroxxerxx", + "repository": "https://ghcr.io/xxroxxerxx/clumoove-frontend", + "revision": "acfa54e4400a05629416ca1b2077236d4e4cb7217a1c7b20547ab43ea20a1679", + "image_repository_url": "https://ghcr.io/xxroxxerxx/clumoove-frontend", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "acfa54e4400a05629416ca1b2077236d4e4cb7217a1c7b20547ab43ea20a1679", + "generated_at": "2026-09-13T15:48:22+00:00" + }, + "container_contract": { + "service_name": "frontend", + "container_name": "clumoove-frontend", + "image": { + "reference": "ghcr.io/xxroxxerxx/clumoove-frontend:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/xxroxxerxx/clumoove-frontend", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "CLUMOOVE_API_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 3000, + "published_example": 8380, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "api-backend", + "image": "ghcr.io/xxroxxerxx/clumoove-api:latest" + }, + { + "name": "migration-worker", + "image": "ghcr.io/xxroxxerxx/clumoove-worker:latest" + }, + { + "name": "postgres-db", + "image": "postgres:latest" + }, + { + "name": "redis-queue", + "image": "redis:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: clumoove\nservices:\n frontend:\n image: ghcr.io/xxroxxerxx/clumoove-frontend:latest\n container_name: clumoove-frontend\n restart: unless-stopped\n ports:\n - target: 3000\n published: '8380'\n protocol: tcp\n environment:\n - CLUMOOVE_API_URL=\n depends_on:\n - api-backend\n networks:\n - clumoove-network\n api-backend:\n image: ghcr.io/xxroxxerxx/clumoove-api:latest\n container_name: clumoove-api\n restart: unless-stopped\n environment:\n - DATABASE_URL=postgres://clumoove:clumoove_secure_password_default@postgres-db:5432/cloud_migration_db?sslmode=disable\n - REDIS_URL=redis://:clumoove_secure_redis_pass@redis-queue:6379\n - PORT=8000\n - ENCRYPTION_SECRET_KEY=${GENERATED_ENCRYPTION_SECRET_KEY}\n - JWT_SECRET_KEY=${GENERATED_JWT_SECRET_KEY}\n - TRUSTED_PROXY=1\n - LOCAL_STORAGE_ROOT=/clumoove\n volumes:\n - type: bind\n source: /DATA/AppData/clumoove/storage\n target: /clumoove\n depends_on:\n - postgres-db\n - redis-queue\n networks:\n - clumoove-network\n migration-worker:\n image: ghcr.io/xxroxxerxx/clumoove-worker:latest\n container_name: clumoove-worker\n restart: unless-stopped\n command:\n - /app/worker\n environment:\n - DATABASE_URL=postgres://clumoove:clumoove_secure_password_default@postgres-db:5432/cloud_migration_db?sslmode=disable\n - REDIS_URL=redis://:clumoove_secure_redis_pass@redis-queue:6379\n - ENCRYPTION_SECRET_KEY=${GENERATED_ENCRYPTION_SECRET_KEY}\n - LOCAL_STORAGE_ROOT=/clumoove\n volumes:\n - type: bind\n source: /DATA/AppData/clumoove/storage\n target: /clumoove\n depends_on:\n - postgres-db\n - redis-queue\n networks:\n - clumoove-network\n postgres-db:\n image: postgres:latest\n container_name: clumoove-postgres\n restart: unless-stopped\n command:\n - postgres\n - -c\n - max_connections=300\n environment:\n POSTGRES_USER: clumoove\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: cloud_migration_db\n volumes:\n - type: bind\n source: /DATA/AppData/clumoove/postgres\n target: /var/lib/postgresql/data\n networks:\n - clumoove-network\n redis-queue:\n image: redis:latest\n container_name: clumoove-redis\n restart: unless-stopped\n command: redis-server --appendonly yes --requirepass \"clumoove_secure_redis_pass\"\n --bind 0.0.0.0\n volumes:\n - type: bind\n source: /DATA/AppData/clumoove/redis\n target: /data\n networks:\n - clumoove-network\nnetworks:\n clumoove-network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "clumoove", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "frontend", + "service_count": 5, + "services": [ + { + "name": "postgres-db", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:latest", + "container_name": "clumoove-postgres", + "restart": "unless-stopped", + "command": [ + "postgres", + "-c", + "max_connections=300" + ], + "environment": { + "POSTGRES_USER": "clumoove", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "cloud_migration_db" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/clumoove/postgres", + "target": "/var/lib/postgresql/data" + } + ], + "networks": [ + "clumoove-network" + ] + } + }, + { + "name": "redis-queue", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "redis:latest", + "container_name": "clumoove-redis", + "restart": "unless-stopped", + "command": "redis-server --appendonly yes --requirepass \"clumoove_secure_redis_pass\" --bind 0.0.0.0", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/clumoove/redis", + "target": "/data" + } + ], + "networks": [ + "clumoove-network" + ] + } + }, + { + "name": "api-backend", + "image": "ghcr.io/xxroxxerxx/clumoove-api:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [ + "postgres-db", + "redis-queue" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "ghcr.io/xxroxxerxx/clumoove-api:latest", + "container_name": "clumoove-api", + "restart": "unless-stopped", + "environment": [ + "DATABASE_URL=postgres://clumoove:clumoove_secure_password_default@postgres-db:5432/cloud_migration_db?sslmode=disable", + "REDIS_URL=redis://:clumoove_secure_redis_pass@redis-queue:6379", + "PORT=8000", + "ENCRYPTION_SECRET_KEY=${GENERATED_ENCRYPTION_SECRET_KEY}", + "JWT_SECRET_KEY=${GENERATED_JWT_SECRET_KEY}", + "TRUSTED_PROXY=1", + "LOCAL_STORAGE_ROOT=/clumoove" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/clumoove/storage", + "target": "/clumoove" + } + ], + "depends_on": [ + "postgres-db", + "redis-queue" + ], + "networks": [ + "clumoove-network" + ] + } + }, + { + "name": "migration-worker", + "image": "ghcr.io/xxroxxerxx/clumoove-worker:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 4, + "depends_on": [ + "postgres-db", + "redis-queue" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "ghcr.io/xxroxxerxx/clumoove-worker:latest", + "container_name": "clumoove-worker", + "restart": "unless-stopped", + "command": [ + "/app/worker" + ], + "environment": [ + "DATABASE_URL=postgres://clumoove:clumoove_secure_password_default@postgres-db:5432/cloud_migration_db?sslmode=disable", + "REDIS_URL=redis://:clumoove_secure_redis_pass@redis-queue:6379", + "ENCRYPTION_SECRET_KEY=${GENERATED_ENCRYPTION_SECRET_KEY}", + "LOCAL_STORAGE_ROOT=/clumoove" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/clumoove/storage", + "target": "/clumoove" + } + ], + "depends_on": [ + "postgres-db", + "redis-queue" + ], + "networks": [ + "clumoove-network" + ] + } + }, + { + "name": "frontend", + "image": "ghcr.io/xxroxxerxx/clumoove-frontend:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "api-backend" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "ghcr.io/xxroxxerxx/clumoove-frontend:latest", + "container_name": "clumoove-frontend", + "restart": "unless-stopped", + "ports": [ + { + "target": 3000, + "published": "8380", + "protocol": "tcp" + } + ], + "environment": [ + "CLUMOOVE_API_URL=" + ], + "depends_on": [ + "api-backend" + ], + "networks": [ + "clumoove-network" + ] + } + } + ], + "top_level": { + "name": "clumoove", + "networks": { + "clumoove-network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "api-backend-volume-0", + "service": "api-backend", + "container_path": "/clumoove", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "migration-worker-volume-0", + "service": "migration-worker", + "container_path": "/clumoove", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "postgres-db-volume-0", + "service": "postgres-db", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "redis-queue-volume-0", + "service": "redis-queue", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for redis-queue:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 5, + "start_order": [ + "postgres-db", + "redis-queue", + "api-backend", + "migration-worker", + "frontend" + ], + "stop_order": [ + "frontend", + "migration-worker", + "api-backend", + "redis-queue", + "postgres-db" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "encryption-secret-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api-backend", + "environment_variable": "ENCRYPTION_SECRET_KEY" + }, + { + "service": "migration-worker", + "environment_variable": "ENCRYPTION_SECRET_KEY" + } + ] + }, + { + "id": "jwt-secret-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api-backend", + "environment_variable": "JWT_SECRET_KEY" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "postgres-db", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "api-backend: perfil de salud y persistencia pendiente", + "migration-worker: perfil de salud y persistencia pendiente", + "postgres-db: comando de dependencia personalizado pendiente", + "redis-queue: comando de dependencia personalizado pendiente", + "volumen compartido entre servicios pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:api-backend:compose-key:depends_on", + "service:migration-worker:compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/code-server.json b/oci/catalog/apps/code-server.json new file mode 100644 index 00000000..e2abed38 --- /dev/null +++ b/oci/catalog/apps/code-server.json @@ -0,0 +1,290 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-code-server", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Code Server" + }, + "tagline": { + "en_US": "Code-server is VS Code running on a remote server, accessible through the browser." + }, + "description": { + "en_US": "Code-server is VS Code running on a remote server, accessible through the browser." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/code-server-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/code-server-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8443, + "path": "/" + }, + "website": "https://coder.com", + "documentation": "https://docs.linuxserver.io/images/docker-code-server/", + "repository": "https://github.com/linuxserver/docker-code-server", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-17", + "note": "Let server listen on both ipv4 and ipv6 even when running container as root." + }, + { + "date": "2025-08-10", + "note": "Let server listen on both ipv4 and ipv6." + }, + { + "date": "2025-06-03", + "note": "Allow setting PWA name using env var `PWA_APPNAME`." + }, + { + "date": "2024-10-13", + "note": "Only chown config folder when change to ownership or new install is detected." + }, + { + "date": "2024-10-09", + "note": "Manage permissions in /config/.ssh according to file type" + } + ], + "display_version": null, + "updated_at": "2026-05-17" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-code-server", + "default_branch": "master", + "revision": "efc786252e7750b6e9915bc57aff86454d88b0f4", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-code-server/efc786252e7750b6e9915bc57aff86454d88b0f4/README.md", + "readme_pushed_at": "2026-09-11T05:22:23Z", + "compose_sha256": "07da8874c9c570566a876e5fba9b523cee9ca8ee54ac950381d7db9b3720bc70", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "code-server", + "container_name": "code-server", + "image": { + "reference": "lscr.io/linuxserver/code-server:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/code-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PASSWORD", + "example": "password", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "HASHED_PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SUDO_PASSWORD", + "example": "password", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SUDO_PASSWORD_HASH", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "PROXY_DOMAIN", + "example": "code-server.my.domain", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEFAULT_WORKSPACE", + "example": "/config/workspace", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PWA_APPNAME", + "example": "code-server", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/code-server/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8443, + "published_example": 8443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n code-server:\n image: lscr.io/linuxserver/code-server:latest\n container_name: code-server\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - PASSWORD=password #optional\n - HASHED_PASSWORD= #optional\n - SUDO_PASSWORD=password #optional\n - SUDO_PASSWORD_HASH= #optional\n - PROXY_DOMAIN=code-server.my.domain #optional\n - DEFAULT_WORKSPACE=/config/workspace #optional\n - PWA_APPNAME=code-server #optional\n volumes:\n - /path/to/code-server/config:/config\n ports:\n - 8443:8443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8443, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/codeproject-ai.json b/oci/catalog/apps/codeproject-ai.json new file mode 100644 index 00000000..4bace122 --- /dev/null +++ b/oci/catalog/apps/codeproject-ai.json @@ -0,0 +1,417 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-codeproject-ai", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "CodeProject.AI Server" + }, + "tagline": { + "en_US": "CodeProject.AI Server" + }, + "description": { + "en_US": "Official latest CPU image with persistent settings and modules. Initial CPU and Coral PCIe inference passed on Intel amd64. Coral module uses its persistent upstream EdgeTPU runtime via module-scoped LD_PRELOAD; missing JSON defaults preserve existing user settings. The TPU needs exclusive access. ARM and NVIDIA channels are not offered by this template; Failures observed on the AMD lab host remain unexplained; no blanket AMD incompatibility is inferred." + }, + "category": "ai", + "category_label": "AI", + "author": "codeproject", + "developer": "codeproject", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 32168, + "path": "/" + }, + "website": "https://github.com/codeproject/CodeProject.AI-Server", + "documentation": "https://github.com/codeproject/CodeProject.AI-Server", + "repository": "https://github.com/codeproject/CodeProject.AI-Server", + "tips": [ + "Official latest CPU image with persistent settings and modules. Initial CPU and Coral PCIe inference passed on Intel amd64. Coral module uses its persistent upstream EdgeTPU runtime via module-scoped LD_PRELOAD; missing JSON defaults preserve existing user settings. The TPU needs exclusive access. ARM and NVIDIA channels are not offered by this template; Failures observed on the AMD lab host remain unexplained; no blanket AMD incompatibility is inferred.", + "Install ObjectDetectionCoral in the dashboard. Stop competing object detectors when assigning its detection route; exposing a device does not configure an inference module." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-16", + "hidden": true, + "hidden_reason": "Temporarily withdrawn at user request pending further hardware validation." + }, + "source": { + "provider": "codeproject", + "repository": "https://github.com/codeproject/CodeProject.AI-Server", + "default_branch": "main", + "revision": "e3468c831b169e27ed6c97f665f1efb48ab0285f", + "readme_raw_url": "https://raw.githubusercontent.com/codeproject/CodeProject.AI-Server/e3468c831b169e27ed6c97f665f1efb48ab0285f/README.md", + "image_repository_url": "https://hub.docker.com/r/codeproject/ai-server", + "compose_sha256": "a8ce9bcbde2cbc0fc9a840b93bab72a33da2a2f4a18857896b837cbc7f462ece", + "generated_at": "2026-09-16T22:00:00+02:00" + }, + "container_contract": { + "service_name": "codeproject-ai", + "container_name": "codeproject-ai", + "image": { + "reference": "codeproject/ai-server:latest", + "registry": "docker.io", + "repository": "codeproject/ai-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "config", + "container_path": "/etc/codeproject/ai", + "compose_source_example": "config-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "modules", + "container_path": "/app/modules", + "compose_source_example": "modules-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 16 + } + } + ], + "ports": [ + { + "container_port": 32168, + "published_example": 32168, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "{\n \"services\": {\n \"codeproject-ai\": {\n \"image\": \"codeproject/ai-server:latest\",\n \"volumes\": [\n \"config-data:/etc/codeproject/ai\",\n \"modules-data:/app/modules\"\n ],\n \"ports\": [\n \"32168:32168\"\n ],\n \"environment\": {},\n \"restart\": \"unless-stopped\"\n }\n }\n}" + }, + "compose_stack": { + "project_name": "mkvtoolnix", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mkvtoolnix", + "service_count": 1, + "services": [ + { + "name": "mkvtoolnix", + "image": "jlesage/mkvtoolnix:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/mkvtoolnix:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "mkvtoolnix-config:/config", + "/mnt/oci-shared/media:/storage" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mkvtoolnix-config", + "service": "mkvtoolnix", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "mkvtoolnix-storage", + "service": "mkvtoolnix", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mkvtoolnix" + ], + "stop_order": [ + "mkvtoolnix" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "passed-amd64-intel" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "not-required" + }, + { + "id": "persistent-coral-module-runtime", + "upstream_behavior": "The official Coral module downloads the EdgeTPU runtime into its module folder, then copies a library into /usr/lib.", + "native_lxc_behavior": "Module-scoped LD_PRELOAD points to the same upstream runtime retained in /app/modules. Missing defaults are merged into the official /etc/codeproject/ai/modulesettings.json.", + "reason": "A new image rootfs does not retain libraries installed after image creation, in Docker or native OCI.", + "behavioral_impact": "Only ObjectDetectionCoral receives this setting; existing user overrides are preserved. No image files or host drivers are changed.", + "validation": "passed-installer-recreation-and-coral-inference-amd64-intel" + } + ], + "installer_profile": { + "optional_devices": [ + { + "id": "coral-pcie", + "kind": "character-device", + "enable_prompt": "Add a Coral PCIe/M.2 device?", + "enabled_default": false, + "path_prompt": "Coral PCIe/M.2 node (e.g. /dev/apex_0)", + "host_path_default": "/dev/apex_0", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 32168, + "path": "/", + "timeout_seconds": 300, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "generated_files": [ + { + "container_path": "/etc/codeproject/ai/modulesettings.json", + "mode": "0644", + "owner": "mapped-root", + "only_if_missing": true, + "json_defaults": true, + "content": "{\n \"Modules\": {\n \"ObjectDetectionCoral\": {\n \"EnvironmentVariables\": {\n \"LD_PRELOAD\": \"/app/modules/ObjectDetectionCoral/edgetpu_runtime/libedgetpu/throttled/k8/libedgetpu.so.1.0\"\n },\n \"LaunchSettings\": {\n \"AutoStart\": false\n }\n }\n }\n}\n" + } + ], + "hardware_acceleration": { + "prompt": "Acceleration for CodeProject.AI", + "default": "cpu", + "profiles": [ + { + "id": "cpu", + "label": "CPU", + "device_requests": [], + "image": { + "reference": "codeproject/ai-server:latest", + "registry": "docker.io", + "repository": "codeproject/ai-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + } + }, + { + "id": "nvidia", + "label": "NVIDIA (CUDA; official GPU image)", + "image": { + "reference": "codeproject/ai-server:gpu", + "registry": "docker.io", + "repository": "codeproject/ai-server", + "tag": "gpu", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + }, + { + "name": "NVIDIA_DRIVER_CAPABILITIES", + "value": "compute,utility" + } + ] + } + ] + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "Official latest CPU image with persistent settings and modules. Initial CPU and Coral PCIe inference passed on Intel amd64. Coral module uses its persistent upstream EdgeTPU runtime via module-scoped LD_PRELOAD; missing JSON defaults preserve existing user settings. The TPU needs exclusive access. ARM and NVIDIA channels are not offered by this template; Failures observed on the AMD lab host remain unexplained; no blanket AMD incompatibility is inferred. NVIDIA uses the official gpu channel with native Toolkit integration; inference validation pending. Intel/AMD GPU inference is not advertised without an upstream compatible module/runtime." + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 32168, + "path": "/", + "source": "https://github.com/codeproject/CodeProject.AI-Server" + } + ], + "credentials": [] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64-intel", + "service_health": "passed-amd64-intel", + "restart_persistence": "passed-amd64-intel", + "backup_restore": "passed-interrupted-candidate-native-recovery", + "update_preserves_data": "passed-same-digest-rootfs-recreation", + "evidence": "docs/lab/new-images-validation-20260918.json" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/convertx.json b/oci/catalog/apps/convertx.json new file mode 100644 index 00000000..c2b8b32d --- /dev/null +++ b/oci/catalog/apps/convertx.json @@ -0,0 +1,427 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-convertx", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "ConvertX" + }, + "tagline": { + "en_US": "A versatile file conversion tool that supports multiple formats." + }, + "description": { + "en_US": "ConvertX is a self-hosted file conversion service that allows users to convert files between different formats through an intuitive web interface. It supports a wide range of file types including documents, images, videos, and audio files, making it a comprehensive solution for all your file conversion needs.\n\nThe service is designed with simplicity and ease of use in mind. Users can simply upload their files, select the desired output format, and let ConvertX handle the conversion process. The web interface provides a clean and user-friendly experience, with drag-and-drop support and batch conversion capabilities.\n\nConvertX runs entirely on your own infrastructure, ensuring that your files remain private and secure. There's no need to upload sensitive documents to third-party services, giving you full control over your data. The service is containerized for easy deployment and can be integrated into existing home server setups.\n\n**Key Features:**\n- Support for multiple file formats (documents, images, videos, audio)\n- Intuitive web interface with drag-and-drop support\n- Batch conversion capabilities\n- Self-hosted for privacy and security\n- Containerized for easy deployment\n- No file size limitations\n\n**Learn More:**\n- [ConvertX GitHub Repository](https://github.com/c4illin/convertx)\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "c4illin", + "developer": "c4illin", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/c4illin/convertx", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "c4illin", + "repository": "https://hub.docker.com/r/c4illin/convertx", + "revision": "20d9f7eb1e084a5dd716a04c49f64bf3e291565b462f17ebfa942e1898fbba91", + "image_repository_url": "https://hub.docker.com/r/c4illin/convertx", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "20d9f7eb1e084a5dd716a04c49f64bf3e291565b462f17ebfa942e1898fbba91", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "convertx", + "container_name": "convertx", + "image": { + "reference": "c4illin/convertx:latest", + "registry": "docker.io", + "repository": "c4illin/convertx", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "JWT_SECRET", + "example": "${GENERATED_JWT_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "HTTP_ALLOWED", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3333, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: convertx\nservices:\n convertx:\n image: c4illin/convertx:latest\n container_name: convertx\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 500M\n ports:\n - 3333:3000\n environment:\n - JWT_SECRET=${GENERATED_JWT_SECRET}\n - HTTP_ALLOWED=true\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /app/data\n network_mode: bridge\n" + }, + "compose_stack": { + "project_name": "convertx", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "convertx", + "service_count": 1, + "services": [ + { + "name": "convertx", + "image": "c4illin/convertx:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "c4illin/convertx:latest", + "container_name": "convertx", + "restart": "unless-stopped", + "deploy": { + "resources": { + "reservations": { + "memory": "500M" + } + } + }, + "ports": [ + "3333:3000" + ], + "environment": [ + "JWT_SECRET=${GENERATED_JWT_SECRET}", + "HTTP_ALLOWED=true" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/app/data" + } + ], + "network_mode": "bridge" + } + } + ], + "top_level": { + "name": "convertx" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "convertx-volume-0", + "service": "convertx", + "container_path": "/app/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "convertx" + ], + "stop_order": [ + "convertx" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "jwt-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "convertx", + "environment_variable": "JWT_SECRET" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 500, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/cops.json b/oci/catalog/apps/cops.json new file mode 100644 index 00000000..5db35fbf --- /dev/null +++ b/oci/catalog/apps/cops.json @@ -0,0 +1,264 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-cops", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Cops" + }, + "tagline": { + "en_US": "Cops by S\u00e9bastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server." + }, + "description": { + "en_US": "Cops by S\u00e9bastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/cops-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/cops-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/mikespub-org/seblucas-cops", + "documentation": "https://docs.linuxserver.io/images/docker-cops/", + "repository": "https://github.com/linuxserver/docker-cops", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-21", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-06-10", + "note": "Existing users should verify: site-confs/default.conf and config/local.php - Update redirect location and use front controller." + }, + { + "date": "2026-02-08", + "note": "Existing users should update: site-confs/default.conf - Deny access to all dotfiles." + }, + { + "date": "2026-02-08", + "note": "Adding missing php-tokenizer package." + }, + { + "date": "2025-10-10", + "note": "Adding missing icu-data-full package." + } + ], + "display_version": null, + "updated_at": "2026-07-21" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-cops", + "default_branch": "master", + "revision": "ff91cb28a95537f8dff796fbf013cf7059362e5c", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-cops/ff91cb28a95537f8dff796fbf013cf7059362e5c/README.md", + "readme_pushed_at": "2026-09-06T22:40:35Z", + "compose_sha256": "181b0f5516fb29ec1ae08d284975f4fd5847c0bcdb9492fb8e0e466caf57381c", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "cops", + "container_name": "cops", + "image": { + "reference": "lscr.io/linuxserver/cops:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/cops", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/cops/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/books", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n cops:\n image: lscr.io/linuxserver/cops:latest\n container_name: cops\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/cops/config:/config\n - /path/to/data:/books\n ports:\n - 80:80\n - 443:443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/copyparty.json b/oci/catalog/apps/copyparty.json new file mode 100644 index 00000000..fb21dc52 --- /dev/null +++ b/oci/catalog/apps/copyparty.json @@ -0,0 +1,434 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-copyparty", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "CopyParty" + }, + "tagline": { + "en_US": "A simple, private file server." + }, + "description": { + "en_US": "**CopyParty** is a fast, privacy-focused file sharing server using a local-first, single-file architecture, ensuring full control over data without cloud dependencies. Its intuitive interface supports offline use, with cross-platform compatibility and multi-protocol access, delivering a secure, efficient file management experience, ideal for users seeking direct data ownership and a lightweight solution.\n\nThe app's core features include accelerated resumable uploads (via the up2k protocol), ensuring reliable large file transfers, and automatic deduplication to optimize storage. It helps users organize folders and media effortlessly, with a web-based file manager that includes a built-in media indexer and thumbnail generator for quick previews. Fine-grained permission controls allow specific user access rules. The \"upload-while-downloading\" feature enhances sharing efficiency, and the zero-dependency design ensures it runs on almost any hardware.\n\nIt integrates multiple access protocols, including HTTP, WebDAV, FTP, and TFTP, supporting connections from standard web browsers, dedicated file clients, and legacy hardware (such as PSP). The app supports Docker and Python for deployment, simplifying setup across various server environments. It facilitates seamless access to local files without complex configuration. Community documentation enhances usability, and the app's simple operation and high flexibility deliver a modern local file service solution.\n\n**Key Features:**\n- Privacy-focused local file sharing\n- Zero-dependency single-file architecture\n- Accelerated resumable uploads\n- Multi-protocol support (HTTP, WebDAV, FTP, etc.)\n- Cross-platform compatibility\n- Media indexing and streaming\n- Smart deduplication\n- User permission management\n\n**Learn More:**\n- [CopyParty GitHub Repository](https://github.com/9001/copyparty)\n" + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "CopyParty", + "developer": "CopyParty", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3923, + "path": "/" + }, + "website": "https://copyparty.eu/", + "documentation": null, + "repository": "https://hub.docker.com/r/icewhaletech/copyparty", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "icewhaletech", + "repository": "https://hub.docker.com/r/icewhaletech/copyparty", + "revision": "5c36ae07cfde54cc3929da3fec0c4632270d7f2b93a0754260802379c0e62ff5", + "image_repository_url": "https://hub.docker.com/r/icewhaletech/copyparty", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "5c36ae07cfde54cc3929da3fec0c4632270d7f2b93a0754260802379c0e62ff5", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "copyparty", + "container_name": "copyparty", + "image": { + "reference": "icewhaletech/copyparty:latest", + "registry": "docker.io", + "repository": "icewhaletech/copyparty", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/w", + "compose_source_example": "/DATA/AppData/$AppID/w", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/cfg", + "compose_source_example": "/DATA/AppData/$AppID/confg", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3923, + "published_example": 29708, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: copyparty\nservices:\n copyparty:\n image: icewhaletech/copyparty:latest\n container_name: copyparty\n ports:\n - target: 3923\n published: '29708'\n protocol: tcp\n network_mode: bridge\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/w\n target: /w\n - type: bind\n source: /DATA/AppData/$AppID/confg\n target: /cfg\n deploy:\n resources:\n reservations:\n memory: 512m\n stdin_open: true\n tty: true\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "copyparty", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "copyparty", + "service_count": 1, + "services": [ + { + "name": "copyparty", + "image": "icewhaletech/copyparty:1.20.13", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "icewhaletech/copyparty:1.20.13", + "container_name": "copyparty", + "ports": [ + { + "target": 3923, + "published": "29708", + "protocol": "tcp" + } + ], + "network_mode": "bridge", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/w", + "target": "/w" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/confg", + "target": "/cfg" + } + ], + "deploy": { + "resources": { + "reservations": { + "memory": "512m" + } + } + }, + "stdin_open": true, + "tty": true, + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "copyparty" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "copyparty-volume-0", + "service": "copyparty", + "container_path": "/w", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "copyparty-volume-1", + "service": "copyparty", + "container_path": "/cfg", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "copyparty" + ], + "stop_order": [ + "copyparty" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3923, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/crafty.json b/oci/catalog/apps/crafty.json new file mode 100644 index 00000000..b69db859 --- /dev/null +++ b/oci/catalog/apps/crafty.json @@ -0,0 +1,535 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-crafty", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Crafty" + }, + "tagline": { + "en_US": "Take control of your Minecraft servers." + }, + "description": { + "en_US": "Crafty is an open source Minecraft control panel built using Tornado and AdminLTE, featuring server scheduling, a interactive console and the ability to run almost any type of Minecraft server" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Crafty Team", + "developer": "Crafty Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 8443, + "path": "/panel" + }, + "website": "https://craftycontrol.com", + "documentation": null, + "repository": "https://registry.gitlab.com/crafty-controller/crafty-4", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://registry.gitlab.com/crafty-controller/crafty-4", + "revision": "dcb128be69705dae3d29ae21c558c74a4f583737259a8b0e8b6e22c1846b1547", + "image_repository_url": "https://registry.gitlab.com/crafty-controller/crafty-4", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "dcb128be69705dae3d29ae21c558c74a4f583737259a8b0e8b6e22c1846b1547", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "crafty", + "container_name": "crafty-container", + "image": { + "reference": "registry.gitlab.com/crafty-controller/crafty-4:latest", + "registry": "registry.gitlab.com", + "repository": "registry.gitlab.com/crafty-controller/crafty-4", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/crafty/backups", + "compose_source_example": "/DATA/AppData/crafty/backups", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/crafty/logs", + "compose_source_example": "/DATA/AppData/crafty/logs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/crafty/servers", + "compose_source_example": "/DATA/AppData/crafty/servers", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/crafty/app/config", + "compose_source_example": "/DATA/AppData/crafty/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-4", + "container_path": "/crafty/import", + "compose_source_example": "/DATA/AppData/crafty/import", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8443, + "published_example": 8111, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8123, + "published_example": 8112, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 19132, + "published_example": 19132, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 25500, + "published_example": 25500, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat", + "container_port_end": 25600, + "published_example_end": 25600 + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: crafty\nversion: '3'\nservices:\n crafty:\n container_name: crafty-container\n image: registry.gitlab.com/crafty-controller/crafty-4:latest\n restart: always\n environment:\n - TZ=Etc/UTC\n ports:\n - 8111:8443\n - 8112:8123\n - 19132:19132/udp\n - 25500-25600:25500-25600\n volumes:\n - /DATA/AppData/crafty/backups:/crafty/backups\n - /DATA/AppData/crafty/logs:/crafty/logs\n - /DATA/AppData/crafty/servers:/crafty/servers\n - /DATA/AppData/crafty/config:/crafty/app/config\n - /DATA/AppData/crafty/import:/crafty/import\n" + }, + "compose_stack": { + "project_name": "crafty", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "crafty", + "service_count": 1, + "services": [ + { + "name": "crafty", + "image": "registry.gitlab.com/crafty-controller/crafty-4:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "crafty-container", + "image": "registry.gitlab.com/crafty-controller/crafty-4:latest", + "restart": "always", + "environment": [ + "TZ=Etc/UTC" + ], + "ports": [ + "8111:8443", + "8112:8123", + "19132:19132/udp", + "25500-25600:25500-25600" + ], + "volumes": [ + "/DATA/AppData/crafty/backups:/crafty/backups", + "/DATA/AppData/crafty/logs:/crafty/logs", + "/DATA/AppData/crafty/servers:/crafty/servers", + "/DATA/AppData/crafty/config:/crafty/app/config", + "/DATA/AppData/crafty/import:/crafty/import" + ] + } + } + ], + "top_level": { + "name": "crafty", + "version": "3" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "crafty-volume-0", + "service": "crafty", + "container_path": "/crafty/backups", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "crafty-volume-1", + "service": "crafty", + "container_path": "/crafty/logs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "crafty-volume-2", + "service": "crafty", + "container_path": "/crafty/servers", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "crafty-volume-3", + "service": "crafty", + "container_path": "/crafty/app/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "crafty-volume-4", + "service": "crafty", + "container_path": "/crafty/import", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "crafty" + ], + "stop_order": [ + "crafty" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 8443, + "path": "/panel", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/cura.json b/oci/catalog/apps/cura.json new file mode 100644 index 00000000..94942bec --- /dev/null +++ b/oci/catalog/apps/cura.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-cura", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Cura" + }, + "tagline": { + "en_US": "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results." + }, + "description": { + "en_US": "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/cura-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/cura-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://ultimaker.com/software/ultimaker-cura/", + "documentation": "https://docs.linuxserver.io/images/docker-cura/", + "repository": "https://github.com/linuxserver/docker-cura", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to resolute." + }, + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Noble." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-06-03", + "note": "Update ingestion from GitHub to handle RC releases." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-cura", + "default_branch": "main", + "revision": "1c918b361988df5bfad56ae4f001f6d9ecdb9e9f", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-cura/1c918b361988df5bfad56ae4f001f6d9ecdb9e9f/README.md", + "readme_pushed_at": "2026-09-07T09:47:30Z", + "compose_sha256": "a8be85a91cd3475f63ee37c5b1d5b99ed67d86d8d4edb574f7f92fd4e134e4ae", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "cura", + "container_name": "cura", + "image": { + "reference": "lscr.io/linuxserver/cura:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/cura", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n cura:\n image: lscr.io/linuxserver/cura:latest\n container_name: cura\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-cura/master/Dockerfile", + "dockerfile_sha256": "70e5f3133d0847de7ff4cf47ab0ad2872c3fbec48bfcd6e523611180b87dcbd4", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/darktable.json b/oci/catalog/apps/darktable.json new file mode 100644 index 00000000..eee10d2a --- /dev/null +++ b/oci/catalog/apps/darktable.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-darktable", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Darktable" + }, + "tagline": { + "en_US": "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them." + }, + "description": { + "en_US": "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/darktable-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/darktable-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.darktable.org/", + "documentation": "https://docs.linuxserver.io/images/docker-darktable/", + "repository": "https://github.com/linuxserver/docker-darktable", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-02-10", + "note": "Update Readme with new env vars and ingest proper PWA icon." + }, + { + "date": "2024-01-21", + "note": "Rebase to Arch as Alpine not longer offers aarch64." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-darktable", + "default_branch": "master", + "revision": "dbda6422572a9b4441d04acc90833efe81845466", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-darktable/dbda6422572a9b4441d04acc90833efe81845466/README.md", + "readme_pushed_at": "2026-08-31T15:21:14Z", + "compose_sha256": "7cd2933e428a3e9257dee5b7760fc13060fb282aad44850f3de7caf1feaa7b2f", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "darktable", + "container_name": "darktable", + "image": { + "reference": "lscr.io/linuxserver/darktable:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/darktable", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n darktable:\n image: lscr.io/linuxserver/darktable:latest\n container_name: darktable\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-darktable/master/Dockerfile", + "dockerfile_sha256": "c43ed3fbf915e09c477b73fd47dec0f1172f74a3943b04dea05325252415b76f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/databag.json b/oci/catalog/apps/databag.json new file mode 100644 index 00000000..b736d000 --- /dev/null +++ b/oci/catalog/apps/databag.json @@ -0,0 +1,393 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-databag", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Databag" + }, + "tagline": { + "en_US": "Messenger for the Decentralized Web" + }, + "description": { + "en_US": "Databag is a federated chat app for self-hosting that focuses on user privacy and security; the service includes clients for iOS, Android, and browser." + }, + "category": "communication", + "category_label": "Communication & Community", + "author": "balzack", + "developer": "balzack", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 7000, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/balzack/databag", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "balzack", + "repository": "https://hub.docker.com/r/balzack/databag", + "revision": "86b3017fe940de09f8842182d09281ac89b0f9be7725c25e5a1125906086bf2e", + "image_repository_url": "https://hub.docker.com/r/balzack/databag", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "86b3017fe940de09f8842182d09281ac89b0f9be7725c25e5a1125906086bf2e", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "databag", + "container_name": "databag", + "image": { + "reference": "balzack/databag:latest", + "registry": "docker.io", + "repository": "balzack/databag", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/lib/databag", + "compose_source_example": "/DATA/AppData/databag/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 7000, + "published_example": 7000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: databag\nservices:\n databag:\n image: balzack/databag:latest\n restart: unless-stopped\n ports:\n - target: 7000\n published: 7000\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/databag/data\n target: /var/lib/databag\n container_name: databag\n" + }, + "compose_stack": { + "project_name": "databag", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "databag", + "service_count": 1, + "services": [ + { + "name": "databag", + "image": "balzack/databag:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "balzack/databag:latest", + "restart": "unless-stopped", + "ports": [ + { + "target": 7000, + "published": 7000, + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/databag/data", + "target": "/var/lib/databag" + } + ], + "container_name": "databag" + } + } + ], + "top_level": { + "name": "databag" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "databag-volume-0", + "service": "databag", + "container_path": "/var/lib/databag", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "databag" + ], + "stop_order": [ + "databag" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/davos.json b/oci/catalog/apps/davos.json new file mode 100644 index 00000000..76f120e2 --- /dev/null +++ b/oci/catalog/apps/davos.json @@ -0,0 +1,257 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-davos", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Davos" + }, + "tagline": { + "en_US": "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow." + }, + "description": { + "en_US": "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/davos-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/davos-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://github.com/linuxserver/davos", + "documentation": "https://docs.linuxserver.io/images/docker-davos/", + "repository": "https://github.com/linuxserver/docker-davos", + "tips": [], + "mini_changelog": [ + { + "date": "2025-01-27", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-24", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-07-12", + "note": "Rebase to Alpine 3.18." + }, + { + "date": "2023-07-07", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + } + ], + "display_version": null, + "updated_at": "2025-01-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-davos", + "default_branch": "master", + "revision": "417449f0627091795348596bae78c970a96cd423", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-davos/417449f0627091795348596bae78c970a96cd423/README.md", + "readme_pushed_at": "2025-11-21T18:46:32Z", + "compose_sha256": "83916341351e702904a000b98f2b63bc43b85f8194162479464a0ba74d7cc622", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "davos", + "container_name": "davos", + "image": { + "reference": "lscr.io/linuxserver/davos:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/davos", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/davos/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/download", + "compose_source_example": "/path/to/downloads/folder", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n davos:\n image: lscr.io/linuxserver/davos:latest\n container_name: davos\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/davos/data:/config\n - /path/to/downloads/folder:/download\n ports:\n - 8080:8080\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ddclient.json b/oci/catalog/apps/ddclient.json new file mode 100644 index 00000000..3678687e --- /dev/null +++ b/oci/catalog/apps/ddclient.json @@ -0,0 +1,225 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ddclient", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Ddclient" + }, + "tagline": { + "en_US": "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways." + }, + "description": { + "en_US": "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways." + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ddclient-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ddclient-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://github.com/ddclient/ddclient", + "documentation": "https://docs.linuxserver.io/images/docker-ddclient/", + "repository": "https://github.com/linuxserver/docker-ddclient", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-10", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-07-08", + "note": "Fix cache issue." + }, + { + "date": "2024-07-08", + "note": "Don't copy config from `/config/ddclient.conf` to `/ddclient.conf` at runtime." + }, + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2025-07-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ddclient", + "default_branch": "master", + "revision": "ed4e3b047328be36aa8ef4f30257e0abe5e885b6", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ddclient/ed4e3b047328be36aa8ef4f30257e0abe5e885b6/README.md", + "readme_pushed_at": "2026-09-08T11:59:00Z", + "compose_sha256": "89d3a953e0914852da81376043c40f101bf90159d68ed5178589433739f064d2", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "ddclient", + "container_name": "ddclient", + "image": { + "reference": "lscr.io/linuxserver/ddclient:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ddclient", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/ddclient/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ddclient:\n image: lscr.io/linuxserver/ddclient:latest\n container_name: ddclient\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/ddclient/config:/config\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ddns-go.json b/oci/catalog/apps/ddns-go.json new file mode 100644 index 00000000..6ba111fd --- /dev/null +++ b/oci/catalog/apps/ddns-go.json @@ -0,0 +1,401 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-ddns-go", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "ddns-go" + }, + "tagline": { + "en_US": "Simple and easy to use DDNS" + }, + "description": { + "en_US": "A simple and easy-to-use DDNS tool. Automatically updates domain name resolution to your public IP (supports Alibaba Cloud, Tencent Cloud, Dnspod, Cloudflare, Callback, Huawei Cloud, Baidu Cloud, Porkbun, GoDaddy, and Google Domain).\n\nDeploy DDNS-go on self-hosted server, and you can bind the public IP of your self-hosted server device to your domain name. This way, you can access your self-hosted server device via the domain name while you are away.\n" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "jeessy2", + "developer": "jeessy2", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9876, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/jeessy/ddns-go", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "jeessy", + "repository": "https://hub.docker.com/r/jeessy/ddns-go", + "revision": "31ce4e8b497a15a2da1f56f7fdf3ad9ef1c41b0521b35ae9fdbf75dc4c5293c8", + "image_repository_url": "https://hub.docker.com/r/jeessy/ddns-go", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "31ce4e8b497a15a2da1f56f7fdf3ad9ef1c41b0521b35ae9fdbf75dc4c5293c8", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "ddns-go", + "container_name": "ddns-go", + "image": { + "reference": "jeessy/ddns-go:latest", + "registry": "docker.io", + "repository": "jeessy/ddns-go", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/root", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 9876, + "published_example": 9876, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: ddns-go\nservices:\n ddns-go:\n image: jeessy/ddns-go:latest\n network_mode: bridge\n deploy:\n resources:\n reservations:\n memory: 32M\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /root\n ports:\n - target: 9876\n published: '9876'\n protocol: tcp\n container_name: ddns-go\n" + }, + "compose_stack": { + "project_name": "ddns-go", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "ddns-go", + "service_count": 1, + "services": [ + { + "name": "ddns-go", + "image": "jeessy/ddns-go:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jeessy/ddns-go:latest", + "network_mode": "bridge", + "deploy": { + "resources": { + "reservations": { + "memory": "32M" + } + } + }, + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/root" + } + ], + "ports": [ + { + "target": 9876, + "published": "9876", + "protocol": "tcp" + } + ], + "container_name": "ddns-go" + } + } + ], + "top_level": { + "name": "ddns-go" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "ddns-go-volume-0", + "service": "ddns-go", + "container_path": "/root", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "ddns-go" + ], + "stop_order": [ + "ddns-go" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9876, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ddns-updater.json b/oci/catalog/apps/ddns-updater.json new file mode 100644 index 00000000..fb72e7c5 --- /dev/null +++ b/oci/catalog/apps/ddns-updater.json @@ -0,0 +1,552 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-ddns-updater", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "ddns-updater" + }, + "tagline": { + "en_US": "Simple and easy to use DDNS" + }, + "description": { + "en_US": "Program to keep DNS A and/or AAAA records updated for multiple DNS providers" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "qmcgaw", + "developer": "qmcgaw", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/qmcgaw/ddns-updater", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "qmcgaw", + "repository": "https://hub.docker.com/r/qmcgaw/ddns-updater", + "revision": "dc9ae469cfe5fcbfba2a840dd40b57eeedda3125499d2c92236830d6062dce10", + "image_repository_url": "https://hub.docker.com/r/qmcgaw/ddns-updater", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "dc9ae469cfe5fcbfba2a840dd40b57eeedda3125499d2c92236830d6062dce10", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "ddns-updater", + "container_name": "ddns-updater", + "image": { + "reference": "qmcgaw/ddns-updater:latest", + "registry": "docker.io", + "repository": "qmcgaw/ddns-updater", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "BACKUP_DIRECTORY", + "example": "/updater/data", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BACKUP_PERIOD", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CONFIG", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "HTTP_TIMEOUT", + "example": "10s", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LISTENING_ADDRESS", + "example": ":8000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOG_CALLER", + "example": "hidden", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOG_LEVEL", + "example": "info", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PERIOD", + "example": "5m", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLICIP_DNS_PROVIDERS", + "example": "all", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLICIP_DNS_TIMEOUT", + "example": "3s", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLICIP_FETCHERS", + "example": "all", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLICIP_HTTP_PROVIDERS", + "example": "all", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLICIPV4_HTTP_PROVIDERS", + "example": "all", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLICIPV6_HTTP_PROVIDERS", + "example": "all", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ROOT_URL", + "example": "/", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SHOUTRRR_ADDRESSES", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "UPDATE_COOLDOWN_PERIOD", + "example": "5m", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/updater/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: ddns-updater\nservices:\n ddns-updater:\n image: qmcgaw/ddns-updater:latest\n network_mode: bridge\n command:\n - touch /data/config.json\n container_name: ddns-updater\n deploy:\n resources:\n limits:\n memory: 32M\n environment:\n - BACKUP_DIRECTORY=/updater/data\n - BACKUP_PERIOD=0\n - CONFIG=\n - HTTP_TIMEOUT=10s\n - LISTENING_ADDRESS=:8000\n - LOG_CALLER=hidden\n - LOG_LEVEL=info\n - PERIOD=5m\n - PUBLICIP_DNS_PROVIDERS=all\n - PUBLICIP_DNS_TIMEOUT=3s\n - PUBLICIP_FETCHERS=all\n - PUBLICIP_HTTP_PROVIDERS=all\n - PUBLICIPV4_HTTP_PROVIDERS=all\n - PUBLICIPV6_HTTP_PROVIDERS=all\n - ROOT_URL=/\n - SHOUTRRR_ADDRESSES=\n - UPDATE_COOLDOWN_PERIOD=5m\n hostname: ddns-updater\n ports:\n - target: 8000\n published: '8000'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /updater/data\n" + }, + "compose_stack": { + "project_name": "ddns-updater", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "ddns-updater", + "service_count": 1, + "services": [ + { + "name": "ddns-updater", + "image": "qmcgaw/ddns-updater:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "qmcgaw/ddns-updater:latest", + "network_mode": "bridge", + "command": [ + "touch /data/config.json" + ], + "container_name": "ddns-updater", + "deploy": { + "resources": { + "limits": { + "memory": "32M" + } + } + }, + "environment": [ + "BACKUP_DIRECTORY=/updater/data", + "BACKUP_PERIOD=0", + "CONFIG=", + "HTTP_TIMEOUT=10s", + "LISTENING_ADDRESS=:8000", + "LOG_CALLER=hidden", + "LOG_LEVEL=info", + "PERIOD=5m", + "PUBLICIP_DNS_PROVIDERS=all", + "PUBLICIP_DNS_TIMEOUT=3s", + "PUBLICIP_FETCHERS=all", + "PUBLICIP_HTTP_PROVIDERS=all", + "PUBLICIPV4_HTTP_PROVIDERS=all", + "PUBLICIPV6_HTTP_PROVIDERS=all", + "ROOT_URL=/", + "SHOUTRRR_ADDRESSES=", + "UPDATE_COOLDOWN_PERIOD=5m" + ], + "hostname": "ddns-updater", + "ports": [ + { + "target": 8000, + "published": "8000", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/updater/data" + } + ] + } + } + ], + "top_level": { + "name": "ddns-updater" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "ddns-updater-volume-0", + "service": "ddns-updater", + "container_path": "/updater/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "ddns-updater" + ], + "stop_order": [ + "ddns-updater" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "touch /data/config.json" + ], + "hostname": "ddns-updater" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/deepseek-ocr-nvidia.json b/oci/catalog/apps/deepseek-ocr-nvidia.json new file mode 100644 index 00000000..28908474 --- /dev/null +++ b/oci/catalog/apps/deepseek-ocr-nvidia.json @@ -0,0 +1,476 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-deepseek-ocr-nvidia", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "DeepSeek OCR(Nvidia GPU)" + }, + "tagline": { + "en_US": "Powerful OCR powered by DeepSeek AI" + }, + "description": { + "en_US": "DeepSeek OCR is a powerful open-source OCR (Optical Character Recognition) tool based on the advanced DeepSeek-AI model. It enables accurate text extraction from images and document scans via a user-friendly web interface and API. Supports various image formats and offers configurations for image size, cropping, and upload limits. Additionally, DeepSeek OCR features four core recognition modes: Plain OCR for raw text extraction, Describe for intelligent image content descriptions, Find for keyword localization with visual bounding box returns, and Freeform for flexible image understanding tasks based on custom prompts.\n\n**Key Features:**\n- High-accuracy text recognition with DeepSeek-OCR, supporting images and multi-page PDF documents\n- Preserves document layout including tables, formulas, and structural formatting\n- Web frontend (React) and REST API (FastAPI) for easy usage and system integration\n- Export results to Markdown, HTML, DOCX, or JSON formats\n- Automatic extraction and embedding of images from PDF files\n- GPU acceleration and Docker deployment for fast and scalable processing\n\n**Prerequisites:**\n- self-hosted server version 1.5.2 or higher, or NVIDIA Open Driver version 580 or higher\n- NVIDIA GPU with >= 8 GB VRAM for optimal performance\n\n**Learn More:**\n- [DeepSeek OCR App (GitHub)](https://github.com/rdumasia303/deepseek_ocr_app)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "rdumasia303", + "developer": "rdumasia303", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/icewhaletech/deepseek-ocr-frontend", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "icewhaletech", + "repository": "https://hub.docker.com/r/icewhaletech/deepseek-ocr-frontend", + "revision": "c8e9a7bebed9e83d7ffedceb9e118c90f489049e456276054d3e344cb1f1e1fe", + "image_repository_url": "https://hub.docker.com/r/icewhaletech/deepseek-ocr-frontend", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "c8e9a7bebed9e83d7ffedceb9e118c90f489049e456276054d3e344cb1f1e1fe", + "generated_at": "2026-09-13T15:48:22+00:00" + }, + "container_contract": { + "service_name": "deepseek-ocr-frontend", + "container_name": "deepseek-ocr-frontend", + "image": { + "reference": "icewhaletech/deepseek-ocr-frontend:latest", + "registry": "docker.io", + "repository": "icewhaletech/deepseek-ocr-frontend", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [ + { + "container_port": 80, + "published_example": 23000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "deepseek-ocr-backend", + "image": "icewhaletech/deepseek-ocr-backend:latest" + } + ], + "restart": null, + "stop_grace_period": null, + "original_compose": "name: deepseek-ocr-nvidia\nservices:\n deepseek-ocr-backend:\n image: icewhaletech/deepseek-ocr-backend:latest\n container_name: deepseek-ocr-backend\n environment:\n API_HOST: 0.0.0.0\n API_PORT: '8000'\n FRONTEND_PORT: '3000'\n MODEL_NAME: deepseek-ai/DeepSeek-OCR\n HF_HOME: /models\n MAX_UPLOAD_SIZE_MB: '100'\n BASE_SIZE: '1024'\n IMAGE_SIZE: '640'\n CROP_MODE: 'true'\n volumes:\n - /DATA/AppData/$AppID/models:/models\n deploy:\n resources:\n reservations:\n devices:\n - driver: nvidia\n count: all\n capabilities:\n - gpu\n memory: 8G\n shm_size: 4g\n ports:\n - target: 8000\n published: '22523'\n protocol: tcp\n networks:\n - deepseek-ocr-network\n deepseek-ocr-frontend:\n image: icewhaletech/deepseek-ocr-frontend:latest\n container_name: deepseek-ocr-frontend\n ports:\n - target: 80\n published: '23000'\n protocol: tcp\n deploy:\n resources:\n reservations:\n memory: 512M\n depends_on:\n - deepseek-ocr-backend\n networks:\n - deepseek-ocr-network\nnetworks:\n deepseek-ocr-network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "deepseek-ocr-nvidia", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "deepseek-ocr-frontend", + "service_count": 2, + "services": [ + { + "name": "deepseek-ocr-backend", + "image": "icewhaletech/deepseek-ocr-backend:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "icewhaletech/deepseek-ocr-backend:latest", + "container_name": "deepseek-ocr-backend", + "environment": { + "API_HOST": "0.0.0.0", + "API_PORT": "8000", + "FRONTEND_PORT": "3000", + "MODEL_NAME": "deepseek-ai/DeepSeek-OCR", + "HF_HOME": "/models", + "MAX_UPLOAD_SIZE_MB": "100", + "BASE_SIZE": "1024", + "IMAGE_SIZE": "640", + "CROP_MODE": "true" + }, + "volumes": [ + "/DATA/AppData/$AppID/models:/models" + ], + "deploy": { + "resources": { + "reservations": { + "devices": [ + { + "driver": "nvidia", + "count": "all", + "capabilities": [ + "gpu" + ] + } + ], + "memory": "8G" + } + } + }, + "shm_size": "4g", + "ports": [ + { + "target": 8000, + "published": "22523", + "protocol": "tcp" + } + ], + "networks": [ + "deepseek-ocr-network" + ] + } + }, + { + "name": "deepseek-ocr-frontend", + "image": "icewhaletech/deepseek-ocr-frontend:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "deepseek-ocr-backend" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "icewhaletech/deepseek-ocr-frontend:latest", + "container_name": "deepseek-ocr-frontend", + "ports": [ + { + "target": 80, + "published": "23000", + "protocol": "tcp" + } + ], + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "depends_on": [ + "deepseek-ocr-backend" + ], + "networks": [ + "deepseek-ocr-network" + ] + } + } + ], + "top_level": { + "name": "deepseek-ocr-nvidia", + "networks": { + "deepseek-ocr-network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "deepseek-ocr-backend-volume-0", + "service": "deepseek-ocr-backend", + "container_path": "/models", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "deepseek-ocr-backend", + "deepseek-ocr-frontend" + ], + "stop_order": [ + "deepseek-ocr-frontend", + "deepseek-ocr-backend" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "deepseek-ocr-backend: perfil de salud y persistencia pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/deluge.json b/oci/catalog/apps/deluge.json new file mode 100644 index 00000000..eec8dd26 --- /dev/null +++ b/oci/catalog/apps/deluge.json @@ -0,0 +1,293 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-deluge", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Deluge" + }, + "tagline": { + "en_US": "Deluge is a lightweight, Free Software, cross-platform BitTorrent client." + }, + "description": { + "en_US": "Deluge is a lightweight, Free Software, cross-platform BitTorrent client." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/deluge-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/deluge-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8112, + "path": "/" + }, + "website": "http://deluge-torrent.org/", + "documentation": "https://docs.linuxserver.io/images/docker-deluge/", + "repository": "https://github.com/linuxserver/docker-deluge", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-02", + "note": "Install from pypi due to Alpine geoip package deprecation." + }, + { + "date": "2025-12-29", + "note": "Fix some issues with GeoIP updates." + }, + { + "date": "2025-08-23", + "note": "Update GeoIP provider, add weekly cronjob to update." + }, + { + "date": "2025-01-12", + "note": "Rebase libtorrentv1 branch to Alpine 3.21." + }, + { + "date": "2024-09-19", + "note": "Prevent race condition related delay during container stop." + } + ], + "display_version": null, + "updated_at": "2026-04-02" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-deluge", + "default_branch": "master", + "revision": "9f6c513aabbf37a820d887e2c41b6f20cdb98e0a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-deluge/9f6c513aabbf37a820d887e2c41b6f20cdb98e0a/README.md", + "readme_pushed_at": "2026-09-07T19:33:30Z", + "compose_sha256": "504673c02864a4a1e9a9ec7bf2a9f4c3d12c1219db86e6868651e13d12539b4a", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "deluge", + "container_name": "deluge", + "image": { + "reference": "lscr.io/linuxserver/deluge:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/deluge", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DELUGE_LOGLEVEL", + "example": "error", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/deluge/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8112, + "published_example": 8112, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 6881, + "published_example": 6881, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 6881, + "published_example": 6881, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 58846, + "published_example": 58846, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n deluge:\n image: lscr.io/linuxserver/deluge:latest\n container_name: deluge\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DELUGE_LOGLEVEL=error #optional\n volumes:\n - /path/to/deluge/config:/config\n - /path/to/downloads:/downloads\n ports:\n - 8112:8112\n - 6881:6881\n - 6881:6881/udp\n - 58846:58846 #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8112, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [ + { + "label": "Default login", + "username": "admin", + "password": "deluge", + "change_required": true, + "source": "linuxserver-readme-application-setup" + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/dify.json b/oci/catalog/apps/dify.json new file mode 100644 index 00000000..2de1205f --- /dev/null +++ b/oci/catalog/apps/dify.json @@ -0,0 +1,1080 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-dify", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "Dify" + }, + "tagline": { + "en_US": "LLM App Development Platform" + }, + "description": { + "en_US": "Dify is an open-source large language model (LLM) application development platform. It combines the concepts of Backend-as-a-Service and LLMOps to enable developers to quickly build production-grade generative AI applications. Even non-technical personnel can participate in the definition and data operations of AI applications." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "LangGenius", + "developer": "LangGenius", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3701, + "path": "/" + }, + "website": "https://dify.ai", + "documentation": null, + "repository": "https://hub.docker.com/r/langgenius/dify-web", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "langgenius", + "repository": "https://hub.docker.com/r/langgenius/dify-web", + "revision": "4610bb3d0fdc309d1ac9020e20a0b9bac9bf84e9e30b2bccebc86873f4e6d177", + "image_repository_url": "https://hub.docker.com/r/langgenius/dify-web", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "4610bb3d0fdc309d1ac9020e20a0b9bac9bf84e9e30b2bccebc86873f4e6d177", + "generated_at": "2026-09-13T15:48:24+00:00" + }, + "container_contract": { + "service_name": "web", + "container_name": "dify-web", + "image": { + "reference": "langgenius/dify-web:latest", + "registry": "docker.io", + "repository": "langgenius/dify-web", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "CONSOLE_API_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "APP_API_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [], + "related_services": [ + { + "name": "config", + "image": "ns2kracy/dify-config:latest" + }, + { + "name": "api", + "image": "langgenius/dify-api:latest" + }, + { + "name": "worker", + "image": "langgenius/dify-api:latest" + }, + { + "name": "db", + "image": "postgres:latest" + }, + { + "name": "redis", + "image": "redis:latest" + }, + { + "name": "weaviate", + "image": "semitechnologies/weaviate:latest" + }, + { + "name": "sandbox", + "image": "langgenius/dify-sandbox:latest" + }, + { + "name": "ssrf_proxy", + "image": "ubuntu/squid:latest" + }, + { + "name": "nginx", + "image": "nginx:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: dify\nservices:\n config:\n container_name: dify-config\n restart: unless-stopped\n image: ns2kracy/dify-config:latest\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data/nginx\n target: /configs/nginx\n - type: bind\n source: /DATA/AppData/$AppID/data/ssrf_proxy\n target: /configs/ssrf_proxy\n - type: bind\n source: /DATA/AppData/$AppID/data/sandbox\n target: /configs/sandbox\n networks:\n - dify\n api:\n image: langgenius/dify-api:latest\n container_name: dify-api\n restart: unless-stopped\n environment:\n MODE: api\n LOG_LEVEL: INFO\n SECRET_KEY: ${GENERATED_SECRET_KEY}\n CONSOLE_WEB_URL: ''\n INIT_PASSWORD: ${GENERATED_INIT_PASSWORD}\n CONSOLE_API_URL: ''\n SERVICE_API_URL: ''\n APP_WEB_URL: ''\n FILES_URL: ''\n FILES_ACCESS_TIMEOUT: '300'\n MIGRATION_ENABLED: 'true'\n DB_USERNAME: postgres\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n DB_HOST: db\n DB_PORT: '5432'\n DB_DATABASE: dify\n REDIS_HOST: redis\n REDIS_PORT: '6379'\n REDIS_PASSWORD: ${GENERATED_REDIS_PASSWORD}\n REDIS_DB: '0'\n CELERY_BROKER_URL: redis://:difyai123456@redis:6379/1\n WEB_API_CORS_ALLOW_ORIGINS: '*'\n CONSOLE_CORS_ALLOW_ORIGINS: '*'\n STORAGE_TYPE: local\n STORAGE_LOCAL_PATH: storage\n VECTOR_STORE: weaviate\n WEAVIATE_ENDPOINT: http://weaviate:8080\n WEAVIATE_API_KEY: ${GENERATED_WEAVIATE_API_KEY}\n CODE_EXECUTION_ENDPOINT: http://sandbox:8194\n CODE_EXECUTION_API_KEY: ${GENERATED_CODE_EXECUTION_API_KEY}\n CODE_MAX_NUMBER: '9223372036854775807'\n CODE_MIN_NUMBER: '-9223372036854775808'\n CODE_MAX_STRING_LENGTH: '80000'\n TEMPLATE_TRANSFORM_MAX_LENGTH: '80000'\n CODE_MAX_STRING_ARRAY_LENGTH: '30'\n CODE_MAX_OBJECT_ARRAY_LENGTH: '30'\n CODE_MAX_NUMBER_ARRAY_LENGTH: '1000'\n SSRF_PROXY_HTTP_URL: http://ssrf_proxy:3128\n SSRF_PROXY_HTTPS_URL: http://ssrf_proxy:3128\n INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH: ${GENERATED_INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH}\n depends_on:\n - db\n - redis\n volumes:\n - /DATA/AppData/$AppID/data/app/api/storage:/app/api/storage\n networks:\n - ssrf_proxy_network\n - dify\n worker:\n image: langgenius/dify-api:latest\n container_name: dify-worker\n restart: unless-stopped\n environment:\n MODE: worker\n LOG_LEVEL: INFO\n SECRET_KEY: ${GENERATED_SECRET_KEY}\n DB_USERNAME: postgres\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n DB_HOST: db\n DB_PORT: '5432'\n DB_DATABASE: dify\n REDIS_HOST: redis\n REDIS_PORT: '6379'\n REDIS_PASSWORD: ${GENERATED_REDIS_PASSWORD}\n REDIS_DB: '0'\n REDIS_USE_SSL: 'false'\n CELERY_BROKER_URL: redis://:difyai123456@redis:6379/1\n STORAGE_TYPE: local\n STORAGE_LOCAL_PATH: storage\n VECTOR_STORE: weaviate\n WEAVIATE_ENDPOINT: http://weaviate:8080\n WEAVIATE_API_KEY: ${GENERATED_WEAVIATE_API_KEY}\n depends_on:\n - db\n - redis\n volumes:\n - /DATA/AppData/$AppID/data/app/api/storage:/app/api/storage\n networks:\n - ssrf_proxy_network\n - dify\n web:\n image: langgenius/dify-web:latest\n container_name: dify-web\n restart: unless-stopped\n environment:\n CONSOLE_API_URL: ''\n APP_API_URL: ''\n deploy:\n resources:\n reservations:\n memory: 2048M\n networks:\n - dify\n db:\n image: postgres:latest\n container_name: dify-db\n restart: unless-stopped\n environment:\n PGUSER: postgres\n POSTGRES_PASSWORD: ${GENERATED_DB_PASSWORD}\n POSTGRES_DB: dify\n PGDATA: /var/lib/postgresql/data/pgdata\n command: \"postgres -c 'max_connections=100'\\n -c 'shared_buffers=128MB'\\n\\\n \\ -c 'work_mem=4MB'\\n -c 'maintenance_work_mem=64MB'\\n \\\n \\ -c 'effective_cache_size=4096MB'\\n\"\n volumes:\n - /DATA/AppData/$AppID/data/db/data:/var/lib/postgresql/data\n healthcheck:\n test:\n - CMD\n - pg_isready\n interval: 1s\n timeout: 3s\n retries: 30\n networks:\n - dify\n redis:\n image: redis:latest\n container_name: dify-redis\n restart: unless-stopped\n environment:\n REDISCLI_AUTH: difyai123456\n volumes:\n - /DATA/AppData/$AppID/data/redis/data:/data\n command: redis-server --requirepass difyai123456\n healthcheck:\n test:\n - CMD\n - redis-cli\n - ping\n networks:\n - dify\n weaviate:\n image: semitechnologies/weaviate:latest\n container_name: dify-weaviate\n restart: unless-stopped\n volumes:\n - /DATA/AppData/$AppID/data/weaviate:/var/lib/weaviate\n environment:\n QUERY_DEFAULTS_LIMIT: '25'\n AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED: 'false'\n PERSISTENCE_DATA_PATH: /var/lib/weaviate\n DEFAULT_VECTORIZER_MODULE: none\n CLUSTER_HOSTNAME: node1\n AUTHENTICATION_APIKEY_ENABLED: ${GENERATED_AUTHENTICATION_APIKEY_ENABLED}\n AUTHENTICATION_APIKEY_ALLOWED_KEYS: ${GENERATED_AUTHENTICATION_APIKEY_ALLOWED_KEYS}\n AUTHENTICATION_APIKEY_USERS: ${GENERATED_AUTHENTICATION_APIKEY_USERS}\n AUTHORIZATION_ADMINLIST_ENABLED: 'true'\n AUTHORIZATION_ADMINLIST_USERS: hello@dify.ai\n networks:\n - dify\n sandbox:\n image: langgenius/dify-sandbox:latest\n container_name: dify-sandbox\n restart: unless-stopped\n environment:\n API_KEY: ${GENERATED_API_KEY}\n GIN_MODE: release\n WORKER_TIMEOUT: '15'\n ENABLE_NETWORK: 'true'\n HTTP_PROXY: http://ssrf_proxy:3128\n HTTPS_PROXY: http://ssrf_proxy:3128\n SANDBOX_PORT: '8194'\n volumes:\n - /DATA/AppData/$AppID/data/sandbox/dependencies:/dependencies\n networks:\n - ssrf_proxy_network\n depends_on:\n - config\n ssrf_proxy:\n image: ubuntu/squid:latest\n container_name: dify-ssrf_proxy\n restart: unless-stopped\n environment:\n HTTP_PORT: 3128\n COREDUMP_DIR: /var/spool/squid\n REVERSE_PROXY_PORT: 8194\n SANDBOX_HOST: sandbox\n SANDBOX_PORT: 8194\n volumes:\n - /DATA/AppData/$AppID/data/ssrf_proxy:/etc/squid\n networks:\n - ssrf_proxy_network\n - dify\n depends_on:\n - config\n nginx:\n image: nginx:latest\n container_name: dify-nginx\n restart: unless-stopped\n volumes:\n - /DATA/AppData/$AppID/data/nginx:/etc/nginx\n depends_on:\n - api\n - web\n - config\n ports:\n - 3701:80\n networks:\n - dify\nnetworks:\n ssrf_proxy_network:\n driver: bridge\n internal: true\n dify:\n name: dify\n" + }, + "compose_stack": { + "project_name": "dify", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "web", + "service_count": 10, + "services": [ + { + "name": "db", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:latest", + "container_name": "dify-db", + "restart": "unless-stopped", + "environment": { + "PGUSER": "postgres", + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}", + "POSTGRES_DB": "dify", + "PGDATA": "/var/lib/postgresql/data/pgdata" + }, + "command": "postgres -c 'max_connections=100'\n -c 'shared_buffers=128MB'\n -c 'work_mem=4MB'\n -c 'maintenance_work_mem=64MB'\n -c 'effective_cache_size=4096MB'\n", + "volumes": [ + "/DATA/AppData/$AppID/data/db/data:/var/lib/postgresql/data" + ], + "healthcheck": { + "test": [ + "CMD", + "pg_isready" + ], + "interval": "1s", + "timeout": "3s", + "retries": 30 + }, + "networks": [ + "dify" + ] + } + }, + { + "name": "redis", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "redis:latest", + "container_name": "dify-redis", + "restart": "unless-stopped", + "environment": { + "REDISCLI_AUTH": "difyai123456" + }, + "volumes": [ + "/DATA/AppData/$AppID/data/redis/data:/data" + ], + "command": "redis-server --requirepass difyai123456", + "healthcheck": { + "test": [ + "CMD", + "redis-cli", + "ping" + ] + }, + "networks": [ + "dify" + ] + } + }, + { + "name": "api", + "image": "langgenius/dify-api:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [ + "db", + "redis" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "langgenius/dify-api:latest", + "container_name": "dify-api", + "restart": "unless-stopped", + "environment": { + "MODE": "api", + "LOG_LEVEL": "INFO", + "SECRET_KEY": "${GENERATED_SECRET_KEY}", + "CONSOLE_WEB_URL": "", + "INIT_PASSWORD": "${GENERATED_INIT_PASSWORD}", + "CONSOLE_API_URL": "", + "SERVICE_API_URL": "", + "APP_WEB_URL": "", + "FILES_URL": "", + "FILES_ACCESS_TIMEOUT": "300", + "MIGRATION_ENABLED": "true", + "DB_USERNAME": "postgres", + "DB_PASSWORD": "${GENERATED_DB_PASSWORD}", + "DB_HOST": "db", + "DB_PORT": "5432", + "DB_DATABASE": "dify", + "REDIS_HOST": "redis", + "REDIS_PORT": "6379", + "REDIS_PASSWORD": "${GENERATED_REDIS_PASSWORD}", + "REDIS_DB": "0", + "CELERY_BROKER_URL": "redis://:difyai123456@redis:6379/1", + "WEB_API_CORS_ALLOW_ORIGINS": "*", + "CONSOLE_CORS_ALLOW_ORIGINS": "*", + "STORAGE_TYPE": "local", + "STORAGE_LOCAL_PATH": "storage", + "VECTOR_STORE": "weaviate", + "WEAVIATE_ENDPOINT": "http://weaviate:8080", + "WEAVIATE_API_KEY": "${GENERATED_WEAVIATE_API_KEY}", + "CODE_EXECUTION_ENDPOINT": "http://sandbox:8194", + "CODE_EXECUTION_API_KEY": "${GENERATED_CODE_EXECUTION_API_KEY}", + "CODE_MAX_NUMBER": "9223372036854775807", + "CODE_MIN_NUMBER": "-9223372036854775808", + "CODE_MAX_STRING_LENGTH": "80000", + "TEMPLATE_TRANSFORM_MAX_LENGTH": "80000", + "CODE_MAX_STRING_ARRAY_LENGTH": "30", + "CODE_MAX_OBJECT_ARRAY_LENGTH": "30", + "CODE_MAX_NUMBER_ARRAY_LENGTH": "1000", + "SSRF_PROXY_HTTP_URL": "http://ssrf_proxy:3128", + "SSRF_PROXY_HTTPS_URL": "http://ssrf_proxy:3128", + "INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH": "${GENERATED_INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH}" + }, + "depends_on": [ + "db", + "redis" + ], + "volumes": [ + "/DATA/AppData/$AppID/data/app/api/storage:/app/api/storage" + ], + "networks": [ + "ssrf_proxy_network", + "dify" + ] + } + }, + { + "name": "config", + "image": "ns2kracy/dify-config:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 4, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "dify-config", + "restart": "unless-stopped", + "image": "ns2kracy/dify-config:latest", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data/nginx", + "target": "/configs/nginx" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data/ssrf_proxy", + "target": "/configs/ssrf_proxy" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data/sandbox", + "target": "/configs/sandbox" + } + ], + "networks": [ + "dify" + ] + } + }, + { + "name": "web", + "image": "langgenius/dify-web:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "langgenius/dify-web:latest", + "container_name": "dify-web", + "restart": "unless-stopped", + "environment": { + "CONSOLE_API_URL": "", + "APP_API_URL": "" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "2048M" + } + } + }, + "networks": [ + "dify" + ] + } + }, + { + "name": "nginx", + "image": "nginx:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 5, + "depends_on": [ + "api", + "config", + "web" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "nginx:latest", + "container_name": "dify-nginx", + "restart": "unless-stopped", + "volumes": [ + "/DATA/AppData/$AppID/data/nginx:/etc/nginx" + ], + "depends_on": [ + "api", + "web", + "config" + ], + "ports": [ + "3701:80" + ], + "networks": [ + "dify" + ] + } + }, + { + "name": "sandbox", + "image": "langgenius/dify-sandbox:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 6, + "depends_on": [ + "config" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "langgenius/dify-sandbox:latest", + "container_name": "dify-sandbox", + "restart": "unless-stopped", + "environment": { + "API_KEY": "${GENERATED_API_KEY}", + "GIN_MODE": "release", + "WORKER_TIMEOUT": "15", + "ENABLE_NETWORK": "true", + "HTTP_PROXY": "http://ssrf_proxy:3128", + "HTTPS_PROXY": "http://ssrf_proxy:3128", + "SANDBOX_PORT": "8194" + }, + "volumes": [ + "/DATA/AppData/$AppID/data/sandbox/dependencies:/dependencies" + ], + "networks": [ + "ssrf_proxy_network" + ], + "depends_on": [ + "config" + ] + } + }, + { + "name": "ssrf_proxy", + "image": "ubuntu/squid:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 7, + "depends_on": [ + "config" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "ubuntu/squid:latest", + "container_name": "dify-ssrf_proxy", + "restart": "unless-stopped", + "environment": { + "HTTP_PORT": 3128, + "COREDUMP_DIR": "/var/spool/squid", + "REVERSE_PROXY_PORT": 8194, + "SANDBOX_HOST": "sandbox", + "SANDBOX_PORT": 8194 + }, + "volumes": [ + "/DATA/AppData/$AppID/data/ssrf_proxy:/etc/squid" + ], + "networks": [ + "ssrf_proxy_network", + "dify" + ], + "depends_on": [ + "config" + ] + } + }, + { + "name": "weaviate", + "image": "semitechnologies/weaviate:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 8, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "semitechnologies/weaviate:latest", + "container_name": "dify-weaviate", + "restart": "unless-stopped", + "volumes": [ + "/DATA/AppData/$AppID/data/weaviate:/var/lib/weaviate" + ], + "environment": { + "QUERY_DEFAULTS_LIMIT": "25", + "AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED": "false", + "PERSISTENCE_DATA_PATH": "/var/lib/weaviate", + "DEFAULT_VECTORIZER_MODULE": "none", + "CLUSTER_HOSTNAME": "node1", + "AUTHENTICATION_APIKEY_ENABLED": "${GENERATED_AUTHENTICATION_APIKEY_ENABLED}", + "AUTHENTICATION_APIKEY_ALLOWED_KEYS": "${GENERATED_AUTHENTICATION_APIKEY_ALLOWED_KEYS}", + "AUTHENTICATION_APIKEY_USERS": "${GENERATED_AUTHENTICATION_APIKEY_USERS}", + "AUTHORIZATION_ADMINLIST_ENABLED": "true", + "AUTHORIZATION_ADMINLIST_USERS": "hello@dify.ai" + }, + "networks": [ + "dify" + ] + } + }, + { + "name": "worker", + "image": "langgenius/dify-api:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 9, + "depends_on": [ + "db", + "redis" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "langgenius/dify-api:latest", + "container_name": "dify-worker", + "restart": "unless-stopped", + "environment": { + "MODE": "worker", + "LOG_LEVEL": "INFO", + "SECRET_KEY": "${GENERATED_SECRET_KEY}", + "DB_USERNAME": "postgres", + "DB_PASSWORD": "${GENERATED_DB_PASSWORD}", + "DB_HOST": "db", + "DB_PORT": "5432", + "DB_DATABASE": "dify", + "REDIS_HOST": "redis", + "REDIS_PORT": "6379", + "REDIS_PASSWORD": "${GENERATED_REDIS_PASSWORD}", + "REDIS_DB": "0", + "REDIS_USE_SSL": "false", + "CELERY_BROKER_URL": "redis://:difyai123456@redis:6379/1", + "STORAGE_TYPE": "local", + "STORAGE_LOCAL_PATH": "storage", + "VECTOR_STORE": "weaviate", + "WEAVIATE_ENDPOINT": "http://weaviate:8080", + "WEAVIATE_API_KEY": "${GENERATED_WEAVIATE_API_KEY}" + }, + "depends_on": [ + "db", + "redis" + ], + "volumes": [ + "/DATA/AppData/$AppID/data/app/api/storage:/app/api/storage" + ], + "networks": [ + "ssrf_proxy_network", + "dify" + ] + } + } + ], + "top_level": { + "name": "dify", + "networks": { + "ssrf_proxy_network": { + "driver": "bridge", + "internal": true + }, + "dify": { + "name": "dify" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "config-volume-0", + "service": "config", + "container_path": "/configs/nginx", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "config-volume-1", + "service": "config", + "container_path": "/configs/ssrf_proxy", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "config-volume-2", + "service": "config", + "container_path": "/configs/sandbox", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "api-volume-0", + "service": "api", + "container_path": "/app/api/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "worker-volume-0", + "service": "worker", + "container_path": "/app/api/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "db-volume-0", + "service": "db", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "redis-volume-0", + "service": "redis", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for redis:/data" + }, + { + "id": "weaviate-volume-0", + "service": "weaviate", + "container_path": "/var/lib/weaviate", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "sandbox-volume-0", + "service": "sandbox", + "container_path": "/dependencies", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "ssrf-proxy-volume-0", + "service": "ssrf_proxy", + "container_path": "/etc/squid", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "nginx-volume-0", + "service": "nginx", + "container_path": "/etc/nginx", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 10, + "start_order": [ + "db", + "redis", + "api", + "config", + "web", + "nginx", + "sandbox", + "ssrf_proxy", + "weaviate", + "worker" + ], + "stop_order": [ + "worker", + "weaviate", + "ssrf_proxy", + "sandbox", + "nginx", + "web", + "config", + "api", + "redis", + "db" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "sandbox", + "environment_variable": "API_KEY" + } + ] + }, + { + "id": "authentication-apikey-allowed-keys", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "weaviate", + "environment_variable": "AUTHENTICATION_APIKEY_ALLOWED_KEYS" + } + ] + }, + { + "id": "authentication-apikey-enabled", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "weaviate", + "environment_variable": "AUTHENTICATION_APIKEY_ENABLED" + } + ] + }, + { + "id": "authentication-apikey-users", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "weaviate", + "environment_variable": "AUTHENTICATION_APIKEY_USERS" + } + ] + }, + { + "id": "code-execution-api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api", + "environment_variable": "CODE_EXECUTION_API_KEY" + } + ] + }, + { + "id": "db-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api", + "environment_variable": "DB_PASSWORD" + }, + { + "service": "worker", + "environment_variable": "DB_PASSWORD" + }, + { + "service": "db", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + }, + { + "id": "indexing-max-segmentation-tokens-length", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api", + "environment_variable": "INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH" + } + ] + }, + { + "id": "init-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api", + "environment_variable": "INIT_PASSWORD" + } + ] + }, + { + "id": "redis-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api", + "environment_variable": "REDIS_PASSWORD" + }, + { + "service": "worker", + "environment_variable": "REDIS_PASSWORD" + } + ] + }, + { + "id": "secret-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api", + "environment_variable": "SECRET_KEY" + }, + { + "service": "worker", + "environment_variable": "SECRET_KEY" + } + ] + }, + { + "id": "weaviate-api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "api", + "environment_variable": "WEAVIATE_API_KEY" + }, + { + "service": "worker", + "environment_variable": "WEAVIATE_API_KEY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3701, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "servicios que dependen del principal pendientes" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "service:api:compose-key:depends_on", + "service:worker:compose-key:depends_on", + "service:db:healthcheck-format", + "service:redis:healthcheck-format", + "service:sandbox:compose-key:depends_on", + "service:ssrf_proxy:compose-key:depends_on", + "service:nginx:compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/digikam.json b/oci/catalog/apps/digikam.json new file mode 100644 index 00000000..a7ff09ad --- /dev/null +++ b/oci/catalog/apps/digikam.json @@ -0,0 +1,272 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-digikam", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Digikam" + }, + "tagline": { + "en_US": "digiKam: Professional Photo Management with the Power of Open Source" + }, + "description": { + "en_US": "digiKam: Professional Photo Management with the Power of Open Source" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/digikam-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/digikam-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.digikam.org/", + "documentation": "https://docs.linuxserver.io/images/docker-digikam/", + "repository": "https://github.com/linuxserver/docker-digikam", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform for chromium fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-28", + "note": "Fix CPU usage bug by disabling fake udev." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-digikam", + "default_branch": "master", + "revision": "9021291eab201301bc2bef11e3492f6d36b1c901", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-digikam/9021291eab201301bc2bef11e3492f6d36b1c901/README.md", + "readme_pushed_at": "2026-09-07T18:35:56Z", + "compose_sha256": "3141590f071938a0ab35a48c8fd81ef99b7195f9dfe078d02aa5c033f159a598", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "digikam", + "container_name": "digikam", + "image": { + "reference": "lscr.io/linuxserver/digikam:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/digikam", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n digikam:\n image: lscr.io/linuxserver/digikam:latest\n container_name: digikam\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/diskover.json b/oci/catalog/apps/diskover.json new file mode 100644 index 00000000..c1aa4b0b --- /dev/null +++ b/oci/catalog/apps/diskover.json @@ -0,0 +1,600 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-diskover", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "Diskover" + }, + "tagline": { + "en_US": "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems." + }, + "description": { + "en_US": "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/diskover-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/diskover-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/diskoverdata/diskover-community", + "documentation": "https://docs.linuxserver.io/images/docker-diskover/", + "repository": "https://github.com/linuxserver/docker-diskover", + "tips": [], + "mini_changelog": [ + { + "date": "2024-09-06", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-03-06", + "note": "Existing users should update: site-confs/default.conf - Cleanup default site conf." + }, + { + "date": "2024-03-06", + "note": "Rebase to Alpine 3.19 with php 8.3." + }, + { + "date": "2023-05-25", + "note": "Rebase to Alpine 3.18, deprecate armhf." + }, + { + "date": "2023-04-13", + "note": "Move ssl.conf include to default.conf." + } + ], + "display_version": null, + "updated_at": "2024-09-06", + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-diskover", + "default_branch": "master", + "revision": "ccd08155ea8dea36794c4f4b3d56c3a9be4d9f4e", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-diskover/ccd08155ea8dea36794c4f4b3d56c3a9be4d9f4e/README.md", + "readme_pushed_at": "2026-09-10T14:55:45Z", + "compose_sha256": "160f74a3ded1b800740c6b9125da52b39f121da1b8a41cc0d1774d57a909cbb7", + "generated_at": "2026-09-13T15:48:25+00:00" + }, + "container_contract": { + "service_name": "diskover", + "container_name": "diskover", + "image": { + "reference": "lscr.io/linuxserver/diskover:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/diskover", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "America/New_York", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ES_HOST", + "example": "elasticsearch", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ES_PORT", + "example": "9200", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/diskover/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/diskover/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "elasticsearch", + "image": "docker.elastic.co/elasticsearch/elasticsearch:7.17.22" + }, + { + "name": "elasticsearch-helper", + "image": "alpine" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "version: '2'\nservices:\n diskover:\n image: lscr.io/linuxserver/diskover\n container_name: diskover\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=America/New_York\n - ES_HOST=elasticsearch\n - ES_PORT=9200\n volumes:\n - /path/to/diskover/config:/config\n - /path/to/diskover/data:/data\n ports:\n - 80:80\n mem_limit: 4096m\n restart: unless-stopped\n depends_on:\n - elasticsearch\n elasticsearch:\n container_name: elasticsearch\n image: docker.elastic.co/elasticsearch/elasticsearch:7.17.22\n environment:\n - discovery.type=single-node\n - xpack.security.enabled=false\n - bootstrap.memory_lock=true\n - \"ES_JAVA_OPTS=-Xms1g -Xmx1g\"\n ulimits:\n memlock:\n soft: -1\n hard: -1\n volumes:\n - /path/to/esdata:/usr/share/elasticsearch/data\n ports:\n - 9200:9200\n depends_on:\n - elasticsearch-helper\n restart: unless-stopped\n elasticsearch-helper:\n image: alpine\n command: sh -c \"sysctl -w vm.max_map_count=262144\"\n privileged: true\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 4096, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "resources": { + "memory_default_mb": 4096 + } + }, + "generic_stack_review": [ + "elasticsearch-helper: perfil de salud y persistencia pendiente", + "elasticsearch-helper: privileged necesita revision de pila", + "elasticsearch: perfil de salud y persistencia pendiente" + ], + "stack_adaptation_notes": [ + "mem_limit is translated to the editable Proxmox memory default; ulimits is translated to native lxc.prlimit entries.", + "The upstream original_compose uses Elasticsearch 7.17.22. The normalized catalog candidate uses latest; tag availability and application compatibility must be reviewed before enabling installation.", + "The privileged elasticsearch-helper modifies host vm.max_map_count. No host sysctl is changed and this helper must not be discarded silently.", + "Elasticsearch persistence, healthchecks and host requirements still block the native stack." + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + }, + "compose_stack": { + "project_name": "diskover", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "diskover", + "service_count": 3, + "services": [ + { + "name": "elasticsearch-helper", + "image": "alpine:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "alpine", + "command": "sh -c \"sysctl -w vm.max_map_count=262144\"", + "privileged": true + } + }, + { + "name": "elasticsearch", + "image": "docker.elastic.co/elasticsearch/elasticsearch:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [ + "elasticsearch-helper" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "elasticsearch", + "image": "docker.elastic.co/elasticsearch/elasticsearch:7.17.22", + "environment": [ + "discovery.type=single-node", + "xpack.security.enabled=false", + "bootstrap.memory_lock=true", + "ES_JAVA_OPTS=-Xms1g -Xmx1g" + ], + "ulimits": { + "memlock": { + "soft": -1, + "hard": -1 + } + }, + "volumes": [ + "/path/to/esdata:/usr/share/elasticsearch/data" + ], + "ports": [ + "9200:9200" + ], + "depends_on": [ + "elasticsearch-helper" + ], + "restart": "unless-stopped" + } + }, + { + "name": "diskover", + "image": "lscr.io/linuxserver/diskover:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "elasticsearch" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "lscr.io/linuxserver/diskover", + "container_name": "diskover", + "environment": [ + "PUID=1000", + "PGID=1000", + "TZ=America/New_York", + "ES_HOST=elasticsearch", + "ES_PORT=9200" + ], + "volumes": [ + "/path/to/diskover/config:/config", + "/path/to/diskover/data:/data" + ], + "ports": [ + "80:80" + ], + "mem_limit": "4096m", + "restart": "unless-stopped", + "depends_on": [ + "elasticsearch" + ] + } + } + ], + "top_level": { + "version": "2" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "diskover-volume-0", + "service": "diskover", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "diskover-volume-1", + "service": "diskover", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for diskover:/data" + }, + { + "id": "elasticsearch-volume-0", + "service": "elasticsearch", + "container_path": "/usr/share/elasticsearch/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "elasticsearch-helper", + "elasticsearch", + "diskover" + ], + "stop_order": [ + "diskover", + "elasticsearch", + "elasticsearch-helper" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + } +} diff --git a/oci/catalog/apps/docker-volume-backup.json b/oci/catalog/apps/docker-volume-backup.json new file mode 100644 index 00000000..7bbb24bf --- /dev/null +++ b/oci/catalog/apps/docker-volume-backup.json @@ -0,0 +1,328 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-docker-volume-backup", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "Docker Volume Backup" + }, + "tagline": { + "en_US": "Docker Volume Backup" + }, + "description": { + "en_US": "Requires real Docker daemon/socket and Docker Compose stacks; cannot back up native Proxmox OCI instances as Docker volumes. Hidden pending explicit external Docker integration; no Docker installed on Proxmox." + }, + "category": "tools", + "category_label": "Tools", + "author": "mrcaringi", + "developer": "mrcaringi", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://github.com/MrCaringi/docker-volume-backup", + "documentation": "https://github.com/MrCaringi/docker-volume-backup", + "repository": "https://github.com/MrCaringi/docker-volume-backup", + "tips": [ + "Requires real Docker daemon/socket and Docker Compose stacks; cannot back up native Proxmox OCI instances as Docker volumes. Hidden pending explicit external Docker integration; no Docker installed on Proxmox." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-16", + "hidden": true, + "hidden_reason": "Requires a real Docker daemon and Compose stacks; native OCI instances are not Docker volumes." + }, + "source": { + "provider": "mrcaringi", + "repository": "https://github.com/MrCaringi/docker-volume-backup", + "default_branch": "main", + "revision": "a12dbb8770687a5f8127fe9843e83755d3addbb6", + "readme_raw_url": "https://raw.githubusercontent.com/MrCaringi/docker-volume-backup/a12dbb8770687a5f8127fe9843e83755d3addbb6/README.md", + "image_repository_url": "https://hub.docker.com/r/mrcaringi/docker-volume-backup", + "compose_sha256": "28758bdfd464f5d2ae5ae88ed334f2b6fe842642ca189548086f0c64a76882ef", + "generated_at": "2026-09-16T22:00:00+02:00" + }, + "container_contract": { + "service_name": "docker-volume-backup", + "container_name": "docker-volume-backup", + "image": { + "reference": "mrcaringi/docker-volume-backup:latest", + "registry": "docker.io", + "repository": "mrcaringi/docker-volume-backup", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "CRON_SCHEDULE", + "example": "0 2 * * *", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": true + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": true + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "config-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "backups", + "container_path": "/backup", + "compose_source_example": "/mnt/oci-shared/backups", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "# docker-compose.yml\nservices:\n container-backups:\n image: mrcaringi/docker-volume-backup:latest\n container_name: container-backups\n hostname: myserver # shown in Telegram notifications\n restart: always\n environment:\n CRON_SCHEDULE: \"0 2 * * *\"\n volumes:\n - /var/run/docker.sock:/var/run/docker.sock\n - ./config.json:/config/config.json:ro\n - /path/to/backups:/backup\n # Mount stack directories at the same path used in config.json\n - /home/user/docker/stacks:/home/user/docker/stacks:ro\n" + }, + "compose_stack": { + "project_name": "mkvtoolnix", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mkvtoolnix", + "service_count": 1, + "services": [ + { + "name": "mkvtoolnix", + "image": "jlesage/mkvtoolnix:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/mkvtoolnix:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "mkvtoolnix-config:/config", + "/mnt/oci-shared/media:/storage" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mkvtoolnix-config", + "service": "mkvtoolnix", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "mkvtoolnix-storage", + "service": "mkvtoolnix", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mkvtoolnix" + ], + "stop_order": [ + "mkvtoolnix" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "pending-clean-install" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "not-required" + } + ], + "installer_profile": {}, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [ + "docker-engine-required-no-native-oci-stack-support" + ], + "policy": "Requires real Docker daemon/socket and Docker Compose stacks; cannot back up native Proxmox OCI instances as Docker volumes. Hidden pending explicit external Docker integration; no Docker installed on Proxmox." + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/docmost.json b/oci/catalog/apps/docmost.json new file mode 100644 index 00000000..fc7f8871 --- /dev/null +++ b/oci/catalog/apps/docmost.json @@ -0,0 +1,588 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-docmost", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Docmost" + }, + "tagline": { + "en_US": "A modern wiki and knowledge base for teams" + }, + "description": { + "en_US": "Docmost is a self-hosted collaborative wiki and documentation tool designed for real-time collaboration, allowing multiple users to edit the same page simultaneously without conflicts. Its intuitive interface is ideal for teams managing knowledge bases, project documentation, or wikis, offering an efficient knowledge creation and sharing experience.\n\nThe tool's core features include real-time collaborative editing and space organization. It supports multiple users editing pages in real time for seamless collaboration and organizes pages into 'spaces' for teams, projects, or departments, each with independent permission settings. A rich text editor with Markdown shortcuts simplifies content creation. Built-in Draw.io, Excalidraw, and Mermaid tools provide robust diagramming capabilities.\n\nIt offers permissions management, assigning access via user groups for content security. Pages can be publicly shared via links for external access. Comments enhance communication and feedback, while page history tracks changes. Features like nested navigation, quick search, file attachments, and Markdown/HTML import/export are supported. The tool\u2019s collaboration and flexibility deliver a modern documentation solution.\n\n**Key Features:**\n- Real-time collaborative editing for multiple users\n- Spaces for organizing pages by team, project or department\n- Permissions management with user group access control\n- Rich text editor with Markdown shortcuts\n- Built-in Draw.io, Excalidraw, Mermaid diagramming tools\n- Public page sharing via links\n- Page comments for communication and feedback\n- Page history, nested navigation, search, and file attachments\n\n**Learn More:**\n- [Docmost Official Website](https://docmost.com/)\n- [Docmost GitHub](https://github.com/docmost/docmost)\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "docmost", + "developer": "docmost", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://docmost.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/docmost/docmost", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/docmost/docmost", + "revision": "39d7992c1d6384964082d60c9ffe8891d6eca6003cc7fc31ec3e8cc63fa27f32", + "image_repository_url": "https://hub.docker.com/r/docmost/docmost", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "39d7992c1d6384964082d60c9ffe8891d6eca6003cc7fc31ec3e8cc63fa27f32", + "generated_at": "2026-09-13T15:48:25+00:00" + }, + "container_contract": { + "service_name": "docmost", + "container_name": "docmost", + "image": { + "reference": "docmost/docmost:latest", + "registry": "docker.io", + "repository": "docmost/docmost", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "APP_URL", + "example": "http://localhost:3000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "APP_SECRET", + "example": "${GENERATED_APP_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "DATABASE_URL", + "example": "postgresql://docmost:jcui51lw747yuuk4zrpm@docmost-db:5432/docmost?schema=public", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REDIS_URL", + "example": "redis://docmost-redis:6379", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/data/storage", + "compose_source_example": "/DATA/AppData/$AppID/storage", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "docmost-db", + "image": "postgres:latest" + }, + { + "name": "docmost-redis", + "image": "redis:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: docmost\nservices:\n docmost:\n image: docmost/docmost:latest\n container_name: docmost\n deploy:\n resources:\n reservations:\n memory: 512M\n restart: unless-stopped\n ports:\n - target: 3000\n published: '3000'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/storage\n target: /app/data/storage\n environment:\n APP_URL: http://localhost:3000\n APP_SECRET: ${GENERATED_APP_SECRET}\n DATABASE_URL: postgresql://docmost:jcui51lw747yuuk4zrpm@docmost-db:5432/docmost?schema=public\n REDIS_URL: redis://docmost-redis:6379\n networks:\n - docmost-network\n depends_on:\n - docmost-db\n - docmost-redis\n docmost-db:\n container_name: docmost-db\n image: postgres:latest\n environment:\n POSTGRES_DB: docmost\n POSTGRES_USER: docmost\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/pgdata\n target: /var/lib/postgresql/data\n networks:\n - docmost-network\n docmost-redis:\n container_name: docmost-redis\n image: redis:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/redis\n target: /data\n networks:\n - docmost-network\nnetworks:\n docmost-network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "docmost", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "docmost", + "service_count": 3, + "services": [ + { + "name": "docmost-db", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "docmost-db", + "image": "postgres:latest", + "environment": { + "POSTGRES_DB": "docmost", + "POSTGRES_USER": "docmost", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}" + }, + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/pgdata", + "target": "/var/lib/postgresql/data" + } + ], + "networks": [ + "docmost-network" + ] + } + }, + { + "name": "docmost-redis", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "docmost-redis", + "image": "redis:latest", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/redis", + "target": "/data" + } + ], + "networks": [ + "docmost-network" + ] + } + }, + { + "name": "docmost", + "image": "docmost/docmost:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "docmost-db", + "docmost-redis" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "docmost/docmost:latest", + "container_name": "docmost", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "restart": "unless-stopped", + "ports": [ + { + "target": 3000, + "published": "3000", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/storage", + "target": "/app/data/storage" + } + ], + "environment": { + "APP_URL": "http://localhost:3000", + "APP_SECRET": "${GENERATED_APP_SECRET}", + "DATABASE_URL": "postgresql://docmost:jcui51lw747yuuk4zrpm@docmost-db:5432/docmost?schema=public", + "REDIS_URL": "redis://docmost-redis:6379" + }, + "networks": [ + "docmost-network" + ], + "depends_on": [ + "docmost-db", + "docmost-redis" + ] + } + } + ], + "top_level": { + "name": "docmost", + "networks": { + "docmost-network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "docmost-volume-0", + "service": "docmost", + "container_path": "/app/data/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "docmost-db-volume-0", + "service": "docmost-db", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "docmost-redis-volume-0", + "service": "docmost-redis", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for docmost-redis:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "docmost-db", + "docmost-redis", + "docmost" + ], + "stop_order": [ + "docmost", + "docmost-redis", + "docmost-db" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "app-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "docmost", + "environment_variable": "APP_SECRET" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "docmost-db", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/dogwalk.json b/oci/catalog/apps/dogwalk.json new file mode 100644 index 00000000..dbb01354 --- /dev/null +++ b/oci/catalog/apps/dogwalk.json @@ -0,0 +1,268 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-dogwalk", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Dogwalk" + }, + "tagline": { + "en_US": "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid." + }, + "description": { + "en_US": "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dogwalk-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dogwalk-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://studio.blender.org/projects/dogwalk/", + "documentation": "https://docs.linuxserver.io/images/docker-dogwalk/", + "repository": "https://github.com/linuxserver/docker-dogwalk", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Trixie, bump Dogwalk." + }, + { + "date": "2025-07-23", + "note": "Bump DOGWALK to 1.0.2." + }, + { + "date": "2025-07-14", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-dogwalk", + "default_branch": "master", + "revision": "84f77259d875c50e31f2b1a19aac8bb310cf7dc8", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-dogwalk/84f77259d875c50e31f2b1a19aac8bb310cf7dc8/README.md", + "readme_pushed_at": "2026-09-06T01:03:22Z", + "compose_sha256": "d87a4db3d9348df763f1362f417447c799e09e001ccb881c29f977428d298a34", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "dogwalk", + "container_name": "dogwalk", + "image": { + "reference": "lscr.io/linuxserver/dogwalk:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/dogwalk", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/dogwalk/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n dogwalk:\n image: lscr.io/linuxserver/dogwalk:latest\n container_name: dogwalk\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/dogwalk/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/dokuwiki.json b/oci/catalog/apps/dokuwiki.json new file mode 100644 index 00000000..894a06b8 --- /dev/null +++ b/oci/catalog/apps/dokuwiki.json @@ -0,0 +1,248 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-dokuwiki", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Dokuwiki" + }, + "tagline": { + "en_US": "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki." + }, + "description": { + "en_US": "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dokuwiki-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dokuwiki-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://www.dokuwiki.org/dokuwiki/", + "documentation": "https://docs.linuxserver.io/images/docker-dokuwiki/", + "repository": "https://github.com/linuxserver/docker-dokuwiki", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-14", + "note": "Rebase to Alpine 3.24, add php-tokenizer." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-05-10", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-01-23", + "note": "Rebase to Alpine 3.19 with php 8.3." + } + ], + "display_version": null, + "updated_at": "2026-07-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-dokuwiki", + "default_branch": "master", + "revision": "1b38892eb8ad265acaffa9baf4cd67f7f63f9cb2", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-dokuwiki/1b38892eb8ad265acaffa9baf4cd67f7f63f9cb2/README.md", + "readme_pushed_at": "2026-09-11T18:58:18Z", + "compose_sha256": "c84c826250cc01a307f3024f0a62e8a0687f1aace5c396b34e49729ef631c39e", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "dokuwiki", + "container_name": "dokuwiki", + "image": { + "reference": "lscr.io/linuxserver/dokuwiki:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/dokuwiki", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/dokuwiki/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n dokuwiki:\n image: lscr.io/linuxserver/dokuwiki:latest\n container_name: dokuwiki\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/dokuwiki/config:/config\n ports:\n - 80:80\n - 443:443 #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/dolphin.json b/oci/catalog/apps/dolphin.json new file mode 100644 index 00000000..d66957b3 --- /dev/null +++ b/oci/catalog/apps/dolphin.json @@ -0,0 +1,272 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-dolphin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Dolphin" + }, + "tagline": { + "en_US": "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience." + }, + "description": { + "en_US": "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dolphin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dolphin-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://dolphin-emu.org/", + "documentation": "https://docs.linuxserver.io/images/docker-dolphin/", + "repository": "https://github.com/linuxserver/docker-dolphin", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-06", + "note": "Build dolphin from source, ingest latest versions, remove aarch64 support." + }, + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-15", + "note": "Rebase to Debian Trixie for updated Dolphin, update controller mapping." + }, + { + "date": "2025-06-18", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-05-06" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-dolphin", + "default_branch": "master", + "revision": "98b20d38e8a96bfab595dc086e35971d3606aadb", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-dolphin/98b20d38e8a96bfab595dc086e35971d3606aadb/README.md", + "readme_pushed_at": "2026-09-06T01:36:27Z", + "compose_sha256": "ab90cd60f54056de4dcdd84b7b383583fc8cb91191bb3ea09f4ab5bf7d5e4126", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "dolphin", + "container_name": "dolphin", + "image": { + "reference": "lscr.io/linuxserver/dolphin:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/dolphin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n dolphin:\n image: lscr.io/linuxserver/dolphin:latest\n container_name: dolphin\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/doplarr.json b/oci/catalog/apps/doplarr.json new file mode 100644 index 00000000..6cfd91cc --- /dev/null +++ b/oci/catalog/apps/doplarr.json @@ -0,0 +1,351 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-doplarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Deprecation Notice" + }, + "tagline": { + "en_US": "Doplarr is an *arr request bot for Discord.\"" + }, + "description": { + "en_US": "Doplarr is an *arr request bot for Discord.\"" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doplarr-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doplarr-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://github.com/kiranshila/Doplarr", + "documentation": "https://docs.linuxserver.io/images/docker-doplarr/", + "repository": "https://github.com/linuxserver/docker-doplarr", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-27", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-24", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-05-25", + "note": "Rebase to Alpine 3.18." + } + ], + "display_version": null, + "updated_at": "2025-07-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-doplarr", + "default_branch": "main", + "revision": "0ae050b6510a9e305207089fc3c11e5290700acd", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-doplarr/0ae050b6510a9e305207089fc3c11e5290700acd/README.md", + "readme_pushed_at": "2026-07-09T23:30:33Z", + "compose_sha256": "12bed6c74e6999994f0266804a2fbe76b3d511dcbdc881e32dd630a123611778", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "doplarr", + "container_name": "doplarr", + "image": { + "reference": "lscr.io/linuxserver/doplarr:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/doplarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DISCORD__TOKEN", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "OVERSEERR__API", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "OVERSEERR__URL", + "example": "http://localhost:5055", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RADARR__API", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RADARR__URL", + "example": "http://localhost:7878", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SONARR__API", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SONARR__URL", + "example": "http://localhost:8989", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DISCORD__MAX_RESULTS", + "example": "25", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DISCORD__REQUESTED_MSG_STYLE", + "example": ":plain", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SONARR__QUALITY_PROFILE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RADARR__QUALITY_PROFILE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SONARR__ROOTFOLDER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RADARR__ROOTFOLDER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SONARR__LANGUAGE_PROFILE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "OVERSEERR__DEFAULT_ID", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PARTIAL_SEASONS", + "example": "true", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOG_LEVEL", + "example": ":info", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "JAVA_OPTS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/doplarr/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n doplarr:\n image: lscr.io/linuxserver/doplarr:latest\n container_name: doplarr\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DISCORD__TOKEN=\n - OVERSEERR__API=\n - OVERSEERR__URL=http://localhost:5055\n - RADARR__API=\n - RADARR__URL=http://localhost:7878\n - SONARR__API=\n - SONARR__URL=http://localhost:8989\n - DISCORD__MAX_RESULTS=25 #optional\n - DISCORD__REQUESTED_MSG_STYLE=:plain #optional\n - SONARR__QUALITY_PROFILE= #optional\n - RADARR__QUALITY_PROFILE= #optional\n - SONARR__ROOTFOLDER= #optional\n - RADARR__ROOTFOLDER= #optional\n - SONARR__LANGUAGE_PROFILE= #optional\n - OVERSEERR__DEFAULT_ID= #optional\n - PARTIAL_SEASONS=true #optional\n - LOG_LEVEL=:info #optional\n - JAVA_OPTS= #optional\n volumes:\n - /path/to/doplarr/config:/config\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/doplarr_rs.json b/oci/catalog/apps/doplarr_rs.json new file mode 100644 index 00000000..1a6a758a --- /dev/null +++ b/oci/catalog/apps/doplarr_rs.json @@ -0,0 +1,209 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-doplarr-rs", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Doplarr_Rs" + }, + "tagline": { + "en_US": "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust." + }, + "description": { + "en_US": "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doplarr_rs-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doplarr_rs-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://github.com/activexray/doplarr_rs", + "documentation": "https://docs.linuxserver.io/images/docker-doplarr_rs/", + "repository": "https://github.com/linuxserver/docker-doplarr_rs", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-22", + "note": "Initial Release." + } + ], + "display_version": null, + "updated_at": "2026-06-22" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-doplarr_rs", + "default_branch": "main", + "revision": "cdbc28479471da2c653feeb549341d1a0f518d07", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-doplarr_rs/cdbc28479471da2c653feeb549341d1a0f518d07/README.md", + "readme_pushed_at": "2026-09-10T18:29:06Z", + "compose_sha256": "1ddaa7250b2fd7e656df299b62cdc3b8e806b283482f9537780f596fc64ddfb9", + "generated_at": "2026-09-12T14:37:25+00:00" + }, + "container_contract": { + "service_name": "doplarr_rs", + "container_name": "doplarr_rs", + "image": { + "reference": "lscr.io/linuxserver/doplarr_rs:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/doplarr_rs", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/doplarr_rs/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n doplarr_rs:\n image: lscr.io/linuxserver/doplarr_rs:latest\n container_name: doplarr_rs\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/doplarr_rs/config:/config\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/dosbox-staging.json b/oci/catalog/apps/dosbox-staging.json new file mode 100644 index 00000000..1fe95cbb --- /dev/null +++ b/oci/catalog/apps/dosbox-staging.json @@ -0,0 +1,264 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-dosbox-staging", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Dosbox Staging" + }, + "tagline": { + "en_US": "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games." + }, + "description": { + "en_US": "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dosbox-staging-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dosbox-staging-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.dosbox-staging.org/", + "documentation": "https://docs.linuxserver.io/images/docker-dosbox-staging/", + "repository": "https://github.com/linuxserver/docker-dosbox-staging", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-30", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-dosbox-staging", + "default_branch": "master", + "revision": "051745936f752276132374cbea348577fc572b7d", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-dosbox-staging/051745936f752276132374cbea348577fc572b7d/README.md", + "readme_pushed_at": "2026-09-11T15:02:25Z", + "compose_sha256": "faa6b73ceccc05b99ec1be478730ae63b745d57c0e484c950dab7568637ef83d", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "dosbox-staging", + "container_name": "dosbox-staging", + "image": { + "reference": "lscr.io/linuxserver/dosbox-staging:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/dosbox-staging", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n dosbox-staging:\n image: lscr.io/linuxserver/dosbox-staging:latest\n container_name: dosbox-staging\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/doublecommander.json b/oci/catalog/apps/doublecommander.json new file mode 100644 index 00000000..ee6d5a03 --- /dev/null +++ b/oci/catalog/apps/doublecommander.json @@ -0,0 +1,389 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-doublecommander", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Doublecommander" + }, + "tagline": { + "en_US": "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas." + }, + "description": { + "en_US": "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doublecommander-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doublecommander-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://doublecmd.sourceforge.io/", + "documentation": "https://docs.linuxserver.io/images/docker-doublecommander/", + "repository": "https://github.com/linuxserver/docker-doublecommander", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-28", + "note": "Fix CPU usage bug by disabling fake udev." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-doublecommander", + "default_branch": "master", + "revision": "269b0d47b74e8ecb24cbafd655929aba24f228ea", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-doublecommander/269b0d47b74e8ecb24cbafd655929aba24f228ea/README.md", + "readme_pushed_at": "2026-09-09T21:59:22Z", + "compose_sha256": "eeee5613cda05a1dadafb70a55194e3d03e5e840f1303ec7305d496d9cca4103", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "doublecommander", + "container_name": "doublecommander", + "image": { + "reference": "lscr.io/linuxserver/doublecommander:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/doublecommander", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n doublecommander:\n image: lscr.io/linuxserver/doublecommander:latest\n container_name: doublecommander\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n - /path/to/data:/data\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-doublecommander/master/Dockerfile", + "dockerfile_sha256": "6f679c5f1b33a4459369165c23f0fa12d3f97b8c9bf6336d46d805539a49a4e7", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/downtify.json b/oci/catalog/apps/downtify.json new file mode 100644 index 00000000..7ff96bb2 --- /dev/null +++ b/oci/catalog/apps/downtify.json @@ -0,0 +1,459 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-downtify", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Downtify" + }, + "tagline": { + "en_US": "Download Spotify music with album art and metadata" + }, + "description": { + "en_US": "With Downtify you can download Spotify musics containing album art, track names, album title and other metadata about the songs. Just copy the Spotify link, whether it's a single song, an album, etc. As soon as your downloads are complete you will be notified!\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Henrique Sebasti\u00e3o", + "developer": "Henrique Sebasti\u00e3o", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://downtify.henriquesebastiao.com", + "documentation": null, + "repository": "https://ghcr.io/henriquesebastiao/downtify", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "henriquesebastiao", + "repository": "https://ghcr.io/henriquesebastiao/downtify", + "revision": "6bebd2e1e6c3ef3531e828bfc0ed887d131c1e4be3b8b33f3f6ef8fe04b8f24c", + "image_repository_url": "https://ghcr.io/henriquesebastiao/downtify", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "6bebd2e1e6c3ef3531e828bfc0ed887d131c1e4be3b8b33f3f6ef8fe04b8f24c", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "downtify", + "container_name": "downtify", + "image": { + "reference": "ghcr.io/henriquesebastiao/downtify:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/henriquesebastiao/downtify", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/downloads", + "compose_source_example": "/DATA/Downloads/downtify", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8582, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: downtify\nservices:\n downtify:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n image: ghcr.io/henriquesebastiao/downtify:latest\n deploy:\n resources:\n reservations:\n memory: 2048M\n ports:\n - target: 8000\n published: '8582'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/Downloads/downtify\n target: /downloads\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n container_name: downtify\n" + }, + "compose_stack": { + "project_name": "downtify", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "downtify", + "service_count": 1, + "services": [ + { + "name": "downtify", + "image": "ghcr.io/henriquesebastiao/downtify:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "image": "ghcr.io/henriquesebastiao/downtify:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "2048M" + } + } + }, + "ports": [ + { + "target": 8000, + "published": "8582", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/Downloads/downtify", + "target": "/downloads" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "container_name": "downtify" + } + } + ], + "top_level": { + "name": "downtify" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "downtify-volume-0", + "service": "downtify", + "container_path": "/downloads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for downtify:/downloads" + }, + { + "id": "downtify-volume-1", + "service": "downtify", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for downtify:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "downtify" + ], + "stop_order": [ + "downtify" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/dsh-harness.json b/oci/catalog/apps/dsh-harness.json new file mode 100644 index 00000000..d1740c09 --- /dev/null +++ b/oci/catalog/apps/dsh-harness.json @@ -0,0 +1,405 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-dsh-harness", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "DeepSeekHarness" + }, + "tagline": { + "en_US": "DeepSeek Harness \u201cEverything is a Plugin\u201c." + }, + "description": { + "en_US": "DeepSeek Harness (dsh) is an open-source agent harness developed by DeepSeek AI." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "DeepSeek", + "developer": "DeepSeek", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3080, + "path": "/" + }, + "website": "https://www.deepseek.com", + "documentation": null, + "repository": "https://ghcr.io/smanx/deepseek-harness", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "smanx", + "repository": "https://ghcr.io/smanx/deepseek-harness", + "revision": "a8b6e3ae11af62c893064328db3da73a362e02c7a53b0c2e5e70331263afa878", + "image_repository_url": "https://ghcr.io/smanx/deepseek-harness", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "a8b6e3ae11af62c893064328db3da73a362e02c7a53b0c2e5e70331263afa878", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "dsh", + "container_name": "dsh-harness", + "image": { + "reference": "ghcr.io/smanx/deepseek-harness:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/smanx/deepseek-harness", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/root/.dsh", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3080, + "published_example": 3080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: dsh-harness\nservices:\n dsh:\n command: null\n container_name: dsh-harness\n entrypoint: null\n image: ghcr.io/smanx/deepseek-harness:latest\n labels:\n icon: https://cdn.jsdelivr.net/gh/selfhst/icons@main/png/deepseek.png\n networks:\n - default\n ports:\n - mode: ingress\n target: 3080\n published: '3080'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /root/.dsh\n bind:\n create_host_path: true\n" + }, + "compose_stack": { + "project_name": "dsh-harness", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "dsh", + "service_count": 1, + "services": [ + { + "name": "dsh", + "image": "ghcr.io/smanx/deepseek-harness:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "command": null, + "container_name": "dsh-harness", + "entrypoint": null, + "image": "ghcr.io/smanx/deepseek-harness:latest", + "labels": { + "icon": "https://cdn.jsdelivr.net/gh/selfhst/icons@main/png/deepseek.png" + }, + "networks": [ + "default" + ], + "ports": [ + { + "mode": "ingress", + "target": 3080, + "published": "3080", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/root/.dsh", + "bind": { + "create_host_path": true + } + } + ] + } + } + ], + "top_level": { + "name": "dsh-harness" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "dsh-volume-0", + "service": "dsh", + "container_path": "/root/.dsh", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "dsh" + ], + "stop_order": [ + "dsh" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/duckdns.json b/oci/catalog/apps/duckdns.json new file mode 100644 index 00000000..1c34b52e --- /dev/null +++ b/oci/catalog/apps/duckdns.json @@ -0,0 +1,370 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-duckdns", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Duckdns" + }, + "tagline": { + "en_US": "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence." + }, + "description": { + "en_US": "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duckdns-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duckdns-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://duckdns.org/", + "documentation": "https://docs.linuxserver.io/images/docker-duckdns/", + "repository": "https://github.com/linuxserver/docker-duckdns", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-15", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-27", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-24", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-06-17", + "note": "Bump CI_DELAY to 120 seconds as ARM builds were failing." + } + ], + "display_version": null, + "updated_at": "2026-07-15" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-duckdns", + "default_branch": "master", + "revision": "bf81649df47b7283ab0751d1fd34e1f768b0a546", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-duckdns/bf81649df47b7283ab0751d1fd34e1f768b0a546/README.md", + "readme_pushed_at": "2026-09-07T08:51:40Z", + "compose_sha256": "2d83e6a8e4d41ecad5aa9b30a6ace4f3458249ac429b8d5938902097f6cb283f", + "generated_at": "2026-09-13T15:47:46+00:00" + }, + "container_contract": { + "service_name": "duckdns", + "container_name": "duckdns", + "image": { + "reference": "lscr.io/linuxserver/duckdns:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/duckdns", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SUBDOMAINS", + "example": "subdomain1,subdomain2", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TOKEN", + "example": "token", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "UPDATE_IP", + "example": "ipv4", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOG_FILE", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/duckdns/config", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n duckdns:\n image: lscr.io/linuxserver/duckdns:latest\n container_name: duckdns\n network_mode: host #optional\n environment:\n - PUID=1000 #optional\n - PGID=1000 #optional\n - TZ=Etc/UTC #optional\n - SUBDOMAINS=subdomain1,subdomain2\n - TOKEN=token\n - UPDATE_IP=ipv4 #optional\n - LOG_FILE=false #optional\n volumes:\n - /path/to/duckdns/config:/config #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "host" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/duckstation.json b/oci/catalog/apps/duckstation.json new file mode 100644 index 00000000..24c0d2ea --- /dev/null +++ b/oci/catalog/apps/duckstation.json @@ -0,0 +1,269 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-duckstation", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Duckstation" + }, + "tagline": { + "en_US": "DuckStation is a PS1 Emulator aiming for the best accuracy and game support." + }, + "description": { + "en_US": "DuckStation is a PS1 Emulator aiming for the best accuracy and game support." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duckstation-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duckstation-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://duckstation.org/", + "documentation": "https://docs.linuxserver.io/images/docker-duckstation/", + "repository": "https://github.com/linuxserver/docker-duckstation", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-06-19", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-duckstation", + "default_branch": "master", + "revision": "7fffa14503a4eda3ec1f7dfc459178536878f9c3", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-duckstation/7fffa14503a4eda3ec1f7dfc459178536878f9c3/README.md", + "readme_pushed_at": "2026-09-09T05:35:37Z", + "compose_sha256": "5731f361cdddf5bb5b74cb5222d288997e7f492d9c5189a8c9edc9e1a0aa7cd0", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "duckstation", + "container_name": "duckstation", + "image": { + "reference": "lscr.io/linuxserver/duckstation:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/duckstation", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n duckstation:\n image: lscr.io/linuxserver/duckstation:latest\n container_name: duckstation\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/duplicati.json b/oci/catalog/apps/duplicati.json new file mode 100644 index 00000000..90246b7c --- /dev/null +++ b/oci/catalog/apps/duplicati.json @@ -0,0 +1,321 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-duplicati", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Duplicati" + }, + "tagline": { + "en_US": "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others." + }, + "description": { + "en_US": "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others." + }, + "category": "backup", + "category_label": "Backup & Recovery", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duplicati-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duplicati-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8200, + "path": "/" + }, + "website": "https://www.duplicati.com/", + "documentation": "https://docs.linuxserver.io/images/docker-duplicati/", + "repository": "https://github.com/linuxserver/docker-duplicati", + "tips": [], + "mini_changelog": [ + { + "date": "2026-09-03", + "note": "Make sure /config is only accessible by the PUID user." + }, + { + "date": "2025-01-31", + "note": "Make `latest` stable releases, move beta releases to `development`." + }, + { + "date": "2025-01-28", + "note": "Add xz-utils." + }, + { + "date": "2024-12-03", + "note": "Add mscorefonts for captcha support." + }, + { + "date": "2024-11-29", + "note": "Rebase to Noble, add support for settings DB encryption." + } + ], + "display_version": null, + "updated_at": "2026-09-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-duplicati", + "default_branch": "master", + "revision": "63a71b5a130e008f9bf20df18820f6bee1b771f3", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-duplicati/63a71b5a130e008f9bf20df18820f6bee1b771f3/README.md", + "readme_pushed_at": "2026-09-12T08:31:37Z", + "compose_sha256": "5f149ca1dc249caeec8903c4d9f08c5632ff52e1ec28cee05259a431f830cbaa", + "generated_at": "2026-09-13T14:38:33+00:00" + }, + "container_contract": { + "service_name": "duplicati", + "container_name": "duplicati", + "image": { + "reference": "lscr.io/linuxserver/duplicati:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/duplicati", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SETTINGS_ENCRYPTION_KEY", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "CLI_ARGS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DUPLICATI__WEBSERVICE_PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/duplicati/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/backups", + "compose_source_example": "/path/to/backups", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/source", + "compose_source_example": "/path/to/source", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8200, + "published_example": 8200, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n duplicati:\n image: lscr.io/linuxserver/duplicati:latest\n container_name: duplicati\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - SETTINGS_ENCRYPTION_KEY=\n - CLI_ARGS= #optional\n - DUPLICATI__WEBSERVICE_PASSWORD= #optional\n volumes:\n - /path/to/duplicati/config:/config\n - /path/to/backups:/backups\n - /path/to/source:/source\n ports:\n - 8200:8200\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8200, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "generated_sensitive_environment": { + "SETTINGS_ENCRYPTION_KEY": { + "strategy": "token-hex", + "bytes": 16, + "prompt": false + } + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/eden.json b/oci/catalog/apps/eden.json new file mode 100644 index 00000000..edc17a83 --- /dev/null +++ b/oci/catalog/apps/eden.json @@ -0,0 +1,268 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-eden", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Eden" + }, + "tagline": { + "en_US": "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind." + }, + "description": { + "en_US": "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/eden-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/eden-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://eden-emu.dev/", + "documentation": "https://docs.linuxserver.io/images/docker-eden/", + "repository": "https://github.com/linuxserver/docker-eden", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-30", + "note": "Optimize build to match PGO v3 builds for better performance." + }, + { + "date": "2026-05-05", + "note": "Rebase to Debian Trixie, build Eden from source, remove arm64 tag." + }, + { + "date": "2026-03-17", + "note": "Ingest releases from self hosted git." + }, + { + "date": "2026-02-18", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-06-30" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-eden", + "default_branch": "master", + "revision": "02aca45158b16c78c91d6e2da9494b6420fd682a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-eden/02aca45158b16c78c91d6e2da9494b6420fd682a/README.md", + "readme_pushed_at": "2026-09-10T08:58:13Z", + "compose_sha256": "77b0432ece0eed1422b9490813b6da52f22ab522a62f770b089339bdf4b25f19", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "eden", + "container_name": "eden", + "image": { + "reference": "lscr.io/linuxserver/eden:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/eden", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n eden:\n image: lscr.io/linuxserver/eden:latest\n container_name: eden\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/emby-official.json b/oci/catalog/apps/emby-official.json new file mode 100644 index 00000000..8d8dea9b --- /dev/null +++ b/oci/catalog/apps/emby-official.json @@ -0,0 +1,486 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "image-emby-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Emby Official" + }, + "tagline": { + "en_US": "Official Emby Media Server image with optional VA-API or NVIDIA acceleration." + }, + "description": { + "en_US": "Emby is a personal media management platform that brings home videos, music, and photos together, automatically converting and streaming to any device. An intuitive design makes it ideal for users to enjoy media content anytime, anywhere, meeting family entertainment and media management needs.\n\nCore features include cross-device media streaming and easy access. It supports real-time conversion and streaming of personal media to any device for seamless playback. A connection service enables easy media access while away from home. Live TV functionality supports streaming, managing DVR, and accessing a library of recordings. Mobile sync delivers media to smartphones and tablets for offline access, automatically updating new content.\n\nIt offers parental controls to restrict children's content access, set schedules and time limits, and remotely monitor sessions. Chromecast support enables easy streaming of videos, music, photos, and Live TV. Content is presented elegantly, enhancing visual experience. Cloud sync supports backup, archiving, and multi-resolution storage for optimized streaming. Web-based media management facilitates editing metadata, images, and searching subtitles, while DLNA integration auto-detects network devices for content streaming. With convenience and versatility at the core, the platform delivers a modern media management solution.\n\n**Key Features:**\n- Automatic conversion and streaming of media to any device\n- Easy access via connection service while away from home\n- Live TV streaming, DVR management, and recording library access\n- Mobile sync to smartphones and tablets for offline access\n- Parental controls with content restrictions, schedules, and remote monitoring\n- Chromecast support for streaming videos, music, photos, and Live TV\n- Cloud sync for backup and multi-resolution storage\n- Web-based media management for editing metadata and searching subtitles\n- DLNA integration for auto-detecting network devices and streaming content\n\n**Learn More:**\n- [Emby Official Website](https://emby.media/)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Emby Team", + "developer": "Emby Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8096, + "path": "/" + }, + "website": "https://emby.media/", + "documentation": "https://hub.docker.com/r/emby/embyserver", + "repository": "https://hub.docker.com/r/emby/embyserver", + "tips": [ + "UID, GID and GIDLIST follow the official image contract.", + "The installer adds the selected render-device GID to GIDLIST for VA-API access.", + "Emby documents VA-API and NVDEC/NVENC support for amd64 only." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "emby", + "repository": "https://hub.docker.com/r/emby/embyserver", + "default_branch": "master", + "revision": "f324967b88a13e1075d6aa6debe31a955a7c6b47abe4c2d34342bc9d1d964518", + "image_repository_url": "https://hub.docker.com/r/emby/embyserver", + "compose_sha256": "b960d39e446660d21c2e88e89d6ae2ce3e1294c31d9d4ee18b8a94c7b9e8d786", + "generated_at": "2026-09-13T21:08:59+00:00" + }, + "container_contract": { + "service_name": "emby", + "container_name": "embyserver", + "image": { + "reference": "emby/embyserver:latest", + "registry": "docker.io", + "repository": "emby/embyserver", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "UID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "UID that Emby runs as" + }, + { + "name": "GID", + "example": "100", + "required": true, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Primary GID for Emby" + }, + { + "name": "GIDLIST", + "example": "100", + "required": true, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Additional media/GPU GIDs, comma-separated" + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "/path/to/programdata", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "tvshows", + "container_path": "/mnt/share1", + "compose_source_example": "/path/to/tvshows", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 32 + } + }, + { + "id": "movies", + "container_path": "/mnt/share2", + "compose_source_example": "/path/to/movies", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 8096, + "published_example": 8096, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8920, + "published_example": 8920, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 7359, + "published_example": 7359, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 1900, + "published_example": 1900, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "on-failure", + "stop_grace_period": null, + "original_compose": "services:\n emby:\n image: emby/embyserver:latest\n container_name: embyserver\n environment:\n - UID=1000\n - GID=100\n - GIDLIST=100\n volumes:\n - /path/to/programdata:/config\n - /path/to/tvshows:/mnt/share1\n - /path/to/movies:/mnt/share2\n ports:\n - 8096:8096/tcp\n - 8920:8920/tcp\n restart: on-failure\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Emby WebUI", + "scheme": "http", + "port": 8096, + "path": "/", + "source": "official-container-documentation" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Emby", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [], + "architectures": [ + "amd64", + "arm64" + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "append_host_device_gid_to_environment": "GIDLIST" + } + ], + "architectures": [ + "amd64" + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose", + "append_host_device_gid_to_environment": "GIDLIST" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ], + "architectures": [ + "amd64" + ] + } + ] + }, + "startup_healthcheck": { + "scheme": "http", + "port": 8096, + "path": "/", + "timeout_seconds": 240, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "catalog": { + "replaces_discovered_ids": [ + "emby", + "emby-nvidia" + ] + }, + "application_options": { + "hardware_transcoding": { + "show_in_catalog": true, + "selectable": true, + "documented_acceleration_architectures": [ + "amd64" + ], + "backends": [ + "VA-API", + "NVDEC/NVENC" + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/emby.json b/oci/catalog/apps/emby.json new file mode 100644 index 00000000..3979fbd0 --- /dev/null +++ b/oci/catalog/apps/emby.json @@ -0,0 +1,464 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-emby", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Emby" + }, + "tagline": { + "en_US": "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server." + }, + "description": { + "en_US": "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/emby-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/emby-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8096, + "path": "/" + }, + "website": "https://emby.media/", + "documentation": "https://docs.linuxserver.io/images/docker-emby/", + "repository": "https://github.com/linuxserver/docker-emby", + "tips": [], + "mini_changelog": [ + { + "date": "2026-09-11", + "note": "Update lib paths to fix hw transcoding." + }, + { + "date": "2026-07-14", + "note": "Rebase to Ubuntu Resolute." + }, + { + "date": "2026-01-12", + "note": "Set home to /config." + }, + { + "date": "2024-08-13", + "note": "Rebase to Ubuntu Noble." + }, + { + "date": "2024-02-12", + "note": "Use universal hardware acceleration blurb" + } + ], + "display_version": null, + "updated_at": "2026-09-11" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-emby", + "default_branch": "master", + "revision": "462ada8bab73929feed69a32dc77a61de865c307", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-emby/462ada8bab73929feed69a32dc77a61de865c307/README.md", + "readme_pushed_at": "2026-09-11T15:36:08Z", + "compose_sha256": "70fe3039076834edadd9ff1f383f9497f87186921225c5d47d8119c9b0473a39", + "generated_at": "2026-09-13T15:35:42+00:00" + }, + "container_contract": { + "service_name": "emby", + "container_name": "emby", + "image": { + "reference": "lscr.io/linuxserver/emby:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/emby", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/emby/library", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data/tvshows", + "compose_source_example": "/path/to/tvshows", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/data/movies", + "compose_source_example": "/path/to/movies", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/opt/vc/lib", + "compose_source_example": "/opt/vc/lib", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8096, + "published_example": 8096, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8920, + "published_example": 8920, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n emby:\n image: lscr.io/linuxserver/emby:latest\n container_name: emby\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/emby/library:/config\n - /path/to/tvshows:/data/tvshows\n - /path/to/movies:/data/movies\n - /opt/vc/lib:/opt/vc/lib #optional\n ports:\n - 8096:8096\n - 8920:8920 #optional\n devices:\n - /dev/dri:/dev/dri #optional\n - /dev/video10:/dev/video10 #optional\n - /dev/video11:/dev/video11 #optional\n - /dev/video12:/dev/video12 #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8096, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "enable_prompt": "VA-API video acceleration", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/dri:/dev/dri" + }, + { + "id": "dev-video10", + "kind": "character-device", + "purpose": "video-capture", + "enable_prompt": "Pass /dev/video10 to the LXC", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Host device for /dev/video10", + "host_path_default": "/dev/video10", + "container_path": "/dev/video10", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/video10:/dev/video10" + }, + { + "id": "dev-video11", + "kind": "character-device", + "purpose": "video-capture", + "enable_prompt": "Pass /dev/video11 to the LXC", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Host device for /dev/video11", + "host_path_default": "/dev/video11", + "container_path": "/dev/video11", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/video11:/dev/video11" + }, + { + "id": "dev-video12", + "kind": "character-device", + "purpose": "video-capture", + "enable_prompt": "Pass /dev/video12 to the LXC", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Host device for /dev/video12", + "host_path_default": "/dev/video12", + "container_path": "/dev/video12", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/video12:/dev/video12" + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/embystat.json b/oci/catalog/apps/embystat.json new file mode 100644 index 00000000..4ccee2c0 --- /dev/null +++ b/oci/catalog/apps/embystat.json @@ -0,0 +1,428 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-embystat", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Embystat" + }, + "tagline": { + "en_US": "Calculate all kinds of statistics from your (local) Emby or Jellyfin server" + }, + "description": { + "en_US": "EmbyStat is a personal web server that can calculate all kinds of statistics from your (local) Emby or Jellyfin server. Just install this on your server and let him calculate all kinds of fun stuff. This project is still in Alpha phase, but feel free to pull in on your computer and test it out yourself. When the time is right I will host a full informational website/release for common platforms and Wiki pages." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Embystart Team", + "developer": "Embystart Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6555, + "path": "/" + }, + "website": "", + "documentation": "https://docs.linuxserver.io/images/docker-embystat/", + "repository": "https://hub.docker.com/r/linuxserver/embystat", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://hub.docker.com/r/linuxserver/embystat", + "revision": "842f624b097fb12f04cae3d3329c232d675fd0f95e1262978da58da85353f202", + "image_repository_url": "https://hub.docker.com/r/linuxserver/embystat", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "842f624b097fb12f04cae3d3329c232d675fd0f95e1262978da58da85353f202", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "embystat", + "container_name": "embystat", + "image": { + "reference": "linuxserver/embystat:latest", + "registry": "docker.io", + "repository": "linuxserver/embystat", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "Europe/London", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/embystat/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 6555, + "published_example": 6555, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: embystat\nservices:\n embystat:\n environment:\n PGID: '1000'\n PUID: '1000'\n TZ: Europe/London\n image: linuxserver/embystat:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 6555\n published: '6555'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/embystat/config\n target: /config\n container_name: embystat\n" + }, + "compose_stack": { + "project_name": "embystat", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "embystat", + "service_count": 1, + "services": [ + { + "name": "embystat", + "image": "linuxserver/embystat:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "1000", + "PUID": "1000", + "TZ": "Europe/London" + }, + "image": "linuxserver/embystat:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 6555, + "published": "6555", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/embystat/config", + "target": "/config" + } + ], + "container_name": "embystat" + } + } + ], + "top_level": { + "name": "embystat" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "embystat-volume-0", + "service": "embystat", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "embystat" + ], + "stop_order": [ + "embystat" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6555, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/emulatorjs.json b/oci/catalog/apps/emulatorjs.json new file mode 100644 index 00000000..69eed79d --- /dev/null +++ b/oci/catalog/apps/emulatorjs.json @@ -0,0 +1,555 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-emulatorjs", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "emulatorjs" + }, + "tagline": { + "en_US": "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes." + }, + "description": { + "en_US": "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "linuxserver.io", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://emulatorjs.org/", + "documentation": "https://docs.linuxserver.io/images/docker-emulatorjs/", + "repository": "https://hub.docker.com/r/linuxserver/emulatorjs", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://hub.docker.com/r/linuxserver/emulatorjs", + "revision": "155869dc2c09f26534a98d6f79e3dd52ff076e1f5855108e74fc686005c048bf", + "image_repository_url": "https://hub.docker.com/r/linuxserver/emulatorjs", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "155869dc2c09f26534a98d6f79e3dd52ff076e1f5855108e74fc686005c048bf", + "generated_at": "2026-09-13T17:20:20+00:00" + }, + "container_contract": { + "service_name": "emulatorjs", + "container_name": "emulatorjs", + "image": { + "reference": "linuxserver/emulatorjs:latest", + "registry": "docker.io", + "repository": "linuxserver/emulatorjs", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SUBFOLDER", + "example": "/", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/data/nes/roms", + "compose_source_example": "/ROMS/nes", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4001, + "published_example": 4001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 80, + "published_example": 88, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: emulatorjs\nservices:\n emulatorjs:\n environment:\n - PGID=$PGID\n - PUID=$PUID\n - SUBFOLDER=/\n - TZ=$TZ\n image: linuxserver/emulatorjs:latest\n network_mode: bridge\n ports:\n - target: 3000\n published: '3001'\n protocol: tcp\n - target: 4001\n published: '4001'\n protocol: tcp\n - target: 80\n published: '88'\n protocol: tcp\n privileged: true\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n - type: bind\n source: /ROMS/nes\n target: /data/nes/roms\n container_name: emulatorjs\n" + }, + "compose_stack": { + "project_name": "emulatorjs", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "emulatorjs", + "service_count": 1, + "services": [ + { + "name": "emulatorjs", + "image": "linuxserver/emulatorjs:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": [ + "PGID=$PGID", + "PUID=$PUID", + "SUBFOLDER=/", + "TZ=$TZ" + ], + "image": "linuxserver/emulatorjs:latest", + "network_mode": "bridge", + "ports": [ + { + "target": 3000, + "published": "3001", + "protocol": "tcp" + }, + { + "target": 4001, + "published": "4001", + "protocol": "tcp" + }, + { + "target": 80, + "published": "88", + "protocol": "tcp" + } + ], + "privileged": true, + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + }, + { + "type": "bind", + "source": "/ROMS/nes", + "target": "/data/nes/roms" + } + ], + "container_name": "emulatorjs" + } + } + ], + "top_level": { + "name": "emulatorjs" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "emulatorjs-volume-0", + "service": "emulatorjs", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "emulatorjs-volume-1", + "service": "emulatorjs", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for emulatorjs:/data" + }, + { + "id": "emulatorjs-volume-2", + "service": "emulatorjs", + "container_path": "/data/nes/roms", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for emulatorjs:/data/nes/roms" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "emulatorjs" + ], + "stop_order": [ + "emulatorjs" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "bridge" + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": false, + "warning": "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "optional-explicit-user-consent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/esphome.json b/oci/catalog/apps/esphome.json new file mode 100644 index 00000000..510808f1 --- /dev/null +++ b/oci/catalog/apps/esphome.json @@ -0,0 +1,421 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-esphome", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "ESPHome" + }, + "tagline": { + "en_US": "Home Automation systems" + }, + "description": { + "en_US": "ESPHome is a system to control your microcontrollers by simple yet powerful configuration files and control them remotely through Home Automation systems." + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "official", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6052, + "path": "/" + }, + "website": "https://esphome.io", + "documentation": null, + "repository": "https://ghcr.io/esphome/esphome", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/esphome/esphome", + "revision": "779c5ca7e920e78c63eabbe87192450b47bdf25c8e3e1d3394545ae77ea8b6e3", + "image_repository_url": "https://ghcr.io/esphome/esphome", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "779c5ca7e920e78c63eabbe87192450b47bdf25c8e3e1d3394545ae77ea8b6e3", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "esphome", + "container_name": "esphome", + "image": { + "reference": "ghcr.io/esphome/esphome:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/esphome/esphome", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ESPHOME_DASHBOARD_USE_PING", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 6052, + "published_example": 6052, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: esphome\nservices:\n esphome:\n container_name: esphome\n deploy:\n resources:\n reservations:\n memory: 512M\n image: ghcr.io/esphome/esphome:latest\n restart: always\n ports:\n - target: 6052\n published: '6052'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n environment:\n ESPHOME_DASHBOARD_USE_PING: 'false'\n TZ: $TZ\n network_mode: host\n privileged: false\n" + }, + "compose_stack": { + "project_name": "esphome", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "esphome", + "service_count": 1, + "services": [ + { + "name": "esphome", + "image": "ghcr.io/esphome/esphome:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "esphome", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "image": "ghcr.io/esphome/esphome:latest", + "restart": "always", + "ports": [ + { + "target": 6052, + "published": "6052", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + } + ], + "environment": { + "ESPHOME_DASHBOARD_USE_PING": "false", + "TZ": "$TZ" + }, + "network_mode": "host", + "privileged": false + } + } + ], + "top_level": { + "name": "esphome" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "esphome-volume-0", + "service": "esphome", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "esphome" + ], + "stop_order": [ + "esphome" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6052, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/etherpad.json b/oci/catalog/apps/etherpad.json new file mode 100644 index 00000000..e6da55a7 --- /dev/null +++ b/oci/catalog/apps/etherpad.json @@ -0,0 +1,522 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-etherpad", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Etherpad" + }, + "tagline": { + "en_US": "Real-time collaborative document editor" + }, + "description": { + "en_US": "Etherpad is a real-time collaborative document editor where multiple people can edit the same pad simultaneously, with every change synchronized instantly and colour-coded per author.\nSelf-hosted, open source, and fully under your control, it is perfect for meeting notes, brainstorming, shared writing, and lightweight knowledge capture.\nIt ships with a built-in admin panel, a plugin ecosystem of 250+ add-ons, native DOCX/PDF/Markdown import & export, and multi-architecture container support (amd64 + arm64).\n\n**Main Features:**\n- Real-time collaborative editing with instant sync\n- Per-author colour coding for clear writing attribution\n- Built-in admin panel and a plugin ecosystem with 250+ add-ons\n- Native DOCX, PDF, and Markdown import & export\n- Open source, self-hosted deployment with amd64 and arm64 support\n\n**Learn More:**\n- [Etherpad Official Website](https://etherpad.org/)\n- [Etherpad GitHub](https://github.com/ether/etherpad)\n- [Etherpad Documentation](https://docs.etherpad.org/)\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "Etherpad Foundation", + "developer": "Etherpad Foundation", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9001, + "path": "/" + }, + "website": "https://etherpad.org/", + "documentation": null, + "repository": "https://hub.docker.com/r/etherpad/etherpad", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/etherpad/etherpad", + "revision": "dcd7e324b25daf810d72ec2a7b0c6bc447ba2413bae1d5e733c0975d7a014ce8", + "image_repository_url": "https://hub.docker.com/r/etherpad/etherpad", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "dcd7e324b25daf810d72ec2a7b0c6bc447ba2413bae1d5e733c0975d7a014ce8", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "etherpad", + "container_name": "etherpad", + "image": { + "reference": "etherpad/etherpad:latest", + "registry": "docker.io", + "repository": "etherpad/etherpad", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TITLE", + "example": "Etherpad", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEFAULT_PAD_TEXT", + "example": "Welcome to Etherpad on etherpad!\n\nThis pad text is synchronized as you type, so that everyone viewing this page sees the same text. This allows you to collaborate seamlessly on documents!\n\nGet involved with Etherpad at https://etherpad.org\n", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ADMIN_PASSWORD", + "example": "${GENERATED_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "AUTHENTICATION_METHOD", + "example": "apikey", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_TYPE", + "example": "dirty", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_FILENAME", + "example": "/opt/etherpad-lite/var/dirty.db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TRUST_PROXY", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SHOW_SETTINGS_IN_ADMIN_PAGE", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REQUIRE_AUTHENTICATION", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REQUIRE_AUTHORIZATION", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt/etherpad-lite/var", + "compose_source_example": "/DATA/AppData/$AppID/var", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 9001, + "published_example": 9001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: etherpad\nservices:\n etherpad:\n image: etherpad/etherpad:latest\n container_name: etherpad\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n restart: unless-stopped\n ports:\n - target: 9001\n published: '9001'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/var\n target: /opt/etherpad-lite/var\n environment:\n TITLE: Etherpad\n DEFAULT_PAD_TEXT: 'Welcome to Etherpad on etherpad!\n\n\n This pad text is synchronized as you type, so that everyone viewing this page\n sees the same text. This allows you to collaborate seamlessly on documents!\n\n\n Get involved with Etherpad at https://etherpad.org\n\n '\n ADMIN_PASSWORD: ${GENERATED_ADMIN_PASSWORD}\n AUTHENTICATION_METHOD: apikey\n DB_TYPE: dirty\n DB_FILENAME: /opt/etherpad-lite/var/dirty.db\n TRUST_PROXY: 'true'\n SHOW_SETTINGS_IN_ADMIN_PAGE: 'true'\n REQUIRE_AUTHENTICATION: 'false'\n REQUIRE_AUTHORIZATION: 'false'\n healthcheck:\n test:\n - CMD\n - wget\n - -q\n - -O-\n - http://localhost:9001/health\n interval: 30s\n timeout: 10s\n retries: 3\n start_period: 30s\n" + }, + "compose_stack": { + "project_name": "etherpad", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "etherpad", + "service_count": 1, + "services": [ + { + "name": "etherpad", + "image": "etherpad/etherpad:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "etherpad/etherpad:latest", + "container_name": "etherpad", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "restart": "unless-stopped", + "ports": [ + { + "target": 9001, + "published": "9001", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/var", + "target": "/opt/etherpad-lite/var" + } + ], + "environment": { + "TITLE": "Etherpad", + "DEFAULT_PAD_TEXT": "Welcome to Etherpad on etherpad!\n\nThis pad text is synchronized as you type, so that everyone viewing this page sees the same text. This allows you to collaborate seamlessly on documents!\n\nGet involved with Etherpad at https://etherpad.org\n", + "ADMIN_PASSWORD": "${GENERATED_ADMIN_PASSWORD}", + "AUTHENTICATION_METHOD": "apikey", + "DB_TYPE": "dirty", + "DB_FILENAME": "/opt/etherpad-lite/var/dirty.db", + "TRUST_PROXY": "true", + "SHOW_SETTINGS_IN_ADMIN_PAGE": "true", + "REQUIRE_AUTHENTICATION": "false", + "REQUIRE_AUTHORIZATION": "false" + }, + "healthcheck": { + "test": [ + "CMD", + "wget", + "-q", + "-O-", + "http://localhost:9001/health" + ], + "interval": "30s", + "timeout": "10s", + "retries": 3, + "start_period": "30s" + } + } + } + ], + "top_level": { + "name": "etherpad" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "etherpad-volume-0", + "service": "etherpad", + "container_path": "/opt/etherpad-lite/var", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "etherpad" + ], + "stop_order": [ + "etherpad" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "etherpad", + "environment_variable": "ADMIN_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9001, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "startup_healthcheck": { + "type": "http", + "scheme": "http", + "port": 9001, + "path": "/health", + "timeout_seconds": 120, + "request_timeout_seconds": 10, + "stability_seconds": 0, + "verify_tls": true, + "required": true, + "source": "compose-healthcheck" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "pending-per-application" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/excalidraw.json b/oci/catalog/apps/excalidraw.json new file mode 100644 index 00000000..2d6c36b6 --- /dev/null +++ b/oci/catalog/apps/excalidraw.json @@ -0,0 +1,363 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-excalidraw", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Excalidraw" + }, + "tagline": { + "en_US": "Virtual whiteboard for sketching hand-drawn like diagrams" + }, + "description": { + "en_US": "Excalidraw is a virtual hand-drawn style whiteboard platform supporting infinite canvas and end-to-end encrypted collaboration. An intuitive interface offers a hand-drawn experience, ideal for brainstorming, design sketches, or educational scenarios, meeting diverse creative needs.\n\nCore features include an infinite canvas whiteboard and end-to-end encrypted collaboration. Hand-drawn style with shape library support allows creating rich graphics, enhanced by image insertion capabilities. Dark mode improves user experience, catering to diverse users.\n\nIt provides export options including PNG, SVG, and clipboard for easy content sharing. Drawing capabilities cover rectangle, circle, diamond, arrow, line, free-draw, and eraser, with arrow-binding and labeled arrow support. Undo, redo, zoom, and panning functionalities optimize operations. With creativity and security at the core, the platform delivers a modern whiteboard design solution.\n\n**Key Features:**\n- Infinite canvas whiteboard supporting hand-drawn style\n- Shape library support for creating rich graphics\n- Image insertion capability\n- Dark mode\n- Export to PNG, SVG, and clipboard\n- Open format - export drawings as an `.excalidraw` json file\n- Wide range of tools - rectangle, circle, diamond, arrow, line, free-draw, eraser...\n- Arrow-binding & labeled arrows\n- Undo and redo\n- Zoom and panning support\n\n**Learn More:**\n- [Excalidraw Official Website](https://excalidraw.com/)\n- [Excalidraw GitHub](https://github.com/excalidraw/excalidraw)\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "excalidraw", + "developer": "excalidraw", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://excalidraw.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/excalidraw/excalidraw", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/excalidraw/excalidraw", + "revision": "0afa4bd5dd3a2dbe663626f420682ee5b92d696420a690a0beda6da90f0f07c6", + "image_repository_url": "https://hub.docker.com/r/excalidraw/excalidraw", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "0afa4bd5dd3a2dbe663626f420682ee5b92d696420a690a0beda6da90f0f07c6", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "excalidraw", + "container_name": "excalidraw", + "image": { + "reference": "excalidraw/excalidraw:latest", + "registry": "docker.io", + "repository": "excalidraw/excalidraw", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [ + { + "container_port": 80, + "published_example": 17638, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: excalidraw\nservices:\n excalidraw:\n image: excalidraw/excalidraw:latest\n container_name: excalidraw\n deploy:\n resources:\n reservations:\n memory: 256M\n restart: unless-stopped\n ports:\n - target: 80\n published: '17638'\n protocol: tcp\n" + }, + "compose_stack": { + "project_name": "excalidraw", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "excalidraw", + "service_count": 1, + "services": [ + { + "name": "excalidraw", + "image": "excalidraw/excalidraw:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "excalidraw/excalidraw:latest", + "container_name": "excalidraw", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "restart": "unless-stopped", + "ports": [ + { + "target": 80, + "published": "17638", + "protocol": "tcp" + } + ] + } + } + ], + "top_level": { + "name": "excalidraw" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "excalidraw" + ], + "stop_order": [ + "excalidraw" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/faster-whisper.json b/oci/catalog/apps/faster-whisper.json new file mode 100644 index 00000000..efc604f6 --- /dev/null +++ b/oci/catalog/apps/faster-whisper.json @@ -0,0 +1,276 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-faster-whisper", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Faster Whisper" + }, + "tagline": { + "en_US": "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper." + }, + "description": { + "en_US": "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/faster-whisper-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/faster-whisper-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 10300, + "path": "/" + }, + "website": "https://github.com/SYSTRAN/faster-whisper", + "documentation": "https://docs.linuxserver.io/images/docker-faster-whisper/", + "repository": "https://github.com/linuxserver/docker-faster-whisper", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-16", + "note": "Rebase to Ubuntu Resolute." + }, + { + "date": "2026-01-26", + "note": "Default to `auto` for model and language if not set." + }, + { + "date": "2025-08-20", + "note": "Add gpu-legacy branch for pre-Turing cards." + }, + { + "date": "2025-08-10", + "note": "Add support for local-only mode." + }, + { + "date": "2024-12-30", + "note": "Add arm64 support for non-GPU builds." + } + ], + "display_version": null, + "updated_at": "2026-08-16" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-faster-whisper", + "default_branch": "main", + "revision": "f506df5f04542fdce45f29b2256628ca70d69c68", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-faster-whisper/f506df5f04542fdce45f29b2256628ca70d69c68/README.md", + "readme_pushed_at": "2026-09-12T01:03:07Z", + "compose_sha256": "ce7ac145487ea70281c626c3962c2d9e22021250b43f183f73bf27cb5aab414b", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "faster-whisper", + "container_name": "faster-whisper", + "image": { + "reference": "lscr.io/linuxserver/faster-whisper:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/faster-whisper", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEBUG", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOCAL_ONLY", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "WHISPER_BEAM", + "example": "1", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "WHISPER_LANG", + "example": "auto", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "WHISPER_MODEL", + "example": "auto", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/faster-whisper/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 10300, + "published_example": 10300, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n faster-whisper:\n image: lscr.io/linuxserver/faster-whisper:latest\n container_name: faster-whisper\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DEBUG= #optional\n - LOCAL_ONLY= #optional\n - WHISPER_BEAM=1 #optional\n - WHISPER_LANG=auto #optional\n - WHISPER_MODEL=auto #optional\n volumes:\n - /path/to/faster-whisper/data:/config\n ports:\n - 10300:10300\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 10300, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ferdium.json b/oci/catalog/apps/ferdium.json new file mode 100644 index 00000000..8f59adc6 --- /dev/null +++ b/oci/catalog/apps/ferdium.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ferdium", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ferdium" + }, + "tagline": { + "en_US": "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application." + }, + "description": { + "en_US": "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ferdium-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ferdium-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://ferdium.org/", + "documentation": "https://docs.linuxserver.io/images/docker-ferdium/", + "repository": "https://github.com/linuxserver/docker-ferdium", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ferdium", + "default_branch": "master", + "revision": "7b0ba3f02d2a7a410933845427c5ef6bfa0e196e", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ferdium/7b0ba3f02d2a7a410933845427c5ef6bfa0e196e/README.md", + "readme_pushed_at": "2026-09-07T20:24:53Z", + "compose_sha256": "b7cbb69404319fa9743f1c71cd8f8ffa1d3b5050f386442d197921c0a46568c4", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "ferdium", + "container_name": "ferdium", + "image": { + "reference": "lscr.io/linuxserver/ferdium:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ferdium", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ferdium:\n image: lscr.io/linuxserver/ferdium:latest\n container_name: ferdium\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-ferdium/master/Dockerfile", + "dockerfile_sha256": "c47d21332c5d5516c76e7593905690c85c42a5d58aabfe0d0e099161b03b4755", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/filebrowser-quantum.json b/oci/catalog/apps/filebrowser-quantum.json new file mode 100644 index 00000000..2e9053a6 --- /dev/null +++ b/oci/catalog/apps/filebrowser-quantum.json @@ -0,0 +1,390 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-filebrowser-quantum", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "FileBrowser Quantum" + }, + "tagline": { + "en_US": "FileBrowser Quantum" + }, + "description": { + "en_US": "Official image with managed persistent configuration and selectable content storage. Validated on amd64: clean install, authenticated login, same-digest recreation and interrupted-candidate recovery. Cross-release migration and arm64 runtime not tested." + }, + "category": "tools", + "category_label": "Tools", + "author": "gtsteffaniak", + "developer": "gtsteffaniak", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/gtsteffaniak/filebrowser", + "documentation": "https://github.com/gtsteffaniak/filebrowser", + "repository": "https://github.com/gtsteffaniak/filebrowser", + "tips": [ + "Official image with managed persistent configuration and selectable content storage. Validated on amd64: clean install, authenticated login, same-digest recreation and interrupted-candidate recovery. Cross-release migration and arm64 runtime not tested." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-16", + "hidden": false + }, + "source": { + "provider": "gtsteffaniak", + "repository": "https://github.com/gtsteffaniak/filebrowser", + "default_branch": "main", + "revision": "fa58eac9c06d769597652712ef9f093971a916d1", + "readme_raw_url": "https://raw.githubusercontent.com/gtsteffaniak/filebrowser/fa58eac9c06d769597652712ef9f093971a916d1/README.md", + "image_repository_url": "https://hub.docker.com/r/gtstef/filebrowser", + "compose_sha256": "1bc09f5ad7bf878a96e53861e52e6274ebc335ed63933b7e195dab0321ce5cdd", + "generated_at": "2026-09-16T22:00:00+02:00" + }, + "container_contract": { + "service_name": "filebrowser-quantum", + "container_name": "filebrowser-quantum", + "image": { + "reference": "gtstef/filebrowser:latest", + "registry": "docker.io", + "repository": "gtstef/filebrowser", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "FILEBROWSER_ADMIN_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "upstream-documentation", + "prompt_user": true + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/home/filebrowser/data", + "compose_source_example": "config-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "files", + "container_path": "/folder", + "compose_source_example": "/mnt/oci-shared/files", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "{\n \"services\": {\n \"filebrowser-quantum\": {\n \"image\": \"gtstef/filebrowser:latest\",\n \"volumes\": [\n \"config-data:/home/filebrowser/data\",\n \"/mnt/oci-shared/files:/folder\"\n ],\n \"ports\": [\n \"80:80\"\n ],\n \"environment\": {\n \"FILEBROWSER_ADMIN_PASSWORD\": \"\"\n },\n \"restart\": \"unless-stopped\"\n }\n }\n}" + }, + "compose_stack": { + "project_name": "mkvtoolnix", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mkvtoolnix", + "service_count": 1, + "services": [ + { + "name": "mkvtoolnix", + "image": "jlesage/mkvtoolnix:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/mkvtoolnix:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "mkvtoolnix-config:/config", + "/mnt/oci-shared/media:/storage" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mkvtoolnix-config", + "service": "mkvtoolnix", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "mkvtoolnix-storage", + "service": "mkvtoolnix", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mkvtoolnix" + ], + "stop_order": [ + "mkvtoolnix" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "passed-amd64-install-recreate-recovery" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "not-required" + } + ], + "installer_profile": { + "volume_owner": { + "uid": 1000, + "gid": 1000 + }, + "volume_preparations": [ + { + "container_path": "/home/filebrowser/data", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/folder", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "security": { + "sysctls": [ + { + "name": "net.ipv4.ip_unprivileged_port_start", + "value": "0" + } + ] + }, + "generated_files": [ + { + "container_path": "/home/filebrowser/data/config.yaml", + "mode": "0644", + "owner": "mapped-application-user", + "only_if_missing": true, + "content": "server:\n port: 80\n cacheDir: /home/filebrowser/data/tmp\n sources:\n - path: /folder\n config:\n defaultEnabled: true\nauth:\n adminUsername: admin\n" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 80, + "path": "/health", + "timeout_seconds": 300, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "Official image with managed persistent configuration and selectable content storage. Validated on amd64: clean install, authenticated login, same-digest recreation and interrupted-candidate recovery. Cross-release migration and arm64 runtime not tested." + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "https://github.com/gtsteffaniak/filebrowser" + } + ], + "credentials": [ + { + "label": "FileBrowser Quantum (new installation)", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "password_environment": "FILEBROWSER_ADMIN_PASSWORD", + "change_required": false, + "source": "https://filebrowserquantum.com/en/docs/reference/cli/" + } + ] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "passed-through-recreation-amd64", + "backup_restore": "passed-managed-configuration-amd64", + "update_preserves_data": "passed-same-digest-recreation-amd64", + "cross_release_upgrade": "not-tested", + "evidence": "docs/lab/new-images-validation-20260918.json" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/filedrop.json b/oci/catalog/apps/filedrop.json new file mode 100644 index 00000000..22d4656e --- /dev/null +++ b/oci/catalog/apps/filedrop.json @@ -0,0 +1,427 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-filedrop", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "FileDrop" + }, + "tagline": { + "en_US": "FileDrop is a free, open source file sharing service" + }, + "description": { + "en_US": "FileDrop is a self-hosted file sharing service that allows you to easily share files with family, friends, or colleagues. It's been designed to be easy to use and light on resources.\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "No\u00e9 Favier (noe.favier@outlook.com)", + "developer": "No\u00e9 Favier (noe.favier@outlook.com)", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/noecl/filedrop", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "noecl", + "repository": "https://hub.docker.com/r/noecl/filedrop", + "revision": "98c8ff69048ddd921d74d3be80c5e67fdb81c25f6a267355c9a8da220fa8ee0e", + "image_repository_url": "https://hub.docker.com/r/noecl/filedrop", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "98c8ff69048ddd921d74d3be80c5e67fdb81c25f6a267355c9a8da220fa8ee0e", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "filedrop", + "container_name": "filedrop", + "image": { + "reference": "noecl/filedrop:latest", + "registry": "docker.io", + "repository": "noecl/filedrop", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/file_drop_files", + "compose_source_example": "/DATA/AppData/filedrop/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: filedrop\nservices:\n filedrop:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n image: noecl/filedrop:latest\n deploy:\n resources:\n reservations:\n memory: 2048M\n restart: unless-stopped\n ports:\n - target: 8000\n published: '8000'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/filedrop/data\n target: /var/file_drop_files\n container_name: filedrop\n" + }, + "compose_stack": { + "project_name": "filedrop", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "filedrop", + "service_count": 1, + "services": [ + { + "name": "filedrop", + "image": "noecl/filedrop:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "image": "noecl/filedrop:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "2048M" + } + } + }, + "restart": "unless-stopped", + "ports": [ + { + "target": 8000, + "published": "8000", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/filedrop/data", + "target": "/var/file_drop_files" + } + ], + "container_name": "filedrop" + } + } + ], + "top_level": { + "name": "filedrop" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "filedrop-volume-0", + "service": "filedrop", + "container_path": "/var/file_drop_files", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "filedrop" + ], + "stop_order": [ + "filedrop" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/fileflows.json b/oci/catalog/apps/fileflows.json new file mode 100644 index 00000000..5220d5e9 --- /dev/null +++ b/oci/catalog/apps/fileflows.json @@ -0,0 +1,632 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-fileflows", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "FileFlows" + }, + "tagline": { + "en_US": "File processing made easy!" + }, + "description": { + "en_US": "Save storage space with efficient file processing.\n\nFileFlows lets you monitor and process any file type with custom flows. Videos, audio, images, archives, comics, eBooks\u2014you name it!\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "FileFlows", + "developer": "FileFlows", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5000, + "path": "/" + }, + "website": "https://fileflows.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/revenz/fileflows", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "revenz", + "repository": "https://hub.docker.com/r/revenz/fileflows", + "revision": "59ca91536e4ddd94579fc78e432226f1d03651e0d289108b3482ac9da729c628", + "image_repository_url": "https://hub.docker.com/r/revenz/fileflows", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "59ca91536e4ddd94579fc78e432226f1d03651e0d289108b3482ac9da729c628", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "fileflows", + "container_name": "fileflows", + "image": { + "reference": "revenz/fileflows:latest", + "registry": "docker.io", + "repository": "revenz/fileflows", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/Data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/app/Logs", + "compose_source_example": "/DATA/AppData/$AppID/logs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/app/common", + "compose_source_example": "/DATA/AppData/$AppID/common", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/temp", + "compose_source_example": "/DATA/AppData/$AppID/temp", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-4", + "container_path": "/Media", + "compose_source_example": "/DATA/Media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-5", + "container_path": "/var/run/docker.sock", + "compose_source_example": "/var/run/docker.sock", + "read_only": false, + "required": false, + "installation_choice": [ + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5000, + "published_example": 19200, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: fileflows\nservices:\n fileflows:\n container_name: fileflows\n devices:\n - /dev/dri:/dev/dri\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n hostname: fileflows\n image: revenz/fileflows:latest\n restart: unless-stopped\n ports:\n - target: 5000\n published: '19200'\n protocol: tcp\n network_mode: bridge\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /app/Data\n - type: bind\n source: /DATA/AppData/$AppID/logs\n target: /app/Logs\n - type: bind\n source: /DATA/AppData/$AppID/common\n target: /app/common\n - type: bind\n source: /DATA/AppData/$AppID/temp\n target: /temp\n - type: bind\n source: /DATA/Media\n target: /Media\n - type: bind\n source: /var/run/docker.sock\n target: /var/run/docker.sock\n" + }, + "compose_stack": { + "project_name": "fileflows", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "fileflows", + "service_count": 1, + "services": [ + { + "name": "fileflows", + "image": "revenz/fileflows:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "fileflows", + "devices": [ + "/dev/dri:/dev/dri" + ], + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "hostname": "fileflows", + "image": "revenz/fileflows:latest", + "restart": "unless-stopped", + "ports": [ + { + "target": 5000, + "published": "19200", + "protocol": "tcp" + } + ], + "network_mode": "bridge", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/app/Data" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/logs", + "target": "/app/Logs" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/common", + "target": "/app/common" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/temp", + "target": "/temp" + }, + { + "type": "bind", + "source": "/DATA/Media", + "target": "/Media" + }, + { + "type": "bind", + "source": "/var/run/docker.sock", + "target": "/var/run/docker.sock" + } + ] + } + } + ], + "top_level": { + "name": "fileflows" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "fileflows-volume-0", + "service": "fileflows", + "container_path": "/app/Data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "fileflows-volume-1", + "service": "fileflows", + "container_path": "/app/Logs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "fileflows-volume-2", + "service": "fileflows", + "container_path": "/app/common", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "fileflows-volume-3", + "service": "fileflows", + "container_path": "/temp", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "fileflows-volume-4", + "service": "fileflows", + "container_path": "/Media", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for fileflows:/Media" + }, + { + "id": "fileflows-volume-5", + "service": "fileflows", + "container_path": "/var/run/docker.sock", + "mode": "runtime-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "fileflows" + ], + "stop_order": [ + "fileflows" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "hostname": "fileflows" + }, + "hardware_acceleration": { + "prompt": "Hardware acceleration for FileFlows", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ] + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "catalog": { + "replaces_discovered_ids": [ + "fileflows" + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/filezilla.json b/oci/catalog/apps/filezilla.json new file mode 100644 index 00000000..06f792de --- /dev/null +++ b/oci/catalog/apps/filezilla.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-filezilla", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Filezilla" + }, + "tagline": { + "en_US": "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface." + }, + "description": { + "en_US": "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/filezilla-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/filezilla-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://filezilla-project.org/", + "documentation": "https://docs.linuxserver.io/images/docker-filezilla/", + "repository": "https://github.com/linuxserver/docker-filezilla", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-20", + "note": "Rebase to Ubuntu Resolute." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-26", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-05-20" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-filezilla", + "default_branch": "master", + "revision": "11e131023ecaea3686fccd65ddc98a7af16abeb5", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-filezilla/11e131023ecaea3686fccd65ddc98a7af16abeb5/README.md", + "readme_pushed_at": "2026-09-07T22:33:52Z", + "compose_sha256": "ff0ff1bd8313ef50207b9854f58e3398748b0059a4ac2831c4127c06a5d5a10d", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "filezilla", + "container_name": "filezilla", + "image": { + "reference": "lscr.io/linuxserver/filezilla:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/filezilla", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n filezilla:\n image: lscr.io/linuxserver/filezilla:latest\n container_name: filezilla\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-filezilla/master/Dockerfile", + "dockerfile_sha256": "57086f8b98f9470374b0c2a5144e4fe931db0d35efa9c81dc65b2066d5cc3982", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/firefly.json b/oci/catalog/apps/firefly.json new file mode 100644 index 00000000..aea2c7a7 --- /dev/null +++ b/oci/catalog/apps/firefly.json @@ -0,0 +1,495 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-firefly", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Firefly" + }, + "tagline": { + "en_US": "Firefly, the easiest using of WireGuard VPN server, plus version of wg-easy." + }, + "description": { + "en_US": "Firefly is a simple and easy to install WireGuard server software, which can be widely used in scenarios such as remote networking, remote work, and expose a local server behind a NAT or firewall to the internet. \ud83c\udfaf Features \ud83d\udfe2 Provide a simple and easy-to-use web management UI \ud83d\udfe3 Supports access to all WireGuard clients \ud83d\udfe1 No need for system installation of WireGuard components \ud83d\udfe0 Single file, no additional library dependencies \ud83d\udd34 Automatically apply for free SSL certificate" + }, + "category": "finance", + "category_label": "Finance & Budgeting", + "author": "Safe3", + "developer": "Safe3", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 50121, + "path": "/" + }, + "website": "https://qq.uusec.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/uusec/firefly", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "uusec", + "repository": "https://hub.docker.com/r/uusec/firefly", + "revision": "35bd2ac3b2a663b5a125c65c35bc84540f45452ddca293a31e2ef509feaec1f4", + "image_repository_url": "https://hub.docker.com/r/uusec/firefly", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "35bd2ac3b2a663b5a125c65c35bc84540f45452ddca293a31e2ef509feaec1f4", + "generated_at": "2026-09-13T15:58:28+00:00" + }, + "container_contract": { + "service_name": "firefly", + "container_name": "firefly", + "image": { + "reference": "uusec/firefly:latest", + "registry": "docker.io", + "repository": "uusec/firefly", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "FIREFLY_PASSWORD", + "example": "${GENERATED_FIREFLY_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/lib/modules", + "compose_source_example": "/lib/modules", + "read_only": false, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/firefly/conf", + "compose_source_example": "/DATA/AppData/firefly/conf", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "version: '3'\nname: firefly\nservices:\n firefly:\n image: uusec/firefly:latest\n container_name: firefly\n devices:\n - /dev/net/tun:/dev/net/tun\n network_mode: host\n volumes:\n - /lib/modules:/lib/modules\n - /DATA/AppData/firefly/conf:/firefly/conf\n cap_add:\n - NET_ADMIN\n - SYS_MODULE\n restart: unless-stopped\n environment:\n - FIREFLY_PASSWORD=${GENERATED_FIREFLY_PASSWORD}\n deploy:\n resources:\n reservations:\n memory: 32M\n" + }, + "compose_stack": { + "project_name": "firefly", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "firefly", + "service_count": 1, + "services": [ + { + "name": "firefly", + "image": "uusec/firefly:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "uusec/firefly:latest", + "container_name": "firefly", + "devices": [ + "/dev/net/tun:/dev/net/tun" + ], + "network_mode": "host", + "volumes": [ + "/lib/modules:/lib/modules", + "/DATA/AppData/firefly/conf:/firefly/conf" + ], + "cap_add": [ + "NET_ADMIN", + "SYS_MODULE" + ], + "restart": "unless-stopped", + "environment": [ + "FIREFLY_PASSWORD=${GENERATED_FIREFLY_PASSWORD}" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "32M" + } + } + } + } + } + ], + "top_level": { + "version": "3", + "name": "firefly" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "firefly-volume-0", + "service": "firefly", + "container_path": "/lib/modules", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "firefly-volume-1", + "service": "firefly", + "container_path": "/firefly/conf", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "firefly" + ], + "stop_order": [ + "firefly" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "firefly-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "firefly", + "environment_variable": "FIREFLY_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 50121, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "dev-net-tun", + "kind": "character-device", + "purpose": "tun", + "enable_prompt": "Pass /dev/net/tun to the LXC", + "enabled_default": true, + "required_by_compose": true, + "path_prompt": "Host device for /dev/net/tun", + "host_path_default": "/dev/net/tun", + "container_path": "/dev/net/tun", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/net/tun:/dev/net/tun" + } + ], + "network": { + "compose_mode": "host" + }, + "security": { + "required_capabilities": [ + "NET_ADMIN", + "SYS_MODULE" + ], + "host_modules": [ + { + "name": "wireguard", + "enable_prompt": "Load and verify the WireGuard module on the Proxmox host", + "enabled_default": true, + "required_by_compose": true + } + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/firefox.json b/oci/catalog/apps/firefox.json new file mode 100644 index 00000000..6ff2983b --- /dev/null +++ b/oci/catalog/apps/firefox.json @@ -0,0 +1,280 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-firefox", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Firefox" + }, + "tagline": { + "en_US": "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards." + }, + "description": { + "en_US": "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/firefox-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/firefox-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.mozilla.org/en-US/firefox/", + "documentation": "https://docs.linuxserver.io/images/docker-firefox/", + "repository": "https://github.com/linuxserver/docker-firefox", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-04", + "note": "Deprecate Kasm branch." + }, + { + "date": "2026-04-19", + "note": "Rebase to resolute." + }, + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-26", + "note": "Suppress sandbox security warning as it's misleading inside a container." + } + ], + "display_version": null, + "updated_at": "2026-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-firefox", + "default_branch": "master", + "revision": "b0424c506af53f07a35604ff6656170fc43f3a14", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-firefox/b0424c506af53f07a35604ff6656170fc43f3a14/README.md", + "readme_pushed_at": "2026-09-09T23:03:18Z", + "compose_sha256": "eec0a6e3ffc2d05c9e72d9d7b0ca2ef22cd899a318fb2408a113768d127a2870", + "generated_at": "2026-09-12T14:37:46+00:00" + }, + "container_contract": { + "service_name": "firefox", + "container_name": "firefox", + "image": { + "reference": "lscr.io/linuxserver/firefox:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/firefox", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FIREFOX_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/firefox/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n firefox:\n image: lscr.io/linuxserver/firefox:latest\n container_name: firefox\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - FIREFOX_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/firefox/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/flaresolverr.json b/oci/catalog/apps/flaresolverr.json new file mode 100644 index 00000000..b5478b21 --- /dev/null +++ b/oci/catalog/apps/flaresolverr.json @@ -0,0 +1,435 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-flaresolverr", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "FlareSolverr" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "" + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "official", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8191, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://ghcr.io/flaresolverr/flaresolverr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/flaresolverr/flaresolverr", + "revision": "060f6098ed0b43417d1b37a081c0252eb6b598b16541ce992a8ff32ed3d66a55", + "image_repository_url": "https://ghcr.io/flaresolverr/flaresolverr", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "060f6098ed0b43417d1b37a081c0252eb6b598b16541ce992a8ff32ed3d66a55", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "flaresolverr", + "container_name": "flaresolverr", + "image": { + "reference": "ghcr.io/flaresolverr/flaresolverr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/flaresolverr/flaresolverr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "UMASK", + "example": "002", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOG_LEVEL", + "example": "info", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOG_HTML", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CAPTCHA_SOLVER", + "example": "none", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 8191, + "published_example": 8191, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: flaresolverr\nservices:\n flaresolverr:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n UMASK: '002'\n LOG_LEVEL: info\n LOG_HTML: 'false'\n CAPTCHA_SOLVER: none\n cpu_shares: 50\n command: []\n container_name: flaresolverr\n deploy:\n resources:\n reservations:\n memory: 64M\n image: ghcr.io/flaresolverr/flaresolverr:latest\n ports:\n - target: 8191\n published: '8191'\n protocol: tcp\n restart: unless-stopped\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "flaresolverr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "flaresolverr", + "service_count": 1, + "services": [ + { + "name": "flaresolverr", + "image": "ghcr.io/flaresolverr/flaresolverr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ", + "UMASK": "002", + "LOG_LEVEL": "info", + "LOG_HTML": "false", + "CAPTCHA_SOLVER": "none" + }, + "cpu_shares": 50, + "command": [], + "container_name": "flaresolverr", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "image": "ghcr.io/flaresolverr/flaresolverr:latest", + "ports": [ + { + "target": 8191, + "published": "8191", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "flaresolverr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "flaresolverr" + ], + "stop_order": [ + "flaresolverr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8191, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [] + }, + "resources": { + "cpu_shares": 50 + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/flexget.json b/oci/catalog/apps/flexget.json new file mode 100644 index 00000000..83ce40c8 --- /dev/null +++ b/oci/catalog/apps/flexget.json @@ -0,0 +1,286 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-flexget", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Flexget" + }, + "tagline": { + "en_US": "Flexget is a multipurpose automation tool for all of your media." + }, + "description": { + "en_US": "Flexget is a multipurpose automation tool for all of your media." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/flexget-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/flexget-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5050, + "path": "/" + }, + "website": "http://flexget.com/", + "documentation": "https://docs.linuxserver.io/images/docker-flexget/", + "repository": "https://github.com/linuxserver/docker-flexget", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-15", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-11-10", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-10-17", + "note": "Add pip to enable [universal-package-install mod](https://github.com/linuxserver/docker-mods/tree/universal-package-install)." + }, + { + "date": "2024-09-18", + "note": "Suppress creation of empty log file when WebUI password is set." + }, + { + "date": "2024-08-17", + "note": "Revert to Alpine 3.20 due to 1st party plugin incompatibility with Python 3.12." + } + ], + "display_version": null, + "updated_at": "2026-08-15" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-flexget", + "default_branch": "main", + "revision": "8904f76df17bcd4f6a66603327a75fee3906f1dd", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-flexget/8904f76df17bcd4f6a66603327a75fee3906f1dd/README.md", + "readme_pushed_at": "2026-09-11T21:37:54Z", + "compose_sha256": "d174ad5994c5b9ad3c365e4309ec762ebd64ee70badf95814efeb935aa7412e0", + "generated_at": "2026-09-12T14:37:26+00:00" + }, + "container_contract": { + "service_name": "flexget", + "container_name": "flexget", + "image": { + "reference": "lscr.io/linuxserver/flexget:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/flexget", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FG_LOG_LEVEL", + "example": "info", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FG_LOG_FILE", + "example": "/config/flexget.log", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FG_CONFIG_FILE", + "example": "/config/.flexget/config.yml", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FG_WEBUI_PASSWORD", + "example": "info", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/flexget/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5050, + "published_example": 5050, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n flexget:\n image: lscr.io/linuxserver/flexget:latest\n container_name: flexget\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - FG_LOG_LEVEL=info\n - FG_LOG_FILE=/config/flexget.log\n - FG_CONFIG_FILE=/config/.flexget/config.yml\n - FG_WEBUI_PASSWORD=info #optional\n volumes:\n - /path/to/flexget/data:/config\n - /path/to/downloads:/data #optional\n ports:\n - 5050:5050\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5050, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/flowise.json b/oci/catalog/apps/flowise.json new file mode 100644 index 00000000..9e5c4a3f --- /dev/null +++ b/oci/catalog/apps/flowise.json @@ -0,0 +1,495 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-flowise", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Flowise" + }, + "tagline": { + "en_US": "An open source generative AI development platform for building AI Agents and LLM workflows" + }, + "description": { + "en_US": "Flowise is a generative AI development platform for building AI agents and LLM workflows. An intuitive interface with a visual editor simplifies complex workflow design, ideal for developers creating diverse AI applications, from chatbots to data processing pipelines.\n\nCore features include visual orchestration and data integration. Support for various models, custom code, and branching, looping, and routing logic enables complex workflow creation. Connection to over 100 data sources, vector databases, and memory modules ensures flexible data ingestion. Monitoring capabilities provide execution logs and visual debugging for workflow transparency and maintenance. Self-hosted and air-gapped deployment options accommodate diverse infrastructure needs.\n\nIt offers data processing with transforms, filters, aggregates, and RAG indexing pipelines. Memory optimization and planning techniques enhance performance, while MCP integration supports tool connections and authentication. Security controls include role-based access, single sign-on, and encrypted credentials for data protection. API, JavaScript and Python SDKs, and command-line interface enable extensibility, with embedded chat components and a template marketplace accelerating development. Scalability supports high-throughput workflows, and evaluation features optimize performance. With flexibility and efficiency at the core, the platform delivers a modern solution for AI development.\n\n**Key Features:**\n- Visual editor supporting multiple models, custom code, branching looping routing logic\n- Connection to over 100 data sources, vector databases, and memory modules\n- Execution logs and visual debugging for enhanced monitoring\n- Data processing with transforms, filters, aggregates, and RAG indexing pipelines\n- Various memory optimization technique and integrations\n- MCP client and server nodes for tool integration\n- Input moderation and output post-processing for safety\n- API, JavaScript and Python SDKs, and command-line interface\n- Customizable embedded chat components\n- Template marketplace and reusable components\n- Role-based access control, single sign-on, encrypted credentials\n- Vertical and horizontal scalability for high-throughput workflows\n- Datasets and evaluation features for workflow optimization\n\n**Learn More:**\n- [Flowise Official Website](https://flowiseai.com/)\n- [Flowise GitHub](https://github.com/flowiseai/flowise)\n- [Flowise Documentation](https://docs.flowiseai.com/)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Flowise", + "developer": "Flowise", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3025, + "path": "/" + }, + "website": "https://flowiseai.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/flowiseai/flowise", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/flowiseai/flowise", + "revision": "b0fcc71bc9b5785dcf7a4e01d112f662783c0ca29716fec98385e23fd51f78cc", + "image_repository_url": "https://hub.docker.com/r/flowiseai/flowise", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "b0fcc71bc9b5785dcf7a4e01d112f662783c0ca29716fec98385e23fd51f78cc", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "flowise", + "container_name": "flowise", + "image": { + "reference": "flowiseai/flowise:latest", + "registry": "docker.io", + "repository": "flowiseai/flowise", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PORT", + "example": "3025", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DATABASE_PATH", + "example": "/root/.flowise", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "APIKEY_PATH", + "example": "${GENERATED_APIKEY_PATH}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "SECRETKEY_PATH", + "example": "${GENERATED_SECRETKEY_PATH}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "LOG_PATH", + "example": "/root/.flowise/logs", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BLOB_STORAGE_PATH", + "example": "/root/.flowise/storage", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "FLOWISE_USERNAME", + "example": "flowise", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "FLOWISE_PASSWORD", + "example": "${GENERATED_FLOWISE_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/root/.flowise", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3025, + "published_example": 3025, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: flowise\nservices:\n flowise:\n image: flowiseai/flowise:latest\n container_name: flowise\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 256M\n environment:\n - PORT=3025\n - DATABASE_PATH=/root/.flowise\n - APIKEY_PATH=${GENERATED_APIKEY_PATH}\n - SECRETKEY_PATH=${GENERATED_SECRETKEY_PATH}\n - LOG_PATH=/root/.flowise/logs\n - BLOB_STORAGE_PATH=/root/.flowise/storage\n - FLOWISE_USERNAME=flowise\n - FLOWISE_PASSWORD=${GENERATED_FLOWISE_PASSWORD}\n ports:\n - 3025:3025\n volumes:\n - /DATA/AppData/$AppID:/root/.flowise\n entrypoint: /bin/sh -c \"sleep 3; flowise start\"\n" + }, + "compose_stack": { + "project_name": "flowise", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "flowise", + "service_count": 1, + "services": [ + { + "name": "flowise", + "image": "flowiseai/flowise:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "flowiseai/flowise:latest", + "container_name": "flowise", + "restart": "unless-stopped", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "environment": [ + "PORT=3025", + "DATABASE_PATH=/root/.flowise", + "APIKEY_PATH=${GENERATED_APIKEY_PATH}", + "SECRETKEY_PATH=${GENERATED_SECRETKEY_PATH}", + "LOG_PATH=/root/.flowise/logs", + "BLOB_STORAGE_PATH=/root/.flowise/storage", + "FLOWISE_USERNAME=flowise", + "FLOWISE_PASSWORD=${GENERATED_FLOWISE_PASSWORD}" + ], + "ports": [ + "3025:3025" + ], + "volumes": [ + "/DATA/AppData/$AppID:/root/.flowise" + ], + "entrypoint": "/bin/sh -c \"sleep 3; flowise start\"" + } + } + ], + "top_level": { + "name": "flowise" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "flowise-volume-0", + "service": "flowise", + "container_path": "/root/.flowise", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "flowise" + ], + "stop_order": [ + "flowise" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "apikey-path", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "flowise", + "environment_variable": "APIKEY_PATH" + } + ] + }, + { + "id": "flowise-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "flowise", + "environment_variable": "FLOWISE_PASSWORD" + } + ] + }, + { + "id": "secretkey-path", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "flowise", + "environment_variable": "SECRETKEY_PATH" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3025, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "compose_entrypoint": "/bin/sh -c \"sleep 3; flowise start\"" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/flycast.json b/oci/catalog/apps/flycast.json new file mode 100644 index 00000000..14eeebb1 --- /dev/null +++ b/oci/catalog/apps/flycast.json @@ -0,0 +1,268 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-flycast", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Flycast" + }, + "tagline": { + "en_US": "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast." + }, + "description": { + "en_US": "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/flycast-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/flycast-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/flyinghead/flycast", + "documentation": "https://docs.linuxserver.io/images/docker-flycast/", + "repository": "https://github.com/linuxserver/docker-flycast", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-06-19", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-flycast", + "default_branch": "master", + "revision": "30b068b62b845200f998a4bf9c6e791f8ba9d37d", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-flycast/30b068b62b845200f998a4bf9c6e791f8ba9d37d/README.md", + "readme_pushed_at": "2026-09-06T19:37:00Z", + "compose_sha256": "cf1ccd0eb8c5ea1891253662d399e5156a2bf938897048b24f73dc775b35d15e", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "flycast", + "container_name": "flycast", + "image": { + "reference": "lscr.io/linuxserver/flycast:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/flycast", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n flycast:\n image: lscr.io/linuxserver/flycast:latest\n container_name: flycast\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/foldingathome.json b/oci/catalog/apps/foldingathome.json new file mode 100644 index 00000000..d9db5440 --- /dev/null +++ b/oci/catalog/apps/foldingathome.json @@ -0,0 +1,262 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-foldingathome", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Foldingathome" + }, + "tagline": { + "en_US": "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics." + }, + "description": { + "en_US": "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/foldingathome-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/foldingathome-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 7396, + "path": "/" + }, + "website": "https://foldingathome.org/", + "documentation": "https://docs.linuxserver.io/images/docker-foldingathome/", + "repository": "https://github.com/linuxserver/docker-foldingathome", + "tips": [], + "mini_changelog": [ + { + "date": "2024-08-10", + "note": "Add libexpat1 for Nvidia support." + }, + { + "date": "2024-06-25", + "note": "***Breaking Changes*** - Please see the Application Setup section for more details. Restructure image for F@H v8." + }, + { + "date": "2024-06-15", + "note": "Rebase to Ubuntu Noble, add optional cli args." + }, + { + "date": "2022-12-14", + "note": "Rebase to Ubuntu Jammy, migrate to s6v3." + }, + { + "date": "2022-01-15", + "note": "Rebase to Ubuntu Focal. Add arm64v8 builds (cpu only). Increase verbosity about gpu driver permission settings." + } + ], + "display_version": null, + "updated_at": "2024-08-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-foldingathome", + "default_branch": "master", + "revision": "e8543b5d2ddefa727eff8076ba6a31b0619e0718", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-foldingathome/e8543b5d2ddefa727eff8076ba6a31b0619e0718/README.md", + "readme_pushed_at": "2026-09-08T07:45:56Z", + "compose_sha256": "8ef7f929c4fc69fbdc081b65b0ec0db3e50ec7d247e2034ca538a7467ed72551", + "generated_at": "2026-09-12T14:37:28+00:00" + }, + "container_contract": { + "service_name": "foldingathome", + "container_name": "foldingathome", + "image": { + "reference": "lscr.io/linuxserver/foldingathome:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/foldingathome", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ACCOUNT_TOKEN", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "MACHINE_NAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CLI_ARGS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/foldingathome/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 7396, + "published_example": 7396, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n foldingathome:\n image: lscr.io/linuxserver/foldingathome:latest\n container_name: foldingathome\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - ACCOUNT_TOKEN=\n - MACHINE_NAME=\n - CLI_ARGS= #optional\n volumes:\n - /path/to/foldingathome/data:/config\n ports:\n - 7396:7396 #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7396, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/freecad.json b/oci/catalog/apps/freecad.json new file mode 100644 index 00000000..00b321f6 --- /dev/null +++ b/oci/catalog/apps/freecad.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-freecad", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Freecad" + }, + "tagline": { + "en_US": "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support." + }, + "description": { + "en_US": "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/freecad-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/freecad-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.freecad.org/", + "documentation": "https://docs.linuxserver.io/images/docker-freecad/", + "repository": "https://github.com/linuxserver/docker-freecad", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-02", + "note": "Rebase to Selkies, HTTPS is now required! Ingest from current appimage." + }, + { + "date": "2024-02-10", + "note": "Update Readme with new env vars and ingest proper PWA icon." + } + ], + "display_version": null, + "updated_at": "2026-03-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-freecad", + "default_branch": "master", + "revision": "d8a6af24acd749f1a190e96f2cf0c1c9dbf881ba", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-freecad/d8a6af24acd749f1a190e96f2cf0c1c9dbf881ba/README.md", + "readme_pushed_at": "2026-09-12T14:09:40Z", + "compose_sha256": "a8880c175cb3132aef97efe4d5dc096b9771d9d44096b55f600fbb17d2209be5", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "freecad", + "container_name": "freecad", + "image": { + "reference": "lscr.io/linuxserver/freecad:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/freecad", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n freecad:\n image: lscr.io/linuxserver/freecad:latest\n container_name: freecad\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-freecad/master/Dockerfile", + "dockerfile_sha256": "3e76dc197f77f9256bf7af2d507ff11e0ccedeb1f65a79ab05ee8ce9d3e42421", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/freshrss-official.json b/oci/catalog/apps/freshrss-official.json new file mode 100644 index 00000000..a8437f47 --- /dev/null +++ b/oci/catalog/apps/freshrss-official.json @@ -0,0 +1,445 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-freshrss-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "FreshRSS" + }, + "tagline": { + "en_US": "A free, self-hostable news aggregator\u2026" + }, + "description": { + "en_US": "FreshRSS is a self-hosted RSS and Atom feed aggregator. It is lightweight, easy to work with, powerful, and customizable." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "FreshRSS", + "developer": "FreshRSS", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://freshrss.org/", + "documentation": null, + "repository": "https://hub.docker.com/r/freshrss/freshrss", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/freshrss/freshrss", + "revision": "6d0b99f554391e2950911d5eedd9a455f60969dcb575d8c47070d2f7bc4ae1c7", + "image_repository_url": "https://hub.docker.com/r/freshrss/freshrss", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "6d0b99f554391e2950911d5eedd9a455f60969dcb575d8c47070d2f7bc4ae1c7", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "freshrss", + "container_name": "freshrss", + "image": { + "reference": "freshrss/freshrss:latest", + "registry": "docker.io", + "repository": "freshrss/freshrss", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CRON_MIN", + "example": "1,31", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/www/FreshRSS/data", + "compose_source_example": "/DATA/AppData/freshrss/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/var/www/FreshRSS/extensions", + "compose_source_example": "/DATA/AppData/freshrss/extensions", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 8749, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: freshrss\nservices:\n freshrss:\n restart: unless-stopped\n environment:\n TZ: ''\n CRON_MIN: 1,31\n image: freshrss/freshrss:latest\n network_mode: bridge\n ports:\n - target: 80\n published: '8749'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/freshrss/data\n target: /var/www/FreshRSS/data\n - type: bind\n source: /DATA/AppData/freshrss/extensions\n target: /var/www/FreshRSS/extensions\n container_name: freshrss\n" + }, + "compose_stack": { + "project_name": "freshrss", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "freshrss", + "service_count": 1, + "services": [ + { + "name": "freshrss", + "image": "freshrss/freshrss:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "restart": "unless-stopped", + "environment": { + "TZ": "", + "CRON_MIN": "1,31" + }, + "image": "freshrss/freshrss:latest", + "network_mode": "bridge", + "ports": [ + { + "target": 80, + "published": "8749", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/freshrss/data", + "target": "/var/www/FreshRSS/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/freshrss/extensions", + "target": "/var/www/FreshRSS/extensions" + } + ], + "container_name": "freshrss" + } + } + ], + "top_level": { + "name": "freshrss" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "freshrss-volume-0", + "service": "freshrss", + "container_path": "/var/www/FreshRSS/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "freshrss-volume-1", + "service": "freshrss", + "container_path": "/var/www/FreshRSS/extensions", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "freshrss" + ], + "stop_order": [ + "freshrss" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/freshrss.json b/oci/catalog/apps/freshrss.json new file mode 100644 index 00000000..9015de5b --- /dev/null +++ b/oci/catalog/apps/freshrss.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-freshrss", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Freshrss" + }, + "tagline": { + "en_US": "Freshrss is a free, self-hostable aggregator for rss feeds." + }, + "description": { + "en_US": "Freshrss is a free, self-hostable aggregator for rss feeds." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/freshrss-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/freshrss-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://freshrss.org/", + "documentation": "https://docs.linuxserver.io/images/docker-freshrss/", + "repository": "https://github.com/linuxserver/docker-freshrss", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-21", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-06-19", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-04-10", + "note": "Added php-exif module to resolve issue with fever api." + }, + { + "date": "2024-03-06", + "note": "Existing users should update: site-confs/default.conf - Cleanup default site conf." + } + ], + "display_version": null, + "updated_at": "2026-07-21" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-freshrss", + "default_branch": "master", + "revision": "06cf008ef4ee874a0f91f492bba082348427e881", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-freshrss/06cf008ef4ee874a0f91f492bba082348427e881/README.md", + "readme_pushed_at": "2026-09-09T18:43:57Z", + "compose_sha256": "3c7d5d2500b1a9a994515e757afceea3e2fa91f4d9ec565794f74fce05341ff8", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "freshrss", + "container_name": "freshrss", + "image": { + "reference": "lscr.io/linuxserver/freshrss:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/freshrss", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/freshrss/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n freshrss:\n image: lscr.io/linuxserver/freshrss:latest\n container_name: freshrss\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/freshrss/config:/config\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/frigate.json b/oci/catalog/apps/frigate.json new file mode 100644 index 00000000..17a212d7 --- /dev/null +++ b/oci/catalog/apps/frigate.json @@ -0,0 +1,1130 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-frigate", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Frigate" + }, + "tagline": { + "en_US": "NVR with optional VA-API video acceleration and hardware object detectors" + }, + "description": { + "en_US": "Frigate adapted as a native Proxmox OCI LXC with persistent configuration, selectable recording storage, tmpfs cache and optional GPU or detector devices." + }, + "category": "nvr", + "category_label": "NVR & Cameras", + "author": "Frigate", + "developer": "Frigate", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5000, + "path": "/" + }, + "website": "https://frigate.video/", + "documentation": "https://docs.frigate.video/", + "repository": "https://github.com/blakeblackshear/frigate", + "tips": [ + "The template installs infrastructure only and never bundles cameras or a Frigate configuration file.", + "VA-API accelerates video decode/encode; it is separate from object detection with Coral, OpenVINO, ROCm or TensorRT.", + "The rolling stable image is kept intact. If unrelated native modules fail intermittently, validate host RAM and CPU stability before changing packages inside the image.", + "GPU passthrough is independent of Coral. Configure Frigate FFmpeg hwaccel_args using preset-vaapi or preset-nvidia; passing devices does not change existing camera configuration. NVIDIA channel workload validation pending." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-12" + }, + "source": { + "provider": "frigate", + "repository": "https://github.com/blakeblackshear/frigate", + "revision": "37f338d5d6d0c8a117a262aacb7e6184660fd157", + "image_repository_url": "https://ghcr.io/blakeblackshear/frigate", + "readme_pushed_at": "2026-09-12T13:30:04Z", + "compose_sha256": "2aa1dc599c69aaac422305d0d653e3980080f2491ca74e615d08b0e9f402b722", + "generated_at": "2026-09-12T15:58:20+00:00", + "default_branch": "dev", + "readme_raw_url": "https://raw.githubusercontent.com/blakeblackshear/frigate/dev/README.md" + }, + "container_contract": { + "service_name": "frigate", + "container_name": "frigate", + "image": { + "reference": "ghcr.io/blakeblackshear/frigate:stable", + "registry": "ghcr.io", + "repository": "ghcr.io/blakeblackshear/frigate", + "tag": "stable", + "digest": null, + "pull_policy": "resolve-rolling-stable-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/etc/localtime", + "compose_source_example": "/etc/localtime", + "read_only": true, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 1 + } + }, + { + "id": "volume-1", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/media/frigate", + "compose_source_example": "/mnt/oci-shared/recordings/frigate", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 100 + } + } + ], + "ports": [ + { + "container_port": 8971, + "published_example": 8971, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8554, + "published_example": 8554, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8555, + "published_example": 8555, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8555, + "published_example": 8555, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": "30s", + "original_compose": "name: frigate\nservices:\n frigate:\n container_name: frigate\n image: ghcr.io/blakeblackshear/frigate:stable\n deploy:\n resources:\n reservations:\n memory: 256M\n devices:\n - /dev/bus/usb:/dev/bus/usb\n - /dev/apex_0:/dev/apex_0\n - /dev/video11:/dev/video11\n - /dev/dri/renderD128:/dev/dri/renderD128\n network_mode: bridge\n privileged: true\n ports:\n - target: 8971\n published: '8971'\n protocol: tcp\n - target: 8554\n published: '8554'\n protocol: tcp\n - target: 8555\n published: '8555'\n protocol: tcp\n - target: 8555\n published: '8555'\n protocol: udp\n restart: unless-stopped\n stop_grace_period: 30s\n shm_size: 512mb\n tmpfs:\n - /tmp/cache:size=1000000000\n volumes:\n - type: bind\n source: /etc/localtime\n target: /etc/localtime\n read_only: true\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/Media\n target: /media/frigate\n" + }, + "compose_stack": { + "project_name": "frigate", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "frigate", + "service_count": 1, + "services": [ + { + "name": "frigate", + "image": "ghcr.io/blakeblackshear/frigate:stable", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "frigate", + "image": "ghcr.io/blakeblackshear/frigate:stable", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "devices": [ + "/dev/bus/usb:/dev/bus/usb", + "/dev/apex_0:/dev/apex_0", + "/dev/video11:/dev/video11", + "/dev/dri/renderD128:/dev/dri/renderD128" + ], + "network_mode": "bridge", + "privileged": true, + "ports": [ + { + "target": 8971, + "published": "8971", + "protocol": "tcp" + }, + { + "target": 8554, + "published": "8554", + "protocol": "tcp" + }, + { + "target": 8555, + "published": "8555", + "protocol": "tcp" + }, + { + "target": 8555, + "published": "8555", + "protocol": "udp" + } + ], + "restart": "unless-stopped", + "stop_grace_period": "30s", + "shm_size": "512mb", + "tmpfs": [ + "/tmp/cache:size=1000000000" + ], + "volumes": [ + { + "type": "bind", + "source": "/etc/localtime", + "target": "/etc/localtime", + "read_only": true + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/Media", + "target": "/media/frigate" + } + ] + } + } + ], + "top_level": { + "name": "frigate" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "frigate-volume-0", + "service": "frigate", + "container_path": "/etc/localtime", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/localtime", + "source_path_prompt": null + }, + { + "id": "frigate-volume-1", + "service": "frigate", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "frigate-volume-2", + "service": "frigate", + "container_path": "/media/frigate", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for frigate:/media/frigate" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "frigate" + ], + "stop_order": [ + "frigate" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Frigate WebUI", + "scheme": "http", + "port": 5000, + "path": "/", + "source": "laboratory-validated-native-oci-endpoint" + }, + { + "label": "go2rtc WebUI", + "scheme": "http", + "port": 1984, + "path": "/", + "source": "integrated-go2rtc-native-oci-endpoint" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "frigate" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 4, + "cpuset_requirement": "none-for-current-openvino-lxc-repair", + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 16, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": false, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-user-values", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "persistent-config-and-recording-storage", + "upstream_behavior": "Docker mounts /config and /media/frigate.", + "native_lxc_behavior": "Use a backup-enabled managed volume for /config and let the user choose a managed volume or host bind for /media/frigate.", + "reason": "Configuration is private state while recordings can be large shared data.", + "behavioral_impact": "Recordings are excluded from vzdump by default.", + "validation": "passed-laboratory-profile" + }, + { + "id": "tmpfs-cache", + "upstream_behavior": "The official Compose mounts a bounded tmpfs at /tmp/cache.", + "native_lxc_behavior": "Create the equivalent size-limited LXC tmpfs mount.", + "reason": "Avoid persistent cache writes and preserve Frigate memory behavior.", + "behavioral_impact": "Cache is cleared on restart.", + "validation": "passed-laboratory-profile" + }, + { + "id": "optional-vaapi-device", + "upstream_behavior": "Docker passes a selected /dev/dri render device.", + "native_lxc_behavior": "Resolve the host render GID and grant only the selected render device to the unprivileged LXC.", + "reason": "Frigate can hardware-accelerate video decode without making the LXC privileged.", + "behavioral_impact": "Requires host-specific device and GID validation.", + "validation": "passed-amd-radeonsi-laboratory-profile" + }, + { + "id": "openvino-lxc-cpu-compatibility", + "upstream_behavior": "Frigate ships its detector runtime in the image.", + "native_lxc_behavior": "On amd64, ensure OpenVINO is at least 2026.1.0 and install that exact version with --no-deps only when the bundled runtime is older.", + "reason": "The 2025.4.1 CPU plugin bundled by Frigate 0.18 stable intermittently segfaults while compiling the default model inside an unprivileged LXC.", + "behavioral_impact": "Only the OpenVINO wheel is replaced; NumPy and every other image dependency remain unchanged.", + "validation": "passed-frigate-0.18.0-stable-amd64-three-starts-twenty-compiles" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "commands": [ + "pct", + "pvesm", + "skopeo" + ], + "features": [ + "native-oci-lxc" + ] + }, + "deployment": { + "runtime": "proxmox-native-oci-lxc", + "unprivileged": true, + "entrypoint": "/init", + "working_directory": "/opt/frigate/", + "hostname_default": "frigate", + "onboot_default": false, + "startup_order_default": 30, + "startup_delay_seconds_default": 10, + "features": [ + "nesting=1" + ], + "ports": [ + { + "port": 5000, + "protocol": "tcp", + "purpose": "native-oci-web-ui" + }, + { + "port": 1984, + "protocol": "tcp", + "purpose": "integrated-go2rtc-web-ui-api" + }, + { + "port": 8554, + "protocol": "tcp", + "purpose": "rtsp-restream" + }, + { + "port": 8555, + "protocol": "tcp", + "purpose": "webrtc" + }, + { + "port": 8555, + "protocol": "udp", + "purpose": "webrtc" + } + ], + "entrypoint_override": "explicit-validated-image-command", + "entrypoint_source": "validated-lxc-oci-profile" + }, + "defaults": { + "resources": { + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 16 + }, + "network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "ipv4_address": null, + "ipv4_gateway": null, + "firewall": false, + "host_managed": true + }, + "environment": { + "TZ": "Europe/Madrid", + "LIBVA_DRIVER_NAME": null + } + }, + "configuration_schema": { + "vmid": { + "type": "integer", + "required": false, + "default": null, + "description": "Identificador manual o siguiente VMID libre si se omite." + }, + "hostname": { + "type": "string", + "required": true, + "default": "frigate", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,62}$" + } + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ] + }, + "rootfs_size_gb": { + "type": "integer", + "required": true, + "default": 16, + "minimum": 8 + }, + "cores": { + "type": "integer", + "required": true, + "default": 4, + "minimum": 2 + }, + "memory_mb": { + "type": "integer", + "required": true, + "default": 4096, + "minimum": 2048 + }, + "swap_mb": { + "type": "integer", + "required": true, + "default": 1024, + "minimum": 0 + }, + "bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "ipv4_mode": { + "type": "select", + "required": true, + "default": "dhcp", + "options": [ + "dhcp", + "static" + ] + }, + "ipv4_address": { + "type": "cidr", + "required_when": { + "field": "ipv4_mode", + "equals": "static" + } + }, + "ipv4_gateway": { + "type": "ipv4", + "required_when": { + "field": "ipv4_mode", + "equals": "static" + } + }, + "config_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "description": "Volumen persistente e independiente para /config." + }, + "config_size_gb": { + "type": "integer", + "required": true, + "default": 8, + "minimum": 2 + }, + "media_storage_mode": { + "type": "select", + "required": true, + "default": "host-bind", + "options": [ + "managed-volume", + "host-bind", + "rootfs" + ], + "description": "Destino persistente de /media/frigate." + }, + "media_storage": { + "type": "storage-selector", + "required_when": { + "field": "media_storage_mode", + "equals": "managed-volume" + }, + "content_types": [ + "rootdir" + ] + }, + "media_size_gb": { + "type": "integer", + "required_when": { + "field": "media_storage_mode", + "equals": "managed-volume" + }, + "default": 100, + "minimum": 10 + }, + "media_host_path": { + "type": "host-directory", + "required_when": { + "field": "media_storage_mode", + "equals": "host-bind" + }, + "default": "/mnt/oci-shared/recordings/frigate/ct${vmid}", + "create_if_missing": true, + "description": "Host path that can be shared with other containers." + }, + "cache_size_mb": { + "type": "integer", + "required": true, + "default": 1024, + "minimum": 256 + }, + "gpu_enabled": { + "type": "boolean", + "required": true, + "default": true + }, + "gpu_render_device": { + "type": "host-device-selector", + "required_when": { + "field": "gpu_enabled", + "equals": true + }, + "default": "/dev/dri/renderD128", + "filter": "/dev/dri/renderD*" + }, + "vaapi_driver": { + "type": "select", + "required": false, + "default": "auto", + "options": [ + "auto", + "radeonsi", + "iHD", + "i965" + ] + }, + "timezone": { + "type": "timezone", + "required": true, + "default": "Europe/Madrid" + }, + "onboot": { + "type": "boolean", + "required": true, + "default": false + }, + "openvino_cpu_compatibility": { + "type": "boolean", + "required": false, + "default": false, + "hidden": true, + "description": "Reservado para una futura adaptacion validada en hardware estable; no modifica la imagen oficial." + } + }, + "mounts": [ + { + "id": "config", + "container_path": "/config", + "source": "managed-volume", + "storage_field": "config_storage", + "size_field": "config_size_gb", + "backup": true, + "required": true + }, + { + "id": "media", + "container_path": "/media/frigate", + "source_field": "media_storage_mode", + "storage_field": "media_storage", + "size_field": "media_size_gb", + "host_path_field": "media_host_path", + "backup": false, + "required": false + }, + { + "id": "cache", + "container_path": "/tmp/cache", + "source": "tmpfs", + "size_field": "cache_size_mb", + "mount_options": [ + "rw", + "noexec", + "nosuid", + "nodev" + ], + "required": true + } + ], + "devices": [ + { + "id": "gpu-render", + "enabled_field": "gpu_enabled", + "host_path_field": "gpu_render_device", + "container_path": "/dev/dri/renderD128", + "permissions": "rwm", + "optional": true + } + ], + "environment": [ + { + "name": "TZ", + "value_from": "timezone" + }, + { + "name": "LIBVA_DRIVER_NAME", + "value_from": "vaapi_driver", + "omit_when": "auto" + } + ], + "compatibility": { + "openvino_cpu": { + "enabled_field": "openvino_cpu_compatibility", + "status": "pending-validation-on-stable-hardware", + "runtime_policy": "preserve-official-image-runtime", + "automatic_internal_configuration": false, + "description": "No se aplica ninguna sustitucion de paquetes mientras la prueba del host presente errores de memoria." + } + }, + "healthcheck": { + "type": "http", + "port": 5000, + "path": "/api/version", + "verify_tls": true, + "interval_seconds": 30, + "timeout_seconds": 10, + "retries": 10, + "start_period_seconds": 120 + }, + "boundaries": { + "bundles_internal_configuration": false, + "bundles_credentials": false, + "bundles_user_data": false, + "installer_must_not_write_config_yaml": true + }, + "notes": [ + "Esta plantilla describe la instalacion OCI y su infraestructura persistente.", + "La configuracion funcional de Frigate se realiza despues desde la aplicacion.", + "La WebUI validada para el LXC OCI nativo se publica como http://IP:5000.", + "La imagen incluye go2rtc 1.9.14 y su WebUI/API queda disponible como http://IP:1984.", + "Frigate stable 0.18.0 en amd64 incluye un wheel de Pandas 2.2.3 que provoca SIGSEGV en el Ryzen 7 5700U del laboratorio; el instalador comprueba el import y solo si falla reinstala la misma version desde PyPI.", + "La configuracion inicial de Frigate 0.18 activa OpenVINO CPU. La version 2025.4.1 incluida falla de forma intermitente al compilar el modelo dentro de LXC; en amd64 el instalador asegura OpenVINO 2026.1.0 con --no-deps y conserva NumPy 1.26.4.", + "El modo host-bind permite compartir el almacenamiento multimedia del host entre varios LXC OCI.", + "La opcion rootfs para multimedia es solo adecuada para pruebas breves.", + "La GPU es opcional; el instalador debe validar el dispositivo antes de arrancar el contenedor." + ] + }, + "application_options": { + "video_acceleration": { + "selectable": true, + "profiles": [ + "none", + "vaapi" + ], + "validated_profile": "amd-radeonsi-vaapi" + }, + "object_detector": { + "selectable": true, + "profiles": [ + "cpu", + "coral", + "openvino", + "rocm", + "tensorrt" + ], + "openvino": { + "available": true, + "laboratory_validated": false, + "validated_device": "CPU", + "observed_inference_ms": 13.92, + "configuration_location": "/config/config.yaml", + "installer_writes_detector_configuration": false, + "runtime_policy": "preserve-official-image-runtime", + "current_stable_validation": "blocked-by-host-memory-failure", + "compatibility_workaround": null + }, + "configuration_owned_by_user": true, + "warning": "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML." + } + }, + "installer_profile": { + "pre_start_repairs": [], + "startup_healthcheck": { + "type": "http", + "scheme": "http", + "port": 5000, + "path": "/api/config", + "timeout_seconds": 120, + "request_timeout_seconds": 3, + "stability_seconds": 0, + "verify_tls": true, + "required": true + }, + "host_bind_policies": { + "/media/frigate": { + "create_if_missing": true, + "purpose": "large-recording-storage-outside-native-lxc-backup" + } + }, + "tmpfs_mounts": [ + { + "id": "frigate-cache", + "container_path": "/tmp/cache", + "default_size_mb": 1024, + "minimum_size_mb": 256, + "size_prompt": "Size of the Frigate temporary cache in MB", + "mount_options": [ + "rw", + "noexec", + "nosuid", + "nodev" + ] + } + ], + "optional_devices": [ + { + "id": "coral-pcie", + "kind": "character-device", + "enable_prompt": "Add a Coral PCIe/M.2 device?", + "enabled_default": false, + "path_prompt": "Coral PCIe/M.2 node (e.g. /dev/apex_0)", + "host_path_default": "/dev/apex_0", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ], + "version_aware_adaptations": {}, + "hardware_acceleration": { + "prompt": "Hardware acceleration for Frigate", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "image": { + "reference": "ghcr.io/blakeblackshear/frigate:stable", + "registry": "ghcr.io", + "repository": "ghcr.io/blakeblackshear/frigate", + "tag": "stable", + "digest": null, + "pull_policy": "resolve-rolling-stable-tag-to-architecture-digest-at-install" + }, + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD VA-API", + "image": { + "reference": "ghcr.io/blakeblackshear/frigate:stable", + "registry": "ghcr.io", + "repository": "ghcr.io/blakeblackshear/frigate", + "tag": "stable", + "digest": null, + "pull_policy": "resolve-rolling-stable-tag-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "gpu-render", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "kind": "character-device", + "container_path_strategy": "same-as-host", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVDEC/CUDA)", + "architectures": [ + "amd64" + ], + "image": { + "reference": "ghcr.io/blakeblackshear/frigate:stable-tensorrt", + "registry": "ghcr.io", + "repository": "ghcr.io/blakeblackshear/frigate", + "tag": "stable-tensorrt", + "digest": null, + "pull_policy": "resolve-rolling-stable-tag-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-video", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + }, + { + "name": "NVIDIA_DRIVER_CAPABILITIES", + "value": "compute,video,utility" + } + ] + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "image_channel_policy": { + "channel": "stable", + "rolling": true, + "version_pinned": false, + "reason": "Frigate publishes stable as its official rolling production tag and does not publish latest.", + "official_reference": "https://docs.frigate.video/frigate/installation/" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The native single-LXC installation path translates persistent storage, the bounded tmpfs cache and optional VA-API device mapping. Frigate cameras and detector configuration remain owned by the user. The rolling stable image and its bundled Python runtime are preserved without package replacement." + }, + "validation": { + "schema": "passed-at-generation", + "validated_profile": { + "id": "pve55-amd-vaapi-openvino", + "description": "Reproducible profile based on a validated working deployment.", + "validated_on": "2026-08-26", + "validation_status": "passed", + "image": { + "repository": "blakeblackshear/frigate", + "tag": "0.17.1", + "architecture": "amd64" + }, + "container": { + "ostype": "debian", + "cmode": "console", + "unprivileged": true, + "entrypoint": "/init", + "working_directory": "/opt/frigate/", + "halt_signal": "SIGTERM", + "features": [ + "nesting=1" + ], + "onboot": false + }, + "resources": { + "cores": 4, + "cpuset": "0-3", + "cpuset_requirement": "must-include-cpu0", + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_storage": "local-lvm", + "rootfs_size_gb": 16 + }, + "network": { + "interface": "eth0", + "type": "veth", + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "host_managed": true, + "firewall": false + }, + "storage": { + "config": { + "mode": "managed-volume", + "storage": "local-lvm", + "size_gb": 8, + "container_path": "/config", + "backup": true + }, + "media": { + "mode": "host-bind", + "host_path_template": "/mnt/oci-shared/frigate/ct${vmid}/media", + "container_path": "/media/frigate", + "backup": false, + "create_if_missing": true, + "pre_start_check": { + "type": "host-mountpoint", + "path": "/mnt/oci-shared", + "failure_mode": "abort-start" + } + }, + "cache": { + "mode": "tmpfs", + "size_mb": 1024, + "container_path": "/tmp/cache", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + }, + "gpu": { + "enabled": true, + "host_path": "/dev/dri/renderD128", + "container_path": "/dev/dri/renderD128", + "mode": "0660", + "gid_strategy": "resolve-render-group-on-host", + "validated_host_gid": 993, + "vaapi_driver": "radeonsi" + }, + "environment_overrides": { + "TZ": "Europe/Madrid", + "LIBVA_DRIVER_NAME": "radeonsi" + }, + "preserve_image_environment": true, + "openvino": { + "enabled": true, + "device": "CPU", + "package": "openvino==2026.1.0", + "installed_version": "2026.1.0-21367-63e31528c62-releases/2026/1", + "installation_scope": "oci-rootfs", + "install_command": [ + "python3", + "-m", + "pip", + "install", + "--no-cache-dir", + "--break-system-packages", + "openvino==2026.1.0" + ], + "detector_configuration_managed_by_installer": false, + "reason": "Evita el fallo del plugin CPU de la version OpenVINO incluida originalmente en Frigate 0.17.1 bajo LXC." + }, + "validation": { + "web_ui": "healthy", + "gpu_vaapi": "passed", + "persistent_config": "passed", + "persistent_media": "passed", + "tmpfs_cache": "passed", + "openvino_cpu": "passed", + "real_streams": "passed", + "openvino_inference_ms_observed": 13.92, + "cpu_detector_inference_ms_observed": 21.23 + } + }, + "stable_validation": { + "validated_on": "2026-09-13", + "host": "pve55-amd-ryzen-7-5700u", + "image": { + "tag": "stable", + "version": "0.18.0-77a66e7", + "digest": "sha256:9678a83a76e4730ac7d9ea7428370e32ae656d6b312aaad30d6c69f3fef14d35" + }, + "status": "blocked-by-host-hardware-instability", + "observed_failure": { + "result": "intermittent-native-faults-across-openvino-shapely-pandas-pvesh-and-perl", + "host_memtester": "failed-possible-bad-address-line", + "storage_health": "nvme-smart-passed-zero-media-errors" + }, + "verification": { + "clean_install": "invalid-until-host-memory-is-repaired", + "official_runtime_preserved": true + } + }, + "source_profile": "frigate-oci.json", + "automatic_installer_translation": { + "persistent_config": "covered", + "recording_storage": "covered-managed-volume-or-created-host-bind", + "tmpfs_cache": "covered-native-lxc-mount-entry", + "vaapi_device": "covered-native-proxmox-dev-property-with-host-gid", + "openvino_stable": "preserve-official-image-runtime-pending-healthy-host-validation", + "clean_install_stable": "blocked-by-confirmed-host-memory-error" + }, + "stable_channel_image": "pending-revalidation-after-host-memory-repair" + }, + "lifecycle": { + "update_strategy": "resolve-stable-image-then-replace-rootfs-preserve-/config-and-selected-/media/frigate-storage", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-source-revision-and-resolved-stable-image-digest", + "automatic_unattended_updates": false, + "validated_workflows": { + "install": [ + "validate-requirements", + "resolve-options", + "pull-oci-image", + "create-container", + "attach-persistent-storage", + "attach-optional-devices", + "apply-runtime-environment", + "apply-optional-compatibility", + "start-container", + "wait-for-healthcheck" + ], + "update": [ + "stop-container", + "backup-container-definition", + "pull-oci-image", + "recreate-rootfs-preserving-mounts", + "start-container", + "wait-for-healthcheck" + ], + "uninstall": { + "remove_rootfs": true, + "preserve_config_by_default": true, + "preserve_media_by_default": true + } + } + } +} diff --git a/oci/catalog/apps/gateway-go.json b/oci/catalog/apps/gateway-go.json new file mode 100644 index 00000000..0504f915 --- /dev/null +++ b/oci/catalog/apps/gateway-go.json @@ -0,0 +1,401 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-gateway-go", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "gateway-go" + }, + "tagline": { + "en_US": "A third-party client for self-hosted server and self-hosted server, remote access management interface, remote access to installed applications." + }, + "description": { + "en_US": "A fast reverse proxy to help you expose a local server behind a NAT or firewall to your client, remote access all your self-hosted server/self-hosted server apps.\n\nUse OpenIoTHub to scan the following QR code add a gateway,then add host,add self-hosted server/self-hosted server host's web page port,finally, enjoy remote control\n" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "iotserv", + "developer": "iotserv", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 34323, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/openiothub/gateway-go", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "openiothub", + "repository": "https://hub.docker.com/r/openiothub/gateway-go", + "revision": "1a68a0fccd234edc526ad742c5784ee97e70b4ac65b351af574b60207d98a27a", + "image_repository_url": "https://hub.docker.com/r/openiothub/gateway-go", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "1a68a0fccd234edc526ad742c5784ee97e70b4ac65b351af574b60207d98a27a", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "gateway-go", + "container_name": "gateway-go", + "image": { + "reference": "openiothub/gateway-go:latest", + "registry": "docker.io", + "repository": "openiothub/gateway-go", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/root", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 34323, + "published_example": 34323, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: gateway-go\nservices:\n gateway-go:\n image: openiothub/gateway-go:latest\n network_mode: host\n deploy:\n resources:\n reservations:\n memory: 32M\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /root\n ports:\n - target: 34323\n published: '34323'\n protocol: tcp\n container_name: gateway-go\n" + }, + "compose_stack": { + "project_name": "gateway-go", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "gateway-go", + "service_count": 1, + "services": [ + { + "name": "gateway-go", + "image": "openiothub/gateway-go:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "openiothub/gateway-go:latest", + "network_mode": "host", + "deploy": { + "resources": { + "reservations": { + "memory": "32M" + } + } + }, + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/root" + } + ], + "ports": [ + { + "target": 34323, + "published": "34323", + "protocol": "tcp" + } + ], + "container_name": "gateway-go" + } + } + ], + "top_level": { + "name": "gateway-go" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "gateway-go-volume-0", + "service": "gateway-go", + "container_path": "/root", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "gateway-go" + ], + "stop_order": [ + "gateway-go" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 34323, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/gimp.json b/oci/catalog/apps/gimp.json new file mode 100644 index 00000000..22daf994 --- /dev/null +++ b/oci/catalog/apps/gimp.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-gimp", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Gimp" + }, + "tagline": { + "en_US": "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable." + }, + "description": { + "en_US": "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gimp-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gimp-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.gimp.org/", + "documentation": "https://docs.linuxserver.io/images/docker-gimp/", + "repository": "https://github.com/linuxserver/docker-gimp", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-24", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Debian Trixie, install resynthesizer, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-23", + "note": "Rebase to Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-03-24" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-gimp", + "default_branch": "master", + "revision": "ca02cc0c37a60eb10253e575a05c941b7d4c9e20", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-gimp/ca02cc0c37a60eb10253e575a05c941b7d4c9e20/README.md", + "readme_pushed_at": "2026-09-08T10:28:59Z", + "compose_sha256": "a85aa80ed6c3b214fabdb36306c80960192e790c07897ef988527b5e2d16ff3c", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "gimp", + "container_name": "gimp", + "image": { + "reference": "lscr.io/linuxserver/gimp:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/gimp", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n gimp:\n image: lscr.io/linuxserver/gimp:latest\n container_name: gimp\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-gimp/master/Dockerfile", + "dockerfile_sha256": "586e73ccdd7e0e9856f9253cf6d44036ce5bcbfbb91c43fa122b0f232858f51f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/gitea.json b/oci/catalog/apps/gitea.json new file mode 100644 index 00000000..550dd057 --- /dev/null +++ b/oci/catalog/apps/gitea.json @@ -0,0 +1,432 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-gitea", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Gitea" + }, + "tagline": { + "en_US": "Self-hosted software development service" + }, + "description": { + "en_US": "Gitea is a painless self-hosted all-in-one software development service, it includes Git hosting, code review, team collaboration, package registry and CI/CD. It is similar to GitHub, Bitbucket and GitLab. \n\n- Code Hosting\nGitea supports creating and managing repositories, browsing commit history and code files, reviewing and merging code submissions, managing collaborators, handling branches, and more. It also supports many common Git features such as tags, Cherry-pick, hooks, integrated collaboration tools, and more.\n\n- Lightweight and Fast\nOne of Gitea's design goals is to be lightweight and fast in response. Unlike some large code hosting platforms, it remains lean, performing well in terms of speed, and is suitable for resource-limited server environments. Due to its lightweight design, Gitea has relatively low resource consumption and performs well in resource-constrained environments.\n\n- Easy Deployment and Maintenance\nIt can be easily deployed on various servers without complex configurations or dependencies. This makes it convenient for individual developers or small teams to set up and manage their own Git services.\n\n- Security\nGitea places a strong emphasis on security, offering features such as user permission management, access control lists, and more to ensure the security of code and data.\n\n- Code Review\nCode review supports both the Pull Request workflow and AGit workflow. Reviewers can browse code online and provide review comments or feedback. Submitters can receive review comments and respond or modify code online. Code reviews can help individuals and organizations enhance code quality.\n\n- CI/CD\nGitea Actions supports CI/CD functionality, compatible with GitHub Actions. Users can write workflows in familiar YAML format and reuse a variety of existing Actions plugins. Actions plugins support downloading from any Git website.\n\n- Project Management\nGitea tracks project requirements, features, and bugs through columns and issues. Issues support features like branches, tags, milestones, assignments, time tracking, due dates, dependencies, and more.\n\n- Artifact Repository\nGitea supports over 20 different types of public or private software package management, including Cargo, Chef, Composer, Conan, Conda, Container, Helm, Maven, npm, NuGet, Pub, PyPI, RubyGems, Vagrant, and more.\n\n- Open Source Community Support\nGitea is an open-source project based on the MIT license. It has an active open-source community that continuously develops and improves the platform. The project also actively welcomes community contributions, ensuring updates and innovation.\n\n- Multilingual Support\nGitea provides interfaces in multiple languages, catering to users globally and promoting internationalization and localization.\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Gitea", + "developer": "Gitea", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://about.gitea.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/gitea/gitea", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/gitea/gitea", + "revision": "c32c184363a27cbb718a57949c72a0569c7a5d6129c3559e79c7794c48d45ce5", + "image_repository_url": "https://hub.docker.com/r/gitea/gitea", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "c32c184363a27cbb718a57949c72a0569c7a5d6129c3559e79c7794c48d45ce5", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "gitea", + "container_name": "gitea", + "image": { + "reference": "gitea/gitea:latest", + "registry": "docker.io", + "repository": "gitea/gitea", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USER_GID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "USER_UID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3002, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 22, + "published_example": 222, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: gitea\nservices:\n gitea:\n environment:\n USER_GID: '1000'\n USER_UID: '1000'\n image: gitea/gitea:latest\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n ports:\n - target: 3000\n published: '3002'\n protocol: tcp\n - target: 22\n published: '222'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n container_name: gitea\n" + }, + "compose_stack": { + "project_name": "gitea", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "gitea", + "service_count": 1, + "services": [ + { + "name": "gitea", + "image": "gitea/gitea:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "USER_GID": "1000", + "USER_UID": "1000" + }, + "image": "gitea/gitea:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 3000, + "published": "3002", + "protocol": "tcp" + }, + { + "target": 22, + "published": "222", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "container_name": "gitea" + } + } + ], + "top_level": { + "name": "gitea" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "gitea-volume-0", + "service": "gitea", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for gitea:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "gitea" + ], + "stop_order": [ + "gitea" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/github-desktop.json b/oci/catalog/apps/github-desktop.json new file mode 100644 index 00000000..292d7167 --- /dev/null +++ b/oci/catalog/apps/github-desktop.json @@ -0,0 +1,480 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-github-desktop", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Github Desktop" + }, + "tagline": { + "en_US": "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React." + }, + "description": { + "en_US": "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/github-desktop-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/github-desktop-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://desktop.github.com/", + "documentation": "https://docs.linuxserver.io/images/docker-github-desktop/", + "repository": "https://github.com/linuxserver/docker-github-desktop", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform flag for apps fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-github-desktop", + "default_branch": "master", + "revision": "31edb1dca04505312addd09daf57fb61d0616de9", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-github-desktop/31edb1dca04505312addd09daf57fb61d0616de9/README.md", + "readme_pushed_at": "2026-09-13T00:12:51Z", + "compose_sha256": "d7d4dc30aa197ed622ff2c3aa2561adea209ffd887787b939f14f45d7b3b4bdc", + "generated_at": "2026-09-13T15:47:48+00:00" + }, + "container_contract": { + "service_name": "github-desktop", + "container_name": "github-desktop", + "image": { + "reference": "lscr.io/linuxserver/github-desktop:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/github-desktop", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/github-desktop/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n github-desktop:\n image: lscr.io/linuxserver/github-desktop:latest\n container_name: github-desktop\n cap_add:\n - IPC_LOCK\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/github-desktop/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "security": { + "required_capabilities": [ + "IPC_LOCK" + ] + }, + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-github-desktop/master/Dockerfile", + "dockerfile_sha256": "3bae15eb6f81e3dac69859063580744abe6e7df149f549ea98901cbe3f78b898", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/gitqlient.json b/oci/catalog/apps/gitqlient.json new file mode 100644 index 00000000..c9442d75 --- /dev/null +++ b/oci/catalog/apps/gitqlient.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-gitqlient", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Gitqlient" + }, + "tagline": { + "en_US": "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality." + }, + "description": { + "en_US": "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gitqlient-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gitqlient-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/francescmm/GitQlient", + "documentation": "https://docs.linuxserver.io/images/docker-gitqlient/", + "repository": "https://github.com/linuxserver/docker-gitqlient", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-gitqlient", + "default_branch": "master", + "revision": "a80248b4b624d1737dbb1310975fa519ef8edaf3", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-gitqlient/a80248b4b624d1737dbb1310975fa519ef8edaf3/README.md", + "readme_pushed_at": "2026-09-07T17:07:53Z", + "compose_sha256": "ddaa8eee1cc762726b559c3eec54b01c18d270575e1bd5d1e20bf874508449a2", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "gitqlient", + "container_name": "gitqlient", + "image": { + "reference": "lscr.io/linuxserver/gitqlient:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/gitqlient", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n gitqlient:\n image: lscr.io/linuxserver/gitqlient:latest\n container_name: gitqlient\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-gitqlient/master/Dockerfile", + "dockerfile_sha256": "6b6e54e80e3fc8da86b02e68c7bc7a3da28b1a2f6dcbae581f48340b1c95ec0b", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/glances.json b/oci/catalog/apps/glances.json new file mode 100644 index 00000000..89692d41 --- /dev/null +++ b/oci/catalog/apps/glances.json @@ -0,0 +1,510 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-glances", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Glances" + }, + "tagline": { + "en_US": "Cross-platform monitoring tool." + }, + "description": { + "en_US": "Glances is an open-source system cross-platform monitoring tool. It allows real-time monitoring of various aspects of your system such as CPU, memory, disk, network usage etc." + }, + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "author": "Nicolas Hennion", + "developer": "Nicolas Hennion", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 61208, + "path": "/" + }, + "website": "https://nicolargo.github.io/glances/", + "documentation": null, + "repository": "https://hub.docker.com/r/nicolargo/glances", + "tips": [ + "Optional host mode: shares the Proxmox IP and metrics. If declined, it installs unprivileged, with its own IP and metrics for the LXC ONLY.", + "Privileged access to the host PID/network and unconfined AppArmor: requires confirmation. Trusted networks only; the host firewall is the one that applies.", + "Neither docker.sock nor the host root directory is mounted. Docker inventory, SMART and capacity of all filesystems are not guaranteed.", + "LXCFS is skipped only in the monitor CT so that the limited container RAM/CPU is not shown.", + "Uses lxc.include with /etc/pve/lxc/proxmenux-host-monitor; this file is not included in vzdump and must be kept when restoring on another host.", + "The CPU limit is applied as cpulimit, without hiding processors through affinity." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "nicolargo", + "repository": "https://hub.docker.com/r/nicolargo/glances", + "revision": "8a12c51716d01e03f2fe30cff811457ef91f6e95efc09449a94a92a3add3caa5", + "image_repository_url": "https://hub.docker.com/r/nicolargo/glances", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "8a12c51716d01e03f2fe30cff811457ef91f6e95efc09449a94a92a3add3caa5", + "generated_at": "2026-09-13T17:20:22+00:00" + }, + "container_contract": { + "service_name": "glances", + "container_name": "glances", + "image": { + "reference": "nicolargo/glances:latest", + "registry": "docker.io", + "repository": "nicolargo/glances", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "GLANCES_OPT", + "example": "-w", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + } + ], + "volumes": [], + "ports": [ + { + "container_port": 61208, + "published_example": 61208, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 61209, + "published_example": 61209, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: glances\nservices:\n glances:\n container_name: glances\n image: nicolargo/glances:latest\n pid: host\n deploy:\n resources:\n reservations:\n memory: 256M\n environment:\n GLANCES_OPT: -w\n restart: unless-stopped\n network_mode: bridge\n privileged: false\n volumes:\n - type: bind\n source: /var/run/docker.sock\n target: /var/run/docker.sock\n - type: bind\n source: /mnt\n target: /mnt\n ports:\n - target: 61208\n published: '61208'\n protocol: tcp\n - target: 61209\n published: '61209'\n protocol: tcp\n" + }, + "compose_stack": { + "project_name": "glances", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "glances", + "service_count": 1, + "services": [ + { + "name": "glances", + "image": "nicolargo/glances:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "glances", + "image": "nicolargo/glances:latest", + "pid": "host", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "environment": { + "GLANCES_OPT": "-w" + }, + "restart": "unless-stopped", + "network_mode": "bridge", + "privileged": false, + "volumes": [ + { + "type": "bind", + "source": "/var/run/docker.sock", + "target": "/var/run/docker.sock" + }, + { + "type": "bind", + "source": "/mnt", + "target": "/mnt" + } + ], + "ports": [ + { + "target": 61208, + "published": "61208", + "protocol": "tcp" + }, + { + "target": 61209, + "published": "61209", + "protocol": "tcp" + } + ] + } + } + ], + "top_level": { + "name": "glances" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "glances-volume-0", + "service": "glances", + "container_path": "/var/run/docker.sock", + "mode": "runtime-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "glances-volume-1", + "service": "glances", + "container_path": "/mnt", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "glances" + ], + "stop_order": [ + "glances" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 61208, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": false, + "ostype": "unmanaged", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "host_monitor": "glances", + "host_monitor_mounts": [ + { + "source": "/etc/os-release", + "target": "/etc/os-release" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 61208, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "verify_tls": false + }, + "security": { + "required_capabilities": [ + "SYS_PTRACE" + ], + "options": { + "apparmor_profile": "unconfined" + } + }, + "host_monitor_optional": true + }, + "security_profile": { + "requires_privileged_lxc": true, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": true, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": true, + "warning": "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "passed-observed-2026-09-14", + "restart_persistence": "passed-observed-2026-09-14", + "backup_restore": "pending", + "update_preserves_data": "pending", + "latest_runtime_observation": { + "date": "2026-09-14", + "vmid": 101, + "architecture": "amd64", + "proxmox": "9.2.18", + "image_digest": "sha256:7bdd499825a9044ad495714421ea2049b73696d64f1fe6697e1ae07bfe164e2c", + "image_version": "v4.5.6", + "http_port": 61208, + "host_pid_namespace": true, + "host_network_namespace": true, + "host_memory_bytes": 16110522368, + "shutdown_start_passed": true, + "companion_include": "/etc/pve/lxc/proxmenux-host-monitor", + "companion_included_in_vzdump": false, + "rolling_tag_validation": "only-observed-digest", + "host_cpu_count": 16, + "host_process_count_observed": 559 + } + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/gopeed.json b/oci/catalog/apps/gopeed.json new file mode 100644 index 00000000..fdbfb672 --- /dev/null +++ b/oci/catalog/apps/gopeed.json @@ -0,0 +1,437 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-gopeed", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Gopeed" + }, + "tagline": { + "en_US": "Open source, lightweight, native, supports (HTTP, BitTorrent, Magnet, etc.) for downloading." + }, + "description": { + "en_US": "Gopeed is a modern high-speed download tool supporting HTTP, BitTorrent, and Magnet protocols, offering a beautiful interface and powerful functionality. Its lightweight design and multi-platform support make it ideal for efficient file downloading across various devices.\n\nThe tool's core features include high-speed downloading and an elegant interface. It leverages Golang coroutines for concurrent downloading, supporting HTTP, HTTPS, BitTorrent, and Magnet protocols for fast, stable performance. The interface follows Material Design standards, including a dark mode, balancing aesthetics and usability. Advanced features include seeding, DHT, PEX, uTP, Webtorrent, and UPnP support, with daily automatic tracker list updates to enhance download efficiency.\n\nIt provides a RESTful API for open integration, allowing users to remotely control download tasks, pause, or delete them. Decentralized extensions enable JavaScript plugins to enhance functionality, such as downloading videos or music from websites. The tool's speed, flexibility, and user-friendly design deliver a modern download solution.\n\n**Key Features:**\n- High-speed downloading with HTTP, BitTorrent, Magnet protocols\n- Seeding, DHT, PEX, uTP, Webtorrent, UPnP\n- Daily automatic tracker list updates\n- RESTful API for remote download task control\n- Decentralized extensions with JavaScript plugins\n\n**Learn More:**\n- [Gopeed Official Website](https://gopeed.com)\n- [Gopeed GitHub Repository](https://github.com/gopeedlab/gopeed)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "GopeedLab", + "developer": "GopeedLab", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9999, + "path": "/" + }, + "website": "https://gopeed.com", + "documentation": null, + "repository": "https://hub.docker.com/r/liwei2633/gopeed", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "liwei2633", + "repository": "https://hub.docker.com/r/liwei2633/gopeed", + "revision": "1623641a69c173a01dc5bb660d8a27bfdf33d15485d525ebacf1a2010e698b96", + "image_repository_url": "https://hub.docker.com/r/liwei2633/gopeed", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "1623641a69c173a01dc5bb660d8a27bfdf33d15485d525ebacf1a2010e698b96", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "gopeed", + "container_name": "gopeed", + "image": { + "reference": "liwei2633/gopeed:latest", + "registry": "docker.io", + "repository": "liwei2633/gopeed", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/storage", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/app/Downloads", + "compose_source_example": "/DATA/Downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 9999, + "published_example": 9999, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: gopeed\nservices:\n gopeed:\n container_name: gopeed\n deploy:\n resources:\n limits:\n memory: 256M\n reservations:\n memory: 256M\n image: liwei2633/gopeed:latest\n ports:\n - target: 9999\n published: '9999'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /app/storage\n - type: bind\n source: /DATA/Downloads\n target: /app/Downloads\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "gopeed", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "gopeed", + "service_count": 1, + "services": [ + { + "name": "gopeed", + "image": "liwei2633/gopeed:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "gopeed", + "deploy": { + "resources": { + "limits": { + "memory": "256M" + }, + "reservations": { + "memory": "256M" + } + } + }, + "image": "liwei2633/gopeed:latest", + "ports": [ + { + "target": 9999, + "published": "9999", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/app/storage" + }, + { + "type": "bind", + "source": "/DATA/Downloads", + "target": "/app/Downloads" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "gopeed" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "gopeed-volume-0", + "service": "gopeed", + "container_path": "/app/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "gopeed-volume-1", + "service": "gopeed", + "container_path": "/app/Downloads", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "gopeed" + ], + "stop_order": [ + "gopeed" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9999, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/grafana.json b/oci/catalog/apps/grafana.json new file mode 100644 index 00000000..928b27be --- /dev/null +++ b/oci/catalog/apps/grafana.json @@ -0,0 +1,401 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-grafana", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Grafana" + }, + "tagline": { + "en_US": "Grafana is a complete observability stack that allows you to monitor and analyze metrics, logs and traces. It allows you to query, visualize, alert on and understand your data no matter where it is stored.\n" + }, + "description": { + "en_US": "Grafana open source is open source visualization and analytics software.Visualizations: Fast and flexible client side graphs with a multitude of options. Panel plugins offer many different ways to visualize metrics and logs. Dynamic Dashboards: Create dynamic & reusable dashboards with template variables that appear as dropdowns at the top of the dashboard. Explore Metrics: Explore your data through ad-hoc queries and dynamic drilldown. Split view and compare different time ranges, queries and data sources side by side. Explore Logs: Experience the magic of switching from metrics to logs with preserved label filters. Quickly search through all your logs or streaming them live. Alerting: Visually define alert rules for your most important metrics. Grafana will continuously evaluate and send notifications to systems like Slack, PagerDuty, VictorOps, OpsGenie. Mixed Data Sources: Mix different data sources in the same graph! You can specify a data source on a per-query basis. This works for even custom datasources.\n" + }, + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "author": "grafana", + "developer": "grafana", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://grafana.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/grafana/grafana", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/grafana/grafana", + "revision": "6e7910d2d0b3f3ce893161fcc82e468756f2ae79fe3d28ecfe1f08bd5cc21c5c", + "image_repository_url": "https://hub.docker.com/r/grafana/grafana", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "6e7910d2d0b3f3ce893161fcc82e468756f2ae79fe3d28ecfe1f08bd5cc21c5c", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "grafana", + "container_name": "grafana", + "image": { + "reference": "grafana/grafana:latest", + "registry": "docker.io", + "repository": "grafana/grafana", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/lib/grafana", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3003, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: grafana\nservices:\n grafana:\n image: grafana/grafana:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 3000\n published: '3003'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /var/lib/grafana\n container_name: grafana\n" + }, + "compose_stack": { + "project_name": "grafana", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "grafana", + "service_count": 1, + "services": [ + { + "name": "grafana", + "image": "grafana/grafana:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "grafana/grafana:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 3000, + "published": "3003", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/var/lib/grafana" + } + ], + "container_name": "grafana" + } + } + ], + "top_level": { + "name": "grafana" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "grafana-volume-0", + "service": "grafana", + "container_path": "/var/lib/grafana", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "grafana" + ], + "stop_order": [ + "grafana" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/grav.json b/oci/catalog/apps/grav.json new file mode 100644 index 00000000..a7b6e8e6 --- /dev/null +++ b/oci/catalog/apps/grav.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-grav", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Grav" + }, + "tagline": { + "en_US": "Grav is a Fast, Simple, and Flexible, file-based Web-platform." + }, + "description": { + "en_US": "Grav is a Fast, Simple, and Flexible, file-based Web-platform." + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/grav-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/grav-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/getgrav/grav/", + "documentation": "https://docs.linuxserver.io/images/docker-grav/", + "repository": "https://github.com/linuxserver/docker-grav", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-27", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-10-11", + "note": "Add php83-pdo and php83-pdo_sqlite" + }, + { + "date": "2024-06-19", + "note": "Rebase to Alpine 3.20. Symlink robots.txt to /config. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-03-06", + "note": "Add brotli to nginx." + }, + { + "date": "2024-03-06", + "note": "Existing users should update: site-confs/default.conf - Cleanup default site conf." + } + ], + "display_version": null, + "updated_at": "2026-06-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-grav", + "default_branch": "main", + "revision": "bf49b9a2c0b9f2ddbeb3c05011f2510813fd8ad0", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-grav/bf49b9a2c0b9f2ddbeb3c05011f2510813fd8ad0/README.md", + "readme_pushed_at": "2026-09-11T22:39:56Z", + "compose_sha256": "6875c97bcd30bc0e0ddd0df1c1e10d3d0ec43165e649ae464d091fa81dc67631", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "grav", + "container_name": "grav", + "image": { + "reference": "lscr.io/linuxserver/grav:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/grav", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/grav/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n grav:\n image: lscr.io/linuxserver/grav:latest\n container_name: grav\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/grav/config:/config\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/grocy.json b/oci/catalog/apps/grocy.json new file mode 100644 index 00000000..dcdafd66 --- /dev/null +++ b/oci/catalog/apps/grocy.json @@ -0,0 +1,250 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-grocy", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Grocy" + }, + "tagline": { + "en_US": "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility." + }, + "description": { + "en_US": "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility." + }, + "category": "gaming", + "category_label": "Gaming & Leisure", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/grocy-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/grocy-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/grocy/grocy", + "documentation": "https://docs.linuxserver.io/images/docker-grocy/", + "repository": "https://github.com/linuxserver/docker-grocy", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-07", + "note": "Rebase to Alpine 3.23 with php 8.5." + }, + { + "date": "2024-05-02", + "note": "Rebase to Alpine 3.21. Add php-opcache package." + }, + { + "date": "2024-06-30", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-03-29", + "note": "Add `clear_env = no` to `php-fpm` to pass on environment variables to workers threads" + }, + { + "date": "2024-03-06", + "note": "Existing users should update: site-confs/default.conf - Cleanup default site conf." + } + ], + "display_version": null, + "updated_at": "2026-03-07" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-grocy", + "default_branch": "master", + "revision": "8b5b1f80ee608a5055d256d7da00d1a69db7a718", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-grocy/8b5b1f80ee608a5055d256d7da00d1a69db7a718/README.md", + "readme_pushed_at": "2026-09-06T11:57:02Z", + "compose_sha256": "e819d919e4cdffc2080d084c87e4ba90c43f93967d3f194dcc793c6d8e775b9e", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "grocy", + "container_name": "grocy", + "image": { + "reference": "lscr.io/linuxserver/grocy:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/grocy", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/grocy/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 9283, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n grocy:\n image: lscr.io/linuxserver/grocy:latest\n container_name: grocy\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/grocy/config:/config\n ports:\n - 9283:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [ + { + "label": "Grocy (new installation; restored data keeps its credentials)", + "type": "static-default", + "username": "admin", + "password": "admin", + "change_required": true, + "source": "https://docs.linuxserver.io/images/docker-grocy/" + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/gzdoom.json b/oci/catalog/apps/gzdoom.json new file mode 100644 index 00000000..a326b190 --- /dev/null +++ b/oci/catalog/apps/gzdoom.json @@ -0,0 +1,269 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-gzdoom", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Gzdoom" + }, + "tagline": { + "en_US": "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities." + }, + "description": { + "en_US": "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gzdoom-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gzdoom-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://gzdoom.app/", + "documentation": "https://docs.linuxserver.io/images/docker-gzdoom/", + "repository": "https://github.com/linuxserver/docker-gzdoom", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to resolute." + }, + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-04", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-gzdoom", + "default_branch": "master", + "revision": "5780855a0bc5f94d8c846224661681ac9613c974", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-gzdoom/5780855a0bc5f94d8c846224661681ac9613c974/README.md", + "readme_pushed_at": "2026-09-08T00:15:20Z", + "compose_sha256": "92b5ca7fb84ae295a45df86df5317b6d70840756e934d1a5e89ad89cac321373", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "gzdoom", + "container_name": "gzdoom", + "image": { + "reference": "lscr.io/linuxserver/gzdoom:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/gzdoom", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n gzdoom:\n image: lscr.io/linuxserver/gzdoom:latest\n container_name: gzdoom\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/habridge.json b/oci/catalog/apps/habridge.json new file mode 100644 index 00000000..254849d6 --- /dev/null +++ b/oci/catalog/apps/habridge.json @@ -0,0 +1,255 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-habridge", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Habridge" + }, + "tagline": { + "en_US": "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API." + }, + "description": { + "en_US": "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/habridge-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/habridge-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://github.com/bwssytems/ha-bridge/", + "documentation": "https://docs.linuxserver.io/images/docker-habridge/", + "repository": "https://github.com/linuxserver/docker-habridge", + "tips": [], + "mini_changelog": [ + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-04-10", + "note": "Revert JRE to 8 due to incomplete upstream support." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19, bump JRE to 17." + }, + { + "date": "2023-08-25", + "note": "Rebase to Alpine 3.18." + }, + { + "date": "2023-07-07", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + } + ], + "display_version": null, + "updated_at": "2024-06-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-habridge", + "default_branch": "master", + "revision": "e6eac399858c2e31bcfb2a9e9a9209869ed32016", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-habridge/e6eac399858c2e31bcfb2a9e9a9209869ed32016/README.md", + "readme_pushed_at": "2026-07-03T23:18:53Z", + "compose_sha256": "274d98ff5d8cd7d828298bfed8677a33f8edd081ed54ac89d68f4e3565c6e1eb", + "generated_at": "2026-09-12T14:37:27+00:00" + }, + "container_contract": { + "service_name": "habridge", + "container_name": "habridge", + "image": { + "reference": "lscr.io/linuxserver/habridge:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/habridge", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SEC_KEY", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/habridge/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 50000, + "published_example": 50000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n habridge:\n image: lscr.io/linuxserver/habridge:latest\n container_name: habridge\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - SEC_KEY=\n volumes:\n - /path/to/habridge/config:/config\n ports:\n - 8080:8080\n - 50000:50000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/handbrake-jlesage.json b/oci/catalog/apps/handbrake-jlesage.json new file mode 100644 index 00000000..5db31309 --- /dev/null +++ b/oci/catalog/apps/handbrake-jlesage.json @@ -0,0 +1,610 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-handbrake-jlesage", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "handbrake" + }, + "tagline": { + "en_US": "Liberate your videos and unleash infinite possibilities." + }, + "description": { + "en_US": "Handbrake is a Docker-based application for video transcoding and compression, offering powerful and flexible multimedia processing across multiple platforms." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "jlesage", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 5800, + "path": "/" + }, + "website": "https://handbrake.fr", + "documentation": null, + "repository": "https://hub.docker.com/r/jlesage/handbrake", + "tips": [ + "Intel/AMD acceleration is enabled by passing /dev/dri to the LXC; it does not require making the LXC privileged.", + "The privileged request from the imported Compose is discarded because it is not part of the official jlesage/handbrake requirements." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "jlesage", + "repository": "https://hub.docker.com/r/jlesage/handbrake", + "revision": "16641c6e75b4558a7c76f4e68d8fa5e4d6088effc308a5b7c31ce2a217ed24f4", + "image_repository_url": "https://hub.docker.com/r/jlesage/handbrake", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "16641c6e75b4558a7c76f4e68d8fa5e4d6088effc308a5b7c31ce2a217ed24f4", + "generated_at": "2026-09-13T21:01:15+00:00" + }, + "container_contract": { + "service_name": "handbrake", + "container_name": "handbrake", + "image": { + "reference": "jlesage/handbrake:latest", + "registry": "docker.io", + "repository": "jlesage/handbrake", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USER_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "jlesage-documentation" + }, + { + "name": "GROUP_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "jlesage-documentation" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "jlesage-documentation" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/storage", + "compose_source_example": "/DATA", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/watch", + "compose_source_example": "/DATA/AppData/$AppID/watch", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/output", + "compose_source_example": "/DATA/Media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 5800, + "published_example": 5800, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: handbrake\nservices:\n handbrake:\n image: jlesage/handbrake:latest\n network_mode: bridge\n ports:\n - target: 5800\n published: '5800'\n protocol: tcp\n privileged: true\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA\n target: /storage\n - type: bind\n source: /DATA/AppData/$AppID/watch\n target: /watch\n - type: bind\n source: /DATA/Media\n target: /output\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n container_name: handbrake\n" + }, + "compose_stack": { + "project_name": "handbrake", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "handbrake", + "service_count": 1, + "services": [ + { + "name": "handbrake", + "image": "jlesage/handbrake:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/handbrake:latest", + "network_mode": "bridge", + "ports": [ + { + "target": 5800, + "published": "5800", + "protocol": "tcp" + } + ], + "privileged": true, + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA", + "target": "/storage" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/watch", + "target": "/watch" + }, + { + "type": "bind", + "source": "/DATA/Media", + "target": "/output" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + } + ], + "container_name": "handbrake" + } + } + ], + "top_level": { + "name": "handbrake" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "handbrake-volume-0", + "service": "handbrake", + "container_path": "/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "handbrake-volume-1", + "service": "handbrake", + "container_path": "/watch", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "handbrake-volume-2", + "service": "handbrake", + "container_path": "/output", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "handbrake-volume-3", + "service": "handbrake", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "handbrake" + ], + "stop_order": [ + "handbrake" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5800, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "enable_prompt": "Enable Intel/AMD VA-API video acceleration", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/dri/renderD128:/dev/dri/renderD128", + "append_host_device_gid_to_environment": "SUP_GROUP_IDS" + } + ], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/storage", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/watch", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/output", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 5800, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "optional-explicit-user-consent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/handbrake.json b/oci/catalog/apps/handbrake.json new file mode 100644 index 00000000..65c59b84 --- /dev/null +++ b/oci/catalog/apps/handbrake.json @@ -0,0 +1,392 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-handbrake", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Handbrake" + }, + "tagline": { + "en_US": "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs." + }, + "description": { + "en_US": "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/handbrake-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/handbrake-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://handbrake.fr/", + "documentation": "https://docs.linuxserver.io/images/docker-handbrake/", + "repository": "https://github.com/linuxserver/docker-handbrake", + "tips": [ + "The managed /config volume is prepared with the configured PUID/PGID before LinuxServer starts.", + "The installer verifies the HTTPS WebUI on port 3001 before reporting success." + ], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-18", + "note": "Add intel media libs." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-11-29", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-handbrake", + "default_branch": "master", + "revision": "f4d1e6ae575a4b2ffc35b3eba0db3027cbbfcae8", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-handbrake/f4d1e6ae575a4b2ffc35b3eba0db3027cbbfcae8/README.md", + "readme_pushed_at": "2026-09-10T14:49:26Z", + "compose_sha256": "595ac1e336aa6b9f0b2d14a7eb6c2146ce0e1e8e5c146977970036b88ab624d1", + "generated_at": "2026-09-13T21:01:15+00:00" + }, + "container_contract": { + "service_name": "handbrake", + "container_name": "handbrake", + "image": { + "reference": "lscr.io/linuxserver/handbrake:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/handbrake", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n handbrake:\n image: lscr.io/linuxserver/handbrake:latest\n container_name: handbrake\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "startup_healthcheck": { + "scheme": "https", + "port": 3001, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/haos-one.json b/oci/catalog/apps/haos-one.json new file mode 100644 index 00000000..bde76045 --- /dev/null +++ b/oci/catalog/apps/haos-one.json @@ -0,0 +1,754 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-haos-one", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "HAOS One" + }, + "tagline": { + "en_US": "Community single-container Home Assistant OS image" + }, + "description": { + "en_US": "Community HAOS One image adapted as a native Proxmox OCI LXC with persistent Supervisor, Core, add-ons and backups under /mnt/data." + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "qweritos", + "developer": "qweritos", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/qweritos/haos-one", + "documentation": "https://github.com/qweritos/haos-one#readme", + "repository": "https://github.com/qweritos/haos-one", + "tips": [ + "This is a third-party community image and is not affiliated with Home Assistant.", + "The validated profile uses a managed /mnt/data volume; preserve it during every image replacement.", + "Port 80 is used by current Core releases in the validated profile; port 8123 may appear during setup or on older releases.", + "Experimental unprivileged profile with nesting and keyctl. Internal AppArmor profiles may not be available.", + "The first start downloads internal images. Success is confirmed only with Supervisor healthy/supported and a real Core, internal services and Observer running.", + "The web port is detected between 80 and 8123. If the check fails, the CT, data and log are kept for diagnosis; success is not confirmed.", + "/mnt/data: Proxmox volume of 32 GB by default, minimum 16 GB, included in backup. Full restore and external image update pending testing." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-20" + }, + "source": { + "provider": "qweritos", + "repository": "https://github.com/qweritos/haos-one", + "revision": "b6dd721c4bf06e6f90ee1f8099a82b892e18af64a63015fe5fdfbfd02d538ede", + "image_repository_url": "https://hub.docker.com/r/qweritos/haos-one", + "readme_pushed_at": "2026-08-20T12:29:50Z", + "compose_sha256": "b6dd721c4bf06e6f90ee1f8099a82b892e18af64a63015fe5fdfbfd02d538ede", + "generated_at": "2026-09-12T15:54:10+00:00", + "default_branch": "master" + }, + "container_contract": { + "service_name": "haos-one", + "container_name": "haos-one", + "image": { + "reference": "qweritos/haos-one:latest", + "registry": "docker.io", + "repository": "qweritos/haos-one", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USE_DUMMY_NETWORKMANAGER", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "USE_UDEV_SHIM", + "example": "auto", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "DEV", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/mnt/data", + "compose_source_example": "haos-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4357, + "published_example": 4357, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": null, + "stop_grace_period": null, + "original_compose": "name: haos-one\nservices:\n haos-one:\n image: qweritos/haos-one:latest\n privileged: true\n environment:\n USE_DUMMY_NETWORKMANAGER: '1'\n USE_UDEV_SHIM: auto\n DEV: '0'\n ports:\n - 80:80\n - 4357:4357\n volumes:\n - haos-data:/mnt/data\n stop_signal: SIGRTMIN+3\nvolumes:\n haos-data: {}\n" + }, + "compose_stack": { + "project_name": "haos-one", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "haos-one", + "service_count": 1, + "services": [ + { + "name": "haos-one", + "image": "qweritos/haos-one:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "qweritos/haos-one:latest", + "privileged": true, + "environment": { + "USE_DUMMY_NETWORKMANAGER": "1", + "USE_UDEV_SHIM": "auto", + "DEV": "0" + }, + "ports": [ + "80:80", + "4357:4357" + ], + "volumes": [ + "haos-data:/mnt/data" + ], + "stop_signal": "SIGRTMIN+3" + } + } + ], + "top_level": { + "name": "haos-one", + "volumes": { + "haos-data": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "haos-one-volume-0", + "service": "haos-one", + "container_path": "/mnt/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "haos-one" + ], + "stop_order": [ + "haos-one" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Home Assistant", + "scheme": "http", + "port": 80, + "path": "/", + "source": "validated-current-core-profile" + }, + { + "label": "Home Assistant Observer", + "scheme": "http", + "port": 4357, + "path": "/", + "source": "haos-one-runtime" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": true, + "ostype": "unmanaged", + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 16, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1", + "keyctl=1" + ], + "shutdown_timeout_seconds": 60 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-user-values", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "haos-ostype-unmanaged", + "upstream_behavior": "The image identifies itself with ID=haos.", + "native_lxc_behavior": "Create the OCI LXC with ostype=unmanaged.", + "reason": "Proxmox VE 9.2 cannot auto-detect the HAOS distribution identifier during OCI import.", + "behavioral_impact": "No application behavior is changed; Proxmox skips distribution-specific guest setup.", + "validation": "passed-clean-oci-import" + }, + { + "id": "nested-runtime-features", + "upstream_behavior": "haos-one starts systemd, Docker, Supervisor and nested Home Assistant containers.", + "native_lxc_behavior": "Use an unprivileged LXC with nesting=1 and keyctl=1.", + "reason": "The inner Docker and containerd runtime require nested namespaces and keyring support.", + "behavioral_impact": "The LXC remains unprivileged; no AppArmor unconfined override was required.", + "validation": "passed-all-inner-containers-running" + }, + { + "id": "managed-data-volume", + "upstream_behavior": "The image declares /mnt/data as its persistent Docker volume.", + "native_lxc_behavior": "Attach a storage-backed Proxmox mp0 at the same /mnt/data path with backup=1.", + "reason": "Preserves the official data path and includes private state in native Proxmox backups.", + "behavioral_impact": "No path translation; data survives LXC restart independently of the OCI rootfs.", + "validation": "passed-restart-marker-and-service-restoration" + }, + { + "id": "current-image-compat-proxy", + "upstream_behavior": "The current project proxy removes Domainname and HostConfig.Ulimits from nested Docker create requests.", + "native_lxc_behavior": "Use an upstream image digest that contains rewrite_create_request_payload; do not patch files locally.", + "reason": "Older builds fail to start Core and plug-ins with kernel.domainname permission denied.", + "behavioral_impact": "Uses the project-provided compatibility behavior unchanged.", + "validation": "passed-source-revision-5bffb27-and-runtime" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.2", + "validated_proxmox_version": "9.2.11", + "commands": [ + "pct", + "pvesm", + "skopeo", + "curl", + "jq" + ], + "features": [ + "native-oci-lxc", + "nested-container-runtime", + "managed-volume-backup", + "host-managed-network" + ], + "minimum_resources": { + "cores": 2, + "memory_mb": 2048, + "rootfs_size_gb": 12, + "data_size_gb": 16 + }, + "recommended_resources": { + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 16, + "data_size_gb": 32 + } + }, + "upstream_contract": { + "entrypoint": [ + "/entrypoint.sh" + ], + "command": [ + "/sbin/init" + ], + "working_directory": "/", + "declared_volume": "/mnt/data", + "declared_port": 8123, + "stop_signal": "SIGRTMIN+3", + "environment_defaults": { + "USE_DUMMY_NETWORKMANAGER": "1", + "USE_UDEV_SHIM": "auto", + "SETUP_PORT": null, + "DEV": "0" + }, + "preserve_without_override": [ + "entrypoint", + "command", + "container-path-/mnt/data", + "stop-signal", + "compatibility-shim" + ] + }, + "configuration_schema": { + "vmid": { + "type": "integer", + "required": false, + "default": null + }, + "hostname": { + "type": "string", + "required": true, + "default": "haos-one", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,62}$" + } + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ] + }, + "data_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "description": "Volumen administrado por Proxmox montado en /mnt/data y protegido con backup=1." + }, + "data_size_gb": { + "type": "integer", + "required": true, + "default": 32, + "minimum": 16 + }, + "bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "ipv4": { + "type": "ipv4-address-or-dhcp", + "required": true, + "default": "dhcp" + }, + "gateway": { + "type": "ipv4-address", + "required": false, + "default": null + }, + "dns_server": { + "type": "ipv4-address", + "required": false, + "default": null + }, + "usb_devices": { + "type": "device-list", + "required": false, + "default": [], + "description": "Optional passthrough of Zigbee, Z-Wave, Bluetooth or other coordinators; not validated in this profile." + } + }, + "deployment": { + "runtime": "proxmox-native-oci-lxc", + "ostype": "unmanaged", + "unprivileged": true, + "entrypoint": "/entrypoint.sh /sbin/init", + "entrypoint_source": "imported-from-oci-image-config", + "entrypoint_override": false, + "features": [ + "nesting=1", + "keyctl=1" + ], + "apparmor_profile_override": false, + "preserve_image_environment": true, + "managed_network": true, + "mounts": [ + { + "type": "proxmox-managed-volume", + "container_path": "/mnt/data", + "size_gb": 32, + "read_only": false, + "backup": true, + "purpose": "Supervisor, Home Assistant Core, add-ons, secrets, databases, Docker images and runtime state" + } + ], + "ports": [ + { + "port": 80, + "protocol": "tcp", + "purpose": "validated-home-assistant-web-for-core-2026.9.1" + }, + { + "port": 4357, + "protocol": "tcp", + "purpose": "home-assistant-observer" + } + ], + "conditional_ports": [ + { + "port": 8123, + "protocol": "tcp", + "condition": "older-core-or-landing-page-stage-or-explicit-SETUP_PORT", + "warning": "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer." + } + ] + }, + "persistence": { + "authoritative_path": "/mnt/data", + "storage_type": "proxmox-managed-volume", + "backup_flag": 1, + "included_content": [ + "/mnt/data/supervisor", + "/mnt/data/supervisor/homeassistant", + "/mnt/data/supervisor/apps", + "/mnt/data/supervisor/app_configs", + "/mnt/data/supervisor/backup", + "/mnt/data/supervisor/share", + "/mnt/data/supervisor/ssl", + "/mnt/data/docker", + "/mnt/data/bluetooth" + ], + "rootfs_role": "replaceable-image-runtime", + "data_role": "persistent-user-and-supervisor-state", + "restart_test": { + "status": "passed", + "method": "write-marker-shutdown-start-verify-hash-and-services", + "marker_sha256": "6c3762cede4f86dd5eeae16eff1067e188e9b47646f48ccc268c077711bffbd0", + "volume_before": "local-lvm:vm-128-disk-1", + "volume_after": "local-lvm:vm-128-disk-1", + "home_assistant_after_restart": "passed-http-200", + "inner_containers_after_restart": "passed-all-running" + }, + "native_backup": { + "expected": "included-by-mp0-backup-1", + "full-vzdump-restore-test": "pending" + } + }, + "installation_steps": [ + "Resolve the selected tag to an architecture-specific immutable digest.", + "Copy the pinned image to an OCI archive with skopeo.", + "Verify the OCI Entrypoint, Cmd, volume declaration and stop signal.", + "Create an unprivileged LXC with ostype=unmanaged, nesting=1 and keyctl=1.", + "Create a Proxmox-managed volume with backup=1 at /mnt/data.", + "Attach a host-managed network interface to the selected bridge.", + "Preserve the imported /entrypoint.sh /sbin/init command and SIGRTMIN+3 stop signal.", + "Start the LXC and allow several minutes for the first pull of Supervisor, Core and plug-ins.", + "Discover the assigned address and probe both port 80 and port 8123.", + "Require Supervisor healthy=true and supported=true before reporting success.", + "Verify Core, CLI, DNS, audio, multicast and observer containers are running.", + "Report non-blocking HAOS resolution issues separately." + ], + "healthchecks": [ + { + "name": "home-assistant-web", + "type": "http", + "candidate_urls": [ + "http://${container_ip}/", + "http://${container_ip}:8123/" + ], + "expected_status": 200, + "startup_grace_seconds": 300 + }, + { + "name": "observer", + "type": "http", + "url": "http://${container_ip}:4357/", + "expected_status": 200 + }, + { + "name": "supervisor", + "type": "ha-cli", + "command": "docker -H unix:///run/docker-real.sock exec hassio_cli ha supervisor info", + "required_fields": { + "healthy": true, + "supported": true + } + } + ], + "update_strategy": { + "core_supervisor_and_addons": "managed-by-home-assistant-supervisor", + "outer_oci_image": "resolve-new-image-and-replace-rootfs-while-preserving-/mnt/data", + "outer_oci_update_validation": "pending", + "required_before_update": [ + "create-and-download-a-full-home-assistant-backup", + "create-a-native-proxmox-backup-including-mp0", + "record-current-image-digest", + "verify-new-image-contains-required-compatibility-rules" + ], + "warning": "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume." + }, + "security": { + "image_is_official_home_assistant": false, + "outer_lxc_unprivileged": true, + "nested_docker": true, + "apparmor_profiles_inside_haos": "cannot-load-in-current-lxc-profile", + "supervisor_health_despite_apparmor_warning": "healthy-and-supported", + "risk_notes": [ + "The image is maintained by a third party and is not affiliated with Home Assistant.", + "Nested containers increase complexity and expand the runtime attack surface compared with a normal single-process OCI image.", + "HAOS AppArmor profiles cannot be loaded inside this unprivileged LXC, reducing inner add-on confinement.", + "Protect /mnt/data because it contains credentials, secrets, databases and backups.", + "Do not expose Home Assistant or Observer directly to the Internet without an authenticated reverse proxy and normal Home Assistant hardening." + ] + }, + "incompatible_builds": [ + { + "reference": "docker.io/qweritos/haos-one:18.1-amd64", + "digest": "sha256:164d579522da0875c3eaa64283c5f7b875afae2013f1b878c86f80c1eac286af", + "status": "failed-native-unprivileged-oci", + "reason": "The bundled compatibility proxy does not rewrite nested container create requests, causing kernel.domainname permission denied for Core and plug-ins.", + "do_not_use_for_this_profile": true + } + ], + "notes": [ + "HAOS One is a community image, not an official Home Assistant image.", + "This is not a simple Home Assistant container: the outer OCI runs systemd, Docker, Supervisor, Core and add-ons.", + "The direct Proxmox OCI path removes one extra Docker layer compared with the upstream-tested Proxmox LXC plus Docker plus haos-one deployment.", + "Proxmox privileged OCI import failed with setgid(0) Invalid argument; the validated profile is unprivileged and functional.", + "Proxmox must use ostype=unmanaged because ID=haos is not recognized by guest distribution detection.", + "The official /mnt/data path is a Proxmox-managed volume with backup=1, not a shared host bind.", + "A clean first boot used approximately 8.6G under /mnt/data after Core and Matter installation; 32G is the recommended starting size.", + "Home Assistant Core 2026.9.1 listens on port 80 in this image. Port 8123 was present only during the landing-page stage and must not be hard-coded.", + "Supervisor reports healthy=true and supported=true even though several host-oriented HAOS units cannot run inside LXC.", + "AppArmor profile loading inside HAOS fails in the current unprivileged LXC; this is a security limitation and must remain visible to users.", + "The current tag 18 works because it includes the upstream Docker API create-request rewrite; tag 18.1-amd64 does not.", + "Mutable tags must be resolved to an immutable architecture-specific digest before installation.", + "Restart persistence is validated. Full vzdump restore, outer OCI image replacement, USB passthrough and real multicast discovery remain pending." + ], + "references": { + "project": "https://github.com/qweritos/haos-one", + "docker_image": "https://hub.docker.com/r/qweritos/haos-one", + "dockerfile": "https://github.com/qweritos/haos-one/blob/master/Dockerfile", + "compatibility_documentation": "https://github.com/qweritos/haos-one/blob/master/docs/haos-one-compat.md", + "home_assistant_os_releases": "https://github.com/home-assistant/operating-system/releases", + "proxmox_pct_manual": "https://pve.proxmox.com/pve-docs/pct.1.html" + } + }, + "installer_profile": { + "haos_healthcheck": { + "timeout_seconds": 1200 + }, + "volume_preparations": [ + { + "container_path": "/mnt/data", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "Native laboratory adaptations implemented. Rolling latest first boot, backup restore and outer-image upgrades still require runtime validation." + }, + "validation": { + "schema": "passed-at-generation", + "validated_architecture": "amd64", + "arm64": "supported-upstream-not-yet-validated-in-proxmenux-laboratory", + "validated_profile": { + "id": "pve55-haos-one-native-oci", + "validated_on": "2026-09-08", + "validation_status": "passed-functional-restart-persistence-with-known-nonblocking-issues", + "proxmox_version": "9.2.11", + "container_id": 128, + "haos_version": "18.2", + "home_assistant_core": "2026.9.1", + "supervisor": "2026.09.0", + "matter_server": "9.2.0", + "resources": { + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs": "local-lvm:16G", + "data": "local-lvm:32G,mp=/mnt/data,backup=1" + }, + "observed_after_first_boot": { + "data_used": "approximately-8.6G", + "memory_used_bytes": 1368289280, + "rootfs_used_bytes": 624910336 + }, + "validation": { + "oci_import": "passed-with-ostype-unmanaged", + "image_entrypoint": "passed-/entrypoint.sh-/sbin/init", + "halt_signal": "passed-SIGRTMIN+3", + "nested_docker": "passed-overlayfs", + "compatibility_proxy": "passed", + "home_assistant_web": "passed-http-200-port-80", + "observer": "passed-http-200-port-4357", + "supervisor_healthy": true, + "supervisor_supported": true, + "core_running": true, + "plugins_running": true, + "matter_addon_running": true, + "restart_persistence": "passed", + "native_volume_backup_flag": "passed-mp0-backup-1", + "full_vzdump_restore": "pending", + "outer_image_upgrade": "pending", + "usb_passthrough": "pending", + "multicast_discovery": "pending-functional-device-test" + }, + "known_nonblocking_resolution_issues": [ + "haos-mglru.service-failed", + "auditd.service-failed", + "sys-kernel-config.mount-failed", + "sys-kernel-debug.mount-failed", + "dummy-networkmanager-may-report-ipv4-or-dns-diagnostics" + ] + }, + "source_profile": "haos-one-oci.json", + "service_health": "passed-observed-2026-09-14", + "restart_persistence": "passed-2026-09-14", + "backup_restore": "pending", + "update_preserves_data": "pending", + "latest_runtime_observation": { + "date": "2026-09-14", + "vmid": 100, + "architecture": "amd64", + "proxmox": "9.2.18", + "kernel": "7.0.14-16-pve", + "core_version": "2026.9.2", + "supervisor_version": "2026.09.0", + "image_reference": "qweritos/haos-one:latest", + "outer_image_digest_verified": false, + "supervisor_healthy": true, + "supervisor_supported": true, + "required_internal_containers_running": true, + "matter_server_healthy_after_restart": true, + "restart_method": "pct shutdown --timeout 90; pct start", + "managed_data_volume_unchanged": true, + "data_volume_gb": 32, + "data_volume_backup_flag": true, + "configuration_yaml_sha256_unchanged": true, + "temporary_marker_sha256_unchanged": true, + "temporary_marker_removed": true, + "core_http_port": 80, + "observer_http_port": 4357, + "lan_address_unchanged": true, + "limitations": [ + "Supervisor AppArmor profile could not be loaded inside this LXC.", + "Host kernel config/debug mounts, auditd and MGLRU units fail in this LXC.", + "PulseAudio warning appeared during boot; hassio_audio subsequently running, audio functionality not tested.", + "Core translation-domain warnings observed; no functionality test of associated integrations.", + "Full vzdump restore and outer OCI image replacement remain untested." + ] + } + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-and-replace-rootfs-preserving-managed-/mnt/data", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false, + "validated_workflows": { + "core_supervisor_and_addons": "managed-by-home-assistant-supervisor", + "outer_oci_image": "resolve-new-image-and-replace-rootfs-while-preserving-/mnt/data", + "outer_oci_update_validation": "pending", + "required_before_update": [ + "create-and-download-a-full-home-assistant-backup", + "create-a-native-proxmox-backup-including-mp0", + "record-current-image-digest", + "verify-new-image-contains-required-compatibility-rules" + ], + "warning": "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume." + } + } +} diff --git a/oci/catalog/apps/healthchecks.json b/oci/catalog/apps/healthchecks.json new file mode 100644 index 00000000..4993931f --- /dev/null +++ b/oci/catalog/apps/healthchecks.json @@ -0,0 +1,381 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-healthchecks", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Healthchecks" + }, + "tagline": { + "en_US": "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface." + }, + "description": { + "en_US": "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface." + }, + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/healthchecks-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/healthchecks-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://github.com/healthchecks/healthchecks", + "documentation": "https://docs.linuxserver.io/images/docker-healthchecks/", + "repository": "https://github.com/linuxserver/docker-healthchecks", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-20", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-08-31", + "note": "Enable IPv6 on uwsgi." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-healthchecks", + "default_branch": "master", + "revision": "cd5aca44b81bea4a20e23fd3e0883c09f4862611", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-healthchecks/cd5aca44b81bea4a20e23fd3e0883c09f4862611/README.md", + "readme_pushed_at": "2026-09-07T14:43:58Z", + "compose_sha256": "15cc2f4d1c28488e710d8185ac2a8dc76d2aaa53df7955ef28afc1e405321b72", + "generated_at": "2026-09-12T14:37:28+00:00" + }, + "container_contract": { + "service_name": "healthchecks", + "container_name": "healthchecks", + "image": { + "reference": "lscr.io/linuxserver/healthchecks:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/healthchecks", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SECRET_KEY", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SITE_ROOT", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SITE_NAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SUPERUSER_EMAIL", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SUPERUSER_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "ALLOWED_HOSTS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APPRISE_ENABLED", + "example": "False", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CSRF_TRUSTED_ORIGINS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEBUG", + "example": "True", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEFAULT_FROM_EMAIL", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EMAIL_HOST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EMAIL_PORT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EMAIL_HOST_USER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EMAIL_HOST_PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "EMAIL_USE_TLS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "INTEGRATIONS_ALLOW_PRIVATE_IPS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PING_EMAIL_DOMAIN", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RP_ID", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SITE_LOGO_URL", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/healthchecks/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 2525, + "published_example": 2525, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n healthchecks:\n image: lscr.io/linuxserver/healthchecks:latest\n container_name: healthchecks\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - SECRET_KEY=\n - SITE_ROOT=\n - SITE_NAME=\n - SUPERUSER_EMAIL=\n - SUPERUSER_PASSWORD=\n - ALLOWED_HOSTS= #optional\n - APPRISE_ENABLED=False #optional\n - CSRF_TRUSTED_ORIGINS= #optional\n - DEBUG=True #optional\n - DEFAULT_FROM_EMAIL= #optional\n - EMAIL_HOST= #optional\n - EMAIL_PORT= #optional\n - EMAIL_HOST_USER= #optional\n - EMAIL_HOST_PASSWORD= #optional\n - EMAIL_USE_TLS= #optional\n - INTEGRATIONS_ALLOW_PRIVATE_IPS= #optional\n - PING_EMAIL_DOMAIN= #optional\n - RP_ID= #optional\n - SITE_LOGO_URL= #optional\n volumes:\n - /path/to/healthchecks/config:/config\n ports:\n - 8000:8000\n - 2525:2525 #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/hedgedoc.json b/oci/catalog/apps/hedgedoc.json new file mode 100644 index 00000000..2cc2e026 --- /dev/null +++ b/oci/catalog/apps/hedgedoc.json @@ -0,0 +1,318 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-hedgedoc", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Hedgedoc" + }, + "tagline": { + "en_US": "HedgeDoc gives you access to all your files wherever you are." + }, + "description": { + "en_US": "HedgeDoc gives you access to all your files wherever you are." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/hedgedoc-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/hedgedoc-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://hedgedoc.org/", + "documentation": "https://docs.linuxserver.io/images/docker-hedgedoc/", + "repository": "https://github.com/linuxserver/docker-hedgedoc", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-29", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-10-14", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-02-24", + "note": "Add missing icu-data-full to fix bug with TextDecoder and image uploads." + }, + { + "date": "2024-06-21", + "note": "Allow using `CMD_DB_DIALECT` to set up the `CMD_DB_URL`." + }, + { + "date": "2024-06-06", + "note": "Rebase to Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-hedgedoc", + "default_branch": "main", + "revision": "bf9e30951c1cb19c98fa14ffa4dfb700d6cd4ee4", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-hedgedoc/bf9e30951c1cb19c98fa14ffa4dfb700d6cd4ee4/README.md", + "readme_pushed_at": "2026-09-09T22:04:01Z", + "compose_sha256": "ae0fb91f8b7b063ed1b442971df383903f452b6c85337717fdc5f88cf6a77e75", + "generated_at": "2026-09-12T14:37:28+00:00" + }, + "container_contract": { + "service_name": "hedgedoc", + "container_name": "hedgedoc", + "image": { + "reference": "lscr.io/linuxserver/hedgedoc:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/hedgedoc", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "3306", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USER", + "example": "hedgedoc", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASS", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_NAME", + "example": "hedgedoc", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CMD_DOMAIN", + "example": "localhost", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CMD_URL_ADDPORT", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CMD_PROTOCOL_USESSL", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CMD_PORT", + "example": "3000", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CMD_ALLOW_ORIGIN", + "example": "['localhost']", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CMD_DB_DIALECT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/hedgedoc/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n hedgedoc:\n image: lscr.io/linuxserver/hedgedoc:latest\n container_name: hedgedoc\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - \"DB_HOST=\"\n - DB_PORT=3306\n - DB_USER=hedgedoc\n - \"DB_PASS=\"\n - DB_NAME=hedgedoc\n - CMD_DOMAIN=localhost\n - CMD_URL_ADDPORT=false #optional\n - CMD_PROTOCOL_USESSL=false #optional\n - CMD_PORT=3000 #optional\n - CMD_ALLOW_ORIGIN=['localhost'] #optional\n - CMD_DB_DIALECT= #optional\n volumes:\n - /path/to/hedgedoc/config:/config\n ports:\n - 3000:3000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/heimdall.json b/oci/catalog/apps/heimdall.json new file mode 100644 index 00000000..f6896bca --- /dev/null +++ b/oci/catalog/apps/heimdall.json @@ -0,0 +1,255 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-heimdall", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Heimdall" + }, + "tagline": { + "en_US": "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way." + }, + "description": { + "en_US": "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/heimdall-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/heimdall-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://heimdall.site", + "documentation": "https://docs.linuxserver.io/images/docker-heimdall/", + "repository": "https://github.com/linuxserver/docker-heimdall", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-14", + "note": "Rebase to Alpine 3.24" + }, + { + "date": "2025-07-20", + "note": "Rebase to Alpine 3.22, enable PHP environment passthrough." + }, + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-03-07", + "note": "Enable the opcache and disable file revalidation." + }, + { + "date": "2024-03-06", + "note": "Existing users should update: site-confs/default.conf - Cleanup default site conf." + } + ], + "display_version": null, + "updated_at": "2026-07-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-heimdall", + "default_branch": "master", + "revision": "eb392755e9e86791d0c26c0de152790f95275697", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-heimdall/eb392755e9e86791d0c26c0de152790f95275697/README.md", + "readme_pushed_at": "2026-09-11T21:14:01Z", + "compose_sha256": "d77430c996bc3add2e19fde8c84163fd98f1a55bb1ab4b4588e46ea4128821db", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "heimdall", + "container_name": "heimdall", + "image": { + "reference": "lscr.io/linuxserver/heimdall:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/heimdall", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ALLOW_INTERNAL_REQUESTS", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/heimdall/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n heimdall:\n image: lscr.io/linuxserver/heimdall:latest\n container_name: heimdall\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - ALLOW_INTERNAL_REQUESTS=false #optional\n volumes:\n - /path/to/heimdall/config:/config\n ports:\n - 80:80\n - 443:443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/helium.json b/oci/catalog/apps/helium.json new file mode 100644 index 00000000..69669f91 --- /dev/null +++ b/oci/catalog/apps/helium.json @@ -0,0 +1,264 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-helium", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Helium" + }, + "tagline": { + "en_US": "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking." + }, + "description": { + "en_US": "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/helium-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/helium-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://helium.computer/", + "documentation": "https://docs.linuxserver.io/images/docker-helium/", + "repository": "https://github.com/linuxserver/docker-helium", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-15", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-15" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-helium", + "default_branch": "master", + "revision": "7e8cab56f575774d6796264a4a4eed960e466e42", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-helium/7e8cab56f575774d6796264a4a4eed960e466e42/README.md", + "readme_pushed_at": "2026-09-12T14:29:44Z", + "compose_sha256": "e831badc82129b1c43abbd5133187b8823f17987815a35620feee084bdf023b4", + "generated_at": "2026-09-12T14:37:28+00:00" + }, + "container_contract": { + "service_name": "helium", + "container_name": "helium", + "image": { + "reference": "lscr.io/linuxserver/helium:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/helium", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "HELIUM_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/helium/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n helium:\n image: lscr.io/linuxserver/helium:latest\n container_name: helium\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - HELIUM_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/helium/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/hermes.json b/oci/catalog/apps/hermes.json new file mode 100644 index 00000000..271f67d0 --- /dev/null +++ b/oci/catalog/apps/hermes.json @@ -0,0 +1,510 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-hermes", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Hermes" + }, + "tagline": { + "en_US": "A self-improving AI agent with memory, skills, messaging, and a web dashboard." + }, + "description": { + "en_US": "Hermes Agent is a self-improving AI agent from Nous Research, designed to be a long-running collaborator rather than a one-off chatbot.\nIts built-in learning loop combines persistent memory, cross-session recall, and reusable skills so it can keep context and improve recurring workflows over time.\nWith a unified gateway, rich toolsets, and a browser-based dashboard, Hermes fits research, automation, cross-platform communication, and ongoing operational work.\n\n**Main Features:**\n- Built-in learning loop with persistent memory, session search, and reusable skills\n- One gateway for CLI, Telegram, Discord, Slack, WhatsApp, Signal, and more\n- Tool-driven workflows with terminal access, web search, browser automation, file editing, and MCP integration\n- Automation and coordination with cron jobs, subagents, the web dashboard, and an OpenAI-compatible API\n\n**Learn More:**\n- [Hermes Agent Official Website](https://hermes-agent.nousresearch.com/)\n- [Hermes Agent GitHub](https://github.com/NousResearch/hermes-agent)\n- [Hermes Agent Documentation](https://hermes-agent.nousresearch.com/docs/)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Nous Research", + "developer": "Nous Research", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9119, + "path": "/" + }, + "website": "https://hermes-agent.nousresearch.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/nousresearch/hermes-agent", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "nousresearch", + "repository": "https://hub.docker.com/r/nousresearch/hermes-agent", + "revision": "56eda31622b6eac120adfd7b8814f84574ccccaf0abaaf5a33fcaa4e8156ffd3", + "image_repository_url": "https://hub.docker.com/r/nousresearch/hermes-agent", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "56eda31622b6eac120adfd7b8814f84574ccccaf0abaaf5a33fcaa4e8156ffd3", + "generated_at": "2026-09-13T19:54:26+00:00" + }, + "container_contract": { + "service_name": "hermes", + "container_name": "hermes", + "image": { + "reference": "nousresearch/hermes-agent:latest", + "registry": "docker.io", + "repository": "nousresearch/hermes-agent", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "HERMES_DASHBOARD", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "HERMES_DASHBOARD_BASIC_AUTH_USERNAME", + "example": "admin", + "required": true, + "sensitive": false, + "source": "official-image-environment" + }, + { + "name": "HERMES_DASHBOARD_BASIC_AUTH_PASSWORD", + "example": "${GENERATED_HERMES_DASHBOARD_PASSWORD}", + "required": true, + "sensitive": true, + "source": "official-image-environment" + }, + { + "name": "HERMES_DASHBOARD_BASIC_AUTH_SECRET", + "example": "${GENERATED_HERMES_DASHBOARD_SESSION_SECRET}", + "required": true, + "sensitive": true, + "source": "official-image-environment" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt/data", + "compose_source_example": "/DATA/AppData/$AppID/", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8642, + "published_example": 8642, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9119, + "published_example": 9119, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: hermes\nservices:\n hermes:\n image: nousresearch/hermes-agent:latest\n container_name: hermes\n deploy:\n resources:\n reservations:\n memory: 1G\n restart: unless-stopped\n command:\n - gateway\n - run\n ports:\n - target: 8642\n published: '8642'\n protocol: tcp\n - target: 9119\n published: '9119'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/\n target: /opt/data\n environment:\n HERMES_DASHBOARD: 1\n HERMES_DASHBOARD_INSECURE: 1\n" + }, + "compose_stack": { + "project_name": "hermes", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "hermes", + "service_count": 1, + "services": [ + { + "name": "hermes", + "image": "nousresearch/hermes-agent:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "nousresearch/hermes-agent:latest", + "container_name": "hermes", + "deploy": { + "resources": { + "reservations": { + "memory": "1G" + } + } + }, + "restart": "unless-stopped", + "command": [ + "gateway", + "run" + ], + "ports": [ + { + "target": 8642, + "published": "8642", + "protocol": "tcp" + }, + { + "target": 9119, + "published": "9119", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/", + "target": "/opt/data" + } + ], + "environment": { + "HERMES_DASHBOARD": 1, + "HERMES_DASHBOARD_INSECURE": 1 + } + } + } + ], + "top_level": { + "name": "hermes" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "hermes-volume-0", + "service": "hermes", + "container_path": "/opt/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "hermes" + ], + "stop_order": [ + "hermes" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Hermes WebUI", + "scheme": "http", + "port": 9119, + "path": "/", + "source": "official-image-dashboard" + } + ], + "credentials": [ + { + "label": "Hermes WebUI", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "HERMES_DASHBOARD_BASIC_AUTH_USERNAME", + "password_environment": "HERMES_DASHBOARD_BASIC_AUTH_PASSWORD", + "change_required": false, + "source": "official-image-environment", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "gateway", + "run" + ] + }, + "generated_sensitive_environment": { + "HERMES_DASHBOARD_BASIC_AUTH_PASSWORD": { + "strategy": "token-hex", + "bytes": 16, + "prompt": true + }, + "HERMES_DASHBOARD_BASIC_AUTH_SECRET": { + "strategy": "token-hex", + "bytes": 32, + "prompt": false + } + }, + "startup_healthcheck": { + "scheme": "http", + "port": 9119, + "path": "/", + "verify_tls": true, + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "stability_seconds": 4 + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/hishtory-server.json b/oci/catalog/apps/hishtory-server.json new file mode 100644 index 00000000..143b72ca --- /dev/null +++ b/oci/catalog/apps/hishtory-server.json @@ -0,0 +1,238 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-hishtory-server", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Hishtory Server" + }, + "tagline": { + "en_US": "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers." + }, + "description": { + "en_US": "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/hishtory-server-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/hishtory-server-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://github.com/ddworken/hishtory", + "documentation": "https://docs.linuxserver.io/images/docker-hishtory-server/", + "repository": "https://github.com/linuxserver/docker-hishtory-server", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-12-25", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-19", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-08-26", + "note": "Bump to go 1.23" + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-hishtory-server", + "default_branch": "main", + "revision": "2ab19293ce67aca74850ada791f3f695b360f412", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-hishtory-server/2ab19293ce67aca74850ada791f3f695b360f412/README.md", + "readme_pushed_at": "2026-09-11T07:39:19Z", + "compose_sha256": "6f9c613b231894bc95d9b7124c7d475da2449ce7768c397c4b412c576696d4c4", + "generated_at": "2026-09-12T14:37:28+00:00" + }, + "container_contract": { + "service_name": "hishtory-server", + "container_name": "hishtory-server", + "image": { + "reference": "lscr.io/linuxserver/hishtory-server:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/hishtory-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "HISHTORY_POSTGRES_DB", + "example": "postgresql://${HISHTORY_DB_USER}:${HISHTORY_DB_PASS}@hishtory-db:5432/hishtory?sslmode=disable", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "HISHTORY_SQLITE_DB", + "example": "/config/hishtory.db", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n hishtory-server:\n image: lscr.io/linuxserver/hishtory-server:latest\n container_name: hishtory-server\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - HISHTORY_POSTGRES_DB=postgresql://${HISHTORY_DB_USER}:${HISHTORY_DB_PASS}@hishtory-db:5432/hishtory?sslmode=disable #optional\n - HISHTORY_SQLITE_DB=/config/hishtory.db #optional\n ports:\n - 8080:8080\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/holoplay.json b/oci/catalog/apps/holoplay.json new file mode 100644 index 00000000..44986e05 --- /dev/null +++ b/oci/catalog/apps/holoplay.json @@ -0,0 +1,390 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-holoplay", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "HoloPlay" + }, + "tagline": { + "en_US": "A web app to listen Youtube audio source." + }, + "description": { + "en_US": "HoloPlay is a web based self-hosted using Invidious API for listening Youtube audio source." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "St\u00e9phane Richin", + "developer": "St\u00e9phane Richin", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/spout8301/holoplay", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "spout8301", + "repository": "https://hub.docker.com/r/spout8301/holoplay", + "revision": "fe85aa9d263bfcda35ff3b46b55f027b61676ae45e4bf78dbf105cab3d5cd2d9", + "image_repository_url": "https://hub.docker.com/r/spout8301/holoplay", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "fe85aa9d263bfcda35ff3b46b55f027b61676ae45e4bf78dbf105cab3d5cd2d9", + "generated_at": "2026-09-13T17:20:20+00:00" + }, + "container_contract": { + "service_name": "holoplay", + "container_name": "holoplay", + "image": { + "reference": "spout8301/holoplay:latest", + "registry": "docker.io", + "repository": "spout8301/holoplay", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: holoplay\nservices:\n holoplay:\n image: spout8301/holoplay:latest\n ports:\n - target: 3000\n published: '3000'\n protocol: tcp\n privileged: true\n restart: unless-stopped\n container_name: holoplay\n" + }, + "compose_stack": { + "project_name": "holoplay", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "holoplay", + "service_count": 1, + "services": [ + { + "name": "holoplay", + "image": "spout8301/holoplay:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "spout8301/holoplay:latest", + "ports": [ + { + "target": 3000, + "published": "3000", + "protocol": "tcp" + } + ], + "privileged": true, + "restart": "unless-stopped", + "container_name": "holoplay" + } + } + ], + "top_level": { + "name": "holoplay" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "holoplay" + ], + "stop_order": [ + "holoplay" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": false, + "warning": "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "optional-explicit-user-consent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/homeassistant-official.json b/oci/catalog/apps/homeassistant-official.json new file mode 100644 index 00000000..5165fd89 --- /dev/null +++ b/oci/catalog/apps/homeassistant-official.json @@ -0,0 +1,515 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-homeassistant-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Home Assistant" + }, + "tagline": { + "en_US": "Open source home automation that puts local control and privacy first." + }, + "description": { + "en_US": "Home Assistant is a smart home management app prioritizing local control and data privacy, managing devices through an intuitive interface with data stored locally, eliminating cloud dependency. Its robust features and community support make it ideal for DIY enthusiasts and home users creating personalized home experiences.\n\nThe app's core features include customizable dashboards, powerful automations, and a voice assistant. Dashboards support drag-and-drop customization, with various card types to display data and control devices like lights or sensors. It offers an advanced automation engine, such as turning on lights at sunset or alerting users to an open garage door. The Assist voice assistant enables natural language control, compatible with phones, tablets, smartwatches, and even traditional telephones, allowing users to customize interactions and experiment with AI conversations to meet diverse needs.\n\nIt extends functionality through add-ons, supporting tools like AdGuard for ad blocking, NodeRed for third-party automations, or turning devices into Spotify Connect targets. Home energy management optimizes solar production and usage planning to save costs. Home Assistant Cast transforms TVs into dashboard displays, and NFC tags trigger music playback or routine automations. Community documentation aids configuration, with local data processing ensuring privacy, suitable for home or small team smart home management.\n\n**Key Features:**\n- Local data storage, prioritizing privacy\n- Drag-and-drop customizable dashboards for device control and data display\n- Advanced automations for triggering smart home events\n- Assist voice assistant for natural language control\n- Add-ons for integrating AdGuard, NodeRed, and more\n- Home energy management for optimized usage and cost savings\n- Home Assistant Cast for TV dashboard displays\n- NFC tags for triggering music or automation tasks\n\n**Learn More:**\n- [Home Assistant Official Website](https://www.home-assistant.io)\n- [Home Assistant GitHub Repository](https://github.com/home-assistant/core)\n- [Home Assistant Documentation](https://www.home-assistant.io/docs)\n- [Home Assistant Community](https://community.home-assistant.io)\n- [Home Assistant Add-ons](https://www.home-assistant.io/addons)\n" + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "Home Assistant", + "developer": "Home Assistant", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8123, + "path": "/" + }, + "website": "https://www.home-assistant.io", + "documentation": null, + "repository": "https://hub.docker.com/r/homeassistant/home-assistant", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/homeassistant/home-assistant", + "revision": "2bff1461930be894c992413020f4ba0006be5b43bf29e17a0004ac96eac0c72c", + "image_repository_url": "https://hub.docker.com/r/homeassistant/home-assistant", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "2bff1461930be894c992413020f4ba0006be5b43bf29e17a0004ac96eac0c72c", + "generated_at": "2026-09-13T17:20:20+00:00" + }, + "container_contract": { + "service_name": "homeassistant", + "container_name": "homeassistant", + "image": { + "reference": "homeassistant/home-assistant:latest", + "registry": "docker.io", + "repository": "homeassistant/home-assistant", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/etc/localtime", + "compose_source_example": "/etc/localtime", + "read_only": true, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/run/dbus", + "compose_source_example": "/run/dbus", + "read_only": true, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: homeassistant\nservices:\n homeassistant:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n image: homeassistant/home-assistant:latest\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: host\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /etc/localtime\n target: /etc/localtime\n read_only: true\n - type: bind\n source: /run/dbus\n target: /run/dbus\n read_only: true\n privileged: true\n container_name: homeassistant\n" + }, + "compose_stack": { + "project_name": "homeassistant", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "homeassistant", + "service_count": 1, + "services": [ + { + "name": "homeassistant", + "image": "homeassistant/home-assistant:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "image": "homeassistant/home-assistant:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "host", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/etc/localtime", + "target": "/etc/localtime", + "read_only": true + }, + { + "type": "bind", + "source": "/run/dbus", + "target": "/run/dbus", + "read_only": true + } + ], + "privileged": true, + "container_name": "homeassistant" + } + } + ], + "top_level": { + "name": "homeassistant" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "homeassistant-volume-0", + "service": "homeassistant", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "homeassistant-volume-1", + "service": "homeassistant", + "container_path": "/etc/localtime", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/localtime", + "source_path_prompt": null + }, + { + "id": "homeassistant-volume-2", + "service": "homeassistant", + "container_path": "/run/dbus", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "homeassistant" + ], + "stop_order": [ + "homeassistant" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8123, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "host" + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": false, + "warning": "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "optional-explicit-user-consent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/homeassistant.json b/oci/catalog/apps/homeassistant.json new file mode 100644 index 00000000..968bd1f5 --- /dev/null +++ b/oci/catalog/apps/homeassistant.json @@ -0,0 +1,376 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-homeassistant", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Homeassistant" + }, + "tagline": { + "en_US": "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server" + }, + "description": { + "en_US": "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server" + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/homeassistant-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/homeassistant-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8123, + "path": "/" + }, + "website": "https://www.home-assistant.io/", + "documentation": "https://docs.linuxserver.io/images/docker-homeassistant/", + "repository": "https://github.com/linuxserver/docker-homeassistant", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-02", + "note": "Rebase to alpine 3.24." + }, + { + "date": "2026-03-05", + "note": "Remove pycups as there are no python 3.14 wheels for it." + }, + { + "date": "2025-10-02", + "note": "Rebase to alpine 3.22, rely on baseimage service for usb device permission fixing." + }, + { + "date": "2025-09-19", + "note": "Add the necessary capabilities in the container to allow the unprivileged user access to bluetooth stack." + }, + { + "date": "2025-01-03", + "note": "Rebase to alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-07-02" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-homeassistant", + "default_branch": "main", + "revision": "2f66f05a2d599d5f3162eaba2f00c545cd6cccda", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-homeassistant/2f66f05a2d599d5f3162eaba2f00c545cd6cccda/README.md", + "readme_pushed_at": "2026-09-11T21:00:06Z", + "compose_sha256": "a0c536a711750869b9b3aa7f1a971973fd6a86020ac3d6f5ce5d3d16ff79c23b", + "generated_at": "2026-09-13T15:57:07+00:00" + }, + "container_contract": { + "service_name": "homeassistant", + "container_name": "homeassistant", + "image": { + "reference": "lscr.io/linuxserver/homeassistant:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/homeassistant", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/homeassistant/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8123, + "published_example": 8123, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n homeassistant:\n image: lscr.io/linuxserver/homeassistant:latest\n container_name: homeassistant\n network_mode: host\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/homeassistant/data:/config\n ports:\n - 8123:8123 #optional\n devices:\n - /path/to/device:/path/to/device #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8123, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "user-selected-device", + "kind": "character-device", + "purpose": "user-selected-device", + "enable_prompt": "Pass a host device to the LXC", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Actual device path on the host", + "host_path_default": "/dev/ttyUSB0", + "container_path_strategy": "same-as-host", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/path/to/device:/path/to/device" + } + ], + "network": { + "compose_mode": "host" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/homebridge.json b/oci/catalog/apps/homebridge.json new file mode 100644 index 00000000..1e860d35 --- /dev/null +++ b/oci/catalog/apps/homebridge.json @@ -0,0 +1,382 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-homebridge", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Homebridge" + }, + "tagline": { + "en_US": "HomeKit support for the impatient." + }, + "description": { + "en_US": "Homebridge is a lightweight NodeJS server you can run on your home network that emulates the iOS HomeKit API. It supports Plugins, which are community-contributed modules that provide a basic bridge from HomeKit to various 3rd-party APIs provided by manufacturers of \"smart home\" devices." + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "Homebridge", + "developer": "Homebridge", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8581, + "path": "/" + }, + "website": "https://homebridge.io/", + "documentation": null, + "repository": "https://hub.docker.com/r/homebridge/homebridge", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/homebridge/homebridge", + "revision": "140bdb39f55b7cb1ab2d7e176329e0802730f9f1c07e8c4bff71f2a9daa50d7e", + "image_repository_url": "https://hub.docker.com/r/homebridge/homebridge", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "140bdb39f55b7cb1ab2d7e176329e0802730f9f1c07e8c4bff71f2a9daa50d7e", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "homebridge", + "container_name": "homebridge", + "image": { + "reference": "homebridge/homebridge:latest", + "registry": "docker.io", + "repository": "homebridge/homebridge", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/homebridge", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: homebridge\nversion: '2'\nservices:\n homebridge:\n image: homebridge/homebridge:latest\n restart: always\n network_mode: host\n volumes:\n - /DATA/AppData/$AppID/config:/homebridge\n logging:\n driver: json-file\n options:\n max-size: 10mb\n max-file: '1'\n" + }, + "compose_stack": { + "project_name": "homebridge", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "homebridge", + "service_count": 1, + "services": [ + { + "name": "homebridge", + "image": "homebridge/homebridge:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "homebridge/homebridge:latest", + "restart": "always", + "network_mode": "host", + "volumes": [ + "/DATA/AppData/$AppID/config:/homebridge" + ], + "logging": { + "driver": "json-file", + "options": { + "max-size": "10mb", + "max-file": "1" + } + } + } + } + ], + "top_level": { + "name": "homebridge", + "version": "2" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "homebridge-volume-0", + "service": "homebridge", + "container_path": "/homebridge", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "homebridge" + ], + "stop_order": [ + "homebridge" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8581, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/htpcmanager.json b/oci/catalog/apps/htpcmanager.json new file mode 100644 index 00000000..849e6f10 --- /dev/null +++ b/oci/catalog/apps/htpcmanager.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-htpcmanager", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Htpcmanager" + }, + "tagline": { + "en_US": "Htpcmanager is a front end for many htpc related applications." + }, + "description": { + "en_US": "Htpcmanager is a front end for many htpc related applications." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/htpcmanager-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/htpcmanager-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8085, + "path": "/" + }, + "website": "https://github.com/HTPC-Manager/HTPC-Manager", + "documentation": "https://docs.linuxserver.io/images/docker-htpcmanager/", + "repository": "https://github.com/linuxserver/docker-htpcmanager", + "tips": [], + "mini_changelog": [ + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-01-08", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-08-25", + "note": "Rebase to Alpine 3.18." + }, + { + "date": "2023-07-04", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + }, + { + "date": "2023-02-13", + "note": "Rebase to Alpine 3.17, migrate to s6v3." + } + ], + "display_version": null, + "updated_at": "2024-06-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-htpcmanager", + "default_branch": "master", + "revision": "b7488238f5e139051ca3cf7f47a9e8fea6161a98", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-htpcmanager/b7488238f5e139051ca3cf7f47a9e8fea6161a98/README.md", + "readme_pushed_at": "2026-09-09T01:45:20Z", + "compose_sha256": "3658d440519c071f91788c3ff95dc8a2cc4e63d213b5bde3debfa0f63d7faf34", + "generated_at": "2026-09-12T14:37:28+00:00" + }, + "container_contract": { + "service_name": "htpcmanager", + "container_name": "htpcmanager", + "image": { + "reference": "lscr.io/linuxserver/htpcmanager:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/htpcmanager", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/htpcmanager/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8085, + "published_example": 8085, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n htpcmanager:\n image: lscr.io/linuxserver/htpcmanager:latest\n container_name: htpcmanager\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/htpcmanager/config:/config\n ports:\n - 8085:8085\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8085, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/hugo.json b/oci/catalog/apps/hugo.json new file mode 100644 index 00000000..b7b9e0cd --- /dev/null +++ b/oci/catalog/apps/hugo.json @@ -0,0 +1,446 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-hugo", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Hugo" + }, + "tagline": { + "en_US": "The world's fastest framework for building websites" + }, + "description": { + "en_US": "Hugo is a high-speed static site generation platform written in Go, optimized for speed and designed for flexibility. Advanced templating system and fast asset pipelines render a complete website in seconds, ideal for creating documentation sites, landing pages, and various project websites.\n\nCore features include optimized speed and a flexible framework. Concurrency in Go enables rapid rendering, supporting image processing (convert, resize, crop, rotate, adjust colors, apply filters, overlay text/images, extract EXIF data), JavaScript bundling (tree shaking, code splitting), Sass processing, and TailwindCSS support. Multilingual support and taxonomy system make it suitable for diverse sites like documentation, news, or events.\n\nIt includes an embedded web server for real-time previews of content, structure, and style changes during development. Frequent releases ensure ongoing feature enhancements, keeping it cutting-edge. With efficiency and flexibility at the core, the platform delivers a modern static site generation solution.\n\n**Key Features:**\n- High-speed rendering, generating sites in seconds\n- Fast asset pipelines: image processing, JavaScript bundling, Sass, and TailwindCSS support\n- Flexible framework with multilingual and taxonomy systems\n- Embedded web server for real-time development previews\n- Rich ecosystem of themes and plugins\n\n\n**Prerequisites for Using Hugo:**\n\n1. Open command line, navigate to `/DATA/AppData/hugo/project` directory\n\n```cd /DATA/AppData/hugo/project```\n\n2. Initialize the `project` directory as an empty Git repository\n\n```git init```\n\n3. Download the Ananke theme\n\n```git submodule add https://github.com/theNewDynamic/gohugo-theme-ananke.git themes/ananke```\n\n4. Specify the current theme\n\n```echo \"theme = 'ananke'\" >> hugo.toml```\n\n5. Restart Hugo\n\n\n**Learn More:**\n- [Hugo Official Website](https://gohugo.io/)\n- [Hugo GitHub](https://github.com/gohugoio/hugo)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "gohugoio", + "developer": "gohugoio", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 1313, + "path": "/" + }, + "website": "https://gohugo.io/", + "documentation": null, + "repository": "https://ghcr.io/gohugoio/hugo", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/gohugoio/hugo", + "revision": "34e95d9bbaab27e7f44c3eadd32c409c6f39ae29c1569e7d12fe913a6a4ab8ba", + "image_repository_url": "https://ghcr.io/gohugoio/hugo", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "34e95d9bbaab27e7f44c3eadd32c409c6f39ae29c1569e7d12fe913a6a4ab8ba", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "hugo", + "container_name": "hugo", + "image": { + "reference": "ghcr.io/gohugoio/hugo:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/gohugoio/hugo", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/project", + "compose_source_example": "/DATA/AppData/$AppID/project", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/cache", + "compose_source_example": "/DATA/AppData/$AppID/cache", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": false, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 1313, + "published_example": 1313, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: hugo\nservices:\n hugo:\n image: ghcr.io/gohugoio/hugo:latest\n container_name: hugo\n deploy:\n resources:\n reservations:\n memory: 256M\n restart: unless-stopped\n user: 0:0\n ports:\n - target: 1313\n published: '1313'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/project\n target: /project\n - type: bind\n source: /DATA/AppData/$AppID/cache\n target: /cache\n command:\n - server\n - --bind=0.0.0.0\n" + }, + "compose_stack": { + "project_name": "hugo", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "hugo", + "service_count": 1, + "services": [ + { + "name": "hugo", + "image": "ghcr.io/gohugoio/hugo:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/gohugoio/hugo:latest", + "container_name": "hugo", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "restart": "unless-stopped", + "user": "0:0", + "ports": [ + { + "target": 1313, + "published": "1313", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/project", + "target": "/project" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/cache", + "target": "/cache" + } + ], + "command": [ + "server", + "--bind=0.0.0.0" + ] + } + } + ], + "top_level": { + "name": "hugo" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "hugo-volume-0", + "service": "hugo", + "container_path": "/project", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "hugo-volume-1", + "service": "hugo", + "container_path": "/cache", + "mode": "managed-volume", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "hugo" + ], + "stop_order": [ + "hugo" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 1313, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "server", + "--bind=0.0.0.0" + ], + "user": "0:0" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/immich.json b/oci/catalog/apps/immich.json new file mode 100644 index 00000000..40c4f77d --- /dev/null +++ b/oci/catalog/apps/immich.json @@ -0,0 +1,1979 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-immich", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Immich" + }, + "tagline": { + "en_US": "Photo and video library with optional GPU transcoding and machine learning" + }, + "description": { + "en_US": "Immich as a coordinated four-LXC native OCI stack with private PostgreSQL and Valkey services, persistent media and model cache, and selectable hardware acceleration." + }, + "category": "media", + "category_label": "Media", + "author": "Immich", + "developer": "Immich", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 2283, + "path": "/" + }, + "website": "https://immich.app/", + "documentation": "https://docs.immich.app/install/docker-compose/", + "repository": "https://github.com/immich-app/immich", + "tips": [ + "The installer creates four coordinated native OCI LXC containers as one application.", + "Video transcoding acceleration and machine-learning acceleration are independent selections.", + "CPU is the validated safe machine-learning default; a GPU profile must pass a real inference test before cutover.", + "PostgreSQL data must remain on local storage and must not be placed on NFS or SMB." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-12" + }, + "source": { + "provider": "immich", + "repository": "https://github.com/immich-app/immich", + "revision": "0f93904a4db59b93558d09097e586d168ce6dbfa00a20afb6967259430a8514c", + "image_repository_url": "https://github.com/immich-app/immich/pkgs/container/immich-server", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "0f93904a4db59b93558d09097e586d168ce6dbfa00a20afb6967259430a8514c", + "generated_at": "2026-09-12T15:45:34+00:00" + }, + "container_contract": { + "service_name": "immich-server", + "container_name": "immich-server", + "image": { + "reference": "ghcr.io/immich-app/immich-server:release", + "registry": "ghcr.io", + "repository": "ghcr.io/immich-app/immich-server", + "tag": "release", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "DB_HOSTNAME", + "example": "database", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "DB_PORT", + "example": "5432", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "DB_DATABASE_NAME", + "example": "immich", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "DB_USERNAME", + "example": "postgres", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "DB_PASSWORD", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "official-compose-environment" + }, + { + "name": "REDIS_HOSTNAME", + "example": "redis", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "REDIS_PORT", + "example": "6379", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "IMMICH_MACHINE_LEARNING_URL", + "example": "http://immich-machine-learning:3003", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + } + ], + "volumes": [ + { + "id": "media", + "container_path": "/data", + "compose_source_example": "${UPLOAD_LOCATION}", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 100 + } + }, + { + "id": "localtime", + "container_path": "/etc/localtime", + "compose_source_example": "/etc/localtime", + "read_only": true, + "required": false, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 1 + } + } + ], + "ports": [ + { + "container_port": 2283, + "published_example": 2283, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "immich-machine-learning", + "image": "ghcr.io/immich-app/immich-machine-learning:release" + }, + { + "name": "redis", + "image": "docker.io/valkey/valkey:9@sha256:70739f85ad2ee01a726a965584a0f94895f01b0c60b3cc8b0aeef11eaa6888cf" + }, + { + "name": "database", + "image": "ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357191b76a916ae5eb93464d65c07511da41e3bf7a8416db519b40b1c23" + } + ], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: immich\nservices:\n immich-server:\n deploy:\n resources:\n reservations:\n memory: 1024M\n container_name: immich-server\n hostname: immich-server\n image: ghcr.io/immich-app/immich-server:release\n volumes:\n - /DATA/Gallery/immich:/usr/src/app/upload\n - /etc/localtime:/etc/localtime:ro\n environment:\n DB_DATABASE_NAME: immich\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n DB_USERNAME: postgres\n ports:\n - 2283:2283\n depends_on:\n - redis\n - database\n restart: unless-stopped\n healthcheck:\n disable: false\n networks:\n - immich\n immich-machine-learning:\n container_name: immich-machine-learning\n hostname: immich-machine-learning\n image: ghcr.io/immich-app/immich-machine-learning:release\n environment:\n DB_DATABASE_NAME: immich\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n DB_USERNAME: postgres\n restart: unless-stopped\n volumes:\n - /DATA/AppData/immich/model-cache:/cache\n healthcheck:\n disable: false\n networks:\n - immich\n redis:\n container_name: immich-redis\n hostname: immich-redis\n image: docker.io/valkey/valkey:9@sha256:70739f85ad2ee01a726a965584a0f94895f01b0c60b3cc8b0aeef11eaa6888cf\n healthcheck:\n test: redis-cli ping || exit 1\n restart: unless-stopped\n networks:\n - immich\n database:\n container_name: immich-postgres\n hostname: immich-postgres\n image: ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357191b76a916ae5eb93464d65c07511da41e3bf7a8416db519b40b1c23\n environment:\n POSTGRES_PASSWORD: ${GENERATED_DB_PASSWORD}\n POSTGRES_USER: postgres\n POSTGRES_DB: immich\n POSTGRES_INITDB_ARGS: --data-checksums\n volumes:\n - /DATA/AppData/immich/pgdata:/var/lib/postgresql/data\n restart: unless-stopped\n networks:\n - immich\nnetworks:\n immich:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "immich", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "immich-server", + "service_count": 4, + "services": [ + { + "name": "database", + "image": "ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "immich_postgres", + "image": "ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0", + "environment": { + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}", + "POSTGRES_USER": "postgres", + "POSTGRES_DB": "immich", + "POSTGRES_INITDB_ARGS": "--data-checksums", + "PGDATA": "/var/lib/postgresql/data/pgdata" + }, + "volumes": [ + "postgres-data:/var/lib/postgresql/data" + ], + "shm_size": "128mb", + "restart": "always", + "healthcheck": { + "disable": false + } + } + }, + { + "name": "redis", + "image": "docker.io/valkey/valkey:9", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "immich_redis", + "image": "docker.io/valkey/valkey:9", + "healthcheck": { + "test": "valkey-cli ping | grep -q PONG || exit 1" + }, + "restart": "always" + } + }, + { + "name": "immich-machine-learning", + "image": "ghcr.io/immich-app/immich-machine-learning:release", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "immich_machine_learning", + "image": "ghcr.io/immich-app/immich-machine-learning:release", + "volumes": [ + "model-cache:/cache" + ], + "environment": { + "TZ": "${TIMEZONE}" + }, + "restart": "always", + "healthcheck": { + "disable": false + } + } + }, + { + "name": "immich-server", + "image": "ghcr.io/immich-app/immich-server:release", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "database", + "redis", + "immich-machine-learning" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "immich_server", + "image": "ghcr.io/immich-app/immich-server:release", + "volumes": [ + "${UPLOAD_LOCATION}:/data", + "/etc/localtime:/etc/localtime:ro" + ], + "environment": { + "TZ": "${TIMEZONE}", + "DB_HOSTNAME": "database", + "DB_PORT": "5432", + "DB_USERNAME": "postgres", + "DB_PASSWORD": "${GENERATED_DB_PASSWORD}", + "DB_DATABASE_NAME": "immich", + "REDIS_HOSTNAME": "redis", + "REDIS_PORT": "6379", + "IMMICH_MACHINE_LEARNING_URL": "http://immich-machine-learning:3003" + }, + "ports": [ + "2283:2283" + ], + "depends_on": [ + "redis", + "database", + "immich-machine-learning" + ], + "restart": "always", + "healthcheck": { + "disable": false + } + } + } + ], + "top_level": { + "name": "immich", + "volumes": { + "model-cache": {}, + "postgres-data": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "database-and-valkey-private-only", + "machine_learning_frontend_access": "enabled-for-model-downloads", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "immich-media", + "service": "immich-server", + "container_path": "/data", + "mode": "user-selectable", + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "user_selectable": true, + "backup": false, + "backup_by_mode": { + "managed-volume": true, + "host-bind": false + }, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for the Immich media library" + }, + { + "id": "localtime", + "service": "immich-server", + "container_path": "/etc/localtime", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/localtime", + "source_path_prompt": null + }, + { + "id": "model-cache", + "service": "immich-machine-learning", + "container_path": "/cache", + "mode": "managed-volume", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "postgres-data", + "service": "database", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null, + "constraints": { + "local_storage_required": true, + "network_filesystem_allowed": false + } + } + ], + "orchestration": { + "reserve_vmids_atomically": 4, + "start_order": [ + "database", + "redis", + "immich-machine-learning", + "immich-server" + ], + "stop_order": [ + "immich-server", + "immich-machine-learning", + "redis", + "database" + ], + "dependency_readiness": "healthcheck-required-before-next-service", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes", + "gpu_failure_policy": "fallback-machine-learning-to-cpu-before-starting-server" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "database_storage", + "media_storage_mode", + "media_destination", + "database_size_gb", + "frontend_bridge", + "frontend_ipv4_mode", + "timezone", + "video_transcoding_acceleration", + "machine_learning_acceleration" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order", + "gpu_preflight_checks", + "machine_learning_cpu_fallback" + ], + "generated_secrets": [ + { + "id": "db-password", + "strategy": "generate-cryptographically-random-alphanumeric-at-install", + "bindings": [ + { + "service": "immich-server", + "environment_variable": "DB_PASSWORD" + }, + { + "service": "database", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 2283, + "path": "/", + "source": "official-compose" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 4, + "memory_mb": 3072, + "swap_mb": 1024, + "rootfs_size_gb": 16, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "rolling-latest-image", + "upstream_behavior": "The official Compose selects an Immich release and pins dependency images.", + "native_lxc_behavior": "The automatic catalog resolves the latest tag of each selected image repository at install time.", + "reason": "Pinned versions belong to the future manual installer while this catalog intentionally tracks latest.", + "behavioral_impact": "A rolling image must be revalidated before unattended updates.", + "validation": "pending-for-each-resolved-latest-digest" + }, + { + "id": "one-native-lxc-per-service", + "upstream_behavior": "Docker Compose starts four containers as one project.", + "native_lxc_behavior": "ProxMenux creates four native OCI LXC containers and controls them as one application.", + "reason": "Proxmox native OCI imports one image per LXC.", + "behavioral_impact": "Equivalent service separation with native Proxmox lifecycle and backup controls.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "private-service-network", + "upstream_behavior": "Compose DNS connects services on a private Docker network.", + "native_lxc_behavior": "Fixed addresses and service aliases are created on a private Proxmox bridge.", + "reason": "The services run in separate LXC network namespaces.", + "behavioral_impact": "PostgreSQL and Valkey remain private; machine learning also receives frontend access for model downloads.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "native-persistent-storage", + "upstream_behavior": "Compose uses upload and database bind mounts plus a named model-cache volume.", + "native_lxc_behavior": "Media uses the selected host bind or managed volume, PostgreSQL uses a local managed backup volume, and model cache uses a reproducible managed volume.", + "reason": "Preserve official container paths while applying native Proxmox backup semantics.", + "behavioral_impact": "Shared media needs its own backup; PostgreSQL participates in vzdump with backup=1.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "ordered-healthchecked-startup", + "upstream_behavior": "Compose starts dependencies and evaluates container health.", + "native_lxc_behavior": "The stack orchestrator starts database, Valkey, machine learning and server in health-checked order.", + "reason": "Proxmox does not provide Compose depends_on semantics across LXC containers.", + "behavioral_impact": "One user action still manages the complete application.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "container-scoped-ld-preload", + "upstream_behavior": "Docker applies LD_PRELOAD inside the machine-learning container.", + "native_lxc_behavior": "ProxMenux removes LD_PRELOAD from the global LXC runtime environment and reapplies it in the machine-learning entrypoint after entering the container rootfs.", + "reason": "Proxmox startup hooks otherwise inherit the container path before chroot and print misleading loader errors.", + "behavioral_impact": "None; the Immich process still loads the official mimalloc library.", + "validation": "passed-in-ct106-restart-2026-09-13" + }, + { + "id": "lxc-route-readiness-wrapper", + "upstream_behavior": "Docker prepares networking before the server process starts.", + "native_lxc_behavior": "A minimal wrapper waits for the eth0 default route before executing the image command.", + "reason": "DHCP route creation can race PID 1 in the native OCI LXC.", + "behavioral_impact": "Startup timing only; the official final command remains unchanged.", + "validation": "passed-in-ct121" + }, + { + "id": "postgres-private-listen", + "upstream_behavior": "PostgreSQL listens on the private Compose network.", + "native_lxc_behavior": "The official entrypoint receives listen_addresses for loopback and the private LXC address.", + "reason": "The database must be reachable without a frontend interface.", + "behavioral_impact": "Equivalent private reachability.", + "validation": "passed-in-ct123" + } + ], + "catalog": { + "replaces_discovered_ids": [ + "immich" + ] + }, + "application_options": { + "video_transcoding": { + "selectable": true, + "independent_from_machine_learning": true, + "profiles": [ + "cpu", + "vaapi", + "quicksync", + "nvenc" + ], + "laboratory_validated_profile": "vaapi-amd", + "validated": true, + "configuration_location": "Immich Administration > Video transcoding", + "installer_writes_application_setting": false, + "device_policy": "run-profile-preflight-and-pass-only-required-host-devices" + }, + "machine_learning": { + "selectable": true, + "profiles": [ + "cpu", + "openvino", + "cuda", + "rocm" + ], + "safe_default": "cpu", + "profile_images": { + "cpu": "ghcr.io/immich-app/immich-machine-learning:release", + "openvino": "ghcr.io/immich-app/immich-machine-learning:release-openvino", + "cuda": "ghcr.io/immich-app/immich-machine-learning:release-cuda", + "rocm": "ghcr.io/immich-app/immich-machine-learning:release-rocm" + }, + "cpu": { + "available": true, + "laboratory_validated": true, + "hardware_accelerated": false + }, + "openvino": { + "available": true, + "laboratory_validated": true, + "vendor": "intel", + "provider": "OpenVINOExecutionProvider", + "hardware_accelerated": true, + "requires": [ + "/dev/dri" + ], + "status": "validated-on-documented-laboratory-hardware", + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md" + }, + "cuda": { + "available": true, + "laboratory_validated": true, + "vendor": "nvidia", + "provider": "CUDAExecutionProvider", + "hardware_accelerated": true, + "minimum_compute_capability": "5.2", + "minimum_driver": "545", + "status": "validated-on-documented-laboratory-hardware", + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md" + }, + "rocm": { + "available": true, + "laboratory_validated": false, + "vendor": "amd", + "provider": "MIGraphXExecutionProvider", + "hardware_accelerated": true, + "requires": [ + "/dev/dri", + "/dev/kfd" + ], + "minimum_free_image_cache_gb": 35, + "status": "compatible-gpu-and-real-inference-validation-required", + "automatic_denylist": [ + { + "pci_id": "1002:164c", + "gpu": "AMD Lucienne integrated graphics", + "reason": "Real buffalo_l inference caused SDMA/compute timeouts and repeated host GPU resets.", + "tested_on": "2026-08-26" + } + ] + }, + "validation_protocol": { + "ping_is_not_sufficient": true, + "required_steps": [ + "Verify the expected ONNX execution provider is available.", + "Run a real facial-recognition detection and embedding request.", + "Run visual and textual smart-search embeddings.", + "Observe GPU utilization during inference.", + "Reject the profile on provider fallback, HTTP 500, kernel timeout or GPU reset.", + "Keep the validated CPU ML service available until GPU validation passes." + ] + }, + "failure_policy": { + "stop_failed_machine_learning_lxc": true, + "preserve_failure_metadata_without_secrets": true, + "record_gpu_pci_id_and_driver": true, + "stop_further_gpu_tests_after_kernel_timeout_or_reset": true, + "recommend_host_reboot_when_gpu_clocks_or_power_do_not_return_to_idle": true, + "automatic_hsa_override_retry": false, + "fallback_profile": "cpu", + "reuse_model_cache_when_compatible": true, + "start_server_only_after_cpu_fallback_is_healthy": true + } + } + }, + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "commands": [ + "pct", + "pvesm", + "skopeo", + "openssl", + "jq" + ], + "features": [ + "native-oci-lxc", + "unprivileged-lxc", + "private-service-network" + ], + "minimum_host_memory_mb": 6144, + "recommended_host_memory_mb": 8192, + "minimum_free_image_cache_gb": 8, + "thin_pool_checks": { + "minimum_free_percent": 15, + "reject_when_data_percent_above": 85, + "warn_when_virtual_allocation_exceeds_pool": true, + "require_autoextend_or_explicit_confirmation": true + }, + "database_storage": { + "must_be_local": true, + "recommended_media": "ssd", + "network_filesystem_allowed": false + } + }, + "defaults": { + "stack_name": "immich", + "timezone": "Europe/Madrid", + "rootfs_storage": "local-lvm", + "database_storage": "local-lvm", + "shared_media_root": "/mnt/oci-shared/media/immich/${stack_name}", + "database_size_gb": 32, + "frontend_network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "firewall": true, + "host_managed": true + }, + "private_network": { + "mode": "create-if-missing", + "bridge": "vmbr10", + "subnet": "10.77.0.0/24", + "host_address": "10.77.0.1/24", + "host_ip": "10.77.0.1", + "server_address": "10.77.0.10/24", + "server_ip": "10.77.0.10", + "machine_learning_address": "10.77.0.11/24", + "machine_learning_ip": "10.77.0.11", + "database_address": "10.77.0.12/24", + "database_ip": "10.77.0.12", + "valkey_address": "10.77.0.13/24", + "valkey_ip": "10.77.0.13", + "address_offsets": { + "host": 1, + "server": 10, + "machine_learning": 11, + "database": 12, + "valkey": 13 + }, + "firewall": true, + "host_managed": true, + "nat": false + }, + "database": { + "name": "immich", + "username": "postgres", + "vector_extension": "vectorchord", + "storage_type": "SSD" + }, + "video_transcoding": { + "acceleration": "vaapi", + "render_device": "/dev/dri/renderD128", + "driver": "auto" + }, + "machine_learning": { + "acceleration": "cpu", + "model_cache_size_gb": 8 + } + }, + "installer_contract": { + "variable_syntax": "dollar-brace dotted path", + "strict_resolution": true, + "reject_unresolved_variables": true, + "input_bindings": { + "frontend_bridge": "frontend_network.bridge", + "frontend_ipv4_mode": "frontend_network.ipv4_mode", + "private_bridge": "private_network.bridge", + "private_subnet": "private_network.subnet", + "database_storage": "database_storage", + "media_storage_mode": "storage.media.mode", + "media_storage": "storage.media.managed_storage", + "media_size_gb": "storage.media.managed_size_gb", + "shared_media_root": "shared_media_root", + "video_transcoding_acceleration": "video_transcoding.acceleration", + "video_render_device": "video_transcoding.render_device", + "vaapi_driver": "video_transcoding.driver", + "machine_learning_acceleration": "machine_learning.acceleration" + }, + "computed_values": { + "vmids": { + "server": "base_vmid + services.server.vmid_offset", + "machine_learning": "base_vmid + services.machine_learning.vmid_offset", + "database": "base_vmid + services.database.vmid_offset", + "valkey": "base_vmid + services.valkey.vmid_offset" + }, + "private_addresses": "Derive IP and CIDR values from private_network.subnet and private_network.address_offsets", + "host_uid_for_container_uid": "unprivileged_idmap_base + container_uid" + }, + "machine_learning_image_resolution": { + "cpu": "machine_learning_cpu", + "rocm": "machine_learning_rocm", + "openvino": "machine_learning_openvino", + "cuda": "machine_learning_cuda" + }, + "machine_learning_resource_profiles": { + "cpu": { + "rootfs_size_gb": 12, + "memory_mb": 2048, + "validated": true + }, + "rocm": { + "rootfs_size_gb": 48, + "memory_mb": 4096, + "validated": false + }, + "openvino": { + "rootfs_size_gb": 20, + "memory_mb": 4096, + "validated": false + }, + "cuda": { + "rootfs_size_gb": 32, + "memory_mb": 4096, + "validated": false + } + }, + "invariants": [ + "Reserve four unused VMIDs atomically before creating any LXC.", + "Never expose database or Valkey on the frontend bridge.", + "Never place PostgreSQL data on network storage.", + "Generate the PostgreSQL password during installation and translate it directly to lxc.environment.runtime, matching Compose environment visibility.", + "Store PostgreSQL data in a managed Proxmox volume with backup enabled.", + "Only the user media library uses a shared host bind by default.", + "Preserve all OCI image environment entries and append explicit Compose and native-LXC overrides after them.", + "Run Valkey with its official entrypoint and a backed-up managed /data volume, without authentication on the private stack network.", + "Start and healthcheck each dependency before starting the next service.", + "Do not enable a GPU ML profile until every profile-specific preflight check passes." + ] + }, + "services": { + "database": { + "vmid_offset": 2, + "hostname_template": "${stack_name}-db", + "image_ref": "database", + "ostype": "auto-detect-from-image", + "unprivileged": true, + "features": [ + "nesting=1" + ], + "resources": { + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8 + }, + "network_interfaces": [ + { + "name": "eth0", + "role": "private", + "bridge_from": "private_network.bridge", + "address_from": "private_network.database_address", + "default_gateway": false + } + ], + "entrypoint": "/usr/local/bin/immich-docker-entrypoint.sh postgres -c config_file=/etc/postgresql/postgresql.conf -c listen_addresses=127.0.0.1,${private_network.database_ip}", + "halt_signal": "SIGINT", + "startup": { + "order": 10, + "up_delay_seconds": 10, + "down_timeout_seconds": 30 + }, + "mounts": [ + "database-data" + ], + "environment": { + "POSTGRES_USER": "${database.username}", + "POSTGRES_DB": "${database.name}", + "POSTGRES_INITDB_ARGS": "--data-checksums", + "PGDATA": "/var/lib/postgresql/data/pgdata", + "DB_STORAGE_TYPE": "${database.storage_type}", + "POSTGRES_PASSWORD": "${generated.db_password}" + }, + "healthcheck": { + "type": "command", + "command": [ + "pg_isready", + "-h", + "${private_network.database_ip}", + "-p", + "5432" + ], + "timeout_seconds": 5, + "retries": 30 + }, + "entrypoint_override": "official-immich-postgres-entrypoint-with-private-listen-argument", + "listen_addresses": [ + "127.0.0.1", + "${private_network.database_ip}" + ] + }, + "valkey": { + "vmid_offset": 3, + "hostname_template": "${stack_name}-valkey", + "image_ref": "valkey", + "ostype": "auto-detect-from-image", + "unprivileged": true, + "features": [ + "nesting=1" + ], + "resources": { + "cores": 1, + "memory_mb": 512, + "swap_mb": 256, + "rootfs_size_gb": 4 + }, + "network_interfaces": [ + { + "name": "eth0", + "role": "private", + "bridge_from": "private_network.bridge", + "address_from": "private_network.valkey_address", + "default_gateway": false + } + ], + "entrypoint": "docker-entrypoint.sh valkey-server", + "working_directory": "/data", + "halt_signal": "SIGTERM", + "startup": { + "order": 20, + "up_delay_seconds": 5, + "down_timeout_seconds": 15 + }, + "mounts": [], + "healthcheck": { + "type": "command", + "command": [ + "valkey-cli", + "-h", + "${private_network.valkey_ip}", + "ping" + ], + "expected_output": "PONG", + "timeout_seconds": 5, + "retries": 30 + }, + "entrypoint_override": "official-image-command" + }, + "machine_learning": { + "vmid_offset": 1, + "hostname_template": "${stack_name}-ml", + "image_ref_from": "machine_learning.acceleration", + "image_resolution_from": "installer_contract.machine_learning_image_resolution", + "resource_profile_from": "installer_contract.machine_learning_resource_profiles", + "devices_from": "hardware_profiles.machine_learning.${machine_learning.acceleration}.devices", + "preflight_checks_from": "hardware_profiles.machine_learning.${machine_learning.acceleration}.preflight_checks", + "ostype": "auto-detect-from-image", + "unprivileged": true, + "features": [ + "nesting=1" + ], + "resources": { + "cores": 2, + "memory_mb": 2048, + "swap_mb": 1024, + "rootfs_size_gb": 12 + }, + "network_interfaces": [ + { + "name": "eth0", + "role": "frontend-downloads", + "bridge_from": "frontend_network.bridge", + "ipv4_mode_from": "frontend_network.ipv4_mode", + "default_gateway": true + }, + { + "name": "eth1", + "role": "private", + "bridge_from": "private_network.bridge", + "address_from": "private_network.machine_learning_address", + "default_gateway": false + } + ], + "entrypoint": "tini -- python -m immich_ml", + "working_directory": "/usr/src", + "halt_signal": "SIGTERM", + "startup": { + "order": 30, + "up_delay_seconds": 10, + "down_timeout_seconds": 30 + }, + "mounts": [ + "machine-learning-cache" + ], + "environment": { + "IMMICH_HOST": "${private_network.machine_learning_ip}", + "IMMICH_PORT": "3003", + "MACHINE_LEARNING_CACHE_FOLDER": "/cache", + "TRANSFORMERS_CACHE": "/cache", + "LD_PRELOAD": "/usr/lib/libmimalloc.so.2" + }, + "healthcheck": { + "type": "http", + "url": "http://${private_network.machine_learning_ip}:3003/ping", + "expected_body": "pong", + "timeout_seconds": 5, + "retries": 40 + }, + "entrypoint_override": "explicit-official-image-command" + }, + "server": { + "vmid_offset": 0, + "hostname_template": "${stack_name}-server", + "image_ref": "server", + "ostype": "auto-detect-from-image", + "unprivileged": true, + "features": [ + "nesting=1" + ], + "resources": { + "cores": 4, + "memory_mb": 3072, + "swap_mb": 1024, + "rootfs_size_gb": 16 + }, + "network_interfaces": [ + { + "name": "eth0", + "role": "frontend", + "bridge_from": "frontend_network.bridge", + "ipv4_mode_from": "frontend_network.ipv4_mode", + "default_gateway": true + }, + { + "name": "eth1", + "role": "private", + "bridge_from": "private_network.bridge", + "address_from": "private_network.server_address", + "default_gateway": false + } + ], + "entrypoint": "tini -- /usr/local/bin/immich-lxc-start", + "working_directory": "/usr/src/app", + "halt_signal": "SIGTERM", + "startup": { + "order": 40, + "up_delay_seconds": 10, + "down_timeout_seconds": 30 + }, + "ports": [ + { + "port": 2283, + "protocol": "tcp", + "purpose": "web-ui-and-api" + } + ], + "mounts": [ + "media" + ], + "devices": [ + "video-render" + ], + "environment": { + "TZ": "${timezone}", + "CPU_CORES": "${services.server.resources.cores}", + "IMMICH_HOST": "0.0.0.0", + "IMMICH_PORT": "2283", + "DB_HOSTNAME": "${private_network.database_ip}", + "DB_PORT": "5432", + "DB_USERNAME": "${database.username}", + "DB_DATABASE_NAME": "${database.name}", + "DB_VECTOR_EXTENSION": "${database.vector_extension}", + "REDIS_HOSTNAME": "${private_network.valkey_ip}", + "REDIS_PORT": "6379", + "IMMICH_MACHINE_LEARNING_URL": "http://${private_network.machine_learning_ip}:3003", + "LIBVA_DRIVER_NAME": "${video_transcoding.driver}", + "DB_PASSWORD": "${generated.db_password}" + }, + "healthcheck": { + "type": "http", + "port": 2283, + "path": "/api/server/ping", + "expected_json": { + "res": "pong" + }, + "timeout_seconds": 5, + "retries": 60, + "start_period_seconds": 120 + }, + "entrypoint_override": "validated-lxc-network-readiness-adaptation" + } + }, + "storage": { + "media": { + "mode": "user-selectable", + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_storage_from": "rootfs_storage", + "managed_size_gb_default": 100, + "host_path_when_shared": "${shared_media_root}", + "container_path": "/data", + "service": "server", + "backup_by_mode": { + "managed-volume": true, + "host-bind": false + }, + "create_if_missing": true, + "shareable_with_other_lxc": true + }, + "database-data": { + "mode": "managed-volume", + "storage_from": "database_storage", + "size_gb_from": "database_size_gb", + "container_path": "/var/lib/postgresql/data", + "service": "database", + "backup": true, + "local_storage_required": true, + "network_filesystem_allowed": false, + "initialization": { + "data_subdirectory": "pgdata", + "reason": "Avoid PostgreSQL initialization failure caused by lost+found at the filesystem root.", + "owner_strategy": "resolve-postgres-uid-through-unprivileged-idmap", + "mode": "0700" + } + }, + "machine-learning-cache": { + "mode": "managed-volume", + "storage_from": "rootfs_storage", + "size_gb_from": "machine_learning.model_cache_size_gb", + "container_path": "/cache", + "service": "machine_learning", + "backup": true + }, + "valkey-data": { + "mode": "managed-volume", + "storage_from": "rootfs_storage", + "size_gb": 4, + "container_path": "/data", + "service": "redis", + "backup": true + } + }, + "devices": { + "video-render": { + "enabled_when": { + "field": "video_transcoding.acceleration", + "not_equals": "cpu" + }, + "host_path_from": "video_transcoding.render_device", + "container_path": "/dev/dri/renderD128", + "permissions": "rwm", + "mode": "0660", + "gid_strategy": "resolve-render-group-on-host", + "service": "server" + } + }, + "hardware_profiles": { + "video_transcoding": { + "cpu": { + "validated": false, + "devices": [] + }, + "vaapi": { + "validated": true, + "service": "server", + "devices": [ + "/dev/dri/renderD128" + ], + "supported_vendors": [ + "amd", + "intel", + "nvidia" + ], + "post_install_application_setting_required": true, + "application_setting": "Administration > Video transcoding > Hardware acceleration > VAAPI" + } + }, + "machine_learning": { + "cpu": { + "validated": true, + "image_ref": "machine_learning_cpu", + "devices": [], + "recognition_accelerated_by_hardware": false + }, + "rocm": { + "validated": false, + "validation_result_on_reference_host": "failed-gpu-reset", + "status": "experimental", + "image_ref": "machine_learning_rocm", + "vendor": "amd", + "provider": "MIGraphXExecutionProvider", + "devices": [ + { + "host_path": "/dev/kfd", + "container_path": "/dev/kfd", + "gid_strategy": "resolve-render-group-on-host" + }, + { + "host_path": "/dev/dri/renderD128", + "container_path": "/dev/dri/renderD128", + "gid_strategy": "resolve-render-group-on-host" + }, + { + "host_path": "/dev/dri/card0", + "container_path": "/dev/dri/card0", + "gid_strategy": "resolve-video-group-on-host" + } + ], + "recognition_accelerated_by_hardware": true, + "minimum_free_image_cache_gb": 35, + "preflight_checks": [ + "amdgpu-kernel-driver-loaded", + "dev-dri-present", + "dev-kfd-present", + "gpu-supported-by-rocm" + ], + "advanced_environment": { + "HSA_OVERRIDE_GFX_VERSION": null, + "HSA_USE_SVM": null + }, + "automatic_denylist": [ + { + "pci_id": "1002:164c", + "gpu": "AMD Lucienne integrated graphics", + "reason": "Real buffalo_l inference caused SDMA/compute timeouts and repeated host GPU resets.", + "tested_on": "2026-08-26" + } + ], + "warning": "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default." + }, + "openvino": { + "validated": false, + "status": "experimental", + "image_ref": "machine_learning_openvino", + "vendor": "intel", + "provider": "OpenVINOExecutionProvider", + "devices": [ + { + "host_path": "/dev/dri/renderD128", + "container_path": "/dev/dri/renderD128", + "gid_strategy": "resolve-render-group-on-host" + } + ], + "optional_devices": [ + "/dev/bus/usb" + ], + "device_cgroup_rules": [ + "c 189:* rmw" + ], + "recognition_accelerated_by_hardware": true, + "preflight_checks": [ + "intel-gpu-detected", + "dev-dri-present", + "kernel-supports-intel-gpu", + "openvino-provider-smoke-test" + ] + }, + "cuda": { + "validated": false, + "status": "experimental", + "image_ref": "machine_learning_cuda", + "vendor": "nvidia", + "provider": "CUDAExecutionProvider", + "device_strategy": "discover-and-pass-required-dev-nvidia-devices-and-driver-libraries", + "recognition_accelerated_by_hardware": true, + "preflight_checks": [ + "nvidia-gpu-compute-capability-at-least-5.2", + "nvidia-driver-version-at-least-545", + "nvidia-container-runtime-dependencies-present", + "cuda-provider-smoke-test" + ] + } + } + }, + "machine_learning_capabilities": { + "facial_recognition": { + "task": "facial-recognition", + "observed_model": "buffalo_l", + "pipeline": [ + "detection", + "recognition" + ], + "gpu_profiles": [ + "rocm", + "openvino", + "cuda" + ], + "configured_by": "Immich administration UI", + "installer_writes_application_setting": false + }, + "smart_search": { + "task": "clip", + "observed_model": "ViT-B-32__openai", + "pipeline": [ + "visual", + "textual" + ], + "gpu_profiles": [ + "rocm", + "openvino", + "cuda" + ], + "configured_by": "Immich administration UI", + "installer_writes_application_setting": false + }, + "validation_protocol": { + "ping_is_not_sufficient": true, + "required_steps": [ + "Verify the expected ONNX execution provider is available.", + "Run a real facial-recognition detection and embedding request.", + "Run visual and textual smart-search embeddings.", + "Observe GPU utilization during inference.", + "Reject the profile on provider fallback, HTTP 500, kernel timeout or GPU reset.", + "Keep the validated CPU ML service available until GPU validation passes." + ] + } + }, + "configuration_schema": { + "stack_name": { + "type": "string", + "required": true, + "default": "immich", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,31}$" + } + }, + "base_vmid": { + "type": "integer", + "required": false, + "default": null, + "description": "VMID of the server; the other three VMIDs are reserved using the template's offsets." + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "default": "local-lvm" + }, + "database_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "default": "local-lvm", + "validation": { + "must_be_local": true, + "network_filesystem_allowed": false + } + }, + "media_storage_mode": { + "type": "select", + "required": true, + "default": "managed-volume", + "options": [ + "managed-volume", + "host-bind" + ] + }, + "media_storage": { + "type": "storage-selector", + "required_when": { + "field": "media_storage_mode", + "equals": "managed-volume" + }, + "content_types": [ + "rootdir" + ], + "default": "local-lvm" + }, + "media_size_gb": { + "type": "integer", + "required_when": { + "field": "media_storage_mode", + "equals": "managed-volume" + }, + "default": 100, + "minimum": 8 + }, + "shared_media_root": { + "type": "host-directory", + "required_when": { + "field": "media_storage_mode", + "equals": "host-bind" + }, + "default": "/mnt/oci-shared/media/immich/${stack_name}", + "create_if_missing": true + }, + "database_size_gb": { + "type": "integer", + "required": true, + "default": 32, + "minimum": 8 + }, + "frontend_bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "frontend_ipv4_mode": { + "type": "select", + "required": true, + "default": "dhcp", + "options": [ + "dhcp", + "static" + ] + }, + "private_bridge": { + "type": "network-bridge", + "required": true, + "default": "vmbr10", + "create_if_missing": true + }, + "private_subnet": { + "type": "cidr", + "required": true, + "default": "10.77.0.0/24", + "validation": { + "must_be_rfc1918": true, + "must_not_overlap_existing_networks": true + } + }, + "video_transcoding_acceleration": { + "type": "select", + "required": true, + "default": "vaapi", + "options": [ + "cpu", + "vaapi" + ] + }, + "video_render_device": { + "type": "host-device-selector", + "required_when": { + "field": "video_transcoding_acceleration", + "equals": "vaapi" + }, + "default": "/dev/dri/renderD128", + "filter": "/dev/dri/renderD*" + }, + "vaapi_driver": { + "type": "select", + "required": false, + "default": "auto", + "options": [ + "auto", + "radeonsi", + "iHD", + "i965" + ] + }, + "machine_learning_acceleration": { + "type": "select", + "required": true, + "default": "cpu", + "options": [ + "cpu", + "rocm", + "openvino", + "cuda" + ], + "automatic_installer_options": [ + "cpu" + ], + "experimental_options": [ + "rocm", + "openvino", + "cuda" + ], + "warnings": { + "rocm": "Experimental and only for ROCm-compatible AMD GPUs. Requires /dev/dri, /dev/kfd and at least 35 GiB free for the image. PCI 1002:164c is denied automatically after a real GPU-reset failure.", + "openvino": "Experimental in native OCI LXC. Intended for compatible Intel GPUs and requires /dev/dri access.", + "cuda": "Experimental in native OCI LXC. Requires a supported NVIDIA GPU, driver 545 or newer and the required NVIDIA runtime devices and libraries." + } + }, + "timezone": { + "type": "timezone", + "required": true, + "default": "Europe/Madrid" + }, + "onboot": { + "type": "boolean", + "required": true, + "default": false + } + }, + "validated_profile": { + "id": "pve55-amd-vaapi-ml-cpu", + "description": "Reproducible profile based on a validated working deployment.", + "validated_on": "2026-08-27", + "validation_status": "passed-clean-import-managed-storage-coordinated-restart", + "host": { + "cpu": "AMD Ryzen 7 5700U", + "gpu": "AMD Lucienne integrated graphics", + "gpu_pci_id": "1002:164c", + "architecture": "amd64", + "video_render_device": "/dev/dri/renderD128", + "validated_render_gid": 993 + }, + "vmids": { + "server": 121, + "machine_learning": 122, + "database": 123, + "valkey": 124 + }, + "network": { + "frontend_bridge": "vmbr0", + "private_bridge": "vmbr10", + "private_subnet": "10.77.0.0/24", + "database_and_valkey_private_only": true + }, + "acceleration": { + "video_transcoding": "vaapi-amd", + "vaapi_h264_encode": "passed", + "machine_learning": "cpu", + "machine_learning_hardware_acceleration": false, + "safe_machine_learning_default": "cpu", + "rocm_on_ryzen_5700u": "failed-unsafe-gpu-reset" + }, + "storage": { + "validated_live_profile": { + "media": "host-bind,backup=0", + "database": "managed-volume,backup=1", + "secrets": "none-compose-environment-model", + "machine_learning_cache": "managed-volume,backup=0", + "valkey": "rootfs-only,ephemeral" + }, + "template_target_model": { + "media": "managed-volume,backup=1 or host-bind,backup=0 selected at installation", + "database": "managed-volume,backup=1", + "valkey": "rootfs-only,ephemeral", + "machine_learning_cache": "managed-volume,backup=0" + }, + "target_model_live_migration": "passed" + }, + "validation": { + "api_ping": "passed", + "web_ui": "passed", + "version": "3.1.0", + "database_public_tables": 66, + "database_persistence": "passed-coordinated-restart", + "native_vzdump_database_inclusion": "configured-backup-1-not-yet-restored", + "machine_learning_ping": "passed", + "rocm_provider_available": "MIGraphXExecutionProvider", + "rocm_test_vmid": 127, + "rocm_test_private_ip": "10.77.0.14", + "rocm_buffalo_l_face_inference": "failed-http-500", + "rocm_gpu_busy_max_percent": 85, + "rocm_host_gpu_reset_observed": true, + "rocm_post_stop_gpu_busy_percent": 99, + "rocm_post_stop_gpu_clock_mhz": 1900, + "rocm_post_stop_memory_clock_mhz": 1200, + "rocm_post_stop_gpu_power_watts": 25, + "rocm_post_stop_gpu_temperature_celsius": 57, + "rocm_post_stop_device_users": 0, + "rocm_host_reboot_recommended": true, + "vaapi_after_rocm_reset": "passed", + "coordinated_restart": "passed", + "historical_custom_valkey_authentication": "passed", + "historical_custom_valkey_unauthenticated_rejection": "passed", + "target_compose_environment_translation": "passed", + "database_data_checksums": "on", + "database_extensions": "cube,earthdistance,pg_trgm,plpgsql,unaccent,uuid-ossp,vchord,vector", + "database_managed_volume_backup_flag": "passed", + "machine_learning_profile": "cpu", + "machine_learning_mimalloc_path": "/usr/lib/libmimalloc.so.2", + "machine_learning_mimalloc_path_validation": "passed", + "vaapi_h264_encode": "passed-encoder-present", + "vaapi_hevc_encode": "passed-encoder-present", + "media_write": "passed", + "runtime_environment_uniqueness": "passed", + "private_dependency_network": "passed" + }, + "previous_validation_status": "passed-historical-profile-target-compose-translation-pending-live-migration", + "validated_lxc_adapted_profile": { + "server_entrypoint": "tini -- /usr/local/bin/immich-lxc-start", + "database_private_listen": true, + "custom_host_services": false, + "validation": "passed-clean-import-managed-storage", + "server_route_detection": "/proc/net/route", + "requires_iproute2": false, + "database_entrypoint": "/usr/local/bin/immich-docker-entrypoint.sh" + }, + "candidate_direct_image_profile": { + "entrypoints": "from-oci-image-config", + "custom_rootfs_files": false, + "validation": "pending-clean-import-and-route-race-test" + } + }, + "backup_restore": { + "native_proxmox_backup": true, + "coordinated_stack_backup_required": true, + "included_managed_volumes": [ + "database-data" + ], + "excluded_volumes": [ + "machine-learning-cache" + ], + "external_backup_required": [ + "media" + ], + "application_consistency": { + "preferred_mode": "stop", + "stop_order": [ + "server", + "machine_learning", + "valkey", + "database" + ], + "logical_database_backup": { + "required": true, + "method": "pg_dump", + "store_outside_database_volume": true + } + }, + "restore_order": [ + "restore-all-four-lxc-backups-from-the-same-backup-set", + "verify-shared-media-host-path", + "start-database", + "start-valkey", + "start-machine-learning", + "start-server", + "wait-for-all-healthchecks" + ] + }, + "boundaries": { + "bundles_internal_immich_configuration": false, + "bundles_credentials": false, + "bundles_user_accounts": false, + "bundles_user_photos_or_videos": false, + "installer_generates_credentials": true, + "installer_must_not_write_immich_application_settings": true, + "installer_must_not_enable_unvalidated_gpu_ml_automatically": true, + "installer_must_enforce_gpu_compatibility_denylist": true, + "installer_must_fallback_to_cpu_after_gpu_validation_failure": false + }, + "notes": [ + "Esta plantilla describe la infraestructura OCI necesaria para instalar Immich; no contiene la configuracion interna de la aplicacion ni datos de usuario.", + "El servidor y machine learning usan dos interfaces; PostgreSQL y Valkey solo usan la red privada.", + "VAAPI acelera la transcodificacion de video, no el reconocimiento facial ni la busqueda inteligente.", + "El perfil ML CPU es el unico perfil seguro y validado en el Ryzen 7 5700U del laboratorio.", + "ROCm puede acelerar reconocimiento facial y busqueda inteligente en GPU AMD compatibles, pero la Lucienne PCI 1002:164c fallo con un reset real de GPU y queda bloqueada para activacion automatica.", + "Tras el fallo ROCm, la GPU Lucienne mantuvo frecuencias y consumo elevados sin procesos asociados; el instalador debe detener las pruebas y recomendar un reinicio del host.", + "OpenVINO para Intel y CUDA para NVIDIA estan declarados como opciones futuras, pero deben superar una inferencia real antes de sustituir al perfil CPU.", + "La base de datos debe permanecer en almacenamiento local; no debe ubicarse en NFS, SMB ni otro recurso de red.", + "New installations use managed backup=1 volumes for PostgreSQL, Valkey /data and the reproducible ML cache; old laboratory layouts are not silently migrated.", + "DB_PASSWORD from the official Immich .env is represented directly in lxc.environment.runtime and is therefore visible in PVE configuration, matching Docker inspection behavior.", + "La biblioteca multimedia puede utilizar un host-bind compartible, pero necesita una estrategia de backup independiente del LXC.", + "El despliegue OCI nativo dentro de LXC es experimental y no es el metodo de instalacion recomendado oficialmente por Immich.", + "La instalacion limpia del 2026-08-27 valido los CT121-124, PostgreSQL en volumen administrado backup=1, cache ML administrada, red privada, reinicio coordinado, VAAPI y la ruta oficial de mimalloc." + ], + "credentials": { + "model": "compose-environment", + "pve_visibility": "visible-by-design", + "explanation": "The DB_PASSWORD value from the official .env is generated or requested by the installer and translated to lxc.environment.runtime. PostgreSQL receives the same value as POSTGRES_PASSWORD.", + "db_password": { + "generator": "openssl-rand-alphanumeric", + "characters": 48, + "allowed_characters": "A-Za-z0-9", + "targets": [ + "services.server.environment.DB_PASSWORD", + "services.database.environment.POSTGRES_PASSWORD" + ], + "verify_identical_values": true + }, + "valkey_password": { + "enabled": false, + "reason": "The official Immich v3.1.0 Compose runs Valkey without authentication on its private network." + }, + "application_accounts": { + "managed_by": "Immich", + "storage": "Immich application database", + "template_contains_accounts": false + } + }, + "generated_assets": { + "server-network-wrapper": { + "target_service": "server", + "target_path": "/usr/local/bin/immich-lxc-start", + "mode": "0755", + "purpose": "Wait for the host-managed frontend default route through /proc/net/route before executing the image-provided command.", + "timeout_seconds": 60, + "post_route_delay_seconds": 3, + "official_final_command": "/bin/bash -c start.sh", + "validation": "passed on clean import in CT121", + "route_detection": "grep -qE '^eth0[[:space:]]+00000000[[:space:]]' /proc/net/route", + "requires_iproute2": false + }, + "postgres-listen-runtime": { + "target_service": "database", + "type": "proxmox-entrypoint-argument", + "value": "/usr/local/bin/immich-docker-entrypoint.sh postgres -c config_file=/etc/postgresql/postgresql.conf -c listen_addresses=127.0.0.1,${private_network.database_ip}", + "purpose": "Bind PostgreSQL only to loopback and the private stack address on every start.", + "validation": "passed on clean import in CT123" + } + }, + "translation_contract": { + "id": "docker-compose-to-proxmox-oci-lxc", + "version": "1.1.0", + "file": "docker-oci-translation-policy.json" + }, + "docker_compatibility": { + "policy": "preserve-upstream-compose-contract", + "upstream_reference": "https://github.com/immich-app/immich/releases/download/v3.1.0/docker-compose.yml", + "mapping": { + "compose_env_file": "lxc.environment.runtime", + "compose_environment": "lxc.environment.runtime", + "upload_bind": "host-bind:/data,backup=0", + "database_bind": "managed-volume:/var/lib/postgresql/data,backup=1", + "model_cache_named_volume": "managed-volume:/cache,backup=1", + "redis_storage": "managed-volume:/data,backup=1", + "credential_visibility": "visible-in-pve-config-by-design", + "model_cache_environment": "preserve-official-LD_PRELOAD=/usr/lib/libmimalloc.so.2" + }, + "adaptations": [ + { + "id": "private-service-addresses", + "upstream_behavior": "Compose service names provide internal DNS discovery.", + "native_lxc_behavior": "Use fixed addresses on a private Proxmox bridge.", + "reason": "The services run in separate native LXC containers without a Compose DNS network.", + "behavioral_impact": "none" + }, + { + "id": "database-managed-volume", + "upstream_behavior": "DB_DATA_LOCATION bind-mounts PostgreSQL data from the Docker host.", + "native_lxc_behavior": "Attach a local managed Proxmox volume at the same container path with backup enabled.", + "reason": "The database is private to its LXC and must participate in native Proxmox backup.", + "behavioral_impact": "storage-management-only" + }, + { + "id": "server-route-wait", + "upstream_behavior": "Docker creates the service network and route before starting the server process.", + "native_lxc_behavior": "A minimal wrapper reads the eth0 default route from /proc/net/route before executing the official server command.", + "reason": "The DHCP frontend route can appear after PID 1 starts in a native OCI LXC.", + "behavioral_impact": "startup-only", + "validation": "passed in CT121; the image intentionally does not include iproute2" + }, + { + "id": "postgres-private-listen", + "upstream_behavior": "PostgreSQL listens on the private Compose network.", + "native_lxc_behavior": "Preserve /usr/local/bin/immich-docker-entrypoint.sh and the official PostgreSQL config_file argument, then append listen_addresses for loopback and the fixed private LXC address.", + "reason": "The database must be reachable from the server LXC without a frontend interface.", + "behavioral_impact": "equivalent-private-reachability", + "validation": "passed in CT123 on clean import" + } + ] + }, + "proxmox_oci_contract": { + "policy": "docker-compose-to-proxmox-oci-lxc", + "version": "1.1.0", + "preserve_official_application_contract": true, + "documented_lxc_adaptations": "allowed-when-required-and-validated", + "candidate_simplifications": "must-pass-equivalent-tests-before-replacement" + }, + "historical_release": { + "version": "v3.1.0", + "validated_on": "2026-08-27", + "note": "Historical validation only; catalog installation resolves rolling latest images." + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "depends_on", + "environment", + "healthcheck", + "image", + "ports", + "restart", + "shm_size", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The native four-LXC installer and coordinated update adapter support CPU, Intel OpenVINO and NVIDIA CUDA. Real rootfs replacement and full native-backup rollback with GPU inference passed on documented Intel/NVIDIA hardware. A real v3.1.0 to v3.2.2 upgrade and rollback also passed on Intel, preserving a laboratory account and synthetic asset. Not universal GPU or arbitrary release-transition validation; ROCm remains pending." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-historical-profile-2026-08-27", + "service_health": "passed-historical-profile", + "restart_persistence": "passed-coordinated-restart", + "backup_restore": "passed-four-member-native-backup-restore", + "update_preserves_data": "passed-real-v3.1.0-to-v3.2.2-coordinated-upgrade-and-rollback-intel", + "historical_version": "3.1.0", + "historical_profile": "pve55-amd-vaapi-ml-cpu", + "private_dependency_network": "passed", + "postgres_local_managed_volume": "passed", + "machine_learning_cpu": "passed", + "video_transcoding_vaapi_amd": "passed", + "machine_learning_openvino": "passed-dedicated-native-stack-synthetic-inference-and-principal-restart", + "machine_learning_cuda": "passed-dedicated-native-stack-dynamic-toolkit-synthetic-inference-and-principal-restart", + "native_ml_gpu_lab_20260918": { + "evidence": "docs/lab/immich-native-gpu-20260918/README.md", + "environment": "Native OCI through the shared installer on Proxmox .50", + "intel": { + "cpu_allocation": "quota", + "four_model_inferences": "passed on GPU.0", + "http_predict": "passed initially and after three shutdown/start cycles", + "cpuset_profile": "intermittent SIGSEGV; original CPU set reproduced failure" + }, + "nvidia": { + "runtime": "dynamic NVIDIA Container Toolkit", + "four_model_inferences": "passed with CUDA execution", + "http_predict": "passed initially and after shutdown/start" + }, + "scope": "Synthetic tensors and JPEG; no accuracy benchmark or sustained library workload", + "dedicated_stack_gpu_integration": "pending", + "coordinated_update_validation": "pending" + }, + "gpu_lab_20260915": { + "environment": "Docker inside unprivileged Debian 13 LXC on Proxmox 9.0.6; not native OCI", + "immich_version": "v3.2.2", + "intel": { + "pci_id": "8086:46a3", + "gpu": "Alder Lake-P GT1 UHD Graphics", + "image_digest": "sha256:4013ec28ccf6344d7ae24554743a116d7f61124b98858f5646a401d5c5df12e2", + "provider": "OpenVINOExecutionProvider", + "device": "GPU.0", + "four_model_inferences": "passed; profiled inference nodes on OpenVINO GPU" + }, + "nvidia": { + "pci_id": "10de:1cb1", + "gpu": "Quadro P1000 4GB", + "driver": "580.178.04", + "image_digest": "sha256:38001e84ce46206e9e019d8ee7f567bf55914f019dff8f6a70d02fd93bb14073", + "provider": "CUDAExecutionProvider", + "four_model_inferences": "passed; CUDA execution confirmed, auxiliary CPU nodes in detection and text" + }, + "models": [ + "buffalo_l detection", + "buffalo_l recognition", + "ViT-B-32__openai visual", + "ViT-B-32__openai textual" + ], + "inputs": "Synthetic tensors, synthetic JPEG and text; no personal photographs", + "http_predict": "Text and synthetic-image requests passed on both backends; synthetic image contains no faces", + "limitations": [ + "Not a recognition-accuracy benchmark", + "Not native OCI validation", + "Not universal GPU compatibility", + "No long-running library workload" + ], + "tested_thread_environment": { + "MACHINE_LEARNING_MODEL_INTRA_OP_THREADS": "2", + "MACHINE_LEARNING_MODEL_INTER_OP_THREADS": "1" + }, + "thread_environment_reason": "Avoid ONNX automatic CPU-affinity warnings within the LXC cpuset; no image patches", + "evidence": "docs/lab/immich-gpu-20260915/README.md" + }, + "machine_learning_rocm_amd_lucienne_1002_164c": "failed-unsafe-gpu-reset-auto-denied", + "rolling_latest": "passed-release-channel-v3.1.0-to-v3.2.2-intel", + "native_stack_gpu_20260918": { + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md", + "intel": "8086:46a3; quota 4; RAM 8192 MiB", + "nvidia": "Quadro P1000; dynamic Container Toolkit; cores 4; RAM 8192 MiB", + "scope": "Four real ML models with synthetic inputs, HTTP inference, server-to-ML private-network requests, principal and ML restart, saved profile recipes", + "exclusions": [ + "Full photo-library workflow and recognition accuracy", + "Host reboot", + "Coordinated stack image updates", + "Universal GPU compatibility" + ] + }, + "coordinated_update_20260918": { + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md", + "intel_vmids": [ + 9821, + 9822, + 9823, + 9824 + ], + "nvidia_vmids": [ + 9831, + 9832, + 9833, + 9834 + ], + "replacement": "passed", + "injected_failure_full_rollback": "passed", + "persistent_data": "library/cache markers, PostgreSQL row, persisted Valkey value", + "gpu": "four real models with synthetic inputs after update and rollback on both backends", + "scope": "Same registry digests; cross-release migration not yet validated" + }, + "cross_release_upgrade_20260918": { + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md", + "source_version": "v3.1.0", + "target_version": "v3.2.2", + "vmids": [ + 9841, + 9842, + 9843, + 9844 + ], + "acceleration": "Intel OpenVINO", + "update": "passed", + "rollback": "passed-after-upgraded-principal-healthcheck", + "application_data": "Laboratory account and synthetic JPEG; identical asset ID/checksum; original download verified after upgrade", + "persistent_data": "Library/cache markers, PostgreSQL row and persisted Valkey value", + "gpu": "Four real models with synthetic inputs before upgrade, after rollback and after committed upgrade", + "scope": "Specific release transition on documented Intel hardware; not arbitrary version jumps or NVIDIA cross-release migration" + } + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-official-compose-and-resolved-latest-digests-for-all-four-images", + "automatic_unattended_updates": false, + "coordinated_stack_required": true, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "starts_stopped_dependencies": true, + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false, + "persistent_contract": "/etc/pve/priv/proxmenux-stack-.json", + "runtime_owner": "proxmox-ve" + }, + "start_order": [ + "database", + "redis", + "immich-machine-learning", + "immich-server" + ], + "stop_order": [ + "immich-server", + "immich-machine-learning", + "redis", + "database" + ], + "backup": { + "native_proxmox_backup": true, + "coordinated_stack_backup_required": true, + "included_managed_volumes": [ + "database-data" + ], + "excluded_volumes": [ + "machine-learning-cache" + ], + "external_backup_required": [ + "media" + ], + "application_consistency": { + "preferred_mode": "stop", + "stop_order": [ + "server", + "machine_learning", + "valkey", + "database" + ], + "logical_database_backup": { + "required": true, + "method": "pg_dump", + "store_outside_database_volume": true + } + }, + "restore_order": [ + "restore-all-four-lxc-backups-from-the-same-backup-set", + "verify-shared-media-host-path", + "start-database", + "start-valkey", + "start-machine-learning", + "start-server", + "wait-for-all-healthchecks" + ] + }, + "gpu_profile_failure_policy": { + "stop_failed_machine_learning_lxc": true, + "preserve_failure_metadata_without_secrets": true, + "record_gpu_pci_id_and_driver": true, + "stop_further_gpu_tests_after_kernel_timeout_or_reset": true, + "recommend_host_reboot_when_gpu_clocks_or_power_do_not_return_to_idle": true, + "automatic_hsa_override_retry": false, + "fallback_profile": "cpu", + "reuse_model_cache_when_compatible": true, + "start_server_only_after_cpu_fallback_is_healthy": true + }, + "uninstall": { + "remove_rootfs": true, + "preserve_media_by_default": true, + "preserve_database_by_default": true, + "remove_private_bridge_only_if_unused": true + } + } +} diff --git a/oci/catalog/apps/index-tts.json b/oci/catalog/apps/index-tts.json new file mode 100644 index 00000000..b6cf6b4a --- /dev/null +++ b/oci/catalog/apps/index-tts.json @@ -0,0 +1,423 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-index-tts", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Index-TTS" + }, + "tagline": { + "en_US": "An Industrial-Level Controllable and Efficient Zero-Shot Text-To-Speech System" + }, + "description": { + "en_US": "IndexTTS2 is an advanced zero-shot text-to-speech model that innovatively achieves complete decoupling of emotional expression and speaker identity. The model supports precise speech duration control and multimodal emotion control, capable of maintaining the target timbre while accurately reproducing the specified emotional intonation.\n\nThe model employs a three-stage training paradigm and introduces GPT latent representations, ensuring excellent speech clarity and stability even under high emotional expression. Through the Qwen-based soft instruction mechanism, users can easily control the emotional characteristics of generated speech using natural language descriptions.\n\nIn multi-dataset evaluations, IndexTTS2 surpasses existing zero-shot TTS models in key metrics such as word error rate, speaker similarity, and emotion fidelity, providing industry-leading speech synthesis quality.\n\n**Key Features:**\n- Zero-shot TTS capability to replicate any timbre without training\n- Independent control of emotion and timbre with multimodal emotion input\n- Precise duration control with explicit token count specification for perfect audio-video synchronization\n- Natural language-based emotion control to guide speech generation through text descriptions\n\n**Additional Notes:**\n- Please ensure available memory > 12 GB, otherwise the application may not run properly\n- This application runs on CPU by default. This mode has low computational efficiency and will cause extremely high resource consumption and potential system instability. For optimal performance and stability, it is strongly recommended to use NVIDIA GPU to run this application\n- If you need to use NVIDIA GPU, please select \"Custom Install\" and enable the GPU option (supported in self-hosted server 1.5.0 and above)\n- For NVIDIA GPU usage, ≥ 8 GB VRAM is required (recommended for optimal performance)\n- For NVIDIA GPU usage, NVIDIA CUDA Toolkit version ≥ 12.8 is required\n\n**Learn More:**\n- [IndexTTS GitHub](https://github.com/index-tts/index-tts)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "icewhaletech", + "developer": "icewhaletech", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 7860, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/icewhaletech/index-tts", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "icewhaletech", + "repository": "https://hub.docker.com/r/icewhaletech/index-tts", + "revision": "bf0a2682da76346567fd3a21166d78a5b0f86364b4761f0fe935dfd27693e863", + "image_repository_url": "https://hub.docker.com/r/icewhaletech/index-tts", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "bf0a2682da76346567fd3a21166d78a5b0f86364b4761f0fe935dfd27693e863", + "generated_at": "2026-09-13T20:38:07+00:00" + }, + "container_contract": { + "service_name": "index-tts", + "container_name": "index-tts", + "image": { + "reference": "icewhaletech/index-tts:latest", + "registry": "docker.io", + "repository": "icewhaletech/index-tts", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [ + { + "container_port": 7860, + "published_example": 17869, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: index-tts\nservices:\n index-tts:\n image: icewhaletech/index-tts:latest\n container_name: index-tts\n restart: unless-stopped\n ports:\n - target: 7860\n published: '17869'\n protocol: tcp\n deploy:\n resources:\n reservations:\n memory: 12G\n" + }, + "compose_stack": { + "project_name": "index-tts", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "index-tts", + "service_count": 1, + "services": [ + { + "name": "index-tts", + "image": "icewhaletech/index-tts:2.0", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "icewhaletech/index-tts:2.0", + "container_name": "index-tts", + "restart": "unless-stopped", + "ports": [ + { + "target": 7860, + "published": "17869", + "protocol": "tcp" + } + ], + "deploy": { + "resources": { + "reservations": { + "memory": "12G" + } + } + } + } + } + ], + "top_level": { + "name": "index-tts" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "index-tts" + ], + "stop_order": [ + "index-tts" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7860, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 12288, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Execution engine for Index-TTS", + "default": "cpu", + "profiles": [ + { + "id": "cpu", + "label": "CPU", + "device_requests": [] + }, + { + "id": "nvidia", + "label": "NVIDIA (CUDA)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ] + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/inkscape.json b/oci/catalog/apps/inkscape.json new file mode 100644 index 00000000..9b0025ea --- /dev/null +++ b/oci/catalog/apps/inkscape.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-inkscape", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Inkscape" + }, + "tagline": { + "en_US": "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers." + }, + "description": { + "en_US": "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/inkscape-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/inkscape-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://inkscape.org/", + "documentation": "https://docs.linuxserver.io/images/docker-inkscape/", + "repository": "https://github.com/linuxserver/docker-inkscape", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-inkscape", + "default_branch": "master", + "revision": "404f58ec50e8da8f3589d1c3be573f68d3fae338", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-inkscape/404f58ec50e8da8f3589d1c3be573f68d3fae338/README.md", + "readme_pushed_at": "2026-09-10T01:54:59Z", + "compose_sha256": "9c54a692e0d022eef24170ac0777a291d1b75405c88648b401dfe030ecb18140", + "generated_at": "2026-09-12T14:37:28+00:00" + }, + "container_contract": { + "service_name": "inkscape", + "container_name": "inkscape", + "image": { + "reference": "lscr.io/linuxserver/inkscape:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/inkscape", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n inkscape:\n image: lscr.io/linuxserver/inkscape:latest\n container_name: inkscape\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-inkscape/master/Dockerfile", + "dockerfile_sha256": "b7cee51c2f2cbc7a547b603b225dbed48b39154d3521f500757d6ae02d00992e", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/intellij-idea.json b/oci/catalog/apps/intellij-idea.json new file mode 100644 index 00000000..a2098ade --- /dev/null +++ b/oci/catalog/apps/intellij-idea.json @@ -0,0 +1,272 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-intellij-idea", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Intellij Idea" + }, + "tagline": { + "en_US": "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters \u2013 building great software." + }, + "description": { + "en_US": "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters \u2013 building great software." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/intellij-idea-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/intellij-idea-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.jetbrains.com/idea/", + "documentation": "https://docs.linuxserver.io/images/docker-intellij-idea/", + "repository": "https://github.com/linuxserver/docker-intellij-idea", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-18", + "note": "Remove aarch64 support as it has been dropped upstream." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-02-18", + "note": "Change aarch64 version to best effort." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-12-02", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-05-18" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-intellij-idea", + "default_branch": "master", + "revision": "7d141e328f82a9be07cd3822eca6e834efb0eaa1", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-intellij-idea/7d141e328f82a9be07cd3822eca6e834efb0eaa1/README.md", + "readme_pushed_at": "2026-09-06T21:23:59Z", + "compose_sha256": "c2bbff438294e2b34a3fd3d931dbcd8000a52675bc431b17d7ddd95eb2b6d2fc", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "intellij-idea", + "container_name": "intellij-idea", + "image": { + "reference": "lscr.io/linuxserver/intellij-idea:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/intellij-idea", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n intellij-idea:\n image: lscr.io/linuxserver/intellij-idea:latest\n container_name: intellij-idea\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/jackett.json b/oci/catalog/apps/jackett.json new file mode 100644 index 00000000..46fe6218 --- /dev/null +++ b/oci/catalog/apps/jackett.json @@ -0,0 +1,271 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-jackett", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Jackett" + }, + "tagline": { + "en_US": "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps." + }, + "description": { + "en_US": "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jackett-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jackett-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9117, + "path": "/" + }, + "website": "https://github.com/Jackett/Jackett", + "documentation": "https://docs.linuxserver.io/images/docker-jackett/", + "repository": "https://github.com/linuxserver/docker-jackett", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-14", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-07-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-12", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-11", + "note": "Rebase to Alpine 3.19. Deprecate development tag as upstream is publishing nightly stable releases." + } + ], + "display_version": null, + "updated_at": "2026-07-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-jackett", + "default_branch": "master", + "revision": "4d5bde8a2a2c5d29d5642229ce245f8dff18e71b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-jackett/4d5bde8a2a2c5d29d5642229ce245f8dff18e71b/README.md", + "readme_pushed_at": "2026-09-12T09:45:50Z", + "compose_sha256": "f0152856854610a5581bed157d4a4d5e23e6fc1a1efc3ac1050c1344a06e2521", + "generated_at": "2026-09-12T14:37:28+00:00" + }, + "container_contract": { + "service_name": "jackett", + "container_name": "jackett", + "image": { + "reference": "lscr.io/linuxserver/jackett:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/jackett", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "AUTO_UPDATE", + "example": "true", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RUN_OPTS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/jackett/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/blackhole", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 9117, + "published_example": 9117, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n jackett:\n image: lscr.io/linuxserver/jackett:latest\n container_name: jackett\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - AUTO_UPDATE=true #optional\n - RUN_OPTS= #optional\n volumes:\n - /path/to/jackett/data:/config\n - /path/to/blackhole:/downloads\n ports:\n - 9117:9117\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9117, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/jdownloader.json b/oci/catalog/apps/jdownloader.json new file mode 100644 index 00000000..6eb741f7 --- /dev/null +++ b/oci/catalog/apps/jdownloader.json @@ -0,0 +1,1017 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-jdownloader", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "JDownloader" + }, + "tagline": { + "en_US": "JDownloader 2 with browser GUI and MyJDownloader support" + }, + "description": { + "en_US": "The maintained jlesage JDownloader 2 image adapted as a native Proxmox OCI LXC with persistent configuration and shared downloads." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "jlesage", + "developer": "jlesage", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 5800, + "path": "/" + }, + "website": "https://jdownloader.org/", + "documentation": "https://github.com/jlesage/docker-jdownloader-2", + "repository": "https://github.com/jlesage/docker-jdownloader-2", + "tips": [ + "JDownloader 2 is the current application name; this curated entry replaces the duplicate jdownloader2 discovery entry.", + "Web authentication requires HTTPS unless the explicitly insecure upstream override is selected." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-26" + }, + "source": { + "provider": "jlesage", + "repository": "https://github.com/jlesage/docker-jdownloader-2", + "revision": "5b7968aaa112f1a8ab8ecc81bd65265bd6ca7423216ee8e32f77e46c0d5b4569", + "image_repository_url": "https://hub.docker.com/r/jlesage/jdownloader-2", + "readme_pushed_at": "2026-08-26T22:06:48Z", + "compose_sha256": "5b7968aaa112f1a8ab8ecc81bd65265bd6ca7423216ee8e32f77e46c0d5b4569", + "generated_at": "2026-09-12T15:54:10+00:00", + "default_branch": "master" + }, + "container_contract": { + "service_name": "jdownloader", + "container_name": "jdownloader", + "image": { + "reference": "jlesage/jdownloader-2:latest", + "registry": "docker.io", + "repository": "jlesage/jdownloader-2", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USER_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "GROUP_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "UMASK", + "example": "002", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "VNC_LOCALHOST_ONLY", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WEB_AUTHENTICATION", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WEB_AUTHENTICATION_USERNAME", + "example": "admin", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WEB_AUTHENTICATION_PASSWORD", + "example": "${GENERATED_WEB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "SECURE_CONNECTION", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "jdownloader-config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/output", + "compose_source_example": "/mnt/oci-shared/downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5800, + "published_example": 5800, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3129, + "published_example": 3129, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: jdownloader\nservices:\n jdownloader:\n image: jlesage/jdownloader-2:latest\n environment:\n USER_ID: '1000'\n GROUP_ID: '1000'\n UMASK: '002'\n TZ: Etc/UTC\n VNC_LOCALHOST_ONLY: '1'\n WEB_AUTHENTICATION: '1'\n WEB_AUTHENTICATION_USERNAME: admin\n WEB_AUTHENTICATION_PASSWORD: ${GENERATED_GENERATED_WEB_PASSWORD}\n SECURE_CONNECTION: '1'\n ports:\n - 5800:5800\n - 3129:3129\n volumes:\n - jdownloader-config:/config\n - /mnt/oci-shared/downloads:/output\n restart: unless-stopped\nvolumes:\n jdownloader-config: {}\n" + }, + "compose_stack": { + "project_name": "jdownloader", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "jdownloader", + "service_count": 1, + "services": [ + { + "name": "jdownloader", + "image": "jlesage/jdownloader-2:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/jdownloader-2:latest", + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "UMASK": "002", + "TZ": "Etc/UTC", + "VNC_LOCALHOST_ONLY": "1", + "WEB_AUTHENTICATION": "1", + "WEB_AUTHENTICATION_USERNAME": "admin", + "WEB_AUTHENTICATION_PASSWORD": "${GENERATED_GENERATED_WEB_PASSWORD}", + "SECURE_CONNECTION": "1" + }, + "ports": [ + "5800:5800", + "3129:3129" + ], + "volumes": [ + "jdownloader-config:/config", + "/mnt/oci-shared/downloads:/output" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "jdownloader", + "volumes": { + "jdownloader-config": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "jdownloader-volume-0", + "service": "jdownloader", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "jdownloader-volume-1", + "service": "jdownloader", + "container_path": "/output", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "jdownloader" + ], + "stop_order": [ + "jdownloader" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "generated-web-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "jdownloader", + "environment_variable": "WEB_AUTHENTICATION_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "JDownloader WebUI", + "scheme": "https", + "port": 5800, + "path": "/", + "source": "upstream-jlesage-readme" + } + ], + "credentials": [ + { + "label": "JDownloader WebUI", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "WEB_AUTHENTICATION_USERNAME", + "password_environment": "WEB_AUTHENTICATION_PASSWORD", + "change_required": true, + "source": "official-image-environment", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "jdownloader2" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image-then-apply-reviewed-lxc-wrapper", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-user-values", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "persistent-config-volume-preparation", + "upstream_behavior": "Docker bind mounts an initially empty directory at /config.", + "native_lxc_behavior": "Create a managed volume at /config, remove its empty lost+found and apply the unprivileged UID mapping before first start.", + "reason": "The image expects /config to be writable by USER_ID/GROUP_ID.", + "behavioral_impact": "Configuration remains included in native Proxmox backups.", + "validation": "passed-laboratory-profile" + }, + { + "id": "secure-web-authentication", + "upstream_behavior": "WEB_AUTHENTICATION requires SECURE_CONNECTION unless the insecure override is enabled.", + "native_lxc_behavior": "Generate a password and enable HTTPS together; expose the self-signed-certificate warning at first run.", + "reason": "The upstream image disables secure sign-in over plain HTTP.", + "behavioral_impact": "The first browser visit must trust the generated certificate or use a reverse proxy.", + "validation": "passed-https-login-laboratory-profile" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "commands": [ + "pct", + "pvesm", + "skopeo", + "curl" + ], + "features": [ + "native-oci-lxc", + "managed-volume-backup" + ] + }, + "configuration_schema": { + "vmid": { + "type": "integer", + "required": false, + "default": null + }, + "hostname": { + "type": "string", + "required": true, + "default": "jdownloader", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,62}$" + } + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ] + }, + "rootfs_size_gb": { + "type": "integer", + "required": true, + "default": 8, + "minimum": 4 + }, + "config_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "description": "Volumen gestionado por Proxmox para /config e incluido en vzdump." + }, + "config_size_gb": { + "type": "integer", + "required": true, + "default": 4, + "minimum": 2 + }, + "downloads_host_path": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared/downloads", + "create_if_missing": true + }, + "management_mode": { + "type": "select", + "required": true, + "default": "myjdownloader-headless", + "options": [ + "myjdownloader-headless", + "web-gui" + ] + }, + "myjdownloader_email": { + "type": "email", + "required_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + }, + "sensitive": true, + "pve_visibility": "visible-by-design" + }, + "myjdownloader_password": { + "type": "password", + "required_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + }, + "sensitive": true, + "pve_visibility": "visible-by-design" + }, + "myjdownloader_device_name": { + "type": "string", + "required": true, + "default": "ProxMenux-JDownloader" + }, + "direct_connect_enabled": { + "type": "boolean", + "required": true, + "default": false, + "description": "No abre puertos en el router; solo declara el puerto local 3129." + }, + "web_authentication_enabled": { + "type": "boolean", + "required_when": { + "field": "management_mode", + "equals": "web-gui" + }, + "default": true + }, + "secure_connection_enabled": { + "type": "boolean", + "required_when": { + "field": "management_mode", + "equals": "web-gui" + }, + "default": true, + "description": "Activa HTTPS. Debe permanecer habilitado cuando web_authentication_enabled sea true porque la imagen oficial deshabilita el formulario de acceso sobre HTTP." + }, + "web_username": { + "type": "string", + "required_when": { + "field": "web_authentication_enabled", + "equals": true + }, + "default": "admin" + }, + "web_password": { + "type": "password", + "required_when": { + "field": "web_authentication_enabled", + "equals": true + }, + "generate_when_empty": true, + "sensitive": true, + "pve_visibility": "visible-by-design" + }, + "user_id": { + "type": "integer", + "required": true, + "default": 1000, + "minimum": 1 + }, + "group_id": { + "type": "integer", + "required": true, + "default": 1000, + "minimum": 1 + }, + "cores": { + "type": "integer", + "required": true, + "default": 2, + "minimum": 1 + }, + "memory_mb": { + "type": "integer", + "required": true, + "default": 2048, + "minimum": 1024 + }, + "swap_mb": { + "type": "integer", + "required": true, + "default": 512, + "minimum": 0 + }, + "bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "ipv4_mode": { + "type": "select", + "required": true, + "default": "dhcp", + "options": [ + "dhcp", + "static" + ] + }, + "timezone": { + "type": "timezone", + "required": true, + "default": "Europe/Madrid" + }, + "onboot": { + "type": "boolean", + "required": true, + "default": false + } + }, + "configuration_constraints": [ + { + "id": "web-authentication-requires-https", + "when": { + "field": "web_authentication_enabled", + "equals": true + }, + "assert": { + "field": "secure_connection_enabled", + "equals": true + }, + "error": "La imagen oficial de JDownloader deshabilita el inicio de sesion web si la conexion no usa HTTPS." + } + ], + "environment": [ + { + "name": "USER_ID", + "value_from": "user_id" + }, + { + "name": "GROUP_ID", + "value_from": "group_id" + }, + { + "name": "UMASK", + "value": "002" + }, + { + "name": "TZ", + "value_from": "timezone" + }, + { + "name": "JDOWNLOADER_HEADLESS", + "value_map": { + "myjdownloader-headless": "1", + "web-gui": "0" + }, + "value_from": "management_mode" + }, + { + "name": "VNC_LOCALHOST_ONLY", + "value": "1" + }, + { + "name": "SECURE_CONNECTION", + "value_map": { + "true": "1", + "false": "0" + }, + "value_from": "secure_connection_enabled", + "enabled_when": { + "field": "management_mode", + "equals": "web-gui" + } + }, + { + "name": "MYJDOWNLOADER_EMAIL", + "value_from": "myjdownloader_email", + "sensitive": true, + "enabled_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + } + }, + { + "name": "MYJDOWNLOADER_PASSWORD", + "value_from": "myjdownloader_password", + "sensitive": true, + "enabled_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + } + }, + { + "name": "MYJDOWNLOADER_DEVICE_NAME", + "value_from": "myjdownloader_device_name", + "enabled_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + } + }, + { + "name": "WEB_AUTHENTICATION", + "value": "1", + "enabled_when": { + "field": "web_authentication_enabled", + "equals": true + } + }, + { + "name": "WEB_AUTHENTICATION_USERNAME", + "value_from": "web_username", + "enabled_when": { + "field": "web_authentication_enabled", + "equals": true + } + }, + { + "name": "WEB_AUTHENTICATION_PASSWORD", + "value_from": "web_password", + "sensitive": true, + "enabled_when": { + "field": "web_authentication_enabled", + "equals": true + } + } + ], + "mounts": [ + { + "id": "config", + "container_path": "/config", + "source": "managed-volume", + "storage_field": "config_storage", + "size_field": "config_size_gb", + "backup": true, + "required": true, + "pre_first_start": [ + "mount-volume-on-host", + "remove-empty-lost-and-found", + "apply-unprivileged-root-ownership", + "unmount-volume" + ] + }, + { + "id": "downloads", + "container_path": "/output", + "source": "host-bind", + "host_path_field": "downloads_host_path", + "read_only": false, + "backup": false, + "required": true, + "pre_start_check": "host-path-mounted-and-writable-by-mapped-user-id" + } + ], + "deployment": { + "runtime": "proxmox-native-oci-lxc", + "unprivileged": true, + "entrypoint": "/usr/local/bin/jdownloader-lxc-start", + "working_directory": "/tmp", + "hostname_default": "jdownloader", + "onboot_default": false, + "startup_order_default": 15, + "startup_delay_seconds_default": 10, + "shutdown_timeout_seconds": 30, + "halt_signal": "SIGTERM", + "features": [ + "nesting=1" + ], + "ports": [ + { + "port": 5800, + "protocol": "tcp", + "purpose": "optional-web-gui", + "enabled_when": { + "field": "management_mode", + "equals": "web-gui" + } + }, + { + "port": 3129, + "protocol": "tcp", + "purpose": "optional-myjdownloader-direct-connect", + "enabled_field": "direct_connect_enabled" + } + ], + "preserve_image_environment": true, + "entrypoint_override": "documented-lxc-runtime-adaptation", + "entrypoint_source": "validated-lxc-oci-profile" + }, + "bootstrap": { + "myjdownloader": { + "enabled_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + }, + "method": "official-image-environment", + "environment": [ + "MYJDOWNLOADER_EMAIL", + "MYJDOWNLOADER_PASSWORD", + "MYJDOWNLOADER_DEVICE_NAME" + ], + "pve_visibility": "visible-by-design", + "procedure": [ + "set-selected-values-in-lxc.environment.runtime", + "start-with-entrypoint-and-cmd-imported-from-the-official-image", + "verify-java-process-and-myjdownloader-device-state" + ] + }, + "web_gui": { + "enabled_when": { + "field": "management_mode", + "equals": "web-gui" + }, + "authentication": { + "default_enabled": true, + "method": "official-image-environment", + "environment": [ + "SECURE_CONNECTION", + "WEB_AUTHENTICATION", + "WEB_AUTHENTICATION_USERNAME", + "WEB_AUTHENTICATION_PASSWORD" + ], + "pve_visibility": "visible-by-design", + "alternative": "Manage multiple users with the image-provided webauth-user tool and /config/webauth-htpasswd." + }, + "security": [ + "keep-vnc-localhost-only", + "require-web-authentication-for-non-lab-deployments", + "require-secure-connection-when-web-authentication-is-enabled", + "generate-self-signed-certificate-when-no-certificate-is-provided", + "allow-user-supplied-certificates-under-config-certs" + ] + } + }, + "healthcheck": { + "profiles": { + "web-gui": { + "type": "http", + "scheme": "https", + "port": 5800, + "path": "/", + "tls_verify": false, + "expected_status": 302, + "expected_location": "/login/" + }, + "myjdownloader-headless": { + "type": "command", + "command": [ + "pgrep", + "-f", + "JDownloader.jar" + ] + } + }, + "interval_seconds": 30, + "timeout_seconds": 10, + "retries": 20, + "start_period_seconds": 180 + }, + "backup_restore": { + "native_proxmox_backup": true, + "included_mounts": [ + "/config" + ], + "excluded_mounts": [ + "/output" + ], + "application_consistency": "Use snapshot mode with guest filesystem freeze; stop mode is preferred during active downloads.", + "restore_order": [ + "restore-vzdump", + "verify-shared-downloads-host-path", + "start-container", + "wait-for-selected-healthcheck" + ] + }, + "boundaries": { + "bundles_credentials": false, + "bundles_download_links": false, + "bundles_downloaded_content": false, + "installer_must_not_store_sensitive_values_in_pve_metadata": false, + "compose_environment_visible_in_pve_metadata": true + }, + "generated_assets": { + "runtime_wrapper": { + "container_path": "/usr/local/bin/jdownloader-lxc-start", + "owner": "root:root", + "mode": "0755", + "content": "#!/bin/sh\nset -e\nexec >>/config/container-start.log 2>&1\nexec /init\n", + "create_before_first_start": true + } + }, + "notes": [ + "La imagen de Jlesage se eligio frente a JayMoulin porque esta mantenida en 2026.", + "El directorio lost+found del volumen ext4 debe eliminarse antes del primer arranque en LXC sin privilegios.", + "La interfaz web no debe publicarse sin autenticacion fuera de un laboratorio local.", + "La imagen oficial requiere HTTPS cuando WEB_AUTHENTICATION=1; sobre HTTP muestra el formulario, pero deshabilita el inicio de sesion.", + "SECURE_CONNECTION=1 genera certificados autofirmados bajo /config/certs si el usuario no proporciona certificados validos.", + "El navegador puede exigir aceptar el certificado autofirmado la primera vez; un despliegue permanente debe admitir certificados propios o un proxy inverso HTTPS correctamente configurado.", + "La ruta /mnt/pve/Piblic/Transmission/eMule fue validada como ejemplo real de host-bind NFS, pero el instalador siempre debe solicitar downloads_host_path al usuario.", + "MyJDownloader es un servicio externo; su cuenta y disponibilidad no forman parte de la imagen OCI." + ] + }, + "installer_profile": { + "generated_sensitive_environment": { + "WEB_AUTHENTICATION_PASSWORD": { + "strategy": "token-hex", + "bytes": 16 + } + }, + "generated_files": [ + { + "id": "jdownloader-first-boot-wrapper", + "container_path": "/usr/local/bin/jdownloader-lxc-start", + "owner": "mapped-root", + "mode": "0755", + "content": "#!/bin/sh\nset -e\nexec >>/config/container-start.log 2>&1\nexec /init\n" + } + ], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-root" + } + ], + "runtime": { + "entrypoint": "/usr/local/bin/jdownloader-lxc-start", + "working_directory": "/tmp", + "halt_signal": "SIGTERM" + }, + "startup_healthcheck": { + "scheme": "https", + "port": 5800, + "path": "/", + "verify_tls": false, + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "stability_seconds": 0 + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The validated first-boot wrapper, secure WebUI credentials and volume preparation are implemented through reusable declarative installer capabilities." + }, + "validation": { + "schema": "passed-at-generation", + "validated_profile": { + "id": "pve55-jdownloader-managed-config", + "validated_on": "2026-08-27", + "validation_status": "passed-web-gui-https-authenticated-myjdownloader-credentials-pending", + "proxmox_version": "9.2.11", + "container_id": 126, + "image": { + "tag": "v26.08.2", + "digest": "sha256:f16d47986bf6a5db6d67484e3b7e76404bce74f6f212809127a79eb76aa1c641", + "archive_sha256": "84aa07101c51a2d5f51d0bf86c2ee9f4ad660788782cff7a16a620cbfc708877" + }, + "storage": { + "rootfs": "local-lvm:8G", + "config": "local-lvm:4G,backup=1", + "downloads": "host-bind:/mnt/pve/Piblic/Transmission/eMule->/output,read-write,backup=0" + }, + "validation": { + "web_gui_https_redirect_to_login": "passed-302", + "http_redirect_to_https": "passed-307", + "self_signed_https_certificate": "passed-generated-for-hostname-jdownloader", + "web_authentication_user_created": "passed-admin-present-in-htpasswd", + "java_process": "passed", + "persistent_config": "passed", + "shared_download_write_as_app_user": "passed", + "default_download_folder": "passed-/output", + "vnc_localhost_only": "passed", + "restart_without_errors": "passed", + "vzdump_config_inclusion": "passed-by-mp0-backup-flag", + "vzdump_restore_to_temporary_ct": "passed-historical-lab-not-repeated-on-ct126", + "myjdownloader_account_connection": "not-tested-no-user-credentials" + }, + "previous_validation_status": "passed-web-gui-myjdownloader-credentials-pending", + "validated_lxc_adapted_profile": { + "entrypoint": "/usr/local/bin/jdownloader-lxc-start", + "custom_rootfs_files": true, + "custom_host_services": false, + "validation": "passed-historical-lab" + }, + "candidate_direct_image_profile": { + "entrypoint": "from-oci-image-config", + "custom_rootfs_files": false, + "custom_host_services": false, + "validation": "pending-clean-import-test" + } + }, + "translation_audit": { + "reviewed_on": "2026-08-27", + "compose_credentials": [ + "MYJDOWNLOADER_EMAIL", + "MYJDOWNLOADER_PASSWORD", + "WEB_AUTHENTICATION_USERNAME", + "WEB_AUTHENTICATION_PASSWORD" + ], + "application_generated_credentials": [ + "JDownloader state and optional htpasswd database under /config" + ], + "result": "aligned-with-official-image-environment" + }, + "source_profile": "jdownloader-oci.json" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-latest-oci-image-preserve-managed-config-volume", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false, + "validated_workflows": { + "install": [ + "validate-requirements", + "validate-storage-capacity", + "create-shared-download-directory", + "prepare-unprivileged-id-mapping-permissions", + "pull-oci-image-by-digest", + "create-container", + "attach-managed-config-volume", + "remove-empty-lost-and-found-from-config-volume", + "attach-shared-downloads-bind", + "inject-runtime-wrapper", + "apply-runtime-environment", + "start-container", + "wait-for-default-config-files", + "run-selected-bootstrap", + "verify-http-redirects-to-https-for-authenticated-web-gui", + "wait-for-selected-healthcheck" + ], + "update": [ + "pause-active-downloads", + "stop-container", + "backup-container", + "pull-new-oci-image", + "recreate-rootfs-preserving-managed-config-volume", + "inject-runtime-wrapper", + "start-container", + "wait-for-selected-healthcheck" + ], + "uninstall": { + "remove_rootfs": true, + "preserve_config_by_default": true, + "preserve_shared_downloads": true + } + } + } +} diff --git a/oci/catalog/apps/jellyfin-official.json b/oci/catalog/apps/jellyfin-official.json new file mode 100644 index 00000000..d59fff21 --- /dev/null +++ b/oci/catalog/apps/jellyfin-official.json @@ -0,0 +1,528 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "image-jellyfin-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Jellyfin Official" + }, + "tagline": { + "en_US": "Official Jellyfin image with optional VA-API or NVIDIA acceleration." + }, + "description": { + "en_US": "Jellyfin is a Free Software Media System that puts you in control of managing and streaming your media. It is an alternative to the proprietary Emby and Plex, to provide media from a dedicated server to end-user devices via multiple apps. Jellyfin is descended from Emby's 3.5.2 release and ported to the .NET Core framework to enable full cross-platform support. There are no strings attached, no premium licenses or features, and no hidden agendas: just a team who want to build something better and work together to achieve it." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Jellyfin Team", + "developer": "Jellyfin Team", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8096, + "path": "/" + }, + "website": "https://jellyfin.org/", + "documentation": "https://jellyfin.org/docs/general/installation/container/", + "repository": "https://github.com/jellyfin/jellyfin-packaging", + "tips": [ + "Configuration and cache use persistent Proxmox volumes by default; media defaults to a shared host directory.", + "Hardware tone mapping is configured persistently after first start when VA-API or NVIDIA is selected.", + "DLNA multicast behavior depends on the selected Proxmox bridge and firewall." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "jellyfin", + "repository": "https://github.com/jellyfin/jellyfin-packaging", + "default_branch": "master", + "revision": "19f2efc7528cc0ec6c04276e1c62d9cdbfb13b6a", + "image_repository_url": "https://github.com/jellyfin/jellyfin-packaging", + "compose_sha256": "db04ff7885b26ca276b747f7d031e9f76f82a1b113c3ba17bcc09bd3a7082f9a", + "generated_at": "2026-09-13T21:08:59+00:00" + }, + "container_contract": { + "service_name": "jellyfin", + "container_name": "jellyfin", + "image": { + "reference": "jellyfin/jellyfin:latest", + "registry": "docker.io", + "repository": "jellyfin/jellyfin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "JELLYFIN_PublishedServerUrl", + "example": "", + "required": false, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Optional published URL for Jellyfin" + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "cache", + "container_path": "/cache", + "compose_source_example": "/path/to/cache", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": false, + "default_size_gb": 8 + } + }, + { + "id": "media", + "container_path": "/media", + "compose_source_example": "/path/to/media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 8096, + "published_example": 8096, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 7359, + "published_example": 7359, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n jellyfin:\n image: jellyfin/jellyfin:latest\n container_name: jellyfin\n ports:\n - 8096:8096/tcp\n - 7359:7359/udp\n environment:\n - JELLYFIN_PublishedServerUrl=\n volumes:\n - /path/to/config:/config\n - /path/to/cache:/cache\n - /path/to/media:/media\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Jellyfin WebUI", + "scheme": "http", + "port": 8096, + "path": "/", + "source": "official-container-documentation" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Jellyfin", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "environment": [ + { + "name": "LIBVA_DRIVER_NAME", + "prompt": "VA-API driver", + "choices": [ + "auto", + "radeonsi", + "iHD", + "i965" + ], + "default": "auto", + "omit_values": [ + "auto" + ] + } + ] + } + ], + "post_start_configurations": [ + { + "id": "jellyfin-vaapi-hdr-tone-mapping", + "type": "jellyfin-encoding-xml", + "enable_prompt": "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping", + "enabled_default": true, + "required": true, + "timeout_seconds": 120, + "candidate_paths": [ + "/config/encoding.xml", + "/config/config/encoding.xml" + ], + "settings": { + "HardwareAccelerationType": "vaapi", + "VaapiDevice": { + "device_path_from": "vaapi-render" + }, + "EnableDecodingColorDepth10Hevc": "true", + "EnableHardwareEncoding": "true", + "EnableTonemapping": "true", + "EnableVppTonemapping": "false", + "TonemappingAlgorithm": "bt2390", + "TonemappingMode": "auto", + "TonemappingRange": "auto" + }, + "lists": { + "HardwareDecodingCodecs": [ + "h264", + "hevc", + "vc1" + ] + } + } + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ], + "post_start_configurations": [ + { + "id": "jellyfin-nvidia-hdr-tone-mapping", + "type": "jellyfin-encoding-xml", + "enable_prompt": "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping", + "enabled_default": true, + "required": true, + "timeout_seconds": 120, + "candidate_paths": [ + "/config/encoding.xml", + "/config/config/encoding.xml" + ], + "settings": { + "HardwareAccelerationType": "nvenc", + "EnableDecodingColorDepth10Hevc": "true", + "EnableEnhancedNvdecDecoder": "true", + "EnableHardwareEncoding": "true", + "EnableTonemapping": "true", + "EnableVppTonemapping": "false", + "TonemappingAlgorithm": "bt2390", + "TonemappingMode": "auto", + "TonemappingRange": "auto" + }, + "lists": { + "HardwareDecodingCodecs": [ + "h264", + "hevc", + "vc1" + ] + } + } + ] + } + ] + }, + "startup_healthcheck": { + "scheme": "http", + "port": 8096, + "path": "/System/Info/Public", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "network": { + "compose_mode": "bridge" + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "application_options": { + "hdr10_dolby_vision_tone_mapping": { + "show_in_catalog": true, + "selectable": true, + "reason": "The installer configures persistent tone mapping according to the selected hardware backend after Jellyfin creates encoding.xml.", + "persistent_configuration_paths": [ + "/config/encoding.xml", + "/config/config/encoding.xml" + ], + "validated_profile": "pending-official-image-validation" + } + }, + "catalog": { + "replaces_discovered_ids": [] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/jellyfin.json b/oci/catalog/apps/jellyfin.json new file mode 100644 index 00000000..2e65225b --- /dev/null +++ b/oci/catalog/apps/jellyfin.json @@ -0,0 +1,643 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-jellyfin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Jellyfin" + }, + "tagline": { + "en_US": "LinuxServer Jellyfin with optional GPU passthrough" + }, + "description": { + "en_US": "Jellyfin is a Free Software Media System that puts you in control of managing and streaming your media. It is an alternative to the proprietary Emby and Plex, to provide media from a dedicated server to end-user devices via multiple apps. Jellyfin is descended from Emby's 3.5.2 release and ported to the .NET Core framework to enable full cross-platform support. There are no strings attached, no premium licenses or features, and no hidden agendas: just a team who want to build something better and work together to achieve it." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8096, + "path": "/" + }, + "website": "https://github.com/jellyfin/jellyfin", + "documentation": "https://docs.linuxserver.io/images/docker-jellyfin/", + "repository": "https://github.com/linuxserver/docker-jellyfin", + "tips": [ + "VA-API and OpenCL tone mapping are separate capabilities. The tested LinuxServer image provides AMD VA-API; AMD OpenCL required the official jellyfin-amd mod.", + "Choose AMD + OpenCL or Intel + OpenCL to install the corresponding official LinuxServer mod at startup. These are options for the same image, not additional catalog variants.", + "ProxMenux passes explicit device paths through ATTACHED_DEVICES_PERMS so the native LinuxServer init grants the service user access. No privileged LXC or mode 0777 is needed.", + "Optional Jellyfin settings are persisted in /config/encoding.xml. AMD OpenCL and VA-API were tested on Lucienne; Intel OpenCL remains untested in this laboratory. Dolby Vision support depends on the source profile and FFmpeg/GPU capabilities." + ], + "mini_changelog": [ + { + "date": "2026-07-14", + "note": "Rebase to Ubuntu Resolute." + }, + { + "date": "2026-03-02", + "note": "Add support for IPv6 OOTB." + }, + { + "date": "2025-10-20", + "note": "Add libjemalloc2 as runtime dep." + }, + { + "date": "2024-10-06", + "note": "Fix fontconfig cache path." + }, + { + "date": "2024-08-13", + "note": "Rebase to Ubuntu Noble." + } + ], + "display_version": null, + "updated_at": "2026-07-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-jellyfin", + "default_branch": "master", + "revision": "868a7bb1f2aa77b87a75e128da7b1869c19b0623", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-jellyfin/868a7bb1f2aa77b87a75e128da7b1869c19b0623/README.md", + "readme_pushed_at": "2026-09-08T02:43:27Z", + "compose_sha256": "933be53b6f9fe99d1c56fad3abe6b1122c448bd9449d8aa4ca8c2ae4ce89ab77", + "generated_at": "2026-09-14T14:56:07+00:00" + }, + "container_contract": { + "service_name": "jellyfin", + "container_name": "jellyfin", + "image": { + "reference": "lscr.io/linuxserver/jellyfin:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/jellyfin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/jellyfin/library", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 16 + } + }, + { + "id": "volume-1", + "container_path": "/data/tvshows", + "compose_source_example": "/path/to/tvseries", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/data/movies", + "compose_source_example": "/path/to/movies", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8096, + "published_example": 8096, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8920, + "published_example": 8920, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 7359, + "published_example": 7359, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 1900, + "published_example": 1900, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n jellyfin:\n image: lscr.io/linuxserver/jellyfin:latest\n container_name: jellyfin\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - JELLYFIN_PublishedServerUrl=http://192.168.0.5 #optional\n volumes:\n - /path/to/jellyfin/library:/config\n - /path/to/tvseries:/data/tvshows\n - /path/to/movies:/data/movies\n ports:\n - 8096:8096\n - 8920:8920 #optional\n - 7359:7359/udp #optional\n - 1900:1900/udp #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8096, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Jellyfin", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD VA-API (no OpenCL mod)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "environment": [ + { + "name": "LIBVA_DRIVER_NAME", + "prompt": "VA-API driver", + "choices": [ + "auto", + "radeonsi", + "iHD", + "i965" + ], + "default": "auto", + "omit_values": [ + "auto" + ] + } + ] + } + ], + "environment_from_devices": { + "ATTACHED_DEVICES_PERMS": [ + "vaapi-render" + ] + } + }, + { + "id": "amd-opencl", + "label": "AMD VA-API + OpenCL (official mod)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x1002", + "0x1022" + ] + }, + { + "id": "amd-kfd", + "kind": "character-device", + "purpose": "amd-opencl", + "path_prompt": "AMD KFD device", + "host_path_default": "/dev/kfd", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ], + "environment_from_devices": { + "ATTACHED_DEVICES_PERMS": [ + "vaapi-render", + "amd-kfd" + ] + }, + "environment": [ + { + "name": "DOCKER_MODS", + "value": "linuxserver/mods:jellyfin-amd" + } + ], + "post_start_configurations": [ + { + "id": "jellyfin-amd-opencl", + "type": "jellyfin-encoding-xml", + "enable_prompt": "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin", + "enabled_default": true, + "required": true, + "timeout_seconds": 120, + "candidate_paths": [ + "/config/encoding.xml" + ], + "settings": { + "HardwareAccelerationType": "vaapi", + "VaapiDevice": { + "device_path_from": "vaapi-render" + }, + "EnableHardwareEncoding": "true", + "EnableTonemapping": "true", + "EnableVppTonemapping": "false" + } + } + ], + "architectures": [ + "amd64" + ] + }, + { + "id": "intel-opencl", + "label": "Intel VA-API + OpenCL (official mod)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086" + ] + } + ], + "environment_from_devices": { + "ATTACHED_DEVICES_PERMS": [ + "vaapi-render" + ] + }, + "environment": [ + { + "name": "DOCKER_MODS", + "value": "linuxserver/mods:jellyfin-opencl-intel" + } + ], + "post_start_configurations": [ + { + "id": "jellyfin-intel-opencl", + "type": "jellyfin-encoding-xml", + "enable_prompt": "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin", + "enabled_default": true, + "required": true, + "timeout_seconds": 120, + "candidate_paths": [ + "/config/encoding.xml" + ], + "settings": { + "HardwareAccelerationType": "vaapi", + "VaapiDevice": { + "device_path_from": "vaapi-render" + }, + "EnableHardwareEncoding": "true", + "EnableTonemapping": "true", + "EnableVppTonemapping": "false" + } + } + ], + "architectures": [ + "amd64" + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ] + } + ] + }, + "startup_healthcheck": { + "scheme": "http", + "port": 8096, + "path": "/System/Info/Public", + "timeout_seconds": 600, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "application_options": { + "hdr10_dolby_vision_tone_mapping": { + "show_in_catalog": true, + "selectable": true, + "provided_by_image": false, + "configuration": "Optional official LinuxServer GPU mod and persistent Jellyfin encoding settings", + "scope": "OpenCL tone mapping; not a guarantee for every HDR/Dolby Vision source" + } + }, + "gpu_lab_references": { + "amd_mod": "https://github.com/linuxserver/docker-mods/tree/jellyfin-amd", + "intel_mod": "https://github.com/linuxserver/docker-mods/tree/jellyfin-opencl-intel" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/jellyseerr.json b/oci/catalog/apps/jellyseerr.json new file mode 100644 index 00000000..eca79c0e --- /dev/null +++ b/oci/catalog/apps/jellyseerr.json @@ -0,0 +1,433 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-jellyseerr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Jellyseerr" + }, + "tagline": { + "en_US": "Jellyseerr is a free and open source software application for managing requests for your media library." + }, + "description": { + "en_US": "Jellyseerr is a self-hosted media request and management tool designed to streamline media library request and discovery processes, offering an intuitive Web interface, ideal for home media server users and small teams. It seamlessly integrates with existing media services, enabling efficient management of movies, shows, and mixed content libraries.\n\nThe tool's core features include a customizable request system and broad media server integration. It allows users to request movies or individual show seasons through a user-friendly interface, with administrators able to approve requests via a simple management UI. It integrates with Jellyfin, Emby, and Plex, supporting user import and authentication with existing accounts. Diverse notification channels (e.g., Discord, Telegram, Email) provide real-time request status updates, and library scanning tracks available media to prevent duplicate requests.\n\nIt offers a granular permission system, enabling precise control over user access and actions. The mobile-friendly design facilitates on-the-go request approvals, while watchlist and blacklist support help users filter content. Support for PostgreSQL and SQLite databases ensures flexible deployment options. Community support via GitHub and Discord provides documentation and assistance, delivering a modern media management solution with intuitive operation and high flexibility.\n\n**Key Features:**\n- Full Jellyfin/Emby/Plex integration including authentication with user import & management.\n- Support for PostgreSQL and SQLite databases.\n- Supports Movies, Shows and Mixed Libraries.\n- Ability to change email addresses for SMTP purposes.\n- Easy integration with your existing services. Currently, Jellyseerr supports Sonarr and Radarr.\n- Jellyfin/Emby/Plex library scan, to keep track of the titles which are already available.\n- Customizable request system, which allows users to request individual seasons or movies in a friendly, easy-to-use interface.\n- Incredibly simple request management UI. Don't dig through the app to simply approve recent requests!\n- Granular permission system.\n- Support for various notification agents.\n- Mobile-friendly design, for when you need to approve requests on the go!\n- Support for watchlisting & blacklisting media.\n\n**Learn More:**\n- [Jellyseerr Documentation](https://docs.jellyseerr.dev/)\n- [Jellyseerr GitHub Repository](https://github.com/Fallenbagel/jellyseerr)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Fallenbagel", + "developer": "Fallenbagel", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5055, + "path": "/" + }, + "website": "https://seerr.dev/", + "documentation": null, + "repository": "https://hub.docker.com/r/fallenbagel/jellyseerr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "fallenbagel", + "repository": "https://hub.docker.com/r/fallenbagel/jellyseerr", + "revision": "ec3b02d9c18cbba40e3b1cece0fa22a60d9743627446c3debfe83c1039b769ab", + "image_repository_url": "https://hub.docker.com/r/fallenbagel/jellyseerr", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "ec3b02d9c18cbba40e3b1cece0fa22a60d9743627446c3debfe83c1039b769ab", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "jellyseerr", + "container_name": "jellyseerr", + "image": { + "reference": "fallenbagel/jellyseerr:latest", + "registry": "docker.io", + "repository": "fallenbagel/jellyseerr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "LOG_LEVEL", + "example": "debug", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/config", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5055, + "published_example": 5055, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: jellyseerr\nservices:\n jellyseerr:\n cpu_shares: 50\n deploy:\n resources:\n limits:\n memory: 256M\n reservations:\n memory: 256M\n environment:\n - LOG_LEVEL=debug\n - TZ=$TZ\n image: fallenbagel/jellyseerr:latest\n ports:\n - mode: ingress\n target: 5055\n published: '5055'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /app/config\n bind:\n create_host_path: true\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "jellyseerr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "jellyseerr", + "service_count": 1, + "services": [ + { + "name": "jellyseerr", + "image": "fallenbagel/jellyseerr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "cpu_shares": 50, + "deploy": { + "resources": { + "limits": { + "memory": "256M" + }, + "reservations": { + "memory": "256M" + } + } + }, + "environment": [ + "LOG_LEVEL=debug", + "TZ=$TZ" + ], + "image": "fallenbagel/jellyseerr:latest", + "ports": [ + { + "mode": "ingress", + "target": 5055, + "published": "5055", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/app/config", + "bind": { + "create_host_path": true + } + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "jellyseerr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "jellyseerr-volume-0", + "service": "jellyseerr", + "container_path": "/app/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "jellyseerr" + ], + "stop_order": [ + "jellyseerr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5055, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "resources": { + "cpu_shares": 50 + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/jenkins.json b/oci/catalog/apps/jenkins.json new file mode 100644 index 00000000..1e27b10e --- /dev/null +++ b/oci/catalog/apps/jenkins.json @@ -0,0 +1,439 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-jenkins", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Jenkins CI/CD" + }, + "tagline": { + "en_US": "Jenkins Continuous Integration and Delivery server." + }, + "description": { + "en_US": "A server for creating pipelines for Jenkins continuous integration and delivery." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "bepp-boop", + "developer": "bepp-boop", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://www.jenkins.io/", + "documentation": null, + "repository": "https://hub.docker.com/r/jenkins/jenkins", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/jenkins/jenkins", + "revision": "a6b27ce976fce57330a09a639b6f2870e6ed0894473f3b9a5e796b4376c56a06", + "image_repository_url": "https://hub.docker.com/r/jenkins/jenkins", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "a6b27ce976fce57330a09a639b6f2870e6ed0894473f3b9a5e796b4376c56a06", + "generated_at": "2026-09-13T15:34:59+00:00" + }, + "container_contract": { + "service_name": "jenkins", + "container_name": "Jenkins", + "image": { + "reference": "jenkins/jenkins:latest", + "registry": "docker.io", + "repository": "jenkins/jenkins", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/Jenkins/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/var/jenkins_home", + "compose_source_example": "/var/lib/docker/volumes/b098c98b2c5dec792246dc33375853c05958ace7c144f4aa157326a6f6c0de4c/_data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: jenkins\nservices:\n jenkins:\n image: jenkins/jenkins:latest\n privileged: false\n user: root\n restart: always\n network_mode: bridge\n cpu_shares: 50\n ports:\n - target: 8080\n published: '8080'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/Jenkins/data\n target: /data\n - type: bind\n source: /var/lib/docker/volumes/b098c98b2c5dec792246dc33375853c05958ace7c144f4aa157326a6f6c0de4c/_data\n target: /var/jenkins_home\n container_name: Jenkins\n hostname: Jenkins\n" + }, + "compose_stack": { + "project_name": "jenkins", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "jenkins", + "service_count": 1, + "services": [ + { + "name": "jenkins", + "image": "jenkins/jenkins:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jenkins/jenkins:latest", + "privileged": false, + "user": "root", + "restart": "always", + "network_mode": "bridge", + "cpu_shares": 50, + "ports": [ + { + "target": 8080, + "published": "8080", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/Jenkins/data", + "target": "/data" + }, + { + "type": "bind", + "source": "/var/lib/docker/volumes/b098c98b2c5dec792246dc33375853c05958ace7c144f4aa157326a6f6c0de4c/_data", + "target": "/var/jenkins_home" + } + ], + "container_name": "Jenkins", + "hostname": "Jenkins" + } + } + ], + "top_level": { + "name": "jenkins" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "jenkins-volume-0", + "service": "jenkins", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for jenkins:/data" + }, + { + "id": "jenkins-volume-1", + "service": "jenkins", + "container_path": "/var/jenkins_home", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "jenkins" + ], + "stop_order": [ + "jenkins" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "user": "root", + "hostname": "Jenkins" + }, + "resources": { + "cpu_shares": 50 + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/joplin.json b/oci/catalog/apps/joplin.json new file mode 100644 index 00000000..60846334 --- /dev/null +++ b/oci/catalog/apps/joplin.json @@ -0,0 +1,268 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-joplin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Joplin" + }, + "tagline": { + "en_US": "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks." + }, + "description": { + "en_US": "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/joplin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/joplin-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://joplinapp.org/", + "documentation": "https://docs.linuxserver.io/images/docker-joplin/", + "repository": "https://github.com/linuxserver/docker-joplin", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-19", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-joplin", + "default_branch": "master", + "revision": "a7a97ca61e33da9e4d0962a33b8e1938f852b7b3", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-joplin/a7a97ca61e33da9e4d0962a33b8e1938f852b7b3/README.md", + "readme_pushed_at": "2026-09-11T19:58:57Z", + "compose_sha256": "947735878d9ff8c413874b05dd7c78713cbdd756f187c64696ef61ee3d5de48c", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "joplin", + "container_name": "joplin", + "image": { + "reference": "lscr.io/linuxserver/joplin:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/joplin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n joplin:\n image: lscr.io/linuxserver/joplin:latest\n container_name: joplin\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/kali-linux.json b/oci/catalog/apps/kali-linux.json new file mode 100644 index 00000000..60914165 --- /dev/null +++ b/oci/catalog/apps/kali-linux.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-kali-linux", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Kali Linux" + }, + "tagline": { + "en_US": "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX \u2122 is a trademark of OffSec." + }, + "description": { + "en_US": "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX \u2122 is a trademark of OffSec." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kali-linux-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kali-linux-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/linuxserver/docker-kali-linux", + "documentation": "https://docs.linuxserver.io/images/docker-kali-linux/", + "repository": "https://github.com/linuxserver/docker-kali-linux", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-06-19", + "note": "Rebase to Selkies baseimage." + }, + { + "date": "2025-01-24", + "note": "Fix SVG icons not rendering." + }, + { + "date": "2024-07-18", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-kali-linux", + "default_branch": "master", + "revision": "89a3d198c8d36f186aabfb65ee061322042a3848", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-kali-linux/89a3d198c8d36f186aabfb65ee061322042a3848/README.md", + "readme_pushed_at": "2026-09-07T15:58:30Z", + "compose_sha256": "632274d62fee5df03104b151e6573f814d5307787fbca8a2c9a75238392bc4d6", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "kali-linux", + "container_name": "kali-linux", + "image": { + "reference": "lscr.io/linuxserver/kali-linux:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/kali-linux", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n kali-linux:\n image: lscr.io/linuxserver/kali-linux:latest\n container_name: kali-linux\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/data:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:kali", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-kali-linux/master/Dockerfile", + "dockerfile_sha256": "cd5947fea72f349b12b60aceb0c9c32629954f5e14ab3003f47d153160be9bc9", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/karakeep.json b/oci/catalog/apps/karakeep.json new file mode 100644 index 00000000..61d7d793 --- /dev/null +++ b/oci/catalog/apps/karakeep.json @@ -0,0 +1,622 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-karakeep", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "Karakeep" + }, + "tagline": { + "en_US": "The Bookmark Everything App" + }, + "description": { + "en_US": "Karakeep is an open-source, self-hosted bookmark manager for links, notes, images, PDFs, and highlights, built to keep everything you want to save in one place.\nIt automatically fetches titles, descriptions, and previews, then helps you organize your library with AI tagging, full-text search, lists, and rule-based automation.\nWith browser extensions, mobile apps, RSS ingestion, and page archiving, Karakeep works well as both a read-later tool and a durable personal content archive.\n\n**Main Features:**\n- Save links, notes, images, PDFs, and text highlights in one library\n- Auto-fetch titles, descriptions, images, and archived pages for later reading\n- Use AI tagging, summarization, OCR, and full-text search to rediscover content quickly\n- Organize content with tags, collaborative lists, RSS feeds, and rule-based workflows\n- Access your collection through the web app, mobile apps, browser extensions, REST API, and CLI\n\n**Learn More:**\n- [Karakeep Official Website](https://karakeep.app/)\n- [Karakeep GitHub](https://github.com/karakeep-app/karakeep)\n- [Karakeep Documentation](https://docs.karakeep.app/)\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "karakeep-app", + "developer": "karakeep-app", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://karakeep.app/", + "documentation": null, + "repository": "https://ghcr.io/karakeep-app/karakeep", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/karakeep-app/karakeep", + "revision": "327acdcb2a5c6267d95f6ff8cc4ab1c6ce9bf6f704291e5000ff32b6231d4e19", + "image_repository_url": "https://ghcr.io/karakeep-app/karakeep", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "327acdcb2a5c6267d95f6ff8cc4ab1c6ce9bf6f704291e5000ff32b6231d4e19", + "generated_at": "2026-09-13T15:48:27+00:00" + }, + "container_contract": { + "service_name": "karakeep", + "container_name": "karakeep", + "image": { + "reference": "ghcr.io/karakeep-app/karakeep:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/karakeep-app/karakeep", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "MEILI_ADDR", + "example": "http://karakeep-meilisearch:7700", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BROWSER_WEB_URL", + "example": "http://karakeep-chrome:9222", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DATA_DIR", + "example": "/data", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_URL", + "example": "http://localhost:14592", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_SECRET", + "example": "${GENERATED_NEXTAUTH_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "MEILI_MASTER_KEY", + "example": "${GENERATED_MEILI_MASTER_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "OPENAI_API_KEY", + "example": "${GENERATED_OPENAI_API_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 14592, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "karakeep-chrome", + "image": "ghcr.io/karakeep-app/karakeep-chrome:latest" + }, + { + "name": "karakeep-meilisearch", + "image": "getmeili/meilisearch:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: karakeep\nservices:\n karakeep:\n image: ghcr.io/karakeep-app/karakeep:latest\n container_name: karakeep\n deploy:\n resources:\n reservations:\n memory: 512M\n restart: unless-stopped\n ports:\n - target: 3000\n published: '14592'\n protocol: tcp\n networks:\n - karakeep\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n environment:\n MEILI_ADDR: http://karakeep-meilisearch:7700\n BROWSER_WEB_URL: http://karakeep-chrome:9222\n DATA_DIR: /data\n NEXTAUTH_URL: http://localhost:14592\n NEXTAUTH_SECRET: ${GENERATED_NEXTAUTH_SECRET}\n MEILI_MASTER_KEY: ${GENERATED_MEILI_MASTER_KEY}\n OPENAI_API_KEY: ${GENERATED_OPENAI_API_KEY}\n karakeep-chrome:\n image: ghcr.io/karakeep-app/karakeep-chrome:latest\n container_name: karakeep-chrome\n deploy:\n resources:\n reservations:\n memory: 512M\n restart: unless-stopped\n init: true\n networks:\n - karakeep\n command:\n - --disable-gpu\n - --disable-dev-shm-usage\n - --hide-scrollbars\n - --disable-blink-features=AutomationControlled\n - --window-size=1440,900\n karakeep-meilisearch:\n image: getmeili/meilisearch:latest\n container_name: karakeep-meilisearch\n deploy:\n resources:\n reservations:\n memory: 256M\n restart: unless-stopped\n networks:\n - karakeep\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/meilisearch\n target: /meili_data\n environment:\n MEILI_MASTER_KEY: ${GENERATED_MEILI_MASTER_KEY}\n MEILI_NO_ANALYTICS: 'true'\nnetworks:\n karakeep:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "karakeep", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "karakeep", + "service_count": 3, + "services": [ + { + "name": "karakeep-chrome", + "image": "ghcr.io/karakeep-app/karakeep-chrome:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "ghcr.io/karakeep-app/karakeep-chrome:latest", + "container_name": "karakeep-chrome", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "restart": "unless-stopped", + "init": true, + "networks": [ + "karakeep" + ], + "command": [ + "--disable-gpu", + "--disable-dev-shm-usage", + "--hide-scrollbars", + "--disable-blink-features=AutomationControlled", + "--window-size=1440,900" + ] + } + }, + { + "name": "karakeep-meilisearch", + "image": "getmeili/meilisearch:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "getmeili/meilisearch:latest", + "container_name": "karakeep-meilisearch", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "restart": "unless-stopped", + "networks": [ + "karakeep" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/meilisearch", + "target": "/meili_data" + } + ], + "environment": { + "MEILI_MASTER_KEY": "${GENERATED_MEILI_MASTER_KEY}", + "MEILI_NO_ANALYTICS": "true" + } + } + }, + { + "name": "karakeep", + "image": "ghcr.io/karakeep-app/karakeep:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "ghcr.io/karakeep-app/karakeep:latest", + "container_name": "karakeep", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "restart": "unless-stopped", + "ports": [ + { + "target": 3000, + "published": "14592", + "protocol": "tcp" + } + ], + "networks": [ + "karakeep" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "environment": { + "MEILI_ADDR": "http://karakeep-meilisearch:7700", + "BROWSER_WEB_URL": "http://karakeep-chrome:9222", + "DATA_DIR": "/data", + "NEXTAUTH_URL": "http://localhost:14592", + "NEXTAUTH_SECRET": "${GENERATED_NEXTAUTH_SECRET}", + "MEILI_MASTER_KEY": "${GENERATED_MEILI_MASTER_KEY}", + "OPENAI_API_KEY": "${GENERATED_OPENAI_API_KEY}" + } + } + } + ], + "top_level": { + "name": "karakeep", + "networks": { + "karakeep": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "karakeep-volume-0", + "service": "karakeep", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for karakeep:/data" + }, + { + "id": "karakeep-meilisearch-volume-0", + "service": "karakeep-meilisearch", + "container_path": "/meili_data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "karakeep-chrome", + "karakeep-meilisearch", + "karakeep" + ], + "stop_order": [ + "karakeep", + "karakeep-meilisearch", + "karakeep-chrome" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "meili-master-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "karakeep", + "environment_variable": "MEILI_MASTER_KEY" + }, + { + "service": "karakeep-meilisearch", + "environment_variable": "MEILI_MASTER_KEY" + } + ] + }, + { + "id": "nextauth-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "karakeep", + "environment_variable": "NEXTAUTH_SECRET" + } + ] + }, + { + "id": "openai-api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "karakeep", + "environment_variable": "OPENAI_API_KEY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "karakeep-chrome: perfil de salud y persistencia pendiente", + "karakeep: credencial externa o booleano GENERATED_OPENAI_API_KEY pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/kasm.json b/oci/catalog/apps/kasm.json new file mode 100644 index 00000000..0b28bc29 --- /dev/null +++ b/oci/catalog/apps/kasm.json @@ -0,0 +1,444 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-kasm", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Kasm" + }, + "tagline": { + "en_US": "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections." + }, + "description": { + "en_US": "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections." + }, + "category": "remote", + "category_label": "Remote Access & VPN", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kasm-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kasm-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://www.kasmweb.com/?utm_campaign=LinuxServer&utm_source=listing", + "documentation": "https://docs.linuxserver.io/images/docker-kasm/", + "repository": "https://github.com/linuxserver/docker-kasm", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-04", + "note": "Give kasm_manager a healthcheck start period so a cold start does not leave kasm_proxy created but never started." + }, + { + "date": "2026-04-16", + "note": "Update for 1.18.1 release. Use rolling service images. Bump docker to v29." + }, + { + "date": "2025-11-13", + "note": "Pin docker to v28 to avoid API deprecation issues." + }, + { + "date": "2025-10-22", + "note": "Update for 1.18.0 release." + }, + { + "date": "2025-06-08", + "note": "Deprecate develop branch." + } + ], + "display_version": null, + "updated_at": "2026-08-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-kasm", + "default_branch": "master", + "revision": "5c366434fc5c361b21f892ce6b49764511f68a97", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-kasm/5c366434fc5c361b21f892ce6b49764511f68a97/README.md", + "readme_pushed_at": "2026-09-08T23:53:43Z", + "compose_sha256": "e416b8d565adfb8a27cbbed64ec0fb38d3a0551175c95303356863c1f9d4856c", + "generated_at": "2026-09-13T17:20:19+00:00" + }, + "container_contract": { + "service_name": "kasm", + "container_name": "kasm", + "image": { + "reference": "lscr.io/linuxserver/kasm:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/kasm", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "KASM_PORT", + "example": "443", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DOCKER_HUB_USERNAME", + "example": "USER", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DOCKER_HUB_PASSWORD", + "example": "PASS", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DOCKER_MTU", + "example": "1500", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt", + "compose_source_example": "/path/to/kasm/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/profiles", + "compose_source_example": "/path/to/kasm/profiles", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/dev/input", + "compose_source_example": "/dev/input", + "read_only": false, + "required": false, + "installation_choice": [ + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/run/udev/data", + "compose_source_example": "/run/udev/data", + "read_only": false, + "required": false, + "installation_choice": [ + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": "90s", + "original_compose": "---\nservices:\n kasm:\n image: lscr.io/linuxserver/kasm:latest\n container_name: kasm\n privileged: true\n security_opt:\n - apparmor:rootlesskit #optional\n environment:\n - KASM_PORT=443\n - DOCKER_HUB_USERNAME=USER #optional\n - DOCKER_HUB_PASSWORD=PASS #optional\n - DOCKER_MTU=1500 #optional\n volumes:\n - /path/to/kasm/data:/opt\n - /path/to/kasm/profiles:/profiles #optional\n - /dev/input:/dev/input #optional\n - /run/udev/data:/run/udev/data #optional\n ports:\n - 3000:3000\n - 443:443\n stop_grace_period: \"90s\" #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 90 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "security": { + "optional_relaxations": [ + { + "id": "apparmor-rootlesskit", + "enable_prompt": "Apply optional security relaxation apparmor:rootlesskit", + "enabled_default": false, + "options": { + "apparmor_profile": "unconfined", + "apparmor_source_profile": "rootlesskit" + } + } + ] + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": true, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": true, + "risk_level": "high", + "confirmation_required": false, + "warning": "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. The Docker rootlesskit profile does not exist in LXC and will be replaced by AppArmor unconfined, which is less restrictive. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/kavita-jvmilazz0.json b/oci/catalog/apps/kavita-jvmilazz0.json new file mode 100644 index 00000000..cb17a2a2 --- /dev/null +++ b/oci/catalog/apps/kavita-jvmilazz0.json @@ -0,0 +1,444 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-kavita-jvmilazz0", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Kavita" + }, + "tagline": { + "en_US": "Kavita is a free and open source web based Comic and Book Server." + }, + "description": { + "en_US": "Kavita is a self-hosted digital library app designed for managing and reading comics, light novels, and e-books (supporting CBZ, CBR, EPUB, PDF, and more), offering a secure and convenient solution for personal reading collections. Its responsive Web interface allows users to access content effortlessly via any browser, with fullscreen reading and full localization support, ideal for comic and e-book enthusiasts building personalized digital libraries.\n\nThe app's core features include robust library management and an enhanced reading experience. Users can organize content with collections, reading lists, and custom tags, editing metadata to keep libraries neatly arranged. The built-in manga reader supports dual-page mode, Webtoon scrolling, and image splitting, while the e-book reader offers customizable fonts, spacing, and themes, with by-line progress syncing across devices. The PDF reader provides light/dark modes and diverse settings. It supports multi-user management, allowing custom permissions for sharing libraries or restricting content access, perfect for family or team use. Bulk imports and full-text search streamline large collection management.\n\nIt can be flexibly deployed on personal servers or NAS devices, with an active community providing extensive documentation to enhance functionality. Folder monitoring automatically detects file changes without manual scans, and sending content to Kindle or other devices improves cross-device access. Whether creating a personal reading hub or sharing media with others, the app's intuitive interface and high customizability deliver a modern management platform, meeting needs from casual reading to professional collections.\n\n**Key Features:**\n- Serve up Manga/Webtoons/Comics (cbr, cbz, zip/rar/rar5, 7zip, raw images) and Books (epub, pdf)\n- First class responsive readers that work great on any device (phone, tablet, desktop)\n- Customizable theming support: [Theme Repo](https://github.com/Kareadita/Themes) and [Documentation](https://wiki.kavitareader.com/guides/themes/)\n- External metadata integration and scrobbling for read status, ratings, and reviews (available via Kavita+)\n- Rich Metadata support with filtering and searching\n- Ways to group reading material: Collections, Reading Lists (CBL Import), Want to Read\n- Ability to manage users with rich Role-based management for age restrictions, abilities within the app, etc\n- Rich web readers supporting webtoon, continuous reading mode (continue without leaving the reader), virtual pages (epub), etc\n- Ability to customize your dashboard and side nav with smart filters, custom order and visibility toggles\n- Ability to download metadata (available via Kavita+)\n\n**Learn More:**\n- [Kavita Official Website](https://www.kavitareader.com)\n- [Kavita GitHub Repository](https://github.com/Kareadita/Kavita)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "jvmilazz0", + "developer": "jvmilazz0", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5000, + "path": "/" + }, + "website": "https://www.kavitareader.com", + "documentation": null, + "repository": "https://hub.docker.com/r/jvmilazz0/kavita", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "jvmilazz0", + "repository": "https://hub.docker.com/r/jvmilazz0/kavita", + "revision": "abb33b75fb957fce843d3b96388cd70a6299291af58df3be8a8d70256f340deb", + "image_repository_url": "https://hub.docker.com/r/jvmilazz0/kavita", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "abb33b75fb957fce843d3b96388cd70a6299291af58df3be8a8d70256f340deb", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "kavita", + "container_name": "kavita", + "image": { + "reference": "jvmilazz0/kavita:latest", + "registry": "docker.io", + "repository": "jvmilazz0/kavita", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/kavita/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/manga", + "compose_source_example": "/DATA/Media/Manga", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5000, + "published_example": 5150, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: kavita\nservices:\n kavita:\n image: jvmilazz0/kavita:latest\n container_name: kavita\n deploy:\n resources:\n reservations:\n memory: 128M\n network_mode: bridge\n restart: unless-stopped\n ports:\n - target: 5000\n published: '5150'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /kavita/config\n - type: bind\n source: /DATA/Media/Manga\n target: /manga\n environment:\n TZ: $TZ\n" + }, + "compose_stack": { + "project_name": "kavita", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "kavita", + "service_count": 1, + "services": [ + { + "name": "kavita", + "image": "jvmilazz0/kavita:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jvmilazz0/kavita:latest", + "container_name": "kavita", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "network_mode": "bridge", + "restart": "unless-stopped", + "ports": [ + { + "target": 5000, + "published": "5150", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/kavita/config" + }, + { + "type": "bind", + "source": "/DATA/Media/Manga", + "target": "/manga" + } + ], + "environment": { + "TZ": "$TZ" + } + } + } + ], + "top_level": { + "name": "kavita" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "kavita-volume-0", + "service": "kavita", + "container_path": "/kavita/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "kavita-volume-1", + "service": "kavita", + "container_path": "/manga", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "kavita" + ], + "stop_order": [ + "kavita" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/kavita.json b/oci/catalog/apps/kavita.json new file mode 100644 index 00000000..095cc79e --- /dev/null +++ b/oci/catalog/apps/kavita.json @@ -0,0 +1,258 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-kavita", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Kavita" + }, + "tagline": { + "en_US": "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!" + }, + "description": { + "en_US": "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kavita-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kavita-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5000, + "path": "/" + }, + "website": "https://github.com/Kareadita/Kavita", + "documentation": "https://docs.linuxserver.io/images/docker-kavita/", + "repository": "https://github.com/linuxserver/docker-kavita", + "tips": [], + "mini_changelog": [ + { + "date": "2026-09-11", + "note": "Rebase to Ubuntu Resolute. Enable jemalloc to reduce memory footprint." + }, + { + "date": "2025-07-05", + "note": "Update init for version 0.8.7 compatibility." + }, + { + "date": "2024-07-10", + "note": "Rebase to Ubuntu Noble." + }, + { + "date": "2023-08-12", + "note": "Fix app file perms to prevent high uid." + }, + { + "date": "2023-08-07", + "note": "Initial Release." + } + ], + "display_version": null, + "updated_at": "2026-09-11" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-kavita", + "default_branch": "main", + "revision": "1d5b762965f0f3067a3960ed2dbadb63ab9c6038", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-kavita/1d5b762965f0f3067a3960ed2dbadb63ab9c6038/README.md", + "readme_pushed_at": "2026-09-11T19:00:02Z", + "compose_sha256": "4d02fcf2e790405c747752c35ec038cf1585c3435ff923f7752039b8a134f78a", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "kavita", + "container_name": "kavita", + "image": { + "reference": "lscr.io/linuxserver/kavita:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/kavita", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/kavita/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5000, + "published_example": 5000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n kavita:\n image: lscr.io/linuxserver/kavita:latest\n container_name: kavita\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/kavita/config:/config\n - /path/to/data:/data #optional\n ports:\n - 5000:5000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/kdenlive.json b/oci/catalog/apps/kdenlive.json new file mode 100644 index 00000000..f842bf27 --- /dev/null +++ b/oci/catalog/apps/kdenlive.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-kdenlive", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Kdenlive" + }, + "tagline": { + "en_US": "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready." + }, + "description": { + "en_US": "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kdenlive-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kdenlive-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://kdenlive.org/", + "documentation": "https://docs.linuxserver.io/images/docker-kdenlive/", + "repository": "https://github.com/linuxserver/docker-kdenlive", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Arch latest Appimage no longer working on Deb distros. Build for arm64 again." + }, + { + "date": "2025-08-06", + "note": "Fix cpu bug, disable gamepad by default." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and use official AppImage, HTTPS IS NOW REQUIRED. Remove arm64 support." + } + ], + "display_version": null, + "updated_at": "2026-03-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-kdenlive", + "default_branch": "master", + "revision": "af705be2f7743576a55ef916a6db596a1fc9359a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-kdenlive/af705be2f7743576a55ef916a6db596a1fc9359a/README.md", + "readme_pushed_at": "2026-09-10T14:57:40Z", + "compose_sha256": "c88b38daec43a7162a516001986d2bcf20b98e5254e49863f8e74269292becac", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "kdenlive", + "container_name": "kdenlive", + "image": { + "reference": "lscr.io/linuxserver/kdenlive:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/kdenlive", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/kdenlive/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n kdenlive:\n image: lscr.io/linuxserver/kdenlive:latest\n container_name: kdenlive\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/kdenlive/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\" #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-kdenlive/master/Dockerfile", + "dockerfile_sha256": "cb69b193c30a69f2f5f2f3d667bae33d41beacb23c60847e69ce71265c29cb0c", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/keepassxc.json b/oci/catalog/apps/keepassxc.json new file mode 100644 index 00000000..181c2424 --- /dev/null +++ b/oci/catalog/apps/keepassxc.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-keepassxc", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Keepassxc" + }, + "tagline": { + "en_US": "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass)." + }, + "description": { + "en_US": "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass)." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/keepassxc-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/keepassxc-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://keepassxc.org/", + "documentation": "https://docs.linuxserver.io/images/docker-keepassxc/", + "repository": "https://github.com/linuxserver/docker-keepassxc", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-keepassxc", + "default_branch": "master", + "revision": "f9eb9b9053040fb9fec2d3ccea0d15bf6e6bbd9c", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-keepassxc/f9eb9b9053040fb9fec2d3ccea0d15bf6e6bbd9c/README.md", + "readme_pushed_at": "2026-09-10T12:09:50Z", + "compose_sha256": "3fb58c091c32ef4825ef19ecc2f3b98b79cd0bf2b299d7a038a6db40d412771b", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "keepassxc", + "container_name": "keepassxc", + "image": { + "reference": "lscr.io/linuxserver/keepassxc:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/keepassxc", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n keepassxc:\n image: lscr.io/linuxserver/keepassxc:latest\n container_name: keepassxc\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-keepassxc/master/Dockerfile", + "dockerfile_sha256": "a850d78ae65c5f6073cd972500b973c9fb7d78e7cea1b88a29add4cbe9c5ef08", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/kicad.json b/oci/catalog/apps/kicad.json new file mode 100644 index 00000000..2fc90a11 --- /dev/null +++ b/oci/catalog/apps/kicad.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-kicad", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Kicad" + }, + "tagline": { + "en_US": "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite." + }, + "description": { + "en_US": "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kicad-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kicad-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.kicad.org/", + "documentation": "https://docs.linuxserver.io/images/docker-kicad/", + "repository": "https://github.com/linuxserver/docker-kicad", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-kicad", + "default_branch": "master", + "revision": "d4c1920f90b2fcc0e6879e8933f30b90e299a0a9", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-kicad/d4c1920f90b2fcc0e6879e8933f30b90e299a0a9/README.md", + "readme_pushed_at": "2026-09-08T15:38:41Z", + "compose_sha256": "744d12df3ba2308d6fe2a02238aa04c4ead14c3bb9e89418fca0fc941ca3ada1", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "kicad", + "container_name": "kicad", + "image": { + "reference": "lscr.io/linuxserver/kicad:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/kicad", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n kicad:\n image: lscr.io/linuxserver/kicad:latest\n container_name: kicad\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-kicad/master/Dockerfile", + "dockerfile_sha256": "663d142e3c9be4c5e244738aff0929a806a118330f5b78c8ab4570cb9116dd21", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/kimai.json b/oci/catalog/apps/kimai.json new file mode 100644 index 00000000..97c06bdd --- /dev/null +++ b/oci/catalog/apps/kimai.json @@ -0,0 +1,569 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-kimai", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Kimai" + }, + "tagline": { + "en_US": "Kimai is a professional grade time-tracking application, free and open-source." + }, + "description": { + "en_US": "Kimai is a professional grade time-tracking application, free and open-source." + }, + "category": "business", + "category_label": "Business & ERP", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kimai-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kimai-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://kimai.org/", + "documentation": "https://docs.linuxserver.io/images/docker-kimai/", + "repository": "https://github.com/linuxserver/docker-kimai", + "tips": [], + "mini_changelog": [ + { + "date": "2027-07-04", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-04", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-04-06", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-30", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + } + ], + "display_version": null, + "updated_at": "2027-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-kimai", + "default_branch": "main", + "revision": "21f7b9db5742edabb76b11e6fa5275f0066cc415", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-kimai/21f7b9db5742edabb76b11e6fa5275f0066cc415/README.md", + "readme_pushed_at": "2026-09-12T00:49:44Z", + "compose_sha256": "745bfbac6203afa250031b71ce2a6ccf09f16206e472efa3a4da653f61a43fb1", + "generated_at": "2026-09-14T16:50:34+00:00" + }, + "container_contract": { + "service_name": "kimai", + "container_name": "kimai", + "image": { + "reference": "lscr.io/linuxserver/kimai:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/kimai", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_SECRET", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DATABASE_URL", + "example": "mysql://your_db_user:your_db_pass@your_db_host:3306/your_db_name?charset=your_db_charset&serverVersion=your_db_version", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TRUSTED_HOSTS", + "example": "kimai.example.com", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TRUSTED_PROXIES", + "example": "127.0.0.1/32", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/kimai/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "mariadb", + "image": "lscr.io/linuxserver/mariadb:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n kimai:\n image: lscr.io/linuxserver/kimai:latest\n container_name: kimai\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - APP_SECRET=\n - DATABASE_URL=mysql://your_db_user:your_db_pass@your_db_host:3306/your_db_name?charset=your_db_charset&serverVersion=your_db_version\n - TRUSTED_HOSTS=kimai.example.com\n - TRUSTED_PROXIES=127.0.0.1/32 #optional\n volumes:\n - /path/to/kimai/config:/config\n ports:\n - 80:80\n - 443:443\n restart: unless-stopped\n\n# This container requires an external application to be run separately.\n# MariaDB\n mariadb:\n image: lscr.io/linuxserver/mariadb:latest\n container_name: mariadb\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - MYSQL_ROOT_PASSWORD=ROOT_ACCESS_PASSWORD\n - MYSQL_DATABASE=your_db_name #optional\n - MYSQL_USER=your_db_user #optional\n - MYSQL_PASSWORD=your_db_pass #optional\n volumes:\n - path_to_data:/config\n ports:\n - 3306:3306\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "stack_environment_overrides": { + "kimai": { + "APP_SECRET": "${GENERATED_APP_SECRET}", + "DATABASE_URL": "mysql://kimai:${GENERATED_KIMAI_DB_PASSWORD}@mariadb:3306/kimai?charset=utf8mb4", + "TRUSTED_HOSTS": "^(?:[0-9]{1,3}[.]){3}[0-9]{1,3}$|^localhost$" + }, + "mariadb": { + "MYSQL_ROOT_PASSWORD": "${GENERATED_MARIADB_ROOT_PASSWORD}", + "MYSQL_DATABASE": "kimai", + "MYSQL_USER": "kimai", + "MYSQL_PASSWORD": "${GENERATED_KIMAI_DB_PASSWORD}" + } + }, + "stack_adaptation_notes": [ + "Both images remain LinuxServer images, including lscr.io/linuxserver/mariadb:latest; no database image substitution.", + "MariaDB persists /config and readiness requires an authenticated SELECT 1 as the application user.", + "The DATABASE_URL uses the shared generated database password and automatic server version detection.", + "Initial TRUSTED_HOSTS permits IPv4 hostnames and localhost. Set the intended domain when configuring a reverse proxy.", + "Create the first administrator using the upstream console kimai:user:create command inside the Kimai LXC; no default account is fabricated.", + "Installation, migrations, administrator creation and persistence remain unvalidated in a real OCI LXC." + ], + "stack_references": [ + "https://docs.linuxserver.io/images/docker-kimai/", + "https://docs.linuxserver.io/images/docker-mariadb/" + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + }, + "stack_completion_notes": [ + "Kimai has no default account. Enter the container with: pct enter {main_vmid}", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN" + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + }, + "compose_stack": { + "project_name": "kimai", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "kimai", + "service_count": 2, + "services": [ + { + "name": "mariadb", + "image": "lscr.io/linuxserver/mariadb:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "lscr.io/linuxserver/mariadb:latest", + "container_name": "mariadb", + "environment": [ + "PUID=1000", + "PGID=1000", + "TZ=Etc/UTC", + "MYSQL_ROOT_PASSWORD=ROOT_ACCESS_PASSWORD", + "MYSQL_DATABASE=your_db_name", + "MYSQL_USER=your_db_user", + "MYSQL_PASSWORD=your_db_pass" + ], + "volumes": [ + "path_to_data:/config" + ], + "ports": [ + "3306:3306" + ], + "restart": "unless-stopped" + } + }, + { + "name": "kimai", + "image": "lscr.io/linuxserver/kimai:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "lscr.io/linuxserver/kimai:latest", + "container_name": "kimai", + "environment": [ + "PUID=1000", + "PGID=1000", + "TZ=Etc/UTC", + "APP_SECRET=", + "DATABASE_URL=mysql://your_db_user:your_db_pass@your_db_host:3306/your_db_name?charset=your_db_charset&serverVersion=your_db_version", + "TRUSTED_HOSTS=kimai.example.com", + "TRUSTED_PROXIES=127.0.0.1/32" + ], + "volumes": [ + "/path/to/kimai/config:/config" + ], + "ports": [ + "80:80", + "443:443" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "kimai-volume-0", + "service": "kimai", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "mariadb-volume-0", + "service": "mariadb", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "mariadb", + "kimai" + ], + "stop_order": [ + "kimai", + "mariadb" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + } +} diff --git a/oci/catalog/apps/kometa.json b/oci/catalog/apps/kometa.json new file mode 100644 index 00000000..1569f76d --- /dev/null +++ b/oci/catalog/apps/kometa.json @@ -0,0 +1,260 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-kometa", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Kometa" + }, + "tagline": { + "en_US": "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more." + }, + "description": { + "en_US": "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kometa-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kometa-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://github.com/Kometa-Team/Kometa", + "documentation": "https://docs.linuxserver.io/images/docker-kometa/", + "repository": "https://github.com/linuxserver/docker-kometa", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-06", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-24", + "note": "Rebase to Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-kometa", + "default_branch": "main", + "revision": "daf08dd7ab16843c5901f3bf46499102ecffdddb", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-kometa/daf08dd7ab16843c5901f3bf46499102ecffdddb/README.md", + "readme_pushed_at": "2026-09-12T01:47:49Z", + "compose_sha256": "0860adea99372d9fcd8f0bcb1daf1c032b5cc0d93109f9736ad65170c81f269c", + "generated_at": "2026-09-12T14:37:29+00:00" + }, + "container_contract": { + "service_name": "kometa", + "container_name": "kometa", + "image": { + "reference": "lscr.io/linuxserver/kometa:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/kometa", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "KOMETA_CONFIG", + "example": "/config/config.yml", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "KOMETA_TIMES", + "example": "03:00", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "KOMETA_RUN", + "example": "False", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "KOMETA_TESTS", + "example": "False", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "KOMETA_NO_MISSING", + "example": "False", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/kometa/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n kometa:\n image: lscr.io/linuxserver/kometa:latest\n container_name: kometa\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - KOMETA_CONFIG=/config/config.yml #optional\n - KOMETA_TIMES=03:00 #optional\n - KOMETA_RUN=False #optional\n - KOMETA_TESTS=False #optional\n - KOMETA_NO_MISSING=False #optional\n volumes:\n - /path/to/kometa/config:/config\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/komga.json b/oci/catalog/apps/komga.json new file mode 100644 index 00000000..7cfd2a6e --- /dev/null +++ b/oci/catalog/apps/komga.json @@ -0,0 +1,484 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-komga", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Komga" + }, + "tagline": { + "en_US": "Komga is a media server for your comics, mangas, BDs, magazines and eBooks." + }, + "description": { + "en_US": "Komga is a self-hosted app designed for managing comics, manga, magazines, and e-books (supporting CBZ, CBR, PDF, and EPUB formats), offering a secure and convenient solution for personal media libraries. Its responsive Web interface enables users to access and manage content effortlessly via any browser, without complex local installations, ideal for comic and e-book enthusiasts.\n\nThe app's core features include versatile content organization and diverse reading options. Users can arrange their library with collections and reading lists, edit metadata for series or books, and keep content neatly organized. It integrates a built-in Web reader, supports Mihon SDK extensions, or connects with third-party OPDS readers, catering to varied reading preferences. Whether managing a personal comic collection or sharing e-books with family, it supports multi-user access and delivers a smooth browsing experience. Bulk import streamlines large media library management, perfect for efficient content organization.\n\nIt can be flexibly deployed on personal servers or NAS devices, with an active community providing support documentation, enabling users to extend functionality through community resources. Whether building a personal digital library or a private media-sharing hub, the app's intuitive interface and high customizability offer a secure, modern media management platform, meeting needs from casual reading to professional collections.\n\n**Key Features:**\n- Organize your library with collections and read lists\n- Edit metadata for your series and books\n- Import embedded metadata automatically\n- Webreader with multiple reading modes\n- Manage multiple users, with per-library access control, age restrictions, and labels restrictions\n- Offers a REST API, many community tools and scripts can interact with Komga\n- OPDS v1 and v2 support\n- Kobo Sync with your Kobo eReader\n- KOReader Sync\n- Download book files, whole series, or read lists\n- Duplicate files detection\n- Duplicate pages detection and removal\n- Import books from outside your libraries directly into your series folder\n- Import ComicRack cbl read lists\n\n**Learn More:**\n- [Komga Official Website](https://komga.org)\n- [Komga GitHub Repository](https://github.com/gotson/komga)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "gotson", + "developer": "gotson", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 25600, + "path": "/" + }, + "website": "https://komga.org", + "documentation": null, + "repository": "https://hub.docker.com/r/gotson/komga", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "gotson", + "repository": "https://hub.docker.com/r/gotson/komga", + "revision": "1b5a7748b9bd132592e3ea7200cd6d04796111507099de3bd21686079f2e2a28", + "image_repository_url": "https://hub.docker.com/r/gotson/komga", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "1b5a7748b9bd132592e3ea7200cd6d04796111507099de3bd21686079f2e2a28", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "komga", + "container_name": "komga", + "image": { + "reference": "gotson/komga:latest", + "registry": "docker.io", + "repository": "gotson/komga", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/etc/timezone", + "compose_source_example": "/etc/timezone", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 25600, + "published_example": 25600, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: komga\nservices:\n komga:\n image: gotson/komga:latest\n container_name: komga\n deploy:\n resources:\n reservations:\n memory: 128M\n network_mode: bridge\n ports:\n - target: 25600\n published: '25600'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n - type: bind\n source: /etc/timezone\n target: /etc/timezone\n environment:\n PGID: '1000'\n PUID: '1000'\n" + }, + "compose_stack": { + "project_name": "komga", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "komga", + "service_count": 1, + "services": [ + { + "name": "komga", + "image": "gotson/komga:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "gotson/komga:latest", + "container_name": "komga", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 25600, + "published": "25600", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + }, + { + "type": "bind", + "source": "/etc/timezone", + "target": "/etc/timezone" + } + ], + "environment": { + "PGID": "1000", + "PUID": "1000" + } + } + } + ], + "top_level": { + "name": "komga" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "komga-volume-0", + "service": "komga", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "komga-volume-1", + "service": "komga", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for komga:/data" + }, + { + "id": "komga-volume-2", + "service": "komga", + "container_path": "/etc/timezone", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/timezone", + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "komga" + ], + "stop_order": [ + "komga" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 25600, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/krita.json b/oci/catalog/apps/krita.json new file mode 100644 index 00000000..4b4ec14e --- /dev/null +++ b/oci/catalog/apps/krita.json @@ -0,0 +1,379 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-krita", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Krita" + }, + "tagline": { + "en_US": "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone." + }, + "description": { + "en_US": "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/krita-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/krita-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://krita.org/en/", + "documentation": "https://docs.linuxserver.io/images/docker-krita/", + "repository": "https://github.com/linuxserver/docker-krita", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Debian, use AppImage, HTTPS IS NOW REQUIRED. Remove arm64 support." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-03-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-krita", + "default_branch": "master", + "revision": "f8dd0899467ae1c2142e5b0a322566f40b189fe6", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-krita/f8dd0899467ae1c2142e5b0a322566f40b189fe6/README.md", + "readme_pushed_at": "2026-09-11T12:45:23Z", + "compose_sha256": "46bf0641852ac0500f637183733c4a2555c06ab2135bbdab6ee6efd6d2305d0e", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "krita", + "container_name": "krita", + "image": { + "reference": "lscr.io/linuxserver/krita:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/krita", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n krita:\n image: lscr.io/linuxserver/krita:latest\n container_name: krita\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI 1", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "linuxserver-readme-application-setup" + }, + { + "label": "Web UI 2", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-krita/master/Dockerfile", + "dockerfile_sha256": "fc2b53881d92760de6ae19281175cfc73966986ce47ec673e2ef275827aa83d1", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/label-studio.json b/oci/catalog/apps/label-studio.json new file mode 100644 index 00000000..d2f47798 --- /dev/null +++ b/oci/catalog/apps/label-studio.json @@ -0,0 +1,427 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-label-studio", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Label Studio" + }, + "tagline": { + "en_US": "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models." + }, + "description": { + "en_US": "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Yidadaa", + "developer": "Yidadaa", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://labelstud.io/", + "documentation": null, + "repository": "https://hub.docker.com/r/heartexlabs/label-studio", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "heartexlabs", + "repository": "https://hub.docker.com/r/heartexlabs/label-studio", + "revision": "27e7bfaa3df5df8b4ed5b8b07b4010ba849893892ffefaa73d5f96b24eace461", + "image_repository_url": "https://hub.docker.com/r/heartexlabs/label-studio", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "27e7bfaa3df5df8b4ed5b8b07b4010ba849893892ffefaa73d5f96b24eace461", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "label-studio", + "container_name": "label-studio", + "image": { + "reference": "heartexlabs/label-studio:latest", + "registry": "docker.io", + "repository": "heartexlabs/label-studio", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/label-studio/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 3080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: label-studio\nservices:\n label-studio:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n image: heartexlabs/label-studio:latest\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n ports:\n - target: 8080\n published: '3080'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /label-studio/data\n" + }, + "compose_stack": { + "project_name": "label-studio", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "label-studio", + "service_count": 1, + "services": [ + { + "name": "label-studio", + "image": "heartexlabs/label-studio:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "image": "heartexlabs/label-studio:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8080, + "published": "3080", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/label-studio/data" + } + ] + } + } + ], + "top_level": { + "name": "label-studio" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "label-studio-volume-0", + "service": "label-studio", + "container_path": "/label-studio/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "label-studio" + ], + "stop_order": [ + "label-studio" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/langflow.json b/oci/catalog/apps/langflow.json new file mode 100644 index 00000000..179c74f2 --- /dev/null +++ b/oci/catalog/apps/langflow.json @@ -0,0 +1,505 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-langflow", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Langflow" + }, + "tagline": { + "en_US": "Open-source UI for building and debugging multi-agent and RAG applications" + }, + "description": { + "en_US": "Langflow is a powerful, open-source UI designed specifically for building and debugging multi-agent and Retrieval-Augmented Generation (RAG) applications. It provides a visual, drag-and-drop interface that simplifies the process of creating complex AI workflows.\n\nThe system consists of two main components:\n- **Langflow**: The main application providing a visual interface for building AI workflows\n- **PostgreSQL**: A robust database system for storing application data and configurations\n\n**Key Features:**\n- Visual, drag-and-drop interface for building AI workflows\n- Support for multi-agent systems and RAG applications\n- Integrated debugging tools for testing and optimization\n- Persistent storage for workflows and configurations\n- Easy deployment with Docker containers\n\n**Learn More:**\n- [Langflow Official Website](https://www.langflow.org)\n- [Langflow GitHub Repository](https://github.com/langflow-ai/langflow)\n- [Documentation](https://docs.langflow.org)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "langflowai", + "developer": "langflowai", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 7860, + "path": "/" + }, + "website": "https://www.langflow.org", + "documentation": null, + "repository": "https://hub.docker.com/r/langflowai/langflow", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/langflowai/langflow", + "revision": "6894f87c8dcf2dcbe9ab9458759d22ff45db68274070202d7d00d300461c9d81", + "image_repository_url": "https://hub.docker.com/r/langflowai/langflow", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "6894f87c8dcf2dcbe9ab9458759d22ff45db68274070202d7d00d300461c9d81", + "generated_at": "2026-09-13T15:48:29+00:00" + }, + "container_contract": { + "service_name": "langflow", + "container_name": "langflow", + "image": { + "reference": "langflowai/langflow:latest", + "registry": "docker.io", + "repository": "langflowai/langflow", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "LANGFLOW_DATABASE_URL", + "example": "postgresql://langflow:langflow@langflow-postgres:5432/langflow", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LANGFLOW_CONFIG_DIR", + "example": "/app/langflow", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/langflow", + "compose_source_example": "/DATA/AppData/$AppID/backend", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 7860, + "published_example": 17860, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "langflow-postgres", + "image": "postgres:latest" + } + ], + "restart": null, + "stop_grace_period": null, + "original_compose": "name: langflow\nservices:\n langflow:\n container_name: langflow\n image: langflowai/langflow:latest\n user: 0:0\n ports:\n - target: 7860\n published: '17860'\n protocol: tcp\n depends_on:\n - langflow-postgres\n networks:\n - langflow-net\n environment:\n - LANGFLOW_DATABASE_URL=postgresql://langflow:langflow@langflow-postgres:5432/langflow\n - LANGFLOW_CONFIG_DIR=/app/langflow\n volumes:\n - /DATA/AppData/$AppID/backend:/app/langflow\n langflow-postgres:\n container_name: langflow-postgress\n image: postgres:latest\n environment:\n - POSTGRES_USER=langflow\n - POSTGRES_PASSWORD=${GENERATED_POSTGRES_PASSWORD}\n - POSTGRES_DB=langflow\n networks:\n - langflow-net\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/postgres\n target: /var/lib/postgresql/data\nnetworks:\n langflow-net:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "langflow", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "langflow", + "service_count": 2, + "services": [ + { + "name": "langflow-postgres", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "langflow-postgress", + "image": "postgres:latest", + "environment": [ + "POSTGRES_USER=langflow", + "POSTGRES_PASSWORD=${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB=langflow" + ], + "networks": [ + "langflow-net" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/postgres", + "target": "/var/lib/postgresql/data" + } + ] + } + }, + { + "name": "langflow", + "image": "langflowai/langflow:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "langflow-postgres" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "langflow", + "image": "langflowai/langflow:latest", + "user": "0:0", + "ports": [ + { + "target": 7860, + "published": "17860", + "protocol": "tcp" + } + ], + "depends_on": [ + "langflow-postgres" + ], + "networks": [ + "langflow-net" + ], + "environment": [ + "LANGFLOW_DATABASE_URL=postgresql://langflow:langflow@langflow-postgres:5432/langflow", + "LANGFLOW_CONFIG_DIR=/app/langflow" + ], + "volumes": [ + "/DATA/AppData/$AppID/backend:/app/langflow" + ] + } + } + ], + "top_level": { + "name": "langflow", + "networks": { + "langflow-net": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "langflow-volume-0", + "service": "langflow", + "container_path": "/app/langflow", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "langflow-postgres-volume-0", + "service": "langflow-postgres", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "langflow-postgres", + "langflow" + ], + "stop_order": [ + "langflow", + "langflow-postgres" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "langflow-postgres", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7860, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/lazylibrarian.json b/oci/catalog/apps/lazylibrarian.json new file mode 100644 index 00000000..0177184e --- /dev/null +++ b/oci/catalog/apps/lazylibrarian.json @@ -0,0 +1,281 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-lazylibrarian", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Lazylibrarian" + }, + "tagline": { + "en_US": "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork." + }, + "description": { + "en_US": "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lazylibrarian-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lazylibrarian-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5299, + "path": "/" + }, + "website": "https://lazylibrarian.gitlab.io/", + "documentation": "https://docs.linuxserver.io/images/docker-lazylibrarian/", + "repository": "https://github.com/linuxserver/docker-lazylibrarian", + "tips": [], + "mini_changelog": [ + { + "date": "2024-08-14", + "note": "Rebase to Ubuntu Noble." + }, + { + "date": "2023-10-07", + "note": "Install unrar from [linuxserver repo](https://github.com/linuxserver/docker-unrar). Switch to Python virtual environment. Add Levenshtein." + }, + { + "date": "2023-08-10", + "note": "Bump unrar to 6.2.10." + }, + { + "date": "2023-07-01", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + }, + { + "date": "2022-12-07", + "note": "Rebase to Ubuntu Jammy, migrate to s6v3. Use pyproject.toml for deps. Build unrar from source." + } + ], + "display_version": null, + "updated_at": "2024-08-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-lazylibrarian", + "default_branch": "master", + "revision": "392d525b8b26d87babcedba20321b4ee3d4d383b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-lazylibrarian/392d525b8b26d87babcedba20321b4ee3d4d383b/README.md", + "readme_pushed_at": "2026-09-12T09:53:07Z", + "compose_sha256": "aef6000bf97af6174f4d58dd875b240912dd1ffd3edda97a64d5c188bd365f1b", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "lazylibrarian", + "container_name": "lazylibrarian", + "image": { + "reference": "lscr.io/linuxserver/lazylibrarian:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/lazylibrarian", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DOCKER_MODS", + "example": "linuxserver/mods:universal-calibre|linuxserver/mods:lazylibrarian-ffmpeg", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/lazylibrarian/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads/", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/books", + "compose_source_example": "/path/to/data/", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5299, + "published_example": 5299, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n lazylibrarian:\n image: lscr.io/linuxserver/lazylibrarian:latest\n container_name: lazylibrarian\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DOCKER_MODS=linuxserver/mods:universal-calibre|linuxserver/mods:lazylibrarian-ffmpeg #optional\n volumes:\n - /path/to/lazylibrarian/data:/config\n - /path/to/downloads/:/downloads\n - /path/to/data/:/books #optional\n ports:\n - 5299:5299\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5299, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ldap-auth.json b/oci/catalog/apps/ldap-auth.json new file mode 100644 index 00000000..a2370df9 --- /dev/null +++ b/oci/catalog/apps/ldap-auth.json @@ -0,0 +1,252 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ldap-auth", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ldap Auth" + }, + "tagline": { + "en_US": "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user\u2019s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012)." + }, + "description": { + "en_US": "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user\u2019s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012)." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ldap-auth-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ldap-auth-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8888, + "path": "/" + }, + "website": "https://github.com/nginxinc/nginx-ldap-auth", + "documentation": "https://docs.linuxserver.io/images/docker-ldap-auth/", + "repository": "https://github.com/linuxserver/docker-ldap-auth", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-17", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2024-12-25", + "note": "Add `legacy-cgi`. Fix fernet key storage." + }, + { + "date": "2024-12-22", + "note": "Rebase to Alpine 3.21. Add support for read-only and non-root." + }, + { + "date": "2024-06-30", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2026-07-17" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ldap-auth", + "default_branch": "master", + "revision": "ffda25e21ae4b01e60f46195496b995b1c95d136", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ldap-auth/ffda25e21ae4b01e60f46195496b995b1c95d136/README.md", + "readme_pushed_at": "2026-09-06T16:30:37Z", + "compose_sha256": "1ea640a52f0ca46062ec1cae9f8cf59ab63b9cbf08fd7af3d2879c003312c8ee", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "ldap-auth", + "container_name": "ldap-auth", + "image": { + "reference": "lscr.io/linuxserver/ldap-auth:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ldap-auth", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FERNETKEY", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CERTFILE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "KEYFILE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 8888, + "published_example": 8888, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9000, + "published_example": 9000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ldap-auth:\n image: lscr.io/linuxserver/ldap-auth:latest\n container_name: ldap-auth\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - FERNETKEY= #optional\n - CERTFILE= #optional\n - KEYFILE= #optional\n ports:\n - 8888:8888\n - 9000:9000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8888, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/librechat.json b/oci/catalog/apps/librechat.json new file mode 100644 index 00000000..594b29d1 --- /dev/null +++ b/oci/catalog/apps/librechat.json @@ -0,0 +1,1305 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-librechat", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "LibreChat" + }, + "tagline": { + "en_US": "A full-featured, open-source AI chat interface" + }, + "description": { + "en_US": "LibreChat is a full-featured, open-source AI chat interface that allows users to interact with multiple AI models through a unified platform. It supports various AI providers and offers advanced features like conversation management, plugin support, and customizable interfaces.\n**Key Features:**\n- Support for multiple AI models and providers\n- Conversation history and management\n- Plugin system for extended functionality\n- Customizable themes and interfaces\n- User authentication and management\n- API integrations for various services\n- Search functionality with MeiliSearch\n- RAG (Retrieval-Augmented Generation) support\n- File upload and processing capabilities\n- Multi-language support\n\n**Learn More:**\n- [LibreChat Official Website](https://www.librechat.ai)\n- [LibreChat GitHub Repository](https://github.com/danny-avila/LibreChat)\n\n**extra:**\nYou can refer to the [Custom AI Endpoints](https://www.librechat.ai/docs/configuration/librechat_yaml/ai_endpoints) documentation to configure the relevant files for calling the APIs of Anyscale, ApiPie, Cohere, Deepseek, Databricks, Fireworks, Groq, HuggingFace, Mistral, OpenRouter, Perplexity, ShuttleAI, TogetherAI, Unify, and xAI.\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "LibreChat", + "developer": "LibreChat", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3080, + "path": "/" + }, + "website": "https://www.librechat.ai", + "documentation": null, + "repository": "https://ghcr.io/danny-avila/librechat-dev", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "danny-avila", + "repository": "https://ghcr.io/danny-avila/librechat-dev", + "revision": "317c5bd2b9967f7396645b303872ca02fa799531ad50c311a670d1d9d7af3db8", + "image_repository_url": "https://ghcr.io/danny-avila/librechat-dev", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "317c5bd2b9967f7396645b303872ca02fa799531ad50c311a670d1d9d7af3db8", + "generated_at": "2026-09-13T15:48:30+00:00" + }, + "container_contract": { + "service_name": "librechat-api", + "container_name": "librechat-api", + "image": { + "reference": "ghcr.io/danny-avila/librechat-dev:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/danny-avila/librechat-dev", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ASSISTANTS_API_KEY", + "example": "${GENERATED_ASSISTANTS_API_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "OPENAI_API_KEY", + "example": "${GENERATED_OPENAI_API_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "GOOGLE_KEY", + "example": "${GENERATED_GOOGLE_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "ANTHROPIC_API_KEY", + "example": "${GENERATED_ANTHROPIC_API_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "HOST", + "example": "0.0.0.0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PORT", + "example": "3080", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DOMAIN_CLIENT", + "example": "http://0.0.0.0:3080", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DOMAIN_SERVER", + "example": "http://0.0.0.0:3080", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NO_INDEX", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TRUST_PROXY", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CONSOLE_JSON", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEBUG_LOGGING", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEBUG_CONSOLE", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MONGO_URI", + "example": "mongodb://librechat-mongodb:27017/LibreChat", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MEILI_HOST", + "example": "http://librechat-meilisearch:7700", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "RAG_PORT", + "example": "8000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "RAG_API_URL", + "example": "http://librechat-rag-api:8000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SEARCH", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MEILI_NO_ANALYTICS", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "OPENAI_MODERATION", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BAN_VIOLATIONS", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BAN_DURATION", + "example": "1000 * 60 * 60 * 2", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BAN_INTERVAL", + "example": "20", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOGIN_VIOLATION_SCORE", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REGISTRATION_VIOLATION_SCORE", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CONCURRENT_VIOLATION_SCORE", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MESSAGE_VIOLATION_SCORE", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NON_BROWSER_VIOLATION_SCORE", + "example": "20", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TTS_VIOLATION_SCORE", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "STT_VIOLATION_SCORE", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "FORK_VIOLATION_SCORE", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "IMPORT_VIOLATION_SCORE", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "FILE_UPLOAD_VIOLATION_SCORE", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOGIN_MAX", + "example": "7", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOGIN_WINDOW", + "example": "5", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REGISTER_MAX", + "example": "5", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REGISTER_WINDOW", + "example": "60", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LIMIT_CONCURRENT_MESSAGES", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CONCURRENT_MESSAGE_MAX", + "example": "2", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LIMIT_MESSAGE_IP", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MESSAGE_IP_MAX", + "example": "40", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MESSAGE_IP_WINDOW", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LIMIT_MESSAGE_USER", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MESSAGE_USER_MAX", + "example": "40", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MESSAGE_USER_WINDOW", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ILLEGAL_MODEL_REQ_SCORE", + "example": "5", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ALLOW_EMAIL_LOGIN", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ALLOW_REGISTRATION", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ALLOW_SOCIAL_LOGIN", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ALLOW_SOCIAL_REGISTRATION", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ALLOW_PASSWORD_RESET", + "example": "${GENERATED_ALLOW_PASSWORD_RESET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "ALLOW_UNVERIFIED_EMAIL_LOGIN", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SESSION_EXPIRY", + "example": "1000 * 60 * 15", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REFRESH_TOKEN_EXPIRY", + "example": "${GENERATED_REFRESH_TOKEN_EXPIRY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "JWT_SECRET", + "example": "${GENERATED_JWT_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "JWT_REFRESH_SECRET", + "example": "${GENERATED_JWT_REFRESH_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "CREDS_KEY", + "example": "${GENERATED_CREDS_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "CREDS_IV", + "example": "e2341419ec3dd3d19b13a1a87fafcbfb", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEBUG_PLUGINS", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEBUG_OPENAI", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/client/public/images", + "compose_source_example": "/DATA/AppData/$AppID/images", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/app/uploads", + "compose_source_example": "/DATA/AppData/$AppID/uploads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/app/api/logs", + "compose_source_example": "/DATA/AppData/$AppID/logs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3080, + "published_example": 3080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "librechat-mongodb", + "image": "mongo:latest" + }, + { + "name": "librechat-meilisearch", + "image": "getmeili/meilisearch:latest" + }, + { + "name": "librechat-vectordb", + "image": "ankane/pgvector:latest" + }, + { + "name": "librechat-rag-api", + "image": "ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: librechat\nservices:\n librechat-api:\n container_name: librechat-api\n ports:\n - 3080:3080\n depends_on:\n - librechat-mongodb\n - librechat-rag-api\n image: ghcr.io/danny-avila/librechat-dev:latest\n restart: unless-stopped\n extra_hosts:\n - host.docker.internal:host-gateway\n environment:\n - ASSISTANTS_API_KEY=${GENERATED_ASSISTANTS_API_KEY}\n - OPENAI_API_KEY=${GENERATED_OPENAI_API_KEY}\n - GOOGLE_KEY=${GENERATED_GOOGLE_KEY}\n - ANTHROPIC_API_KEY=${GENERATED_ANTHROPIC_API_KEY}\n - HOST=0.0.0.0\n - PORT=3080\n - DOMAIN_CLIENT=http://0.0.0.0:3080\n - DOMAIN_SERVER=http://0.0.0.0:3080\n - NO_INDEX=true\n - TRUST_PROXY=1\n - CONSOLE_JSON=false\n - DEBUG_LOGGING=true\n - DEBUG_CONSOLE=false\n - MONGO_URI=mongodb://librechat-mongodb:27017/LibreChat\n - MEILI_HOST=http://librechat-meilisearch:7700\n - RAG_PORT=8000\n - RAG_API_URL=http://librechat-rag-api:8000\n - SEARCH=true\n - MEILI_NO_ANALYTICS=true\n - OPENAI_MODERATION=false\n - BAN_VIOLATIONS=true\n - BAN_DURATION=1000 * 60 * 60 * 2\n - BAN_INTERVAL=20\n - LOGIN_VIOLATION_SCORE=1\n - REGISTRATION_VIOLATION_SCORE=1\n - CONCURRENT_VIOLATION_SCORE=1\n - MESSAGE_VIOLATION_SCORE=1\n - NON_BROWSER_VIOLATION_SCORE=20\n - TTS_VIOLATION_SCORE=0\n - STT_VIOLATION_SCORE=0\n - FORK_VIOLATION_SCORE=0\n - IMPORT_VIOLATION_SCORE=0\n - FILE_UPLOAD_VIOLATION_SCORE=0\n - LOGIN_MAX=7\n - LOGIN_WINDOW=5\n - REGISTER_MAX=5\n - REGISTER_WINDOW=60\n - LIMIT_CONCURRENT_MESSAGES=true\n - CONCURRENT_MESSAGE_MAX=2\n - LIMIT_MESSAGE_IP=true\n - MESSAGE_IP_MAX=40\n - MESSAGE_IP_WINDOW=1\n - LIMIT_MESSAGE_USER=false\n - MESSAGE_USER_MAX=40\n - MESSAGE_USER_WINDOW=1\n - ILLEGAL_MODEL_REQ_SCORE=5\n - ALLOW_EMAIL_LOGIN=true\n - ALLOW_REGISTRATION=true\n - ALLOW_SOCIAL_LOGIN=false\n - ALLOW_SOCIAL_REGISTRATION=false\n - ALLOW_PASSWORD_RESET=${GENERATED_ALLOW_PASSWORD_RESET}\n - ALLOW_UNVERIFIED_EMAIL_LOGIN=true\n - SESSION_EXPIRY=1000 * 60 * 15\n - REFRESH_TOKEN_EXPIRY=${GENERATED_REFRESH_TOKEN_EXPIRY}\n - JWT_SECRET=${GENERATED_JWT_SECRET}\n - JWT_REFRESH_SECRET=${GENERATED_JWT_REFRESH_SECRET}\n - CREDS_KEY=${GENERATED_CREDS_KEY}\n - CREDS_IV=e2341419ec3dd3d19b13a1a87fafcbfb\n - DEBUG_PLUGINS=true\n - DEBUG_OPENAI=false\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/images\n target: /app/client/public/images\n - type: bind\n source: /DATA/AppData/$AppID/uploads\n target: /app/uploads\n - type: bind\n source: /DATA/AppData/$AppID/logs\n target: /app/api/logs\n networks:\n - librechat-net\n deploy:\n resources:\n reservations:\n memory: 1024M\n librechat-mongodb:\n container_name: librechat-mongodb\n image: mongo:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data-node\n target: /data/db\n command:\n - mongod\n - --noauth\n networks:\n - librechat-net\n deploy:\n resources:\n reservations:\n memory: 1024M\n librechat-meilisearch:\n container_name: librechat-meilisearch\n image: getmeili/meilisearch:latest\n restart: unless-stopped\n user: 1000:1000\n environment:\n - MEILI_HOST=http://librechat-meilisearch:7700\n - MEILI_NO_ANALYTICS=true\n - MEILI_MASTER_KEY=${GENERATED_MEILI_MASTER_KEY}\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/meili_data_v1.12\n target: /meili_data\n networks:\n - librechat-net\n librechat-vectordb:\n container_name: librechat-vectordb\n image: ankane/pgvector:latest\n environment:\n POSTGRES_DB: mydatabase\n POSTGRES_USER: myuser\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n restart: unless-stopped\n volumes:\n - /DATA/AppData/$AppID/postgresql/data:/var/lib/postgresql/data\n networks:\n - librechat-net\n deploy:\n resources:\n reservations:\n memory: 500M\n librechat-rag-api:\n container_name: librechat-rag-api\n image: ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest\n environment:\n - DB_HOST=librechat-vectordb\n - RAG_PORT=8000\n restart: unless-stopped\n depends_on:\n - librechat-vectordb\n networks:\n - librechat-net\n deploy:\n resources:\n reservations:\n memory: 1024M\nnetworks:\n librechat-net:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "librechat", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "librechat-api", + "service_count": 5, + "services": [ + { + "name": "librechat-meilisearch", + "image": "getmeili/meilisearch:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "librechat-meilisearch", + "image": "getmeili/meilisearch:latest", + "restart": "unless-stopped", + "user": "1000:1000", + "environment": [ + "MEILI_HOST=http://librechat-meilisearch:7700", + "MEILI_NO_ANALYTICS=true", + "MEILI_MASTER_KEY=${GENERATED_MEILI_MASTER_KEY}" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/meili_data_v1.12", + "target": "/meili_data" + } + ], + "networks": [ + "librechat-net" + ] + } + }, + { + "name": "librechat-mongodb", + "image": "mongo:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "librechat-mongodb", + "image": "mongo:latest", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data-node", + "target": "/data/db" + } + ], + "command": [ + "mongod", + "--noauth" + ], + "networks": [ + "librechat-net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + }, + { + "name": "librechat-vectordb", + "image": "ankane/pgvector:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "librechat-vectordb", + "image": "ankane/pgvector:latest", + "environment": { + "POSTGRES_DB": "mydatabase", + "POSTGRES_USER": "myuser", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}" + }, + "restart": "unless-stopped", + "volumes": [ + "/DATA/AppData/$AppID/postgresql/data:/var/lib/postgresql/data" + ], + "networks": [ + "librechat-net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "500M" + } + } + } + } + }, + { + "name": "librechat-rag-api", + "image": "ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 4, + "depends_on": [ + "librechat-vectordb" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "librechat-rag-api", + "image": "ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest", + "environment": [ + "DB_HOST=librechat-vectordb", + "RAG_PORT=8000" + ], + "restart": "unless-stopped", + "depends_on": [ + "librechat-vectordb" + ], + "networks": [ + "librechat-net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + }, + { + "name": "librechat-api", + "image": "ghcr.io/danny-avila/librechat-dev:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "librechat-mongodb", + "librechat-rag-api" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "librechat-api", + "ports": [ + "3080:3080" + ], + "depends_on": [ + "librechat-mongodb", + "librechat-rag-api" + ], + "image": "ghcr.io/danny-avila/librechat-dev:latest", + "restart": "unless-stopped", + "extra_hosts": [ + "host.docker.internal:host-gateway" + ], + "environment": [ + "ASSISTANTS_API_KEY=${GENERATED_ASSISTANTS_API_KEY}", + "OPENAI_API_KEY=${GENERATED_OPENAI_API_KEY}", + "GOOGLE_KEY=${GENERATED_GOOGLE_KEY}", + "ANTHROPIC_API_KEY=${GENERATED_ANTHROPIC_API_KEY}", + "HOST=0.0.0.0", + "PORT=3080", + "DOMAIN_CLIENT=http://0.0.0.0:3080", + "DOMAIN_SERVER=http://0.0.0.0:3080", + "NO_INDEX=true", + "TRUST_PROXY=1", + "CONSOLE_JSON=false", + "DEBUG_LOGGING=true", + "DEBUG_CONSOLE=false", + "MONGO_URI=mongodb://librechat-mongodb:27017/LibreChat", + "MEILI_HOST=http://librechat-meilisearch:7700", + "RAG_PORT=8000", + "RAG_API_URL=http://librechat-rag-api:8000", + "SEARCH=true", + "MEILI_NO_ANALYTICS=true", + "OPENAI_MODERATION=false", + "BAN_VIOLATIONS=true", + "BAN_DURATION=1000 * 60 * 60 * 2", + "BAN_INTERVAL=20", + "LOGIN_VIOLATION_SCORE=1", + "REGISTRATION_VIOLATION_SCORE=1", + "CONCURRENT_VIOLATION_SCORE=1", + "MESSAGE_VIOLATION_SCORE=1", + "NON_BROWSER_VIOLATION_SCORE=20", + "TTS_VIOLATION_SCORE=0", + "STT_VIOLATION_SCORE=0", + "FORK_VIOLATION_SCORE=0", + "IMPORT_VIOLATION_SCORE=0", + "FILE_UPLOAD_VIOLATION_SCORE=0", + "LOGIN_MAX=7", + "LOGIN_WINDOW=5", + "REGISTER_MAX=5", + "REGISTER_WINDOW=60", + "LIMIT_CONCURRENT_MESSAGES=true", + "CONCURRENT_MESSAGE_MAX=2", + "LIMIT_MESSAGE_IP=true", + "MESSAGE_IP_MAX=40", + "MESSAGE_IP_WINDOW=1", + "LIMIT_MESSAGE_USER=false", + "MESSAGE_USER_MAX=40", + "MESSAGE_USER_WINDOW=1", + "ILLEGAL_MODEL_REQ_SCORE=5", + "ALLOW_EMAIL_LOGIN=true", + "ALLOW_REGISTRATION=true", + "ALLOW_SOCIAL_LOGIN=false", + "ALLOW_SOCIAL_REGISTRATION=false", + "ALLOW_PASSWORD_RESET=${GENERATED_ALLOW_PASSWORD_RESET}", + "ALLOW_UNVERIFIED_EMAIL_LOGIN=true", + "SESSION_EXPIRY=1000 * 60 * 15", + "REFRESH_TOKEN_EXPIRY=${GENERATED_REFRESH_TOKEN_EXPIRY}", + "JWT_SECRET=${GENERATED_JWT_SECRET}", + "JWT_REFRESH_SECRET=${GENERATED_JWT_REFRESH_SECRET}", + "CREDS_KEY=${GENERATED_CREDS_KEY}", + "CREDS_IV=e2341419ec3dd3d19b13a1a87fafcbfb", + "DEBUG_PLUGINS=true", + "DEBUG_OPENAI=false" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/images", + "target": "/app/client/public/images" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/uploads", + "target": "/app/uploads" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/logs", + "target": "/app/api/logs" + } + ], + "networks": [ + "librechat-net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + } + ], + "top_level": { + "name": "librechat", + "networks": { + "librechat-net": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "librechat-api-volume-0", + "service": "librechat-api", + "container_path": "/app/client/public/images", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "librechat-api-volume-1", + "service": "librechat-api", + "container_path": "/app/uploads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for librechat-api:/app/uploads" + }, + { + "id": "librechat-api-volume-2", + "service": "librechat-api", + "container_path": "/app/api/logs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "librechat-mongodb-volume-0", + "service": "librechat-mongodb", + "container_path": "/data/db", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for librechat-mongodb:/data/db" + }, + { + "id": "librechat-meilisearch-volume-0", + "service": "librechat-meilisearch", + "container_path": "/meili_data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "librechat-vectordb-volume-0", + "service": "librechat-vectordb", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 5, + "start_order": [ + "librechat-meilisearch", + "librechat-mongodb", + "librechat-vectordb", + "librechat-rag-api", + "librechat-api" + ], + "stop_order": [ + "librechat-api", + "librechat-rag-api", + "librechat-vectordb", + "librechat-mongodb", + "librechat-meilisearch" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "allow-password-reset", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "ALLOW_PASSWORD_RESET" + } + ] + }, + { + "id": "anthropic-api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "ANTHROPIC_API_KEY" + } + ] + }, + { + "id": "assistants-api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "ASSISTANTS_API_KEY" + } + ] + }, + { + "id": "creds-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "CREDS_KEY" + } + ] + }, + { + "id": "google-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "GOOGLE_KEY" + } + ] + }, + { + "id": "jwt-refresh-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "JWT_REFRESH_SECRET" + } + ] + }, + { + "id": "jwt-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "JWT_SECRET" + } + ] + }, + { + "id": "meili-master-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-meilisearch", + "environment_variable": "MEILI_MASTER_KEY" + } + ] + }, + { + "id": "openai-api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "OPENAI_API_KEY" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-vectordb", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + }, + { + "id": "refresh-token-expiry", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "librechat-api", + "environment_variable": "REFRESH_TOKEN_EXPIRY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "extra_hosts": [ + { + "hostname": "host.docker.internal", + "address": "host-gateway" + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "librechat-api: credencial externa o booleano GENERATED_ANTHROPIC_API_KEY pendiente", + "librechat-api: credencial externa o booleano GENERATED_ASSISTANTS_API_KEY pendiente", + "librechat-api: credencial externa o booleano GENERATED_OPENAI_API_KEY pendiente", + "librechat-api: extra_hosts necesita revision de pila", + "librechat-mongodb: comando de dependencia personalizado pendiente", + "librechat-rag-api: perfil de salud y persistencia pendiente", + "librechat-vectordb: perfil de salud y persistencia pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:librechat-rag-api:compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/libredb-studio.json b/oci/catalog/apps/libredb-studio.json new file mode 100644 index 00000000..bfeee30b --- /dev/null +++ b/oci/catalog/apps/libredb-studio.json @@ -0,0 +1,500 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-libredb-studio", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "LibreDB Studio" + }, + "tagline": { + "en_US": "Open-source self-hosted SQL IDE." + }, + "description": { + "en_US": "LibreDB Studio is an open-source (MIT), self-hosted SQL IDE. It provides a modern web-based interface to connect to 16 database engines (PostgreSQL, MySQL, MongoDB, Redis, ClickHouse and more), browse schemas, write and run SQL queries, and manage your data from any browser on your LAN. Data is stored locally in a SQLite database, so everything stays under your control." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "libredb", + "developer": "libredb", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://libredb.org", + "documentation": null, + "repository": "https://hub.docker.com/r/libredb/libredb-studio", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/libredb/libredb-studio", + "revision": "0d1082ed7c4ce17750dc11ffe2f85aae75d00b8135a238f13a746c71f96b0133", + "image_repository_url": "https://hub.docker.com/r/libredb/libredb-studio", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "0d1082ed7c4ce17750dc11ffe2f85aae75d00b8135a238f13a746c71f96b0133", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "libredb-studio", + "container_name": "libredb-studio", + "image": { + "reference": "libredb/libredb-studio:latest", + "registry": "docker.io", + "repository": "libredb/libredb-studio", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ADMIN_EMAIL", + "example": "admin@libredb.org", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ADMIN_PASSWORD", + "example": "${GENERATED_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "JWT_SECRET", + "example": "${GENERATED_JWT_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "STORAGE_PROVIDER", + "example": "sqlite", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "STORAGE_SQLITE_PATH", + "example": "/app/data/libredb-storage.db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "AUTH_COOKIE_SECURE", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3016, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: libredb-studio\nservices:\n libredb-studio:\n image: libredb/libredb-studio:latest\n container_name: libredb-studio\n restart: unless-stopped\n ports:\n - target: 3000\n published: '3016'\n protocol: tcp\n environment:\n ADMIN_EMAIL: admin@libredb.org\n ADMIN_PASSWORD: ${GENERATED_ADMIN_PASSWORD}\n JWT_SECRET: ${GENERATED_JWT_SECRET}\n STORAGE_PROVIDER: sqlite\n STORAGE_SQLITE_PATH: /app/data/libredb-storage.db\n AUTH_COOKIE_SECURE: 'false'\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /app/data\n healthcheck:\n test:\n - CMD\n - node\n - -e\n - require('http').get('http://127.0.0.1:3000/api/db/health',r=>process.exit(r.statusCode===200?0:1)).on('error',()=>process.exit(1))\n interval: 30s\n timeout: 5s\n retries: 5\n start_period: 40s\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "libredb-studio", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "libredb-studio", + "service_count": 1, + "services": [ + { + "name": "libredb-studio", + "image": "libredb/libredb-studio:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "libredb/libredb-studio:latest", + "container_name": "libredb-studio", + "restart": "unless-stopped", + "ports": [ + { + "target": 3000, + "published": "3016", + "protocol": "tcp" + } + ], + "environment": { + "ADMIN_EMAIL": "admin@libredb.org", + "ADMIN_PASSWORD": "${GENERATED_ADMIN_PASSWORD}", + "JWT_SECRET": "${GENERATED_JWT_SECRET}", + "STORAGE_PROVIDER": "sqlite", + "STORAGE_SQLITE_PATH": "/app/data/libredb-storage.db", + "AUTH_COOKIE_SECURE": "false" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/app/data" + } + ], + "healthcheck": { + "test": [ + "CMD", + "node", + "-e", + "require('http').get('http://127.0.0.1:3000/api/db/health',r=>process.exit(r.statusCode===200?0:1)).on('error',()=>process.exit(1))" + ], + "interval": "30s", + "timeout": "5s", + "retries": 5, + "start_period": "40s" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "libredb-studio" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "libredb-studio-volume-0", + "service": "libredb-studio", + "container_path": "/app/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "libredb-studio" + ], + "stop_order": [ + "libredb-studio" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "libredb-studio", + "environment_variable": "ADMIN_PASSWORD" + } + ] + }, + { + "id": "jwt-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "libredb-studio", + "environment_variable": "JWT_SECRET" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "startup_healthcheck": { + "type": "http", + "scheme": "http", + "port": 3000, + "path": "/api/db/health", + "timeout_seconds": 190, + "request_timeout_seconds": 5, + "stability_seconds": 0, + "verify_tls": true, + "required": true, + "source": "compose-healthcheck" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "pending-per-application" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/libreoffice.json b/oci/catalog/apps/libreoffice.json new file mode 100644 index 00000000..5e0335cd --- /dev/null +++ b/oci/catalog/apps/libreoffice.json @@ -0,0 +1,389 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-libreoffice", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Libreoffice" + }, + "tagline": { + "en_US": "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity." + }, + "description": { + "en_US": "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/libreoffice-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/libreoffice-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.libreoffice.org/", + "documentation": "https://docs.linuxserver.io/images/docker-libreoffice/", + "repository": "https://github.com/linuxserver/docker-libreoffice", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, Alpine 3.22, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-libreoffice", + "default_branch": "master", + "revision": "25ce6e30eda02f21670b957bad52fb2565e85c1f", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-libreoffice/25ce6e30eda02f21670b957bad52fb2565e85c1f/README.md", + "readme_pushed_at": "2026-09-08T01:30:30Z", + "compose_sha256": "957be641c2fc4adca30d8f73438d79076fad1249abca297789ae2e80ef6dba06", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "libreoffice", + "container_name": "libreoffice", + "image": { + "reference": "lscr.io/linuxserver/libreoffice:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/libreoffice", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n libreoffice:\n image: lscr.io/linuxserver/libreoffice:latest\n container_name: libreoffice\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "libreoffice-nginx-runtime", + "upstream_behavior": "nginx writes its PID under /run/nginx.", + "native_lxc_behavior": "A native LXC tmpfs creates /run/nginx with mode 0755 on every boot.", + "reason": "The volatile LXC /run hides the directory from the image rootfs.", + "validation": "CT 115 on .55: HTTPS 3001 returned 200 after restart." + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "startup_healthcheck": { + "scheme": "https", + "port": 3001, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-libreoffice/master/Dockerfile", + "dockerfile_sha256": "95ca149b38966fc1819724c0e16f35b7c84faf7ebfe57694ec37927818f282b9", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/librespeed.json b/oci/catalog/apps/librespeed.json new file mode 100644 index 00000000..4087475b --- /dev/null +++ b/oci/catalog/apps/librespeed.json @@ -0,0 +1,304 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-librespeed", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Librespeed" + }, + "tagline": { + "en_US": "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers." + }, + "description": { + "en_US": "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/librespeed-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/librespeed-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/librespeed/speedtest", + "documentation": "https://docs.linuxserver.io/images/docker-librespeed/", + "repository": "https://github.com/linuxserver/docker-librespeed", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-29", + "note": "Rebase to Alpine 3.24. Enable new UI with additional settings files available in the config folder." + }, + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19 with php 8.3." + }, + { + "date": "2023-12-06", + "note": "Replace php mysqli with php pdo_pgsql." + } + ], + "display_version": null, + "updated_at": "2026-07-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-librespeed", + "default_branch": "master", + "revision": "92b3f37f527fe046a163eebcece28b6d02e59320", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-librespeed/92b3f37f527fe046a163eebcece28b6d02e59320/README.md", + "readme_pushed_at": "2026-09-12T13:17:52Z", + "compose_sha256": "229bb9d88560c3f99982a35304a6e4bcfcca79fd2d08ca3b8a091a5f2293ce39", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "librespeed", + "container_name": "librespeed", + "image": { + "reference": "lscr.io/linuxserver/librespeed:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/librespeed", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PASSWORD", + "example": "PASSWORD", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "CUSTOM_RESULTS", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_TYPE", + "example": "sqlite", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_NAME", + "example": "DB_NAME", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOSTNAME", + "example": "DB_HOSTNAME", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USERNAME", + "example": "DB_USERNAME", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "DB_PASSWORD", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "DB_PORT", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "IPINFO_APIKEY", + "example": "ACCESS_TOKEN", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/librespeed/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n librespeed:\n image: lscr.io/linuxserver/librespeed:latest\n container_name: librespeed\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - PASSWORD=PASSWORD\n - CUSTOM_RESULTS=false #optional\n - DB_TYPE=sqlite #optional\n - DB_NAME=DB_NAME #optional\n - DB_HOSTNAME=DB_HOSTNAME #optional\n - DB_USERNAME=DB_USERNAME #optional\n - DB_PASSWORD=DB_PASSWORD #optional\n - DB_PORT=DB_PORT #optional\n - IPINFO_APIKEY=ACCESS_TOKEN #optional\n volumes:\n - /path/to/librespeed/config:/config\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/librewolf.json b/oci/catalog/apps/librewolf.json new file mode 100644 index 00000000..6b7429ec --- /dev/null +++ b/oci/catalog/apps/librewolf.json @@ -0,0 +1,380 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-librewolf", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Librewolf" + }, + "tagline": { + "en_US": "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM." + }, + "description": { + "en_US": "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/librewolf-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/librewolf-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://librewolf.net/", + "documentation": "https://docs.linuxserver.io/images/docker-librewolf/", + "repository": "https://github.com/linuxserver/docker-librewolf", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-10-12", + "note": "Publish aarch64 image. Switch to new upstream repo." + } + ], + "display_version": null, + "updated_at": "2026-03-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-librewolf", + "default_branch": "master", + "revision": "36e268ea357a19e43e6e629d18abe445716d47ac", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-librewolf/36e268ea357a19e43e6e629d18abe445716d47ac/README.md", + "readme_pushed_at": "2026-09-07T07:42:13Z", + "compose_sha256": "b3d366f827b82e7a56d8166f34e8cf7f67cbea61e9d08364128aec3ec0744bf0", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "librewolf", + "container_name": "librewolf", + "image": { + "reference": "lscr.io/linuxserver/librewolf:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/librewolf", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LIBREWOLF_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/librewolf/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n librewolf:\n image: lscr.io/linuxserver/librewolf:latest\n container_name: librewolf\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - LIBREWOLF_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/librewolf/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-librewolf/master/Dockerfile", + "dockerfile_sha256": "85e8f7956eb72f49b520008050bafb77fcd6c3983cdd5cae62aee0c9a6120e33", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/lidarr.json b/oci/catalog/apps/lidarr.json new file mode 100644 index 00000000..9eaa23ec --- /dev/null +++ b/oci/catalog/apps/lidarr.json @@ -0,0 +1,275 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-lidarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Lidarr" + }, + "tagline": { + "en_US": "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available." + }, + "description": { + "en_US": "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lidarr-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lidarr-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8686, + "path": "/" + }, + "website": "https://github.com/lidarr/Lidarr", + "documentation": "https://docs.linuxserver.io/images/docker-lidarr/", + "repository": "https://github.com/linuxserver/docker-lidarr", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-04", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-15", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-23", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase to Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-lidarr", + "default_branch": "master", + "revision": "39b4639a8b6d7685ace64606e2ee89372d0076e4", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-lidarr/39b4639a8b6d7685ace64606e2ee89372d0076e4/README.md", + "readme_pushed_at": "2026-09-09T06:18:59Z", + "compose_sha256": "03a6ff6e86e26a1d0a61a304aeb0d901cf14351bbf28662932214f7557668d1b", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "lidarr", + "container_name": "lidarr", + "image": { + "reference": "lscr.io/linuxserver/lidarr:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/lidarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/lidarr/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/music", + "compose_source_example": "/path/to/music", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8686, + "published_example": 8686, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n lidarr:\n image: lscr.io/linuxserver/lidarr:latest\n container_name: lidarr\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/lidarr/config:/config\n - /path/to/music:/music #optional\n - /path/to/downloads:/downloads #optional\n ports:\n - 8686:8686\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8686, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/limnoria.json b/oci/catalog/apps/limnoria.json new file mode 100644 index 00000000..43eec790 --- /dev/null +++ b/oci/catalog/apps/limnoria.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-limnoria", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Limnoria" + }, + "tagline": { + "en_US": "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot." + }, + "description": { + "en_US": "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/limnoria-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/limnoria-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://github.com/ProgVal/limnoria", + "documentation": "https://docs.linuxserver.io/images/docker-limnoria/", + "repository": "https://github.com/linuxserver/docker-limnoria", + "tips": [], + "mini_changelog": [ + { + "date": "2025-02-01", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-05-25", + "note": "Rebase to Alpine 3.18, deprecate armhf." + }, + { + "date": "2022-12-22", + "note": "Rebase to alpine 3.17." + } + ], + "display_version": null, + "updated_at": "2025-02-01" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-limnoria", + "default_branch": "master", + "revision": "0f3b5d605bc5337d1da33c72729feec8bdb29a85", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-limnoria/0f3b5d605bc5337d1da33c72729feec8bdb29a85/README.md", + "readme_pushed_at": "2026-09-11T21:29:19Z", + "compose_sha256": "da30ad02d12000c1cc5fff51e026c8742110fd96831cd220a3956ece54e1ccda", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "limnoria", + "container_name": "limnoria", + "image": { + "reference": "lscr.io/linuxserver/limnoria:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/limnoria", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/limnoria/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n limnoria:\n image: lscr.io/linuxserver/limnoria:latest\n container_name: limnoria\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/limnoria/config:/config\n ports:\n - 8080:8080\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/linkwarden.json b/oci/catalog/apps/linkwarden.json new file mode 100644 index 00000000..902dbdfe --- /dev/null +++ b/oci/catalog/apps/linkwarden.json @@ -0,0 +1,701 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-linkwarden", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Linkwarden" + }, + "tagline": { + "en_US": "Self-hosted collaborative bookmark manager to collect, read, annotate, and fully preserve what matters, all in one place." + }, + "description": { + "en_US": "Linkwarden is an open-source self-hosted bookmark and web archive manager designed to help users collect, organize, and preserve important online content in one place. In addition to traditional bookmarking capabilities, it provides full webpage backup so valuable information remains safely accessible over time.\n\nBuilt around long-term content preservation, Linkwarden can automatically capture webpage screenshots, PDFs, and full HTML files to help prevent link rot. It also includes reading mode, annotations, local AI-powered tagging, full-text search, and a multi-level classification system for smarter and more efficient information management. Its modular architecture supports self-hosting, browser extensions, and cross-device sync.\n\nIn practice, Linkwarden is suitable not only for personal knowledge management and content collection, but also for team collaboration and shared curation. With collections and permission controls, users can organize content together and manage it publicly or privately. It is a modern bookmarking tool that balances data ownership, security, and collaboration.\n\n**Key Features:**\n\n- Full webpage archiving (screenshots, PDFs, HTML) to prevent link rot\n- AI-powered auto-tagging and full-text search\n- Reading mode, text highlighting, and annotations\n- Multi-level categories and tags for flexible organization\n- Team collaboration and permission management\n\n**Learn more:**\n\n- [Linkwarden GitHub](https://github.com/linkwarden/linkwarden)\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "linkwarden", + "developer": "linkwarden", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://linkwarden.app/", + "documentation": null, + "repository": "https://ghcr.io/linkwarden/linkwarden", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/linkwarden/linkwarden", + "revision": "ca4a37aedfa1786f80a2a8a1d03e337b8bbc8d6f21adedabd357f9d14bfd88ea", + "image_repository_url": "https://ghcr.io/linkwarden/linkwarden", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "ca4a37aedfa1786f80a2a8a1d03e337b8bbc8d6f21adedabd357f9d14bfd88ea", + "generated_at": "2026-09-13T15:48:30+00:00" + }, + "container_contract": { + "service_name": "linkwarden", + "container_name": "linkwarden", + "image": { + "reference": "ghcr.io/linkwarden/linkwarden:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/linkwarden/linkwarden", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_URL", + "example": "http://localhost:3000/api/v1/auth", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_SECRET", + "example": "${GENERATED_NEXTAUTH_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "DATABASE_URL", + "example": "postgresql://postgres:abc123@linkwarden-postgres:5432/linkwarden", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "STORAGE_FOLDER", + "example": "/data", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MEILI_HOST", + "example": "http://linkwarden-meilisearch:7700", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MEILI_MASTER_KEY", + "example": "${GENERATED_MEILI_MASTER_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "NEXT_PUBLIC_DISABLE_REGISTRATION", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXT_PUBLIC_CREDENTIALS_ENABLED", + "example": "${GENERATED_NEXT_PUBLIC_CREDENTIALS_ENABLED}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3428, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "linkwarden-postgres", + "image": "postgres:latest" + }, + { + "name": "linkwarden-meilisearch", + "image": "getmeili/meilisearch:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n linkwarden:\n image: ghcr.io/linkwarden/linkwarden:latest\n container_name: linkwarden\n restart: unless-stopped\n depends_on:\n linkwarden-postgres:\n condition: service_healthy\n linkwarden-meilisearch:\n condition: service_started\n ports:\n - target: 3000\n published: '3428'\n protocol: tcp\n environment:\n TZ: $TZ\n NEXTAUTH_URL: http://localhost:3000/api/v1/auth\n NEXTAUTH_SECRET: ${GENERATED_NEXTAUTH_SECRET}\n DATABASE_URL: postgresql://postgres:abc123@linkwarden-postgres:5432/linkwarden\n STORAGE_FOLDER: /data\n MEILI_HOST: http://linkwarden-meilisearch:7700\n MEILI_MASTER_KEY: ${GENERATED_MEILI_MASTER_KEY}\n NEXT_PUBLIC_DISABLE_REGISTRATION: 'false'\n NEXT_PUBLIC_CREDENTIALS_ENABLED: ${GENERATED_NEXT_PUBLIC_CREDENTIALS_ENABLED}\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data/data\n networks:\n - linkwarden-net\n deploy:\n resources:\n reservations:\n memory: 512m\n linkwarden-postgres:\n image: postgres:latest\n container_name: linkwarden-postgres\n restart: unless-stopped\n environment:\n POSTGRES_USER: postgres\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: linkwarden\n TZ: $TZ\n networks:\n - linkwarden-net\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/pgdata\n target: /var/lib/postgresql/data\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U postgres -d linkwarden\n interval: 10s\n timeout: 5s\n retries: 10\n deploy:\n resources:\n reservations:\n memory: 256m\n linkwarden-meilisearch:\n image: getmeili/meilisearch:latest\n container_name: linkwarden-meilisearch\n restart: unless-stopped\n environment:\n MEILI_MASTER_KEY: ${GENERATED_MEILI_MASTER_KEY}\n MEILI_ENV: production\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/meili_data\n target: /meili_data\n networks:\n - linkwarden-net\n deploy:\n resources:\n reservations:\n memory: 256m\nnetworks:\n linkwarden-net:\n driver: bridge\nname: linkwarden\n" + }, + "compose_stack": { + "project_name": "linkwarden", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "linkwarden", + "service_count": 3, + "services": [ + { + "name": "linkwarden-meilisearch", + "image": "getmeili/meilisearch:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "getmeili/meilisearch:latest", + "container_name": "linkwarden-meilisearch", + "restart": "unless-stopped", + "environment": { + "MEILI_MASTER_KEY": "${GENERATED_MEILI_MASTER_KEY}", + "MEILI_ENV": "production" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/meili_data", + "target": "/meili_data" + } + ], + "networks": [ + "linkwarden-net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "256m" + } + } + } + } + }, + { + "name": "linkwarden-postgres", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:latest", + "container_name": "linkwarden-postgres", + "restart": "unless-stopped", + "environment": { + "POSTGRES_USER": "postgres", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "linkwarden", + "TZ": "$TZ" + }, + "networks": [ + "linkwarden-net" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/pgdata", + "target": "/var/lib/postgresql/data" + } + ], + "healthcheck": { + "test": [ + "CMD-SHELL", + "pg_isready -U postgres -d linkwarden" + ], + "interval": "10s", + "timeout": "5s", + "retries": 10 + }, + "deploy": { + "resources": { + "reservations": { + "memory": "256m" + } + } + } + } + }, + { + "name": "linkwarden", + "image": "ghcr.io/linkwarden/linkwarden:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "linkwarden-meilisearch", + "linkwarden-postgres" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "ghcr.io/linkwarden/linkwarden:latest", + "container_name": "linkwarden", + "restart": "unless-stopped", + "depends_on": { + "linkwarden-postgres": { + "condition": "service_healthy" + }, + "linkwarden-meilisearch": { + "condition": "service_started" + } + }, + "ports": [ + { + "target": 3000, + "published": "3428", + "protocol": "tcp" + } + ], + "environment": { + "TZ": "$TZ", + "NEXTAUTH_URL": "http://localhost:3000/api/v1/auth", + "NEXTAUTH_SECRET": "${GENERATED_NEXTAUTH_SECRET}", + "DATABASE_URL": "postgresql://postgres:abc123@linkwarden-postgres:5432/linkwarden", + "STORAGE_FOLDER": "/data", + "MEILI_HOST": "http://linkwarden-meilisearch:7700", + "MEILI_MASTER_KEY": "${GENERATED_MEILI_MASTER_KEY}", + "NEXT_PUBLIC_DISABLE_REGISTRATION": "false", + "NEXT_PUBLIC_CREDENTIALS_ENABLED": "${GENERATED_NEXT_PUBLIC_CREDENTIALS_ENABLED}" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data/data" + } + ], + "networks": [ + "linkwarden-net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "512m" + } + } + } + } + } + ], + "top_level": { + "networks": { + "linkwarden-net": { + "driver": "bridge" + } + }, + "name": "linkwarden" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "linkwarden-volume-0", + "service": "linkwarden", + "container_path": "/data/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for linkwarden:/data/data" + }, + { + "id": "linkwarden-postgres-volume-0", + "service": "linkwarden-postgres", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "linkwarden-meilisearch-volume-0", + "service": "linkwarden-meilisearch", + "container_path": "/meili_data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "linkwarden-meilisearch", + "linkwarden-postgres", + "linkwarden" + ], + "stop_order": [ + "linkwarden", + "linkwarden-postgres", + "linkwarden-meilisearch" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "meili-master-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "linkwarden", + "environment_variable": "MEILI_MASTER_KEY" + }, + { + "service": "linkwarden-meilisearch", + "environment_variable": "MEILI_MASTER_KEY" + } + ] + }, + { + "id": "next-public-credentials-enabled", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "linkwarden", + "environment_variable": "NEXT_PUBLIC_CREDENTIALS_ENABLED" + } + ] + }, + { + "id": "nextauth-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "linkwarden", + "environment_variable": "NEXTAUTH_SECRET" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "linkwarden-postgres", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "stack_environment_overrides": { + "linkwarden": { + "NEXT_PUBLIC_CREDENTIALS_ENABLED": "true", + "STORAGE_FOLDER": "/data/data" + } + }, + "stack_adaptation_notes": [ + "Credential login is a boolean option, never a generated secret.", + "STORAGE_FOLDER points to the persisted /data/data mount.", + "The same generated MEILI_MASTER_KEY is used by Linkwarden and Meilisearch.", + "Latest dependency tags remain selected; application compatibility must be checked by an actual installation." + ], + "stack_references": [ + "https://github.com/linkwarden/linkwarden/blob/main/docker-compose.yml", + "https://docs.linkwarden.app/self-hosting/environment-variables", + "https://www.meilisearch.com/docs/reference/api/health/get-health" + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/llama-factory-nvidia.json b/oci/catalog/apps/llama-factory-nvidia.json new file mode 100644 index 00000000..18dc7d13 --- /dev/null +++ b/oci/catalog/apps/llama-factory-nvidia.json @@ -0,0 +1,404 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-llama-factory-nvidia", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "LLaMA Factory(Nvidia GPU)" + }, + "tagline": { + "en_US": "Unified LLM Fine-Tuning with 100+ Models" + }, + "description": { + "en_US": "LLaMA Factory is a comprehensive framework for fine-tuning Large Language Models (LLMs) with support for over 100 models. It provides a user-friendly web interface and powerful training methods including LoRA, QLoRA, and full-parameter training.\n\n**Key Features:**\n- Support for 100+ LLMs including LLaMA, Mistral, Qwen, and more\n- Multiple fine-tuning methods (LoRA, QLoRA, Full, Freeze)\n- Intuitive Web UI for easy model management\n- Built-in API server for model inference\n- Multi-GPU training support\n- Quantization and model export capabilities\n\n**Hardware Requirements:**\n- GPU: NVIDIA GPU with CUDA support required\n\n**Learn More:**\n- [GitHub Repository](https://github.com/hiyouga/LLaMA-Factory)\n- [Documentation](https://llamafactory.readthedocs.io/)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "hiyouga", + "developer": "hiyouga", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 7860, + "path": "/" + }, + "website": "https://llamafactory.readthedocs.io/", + "documentation": null, + "repository": "https://hub.docker.com/r/hiyouga/llamafactory", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "hiyouga", + "repository": "https://hub.docker.com/r/hiyouga/llamafactory", + "revision": "ac992e2b46bf335db07219cd66f1acfa58cbc4bf14b9e094ce650364c9087792", + "image_repository_url": "https://hub.docker.com/r/hiyouga/llamafactory", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "ac992e2b46bf335db07219cd66f1acfa58cbc4bf14b9e094ce650364c9087792", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "llama-factory-nvidia", + "container_name": "llama-factory-nvidia", + "image": { + "reference": "hiyouga/llamafactory:latest", + "registry": "docker.io", + "repository": "hiyouga/llamafactory", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [ + { + "container_port": 7860, + "published_example": 18877, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: llama-factory-nvidia\nservices:\n llama-factory-nvidia:\n image: hiyouga/llamafactory:latest\n container_name: llama-factory-nvidia\n ports:\n - target: 7860\n published: '18877'\n protocol: tcp\n tty: true\n stdin_open: true\n command:\n - llamafactory-cli\n - webui\n deploy:\n resources:\n reservations:\n memory: 6G\n devices:\n - driver: nvidia\n count: all\n capabilities:\n - gpu\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "llama-factory-nvidia", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "llama-factory-nvidia", + "service_count": 1, + "services": [ + { + "name": "llama-factory-nvidia", + "image": "hiyouga/llamafactory:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "hiyouga/llamafactory:latest", + "container_name": "llama-factory-nvidia", + "ports": [ + { + "target": 7860, + "published": "18877", + "protocol": "tcp" + } + ], + "tty": true, + "stdin_open": true, + "command": [ + "llamafactory-cli", + "webui" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "6G", + "devices": [ + { + "driver": "nvidia", + "count": "all", + "capabilities": [ + "gpu" + ] + } + ] + } + } + }, + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "llama-factory-nvidia" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "llama-factory-nvidia" + ], + "stop_order": [ + "llama-factory-nvidia" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7860, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 6144, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "llamafactory-cli", + "webui" + ] + }, + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "enable_prompt": "Enable the NVIDIA GPU requested by the image", + "enabled_default": true, + "required_by_compose": true, + "risk_level": "hardware-access", + "device_selection": "all-requested-by-compose", + "driver_libraries": "bind-compatible-host-driver-libraries-read-only" + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/llamacpp.json b/oci/catalog/apps/llamacpp.json new file mode 100644 index 00000000..3ed8fc65 --- /dev/null +++ b/oci/catalog/apps/llamacpp.json @@ -0,0 +1,430 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-llamacpp", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "llama.cpp" + }, + "tagline": { + "en_US": "Run GGUF LLMs locally with GPU acceleration" + }, + "description": { + "en_US": "llama.cpp is a pure C/C++ inference engine for GGUF large language models, with the official OpenAI-compatible server and a built-in Web UI.\n\n**Key Features:**\n- Run GGUF models (Llama, Qwen, DeepSeek, Gemma, Mistral and more) on CPU or GPU\n- Vulkan backend works on AMD / Intel / NVIDIA GPUs out of the box\n- Great fit for unified-memory machines (e.g. AMD Ryzen AI Max 395)\n- OpenAI-compatible API for integration with Open WebUI, ChatGPT-Next-Web and more\n- Built-in chat Web UI with runtime model loading\n\n**Getting started:**\n1. Put GGUF model files into the models volume (`/models`)\n2. Open the Web UI at `http://:18080` and load a model\n3. Keep `/dev/dri` mapped for Vulkan acceleration; remove it for CPU-only mode" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "ggml-org", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://github.com/ggml-org/llama.cpp", + "documentation": null, + "repository": "https://ghcr.io/ggml-org/llama.cpp", + "tips": [ + "The generic latest image uses its default backend. VA-API device passthrough was removed because it does not select a llama.cpp compute backend." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "ggml-org", + "repository": "https://ghcr.io/ggml-org/llama.cpp", + "revision": "c6c95211bb6027b0e7849d4b97c26df894484a73393e4348d1ff89fb694bb2b1", + "image_repository_url": "https://ghcr.io/ggml-org/llama.cpp", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "c6c95211bb6027b0e7849d4b97c26df894484a73393e4348d1ff89fb694bb2b1", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "llamacpp", + "container_name": "llamacpp", + "image": { + "reference": "ghcr.io/ggml-org/llama.cpp:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/ggml-org/llama.cpp", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "LLAMA_ARG_N_GPU_LAYERS", + "example": "999", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LLAMA_ARG_CONTEXT_SIZE", + "example": "8192", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/models", + "compose_source_example": "/DATA/AppData/$AppID/models", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 18080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: llamacpp\nservices:\n llamacpp:\n image: ghcr.io/ggml-org/llama.cpp:latest\n container_name: llamacpp\n ports:\n - target: 8080\n published: '18080'\n protocol: tcp\n environment:\n - LLAMA_ARG_N_GPU_LAYERS=999\n - LLAMA_ARG_CONTEXT_SIZE=8192\n devices:\n - /dev/dri:/dev/dri\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/models\n target: /models\n bind:\n create_host_path: true\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "llamacpp", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "llamacpp", + "service_count": 1, + "services": [ + { + "name": "llamacpp", + "image": "ghcr.io/ggml-org/llama.cpp:server", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/ggml-org/llama.cpp:server", + "container_name": "llamacpp", + "ports": [ + { + "target": 8080, + "published": "18080", + "protocol": "tcp" + } + ], + "environment": [ + "LLAMA_ARG_N_GPU_LAYERS=999", + "LLAMA_ARG_CONTEXT_SIZE=8192" + ], + "devices": [ + "/dev/dri:/dev/dri" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/models", + "target": "/models", + "bind": { + "create_host_path": true + } + } + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "llamacpp" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "llamacpp-volume-0", + "service": "llamacpp", + "container_path": "/models", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "llamacpp" + ], + "stop_order": [ + "llamacpp" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": {}, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "base", + "gpu_passthrough": "not-configured" + }, + "catalog": { + "replaces_discovered_ids": [ + "llamacpp" + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/lm-studio.json b/oci/catalog/apps/lm-studio.json new file mode 100644 index 00000000..c57550d3 --- /dev/null +++ b/oci/catalog/apps/lm-studio.json @@ -0,0 +1,256 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-lm-studio", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Lm Studio" + }, + "tagline": { + "en_US": "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer." + }, + "description": { + "en_US": "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lm-studio-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lm-studio-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://lmstudio.ai/", + "documentation": "https://docs.linuxserver.io/images/docker-lm-studio/", + "repository": "https://github.com/linuxserver/docker-lm-studio", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-22", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-06-22" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-lm-studio", + "default_branch": "master", + "revision": "09b2b48f61a55429dfef4e99ac7a12815aed7885", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-lm-studio/09b2b48f61a55429dfef4e99ac7a12815aed7885/README.md", + "readme_pushed_at": "2026-09-11T23:41:28Z", + "compose_sha256": "5fa5ae8cbf9bc9f441f32ea974dfea1208e09ad780a1756d1dd36d6a4fa82e01", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "lm-studio", + "container_name": "lm-studio", + "image": { + "reference": "lscr.io/linuxserver/lm-studio:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/lm-studio", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n lm-studio:\n image: lscr.io/linuxserver/lm-studio:latest\n container_name: lm-studio\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\" #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/logseq.json b/oci/catalog/apps/logseq.json new file mode 100644 index 00000000..61213890 --- /dev/null +++ b/oci/catalog/apps/logseq.json @@ -0,0 +1,502 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-logseq", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Logseq" + }, + "tagline": { + "en_US": "A privacy-first, open-source platform for knowledge management and collaboration." + }, + "description": { + "en_US": "A privacy-first, open-source platform for knowledge management and collaboration." + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "Logseq Team", + "developer": "Logseq Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://logseq.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/correctroad/logseq", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "correctroad", + "repository": "https://hub.docker.com/r/correctroad/logseq", + "revision": "07b09fd3b4c56e3af2531be58cc75492ffb1bfcd4567edf3c06a760a9f5a9071", + "image_repository_url": "https://hub.docker.com/r/correctroad/logseq", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "07b09fd3b4c56e3af2531be58cc75492ffb1bfcd4567edf3c06a760a9f5a9071", + "generated_at": "2026-09-13T17:20:21+00:00" + }, + "container_contract": { + "service_name": "logseq", + "container_name": "logseq", + "image": { + "reference": "correctroad/logseq:latest", + "registry": "docker.io", + "repository": "correctroad/logseq", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/logseq/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/notes", + "compose_source_example": "/DATA/Documents/Notes", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3325, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 12315, + "published_example": 12315, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: logseq\nservices:\n logseq:\n environment:\n PGID: '0'\n PUID: '0'\n image: correctroad/logseq:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 3000\n published: '3325'\n protocol: tcp\n - target: 12315\n published: '12315'\n protocol: tcp\n privileged: true\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/logseq/config\n target: /config\n - type: bind\n source: /DATA/Documents/Notes\n target: /notes\n container_name: logseq\n" + }, + "compose_stack": { + "project_name": "logseq", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "logseq", + "service_count": 1, + "services": [ + { + "name": "logseq", + "image": "correctroad/logseq:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "0", + "PUID": "0" + }, + "image": "correctroad/logseq:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 3000, + "published": "3325", + "protocol": "tcp" + }, + { + "target": 12315, + "published": "12315", + "protocol": "tcp" + } + ], + "privileged": true, + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/logseq/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/Documents/Notes", + "target": "/notes" + } + ], + "container_name": "logseq" + } + } + ], + "top_level": { + "name": "logseq" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "logseq-volume-0", + "service": "logseq", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "logseq-volume-1", + "service": "logseq", + "container_path": "/notes", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "logseq" + ], + "stop_order": [ + "logseq" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "bridge" + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": false, + "warning": "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "optional-explicit-user-consent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/lollypop.json b/oci/catalog/apps/lollypop.json new file mode 100644 index 00000000..42749b91 --- /dev/null +++ b/oci/catalog/apps/lollypop.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-lollypop", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Lollypop" + }, + "tagline": { + "en_US": "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment." + }, + "description": { + "en_US": "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lollypop-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lollypop-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://wiki.gnome.org/Apps/Lollypop", + "documentation": "https://docs.linuxserver.io/images/docker-lollypop/", + "repository": "https://github.com/linuxserver/docker-lollypop", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false, rebase to Alpine 3.24." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-23", + "note": "Rebase to Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-lollypop", + "default_branch": "master", + "revision": "554d25e15aa89fad6e4c088f6bcd31d2db151022", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-lollypop/554d25e15aa89fad6e4c088f6bcd31d2db151022/README.md", + "readme_pushed_at": "2026-09-11T18:11:52Z", + "compose_sha256": "81bc637f4bff0703470dd2f33da0dbd2818af70581bf1bce95c1ccdd3d21b7be", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "lollypop", + "container_name": "lollypop", + "image": { + "reference": "lscr.io/linuxserver/lollypop:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/lollypop", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n lollypop:\n image: lscr.io/linuxserver/lollypop:latest\n container_name: lollypop\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-lollypop/master/Dockerfile", + "dockerfile_sha256": "e5e217c30e00bbaeec0bd5f39108ad500fe39cb351513d65c7826604494e6b7f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/luanti.json b/oci/catalog/apps/luanti.json new file mode 100644 index 00000000..11617339 --- /dev/null +++ b/oci/catalog/apps/luanti.json @@ -0,0 +1,232 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-luanti", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Luanti" + }, + "tagline": { + "en_US": "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation" + }, + "description": { + "en_US": "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/luanti-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/luanti-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://www.luanti.org/", + "documentation": "https://docs.linuxserver.io/images/docker-luanti/", + "repository": "https://github.com/linuxserver/docker-luanti", + "tips": [], + "mini_changelog": [ + { + "date": "2025-11-03", + "note": "Use latest LuaJIT from git to fix math bugs" + }, + { + "date": "2025-07-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-30", + "note": "Initial Release." + } + ], + "display_version": null, + "updated_at": "2025-11-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-luanti", + "default_branch": "main", + "revision": "2ae617b25b7a7e03d263d5db60a25cf561d2ebdc", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-luanti/2ae617b25b7a7e03d263d5db60a25cf561d2ebdc/README.md", + "readme_pushed_at": "2026-09-06T23:42:51Z", + "compose_sha256": "565f0ab73806b4931f0f9cb7c7ea4424ac0d35557ae17f495893f423e32badbf", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "luanti", + "container_name": "luanti", + "image": { + "reference": "lscr.io/linuxserver/luanti:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/luanti", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CLI_ARGS", + "example": "--gameid devtest", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config/.minetest", + "compose_source_example": "/path/to/luanti/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 30000, + "published_example": 30000, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n luanti:\n image: lscr.io/linuxserver/luanti:latest\n container_name: luanti\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - \"CLI_ARGS=--gameid devtest\" #optional\n volumes:\n - /path/to/luanti/data:/config/.minetest\n ports:\n - 30000:30000/udp\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/lucky.json b/oci/catalog/apps/lucky.json new file mode 100644 index 00000000..f82b63b2 --- /dev/null +++ b/oci/catalog/apps/lucky.json @@ -0,0 +1,397 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-lucky", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Lucky" + }, + "tagline": { + "en_US": "Powerful networking tool" + }, + "description": { + "en_US": "A powerful tool for port forwarding, reverse proxy, dynamic DNS, wake-on-LAN, IPv4 NAT traversal, webdav services, task scheduling, and automatic certificate management." + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "gdy666", + "developer": "gdy666", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 16601, + "path": "/" + }, + "website": "https://lucky666.cn/", + "documentation": null, + "repository": "https://hub.docker.com/r/gdy666/lucky", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "gdy666", + "repository": "https://hub.docker.com/r/gdy666/lucky", + "revision": "81fc49f7ca87b7ac2dcb70ad3c055ff30895dc6688dbe95b352ba7a21298a32f", + "image_repository_url": "https://hub.docker.com/r/gdy666/lucky", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "81fc49f7ca87b7ac2dcb70ad3c055ff30895dc6688dbe95b352ba7a21298a32f", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "lucky", + "container_name": "lucky", + "image": { + "reference": "gdy666/lucky:latest", + "registry": "docker.io", + "repository": "gdy666/lucky", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/goodluck", + "compose_source_example": "/DATA/AppData/lucky", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: lucky\nservices:\n lucky:\n deploy:\n resources:\n reservations:\n memory: 64M\n image: gdy666/lucky:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/lucky\n target: /goodluck\n environment:\n TZ: $TZ\n network_mode: host\n privileged: false\n" + }, + "compose_stack": { + "project_name": "lucky", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "lucky", + "service_count": 1, + "services": [ + { + "name": "lucky", + "image": "gdy666/lucky:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "image": "gdy666/lucky:latest", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/lucky", + "target": "/goodluck" + } + ], + "environment": { + "TZ": "$TZ" + }, + "network_mode": "host", + "privileged": false + } + } + ], + "top_level": { + "name": "lucky" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "lucky-volume-0", + "service": "lucky", + "container_path": "/goodluck", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "lucky" + ], + "stop_order": [ + "lucky" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 16601, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/lychee.json b/oci/catalog/apps/lychee.json new file mode 100644 index 00000000..de77c29f --- /dev/null +++ b/oci/catalog/apps/lychee.json @@ -0,0 +1,320 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-lychee", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Lychee" + }, + "tagline": { + "en_US": "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely." + }, + "description": { + "en_US": "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lychee-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lychee-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://lycheeorg.github.io/", + "documentation": "https://docs.linuxserver.io/images/docker-lychee/", + "repository": "https://github.com/linuxserver/docker-lychee", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-07-09", + "note": "Add php84-ldap as dependency." + }, + { + "date": "2025-07-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-03", + "note": "Verify build artifacts with cosign." + }, + { + "date": "2024-05-27", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-lychee", + "default_branch": "master", + "revision": "f62b41004fd4a9c5021b67a4418285f3c873e5fb", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-lychee/f62b41004fd4a9c5021b67a4418285f3c873e5fb/README.md", + "readme_pushed_at": "2026-09-10T07:23:35Z", + "compose_sha256": "62b06c89d031b93e36acad44112547de7b3809b728b68c0e810dcef6630ac033", + "generated_at": "2026-09-12T14:37:30+00:00" + }, + "container_contract": { + "service_name": "lychee", + "container_name": "lychee", + "image": { + "reference": "lscr.io/linuxserver/lychee:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/lychee", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_CONNECTION", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USERNAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_DATABASE", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_NAME", + "example": "Lychee", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_URL", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TRUSTED_PROXIES", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/lychee/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/pictures", + "compose_source_example": "/path/to/pictures", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n lychee:\n image: lscr.io/linuxserver/lychee:latest\n container_name: lychee\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DB_CONNECTION=\n - DB_HOST=\n - DB_PORT=\n - DB_USERNAME=\n - DB_PASSWORD=\n - DB_DATABASE=\n - APP_NAME=Lychee #optional\n - APP_URL= #optional\n - TRUSTED_PROXIES= #optional\n volumes:\n - /path/to/lychee/config:/config\n - /path/to/pictures:/pictures\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/lyrionmusicserver.json b/oci/catalog/apps/lyrionmusicserver.json new file mode 100644 index 00000000..5e2f7aa6 --- /dev/null +++ b/oci/catalog/apps/lyrionmusicserver.json @@ -0,0 +1,579 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-lyrionmusicserver", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "LyrionMusicServer" + }, + "tagline": { + "en_US": "Lyrion Music Server is a streaming audio server for Squeezebox audio players." + }, + "description": { + "en_US": "Lyrion Music Server is a self-hosted music management app designed to control a variety of audio playback devices, supporting streaming of local music collections, internet radio, and multiple streaming services (with or without subscriptions). Its intuitive Web interface enables users to access and control music effortlessly via any browser, ideal for music enthusiasts creating personalized audio experiences.\n\nThe app's core features include versatile music streaming and extensive customization. Users can seamlessly play local music libraries, listen to global internet radio, or connect to streaming services, catering to diverse listening needs. It offers flexible control options, allowing customization of server functionality, interaction methods, and interface appearance. Additionally, it supports a unified interface across multiple devices, ensuring a consistent experience on phones, computers, or other players, with the ability to select the ideal playback device for any scenario.\n\nIt can be flexibly deployed on personal servers or NAS devices, with community-provided documentation aiding users in optimising setups and extending functionality. Whether managing personal music collections or creating a shared audio hub for family, the app's intuitive operation and high flexibility deliver a modern music management platform, meeting needs from casual listening to professional audio management.\n\n**Key Features:**\n- Music streaming for local collections, internet radio, and multiple streaming services\n- Intuitive Web interface for effortless music access and control via any browser\n- Extensive customisation options for server functionality, interaction methods, and interface appearance\n- Unified multi-device interface ensuring consistent experience across phones, computers, and other players\n- Community documentation support for optimising setups and extending functionality\n\n**Learn More:**\n- [Lyrion Music Server Official Website](https://www.lyrion.org)\n- [Lyrion Music Server GitHub Repository](https://github.com/lms-community/slimserver)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LMS-Community", + "developer": "LMS-Community", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9000, + "path": "/" + }, + "website": "https://www.lyrion.org", + "documentation": null, + "repository": "https://hub.docker.com/r/lmscommunity/lyrionmusicserver", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "lmscommunity", + "repository": "https://hub.docker.com/r/lmscommunity/lyrionmusicserver", + "revision": "cb5cf4f87fe07102a9b21648a593964b6780e68646c07ce894d552ae3996f110", + "image_repository_url": "https://hub.docker.com/r/lmscommunity/lyrionmusicserver", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "cb5cf4f87fe07102a9b21648a593964b6780e68646c07ce894d552ae3996f110", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "lyrionmusicserver", + "container_name": "lyrionmusicserver", + "image": { + "reference": "lmscommunity/lyrionmusicserver:latest", + "registry": "docker.io", + "repository": "lmscommunity/lyrionmusicserver", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "HTTP_PORT", + "example": "9000", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/music", + "compose_source_example": "/DATA/Media/Music", + "read_only": true, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/playlist", + "compose_source_example": "/DATA/AppData/$AppID/playlists", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/etc/localtime", + "compose_source_example": "/etc/localtime", + "read_only": true, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-4", + "container_path": "/etc/timezone", + "compose_source_example": "/etc/timezone", + "read_only": true, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 9000, + "published_example": 9000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9090, + "published_example": 9090, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3483, + "published_example": 3483, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3483, + "published_example": 3483, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: lyrionmusicserver\nservices:\n lyrionmusicserver:\n image: lmscommunity/lyrionmusicserver:latest\n container_name: lyrionmusicserver\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n restart: unless-stopped\n ports:\n - target: 9000\n published: '9000'\n protocol: tcp\n - target: 9090\n published: '9090'\n protocol: tcp\n - target: 3483\n published: '3483'\n protocol: tcp\n - target: 3483\n published: '3483'\n protocol: udp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/Media/Music\n target: /music\n read_only: true\n - type: bind\n source: /DATA/AppData/$AppID/playlists\n target: /playlist\n - type: bind\n source: /etc/localtime\n target: /etc/localtime\n read_only: true\n - type: bind\n source: /etc/timezone\n target: /etc/timezone\n read_only: true\n environment:\n HTTP_PORT: '9000'\n" + }, + "compose_stack": { + "project_name": "lyrionmusicserver", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "lyrionmusicserver", + "service_count": 1, + "services": [ + { + "name": "lyrionmusicserver", + "image": "lmscommunity/lyrionmusicserver:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "lmscommunity/lyrionmusicserver:latest", + "container_name": "lyrionmusicserver", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "restart": "unless-stopped", + "ports": [ + { + "target": 9000, + "published": "9000", + "protocol": "tcp" + }, + { + "target": 9090, + "published": "9090", + "protocol": "tcp" + }, + { + "target": 3483, + "published": "3483", + "protocol": "tcp" + }, + { + "target": 3483, + "published": "3483", + "protocol": "udp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/Media/Music", + "target": "/music", + "read_only": true + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/playlists", + "target": "/playlist" + }, + { + "type": "bind", + "source": "/etc/localtime", + "target": "/etc/localtime", + "read_only": true + }, + { + "type": "bind", + "source": "/etc/timezone", + "target": "/etc/timezone", + "read_only": true + } + ], + "environment": { + "HTTP_PORT": "9000" + } + } + } + ], + "top_level": { + "name": "lyrionmusicserver" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "lyrionmusicserver-volume-0", + "service": "lyrionmusicserver", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "lyrionmusicserver-volume-1", + "service": "lyrionmusicserver", + "container_path": "/music", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for lyrionmusicserver:/music" + }, + { + "id": "lyrionmusicserver-volume-2", + "service": "lyrionmusicserver", + "container_path": "/playlist", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "lyrionmusicserver-volume-3", + "service": "lyrionmusicserver", + "container_path": "/etc/localtime", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/localtime", + "source_path_prompt": null + }, + { + "id": "lyrionmusicserver-volume-4", + "service": "lyrionmusicserver", + "container_path": "/etc/timezone", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/timezone", + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "lyrionmusicserver" + ], + "stop_order": [ + "lyrionmusicserver" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/makemkv.json b/oci/catalog/apps/makemkv.json new file mode 100644 index 00000000..a6a66626 --- /dev/null +++ b/oci/catalog/apps/makemkv.json @@ -0,0 +1,455 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-makemkv", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "MakeMKV" + }, + "tagline": { + "en_US": "Rip DVD and Blu-ray media from a browser" + }, + "description": { + "en_US": "The maintained jlesage MakeMKV image with persistent settings, shared input/output storage and optional native optical-drive passthrough." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "jlesage", + "developer": "jlesage", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5800, + "path": "/" + }, + "website": "https://github.com/jlesage/docker-makemkv", + "documentation": "https://github.com/jlesage/docker-makemkv", + "repository": "https://github.com/jlesage/docker-makemkv", + "tips": [ + "To read an optical drive, select the /dev/sgX that matches the drive; /dev/srX is optional but improves performance.", + "The /storage library is mounted read-only and /output read/write." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-26" + }, + "source": { + "provider": "jlesage", + "repository": "https://github.com/jlesage/docker-makemkv", + "default_branch": "master", + "revision": "63373b8a76faeae246d73c5b070e8d97a2d018c5", + "readme_raw_url": "https://raw.githubusercontent.com/jlesage/docker-makemkv/master/README.md", + "image_repository_url": "https://hub.docker.com/r/jlesage/makemkv", + "readme_pushed_at": "2026-08-26T22:06:48Z", + "compose_sha256": "18936fa4593769be1a8bc9a81c05b35e4f905746b10e772749936c637d9a3f36", + "generated_at": "2026-09-14T15:24:39+00:00" + }, + "container_contract": { + "service_name": "makemkv", + "container_name": "makemkv", + "image": { + "reference": "jlesage/makemkv:latest", + "registry": "docker.io", + "repository": "jlesage/makemkv", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USER_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "GROUP_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "SUP_GROUP_IDS", + "example": null, + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "makemkv-config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "storage", + "container_path": "/storage", + "compose_source_example": "/mnt/oci-shared/media", + "read_only": true, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + }, + { + "id": "output", + "container_path": "/output", + "compose_source_example": "/mnt/oci-shared/makemkv/output", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 5800, + "published_example": 5800, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "{\n \"services\": {\n \"makemkv\": {\n \"image\": \"jlesage/makemkv:latest\",\n \"ports\": [\n \"5800:5800\"\n ],\n \"environment\": {\n \"USER_ID\": \"1000\",\n \"GROUP_ID\": \"1000\",\n \"TZ\": \"Europe/Madrid\"\n },\n \"volumes\": [\n \"makemkv-config:/config\",\n \"/mnt/oci-shared/media:/storage:ro\",\n \"/mnt/oci-shared/makemkv/output:/output\"\n ],\n \"restart\": \"unless-stopped\"\n }\n }\n}" + }, + "compose_stack": { + "project_name": "makemkv", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "makemkv", + "service_count": 1, + "services": [ + { + "name": "makemkv", + "image": "jlesage/makemkv:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/makemkv:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "makemkv-config:/config", + "/mnt/oci-shared/media:/storage:ro", + "/mnt/oci-shared/makemkv/output:/output" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "makemkv-config", + "service": "makemkv", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "makemkv-storage", + "service": "makemkv", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "makemkv-output", + "service": "makemkv", + "container_path": "/output", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "makemkv" + ], + "stop_order": [ + "makemkv" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "makemkv" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "pending-clean-install" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "pending-device-host-test" + } + ], + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "device_requests": [ + { + "id": "optical-scsi-generic", + "kind": "character-device", + "purpose": "optical-drive-control", + "enable_prompt": "Enable an optical drive for MakeMKV", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Generic SCSI device associated with the drive (e.g. /dev/sg2)", + "host_path_default": "/dev/sg0", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "append_host_device_gid_to_environment": "SUP_GROUP_IDS", + "source_mapping": "/dev/sgX:/dev/sgX" + }, + { + "id": "optical-block-device", + "kind": "block-device", + "purpose": "optical-drive-performance", + "enable_prompt": "Also add the /dev/srX optical device (recommended)", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Optical block device (e.g. /dev/sr0)", + "host_path_default": "/dev/sr0", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "append_host_device_gid_to_environment": "SUP_GROUP_IDS", + "source_mapping": "/dev/srX:/dev/srX" + } + ], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/storage", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/output", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 5800, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The official single-image contract has a reviewed native OCI-LXC mapping; clean-install validation remains pending." + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5800, + "path": "/", + "source": "upstream-documentation" + } + ], + "credentials": [] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mame.json b/oci/catalog/apps/mame.json new file mode 100644 index 00000000..41a5f7ea --- /dev/null +++ b/oci/catalog/apps/mame.json @@ -0,0 +1,285 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-mame", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Mame" + }, + "tagline": { + "en_US": "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers." + }, + "description": { + "en_US": "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mame-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mame-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.mamedev.org/", + "documentation": "https://docs.linuxserver.io/images/docker-mame/", + "repository": "https://github.com/linuxserver/docker-mame", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-04", + "note": "Rebase to resolute." + }, + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-03", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-05-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-mame", + "default_branch": "master", + "revision": "44fbe159dd43c5ebf352431f4500e5a952164116", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-mame/44fbe159dd43c5ebf352431f4500e5a952164116/README.md", + "readme_pushed_at": "2026-09-08T18:33:08Z", + "compose_sha256": "f658cb321cfad5b7c2f7c52f2915108f70e3c13f263e55566cd19649695f0202", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "mame", + "container_name": "mame", + "image": { + "reference": "lscr.io/linuxserver/mame:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/mame", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/mame", + "compose_source_example": "/path/to/mame/assets", + "read_only": true, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n mame:\n image: lscr.io/linuxserver/mame:latest\n container_name: mame\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n - /path/to/mame/assets:/mame:ro\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/manyfold.json b/oci/catalog/apps/manyfold.json new file mode 100644 index 00000000..6be1d416 --- /dev/null +++ b/oci/catalog/apps/manyfold.json @@ -0,0 +1,279 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-manyfold", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Manyfold" + }, + "tagline": { + "en_US": "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing." + }, + "description": { + "en_US": "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing." + }, + "category": "gaming", + "category_label": "Gaming & Leisure", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/manyfold-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/manyfold-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3214, + "path": "/" + }, + "website": "https://github.com/manyfold3d/manyfold/", + "documentation": "https://docs.linuxserver.io/images/docker-manyfold/", + "repository": "https://github.com/linuxserver/docker-manyfold", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-13", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-10-08", + "note": "Change key init to auto generate and persist." + }, + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-12", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-manyfold", + "default_branch": "main", + "revision": "038d81c8e2a0e68ada7ae1c433e264193ef85a97", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-manyfold/038d81c8e2a0e68ada7ae1c433e264193ef85a97/README.md", + "readme_pushed_at": "2026-09-07T19:04:38Z", + "compose_sha256": "bcfef7285dba7f890a43c8bea68d4211e4e1e84fbd5bebb627cbfbf3862b1a2c", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "manyfold", + "container_name": "manyfold", + "image": { + "reference": "lscr.io/linuxserver/manyfold:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/manyfold", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DATABASE_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SECRET_KEY_BASE", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/manyfold/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/libraries", + "compose_source_example": "/path/to/libraries", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3214, + "published_example": 3214, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n manyfold:\n image: lscr.io/linuxserver/manyfold:latest\n container_name: manyfold\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DATABASE_URL=\n - REDIS_URL=\n - SECRET_KEY_BASE=\n volumes:\n - /path/to/manyfold/config:/config\n - /path/to/libraries:/libraries #optional\n ports:\n - 3214:3214\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3214, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mariadb.json b/oci/catalog/apps/mariadb.json new file mode 100644 index 00000000..3d05b490 --- /dev/null +++ b/oci/catalog/apps/mariadb.json @@ -0,0 +1,283 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-mariadb", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Mariadb" + }, + "tagline": { + "en_US": "Mariadb is one of the most popular database servers. Made by the original developers of MySQL." + }, + "description": { + "en_US": "Mariadb is one of the most popular database servers. Made by the original developers of MySQL." + }, + "category": "databases", + "category_label": "Databases", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mariadb-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mariadb-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3306, + "path": "/" + }, + "website": "https://mariadb.org/", + "documentation": "https://docs.linuxserver.io/images/docker-mariadb/", + "repository": "https://github.com/linuxserver/docker-mariadb", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-02-14", + "note": "Rebase to Alpine 3.23. Add ability to pass CLI options to mariadbd." + }, + { + "date": "2025-07-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-11", + "note": "Add log rotation, follow the instructions in the container log." + }, + { + "date": "2025-01-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-mariadb", + "default_branch": "master", + "revision": "1953f1c35734a73c993000f5a7c4f77d7c7cf12c", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-mariadb/1953f1c35734a73c993000f5a7c4f77d7c7cf12c/README.md", + "readme_pushed_at": "2026-09-08T12:40:37Z", + "compose_sha256": "d0532f8e6e8bf29ebbd6551c75ca9fb85db9526ee9eb70911e6703515f5027a9", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "mariadb", + "container_name": "mariadb", + "image": { + "reference": "lscr.io/linuxserver/mariadb:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/mariadb", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MYSQL_ROOT_PASSWORD", + "example": "ROOT_ACCESS_PASSWORD", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "MYSQL_DATABASE", + "example": "USER_DB_NAME", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MYSQL_USER", + "example": "MYSQL_USER", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MYSQL_PASSWORD", + "example": "DATABASE_PASSWORD", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_SQL", + "example": "http://URL1/your.sql,https://URL2/your.sql", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CLI_OPTS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/mariadb/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3306, + "published_example": 3306, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n mariadb:\n image: lscr.io/linuxserver/mariadb:latest\n container_name: mariadb\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - MYSQL_ROOT_PASSWORD=ROOT_ACCESS_PASSWORD\n - MYSQL_DATABASE=USER_DB_NAME #optional\n - MYSQL_USER=MYSQL_USER #optional\n - MYSQL_PASSWORD=DATABASE_PASSWORD #optional\n - REMOTE_SQL=http://URL1/your.sql,https://URL2/your.sql #optional\n - CLI_OPTS= #optional\n volumes:\n - /path/to/mariadb/config:/config\n ports:\n - 3306:3306\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3306, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mastodon.json b/oci/catalog/apps/mastodon.json new file mode 100644 index 00000000..15b0d5fb --- /dev/null +++ b/oci/catalog/apps/mastodon.json @@ -0,0 +1,521 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-mastodon", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Mastodon" + }, + "tagline": { + "en_US": "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones.." + }, + "description": { + "en_US": "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones.." + }, + "category": "communication", + "category_label": "Communication & Community", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mastodon-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mastodon-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/mastodon/mastodon/", + "documentation": "https://docs.linuxserver.io/images/docker-mastodon/", + "repository": "https://github.com/linuxserver/docker-mastodon", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-10-21", + "note": "Add prometheus exporter support." + }, + { + "date": "2025-10-20", + "note": "Add vips-heif." + }, + { + "date": "2025-07-08", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-06-06", + "note": "Rebase to Alpine 3.21, replace deprecated imagemagick with vips." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-mastodon", + "default_branch": "main", + "revision": "04011d5a66e8bc029223439e09b3f4a84e906d01", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-mastodon/04011d5a66e8bc029223439e09b3f4a84e906d01/README.md", + "readme_pushed_at": "2026-09-10T15:01:58Z", + "compose_sha256": "a51333798189b884423a5fd2f56af4ac75468247b783c07defb06bf7bedbb71c", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "mastodon", + "container_name": "mastodon", + "image": { + "reference": "lscr.io/linuxserver/mastodon:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/mastodon", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOCAL_DOMAIN", + "example": "example.com", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_HOST", + "example": "redis", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_PORT", + "example": "6379", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "db", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USER", + "example": "mastodon", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_NAME", + "example": "mastodon", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASS", + "example": "mastodon", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "5432", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ES_ENABLED", + "example": "false", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SECRET_KEY_BASE", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "OTP_SECRET", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "VAPID_PRIVATE_KEY", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "VAPID_PUBLIC_KEY", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SMTP_SERVER", + "example": "mail.example.com", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SMTP_PORT", + "example": "25", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SMTP_LOGIN", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SMTP_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SMTP_FROM_ADDRESS", + "example": "notifications@example.com", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "S3_ENABLED", + "example": "false", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "WEB_DOMAIN", + "example": "mastodon.example.com", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ES_HOST", + "example": "es", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ES_PORT", + "example": "9200", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ES_USER", + "example": "elastic", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ES_PASS", + "example": "elastic", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "S3_BUCKET", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "AWS_ACCESS_KEY_ID", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "AWS_SECRET_ACCESS_KEY", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "S3_ALIAS_HOST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SIDEKIQ_ONLY", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SIDEKIQ_QUEUE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SIDEKIQ_DEFAULT", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SIDEKIQ_THREADS", + "example": "5", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_POOL", + "example": "5", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "NO_CHOWN", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MASTODON_PROMETHEUS_EXPORTER_ENABLED", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/mastodon/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9394, + "published_example": 9394, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n mastodon:\n image: lscr.io/linuxserver/mastodon:latest\n container_name: mastodon\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - LOCAL_DOMAIN=example.com\n - REDIS_HOST=redis\n - REDIS_PORT=6379\n - DB_HOST=db\n - DB_USER=mastodon\n - DB_NAME=mastodon\n - DB_PASS=mastodon\n - DB_PORT=5432\n - ES_ENABLED=false\n - ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY=\n - ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY=\n - ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT=\n - SECRET_KEY_BASE=\n - OTP_SECRET=\n - VAPID_PRIVATE_KEY=\n - VAPID_PUBLIC_KEY=\n - SMTP_SERVER=mail.example.com\n - SMTP_PORT=25\n - SMTP_LOGIN=\n - SMTP_PASSWORD=\n - SMTP_FROM_ADDRESS=notifications@example.com\n - S3_ENABLED=false\n - WEB_DOMAIN=mastodon.example.com #optional\n - ES_HOST=es #optional\n - ES_PORT=9200 #optional\n - ES_USER=elastic #optional\n - ES_PASS=elastic #optional\n - S3_BUCKET= #optional\n - AWS_ACCESS_KEY_ID= #optional\n - AWS_SECRET_ACCESS_KEY= #optional\n - S3_ALIAS_HOST= #optional\n - SIDEKIQ_ONLY=false #optional\n - SIDEKIQ_QUEUE= #optional\n - SIDEKIQ_DEFAULT=false #optional\n - SIDEKIQ_THREADS=5 #optional\n - DB_POOL=5 #optional\n - NO_CHOWN= #optional\n - MASTODON_PROMETHEUS_EXPORTER_ENABLED= #optional\n volumes:\n - /path/to/mastodon/config:/config\n ports:\n - 80:80\n - 443:443\n - 9394:9394 #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/maybe.json b/oci/catalog/apps/maybe.json new file mode 100644 index 00000000..e1e0b7cd --- /dev/null +++ b/oci/catalog/apps/maybe.json @@ -0,0 +1,766 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-maybe", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "Maybe" + }, + "tagline": { + "en_US": "Personal finance management application" + }, + "description": { + "en_US": "Maybe is a personal finance management application designed to help you track your expenses, income, and investments in one place. With an intuitive interface and powerful features, Maybe makes it easy to understand your financial situation and make informed decisions about your money.\n\n**Key Features:**\n- **Expense Tracking**: Easily log and categorize your expenses\n- **Income Management**: Track multiple income sources\n- **Investment Monitoring**: Keep an eye on your investments and their performance\n- **Budget Planning**: Create and maintain budgets to control your spending\n- **Financial Reports**: Generate detailed reports to understand your financial habits\n- **AI-Powered Insights**: Get personalized financial advice using AI technology\n\n**Use Cases:**\n- Personal budget management\n- Expense tracking and categorization\n- Investment portfolio monitoring\n- Financial goal setting and tracking\n- Cash flow analysis\n\n**Learn More:**\n- [Maybe GitHub Repository](https://github.com/maybe-finance/maybe)\n" + }, + "category": "finance", + "category_label": "Finance & Budgeting", + "author": "maybe-finance", + "developer": "maybe-finance", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://ghcr.io/maybe-finance/maybe", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/maybe-finance/maybe", + "revision": "e2a38474cc89874ea285a0f1f67662a4062157b52a4e50ba90b32f45117e18a1", + "image_repository_url": "https://ghcr.io/maybe-finance/maybe", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "e2a38474cc89874ea285a0f1f67662a4062157b52a4e50ba90b32f45117e18a1", + "generated_at": "2026-09-13T15:48:30+00:00" + }, + "container_contract": { + "service_name": "maybe-web", + "container_name": "maybe-web", + "image": { + "reference": "ghcr.io/maybe-finance/maybe:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/maybe-finance/maybe", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "POSTGRES_USER", + "example": "maybe_user", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_PASSWORD", + "example": "${GENERATED_POSTGRES_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "POSTGRES_DB", + "example": "maybe_production", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SECRET_KEY_BASE", + "example": "${GENERATED_SECRET_KEY_BASE}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "SELF_HOSTED", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "RAILS_FORCE_SSL", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "RAILS_ASSUME_SSL", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_HOST", + "example": "maybe-db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_PORT", + "example": "5432", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REDIS_URL", + "example": "redis://maybe-redis:6379/1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "OPENAI_ACCESS_TOKEN", + "example": "${GENERATED_OPENAI_ACCESS_TOKEN}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/rails/storage", + "compose_source_example": "/DATA/AppData/$AppID/app/storage", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 23000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "maybe-worker", + "image": "ghcr.io/maybe-finance/maybe:latest" + }, + { + "name": "maybe-db", + "image": "postgres:latest" + }, + { + "name": "maybe-redis", + "image": "redis:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: maybe\nservices:\n maybe-web:\n container_name: maybe-web\n image: ghcr.io/maybe-finance/maybe:latest\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/app/storage\n target: /rails/storage\n ports:\n - target: 3000\n published: '23000'\n protocol: tcp\n restart: unless-stopped\n environment:\n POSTGRES_USER: maybe_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: maybe_production\n SECRET_KEY_BASE: ${GENERATED_SECRET_KEY_BASE}\n SELF_HOSTED: 'true'\n RAILS_FORCE_SSL: 'false'\n RAILS_ASSUME_SSL: 'false'\n DB_HOST: maybe-db\n DB_PORT: 5432\n REDIS_URL: redis://maybe-redis:6379/1\n OPENAI_ACCESS_TOKEN: ${GENERATED_OPENAI_ACCESS_TOKEN}\n depends_on:\n maybe-db:\n condition: service_healthy\n maybe-redis:\n condition: service_healthy\n networks:\n - maybe_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n maybe-worker:\n container_name: maybe-worker\n image: ghcr.io/maybe-finance/maybe:latest\n command:\n - bundle\n - exec\n - sidekiq\n restart: unless-stopped\n depends_on:\n maybe-redis:\n condition: service_healthy\n environment:\n POSTGRES_USER: maybe_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: maybe_production\n SECRET_KEY_BASE: ${GENERATED_SECRET_KEY_BASE}\n SELF_HOSTED: 'true'\n RAILS_FORCE_SSL: 'false'\n RAILS_ASSUME_SSL: 'false'\n DB_HOST: maybe-db\n DB_PORT: 5432\n REDIS_URL: redis://maybe-redis:6379/1\n OPENAI_ACCESS_TOKEN: ${GENERATED_OPENAI_ACCESS_TOKEN}\n networks:\n - maybe_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n maybe-db:\n container_name: maybe-db\n image: postgres:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/pgdata\n target: /var/lib/postgresql/data\n environment:\n POSTGRES_USER: maybe_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: maybe_production\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U maybe_user -d maybe_production\n interval: 5s\n timeout: 5s\n retries: 5\n networks:\n - maybe_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n maybe-redis:\n container_name: maybe-redis\n image: redis:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/redis/data\n target: /data\n healthcheck:\n test:\n - CMD\n - redis-cli\n - ping\n interval: 5s\n timeout: 5s\n retries: 5\n networks:\n - maybe_net\n deploy:\n resources:\n reservations:\n memory: 1024M\nnetworks:\n maybe_net:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "maybe", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "maybe-web", + "service_count": 4, + "services": [ + { + "name": "maybe-db", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "maybe-db", + "image": "postgres:latest", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/pgdata", + "target": "/var/lib/postgresql/data" + } + ], + "environment": { + "POSTGRES_USER": "maybe_user", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "maybe_production" + }, + "healthcheck": { + "test": [ + "CMD-SHELL", + "pg_isready -U maybe_user -d maybe_production" + ], + "interval": "5s", + "timeout": "5s", + "retries": 5 + }, + "networks": [ + "maybe_net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + }, + { + "name": "maybe-redis", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "maybe-redis", + "image": "redis:latest", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/redis/data", + "target": "/data" + } + ], + "healthcheck": { + "test": [ + "CMD", + "redis-cli", + "ping" + ], + "interval": "5s", + "timeout": "5s", + "retries": 5 + }, + "networks": [ + "maybe_net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + }, + { + "name": "maybe-worker", + "image": "ghcr.io/maybe-finance/maybe:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [ + "maybe-redis" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "maybe-worker", + "image": "ghcr.io/maybe-finance/maybe:latest", + "command": [ + "bundle", + "exec", + "sidekiq" + ], + "restart": "unless-stopped", + "depends_on": { + "maybe-redis": { + "condition": "service_healthy" + } + }, + "environment": { + "POSTGRES_USER": "maybe_user", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "maybe_production", + "SECRET_KEY_BASE": "${GENERATED_SECRET_KEY_BASE}", + "SELF_HOSTED": "true", + "RAILS_FORCE_SSL": "false", + "RAILS_ASSUME_SSL": "false", + "DB_HOST": "maybe-db", + "DB_PORT": 5432, + "REDIS_URL": "redis://maybe-redis:6379/1", + "OPENAI_ACCESS_TOKEN": "${GENERATED_OPENAI_ACCESS_TOKEN}" + }, + "networks": [ + "maybe_net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + }, + { + "name": "maybe-web", + "image": "ghcr.io/maybe-finance/maybe:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "maybe-db", + "maybe-redis" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "maybe-web", + "image": "ghcr.io/maybe-finance/maybe:latest", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/app/storage", + "target": "/rails/storage" + } + ], + "ports": [ + { + "target": 3000, + "published": "23000", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "environment": { + "POSTGRES_USER": "maybe_user", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "maybe_production", + "SECRET_KEY_BASE": "${GENERATED_SECRET_KEY_BASE}", + "SELF_HOSTED": "true", + "RAILS_FORCE_SSL": "false", + "RAILS_ASSUME_SSL": "false", + "DB_HOST": "maybe-db", + "DB_PORT": 5432, + "REDIS_URL": "redis://maybe-redis:6379/1", + "OPENAI_ACCESS_TOKEN": "${GENERATED_OPENAI_ACCESS_TOKEN}" + }, + "depends_on": { + "maybe-db": { + "condition": "service_healthy" + }, + "maybe-redis": { + "condition": "service_healthy" + } + }, + "networks": [ + "maybe_net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + } + ], + "top_level": { + "name": "maybe", + "networks": { + "maybe_net": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "maybe-web-volume-0", + "service": "maybe-web", + "container_path": "/rails/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "maybe-db-volume-0", + "service": "maybe-db", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "maybe-redis-volume-0", + "service": "maybe-redis", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for maybe-redis:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 4, + "start_order": [ + "maybe-db", + "maybe-redis", + "maybe-worker", + "maybe-web" + ], + "stop_order": [ + "maybe-web", + "maybe-worker", + "maybe-redis", + "maybe-db" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "openai-access-token", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "maybe-web", + "environment_variable": "OPENAI_ACCESS_TOKEN" + }, + { + "service": "maybe-worker", + "environment_variable": "OPENAI_ACCESS_TOKEN" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "maybe-web", + "environment_variable": "POSTGRES_PASSWORD" + }, + { + "service": "maybe-worker", + "environment_variable": "POSTGRES_PASSWORD" + }, + { + "service": "maybe-db", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + }, + { + "id": "secret-key-base", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "maybe-web", + "environment_variable": "SECRET_KEY_BASE" + }, + { + "service": "maybe-worker", + "environment_variable": "SECRET_KEY_BASE" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "maybe-worker: perfil de salud y persistencia pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:maybe-worker:compose-key:depends_on", + "service:maybe-db:healthcheck-format", + "service:maybe-redis:healthcheck-format", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mediaelch.json b/oci/catalog/apps/mediaelch.json new file mode 100644 index 00000000..f314218b --- /dev/null +++ b/oci/catalog/apps/mediaelch.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-mediaelch", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Mediaelch" + }, + "tagline": { + "en_US": "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well." + }, + "description": { + "en_US": "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mediaelch-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mediaelch-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/Komet/MediaElch", + "documentation": "https://docs.linuxserver.io/images/docker-mediaelch/", + "repository": "https://github.com/linuxserver/docker-mediaelch", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to Debian Trixie, ingest appimage from github." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-14", + "note": "Rebase to noble, ingest latest stable version, install qt deps." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-mediaelch", + "default_branch": "master", + "revision": "7ba5da55e8c859d6826a04938fae346cd052c14e", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-mediaelch/7ba5da55e8c859d6826a04938fae346cd052c14e/README.md", + "readme_pushed_at": "2026-09-05T16:19:19Z", + "compose_sha256": "e1297511a1d3929f55f196692260c756387dda61d2e72bc61daad6a5da485980", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "mediaelch", + "container_name": "mediaelch", + "image": { + "reference": "lscr.io/linuxserver/mediaelch:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/mediaelch", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/mediaelch/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n mediaelch:\n image: lscr.io/linuxserver/mediaelch:latest\n container_name: mediaelch\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/mediaelch/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-mediaelch/master/Dockerfile", + "dockerfile_sha256": "4291ab245dee3d06037908bc3e51b079c352756901809177244185e41e80dfe0", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/medusa-official.json b/oci/catalog/apps/medusa-official.json new file mode 100644 index 00000000..0f99e6b8 --- /dev/null +++ b/oci/catalog/apps/medusa-official.json @@ -0,0 +1,477 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-medusa-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Medusa" + }, + "tagline": { + "en_US": "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic." + }, + "description": { + "en_US": "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "pyMedusa (https://github.com/pymedusa)", + "developer": "pyMedusa (https://github.com/pymedusa)", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8081, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/pymedusa/medusa", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/pymedusa/medusa", + "revision": "ba2c24a573ade552084a23cbdecfdb03339e7476d521a605f1dbb3f7614753b7", + "image_repository_url": "https://hub.docker.com/r/pymedusa/medusa", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "ba2c24a573ade552084a23cbdecfdb03339e7476d521a605f1dbb3f7614753b7", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "medusa", + "container_name": "medusa", + "image": { + "reference": "pymedusa/medusa:latest", + "registry": "docker.io", + "repository": "pymedusa/medusa", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": " $TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/DATA/AppData/$AppID/Downloads/Television", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/tv", + "compose_source_example": "/DATA/AppData/$AppID/Media/Television", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8081, + "published_example": 8081, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: medusa\nservices:\n medusa:\n container_name: medusa\n deploy:\n resources:\n limits:\n memory: 7848M\n environment:\n - TZ= $TZ\n image: pymedusa/medusa:latest\n ports:\n - target: 8081\n published: '8081'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /config\n - type: bind\n source: /DATA/AppData/$AppID/Downloads/Television\n target: /downloads\n - type: bind\n source: /DATA/AppData/$AppID/Media/Television\n target: /tv\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "medusa", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "medusa", + "service_count": 1, + "services": [ + { + "name": "medusa", + "image": "pymedusa/medusa:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "medusa", + "deploy": { + "resources": { + "limits": { + "memory": "7848M" + } + } + }, + "environment": [ + "TZ= $TZ" + ], + "image": "pymedusa/medusa:latest", + "ports": [ + { + "target": 8081, + "published": "8081", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/Downloads/Television", + "target": "/downloads" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/Media/Television", + "target": "/tv" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "medusa" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "medusa-volume-0", + "service": "medusa", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "medusa-volume-1", + "service": "medusa", + "container_path": "/downloads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for medusa:/downloads" + }, + { + "id": "medusa-volume-2", + "service": "medusa", + "container_path": "/tv", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for medusa:/tv" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "medusa" + ], + "stop_order": [ + "medusa" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8081, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/medusa.json b/oci/catalog/apps/medusa.json new file mode 100644 index 00000000..d13d38e4 --- /dev/null +++ b/oci/catalog/apps/medusa.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-medusa", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Medusa" + }, + "tagline": { + "en_US": "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic." + }, + "description": { + "en_US": "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/medusa-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/medusa-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8081, + "path": "/" + }, + "website": "https://pymedusa.com/", + "documentation": "https://docs.linuxserver.io/images/docker-medusa/", + "repository": "https://github.com/linuxserver/docker-medusa", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-16", + "note": "Rebase to Alpine 3.23. Add python gdbm backend." + }, + { + "date": "2025-11-10", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-04-07", + "note": "Revert to Alpine 3.19 due to upstream issues with Python 3.12 support." + }, + { + "date": "2025-03-02", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-01-08", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2026-08-16" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-medusa", + "default_branch": "master", + "revision": "e5a22333a4ce12dc4c4bf0ab4f6a972bee21749b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-medusa/e5a22333a4ce12dc4c4bf0ab4f6a972bee21749b/README.md", + "readme_pushed_at": "2026-09-10T17:58:29Z", + "compose_sha256": "b3d1e2bcaa8e8504ffba536018315de9bc61862b6766d9f9a3b2fb02fdfe2d73", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "medusa", + "container_name": "medusa", + "image": { + "reference": "lscr.io/linuxserver/medusa:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/medusa", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/medusa/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/tv", + "compose_source_example": "/path/to/tv/shows", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8081, + "published_example": 8081, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n medusa:\n image: lscr.io/linuxserver/medusa:latest\n container_name: medusa\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/medusa/config:/config\n - /path/to/downloads:/downloads\n - /path/to/tv/shows:/tv\n ports:\n - 8081:8081\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8081, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/melonds.json b/oci/catalog/apps/melonds.json new file mode 100644 index 00000000..592eaaaa --- /dev/null +++ b/oci/catalog/apps/melonds.json @@ -0,0 +1,265 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-melonds", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Melonds" + }, + "tagline": { + "en_US": "melonDS aims at providing fast and accurate Nintendo DS emulation." + }, + "description": { + "en_US": "melonDS aims at providing fast and accurate Nintendo DS emulation." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/melonds-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/melonds-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://melonds.kuribo64.net/", + "documentation": "https://docs.linuxserver.io/images/docker-melonds/", + "repository": "https://github.com/linuxserver/docker-melonds", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-29", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-melonds", + "default_branch": "master", + "revision": "60d2316d7508818b035af3da2bf4712f2d767ca5", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-melonds/60d2316d7508818b035af3da2bf4712f2d767ca5/README.md", + "readme_pushed_at": "2026-09-07T21:14:11Z", + "compose_sha256": "f8fe36fb6e03def15ebd5a3d23f94a9a1ec8a9ca6ec4f7012515697b09211498", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "melonds", + "container_name": "melonds", + "image": { + "reference": "lscr.io/linuxserver/melonds:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/melonds", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n melonds:\n image: lscr.io/linuxserver/melonds:latest\n container_name: melonds\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/memos.json b/oci/catalog/apps/memos.json new file mode 100644 index 00000000..85ac11e7 --- /dev/null +++ b/oci/catalog/apps/memos.json @@ -0,0 +1,428 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-memos", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Memos" + }, + "tagline": { + "en_US": "Memos is a lightweight, self-hosted memo hub. Open Source and Free forever." + }, + "description": { + "en_US": "Memos is a lightweight, open-source, self-hosted note-taking application that offers a secure and streamlined solution for users prioritizing privacy and data control. All notes are stored on the user\u2019s own server, eliminating risks associated with third-party cloud services. Its minimalist Web interface supports Markdown syntax and tag-based organization, enabling effortless capture of ideas, personal knowledge management, or small-scale team collaboration. The open-source design ensures transparency, long-term maintainability, and no subscription costs, making it ideal for users seeking data ownership and cost efficiency.\n\nDesigned for simplicity and efficiency, Memos caters to a variety of use cases. Whether jotting down daily thoughts, organizing study notes, or sharing task memos in small teams, Memos delivers a seamless experience through its intuitive tag system and Markdown formatting. Accessible via any web browser, it requires no proprietary clients or complex setup, allowing users to manage notes anytime, anywhere.\n\nWhether used for long-term personal knowledge archiving or as a lightweight tool for team collaboration, Memos offers a secure, flexible, and user-friendly solution, empowering users to maintain full control over their data while enjoying a streamlined note-taking experience.\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "usememos Team", + "developer": "usememos Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5230, + "path": "/" + }, + "website": "https://usememos.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/neosmemo/memos", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "neosmemo", + "repository": "https://hub.docker.com/r/neosmemo/memos", + "revision": "87dc38cd4cffd89c459897dac2c7ab230c0dc5616fd6cdbf673ab8d46604216b", + "image_repository_url": "https://hub.docker.com/r/neosmemo/memos", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "87dc38cd4cffd89c459897dac2c7ab230c0dc5616fd6cdbf673ab8d46604216b", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "memos", + "container_name": "memos", + "image": { + "reference": "neosmemo/memos:latest", + "registry": "docker.io", + "repository": "neosmemo/memos", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/opt/memos", + "compose_source_example": "/DATA/AppData/memos/memos", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5230, + "published_example": 5230, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: memos\nservices:\n memos:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n image: neosmemo/memos:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 5230\n published: '5230'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/memos/memos\n target: /var/opt/memos\n container_name: memos\n" + }, + "compose_stack": { + "project_name": "memos", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "memos", + "service_count": 1, + "services": [ + { + "name": "memos", + "image": "neosmemo/memos:stable", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "image": "neosmemo/memos:stable", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 5230, + "published": "5230", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/memos/memos", + "target": "/var/opt/memos" + } + ], + "container_name": "memos" + } + } + ], + "top_level": { + "name": "memos" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "memos-volume-0", + "service": "memos", + "container_path": "/var/opt/memos", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "memos" + ], + "stop_order": [ + "memos" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5230, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mineos-node.json b/oci/catalog/apps/mineos-node.json new file mode 100644 index 00000000..830e97a7 --- /dev/null +++ b/oci/catalog/apps/mineos-node.json @@ -0,0 +1,468 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-mineos-node", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "MineOS" + }, + "tagline": { + "en_US": "Free and easy to use Minecraft server management tool." + }, + "description": { + "en_US": "MineOS is a server front-end to ease managing Minecraft administrative tasks. This iteration using Node.js aims to enhance previous MineOS scripts (Python-based), by leveraging the event-triggering, asyncronous model of Node.JS and websockets." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "hexparrot", + "developer": "hexparrot", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 8443, + "path": "/admin/index.html" + }, + "website": "https://www.mineos.net/", + "documentation": null, + "repository": "https://hub.docker.com/r/hexparrot/mineos", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "hexparrot", + "repository": "https://hub.docker.com/r/hexparrot/mineos", + "revision": "ececc5d3950be3d6866e92cb732cc6d849432d429b4169c961444cc3cddb8729", + "image_repository_url": "https://hub.docker.com/r/hexparrot/mineos", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "ececc5d3950be3d6866e92cb732cc6d849432d429b4169c961444cc3cddb8729", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "mineos", + "container_name": "mineos_server", + "image": { + "reference": "hexparrot/mineos:latest", + "registry": "docker.io", + "repository": "hexparrot/mineos", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USE_HTTPS", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SERVER_PORT", + "example": "8443", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "USER_NAME", + "example": "mc", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "USER_UID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "USER_PASSWORD", + "example": "${GENERATED_USER_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/games/minecraft", + "compose_source_example": "/var/games/mineos/minecraft", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8443, + "published_example": 8444, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 25565, + "published_example": 25565, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat", + "container_port_end": 25570, + "published_example_end": 25570 + }, + { + "container_port": 25565, + "published_example": 25565, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat", + "container_port_end": 25570, + "published_example_end": 25570 + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": "10m", + "original_compose": "name: mineos-node\nservices:\n mineos:\n image: hexparrot/mineos:latest\n container_name: mineos_server\n networks:\n - mineos\n restart: unless-stopped\n stop_grace_period: 10m\n volumes:\n - /var/games/mineos/minecraft:/var/games/minecraft\n environment:\n USE_HTTPS: 'true'\n SERVER_PORT: 8443\n USER_NAME: mc\n USER_UID: 1000\n USER_PASSWORD: ${GENERATED_USER_PASSWORD}\n ports:\n - 8444:8443/tcp\n - 25565-25570:25565-25570/tcp\n - 25565-25570:25565-25570/udp\nvolumes:\n mineos_data: null\nnetworks:\n mineos: null\n" + }, + "compose_stack": { + "project_name": "mineos-node", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mineos", + "service_count": 1, + "services": [ + { + "name": "mineos", + "image": "hexparrot/mineos:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "hexparrot/mineos:latest", + "container_name": "mineos_server", + "networks": [ + "mineos" + ], + "restart": "unless-stopped", + "stop_grace_period": "10m", + "volumes": [ + "/var/games/mineos/minecraft:/var/games/minecraft" + ], + "environment": { + "USE_HTTPS": "true", + "SERVER_PORT": 8443, + "USER_NAME": "mc", + "USER_UID": 1000, + "USER_PASSWORD": "${GENERATED_USER_PASSWORD}" + }, + "ports": [ + "8444:8443/tcp", + "25565-25570:25565-25570/tcp", + "25565-25570:25565-25570/udp" + ] + } + } + ], + "top_level": { + "name": "mineos-node", + "volumes": { + "mineos_data": null + }, + "networks": { + "mineos": null + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mineos-volume-0", + "service": "mineos", + "container_path": "/var/games/minecraft", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mineos" + ], + "stop_order": [ + "mineos" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "user-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "mineos", + "environment_variable": "USER_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 8443, + "path": "/admin/index.html", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 600 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/minisatip.json b/oci/catalog/apps/minisatip.json new file mode 100644 index 00000000..42cbb978 --- /dev/null +++ b/oci/catalog/apps/minisatip.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-minisatip", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Minisatip" + }, + "tagline": { + "en_US": "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards." + }, + "description": { + "en_US": "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/minisatip-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/minisatip-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8875, + "path": "/" + }, + "website": "https://github.com/catalinii/minisatip", + "documentation": "https://docs.linuxserver.io/images/docker-minisatip/", + "repository": "https://github.com/linuxserver/docker-minisatip", + "tips": [], + "mini_changelog": [ + { + "date": "2026-02-20", + "note": "Build with cmake. Clean up source files." + }, + { + "date": "2025-06-10", + "note": "Remove dvb-apps as upstream repo no longer exists." + }, + { + "date": "2025-05-21", + "note": "Rebase to Ubuntu Noble as the new upstream version requires glibc." + }, + { + "date": "2024-06-30", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-08", + "note": "Rebase to Alpine 3.19, switch to building from releases rather than commits." + } + ], + "display_version": null, + "updated_at": "2026-02-20" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-minisatip", + "default_branch": "master", + "revision": "3d996feb5c9c74332b1662fb0da9728174856939", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-minisatip/3d996feb5c9c74332b1662fb0da9728174856939/README.md", + "readme_pushed_at": "2026-09-08T12:51:54Z", + "compose_sha256": "17503eaf03ef05c9ce3e3682b04deeecafd6bb45cd38fe11b0ef1fff907dfa86", + "generated_at": "2026-09-13T15:35:44+00:00" + }, + "container_contract": { + "service_name": "minisatip", + "container_name": "minisatip", + "image": { + "reference": "lscr.io/linuxserver/minisatip:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/minisatip", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RUN_OPTS", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/minisatip/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8875, + "published_example": 8875, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 554, + "published_example": 554, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 1900, + "published_example": 1900, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n minisatip:\n image: lscr.io/linuxserver/minisatip:latest\n container_name: minisatip\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - RUN_OPTS=\n volumes:\n - /path/to/minisatip/config:/config\n ports:\n - 8875:8875\n - 554:554\n - 1900:1900/udp\n devices:\n - /dev/dvb:/dev/dvb\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8875, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "dev-dvb", + "kind": "character-device-tree", + "purpose": "dvb", + "enable_prompt": "Host DVB tuners", + "enabled_default": true, + "required_by_compose": true, + "path_prompt": "DVB device directory", + "host_path_default": "/dev/dvb", + "container_path": "/dev/dvb", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/dvb:/dev/dvb" + } + ] + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mkvtoolnix.json b/oci/catalog/apps/mkvtoolnix.json new file mode 100644 index 00000000..ad645270 --- /dev/null +++ b/oci/catalog/apps/mkvtoolnix.json @@ -0,0 +1,376 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-mkvtoolnix", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "MKVToolNix" + }, + "tagline": { + "en_US": "Create and edit Matroska files from a browser" + }, + "description": { + "en_US": "The maintained jlesage MKVToolNix image with browser GUI, persistent settings and user-selectable shared storage." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "jlesage", + "developer": "jlesage", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5800, + "path": "/" + }, + "website": "https://github.com/jlesage/docker-mkvtoolnix", + "documentation": "https://github.com/jlesage/docker-mkvtoolnix", + "repository": "https://github.com/jlesage/docker-mkvtoolnix", + "tips": [ + "/storage can point to the common directory used by Jellyfin, Plex, MakeMKV or other media applications." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-26" + }, + "source": { + "provider": "jlesage", + "repository": "https://github.com/jlesage/docker-mkvtoolnix", + "default_branch": "master", + "revision": "8a51f353e1b186dff36465a27c201d8614f80dc3", + "readme_raw_url": "https://raw.githubusercontent.com/jlesage/docker-mkvtoolnix/master/README.md", + "image_repository_url": "https://hub.docker.com/r/jlesage/mkvtoolnix", + "readme_pushed_at": "2026-08-26T22:06:48Z", + "compose_sha256": "4c11b71b299901116f68d039b11a4c86900882c4df45b3082a85215bdb42f757", + "generated_at": "2026-09-14T15:24:39+00:00" + }, + "container_contract": { + "service_name": "mkvtoolnix", + "container_name": "mkvtoolnix", + "image": { + "reference": "jlesage/mkvtoolnix:latest", + "registry": "docker.io", + "repository": "jlesage/mkvtoolnix", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USER_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "GROUP_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "mkvtoolnix-config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "storage", + "container_path": "/storage", + "compose_source_example": "/mnt/oci-shared/media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 5800, + "published_example": 5800, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "{\n \"services\": {\n \"mkvtoolnix\": {\n \"image\": \"jlesage/mkvtoolnix:latest\",\n \"ports\": [\n \"5800:5800\"\n ],\n \"environment\": {\n \"USER_ID\": \"1000\",\n \"GROUP_ID\": \"1000\",\n \"TZ\": \"Europe/Madrid\"\n },\n \"volumes\": [\n \"mkvtoolnix-config:/config\",\n \"/mnt/oci-shared/media:/storage\"\n ],\n \"restart\": \"unless-stopped\"\n }\n }\n}" + }, + "compose_stack": { + "project_name": "mkvtoolnix", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mkvtoolnix", + "service_count": 1, + "services": [ + { + "name": "mkvtoolnix", + "image": "jlesage/mkvtoolnix:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/mkvtoolnix:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "mkvtoolnix-config:/config", + "/mnt/oci-shared/media:/storage" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mkvtoolnix-config", + "service": "mkvtoolnix", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "mkvtoolnix-storage", + "service": "mkvtoolnix", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mkvtoolnix" + ], + "stop_order": [ + "mkvtoolnix" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "mkvtoolnix" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "pending-clean-install" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "not-required" + } + ], + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "device_requests": [], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/storage", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 5800, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The official single-image contract has a reviewed native OCI-LXC mapping; clean-install validation remains pending." + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5800, + "path": "/", + "source": "upstream-documentation" + } + ], + "credentials": [] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mongodb.json b/oci/catalog/apps/mongodb.json new file mode 100644 index 00000000..c4569dfe --- /dev/null +++ b/oci/catalog/apps/mongodb.json @@ -0,0 +1,444 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-mongodb", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "MongoDB" + }, + "tagline": { + "en_US": "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata." + }, + "description": { + "en_US": "MongoDB is a free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata. MongoDB is developed by MongoDB Inc., and is published under a combination of the Server Side Public License and the Apache License." + }, + "category": "databases", + "category_label": "Databases", + "author": "MongoDB Inc.", + "developer": "MongoDB Inc.", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://www.mongodb.com/", + "documentation": null, + "repository": "https://hub.docker.com/_/mongo", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/_/mongo", + "revision": "f913408ef67cdc084de4737f48afb10e8db8863ceaa270b587c5ca089d0e1d15", + "image_repository_url": "https://hub.docker.com/_/mongo", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "f913408ef67cdc084de4737f48afb10e8db8863ceaa270b587c5ca089d0e1d15", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "mongo", + "container_name": "mongo", + "image": { + "reference": "mongo:latest", + "registry": "docker.io", + "repository": "mongo", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data/configdb", + "compose_source_example": "/DATA/AppData/mongo/data/configdb", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/data/db", + "compose_source_example": "/DATA/AppData/mongo/data/db", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 27017, + "published_example": 27017, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: mongodb\nservices:\n mongo:\n image: mongo:latest\n restart: unless-stopped\n environment:\n PUID: $PUID\n PGID: $PGID\n TZ: $TZ\n ports:\n - target: 27017\n published: 27017\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/mongo/data/configdb\n target: /data/configdb\n - type: bind\n source: /DATA/AppData/mongo/data/db\n target: /data/db\n container_name: mongo\n" + }, + "compose_stack": { + "project_name": "mongodb", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mongo", + "service_count": 1, + "services": [ + { + "name": "mongo", + "image": "mongo:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "mongo:latest", + "restart": "unless-stopped", + "environment": { + "PUID": "$PUID", + "PGID": "$PGID", + "TZ": "$TZ" + }, + "ports": [ + { + "target": 27017, + "published": 27017, + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/mongo/data/configdb", + "target": "/data/configdb" + }, + { + "type": "bind", + "source": "/DATA/AppData/mongo/data/db", + "target": "/data/db" + } + ], + "container_name": "mongo" + } + } + ], + "top_level": { + "name": "mongodb" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mongo-volume-0", + "service": "mongo", + "container_path": "/data/configdb", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for mongo:/data/configdb" + }, + { + "id": "mongo-volume-1", + "service": "mongo", + "container_path": "/data/db", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for mongo:/data/db" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mongo" + ], + "stop_order": [ + "mongo" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mongodb4.json b/oci/catalog/apps/mongodb4.json new file mode 100644 index 00000000..fd816711 --- /dev/null +++ b/oci/catalog/apps/mongodb4.json @@ -0,0 +1,444 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-mongodb4", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "MongoDB 4" + }, + "tagline": { + "en_US": "A free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata." + }, + "description": { + "en_US": "MongoDB is a free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata. MongoDB is developed by MongoDB Inc., and is published under a combination of the Server Side Public License and the Apache License." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "MongoDB Inc.", + "developer": "MongoDB Inc.", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://www.mongodb.com/", + "documentation": null, + "repository": "https://hub.docker.com/_/mongo", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/_/mongo", + "revision": "9a9681d4f601278b5a3108c455e0afc194cb10a4b58230631705f2585b2f6c5c", + "image_repository_url": "https://hub.docker.com/_/mongo", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "9a9681d4f601278b5a3108c455e0afc194cb10a4b58230631705f2585b2f6c5c", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "mongodb4", + "container_name": "mongodb4", + "image": { + "reference": "mongo:latest", + "registry": "docker.io", + "repository": "mongo", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data/configdb", + "compose_source_example": "/DATA/AppData/mongodb4/data/configdb", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/data/db", + "compose_source_example": "/DATA/AppData/mongodb4/data/db", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 27017, + "published_example": 27017, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: mongodb4\nservices:\n mongodb4:\n image: mongo:latest\n restart: unless-stopped\n environment:\n PUID: $PUID\n PGID: $PGID\n TZ: $TZ\n ports:\n - target: 27017\n published: '27017'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/mongodb4/data/configdb\n target: /data/configdb\n - type: bind\n source: /DATA/AppData/mongodb4/data/db\n target: /data/db\n container_name: mongodb4\n" + }, + "compose_stack": { + "project_name": "mongodb4", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mongodb4", + "service_count": 1, + "services": [ + { + "name": "mongodb4", + "image": "mongo:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "mongo:latest", + "restart": "unless-stopped", + "environment": { + "PUID": "$PUID", + "PGID": "$PGID", + "TZ": "$TZ" + }, + "ports": [ + { + "target": 27017, + "published": "27017", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/mongodb4/data/configdb", + "target": "/data/configdb" + }, + { + "type": "bind", + "source": "/DATA/AppData/mongodb4/data/db", + "target": "/data/db" + } + ], + "container_name": "mongodb4" + } + } + ], + "top_level": { + "name": "mongodb4" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mongodb4-volume-0", + "service": "mongodb4", + "container_path": "/data/configdb", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for mongodb4:/data/configdb" + }, + { + "id": "mongodb4-volume-1", + "service": "mongodb4", + "container_path": "/data/db", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for mongodb4:/data/db" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mongodb4" + ], + "stop_order": [ + "mongodb4" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/monica-official.json b/oci/catalog/apps/monica-official.json new file mode 100644 index 00000000..cccdcd8d --- /dev/null +++ b/oci/catalog/apps/monica-official.json @@ -0,0 +1,594 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-monica-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Monica" + }, + "tagline": { + "en_US": "A Personal Relationship Management tool to help you document your social life." + }, + "description": { + "en_US": "Monica is a self-hosted personal relationship management tool that helps users document and organize interactions with family and friends via an intuitive Web interface, creating a personalized contact database. It is ideal for users balancing work and life, ensuring key personal connections are never missed.\n\nThe tool's core features include comprehensive contact management and smart reminders. It supports creating detailed contact profiles, logging personal details, relationships (e.g., family, friends), and how contacts were met. Users can set automatic reminders for birthdays, anniversaries, and other key dates, while tracking conversations, activities, and gift ideas. A diary feature records daily moods and significant moments, maintaining a clear life record.\n\nIt offers task and debt management to track to-dos or financial interactions. Users can upload photos and documents, favorite contacts, and organize relationships with labels for streamlined data management. Full control over local data ensures privacy. The tool\u2019s intuitive operation and high flexibility deliver a modern relationship management solution.\n\n**Key Features:**\n- Comprehensive contact management with detailed profiles\n- Automatic reminders for birthdays, anniversaries, and key dates\n- Track conversations, activities, and gift ideas\n- Diary feature to record daily moods and moments\n- Task and debt management for to-dos and finances\n- Upload photos and documents, favorite contacts\n- Organize contacts with labels\n- Local data storage for privacy assurance\n\n**Learn More:**\n- [Monica Official Website](https://www.monicahq.com)\n- [Monica GitHub Repository](https://github.com/monicahq/monica)\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "monica", + "developer": "monica", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://www.monicahq.com", + "documentation": null, + "repository": "https://hub.docker.com/_/monica", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/_/monica", + "revision": "834c144baa356237d20c37694693bac9e823c3541e882e6faa330a7c178a0c35", + "image_repository_url": "https://hub.docker.com/_/monica", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "834c144baa356237d20c37694693bac9e823c3541e882e6faa330a7c178a0c35", + "generated_at": "2026-09-13T15:48:31+00:00" + }, + "container_contract": { + "service_name": "monica", + "container_name": "monica", + "image": { + "reference": "monica:latest", + "registry": "docker.io", + "repository": "monica", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "APP_KEY", + "example": "${GENERATED_APP_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "DB_HOST", + "example": "monica-db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_USERNAME", + "example": "monicauser", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_PASSWORD", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/www/html/storage", + "compose_source_example": "/DATA/AppData/$AppID/storage", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 18930, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "monica-db", + "image": "mariadb:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: monica\nservices:\n monica:\n image: monica:latest\n container_name: monica\n deploy:\n resources:\n limits:\n memory: 256M\n reservations:\n memory: 256M\n restart: unless-stopped\n ports:\n - target: 80\n published: '18930'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/storage\n target: /var/www/html/storage\n environment:\n APP_KEY: ${GENERATED_APP_KEY}\n DB_HOST: monica-db\n DB_USERNAME: monicauser\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n networks:\n - monica_network\n depends_on:\n - monica-db\n monica-db:\n image: mariadb:latest\n container_name: monica-db\n deploy:\n resources:\n reservations:\n memory: 256M\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/mysql\n target: /var/lib/mysql\n environment:\n MARIADB_RANDOM_ROOT_PASSWORD: ${GENERATED_MARIADB_RANDOM_ROOT_PASSWORD}\n MARIADB_DATABASE: monica\n MARIADB_USER: monicauser\n MARIADB_PASSWORD: ${GENERATED_DB_PASSWORD}\n restart: unless-stopped\n networks:\n - monica_network\nnetworks:\n monica_network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "monica", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "monica", + "service_count": 2, + "services": [ + { + "name": "monica-db", + "image": "mariadb:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "mariadb:latest", + "container_name": "monica-db", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/mysql", + "target": "/var/lib/mysql" + } + ], + "environment": { + "MARIADB_RANDOM_ROOT_PASSWORD": "${GENERATED_MARIADB_RANDOM_ROOT_PASSWORD}", + "MARIADB_DATABASE": "monica", + "MARIADB_USER": "monicauser", + "MARIADB_PASSWORD": "${GENERATED_DB_PASSWORD}" + }, + "restart": "unless-stopped", + "networks": [ + "monica_network" + ] + } + }, + { + "name": "monica", + "image": "monica:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "monica-db" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "monica:latest", + "container_name": "monica", + "deploy": { + "resources": { + "limits": { + "memory": "256M" + }, + "reservations": { + "memory": "256M" + } + } + }, + "restart": "unless-stopped", + "ports": [ + { + "target": 80, + "published": "18930", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/storage", + "target": "/var/www/html/storage" + } + ], + "environment": { + "APP_KEY": "${GENERATED_APP_KEY}", + "DB_HOST": "monica-db", + "DB_USERNAME": "monicauser", + "DB_PASSWORD": "${GENERATED_DB_PASSWORD}" + }, + "networks": [ + "monica_network" + ], + "depends_on": [ + "monica-db" + ] + } + } + ], + "top_level": { + "name": "monica", + "networks": { + "monica_network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "monica-volume-0", + "service": "monica", + "container_path": "/var/www/html/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "monica-db-volume-0", + "service": "monica-db", + "container_path": "/var/lib/mysql", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "monica-db", + "monica" + ], + "stop_order": [ + "monica", + "monica-db" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "app-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "monica", + "environment_variable": "APP_KEY" + } + ] + }, + { + "id": "db-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "monica", + "environment_variable": "DB_PASSWORD" + }, + { + "service": "monica-db", + "environment_variable": "MARIADB_PASSWORD" + } + ] + }, + { + "id": "mariadb-random-root-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "monica-db", + "environment_variable": "MARIADB_RANDOM_ROOT_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "stack_environment_overrides": { + "monica-db": { + "MARIADB_RANDOM_ROOT_PASSWORD": "yes" + }, + "monica": { + "DB_DATABASE": "monica", + "APP_URL": "http://localhost" + } + }, + "stack_generators": { + "GENERATED_APP_KEY": { + "encoding": "base64", + "bytes": 32, + "prefix": "base64:" + } + }, + "stack_adaptation_notes": [ + "APP_KEY follows the official base64: plus 32 random bytes format; it is generated once per deployment and persisted in the LXC environment.", + "MARIADB_RANDOM_ROOT_PASSWORD is a boolean switch, not a password.", + "Create the first Monica account through its web setup. Internet exposure requires HTTPS configuration." + ], + "stack_references": [ + "https://github.com/monicahq/docker", + "https://github.com/MariaDB/mariadb-docker/blob/master/healthcheck.sh" + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/monica.json b/oci/catalog/apps/monica.json new file mode 100644 index 00000000..30b1d49f --- /dev/null +++ b/oci/catalog/apps/monica.json @@ -0,0 +1,311 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-monica", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Deprecation Notice" + }, + "tagline": { + "en_US": "Monica is an open source personal relationship management system, that lets you document your life." + }, + "description": { + "en_US": "Monica is an open source personal relationship management system, that lets you document your life." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/monica-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/monica-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/monicahq/monica", + "documentation": "https://docs.linuxserver.io/images/docker-monica/", + "repository": "https://github.com/linuxserver/docker-monica", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-03", + "note": "Deprecate due to lack of upstream development." + }, + { + "date": "2024-12-21", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-27", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-05-02", + "note": "Rebase to Alpine 3.19 and PHP 8.3." + }, + { + "date": "2024-01-17", + "note": "Initial Release." + } + ], + "display_version": null, + "updated_at": "2026-07-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-monica", + "default_branch": "main", + "revision": "66f4dcc65cbe64e1ce9a5ac9839e2433a90c5a68", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-monica/66f4dcc65cbe64e1ce9a5ac9839e2433a90c5a68/README.md", + "readme_pushed_at": "2026-07-03T20:21:28Z", + "compose_sha256": "d0aa20413ffb1964fb51b383576e1f794df38fab6b51b34376ab97e8358fd1ea", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "monica", + "container_name": "monica", + "image": { + "reference": "lscr.io/linuxserver/monica:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/monica", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USERNAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_DATABASE", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_URL", + "example": "http://localhost:80", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TRUSTED_PROXIES", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_ENV", + "example": "local", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_DISABLE_SIGNUP", + "example": "true", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/monica/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n monica:\n image: lscr.io/linuxserver/monica:latest\n container_name: monica\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DB_HOST=\n - DB_PORT=\n - DB_USERNAME=\n - DB_PASSWORD=\n - DB_DATABASE=\n - APP_URL=http://localhost:80 #optional\n - TRUSTED_PROXIES= #optional\n - APP_ENV=local #optional\n - APP_DISABLE_SIGNUP=true #optional\n volumes:\n - /path/to/monica/config:/config\n ports:\n - 80:80\n - 443:443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/motioneye.json b/oci/catalog/apps/motioneye.json new file mode 100644 index 00000000..28a31bd2 --- /dev/null +++ b/oci/catalog/apps/motioneye.json @@ -0,0 +1,426 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-motioneye", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Motioneye" + }, + "tagline": { + "en_US": "A web frontend for the motion daemon." + }, + "description": { + "en_US": "motionEye is a web-based frontend for motion. Check out the wiki for more details. Changelog is available on the releases page. https://github.com/motioneye-project/motioneye" + }, + "category": "nvr", + "category_label": "NVR & Cameras", + "author": "Motioneye", + "developer": "Motioneye", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8765, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/ccrisan/motioneye", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "ccrisan", + "repository": "https://hub.docker.com/r/ccrisan/motioneye", + "revision": "87d41c6760b5c974c7e2d37d693c46dd25de3624da3ce8d8a5ea1b35c80fe3a3", + "image_repository_url": "https://hub.docker.com/r/ccrisan/motioneye", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "87d41c6760b5c974c7e2d37d693c46dd25de3624da3ce8d8a5ea1b35c80fe3a3", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "motioneye", + "container_name": "motioneye", + "image": { + "reference": "ccrisan/motioneye:latest", + "registry": "docker.io", + "repository": "ccrisan/motioneye", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/etc/motioneye", + "compose_source_example": "/DATA/AppData/motioneye/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/var/lib/motioneye", + "compose_source_example": "/DATA/Media/motioneye", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8765, + "published_example": 8765, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: motioneye\nservices:\n motioneye:\n container_name: motioneye\n image: ccrisan/motioneye:latest\n ports:\n - target: 8765\n published: '8765'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/motioneye/config\n target: /etc/motioneye\n - type: bind\n source: /DATA/Media/motioneye\n target: /var/lib/motioneye\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "motioneye", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "motioneye", + "service_count": 1, + "services": [ + { + "name": "motioneye", + "image": "ghcr.io/motioneye-project/motioneye:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "motioneye", + "image": "ghcr.io/motioneye-project/motioneye:latest", + "ports": [ + { + "target": 8765, + "published": "8765", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/motioneye/config", + "target": "/etc/motioneye" + }, + { + "type": "bind", + "source": "/DATA/Media/motioneye", + "target": "/var/lib/motioneye" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "motioneye" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "motioneye-volume-0", + "service": "motioneye", + "container_path": "/etc/motioneye", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "motioneye-volume-1", + "service": "motioneye", + "container_path": "/var/lib/motioneye", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "motioneye" + ], + "stop_order": [ + "motioneye" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8765, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/msedge.json b/oci/catalog/apps/msedge.json new file mode 100644 index 00000000..4d0b34bf --- /dev/null +++ b/oci/catalog/apps/msedge.json @@ -0,0 +1,386 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-msedge", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Msedge" + }, + "tagline": { + "en_US": "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium." + }, + "description": { + "en_US": "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/msedge-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/msedge-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://www.microsoft.com/edge", + "documentation": "https://docs.linuxserver.io/images/docker-msedge/", + "repository": "https://github.com/linuxserver/docker-msedge", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2025-02-04", + "note": "Clean up Singletons if container is shut down while windows are open." + } + ], + "display_version": null, + "updated_at": "2026-03-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-msedge", + "default_branch": "master", + "revision": "30fab779e787b520bcac4d5783ce235cc497afcb", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-msedge/30fab779e787b520bcac4d5783ce235cc497afcb/README.md", + "readme_pushed_at": "2026-09-11T00:50:56Z", + "compose_sha256": "954846650c04c4698d716ea359427cf78fcdce40e055d4eeaed17c25decc3195", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "msedge", + "container_name": "msedge", + "image": { + "reference": "lscr.io/linuxserver/msedge:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/msedge", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EDGE_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n msedge:\n image: lscr.io/linuxserver/msedge:latest\n container_name: msedge\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - EDGE_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI 1", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "linuxserver-readme-application-setup" + }, + { + "label": "Web UI 2", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-msedge/master/Dockerfile", + "dockerfile_sha256": "1ca2b22799881c9879c18eaba2ea62f1a00cf4809a193a6265f47f3c850d3743", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mstream.json b/oci/catalog/apps/mstream.json new file mode 100644 index 00000000..4d911458 --- /dev/null +++ b/oci/catalog/apps/mstream.json @@ -0,0 +1,257 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-mstream", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Mstream" + }, + "tagline": { + "en_US": "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone." + }, + "description": { + "en_US": "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mstream-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mstream-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://mstream.io/", + "documentation": "https://docs.linuxserver.io/images/docker-mstream/", + "repository": "https://github.com/linuxserver/docker-mstream", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-08", + "note": "Rebase to Alpine 3.24. Use the distro onnxruntime so the discovery/recommendation features work on musl." + }, + { + "date": "2026-04-24", + "note": "Make waveform data persistent." + }, + { + "date": "2026-04-20", + "note": "Fix perms on rust binaries." + }, + { + "date": "2026-04-07", + "note": "Add ffmpeg and yt-dlp." + }, + { + "date": "2026-04-06", + "note": "Rebase to Alpine 3.23." + } + ], + "display_version": null, + "updated_at": "2026-07-08" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-mstream", + "default_branch": "master", + "revision": "61d8e80aba3ebebf26510d2d3811d42b641cb14c", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-mstream/61d8e80aba3ebebf26510d2d3811d42b641cb14c/README.md", + "readme_pushed_at": "2026-09-09T05:40:58Z", + "compose_sha256": "65e169395ae937db64cd3cd9b5f33cf9f721dfd5d4d67e0991ada4b206b320fc", + "generated_at": "2026-09-12T14:37:31+00:00" + }, + "container_contract": { + "service_name": "mstream", + "container_name": "mstream", + "image": { + "reference": "lscr.io/linuxserver/mstream:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/mstream", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/mstream/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/music", + "compose_source_example": "/path/to/music", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n mstream:\n image: lscr.io/linuxserver/mstream:latest\n container_name: mstream\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/mstream/data:/config\n - /path/to/music:/music\n ports:\n - 3000:3000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mullvad-browser.json b/oci/catalog/apps/mullvad-browser.json new file mode 100644 index 00000000..1fbdd24f --- /dev/null +++ b/oci/catalog/apps/mullvad-browser.json @@ -0,0 +1,486 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-mullvad-browser", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Mullvad Browser" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mullvad-browser-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mullvad-browser-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": null, + "documentation": "https://docs.linuxserver.io/images/docker-mullvad-browser/", + "repository": "https://github.com/linuxserver/docker-mullvad-browser", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to resolute." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-26", + "note": "Suppress sandbox security warning as it's misleading inside a container." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-mullvad-browser", + "default_branch": "main", + "revision": "3ab7f8d7c3b160188aa7a77acf3afd447b4ae911", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-mullvad-browser/3ab7f8d7c3b160188aa7a77acf3afd447b4ae911/README.md", + "readme_pushed_at": "2026-09-06T23:35:48Z", + "compose_sha256": "ce3ebdc3f6cd57867f3818949685faf985330fbd0a7bb7e1e407b550c400bd48", + "generated_at": "2026-09-13T15:47:49+00:00" + }, + "container_contract": { + "service_name": "mullvad-browser", + "container_name": "mullvad-browser", + "image": { + "reference": "lscr.io/linuxserver/mullvad-browser:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/mullvad-browser", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOCAL_NET", + "example": "192.168.0.0/16", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/mullvad-browser/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n mullvad-browser:\n image: lscr.io/linuxserver/mullvad-browser:latest\n container_name: mullvad-browser\n cap_add:\n - NET_ADMIN\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - LOCAL_NET=192.168.0.0/16 #optional\n volumes:\n - /path/to/mullvad-browser/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "security": { + "required_capabilities": [ + "NET_ADMIN" + ] + }, + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-mullvad-browser/master/Dockerfile", + "dockerfile_sha256": "1514544621cf06f20a7675f86b13ec6af9145d8a94d0a52f684cc7dd925370cd", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mylar3.json b/oci/catalog/apps/mylar3.json new file mode 100644 index 00000000..6726002d --- /dev/null +++ b/oci/catalog/apps/mylar3.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-mylar3", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Mylar3" + }, + "tagline": { + "en_US": "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL." + }, + "description": { + "en_US": "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mylar3-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mylar3-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8090, + "path": "/" + }, + "website": "https://github.com/MylarComics/mylar3", + "documentation": "https://docs.linuxserver.io/images/docker-mylar3/", + "repository": "https://github.com/linuxserver/docker-mylar3", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-06", + "note": "Switch upstream to maintained fork at https://github.com/MylarComics/mylar3. Drop `unstable` tag." + }, + { + "date": "2026-02-19", + "note": "Rebase `latest` tag based on commits to upstream `python3-dev` branch. `nightly` will build commits to upstream `1000papercuts` branch. `unstable` tag will also build commits to upstream `1000papercuts` branch, but on alpine 3.23 with python 3.12." + }, + { + "date": "2026-02-05", + "note": "Release `unstable` tag based on commits to upstream `1000papercuts` branch." + }, + { + "date": "2025-11-21", + "note": "Rebase to Ubuntu Jammy." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2026-04-06" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-mylar3", + "default_branch": "master", + "revision": "4e74010382723b546131945289f4e96e14772c89", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-mylar3/4e74010382723b546131945289f4e96e14772c89/README.md", + "readme_pushed_at": "2026-09-11T08:58:58Z", + "compose_sha256": "7bc88e9c85db2dd5f35b339fd52fc5d4b4e50c4dcdc86b6448e04fadfb7f6b9c", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "mylar3", + "container_name": "mylar3", + "image": { + "reference": "lscr.io/linuxserver/mylar3:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/mylar3", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/mylar3/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/comics", + "compose_source_example": "/path/to/comics", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8090, + "published_example": 8090, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n mylar3:\n image: lscr.io/linuxserver/mylar3:latest\n container_name: mylar3\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/mylar3/config:/config\n - /path/to/comics:/comics\n - /path/to/downloads:/downloads\n ports:\n - 8090:8090\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8090, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/myspeed.json b/oci/catalog/apps/myspeed.json new file mode 100644 index 00000000..08270762 --- /dev/null +++ b/oci/catalog/apps/myspeed.json @@ -0,0 +1,402 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-myspeed", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "MySpeed" + }, + "tagline": { + "en_US": "Analysis software that shows your internet speed for up to 30 days." + }, + "description": { + "en_US": "MySpeed is a speed test analysis software that stores the speed of your internet for up to 30 days. This can also be useful if you want to know when your network might have drops or if you want to check if your internet matches the booked values from your contract." + }, + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "author": "Mathias Wagner", + "developer": "Mathias Wagner", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5216, + "path": "/" + }, + "website": "https://myspeed.dev", + "documentation": null, + "repository": "https://hub.docker.com/r/germannewsmaker/myspeed", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "germannewsmaker", + "repository": "https://hub.docker.com/r/germannewsmaker/myspeed", + "revision": "85bf729881292fb36e9460304492976c4103b250f225b983c06e47374eb6a4f2", + "image_repository_url": "https://hub.docker.com/r/germannewsmaker/myspeed", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "85bf729881292fb36e9460304492976c4103b250f225b983c06e47374eb6a4f2", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "myspeed", + "container_name": "myspeed", + "image": { + "reference": "germannewsmaker/myspeed:latest", + "registry": "docker.io", + "repository": "germannewsmaker/myspeed", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/myspeed/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5216, + "published_example": 5216, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: myspeed\nservices:\n myspeed:\n container_name: myspeed\n deploy:\n resources:\n limits:\n memory: 256M\n image: germannewsmaker/myspeed:latest\n ports:\n - target: 5216\n published: '5216'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /myspeed/data\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "myspeed", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "myspeed", + "service_count": 1, + "services": [ + { + "name": "myspeed", + "image": "germannewsmaker/myspeed:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "myspeed", + "deploy": { + "resources": { + "limits": { + "memory": "256M" + } + } + }, + "image": "germannewsmaker/myspeed:latest", + "ports": [ + { + "target": 5216, + "published": "5216", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/myspeed/data" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "myspeed" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "myspeed-volume-0", + "service": "myspeed", + "container_path": "/myspeed/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "myspeed" + ], + "stop_order": [ + "myspeed" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5216, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/mysql-workbench.json b/oci/catalog/apps/mysql-workbench.json new file mode 100644 index 00000000..c4894699 --- /dev/null +++ b/oci/catalog/apps/mysql-workbench.json @@ -0,0 +1,479 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-mysql-workbench", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Mysql Workbench" + }, + "tagline": { + "en_US": "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more." + }, + "description": { + "en_US": "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mysql-workbench-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mysql-workbench-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.mysql.com/products/workbench/", + "documentation": "https://docs.linuxserver.io/images/docker-mysql-workbench/", + "repository": "https://github.com/linuxserver/docker-mysql-workbench", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-18", + "note": "Rebase to Arch Linux." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-07-01", + "note": "Rebase to Noble." + } + ], + "display_version": null, + "updated_at": "2026-05-18" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-mysql-workbench", + "default_branch": "master", + "revision": "e1e8be3afac3b562301b040fe36b1c7420c32571", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-mysql-workbench/e1e8be3afac3b562301b040fe36b1c7420c32571/README.md", + "readme_pushed_at": "2026-09-12T12:26:36Z", + "compose_sha256": "333b14ebfdba5cbe816e81081e19a17caf6eaf85600be485c269ade0424102a5", + "generated_at": "2026-09-13T15:47:50+00:00" + }, + "container_contract": { + "service_name": "mysql-workbench", + "container_name": "mysql-workbench", + "image": { + "reference": "lscr.io/linuxserver/mysql-workbench:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/mysql-workbench", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n mysql-workbench:\n image: lscr.io/linuxserver/mysql-workbench:latest\n container_name: mysql-workbench\n cap_add:\n - IPC_LOCK\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "security": { + "required_capabilities": [ + "IPC_LOCK" + ] + }, + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-mysql-workbench/master/Dockerfile", + "dockerfile_sha256": "10fef7181221fb1552c66caaaac5fdc5712f036153961ec2f086500b3b81b1f1", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/n8n.json b/oci/catalog/apps/n8n.json new file mode 100644 index 00000000..63577050 --- /dev/null +++ b/oci/catalog/apps/n8n.json @@ -0,0 +1,420 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-n8n", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "n8n" + }, + "tagline": { + "en_US": "Workflow automation tool" + }, + "description": { + "en_US": "n8n is a powerful open-source workflow automation and conversational AI platform that blends the flexibility of coding with the simplicity of no-code development, empowering users to create efficient and secure automation workflows. It seamlessly connects any app with an API, leveraging native AI capabilities (like LangChain-based AI agent workflows) to process custom data, ideal for personal task management, team collaboration, or enterprise-grade automation. Its vibrant community offers over 400 integrations and 900+ ready-to-use templates, enabling users to deploy automations quickly.\n\nThe platform supports highly customizable workflow design, allowing users to write JavaScript/Python, add npm packages, or use an intuitive visual interface to manage data, catering to both simple tasks and complex processes. Enterprise-grade features like advanced permissions and air-gapped deployments ensure security, while multilingual support makes it accessible globally. n8n delivers a versatile and user-friendly automation solution.\n\nDiscover n8n\u2019s Automation Scenarios\nn8n\u2019s community resources provide extensive support and inspiration, helping users explore its scenario-based value and easily build automation workflows. Below are two key resources showcasing n8n\u2019s capabilities across various use cases:\n\n1. [n8n Official Community Forum](https://community.n8n.io/): \nThe forum is a hub for user collaboration and learning, offering resources from beginner guides to advanced workflow designs. Shared use cases include automating social media posts or real-time data syncing, such as using n8n to pull data from Google Sheets and send Slack notifications, boosting team collaboration and data efficiency.\n\n2. [n8n Official Template Library](https://n8n.io/workflows/): \nThe template library offers over 900 ready-to-use workflows for scenarios like marketing automation, data analytics, and customer support. For example, a template can link Shopify to Mailchimp, automatically adding new customers to mailing lists and sending welcome emails, making automation accessible to non-technical users. AI-driven workflows, like handling customer queries with LangChain, highlight n8n\u2019s strength in intelligent interactions.\n" + }, + "category": "automation", + "category_label": "Automation & Scheduling", + "author": "n8n", + "developer": "n8n", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5678, + "path": "/" + }, + "website": "https://n8n.io", + "documentation": null, + "repository": "https://hub.docker.com/r/n8nio/n8n", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/n8nio/n8n", + "revision": "82af44e6a55a8659184e8561c902136510f5e0f61b754f39ee5528a394903a7b", + "image_repository_url": "https://hub.docker.com/r/n8nio/n8n", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "82af44e6a55a8659184e8561c902136510f5e0f61b754f39ee5528a394903a7b", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "n8n", + "container_name": "n8n", + "image": { + "reference": "n8nio/n8n:latest", + "registry": "docker.io", + "repository": "n8nio/n8n", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "N8N_SECURE_COOKIE", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/home/node/.n8n", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5678, + "published_example": 5678, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: n8n\nservices:\n n8n:\n environment:\n TZ: $TZ\n N8N_SECURE_COOKIE: 'false'\n image: n8nio/n8n:latest\n deploy:\n resources:\n reservations:\n memory: 320M\n network_mode: bridge\n ports:\n - target: 5678\n published: '5678'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /home/node/.n8n\n container_name: n8n\n" + }, + "compose_stack": { + "project_name": "n8n", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "n8n", + "service_count": 1, + "services": [ + { + "name": "n8n", + "image": "n8nio/n8n:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "TZ": "$TZ", + "N8N_SECURE_COOKIE": "false" + }, + "image": "n8nio/n8n:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "320M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 5678, + "published": "5678", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/home/node/.n8n" + } + ], + "container_name": "n8n" + } + } + ], + "top_level": { + "name": "n8n" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "n8n-volume-0", + "service": "n8n", + "container_path": "/home/node/.n8n", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "n8n" + ], + "stop_order": [ + "n8n" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5678, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 320, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/navidrome.json b/oci/catalog/apps/navidrome.json new file mode 100644 index 00000000..ed1ce67d --- /dev/null +++ b/oci/catalog/apps/navidrome.json @@ -0,0 +1,477 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-navidrome", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Navidrome" + }, + "tagline": { + "en_US": "Music Collection and Streaming Server" + }, + "description": { + "en_US": "Navidrome is an open source web-based music collection server and streamer. It gives you freedom to listen to your music collection from any browser or mobile device. It's like your personal Spotify!" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "deluan", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 4533, + "path": "/" + }, + "website": "https://www.navidrome.org", + "documentation": null, + "repository": "https://hub.docker.com/r/deluan/navidrome", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "deluan", + "repository": "https://hub.docker.com/r/deluan/navidrome", + "revision": "1b7f9cbe4e6dc0a70e7403ba699cae46ce23ee687a56588d37579b7479df0648", + "image_repository_url": "https://hub.docker.com/r/deluan/navidrome", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "1b7f9cbe4e6dc0a70e7403ba699cae46ce23ee687a56588d37579b7479df0648", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "navidrome", + "container_name": "navidrome", + "image": { + "reference": "deluan/navidrome:latest", + "registry": "docker.io", + "repository": "deluan/navidrome", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ND_SCANSCHEDULE", + "example": "1h", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ND_LOGLEVEL", + "example": "info", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ND_SESSIONTIMEOUT", + "example": "24h", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "ND_BASEURL", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/music", + "compose_source_example": "/DATA/Media/Music", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 4533, + "published_example": 4533, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: navidrome\nservices:\n navidrome:\n container_name: navidrome\n deploy:\n resources:\n reservations:\n memory: 1024M\n image: deluan/navidrome:latest\n restart: unless-stopped\n ports:\n - target: 4533\n published: '4533'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n - type: bind\n source: /DATA/Media/Music\n target: /music\n environment:\n ND_SCANSCHEDULE: 1h\n ND_LOGLEVEL: info\n ND_SESSIONTIMEOUT: 24h\n ND_BASEURL: ''\n TZ: $TZ\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "navidrome", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "navidrome", + "service_count": 1, + "services": [ + { + "name": "navidrome", + "image": "deluan/navidrome:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "navidrome", + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + }, + "image": "deluan/navidrome:latest", + "restart": "unless-stopped", + "ports": [ + { + "target": 4533, + "published": "4533", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + }, + { + "type": "bind", + "source": "/DATA/Media/Music", + "target": "/music" + } + ], + "environment": { + "ND_SCANSCHEDULE": "1h", + "ND_LOGLEVEL": "info", + "ND_SESSIONTIMEOUT": "24h", + "ND_BASEURL": "", + "TZ": "$TZ" + }, + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "navidrome" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "navidrome-volume-0", + "service": "navidrome", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for navidrome:/data" + }, + { + "id": "navidrome-volume-1", + "service": "navidrome", + "container_path": "/music", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for navidrome:/music" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "navidrome" + ], + "stop_order": [ + "navidrome" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 4533, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/netbird.json b/oci/catalog/apps/netbird.json new file mode 100644 index 00000000..1aa51958 --- /dev/null +++ b/oci/catalog/apps/netbird.json @@ -0,0 +1,467 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-netbird", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "NetBird" + }, + "tagline": { + "en_US": "Connect your devices into a secure WireGuard\u00ae-based overlay network with SSO, MFA and granular access controls." + }, + "description": { + "en_US": "NetBird combines a WireGuard\u00ae-based overlay network with Zero Trust Network Access, providing a unified open source platform for reliable and secure connectivity.\n\n- Secure Remote Access \u2013 Enable least privilege network access in a few clicks\n- Zero-Config Deployment \u2013 Replace legacy VPNs with a peer-to-peer WireGuard\u00ae-based network\n- Seamless SSO with MFA \u2013 Secure your network access with session-based SSO & MFA\n- Dynamic Posture Checks \u2013 Grant access only to devices meeting your security rules\n- Centralized Network Management \u2013 Control your private network from a single place\n- Detailed Activity Logging \u2013 Identify who did what, and when in your network\n\n**Learn More:**\n- [NetBird Website](https://netbird.io)\n- [Documentation](https://docs.netbird.io)\n- [Self-Hosting Guide](https://docs.netbird.io/selfhosted/selfhosted-quickstart)\n- [NetBird GitHub](https://github.com/netbirdio/netbird)\n- [Slack Community](https://docs.netbird.io/slack-url)\n" + }, + "category": "remote", + "category_label": "Remote Access & VPN", + "author": "NetBird GmbH", + "developer": "NetBird GmbH", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://netbird.io", + "documentation": null, + "repository": "https://hub.docker.com/r/netbirdio/netbird", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/netbirdio/netbird", + "revision": "d01b5c4459400fe46c8ef8471c945c62630cd85965fb0a002c5905cf044b8f7f", + "image_repository_url": "https://hub.docker.com/r/netbirdio/netbird", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "d01b5c4459400fe46c8ef8471c945c62630cd85965fb0a002c5905cf044b8f7f", + "generated_at": "2026-09-13T15:47:50+00:00" + }, + "container_contract": { + "service_name": "netbird", + "container_name": "netbird", + "image": { + "reference": "netbirdio/netbird:latest", + "registry": "docker.io", + "repository": "netbirdio/netbird", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "NB_SETUP_KEY", + "example": "${GENERATED_NB_SETUP_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "NB_MANAGEMENT_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NB_HOSTNAME", + "example": "netbird", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NB_ENABLE_SSH_ROOT", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NB_ALLOW_SERVER_SSH", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/lib/netbird", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: netbird\nservices:\n netbird:\n image: netbirdio/netbird:latest\n container_name: netbird\n network_mode: host\n restart: unless-stopped\n cap_add:\n - NET_ADMIN\n - SYS_ADMIN\n - SYS_RESOURCE\n deploy:\n resources:\n reservations:\n memory: 128M\n environment:\n NB_SETUP_KEY: ${GENERATED_NB_SETUP_KEY}\n NB_MANAGEMENT_URL: ''\n NB_HOSTNAME: netbird\n NB_ENABLE_SSH_ROOT: 'true'\n NB_ALLOW_SERVER_SSH: 'true'\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /var/lib/netbird\n" + }, + "compose_stack": { + "project_name": "netbird", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "netbird", + "service_count": 1, + "services": [ + { + "name": "netbird", + "image": "netbirdio/netbird:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "netbirdio/netbird:latest", + "container_name": "netbird", + "network_mode": "host", + "restart": "unless-stopped", + "cap_add": [ + "NET_ADMIN", + "SYS_ADMIN", + "SYS_RESOURCE" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "environment": { + "NB_SETUP_KEY": "${GENERATED_NB_SETUP_KEY}", + "NB_MANAGEMENT_URL": "", + "NB_HOSTNAME": "netbird", + "NB_ENABLE_SSH_ROOT": "true", + "NB_ALLOW_SERVER_SSH": "true" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/var/lib/netbird" + } + ] + } + } + ], + "top_level": { + "name": "netbird" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "netbird-volume-0", + "service": "netbird", + "container_path": "/var/lib/netbird", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "netbird" + ], + "stop_order": [ + "netbird" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "nb-setup-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "netbird", + "environment_variable": "NB_SETUP_KEY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "host" + }, + "security": { + "required_capabilities": [ + "NET_ADMIN", + "SYS_ADMIN", + "SYS_RESOURCE" + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/netbox.json b/oci/catalog/apps/netbox.json new file mode 100644 index 00000000..1f209da1 --- /dev/null +++ b/oci/catalog/apps/netbox.json @@ -0,0 +1,395 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-netbox", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Netbox" + }, + "tagline": { + "en_US": "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations." + }, + "description": { + "en_US": "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations." + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/netbox-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/netbox-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://github.com/netbox-community/netbox", + "documentation": "https://docs.linuxserver.io/images/docker-netbox/", + "repository": "https://github.com/linuxserver/docker-netbox", + "tips": [], + "mini_changelog": [ + { + "date": "2026-01-05", + "note": "Rebase to Alpine 3.23. Add CSRF_TRUSTED_ORIGINS env settings. Drop support for environments with explicitly disabled IPv6." + }, + { + "date": "2024-08-26", + "note": "Restructure init to allow for plugins as mods." + }, + { + "date": "2024-07-16", + "note": "Add required packages for LDAP support." + }, + { + "date": "2024-06-01", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2026-01-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-netbox", + "default_branch": "master", + "revision": "ff7be89287df90a2204cb7443649f7ad061704e2", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-netbox/ff7be89287df90a2204cb7443649f7ad061704e2/README.md", + "readme_pushed_at": "2026-09-10T18:59:34Z", + "compose_sha256": "c90d3bd873cb09a3906d82ede5bff290ea6916b86664d244992a37ca8faf8f76", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "netbox", + "container_name": "netbox", + "image": { + "reference": "lscr.io/linuxserver/netbox:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/netbox", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SUPERUSER_EMAIL", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SUPERUSER_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "ALLOWED_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_NAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USER", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_PORT", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_USERNAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_DB_TASK", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_DB_CACHE", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "BASE_PATH", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CSRF_TRUSTED_ORIGINS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_ENABLED", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_BACKEND", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_HEADER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_AUTO_CREATE_USER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_DEFAULT_GROUPS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_DEFAULT_PERMISSIONS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/netbox/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n netbox:\n image: lscr.io/linuxserver/netbox:latest\n container_name: netbox\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - SUPERUSER_EMAIL=\n - SUPERUSER_PASSWORD=\n - ALLOWED_HOST=\n - DB_NAME=\n - DB_USER=\n - DB_PASSWORD=\n - DB_HOST=\n - DB_PORT=\n - REDIS_HOST=\n - REDIS_PORT=\n - REDIS_USERNAME=\n - REDIS_PASSWORD=\n - REDIS_DB_TASK=\n - REDIS_DB_CACHE=\n - BASE_PATH= #optional\n - CSRF_TRUSTED_ORIGINS= #optional\n - REMOTE_AUTH_ENABLED= #optional\n - REMOTE_AUTH_BACKEND= #optional\n - REMOTE_AUTH_HEADER= #optional\n - REMOTE_AUTH_AUTO_CREATE_USER= #optional\n - REMOTE_AUTH_DEFAULT_GROUPS= #optional\n - REMOTE_AUTH_DEFAULT_PERMISSIONS= #optional\n volumes:\n - /path/to/netbox/config:/config\n ports:\n - 8000:8000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/netdata.json b/oci/catalog/apps/netdata.json new file mode 100644 index 00000000..5ca3ba5f --- /dev/null +++ b/oci/catalog/apps/netdata.json @@ -0,0 +1,679 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-netdata", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Netdata" + }, + "tagline": { + "en_US": "Real-time Performance Monitoring" + }, + "description": { + "en_US": "Netdata is a real-time performance and health monitoring solution that helps you visualize and understand the behavior of your systems." + }, + "category": "management", + "category_label": "Host Management", + "author": "official", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 19999, + "path": "/" + }, + "website": "https://www.netdata.cloud", + "documentation": null, + "repository": "https://hub.docker.com/r/netdata/netdata", + "tips": [ + "Monitors host processes, CPU, memory and network; uses the host IP, not its own IP.", + "Privileged access to the host PID/network and unconfined AppArmor: requires confirmation. Trusted networks only; the host firewall is the one that applies.", + "Neither docker.sock nor the host root directory is mounted. Docker inventory, SMART and capacity of all filesystems are not guaranteed.", + "LXCFS is skipped only in the monitor CT so that the limited container RAM/CPU is not shown.", + "Uses lxc.include with /etc/pve/lxc/proxmenux-host-monitor; this file is not included in vzdump and must be kept when restoring on another host.", + "The CPU limit is applied as cpulimit, without hiding processors through affinity." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/netdata/netdata", + "revision": "dcdda5b4b23b1d171478c98540b2391bc1c96e7fb44605a14419bfdea48ad63a", + "image_repository_url": "https://hub.docker.com/r/netdata/netdata", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "dcdda5b4b23b1d171478c98540b2391bc1c96e7fb44605a14419bfdea48ad63a", + "generated_at": "2026-09-13T17:20:19+00:00" + }, + "container_contract": { + "service_name": "netdata", + "container_name": "netdata", + "image": { + "reference": "netdata/netdata:latest", + "registry": "docker.io", + "repository": "netdata/netdata", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/etc/netdata", + "compose_source_example": "/DATA/AppData/Netdata/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/var/lib/netdata", + "compose_source_example": "/DATA/AppData/Netdata/lib", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/var/cache/netdata", + "compose_source_example": "/DATA/AppData/Netdata/cache", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 19999, + "published_example": 19999, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: netdata\nservices:\n netdata:\n cap_add:\n - SYS_PTRACE\n - SYS_ADMIN\n cpu_shares: 90\n container_name: netdata\n deploy:\n resources:\n limits:\n memory: 1794M\n image: netdata/netdata:latest\n pid: host\n ports:\n - target: 19999\n published: '19999'\n protocol: tcp\n restart: unless-stopped\n security_opt:\n - apparmor:unconfined\n volumes:\n - type: bind\n source: /DATA/AppData/Netdata/config\n target: /etc/netdata\n - type: bind\n source: /DATA/AppData/Netdata/lib\n target: /var/lib/netdata\n - type: bind\n source: /DATA/AppData/Netdata/cache\n target: /var/cache/netdata\n - type: bind\n source: /etc/passwd\n target: /host/etc/passwd\n - type: bind\n source: /etc/group\n target: /host/etc/group\n - type: bind\n source: /proc\n target: /host/proc\n - type: bind\n source: /sys\n target: /host/sys\n - type: bind\n source: /etc/os-release\n target: /host/etc/os-release\n - type: bind\n source: /var/run/docker.sock\n target: /var/run/docker.sock\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "netdata", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "netdata", + "service_count": 1, + "services": [ + { + "name": "netdata", + "image": "netdata/netdata:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "cap_add": [ + "SYS_PTRACE", + "SYS_ADMIN" + ], + "cpu_shares": 90, + "container_name": "netdata", + "deploy": { + "resources": { + "limits": { + "memory": "1794M" + } + } + }, + "image": "netdata/netdata:latest", + "pid": "host", + "ports": [ + { + "target": 19999, + "published": "19999", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "security_opt": [ + "apparmor:unconfined" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/Netdata/config", + "target": "/etc/netdata" + }, + { + "type": "bind", + "source": "/DATA/AppData/Netdata/lib", + "target": "/var/lib/netdata" + }, + { + "type": "bind", + "source": "/DATA/AppData/Netdata/cache", + "target": "/var/cache/netdata" + }, + { + "type": "bind", + "source": "/etc/passwd", + "target": "/host/etc/passwd" + }, + { + "type": "bind", + "source": "/etc/group", + "target": "/host/etc/group" + }, + { + "type": "bind", + "source": "/proc", + "target": "/host/proc" + }, + { + "type": "bind", + "source": "/sys", + "target": "/host/sys" + }, + { + "type": "bind", + "source": "/etc/os-release", + "target": "/host/etc/os-release" + }, + { + "type": "bind", + "source": "/var/run/docker.sock", + "target": "/var/run/docker.sock" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "netdata" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "netdata-volume-0", + "service": "netdata", + "container_path": "/etc/netdata", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "netdata-volume-1", + "service": "netdata", + "container_path": "/var/lib/netdata", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "netdata-volume-2", + "service": "netdata", + "container_path": "/var/cache/netdata", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "netdata-volume-3", + "service": "netdata", + "container_path": "/host/etc/passwd", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "netdata-volume-4", + "service": "netdata", + "container_path": "/host/etc/group", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "netdata-volume-5", + "service": "netdata", + "container_path": "/host/proc", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "netdata-volume-6", + "service": "netdata", + "container_path": "/host/sys", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "netdata-volume-7", + "service": "netdata", + "container_path": "/host/etc/os-release", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "netdata-volume-8", + "service": "netdata", + "container_path": "/var/run/docker.sock", + "mode": "runtime-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "netdata" + ], + "stop_order": [ + "netdata" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 19999, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": false, + "ostype": "unmanaged", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "resources": { + "cpu_shares": 90 + }, + "network": { + "compose_mode": "bridge" + }, + "security": { + "required_capabilities": [ + "SYS_PTRACE", + "SYS_ADMIN" + ], + "options": { + "apparmor_profile": "unconfined" + } + }, + "host_monitor": "netdata", + "host_monitor_mounts": [ + { + "source": "/proc", + "target": "/host/proc" + }, + { + "source": "/sys", + "target": "/host/sys" + }, + { + "source": "/etc/passwd", + "target": "/host/etc/passwd" + }, + { + "source": "/etc/group", + "target": "/host/etc/group" + }, + { + "source": "/etc/os-release", + "target": "/host/etc/os-release" + }, + { + "source": "/sys/fs/cgroup", + "target": "/host/sys/fs/cgroup" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 19999, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "verify_tls": false + } + }, + "security_profile": { + "requires_privileged_lxc": true, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": true, + "source_requests_relaxed_confinement": true, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": true, + "warning": "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "passed-observed-2026-09-14", + "restart_persistence": "passed-observed-2026-09-14", + "backup_restore": "pending", + "update_preserves_data": "pending", + "latest_runtime_observation": { + "date": "2026-09-14", + "vmid": 105, + "architecture": "amd64", + "proxmox": "9.2.18", + "image_digest": "sha256:9317b3621e0a1f7406051d2dda6b94bf81ecebc79f24447aedaa92405b0a171e", + "image_version": "v2.11.0-340-nightly", + "http_port": 19999, + "host_pid_namespace": true, + "host_network_namespace": true, + "host_memory_bytes": 16110522368, + "shutdown_start_passed": true, + "companion_include": "/etc/pve/lxc/proxmenux-host-monitor", + "companion_included_in_vzdump": false, + "rolling_tag_validation": "only-observed-digest", + "cgroup_charts_observed": 144, + "persistent_registry_uid_unchanged": true, + "managed_volumes_backup": true + } + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/netronome.json b/oci/catalog/apps/netronome.json new file mode 100644 index 00000000..b8fe868c --- /dev/null +++ b/oci/catalog/apps/netronome.json @@ -0,0 +1,468 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-netronome", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Netronome" + }, + "tagline": { + "en_US": "Monitor, analyze, and alert on network performance." + }, + "description": { + "en_US": "Netronome is a complete network performance monitoring solution with speed tests, continuous packet-loss monitoring, distributed server agents, automated alerts, visualizations, and historical tracking." + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "autobrr", + "developer": "autobrr", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 7575, + "path": "/" + }, + "website": "https://netrono.me", + "documentation": null, + "repository": "https://ghcr.io/autobrr/netronome", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "autobrr", + "repository": "https://ghcr.io/autobrr/netronome", + "revision": "f1ba2fa2ec132ed83be9fe40ab0e950f69923ffcf910bab4ecdbba71402731c3", + "image_repository_url": "https://ghcr.io/autobrr/netronome", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "f1ba2fa2ec132ed83be9fe40ab0e950f69923ffcf910bab4ecdbba71402731c3", + "generated_at": "2026-09-13T15:47:50+00:00" + }, + "container_contract": { + "service_name": "netronome", + "container_name": "netronome", + "image": { + "reference": "ghcr.io/autobrr/netronome:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/autobrr/netronome", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NETRONOME__HOST", + "example": "0.0.0.0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NETRONOME__PORT", + "example": "7575", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 7575, + "published_example": 7575, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: netronome\nservices:\n netronome:\n image: ghcr.io/autobrr/netronome:latest\n container_name: netronome\n restart: unless-stopped\n entrypoint:\n - /sbin/tini\n - --\n - /bin/sh\n - -c\n command:\n - \"config=/data/.config/netronome/config.toml\\nif [ ! -f \\\"$$config\\\" ]; then\\n\\\n \\ netronome generate-config\\nfi\\nexec netronome serve\"\n ports:\n - target: 7575\n published: '7575'\n protocol: tcp\n environment:\n TZ: $TZ\n NETRONOME__HOST: 0.0.0.0\n NETRONOME__PORT: 7575\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n cap_add:\n - NET_RAW\n" + }, + "compose_stack": { + "project_name": "netronome", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "netronome", + "service_count": 1, + "services": [ + { + "name": "netronome", + "image": "ghcr.io/autobrr/netronome:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/autobrr/netronome:latest", + "container_name": "netronome", + "restart": "unless-stopped", + "entrypoint": [ + "/sbin/tini", + "--", + "/bin/sh", + "-c" + ], + "command": [ + "config=/data/.config/netronome/config.toml\nif [ ! -f \"$$config\" ]; then\n netronome generate-config\nfi\nexec netronome serve" + ], + "ports": [ + { + "target": 7575, + "published": "7575", + "protocol": "tcp" + } + ], + "environment": { + "TZ": "$TZ", + "NETRONOME__HOST": "0.0.0.0", + "NETRONOME__PORT": 7575 + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "cap_add": [ + "NET_RAW" + ] + } + } + ], + "top_level": { + "name": "netronome" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "netronome-volume-0", + "service": "netronome", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for netronome:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "netronome" + ], + "stop_order": [ + "netronome" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7575, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "config=/data/.config/netronome/config.toml\nif [ ! -f \"$$config\" ]; then\n netronome generate-config\nfi\nexec netronome serve" + ], + "compose_entrypoint": [ + "/sbin/tini", + "--", + "/bin/sh", + "-c" + ] + }, + "security": { + "required_capabilities": [ + "NET_RAW" + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/nextcloud-official.json b/oci/catalog/apps/nextcloud-official.json new file mode 100644 index 00000000..926510de --- /dev/null +++ b/oci/catalog/apps/nextcloud-official.json @@ -0,0 +1,413 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-nextcloud-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Nextcloud" + }, + "tagline": { + "en_US": "Content collaboration platform" + }, + "description": { + "en_US": "Discover the ultimate solution for remote collaboration with Nextcloud. Unlike traditional office software, Nextcloud seamlessly integrates files, communication, and productivity tools into one platform, enhancing teamwork and streamlining your workflow. Say goodbye to the limitations of conventional tools and embrace a new era of collaboration.\n\nNextcloud stands out with its robust features tailored for every need. Enjoy secure file storage, real-time communication via Talk, comprehensive groupware, and powerful office integration, all in one place. Experience these top-notch features at an affordable price, making it accessible for everyone to elevate their collaboration game.\n\nDeploying Nextcloud on a self-hosted server private cloud device brings unparalleled convenience. Benefit from unlimited storage, secure data privacy, local network speeds, and multi-device access, ensuring you have everything you need at your fingertips.\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Nextcloud", + "developer": "Nextcloud", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://nextcloud.com", + "documentation": null, + "repository": "https://hub.docker.com/_/nextcloud", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/_/nextcloud", + "revision": "c6287dcc5a8304e977e6c44f6379cb7adf41840743860d9e35760e5cb217cded", + "image_repository_url": "https://hub.docker.com/_/nextcloud", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "c6287dcc5a8304e977e6c44f6379cb7adf41840743860d9e35760e5cb217cded", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "nextcloud", + "container_name": "nextcloud", + "image": { + "reference": "nextcloud:latest", + "registry": "docker.io", + "repository": "nextcloud", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/www/html", + "compose_source_example": "/DATA/AppData/$AppID/var/www/html", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 10081, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 10443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: nextcloud\nservices:\n nextcloud:\n image: nextcloud:latest\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 80\n published: '10081'\n protocol: tcp\n - target: 443\n published: '10443'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/var/www/html\n target: /var/www/html\n container_name: nextcloud\n" + }, + "compose_stack": { + "project_name": "nextcloud", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "nextcloud", + "service_count": 1, + "services": [ + { + "name": "nextcloud", + "image": "nextcloud:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "nextcloud:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 80, + "published": "10081", + "protocol": "tcp" + }, + { + "target": 443, + "published": "10443", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/var/www/html", + "target": "/var/www/html" + } + ], + "container_name": "nextcloud" + } + } + ], + "top_level": { + "name": "nextcloud" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "nextcloud-volume-0", + "service": "nextcloud", + "container_path": "/var/www/html", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "nextcloud" + ], + "stop_order": [ + "nextcloud" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/nextcloud-stack.json b/oci/catalog/apps/nextcloud-stack.json new file mode 100644 index 00000000..2472968c --- /dev/null +++ b/oci/catalog/apps/nextcloud-stack.json @@ -0,0 +1,613 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-nextcloud-stack", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Nextcloud Stack" + }, + "tagline": { + "en_US": "Nextcloud with private PostgreSQL and Redis dependencies" + }, + "description": { + "en_US": "A three-service Nextcloud deployment adapted to native Proxmox OCI LXC containers." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Nextcloud", + "developer": "Nextcloud", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://nextcloud.com/", + "documentation": "https://github.com/nextcloud/docker", + "repository": "https://github.com/nextcloud/docker", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-27" + }, + "source": { + "provider": "nextcloud", + "repository": "https://github.com/nextcloud/docker", + "revision": "efbfd48ff39b00cdb9b5283b68db9d62542523979ae65da68b43f607b678bae5", + "image_repository_url": "https://hub.docker.com/_/nextcloud", + "readme_pushed_at": "2026-08-27T00:00:00Z", + "compose_sha256": "efbfd48ff39b00cdb9b5283b68db9d62542523979ae65da68b43f607b678bae5", + "generated_at": "2026-09-12T15:37:08+00:00" + }, + "container_contract": { + "service_name": "application", + "container_name": "application", + "image": { + "reference": "nextcloud:latest", + "registry": "docker.io", + "repository": "nextcloud", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "POSTGRES_HOST", + "example": "database", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_DB", + "example": "nextcloud", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_USER", + "example": "nextcloud", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_PASSWORD", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "REDIS_HOST", + "example": "cache", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTCLOUD_ADMIN_USER", + "example": "admin", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTCLOUD_ADMIN_PASSWORD", + "example": "${GENERATED_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "NEXTCLOUD_INIT_HTACCESS", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/www/html", + "compose_source_example": "nextcloud-html", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "database", + "image": "postgres:latest" + }, + { + "name": "cache", + "image": "redis:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: nextcloud-stack\nservices:\n application:\n image: nextcloud:latest\n depends_on:\n database:\n condition: service_healthy\n cache:\n condition: service_healthy\n environment:\n POSTGRES_HOST: database\n POSTGRES_DB: nextcloud\n POSTGRES_USER: nextcloud\n POSTGRES_PASSWORD: ${GENERATED_DB_PASSWORD}\n REDIS_HOST: cache\n NEXTCLOUD_ADMIN_USER: admin\n NEXTCLOUD_ADMIN_PASSWORD: ${GENERATED_ADMIN_PASSWORD}\n NEXTCLOUD_INIT_HTACCESS: 'true'\n ports:\n - 80:80\n volumes:\n - nextcloud-html:/var/www/html\n restart: unless-stopped\n database:\n image: postgres:latest\n command:\n - postgres\n - -c\n - listen_addresses=0.0.0.0\n environment:\n POSTGRES_DB: nextcloud\n POSTGRES_USER: nextcloud\n POSTGRES_PASSWORD: ${GENERATED_DB_PASSWORD}\n POSTGRES_INITDB_ARGS: --data-checksums\n PGDATA: /var/lib/postgresql/data/pgdata\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U nextcloud -d nextcloud\n interval: 5s\n timeout: 5s\n retries: 30\n volumes:\n - postgres-data:/var/lib/postgresql/data\n restart: unless-stopped\n cache:\n image: redis:latest\n command: redis-server\n healthcheck:\n test:\n - CMD\n - redis-cli\n - ping\n interval: 5s\n timeout: 5s\n retries: 30\n restart: unless-stopped\nvolumes:\n nextcloud-html: {}\n postgres-data: {}\n" + }, + "compose_stack": { + "project_name": "nextcloud-stack", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "application", + "service_count": 3, + "services": [ + { + "name": "cache", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "redis:latest", + "command": "redis-server", + "healthcheck": { + "test": [ + "CMD", + "redis-cli", + "ping" + ], + "interval": "5s", + "timeout": "5s", + "retries": 30 + }, + "restart": "unless-stopped" + } + }, + { + "name": "database", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:latest", + "command": [ + "postgres", + "-c", + "listen_addresses=0.0.0.0" + ], + "environment": { + "POSTGRES_DB": "nextcloud", + "POSTGRES_USER": "nextcloud", + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}", + "POSTGRES_INITDB_ARGS": "--data-checksums", + "PGDATA": "/var/lib/postgresql/data/pgdata" + }, + "healthcheck": { + "test": [ + "CMD-SHELL", + "pg_isready -U nextcloud -d nextcloud" + ], + "interval": "5s", + "timeout": "5s", + "retries": 30 + }, + "volumes": [ + "postgres-data:/var/lib/postgresql" + ], + "restart": "unless-stopped" + } + }, + { + "name": "application", + "image": "nextcloud:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "cache", + "database" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "nextcloud:latest", + "depends_on": { + "database": { + "condition": "service_healthy" + }, + "cache": { + "condition": "service_healthy" + } + }, + "environment": { + "POSTGRES_HOST": "database", + "POSTGRES_DB": "nextcloud", + "POSTGRES_USER": "nextcloud", + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}", + "REDIS_HOST": "cache", + "NEXTCLOUD_ADMIN_USER": "admin", + "NEXTCLOUD_ADMIN_PASSWORD": "${GENERATED_ADMIN_PASSWORD}", + "NEXTCLOUD_INIT_HTACCESS": "true" + }, + "ports": [ + "80:80" + ], + "volumes": [ + "nextcloud-html:/var/www/html" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "nextcloud-stack", + "volumes": { + "nextcloud-html": {}, + "postgres-data": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "application-volume-0", + "service": "application", + "container_path": "/var/www/html", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "database-volume-0", + "service": "database", + "container_path": "/var/lib/postgresql", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "cache", + "database", + "application" + ], + "stop_order": [ + "application", + "database", + "cache" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-all-new-lxc-and-new-managed-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "application", + "environment_variable": "NEXTCLOUD_ADMIN_PASSWORD" + } + ] + }, + { + "id": "db-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "application", + "environment_variable": "POSTGRES_PASSWORD" + }, + { + "service": "database", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [ + { + "label": "Generated administrator login", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "proxmenux-installer-generated", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "postgres-declared-volume-persistence", + "upstream_behavior": "Current PostgreSQL latest images declare /var/lib/postgresql as their persistent volume.", + "native_lxc_behavior": "The managed backup-enabled volume covers /var/lib/postgresql; explicit PGDATA remains /var/lib/postgresql/data/pgdata.", + "reason": "Image replacement must not discard declared persistence.", + "behavioral_impact": "Existing child-path volumes need a reviewed migration; update never moves their data implicitly.", + "validation": "clean-install-passed-20260916" + }, + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "A reviewed three-LXC orchestrator translates every required service option into native Proxmox OCI LXC configuration.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "One catalog action installs the complete application stack.", + "validation": "passed-in-historical-laboratory-profile" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "private-service-network", + "upstream_behavior": "Compose DNS connects the application to PostgreSQL and Redis by service name.", + "native_lxc_behavior": "Three LXC containers use automatic private addresses and matching service aliases.", + "reason": "Native OCI services run in separate LXC network namespaces.", + "behavioral_impact": "Database and cache remain inaccessible from the frontend network.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "managed-application-and-database-volumes", + "upstream_behavior": "Named Docker volumes persist /var/www/html and PostgreSQL data.", + "native_lxc_behavior": "Proxmox-managed mpN volumes preserve the same paths with backup=1.", + "reason": "Private application and database state belongs in native Proxmox backups.", + "behavioral_impact": "No shared host directory is created for Nextcloud user data.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "ordered-healthchecked-startup", + "upstream_behavior": "Compose dependency health controls application startup.", + "native_lxc_behavior": "The stack orchestrator starts PostgreSQL, Redis and Nextcloud in health-checked order.", + "reason": "Proxmox does not provide Compose depends_on semantics across LXC containers.", + "behavioral_impact": "One user action still installs and controls the complete application.", + "validation": "passed-in-laboratory-profile-2026-08-27" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "minimum_host_memory_mb": 4096, + "recommended_host_memory_mb": 6144, + "database_storage": { + "must_be_local": true, + "network_filesystem_allowed": false + } + }, + "defaults": { + "stack_name": "nextcloud", + "timezone": "Europe/Madrid", + "rootfs_storage": "local-lvm", + "application_storage": "local-lvm", + "database_storage": "local-lvm", + "shared_application_root": "/mnt/oci-shared/nextcloud/${stack_name}", + "application_volume_size_gb": 32, + "database_volume_size_gb": 8, + "frontend_network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "firewall": true, + "host_managed": true + }, + "private_network": { + "mode": "create-if-missing", + "bridge": "vmbr10", + "subnet": "10.77.0.0/24", + "host_address": "10.77.0.1/24", + "application_address": "10.77.0.20/24", + "database_address": "10.77.0.21/24", + "cache_address": "10.77.0.22/24", + "nat": false + }, + "application": { + "admin_username": "admin", + "php_memory_limit": "1G", + "php_upload_limit": "2G", + "apache_body_limit": "0" + }, + "maintenance_window_start_utc": 3, + "default_phone_region": "ES" + }, + "installer_contract": { + "deployment_kind": "nextcloud-three-lxc-stack", + "reserve_vmids_atomically": 3, + "generated_secrets": [ + "POSTGRES_PASSWORD", + "NEXTCLOUD_ADMIN_PASSWORD" + ], + "application_volume": { + "container_path": "/var/www/html", + "choices": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume" + }, + "database_volume": { + "container_path": "/var/lib/postgresql", + "mode": "managed-volume", + "backup": true, + "local_storage_required": true + }, + "start_order": [ + "database", + "cache", + "application" + ], + "stop_order": [ + "application", + "cache", + "database" + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The three-LXC architecture and LXC adaptations were validated in the laboratory. Rolling latest images are installable and require a fresh validation run." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending-current-rolling-images", + "service_health": "pending-current-rolling-images", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending", + "historical_lab_profile": "passed-2026-08-27-nextcloud-33.0.5-postgres-17.11-redis-8", + "private_dependency_network": "passed-historical-profile", + "managed_volume_persistence": "passed-historical-profile", + "ordered_restart": "passed-historical-profile", + "rolling_latest": "installable-pending-current-run" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "starts_stopped_dependencies": true, + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false, + "persistent_contract": "/etc/pve/priv/proxmenux-stack-.json", + "runtime_owner": "proxmox-ve" + } + } +} diff --git a/oci/catalog/apps/nextcloud.json b/oci/catalog/apps/nextcloud.json new file mode 100644 index 00000000..430778be --- /dev/null +++ b/oci/catalog/apps/nextcloud.json @@ -0,0 +1,257 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-nextcloud", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Nextcloud" + }, + "tagline": { + "en_US": "Nextcloud gives you access to all your files wherever you are." + }, + "description": { + "en_US": "Nextcloud gives you access to all your files wherever you are." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nextcloud-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nextcloud-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 443, + "path": "/" + }, + "website": "https://nextcloud.com/", + "documentation": "https://docs.linuxserver.io/images/docker-nextcloud/", + "repository": "https://github.com/linuxserver/docker-nextcloud", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-10", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-02-12", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2025-01-09", + "note": "Fix uploading large files. Existing users should update their nginx confs." + }, + { + "date": "2024-07-09", + "note": "Add `previous` tag for n-1 releases." + }, + { + "date": "2024-06-24", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + } + ], + "display_version": null, + "updated_at": "2025-07-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-nextcloud", + "default_branch": "master", + "revision": "d89ff1850ca1c95c26c774c01f0dd56c837e6c0b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-nextcloud/d89ff1850ca1c95c26c774c01f0dd56c837e6c0b/README.md", + "readme_pushed_at": "2026-09-10T15:04:34Z", + "compose_sha256": "96cf96e11225525dd723b7de74003614a7b5a4b4476b8909ee8c889156001c70", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "nextcloud", + "container_name": "nextcloud", + "image": { + "reference": "lscr.io/linuxserver/nextcloud:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/nextcloud", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/nextcloud/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n nextcloud:\n image: lscr.io/linuxserver/nextcloud:latest\n container_name: nextcloud\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/nextcloud/config:/config\n - /path/to/data:/data\n ports:\n - 443:443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 443, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/nginx.json b/oci/catalog/apps/nginx.json new file mode 100644 index 00000000..b557cd15 --- /dev/null +++ b/oci/catalog/apps/nginx.json @@ -0,0 +1,262 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-nginx", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Nginx" + }, + "tagline": { + "en_US": "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server." + }, + "description": { + "en_US": "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nginx-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nginx-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://nginx.org/", + "documentation": "https://docs.linuxserver.io/images/docker-nginx/", + "repository": "https://github.com/linuxserver/docker-nginx", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24 with PHP 8.5." + }, + { + "date": "2025-07-13", + "note": "Fixed auto-reload functionality." + }, + { + "date": "2025-06-16", + "note": "Rebase to Alpine 3.22 with PHP 8.4. Add [Auto Reload](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload) functionality. Drop PHP bindings for mcrypt as it is no longer maintained." + }, + { + "date": "2024-12-17", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-nginx", + "default_branch": "master", + "revision": "ce0dea21c74de4740888eeaa38403c88e4b0f43b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-nginx/ce0dea21c74de4740888eeaa38403c88e4b0f43b/README.md", + "readme_pushed_at": "2026-09-10T09:03:57Z", + "compose_sha256": "1acfc48980b29c494738da7af18e296a176ff51249145610b979223253303f87", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "nginx", + "container_name": "nginx", + "image": { + "reference": "lscr.io/linuxserver/nginx:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/nginx", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "NGINX_AUTORELOAD", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "NGINX_AUTORELOAD_WATCHLIST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/nginx/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n nginx:\n image: lscr.io/linuxserver/nginx:latest\n container_name: nginx\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - NGINX_AUTORELOAD= #optional\n - NGINX_AUTORELOAD_WATCHLIST= #optional\n volumes:\n - /path/to/nginx/config:/config\n ports:\n - 80:80\n - 443:443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/nginxproxymanager.json b/oci/catalog/apps/nginxproxymanager.json new file mode 100644 index 00000000..f673b712 --- /dev/null +++ b/oci/catalog/apps/nginxproxymanager.json @@ -0,0 +1,457 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-nginxproxymanager", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Nginx Proxy Manager" + }, + "tagline": { + "en_US": "Managing Nginx proxy hosts with a simple, powerful interface." + }, + "description": { + "en_US": "Nginx Proxy Manager is a simple, powerful tool to help you host multiple websites on a single server." + }, + "category": "web", + "category_label": "Webservers & Proxies", + "author": "Nginx Proxy Manager", + "developer": "Nginx Proxy Manager", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 81, + "path": "/" + }, + "website": "https://nginxproxymanager.com", + "documentation": null, + "repository": "https://hub.docker.com/r/jc21/nginx-proxy-manager", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "jc21", + "repository": "https://hub.docker.com/r/jc21/nginx-proxy-manager", + "revision": "cb47dd25506b3493cad77501c2383bdcde497a1ff0bd628bba7590bb8571545d", + "image_repository_url": "https://hub.docker.com/r/jc21/nginx-proxy-manager", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "cb47dd25506b3493cad77501c2383bdcde497a1ff0bd628bba7590bb8571545d", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "nginxproxymanager", + "container_name": "nginxproxymanager", + "image": { + "reference": "jc21/nginx-proxy-manager:latest", + "registry": "docker.io", + "repository": "jc21/nginx-proxy-manager", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/etc/letsencrypt", + "compose_source_example": "/DATA/AppData/$AppID/etc/letsencrypt", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 81, + "published_example": 81, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: nginxproxymanager\nservices:\n nginxproxymanager:\n image: jc21/nginx-proxy-manager:latest\n deploy:\n resources:\n reservations:\n memory: 128M\n network_mode: bridge\n ports:\n - target: 80\n published: '80'\n protocol: tcp\n - target: 443\n published: '443'\n protocol: tcp\n - target: 81\n published: '81'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n - type: bind\n source: /DATA/AppData/$AppID/etc/letsencrypt\n target: /etc/letsencrypt\n container_name: nginxproxymanager\n" + }, + "compose_stack": { + "project_name": "nginxproxymanager", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "nginxproxymanager", + "service_count": 1, + "services": [ + { + "name": "nginxproxymanager", + "image": "jc21/nginx-proxy-manager:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jc21/nginx-proxy-manager:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 80, + "published": "80", + "protocol": "tcp" + }, + { + "target": 443, + "published": "443", + "protocol": "tcp" + }, + { + "target": 81, + "published": "81", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/etc/letsencrypt", + "target": "/etc/letsencrypt" + } + ], + "container_name": "nginxproxymanager" + } + } + ], + "top_level": { + "name": "nginxproxymanager" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "nginxproxymanager-volume-0", + "service": "nginxproxymanager", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for nginxproxymanager:/data" + }, + { + "id": "nginxproxymanager-volume-1", + "service": "nginxproxymanager", + "container_path": "/etc/letsencrypt", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "nginxproxymanager" + ], + "stop_order": [ + "nginxproxymanager" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 81, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ngircd.json b/oci/catalog/apps/ngircd.json new file mode 100644 index 00000000..5874fa3a --- /dev/null +++ b/oci/catalog/apps/ngircd.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ngircd", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ngircd" + }, + "tagline": { + "en_US": "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd." + }, + "description": { + "en_US": "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ngircd-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ngircd-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6667, + "path": "/" + }, + "website": "https://ngircd.barton.de/", + "documentation": "https://docs.linuxserver.io/images/docker-ngircd/", + "repository": "https://github.com/linuxserver/docker-ngircd", + "tips": [], + "mini_changelog": [ + { + "date": "2024-10-14", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-07-12", + "note": "Rebase to Alpine 3.18." + }, + { + "date": "2023-07-01", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + } + ], + "display_version": null, + "updated_at": "2024-10-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ngircd", + "default_branch": "master", + "revision": "aa2feb02afbb86cd66155664d8a30559e4f9fb24", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ngircd/aa2feb02afbb86cd66155664d8a30559e4f9fb24/README.md", + "readme_pushed_at": "2026-07-11T15:45:47Z", + "compose_sha256": "e4c9822c9c1b5331b9625b9968cf6bfc54fae231ea544fdf20fa40b72b50753e", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "ngircd", + "container_name": "ngircd", + "image": { + "reference": "lscr.io/linuxserver/ngircd:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ngircd", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/ngircd/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 6667, + "published_example": 6667, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ngircd:\n image: lscr.io/linuxserver/ngircd:latest\n container_name: ngircd\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/ngircd/config:/config\n ports:\n - 6667:6667\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6667, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/node-red.json b/oci/catalog/apps/node-red.json new file mode 100644 index 00000000..858c8320 --- /dev/null +++ b/oci/catalog/apps/node-red.json @@ -0,0 +1,401 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-node-red", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Node-RED" + }, + "tagline": { + "en_US": "Low-code programming for event-driven applications" + }, + "description": { + "en_US": "Node-RED is a flow-based low-code development platform that enables creating automation tasks and applications by connecting various nodes. A browser-based editor, simple to use, makes it ideal for users in home automation, industrial control, or other fields to quickly build data processing flows.\n\nCore features include a low-code flow editor and robust data handling. Built on Node.js with an event-driven, non-blocking model, the platform supports real-time data collection, transformation, and visualization. A palette with over 5000 nodes allows users to construct flows via drag-and-drop. A rich text editor enables creating JavaScript functions for enhanced customization.\n\nIt stores flows in JSON format, facilitating easy import and export for sharing. A built-in library allows saving useful functions, templates, or flows for reuse, and an online flow library supports sharing top flows globally. With ease of use and efficiency at the core, the platform delivers a modern solution for diverse automation needs.\n\n**Key Features:**\n- Browser-based low-code flow editor with drag-and-drop node connections\n- Real-time data collection, transformation, and visualization\n- Event-driven, non-blocking model with Node.js\n- Palette with over 5000 nodes for extended functionality\n- Rich text editor for creating JavaScript functions\n- JSON-based flow storage for easy sharing\n- Built-in library for saving functions, templates, and flows\n- Online flow library for sharing top flows\n\n**Learn More:**\n- [Node-RED Official Website](https://nodered.org/)\n- [Node-RED GitHub](https://github.com/node-red/node-red)\n" + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "Node-RED", + "developer": "Node-RED", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 1880, + "path": "/" + }, + "website": "https://nodered.org/", + "documentation": null, + "repository": "https://hub.docker.com/r/nodered/node-red", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/nodered/node-red", + "revision": "7197d1b1debcb07a6287b7f2068d9180f9e6cb962c4aa0033d4949e8fd5a43c2", + "image_repository_url": "https://hub.docker.com/r/nodered/node-red", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "7197d1b1debcb07a6287b7f2068d9180f9e6cb962c4aa0033d4949e8fd5a43c2", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "node-red", + "container_name": "node-red", + "image": { + "reference": "nodered/node-red:latest", + "registry": "docker.io", + "repository": "nodered/node-red", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 1880, + "published_example": 1880, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: node-red\nservices:\n node-red:\n image: nodered/node-red:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: host\n ports:\n - target: 1880\n published: '1880'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n container_name: node-red\n" + }, + "compose_stack": { + "project_name": "node-red", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "node-red", + "service_count": 1, + "services": [ + { + "name": "node-red", + "image": "nodered/node-red:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "nodered/node-red:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "host", + "ports": [ + { + "target": 1880, + "published": "1880", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "container_name": "node-red" + } + } + ], + "top_level": { + "name": "node-red" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "node-red-volume-0", + "service": "node-red", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for node-red:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "node-red" + ], + "stop_order": [ + "node-red" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 1880, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/nzbfast.json b/oci/catalog/apps/nzbfast.json new file mode 100644 index 00000000..bea0a557 --- /dev/null +++ b/oci/catalog/apps/nzbfast.json @@ -0,0 +1,511 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-nzbfast", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "nzbfast" + }, + "tagline": { + "en_US": "Fast Usenet downloader with a SABnzbd-compatible API" + }, + "description": { + "en_US": "nzbfast is a speed-focused Usenet (NZB) downloader written in Rust. It is one small binary with a low memory footprint, and it saturates a fast line with a handful of connections.\n\nArticles are verified while they arrive, so most jobs finish with no separate verify pass. Repair and unpack run only when they are actually needed, and extraction starts before the last article lands.\n\nThe web dashboard on port 6790 also serves a SABnzbd-compatible API, so Sonarr, Radarr, Prowlarr and friends work with no extra glue. Add an .nzb from the dashboard, or drop one into the watch folder.\n\nFirst run: open the dashboard, add your Usenet provider under Settings, and copy the API key it shows you into your *arr apps. If you would rather pin the key yourself so it survives a reinstall, set NZBFAST_APIKEY before the first start. Leave it empty and nzbfast generates one for you." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "nzbfast", + "developer": "nzbfast", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6789, + "path": "/" + }, + "website": "https://nzbfast.github.io/nzbfast/", + "documentation": null, + "repository": "https://hub.docker.com/r/nzbfast/nzbfast", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/nzbfast/nzbfast", + "revision": "cb158c7f9453a7b84119c00f012097062a7dfc4fa94db9722acf2edd1b5fe80e", + "image_repository_url": "https://hub.docker.com/r/nzbfast/nzbfast", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "cb158c7f9453a7b84119c00f012097062a7dfc4fa94db9722acf2edd1b5fe80e", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "nzbfast", + "container_name": "nzbfast", + "image": { + "reference": "nzbfast/nzbfast:latest", + "registry": "docker.io", + "repository": "nzbfast/nzbfast", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NZBFAST_APIKEY", + "example": "${GENERATED_NZBFAST_APIKEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/watch", + "compose_source_example": "/DATA/AppData/$AppID/watch", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/DATA/Downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 6789, + "published_example": 6790, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: nzbfast\nservices:\n nzbfast:\n image: nzbfast/nzbfast:latest\n container_name: nzbfast\n network_mode: bridge\n restart: unless-stopped\n environment:\n PUID: $PUID\n PGID: $PGID\n TZ: $TZ\n NZBFAST_APIKEY: ${GENERATED_NZBFAST_APIKEY}\n ports:\n - target: 6789\n published: '6790'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/AppData/$AppID/watch\n target: /watch\n - type: bind\n source: /DATA/Downloads\n target: /downloads\n deploy:\n resources:\n reservations:\n memory: 128M\n" + }, + "compose_stack": { + "project_name": "nzbfast", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "nzbfast", + "service_count": 1, + "services": [ + { + "name": "nzbfast", + "image": "nzbfast/nzbfast:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "nzbfast/nzbfast:latest", + "container_name": "nzbfast", + "network_mode": "bridge", + "restart": "unless-stopped", + "environment": { + "PUID": "$PUID", + "PGID": "$PGID", + "TZ": "$TZ", + "NZBFAST_APIKEY": "${GENERATED_NZBFAST_APIKEY}" + }, + "ports": [ + { + "target": 6789, + "published": "6790", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/watch", + "target": "/watch" + }, + { + "type": "bind", + "source": "/DATA/Downloads", + "target": "/downloads" + } + ], + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + } + } + } + ], + "top_level": { + "name": "nzbfast" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "nzbfast-volume-0", + "service": "nzbfast", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "nzbfast-volume-1", + "service": "nzbfast", + "container_path": "/watch", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "nzbfast-volume-2", + "service": "nzbfast", + "container_path": "/downloads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for nzbfast:/downloads" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "nzbfast" + ], + "stop_order": [ + "nzbfast" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "nzbfast-apikey", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "nzbfast", + "environment_variable": "NZBFAST_APIKEY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6789, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/nzbget.json b/oci/catalog/apps/nzbget.json new file mode 100644 index 00000000..2df52639 --- /dev/null +++ b/oci/catalog/apps/nzbget.json @@ -0,0 +1,272 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-nzbget", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Nzbget" + }, + "tagline": { + "en_US": "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources." + }, + "description": { + "en_US": "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nzbget-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nzbget-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6789, + "path": "/" + }, + "website": "http://nzbget.com/", + "documentation": "https://docs.linuxserver.io/images/docker-nzbget/", + "repository": "https://github.com/linuxserver/docker-nzbget", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-06-05", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-09-01", + "note": "Add new dependency for boost filesystem." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-24", + "note": "Rebase to Alpine 3.21. Move MainDir to /config, leave default DestDir/InterDir as /downloads." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-nzbget", + "default_branch": "master", + "revision": "29c14de09f0bd9553202683b435afaed3f330f84", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-nzbget/29c14de09f0bd9553202683b435afaed3f330f84/README.md", + "readme_pushed_at": "2026-09-11T18:54:13Z", + "compose_sha256": "2a71f1374d6d446469b9710d1cc75c14fd58de2982311c4c3cabfa0c5d08580e", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "nzbget", + "container_name": "nzbget", + "image": { + "reference": "lscr.io/linuxserver/nzbget:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/nzbget", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "NZBGET_USER", + "example": "nzbget", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "NZBGET_PASS", + "example": "tegbzn6789", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/nzbget/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 6789, + "published_example": 6789, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n nzbget:\n image: lscr.io/linuxserver/nzbget:latest\n container_name: nzbget\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - NZBGET_USER=nzbget #optional\n - NZBGET_PASS=tegbzn6789 #optional\n volumes:\n - /path/to/nzbget/data:/config\n - /path/to/downloads:/downloads #optional\n ports:\n - 6789:6789\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6789, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/nzbhydra2.json b/oci/catalog/apps/nzbhydra2.json new file mode 100644 index 00000000..4189ce1c --- /dev/null +++ b/oci/catalog/apps/nzbhydra2.json @@ -0,0 +1,258 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-nzbhydra2", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Nzbhydra2" + }, + "tagline": { + "en_US": "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra." + }, + "description": { + "en_US": "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nzbhydra2-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nzbhydra2-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5076, + "path": "/" + }, + "website": "https://github.com/theotherp/nzbhydra2", + "documentation": "https://docs.linuxserver.io/images/docker-nzbhydra2/", + "repository": "https://github.com/linuxserver/docker-nzbhydra2", + "tips": [], + "mini_changelog": [ + { + "date": "2024-07-18", + "note": "Rebase to Ubuntu Noble. Remove standalone JRE ([#46](https://github.com/linuxserver/docker-nzbhydra2/pull/46))." + }, + { + "date": "2023-07-04", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + }, + { + "date": "2023-01-22", + "note": "Update release URL for arch-specific packages." + }, + { + "date": "2023-01-20", + "note": "Update dependencies for v5." + }, + { + "date": "2022-12-10", + "note": "Bump master JRE to v17. Default mapIpToHost to false." + } + ], + "display_version": null, + "updated_at": "2024-07-18" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-nzbhydra2", + "default_branch": "master", + "revision": "e8cf2bb91e6ab21d0d223994353f58a2b9fdd270", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-nzbhydra2/e8cf2bb91e6ab21d0d223994353f58a2b9fdd270/README.md", + "readme_pushed_at": "2026-09-09T23:57:43Z", + "compose_sha256": "419c9643452e70efa5f53d5ee6852e0c0dadf50db3d6fa6cfbdcf70f59e74c47", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "nzbhydra2", + "container_name": "nzbhydra2", + "image": { + "reference": "lscr.io/linuxserver/nzbhydra2:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/nzbhydra2", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/nzbhydra2/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5076, + "published_example": 5076, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n nzbhydra2:\n image: lscr.io/linuxserver/nzbhydra2:latest\n container_name: nzbhydra2\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/nzbhydra2/data:/config\n - /path/to/downloads:/downloads #optional\n ports:\n - 5076:5076\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5076, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/obsidian.json b/oci/catalog/apps/obsidian.json new file mode 100644 index 00000000..8727afea --- /dev/null +++ b/oci/catalog/apps/obsidian.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-obsidian", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Obsidian" + }, + "tagline": { + "en_US": "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption." + }, + "description": { + "en_US": "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/obsidian-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/obsidian-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://obsidian.md", + "documentation": "https://docs.linuxserver.io/images/docker-obsidian/", + "repository": "https://github.com/linuxserver/docker-obsidian", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-20", + "note": "Use Wayland ozone platform fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-21", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies add no sandbox to launcher, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-03" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-obsidian", + "default_branch": "main", + "revision": "69aec65499d3c9370d8c9399717ef51924ce0803", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-obsidian/69aec65499d3c9370d8c9399717ef51924ce0803/README.md", + "readme_pushed_at": "2026-09-06T14:25:02Z", + "compose_sha256": "50e5851791b5ff4ceee8b0dff255f3032511732633cf53abb892a571d63ffe91", + "generated_at": "2026-09-12T14:37:33+00:00" + }, + "container_contract": { + "service_name": "obsidian", + "container_name": "obsidian", + "image": { + "reference": "lscr.io/linuxserver/obsidian:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/obsidian", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n obsidian:\n image: lscr.io/linuxserver/obsidian:latest\n container_name: obsidian\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-obsidian/master/Dockerfile", + "dockerfile_sha256": "daa45670e56f10924a93621d7d419c1b4ca4e8aa14636b1f5b5b32f2a55ba500", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ollama.json b/oci/catalog/apps/ollama.json new file mode 100644 index 00000000..5d63ad36 --- /dev/null +++ b/oci/catalog/apps/ollama.json @@ -0,0 +1,463 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-ollama", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ollama" + }, + "tagline": { + "en_US": "Get up and running with large language models locally" + }, + "description": { + "en_US": "Ollama is a tool for running large language models locally, designed to help users quickly deploy and manage AI models via a simple command-line interface and server. Its intuitive Web interface and efficient design make it ideal for developers, researchers, and AI enthusiasts working on local hardware.\n\nThe tool's core features include local model execution and multi-model support. It enables running models like Llama 3, Mistral, and Gemma, with simple commands for downloading and switching models. All data processing occurs locally, ensuring privacy. Low resource usage optimizes model loading, allowing smooth operation on limited hardware.\n\nIt offers a RESTful API for application integration and supports tool calling (e.g., Llama 3.1) for complex tasks. Model management via Modelfile bundles weights and configurations for ease of use. The tool's efficiency and user control deliver a modern local AI solution.\n\n**Key Features:**\n- **Local Execution**: Run LLMs directly on your hardware without internet dependency\n- **Multiple Model Support**: Access to dozens of pre-trained models including Llama 3, Mistral, Gemma, Code Llama, and more\n- **Easy Model Management**: Simple commands to pull, run, and manage different models\n- **API Integration**: RESTful API for building applications and integrations\n- **Memory Efficient**: Optimized model loading and memory management\n- **Privacy-Focused**: All processing happens locally, ensuring data privacy\n\n**Supported Models:**\n- DeepSeek-R1 (1.5B, 7B, 8B, 14B, 32B, 70B, 671B parameters)\n- Gemma3n (2B, 4B parameters)\n- Gemma3 (1B, 4B, 12B, 27B parameters)\n- Qwen3 (0.6B, 1.7B, 4B, 8B, 14B, 30B, 32B, 235B parameters)\n- Qwen2.5vl (3B, 7B, 32B, 72B parameters)\n- Llama3.1 (8B, 70B, 405B parameters)\n- Llama3.2 (1B, 3B parameters)\n- Mistral (7B parameters)\n- And many more...\n\n**Use Cases:**\n- Local AI development and experimentation\n- Educational purposes and research\n- Building AI-powered applications\n- Code generation and assistance\n- Text generation and completion\n- Chatbots and conversational AI\n- Data analysis and insights\n\n**Learn More:**\n- [Ollama Official Website](https://ollama.com/)\n- [Ollama GitHub Repository](https://github.com/ollama/ollama)\n- [Model Library](https://ollama.com/library)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "ollama", + "developer": "ollama", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 11434, + "path": "/" + }, + "website": "https://ollama.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/ollama/ollama", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/ollama/ollama", + "revision": "539c2f5b08875fd9d1fa9e9c490379abded23be7bb651a69a6db67e610a0e7a9", + "image_repository_url": "https://hub.docker.com/r/ollama/ollama", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "539c2f5b08875fd9d1fa9e9c490379abded23be7bb651a69a6db67e610a0e7a9", + "generated_at": "2026-09-13T20:38:06+00:00" + }, + "container_contract": { + "service_name": "ollama", + "container_name": "ollama", + "image": { + "reference": "ollama/ollama:latest", + "registry": "docker.io", + "repository": "ollama/ollama", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/root/.ollama", + "compose_source_example": "/DATA/AppData/$AppID/", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 11434, + "published_example": 11434, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: ollama\nservices:\n ollama:\n image: ollama/ollama:latest\n container_name: ollama\n deploy:\n resources:\n limits:\n memory: 4G\n reservations:\n memory: 2G\n restart: unless-stopped\n ports:\n - target: 11434\n published: '11434'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/\n target: /root/.ollama\n" + }, + "compose_stack": { + "project_name": "ollama", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "ollama", + "service_count": 1, + "services": [ + { + "name": "ollama", + "image": "ollama/ollama:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ollama/ollama:latest", + "container_name": "ollama", + "deploy": { + "resources": { + "limits": { + "memory": "4G" + }, + "reservations": { + "memory": "2G" + } + } + }, + "restart": "unless-stopped", + "ports": [ + { + "target": 11434, + "published": "11434", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/", + "target": "/root/.ollama" + } + ] + } + } + ], + "top_level": { + "name": "ollama" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "ollama-volume-0", + "service": "ollama", + "container_path": "/root/.ollama", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "ollama" + ], + "stop_order": [ + "ollama" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 11434, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Acceleration for Ollama", + "default": "cpu", + "profiles": [ + { + "id": "cpu", + "label": "CPU", + "device_requests": [] + }, + { + "id": "nvidia", + "label": "NVIDIA (CUDA)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ] + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ombi.json b/oci/catalog/apps/ombi.json new file mode 100644 index 00000000..5e00044c --- /dev/null +++ b/oci/catalog/apps/ombi.json @@ -0,0 +1,248 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ombi", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ombi" + }, + "tagline": { + "en_US": "Ombi allows you to host your own Plex Request and user management system." + }, + "description": { + "en_US": "Ombi allows you to host your own Plex Request and user management system." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ombi-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ombi-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3579, + "path": "/" + }, + "website": "https://ombi.io", + "documentation": "https://docs.linuxserver.io/images/docker-ombi/", + "repository": "https://github.com/linuxserver/docker-ombi", + "tips": [], + "mini_changelog": [ + { + "date": "2024-07-08", + "note": "Rebase to Ubuntu Noble." + }, + { + "date": "2023-07-01", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + }, + { + "date": "2022-09-11", + "note": "Migrate to s6v3." + }, + { + "date": "2022-05-01", + "note": "Rebase to Jammy." + }, + { + "date": "2021-04-26", + "note": "Update tarball name, allow for v4 builds in stable." + } + ], + "display_version": null, + "updated_at": "2024-07-08" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ombi", + "default_branch": "master", + "revision": "96066cb952cd76edce1b701ef19f35486a472ae2", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ombi/96066cb952cd76edce1b701ef19f35486a472ae2/README.md", + "readme_pushed_at": "2026-09-05T23:58:09Z", + "compose_sha256": "0ec8d7cb794b2f8499f4c26496c081e11fcc0face869cce7ce5484aa38eedc02", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "ombi", + "container_name": "ombi", + "image": { + "reference": "lscr.io/linuxserver/ombi:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ombi", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "BASE_URL", + "example": "/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/ombi/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3579, + "published_example": 3579, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ombi:\n image: lscr.io/linuxserver/ombi:latest\n container_name: ombi\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - BASE_URL=/ #optional\n volumes:\n - /path/to/ombi/config:/config\n ports:\n - 3579:3579\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3579, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/onlyoffice.json b/oci/catalog/apps/onlyoffice.json new file mode 100644 index 00000000..486b920a --- /dev/null +++ b/oci/catalog/apps/onlyoffice.json @@ -0,0 +1,264 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-onlyoffice", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Onlyoffice" + }, + "tagline": { + "en_US": "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms." + }, + "description": { + "en_US": "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms." + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/onlyoffice-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/onlyoffice-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.onlyoffice.com/", + "documentation": "https://docs.linuxserver.io/images/docker-onlyoffice/", + "repository": "https://github.com/linuxserver/docker-onlyoffice", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-08", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-onlyoffice", + "default_branch": "master", + "revision": "eb36416039912762044b889cf09c84756b39e68b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-onlyoffice/eb36416039912762044b889cf09c84756b39e68b/README.md", + "readme_pushed_at": "2026-09-11T11:35:22Z", + "compose_sha256": "505bf6eee2575c1d85165e53d50f76ef552002a643418d57630f80128b9a5b1b", + "generated_at": "2026-09-12T14:37:32+00:00" + }, + "container_contract": { + "service_name": "onlyoffice", + "container_name": "onlyoffice", + "image": { + "reference": "lscr.io/linuxserver/onlyoffice:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/onlyoffice", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n onlyoffice:\n image: lscr.io/linuxserver/onlyoffice:latest\n container_name: onlyoffice\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/open-webui-cuda.json b/oci/catalog/apps/open-webui-cuda.json new file mode 100644 index 00000000..63fb234d --- /dev/null +++ b/oci/catalog/apps/open-webui-cuda.json @@ -0,0 +1,468 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-open-webui-cuda", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Open WebUI CUDA" + }, + "tagline": { + "en_US": "User-friendly WebUI for LLMs (Formerly Ollama WebUI)" + }, + "description": { + "en_US": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Tim J. Baek", + "developer": "Tim J. Baek", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://openwebui.com", + "documentation": null, + "repository": "https://ghcr.io/open-webui/open-webui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "open-webui", + "repository": "https://ghcr.io/open-webui/open-webui", + "revision": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "image_repository_url": "https://ghcr.io/open-webui/open-webui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "open-webui-ollama", + "container_name": "open-webui-ollama", + "image": { + "reference": "ghcr.io/open-webui/open-webui:cuda", + "registry": "ghcr.io", + "repository": "ghcr.io/open-webui/open-webui", + "tag": "cuda", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/backend/data", + "compose_source_example": "/DATA/AppData/open-webui-ollama/open-webui", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 3050, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: open-webui-ollama\nservices:\n open-webui-ollama:\n image: ghcr.io/open-webui/open-webui:latest\n runtime: nvidia\n ipc: host\n environment:\n CPU_FALLBACK: 'true'\n NVIDIA_VISIBLE_DEVICES: all\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 8080\n published: '3050'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/open-webui-ollama/open-webui\n target: /app/backend/data\n - type: bind\n source: /DATA/AppData/open-webui-ollama/ollama\n target: /root/.ollama\n privileged: false\n container_name: open-webui-ollama\n" + }, + "compose_stack": { + "project_name": "open-webui-ollama", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "open-webui-ollama", + "service_count": 1, + "services": [ + { + "name": "open-webui-ollama", + "image": "ghcr.io/open-webui/open-webui:cuda", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/open-webui/open-webui:latest", + "runtime": "nvidia", + "ipc": "host", + "environment": { + "CPU_FALLBACK": "true", + "NVIDIA_VISIBLE_DEVICES": "all" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8080, + "published": "3050", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/open-webui", + "target": "/app/backend/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/ollama", + "target": "/root/.ollama" + } + ], + "privileged": false, + "container_name": "open-webui-ollama" + } + } + ], + "top_level": { + "name": "open-webui-ollama" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "open-webui-ollama-volume-0", + "service": "open-webui-ollama", + "container_path": "/app/backend/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "open-webui-ollama-volume-1", + "service": "open-webui-ollama", + "container_path": "/root/.ollama", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "open-webui-ollama" + ], + "stop_order": [ + "open-webui-ollama" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-ipc-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 64, + "size_prompt": "Shared memory size for the GPU workload in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ], + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose", + "enable_prompt": "Enable the NVIDIA GPU required by Open WebUI CUDA", + "enabled_default": true, + "required_by_compose": true, + "required_for_runtime": true + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "pending-per-application" + } + ], + "deployment_profile": { + "variant": "cuda", + "gpu_passthrough": "required-nvidia" + }, + "catalog": { + "replaces_discovered_ids": [] + }, + "image_variant": { + "rolling_tag": "cuda", + "functional_variant": true, + "preserve_tag": true + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/open-webui-ollama.json b/oci/catalog/apps/open-webui-ollama.json new file mode 100644 index 00000000..30674282 --- /dev/null +++ b/oci/catalog/apps/open-webui-ollama.json @@ -0,0 +1,469 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-open-webui-ollama", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Open WebUI + Ollama" + }, + "tagline": { + "en_US": "User-friendly WebUI for LLMs (Formerly Ollama WebUI)" + }, + "description": { + "en_US": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Tim J. Baek", + "developer": "Tim J. Baek", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://openwebui.com", + "documentation": null, + "repository": "https://ghcr.io/open-webui/open-webui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "open-webui", + "repository": "https://ghcr.io/open-webui/open-webui", + "revision": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "image_repository_url": "https://ghcr.io/open-webui/open-webui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "open-webui-ollama", + "container_name": "open-webui-ollama", + "image": { + "reference": "ghcr.io/open-webui/open-webui:ollama", + "registry": "ghcr.io", + "repository": "ghcr.io/open-webui/open-webui", + "tag": "ollama", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/backend/data", + "compose_source_example": "/DATA/AppData/open-webui-ollama/open-webui", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/root/.ollama", + "compose_source_example": "/DATA/AppData/open-webui-ollama/ollama", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 3050, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: open-webui-ollama\nservices:\n open-webui-ollama:\n image: ghcr.io/open-webui/open-webui:latest\n runtime: nvidia\n ipc: host\n environment:\n CPU_FALLBACK: 'true'\n NVIDIA_VISIBLE_DEVICES: all\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 8080\n published: '3050'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/open-webui-ollama/open-webui\n target: /app/backend/data\n - type: bind\n source: /DATA/AppData/open-webui-ollama/ollama\n target: /root/.ollama\n privileged: false\n container_name: open-webui-ollama\n" + }, + "compose_stack": { + "project_name": "open-webui-ollama", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "open-webui-ollama", + "service_count": 1, + "services": [ + { + "name": "open-webui-ollama", + "image": "ghcr.io/open-webui/open-webui:ollama", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/open-webui/open-webui:latest", + "runtime": "nvidia", + "ipc": "host", + "environment": { + "CPU_FALLBACK": "true", + "NVIDIA_VISIBLE_DEVICES": "all" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8080, + "published": "3050", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/open-webui", + "target": "/app/backend/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/ollama", + "target": "/root/.ollama" + } + ], + "privileged": false, + "container_name": "open-webui-ollama" + } + } + ], + "top_level": { + "name": "open-webui-ollama" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "open-webui-ollama-volume-0", + "service": "open-webui-ollama", + "container_path": "/app/backend/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "open-webui-ollama-volume-1", + "service": "open-webui-ollama", + "container_path": "/root/.ollama", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "open-webui-ollama" + ], + "stop_order": [ + "open-webui-ollama" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-ipc-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 64, + "size_prompt": "Shared memory size for the GPU workload in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "pending-per-application" + } + ], + "deployment_profile": { + "variant": "ollama", + "gpu_passthrough": "not-required" + }, + "catalog": { + "replaces_discovered_ids": [ + "open-webui-ollama" + ] + }, + "image_variant": { + "rolling_tag": "ollama", + "functional_variant": true, + "preserve_tag": true + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/open-webui.json b/oci/catalog/apps/open-webui.json new file mode 100644 index 00000000..c7f93099 --- /dev/null +++ b/oci/catalog/apps/open-webui.json @@ -0,0 +1,451 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-open-webui", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Open WebUI" + }, + "tagline": { + "en_US": "User-friendly WebUI for LLMs (Formerly Ollama WebUI)" + }, + "description": { + "en_US": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Tim J. Baek", + "developer": "Tim J. Baek", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://openwebui.com", + "documentation": null, + "repository": "https://ghcr.io/open-webui/open-webui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "open-webui", + "repository": "https://ghcr.io/open-webui/open-webui", + "revision": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "image_repository_url": "https://ghcr.io/open-webui/open-webui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "open-webui-ollama", + "container_name": "open-webui-ollama", + "image": { + "reference": "ghcr.io/open-webui/open-webui:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/open-webui/open-webui", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/backend/data", + "compose_source_example": "/DATA/AppData/open-webui-ollama/open-webui", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 3050, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: open-webui-ollama\nservices:\n open-webui-ollama:\n image: ghcr.io/open-webui/open-webui:latest\n runtime: nvidia\n ipc: host\n environment:\n CPU_FALLBACK: 'true'\n NVIDIA_VISIBLE_DEVICES: all\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 8080\n published: '3050'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/open-webui-ollama/open-webui\n target: /app/backend/data\n - type: bind\n source: /DATA/AppData/open-webui-ollama/ollama\n target: /root/.ollama\n privileged: false\n container_name: open-webui-ollama\n" + }, + "compose_stack": { + "project_name": "open-webui-ollama", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "open-webui-ollama", + "service_count": 1, + "services": [ + { + "name": "open-webui-ollama", + "image": "ghcr.io/open-webui/open-webui:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/open-webui/open-webui:latest", + "runtime": "nvidia", + "ipc": "host", + "environment": { + "CPU_FALLBACK": "true", + "NVIDIA_VISIBLE_DEVICES": "all" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8080, + "published": "3050", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/open-webui", + "target": "/app/backend/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/ollama", + "target": "/root/.ollama" + } + ], + "privileged": false, + "container_name": "open-webui-ollama" + } + } + ], + "top_level": { + "name": "open-webui-ollama" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "open-webui-ollama-volume-0", + "service": "open-webui-ollama", + "container_path": "/app/backend/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "open-webui-ollama-volume-1", + "service": "open-webui-ollama", + "container_path": "/root/.ollama", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "open-webui-ollama" + ], + "stop_order": [ + "open-webui-ollama" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-ipc-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 64, + "size_prompt": "Shared memory size for the GPU workload in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "pending-per-application" + } + ], + "deployment_profile": { + "variant": "latest", + "gpu_passthrough": "not-required" + }, + "catalog": { + "replaces_discovered_ids": [] + }, + "image_variant": { + "rolling_tag": "latest", + "functional_variant": false, + "preserve_tag": false + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/openclaw.json b/oci/catalog/apps/openclaw.json new file mode 100644 index 00000000..9ce75483 --- /dev/null +++ b/oci/catalog/apps/openclaw.json @@ -0,0 +1,502 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-openclaw", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "OpenClaw" + }, + "tagline": { + "en_US": "OpenClaw is a personal AI assistant you run on your own devices" + }, + "description": { + "en_US": "OpenClaw is an open-source personal AI assistant designed to extend the capabilities of large language models (LLMs) into intelligent agents that actively execute tasks, interact across multiple platforms, and operate continuously. It supports 24/7 operation on the user's own device or server and provides intelligent automation services through common communication tools. OpenClaw connects AI to existing chat channels (such as WhatsApp, Telegram, Discord, etc.) via a locally running \"gateway + agent\" architecture, enabling it not only to answer questions but also to proactively perform actions, manage schedules, process emails, automate workflows, and more.\n\n**Key Features**:\n\n- Multi-channel Communication Integration: Interact directly with AI through common communication platforms like WhatsApp, Telegram, Slack, Discord, Signal, iMessage, Microsoft Teams, etc., without the need for additional applications.\n\n- Continuous Online & Long-term Memory: OpenClaw can run 24/7, possessing persistent memory and context retention capabilities, allowing it to remember preferences, historical conversations, and provide personalized services.\n\n- Real Action Execution: Beyond text replies, it can perform system tasks (e.g., clear inbox, send emails, fill forms, schedule appointments, browse web, control browser, etc.).\n\n- Skill Expansion & Automated Workflows: Supports community plugins, extended skills, and custom automation scripts, enabling the AI to execute complex tasks in various scenarios.\n\n**Learn More:**\n\n- [Official Website](https://openclaw.ai)\n\n- [Official Documentation](https://docs.openclaw.ai/)\n\n- [OpenClaw GitHub Repository](https://github.com/openclaw/openclaw)\n\n- [Configure Guide](https://www.self-hosted serverspace.com/docs/self-hosted server/How-to-Deploy-OpenClaw)" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "openclaw", + "developer": "openclaw", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 18789, + "path": "/" + }, + "website": "https://openclaw.ai", + "documentation": null, + "repository": "https://hub.docker.com/r/icewhaletech/openclaw", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "icewhaletech", + "repository": "https://hub.docker.com/r/icewhaletech/openclaw", + "revision": "4b24c5c9b7a3638c469f99b099e12ffd356a63a6616fc7831358e8f8a7c017b6", + "image_repository_url": "https://hub.docker.com/r/icewhaletech/openclaw", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "4b24c5c9b7a3638c469f99b099e12ffd356a63a6616fc7831358e8f8a7c017b6", + "generated_at": "2026-09-13T17:20:21+00:00" + }, + "container_contract": { + "service_name": "openclaw", + "container_name": "openclaw", + "image": { + "reference": "icewhaletech/openclaw:latest", + "registry": "docker.io", + "repository": "icewhaletech/openclaw", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "HOME", + "example": "/home/node", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TERM", + "example": "xterm-256color", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "OPENCLAW_GATEWAY_TOKEN", + "example": "${GENERATED_OPENCLAW_GATEWAY_TOKEN}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/home/node/.openclaw", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 18789, + "published_example": 24190, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 18790, + "published_example": 18790, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n openclaw:\n image: icewhaletech/openclaw:latest\n environment:\n HOME: /home/node\n TERM: xterm-256color\n OPENCLAW_GATEWAY_TOKEN: ${GENERATED_OPENCLAW_GATEWAY_TOKEN}\n network_mode: bridge\n deploy:\n resources:\n reservations:\n memory: 1G\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /home/node/.openclaw\n ports:\n - target: 18789\n published: '24190'\n protocol: tcp\n - target: 18790\n published: '18790'\n protocol: tcp\n init: true\n restart: unless-stopped\n privileged: true\n command:\n - /bin/bash\n - -c\n - /app/start.sh && node dist/index.js gateway --bind lan --allow-unconfigured\n --port '18789'\n container_name: openclaw\nname: openclaw\n" + }, + "compose_stack": { + "project_name": "openclaw", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "openclaw", + "service_count": 1, + "services": [ + { + "name": "openclaw", + "image": "icewhaletech/openclaw:2026.5.7", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "icewhaletech/openclaw:2026.5.7", + "environment": { + "HOME": "/home/node", + "TERM": "xterm-256color", + "OPENCLAW_GATEWAY_TOKEN": "${GENERATED_OPENCLAW_GATEWAY_TOKEN}" + }, + "network_mode": "bridge", + "deploy": { + "resources": { + "reservations": { + "memory": "1G" + } + } + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/home/node/.openclaw" + } + ], + "ports": [ + { + "target": 18789, + "published": "24190", + "protocol": "tcp" + }, + { + "target": 18790, + "published": "18790", + "protocol": "tcp" + } + ], + "init": true, + "restart": "unless-stopped", + "privileged": true, + "command": [ + "/bin/bash", + "-c", + "/app/start.sh && node dist/index.js gateway --bind lan --allow-unconfigured --port '18789'" + ], + "container_name": "openclaw" + } + } + ], + "top_level": { + "name": "openclaw" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "openclaw-volume-0", + "service": "openclaw", + "container_path": "/home/node/.openclaw", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "openclaw" + ], + "stop_order": [ + "openclaw" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "openclaw-gateway-token", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "openclaw", + "environment_variable": "OPENCLAW_GATEWAY_TOKEN" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 18789, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "/bin/bash", + "-c", + "/app/start.sh && node dist/index.js gateway --bind lan --allow-unconfigured --port '18789'" + ] + }, + "network": { + "compose_mode": "bridge" + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": false, + "warning": "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "optional-explicit-user-consent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/openhab.json b/oci/catalog/apps/openhab.json new file mode 100644 index 00000000..aa869c80 --- /dev/null +++ b/oci/catalog/apps/openhab.json @@ -0,0 +1,543 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-openhab", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "OpenHAB" + }, + "tagline": { + "en_US": "Empowering the smart home" + }, + "description": { + "en_US": "The open Home Automation Bus (openHAB, pronounced \u02c8\u0259\u028ap\u0259n\u02c8h\u00e6b) is an open source, technology agnostic home automation platform which runs as the center of your smart home! Its ability to integrate a multitude of other devices and systems. openHAB includes other home automation systems, (smart) devices and other technologies into a single solution. To provide a uniform user interface and a common approach to automation rules across the entire system, regardless of the number of manufacturers and sub-systems involved. Giving you the most flexible tool available to make almost any home automation wish come true; if you can think it, odds are that you can implement it with openHAB." + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "openHAB", + "developer": "openHAB", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://www.openhab.org", + "documentation": null, + "repository": "https://hub.docker.com/r/openhab/openhab", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/openhab/openhab", + "revision": "96e59ebc1f125a0c992de2885f43a198d7cea76c4e3c393bbc091847d5675a5b", + "image_repository_url": "https://hub.docker.com/r/openhab/openhab", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "96e59ebc1f125a0c992de2885f43a198d7cea76c4e3c393bbc091847d5675a5b", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "openhab", + "container_name": "openhab", + "image": { + "reference": "openhab/openhab:latest", + "registry": "docker.io", + "repository": "openhab/openhab", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "CRYPTO_POLICY", + "example": "unlimited", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/etc/localtime", + "compose_source_example": "/etc/localtime", + "read_only": true, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/etc/timezone", + "compose_source_example": "/etc/timezone", + "read_only": true, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/openhab/addons", + "compose_source_example": "/DATA/AppData/$AppID/addons", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/openhab/conf", + "compose_source_example": "/DATA/AppData/$AppID/conf", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-4", + "container_path": "/openhab/userdata", + "compose_source_example": "/DATA/AppData/$AppID/userdata", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: openhab\nservices:\n openhab:\n environment:\n CRYPTO_POLICY: unlimited\n PGID: $PGID\n PUID: $PUID\n image: openhab/openhab:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: host\n restart: unless-stopped\n volumes:\n - type: bind\n source: /etc/localtime\n target: /etc/localtime\n read_only: true\n - type: bind\n source: /etc/timezone\n target: /etc/timezone\n read_only: true\n - type: bind\n source: /DATA/AppData/$AppID/addons\n target: /openhab/addons\n - type: bind\n source: /DATA/AppData/$AppID/conf\n target: /openhab/conf\n - type: bind\n source: /DATA/AppData/$AppID/userdata\n target: /openhab/userdata\n container_name: openhab\n" + }, + "compose_stack": { + "project_name": "openhab", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "openhab", + "service_count": 1, + "services": [ + { + "name": "openhab", + "image": "openhab/openhab:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "CRYPTO_POLICY": "unlimited", + "PGID": "$PGID", + "PUID": "$PUID" + }, + "image": "openhab/openhab:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "host", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/etc/localtime", + "target": "/etc/localtime", + "read_only": true + }, + { + "type": "bind", + "source": "/etc/timezone", + "target": "/etc/timezone", + "read_only": true + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/addons", + "target": "/openhab/addons" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/conf", + "target": "/openhab/conf" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/userdata", + "target": "/openhab/userdata" + } + ], + "container_name": "openhab" + } + } + ], + "top_level": { + "name": "openhab" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "openhab-volume-0", + "service": "openhab", + "container_path": "/etc/localtime", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/localtime", + "source_path_prompt": null + }, + { + "id": "openhab-volume-1", + "service": "openhab", + "container_path": "/etc/timezone", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/timezone", + "source_path_prompt": null + }, + { + "id": "openhab-volume-2", + "service": "openhab", + "container_path": "/openhab/addons", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "openhab-volume-3", + "service": "openhab", + "container_path": "/openhab/conf", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "openhab-volume-4", + "service": "openhab", + "container_path": "/openhab/userdata", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "openhab" + ], + "stop_order": [ + "openhab" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/openhands.json b/oci/catalog/apps/openhands.json new file mode 100644 index 00000000..a731ad6f --- /dev/null +++ b/oci/catalog/apps/openhands.json @@ -0,0 +1,471 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-openhands", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "OpenHands" + }, + "tagline": { + "en_US": "Open-source AI-powered coding assistant" + }, + "description": { + "en_US": "OpenHands is an open-source AI-powered coding assistant that provides developers with intelligent code completion, generation, and debugging capabilities. It runs in a sandboxed environment to ensure security and isolation while allowing access to various development tools and resources.\n\n**Key Features:**\n- AI-powered code completion and generation\n- Interactive debugging and error resolution\n- Support for multiple programming languages\n- Secure sandboxed execution environment\n- Customizable runtime configurations\n- Integration with Docker for containerized workflows\n\n**Learn More:**\n- [OpenHands Official Website](https://www.all-hands.dev)\n- [OpenHands GitHub Repository](https://github.com/All-Hands-AI/OpenHands)\n- [Documentation](https://docs.all-hands.dev)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "All-Hands-AI", + "developer": "All-Hands-AI", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://www.openhands.dev/", + "documentation": null, + "repository": "https://ghcr.io/all-hands-ai/openhands", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "all-hands-ai", + "repository": "https://ghcr.io/all-hands-ai/openhands", + "revision": "4830bc2d4e59f1b9bb0670d9831e8d1cee381be8adf955ba992fcc2af55d4c65", + "image_repository_url": "https://ghcr.io/all-hands-ai/openhands", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "4830bc2d4e59f1b9bb0670d9831e8d1cee381be8adf955ba992fcc2af55d4c65", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "openhands", + "container_name": "openhands", + "image": { + "reference": "ghcr.io/all-hands-ai/openhands:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/all-hands-ai/openhands", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "SANDBOX_RUNTIME_CONTAINER_IMAGE", + "example": "ghcr.io/all-hands-ai/runtime:main-nikolaik", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WORKSPACE_MOUNT_PATH", + "example": "/DATA/AppData/$AppID/workspace", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/run/docker.sock", + "compose_source_example": "/var/run/docker.sock", + "read_only": false, + "required": false, + "installation_choice": [ + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/.openhands", + "compose_source_example": "/DATA/AppData/$AppID/openhands", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/opt/workspace_base", + "compose_source_example": "/DATA/AppData/$AppID/workspace", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 13333, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": null, + "stop_grace_period": null, + "original_compose": "name: openhands\nservices:\n openhands:\n image: ghcr.io/all-hands-ai/openhands:latest\n container_name: openhands\n environment:\n - SANDBOX_RUNTIME_CONTAINER_IMAGE=ghcr.io/all-hands-ai/runtime:main-nikolaik\n - WORKSPACE_MOUNT_PATH=/DATA/AppData/$AppID/workspace\n ports:\n - 13333:3000\n extra_hosts:\n - host.docker.internal:host-gateway\n volumes:\n - /var/run/docker.sock:/var/run/docker.sock\n - /DATA/AppData/$AppID/openhands:/.openhands\n - /DATA/AppData/$AppID/workspace:/opt/workspace_base\n stdin_open: true\n tty: true\n" + }, + "compose_stack": { + "project_name": "openhands", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "openhands", + "service_count": 1, + "services": [ + { + "name": "openhands", + "image": "ghcr.io/all-hands-ai/openhands:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/all-hands-ai/openhands:latest", + "container_name": "openhands", + "environment": [ + "SANDBOX_RUNTIME_CONTAINER_IMAGE=ghcr.io/all-hands-ai/runtime:main-nikolaik", + "WORKSPACE_MOUNT_PATH=/DATA/AppData/$AppID/workspace" + ], + "ports": [ + "13333:3000" + ], + "extra_hosts": [ + "host.docker.internal:host-gateway" + ], + "volumes": [ + "/var/run/docker.sock:/var/run/docker.sock", + "/DATA/AppData/$AppID/openhands:/.openhands", + "/DATA/AppData/$AppID/workspace:/opt/workspace_base" + ], + "stdin_open": true, + "tty": true + } + } + ], + "top_level": { + "name": "openhands" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "openhands-volume-0", + "service": "openhands", + "container_path": "/var/run/docker.sock", + "mode": "runtime-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "openhands-volume-1", + "service": "openhands", + "container_path": "/.openhands", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "openhands-volume-2", + "service": "openhands", + "container_path": "/opt/workspace_base", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "openhands" + ], + "stop_order": [ + "openhands" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "extra_hosts": [ + { + "hostname": "host.docker.internal", + "address": "host-gateway" + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/openlist.json b/oci/catalog/apps/openlist.json new file mode 100644 index 00000000..2b38f728 --- /dev/null +++ b/oci/catalog/apps/openlist.json @@ -0,0 +1,437 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-openlist", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "OpenList" + }, + "tagline": { + "en_US": "Mount your cloud drive on your home NAS" + }, + "description": { + "en_US": "OpenList is a community-driven, self-hosted file listing and cloud drive mounting service that supports multiple storage backends in one place.\nIt brings local storage plus services like OneDrive, Google Drive, S3, WebDAV, SMB, and many other providers into one browser-based file hub.\nWith previews, uploads, sharing, WebDAV, offline download, and package download built in, it works well for home NAS setups, personal cloud libraries, and lightweight team file portals.\n\n**Main Features:**\n- Connect local disks, cloud drives, object storage, and WebDAV or SMB endpoints in one place\n- Preview documents, images, audio, video, code, Markdown, and Office files directly in the browser\n- Upload, move, rename, copy, delete, and batch download files and folders from a single interface\n- Enable WebDAV, protected routes, sharing, dark mode, and multi-language support\n- Support offline downloads, cross-storage file copying, and multi-thread acceleration\n\n**Learn More:**\n- [OpenList Official Website](https://oplist.org/)\n- [OpenList GitHub](https://github.com/OpenListTeam/OpenList)\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "OpenListTeam", + "developer": "OpenListTeam", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5244, + "path": "/" + }, + "website": "https://oplist.org/", + "documentation": null, + "repository": "https://hub.docker.com/r/openlistteam/openlist", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/openlistteam/openlist", + "revision": "914c79f66f2c1baa7d241f94ae51729de562c6a76d9eb8da711b1905f8f1c31b", + "image_repository_url": "https://hub.docker.com/r/openlistteam/openlist", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "914c79f66f2c1baa7d241f94ae51729de562c6a76d9eb8da711b1905f8f1c31b", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "openlist", + "container_name": "openlist", + "image": { + "reference": "openlistteam/openlist:latest", + "registry": "docker.io", + "repository": "openlistteam/openlist", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "UMASK", + "example": "022", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "OPENLIST_ADMIN_PASSWORD", + "example": "${GENERATED_OPENLIST_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt/openlist/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5244, + "published_example": 5244, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: openlist\nservices:\n openlist:\n image: openlistteam/openlist:latest\n container_name: openlist\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n restart: unless-stopped\n user: 999:1000\n ports:\n - target: 5244\n published: '5244'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /opt/openlist/data\n environment:\n UMASK: '022'\n OPENLIST_ADMIN_PASSWORD: ${GENERATED_OPENLIST_ADMIN_PASSWORD}\n" + }, + "compose_stack": { + "project_name": "openlist", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "openlist", + "service_count": 1, + "services": [ + { + "name": "openlist", + "image": "openlistteam/openlist:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "openlistteam/openlist:latest", + "container_name": "openlist", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "restart": "unless-stopped", + "user": "999:1000", + "ports": [ + { + "target": 5244, + "published": "5244", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/opt/openlist/data" + } + ], + "environment": { + "UMASK": "022", + "OPENLIST_ADMIN_PASSWORD": "${GENERATED_OPENLIST_ADMIN_PASSWORD}" + } + } + } + ], + "top_level": { + "name": "openlist" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "openlist-volume-0", + "service": "openlist", + "container_path": "/opt/openlist/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "openlist" + ], + "stop_order": [ + "openlist" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "openlist-admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "openlist", + "environment_variable": "OPENLIST_ADMIN_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5244, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "user": "999:1000" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/openshot.json b/oci/catalog/apps/openshot.json new file mode 100644 index 00000000..82ed532d --- /dev/null +++ b/oci/catalog/apps/openshot.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-openshot", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Openshot" + }, + "tagline": { + "en_US": "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world." + }, + "description": { + "en_US": "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openshot-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openshot-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://openshot.org/", + "documentation": "https://docs.linuxserver.io/images/docker-openshot/", + "repository": "https://github.com/linuxserver/docker-openshot", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-07", + "note": "Rebase to Ubuntu Resolute, install from ppa." + }, + { + "date": "2026-04-03", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-29", + "note": "Rebase to selkies. Breaking Change: HTTPS is now required. Either use a reverse proxy (like SWAG) with SSL cert or direct connect to port 3001 with HTTPS." + }, + { + "date": "2024-12-23", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-08-07" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-openshot", + "default_branch": "main", + "revision": "2fa9899b0ed89c8a3f9f7a40a2d1c779f3a978f7", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-openshot/2fa9899b0ed89c8a3f9f7a40a2d1c779f3a978f7/README.md", + "readme_pushed_at": "2026-09-12T00:56:49Z", + "compose_sha256": "7acc5554bb1ae0a3418f89a2d1aa23610264f49743121bf42d80f1928e00f473", + "generated_at": "2026-09-12T14:37:33+00:00" + }, + "container_contract": { + "service_name": "openshot", + "container_name": "openshot", + "image": { + "reference": "lscr.io/linuxserver/openshot:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/openshot", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/openshot/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n openshot:\n image: lscr.io/linuxserver/openshot:latest\n container_name: openshot\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/openshot/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-openshot/master/Dockerfile", + "dockerfile_sha256": "ee94083f4d4b9ba7db68310b5e6221c9a4e994c89e430cf5a033c9edd267a091", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/openspeedtest.json b/oci/catalog/apps/openspeedtest.json new file mode 100644 index 00000000..622a99b6 --- /dev/null +++ b/oci/catalog/apps/openspeedtest.json @@ -0,0 +1,365 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-openspeedtest", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "OpenSpeedTest" + }, + "tagline": { + "en_US": "HTML5 Network Speed Test Server." + }, + "description": { + "en_US": "An application for launching HTML5 Network Speed Test Server. You can test download & upload speed from any device within your network with a web browser that is IE10 or new." + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "OpenSpeedTest", + "developer": "OpenSpeedTest", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/openspeedtest/latest", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/openspeedtest/latest", + "revision": "dc3ae0aece7c61c4136787e71fc26061ed7ec8654eaca7a5ec9eabbf9f286046", + "image_repository_url": "https://hub.docker.com/r/openspeedtest/latest", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "dc3ae0aece7c61c4136787e71fc26061ed7ec8654eaca7a5ec9eabbf9f286046", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "openspeedtest", + "container_name": "openspeedtest", + "image": { + "reference": "openspeedtest/latest:latest", + "registry": "docker.io", + "repository": "openspeedtest/latest", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [ + { + "container_port": 3000, + "published_example": 3004, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: openspeedtest\nservices:\n openspeedtest:\n image: openspeedtest/latest:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 3000\n published: '3004'\n protocol: tcp\n restart: always\n container_name: openspeedtest\n" + }, + "compose_stack": { + "project_name": "openspeedtest", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "openspeedtest", + "service_count": 1, + "services": [ + { + "name": "openspeedtest", + "image": "openspeedtest/latest:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "openspeedtest/latest:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 3000, + "published": "3004", + "protocol": "tcp" + } + ], + "restart": "always", + "container_name": "openspeedtest" + } + } + ], + "top_level": { + "name": "openspeedtest" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "openspeedtest" + ], + "stop_order": [ + "openspeedtest" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/openssh-server.json b/oci/catalog/apps/openssh-server.json new file mode 100644 index 00000000..8a0019fb --- /dev/null +++ b/oci/catalog/apps/openssh-server.json @@ -0,0 +1,390 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-openssh-server", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Openssh Server" + }, + "tagline": { + "en_US": "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server." + }, + "description": { + "en_US": "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openssh-server-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openssh-server-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 2222, + "path": "/" + }, + "website": "https://www.openssh.com/", + "documentation": "https://docs.linuxserver.io/images/docker-openssh-server/", + "repository": "https://github.com/linuxserver/docker-openssh-server", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-02-10", + "note": "Add support for sshd_config.d" + }, + { + "date": "2025-01-12", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-openssh-server", + "default_branch": "master", + "revision": "4e43b1ae9bc8cb3aba5f59ab96e4ba231f9a8455", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-openssh-server/4e43b1ae9bc8cb3aba5f59ab96e4ba231f9a8455/README.md", + "readme_pushed_at": "2026-09-06T21:01:44Z", + "compose_sha256": "d8bca8e6e562b6d563ef25a2559f7ab0c650adabd17b1c96889c23ab1e9fcf6f", + "generated_at": "2026-09-13T14:54:03+00:00" + }, + "container_contract": { + "service_name": "openssh-server", + "container_name": "openssh-server", + "image": { + "reference": "lscr.io/linuxserver/openssh-server:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/openssh-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PUBLIC_KEY", + "example": "yourpublickey", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "PUBLIC_KEY_FILE", + "example": "/path/to/file", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "PUBLIC_KEY_DIR", + "example": "/path/to/directory/containing/_only_/pubkeys", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "PUBLIC_KEY_URL", + "example": "https://github.com/username.keys", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SUDO_ACCESS", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PASSWORD_ACCESS", + "example": "false", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "USER_PASSWORD", + "example": "password", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "USER_PASSWORD_FILE", + "example": "/path/to/file", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "USER_NAME", + "example": "linuxserver.io", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOG_STDOUT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/openssh-server/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 2222, + "published_example": 2222, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n openssh-server:\n image: lscr.io/linuxserver/openssh-server:latest\n container_name: openssh-server\n hostname: openssh-server #optional\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - PUBLIC_KEY=yourpublickey #optional\n - PUBLIC_KEY_FILE=/path/to/file #optional\n - PUBLIC_KEY_DIR=/path/to/directory/containing/_only_/pubkeys #optional\n - PUBLIC_KEY_URL=https://github.com/username.keys #optional\n - SUDO_ACCESS=false #optional\n - PASSWORD_ACCESS=false #optional\n - USER_PASSWORD=password #optional\n - USER_PASSWORD_FILE=/path/to/file #optional\n - USER_NAME=linuxserver.io #optional\n - LOG_STDOUT= #optional\n volumes:\n - /path/to/openssh-server/config:/config\n ports:\n - 2222:2222\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 2222, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "hostname": "openssh-server" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending", + "authenticated_login": "passed-amd64" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/openvscode-server.json b/oci/catalog/apps/openvscode-server.json new file mode 100644 index 00000000..94d0ceb1 --- /dev/null +++ b/oci/catalog/apps/openvscode-server.json @@ -0,0 +1,269 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-openvscode-server", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Deprecation Notice" + }, + "tagline": { + "en_US": "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser." + }, + "description": { + "en_US": "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openvscode-server-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openvscode-server-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://github.com/gitpod-io/openvscode-server", + "documentation": "https://docs.linuxserver.io/images/docker-openvscode-server/", + "repository": "https://github.com/linuxserver/docker-openvscode-server", + "tips": [], + "mini_changelog": [ + { + "date": "2024-08-19", + "note": "Rebase to Ubuntu Noble." + }, + { + "date": "2023-07-01", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + }, + { + "date": "2022-09-29", + "note": "Rebase to jammy, switch to s6v3. Fix chown logic to skip `/config/workspace` contents." + }, + { + "date": "2022-02-12", + "note": "Update `install-extension` helper to compensate for upstream changes." + }, + { + "date": "2022-02-04", + "note": "Update binary for 1.64.0+. Allow for no token set when both toekn env vars are unset. Add libsecret for keytar." + } + ], + "display_version": null, + "updated_at": "2024-08-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-openvscode-server", + "default_branch": "main", + "revision": "4383ccfe489c7d63cc30af2e986655d9e4a1b2df", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-openvscode-server/4383ccfe489c7d63cc30af2e986655d9e4a1b2df/README.md", + "readme_pushed_at": "2026-07-16T16:49:20Z", + "compose_sha256": "a410ab519d8064c1808828d8f22205007477bf7eb875dc4f26f4f0d7776aa0e4", + "generated_at": "2026-09-12T14:37:33+00:00" + }, + "container_contract": { + "service_name": "openvscode-server", + "container_name": "openvscode-server", + "image": { + "reference": "lscr.io/linuxserver/openvscode-server:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/openvscode-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CONNECTION_TOKEN", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "CONNECTION_SECRET", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SUDO_PASSWORD", + "example": "password", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SUDO_PASSWORD_HASH", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/openvscode-server/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n openvscode-server:\n image: lscr.io/linuxserver/openvscode-server:latest\n container_name: openvscode-server\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - CONNECTION_TOKEN= #optional\n - CONNECTION_SECRET= #optional\n - SUDO_PASSWORD=password #optional\n - SUDO_PASSWORD_HASH= #optional\n volumes:\n - /path/to/openvscode-server/config:/config\n ports:\n - 3000:3000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/opera.json b/oci/catalog/apps/opera.json new file mode 100644 index 00000000..352d8721 --- /dev/null +++ b/oci/catalog/apps/opera.json @@ -0,0 +1,379 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-opera", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Opera" + }, + "tagline": { + "en_US": "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features." + }, + "description": { + "en_US": "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/opera-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/opera-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.opera.com/", + "documentation": "https://docs.linuxserver.io/images/docker-opera/", + "repository": "https://github.com/linuxserver/docker-opera", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-03", + "note": "Rebase to Selkies HTTPS is now required." + }, + { + "date": "2025-03-12", + "note": "Clear singletons on launch to properly support persistance." + } + ], + "display_version": null, + "updated_at": "2026-03-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-opera", + "default_branch": "master", + "revision": "81b23206ce046e95ef214debe45042b44b59d971", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-opera/81b23206ce046e95ef214debe45042b44b59d971/README.md", + "readme_pushed_at": "2026-09-11T14:55:26Z", + "compose_sha256": "e1e71fcecd5e4e22ef381191311a44b6cb15573f02d013ba22053516087f621a", + "generated_at": "2026-09-12T14:37:33+00:00" + }, + "container_contract": { + "service_name": "opera", + "container_name": "opera", + "image": { + "reference": "lscr.io/linuxserver/opera:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/opera", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "OPERA_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n opera:\n image: lscr.io/linuxserver/opera:latest\n container_name: opera\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - OPERA_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-opera/master/Dockerfile", + "dockerfile_sha256": "889ef38200d79dcadeda61535c2d06985b0f03d1d0a746704ff885ea813ffc21", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/opodsync.json b/oci/catalog/apps/opodsync.json new file mode 100644 index 00000000..c70a3ee7 --- /dev/null +++ b/oci/catalog/apps/opodsync.json @@ -0,0 +1,399 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-opodsync", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "oPodSync" + }, + "tagline": { + "en_US": "Podcast synchronization service" + }, + "description": { + "en_US": "oPodSync is a podcast synchronization service that allows users to sync their podcast subscriptions and listening progress across multiple devices. It provides a server-side solution for managing podcast data and ensures that users can seamlessly switch between their devices.\n\n**Key Features:**\n- Sync podcast subscriptions\n- Track listening progress across devices\n- Web-based management interface\n- Support for multiple podcast clients\n- Centralized data storage\n- Easy setup and configuration\n\n**Learn More:**\n- [oPodSync GitHub Repo](https://github.com/kd2org/oPodSync)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "ganeshlab", + "developer": "ganeshlab", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://fossil.kd2.org/opodsync/", + "documentation": null, + "repository": "https://hub.docker.com/r/ganeshlab/opodsync", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "ganeshlab", + "repository": "https://hub.docker.com/r/ganeshlab/opodsync", + "revision": "30fcd8bc474d69fc431e99ea83896d112614b57e30951cad28831123c32ab583", + "image_repository_url": "https://hub.docker.com/r/ganeshlab/opodsync", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "30fcd8bc474d69fc431e99ea83896d112614b57e30951cad28831123c32ab583", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "opodsync", + "container_name": "opodsync", + "image": { + "reference": "ganeshlab/opodsync:latest", + "registry": "docker.io", + "repository": "ganeshlab/opodsync", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/www/server/data", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8086, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": null, + "stop_grace_period": null, + "original_compose": "name: opodsync\nservices:\n opodsync:\n image: ganeshlab/opodsync:latest\n container_name: opodsync\n deploy:\n resources:\n reservations:\n memory: 512M\n ports:\n - target: 8080\n published: '8086'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /var/www/server/data\n" + }, + "compose_stack": { + "project_name": "opodsync", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "opodsync", + "service_count": 1, + "services": [ + { + "name": "opodsync", + "image": "ganeshlab/opodsync:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ganeshlab/opodsync:latest", + "container_name": "opodsync", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "ports": [ + { + "target": 8080, + "published": "8086", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/var/www/server/data" + } + ] + } + } + ], + "top_level": { + "name": "opodsync" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "opodsync-volume-0", + "service": "opodsync", + "container_path": "/var/www/server/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "opodsync" + ], + "stop_order": [ + "opodsync" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/orcaslicer.json b/oci/catalog/apps/orcaslicer.json new file mode 100644 index 00000000..80c0c9e4 --- /dev/null +++ b/oci/catalog/apps/orcaslicer.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-orcaslicer", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Orcaslicer" + }, + "tagline": { + "en_US": "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community" + }, + "description": { + "en_US": "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/orcaslicer-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/orcaslicer-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/SoftFever/OrcaSlicer", + "documentation": "https://docs.linuxserver.io/images/docker-orcaslicer/", + "repository": "https://github.com/linuxserver/docker-orcaslicer", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-20", + "note": "Add aarch64 platform." + }, + { + "date": "2026-05-11", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2026-04-19", + "note": "Rebase to resolute." + }, + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-01-01", + "note": "Add wayland init." + } + ], + "display_version": null, + "updated_at": "2026-06-20" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-orcaslicer", + "default_branch": "master", + "revision": "07cb2596ff2a8bd426b42c897ed630de8873949b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-orcaslicer/07cb2596ff2a8bd426b42c897ed630de8873949b/README.md", + "readme_pushed_at": "2026-09-08T17:21:08Z", + "compose_sha256": "cd52fd4e315c3dd77af2e6cbca385d123183922a2f8935af3a84b594af2720cc", + "generated_at": "2026-09-12T14:37:33+00:00" + }, + "container_contract": { + "service_name": "orcaslicer", + "container_name": "orcaslicer", + "image": { + "reference": "lscr.io/linuxserver/orcaslicer:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/orcaslicer", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n orcaslicer:\n image: lscr.io/linuxserver/orcaslicer:latest\n container_name: orcaslicer\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\" #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/oscam.json b/oci/catalog/apps/oscam.json new file mode 100644 index 00000000..d2f4a5d7 --- /dev/null +++ b/oci/catalog/apps/oscam.json @@ -0,0 +1,352 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-oscam", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Oscam" + }, + "tagline": { + "en_US": "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client." + }, + "description": { + "en_US": "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/oscam-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/oscam-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8888, + "path": "/" + }, + "website": "https://git.streamboard.tv/common/oscam", + "documentation": "https://docs.linuxserver.io/images/docker-oscam/", + "repository": "https://github.com/linuxserver/docker-oscam", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-17", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-04-28", + "note": "Disable binary signing to prevent compile errors." + }, + { + "date": "2026-01-15", + "note": "Rebase to Alpine 3.23, add support for wiki submodule." + }, + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-04-19", + "note": "Retrieve Oscam from the new git repo." + } + ], + "display_version": null, + "updated_at": "2026-07-17" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-oscam", + "default_branch": "master", + "revision": "77e4c09f6f5e8e9506c8edacc81f6ac21c3310ee", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-oscam/77e4c09f6f5e8e9506c8edacc81f6ac21c3310ee/README.md", + "readme_pushed_at": "2026-09-11T13:22:43Z", + "compose_sha256": "77335cfa0242fda5a8e966c00d04b49f0522f04263e8cbe6dff061a350d3f609", + "generated_at": "2026-09-13T15:35:45+00:00" + }, + "container_contract": { + "service_name": "oscam", + "container_name": "oscam", + "image": { + "reference": "lscr.io/linuxserver/oscam:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/oscam", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/oscam/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8888, + "published_example": 8888, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n oscam:\n image: lscr.io/linuxserver/oscam:latest\n container_name: oscam\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/oscam/data:/config\n ports:\n - 8888:8888\n devices:\n - /dev/ttyUSB0:/dev/ttyUSB0\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8888, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "dev-ttyusb0", + "kind": "character-device", + "purpose": "serial", + "enable_prompt": "Pass /dev/ttyUSB0 to the LXC", + "enabled_default": true, + "required_by_compose": true, + "path_prompt": "Host device for /dev/ttyUSB0", + "host_path_default": "/dev/ttyUSB0", + "container_path": "/dev/ttyUSB0", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/ttyUSB0:/dev/ttyUSB0" + } + ] + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/overseerr.json b/oci/catalog/apps/overseerr.json new file mode 100644 index 00000000..1a543c55 --- /dev/null +++ b/oci/catalog/apps/overseerr.json @@ -0,0 +1,420 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-overseerr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Overseerr" + }, + "tagline": { + "en_US": "Overseerr is a request management and media discovery tool built to work with your existing Plex ecosystem." + }, + "description": { + "en_US": "Overseerr is a free and open source software application for managing requests for your media library. It integrates with your existing services, such as Sonarr, Radarr, and Plex!" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": "LinuxServer.io", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5055, + "path": "/" + }, + "website": "https://overseerr.dev", + "documentation": "https://docs.linuxserver.io/images/docker-overseerr/", + "repository": "https://hub.docker.com/r/linuxserver/overseerr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://hub.docker.com/r/linuxserver/overseerr", + "revision": "0ec8c6664532c31b2f6600555451a91f2647f7e2a056912f3f5a56060fe6ac79", + "image_repository_url": "https://hub.docker.com/r/linuxserver/overseerr", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "0ec8c6664532c31b2f6600555451a91f2647f7e2a056912f3f5a56060fe6ac79", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "overseerr", + "container_name": "overseerr", + "image": { + "reference": "linuxserver/overseerr:latest", + "registry": "docker.io", + "repository": "linuxserver/overseerr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/overseerr/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 5055, + "published_example": 5055, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: overseerr\nservices:\n overseerr:\n image: linuxserver/overseerr:latest\n restart: unless-stopped\n environment:\n PUID: $PUID\n PGID: $PGID\n TZ: $TZ\n ports:\n - target: 5055\n published: 5055\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/overseerr/config\n target: /config\n container_name: overseerr\n" + }, + "compose_stack": { + "project_name": "overseerr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "overseerr", + "service_count": 1, + "services": [ + { + "name": "overseerr", + "image": "linuxserver/overseerr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "linuxserver/overseerr:latest", + "restart": "unless-stopped", + "environment": { + "PUID": "$PUID", + "PGID": "$PGID", + "TZ": "$TZ" + }, + "ports": [ + { + "target": 5055, + "published": 5055, + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/overseerr/config", + "target": "/config" + } + ], + "container_name": "overseerr" + } + } + ], + "top_level": { + "name": "overseerr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "overseerr-volume-0", + "service": "overseerr", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "overseerr" + ], + "stop_order": [ + "overseerr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5055, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pairdrop.json b/oci/catalog/apps/pairdrop.json new file mode 100644 index 00000000..6fd66032 --- /dev/null +++ b/oci/catalog/apps/pairdrop.json @@ -0,0 +1,252 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-pairdrop", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pairdrop" + }, + "tagline": { + "en_US": "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices." + }, + "description": { + "en_US": "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pairdrop-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pairdrop-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://github.com/schlagmichdoch/PairDrop", + "documentation": "https://docs.linuxserver.io/images/docker-pairdrop/", + "repository": "https://github.com/linuxserver/docker-pairdrop", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-21", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-01-31", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-05-30", + "note": "Rebase to Alpine 3.18." + } + ], + "display_version": null, + "updated_at": "2025-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-pairdrop", + "default_branch": "main", + "revision": "16987ef97bd67744dc088e0e11c9fd29f162943a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-pairdrop/16987ef97bd67744dc088e0e11c9fd29f162943a/README.md", + "readme_pushed_at": "2026-09-12T14:29:13Z", + "compose_sha256": "3c4ad606c6fd90d0e552b876a7a2decf27062b0779c68cc45725f71ab86450a1", + "generated_at": "2026-09-12T14:37:33+00:00" + }, + "container_contract": { + "service_name": "pairdrop", + "container_name": "pairdrop", + "image": { + "reference": "lscr.io/linuxserver/pairdrop:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/pairdrop", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RATE_LIMIT", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "WS_FALLBACK", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RTC_CONFIG", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEBUG_MODE", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n pairdrop:\n image: lscr.io/linuxserver/pairdrop:latest\n container_name: pairdrop\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - RATE_LIMIT=false #optional\n - WS_FALLBACK=false #optional\n - RTC_CONFIG= #optional\n - DEBUG_MODE=false #optional\n ports:\n - 3000:3000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/paperless-ngx.json b/oci/catalog/apps/paperless-ngx.json new file mode 100644 index 00000000..d379f0b0 --- /dev/null +++ b/oci/catalog/apps/paperless-ngx.json @@ -0,0 +1,669 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-paperless-ngx", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Paperless-ngx" + }, + "tagline": { + "en_US": "Searchable document archive with OCR" + }, + "description": { + "en_US": "Official Paperless-ngx deployment with private PostgreSQL and Valkey dependencies." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Paperless-ngx", + "developer": "Paperless-ngx", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://docs.paperless-ngx.com/", + "documentation": "https://docs.paperless-ngx.com/setup/", + "repository": "https://github.com/paperless-ngx/paperless-ngx", + "tips": [ + "Documents are stored unencrypted inside the media volume; protect and back up the host.", + "The consume and export folders can be Proxmox volumes or shared host directories." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-13" + }, + "source": { + "provider": "paperless-ngx", + "repository": "https://github.com/paperless-ngx/paperless-ngx", + "default_branch": "main", + "revision": "72ea38ab126e92fb63d68b7f5d0e6d9abaafe589", + "readme_raw_url": "https://raw.githubusercontent.com/paperless-ngx/paperless-ngx/main/docker/compose/docker-compose.postgres.yml", + "image_repository_url": "https://github.com/paperless-ngx/paperless-ngx/pkgs/container/paperless-ngx", + "readme_pushed_at": "2026-09-13T00:00:00Z", + "compose_sha256": "85206b8ae6cd74db70998de6479b4c1f7b50c077772a1af2c026c9ecb35b689c", + "generated_at": "2026-09-13T00:00:00+00:00" + }, + "container_contract": { + "service_name": "webserver", + "container_name": "paperless-ngx", + "image": { + "reference": "ghcr.io/paperless-ngx/paperless-ngx:latest", + "registry": "ghcr.io", + "repository": "paperless-ngx/paperless-ngx", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PAPERLESS_REDIS", + "example": "redis://broker:6379", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PAPERLESS_DBHOST", + "example": "db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PAPERLESS_DBENGINE", + "example": "postgresql", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PAPERLESS_DBNAME", + "example": "paperless", + "required": true, + "sensitive": false, + "source": "proxmenux-installer" + }, + { + "name": "PAPERLESS_DBUSER", + "example": "paperless", + "required": true, + "sensitive": false, + "source": "proxmenux-installer" + }, + { + "name": "PAPERLESS_DBPASS", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "proxmenux-installer" + }, + { + "name": "PAPERLESS_SECRET_KEY", + "example": "${GENERATED_SECRET_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose.env" + }, + { + "name": "PAPERLESS_ADMIN_USER", + "example": "admin", + "required": true, + "sensitive": false, + "source": "paperless-ngx-configuration" + }, + { + "name": "PAPERLESS_ADMIN_PASSWORD", + "example": "${GENERATED_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "paperless-ngx-configuration" + }, + { + "name": "PAPERLESS_TIME_ZONE", + "example": "Europe/Madrid", + "required": false, + "sensitive": false, + "source": "docker-compose.env" + }, + { + "name": "PAPERLESS_OCR_LANGUAGE", + "example": "spa", + "required": false, + "sensitive": false, + "source": "docker-compose.env" + } + ], + "volumes": [ + { + "id": "paperless-data", + "container_path": "/usr/src/paperless/data", + "compose_source_example": "data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "paperless-media", + "container_path": "/usr/src/paperless/media", + "compose_source_example": "media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 64 + } + }, + { + "id": "paperless-export", + "container_path": "/usr/src/paperless/export", + "compose_source_example": "./export", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "paperless-consume", + "container_path": "/usr/src/paperless/consume", + "compose_source_example": "./consume", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "db", + "image": "docker.io/library/postgres:18" + }, + { + "name": "broker", + "image": "docker.io/valkey/valkey:9-alpine" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n broker:\n image: docker.io/valkey/valkey:9-alpine\n restart: unless-stopped\n volumes:\n - redisdata:/data\n db:\n image: docker.io/library/postgres:18\n restart: unless-stopped\n volumes:\n - pgdata:/var/lib/postgresql\n environment:\n POSTGRES_DB: paperless\n POSTGRES_USER: paperless\n POSTGRES_PASSWORD: paperless\n webserver:\n image: ghcr.io/paperless-ngx/paperless-ngx:latest\n restart: unless-stopped\n depends_on:\n - db\n - broker\n ports:\n - '8000:8000'\n volumes:\n - data:/usr/src/paperless/data\n - media:/usr/src/paperless/media\n - ./export:/usr/src/paperless/export\n - ./consume:/usr/src/paperless/consume\n env_file: docker-compose.env\n environment:\n PAPERLESS_REDIS: redis://broker:6379\n PAPERLESS_DBHOST: db\n PAPERLESS_DBENGINE: postgresql\nvolumes:\n data:\n media:\n pgdata:\n redisdata:\n" + }, + "compose_stack": { + "project_name": "paperless-ngx", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "webserver", + "service_count": 3, + "services": [ + { + "name": "broker", + "image": "docker.io/valkey/valkey:9-alpine", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "docker.io/valkey/valkey:9-alpine", + "restart": "unless-stopped", + "volumes": [ + "redisdata:/data" + ] + } + }, + { + "name": "db", + "image": "docker.io/library/postgres:18", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "docker.io/library/postgres:18", + "environment": { + "POSTGRES_DB": "paperless", + "POSTGRES_USER": "paperless", + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}" + }, + "restart": "unless-stopped", + "volumes": [ + "pgdata:/var/lib/postgresql" + ] + } + }, + { + "name": "webserver", + "image": "ghcr.io/paperless-ngx/paperless-ngx:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "db", + "broker" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "ghcr.io/paperless-ngx/paperless-ngx:latest", + "ports": [ + "8000:8000" + ], + "volumes": [ + "data:/usr/src/paperless/data", + "media:/usr/src/paperless/media", + "./export:/usr/src/paperless/export", + "./consume:/usr/src/paperless/consume" + ], + "environment": { + "PAPERLESS_REDIS": "redis://broker:6379", + "PAPERLESS_DBHOST": "db", + "PAPERLESS_DBENGINE": "postgresql" + }, + "restart": "unless-stopped" + } + } + ], + "top_level": { + "volumes": { + "data": {}, + "media": {}, + "pgdata": {}, + "redisdata": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-replace-compose-service-dns", + "dependency_external_access": "disabled", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "webserver-data", + "service": "webserver", + "container_path": "/usr/src/paperless/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + }, + { + "id": "webserver-media", + "service": "webserver", + "container_path": "/usr/src/paperless/media", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + }, + { + "id": "webserver-export", + "service": "webserver", + "container_path": "/usr/src/paperless/export", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "webserver-consume", + "service": "webserver", + "container_path": "/usr/src/paperless/consume", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "database-data", + "service": "db", + "container_path": "/var/lib/postgresql", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + }, + { + "id": "broker-data", + "service": "broker", + "container_path": "/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "db", + "broker", + "webserver" + ], + "stop_order": [ + "webserver", + "broker", + "db" + ], + "dependency_readiness": "healthcheck-before-webserver", + "rollback_on_failure": "remove-all-new-lxc-and-new-managed-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "timezone", + "ocr_language", + "admin_username" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_addresses", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install" + }, + { + "id": "database-password", + "strategy": "generate-cryptographically-random-at-install" + }, + { + "id": "secret-key", + "strategy": "generate-cryptographically-random-at-install" + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Paperless-ngx WebUI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "official-compose" + } + ], + "credentials": [ + { + "label": "Generated Paperless administrator", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "proxmenux-installer-generated", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 1024, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "catalog": { + "replaces_discovered_ids": [ + "paperless-ngx" + ] + }, + "adaptations": [ + { + "id": "three-native-lxc-services", + "upstream_behavior": "Docker Compose starts Paperless-ngx, PostgreSQL and Valkey together.", + "native_lxc_behavior": "One catalog action creates three native OCI LXC containers.", + "reason": "Each OCI image is imported as its own Proxmox LXC.", + "behavioral_impact": "The user still installs one application stack.", + "validation": "passed-laboratory-2026-09-13" + }, + { + "id": "private-service-network", + "upstream_behavior": "Compose DNS connects webserver to db and broker.", + "native_lxc_behavior": "A private Proxmox bridge assigns fixed addresses to all three services.", + "reason": "Native LXC containers do not share Docker service discovery.", + "behavioral_impact": "PostgreSQL and Valkey are not exposed on the LAN.", + "validation": "passed-laboratory-2026-09-13" + }, + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker named volumes persist data, media, PostgreSQL and Valkey.", + "native_lxc_behavior": "Proxmox-managed mpN volumes preserve the same container paths with backup=1.", + "reason": "Private state must participate in native Proxmox backup and restore.", + "behavioral_impact": "No application state depends on the root filesystem.", + "validation": "passed-laboratory-2026-09-13" + }, + { + "id": "selectable-transfer-directories", + "upstream_behavior": "Compose bind-mounts local export and consume directories.", + "native_lxc_behavior": "The installer offers managed volumes or host directories and creates selected host paths.", + "reason": "Scanners and other OCI applications may need access to consume and export.", + "behavioral_impact": "Host-bound transfer folders are excluded from native LXC backups.", + "validation": "passed-laboratory-2026-09-13" + }, + { + "id": "generated-first-run-secrets", + "upstream_behavior": "The administrator and required secret key are configured outside the Compose file.", + "native_lxc_behavior": "The installer generates an admin password, database password and Paperless secret key.", + "reason": "A new deployment must not use published default secrets.", + "behavioral_impact": "The initial administrator credentials are printed once after installation.", + "validation": "passed-laboratory-2026-09-13" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "minimum_host_memory_mb": 4096, + "recommended_host_memory_mb": 6144, + "database_storage": { + "must_be_local": true, + "network_filesystem_allowed": false + } + }, + "defaults": { + "stack_name": "paperless", + "timezone": "Europe/Madrid", + "ocr_language": "spa", + "rootfs_storage": "local-lvm", + "application_storage": "local-lvm", + "database_storage": "local-lvm", + "data_volume_size_gb": 8, + "media_volume_size_gb": 64, + "database_volume_size_gb": 8, + "broker_volume_size_gb": 4, + "transfer_volume_size_gb": 8, + "shared_transfer_root": "/mnt/oci-shared/paperless/${stack_name}", + "frontend_network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "firewall": true, + "host_managed": true + }, + "private_network": { + "mode": "create-if-missing", + "bridge": "vmbr10", + "subnet": "10.77.0.0/24", + "host_address": "10.77.0.1/24", + "application_address": "10.77.0.30/24", + "database_address": "10.77.0.31/24", + "broker_address": "10.77.0.32/24", + "nat": false + }, + "application": { + "admin_username": "admin" + } + }, + "installer_contract": { + "deployment_kind": "paperless-three-lxc-stack", + "reserve_vmids_atomically": 3, + "generated_secrets": [ + "POSTGRES_PASSWORD", + "PAPERLESS_ADMIN_PASSWORD", + "PAPERLESS_SECRET_KEY" + ], + "private_volumes": { + "data": "/usr/src/paperless/data", + "media": "/usr/src/paperless/media", + "database": "/var/lib/postgresql", + "broker": "/data" + }, + "transfer_directories": { + "choices": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind" + }, + "start_order": [ + "db", + "broker", + "webserver" + ], + "stop_order": [ + "webserver", + "broker", + "db" + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "depends_on", + "env_file", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The official three-service PostgreSQL Compose has a dedicated native LXC orchestrator validated by clean installation and ordered restart." + }, + "validation": { + "schema": "passed", + "clean_install": "passed-2026-09-13-paperless-ngx-3.1.3", + "service_health": "passed-paperless-postgresql-valkey", + "restart_persistence": "passed-ordered-stop-start-admin-preserved", + "backup_restore": "pending", + "update_preserves_data": "pending", + "private_dependency_network": "passed-10.77.0.30-32", + "managed_volume_persistence": "passed-data-media-postgresql-valkey", + "ocr_languages": "passed-eng-spa", + "laboratory_versions": { + "paperless_ngx": "3.1.3", + "postgresql": "18.6", + "valkey": "9.1.2" + } + }, + "lifecycle": { + "update_strategy": "resolve-selected-tags-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-image-digests", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "starts_stopped_dependencies": true, + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false, + "persistent_contract": "/etc/pve/priv/proxmenux-stack-.json", + "runtime_owner": "proxmox-ve" + } + } +} diff --git a/oci/catalog/apps/pcsx2.json b/oci/catalog/apps/pcsx2.json new file mode 100644 index 00000000..d4989370 --- /dev/null +++ b/oci/catalog/apps/pcsx2.json @@ -0,0 +1,272 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-pcsx2", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pcsx2" + }, + "tagline": { + "en_US": "PCSX2 is an open source PS2 Emulator." + }, + "description": { + "en_US": "PCSX2 is an open source PS2 Emulator." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pcsx2-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pcsx2-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://pcsx2.net/", + "documentation": "https://docs.linuxserver.io/images/docker-pcsx2/", + "repository": "https://github.com/linuxserver/docker-pcsx2", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-29", + "note": "Rebase to resolute." + }, + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-15", + "note": "Switch to stable release for pcsx2." + }, + { + "date": "2025-06-26", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-pcsx2", + "default_branch": "master", + "revision": "687850663915c6cbe3d9693eb81f02a9c7e5cf19", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-pcsx2/687850663915c6cbe3d9693eb81f02a9c7e5cf19/README.md", + "readme_pushed_at": "2026-09-11T23:09:27Z", + "compose_sha256": "e807ff57d706a177edbb31fa23687e4e81ce55e0a227466b2a1f8be2484ffab4", + "generated_at": "2026-09-12T14:37:33+00:00" + }, + "container_contract": { + "service_name": "pcsx2", + "container_name": "pcsx2", + "image": { + "reference": "lscr.io/linuxserver/pcsx2:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/pcsx2", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n pcsx2:\n image: lscr.io/linuxserver/pcsx2:latest\n container_name: pcsx2\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pdfding.json b/oci/catalog/apps/pdfding.json new file mode 100644 index 00000000..ce089101 --- /dev/null +++ b/oci/catalog/apps/pdfding.json @@ -0,0 +1,487 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-pdfding", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "PdfDing" + }, + "tagline": { + "en_US": "Selfhosted PDF manager, viewer and editor" + }, + "description": { + "en_US": "PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. It's designed to be minimal, fast, and easy to set up using Docker.\n\nWith features like seamless browser-based PDF viewing that remembers your current position, multi-level tagging, starring and archiving functionalities, PDF editing with comments, highlighting and drawings, clean intuitive UI with dark mode, SSO support via OIDC, PDF sharing with external audience, markdown notes, and progress bars showing reading progress, PdfDing ensures an excellent PDF management experience.\n\nDeploying PdfDing on private cloud devices like self-hosted server brings unmatched convenience with multi-device access, ensuring your PDF collection is always within reach and secure, no matter where you are.\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "mrmn2", + "developer": "mrmn2", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://www.pdfding.com", + "documentation": null, + "repository": "https://hub.docker.com/r/mrmn/pdfding", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "mrmn", + "repository": "https://hub.docker.com/r/mrmn/pdfding", + "revision": "b917d1fda3ebe37b55c296db866d2ffdf619bc4a5375bb7cde7380c40a7c4688", + "image_repository_url": "https://hub.docker.com/r/mrmn/pdfding", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "b917d1fda3ebe37b55c296db866d2ffdf619bc4a5375bb7cde7380c40a7c4688", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "pdfding", + "container_name": "pdfding", + "image": { + "reference": "mrmn/pdfding:latest", + "registry": "docker.io", + "repository": "mrmn/pdfding", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "HOST_NAME", + "example": "*", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SECRET_KEY", + "example": "${GENERATED_SECRET_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "CSRF_COOKIE_SECURE", + "example": "FALSE", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SESSION_COOKIE_SECURE", + "example": "FALSE", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEBUG", + "example": "FALSE", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/home/nonroot/pdfding/db", + "compose_source_example": "/DATA/AppData/$AppID/db", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/home/nonroot/pdfding/media", + "compose_source_example": "/DATA/AppData/$AppID/media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: pdfding\nservices:\n pdfding:\n image: mrmn/pdfding:latest\n deploy:\n resources:\n reservations:\n memory: 128M\n network_mode: bridge\n ports:\n - target: 8000\n published: '8000'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/db\n target: /home/nonroot/pdfding/db\n - type: bind\n source: /DATA/AppData/$AppID/media\n target: /home/nonroot/pdfding/media\n environment:\n - HOST_NAME=*\n - SECRET_KEY=${GENERATED_SECRET_KEY}\n - CSRF_COOKIE_SECURE=FALSE\n - SESSION_COOKIE_SECURE=FALSE\n - DEBUG=FALSE\n container_name: pdfding\n" + }, + "compose_stack": { + "project_name": "pdfding", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "pdfding", + "service_count": 1, + "services": [ + { + "name": "pdfding", + "image": "mrmn/pdfding:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "mrmn/pdfding:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8000, + "published": "8000", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/db", + "target": "/home/nonroot/pdfding/db" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/media", + "target": "/home/nonroot/pdfding/media" + } + ], + "environment": [ + "HOST_NAME=*", + "SECRET_KEY=${GENERATED_SECRET_KEY}", + "CSRF_COOKIE_SECURE=FALSE", + "SESSION_COOKIE_SECURE=FALSE", + "DEBUG=FALSE" + ], + "container_name": "pdfding" + } + } + ], + "top_level": { + "name": "pdfding" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "pdfding-volume-0", + "service": "pdfding", + "container_path": "/home/nonroot/pdfding/db", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "pdfding-volume-1", + "service": "pdfding", + "container_path": "/home/nonroot/pdfding/media", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "pdfding" + ], + "stop_order": [ + "pdfding" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "secret-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "pdfding", + "environment_variable": "SECRET_KEY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/peanut.json b/oci/catalog/apps/peanut.json new file mode 100644 index 00000000..d971dfc6 --- /dev/null +++ b/oci/catalog/apps/peanut.json @@ -0,0 +1,411 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-peanut", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "PeaNUT" + }, + "tagline": { + "en_US": "UPS monitoring and power outage notification system" + }, + "description": { + "en_US": "PeaNUT is a web-based UPS monitoring system specifically designed for monitoring Uninterruptible Power Supplies (UPS). It provides a user-friendly interface for monitoring UPS status, battery life, and power outage notifications to ensure your systems are always protected.\n\n**Key Features:**\n- Real-time UPS status monitoring and control\n- Battery life and charge level monitoring\n- Automatic power outage notifications via email/webhook\n- Historical data logging and reporting\n- Support for various UPS manufacturers and models\n- Mobile-friendly responsive web interface for remote access\n- Configurable warning thresholds and alerts\n- Docker-based deployment for easy installation\n\n**Learn More:**\n- [PeaNUT GitHub Repository](https://github.com/brandawg93/peanut)\n" + }, + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "author": "brandawg93", + "developer": "brandawg93", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/brandawg93/peanut", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "brandawg93", + "repository": "https://hub.docker.com/r/brandawg93/peanut", + "revision": "ffedd2649a0cdbeb049c5a91527f6dc82b82886b32f7856d42c20ab48ea4af60", + "image_repository_url": "https://hub.docker.com/r/brandawg93/peanut", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "ffedd2649a0cdbeb049c5a91527f6dc82b82886b32f7856d42c20ab48ea4af60", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "peanut", + "container_name": "PeaNUT", + "image": { + "reference": "brandawg93/peanut:latest", + "registry": "docker.io", + "repository": "brandawg93/peanut", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "WEB_PORT", + "example": "8080", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8084, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: peanut\nservices:\n peanut:\n image: brandawg93/peanut:latest\n container_name: PeaNUT\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n ports:\n - target: 8080\n published: '8084'\n protocol: tcp\n environment:\n WEB_PORT: 8080\n deploy:\n resources:\n reservations:\n memory: 256M\n" + }, + "compose_stack": { + "project_name": "peanut", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "peanut", + "service_count": 1, + "services": [ + { + "name": "peanut", + "image": "brandawg93/peanut:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "brandawg93/peanut:latest", + "container_name": "PeaNUT", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + } + ], + "ports": [ + { + "target": 8080, + "published": "8084", + "protocol": "tcp" + } + ], + "environment": { + "WEB_PORT": 8080 + }, + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + } + } + } + ], + "top_level": { + "name": "peanut" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "peanut-volume-0", + "service": "peanut", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "peanut" + ], + "stop_order": [ + "peanut" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pelorus.json b/oci/catalog/apps/pelorus.json new file mode 100644 index 00000000..1d7327e8 --- /dev/null +++ b/oci/catalog/apps/pelorus.json @@ -0,0 +1,349 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-pelorus", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pelorus" + }, + "tagline": { + "en_US": "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration." + }, + "description": { + "en_US": "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pelorus-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pelorus-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/linuxserver/pelorus", + "documentation": "https://docs.linuxserver.io/images/docker-pelorus/", + "repository": "https://github.com/linuxserver/docker-pelorus", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-19", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-07-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-pelorus", + "default_branch": "master", + "revision": "3bfbbc97813ca36bcefae2e4300b73b19d24d660", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-pelorus/3bfbbc97813ca36bcefae2e4300b73b19d24d660/README.md", + "readme_pushed_at": "2026-09-07T05:58:26Z", + "compose_sha256": "379898d7f867fdabdbd90d4f0b7f8f9309ea13120a6fccca2ddbb3eb42d81e6f", + "generated_at": "2026-09-12T14:37:33+00:00" + }, + "container_contract": { + "service_name": "pelorus", + "container_name": "pelorus", + "image": { + "reference": "lscr.io/linuxserver/pelorus:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/pelorus", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/pelorus/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n pelorus:\n image: lscr.io/linuxserver/pelorus:latest\n container_name: pelorus\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/pelorus/config:/config\n ports:\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3001, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-pelorus/master/Dockerfile", + "dockerfile_sha256": "0ce9c54fda7045fe7e106400657bc9c66aa30c00b24deb05e2a0981136dbafe9", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/petio.json b/oci/catalog/apps/petio.json new file mode 100644 index 00000000..e04f5a00 --- /dev/null +++ b/oci/catalog/apps/petio.json @@ -0,0 +1,533 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-petio", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Petio" + }, + "tagline": { + "en_US": "A third party companion app available to Plex server owners to allow their users to request, review and discover content." + }, + "description": { + "en_US": "Petio is a third party companion app available to Plex server owners to allow their users to request, review and discover content. The app is built to appear instantly familiar and intuitive to even the most tech-agnostic users. Petio will help you manage requests from your users, connect to other third party apps such as Sonarr and Radarr, notify users when content is available and track request progress. Petio also allows users to discover media both on and off your server, quickly and easily find related content and review to leave their opinion for other users.\n\nPetio is an ongoing, forever free, always evolving project currently in alpha prototype stage and now available!\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Petio Team", + "developer": "Petio Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 7777, + "path": "/" + }, + "website": "https://petio.tv", + "documentation": null, + "repository": "https://ghcr.io/petio-team/petio", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/petio-team/petio", + "revision": "1212f5f9c5cb47439f2aeb7212b3f66ae6429788fe9ea6edad60d4fa758814af", + "image_repository_url": "https://ghcr.io/petio-team/petio", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "1212f5f9c5cb47439f2aeb7212b3f66ae6429788fe9ea6edad60d4fa758814af", + "generated_at": "2026-09-13T15:48:32+00:00" + }, + "container_contract": { + "service_name": "petio", + "container_name": "petio-petio", + "image": { + "reference": "ghcr.io/petio-team/petio:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/petio-team/petio", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/api/config", + "compose_source_example": "/DATA/AppData/petio/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/app/logs", + "compose_source_example": "/DATA/AppData/petio/logs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 7777, + "published_example": 7777, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "mongo", + "image": "mongo:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: petio\nservices:\n petio:\n image: ghcr.io/petio-team/petio:latest\n restart: unless-stopped\n networks:\n - petio-network\n depends_on:\n - mongo\n environment:\n PUID: $PUID\n PGID: $PGID\n TZ: $TZ\n ports:\n - target: 7777\n published: '7777'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/petio/config\n target: /app/api/config\n - type: bind\n source: /DATA/AppData/petio/logs\n target: /app/logs\n container_name: petio-petio\n mongo:\n image: mongo:latest\n restart: unless-stopped\n hostname: mongo\n networks:\n - petio-network\n environment:\n PUID: $PUID\n PGID: $PGID\n TZ: $TZ\n container_name: petio-mongo\nnetworks:\n petio-network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "petio", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "petio", + "service_count": 2, + "services": [ + { + "name": "mongo", + "image": "mongo:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "mongo:latest", + "restart": "unless-stopped", + "hostname": "mongo", + "networks": [ + "petio-network" + ], + "environment": { + "PUID": "$PUID", + "PGID": "$PGID", + "TZ": "$TZ" + }, + "container_name": "petio-mongo" + } + }, + { + "name": "petio", + "image": "ghcr.io/petio-team/petio:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "mongo" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "ghcr.io/petio-team/petio:latest", + "restart": "unless-stopped", + "networks": [ + "petio-network" + ], + "depends_on": [ + "mongo" + ], + "environment": { + "PUID": "$PUID", + "PGID": "$PGID", + "TZ": "$TZ" + }, + "ports": [ + { + "target": 7777, + "published": "7777", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/petio/config", + "target": "/app/api/config" + }, + { + "type": "bind", + "source": "/DATA/AppData/petio/logs", + "target": "/app/logs" + } + ], + "container_name": "petio-petio" + } + } + ], + "top_level": { + "name": "petio", + "networks": { + "petio-network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "petio-volume-0", + "service": "petio", + "container_path": "/app/api/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "petio-volume-1", + "service": "petio", + "container_path": "/app/logs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "mongo", + "petio" + ], + "stop_order": [ + "petio", + "mongo" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7777, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "stack_adaptation_notes": [ + "MongoDB implicit image volumes /data/db and /data/configdb receive managed Proxmox volumes with backup enabled.", + "MongoDB has no LAN interface; its unauthenticated upstream configuration is limited to the private stack network (also reachable by the Proxmox host).", + "Complete Petio web setup with MongoDB host mongo and port 27017. Plex credentials remain user-provided.", + "The latest MongoDB image requires compatible CPU instructions; application and hardware compatibility remain unvalidated." + ], + "stack_references": [ + "https://github.com/docker-library/docs/tree/master/mongo", + "https://github.com/petio-team/petio" + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/photoprism.json b/oci/catalog/apps/photoprism.json new file mode 100644 index 00000000..651ee175 --- /dev/null +++ b/oci/catalog/apps/photoprism.json @@ -0,0 +1,471 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-photoprism", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "PhotoPrism" + }, + "tagline": { + "en_US": "Browse Your Life in Images" + }, + "description": { + "en_US": "Your AI-Powered Photos App for the Decentralized Web\n\nPhotoPrism brings the magic of AI to your home TV, phone, and multiple devices, revolutionizing the way you manage and share your photos. Unlike traditional photo albums that require manual organization, PhotoPrism automatically tags and finds your pictures, making it easier than ever to relive your memories. Whether you're showing family photos on your TV or sharing vacation snapshots on your phone, PhotoPrism makes the experience seamless and enjoyable.\n\nPhotoPrism offers a host of features designed to enhance your photo management experience. With powerful search capabilities, automatic tagging, and a user-friendly interface, you'll find it easy to keep your photo collection organized. The app is free to use, with premium options available for those seeking additional features and support. Users can expect a smooth, intuitive experience that blends cutting-edge technology with everyday convenience.\n\nDeploying PhotoPrism on self-hosted server private cloud devices offers unparalleled convenience. Enjoy unlimited storage capacity, the speed of your local network, and access from multiple devices without the need for the internet. It's the perfect solution for NAS enthusiasts who value privacy and performance.\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "PhotoPrism", + "developer": "PhotoPrism", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 2342, + "path": "/" + }, + "website": "https://www.photoprism.app", + "documentation": null, + "repository": "https://hub.docker.com/r/photoprism/photoprism", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/photoprism/photoprism", + "revision": "70bb638c51c80221a3c068216bd7f3dbdc532288e240532e7ca535788c634be1", + "image_repository_url": "https://hub.docker.com/r/photoprism/photoprism", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "70bb638c51c80221a3c068216bd7f3dbdc532288e240532e7ca535788c634be1", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "photoprism", + "container_name": "photoprism", + "image": { + "reference": "photoprism/photoprism:latest", + "registry": "docker.io", + "repository": "photoprism/photoprism", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PHOTOPRISM_ADMIN_PASSWORD", + "example": "${GENERATED_PHOTOPRISM_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "PHOTOPRISM_UPLOAD_NSFW", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/photoprism/storage", + "compose_source_example": "/DATA/AppData/$AppID/photoprism/storage", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/photoprism/originals", + "compose_source_example": "/DATA/Gallery", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 2342, + "published_example": 2342, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: photoprism\nservices:\n photoprism:\n environment:\n PHOTOPRISM_ADMIN_PASSWORD: ${GENERATED_PHOTOPRISM_ADMIN_PASSWORD}\n PHOTOPRISM_UPLOAD_NSFW: 'true'\n TZ: $TZ\n image: photoprism/photoprism:latest\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 2342\n published: '2342'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/photoprism/storage\n target: /photoprism/storage\n - type: bind\n source: /DATA/Gallery\n target: /photoprism/originals\n container_name: photoprism\n" + }, + "compose_stack": { + "project_name": "photoprism", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "photoprism", + "service_count": 1, + "services": [ + { + "name": "photoprism", + "image": "photoprism/photoprism:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PHOTOPRISM_ADMIN_PASSWORD": "${GENERATED_PHOTOPRISM_ADMIN_PASSWORD}", + "PHOTOPRISM_UPLOAD_NSFW": "true", + "TZ": "$TZ" + }, + "image": "photoprism/photoprism:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 2342, + "published": "2342", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/photoprism/storage", + "target": "/photoprism/storage" + }, + { + "type": "bind", + "source": "/DATA/Gallery", + "target": "/photoprism/originals" + } + ], + "container_name": "photoprism" + } + } + ], + "top_level": { + "name": "photoprism" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "photoprism-volume-0", + "service": "photoprism", + "container_path": "/photoprism/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "photoprism-volume-1", + "service": "photoprism", + "container_path": "/photoprism/originals", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "photoprism" + ], + "stop_order": [ + "photoprism" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "photoprism-admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "photoprism", + "environment_variable": "PHOTOPRISM_ADMIN_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 2342, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/phpmyadmin.json b/oci/catalog/apps/phpmyadmin.json new file mode 100644 index 00000000..b45a864e --- /dev/null +++ b/oci/catalog/apps/phpmyadmin.json @@ -0,0 +1,255 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-phpmyadmin", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Phpmyadmin" + }, + "tagline": { + "en_US": "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB." + }, + "description": { + "en_US": "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB." + }, + "category": "databases", + "category_label": "Databases", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/phpmyadmin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/phpmyadmin-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/phpmyadmin/phpmyadmin/", + "documentation": "https://docs.linuxserver.io/images/docker-phpmyadmin/", + "repository": "https://github.com/linuxserver/docker-phpmyadmin", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-08-23", + "note": "Add support for mTLS. Existing users will need to delete their config.inc.php and restart the container." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-19", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-phpmyadmin", + "default_branch": "main", + "revision": "defdc6e1987275676ce73ecc5c08ed844e45aa1d", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-phpmyadmin/defdc6e1987275676ce73ecc5c08ed844e45aa1d/README.md", + "readme_pushed_at": "2026-09-11T23:39:09Z", + "compose_sha256": "fd9a5d0ba3024593d0fc6d5f494695104a87b6506aa1735da41bf4a6dfe10cfa", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "phpmyadmin", + "container_name": "phpmyadmin", + "image": { + "reference": "lscr.io/linuxserver/phpmyadmin:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/phpmyadmin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PMA_ARBITRARY", + "example": "1", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PMA_ABSOLUTE_URI", + "example": "https://phpmyadmin.example.com", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/phpmyadmin/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n phpmyadmin:\n image: lscr.io/linuxserver/phpmyadmin:latest\n container_name: phpmyadmin\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - PMA_ARBITRARY=1 #optional\n - PMA_ABSOLUTE_URI=https://phpmyadmin.example.com #optional\n volumes:\n - /path/to/phpmyadmin/config:/config\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pidgin.json b/oci/catalog/apps/pidgin.json new file mode 100644 index 00000000..6110fcc9 --- /dev/null +++ b/oci/catalog/apps/pidgin.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-pidgin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pidgin" + }, + "tagline": { + "en_US": "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time." + }, + "description": { + "en_US": "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pidgin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pidgin-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://pidgin.im/", + "documentation": "https://docs.linuxserver.io/images/docker-pidgin/", + "repository": "https://github.com/linuxserver/docker-pidgin", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-05-07", + "note": "Remove Skype plugin." + }, + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-pidgin", + "default_branch": "master", + "revision": "3b6447c238e6cc67d9f8c5b9b05bb7bbb2ebb204", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-pidgin/3b6447c238e6cc67d9f8c5b9b05bb7bbb2ebb204/README.md", + "readme_pushed_at": "2026-09-09T21:47:20Z", + "compose_sha256": "19ff2efa8c7e2115a6d6c9067f10d38a706305ec5dfff2c54afc55aec4d84931", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "pidgin", + "container_name": "pidgin", + "image": { + "reference": "lscr.io/linuxserver/pidgin:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/pidgin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n pidgin:\n image: lscr.io/linuxserver/pidgin:latest\n container_name: pidgin\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-pidgin/master/Dockerfile", + "dockerfile_sha256": "81f8176b9843bc7a4b9a7f762910f58e735f35d34d78834e191bae6e5ee851b2", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pihole.json b/oci/catalog/apps/pihole.json new file mode 100644 index 00000000..0cb35381 --- /dev/null +++ b/oci/catalog/apps/pihole.json @@ -0,0 +1,506 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-pihole", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pi-hole" + }, + "tagline": { + "en_US": "Network-wide Ad Blocking" + }, + "description": { + "en_US": "Pi-hole is a network-wide ad-blocking platform for Linux hardware, using DNS sinkhole technology to protect devices from unwanted content without requiring client-side software. Designed for home or enterprise networks, it offers efficient ad blocking and network optimization.\n\nCore features include network-wide ad blocking and content blocking in non-browser environments. It uses DNS sinkhole to block ads, covering mobile apps and smart TVs. Caching DNS queries speeds up everyday browsing. A command-line interface ensures interoperability with reliable control options.\n\nIt provides an intuitive web interface dashboard for viewing and managing system status. An optional DHCP server function automatically protects all devices. Capable of handling high query volumes on server-grade hardware, it supports ad blocking over IPv4 and IPv6. With efficiency and versatility at the core, the platform delivers a modern network protection solution.\n\n**Key Features:**\n- Network-wide ad blocking via DNS sinkhole technology\n- Blocking content in non-browser environments, including mobile apps and smart TVs\n- Caching DNS queries to speed up browsing\n- Command-line interface for interoperability\n- Intuitive web interface dashboard for system viewing and control\n- Optional DHCP server function for automatic device protection\n- Ad blocking support for IPv4 and IPv6\n\n**Learn More:**\n- [Pi-hole Official Website](https://pi-hole.net/)\n- [Pi-hole GitHub](https://github.com/pi-hole/pi-hole)\n" + }, + "category": "adblock", + "category_label": "Adblock & DNS", + "author": "Pi-hole", + "developer": "Pi-hole", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/admin" + }, + "website": "https://pi-hole.net/", + "documentation": null, + "repository": "https://hub.docker.com/r/pihole/pihole", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/pihole/pihole", + "revision": "61afbadbdb54bca4ff5b29050ebb82aaa601a7015b434efa5291c7db703ac7fa", + "image_repository_url": "https://hub.docker.com/r/pihole/pihole", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "61afbadbdb54bca4ff5b29050ebb82aaa601a7015b434efa5291c7db703ac7fa", + "generated_at": "2026-09-13T15:47:51+00:00" + }, + "container_contract": { + "service_name": "pihole", + "container_name": "pihole", + "image": { + "reference": "pihole/pihole:latest", + "registry": "docker.io", + "repository": "pihole/pihole", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "FTLCONF_webserver_api_password", + "example": "${GENERATED_FTLCONF_WEBSERVER_API_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "FTLCONF_dns_listeningMode", + "example": "all", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/etc/pihole", + "compose_source_example": "/DATA/AppData/$AppID/etc/pihole/", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 8800, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 53, + "published_example": 53, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 53, + "published_example": 53, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 8443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: pihole\nservices:\n pihole:\n environment:\n TZ: $TZ\n FTLCONF_webserver_api_password: ${GENERATED_FTLCONF_WEBSERVER_API_PASSWORD}\n FTLCONF_dns_listeningMode: all\n image: pihole/pihole:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 80\n published: '8800'\n protocol: tcp\n - target: 53\n published: '53'\n protocol: tcp\n - target: 53\n published: '53'\n protocol: udp\n - target: 443\n published: '8443'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/etc/pihole/\n target: /etc/pihole\n cap_add:\n - NET_ADMIN\n container_name: pihole\n" + }, + "compose_stack": { + "project_name": "pihole", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "pihole", + "service_count": 1, + "services": [ + { + "name": "pihole", + "image": "pihole/pihole:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "TZ": "$TZ", + "FTLCONF_webserver_api_password": "${GENERATED_FTLCONF_WEBSERVER_API_PASSWORD}", + "FTLCONF_dns_listeningMode": "all" + }, + "image": "pihole/pihole:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 80, + "published": "8800", + "protocol": "tcp" + }, + { + "target": 53, + "published": "53", + "protocol": "tcp" + }, + { + "target": 53, + "published": "53", + "protocol": "udp" + }, + { + "target": 443, + "published": "8443", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/etc/pihole/", + "target": "/etc/pihole" + } + ], + "cap_add": [ + "NET_ADMIN" + ], + "container_name": "pihole" + } + } + ], + "top_level": { + "name": "pihole" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "pihole-volume-0", + "service": "pihole", + "container_path": "/etc/pihole", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "pihole" + ], + "stop_order": [ + "pihole" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "ftlconf-webserver-api-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "pihole", + "environment_variable": "FTLCONF_webserver_api_password" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/admin", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "security": { + "required_capabilities": [ + "NET_ADMIN" + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pinchflat.json b/oci/catalog/apps/pinchflat.json new file mode 100644 index 00000000..50b6f730 --- /dev/null +++ b/oci/catalog/apps/pinchflat.json @@ -0,0 +1,459 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-pinchflat", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pinchflat" + }, + "tagline": { + "en_US": "Your next YouTube media manager" + }, + "description": { + "en_US": "Pinchflat is a self-hosted app for downloading YouTube content built using yt-dlp. It's designed to be lightweight, self-contained, and easy to use. You set up rules for how to download content from YouTube channels or playlists and it'll do the rest, periodically checking for new content.\n\nKey features include:\n- Self-contained - just one Docker container with no external dependencies\n- Powerful naming system so content is stored where and how you want it\n- Easy-to-use web interface with presets to get you started right away\n- First-class support for media center apps like Plex, Jellyfin, and Kodi\n- Supports serving RSS feeds to your favourite podcast app\n- Automatically downloads new content from channels and playlists\n- Supports downloading audio content\n- Custom rules for handling YouTube Shorts and livestreams\n- Apprise support for notifications\n- Optionally automatically delete old content\n- Advanced options like setting cutoff dates and filtering by title\n- Reliable hands-off operation\n- Can pass cookies to YouTube to download your private playlists\n- Sponsorblock integration\n- Supports running custom scripts when after downloading/deleting media\n\nPerfect for people who want to download content for use with a media center app or for those who want to archive media!\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "kieraneglin", + "developer": "kieraneglin", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8945, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://ghcr.io/kieraneglin/pinchflat", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "kieraneglin", + "repository": "https://ghcr.io/kieraneglin/pinchflat", + "revision": "e940bb4bfdbbfd4a07cf3de0b488c5bc23da0a109310f2bd7bbd4305df6c4e4b", + "image_repository_url": "https://ghcr.io/kieraneglin/pinchflat", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "e940bb4bfdbbfd4a07cf3de0b488c5bc23da0a109310f2bd7bbd4305df6c4e4b", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "pinchflat", + "container_name": "pinchflat", + "image": { + "reference": "ghcr.io/kieraneglin/pinchflat:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/kieraneglin/pinchflat", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/DATA/Media/Downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8945, + "published_example": 8945, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: pinchflat\nservices:\n pinchflat:\n image: ghcr.io/kieraneglin/pinchflat:latest\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n ports:\n - target: 8945\n published: '8945'\n protocol: tcp\n restart: unless-stopped\n environment:\n - TZ=$TZ\n - PUID=$PUID\n - PGID=$PGID\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/Media/Downloads\n target: /downloads\n container_name: pinchflat\n" + }, + "compose_stack": { + "project_name": "pinchflat", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "pinchflat", + "service_count": 1, + "services": [ + { + "name": "pinchflat", + "image": "ghcr.io/kieraneglin/pinchflat:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/kieraneglin/pinchflat:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8945, + "published": "8945", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "environment": [ + "TZ=$TZ", + "PUID=$PUID", + "PGID=$PGID" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/Media/Downloads", + "target": "/downloads" + } + ], + "container_name": "pinchflat" + } + } + ], + "top_level": { + "name": "pinchflat" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "pinchflat-volume-0", + "service": "pinchflat", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "pinchflat-volume-1", + "service": "pinchflat", + "container_path": "/downloads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for pinchflat:/downloads" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "pinchflat" + ], + "stop_order": [ + "pinchflat" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8945, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pingvin-share.json b/oci/catalog/apps/pingvin-share.json new file mode 100644 index 00000000..55af2a7a --- /dev/null +++ b/oci/catalog/apps/pingvin-share.json @@ -0,0 +1,442 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-pingvin-share", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pingvin-Share" + }, + "tagline": { + "en_US": "Self-hosted file sharing with a modern web interface" + }, + "description": { + "en_US": "Pingvin-Share is a self-hosted file sharing application compatible with Nextcloud apps, offering a modern and intuitive web interface. It enables users to securely store, organize, and share files without relying on external cloud services. The application supports multiple authentication methods and provides features such as share links, user accounts, and a responsive interface.\n\n**Key features:**\n- Modern, responsive web interface\n- User accounts with a permission system\n- Secure share links for files\n- Drag-and-drop file upload\n- Password-protected shares\n- Multiple authentication methods\n- Docker-based deployment for easy installation\n\n**Learn more:**\n- [Pingvin-Share GitHub](https://github.com/stonith404/pingvin-share)\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "stonith404", + "developer": "stonith404", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://stonith404.github.io/pingvin-share/", + "documentation": null, + "repository": "https://hub.docker.com/r/stonith404/pingvin-share", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "stonith404", + "repository": "https://hub.docker.com/r/stonith404/pingvin-share", + "revision": "f5259ec44d34ad0b2186ec7e2b089e03577385ae734e68b5222ff8bf77a11d6f", + "image_repository_url": "https://hub.docker.com/r/stonith404/pingvin-share", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "f5259ec44d34ad0b2186ec7e2b089e03577385ae734e68b5222ff8bf77a11d6f", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "pingvin-share", + "container_name": "pingvin-share", + "image": { + "reference": "stonith404/pingvin-share:latest", + "registry": "docker.io", + "repository": "stonith404/pingvin-share", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TRUST_PROXY", + "example": "False", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/opt/app/backend/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/opt/app/frontend/public/img", + "compose_source_example": "/DATA/AppData/$AppID/images", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3410, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: pingvin-share\nservices:\n pingvin-share:\n image: stonith404/pingvin-share:latest\n restart: unless-stopped\n ports:\n - target: 3000\n published: '3410'\n protocol: tcp\n environment:\n TRUST_PROXY: false\n deploy:\n resources:\n reservations:\n memory: 256M\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /opt/app/backend/data\n - type: bind\n source: /DATA/AppData/$AppID/images\n target: /opt/app/frontend/public/img\n" + }, + "compose_stack": { + "project_name": "pingvin-share", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "pingvin-share", + "service_count": 1, + "services": [ + { + "name": "pingvin-share", + "image": "stonith404/pingvin-share:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "stonith404/pingvin-share:latest", + "restart": "unless-stopped", + "ports": [ + { + "target": 3000, + "published": "3410", + "protocol": "tcp" + } + ], + "environment": { + "TRUST_PROXY": false + }, + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/opt/app/backend/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/images", + "target": "/opt/app/frontend/public/img" + } + ] + } + } + ], + "top_level": { + "name": "pingvin-share" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "pingvin-share-volume-0", + "service": "pingvin-share", + "container_path": "/opt/app/backend/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "pingvin-share-volume-1", + "service": "pingvin-share", + "container_path": "/opt/app/frontend/public/img", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "pingvin-share" + ], + "stop_order": [ + "pingvin-share" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/piper.json b/oci/catalog/apps/piper.json new file mode 100644 index 00000000..abddea01 --- /dev/null +++ b/oci/catalog/apps/piper.json @@ -0,0 +1,290 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-piper", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Piper" + }, + "tagline": { + "en_US": "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper." + }, + "description": { + "en_US": "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/piper-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/piper-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 10200, + "path": "/" + }, + "website": "https://github.com/rhasspy/wyoming-piper", + "documentation": "https://docs.linuxserver.io/images/docker-piper/", + "repository": "https://github.com/linuxserver/docker-piper", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-14", + "note": "Rebase to Ubuntu Resolute." + }, + { + "date": "2025-08-29", + "note": "Add support for local only mode." + }, + { + "date": "2025-08-10", + "note": "Add streaming support." + }, + { + "date": "2024-07-18", + "note": "Rebase to Ubuntu Noble." + }, + { + "date": "2023-11-25", + "note": "Initial Release." + } + ], + "display_version": null, + "updated_at": "2026-07-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-piper", + "default_branch": "main", + "revision": "1efb7d8c03aeb86d4999bd4ce0ade6d5066aac10", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-piper/1efb7d8c03aeb86d4999bd4ce0ade6d5066aac10/README.md", + "readme_pushed_at": "2026-09-11T22:05:31Z", + "compose_sha256": "a0719a86198e501048127a4a2dc0b2c21851cff1eb0f6253539e00d72d75acaa", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "piper", + "container_name": "piper", + "image": { + "reference": "lscr.io/linuxserver/piper:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/piper", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PIPER_VOICE", + "example": "en_US-lessac-medium", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOCAL_ONLY", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PIPER_LENGTH", + "example": "1.0", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PIPER_NOISE", + "example": "0.667", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PIPER_NOISEW", + "example": "0.333", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PIPER_SPEAKER", + "example": "0", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "NO_STREAMING", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/piper/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 10200, + "published_example": 10200, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n piper:\n image: lscr.io/linuxserver/piper:latest\n container_name: piper\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - PIPER_VOICE=en_US-lessac-medium\n - LOCAL_ONLY= #optional\n - PIPER_LENGTH=1.0 #optional\n - PIPER_NOISE=0.667 #optional\n - PIPER_NOISEW=0.333 #optional\n - PIPER_SPEAKER=0 #optional\n - NO_STREAMING= #optional\n volumes:\n - /path/to/piper/data:/config\n ports:\n - 10200:10200\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 10200, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/piwigo.json b/oci/catalog/apps/piwigo.json new file mode 100644 index 00000000..0655821e --- /dev/null +++ b/oci/catalog/apps/piwigo.json @@ -0,0 +1,257 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-piwigo", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Piwigo" + }, + "tagline": { + "en_US": "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures." + }, + "description": { + "en_US": "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/piwigo-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/piwigo-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "http://piwigo.org/", + "documentation": "https://docs.linuxserver.io/images/docker-piwigo/", + "repository": "https://github.com/linuxserver/docker-piwigo", + "tips": [], + "mini_changelog": [ + { + "date": "2026-01-04", + "note": "Rebase to Alpine 3.22, always update default theme on startup." + }, + { + "date": "2025-08-05", + "note": "Revert to Alpine 3.21 due to incorrectly stated upstream support for PHP 8.4." + }, + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-05-31", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-04-07", + "note": "Increase php workers to fix Android uploading in bulk" + } + ], + "display_version": null, + "updated_at": "2026-01-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-piwigo", + "default_branch": "master", + "revision": "cd247a58fbe802e6ad812e693739afae51757893", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-piwigo/cd247a58fbe802e6ad812e693739afae51757893/README.md", + "readme_pushed_at": "2026-09-05T17:38:12Z", + "compose_sha256": "04ad16adecece5e5a1a621c7b20e8057d65ef4b88a575b93e3103f71c8dc9d8c", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "piwigo", + "container_name": "piwigo", + "image": { + "reference": "lscr.io/linuxserver/piwigo:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/piwigo", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/piwigo/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/gallery", + "compose_source_example": "/path/to/appdata/gallery", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n piwigo:\n image: lscr.io/linuxserver/piwigo:latest\n container_name: piwigo\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/piwigo/config:/config\n - /path/to/appdata/gallery:/gallery\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/planka.json b/oci/catalog/apps/planka.json new file mode 100644 index 00000000..f2020d2f --- /dev/null +++ b/oci/catalog/apps/planka.json @@ -0,0 +1,304 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-planka", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Planka" + }, + "tagline": { + "en_US": "Planka is an elegant open source project tracking tool." + }, + "description": { + "en_US": "Planka is an elegant open source project tracking tool." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/planka-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/planka-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 1337, + "path": "/" + }, + "website": "https://github.com/plankanban/planka/", + "documentation": "https://docs.linuxserver.io/images/docker-planka/", + "repository": "https://github.com/linuxserver/docker-planka", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-24", + "note": "Add python dep, apprise." + }, + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-02-13", + "note": "Rebase to Alpine 3.23. Updates for v2. Users should update `TRUST_PROXY` to use `true`/`false` instead of `1`/`0`." + }, + { + "date": "2025-01-12", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-09-18", + "note": "Update default user docs." + } + ], + "display_version": null, + "updated_at": "2026-08-24" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-planka", + "default_branch": "main", + "revision": "670c97e17338971e9cda2c907a2ccad2e045b853", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-planka/670c97e17338971e9cda2c907a2ccad2e045b853/README.md", + "readme_pushed_at": "2026-09-10T18:53:49Z", + "compose_sha256": "796b79b05a1ecfbdb3909b739daadec9cf670462ec7b866d6cf20c46edf78ab7", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "planka", + "container_name": "planka", + "image": { + "reference": "lscr.io/linuxserver/planka:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/planka", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "BASE_URL", + "example": "https://planka.example.com", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DATABASE_URL", + "example": "postgresql://user:password@planka-db:5432/planka", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEFAULT_ADMIN_EMAIL", + "example": "demo@demo.demo", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEFAULT_ADMIN_USERNAME", + "example": "demo", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEFAULT_ADMIN_PASSWORD", + "example": "demo", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DEFAULT_ADMIN_NAME", + "example": "Demo User", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SECRET_KEY", + "example": "notasecretkey", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "TRUST_PROXY", + "example": "false", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DEFAULT_LANGUAGE", + "example": "en-US", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/planka/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 1337, + "published_example": 1337, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n planka:\n image: lscr.io/linuxserver/planka:latest\n container_name: planka\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - BASE_URL=https://planka.example.com\n - DATABASE_URL=postgresql://user:password@planka-db:5432/planka\n - DEFAULT_ADMIN_EMAIL=demo@demo.demo\n - DEFAULT_ADMIN_USERNAME=demo\n - DEFAULT_ADMIN_PASSWORD=demo\n - \"DEFAULT_ADMIN_NAME=Demo User\"\n - SECRET_KEY=notasecretkey\n - TRUST_PROXY=false\n - DEFAULT_LANGUAGE=en-US #optional\n volumes:\n - /path/to/planka/data:/config\n ports:\n - 1337:1337\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 1337, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/playit-agent.json b/oci/catalog/apps/playit-agent.json new file mode 100644 index 00000000..e290f6e4 --- /dev/null +++ b/oci/catalog/apps/playit-agent.json @@ -0,0 +1,335 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-playit-agent", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Playit Agent" + }, + "tagline": { + "en_US": "A free reverse proxy for tunneling services (not self-hosted)." + }, + "description": { + "en_US": "" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "Patrick Lorio", + "developer": "Patrick Lorio", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://playit.gg", + "documentation": null, + "repository": "https://ghcr.io/mafen/playit-docker", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "mafen", + "repository": "https://ghcr.io/mafen/playit-docker", + "revision": "0b7353eecf721c22f09a41a16bf72efe683f49f55450a92e43be1b10635d9cb5", + "image_repository_url": "https://ghcr.io/mafen/playit-docker", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "0b7353eecf721c22f09a41a16bf72efe683f49f55450a92e43be1b10635d9cb5", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "playit-agent", + "container_name": "playit-agent", + "image": { + "reference": "ghcr.io/mafen/playit-docker:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/mafen/playit-docker", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: playit-agent\nservices:\n playit-agent:\n restart: unless-stopped\n image: ghcr.io/mafen/playit-docker:latest\n network_mode: bridge\n container_name: playit-agent\n" + }, + "compose_stack": { + "project_name": "playit-agent", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "playit-agent", + "service_count": 1, + "services": [ + { + "name": "playit-agent", + "image": "ghcr.io/mafen/playit-docker:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "restart": "unless-stopped", + "image": "ghcr.io/mafen/playit-docker:latest", + "network_mode": "bridge", + "container_name": "playit-agent" + } + } + ], + "top_level": { + "name": "playit-agent" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "playit-agent" + ], + "stop_order": [ + "playit-agent" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/plex-official.json b/oci/catalog/apps/plex-official.json new file mode 100644 index 00000000..38ac3a6e --- /dev/null +++ b/oci/catalog/apps/plex-official.json @@ -0,0 +1,528 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "image-plex-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Plex Official" + }, + "tagline": { + "en_US": "Official Plex Media Server image with optional hardware transcoding." + }, + "description": { + "en_US": "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Plex, Inc.", + "developer": "Plex, Inc.", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/plex-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/plex-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 32400, + "path": "/web" + }, + "website": "https://www.plex.tv/media-server-downloads/", + "documentation": "https://github.com/plexinc/pms-docker/blob/master/README.md", + "repository": "https://github.com/plexinc/pms-docker", + "tips": [ + "PLEX_CLAIM is optional and only used during first run.", + "Keep the Plex database on a local Proxmox-backed volume because filesystems without reliable locking can corrupt it.", + "Hardware transcoding requires Plex Pass and must also be enabled under Settings > Transcoder." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "plex", + "repository": "https://github.com/plexinc/pms-docker", + "default_branch": "master", + "revision": "d6d268472090c5620f9c505cdb20be6a86d37f5b", + "image_repository_url": "https://github.com/plexinc/pms-docker", + "compose_sha256": "9f0203d20c2c719b50111eb8c419c5c15080602e5bdf4dcf59304de6d898ddf8", + "generated_at": "2026-09-13T21:08:59+00:00" + }, + "container_contract": { + "service_name": "plex", + "container_name": "plex", + "image": { + "reference": "plexinc/pms-docker:latest", + "registry": "docker.io", + "repository": "plexinc/pms-docker", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "official-container-documentation" + }, + { + "name": "PLEX_CLAIM", + "example": "", + "required": false, + "sensitive": true, + "source": "official-container-documentation", + "prompt": "Optional token from https://www.plex.tv/claim" + }, + { + "name": "ADVERTISE_IP", + "example": "", + "required": false, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Additional URL advertised by Plex (optional)" + }, + { + "name": "PLEX_UID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "UID of the plex user (also owner of the GPU device)" + }, + { + "name": "PLEX_GID", + "example": "", + "required": false, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Optional GID of the plex group" + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "/path/to/plex/database", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 16 + } + }, + { + "id": "transcode", + "container_path": "/transcode", + "compose_source_example": "/path/to/transcode/temp", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "managed-volume", + "managed_volume": { + "backup": false, + "default_size_gb": 16 + } + }, + { + "id": "media", + "container_path": "/data", + "compose_source_example": "/path/to/media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 32400, + "published_example": 32400, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8324, + "published_example": 8324, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32469, + "published_example": 32469, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 1900, + "published_example": 1900, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32410, + "published_example": 32410, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32412, + "published_example": 32412, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32413, + "published_example": 32413, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32414, + "published_example": 32414, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n plex:\n image: plexinc/pms-docker:latest\n container_name: plex\n environment:\n - TZ=Europe/Madrid\n - PLEX_CLAIM=\n - ADVERTISE_IP=\n volumes:\n - /path/to/plex/database:/config\n - /path/to/transcode/temp:/transcode\n - /path/to/media:/data\n ports:\n - 32400:32400/tcp\n - 8324:8324/tcp\n - 32469:32469/tcp\n - 1900:1900/udp\n - 32410:32410/udp\n - 32412:32412/udp\n - 32413:32413/udp\n - 32414:32414/udp\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Plex WebUI", + "scheme": "http", + "port": 32400, + "path": "/web", + "source": "official-container-documentation" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Plex", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [], + "architectures": [ + "amd64", + "arm64" + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "uid_from_environment": "PLEX_UID" + } + ], + "architectures": [ + "amd64" + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ], + "architectures": [ + "amd64", + "arm64" + ] + } + ] + }, + "network": { + "compose_mode": "bridge" + }, + "startup_healthcheck": { + "scheme": "http", + "port": 32400, + "path": "/identity", + "timeout_seconds": 240, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "application_options": { + "hardware_transcoding": { + "show_in_catalog": true, + "selectable": true, + "requires_subscription": "Plex Pass", + "panel_configuration_required": "Settings > Transcoder > Use hardware acceleration when available" + } + }, + "catalog": { + "replaces_discovered_ids": [] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/plex.json b/oci/catalog/apps/plex.json new file mode 100644 index 00000000..66cd557a --- /dev/null +++ b/oci/catalog/apps/plex.json @@ -0,0 +1,471 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-plex", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Plex" + }, + "tagline": { + "en_US": "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster." + }, + "description": { + "en_US": "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/plex-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/plex-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 32400, + "path": "/web" + }, + "website": "https://plex.tv", + "documentation": "https://docs.linuxserver.io/images/docker-plex/", + "repository": "https://github.com/linuxserver/docker-plex", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-06", + "note": "Rebase to Ubuntu Resolute." + }, + { + "date": "2026-03-15", + "note": "Allow TMPDIR to be changed to better support read-only containers" + }, + { + "date": "2026-03-15", + "note": "Fix initial claim setup on non-root containers" + }, + { + "date": "2024-11-04", + "note": "Add Nvidia capability needed for h265" + }, + { + "date": "2024-07-18", + "note": "Rebase to Ubuntu Noble." + } + ], + "display_version": null, + "updated_at": "2026-07-06" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-plex", + "default_branch": "master", + "revision": "e7983495304389538f829afd4985256c22eb3a4b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-plex/e7983495304389538f829afd4985256c22eb3a4b/README.md", + "readme_pushed_at": "2026-09-10T19:57:19Z", + "compose_sha256": "41bd50a27b1f544d4f677bc0c46e735c145b088927204286207e2e247034c303", + "generated_at": "2026-09-13T20:38:06+00:00" + }, + "container_contract": { + "service_name": "plex", + "container_name": "plex", + "image": { + "reference": "lscr.io/linuxserver/plex:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/plex", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "VERSION", + "example": "docker", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PLEX_CLAIM", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/plex/library", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/tv", + "compose_source_example": "/path/to/tvseries", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/movies", + "compose_source_example": "/path/to/movies", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 32400, + "published_example": 32400, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n plex:\n image: lscr.io/linuxserver/plex:latest\n container_name: plex\n network_mode: host\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - VERSION=docker\n - PLEX_CLAIM= #optional\n volumes:\n - /path/to/plex/library:/config\n - /path/to/tvseries:/tv\n - /path/to/movies:/movies\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Plex WebUI", + "scheme": "http", + "port": 32400, + "path": "/web", + "source": "linuxserver-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "host" + }, + "hardware_acceleration": { + "prompt": "Hardware acceleration for Plex", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "environment_from_devices": { + "ATTACHED_DEVICES_PERMS": [ + "vaapi-render" + ] + }, + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ] + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pocketbase.json b/oci/catalog/apps/pocketbase.json new file mode 100644 index 00000000..ae67eb46 --- /dev/null +++ b/oci/catalog/apps/pocketbase.json @@ -0,0 +1,400 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-pocketbase", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "PocketBase" + }, + "tagline": { + "en_US": "Open Source realtime backend in 1 file" + }, + "description": { + "en_US": "PocketBase is an open-source backend solution that combines a real-time database, authentication, file storage, and an admin dashboard into a single, portable executable." + }, + "category": "databases", + "category_label": "Databases", + "author": "Gani Georgiev", + "developer": "Gani Georgiev", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8090, + "path": "/_/" + }, + "website": "https://pocketbase.io", + "documentation": null, + "repository": "https://hub.docker.com/r/argonptg/pocketbase", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "argonptg", + "repository": "https://hub.docker.com/r/argonptg/pocketbase", + "revision": "4aef0707f4ff990127c7fb1169f171b558e4d034858a4f363be3c68b2ca55af2", + "image_repository_url": "https://hub.docker.com/r/argonptg/pocketbase", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "4aef0707f4ff990127c7fb1169f171b558e4d034858a4f363be3c68b2ca55af2", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "pocketbase", + "container_name": "pocketbase", + "image": { + "reference": "argonptg/pocketbase:latest", + "registry": "docker.io", + "repository": "argonptg/pocketbase", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/pb_data", + "compose_source_example": "/DATA/AppData/$AppID/pb_data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8090, + "published_example": 8090, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: pocketbase\nservices:\n pocketbase:\n image: argonptg/pocketbase:latest\n deploy:\n resources:\n limits:\n memory: 1024M\n network_mode: bridge\n ports:\n - target: 8090\n published: '8090'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/pb_data\n target: /pb_data\n container_name: pocketbase\n" + }, + "compose_stack": { + "project_name": "pocketbase", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "pocketbase", + "service_count": 1, + "services": [ + { + "name": "pocketbase", + "image": "argonptg/pocketbase:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "argonptg/pocketbase:latest", + "deploy": { + "resources": { + "limits": { + "memory": "1024M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8090, + "published": "8090", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/pb_data", + "target": "/pb_data" + } + ], + "container_name": "pocketbase" + } + } + ], + "top_level": { + "name": "pocketbase" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "pocketbase-volume-0", + "service": "pocketbase", + "container_path": "/pb_data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "pocketbase" + ], + "stop_order": [ + "pocketbase" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8090, + "path": "/_/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/podfetch.json b/oci/catalog/apps/podfetch.json new file mode 100644 index 00000000..085430ab --- /dev/null +++ b/oci/catalog/apps/podfetch.json @@ -0,0 +1,460 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-podfetch", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "PodFetch" + }, + "tagline": { + "en_US": "Sleek podcast downloader with GPodder sync" + }, + "description": { + "en_US": "PodFetch is a sleek and efficient self-hosted podcast manager written in Rust. It automatically downloads new episodes of your favorite podcasts on a configurable interval and lets you listen to them from a clean, fast web UI on any device.\n\nIts standout feature is a GPodder-compatible sync API: keep using mobile podcast apps like AntennaPod while subscriptions, episode actions, and playback positions stay in sync with your server. PodFetch also supports multi-user setups with invites and roles, playlists, favorites, OPML import and export, podcast search via iTunes or Podcast Index, and optional OIDC or basic authentication.\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "SamTV12345", + "developer": "SamTV12345", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://samtv12345.github.io/PodFetch/", + "documentation": null, + "repository": "https://hub.docker.com/r/samuel19982/podfetch", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "samuel19982", + "repository": "https://hub.docker.com/r/samuel19982/podfetch", + "revision": "6fd1348f51e66429b2e961550bf90596500d86ee958ce1f3d156586f6ec1dec7", + "image_repository_url": "https://hub.docker.com/r/samuel19982/podfetch", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "6fd1348f51e66429b2e961550bf90596500d86ee958ce1f3d156586f6ec1dec7", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "podfetch", + "container_name": "podfetch", + "image": { + "reference": "samuel19982/podfetch:latest", + "registry": "docker.io", + "repository": "samuel19982/podfetch", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "DATABASE_URL", + "example": "sqlite:///app/db/podcast.db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POLLING_INTERVAL", + "example": "300", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BASIC_AUTH", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "GPODDER_INTEGRATION_ENABLED", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/podcasts", + "compose_source_example": "/DATA/AppData/$AppID/podcasts", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/app/db", + "compose_source_example": "/DATA/AppData/$AppID/db", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: podfetch\nservices:\n podfetch:\n image: samuel19982/podfetch:latest\n environment:\n DATABASE_URL: sqlite:///app/db/podcast.db\n POLLING_INTERVAL: '300'\n BASIC_AUTH: 'false'\n GPODDER_INTEGRATION_ENABLED: 'false'\n network_mode: bridge\n ports:\n - target: 8000\n published: '8000'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/podcasts\n target: /app/podcasts\n - type: bind\n source: /DATA/AppData/$AppID/db\n target: /app/db\n" + }, + "compose_stack": { + "project_name": "podfetch", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "podfetch", + "service_count": 1, + "services": [ + { + "name": "podfetch", + "image": "samuel19982/podfetch:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "samuel19982/podfetch:latest", + "environment": { + "DATABASE_URL": "sqlite:///app/db/podcast.db", + "POLLING_INTERVAL": "300", + "BASIC_AUTH": "false", + "GPODDER_INTEGRATION_ENABLED": "false" + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8000, + "published": "8000", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/podcasts", + "target": "/app/podcasts" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/db", + "target": "/app/db" + } + ] + } + } + ], + "top_level": { + "name": "podfetch" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "podfetch-volume-0", + "service": "podfetch", + "container_path": "/app/podcasts", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "podfetch-volume-1", + "service": "podfetch", + "container_path": "/app/db", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "podfetch" + ], + "stop_order": [ + "podfetch" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/portainer.json b/oci/catalog/apps/portainer.json new file mode 100644 index 00000000..8c6e065c --- /dev/null +++ b/oci/catalog/apps/portainer.json @@ -0,0 +1,457 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-portainer", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Portainer" + }, + "tagline": { + "en_US": "Lightweight Docker management UI" + }, + "description": { + "en_US": "Portainer Community Edition (CE) is a lightweight container management tool offering an intuitive Web interface to simplify building, managing, and monitoring containerized applications. With over 500,000 active users, it is widely appreciated for its ease of use and robust functionality, ideal for individual developers, home lab users, and small teams.\n\nThe tool's core features include multi-platform support, resource management, and real-time monitoring. It supports managing various container platforms, covering containers, images, volumes, and networks. Users can quickly create, deploy, and manage containers via a \u201csmart\u201d graphical interface or comprehensive API, without needing deep command-line expertise. It provides real-time container status monitoring, log viewing, and configuration management, ensuring efficient control over application operations.\n\nIts design philosophy is to \u201csimplify container complexity\u201d with an intuitive interface and default settings that lower the technical barrier. Users can manage containerized applications without complex configurations, saving time and boosting efficiency. It is completely free, with data stored locally, ensuring full user control. Community support via GitHub Discussions and Slack, along with rich documentation and regular updates, enhances the user experience, making it suitable for learning container technology or managing small projects.\n\n**Key Features:**\n- Intuitive Web interface for simplified containerized app management\n- Supports multiple container platforms for unified resource management\n- Real-time monitoring of container status and logs\n- Rapid container deployment and management via API\n- Community support with extensive documentation and assistance\n\n**Learn More:**\n- [Portainer Official Website](https://www.portainer.io/)\n- [Portainer GitHub Repository](https://github.com/portainer/portainer)\n" + }, + "category": "containers", + "category_label": "Containers & Docker", + "author": "Portainer", + "developer": "Portainer", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9000, + "path": "/" + }, + "website": "https://www.portainer.io/", + "documentation": null, + "repository": "https://hub.docker.com/r/portainer/portainer-ce", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/portainer/portainer-ce", + "revision": "a388d18353c8b3f9ed0b7d5c3fc8718af56d90f2715fc246226695a0428c2f94", + "image_repository_url": "https://hub.docker.com/r/portainer/portainer-ce", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "a388d18353c8b3f9ed0b7d5c3fc8718af56d90f2715fc246226695a0428c2f94", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "portainer", + "container_name": "portainer", + "image": { + "reference": "portainer/portainer-ce:latest", + "registry": "docker.io", + "repository": "portainer/portainer-ce", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/var/run/docker.sock", + "compose_source_example": "/var/run/docker.sock", + "read_only": false, + "required": false, + "installation_choice": [ + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9000, + "published_example": 9000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9443, + "published_example": 9443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: portainer\nservices:\n portainer:\n image: portainer/portainer-ce:latest\n deploy:\n resources:\n reservations:\n memory: 32M\n network_mode: bridge\n ports:\n - target: 8000\n published: '8000'\n protocol: tcp\n - target: 9000\n published: '9000'\n protocol: tcp\n - target: 9443\n published: '9443'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /data\n - type: bind\n source: /var/run/docker.sock\n target: /var/run/docker.sock\n container_name: portainer\n" + }, + "compose_stack": { + "project_name": "portainer", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "portainer", + "service_count": 1, + "services": [ + { + "name": "portainer", + "image": "portainer/portainer-ce:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "portainer/portainer-ce:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "32M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8000, + "published": "8000", + "protocol": "tcp" + }, + { + "target": 9000, + "published": "9000", + "protocol": "tcp" + }, + { + "target": 9443, + "published": "9443", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/data" + }, + { + "type": "bind", + "source": "/var/run/docker.sock", + "target": "/var/run/docker.sock" + } + ], + "container_name": "portainer" + } + } + ], + "top_level": { + "name": "portainer" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "portainer-volume-0", + "service": "portainer", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for portainer:/data" + }, + { + "id": "portainer-volume-1", + "service": "portainer", + "container_path": "/var/run/docker.sock", + "mode": "runtime-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "portainer" + ], + "stop_order": [ + "portainer" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/postgresql.json b/oci/catalog/apps/postgresql.json new file mode 100644 index 00000000..46c8095d --- /dev/null +++ b/oci/catalog/apps/postgresql.json @@ -0,0 +1,454 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-postgresql", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "PostgreSQL" + }, + "tagline": { + "en_US": "PostgreSQL is an advanced, enterprise-class, and open-source relational database system. PostgreSQL supports both SQL (relational) and JSON (non-relational) querying." + }, + "description": { + "en_US": "PostgreSQL is a powerful, open source object-relational database system with over 35 years of active development that has earned it a strong reputation for reliability, feature robustness, and performance.\n\nPostgreSQL is a highly stable database backed by more than 20 years of development by the open-source community.\n\nPostgreSQL is used as a primary database for many web applications as well as mobile and analytics applications.\n" + }, + "category": "databases", + "category_label": "Databases", + "author": "PostgreSQL Global Dev't Group", + "developer": "PostgreSQL Global Dev't Group", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://www.postgresql.org", + "documentation": null, + "repository": "https://hub.docker.com/_/postgres", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/_/postgres", + "revision": "d97099b5ce54753e597eb5d96762c8ba41ad78d58a50842212110a8540db452a", + "image_repository_url": "https://hub.docker.com/_/postgres", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "d97099b5ce54753e597eb5d96762c8ba41ad78d58a50842212110a8540db452a", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "postgresql", + "container_name": "postgresql", + "image": { + "reference": "postgres:latest", + "registry": "docker.io", + "repository": "postgres", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_USER", + "example": "postgresql", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_PASSWORD", + "example": "${GENERATED_POSTGRES_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "POSTGRES_DB", + "example": "postgresql", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/lib/postgresql/data", + "compose_source_example": "/DATA/AppData/postgresql/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5432, + "published_example": 5432, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: postgresql\nservices:\n postgresql:\n environment:\n PUID: $PUID\n PGID: $PGID\n TZ: $TZ\n POSTGRES_USER: postgresql\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: postgresql\n image: postgres:latest\n deploy:\n resources:\n reservations:\n memory: 2048M\n restart: unless-stopped\n ports:\n - target: 5432\n published: '5432'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/postgresql/data\n target: /var/lib/postgresql/data\n container_name: postgresql\n" + }, + "compose_stack": { + "project_name": "postgresql", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "postgresql", + "service_count": 1, + "services": [ + { + "name": "postgresql", + "image": "postgres:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PUID": "$PUID", + "PGID": "$PGID", + "TZ": "$TZ", + "POSTGRES_USER": "postgresql", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "postgresql" + }, + "image": "postgres:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "2048M" + } + } + }, + "restart": "unless-stopped", + "ports": [ + { + "target": 5432, + "published": "5432", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/postgresql/data", + "target": "/var/lib/postgresql/data" + } + ], + "container_name": "postgresql" + } + } + ], + "top_level": { + "name": "postgresql" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "postgresql-volume-0", + "service": "postgresql", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "postgresql" + ], + "stop_order": [ + "postgresql" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "postgresql", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ppsspp.json b/oci/catalog/apps/ppsspp.json new file mode 100644 index 00000000..a12c2640 --- /dev/null +++ b/oci/catalog/apps/ppsspp.json @@ -0,0 +1,256 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ppsspp", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ppsspp" + }, + "tagline": { + "en_US": "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability." + }, + "description": { + "en_US": "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ppsspp-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ppsspp-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.ppsspp.org/", + "documentation": "https://docs.linuxserver.io/images/docker-ppsspp/", + "repository": "https://github.com/linuxserver/docker-ppsspp", + "tips": [], + "mini_changelog": [ + { + "date": "2026-01-12", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-01-12" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ppsspp", + "default_branch": "master", + "revision": "bae91744a0391413ad69ce673c215d99c25b001a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ppsspp/bae91744a0391413ad69ce673c215d99c25b001a/README.md", + "readme_pushed_at": "2026-09-08T13:01:28Z", + "compose_sha256": "8b634947c60d85425c2b5f706a41563e4747c354679be3cae37dd4f6a9a8f545", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "ppsspp", + "container_name": "ppsspp", + "image": { + "reference": "lscr.io/linuxserver/ppsspp:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ppsspp", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/ppsspp/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ppsspp:\n image: lscr.io/linuxserver/ppsspp:latest\n container_name: ppsspp\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/ppsspp/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\" #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/projectsend.json b/oci/catalog/apps/projectsend.json new file mode 100644 index 00000000..e502f590 --- /dev/null +++ b/oci/catalog/apps/projectsend.json @@ -0,0 +1,257 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-projectsend", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Projectsend" + }, + "tagline": { + "en_US": "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files." + }, + "description": { + "en_US": "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files." + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/projectsend-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/projectsend-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "http://www.projectsend.org", + "documentation": "https://docs.linuxserver.io/images/docker-projectsend/", + "repository": "https://github.com/linuxserver/docker-projectsend", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-10", + "note": "Switch to legacy repo until migration steps are figured out." + }, + { + "date": "2025-12-14", + "note": "Add php ldap module." + }, + { + "date": "2025-11-16", + "note": "Add missing language files to default install." + }, + { + "date": "2025-10-14", + "note": "Rebase to 3.22." + }, + { + "date": "2025-06-06", + "note": "Add crontab handler for scheduled tasks." + } + ], + "display_version": null, + "updated_at": "2026-08-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-projectsend", + "default_branch": "master", + "revision": "a55c01acfea91d9f0155d828e46aff3ec2b34263", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-projectsend/a55c01acfea91d9f0155d828e46aff3ec2b34263/README.md", + "readme_pushed_at": "2026-09-07T23:43:11Z", + "compose_sha256": "e967c0d7e36573b730add5b0eeaba62ccdbf795a037b2fe4f4a9aa7677345042", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "projectsend", + "container_name": "projectsend", + "image": { + "reference": "lscr.io/linuxserver/projectsend:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/projectsend", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/projectsend/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n projectsend:\n image: lscr.io/linuxserver/projectsend:latest\n container_name: projectsend\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/projectsend/config:/config\n - /path/to/data:/data\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/prowlarr.json b/oci/catalog/apps/prowlarr.json new file mode 100644 index 00000000..5a979769 --- /dev/null +++ b/oci/catalog/apps/prowlarr.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-prowlarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Prowlarr" + }, + "tagline": { + "en_US": "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all)." + }, + "description": { + "en_US": "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all)." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/prowlarr-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/prowlarr-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9696, + "path": "/" + }, + "website": "https://github.com/Prowlarr/Prowlarr", + "documentation": "https://docs.linuxserver.io/images/docker-prowlarr/", + "repository": "https://github.com/linuxserver/docker-prowlarr", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-04", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-15", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase Alpine 3.22." + }, + { + "date": "2024-12-23", + "note": "Rebase Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-prowlarr", + "default_branch": "main", + "revision": "c03ac6b60306a6fadb7f5e491ddf3a6a665113df", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-prowlarr/c03ac6b60306a6fadb7f5e491ddf3a6a665113df/README.md", + "readme_pushed_at": "2026-09-09T08:40:12Z", + "compose_sha256": "9fd00779e731abb238dbcf64fdb61209138468b0d70457c1fb0e842546eb994d", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "prowlarr", + "container_name": "prowlarr", + "image": { + "reference": "lscr.io/linuxserver/prowlarr:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/prowlarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/prowlarr/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 9696, + "published_example": 9696, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n prowlarr:\n image: lscr.io/linuxserver/prowlarr:latest\n container_name: prowlarr\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/prowlarr/data:/config\n ports:\n - 9696:9696\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9696, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/psitransfer.json b/oci/catalog/apps/psitransfer.json new file mode 100644 index 00000000..e9e05e74 --- /dev/null +++ b/oci/catalog/apps/psitransfer.json @@ -0,0 +1,422 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-psitransfer", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "PsiTransfer" + }, + "tagline": { + "en_US": "A simple, open-source file sharing host." + }, + "description": { + "en_US": "PsiTransfer is a simple, self-hosted open-source file sharing service that allows you to share files securely and easily without registration.\n\n**Key Features:**\n- **No Registration Required:** Share files instantly without creating an account.\n- **Privacy and Control:** All files are stored on your own server, giving you complete control over your data.\n- **Password Protection:** Protect shared files with a password for enhanced security.\n- **Upload Expiry:** Set uploaded files to automatically expire after a specific time to save storage space.\n- **Admin Panel:** Manage all uploads through a clean admin panel.\n- **Delivery Target:** Send files to predefined email addresses (configuration required).\n- **Responsive Web Interface:** Clean and user-friendly interface that works perfectly on all devices.\n\n**Learn More:**\n- [PsiTransfer GitHub Repository](https://github.com/psi-4ward/psitransfer)\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "psitrax", + "developer": "psitrax", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/psitrax/psitransfer", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "psitrax", + "repository": "https://hub.docker.com/r/psitrax/psitransfer", + "revision": "edcb0eb5308ed8f8c7d5a3d9b85a39d0e8362f695544ccac17659a3ea2e83382", + "image_repository_url": "https://hub.docker.com/r/psitrax/psitransfer", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "edcb0eb5308ed8f8c7d5a3d9b85a39d0e8362f695544ccac17659a3ea2e83382", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "psitransfer", + "container_name": "psitransfer", + "image": { + "reference": "psitrax/psitransfer:latest", + "registry": "docker.io", + "repository": "psitrax/psitransfer", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PSITRANSFER_ADMIN_PASS", + "example": "${GENERATED_PSITRANSFER_ADMIN_PASS}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 13001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: psitransfer\nservices:\n psitransfer:\n image: psitrax/psitransfer:latest\n container_name: psitransfer\n ports:\n - target: '3000'\n published: '13001'\n protocol: tcp\n environment:\n PSITRANSFER_ADMIN_PASS: ${GENERATED_PSITRANSFER_ADMIN_PASS}\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n deploy:\n resources:\n reservations:\n memory: 256M\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "psitransfer", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "psitransfer", + "service_count": 1, + "services": [ + { + "name": "psitransfer", + "image": "psitrax/psitransfer:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "psitrax/psitransfer:latest", + "container_name": "psitransfer", + "ports": [ + { + "target": "3000", + "published": "13001", + "protocol": "tcp" + } + ], + "environment": { + "PSITRANSFER_ADMIN_PASS": "${GENERATED_PSITRANSFER_ADMIN_PASS}" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "psitransfer" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "psitransfer-volume-0", + "service": "psitransfer", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for psitransfer:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "psitransfer" + ], + "stop_order": [ + "psitransfer" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "psitransfer-admin-pass", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "psitransfer", + "environment_variable": "PSITRANSFER_ADMIN_PASS" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pwndrop.json b/oci/catalog/apps/pwndrop.json new file mode 100644 index 00000000..4177b435 --- /dev/null +++ b/oci/catalog/apps/pwndrop.json @@ -0,0 +1,248 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-pwndrop", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pwndrop" + }, + "tagline": { + "en_US": "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV." + }, + "description": { + "en_US": "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pwndrop-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pwndrop-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://github.com/kgretzky/pwndrop", + "documentation": "https://docs.linuxserver.io/images/docker-pwndrop/", + "repository": "https://github.com/linuxserver/docker-pwndrop", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-17", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2024-06-04", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-08-07", + "note": "Rebase to Alpine 3.18." + }, + { + "date": "2023-07-03", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + } + ], + "display_version": null, + "updated_at": "2026-07-17" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-pwndrop", + "default_branch": "master", + "revision": "ec2c798f586d626033387fd7035cdb284bae7d96", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-pwndrop/ec2c798f586d626033387fd7035cdb284bae7d96/README.md", + "readme_pushed_at": "2026-09-07T20:21:35Z", + "compose_sha256": "7bd7524f5122d5c770b867cd70bffd222dd73315c7571218aab163c0513a6418", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "pwndrop", + "container_name": "pwndrop", + "image": { + "reference": "lscr.io/linuxserver/pwndrop:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/pwndrop", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SECRET_PATH", + "example": "/pwndrop", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/pwndrop/appdata", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n pwndrop:\n image: lscr.io/linuxserver/pwndrop:latest\n container_name: pwndrop\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - SECRET_PATH=/pwndrop #optional\n volumes:\n - /path/to/pwndrop/appdata:/config\n ports:\n - 8080:8080\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pycharm.json b/oci/catalog/apps/pycharm.json new file mode 100644 index 00000000..f014cd01 --- /dev/null +++ b/oci/catalog/apps/pycharm.json @@ -0,0 +1,264 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-pycharm", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pycharm" + }, + "tagline": { + "en_US": "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more." + }, + "description": { + "en_US": "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pycharm-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pycharm-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.jetbrains.com/pycharm/", + "documentation": "https://docs.linuxserver.io/images/docker-pycharm/", + "repository": "https://github.com/linuxserver/docker-pycharm", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-12-02", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-04-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-pycharm", + "default_branch": "master", + "revision": "d35a38c088d403ed2036a8eb33f45da8b8dd9005", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-pycharm/d35a38c088d403ed2036a8eb33f45da8b8dd9005/README.md", + "readme_pushed_at": "2026-09-11T19:59:37Z", + "compose_sha256": "749197d7b26dfd57f1acb60e1e2cd6840157bfdb392573b62dfa1d8c6f3def1c", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "pycharm", + "container_name": "pycharm", + "image": { + "reference": "lscr.io/linuxserver/pycharm:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/pycharm", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n pycharm:\n image: lscr.io/linuxserver/pycharm:latest\n container_name: pycharm\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pydio-cells.json b/oci/catalog/apps/pydio-cells.json new file mode 100644 index 00000000..1fa523de --- /dev/null +++ b/oci/catalog/apps/pydio-cells.json @@ -0,0 +1,333 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-pydio-cells", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pydio Cells" + }, + "tagline": { + "en_US": "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture." + }, + "description": { + "en_US": "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pydio-cells-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pydio-cells-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 8080, + "path": "/" + }, + "website": "https://pydio.com/", + "documentation": "https://docs.linuxserver.io/images/docker-pydio-cells/", + "repository": "https://github.com/linuxserver/docker-pydio-cells", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-17", + "note": "Rebasing to Alpine 3.24." + }, + { + "date": "2025-07-27", + "note": "Rebasing to Alpine 3.22." + }, + { + "date": "2024-06-27", + "note": "Rebasing to Alpine 3.20." + }, + { + "date": "2024-03-14", + "note": "Rebasing to alpine 3.19. Grpc port defaults to 8080." + }, + { + "date": "2023-10-11", + "note": "Rebasing to alpine 3.18. Build on alpine edge with Go 1.21." + } + ], + "display_version": null, + "updated_at": "2026-07-17" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-pydio-cells", + "default_branch": "master", + "revision": "fafe2f795687ffcfeb9abc04ca9ddfc3e6b9ff05", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-pydio-cells/fafe2f795687ffcfeb9abc04ca9ddfc3e6b9ff05/README.md", + "readme_pushed_at": "2026-08-27T14:24:17Z", + "compose_sha256": "9618358bec84278fd83dcb9cb2f8b2c1274a730f5fb665248a7fb9e2c3da339f", + "generated_at": "2026-09-13T14:54:07+00:00" + }, + "container_contract": { + "service_name": "pydio-cells", + "container_name": "pydio-cells", + "image": { + "reference": "lscr.io/linuxserver/pydio-cells:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/pydio-cells", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EXTERNALURL", + "example": "yourdomain.url", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SERVER_IP", + "example": "0.0.0.0", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/pydio-cells/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n pydio-cells:\n image: lscr.io/linuxserver/pydio-cells:latest\n container_name: pydio-cells\n hostname: pydio-cells\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - EXTERNALURL=yourdomain.url\n - SERVER_IP=0.0.0.0 #optional\n volumes:\n - /path/to/pydio-cells/config:/config\n ports:\n - 8080:8080\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 8080, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "hostname": "pydio-cells" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/pyload-ng.json b/oci/catalog/apps/pyload-ng.json new file mode 100644 index 00000000..8ad0bc6e --- /dev/null +++ b/oci/catalog/apps/pyload-ng.json @@ -0,0 +1,264 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-pyload-ng", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Pyload Ng" + }, + "tagline": { + "en_US": "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web." + }, + "description": { + "en_US": "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pyload-ng-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pyload-ng-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://pyload.net/", + "documentation": "https://docs.linuxserver.io/images/docker-pyload-ng/", + "repository": "https://github.com/linuxserver/docker-pyload-ng", + "tips": [], + "mini_changelog": [ + { + "date": "2026-01-09", + "note": "Add gcompat for mini-racer." + }, + { + "date": "2025-09-01", + "note": "Add new dep, libatomic." + }, + { + "date": "2025-06-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-07-20", + "note": "Revert to Alpine 3.19 due to inconsistent upstream addon support for Python 3.12." + }, + { + "date": "2024-06-27", + "note": "Rebase to Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-01-09" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-pyload-ng", + "default_branch": "main", + "revision": "e71fe7b5258fe4ba3c71062a4c89fbdda795ef14", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-pyload-ng/e71fe7b5258fe4ba3c71062a4c89fbdda795ef14/README.md", + "readme_pushed_at": "2026-09-11T22:03:25Z", + "compose_sha256": "be4d539685af4c47d8c55aa2dce004bd7b2d478fc0fe64abbb0fb9e00a321de4", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "pyload-ng", + "container_name": "pyload-ng", + "image": { + "reference": "lscr.io/linuxserver/pyload-ng:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/pyload-ng", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/pyload-ng/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9666, + "published_example": 9666, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n pyload-ng:\n image: lscr.io/linuxserver/pyload-ng:latest\n container_name: pyload-ng\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/pyload-ng/config:/config\n - /path/to/downloads:/downloads\n ports:\n - 8000:8000\n - 9666:9666 #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/qbittorrent-hotio.json b/oci/catalog/apps/qbittorrent-hotio.json new file mode 100644 index 00000000..1b52183c --- /dev/null +++ b/oci/catalog/apps/qbittorrent-hotio.json @@ -0,0 +1,468 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-qbittorrent-hotio", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "qBittorrent" + }, + "tagline": { + "en_US": "P2P bittorrent download" + }, + "description": { + "en_US": "**Elevate Your Home Media Experience**. qBittorrent transforms your home media setup with a polished interface reminiscent of \u00b5Torrent, minus the ads. Unlike traditional download tools, it offers a streamlined, efficient, and ad-free experience. This makes it a perfect fit for those seeking a hassle-free way to manage and enjoy their media collections at home.\n\n**Feature-Rich and User-Friendly**. With qBittorrent, you gain access to a well-integrated and extensible search engine, allowing simultaneous searches across multiple torrent sites, and category-specific searches for books, music, and software. Its support for RSS feeds with advanced filters, magnet links, encrypted connections, and more, ensures you have complete control over your downloads. Available on all major platforms and in around 70 languages, qBittorrent is both versatile and accessible.\n\n**Seamless Integration with Private Clouds like self-hosted server**. Deploying qBittorrent on private cloud devices such as self-hosted server offers unparalleled convenience. Enjoy virtually unlimited storage, enhanced privacy for your data, and local network speeds that make downloading and streaming effortless. This setup ensures that your media library is always at your fingertips, securely and swiftly.\n" + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "qBittorrent", + "developer": "qBittorrent", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://www.qbittorrent.org", + "documentation": null, + "repository": "https://ghcr.io/hotio/qbittorrent", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "hotio", + "repository": "https://ghcr.io/hotio/qbittorrent", + "revision": "e7277780936e31302428de9ac97ed42ffc7b83456150974cb407078d32cdab8f", + "image_repository_url": "https://ghcr.io/hotio/qbittorrent", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "e7277780936e31302428de9ac97ed42ffc7b83456150974cb407078d32cdab8f", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "qbittorrent", + "container_name": "qbittorrent", + "image": { + "reference": "ghcr.io/hotio/qbittorrent:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/hotio/qbittorrent", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "UMASK", + "example": "002", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/DATA", + "compose_source_example": "/DATA", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8181, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: qbittorrent\nservices:\n qbittorrent:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n UMASK: '002'\n image: ghcr.io/hotio/qbittorrent:latest\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n ports:\n - target: 8080\n published: '8181'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA\n target: /DATA\n container_name: qbittorrent\n" + }, + "compose_stack": { + "project_name": "qbittorrent", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "qbittorrent", + "service_count": 1, + "services": [ + { + "name": "qbittorrent", + "image": "ghcr.io/hotio/qbittorrent:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ", + "UMASK": "002" + }, + "image": "ghcr.io/hotio/qbittorrent:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8080, + "published": "8181", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA", + "target": "/DATA" + } + ], + "container_name": "qbittorrent" + } + } + ], + "top_level": { + "name": "qbittorrent" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "qbittorrent-volume-0", + "service": "qbittorrent", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "qbittorrent-volume-1", + "service": "qbittorrent", + "container_path": "/DATA", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for qbittorrent:/DATA" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "qbittorrent" + ], + "stop_order": [ + "qbittorrent" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/qbittorrent.json b/oci/catalog/apps/qbittorrent.json new file mode 100644 index 00000000..335ca381 --- /dev/null +++ b/oci/catalog/apps/qbittorrent.json @@ -0,0 +1,300 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-qbittorrent", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Qbittorrent" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "" + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/qbittorrent-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/qbittorrent-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": null, + "documentation": "https://docs.linuxserver.io/images/docker-qbittorrent/", + "repository": "https://github.com/linuxserver/docker-qbittorrent", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-05-04", + "note": "Switch to static builds for parity with libtorrentv1 branch. Rebase to Alpine 3.23." + }, + { + "date": "2024-07-17", + "note": "Restore qbittorrent-cli as it now supports openssl 3." + }, + { + "date": "2024-05-25", + "note": "Remove qbittorrent-cli as it still requires openssl 1.1 which is EOL." + }, + { + "date": "2024-02-14", + "note": "Only set/override torrenting port if the optional env var is set." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-qbittorrent", + "default_branch": "master", + "revision": "7ea424e9205850ccbcc25b9a902134f401ee0de8", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-qbittorrent/7ea424e9205850ccbcc25b9a902134f401ee0de8/README.md", + "readme_pushed_at": "2026-09-06T11:41:35Z", + "compose_sha256": "a7407d30438c65d6657b3af10514028fe203fd3de5b5ec514c6e1f98d9b03071", + "generated_at": "2026-09-12T14:50:16+00:00" + }, + "container_contract": { + "service_name": "qbittorrent", + "container_name": "qbittorrent", + "image": { + "reference": "lscr.io/linuxserver/qbittorrent:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/qbittorrent", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "WEBUI_PORT", + "example": "8080", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TORRENTING_PORT", + "example": "6881", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/qbittorrent/appdata", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 6881, + "published_example": 6881, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 6881, + "published_example": 6881, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": "10s", + "original_compose": "---\nservices:\n qbittorrent:\n image: lscr.io/linuxserver/qbittorrent:latest\n container_name: qbittorrent\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - WEBUI_PORT=8080\n - TORRENTING_PORT=6881\n volumes:\n - /path/to/qbittorrent/appdata:/config\n - /path/to/downloads:/downloads #optional\n ports:\n - 8080:8080\n - 6881:6881\n - 6881:6881/udp\n stop_grace_period: \"10s\" #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [ + { + "label": "Temporary login", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": { + "method": "container-console-pattern", + "pattern_id": "linuxserver-temporary-password", + "timeout_seconds": 90 + } + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 10 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "pending-per-application" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/qdirstat.json b/oci/catalog/apps/qdirstat.json new file mode 100644 index 00000000..90bf3c77 --- /dev/null +++ b/oci/catalog/apps/qdirstat.json @@ -0,0 +1,389 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-qdirstat", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Qdirstat" + }, + "tagline": { + "en_US": "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat." + }, + "description": { + "en_US": "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/qdirstat-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/qdirstat-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/shundhammer/qdirstat", + "documentation": "https://docs.linuxserver.io/images/docker-qdirstat/", + "repository": "https://github.com/linuxserver/docker-qdirstat", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to resolute." + }, + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-01-18", + "note": "Update build logic for Qt6 and version 2.0." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-qdirstat", + "default_branch": "master", + "revision": "e16a3ccc0e4d3c4ebddc77fc98e136d1ff9dfe09", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-qdirstat/e16a3ccc0e4d3c4ebddc77fc98e136d1ff9dfe09/README.md", + "readme_pushed_at": "2026-09-06T22:49:49Z", + "compose_sha256": "8801ce61a6bf3393a8e6e827eaf4de9d65e64c289d7c7d6705e826f2eda9d8d9", + "generated_at": "2026-09-12T14:38:06+00:00" + }, + "container_contract": { + "service_name": "qdirstat", + "container_name": "qdirstat", + "image": { + "reference": "lscr.io/linuxserver/qdirstat:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/qdirstat", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/qdirstat/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n qdirstat:\n image: lscr.io/linuxserver/qdirstat:latest\n container_name: qdirstat\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/qdirstat/config:/config\n - /path/to/data:/data\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-qdirstat/master/Dockerfile", + "dockerfile_sha256": "4757c227ff57423027521037d12ca2076874b5fe293f3486dea6d55df7be078e", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/qui.json b/oci/catalog/apps/qui.json new file mode 100644 index 00000000..faa844c8 --- /dev/null +++ b/oci/catalog/apps/qui.json @@ -0,0 +1,524 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-qui", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Qui" + }, + "tagline": { + "en_US": "Fast, modern web interface for qBittorrent" + }, + "description": { + "en_US": "**One dashboard for all your qBittorrent instances.** Qui is a fast, modern web interface for qBittorrent. Instead of juggling several separate WebUI tabs, you connect every qBittorrent instance to Qui and manage them all from a single, responsive dashboard. It ships as a lightweight single binary, so it stays quick and resource-friendly even when you are watching thousands of torrents.\n\n**Automation and cross-seeding built in.** Built by the team behind autobrr, Qui goes well beyond basic torrent listing. It adds powerful rule-based automation, built-in cross-seeding that automatically finds and adds matching torrents across your trackers, scheduled backups with restore, and a clean multi-language interface. Point it at your Torznab-compatible indexers \u2014 such as Prowlarr or Jackett \u2014 to put cross-seeding on autopilot, then filter, search, and bulk-manage torrents across every instance at once.\n\n**Made for your private cloud.** Running Qui on a private cloud device like self-hosted server keeps everything in one place on hardware you control. Pair it with your qBittorrent containers for local-network speeds, full ownership of your data, and a single tidy interface for your entire download stack \u2014 accessible from any device in your home.\n" + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "autobrr", + "developer": "autobrr", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 7476, + "path": "/" + }, + "website": "https://getqui.com", + "documentation": null, + "repository": "https://ghcr.io/autobrr/qui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "autobrr", + "repository": "https://ghcr.io/autobrr/qui", + "revision": "ad5ca109561362840d4319a338d33842961d5552b096a1c70f895cce4c189871", + "image_repository_url": "https://ghcr.io/autobrr/qui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "ad5ca109561362840d4319a338d33842961d5552b096a1c70f895cce4c189871", + "generated_at": "2026-09-13T15:48:32+00:00" + }, + "container_contract": { + "service_name": "qui", + "container_name": "qui", + "image": { + "reference": "ghcr.io/autobrr/qui:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/autobrr/qui", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "QUI__DATABASE_ENGINE", + "example": "postgres", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "QUI__DATABASE_DSN", + "example": "postgres://qui:qui@qui-postgres:5432/qui?sslmode=disable", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/qui", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 7476, + "published_example": 7476, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "postgres", + "image": "postgres:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: qui\nservices:\n qui:\n container_name: qui\n image: ghcr.io/autobrr/qui:latest\n restart: unless-stopped\n depends_on:\n postgres:\n condition: service_healthy\n deploy:\n resources:\n reservations:\n memory: 128M\n ports:\n - 7476:7476\n volumes:\n - /DATA/AppData/$AppID/qui:/config\n environment:\n QUI__DATABASE_ENGINE: postgres\n QUI__DATABASE_DSN: postgres://qui:qui@qui-postgres:5432/qui?sslmode=disable\n networks:\n - qui_network\n postgres:\n container_name: qui-postgres\n image: postgres:latest\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 128M\n environment:\n POSTGRES_USER: qui\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: qui\n volumes:\n - /DATA/AppData/$AppID/postgres:/var/lib/postgresql/data\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U $$POSTGRES_USER -d $$POSTGRES_DB\n interval: 10s\n timeout: 5s\n retries: 5\n networks:\n - qui_network\nnetworks:\n qui_network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "qui", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "qui", + "service_count": 2, + "services": [ + { + "name": "postgres", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "qui-postgres", + "image": "postgres:latest", + "restart": "unless-stopped", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "environment": { + "POSTGRES_USER": "qui", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "qui" + }, + "volumes": [ + "/DATA/AppData/$AppID/postgres:/var/lib/postgresql/data" + ], + "healthcheck": { + "test": [ + "CMD-SHELL", + "pg_isready -U $$POSTGRES_USER -d $$POSTGRES_DB" + ], + "interval": "10s", + "timeout": "5s", + "retries": 5 + }, + "networks": [ + "qui_network" + ] + } + }, + { + "name": "qui", + "image": "ghcr.io/autobrr/qui:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "postgres" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "qui", + "image": "ghcr.io/autobrr/qui:latest", + "restart": "unless-stopped", + "depends_on": { + "postgres": { + "condition": "service_healthy" + } + }, + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "ports": [ + "7476:7476" + ], + "volumes": [ + "/DATA/AppData/$AppID/qui:/config" + ], + "environment": { + "QUI__DATABASE_ENGINE": "postgres", + "QUI__DATABASE_DSN": "postgres://qui:qui@qui-postgres:5432/qui?sslmode=disable" + }, + "networks": [ + "qui_network" + ] + } + } + ], + "top_level": { + "name": "qui", + "networks": { + "qui_network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "qui-volume-0", + "service": "qui", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "postgres-volume-0", + "service": "postgres", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "postgres", + "qui" + ], + "stop_order": [ + "qui", + "postgres" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "postgres", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7476, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/radarr.json b/oci/catalog/apps/radarr.json new file mode 100644 index 00000000..3b6a8081 --- /dev/null +++ b/oci/catalog/apps/radarr.json @@ -0,0 +1,275 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-radarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Radarr" + }, + "tagline": { + "en_US": "Radarr - A fork of Sonarr to work with movies \u00e0 la Couchpotato." + }, + "description": { + "en_US": "Radarr - A fork of Sonarr to work with movies \u00e0 la Couchpotato." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/radarr-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/radarr-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 7878, + "path": "/" + }, + "website": "https://github.com/Radarr/Radarr", + "documentation": "https://docs.linuxserver.io/images/docker-radarr/", + "repository": "https://github.com/linuxserver/docker-radarr", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-04", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-15", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-23", + "note": "Rebase Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-radarr", + "default_branch": "master", + "revision": "6fea55f24c3bab025a2651450ac02a62c7662319", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-radarr/6fea55f24c3bab025a2651450ac02a62c7662319/README.md", + "readme_pushed_at": "2026-09-11T22:00:14Z", + "compose_sha256": "ebb86fe538183f8e29344d0c9a08e43a748e720053df29ce4eb51c79aaa3f0d5", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "radarr", + "container_name": "radarr", + "image": { + "reference": "lscr.io/linuxserver/radarr:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/radarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/radarr/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/movies", + "compose_source_example": "/path/to/movies", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/path/to/download-client-downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 7878, + "published_example": 7878, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n radarr:\n image: lscr.io/linuxserver/radarr:latest\n container_name: radarr\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/radarr/data:/config\n - /path/to/movies:/movies #optional\n - /path/to/download-client-downloads:/downloads #optional\n ports:\n - 7878:7878\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7878, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ragflow.json b/oci/catalog/apps/ragflow.json new file mode 100644 index 00000000..47a48b01 --- /dev/null +++ b/oci/catalog/apps/ragflow.json @@ -0,0 +1,1283 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-ragflow", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "RagFlow" + }, + "tagline": { + "en_US": "RagFlow is an open-source RAG engine based on deep document understanding." + }, + "description": { + "en_US": "RagFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. It enables users to build their own private ChatGPT by leveraging the power of large language models and deep document parsing capabilities. RagFlow supports various document formats including PDF, Word, Markdown, and more, allowing users to create intelligent question-answering systems based on their own documents.\n\n**Key Features:**\n- Deep document understanding with advanced parsing capabilities\n- Support for multiple document formats (PDF, Word, Markdown, etc.)\n- Private knowledge base with data security assurance\n- Customizable RAG workflows for different use cases\n- Integration with popular large language models\n- Web-based interface for easy management and interaction\n\n**Hardware Requirements:**\n- CPU >= 4 cores\n- RAM >= 16 GB\n- Disk >= 50 GB\n\n**Learn More:**\n- [RagFlow Official Website](https://ragflow.io)\n- [RagFlow GitHub Repository](https://github.com/infiniflow/ragflow)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "RagFlow", + "developer": "RagFlow", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://ragflow.io", + "documentation": null, + "repository": "https://hub.docker.com/r/icewhaletech/ragflow", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "icewhaletech", + "repository": "https://hub.docker.com/r/icewhaletech/ragflow", + "revision": "2481edea5fc620a90beaff48f4a39b34de4279fbc34b73e5a2f562fde77fe6f0", + "image_repository_url": "https://hub.docker.com/r/icewhaletech/ragflow", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "2481edea5fc620a90beaff48f4a39b34de4279fbc34b73e5a2f562fde77fe6f0", + "generated_at": "2026-09-13T15:53:11+00:00" + }, + "container_contract": { + "service_name": "ragflow", + "container_name": "ragflow-server", + "image": { + "reference": "icewhaletech/ragflow:latest", + "registry": "docker.io", + "repository": "icewhaletech/ragflow", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ES_HOST", + "example": "ragflow-es01", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "INFINITY_HOST", + "example": "ragflow-infinity", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MINIO_HOST", + "example": "ragflow-minio", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MYSQL_HOST", + "example": "ragflow-mysql", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "OS_HOST", + "example": "ragflow-opensearch01", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REDIS_HOST", + "example": "ragflow-redis", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/ragflow/logs", + "compose_source_example": "/DATA/AppData/$AppID/ragflow-logs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/ragflow/history_data_agent", + "compose_source_example": "/DATA/AppData/$AppID/history_data_agent", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 9380, + "published_example": 9380, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 80, + "published_example": 30080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 10443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 5678, + "published_example": 5678, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 5679, + "published_example": 5679, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9382, + "published_example": 9382, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "ragflow-es01", + "image": "elasticsearch:latest" + }, + { + "name": "ragflow-infinity", + "image": "icewhaletech/ragflow-infinity:latest" + }, + { + "name": "ragflow-minio", + "image": "quay.io/minio/minio:latest" + }, + { + "name": "ragflow-mysql", + "image": "icewhaletech/ragflow-mysql:latest" + }, + { + "name": "ragflow-opensearch01", + "image": "opensearchproject/opensearch:latest" + }, + { + "name": "ragflow-redis", + "image": "valkey/valkey:latest" + }, + { + "name": "ragflow-sandbox-executor-manager", + "image": "infiniflow/sandbox-executor-manager:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: ragflow\nservices:\n ragflow:\n container_name: ragflow-server\n depends_on:\n ragflow-mysql:\n condition: service_healthy\n required: true\n deploy:\n resources:\n reservations:\n memory: 8G\n environment:\n - ES_HOST=ragflow-es01\n - INFINITY_HOST=ragflow-infinity\n - MINIO_HOST=ragflow-minio\n - MYSQL_HOST=ragflow-mysql\n - OS_HOST=ragflow-opensearch01\n - REDIS_HOST=ragflow-redis\n - TZ=$TZ\n extra_hosts:\n - host.docker.internal:host-gateway\n image: icewhaletech/ragflow:latest\n ports:\n - target: 9380\n published: '9380'\n protocol: tcp\n - target: 80\n published: '30080'\n protocol: tcp\n - target: 443\n published: '10443'\n protocol: tcp\n - target: 5678\n published: '5678'\n protocol: tcp\n - target: 5679\n published: '5679'\n protocol: tcp\n - target: 9382\n published: '9382'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/ragflow-logs\n target: /ragflow/logs\n bind:\n create_host_path: true\n - type: bind\n source: /DATA/AppData/$AppID/history_data_agent\n target: /ragflow/history_data_agent\n bind:\n create_host_path: true\n networks:\n - ragflow\n privileged: false\n cpu_shares: 90\n ragflow-es01:\n container_name: ragflow-es01\n deploy:\n resources:\n reservations:\n memory: 3G\n environment:\n - ELASTIC_PASSWORD=${GENERATED_ELASTIC_PASSWORD}\n - TZ=$TZ\n - bootstrap.memory_lock=false\n - cluster.routing.allocation.disk.watermark.flood_stage=2gb\n - cluster.routing.allocation.disk.watermark.high=3gb\n - cluster.routing.allocation.disk.watermark.low=5gb\n - discovery.type=single-node\n - node.name=es01\n - xpack.security.enabled=true\n - xpack.security.http.ssl.enabled=false\n - xpack.security.transport.ssl.enabled=false\n healthcheck:\n test:\n - CMD-SHELL\n - curl http://localhost:9200\n timeout: 10s\n interval: 10s\n retries: 120\n image: elasticsearch:latest\n ports:\n - target: 9200\n published: '9200'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/es01\n target: /usr/share/elasticsearch/data\n networks:\n - ragflow\n privileged: false\n cpu_shares: 90\n ragflow-infinity:\n container_name: ragflow-infinity\n environment:\n - TZ=$TZ\n healthcheck:\n test:\n - CMD\n - curl\n - http://localhost:23820/admin/node/current\n timeout: 10s\n interval: 10s\n retries: 120\n image: icewhaletech/ragflow-infinity:latest\n ports:\n - target: 23817\n published: '23817'\n protocol: tcp\n - target: 23820\n published: '23820'\n protocol: tcp\n - target: 5432\n published: '15432'\n protocol: tcp\n restart: unless-stopped\n ulimits:\n nofile:\n soft: 500000\n hard: 500000\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/infinity\n target: /var/infinity\n networks:\n - ragflow\n privileged: false\n cpu_shares: 90\n deploy:\n resources:\n reservations:\n memory: 1.5G\n ragflow-minio:\n command:\n - server\n - --console-address\n - :9001\n - /data\n container_name: ragflow-minio\n deploy:\n resources:\n reservations:\n memory: 512M\n environment:\n - MINIO_ROOT_PASSWORD=${GENERATED_MINIO_ROOT_PASSWORD}\n - MINIO_ROOT_USER=rag_flow\n - TZ=$TZ\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:9000/minio/health/live\n timeout: 20s\n interval: 30s\n retries: 3\n image: quay.io/minio/minio:latest\n ports:\n - target: 9000\n published: '9000'\n protocol: tcp\n - target: 9001\n published: '9001'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/minio\n target: /data\n networks:\n - ragflow\n privileged: false\n cpu_shares: 90\n ragflow-mysql:\n command:\n - --max_connections=1000\n - --character-set-server=utf8mb4\n - --collation-server=utf8mb4_unicode_ci\n - --default-authentication-plugin=mysql_native_password\n - --tls_version=TLSv1.2,TLSv1.3\n - --binlog_expire_logs_seconds=604800\n container_name: ragflow-mysql\n deploy:\n resources:\n reservations:\n memory: 512M\n environment:\n - MYSQL_PASSWORD=${GENERATED_MYSQL_PASSWORD}\n - MYSQL_ROOT_PASSWORD=${GENERATED_MYSQL_ROOT_PASSWORD}\n - TZ=$TZ\n healthcheck:\n test:\n - CMD\n - mysqladmin\n - ping\n - -uroot\n - -pinfini_rag_flow\n timeout: 10s\n interval: 10s\n retries: 10\n start_period: 90s\n image: icewhaletech/ragflow-mysql:latest\n ports:\n - target: 3306\n published: '5455'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/mysql\n target: /var/lib/mysql\n networks:\n - ragflow\n privileged: false\n cpu_shares: 90\n ragflow-opensearch01:\n container_name: ragflow-opensearch-01\n deploy:\n resources:\n reservations:\n memory: 2G\n environment:\n - OPENSEARCH_INITIAL_ADMIN_PASSWORD=${GENERATED_OPENSEARCH_INITIAL_ADMIN_PASSWORD}\n - OPENSEARCH_PASSWORD=${GENERATED_OPENSEARCH_PASSWORD}\n - TZ=$TZ\n - bootstrap.memory_lock=false\n - cluster.routing.allocation.disk.watermark.flood_stage=2gb\n - cluster.routing.allocation.disk.watermark.high=3gb\n - cluster.routing.allocation.disk.watermark.low=5gb\n - discovery.type=single-node\n - http.port=9201\n - node.name=opensearch01\n - plugins.security.disabled=false\n - plugins.security.ssl.http.enabled=false\n - plugins.security.ssl.transport.enabled=true\n healthcheck:\n test:\n - CMD-SHELL\n - curl http://localhost:9201\n timeout: 10s\n interval: 10s\n retries: 120\n image: opensearchproject/opensearch:latest\n ports:\n - target: 9201\n published: '9201'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/opensearch01\n target: /usr/share/opensearch/data\n networks:\n - ragflow\n privileged: false\n cpu_shares: 90\n ragflow-redis:\n command:\n - redis-server\n - --requirepass\n - infini_rag_flow\n - --maxmemory\n - 128mb\n - --maxmemory-policy\n - allkeys-lru\n container_name: ragflow-redis\n deploy:\n resources:\n reservations:\n memory: 512M\n healthcheck:\n test:\n - CMD\n - redis-cli\n - -a\n - infini_rag_flow\n - ping\n timeout: 3s\n interval: 5s\n retries: 3\n start_period: 10s\n image: valkey/valkey:latest\n ports:\n - target: 6379\n published: '6379'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/redis\n target: /data\n networks:\n - ragflow\n privileged: false\n cpu_shares: 90\n ragflow-sandbox-executor-manager:\n container_name: ragflow-sandbox-executor-manager\n deploy:\n resources:\n limits:\n memory: 7656M\n reservations:\n memory: 512M\n environment:\n - SANDBOX_BASE_NODEJS_IMAGE=infiniflow/sandbox-base-nodejs:latest\n - SANDBOX_BASE_PYTHON_IMAGE=infiniflow/sandbox-base-python:latest\n - SANDBOX_ENABLE_SECCOMP=false\n - SANDBOX_EXECUTOR_MANAGER_POOL_SIZE=3\n - SANDBOX_MAX_MEMORY=256m\n - SANDBOX_TIMEOUT=10s\n - TZ=$TZ\n healthcheck:\n test:\n - CMD\n - curl\n - http://localhost:9385/healthz\n timeout: 5s\n interval: 10s\n retries: 5\n image: infiniflow/sandbox-executor-manager:latest\n ports:\n - target: 9385\n published: '9385'\n protocol: tcp\n privileged: true\n restart: unless-stopped\n security_opt:\n - no-new-privileges:true\n volumes:\n - type: bind\n source: /var/run/docker.sock\n target: /var/run/docker.sock\n bind:\n create_host_path: true\n networks:\n - ragflow\n cpu_shares: 90\nnetworks:\n ragflow:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "ragflow", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "ragflow", + "service_count": 8, + "services": [ + { + "name": "ragflow-es01", + "image": "elasticsearch:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "ragflow-es01", + "deploy": { + "resources": { + "reservations": { + "memory": "3G" + } + } + }, + "environment": [ + "ELASTIC_PASSWORD=${GENERATED_ELASTIC_PASSWORD}", + "TZ=$TZ", + "bootstrap.memory_lock=false", + "cluster.routing.allocation.disk.watermark.flood_stage=2gb", + "cluster.routing.allocation.disk.watermark.high=3gb", + "cluster.routing.allocation.disk.watermark.low=5gb", + "discovery.type=single-node", + "node.name=es01", + "xpack.security.enabled=true", + "xpack.security.http.ssl.enabled=false", + "xpack.security.transport.ssl.enabled=false" + ], + "healthcheck": { + "test": [ + "CMD-SHELL", + "curl http://localhost:9200" + ], + "timeout": "10s", + "interval": "10s", + "retries": 120 + }, + "image": "elasticsearch:latest", + "ports": [ + { + "target": 9200, + "published": "9200", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/es01", + "target": "/usr/share/elasticsearch/data" + } + ], + "networks": [ + "ragflow" + ], + "privileged": false, + "cpu_shares": 90 + } + }, + { + "name": "ragflow-infinity", + "image": "icewhaletech/ragflow-infinity:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "ragflow-infinity", + "environment": [ + "TZ=$TZ" + ], + "healthcheck": { + "test": [ + "CMD", + "curl", + "http://localhost:23820/admin/node/current" + ], + "timeout": "10s", + "interval": "10s", + "retries": 120 + }, + "image": "icewhaletech/ragflow-infinity:latest", + "ports": [ + { + "target": 23817, + "published": "23817", + "protocol": "tcp" + }, + { + "target": 23820, + "published": "23820", + "protocol": "tcp" + }, + { + "target": 5432, + "published": "15432", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "ulimits": { + "nofile": { + "soft": 500000, + "hard": 500000 + } + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/infinity", + "target": "/var/infinity" + } + ], + "networks": [ + "ragflow" + ], + "privileged": false, + "cpu_shares": 90, + "deploy": { + "resources": { + "reservations": { + "memory": "1.5G" + } + } + } + } + }, + { + "name": "ragflow-minio", + "image": "quay.io/minio/minio:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "command": [ + "server", + "--console-address", + ":9001", + "/data" + ], + "container_name": "ragflow-minio", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "environment": [ + "MINIO_ROOT_PASSWORD=${GENERATED_MINIO_ROOT_PASSWORD}", + "MINIO_ROOT_USER=rag_flow", + "TZ=$TZ" + ], + "healthcheck": { + "test": [ + "CMD", + "curl", + "-f", + "http://localhost:9000/minio/health/live" + ], + "timeout": "20s", + "interval": "30s", + "retries": 3 + }, + "image": "quay.io/minio/minio:latest", + "ports": [ + { + "target": 9000, + "published": "9000", + "protocol": "tcp" + }, + { + "target": 9001, + "published": "9001", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/minio", + "target": "/data" + } + ], + "networks": [ + "ragflow" + ], + "privileged": false, + "cpu_shares": 90 + } + }, + { + "name": "ragflow-mysql", + "image": "icewhaletech/ragflow-mysql:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 4, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "command": [ + "--max_connections=1000", + "--character-set-server=utf8mb4", + "--collation-server=utf8mb4_unicode_ci", + "--default-authentication-plugin=mysql_native_password", + "--tls_version=TLSv1.2,TLSv1.3", + "--binlog_expire_logs_seconds=604800" + ], + "container_name": "ragflow-mysql", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "environment": [ + "MYSQL_PASSWORD=${GENERATED_MYSQL_PASSWORD}", + "MYSQL_ROOT_PASSWORD=${GENERATED_MYSQL_ROOT_PASSWORD}", + "TZ=$TZ" + ], + "healthcheck": { + "test": [ + "CMD", + "mysqladmin", + "ping", + "-uroot", + "-pinfini_rag_flow" + ], + "timeout": "10s", + "interval": "10s", + "retries": 10, + "start_period": "90s" + }, + "image": "icewhaletech/ragflow-mysql:latest", + "ports": [ + { + "target": 3306, + "published": "5455", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/mysql", + "target": "/var/lib/mysql" + } + ], + "networks": [ + "ragflow" + ], + "privileged": false, + "cpu_shares": 90 + } + }, + { + "name": "ragflow-opensearch01", + "image": "opensearchproject/opensearch:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 5, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "ragflow-opensearch-01", + "deploy": { + "resources": { + "reservations": { + "memory": "2G" + } + } + }, + "environment": [ + "OPENSEARCH_INITIAL_ADMIN_PASSWORD=${GENERATED_OPENSEARCH_INITIAL_ADMIN_PASSWORD}", + "OPENSEARCH_PASSWORD=${GENERATED_OPENSEARCH_PASSWORD}", + "TZ=$TZ", + "bootstrap.memory_lock=false", + "cluster.routing.allocation.disk.watermark.flood_stage=2gb", + "cluster.routing.allocation.disk.watermark.high=3gb", + "cluster.routing.allocation.disk.watermark.low=5gb", + "discovery.type=single-node", + "http.port=9201", + "node.name=opensearch01", + "plugins.security.disabled=false", + "plugins.security.ssl.http.enabled=false", + "plugins.security.ssl.transport.enabled=true" + ], + "healthcheck": { + "test": [ + "CMD-SHELL", + "curl http://localhost:9201" + ], + "timeout": "10s", + "interval": "10s", + "retries": 120 + }, + "image": "opensearchproject/opensearch:latest", + "ports": [ + { + "target": 9201, + "published": "9201", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/opensearch01", + "target": "/usr/share/opensearch/data" + } + ], + "networks": [ + "ragflow" + ], + "privileged": false, + "cpu_shares": 90 + } + }, + { + "name": "ragflow-redis", + "image": "valkey/valkey:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 6, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "command": [ + "redis-server", + "--requirepass", + "infini_rag_flow", + "--maxmemory", + "128mb", + "--maxmemory-policy", + "allkeys-lru" + ], + "container_name": "ragflow-redis", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "healthcheck": { + "test": [ + "CMD", + "redis-cli", + "-a", + "infini_rag_flow", + "ping" + ], + "timeout": "3s", + "interval": "5s", + "retries": 3, + "start_period": "10s" + }, + "image": "valkey/valkey:latest", + "ports": [ + { + "target": 6379, + "published": "6379", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/redis", + "target": "/data" + } + ], + "networks": [ + "ragflow" + ], + "privileged": false, + "cpu_shares": 90 + } + }, + { + "name": "ragflow-sandbox-executor-manager", + "image": "infiniflow/sandbox-executor-manager:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 7, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "ragflow-sandbox-executor-manager", + "deploy": { + "resources": { + "limits": { + "memory": "7656M" + }, + "reservations": { + "memory": "512M" + } + } + }, + "environment": [ + "SANDBOX_BASE_NODEJS_IMAGE=infiniflow/sandbox-base-nodejs:latest", + "SANDBOX_BASE_PYTHON_IMAGE=infiniflow/sandbox-base-python:latest", + "SANDBOX_ENABLE_SECCOMP=false", + "SANDBOX_EXECUTOR_MANAGER_POOL_SIZE=3", + "SANDBOX_MAX_MEMORY=256m", + "SANDBOX_TIMEOUT=10s", + "TZ=$TZ" + ], + "healthcheck": { + "test": [ + "CMD", + "curl", + "http://localhost:9385/healthz" + ], + "timeout": "5s", + "interval": "10s", + "retries": 5 + }, + "image": "infiniflow/sandbox-executor-manager:latest", + "ports": [ + { + "target": 9385, + "published": "9385", + "protocol": "tcp" + } + ], + "privileged": true, + "restart": "unless-stopped", + "security_opt": [ + "no-new-privileges:true" + ], + "volumes": [ + { + "type": "bind", + "source": "/var/run/docker.sock", + "target": "/var/run/docker.sock", + "bind": { + "create_host_path": true + } + } + ], + "networks": [ + "ragflow" + ], + "cpu_shares": 90 + } + }, + { + "name": "ragflow", + "image": "icewhaletech/ragflow:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "ragflow-mysql" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "ragflow-server", + "depends_on": { + "ragflow-mysql": { + "condition": "service_healthy", + "required": true + } + }, + "deploy": { + "resources": { + "reservations": { + "memory": "8G" + } + } + }, + "environment": [ + "ES_HOST=ragflow-es01", + "INFINITY_HOST=ragflow-infinity", + "MINIO_HOST=ragflow-minio", + "MYSQL_HOST=ragflow-mysql", + "OS_HOST=ragflow-opensearch01", + "REDIS_HOST=ragflow-redis", + "TZ=$TZ" + ], + "extra_hosts": [ + "host.docker.internal:host-gateway" + ], + "image": "icewhaletech/ragflow:latest", + "ports": [ + { + "target": 9380, + "published": "9380", + "protocol": "tcp" + }, + { + "target": 80, + "published": "30080", + "protocol": "tcp" + }, + { + "target": 443, + "published": "10443", + "protocol": "tcp" + }, + { + "target": 5678, + "published": "5678", + "protocol": "tcp" + }, + { + "target": 5679, + "published": "5679", + "protocol": "tcp" + }, + { + "target": 9382, + "published": "9382", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/ragflow-logs", + "target": "/ragflow/logs", + "bind": { + "create_host_path": true + } + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/history_data_agent", + "target": "/ragflow/history_data_agent", + "bind": { + "create_host_path": true + } + } + ], + "networks": [ + "ragflow" + ], + "privileged": false, + "cpu_shares": 90 + } + } + ], + "top_level": { + "name": "ragflow", + "networks": { + "ragflow": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "ragflow-volume-0", + "service": "ragflow", + "container_path": "/ragflow/logs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "ragflow-volume-1", + "service": "ragflow", + "container_path": "/ragflow/history_data_agent", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "ragflow-es01-volume-0", + "service": "ragflow-es01", + "container_path": "/usr/share/elasticsearch/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "ragflow-infinity-volume-0", + "service": "ragflow-infinity", + "container_path": "/var/infinity", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "ragflow-minio-volume-0", + "service": "ragflow-minio", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for ragflow-minio:/data" + }, + { + "id": "ragflow-mysql-volume-0", + "service": "ragflow-mysql", + "container_path": "/var/lib/mysql", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "ragflow-opensearch01-volume-0", + "service": "ragflow-opensearch01", + "container_path": "/usr/share/opensearch/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "ragflow-redis-volume-0", + "service": "ragflow-redis", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for ragflow-redis:/data" + }, + { + "id": "ragflow-sandbox-executor-manager-volume-0", + "service": "ragflow-sandbox-executor-manager", + "container_path": "/var/run/docker.sock", + "mode": "runtime-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 8, + "start_order": [ + "ragflow-es01", + "ragflow-infinity", + "ragflow-minio", + "ragflow-mysql", + "ragflow-opensearch01", + "ragflow-redis", + "ragflow-sandbox-executor-manager", + "ragflow" + ], + "stop_order": [ + "ragflow", + "ragflow-sandbox-executor-manager", + "ragflow-redis", + "ragflow-opensearch01", + "ragflow-mysql", + "ragflow-minio", + "ragflow-infinity", + "ragflow-es01" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "elastic-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "ragflow-es01", + "environment_variable": "ELASTIC_PASSWORD" + } + ] + }, + { + "id": "minio-root-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "ragflow-minio", + "environment_variable": "MINIO_ROOT_PASSWORD" + } + ] + }, + { + "id": "mysql-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "ragflow-mysql", + "environment_variable": "MYSQL_PASSWORD" + } + ] + }, + { + "id": "mysql-root-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "ragflow-mysql", + "environment_variable": "MYSQL_ROOT_PASSWORD" + } + ] + }, + { + "id": "opensearch-initial-admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "ragflow-opensearch01", + "environment_variable": "OPENSEARCH_INITIAL_ADMIN_PASSWORD" + } + ] + }, + { + "id": "opensearch-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "ragflow-opensearch01", + "environment_variable": "OPENSEARCH_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 8192, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "resources": { + "cpu_shares": 90 + }, + "extra_hosts": [ + { + "hostname": "host.docker.internal", + "address": "host-gateway" + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "montaje de sistema pendiente", + "opciones de volumen pendientes", + "ragflow-es01: perfil de salud y persistencia pendiente", + "ragflow-infinity: perfil de salud y persistencia pendiente", + "ragflow-minio: perfil de salud y persistencia pendiente", + "ragflow-mysql: perfil de salud y persistencia pendiente", + "ragflow-opensearch01: perfil de salud y persistencia pendiente", + "ragflow-redis: comando de dependencia personalizado pendiente", + "ragflow-sandbox-executor-manager: perfil de salud y persistencia pendiente", + "ragflow-sandbox-executor-manager: privileged necesita revision de pila", + "ragflow-sandbox-executor-manager: security_opt necesita revision de pila", + "ragflow: extra_hosts necesita revision de pila" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:ragflow-mysql:healthcheck-format", + "service:ragflow-redis:healthcheck-format", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/raneto.json b/oci/catalog/apps/raneto.json new file mode 100644 index 00000000..b2c56cfb --- /dev/null +++ b/oci/catalog/apps/raneto.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-raneto", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Raneto" + }, + "tagline": { + "en_US": "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase." + }, + "description": { + "en_US": "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/raneto-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/raneto-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "http://raneto.com/", + "documentation": "https://docs.linuxserver.io/images/docker-raneto/", + "repository": "https://github.com/linuxserver/docker-raneto", + "tips": [], + "mini_changelog": [ + { + "date": "2025-09-16", + "note": "Many changes for upstream release, if upgrading a new configuration file might be needed." + }, + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-02-01", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-06", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2025-09-16" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-raneto", + "default_branch": "master", + "revision": "02a84dc1fb71d5855487de27e014abd743e2f35a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-raneto/02a84dc1fb71d5855487de27e014abd743e2f35a/README.md", + "readme_pushed_at": "2026-09-05T23:34:22Z", + "compose_sha256": "9db0d77d6b43014b4eeee23597ade53e0bd3e90ab03ca1b02717f774d1cbe378", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "raneto", + "container_name": "raneto", + "image": { + "reference": "lscr.io/linuxserver/raneto:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/raneto", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/raneto/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n raneto:\n image: lscr.io/linuxserver/raneto:latest\n container_name: raneto\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/raneto/data:/config\n ports:\n - 3000:3000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/rawtherapee.json b/oci/catalog/apps/rawtherapee.json new file mode 100644 index 00000000..3eda4d8c --- /dev/null +++ b/oci/catalog/apps/rawtherapee.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-rawtherapee", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Rawtherapee" + }, + "tagline": { + "en_US": "RawTherapee is a free, cross-platform raw image processing program!" + }, + "description": { + "en_US": "RawTherapee is a free, cross-platform raw image processing program!" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rawtherapee-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rawtherapee-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://rawtherapee.com/", + "documentation": "https://docs.linuxserver.io/images/docker-rawtherapee/", + "repository": "https://github.com/linuxserver/docker-rawtherapee", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-26", + "note": "Add aarch64 support." + }, + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-29", + "note": "Rebase to selkies. Breaking Change: HTTPS is now required. Either use a reverse proxy with SSL cert or direct connect to port 8181 with HTTPS." + } + ], + "display_version": null, + "updated_at": "2026-07-26" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-rawtherapee", + "default_branch": "main", + "revision": "ab95b090e90022619038a24e394327dae7e5bb7c", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-rawtherapee/ab95b090e90022619038a24e394327dae7e5bb7c/README.md", + "readme_pushed_at": "2026-09-06T07:50:19Z", + "compose_sha256": "79f321ddef90e568bb1bc7a42235994e7058c43be4aa3e153429cebc427e2d49", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "rawtherapee", + "container_name": "rawtherapee", + "image": { + "reference": "lscr.io/linuxserver/rawtherapee:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/rawtherapee", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/rawtherapee/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n rawtherapee:\n image: lscr.io/linuxserver/rawtherapee:latest\n container_name: rawtherapee\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/rawtherapee/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-rawtherapee/master/Dockerfile", + "dockerfile_sha256": "7fb1fade53874b81555a04489475d47a8a64d733a689024b91c09b749fcec517", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/rclone.json b/oci/catalog/apps/rclone.json new file mode 100644 index 00000000..4bc4f3ff --- /dev/null +++ b/oci/catalog/apps/rclone.json @@ -0,0 +1,946 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-rclone", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Rclone WebUI" + }, + "tagline": { + "en_US": "Cloud storage synchronization and FUSE mounts" + }, + "description": { + "en_US": "Official Rclone image adapted as a native Proxmox OCI LXC with persistent configuration, authenticated WebUI and optional FUSE publication for other LXCs." + }, + "category": "backup", + "category_label": "Backup & Recovery", + "author": "Rclone", + "developer": "Rclone", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5572, + "path": "/" + }, + "website": "https://rclone.org/", + "documentation": "https://rclone.org/install/#docker-installation", + "repository": "https://github.com/rclone/rclone", + "tips": [ + "The installer generates WebUI credentials; the user creates and authorizes their own remote.", + "FUSE publication is optional and requires a privileged LXC plus explicit Proxmox host adaptations." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-12" + }, + "source": { + "provider": "rclone", + "repository": "https://github.com/rclone/rclone", + "revision": "049e11eb7df3d9b30e6e5d400945866db980041bdc0c50b4ede09e079b2e9f52", + "image_repository_url": "https://hub.docker.com/r/rclone/rclone", + "readme_pushed_at": "2026-09-12T11:36:50Z", + "compose_sha256": "049e11eb7df3d9b30e6e5d400945866db980041bdc0c50b4ede09e079b2e9f52", + "generated_at": "2026-09-12T15:54:10+00:00", + "default_branch": "master" + }, + "container_contract": { + "service_name": "rclone", + "container_name": "rclone", + "image": { + "reference": "rclone/rclone:latest", + "registry": "docker.io", + "repository": "rclone/rclone", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "XDG_CONFIG_HOME", + "example": "/config", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config/rclone", + "compose_source_example": "rclone-config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/mnt/oci-shared/rclone/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5572, + "published_example": 5572, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 5573, + "published_example": 5573, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: rclone\nservices:\n rclone:\n image: rclone/rclone:latest\n command:\n - gui\n - --no-open-browser\n - --addr=:5572\n - --api-addr=:5573\n - --config=/config/rclone/rclone.conf\n environment:\n XDG_CONFIG_HOME: /config\n ports:\n - 5572:5572\n - 5573:5573\n volumes:\n - rclone-config:/config/rclone\n - /mnt/oci-shared/rclone/data:/data\n devices:\n - /dev/fuse:/dev/fuse\n cap_add:\n - SYS_ADMIN\n security_opt:\n - apparmor:unconfined\n restart: unless-stopped\nvolumes:\n rclone-config: {}\n" + }, + "compose_stack": { + "project_name": "rclone", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "rclone", + "service_count": 1, + "services": [ + { + "name": "rclone", + "image": "rclone/rclone:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "rclone/rclone:latest", + "command": [ + "gui", + "--no-open-browser", + "--addr=:5572", + "--api-addr=:5573", + "--config=/config/rclone/rclone.conf" + ], + "environment": { + "XDG_CONFIG_HOME": "/config" + }, + "ports": [ + "5572:5572", + "5573:5573" + ], + "volumes": [ + "rclone-config:/config/rclone", + "/mnt/oci-shared/rclone/data:/data" + ], + "devices": [ + "/dev/fuse:/dev/fuse" + ], + "cap_add": [ + "SYS_ADMIN" + ], + "security_opt": [ + "apparmor:unconfined" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "rclone", + "volumes": { + "rclone-config": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "rclone-volume-0", + "service": "rclone", + "container_path": "/config/rclone", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "rclone-volume-1", + "service": "rclone", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for rclone:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "rclone" + ], + "stop_order": [ + "rclone" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Rclone WebUI", + "scheme": "http", + "port": 5572, + "path": "/", + "source": "validated-laboratory-profile" + } + ], + "credentials": [ + { + "label": "Rclone WebUI", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "RCLONE_RC_USER", + "password_environment": "RCLONE_RC_PASS", + "change_required": false, + "source": "official-rclone-rc-environment", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": false, + "privileged_required": true, + "ostype": "auto-from-image", + "cores": 1, + "memory_mb": 512, + "swap_mb": 256, + "rootfs_size_gb": 4, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": true, + "features": [ + "nesting=1", + "fuse=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image-or-reviewed-generated-wrapper", + "cmd": "apply-selected-rclone-mode", + "environment": "preserve-image-env-then-apply-user-values", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "fuse-inside-oci-lxc", + "upstream_behavior": "The official Rclone Docker deployment receives /dev/fuse and SYS_ADMIN to run rclone mount.", + "native_lxc_behavior": "Create a privileged Proxmox OCI LXC with features fuse=1; a minimal wrapper reads persistent RC credentials, waits for host-managed networking and execs the official Rclone binary as PID 1.", + "reason": "FUSE is the core function, and the OCI process can start before Proxmox finishes host-managed networking.", + "behavioral_impact": "Equivalent mount and RC behavior; credentials remain at the official persistent configuration boundary.", + "validation": "Passed on CT138 with gdrive:; official Rclone became PID 1 and the internal fuse.rclone mount survived stop/start." + }, + { + "id": "publish-fuse-submount", + "upstream_behavior": "Docker can publish a FUSE submount through a bind configured with shared propagation.", + "native_lxc_behavior": "A Proxmox hook starts a transient one-shot waiter after post-start. The waiter clones the FUSE tree from the LXC mount namespace with open_tree, creates canonical read/write and recursive read-only views with mount_setattr, and publishes both in the host namespace with move_mount; pre-stop removes them.", + "reason": "LXC makes the container mount tree a slave of the host, so rshared alone cannot propagate a container-created mount back to the host.", + "behavioral_impact": "Namespace topology only; no Rclone process, remote protocol or application data is moved to the host.", + "validation": "Passed on Proxmox VE 9.2.11/kernel 7.0.14-14-pve: canonical read/write publication, recursive read-only publication, clean unpublish, republish, and simultaneous Plex/Jellyfin consumption." + }, + { + "id": "consumer-parent-plus-exact-mounts", + "upstream_behavior": "Consumers bind the published Docker host path with the requested read/write policy.", + "native_lxc_behavior": "Read-only consumers receive the shared remotes-ro root first and one exact mpN from that same intrinsically read-only publication per selected remote second.", + "reason": "The parent mount carries future mount/unmount propagation while the exact mpN includes an already-published FUSE tree during consumer startup; the host publication itself enforces read-only after Rclone mount replacement.", + "behavioral_impact": "Equivalent consumer path with explicit Proxmox storage metadata.", + "validation": "Validated with CT131 Plex and CT128 Jellyfin before and after restarting CT138 Rclone; both exposed the remote through the recursive read-only publication." + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "commands": [ + "pct", + "pvesm", + "skopeo", + "curl", + "jq", + "openssl" + ], + "features": [ + "native-oci-lxc", + "privileged-lxc", + "fuse=1", + "documented-mount-propagation", + "managed-volume-backup", + "authenticated-webui" + ], + "thin_pool_checks": { + "minimum_free_percent": 15, + "warn_when_virtual_allocation_exceeds_pool": true, + "require_autoextend_or_explicit_confirmation": true + }, + "security": { + "privileged_container_warning": true, + "dedicated_service_lxc": true, + "never_expose_rc_webui_to_untrusted_networks": true, + "consumer_paths_read_only_by_default": true + } + }, + "configuration_schema": { + "vmid": { + "type": "integer", + "required": false, + "default": null + }, + "hostname": { + "type": "string", + "required": true, + "default": "rclone", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,62}$" + } + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "default": "local-lvm" + }, + "rootfs_size_gb": { + "type": "integer", + "required": true, + "default": 4, + "minimum": 2 + }, + "config_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "default": "local-lvm" + }, + "config_size_gb": { + "type": "integer", + "required": true, + "default": 2, + "minimum": 1 + }, + "data_host_path": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared/rclone/data", + "create_if_missing": true, + "description": "Directorio local para operaciones copy y sync. No contiene la configuracion persistente." + }, + "webui_username": { + "type": "string", + "required": true, + "default": "admin", + "validation": { + "pattern": "^[A-Za-z0-9._-]{1,64}$" + } + }, + "webui_password": { + "type": "generated-password", + "required": true, + "generate_when_empty": true, + "minimum_length": 24, + "sensitive": true + }, + "webui_port": { + "type": "port", + "required": true, + "default": 5572 + }, + "api_port": { + "type": "port", + "required": true, + "default": 5573 + }, + "bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "ipv4_mode": { + "type": "select", + "required": true, + "default": "dhcp", + "options": [ + "dhcp", + "static" + ] + }, + "ipv4_address": { + "type": "ipv4-cidr", + "required_when": { + "field": "ipv4_mode", + "equals": "static" + } + }, + "gateway": { + "type": "ipv4", + "required_when": { + "field": "ipv4_mode", + "equals": "static" + } + }, + "onboot": { + "type": "boolean", + "required": true, + "default": true + }, + "shared_mount_root": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared/remotes", + "create_if_missing": true, + "description": "Host root where the remote mounts appear, to be assigned afterwards to Plex, Jellyfin, qBittorrent or other OCI containers." + }, + "mount_name": { + "type": "string", + "required": true, + "default": "remote", + "validation": { + "pattern": "^[A-Za-z0-9._-]{1,64}$" + } + }, + "remote_name": { + "type": "rclone-remote-selector", + "required_after": "authorize_remote", + "description": "Remote created by the user; it is never included in the template." + }, + "remote_path": { + "type": "string", + "required": true, + "default": "" + }, + "vfs_cache_mode": { + "type": "select", + "required": true, + "default": "full", + "options": [ + "off", + "minimal", + "writes", + "full" + ] + }, + "shared_mount_root_parent": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared", + "create_if_missing": true, + "description": "Punto de montaje del host que contiene las publicaciones de lectura/escritura y de solo lectura; el hook lo configura como rshared." + }, + "shared_mount_read_only_root": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared/remotes-ro", + "create_if_missing": true, + "description": "Vista FUSE recursivamente de solo lectura para consumidores multimedia como Plex y Jellyfin." + } + }, + "mounts": [ + { + "id": "config", + "container_path": "/config/rclone", + "source": "managed-volume", + "storage_field": "config_storage", + "size_field": "config_size_gb", + "backup": true, + "required": true, + "contains_secrets": true, + "contains": [ + "rclone.conf", + "rclone.log", + "cache" + ] + }, + { + "id": "internal-fuse-root", + "container_path": "/data/mounts", + "source": "container-rootfs-directory", + "read_only": false, + "backup": false, + "required_in_mount_mode": true, + "purpose": "Internal target for official rclone mount before host publication." + } + ], + "environment": [ + { + "name": "XDG_CONFIG_HOME", + "value": "/config" + } + ], + "deployment": { + "runtime": "proxmox-native-oci-lxc", + "unprivileged": false, + "privileged_container_required": true, + "fuse_device_inside_container_required": true, + "entrypoint": "/usr/local/bin/rclone gui --no-open-browser --addr=:${webui_port} --api-addr=:${api_port} --config=/config/rclone/rclone.conf --cache-dir=/config/rclone/cache --log-file=/config/rclone/rclone.log --log-level=${log_level}", + "working_directory": "/data", + "hostname_default": "rclone", + "onboot_default": true, + "startup_order_default": 10, + "startup_delay_seconds_default": 20, + "shutdown_timeout_seconds": 30, + "halt_signal": "SIGTERM", + "features": [ + "nesting=1", + "fuse=1" + ], + "ports": [ + { + "port_from": "webui_port", + "protocol": "tcp", + "purpose": "authenticated-web-ui" + }, + { + "port_from": "api_port", + "protocol": "tcp", + "purpose": "authenticated-remote-control-api" + } + ], + "preserve_image_environment": true, + "restart_method": "clean-stop-then-start", + "restart_note": "On some OCI containers, pct reboot left a residual lxc-start monitor behind. The installer prefers pct stop followed by pct start, and checks the new PID.", + "entrypoint_source": "setup-direct-command-or-generated-mount-wrapper", + "entrypoint_override": "setup-mode-official-rclone-gui-command", + "runtime_modes": { + "setup": { + "purpose": "Create and authorize the user's own remote through the authenticated WebUI.", + "entrypoint": "/usr/local/bin/rclone gui --no-open-browser --addr=:${webui_port} --api-addr=:${api_port} --config=/config/rclone/rclone.conf --cache-dir=/config/rclone/cache --log-file=/config/rclone/rclone.log --log-level=${log_level}" + }, + "mount": { + "purpose": "Mount one selected remote, keep the authenticated RC WebUI/API available and publish the FUSE tree for native Proxmox consumers.", + "entrypoint": "/usr/local/bin/rclone-mount-lxc-start", + "wrapper_behavior": "Read RC credentials from /config, wait for host-managed networking, then exec the official Rclone binary.", + "official_command": "/usr/local/bin/rclone mount ${remote_name}:${remote_path} /data/mounts/${mount_name}", + "webui_assets": "official-rclone-webui-selected-by---rc-web-gui", + "webui_serving": "official --rc-web-gui flags on the RC listener", + "pid1": "official-rclone-binary-after-wrapper-exec", + "restart_persistence": "Proxmox starts the generated mount wrapper on every boot.", + "credentials": { + "source": "/config/rclone/webui.credentials", + "mode": "0600", + "exported_only_inside_lxc": [ + "RCLONE_RC_USER", + "RCLONE_RC_PASS" + ], + "stored_in_pve_config": false + } + } + } + }, + "bootstrap": { + "mode": "two-phase-official-rclone-process", + "steps": [ + "validate-privileged-fuse-and-propagation-requirements", + "pull-oci-image-by-digest", + "create-managed-config-volume", + "create-shared-mount-root", + "generate-webui-password-when-empty", + "apply-webui-credentials-to-proxmox-env", + "create-privileged-container-with-fuse", + "start-setup-mode", + "verify-authenticated-webui-and-api", + "show-authorize-remote-next-action" + ], + "credentials_policy": { + "delivery": "Proxmox env property", + "environment": [ + "RCLONE_RC_USER", + "RCLONE_RC_PASS" + ], + "pve_visibility": "visible-by-design", + "remote_credentials_storage": "/config/rclone/rclone.conf" + } + }, + "post_install_workflows": { + "authorize_remote": { + "when": "after-base-install", + "performed_by": "user-in-authenticated-webui", + "requires_terminal": false, + "initial_state": { + "rclone_config": "empty", + "preconfigured_remotes": 0, + "import_remote_from_another_installation": false + }, + "steps": [ + "open-generated-webui-access-url", + "select-new-remote-provider", + "create-new-remote-from-scratch", + "complete-provider-oauth", + "verify-remote-with-authenticated-rc-api" + ], + "result": { + "config_path": "/config/rclone/rclone.conf", + "tokens_persist_in_managed_config_volume": true + } + }, + "publish_remote": { + "when": "after-authorize-remote", + "performed_by": "installer-with-explicit-user-selection", + "requires_terminal": false, + "steps": [ + "list-user-created-remotes-through-authenticated-rc-api", + "ask-user-for-remote-path-and-mount-name", + "stop-setup-mode", + "apply-official-rclone-mount-entrypoint", + "start-container", + "verify-fuse-inside-container", + "verify-submount-visible-on-host", + "optionally-assign-published-path-to-selected-consumer-lxc" + ], + "consumer_policy": "Consumers are never modified unless the user selects them explicitly.", + "status": "installer-implemented" + } + }, + "healthcheck": { + "type": "authenticated-http-and-api", + "webui": { + "port_from": "webui_port", + "path": "/", + "expected_status": 200 + }, + "api": { + "port_from": "api_port", + "method": "POST", + "path": "/core/version", + "expected_version": "v1.75.0", + "credentials_from": "lxc.environment.runtime:RCLONE_RC_USER,RCLONE_RC_PASS" + }, + "retries": 30, + "start_period_seconds": 60 + }, + "backup_restore": { + "native_proxmox_backup": true, + "included_mounts": [ + "/config/rclone" + ], + "excluded_mounts": [ + "/data" + ], + "external_backup_recommended": [ + "data_host_path-if-it-contains-unique-local-data" + ], + "restore_order": [ + "restore-vzdump", + "verify-managed-config-volume", + "verify-data-host-path", + "start-rclone-oci", + "verify-authenticated-webui-and-api" + ], + "application_consistency": "Use stop mode when active copy or sync jobs require a consistent snapshot. OAuth tokens in rclone.conf are included in the managed config volume." + }, + "boundaries": { + "bundles_webui_credentials": false, + "bundles_remote_credentials": false, + "bundles_rclone_remotes": false, + "bundles_user_data": false, + "installer_must_not_create_external_remotes": true, + "installer_must_not_import_remotes_from_other_lxcs": true, + "template_starts_with_empty_rclone_config": true, + "user_must_create_and_authorize_own_remote": true, + "cross_lxc_fuse_publication_supported": "laboratory-validated", + "consumer_assignments_require_explicit_user_selection": true, + "rclone_runs_inside_its_oci_lxc": true, + "no_host_rclone_binary_or_application_supervisor": true + }, + "post_install_output": { + "url_template": "http://${container_ip}:${webui_port}/login?pass=${urlencode(webui_password)}&url=${urlencode(http://${container_ip}:${api_port}/)}&user=${urlencode(webui_username)}", + "sensitive": true, + "display_once_after_install": true, + "never_log": true + }, + "generated_assets": { + "mount-mode-wrapper": { + "target": "lxc:/usr/local/bin/rclone-mount-lxc-start", + "mode": "0755", + "content_template": "#!/bin/sh\nset -eu\n\ncredentials=/config/rclone/webui.credentials\nexport RCLONE_RC_USER=\"$(sed -n 's/^username=//p' \"$credentials\")\"\nexport RCLONE_RC_PASS=\"$(sed -n 's/^password=//p' \"$credentials\")\"\nremote_name=\"$(printf '%s' '{{remote_name_base64}}' | base64 -d)\"\nremote_path=\"$(printf '%s' '{{remote_path_base64}}' | base64 -d)\"\n\ntest -n \"$RCLONE_RC_USER\"\ntest -n \"$RCLONE_RC_PASS\"\ntest -n \"$remote_name\"\n\nnetwork_ready=false\nfor _ in $(seq 1 120); do\n if ip route get 1.1.1.1 >/dev/null 2>&1; then\n network_ready=true\n break\n fi\n sleep 1\ndone\ntest \"$network_ready\" = true\n\nexec /usr/local/bin/rclone mount \"${remote_name}:${remote_path}\" /data/mounts/{{mount_name}} \\\n --config /config/rclone/rclone.conf \\\n --allow-other \\\n --vfs-cache-mode {{vfs_cache_mode}} \\\n --cache-dir /config/rclone/cache \\\n --rc \\\n --rc-addr :{{webui_port}} \\\n --rc-web-gui \\\n --rc-web-gui-no-open-browser \\\n --log-file /config/rclone/rclone.log \\\n --log-level ERROR\n" + }, + "mount-tree-publisher-source": { + "target": "host:/usr/local/libexec/proxmenux-oci-mount-publish", + "runtime": "python3-from-proxmox-host", + "mode": "0755", + "content": "#!/usr/bin/env python3\n\"\"\"Clone a FUSE mount from an LXC namespace into the Proxmox host namespace.\"\"\"\n\nfrom __future__ import annotations\n\nimport ctypes\nimport os\nimport platform\nimport sys\n\n\nAT_FDCWD = -100\nAT_EMPTY_PATH = 0x1000\nAT_RECURSIVE = 0x8000\nCLONE_NEWNS = 0x00020000\nMOVE_MOUNT_F_EMPTY_PATH = 0x00000004\nMOUNT_ATTR_RDONLY = 0x00000001\nOPEN_TREE_CLONE = 1\n\nSYSCALLS = {\n \"x86_64\": (428, 429, 442),\n \"amd64\": (428, 429, 442),\n \"aarch64\": (428, 429, 442),\n \"arm64\": (428, 429, 442),\n}\n\n\nclass MountAttr(ctypes.Structure):\n _fields_ = [\n (\"attr_set\", ctypes.c_uint64),\n (\"attr_clr\", ctypes.c_uint64),\n (\"propagation\", ctypes.c_uint64),\n (\"userns_fd\", ctypes.c_uint64),\n ]\n\n\ndef fail(step: str) -> None:\n error = ctypes.get_errno()\n raise OSError(error, f\"{step}: {os.strerror(error)}\")\n\n\ndef main() -> int:\n if len(sys.argv) != 5 or sys.argv[4] not in {\"rw\", \"ro\"}:\n print(f\"usage: {sys.argv[0]} PID SOURCE TARGET rw|ro\", file=sys.stderr)\n return 2\n machine = platform.machine().lower()\n if machine not in SYSCALLS:\n print(f\"unsupported host architecture: {machine}\", file=sys.stderr)\n return 2\n open_tree_nr, move_mount_nr, mount_setattr_nr = SYSCALLS[machine]\n pid, source, target, mode = sys.argv[1:]\n libc = ctypes.CDLL(None, use_errno=True)\n libc.syscall.restype = ctypes.c_long\n libc.setns.argtypes = (ctypes.c_int, ctypes.c_int)\n libc.setns.restype = ctypes.c_int\n\n host_ns = os.open(\"/proc/self/ns/mnt\", os.O_RDONLY | os.O_CLOEXEC)\n host_root = os.open(\"/\", os.O_PATH | os.O_DIRECTORY | os.O_CLOEXEC)\n ct_ns = os.open(f\"/proc/{pid}/ns/mnt\", os.O_RDONLY | os.O_CLOEXEC)\n ct_root = os.open(f\"/proc/{pid}/root\", os.O_PATH | os.O_DIRECTORY | os.O_CLOEXEC)\n try:\n if libc.setns(ct_ns, CLONE_NEWNS) != 0:\n fail(\"enter container namespace\")\n os.fchdir(ct_root)\n os.chroot(\".\")\n os.chdir(\"/\")\n tree = libc.syscall(\n open_tree_nr,\n AT_FDCWD,\n os.fsencode(source),\n OPEN_TREE_CLONE | os.O_CLOEXEC,\n )\n if tree < 0:\n fail(\"clone source mount tree\")\n try:\n if mode == \"ro\":\n attributes = MountAttr(attr_set=MOUNT_ATTR_RDONLY)\n result = libc.syscall(\n mount_setattr_nr,\n tree,\n ctypes.c_char_p(b\"\"),\n AT_EMPTY_PATH | AT_RECURSIVE,\n ctypes.byref(attributes),\n ctypes.sizeof(attributes),\n )\n if result != 0:\n fail(\"make cloned mount tree read-only\")\n if libc.setns(host_ns, CLONE_NEWNS) != 0:\n fail(\"return to host namespace\")\n os.fchdir(host_root)\n os.chroot(\".\")\n os.chdir(\"/\")\n result = libc.syscall(\n move_mount_nr,\n tree,\n ctypes.c_char_p(b\"\"),\n AT_FDCWD,\n os.fsencode(target),\n MOVE_MOUNT_F_EMPTY_PATH,\n )\n if result != 0:\n fail(\"publish mount tree\")\n finally:\n os.close(tree)\n finally:\n for descriptor in (ct_root, ct_ns, host_root, host_ns):\n os.close(descriptor)\n return 0\n\n\nif __name__ == \"__main__\":\n try:\n raise SystemExit(main())\n except OSError as exc:\n print(exc, file=sys.stderr)\n raise SystemExit(1)\n" + }, + "mount-publication-waiter": { + "target": "host:/usr/local/libexec/proxmenux-oci-mount-wait", + "mode": "0755", + "lifecycle": "transient-systemd-oneshot-only", + "content": "#!/usr/bin/env bash\nset -euo pipefail\n\nvmid=${1:?missing VMID}\ninside=${2:?missing source path}\npublished=${3:?missing target path}\npublished_ro=${4:?missing read-only target path}\nhelper=${5:?missing publisher helper}\n\nunpublish() {\n local target=$1\n if mountpoint -q \"$target\"; then\n umount \"$target\" || umount -l \"$target\"\n fi\n}\n\nfor _ in $(seq 1 300); do\n pid=$(lxc-info -n \"$vmid\" -pH 2>/dev/null || true)\n if [[ -n $pid ]] && awk -v path=\"$inside\" '$5 == path && $0 ~ / - fuse(\\.rclone)? / { found=1 } END { exit !found }' \"/proc/$pid/mountinfo\"; then\n unpublish \"$published_ro\"\n unpublish \"$published\"\n \"$helper\" \"$pid\" \"$inside\" \"$published\" rw\n if ! \"$helper\" \"$pid\" \"$inside\" \"$published_ro\" ro; then\n unpublish \"$published\"\n exit 1\n fi\n findmnt -T \"$published\" -n -o FSTYPE | grep -q '^fuse'\n findmnt -T \"$published_ro\" -n -o FSTYPE | grep -q '^fuse'\n findmnt -T \"$published_ro\" -n -o VFS-OPTIONS | tr ',' '\n' | grep -qx ro\n logger -t proxmenux-rclone \"Published CT $vmid $inside at $published (rw) and $published_ro (ro)\"\n exit 0\n fi\n sleep 1\ndone\n\nlogger -t proxmenux-rclone \"Timed out waiting for CT $vmid FUSE mount at $inside\"\nexit 1\n" + }, + "proxmox-hookscript": { + "target": "snippet-storage:proxmenux-rclone-${ctid}-fuse-hook.sh", + "mode": "0755", + "phases": [ + "pre-start", + "post-start", + "pre-stop", + "post-stop" + ], + "content_template": "#!/usr/bin/env bash\nset -euo pipefail\n\nvmid=${1:?missing VMID}\nphase=${2:?missing phase}\ninside=/data/mounts/{{mount_name}}\npublished={{shared_mount_root}}/{{mount_name}}\npublished_ro={{shared_mount_read_only_root}}/{{mount_name}}\nhelper=/usr/local/libexec/proxmenux-oci-mount-publish\nwaiter=/usr/local/libexec/proxmenux-oci-mount-wait\nunit=\"proxmenux-rclone-publish-$vmid.service\"\n\nunpublish() {\n local target=$1\n if mountpoint -q \"$target\"; then\n umount \"$target\" || umount -l \"$target\"\n fi\n}\n\nstop_waiter() {\n systemctl stop \"$unit\" >/dev/null 2>&1 || true\n systemctl reset-failed \"$unit\" >/dev/null 2>&1 || true\n}\n\ncase \"$phase\" in\n pre-start)\n install -d -m 0755 \"$published\" \"$published_ro\"\n if ! mountpoint -q {{shared_mount_root_parent}}; then\n mount --bind {{shared_mount_root_parent}} {{shared_mount_root_parent}}\n fi\n mount --make-rshared {{shared_mount_root_parent}}\n stop_waiter\n unpublish \"$published_ro\"\n unpublish \"$published\"\n ;;\n post-start)\n stop_waiter\n systemd-run --quiet --collect --unit=\"$unit\" -- \\\n \"$waiter\" \"$vmid\" \"$inside\" \"$published\" \"$published_ro\" \"$helper\"\n ;;\n pre-stop|post-stop)\n stop_waiter\n unpublish \"$published_ro\"\n unpublish \"$published\"\n ;;\nesac\n" + } + }, + "consumer_integration": { + "optional": true, + "canonical_read_write_root_host_path": "${shared_mount_root}", + "read_only_root_host_path": "${shared_mount_read_only_root}", + "read_only_remote_host_path": "${shared_mount_read_only_root}/${mount_name}", + "required_mount_order": [ + "shared-root-parent", + "exact-published-remote" + ], + "plex_example": { + "parent": "${shared_mount_read_only_root},mp=/data/remotes,backup=0,ro=1", + "exact": "${shared_mount_read_only_root}/${mount_name},mp=/data/remotes/${mount_name},backup=0,ro=1" + }, + "jellyfin_example": { + "parent": "${shared_mount_read_only_root},mp=/media/remotes,backup=0,ro=1", + "exact": "${shared_mount_read_only_root}/${mount_name},mp=/media/remotes/${mount_name},backup=0,ro=1" + }, + "restart_rule": "Keep both parent and exact mpN declarations so consumers recover when the Rclone FUSE publication is replaced." + }, + "notes": [ + "La configuracion, los tokens y las credenciales RC permanecen en /config/rclone dentro del volumen backup=1.", + "El usuario crea y autoriza su propio remote desde la WebUI; la plantilla no incluye remotes del laboratorio.", + "El modo mount usa un wrapper minimo que termina con exec del binario oficial; Rclone queda como PID 1.", + "La publicacion usa un hookscript oficial de Proxmox y una tarea systemd transitoria; no instala Rclone ni un supervisor permanente en el host.", + "Cada remoto se publica en una raiz canonica de lectura/escritura y en otra raiz recursivamente de solo lectura; cada consumidor selecciona la politica adecuada.", + "Los consumidores son opcionales y deben declarar el padre compartido mas un mpN exacto por remoto.", + "El perfil fue validado con reinicios de Rclone, Plex y Jellyfin." + ], + "references": { + "official_docker_install": "https://rclone.org/install/#docker-installation", + "official_gui_command": "https://rclone.org/commands/rclone_gui/", + "official_mount_command": "https://rclone.org/commands/rclone_mount/", + "official_vfs_documentation": "https://rclone.org/commands/rclone_mount/#vfs-file-caching" + } + }, + "security_profile": { + "requires_privileged_lxc": true, + "risk_level": "high", + "confirmation_required": true, + "warning": "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network." + }, + "installer_profile": { + "generated_files": [ + { + "id": "rclone-setup-wrapper", + "container_path": "/usr/local/bin/rclone-setup-lxc-start", + "owner": "mapped-root", + "mode": "0755", + "content": "#!/bin/sh\nset -eu\nmkdir -p /config/rclone/cache\nexec /usr/local/bin/rclone gui --no-open-browser --addr=:5572 --api-addr=:5573 --config=/config/rclone/rclone.conf --cache-dir=/config/rclone/cache --log-file=/config/rclone/rclone.log --log-level=ERROR\n" + } + ], + "volume_preparations": [ + { + "container_path": "/config/rclone", + "remove_lost_found": true, + "owner_strategy": "mapped-root" + } + ], + "runtime": { + "entrypoint": "/usr/local/bin/rclone-setup-lxc-start", + "working_directory": "/data", + "halt_signal": "SIGTERM" + }, + "startup_healthcheck": { + "scheme": "http", + "port": 5572, + "path": "/", + "verify_tls": false, + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "stability_seconds": 0 + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "Automatic installation implements the validated privileged FUSE LXC, generated wrappers, and host publication workflow with explicit user consent." + }, + "validation": { + "schema": "passed-at-generation", + "profile": { + "reference_host": "Proxmox VE 9.2.11, kernel 7.0.14-16-pve", + "reference_lxc": "CT120", + "internal_fuse_mount": "passed", + "host_publication": "passed", + "host_read_write_publication": "passed", + "host_recursive_read_only_publication": "passed", + "host_to_lxc_visibility": "passed", + "lxc_to_host_visibility": "passed", + "stop_unpublish": "passed", + "restart_republish_seconds": 2, + "plex_consumer": "passed-read-only", + "jellyfin_consumer": "passed-read-only", + "credentials_outside_config": false, + "transient_waiter_after_success": "inactive", + "installer_base_mode": "passed", + "privileged_oci_import_conversion": "passed-preserving-xattrs", + "official_rclone_version": "1.75.1", + "webui_mode": "passed-official-embedded-webui" + }, + "validated_profile": { + "id": "pve55-rclone-direct-fuse", + "container_id": 120, + "validation_status": "passed", + "passed": [ + "allow-other", + "consumer-lxc-read-only-policy", + "fuse-mount-inside-lxc", + "host-read-write-and-recursive-read-only-views", + "managed-config-volume", + "no-host-rclone-supervisor", + "official-rclone-binary-as-pid1", + "restart-with-published-host-mount", + "reverse-submount-publication-to-host" + ], + "pending": [] + }, + "source_profile": "rclone-oci.json" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-latest-oci-image-preserve-managed-config-volume-and-reapply-reviewed-assets", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false, + "validated_workflows": { + "install": [ + "validate-requirements", + "pull-oci-image-by-digest", + "create-managed-config-volume", + "create-shared-mount-root", + "create-privileged-fuse-container", + "install-generated-fuse-publication-assets-on-host", + "attach-proxmox-hookscript", + "start-setup-mode", + "wait-for-authenticated-healthcheck", + "show-authorize-remote-next-action" + ], + "update": [ + "stop-active-mount-cleanly-and-unpublish-host-tree", + "backup-container", + "pull-version-pinned-image", + "recreate-rootfs-preserving-managed-config-volume", + "reinstall-generated-wrapper-and-publication-assets", + "restore-selected-runtime-mode", + "start-container", + "verify-authenticated-api-internal-fuse-host-publication-and-consumers" + ], + "uninstall": { + "remove_rootfs": true, + "preserve_config_by_default": true, + "preserve_data_by_default": true + }, + "activate_mount": [ + "validate-selected-remote", + "generate-mount-wrapper-without-embedding-secrets", + "remove-legacy-rclone-rc-runtime-secret-lines-from-pve-config", + "set-mount-wrapper-as-entrypoint", + "stop-then-start-container", + "wait-for-host-published-fuse-tree", + "attach-shared-root-and-exact-remote-mounts-to-selected-consumers", + "validate-read-policy-from-each-consumer" + ] + } + } +} diff --git a/oci/catalog/apps/rdtclient.json b/oci/catalog/apps/rdtclient.json new file mode 100644 index 00000000..d6c037a6 --- /dev/null +++ b/oci/catalog/apps/rdtclient.json @@ -0,0 +1,479 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-rdtclient", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Real-Debrid Torrent Client" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "" + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "rogerfar", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6500, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/rogerfar/rdtclient", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "rogerfar", + "repository": "https://hub.docker.com/r/rogerfar/rdtclient", + "revision": "5bd0b78565c3535c23c5d5106d4f24028c3df0cd341a319f6d6496601612ebfb", + "image_repository_url": "https://hub.docker.com/r/rogerfar/rdtclient", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "5bd0b78565c3535c23c5d5106d4f24028c3df0cd341a319f6d6496601612ebfb", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "rdtclient", + "container_name": "rdtclient", + "image": { + "reference": "rogerfar/rdtclient:latest", + "registry": "docker.io", + "repository": "rogerfar/rdtclient", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "UMASK", + "example": "002", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data/downloads", + "compose_source_example": "/DATA/Downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/data/db", + "compose_source_example": "/DATA/AppData/$AppID/db", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 6500, + "published_example": 6500, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: rdtclient\nservices:\n rdtclient:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n UMASK: '002'\n cpu_shares: 50\n command: []\n container_name: rdtclient\n deploy:\n resources:\n reservations:\n memory: 64M\n image: rogerfar/rdtclient:latest\n ports:\n - target: 6500\n published: '6500'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/Downloads\n target: /data/downloads\n - type: bind\n source: /DATA/AppData/$AppID/db\n target: /data/db\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "rdtclient", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "rdtclient", + "service_count": 1, + "services": [ + { + "name": "rdtclient", + "image": "rogerfar/rdtclient:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ", + "UMASK": "002" + }, + "cpu_shares": 50, + "command": [], + "container_name": "rdtclient", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "image": "rogerfar/rdtclient:latest", + "ports": [ + { + "target": 6500, + "published": "6500", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/Downloads", + "target": "/data/downloads" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/db", + "target": "/data/db" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "rdtclient" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "rdtclient-volume-0", + "service": "rdtclient", + "container_path": "/data/downloads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for rdtclient:/data/downloads" + }, + { + "id": "rdtclient-volume-1", + "service": "rdtclient", + "container_path": "/data/db", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for rdtclient:/data/db" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "rdtclient" + ], + "stop_order": [ + "rdtclient" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6500, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [] + }, + "resources": { + "cpu_shares": 50 + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/readarr.json b/oci/catalog/apps/readarr.json new file mode 100644 index 00000000..56f81a6a --- /dev/null +++ b/oci/catalog/apps/readarr.json @@ -0,0 +1,492 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-readarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Readarr" + }, + "tagline": { + "en_US": "Ebook and audiobook collection manager for Usenet and BitTorrent users." + }, + "description": { + "en_US": "Readarr is a ebook collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new books from your favorite authors and will interface with clients and indexers to grab, sort, and rename them." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Readarr Team", + "developer": "Readarr Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8787, + "path": "/" + }, + "website": "https://readarr.com", + "documentation": "https://docs.linuxserver.io/images/docker-readarr/", + "repository": "https://hub.docker.com/r/linuxserver/readarr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://hub.docker.com/r/linuxserver/readarr", + "revision": "f24be567d7cc5f0d2b32256f7aca5b6d62d822bed0b4242a6d927408f7dca923", + "image_repository_url": "https://hub.docker.com/r/linuxserver/readarr", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "f24be567d7cc5f0d2b32256f7aca5b6d62d822bed0b4242a6d927408f7dca923", + "generated_at": "2026-09-13T15:35:02+00:00" + }, + "container_contract": { + "service_name": "readarr", + "container_name": "readarr", + "image": { + "reference": "linuxserver/readarr:latest", + "registry": "docker.io", + "repository": "linuxserver/readarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/books", + "compose_source_example": "/DATA/Media/Books", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/DATA/Downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8787, + "published_example": 8787, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: readarr\nservices:\n readarr:\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n image: linuxserver/readarr:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 8787\n published: '8787'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/Media/Books\n target: /books\n - type: bind\n source: /DATA/Downloads\n target: /downloads\n container_name: readarr\n" + }, + "compose_stack": { + "project_name": "readarr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "readarr", + "service_count": 1, + "services": [ + { + "name": "readarr", + "image": "linuxserver/readarr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "image": "linuxserver/readarr:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8787, + "published": "8787", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/Media/Books", + "target": "/books" + }, + { + "type": "bind", + "source": "/DATA/Downloads", + "target": "/downloads" + } + ], + "container_name": "readarr" + } + } + ], + "top_level": { + "name": "readarr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "readarr-volume-0", + "service": "readarr", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "readarr-volume-1", + "service": "readarr", + "container_path": "/books", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "readarr-volume-2", + "service": "readarr", + "container_path": "/downloads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for readarr:/downloads" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "readarr" + ], + "stop_order": [ + "readarr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8787, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/remmina.json b/oci/catalog/apps/remmina.json new file mode 100644 index 00000000..41e5dccb --- /dev/null +++ b/oci/catalog/apps/remmina.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-remmina", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Remmina" + }, + "tagline": { + "en_US": "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported." + }, + "description": { + "en_US": "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/remmina-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/remmina-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://remmina.org/", + "documentation": "https://docs.linuxserver.io/images/docker-remmina/", + "repository": "https://github.com/linuxserver/docker-remmina", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-20", + "note": "Rebase to resolute, stop ingesting from ppa." + }, + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-14", + "note": "Ingest from PPA." + }, + { + "date": "2025-08-11", + "note": "Install librsvg2 for icons." + } + ], + "display_version": null, + "updated_at": "2026-06-20" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-remmina", + "default_branch": "master", + "revision": "0337a6863dcceaf00c6fa37037e5ea22b60be9f6", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-remmina/0337a6863dcceaf00c6fa37037e5ea22b60be9f6/README.md", + "readme_pushed_at": "2026-09-09T18:26:31Z", + "compose_sha256": "7be1d7cd978700aafa354daeafa98a19c1d01a6008ec4c8b588873ec5cebc67b", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "remmina", + "container_name": "remmina", + "image": { + "reference": "lscr.io/linuxserver/remmina:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/remmina", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/remmina/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n remmina:\n image: lscr.io/linuxserver/remmina:latest\n container_name: remmina\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/remmina/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/resilio-sync.json b/oci/catalog/apps/resilio-sync.json new file mode 100644 index 00000000..a1830965 --- /dev/null +++ b/oci/catalog/apps/resilio-sync.json @@ -0,0 +1,280 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-resilio-sync", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Resilio Sync" + }, + "tagline": { + "en_US": "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes." + }, + "description": { + "en_US": "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/resilio-sync-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/resilio-sync-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8888, + "path": "/" + }, + "website": "https://www.resilio.com/individuals/", + "documentation": "https://docs.linuxserver.io/images/docker-resilio-sync/", + "repository": "https://github.com/linuxserver/docker-resilio-sync", + "tips": [], + "mini_changelog": [ + { + "date": "2024-08-21", + "note": "Rebase to Noble." + }, + { + "date": "2023-07-03", + "note": "Deprecate armhf. As announced [here](https://www.linuxserver.io/blog/a-farewell-to-arm-hf)" + }, + { + "date": "2022-12-14", + "note": "Rebase to Jammy, migrate to s6v3." + }, + { + "date": "2021-10-03", + "note": "Use upstream apt repo to install. Rebase to focal." + }, + { + "date": "2021-01-20", + "note": "Deprecate `UMASK_SET` in favor of UMASK in baseimage, see above for more information." + } + ], + "display_version": null, + "updated_at": "2024-08-21" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-resilio-sync", + "default_branch": "master", + "revision": "9a73b51684b714454bfa560745a258351b159fa9", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-resilio-sync/9a73b51684b714454bfa560745a258351b159fa9/README.md", + "readme_pushed_at": "2026-09-08T01:30:09Z", + "compose_sha256": "4a343c66a57cf259cf4d1f09da41e4cf01b1c77abf9cfe5674e39f56468377ad", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "resilio-sync", + "container_name": "resilio-sync", + "image": { + "reference": "lscr.io/linuxserver/resilio-sync:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/resilio-sync", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/resilio-sync/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/sync", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8888, + "published_example": 8888, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 55555, + "published_example": 55555, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n resilio-sync:\n image: lscr.io/linuxserver/resilio-sync:latest\n container_name: resilio-sync\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/resilio-sync/config:/config\n - /path/to/downloads:/downloads\n - /path/to/data:/sync\n ports:\n - 8888:8888\n - 55555:55555\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8888, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/retroarch-inglebard.json b/oci/catalog/apps/retroarch-inglebard.json new file mode 100644 index 00000000..9792c9d8 --- /dev/null +++ b/oci/catalog/apps/retroarch-inglebard.json @@ -0,0 +1,371 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-retroarch-inglebard", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "RetroArch" + }, + "tagline": { + "en_US": "Online retro games emulator" + }, + "description": { + "en_US": "RetroArch-web is a web-based classic game emulator that enables users to enjoy a wide range of retro games directly in modern browsers. Supporting platforms like GBA, N64, DOS games, and NES (FC), it brings nostalgic gaming to life. Built on the open-source RetroArch project, RetroArch-web delivers robust features, including high-quality graphics rendering, audio processing, input controls, and save/load game progress, ensuring a precise and smooth emulation experience.\n\nDesigned for ease of use, RetroArch-web requires no complex software installation, running seamlessly in browsers. Its flexible configuration options let users customize controller setups, visual filters, and audio settings to suit individual preferences. With broad cross-platform compatibility, it ensures stable performance across devices, offering retro gaming enthusiasts a consistent experience on the go.\n\nBacked by an active open-source community, RetroArch-web continually improves performance and expands supported game platforms. Whether revisiting classic arcade titles or exploring vintage console games, RetroArch-web stands out as the ideal choice for retro gamers, combining powerful emulation with a user-friendly interface.\n\n**Key Features:**\n- Polished interface for browsing game collections with thumbnails and animated backgrounds\n- Supports multiple emulators and game engines for running classic games and discs\n- Next-frame response time for near-native hardware low-latency experience\n- Highly configurable settings to tweak game performance and display options\n- Automatic controller configuration for easy multiplayer gaming\n- Shaders to enhance old game rendering and mimic CRT monitor effects\n- Netplay for multiplayer gaming and spectator mode\n- Achievements system to unlock trophies and badges in classic games\n- Recording and streaming for capturing gameplay or live streaming\n\n**Learn More:**\n- [RetroArch Official Website](https://www.retroarch.com)\n- [RetroArch GitHub Repository](https://github.com/libretro/RetroArch)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "inglebard", + "developer": "inglebard", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://www.retroarch.com", + "documentation": null, + "repository": "https://hub.docker.com/r/inglebard/retroarch-web", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "inglebard", + "repository": "https://hub.docker.com/r/inglebard/retroarch-web", + "revision": "a52764be70c93eda4f14f621fffa341a3d5811cd07217a186e2d3549f1b04e03", + "image_repository_url": "https://hub.docker.com/r/inglebard/retroarch-web", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "a52764be70c93eda4f14f621fffa341a3d5811cd07217a186e2d3549f1b04e03", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "retroarch", + "container_name": "retroarch", + "image": { + "reference": "inglebard/retroarch-web:latest", + "registry": "docker.io", + "repository": "inglebard/retroarch-web", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ROOT_WWW_PATH", + "example": "\"/var/www/html\"", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 80, + "published_example": 8183, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: retroarch\nservices:\n retroarch:\n image: inglebard/retroarch-web:latest\n container_name: retroarch\n deploy:\n resources:\n reservations:\n memory: 64M\n restart: unless-stopped\n environment:\n - ROOT_WWW_PATH=\"/var/www/html\"\n ports:\n - 8183:80\n" + }, + "compose_stack": { + "project_name": "retroarch", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "retroarch", + "service_count": 1, + "services": [ + { + "name": "retroarch", + "image": "inglebard/retroarch-web:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "inglebard/retroarch-web:latest", + "container_name": "retroarch", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "restart": "unless-stopped", + "environment": [ + "ROOT_WWW_PATH=\"/var/www/html\"" + ], + "ports": [ + "8183:80" + ] + } + } + ], + "top_level": { + "name": "retroarch" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "retroarch" + ], + "stop_order": [ + "retroarch" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/retroarch.json b/oci/catalog/apps/retroarch.json new file mode 100644 index 00000000..c8c9306f --- /dev/null +++ b/oci/catalog/apps/retroarch.json @@ -0,0 +1,269 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-retroarch", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Retroarch" + }, + "tagline": { + "en_US": "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface." + }, + "description": { + "en_US": "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/retroarch-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/retroarch-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://retroarch.com/", + "documentation": "https://docs.linuxserver.io/images/docker-retroarch/", + "repository": "https://github.com/linuxserver/docker-retroarch", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-19", + "note": "Rebase to Resolute." + }, + { + "date": "2026-03-05", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-05-25", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-04-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-retroarch", + "default_branch": "master", + "revision": "d7f836162dbd4b24d4cc99b85a3bd7c841ad4e1d", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-retroarch/d7f836162dbd4b24d4cc99b85a3bd7c841ad4e1d/README.md", + "readme_pushed_at": "2026-09-06T19:13:28Z", + "compose_sha256": "12178dbc8a77a51fd22568220d91edb9676b9a57282eb73e2d7fb8b8fca103cb", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "retroarch", + "container_name": "retroarch", + "image": { + "reference": "lscr.io/linuxserver/retroarch:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/retroarch", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n retroarch:\n image: lscr.io/linuxserver/retroarch:latest\n container_name: retroarch\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/romm.json b/oci/catalog/apps/romm.json new file mode 100644 index 00000000..692de4a3 --- /dev/null +++ b/oci/catalog/apps/romm.json @@ -0,0 +1,826 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-romm", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "RomM" + }, + "tagline": { + "en_US": "RomM is a self-hosted ROM manager for managing and playing game collections." + }, + "description": { + "en_US": "RomM is a self-hosted game collection management app designed for emulator enthusiasts, offering a convenient way to scan, enrich, browse, and play games. Its responsive Web interface allows users to manage collections via any modern browser, supporting over 400 platforms, ideal for retro gaming fans building personal game libraries.\n\nThe app's core features include robust library management and seamless gameplay. It fetches metadata from IGDB, Screenscraper, and MobyGames, and custom artwork from SteamGridDB, enhancing the visual appeal of collections. Users can play games directly in the browser using EmulatorJS and RuffleRS, with support for multi-disk games, DLCs, patches, and manuals. It also enables parsing and filtering by filename tags for tailored organization. Additionally, it supports multi-user accounts with limited access permissions, allowing library sharing with friends and displaying RetroAchievements.\n\nIt can be flexibly deployed on personal servers or NAS devices, with official apps for Playnite and muOS enhancing cross-device access. Users can upload, update, or delete games via the Web interface, with community support documentation expanding functionality. Whether managing a personal retro game library or sharing with others, the app's intuitive interface and high customizability deliver a modern game management platform, meeting diverse needs.\n\n**Key Features:**\n- Scan and enhance your game library with metadata from IGDB, Screenscraper and MobyGames\n- Fetch custom artwork from SteamGridDB\n- Display your achievements from Retroachievements\n- Metadata available for 400+ platforms\n- Play games directly from the browser using EmulatorJS and RuffleRS\n- Share your library with friends with limited access and permissions\n- Official apps for Playnite and muOS\n- Supports multi-disk games, DLCs, mods, hacks, patches, and manuals\n- Parse and filter by tags in filenames\n- View, upload, update, and delete games from any modern web browser\n\n**Learn More:**\n- [RomM Official Website](https://romm.app)\n- [RomM GitHub Repository](https://github.com/rommapp/romm)\n" + }, + "category": "gaming", + "category_label": "Gaming & Leisure", + "author": "rommapp", + "developer": "rommapp", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://romm.app", + "documentation": null, + "repository": "https://hub.docker.com/r/rommapp/romm", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/rommapp/romm", + "revision": "f1558e8732d595b63401c73b5da7c155cc2f27c664fb12e1bbd67fa15eb06777", + "image_repository_url": "https://hub.docker.com/r/rommapp/romm", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "f1558e8732d595b63401c73b5da7c155cc2f27c664fb12e1bbd67fa15eb06777", + "generated_at": "2026-09-13T15:48:33+00:00" + }, + "container_contract": { + "service_name": "romm", + "container_name": "romm", + "image": { + "reference": "rommapp/romm:latest", + "registry": "docker.io", + "repository": "rommapp/romm", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "DB_HOST", + "example": "romm-db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_NAME", + "example": "romm", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_USER", + "example": "romm-user", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_PASSWD", + "example": "${GENERATED_DB_PASSWD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "ROMM_AUTH_SECRET_KEY", + "example": "${GENERATED_ROMM_AUTH_SECRET_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "IGDB_CLIENT_ID", + "example": "\"\"", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "IGDB_CLIENT_SECRET", + "example": "${GENERATED_IGDB_CLIENT_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "SCREENSCRAPER_USER", + "example": "\"\"", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SCREENSCRAPER_PASSWORD", + "example": "${GENERATED_SCREENSCRAPER_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "STEAMGRIDDB_API_KEY", + "example": "${GENERATED_STEAMGRIDDB_API_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/romm/resources", + "compose_source_example": "/DATA/AppData/$AppID/resources", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/redis-data", + "compose_source_example": "/DATA/AppData/$AppID/redis-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/romm/library", + "compose_source_example": "/DATA/AppData/$AppID/library", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/romm/assets", + "compose_source_example": "/DATA/AppData/$AppID/assets", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-4", + "container_path": "/romm/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8285, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "romm-db", + "image": "mariadb:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: romm\nservices:\n romm:\n image: rommapp/romm:latest\n container_name: romm\n deploy:\n resources:\n reservations:\n memory: 512M\n networks:\n - romm-network\n restart: unless-stopped\n ports:\n - 8285:8080\n environment:\n - DB_HOST=romm-db\n - DB_NAME=romm\n - DB_USER=romm-user\n - DB_PASSWD=${GENERATED_DB_PASSWD}\n - ROMM_AUTH_SECRET_KEY=${GENERATED_ROMM_AUTH_SECRET_KEY}\n - IGDB_CLIENT_ID=\"\"\n - IGDB_CLIENT_SECRET=${GENERATED_IGDB_CLIENT_SECRET}\n - SCREENSCRAPER_USER=\"\"\n - SCREENSCRAPER_PASSWORD=${GENERATED_SCREENSCRAPER_PASSWORD}\n - STEAMGRIDDB_API_KEY=${GENERATED_STEAMGRIDDB_API_KEY}\n volumes:\n - /DATA/AppData/$AppID/resources:/romm/resources\n - /DATA/AppData/$AppID/redis-data:/redis-data\n - /DATA/AppData/$AppID/library:/romm/library\n - /DATA/AppData/$AppID/assets:/romm/assets\n - /DATA/AppData/$AppID/config:/romm/config\n depends_on:\n romm-db:\n condition: service_healthy\n restart: true\n romm-db:\n image: mariadb:latest\n container_name: romm-db\n restart: unless-stopped\n networks:\n - romm-network\n environment:\n - MARIADB_ROOT_PASSWORD=${GENERATED_MARIADB_ROOT_PASSWORD}\n - MARIADB_DATABASE=romm\n - MARIADB_USER=romm-user\n - MARIADB_PASSWORD=${GENERATED_MARIADB_PASSWORD}\n volumes:\n - /DATA/AppData/$AppID/mysql:/var/lib/mysql\n healthcheck:\n test:\n - CMD\n - healthcheck.sh\n - --connect\n - --innodb_initialized\n start_period: 30s\n start_interval: 10s\n interval: 10s\n timeout: 5s\n retries: 5\nnetworks:\n romm-network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "romm", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "romm", + "service_count": 2, + "services": [ + { + "name": "romm-db", + "image": "mariadb:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "mariadb:latest", + "container_name": "romm-db", + "restart": "unless-stopped", + "networks": [ + "romm-network" + ], + "environment": [ + "MARIADB_ROOT_PASSWORD=${GENERATED_MARIADB_ROOT_PASSWORD}", + "MARIADB_DATABASE=romm", + "MARIADB_USER=romm-user", + "MARIADB_PASSWORD=${GENERATED_MARIADB_PASSWORD}" + ], + "volumes": [ + "/DATA/AppData/$AppID/mysql:/var/lib/mysql" + ], + "healthcheck": { + "test": [ + "CMD", + "healthcheck.sh", + "--connect", + "--innodb_initialized" + ], + "start_period": "30s", + "start_interval": "10s", + "interval": "10s", + "timeout": "5s", + "retries": 5 + } + } + }, + { + "name": "romm", + "image": "rommapp/romm:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "romm-db" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "rommapp/romm:latest", + "container_name": "romm", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "networks": [ + "romm-network" + ], + "restart": "unless-stopped", + "ports": [ + "8285:8080" + ], + "environment": [ + "DB_HOST=romm-db", + "DB_NAME=romm", + "DB_USER=romm-user", + "DB_PASSWD=${GENERATED_DB_PASSWD}", + "ROMM_AUTH_SECRET_KEY=${GENERATED_ROMM_AUTH_SECRET_KEY}", + "IGDB_CLIENT_ID=\"\"", + "IGDB_CLIENT_SECRET=${GENERATED_IGDB_CLIENT_SECRET}", + "SCREENSCRAPER_USER=\"\"", + "SCREENSCRAPER_PASSWORD=${GENERATED_SCREENSCRAPER_PASSWORD}", + "STEAMGRIDDB_API_KEY=${GENERATED_STEAMGRIDDB_API_KEY}" + ], + "volumes": [ + "/DATA/AppData/$AppID/resources:/romm/resources", + "/DATA/AppData/$AppID/redis-data:/redis-data", + "/DATA/AppData/$AppID/library:/romm/library", + "/DATA/AppData/$AppID/assets:/romm/assets", + "/DATA/AppData/$AppID/config:/romm/config" + ], + "depends_on": { + "romm-db": { + "condition": "service_healthy", + "restart": true + } + } + } + } + ], + "top_level": { + "name": "romm", + "networks": { + "romm-network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "romm-volume-0", + "service": "romm", + "container_path": "/romm/resources", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "romm-volume-1", + "service": "romm", + "container_path": "/redis-data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "romm-volume-2", + "service": "romm", + "container_path": "/romm/library", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for romm:/romm/library" + }, + { + "id": "romm-volume-3", + "service": "romm", + "container_path": "/romm/assets", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "romm-volume-4", + "service": "romm", + "container_path": "/romm/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "romm-db-volume-0", + "service": "romm-db", + "container_path": "/var/lib/mysql", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "romm-db", + "romm" + ], + "stop_order": [ + "romm", + "romm-db" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "db-passwd", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "romm", + "environment_variable": "DB_PASSWD" + } + ] + }, + { + "id": "igdb-client-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "romm", + "environment_variable": "IGDB_CLIENT_SECRET" + } + ] + }, + { + "id": "mariadb-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "romm-db", + "environment_variable": "MARIADB_PASSWORD" + } + ] + }, + { + "id": "mariadb-root-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "romm-db", + "environment_variable": "MARIADB_ROOT_PASSWORD" + } + ] + }, + { + "id": "romm-auth-secret-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "romm", + "environment_variable": "ROMM_AUTH_SECRET_KEY" + } + ] + }, + { + "id": "screenscraper-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "romm", + "environment_variable": "SCREENSCRAPER_PASSWORD" + } + ] + }, + { + "id": "steamgriddb-api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "romm", + "environment_variable": "STEAMGRIDDB_API_KEY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "stack_environment_overrides": { + "romm": { + "ROMM_DB_DRIVER": "mariadb", + "DB_PASSWD": "${GENERATED_MARIADB_PASSWORD}", + "IGDB_CLIENT_ID": "", + "IGDB_CLIENT_SECRET": "", + "SCREENSCRAPER_USER": "", + "SCREENSCRAPER_PASSWORD": "", + "STEAMGRIDDB_API_KEY": "" + } + }, + "stack_optional_environment": [ + { + "service": "romm", + "label": "IGDB", + "fields": [ + { + "name": "IGDB_CLIENT_ID", + "label": "IGDB Client ID", + "sensitive": false + }, + { + "name": "IGDB_CLIENT_SECRET", + "label": "IGDB Client Secret", + "sensitive": true + } + ] + }, + { + "service": "romm", + "label": "ScreenScraper", + "fields": [ + { + "name": "SCREENSCRAPER_USER", + "label": "ScreenScraper username", + "sensitive": false + }, + { + "name": "SCREENSCRAPER_PASSWORD", + "label": "ScreenScraper password", + "sensitive": true + } + ] + }, + { + "service": "romm", + "label": "SteamGridDB", + "fields": [ + { + "name": "STEAMGRIDDB_API_KEY", + "label": "SteamGridDB API key", + "sensitive": true + } + ] + } + ], + "stack_adaptation_notes": [ + "DB_PASSWD and MARIADB_PASSWORD share one generated secret. The MariaDB root password is independent.", + "External metadata credentials are optional user input, never randomly generated. Without them, associated metadata integrations are not configured.", + "Configuration, assets, library, resources and database volumes default to private backed-up Proxmox volumes. Users can select host directories explicitly.", + "The hook starts stopped dependencies before RomM. It does not propagate manual dependency restarts to the application like Compose depends_on restart:true.", + "Latest tags are retained; first boot, hardware and upstream version compatibility remain unvalidated." + ], + "stack_references": [ + "https://docs.romm.app/5.2.0/install/databases/", + "https://docs.romm.app/5.2.0/reference/environment-variables/" + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/roonserver.json b/oci/catalog/apps/roonserver.json new file mode 100644 index 00000000..e7f792cc --- /dev/null +++ b/oci/catalog/apps/roonserver.json @@ -0,0 +1,630 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-roonserver", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Roon Server" + }, + "tagline": { + "en_US": "Music software that transforms your listening experience" + }, + "description": { + "en_US": "Roon music software transforms your listening experience with rich metadata, discovery features, and audiophile sound. It works with streaming services and local files.\n\nRoon brings all your music together and adds bios, reviews, photos, lyrics, tour dates, and cross-linked credits for performers, songwriters, producers, engineers, and composers. Everything about music - browsing, discovery, collecting, and listening - is more engaging with Roon.\n\nRoonServer is the central server component. It runs on a Linux amd64/x86_64 host, stores the Roon database and settings, and serves your library to Roon Remote clients and audio endpoints on your local network. It is controlled from the Roon app and does not provide a browser-based WebUI.\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Roon Labs", + "developer": "Roon Labs", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://roon.app", + "documentation": null, + "repository": "https://ghcr.io/roonlabs/roonserver", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "roonlabs", + "repository": "https://ghcr.io/roonlabs/roonserver", + "revision": "5887607d4ca3e9334fea6c4e49ff2e0884595935ae057f3976c90dc98b8bd106", + "image_repository_url": "https://ghcr.io/roonlabs/roonserver", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "5887607d4ca3e9334fea6c4e49ff2e0884595935ae057f3976c90dc98b8bd106", + "generated_at": "2026-09-13T17:20:19+00:00" + }, + "container_contract": { + "service_name": "roonserver", + "container_name": "roonserver", + "image": { + "reference": "ghcr.io/roonlabs/roonserver:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/roonlabs/roonserver", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ROON_INSTALL_BRANCH", + "example": "production", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/Roon", + "compose_source_example": "/DATA/AppData/$AppID/Roon", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/Music", + "compose_source_example": "/DATA/Media/Music", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/RoonBackups", + "compose_source_example": "/DATA/AppData/$AppID/RoonBackups", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/run/udev", + "compose_source_example": "/run/udev", + "read_only": true, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: roonserver\nservices:\n roonserver:\n image: ghcr.io/roonlabs/roonserver:latest\n container_name: roonserver\n network_mode: host\n restart: unless-stopped\n environment:\n ROON_INSTALL_BRANCH: production\n TZ: $TZ\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/Roon\n target: /Roon\n - type: bind\n source: /DATA/Media/Music\n target: /Music\n - type: bind\n source: /DATA/AppData/$AppID/RoonBackups\n target: /RoonBackups\n - type: bind\n source: /run/udev\n target: /run/udev\n read_only: true\n cap_add:\n - SYS_ADMIN\n - DAC_READ_SEARCH\n security_opt:\n - apparmor:unconfined\n - label:disable\n devices:\n - /dev/snd:/dev/snd\n - /dev/bus/usb:/dev/bus/usb\n - /dev/dri:/dev/dri\n group_add:\n - audio\n logging:\n driver: local\n" + }, + "compose_stack": { + "project_name": "roonserver", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "roonserver", + "service_count": 1, + "services": [ + { + "name": "roonserver", + "image": "ghcr.io/roonlabs/roonserver:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/roonlabs/roonserver:latest", + "container_name": "roonserver", + "network_mode": "host", + "restart": "unless-stopped", + "environment": { + "ROON_INSTALL_BRANCH": "production", + "TZ": "$TZ" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/Roon", + "target": "/Roon" + }, + { + "type": "bind", + "source": "/DATA/Media/Music", + "target": "/Music" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/RoonBackups", + "target": "/RoonBackups" + }, + { + "type": "bind", + "source": "/run/udev", + "target": "/run/udev", + "read_only": true + } + ], + "cap_add": [ + "SYS_ADMIN", + "DAC_READ_SEARCH" + ], + "security_opt": [ + "apparmor:unconfined", + "label:disable" + ], + "devices": [ + "/dev/snd:/dev/snd", + "/dev/bus/usb:/dev/bus/usb", + "/dev/dri:/dev/dri" + ], + "group_add": [ + "audio" + ], + "logging": { + "driver": "local" + } + } + } + ], + "top_level": { + "name": "roonserver" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "roonserver-volume-0", + "service": "roonserver", + "container_path": "/Roon", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "roonserver-volume-1", + "service": "roonserver", + "container_path": "/Music", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for roonserver:/Music" + }, + { + "id": "roonserver-volume-2", + "service": "roonserver", + "container_path": "/RoonBackups", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "roonserver-volume-3", + "service": "roonserver", + "container_path": "/run/udev", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "roonserver" + ], + "stop_order": [ + "roonserver" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "supplemental_groups": [ + "audio" + ] + }, + "network": { + "compose_mode": "host" + }, + "security": { + "required_capabilities": [ + "SYS_ADMIN", + "DAC_READ_SEARCH" + ], + "options": { + "apparmor_profile": "unconfined", + "selinux_label_disabled": true + } + }, + "hardware_acceleration": { + "prompt": "Hardware acceleration for Roon Server", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ] + } + ] + }, + "optional_devices": [ + { + "id": "dev-snd", + "kind": "character-device-tree", + "purpose": "audio", + "enable_prompt": "Host audio devices", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Audio device directory", + "host_path_default": "/dev/snd", + "container_path": "/dev/snd", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/snd:/dev/snd" + }, + { + "id": "dev-bus-usb", + "kind": "character-device-tree", + "purpose": "usb", + "enable_prompt": "Host USB bus", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "USB bus directory", + "host_path_default": "/dev/bus/usb", + "container_path": "/dev/bus/usb", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/bus/usb:/dev/bus/usb" + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": true, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": true, + "warning": "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "catalog": { + "replaces_discovered_ids": [ + "roonserver" + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/rpcs3.json b/oci/catalog/apps/rpcs3.json new file mode 100644 index 00000000..eff0637a --- /dev/null +++ b/oci/catalog/apps/rpcs3.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-rpcs3", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Rpcs3" + }, + "tagline": { + "en_US": "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD." + }, + "description": { + "en_US": "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rpcs3-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rpcs3-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://rpcs3.net/", + "documentation": "https://docs.linuxserver.io/images/docker-rpcs3/", + "repository": "https://github.com/linuxserver/docker-rpcs3", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-30", + "note": "Start ingesting head appimage again, add notes on using SDL for controller support." + }, + { + "date": "2026-03-20", + "note": "Pin back to latest v0.0.37 build to function, make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-06-19", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-07-30" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-rpcs3", + "default_branch": "master", + "revision": "14bfb43509b393eee7333715c5af795907f530e2", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-rpcs3/14bfb43509b393eee7333715c5af795907f530e2/README.md", + "readme_pushed_at": "2026-09-11T22:09:47Z", + "compose_sha256": "a01d740b7e7b50ee0bfa63002b34561728d06a0d6fc9b347d24e2623bf34b7e7", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "rpcs3", + "container_name": "rpcs3", + "image": { + "reference": "lscr.io/linuxserver/rpcs3:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/rpcs3", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n rpcs3:\n image: lscr.io/linuxserver/rpcs3:latest\n container_name: rpcs3\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/rsnapshot.json b/oci/catalog/apps/rsnapshot.json new file mode 100644 index 00000000..7591f18a --- /dev/null +++ b/oci/catalog/apps/rsnapshot.json @@ -0,0 +1,259 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-rsnapshot", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Rsnapshot" + }, + "tagline": { + "en_US": "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required." + }, + "description": { + "en_US": "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rsnapshot-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rsnapshot-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "http://www.rsnapshot.org/", + "documentation": "https://docs.linuxserver.io/images/docker-rsnapshot/", + "repository": "https://github.com/linuxserver/docker-rsnapshot", + "tips": [], + "mini_changelog": [ + { + "date": "2025-02-01", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-03-06", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19, add root periodic crontabs for logrotate." + }, + { + "date": "2023-05-25", + "note": "Rebase to Alpine 3.18, deprecate armhf." + }, + { + "date": "2023-03-02", + "note": "Split cron into separate init step and set crontab permissions." + } + ], + "display_version": null, + "updated_at": "2025-02-01" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-rsnapshot", + "default_branch": "master", + "revision": "cfc80cd19f1acb519b94587bb4f010b39c26753c", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-rsnapshot/cfc80cd19f1acb519b94587bb4f010b39c26753c/README.md", + "readme_pushed_at": "2026-09-10T09:13:39Z", + "compose_sha256": "258d8ef5616e04b90448db4005e4e7af58ccb070e94e123402e155c1eaadb6fa", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "rsnapshot", + "container_name": "rsnapshot", + "image": { + "reference": "lscr.io/linuxserver/rsnapshot:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/rsnapshot", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/rsnapshot/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/.snapshots", + "compose_source_example": "/path/to/snapshots", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/data", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n rsnapshot:\n image: lscr.io/linuxserver/rsnapshot:latest\n container_name: rsnapshot\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/rsnapshot/config:/config\n - /path/to/snapshots:/.snapshots #optional\n - /path/to/data:/data #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/rustdesk.json b/oci/catalog/apps/rustdesk.json new file mode 100644 index 00000000..2fc9f83a --- /dev/null +++ b/oci/catalog/apps/rustdesk.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-rustdesk", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Rustdesk" + }, + "tagline": { + "en_US": "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration." + }, + "description": { + "en_US": "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rustdesk-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rustdesk-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://rustdesk.com/", + "documentation": "https://docs.linuxserver.io/images/docker-rustdesk/", + "repository": "https://github.com/linuxserver/docker-rustdesk", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-07-25", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-rustdesk", + "default_branch": "master", + "revision": "c968e1d72cca16ceafe363e42a62a55ba0146431", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-rustdesk/c968e1d72cca16ceafe363e42a62a55ba0146431/README.md", + "readme_pushed_at": "2026-09-10T18:43:55Z", + "compose_sha256": "b430167abdc02cff9b6899bc266f816c11a4cb2bc29253d01eb925d8ee9a1b85", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "rustdesk", + "container_name": "rustdesk", + "image": { + "reference": "lscr.io/linuxserver/rustdesk:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/rustdesk", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n rustdesk:\n image: lscr.io/linuxserver/rustdesk:latest\n container_name: rustdesk\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-rustdesk/master/Dockerfile", + "dockerfile_sha256": "f1b789a119aed58821c2e113e74a7381f671e97c2f71eac60416f45d5c1ade14", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/sabnzbd.json b/oci/catalog/apps/sabnzbd.json new file mode 100644 index 00000000..8f629c4d --- /dev/null +++ b/oci/catalog/apps/sabnzbd.json @@ -0,0 +1,275 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-sabnzbd", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Sabnzbd" + }, + "tagline": { + "en_US": "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction." + }, + "description": { + "en_US": "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sabnzbd-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sabnzbd-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "http://sabnzbd.org/", + "documentation": "https://docs.linuxserver.io/images/docker-sabnzbd/", + "repository": "https://github.com/linuxserver/docker-sabnzbd", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-04", + "note": "Rebase to Alpine 3.24" + }, + { + "date": "2025-12-28", + "note": "Rebase to Alpine 3.23. Add RISCV build." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-23", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase to Alpine 3.20. Remove nzbnotify as apprise is now included with SABnzbd." + } + ], + "display_version": null, + "updated_at": "2026-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-sabnzbd", + "default_branch": "master", + "revision": "4938896535f9173c3429caf9f24b53013f5f2019", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-sabnzbd/4938896535f9173c3429caf9f24b53013f5f2019/README.md", + "readme_pushed_at": "2026-09-11T15:27:05Z", + "compose_sha256": "2c1d3c3382e2cbc33ae9f66cfc178cc6d9d67f59435d7352111e8b9ee4aa4d29", + "generated_at": "2026-09-12T14:37:35+00:00" + }, + "container_contract": { + "service_name": "sabnzbd", + "container_name": "sabnzbd", + "image": { + "reference": "lscr.io/linuxserver/sabnzbd:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/sabnzbd", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/sabnzbd/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/incomplete-downloads", + "compose_source_example": "/path/to/incomplete/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n sabnzbd:\n image: lscr.io/linuxserver/sabnzbd:latest\n container_name: sabnzbd\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/sabnzbd/config:/config\n - /path/to/incomplete/downloads:/incomplete-downloads #optional\n - /path/to/downloads:/downloads #optional\n ports:\n - 8080:8080\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/scummvm.json b/oci/catalog/apps/scummvm.json new file mode 100644 index 00000000..309f6bef --- /dev/null +++ b/oci/catalog/apps/scummvm.json @@ -0,0 +1,378 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-scummvm", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Scummvm" + }, + "tagline": { + "en_US": "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator." + }, + "description": { + "en_US": "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/scummvm-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/scummvm-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.scummvm.org/", + "documentation": "https://docs.linuxserver.io/images/docker-scummvm/", + "repository": "https://github.com/linuxserver/docker-scummvm", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-20", + "note": "Rebase to Debian Trixie, make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-01-13", + "note": "Rebase to Ubuntu Noble, add wayland init." + }, + { + "date": "2025-08-25", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-06-20" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-scummvm", + "default_branch": "master", + "revision": "c319e98cbee1e614f4270977855344eb3a214d2b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-scummvm/c319e98cbee1e614f4270977855344eb3a214d2b/README.md", + "readme_pushed_at": "2026-09-09T22:29:59Z", + "compose_sha256": "37a5af91ce004c9a36aa5cd5d6f13038f58b79a30148e419d049c3daab54c2ef", + "generated_at": "2026-09-13T17:20:16+00:00" + }, + "container_contract": { + "service_name": "scummvm", + "container_name": "scummvm", + "image": { + "reference": "lscr.io/linuxserver/scummvm:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/scummvm", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n scummvm:\n image: lscr.io/linuxserver/scummvm:latest\n container_name: scummvm\n security_opt:\n - seccomp:unconfined #optional\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "security": { + "optional_relaxations": [ + { + "id": "seccomp-unconfined", + "enable_prompt": "Apply optional security relaxation seccomp:unconfined", + "enabled_default": false, + "options": { + "seccomp_profile": "unconfined" + } + } + ] + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": true, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": true, + "risk_level": "high", + "confirmation_required": false, + "warning": "The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/sealskin.json b/oci/catalog/apps/sealskin.json new file mode 100644 index 00000000..36d2cb52 --- /dev/null +++ b/oci/catalog/apps/sealskin.json @@ -0,0 +1,287 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-sealskin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Sealskin" + }, + "tagline": { + "en_US": "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions\u2014such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server." + }, + "description": { + "en_US": "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions\u2014such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sealskin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sealskin-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8443, + "path": "/" + }, + "website": "https://github.com/selkies-project/sealskin/", + "documentation": "https://docs.linuxserver.io/images/docker-sealskin/", + "repository": "https://github.com/linuxserver/docker-sealskin", + "tips": [], + "mini_changelog": [ + { + "date": "2026-09-05", + "note": "Install Sealskin from the upstream Python wheel, rebase to Alpine 3.24." + }, + { + "date": "2026-02-11", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2026-01-19", + "note": "Fix init race condition." + }, + { + "date": "2026-01-17", + "note": "Update docs to remove network and port requirement, add link to Firefox add on." + }, + { + "date": "2026-01-08", + "note": "Improve permission fixing." + } + ], + "display_version": null, + "updated_at": "2026-09-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-sealskin", + "default_branch": "master", + "revision": "f94888a6d7537c97ea3bb38accc4aff057af8329", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-sealskin/f94888a6d7537c97ea3bb38accc4aff057af8329/README.md", + "readme_pushed_at": "2026-09-11T18:38:38Z", + "compose_sha256": "252970005a2464ae2f667d8369352b252f71944b69250d20daaf7873d71b9abc", + "generated_at": "2026-09-12T14:37:36+00:00" + }, + "container_contract": { + "service_name": "sealskin", + "container_name": "sealskin", + "image": { + "reference": "lscr.io/linuxserver/sealskin:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/sealskin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "HOST_URL", + "example": "IP or subdomain.doman.com", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/sealskin/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/storage", + "compose_source_example": "/path/to/sealskin/storage", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/var/run/docker.sock", + "compose_source_example": "/var/run/docker.sock", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8443, + "published_example": 8443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n sealskin:\n image: lscr.io/linuxserver/sealskin:latest\n container_name: sealskin\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - \"HOST_URL=IP or subdomain.doman.com\" #optional\n volumes:\n - /path/to/sealskin/config:/config\n - /path/to/sealskin/storage:/storage\n - /var/run/docker.sock:/var/run/docker.sock\n ports:\n - 8443:8443\n - 8000:8000 #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8443, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/seerr.json b/oci/catalog/apps/seerr.json new file mode 100644 index 00000000..60596c0b --- /dev/null +++ b/oci/catalog/apps/seerr.json @@ -0,0 +1,459 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-seerr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Seerr" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "Media discovery and request management for Jellyfin, Plex and Emby." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "official", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5055, + "path": "/" + }, + "website": "https://docs.seerr.dev/getting-started/docker/", + "documentation": "https://docs.seerr.dev/getting-started/docker/", + "repository": "https://github.com/seerr-team/seerr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://github.com/seerr-team/seerr", + "revision": "872efff668cfd0f1e026111a266306b1b582b86746fff5467f11e5daddddf671", + "image_repository_url": "https://ghcr.io/seerr-team/seerr", + "readme_pushed_at": "", + "compose_sha256": "872efff668cfd0f1e026111a266306b1b582b86746fff5467f11e5daddddf671", + "generated_at": "2026-09-14T17:13:55+00:00" + }, + "container_contract": { + "service_name": "seerr", + "container_name": "seerr", + "image": { + "reference": "ghcr.io/seerr-team/seerr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/seerr-team/seerr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PORT", + "example": "5055", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOG_LEVEL", + "example": "info", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5055, + "published_example": 5055, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: seerr\nservices:\n seerr:\n image: ghcr.io/seerr-team/seerr:latest\n init: true\n environment:\n TZ: Europe/Madrid\n PORT: '5055'\n LOG_LEVEL: info\n ports:\n - 5055:5055\n volumes:\n - /path/to/config:/app/config\n security_opt:\n - no-new-privileges\n cap_drop:\n - ALL\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "seerr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "seerr", + "service_count": 1, + "services": [ + { + "name": "seerr", + "image": "ghcr.io/seerr-team/seerr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/seerr-team/seerr:latest", + "init": true, + "environment": { + "TZ": "Europe/Madrid", + "PORT": "5055", + "LOG_LEVEL": "info" + }, + "ports": [ + "5055:5055" + ], + "volumes": [ + "/path/to/config:/app/config" + ], + "security_opt": [ + "no-new-privileges" + ], + "cap_drop": [ + "ALL" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "seerr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "seerr-volume-0", + "service": "seerr", + "container_path": "/app/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "seerr" + ], + "stop_order": [ + "seerr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Seerr WebUI", + "scheme": "http", + "port": 5055, + "path": "/", + "source": "upstream-documentation" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "references": [ + "https://docs.seerr.dev/getting-started/docker/" + ], + "startup_healthcheck": { + "scheme": "http", + "port": 5055, + "path": "/api/v1/settings/public", + "timeout_seconds": 360 + }, + "security": { + "options": { + "no_new_privileges": true, + "drop_all_capabilities": true + } + }, + "adaptations": [ + "Compose cap_drop ALL -> lxc.cap.drop reset and lxc.cap.keep none; no-new-privileges -> lxc.no_new_privs 1." + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "cap_drop", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/shadps4.json b/oci/catalog/apps/shadps4.json new file mode 100644 index 00000000..89584b54 --- /dev/null +++ b/oci/catalog/apps/shadps4.json @@ -0,0 +1,256 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-shadps4", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Shadps4" + }, + "tagline": { + "en_US": "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++." + }, + "description": { + "en_US": "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/shadps4-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/shadps4-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://shadps4.net/", + "documentation": "https://docs.linuxserver.io/images/docker-shadps4/", + "repository": "https://github.com/linuxserver/docker-shadps4", + "tips": [], + "mini_changelog": [ + { + "date": "2026-02-25", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-02-25" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-shadps4", + "default_branch": "master", + "revision": "6547664b4100593aa1211e98f1ba2b1f2d3ba602", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-shadps4/6547664b4100593aa1211e98f1ba2b1f2d3ba602/README.md", + "readme_pushed_at": "2026-09-12T09:53:43Z", + "compose_sha256": "cd44bbe5cc1ea4813c08bb7c10fe059d2138358faade1dbf70b054b83c18f54d", + "generated_at": "2026-09-12T14:37:36+00:00" + }, + "container_contract": { + "service_name": "shadps4", + "container_name": "shadps4", + "image": { + "reference": "lscr.io/linuxserver/shadps4:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/shadps4", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n shadps4:\n image: lscr.io/linuxserver/shadps4:latest\n container_name: shadps4\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/shotcut.json b/oci/catalog/apps/shotcut.json new file mode 100644 index 00000000..a6b862ae --- /dev/null +++ b/oci/catalog/apps/shotcut.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-shotcut", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Shotcut" + }, + "tagline": { + "en_US": "Shotcut is a free, open source, cross-platform video editor." + }, + "description": { + "en_US": "Shotcut is a free, open source, cross-platform video editor." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/shotcut-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/shotcut-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.shotcut.org/", + "documentation": "https://docs.linuxserver.io/images/docker-shotcut/", + "repository": "https://github.com/linuxserver/docker-shotcut", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-30", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-02-05", + "note": "Disable gamepad interposer." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-03-30" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-shotcut", + "default_branch": "main", + "revision": "9c28483232efa3843e8bd3662bb1f72984af5fab", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-shotcut/9c28483232efa3843e8bd3662bb1f72984af5fab/README.md", + "readme_pushed_at": "2026-09-09T07:50:00Z", + "compose_sha256": "4c35cd5d199901b77112da9fc99ffd5345dc54af57257113890ac2e5e138b81a", + "generated_at": "2026-09-12T14:37:36+00:00" + }, + "container_contract": { + "service_name": "shotcut", + "container_name": "shotcut", + "image": { + "reference": "lscr.io/linuxserver/shotcut:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/shotcut", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n shotcut:\n image: lscr.io/linuxserver/shotcut:latest\n container_name: shotcut\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/data:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-shotcut/master/Dockerfile", + "dockerfile_sha256": "2bf9ad9e5688aa694451425e906c8c4ad0158f8122dbf00148847c46a78db6b4", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/sickchill.json b/oci/catalog/apps/sickchill.json new file mode 100644 index 00000000..83cd80d3 --- /dev/null +++ b/oci/catalog/apps/sickchill.json @@ -0,0 +1,492 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-sickchill", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Sickchill" + }, + "tagline": { + "en_US": "Automatic video library manager for TV Shows" + }, + "description": { + "en_US": "SickChill is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic: automatic torrent/nzb searching, downloading, and processing at the qualities you want.\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Sickchill Team", + "developer": "Sickchill Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8081, + "path": "/" + }, + "website": "https://sickchill.github.io", + "documentation": "https://docs.linuxserver.io/images/docker-sickchill/", + "repository": "https://hub.docker.com/r/linuxserver/sickchill", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://hub.docker.com/r/linuxserver/sickchill", + "revision": "c5c5049627b04d9ee014af2d18a1cae5dbf0601653d678e29937f0d226383939", + "image_repository_url": "https://hub.docker.com/r/linuxserver/sickchill", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "c5c5049627b04d9ee014af2d18a1cae5dbf0601653d678e29937f0d226383939", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "sickchill", + "container_name": "sickchill", + "image": { + "reference": "linuxserver/sickchill:latest", + "registry": "docker.io", + "repository": "linuxserver/sickchill", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "Europe/London", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/sickchill/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/DATA/Downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/tv", + "compose_source_example": "/DATA/Media/TV Shows", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8081, + "published_example": 8081, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: sickchill\nservices:\n sickchill:\n environment:\n PGID: '1000'\n PUID: '1000'\n TZ: Europe/London\n image: linuxserver/sickchill:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 8081\n published: '8081'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/sickchill/config\n target: /config\n - type: bind\n source: /DATA/Downloads\n target: /downloads\n - type: bind\n source: /DATA/Media/TV Shows\n target: /tv\n container_name: sickchill\n" + }, + "compose_stack": { + "project_name": "sickchill", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "sickchill", + "service_count": 1, + "services": [ + { + "name": "sickchill", + "image": "linuxserver/sickchill:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "PGID": "1000", + "PUID": "1000", + "TZ": "Europe/London" + }, + "image": "linuxserver/sickchill:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8081, + "published": "8081", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/sickchill/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/Downloads", + "target": "/downloads" + }, + { + "type": "bind", + "source": "/DATA/Media/TV Shows", + "target": "/tv" + } + ], + "container_name": "sickchill" + } + } + ], + "top_level": { + "name": "sickchill" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "sickchill-volume-0", + "service": "sickchill", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "sickchill-volume-1", + "service": "sickchill", + "container_path": "/downloads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for sickchill:/downloads" + }, + { + "id": "sickchill-volume-2", + "service": "sickchill", + "container_path": "/tv", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for sickchill:/tv" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "sickchill" + ], + "stop_order": [ + "sickchill" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8081, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/sickgear.json b/oci/catalog/apps/sickgear.json new file mode 100644 index 00000000..b576b0e2 --- /dev/null +++ b/oci/catalog/apps/sickgear.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-sickgear", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Sickgear" + }, + "tagline": { + "en_US": "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more.." + }, + "description": { + "en_US": "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more.." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sickgear-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sickgear-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8081, + "path": "/" + }, + "website": "https://github.com/sickgear/sickgear", + "documentation": "https://docs.linuxserver.io/images/docker-sickgear/", + "repository": "https://github.com/linuxserver/docker-sickgear", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-06-25", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-10-08", + "note": "Install unrar from [linuxserver repo](https://github.com/linuxserver/docker-unrar)." + }, + { + "date": "2023-08-10", + "note": "Bump unrar to 6.2.10." + } + ], + "display_version": null, + "updated_at": "2025-07-09" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-sickgear", + "default_branch": "master", + "revision": "d9466bc369c70a9fd90dae3eff53322337cc0db8", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-sickgear/d9466bc369c70a9fd90dae3eff53322337cc0db8/README.md", + "readme_pushed_at": "2026-09-11T00:20:14Z", + "compose_sha256": "15464604d4b06c7264aa0fffd1070e05b78fc21e3b1c26b1748a3f97ca883c0c", + "generated_at": "2026-09-12T14:37:36+00:00" + }, + "container_contract": { + "service_name": "sickgear", + "container_name": "sickgear", + "image": { + "reference": "lscr.io/linuxserver/sickgear:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/sickgear", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/sickgear/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/tv", + "compose_source_example": "/path/to/tv", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8081, + "published_example": 8081, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n sickgear:\n image: lscr.io/linuxserver/sickgear:latest\n container_name: sickgear\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/sickgear/data:/config\n - /path/to/tv:/tv\n - /path/to/downloads:/downloads\n ports:\n - 8081:8081\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8081, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/signal.json b/oci/catalog/apps/signal.json new file mode 100644 index 00000000..eb1c9e60 --- /dev/null +++ b/oci/catalog/apps/signal.json @@ -0,0 +1,268 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-signal", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Signal" + }, + "tagline": { + "en_US": "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private." + }, + "description": { + "en_US": "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/signal-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/signal-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://signal.org/", + "documentation": "https://docs.linuxserver.io/images/docker-signal/", + "repository": "https://github.com/linuxserver/docker-signal", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-12-02", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-04-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-signal", + "default_branch": "master", + "revision": "4e025ada42aa0e832a7cb34a710e1fb1d54ea998", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-signal/4e025ada42aa0e832a7cb34a710e1fb1d54ea998/README.md", + "readme_pushed_at": "2026-09-12T10:05:22Z", + "compose_sha256": "d5d7b9f1fcaafdb6327d6d34bb071a3e6d9f25b14713a6a9b80bbad2aa9daec7", + "generated_at": "2026-09-12T14:37:36+00:00" + }, + "container_contract": { + "service_name": "signal", + "container_name": "signal", + "image": { + "reference": "lscr.io/linuxserver/signal:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/signal", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n signal:\n image: lscr.io/linuxserver/signal:latest\n container_name: signal\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/siyuan-note.json b/oci/catalog/apps/siyuan-note.json new file mode 100644 index 00000000..93c3bb5d --- /dev/null +++ b/oci/catalog/apps/siyuan-note.json @@ -0,0 +1,426 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-siyuan-note", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "SiYuan Note" + }, + "tagline": { + "en_US": "Private personal knowledge management" + }, + "description": { + "en_US": "Experience Seamless Knowledge Management with SiYuan. SiYuan redefines knowledge management by seamlessly integrating with your home TV, mobile devices, and other platforms. Unlike traditional knowledge systems, SiYuan offers a cohesive and flexible environment that adapts to your lifestyle, allowing you to access and organize information effortlessly across all your devices. Whether you are a creator or a regular consumer, SiYuan's innovative approach ensures your knowledge is always at your fingertips.\n\nPowerful Features, Minimal Cost. SiYuan stands out with its robust set of features, most of which are free, even for commercial use. Enjoy block-level referencing, two-way links, custom attributes, SQL query embeds, and the unique protocol siyuan://. The editor supports block-style, markdown WYSIWYG, list outlines, and block zoom-in. Handle large documents with ease and include mathematical formulas, charts, flowcharts, and more. Capture web content, annotate PDFs, and export in various formats including Markdown, PDF, Word, and HTML. SiYuan also offers AI-powered writing and Q/A chat via OpenAI API, Tesseract OCR, and multi-tab support for a comprehensive and seamless experience.\n\nUnlimited Storage, Local Speed, Multi-Device Access. Deploying Alist on self-hosted server private cloud devices brings unparalleled convenience. Enjoy unlimited storage, blazing-fast local network speeds, and access from multiple devices. This setup ensures that your data is always available, secure, and quickly accessible, providing a superior alternative to traditional cloud services.\n" + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "siyuan-note", + "developer": "siyuan-note", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6806, + "path": "/" + }, + "website": "https://b3log.org/siyuan/", + "documentation": null, + "repository": "https://hub.docker.com/r/b3log/siyuan", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "b3log", + "repository": "https://hub.docker.com/r/b3log/siyuan", + "revision": "58e993a4cc27f99134e898256a55e4c6e2e811973b6d227b1e843ba38fd90f05", + "image_repository_url": "https://hub.docker.com/r/b3log/siyuan", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "58e993a4cc27f99134e898256a55e4c6e2e811973b6d227b1e843ba38fd90f05", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "siyuan-note", + "container_name": "siyuan-note", + "image": { + "reference": "b3log/siyuan:latest", + "registry": "docker.io", + "repository": "b3log/siyuan", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/siyuan/workspace", + "compose_source_example": "/DATA/AppData/$AppID/workspace", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 6806, + "published_example": 6806, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: siyuan-note\nservices:\n siyuan-note:\n command: --accessAuthCode=siyuan-note --workspace=/siyuan/workspace/\n environment:\n PUID: '1000'\n PGID: '1000'\n image: b3log/siyuan:latest\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 6806\n published: '6806'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/workspace\n target: /siyuan/workspace\n container_name: siyuan-note\n" + }, + "compose_stack": { + "project_name": "siyuan-note", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "siyuan-note", + "service_count": 1, + "services": [ + { + "name": "siyuan-note", + "image": "b3log/siyuan:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "command": "--accessAuthCode=siyuan-note --workspace=/siyuan/workspace/", + "environment": { + "PUID": "1000", + "PGID": "1000" + }, + "image": "b3log/siyuan:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 6806, + "published": "6806", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/workspace", + "target": "/siyuan/workspace" + } + ], + "container_name": "siyuan-note" + } + } + ], + "top_level": { + "name": "siyuan-note" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "siyuan-note-volume-0", + "service": "siyuan-note", + "container_path": "/siyuan/workspace", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "siyuan-note" + ], + "stop_order": [ + "siyuan-note" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6806, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": "--accessAuthCode=casaos --workspace=/siyuan/workspace/" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/smokeping.json b/oci/catalog/apps/smokeping.json new file mode 100644 index 00000000..3e84fb7a --- /dev/null +++ b/oci/catalog/apps/smokeping.json @@ -0,0 +1,356 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-smokeping", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Smokeping" + }, + "tagline": { + "en_US": "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis." + }, + "description": { + "en_US": "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis." + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/smokeping-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/smokeping-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://oss.oetiker.ch/smokeping/", + "documentation": "https://docs.linuxserver.io/images/docker-smokeping/", + "repository": "https://github.com/linuxserver/docker-smokeping", + "tips": [], + "mini_changelog": [ + { + "date": "2025-12-17", + "note": "Replace busybox traceroute with APK version." + }, + { + "date": "2025-09-26", + "note": "Add IO::Socket::INET6 perl module to improve IPv6 abilities." + }, + { + "date": "2025-06-05", + "note": "Update TCPPing to 2.7 to fix traceroute incompatibility." + }, + { + "date": "2025-06-03", + "note": "Rebase to Alpine 3.22. Update TCPPing. Add curl probe." + }, + { + "date": "2024-07-27", + "note": "Add additional dependency packages for InfluxDB." + } + ], + "display_version": null, + "updated_at": "2025-12-17" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-smokeping", + "default_branch": "master", + "revision": "4d554b33371fedc8478d21a386f222d0cd802c0f", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-smokeping/4d554b33371fedc8478d21a386f222d0cd802c0f/README.md", + "readme_pushed_at": "2026-09-08T23:14:48Z", + "compose_sha256": "8d4fd2d4a87fc7673b8f9640889a49bd7abce6835397fe562850198a80a46253", + "generated_at": "2026-09-13T14:54:05+00:00" + }, + "container_contract": { + "service_name": "smokeping", + "container_name": "smokeping", + "image": { + "reference": "lscr.io/linuxserver/smokeping:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/smokeping", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MASTER_URL", + "example": "http://:80/smokeping/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SHARED_SECRET", + "example": "password", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "CACHE_DIR", + "example": "/tmp", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/smokeping/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/smokeping/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n smokeping:\n image: lscr.io/linuxserver/smokeping:latest\n container_name: smokeping\n hostname: smokeping #optional\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - MASTER_URL=http://:80/smokeping/ #optional\n - SHARED_SECRET=password #optional\n - CACHE_DIR=/tmp #optional\n volumes:\n - /path/to/smokeping/config:/config\n - /path/to/smokeping/data:/data\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "hostname": "smokeping" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/snapdrop.json b/oci/catalog/apps/snapdrop.json new file mode 100644 index 00000000..6e83a6fe --- /dev/null +++ b/oci/catalog/apps/snapdrop.json @@ -0,0 +1,434 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-snapdrop", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "snapdrop" + }, + "tagline": { + "en_US": "Cross-platform file sharing made easy." + }, + "description": { + "en_US": "Snapdrop is a Progressive Web App (PWA) that allows you to transfer files between devices in the same network without having to install anything." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "linuxserver.io", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://snapdrop.net", + "documentation": "https://docs.linuxserver.io/images/docker-snapdrop/", + "repository": "https://hub.docker.com/r/linuxserver/snapdrop", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://hub.docker.com/r/linuxserver/snapdrop", + "revision": "3bff428dfc1c5efc60f358ce470fbfc477194e39ea38fb8b6f1603289916c49a", + "image_repository_url": "https://hub.docker.com/r/linuxserver/snapdrop", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "3bff428dfc1c5efc60f358ce470fbfc477194e39ea38fb8b6f1603289916c49a", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "snapdrop", + "container_name": "snapdrop", + "image": { + "reference": "linuxserver/snapdrop:latest", + "registry": "docker.io", + "repository": "linuxserver/snapdrop", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 80, + "published_example": 89, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: snapdrop\nservices:\n snapdrop:\n environment:\n - PGID=$PGID\n - PUID=$PUID\n - TZ=$TZ\n image: linuxserver/snapdrop:latest\n network_mode: bridge\n ports:\n - target: 443\n published: '443'\n protocol: tcp\n - target: 80\n published: '89'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n privileged: false\n container_name: snapdrop\n" + }, + "compose_stack": { + "project_name": "snapdrop", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "snapdrop", + "service_count": 1, + "services": [ + { + "name": "snapdrop", + "image": "linuxserver/snapdrop:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": [ + "PGID=$PGID", + "PUID=$PUID", + "TZ=$TZ" + ], + "image": "linuxserver/snapdrop:latest", + "network_mode": "bridge", + "ports": [ + { + "target": 443, + "published": "443", + "protocol": "tcp" + }, + { + "target": 80, + "published": "89", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + } + ], + "privileged": false, + "container_name": "snapdrop" + } + } + ], + "top_level": { + "name": "snapdrop" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "snapdrop-volume-0", + "service": "snapdrop", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "snapdrop" + ], + "stop_order": [ + "snapdrop" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/snapotter.json b/oci/catalog/apps/snapotter.json new file mode 100644 index 00000000..9bfd6095 --- /dev/null +++ b/oci/catalog/apps/snapotter.json @@ -0,0 +1,529 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-snapotter", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "SnapOtter" + }, + "tagline": { + "en_US": "Self-hosted file toolkit for images, video, audio, PDFs, and files" + }, + "description": { + "en_US": "SnapOtter is an open-source, self-hosted file manipulation suite with 200+ tools across images, video, audio, PDFs, and files. It includes batch processing, reusable pipelines, local AI tools, a browser image editor, and a REST API so files stay on your own server.\n\nThis package uses SnapOtter's single-container embedded mode for an easy self-hosted server install. PostgreSQL 17 and Redis 8 run inside the container when DATABASE_URL and REDIS_URL are left unset, with persistent data stored under /data.\n\nDefault login is admin / admin. SnapOtter asks you to change the default password after first login.\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "SnapOtter", + "developer": "SnapOtter", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 1349, + "path": "/" + }, + "website": "https://snapotter.com", + "documentation": null, + "repository": "https://hub.docker.com/r/snapotter/snapotter", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/snapotter/snapotter", + "revision": "9cef44cb2f09c4646a6e175825b26d100303c531fd14d83f9a3b8a82073f8fdf", + "image_repository_url": "https://hub.docker.com/r/snapotter/snapotter", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "9cef44cb2f09c4646a6e175825b26d100303c531fd14d83f9a3b8a82073f8fdf", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "snapotter", + "container_name": "snapotter", + "image": { + "reference": "snapotter/snapotter:latest", + "registry": "docker.io", + "repository": "snapotter/snapotter", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "AUTH_ENABLED", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEFAULT_USERNAME", + "example": "admin", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEFAULT_PASSWORD", + "example": "${GENERATED_DEFAULT_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "MAX_UPLOAD_SIZE_MB", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MAX_BATCH_SIZE", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CONCURRENT_JOBS", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REDIS_MAXMEMORY", + "example": "512mb", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/tmp/workspace", + "compose_source_example": "/DATA/AppData/$AppID/workspace", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 1349, + "published_example": 1349, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: snapotter\nservices:\n snapotter:\n image: snapotter/snapotter:latest\n deploy:\n resources:\n reservations:\n memory: 1024M\n network_mode: bridge\n ports:\n - target: 1349\n published: '1349'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n - type: bind\n source: /DATA/AppData/$AppID/workspace\n target: /tmp/workspace\n environment:\n - AUTH_ENABLED=true\n - DEFAULT_USERNAME=admin\n - DEFAULT_PASSWORD=${GENERATED_DEFAULT_PASSWORD}\n - MAX_UPLOAD_SIZE_MB=0\n - MAX_BATCH_SIZE=0\n - CONCURRENT_JOBS=0\n - REDIS_MAXMEMORY=512mb\n healthcheck:\n test:\n - CMD\n - curl\n - -fsS\n - http://localhost:1349/api/v1/health\n interval: 30s\n timeout: 10s\n retries: 10\n start_period: 90s\n container_name: snapotter\n" + }, + "compose_stack": { + "project_name": "snapotter", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "snapotter", + "service_count": 1, + "services": [ + { + "name": "snapotter", + "image": "snapotter/snapotter:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "snapotter/snapotter:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 1349, + "published": "1349", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/workspace", + "target": "/tmp/workspace" + } + ], + "environment": [ + "AUTH_ENABLED=true", + "DEFAULT_USERNAME=admin", + "DEFAULT_PASSWORD=${GENERATED_DEFAULT_PASSWORD}", + "MAX_UPLOAD_SIZE_MB=0", + "MAX_BATCH_SIZE=0", + "CONCURRENT_JOBS=0", + "REDIS_MAXMEMORY=512mb" + ], + "healthcheck": { + "test": [ + "CMD", + "curl", + "-fsS", + "http://localhost:1349/api/v1/health" + ], + "interval": "30s", + "timeout": "10s", + "retries": 10, + "start_period": "90s" + }, + "container_name": "snapotter" + } + } + ], + "top_level": { + "name": "snapotter" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "snapotter-volume-0", + "service": "snapotter", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for snapotter:/data" + }, + { + "id": "snapotter-volume-1", + "service": "snapotter", + "container_path": "/tmp/workspace", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "snapotter" + ], + "stop_order": [ + "snapotter" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "default-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "snapotter", + "environment_variable": "DEFAULT_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 1349, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "startup_healthcheck": { + "type": "http", + "scheme": "http", + "port": 1349, + "path": "/api/v1/health", + "timeout_seconds": 390, + "request_timeout_seconds": 10, + "stability_seconds": 0, + "verify_tls": true, + "required": true, + "source": "compose-healthcheck" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "pending-per-application" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/sonarr.json b/oci/catalog/apps/sonarr.json new file mode 100644 index 00000000..70328ebe --- /dev/null +++ b/oci/catalog/apps/sonarr.json @@ -0,0 +1,275 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-sonarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Sonarr" + }, + "tagline": { + "en_US": "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available." + }, + "description": { + "en_US": "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sonarr-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sonarr-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8989, + "path": "/" + }, + "website": "https://sonarr.tv/", + "documentation": "https://docs.linuxserver.io/images/docker-sonarr/", + "repository": "https://github.com/linuxserver/docker-sonarr", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-09", + "note": "Workaround malformed ncurses database." + }, + { + "date": "2026-07-04", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-15", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-09", + "note": "Fix rootless entrypoint." + } + ], + "display_version": null, + "updated_at": "2026-07-09" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-sonarr", + "default_branch": "master", + "revision": "e9da3fa2a7d36fe9ac80022bf5f2f222e6b906eb", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-sonarr/e9da3fa2a7d36fe9ac80022bf5f2f222e6b906eb/README.md", + "readme_pushed_at": "2026-09-12T01:31:34Z", + "compose_sha256": "d55907541f016ebd5a7fda5b5988a7b96fc384921a632dcab67b5c8081550d9a", + "generated_at": "2026-09-12T14:37:36+00:00" + }, + "container_contract": { + "service_name": "sonarr", + "container_name": "sonarr", + "image": { + "reference": "lscr.io/linuxserver/sonarr:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/sonarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/sonarr/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/tv", + "compose_source_example": "/path/to/tvseries", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloadclient-downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8989, + "published_example": 8989, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n sonarr:\n image: lscr.io/linuxserver/sonarr:latest\n container_name: sonarr\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/sonarr/data:/config\n - /path/to/tvseries:/tv #optional\n - /path/to/downloadclient-downloads:/downloads #optional\n ports:\n - 8989:8989\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8989, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/speedtest-tracker.json b/oci/catalog/apps/speedtest-tracker.json new file mode 100644 index 00000000..bcb0a581 --- /dev/null +++ b/oci/catalog/apps/speedtest-tracker.json @@ -0,0 +1,325 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-speedtest-tracker", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Speedtest Tracker" + }, + "tagline": { + "en_US": "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service." + }, + "description": { + "en_US": "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service." + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/speedtest-tracker-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/speedtest-tracker-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/alexjustesen/speedtest-tracker", + "documentation": "https://docs.linuxserver.io/images/docker-speedtest-tracker/", + "repository": "https://github.com/linuxserver/docker-speedtest-tracker", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-10-11", + "note": "Update nginx configs for v1.7.2. Existing users should update their nginx confs to avoid errors." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-20", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-07", + "note": "Cache Filament components and added APP_KEY as a required param." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-speedtest-tracker", + "default_branch": "main", + "revision": "6e2dcc96380d632e46a0709ddf299d1a477778a2", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-speedtest-tracker/6e2dcc96380d632e46a0709ddf299d1a477778a2/README.md", + "readme_pushed_at": "2026-09-05T23:00:15Z", + "compose_sha256": "ebf8cbab5b42e3f95aa1f33dd6901b285588ec6e3c7fdc2bb849bb821dfda2a2", + "generated_at": "2026-09-12T14:37:36+00:00" + }, + "container_contract": { + "service_name": "speedtest-tracker", + "container_name": "speedtest-tracker", + "image": { + "reference": "lscr.io/linuxserver/speedtest-tracker:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/speedtest-tracker", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_KEY", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_CONNECTION", + "example": "sqlite", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SPEEDTEST_SCHEDULE", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SPEEDTEST_SERVERS", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_DATABASE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USERNAME", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DISPLAY_TIMEZONE", + "example": "Etc/UTC", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PRUNE_RESULTS_OLDER_THAN", + "example": "0", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/speedtest-tracker/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n speedtest-tracker:\n image: lscr.io/linuxserver/speedtest-tracker:latest\n container_name: speedtest-tracker\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - APP_KEY=\n - APP_URL=\n - DB_CONNECTION=sqlite\n - SPEEDTEST_SCHEDULE=\n - SPEEDTEST_SERVERS=\n - DB_HOST= #optional\n - DB_PORT= #optional\n - DB_DATABASE= #optional\n - DB_USERNAME= #optional\n - DB_PASSWORD= #optional\n - DISPLAY_TIMEZONE=Etc/UTC #optional\n - PRUNE_RESULTS_OLDER_THAN=0 #optional\n volumes:\n - /path/to/speedtest-tracker/data:/config\n ports:\n - 80:80\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/spotube.json b/oci/catalog/apps/spotube.json new file mode 100644 index 00000000..bd0e5c75 --- /dev/null +++ b/oci/catalog/apps/spotube.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-spotube", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Spotube" + }, + "tagline": { + "en_US": "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium" + }, + "description": { + "en_US": "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/spotube-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/spotube-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://spotube.krtirtho.dev/", + "documentation": "https://docs.linuxserver.io/images/docker-spotube/", + "repository": "https://github.com/linuxserver/docker-spotube", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-10-09", + "note": "Add aarch64 support." + } + ], + "display_version": null, + "updated_at": "2026-04-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-spotube", + "default_branch": "master", + "revision": "edcf581f4932110d52cec4402d3abdf131ec01a8", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-spotube/edcf581f4932110d52cec4402d3abdf131ec01a8/README.md", + "readme_pushed_at": "2026-09-11T19:02:13Z", + "compose_sha256": "13f41b0eed8a747c4bb53b36dbc061ba39c2d0783982703ce3325a64c6c067a7", + "generated_at": "2026-09-12T14:37:37+00:00" + }, + "container_contract": { + "service_name": "spotube", + "container_name": "spotube", + "image": { + "reference": "lscr.io/linuxserver/spotube:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/spotube", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/spotube/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n spotube:\n image: lscr.io/linuxserver/spotube:latest\n container_name: spotube\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/spotube/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-spotube/master/Dockerfile", + "dockerfile_sha256": "f283a559a359244aba83d787b9e1457554df5360f503faa370a181b26c8e1e65", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/sqlitebrowser.json b/oci/catalog/apps/sqlitebrowser.json new file mode 100644 index 00000000..c42400bc --- /dev/null +++ b/oci/catalog/apps/sqlitebrowser.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-sqlitebrowser", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Sqlitebrowser" + }, + "tagline": { + "en_US": "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite." + }, + "description": { + "en_US": "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sqlitebrowser-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sqlitebrowser-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://sqlitebrowser.org/", + "documentation": "https://docs.linuxserver.io/images/docker-sqlitebrowser/", + "repository": "https://github.com/linuxserver/docker-sqlitebrowser", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-30", + "note": "Install Qt SVG for icon support." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-sqlitebrowser", + "default_branch": "master", + "revision": "2fbaf945ee94564e4c6d53d5f825b20e162bb246", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-sqlitebrowser/2fbaf945ee94564e4c6d53d5f825b20e162bb246/README.md", + "readme_pushed_at": "2026-09-12T06:53:37Z", + "compose_sha256": "61602c9185b2c63ee6336c9b796494bd8bdad3637fa9d90ed05acc89b44ee2a6", + "generated_at": "2026-09-12T14:37:37+00:00" + }, + "container_contract": { + "service_name": "sqlitebrowser", + "container_name": "sqlitebrowser", + "image": { + "reference": "lscr.io/linuxserver/sqlitebrowser:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/sqlitebrowser", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n sqlitebrowser:\n image: lscr.io/linuxserver/sqlitebrowser:latest\n container_name: sqlitebrowser\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-sqlitebrowser/master/Dockerfile", + "dockerfile_sha256": "730169e09e92074dbac9dfe5e16ad5841a2179d6c04413cf3522c98b45a57b51", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/stable-diffusion-webui-nvidia.json b/oci/catalog/apps/stable-diffusion-webui-nvidia.json new file mode 100644 index 00000000..caf53059 --- /dev/null +++ b/oci/catalog/apps/stable-diffusion-webui-nvidia.json @@ -0,0 +1,520 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-stable-diffusion-webui-nvidia", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Stable Diffusion" + }, + "tagline": { + "en_US": "An AI model used to generate images conditioned on text descriptions." + }, + "description": { + "en_US": "Stable Diffusion is a deep learning, text-to-image model released in 2022 based on diffusion techniques. It is primarily used to generate detailed images conditioned on text descriptions, though it can also be applied to other tasks such as inpainting, outpainting, and generating image-to-image translations guided by a text prompt." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "stability.ai", + "developer": "stability.ai", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 7860, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/johnguan/stable-diffusion-webui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "johnguan", + "repository": "https://hub.docker.com/r/johnguan/stable-diffusion-webui", + "revision": "c836d11a834ca88b5d5ad3d60397dffec94aef438446121f70d7bafa2028e930", + "image_repository_url": "https://hub.docker.com/r/johnguan/stable-diffusion-webui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "c836d11a834ca88b5d5ad3d60397dffec94aef438446121f70d7bafa2028e930", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "icewhale-stable-diffusion-webui", + "container_name": "icewhale-stable-diffusion-webui", + "image": { + "reference": "johnguan/stable-diffusion-webui:latest", + "registry": "docker.io", + "repository": "johnguan/stable-diffusion-webui", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "example": "all", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CPU_FALLBACK", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data/models", + "compose_source_example": "/DATA/AppData/Stable-Diffusion-WebUI/models", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/data/outputs", + "compose_source_example": "/DATA/AppData/Stable-Diffusion-WebUI/outputs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/data/config", + "compose_source_example": "/DATA/AppData/Stable-Diffusion-WebUI/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 7860, + "published_example": 7860, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: icewhale-stable-diffusion-webui\nservices:\n icewhale-stable-diffusion-webui:\n image: johnguan/stable-diffusion-webui:latest\n runtime: nvidia\n ipc: host\n environment:\n - NVIDIA_VISIBLE_DEVICES=all\n - CPU_FALLBACK=true\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 7860\n published: '7860'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/Stable-Diffusion-WebUI/models\n target: /data/models\n - type: bind\n source: /DATA/AppData/Stable-Diffusion-WebUI/outputs\n target: /data/outputs\n - type: bind\n source: /DATA/AppData/Stable-Diffusion-WebUI/config\n target: /data/config\n privileged: false\n container_name: icewhale-stable-diffusion-webui\n" + }, + "compose_stack": { + "project_name": "icewhale-stable-diffusion-webui", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "icewhale-stable-diffusion-webui", + "service_count": 1, + "services": [ + { + "name": "icewhale-stable-diffusion-webui", + "image": "johnguan/stable-diffusion-webui:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "johnguan/stable-diffusion-webui:latest", + "runtime": "nvidia", + "ipc": "host", + "environment": [ + "NVIDIA_VISIBLE_DEVICES=all", + "CPU_FALLBACK=true" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 7860, + "published": "7860", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/Stable-Diffusion-WebUI/models", + "target": "/data/models" + }, + { + "type": "bind", + "source": "/DATA/AppData/Stable-Diffusion-WebUI/outputs", + "target": "/data/outputs" + }, + { + "type": "bind", + "source": "/DATA/AppData/Stable-Diffusion-WebUI/config", + "target": "/data/config" + } + ], + "privileged": false, + "container_name": "icewhale-stable-diffusion-webui" + } + } + ], + "top_level": { + "name": "icewhale-stable-diffusion-webui" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "icewhale-stable-diffusion-webui-volume-0", + "service": "icewhale-stable-diffusion-webui", + "container_path": "/data/models", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for icewhale-stable-diffusion-webui:/data/models" + }, + { + "id": "icewhale-stable-diffusion-webui-volume-1", + "service": "icewhale-stable-diffusion-webui", + "container_path": "/data/outputs", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for icewhale-stable-diffusion-webui:/data/outputs" + }, + { + "id": "icewhale-stable-diffusion-webui-volume-2", + "service": "icewhale-stable-diffusion-webui", + "container_path": "/data/config", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for icewhale-stable-diffusion-webui:/data/config" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "icewhale-stable-diffusion-webui" + ], + "stop_order": [ + "icewhale-stable-diffusion-webui" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7860, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "enable_prompt": "Enable the NVIDIA GPU requested by the image", + "enabled_default": true, + "required_by_compose": true, + "risk_level": "hardware-access", + "device_selection": "all-requested-by-compose", + "driver_libraries": "bind-compatible-host-driver-libraries-read-only" + } + ], + "tmpfs_mounts": [ + { + "id": "compose-ipc-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 64, + "size_prompt": "Shared memory size for the GPU workload in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "pending-per-application" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/steam.json b/oci/catalog/apps/steam.json new file mode 100644 index 00000000..e4fe07c5 --- /dev/null +++ b/oci/catalog/apps/steam.json @@ -0,0 +1,395 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-steam", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Steam" + }, + "tagline": { + "en_US": "Steam is the ultimate destination for playing, discussing, and creating games." + }, + "description": { + "en_US": "Steam is the ultimate destination for playing, discussing, and creating games." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/steam-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/steam-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://store.steampowered.com/", + "documentation": "https://docs.linuxserver.io/images/docker-steam/", + "repository": "https://github.com/linuxserver/docker-steam", + "tips": [], + "mini_changelog": [ + { + "date": "2026-02-04", + "note": "Add ProtonUp Qt for runtime management and umu-run for custom auto game launching." + }, + { + "date": "2026-01-17", + "note": "Document Nvidia support." + }, + { + "date": "2026-01-09", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-02-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-steam", + "default_branch": "master", + "revision": "179e0d2a487cfd7568b347148c4ad5e7112464cb", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-steam/179e0d2a487cfd7568b347148c4ad5e7112464cb/README.md", + "readme_pushed_at": "2026-09-12T23:34:08Z", + "compose_sha256": "1df54efd1463e0453cc90a544a6136f073eae53909fb1faeea3f7eef856b765d", + "generated_at": "2026-09-13T17:20:18+00:00" + }, + "container_contract": { + "service_name": "steam", + "container_name": "steam", + "image": { + "reference": "lscr.io/linuxserver/steam:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/steam", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n steam:\n image: lscr.io/linuxserver/steam:latest\n container_name: steam\n security_opt:\n - seccomp:unconfined\n - apparmor:unconfined #optional\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ], + "security": { + "options": { + "seccomp_profile": "unconfined" + }, + "optional_relaxations": [ + { + "id": "apparmor-unconfined", + "enable_prompt": "Apply optional security relaxation apparmor:unconfined", + "enabled_default": false, + "options": { + "apparmor_profile": "unconfined" + } + } + ] + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": true, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": true, + "risk_level": "high", + "confirmation_required": true, + "warning": "The image requests disabling part of the AppArmor or seccomp confinement. The Compose offers an optional AppArmor or seccomp relaxation; it will stay disabled unless the user selects it. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/stremio.json b/oci/catalog/apps/stremio.json new file mode 100644 index 00000000..7291043a --- /dev/null +++ b/oci/catalog/apps/stremio.json @@ -0,0 +1,480 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-stremio", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Stremio" + }, + "tagline": { + "en_US": "Stremio is a modern media center that gives you the freedom to watch everything you want." + }, + "description": { + "en_US": "Stremio offers a secure, modern and seamless entertainment experience. With its easy-to-use interface and diverse content library, including 4K HDR support, users can enjoy their favorite movies and TV shows across all their devices. And with its commitment to security, Stremio is the ultimate choice for a worry-free, high-quality streaming experience." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Andreas Tsarida / Stremio", + "developer": "Andreas Tsarida / Stremio", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://www.stremio.com", + "documentation": null, + "repository": "https://hub.docker.com/r/tsaridas/stremio-docker", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "tsaridas", + "repository": "https://hub.docker.com/r/tsaridas/stremio-docker", + "revision": "690dd7312cee4d8974f44c7e64b4f49281f1144eead8c5df5ada9436a2479fdd", + "image_repository_url": "https://hub.docker.com/r/tsaridas/stremio-docker", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "690dd7312cee4d8974f44c7e64b4f49281f1144eead8c5df5ada9436a2479fdd", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "stremio", + "container_name": "stremio", + "image": { + "reference": "tsaridas/stremio-docker:latest", + "registry": "docker.io", + "repository": "tsaridas/stremio-docker", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "NO_CORS", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "AUTO_SERVER_URL", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/root/.stremio-server", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 11470, + "published_example": 11470, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8080, + "published_example": 8100, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: stremio\nservices:\n stremio:\n container_name: stremio\n deploy:\n resources:\n limits:\n memory: 1024M\n environment:\n - NO_CORS=1\n - AUTO_SERVER_URL=1\n devices:\n - /dev/dri:/dev/dri\n image: tsaridas/stremio-docker:latest\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /root/.stremio-server\n ports:\n - target: 11470\n published: '11470'\n protocol: tcp\n - target: 8080\n published: '8100'\n protocol: tcp\n restart: unless-stopped\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "stremio", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "stremio", + "service_count": 1, + "services": [ + { + "name": "stremio", + "image": "tsaridas/stremio-docker:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "stremio", + "deploy": { + "resources": { + "limits": { + "memory": "1024M" + } + } + }, + "environment": [ + "NO_CORS=1", + "AUTO_SERVER_URL=1" + ], + "devices": [ + "/dev/dri:/dev/dri" + ], + "image": "tsaridas/stremio-docker:latest", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/root/.stremio-server" + } + ], + "ports": [ + { + "target": 11470, + "published": "11470", + "protocol": "tcp" + }, + { + "target": 8080, + "published": "8100", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "stremio" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "stremio-volume-0", + "service": "stremio", + "container_path": "/root/.stremio-server", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "stremio" + ], + "stop_order": [ + "stremio" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Stremio", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ] + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "catalog": { + "replaces_discovered_ids": [ + "stremio" + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/suite-arr.json b/oci/catalog/apps/suite-arr.json new file mode 100644 index 00000000..c8c07c54 --- /dev/null +++ b/oci/catalog/apps/suite-arr.json @@ -0,0 +1,335 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "image-suite-arr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Suite Arr" + }, + "tagline": { + "en_US": "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all)." + }, + "description": { + "en_US": "Selectable Arr media suite with shared content and a choice of Jellyfin, Plex or Emby." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/prowlarr-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/prowlarr-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9696, + "path": "/" + }, + "website": "https://github.com/Prowlarr/Prowlarr", + "documentation": "https://docs.linuxserver.io/images/docker-prowlarr/", + "repository": "https://github.com/linuxserver/docker-prowlarr", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-04", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-15", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase Alpine 3.22." + }, + { + "date": "2024-12-23", + "note": "Rebase Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-prowlarr", + "default_branch": "main", + "revision": "c03ac6b60306a6fadb7f5e491ddf3a6a665113df", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-prowlarr/c03ac6b60306a6fadb7f5e491ddf3a6a665113df/README.md", + "readme_pushed_at": "2026-09-09T08:40:12Z", + "compose_sha256": "9fd00779e731abb238dbcf64fdb61209138468b0d70457c1fb0e842546eb994d", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "prowlarr", + "container_name": "prowlarr", + "image": { + "reference": "lscr.io/linuxserver/prowlarr:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/prowlarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/prowlarr/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 9696, + "published_example": 9696, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n prowlarr:\n image: lscr.io/linuxserver/prowlarr:latest\n container_name: prowlarr\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/prowlarr/data:/config\n ports:\n - 9696:9696\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "stack_driver": "arr-suite", + "applications": [ + "prowlarr", + "sonarr", + "radarr", + "qbittorrent", + "lidarr", + "bazarr", + "sabnzbd", + "seerr", + "unpackerr" + ], + "automatic_configuration": [ + "media-root-folders", + "prowlarr-application-connections", + "optional-qbittorrent-persistent-login", + "qbittorrent-download-paths-and-categories", + "sonarr-radarr-download-client-connections" + ], + "manual_configuration": [ + "arr-authentication-and-indexers", + "quality-profiles", + "media-server-account-and-library-selection", + "seerr-initial-account-and-connections", + "bazarr-providers-and-arr-connections", + "sabnzbd-usenet-provider-and-arr-client-connection" + ], + "references": [ + "https://wiki.servarr.com/docker-guide", + "https://docs.linuxserver.io/images/docker-prowlarr/", + "https://docs.linuxserver.io/images/docker-sonarr/", + "https://docs.linuxserver.io/images/docker-radarr/", + "https://docs.linuxserver.io/images/docker-qbittorrent/", + "https://github.com/qbittorrent/qBittorrent/wiki/WebUI-API-(qBittorrent-5.0)" + ], + "qbittorrent": { + "optional": true, + "username": "admin", + "password": "asked-at-installation", + "persistent_config": "/config/qBittorrent/qBittorrent.conf", + "shared_data": "/data", + "categories": { + "sonarr": "tv", + "radarr": "movies" + }, + "vpn": false, + "starts_downloads": false, + "runtime_validation": "pending", + "authentication": { + "legacy": "HTTP 200, Ok., SID cookie", + "5.2": "HTTP 204, empty body, QBT_SID_ cookie", + "verification": "Authenticated GET app/preferences before changing settings" + }, + "path_verification": "Compare absolute paths ignoring trailing slash; require temp_path_enabled=true." + }, + "default_applications": [ + "prowlarr", + "sonarr", + "radarr", + "qbittorrent" + ], + "media_players": { + "choices": [ + "jellyfin", + "plex", + "emby", + "none" + ], + "default": "jellyfin", + "selection": "single" + }, + "shared_content": { + "host_directory": "ask-at-installation", + "create_if_missing": true, + "container_path": "/data", + "directories": [ + "downloads/tv", + "downloads/movies", + "downloads/music", + "downloads/incomplete", + "downloads/usenet", + "downloads/usenet-incomplete", + "media/movies", + "media/series", + "media/music" + ], + "backup": false, + "private_configuration": "managed-volume-with-backup" + }, + "vpn": { + "status": "deferred", + "enabled": false + }, + "lifecycle": { + "mode": "independent", + "primary_service": null, + "hookscript": false, + "onboot": "user-choice-applied-to-each-lxc", + "initial_start": "installer-only-for-first-configuration" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/sure.json b/oci/catalog/apps/sure.json new file mode 100644 index 00000000..bca5ae78 --- /dev/null +++ b/oci/catalog/apps/sure.json @@ -0,0 +1,785 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-sure", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "Sure" + }, + "tagline": { + "en_US": "Personal finance management application" + }, + "description": { + "en_US": "Sure is a personal finance management application designed to help you track your expenses, income, and investments in one place. With an intuitive interface and powerful features, Sure makes it easy to understand your financial situation and make informed decisions about your money.\n\n**Key Features:**\n- **Expense Tracking**: Easily log and categorize your expenses\n- **Income Management**: Track multiple income sources\n- **Investment Monitoring**: Keep an eye on your investments and their performance\n- **Budget Planning**: Create and maintain budgets to control your spending\n- **Financial Reports**: Generate detailed reports to understand your financial habits\n- **AI-Powered Insights**: Get personalized financial advice using AI technology\n\n**Use Cases:**\n- Personal budget management\n- Expense tracking and categorization\n- Investment portfolio monitoring\n- Financial goal setting and tracking\n- Cash flow analysis\n\n**Learn More:**\n- [Sure GitHub Repository](https://github.com/we-promise/sure)\n" + }, + "category": "finance", + "category_label": "Finance & Budgeting", + "author": "we-promise", + "developer": "we-promise", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://sure.am", + "documentation": null, + "repository": "https://ghcr.io/we-promise/sure", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "we-promise", + "repository": "https://ghcr.io/we-promise/sure", + "revision": "718bd241b4efcd93081328852f7a803b562a24fcac223882076cfc4198da3161", + "image_repository_url": "https://ghcr.io/we-promise/sure", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "718bd241b4efcd93081328852f7a803b562a24fcac223882076cfc4198da3161", + "generated_at": "2026-09-13T15:48:36+00:00" + }, + "container_contract": { + "service_name": "sure-web", + "container_name": "sure-web", + "image": { + "reference": "ghcr.io/we-promise/sure:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/we-promise/sure", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "POSTGRES_USER", + "example": "sure_user", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_PASSWORD", + "example": "${GENERATED_POSTGRES_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "POSTGRES_DB", + "example": "sure_production", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SECRET_KEY_BASE", + "example": "${GENERATED_SECRET_KEY_BASE}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "SELF_HOSTED", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "RAILS_FORCE_SSL", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "RAILS_ASSUME_SSL", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_HOST", + "example": "sure-db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_PORT", + "example": "5432", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REDIS_URL", + "example": "redis://sure-redis:6379/1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "OPENAI_ACCESS_TOKEN", + "example": "${GENERATED_OPENAI_ACCESS_TOKEN}", + "required": true, + "sensitive": true, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/rails/storage", + "compose_source_example": "/DATA/AppData/$AppID/app/storage", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 23000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "sure-worker", + "image": "ghcr.io/we-promise/sure:latest" + }, + { + "name": "sure-db", + "image": "postgres:latest" + }, + { + "name": "sure-redis", + "image": "redis:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: sure\nservices:\n sure-web:\n container_name: sure-web\n image: ghcr.io/we-promise/sure:latest\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/app/storage\n target: /rails/storage\n ports:\n - target: 3000\n published: '23000'\n protocol: tcp\n restart: unless-stopped\n environment:\n POSTGRES_USER: sure_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: sure_production\n SECRET_KEY_BASE: ${GENERATED_SECRET_KEY_BASE}\n SELF_HOSTED: 'true'\n RAILS_FORCE_SSL: 'false'\n RAILS_ASSUME_SSL: 'false'\n DB_HOST: sure-db\n DB_PORT: 5432\n REDIS_URL: redis://sure-redis:6379/1\n OPENAI_ACCESS_TOKEN: ${GENERATED_OPENAI_ACCESS_TOKEN}\n depends_on:\n sure-db:\n condition: service_healthy\n sure-redis:\n condition: service_healthy\n networks:\n - sure_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n sure-worker:\n container_name: sure-worker\n image: ghcr.io/we-promise/sure:latest\n command:\n - bundle\n - exec\n - sidekiq\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/app/storage\n target: /rails/storage\n depends_on:\n sure-redis:\n condition: service_healthy\n environment:\n POSTGRES_USER: sure_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: sure_production\n SECRET_KEY_BASE: ${GENERATED_SECRET_KEY_BASE}\n SELF_HOSTED: 'true'\n RAILS_FORCE_SSL: 'false'\n RAILS_ASSUME_SSL: 'false'\n DB_HOST: sure-db\n DB_PORT: 5432\n REDIS_URL: redis://sure-redis:6379/1\n OPENAI_ACCESS_TOKEN: ${GENERATED_OPENAI_ACCESS_TOKEN}\n networks:\n - sure_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n sure-db:\n container_name: sure-db\n image: postgres:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/pgdata\n target: /var/lib/postgresql/data\n environment:\n POSTGRES_USER: sure_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: sure_production\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U sure_user -d sure_production\n interval: 5s\n timeout: 5s\n retries: 5\n networks:\n - sure_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n sure-redis:\n container_name: sure-redis\n image: redis:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/redis/data\n target: /data\n healthcheck:\n test:\n - CMD\n - redis-cli\n - ping\n interval: 5s\n timeout: 5s\n retries: 5\n networks:\n - sure_net\n deploy:\n resources:\n reservations:\n memory: 1024M\nnetworks:\n sure_net:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "sure", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "sure-web", + "service_count": 4, + "services": [ + { + "name": "sure-db", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "sure-db", + "image": "postgres:latest", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/pgdata", + "target": "/var/lib/postgresql/data" + } + ], + "environment": { + "POSTGRES_USER": "sure_user", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "sure_production" + }, + "healthcheck": { + "test": [ + "CMD-SHELL", + "pg_isready -U sure_user -d sure_production" + ], + "interval": "5s", + "timeout": "5s", + "retries": 5 + }, + "networks": [ + "sure_net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + }, + { + "name": "sure-redis", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "sure-redis", + "image": "redis:latest", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/redis/data", + "target": "/data" + } + ], + "healthcheck": { + "test": [ + "CMD", + "redis-cli", + "ping" + ], + "interval": "5s", + "timeout": "5s", + "retries": 5 + }, + "networks": [ + "sure_net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + }, + { + "name": "sure-worker", + "image": "ghcr.io/we-promise/sure:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [ + "sure-redis" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "sure-worker", + "image": "ghcr.io/we-promise/sure:latest", + "command": [ + "bundle", + "exec", + "sidekiq" + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/app/storage", + "target": "/rails/storage" + } + ], + "depends_on": { + "sure-redis": { + "condition": "service_healthy" + } + }, + "environment": { + "POSTGRES_USER": "sure_user", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "sure_production", + "SECRET_KEY_BASE": "${GENERATED_SECRET_KEY_BASE}", + "SELF_HOSTED": "true", + "RAILS_FORCE_SSL": "false", + "RAILS_ASSUME_SSL": "false", + "DB_HOST": "sure-db", + "DB_PORT": 5432, + "REDIS_URL": "redis://sure-redis:6379/1", + "OPENAI_ACCESS_TOKEN": "${GENERATED_OPENAI_ACCESS_TOKEN}" + }, + "networks": [ + "sure_net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + }, + { + "name": "sure-web", + "image": "ghcr.io/we-promise/sure:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "sure-db", + "sure-redis" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "sure-web", + "image": "ghcr.io/we-promise/sure:latest", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/app/storage", + "target": "/rails/storage" + } + ], + "ports": [ + { + "target": 3000, + "published": "23000", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "environment": { + "POSTGRES_USER": "sure_user", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "sure_production", + "SECRET_KEY_BASE": "${GENERATED_SECRET_KEY_BASE}", + "SELF_HOSTED": "true", + "RAILS_FORCE_SSL": "false", + "RAILS_ASSUME_SSL": "false", + "DB_HOST": "sure-db", + "DB_PORT": 5432, + "REDIS_URL": "redis://sure-redis:6379/1", + "OPENAI_ACCESS_TOKEN": "${GENERATED_OPENAI_ACCESS_TOKEN}" + }, + "depends_on": { + "sure-db": { + "condition": "service_healthy" + }, + "sure-redis": { + "condition": "service_healthy" + } + }, + "networks": [ + "sure_net" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "1024M" + } + } + } + } + } + ], + "top_level": { + "name": "sure", + "networks": { + "sure_net": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "sure-web-volume-0", + "service": "sure-web", + "container_path": "/rails/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "sure-worker-volume-0", + "service": "sure-worker", + "container_path": "/rails/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "sure-db-volume-0", + "service": "sure-db", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "sure-redis-volume-0", + "service": "sure-redis", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for sure-redis:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 4, + "start_order": [ + "sure-db", + "sure-redis", + "sure-worker", + "sure-web" + ], + "stop_order": [ + "sure-web", + "sure-worker", + "sure-redis", + "sure-db" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "openai-access-token", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "sure-web", + "environment_variable": "OPENAI_ACCESS_TOKEN" + }, + { + "service": "sure-worker", + "environment_variable": "OPENAI_ACCESS_TOKEN" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "sure-web", + "environment_variable": "POSTGRES_PASSWORD" + }, + { + "service": "sure-worker", + "environment_variable": "POSTGRES_PASSWORD" + }, + { + "service": "sure-db", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + }, + { + "id": "secret-key-base", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "sure-web", + "environment_variable": "SECRET_KEY_BASE" + }, + { + "service": "sure-worker", + "environment_variable": "SECRET_KEY_BASE" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "sure-worker: perfil de salud y persistencia pendiente", + "volumen compartido entre servicios pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:sure-worker:compose-key:depends_on", + "service:sure-db:healthcheck-format", + "service:sure-redis:healthcheck-format", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/swag.json b/oci/catalog/apps/swag.json new file mode 100644 index 00000000..a8e5a21c --- /dev/null +++ b/oci/catalog/apps/swag.json @@ -0,0 +1,471 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-swag", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Swag" + }, + "tagline": { + "en_US": "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention." + }, + "description": { + "en_US": "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/swag-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/swag-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 443, + "path": "/" + }, + "website": null, + "documentation": "https://docs.linuxserver.io/images/docker-swag/", + "repository": "https://github.com/linuxserver/docker-swag", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-19", + "note": "Rebase to Alpine 3.24 with PHP 8.5." + }, + { + "date": "2026-07-10", + "note": "Add support for Let's Encrypt cert profiles. Run certbot twice daily with a random delay." + }, + { + "date": "2026-06-19", + "note": "Add support for mijn.host dns validation." + }, + { + "date": "2026-06-01", + "note": "Remove obsolete old cert check logic." + }, + { + "date": "2026-01-23", + "note": "Reorder init to fix proxy conf version checks." + } + ], + "display_version": null, + "updated_at": "2026-07-19" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-swag", + "default_branch": "master", + "revision": "6559a9b1b69686741bfab99d97df6356ba3e69e4", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-swag/6559a9b1b69686741bfab99d97df6356ba3e69e4/README.md", + "readme_pushed_at": "2026-09-12T08:06:16Z", + "compose_sha256": "7fa096ed0d74d7db88d09f7f9adfb0116e32ce0d3706bc5a57f41df8ae2a8e4a", + "generated_at": "2026-09-13T15:47:53+00:00" + }, + "container_contract": { + "service_name": "swag", + "container_name": "swag", + "image": { + "reference": "lscr.io/linuxserver/swag:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/swag", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "URL", + "example": "example.com", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "VALIDATION", + "example": "http", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SUBDOMAINS", + "example": "www,", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CERTPROVIDER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CERT_PROFILE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DNSPLUGIN", + "example": "cloudflare", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PROPAGATION", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EMAIL", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ONLY_SUBDOMAINS", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EXTRA_DOMAINS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "STAGING", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DISABLE_F2B", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SWAG_AUTORELOAD", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SWAG_AUTORELOAD_WATCHLIST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/swag/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n swag:\n image: lscr.io/linuxserver/swag:latest\n container_name: swag\n cap_add:\n - NET_ADMIN\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - URL=example.com\n - VALIDATION=http\n - SUBDOMAINS=www, #optional\n - CERTPROVIDER= #optional\n - CERT_PROFILE= #optional\n - DNSPLUGIN=cloudflare #optional\n - PROPAGATION= #optional\n - EMAIL= #optional\n - ONLY_SUBDOMAINS=false #optional\n - EXTRA_DOMAINS= #optional\n - STAGING=false #optional\n - DISABLE_F2B= #optional\n - SWAG_AUTORELOAD= #optional\n - SWAG_AUTORELOAD_WATCHLIST= #optional\n volumes:\n - /path/to/swag/config:/config\n ports:\n - 443:443\n - 80:80 #optional\n - 443:443/udp #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 443, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "security": { + "required_capabilities": [ + "NET_ADMIN" + ] + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/swingmusic.json b/oci/catalog/apps/swingmusic.json new file mode 100644 index 00000000..2280f57a --- /dev/null +++ b/oci/catalog/apps/swingmusic.json @@ -0,0 +1,420 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-swingmusic", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Swing Music" + }, + "tagline": { + "en_US": "Swing Music is a beautifully designed, self-hosted music streaming server. Like a cooler Spotify ... but bring your own music." + }, + "description": { + "en_US": "Swing Music is a fast, beautiful, self-hosted music player designed for your local audio files, offering a sleek experience akin to Spotify but powered by your own music library. Simply run the app and access your music collection effortlessly through a web browser.\n\nSwing Music curates Daily Mixes based on your listening habits, ensures a clean and consistent library with metadata normalization, and supports album versioning (e.g., Deluxe, Remaster) alongside related artist and album recommendations. Browse your music library via folder view, manage playlists, and enjoy a seamless listening experience with silence detection and cross-fade. Additional features include listening statistics, lyrics view, Last.fm scrobbling, multi-user support, and personalized collections for grouping albums and artists.\n\nWith its stunning browser-based interface and robust functionality, Swing Music is the perfect choice for music enthusiasts seeking a beautiful and practical way to manage and enjoy their local music collection.\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "SwingMX", + "developer": "SwingMX", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 1970, + "path": "/" + }, + "website": "https://swingmx.com", + "documentation": null, + "repository": "https://ghcr.io/swingmx/swingmusic", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "swingmx", + "repository": "https://ghcr.io/swingmx/swingmusic", + "revision": "e1581b85b474ee9fa9c36d244c1e35b33e604e819502d0a4ef2edfa8431046ba", + "image_repository_url": "https://ghcr.io/swingmx/swingmusic", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "e1581b85b474ee9fa9c36d244c1e35b33e604e819502d0a4ef2edfa8431046ba", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "swingmusic", + "container_name": "swingmusic", + "image": { + "reference": "ghcr.io/swingmx/swingmusic:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/swingmx/swingmusic", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/music", + "compose_source_example": "/DATA/Media/Music", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 1970, + "published_example": 1970, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: swingmusic\nservices:\n swingmusic:\n image: ghcr.io/swingmx/swingmusic:latest\n container_name: swingmusic\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/Media/Music\n target: /music\n ports:\n - 1970:1970\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "swingmusic", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "swingmusic", + "service_count": 1, + "services": [ + { + "name": "swingmusic", + "image": "ghcr.io/swingmx/swingmusic:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/swingmx/swingmusic:latest", + "container_name": "swingmusic", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/Media/Music", + "target": "/music" + } + ], + "ports": [ + "1970:1970" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "swingmusic" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "swingmusic-volume-0", + "service": "swingmusic", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "swingmusic-volume-1", + "service": "swingmusic", + "container_path": "/music", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for swingmusic:/music" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "swingmusic" + ], + "stop_order": [ + "swingmusic" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 1970, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/synclounge.json b/oci/catalog/apps/synclounge.json new file mode 100644 index 00000000..fc98ddcd --- /dev/null +++ b/oci/catalog/apps/synclounge.json @@ -0,0 +1,210 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-synclounge", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Synclounge" + }, + "tagline": { + "en_US": "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are." + }, + "description": { + "en_US": "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/synclounge-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/synclounge-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8088, + "path": "/" + }, + "website": "https://github.com/samcm/synclounge", + "documentation": "https://docs.linuxserver.io/images/docker-synclounge/", + "repository": "https://github.com/linuxserver/docker-synclounge", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-15", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2024-12-19", + "note": "Add support for read-only and non-root operation." + }, + { + "date": "2024-12-05", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-04", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-08-26", + "note": "Rebase to Alpine 3.19. Remove deprecated `AUTOJOIN_ENABLED` & `AUTOJOIN_ROOM` options." + } + ], + "display_version": null, + "updated_at": "2026-07-15" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-synclounge", + "default_branch": "master", + "revision": "83691043b6a2c7207ebb96072a956c64215f3cbf", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-synclounge/83691043b6a2c7207ebb96072a956c64215f3cbf/README.md", + "readme_pushed_at": "2026-09-08T17:58:13Z", + "compose_sha256": "fa1ef4dc2b3beacb633dcf8b40b4ee87f7ba575c405bf026aaaa1309f9b55308", + "generated_at": "2026-09-12T14:37:37+00:00" + }, + "container_contract": { + "service_name": "synclounge", + "container_name": "synclounge", + "image": { + "reference": "lscr.io/linuxserver/synclounge:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/synclounge", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "AUTH_LIST", + "example": "plexuser1,plexuser2,email1,machineid1", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 8088, + "published_example": 8088, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n synclounge:\n image: lscr.io/linuxserver/synclounge:latest\n container_name: synclounge\n environment:\n - AUTH_LIST=plexuser1,plexuser2,email1,machineid1 #optional\n ports:\n - 8088:8088\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8088, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/syncthing.json b/oci/catalog/apps/syncthing.json new file mode 100644 index 00000000..bea1c700 --- /dev/null +++ b/oci/catalog/apps/syncthing.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-syncthing", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Syncthing" + }, + "tagline": { + "en_US": "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet." + }, + "description": { + "en_US": "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/syncthing-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/syncthing-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8384, + "path": "/" + }, + "website": "https://syncthing.net", + "documentation": "https://docs.linuxserver.io/images/docker-syncthing/", + "repository": "https://github.com/linuxserver/docker-syncthing", + "tips": [], + "mini_changelog": [ + { + "date": "2026-09-10", + "note": "Rebase to Alpine 3.24. Compile on Alpine edge." + }, + { + "date": "2026-03-03", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-08-16", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-08-13", + "note": "Use double-dash long options for syncthing v2.0.0." + }, + { + "date": "2024-12-03", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-09-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-syncthing", + "default_branch": "master", + "revision": "8bbbeb64ac19f13daa8159a67cbb832df856fd94", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-syncthing/8bbbeb64ac19f13daa8159a67cbb832df856fd94/README.md", + "readme_pushed_at": "2026-09-10T15:29:13Z", + "compose_sha256": "5871a4f584f9e02424602b03c818da39741f9af7c92c35f5b2a6c5d3325f62b0", + "generated_at": "2026-09-13T14:54:08+00:00" + }, + "container_contract": { + "service_name": "syncthing", + "container_name": "syncthing", + "image": { + "reference": "lscr.io/linuxserver/syncthing:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/syncthing", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/syncthing/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data1", + "compose_source_example": "/path/to/data1", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/data2", + "compose_source_example": "/path/to/data2", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8384, + "published_example": 8384, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 22000, + "published_example": 22000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 22000, + "published_example": 22000, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 21027, + "published_example": 21027, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n syncthing:\n image: lscr.io/linuxserver/syncthing:latest\n container_name: syncthing\n hostname: syncthing #optional\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/syncthing/config:/config\n - /path/to/data1:/data1\n - /path/to/data2:/data2\n ports:\n - 8384:8384\n - 22000:22000/tcp\n - 22000:22000/udp\n - 21027:21027/udp\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8384, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "hostname": "syncthing" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/syslog-ng.json b/oci/catalog/apps/syslog-ng.json new file mode 100644 index 00000000..09979344 --- /dev/null +++ b/oci/catalog/apps/syslog-ng.json @@ -0,0 +1,279 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-syslog-ng", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Syslog Ng" + }, + "tagline": { + "en_US": "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools." + }, + "description": { + "en_US": "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/syslog-ng-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/syslog-ng-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6601, + "path": "/" + }, + "website": "https://www.syslog-ng.com/products/open-source-log-management/", + "documentation": "https://docs.linuxserver.io/images/docker-syslog-ng/", + "repository": "https://github.com/linuxserver/docker-syslog-ng", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-12-26", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-20", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-09-24", + "note": "Add opt to log to stdout." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-syslog-ng", + "default_branch": "main", + "revision": "722b52d3d432be0d78e33a25856496308140907f", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-syslog-ng/722b52d3d432be0d78e33a25856496308140907f/README.md", + "readme_pushed_at": "2026-09-10T21:27:28Z", + "compose_sha256": "9bdc114b3fac579e4a3676d0ac183777f760dda15fc5d95ec80aa2e9181e9cc1", + "generated_at": "2026-09-12T14:37:37+00:00" + }, + "container_contract": { + "service_name": "syslog-ng", + "container_name": "syslog-ng", + "image": { + "reference": "lscr.io/linuxserver/syslog-ng:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/syslog-ng", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOG_TO_STDOUT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/syslog-ng/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/var/log", + "compose_source_example": "/path/to/log", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5514, + "published_example": 514, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 6601, + "published_example": 601, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 6514, + "published_example": 6514, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n syslog-ng:\n image: lscr.io/linuxserver/syslog-ng:latest\n container_name: syslog-ng\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - LOG_TO_STDOUT= #optional\n volumes:\n - /path/to/syslog-ng/config:/config\n - /path/to/log:/var/log #optional\n ports:\n - 514:5514/udp\n - 601:6601/tcp\n - 6514:6514/tcp\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6601, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/tailscale.json b/oci/catalog/apps/tailscale.json new file mode 100644 index 00000000..bd687756 --- /dev/null +++ b/oci/catalog/apps/tailscale.json @@ -0,0 +1,466 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-tailscale", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Tailscale" + }, + "tagline": { + "en_US": "Connect your devices and users together in your own secure virtual private network." + }, + "description": { + "en_US": "A modern self-hosted networking app built on WireGuard\u00ae, providing secure, encrypted connections between devices regardless of their location. Its zero-configuration networking eliminates the need for complex firewall rules, port forwarding, or network administration, making it ideal for businesses and individuals creating efficient, secure network environments.\n\nThe app's core features include seamless device connectivity and robust security. It uses WireGuard\u00ae for end-to-end encryption, ensuring traffic cannot be intercepted, with private keys stored solely on user devices. Automatic NAT traversal enables connections across computers, phones, servers, and IoT devices over different network types, forming a unified private network. It also offers identity-based access control, integrating with Google, Microsoft, GitHub, or custom SSO solutions for simple authentication, replacing traditional IP-based restrictions to enhance security.\n\nIt excels in delivering secure remote access to services and infrastructure. Users can effortlessly access home servers, connect to office networks while traveling, or establish secure links between cloud services. Subnet routing allows access to entire networks, exit nodes enable secure internet browsing, and MagicDNS simplifies device discovery. These features ensure efficient, secure access to resources from any location.\n\nIt supports nearly all platforms, including Linux, Windows, macOS, iOS, Android, and various router firmwares, with flexible deployment in cloud or on-premises environments. A user-friendly Web interface provides real-time monitoring of network topology, device status, and access controls, with community documentation aiding configuration optimization. Whether setting up secure access for small teams or managing enterprise-scale networks, the app\u2019s intuitive operation and high flexibility deliver a modern networking solution.\n\n**Key Features:**\n- End-to-end encryption via WireGuard\u00ae, ensuring uninterceptible traffic\n- Zero-configuration networking, eliminating complex firewall or port forwarding setup\n- Automatic NAT traversal for seamless device connectivity across network types\n- Identity-based access control with SSO integration (Google, Microsoft, GitHub)\n- Subnet routing for secure network-wide access\n- Exit nodes for safe internet browsing\n- MagicDNS for simplified device discovery\n\n**Learn More:**\n- [Tailscale Official Website](https://tailscale.com)\n- [Tailscale GitHub Repository](https://github.com/tailscale/tailscale)\n" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "Tailscale Inc.", + "developer": "Tailscale Inc.", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5252, + "path": "/" + }, + "website": "https://tailscale.com", + "documentation": null, + "repository": "https://hub.docker.com/r/tailscale/tailscale", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/tailscale/tailscale", + "revision": "3cce807ad13baf35d515a7822a05bc7d77248484497311a2eb1d2e64ac4e3c22", + "image_repository_url": "https://hub.docker.com/r/tailscale/tailscale", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "3cce807ad13baf35d515a7822a05bc7d77248484497311a2eb1d2e64ac4e3c22", + "generated_at": "2026-09-13T15:47:53+00:00" + }, + "container_contract": { + "service_name": "tailscale", + "container_name": "tailscale", + "image": { + "reference": "tailscale/tailscale:latest", + "registry": "docker.io", + "repository": "tailscale/tailscale", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TS_STATE_DIR", + "example": "/var/lib/tailscale", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/lib/tailscale", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/dev/net/tun", + "compose_source_example": "/dev/net/tun", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: tailscale\nservices:\n tailscale:\n image: tailscale/tailscale:latest\n container_name: tailscale\n deploy:\n resources:\n reservations:\n memory: 128M\n network_mode: host\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /var/lib/tailscale\n - type: bind\n source: /dev/net/tun\n target: /dev/net/tun\n environment:\n TS_STATE_DIR: /var/lib/tailscale\n cap_add:\n - NET_ADMIN\n - NET_RAW\n entrypoint: /bin/sh -c \"tailscaled --state=/var/lib/tailscale/tailscaled.state\n & sleep 10; tailscale web --listen 0.0.0.0:5252\"\n" + }, + "compose_stack": { + "project_name": "tailscale", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "tailscale", + "service_count": 1, + "services": [ + { + "name": "tailscale", + "image": "tailscale/tailscale:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "tailscale/tailscale:latest", + "container_name": "tailscale", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "network_mode": "host", + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/var/lib/tailscale" + }, + { + "type": "bind", + "source": "/dev/net/tun", + "target": "/dev/net/tun" + } + ], + "environment": { + "TS_STATE_DIR": "/var/lib/tailscale" + }, + "cap_add": [ + "NET_ADMIN", + "NET_RAW" + ], + "entrypoint": "/bin/sh -c \"tailscaled --state=/var/lib/tailscale/tailscaled.state & sleep 10; tailscale web --listen 0.0.0.0:5252\"" + } + } + ], + "top_level": { + "name": "tailscale" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "tailscale-volume-0", + "service": "tailscale", + "container_path": "/var/lib/tailscale", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "tailscale-volume-1", + "service": "tailscale", + "container_path": "/dev/net/tun", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "tailscale" + ], + "stop_order": [ + "tailscale" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5252, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "compose_entrypoint": "/bin/sh -c \"tailscaled --state=/var/lib/tailscale/tailscaled.state & sleep 10; tailscale web --listen 0.0.0.0:5252\"" + }, + "network": { + "compose_mode": "host" + }, + "security": { + "required_capabilities": [ + "NET_ADMIN", + "NET_RAW" + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/tandoor.json b/oci/catalog/apps/tandoor.json new file mode 100644 index 00000000..4bc70d5c --- /dev/null +++ b/oci/catalog/apps/tandoor.json @@ -0,0 +1,544 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-tandoor", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Tandoor Recipes" + }, + "tagline": { + "en_US": "Self-hosted recipe manager and meal planner" + }, + "description": { + "en_US": "Official Tandoor Recipes deployment with its integrated web server and an isolated PostgreSQL dependency." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Tandoor Recipes", + "developer": "Tandoor Recipes", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://tandoor.dev/", + "documentation": "https://docs.tandoor.dev/install/docker/", + "repository": "https://github.com/vabene1111/recipes", + "tips": [ + "The installation creates PostgreSQL in a dependent LXC without access to the home network.", + "ALLOWED_HOSTS uses * by default to allow first access through the DHCP IP; restrict it to your domains when publishing the service.", + "The installer creates a superuser with the official Django command and shows its password only once." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-11" + }, + "source": { + "provider": "tandoor", + "repository": "https://github.com/vabene1111/recipes", + "default_branch": "develop", + "revision": "a5179f8a76fd865182df1b62ea212914027e4069", + "readme_raw_url": "https://raw.githubusercontent.com/vabene1111/recipes/develop/docs/install/docker/plain/docker-compose.yml", + "image_repository_url": "https://hub.docker.com/r/vabene1111/recipes", + "readme_pushed_at": "2026-09-11T23:39:42Z", + "compose_sha256": "4a996ad284a638050d3997793d9bc273d8591dd5d2284d2ada619c6441a3fd97", + "generated_at": "2026-09-14T15:24:39+00:00" + }, + "container_contract": { + "service_name": "web_recipes", + "container_name": "tandoor", + "image": { + "reference": "vabene1111/recipes:latest", + "registry": "docker.io", + "repository": "vabene1111/recipes", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "SECRET_KEY", + "example": "${GENERATED_SECRET_KEY}", + "required": true, + "sensitive": true, + "source": "upstream-documentation" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "ALLOWED_HOSTS", + "example": "*", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "DB_ENGINE", + "example": "django.db.backends.postgresql", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_HOST", + "example": "db_recipes", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_DB", + "example": "djangodb", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_PORT", + "example": "5432", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_USER", + "example": "djangouser", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_PASSWORD", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "upstream-documentation", + "prompt_user": false + } + ], + "volumes": [ + { + "id": "staticfiles", + "container_path": "/opt/recipes/staticfiles", + "compose_source_example": "staticfiles", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 2 + } + }, + { + "id": "mediafiles", + "container_path": "/opt/recipes/mediafiles", + "compose_source_example": "mediafiles", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 16 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "db_recipes", + "image": "postgres:16-alpine" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n db_recipes:\n restart: always\n image: postgres:16-alpine\n volumes:\n - ./postgresql:/var/lib/postgresql/data\n env_file:\n - ./.env\n\n web_recipes:\n restart: always\n image: vabene1111/recipes\n env_file:\n - ./.env\n ports:\n - 80:80\n volumes:\n - staticfiles:/opt/recipes/staticfiles\n - ./mediafiles:/opt/recipes/mediafiles\n depends_on:\n - db_recipes\n\nvolumes:\n staticfiles:\n" + }, + "compose_stack": { + "project_name": "tandoor", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "web_recipes", + "service_count": 2, + "services": [ + { + "name": "db_recipes", + "image": "postgres:16-alpine", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:16-alpine", + "restart": "unless-stopped", + "volumes": [ + "postgresql:/var/lib/postgresql/data" + ] + } + }, + { + "name": "web_recipes", + "image": "vabene1111/recipes:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "db_recipes" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "vabene1111/recipes:latest", + "restart": "unless-stopped", + "ports": [ + "80:80" + ], + "volumes": [ + "staticfiles:/opt/recipes/staticfiles", + "mediafiles:/opt/recipes/mediafiles" + ], + "env_file": [ + ".env" + ] + } + } + ], + "top_level": { + "volumes": { + "postgresql": {}, + "staticfiles": {}, + "mediafiles": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-replace-compose-service-dns", + "dependency_external_access": "disabled", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "web-staticfiles", + "service": "web_recipes", + "container_path": "/opt/recipes/staticfiles", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + }, + { + "id": "web-mediafiles", + "service": "web_recipes", + "container_path": "/opt/recipes/mediafiles", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "database-data", + "service": "db_recipes", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "db_recipes", + "web_recipes" + ], + "stop_order": [ + "web_recipes", + "db_recipes" + ], + "dependency_readiness": "healthcheck-before-application", + "rollback_on_failure": "remove-all-new-lxc-and-new-managed-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "timezone", + "allowed_hosts", + "admin_username", + "admin_email" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_addresses", + "generated_secrets", + "dependency_start_and_stop_order", + "generated_admin_password" + ], + "generated_secrets": [ + { + "id": "database-password", + "strategy": "generate-cryptographically-random-at-install" + }, + { + "id": "secret-key", + "strategy": "generate-cryptographically-random-at-install" + }, + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install" + } + ] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "tandoor" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "compose-dependency-network", + "upstream_behavior": "Docker Compose provides service-name DNS and an isolated application network.", + "native_lxc_behavior": "The installer creates or reuses an automatically allocated Proxmox bridge and injects private static addresses.", + "reason": "Each Compose service becomes one native OCI LXC.", + "behavioral_impact": "PostgreSQL is reachable only on the private bridge.", + "validation": "pending-clean-install" + }, + { + "id": "generated-compose-secrets", + "upstream_behavior": "The administrator supplies SECRET_KEY and POSTGRES_PASSWORD in the Compose .env file.", + "native_lxc_behavior": "The installer generates both values and injects them as native LXC runtime environment variables.", + "reason": "Fresh installations must not reuse published secrets.", + "behavioral_impact": "Secrets remain in the protected Proxmox LXC configuration like other Compose environment variables.", + "validation": "pending-clean-install" + } + ], + "installer_profile": {}, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "The reviewed Tandoor stack does not require a privileged LXC." + }, + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "minimum_host_memory_mb": 3072, + "recommended_host_memory_mb": 4096, + "database_storage": { + "must_be_local": true, + "network_filesystem_allowed": false + } + }, + "defaults": { + "stack_name": "tandoor", + "timezone": "Europe/Madrid", + "allowed_hosts": "*", + "rootfs_storage": "local-lvm", + "application_storage": "local-lvm", + "database_storage": "local-lvm", + "shared_media_root": "/mnt/oci-shared/tandoor/${stack_name}/mediafiles", + "static_volume_size_gb": 2, + "media_volume_size_gb": 16, + "database_volume_size_gb": 8, + "frontend_network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "firewall": true, + "host_managed": true + }, + "private_network": { + "mode": "create-if-missing", + "bridge": "vmbr10", + "subnet": "10.77.0.0/24", + "host_address": "10.77.0.1/24", + "application_address": "10.77.0.40/24", + "database_address": "10.77.0.41/24", + "nat": false + }, + "application": { + "admin_username": "admin", + "admin_email": "admin@example.local" + } + }, + "installer_contract": { + "deployment_kind": "tandoor-two-lxc-stack", + "reserve_vmids_atomically": 2, + "generated_secrets": [ + "POSTGRES_PASSWORD", + "SECRET_KEY", + "DJANGO_SUPERUSER_PASSWORD" + ], + "private_volumes": { + "staticfiles": "/opt/recipes/staticfiles", + "database": "/var/lib/postgresql/data" + }, + "media_volume": { + "container_path": "/opt/recipes/mediafiles", + "choices": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume" + }, + "start_order": [ + "db_recipes", + "web_recipes" + ], + "stop_order": [ + "web_recipes", + "db_recipes" + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "depends_on", + "env_file", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The official two-service PostgreSQL Compose has a dedicated native LXC orchestrator; clean-install validation remains pending." + }, + "first_run": { + "endpoints": [ + { + "label": "Tandoor WebUI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "official-compose" + } + ], + "credentials": [ + { + "label": "Generated Tandoor administrator", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "proxmenux-installer-generated", + "retrieval": null + } + ] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-images-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-image-digests", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "starts_stopped_dependencies": true, + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false, + "persistent_contract": "/etc/pve/priv/proxmenux-stack-.json", + "runtime_owner": "proxmox-ve" + } + } +} diff --git a/oci/catalog/apps/taskingai.json b/oci/catalog/apps/taskingai.json new file mode 100644 index 00000000..80561d72 --- /dev/null +++ b/oci/catalog/apps/taskingai.json @@ -0,0 +1,843 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-taskingai", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "TaskingAI" + }, + "tagline": { + "en_US": "The developer-friendly cloud platform for building and running LLM agents for AI-native applications." + }, + "description": { + "en_US": "The developer-friendly cloud platform for building and running LLM agents for AI-native applications." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "TaskingAI Team", + "developer": "TaskingAI Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3080, + "path": "/" + }, + "website": "https://docs.tasking.ai/", + "documentation": null, + "repository": "https://hub.docker.com/r/taskingai/taskingai-console", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/taskingai/taskingai-console", + "revision": "a40cf6e5813b67c10f46b567adb72239e37ee1e862b949d80d41d19bf95caaf9", + "image_repository_url": "https://hub.docker.com/r/taskingai/taskingai-console", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "a40cf6e5813b67c10f46b567adb72239e37ee1e862b949d80d41d19bf95caaf9", + "generated_at": "2026-09-13T15:48:36+00:00" + }, + "container_contract": { + "service_name": "frontend", + "container_name": "frontend", + "image": { + "reference": "taskingai/taskingai-console:latest", + "registry": "docker.io", + "repository": "taskingai/taskingai-console", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [], + "ports": [], + "related_services": [ + { + "name": "backend-inference", + "image": "taskingai/taskingai-inference:latest" + }, + { + "name": "backend-plugin", + "image": "taskingai/taskingai-plugin:latest" + }, + { + "name": "backend-api", + "image": "taskingai/taskingai-server:latest" + }, + { + "name": "backend-web", + "image": "taskingai/taskingai-server:latest" + }, + { + "name": "db", + "image": "ankane/pgvector:latest" + }, + { + "name": "cache", + "image": "redis:latest" + }, + { + "name": "nginx", + "image": "nginx:latest" + } + ], + "restart": null, + "stop_grace_period": null, + "original_compose": "name: taskingai\nservices:\n frontend:\n image: taskingai/taskingai-console:latest\n depends_on:\n - backend-web\n - backend-api\n networks:\n - taskingai_network\n backend-inference:\n image: taskingai/taskingai-inference:latest\n environment:\n AES_ENCRYPTION_KEY: ${GENERATED_AES_ENCRYPTION_KEY}\n ICON_URL_PREFIX: http://nginx:3080\n PROJECT_ID: taskingai\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8000/v1/health_check\n interval: 15s\n timeout: 10s\n retries: 5\n networks:\n - taskingai_network\n backend-plugin:\n image: taskingai/taskingai-plugin:latest\n environment:\n AES_ENCRYPTION_KEY: ${GENERATED_AES_ENCRYPTION_KEY}\n ICON_URL_PREFIX: http://nginx:3080\n OBJECT_STORAGE_TYPE: local\n HOST_URL: http://nginx:3080\n PATH_TO_VOLUME: /var/lib/data\n PROJECT_ID: taskingai\n volumes:\n - /DATA/AppData/$AppID/data/object_storage:/var/lib/data\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8000/v1/health_check\n interval: 15s\n timeout: 10s\n retries: 5\n networks:\n - taskingai_network\n backend-api:\n image: taskingai/taskingai-server:latest\n environment:\n POSTGRES_URL: postgres://postgres:TaskingAI321@db:5432/taskingai\n REDIS_URL: redis://:TaskingAI321@cache:6379/0\n TASKINGAI_INFERENCE_URL: http://backend-inference:8000\n TASKINGAI_PLUGIN_URL: http://backend-plugin:8000\n AES_ENCRYPTION_KEY: ${GENERATED_AES_ENCRYPTION_KEY}\n OBJECT_STORAGE_TYPE: local\n HOST_URL: http://nginx:3080\n PATH_TO_VOLUME: /var/lib/data\n PROJECT_ID: taskingai\n volumes:\n - /DATA/AppData/$AppID/data/object_storage:/var/lib/data\n depends_on:\n - db\n - cache\n - backend-inference\n - backend-plugin\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8000/v1/health_check\n interval: 15s\n timeout: 10s\n retries: 5\n networks:\n - taskingai_network\n backend-web:\n image: taskingai/taskingai-server:latest\n environment:\n POSTGRES_URL: postgres://postgres:TaskingAI321@db:5432/taskingai\n REDIS_URL: redis://:TaskingAI321@cache:6379/0\n TASKINGAI_INFERENCE_URL: http://backend-inference:8000\n TASKINGAI_PLUGIN_URL: http://backend-plugin:8000\n AES_ENCRYPTION_KEY: ${GENERATED_AES_ENCRYPTION_KEY}\n JWT_SECRET_KEY: ${GENERATED_JWT_SECRET_KEY}\n PURPOSE: WEB\n DEFAULT_ADMIN_USERNAME: admin\n DEFAULT_ADMIN_PASSWORD: ${GENERATED_DEFAULT_ADMIN_PASSWORD}\n OBJECT_STORAGE_TYPE: local\n HOST_URL: http://nginx:3080\n PATH_TO_VOLUME: /var/lib/data\n PROJECT_ID: taskingai\n volumes:\n - /DATA/AppData/$AppID/data/object_storage:/var/lib/data\n depends_on:\n - db\n - cache\n - backend-inference\n - backend-plugin\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8000/v1/health_check\n interval: 15s\n timeout: 10s\n retries: 5\n networks:\n - taskingai_network\n db:\n image: ankane/pgvector:latest\n environment:\n POSTGRES_DB: taskingai\n POSTGRES_USER: postgres\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n volumes:\n - /DATA/AppData/$AppID/data/postgres:/var/lib/postgresql/data\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U postgres\n interval: 5s\n timeout: 5s\n retries: 10\n restart: always\n networks:\n - taskingai_network\n cache:\n image: redis:latest\n command:\n - redis-server\n - --requirepass\n - TaskingAI321\n volumes:\n - /DATA/AppData/$AppID/data/redis:/data\n healthcheck:\n test:\n - CMD\n - redis-cli\n - auth\n - TaskingAI321\n - ping\n interval: 5s\n timeout: 5s\n retries: 10\n restart: always\n networks:\n - taskingai_network\n nginx:\n image: nginx:latest\n ports:\n - 3080:80\n volumes:\n - /DATA/AppData/$AppID/data/nginx_cache:/var/cache/nginx\n depends_on:\n - frontend\n - backend-web\n - backend-api\n networks:\n - taskingai_network\n configs:\n - source: nginx_config\n target: /etc/nginx/conf.d/default.conf\nnetworks:\n taskingai_network:\n driver: bridge\nconfigs:\n nginx_config:\n content: \"server {\\n listen 80;\\n\\n client_max_body_size 20M;\\n\\n location\\\n \\ /images/providers/icons/ {\\n proxy_pass http://backend-inference:8000;\\n\\\n \\ }\\n\\n location /images/plugins/bundles/icons/ {\\n proxy_pass http://backend-plugin:8000;\\n\\\n \\ }\\n\\n location /api/v1/ {\\n proxy_pass http://backend-web:8000;\\n \\\n \\ proxy_http_version 1.1;\\n proxy_set_header Connection '';\\n \\\n \\ proxy_buffering off;\\n proxy_cache off;\\n proxy_read_timeout 24h;\\n\\\n \\ }\\n\\n location /v1/ {\\n proxy_pass http://backend-api:8000;\\n \\\n \\ proxy_http_version 1.1;\\n proxy_set_header Connection '';\\n proxy_buffering\\\n \\ off;\\n proxy_cache off;\\n proxy_read_timeout 24h;\\n }\\n\\n location\\\n \\ /imgs/ {\\n proxy_pass http://backend-web:8000;\\n }\\n\\n location / {\\n\\\n \\ proxy_pass http://frontend:80;\\n }\\n}\\n\"\n" + }, + "compose_stack": { + "project_name": "taskingai", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "frontend", + "service_count": 8, + "services": [ + { + "name": "backend-inference", + "image": "taskingai/taskingai-inference:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "taskingai/taskingai-inference:latest", + "environment": { + "AES_ENCRYPTION_KEY": "${GENERATED_AES_ENCRYPTION_KEY}", + "ICON_URL_PREFIX": "http://nginx:3080", + "PROJECT_ID": "taskingai" + }, + "healthcheck": { + "test": [ + "CMD", + "curl", + "-f", + "http://localhost:8000/v1/health_check" + ], + "interval": "15s", + "timeout": "10s", + "retries": 5 + }, + "networks": [ + "taskingai_network" + ] + } + }, + { + "name": "backend-plugin", + "image": "taskingai/taskingai-plugin:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "taskingai/taskingai-plugin:latest", + "environment": { + "AES_ENCRYPTION_KEY": "${GENERATED_AES_ENCRYPTION_KEY}", + "ICON_URL_PREFIX": "http://nginx:3080", + "OBJECT_STORAGE_TYPE": "local", + "HOST_URL": "http://nginx:3080", + "PATH_TO_VOLUME": "/var/lib/data", + "PROJECT_ID": "taskingai" + }, + "volumes": [ + "/DATA/AppData/$AppID/data/object_storage:/var/lib/data" + ], + "healthcheck": { + "test": [ + "CMD", + "curl", + "-f", + "http://localhost:8000/v1/health_check" + ], + "interval": "15s", + "timeout": "10s", + "retries": 5 + }, + "networks": [ + "taskingai_network" + ] + } + }, + { + "name": "cache", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "redis:latest", + "command": [ + "redis-server", + "--requirepass", + "TaskingAI321" + ], + "volumes": [ + "/DATA/AppData/$AppID/data/redis:/data" + ], + "healthcheck": { + "test": [ + "CMD", + "redis-cli", + "auth", + "TaskingAI321", + "ping" + ], + "interval": "5s", + "timeout": "5s", + "retries": 10 + }, + "restart": "always", + "networks": [ + "taskingai_network" + ] + } + }, + { + "name": "db", + "image": "ankane/pgvector:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 4, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "ankane/pgvector:latest", + "environment": { + "POSTGRES_DB": "taskingai", + "POSTGRES_USER": "postgres", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}" + }, + "volumes": [ + "/DATA/AppData/$AppID/data/postgres:/var/lib/postgresql/data" + ], + "healthcheck": { + "test": [ + "CMD-SHELL", + "pg_isready -U postgres" + ], + "interval": "5s", + "timeout": "5s", + "retries": 10 + }, + "restart": "always", + "networks": [ + "taskingai_network" + ] + } + }, + { + "name": "backend-api", + "image": "taskingai/taskingai-server:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 5, + "depends_on": [ + "backend-inference", + "backend-plugin", + "cache", + "db" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "taskingai/taskingai-server:latest", + "environment": { + "POSTGRES_URL": "postgres://postgres:TaskingAI321@db:5432/taskingai", + "REDIS_URL": "redis://:TaskingAI321@cache:6379/0", + "TASKINGAI_INFERENCE_URL": "http://backend-inference:8000", + "TASKINGAI_PLUGIN_URL": "http://backend-plugin:8000", + "AES_ENCRYPTION_KEY": "${GENERATED_AES_ENCRYPTION_KEY}", + "OBJECT_STORAGE_TYPE": "local", + "HOST_URL": "http://nginx:3080", + "PATH_TO_VOLUME": "/var/lib/data", + "PROJECT_ID": "taskingai" + }, + "volumes": [ + "/DATA/AppData/$AppID/data/object_storage:/var/lib/data" + ], + "depends_on": [ + "db", + "cache", + "backend-inference", + "backend-plugin" + ], + "healthcheck": { + "test": [ + "CMD", + "curl", + "-f", + "http://localhost:8000/v1/health_check" + ], + "interval": "15s", + "timeout": "10s", + "retries": 5 + }, + "networks": [ + "taskingai_network" + ] + } + }, + { + "name": "backend-web", + "image": "taskingai/taskingai-server:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 6, + "depends_on": [ + "backend-inference", + "backend-plugin", + "cache", + "db" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "taskingai/taskingai-server:latest", + "environment": { + "POSTGRES_URL": "postgres://postgres:TaskingAI321@db:5432/taskingai", + "REDIS_URL": "redis://:TaskingAI321@cache:6379/0", + "TASKINGAI_INFERENCE_URL": "http://backend-inference:8000", + "TASKINGAI_PLUGIN_URL": "http://backend-plugin:8000", + "AES_ENCRYPTION_KEY": "${GENERATED_AES_ENCRYPTION_KEY}", + "JWT_SECRET_KEY": "${GENERATED_JWT_SECRET_KEY}", + "PURPOSE": "WEB", + "DEFAULT_ADMIN_USERNAME": "admin", + "DEFAULT_ADMIN_PASSWORD": "${GENERATED_DEFAULT_ADMIN_PASSWORD}", + "OBJECT_STORAGE_TYPE": "local", + "HOST_URL": "http://nginx:3080", + "PATH_TO_VOLUME": "/var/lib/data", + "PROJECT_ID": "taskingai" + }, + "volumes": [ + "/DATA/AppData/$AppID/data/object_storage:/var/lib/data" + ], + "depends_on": [ + "db", + "cache", + "backend-inference", + "backend-plugin" + ], + "healthcheck": { + "test": [ + "CMD", + "curl", + "-f", + "http://localhost:8000/v1/health_check" + ], + "interval": "15s", + "timeout": "10s", + "retries": 5 + }, + "networks": [ + "taskingai_network" + ] + } + }, + { + "name": "frontend", + "image": "taskingai/taskingai-console:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "backend-api", + "backend-web" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "taskingai/taskingai-console:latest", + "depends_on": [ + "backend-web", + "backend-api" + ], + "networks": [ + "taskingai_network" + ] + } + }, + { + "name": "nginx", + "image": "nginx:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 7, + "depends_on": [ + "backend-api", + "backend-web", + "frontend" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "nginx:latest", + "ports": [ + "3080:80" + ], + "volumes": [ + "/DATA/AppData/$AppID/data/nginx_cache:/var/cache/nginx" + ], + "depends_on": [ + "frontend", + "backend-web", + "backend-api" + ], + "networks": [ + "taskingai_network" + ], + "configs": [ + { + "source": "nginx_config", + "target": "/etc/nginx/conf.d/default.conf" + } + ] + } + } + ], + "top_level": { + "name": "taskingai", + "networks": { + "taskingai_network": { + "driver": "bridge" + } + }, + "configs": { + "nginx_config": { + "content": "server {\n listen 80;\n\n client_max_body_size 20M;\n\n location /images/providers/icons/ {\n proxy_pass http://backend-inference:8000;\n }\n\n location /images/plugins/bundles/icons/ {\n proxy_pass http://backend-plugin:8000;\n }\n\n location /api/v1/ {\n proxy_pass http://backend-web:8000;\n proxy_http_version 1.1;\n proxy_set_header Connection '';\n proxy_buffering off;\n proxy_cache off;\n proxy_read_timeout 24h;\n }\n\n location /v1/ {\n proxy_pass http://backend-api:8000;\n proxy_http_version 1.1;\n proxy_set_header Connection '';\n proxy_buffering off;\n proxy_cache off;\n proxy_read_timeout 24h;\n }\n\n location /imgs/ {\n proxy_pass http://backend-web:8000;\n }\n\n location / {\n proxy_pass http://frontend:80;\n }\n}\n" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "backend-plugin-volume-0", + "service": "backend-plugin", + "container_path": "/var/lib/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "backend-api-volume-0", + "service": "backend-api", + "container_path": "/var/lib/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "backend-web-volume-0", + "service": "backend-web", + "container_path": "/var/lib/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "db-volume-0", + "service": "db", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "cache-volume-0", + "service": "cache", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for cache:/data" + }, + { + "id": "nginx-volume-0", + "service": "nginx", + "container_path": "/var/cache/nginx", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 8, + "start_order": [ + "backend-inference", + "backend-plugin", + "cache", + "db", + "backend-api", + "backend-web", + "frontend", + "nginx" + ], + "stop_order": [ + "nginx", + "frontend", + "backend-web", + "backend-api", + "db", + "cache", + "backend-plugin", + "backend-inference" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "aes-encryption-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "backend-inference", + "environment_variable": "AES_ENCRYPTION_KEY" + }, + { + "service": "backend-plugin", + "environment_variable": "AES_ENCRYPTION_KEY" + }, + { + "service": "backend-api", + "environment_variable": "AES_ENCRYPTION_KEY" + }, + { + "service": "backend-web", + "environment_variable": "AES_ENCRYPTION_KEY" + } + ] + }, + { + "id": "default-admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "backend-web", + "environment_variable": "DEFAULT_ADMIN_PASSWORD" + } + ] + }, + { + "id": "jwt-secret-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "backend-web", + "environment_variable": "JWT_SECRET_KEY" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "db", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "servicios que dependen del principal pendientes" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:backend-api:compose-key:depends_on", + "service:backend-web:compose-key:depends_on", + "service:db:healthcheck-format", + "service:cache:healthcheck-format", + "service:nginx:compose-key:configs", + "service:nginx:compose-key:depends_on", + "top-level-configs", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/tasmoadmin.json b/oci/catalog/apps/tasmoadmin.json new file mode 100644 index 00000000..7974be0b --- /dev/null +++ b/oci/catalog/apps/tasmoadmin.json @@ -0,0 +1,423 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-tasmoadmin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "TasmoAdmin" + }, + "tagline": { + "en_US": "Web interface to manage devices running Tasmota firmware." + }, + "description": { + "en_US": "TasmoAdmin manages the devices on a network that run Tasmota firmware, from one web interface: it finds them by scanning an address range or through an MQTT broker, shows their sensor readings and configuration, sends commands and backs them up, and updates the firmware of several devices at once, downloading the release from the Tasmota OTA site." + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "TasmoAdmin", + "developer": null, + "icon": "https://raw.githubusercontent.com/TasmoAdmin/TasmoAdmin/master/assets/logo.svg", + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/TasmoAdmin/TasmoAdmin", + "documentation": "https://github.com/TasmoAdmin/TasmoAdmin/wiki", + "repository": "https://github.com/TasmoAdmin/TasmoAdmin", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "tasmoadmin", + "repository": "https://github.com/TasmoAdmin/TasmoAdmin", + "revision": "b23a54b3b9c99a558103b6216939ec66c3fcada84622980bb2eaef3e2a186168", + "image_repository_url": "https://ghcr.io/tasmoadmin/tasmoadmin", + "readme_pushed_at": "", + "compose_sha256": "b23a54b3b9c99a558103b6216939ec66c3fcada84622980bb2eaef3e2a186168", + "generated_at": "2026-09-21T11:26:57+00:00" + }, + "container_contract": { + "service_name": "tasmoadmin", + "container_name": "tasmoadmin", + "image": { + "reference": "ghcr.io/tasmoadmin/tasmoadmin:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/tasmoadmin/tasmoadmin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "tasmoadmin_data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n tasmoadmin:\n image: ghcr.io/tasmoadmin/tasmoadmin:latest\n container_name: tasmoadmin\n restart: unless-stopped\n volumes:\n - tasmoadmin_data:/data\n ports:\n - 8080:80\n" + }, + "compose_stack": { + "project_name": "tasmoadmin", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "tasmoadmin", + "service_count": 1, + "services": [ + { + "name": "tasmoadmin", + "image": "ghcr.io/tasmoadmin/tasmoadmin:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/tasmoadmin/tasmoadmin:latest", + "container_name": "tasmoadmin", + "restart": "unless-stopped", + "volumes": [ + "tasmoadmin_data:/data" + ], + "ports": [ + "8080:80" + ] + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "tasmoadmin-volume-0", + "service": "tasmoadmin", + "container_path": "/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "tasmoadmin" + ], + "stop_order": [ + "tasmoadmin" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "volume_preparations": [ + { + "container_path": "/data", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "mem_limit", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "ulimits", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/tautulli.json b/oci/catalog/apps/tautulli.json new file mode 100644 index 00000000..a2727e12 --- /dev/null +++ b/oci/catalog/apps/tautulli.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-tautulli", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Tautulli" + }, + "tagline": { + "en_US": "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server." + }, + "description": { + "en_US": "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/tautulli-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/tautulli-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8181, + "path": "/" + }, + "website": "http://tautulli.com", + "documentation": "https://docs.linuxserver.io/images/docker-tautulli/", + "repository": "https://github.com/linuxserver/docker-tautulli", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-15", + "note": "Re-Rebase to Alpine 3.23." + }, + { + "date": "2026-01-08", + "note": "Revert to Alpine 3.22 due to sqlite bug." + }, + { + "date": "2026-01-04", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase to Alpine 3.22." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-tautulli", + "default_branch": "master", + "revision": "6a8e16ca3b9ec86f903a8f2e60a3b23f82a48430", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-tautulli/6a8e16ca3b9ec86f903a8f2e60a3b23f82a48430/README.md", + "readme_pushed_at": "2026-09-11T01:25:01Z", + "compose_sha256": "d2a1a0654ca103716a486bb2916b5148128e1e1a26a9fc7f1fb251d0c1433018", + "generated_at": "2026-09-12T14:37:37+00:00" + }, + "container_contract": { + "service_name": "tautulli", + "container_name": "tautulli", + "image": { + "reference": "lscr.io/linuxserver/tautulli:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/tautulli", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/tautulli/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8181, + "published_example": 8181, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n tautulli:\n image: lscr.io/linuxserver/tautulli:latest\n container_name: tautulli\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/tautulli/config:/config\n ports:\n - 8181:8181\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8181, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/tdarr.json b/oci/catalog/apps/tdarr.json new file mode 100644 index 00000000..670674fd --- /dev/null +++ b/oci/catalog/apps/tdarr.json @@ -0,0 +1,684 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-tdarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Tdarr" + }, + "tagline": { + "en_US": "Media library transcoding and health checking, with an internal worker node." + }, + "description": { + "en_US": "Tdarr keeps a media library in the formats and codecs chosen for it: it scans the library, checks the health of every file and transcodes what does not match, with its own worker node inside the container. The web interface is on port 8265 and the node listens on 8266." + }, + "category": "media", + "category_label": "Media", + "author": "HaveAGitGat", + "developer": null, + "icon": "https://raw.githubusercontent.com/HaveAGitGat/Tdarr/master/assets/tdarr.png", + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8265, + "path": "/" + }, + "website": "https://tdarr.io", + "documentation": "https://docs.tdarr.io", + "repository": "https://github.com/HaveAGitGat/Tdarr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "haveagitgat", + "repository": "https://github.com/HaveAGitGat/Tdarr", + "revision": "25b13a5fbad493ebda195d1aa1aa893ba737a2b774690ca02dbb976733cd1146", + "image_repository_url": "https://ghcr.io/haveagitgat/tdarr", + "readme_pushed_at": "", + "compose_sha256": "25b13a5fbad493ebda195d1aa1aa893ba737a2b774690ca02dbb976733cd1146", + "generated_at": "2026-09-20T14:43:04+00:00" + }, + "container_contract": { + "service_name": "tdarr", + "container_name": "tdarr", + "image": { + "reference": "ghcr.io/haveagitgat/tdarr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/haveagitgat/tdarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "serverIP", + "example": "0.0.0.0", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "serverPort", + "example": "8266", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "webUIPort", + "example": "8265", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "internalNode", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "inContainer", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "ffmpegVersion", + "example": "7", + "required": false, + "sensitive": false, + "source": "docker-compose", + "prompt": "FFmpeg version the node uses (7 by default)" + }, + { + "name": "nodeName", + "example": "InternalNode", + "required": false, + "sensitive": false, + "source": "docker-compose", + "prompt": "Name of the internal worker node" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/configs", + "compose_source_example": "./configs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/app/logs", + "compose_source_example": "./logs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/media", + "compose_source_example": "./media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/temp", + "compose_source_example": "./temp", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8265, + "published_example": 8265, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8266, + "published_example": 8266, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": null, + "stop_grace_period": null, + "original_compose": "services:\n tdarr:\n image: ghcr.io/haveagitgat/tdarr:latest\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - serverIP=0.0.0.0\n - serverPort=8266\n - webUIPort=8265\n - internalNode=true\n - inContainer=true\n - ffmpegVersion=7\n - nodeName=InternalNode\n ports:\n - 8265:8265\n - 8266:8266\n volumes:\n - ./configs:/app/configs\n - ./logs:/app/logs\n - ./media:/media\n - ./temp:/temp\n" + }, + "compose_stack": { + "project_name": "tdarr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "tdarr", + "service_count": 1, + "services": [ + { + "name": "tdarr", + "image": "ghcr.io/haveagitgat/tdarr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/haveagitgat/tdarr:latest", + "environment": [ + "PUID=1000", + "PGID=1000", + "TZ=Etc/UTC", + "serverIP=0.0.0.0", + "serverPort=8266", + "webUIPort=8265", + "internalNode=true", + "inContainer=true", + "ffmpegVersion=7", + "nodeName=InternalNode" + ], + "ports": [ + "8265:8265", + "8266:8266" + ], + "volumes": [ + "./configs:/app/configs", + "./logs:/app/logs", + "./media:/media", + "./temp:/temp" + ] + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "tdarr-volume-0", + "service": "tdarr", + "container_path": "/app/configs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "tdarr-volume-1", + "service": "tdarr", + "container_path": "/app/logs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "tdarr-volume-2", + "service": "tdarr", + "container_path": "/media", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "tdarr-volume-3", + "service": "tdarr", + "container_path": "/temp", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "tdarr" + ], + "stop_order": [ + "tdarr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8265, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 12, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "startup_healthcheck": { + "scheme": "http", + "port": 8265, + "path": "/", + "timeout_seconds": 300, + "request_timeout_seconds": 10, + "stability_seconds": 5, + "verify_tls": false + }, + "hardware_acceleration": { + "prompt": "Hardware acceleration for Tdarr", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "image": { + "reference": "ghcr.io/haveagitgat/tdarr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/haveagitgat/tdarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API and QSV)", + "image": { + "reference": "ghcr.io/haveagitgat/tdarr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/haveagitgat/tdarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "gpu-render", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "kind": "character-device", + "container_path_strategy": "same-as-host", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "architectures": [ + "amd64" + ], + "image": { + "reference": "ghcr.io/haveagitgat/tdarr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/haveagitgat/tdarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-video", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + }, + { + "name": "NVIDIA_DRIVER_CAPABILITIES", + "value": "compute,video,utility" + } + ] + } + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "mem_limit", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "ulimits", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Official image of the project, taken from its own Compose file. The library and the transcode cache are offered as a container volume or as a host directory; the configuration and the logs stay in container volumes." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/teable.json b/oci/catalog/apps/teable.json new file mode 100644 index 00000000..8ad95bc9 --- /dev/null +++ b/oci/catalog/apps/teable.json @@ -0,0 +1,668 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-teable", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Teable" + }, + "tagline": { + "en_US": "Teable adopts a concise spreadsheet interface, yet creates powerful database applications" + }, + "description": { + "en_US": "Teable is a new generation open-source database platform. It provides an intuitive spreadsheet-like experience, while being powered by a high-performance Postgres database underneath, combining ease of use with powerful data processing capabilities.\n\n**Key Features:**\n- **High Performance**: Built on the Postgres core, it effortlessly handles millions of records with extremely fast response times.\n- **Modern Interface**: Offers multiple views including grid, kanban, gallery, and forms, with a clean and user-friendly design.\n- **Real-time Collaboration**: Supports multi-user online collaboration with real-time data synchronisation.\n- **Automation & API**: Provides powerful RESTful APIs to enable flexible integration and automation.\n\n**Learn More:**\n- [Teable Official Website](https://teable.ai)\n- [Teable GitHub Repository](https://github.com/teableio/teable)\n- [Help Documentation](https://help.teable.ai)\n" + }, + "category": "databases", + "category_label": "Databases", + "author": "teableio", + "developer": "teableio", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://teable.ai", + "documentation": null, + "repository": "https://hub.docker.com/r/teableio/teable", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/teableio/teable", + "revision": "f59c957cd4de1446da35128c8e74c0288ee4c9dd92eeb194a781b4d224c9a53b", + "image_repository_url": "https://hub.docker.com/r/teableio/teable", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "f59c957cd4de1446da35128c8e74c0288ee4c9dd92eeb194a781b4d224c9a53b", + "generated_at": "2026-09-13T15:48:36+00:00" + }, + "container_contract": { + "service_name": "teable", + "container_name": "teable", + "image": { + "reference": "teableio/teable:latest", + "registry": "docker.io", + "repository": "teableio/teable", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXT_ENV_IMAGES_ALL_REMOTE", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUBLIC_ORIGIN", + "example": "http://127.0.0.1:3000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PRISMA_DATABASE_URL", + "example": "postgresql://example:example@teable-db:5432/teable-db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BACKEND_CACHE_PROVIDER", + "example": "redis", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BACKEND_CACHE_REDIS_URI", + "example": "redis://default:password@teable-cache:6379/0", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/.assets", + "compose_source_example": "/DATA/AppData/$AppID/assets", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3200, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "teable-db", + "image": "postgres:latest" + }, + { + "name": "teable-cache", + "image": "redis:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: teable\nservices:\n teable:\n image: teableio/teable:latest\n container_name: teable\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 512M\n ports:\n - target: 3000\n published: '3200'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/assets\n target: /app/.assets\n environment:\n - TZ=$TZ\n - NEXT_ENV_IMAGES_ALL_REMOTE=true\n - PUBLIC_ORIGIN=http://127.0.0.1:3000\n - PRISMA_DATABASE_URL=postgresql://example:example@teable-db:5432/teable-db\n - BACKEND_CACHE_PROVIDER=redis\n - BACKEND_CACHE_REDIS_URI=redis://default:password@teable-cache:6379/0\n networks:\n - teable-network\n depends_on:\n teable-db:\n condition: service_healthy\n teable-cache:\n condition: service_healthy\n teable-db:\n image: postgres:latest\n restart: unless-stopped\n container_name: teable-db\n deploy:\n resources:\n reservations:\n memory: 256M\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /var/lib/postgresql/data\n environment:\n - TZ=$TZ\n - POSTGRES_DB=teable-db\n - POSTGRES_USER=example\n - POSTGRES_PASSWORD=${GENERATED_POSTGRES_PASSWORD}\n networks:\n - teable-network\n healthcheck:\n test:\n - CMD-SHELL\n - sh -c 'pg_isready -U example -d teable-db'\n interval: 10s\n timeout: 3s\n retries: 3\n teable-cache:\n image: redis:latest\n restart: unless-stopped\n container_name: teable-cache\n deploy:\n resources:\n reservations:\n memory: 256M\n expose:\n - '6379'\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/teable-cache-data\n target: /data\n networks:\n - teable-network\n command:\n - redis-server\n - --requirepass password\n healthcheck:\n test:\n - CMD\n - redis-cli\n - --raw\n - incr\n - ping\n interval: 10s\n timeout: 3s\n retries: 3\nnetworks:\n teable-network:\n name: teable-network\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "teable", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "teable", + "service_count": 3, + "services": [ + { + "name": "teable-cache", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "redis:latest", + "restart": "unless-stopped", + "container_name": "teable-cache", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "expose": [ + "6379" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/teable-cache-data", + "target": "/data" + } + ], + "networks": [ + "teable-network" + ], + "command": [ + "redis-server", + "--requirepass password" + ], + "healthcheck": { + "test": [ + "CMD", + "redis-cli", + "--raw", + "incr", + "ping" + ], + "interval": "10s", + "timeout": "3s", + "retries": 3 + } + } + }, + { + "name": "teable-db", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:latest", + "restart": "unless-stopped", + "container_name": "teable-db", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/var/lib/postgresql/data" + } + ], + "environment": [ + "TZ=$TZ", + "POSTGRES_DB=teable-db", + "POSTGRES_USER=example", + "POSTGRES_PASSWORD=${GENERATED_POSTGRES_PASSWORD}" + ], + "networks": [ + "teable-network" + ], + "healthcheck": { + "test": [ + "CMD-SHELL", + "sh -c 'pg_isready -U example -d teable-db'" + ], + "interval": "10s", + "timeout": "3s", + "retries": 3 + } + } + }, + { + "name": "teable", + "image": "teableio/teable:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "teable-cache", + "teable-db" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "teableio/teable:latest", + "container_name": "teable", + "restart": "unless-stopped", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "ports": [ + { + "target": 3000, + "published": "3200", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/assets", + "target": "/app/.assets" + } + ], + "environment": [ + "TZ=$TZ", + "NEXT_ENV_IMAGES_ALL_REMOTE=true", + "PUBLIC_ORIGIN=http://127.0.0.1:3000", + "PRISMA_DATABASE_URL=postgresql://example:example@teable-db:5432/teable-db", + "BACKEND_CACHE_PROVIDER=redis", + "BACKEND_CACHE_REDIS_URI=redis://default:password@teable-cache:6379/0" + ], + "networks": [ + "teable-network" + ], + "depends_on": { + "teable-db": { + "condition": "service_healthy" + }, + "teable-cache": { + "condition": "service_healthy" + } + } + } + } + ], + "top_level": { + "name": "teable", + "networks": { + "teable-network": { + "name": "teable-network", + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "teable-volume-0", + "service": "teable", + "container_path": "/app/.assets", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "teable-db-volume-0", + "service": "teable-db", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "teable-cache-volume-0", + "service": "teable-cache", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for teable-cache:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "teable-cache", + "teable-db", + "teable" + ], + "stop_order": [ + "teable", + "teable-db", + "teable-cache" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "teable-db", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "stack_environment_overrides": { + "teable-cache": { + "REDISCLI_AUTH": "${GENERATED_REDIS_PASSWORD}" + }, + "teable": { + "BACKEND_CACHE_REDIS_URI": "redis://default:${GENERATED_REDIS_PASSWORD}@teable-cache:6379/0" + } + }, + "stack_command_overrides": { + "teable-cache": [ + "redis-server", + "--requirepass", + "${REDISCLI_AUTH}" + ] + }, + "stack_adaptation_notes": [ + "The malformed imported '--requirepass password' argument is translated to separate Redis command arguments, preserving its upstream entrypoint.", + "Redis, its authenticated healthcheck and Teable share one generated password. The hook contains no secret; redis-cli reads REDISCLI_AUTH inside the LXC.", + "The named internal Compose bridge becomes an automatically allocated private Proxmox bridge, avoiding fixed-name collisions.", + "Redis readiness requires the exact PONG response, not only redis-cli exit status.", + "Credentials persist in native LXC runtime metadata; administrator access can read them. Latest images and first boot remain unvalidated." + ], + "stack_references": [ + "https://github.com/teableio/teable", + "https://redis.io/docs/latest/develop/tools/cli/" + ], + "installer_profile": { + "stack_driver": "generic-multi-lxc-stack" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false + } + } +} diff --git a/oci/catalog/apps/telegram.json b/oci/catalog/apps/telegram.json new file mode 100644 index 00000000..640bf0cd --- /dev/null +++ b/oci/catalog/apps/telegram.json @@ -0,0 +1,269 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-telegram", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Telegram" + }, + "tagline": { + "en_US": "Telegram is a cloud-based mobile and desktop messaging app." + }, + "description": { + "en_US": "Telegram is a cloud-based mobile and desktop messaging app." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/telegram-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/telegram-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://telegram.org/", + "documentation": "https://docs.linuxserver.io/images/docker-telegram/", + "repository": "https://github.com/linuxserver/docker-telegram", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform for chromium fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-12-02", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-04-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-telegram", + "default_branch": "master", + "revision": "15c142d5c491ec6eb9fa2d6ef168c111086ccffd", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-telegram/15c142d5c491ec6eb9fa2d6ef168c111086ccffd/README.md", + "readme_pushed_at": "2026-09-11T17:25:15Z", + "compose_sha256": "7b15f64212c891b53eef25f441c92e4cec94bbaec145ae12d2a8a8934f04d8f6", + "generated_at": "2026-09-12T14:37:37+00:00" + }, + "container_contract": { + "service_name": "telegram", + "container_name": "telegram", + "image": { + "reference": "lscr.io/linuxserver/telegram:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/telegram", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n telegram:\n image: lscr.io/linuxserver/telegram:latest\n container_name: telegram\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/thelounge.json b/oci/catalog/apps/thelounge.json new file mode 100644 index 00000000..593f0ef3 --- /dev/null +++ b/oci/catalog/apps/thelounge.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-thelounge", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Thelounge" + }, + "tagline": { + "en_US": "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server." + }, + "description": { + "en_US": "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/thelounge-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/thelounge-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9000, + "path": "/" + }, + "website": "https://thelounge.github.io/", + "documentation": "https://docs.linuxserver.io/images/docker-thelounge/", + "repository": "https://github.com/linuxserver/docker-thelounge", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-06-06", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-05-25", + "note": "Rebase to Alpine 3.18, deprecate armhf." + }, + { + "date": "2022-12-18", + "note": "Rebasing master to alpine 3.17." + } + ], + "display_version": null, + "updated_at": "2025-07-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-thelounge", + "default_branch": "master", + "revision": "5ff7f0e52c3537fd08aebfed15102150757b11a3", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-thelounge/5ff7f0e52c3537fd08aebfed15102150757b11a3/README.md", + "readme_pushed_at": "2026-09-08T07:52:55Z", + "compose_sha256": "b2dfcca2a6d706b789d825adf7e3b44ee60e708fd891764a818b09afe534dbd3", + "generated_at": "2026-09-12T14:37:37+00:00" + }, + "container_contract": { + "service_name": "thelounge", + "container_name": "thelounge", + "image": { + "reference": "lscr.io/linuxserver/thelounge:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/thelounge", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/thelounge/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 9000, + "published_example": 9000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n thelounge:\n image: lscr.io/linuxserver/thelounge:latest\n container_name: thelounge\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/thelounge/config:/config\n ports:\n - 9000:9000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/threadfin.json b/oci/catalog/apps/threadfin.json new file mode 100644 index 00000000..d7e62357 --- /dev/null +++ b/oci/catalog/apps/threadfin.json @@ -0,0 +1,444 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-threadfin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Threadfin" + }, + "tagline": { + "en_US": "M3U proxy server" + }, + "description": { + "en_US": "Threadfin is a M3U proxy server for Plex, Emby, Jellyfin and any client and provider which supports the .TS and .M3U8 (HLS) streaming formats." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "jdownloader", + "developer": "jdownloader", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 34400, + "path": "/web/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/fyb3roptik/threadfin", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "fyb3roptik", + "repository": "https://hub.docker.com/r/fyb3roptik/threadfin", + "revision": "4e91ca790a8c3737e41cbe97f71fca875b477c2b82971d158aace53c3adfa27d", + "image_repository_url": "https://hub.docker.com/r/fyb3roptik/threadfin", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "4e91ca790a8c3737e41cbe97f71fca875b477c2b82971d158aace53c3adfa27d", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "threadfin", + "container_name": "threadfin", + "image": { + "reference": "fyb3roptik/threadfin:latest", + "registry": "docker.io", + "repository": "fyb3roptik/threadfin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "THREADFIN_BRANCH", + "example": "main", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "THREADFIN_DEBUG", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/home/threadfin/conf/data", + "compose_source_example": "/DATA/AppData/threadfin/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/home/threadfin/conf/backup", + "compose_source_example": "/DATA/AppData/threadfin/backup", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 34400, + "published_example": 34400, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: threadfin\nservices:\n threadfin:\n image: fyb3roptik/threadfin:latest\n restart: unless-stopped\n environment:\n - THREADFIN_BRANCH=main\n - THREADFIN_DEBUG=0\n ports:\n - target: 34400\n published: '34400'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/threadfin/config\n target: /home/threadfin/conf/data\n - type: bind\n source: /DATA/AppData/threadfin/backup\n target: /home/threadfin/conf/backup\n container_name: threadfin\n" + }, + "compose_stack": { + "project_name": "threadfin", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "threadfin", + "service_count": 1, + "services": [ + { + "name": "threadfin", + "image": "fyb3roptik/threadfin:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "fyb3roptik/threadfin:latest", + "restart": "unless-stopped", + "environment": [ + "THREADFIN_BRANCH=main", + "THREADFIN_DEBUG=0" + ], + "ports": [ + { + "target": 34400, + "published": "34400", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/threadfin/config", + "target": "/home/threadfin/conf/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/threadfin/backup", + "target": "/home/threadfin/conf/backup" + } + ], + "container_name": "threadfin" + } + } + ], + "top_level": { + "name": "threadfin" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "threadfin-volume-0", + "service": "threadfin", + "container_path": "/home/threadfin/conf/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "threadfin-volume-1", + "service": "threadfin", + "container_path": "/home/threadfin/conf/backup", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "threadfin" + ], + "stop_order": [ + "threadfin" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 34400, + "path": "/web/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/thunderbird.json b/oci/catalog/apps/thunderbird.json new file mode 100644 index 00000000..56b35e1a --- /dev/null +++ b/oci/catalog/apps/thunderbird.json @@ -0,0 +1,269 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-thunderbird", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Thunderbird" + }, + "tagline": { + "en_US": "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client." + }, + "description": { + "en_US": "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/thunderbird-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/thunderbird-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.thunderbird.net/", + "documentation": "https://docs.linuxserver.io/images/docker-thunderbird/", + "repository": "https://github.com/linuxserver/docker-thunderbird", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-31", + "note": "Rebase to resolute." + }, + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-12-02", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-05-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-thunderbird", + "default_branch": "master", + "revision": "64e300ec181ede03bf91c053c2832506b657dcc1", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-thunderbird/64e300ec181ede03bf91c053c2832506b657dcc1/README.md", + "readme_pushed_at": "2026-09-07T16:54:04Z", + "compose_sha256": "73745a32cfcb7701916c16183d5e2a1231d1f7c12f2343eef90eeb90a40d4af4", + "generated_at": "2026-09-12T14:37:38+00:00" + }, + "container_contract": { + "service_name": "thunderbird", + "container_name": "thunderbird", + "image": { + "reference": "lscr.io/linuxserver/thunderbird:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/thunderbird", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n thunderbird:\n image: lscr.io/linuxserver/thunderbird:latest\n container_name: thunderbird\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/transmission.json b/oci/catalog/apps/transmission.json new file mode 100644 index 00000000..a42fbf5a --- /dev/null +++ b/oci/catalog/apps/transmission.json @@ -0,0 +1,331 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-transmission", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Transmission" + }, + "tagline": { + "en_US": "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, \u00b5TP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more." + }, + "description": { + "en_US": "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, \u00b5TP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/transmission-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/transmission-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9091, + "path": "/" + }, + "website": "https://www.transmissionbt.com/", + "documentation": "https://docs.linuxserver.io/images/docker-transmission/", + "repository": "https://github.com/linuxserver/docker-transmission", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-31", + "note": "Bind RPC to IPv6 interface by default, fall back to IPv4 if unavailable." + }, + { + "date": "2024-11-29", + "note": "Fix PEERPORT setting." + }, + { + "date": "2023-10-07", + "note": "Install unrar from [linuxserver repo](https://github.com/linuxserver/docker-unrar)." + }, + { + "date": "2023-08-10", + "note": "Bump unrar to 6.2.10." + }, + { + "date": "2023-06-10", + "note": "Bump unrar to 6.2.8, install transmission-extra." + } + ], + "display_version": null, + "updated_at": "2026-05-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-transmission", + "default_branch": "master", + "revision": "106756a4b83bd0d6949d3d1e2adfb25eeda27413", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-transmission/106756a4b83bd0d6949d3d1e2adfb25eeda27413/README.md", + "readme_pushed_at": "2026-09-08T14:50:39Z", + "compose_sha256": "0fcf915c79ea428177c5bf055ad0ac5fd8834e6c6dc7d0f32423aca7c655ec26", + "generated_at": "2026-09-12T14:37:38+00:00" + }, + "container_contract": { + "service_name": "transmission", + "container_name": "transmission", + "image": { + "reference": "lscr.io/linuxserver/transmission:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/transmission", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TRANSMISSION_WEB_HOME", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "USER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PASS", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "WHITELIST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PEERPORT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "HOST_WHITELIST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/transmission/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/watch", + "compose_source_example": "/path/to/watch/folder", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 9091, + "published_example": 9091, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 51413, + "published_example": 51413, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 51413, + "published_example": 51413, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n transmission:\n image: lscr.io/linuxserver/transmission:latest\n container_name: transmission\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - TRANSMISSION_WEB_HOME= #optional\n - USER= #optional\n - PASS= #optional\n - WHITELIST= #optional\n - PEERPORT= #optional\n - HOST_WHITELIST= #optional\n volumes:\n - /path/to/transmission/data:/config\n - /path/to/downloads:/downloads #optional\n - /path/to/watch/folder:/watch #optional\n ports:\n - 9091:9091\n - 51413:51413\n - 51413:51413/udp\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9091, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/trilium.json b/oci/catalog/apps/trilium.json new file mode 100644 index 00000000..6041f340 --- /dev/null +++ b/oci/catalog/apps/trilium.json @@ -0,0 +1,408 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-trilium", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Trilium" + }, + "tagline": { + "en_US": "Build your personal knowledge base with TriliumNext Notes" + }, + "description": { + "en_US": "TriliumNext Notes is a cross-platform hierarchical note-taking tool focused on building large personal knowledge bases, offering robust organization and editing capabilities. Its intuitive interface and versatile features make it ideal for scholars, developers, and note-taking enthusiasts managing complex knowledge.\n\nThe tool's core features include hierarchical note organization and rich editing. Users can arrange notes in an arbitrarily deep tree structure, with single notes clonable to multiple locations. It supports a WYSIWYG editor with tables, images, math, and Markdown autoformatting for efficiency. Code notes feature syntax highlighting, while fast navigation includes full-text search and note hoisting. Seamless versioning and note attributes enable organization, querying, and advanced scripting.\n\nIt offers secure login (OpenID, TOTP), supports self-hosted synchronization servers or third-party services, and provides per-note encryption for privacy. Users can sketch diagrams with Excalidraw, create relation/link maps, mind maps with Mind Elixir, and geo maps with location pins and GPX tracks. A REST API enables automation, with scalability for over 100,000 notes. Touch-optimized mobile frontend, dark theme, user themes, Evernote/Markdown import/export, and Web Clipper enhance usability.\n\n**Key Features:**\n- Notes can be arranged into arbitrarily deep tree. Single note can be placed into multiple places in the tree (see [cloning](https://triliumnext.github.io/Docs/Wiki/cloning-notes))\n- Rich WYSIWYG note editor including e.g. tables, images and [math](https://triliumnext.github.io/Docs/Wiki/text-notes) with markdown [autoformat](https://triliumnext.github.io/Docs/Wiki/text-notes#autoformat)\n- Support for editing [notes with source code](https://triliumnext.github.io/Docs/Wiki/code-notes), including syntax highlighting\n- Fast and easy [navigation between notes](https://triliumnext.github.io/Docs/Wiki/note-navigation), full text search and [note hoisting](https://triliumnext.github.io/Docs/Wiki/note-hoisting)\n- Seamless [note versioning](https://triliumnext.github.io/Docs/Wiki/note-revisions)\n- Note [attributes](https://triliumnext.github.io/Docs/Wiki/attributes) can be used for note organization, querying and advanced [scripting](https://triliumnext.github.io/Docs/Wiki/scripts)\n- Direct [OpenID and TOTP integration](https://github.com/TriliumNext/Trilium/blob/main/docs/User%20Guide/User%20Guide/Installation%20%26%20Setup/Server%20Installation/Multi-Factor%20Authentication.md) for more secure login\n- [Synchronization](https://triliumnext.github.io/Docs/Wiki/synchronization) with self-hosted sync server\n - there's a [3rd party service for hosting synchronisation server](https://trilium.cc/paid-hosting)\n- [Sharing](https://triliumnext.github.io/Docs/Wiki/sharing) (publishing) notes to public internet\n- Strong [note encryption](https://triliumnext.github.io/Docs/Wiki/protected-notes) with per-note granularity\n- Sketching diagrams, based on [Excalidraw](https://excalidraw.com/) (note type canvas)\n- [Relation maps](https://triliumnext.github.io/Docs/Wiki/relation-map) and [link maps](https://triliumnext.github.io/Docs/Wiki/link-map) for visualizing notes and their relations\n- Mind maps, based on [Mind Elixir](https://docs.mind-elixir.com/)\n- [Geo maps](https://github.com/TriliumNext/Trilium/blob/main/docs/User%20Guide/User%20Guide/Note%20Types/Geo%20Map.md) with location pins and GPX tracks\n- [Scripting](https://triliumnext.github.io/Docs/Wiki/scripts) - see [Advanced showcases](https://triliumnext.github.io/Docs/Wiki/advanced-showcases)\n- [REST API](https://triliumnext.github.io/Docs/Wiki/etapi) for automation\n- Scales well in both usability and performance upwards of 100 000 notes\n- Touch optimized [mobile frontend](https://triliumnext.github.io/Docs/Wiki/mobile-frontend) for smartphones and tablets\n- Built-in [dark theme](https://triliumnext.github.io/Docs/Wiki/themes), support for user themes\n- [Evernote](https://triliumnext.github.io/Docs/Wiki/evernote-import) and [Markdown import & export](https://triliumnext.github.io/Docs/Wiki/markdown)\n- [Web Clipper](https://triliumnext.github.io/Docs/Wiki/web-clipper) for easy saving of web content\n- Customizable UI (sidebar buttons, user-defined widgets,...)\n- [Metrics](https://github.com/TriliumNext/Trilium/blob/main/docs/User%20Guide/User%20Guide/Advanced%20Usage/Metrics.md), along with a [Grafana Dashboard](https://github.com/TriliumNext/Trilium/blob/main/docs/User%20Guide/User%20Guide/Advanced%20Usage/Metrics/grafana-dashboard.json)\n\n**Learn More:**\n- [TriliumNext GitHub Repository](https://github.com/TriliumNext/Trilium)\n- [awesome-trilium](https://github.com/Nriver/awesome-trilium) for 3rd party themes, scripts, plugins and more\n- [TriliumRocks!](https://trilium.rocks/) for tutorials, guides, and much more\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "zadam", + "developer": "zadam", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://triliumnext.github.io/Docs/", + "documentation": null, + "repository": "https://hub.docker.com/r/triliumnext/trilium", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/triliumnext/trilium", + "revision": "0f07c00bf1b80f8303a5fea1f327c85c74a2d1de2b3c5ed1763c370fd21532a0", + "image_repository_url": "https://hub.docker.com/r/triliumnext/trilium", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "0f07c00bf1b80f8303a5fea1f327c85c74a2d1de2b3c5ed1763c370fd21532a0", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "trilium", + "container_name": "trilium", + "image": { + "reference": "triliumnext/trilium:latest", + "registry": "docker.io", + "repository": "triliumnext/trilium", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/home/node/trilium-data", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 8088, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: trilium\nservices:\n trilium:\n command: []\n container_name: trilium\n deploy:\n resources:\n reservations:\n memory: 256M\n image: triliumnext/trilium:latest\n ports:\n - target: 8080\n published: '8088'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /home/node/trilium-data\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "trilium", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "trilium", + "service_count": 1, + "services": [ + { + "name": "trilium", + "image": "triliumnext/trilium:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "command": [], + "container_name": "trilium", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "image": "triliumnext/trilium:latest", + "ports": [ + { + "target": 8080, + "published": "8088", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/home/node/trilium-data" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "trilium" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "trilium-volume-0", + "service": "trilium", + "container_path": "/home/node/trilium-data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "trilium" + ], + "stop_order": [ + "trilium" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/turbodiffusion-nvidia.json b/oci/catalog/apps/turbodiffusion-nvidia.json new file mode 100644 index 00000000..f8fc84b2 --- /dev/null +++ b/oci/catalog/apps/turbodiffusion-nvidia.json @@ -0,0 +1,515 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-turbodiffusion-nvidia", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "TurboDiffusion(Nvidia GPU)" + }, + "tagline": { + "en_US": "An accelerated video generation framework that speeds up end-to-end diffusion while preserving video quality" + }, + "description": { + "en_US": "TurboDiffusion is an accelerated text-to-video generation framework based on the Latent Consistency Model (LCM). It leverages various TurboWan2 models to rapidly generate high-quality videos from text descriptions. The framework supports both image and video generation and provides optimized checkpoints for different GPU configurations.\n\n**Key Features:**\n- Ultra-fast video and image generation\n- Intuitive Gradio WebUI\n- Optimized for different GPU configurations\n- Quantized and unquantized checkpoints\n- Flexible model configuration\n\n**Hardware Requirements:**\n- Recommended: RTX 3090 or above\n- GPU VRAM: > 30 GB\n- System RAM: > 40 GB\n- CUDA-compatible NVIDIA drivers\n\n**Learn More:**\n- [TurboDiffusion GitHub](https://github.com/thu-ml/TurboDiffusion)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "thu-ml", + "developer": "thu-ml", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 7860, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/icewhaletech/turbodiffusion", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "icewhaletech", + "repository": "https://hub.docker.com/r/icewhaletech/turbodiffusion", + "revision": "0b18f7247669a9dc4c3c89ca970590be74fcac52bcedc2263ca90907bf58044b", + "image_repository_url": "https://hub.docker.com/r/icewhaletech/turbodiffusion", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "0b18f7247669a9dc4c3c89ca970590be74fcac52bcedc2263ca90907bf58044b", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "turbodiffusion", + "container_name": "turbodiffusion", + "image": { + "reference": "icewhaletech/turbodiffusion:latest", + "registry": "docker.io", + "repository": "icewhaletech/turbodiffusion", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "MODEL_PATHS", + "example": "/workspace/TurboDiffusion/checkpoints_host,/workspace/TurboDiffusion/checkpoints", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NVIDIA_VISIBLE_DEVICES", + "example": "all", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NVIDIA_DRIVER_CAPABILITIES", + "example": "compute,utility,video", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CUDA_HOME", + "example": "/usr/local/cuda", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PYTHONPATH", + "example": "/workspace/TurboDiffusion/turbodiffusion", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/workspace/TurboDiffusion/checkpoints_host", + "compose_source_example": "/DATA/AppData/$AppID/models", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/workspace/TurboDiffusion/outputs", + "compose_source_example": "/DATA/AppData/$AppID/outputs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 7860, + "published_example": 27860, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: turbodiffusion_nvidia\nservices:\n turbodiffusion:\n image: icewhaletech/turbodiffusion:latest\n container_name: turbodiffusion\n deploy:\n resources:\n reservations:\n memory: 40G\n devices:\n - driver: nvidia\n count: all\n capabilities:\n - gpu\n environment:\n MODEL_PATHS: /workspace/TurboDiffusion/checkpoints_host,/workspace/TurboDiffusion/checkpoints\n NVIDIA_VISIBLE_DEVICES: all\n NVIDIA_DRIVER_CAPABILITIES: compute,utility,video\n CUDA_HOME: /usr/local/cuda\n PYTHONPATH: /workspace/TurboDiffusion/turbodiffusion\n ports:\n - target: 7860\n published: '27860'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/models\n target: /workspace/TurboDiffusion/checkpoints_host\n - type: bind\n source: /DATA/AppData/$AppID/outputs\n target: /workspace/TurboDiffusion/outputs\n working_dir: /workspace/TurboDiffusion\n command:\n - python\n - turbodiffusion/app_gradio.py\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "turbodiffusion_nvidia", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "turbodiffusion", + "service_count": 1, + "services": [ + { + "name": "turbodiffusion", + "image": "icewhaletech/turbodiffusion:20260312", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "icewhaletech/turbodiffusion:20260312", + "container_name": "turbodiffusion", + "deploy": { + "resources": { + "reservations": { + "memory": "40G", + "devices": [ + { + "driver": "nvidia", + "count": "all", + "capabilities": [ + "gpu" + ] + } + ] + } + } + }, + "environment": { + "MODEL_PATHS": "/workspace/TurboDiffusion/checkpoints_host,/workspace/TurboDiffusion/checkpoints", + "NVIDIA_VISIBLE_DEVICES": "all", + "NVIDIA_DRIVER_CAPABILITIES": "compute,utility,video", + "CUDA_HOME": "/usr/local/cuda", + "PYTHONPATH": "/workspace/TurboDiffusion/turbodiffusion" + }, + "ports": [ + { + "target": 7860, + "published": "27860", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/models", + "target": "/workspace/TurboDiffusion/checkpoints_host" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/outputs", + "target": "/workspace/TurboDiffusion/outputs" + } + ], + "working_dir": "/workspace/TurboDiffusion", + "command": [ + "python", + "turbodiffusion/app_gradio.py" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "turbodiffusion_nvidia" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "turbodiffusion-volume-0", + "service": "turbodiffusion", + "container_path": "/workspace/TurboDiffusion/checkpoints_host", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "turbodiffusion-volume-1", + "service": "turbodiffusion", + "container_path": "/workspace/TurboDiffusion/outputs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "turbodiffusion" + ], + "stop_order": [ + "turbodiffusion" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 7860, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 40960, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "python", + "turbodiffusion/app_gradio.py" + ], + "working_directory": "/workspace/TurboDiffusion" + }, + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "enable_prompt": "Enable the NVIDIA GPU requested by the image", + "enabled_default": true, + "required_by_compose": true, + "risk_level": "hardware-access", + "device_selection": "all-requested-by-compose", + "driver_libraries": "bind-compatible-host-driver-libraries-read-only" + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/tvheadend.json b/oci/catalog/apps/tvheadend.json new file mode 100644 index 00000000..563f8de4 --- /dev/null +++ b/oci/catalog/apps/tvheadend.json @@ -0,0 +1,408 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-tvheadend", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Tvheadend" + }, + "tagline": { + "en_US": "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources." + }, + "description": { + "en_US": "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/tvheadend-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/tvheadend-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9981, + "path": "/" + }, + "website": "https://www.tvheadend.org/", + "documentation": "https://docs.linuxserver.io/images/docker-tvheadend/", + "repository": "https://github.com/linuxserver/docker-tvheadend", + "tips": [], + "mini_changelog": [ + { + "date": "2024-06-25", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-10-16", + "note": "Add mesa-va-gallium package for AMD transcoding." + }, + { + "date": "2023-09-20", + "note": "Add perl-json-xs package." + }, + { + "date": "2023-05-18", + "note": "Install XMLTV from Alpine repos." + } + ], + "display_version": null, + "updated_at": "2024-06-25" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-tvheadend", + "default_branch": "master", + "revision": "07983385fc80396c977578212df205c76d29f1fe", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-tvheadend/07983385fc80396c977578212df205c76d29f1fe/README.md", + "readme_pushed_at": "2026-09-12T18:05:33Z", + "compose_sha256": "977961da6039fd3cfa9618898cf51d5e67507086ed11d14a880d4bb976e78a8e", + "generated_at": "2026-09-13T15:35:46+00:00" + }, + "container_contract": { + "service_name": "tvheadend", + "container_name": "tvheadend", + "image": { + "reference": "lscr.io/linuxserver/tvheadend:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/tvheadend", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "RUN_OPTS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/tvheadend/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/recordings", + "compose_source_example": "/path/to/recordings", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 9981, + "published_example": 9981, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 9982, + "published_example": 9982, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n tvheadend:\n image: lscr.io/linuxserver/tvheadend:latest\n container_name: tvheadend\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - RUN_OPTS= #optional\n volumes:\n - /path/to/tvheadend/data:/config\n - /path/to/recordings:/recordings\n ports:\n - 9981:9981\n - 9982:9982\n devices:\n - /dev/dri:/dev/dri #optional\n - /dev/dvb:/dev/dvb #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9981, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "enable_prompt": "VA-API video acceleration", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/dri:/dev/dri" + }, + { + "id": "dev-dvb", + "kind": "character-device-tree", + "purpose": "dvb", + "enable_prompt": "Host DVB tuners", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "DVB device directory", + "host_path_default": "/dev/dvb", + "container_path": "/dev/dvb", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/dvb:/dev/dvb" + } + ], + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/twingate-connector.json b/oci/catalog/apps/twingate-connector.json new file mode 100644 index 00000000..7f1853e8 --- /dev/null +++ b/oci/catalog/apps/twingate-connector.json @@ -0,0 +1,445 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-twingate-connector", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Twingate" + }, + "tagline": { + "en_US": "Twingate Connector for self-hosted server" + }, + "description": { + "en_US": "It's a connector for Twingate\"." + }, + "category": "remote", + "category_label": "Remote Access & VPN", + "author": "Twingate", + "developer": "Twingate", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://www.twingate.com", + "documentation": null, + "repository": "https://hub.docker.com/r/twingate/connector", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/twingate/connector", + "revision": "5042e75680cd0b8bb7bdd89744bbbbad500ecfae555f7826ae5243c719e15054", + "image_repository_url": "https://hub.docker.com/r/twingate/connector", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "5042e75680cd0b8bb7bdd89744bbbbad500ecfae555f7826ae5243c719e15054", + "generated_at": "2026-09-13T15:47:53+00:00" + }, + "container_contract": { + "service_name": "twingate-connector", + "container_name": "twingate-connector", + "image": { + "reference": "twingate/connector:latest", + "registry": "docker.io", + "repository": "twingate/connector", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TWINGATE_NETWORK", + "example": "", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TWINGATE_ACCESS_TOKEN", + "example": "${GENERATED_TWINGATE_ACCESS_TOKEN}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "TWINGATE_REFRESH_TOKEN", + "example": "${GENERATED_TWINGATE_REFRESH_TOKEN}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "TWINGATE_LABEL_HOSTNAME", + "example": "${HOSTNAME}", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: twingate-connector\nservices:\n twingate-connector:\n image: twingate/connector:latest\n container_name: twingate-connector\n command:\n - /connectord\n environment:\n TWINGATE_NETWORK: ''\n TWINGATE_ACCESS_TOKEN: ${GENERATED_TWINGATE_ACCESS_TOKEN}\n TWINGATE_REFRESH_TOKEN: ${GENERATED_TWINGATE_REFRESH_TOKEN}\n TWINGATE_LABEL_HOSTNAME: ${HOSTNAME}\n restart: unless-stopped\n sysctls:\n net.ipv4.ping_group_range: 0 2147483647\n network_mode: default\n privileged: false\n cpu_shares: 90\n deploy:\n resources:\n reservations:\n memory: 500M\n" + }, + "compose_stack": { + "project_name": "twingate-connector", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "twingate-connector", + "service_count": 1, + "services": [ + { + "name": "twingate-connector", + "image": "twingate/connector:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "twingate/connector:latest", + "container_name": "twingate-connector", + "command": [ + "/connectord" + ], + "environment": { + "TWINGATE_NETWORK": "", + "TWINGATE_ACCESS_TOKEN": "${GENERATED_TWINGATE_ACCESS_TOKEN}", + "TWINGATE_REFRESH_TOKEN": "${GENERATED_TWINGATE_REFRESH_TOKEN}", + "TWINGATE_LABEL_HOSTNAME": "${HOSTNAME}" + }, + "restart": "unless-stopped", + "sysctls": { + "net.ipv4.ping_group_range": "0 2147483647" + }, + "network_mode": "default", + "privileged": false, + "cpu_shares": 90, + "deploy": { + "resources": { + "reservations": { + "memory": "500M" + } + } + } + } + } + ], + "top_level": { + "name": "twingate-connector" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "twingate-connector" + ], + "stop_order": [ + "twingate-connector" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "twingate-access-token", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "twingate-connector", + "environment_variable": "TWINGATE_ACCESS_TOKEN" + } + ] + }, + { + "id": "twingate-refresh-token", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "twingate-connector", + "environment_variable": "TWINGATE_REFRESH_TOKEN" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 500, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [ + "/connectord" + ] + }, + "resources": { + "cpu_shares": 90 + }, + "network": { + "compose_mode": "default" + }, + "security": { + "sysctls": [ + { + "name": "net.ipv4.ping_group_range", + "value": "0 2147483647" + } + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ubooquity.json b/oci/catalog/apps/ubooquity.json new file mode 100644 index 00000000..d0e4a352 --- /dev/null +++ b/oci/catalog/apps/ubooquity.json @@ -0,0 +1,303 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ubooquity", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ubooquity" + }, + "tagline": { + "en_US": "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer." + }, + "description": { + "en_US": "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ubooquity-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ubooquity-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 2202, + "path": "/" + }, + "website": "https://vaemendis.net/ubooquity/", + "documentation": "https://docs.linuxserver.io/images/docker-ubooquity/", + "repository": "https://github.com/linuxserver/docker-ubooquity", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-06-06", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-20", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2023-10-29", + "note": "Bump JRE to 17 to support v3." + }, + { + "date": "2023-07-12", + "note": "Rebase to Alpine 3.18." + } + ], + "display_version": null, + "updated_at": "2025-07-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ubooquity", + "default_branch": "master", + "revision": "611b09d7dca1b5f23c246ae36646ce3abedfdce6", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ubooquity/611b09d7dca1b5f23c246ae36646ce3abedfdce6/README.md", + "readme_pushed_at": "2026-09-09T00:39:52Z", + "compose_sha256": "aeb5369ea34063e1fbc59f8b392b242439978806ae6a0b4efccfb90482b0348c", + "generated_at": "2026-09-12T14:37:38+00:00" + }, + "container_contract": { + "service_name": "ubooquity", + "container_name": "ubooquity", + "image": { + "reference": "lscr.io/linuxserver/ubooquity:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ubooquity", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MAXMEM", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/ubooquity/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/books", + "compose_source_example": "/path/to/books", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/comics", + "compose_source_example": "/path/to/comics", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/files", + "compose_source_example": "/path/to/raw/files", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 2202, + "published_example": 2202, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 2203, + "published_example": 2203, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ubooquity:\n image: lscr.io/linuxserver/ubooquity:latest\n container_name: ubooquity\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - MAXMEM= #optional\n volumes:\n - /path/to/ubooquity/data:/config\n - /path/to/books:/books\n - /path/to/comics:/comics\n - /path/to/raw/files:/files\n ports:\n - 2202:2202\n - 2203:2203\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 2202, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ungoogled-chromium.json b/oci/catalog/apps/ungoogled-chromium.json new file mode 100644 index 00000000..58608e23 --- /dev/null +++ b/oci/catalog/apps/ungoogled-chromium.json @@ -0,0 +1,380 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-ungoogled-chromium", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Ungoogled Chromium" + }, + "tagline": { + "en_US": "Ungoogled Chromium is Google Chromium, sans dependency on Google web services." + }, + "description": { + "en_US": "Ungoogled Chromium is Google Chromium, sans dependency on Google web services." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ungoogled-chromium-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ungoogled-chromium-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/ungoogled-software/ungoogled-chromium", + "documentation": "https://docs.linuxserver.io/images/docker-ungoogled-chromium/", + "repository": "https://github.com/linuxserver/docker-ungoogled-chromium", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-27", + "note": "Multi arch arm64 support added." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-03-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-ungoogled-chromium", + "default_branch": "master", + "revision": "960ea2ca792b0a860f40eb8931fbf95ae798b6f7", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-ungoogled-chromium/960ea2ca792b0a860f40eb8931fbf95ae798b6f7/README.md", + "readme_pushed_at": "2026-09-08T06:58:56Z", + "compose_sha256": "58201a877a1e23d5b7c73e56c2106eb9857b4ca76606ed762d0d98f67dc6bd3f", + "generated_at": "2026-09-12T14:37:38+00:00" + }, + "container_contract": { + "service_name": "ungoogled-chromium", + "container_name": "ungoogled-chromium", + "image": { + "reference": "lscr.io/linuxserver/ungoogled-chromium:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/ungoogled-chromium", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CHROME_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n ungoogled-chromium:\n image: lscr.io/linuxserver/ungoogled-chromium:latest\n container_name: ungoogled-chromium\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - CHROME_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-ungoogled-chromium/master/Dockerfile", + "dockerfile_sha256": "8d4a62f74204c7ce4f5c909994b4ab1460a3c482a3fba32eef90f7c927b9618b", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/unifi-controller.json b/oci/catalog/apps/unifi-controller.json new file mode 100644 index 00000000..b7cf5bfe --- /dev/null +++ b/oci/catalog/apps/unifi-controller.json @@ -0,0 +1,532 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-unifi-controller", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Unifi-controller [legacy]" + }, + "tagline": { + "en_US": "The Unifi-controller software is a powerful, enterprise wireless software engine ideal for high-density client deployments requiring low latency and high uptime performance." + }, + "description": { + "en_US": "For Unifi to adopt other devices, e.g. an Access Point, it is required to change the inform IP address. Because Unifi runs inside Docker by default it uses an IP address not accessible by other devices. To change this go to Settings > System Settings > Controller Configuration and set the Controller Hostname/IP to a hostname or IP address accessible by your devices. Additionally the checkbox \"Override inform host with controller hostname/IP\" has to be checked, so that devices can connect to the controller during adoption (devices use the inform-endpoint during adoption)." + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "LinuxServer.io", + "developer": "LinuxServer.io", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://ui.com", + "documentation": "https://docs.linuxserver.io/images/docker-unifi-controller/", + "repository": "https://hub.docker.com/r/linuxserver/unifi-controller", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://hub.docker.com/r/linuxserver/unifi-controller", + "revision": "1c163afdda8b1c00f89c2bbb7bc1e7f47ffa59e8710e395cd00d6f53c45df5f2", + "image_repository_url": "https://hub.docker.com/r/linuxserver/unifi-controller", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "1c163afdda8b1c00f89c2bbb7bc1e7f47ffa59e8710e395cd00d6f53c45df5f2", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "unifi-controller", + "container_name": "unifi-controller", + "image": { + "reference": "linuxserver/unifi-controller:latest", + "registry": "docker.io", + "repository": "linuxserver/unifi-controller", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "MEM_LIMIT", + "example": "1024", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MEM_STARTUP", + "example": "1024", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3478, + "published_example": 3478, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 10001, + "published_example": 10001, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8080, + "published_example": 8383, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8443, + "published_example": 8443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 1900, + "published_example": 1900, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8843, + "published_example": 8843, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8880, + "published_example": 8880, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 6789, + "published_example": 6789, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 5514, + "published_example": 5514, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: unifi-controller\nservices:\n unifi-controller:\n environment:\n MEM_LIMIT: '1024'\n MEM_STARTUP: '1024'\n PGID: '1000'\n PUID: '1000'\n image: linuxserver/unifi-controller:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 3478\n published: '3478'\n protocol: udp\n - target: 10001\n published: '10001'\n protocol: udp\n - target: 8080\n published: '8383'\n protocol: tcp\n - target: 8443\n published: '8443'\n protocol: tcp\n - target: 1900\n published: '1900'\n protocol: udp\n - target: 8843\n published: '8843'\n protocol: tcp\n - target: 8880\n published: '8880'\n protocol: tcp\n - target: 6789\n published: '6789'\n protocol: tcp\n - target: 5514\n published: '5514'\n protocol: udp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n container_name: unifi-controller\n" + }, + "compose_stack": { + "project_name": "unifi-controller", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "unifi-controller", + "service_count": 1, + "services": [ + { + "name": "unifi-controller", + "image": "linuxserver/unifi-controller:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "MEM_LIMIT": "1024", + "MEM_STARTUP": "1024", + "PGID": "1000", + "PUID": "1000" + }, + "image": "linuxserver/unifi-controller:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 3478, + "published": "3478", + "protocol": "udp" + }, + { + "target": 10001, + "published": "10001", + "protocol": "udp" + }, + { + "target": 8080, + "published": "8383", + "protocol": "tcp" + }, + { + "target": 8443, + "published": "8443", + "protocol": "tcp" + }, + { + "target": 1900, + "published": "1900", + "protocol": "udp" + }, + { + "target": 8843, + "published": "8843", + "protocol": "tcp" + }, + { + "target": 8880, + "published": "8880", + "protocol": "tcp" + }, + { + "target": 6789, + "published": "6789", + "protocol": "tcp" + }, + { + "target": 5514, + "published": "5514", + "protocol": "udp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + } + ], + "container_name": "unifi-controller" + } + } + ], + "top_level": { + "name": "unifi-controller" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "unifi-controller-volume-0", + "service": "unifi-controller", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "unifi-controller" + ], + "stop_order": [ + "unifi-controller" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/unifi-network-application.json b/oci/catalog/apps/unifi-network-application.json new file mode 100644 index 00000000..01885968 --- /dev/null +++ b/oci/catalog/apps/unifi-network-application.json @@ -0,0 +1,367 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-unifi-network-application", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Unifi Network Application" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "" + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/unifi-network-application-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/unifi-network-application-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 8443, + "path": "/" + }, + "website": null, + "documentation": "https://docs.linuxserver.io/images/docker-unifi-network-application/", + "repository": "https://github.com/linuxserver/docker-unifi-network-application", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-14", + "note": "Rebase to Ubuntu Resolute." + }, + { + "date": "2026-04-20", + "note": "Bump JRE to v25 to support v10.3+ of the application." + }, + { + "date": "2025-10-20", + "note": "Switch to using FW API endpoint for version checks." + }, + { + "date": "2025-05-08", + "note": "Update sample `init-mongo.sh` for compatibility with 9.1.120 (only affects new installs)." + }, + { + "date": "2025-02-13", + "note": "Revert JRE to 17." + } + ], + "display_version": null, + "updated_at": "2026-07-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-unifi-network-application", + "default_branch": "main", + "revision": "8bba858a1b5f2275819d81102e131baa566247ab", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-unifi-network-application/8bba858a1b5f2275819d81102e131baa566247ab/README.md", + "readme_pushed_at": "2026-09-08T20:23:32Z", + "compose_sha256": "6c2dd55372cb57597115bb957f161a10a29052badd2d07ae41e7420b07382f02", + "generated_at": "2026-09-12T14:37:38+00:00" + }, + "container_contract": { + "service_name": "unifi-network-application", + "container_name": "unifi-network-application", + "image": { + "reference": "lscr.io/linuxserver/unifi-network-application:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/unifi-network-application", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MONGO_USER", + "example": "unifi", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MONGO_PASS", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "MONGO_HOST", + "example": "unifi-db", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MONGO_PORT", + "example": "27017", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MONGO_DBNAME", + "example": "unifi", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MONGO_AUTHSOURCE", + "example": "admin", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MEM_LIMIT", + "example": "1024", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MEM_STARTUP", + "example": "1024", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MONGO_TLS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/unifi-network-application/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8443, + "published_example": 8443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3478, + "published_example": 3478, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 10001, + "published_example": 10001, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8080, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 1900, + "published_example": 1900, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8843, + "published_example": 8843, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8880, + "published_example": 8880, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 6789, + "published_example": 6789, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 5514, + "published_example": 5514, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n unifi-network-application:\n image: lscr.io/linuxserver/unifi-network-application:latest\n container_name: unifi-network-application\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - MONGO_USER=unifi\n - MONGO_PASS=\n - MONGO_HOST=unifi-db\n - MONGO_PORT=27017\n - MONGO_DBNAME=unifi\n - MONGO_AUTHSOURCE=admin\n - MEM_LIMIT=1024 #optional\n - MEM_STARTUP=1024 #optional\n - MONGO_TLS= #optional\n volumes:\n - /path/to/unifi-network-application/data:/config\n ports:\n - 8443:8443\n - 3478:3478/udp\n - 10001:10001/udp\n - 8080:8080\n - 1900:1900/udp #optional\n - 8843:8843 #optional\n - 8880:8880 #optional\n - 6789:6789 #optional\n - 5514:5514/udp #optional\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI 1", + "scheme": "https", + "port": 8443, + "path": "/", + "source": "linuxserver-readme-application-setup" + }, + { + "label": "Web UI 2", + "scheme": "http", + "port": 8080, + "path": "/inform", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/unpackerr.json b/oci/catalog/apps/unpackerr.json new file mode 100644 index 00000000..aaead7d1 --- /dev/null +++ b/oci/catalog/apps/unpackerr.json @@ -0,0 +1,436 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-unpackerr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Unpackerr" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "Background archive extraction for Arr download queues. No web interface." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "golift", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://unpackerr.zip/docs/install/docker/", + "documentation": "https://unpackerr.zip/docs/install/docker/", + "repository": "https://github.com/Unpackerr/unpackerr", + "tips": [ + "Service without a web interface. Configure the Arr connections through the official UN_* variables or /config/unpackerr.conf." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "golift", + "repository": "https://github.com/Unpackerr/unpackerr", + "revision": "5909b075d14d21eaa4e76a2fc53528e2e33066821e06ff0f984479ee57731eac", + "image_repository_url": "https://hub.docker.com/r/golift/unpackerr", + "readme_pushed_at": "", + "compose_sha256": "5909b075d14d21eaa4e76a2fc53528e2e33066821e06ff0f984479ee57731eac", + "generated_at": "2026-09-14T17:13:55+00:00" + }, + "container_contract": { + "service_name": "unpackerr", + "container_name": "unpackerr", + "image": { + "reference": "golift/unpackerr:latest", + "registry": "docker.io", + "repository": "golift/unpackerr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: unpackerr\nservices:\n unpackerr:\n image: golift/unpackerr:latest\n user: 1000:1000\n environment:\n TZ: Europe/Madrid\n volumes:\n - /path/to/config:/config\n - /path/to/downloads:/data\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "unpackerr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "unpackerr", + "service_count": 1, + "services": [ + { + "name": "unpackerr", + "image": "golift/unpackerr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "golift/unpackerr:latest", + "user": "1000:1000", + "environment": { + "TZ": "Europe/Madrid" + }, + "volumes": [ + "/path/to/config:/config", + "/path/to/downloads:/data" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "unpackerr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "unpackerr-volume-0", + "service": "unpackerr", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "unpackerr-volume-1", + "service": "unpackerr", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for unpackerr:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "unpackerr" + ], + "stop_order": [ + "unpackerr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "user": "1000:1000" + }, + "references": [ + "https://unpackerr.zip/docs/install/docker/" + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/uptimekuma.json b/oci/catalog/apps/uptimekuma.json new file mode 100644 index 00000000..5e7104c7 --- /dev/null +++ b/oci/catalog/apps/uptimekuma.json @@ -0,0 +1,401 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-uptimekuma", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Uptime Kuma" + }, + "tagline": { + "en_US": "A fancy monitoring tool" + }, + "description": { + "en_US": "Uptime Kuma is a free, easy-to-use self-hosted monitoring tool designed for real-time tracking of network services and infrastructure, offering a modern interface and robust functionality. It provides an intuitive Web dashboard for managing services, ideal for individual developers, home lab users, and small teams.\n\nThe tool's core features include comprehensive monitoring and diverse notification channels. It monitors HTTP/HTTPS, TCP ports, DNS records, databases, Ping, and Steam game servers, with interactive Ping charts visually displaying response times and status. Users can receive real-time alerts via Telegram, Discord, Slack, Email (SMTP), and over 95 other notification services. SSL certificate monitoring checks certificate validity and expiration, aiding timely renewals.\n\nIt supports 20-second monitoring intervals for rapid downtime detection and offers multiple status pages to share real-time service status with customers. Proxy support enables remote access via Cloudflare, Nginx, or similar services, enhancing flexibility. Two-factor authentication (2FA) and API keys bolster security, ensuring full user control over local data. The tool delivers an efficient monitoring solution with intuitive operation and community support.\n\n**Key Features:**\n- Monitor HTTP/HTTPS, TCP, DNS, databases, and other services\n- Notifications via Telegram, Discord, Slack, and over 95 other channels\n- Interactive Ping charts displaying response times and status\n- SSL certificate monitoring for validity and expiration\n- 20-second monitoring intervals for rapid downtime detection\n- Multiple status pages for sharing service status\n- Proxy support compatible with Cloudflare, Nginx, and more\n- Two-factor authentication (2FA) and API keys for enhanced security\n\n**Learn More:**\n- [Uptime Kuma Official Website](https://uptimekuma.org)\n- [Uptime Kuma GitHub Repository](https://github.com/louislam/uptime-kuma)\n" + }, + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "author": "Louis Lam", + "developer": "Louis Lam", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3001, + "path": "/" + }, + "website": "https://uptimekuma.org", + "documentation": null, + "repository": "https://hub.docker.com/r/louislam/uptime-kuma", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "louislam", + "repository": "https://hub.docker.com/r/louislam/uptime-kuma", + "revision": "06b0fa62032a12399473460539c2724d95c0e08afabb143ab7e9033e00d56a7a", + "image_repository_url": "https://hub.docker.com/r/louislam/uptime-kuma", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "06b0fa62032a12399473460539c2724d95c0e08afabb143ab7e9033e00d56a7a", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "uptimekuma", + "container_name": "uptimekuma", + "image": { + "reference": "louislam/uptime-kuma:latest", + "registry": "docker.io", + "repository": "louislam/uptime-kuma", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/data", + "compose_source_example": "/DATA/AppData/$AppID/app/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: uptimekuma\nservices:\n uptimekuma:\n image: louislam/uptime-kuma:latest\n deploy:\n resources:\n reservations:\n memory: 128M\n network_mode: bridge\n ports:\n - target: 3001\n published: '3001'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/app/data\n target: /app/data\n container_name: uptimekuma\n" + }, + "compose_stack": { + "project_name": "uptimekuma", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "uptimekuma", + "service_count": 1, + "services": [ + { + "name": "uptimekuma", + "image": "louislam/uptime-kuma:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "louislam/uptime-kuma:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 3001, + "published": "3001", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/app/data", + "target": "/app/data" + } + ], + "container_name": "uptimekuma" + } + } + ], + "top_level": { + "name": "uptimekuma" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "uptimekuma-volume-0", + "service": "uptimekuma", + "container_path": "/app/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "uptimekuma" + ], + "stop_order": [ + "uptimekuma" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3001, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/v2raya.json b/oci/catalog/apps/v2raya.json new file mode 100644 index 00000000..8f873477 --- /dev/null +++ b/oci/catalog/apps/v2raya.json @@ -0,0 +1,487 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-v2raya", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "V2rayA" + }, + "tagline": { + "en_US": "A web GUI client of Project V which supports VMess, VLESS, SS, SSR, Trojan, Tuic and Juicity protocols" + }, + "description": { + "en_US": "v2rayA is a V2Ray client supporting global transparent proxy, compatible with SS, SSR, Trojan (trojan-go), Tuic, and Juicity protocols. Designed for simplicity, it meets most user needs, ideal for scenarios requiring efficient proxy services.\n\nCore features include global transparent proxy and multi-outbound load balancing with traffic splitting. It provides proxy services for nearly all applications without requiring application-specific proxy support. Support for creating and connecting multiple outbound nodes ensures load balancing and efficient traffic splitting for optimal network performance.\n\nIt offers RoutingA, a custom routing language for V2Ray, providing powerful and convenient traffic splitting support. Multiple strategies address DNS pollution, with advanced settings enabling customized configurations. With simplicity and functionality at the core, the platform delivers a modern solution for proxy management.\n\n**Key Features:**\n- Web-based GUI for easy configuration and management\n- Support for multiple protocols: VMess, VLESS, SS, SSR, Trojan, Tuic, Juicity\n- Global transparent proxy for seamless application proxy services\n- Multi-outbound load balancing and traffic splitting\n- RoutingA custom routing for convenient traffic splitting\n- Multiple DNS pollution mitigation strategies with advanced custom settings\n\n**Learn More:**\n- [V2rayA Official Website](https://v2raya.org/)\n- [V2rayA GitHub](https://github.com/v2rayA/v2rayA)\n" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "v2rayA", + "developer": "v2rayA", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 2017, + "path": "/" + }, + "website": "https://v2raya.org/", + "documentation": null, + "repository": "https://hub.docker.com/r/mzz2017/v2raya", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "mzz2017", + "repository": "https://hub.docker.com/r/mzz2017/v2raya", + "revision": "419e614c41c82a21644a201dd0db4b5eaa5d39fa63a79f40b330e2bad8566787", + "image_repository_url": "https://hub.docker.com/r/mzz2017/v2raya", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "419e614c41c82a21644a201dd0db4b5eaa5d39fa63a79f40b330e2bad8566787", + "generated_at": "2026-09-13T17:20:21+00:00" + }, + "container_contract": { + "service_name": "v2raya", + "container_name": "v2raya", + "image": { + "reference": "mzz2017/v2raya:latest", + "registry": "docker.io", + "repository": "mzz2017/v2raya", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/lib/modules", + "compose_source_example": "/lib/modules", + "read_only": true, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/etc/resolv.conf", + "compose_source_example": "/etc/resolv.conf", + "read_only": false, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/etc/v2raya", + "compose_source_example": "/DATA/AppData/$AppID", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: v2raya\nservices:\n v2raya:\n image: mzz2017/v2raya:latest\n container_name: v2raya\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n privileged: true\n network_mode: host\n volumes:\n - type: bind\n source: /lib/modules\n target: /lib/modules\n read_only: true\n - type: bind\n source: /etc/resolv.conf\n target: /etc/resolv.conf\n - type: bind\n source: /DATA/AppData/$AppID\n target: /etc/v2raya\n" + }, + "compose_stack": { + "project_name": "v2raya", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "v2raya", + "service_count": 1, + "services": [ + { + "name": "v2raya", + "image": "mzz2017/v2raya:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "mzz2017/v2raya:latest", + "container_name": "v2raya", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "restart": "unless-stopped", + "privileged": true, + "network_mode": "host", + "volumes": [ + { + "type": "bind", + "source": "/lib/modules", + "target": "/lib/modules", + "read_only": true + }, + { + "type": "bind", + "source": "/etc/resolv.conf", + "target": "/etc/resolv.conf" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID", + "target": "/etc/v2raya" + } + ] + } + } + ], + "top_level": { + "name": "v2raya" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "v2raya-volume-0", + "service": "v2raya", + "container_path": "/lib/modules", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "v2raya-volume-1", + "service": "v2raya", + "container_path": "/etc/resolv.conf", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "v2raya-volume-2", + "service": "v2raya", + "container_path": "/etc/v2raya", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "v2raya" + ], + "stop_order": [ + "v2raya" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 2017, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "host" + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": false, + "warning": "The source Compose requests privileged: true, but this does not prove that the image needs a privileged LXC. ProxMenux will use an unprivileged LXC by default and will offer the broad mode only as an option. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "optional-explicit-user-consent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/vaultwarden.json b/oci/catalog/apps/vaultwarden.json new file mode 100644 index 00000000..cc75c422 --- /dev/null +++ b/oci/catalog/apps/vaultwarden.json @@ -0,0 +1,462 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-vaultwarden", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Vaultwarden" + }, + "tagline": { + "en_US": "A self-hosted Bitwarden server" + }, + "description": { + "en_US": "Alternative implementation of the Bitwarden server API written in Rust and compatible with upstream Bitwarden clients*, perfect for self-hosted deployment where running the official resource-heavy service might not be ideal." + }, + "category": "security", + "category_label": "Authentication & Security", + "author": "Daniel Garc\u00eda", + "developer": "Daniel Garc\u00eda", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 443, + "path": "/" + }, + "website": "https://vaultwarden.net", + "documentation": null, + "repository": "https://hub.docker.com/r/vaultwarden/server", + "tips": [ + "The Web Vault requires a secure context. ProxMenux enables Vaultwarden's native Rocket TLS listener on port 443.", + "A persistent self-signed certificate is generated under /data/tls. Browsers must trust or explicitly accept it; a trusted reverse proxy certificate can replace these files later." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/vaultwarden/server", + "revision": "6ef8cd9cd0f00712c9e8d6a2cd99de60feab19bce779cdf7ae9023a010537b81", + "image_repository_url": "https://hub.docker.com/r/vaultwarden/server", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "6ef8cd9cd0f00712c9e8d6a2cd99de60feab19bce779cdf7ae9023a010537b81", + "generated_at": "2026-09-14T15:00:43+00:00" + }, + "container_contract": { + "service_name": "vaultwarden", + "container_name": "vaultwarden", + "image": { + "reference": "vaultwarden/server:latest", + "registry": "docker.io", + "repository": "vaultwarden/server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ROCKET_PORT", + "example": "443", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "vaultwarden-rocket-tls" + }, + { + "name": "ROCKET_TLS", + "example": "{certs=\"/data/tls/vaultwarden.crt\",key=\"/data/tls/vaultwarden.key\"}", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "vaultwarden-rocket-tls" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: vaultwarden\nservices:\n vaultwarden:\n image: vaultwarden/server:latest\n deploy:\n resources:\n reservations:\n memory: 256M\n network_mode: bridge\n ports:\n - target: 80\n published: '10380'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n container_name: vaultwarden\n" + }, + "compose_stack": { + "project_name": "vaultwarden", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "vaultwarden", + "service_count": 1, + "services": [ + { + "name": "vaultwarden", + "image": "vaultwarden/server:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "vaultwarden/server:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 80, + "published": "10380", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/data" + } + ], + "container_name": "vaultwarden" + } + } + ], + "top_level": { + "name": "vaultwarden" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "vaultwarden-volume-0", + "service": "vaultwarden", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for vaultwarden:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "vaultwarden" + ], + "stop_order": [ + "vaultwarden" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Vaultwarden Web Vault", + "scheme": "https", + "port": 443, + "path": "/", + "source": "vaultwarden-native-rocket-tls" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "self_signed_tls": { + "certificate_path": "/data/tls/vaultwarden.crt", + "private_key_path": "/data/tls/vaultwarden.key", + "common_name_from": "deployment-hostname", + "valid_days": 3650, + "preserve_existing": true + }, + "startup_healthcheck": { + "scheme": "https", + "port": 443, + "path": "/alive", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/virt-manager.json b/oci/catalog/apps/virt-manager.json new file mode 100644 index 00000000..762ee6f4 --- /dev/null +++ b/oci/catalog/apps/virt-manager.json @@ -0,0 +1,499 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-virt-manager", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Virtual Machine Manager" + }, + "tagline": { + "en_US": "A GTK Broadway web UI for libvirt and virt-manager." + }, + "description": { + "en_US": "A GTK Broadway web UI for libvirt and virt-manager, to run virtual machines using QEMU/KVM." + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Red Hat", + "developer": "Red Hat", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://virt-manager.org", + "documentation": null, + "repository": "https://hub.docker.com/r/mber5/virt-manager", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "mber5", + "repository": "https://hub.docker.com/r/mber5/virt-manager", + "revision": "98624fe99aa26c3cebcfa11192aa4a0fe1356e4f8420a6c93117c9c6aae0c979", + "image_repository_url": "https://hub.docker.com/r/mber5/virt-manager", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "98624fe99aa26c3cebcfa11192aa4a0fe1356e4f8420a6c93117c9c6aae0c979", + "generated_at": "2026-09-13T15:35:04+00:00" + }, + "container_contract": { + "service_name": "virt-manager", + "container_name": "virt-manager", + "image": { + "reference": "mber5/virt-manager:latest", + "registry": "docker.io", + "repository": "mber5/virt-manager", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "DARK_MODE", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "HOSTS", + "example": "['qemu:///system']", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/run/libvirt/libvirt-sock", + "compose_source_example": "/var/run/libvirt/libvirt-sock", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/var/lib/libvirt", + "compose_source_example": "/var/lib/libvirt", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/DATA/Downloads", + "compose_source_example": "/DATA/Downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 8185, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: virt-manager\nservices:\n virt-manager:\n restart: always\n devices:\n - /dev/kvm:/dev/kvm\n environment:\n DARK_MODE: 'false'\n HOSTS: '[''qemu:///system'']'\n image: mber5/virt-manager:latest\n network_mode: bridge\n ports:\n - target: 80\n published: '8185'\n protocol: tcp\n volumes:\n - type: bind\n source: /var/run/libvirt/libvirt-sock\n target: /var/run/libvirt/libvirt-sock\n - type: bind\n source: /var/lib/libvirt\n target: /var/lib/libvirt\n - type: bind\n source: /DATA/Downloads\n target: /DATA/Downloads\n container_name: virt-manager\n" + }, + "compose_stack": { + "project_name": "virt-manager", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "virt-manager", + "service_count": 1, + "services": [ + { + "name": "virt-manager", + "image": "mber5/virt-manager:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "restart": "always", + "devices": [ + "/dev/kvm:/dev/kvm" + ], + "environment": { + "DARK_MODE": "false", + "HOSTS": "['qemu:///system']" + }, + "image": "mber5/virt-manager:latest", + "network_mode": "bridge", + "ports": [ + { + "target": 80, + "published": "8185", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/var/run/libvirt/libvirt-sock", + "target": "/var/run/libvirt/libvirt-sock" + }, + { + "type": "bind", + "source": "/var/lib/libvirt", + "target": "/var/lib/libvirt" + }, + { + "type": "bind", + "source": "/DATA/Downloads", + "target": "/DATA/Downloads" + } + ], + "container_name": "virt-manager" + } + } + ], + "top_level": { + "name": "virt-manager" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "virt-manager-volume-0", + "service": "virt-manager", + "container_path": "/var/run/libvirt/libvirt-sock", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "virt-manager-volume-1", + "service": "virt-manager", + "container_path": "/var/lib/libvirt", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "virt-manager-volume-2", + "service": "virt-manager", + "container_path": "/DATA/Downloads", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for virt-manager:/DATA/Downloads" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "virt-manager" + ], + "stop_order": [ + "virt-manager" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "device_requests": [ + { + "id": "dev-kvm", + "kind": "character-device", + "purpose": "kvm", + "enable_prompt": "Pass /dev/kvm to the LXC", + "enabled_default": true, + "required_by_compose": true, + "path_prompt": "Host device for /dev/kvm", + "host_path_default": "/dev/kvm", + "container_path": "/dev/kvm", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/kvm:/dev/kvm" + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/vivaldi.json b/oci/catalog/apps/vivaldi.json new file mode 100644 index 00000000..9d6b6424 --- /dev/null +++ b/oci/catalog/apps/vivaldi.json @@ -0,0 +1,272 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-vivaldi", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Vivaldi" + }, + "tagline": { + "en_US": "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies." + }, + "description": { + "en_US": "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vivaldi-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vivaldi-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://vivaldi.com/", + "documentation": "https://docs.linuxserver.io/images/docker-vivaldi/", + "repository": "https://github.com/linuxserver/docker-vivaldi", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-06", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-vivaldi", + "default_branch": "master", + "revision": "5b93515ab0e6c7e4d8516c3113efbb012e109cb6", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-vivaldi/5b93515ab0e6c7e4d8516c3113efbb012e109cb6/README.md", + "readme_pushed_at": "2026-09-12T05:43:20Z", + "compose_sha256": "5e53fdb8a67cce396867611e6696e73328f3fc0a23ed087935ead40a140e30e9", + "generated_at": "2026-09-12T14:37:38+00:00" + }, + "container_contract": { + "service_name": "vivaldi", + "container_name": "vivaldi", + "image": { + "reference": "lscr.io/linuxserver/vivaldi:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/vivaldi", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "VIVALDI_CLI", + "example": "https://www.linuxserver.io/", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/vivaldi/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n vivaldi:\n image: lscr.io/linuxserver/vivaldi:latest\n container_name: vivaldi\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - VIVALDI_CLI=https://www.linuxserver.io/ #optional\n volumes:\n - /path/to/vivaldi/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/vlc.json b/oci/catalog/apps/vlc.json new file mode 100644 index 00000000..bb87bc92 --- /dev/null +++ b/oci/catalog/apps/vlc.json @@ -0,0 +1,272 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-vlc", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Vlc" + }, + "tagline": { + "en_US": "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices." + }, + "description": { + "en_US": "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vlc-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vlc-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.videolan.org/vlc/", + "documentation": "https://docs.linuxserver.io/images/docker-vlc/", + "repository": "https://github.com/linuxserver/docker-vlc", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-30", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-12-01", + "note": "Initial Version." + } + ], + "display_version": null, + "updated_at": "2026-03-30" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-vlc", + "default_branch": "master", + "revision": "c6a04b8a2446fc586cee7ef3f5a97764c3e7f7c6", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-vlc/c6a04b8a2446fc586cee7ef3f5a97764c3e7f7c6/README.md", + "readme_pushed_at": "2026-09-08T17:57:39Z", + "compose_sha256": "f5c3d53db4099a5d631309d7fb48dc86832e3eb938526ebb37539cf79cded06d", + "generated_at": "2026-09-12T14:37:38+00:00" + }, + "container_contract": { + "service_name": "vlc", + "container_name": "vlc", + "image": { + "reference": "lscr.io/linuxserver/vlc:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/vlc", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "VLC_CLI", + "example": "--no-qt-minimal-view", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n vlc:\n image: lscr.io/linuxserver/vlc:latest\n container_name: vlc\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - VLC_CLI=--no-qt-minimal-view #optional\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/vocechat.json b/oci/catalog/apps/vocechat.json new file mode 100644 index 00000000..cc0a8dc9 --- /dev/null +++ b/oci/catalog/apps/vocechat.json @@ -0,0 +1,411 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-vocechat", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "VoceChat" + }, + "tagline": { + "en_US": "Have a Private Social Space Hosted on Your Site" + }, + "description": { + "en_US": "VoceChat is a secure chat software designed for independent deployment, offering a flexible solution for seamless communication. It combines instant messaging with channel-based group chats, allowing you to engage in one-on-one conversations or create themed channels for group discussions.\n\nVoceChat supports a variety of message formats, including text, images, files, emojis, and rich text (Markdown), making your communication vibrant and expressive. Once deployed, it can be accessed via a WebAPP or mobile APP, ensuring a consistent experience across platforms.\n\nWith robust management features, VoceChat enables easy member and channel administration, giving you full control over your team or group\u2019s communication environment. Whether for individual users or enterprise teams, VoceChat delivers a secure, versatile, and efficient chat solution.\n" + }, + "category": "communication", + "category_label": "Communication & Community", + "author": "Privoce", + "developer": "Privoce", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://voce.chat", + "documentation": null, + "repository": "https://hub.docker.com/r/privoce/vocechat-server", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "privoce", + "repository": "https://hub.docker.com/r/privoce/vocechat-server", + "revision": "de14b3b6035f147c9dbee9330de90cbee5f7816df0dbe853763b962ca6da5944", + "image_repository_url": "https://hub.docker.com/r/privoce/vocechat-server", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "de14b3b6035f147c9dbee9330de90cbee5f7816df0dbe853763b962ca6da5944", + "generated_at": "2026-09-13T15:35:04+00:00" + }, + "container_contract": { + "service_name": "vocechat", + "container_name": "vocechat", + "image": { + "reference": "privoce/vocechat-server:latest", + "registry": "docker.io", + "repository": "privoce/vocechat-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/home/vocechat-server/data", + "compose_source_example": "/DATA/AppData/$AppID/home/vocechat-server/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3009, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: vocechat\nservices:\n vocechat:\n environment:\n TZ: $TZ\n image: privoce/vocechat-server:latest\n deploy:\n resources:\n reservations:\n memory: 64M\n network_mode: bridge\n ports:\n - target: 3000\n published: '3009'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/home/vocechat-server/data\n target: /home/vocechat-server/data\n container_name: vocechat\n" + }, + "compose_stack": { + "project_name": "vocechat", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "vocechat", + "service_count": 1, + "services": [ + { + "name": "vocechat", + "image": "privoce/vocechat-server:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "environment": { + "TZ": "$TZ" + }, + "image": "privoce/vocechat-server:latest", + "deploy": { + "resources": { + "reservations": { + "memory": "64M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 3000, + "published": "3009", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/home/vocechat-server/data", + "target": "/home/vocechat-server/data" + } + ], + "container_name": "vocechat" + } + } + ], + "top_level": { + "name": "vocechat" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "vocechat-volume-0", + "service": "vocechat", + "container_path": "/home/vocechat-server/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "vocechat" + ], + "stop_order": [ + "vocechat" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/vscode.json b/oci/catalog/apps/vscode.json new file mode 100644 index 00000000..e5f8d889 --- /dev/null +++ b/oci/catalog/apps/vscode.json @@ -0,0 +1,368 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-vscode", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Vscode" + }, + "tagline": { + "en_US": "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server." + }, + "description": { + "en_US": "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscode-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscode-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://code.visualstudio.com/", + "documentation": "https://docs.linuxserver.io/images/docker-vscode/", + "repository": "https://github.com/linuxserver/docker-vscode", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-20", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-vscode", + "default_branch": "master", + "revision": "3ea9be962ff0129d8d58e1ae1fcbe8e8687cfa6f", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-vscode/3ea9be962ff0129d8d58e1ae1fcbe8e8687cfa6f/README.md", + "readme_pushed_at": "2026-09-08T18:36:38Z", + "compose_sha256": "1ca9d612229816c394a35916c54bfdeaefc1ac5f3d0b1986d82cd6b74a87b271", + "generated_at": "2026-09-13T15:47:54+00:00" + }, + "container_contract": { + "service_name": "vscode", + "container_name": "vscode", + "image": { + "reference": "lscr.io/linuxserver/vscode:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/vscode", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/vscode/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n vscode:\n image: lscr.io/linuxserver/vscode:latest\n container_name: vscode\n cap_add:\n - IPC_LOCK\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/vscode/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ], + "security": { + "required_capabilities": [ + "IPC_LOCK" + ] + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/vscodium-web.json b/oci/catalog/apps/vscodium-web.json new file mode 100644 index 00000000..e126f54f --- /dev/null +++ b/oci/catalog/apps/vscodium-web.json @@ -0,0 +1,268 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-vscodium-web", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Vscodium Web" + }, + "tagline": { + "en_US": "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code." + }, + "description": { + "en_US": "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscodium-web-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscodium-web-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://vscodium.com/", + "documentation": "https://docs.linuxserver.io/images/docker-vscodium-web/", + "repository": "https://github.com/linuxserver/docker-vscodium-web", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-24", + "note": "Temporarily disable RISCV build due to ci issues." + }, + { + "date": "2026-02-28", + "note": "Add RISCV build." + }, + { + "date": "2025-12-18", + "note": "Initial Release." + } + ], + "display_version": null, + "updated_at": "2026-06-24" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-vscodium-web", + "default_branch": "main", + "revision": "2aa5b5f6a33a737b4b92bda6f1daaf7262c52fcc", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-vscodium-web/2aa5b5f6a33a737b4b92bda6f1daaf7262c52fcc/README.md", + "readme_pushed_at": "2026-09-09T12:15:12Z", + "compose_sha256": "a18caa55d44f59b2a6534c3d154968d8a0ab3b9ded29aa713c30633fa60b91cd", + "generated_at": "2026-09-12T14:37:38+00:00" + }, + "container_contract": { + "service_name": "vscodium-web", + "container_name": "vscodium-web", + "image": { + "reference": "lscr.io/linuxserver/vscodium-web:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/vscodium-web", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CONNECTION_TOKEN", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "CONNECTION_TOKEN_FILE", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SUDO_PASSWORD", + "example": "password", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SUDO_PASSWORD_HASH", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "CODE_ARGS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/vscodium-web/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n vscodium-web:\n image: lscr.io/linuxserver/vscodium-web:latest\n container_name: vscodium-web\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - CONNECTION_TOKEN= #optional\n - CONNECTION_TOKEN_FILE= #optional\n - SUDO_PASSWORD=password #optional\n - SUDO_PASSWORD_HASH= #optional\n - CODE_ARGS= #optional\n volumes:\n - /path/to/vscodium-web/config:/config\n ports:\n - 8000:8000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/vscodium.json b/oci/catalog/apps/vscodium.json new file mode 100644 index 00000000..a40a8306 --- /dev/null +++ b/oci/catalog/apps/vscodium.json @@ -0,0 +1,380 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-vscodium", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Vscodium" + }, + "tagline": { + "en_US": "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft\u2019s editor VS Code." + }, + "description": { + "en_US": "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft\u2019s editor VS Code." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscodium-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscodium-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://vscodium.com/", + "documentation": "https://docs.linuxserver.io/images/docker-vscodium/", + "repository": "https://github.com/linuxserver/docker-vscodium", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-24", + "note": "Swap from thunar to caja for filebrowser." + } + ], + "display_version": null, + "updated_at": "2026-04-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-vscodium", + "default_branch": "master", + "revision": "6e2fddb9f6af906aa0516173a4b6acdb641f0256", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-vscodium/6e2fddb9f6af906aa0516173a4b6acdb641f0256/README.md", + "readme_pushed_at": "2026-09-09T10:34:25Z", + "compose_sha256": "89cc1c193cb4f53936b958af93e17055235da70cff10dbe1d75b735bfeb85e1d", + "generated_at": "2026-09-13T15:47:55+00:00" + }, + "container_contract": { + "service_name": "vscodium", + "container_name": "vscodium", + "image": { + "reference": "lscr.io/linuxserver/vscodium:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/vscodium", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/vscodium/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n vscodium:\n image: lscr.io/linuxserver/vscodium:latest\n container_name: vscodium\n cap_add:\n - IPC_LOCK\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/vscodium/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ], + "security": { + "required_capabilities": [ + "IPC_LOCK" + ] + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/wallabag.json b/oci/catalog/apps/wallabag.json new file mode 100644 index 00000000..4a9c3dbc --- /dev/null +++ b/oci/catalog/apps/wallabag.json @@ -0,0 +1,446 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-wallabag", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Wallabag" + }, + "tagline": { + "en_US": "Save and classify articles. Read them later. Freely." + }, + "description": { + "en_US": "Wallabag is a web page saving app that allows users to save articles for offline reading, extracting content for a distraction-free experience. Its intuitive Web interface enables saving articles with a click, ensuring users can read them at their convenience.\n\nThe app's core features include convenient web page saving, optimized reading, and flexible content organization. It extracts only the article's content, removing pop-ups and ads, and displays it in a clean, comfortable view. Users can organize saved articles with tags and automatic tagging rules, creating a personalized content library accessible on demand. Browser extensions enable quick saving, compatible with Chrome, Firefox, Opera, and more. Cross-platform clients cover Android, iOS, and other devices, ensuring a seamless reading experience. It also supports multi-user collaboration for sharing saved articles.\n\nIt enables importing data from services like Pocket, Readability, Instapaper, or Pinboard, simplifying content library migration. RSS generation allows users to access saved articles in RSS readers. Community documentation enhances usability, and the app's high flexibility and intuitive operation deliver a modern web content management solution.\n\n**Key Features:**\n- Save web pages for offline reading\n- Extract pure content for a distraction-free reading view\n- Article classification with automatic tagging rules for a personalized content library\n- Browser extensions for quick web page saving\n- Cross-platform clients (Android, iOS, Chrome, Firefox, Opera)\n- Multi-user collaboration for sharing saved articles\n- Import data from Pocket, Readability, Instapaper, Pinboard and other services\n- RSS generation for accessing saved articles in readers\n\n**Learn More:**\n- [Wallabag Official Website](https://wallabag.org)\n- [Wallabag GitHub Repository](https://github.com/wallabag/wallabag)\n- [Wallabag Documentation](https://doc.wallabag.org)\n- [Wallabag Docker Image](https://hub.docker.com/r/wallabag/wallabag)\n" + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "wallabag", + "developer": "wallabag", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://wallabag.org", + "documentation": null, + "repository": "https://hub.docker.com/r/wallabag/wallabag", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://hub.docker.com/r/wallabag/wallabag", + "revision": "a7e086cf45962f635b92bc1d0906d61df1d03cb6ff2bc626173038a3a0b7ab69", + "image_repository_url": "https://hub.docker.com/r/wallabag/wallabag", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "a7e086cf45962f635b92bc1d0906d61df1d03cb6ff2bc626173038a3a0b7ab69", + "generated_at": "2026-09-13T15:35:04+00:00" + }, + "container_contract": { + "service_name": "wallabag", + "container_name": "wallabag", + "image": { + "reference": "wallabag/wallabag:latest", + "registry": "docker.io", + "repository": "wallabag/wallabag", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "SYMFONY__ENV__DOMAIN_NAME", + "example": "http://:25661", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SYMFONY__ENV__SERVER_NAME", + "example": "Wallabag", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/www/wallabag/web/assets/images", + "compose_source_example": "/DATA/AppData/$AppID/images", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 25661, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: wallabag\nservices:\n wallabag:\n image: wallabag/wallabag:latest\n container_name: wallabag\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 80\n published: '25661'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/images\n target: /var/www/wallabag/web/assets/images\n environment:\n SYMFONY__ENV__DOMAIN_NAME: http://:25661\n SYMFONY__ENV__SERVER_NAME: Wallabag\n healthcheck:\n test:\n - CMD\n - wget\n - --no-verbose\n - --tries=1\n - --spider\n - http://localhost/api/info\n interval: 1m\n timeout: 3s\n" + }, + "compose_stack": { + "project_name": "wallabag", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "wallabag", + "service_count": 1, + "services": [ + { + "name": "wallabag", + "image": "wallabag/wallabag:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "wallabag/wallabag:latest", + "container_name": "wallabag", + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 80, + "published": "25661", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/images", + "target": "/var/www/wallabag/web/assets/images" + } + ], + "environment": { + "SYMFONY__ENV__DOMAIN_NAME": "http://:25661", + "SYMFONY__ENV__SERVER_NAME": "Wallabag" + }, + "healthcheck": { + "test": [ + "CMD", + "wget", + "--no-verbose", + "--tries=1", + "--spider", + "http://localhost/api/info" + ], + "interval": "1m", + "timeout": "3s" + } + } + } + ], + "top_level": { + "name": "wallabag" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "wallabag-volume-0", + "service": "wallabag", + "container_path": "/var/www/wallabag/web/assets/images", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "wallabag" + ], + "stop_order": [ + "wallabag" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "startup_healthcheck": { + "type": "http", + "scheme": "http", + "port": 80, + "path": "/api/info", + "timeout_seconds": 180, + "request_timeout_seconds": 3, + "stability_seconds": 0, + "verify_tls": true, + "required": true, + "source": "compose-healthcheck" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "pending-per-application" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/webcord.json b/oci/catalog/apps/webcord.json new file mode 100644 index 00000000..e05c3b61 --- /dev/null +++ b/oci/catalog/apps/webcord.json @@ -0,0 +1,373 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-webcord", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Webcord" + }, + "tagline": { + "en_US": "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes)." + }, + "description": { + "en_US": "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes)." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webcord-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webcord-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/SpacingBat3/WebCord", + "documentation": "https://docs.linuxserver.io/images/docker-webcord/", + "repository": "https://github.com/linuxserver/docker-webcord", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-10", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Switch to Selkies base image, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-04-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-webcord", + "default_branch": "master", + "revision": "01c2cbee59ea482cd8a5c53a886ef75fdbe27e33", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-webcord/01c2cbee59ea482cd8a5c53a886ef75fdbe27e33/README.md", + "readme_pushed_at": "2026-09-10T09:27:57Z", + "compose_sha256": "fdf51721be21a8ff3e7bc4537e34a96efb5cf20ee930e8bc014913de5a817085", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "webcord", + "container_name": "webcord", + "image": { + "reference": "lscr.io/linuxserver/webcord:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/webcord", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n webcord:\n image: lscr.io/linuxserver/webcord:latest\n container_name: webcord\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-webcord/master/Dockerfile", + "dockerfile_sha256": "8af90f5928c6de1e2d89f96ca11cb1cfa1c09aa724c887e7f4767b90e64195f6", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/webdav.json b/oci/catalog/apps/webdav.json new file mode 100644 index 00000000..24c7f8c0 --- /dev/null +++ b/oci/catalog/apps/webdav.json @@ -0,0 +1,466 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-webdav", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "WebDAV" + }, + "tagline": { + "en_US": "A web-based file sharing and management protocol" + }, + "description": { + "en_US": "WebDAV is a web-based protocol that allows you to share and manage files over the internet, providing a collaborative environment for file editing and versioning." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Team", + "developer": "Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://hub.docker.com/r/ugeek/webdav", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "ugeek", + "repository": "https://hub.docker.com/r/ugeek/webdav", + "revision": "7b8c2b86aa4ab103724df422d3d5f8c268dccd11295c07a99d400c6303caf892", + "image_repository_url": "https://hub.docker.com/r/ugeek/webdav", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "7b8c2b86aa4ab103724df422d3d5f8c268dccd11295c07a99d400c6303caf892", + "generated_at": "2026-09-13T15:35:04+00:00" + }, + "container_contract": { + "service_name": "webdav", + "container_name": "webdav", + "image": { + "reference": "ugeek/webdav:latest", + "registry": "docker.io", + "repository": "ugeek/webdav", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "GID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PASSWORD", + "example": "${GENERATED_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "UDI", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "USERNAME", + "example": "webdav", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/media", + "compose_source_example": "/media/webdav-HD/Media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 5005, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: webdav\nservices:\n webdav:\n cpu_shares: 90\n command: []\n container_name: webdav\n deploy:\n resources:\n limits:\n memory: 15806M\n environment:\n - GID=1000\n - PASSWORD=${GENERATED_PASSWORD}\n - TZ=Europe/Madrid\n - UDI=1000\n - USERNAME=webdav\n image: ugeek/webdav:latest\n ports:\n - target: 80\n published: '5005'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /media/webdav-HD/Media\n target: /media\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "webdav", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "webdav", + "service_count": 1, + "services": [ + { + "name": "webdav", + "image": "ugeek/webdav:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "cpu_shares": 90, + "command": [], + "container_name": "webdav", + "deploy": { + "resources": { + "limits": { + "memory": "15806M" + } + } + }, + "environment": [ + "GID=1000", + "PASSWORD=${GENERATED_PASSWORD}", + "TZ=Europe/Madrid", + "UDI=1000", + "USERNAME=webdav" + ], + "image": "ugeek/webdav:latest", + "ports": [ + { + "target": 80, + "published": "5005", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "volumes": [ + { + "type": "bind", + "source": "/media/webdav-HD/Media", + "target": "/media" + } + ], + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "webdav" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "webdav-volume-0", + "service": "webdav", + "container_path": "/media", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for webdav:/media" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "webdav" + ], + "stop_order": [ + "webdav" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "webdav", + "environment_variable": "PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "command": [] + }, + "resources": { + "cpu_shares": 90 + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/webgrabplus.json b/oci/catalog/apps/webgrabplus.json new file mode 100644 index 00000000..933b6009 --- /dev/null +++ b/oci/catalog/apps/webgrabplus.json @@ -0,0 +1,319 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-webgrabplus", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Webgrabplus" + }, + "tagline": { + "en_US": "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels." + }, + "description": { + "en_US": "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webgrabplus-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webgrabplus-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://www.webgrabplus.com", + "documentation": "https://docs.linuxserver.io/images/docker-webgrabplus/", + "repository": "https://github.com/linuxserver/docker-webgrabplus", + "tips": [], + "mini_changelog": [ + { + "date": "2025-09-14", + "note": "Rebase to Alpine 3.22, upgrade dotnet to 9.0." + }, + { + "date": "2024-06-25", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-25", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-04-23", + "note": "Bump dotnet framework to 8.x." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + } + ], + "display_version": null, + "updated_at": "2025-09-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-webgrabplus", + "default_branch": "master", + "revision": "6ed5c7bed77a57ba29fc158a21f9201f4717ee9d", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-webgrabplus/6ed5c7bed77a57ba29fc158a21f9201f4717ee9d/README.md", + "readme_pushed_at": "2026-09-10T15:25:37Z", + "compose_sha256": "fd329f1ecf2f52a8dba24e0d53fe153f9f0e7a36b8a4e12bfd3629b544d9750e", + "generated_at": "2026-09-13T14:54:04+00:00" + }, + "container_contract": { + "service_name": "webgrabplus", + "container_name": "webgrabplus", + "image": { + "reference": "lscr.io/linuxserver/webgrabplus:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/webgrabplus", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/webgrabplus/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n webgrabplus:\n image: lscr.io/linuxserver/webgrabplus:latest\n container_name: webgrabplus\n hostname: webgrabplus\n mac_address: 00:00:00:00:00:00\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/webgrabplus/config:/config\n - /path/to/data:/data\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "hostname": "webgrabplus" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "labels", + "logging", + "mac_address", + "networks", + "ports", + "privileged", + "restart", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/webstation.json b/oci/catalog/apps/webstation.json new file mode 100644 index 00000000..df719925 --- /dev/null +++ b/oci/catalog/apps/webstation.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-webstation", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Webstation" + }, + "tagline": { + "en_US": "Webstation is a web native emulation focused LXQt desktop based on Ubuntu." + }, + "description": { + "en_US": "Webstation is a web native emulation focused LXQt desktop based on Ubuntu." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webstation-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webstation-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/linuxserver/docker-webstation", + "documentation": "https://docs.linuxserver.io/images/docker-webstation/", + "repository": "https://github.com/linuxserver/docker-webstation", + "tips": [], + "mini_changelog": [ + { + "date": "2026-08-21", + "note": "Add Xenia Edge emulator." + }, + { + "date": "2026-08-13", + "note": "Add Azahar emulator." + }, + { + "date": "2026-08-10", + "note": "Add Cemu emulator." + }, + { + "date": "2026-05-05", + "note": "Rebase to resolute." + }, + { + "date": "2026-03-28", + "note": "Swap UI to baked in selkies-desktop." + } + ], + "display_version": null, + "updated_at": "2026-08-21" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-webstation", + "default_branch": "master", + "revision": "414f57bfd8ceb343ac47414e8df2984bc76062dc", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-webstation/414f57bfd8ceb343ac47414e8df2984bc76062dc/README.md", + "readme_pushed_at": "2026-09-06T10:53:47Z", + "compose_sha256": "240739c3be17a98702a0487cee80620e62771545de9b20a6cab20a1951b444b0", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "webstation", + "container_name": "webstation", + "image": { + "reference": "lscr.io/linuxserver/webstation:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/webstation", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n webstation:\n image: lscr.io/linuxserver/webstation:latest\n container_name: webstation\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute AS dolphin", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-webstation/master/Dockerfile", + "dockerfile_sha256": "9785b95c2d38764864f9c11d4c8e79e8fad65cd246196f310d3cbdaed3834b80", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/webtop.json b/oci/catalog/apps/webtop.json new file mode 100644 index 00000000..75754f9f --- /dev/null +++ b/oci/catalog/apps/webtop.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-webtop", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Webtop" + }, + "tagline": { + "en_US": "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser." + }, + "description": { + "en_US": "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webtop-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webtop-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://github.com/linuxserver/docker-webtop", + "documentation": "https://docs.linuxserver.io/images/docker-webtop/", + "repository": "https://github.com/linuxserver/docker-webtop", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase Alpine images to 3.24." + }, + { + "date": "2026-05-07", + "note": "Deprecate Enterprise Linux tags." + }, + { + "date": "2026-04-07", + "note": "Rebase Ubuntu images to Resolute." + }, + { + "date": "2026-03-26", + "note": "Rebase Fedora images to 44." + }, + { + "date": "2026-03-24", + "note": "Update tags that support Wayland to pass ozone platform for chromium." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-webtop", + "default_branch": "master", + "revision": "1b47585460083f94d571659c7361d50e1b9d1d01", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-webtop/1b47585460083f94d571659c7361d50e1b9d1d01/README.md", + "readme_pushed_at": "2026-09-10T23:50:56Z", + "compose_sha256": "99ff5e1a9b0553d4102a151656ca81a85894bdb69f1d96ab0cb2acd4ac941770", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "webtop", + "container_name": "webtop", + "image": { + "reference": "lscr.io/linuxserver/webtop:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/webtop", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n webtop:\n image: lscr.io/linuxserver/webtop:latest\n container_name: webtop\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/data:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/weixin.json b/oci/catalog/apps/weixin.json new file mode 100644 index 00000000..77e09602 --- /dev/null +++ b/oci/catalog/apps/weixin.json @@ -0,0 +1,269 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-weixin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Weixin" + }, + "tagline": { + "en_US": "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent." + }, + "description": { + "en_US": "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/weixin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/weixin-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://weixin.qq.com/", + "documentation": "https://docs.linuxserver.io/images/docker-weixin/", + "repository": "https://github.com/linuxserver/docker-weixin", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-29", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-08", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-29" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-weixin", + "default_branch": "master", + "revision": "52b0b3dc0e99d54dc010fecad9c31a5e8aae985c", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-weixin/52b0b3dc0e99d54dc010fecad9c31a5e8aae985c/README.md", + "readme_pushed_at": "2026-09-06T15:35:58Z", + "compose_sha256": "d6be1667a3964871ca1c4bbc8d86dc6379e9180ad4e14a12fa8950f0324b723b", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "weixin", + "container_name": "weixin", + "image": { + "reference": "lscr.io/linuxserver/weixin:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/weixin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/weixin/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n weixin:\n image: lscr.io/linuxserver/weixin:latest\n container_name: weixin\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/weixin/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/weknora.json b/oci/catalog/apps/weknora.json new file mode 100644 index 00000000..48a2e85a --- /dev/null +++ b/oci/catalog/apps/weknora.json @@ -0,0 +1,1124 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-weknora", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "WeKnora" + }, + "tagline": { + "en_US": "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents." + }, + "description": { + "en_US": "WeKnora is a deep document understanding and semantic retrieval framework based on Large Language Models (LLM), specifically designed for document scenarios with complex structures and heterogeneous content. It adopts a modular architecture, integrating key technologies such as multimodal preprocessing, semantic vector indexing, intelligent retrieval, and large model inference. Based on the Retrieval-Augmented Generation (RAG) paradigm, it achieves context-aware, high-quality Q&A capabilities. WeKnora can deeply understand document content in different formats, combine relevant document fragments with language model inference, and output accurate, coherent semantic results.\n\n**Key Features:**\n- Multimodal Deep Parsing: Supports structured content extraction from various formats such as PDF, Word, TXT, images, including OCR image text recognition.\n- Semantic Vector Indexing and Intelligent Retrieval: Achieves high-precision semantic matching and recall through a combination of vector retrieval, keyword retrieval, and even knowledge graph-enhanced retrieval.\n- RAG Closed-Loop Q&A Generation: Generates accurate and coherent content answers by leveraging large language model inference and retrieval fragment fusion.\n- Agent Mode Enhanced Capabilities: Supports ReACT Agent mode, which can call built-in tools, external web search, etc., during multi-round iterations, to improve complex task processing capabilities.\n- Multi-type Knowledge Base Management: Can create FAQ and document-type knowledge bases, and flexibly manage tags, batch import files or URLs.\n- Configurable Dialogue Strategy and UI: Provides an intuitive Web interface and REST API, allowing online adjustment of models, retrieval thresholds, and Prompt to control dialogue behavior.\n\n**Learn More:**\n- [Official Website](https://weknora.weixin.qq.com)\n- [GitHub Link](https://github.com/Tencent/WeKnora)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Tencent", + "developer": "Tencent", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://weknora.weixin.qq.com", + "documentation": null, + "repository": "https://hub.docker.com/r/wechatopenai/weknora-ui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "wechatopenai", + "repository": "https://hub.docker.com/r/wechatopenai/weknora-ui", + "revision": "81f6e87d7c0bb716b9f019183ac34e4bff46599d904f6e81935e469145afc435", + "image_repository_url": "https://hub.docker.com/r/wechatopenai/weknora-ui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "81f6e87d7c0bb716b9f019183ac34e4bff46599d904f6e81935e469145afc435", + "generated_at": "2026-09-13T15:48:37+00:00" + }, + "container_contract": { + "service_name": "weknora", + "container_name": "weknora", + "image": { + "reference": "wechatopenai/weknora-ui:latest", + "registry": "docker.io", + "repository": "wechatopenai/weknora-ui", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "MAX_FILE_SIZE_MB", + "example": "50", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 80, + "published_example": 1080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "app", + "image": "wechatopenai/weknora-app:latest" + }, + { + "name": "weknora-docreader", + "image": "wechatopenai/weknora-docreader:latest" + }, + { + "name": "weknora-postgres", + "image": "paradedb/paradedb:latest" + }, + { + "name": "weknora-redis", + "image": "redis:latest" + }, + { + "name": "minio", + "image": "minio/minio:latest" + }, + { + "name": "jaeger", + "image": "jaegertracing/all-in-one:latest" + }, + { + "name": "neo4j", + "image": "neo4j:latest" + }, + { + "name": "qdrant", + "image": "qdrant/qdrant:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: weknora\nservices:\n weknora:\n image: wechatopenai/weknora-ui:latest\n container_name: weknora\n ports:\n - target: 80\n published: '1080'\n protocol: tcp\n environment:\n - MAX_FILE_SIZE_MB=50\n depends_on:\n app:\n condition: service_healthy\n networks:\n - weknora-network\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 128M\n app:\n image: wechatopenai/weknora-app:latest\n container_name: weknora-app\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/files\n target: /data/files\n deploy:\n resources:\n reservations:\n memory: 512M\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8080/health\n interval: 30s\n timeout: 10s\n retries: 3\n start_period: 60s\n environment:\n - OTEL_EXPORTER_OTLP_ENDPOINT=jaeger:4317\n - OTEL_SERVICE_NAME=WeKnora\n - OTEL_TRACES_EXPORTER=otlp\n - OTEL_METRICS_EXPORTER=none\n - OTEL_LOGS_EXPORTER=none\n - OTEL_PROPAGATORS=tracecontext,baggage\n - QDRANT_HOST=qdrant\n - QDRANT_PORT=6334\n - QDRANT_COLLECTION=weknora_embeddings\n - QDRANT_API_KEY=${GENERATED_QDRANT_API_KEY}\n - QDRANT_USE_TLS=false\n - MINIO_ENDPOINT=minio:9000\n - MINIO_ACCESS_KEY_ID=${GENERATED_MINIO_ACCESS_KEY_ID}\n - MINIO_SECRET_ACCESS_KEY=${GENERATED_MINIO_SECRET_ACCESS_KEY}\n - MINIO_BUCKET_NAME=weknora\n - GIN_MODE=release\n - DISABLE_REGISTRATION=false\n - DB_DRIVER=postgres\n - DB_HOST=weknora-postgres\n - DB_PORT=5432\n - DB_USER=postgres\n - DB_PASSWORD=${GENERATED_DB_PASSWORD}\n - DB_NAME=WeKnora\n - TZ=$TZ\n - RETRIEVE_DRIVER=postgres\n - DOCREADER_ADDR=weknora-docreader:50051\n - STORAGE_TYPE=minio\n - LOCAL_STORAGE_BASE_DIR=/data/files\n - AUTO_RECOVER_DIRTY=true\n - OLLAMA_BASE_URL=http://host.docker.internal:11434\n - STREAM_MANAGER_TYPE=redis\n - REDIS_ADDR=weknora-redis:6379\n - REDIS_PASSWORD=${GENERATED_REDIS_PASSWORD}\n - REDIS_DB=0\n - REDIS_PREFIX=\"stream:\"\n - TENANT_AES_KEY=${GENERATED_TENANT_AES_KEY}\n - CONCURRENCY_POOL_SIZE=5\n - JWT_SECRET=${GENERATED_JWT_SECRET}\n - MAX_FILE_SIZE_MB=50\n depends_on:\n weknora-redis:\n condition: service_started\n weknora-postgres:\n condition: service_healthy\n weknora-docreader:\n condition: service_healthy\n networks:\n - weknora-network\n restart: unless-stopped\n extra_hosts:\n - host.docker.internal:host-gateway\n weknora-docreader:\n image: wechatopenai/weknora-docreader:latest\n container_name: weknora-docreader\n environment:\n - MAX_FILE_SIZE_MB=50\n - MINIO_ENDPOINT=minio:9000\n - MINIO_ACCESS_KEY_ID=${GENERATED_MINIO_ACCESS_KEY_ID}\n - MINIO_SECRET_ACCESS_KEY=${GENERATED_MINIO_SECRET_ACCESS_KEY}\n - MINIO_BUCKET_NAME=weknora\n deploy:\n resources:\n reservations:\n memory: 256M\n healthcheck:\n test:\n - CMD\n - grpc_health_probe\n - -addr=:50051\n interval: 30s\n timeout: 10s\n retries: 3\n start_period: 60s\n networks:\n - weknora-network\n restart: unless-stopped\n extra_hosts:\n - host.docker.internal:host-gateway\n weknora-postgres:\n image: paradedb/paradedb:latest\n container_name: weknora-postgres\n environment:\n - POSTGRES_USER=postgres\n - POSTGRES_PASSWORD=${GENERATED_DB_PASSWORD}\n - POSTGRES_DB=WeKnora\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /var/lib/postgresql/data\n networks:\n - weknora-network\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U postgres\n interval: 10s\n timeout: 10s\n retries: 3\n start_period: 30s\n deploy:\n resources:\n reservations:\n memory: 512M\n restart: unless-stopped\n stop_grace_period: 1m\n weknora-redis:\n image: redis:latest\n container_name: weknora-redis\n command:\n - redis-server\n - --requirepass redis123!@#\n - --appendonly\n - true\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - weknora-network\n minio:\n image: minio/minio:latest\n container_name: weknora-minio\n ports:\n - target: 9000\n published: '19000'\n protocol: tcp\n - target: 9001\n published: '19001'\n protocol: tcp\n environment:\n - MINIO_ROOT_USER=minioadmin\n - MINIO_ROOT_PASSWORD=${GENERATED_MINIO_ROOT_PASSWORD}\n deploy:\n resources:\n reservations:\n memory: 512M\n command:\n - server\n - /data\n - --console-address\n - :9001\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/minio-data\n target: /data\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:9000/minio/health/live\n interval: 30s\n timeout: 20s\n retries: 3\n networks:\n - weknora-network\n restart: unless-stopped\n jaeger:\n image: jaegertracing/all-in-one:latest\n container_name: weknora-jaeger\n ports:\n - target: 6831\n published: '46831'\n protocol: udp\n - target: 6832\n published: '46832'\n protocol: udp\n - target: 5778\n published: '45778'\n protocol: tcp\n - target: 16686\n published: '16686'\n protocol: tcp\n - target: 4317\n published: '44317'\n protocol: tcp\n - target: 4318\n published: '44318'\n protocol: tcp\n - target: 14250\n published: '14250'\n protocol: tcp\n - target: 14268\n published: '14268'\n protocol: tcp\n - target: 9411\n published: '49411'\n protocol: tcp\n environment:\n - COLLECTOR_OTLP_ENABLED=true\n - COLLECTOR_ZIPKIN_HOST_PORT=:9411\n deploy:\n resources:\n reservations:\n memory: 512M\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/jaeger\n target: /var/lib/jaeger\n networks:\n - weknora-network\n restart: unless-stopped\n neo4j:\n image: neo4j:latest\n container_name: weknora-neo4j\n profiles:\n - neo4j\n - full\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/neo4j-data\n target: /data\n environment:\n - NEO4J_AUTH=neo4j/password\n - NEO4J_apoc_export_file_enabled=true\n - NEO4J_apoc_import_file_enabled=true\n - NEO4J_apoc_import_file_use__neo4j__config=true\n - NEO4JLABS_PLUGINS=[\"apoc\"]\n ports:\n - target: 7474\n published: '47474'\n protocol: tcp\n - target: 7687\n published: '47687'\n protocol: tcp\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 256M\n networks:\n - weknora-network\n qdrant:\n image: qdrant/qdrant:latest\n container_name: weknora-qdrant\n profiles:\n - qdrant\n - full\n ports:\n - target: 6333\n published: '46333'\n protocol: tcp\n - target: 6334\n published: '46334'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/storage\n target: /qdrant/storage\n networks:\n - weknora-network\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 256M\nnetworks:\n weknora-network:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "weknora", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "weknora", + "service_count": 9, + "services": [ + { + "name": "weknora-docreader", + "image": "wechatopenai/weknora-docreader:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "wechatopenai/weknora-docreader:latest", + "container_name": "weknora-docreader", + "environment": [ + "MAX_FILE_SIZE_MB=50", + "MINIO_ENDPOINT=minio:9000", + "MINIO_ACCESS_KEY_ID=${GENERATED_MINIO_ACCESS_KEY_ID}", + "MINIO_SECRET_ACCESS_KEY=${GENERATED_MINIO_SECRET_ACCESS_KEY}", + "MINIO_BUCKET_NAME=weknora" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "healthcheck": { + "test": [ + "CMD", + "grpc_health_probe", + "-addr=:50051" + ], + "interval": "30s", + "timeout": "10s", + "retries": 3, + "start_period": "60s" + }, + "networks": [ + "weknora-network" + ], + "restart": "unless-stopped", + "extra_hosts": [ + "host.docker.internal:host-gateway" + ] + } + }, + { + "name": "weknora-postgres", + "image": "paradedb/paradedb:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "paradedb/paradedb:latest", + "container_name": "weknora-postgres", + "environment": [ + "POSTGRES_USER=postgres", + "POSTGRES_PASSWORD=${GENERATED_DB_PASSWORD}", + "POSTGRES_DB=WeKnora" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/var/lib/postgresql/data" + } + ], + "networks": [ + "weknora-network" + ], + "healthcheck": { + "test": [ + "CMD-SHELL", + "pg_isready -U postgres" + ], + "interval": "10s", + "timeout": "10s", + "retries": 3, + "start_period": "30s" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "restart": "unless-stopped", + "stop_grace_period": "1m" + } + }, + { + "name": "weknora-redis", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "redis:latest", + "container_name": "weknora-redis", + "command": [ + "redis-server", + "--requirepass redis123!@#", + "--appendonly", + true + ], + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + }, + "restart": "unless-stopped", + "networks": [ + "weknora-network" + ] + } + }, + { + "name": "app", + "image": "wechatopenai/weknora-app:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 4, + "depends_on": [ + "weknora-docreader", + "weknora-postgres", + "weknora-redis" + ], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "wechatopenai/weknora-app:latest", + "container_name": "weknora-app", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/files", + "target": "/data/files" + } + ], + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "healthcheck": { + "test": [ + "CMD", + "curl", + "-f", + "http://localhost:8080/health" + ], + "interval": "30s", + "timeout": "10s", + "retries": 3, + "start_period": "60s" + }, + "environment": [ + "OTEL_EXPORTER_OTLP_ENDPOINT=jaeger:4317", + "OTEL_SERVICE_NAME=WeKnora", + "OTEL_TRACES_EXPORTER=otlp", + "OTEL_METRICS_EXPORTER=none", + "OTEL_LOGS_EXPORTER=none", + "OTEL_PROPAGATORS=tracecontext,baggage", + "QDRANT_HOST=qdrant", + "QDRANT_PORT=6334", + "QDRANT_COLLECTION=weknora_embeddings", + "QDRANT_API_KEY=${GENERATED_QDRANT_API_KEY}", + "QDRANT_USE_TLS=false", + "MINIO_ENDPOINT=minio:9000", + "MINIO_ACCESS_KEY_ID=${GENERATED_MINIO_ACCESS_KEY_ID}", + "MINIO_SECRET_ACCESS_KEY=${GENERATED_MINIO_SECRET_ACCESS_KEY}", + "MINIO_BUCKET_NAME=weknora", + "GIN_MODE=release", + "DISABLE_REGISTRATION=false", + "DB_DRIVER=postgres", + "DB_HOST=weknora-postgres", + "DB_PORT=5432", + "DB_USER=postgres", + "DB_PASSWORD=${GENERATED_DB_PASSWORD}", + "DB_NAME=WeKnora", + "TZ=$TZ", + "RETRIEVE_DRIVER=postgres", + "DOCREADER_ADDR=weknora-docreader:50051", + "STORAGE_TYPE=minio", + "LOCAL_STORAGE_BASE_DIR=/data/files", + "AUTO_RECOVER_DIRTY=true", + "OLLAMA_BASE_URL=http://host.docker.internal:11434", + "STREAM_MANAGER_TYPE=redis", + "REDIS_ADDR=weknora-redis:6379", + "REDIS_PASSWORD=${GENERATED_REDIS_PASSWORD}", + "REDIS_DB=0", + "REDIS_PREFIX=\"stream:\"", + "TENANT_AES_KEY=${GENERATED_TENANT_AES_KEY}", + "CONCURRENCY_POOL_SIZE=5", + "JWT_SECRET=${GENERATED_JWT_SECRET}", + "MAX_FILE_SIZE_MB=50" + ], + "depends_on": { + "weknora-redis": { + "condition": "service_started" + }, + "weknora-postgres": { + "condition": "service_healthy" + }, + "weknora-docreader": { + "condition": "service_healthy" + } + }, + "networks": [ + "weknora-network" + ], + "restart": "unless-stopped", + "extra_hosts": [ + "host.docker.internal:host-gateway" + ] + } + }, + { + "name": "jaeger", + "image": "jaegertracing/all-in-one:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 5, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "jaegertracing/all-in-one:latest", + "container_name": "weknora-jaeger", + "ports": [ + { + "target": 6831, + "published": "46831", + "protocol": "udp" + }, + { + "target": 6832, + "published": "46832", + "protocol": "udp" + }, + { + "target": 5778, + "published": "45778", + "protocol": "tcp" + }, + { + "target": 16686, + "published": "16686", + "protocol": "tcp" + }, + { + "target": 4317, + "published": "44317", + "protocol": "tcp" + }, + { + "target": 4318, + "published": "44318", + "protocol": "tcp" + }, + { + "target": 14250, + "published": "14250", + "protocol": "tcp" + }, + { + "target": 14268, + "published": "14268", + "protocol": "tcp" + }, + { + "target": 9411, + "published": "49411", + "protocol": "tcp" + } + ], + "environment": [ + "COLLECTOR_OTLP_ENABLED=true", + "COLLECTOR_ZIPKIN_HOST_PORT=:9411" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/jaeger", + "target": "/var/lib/jaeger" + } + ], + "networks": [ + "weknora-network" + ], + "restart": "unless-stopped" + } + }, + { + "name": "minio", + "image": "minio/minio:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 6, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "minio/minio:latest", + "container_name": "weknora-minio", + "ports": [ + { + "target": 9000, + "published": "19000", + "protocol": "tcp" + }, + { + "target": 9001, + "published": "19001", + "protocol": "tcp" + } + ], + "environment": [ + "MINIO_ROOT_USER=minioadmin", + "MINIO_ROOT_PASSWORD=${GENERATED_MINIO_ROOT_PASSWORD}" + ], + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "command": [ + "server", + "/data", + "--console-address", + ":9001" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/minio-data", + "target": "/data" + } + ], + "healthcheck": { + "test": [ + "CMD", + "curl", + "-f", + "http://localhost:9000/minio/health/live" + ], + "interval": "30s", + "timeout": "20s", + "retries": 3 + }, + "networks": [ + "weknora-network" + ], + "restart": "unless-stopped" + } + }, + { + "name": "neo4j", + "image": "neo4j:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 7, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "neo4j:latest", + "container_name": "weknora-neo4j", + "profiles": [ + "neo4j", + "full" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/neo4j-data", + "target": "/data" + } + ], + "environment": [ + "NEO4J_AUTH=neo4j/password", + "NEO4J_apoc_export_file_enabled=true", + "NEO4J_apoc_import_file_enabled=true", + "NEO4J_apoc_import_file_use__neo4j__config=true", + "NEO4JLABS_PLUGINS=[\"apoc\"]" + ], + "ports": [ + { + "target": 7474, + "published": "47474", + "protocol": "tcp" + }, + { + "target": 7687, + "published": "47687", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "networks": [ + "weknora-network" + ] + } + }, + { + "name": "qdrant", + "image": "qdrant/qdrant:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 8, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "qdrant/qdrant:latest", + "container_name": "weknora-qdrant", + "profiles": [ + "qdrant", + "full" + ], + "ports": [ + { + "target": 6333, + "published": "46333", + "protocol": "tcp" + }, + { + "target": 6334, + "published": "46334", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/storage", + "target": "/qdrant/storage" + } + ], + "networks": [ + "weknora-network" + ], + "restart": "unless-stopped", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + } + } + }, + { + "name": "weknora", + "image": "wechatopenai/weknora-ui:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "app" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "wechatopenai/weknora-ui:latest", + "container_name": "weknora", + "ports": [ + { + "target": 80, + "published": "1080", + "protocol": "tcp" + } + ], + "environment": [ + "MAX_FILE_SIZE_MB=50" + ], + "depends_on": { + "app": { + "condition": "service_healthy" + } + }, + "networks": [ + "weknora-network" + ], + "restart": "unless-stopped", + "deploy": { + "resources": { + "reservations": { + "memory": "128M" + } + } + } + } + } + ], + "top_level": { + "name": "weknora", + "networks": { + "weknora-network": { + "driver": "bridge" + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "app-volume-0", + "service": "app", + "container_path": "/data/files", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for app:/data/files" + }, + { + "id": "weknora-postgres-volume-0", + "service": "weknora-postgres", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "minio-volume-0", + "service": "minio", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for minio:/data" + }, + { + "id": "jaeger-volume-0", + "service": "jaeger", + "container_path": "/var/lib/jaeger", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "neo4j-volume-0", + "service": "neo4j", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for neo4j:/data" + }, + { + "id": "qdrant-volume-0", + "service": "qdrant", + "container_path": "/qdrant/storage", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 9, + "start_order": [ + "weknora-docreader", + "weknora-postgres", + "weknora-redis", + "app", + "jaeger", + "minio", + "neo4j", + "qdrant", + "weknora" + ], + "stop_order": [ + "weknora", + "qdrant", + "neo4j", + "minio", + "jaeger", + "app", + "weknora-redis", + "weknora-postgres", + "weknora-docreader" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "db-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "app", + "environment_variable": "DB_PASSWORD" + }, + { + "service": "weknora-postgres", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + }, + { + "id": "jwt-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "app", + "environment_variable": "JWT_SECRET" + } + ] + }, + { + "id": "minio-access-key-id", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "app", + "environment_variable": "MINIO_ACCESS_KEY_ID" + }, + { + "service": "weknora-docreader", + "environment_variable": "MINIO_ACCESS_KEY_ID" + } + ] + }, + { + "id": "minio-root-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "minio", + "environment_variable": "MINIO_ROOT_PASSWORD" + } + ] + }, + { + "id": "minio-secret-access-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "app", + "environment_variable": "MINIO_SECRET_ACCESS_KEY" + }, + { + "service": "weknora-docreader", + "environment_variable": "MINIO_SECRET_ACCESS_KEY" + } + ] + }, + { + "id": "qdrant-api-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "app", + "environment_variable": "QDRANT_API_KEY" + } + ] + }, + { + "id": "redis-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "app", + "environment_variable": "REDIS_PASSWORD" + } + ] + }, + { + "id": "tenant-aes-key", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "app", + "environment_variable": "TENANT_AES_KEY" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 128, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "app: credencial externa o booleano GENERATED_QDRANT_API_KEY pendiente", + "app: extra_hosts necesita revision de pila", + "app: perfil de salud y persistencia pendiente", + "jaeger: perfil de salud y persistencia pendiente", + "minio: perfil de salud y persistencia pendiente", + "neo4j: compose-key:profiles", + "neo4j: perfil de salud y persistencia pendiente", + "neo4j: profiles necesita revision de pila", + "qdrant: compose-key:profiles", + "qdrant: perfil de salud y persistencia pendiente", + "qdrant: profiles necesita revision de pila", + "weknora-docreader: extra_hosts necesita revision de pila", + "weknora-docreader: perfil de salud y persistencia pendiente", + "weknora-postgres: perfil de salud y persistencia pendiente", + "weknora-redis: comando de dependencia personalizado pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:app:compose-key:depends_on", + "service:weknora-docreader:healthcheck-format", + "service:weknora-postgres:healthcheck-format", + "service:neo4j:compose-key:profiles", + "service:qdrant:compose-key:profiles", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/wg-easy.json b/oci/catalog/apps/wg-easy.json new file mode 100644 index 00000000..b70931ed --- /dev/null +++ b/oci/catalog/apps/wg-easy.json @@ -0,0 +1,509 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-wg-easy", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "WireGuard Easy" + }, + "tagline": { + "en_US": "WEB UI to manage WireGuard VPN." + }, + "description": { + "en_US": "You have found the easiest way to install & manage WireGuard on any Linux host!" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "WeejeWel", + "developer": "WeejeWel", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 51821, + "path": "/" + }, + "website": "", + "documentation": null, + "repository": "https://ghcr.io/wg-easy/wg-easy", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://ghcr.io/wg-easy/wg-easy", + "revision": "74665acad9d4730afa34d5ff4890702c94e8b9a39b366b544174b3b765d76f07", + "image_repository_url": "https://ghcr.io/wg-easy/wg-easy", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "74665acad9d4730afa34d5ff4890702c94e8b9a39b366b544174b3b765d76f07", + "generated_at": "2026-09-13T15:58:29+00:00" + }, + "container_contract": { + "service_name": "wg-easy", + "container_name": "wg-easy", + "image": { + "reference": "ghcr.io/wg-easy/wg-easy:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/wg-easy/wg-easy", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PASSWORD", + "example": "${GENERATED_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "WG_HOST", + "example": "wg-easy.local", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WG_PORT", + "example": "51820", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WG_DEFAULT_DNS", + "example": "1.1.1.1", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/etc/wireguard", + "compose_source_example": "/DATA/AppData/$AppID/wireguard", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 51820, + "published_example": 51820, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 51821, + "published_example": 51821, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: wg-easy\nservices:\n wg-easy:\n image: ghcr.io/wg-easy/wg-easy:latest\n restart: unless-stopped\n network_mode: bridge\n environment:\n PASSWORD: ${GENERATED_PASSWORD}\n WG_HOST: wg-easy.local\n WG_PORT: '51820'\n WG_DEFAULT_DNS: 1.1.1.1\n ports:\n - target: 51820\n published: '51820'\n protocol: udp\n - target: 51821\n published: '51821'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/wireguard\n target: /etc/wireguard\n cap_add:\n - NET_ADMIN\n - SYS_MODULE\n sysctls:\n - net.ipv4.ip_forward=1\n - net.ipv4.conf.all.src_valid_mark=1\n container_name: wg-easy\n" + }, + "compose_stack": { + "project_name": "wg-easy", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "wg-easy", + "service_count": 1, + "services": [ + { + "name": "wg-easy", + "image": "ghcr.io/wg-easy/wg-easy:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/wg-easy/wg-easy:latest", + "restart": "unless-stopped", + "network_mode": "bridge", + "environment": { + "PASSWORD": "${GENERATED_PASSWORD}", + "WG_HOST": "wg-easy.local", + "WG_PORT": "51820", + "WG_DEFAULT_DNS": "1.1.1.1" + }, + "ports": [ + { + "target": 51820, + "published": "51820", + "protocol": "udp" + }, + { + "target": 51821, + "published": "51821", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/wireguard", + "target": "/etc/wireguard" + } + ], + "cap_add": [ + "NET_ADMIN", + "SYS_MODULE" + ], + "sysctls": [ + "net.ipv4.ip_forward=1", + "net.ipv4.conf.all.src_valid_mark=1" + ], + "container_name": "wg-easy" + } + } + ], + "top_level": { + "name": "wg-easy" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "wg-easy-volume-0", + "service": "wg-easy", + "container_path": "/etc/wireguard", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "wg-easy" + ], + "stop_order": [ + "wg-easy" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "wg-easy", + "environment_variable": "PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 51821, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "security": { + "required_capabilities": [ + "NET_ADMIN", + "SYS_MODULE" + ], + "host_modules": [ + { + "name": "wireguard", + "enable_prompt": "Load and verify the WireGuard module on the Proxmox host", + "enabled_default": true, + "required_by_compose": true + } + ], + "sysctls": [ + { + "name": "net.ipv4.ip_forward", + "value": "1" + }, + { + "name": "net.ipv4.conf.all.src_valid_mark", + "value": "1" + } + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/wikijs.json b/oci/catalog/apps/wikijs.json new file mode 100644 index 00000000..75e2ad63 --- /dev/null +++ b/oci/catalog/apps/wikijs.json @@ -0,0 +1,299 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-wikijs", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Wikijs" + }, + "tagline": { + "en_US": "Wikijs A modern, lightweight and powerful wiki app built on NodeJS." + }, + "description": { + "en_US": "Wikijs A modern, lightweight and powerful wiki app built on NodeJS." + }, + "category": "documents", + "category_label": "Documents & Notes", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wikijs-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wikijs-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://github.com/Requarks/wiki", + "documentation": "https://docs.linuxserver.io/images/docker-wikijs/", + "repository": "https://github.com/linuxserver/docker-wikijs", + "tips": [], + "mini_changelog": [ + { + "date": "2025-10-14", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2025-01-18", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-06-01", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2023-12-23", + "note": "Rebase to Alpine 3.19." + }, + { + "date": "2022-08-25", + "note": "Rebase to Alpine 3.18." + } + ], + "display_version": null, + "updated_at": "2025-10-14" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-wikijs", + "default_branch": "master", + "revision": "bff595097b5aab72c17ee3a45bdbe8dd73984a92", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-wikijs/bff595097b5aab72c17ee3a45bdbe8dd73984a92/README.md", + "readme_pushed_at": "2026-09-11T17:24:46Z", + "compose_sha256": "7883e4820ce52ec57a36ead15232974a7091f90c7c0855c8fdd8191b0998e0ed", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "wikijs", + "container_name": "wikijs", + "image": { + "reference": "lscr.io/linuxserver/wikijs:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/wikijs", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_TYPE", + "example": "sqlite", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_NAME", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASS", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/wikijs/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n wikijs:\n image: lscr.io/linuxserver/wikijs:latest\n container_name: wikijs\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - DB_TYPE=sqlite #optional\n - DB_HOST= #optional\n - DB_PORT= #optional\n - DB_NAME= #optional\n - DB_USER= #optional\n - DB_PASS= #optional\n volumes:\n - /path/to/wikijs/config:/config\n - /path/to/data:/data\n ports:\n - 3000:3000\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/winegui.json b/oci/catalog/apps/winegui.json new file mode 100644 index 00000000..590ed49e --- /dev/null +++ b/oci/catalog/apps/winegui.json @@ -0,0 +1,256 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-winegui", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Winegui" + }, + "tagline": { + "en_US": "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles." + }, + "description": { + "en_US": "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/winegui-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/winegui-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://gitlab.melroy.org/melroy/winegui", + "documentation": "https://docs.linuxserver.io/images/docker-winegui/", + "repository": "https://github.com/linuxserver/docker-winegui", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-22", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-04-22" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-winegui", + "default_branch": "master", + "revision": "7c25477778e02cc2c91bac3d020823966ca1de2b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-winegui/7c25477778e02cc2c91bac3d020823966ca1de2b/README.md", + "readme_pushed_at": "2026-09-09T20:07:00Z", + "compose_sha256": "2e88be29943f0deceb0ac26a4ad134d84f24b86b5c2ebcb930741bcda27b73e5", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "winegui", + "container_name": "winegui", + "image": { + "reference": "lscr.io/linuxserver/winegui:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/winegui", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/winegui/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n winegui:\n image: lscr.io/linuxserver/winegui:latest\n container_name: winegui\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/winegui/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/wireguard.json b/oci/catalog/apps/wireguard.json new file mode 100644 index 00000000..236b6b27 --- /dev/null +++ b/oci/catalog/apps/wireguard.json @@ -0,0 +1,440 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-wireguard", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Wireguard" + }, + "tagline": { + "en_US": "WireGuard\u00ae is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry." + }, + "description": { + "en_US": "WireGuard\u00ae is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry." + }, + "category": "remote", + "category_label": "Remote Access & VPN", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wireguard-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wireguard-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://www.wireguard.com/", + "documentation": "https://docs.linuxserver.io/images/docker-wireguard/", + "repository": "https://github.com/linuxserver/docker-wireguard", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-24", + "note": "Rebase to Alpine 3.23 again as openresolv alpine 3.23 package has now been updated." + }, + { + "date": "2026-01-22", + "note": "Revert to Alpine 3.22 due to resolvconf bug." + }, + { + "date": "2026-01-04", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-15", + "note": "Rebase to Alpine 3.22. Remove iptables-legacy shim." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-wireguard", + "default_branch": "master", + "revision": "ed4c08a68f548225188988ebee9ee00c5c7f120a", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-wireguard/ed4c08a68f548225188988ebee9ee00c5c7f120a/README.md", + "readme_pushed_at": "2026-09-10T15:09:55Z", + "compose_sha256": "dd70323a1792cf1a9be716d3f85d102d8b7b682fd6aa7ed86a252be06321d261", + "generated_at": "2026-09-13T15:58:30+00:00" + }, + "container_contract": { + "service_name": "wireguard", + "container_name": "wireguard", + "image": { + "reference": "lscr.io/linuxserver/wireguard:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/wireguard", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SERVERURL", + "example": "wireguard.domain.com", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SERVERPORT", + "example": "51820", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PEERS", + "example": "1", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PEERDNS", + "example": "auto", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "INTERNAL_SUBNET", + "example": "10.13.13.0", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ALLOWEDIPS", + "example": "0.0.0.0/0", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PERSISTENTKEEPALIVE_PEERS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOG_CONFS", + "example": "true", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/wireguard/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/lib/modules", + "compose_source_example": "/lib/modules", + "read_only": false, + "required": false, + "installation_choice": [ + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 51820, + "published_example": 51820, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n wireguard:\n image: lscr.io/linuxserver/wireguard:latest\n container_name: wireguard\n cap_add:\n - NET_ADMIN\n - SYS_MODULE #optional\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - SERVERURL=wireguard.domain.com #optional\n - SERVERPORT=51820 #optional\n - PEERS=1 #optional\n - PEERDNS=auto #optional\n - INTERNAL_SUBNET=10.13.13.0 #optional\n - ALLOWEDIPS=0.0.0.0/0 #optional\n - PERSISTENTKEEPALIVE_PEERS= #optional\n - LOG_CONFS=true #optional\n volumes:\n - /path/to/wireguard/config:/config\n - /lib/modules:/lib/modules #optional\n ports:\n - 51820:51820/udp\n sysctls:\n - net.ipv4.conf.all.src_valid_mark=1\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "security": { + "required_capabilities": [ + "NET_ADMIN", + "SYS_MODULE" + ], + "host_modules": [ + { + "name": "wireguard", + "enable_prompt": "Load and verify the WireGuard module on the Proxmox host", + "enabled_default": true, + "required_by_compose": true + } + ], + "sysctls": [ + { + "name": "net.ipv4.conf.all.src_valid_mark", + "value": "1" + } + ] + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/wireshark.json b/oci/catalog/apps/wireshark.json new file mode 100644 index 00000000..06b668c0 --- /dev/null +++ b/oci/catalog/apps/wireshark.json @@ -0,0 +1,483 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-wireshark", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Wireshark" + }, + "tagline": { + "en_US": "Wireshark is the world\u2019s foremost and widely-used network protocol analyzer. It lets you see what\u2019s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998." + }, + "description": { + "en_US": "Wireshark is the world\u2019s foremost and widely-used network protocol analyzer. It lets you see what\u2019s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wireshark-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wireshark-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.wireshark.org/", + "documentation": "https://docs.linuxserver.io/images/docker-wireshark/", + "repository": "https://github.com/linuxserver/docker-wireshark", + "tips": [], + "mini_changelog": [ + { + "date": "2026-06-10", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic, rebase to Alpine 3.23." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies and Alpine 3.22, HTTPS IS NOW REQUIRED." + }, + { + "date": "2024-12-06", + "note": "Rebase to Alpine 3.21." + } + ], + "display_version": null, + "updated_at": "2026-06-10" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-wireshark", + "default_branch": "master", + "revision": "259f22643b536b5402b475ef099432e16bdc0d49", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-wireshark/259f22643b536b5402b475ef099432e16bdc0d49/README.md", + "readme_pushed_at": "2026-09-07T19:32:17Z", + "compose_sha256": "bbd3e65c0c26658e6cfc63cad67c9b71e6589ac9766878d0d157225ef69dafcf", + "generated_at": "2026-09-13T15:47:57+00:00" + }, + "container_contract": { + "service_name": "wireshark", + "container_name": "wireshark", + "image": { + "reference": "lscr.io/linuxserver/wireshark:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/wireshark", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/wireshark/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n wireshark:\n image: lscr.io/linuxserver/wireshark:latest\n container_name: wireshark\n cap_add:\n - NET_ADMIN\n network_mode: host\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/wireshark/config:/config\n ports:\n - 3000:3000 #optional\n - 3001:3001 #optional\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "network": { + "compose_mode": "host" + }, + "security": { + "required_capabilities": [ + "NET_ADMIN" + ] + }, + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-wireshark/master/Dockerfile", + "dockerfile_sha256": "6afcc209c79818fe574d869b1933df50194eaf978b26f16304ed0dce16f8a37a", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/wps-office.json b/oci/catalog/apps/wps-office.json new file mode 100644 index 00000000..d701a9a9 --- /dev/null +++ b/oci/catalog/apps/wps-office.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-wps-office", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Wps Office" + }, + "tagline": { + "en_US": "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency." + }, + "description": { + "en_US": "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wps-office-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wps-office-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.wps.com/", + "documentation": "https://docs.linuxserver.io/images/docker-wps-office/", + "repository": "https://github.com/linuxserver/docker-wps-office", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-11", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform for chromium fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-10", + "note": "Rebase to Selkies HTTPS IS NOW REQUIRED, merge chinese and english image." + }, + { + "date": "2024-02-10", + "note": "Update Readme with new env vars and ingest proper PWA icon." + } + ], + "display_version": null, + "updated_at": "2026-04-11" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-wps-office", + "default_branch": "master", + "revision": "04944a54d61cfc5763bfddbc880ac8d4ea7d5681", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-wps-office/04944a54d61cfc5763bfddbc880ac8d4ea7d5681/README.md", + "readme_pushed_at": "2026-09-07T17:45:52Z", + "compose_sha256": "7b58c6b2c25d8bf7f29fe9c81442c589e46a4e001f8717b124d5532fb346d738", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "wps-office", + "container_name": "wps-office", + "image": { + "reference": "lscr.io/linuxserver/wps-office:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/wps-office", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n wps-office:\n image: lscr.io/linuxserver/wps-office:latest\n container_name: wps-office\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-wps-office/master/Dockerfile", + "dockerfile_sha256": "195689c826f891fa8e50019092eef4aa817eca18bf7012175d6ba44474170e4b", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/xbackbone.json b/oci/catalog/apps/xbackbone.json new file mode 100644 index 00000000..1d13489d --- /dev/null +++ b/oci/catalog/apps/xbackbone.json @@ -0,0 +1,248 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-xbackbone", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Xbackbone" + }, + "tagline": { + "en_US": "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support." + }, + "description": { + "en_US": "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/xbackbone-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/xbackbone-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/SergiX44/XBackBone", + "documentation": "https://docs.linuxserver.io/images/docker-xbackbone/", + "repository": "https://github.com/linuxserver/docker-xbackbone", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-07-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-05-27", + "note": "Rebase to Alpine 3.20. Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2023-12-28", + "note": "Rebase to Alpine 3.19 with php 8.3." + }, + { + "date": "2023-12-25", + "note": "Existing users should update: site-confs/default.conf - Cleanup default site conf." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-xbackbone", + "default_branch": "main", + "revision": "7f242fe8e7346a2024b701f0aecf3caafb080cef", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-xbackbone/7f242fe8e7346a2024b701f0aecf3caafb080cef/README.md", + "readme_pushed_at": "2026-09-06T07:15:58Z", + "compose_sha256": "ed7f0848a2e604764451440c607358b36507ee414daa9e57d205a493f08b0d7a", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "xbackbone", + "container_name": "xbackbone", + "image": { + "reference": "lscr.io/linuxserver/xbackbone:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/xbackbone", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/xbackbone/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n xbackbone:\n image: lscr.io/linuxserver/xbackbone:latest\n container_name: xbackbone\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/xbackbone/config:/config\n ports:\n - 80:80\n - 443:443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/xemu.json b/oci/catalog/apps/xemu.json new file mode 100644 index 00000000..bf65e8c0 --- /dev/null +++ b/oci/catalog/apps/xemu.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-xemu", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Xemu" + }, + "tagline": { + "en_US": "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems." + }, + "description": { + "en_US": "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/xemu-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/xemu-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://xemu.app/", + "documentation": "https://docs.linuxserver.io/images/docker-xemu/", + "repository": "https://github.com/linuxserver/docker-xemu", + "tips": [], + "mini_changelog": [ + { + "date": "2026-05-09", + "note": "Rebase to resolute, Pin to current pre-release until next release is cut for audio support." + }, + { + "date": "2025-12-20", + "note": "Add libpipewire dep for appimage, pin to v0.8.133." + }, + { + "date": "2025-12-20", + "note": "Add libusb dep for appimage." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-07", + "note": "Install GTK libs for file chooser." + } + ], + "display_version": null, + "updated_at": "2026-05-09" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-xemu", + "default_branch": "master", + "revision": "af7a3d6d3b1b2e48078d783b65df1987e87efc5b", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-xemu/af7a3d6d3b1b2e48078d783b65df1987e87efc5b/README.md", + "readme_pushed_at": "2026-09-08T00:04:23Z", + "compose_sha256": "771e83946d21aca779087de4dcfc707a04f0f123cf10bb86d33dc923d788b566", + "generated_at": "2026-09-12T14:37:39+00:00" + }, + "container_contract": { + "service_name": "xemu", + "container_name": "xemu", + "image": { + "reference": "lscr.io/linuxserver/xemu:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/xemu", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n xemu:\n image: lscr.io/linuxserver/xemu:latest\n container_name: xemu\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/yaak.json b/oci/catalog/apps/yaak.json new file mode 100644 index 00000000..b2f0872a --- /dev/null +++ b/oci/catalog/apps/yaak.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-yaak", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Yaak" + }, + "tagline": { + "en_US": "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS." + }, + "description": { + "en_US": "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/yaak-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/yaak-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://yaak.app/", + "documentation": "https://docs.linuxserver.io/images/docker-yaak/", + "repository": "https://github.com/linuxserver/docker-yaak", + "tips": [], + "mini_changelog": [ + { + "date": "2026-04-20", + "note": "Rebase to resolute." + }, + { + "date": "2026-04-04", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-11", + "note": "Push aarch64 image. Update external trigger." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-07-29", + "note": "Rebase to selkies. Breaking Change: HTTPS is now required. Either use a reverse proxy with SSL cert or direct connect to port 8181 with HTTPS." + } + ], + "display_version": null, + "updated_at": "2026-04-20" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-yaak", + "default_branch": "main", + "revision": "a220fe1cc8d6522aabac8dcfb56833925609152c", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-yaak/a220fe1cc8d6522aabac8dcfb56833925609152c/README.md", + "readme_pushed_at": "2026-09-08T08:58:32Z", + "compose_sha256": "8a52d3ec242e234d26b1e2f2ebe5b0979b2b862e534f81b76e27f48fd4ca4422", + "generated_at": "2026-09-12T14:37:40+00:00" + }, + "container_contract": { + "service_name": "yaak", + "container_name": "yaak", + "image": { + "reference": "lscr.io/linuxserver/yaak:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/yaak", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/yaak/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n yaak:\n image: lscr.io/linuxserver/yaak:latest\n container_name: yaak\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/yaak/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-yaak/master/Dockerfile", + "dockerfile_sha256": "b6ce329b48b85150b2dbf4a1dabd353b1d12a2bec53adbd1adf92f80a290691f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/your_spotify.json b/oci/catalog/apps/your_spotify.json new file mode 100644 index 00000000..6acaeaf5 --- /dev/null +++ b/oci/catalog/apps/your_spotify.json @@ -0,0 +1,273 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-your-spotify", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Your_Spotify" + }, + "tagline": { + "en_US": "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics." + }, + "description": { + "en_US": "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/your_spotify-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/your_spotify-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/Yooooomi/your_spotify", + "documentation": "https://docs.linuxserver.io/images/docker-your_spotify/", + "repository": "https://github.com/linuxserver/docker-your_spotify", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-05", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2025-07-09", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-12-20", + "note": "Rebase to Alpine 3.21." + }, + { + "date": "2024-05-27", + "note": "Existing users should update their nginx confs to avoid http2 deprecation warnings." + }, + { + "date": "2024-05-24", + "note": "Rebase to Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-05" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-your_spotify", + "default_branch": "main", + "revision": "57b559b319b0dbf33e2b60da968ba079fac95f39", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-your_spotify/57b559b319b0dbf33e2b60da968ba079fac95f39/README.md", + "readme_pushed_at": "2026-09-09T21:24:34Z", + "compose_sha256": "d413f5f3dffb16b510c12666002a7b7a7a81dc86a46937ab6f3f3499552fa5d6", + "generated_at": "2026-09-12T14:37:40+00:00" + }, + "container_contract": { + "service_name": "your_spotify", + "container_name": "your_spotify", + "image": { + "reference": "lscr.io/linuxserver/your_spotify:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/your_spotify", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_URL", + "example": "http://localhost", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SPOTIFY_PUBLIC", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SPOTIFY_SECRET", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SPOTIFY_API_DELAY_MS", + "example": "2000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CORS", + "example": "http://localhost:80,https://localhost:443", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "MONGO_ENDPOINT", + "example": "mongodb://mongo:27017/your_spotify", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n your_spotify:\n image: lscr.io/linuxserver/your_spotify:latest\n container_name: your_spotify\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - APP_URL=http://localhost\n - SPOTIFY_PUBLIC=\n - SPOTIFY_SECRET=\n - SPOTIFY_API_DELAY_MS=2000\n - CORS=http://localhost:80,https://localhost:443\n - MONGO_ENDPOINT=mongodb://mongo:27017/your_spotify\n ports:\n - 80:80\n - 443:443\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/zen.json b/oci/catalog/apps/zen.json new file mode 100644 index 00000000..0b3197d5 --- /dev/null +++ b/oci/catalog/apps/zen.json @@ -0,0 +1,265 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-zen", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Zen" + }, + "tagline": { + "en_US": "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design." + }, + "description": { + "en_US": "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/zen-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/zen-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://zen-browser.app/", + "documentation": "https://docs.linuxserver.io/images/docker-zen/", + "repository": "https://github.com/linuxserver/docker-zen", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-31", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2025-12-20", + "note": "Add Wayland init logic." + }, + { + "date": "2025-08-19", + "note": "Initial release." + } + ], + "display_version": null, + "updated_at": "2026-03-31" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-zen", + "default_branch": "master", + "revision": "9c01db7c645875022f0490ef947e1254636c4200", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-zen/9c01db7c645875022f0490ef947e1254636c4200/README.md", + "readme_pushed_at": "2026-09-05T21:30:12Z", + "compose_sha256": "5ce01a52cc66d4ce86697c6fcd721d44776f5e16b174c1a8999d7dc5377ae1a9", + "generated_at": "2026-09-12T14:37:40+00:00" + }, + "container_contract": { + "service_name": "zen", + "container_name": "zen", + "image": { + "reference": "lscr.io/linuxserver/zen:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/zen", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n zen:\n image: lscr.io/linuxserver/zen:latest\n container_name: zen\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/znc.json b/oci/catalog/apps/znc.json new file mode 100644 index 00000000..b6e6edf7 --- /dev/null +++ b/oci/catalog/apps/znc.json @@ -0,0 +1,241 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-znc", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Znc" + }, + "tagline": { + "en_US": "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC." + }, + "description": { + "en_US": "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/znc-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/znc-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 6501, + "path": "/" + }, + "website": "http://wiki.znc.in/ZNC", + "documentation": "https://docs.linuxserver.io/images/docker-znc/", + "repository": "https://github.com/linuxserver/docker-znc", + "tips": [], + "mini_changelog": [ + { + "date": "2025-07-27", + "note": "Rebase to Alpine 3.22." + }, + { + "date": "2024-06-10", + "note": "Migrate default config file to newer format." + }, + { + "date": "2024-06-06", + "note": "Rebase to Alpine 3.20." + }, + { + "date": "2024-03-26", + "note": "Switch back to multi-threaded builds and ignore `-beta` and `-alpha` tags as well as `-rc`." + }, + { + "date": "2024-02-22", + "note": "Update build system for v1.9.0 (use cmake)." + } + ], + "display_version": null, + "updated_at": "2025-07-27" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-znc", + "default_branch": "master", + "revision": "e023b9b227e84c71973e0c9b17d6974187545d44", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-znc/e023b9b227e84c71973e0c9b17d6974187545d44/README.md", + "readme_pushed_at": "2026-09-11T07:42:00Z", + "compose_sha256": "4e3c50ae2caf4fe6c0022436c95c9ee0f30f80640b97ad5a170c22e06df11163", + "generated_at": "2026-09-12T14:37:40+00:00" + }, + "container_contract": { + "service_name": "znc", + "container_name": "znc", + "image": { + "reference": "lscr.io/linuxserver/znc:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/znc", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/znc/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 6501, + "published_example": 6501, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n znc:\n image: lscr.io/linuxserver/znc:latest\n container_name: znc\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/znc/config:/config\n ports:\n - 6501:6501\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 6501, + "path": "/", + "source": "compose-first-tcp-port-fallback" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/zotero.json b/oci/catalog/apps/zotero.json new file mode 100644 index 00000000..69247efe --- /dev/null +++ b/oci/catalog/apps/zotero.json @@ -0,0 +1,372 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "linuxserver-zotero", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Zotero" + }, + "tagline": { + "en_US": "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research." + }, + "description": { + "en_US": "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research." + }, + "category": "misc", + "category_label": "Miscellaneous", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/zotero-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/zotero-banner.png", + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "https", + "port": 3001, + "path": "/" + }, + "website": "https://www.zotero.org/", + "documentation": "https://docs.linuxserver.io/images/docker-zotero/", + "repository": "https://github.com/linuxserver/docker-zotero", + "tips": [], + "mini_changelog": [ + { + "date": "2026-03-30", + "note": "Make Wayland default disable with PIXELFLUX_WAYLAND=false." + }, + { + "date": "2026-03-21", + "note": "Use Wayland ozone platform for chromium fixes scaling and acceleration." + }, + { + "date": "2025-12-28", + "note": "Add Wayland init logic." + }, + { + "date": "2025-09-22", + "note": "Rebase to Debian Trixie." + }, + { + "date": "2025-07-12", + "note": "Rebase to Selkies, HTTPS IS NOW REQUIRED." + } + ], + "display_version": null, + "updated_at": "2026-03-30" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-zotero", + "default_branch": "master", + "revision": "26fd1667dc37c14763e2da0567a60a6bd228e0d9", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-zotero/26fd1667dc37c14763e2da0567a60a6bd228e0d9/README.md", + "readme_pushed_at": "2026-09-09T22:15:01Z", + "compose_sha256": "c66730f1ca728ddf828910edf05c2a6029ddd76f963e7938215af413c9d97120", + "generated_at": "2026-09-12T14:37:40+00:00" + }, + "container_contract": { + "service_name": "zotero", + "container_name": "zotero", + "image": { + "reference": "lscr.io/linuxserver/zotero:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/zotero", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LC_ALL", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt": "Language/locale (e.g. es_ES.UTF-8; translation of every application is not guaranteed)" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3001, + "published_example": 3001, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n zotero:\n image: lscr.io/linuxserver/zotero:latest\n container_name: zotero\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/config:/config\n ports:\n - 3000:3000\n - 3001:3001\n shm_size: \"1gb\"\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "https", + "port": 3001, + "path": "/", + "source": "linuxserver-readme-application-setup" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + } + ], + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + }, + { + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0755" + ] + } + ], + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-zotero/master/Dockerfile", + "dockerfile_sha256": "7a4334dda5023bb812a3532498d92ede4eeccc4c4e4fa8b6652c6f0b137d00f4", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + }, + "optional_devices": [], + "hardware_acceleration": { + "prompt": "Selkies desktop and streaming acceleration", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No GPU (CPU)", + "device_requests": [], + "environment": [ + { + "name": "AUTO_GPU", + "value": "false" + } + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (streaming rendering and encoding)", + "device_requests": [ + { + "id": "selkies-render", + "kind": "character-device", + "path_prompt": "Intel/AMD render node", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ], + "environment": [ + { + "name": "PIXELFLUX_WAYLAND", + "value": "true" + }, + { + "name": "AUTO_GPU", + "value": "false" + } + ], + "environment_from_devices": { + "DRINODE": [ + "selkies-render" + ], + "DRI_NODE": [ + "selkies-render" + ], + "ATTACHED_DEVICES_PERMS": [ + "selkies-render" + ] + } + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + }, + "device_permissions": { + "strategy": "linuxserver-native-init", + "service_user": "abc", + "environment": "ATTACHED_DEVICES_PERMS", + "paths": "all-resolved-selected-character-devices" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "shm_size", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/apps/ztnet.json b/oci/catalog/apps/ztnet.json new file mode 100644 index 00000000..04e4fd05 --- /dev/null +++ b/oci/catalog/apps/ztnet.json @@ -0,0 +1,602 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-ztnet", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "ZTnet" + }, + "tagline": { + "en_US": "Self-hosted ZeroTier network controller with web UI for centralized management." + }, + "description": { + "en_US": "ZTNET is a powerful ZeroTier network management tool that simplifies network configuration and management through an intuitive Web interface, ideal for teams and individual users. Its modern design and rich features provide an efficient solution for building secure, scalable virtual networks.\n\nThe tool centers on an intuitive Web interface and organization with multi-user support. Developed in TypeScript, it acts as an intermediary between users and the ZeroTier Controller API, enabling collaborative network management within organizations to streamline team tasks. Integration with ZeroTier Central API allows direct management of networks, nodes, and members through a user-friendly interface, enhancing configuration efficiency.\n\nIt supports custom private root servers to create isolated network environments, improving privacy and control. Personalized user spaces enable users to independently create and manage networks. Support for 6plane and rfc4193 IPv6 addressing enriches enterprise or personal networking capabilities. Compatibility with ARM64 and AMD64 architectures ensures broad device support. The tool focuses on user-friendly and flexible design to deliver a modern network management experience.\n\n**Key Features:**\n- Intuitive Web interface for simplified ZeroTier network management\n- Organization and multi-user support for team collaboration\n- Integration with ZeroTier Central API for managing networks and nodes\n- Custom private root server for enhanced privacy and control\n- Personalized user spaces for independent network creation and management\n- Support for 6plane and rfc4193 IPv6 addressing\n- Compatibility with ARM64 and AMD64 architectures for diverse devices\n\n**Learn More:**\n- [ZTnet Official Website](https://ztnet.network/)\n- [ZTnet GitHub](https://github.com/sinamics/ztnet)\n" + }, + "category": "network", + "category_label": "Network & Firewall", + "author": "sinamics", + "developer": "sinamics", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 3000, + "path": "/" + }, + "website": "https://ztnet.network/", + "documentation": null, + "repository": "https://hub.docker.com/r/sinamics/ztnet", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null, + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + }, + "source": { + "provider": "sinamics", + "repository": "https://hub.docker.com/r/sinamics/ztnet", + "revision": "b0cc510fa06505c4e2f32d9377547830447672282fc5b787604c0b8ee36aae52", + "image_repository_url": "https://hub.docker.com/r/sinamics/ztnet", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "b0cc510fa06505c4e2f32d9377547830447672282fc5b787604c0b8ee36aae52", + "generated_at": "2026-09-13T15:48:39+00:00" + }, + "container_contract": { + "service_name": "ztnet", + "container_name": "ztnet", + "image": { + "reference": "sinamics/ztnet:latest", + "registry": "docker.io", + "repository": "sinamics/ztnet", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ZT_ADDR", + "example": "http://172.17.0.1:9993", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_HOST", + "example": "ztnet-postgres", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_PORT", + "example": "5432", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_USER", + "example": "ztnet", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_PASSWORD", + "example": "${GENERATED_POSTGRES_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "POSTGRES_DB", + "example": "ztnet", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_URL", + "example": "http://0.0.0.0:3050", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_SECRET", + "example": "${GENERATED_NEXTAUTH_SECRET}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "NEXTAUTH_URL_INTERNAL", + "example": "http://ztnet:3000", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/lib/zerotier-one", + "compose_source_example": "/var/lib/zerotier-one", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 3000, + "published_example": 3050, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "ztnet-postgres", + "image": "postgres:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: ztnet\nservices:\n ztnet:\n image: sinamics/ztnet:latest\n container_name: ztnet\n deploy:\n resources:\n reservations:\n memory: 256M\n restart: unless-stopped\n working_dir: /app\n ports:\n - target: 3000\n published: '3050'\n protocol: tcp\n volumes:\n - type: bind\n source: /var/lib/zerotier-one\n target: /var/lib/zerotier-one\n environment:\n ZT_ADDR: http://172.17.0.1:9993\n POSTGRES_HOST: ztnet-postgres\n POSTGRES_PORT: 5432\n POSTGRES_USER: ztnet\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: ztnet\n NEXTAUTH_URL: http://0.0.0.0:3050\n NEXTAUTH_SECRET: ${GENERATED_NEXTAUTH_SECRET}\n NEXTAUTH_URL_INTERNAL: http://ztnet:3000\n networks:\n - ztnet-network\n depends_on:\n - ztnet-postgres\n ztnet-postgres:\n container_name: ztnet-postgres\n image: postgres:latest\n restart: unless-stopped\n environment:\n POSTGRES_USER: ztnet\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: ztnet\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/postgres-data\n target: /var/lib/postgresql/data\n networks:\n - ztnet-network\nnetworks:\n ztnet-network:\n driver: bridge\n ipam:\n driver: default\n config:\n - subnet: 172.31.255.0/29\n" + }, + "compose_stack": { + "project_name": "ztnet", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "ztnet", + "service_count": 2, + "services": [ + { + "name": "ztnet-postgres", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "ztnet-postgres", + "image": "postgres:latest", + "restart": "unless-stopped", + "environment": { + "POSTGRES_USER": "ztnet", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "ztnet" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/postgres-data", + "target": "/var/lib/postgresql/data" + } + ], + "networks": [ + "ztnet-network" + ] + } + }, + { + "name": "ztnet", + "image": "sinamics/ztnet:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "ztnet-postgres" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "sinamics/ztnet:latest", + "container_name": "ztnet", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "restart": "unless-stopped", + "working_dir": "/app", + "ports": [ + { + "target": 3000, + "published": "3050", + "protocol": "tcp" + } + ], + "volumes": [ + { + "type": "bind", + "source": "/var/lib/zerotier-one", + "target": "/var/lib/zerotier-one" + } + ], + "environment": { + "ZT_ADDR": "http://172.17.0.1:9993", + "POSTGRES_HOST": "ztnet-postgres", + "POSTGRES_PORT": 5432, + "POSTGRES_USER": "ztnet", + "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}", + "POSTGRES_DB": "ztnet", + "NEXTAUTH_URL": "http://0.0.0.0:3050", + "NEXTAUTH_SECRET": "${GENERATED_NEXTAUTH_SECRET}", + "NEXTAUTH_URL_INTERNAL": "http://ztnet:3000" + }, + "networks": [ + "ztnet-network" + ], + "depends_on": [ + "ztnet-postgres" + ] + } + } + ], + "top_level": { + "name": "ztnet", + "networks": { + "ztnet-network": { + "driver": "bridge", + "ipam": { + "driver": "default", + "config": [ + { + "subnet": "172.31.255.0/29" + } + ] + } + } + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "ztnet-volume-0", + "service": "ztnet", + "container_path": "/var/lib/zerotier-one", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "ztnet-postgres-volume-0", + "service": "ztnet-postgres", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "ztnet-postgres", + "ztnet" + ], + "stop_order": [ + "ztnet", + "ztnet-postgres" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "nextauth-secret", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "ztnet", + "environment_variable": "NEXTAUTH_SECRET" + } + ] + }, + { + "id": "postgres-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "ztnet", + "environment_variable": "POSTGRES_PASSWORD" + }, + { + "service": "ztnet-postgres", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 3000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 256, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "working_directory": "/app" + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "generic_stack_review": [ + "topologia de varias redes o red externa pendiente" + ] + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/categories.json b/oci/catalog/categories.json new file mode 100644 index 00000000..4b023581 --- /dev/null +++ b/oci/catalog/categories.json @@ -0,0 +1,188 @@ +{ + "labels": { + "misc": "Miscellaneous", + "media": "Media & Streaming", + "ai": "AI / Coding & Dev-Tools", + "productivity": "Productivity & Workflows", + "network": "Network & Firewall", + "documents": "Documents & Notes", + "downloads": "Files & Downloads", + "arr": "*Arr Suite", + "smarthome": "IoT & Smart Home", + "monitoring": "Monitoring & Analytics", + "databases": "Databases", + "remote": "Remote Access & VPN", + "finance": "Finance & Budgeting", + "communication": "Communication & Community", + "gaming": "Gaming & Leisure", + "security": "Authentication & Security", + "adblock": "Adblock & DNS", + "web": "Webservers & Proxies", + "backup": "Backup & Recovery", + "nvr": "NVR & Cameras", + "messaging": "Messaging & Queues", + "tools": "Tools", + "business": "Business & ERP", + "automation": "Automation & Scheduling", + "management": "Host Management", + "containers": "Containers & Docker", + "creative": "Creative & Design", + "desktop": "Browsers & Web Desktops" + }, + "applications": { + "adminer": "databases", + "airsonic-advanced": "media", + "altus": "communication", + "ardour": "creative", + "audacity": "creative", + "azahar": "gaming", + "bambustudio": "creative", + "beets": "media", + "bitcoin-knots": "finance", + "blade-of-agony": "gaming", + "blender": "creative", + "brave": "desktop", + "budge": "finance", + "calibre": "media", + "calligra": "documents", + "changedetection.io": "monitoring", + "chrome": "desktop", + "chromium": "desktop", + "cloudbeaver": "databases", + "code-server": "ai", + "cops": "media", + "crafty": "gaming", + "cura": "creative", + "darktable": "creative", + "davos": "downloads", + "digikam": "creative", + "dogwalk": "gaming", + "dokuwiki": "documents", + "dolphin": "gaming", + "doplarr": "arr", + "doplarr_rs": "arr", + "dosbox-staging": "gaming", + "doublecommander": "tools", + "duckdns": "network", + "duckstation": "gaming", + "eden": "gaming", + "emulatorjs": "gaming", + "faster-whisper": "ai", + "ferdium": "communication", + "filezilla": "downloads", + "firefox": "desktop", + "flexget": "arr", + "flycast": "gaming", + "freecad": "creative", + "gimp": "creative", + "github-desktop": "ai", + "gitqlient": "ai", + "grocy": "productivity", + "gzdoom": "gaming", + "habridge": "smarthome", + "handbrake": "media", + "hedgedoc": "documents", + "heimdall": "productivity", + "helium": "desktop", + "hishtory-server": "ai", + "htpcmanager": "media", + "hugo": "web", + "inkscape": "creative", + "intellij-idea": "ai", + "joplin": "documents", + "kali-linux": "security", + "kdenlive": "creative", + "keepassxc": "security", + "kicad": "creative", + "krita": "creative", + "ldap-auth": "security", + "libreoffice": "documents", + "librespeed": "network", + "librewolf": "desktop", + "limnoria": "communication", + "lm-studio": "ai", + "lollypop": "media", + "luanti": "gaming", + "mame": "gaming", + "mediaelch": "media", + "melonds": "gaming", + "mineos-node": "gaming", + "minisatip": "media", + "mongodb4": "databases", + "msedge": "desktop", + "mstream": "media", + "mullvad-browser": "desktop", + "mysql-workbench": "databases", + "nextcloud": "productivity", + "nginx": "web", + "ngircd": "communication", + "nzbhydra2": "arr", + "obsidian": "documents", + "openshot": "creative", + "openssh-server": "remote", + "openvscode-server": "ai", + "opera": "desktop", + "orcaslicer": "creative", + "oscam": "media", + "pcsx2": "gaming", + "pelorus": "ai", + "pidgin": "communication", + "piper": "ai", + "piwigo": "media", + "ppsspp": "gaming", + "pwndrop": "downloads", + "pycharm": "ai", + "pydio-cells": "downloads", + "pyload-ng": "downloads", + "qdirstat": "tools", + "raneto": "documents", + "rawtherapee": "creative", + "remmina": "remote", + "resilio-sync": "downloads", + "retroarch": "gaming", + "retroarch-inglebard": "gaming", + "rpcs3": "gaming", + "rsnapshot": "backup", + "rustdesk": "remote", + "scummvm": "gaming", + "sealskin": "desktop", + "shadps4": "gaming", + "shotcut": "creative", + "sickgear": "arr", + "signal": "communication", + "spotube": "media", + "sqlitebrowser": "databases", + "steam": "gaming", + "swag": "web", + "synclounge": "media", + "syslog-ng": "monitoring", + "telegram": "communication", + "thelounge": "communication", + "thunderbird": "communication", + "tvheadend": "media", + "ubooquity": "media", + "ungoogled-chromium": "desktop", + "unifi-network-application": "network", + "virt-manager": "management", + "vivaldi": "desktop", + "vlc": "media", + "vscode": "ai", + "vscodium": "ai", + "vscodium-web": "ai", + "webcord": "communication", + "webgrabplus": "media", + "webstation": "desktop", + "webtop": "desktop", + "weixin": "communication", + "winegui": "desktop", + "wireshark": "network", + "wps-office": "documents", + "xbackbone": "downloads", + "xemu": "gaming", + "yaak": "ai", + "your_spotify": "media", + "zen": "desktop", + "znc": "communication", + "zotero": "documents" + } +} diff --git a/oci/catalog/curated/amule.json b/oci/catalog/curated/amule.json new file mode 100644 index 00000000..fa3df805 --- /dev/null +++ b/oci/catalog/curated/amule.json @@ -0,0 +1,465 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "image-amule", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "aMule" + }, + "tagline": { + "en_US": "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule." + }, + "description": { + "en_US": "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "ngosang", + "developer": "ngosang", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 4711, + "path": "/" + }, + "website": "https://github.com/amule-org/amule", + "documentation": "https://github.com/ngosang/docker-amule", + "repository": "https://github.com/ngosang/docker-amule", + "tips": [ + "Configuration stays on a private managed Proxmox volume with backup enabled. Downloads may use a managed volume or an explicitly selected host directory.", + "Completed files use /downloads/incoming; incomplete files use /downloads/temp. Keeping both under one mount preserves moves on the same filesystem.", + "GUI_PWD and WEBUI_PWD are required upstream passwords, not built-in credentials. The web login requests no username.", + "Optional MOD variables are upstream features, not LinuxServer mods. They are not enabled automatically by this template.", + "Do not expose HTTP port 4711 or External Connections port 4712 directly to the Internet. Router port forwarding is a separate user action; this installer does not change the router." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-18" + }, + "source": { + "provider": "ngosang", + "repository": "https://github.com/ngosang/docker-amule", + "default_branch": "master", + "revision": "356d94c46b8e1d02eac35ca23875d15fc01864d8", + "readme_raw_url": "https://raw.githubusercontent.com/ngosang/docker-amule/356d94c46b8e1d02eac35ca23875d15fc01864d8/README.md", + "readme_pushed_at": "2026-09-18", + "compose_sha256": "c491822b91bc3e0e8af1e63f3e3cf5f1659185688afc7d9510034924662a51e6", + "generated_at": "2026-09-18T20:05:19+00:00" + }, + "container_contract": { + "service_name": "amule", + "container_name": "amule", + "image": { + "reference": "ngosang/amule:latest", + "registry": "docker.io", + "repository": "ngosang/amule", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "TZ", + "example": "Europe/London", + "required": true, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "GUI_PWD", + "example": "", + "required": true, + "sensitive": true, + "source": "upstream-compose", + "prompt": "Password for aMule external connections (remote client)" + }, + { + "name": "WEBUI_PWD", + "example": "", + "required": true, + "sensitive": true, + "source": "upstream-compose", + "prompt": "Password to access the aMule web interface" + }, + { + "name": "MOD_AUTO_RESTART_ENABLED", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "MOD_AUTO_RESTART_CRON", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "MOD_AUTO_SHARE_ENABLED", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-compose" + }, + { + "name": "MOD_AUTO_SHARE_DIRECTORIES", + "example": "", + "required": false, + "sensitive": false, + "source": "upstream-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/home/amule/.aMule", + "compose_source_example": "", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/downloads", + "compose_source_example": "", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 4711, + "published_example": 4711, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4712, + "published_example": 4712, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4662, + "published_example": 4662, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4665, + "published_example": 4665, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4672, + "published_example": 4672, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n amule:\n image: ngosang/amule\n container_name: amule\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Europe/London\n - GUI_PWD=\n - WEBUI_PWD=\n - MOD_AUTO_RESTART_ENABLED=true\n - MOD_AUTO_RESTART_CRON=0 6 * * *\n - MOD_AUTO_SHARE_ENABLED=false\n - MOD_AUTO_SHARE_DIRECTORIES=/downloads/incoming;/my_movies\n ports:\n - \"4711:4711\" # Web UI and REST API (amuleapi)\n - \"4712:4712\" # External connections (amuleapi, amulegui, amulecmd)\n - \"4662:4662\" # ED2K client-to-client TCP (required for High ID)\n - \"4665:4665/udp\" # ED2K server UDP (global searches, TCP port +3)\n - \"4672:4672/udp\" # Extended eMule protocol and Kademlia UDP\n volumes:\n - :/home/amule/.aMule\n - :/downloads\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 4711, + "path": "/", + "source": "upstream-documentation" + } + ], + "credentials": [ + { + "label": "aMule WebUI (password only, no username)", + "type": "configured-or-installer-generated", + "username": "Not required (password only)", + "password": null, + "password_environment": "WEBUI_PWD", + "change_required": false, + "source": "https://github.com/ngosang/docker-amule" + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "device_requests": [], + "startup_healthcheck": { + "scheme": "http", + "port": 4711, + "path": "/", + "timeout_seconds": 600, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "mem_limit", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "ulimits", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Reviewed official single-image mapping. Validated on amd64: clean install, authenticated web login, same-digest recreation and interrupted-candidate recovery with managed configuration and downloads. Cross-release migration, arm64 runtime and P2P downloads not tested." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "authenticated_login": "passed-after-recovery-amd64", + "restart_persistence": "passed-through-recreation-amd64", + "backup_restore": "passed-managed-configuration-and-downloads-amd64", + "update_preserves_data": "passed-same-digest-recreation-amd64", + "cross_release_upgrade": "not-tested", + "p2p_download": "not-tested", + "evidence": "docs/lab/new-images-validation-20260918.json" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/codeproject-ai.json b/oci/catalog/curated/codeproject-ai.json new file mode 100644 index 00000000..4bace122 --- /dev/null +++ b/oci/catalog/curated/codeproject-ai.json @@ -0,0 +1,417 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-codeproject-ai", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "CodeProject.AI Server" + }, + "tagline": { + "en_US": "CodeProject.AI Server" + }, + "description": { + "en_US": "Official latest CPU image with persistent settings and modules. Initial CPU and Coral PCIe inference passed on Intel amd64. Coral module uses its persistent upstream EdgeTPU runtime via module-scoped LD_PRELOAD; missing JSON defaults preserve existing user settings. The TPU needs exclusive access. ARM and NVIDIA channels are not offered by this template; Failures observed on the AMD lab host remain unexplained; no blanket AMD incompatibility is inferred." + }, + "category": "ai", + "category_label": "AI", + "author": "codeproject", + "developer": "codeproject", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 32168, + "path": "/" + }, + "website": "https://github.com/codeproject/CodeProject.AI-Server", + "documentation": "https://github.com/codeproject/CodeProject.AI-Server", + "repository": "https://github.com/codeproject/CodeProject.AI-Server", + "tips": [ + "Official latest CPU image with persistent settings and modules. Initial CPU and Coral PCIe inference passed on Intel amd64. Coral module uses its persistent upstream EdgeTPU runtime via module-scoped LD_PRELOAD; missing JSON defaults preserve existing user settings. The TPU needs exclusive access. ARM and NVIDIA channels are not offered by this template; Failures observed on the AMD lab host remain unexplained; no blanket AMD incompatibility is inferred.", + "Install ObjectDetectionCoral in the dashboard. Stop competing object detectors when assigning its detection route; exposing a device does not configure an inference module." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-16", + "hidden": true, + "hidden_reason": "Temporarily withdrawn at user request pending further hardware validation." + }, + "source": { + "provider": "codeproject", + "repository": "https://github.com/codeproject/CodeProject.AI-Server", + "default_branch": "main", + "revision": "e3468c831b169e27ed6c97f665f1efb48ab0285f", + "readme_raw_url": "https://raw.githubusercontent.com/codeproject/CodeProject.AI-Server/e3468c831b169e27ed6c97f665f1efb48ab0285f/README.md", + "image_repository_url": "https://hub.docker.com/r/codeproject/ai-server", + "compose_sha256": "a8ce9bcbde2cbc0fc9a840b93bab72a33da2a2f4a18857896b837cbc7f462ece", + "generated_at": "2026-09-16T22:00:00+02:00" + }, + "container_contract": { + "service_name": "codeproject-ai", + "container_name": "codeproject-ai", + "image": { + "reference": "codeproject/ai-server:latest", + "registry": "docker.io", + "repository": "codeproject/ai-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "config", + "container_path": "/etc/codeproject/ai", + "compose_source_example": "config-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "modules", + "container_path": "/app/modules", + "compose_source_example": "modules-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 16 + } + } + ], + "ports": [ + { + "container_port": 32168, + "published_example": 32168, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "{\n \"services\": {\n \"codeproject-ai\": {\n \"image\": \"codeproject/ai-server:latest\",\n \"volumes\": [\n \"config-data:/etc/codeproject/ai\",\n \"modules-data:/app/modules\"\n ],\n \"ports\": [\n \"32168:32168\"\n ],\n \"environment\": {},\n \"restart\": \"unless-stopped\"\n }\n }\n}" + }, + "compose_stack": { + "project_name": "mkvtoolnix", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mkvtoolnix", + "service_count": 1, + "services": [ + { + "name": "mkvtoolnix", + "image": "jlesage/mkvtoolnix:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/mkvtoolnix:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "mkvtoolnix-config:/config", + "/mnt/oci-shared/media:/storage" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mkvtoolnix-config", + "service": "mkvtoolnix", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "mkvtoolnix-storage", + "service": "mkvtoolnix", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mkvtoolnix" + ], + "stop_order": [ + "mkvtoolnix" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "passed-amd64-intel" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "not-required" + }, + { + "id": "persistent-coral-module-runtime", + "upstream_behavior": "The official Coral module downloads the EdgeTPU runtime into its module folder, then copies a library into /usr/lib.", + "native_lxc_behavior": "Module-scoped LD_PRELOAD points to the same upstream runtime retained in /app/modules. Missing defaults are merged into the official /etc/codeproject/ai/modulesettings.json.", + "reason": "A new image rootfs does not retain libraries installed after image creation, in Docker or native OCI.", + "behavioral_impact": "Only ObjectDetectionCoral receives this setting; existing user overrides are preserved. No image files or host drivers are changed.", + "validation": "passed-installer-recreation-and-coral-inference-amd64-intel" + } + ], + "installer_profile": { + "optional_devices": [ + { + "id": "coral-pcie", + "kind": "character-device", + "enable_prompt": "Add a Coral PCIe/M.2 device?", + "enabled_default": false, + "path_prompt": "Coral PCIe/M.2 node (e.g. /dev/apex_0)", + "host_path_default": "/dev/apex_0", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 32168, + "path": "/", + "timeout_seconds": 300, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "generated_files": [ + { + "container_path": "/etc/codeproject/ai/modulesettings.json", + "mode": "0644", + "owner": "mapped-root", + "only_if_missing": true, + "json_defaults": true, + "content": "{\n \"Modules\": {\n \"ObjectDetectionCoral\": {\n \"EnvironmentVariables\": {\n \"LD_PRELOAD\": \"/app/modules/ObjectDetectionCoral/edgetpu_runtime/libedgetpu/throttled/k8/libedgetpu.so.1.0\"\n },\n \"LaunchSettings\": {\n \"AutoStart\": false\n }\n }\n }\n}\n" + } + ], + "hardware_acceleration": { + "prompt": "Acceleration for CodeProject.AI", + "default": "cpu", + "profiles": [ + { + "id": "cpu", + "label": "CPU", + "device_requests": [], + "image": { + "reference": "codeproject/ai-server:latest", + "registry": "docker.io", + "repository": "codeproject/ai-server", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + } + }, + { + "id": "nvidia", + "label": "NVIDIA (CUDA; official GPU image)", + "image": { + "reference": "codeproject/ai-server:gpu", + "registry": "docker.io", + "repository": "codeproject/ai-server", + "tag": "gpu", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + }, + { + "name": "NVIDIA_DRIVER_CAPABILITIES", + "value": "compute,utility" + } + ] + } + ] + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "Official latest CPU image with persistent settings and modules. Initial CPU and Coral PCIe inference passed on Intel amd64. Coral module uses its persistent upstream EdgeTPU runtime via module-scoped LD_PRELOAD; missing JSON defaults preserve existing user settings. The TPU needs exclusive access. ARM and NVIDIA channels are not offered by this template; Failures observed on the AMD lab host remain unexplained; no blanket AMD incompatibility is inferred. NVIDIA uses the official gpu channel with native Toolkit integration; inference validation pending. Intel/AMD GPU inference is not advertised without an upstream compatible module/runtime." + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 32168, + "path": "/", + "source": "https://github.com/codeproject/CodeProject.AI-Server" + } + ], + "credentials": [] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64-intel", + "service_health": "passed-amd64-intel", + "restart_persistence": "passed-amd64-intel", + "backup_restore": "passed-interrupted-candidate-native-recovery", + "update_preserves_data": "passed-same-digest-rootfs-recreation", + "evidence": "docs/lab/new-images-validation-20260918.json" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/docker-volume-backup.json b/oci/catalog/curated/docker-volume-backup.json new file mode 100644 index 00000000..7bbb24bf --- /dev/null +++ b/oci/catalog/curated/docker-volume-backup.json @@ -0,0 +1,328 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-docker-volume-backup", + "status": "generated-review-required", + "catalog_ui": { + "title": { + "en_US": "Docker Volume Backup" + }, + "tagline": { + "en_US": "Docker Volume Backup" + }, + "description": { + "en_US": "Requires real Docker daemon/socket and Docker Compose stacks; cannot back up native Proxmox OCI instances as Docker volumes. Hidden pending explicit external Docker integration; no Docker installed on Proxmox." + }, + "category": "tools", + "category_label": "Tools", + "author": "mrcaringi", + "developer": "mrcaringi", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://github.com/MrCaringi/docker-volume-backup", + "documentation": "https://github.com/MrCaringi/docker-volume-backup", + "repository": "https://github.com/MrCaringi/docker-volume-backup", + "tips": [ + "Requires real Docker daemon/socket and Docker Compose stacks; cannot back up native Proxmox OCI instances as Docker volumes. Hidden pending explicit external Docker integration; no Docker installed on Proxmox." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-16", + "hidden": true, + "hidden_reason": "Requires a real Docker daemon and Compose stacks; native OCI instances are not Docker volumes." + }, + "source": { + "provider": "mrcaringi", + "repository": "https://github.com/MrCaringi/docker-volume-backup", + "default_branch": "main", + "revision": "a12dbb8770687a5f8127fe9843e83755d3addbb6", + "readme_raw_url": "https://raw.githubusercontent.com/MrCaringi/docker-volume-backup/a12dbb8770687a5f8127fe9843e83755d3addbb6/README.md", + "image_repository_url": "https://hub.docker.com/r/mrcaringi/docker-volume-backup", + "compose_sha256": "28758bdfd464f5d2ae5ae88ed334f2b6fe842642ca189548086f0c64a76882ef", + "generated_at": "2026-09-16T22:00:00+02:00" + }, + "container_contract": { + "service_name": "docker-volume-backup", + "container_name": "docker-volume-backup", + "image": { + "reference": "mrcaringi/docker-volume-backup:latest", + "registry": "docker.io", + "repository": "mrcaringi/docker-volume-backup", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "CRON_SCHEDULE", + "example": "0 2 * * *", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": true + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": true + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "config-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "backups", + "container_path": "/backup", + "compose_source_example": "/mnt/oci-shared/backups", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "# docker-compose.yml\nservices:\n container-backups:\n image: mrcaringi/docker-volume-backup:latest\n container_name: container-backups\n hostname: myserver # shown in Telegram notifications\n restart: always\n environment:\n CRON_SCHEDULE: \"0 2 * * *\"\n volumes:\n - /var/run/docker.sock:/var/run/docker.sock\n - ./config.json:/config/config.json:ro\n - /path/to/backups:/backup\n # Mount stack directories at the same path used in config.json\n - /home/user/docker/stacks:/home/user/docker/stacks:ro\n" + }, + "compose_stack": { + "project_name": "mkvtoolnix", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mkvtoolnix", + "service_count": 1, + "services": [ + { + "name": "mkvtoolnix", + "image": "jlesage/mkvtoolnix:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/mkvtoolnix:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "mkvtoolnix-config:/config", + "/mnt/oci-shared/media:/storage" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mkvtoolnix-config", + "service": "mkvtoolnix", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "mkvtoolnix-storage", + "service": "mkvtoolnix", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mkvtoolnix" + ], + "stop_order": [ + "mkvtoolnix" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "pending-clean-install" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "not-required" + } + ], + "installer_profile": {}, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": false, + "validated": false, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [ + "docker-engine-required-no-native-oci-stack-support" + ], + "policy": "Requires real Docker daemon/socket and Docker Compose stacks; cannot back up native Proxmox OCI instances as Docker volumes. Hidden pending explicit external Docker integration; no Docker installed on Proxmox." + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/emby-official.json b/oci/catalog/curated/emby-official.json new file mode 100644 index 00000000..4ba13fca --- /dev/null +++ b/oci/catalog/curated/emby-official.json @@ -0,0 +1,481 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "image-emby-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Emby Official" + }, + "tagline": { + "en_US": "Official Emby Media Server image with optional VA-API or NVIDIA acceleration." + }, + "description": { + "en_US": "Emby is a personal media management platform that brings home videos, music, and photos together, automatically converting and streaming to any device. An intuitive design makes it ideal for users to enjoy media content anytime, anywhere, meeting family entertainment and media management needs.\n\nCore features include cross-device media streaming and easy access. It supports real-time conversion and streaming of personal media to any device for seamless playback. A connection service enables easy media access while away from home. Live TV functionality supports streaming, managing DVR, and accessing a library of recordings. Mobile sync delivers media to smartphones and tablets for offline access, automatically updating new content.\n\nIt offers parental controls to restrict children's content access, set schedules and time limits, and remotely monitor sessions. Chromecast support enables easy streaming of videos, music, photos, and Live TV. Content is presented elegantly, enhancing visual experience. Cloud sync supports backup, archiving, and multi-resolution storage for optimized streaming. Web-based media management facilitates editing metadata, images, and searching subtitles, while DLNA integration auto-detects network devices for content streaming. With convenience and versatility at the core, the platform delivers a modern media management solution.\n\n**Key Features:**\n- Automatic conversion and streaming of media to any device\n- Easy access via connection service while away from home\n- Live TV streaming, DVR management, and recording library access\n- Mobile sync to smartphones and tablets for offline access\n- Parental controls with content restrictions, schedules, and remote monitoring\n- Chromecast support for streaming videos, music, photos, and Live TV\n- Cloud sync for backup and multi-resolution storage\n- Web-based media management for editing metadata and searching subtitles\n- DLNA integration for auto-detecting network devices and streaming content\n\n**Learn More:**\n- [Emby Official Website](https://emby.media/)\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Emby Team", + "developer": "Emby Team", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8096, + "path": "/" + }, + "website": "https://emby.media/", + "documentation": "https://hub.docker.com/r/emby/embyserver", + "repository": "https://hub.docker.com/r/emby/embyserver", + "tips": [ + "UID, GID and GIDLIST follow the official image contract.", + "The installer adds the selected render-device GID to GIDLIST for VA-API access.", + "Emby documents VA-API and NVDEC/NVENC support for amd64 only." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "emby", + "repository": "https://hub.docker.com/r/emby/embyserver", + "default_branch": "master", + "revision": "f324967b88a13e1075d6aa6debe31a955a7c6b47abe4c2d34342bc9d1d964518", + "image_repository_url": "https://hub.docker.com/r/emby/embyserver", + "compose_sha256": "b960d39e446660d21c2e88e89d6ae2ce3e1294c31d9d4ee18b8a94c7b9e8d786", + "generated_at": "2026-09-13T21:08:59+00:00" + }, + "container_contract": { + "service_name": "emby", + "container_name": "embyserver", + "image": { + "reference": "emby/embyserver:latest", + "registry": "docker.io", + "repository": "emby/embyserver", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "UID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "UID that Emby runs as" + }, + { + "name": "GID", + "example": "100", + "required": true, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Primary GID for Emby" + }, + { + "name": "GIDLIST", + "example": "100", + "required": true, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Additional media/GPU GIDs, comma-separated" + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "/path/to/programdata", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "tvshows", + "container_path": "/mnt/share1", + "compose_source_example": "/path/to/tvshows", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 32 + } + }, + { + "id": "movies", + "container_path": "/mnt/share2", + "compose_source_example": "/path/to/movies", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 8096, + "published_example": 8096, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8920, + "published_example": 8920, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 7359, + "published_example": 7359, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 1900, + "published_example": 1900, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "on-failure", + "stop_grace_period": null, + "original_compose": "services:\n emby:\n image: emby/embyserver:latest\n container_name: embyserver\n environment:\n - UID=1000\n - GID=100\n - GIDLIST=100\n volumes:\n - /path/to/programdata:/config\n - /path/to/tvshows:/mnt/share1\n - /path/to/movies:/mnt/share2\n ports:\n - 8096:8096/tcp\n - 8920:8920/tcp\n restart: on-failure\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Emby WebUI", + "scheme": "http", + "port": 8096, + "path": "/", + "source": "official-container-documentation" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Emby", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [], + "architectures": [ + "amd64", + "arm64" + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "append_host_device_gid_to_environment": "GIDLIST" + } + ], + "architectures": [ + "amd64" + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose", + "append_host_device_gid_to_environment": "GIDLIST" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ], + "architectures": [ + "amd64" + ] + } + ] + }, + "startup_healthcheck": { + "scheme": "http", + "port": 8096, + "path": "/", + "timeout_seconds": 240, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "catalog": { + "replaces_discovered_ids": [ + "emby", + "emby-nvidia" + ] + }, + "application_options": { + "hardware_transcoding": { + "show_in_catalog": true, + "selectable": true, + "documented_acceleration_architectures": [ + "amd64" + ], + "backends": [ + "VA-API", + "NVDEC/NVENC" + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/filebrowser-quantum.json b/oci/catalog/curated/filebrowser-quantum.json new file mode 100644 index 00000000..2e9053a6 --- /dev/null +++ b/oci/catalog/curated/filebrowser-quantum.json @@ -0,0 +1,390 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-filebrowser-quantum", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "FileBrowser Quantum" + }, + "tagline": { + "en_US": "FileBrowser Quantum" + }, + "description": { + "en_US": "Official image with managed persistent configuration and selectable content storage. Validated on amd64: clean install, authenticated login, same-digest recreation and interrupted-candidate recovery. Cross-release migration and arm64 runtime not tested." + }, + "category": "tools", + "category_label": "Tools", + "author": "gtsteffaniak", + "developer": "gtsteffaniak", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/gtsteffaniak/filebrowser", + "documentation": "https://github.com/gtsteffaniak/filebrowser", + "repository": "https://github.com/gtsteffaniak/filebrowser", + "tips": [ + "Official image with managed persistent configuration and selectable content storage. Validated on amd64: clean install, authenticated login, same-digest recreation and interrupted-candidate recovery. Cross-release migration and arm64 runtime not tested." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-16", + "hidden": false + }, + "source": { + "provider": "gtsteffaniak", + "repository": "https://github.com/gtsteffaniak/filebrowser", + "default_branch": "main", + "revision": "fa58eac9c06d769597652712ef9f093971a916d1", + "readme_raw_url": "https://raw.githubusercontent.com/gtsteffaniak/filebrowser/fa58eac9c06d769597652712ef9f093971a916d1/README.md", + "image_repository_url": "https://hub.docker.com/r/gtstef/filebrowser", + "compose_sha256": "1bc09f5ad7bf878a96e53861e52e6274ebc335ed63933b7e195dab0321ce5cdd", + "generated_at": "2026-09-16T22:00:00+02:00" + }, + "container_contract": { + "service_name": "filebrowser-quantum", + "container_name": "filebrowser-quantum", + "image": { + "reference": "gtstef/filebrowser:latest", + "registry": "docker.io", + "repository": "gtstef/filebrowser", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "FILEBROWSER_ADMIN_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "upstream-documentation", + "prompt_user": true + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/home/filebrowser/data", + "compose_source_example": "config-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "files", + "container_path": "/folder", + "compose_source_example": "/mnt/oci-shared/files", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "{\n \"services\": {\n \"filebrowser-quantum\": {\n \"image\": \"gtstef/filebrowser:latest\",\n \"volumes\": [\n \"config-data:/home/filebrowser/data\",\n \"/mnt/oci-shared/files:/folder\"\n ],\n \"ports\": [\n \"80:80\"\n ],\n \"environment\": {\n \"FILEBROWSER_ADMIN_PASSWORD\": \"\"\n },\n \"restart\": \"unless-stopped\"\n }\n }\n}" + }, + "compose_stack": { + "project_name": "mkvtoolnix", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mkvtoolnix", + "service_count": 1, + "services": [ + { + "name": "mkvtoolnix", + "image": "jlesage/mkvtoolnix:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/mkvtoolnix:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "mkvtoolnix-config:/config", + "/mnt/oci-shared/media:/storage" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mkvtoolnix-config", + "service": "mkvtoolnix", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "mkvtoolnix-storage", + "service": "mkvtoolnix", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mkvtoolnix" + ], + "stop_order": [ + "mkvtoolnix" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "passed-amd64-install-recreate-recovery" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "not-required" + } + ], + "installer_profile": { + "volume_owner": { + "uid": 1000, + "gid": 1000 + }, + "volume_preparations": [ + { + "container_path": "/home/filebrowser/data", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/folder", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "security": { + "sysctls": [ + { + "name": "net.ipv4.ip_unprivileged_port_start", + "value": "0" + } + ] + }, + "generated_files": [ + { + "container_path": "/home/filebrowser/data/config.yaml", + "mode": "0644", + "owner": "mapped-application-user", + "only_if_missing": true, + "content": "server:\n port: 80\n cacheDir: /home/filebrowser/data/tmp\n sources:\n - path: /folder\n config:\n defaultEnabled: true\nauth:\n adminUsername: admin\n" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 80, + "path": "/health", + "timeout_seconds": 300, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "Official image with managed persistent configuration and selectable content storage. Validated on amd64: clean install, authenticated login, same-digest recreation and interrupted-candidate recovery. Cross-release migration and arm64 runtime not tested." + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "https://github.com/gtsteffaniak/filebrowser" + } + ], + "credentials": [ + { + "label": "FileBrowser Quantum (new installation)", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "password_environment": "FILEBROWSER_ADMIN_PASSWORD", + "change_required": false, + "source": "https://filebrowserquantum.com/en/docs/reference/cli/" + } + ] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-amd64", + "service_health": "passed-amd64", + "restart_persistence": "passed-through-recreation-amd64", + "backup_restore": "passed-managed-configuration-amd64", + "update_preserves_data": "passed-same-digest-recreation-amd64", + "cross_release_upgrade": "not-tested", + "evidence": "docs/lab/new-images-validation-20260918.json" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/fileflows.json b/oci/catalog/curated/fileflows.json new file mode 100644 index 00000000..1fe6b595 --- /dev/null +++ b/oci/catalog/curated/fileflows.json @@ -0,0 +1,627 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-fileflows", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "FileFlows" + }, + "tagline": { + "en_US": "File processing made easy!" + }, + "description": { + "en_US": "Save storage space with efficient file processing.\n\nFileFlows lets you monitor and process any file type with custom flows. Videos, audio, images, archives, comics, eBooks—you name it!\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "FileFlows", + "developer": "FileFlows", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5000, + "path": "/" + }, + "website": "https://fileflows.com/", + "documentation": null, + "repository": "https://hub.docker.com/r/revenz/fileflows", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "revenz", + "repository": "https://hub.docker.com/r/revenz/fileflows", + "revision": "59ca91536e4ddd94579fc78e432226f1d03651e0d289108b3482ac9da729c628", + "image_repository_url": "https://hub.docker.com/r/revenz/fileflows", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "59ca91536e4ddd94579fc78e432226f1d03651e0d289108b3482ac9da729c628", + "generated_at": "2026-09-13T15:34:58+00:00" + }, + "container_contract": { + "service_name": "fileflows", + "container_name": "fileflows", + "image": { + "reference": "revenz/fileflows:latest", + "registry": "docker.io", + "repository": "revenz/fileflows", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/Data", + "compose_source_example": "/DATA/AppData/$AppID/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/app/Logs", + "compose_source_example": "/DATA/AppData/$AppID/logs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/app/common", + "compose_source_example": "/DATA/AppData/$AppID/common", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/temp", + "compose_source_example": "/DATA/AppData/$AppID/temp", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-4", + "container_path": "/Media", + "compose_source_example": "/DATA/Media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-5", + "container_path": "/var/run/docker.sock", + "compose_source_example": "/var/run/docker.sock", + "read_only": false, + "required": false, + "installation_choice": [ + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5000, + "published_example": 19200, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: fileflows\nservices:\n fileflows:\n container_name: fileflows\n devices:\n - /dev/dri:/dev/dri\n environment:\n PGID: $PGID\n PUID: $PUID\n TZ: $TZ\n hostname: fileflows\n image: revenz/fileflows:latest\n restart: unless-stopped\n ports:\n - target: 5000\n published: '19200'\n protocol: tcp\n network_mode: bridge\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /app/Data\n - type: bind\n source: /DATA/AppData/$AppID/logs\n target: /app/Logs\n - type: bind\n source: /DATA/AppData/$AppID/common\n target: /app/common\n - type: bind\n source: /DATA/AppData/$AppID/temp\n target: /temp\n - type: bind\n source: /DATA/Media\n target: /Media\n - type: bind\n source: /var/run/docker.sock\n target: /var/run/docker.sock\n" + }, + "compose_stack": { + "project_name": "fileflows", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "fileflows", + "service_count": 1, + "services": [ + { + "name": "fileflows", + "image": "revenz/fileflows:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "fileflows", + "devices": [ + "/dev/dri:/dev/dri" + ], + "environment": { + "PGID": "$PGID", + "PUID": "$PUID", + "TZ": "$TZ" + }, + "hostname": "fileflows", + "image": "revenz/fileflows:latest", + "restart": "unless-stopped", + "ports": [ + { + "target": 5000, + "published": "19200", + "protocol": "tcp" + } + ], + "network_mode": "bridge", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/data", + "target": "/app/Data" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/logs", + "target": "/app/Logs" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/common", + "target": "/app/common" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/temp", + "target": "/temp" + }, + { + "type": "bind", + "source": "/DATA/Media", + "target": "/Media" + }, + { + "type": "bind", + "source": "/var/run/docker.sock", + "target": "/var/run/docker.sock" + } + ] + } + } + ], + "top_level": { + "name": "fileflows" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "fileflows-volume-0", + "service": "fileflows", + "container_path": "/app/Data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "fileflows-volume-1", + "service": "fileflows", + "container_path": "/app/Logs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "fileflows-volume-2", + "service": "fileflows", + "container_path": "/app/common", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "fileflows-volume-3", + "service": "fileflows", + "container_path": "/temp", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "fileflows-volume-4", + "service": "fileflows", + "container_path": "/Media", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for fileflows:/Media" + }, + { + "id": "fileflows-volume-5", + "service": "fileflows", + "container_path": "/var/run/docker.sock", + "mode": "runtime-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "fileflows" + ], + "stop_order": [ + "fileflows" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5000, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "hostname": "fileflows" + }, + "hardware_acceleration": { + "prompt": "Hardware acceleration for FileFlows", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ] + } + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "catalog": { + "replaces_discovered_ids": [ + "fileflows" + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/frigate.json b/oci/catalog/curated/frigate.json new file mode 100644 index 00000000..17a212d7 --- /dev/null +++ b/oci/catalog/curated/frigate.json @@ -0,0 +1,1130 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-frigate", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Frigate" + }, + "tagline": { + "en_US": "NVR with optional VA-API video acceleration and hardware object detectors" + }, + "description": { + "en_US": "Frigate adapted as a native Proxmox OCI LXC with persistent configuration, selectable recording storage, tmpfs cache and optional GPU or detector devices." + }, + "category": "nvr", + "category_label": "NVR & Cameras", + "author": "Frigate", + "developer": "Frigate", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5000, + "path": "/" + }, + "website": "https://frigate.video/", + "documentation": "https://docs.frigate.video/", + "repository": "https://github.com/blakeblackshear/frigate", + "tips": [ + "The template installs infrastructure only and never bundles cameras or a Frigate configuration file.", + "VA-API accelerates video decode/encode; it is separate from object detection with Coral, OpenVINO, ROCm or TensorRT.", + "The rolling stable image is kept intact. If unrelated native modules fail intermittently, validate host RAM and CPU stability before changing packages inside the image.", + "GPU passthrough is independent of Coral. Configure Frigate FFmpeg hwaccel_args using preset-vaapi or preset-nvidia; passing devices does not change existing camera configuration. NVIDIA channel workload validation pending." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-12" + }, + "source": { + "provider": "frigate", + "repository": "https://github.com/blakeblackshear/frigate", + "revision": "37f338d5d6d0c8a117a262aacb7e6184660fd157", + "image_repository_url": "https://ghcr.io/blakeblackshear/frigate", + "readme_pushed_at": "2026-09-12T13:30:04Z", + "compose_sha256": "2aa1dc599c69aaac422305d0d653e3980080f2491ca74e615d08b0e9f402b722", + "generated_at": "2026-09-12T15:58:20+00:00", + "default_branch": "dev", + "readme_raw_url": "https://raw.githubusercontent.com/blakeblackshear/frigate/dev/README.md" + }, + "container_contract": { + "service_name": "frigate", + "container_name": "frigate", + "image": { + "reference": "ghcr.io/blakeblackshear/frigate:stable", + "registry": "ghcr.io", + "repository": "ghcr.io/blakeblackshear/frigate", + "tag": "stable", + "digest": null, + "pull_policy": "resolve-rolling-stable-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/etc/localtime", + "compose_source_example": "/etc/localtime", + "read_only": true, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 1 + } + }, + { + "id": "volume-1", + "container_path": "/config", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/media/frigate", + "compose_source_example": "/mnt/oci-shared/recordings/frigate", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 100 + } + } + ], + "ports": [ + { + "container_port": 8971, + "published_example": 8971, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8554, + "published_example": 8554, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8555, + "published_example": 8555, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8555, + "published_example": 8555, + "protocol": "udp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": "30s", + "original_compose": "name: frigate\nservices:\n frigate:\n container_name: frigate\n image: ghcr.io/blakeblackshear/frigate:stable\n deploy:\n resources:\n reservations:\n memory: 256M\n devices:\n - /dev/bus/usb:/dev/bus/usb\n - /dev/apex_0:/dev/apex_0\n - /dev/video11:/dev/video11\n - /dev/dri/renderD128:/dev/dri/renderD128\n network_mode: bridge\n privileged: true\n ports:\n - target: 8971\n published: '8971'\n protocol: tcp\n - target: 8554\n published: '8554'\n protocol: tcp\n - target: 8555\n published: '8555'\n protocol: tcp\n - target: 8555\n published: '8555'\n protocol: udp\n restart: unless-stopped\n stop_grace_period: 30s\n shm_size: 512mb\n tmpfs:\n - /tmp/cache:size=1000000000\n volumes:\n - type: bind\n source: /etc/localtime\n target: /etc/localtime\n read_only: true\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /config\n - type: bind\n source: /DATA/Media\n target: /media/frigate\n" + }, + "compose_stack": { + "project_name": "frigate", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "frigate", + "service_count": 1, + "services": [ + { + "name": "frigate", + "image": "ghcr.io/blakeblackshear/frigate:stable", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "frigate", + "image": "ghcr.io/blakeblackshear/frigate:stable", + "deploy": { + "resources": { + "reservations": { + "memory": "256M" + } + } + }, + "devices": [ + "/dev/bus/usb:/dev/bus/usb", + "/dev/apex_0:/dev/apex_0", + "/dev/video11:/dev/video11", + "/dev/dri/renderD128:/dev/dri/renderD128" + ], + "network_mode": "bridge", + "privileged": true, + "ports": [ + { + "target": 8971, + "published": "8971", + "protocol": "tcp" + }, + { + "target": 8554, + "published": "8554", + "protocol": "tcp" + }, + { + "target": 8555, + "published": "8555", + "protocol": "tcp" + }, + { + "target": 8555, + "published": "8555", + "protocol": "udp" + } + ], + "restart": "unless-stopped", + "stop_grace_period": "30s", + "shm_size": "512mb", + "tmpfs": [ + "/tmp/cache:size=1000000000" + ], + "volumes": [ + { + "type": "bind", + "source": "/etc/localtime", + "target": "/etc/localtime", + "read_only": true + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/config" + }, + { + "type": "bind", + "source": "/DATA/Media", + "target": "/media/frigate" + } + ] + } + } + ], + "top_level": { + "name": "frigate" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "frigate-volume-0", + "service": "frigate", + "container_path": "/etc/localtime", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/localtime", + "source_path_prompt": null + }, + { + "id": "frigate-volume-1", + "service": "frigate", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "frigate-volume-2", + "service": "frigate", + "container_path": "/media/frigate", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for frigate:/media/frigate" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "frigate" + ], + "stop_order": [ + "frigate" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Frigate WebUI", + "scheme": "http", + "port": 5000, + "path": "/", + "source": "laboratory-validated-native-oci-endpoint" + }, + { + "label": "go2rtc WebUI", + "scheme": "http", + "port": 1984, + "path": "/", + "source": "integrated-go2rtc-native-oci-endpoint" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "frigate" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 4, + "cpuset_requirement": "none-for-current-openvino-lxc-repair", + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 16, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": false, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-user-values", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "persistent-config-and-recording-storage", + "upstream_behavior": "Docker mounts /config and /media/frigate.", + "native_lxc_behavior": "Use a backup-enabled managed volume for /config and let the user choose a managed volume or host bind for /media/frigate.", + "reason": "Configuration is private state while recordings can be large shared data.", + "behavioral_impact": "Recordings are excluded from vzdump by default.", + "validation": "passed-laboratory-profile" + }, + { + "id": "tmpfs-cache", + "upstream_behavior": "The official Compose mounts a bounded tmpfs at /tmp/cache.", + "native_lxc_behavior": "Create the equivalent size-limited LXC tmpfs mount.", + "reason": "Avoid persistent cache writes and preserve Frigate memory behavior.", + "behavioral_impact": "Cache is cleared on restart.", + "validation": "passed-laboratory-profile" + }, + { + "id": "optional-vaapi-device", + "upstream_behavior": "Docker passes a selected /dev/dri render device.", + "native_lxc_behavior": "Resolve the host render GID and grant only the selected render device to the unprivileged LXC.", + "reason": "Frigate can hardware-accelerate video decode without making the LXC privileged.", + "behavioral_impact": "Requires host-specific device and GID validation.", + "validation": "passed-amd-radeonsi-laboratory-profile" + }, + { + "id": "openvino-lxc-cpu-compatibility", + "upstream_behavior": "Frigate ships its detector runtime in the image.", + "native_lxc_behavior": "On amd64, ensure OpenVINO is at least 2026.1.0 and install that exact version with --no-deps only when the bundled runtime is older.", + "reason": "The 2025.4.1 CPU plugin bundled by Frigate 0.18 stable intermittently segfaults while compiling the default model inside an unprivileged LXC.", + "behavioral_impact": "Only the OpenVINO wheel is replaced; NumPy and every other image dependency remain unchanged.", + "validation": "passed-frigate-0.18.0-stable-amd64-three-starts-twenty-compiles" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "commands": [ + "pct", + "pvesm", + "skopeo" + ], + "features": [ + "native-oci-lxc" + ] + }, + "deployment": { + "runtime": "proxmox-native-oci-lxc", + "unprivileged": true, + "entrypoint": "/init", + "working_directory": "/opt/frigate/", + "hostname_default": "frigate", + "onboot_default": false, + "startup_order_default": 30, + "startup_delay_seconds_default": 10, + "features": [ + "nesting=1" + ], + "ports": [ + { + "port": 5000, + "protocol": "tcp", + "purpose": "native-oci-web-ui" + }, + { + "port": 1984, + "protocol": "tcp", + "purpose": "integrated-go2rtc-web-ui-api" + }, + { + "port": 8554, + "protocol": "tcp", + "purpose": "rtsp-restream" + }, + { + "port": 8555, + "protocol": "tcp", + "purpose": "webrtc" + }, + { + "port": 8555, + "protocol": "udp", + "purpose": "webrtc" + } + ], + "entrypoint_override": "explicit-validated-image-command", + "entrypoint_source": "validated-lxc-oci-profile" + }, + "defaults": { + "resources": { + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 16 + }, + "network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "ipv4_address": null, + "ipv4_gateway": null, + "firewall": false, + "host_managed": true + }, + "environment": { + "TZ": "Europe/Madrid", + "LIBVA_DRIVER_NAME": null + } + }, + "configuration_schema": { + "vmid": { + "type": "integer", + "required": false, + "default": null, + "description": "Identificador manual o siguiente VMID libre si se omite." + }, + "hostname": { + "type": "string", + "required": true, + "default": "frigate", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,62}$" + } + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ] + }, + "rootfs_size_gb": { + "type": "integer", + "required": true, + "default": 16, + "minimum": 8 + }, + "cores": { + "type": "integer", + "required": true, + "default": 4, + "minimum": 2 + }, + "memory_mb": { + "type": "integer", + "required": true, + "default": 4096, + "minimum": 2048 + }, + "swap_mb": { + "type": "integer", + "required": true, + "default": 1024, + "minimum": 0 + }, + "bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "ipv4_mode": { + "type": "select", + "required": true, + "default": "dhcp", + "options": [ + "dhcp", + "static" + ] + }, + "ipv4_address": { + "type": "cidr", + "required_when": { + "field": "ipv4_mode", + "equals": "static" + } + }, + "ipv4_gateway": { + "type": "ipv4", + "required_when": { + "field": "ipv4_mode", + "equals": "static" + } + }, + "config_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "description": "Volumen persistente e independiente para /config." + }, + "config_size_gb": { + "type": "integer", + "required": true, + "default": 8, + "minimum": 2 + }, + "media_storage_mode": { + "type": "select", + "required": true, + "default": "host-bind", + "options": [ + "managed-volume", + "host-bind", + "rootfs" + ], + "description": "Destino persistente de /media/frigate." + }, + "media_storage": { + "type": "storage-selector", + "required_when": { + "field": "media_storage_mode", + "equals": "managed-volume" + }, + "content_types": [ + "rootdir" + ] + }, + "media_size_gb": { + "type": "integer", + "required_when": { + "field": "media_storage_mode", + "equals": "managed-volume" + }, + "default": 100, + "minimum": 10 + }, + "media_host_path": { + "type": "host-directory", + "required_when": { + "field": "media_storage_mode", + "equals": "host-bind" + }, + "default": "/mnt/oci-shared/recordings/frigate/ct${vmid}", + "create_if_missing": true, + "description": "Host path that can be shared with other containers." + }, + "cache_size_mb": { + "type": "integer", + "required": true, + "default": 1024, + "minimum": 256 + }, + "gpu_enabled": { + "type": "boolean", + "required": true, + "default": true + }, + "gpu_render_device": { + "type": "host-device-selector", + "required_when": { + "field": "gpu_enabled", + "equals": true + }, + "default": "/dev/dri/renderD128", + "filter": "/dev/dri/renderD*" + }, + "vaapi_driver": { + "type": "select", + "required": false, + "default": "auto", + "options": [ + "auto", + "radeonsi", + "iHD", + "i965" + ] + }, + "timezone": { + "type": "timezone", + "required": true, + "default": "Europe/Madrid" + }, + "onboot": { + "type": "boolean", + "required": true, + "default": false + }, + "openvino_cpu_compatibility": { + "type": "boolean", + "required": false, + "default": false, + "hidden": true, + "description": "Reservado para una futura adaptacion validada en hardware estable; no modifica la imagen oficial." + } + }, + "mounts": [ + { + "id": "config", + "container_path": "/config", + "source": "managed-volume", + "storage_field": "config_storage", + "size_field": "config_size_gb", + "backup": true, + "required": true + }, + { + "id": "media", + "container_path": "/media/frigate", + "source_field": "media_storage_mode", + "storage_field": "media_storage", + "size_field": "media_size_gb", + "host_path_field": "media_host_path", + "backup": false, + "required": false + }, + { + "id": "cache", + "container_path": "/tmp/cache", + "source": "tmpfs", + "size_field": "cache_size_mb", + "mount_options": [ + "rw", + "noexec", + "nosuid", + "nodev" + ], + "required": true + } + ], + "devices": [ + { + "id": "gpu-render", + "enabled_field": "gpu_enabled", + "host_path_field": "gpu_render_device", + "container_path": "/dev/dri/renderD128", + "permissions": "rwm", + "optional": true + } + ], + "environment": [ + { + "name": "TZ", + "value_from": "timezone" + }, + { + "name": "LIBVA_DRIVER_NAME", + "value_from": "vaapi_driver", + "omit_when": "auto" + } + ], + "compatibility": { + "openvino_cpu": { + "enabled_field": "openvino_cpu_compatibility", + "status": "pending-validation-on-stable-hardware", + "runtime_policy": "preserve-official-image-runtime", + "automatic_internal_configuration": false, + "description": "No se aplica ninguna sustitucion de paquetes mientras la prueba del host presente errores de memoria." + } + }, + "healthcheck": { + "type": "http", + "port": 5000, + "path": "/api/version", + "verify_tls": true, + "interval_seconds": 30, + "timeout_seconds": 10, + "retries": 10, + "start_period_seconds": 120 + }, + "boundaries": { + "bundles_internal_configuration": false, + "bundles_credentials": false, + "bundles_user_data": false, + "installer_must_not_write_config_yaml": true + }, + "notes": [ + "Esta plantilla describe la instalacion OCI y su infraestructura persistente.", + "La configuracion funcional de Frigate se realiza despues desde la aplicacion.", + "La WebUI validada para el LXC OCI nativo se publica como http://IP:5000.", + "La imagen incluye go2rtc 1.9.14 y su WebUI/API queda disponible como http://IP:1984.", + "Frigate stable 0.18.0 en amd64 incluye un wheel de Pandas 2.2.3 que provoca SIGSEGV en el Ryzen 7 5700U del laboratorio; el instalador comprueba el import y solo si falla reinstala la misma version desde PyPI.", + "La configuracion inicial de Frigate 0.18 activa OpenVINO CPU. La version 2025.4.1 incluida falla de forma intermitente al compilar el modelo dentro de LXC; en amd64 el instalador asegura OpenVINO 2026.1.0 con --no-deps y conserva NumPy 1.26.4.", + "El modo host-bind permite compartir el almacenamiento multimedia del host entre varios LXC OCI.", + "La opcion rootfs para multimedia es solo adecuada para pruebas breves.", + "La GPU es opcional; el instalador debe validar el dispositivo antes de arrancar el contenedor." + ] + }, + "application_options": { + "video_acceleration": { + "selectable": true, + "profiles": [ + "none", + "vaapi" + ], + "validated_profile": "amd-radeonsi-vaapi" + }, + "object_detector": { + "selectable": true, + "profiles": [ + "cpu", + "coral", + "openvino", + "rocm", + "tensorrt" + ], + "openvino": { + "available": true, + "laboratory_validated": false, + "validated_device": "CPU", + "observed_inference_ms": 13.92, + "configuration_location": "/config/config.yaml", + "installer_writes_detector_configuration": false, + "runtime_policy": "preserve-official-image-runtime", + "current_stable_validation": "blocked-by-host-memory-failure", + "compatibility_workaround": null + }, + "configuration_owned_by_user": true, + "warning": "Video acceleration and object detection are independent choices; the installer does not write camera or detector YAML." + } + }, + "installer_profile": { + "pre_start_repairs": [], + "startup_healthcheck": { + "type": "http", + "scheme": "http", + "port": 5000, + "path": "/api/config", + "timeout_seconds": 120, + "request_timeout_seconds": 3, + "stability_seconds": 0, + "verify_tls": true, + "required": true + }, + "host_bind_policies": { + "/media/frigate": { + "create_if_missing": true, + "purpose": "large-recording-storage-outside-native-lxc-backup" + } + }, + "tmpfs_mounts": [ + { + "id": "frigate-cache", + "container_path": "/tmp/cache", + "default_size_mb": 1024, + "minimum_size_mb": 256, + "size_prompt": "Size of the Frigate temporary cache in MB", + "mount_options": [ + "rw", + "noexec", + "nosuid", + "nodev" + ] + } + ], + "optional_devices": [ + { + "id": "coral-pcie", + "kind": "character-device", + "enable_prompt": "Add a Coral PCIe/M.2 device?", + "enabled_default": false, + "path_prompt": "Coral PCIe/M.2 node (e.g. /dev/apex_0)", + "host_path_default": "/dev/apex_0", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ], + "version_aware_adaptations": {}, + "hardware_acceleration": { + "prompt": "Hardware acceleration for Frigate", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "image": { + "reference": "ghcr.io/blakeblackshear/frigate:stable", + "registry": "ghcr.io", + "repository": "ghcr.io/blakeblackshear/frigate", + "tag": "stable", + "digest": null, + "pull_policy": "resolve-rolling-stable-tag-to-architecture-digest-at-install" + }, + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD VA-API", + "image": { + "reference": "ghcr.io/blakeblackshear/frigate:stable", + "registry": "ghcr.io", + "repository": "ghcr.io/blakeblackshear/frigate", + "tag": "stable", + "digest": null, + "pull_policy": "resolve-rolling-stable-tag-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "gpu-render", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "kind": "character-device", + "container_path_strategy": "same-as-host", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVDEC/CUDA)", + "architectures": [ + "amd64" + ], + "image": { + "reference": "ghcr.io/blakeblackshear/frigate:stable-tensorrt", + "registry": "ghcr.io", + "repository": "ghcr.io/blakeblackshear/frigate", + "tag": "stable-tensorrt", + "digest": null, + "pull_policy": "resolve-rolling-stable-tag-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-video", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + }, + { + "name": "NVIDIA_DRIVER_CAPABILITIES", + "value": "compute,video,utility" + } + ] + } + ] + }, + "gpu_validation": { + "device_inventory": "host-sysfs-and-stat", + "application_acceleration": "requires-workload-test", + "tone_mapping": "not-implied-by-device-access" + } + }, + "image_channel_policy": { + "channel": "stable", + "rolling": true, + "version_pinned": false, + "reason": "Frigate publishes stable as its official rolling production tag and does not publish latest.", + "official_reference": "https://docs.frigate.video/frigate/installation/" + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The native single-LXC installation path translates persistent storage, the bounded tmpfs cache and optional VA-API device mapping. Frigate cameras and detector configuration remain owned by the user. The rolling stable image and its bundled Python runtime are preserved without package replacement." + }, + "validation": { + "schema": "passed-at-generation", + "validated_profile": { + "id": "pve55-amd-vaapi-openvino", + "description": "Reproducible profile based on a validated working deployment.", + "validated_on": "2026-08-26", + "validation_status": "passed", + "image": { + "repository": "blakeblackshear/frigate", + "tag": "0.17.1", + "architecture": "amd64" + }, + "container": { + "ostype": "debian", + "cmode": "console", + "unprivileged": true, + "entrypoint": "/init", + "working_directory": "/opt/frigate/", + "halt_signal": "SIGTERM", + "features": [ + "nesting=1" + ], + "onboot": false + }, + "resources": { + "cores": 4, + "cpuset": "0-3", + "cpuset_requirement": "must-include-cpu0", + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_storage": "local-lvm", + "rootfs_size_gb": 16 + }, + "network": { + "interface": "eth0", + "type": "veth", + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "host_managed": true, + "firewall": false + }, + "storage": { + "config": { + "mode": "managed-volume", + "storage": "local-lvm", + "size_gb": 8, + "container_path": "/config", + "backup": true + }, + "media": { + "mode": "host-bind", + "host_path_template": "/mnt/oci-shared/frigate/ct${vmid}/media", + "container_path": "/media/frigate", + "backup": false, + "create_if_missing": true, + "pre_start_check": { + "type": "host-mountpoint", + "path": "/mnt/oci-shared", + "failure_mode": "abort-start" + } + }, + "cache": { + "mode": "tmpfs", + "size_mb": 1024, + "container_path": "/tmp/cache", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + }, + "gpu": { + "enabled": true, + "host_path": "/dev/dri/renderD128", + "container_path": "/dev/dri/renderD128", + "mode": "0660", + "gid_strategy": "resolve-render-group-on-host", + "validated_host_gid": 993, + "vaapi_driver": "radeonsi" + }, + "environment_overrides": { + "TZ": "Europe/Madrid", + "LIBVA_DRIVER_NAME": "radeonsi" + }, + "preserve_image_environment": true, + "openvino": { + "enabled": true, + "device": "CPU", + "package": "openvino==2026.1.0", + "installed_version": "2026.1.0-21367-63e31528c62-releases/2026/1", + "installation_scope": "oci-rootfs", + "install_command": [ + "python3", + "-m", + "pip", + "install", + "--no-cache-dir", + "--break-system-packages", + "openvino==2026.1.0" + ], + "detector_configuration_managed_by_installer": false, + "reason": "Evita el fallo del plugin CPU de la version OpenVINO incluida originalmente en Frigate 0.17.1 bajo LXC." + }, + "validation": { + "web_ui": "healthy", + "gpu_vaapi": "passed", + "persistent_config": "passed", + "persistent_media": "passed", + "tmpfs_cache": "passed", + "openvino_cpu": "passed", + "real_streams": "passed", + "openvino_inference_ms_observed": 13.92, + "cpu_detector_inference_ms_observed": 21.23 + } + }, + "stable_validation": { + "validated_on": "2026-09-13", + "host": "pve55-amd-ryzen-7-5700u", + "image": { + "tag": "stable", + "version": "0.18.0-77a66e7", + "digest": "sha256:9678a83a76e4730ac7d9ea7428370e32ae656d6b312aaad30d6c69f3fef14d35" + }, + "status": "blocked-by-host-hardware-instability", + "observed_failure": { + "result": "intermittent-native-faults-across-openvino-shapely-pandas-pvesh-and-perl", + "host_memtester": "failed-possible-bad-address-line", + "storage_health": "nvme-smart-passed-zero-media-errors" + }, + "verification": { + "clean_install": "invalid-until-host-memory-is-repaired", + "official_runtime_preserved": true + } + }, + "source_profile": "frigate-oci.json", + "automatic_installer_translation": { + "persistent_config": "covered", + "recording_storage": "covered-managed-volume-or-created-host-bind", + "tmpfs_cache": "covered-native-lxc-mount-entry", + "vaapi_device": "covered-native-proxmox-dev-property-with-host-gid", + "openvino_stable": "preserve-official-image-runtime-pending-healthy-host-validation", + "clean_install_stable": "blocked-by-confirmed-host-memory-error" + }, + "stable_channel_image": "pending-revalidation-after-host-memory-repair" + }, + "lifecycle": { + "update_strategy": "resolve-stable-image-then-replace-rootfs-preserve-/config-and-selected-/media/frigate-storage", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-source-revision-and-resolved-stable-image-digest", + "automatic_unattended_updates": false, + "validated_workflows": { + "install": [ + "validate-requirements", + "resolve-options", + "pull-oci-image", + "create-container", + "attach-persistent-storage", + "attach-optional-devices", + "apply-runtime-environment", + "apply-optional-compatibility", + "start-container", + "wait-for-healthcheck" + ], + "update": [ + "stop-container", + "backup-container-definition", + "pull-oci-image", + "recreate-rootfs-preserving-mounts", + "start-container", + "wait-for-healthcheck" + ], + "uninstall": { + "remove_rootfs": true, + "preserve_config_by_default": true, + "preserve_media_by_default": true + } + } + } +} diff --git a/oci/catalog/curated/haos-one.json b/oci/catalog/curated/haos-one.json new file mode 100644 index 00000000..bde76045 --- /dev/null +++ b/oci/catalog/curated/haos-one.json @@ -0,0 +1,754 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-haos-one", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "HAOS One" + }, + "tagline": { + "en_US": "Community single-container Home Assistant OS image" + }, + "description": { + "en_US": "Community HAOS One image adapted as a native Proxmox OCI LXC with persistent Supervisor, Core, add-ons and backups under /mnt/data." + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "qweritos", + "developer": "qweritos", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/qweritos/haos-one", + "documentation": "https://github.com/qweritos/haos-one#readme", + "repository": "https://github.com/qweritos/haos-one", + "tips": [ + "This is a third-party community image and is not affiliated with Home Assistant.", + "The validated profile uses a managed /mnt/data volume; preserve it during every image replacement.", + "Port 80 is used by current Core releases in the validated profile; port 8123 may appear during setup or on older releases.", + "Experimental unprivileged profile with nesting and keyctl. Internal AppArmor profiles may not be available.", + "The first start downloads internal images. Success is confirmed only with Supervisor healthy/supported and a real Core, internal services and Observer running.", + "The web port is detected between 80 and 8123. If the check fails, the CT, data and log are kept for diagnosis; success is not confirmed.", + "/mnt/data: Proxmox volume of 32 GB by default, minimum 16 GB, included in backup. Full restore and external image update pending testing." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-20" + }, + "source": { + "provider": "qweritos", + "repository": "https://github.com/qweritos/haos-one", + "revision": "b6dd721c4bf06e6f90ee1f8099a82b892e18af64a63015fe5fdfbfd02d538ede", + "image_repository_url": "https://hub.docker.com/r/qweritos/haos-one", + "readme_pushed_at": "2026-08-20T12:29:50Z", + "compose_sha256": "b6dd721c4bf06e6f90ee1f8099a82b892e18af64a63015fe5fdfbfd02d538ede", + "generated_at": "2026-09-12T15:54:10+00:00", + "default_branch": "master" + }, + "container_contract": { + "service_name": "haos-one", + "container_name": "haos-one", + "image": { + "reference": "qweritos/haos-one:latest", + "registry": "docker.io", + "repository": "qweritos/haos-one", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USE_DUMMY_NETWORKMANAGER", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "USE_UDEV_SHIM", + "example": "auto", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "DEV", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/mnt/data", + "compose_source_example": "haos-data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 4357, + "published_example": 4357, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": null, + "stop_grace_period": null, + "original_compose": "name: haos-one\nservices:\n haos-one:\n image: qweritos/haos-one:latest\n privileged: true\n environment:\n USE_DUMMY_NETWORKMANAGER: '1'\n USE_UDEV_SHIM: auto\n DEV: '0'\n ports:\n - 80:80\n - 4357:4357\n volumes:\n - haos-data:/mnt/data\n stop_signal: SIGRTMIN+3\nvolumes:\n haos-data: {}\n" + }, + "compose_stack": { + "project_name": "haos-one", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "haos-one", + "service_count": 1, + "services": [ + { + "name": "haos-one", + "image": "qweritos/haos-one:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "qweritos/haos-one:latest", + "privileged": true, + "environment": { + "USE_DUMMY_NETWORKMANAGER": "1", + "USE_UDEV_SHIM": "auto", + "DEV": "0" + }, + "ports": [ + "80:80", + "4357:4357" + ], + "volumes": [ + "haos-data:/mnt/data" + ], + "stop_signal": "SIGRTMIN+3" + } + } + ], + "top_level": { + "name": "haos-one", + "volumes": { + "haos-data": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "haos-one-volume-0", + "service": "haos-one", + "container_path": "/mnt/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "haos-one" + ], + "stop_order": [ + "haos-one" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Home Assistant", + "scheme": "http", + "port": 80, + "path": "/", + "source": "validated-current-core-profile" + }, + { + "label": "Home Assistant Observer", + "scheme": "http", + "port": 4357, + "path": "/", + "source": "haos-one-runtime" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": true, + "ostype": "unmanaged", + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 16, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1", + "keyctl=1" + ], + "shutdown_timeout_seconds": 60 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-user-values", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "haos-ostype-unmanaged", + "upstream_behavior": "The image identifies itself with ID=haos.", + "native_lxc_behavior": "Create the OCI LXC with ostype=unmanaged.", + "reason": "Proxmox VE 9.2 cannot auto-detect the HAOS distribution identifier during OCI import.", + "behavioral_impact": "No application behavior is changed; Proxmox skips distribution-specific guest setup.", + "validation": "passed-clean-oci-import" + }, + { + "id": "nested-runtime-features", + "upstream_behavior": "haos-one starts systemd, Docker, Supervisor and nested Home Assistant containers.", + "native_lxc_behavior": "Use an unprivileged LXC with nesting=1 and keyctl=1.", + "reason": "The inner Docker and containerd runtime require nested namespaces and keyring support.", + "behavioral_impact": "The LXC remains unprivileged; no AppArmor unconfined override was required.", + "validation": "passed-all-inner-containers-running" + }, + { + "id": "managed-data-volume", + "upstream_behavior": "The image declares /mnt/data as its persistent Docker volume.", + "native_lxc_behavior": "Attach a storage-backed Proxmox mp0 at the same /mnt/data path with backup=1.", + "reason": "Preserves the official data path and includes private state in native Proxmox backups.", + "behavioral_impact": "No path translation; data survives LXC restart independently of the OCI rootfs.", + "validation": "passed-restart-marker-and-service-restoration" + }, + { + "id": "current-image-compat-proxy", + "upstream_behavior": "The current project proxy removes Domainname and HostConfig.Ulimits from nested Docker create requests.", + "native_lxc_behavior": "Use an upstream image digest that contains rewrite_create_request_payload; do not patch files locally.", + "reason": "Older builds fail to start Core and plug-ins with kernel.domainname permission denied.", + "behavioral_impact": "Uses the project-provided compatibility behavior unchanged.", + "validation": "passed-source-revision-5bffb27-and-runtime" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.2", + "validated_proxmox_version": "9.2.11", + "commands": [ + "pct", + "pvesm", + "skopeo", + "curl", + "jq" + ], + "features": [ + "native-oci-lxc", + "nested-container-runtime", + "managed-volume-backup", + "host-managed-network" + ], + "minimum_resources": { + "cores": 2, + "memory_mb": 2048, + "rootfs_size_gb": 12, + "data_size_gb": 16 + }, + "recommended_resources": { + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 16, + "data_size_gb": 32 + } + }, + "upstream_contract": { + "entrypoint": [ + "/entrypoint.sh" + ], + "command": [ + "/sbin/init" + ], + "working_directory": "/", + "declared_volume": "/mnt/data", + "declared_port": 8123, + "stop_signal": "SIGRTMIN+3", + "environment_defaults": { + "USE_DUMMY_NETWORKMANAGER": "1", + "USE_UDEV_SHIM": "auto", + "SETUP_PORT": null, + "DEV": "0" + }, + "preserve_without_override": [ + "entrypoint", + "command", + "container-path-/mnt/data", + "stop-signal", + "compatibility-shim" + ] + }, + "configuration_schema": { + "vmid": { + "type": "integer", + "required": false, + "default": null + }, + "hostname": { + "type": "string", + "required": true, + "default": "haos-one", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,62}$" + } + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ] + }, + "data_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "description": "Volumen administrado por Proxmox montado en /mnt/data y protegido con backup=1." + }, + "data_size_gb": { + "type": "integer", + "required": true, + "default": 32, + "minimum": 16 + }, + "bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "ipv4": { + "type": "ipv4-address-or-dhcp", + "required": true, + "default": "dhcp" + }, + "gateway": { + "type": "ipv4-address", + "required": false, + "default": null + }, + "dns_server": { + "type": "ipv4-address", + "required": false, + "default": null + }, + "usb_devices": { + "type": "device-list", + "required": false, + "default": [], + "description": "Optional passthrough of Zigbee, Z-Wave, Bluetooth or other coordinators; not validated in this profile." + } + }, + "deployment": { + "runtime": "proxmox-native-oci-lxc", + "ostype": "unmanaged", + "unprivileged": true, + "entrypoint": "/entrypoint.sh /sbin/init", + "entrypoint_source": "imported-from-oci-image-config", + "entrypoint_override": false, + "features": [ + "nesting=1", + "keyctl=1" + ], + "apparmor_profile_override": false, + "preserve_image_environment": true, + "managed_network": true, + "mounts": [ + { + "type": "proxmox-managed-volume", + "container_path": "/mnt/data", + "size_gb": 32, + "read_only": false, + "backup": true, + "purpose": "Supervisor, Home Assistant Core, add-ons, secrets, databases, Docker images and runtime state" + } + ], + "ports": [ + { + "port": 80, + "protocol": "tcp", + "purpose": "validated-home-assistant-web-for-core-2026.9.1" + }, + { + "port": 4357, + "protocol": "tcp", + "purpose": "home-assistant-observer" + } + ], + "conditional_ports": [ + { + "port": 8123, + "protocol": "tcp", + "condition": "older-core-or-landing-page-stage-or-explicit-SETUP_PORT", + "warning": "Do not assume port 8123 remains active after onboarding on Home Assistant Core 2026.8 or newer." + } + ] + }, + "persistence": { + "authoritative_path": "/mnt/data", + "storage_type": "proxmox-managed-volume", + "backup_flag": 1, + "included_content": [ + "/mnt/data/supervisor", + "/mnt/data/supervisor/homeassistant", + "/mnt/data/supervisor/apps", + "/mnt/data/supervisor/app_configs", + "/mnt/data/supervisor/backup", + "/mnt/data/supervisor/share", + "/mnt/data/supervisor/ssl", + "/mnt/data/docker", + "/mnt/data/bluetooth" + ], + "rootfs_role": "replaceable-image-runtime", + "data_role": "persistent-user-and-supervisor-state", + "restart_test": { + "status": "passed", + "method": "write-marker-shutdown-start-verify-hash-and-services", + "marker_sha256": "6c3762cede4f86dd5eeae16eff1067e188e9b47646f48ccc268c077711bffbd0", + "volume_before": "local-lvm:vm-128-disk-1", + "volume_after": "local-lvm:vm-128-disk-1", + "home_assistant_after_restart": "passed-http-200", + "inner_containers_after_restart": "passed-all-running" + }, + "native_backup": { + "expected": "included-by-mp0-backup-1", + "full-vzdump-restore-test": "pending" + } + }, + "installation_steps": [ + "Resolve the selected tag to an architecture-specific immutable digest.", + "Copy the pinned image to an OCI archive with skopeo.", + "Verify the OCI Entrypoint, Cmd, volume declaration and stop signal.", + "Create an unprivileged LXC with ostype=unmanaged, nesting=1 and keyctl=1.", + "Create a Proxmox-managed volume with backup=1 at /mnt/data.", + "Attach a host-managed network interface to the selected bridge.", + "Preserve the imported /entrypoint.sh /sbin/init command and SIGRTMIN+3 stop signal.", + "Start the LXC and allow several minutes for the first pull of Supervisor, Core and plug-ins.", + "Discover the assigned address and probe both port 80 and port 8123.", + "Require Supervisor healthy=true and supported=true before reporting success.", + "Verify Core, CLI, DNS, audio, multicast and observer containers are running.", + "Report non-blocking HAOS resolution issues separately." + ], + "healthchecks": [ + { + "name": "home-assistant-web", + "type": "http", + "candidate_urls": [ + "http://${container_ip}/", + "http://${container_ip}:8123/" + ], + "expected_status": 200, + "startup_grace_seconds": 300 + }, + { + "name": "observer", + "type": "http", + "url": "http://${container_ip}:4357/", + "expected_status": 200 + }, + { + "name": "supervisor", + "type": "ha-cli", + "command": "docker -H unix:///run/docker-real.sock exec hassio_cli ha supervisor info", + "required_fields": { + "healthy": true, + "supported": true + } + } + ], + "update_strategy": { + "core_supervisor_and_addons": "managed-by-home-assistant-supervisor", + "outer_oci_image": "resolve-new-image-and-replace-rootfs-while-preserving-/mnt/data", + "outer_oci_update_validation": "pending", + "required_before_update": [ + "create-and-download-a-full-home-assistant-backup", + "create-a-native-proxmox-backup-including-mp0", + "record-current-image-digest", + "verify-new-image-contains-required-compatibility-rules" + ], + "warning": "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume." + }, + "security": { + "image_is_official_home_assistant": false, + "outer_lxc_unprivileged": true, + "nested_docker": true, + "apparmor_profiles_inside_haos": "cannot-load-in-current-lxc-profile", + "supervisor_health_despite_apparmor_warning": "healthy-and-supported", + "risk_notes": [ + "The image is maintained by a third party and is not affiliated with Home Assistant.", + "Nested containers increase complexity and expand the runtime attack surface compared with a normal single-process OCI image.", + "HAOS AppArmor profiles cannot be loaded inside this unprivileged LXC, reducing inner add-on confinement.", + "Protect /mnt/data because it contains credentials, secrets, databases and backups.", + "Do not expose Home Assistant or Observer directly to the Internet without an authenticated reverse proxy and normal Home Assistant hardening." + ] + }, + "incompatible_builds": [ + { + "reference": "docker.io/qweritos/haos-one:18.1-amd64", + "digest": "sha256:164d579522da0875c3eaa64283c5f7b875afae2013f1b878c86f80c1eac286af", + "status": "failed-native-unprivileged-oci", + "reason": "The bundled compatibility proxy does not rewrite nested container create requests, causing kernel.domainname permission denied for Core and plug-ins.", + "do_not_use_for_this_profile": true + } + ], + "notes": [ + "HAOS One is a community image, not an official Home Assistant image.", + "This is not a simple Home Assistant container: the outer OCI runs systemd, Docker, Supervisor, Core and add-ons.", + "The direct Proxmox OCI path removes one extra Docker layer compared with the upstream-tested Proxmox LXC plus Docker plus haos-one deployment.", + "Proxmox privileged OCI import failed with setgid(0) Invalid argument; the validated profile is unprivileged and functional.", + "Proxmox must use ostype=unmanaged because ID=haos is not recognized by guest distribution detection.", + "The official /mnt/data path is a Proxmox-managed volume with backup=1, not a shared host bind.", + "A clean first boot used approximately 8.6G under /mnt/data after Core and Matter installation; 32G is the recommended starting size.", + "Home Assistant Core 2026.9.1 listens on port 80 in this image. Port 8123 was present only during the landing-page stage and must not be hard-coded.", + "Supervisor reports healthy=true and supported=true even though several host-oriented HAOS units cannot run inside LXC.", + "AppArmor profile loading inside HAOS fails in the current unprivileged LXC; this is a security limitation and must remain visible to users.", + "The current tag 18 works because it includes the upstream Docker API create-request rewrite; tag 18.1-amd64 does not.", + "Mutable tags must be resolved to an immutable architecture-specific digest before installation.", + "Restart persistence is validated. Full vzdump restore, outer OCI image replacement, USB passthrough and real multicast discovery remain pending." + ], + "references": { + "project": "https://github.com/qweritos/haos-one", + "docker_image": "https://hub.docker.com/r/qweritos/haos-one", + "dockerfile": "https://github.com/qweritos/haos-one/blob/master/Dockerfile", + "compatibility_documentation": "https://github.com/qweritos/haos-one/blob/master/docs/haos-one-compat.md", + "home_assistant_os_releases": "https://github.com/home-assistant/operating-system/releases", + "proxmox_pct_manual": "https://pve.proxmox.com/pve-docs/pct.1.html" + } + }, + "installer_profile": { + "haos_healthcheck": { + "timeout_seconds": 1200 + }, + "volume_preparations": [ + { + "container_path": "/mnt/data", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "Native laboratory adaptations implemented. Rolling latest first boot, backup restore and outer-image upgrades still require runtime validation." + }, + "validation": { + "schema": "passed-at-generation", + "validated_architecture": "amd64", + "arm64": "supported-upstream-not-yet-validated-in-proxmenux-laboratory", + "validated_profile": { + "id": "pve55-haos-one-native-oci", + "validated_on": "2026-09-08", + "validation_status": "passed-functional-restart-persistence-with-known-nonblocking-issues", + "proxmox_version": "9.2.11", + "container_id": 128, + "haos_version": "18.2", + "home_assistant_core": "2026.9.1", + "supervisor": "2026.09.0", + "matter_server": "9.2.0", + "resources": { + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs": "local-lvm:16G", + "data": "local-lvm:32G,mp=/mnt/data,backup=1" + }, + "observed_after_first_boot": { + "data_used": "approximately-8.6G", + "memory_used_bytes": 1368289280, + "rootfs_used_bytes": 624910336 + }, + "validation": { + "oci_import": "passed-with-ostype-unmanaged", + "image_entrypoint": "passed-/entrypoint.sh-/sbin/init", + "halt_signal": "passed-SIGRTMIN+3", + "nested_docker": "passed-overlayfs", + "compatibility_proxy": "passed", + "home_assistant_web": "passed-http-200-port-80", + "observer": "passed-http-200-port-4357", + "supervisor_healthy": true, + "supervisor_supported": true, + "core_running": true, + "plugins_running": true, + "matter_addon_running": true, + "restart_persistence": "passed", + "native_volume_backup_flag": "passed-mp0-backup-1", + "full_vzdump_restore": "pending", + "outer_image_upgrade": "pending", + "usb_passthrough": "pending", + "multicast_discovery": "pending-functional-device-test" + }, + "known_nonblocking_resolution_issues": [ + "haos-mglru.service-failed", + "auditd.service-failed", + "sys-kernel-config.mount-failed", + "sys-kernel-debug.mount-failed", + "dummy-networkmanager-may-report-ipv4-or-dns-diagnostics" + ] + }, + "source_profile": "haos-one-oci.json", + "service_health": "passed-observed-2026-09-14", + "restart_persistence": "passed-2026-09-14", + "backup_restore": "pending", + "update_preserves_data": "pending", + "latest_runtime_observation": { + "date": "2026-09-14", + "vmid": 100, + "architecture": "amd64", + "proxmox": "9.2.18", + "kernel": "7.0.14-16-pve", + "core_version": "2026.9.2", + "supervisor_version": "2026.09.0", + "image_reference": "qweritos/haos-one:latest", + "outer_image_digest_verified": false, + "supervisor_healthy": true, + "supervisor_supported": true, + "required_internal_containers_running": true, + "matter_server_healthy_after_restart": true, + "restart_method": "pct shutdown --timeout 90; pct start", + "managed_data_volume_unchanged": true, + "data_volume_gb": 32, + "data_volume_backup_flag": true, + "configuration_yaml_sha256_unchanged": true, + "temporary_marker_sha256_unchanged": true, + "temporary_marker_removed": true, + "core_http_port": 80, + "observer_http_port": 4357, + "lan_address_unchanged": true, + "limitations": [ + "Supervisor AppArmor profile could not be loaded inside this LXC.", + "Host kernel config/debug mounts, auditd and MGLRU units fail in this LXC.", + "PulseAudio warning appeared during boot; hassio_audio subsequently running, audio functionality not tested.", + "Core translation-domain warnings observed; no functionality test of associated integrations.", + "Full vzdump restore and outer OCI image replacement remain untested." + ] + } + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-and-replace-rootfs-preserving-managed-/mnt/data", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false, + "validated_workflows": { + "core_supervisor_and_addons": "managed-by-home-assistant-supervisor", + "outer_oci_image": "resolve-new-image-and-replace-rootfs-while-preserving-/mnt/data", + "outer_oci_update_validation": "pending", + "required_before_update": [ + "create-and-download-a-full-home-assistant-backup", + "create-a-native-proxmox-backup-including-mp0", + "record-current-image-digest", + "verify-new-image-contains-required-compatibility-rules" + ], + "warning": "Do not claim in-place OCI image updates are validated until rootfs replacement and rollback have been tested without losing the managed /mnt/data volume." + } + } +} diff --git a/oci/catalog/curated/immich.json b/oci/catalog/curated/immich.json new file mode 100644 index 00000000..de756849 --- /dev/null +++ b/oci/catalog/curated/immich.json @@ -0,0 +1,1979 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-immich", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Immich" + }, + "tagline": { + "en_US": "Photo and video library with optional GPU transcoding and machine learning" + }, + "description": { + "en_US": "Immich as a coordinated four-LXC native OCI stack with private PostgreSQL and Valkey services, persistent media and model cache, and selectable hardware acceleration." + }, + "category": "media", + "category_label": "Media", + "author": "Immich", + "developer": "Immich", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 2283, + "path": "/" + }, + "website": "https://immich.app/", + "documentation": "https://docs.immich.app/install/docker-compose/", + "repository": "https://github.com/immich-app/immich", + "tips": [ + "The installer creates four coordinated native OCI LXC containers as one application.", + "Video transcoding acceleration and machine-learning acceleration are independent selections.", + "CPU is the validated safe machine-learning default; a GPU profile must pass a real inference test before cutover.", + "PostgreSQL data must remain on local storage and must not be placed on NFS or SMB." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-12" + }, + "source": { + "provider": "immich", + "repository": "https://github.com/immich-app/immich", + "revision": "0f93904a4db59b93558d09097e586d168ce6dbfa00a20afb6967259430a8514c", + "image_repository_url": "https://github.com/immich-app/immich/pkgs/container/immich-server", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "0f93904a4db59b93558d09097e586d168ce6dbfa00a20afb6967259430a8514c", + "generated_at": "2026-09-12T15:45:34+00:00" + }, + "container_contract": { + "service_name": "immich-server", + "container_name": "immich-server", + "image": { + "reference": "ghcr.io/immich-app/immich-server:release", + "registry": "ghcr.io", + "repository": "ghcr.io/immich-app/immich-server", + "tag": "release", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "DB_HOSTNAME", + "example": "database", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "DB_PORT", + "example": "5432", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "DB_DATABASE_NAME", + "example": "immich", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "DB_USERNAME", + "example": "postgres", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "DB_PASSWORD", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "official-compose-environment" + }, + { + "name": "REDIS_HOSTNAME", + "example": "redis", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "REDIS_PORT", + "example": "6379", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "IMMICH_MACHINE_LEARNING_URL", + "example": "http://immich-machine-learning:3003", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "official-compose-environment" + } + ], + "volumes": [ + { + "id": "media", + "container_path": "/data", + "compose_source_example": "${UPLOAD_LOCATION}", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 100 + } + }, + { + "id": "localtime", + "container_path": "/etc/localtime", + "compose_source_example": "/etc/localtime", + "read_only": true, + "required": false, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 1 + } + } + ], + "ports": [ + { + "container_port": 2283, + "published_example": 2283, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "immich-machine-learning", + "image": "ghcr.io/immich-app/immich-machine-learning:release" + }, + { + "name": "redis", + "image": "docker.io/valkey/valkey:9@sha256:70739f85ad2ee01a726a965584a0f94895f01b0c60b3cc8b0aeef11eaa6888cf" + }, + { + "name": "database", + "image": "ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357191b76a916ae5eb93464d65c07511da41e3bf7a8416db519b40b1c23" + } + ], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: immich\nservices:\n immich-server:\n deploy:\n resources:\n reservations:\n memory: 1024M\n container_name: immich-server\n hostname: immich-server\n image: ghcr.io/immich-app/immich-server:release\n volumes:\n - /DATA/Gallery/immich:/usr/src/app/upload\n - /etc/localtime:/etc/localtime:ro\n environment:\n DB_DATABASE_NAME: immich\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n DB_USERNAME: postgres\n ports:\n - 2283:2283\n depends_on:\n - redis\n - database\n restart: unless-stopped\n healthcheck:\n disable: false\n networks:\n - immich\n immich-machine-learning:\n container_name: immich-machine-learning\n hostname: immich-machine-learning\n image: ghcr.io/immich-app/immich-machine-learning:release\n environment:\n DB_DATABASE_NAME: immich\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n DB_USERNAME: postgres\n restart: unless-stopped\n volumes:\n - /DATA/AppData/immich/model-cache:/cache\n healthcheck:\n disable: false\n networks:\n - immich\n redis:\n container_name: immich-redis\n hostname: immich-redis\n image: docker.io/valkey/valkey:9@sha256:70739f85ad2ee01a726a965584a0f94895f01b0c60b3cc8b0aeef11eaa6888cf\n healthcheck:\n test: redis-cli ping || exit 1\n restart: unless-stopped\n networks:\n - immich\n database:\n container_name: immich-postgres\n hostname: immich-postgres\n image: ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357191b76a916ae5eb93464d65c07511da41e3bf7a8416db519b40b1c23\n environment:\n POSTGRES_PASSWORD: ${GENERATED_DB_PASSWORD}\n POSTGRES_USER: postgres\n POSTGRES_DB: immich\n POSTGRES_INITDB_ARGS: --data-checksums\n volumes:\n - /DATA/AppData/immich/pgdata:/var/lib/postgresql/data\n restart: unless-stopped\n networks:\n - immich\nnetworks:\n immich:\n driver: bridge\n" + }, + "compose_stack": { + "project_name": "immich", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "immich-server", + "service_count": 4, + "services": [ + { + "name": "database", + "image": "ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "immich_postgres", + "image": "ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0", + "environment": { + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}", + "POSTGRES_USER": "postgres", + "POSTGRES_DB": "immich", + "POSTGRES_INITDB_ARGS": "--data-checksums", + "PGDATA": "/var/lib/postgresql/data/pgdata" + }, + "volumes": [ + "postgres-data:/var/lib/postgresql/data" + ], + "shm_size": "128mb", + "restart": "always", + "healthcheck": { + "disable": false + } + } + }, + { + "name": "redis", + "image": "docker.io/valkey/valkey:9", + "is_main": false, + "role": "dependency", + "vmid_offset": 3, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "container_name": "immich_redis", + "image": "docker.io/valkey/valkey:9", + "healthcheck": { + "test": "valkey-cli ping | grep -q PONG || exit 1" + }, + "restart": "always" + } + }, + { + "name": "immich-machine-learning", + "image": "ghcr.io/immich-app/immich-machine-learning:release", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "immich_machine_learning", + "image": "ghcr.io/immich-app/immich-machine-learning:release", + "volumes": [ + "model-cache:/cache" + ], + "environment": { + "TZ": "${TIMEZONE}" + }, + "restart": "always", + "healthcheck": { + "disable": false + } + } + }, + { + "name": "immich-server", + "image": "ghcr.io/immich-app/immich-server:release", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "database", + "redis", + "immich-machine-learning" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "container_name": "immich_server", + "image": "ghcr.io/immich-app/immich-server:release", + "volumes": [ + "${UPLOAD_LOCATION}:/data", + "/etc/localtime:/etc/localtime:ro" + ], + "environment": { + "TZ": "${TIMEZONE}", + "DB_HOSTNAME": "database", + "DB_PORT": "5432", + "DB_USERNAME": "postgres", + "DB_PASSWORD": "${GENERATED_DB_PASSWORD}", + "DB_DATABASE_NAME": "immich", + "REDIS_HOSTNAME": "redis", + "REDIS_PORT": "6379", + "IMMICH_MACHINE_LEARNING_URL": "http://immich-machine-learning:3003" + }, + "ports": [ + "2283:2283" + ], + "depends_on": [ + "redis", + "database", + "immich-machine-learning" + ], + "restart": "always", + "healthcheck": { + "disable": false + } + } + } + ], + "top_level": { + "name": "immich", + "volumes": { + "model-cache": {}, + "postgres-data": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "database-and-valkey-private-only", + "machine_learning_frontend_access": "enabled-for-model-downloads", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "immich-media", + "service": "immich-server", + "container_path": "/data", + "mode": "user-selectable", + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "user_selectable": true, + "backup": false, + "backup_by_mode": { + "managed-volume": true, + "host-bind": false + }, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for the Immich media library" + }, + { + "id": "localtime", + "service": "immich-server", + "container_path": "/etc/localtime", + "mode": "system-bind", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": "/etc/localtime", + "source_path_prompt": null + }, + { + "id": "model-cache", + "service": "immich-machine-learning", + "container_path": "/cache", + "mode": "managed-volume", + "user_selectable": false, + "backup": false, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "postgres-data", + "service": "database", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null, + "constraints": { + "local_storage_required": true, + "network_filesystem_allowed": false + } + } + ], + "orchestration": { + "reserve_vmids_atomically": 4, + "start_order": [ + "database", + "redis", + "immich-machine-learning", + "immich-server" + ], + "stop_order": [ + "immich-server", + "immich-machine-learning", + "redis", + "database" + ], + "dependency_readiness": "healthcheck-required-before-next-service", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes", + "gpu_failure_policy": "fallback-machine-learning-to-cpu-before-starting-server" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "database_storage", + "media_storage_mode", + "media_destination", + "database_size_gb", + "frontend_bridge", + "frontend_ipv4_mode", + "timezone", + "video_transcoding_acceleration", + "machine_learning_acceleration" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order", + "gpu_preflight_checks", + "machine_learning_cpu_fallback" + ], + "generated_secrets": [ + { + "id": "db-password", + "strategy": "generate-cryptographically-random-alphanumeric-at-install", + "bindings": [ + { + "service": "immich-server", + "environment_variable": "DB_PASSWORD" + }, + { + "service": "database", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 2283, + "path": "/", + "source": "official-compose" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 4, + "memory_mb": 3072, + "swap_mb": 1024, + "rootfs_size_gb": 16, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "rolling-latest-image", + "upstream_behavior": "The official Compose selects an Immich release and pins dependency images.", + "native_lxc_behavior": "The automatic catalog resolves the latest tag of each selected image repository at install time.", + "reason": "Pinned versions belong to the future manual installer while this catalog intentionally tracks latest.", + "behavioral_impact": "A rolling image must be revalidated before unattended updates.", + "validation": "pending-for-each-resolved-latest-digest" + }, + { + "id": "one-native-lxc-per-service", + "upstream_behavior": "Docker Compose starts four containers as one project.", + "native_lxc_behavior": "ProxMenux creates four native OCI LXC containers and controls them as one application.", + "reason": "Proxmox native OCI imports one image per LXC.", + "behavioral_impact": "Equivalent service separation with native Proxmox lifecycle and backup controls.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "private-service-network", + "upstream_behavior": "Compose DNS connects services on a private Docker network.", + "native_lxc_behavior": "Fixed addresses and service aliases are created on a private Proxmox bridge.", + "reason": "The services run in separate LXC network namespaces.", + "behavioral_impact": "PostgreSQL and Valkey remain private; machine learning also receives frontend access for model downloads.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "native-persistent-storage", + "upstream_behavior": "Compose uses upload and database bind mounts plus a named model-cache volume.", + "native_lxc_behavior": "Media uses the selected host bind or managed volume, PostgreSQL uses a local managed backup volume, and model cache uses a reproducible managed volume.", + "reason": "Preserve official container paths while applying native Proxmox backup semantics.", + "behavioral_impact": "Shared media needs its own backup; PostgreSQL participates in vzdump with backup=1.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "ordered-healthchecked-startup", + "upstream_behavior": "Compose starts dependencies and evaluates container health.", + "native_lxc_behavior": "The stack orchestrator starts database, Valkey, machine learning and server in health-checked order.", + "reason": "Proxmox does not provide Compose depends_on semantics across LXC containers.", + "behavioral_impact": "One user action still manages the complete application.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "container-scoped-ld-preload", + "upstream_behavior": "Docker applies LD_PRELOAD inside the machine-learning container.", + "native_lxc_behavior": "ProxMenux removes LD_PRELOAD from the global LXC runtime environment and reapplies it in the machine-learning entrypoint after entering the container rootfs.", + "reason": "Proxmox startup hooks otherwise inherit the container path before chroot and print misleading loader errors.", + "behavioral_impact": "None; the Immich process still loads the official mimalloc library.", + "validation": "passed-in-ct106-restart-2026-09-13" + }, + { + "id": "lxc-route-readiness-wrapper", + "upstream_behavior": "Docker prepares networking before the server process starts.", + "native_lxc_behavior": "A minimal wrapper waits for the eth0 default route before executing the image command.", + "reason": "DHCP route creation can race PID 1 in the native OCI LXC.", + "behavioral_impact": "Startup timing only; the official final command remains unchanged.", + "validation": "passed-in-ct121" + }, + { + "id": "postgres-private-listen", + "upstream_behavior": "PostgreSQL listens on the private Compose network.", + "native_lxc_behavior": "The official entrypoint receives listen_addresses for loopback and the private LXC address.", + "reason": "The database must be reachable without a frontend interface.", + "behavioral_impact": "Equivalent private reachability.", + "validation": "passed-in-ct123" + } + ], + "catalog": { + "replaces_discovered_ids": [ + "immich" + ] + }, + "application_options": { + "video_transcoding": { + "selectable": true, + "independent_from_machine_learning": true, + "profiles": [ + "cpu", + "vaapi", + "quicksync", + "nvenc" + ], + "laboratory_validated_profile": "vaapi-amd", + "validated": true, + "configuration_location": "Immich Administration > Video transcoding", + "installer_writes_application_setting": false, + "device_policy": "run-profile-preflight-and-pass-only-required-host-devices" + }, + "machine_learning": { + "selectable": true, + "profiles": [ + "cpu", + "openvino", + "cuda", + "rocm" + ], + "safe_default": "cpu", + "profile_images": { + "cpu": "ghcr.io/immich-app/immich-machine-learning:release", + "openvino": "ghcr.io/immich-app/immich-machine-learning:release-openvino", + "cuda": "ghcr.io/immich-app/immich-machine-learning:release-cuda", + "rocm": "ghcr.io/immich-app/immich-machine-learning:release-rocm" + }, + "cpu": { + "available": true, + "laboratory_validated": true, + "hardware_accelerated": false + }, + "openvino": { + "available": true, + "laboratory_validated": true, + "vendor": "intel", + "provider": "OpenVINOExecutionProvider", + "hardware_accelerated": true, + "requires": [ + "/dev/dri" + ], + "status": "validated-on-documented-laboratory-hardware", + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md" + }, + "cuda": { + "available": true, + "laboratory_validated": true, + "vendor": "nvidia", + "provider": "CUDAExecutionProvider", + "hardware_accelerated": true, + "minimum_compute_capability": "5.2", + "minimum_driver": "545", + "status": "validated-on-documented-laboratory-hardware", + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md" + }, + "rocm": { + "available": true, + "laboratory_validated": false, + "vendor": "amd", + "provider": "MIGraphXExecutionProvider", + "hardware_accelerated": true, + "requires": [ + "/dev/dri", + "/dev/kfd" + ], + "minimum_free_image_cache_gb": 35, + "status": "compatible-gpu-and-real-inference-validation-required", + "automatic_denylist": [ + { + "pci_id": "1002:164c", + "gpu": "AMD Lucienne integrated graphics", + "reason": "Real buffalo_l inference caused SDMA/compute timeouts and repeated host GPU resets.", + "tested_on": "2026-08-26" + } + ] + }, + "validation_protocol": { + "ping_is_not_sufficient": true, + "required_steps": [ + "Verify the expected ONNX execution provider is available.", + "Run a real facial-recognition detection and embedding request.", + "Run visual and textual smart-search embeddings.", + "Observe GPU utilization during inference.", + "Reject the profile on provider fallback, HTTP 500, kernel timeout or GPU reset.", + "Keep the validated CPU ML service available until GPU validation passes." + ] + }, + "failure_policy": { + "stop_failed_machine_learning_lxc": true, + "preserve_failure_metadata_without_secrets": true, + "record_gpu_pci_id_and_driver": true, + "stop_further_gpu_tests_after_kernel_timeout_or_reset": true, + "recommend_host_reboot_when_gpu_clocks_or_power_do_not_return_to_idle": true, + "automatic_hsa_override_retry": false, + "fallback_profile": "cpu", + "reuse_model_cache_when_compatible": true, + "start_server_only_after_cpu_fallback_is_healthy": true + } + } + }, + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "commands": [ + "pct", + "pvesm", + "skopeo", + "openssl", + "jq" + ], + "features": [ + "native-oci-lxc", + "unprivileged-lxc", + "private-service-network" + ], + "minimum_host_memory_mb": 6144, + "recommended_host_memory_mb": 8192, + "minimum_free_image_cache_gb": 8, + "thin_pool_checks": { + "minimum_free_percent": 15, + "reject_when_data_percent_above": 85, + "warn_when_virtual_allocation_exceeds_pool": true, + "require_autoextend_or_explicit_confirmation": true + }, + "database_storage": { + "must_be_local": true, + "recommended_media": "ssd", + "network_filesystem_allowed": false + } + }, + "defaults": { + "stack_name": "immich", + "timezone": "Europe/Madrid", + "rootfs_storage": "local-lvm", + "database_storage": "local-lvm", + "shared_media_root": "/mnt/oci-shared/media/immich/${stack_name}", + "database_size_gb": 32, + "frontend_network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "firewall": true, + "host_managed": true + }, + "private_network": { + "mode": "create-if-missing", + "bridge": "vmbr10", + "subnet": "10.77.0.0/24", + "host_address": "10.77.0.1/24", + "host_ip": "10.77.0.1", + "server_address": "10.77.0.10/24", + "server_ip": "10.77.0.10", + "machine_learning_address": "10.77.0.11/24", + "machine_learning_ip": "10.77.0.11", + "database_address": "10.77.0.12/24", + "database_ip": "10.77.0.12", + "valkey_address": "10.77.0.13/24", + "valkey_ip": "10.77.0.13", + "address_offsets": { + "host": 1, + "server": 10, + "machine_learning": 11, + "database": 12, + "valkey": 13 + }, + "firewall": true, + "host_managed": true, + "nat": false + }, + "database": { + "name": "immich", + "username": "postgres", + "vector_extension": "vectorchord", + "storage_type": "SSD" + }, + "video_transcoding": { + "acceleration": "vaapi", + "render_device": "/dev/dri/renderD128", + "driver": "auto" + }, + "machine_learning": { + "acceleration": "cpu", + "model_cache_size_gb": 8 + } + }, + "installer_contract": { + "variable_syntax": "dollar-brace dotted path", + "strict_resolution": true, + "reject_unresolved_variables": true, + "input_bindings": { + "frontend_bridge": "frontend_network.bridge", + "frontend_ipv4_mode": "frontend_network.ipv4_mode", + "private_bridge": "private_network.bridge", + "private_subnet": "private_network.subnet", + "database_storage": "database_storage", + "media_storage_mode": "storage.media.mode", + "media_storage": "storage.media.managed_storage", + "media_size_gb": "storage.media.managed_size_gb", + "shared_media_root": "shared_media_root", + "video_transcoding_acceleration": "video_transcoding.acceleration", + "video_render_device": "video_transcoding.render_device", + "vaapi_driver": "video_transcoding.driver", + "machine_learning_acceleration": "machine_learning.acceleration" + }, + "computed_values": { + "vmids": { + "server": "base_vmid + services.server.vmid_offset", + "machine_learning": "base_vmid + services.machine_learning.vmid_offset", + "database": "base_vmid + services.database.vmid_offset", + "valkey": "base_vmid + services.valkey.vmid_offset" + }, + "private_addresses": "Derive IP and CIDR values from private_network.subnet and private_network.address_offsets", + "host_uid_for_container_uid": "unprivileged_idmap_base + container_uid" + }, + "machine_learning_image_resolution": { + "cpu": "machine_learning_cpu", + "rocm": "machine_learning_rocm", + "openvino": "machine_learning_openvino", + "cuda": "machine_learning_cuda" + }, + "machine_learning_resource_profiles": { + "cpu": { + "rootfs_size_gb": 12, + "memory_mb": 2048, + "validated": true + }, + "rocm": { + "rootfs_size_gb": 48, + "memory_mb": 4096, + "validated": false + }, + "openvino": { + "rootfs_size_gb": 20, + "memory_mb": 4096, + "validated": false + }, + "cuda": { + "rootfs_size_gb": 32, + "memory_mb": 4096, + "validated": false + } + }, + "invariants": [ + "Reserve four unused VMIDs atomically before creating any LXC.", + "Never expose database or Valkey on the frontend bridge.", + "Never place PostgreSQL data on network storage.", + "Generate the PostgreSQL password during installation and translate it directly to lxc.environment.runtime, matching Compose environment visibility.", + "Store PostgreSQL data in a managed Proxmox volume with backup enabled.", + "Only the user media library uses a shared host bind by default.", + "Preserve all OCI image environment entries and append explicit Compose and native-LXC overrides after them.", + "Run Valkey with its official entrypoint and a backed-up managed /data volume, without authentication on the private stack network.", + "Start and healthcheck each dependency before starting the next service.", + "Do not enable a GPU ML profile until every profile-specific preflight check passes." + ] + }, + "services": { + "database": { + "vmid_offset": 2, + "hostname_template": "${stack_name}-db", + "image_ref": "database", + "ostype": "auto-detect-from-image", + "unprivileged": true, + "features": [ + "nesting=1" + ], + "resources": { + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8 + }, + "network_interfaces": [ + { + "name": "eth0", + "role": "private", + "bridge_from": "private_network.bridge", + "address_from": "private_network.database_address", + "default_gateway": false + } + ], + "entrypoint": "/usr/local/bin/immich-docker-entrypoint.sh postgres -c config_file=/etc/postgresql/postgresql.conf -c listen_addresses=127.0.0.1,${private_network.database_ip}", + "halt_signal": "SIGINT", + "startup": { + "order": 10, + "up_delay_seconds": 10, + "down_timeout_seconds": 30 + }, + "mounts": [ + "database-data" + ], + "environment": { + "POSTGRES_USER": "${database.username}", + "POSTGRES_DB": "${database.name}", + "POSTGRES_INITDB_ARGS": "--data-checksums", + "PGDATA": "/var/lib/postgresql/data/pgdata", + "DB_STORAGE_TYPE": "${database.storage_type}", + "POSTGRES_PASSWORD": "${generated.db_password}" + }, + "healthcheck": { + "type": "command", + "command": [ + "pg_isready", + "-h", + "${private_network.database_ip}", + "-p", + "5432" + ], + "timeout_seconds": 5, + "retries": 30 + }, + "entrypoint_override": "official-immich-postgres-entrypoint-with-private-listen-argument", + "listen_addresses": [ + "127.0.0.1", + "${private_network.database_ip}" + ] + }, + "valkey": { + "vmid_offset": 3, + "hostname_template": "${stack_name}-valkey", + "image_ref": "valkey", + "ostype": "auto-detect-from-image", + "unprivileged": true, + "features": [ + "nesting=1" + ], + "resources": { + "cores": 1, + "memory_mb": 512, + "swap_mb": 256, + "rootfs_size_gb": 4 + }, + "network_interfaces": [ + { + "name": "eth0", + "role": "private", + "bridge_from": "private_network.bridge", + "address_from": "private_network.valkey_address", + "default_gateway": false + } + ], + "entrypoint": "docker-entrypoint.sh valkey-server", + "working_directory": "/data", + "halt_signal": "SIGTERM", + "startup": { + "order": 20, + "up_delay_seconds": 5, + "down_timeout_seconds": 15 + }, + "mounts": [], + "healthcheck": { + "type": "command", + "command": [ + "valkey-cli", + "-h", + "${private_network.valkey_ip}", + "ping" + ], + "expected_output": "PONG", + "timeout_seconds": 5, + "retries": 30 + }, + "entrypoint_override": "official-image-command" + }, + "machine_learning": { + "vmid_offset": 1, + "hostname_template": "${stack_name}-ml", + "image_ref_from": "machine_learning.acceleration", + "image_resolution_from": "installer_contract.machine_learning_image_resolution", + "resource_profile_from": "installer_contract.machine_learning_resource_profiles", + "devices_from": "hardware_profiles.machine_learning.${machine_learning.acceleration}.devices", + "preflight_checks_from": "hardware_profiles.machine_learning.${machine_learning.acceleration}.preflight_checks", + "ostype": "auto-detect-from-image", + "unprivileged": true, + "features": [ + "nesting=1" + ], + "resources": { + "cores": 2, + "memory_mb": 2048, + "swap_mb": 1024, + "rootfs_size_gb": 12 + }, + "network_interfaces": [ + { + "name": "eth0", + "role": "frontend-downloads", + "bridge_from": "frontend_network.bridge", + "ipv4_mode_from": "frontend_network.ipv4_mode", + "default_gateway": true + }, + { + "name": "eth1", + "role": "private", + "bridge_from": "private_network.bridge", + "address_from": "private_network.machine_learning_address", + "default_gateway": false + } + ], + "entrypoint": "tini -- python -m immich_ml", + "working_directory": "/usr/src", + "halt_signal": "SIGTERM", + "startup": { + "order": 30, + "up_delay_seconds": 10, + "down_timeout_seconds": 30 + }, + "mounts": [ + "machine-learning-cache" + ], + "environment": { + "IMMICH_HOST": "${private_network.machine_learning_ip}", + "IMMICH_PORT": "3003", + "MACHINE_LEARNING_CACHE_FOLDER": "/cache", + "TRANSFORMERS_CACHE": "/cache", + "LD_PRELOAD": "/usr/lib/libmimalloc.so.2" + }, + "healthcheck": { + "type": "http", + "url": "http://${private_network.machine_learning_ip}:3003/ping", + "expected_body": "pong", + "timeout_seconds": 5, + "retries": 40 + }, + "entrypoint_override": "explicit-official-image-command" + }, + "server": { + "vmid_offset": 0, + "hostname_template": "${stack_name}-server", + "image_ref": "server", + "ostype": "auto-detect-from-image", + "unprivileged": true, + "features": [ + "nesting=1" + ], + "resources": { + "cores": 4, + "memory_mb": 3072, + "swap_mb": 1024, + "rootfs_size_gb": 16 + }, + "network_interfaces": [ + { + "name": "eth0", + "role": "frontend", + "bridge_from": "frontend_network.bridge", + "ipv4_mode_from": "frontend_network.ipv4_mode", + "default_gateway": true + }, + { + "name": "eth1", + "role": "private", + "bridge_from": "private_network.bridge", + "address_from": "private_network.server_address", + "default_gateway": false + } + ], + "entrypoint": "tini -- /usr/local/bin/immich-lxc-start", + "working_directory": "/usr/src/app", + "halt_signal": "SIGTERM", + "startup": { + "order": 40, + "up_delay_seconds": 10, + "down_timeout_seconds": 30 + }, + "ports": [ + { + "port": 2283, + "protocol": "tcp", + "purpose": "web-ui-and-api" + } + ], + "mounts": [ + "media" + ], + "devices": [ + "video-render" + ], + "environment": { + "TZ": "${timezone}", + "CPU_CORES": "${services.server.resources.cores}", + "IMMICH_HOST": "0.0.0.0", + "IMMICH_PORT": "2283", + "DB_HOSTNAME": "${private_network.database_ip}", + "DB_PORT": "5432", + "DB_USERNAME": "${database.username}", + "DB_DATABASE_NAME": "${database.name}", + "DB_VECTOR_EXTENSION": "${database.vector_extension}", + "REDIS_HOSTNAME": "${private_network.valkey_ip}", + "REDIS_PORT": "6379", + "IMMICH_MACHINE_LEARNING_URL": "http://${private_network.machine_learning_ip}:3003", + "LIBVA_DRIVER_NAME": "${video_transcoding.driver}", + "DB_PASSWORD": "${generated.db_password}" + }, + "healthcheck": { + "type": "http", + "port": 2283, + "path": "/api/server/ping", + "expected_json": { + "res": "pong" + }, + "timeout_seconds": 5, + "retries": 60, + "start_period_seconds": 120 + }, + "entrypoint_override": "validated-lxc-network-readiness-adaptation" + } + }, + "storage": { + "media": { + "mode": "user-selectable", + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_storage_from": "rootfs_storage", + "managed_size_gb_default": 100, + "host_path_when_shared": "${shared_media_root}", + "container_path": "/data", + "service": "server", + "backup_by_mode": { + "managed-volume": true, + "host-bind": false + }, + "create_if_missing": true, + "shareable_with_other_lxc": true + }, + "database-data": { + "mode": "managed-volume", + "storage_from": "database_storage", + "size_gb_from": "database_size_gb", + "container_path": "/var/lib/postgresql/data", + "service": "database", + "backup": true, + "local_storage_required": true, + "network_filesystem_allowed": false, + "initialization": { + "data_subdirectory": "pgdata", + "reason": "Avoid PostgreSQL initialization failure caused by lost+found at the filesystem root.", + "owner_strategy": "resolve-postgres-uid-through-unprivileged-idmap", + "mode": "0700" + } + }, + "machine-learning-cache": { + "mode": "managed-volume", + "storage_from": "rootfs_storage", + "size_gb_from": "machine_learning.model_cache_size_gb", + "container_path": "/cache", + "service": "machine_learning", + "backup": true + }, + "valkey-data": { + "mode": "managed-volume", + "storage_from": "rootfs_storage", + "size_gb": 4, + "container_path": "/data", + "service": "redis", + "backup": true + } + }, + "devices": { + "video-render": { + "enabled_when": { + "field": "video_transcoding.acceleration", + "not_equals": "cpu" + }, + "host_path_from": "video_transcoding.render_device", + "container_path": "/dev/dri/renderD128", + "permissions": "rwm", + "mode": "0660", + "gid_strategy": "resolve-render-group-on-host", + "service": "server" + } + }, + "hardware_profiles": { + "video_transcoding": { + "cpu": { + "validated": false, + "devices": [] + }, + "vaapi": { + "validated": true, + "service": "server", + "devices": [ + "/dev/dri/renderD128" + ], + "supported_vendors": [ + "amd", + "intel", + "nvidia" + ], + "post_install_application_setting_required": true, + "application_setting": "Administration > Video transcoding > Hardware acceleration > VAAPI" + } + }, + "machine_learning": { + "cpu": { + "validated": true, + "image_ref": "machine_learning_cpu", + "devices": [], + "recognition_accelerated_by_hardware": false + }, + "rocm": { + "validated": false, + "validation_result_on_reference_host": "failed-gpu-reset", + "status": "experimental", + "image_ref": "machine_learning_rocm", + "vendor": "amd", + "provider": "MIGraphXExecutionProvider", + "devices": [ + { + "host_path": "/dev/kfd", + "container_path": "/dev/kfd", + "gid_strategy": "resolve-render-group-on-host" + }, + { + "host_path": "/dev/dri/renderD128", + "container_path": "/dev/dri/renderD128", + "gid_strategy": "resolve-render-group-on-host" + }, + { + "host_path": "/dev/dri/card0", + "container_path": "/dev/dri/card0", + "gid_strategy": "resolve-video-group-on-host" + } + ], + "recognition_accelerated_by_hardware": true, + "minimum_free_image_cache_gb": 35, + "preflight_checks": [ + "amdgpu-kernel-driver-loaded", + "dev-dri-present", + "dev-kfd-present", + "gpu-supported-by-rocm" + ], + "advanced_environment": { + "HSA_OVERRIDE_GFX_VERSION": null, + "HSA_USE_SVM": null + }, + "automatic_denylist": [ + { + "pci_id": "1002:164c", + "gpu": "AMD Lucienne integrated graphics", + "reason": "Real buffalo_l inference caused SDMA/compute timeouts and repeated host GPU resets.", + "tested_on": "2026-08-26" + } + ], + "warning": "Do not enable automatically on unsupported AMD integrated GPUs. HSA overrides are manual compatibility experiments, not a validated default." + }, + "openvino": { + "validated": false, + "status": "experimental", + "image_ref": "machine_learning_openvino", + "vendor": "intel", + "provider": "OpenVINOExecutionProvider", + "devices": [ + { + "host_path": "/dev/dri/renderD128", + "container_path": "/dev/dri/renderD128", + "gid_strategy": "resolve-render-group-on-host" + } + ], + "optional_devices": [ + "/dev/bus/usb" + ], + "device_cgroup_rules": [ + "c 189:* rmw" + ], + "recognition_accelerated_by_hardware": true, + "preflight_checks": [ + "intel-gpu-detected", + "dev-dri-present", + "kernel-supports-intel-gpu", + "openvino-provider-smoke-test" + ] + }, + "cuda": { + "validated": false, + "status": "experimental", + "image_ref": "machine_learning_cuda", + "vendor": "nvidia", + "provider": "CUDAExecutionProvider", + "device_strategy": "discover-and-pass-required-dev-nvidia-devices-and-driver-libraries", + "recognition_accelerated_by_hardware": true, + "preflight_checks": [ + "nvidia-gpu-compute-capability-at-least-5.2", + "nvidia-driver-version-at-least-545", + "nvidia-container-runtime-dependencies-present", + "cuda-provider-smoke-test" + ] + } + } + }, + "machine_learning_capabilities": { + "facial_recognition": { + "task": "facial-recognition", + "observed_model": "buffalo_l", + "pipeline": [ + "detection", + "recognition" + ], + "gpu_profiles": [ + "rocm", + "openvino", + "cuda" + ], + "configured_by": "Immich administration UI", + "installer_writes_application_setting": false + }, + "smart_search": { + "task": "clip", + "observed_model": "ViT-B-32__openai", + "pipeline": [ + "visual", + "textual" + ], + "gpu_profiles": [ + "rocm", + "openvino", + "cuda" + ], + "configured_by": "Immich administration UI", + "installer_writes_application_setting": false + }, + "validation_protocol": { + "ping_is_not_sufficient": true, + "required_steps": [ + "Verify the expected ONNX execution provider is available.", + "Run a real facial-recognition detection and embedding request.", + "Run visual and textual smart-search embeddings.", + "Observe GPU utilization during inference.", + "Reject the profile on provider fallback, HTTP 500, kernel timeout or GPU reset.", + "Keep the validated CPU ML service available until GPU validation passes." + ] + } + }, + "configuration_schema": { + "stack_name": { + "type": "string", + "required": true, + "default": "immich", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,31}$" + } + }, + "base_vmid": { + "type": "integer", + "required": false, + "default": null, + "description": "VMID of the server; the other three VMIDs are reserved using the template's offsets." + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "default": "local-lvm" + }, + "database_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "default": "local-lvm", + "validation": { + "must_be_local": true, + "network_filesystem_allowed": false + } + }, + "media_storage_mode": { + "type": "select", + "required": true, + "default": "managed-volume", + "options": [ + "managed-volume", + "host-bind" + ] + }, + "media_storage": { + "type": "storage-selector", + "required_when": { + "field": "media_storage_mode", + "equals": "managed-volume" + }, + "content_types": [ + "rootdir" + ], + "default": "local-lvm" + }, + "media_size_gb": { + "type": "integer", + "required_when": { + "field": "media_storage_mode", + "equals": "managed-volume" + }, + "default": 100, + "minimum": 8 + }, + "shared_media_root": { + "type": "host-directory", + "required_when": { + "field": "media_storage_mode", + "equals": "host-bind" + }, + "default": "/mnt/oci-shared/media/immich/${stack_name}", + "create_if_missing": true + }, + "database_size_gb": { + "type": "integer", + "required": true, + "default": 32, + "minimum": 8 + }, + "frontend_bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "frontend_ipv4_mode": { + "type": "select", + "required": true, + "default": "dhcp", + "options": [ + "dhcp", + "static" + ] + }, + "private_bridge": { + "type": "network-bridge", + "required": true, + "default": "vmbr10", + "create_if_missing": true + }, + "private_subnet": { + "type": "cidr", + "required": true, + "default": "10.77.0.0/24", + "validation": { + "must_be_rfc1918": true, + "must_not_overlap_existing_networks": true + } + }, + "video_transcoding_acceleration": { + "type": "select", + "required": true, + "default": "vaapi", + "options": [ + "cpu", + "vaapi" + ] + }, + "video_render_device": { + "type": "host-device-selector", + "required_when": { + "field": "video_transcoding_acceleration", + "equals": "vaapi" + }, + "default": "/dev/dri/renderD128", + "filter": "/dev/dri/renderD*" + }, + "vaapi_driver": { + "type": "select", + "required": false, + "default": "auto", + "options": [ + "auto", + "radeonsi", + "iHD", + "i965" + ] + }, + "machine_learning_acceleration": { + "type": "select", + "required": true, + "default": "cpu", + "options": [ + "cpu", + "rocm", + "openvino", + "cuda" + ], + "automatic_installer_options": [ + "cpu" + ], + "experimental_options": [ + "rocm", + "openvino", + "cuda" + ], + "warnings": { + "rocm": "Experimental and only for ROCm-compatible AMD GPUs. Requires /dev/dri, /dev/kfd and at least 35 GiB free for the image. PCI 1002:164c is denied automatically after a real GPU-reset failure.", + "openvino": "Experimental in native OCI LXC. Intended for compatible Intel GPUs and requires /dev/dri access.", + "cuda": "Experimental in native OCI LXC. Requires a supported NVIDIA GPU, driver 545 or newer and the required NVIDIA runtime devices and libraries." + } + }, + "timezone": { + "type": "timezone", + "required": true, + "default": "Europe/Madrid" + }, + "onboot": { + "type": "boolean", + "required": true, + "default": false + } + }, + "validated_profile": { + "id": "pve55-amd-vaapi-ml-cpu", + "description": "Reproducible profile based on a validated working deployment.", + "validated_on": "2026-08-27", + "validation_status": "passed-clean-import-managed-storage-coordinated-restart", + "host": { + "cpu": "AMD Ryzen 7 5700U", + "gpu": "AMD Lucienne integrated graphics", + "gpu_pci_id": "1002:164c", + "architecture": "amd64", + "video_render_device": "/dev/dri/renderD128", + "validated_render_gid": 993 + }, + "vmids": { + "server": 121, + "machine_learning": 122, + "database": 123, + "valkey": 124 + }, + "network": { + "frontend_bridge": "vmbr0", + "private_bridge": "vmbr10", + "private_subnet": "10.77.0.0/24", + "database_and_valkey_private_only": true + }, + "acceleration": { + "video_transcoding": "vaapi-amd", + "vaapi_h264_encode": "passed", + "machine_learning": "cpu", + "machine_learning_hardware_acceleration": false, + "safe_machine_learning_default": "cpu", + "rocm_on_ryzen_5700u": "failed-unsafe-gpu-reset" + }, + "storage": { + "validated_live_profile": { + "media": "host-bind,backup=0", + "database": "managed-volume,backup=1", + "secrets": "none-compose-environment-model", + "machine_learning_cache": "managed-volume,backup=0", + "valkey": "rootfs-only,ephemeral" + }, + "template_target_model": { + "media": "managed-volume,backup=1 or host-bind,backup=0 selected at installation", + "database": "managed-volume,backup=1", + "valkey": "rootfs-only,ephemeral", + "machine_learning_cache": "managed-volume,backup=0" + }, + "target_model_live_migration": "passed" + }, + "validation": { + "api_ping": "passed", + "web_ui": "passed", + "version": "3.1.0", + "database_public_tables": 66, + "database_persistence": "passed-coordinated-restart", + "native_vzdump_database_inclusion": "configured-backup-1-not-yet-restored", + "machine_learning_ping": "passed", + "rocm_provider_available": "MIGraphXExecutionProvider", + "rocm_test_vmid": 127, + "rocm_test_private_ip": "10.77.0.14", + "rocm_buffalo_l_face_inference": "failed-http-500", + "rocm_gpu_busy_max_percent": 85, + "rocm_host_gpu_reset_observed": true, + "rocm_post_stop_gpu_busy_percent": 99, + "rocm_post_stop_gpu_clock_mhz": 1900, + "rocm_post_stop_memory_clock_mhz": 1200, + "rocm_post_stop_gpu_power_watts": 25, + "rocm_post_stop_gpu_temperature_celsius": 57, + "rocm_post_stop_device_users": 0, + "rocm_host_reboot_recommended": true, + "vaapi_after_rocm_reset": "passed", + "coordinated_restart": "passed", + "historical_custom_valkey_authentication": "passed", + "historical_custom_valkey_unauthenticated_rejection": "passed", + "target_compose_environment_translation": "passed", + "database_data_checksums": "on", + "database_extensions": "cube,earthdistance,pg_trgm,plpgsql,unaccent,uuid-ossp,vchord,vector", + "database_managed_volume_backup_flag": "passed", + "machine_learning_profile": "cpu", + "machine_learning_mimalloc_path": "/usr/lib/libmimalloc.so.2", + "machine_learning_mimalloc_path_validation": "passed", + "vaapi_h264_encode": "passed-encoder-present", + "vaapi_hevc_encode": "passed-encoder-present", + "media_write": "passed", + "runtime_environment_uniqueness": "passed", + "private_dependency_network": "passed" + }, + "previous_validation_status": "passed-historical-profile-target-compose-translation-pending-live-migration", + "validated_lxc_adapted_profile": { + "server_entrypoint": "tini -- /usr/local/bin/immich-lxc-start", + "database_private_listen": true, + "custom_host_services": false, + "validation": "passed-clean-import-managed-storage", + "server_route_detection": "/proc/net/route", + "requires_iproute2": false, + "database_entrypoint": "/usr/local/bin/immich-docker-entrypoint.sh" + }, + "candidate_direct_image_profile": { + "entrypoints": "from-oci-image-config", + "custom_rootfs_files": false, + "validation": "pending-clean-import-and-route-race-test" + } + }, + "backup_restore": { + "native_proxmox_backup": true, + "coordinated_stack_backup_required": true, + "included_managed_volumes": [ + "database-data" + ], + "excluded_volumes": [ + "machine-learning-cache" + ], + "external_backup_required": [ + "media" + ], + "application_consistency": { + "preferred_mode": "stop", + "stop_order": [ + "server", + "machine_learning", + "valkey", + "database" + ], + "logical_database_backup": { + "required": true, + "method": "pg_dump", + "store_outside_database_volume": true + } + }, + "restore_order": [ + "restore-all-four-lxc-backups-from-the-same-backup-set", + "verify-shared-media-host-path", + "start-database", + "start-valkey", + "start-machine-learning", + "start-server", + "wait-for-all-healthchecks" + ] + }, + "boundaries": { + "bundles_internal_immich_configuration": false, + "bundles_credentials": false, + "bundles_user_accounts": false, + "bundles_user_photos_or_videos": false, + "installer_generates_credentials": true, + "installer_must_not_write_immich_application_settings": true, + "installer_must_not_enable_unvalidated_gpu_ml_automatically": true, + "installer_must_enforce_gpu_compatibility_denylist": true, + "installer_must_fallback_to_cpu_after_gpu_validation_failure": false + }, + "notes": [ + "Esta plantilla describe la infraestructura OCI necesaria para instalar Immich; no contiene la configuracion interna de la aplicacion ni datos de usuario.", + "El servidor y machine learning usan dos interfaces; PostgreSQL y Valkey solo usan la red privada.", + "VAAPI acelera la transcodificacion de video, no el reconocimiento facial ni la busqueda inteligente.", + "El perfil ML CPU es el unico perfil seguro y validado en el Ryzen 7 5700U del laboratorio.", + "ROCm puede acelerar reconocimiento facial y busqueda inteligente en GPU AMD compatibles, pero la Lucienne PCI 1002:164c fallo con un reset real de GPU y queda bloqueada para activacion automatica.", + "Tras el fallo ROCm, la GPU Lucienne mantuvo frecuencias y consumo elevados sin procesos asociados; el instalador debe detener las pruebas y recomendar un reinicio del host.", + "OpenVINO para Intel y CUDA para NVIDIA estan declarados como opciones futuras, pero deben superar una inferencia real antes de sustituir al perfil CPU.", + "La base de datos debe permanecer en almacenamiento local; no debe ubicarse en NFS, SMB ni otro recurso de red.", + "New installations use managed backup=1 volumes for PostgreSQL, Valkey /data and the reproducible ML cache; old laboratory layouts are not silently migrated.", + "DB_PASSWORD from the official Immich .env is represented directly in lxc.environment.runtime and is therefore visible in PVE configuration, matching Docker inspection behavior.", + "La biblioteca multimedia puede utilizar un host-bind compartible, pero necesita una estrategia de backup independiente del LXC.", + "El despliegue OCI nativo dentro de LXC es experimental y no es el metodo de instalacion recomendado oficialmente por Immich.", + "La instalacion limpia del 2026-08-27 valido los CT121-124, PostgreSQL en volumen administrado backup=1, cache ML administrada, red privada, reinicio coordinado, VAAPI y la ruta oficial de mimalloc." + ], + "credentials": { + "model": "compose-environment", + "pve_visibility": "visible-by-design", + "explanation": "The DB_PASSWORD value from the official .env is generated or requested by the installer and translated to lxc.environment.runtime. PostgreSQL receives the same value as POSTGRES_PASSWORD.", + "db_password": { + "generator": "openssl-rand-alphanumeric", + "characters": 48, + "allowed_characters": "A-Za-z0-9", + "targets": [ + "services.server.environment.DB_PASSWORD", + "services.database.environment.POSTGRES_PASSWORD" + ], + "verify_identical_values": true + }, + "valkey_password": { + "enabled": false, + "reason": "The official Immich v3.1.0 Compose runs Valkey without authentication on its private network." + }, + "application_accounts": { + "managed_by": "Immich", + "storage": "Immich application database", + "template_contains_accounts": false + } + }, + "generated_assets": { + "server-network-wrapper": { + "target_service": "server", + "target_path": "/usr/local/bin/immich-lxc-start", + "mode": "0755", + "purpose": "Wait for the host-managed frontend default route through /proc/net/route before executing the image-provided command.", + "timeout_seconds": 60, + "post_route_delay_seconds": 3, + "official_final_command": "/bin/bash -c start.sh", + "validation": "passed on clean import in CT121", + "route_detection": "grep -qE '^eth0[[:space:]]+00000000[[:space:]]' /proc/net/route", + "requires_iproute2": false + }, + "postgres-listen-runtime": { + "target_service": "database", + "type": "proxmox-entrypoint-argument", + "value": "/usr/local/bin/immich-docker-entrypoint.sh postgres -c config_file=/etc/postgresql/postgresql.conf -c listen_addresses=127.0.0.1,${private_network.database_ip}", + "purpose": "Bind PostgreSQL only to loopback and the private stack address on every start.", + "validation": "passed on clean import in CT123" + } + }, + "translation_contract": { + "id": "docker-compose-to-proxmox-oci-lxc", + "version": "1.1.0", + "file": "docker-oci-translation-policy.json" + }, + "docker_compatibility": { + "policy": "preserve-upstream-compose-contract", + "upstream_reference": "https://github.com/immich-app/immich/releases/download/v3.1.0/docker-compose.yml", + "mapping": { + "compose_env_file": "lxc.environment.runtime", + "compose_environment": "lxc.environment.runtime", + "upload_bind": "host-bind:/data,backup=0", + "database_bind": "managed-volume:/var/lib/postgresql/data,backup=1", + "model_cache_named_volume": "managed-volume:/cache,backup=1", + "redis_storage": "managed-volume:/data,backup=1", + "credential_visibility": "visible-in-pve-config-by-design", + "model_cache_environment": "preserve-official-LD_PRELOAD=/usr/lib/libmimalloc.so.2" + }, + "adaptations": [ + { + "id": "private-service-addresses", + "upstream_behavior": "Compose service names provide internal DNS discovery.", + "native_lxc_behavior": "Use fixed addresses on a private Proxmox bridge.", + "reason": "The services run in separate native LXC containers without a Compose DNS network.", + "behavioral_impact": "none" + }, + { + "id": "database-managed-volume", + "upstream_behavior": "DB_DATA_LOCATION bind-mounts PostgreSQL data from the Docker host.", + "native_lxc_behavior": "Attach a local managed Proxmox volume at the same container path with backup enabled.", + "reason": "The database is private to its LXC and must participate in native Proxmox backup.", + "behavioral_impact": "storage-management-only" + }, + { + "id": "server-route-wait", + "upstream_behavior": "Docker creates the service network and route before starting the server process.", + "native_lxc_behavior": "A minimal wrapper reads the eth0 default route from /proc/net/route before executing the official server command.", + "reason": "The DHCP frontend route can appear after PID 1 starts in a native OCI LXC.", + "behavioral_impact": "startup-only", + "validation": "passed in CT121; the image intentionally does not include iproute2" + }, + { + "id": "postgres-private-listen", + "upstream_behavior": "PostgreSQL listens on the private Compose network.", + "native_lxc_behavior": "Preserve /usr/local/bin/immich-docker-entrypoint.sh and the official PostgreSQL config_file argument, then append listen_addresses for loopback and the fixed private LXC address.", + "reason": "The database must be reachable from the server LXC without a frontend interface.", + "behavioral_impact": "equivalent-private-reachability", + "validation": "passed in CT123 on clean import" + } + ] + }, + "proxmox_oci_contract": { + "policy": "docker-compose-to-proxmox-oci-lxc", + "version": "1.1.0", + "preserve_official_application_contract": true, + "documented_lxc_adaptations": "allowed-when-required-and-validated", + "candidate_simplifications": "must-pass-equivalent-tests-before-replacement" + }, + "historical_release": { + "version": "v3.1.0", + "validated_on": "2026-08-27", + "note": "Historical validation only; catalog installation resolves rolling latest images." + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "depends_on", + "environment", + "healthcheck", + "image", + "ports", + "restart", + "shm_size", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The native four-LXC installer and coordinated update adapter support CPU, Intel OpenVINO and NVIDIA CUDA. Real rootfs replacement and full native-backup rollback with GPU inference passed on documented Intel/NVIDIA hardware. A real v3.1.0 to v3.2.2 upgrade and rollback also passed on Intel, preserving a laboratory account and synthetic asset. Not universal GPU or arbitrary release-transition validation; ROCm remains pending." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "passed-historical-profile-2026-08-27", + "service_health": "passed-historical-profile", + "restart_persistence": "passed-coordinated-restart", + "backup_restore": "passed-four-member-native-backup-restore", + "update_preserves_data": "passed-real-v3.1.0-to-v3.2.2-coordinated-upgrade-and-rollback-intel", + "historical_version": "3.1.0", + "historical_profile": "pve55-amd-vaapi-ml-cpu", + "private_dependency_network": "passed", + "postgres_local_managed_volume": "passed", + "machine_learning_cpu": "passed", + "video_transcoding_vaapi_amd": "passed", + "machine_learning_openvino": "passed-dedicated-native-stack-synthetic-inference-and-principal-restart", + "machine_learning_cuda": "passed-dedicated-native-stack-dynamic-toolkit-synthetic-inference-and-principal-restart", + "gpu_lab_20260915": { + "environment": "Docker inside unprivileged Debian 13 LXC on Proxmox 9.0.6; not native OCI", + "immich_version": "v3.2.2", + "intel": { + "pci_id": "8086:46a3", + "gpu": "Alder Lake-P GT1 UHD Graphics", + "image_digest": "sha256:4013ec28ccf6344d7ae24554743a116d7f61124b98858f5646a401d5c5df12e2", + "provider": "OpenVINOExecutionProvider", + "device": "GPU.0", + "four_model_inferences": "passed; profiled inference nodes on OpenVINO GPU" + }, + "nvidia": { + "pci_id": "10de:1cb1", + "gpu": "Quadro P1000 4GB", + "driver": "580.178.04", + "image_digest": "sha256:38001e84ce46206e9e019d8ee7f567bf55914f019dff8f6a70d02fd93bb14073", + "provider": "CUDAExecutionProvider", + "four_model_inferences": "passed; CUDA execution confirmed, auxiliary CPU nodes in detection and text" + }, + "models": [ + "buffalo_l detection", + "buffalo_l recognition", + "ViT-B-32__openai visual", + "ViT-B-32__openai textual" + ], + "inputs": "Synthetic tensors, synthetic JPEG and text; no personal photographs", + "http_predict": "Text and synthetic-image requests passed on both backends; synthetic image contains no faces", + "limitations": [ + "Not a recognition-accuracy benchmark", + "Not native OCI validation", + "Not universal GPU compatibility", + "No long-running library workload" + ], + "tested_thread_environment": { + "MACHINE_LEARNING_MODEL_INTRA_OP_THREADS": "2", + "MACHINE_LEARNING_MODEL_INTER_OP_THREADS": "1" + }, + "thread_environment_reason": "Avoid ONNX automatic CPU-affinity warnings within the LXC cpuset; no image patches", + "evidence": "docs/lab/immich-gpu-20260915/README.md" + }, + "machine_learning_rocm_amd_lucienne_1002_164c": "failed-unsafe-gpu-reset-auto-denied", + "rolling_latest": "passed-release-channel-v3.1.0-to-v3.2.2-intel", + "native_stack_gpu_20260918": { + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md", + "intel": "8086:46a3; quota 4; RAM 8192 MiB", + "nvidia": "Quadro P1000; dynamic Container Toolkit; cores 4; RAM 8192 MiB", + "scope": "Four real ML models with synthetic inputs, HTTP inference, server-to-ML private-network requests, principal and ML restart, saved profile recipes", + "exclusions": [ + "Full photo-library workflow and recognition accuracy", + "Host reboot", + "Coordinated stack image updates", + "Universal GPU compatibility" + ] + }, + "coordinated_update_20260918": { + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md", + "intel_vmids": [ + 9821, + 9822, + 9823, + 9824 + ], + "nvidia_vmids": [ + 9831, + 9832, + 9833, + 9834 + ], + "replacement": "passed", + "injected_failure_full_rollback": "passed", + "persistent_data": "library/cache markers, PostgreSQL row, persisted Valkey value", + "gpu": "four real models with synthetic inputs after update and rollback on both backends", + "scope": "Same registry digests; cross-release migration not yet validated" + }, + "cross_release_upgrade_20260918": { + "evidence": "docs/lab/immich-stack-gpu-20260918/README.md", + "source_version": "v3.1.0", + "target_version": "v3.2.2", + "vmids": [ + 9841, + 9842, + 9843, + 9844 + ], + "acceleration": "Intel OpenVINO", + "update": "passed", + "rollback": "passed-after-upgraded-principal-healthcheck", + "application_data": "Laboratory account and synthetic JPEG; identical asset ID/checksum; original download verified after upgrade", + "persistent_data": "Library/cache markers, PostgreSQL row and persisted Valkey value", + "gpu": "Four real models with synthetic inputs before upgrade, after rollback and after committed upgrade", + "scope": "Specific release transition on documented Intel hardware; not arbitrary version jumps or NVIDIA cross-release migration" + }, + "native_ml_gpu_lab_20260918": { + "evidence": "docs/lab/immich-native-gpu-20260918/README.md", + "environment": "Native OCI through the shared installer on Proxmox .50", + "intel": { + "cpu_allocation": "quota", + "four_model_inferences": "passed on GPU.0", + "http_predict": "passed initially and after three shutdown/start cycles", + "cpuset_profile": "intermittent SIGSEGV; original CPU set reproduced failure" + }, + "nvidia": { + "runtime": "dynamic NVIDIA Container Toolkit", + "four_model_inferences": "passed with CUDA execution", + "http_predict": "passed initially and after shutdown/start" + }, + "scope": "Synthetic tensors and JPEG; no accuracy benchmark or sustained library workload", + "dedicated_stack_gpu_integration": "pending", + "coordinated_update_validation": "pending" + } + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-official-compose-and-resolved-latest-digests-for-all-four-images", + "automatic_unattended_updates": false, + "coordinated_stack_required": true, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "starts_stopped_dependencies": true, + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false, + "persistent_contract": "/etc/pve/priv/proxmenux-stack-.json", + "runtime_owner": "proxmox-ve" + }, + "start_order": [ + "database", + "redis", + "immich-machine-learning", + "immich-server" + ], + "stop_order": [ + "immich-server", + "immich-machine-learning", + "redis", + "database" + ], + "backup": { + "native_proxmox_backup": true, + "coordinated_stack_backup_required": true, + "included_managed_volumes": [ + "database-data" + ], + "excluded_volumes": [ + "machine-learning-cache" + ], + "external_backup_required": [ + "media" + ], + "application_consistency": { + "preferred_mode": "stop", + "stop_order": [ + "server", + "machine_learning", + "valkey", + "database" + ], + "logical_database_backup": { + "required": true, + "method": "pg_dump", + "store_outside_database_volume": true + } + }, + "restore_order": [ + "restore-all-four-lxc-backups-from-the-same-backup-set", + "verify-shared-media-host-path", + "start-database", + "start-valkey", + "start-machine-learning", + "start-server", + "wait-for-all-healthchecks" + ] + }, + "gpu_profile_failure_policy": { + "stop_failed_machine_learning_lxc": true, + "preserve_failure_metadata_without_secrets": true, + "record_gpu_pci_id_and_driver": true, + "stop_further_gpu_tests_after_kernel_timeout_or_reset": true, + "recommend_host_reboot_when_gpu_clocks_or_power_do_not_return_to_idle": true, + "automatic_hsa_override_retry": false, + "fallback_profile": "cpu", + "reuse_model_cache_when_compatible": true, + "start_server_only_after_cpu_fallback_is_healthy": true + }, + "uninstall": { + "remove_rootfs": true, + "preserve_media_by_default": true, + "preserve_database_by_default": true, + "remove_private_bridge_only_if_unused": true + } + } +} diff --git a/oci/catalog/curated/jdownloader.json b/oci/catalog/curated/jdownloader.json new file mode 100644 index 00000000..6eb741f7 --- /dev/null +++ b/oci/catalog/curated/jdownloader.json @@ -0,0 +1,1017 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-jdownloader", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "JDownloader" + }, + "tagline": { + "en_US": "JDownloader 2 with browser GUI and MyJDownloader support" + }, + "description": { + "en_US": "The maintained jlesage JDownloader 2 image adapted as a native Proxmox OCI LXC with persistent configuration and shared downloads." + }, + "category": "downloads", + "category_label": "Files & Downloads", + "author": "jlesage", + "developer": "jlesage", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 5800, + "path": "/" + }, + "website": "https://jdownloader.org/", + "documentation": "https://github.com/jlesage/docker-jdownloader-2", + "repository": "https://github.com/jlesage/docker-jdownloader-2", + "tips": [ + "JDownloader 2 is the current application name; this curated entry replaces the duplicate jdownloader2 discovery entry.", + "Web authentication requires HTTPS unless the explicitly insecure upstream override is selected." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-26" + }, + "source": { + "provider": "jlesage", + "repository": "https://github.com/jlesage/docker-jdownloader-2", + "revision": "5b7968aaa112f1a8ab8ecc81bd65265bd6ca7423216ee8e32f77e46c0d5b4569", + "image_repository_url": "https://hub.docker.com/r/jlesage/jdownloader-2", + "readme_pushed_at": "2026-08-26T22:06:48Z", + "compose_sha256": "5b7968aaa112f1a8ab8ecc81bd65265bd6ca7423216ee8e32f77e46c0d5b4569", + "generated_at": "2026-09-12T15:54:10+00:00", + "default_branch": "master" + }, + "container_contract": { + "service_name": "jdownloader", + "container_name": "jdownloader", + "image": { + "reference": "jlesage/jdownloader-2:latest", + "registry": "docker.io", + "repository": "jlesage/jdownloader-2", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USER_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "GROUP_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "UMASK", + "example": "002", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "VNC_LOCALHOST_ONLY", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WEB_AUTHENTICATION", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WEB_AUTHENTICATION_USERNAME", + "example": "admin", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "WEB_AUTHENTICATION_PASSWORD", + "example": "${GENERATED_WEB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "SECURE_CONNECTION", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "jdownloader-config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/output", + "compose_source_example": "/mnt/oci-shared/downloads", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5800, + "published_example": 5800, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 3129, + "published_example": 3129, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: jdownloader\nservices:\n jdownloader:\n image: jlesage/jdownloader-2:latest\n environment:\n USER_ID: '1000'\n GROUP_ID: '1000'\n UMASK: '002'\n TZ: Etc/UTC\n VNC_LOCALHOST_ONLY: '1'\n WEB_AUTHENTICATION: '1'\n WEB_AUTHENTICATION_USERNAME: admin\n WEB_AUTHENTICATION_PASSWORD: ${GENERATED_GENERATED_WEB_PASSWORD}\n SECURE_CONNECTION: '1'\n ports:\n - 5800:5800\n - 3129:3129\n volumes:\n - jdownloader-config:/config\n - /mnt/oci-shared/downloads:/output\n restart: unless-stopped\nvolumes:\n jdownloader-config: {}\n" + }, + "compose_stack": { + "project_name": "jdownloader", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "jdownloader", + "service_count": 1, + "services": [ + { + "name": "jdownloader", + "image": "jlesage/jdownloader-2:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/jdownloader-2:latest", + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "UMASK": "002", + "TZ": "Etc/UTC", + "VNC_LOCALHOST_ONLY": "1", + "WEB_AUTHENTICATION": "1", + "WEB_AUTHENTICATION_USERNAME": "admin", + "WEB_AUTHENTICATION_PASSWORD": "${GENERATED_GENERATED_WEB_PASSWORD}", + "SECURE_CONNECTION": "1" + }, + "ports": [ + "5800:5800", + "3129:3129" + ], + "volumes": [ + "jdownloader-config:/config", + "/mnt/oci-shared/downloads:/output" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "jdownloader", + "volumes": { + "jdownloader-config": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "jdownloader-volume-0", + "service": "jdownloader", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "jdownloader-volume-1", + "service": "jdownloader", + "container_path": "/output", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "jdownloader" + ], + "stop_order": [ + "jdownloader" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "generated-web-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "jdownloader", + "environment_variable": "WEB_AUTHENTICATION_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "JDownloader WebUI", + "scheme": "https", + "port": 5800, + "path": "/", + "source": "upstream-jlesage-readme" + } + ], + "credentials": [ + { + "label": "JDownloader WebUI", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "WEB_AUTHENTICATION_USERNAME", + "password_environment": "WEB_AUTHENTICATION_PASSWORD", + "change_required": true, + "source": "official-image-environment", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "jdownloader2" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image-then-apply-reviewed-lxc-wrapper", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-user-values", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "persistent-config-volume-preparation", + "upstream_behavior": "Docker bind mounts an initially empty directory at /config.", + "native_lxc_behavior": "Create a managed volume at /config, remove its empty lost+found and apply the unprivileged UID mapping before first start.", + "reason": "The image expects /config to be writable by USER_ID/GROUP_ID.", + "behavioral_impact": "Configuration remains included in native Proxmox backups.", + "validation": "passed-laboratory-profile" + }, + { + "id": "secure-web-authentication", + "upstream_behavior": "WEB_AUTHENTICATION requires SECURE_CONNECTION unless the insecure override is enabled.", + "native_lxc_behavior": "Generate a password and enable HTTPS together; expose the self-signed-certificate warning at first run.", + "reason": "The upstream image disables secure sign-in over plain HTTP.", + "behavioral_impact": "The first browser visit must trust the generated certificate or use a reverse proxy.", + "validation": "passed-https-login-laboratory-profile" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "commands": [ + "pct", + "pvesm", + "skopeo", + "curl" + ], + "features": [ + "native-oci-lxc", + "managed-volume-backup" + ] + }, + "configuration_schema": { + "vmid": { + "type": "integer", + "required": false, + "default": null + }, + "hostname": { + "type": "string", + "required": true, + "default": "jdownloader", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,62}$" + } + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ] + }, + "rootfs_size_gb": { + "type": "integer", + "required": true, + "default": 8, + "minimum": 4 + }, + "config_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "description": "Volumen gestionado por Proxmox para /config e incluido en vzdump." + }, + "config_size_gb": { + "type": "integer", + "required": true, + "default": 4, + "minimum": 2 + }, + "downloads_host_path": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared/downloads", + "create_if_missing": true + }, + "management_mode": { + "type": "select", + "required": true, + "default": "myjdownloader-headless", + "options": [ + "myjdownloader-headless", + "web-gui" + ] + }, + "myjdownloader_email": { + "type": "email", + "required_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + }, + "sensitive": true, + "pve_visibility": "visible-by-design" + }, + "myjdownloader_password": { + "type": "password", + "required_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + }, + "sensitive": true, + "pve_visibility": "visible-by-design" + }, + "myjdownloader_device_name": { + "type": "string", + "required": true, + "default": "ProxMenux-JDownloader" + }, + "direct_connect_enabled": { + "type": "boolean", + "required": true, + "default": false, + "description": "No abre puertos en el router; solo declara el puerto local 3129." + }, + "web_authentication_enabled": { + "type": "boolean", + "required_when": { + "field": "management_mode", + "equals": "web-gui" + }, + "default": true + }, + "secure_connection_enabled": { + "type": "boolean", + "required_when": { + "field": "management_mode", + "equals": "web-gui" + }, + "default": true, + "description": "Activa HTTPS. Debe permanecer habilitado cuando web_authentication_enabled sea true porque la imagen oficial deshabilita el formulario de acceso sobre HTTP." + }, + "web_username": { + "type": "string", + "required_when": { + "field": "web_authentication_enabled", + "equals": true + }, + "default": "admin" + }, + "web_password": { + "type": "password", + "required_when": { + "field": "web_authentication_enabled", + "equals": true + }, + "generate_when_empty": true, + "sensitive": true, + "pve_visibility": "visible-by-design" + }, + "user_id": { + "type": "integer", + "required": true, + "default": 1000, + "minimum": 1 + }, + "group_id": { + "type": "integer", + "required": true, + "default": 1000, + "minimum": 1 + }, + "cores": { + "type": "integer", + "required": true, + "default": 2, + "minimum": 1 + }, + "memory_mb": { + "type": "integer", + "required": true, + "default": 2048, + "minimum": 1024 + }, + "swap_mb": { + "type": "integer", + "required": true, + "default": 512, + "minimum": 0 + }, + "bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "ipv4_mode": { + "type": "select", + "required": true, + "default": "dhcp", + "options": [ + "dhcp", + "static" + ] + }, + "timezone": { + "type": "timezone", + "required": true, + "default": "Europe/Madrid" + }, + "onboot": { + "type": "boolean", + "required": true, + "default": false + } + }, + "configuration_constraints": [ + { + "id": "web-authentication-requires-https", + "when": { + "field": "web_authentication_enabled", + "equals": true + }, + "assert": { + "field": "secure_connection_enabled", + "equals": true + }, + "error": "La imagen oficial de JDownloader deshabilita el inicio de sesion web si la conexion no usa HTTPS." + } + ], + "environment": [ + { + "name": "USER_ID", + "value_from": "user_id" + }, + { + "name": "GROUP_ID", + "value_from": "group_id" + }, + { + "name": "UMASK", + "value": "002" + }, + { + "name": "TZ", + "value_from": "timezone" + }, + { + "name": "JDOWNLOADER_HEADLESS", + "value_map": { + "myjdownloader-headless": "1", + "web-gui": "0" + }, + "value_from": "management_mode" + }, + { + "name": "VNC_LOCALHOST_ONLY", + "value": "1" + }, + { + "name": "SECURE_CONNECTION", + "value_map": { + "true": "1", + "false": "0" + }, + "value_from": "secure_connection_enabled", + "enabled_when": { + "field": "management_mode", + "equals": "web-gui" + } + }, + { + "name": "MYJDOWNLOADER_EMAIL", + "value_from": "myjdownloader_email", + "sensitive": true, + "enabled_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + } + }, + { + "name": "MYJDOWNLOADER_PASSWORD", + "value_from": "myjdownloader_password", + "sensitive": true, + "enabled_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + } + }, + { + "name": "MYJDOWNLOADER_DEVICE_NAME", + "value_from": "myjdownloader_device_name", + "enabled_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + } + }, + { + "name": "WEB_AUTHENTICATION", + "value": "1", + "enabled_when": { + "field": "web_authentication_enabled", + "equals": true + } + }, + { + "name": "WEB_AUTHENTICATION_USERNAME", + "value_from": "web_username", + "enabled_when": { + "field": "web_authentication_enabled", + "equals": true + } + }, + { + "name": "WEB_AUTHENTICATION_PASSWORD", + "value_from": "web_password", + "sensitive": true, + "enabled_when": { + "field": "web_authentication_enabled", + "equals": true + } + } + ], + "mounts": [ + { + "id": "config", + "container_path": "/config", + "source": "managed-volume", + "storage_field": "config_storage", + "size_field": "config_size_gb", + "backup": true, + "required": true, + "pre_first_start": [ + "mount-volume-on-host", + "remove-empty-lost-and-found", + "apply-unprivileged-root-ownership", + "unmount-volume" + ] + }, + { + "id": "downloads", + "container_path": "/output", + "source": "host-bind", + "host_path_field": "downloads_host_path", + "read_only": false, + "backup": false, + "required": true, + "pre_start_check": "host-path-mounted-and-writable-by-mapped-user-id" + } + ], + "deployment": { + "runtime": "proxmox-native-oci-lxc", + "unprivileged": true, + "entrypoint": "/usr/local/bin/jdownloader-lxc-start", + "working_directory": "/tmp", + "hostname_default": "jdownloader", + "onboot_default": false, + "startup_order_default": 15, + "startup_delay_seconds_default": 10, + "shutdown_timeout_seconds": 30, + "halt_signal": "SIGTERM", + "features": [ + "nesting=1" + ], + "ports": [ + { + "port": 5800, + "protocol": "tcp", + "purpose": "optional-web-gui", + "enabled_when": { + "field": "management_mode", + "equals": "web-gui" + } + }, + { + "port": 3129, + "protocol": "tcp", + "purpose": "optional-myjdownloader-direct-connect", + "enabled_field": "direct_connect_enabled" + } + ], + "preserve_image_environment": true, + "entrypoint_override": "documented-lxc-runtime-adaptation", + "entrypoint_source": "validated-lxc-oci-profile" + }, + "bootstrap": { + "myjdownloader": { + "enabled_when": { + "field": "management_mode", + "equals": "myjdownloader-headless" + }, + "method": "official-image-environment", + "environment": [ + "MYJDOWNLOADER_EMAIL", + "MYJDOWNLOADER_PASSWORD", + "MYJDOWNLOADER_DEVICE_NAME" + ], + "pve_visibility": "visible-by-design", + "procedure": [ + "set-selected-values-in-lxc.environment.runtime", + "start-with-entrypoint-and-cmd-imported-from-the-official-image", + "verify-java-process-and-myjdownloader-device-state" + ] + }, + "web_gui": { + "enabled_when": { + "field": "management_mode", + "equals": "web-gui" + }, + "authentication": { + "default_enabled": true, + "method": "official-image-environment", + "environment": [ + "SECURE_CONNECTION", + "WEB_AUTHENTICATION", + "WEB_AUTHENTICATION_USERNAME", + "WEB_AUTHENTICATION_PASSWORD" + ], + "pve_visibility": "visible-by-design", + "alternative": "Manage multiple users with the image-provided webauth-user tool and /config/webauth-htpasswd." + }, + "security": [ + "keep-vnc-localhost-only", + "require-web-authentication-for-non-lab-deployments", + "require-secure-connection-when-web-authentication-is-enabled", + "generate-self-signed-certificate-when-no-certificate-is-provided", + "allow-user-supplied-certificates-under-config-certs" + ] + } + }, + "healthcheck": { + "profiles": { + "web-gui": { + "type": "http", + "scheme": "https", + "port": 5800, + "path": "/", + "tls_verify": false, + "expected_status": 302, + "expected_location": "/login/" + }, + "myjdownloader-headless": { + "type": "command", + "command": [ + "pgrep", + "-f", + "JDownloader.jar" + ] + } + }, + "interval_seconds": 30, + "timeout_seconds": 10, + "retries": 20, + "start_period_seconds": 180 + }, + "backup_restore": { + "native_proxmox_backup": true, + "included_mounts": [ + "/config" + ], + "excluded_mounts": [ + "/output" + ], + "application_consistency": "Use snapshot mode with guest filesystem freeze; stop mode is preferred during active downloads.", + "restore_order": [ + "restore-vzdump", + "verify-shared-downloads-host-path", + "start-container", + "wait-for-selected-healthcheck" + ] + }, + "boundaries": { + "bundles_credentials": false, + "bundles_download_links": false, + "bundles_downloaded_content": false, + "installer_must_not_store_sensitive_values_in_pve_metadata": false, + "compose_environment_visible_in_pve_metadata": true + }, + "generated_assets": { + "runtime_wrapper": { + "container_path": "/usr/local/bin/jdownloader-lxc-start", + "owner": "root:root", + "mode": "0755", + "content": "#!/bin/sh\nset -e\nexec >>/config/container-start.log 2>&1\nexec /init\n", + "create_before_first_start": true + } + }, + "notes": [ + "La imagen de Jlesage se eligio frente a JayMoulin porque esta mantenida en 2026.", + "El directorio lost+found del volumen ext4 debe eliminarse antes del primer arranque en LXC sin privilegios.", + "La interfaz web no debe publicarse sin autenticacion fuera de un laboratorio local.", + "La imagen oficial requiere HTTPS cuando WEB_AUTHENTICATION=1; sobre HTTP muestra el formulario, pero deshabilita el inicio de sesion.", + "SECURE_CONNECTION=1 genera certificados autofirmados bajo /config/certs si el usuario no proporciona certificados validos.", + "El navegador puede exigir aceptar el certificado autofirmado la primera vez; un despliegue permanente debe admitir certificados propios o un proxy inverso HTTPS correctamente configurado.", + "La ruta /mnt/pve/Piblic/Transmission/eMule fue validada como ejemplo real de host-bind NFS, pero el instalador siempre debe solicitar downloads_host_path al usuario.", + "MyJDownloader es un servicio externo; su cuenta y disponibilidad no forman parte de la imagen OCI." + ] + }, + "installer_profile": { + "generated_sensitive_environment": { + "WEB_AUTHENTICATION_PASSWORD": { + "strategy": "token-hex", + "bytes": 16 + } + }, + "generated_files": [ + { + "id": "jdownloader-first-boot-wrapper", + "container_path": "/usr/local/bin/jdownloader-lxc-start", + "owner": "mapped-root", + "mode": "0755", + "content": "#!/bin/sh\nset -e\nexec >>/config/container-start.log 2>&1\nexec /init\n" + } + ], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-root" + } + ], + "runtime": { + "entrypoint": "/usr/local/bin/jdownloader-lxc-start", + "working_directory": "/tmp", + "halt_signal": "SIGTERM" + }, + "startup_healthcheck": { + "scheme": "https", + "port": 5800, + "path": "/", + "verify_tls": false, + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "stability_seconds": 0 + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The validated first-boot wrapper, secure WebUI credentials and volume preparation are implemented through reusable declarative installer capabilities." + }, + "validation": { + "schema": "passed-at-generation", + "validated_profile": { + "id": "pve55-jdownloader-managed-config", + "validated_on": "2026-08-27", + "validation_status": "passed-web-gui-https-authenticated-myjdownloader-credentials-pending", + "proxmox_version": "9.2.11", + "container_id": 126, + "image": { + "tag": "v26.08.2", + "digest": "sha256:f16d47986bf6a5db6d67484e3b7e76404bce74f6f212809127a79eb76aa1c641", + "archive_sha256": "84aa07101c51a2d5f51d0bf86c2ee9f4ad660788782cff7a16a620cbfc708877" + }, + "storage": { + "rootfs": "local-lvm:8G", + "config": "local-lvm:4G,backup=1", + "downloads": "host-bind:/mnt/pve/Piblic/Transmission/eMule->/output,read-write,backup=0" + }, + "validation": { + "web_gui_https_redirect_to_login": "passed-302", + "http_redirect_to_https": "passed-307", + "self_signed_https_certificate": "passed-generated-for-hostname-jdownloader", + "web_authentication_user_created": "passed-admin-present-in-htpasswd", + "java_process": "passed", + "persistent_config": "passed", + "shared_download_write_as_app_user": "passed", + "default_download_folder": "passed-/output", + "vnc_localhost_only": "passed", + "restart_without_errors": "passed", + "vzdump_config_inclusion": "passed-by-mp0-backup-flag", + "vzdump_restore_to_temporary_ct": "passed-historical-lab-not-repeated-on-ct126", + "myjdownloader_account_connection": "not-tested-no-user-credentials" + }, + "previous_validation_status": "passed-web-gui-myjdownloader-credentials-pending", + "validated_lxc_adapted_profile": { + "entrypoint": "/usr/local/bin/jdownloader-lxc-start", + "custom_rootfs_files": true, + "custom_host_services": false, + "validation": "passed-historical-lab" + }, + "candidate_direct_image_profile": { + "entrypoint": "from-oci-image-config", + "custom_rootfs_files": false, + "custom_host_services": false, + "validation": "pending-clean-import-test" + } + }, + "translation_audit": { + "reviewed_on": "2026-08-27", + "compose_credentials": [ + "MYJDOWNLOADER_EMAIL", + "MYJDOWNLOADER_PASSWORD", + "WEB_AUTHENTICATION_USERNAME", + "WEB_AUTHENTICATION_PASSWORD" + ], + "application_generated_credentials": [ + "JDownloader state and optional htpasswd database under /config" + ], + "result": "aligned-with-official-image-environment" + }, + "source_profile": "jdownloader-oci.json" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-latest-oci-image-preserve-managed-config-volume", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false, + "validated_workflows": { + "install": [ + "validate-requirements", + "validate-storage-capacity", + "create-shared-download-directory", + "prepare-unprivileged-id-mapping-permissions", + "pull-oci-image-by-digest", + "create-container", + "attach-managed-config-volume", + "remove-empty-lost-and-found-from-config-volume", + "attach-shared-downloads-bind", + "inject-runtime-wrapper", + "apply-runtime-environment", + "start-container", + "wait-for-default-config-files", + "run-selected-bootstrap", + "verify-http-redirects-to-https-for-authenticated-web-gui", + "wait-for-selected-healthcheck" + ], + "update": [ + "pause-active-downloads", + "stop-container", + "backup-container", + "pull-new-oci-image", + "recreate-rootfs-preserving-managed-config-volume", + "inject-runtime-wrapper", + "start-container", + "wait-for-selected-healthcheck" + ], + "uninstall": { + "remove_rootfs": true, + "preserve_config_by_default": true, + "preserve_shared_downloads": true + } + } + } +} diff --git a/oci/catalog/curated/jellyfin-official.json b/oci/catalog/curated/jellyfin-official.json new file mode 100644 index 00000000..4242c9e8 --- /dev/null +++ b/oci/catalog/curated/jellyfin-official.json @@ -0,0 +1,523 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "image-jellyfin-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Jellyfin Official" + }, + "tagline": { + "en_US": "Official Jellyfin image with optional VA-API or NVIDIA acceleration." + }, + "description": { + "en_US": "Jellyfin is a Free Software Media System that puts you in control of managing and streaming your media. It is an alternative to the proprietary Emby and Plex, to provide media from a dedicated server to end-user devices via multiple apps. Jellyfin is descended from Emby's 3.5.2 release and ported to the .NET Core framework to enable full cross-platform support. There are no strings attached, no premium licenses or features, and no hidden agendas: just a team who want to build something better and work together to achieve it." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Jellyfin Team", + "developer": "Jellyfin Team", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8096, + "path": "/" + }, + "website": "https://jellyfin.org/", + "documentation": "https://jellyfin.org/docs/general/installation/container/", + "repository": "https://github.com/jellyfin/jellyfin-packaging", + "tips": [ + "Configuration and cache use persistent Proxmox volumes by default; media defaults to a shared host directory.", + "Hardware tone mapping is configured persistently after first start when VA-API or NVIDIA is selected.", + "DLNA multicast behavior depends on the selected Proxmox bridge and firewall." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "jellyfin", + "repository": "https://github.com/jellyfin/jellyfin-packaging", + "default_branch": "master", + "revision": "19f2efc7528cc0ec6c04276e1c62d9cdbfb13b6a", + "image_repository_url": "https://github.com/jellyfin/jellyfin-packaging", + "compose_sha256": "db04ff7885b26ca276b747f7d031e9f76f82a1b113c3ba17bcc09bd3a7082f9a", + "generated_at": "2026-09-13T21:08:59+00:00" + }, + "container_contract": { + "service_name": "jellyfin", + "container_name": "jellyfin", + "image": { + "reference": "jellyfin/jellyfin:latest", + "registry": "docker.io", + "repository": "jellyfin/jellyfin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "JELLYFIN_PublishedServerUrl", + "example": "", + "required": false, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Optional published URL for Jellyfin" + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "cache", + "container_path": "/cache", + "compose_source_example": "/path/to/cache", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": false, + "default_size_gb": 8 + } + }, + { + "id": "media", + "container_path": "/media", + "compose_source_example": "/path/to/media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 8096, + "published_example": 8096, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 7359, + "published_example": 7359, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n jellyfin:\n image: jellyfin/jellyfin:latest\n container_name: jellyfin\n ports:\n - 8096:8096/tcp\n - 7359:7359/udp\n environment:\n - JELLYFIN_PublishedServerUrl=\n volumes:\n - /path/to/config:/config\n - /path/to/cache:/cache\n - /path/to/media:/media\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Jellyfin WebUI", + "scheme": "http", + "port": 8096, + "path": "/", + "source": "official-container-documentation" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Jellyfin", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "environment": [ + { + "name": "LIBVA_DRIVER_NAME", + "prompt": "VA-API driver", + "choices": [ + "auto", + "radeonsi", + "iHD", + "i965" + ], + "default": "auto", + "omit_values": [ + "auto" + ] + } + ] + } + ], + "post_start_configurations": [ + { + "id": "jellyfin-vaapi-hdr-tone-mapping", + "type": "jellyfin-encoding-xml", + "enable_prompt": "Enable VA-API transcoding and HDR10/Dolby Vision to SDR tone mapping", + "enabled_default": true, + "required": true, + "timeout_seconds": 120, + "candidate_paths": [ + "/config/encoding.xml", + "/config/config/encoding.xml" + ], + "settings": { + "HardwareAccelerationType": "vaapi", + "VaapiDevice": { + "device_path_from": "vaapi-render" + }, + "EnableDecodingColorDepth10Hevc": "true", + "EnableHardwareEncoding": "true", + "EnableTonemapping": "true", + "EnableVppTonemapping": "false", + "TonemappingAlgorithm": "bt2390", + "TonemappingMode": "auto", + "TonemappingRange": "auto" + }, + "lists": { + "HardwareDecodingCodecs": [ + "h264", + "hevc", + "vc1" + ] + } + } + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ], + "post_start_configurations": [ + { + "id": "jellyfin-nvidia-hdr-tone-mapping", + "type": "jellyfin-encoding-xml", + "enable_prompt": "Enable NVIDIA transcoding and HDR10/Dolby Vision to SDR tone mapping", + "enabled_default": true, + "required": true, + "timeout_seconds": 120, + "candidate_paths": [ + "/config/encoding.xml", + "/config/config/encoding.xml" + ], + "settings": { + "HardwareAccelerationType": "nvenc", + "EnableDecodingColorDepth10Hevc": "true", + "EnableEnhancedNvdecDecoder": "true", + "EnableHardwareEncoding": "true", + "EnableTonemapping": "true", + "EnableVppTonemapping": "false", + "TonemappingAlgorithm": "bt2390", + "TonemappingMode": "auto", + "TonemappingRange": "auto" + }, + "lists": { + "HardwareDecodingCodecs": [ + "h264", + "hevc", + "vc1" + ] + } + } + ] + } + ] + }, + "startup_healthcheck": { + "scheme": "http", + "port": 8096, + "path": "/System/Info/Public", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + }, + "network": { + "compose_mode": "bridge" + } + }, + "application_options": { + "hdr10_dolby_vision_tone_mapping": { + "show_in_catalog": true, + "selectable": true, + "reason": "The installer configures persistent tone mapping according to the selected hardware backend after Jellyfin creates encoding.xml.", + "persistent_configuration_paths": [ + "/config/encoding.xml", + "/config/config/encoding.xml" + ], + "validated_profile": "pending-official-image-validation" + } + }, + "catalog": { + "replaces_discovered_ids": [] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/llamacpp.json b/oci/catalog/curated/llamacpp.json new file mode 100644 index 00000000..3ed8fc65 --- /dev/null +++ b/oci/catalog/curated/llamacpp.json @@ -0,0 +1,430 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-llamacpp", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "llama.cpp" + }, + "tagline": { + "en_US": "Run GGUF LLMs locally with GPU acceleration" + }, + "description": { + "en_US": "llama.cpp is a pure C/C++ inference engine for GGUF large language models, with the official OpenAI-compatible server and a built-in Web UI.\n\n**Key Features:**\n- Run GGUF models (Llama, Qwen, DeepSeek, Gemma, Mistral and more) on CPU or GPU\n- Vulkan backend works on AMD / Intel / NVIDIA GPUs out of the box\n- Great fit for unified-memory machines (e.g. AMD Ryzen AI Max 395)\n- OpenAI-compatible API for integration with Open WebUI, ChatGPT-Next-Web and more\n- Built-in chat Web UI with runtime model loading\n\n**Getting started:**\n1. Put GGUF model files into the models volume (`/models`)\n2. Open the Web UI at `http://:18080` and load a model\n3. Keep `/dev/dri` mapped for Vulkan acceleration; remove it for CPU-only mode" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "ggml-org", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://github.com/ggml-org/llama.cpp", + "documentation": null, + "repository": "https://ghcr.io/ggml-org/llama.cpp", + "tips": [ + "The generic latest image uses its default backend. VA-API device passthrough was removed because it does not select a llama.cpp compute backend." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "ggml-org", + "repository": "https://ghcr.io/ggml-org/llama.cpp", + "revision": "c6c95211bb6027b0e7849d4b97c26df894484a73393e4348d1ff89fb694bb2b1", + "image_repository_url": "https://ghcr.io/ggml-org/llama.cpp", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "c6c95211bb6027b0e7849d4b97c26df894484a73393e4348d1ff89fb694bb2b1", + "generated_at": "2026-09-13T15:35:00+00:00" + }, + "container_contract": { + "service_name": "llamacpp", + "container_name": "llamacpp", + "image": { + "reference": "ghcr.io/ggml-org/llama.cpp:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/ggml-org/llama.cpp", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "LLAMA_ARG_N_GPU_LAYERS", + "example": "999", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LLAMA_ARG_CONTEXT_SIZE", + "example": "8192", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/models", + "compose_source_example": "/DATA/AppData/$AppID/models", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 18080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: llamacpp\nservices:\n llamacpp:\n image: ghcr.io/ggml-org/llama.cpp:latest\n container_name: llamacpp\n ports:\n - target: 8080\n published: '18080'\n protocol: tcp\n environment:\n - LLAMA_ARG_N_GPU_LAYERS=999\n - LLAMA_ARG_CONTEXT_SIZE=8192\n devices:\n - /dev/dri:/dev/dri\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/models\n target: /models\n bind:\n create_host_path: true\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "llamacpp", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "llamacpp", + "service_count": 1, + "services": [ + { + "name": "llamacpp", + "image": "ghcr.io/ggml-org/llama.cpp:server", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/ggml-org/llama.cpp:server", + "container_name": "llamacpp", + "ports": [ + { + "target": 8080, + "published": "18080", + "protocol": "tcp" + } + ], + "environment": [ + "LLAMA_ARG_N_GPU_LAYERS=999", + "LLAMA_ARG_CONTEXT_SIZE=8192" + ], + "devices": [ + "/dev/dri:/dev/dri" + ], + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/models", + "target": "/models", + "bind": { + "create_host_path": true + } + } + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "llamacpp" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "llamacpp-volume-0", + "service": "llamacpp", + "container_path": "/models", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "llamacpp" + ], + "stop_order": [ + "llamacpp" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": {}, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "base", + "gpu_passthrough": "not-configured" + }, + "catalog": { + "replaces_discovered_ids": [ + "llamacpp" + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/makemkv.json b/oci/catalog/curated/makemkv.json new file mode 100644 index 00000000..a6a66626 --- /dev/null +++ b/oci/catalog/curated/makemkv.json @@ -0,0 +1,455 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-makemkv", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "MakeMKV" + }, + "tagline": { + "en_US": "Rip DVD and Blu-ray media from a browser" + }, + "description": { + "en_US": "The maintained jlesage MakeMKV image with persistent settings, shared input/output storage and optional native optical-drive passthrough." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "jlesage", + "developer": "jlesage", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5800, + "path": "/" + }, + "website": "https://github.com/jlesage/docker-makemkv", + "documentation": "https://github.com/jlesage/docker-makemkv", + "repository": "https://github.com/jlesage/docker-makemkv", + "tips": [ + "To read an optical drive, select the /dev/sgX that matches the drive; /dev/srX is optional but improves performance.", + "The /storage library is mounted read-only and /output read/write." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-26" + }, + "source": { + "provider": "jlesage", + "repository": "https://github.com/jlesage/docker-makemkv", + "default_branch": "master", + "revision": "63373b8a76faeae246d73c5b070e8d97a2d018c5", + "readme_raw_url": "https://raw.githubusercontent.com/jlesage/docker-makemkv/master/README.md", + "image_repository_url": "https://hub.docker.com/r/jlesage/makemkv", + "readme_pushed_at": "2026-08-26T22:06:48Z", + "compose_sha256": "18936fa4593769be1a8bc9a81c05b35e4f905746b10e772749936c637d9a3f36", + "generated_at": "2026-09-14T15:24:39+00:00" + }, + "container_contract": { + "service_name": "makemkv", + "container_name": "makemkv", + "image": { + "reference": "jlesage/makemkv:latest", + "registry": "docker.io", + "repository": "jlesage/makemkv", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USER_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "GROUP_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "SUP_GROUP_IDS", + "example": null, + "required": false, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "makemkv-config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "storage", + "container_path": "/storage", + "compose_source_example": "/mnt/oci-shared/media", + "read_only": true, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + }, + { + "id": "output", + "container_path": "/output", + "compose_source_example": "/mnt/oci-shared/makemkv/output", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 5800, + "published_example": 5800, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "{\n \"services\": {\n \"makemkv\": {\n \"image\": \"jlesage/makemkv:latest\",\n \"ports\": [\n \"5800:5800\"\n ],\n \"environment\": {\n \"USER_ID\": \"1000\",\n \"GROUP_ID\": \"1000\",\n \"TZ\": \"Europe/Madrid\"\n },\n \"volumes\": [\n \"makemkv-config:/config\",\n \"/mnt/oci-shared/media:/storage:ro\",\n \"/mnt/oci-shared/makemkv/output:/output\"\n ],\n \"restart\": \"unless-stopped\"\n }\n }\n}" + }, + "compose_stack": { + "project_name": "makemkv", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "makemkv", + "service_count": 1, + "services": [ + { + "name": "makemkv", + "image": "jlesage/makemkv:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/makemkv:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "makemkv-config:/config", + "/mnt/oci-shared/media:/storage:ro", + "/mnt/oci-shared/makemkv/output:/output" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "makemkv-config", + "service": "makemkv", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "makemkv-storage", + "service": "makemkv", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "makemkv-output", + "service": "makemkv", + "container_path": "/output", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "makemkv" + ], + "stop_order": [ + "makemkv" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "makemkv" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "pending-clean-install" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "pending-device-host-test" + } + ], + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "device_requests": [ + { + "id": "optical-scsi-generic", + "kind": "character-device", + "purpose": "optical-drive-control", + "enable_prompt": "Enable an optical drive for MakeMKV", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Generic SCSI device associated with the drive (e.g. /dev/sg2)", + "host_path_default": "/dev/sg0", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "append_host_device_gid_to_environment": "SUP_GROUP_IDS", + "source_mapping": "/dev/sgX:/dev/sgX" + }, + { + "id": "optical-block-device", + "kind": "block-device", + "purpose": "optical-drive-performance", + "enable_prompt": "Also add the /dev/srX optical device (recommended)", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Optical block device (e.g. /dev/sr0)", + "host_path_default": "/dev/sr0", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "append_host_device_gid_to_environment": "SUP_GROUP_IDS", + "source_mapping": "/dev/srX:/dev/srX" + } + ], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/storage", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/output", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 5800, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The official single-image contract has a reviewed native OCI-LXC mapping; clean-install validation remains pending." + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5800, + "path": "/", + "source": "upstream-documentation" + } + ], + "credentials": [] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/mkvtoolnix.json b/oci/catalog/curated/mkvtoolnix.json new file mode 100644 index 00000000..ad645270 --- /dev/null +++ b/oci/catalog/curated/mkvtoolnix.json @@ -0,0 +1,376 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-mkvtoolnix", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "MKVToolNix" + }, + "tagline": { + "en_US": "Create and edit Matroska files from a browser" + }, + "description": { + "en_US": "The maintained jlesage MKVToolNix image with browser GUI, persistent settings and user-selectable shared storage." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "jlesage", + "developer": "jlesage", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5800, + "path": "/" + }, + "website": "https://github.com/jlesage/docker-mkvtoolnix", + "documentation": "https://github.com/jlesage/docker-mkvtoolnix", + "repository": "https://github.com/jlesage/docker-mkvtoolnix", + "tips": [ + "/storage can point to the common directory used by Jellyfin, Plex, MakeMKV or other media applications." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-26" + }, + "source": { + "provider": "jlesage", + "repository": "https://github.com/jlesage/docker-mkvtoolnix", + "default_branch": "master", + "revision": "8a51f353e1b186dff36465a27c201d8614f80dc3", + "readme_raw_url": "https://raw.githubusercontent.com/jlesage/docker-mkvtoolnix/master/README.md", + "image_repository_url": "https://hub.docker.com/r/jlesage/mkvtoolnix", + "readme_pushed_at": "2026-08-26T22:06:48Z", + "compose_sha256": "4c11b71b299901116f68d039b11a4c86900882c4df45b3082a85215bdb42f757", + "generated_at": "2026-09-14T15:24:39+00:00" + }, + "container_contract": { + "service_name": "mkvtoolnix", + "container_name": "mkvtoolnix", + "image": { + "reference": "jlesage/mkvtoolnix:latest", + "registry": "docker.io", + "repository": "jlesage/mkvtoolnix", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "USER_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "GROUP_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "mkvtoolnix-config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "storage", + "container_path": "/storage", + "compose_source_example": "/mnt/oci-shared/media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 5800, + "published_example": 5800, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "{\n \"services\": {\n \"mkvtoolnix\": {\n \"image\": \"jlesage/mkvtoolnix:latest\",\n \"ports\": [\n \"5800:5800\"\n ],\n \"environment\": {\n \"USER_ID\": \"1000\",\n \"GROUP_ID\": \"1000\",\n \"TZ\": \"Europe/Madrid\"\n },\n \"volumes\": [\n \"mkvtoolnix-config:/config\",\n \"/mnt/oci-shared/media:/storage\"\n ],\n \"restart\": \"unless-stopped\"\n }\n }\n}" + }, + "compose_stack": { + "project_name": "mkvtoolnix", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "mkvtoolnix", + "service_count": 1, + "services": [ + { + "name": "mkvtoolnix", + "image": "jlesage/mkvtoolnix:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "jlesage/mkvtoolnix:latest", + "ports": [ + "5800:5800" + ], + "environment": { + "USER_ID": "1000", + "GROUP_ID": "1000", + "TZ": "Europe/Madrid" + }, + "volumes": [ + "mkvtoolnix-config:/config", + "/mnt/oci-shared/media:/storage" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "not-required", + "private_address_allocation": "not-required", + "service_discovery": "dedicated-lxc-address", + "dependency_external_access": "not-applicable", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "mkvtoolnix-config", + "service": "mkvtoolnix", + "container_path": "/config", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "mkvtoolnix-storage", + "service": "mkvtoolnix", + "container_path": "/storage", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "mkvtoolnix" + ], + "stop_order": [ + "mkvtoolnix" + ], + "dependency_readiness": "mandatory-http-first-start-healthcheck", + "rollback_on_failure": "remove-new-rootfs-preserve-external-host-data" + }, + "installer_inputs": { + "prompted": [ + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "image_digest_resolution", + "managed_volume_preparation" + ], + "generated_secrets": [] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "mkvtoolnix" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker bind mounts persistent directories into the image.", + "native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.", + "reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.", + "behavioral_impact": "None expected.", + "validation": "pending-clean-install" + }, + { + "id": "native-device-passthrough", + "upstream_behavior": "Docker exposes explicitly selected host devices to the container.", + "native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.", + "reason": "The OCI process runs directly inside an LXC rather than through Docker.", + "behavioral_impact": "Only devices explicitly selected by the user are exposed.", + "validation": "not-required" + } + ], + "installer_profile": { + "network": { + "compose_mode": "bridge" + }, + "device_requests": [], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/storage", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 5800, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "No security relaxation is required for the reviewed profile." + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "devices", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The official single-image contract has a reviewed native OCI-LXC mapping; clean-install validation remains pending." + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 5800, + "path": "/", + "source": "upstream-documentation" + } + ], + "credentials": [] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-readme-revision-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/nextcloud-stack.json b/oci/catalog/curated/nextcloud-stack.json new file mode 100644 index 00000000..2472968c --- /dev/null +++ b/oci/catalog/curated/nextcloud-stack.json @@ -0,0 +1,613 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-nextcloud-stack", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Nextcloud Stack" + }, + "tagline": { + "en_US": "Nextcloud with private PostgreSQL and Redis dependencies" + }, + "description": { + "en_US": "A three-service Nextcloud deployment adapted to native Proxmox OCI LXC containers." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Nextcloud", + "developer": "Nextcloud", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://nextcloud.com/", + "documentation": "https://github.com/nextcloud/docker", + "repository": "https://github.com/nextcloud/docker", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-08-27" + }, + "source": { + "provider": "nextcloud", + "repository": "https://github.com/nextcloud/docker", + "revision": "efbfd48ff39b00cdb9b5283b68db9d62542523979ae65da68b43f607b678bae5", + "image_repository_url": "https://hub.docker.com/_/nextcloud", + "readme_pushed_at": "2026-08-27T00:00:00Z", + "compose_sha256": "efbfd48ff39b00cdb9b5283b68db9d62542523979ae65da68b43f607b678bae5", + "generated_at": "2026-09-12T15:37:08+00:00" + }, + "container_contract": { + "service_name": "application", + "container_name": "application", + "image": { + "reference": "nextcloud:latest", + "registry": "docker.io", + "repository": "nextcloud", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "POSTGRES_HOST", + "example": "database", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_DB", + "example": "nextcloud", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_USER", + "example": "nextcloud", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_PASSWORD", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "REDIS_HOST", + "example": "cache", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTCLOUD_ADMIN_USER", + "example": "admin", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "NEXTCLOUD_ADMIN_PASSWORD", + "example": "${GENERATED_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "docker-compose" + }, + { + "name": "NEXTCLOUD_INIT_HTACCESS", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/var/www/html", + "compose_source_example": "nextcloud-html", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "database", + "image": "postgres:latest" + }, + { + "name": "cache", + "image": "redis:latest" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: nextcloud-stack\nservices:\n application:\n image: nextcloud:latest\n depends_on:\n database:\n condition: service_healthy\n cache:\n condition: service_healthy\n environment:\n POSTGRES_HOST: database\n POSTGRES_DB: nextcloud\n POSTGRES_USER: nextcloud\n POSTGRES_PASSWORD: ${GENERATED_DB_PASSWORD}\n REDIS_HOST: cache\n NEXTCLOUD_ADMIN_USER: admin\n NEXTCLOUD_ADMIN_PASSWORD: ${GENERATED_ADMIN_PASSWORD}\n NEXTCLOUD_INIT_HTACCESS: 'true'\n ports:\n - 80:80\n volumes:\n - nextcloud-html:/var/www/html\n restart: unless-stopped\n database:\n image: postgres:latest\n command:\n - postgres\n - -c\n - listen_addresses=0.0.0.0\n environment:\n POSTGRES_DB: nextcloud\n POSTGRES_USER: nextcloud\n POSTGRES_PASSWORD: ${GENERATED_DB_PASSWORD}\n POSTGRES_INITDB_ARGS: --data-checksums\n PGDATA: /var/lib/postgresql/data/pgdata\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U nextcloud -d nextcloud\n interval: 5s\n timeout: 5s\n retries: 30\n volumes:\n - postgres-data:/var/lib/postgresql/data\n restart: unless-stopped\n cache:\n image: redis:latest\n command: redis-server\n healthcheck:\n test:\n - CMD\n - redis-cli\n - ping\n interval: 5s\n timeout: 5s\n retries: 30\n restart: unless-stopped\nvolumes:\n nextcloud-html: {}\n postgres-data: {}\n" + }, + "compose_stack": { + "project_name": "nextcloud-stack", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "application", + "service_count": 3, + "services": [ + { + "name": "cache", + "image": "redis:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "redis:latest", + "command": "redis-server", + "healthcheck": { + "test": [ + "CMD", + "redis-cli", + "ping" + ], + "interval": "5s", + "timeout": "5s", + "retries": 30 + }, + "restart": "unless-stopped" + } + }, + { + "name": "database", + "image": "postgres:latest", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:latest", + "command": [ + "postgres", + "-c", + "listen_addresses=0.0.0.0" + ], + "environment": { + "POSTGRES_DB": "nextcloud", + "POSTGRES_USER": "nextcloud", + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}", + "POSTGRES_INITDB_ARGS": "--data-checksums", + "PGDATA": "/var/lib/postgresql/data/pgdata" + }, + "healthcheck": { + "test": [ + "CMD-SHELL", + "pg_isready -U nextcloud -d nextcloud" + ], + "interval": "5s", + "timeout": "5s", + "retries": 30 + }, + "volumes": [ + "postgres-data:/var/lib/postgresql" + ], + "restart": "unless-stopped" + } + }, + { + "name": "application", + "image": "nextcloud:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "cache", + "database" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "nextcloud:latest", + "depends_on": { + "database": { + "condition": "service_healthy" + }, + "cache": { + "condition": "service_healthy" + } + }, + "environment": { + "POSTGRES_HOST": "database", + "POSTGRES_DB": "nextcloud", + "POSTGRES_USER": "nextcloud", + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}", + "REDIS_HOST": "cache", + "NEXTCLOUD_ADMIN_USER": "admin", + "NEXTCLOUD_ADMIN_PASSWORD": "${GENERATED_ADMIN_PASSWORD}", + "NEXTCLOUD_INIT_HTACCESS": "true" + }, + "ports": [ + "80:80" + ], + "volumes": [ + "nextcloud-html:/var/www/html" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "nextcloud-stack", + "volumes": { + "nextcloud-html": {}, + "postgres-data": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "application-volume-0", + "service": "application", + "container_path": "/var/www/html", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "database-volume-0", + "service": "database", + "container_path": "/var/lib/postgresql", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "cache", + "database", + "application" + ], + "stop_order": [ + "application", + "database", + "cache" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-all-new-lxc-and-new-managed-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "application", + "environment_variable": "NEXTCLOUD_ADMIN_PASSWORD" + } + ] + }, + { + "id": "db-password", + "strategy": "generate-cryptographically-random-at-install", + "bindings": [ + { + "service": "application", + "environment_variable": "POSTGRES_PASSWORD" + }, + { + "service": "database", + "environment_variable": "POSTGRES_PASSWORD" + } + ] + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [ + { + "label": "Generated administrator login", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "proxmenux-installer-generated", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "postgres-declared-volume-persistence", + "upstream_behavior": "Current PostgreSQL latest images declare /var/lib/postgresql as their persistent volume.", + "native_lxc_behavior": "The managed backup-enabled volume covers /var/lib/postgresql; explicit PGDATA remains /var/lib/postgresql/data/pgdata.", + "reason": "Image replacement must not discard declared persistence.", + "behavioral_impact": "Existing child-path volumes need a reviewed migration; update never moves their data implicitly.", + "validation": "clean-install-passed-20260916" + }, + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "A reviewed three-LXC orchestrator translates every required service option into native Proxmox OCI LXC configuration.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "One catalog action installs the complete application stack.", + "validation": "passed-in-historical-laboratory-profile" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "private-service-network", + "upstream_behavior": "Compose DNS connects the application to PostgreSQL and Redis by service name.", + "native_lxc_behavior": "Three LXC containers use automatic private addresses and matching service aliases.", + "reason": "Native OCI services run in separate LXC network namespaces.", + "behavioral_impact": "Database and cache remain inaccessible from the frontend network.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "managed-application-and-database-volumes", + "upstream_behavior": "Named Docker volumes persist /var/www/html and PostgreSQL data.", + "native_lxc_behavior": "Proxmox-managed mpN volumes preserve the same paths with backup=1.", + "reason": "Private application and database state belongs in native Proxmox backups.", + "behavioral_impact": "No shared host directory is created for Nextcloud user data.", + "validation": "passed-in-laboratory-profile-2026-08-27" + }, + { + "id": "ordered-healthchecked-startup", + "upstream_behavior": "Compose dependency health controls application startup.", + "native_lxc_behavior": "The stack orchestrator starts PostgreSQL, Redis and Nextcloud in health-checked order.", + "reason": "Proxmox does not provide Compose depends_on semantics across LXC containers.", + "behavioral_impact": "One user action still installs and controls the complete application.", + "validation": "passed-in-laboratory-profile-2026-08-27" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "minimum_host_memory_mb": 4096, + "recommended_host_memory_mb": 6144, + "database_storage": { + "must_be_local": true, + "network_filesystem_allowed": false + } + }, + "defaults": { + "stack_name": "nextcloud", + "timezone": "Europe/Madrid", + "rootfs_storage": "local-lvm", + "application_storage": "local-lvm", + "database_storage": "local-lvm", + "shared_application_root": "/mnt/oci-shared/nextcloud/${stack_name}", + "application_volume_size_gb": 32, + "database_volume_size_gb": 8, + "frontend_network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "firewall": true, + "host_managed": true + }, + "private_network": { + "mode": "create-if-missing", + "bridge": "vmbr10", + "subnet": "10.77.0.0/24", + "host_address": "10.77.0.1/24", + "application_address": "10.77.0.20/24", + "database_address": "10.77.0.21/24", + "cache_address": "10.77.0.22/24", + "nat": false + }, + "application": { + "admin_username": "admin", + "php_memory_limit": "1G", + "php_upload_limit": "2G", + "apache_body_limit": "0" + }, + "maintenance_window_start_utc": 3, + "default_phone_region": "ES" + }, + "installer_contract": { + "deployment_kind": "nextcloud-three-lxc-stack", + "reserve_vmids_atomically": 3, + "generated_secrets": [ + "POSTGRES_PASSWORD", + "NEXTCLOUD_ADMIN_PASSWORD" + ], + "application_volume": { + "container_path": "/var/www/html", + "choices": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume" + }, + "database_volume": { + "container_path": "/var/lib/postgresql", + "mode": "managed-volume", + "backup": true, + "local_storage_required": true + }, + "start_order": [ + "database", + "cache", + "application" + ], + "stop_order": [ + "application", + "cache", + "database" + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The three-LXC architecture and LXC adaptations were validated in the laboratory. Rolling latest images are installable and require a fresh validation run." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending-current-rolling-images", + "service_health": "pending-current-rolling-images", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending", + "historical_lab_profile": "passed-2026-08-27-nextcloud-33.0.5-postgres-17.11-redis-8", + "private_dependency_network": "passed-historical-profile", + "managed_volume_persistence": "passed-historical-profile", + "ordered_restart": "passed-historical-profile", + "rolling_latest": "installable-pending-current-run" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "starts_stopped_dependencies": true, + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false, + "persistent_contract": "/etc/pve/priv/proxmenux-stack-.json", + "runtime_owner": "proxmox-ve" + } + } +} diff --git a/oci/catalog/curated/open-webui-cuda.json b/oci/catalog/curated/open-webui-cuda.json new file mode 100644 index 00000000..50d7d60a --- /dev/null +++ b/oci/catalog/curated/open-webui-cuda.json @@ -0,0 +1,463 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-open-webui-cuda", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Open WebUI CUDA" + }, + "tagline": { + "en_US": "User-friendly WebUI for LLMs (Formerly Ollama WebUI)" + }, + "description": { + "en_US": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Tim J. Baek", + "developer": "Tim J. Baek", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://openwebui.com", + "documentation": null, + "repository": "https://ghcr.io/open-webui/open-webui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "open-webui", + "repository": "https://ghcr.io/open-webui/open-webui", + "revision": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "image_repository_url": "https://ghcr.io/open-webui/open-webui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "open-webui-ollama", + "container_name": "open-webui-ollama", + "image": { + "reference": "ghcr.io/open-webui/open-webui:cuda", + "registry": "ghcr.io", + "repository": "ghcr.io/open-webui/open-webui", + "tag": "cuda", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/backend/data", + "compose_source_example": "/DATA/AppData/open-webui-ollama/open-webui", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 3050, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: open-webui-ollama\nservices:\n open-webui-ollama:\n image: ghcr.io/open-webui/open-webui:latest\n runtime: nvidia\n ipc: host\n environment:\n CPU_FALLBACK: 'true'\n NVIDIA_VISIBLE_DEVICES: all\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 8080\n published: '3050'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/open-webui-ollama/open-webui\n target: /app/backend/data\n - type: bind\n source: /DATA/AppData/open-webui-ollama/ollama\n target: /root/.ollama\n privileged: false\n container_name: open-webui-ollama\n" + }, + "compose_stack": { + "project_name": "open-webui-ollama", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "open-webui-ollama", + "service_count": 1, + "services": [ + { + "name": "open-webui-ollama", + "image": "ghcr.io/open-webui/open-webui:cuda", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/open-webui/open-webui:latest", + "runtime": "nvidia", + "ipc": "host", + "environment": { + "CPU_FALLBACK": "true", + "NVIDIA_VISIBLE_DEVICES": "all" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8080, + "published": "3050", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/open-webui", + "target": "/app/backend/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/ollama", + "target": "/root/.ollama" + } + ], + "privileged": false, + "container_name": "open-webui-ollama" + } + } + ], + "top_level": { + "name": "open-webui-ollama" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "open-webui-ollama-volume-0", + "service": "open-webui-ollama", + "container_path": "/app/backend/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "open-webui-ollama-volume-1", + "service": "open-webui-ollama", + "container_path": "/root/.ollama", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "open-webui-ollama" + ], + "stop_order": [ + "open-webui-ollama" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-ipc-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 64, + "size_prompt": "Shared memory size for the GPU workload in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ], + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose", + "enable_prompt": "Enable the NVIDIA GPU required by Open WebUI CUDA", + "enabled_default": true, + "required_by_compose": true, + "required_for_runtime": true + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "pending-per-application" + } + ], + "deployment_profile": { + "variant": "cuda", + "gpu_passthrough": "required-nvidia" + }, + "catalog": { + "replaces_discovered_ids": [] + }, + "image_variant": { + "rolling_tag": "cuda", + "functional_variant": true, + "preserve_tag": true + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/open-webui-ollama.json b/oci/catalog/curated/open-webui-ollama.json new file mode 100644 index 00000000..30674282 --- /dev/null +++ b/oci/catalog/curated/open-webui-ollama.json @@ -0,0 +1,469 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-open-webui-ollama", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Open WebUI + Ollama" + }, + "tagline": { + "en_US": "User-friendly WebUI for LLMs (Formerly Ollama WebUI)" + }, + "description": { + "en_US": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Tim J. Baek", + "developer": "Tim J. Baek", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://openwebui.com", + "documentation": null, + "repository": "https://ghcr.io/open-webui/open-webui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "open-webui", + "repository": "https://ghcr.io/open-webui/open-webui", + "revision": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "image_repository_url": "https://ghcr.io/open-webui/open-webui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "open-webui-ollama", + "container_name": "open-webui-ollama", + "image": { + "reference": "ghcr.io/open-webui/open-webui:ollama", + "registry": "ghcr.io", + "repository": "ghcr.io/open-webui/open-webui", + "tag": "ollama", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/backend/data", + "compose_source_example": "/DATA/AppData/open-webui-ollama/open-webui", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/root/.ollama", + "compose_source_example": "/DATA/AppData/open-webui-ollama/ollama", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 3050, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: open-webui-ollama\nservices:\n open-webui-ollama:\n image: ghcr.io/open-webui/open-webui:latest\n runtime: nvidia\n ipc: host\n environment:\n CPU_FALLBACK: 'true'\n NVIDIA_VISIBLE_DEVICES: all\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 8080\n published: '3050'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/open-webui-ollama/open-webui\n target: /app/backend/data\n - type: bind\n source: /DATA/AppData/open-webui-ollama/ollama\n target: /root/.ollama\n privileged: false\n container_name: open-webui-ollama\n" + }, + "compose_stack": { + "project_name": "open-webui-ollama", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "open-webui-ollama", + "service_count": 1, + "services": [ + { + "name": "open-webui-ollama", + "image": "ghcr.io/open-webui/open-webui:ollama", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/open-webui/open-webui:latest", + "runtime": "nvidia", + "ipc": "host", + "environment": { + "CPU_FALLBACK": "true", + "NVIDIA_VISIBLE_DEVICES": "all" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8080, + "published": "3050", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/open-webui", + "target": "/app/backend/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/ollama", + "target": "/root/.ollama" + } + ], + "privileged": false, + "container_name": "open-webui-ollama" + } + } + ], + "top_level": { + "name": "open-webui-ollama" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "open-webui-ollama-volume-0", + "service": "open-webui-ollama", + "container_path": "/app/backend/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "open-webui-ollama-volume-1", + "service": "open-webui-ollama", + "container_path": "/root/.ollama", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "open-webui-ollama" + ], + "stop_order": [ + "open-webui-ollama" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-ipc-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 64, + "size_prompt": "Shared memory size for the GPU workload in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "pending-per-application" + } + ], + "deployment_profile": { + "variant": "ollama", + "gpu_passthrough": "not-required" + }, + "catalog": { + "replaces_discovered_ids": [ + "open-webui-ollama" + ] + }, + "image_variant": { + "rolling_tag": "ollama", + "functional_variant": true, + "preserve_tag": true + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/open-webui.json b/oci/catalog/curated/open-webui.json new file mode 100644 index 00000000..c7f93099 --- /dev/null +++ b/oci/catalog/curated/open-webui.json @@ -0,0 +1,451 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-open-webui", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Open WebUI" + }, + "tagline": { + "en_US": "User-friendly WebUI for LLMs (Formerly Ollama WebUI)" + }, + "description": { + "en_US": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n" + }, + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "author": "Tim J. Baek", + "developer": "Tim J. Baek", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://openwebui.com", + "documentation": null, + "repository": "https://ghcr.io/open-webui/open-webui", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "open-webui", + "repository": "https://ghcr.io/open-webui/open-webui", + "revision": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "image_repository_url": "https://ghcr.io/open-webui/open-webui", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "92018597bf4a549ce5b6cd69d2a4b4fbc53374c3637822c4f7e413477527fd2e", + "generated_at": "2026-09-13T15:35:01+00:00" + }, + "container_contract": { + "service_name": "open-webui-ollama", + "container_name": "open-webui-ollama", + "image": { + "reference": "ghcr.io/open-webui/open-webui:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/open-webui/open-webui", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/backend/data", + "compose_source_example": "/DATA/AppData/open-webui-ollama/open-webui", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8080, + "published_example": 3050, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "always", + "stop_grace_period": null, + "original_compose": "name: open-webui-ollama\nservices:\n open-webui-ollama:\n image: ghcr.io/open-webui/open-webui:latest\n runtime: nvidia\n ipc: host\n environment:\n CPU_FALLBACK: 'true'\n NVIDIA_VISIBLE_DEVICES: all\n deploy:\n resources:\n reservations:\n memory: 512M\n network_mode: bridge\n ports:\n - target: 8080\n published: '3050'\n protocol: tcp\n restart: always\n volumes:\n - type: bind\n source: /DATA/AppData/open-webui-ollama/open-webui\n target: /app/backend/data\n - type: bind\n source: /DATA/AppData/open-webui-ollama/ollama\n target: /root/.ollama\n privileged: false\n container_name: open-webui-ollama\n" + }, + "compose_stack": { + "project_name": "open-webui-ollama", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "open-webui-ollama", + "service_count": 1, + "services": [ + { + "name": "open-webui-ollama", + "image": "ghcr.io/open-webui/open-webui:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/open-webui/open-webui:latest", + "runtime": "nvidia", + "ipc": "host", + "environment": { + "CPU_FALLBACK": "true", + "NVIDIA_VISIBLE_DEVICES": "all" + }, + "deploy": { + "resources": { + "reservations": { + "memory": "512M" + } + } + }, + "network_mode": "bridge", + "ports": [ + { + "target": 8080, + "published": "3050", + "protocol": "tcp" + } + ], + "restart": "always", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/open-webui", + "target": "/app/backend/data" + }, + { + "type": "bind", + "source": "/DATA/AppData/open-webui-ollama/ollama", + "target": "/root/.ollama" + } + ], + "privileged": false, + "container_name": "open-webui-ollama" + } + } + ], + "top_level": { + "name": "open-webui-ollama" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "open-webui-ollama-volume-0", + "service": "open-webui-ollama", + "container_path": "/app/backend/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "open-webui-ollama-volume-1", + "service": "open-webui-ollama", + "container_path": "/root/.ollama", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "open-webui-ollama" + ], + "stop_order": [ + "open-webui-ollama" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 512, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "tmpfs_mounts": [ + { + "id": "compose-ipc-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 64, + "size_prompt": "Shared memory size for the GPU workload in MB", + "mount_options": [ + "rw", + "nosuid", + "nodev" + ] + } + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "pending-per-application" + } + ], + "deployment_profile": { + "variant": "latest", + "gpu_passthrough": "not-required" + }, + "catalog": { + "replaces_discovered_ids": [] + }, + "image_variant": { + "rolling_tag": "latest", + "functional_variant": false, + "preserve_tag": false + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/paperless-ngx.json b/oci/catalog/curated/paperless-ngx.json new file mode 100644 index 00000000..d379f0b0 --- /dev/null +++ b/oci/catalog/curated/paperless-ngx.json @@ -0,0 +1,669 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-paperless-ngx", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Paperless-ngx" + }, + "tagline": { + "en_US": "Searchable document archive with OCR" + }, + "description": { + "en_US": "Official Paperless-ngx deployment with private PostgreSQL and Valkey dependencies." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Paperless-ngx", + "developer": "Paperless-ngx", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8000, + "path": "/" + }, + "website": "https://docs.paperless-ngx.com/", + "documentation": "https://docs.paperless-ngx.com/setup/", + "repository": "https://github.com/paperless-ngx/paperless-ngx", + "tips": [ + "Documents are stored unencrypted inside the media volume; protect and back up the host.", + "The consume and export folders can be Proxmox volumes or shared host directories." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-13" + }, + "source": { + "provider": "paperless-ngx", + "repository": "https://github.com/paperless-ngx/paperless-ngx", + "default_branch": "main", + "revision": "72ea38ab126e92fb63d68b7f5d0e6d9abaafe589", + "readme_raw_url": "https://raw.githubusercontent.com/paperless-ngx/paperless-ngx/main/docker/compose/docker-compose.postgres.yml", + "image_repository_url": "https://github.com/paperless-ngx/paperless-ngx/pkgs/container/paperless-ngx", + "readme_pushed_at": "2026-09-13T00:00:00Z", + "compose_sha256": "85206b8ae6cd74db70998de6479b4c1f7b50c077772a1af2c026c9ecb35b689c", + "generated_at": "2026-09-13T00:00:00+00:00" + }, + "container_contract": { + "service_name": "webserver", + "container_name": "paperless-ngx", + "image": { + "reference": "ghcr.io/paperless-ngx/paperless-ngx:latest", + "registry": "ghcr.io", + "repository": "paperless-ngx/paperless-ngx", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PAPERLESS_REDIS", + "example": "redis://broker:6379", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PAPERLESS_DBHOST", + "example": "db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PAPERLESS_DBENGINE", + "example": "postgresql", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PAPERLESS_DBNAME", + "example": "paperless", + "required": true, + "sensitive": false, + "source": "proxmenux-installer" + }, + { + "name": "PAPERLESS_DBUSER", + "example": "paperless", + "required": true, + "sensitive": false, + "source": "proxmenux-installer" + }, + { + "name": "PAPERLESS_DBPASS", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "proxmenux-installer" + }, + { + "name": "PAPERLESS_SECRET_KEY", + "example": "${GENERATED_SECRET_KEY}", + "required": true, + "sensitive": true, + "source": "docker-compose.env" + }, + { + "name": "PAPERLESS_ADMIN_USER", + "example": "admin", + "required": true, + "sensitive": false, + "source": "paperless-ngx-configuration" + }, + { + "name": "PAPERLESS_ADMIN_PASSWORD", + "example": "${GENERATED_ADMIN_PASSWORD}", + "required": true, + "sensitive": true, + "source": "paperless-ngx-configuration" + }, + { + "name": "PAPERLESS_TIME_ZONE", + "example": "Europe/Madrid", + "required": false, + "sensitive": false, + "source": "docker-compose.env" + }, + { + "name": "PAPERLESS_OCR_LANGUAGE", + "example": "spa", + "required": false, + "sensitive": false, + "source": "docker-compose.env" + } + ], + "volumes": [ + { + "id": "paperless-data", + "container_path": "/usr/src/paperless/data", + "compose_source_example": "data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "paperless-media", + "container_path": "/usr/src/paperless/media", + "compose_source_example": "media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 64 + } + }, + { + "id": "paperless-export", + "container_path": "/usr/src/paperless/export", + "compose_source_example": "./export", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "paperless-consume", + "container_path": "/usr/src/paperless/consume", + "compose_source_example": "./consume", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8000, + "published_example": 8000, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "db", + "image": "docker.io/library/postgres:18" + }, + { + "name": "broker", + "image": "docker.io/valkey/valkey:9-alpine" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n broker:\n image: docker.io/valkey/valkey:9-alpine\n restart: unless-stopped\n volumes:\n - redisdata:/data\n db:\n image: docker.io/library/postgres:18\n restart: unless-stopped\n volumes:\n - pgdata:/var/lib/postgresql\n environment:\n POSTGRES_DB: paperless\n POSTGRES_USER: paperless\n POSTGRES_PASSWORD: paperless\n webserver:\n image: ghcr.io/paperless-ngx/paperless-ngx:latest\n restart: unless-stopped\n depends_on:\n - db\n - broker\n ports:\n - '8000:8000'\n volumes:\n - data:/usr/src/paperless/data\n - media:/usr/src/paperless/media\n - ./export:/usr/src/paperless/export\n - ./consume:/usr/src/paperless/consume\n env_file: docker-compose.env\n environment:\n PAPERLESS_REDIS: redis://broker:6379\n PAPERLESS_DBHOST: db\n PAPERLESS_DBENGINE: postgresql\nvolumes:\n data:\n media:\n pgdata:\n redisdata:\n" + }, + "compose_stack": { + "project_name": "paperless-ngx", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "webserver", + "service_count": 3, + "services": [ + { + "name": "broker", + "image": "docker.io/valkey/valkey:9-alpine", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "docker.io/valkey/valkey:9-alpine", + "restart": "unless-stopped", + "volumes": [ + "redisdata:/data" + ] + } + }, + { + "name": "db", + "image": "docker.io/library/postgres:18", + "is_main": false, + "role": "dependency", + "vmid_offset": 2, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "docker.io/library/postgres:18", + "environment": { + "POSTGRES_DB": "paperless", + "POSTGRES_USER": "paperless", + "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}" + }, + "restart": "unless-stopped", + "volumes": [ + "pgdata:/var/lib/postgresql" + ] + } + }, + { + "name": "webserver", + "image": "ghcr.io/paperless-ngx/paperless-ngx:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "db", + "broker" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "ghcr.io/paperless-ngx/paperless-ngx:latest", + "ports": [ + "8000:8000" + ], + "volumes": [ + "data:/usr/src/paperless/data", + "media:/usr/src/paperless/media", + "./export:/usr/src/paperless/export", + "./consume:/usr/src/paperless/consume" + ], + "environment": { + "PAPERLESS_REDIS": "redis://broker:6379", + "PAPERLESS_DBHOST": "db", + "PAPERLESS_DBENGINE": "postgresql" + }, + "restart": "unless-stopped" + } + } + ], + "top_level": { + "volumes": { + "data": {}, + "media": {}, + "pgdata": {}, + "redisdata": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-replace-compose-service-dns", + "dependency_external_access": "disabled", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "webserver-data", + "service": "webserver", + "container_path": "/usr/src/paperless/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + }, + { + "id": "webserver-media", + "service": "webserver", + "container_path": "/usr/src/paperless/media", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + }, + { + "id": "webserver-export", + "service": "webserver", + "container_path": "/usr/src/paperless/export", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "webserver-consume", + "service": "webserver", + "container_path": "/usr/src/paperless/consume", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "host-bind", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "database-data", + "service": "db", + "container_path": "/var/lib/postgresql", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + }, + { + "id": "broker-data", + "service": "broker", + "container_path": "/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + } + ], + "orchestration": { + "reserve_vmids_atomically": 3, + "start_order": [ + "db", + "broker", + "webserver" + ], + "stop_order": [ + "webserver", + "broker", + "db" + ], + "dependency_readiness": "healthcheck-before-webserver", + "rollback_on_failure": "remove-all-new-lxc-and-new-managed-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "timezone", + "ocr_language", + "admin_username" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_addresses", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [ + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install" + }, + { + "id": "database-password", + "strategy": "generate-cryptographically-random-at-install" + }, + { + "id": "secret-key", + "strategy": "generate-cryptographically-random-at-install" + } + ] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Paperless-ngx WebUI", + "scheme": "http", + "port": 8000, + "path": "/", + "source": "official-compose" + } + ], + "credentials": [ + { + "label": "Generated Paperless administrator", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "proxmenux-installer-generated", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 1024, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "catalog": { + "replaces_discovered_ids": [ + "paperless-ngx" + ] + }, + "adaptations": [ + { + "id": "three-native-lxc-services", + "upstream_behavior": "Docker Compose starts Paperless-ngx, PostgreSQL and Valkey together.", + "native_lxc_behavior": "One catalog action creates three native OCI LXC containers.", + "reason": "Each OCI image is imported as its own Proxmox LXC.", + "behavioral_impact": "The user still installs one application stack.", + "validation": "passed-laboratory-2026-09-13" + }, + { + "id": "private-service-network", + "upstream_behavior": "Compose DNS connects webserver to db and broker.", + "native_lxc_behavior": "A private Proxmox bridge assigns fixed addresses to all three services.", + "reason": "Native LXC containers do not share Docker service discovery.", + "behavioral_impact": "PostgreSQL and Valkey are not exposed on the LAN.", + "validation": "passed-laboratory-2026-09-13" + }, + { + "id": "native-persistent-volumes", + "upstream_behavior": "Docker named volumes persist data, media, PostgreSQL and Valkey.", + "native_lxc_behavior": "Proxmox-managed mpN volumes preserve the same container paths with backup=1.", + "reason": "Private state must participate in native Proxmox backup and restore.", + "behavioral_impact": "No application state depends on the root filesystem.", + "validation": "passed-laboratory-2026-09-13" + }, + { + "id": "selectable-transfer-directories", + "upstream_behavior": "Compose bind-mounts local export and consume directories.", + "native_lxc_behavior": "The installer offers managed volumes or host directories and creates selected host paths.", + "reason": "Scanners and other OCI applications may need access to consume and export.", + "behavioral_impact": "Host-bound transfer folders are excluded from native LXC backups.", + "validation": "passed-laboratory-2026-09-13" + }, + { + "id": "generated-first-run-secrets", + "upstream_behavior": "The administrator and required secret key are configured outside the Compose file.", + "native_lxc_behavior": "The installer generates an admin password, database password and Paperless secret key.", + "reason": "A new deployment must not use published default secrets.", + "behavioral_impact": "The initial administrator credentials are printed once after installation.", + "validation": "passed-laboratory-2026-09-13" + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "minimum_host_memory_mb": 4096, + "recommended_host_memory_mb": 6144, + "database_storage": { + "must_be_local": true, + "network_filesystem_allowed": false + } + }, + "defaults": { + "stack_name": "paperless", + "timezone": "Europe/Madrid", + "ocr_language": "spa", + "rootfs_storage": "local-lvm", + "application_storage": "local-lvm", + "database_storage": "local-lvm", + "data_volume_size_gb": 8, + "media_volume_size_gb": 64, + "database_volume_size_gb": 8, + "broker_volume_size_gb": 4, + "transfer_volume_size_gb": 8, + "shared_transfer_root": "/mnt/oci-shared/paperless/${stack_name}", + "frontend_network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "firewall": true, + "host_managed": true + }, + "private_network": { + "mode": "create-if-missing", + "bridge": "vmbr10", + "subnet": "10.77.0.0/24", + "host_address": "10.77.0.1/24", + "application_address": "10.77.0.30/24", + "database_address": "10.77.0.31/24", + "broker_address": "10.77.0.32/24", + "nat": false + }, + "application": { + "admin_username": "admin" + } + }, + "installer_contract": { + "deployment_kind": "paperless-three-lxc-stack", + "reserve_vmids_atomically": 3, + "generated_secrets": [ + "POSTGRES_PASSWORD", + "PAPERLESS_ADMIN_PASSWORD", + "PAPERLESS_SECRET_KEY" + ], + "private_volumes": { + "data": "/usr/src/paperless/data", + "media": "/usr/src/paperless/media", + "database": "/var/lib/postgresql", + "broker": "/data" + }, + "transfer_directories": { + "choices": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind" + }, + "start_order": [ + "db", + "broker", + "webserver" + ], + "stop_order": [ + "webserver", + "broker", + "db" + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "depends_on", + "env_file", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The official three-service PostgreSQL Compose has a dedicated native LXC orchestrator validated by clean installation and ordered restart." + }, + "validation": { + "schema": "passed", + "clean_install": "passed-2026-09-13-paperless-ngx-3.1.3", + "service_health": "passed-paperless-postgresql-valkey", + "restart_persistence": "passed-ordered-stop-start-admin-preserved", + "backup_restore": "pending", + "update_preserves_data": "pending", + "private_dependency_network": "passed-10.77.0.30-32", + "managed_volume_persistence": "passed-data-media-postgresql-valkey", + "ocr_languages": "passed-eng-spa", + "laboratory_versions": { + "paperless_ngx": "3.1.3", + "postgresql": "18.6", + "valkey": "9.1.2" + } + }, + "lifecycle": { + "update_strategy": "resolve-selected-tags-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-image-digests", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "starts_stopped_dependencies": true, + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false, + "persistent_contract": "/etc/pve/priv/proxmenux-stack-.json", + "runtime_owner": "proxmox-ve" + } + } +} diff --git a/oci/catalog/curated/plex-official.json b/oci/catalog/curated/plex-official.json new file mode 100644 index 00000000..338f1186 --- /dev/null +++ b/oci/catalog/curated/plex-official.json @@ -0,0 +1,523 @@ +{ + "schema_version": "0.4.0", + "kind": "proxmenux.oci-template", + "id": "image-plex-official", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Plex Official" + }, + "tagline": { + "en_US": "Official Plex Media Server image with optional hardware transcoding." + }, + "description": { + "en_US": "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Plex, Inc.", + "developer": "Plex, Inc.", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/plex-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/plex-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 32400, + "path": "/web" + }, + "website": "https://www.plex.tv/media-server-downloads/", + "documentation": "https://github.com/plexinc/pms-docker/blob/master/README.md", + "repository": "https://github.com/plexinc/pms-docker", + "tips": [ + "PLEX_CLAIM is optional and only used during first run.", + "Keep the Plex database on a local Proxmox-backed volume because filesystems without reliable locking can corrupt it.", + "Hardware transcoding requires Plex Pass and must also be enabled under Settings > Transcoder." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "plex", + "repository": "https://github.com/plexinc/pms-docker", + "default_branch": "master", + "revision": "d6d268472090c5620f9c505cdb20be6a86d37f5b", + "image_repository_url": "https://github.com/plexinc/pms-docker", + "compose_sha256": "9f0203d20c2c719b50111eb8c419c5c15080602e5bdf4dcf59304de6d898ddf8", + "generated_at": "2026-09-13T21:08:59+00:00" + }, + "container_contract": { + "service_name": "plex", + "container_name": "plex", + "image": { + "reference": "plexinc/pms-docker:latest", + "registry": "docker.io", + "repository": "plexinc/pms-docker", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "official-container-documentation" + }, + { + "name": "PLEX_CLAIM", + "example": "", + "required": false, + "sensitive": true, + "source": "official-container-documentation", + "prompt": "Optional token from https://www.plex.tv/claim" + }, + { + "name": "ADVERTISE_IP", + "example": "", + "required": false, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Additional URL advertised by Plex (optional)" + }, + { + "name": "PLEX_UID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "UID of the plex user (also owner of the GPU device)" + }, + { + "name": "PLEX_GID", + "example": "", + "required": false, + "sensitive": false, + "source": "official-container-documentation", + "prompt": "Optional GID of the plex group" + } + ], + "volumes": [ + { + "id": "config", + "container_path": "/config", + "compose_source_example": "/path/to/plex/database", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 16 + } + }, + { + "id": "transcode", + "container_path": "/transcode", + "compose_source_example": "/path/to/transcode/temp", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "managed-volume", + "managed_volume": { + "backup": false, + "default_size_gb": 16 + } + }, + { + "id": "media", + "container_path": "/data", + "compose_source_example": "/path/to/media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": false, + "default_size_gb": 32 + } + } + ], + "ports": [ + { + "container_port": 32400, + "published_example": 32400, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8324, + "published_example": 8324, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32469, + "published_example": 32469, + "protocol": "tcp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 1900, + "published_example": 1900, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32410, + "published_example": 32410, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32412, + "published_example": 32412, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32413, + "published_example": 32413, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 32414, + "published_example": 32414, + "protocol": "udp", + "required": false, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n plex:\n image: plexinc/pms-docker:latest\n container_name: plex\n environment:\n - TZ=Europe/Madrid\n - PLEX_CLAIM=\n - ADVERTISE_IP=\n volumes:\n - /path/to/plex/database:/config\n - /path/to/transcode/temp:/transcode\n - /path/to/media:/data\n ports:\n - 32400:32400/tcp\n - 8324:8324/tcp\n - 32469:32469/tcp\n - 1900:1900/udp\n - 32410:32410/udp\n - 32412:32412/udp\n - 32413:32413/udp\n - 32414:32414/udp\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [ + { + "label": "Plex WebUI", + "scheme": "http", + "port": 32400, + "path": "/web", + "source": "official-container-documentation" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Plex", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [], + "architectures": [ + "amd64", + "arm64" + ] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "uid_from_environment": "PLEX_UID" + } + ], + "architectures": [ + "amd64" + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ], + "architectures": [ + "amd64", + "arm64" + ] + } + ] + }, + "network": { + "compose_mode": "bridge" + }, + "startup_healthcheck": { + "scheme": "http", + "port": 32400, + "path": "/identity", + "timeout_seconds": 240, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "application_options": { + "hardware_transcoding": { + "show_in_catalog": true, + "selectable": true, + "requires_subscription": "Plex Pass", + "panel_configuration_required": "Settings > Transcoder > Use hardware acceleration when available" + } + }, + "catalog": { + "replaces_discovered_ids": [] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/rclone.json b/oci/catalog/curated/rclone.json new file mode 100644 index 00000000..4bc4f3ff --- /dev/null +++ b/oci/catalog/curated/rclone.json @@ -0,0 +1,946 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-rclone", + "status": "laboratory-validated", + "catalog_ui": { + "title": { + "en_US": "Rclone WebUI" + }, + "tagline": { + "en_US": "Cloud storage synchronization and FUSE mounts" + }, + "description": { + "en_US": "Official Rclone image adapted as a native Proxmox OCI LXC with persistent configuration, authenticated WebUI and optional FUSE publication for other LXCs." + }, + "category": "backup", + "category_label": "Backup & Recovery", + "author": "Rclone", + "developer": "Rclone", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5572, + "path": "/" + }, + "website": "https://rclone.org/", + "documentation": "https://rclone.org/install/#docker-installation", + "repository": "https://github.com/rclone/rclone", + "tips": [ + "The installer generates WebUI credentials; the user creates and authorizes their own remote.", + "FUSE publication is optional and requires a privileged LXC plus explicit Proxmox host adaptations." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-12" + }, + "source": { + "provider": "rclone", + "repository": "https://github.com/rclone/rclone", + "revision": "049e11eb7df3d9b30e6e5d400945866db980041bdc0c50b4ede09e079b2e9f52", + "image_repository_url": "https://hub.docker.com/r/rclone/rclone", + "readme_pushed_at": "2026-09-12T11:36:50Z", + "compose_sha256": "049e11eb7df3d9b30e6e5d400945866db980041bdc0c50b4ede09e079b2e9f52", + "generated_at": "2026-09-12T15:54:10+00:00", + "default_branch": "master" + }, + "container_contract": { + "service_name": "rclone", + "container_name": "rclone", + "image": { + "reference": "rclone/rclone:latest", + "registry": "docker.io", + "repository": "rclone/rclone", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "XDG_CONFIG_HOME", + "example": "/config", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config/rclone", + "compose_source_example": "rclone-config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/mnt/oci-shared/rclone/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5572, + "published_example": 5572, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 5573, + "published_example": 5573, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: rclone\nservices:\n rclone:\n image: rclone/rclone:latest\n command:\n - gui\n - --no-open-browser\n - --addr=:5572\n - --api-addr=:5573\n - --config=/config/rclone/rclone.conf\n environment:\n XDG_CONFIG_HOME: /config\n ports:\n - 5572:5572\n - 5573:5573\n volumes:\n - rclone-config:/config/rclone\n - /mnt/oci-shared/rclone/data:/data\n devices:\n - /dev/fuse:/dev/fuse\n cap_add:\n - SYS_ADMIN\n security_opt:\n - apparmor:unconfined\n restart: unless-stopped\nvolumes:\n rclone-config: {}\n" + }, + "compose_stack": { + "project_name": "rclone", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "rclone", + "service_count": 1, + "services": [ + { + "name": "rclone", + "image": "rclone/rclone:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "rclone/rclone:latest", + "command": [ + "gui", + "--no-open-browser", + "--addr=:5572", + "--api-addr=:5573", + "--config=/config/rclone/rclone.conf" + ], + "environment": { + "XDG_CONFIG_HOME": "/config" + }, + "ports": [ + "5572:5572", + "5573:5573" + ], + "volumes": [ + "rclone-config:/config/rclone", + "/mnt/oci-shared/rclone/data:/data" + ], + "devices": [ + "/dev/fuse:/dev/fuse" + ], + "cap_add": [ + "SYS_ADMIN" + ], + "security_opt": [ + "apparmor:unconfined" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "rclone", + "volumes": { + "rclone-config": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "rclone-volume-0", + "service": "rclone", + "container_path": "/config/rclone", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "rclone-volume-1", + "service": "rclone", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for rclone:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "rclone" + ], + "stop_order": [ + "rclone" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Rclone WebUI", + "scheme": "http", + "port": 5572, + "path": "/", + "source": "validated-laboratory-profile" + } + ], + "credentials": [ + { + "label": "Rclone WebUI", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "RCLONE_RC_USER", + "password_environment": "RCLONE_RC_PASS", + "change_required": false, + "source": "official-rclone-rc-environment", + "retrieval": null + } + ] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [] + }, + "defaults": { + "unprivileged": false, + "privileged_required": true, + "ostype": "auto-from-image", + "cores": 1, + "memory_mb": 512, + "swap_mb": 256, + "rootfs_size_gb": 4, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": true, + "features": [ + "nesting=1", + "fuse=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image-or-reviewed-generated-wrapper", + "cmd": "apply-selected-rclone-mode", + "environment": "preserve-image-env-then-apply-user-values", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "fuse-inside-oci-lxc", + "upstream_behavior": "The official Rclone Docker deployment receives /dev/fuse and SYS_ADMIN to run rclone mount.", + "native_lxc_behavior": "Create a privileged Proxmox OCI LXC with features fuse=1; a minimal wrapper reads persistent RC credentials, waits for host-managed networking and execs the official Rclone binary as PID 1.", + "reason": "FUSE is the core function, and the OCI process can start before Proxmox finishes host-managed networking.", + "behavioral_impact": "Equivalent mount and RC behavior; credentials remain at the official persistent configuration boundary.", + "validation": "Passed on CT138 with gdrive:; official Rclone became PID 1 and the internal fuse.rclone mount survived stop/start." + }, + { + "id": "publish-fuse-submount", + "upstream_behavior": "Docker can publish a FUSE submount through a bind configured with shared propagation.", + "native_lxc_behavior": "A Proxmox hook starts a transient one-shot waiter after post-start. The waiter clones the FUSE tree from the LXC mount namespace with open_tree, creates canonical read/write and recursive read-only views with mount_setattr, and publishes both in the host namespace with move_mount; pre-stop removes them.", + "reason": "LXC makes the container mount tree a slave of the host, so rshared alone cannot propagate a container-created mount back to the host.", + "behavioral_impact": "Namespace topology only; no Rclone process, remote protocol or application data is moved to the host.", + "validation": "Passed on Proxmox VE 9.2.11/kernel 7.0.14-14-pve: canonical read/write publication, recursive read-only publication, clean unpublish, republish, and simultaneous Plex/Jellyfin consumption." + }, + { + "id": "consumer-parent-plus-exact-mounts", + "upstream_behavior": "Consumers bind the published Docker host path with the requested read/write policy.", + "native_lxc_behavior": "Read-only consumers receive the shared remotes-ro root first and one exact mpN from that same intrinsically read-only publication per selected remote second.", + "reason": "The parent mount carries future mount/unmount propagation while the exact mpN includes an already-published FUSE tree during consumer startup; the host publication itself enforces read-only after Rclone mount replacement.", + "behavioral_impact": "Equivalent consumer path with explicit Proxmox storage metadata.", + "validation": "Validated with CT131 Plex and CT128 Jellyfin before and after restarting CT138 Rclone; both exposed the remote through the recursive read-only publication." + } + ], + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "commands": [ + "pct", + "pvesm", + "skopeo", + "curl", + "jq", + "openssl" + ], + "features": [ + "native-oci-lxc", + "privileged-lxc", + "fuse=1", + "documented-mount-propagation", + "managed-volume-backup", + "authenticated-webui" + ], + "thin_pool_checks": { + "minimum_free_percent": 15, + "warn_when_virtual_allocation_exceeds_pool": true, + "require_autoextend_or_explicit_confirmation": true + }, + "security": { + "privileged_container_warning": true, + "dedicated_service_lxc": true, + "never_expose_rc_webui_to_untrusted_networks": true, + "consumer_paths_read_only_by_default": true + } + }, + "configuration_schema": { + "vmid": { + "type": "integer", + "required": false, + "default": null + }, + "hostname": { + "type": "string", + "required": true, + "default": "rclone", + "validation": { + "pattern": "^[a-z0-9][a-z0-9-]{0,62}$" + } + }, + "rootfs_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "default": "local-lvm" + }, + "rootfs_size_gb": { + "type": "integer", + "required": true, + "default": 4, + "minimum": 2 + }, + "config_storage": { + "type": "storage-selector", + "required": true, + "content_types": [ + "rootdir" + ], + "default": "local-lvm" + }, + "config_size_gb": { + "type": "integer", + "required": true, + "default": 2, + "minimum": 1 + }, + "data_host_path": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared/rclone/data", + "create_if_missing": true, + "description": "Directorio local para operaciones copy y sync. No contiene la configuracion persistente." + }, + "webui_username": { + "type": "string", + "required": true, + "default": "admin", + "validation": { + "pattern": "^[A-Za-z0-9._-]{1,64}$" + } + }, + "webui_password": { + "type": "generated-password", + "required": true, + "generate_when_empty": true, + "minimum_length": 24, + "sensitive": true + }, + "webui_port": { + "type": "port", + "required": true, + "default": 5572 + }, + "api_port": { + "type": "port", + "required": true, + "default": 5573 + }, + "bridge": { + "type": "network-bridge-selector", + "required": true, + "default": "vmbr0" + }, + "ipv4_mode": { + "type": "select", + "required": true, + "default": "dhcp", + "options": [ + "dhcp", + "static" + ] + }, + "ipv4_address": { + "type": "ipv4-cidr", + "required_when": { + "field": "ipv4_mode", + "equals": "static" + } + }, + "gateway": { + "type": "ipv4", + "required_when": { + "field": "ipv4_mode", + "equals": "static" + } + }, + "onboot": { + "type": "boolean", + "required": true, + "default": true + }, + "shared_mount_root": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared/remotes", + "create_if_missing": true, + "description": "Host root where the remote mounts appear, to be assigned afterwards to Plex, Jellyfin, qBittorrent or other OCI containers." + }, + "mount_name": { + "type": "string", + "required": true, + "default": "remote", + "validation": { + "pattern": "^[A-Za-z0-9._-]{1,64}$" + } + }, + "remote_name": { + "type": "rclone-remote-selector", + "required_after": "authorize_remote", + "description": "Remote created by the user; it is never included in the template." + }, + "remote_path": { + "type": "string", + "required": true, + "default": "" + }, + "vfs_cache_mode": { + "type": "select", + "required": true, + "default": "full", + "options": [ + "off", + "minimal", + "writes", + "full" + ] + }, + "shared_mount_root_parent": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared", + "create_if_missing": true, + "description": "Punto de montaje del host que contiene las publicaciones de lectura/escritura y de solo lectura; el hook lo configura como rshared." + }, + "shared_mount_read_only_root": { + "type": "host-directory", + "required": true, + "default": "/mnt/oci-shared/remotes-ro", + "create_if_missing": true, + "description": "Vista FUSE recursivamente de solo lectura para consumidores multimedia como Plex y Jellyfin." + } + }, + "mounts": [ + { + "id": "config", + "container_path": "/config/rclone", + "source": "managed-volume", + "storage_field": "config_storage", + "size_field": "config_size_gb", + "backup": true, + "required": true, + "contains_secrets": true, + "contains": [ + "rclone.conf", + "rclone.log", + "cache" + ] + }, + { + "id": "internal-fuse-root", + "container_path": "/data/mounts", + "source": "container-rootfs-directory", + "read_only": false, + "backup": false, + "required_in_mount_mode": true, + "purpose": "Internal target for official rclone mount before host publication." + } + ], + "environment": [ + { + "name": "XDG_CONFIG_HOME", + "value": "/config" + } + ], + "deployment": { + "runtime": "proxmox-native-oci-lxc", + "unprivileged": false, + "privileged_container_required": true, + "fuse_device_inside_container_required": true, + "entrypoint": "/usr/local/bin/rclone gui --no-open-browser --addr=:${webui_port} --api-addr=:${api_port} --config=/config/rclone/rclone.conf --cache-dir=/config/rclone/cache --log-file=/config/rclone/rclone.log --log-level=${log_level}", + "working_directory": "/data", + "hostname_default": "rclone", + "onboot_default": true, + "startup_order_default": 10, + "startup_delay_seconds_default": 20, + "shutdown_timeout_seconds": 30, + "halt_signal": "SIGTERM", + "features": [ + "nesting=1", + "fuse=1" + ], + "ports": [ + { + "port_from": "webui_port", + "protocol": "tcp", + "purpose": "authenticated-web-ui" + }, + { + "port_from": "api_port", + "protocol": "tcp", + "purpose": "authenticated-remote-control-api" + } + ], + "preserve_image_environment": true, + "restart_method": "clean-stop-then-start", + "restart_note": "On some OCI containers, pct reboot left a residual lxc-start monitor behind. The installer prefers pct stop followed by pct start, and checks the new PID.", + "entrypoint_source": "setup-direct-command-or-generated-mount-wrapper", + "entrypoint_override": "setup-mode-official-rclone-gui-command", + "runtime_modes": { + "setup": { + "purpose": "Create and authorize the user's own remote through the authenticated WebUI.", + "entrypoint": "/usr/local/bin/rclone gui --no-open-browser --addr=:${webui_port} --api-addr=:${api_port} --config=/config/rclone/rclone.conf --cache-dir=/config/rclone/cache --log-file=/config/rclone/rclone.log --log-level=${log_level}" + }, + "mount": { + "purpose": "Mount one selected remote, keep the authenticated RC WebUI/API available and publish the FUSE tree for native Proxmox consumers.", + "entrypoint": "/usr/local/bin/rclone-mount-lxc-start", + "wrapper_behavior": "Read RC credentials from /config, wait for host-managed networking, then exec the official Rclone binary.", + "official_command": "/usr/local/bin/rclone mount ${remote_name}:${remote_path} /data/mounts/${mount_name}", + "webui_assets": "official-rclone-webui-selected-by---rc-web-gui", + "webui_serving": "official --rc-web-gui flags on the RC listener", + "pid1": "official-rclone-binary-after-wrapper-exec", + "restart_persistence": "Proxmox starts the generated mount wrapper on every boot.", + "credentials": { + "source": "/config/rclone/webui.credentials", + "mode": "0600", + "exported_only_inside_lxc": [ + "RCLONE_RC_USER", + "RCLONE_RC_PASS" + ], + "stored_in_pve_config": false + } + } + } + }, + "bootstrap": { + "mode": "two-phase-official-rclone-process", + "steps": [ + "validate-privileged-fuse-and-propagation-requirements", + "pull-oci-image-by-digest", + "create-managed-config-volume", + "create-shared-mount-root", + "generate-webui-password-when-empty", + "apply-webui-credentials-to-proxmox-env", + "create-privileged-container-with-fuse", + "start-setup-mode", + "verify-authenticated-webui-and-api", + "show-authorize-remote-next-action" + ], + "credentials_policy": { + "delivery": "Proxmox env property", + "environment": [ + "RCLONE_RC_USER", + "RCLONE_RC_PASS" + ], + "pve_visibility": "visible-by-design", + "remote_credentials_storage": "/config/rclone/rclone.conf" + } + }, + "post_install_workflows": { + "authorize_remote": { + "when": "after-base-install", + "performed_by": "user-in-authenticated-webui", + "requires_terminal": false, + "initial_state": { + "rclone_config": "empty", + "preconfigured_remotes": 0, + "import_remote_from_another_installation": false + }, + "steps": [ + "open-generated-webui-access-url", + "select-new-remote-provider", + "create-new-remote-from-scratch", + "complete-provider-oauth", + "verify-remote-with-authenticated-rc-api" + ], + "result": { + "config_path": "/config/rclone/rclone.conf", + "tokens_persist_in_managed_config_volume": true + } + }, + "publish_remote": { + "when": "after-authorize-remote", + "performed_by": "installer-with-explicit-user-selection", + "requires_terminal": false, + "steps": [ + "list-user-created-remotes-through-authenticated-rc-api", + "ask-user-for-remote-path-and-mount-name", + "stop-setup-mode", + "apply-official-rclone-mount-entrypoint", + "start-container", + "verify-fuse-inside-container", + "verify-submount-visible-on-host", + "optionally-assign-published-path-to-selected-consumer-lxc" + ], + "consumer_policy": "Consumers are never modified unless the user selects them explicitly.", + "status": "installer-implemented" + } + }, + "healthcheck": { + "type": "authenticated-http-and-api", + "webui": { + "port_from": "webui_port", + "path": "/", + "expected_status": 200 + }, + "api": { + "port_from": "api_port", + "method": "POST", + "path": "/core/version", + "expected_version": "v1.75.0", + "credentials_from": "lxc.environment.runtime:RCLONE_RC_USER,RCLONE_RC_PASS" + }, + "retries": 30, + "start_period_seconds": 60 + }, + "backup_restore": { + "native_proxmox_backup": true, + "included_mounts": [ + "/config/rclone" + ], + "excluded_mounts": [ + "/data" + ], + "external_backup_recommended": [ + "data_host_path-if-it-contains-unique-local-data" + ], + "restore_order": [ + "restore-vzdump", + "verify-managed-config-volume", + "verify-data-host-path", + "start-rclone-oci", + "verify-authenticated-webui-and-api" + ], + "application_consistency": "Use stop mode when active copy or sync jobs require a consistent snapshot. OAuth tokens in rclone.conf are included in the managed config volume." + }, + "boundaries": { + "bundles_webui_credentials": false, + "bundles_remote_credentials": false, + "bundles_rclone_remotes": false, + "bundles_user_data": false, + "installer_must_not_create_external_remotes": true, + "installer_must_not_import_remotes_from_other_lxcs": true, + "template_starts_with_empty_rclone_config": true, + "user_must_create_and_authorize_own_remote": true, + "cross_lxc_fuse_publication_supported": "laboratory-validated", + "consumer_assignments_require_explicit_user_selection": true, + "rclone_runs_inside_its_oci_lxc": true, + "no_host_rclone_binary_or_application_supervisor": true + }, + "post_install_output": { + "url_template": "http://${container_ip}:${webui_port}/login?pass=${urlencode(webui_password)}&url=${urlencode(http://${container_ip}:${api_port}/)}&user=${urlencode(webui_username)}", + "sensitive": true, + "display_once_after_install": true, + "never_log": true + }, + "generated_assets": { + "mount-mode-wrapper": { + "target": "lxc:/usr/local/bin/rclone-mount-lxc-start", + "mode": "0755", + "content_template": "#!/bin/sh\nset -eu\n\ncredentials=/config/rclone/webui.credentials\nexport RCLONE_RC_USER=\"$(sed -n 's/^username=//p' \"$credentials\")\"\nexport RCLONE_RC_PASS=\"$(sed -n 's/^password=//p' \"$credentials\")\"\nremote_name=\"$(printf '%s' '{{remote_name_base64}}' | base64 -d)\"\nremote_path=\"$(printf '%s' '{{remote_path_base64}}' | base64 -d)\"\n\ntest -n \"$RCLONE_RC_USER\"\ntest -n \"$RCLONE_RC_PASS\"\ntest -n \"$remote_name\"\n\nnetwork_ready=false\nfor _ in $(seq 1 120); do\n if ip route get 1.1.1.1 >/dev/null 2>&1; then\n network_ready=true\n break\n fi\n sleep 1\ndone\ntest \"$network_ready\" = true\n\nexec /usr/local/bin/rclone mount \"${remote_name}:${remote_path}\" /data/mounts/{{mount_name}} \\\n --config /config/rclone/rclone.conf \\\n --allow-other \\\n --vfs-cache-mode {{vfs_cache_mode}} \\\n --cache-dir /config/rclone/cache \\\n --rc \\\n --rc-addr :{{webui_port}} \\\n --rc-web-gui \\\n --rc-web-gui-no-open-browser \\\n --log-file /config/rclone/rclone.log \\\n --log-level ERROR\n" + }, + "mount-tree-publisher-source": { + "target": "host:/usr/local/libexec/proxmenux-oci-mount-publish", + "runtime": "python3-from-proxmox-host", + "mode": "0755", + "content": "#!/usr/bin/env python3\n\"\"\"Clone a FUSE mount from an LXC namespace into the Proxmox host namespace.\"\"\"\n\nfrom __future__ import annotations\n\nimport ctypes\nimport os\nimport platform\nimport sys\n\n\nAT_FDCWD = -100\nAT_EMPTY_PATH = 0x1000\nAT_RECURSIVE = 0x8000\nCLONE_NEWNS = 0x00020000\nMOVE_MOUNT_F_EMPTY_PATH = 0x00000004\nMOUNT_ATTR_RDONLY = 0x00000001\nOPEN_TREE_CLONE = 1\n\nSYSCALLS = {\n \"x86_64\": (428, 429, 442),\n \"amd64\": (428, 429, 442),\n \"aarch64\": (428, 429, 442),\n \"arm64\": (428, 429, 442),\n}\n\n\nclass MountAttr(ctypes.Structure):\n _fields_ = [\n (\"attr_set\", ctypes.c_uint64),\n (\"attr_clr\", ctypes.c_uint64),\n (\"propagation\", ctypes.c_uint64),\n (\"userns_fd\", ctypes.c_uint64),\n ]\n\n\ndef fail(step: str) -> None:\n error = ctypes.get_errno()\n raise OSError(error, f\"{step}: {os.strerror(error)}\")\n\n\ndef main() -> int:\n if len(sys.argv) != 5 or sys.argv[4] not in {\"rw\", \"ro\"}:\n print(f\"usage: {sys.argv[0]} PID SOURCE TARGET rw|ro\", file=sys.stderr)\n return 2\n machine = platform.machine().lower()\n if machine not in SYSCALLS:\n print(f\"unsupported host architecture: {machine}\", file=sys.stderr)\n return 2\n open_tree_nr, move_mount_nr, mount_setattr_nr = SYSCALLS[machine]\n pid, source, target, mode = sys.argv[1:]\n libc = ctypes.CDLL(None, use_errno=True)\n libc.syscall.restype = ctypes.c_long\n libc.setns.argtypes = (ctypes.c_int, ctypes.c_int)\n libc.setns.restype = ctypes.c_int\n\n host_ns = os.open(\"/proc/self/ns/mnt\", os.O_RDONLY | os.O_CLOEXEC)\n host_root = os.open(\"/\", os.O_PATH | os.O_DIRECTORY | os.O_CLOEXEC)\n ct_ns = os.open(f\"/proc/{pid}/ns/mnt\", os.O_RDONLY | os.O_CLOEXEC)\n ct_root = os.open(f\"/proc/{pid}/root\", os.O_PATH | os.O_DIRECTORY | os.O_CLOEXEC)\n try:\n if libc.setns(ct_ns, CLONE_NEWNS) != 0:\n fail(\"enter container namespace\")\n os.fchdir(ct_root)\n os.chroot(\".\")\n os.chdir(\"/\")\n tree = libc.syscall(\n open_tree_nr,\n AT_FDCWD,\n os.fsencode(source),\n OPEN_TREE_CLONE | os.O_CLOEXEC,\n )\n if tree < 0:\n fail(\"clone source mount tree\")\n try:\n if mode == \"ro\":\n attributes = MountAttr(attr_set=MOUNT_ATTR_RDONLY)\n result = libc.syscall(\n mount_setattr_nr,\n tree,\n ctypes.c_char_p(b\"\"),\n AT_EMPTY_PATH | AT_RECURSIVE,\n ctypes.byref(attributes),\n ctypes.sizeof(attributes),\n )\n if result != 0:\n fail(\"make cloned mount tree read-only\")\n if libc.setns(host_ns, CLONE_NEWNS) != 0:\n fail(\"return to host namespace\")\n os.fchdir(host_root)\n os.chroot(\".\")\n os.chdir(\"/\")\n result = libc.syscall(\n move_mount_nr,\n tree,\n ctypes.c_char_p(b\"\"),\n AT_FDCWD,\n os.fsencode(target),\n MOVE_MOUNT_F_EMPTY_PATH,\n )\n if result != 0:\n fail(\"publish mount tree\")\n finally:\n os.close(tree)\n finally:\n for descriptor in (ct_root, ct_ns, host_root, host_ns):\n os.close(descriptor)\n return 0\n\n\nif __name__ == \"__main__\":\n try:\n raise SystemExit(main())\n except OSError as exc:\n print(exc, file=sys.stderr)\n raise SystemExit(1)\n" + }, + "mount-publication-waiter": { + "target": "host:/usr/local/libexec/proxmenux-oci-mount-wait", + "mode": "0755", + "lifecycle": "transient-systemd-oneshot-only", + "content": "#!/usr/bin/env bash\nset -euo pipefail\n\nvmid=${1:?missing VMID}\ninside=${2:?missing source path}\npublished=${3:?missing target path}\npublished_ro=${4:?missing read-only target path}\nhelper=${5:?missing publisher helper}\n\nunpublish() {\n local target=$1\n if mountpoint -q \"$target\"; then\n umount \"$target\" || umount -l \"$target\"\n fi\n}\n\nfor _ in $(seq 1 300); do\n pid=$(lxc-info -n \"$vmid\" -pH 2>/dev/null || true)\n if [[ -n $pid ]] && awk -v path=\"$inside\" '$5 == path && $0 ~ / - fuse(\\.rclone)? / { found=1 } END { exit !found }' \"/proc/$pid/mountinfo\"; then\n unpublish \"$published_ro\"\n unpublish \"$published\"\n \"$helper\" \"$pid\" \"$inside\" \"$published\" rw\n if ! \"$helper\" \"$pid\" \"$inside\" \"$published_ro\" ro; then\n unpublish \"$published\"\n exit 1\n fi\n findmnt -T \"$published\" -n -o FSTYPE | grep -q '^fuse'\n findmnt -T \"$published_ro\" -n -o FSTYPE | grep -q '^fuse'\n findmnt -T \"$published_ro\" -n -o VFS-OPTIONS | tr ',' '\n' | grep -qx ro\n logger -t proxmenux-rclone \"Published CT $vmid $inside at $published (rw) and $published_ro (ro)\"\n exit 0\n fi\n sleep 1\ndone\n\nlogger -t proxmenux-rclone \"Timed out waiting for CT $vmid FUSE mount at $inside\"\nexit 1\n" + }, + "proxmox-hookscript": { + "target": "snippet-storage:proxmenux-rclone-${ctid}-fuse-hook.sh", + "mode": "0755", + "phases": [ + "pre-start", + "post-start", + "pre-stop", + "post-stop" + ], + "content_template": "#!/usr/bin/env bash\nset -euo pipefail\n\nvmid=${1:?missing VMID}\nphase=${2:?missing phase}\ninside=/data/mounts/{{mount_name}}\npublished={{shared_mount_root}}/{{mount_name}}\npublished_ro={{shared_mount_read_only_root}}/{{mount_name}}\nhelper=/usr/local/libexec/proxmenux-oci-mount-publish\nwaiter=/usr/local/libexec/proxmenux-oci-mount-wait\nunit=\"proxmenux-rclone-publish-$vmid.service\"\n\nunpublish() {\n local target=$1\n if mountpoint -q \"$target\"; then\n umount \"$target\" || umount -l \"$target\"\n fi\n}\n\nstop_waiter() {\n systemctl stop \"$unit\" >/dev/null 2>&1 || true\n systemctl reset-failed \"$unit\" >/dev/null 2>&1 || true\n}\n\ncase \"$phase\" in\n pre-start)\n install -d -m 0755 \"$published\" \"$published_ro\"\n if ! mountpoint -q {{shared_mount_root_parent}}; then\n mount --bind {{shared_mount_root_parent}} {{shared_mount_root_parent}}\n fi\n mount --make-rshared {{shared_mount_root_parent}}\n stop_waiter\n unpublish \"$published_ro\"\n unpublish \"$published\"\n ;;\n post-start)\n stop_waiter\n systemd-run --quiet --collect --unit=\"$unit\" -- \\\n \"$waiter\" \"$vmid\" \"$inside\" \"$published\" \"$published_ro\" \"$helper\"\n ;;\n pre-stop|post-stop)\n stop_waiter\n unpublish \"$published_ro\"\n unpublish \"$published\"\n ;;\nesac\n" + } + }, + "consumer_integration": { + "optional": true, + "canonical_read_write_root_host_path": "${shared_mount_root}", + "read_only_root_host_path": "${shared_mount_read_only_root}", + "read_only_remote_host_path": "${shared_mount_read_only_root}/${mount_name}", + "required_mount_order": [ + "shared-root-parent", + "exact-published-remote" + ], + "plex_example": { + "parent": "${shared_mount_read_only_root},mp=/data/remotes,backup=0,ro=1", + "exact": "${shared_mount_read_only_root}/${mount_name},mp=/data/remotes/${mount_name},backup=0,ro=1" + }, + "jellyfin_example": { + "parent": "${shared_mount_read_only_root},mp=/media/remotes,backup=0,ro=1", + "exact": "${shared_mount_read_only_root}/${mount_name},mp=/media/remotes/${mount_name},backup=0,ro=1" + }, + "restart_rule": "Keep both parent and exact mpN declarations so consumers recover when the Rclone FUSE publication is replaced." + }, + "notes": [ + "La configuracion, los tokens y las credenciales RC permanecen en /config/rclone dentro del volumen backup=1.", + "El usuario crea y autoriza su propio remote desde la WebUI; la plantilla no incluye remotes del laboratorio.", + "El modo mount usa un wrapper minimo que termina con exec del binario oficial; Rclone queda como PID 1.", + "La publicacion usa un hookscript oficial de Proxmox y una tarea systemd transitoria; no instala Rclone ni un supervisor permanente en el host.", + "Cada remoto se publica en una raiz canonica de lectura/escritura y en otra raiz recursivamente de solo lectura; cada consumidor selecciona la politica adecuada.", + "Los consumidores son opcionales y deben declarar el padre compartido mas un mpN exacto por remoto.", + "El perfil fue validado con reinicios de Rclone, Plex y Jellyfin." + ], + "references": { + "official_docker_install": "https://rclone.org/install/#docker-installation", + "official_gui_command": "https://rclone.org/commands/rclone_gui/", + "official_mount_command": "https://rclone.org/commands/rclone_mount/", + "official_vfs_documentation": "https://rclone.org/commands/rclone_mount/#vfs-file-caching" + } + }, + "security_profile": { + "requires_privileged_lxc": true, + "risk_level": "high", + "confirmation_required": true, + "warning": "Rclone mount requires a privileged LXC with FUSE access. Use this profile only on a trusted node and network." + }, + "installer_profile": { + "generated_files": [ + { + "id": "rclone-setup-wrapper", + "container_path": "/usr/local/bin/rclone-setup-lxc-start", + "owner": "mapped-root", + "mode": "0755", + "content": "#!/bin/sh\nset -eu\nmkdir -p /config/rclone/cache\nexec /usr/local/bin/rclone gui --no-open-browser --addr=:5572 --api-addr=:5573 --config=/config/rclone/rclone.conf --cache-dir=/config/rclone/cache --log-file=/config/rclone/rclone.log --log-level=ERROR\n" + } + ], + "volume_preparations": [ + { + "container_path": "/config/rclone", + "remove_lost_found": true, + "owner_strategy": "mapped-root" + } + ], + "runtime": { + "entrypoint": "/usr/local/bin/rclone-setup-lxc-start", + "working_directory": "/data", + "halt_signal": "SIGTERM" + }, + "startup_healthcheck": { + "scheme": "http", + "port": 5572, + "path": "/", + "verify_tls": false, + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "stability_seconds": 0 + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": true, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "Automatic installation implements the validated privileged FUSE LXC, generated wrappers, and host publication workflow with explicit user consent." + }, + "validation": { + "schema": "passed-at-generation", + "profile": { + "reference_host": "Proxmox VE 9.2.11, kernel 7.0.14-16-pve", + "reference_lxc": "CT120", + "internal_fuse_mount": "passed", + "host_publication": "passed", + "host_read_write_publication": "passed", + "host_recursive_read_only_publication": "passed", + "host_to_lxc_visibility": "passed", + "lxc_to_host_visibility": "passed", + "stop_unpublish": "passed", + "restart_republish_seconds": 2, + "plex_consumer": "passed-read-only", + "jellyfin_consumer": "passed-read-only", + "credentials_outside_config": false, + "transient_waiter_after_success": "inactive", + "installer_base_mode": "passed", + "privileged_oci_import_conversion": "passed-preserving-xattrs", + "official_rclone_version": "1.75.1", + "webui_mode": "passed-official-embedded-webui" + }, + "validated_profile": { + "id": "pve55-rclone-direct-fuse", + "container_id": 120, + "validation_status": "passed", + "passed": [ + "allow-other", + "consumer-lxc-read-only-policy", + "fuse-mount-inside-lxc", + "host-read-write-and-recursive-read-only-views", + "managed-config-volume", + "no-host-rclone-supervisor", + "official-rclone-binary-as-pid1", + "restart-with-published-host-mount", + "reverse-submount-publication-to-host" + ], + "pending": [] + }, + "source_profile": "rclone-oci.json" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-latest-oci-image-preserve-managed-config-volume-and-reapply-reviewed-assets", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false, + "validated_workflows": { + "install": [ + "validate-requirements", + "pull-oci-image-by-digest", + "create-managed-config-volume", + "create-shared-mount-root", + "create-privileged-fuse-container", + "install-generated-fuse-publication-assets-on-host", + "attach-proxmox-hookscript", + "start-setup-mode", + "wait-for-authenticated-healthcheck", + "show-authorize-remote-next-action" + ], + "update": [ + "stop-active-mount-cleanly-and-unpublish-host-tree", + "backup-container", + "pull-version-pinned-image", + "recreate-rootfs-preserving-managed-config-volume", + "reinstall-generated-wrapper-and-publication-assets", + "restore-selected-runtime-mode", + "start-container", + "verify-authenticated-api-internal-fuse-host-publication-and-consumers" + ], + "uninstall": { + "remove_rootfs": true, + "preserve_config_by_default": true, + "preserve_data_by_default": true + }, + "activate_mount": [ + "validate-selected-remote", + "generate-mount-wrapper-without-embedding-secrets", + "remove-legacy-rclone-rc-runtime-secret-lines-from-pve-config", + "set-mount-wrapper-as-entrypoint", + "stop-then-start-container", + "wait-for-host-published-fuse-tree", + "attach-shared-root-and-exact-remote-mounts-to-selected-consumers", + "validate-read-policy-from-each-consumer" + ] + } + } +} diff --git a/oci/catalog/curated/roonserver.json b/oci/catalog/curated/roonserver.json new file mode 100644 index 00000000..9d46d916 --- /dev/null +++ b/oci/catalog/curated/roonserver.json @@ -0,0 +1,625 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-roonserver", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Roon Server" + }, + "tagline": { + "en_US": "Music software that transforms your listening experience" + }, + "description": { + "en_US": "Roon music software transforms your listening experience with rich metadata, discovery features, and audiophile sound. It works with streaming services and local files.\n\nRoon brings all your music together and adds bios, reviews, photos, lyrics, tour dates, and cross-linked credits for performers, songwriters, producers, engineers, and composers. Everything about music - browsing, discovery, collecting, and listening - is more engaging with Roon.\n\nRoonServer is the central server component. It runs on a Linux amd64/x86_64 host, stores the Roon database and settings, and serves your library to Roon Remote clients and audio endpoints on your local network. It is controlled from the Roon app and does not provide a browser-based WebUI.\n" + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Roon Labs", + "developer": "Roon Labs", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://roon.app", + "documentation": null, + "repository": "https://ghcr.io/roonlabs/roonserver", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "roonlabs", + "repository": "https://ghcr.io/roonlabs/roonserver", + "revision": "5887607d4ca3e9334fea6c4e49ff2e0884595935ae057f3976c90dc98b8bd106", + "image_repository_url": "https://ghcr.io/roonlabs/roonserver", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "5887607d4ca3e9334fea6c4e49ff2e0884595935ae057f3976c90dc98b8bd106", + "generated_at": "2026-09-13T17:20:19+00:00" + }, + "container_contract": { + "service_name": "roonserver", + "container_name": "roonserver", + "image": { + "reference": "ghcr.io/roonlabs/roonserver:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/roonlabs/roonserver", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "ROON_INSTALL_BRANCH", + "example": "production", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/Roon", + "compose_source_example": "/DATA/AppData/$AppID/Roon", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/Music", + "compose_source_example": "/DATA/Media/Music", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/RoonBackups", + "compose_source_example": "/DATA/AppData/$AppID/RoonBackups", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/run/udev", + "compose_source_example": "/run/udev", + "read_only": true, + "required": true, + "installation_choice": [ + "host-bind" + ], + "default": "host-bind", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: roonserver\nservices:\n roonserver:\n image: ghcr.io/roonlabs/roonserver:latest\n container_name: roonserver\n network_mode: host\n restart: unless-stopped\n environment:\n ROON_INSTALL_BRANCH: production\n TZ: $TZ\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/Roon\n target: /Roon\n - type: bind\n source: /DATA/Media/Music\n target: /Music\n - type: bind\n source: /DATA/AppData/$AppID/RoonBackups\n target: /RoonBackups\n - type: bind\n source: /run/udev\n target: /run/udev\n read_only: true\n cap_add:\n - SYS_ADMIN\n - DAC_READ_SEARCH\n security_opt:\n - apparmor:unconfined\n - label:disable\n devices:\n - /dev/snd:/dev/snd\n - /dev/bus/usb:/dev/bus/usb\n - /dev/dri:/dev/dri\n group_add:\n - audio\n logging:\n driver: local\n" + }, + "compose_stack": { + "project_name": "roonserver", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "roonserver", + "service_count": 1, + "services": [ + { + "name": "roonserver", + "image": "ghcr.io/roonlabs/roonserver:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/roonlabs/roonserver:latest", + "container_name": "roonserver", + "network_mode": "host", + "restart": "unless-stopped", + "environment": { + "ROON_INSTALL_BRANCH": "production", + "TZ": "$TZ" + }, + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/Roon", + "target": "/Roon" + }, + { + "type": "bind", + "source": "/DATA/Media/Music", + "target": "/Music" + }, + { + "type": "bind", + "source": "/DATA/AppData/$AppID/RoonBackups", + "target": "/RoonBackups" + }, + { + "type": "bind", + "source": "/run/udev", + "target": "/run/udev", + "read_only": true + } + ], + "cap_add": [ + "SYS_ADMIN", + "DAC_READ_SEARCH" + ], + "security_opt": [ + "apparmor:unconfined", + "label:disable" + ], + "devices": [ + "/dev/snd:/dev/snd", + "/dev/bus/usb:/dev/bus/usb", + "/dev/dri:/dev/dri" + ], + "group_add": [ + "audio" + ], + "logging": { + "driver": "local" + } + } + } + ], + "top_level": { + "name": "roonserver" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "roonserver-volume-0", + "service": "roonserver", + "container_path": "/Roon", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "roonserver-volume-1", + "service": "roonserver", + "container_path": "/Music", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for roonserver:/Music" + }, + { + "id": "roonserver-volume-2", + "service": "roonserver", + "container_path": "/RoonBackups", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "roonserver-volume-3", + "service": "roonserver", + "container_path": "/run/udev", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "roonserver" + ], + "stop_order": [ + "roonserver" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "supplemental_groups": [ + "audio" + ] + }, + "network": { + "compose_mode": "host" + }, + "security": { + "required_capabilities": [ + "SYS_ADMIN", + "DAC_READ_SEARCH" + ], + "options": { + "apparmor_profile": "unconfined", + "selinux_label_disabled": true + } + }, + "hardware_acceleration": { + "prompt": "Hardware acceleration for Roon Server", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ] + } + ] + }, + "optional_devices": [ + { + "id": "dev-snd", + "kind": "character-device-tree", + "purpose": "audio", + "enable_prompt": "Host audio devices", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "Audio device directory", + "host_path_default": "/dev/snd", + "container_path": "/dev/snd", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/snd:/dev/snd" + }, + { + "id": "dev-bus-usb", + "kind": "character-device-tree", + "purpose": "usb", + "enable_prompt": "Host USB bus", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "USB bus directory", + "host_path_default": "/dev/bus/usb", + "container_path": "/dev/bus/usb", + "mode": "preserve-host", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/bus/usb:/dev/bus/usb" + } + ] + }, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": true, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "risk_level": "high", + "confirmation_required": true, + "warning": "The image requests disabling part of the AppArmor or seccomp confinement. Continue only if you trust the image and accept this risk." + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "pending-per-application" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "pending-per-application" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "pending-per-application" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "catalog": { + "replaces_discovered_ids": [ + "roonserver" + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/seerr.json b/oci/catalog/curated/seerr.json new file mode 100644 index 00000000..60596c0b --- /dev/null +++ b/oci/catalog/curated/seerr.json @@ -0,0 +1,459 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-seerr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Seerr" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "Media discovery and request management for Jellyfin, Plex and Emby." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "official", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 5055, + "path": "/" + }, + "website": "https://docs.seerr.dev/getting-started/docker/", + "documentation": "https://docs.seerr.dev/getting-started/docker/", + "repository": "https://github.com/seerr-team/seerr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "official", + "repository": "https://github.com/seerr-team/seerr", + "revision": "872efff668cfd0f1e026111a266306b1b582b86746fff5467f11e5daddddf671", + "image_repository_url": "https://ghcr.io/seerr-team/seerr", + "readme_pushed_at": "", + "compose_sha256": "872efff668cfd0f1e026111a266306b1b582b86746fff5467f11e5daddddf671", + "generated_at": "2026-09-14T17:13:55+00:00" + }, + "container_contract": { + "service_name": "seerr", + "container_name": "seerr", + "image": { + "reference": "ghcr.io/seerr-team/seerr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/seerr-team/seerr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PORT", + "example": "5055", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LOG_LEVEL", + "example": "info", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 5055, + "published_example": 5055, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: seerr\nservices:\n seerr:\n image: ghcr.io/seerr-team/seerr:latest\n init: true\n environment:\n TZ: Europe/Madrid\n PORT: '5055'\n LOG_LEVEL: info\n ports:\n - 5055:5055\n volumes:\n - /path/to/config:/app/config\n security_opt:\n - no-new-privileges\n cap_drop:\n - ALL\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "seerr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "seerr", + "service_count": 1, + "services": [ + { + "name": "seerr", + "image": "ghcr.io/seerr-team/seerr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/seerr-team/seerr:latest", + "init": true, + "environment": { + "TZ": "Europe/Madrid", + "PORT": "5055", + "LOG_LEVEL": "info" + }, + "ports": [ + "5055:5055" + ], + "volumes": [ + "/path/to/config:/app/config" + ], + "security_opt": [ + "no-new-privileges" + ], + "cap_drop": [ + "ALL" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "seerr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "seerr-volume-0", + "service": "seerr", + "container_path": "/app/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "seerr" + ], + "stop_order": [ + "seerr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Seerr WebUI", + "scheme": "http", + "port": 5055, + "path": "/", + "source": "upstream-documentation" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "references": [ + "https://docs.seerr.dev/getting-started/docker/" + ], + "startup_healthcheck": { + "scheme": "http", + "port": 5055, + "path": "/api/v1/settings/public", + "timeout_seconds": 360 + }, + "security": { + "options": { + "no_new_privileges": true, + "drop_all_capabilities": true + } + }, + "adaptations": [ + "Compose cap_drop ALL -> lxc.cap.drop reset and lxc.cap.keep none; no-new-privileges -> lxc.no_new_privs 1." + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "cap_drop", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/stremio.json b/oci/catalog/curated/stremio.json new file mode 100644 index 00000000..63288656 --- /dev/null +++ b/oci/catalog/curated/stremio.json @@ -0,0 +1,475 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-stremio", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Stremio" + }, + "tagline": { + "en_US": "Stremio is a modern media center that gives you the freedom to watch everything you want." + }, + "description": { + "en_US": "Stremio offers a secure, modern and seamless entertainment experience. With its easy-to-use interface and diverse content library, including 4K HDR support, users can enjoy their favorite movies and TV shows across all their devices. And with its commitment to security, Stremio is the ultimate choice for a worry-free, high-quality streaming experience." + }, + "category": "media", + "category_label": "Media & Streaming", + "author": "Andreas Tsarida / Stremio", + "developer": "Andreas Tsarida / Stremio", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8080, + "path": "/" + }, + "website": "https://www.stremio.com", + "documentation": null, + "repository": "https://hub.docker.com/r/tsaridas/stremio-docker", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "tsaridas", + "repository": "https://hub.docker.com/r/tsaridas/stremio-docker", + "revision": "690dd7312cee4d8974f44c7e64b4f49281f1144eead8c5df5ada9436a2479fdd", + "image_repository_url": "https://hub.docker.com/r/tsaridas/stremio-docker", + "readme_pushed_at": "2026-09-11T10:43:22Z", + "compose_sha256": "690dd7312cee4d8974f44c7e64b4f49281f1144eead8c5df5ada9436a2479fdd", + "generated_at": "2026-09-13T15:35:03+00:00" + }, + "container_contract": { + "service_name": "stremio", + "container_name": "stremio", + "image": { + "reference": "tsaridas/stremio-docker:latest", + "registry": "docker.io", + "repository": "tsaridas/stremio-docker", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "NO_CORS", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "AUTO_SERVER_URL", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/root/.stremio-server", + "compose_source_example": "/DATA/AppData/$AppID/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 11470, + "published_example": 11470, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8080, + "published_example": 8100, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: stremio\nservices:\n stremio:\n container_name: stremio\n deploy:\n resources:\n limits:\n memory: 1024M\n environment:\n - NO_CORS=1\n - AUTO_SERVER_URL=1\n devices:\n - /dev/dri:/dev/dri\n image: tsaridas/stremio-docker:latest\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/config\n target: /root/.stremio-server\n ports:\n - target: 11470\n published: '11470'\n protocol: tcp\n - target: 8080\n published: '8100'\n protocol: tcp\n restart: unless-stopped\n network_mode: bridge\n privileged: false\n" + }, + "compose_stack": { + "project_name": "stremio", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "stremio", + "service_count": 1, + "services": [ + { + "name": "stremio", + "image": "tsaridas/stremio-docker:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "container_name": "stremio", + "deploy": { + "resources": { + "limits": { + "memory": "1024M" + } + } + }, + "environment": [ + "NO_CORS=1", + "AUTO_SERVER_URL=1" + ], + "devices": [ + "/dev/dri:/dev/dri" + ], + "image": "tsaridas/stremio-docker:latest", + "volumes": [ + { + "type": "bind", + "source": "/DATA/AppData/$AppID/config", + "target": "/root/.stremio-server" + } + ], + "ports": [ + { + "target": 11470, + "published": "11470", + "protocol": "tcp" + }, + { + "target": 8080, + "published": "8100", + "protocol": "tcp" + } + ], + "restart": "unless-stopped", + "network_mode": "bridge", + "privileged": false + } + } + ], + "top_level": { + "name": "stremio" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "stremio-volume-0", + "service": "stremio", + "container_path": "/root/.stremio-server", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "stremio" + ], + "stop_order": [ + "stremio" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8080, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Stremio", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ] + } + ] + } + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", + "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "pending-per-application" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "catalog": { + "replaces_discovered_ids": [ + "stremio" + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "shm_size", + "stdin_open", + "stop_grace_period", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/suite-arr.json b/oci/catalog/curated/suite-arr.json new file mode 100644 index 00000000..c8c07c54 --- /dev/null +++ b/oci/catalog/curated/suite-arr.json @@ -0,0 +1,335 @@ +{ + "schema_version": "0.3.0", + "kind": "proxmenux.oci-template", + "id": "image-suite-arr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Suite Arr" + }, + "tagline": { + "en_US": "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all)." + }, + "description": { + "en_US": "Selectable Arr media suite with shared content and a choice of Jellyfin, Plex or Emby." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "LinuxServer.io", + "developer": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/prowlarr-icon.png", + "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/prowlarr-banner.png", + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 9696, + "path": "/" + }, + "website": "https://github.com/Prowlarr/Prowlarr", + "documentation": "https://docs.linuxserver.io/images/docker-prowlarr/", + "repository": "https://github.com/linuxserver/docker-prowlarr", + "tips": [], + "mini_changelog": [ + { + "date": "2026-07-04", + "note": "Rebase to Alpine 3.24." + }, + { + "date": "2026-01-15", + "note": "Rebase to Alpine 3.23." + }, + { + "date": "2025-07-05", + "note": "Rebase Alpine 3.22." + }, + { + "date": "2024-12-23", + "note": "Rebase Alpine 3.21." + }, + { + "date": "2024-05-31", + "note": "Rebase Alpine 3.20." + } + ], + "display_version": null, + "updated_at": "2026-07-04" + }, + "source": { + "provider": "linuxserver.io", + "repository": "https://github.com/linuxserver/docker-prowlarr", + "default_branch": "main", + "revision": "c03ac6b60306a6fadb7f5e491ddf3a6a665113df", + "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-prowlarr/c03ac6b60306a6fadb7f5e491ddf3a6a665113df/README.md", + "readme_pushed_at": "2026-09-09T08:40:12Z", + "compose_sha256": "9fd00779e731abb238dbcf64fdb61209138468b0d70457c1fb0e842546eb994d", + "generated_at": "2026-09-12T14:37:34+00:00" + }, + "container_contract": { + "service_name": "prowlarr", + "container_name": "prowlarr", + "image": { + "reference": "lscr.io/linuxserver/prowlarr:latest", + "registry": "lscr.io", + "repository": "lscr.io/linuxserver/prowlarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/prowlarr/data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + } + ], + "ports": [ + { + "container_port": 9696, + "published_example": 9696, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "---\nservices:\n prowlarr:\n image: lscr.io/linuxserver/prowlarr:latest\n container_name: prowlarr\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n volumes:\n - /path/to/prowlarr/data:/config\n ports:\n - 9696:9696\n restart: unless-stopped\n" + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", + "validation": "pending-per-application" + }, + { + "id": "compose-environment-overlay", + "upstream_behavior": "Compose environment values override OCI image environment values.", + "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", + "reason": "PVE imports image Env automatically; Compose values still need to override it.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" + }, + { + "id": "stop-grace-period", + "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", + "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", + "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", + "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "stack_driver": "arr-suite", + "applications": [ + "prowlarr", + "sonarr", + "radarr", + "qbittorrent", + "lidarr", + "bazarr", + "sabnzbd", + "seerr", + "unpackerr" + ], + "automatic_configuration": [ + "media-root-folders", + "prowlarr-application-connections", + "optional-qbittorrent-persistent-login", + "qbittorrent-download-paths-and-categories", + "sonarr-radarr-download-client-connections" + ], + "manual_configuration": [ + "arr-authentication-and-indexers", + "quality-profiles", + "media-server-account-and-library-selection", + "seerr-initial-account-and-connections", + "bazarr-providers-and-arr-connections", + "sabnzbd-usenet-provider-and-arr-client-connection" + ], + "references": [ + "https://wiki.servarr.com/docker-guide", + "https://docs.linuxserver.io/images/docker-prowlarr/", + "https://docs.linuxserver.io/images/docker-sonarr/", + "https://docs.linuxserver.io/images/docker-radarr/", + "https://docs.linuxserver.io/images/docker-qbittorrent/", + "https://github.com/qbittorrent/qBittorrent/wiki/WebUI-API-(qBittorrent-5.0)" + ], + "qbittorrent": { + "optional": true, + "username": "admin", + "password": "asked-at-installation", + "persistent_config": "/config/qBittorrent/qBittorrent.conf", + "shared_data": "/data", + "categories": { + "sonarr": "tv", + "radarr": "movies" + }, + "vpn": false, + "starts_downloads": false, + "runtime_validation": "pending", + "authentication": { + "legacy": "HTTP 200, Ok., SID cookie", + "5.2": "HTTP 204, empty body, QBT_SID_ cookie", + "verification": "Authenticated GET app/preferences before changing settings" + }, + "path_verification": "Compare absolute paths ignoring trailing slash; require temp_path_enabled=true." + }, + "default_applications": [ + "prowlarr", + "sonarr", + "radarr", + "qbittorrent" + ], + "media_players": { + "choices": [ + "jellyfin", + "plex", + "emby", + "none" + ], + "default": "jellyfin", + "selection": "single" + }, + "shared_content": { + "host_directory": "ask-at-installation", + "create_if_missing": true, + "container_path": "/data", + "directories": [ + "downloads/tv", + "downloads/movies", + "downloads/music", + "downloads/incomplete", + "downloads/usenet", + "downloads/usenet-incomplete", + "media/movies", + "media/series", + "media/music" + ], + "backup": false, + "private_configuration": "managed-volume-with-backup" + }, + "vpn": { + "status": "deferred", + "enabled": false + }, + "lifecycle": { + "mode": "independent", + "primary_service": null, + "hookscript": false, + "onboot": "user-choice-applied-to-each-lxc", + "initial_start": "installer-only-for-first-configuration" + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "container_name", + "environment", + "image", + "ports", + "restart", + "stop_grace_period", + "volumes" + ], + "untranslated_blockers": [], + "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-resolved-architecture-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/tandoor.json b/oci/catalog/curated/tandoor.json new file mode 100644 index 00000000..4bc70d5c --- /dev/null +++ b/oci/catalog/curated/tandoor.json @@ -0,0 +1,544 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-tandoor", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Tandoor Recipes" + }, + "tagline": { + "en_US": "Self-hosted recipe manager and meal planner" + }, + "description": { + "en_US": "Official Tandoor Recipes deployment with its integrated web server and an isolated PostgreSQL dependency." + }, + "category": "productivity", + "category_label": "Productivity & Workflows", + "author": "Tandoor Recipes", + "developer": "Tandoor Recipes", + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://tandoor.dev/", + "documentation": "https://docs.tandoor.dev/install/docker/", + "repository": "https://github.com/vabene1111/recipes", + "tips": [ + "The installation creates PostgreSQL in a dependent LXC without access to the home network.", + "ALLOWED_HOSTS uses * by default to allow first access through the DHCP IP; restrict it to your domains when publishing the service.", + "The installer creates a superuser with the official Django command and shows its password only once." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": "2026-09-11" + }, + "source": { + "provider": "tandoor", + "repository": "https://github.com/vabene1111/recipes", + "default_branch": "develop", + "revision": "a5179f8a76fd865182df1b62ea212914027e4069", + "readme_raw_url": "https://raw.githubusercontent.com/vabene1111/recipes/develop/docs/install/docker/plain/docker-compose.yml", + "image_repository_url": "https://hub.docker.com/r/vabene1111/recipes", + "readme_pushed_at": "2026-09-11T23:39:42Z", + "compose_sha256": "4a996ad284a638050d3997793d9bc273d8591dd5d2284d2ada619c6441a3fd97", + "generated_at": "2026-09-14T15:24:39+00:00" + }, + "container_contract": { + "service_name": "web_recipes", + "container_name": "tandoor", + "image": { + "reference": "vabene1111/recipes:latest", + "registry": "docker.io", + "repository": "vabene1111/recipes", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "SECRET_KEY", + "example": "${GENERATED_SECRET_KEY}", + "required": true, + "sensitive": true, + "source": "upstream-documentation" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "ALLOWED_HOSTS", + "example": "*", + "required": true, + "sensitive": false, + "source": "upstream-documentation" + }, + { + "name": "DB_ENGINE", + "example": "django.db.backends.postgresql", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_HOST", + "example": "db_recipes", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_DB", + "example": "djangodb", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_PORT", + "example": "5432", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_USER", + "example": "djangouser", + "required": true, + "sensitive": false, + "source": "upstream-documentation", + "prompt_user": false + }, + { + "name": "POSTGRES_PASSWORD", + "example": "${GENERATED_DB_PASSWORD}", + "required": true, + "sensitive": true, + "source": "upstream-documentation", + "prompt_user": false + } + ], + "volumes": [ + { + "id": "staticfiles", + "container_path": "/opt/recipes/staticfiles", + "compose_source_example": "staticfiles", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 2 + } + }, + { + "id": "mediafiles", + "container_path": "/opt/recipes/mediafiles", + "compose_source_example": "mediafiles", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 16 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 80, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [ + { + "name": "db_recipes", + "image": "postgres:16-alpine" + } + ], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n db_recipes:\n restart: always\n image: postgres:16-alpine\n volumes:\n - ./postgresql:/var/lib/postgresql/data\n env_file:\n - ./.env\n\n web_recipes:\n restart: always\n image: vabene1111/recipes\n env_file:\n - ./.env\n ports:\n - 80:80\n volumes:\n - staticfiles:/opt/recipes/staticfiles\n - ./mediafiles:/opt/recipes/mediafiles\n depends_on:\n - db_recipes\n\nvolumes:\n staticfiles:\n" + }, + "compose_stack": { + "project_name": "tandoor", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "web_recipes", + "service_count": 2, + "services": [ + { + "name": "db_recipes", + "image": "postgres:16-alpine", + "is_main": false, + "role": "dependency", + "vmid_offset": 1, + "depends_on": [], + "frontend_network": false, + "private_network": true, + "compose": { + "image": "postgres:16-alpine", + "restart": "unless-stopped", + "volumes": [ + "postgresql:/var/lib/postgresql/data" + ] + } + }, + { + "name": "web_recipes", + "image": "vabene1111/recipes:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [ + "db_recipes" + ], + "frontend_network": true, + "private_network": true, + "compose": { + "image": "vabene1111/recipes:latest", + "restart": "unless-stopped", + "ports": [ + "80:80" + ], + "volumes": [ + "staticfiles:/opt/recipes/staticfiles", + "mediafiles:/opt/recipes/mediafiles" + ], + "env_file": [ + ".env" + ] + } + } + ], + "top_level": { + "volumes": { + "postgresql": {}, + "staticfiles": {}, + "mediafiles": {} + } + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": true, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-replace-compose-service-dns", + "dependency_external_access": "disabled", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "web-staticfiles", + "service": "web_recipes", + "container_path": "/opt/recipes/staticfiles", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + }, + { + "id": "web-mediafiles", + "service": "web_recipes", + "container_path": "/opt/recipes/mediafiles", + "mode": "user-selectable", + "user_selectable": true, + "backup": true, + "shared_with_other_lxc": true, + "default": "managed-volume", + "installation_choice": [ + "managed-volume", + "host-bind" + ] + }, + { + "id": "database-data", + "service": "db_recipes", + "container_path": "/var/lib/postgresql/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false + } + ], + "orchestration": { + "reserve_vmids_atomically": 2, + "start_order": [ + "db_recipes", + "web_recipes" + ], + "stop_order": [ + "web_recipes", + "db_recipes" + ], + "dependency_readiness": "healthcheck-before-application", + "rollback_on_failure": "remove-all-new-lxc-and-new-managed-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "timezone", + "allowed_hosts", + "admin_username", + "admin_email" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_addresses", + "generated_secrets", + "dependency_start_and_stop_order", + "generated_admin_password" + ], + "generated_secrets": [ + { + "id": "database-password", + "strategy": "generate-cryptographically-random-at-install" + }, + { + "id": "secret-key", + "strategy": "generate-cryptographically-random-at-install" + }, + { + "id": "admin-password", + "strategy": "generate-cryptographically-random-at-install" + } + ] + } + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "catalog": { + "replaces_discovered_ids": [ + "tandoor" + ] + }, + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 2048, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "compose-dependency-network", + "upstream_behavior": "Docker Compose provides service-name DNS and an isolated application network.", + "native_lxc_behavior": "The installer creates or reuses an automatically allocated Proxmox bridge and injects private static addresses.", + "reason": "Each Compose service becomes one native OCI LXC.", + "behavioral_impact": "PostgreSQL is reachable only on the private bridge.", + "validation": "pending-clean-install" + }, + { + "id": "generated-compose-secrets", + "upstream_behavior": "The administrator supplies SECRET_KEY and POSTGRES_PASSWORD in the Compose .env file.", + "native_lxc_behavior": "The installer generates both values and injects them as native LXC runtime environment variables.", + "reason": "Fresh installations must not reuse published secrets.", + "behavioral_impact": "Secrets remain in the protected Proxmox LXC configuration like other Compose environment variables.", + "validation": "pending-clean-install" + } + ], + "installer_profile": {}, + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "source_requests_relaxed_confinement": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "The reviewed Tandoor stack does not require a privileged LXC." + }, + "laboratory_contract": { + "requirements": { + "proxmox_min_version": "9.1", + "minimum_host_memory_mb": 3072, + "recommended_host_memory_mb": 4096, + "database_storage": { + "must_be_local": true, + "network_filesystem_allowed": false + } + }, + "defaults": { + "stack_name": "tandoor", + "timezone": "Europe/Madrid", + "allowed_hosts": "*", + "rootfs_storage": "local-lvm", + "application_storage": "local-lvm", + "database_storage": "local-lvm", + "shared_media_root": "/mnt/oci-shared/tandoor/${stack_name}/mediafiles", + "static_volume_size_gb": 2, + "media_volume_size_gb": 16, + "database_volume_size_gb": 8, + "frontend_network": { + "bridge": "vmbr0", + "ipv4_mode": "dhcp", + "firewall": true, + "host_managed": true + }, + "private_network": { + "mode": "create-if-missing", + "bridge": "vmbr10", + "subnet": "10.77.0.0/24", + "host_address": "10.77.0.1/24", + "application_address": "10.77.0.40/24", + "database_address": "10.77.0.41/24", + "nat": false + }, + "application": { + "admin_username": "admin", + "admin_email": "admin@example.local" + } + }, + "installer_contract": { + "deployment_kind": "tandoor-two-lxc-stack", + "reserve_vmids_atomically": 2, + "generated_secrets": [ + "POSTGRES_PASSWORD", + "SECRET_KEY", + "DJANGO_SUPERUSER_PASSWORD" + ], + "private_volumes": { + "staticfiles": "/opt/recipes/staticfiles", + "database": "/var/lib/postgresql/data" + }, + "media_volume": { + "container_path": "/opt/recipes/mediafiles", + "choices": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume" + }, + "start_order": [ + "db_recipes", + "web_recipes" + ], + "stop_order": [ + "web_recipes", + "db_recipes" + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "depends_on", + "env_file", + "environment", + "image", + "ports", + "restart", + "volumes" + ], + "untranslated_blockers": [], + "policy": "The official two-service PostgreSQL Compose has a dedicated native LXC orchestrator; clean-install validation remains pending." + }, + "first_run": { + "endpoints": [ + { + "label": "Tandoor WebUI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "official-compose" + } + ], + "credentials": [ + { + "label": "Generated Tandoor administrator", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "proxmenux-installer-generated", + "retrieval": null + } + ] + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-images-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-image-digests", + "automatic_unattended_updates": false, + "dependency_lifecycle": { + "implementation": "proxmox-hookscript", + "trigger": "main-lxc-pre-start", + "starts_stopped_dependencies": true, + "waits_for_dependency_healthchecks": true, + "stops_dependencies_with_main": false, + "persistent_contract": "/etc/pve/priv/proxmenux-stack-.json", + "runtime_owner": "proxmox-ve" + } + } +} diff --git a/oci/catalog/curated/tasmoadmin.json b/oci/catalog/curated/tasmoadmin.json new file mode 100644 index 00000000..7974be0b --- /dev/null +++ b/oci/catalog/curated/tasmoadmin.json @@ -0,0 +1,423 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-tasmoadmin", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "TasmoAdmin" + }, + "tagline": { + "en_US": "Web interface to manage devices running Tasmota firmware." + }, + "description": { + "en_US": "TasmoAdmin manages the devices on a network that run Tasmota firmware, from one web interface: it finds them by scanning an address range or through an MQTT broker, shows their sensor readings and configuration, sends commands and backs them up, and updates the firmware of several devices at once, downloading the release from the Tasmota OTA site." + }, + "category": "smarthome", + "category_label": "IoT & Smart Home", + "author": "TasmoAdmin", + "developer": null, + "icon": "https://raw.githubusercontent.com/TasmoAdmin/TasmoAdmin/master/assets/logo.svg", + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 80, + "path": "/" + }, + "website": "https://github.com/TasmoAdmin/TasmoAdmin", + "documentation": "https://github.com/TasmoAdmin/TasmoAdmin/wiki", + "repository": "https://github.com/TasmoAdmin/TasmoAdmin", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "tasmoadmin", + "repository": "https://github.com/TasmoAdmin/TasmoAdmin", + "revision": "b23a54b3b9c99a558103b6216939ec66c3fcada84622980bb2eaef3e2a186168", + "image_repository_url": "https://ghcr.io/tasmoadmin/tasmoadmin", + "readme_pushed_at": "", + "compose_sha256": "b23a54b3b9c99a558103b6216939ec66c3fcada84622980bb2eaef3e2a186168", + "generated_at": "2026-09-21T11:26:57+00:00" + }, + "container_contract": { + "service_name": "tasmoadmin", + "container_name": "tasmoadmin", + "image": { + "reference": "ghcr.io/tasmoadmin/tasmoadmin:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/tasmoadmin/tasmoadmin", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "environment": [], + "volumes": [ + { + "id": "volume-0", + "container_path": "/data", + "compose_source_example": "tasmoadmin_data", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 80, + "published_example": 8080, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "services:\n tasmoadmin:\n image: ghcr.io/tasmoadmin/tasmoadmin:latest\n container_name: tasmoadmin\n restart: unless-stopped\n volumes:\n - tasmoadmin_data:/data\n ports:\n - 8080:80\n" + }, + "compose_stack": { + "project_name": "tasmoadmin", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "tasmoadmin", + "service_count": 1, + "services": [ + { + "name": "tasmoadmin", + "image": "ghcr.io/tasmoadmin/tasmoadmin:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/tasmoadmin/tasmoadmin:latest", + "container_name": "tasmoadmin", + "restart": "unless-stopped", + "volumes": [ + "tasmoadmin_data:/data" + ], + "ports": [ + "8080:80" + ] + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "tasmoadmin-volume-0", + "service": "tasmoadmin", + "container_path": "/data", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "tasmoadmin" + ], + "stop_order": [ + "tasmoadmin" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 80, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "volume_preparations": [ + { + "container_path": "/data", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ] + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "mem_limit", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "ulimits", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/tdarr.json b/oci/catalog/curated/tdarr.json new file mode 100644 index 00000000..670674fd --- /dev/null +++ b/oci/catalog/curated/tdarr.json @@ -0,0 +1,684 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-tdarr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Tdarr" + }, + "tagline": { + "en_US": "Media library transcoding and health checking, with an internal worker node." + }, + "description": { + "en_US": "Tdarr keeps a media library in the formats and codecs chosen for it: it scans the library, checks the health of every file and transcodes what does not match, with its own worker node inside the container. The web interface is on port 8265 and the node listens on 8266." + }, + "category": "media", + "category_label": "Media", + "author": "HaveAGitGat", + "developer": null, + "icon": "https://raw.githubusercontent.com/HaveAGitGat/Tdarr/master/assets/tdarr.png", + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": 8265, + "path": "/" + }, + "website": "https://tdarr.io", + "documentation": "https://docs.tdarr.io", + "repository": "https://github.com/HaveAGitGat/Tdarr", + "tips": [], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "haveagitgat", + "repository": "https://github.com/HaveAGitGat/Tdarr", + "revision": "25b13a5fbad493ebda195d1aa1aa893ba737a2b774690ca02dbb976733cd1146", + "image_repository_url": "https://ghcr.io/haveagitgat/tdarr", + "readme_pushed_at": "", + "compose_sha256": "25b13a5fbad493ebda195d1aa1aa893ba737a2b774690ca02dbb976733cd1146", + "generated_at": "2026-09-20T14:43:04+00:00" + }, + "container_contract": { + "service_name": "tdarr", + "container_name": "tdarr", + "image": { + "reference": "ghcr.io/haveagitgat/tdarr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/haveagitgat/tdarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "serverIP", + "example": "0.0.0.0", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "serverPort", + "example": "8266", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "webUIPort", + "example": "8265", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "internalNode", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "inContainer", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + }, + { + "name": "ffmpegVersion", + "example": "7", + "required": false, + "sensitive": false, + "source": "docker-compose", + "prompt": "FFmpeg version the node uses (7 by default)" + }, + { + "name": "nodeName", + "example": "InternalNode", + "required": false, + "sensitive": false, + "source": "docker-compose", + "prompt": "Name of the internal worker node" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/app/configs", + "compose_source_example": "./configs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/app/logs", + "compose_source_example": "./logs", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/media", + "compose_source_example": "./media", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-3", + "container_path": "/temp", + "compose_source_example": "./temp", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [ + { + "container_port": 8265, + "published_example": 8265, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }, + { + "container_port": 8266, + "published_example": 8266, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ], + "related_services": [], + "restart": null, + "stop_grace_period": null, + "original_compose": "services:\n tdarr:\n image: ghcr.io/haveagitgat/tdarr:latest\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - serverIP=0.0.0.0\n - serverPort=8266\n - webUIPort=8265\n - internalNode=true\n - inContainer=true\n - ffmpegVersion=7\n - nodeName=InternalNode\n ports:\n - 8265:8265\n - 8266:8266\n volumes:\n - ./configs:/app/configs\n - ./logs:/app/logs\n - ./media:/media\n - ./temp:/temp\n" + }, + "compose_stack": { + "project_name": "tdarr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "tdarr", + "service_count": 1, + "services": [ + { + "name": "tdarr", + "image": "ghcr.io/haveagitgat/tdarr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "ghcr.io/haveagitgat/tdarr:latest", + "environment": [ + "PUID=1000", + "PGID=1000", + "TZ=Etc/UTC", + "serverIP=0.0.0.0", + "serverPort=8266", + "webUIPort=8265", + "internalNode=true", + "inContainer=true", + "ffmpegVersion=7", + "nodeName=InternalNode" + ], + "ports": [ + "8265:8265", + "8266:8266" + ], + "volumes": [ + "./configs:/app/configs", + "./logs:/app/logs", + "./media:/media", + "./temp:/temp" + ] + } + } + ], + "top_level": {}, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "tdarr-volume-0", + "service": "tdarr", + "container_path": "/app/configs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "tdarr-volume-1", + "service": "tdarr", + "container_path": "/app/logs", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "tdarr-volume-2", + "service": "tdarr", + "container_path": "/media", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "tdarr-volume-3", + "service": "tdarr", + "container_path": "/temp", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "tdarr" + ], + "stop_order": [ + "tdarr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 8265, + "path": "/", + "source": "compose-metadata" + } + ], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 4, + "memory_mb": 4096, + "swap_mb": 1024, + "rootfs_size_gb": 12, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ], + "installer_profile": { + "startup_healthcheck": { + "scheme": "http", + "port": 8265, + "path": "/", + "timeout_seconds": 300, + "request_timeout_seconds": 10, + "stability_seconds": 5, + "verify_tls": false + }, + "hardware_acceleration": { + "prompt": "Hardware acceleration for Tdarr", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "image": { + "reference": "ghcr.io/haveagitgat/tdarr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/haveagitgat/tdarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API and QSV)", + "image": { + "reference": "ghcr.io/haveagitgat/tdarr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/haveagitgat/tdarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "gpu-render", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "kind": "character-device", + "container_path_strategy": "same-as-host", + "drm_vendor_ids": [ + "0x8086", + "0x1002" + ] + } + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "architectures": [ + "amd64" + ], + "image": { + "reference": "ghcr.io/haveagitgat/tdarr:latest", + "registry": "ghcr.io", + "repository": "ghcr.io/haveagitgat/tdarr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-written-reference-to-architecture-digest-at-install" + }, + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-video", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + }, + { + "name": "NVIDIA_DRIVER_CAPABILITIES", + "value": "compute,video,utility" + } + ] + } + ] + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "mem_limit", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "ulimits", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Official image of the project, taken from its own Compose file. The library and the transcode cache are offered as a container volume or as a host directory; the configuration and the logs stay in container volumes." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/curated/unpackerr.json b/oci/catalog/curated/unpackerr.json new file mode 100644 index 00000000..aaead7d1 --- /dev/null +++ b/oci/catalog/curated/unpackerr.json @@ -0,0 +1,436 @@ +{ + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": "image-unpackerr", + "status": "generated-unvalidated", + "catalog_ui": { + "title": { + "en_US": "Unpackerr" + }, + "tagline": { + "en_US": "" + }, + "description": { + "en_US": "Background archive extraction for Arr download queues. No web interface." + }, + "category": "arr", + "category_label": "*Arr Suite", + "author": "golift", + "developer": null, + "icon": null, + "thumbnail": null, + "screenshots": [], + "architectures": [ + "amd64", + "arm64" + ], + "launch": { + "scheme": "http", + "port": null, + "path": "/" + }, + "website": "https://unpackerr.zip/docs/install/docker/", + "documentation": "https://unpackerr.zip/docs/install/docker/", + "repository": "https://github.com/Unpackerr/unpackerr", + "tips": [ + "Service without a web interface. Configure the Arr connections through the official UN_* variables or /config/unpackerr.conf." + ], + "mini_changelog": [], + "display_version": null, + "updated_at": null + }, + "source": { + "provider": "golift", + "repository": "https://github.com/Unpackerr/unpackerr", + "revision": "5909b075d14d21eaa4e76a2fc53528e2e33066821e06ff0f984479ee57731eac", + "image_repository_url": "https://hub.docker.com/r/golift/unpackerr", + "readme_pushed_at": "", + "compose_sha256": "5909b075d14d21eaa4e76a2fc53528e2e33066821e06ff0f984479ee57731eac", + "generated_at": "2026-09-14T17:13:55+00:00" + }, + "container_contract": { + "service_name": "unpackerr", + "container_name": "unpackerr", + "image": { + "reference": "golift/unpackerr:latest", + "registry": "docker.io", + "repository": "golift/unpackerr", + "tag": "latest", + "digest": null, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" + }, + "environment": [ + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 4 + } + }, + { + "id": "volume-1", + "container_path": "/data", + "compose_source_example": "/path/to/downloads", + "read_only": false, + "required": false, + "installation_choice": [ + "managed-volume", + "host-bind", + "skip" + ], + "default": "skip", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ], + "ports": [], + "related_services": [], + "restart": "unless-stopped", + "stop_grace_period": null, + "original_compose": "name: unpackerr\nservices:\n unpackerr:\n image: golift/unpackerr:latest\n user: 1000:1000\n environment:\n TZ: Europe/Madrid\n volumes:\n - /path/to/config:/config\n - /path/to/downloads:/data\n restart: unless-stopped\n" + }, + "compose_stack": { + "project_name": "unpackerr", + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": "unpackerr", + "service_count": 1, + "services": [ + { + "name": "unpackerr", + "image": "golift/unpackerr:latest", + "is_main": true, + "role": "frontend", + "vmid_offset": 0, + "depends_on": [], + "frontend_network": true, + "private_network": false, + "compose": { + "image": "golift/unpackerr:latest", + "user": "1000:1000", + "environment": { + "TZ": "Europe/Madrid" + }, + "volumes": [ + "/path/to/config:/config", + "/path/to/downloads:/data" + ], + "restart": "unless-stopped" + } + } + ], + "top_level": { + "name": "unpackerr" + }, + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": false, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": false + }, + "storage": [ + { + "id": "unpackerr-volume-0", + "service": "unpackerr", + "container_path": "/config", + "mode": "managed-volume", + "user_selectable": false, + "backup": true, + "shared_with_other_lxc": false, + "source_path": null, + "source_path_prompt": null + }, + { + "id": "unpackerr-volume-1", + "service": "unpackerr", + "container_path": "/data", + "mode": "host-bind", + "user_selectable": true, + "backup": false, + "shared_with_other_lxc": true, + "source_path": null, + "source_path_prompt": "Host directory for unpackerr:/data" + } + ], + "orchestration": { + "reserve_vmids_atomically": 1, + "start_order": [ + "unpackerr" + ], + "stop_order": [ + "unpackerr" + ], + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode" + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order" + ], + "generated_secrets": [] + } + }, + "first_run": { + "endpoints": [], + "credentials": [] + }, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": true, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": 1024, + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": true, + "host_managed_network": true, + "onboot": false, + "features": [ + "nesting=1" + ], + "shutdown_timeout_seconds": 30 + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image" + }, + "installer_profile": { + "runtime": { + "user": "1000:1000" + }, + "references": [ + "https://unpackerr.zip/docs/install/docker/" + ] + }, + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application" + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application" + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application" + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "native-equivalent" + }, + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": "pending-per-application" + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": "not-requested-by-compose" + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": "not-requested-by-compose" + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": "not-requested-by-compose" + } + ] + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "supported_compose_keys": [ + "cap_add", + "command", + "container_name", + "cpu_shares", + "deploy", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "network_mode", + "networks", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "user", + "volumes", + "working_dir" + ], + "untranslated_blockers": [], + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending" + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": null, + "resolved_digest": null, + "image_version_label": null, + "image_created": null + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": false + } +} diff --git a/oci/catalog/exclusions.json b/oci/catalog/exclusions.json new file mode 100644 index 00000000..ae03bd2a --- /dev/null +++ b/oci/catalog/exclusions.json @@ -0,0 +1,29 @@ +{ + "schema_version": "0.1.0", + "imported_applications": [ + { + "id": "jellyfin", + "reason": "same-image-hardware-profile-merged-into-linuxserver-jellyfin" + }, + { + "id": "jellyfin-nvidia", + "reason": "same-image-hardware-profile-merged-into-linuxserver-jellyfin" + }, + { + "id": "plex", + "reason": "same-image-hardware-profile-merged-into-linuxserver-plex" + }, + { + "id": "plex-nvidia", + "reason": "same-image-hardware-profile-merged-into-linuxserver-plex" + }, + { + "id": "ollama-nvidia", + "reason": "same-image-hardware-profile-merged-into-ollama" + }, + { + "id": "index-tts-nvidia", + "reason": "same-image-hardware-profile-merged-into-index-tts" + } + ] +} diff --git a/oci/catalog/generation-report-curated.json b/oci/catalog/generation-report-curated.json new file mode 100644 index 00000000..a08de59b --- /dev/null +++ b/oci/catalog/generation-report-curated.json @@ -0,0 +1,27 @@ +{ + "generated": [ + "emby-official", + "fileflows", + "frigate", + "haos-one", + "immich", + "jdownloader", + "jellyfin-official", + "llamacpp", + "makemkv", + "mkvtoolnix", + "nextcloud-stack", + "open-webui", + "open-webui-cuda", + "open-webui-ollama", + "paperless-ngx", + "plex-official", + "rclone", + "roonserver", + "stremio", + "tandoor" + ], + "generated_count": 20, + "failed": [], + "failed_count": 0 +} diff --git a/oci/catalog/generation-report-imported.json b/oci/catalog/generation-report-imported.json new file mode 100644 index 00000000..b0c8af97 --- /dev/null +++ b/oci/catalog/generation-report-imported.json @@ -0,0 +1,158 @@ +{ + "generated": [ + "2fauth", + "actualbudget", + "adguard-home", + "adminer", + "albyhub", + "alist", + "alist-sync", + "anaconda3", + "anythingllm", + "archivebox", + "audiobookshelf", + "autobrr", + "beaverhabittracker", + "bentopdf", + "blinko", + "chatbot-ui", + "chatgpt-next-web", + "cloudbeaver", + "cloudflared", + "clumoove", + "convertx", + "copyparty", + "crafty", + "databag", + "ddns-go", + "ddns-updater", + "deepseek-ocr-nvidia", + "dify", + "docmost", + "downtify", + "dsh-harness", + "emby-nvidia", + "emby-vaapi", + "embystat", + "emulatorjs", + "esphome", + "etherpad", + "excalidraw", + "filedrop", + "fileflows-vaapi", + "firefly", + "flaresolverr", + "flowise", + "freshrss-official", + "gateway-go", + "gitea", + "glances", + "gopeed", + "grafana", + "handbrake-jlesage", + "hermes", + "holoplay", + "homeassistant-official", + "homebridge", + "hugo", + "index-tts", + "index-tts-nvidia", + "jellyfin-nvidia", + "jellyfin-vaapi", + "jellyseerr", + "jenkins", + "karakeep", + "kavita-jvmilazz0", + "komga", + "label-studio", + "langflow", + "librechat", + "libredb-studio", + "linkwarden", + "llama-factory-nvidia", + "llamacpp-vaapi", + "logseq", + "lucky", + "lyrionmusicserver", + "maybe", + "medusa-official", + "memos", + "mineos-node", + "mongodb", + "mongodb4", + "monica-official", + "motioneye", + "myspeed", + "n8n", + "navidrome", + "netbird", + "netdata", + "netronome", + "nextcloud-official", + "nginxproxymanager", + "node-red", + "nzbfast", + "ollama", + "ollama-nvidia", + "open-webui-ollama-nvidia", + "openclaw", + "openhab", + "openhands", + "openlist", + "openspeedtest", + "opodsync", + "overseerr", + "pdfding", + "peanut", + "petio", + "photoprism", + "pihole", + "pinchflat", + "pingvin-share", + "playit-agent", + "plex-nvidia", + "plex-vaapi", + "pocketbase", + "podfetch", + "portainer", + "postgresql", + "psitransfer", + "qbittorrent-hotio", + "qui", + "ragflow", + "rdtclient", + "readarr", + "retroarch-inglebard", + "romm", + "roonserver-vaapi", + "sickchill", + "siyuan-note", + "snapdrop", + "snapotter", + "stable-diffusion-webui-nvidia", + "stremio-vaapi", + "sure", + "swingmusic", + "tailscale", + "taskingai", + "teable", + "threadfin", + "trilium", + "turbodiffusion-nvidia", + "twingate-connector", + "unifi-controller", + "uptimekuma", + "v2raya", + "vaultwarden", + "virt-manager", + "vocechat", + "wallabag", + "webdav", + "weknora", + "wg-easy", + "ztnet" + ], + "generated_count": 151, + "failed": [], + "failed_count": 0 +} diff --git a/oci/catalog/generation-report.json b/oci/catalog/generation-report.json new file mode 100644 index 00000000..19495d0c --- /dev/null +++ b/oci/catalog/generation-report.json @@ -0,0 +1,206 @@ +{ + "generated": [ + "adguardhome-sync", + "airsonic-advanced", + "altus", + "apprise-api", + "ardour", + "audacity", + "azahar", + "babybuddy", + "bambustudio", + "bazarr", + "beets", + "bitcoin-knots", + "blade-of-agony", + "blender", + "boinc", + "bookstack", + "brave", + "budge", + "calibre", + "calibre-web", + "calligra", + "changedetection.io", + "chrome", + "chromium", + "code-server", + "cops", + "cura", + "darktable", + "davos", + "ddclient", + "deluge", + "digikam", + "diskover", + "dogwalk", + "dokuwiki", + "dolphin", + "doplarr", + "doplarr_rs", + "dosbox-staging", + "doublecommander", + "duckdns", + "duckstation", + "duplicati", + "eden", + "emby", + "fail2ban", + "faster-whisper", + "ferdium", + "filezilla", + "firefox", + "flexget", + "flycast", + "foldingathome", + "freecad", + "freshrss", + "gimp", + "github-desktop", + "gitqlient", + "grav", + "grocy", + "gzdoom", + "habridge", + "handbrake", + "healthchecks", + "hedgedoc", + "heimdall", + "helium", + "hishtory-server", + "homeassistant", + "htpcmanager", + "inkscape", + "intellij-idea", + "jackett", + "jellyfin", + "joplin", + "kali-linux", + "kasm", + "kavita", + "kdenlive", + "keepassxc", + "kicad", + "kimai", + "kometa", + "krita", + "lazylibrarian", + "ldap-auth", + "libreoffice", + "librespeed", + "librewolf", + "lidarr", + "limnoria", + "lm-studio", + "lollypop", + "luanti", + "lychee", + "mame", + "manyfold", + "mariadb", + "mastodon", + "mediaelch", + "medusa", + "melonds", + "minisatip", + "monica", + "msedge", + "mstream", + "mullvad-browser", + "mylar3", + "mysql-workbench", + "netbox", + "nextcloud", + "nginx", + "ngircd", + "nzbget", + "nzbhydra2", + "obsidian", + "ombi", + "onlyoffice", + "openshot", + "openssh-server", + "openvscode-server", + "opera", + "orcaslicer", + "oscam", + "pairdrop", + "pcsx2", + "pelorus", + "phpmyadmin", + "pidgin", + "piper", + "piwigo", + "planka", + "plex", + "ppsspp", + "projectsend", + "prowlarr", + "pwndrop", + "pycharm", + "pydio-cells", + "pyload-ng", + "qbittorrent", + "qdirstat", + "radarr", + "raneto", + "rawtherapee", + "remmina", + "resilio-sync", + "retroarch", + "rpcs3", + "rsnapshot", + "rustdesk", + "sabnzbd", + "scummvm", + "sealskin", + "shadps4", + "shotcut", + "sickgear", + "signal", + "smokeping", + "sonarr", + "speedtest-tracker", + "spotube", + "sqlitebrowser", + "steam", + "swag", + "synclounge", + "syncthing", + "syslog-ng", + "tautulli", + "telegram", + "thelounge", + "thunderbird", + "transmission", + "tvheadend", + "ubooquity", + "ungoogled-chromium", + "unifi-network-application", + "vivaldi", + "vlc", + "vscode", + "vscodium", + "vscodium-web", + "webcord", + "webgrabplus", + "webstation", + "webtop", + "weixin", + "wikijs", + "winegui", + "wireguard", + "wireshark", + "wps-office", + "xbackbone", + "xemu", + "yaak", + "your_spotify", + "zen", + "znc", + "zotero" + ], + "generated_count": 199, + "failed": [], + "failed_count": 0 +} diff --git a/oci/catalog/index.json b/oci/catalog/index.json new file mode 100644 index 00000000..532b8ef5 --- /dev/null +++ b/oci/catalog/index.json @@ -0,0 +1,12622 @@ +{ + "schema_version": "0.2.0", + "kind": "proxmenux.oci-catalog-index", + "provider": "multiple-container-images", + "generated_at": "2026-09-13T21:11:40+00:00", + "applications": [ + { + "id": "2fauth", + "source_app_id": "2fauth", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "2FAuth", + "repository": "https://hub.docker.com/r/2fauth/2fauth", + "description": "2FAuth is a web based self-hosted alternative to One Time Passcode (OTP) generators like Google Authenticator, designed for both mobile and desktop.", + "website": "https://2fauth.app", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/2FAuth/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-03", + "main_image": "2fauth/2fauth:latest", + "category": "security", + "category_label": "Authentication & Security", + "template": "apps/2fauth.json", + "template_status": "laboratory-validated", + "content_hash": "31670274bb80ae4fd49723d781b12df06cd14eb82c707f71cee836f3cb62fb96", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "actualbudget", + "source_app_id": "actualbudget", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Actual Budget", + "repository": "https://hub.docker.com/r/actualbudget/actual-server", + "description": "Actual Budget is a fast, privacy-focused finance management app using local-first envelope budgeting, ensuring full control over data. Its intuitive interface supports offline use, with multi-device sync and optional end-to-end encryption, delivering a secure, efficient financial management experience, ideal for users seeking clear financial oversight.\n\nThe app's core features include envelope budgeting based on real income, rapid transaction handling, and intuitive financial reporting. It helps users track spending and monitor monthly savings clearly, with a streamlined transaction editor for quick categorization, split transactions, and transfers. Built-in net worth and cash flow reports provide financial insights, and a custom report engine allows tailored reports for specific needs. Undo and redo functionality ensures users can easily correct mistakes, maintaining operational flexibility.\n\nIt integrates bank accounts via goCardless (EU/UK) or SimpleFIN (US/Canada), supports multi-device syncing for data privacy, and enables importing transaction data from YNAB4, nYNAB, and QIF, OFX, QFX, CAMT.053, CSV files, simplifying migration of existing financial records. Community documentation enhances usability, and the app's simple operation and high flexibility deliver a modern finance management solution.\n\n**Key Features:**\n- Privacy-focused personal finance management\n- Envelope budgeting methodology\n- Multi-device synchronization\n- End-to-end encryption support\n- Local data ownership\n- Fast and responsive interface\n- Open source and self-hosted\n- Bank account synchronization\n- Detailed financial reporting\n- Budget tracking and analysis\n\n**Learn More:**\n- [Actual Budget Official Website](https://actualbudget.org)\n- [Actual Budget GitHub Repository](https://github.com/actualbudget/actual)\n- [Actual Budget Docker Image](https://hub.docker.com/r/actualbudget/actual-server)\n", + "website": "https://actualbudget.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/ActualBudget/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-08", + "main_image": "actualbudget/actual-server:latest", + "category": "finance", + "category_label": "Finance & Budgeting", + "template": "apps/actualbudget.json", + "template_status": "generated-unvalidated", + "content_hash": "7d1715f645a9171dbf1978ab4c6184185b024dee6c9126417005086ed7d1b07c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "adguard-home", + "source_app_id": "adguard-home", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "AdGuard Home", + "repository": "https://hub.docker.com/r/adguard/adguardhome", + "description": "Difference from Traditional Ad Blockers. Unlike traditional ad-blocking plugins that work only on individual devices, AdGuard Home offers a network-wide solution. By setting it up, you can block ads and trackers across all your home devices without needing to install any additional software on each device. This means comprehensive protection with minimal effort.\n\nHow AdGuard Home Works and How to Use It. AdGuard Home functions as a DNS server that reroutes tracking domains to a \"black hole,\" effectively preventing your devices from connecting to these servers. This blocks ads and trackers not only on your computer but also on your smartphone and smart home devices. To start using AdGuard Home, deploy it on your device, then change the DNS address assigned by DHCP on your router to the IP address of your AdGuard Home server.\n\nBenefits of Deploying AdGuard Home on self-hosted server Private Cloud. Deploying AdGuard Home on a self-hosted server device simplifies network-wide ad and tracker blocking, providing a seamless and secure browsing experience for all your home devices. With self-hosted server, you gain the flexibility to monitor network activity and create custom filtering rules tailored to your needs.\n", + "website": "https://adguard.com/en/adguard-home/overview.html", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/AdGuardHome/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-09-01", + "main_image": "adguard/adguardhome:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/adguard-home.json", + "template_status": "generated-unvalidated", + "content_hash": "7437656a5d50e8fbd642bfc2973a4942334114c4d6a6b4e7b424396f147d76c1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "adguardhome-sync", + "provider": "linuxserver.io", + "title": "Adguardhome Sync", + "repository_name": "docker-adguardhome-sync", + "repository": "https://github.com/linuxserver/docker-adguardhome-sync", + "description": "Adguardhome-sync is a tool to synchronize AdGuardHome config to replica instances.", + "website": "https://github.com/bakito/adguardhome-sync/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/adguardhome-sync-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-13T14:34:44Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/adguardhome-sync:latest", + "category": "adblock", + "category_label": "Adblock & DNS", + "template": "apps/adguardhome-sync.json", + "template_status": "laboratory-validated", + "content_hash": "e7e8cff6b839004bca3259a9bd6d5471cca6462c59111835407447b8e5c9b807", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "adminer", + "source_app_id": "adminer", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Adminer", + "repository": "https://hub.docker.com/_/adminer", + "description": "Adminer (formerly phpMinAdmin) is a full-featured database management tool written in PHP. Conversely to phpMyAdmin, it consist of a single file ready to deploy to the target server. Adminer is available for MySQL, PostgreSQL, SQLite, MS SQL, Oracle, Firebird, SimpleDB, Elasticsearch and MongoDB.", + "website": "https://www.adminer.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Adminer/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-02-08", + "main_image": "adminer:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/adminer.json", + "template_status": "generated-unvalidated", + "content_hash": "1ec8eae75e1a952b5cc2b8f3516cb8cc5eec2226d0ddad566b7e244e10cc38d4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "airsonic-advanced", + "provider": "linuxserver.io", + "title": "Airsonic Advanced", + "repository_name": "docker-airsonic-advanced", + "repository": "https://github.com/linuxserver/docker-airsonic-advanced", + "description": "Airsonic-advanced is a free, web-based media streamer, providing ubiquitious access to your music. Use it to share your music with friends, or to listen to your own music while at work. You can stream to multiple players simultaneously, for instance to one player in your kitchen and another in your living room.", + "website": "https://github.com/kagemomiji/airsonic-advanced", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/airsonic-advanced-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T12:53:04Z", + "updated_at": "2024-12-21", + "main_image": "lscr.io/linuxserver/airsonic-advanced:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/airsonic-advanced.json", + "template_status": "generated-unvalidated", + "content_hash": "2ac8e1b0163d81c7c542119501b0cbd950b558f712409db48e1d52d2da95e158", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "albyhub", + "source_app_id": "albyhub", + "provider": "getalby", + "template_family": "imported-compose", + "variant": null, + "title": "Alby Hub \u2728", + "repository": "https://ghcr.io/getalby/hub", + "description": "Alby Hub is an open-source, self-custodial Bitcoin Lightning wallet, with the easiest-to-use Lightning Network node for everyone.\nWhether you're an individual, creator, or developer, Alby Hub is your centre for seamless Bitcoin payments.\nEffortlessly connect to a variety of apps like the Alby Browser Extension or Alby Go mobile app, create sub-wallets for family and friends, and take full control of your funds\u2014all within an intuitive interface and developer-ready APIs.\n\n**USEFUL LINKS**\n- [Source Repository](https://github.com/getAlby/hub)\n- [Support](https://support.getalby.com/)\n- [Marketing Site](https://albyhub.com/)\n- [Community of users and developers](https://discord.getalby.com)\n- [Feedback Board, feature requests, bug reports[(https://feedback.getalby.com)\n", + "website": "https://albyhub.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/AlbyHub/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-11", + "main_image": "ghcr.io/getalby/hub:latest", + "category": "finance", + "category_label": "Finance & Budgeting", + "template": "apps/albyhub.json", + "template_status": "laboratory-validated", + "content_hash": "b90d4c2f6787337a534fbbe2f3232a0bcdf3eb0511bec192a19aff6920371799", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "alist", + "source_app_id": "alist", + "provider": "xhofe", + "template_family": "imported-compose", + "variant": null, + "title": "Alist", + "repository": "https://hub.docker.com/r/xhofe/alist", + "description": "Alist transforms how you manage and access your files at home, whether on your TV, phone, or any other device. Unlike traditional cloud storage, Alist offers a unified experience across multiple platforms, making it a breeze to keep your media and documents at your fingertips.\n\nWith features like easy installation, support for multiple storage providers (local, Aliyundrive, Onedrive, Google Drive), WebDAV support, dark mode, protected routes with password authentication, file previews for videos, audio, office files, PDFs, code, images, package and batch downloads, single sign-on, offline torrent downloads, file encryption, and additional tools like a text editor and Cloudflare workers proxy, Alist ensures a seamless and secure file management experience.\n\nDeploying Alist on private cloud devices like self-hosted server brings unmatched convenience with multi-device access, ensuring your files are always within reach and secure, no matter where you are.\n", + "website": "https://alistgo.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Alist/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-11-22", + "main_image": "xhofe/alist:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/alist.json", + "template_status": "laboratory-validated", + "content_hash": "6e35ed8af6576b616fcecb1daec77dc5a94858f0b29eaae5ec3c63e6cc341148", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "alist-sync", + "source_app_id": "alist-sync", + "provider": "xjxjin", + "template_family": "imported-compose", + "variant": null, + "title": "Alist-Sync", + "repository": "https://hub.docker.com/r/xjxjin/alist-sync", + "description": "Alist-Sync is a storage synchronization tool based on the Web interface. It can achieve data synchronization and mutual backup among multiple network disks, and also has practical functions such as multi-task management, scheduled synchronization and difference handling.\n", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Alist-Sync/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-03-15", + "main_image": "xjxjin/alist-sync:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/alist-sync.json", + "template_status": "generated-unvalidated", + "content_hash": "63630a665e638c0b978abd7a64185e54c9c2ef603110525bbcff1734d6445ba4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "altus", + "provider": "linuxserver.io", + "title": "Altus", + "repository_name": "docker-altus", + "repository": "https://github.com/linuxserver/docker-altus", + "description": "Altus is an Electron-based WhatsApp client with themes and multiple account support.", + "website": "https://github.com/amanharwara/altus", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/altus-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T08:16:57Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/altus:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/altus.json", + "template_status": "generated-unvalidated", + "content_hash": "2cd8310e6f13ff9ec6e2cb6fe853ae36f51a622fb197a5b5f53079d04a053dac", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "amule", + "provider": "ngosang", + "template_family": "curated-profile", + "title": "aMule", + "repository": "https://github.com/ngosang/docker-amule", + "description": "aMule is a multi-platform client for the ED2K file sharing network and based on the windows client eMule. aMule started in August 2003, as a fork of xMule, which is a fork of lMule.", + "website": "https://github.com/amule-org/amule", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-18", + "main_image": "ngosang/amule:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/amule.json", + "template": "apps/amule.json", + "template_status": "laboratory-validated", + "hidden": false, + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "content_hash": "bcef3879a8ce1483332eed56175200e8822600aaa6dfcb73a6e1b32209981229" + }, + { + "id": "anaconda3", + "source_app_id": "anaconda3", + "provider": "continuumio", + "template_family": "imported-compose", + "variant": null, + "title": "Anaconda3", + "repository": "https://hub.docker.com/r/continuumio/anaconda3", + "description": "Your machine learning Env work with Jupyter Lab", + "website": "https://www.anaconda.com", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/Anaconda3/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-10-31", + "main_image": "continuumio/anaconda3:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/anaconda3.json", + "template_status": "generated-unvalidated", + "content_hash": "95b0cd1c6adc5cabef717c7d948b4878e6ff0f392cd46305e06c99e71bf644cd", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "anythingllm", + "source_app_id": "anythingllm", + "provider": "mintplexlabs", + "template_family": "imported-compose", + "variant": null, + "title": "AnythingLLM", + "repository": "https://hub.docker.com/r/mintplexlabs/anythingllm", + "description": "AnythingLLM is the easiest to use, all-in-one AI application that can do RAG, AI Agents, and much more with no code or infrastructure headaches.", + "website": "https://anythingllm.com", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/AnythingLLM/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-19", + "main_image": "mintplexlabs/anythingllm:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/anythingllm.json", + "template_status": "generated-unvalidated", + "content_hash": "545fd1cfbf25c18795fe8062ba3e6b3a16ab859c2f1d6dc8c3be77da6b069908", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "apprise-api", + "provider": "linuxserver.io", + "title": "Apprise Api", + "repository_name": "docker-apprise-api", + "repository": "https://github.com/linuxserver/docker-apprise-api", + "description": "Apprise-api Takes advantage of Apprise through your network with a user-friendly API.", + "website": "https://github.com/caronc/apprise-api", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/apprise-api-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-07T15:41:13Z", + "updated_at": "2025-07-05", + "main_image": "lscr.io/linuxserver/apprise-api:latest", + "category": "messaging", + "category_label": "Messaging & Queues", + "template": "apps/apprise-api.json", + "template_status": "generated-unvalidated", + "content_hash": "48ea1b2eea8523bcb7ab2c03e5e9129ba46effa855528c171414270c2f3b4366", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "archivebox", + "source_app_id": "archivebox", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "ArchiveBox", + "repository": "https://hub.docker.com/r/archivebox/archivebox", + "description": "ArchiveBox is a powerful, self-hosted internet archiving solution that allows you to create your own personal archive of web pages, PDFs, videos, and more. It functions as a personal internet archive, saving content in multiple formats for long-term preservation.\n\nThe system consists of multiple components:\n- **ArchiveBox**: The main application providing the web interface and archiving capabilities\n- **Sonic**: A fast search backend for full-text search across archived content\n- **ArchiveBox Scheduler**: A background service for scheduled archiving tasks\n- **NoVNC**: A web-based VNC client for browser-based archiving\n\n**Key Features:**\n- Save web pages in multiple formats (HTML, PDF, screenshots, etc.)\n- Full-text search across all archived content\n- Scheduled archiving of websites and RSS feeds\n- Browser-based archiving with NoVNC\n- User authentication and access control\n- Extract and save media files (videos, audio, PDFs, etc.)\n\n**Learn More:**\n- [ArchiveBox Official Website](https://archivebox.io)\n- [ArchiveBox GitHub Repository](https://github.com/ArchiveBox/ArchiveBox)\n- [ArchiveBox Documentation](https://github.com/ArchiveBox/ArchiveBox/wiki)\n", + "website": "https://archivebox.io", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/ArchiveBox/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "archivebox/archivebox:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/archivebox.json", + "template_status": "generated-review-required", + "content_hash": "29e6c737e7fb7c17083032349b168c457d941ee144022c675b9294e6ece3426a", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:archivebox_scheduler:compose-key:depends_on", + "service:archivebox_sonic:compose-key:expose", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "ardour", + "provider": "linuxserver.io", + "title": "Ardour", + "repository_name": "docker-ardour", + "repository": "https://github.com/linuxserver/docker-ardour", + "description": "Ardour is an open source, collaborative effort of a worldwide team including musicians, programmers, and professional recording engineers.", + "website": "https://ardour.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ardour-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-06-25T16:52:13Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/ardour:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/ardour.json", + "template_status": "generated-unvalidated", + "content_hash": "736ed876a5b5766151c3b7e0634cdd7db3b15c628f8787fe953a146b602b0c73", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "audacity", + "provider": "linuxserver.io", + "title": "Audacity", + "repository_name": "docker-audacity", + "repository": "https://github.com/linuxserver/docker-audacity", + "description": "Audacity is an easy-to-use, multi-track audio editor and recorder. Developed by a group of volunteers as open source.", + "website": "https://www.audacityteam.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/audacity-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "main", + "pushed_at": "2026-09-08T09:28:27Z", + "updated_at": "2026-04-29", + "main_image": "lscr.io/linuxserver/audacity:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/audacity.json", + "template_status": "generated-unvalidated", + "content_hash": "78fd3449e7fd71b6441c4eb3936b2151c7f9a56139ca0d598e737fdeb0af3b4c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "audiobookshelf", + "source_app_id": "audiobookshelf", + "provider": "advplyr", + "template_family": "imported-compose", + "variant": null, + "title": "Audiobookshelf", + "repository": "https://ghcr.io/advplyr/audiobookshelf", + "description": "Audiobookshelf is a self-hosted media server designed for managing and streaming audiobooks, podcasts, and e-books, offering a secure and flexible solution for personal media libraries. Its lightweight architecture and intuitive Web interface (available as a Progressive Web App, PWA) enable seamless access from any browser, while beta Android and iOS apps support offline listening, catering to privacy-focused media enthusiasts.\n\nThe app supports on-the-fly streaming of all audio formats and provides robust management tools, including automatic metadata and cover art fetching from multiple sources, bulk drag-and-drop uploads for books and podcasts, and chapter editing with lookup via the Audnexus API. Users can search and subscribe to podcasts with auto-downloading episodes or manage content via open RSS feeds. It supports multi-user access with custom permissions, ensuring individual playback progress syncs across devices. Additionally, it offers audio tools (like merging files into m4b or embedding metadata) and experimental e-book support (epub, pdf, cbr, cbz), with the ability to send e-books to devices like Kindle.\n\nIt automatically detects library updates, eliminating manual rescans, and includes daily automated backups to safeguard metadata. Chromecast support (on Web and Android apps) enhances streaming capabilities, while an active community provides support documentation for continuous improvements. Whether for personal collections or family sharing, the app's intuitive interface and versatile features deliver a modern media management platform, meeting diverse needs.\n\n**Key Features:**\n- Multi-user support w/ custom permissions\n- Keeps progress per user and syncs across devices\n- Lookup and apply metadata and cover art from several providers\n- Audiobook chapter editor w/ chapter lookup\n- Audiobook tools: Embed metadata in audio files & merge multiple audio files to a single m4b\n- Search and add podcasts to download episodes w/ auto-download\n- Open RSS feeds for audiobooks and podcast episodes\n- Backups with automated backup scheduling\n- Basic ebook support and ereader (epub, pdf, cbr, cbz) + send to device (i.e. Kindle)\n\n**Learn More:**\n- [Audiobookshelf Official Website](https://audiobookshelf.org)\n- [Audiobookshelf GitHub Repository](https://github.com/advplyr/audiobookshelf)\n", + "website": "https://audiobookshelf.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Audiobookshelf/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-17", + "main_image": "ghcr.io/advplyr/audiobookshelf:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/audiobookshelf.json", + "template_status": "generated-unvalidated", + "content_hash": "a4541cd70188b88a63920500676ca49bd2778a0f51098751c22f20610a6f208f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "autobrr", + "source_app_id": "autobrr", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Autobrr", + "repository": "https://ghcr.io/autobrr/autobrr", + "description": "Autobrr is the modern download automation tool for torrents and usenet. With inspiration and ideas from tools like trackarr, autodl-irssi and flexget we built one tool that can do it all, and then some.", + "website": "https://autobrr.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Autobrr/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-17", + "main_image": "ghcr.io/autobrr/autobrr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/autobrr.json", + "template_status": "generated-unvalidated", + "content_hash": "65257f5fb4779a0bb71324151b77a36ca47f4111500a1b8aad8a6b831f3fc8f5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "azahar", + "provider": "linuxserver.io", + "title": "Azahar", + "repository_name": "docker-azahar", + "repository": "https://github.com/linuxserver/docker-azahar", + "description": "Azahar is an open-source 3DS emulator based on Citra.", + "website": "https://azahar-emu.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/azahar-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T04:47:01Z", + "updated_at": "2026-03-05", + "main_image": "lscr.io/linuxserver/azahar:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/azahar.json", + "template_status": "generated-unvalidated", + "content_hash": "6d5a5c7f43ac8f35a586dbedeb6312eeaf5c028ac407b43c141c8fbf517820ff", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "babybuddy", + "provider": "linuxserver.io", + "title": "Babybuddy", + "repository_name": "docker-babybuddy", + "repository": "https://github.com/linuxserver/docker-babybuddy", + "description": "Babybuddy is a buddy for babies! Helps caregivers track sleep, feedings, diaper changes, tummy time and more to learn about and predict baby's needs without (as much) guess work.", + "website": "https://github.com/babybuddy/babybuddy", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/babybuddy-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-12T14:42:32Z", + "updated_at": "2026-07-21", + "main_image": "lscr.io/linuxserver/babybuddy:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/babybuddy.json", + "template_status": "generated-unvalidated", + "content_hash": "a79a6cd2ec035041d411b2921cfe72189e452e738df1d957308f27b8f7fb2b6b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "bambustudio", + "provider": "linuxserver.io", + "title": "Bambustudio", + "repository_name": "docker-bambustudio", + "repository": "https://github.com/linuxserver/docker-bambustudio", + "description": "Bambu Studio is an open-source, cutting-edge, feature-rich slicing software. It contains project-based workflows, systematically optimized slicing algorithms, and an easy-to-use graphical interface, bringing users an incredibly smooth printing experience.", + "website": "https://bambulab.com/en/download/studio", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bambustudio-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T09:25:40Z", + "updated_at": "2026-04-29", + "main_image": "lscr.io/linuxserver/bambustudio:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/bambustudio.json", + "template_status": "generated-unvalidated", + "content_hash": "b8cc49805839eec5d60652cecb7f3b672b76e74d4b9c5851b7c891d4c707cd8b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "bazarr", + "provider": "linuxserver.io", + "title": "Bazarr", + "repository_name": "docker-bazarr", + "repository": "https://github.com/linuxserver/docker-bazarr", + "description": "Bazarr is a companion application to Sonarr and Radarr. It can manage and download subtitles based on your requirements. You define your preferences by TV show or movie and Bazarr takes care of everything for you.", + "website": "https://www.bazarr.media/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bazarr-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T16:32:13Z", + "updated_at": "2025-12-28", + "main_image": "lscr.io/linuxserver/bazarr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/bazarr.json", + "template_status": "generated-unvalidated", + "content_hash": "d897ec3641bf34903e19ef702073af43c2ae19a637b22a5a26b08682e9580a60", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "beaverhabittracker", + "source_app_id": "beaverhabittracker", + "provider": "daya0576", + "template_family": "imported-compose", + "variant": null, + "title": "BeaverHabitTracker", + "repository": "https://hub.docker.com/r/daya0576/beaverhabits", + "description": "Beaver Habit Tracker is a self-hosted habit tracking tool designed for users who want to effortlessly monitor daily behaviors without the stress of goal-setting. Its intuitive Web interface offers a pressure-free tracking experience, ideal for those focused on behavior observation and personal growth.\n\nThe tool's core features include goal-free habit tracking and a minimalist interface. It allows users to log multiple habits easily, without focusing on streaks or targets, and provides simple visualizations to understand behavior patterns. Users can add daily notes to record specific activities or reflections, with a smooth, low-effort interface.\n\nIt uses a self-hosted approach, ensuring data privacy and full control, with a lightweight, efficient design requiring minimal server resources. Users can manually reorder habits for an optimized experience. The tool's stress-free observation and intuitive operation help users gradually improve habits, delivering a modern habit management solution.\n\n**Key Features:**\n- Goal-free habit tracking focused on awareness, not achievement\n- Clean, minimalist interface for effortless daily logging\n- Lightweight and efficient, requiring minimal server resources\n- Simple visualizations to understand behavior patterns\n- Daily notes for recording activities or reflections\n\n**Learn More:**\n- [Beaver Habit Tracker Official Website](https://beaverhabits.com/)\n- [Beaver Habit Tracker GitHub](https://github.com/daya0576/beaverhabits)\n", + "website": "https://beaverhabits.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/BeaverHabitTracker/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-20", + "main_image": "daya0576/beaverhabits:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/beaverhabittracker.json", + "template_status": "generated-unvalidated", + "content_hash": "73ee3d95e26d072616ffc33c02db8d52024546effbf4776ceadddf8e00ce66ed", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "beets", + "provider": "linuxserver.io", + "title": "Beets", + "repository_name": "docker-beets", + "repository": "https://github.com/linuxserver/docker-beets", + "description": "Beets is a music library manager and not, for the most part, a music player. It does include a simple player plugin and an experimental Web-based player, but it generally leaves actual sound-reproduction to specialized tools.", + "website": "http://beets.io/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/beets-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T17:00:11Z", + "updated_at": "2026-02-01", + "main_image": "lscr.io/linuxserver/beets:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/beets.json", + "template_status": "generated-unvalidated", + "content_hash": "beaa3825b76040e57e7f81fa3ff15561a3dcbeda4b13c705a5b3a5506d6c4193", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "bentopdf", + "source_app_id": "bentopdf", + "provider": "alam00000", + "template_family": "imported-compose", + "variant": null, + "title": "BentoPDF", + "repository": "https://ghcr.io/alam00000/bentopdf-simple", + "description": "**Your PDFs never leave your device.** BentoPDF is a privacy-first PDF toolkit that runs entirely in your browser. Every merge, split, conversion, and edit happens locally on your machine \u2014 no file is ever uploaded to a server. More than 50 tools are bundled into one clean, fast, ad-free interface.\n\n**One app for every PDF job.** Organize and edit your documents (merge, split, reorder, rotate, crop, watermark, page numbers, redaction, annotations and forms), convert to and from PDF (images, Word, Excel, PowerPoint, EPUB, Markdown and more), run OCR, and secure your files with compression, encryption, digital signatures, and metadata cleanup.\n\n**Made for your private cloud.** Self-hosting BentoPDF on a private cloud device like self-hosted server gives your whole household or team a single, ad-free PDF workshop on hardware you control \u2014 fast over the local network, with your documents staying private by design.\n", + "website": "https://bentopdf.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/BentoPDF/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-09-03", + "main_image": "ghcr.io/alam00000/bentopdf-simple:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/bentopdf.json", + "template_status": "generated-unvalidated", + "content_hash": "eaa6ac9f7c1c92e623d7d60a96bc0c6e2237941b7d0381825d0763d4c2609bec", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "bitcoin-knots", + "provider": "linuxserver.io", + "title": "Bitcoin Knots", + "repository_name": "docker-bitcoin-knots", + "repository": "https://github.com/linuxserver/docker-bitcoin-knots", + "description": "Bitcoin Knots can be used as a desktop client for regular payments or as a full node server utility for merchants and other payment services.", + "website": "https://bitcoinknots.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bitcoin-knots-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T22:37:03Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/bitcoin-knots:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/bitcoin-knots.json", + "template_status": "generated-unvalidated", + "content_hash": "1df82e85d15c1bb90aba6121087b85d578cd9d500427de928b663d2ddbad4d7d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "blade-of-agony", + "provider": "linuxserver.io", + "title": "Blade Of Agony", + "repository_name": "docker-blade-of-agony", + "repository": "https://github.com/linuxserver/docker-blade-of-agony", + "description": "Wolfenstein: Blade of Agony is a story-driven WWII shooter inspired by Wolfenstein and Doom.", + "website": "https://boa.realm667.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/blade-of-agony-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T20:27:01Z", + "updated_at": "2026-03-26", + "main_image": "lscr.io/linuxserver/blade-of-agony:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/blade-of-agony.json", + "template_status": "generated-unvalidated", + "content_hash": "fb8c8dc4bfdf72ac202ee75e90f7102e9f2418b6a370cd6321af273b6bdc16e2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "blender", + "provider": "linuxserver.io", + "title": "Blender", + "repository_name": "docker-blender", + "repository": "https://github.com/linuxserver/docker-blender", + "description": "Blender is a free and open-source 3D computer graphics software toolset used for creating animated films, visual effects, art, 3D printed models, motion graphics, interactive 3D applications, virtual reality, and computer games. **This image does not support GPU rendering out of the box only accelerated workspace experience**", + "website": "https://www.blender.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/blender-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T18:27:11Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/blender:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/blender.json", + "template_status": "generated-unvalidated", + "content_hash": "8ec78837752083a858e6efba3daa6facc48ece115769b2659f93ca31bd5f49b5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "blinko", + "source_app_id": "blinko", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Blinko", + "repository": "https://hub.docker.com/r/blinkospace/blinko", + "description": "Blinko is an open-source personal knowledge management and information recording platform, focused on providing users with a lightweight, efficient, and scalable note-taking and knowledge organization experience. Through modular design and a modern technology stack, it enables users to quickly capture ideas, organize knowledge, and build their own information system.\n\nThe project emphasizes simplicity and customizability, supporting flexible combinations of various content types (text, tags, links, etc.), while its clear structured design helps users efficiently retrieve and connect information. Blinko also provides excellent extensibility, making it easy for developers to customize and enhance functionality according to their needs.\n\nIn practical use, Blinko balances usability and functionality, offering a smooth experience for daily note-taking, knowledge accumulation, or project document management - an ideal knowledge tool for long-term personal growth.\n\n**Main features:**\n\n- Lightweight note system for quick content recording and editing\n- Tags and structured organization to improve information retrieval efficiency\n- Support for multiple content types (text, links, etc.)\n- Extensible architecture for custom functionality and plugin development\n- Clean interface design focused on content rather than complex operations\n\n**Learn more:**\n\n- [Blinko GitHub](https://github.com/blinkospace/blinko)\n", + "website": "https://blinko.space/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Blinko/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "blinkospace/blinko:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/blinko.json", + "template_status": "generated-unvalidated", + "content_hash": "37aae02b1b7f699d27338aec1b622c7c234ffe4e2ce0f1c731f9f39eb6801e55", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "boinc", + "provider": "linuxserver.io", + "title": "Boinc", + "repository_name": "docker-boinc", + "repository": "https://github.com/linuxserver/docker-boinc", + "description": "BOINC is a platform for high-throughput computing on a large scale (thousands or millions of computers). It can be used for volunteer computing (using consumer devices) or grid computing (using organizational resources). It supports virtualized, parallel, and GPU-based applications.", + "website": "https://boinc.berkeley.edu/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/boinc-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T15:56:45Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/boinc:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/boinc.json", + "template_status": "generated-unvalidated", + "content_hash": "3cf3a1f1d92ba4953c138fa9856fa0d344504bdb8434990c0ba56c0cbd092db9", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "bookstack", + "provider": "linuxserver.io", + "title": "Bookstack", + "repository_name": "docker-bookstack", + "repository": "https://github.com/linuxserver/docker-bookstack", + "description": "Bookstack is a free and open source Wiki designed for creating beautiful documentation. Featuring a simple, but powerful WYSIWYG editor it allows for teams to create detailed and useful documentation with ease.", + "website": "https://codeberg.org/bookstack/bookstack", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/bookstack-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T21:32:19Z", + "updated_at": "2026-08-05", + "main_image": "lscr.io/linuxserver/bookstack:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/bookstack.json", + "template_status": "generated-unvalidated", + "content_hash": "7f23afaba8b32b5baa95396a405ce650d5ede362555e1bd3e0756ce18efafda5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "brave", + "provider": "linuxserver.io", + "title": "Brave", + "repository_name": "docker-brave", + "repository": "https://github.com/linuxserver/docker-brave", + "description": "The Brave browser is a fast, private and secure web browser for PC, Mac and mobile.", + "website": "https://brave.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/brave-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T17:22:56Z", + "updated_at": "2026-04-20", + "main_image": "lscr.io/linuxserver/brave:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/brave.json", + "template_status": "generated-unvalidated", + "content_hash": "9c11de8124e0962c9be80a78d927ca635d246ea5c1250172ea7065cdb00ea1b4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "budge", + "provider": "linuxserver.io", + "title": "Budge", + "repository_name": "docker-budge", + "repository": "https://github.com/linuxserver/docker-budge", + "description": "budge is an open source 'budgeting with envelopes' personal finance app.", + "website": "https://github.com/linuxserver/budge", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/budge-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-06-28T06:11:17Z", + "updated_at": "2024-06-06", + "main_image": "lscr.io/linuxserver/budge:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/budge.json", + "template_status": "generated-unvalidated", + "content_hash": "b770ea0c4b5f658c4e9d98ee6eb4334a232c72608bfab0fd015cfe6a17b0f791", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "calibre", + "provider": "linuxserver.io", + "title": "Calibre", + "repository_name": "docker-calibre", + "repository": "https://github.com/linuxserver/docker-calibre", + "description": "Calibre is a powerful and easy to use e-book manager. Users say it's outstanding and a must-have. It'll allow you to do nearly everything and it takes things a step beyond normal e-book software. It's also completely free and open source and great for both casual users and computer experts.", + "website": "https://calibre-ebook.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calibre-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T12:02:26Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/calibre:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/calibre.json", + "template_status": "generated-unvalidated", + "content_hash": "85b7d4d3798e697e5e9ac1541d9b2ccc27c01a3c9b1d4a742a6a0ef8038bd072", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": true, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "calibre-web", + "provider": "linuxserver.io", + "title": "Calibre Web", + "repository_name": "docker-calibre-web", + "repository": "https://github.com/linuxserver/docker-calibre-web", + "description": "Calibre-web is a web app providing a clean interface for browsing, reading and downloading eBooks using an existing Calibre database. It is also possible to integrate google drive and edit metadata and your calibre library through the app itself.", + "website": "https://github.com/janeczku/calibre-web", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calibre-web-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T04:59:16Z", + "updated_at": "2025-10-28", + "main_image": "lscr.io/linuxserver/calibre-web:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/calibre-web.json", + "template_status": "generated-unvalidated", + "content_hash": "4f258d503a2df1e227ccac6d9630de608b06b055236a1698090a6918ba250e2b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "calligra", + "provider": "linuxserver.io", + "title": "Calligra", + "repository_name": "docker-calligra", + "repository": "https://github.com/linuxserver/docker-calligra", + "description": "Calligra is an office and graphic art suite by KDE. It is available for desktop PCs, tablet computers, and smartphones. It contains applications for word processing, spreadsheets, presentation, vector graphics, and editing databases.", + "website": "https://calligra.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/calligra-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T14:06:16Z", + "updated_at": "2026-03-30", + "main_image": "lscr.io/linuxserver/calligra:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/calligra.json", + "template_status": "generated-unvalidated", + "content_hash": "afda96f6a3d65573e1ede68f13fb7ece6321b9637e2027ddc66b4b79b761ec39", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "changedetection.io", + "provider": "linuxserver.io", + "title": "Changedetection.Io", + "repository_name": "docker-changedetection.io", + "repository": "https://github.com/linuxserver/docker-changedetection.io", + "description": "Changedetection.io provides free, open-source web page monitoring, notification and change detection.", + "website": "https://github.com/dgtlmoon/changedetection.io", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/changedetection.io-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-10T10:18:30Z", + "updated_at": "2026-02-18", + "main_image": "lscr.io/linuxserver/changedetection.io:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/changedetection.io.json", + "template_status": "generated-unvalidated", + "content_hash": "12b84b068f8bcecfa0370ed3cdb06108b6c06326ce84a716d6b1066443c49670", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "chatbot-ui", + "source_app_id": "chatbot-ui", + "provider": "mckaywrigley", + "template_family": "imported-compose", + "variant": null, + "title": "Chatbot UI", + "repository": "https://ghcr.io/mckaywrigley/chatbot-ui", + "description": "Chatbot UI is an open source chat UI for AI models.", + "website": "https://www.chatbotui.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/ChatbotUI/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-01-04", + "main_image": "ghcr.io/mckaywrigley/chatbot-ui:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/chatbot-ui.json", + "template_status": "generated-unvalidated", + "content_hash": "113fbb9125527ac334c1d027733167c594a8b6dc2721e605a0d6705ff9326c61", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "chatgpt-next-web", + "source_app_id": "chatgpt-next-web", + "provider": "yidadaa", + "template_family": "imported-compose", + "variant": null, + "title": "ChatGPT Next Web", + "repository": "https://hub.docker.com/r/yidadaa/chatgpt-next-web", + "description": "An intelligent chat application based on ChatGPT, supports fast deployment, Markdown, beautiful UI, fluid response, privacy and security, and allows customization of preset roles for quick creation, sharing, and debugging of personalized conversations.", + "website": "https://nextchat.club", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/ChatGPT-Next-Web/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-07-29", + "main_image": "yidadaa/chatgpt-next-web:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/chatgpt-next-web.json", + "template_status": "generated-unvalidated", + "content_hash": "2017c467fa03002df0e23c36e2141939877c30f44b5d309d419c8ee2834d3912", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "chrome", + "provider": "linuxserver.io", + "title": "Chrome", + "repository_name": "docker-chrome", + "repository": "https://github.com/linuxserver/docker-chrome", + "description": "Chrome is the official web browser from Google, built to be fast, secure, and customizable.", + "website": "https://www.google.com/chrome/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/chrome-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T00:55:14Z", + "updated_at": "2026-07-27", + "main_image": "lscr.io/linuxserver/chrome:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/chrome.json", + "template_status": "generated-unvalidated", + "content_hash": "64a099762a3c52dc163c02761973977edee09538c9fe34a4bbe55e5b93ad7bb5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "chromium", + "provider": "linuxserver.io", + "title": "Chromium", + "repository_name": "docker-chromium", + "repository": "https://github.com/linuxserver/docker-chromium", + "description": "Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.", + "website": "https://www.chromium.org/chromium-projects/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/chromium-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T14:32:01Z", + "updated_at": "2026-07-04", + "main_image": "lscr.io/linuxserver/chromium:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/chromium.json", + "template_status": "generated-unvalidated", + "content_hash": "4626a1a3afafb2eea46a2223ff6facfc8a372c6fff546d0882f17071497f9d4b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "cloudbeaver", + "source_app_id": "cloudbeaver", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "CloudBeaver", + "repository": "https://hub.docker.com/r/dbeaver/cloudbeaver", + "description": "CloudBeaver is a web-based database GUI tool which provides rich web interface. You can use it to manage PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, DB2, Firebird, H2, Trino.", + "website": "https://dbeaver.com/download/cloudbeaver/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/CloudBeaver/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-18", + "main_image": "dbeaver/cloudbeaver:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/cloudbeaver.json", + "template_status": "generated-unvalidated", + "content_hash": "073c51f6bbb540cb92a54860e131531e89078865964dcf942ebecf2c9fa6a832", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "cloudflared", + "source_app_id": "cloudflared", + "provider": "wisdomsky", + "template_family": "imported-compose", + "variant": null, + "title": "Cloudflared", + "repository": "https://hub.docker.com/r/wisdomsky/cloudflared-web", + "description": "Cloudflare Tunnel offers an easy way to expose web servers securely to the internet, without opening up firewall ports and configuring ACLs. Cloudflare Tunnel also ensures requests route through Cloudflare before reaching the web server, so you can be sure attack traffic is stopped with Cloudflare\u2019s WAF and Unmetered DDoS mitigation, and authenticated with Access if you\u2019ve enabled those features for your account.\n\nThe software provides a seamless way to securely expose web servers to the internet without configuring firewall ports or access control lists (ACLs). All requests are routed through Cloudflare before reaching your web server, leveraging Cloudflare\u2019s Web Application Firewall (WAF) and unmetered DDoS mitigation to block attack traffic, with optional authentication via Cloudflare Access if enabled. With its intuitive Web interface and efficient tunnel management, this tool is the perfect solution for securely deploying web services.\n\n**Discover How to Connect self-hosted server to Cloudflare Tunnel**\nIntegrating self-hosted server with Cloudflare Tunnel allows you to securely expose local services to the internet without opening firewall ports, enabling seamless remote access. Below are two practical resources to guide you through the setup process:\n1. [**Cloudflare Official Tutorial**](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/get-started/create-remote-tunnel/): \n This tutorial provides detailed steps for creating and managing a Cloudflare Tunnel.\n2. [**Phiptech Practical Guide**](https://phiptech.com/how-to-setup-cloudflare-tunnel-and-expose-your-local-service-or-application/): \n This guide offers a concise, step-by-step walkthrough for setting up Cloudflare Tunnel on local devices like self-hosted server, with practical examples to help users easily expose services to the public internet.\n", + "website": "https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/get-started/create-remote-tunnel/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Cloudflared/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-16", + "main_image": "wisdomsky/cloudflared-web:latest", + "category": "web", + "category_label": "Webservers & Proxies", + "template": "apps/cloudflared.json", + "template_status": "generated-unvalidated", + "content_hash": "baf32b04617df02dca4979a2017ef0134d543bfd29579de8b9d57f163343cc42", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "clumoove", + "source_app_id": "clumoove", + "provider": "xxroxxerxx", + "template_family": "imported-compose", + "variant": null, + "title": "Clumoove", + "repository": "https://ghcr.io/xxroxxerxx/clumoove-frontend", + "description": "Clumoove is a modern, self-hosted cloud data migration and synchronization platform for files, calendars, and contacts.\n\nEasily connect, transfer, and synchronize data between cloud storage providers including Nextcloud, Google Drive, Dropbox, OneDrive, HiDrive, S3, WebDAV, SMB, SFTP, FTP, Immich, Seafile, Koofr, MEGA, and local storage.\n\nKey Features:\n- Zero-disk streaming transfers (no local temporary storage retention during migration)\n- Multi-threaded background migrations and cron-based synchronization schedules\n- Robust 3-way hash integrity verification & flexible conflict resolution\n- Integrated cloud file manager with multi-format previews and thumbnails\n- Multi-channel notification delivery (Gotify, ntfy, Telegram, Discord, Email)\n- Enterprise-grade security with AES-256-GCM encryption, TOTP 2FA, and audit logging\n", + "website": "https://clumoove.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Clumoove/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ghcr.io/xxroxxerxx/clumoove-frontend:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/clumoove.json", + "template_status": "generated-review-required", + "content_hash": "ffce6d14549c58c150c7282eae67f0ffb35929c80045def74a0d7aa2f6309cbe", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:api-backend:compose-key:depends_on", + "service:migration-worker:compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "code-server", + "provider": "linuxserver.io", + "title": "Code Server", + "repository_name": "docker-code-server", + "repository": "https://github.com/linuxserver/docker-code-server", + "description": "Code-server is VS Code running on a remote server, accessible through the browser.", + "website": "https://coder.com", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/code-server-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T05:22:23Z", + "updated_at": "2026-05-17", + "main_image": "lscr.io/linuxserver/code-server:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/code-server.json", + "template_status": "generated-unvalidated", + "content_hash": "b50f59e5d639cd53d9213e332de23935795fdbc30300d9d8630ba00bec320822", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "codeproject-ai", + "provider": "codeproject", + "template_family": "curated-profile", + "title": "CodeProject.AI Server", + "repository": "https://github.com/codeproject/CodeProject.AI-Server", + "description": "Official latest CPU image with persistent settings and modules. Initial CPU and Coral PCIe inference passed on Intel amd64. Coral module uses its persistent upstream EdgeTPU runtime via module-scoped LD_PRELOAD; missing JSON defaults preserve existing user settings. The TPU needs exclusive access. ARM and NVIDIA channels are not offered by this template; Failures observed on the AMD lab host remain unexplained; no blanket AMD incompatibility is inferred.", + "website": "https://github.com/codeproject/CodeProject.AI-Server", + "icon": null, + "architectures": [ + "amd64" + ], + "updated_at": "2026-09-16", + "main_image": "codeproject/ai-server:latest", + "category": "ai", + "category_label": "AI", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/codeproject-ai.json", + "template": "apps/codeproject-ai.json", + "template_status": "laboratory-validated", + "content_hash": "a520a1c0df3901f280458d944ded774252cd856dec736bb2011a908e4c6c9016", + "hidden": true, + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false + }, + { + "id": "convertx", + "source_app_id": "convertx", + "provider": "c4illin", + "template_family": "imported-compose", + "variant": null, + "title": "ConvertX", + "repository": "https://hub.docker.com/r/c4illin/convertx", + "description": "ConvertX is a self-hosted file conversion service that allows users to convert files between different formats through an intuitive web interface. It supports a wide range of file types including documents, images, videos, and audio files, making it a comprehensive solution for all your file conversion needs.\n\nThe service is designed with simplicity and ease of use in mind. Users can simply upload their files, select the desired output format, and let ConvertX handle the conversion process. The web interface provides a clean and user-friendly experience, with drag-and-drop support and batch conversion capabilities.\n\nConvertX runs entirely on your own infrastructure, ensuring that your files remain private and secure. There's no need to upload sensitive documents to third-party services, giving you full control over your data. The service is containerized for easy deployment and can be integrated into existing home server setups.\n\n**Key Features:**\n- Support for multiple file formats (documents, images, videos, audio)\n- Intuitive web interface with drag-and-drop support\n- Batch conversion capabilities\n- Self-hosted for privacy and security\n- Containerized for easy deployment\n- No file size limitations\n\n**Learn More:**\n- [ConvertX GitHub Repository](https://github.com/c4illin/convertx)\n", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/ConvertX/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-01-13", + "main_image": "c4illin/convertx:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/convertx.json", + "template_status": "generated-unvalidated", + "content_hash": "86d0231ff2c198ceeb0345011d8d91b28bd843db3fe58ac99ff99098ff631e6e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "cops", + "provider": "linuxserver.io", + "title": "Cops", + "repository_name": "docker-cops", + "repository": "https://github.com/linuxserver/docker-cops", + "description": "Cops by S\u00e9bastien Lucas, now maintained by MikesPub, stands for Calibre OPDS (and HTML) Php Server.", + "website": "https://github.com/mikespub-org/seblucas-cops", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/cops-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-06T22:40:35Z", + "updated_at": "2026-07-21", + "main_image": "lscr.io/linuxserver/cops:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/cops.json", + "template_status": "generated-unvalidated", + "content_hash": "81c6691f9a3a0d3dcad26dcc598ad86ce59ee45b613862a5886956a947d26629", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "copyparty", + "source_app_id": "copyparty", + "provider": "icewhaletech", + "template_family": "imported-compose", + "variant": null, + "title": "CopyParty", + "repository": "https://hub.docker.com/r/icewhaletech/copyparty", + "description": "**CopyParty** is a fast, privacy-focused file sharing server using a local-first, single-file architecture, ensuring full control over data without cloud dependencies. Its intuitive interface supports offline use, with cross-platform compatibility and multi-protocol access, delivering a secure, efficient file management experience, ideal for users seeking direct data ownership and a lightweight solution.\n\nThe app's core features include accelerated resumable uploads (via the up2k protocol), ensuring reliable large file transfers, and automatic deduplication to optimize storage. It helps users organize folders and media effortlessly, with a web-based file manager that includes a built-in media indexer and thumbnail generator for quick previews. Fine-grained permission controls allow specific user access rules. The \"upload-while-downloading\" feature enhances sharing efficiency, and the zero-dependency design ensures it runs on almost any hardware.\n\nIt integrates multiple access protocols, including HTTP, WebDAV, FTP, and TFTP, supporting connections from standard web browsers, dedicated file clients, and legacy hardware (such as PSP). The app supports Docker and Python for deployment, simplifying setup across various server environments. It facilitates seamless access to local files without complex configuration. Community documentation enhances usability, and the app's simple operation and high flexibility deliver a modern local file service solution.\n\n**Key Features:**\n- Privacy-focused local file sharing\n- Zero-dependency single-file architecture\n- Accelerated resumable uploads\n- Multi-protocol support (HTTP, WebDAV, FTP, etc.)\n- Cross-platform compatibility\n- Media indexing and streaming\n- Smart deduplication\n- User permission management\n\n**Learn More:**\n- [CopyParty GitHub Repository](https://github.com/9001/copyparty)\n", + "website": "https://copyparty.eu/", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/CopyParty/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-03-25", + "main_image": "icewhaletech/copyparty:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/copyparty.json", + "template_status": "laboratory-validated", + "content_hash": "7b8f71f67904ac34329246019299164b8b7ee5c5557e01d3280d23fe80615233", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "crafty", + "source_app_id": "crafty", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Crafty", + "repository": "https://registry.gitlab.com/crafty-controller/crafty-4", + "description": "Crafty is an open source Minecraft control panel built using Tornado and AdminLTE, featuring server scheduling, a interactive console and the ability to run almost any type of Minecraft server", + "website": "https://craftycontrol.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Crafty/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-20", + "main_image": "registry.gitlab.com/crafty-controller/crafty-4:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/crafty.json", + "template_status": "laboratory-validated", + "content_hash": "b586bf376d6ceca65a6a3e2c9402fa667abccfa4ec91283ffcfae78404df05c3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "cura", + "provider": "linuxserver.io", + "title": "Cura", + "repository_name": "docker-cura", + "repository": "https://github.com/linuxserver/docker-cura", + "description": "UltiMaker Cura is free, easy-to-use 3D printing software trusted by millions of users. Fine-tune your 3D model with 400+ settings for the best slicing and printing results.", + "website": "https://ultimaker.com/software/ultimaker-cura/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/cura-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "main", + "pushed_at": "2026-09-07T09:47:30Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/cura:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/cura.json", + "template_status": "generated-unvalidated", + "content_hash": "b967c24a5655dd9b9d95bf04d06e226efc3a03cf28fc54dac551176f30a2f3a7", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "darktable", + "provider": "linuxserver.io", + "title": "Darktable", + "repository_name": "docker-darktable", + "repository": "https://github.com/linuxserver/docker-darktable", + "description": "darktable is an open source photography workflow application and raw developer. A virtual lighttable and darkroom for photographers. It manages your digital negatives in a database, lets you view them through a zoomable lighttable and enables you to develop raw images and enhance them.", + "website": "https://www.darktable.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/darktable-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-08-31T15:21:14Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/darktable:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/darktable.json", + "template_status": "generated-unvalidated", + "content_hash": "b9e748556222df78760e3505bf08b9e8d277fbf31a55141077ac5641b5e96928", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "databag", + "source_app_id": "databag", + "provider": "balzack", + "template_family": "imported-compose", + "variant": null, + "title": "Databag", + "repository": "https://hub.docker.com/r/balzack/databag", + "description": "Databag is a federated chat app for self-hosting that focuses on user privacy and security; the service includes clients for iOS, Android, and browser.", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Databag/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-10-15", + "main_image": "balzack/databag:latest", + "category": "communication", + "category_label": "Communication & Community", + "template": "apps/databag.json", + "template_status": "generated-unvalidated", + "content_hash": "dc06124241f39e9af4417d246a6fb8b4a777613050a84cee9fd7dcf2be524320", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "davos", + "provider": "linuxserver.io", + "title": "Davos", + "repository_name": "docker-davos", + "repository": "https://github.com/linuxserver/docker-davos", + "description": "Davos is an FTP automation tool that periodically scans given host locations for new files. It can be configured for various purposes, including listening for specific files to appear in the host location, ready for it to download and then move, if required. It also supports completion notifications as well as downstream API calls, to further the workflow.", + "website": "https://github.com/linuxserver/davos", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/davos-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2025-11-21T18:46:32Z", + "updated_at": "2025-01-27", + "main_image": "lscr.io/linuxserver/davos:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/davos.json", + "template_status": "generated-unvalidated", + "content_hash": "e3a6c26b81f0d93c411bb1b0046fbff0fc33d453a000efe486e6cd9b32905658", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ddclient", + "provider": "linuxserver.io", + "title": "Ddclient", + "repository_name": "docker-ddclient", + "repository": "https://github.com/linuxserver/docker-ddclient", + "description": "Ddclient is a Perl client used to update dynamic DNS entries for accounts on Dynamic DNS Network Service Provider. It was originally written by Paul Burry and is now mostly by wimpunk. It has the capability to update more than just dyndns and it can fetch your WAN-ipaddress in a few different ways.", + "website": "https://github.com/ddclient/ddclient", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ddclient-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T11:59:00Z", + "updated_at": "2025-07-10", + "main_image": "lscr.io/linuxserver/ddclient:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/ddclient.json", + "template_status": "laboratory-validated", + "content_hash": "91512aa83c7fe69d3b7ab3be11aac61cb3e41391a57d7beae44d240dceb103d3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ddns-go", + "source_app_id": "ddns-go", + "provider": "jeessy", + "template_family": "imported-compose", + "variant": null, + "title": "ddns-go", + "repository": "https://hub.docker.com/r/jeessy/ddns-go", + "description": "A simple and easy-to-use DDNS tool. Automatically updates domain name resolution to your public IP (supports Alibaba Cloud, Tencent Cloud, Dnspod, Cloudflare, Callback, Huawei Cloud, Baidu Cloud, Porkbun, GoDaddy, and Google Domain).\n\nDeploy DDNS-go on self-hosted server, and you can bind the public IP of your self-hosted server device to your domain name. This way, you can access your self-hosted server device via the domain name while you are away.\n", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Ddns-go/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-31", + "main_image": "jeessy/ddns-go:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/ddns-go.json", + "template_status": "generated-unvalidated", + "content_hash": "6ef6f75472f0e7a23f4b3dea4d98bff610c20004bdedd6dabadf5ab35af6b1f7", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ddns-updater", + "source_app_id": "ddns-updater", + "provider": "qmcgaw", + "template_family": "imported-compose", + "variant": null, + "title": "ddns-updater", + "repository": "https://hub.docker.com/r/qmcgaw/ddns-updater", + "description": "Program to keep DNS A and/or AAAA records updated for multiple DNS providers", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/DDNS-Updater/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-01", + "main_image": "qmcgaw/ddns-updater:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/ddns-updater.json", + "template_status": "generated-unvalidated", + "content_hash": "012d83f253220a95a83eb5251ed3f72153192a83a3109becea0d32b7c741bebe", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "deepseek-ocr-nvidia", + "source_app_id": "deepseek-ocr-nvidia", + "provider": "icewhaletech", + "template_family": "imported-compose", + "variant": "nvidia", + "title": "DeepSeek OCR(Nvidia GPU)", + "repository": "https://hub.docker.com/r/icewhaletech/deepseek-ocr-frontend", + "description": "DeepSeek OCR is a powerful open-source OCR (Optical Character Recognition) tool based on the advanced DeepSeek-AI model. It enables accurate text extraction from images and document scans via a user-friendly web interface and API. Supports various image formats and offers configurations for image size, cropping, and upload limits. Additionally, DeepSeek OCR features four core recognition modes: Plain OCR for raw text extraction, Describe for intelligent image content descriptions, Find for keyword localization with visual bounding box returns, and Freeform for flexible image understanding tasks based on custom prompts.\n\n**Key Features:**\n- High-accuracy text recognition with DeepSeek-OCR, supporting images and multi-page PDF documents\n- Preserves document layout including tables, formulas, and structural formatting\n- Web frontend (React) and REST API (FastAPI) for easy usage and system integration\n- Export results to Markdown, HTML, DOCX, or JSON formats\n- Automatic extraction and embedding of images from PDF files\n- GPU acceleration and Docker deployment for fast and scalable processing\n\n**Prerequisites:**\n- self-hosted server version 1.5.2 or higher, or NVIDIA Open Driver version 580 or higher\n- NVIDIA GPU with >= 8 GB VRAM for optimal performance\n\n**Learn More:**\n- [DeepSeek OCR App (GitHub)](https://github.com/rdumasia303/deepseek_ocr_app)\n", + "website": "", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/DeepSeek-OCR_Nvidia/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "icewhaletech/deepseek-ocr-frontend:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/deepseek-ocr-nvidia.json", + "template_status": "generated-review-required", + "content_hash": "7d18da1b0651ef9d6be7e2ec5f3932b3bfa7e1ef4169507284fffc2b1dcd993c", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "deluge", + "provider": "linuxserver.io", + "title": "Deluge", + "repository_name": "docker-deluge", + "repository": "https://github.com/linuxserver/docker-deluge", + "description": "Deluge is a lightweight, Free Software, cross-platform BitTorrent client.", + "website": "http://deluge-torrent.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/deluge-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T19:33:30Z", + "updated_at": "2026-04-02", + "main_image": "lscr.io/linuxserver/deluge:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/deluge.json", + "template_status": "generated-unvalidated", + "content_hash": "106809a4fd1a5c48d919c8512bd3af7329126ab2f3fc49b7efc42192d57c4c97", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "dify", + "source_app_id": "dify", + "provider": "langgenius", + "template_family": "imported-compose", + "variant": null, + "title": "Dify", + "repository": "https://hub.docker.com/r/langgenius/dify-web", + "description": "Dify is an open-source large language model (LLM) application development platform. It combines the concepts of Backend-as-a-Service and LLMOps to enable developers to quickly build production-grade generative AI applications. Even non-technical personnel can participate in the definition and data operations of AI applications.", + "website": "https://dify.ai", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/Dify/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "langgenius/dify-web:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/dify.json", + "template_status": "generated-review-required", + "content_hash": "b36ab46f437fe147c8bce574afcba73634569a7377a88f2464e48784857a957f", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "service:api:compose-key:depends_on", + "service:worker:compose-key:depends_on", + "service:db:healthcheck-format", + "service:redis:healthcheck-format", + "service:sandbox:compose-key:depends_on", + "service:ssrf_proxy:compose-key:depends_on", + "service:nginx:compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "digikam", + "provider": "linuxserver.io", + "title": "Digikam", + "repository_name": "docker-digikam", + "repository": "https://github.com/linuxserver/docker-digikam", + "description": "digiKam: Professional Photo Management with the Power of Open Source", + "website": "https://www.digikam.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/digikam-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T18:35:56Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/digikam:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/digikam.json", + "template_status": "generated-unvalidated", + "content_hash": "363dae41fce55565c023cf71b710511c779fa5c5e8d981836858508c633c14b0", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "diskover", + "provider": "linuxserver.io", + "title": "Diskover", + "repository_name": "docker-diskover", + "repository": "https://github.com/linuxserver/docker-diskover", + "description": "diskover is an open source file system indexer that uses Elasticsearch to index and manage data across heterogeneous storage systems.", + "website": "https://github.com/diskoverdata/diskover-community", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/diskover-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T14:55:45Z", + "updated_at": "2024-09-06", + "main_image": "lscr.io/linuxserver/diskover:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/diskover.json", + "template_status": "generated-review-required", + "content_hash": "e4b1dd687f063a69d38b221b62459c3a11a609aa28bbbdc0e3ce23a7888e6f6a", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "docker-volume-backup", + "provider": "mrcaringi", + "template_family": "curated-profile", + "title": "Docker Volume Backup", + "repository": "https://github.com/MrCaringi/docker-volume-backup", + "description": "Requires real Docker daemon/socket and Docker Compose stacks; cannot back up native Proxmox OCI instances as Docker volumes. Hidden pending explicit external Docker integration; no Docker installed on Proxmox.", + "website": "https://github.com/MrCaringi/docker-volume-backup", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-16", + "main_image": "mrcaringi/docker-volume-backup:latest", + "category": "tools", + "category_label": "Tools", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/docker-volume-backup.json", + "template": "apps/docker-volume-backup.json", + "template_status": "generated-review-required", + "content_hash": "aff9dd3a2a65b1ce7d987019c44bc95881ddf2a778362e808409ec424eebbd22", + "hidden": true, + "automatic_install_candidate": false, + "untranslated_blockers": [ + "docker-engine-required-no-native-oci-stack-support" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false + }, + { + "id": "docmost", + "source_app_id": "docmost", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Docmost", + "repository": "https://hub.docker.com/r/docmost/docmost", + "description": "Docmost is a self-hosted collaborative wiki and documentation tool designed for real-time collaboration, allowing multiple users to edit the same page simultaneously without conflicts. Its intuitive interface is ideal for teams managing knowledge bases, project documentation, or wikis, offering an efficient knowledge creation and sharing experience.\n\nThe tool's core features include real-time collaborative editing and space organization. It supports multiple users editing pages in real time for seamless collaboration and organizes pages into 'spaces' for teams, projects, or departments, each with independent permission settings. A rich text editor with Markdown shortcuts simplifies content creation. Built-in Draw.io, Excalidraw, and Mermaid tools provide robust diagramming capabilities.\n\nIt offers permissions management, assigning access via user groups for content security. Pages can be publicly shared via links for external access. Comments enhance communication and feedback, while page history tracks changes. Features like nested navigation, quick search, file attachments, and Markdown/HTML import/export are supported. The tool\u2019s collaboration and flexibility deliver a modern documentation solution.\n\n**Key Features:**\n- Real-time collaborative editing for multiple users\n- Spaces for organizing pages by team, project or department\n- Permissions management with user group access control\n- Rich text editor with Markdown shortcuts\n- Built-in Draw.io, Excalidraw, Mermaid diagramming tools\n- Public page sharing via links\n- Page comments for communication and feedback\n- Page history, nested navigation, search, and file attachments\n\n**Learn More:**\n- [Docmost Official Website](https://docmost.com/)\n- [Docmost GitHub](https://github.com/docmost/docmost)\n", + "website": "https://docmost.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Docmost/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "docmost/docmost:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/docmost.json", + "template_status": "generated-unvalidated", + "content_hash": "e590f26dd7df021490e58a84e6375ef79166b45f1439887ed4d23c58fa7110d4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "dogwalk", + "provider": "linuxserver.io", + "title": "Dogwalk", + "repository_name": "docker-dogwalk", + "repository": "https://github.com/linuxserver/docker-dogwalk", + "description": "DOGWALK is Blender Studio's long awaited second game project, focused on creating a bite-sized interactive storytelling playground. Play as a big adorable dog and explore the winter woods with a little kid.", + "website": "https://studio.blender.org/projects/dogwalk/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dogwalk-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-06T01:03:22Z", + "updated_at": "2026-03-31", + "main_image": "lscr.io/linuxserver/dogwalk:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/dogwalk.json", + "template_status": "generated-unvalidated", + "content_hash": "987a713a13a56cb9b0b25d264697a37a266727bb192c15c67653e737042b7b4a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "dokuwiki", + "provider": "linuxserver.io", + "title": "Dokuwiki", + "repository_name": "docker-dokuwiki", + "repository": "https://github.com/linuxserver/docker-dokuwiki", + "description": "Dokuwiki is a simple to use and highly versatile Open Source wiki software that doesn't require a database. It is loved by users for its clean and readable syntax. The ease of maintenance, backup and integration makes it an administrator's favorite. Built in access controls and authentication connectors make DokuWiki especially useful in the enterprise context and the large number of plugins contributed by its vibrant community allow for a broad range of use cases beyond a traditional wiki.", + "website": "https://www.dokuwiki.org/dokuwiki/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dokuwiki-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T18:58:18Z", + "updated_at": "2026-07-14", + "main_image": "lscr.io/linuxserver/dokuwiki:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/dokuwiki.json", + "template_status": "generated-unvalidated", + "content_hash": "6736c22b1b7c79d63952c63c192c73c760c317133b4b6e52dd84bdae585cbd4c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "dolphin", + "provider": "linuxserver.io", + "title": "Dolphin", + "repository_name": "docker-dolphin", + "repository": "https://github.com/linuxserver/docker-dolphin", + "description": "Dolphin Emulator lets you play GameCube and Wii games with various graphical enhancements and other features are available to improve your game experience.", + "website": "https://dolphin-emu.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dolphin-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T01:28:48Z", + "updated_at": "2026-05-06", + "main_image": "lscr.io/linuxserver/dolphin:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/dolphin.json", + "template_status": "generated-unvalidated", + "content_hash": "02b815f93359d2912ae83bb5fd592d4ec254511383285789c7d4dc73a1e1d877", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "doplarr", + "provider": "linuxserver.io", + "title": "Deprecation Notice", + "repository_name": "docker-doplarr", + "repository": "https://github.com/linuxserver/docker-doplarr", + "description": "Doplarr is an *arr request bot for Discord.\"", + "website": "https://github.com/kiranshila/Doplarr", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doplarr-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-07-09T23:30:33Z", + "updated_at": "2025-07-27", + "main_image": "lscr.io/linuxserver/doplarr:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/doplarr.json", + "template_status": "generated-unvalidated", + "content_hash": "fab02855609ab1483299490ddbe8cce934dfec2197bcfbf9810bb2bd38344aec", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "doplarr_rs", + "provider": "linuxserver.io", + "title": "Doplarr_Rs", + "repository_name": "docker-doplarr_rs", + "repository": "https://github.com/linuxserver/docker-doplarr_rs", + "description": "Doplarr_rs is a Discord bot for requesting media through *arr backends, written in Rust.", + "website": "https://github.com/activexray/doplarr_rs", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doplarr_rs-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-10T18:29:06Z", + "updated_at": "2026-06-22", + "main_image": "lscr.io/linuxserver/doplarr_rs:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/doplarr_rs.json", + "template_status": "generated-unvalidated", + "content_hash": "49b97eb2dffe7bcbf3a4aac206d70047829e610d13305cd70be2cf61d82ca44f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "dosbox-staging", + "provider": "linuxserver.io", + "title": "Dosbox Staging", + "repository_name": "docker-dosbox-staging", + "repository": "https://github.com/linuxserver/docker-dosbox-staging", + "description": "DOSBox Staging is a modern continuation of DOSBox a free and open-source emulator that enables the execution of MS-DOS software, especially video games.", + "website": "https://www.dosbox-staging.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/dosbox-staging-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T15:02:25Z", + "updated_at": "2026-03-05", + "main_image": "lscr.io/linuxserver/dosbox-staging:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/dosbox-staging.json", + "template_status": "generated-unvalidated", + "content_hash": "b8d2edd63d44ab1341f855849bf6b0c86c171b7e84b21975ed0a114c43797172", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "doublecommander", + "provider": "linuxserver.io", + "title": "Doublecommander", + "repository_name": "docker-doublecommander", + "repository": "https://github.com/linuxserver/docker-doublecommander", + "description": "Double Commander is a free cross platform open source file manager with two panels side by side. It is inspired by Total Commander and features some new ideas.", + "website": "https://doublecmd.sourceforge.io/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/doublecommander-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T21:59:22Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/doublecommander:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/doublecommander.json", + "template_status": "generated-unvalidated", + "content_hash": "01fc0e09ef0b2409f14b1903423ee782b1caf286f52a9119bed34f408f251ea6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "downtify", + "source_app_id": "downtify", + "provider": "henriquesebastiao", + "template_family": "imported-compose", + "variant": null, + "title": "Downtify", + "repository": "https://ghcr.io/henriquesebastiao/downtify", + "description": "With Downtify you can download Spotify musics containing album art, track names, album title and other metadata about the songs. Just copy the Spotify link, whether it's a single song, an album, etc. As soon as your downloads are complete you will be notified!\n", + "website": "https://downtify.henriquesebastiao.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Downtify/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-11", + "main_image": "ghcr.io/henriquesebastiao/downtify:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/downtify.json", + "template_status": "generated-unvalidated", + "content_hash": "e19bcae00f2562cd506380effdfda90faf327476c7b30e9eedba52dcf8b595dc", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "dsh-harness", + "source_app_id": "dsh-harness", + "provider": "smanx", + "template_family": "imported-compose", + "variant": null, + "title": "DeepSeekHarness", + "repository": "https://ghcr.io/smanx/deepseek-harness", + "description": "DeepSeek Harness (dsh) is an open-source agent harness developed by DeepSeek AI.", + "website": "https://www.deepseek.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/DeepSeekHarness/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-08-19", + "main_image": "ghcr.io/smanx/deepseek-harness:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/dsh-harness.json", + "template_status": "generated-unvalidated", + "content_hash": "fea31b738bde87dd3cbf9d49b963e8b9f090ac5ae68e9c7529fe5122a0a5a50d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "duckdns", + "provider": "linuxserver.io", + "title": "Duckdns", + "repository_name": "docker-duckdns", + "repository": "https://github.com/linuxserver/docker-duckdns", + "description": "Duckdns is a free service which will point a DNS (sub domains of duckdns.org) to an IP of your choice. The service is completely free, and doesn't require reactivation or forum posts to maintain its existence.", + "website": "https://duckdns.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duckdns-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T08:51:40Z", + "updated_at": "2026-07-15", + "main_image": "lscr.io/linuxserver/duckdns:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/duckdns.json", + "template_status": "generated-unvalidated", + "content_hash": "4eefc97b4a4f876fb55563b28e2f61850ec84117b1548aa38263a05c5785ef7d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "duckstation", + "provider": "linuxserver.io", + "title": "Duckstation", + "repository_name": "docker-duckstation", + "repository": "https://github.com/linuxserver/docker-duckstation", + "description": "DuckStation is a PS1 Emulator aiming for the best accuracy and game support.", + "website": "https://duckstation.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duckstation-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T05:35:37Z", + "updated_at": "2026-03-05", + "main_image": "lscr.io/linuxserver/duckstation:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/duckstation.json", + "template_status": "generated-unvalidated", + "content_hash": "f80996b8b0a9fcb901a750f03c33eb3e891896b812378e18712b8c05b14fdd88", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "duplicati", + "provider": "linuxserver.io", + "title": "Duplicati", + "repository_name": "docker-duplicati", + "repository": "https://github.com/linuxserver/docker-duplicati", + "description": "Duplicati is a backup client that securely stores encrypted, incremental, compressed backups on local storage, cloud storage services and remote file servers. It works with standard protocols like FTP, SSH, WebDAV as well as popular services like Microsoft OneDrive, Amazon S3, Google Drive, box.com, Mega, B2, and many others.", + "website": "https://www.duplicati.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/duplicati-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T08:31:37Z", + "updated_at": "2026-09-03", + "main_image": "lscr.io/linuxserver/duplicati:latest", + "category": "backup", + "category_label": "Backup & Recovery", + "template": "apps/duplicati.json", + "template_status": "laboratory-validated", + "content_hash": "13fa5a981587604e9bb8442b67947ca7169a9ce67a1a5ca040ef48b8cb1abc12", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "eden", + "provider": "linuxserver.io", + "title": "Eden", + "repository_name": "docker-eden", + "repository": "https://github.com/linuxserver/docker-eden", + "description": "Eden is an experimental open-source emulator for the Nintendo Switch, built with performance and stability in mind.", + "website": "https://eden-emu.dev/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/eden-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T08:58:13Z", + "updated_at": "2026-06-30", + "main_image": "lscr.io/linuxserver/eden:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/eden.json", + "template_status": "generated-unvalidated", + "content_hash": "514de91483fab4b1a0f63137a4b6901d4d0c7bd7666874a255ea322fe1f2afac", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "emby", + "provider": "linuxserver.io", + "title": "Emby", + "repository_name": "docker-emby", + "repository": "https://github.com/linuxserver/docker-emby", + "description": "Emby organizes video, music, live TV, and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone emby Media Server.", + "website": "https://emby.media/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/emby-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T15:36:08Z", + "updated_at": "2026-09-11", + "main_image": "lscr.io/linuxserver/emby:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/emby.json", + "template_status": "generated-unvalidated", + "content_hash": "8d581f363c65f0e4ccadb3512cab7c0e241fb77583671f26d04804e5b7a174af", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "emby-official", + "provider": "emby", + "template_family": "curated-profile", + "title": "Emby Official", + "repository": "https://hub.docker.com/r/emby/embyserver", + "description": "Emby is a personal media management platform that brings home videos, music, and photos together, automatically converting and streaming to any device. An intuitive design makes it ideal for users to enjoy media content anytime, anywhere, meeting family entertainment and media management needs.\n\nCore features include cross-device media streaming and easy access. It supports real-time conversion and streaming of personal media to any device for seamless playback. A connection service enables easy media access while away from home. Live TV functionality supports streaming, managing DVR, and accessing a library of recordings. Mobile sync delivers media to smartphones and tablets for offline access, automatically updating new content.\n\nIt offers parental controls to restrict children's content access, set schedules and time limits, and remotely monitor sessions. Chromecast support enables easy streaming of videos, music, photos, and Live TV. Content is presented elegantly, enhancing visual experience. Cloud sync supports backup, archiving, and multi-resolution storage for optimized streaming. Web-based media management facilitates editing metadata, images, and searching subtitles, while DLNA integration auto-detects network devices for content streaming. With convenience and versatility at the core, the platform delivers a modern media management solution.\n\n**Key Features:**\n- Automatic conversion and streaming of media to any device\n- Easy access via connection service while away from home\n- Live TV streaming, DVR management, and recording library access\n- Mobile sync to smartphones and tablets for offline access\n- Parental controls with content restrictions, schedules, and remote monitoring\n- Chromecast support for streaming videos, music, photos, and Live TV\n- Cloud sync for backup and multi-resolution storage\n- Web-based media management for editing metadata and searching subtitles\n- DLNA integration for auto-detecting network devices and streaming content\n\n**Learn More:**\n- [Emby Official Website](https://emby.media/)\n", + "website": "https://emby.media/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": null, + "main_image": "emby/embyserver:latest", + "category": "media", + "category_label": "Media & Streaming", + "replaces_discovered_ids": [ + "emby", + "emby-nvidia" + ], + "curated_path": "catalog/curated/emby-official.json", + "template": "apps/emby-official.json", + "template_status": "generated-unvalidated", + "content_hash": "90c70b79980c766f6eabb20a29b738feb321c096bb8dc36e0b8eb2a4c1934ab3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "embystat", + "source_app_id": "embystat", + "provider": "linuxserver.io", + "template_family": "imported-compose", + "variant": null, + "title": "Embystat", + "repository": "https://hub.docker.com/r/linuxserver/embystat", + "description": "EmbyStat is a personal web server that can calculate all kinds of statistics from your (local) Emby or Jellyfin server. Just install this on your server and let him calculate all kinds of fun stuff. This project is still in Alpha phase, but feel free to pull in on your computer and test it out yourself. When the time is right I will host a full informational website/release for common platforms and Wiki pages.", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Embystat/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2023-10-25", + "main_image": "linuxserver/embystat:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/embystat.json", + "template_status": "generated-unvalidated", + "content_hash": "22fa2fa636cdb34f54d3ce645ad5bcabe1f5e5dcd413785573b9cbe0cb9d5a6f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "emulatorjs", + "source_app_id": "emulatorjs", + "provider": "linuxserver.io", + "template_family": "imported-compose", + "variant": null, + "title": "emulatorjs", + "repository": "https://hub.docker.com/r/linuxserver/emulatorjs", + "description": "EmulatorJS is a Docker-based emulator application that can simulate various operating systems and device environments within containers for development, testing, and learning purposes.", + "website": "https://emulatorjs.org/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/EmulatorJS/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-06-09", + "main_image": "linuxserver/emulatorjs:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/emulatorjs.json", + "template_status": "generated-unvalidated", + "content_hash": "267a6a6afae93ed0ba99322abe4732811427e4e49d961b016b23987d562cb173", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "esphome", + "source_app_id": "esphome", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "ESPHome", + "repository": "https://ghcr.io/esphome/esphome", + "description": "ESPHome is a system to control your microcontrollers by simple yet powerful configuration files and control them remotely through Home Automation systems.", + "website": "https://esphome.io", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/ESPHome/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-24", + "main_image": "ghcr.io/esphome/esphome:latest", + "category": "smarthome", + "category_label": "IoT & Smart Home", + "template": "apps/esphome.json", + "template_status": "generated-unvalidated", + "content_hash": "b270ae8c95e66626531ba3820c59f6fca861c94ff2b496fc837ae29ceba83da1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "etherpad", + "source_app_id": "etherpad", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Etherpad", + "repository": "https://hub.docker.com/r/etherpad/etherpad", + "description": "Etherpad is a real-time collaborative document editor where multiple people can edit the same pad simultaneously, with every change synchronized instantly and colour-coded per author.\nSelf-hosted, open source, and fully under your control, it is perfect for meeting notes, brainstorming, shared writing, and lightweight knowledge capture.\nIt ships with a built-in admin panel, a plugin ecosystem of 250+ add-ons, native DOCX/PDF/Markdown import & export, and multi-architecture container support (amd64 + arm64).\n\n**Main Features:**\n- Real-time collaborative editing with instant sync\n- Per-author colour coding for clear writing attribution\n- Built-in admin panel and a plugin ecosystem with 250+ add-ons\n- Native DOCX, PDF, and Markdown import & export\n- Open source, self-hosted deployment with amd64 and arm64 support\n\n**Learn More:**\n- [Etherpad Official Website](https://etherpad.org/)\n- [Etherpad GitHub](https://github.com/ether/etherpad)\n- [Etherpad Documentation](https://docs.etherpad.org/)\n", + "website": "https://etherpad.org/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Etherpad/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-17", + "main_image": "etherpad/etherpad:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/etherpad.json", + "template_status": "laboratory-validated", + "content_hash": "eb9bca30dae0a541947d47a157fe60f7cd9dbef5338a90fb7de2e546e7418489", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "excalidraw", + "source_app_id": "excalidraw", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Excalidraw", + "repository": "https://hub.docker.com/r/excalidraw/excalidraw", + "description": "Excalidraw is a virtual hand-drawn style whiteboard platform supporting infinite canvas and end-to-end encrypted collaboration. An intuitive interface offers a hand-drawn experience, ideal for brainstorming, design sketches, or educational scenarios, meeting diverse creative needs.\n\nCore features include an infinite canvas whiteboard and end-to-end encrypted collaboration. Hand-drawn style with shape library support allows creating rich graphics, enhanced by image insertion capabilities. Dark mode improves user experience, catering to diverse users.\n\nIt provides export options including PNG, SVG, and clipboard for easy content sharing. Drawing capabilities cover rectangle, circle, diamond, arrow, line, free-draw, and eraser, with arrow-binding and labeled arrow support. Undo, redo, zoom, and panning functionalities optimize operations. With creativity and security at the core, the platform delivers a modern whiteboard design solution.\n\n**Key Features:**\n- Infinite canvas whiteboard supporting hand-drawn style\n- Shape library support for creating rich graphics\n- Image insertion capability\n- Dark mode\n- Export to PNG, SVG, and clipboard\n- Open format - export drawings as an `.excalidraw` json file\n- Wide range of tools - rectangle, circle, diamond, arrow, line, free-draw, eraser...\n- Arrow-binding & labeled arrows\n- Undo and redo\n- Zoom and panning support\n\n**Learn More:**\n- [Excalidraw Official Website](https://excalidraw.com/)\n- [Excalidraw GitHub](https://github.com/excalidraw/excalidraw)\n", + "website": "https://excalidraw.com/", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/Excalidraw/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-06", + "main_image": "excalidraw/excalidraw:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/excalidraw.json", + "template_status": "generated-unvalidated", + "content_hash": "721d8393158e1fe316b7b64774efa9fa934ff08eda07363cfda9a77d2307ee82", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "faster-whisper", + "provider": "linuxserver.io", + "title": "Faster Whisper", + "repository_name": "docker-faster-whisper", + "repository": "https://github.com/linuxserver/docker-faster-whisper", + "description": "Faster-whisper is a reimplementation of OpenAI's Whisper model using CTranslate2, which is a fast inference engine for Transformer models. This container provides a Wyoming protocol server for faster-whisper.", + "website": "https://github.com/SYSTRAN/faster-whisper", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/faster-whisper-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-12T01:03:07Z", + "updated_at": "2026-08-16", + "main_image": "lscr.io/linuxserver/faster-whisper:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/faster-whisper.json", + "template_status": "generated-unvalidated", + "content_hash": "6101b77660f6e1714e300703a1f7730ac698be028aa6e5982f262f1c8fac9e1a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ferdium", + "provider": "linuxserver.io", + "title": "Ferdium", + "repository_name": "docker-ferdium", + "repository": "https://github.com/linuxserver/docker-ferdium", + "description": "Ferdium is a desktop app that helps you organize how you use your favourite apps by combining them into one application.", + "website": "https://ferdium.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ferdium-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T08:34:05Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/ferdium:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/ferdium.json", + "template_status": "generated-unvalidated", + "content_hash": "88327550e74883d21cb62ccd94ea6bdaeb952ab3a158f1f984a14e25e0c56afb", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "filebrowser-quantum", + "provider": "gtsteffaniak", + "template_family": "curated-profile", + "title": "FileBrowser Quantum", + "repository": "https://github.com/gtsteffaniak/filebrowser", + "description": "Official image with managed persistent configuration and selectable content storage. Validated on amd64: clean install, authenticated login, same-digest recreation and interrupted-candidate recovery. Cross-release migration and arm64 runtime not tested.", + "website": "https://github.com/gtsteffaniak/filebrowser", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-16", + "main_image": "gtstef/filebrowser:latest", + "category": "tools", + "category_label": "Tools", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/filebrowser-quantum.json", + "template": "apps/filebrowser-quantum.json", + "template_status": "laboratory-validated", + "content_hash": "3eda37d759f056df9c2767a1037398259086ab2b8b442a9ca886bd534fc28819", + "hidden": false, + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false + }, + { + "id": "filedrop", + "source_app_id": "filedrop", + "provider": "noecl", + "template_family": "imported-compose", + "variant": null, + "title": "FileDrop", + "repository": "https://hub.docker.com/r/noecl/filedrop", + "description": "FileDrop is a self-hosted file sharing service that allows you to easily share files with family, friends, or colleagues. It's been designed to be easy to use and light on resources.\n", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Filedrop/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2023-09-13", + "main_image": "noecl/filedrop:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/filedrop.json", + "template_status": "generated-unvalidated", + "content_hash": "4b1e1a2caa97dc333688dafa6a119d94f092d3238ec069a430e3d11bf56d20f3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "fileflows", + "provider": "revenz", + "template_family": "curated-profile", + "title": "FileFlows", + "repository": "https://hub.docker.com/r/revenz/fileflows", + "description": "Save storage space with efficient file processing.\n\nFileFlows lets you monitor and process any file type with custom flows. Videos, audio, images, archives, comics, eBooks\u2014you name it!\n", + "website": "https://fileflows.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": null, + "main_image": "revenz/fileflows:latest", + "category": "media", + "category_label": "Media & Streaming", + "replaces_discovered_ids": [ + "fileflows" + ], + "curated_path": "catalog/curated/fileflows.json", + "template": "apps/fileflows.json", + "template_status": "generated-unvalidated", + "content_hash": "7c50616174ce22f228a86d57629b56311339cec9db84be17bd9f45b40263768a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "filezilla", + "provider": "linuxserver.io", + "title": "Filezilla", + "repository_name": "docker-filezilla", + "repository": "https://github.com/linuxserver/docker-filezilla", + "description": "FIleZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface.", + "website": "https://filezilla-project.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/filezilla-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T22:33:52Z", + "updated_at": "2026-05-20", + "main_image": "lscr.io/linuxserver/filezilla:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/filezilla.json", + "template_status": "generated-unvalidated", + "content_hash": "5751f36bb751fe2a8a712ca37189576dca7162d65148391d6815eb1181f5300d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "firefly", + "source_app_id": "firefly", + "provider": "uusec", + "template_family": "imported-compose", + "variant": null, + "title": "Firefly", + "repository": "https://hub.docker.com/r/uusec/firefly", + "description": "Firefly is a simple and easy to install WireGuard server software, which can be widely used in scenarios such as remote networking, remote work, and expose a local server behind a NAT or firewall to the internet. \ud83c\udfaf Features \ud83d\udfe2 Provide a simple and easy-to-use web management UI \ud83d\udfe3 Supports access to all WireGuard clients \ud83d\udfe1 No need for system installation of WireGuard components \ud83d\udfe0 Single file, no additional library dependencies \ud83d\udd34 Automatically apply for free SSL certificate", + "website": "https://qq.uusec.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Firefly/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-02-21", + "main_image": "uusec/firefly:latest", + "category": "finance", + "category_label": "Finance & Budgeting", + "template": "apps/firefly.json", + "template_status": "generated-unvalidated", + "content_hash": "0f2d454734f3abea20a0e1b2e8d616f6c815c6302f1cf00321d94bd19f302178", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "firefox", + "provider": "linuxserver.io", + "title": "Firefox", + "repository_name": "docker-firefox", + "repository": "https://github.com/linuxserver/docker-firefox", + "description": "Firefox Browser, also known as Mozilla Firefox or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. Firefox uses the Gecko layout engine to render web pages, which implements current and anticipated web standards.", + "website": "https://www.mozilla.org/en-US/firefox/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/firefox-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T23:15:25Z", + "updated_at": "2026-07-04", + "main_image": "lscr.io/linuxserver/firefox:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/firefox.json", + "template_status": "generated-unvalidated", + "content_hash": "1e626c8a42bb9ca6a5d471e5b091a63ab3d4f7a3c80f7d9b20c92864f578196d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "flaresolverr", + "source_app_id": "flaresolverr", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "FlareSolverr", + "repository": "https://ghcr.io/flaresolverr/flaresolverr", + "description": "", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/FlareSolverr/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-11-29", + "main_image": "ghcr.io/flaresolverr/flaresolverr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/flaresolverr.json", + "template_status": "laboratory-validated", + "content_hash": "fd17defd88e466d6e2681673041418e0fad75ec443db7bcd01551336e9452a2e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "flexget", + "provider": "linuxserver.io", + "title": "Flexget", + "repository_name": "docker-flexget", + "repository": "https://github.com/linuxserver/docker-flexget", + "description": "Flexget is a multipurpose automation tool for all of your media.", + "website": "http://flexget.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/flexget-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-11T21:37:54Z", + "updated_at": "2026-08-15", + "main_image": "lscr.io/linuxserver/flexget:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/flexget.json", + "template_status": "laboratory-validated", + "content_hash": "79cb8eb32708faf01774ccdd3beced9579f95aab0c47c91c7c800ae0993e2e45", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "flowise", + "source_app_id": "flowise", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Flowise", + "repository": "https://hub.docker.com/r/flowiseai/flowise", + "description": "Flowise is a generative AI development platform for building AI agents and LLM workflows. An intuitive interface with a visual editor simplifies complex workflow design, ideal for developers creating diverse AI applications, from chatbots to data processing pipelines.\n\nCore features include visual orchestration and data integration. Support for various models, custom code, and branching, looping, and routing logic enables complex workflow creation. Connection to over 100 data sources, vector databases, and memory modules ensures flexible data ingestion. Monitoring capabilities provide execution logs and visual debugging for workflow transparency and maintenance. Self-hosted and air-gapped deployment options accommodate diverse infrastructure needs.\n\nIt offers data processing with transforms, filters, aggregates, and RAG indexing pipelines. Memory optimization and planning techniques enhance performance, while MCP integration supports tool connections and authentication. Security controls include role-based access, single sign-on, and encrypted credentials for data protection. API, JavaScript and Python SDKs, and command-line interface enable extensibility, with embedded chat components and a template marketplace accelerating development. Scalability supports high-throughput workflows, and evaluation features optimize performance. With flexibility and efficiency at the core, the platform delivers a modern solution for AI development.\n\n**Key Features:**\n- Visual editor supporting multiple models, custom code, branching looping routing logic\n- Connection to over 100 data sources, vector databases, and memory modules\n- Execution logs and visual debugging for enhanced monitoring\n- Data processing with transforms, filters, aggregates, and RAG indexing pipelines\n- Various memory optimization technique and integrations\n- MCP client and server nodes for tool integration\n- Input moderation and output post-processing for safety\n- API, JavaScript and Python SDKs, and command-line interface\n- Customizable embedded chat components\n- Template marketplace and reusable components\n- Role-based access control, single sign-on, encrypted credentials\n- Vertical and horizontal scalability for high-throughput workflows\n- Datasets and evaluation features for workflow optimization\n\n**Learn More:**\n- [Flowise Official Website](https://flowiseai.com/)\n- [Flowise GitHub](https://github.com/flowiseai/flowise)\n- [Flowise Documentation](https://docs.flowiseai.com/)\n", + "website": "https://flowiseai.com/", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/FlowiseAi/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-14", + "main_image": "flowiseai/flowise:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/flowise.json", + "template_status": "generated-unvalidated", + "content_hash": "1139477888afa4cf584ac9b300f5bcdc67e70f2f1308cec33dcf1c5a0087eff1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "flycast", + "provider": "linuxserver.io", + "title": "Flycast", + "repository_name": "docker-flycast", + "repository": "https://github.com/linuxserver/docker-flycast", + "description": "Flycast is a multi-platform Sega Dreamcast, Naomi, Naomi 2, and Atomiswave emulator derived from reicast.", + "website": "https://github.com/flyinghead/flycast", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/flycast-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T19:48:32Z", + "updated_at": "2026-03-05", + "main_image": "lscr.io/linuxserver/flycast:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/flycast.json", + "template_status": "generated-unvalidated", + "content_hash": "52c339b1b7c8cefc8571fc22ab3c4b3f58b40dbf6f028bd4f3d7b1360e7e56c1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "foldingathome", + "provider": "linuxserver.io", + "title": "Foldingathome", + "repository_name": "docker-foldingathome", + "repository": "https://github.com/linuxserver/docker-foldingathome", + "description": "Folding@home is a distributed computing project for simulating protein dynamics, including the process of protein folding and the movements of proteins implicated in a variety of diseases. It brings together citizen scientists who volunteer to run simulations of protein dynamics on their personal computers. Insights from this data are helping scientists to better understand biology, and providing new opportunities for developing therapeutics.", + "website": "https://foldingathome.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/foldingathome-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T07:45:56Z", + "updated_at": "2024-08-10", + "main_image": "lscr.io/linuxserver/foldingathome:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/foldingathome.json", + "template_status": "generated-unvalidated", + "content_hash": "4254b1c8c1616a6c3bb85a2e638dcea3156c1b37c273e11a9b76615bd406a174", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "freecad", + "provider": "linuxserver.io", + "title": "Freecad", + "repository_name": "docker-freecad", + "repository": "https://github.com/linuxserver/docker-freecad", + "description": "FreeCAD is a general-purpose parametric 3D computer-aided design (CAD) modeler and a building information modeling (BIM) software application with finite element method (FEM) support.", + "website": "https://www.freecad.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/freecad-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T15:34:22Z", + "updated_at": "2026-03-29", + "main_image": "lscr.io/linuxserver/freecad:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/freecad.json", + "template_status": "generated-unvalidated", + "content_hash": "afdc74c18ce6064a650669040d8398487703843fe8390f2ac831cc62b8e7ac46", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "freshrss", + "provider": "linuxserver.io", + "title": "Freshrss", + "repository_name": "docker-freshrss", + "repository": "https://github.com/linuxserver/docker-freshrss", + "description": "Freshrss is a free, self-hostable aggregator for rss feeds.", + "website": "https://freshrss.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/freshrss-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T16:49:33Z", + "updated_at": "2026-07-21", + "main_image": "lscr.io/linuxserver/freshrss:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/freshrss.json", + "template_status": "generated-unvalidated", + "content_hash": "3a7d21c46f0a9e5d04e4441fda4ac1e77ba400a5822de725bbb78a86fcf4e680", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "freshrss-official", + "source_app_id": "freshrss", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "FreshRSS", + "repository": "https://hub.docker.com/r/freshrss/freshrss", + "description": "FreshRSS is a self-hosted RSS and Atom feed aggregator. It is lightweight, easy to work with, powerful, and customizable.", + "website": "https://freshrss.org/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/FreshRSS/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-20", + "main_image": "freshrss/freshrss:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/freshrss-official.json", + "template_status": "generated-unvalidated", + "content_hash": "fbda38d47d0da0b3f126fe0392c29217a9993d2888176a903dace8e1a3ac23d5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "frigate", + "provider": "frigate", + "template_family": "curated-profile", + "title": "Frigate", + "repository": "https://github.com/blakeblackshear/frigate", + "description": "Frigate adapted as a native Proxmox OCI LXC with persistent configuration, selectable recording storage, tmpfs cache and optional GPU or detector devices.", + "website": "https://frigate.video/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-12", + "main_image": "ghcr.io/blakeblackshear/frigate:stable", + "category": "nvr", + "category_label": "NVR & Cameras", + "replaces_discovered_ids": [ + "frigate" + ], + "curated_path": "catalog/curated/frigate.json", + "template": "apps/frigate.json", + "template_status": "laboratory-validated", + "content_hash": "536b81d3a4a515f3b2f27fa35f0fcbc58bb88359374641493e644aa02061d81a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "gateway-go", + "source_app_id": "gateway-go", + "provider": "openiothub", + "template_family": "imported-compose", + "variant": null, + "title": "gateway-go", + "repository": "https://hub.docker.com/r/openiothub/gateway-go", + "description": "A fast reverse proxy to help you expose a local server behind a NAT or firewall to your client, remote access all your self-hosted server/self-hosted server apps.\n\nUse OpenIoTHub to scan the following QR code add a gateway,then add host,add self-hosted server/self-hosted server host's web page port,finally, enjoy remote control\n", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Gateway-go/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-01-11", + "main_image": "openiothub/gateway-go:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/gateway-go.json", + "template_status": "generated-unvalidated", + "content_hash": "0ea76602729dea636b6325cedcdc6d3ec4d5dc78dce053340fb1f91a91767b58", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "gimp", + "provider": "linuxserver.io", + "title": "Gimp", + "repository_name": "docker-gimp", + "repository": "https://github.com/linuxserver/docker-gimp", + "description": "GIMP is a free and open-source raster graphics editor used for image manipulation (retouching) and image editing, free-form drawing, transcoding between different image file formats, and more specialized tasks. It is extensible by means of plugins, and scriptable.", + "website": "https://www.gimp.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gimp-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T10:28:59Z", + "updated_at": "2026-03-24", + "main_image": "lscr.io/linuxserver/gimp:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/gimp.json", + "template_status": "generated-unvalidated", + "content_hash": "457bbc6a87847e3366d82c45f9cccdffade435f5f9684a8ffd471f40dd3c750e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "gitea", + "source_app_id": "gitea", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Gitea", + "repository": "https://hub.docker.com/r/gitea/gitea", + "description": "Gitea is a painless self-hosted all-in-one software development service, it includes Git hosting, code review, team collaboration, package registry and CI/CD. It is similar to GitHub, Bitbucket and GitLab. \n\n- Code Hosting\nGitea supports creating and managing repositories, browsing commit history and code files, reviewing and merging code submissions, managing collaborators, handling branches, and more. It also supports many common Git features such as tags, Cherry-pick, hooks, integrated collaboration tools, and more.\n\n- Lightweight and Fast\nOne of Gitea's design goals is to be lightweight and fast in response. Unlike some large code hosting platforms, it remains lean, performing well in terms of speed, and is suitable for resource-limited server environments. Due to its lightweight design, Gitea has relatively low resource consumption and performs well in resource-constrained environments.\n\n- Easy Deployment and Maintenance\nIt can be easily deployed on various servers without complex configurations or dependencies. This makes it convenient for individual developers or small teams to set up and manage their own Git services.\n\n- Security\nGitea places a strong emphasis on security, offering features such as user permission management, access control lists, and more to ensure the security of code and data.\n\n- Code Review\nCode review supports both the Pull Request workflow and AGit workflow. Reviewers can browse code online and provide review comments or feedback. Submitters can receive review comments and respond or modify code online. Code reviews can help individuals and organizations enhance code quality.\n\n- CI/CD\nGitea Actions supports CI/CD functionality, compatible with GitHub Actions. Users can write workflows in familiar YAML format and reuse a variety of existing Actions plugins. Actions plugins support downloading from any Git website.\n\n- Project Management\nGitea tracks project requirements, features, and bugs through columns and issues. Issues support features like branches, tags, milestones, assignments, time tracking, due dates, dependencies, and more.\n\n- Artifact Repository\nGitea supports over 20 different types of public or private software package management, including Cargo, Chef, Composer, Conan, Conda, Container, Helm, Maven, npm, NuGet, Pub, PyPI, RubyGems, Vagrant, and more.\n\n- Open Source Community Support\nGitea is an open-source project based on the MIT license. It has an active open-source community that continuously develops and improves the platform. The project also actively welcomes community contributions, ensuring updates and innovation.\n\n- Multilingual Support\nGitea provides interfaces in multiple languages, catering to users globally and promoting internationalization and localization.\n", + "website": "https://about.gitea.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Gitea/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-20", + "main_image": "gitea/gitea:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/gitea.json", + "template_status": "generated-unvalidated", + "content_hash": "898dcb083d50e327908f79c5925286bfc65c37d6181f703e054ea0cb8ebe2fbd", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "github-desktop", + "provider": "linuxserver.io", + "title": "Github Desktop", + "repository_name": "docker-github-desktop", + "repository": "https://github.com/linuxserver/docker-github-desktop", + "description": "Github Desktop is an open source Electron-based GitHub app. It is written in TypeScript and uses React.", + "website": "https://desktop.github.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/github-desktop-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T00:12:51Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/github-desktop:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/github-desktop.json", + "template_status": "generated-unvalidated", + "content_hash": "340f5476ceacc540de5985e42869bd06c0f0fc8cca0a87c70110f1172e45a03e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "gitqlient", + "provider": "linuxserver.io", + "title": "Gitqlient", + "repository_name": "docker-gitqlient", + "repository": "https://github.com/linuxserver/docker-gitqlient", + "description": "GitQlient is a multi-platform Git client originally forked from QGit. Nowadays it goes beyond of just a fork and adds a lot of new functionality.", + "website": "https://github.com/francescmm/GitQlient", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gitqlient-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T17:07:53Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/gitqlient:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/gitqlient.json", + "template_status": "generated-unvalidated", + "content_hash": "43abbf314e5c5e4df6bb06f22a861191d5ff02da81c4b30bc2aebc807e18d734", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "glances", + "source_app_id": "glances", + "provider": "nicolargo", + "template_family": "imported-compose", + "variant": null, + "title": "Glances", + "repository": "https://hub.docker.com/r/nicolargo/glances", + "description": "Glances is an open-source system cross-platform monitoring tool. It allows real-time monitoring of various aspects of your system such as CPU, memory, disk, network usage etc.", + "website": "https://nicolargo.github.io/glances/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Glances/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "nicolargo/glances:latest", + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "template": "apps/glances.json", + "template_status": "generated-unvalidated", + "content_hash": "3acd3e93cf8c7e4bde21759120191eccab5babcade9dcd04a320cef2e2bc3c95", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": true, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": true, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "requires_security_confirmation": true, + "hidden": false + }, + { + "id": "gopeed", + "source_app_id": "gopeed", + "provider": "liwei2633", + "template_family": "imported-compose", + "variant": null, + "title": "Gopeed", + "repository": "https://hub.docker.com/r/liwei2633/gopeed", + "description": "Gopeed is a modern high-speed download tool supporting HTTP, BitTorrent, and Magnet protocols, offering a beautiful interface and powerful functionality. Its lightweight design and multi-platform support make it ideal for efficient file downloading across various devices.\n\nThe tool's core features include high-speed downloading and an elegant interface. It leverages Golang coroutines for concurrent downloading, supporting HTTP, HTTPS, BitTorrent, and Magnet protocols for fast, stable performance. The interface follows Material Design standards, including a dark mode, balancing aesthetics and usability. Advanced features include seeding, DHT, PEX, uTP, Webtorrent, and UPnP support, with daily automatic tracker list updates to enhance download efficiency.\n\nIt provides a RESTful API for open integration, allowing users to remotely control download tasks, pause, or delete them. Decentralized extensions enable JavaScript plugins to enhance functionality, such as downloading videos or music from websites. The tool's speed, flexibility, and user-friendly design deliver a modern download solution.\n\n**Key Features:**\n- High-speed downloading with HTTP, BitTorrent, Magnet protocols\n- Seeding, DHT, PEX, uTP, Webtorrent, UPnP\n- Daily automatic tracker list updates\n- RESTful API for remote download task control\n- Decentralized extensions with JavaScript plugins\n\n**Learn More:**\n- [Gopeed Official Website](https://gopeed.com)\n- [Gopeed GitHub Repository](https://github.com/gopeedlab/gopeed)\n", + "website": "https://gopeed.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Gopeed/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-03-18", + "main_image": "liwei2633/gopeed:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/gopeed.json", + "template_status": "generated-unvalidated", + "content_hash": "0f6d14d6fb6be73ca132a1d5d4816217c17247f672f934fd67b5b13027a3875a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "grafana", + "source_app_id": "grafana", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Grafana", + "repository": "https://hub.docker.com/r/grafana/grafana", + "description": "Grafana open source is open source visualization and analytics software.Visualizations: Fast and flexible client side graphs with a multitude of options. Panel plugins offer many different ways to visualize metrics and logs. Dynamic Dashboards: Create dynamic & reusable dashboards with template variables that appear as dropdowns at the top of the dashboard. Explore Metrics: Explore your data through ad-hoc queries and dynamic drilldown. Split view and compare different time ranges, queries and data sources side by side. Explore Logs: Experience the magic of switching from metrics to logs with preserved label filters. Quickly search through all your logs or streaming them live. Alerting: Visually define alert rules for your most important metrics. Grafana will continuously evaluate and send notifications to systems like Slack, PagerDuty, VictorOps, OpsGenie. Mixed Data Sources: Mix different data sources in the same graph! You can specify a data source on a per-query basis. This works for even custom datasources.\n", + "website": "https://grafana.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Grafana/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-12", + "main_image": "grafana/grafana:latest", + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "template": "apps/grafana.json", + "template_status": "laboratory-validated", + "content_hash": "233860093c838ee21ec2cdca7a203deb5b8de17f0be1e796672fffcf11e8d4c3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "grav", + "provider": "linuxserver.io", + "title": "Grav", + "repository_name": "docker-grav", + "repository": "https://github.com/linuxserver/docker-grav", + "description": "Grav is a Fast, Simple, and Flexible, file-based Web-platform.", + "website": "https://github.com/getgrav/grav/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/grav-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-11T22:39:56Z", + "updated_at": "2026-06-27", + "main_image": "lscr.io/linuxserver/grav:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/grav.json", + "template_status": "generated-unvalidated", + "content_hash": "3d2c3c1febc7ce0b446c8d5044a5d70d6211bb1da766aeba7faa903dc64dbb22", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "grocy", + "provider": "linuxserver.io", + "title": "Grocy", + "repository_name": "docker-grocy", + "repository": "https://github.com/linuxserver/docker-grocy", + "description": "Grocy is an ERP system for your kitchen! Cut down on food waste, and manage your chores with this brilliant utility.", + "website": "https://github.com/grocy/grocy", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/grocy-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T13:04:43Z", + "updated_at": "2026-03-07", + "main_image": "lscr.io/linuxserver/grocy:latest", + "category": "gaming", + "category_label": "Gaming & Leisure", + "template": "apps/grocy.json", + "template_status": "generated-unvalidated", + "content_hash": "2aa466029f5147c1ec588c7addd54b57a6d1c9a47add459d669a1c7a91e5ef51", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "gzdoom", + "provider": "linuxserver.io", + "title": "Gzdoom", + "repository_name": "docker-gzdoom", + "repository": "https://github.com/linuxserver/docker-gzdoom", + "description": "GZDoom is a feature centric port for all Doom engine games, based on ZDoom, adding an OpenGL renderer and powerful scripting capabilities.", + "website": "https://gzdoom.app/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/gzdoom-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T00:15:20Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/gzdoom:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/gzdoom.json", + "template_status": "generated-unvalidated", + "content_hash": "b8d8ab7e5cbb9c178b1d5e83f6a3bb077675af88e51e6b5e3ae75aa7d003b500", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "habridge", + "provider": "linuxserver.io", + "title": "Habridge", + "repository_name": "docker-habridge", + "repository": "https://github.com/linuxserver/docker-habridge", + "description": "Habridge emulates Philips Hue API to other home automation gateways such as an Amazon Echo/Dot Gen 1 (gen 2 has issues discovering ha-bridge) or other systems that support Philips Hue. The Bridge handles basic commands such as On, Off and brightness commands of the hue protocol. This bridge can control most devices that have a distinct API.", + "website": "https://github.com/bwssytems/ha-bridge/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/habridge-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-07-03T23:18:53Z", + "updated_at": "2024-06-27", + "main_image": "lscr.io/linuxserver/habridge:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/habridge.json", + "template_status": "generated-unvalidated", + "content_hash": "a822928bdd3bd3fdc19dbcd7d16ee178965e6fdd8288b1047e9b59d4cadfbb5c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "handbrake", + "provider": "linuxserver.io", + "title": "Handbrake", + "repository_name": "docker-handbrake", + "repository": "https://github.com/linuxserver/docker-handbrake", + "description": "HandBrake is an open-source tool, built by volunteers, for converting video from nearly any format to a selection of modern, widely supported codecs.", + "website": "https://handbrake.fr/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/handbrake-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T14:49:26Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/handbrake:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/handbrake.json", + "template_status": "generated-unvalidated", + "content_hash": "dd4eda75149e2fda09a2387579f4f59b1e3ffa23be520ce4e76358009dc7b2b2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "handbrake-jlesage", + "source_app_id": "handbrake", + "provider": "jlesage", + "template_family": "imported-compose", + "variant": null, + "title": "handbrake", + "repository": "https://hub.docker.com/r/jlesage/handbrake", + "description": "Handbrake is a Docker-based application for video transcoding and compression, offering powerful and flexible multimedia processing across multiple platforms.", + "website": "https://handbrake.fr", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/Handbrake/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "jlesage/handbrake:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/handbrake-jlesage.json", + "template_status": "generated-unvalidated", + "content_hash": "8737b8977451d4b9e9f9c2a9839f8d92e9977befd3b308cb6ba272e6abce1b41", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "haos-one", + "provider": "qweritos", + "template_family": "curated-profile", + "title": "HAOS One", + "repository": "https://github.com/qweritos/haos-one", + "description": "Community HAOS One image adapted as a native Proxmox OCI LXC with persistent Supervisor, Core, add-ons and backups under /mnt/data.", + "website": "https://github.com/qweritos/haos-one", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-08-20", + "main_image": "qweritos/haos-one:latest", + "category": "smarthome", + "category_label": "IoT & Smart Home", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/haos-one.json", + "template": "apps/haos-one.json", + "template_status": "generated-unvalidated", + "content_hash": "7e817118efb64ed24d1bf6d7a2088b15d24fb4333c12b2d12e2e0b48a581e09f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "healthchecks", + "provider": "linuxserver.io", + "title": "Healthchecks", + "repository_name": "docker-healthchecks", + "repository": "https://github.com/linuxserver/docker-healthchecks", + "description": "Healthchecks is a watchdog for your cron jobs. It's a web server that listens for pings from your cron jobs, plus a web interface.", + "website": "https://github.com/healthchecks/healthchecks", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/healthchecks-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T14:43:58Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/healthchecks:latest", + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "template": "apps/healthchecks.json", + "template_status": "generated-unvalidated", + "content_hash": "32dd421e75b32d98dac09ce394d38726862fdf3b9439e8d2e5108841d0c4fd1f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "hedgedoc", + "provider": "linuxserver.io", + "title": "Hedgedoc", + "repository_name": "docker-hedgedoc", + "repository": "https://github.com/linuxserver/docker-hedgedoc", + "description": "HedgeDoc gives you access to all your files wherever you are.", + "website": "https://hedgedoc.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/hedgedoc-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-09T22:04:01Z", + "updated_at": "2026-07-29", + "main_image": "lscr.io/linuxserver/hedgedoc:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/hedgedoc.json", + "template_status": "generated-unvalidated", + "content_hash": "1cbc155638760ea9d871454c1d79f9f4ca7b2a646b4d8ad96b4f91cc7a422be2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "heimdall", + "provider": "linuxserver.io", + "title": "Heimdall", + "repository_name": "docker-heimdall", + "repository": "https://github.com/linuxserver/docker-heimdall", + "description": "Heimdall is a way to organise all those links to your most used web sites and web applications in a simple way.", + "website": "https://heimdall.site", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/heimdall-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T21:14:01Z", + "updated_at": "2026-07-14", + "main_image": "lscr.io/linuxserver/heimdall:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/heimdall.json", + "template_status": "generated-unvalidated", + "content_hash": "460fcddde0f8011c7c127c9d1bad5f847cee67093cdabb3266d26d7586a331f3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "helium", + "provider": "linuxserver.io", + "title": "Helium", + "repository_name": "docker-helium", + "repository": "https://github.com/linuxserver/docker-helium", + "description": "Helium is a Chromium-based web browser made for people, with love. Privacy-first with unbiased ad-blocking.", + "website": "https://helium.computer/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/helium-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T14:29:44Z", + "updated_at": "2026-04-15", + "main_image": "lscr.io/linuxserver/helium:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/helium.json", + "template_status": "generated-unvalidated", + "content_hash": "2c213623ffd8246b3c0805747ac126d76b9aae81a96c06dfc5affeb967432dc2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "hermes", + "source_app_id": "hermes", + "provider": "nousresearch", + "template_family": "imported-compose", + "variant": null, + "title": "Hermes", + "repository": "https://hub.docker.com/r/nousresearch/hermes-agent", + "description": "Hermes Agent is a self-improving AI agent from Nous Research, designed to be a long-running collaborator rather than a one-off chatbot.\nIts built-in learning loop combines persistent memory, cross-session recall, and reusable skills so it can keep context and improve recurring workflows over time.\nWith a unified gateway, rich toolsets, and a browser-based dashboard, Hermes fits research, automation, cross-platform communication, and ongoing operational work.\n\n**Main Features:**\n- Built-in learning loop with persistent memory, session search, and reusable skills\n- One gateway for CLI, Telegram, Discord, Slack, WhatsApp, Signal, and more\n- Tool-driven workflows with terminal access, web search, browser automation, file editing, and MCP integration\n- Automation and coordination with cron jobs, subagents, the web dashboard, and an OpenAI-compatible API\n\n**Learn More:**\n- [Hermes Agent Official Website](https://hermes-agent.nousresearch.com/)\n- [Hermes Agent GitHub](https://github.com/NousResearch/hermes-agent)\n- [Hermes Agent Documentation](https://hermes-agent.nousresearch.com/docs/)\n", + "website": "https://hermes-agent.nousresearch.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Hermes/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-06-05", + "main_image": "nousresearch/hermes-agent:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/hermes.json", + "template_status": "generated-unvalidated", + "content_hash": "21e7836e7ab9cfc90e043e71f312b6051864357550ebdfd9fd084d7149dfd254", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "hishtory-server", + "provider": "linuxserver.io", + "title": "Hishtory Server", + "repository_name": "docker-hishtory-server", + "repository": "https://github.com/linuxserver/docker-hishtory-server", + "description": "hiSHtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers.", + "website": "https://github.com/ddworken/hishtory", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/hishtory-server-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-11T07:39:19Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/hishtory-server:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/hishtory-server.json", + "template_status": "generated-unvalidated", + "content_hash": "45aa45c3ed882f849ad8a36db5426eeac9dc5193c956d07cd987b8cc30f89dd6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "holoplay", + "source_app_id": "holoplay", + "provider": "spout8301", + "template_family": "imported-compose", + "variant": null, + "title": "HoloPlay", + "repository": "https://hub.docker.com/r/spout8301/holoplay", + "description": "HoloPlay is a web based self-hosted using Invidious API for listening Youtube audio source.", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/HoloPlay/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-07-22", + "main_image": "spout8301/holoplay:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/holoplay.json", + "template_status": "generated-unvalidated", + "content_hash": "c8c13100b65ff4ca33b41edfb415aca273d236f92a17356ca31c4efe61f500d1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "homeassistant", + "provider": "linuxserver.io", + "title": "Homeassistant", + "repository_name": "docker-homeassistant", + "repository": "https://github.com/linuxserver/docker-homeassistant", + "description": "Home Assistant Core - Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server", + "website": "https://www.home-assistant.io/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/homeassistant-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-11T21:00:06Z", + "updated_at": "2026-07-02", + "main_image": "lscr.io/linuxserver/homeassistant:latest", + "category": "smarthome", + "category_label": "IoT & Smart Home", + "template": "apps/homeassistant.json", + "template_status": "generated-unvalidated", + "content_hash": "7fc947ae7aaeb257754d85aeee005bd3ce0f2d8ace5e92290cd29f01df9446a4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "homeassistant-official", + "source_app_id": "homeassistant", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Home Assistant", + "repository": "https://hub.docker.com/r/homeassistant/home-assistant", + "description": "Home Assistant is a smart home management app prioritizing local control and data privacy, managing devices through an intuitive interface with data stored locally, eliminating cloud dependency. Its robust features and community support make it ideal for DIY enthusiasts and home users creating personalized home experiences.\n\nThe app's core features include customizable dashboards, powerful automations, and a voice assistant. Dashboards support drag-and-drop customization, with various card types to display data and control devices like lights or sensors. It offers an advanced automation engine, such as turning on lights at sunset or alerting users to an open garage door. The Assist voice assistant enables natural language control, compatible with phones, tablets, smartwatches, and even traditional telephones, allowing users to customize interactions and experiment with AI conversations to meet diverse needs.\n\nIt extends functionality through add-ons, supporting tools like AdGuard for ad blocking, NodeRed for third-party automations, or turning devices into Spotify Connect targets. Home energy management optimizes solar production and usage planning to save costs. Home Assistant Cast transforms TVs into dashboard displays, and NFC tags trigger music playback or routine automations. Community documentation aids configuration, with local data processing ensuring privacy, suitable for home or small team smart home management.\n\n**Key Features:**\n- Local data storage, prioritizing privacy\n- Drag-and-drop customizable dashboards for device control and data display\n- Advanced automations for triggering smart home events\n- Assist voice assistant for natural language control\n- Add-ons for integrating AdGuard, NodeRed, and more\n- Home energy management for optimized usage and cost savings\n- Home Assistant Cast for TV dashboard displays\n- NFC tags for triggering music or automation tasks\n\n**Learn More:**\n- [Home Assistant Official Website](https://www.home-assistant.io)\n- [Home Assistant GitHub Repository](https://github.com/home-assistant/core)\n- [Home Assistant Documentation](https://www.home-assistant.io/docs)\n- [Home Assistant Community](https://community.home-assistant.io)\n- [Home Assistant Add-ons](https://www.home-assistant.io/addons)\n", + "website": "https://www.home-assistant.io", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/HomeAssistant/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-22", + "main_image": "homeassistant/home-assistant:latest", + "category": "smarthome", + "category_label": "IoT & Smart Home", + "template": "apps/homeassistant-official.json", + "template_status": "generated-unvalidated", + "content_hash": "c0d8168fddf1dde10c064f7d43464133b166c9863488b869ef8dd65d3e35e822", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "homebridge", + "source_app_id": "homebridge", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Homebridge", + "repository": "https://hub.docker.com/r/homebridge/homebridge", + "description": "Homebridge is a lightweight NodeJS server you can run on your home network that emulates the iOS HomeKit API. It supports Plugins, which are community-contributed modules that provide a basic bridge from HomeKit to various 3rd-party APIs provided by manufacturers of \"smart home\" devices.", + "website": "https://homebridge.io/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Homebridge/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-13", + "main_image": "homebridge/homebridge:latest", + "category": "smarthome", + "category_label": "IoT & Smart Home", + "template": "apps/homebridge.json", + "template_status": "generated-unvalidated", + "content_hash": "d9b674d72bdebe38949ff5012eb7f87705e33b00929f12a3a5c0e48a62ff904e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "htpcmanager", + "provider": "linuxserver.io", + "title": "Htpcmanager", + "repository_name": "docker-htpcmanager", + "repository": "https://github.com/linuxserver/docker-htpcmanager", + "description": "Htpcmanager is a front end for many htpc related applications.", + "website": "https://github.com/HTPC-Manager/HTPC-Manager", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/htpcmanager-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T01:45:20Z", + "updated_at": "2024-06-27", + "main_image": "lscr.io/linuxserver/htpcmanager:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/htpcmanager.json", + "template_status": "generated-unvalidated", + "content_hash": "be7d35d539b80274bdee5287b40e098c88e0488ac5c59705ffe58c60ae088be9", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "hugo", + "source_app_id": "hugo", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Hugo", + "repository": "https://ghcr.io/gohugoio/hugo", + "description": "Hugo is a high-speed static site generation platform written in Go, optimized for speed and designed for flexibility. Advanced templating system and fast asset pipelines render a complete website in seconds, ideal for creating documentation sites, landing pages, and various project websites.\n\nCore features include optimized speed and a flexible framework. Concurrency in Go enables rapid rendering, supporting image processing (convert, resize, crop, rotate, adjust colors, apply filters, overlay text/images, extract EXIF data), JavaScript bundling (tree shaking, code splitting), Sass processing, and TailwindCSS support. Multilingual support and taxonomy system make it suitable for diverse sites like documentation, news, or events.\n\nIt includes an embedded web server for real-time previews of content, structure, and style changes during development. Frequent releases ensure ongoing feature enhancements, keeping it cutting-edge. With efficiency and flexibility at the core, the platform delivers a modern static site generation solution.\n\n**Key Features:**\n- High-speed rendering, generating sites in seconds\n- Fast asset pipelines: image processing, JavaScript bundling, Sass, and TailwindCSS support\n- Flexible framework with multilingual and taxonomy systems\n- Embedded web server for real-time development previews\n- Rich ecosystem of themes and plugins\n\n\n**Prerequisites for Using Hugo:**\n\n1. Open command line, navigate to `/DATA/AppData/hugo/project` directory\n\n```cd /DATA/AppData/hugo/project```\n\n2. Initialize the `project` directory as an empty Git repository\n\n```git init```\n\n3. Download the Ananke theme\n\n```git submodule add https://github.com/theNewDynamic/gohugo-theme-ananke.git themes/ananke```\n\n4. Specify the current theme\n\n```echo \"theme = 'ananke'\" >> hugo.toml```\n\n5. Restart Hugo\n\n\n**Learn More:**\n- [Hugo Official Website](https://gohugo.io/)\n- [Hugo GitHub](https://github.com/gohugoio/hugo)\n", + "website": "https://gohugo.io/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Hugo/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-29", + "main_image": "ghcr.io/gohugoio/hugo:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/hugo.json", + "template_status": "generated-unvalidated", + "content_hash": "cc1e4196d8e67b7ad39f45c5e1df6632eed1346803536d65e15444337ab8651f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "immich", + "provider": "immich", + "template_family": "curated-profile", + "title": "Immich", + "repository": "https://github.com/immich-app/immich", + "description": "Immich as a coordinated four-LXC native OCI stack with private PostgreSQL and Valkey services, persistent media and model cache, and selectable hardware acceleration.", + "website": "https://immich.app/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-12", + "main_image": "ghcr.io/immich-app/immich-server:release", + "category": "media", + "category_label": "Media", + "replaces_discovered_ids": [ + "immich" + ], + "curated_path": "catalog/curated/immich.json", + "template": "apps/immich.json", + "template_status": "laboratory-validated", + "content_hash": "4cab5178521f8495588b8432717832857c911ed0012fd6bd48efbb7ab80b80a6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "index-tts", + "source_app_id": "index-tts", + "provider": "icewhaletech", + "template_family": "imported-compose", + "variant": null, + "title": "Index-TTS", + "repository": "https://hub.docker.com/r/icewhaletech/index-tts", + "description": "IndexTTS2 is an advanced zero-shot text-to-speech model that innovatively achieves complete decoupling of emotional expression and speaker identity. The model supports precise speech duration control and multimodal emotion control, capable of maintaining the target timbre while accurately reproducing the specified emotional intonation.\n\nThe model employs a three-stage training paradigm and introduces GPT latent representations, ensuring excellent speech clarity and stability even under high emotional expression. Through the Qwen-based soft instruction mechanism, users can easily control the emotional characteristics of generated speech using natural language descriptions.\n\nIn multi-dataset evaluations, IndexTTS2 surpasses existing zero-shot TTS models in key metrics such as word error rate, speaker similarity, and emotion fidelity, providing industry-leading speech synthesis quality.\n\n**Key Features:**\n- Zero-shot TTS capability to replicate any timbre without training\n- Independent control of emotion and timbre with multimodal emotion input\n- Precise duration control with explicit token count specification for perfect audio-video synchronization\n- Natural language-based emotion control to guide speech generation through text descriptions\n\n**Additional Notes:**\n- Please ensure available memory > 12 GB, otherwise the application may not run properly\n- This application runs on CPU by default. This mode has low computational efficiency and will cause extremely high resource consumption and potential system instability. For optimal performance and stability, it is strongly recommended to use NVIDIA GPU to run this application\n- If you need to use NVIDIA GPU, please select \"Custom Install\" and enable the GPU option (supported in self-hosted server 1.5.0 and above)\n- For NVIDIA GPU usage, \u2265 8 GB VRAM is required (recommended for optimal performance)\n- For NVIDIA GPU usage, NVIDIA CUDA Toolkit version \u2265 12.8 is required\n\n**Learn More:**\n- [IndexTTS GitHub](https://github.com/index-tts/index-tts)\n", + "website": "", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/Index-TTS/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "icewhaletech/index-tts:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/index-tts.json", + "template_status": "generated-unvalidated", + "content_hash": "daa4048d982c733b3d19ea1acf30ec794f5d6aae20b4d54e208483f35860abc5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "inkscape", + "provider": "linuxserver.io", + "title": "Inkscape", + "repository_name": "docker-inkscape", + "repository": "https://github.com/linuxserver/docker-inkscape", + "description": "Inkscape is professional quality vector graphics software which runs on Linux, Mac OS X and Windows desktop computers.", + "website": "https://inkscape.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/inkscape-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T01:54:59Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/inkscape:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/inkscape.json", + "template_status": "generated-unvalidated", + "content_hash": "e16bb57dd452200d6d57bfe39a6bb850b1d58095afca5ac035892aa76e45361d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "intellij-idea", + "provider": "linuxserver.io", + "title": "Intellij Idea", + "repository_name": "docker-intellij-idea", + "repository": "https://github.com/linuxserver/docker-intellij-idea", + "description": "IntelliJ IDEA helps you write code faster with tools that eliminate tedious tasks and let you focus on what matters \u2013 building great software.", + "website": "https://www.jetbrains.com/idea/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/intellij-idea-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-06T21:23:59Z", + "updated_at": "2026-05-18", + "main_image": "lscr.io/linuxserver/intellij-idea:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/intellij-idea.json", + "template_status": "generated-unvalidated", + "content_hash": "8b0718256a4a838336d405b486487387a929f7e95856462ba5ee1ef18ba4effc", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "jackett", + "provider": "linuxserver.io", + "title": "Jackett", + "repository_name": "docker-jackett", + "repository": "https://github.com/linuxserver/docker-jackett", + "description": "Jackett works as a proxy server: it translates queries from apps (Sonarr, SickRage, CouchPotato, Mylar, etc) into tracker-site-specific http queries, parses the html response, then sends results back to the requesting software. This allows for getting recent uploads (like RSS) and performing searches. Jackett is a single repository of maintained indexer scraping & translation logic - removing the burden from other apps.", + "website": "https://github.com/Jackett/Jackett", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jackett-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T10:40:23Z", + "updated_at": "2026-07-14", + "main_image": "lscr.io/linuxserver/jackett:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/jackett.json", + "template_status": "generated-unvalidated", + "content_hash": "1c1fe77e445cbd2d1db67bc397ec88e796cf359309f71d6e8a239bf4853c104d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "jdownloader", + "provider": "jlesage", + "template_family": "curated-profile", + "title": "JDownloader", + "repository": "https://github.com/jlesage/docker-jdownloader-2", + "description": "The maintained jlesage JDownloader 2 image adapted as a native Proxmox OCI LXC with persistent configuration and shared downloads.", + "website": "https://jdownloader.org/", + "icon": null, + "architectures": [ + "amd64" + ], + "updated_at": "2026-08-26", + "main_image": "jlesage/jdownloader-2:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "replaces_discovered_ids": [ + "jdownloader2" + ], + "curated_path": "catalog/curated/jdownloader.json", + "template": "apps/jdownloader.json", + "template_status": "laboratory-validated", + "content_hash": "49466605a5831af3ed81ef72d52bd6a0cd21fd805932b4e1eed81b768be641ad", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "jellyfin", + "provider": "linuxserver.io", + "title": "Jellyfin", + "repository_name": "docker-jellyfin", + "repository": "https://github.com/linuxserver/docker-jellyfin", + "description": "Jellyfin is a Free Software Media System that puts you in control of managing and streaming your media. It is an alternative to the proprietary Emby and Plex, to provide media from a dedicated server to end-user devices via multiple apps. Jellyfin is descended from Emby's 3.5.2 release and ported to the .NET Core framework to enable full cross-platform support. There are no strings attached, no premium licenses or features, and no hidden agendas: just a team who want to build something better and work together to achieve it.", + "website": "https://github.com/jellyfin/jellyfin", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T02:43:27Z", + "updated_at": "2026-07-14", + "main_image": "lscr.io/linuxserver/jellyfin:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/jellyfin.json", + "template_status": "generated-unvalidated", + "content_hash": "2dd8c7de4ed18fbf753f39fe92ee4d9913cf25d0b8134d1e851aa7999f8c8f03", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "jellyfin-official", + "provider": "jellyfin", + "template_family": "curated-profile", + "title": "Jellyfin Official", + "repository": "https://github.com/jellyfin/jellyfin-packaging", + "description": "Jellyfin is a Free Software Media System that puts you in control of managing and streaming your media. It is an alternative to the proprietary Emby and Plex, to provide media from a dedicated server to end-user devices via multiple apps. Jellyfin is descended from Emby's 3.5.2 release and ported to the .NET Core framework to enable full cross-platform support. There are no strings attached, no premium licenses or features, and no hidden agendas: just a team who want to build something better and work together to achieve it.", + "website": "https://jellyfin.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": null, + "main_image": "jellyfin/jellyfin:latest", + "category": "media", + "category_label": "Media & Streaming", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/jellyfin-official.json", + "template": "apps/jellyfin-official.json", + "template_status": "generated-unvalidated", + "content_hash": "4c6c9892cb1570bfa2f67205956b7a9d2be82ac9a51406c07b11196d24305e1c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "jellyseerr", + "source_app_id": "jellyseerr", + "provider": "fallenbagel", + "template_family": "imported-compose", + "variant": null, + "title": "Jellyseerr", + "repository": "https://hub.docker.com/r/fallenbagel/jellyseerr", + "description": "Jellyseerr is a self-hosted media request and management tool designed to streamline media library request and discovery processes, offering an intuitive Web interface, ideal for home media server users and small teams. It seamlessly integrates with existing media services, enabling efficient management of movies, shows, and mixed content libraries.\n\nThe tool's core features include a customizable request system and broad media server integration. It allows users to request movies or individual show seasons through a user-friendly interface, with administrators able to approve requests via a simple management UI. It integrates with Jellyfin, Emby, and Plex, supporting user import and authentication with existing accounts. Diverse notification channels (e.g., Discord, Telegram, Email) provide real-time request status updates, and library scanning tracks available media to prevent duplicate requests.\n\nIt offers a granular permission system, enabling precise control over user access and actions. The mobile-friendly design facilitates on-the-go request approvals, while watchlist and blacklist support help users filter content. Support for PostgreSQL and SQLite databases ensures flexible deployment options. Community support via GitHub and Discord provides documentation and assistance, delivering a modern media management solution with intuitive operation and high flexibility.\n\n**Key Features:**\n- Full Jellyfin/Emby/Plex integration including authentication with user import & management.\n- Support for PostgreSQL and SQLite databases.\n- Supports Movies, Shows and Mixed Libraries.\n- Ability to change email addresses for SMTP purposes.\n- Easy integration with your existing services. Currently, Jellyseerr supports Sonarr and Radarr.\n- Jellyfin/Emby/Plex library scan, to keep track of the titles which are already available.\n- Customizable request system, which allows users to request individual seasons or movies in a friendly, easy-to-use interface.\n- Incredibly simple request management UI. Don't dig through the app to simply approve recent requests!\n- Granular permission system.\n- Support for various notification agents.\n- Mobile-friendly design, for when you need to approve requests on the go!\n- Support for watchlisting & blacklisting media.\n\n**Learn More:**\n- [Jellyseerr Documentation](https://docs.jellyseerr.dev/)\n- [Jellyseerr GitHub Repository](https://github.com/Fallenbagel/jellyseerr)\n", + "website": "https://seerr.dev/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Jellyseerr/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-08-14", + "main_image": "fallenbagel/jellyseerr:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/jellyseerr.json", + "template_status": "generated-unvalidated", + "content_hash": "0d28c61a767b4859af16be46bd6f75f4c6839a57b24b0be6d98c07f807def569", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "jenkins", + "source_app_id": "jenkins", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Jenkins CI/CD", + "repository": "https://hub.docker.com/r/jenkins/jenkins", + "description": "A server for creating pipelines for Jenkins continuous integration and delivery.", + "website": "https://www.jenkins.io/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Jenkin/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-03-18", + "main_image": "jenkins/jenkins:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/jenkins.json", + "template_status": "laboratory-validated", + "content_hash": "65ad6556818ae2a78fa96d064094d79b8a0affa14f75ee774f9de023cc9d2e37", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "joplin", + "provider": "linuxserver.io", + "title": "Joplin", + "repository_name": "docker-joplin", + "repository": "https://github.com/linuxserver/docker-joplin", + "description": "Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.", + "website": "https://joplinapp.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/joplin-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T19:58:57Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/joplin:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/joplin.json", + "template_status": "generated-unvalidated", + "content_hash": "edc8231ac1a6b45570600949ae3db3b41b8c2dea35b8be1b70fb1d6bb09930bc", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "kali-linux", + "provider": "linuxserver.io", + "title": "Kali Linux", + "repository_name": "docker-kali-linux", + "repository": "https://github.com/linuxserver/docker-kali-linux", + "description": "Kali-linux - is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. KALI LINUX \u2122 is a trademark of OffSec.", + "website": "https://github.com/linuxserver/docker-kali-linux", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kali-linux-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T00:53:19Z", + "updated_at": "2026-03-29", + "main_image": "lscr.io/linuxserver/kali-linux:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/kali-linux.json", + "template_status": "generated-unvalidated", + "content_hash": "16ad4a1d5e51021cc3e81ec206712ae888a5bdcf4cd409665c971d03962d65ae", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "karakeep", + "source_app_id": "karakeep", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Karakeep", + "repository": "https://ghcr.io/karakeep-app/karakeep", + "description": "Karakeep is an open-source, self-hosted bookmark manager for links, notes, images, PDFs, and highlights, built to keep everything you want to save in one place.\nIt automatically fetches titles, descriptions, and previews, then helps you organize your library with AI tagging, full-text search, lists, and rule-based automation.\nWith browser extensions, mobile apps, RSS ingestion, and page archiving, Karakeep works well as both a read-later tool and a durable personal content archive.\n\n**Main Features:**\n- Save links, notes, images, PDFs, and text highlights in one library\n- Auto-fetch titles, descriptions, images, and archived pages for later reading\n- Use AI tagging, summarization, OCR, and full-text search to rediscover content quickly\n- Organize content with tags, collaborative lists, RSS feeds, and rule-based workflows\n- Access your collection through the web app, mobile apps, browser extensions, REST API, and CLI\n\n**Learn More:**\n- [Karakeep Official Website](https://karakeep.app/)\n- [Karakeep GitHub](https://github.com/karakeep-app/karakeep)\n- [Karakeep Documentation](https://docs.karakeep.app/)\n", + "website": "https://karakeep.app/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Karakeep/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ghcr.io/karakeep-app/karakeep:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/karakeep.json", + "template_status": "generated-review-required", + "content_hash": "abb0876d91ad1e5ca5580512e6db2284e8e2417fd5a393e95c50dc73f81c694d", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "kasm", + "provider": "linuxserver.io", + "title": "Kasm", + "repository_name": "docker-kasm", + "repository": "https://github.com/linuxserver/docker-kasm", + "description": "Kasm Workspaces is a docker container streaming platform for delivering browser-based access to desktops, applications, and web services. Kasm uses devops-enabled Containerized Desktop Infrastructure (CDI) to create on-demand, disposable, docker containers that are accessible via web browser. Example use-cases include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), Desktop as a Service (DaaS), Secure Remote Access Services (RAS), and Open Source Intelligence (OSINT) collections.", + "website": "https://www.kasmweb.com/?utm_campaign=LinuxServer&utm_source=listing", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kasm-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T23:53:43Z", + "updated_at": "2026-08-04", + "main_image": "lscr.io/linuxserver/kasm:latest", + "category": "remote", + "category_label": "Remote Access & VPN", + "template": "apps/kasm.json", + "template_status": "generated-unvalidated", + "content_hash": "0433a0ebb85b6ba3c9c714c6b99e560dc07b5e18d6bd44af32893e43017bc12a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": true, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "kavita", + "provider": "linuxserver.io", + "title": "Kavita", + "repository_name": "docker-kavita", + "repository": "https://github.com/linuxserver/docker-kavita", + "description": "Kavita is a fast, feature rich, cross platform reading server. Built with a focus for being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family!", + "website": "https://github.com/Kareadita/Kavita", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kavita-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-11T19:00:02Z", + "updated_at": "2026-09-11", + "main_image": "lscr.io/linuxserver/kavita:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/kavita.json", + "template_status": "generated-unvalidated", + "content_hash": "8c9699f694d326fa5d01320fe37801a3c02769d21bd2011d3c4c868a2eb1bd9e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "kavita-jvmilazz0", + "source_app_id": "kavita", + "provider": "jvmilazz0", + "template_family": "imported-compose", + "variant": null, + "title": "Kavita", + "repository": "https://hub.docker.com/r/jvmilazz0/kavita", + "description": "Kavita is a self-hosted digital library app designed for managing and reading comics, light novels, and e-books (supporting CBZ, CBR, EPUB, PDF, and more), offering a secure and convenient solution for personal reading collections. Its responsive Web interface allows users to access content effortlessly via any browser, with fullscreen reading and full localization support, ideal for comic and e-book enthusiasts building personalized digital libraries.\n\nThe app's core features include robust library management and an enhanced reading experience. Users can organize content with collections, reading lists, and custom tags, editing metadata to keep libraries neatly arranged. The built-in manga reader supports dual-page mode, Webtoon scrolling, and image splitting, while the e-book reader offers customizable fonts, spacing, and themes, with by-line progress syncing across devices. The PDF reader provides light/dark modes and diverse settings. It supports multi-user management, allowing custom permissions for sharing libraries or restricting content access, perfect for family or team use. Bulk imports and full-text search streamline large collection management.\n\nIt can be flexibly deployed on personal servers or NAS devices, with an active community providing extensive documentation to enhance functionality. Folder monitoring automatically detects file changes without manual scans, and sending content to Kindle or other devices improves cross-device access. Whether creating a personal reading hub or sharing media with others, the app's intuitive interface and high customizability deliver a modern management platform, meeting needs from casual reading to professional collections.\n\n**Key Features:**\n- Serve up Manga/Webtoons/Comics (cbr, cbz, zip/rar/rar5, 7zip, raw images) and Books (epub, pdf)\n- First class responsive readers that work great on any device (phone, tablet, desktop)\n- Customizable theming support: [Theme Repo](https://github.com/Kareadita/Themes) and [Documentation](https://wiki.kavitareader.com/guides/themes/)\n- External metadata integration and scrobbling for read status, ratings, and reviews (available via Kavita+)\n- Rich Metadata support with filtering and searching\n- Ways to group reading material: Collections, Reading Lists (CBL Import), Want to Read\n- Ability to manage users with rich Role-based management for age restrictions, abilities within the app, etc\n- Rich web readers supporting webtoon, continuous reading mode (continue without leaving the reader), virtual pages (epub), etc\n- Ability to customize your dashboard and side nav with smart filters, custom order and visibility toggles\n- Ability to download metadata (available via Kavita+)\n\n**Learn More:**\n- [Kavita Official Website](https://www.kavitareader.com)\n- [Kavita GitHub Repository](https://github.com/Kareadita/Kavita)\n", + "website": "https://www.kavitareader.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Kavita/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-14", + "main_image": "jvmilazz0/kavita:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/kavita-jvmilazz0.json", + "template_status": "generated-unvalidated", + "content_hash": "a6509341fdc1c2ea1e960e48f1bb0054e3a686a715284a713084b4fb5be8fd2e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "kdenlive", + "provider": "linuxserver.io", + "title": "Kdenlive", + "repository_name": "docker-kdenlive", + "repository": "https://github.com/linuxserver/docker-kdenlive", + "description": "Kdenlive is a powerful free and open source cross-platform video editing program made by the KDE community. Feature rich and production ready.", + "website": "https://kdenlive.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kdenlive-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T14:57:40Z", + "updated_at": "2026-03-29", + "main_image": "lscr.io/linuxserver/kdenlive:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/kdenlive.json", + "template_status": "generated-unvalidated", + "content_hash": "da38a79d680b6dfb2a2f096575e0ad31fdf403764b6fdc91f803ed6afde2274f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "keepassxc", + "provider": "linuxserver.io", + "title": "Keepassxc", + "repository_name": "docker-keepassxc", + "repository": "https://github.com/linuxserver/docker-keepassxc", + "description": "KeePassXC is a free and open-source password manager. It started as a community fork of KeePassX (itself a cross-platform port of KeePass).", + "website": "https://keepassxc.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/keepassxc-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T12:09:50Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/keepassxc:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/keepassxc.json", + "template_status": "generated-unvalidated", + "content_hash": "8a45a46593c2532263617b77b94cc23772aebff155c07abeafbfe368540408be", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "kicad", + "provider": "linuxserver.io", + "title": "Kicad", + "repository_name": "docker-kicad", + "repository": "https://github.com/linuxserver/docker-kicad", + "description": "KiCad - A Cross Platform and Open Source Electronics Design Automation Suite.", + "website": "https://www.kicad.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kicad-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T15:38:41Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/kicad:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/kicad.json", + "template_status": "generated-unvalidated", + "content_hash": "7fb41022747d47c6b2e3f02448f4a986c46e2eff9ca9e74bf790743698c77a50", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "kimai", + "provider": "linuxserver.io", + "title": "Kimai", + "repository_name": "docker-kimai", + "repository": "https://github.com/linuxserver/docker-kimai", + "description": "Kimai is a professional grade time-tracking application, free and open-source.", + "website": "https://kimai.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kimai-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-12T00:49:44Z", + "updated_at": "2027-07-04", + "main_image": "lscr.io/linuxserver/kimai:latest", + "category": "business", + "category_label": "Business & ERP", + "template": "apps/kimai.json", + "template_status": "generated-unvalidated", + "content_hash": "1bf2e64488d7179e488a059b39de4e71a4621c8366212dcd244c96833c63656c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "kometa", + "provider": "linuxserver.io", + "title": "Kometa", + "repository_name": "docker-kometa", + "repository": "https://github.com/linuxserver/docker-kometa", + "description": "Kometa is a powerful tool designed to give you complete control over your media libraries. With Kometa, you can take your customization to the next level, with granular control over metadata, collections, overlays, and much more.", + "website": "https://github.com/Kometa-Team/Kometa", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/kometa-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-13T17:13:50Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/kometa:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/kometa.json", + "template_status": "generated-unvalidated", + "content_hash": "ce63980a05cbd8677668ace1ed71051001b61a99501d453463aafff598f1bcc7", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "komga", + "source_app_id": "komga", + "provider": "gotson", + "template_family": "imported-compose", + "variant": null, + "title": "Komga", + "repository": "https://hub.docker.com/r/gotson/komga", + "description": "Komga is a self-hosted app designed for managing comics, manga, magazines, and e-books (supporting CBZ, CBR, PDF, and EPUB formats), offering a secure and convenient solution for personal media libraries. Its responsive Web interface enables users to access and manage content effortlessly via any browser, without complex local installations, ideal for comic and e-book enthusiasts.\n\nThe app's core features include versatile content organization and diverse reading options. Users can arrange their library with collections and reading lists, edit metadata for series or books, and keep content neatly organized. It integrates a built-in Web reader, supports Mihon SDK extensions, or connects with third-party OPDS readers, catering to varied reading preferences. Whether managing a personal comic collection or sharing e-books with family, it supports multi-user access and delivers a smooth browsing experience. Bulk import streamlines large media library management, perfect for efficient content organization.\n\nIt can be flexibly deployed on personal servers or NAS devices, with an active community providing support documentation, enabling users to extend functionality through community resources. Whether building a personal digital library or a private media-sharing hub, the app's intuitive interface and high customizability offer a secure, modern media management platform, meeting needs from casual reading to professional collections.\n\n**Key Features:**\n- Organize your library with collections and read lists\n- Edit metadata for your series and books\n- Import embedded metadata automatically\n- Webreader with multiple reading modes\n- Manage multiple users, with per-library access control, age restrictions, and labels restrictions\n- Offers a REST API, many community tools and scripts can interact with Komga\n- OPDS v1 and v2 support\n- Kobo Sync with your Kobo eReader\n- KOReader Sync\n- Download book files, whole series, or read lists\n- Duplicate files detection\n- Duplicate pages detection and removal\n- Import books from outside your libraries directly into your series folder\n- Import ComicRack cbl read lists\n\n**Learn More:**\n- [Komga Official Website](https://komga.org)\n- [Komga GitHub Repository](https://github.com/gotson/komga)\n", + "website": "https://komga.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Komga/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-24", + "main_image": "gotson/komga:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/komga.json", + "template_status": "generated-unvalidated", + "content_hash": "9303aecca778bd962327f90df48fe0b52bb8be170c34912f0d0bbf8ac5320fe9", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "krita", + "provider": "linuxserver.io", + "title": "Krita", + "repository_name": "docker-krita", + "repository": "https://github.com/linuxserver/docker-krita", + "description": "Krita is a professional FREE and open source painting program. It is made by artists that want to see affordable art tools for everyone.", + "website": "https://krita.org/en/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/krita-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T12:45:23Z", + "updated_at": "2026-03-29", + "main_image": "lscr.io/linuxserver/krita:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/krita.json", + "template_status": "generated-unvalidated", + "content_hash": "e746fb2c27b281cc05061a32bbc18e741c7a33b15a65bb7efe4f7bbec76c7f60", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "label-studio", + "source_app_id": "label-studio", + "provider": "heartexlabs", + "template_family": "imported-compose", + "variant": null, + "title": "Label Studio", + "repository": "https://hub.docker.com/r/heartexlabs/label-studio", + "description": "Label Studio is an open source data labeling tool. It lets you label data types like audio, text, images, videos, and time series with a simple and straightforward UI and export to various model formats. It can be used to prepare raw data or improve existing training data to get more accurate ML models.", + "website": "https://labelstud.io/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/LabelStudio/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-03-13", + "main_image": "heartexlabs/label-studio:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/label-studio.json", + "template_status": "generated-unvalidated", + "content_hash": "e7c4fd3ae8c0b249ec5ee738fb9ab3283c5abe61a621746bb890238e1cff4e53", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "langflow", + "source_app_id": "langflow", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Langflow", + "repository": "https://hub.docker.com/r/langflowai/langflow", + "description": "Langflow is a powerful, open-source UI designed specifically for building and debugging multi-agent and Retrieval-Augmented Generation (RAG) applications. It provides a visual, drag-and-drop interface that simplifies the process of creating complex AI workflows.\n\nThe system consists of two main components:\n- **Langflow**: The main application providing a visual interface for building AI workflows\n- **PostgreSQL**: A robust database system for storing application data and configurations\n\n**Key Features:**\n- Visual, drag-and-drop interface for building AI workflows\n- Support for multi-agent systems and RAG applications\n- Integrated debugging tools for testing and optimization\n- Persistent storage for workflows and configurations\n- Easy deployment with Docker containers\n\n**Learn More:**\n- [Langflow Official Website](https://www.langflow.org)\n- [Langflow GitHub Repository](https://github.com/langflow-ai/langflow)\n- [Documentation](https://docs.langflow.org)\n", + "website": "https://www.langflow.org", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/LangFlow/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "langflowai/langflow:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/langflow.json", + "template_status": "generated-unvalidated", + "content_hash": "03601b6544245bc7a3a02d254326d6261fe1b57ac8cd5284b25c1193b24e0dab", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "lazylibrarian", + "provider": "linuxserver.io", + "title": "Lazylibrarian", + "repository_name": "docker-lazylibrarian", + "repository": "https://github.com/linuxserver/docker-lazylibrarian", + "description": "Lazylibrarian is a program to follow authors and grab metadata for all your digital reading needs. It uses a combination of Goodreads Librarything and optionally GoogleBooks as sources for author info and book info. This container is based on the DobyTang fork.", + "website": "https://lazylibrarian.gitlab.io/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lazylibrarian-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T12:31:30Z", + "updated_at": "2024-08-14", + "main_image": "lscr.io/linuxserver/lazylibrarian:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/lazylibrarian.json", + "template_status": "generated-unvalidated", + "content_hash": "d4c450baa35b964f4f7759fd5206b29999550f06a8d35e2d128e5ae27ead9777", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ldap-auth", + "provider": "linuxserver.io", + "title": "Ldap Auth", + "repository_name": "docker-ldap-auth", + "repository": "https://github.com/linuxserver/docker-ldap-auth", + "description": "Ldap-auth software is for authenticating users who request protected resources from servers proxied by nginx. It includes a daemon (ldap-auth) that communicates with an authentication server, and a webserver daemon that generates an authentication cookie based on the user\u2019s credentials. The daemons are written in Python for use with a Lightweight Directory Access Protocol (LDAP) authentication server (OpenLDAP or Microsoft Windows Active Directory 2003 and 2012).", + "website": "https://github.com/nginxinc/nginx-ldap-auth", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ldap-auth-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T17:09:48Z", + "updated_at": "2026-07-17", + "main_image": "lscr.io/linuxserver/ldap-auth:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/ldap-auth.json", + "template_status": "generated-unvalidated", + "content_hash": "ec1d5723bce0784ead049f63fe0e3d1ca13c6d30156df54fea10e20f39369afa", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "librechat", + "source_app_id": "librechat", + "provider": "danny-avila", + "template_family": "imported-compose", + "variant": null, + "title": "LibreChat", + "repository": "https://ghcr.io/danny-avila/librechat-dev", + "description": "LibreChat is a full-featured, open-source AI chat interface that allows users to interact with multiple AI models through a unified platform. It supports various AI providers and offers advanced features like conversation management, plugin support, and customizable interfaces.\n**Key Features:**\n- Support for multiple AI models and providers\n- Conversation history and management\n- Plugin system for extended functionality\n- Customizable themes and interfaces\n- User authentication and management\n- API integrations for various services\n- Search functionality with MeiliSearch\n- RAG (Retrieval-Augmented Generation) support\n- File upload and processing capabilities\n- Multi-language support\n\n**Learn More:**\n- [LibreChat Official Website](https://www.librechat.ai)\n- [LibreChat GitHub Repository](https://github.com/danny-avila/LibreChat)\n\n**extra:**\nYou can refer to the [Custom AI Endpoints](https://www.librechat.ai/docs/configuration/librechat_yaml/ai_endpoints) documentation to configure the relevant files for calling the APIs of Anyscale, ApiPie, Cohere, Deepseek, Databricks, Fireworks, Groq, HuggingFace, Mistral, OpenRouter, Perplexity, ShuttleAI, TogetherAI, Unify, and xAI.\n", + "website": "https://www.librechat.ai", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/LibreChat/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ghcr.io/danny-avila/librechat-dev:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/librechat.json", + "template_status": "generated-review-required", + "content_hash": "bd6cc98712081bcf10059d0a38a5ce98b6fea70439d11375559887407e3f95ce", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:librechat-rag-api:compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "libredb-studio", + "source_app_id": "libredb-studio", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "LibreDB Studio", + "repository": "https://hub.docker.com/r/libredb/libredb-studio", + "description": "LibreDB Studio is an open-source (MIT), self-hosted SQL IDE. It provides a modern web-based interface to connect to 16 database engines (PostgreSQL, MySQL, MongoDB, Redis, ClickHouse and more), browse schemas, write and run SQL queries, and manage your data from any browser on your LAN. Data is stored locally in a SQLite database, so everything stays under your control.", + "website": "https://libredb.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/LibreDBStudio/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-09-09", + "main_image": "libredb/libredb-studio:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/libredb-studio.json", + "template_status": "generated-unvalidated", + "content_hash": "6485b09351e49ed6eaecf510644a8c4d2e5044edc4cb974a892ca3184dff31c0", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "libreoffice", + "provider": "linuxserver.io", + "title": "Libreoffice", + "repository_name": "docker-libreoffice", + "repository": "https://github.com/linuxserver/docker-libreoffice", + "description": "LibreOffice is a free and powerful office suite, and a successor to OpenOffice.org (commonly known as OpenOffice). Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity.", + "website": "https://www.libreoffice.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/libreoffice-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T01:30:30Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/libreoffice:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/libreoffice.json", + "template_status": "generated-unvalidated", + "content_hash": "fcc02118053fb469c9aeb695b26a58447cc3d9ef7c815919a8f4714c2e519cdb", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "librespeed", + "provider": "linuxserver.io", + "title": "Librespeed", + "repository_name": "docker-librespeed", + "repository": "https://github.com/linuxserver/docker-librespeed", + "description": "Librespeed is a very lightweight Speedtest implemented in Javascript, using XMLHttpRequest and Web Workers.", + "website": "https://github.com/librespeed/speedtest", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/librespeed-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T13:17:52Z", + "updated_at": "2026-07-29", + "main_image": "lscr.io/linuxserver/librespeed:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/librespeed.json", + "template_status": "generated-unvalidated", + "content_hash": "cdfd71305229d535495af5189e4c4b5e0321c008f4ef794734c19b8bd17da2a2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "librewolf", + "provider": "linuxserver.io", + "title": "Librewolf", + "repository_name": "docker-librewolf", + "repository": "https://github.com/linuxserver/docker-librewolf", + "description": "LibreWolf is a custom and independent version of Firefox, with the primary goals of privacy, security and user freedom. LibreWolf also aims to remove all the telemetry, data collection and annoyances, as well as disabling anti-freedom features like DRM.", + "website": "https://librewolf.net/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/librewolf-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T07:42:13Z", + "updated_at": "2026-03-31", + "main_image": "lscr.io/linuxserver/librewolf:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/librewolf.json", + "template_status": "generated-unvalidated", + "content_hash": "912397d7d438a946bdb1ead5b6685665f1f9e3b8438d612ecf09cbfe80b00ab4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "lidarr", + "provider": "linuxserver.io", + "title": "Lidarr", + "repository_name": "docker-lidarr", + "repository": "https://github.com/linuxserver/docker-lidarr", + "description": "Lidarr is a music collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new tracks from your favorite artists and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.", + "website": "https://github.com/lidarr/Lidarr", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lidarr-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T05:30:58Z", + "updated_at": "2026-07-04", + "main_image": "lscr.io/linuxserver/lidarr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/lidarr.json", + "template_status": "generated-unvalidated", + "content_hash": "62422a5b8a054cfebef1de1d19ca9c5cfa8a85a8063596234f145dfb34807a00", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "limnoria", + "provider": "linuxserver.io", + "title": "Limnoria", + "repository_name": "docker-limnoria", + "repository": "https://github.com/linuxserver/docker-limnoria", + "description": "Limnoria A robust, full-featured, and user/programmer-friendly Python IRC bot, with many existing plugins. Successor of the well-known Supybot.", + "website": "https://github.com/ProgVal/limnoria", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/limnoria-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T21:29:19Z", + "updated_at": "2025-02-01", + "main_image": "lscr.io/linuxserver/limnoria:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/limnoria.json", + "template_status": "generated-unvalidated", + "content_hash": "a210b002667bf30202710e7393b3f253f7f9e797d188ef1ef3a2a3b88ad5a9f1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "linkwarden", + "source_app_id": "linkwarden", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Linkwarden", + "repository": "https://ghcr.io/linkwarden/linkwarden", + "description": "Linkwarden is an open-source self-hosted bookmark and web archive manager designed to help users collect, organize, and preserve important online content in one place. In addition to traditional bookmarking capabilities, it provides full webpage backup so valuable information remains safely accessible over time.\n\nBuilt around long-term content preservation, Linkwarden can automatically capture webpage screenshots, PDFs, and full HTML files to help prevent link rot. It also includes reading mode, annotations, local AI-powered tagging, full-text search, and a multi-level classification system for smarter and more efficient information management. Its modular architecture supports self-hosting, browser extensions, and cross-device sync.\n\nIn practice, Linkwarden is suitable not only for personal knowledge management and content collection, but also for team collaboration and shared curation. With collections and permission controls, users can organize content together and manage it publicly or privately. It is a modern bookmarking tool that balances data ownership, security, and collaboration.\n\n**Key Features:**\n\n- Full webpage archiving (screenshots, PDFs, HTML) to prevent link rot\n- AI-powered auto-tagging and full-text search\n- Reading mode, text highlighting, and annotations\n- Multi-level categories and tags for flexible organization\n- Team collaboration and permission management\n\n**Learn more:**\n\n- [Linkwarden GitHub](https://github.com/linkwarden/linkwarden)\n", + "website": "https://linkwarden.app/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Linkwarden/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ghcr.io/linkwarden/linkwarden:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/linkwarden.json", + "template_status": "laboratory-validated", + "content_hash": "abf2884e8ba3534a27a4a7dcb9d86e056c1329ac533d258d44caa62edb0b8347", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "llama-factory-nvidia", + "source_app_id": "llama-factory-nvidia", + "provider": "hiyouga", + "template_family": "imported-compose", + "variant": "nvidia", + "title": "LLaMA Factory(Nvidia GPU)", + "repository": "https://hub.docker.com/r/hiyouga/llamafactory", + "description": "LLaMA Factory is a comprehensive framework for fine-tuning Large Language Models (LLMs) with support for over 100 models. It provides a user-friendly web interface and powerful training methods including LoRA, QLoRA, and full-parameter training.\n\n**Key Features:**\n- Support for 100+ LLMs including LLaMA, Mistral, Qwen, and more\n- Multiple fine-tuning methods (LoRA, QLoRA, Full, Freeze)\n- Intuitive Web UI for easy model management\n- Built-in API server for model inference\n- Multi-GPU training support\n- Quantization and model export capabilities\n\n**Hardware Requirements:**\n- GPU: NVIDIA GPU with CUDA support required\n\n**Learn More:**\n- [GitHub Repository](https://github.com/hiyouga/LLaMA-Factory)\n- [Documentation](https://llamafactory.readthedocs.io/)\n", + "website": "https://llamafactory.readthedocs.io/", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/LLaMA-Factory_Nvidia/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "hiyouga/llamafactory:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/llama-factory-nvidia.json", + "template_status": "generated-unvalidated", + "content_hash": "27eedb0ae6dc7b54b199903c5ea65a799be7985bffb74117610838239a680626", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "llamacpp", + "provider": "ggml-org", + "template_family": "curated-profile", + "title": "llama.cpp", + "repository": "https://ghcr.io/ggml-org/llama.cpp", + "description": "llama.cpp is a pure C/C++ inference engine for GGUF large language models, with the official OpenAI-compatible server and a built-in Web UI.\n\n**Key Features:**\n- Run GGUF models (Llama, Qwen, DeepSeek, Gemma, Mistral and more) on CPU or GPU\n- Vulkan backend works on AMD / Intel / NVIDIA GPUs out of the box\n- Great fit for unified-memory machines (e.g. AMD Ryzen AI Max 395)\n- OpenAI-compatible API for integration with Open WebUI, ChatGPT-Next-Web and more\n- Built-in chat Web UI with runtime model loading\n\n**Getting started:**\n1. Put GGUF model files into the models volume (`/models`)\n2. Open the Web UI at `http://:18080` and load a model\n3. Keep `/dev/dri` mapped for Vulkan acceleration; remove it for CPU-only mode", + "website": "https://github.com/ggml-org/llama.cpp", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": null, + "main_image": "ghcr.io/ggml-org/llama.cpp:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "replaces_discovered_ids": [ + "llamacpp" + ], + "curated_path": "catalog/curated/llamacpp.json", + "template": "apps/llamacpp.json", + "template_status": "generated-unvalidated", + "content_hash": "ca744a983663b3ebed1d33b8b1e9b0e52e34ef57827f0f41e19c6c9e8a2275c3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "lm-studio", + "provider": "linuxserver.io", + "title": "Lm Studio", + "repository_name": "docker-lm-studio", + "repository": "https://github.com/linuxserver/docker-lm-studio", + "description": "LM Studio can run local AI models like gpt-oss, Llama, Gemma, Qwen, and DeepSeek privately on your computer.", + "website": "https://lmstudio.ai/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lm-studio-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T18:47:08Z", + "updated_at": "2026-06-22", + "main_image": "lscr.io/linuxserver/lm-studio:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/lm-studio.json", + "template_status": "generated-unvalidated", + "content_hash": "44997beed91523470d9493853cb8c38c231cbceff15c45d92e9a0b83cdd5f52f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "logseq", + "source_app_id": "logseq", + "provider": "correctroad", + "template_family": "imported-compose", + "variant": null, + "title": "Logseq", + "repository": "https://hub.docker.com/r/correctroad/logseq", + "description": "A privacy-first, open-source platform for knowledge management and collaboration.", + "website": "https://logseq.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Logseq/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-11-27", + "main_image": "correctroad/logseq:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/logseq.json", + "template_status": "generated-unvalidated", + "content_hash": "687143e4e10ca33c3ca39a5fe64f1ea46ccee60aa3ce977eb4c478c1e22db058", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "lollypop", + "provider": "linuxserver.io", + "title": "Lollypop", + "repository_name": "docker-lollypop", + "repository": "https://github.com/linuxserver/docker-lollypop", + "description": "Lollypop is a lightweight modern music player designed to work excellently on the GNOME desktop environment.", + "website": "https://wiki.gnome.org/Apps/Lollypop", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lollypop-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T18:11:52Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/lollypop:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/lollypop.json", + "template_status": "generated-unvalidated", + "content_hash": "4ddf7603f638ae064a68c9683877247a6499a221008b431454384414b429ebfb", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "luanti", + "provider": "linuxserver.io", + "title": "Luanti", + "repository_name": "docker-luanti", + "repository": "https://github.com/linuxserver/docker-luanti", + "description": "Luanti (formerly Minetest) is an open source voxel game-creation platform with easy modding and game creation", + "website": "https://www.luanti.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/luanti-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-06T23:42:51Z", + "updated_at": "2025-11-03", + "main_image": "lscr.io/linuxserver/luanti:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/luanti.json", + "template_status": "generated-unvalidated", + "content_hash": "e2e3a7ec526e5ebc37496068997d1f3b42a4f316f09c449a22223f475a116a9b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "lucky", + "source_app_id": "lucky", + "provider": "gdy666", + "template_family": "imported-compose", + "variant": null, + "title": "Lucky", + "repository": "https://hub.docker.com/r/gdy666/lucky", + "description": "A powerful tool for port forwarding, reverse proxy, dynamic DNS, wake-on-LAN, IPv4 NAT traversal, webdav services, task scheduling, and automatic certificate management.", + "website": "https://lucky666.cn/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Lucky/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-02-15", + "main_image": "gdy666/lucky:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/lucky.json", + "template_status": "generated-unvalidated", + "content_hash": "f2b9ed8d035576997d9e78403eebfce848f319c25c7775d47643e92bf1e08fdd", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "lychee", + "provider": "linuxserver.io", + "title": "Lychee", + "repository_name": "docker-lychee", + "repository": "https://github.com/linuxserver/docker-lychee", + "description": "Lychee is a free photo-management tool, which runs on your server or web-space. Installing is a matter of seconds. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.", + "website": "https://lycheeorg.github.io/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/lychee-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T07:23:35Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/lychee:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/lychee.json", + "template_status": "generated-unvalidated", + "content_hash": "8074e339789781dee4e5099df9132a52ca7e257376f6d17f6a50951fddc43b4e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "lyrionmusicserver", + "source_app_id": "lyrionmusicserver", + "provider": "lmscommunity", + "template_family": "imported-compose", + "variant": null, + "title": "LyrionMusicServer", + "repository": "https://hub.docker.com/r/lmscommunity/lyrionmusicserver", + "description": "Lyrion Music Server is a self-hosted music management app designed to control a variety of audio playback devices, supporting streaming of local music collections, internet radio, and multiple streaming services (with or without subscriptions). Its intuitive Web interface enables users to access and control music effortlessly via any browser, ideal for music enthusiasts creating personalized audio experiences.\n\nThe app's core features include versatile music streaming and extensive customization. Users can seamlessly play local music libraries, listen to global internet radio, or connect to streaming services, catering to diverse listening needs. It offers flexible control options, allowing customization of server functionality, interaction methods, and interface appearance. Additionally, it supports a unified interface across multiple devices, ensuring a consistent experience on phones, computers, or other players, with the ability to select the ideal playback device for any scenario.\n\nIt can be flexibly deployed on personal servers or NAS devices, with community-provided documentation aiding users in optimising setups and extending functionality. Whether managing personal music collections or creating a shared audio hub for family, the app's intuitive operation and high flexibility deliver a modern music management platform, meeting needs from casual listening to professional audio management.\n\n**Key Features:**\n- Music streaming for local collections, internet radio, and multiple streaming services\n- Intuitive Web interface for effortless music access and control via any browser\n- Extensive customisation options for server functionality, interaction methods, and interface appearance\n- Unified multi-device interface ensuring consistent experience across phones, computers, and other players\n- Community documentation support for optimising setups and extending functionality\n\n**Learn More:**\n- [Lyrion Music Server Official Website](https://www.lyrion.org)\n- [Lyrion Music Server GitHub Repository](https://github.com/lms-community/slimserver)\n", + "website": "https://www.lyrion.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/LyrionMusicServer/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-24", + "main_image": "lmscommunity/lyrionmusicserver:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/lyrionmusicserver.json", + "template_status": "generated-unvalidated", + "content_hash": "7261549cf4937936afed3e4ae63e533aabddb7c975d0bdad2b5c9668fa9bcbf4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "makemkv", + "provider": "jlesage", + "template_family": "curated-profile", + "title": "MakeMKV", + "repository": "https://github.com/jlesage/docker-makemkv", + "description": "The maintained jlesage MakeMKV image with persistent settings, shared input/output storage and optional native optical-drive passthrough.", + "website": "https://github.com/jlesage/docker-makemkv", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-08-26", + "main_image": "jlesage/makemkv:latest", + "category": "media", + "category_label": "Media & Streaming", + "replaces_discovered_ids": [ + "makemkv" + ], + "curated_path": "catalog/curated/makemkv.json", + "template": "apps/makemkv.json", + "template_status": "generated-unvalidated", + "content_hash": "5e22f5d17e107f9c5cbaca06010e5204ef23754d2125a93ceb09c28e59377056", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mame", + "provider": "linuxserver.io", + "title": "Mame", + "repository_name": "docker-mame", + "repository": "https://github.com/linuxserver/docker-mame", + "description": "MAME is a free and open-source emulator designed to emulate the hardware of arcade games, video game consoles, old computers and other systems in software on modern personal computers.", + "website": "https://www.mamedev.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mame-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T18:33:08Z", + "updated_at": "2026-05-04", + "main_image": "lscr.io/linuxserver/mame:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/mame.json", + "template_status": "generated-unvalidated", + "content_hash": "8673f83e98d515c83ce7678e132c32c08bb181d7df462427015a0d3248a23525", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "manyfold", + "provider": "linuxserver.io", + "title": "Manyfold", + "repository_name": "docker-manyfold", + "repository": "https://github.com/linuxserver/docker-manyfold", + "description": "Manyfold is an open source, self-hosted web application for managing a collection of 3D models, particularly focused on 3D printing.", + "website": "https://github.com/manyfold3d/manyfold/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/manyfold-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-07T19:04:38Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/manyfold:latest", + "category": "gaming", + "category_label": "Gaming & Leisure", + "template": "apps/manyfold.json", + "template_status": "generated-unvalidated", + "content_hash": "106687d51c574d2e4c51ad923629be3665eda59e6edcb75aa00e8bdf4ce277f0", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mariadb", + "provider": "linuxserver.io", + "title": "Mariadb", + "repository_name": "docker-mariadb", + "repository": "https://github.com/linuxserver/docker-mariadb", + "description": "Mariadb is one of the most popular database servers. Made by the original developers of MySQL.", + "website": "https://mariadb.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mariadb-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T12:40:37Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/mariadb:latest", + "category": "databases", + "category_label": "Databases", + "template": "apps/mariadb.json", + "template_status": "generated-unvalidated", + "content_hash": "2105289fbccefd7c42c511d04ec4dcda17e923027a6a192b8db0256cfdb1e22f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mastodon", + "provider": "linuxserver.io", + "title": "Mastodon", + "repository_name": "docker-mastodon", + "repository": "https://github.com/linuxserver/docker-mastodon", + "description": "Mastodon is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..", + "website": "https://github.com/mastodon/mastodon/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mastodon-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-10T15:01:58Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/mastodon:latest", + "category": "communication", + "category_label": "Communication & Community", + "template": "apps/mastodon.json", + "template_status": "generated-unvalidated", + "content_hash": "66ced75d362288b843b6f2e1baefbc01580f0f7d28775b2c35b53feb876dd581", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "maybe", + "source_app_id": "maybe", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Maybe", + "repository": "https://ghcr.io/maybe-finance/maybe", + "description": "Maybe is a personal finance management application designed to help you track your expenses, income, and investments in one place. With an intuitive interface and powerful features, Maybe makes it easy to understand your financial situation and make informed decisions about your money.\n\n**Key Features:**\n- **Expense Tracking**: Easily log and categorize your expenses\n- **Income Management**: Track multiple income sources\n- **Investment Monitoring**: Keep an eye on your investments and their performance\n- **Budget Planning**: Create and maintain budgets to control your spending\n- **Financial Reports**: Generate detailed reports to understand your financial habits\n- **AI-Powered Insights**: Get personalized financial advice using AI technology\n\n**Use Cases:**\n- Personal budget management\n- Expense tracking and categorization\n- Investment portfolio monitoring\n- Financial goal setting and tracking\n- Cash flow analysis\n\n**Learn More:**\n- [Maybe GitHub Repository](https://github.com/maybe-finance/maybe)\n", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Maybe/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ghcr.io/maybe-finance/maybe:latest", + "category": "finance", + "category_label": "Finance & Budgeting", + "template": "apps/maybe.json", + "template_status": "generated-review-required", + "content_hash": "7713d5ab86b589c46068685965198baf89a469906bbf1b86bc8ae5b292298b3a", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:maybe-worker:compose-key:depends_on", + "service:maybe-db:healthcheck-format", + "service:maybe-redis:healthcheck-format", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "mediaelch", + "provider": "linuxserver.io", + "title": "Mediaelch", + "repository_name": "docker-mediaelch", + "repository": "https://github.com/linuxserver/docker-mediaelch", + "description": "MediaElch is a MediaManager for Kodi. Information about Movies, TV Shows, Concerts and Music are stored as nfo files. Fanarts are downloaded automatically from fanart.tv. Using the nfo generator, MediaElch can be used with other MediaCenters as well.", + "website": "https://github.com/Komet/MediaElch", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mediaelch-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T16:40:13Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/mediaelch:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/mediaelch.json", + "template_status": "generated-unvalidated", + "content_hash": "76fb38efb00bd0484f6a3cf2f636780605e8ca11e9dd8dbe7cb72b313b20be79", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "medusa", + "provider": "linuxserver.io", + "title": "Medusa", + "repository_name": "docker-medusa", + "repository": "https://github.com/linuxserver/docker-medusa", + "description": "Medusa is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.", + "website": "https://pymedusa.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/medusa-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T17:58:29Z", + "updated_at": "2026-08-16", + "main_image": "lscr.io/linuxserver/medusa:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/medusa.json", + "template_status": "generated-unvalidated", + "content_hash": "1ed6164183310cc30163962101df86050e4f9f76d8207627d98b06d377d8946c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "medusa-official", + "source_app_id": "medusa", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Medusa", + "repository": "https://hub.docker.com/r/pymedusa/medusa", + "description": "Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic.", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Medusa/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-17", + "main_image": "pymedusa/medusa:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/medusa-official.json", + "template_status": "generated-unvalidated", + "content_hash": "5a8cd1fcf43cd8f7ff95925300f38e55f7d01fd229fb26f87ec2c914e5378822", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "melonds", + "provider": "linuxserver.io", + "title": "Melonds", + "repository_name": "docker-melonds", + "repository": "https://github.com/linuxserver/docker-melonds", + "description": "melonDS aims at providing fast and accurate Nintendo DS emulation.", + "website": "https://melonds.kuribo64.net/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/melonds-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T21:14:11Z", + "updated_at": "2026-03-05", + "main_image": "lscr.io/linuxserver/melonds:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/melonds.json", + "template_status": "generated-unvalidated", + "content_hash": "2b550d653a1de88d15c7d171e42ca2b335cfc1a6ad1cec05e183a4cfd8ddeec7", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "memos", + "source_app_id": "memos", + "provider": "neosmemo", + "template_family": "imported-compose", + "variant": null, + "title": "Memos", + "repository": "https://hub.docker.com/r/neosmemo/memos", + "description": "Memos is a lightweight, open-source, self-hosted note-taking application that offers a secure and streamlined solution for users prioritizing privacy and data control. All notes are stored on the user\u2019s own server, eliminating risks associated with third-party cloud services. Its minimalist Web interface supports Markdown syntax and tag-based organization, enabling effortless capture of ideas, personal knowledge management, or small-scale team collaboration. The open-source design ensures transparency, long-term maintainability, and no subscription costs, making it ideal for users seeking data ownership and cost efficiency.\n\nDesigned for simplicity and efficiency, Memos caters to a variety of use cases. Whether jotting down daily thoughts, organizing study notes, or sharing task memos in small teams, Memos delivers a seamless experience through its intuitive tag system and Markdown formatting. Accessible via any web browser, it requires no proprietary clients or complex setup, allowing users to manage notes anytime, anywhere.\n\nWhether used for long-term personal knowledge archiving or as a lightweight tool for team collaboration, Memos offers a secure, flexible, and user-friendly solution, empowering users to maintain full control over their data while enjoying a streamlined note-taking experience.\n", + "website": "https://usememos.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Memos/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-27", + "main_image": "neosmemo/memos:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/memos.json", + "template_status": "laboratory-validated", + "content_hash": "94ac9cc627c820d0912956e1c5c6a08ecf4242d240b322f2c5f2b3a48d9bb37a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mineos-node", + "source_app_id": "mineos-node", + "provider": "hexparrot", + "template_family": "imported-compose", + "variant": null, + "title": "MineOS", + "repository": "https://hub.docker.com/r/hexparrot/mineos", + "description": "MineOS is a server front-end to ease managing Minecraft administrative tasks. This iteration using Node.js aims to enhance previous MineOS scripts (Python-based), by leveraging the event-triggering, asyncronous model of Node.JS and websockets.", + "website": "https://www.mineos.net/", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/MineOS/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2022-04-25", + "main_image": "hexparrot/mineos:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/mineos-node.json", + "template_status": "laboratory-validated", + "content_hash": "ff052e25508b01568438d176fc961b57579b98115a5abc494734c5cb94cc820b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "minisatip", + "provider": "linuxserver.io", + "title": "Minisatip", + "repository_name": "docker-minisatip", + "repository": "https://github.com/linuxserver/docker-minisatip", + "description": "Minisatip is a multi-threaded satip server version 1.2 that runs under Linux and it was tested with DVB-S, DVB-S2, DVB-T, DVB-T2, DVB-C, DVB-C2, ATSC and ISDB-T cards.", + "website": "https://github.com/catalinii/minisatip", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/minisatip-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T12:51:54Z", + "updated_at": "2026-02-20", + "main_image": "lscr.io/linuxserver/minisatip:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/minisatip.json", + "template_status": "generated-unvalidated", + "content_hash": "5528556b3663f9dc0c8c9a64c2dae24188afea840f236b43823d72a7ef7d221f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mkvtoolnix", + "provider": "jlesage", + "template_family": "curated-profile", + "title": "MKVToolNix", + "repository": "https://github.com/jlesage/docker-mkvtoolnix", + "description": "The maintained jlesage MKVToolNix image with browser GUI, persistent settings and user-selectable shared storage.", + "website": "https://github.com/jlesage/docker-mkvtoolnix", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-08-26", + "main_image": "jlesage/mkvtoolnix:latest", + "category": "media", + "category_label": "Media & Streaming", + "replaces_discovered_ids": [ + "mkvtoolnix" + ], + "curated_path": "catalog/curated/mkvtoolnix.json", + "template": "apps/mkvtoolnix.json", + "template_status": "generated-unvalidated", + "content_hash": "c17222631fb1734d0b5b0395e25e53b0f5034332746933cf04db7597c3722976", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mongodb", + "source_app_id": "mongodb", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "MongoDB", + "repository": "https://hub.docker.com/_/mongo", + "description": "MongoDB is a free and open-source cross-platform document-oriented database program. Classified as a NoSQL database program, MongoDB uses JSON-like documents with schemata. MongoDB is developed by MongoDB Inc., and is published under a combination of the Server Side Public License and the Apache License.", + "website": "https://www.mongodb.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Mongo/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-12-09", + "main_image": "mongo:latest", + "category": "databases", + "category_label": "Databases", + "template": "apps/mongodb.json", + "template_status": "generated-unvalidated", + "content_hash": "2f0c3b4678bc496e865291fa850c77880b488e74a8799cead539d285299690ad", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mongodb4", + "source_app_id": "mongodb4", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "MongoDB 4", + "repository": "https://hub.docker.com/_/mongo", + "description": "The 4.4 series of MongoDB, the document-oriented NoSQL database. MongoDB 5 and later require a CPU with AVX support and will not start without it, which leaves the low-power processors common in home servers unable to run them at all. This entry exists for those machines: it is pinned to the 4.4 series rather than following the latest release. The series reached its end of life in February 2024 and receives no further fixes, so where the processor does support AVX, the MongoDB entry installs a maintained release instead.", + "website": "https://www.mongodb.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/MongoDB4/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2023-07-04", + "main_image": "mongo:4", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/mongodb4.json", + "template_status": "generated-unvalidated", + "content_hash": "ded611e14715be7ecf655239a1b4e4464eba18c8096bd9c9671011708072278b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "monica", + "provider": "linuxserver.io", + "title": "Deprecation Notice", + "repository_name": "docker-monica", + "repository": "https://github.com/linuxserver/docker-monica", + "description": "Monica is an open source personal relationship management system, that lets you document your life.", + "website": "https://github.com/monicahq/monica", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/monica-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-07-03T20:21:28Z", + "updated_at": "2026-07-03", + "main_image": "lscr.io/linuxserver/monica:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/monica.json", + "template_status": "generated-unvalidated", + "content_hash": "12779fdf8dc6617f198257445fadc783ccdf90bb64b518c32db3d88dedc4ea94", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "monica-official", + "source_app_id": "monica", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Monica", + "repository": "https://hub.docker.com/_/monica", + "description": "Monica is a self-hosted personal relationship management tool that helps users document and organize interactions with family and friends via an intuitive Web interface, creating a personalized contact database. It is ideal for users balancing work and life, ensuring key personal connections are never missed.\n\nThe tool's core features include comprehensive contact management and smart reminders. It supports creating detailed contact profiles, logging personal details, relationships (e.g., family, friends), and how contacts were met. Users can set automatic reminders for birthdays, anniversaries, and other key dates, while tracking conversations, activities, and gift ideas. A diary feature records daily moods and significant moments, maintaining a clear life record.\n\nIt offers task and debt management to track to-dos or financial interactions. Users can upload photos and documents, favorite contacts, and organize relationships with labels for streamlined data management. Full control over local data ensures privacy. The tool\u2019s intuitive operation and high flexibility deliver a modern relationship management solution.\n\n**Key Features:**\n- Comprehensive contact management with detailed profiles\n- Automatic reminders for birthdays, anniversaries, and key dates\n- Track conversations, activities, and gift ideas\n- Diary feature to record daily moods and moments\n- Task and debt management for to-dos and finances\n- Upload photos and documents, favorite contacts\n- Organize contacts with labels\n- Local data storage for privacy assurance\n\n**Learn More:**\n- [Monica Official Website](https://www.monicahq.com)\n- [Monica GitHub Repository](https://github.com/monicahq/monica)\n", + "website": "https://www.monicahq.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Monica/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "monica:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/monica-official.json", + "template_status": "generated-unvalidated", + "content_hash": "8d9b5e07a261ef5245cd9aa8108fb39a5101507fefdec5aea78b881f4f54ccfa", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "motioneye", + "source_app_id": "motioneye", + "provider": "ccrisan", + "template_family": "imported-compose", + "variant": null, + "title": "Motioneye", + "repository": "https://hub.docker.com/r/ccrisan/motioneye", + "description": "motionEye is a web-based frontend for motion. Check out the wiki for more details. Changelog is available on the releases page. https://github.com/motioneye-project/motioneye", + "website": "", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/Motioneye/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2020-06-06", + "main_image": "ccrisan/motioneye:latest", + "category": "nvr", + "category_label": "NVR & Cameras", + "template": "apps/motioneye.json", + "template_status": "laboratory-validated", + "content_hash": "2c4932fde23765f83296739cf3e0196fc77f2dd89b6ea02588cd0448291df83c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "msedge", + "provider": "linuxserver.io", + "title": "Msedge", + "repository_name": "docker-msedge", + "repository": "https://github.com/linuxserver/docker-msedge", + "description": "Microsoft Edge is a cross-platform web browser developed by Microsoft and based on Chromium.", + "website": "https://www.microsoft.com/edge", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/msedge-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T00:50:56Z", + "updated_at": "2026-03-31", + "main_image": "lscr.io/linuxserver/msedge:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/msedge.json", + "template_status": "generated-unvalidated", + "content_hash": "246930a1ee01fb550fb469d05eeba09a1da217925ae876e9ed0a1ff17350b9ea", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mstream", + "provider": "linuxserver.io", + "title": "Mstream", + "repository_name": "docker-mstream", + "repository": "https://github.com/linuxserver/docker-mstream", + "description": "mstream is a personal music streaming server. You can use mStream to stream your music from your home computer to any device, anywhere. There are mobile apps available for both Android and iPhone.", + "website": "https://mstream.io/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mstream-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T23:48:00Z", + "updated_at": "2026-07-08", + "main_image": "lscr.io/linuxserver/mstream:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/mstream.json", + "template_status": "generated-unvalidated", + "content_hash": "21fbe98c8b13ed061b21be07261e5048db60c3a86234b840692adeeb0f631249", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mullvad-browser", + "provider": "linuxserver.io", + "title": "Mullvad Browser", + "repository_name": "docker-mullvad-browser", + "repository": "https://github.com/linuxserver/docker-mullvad-browser", + "description": "", + "website": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mullvad-browser-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "main", + "pushed_at": "2026-09-06T23:35:48Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/mullvad-browser:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/mullvad-browser.json", + "template_status": "generated-unvalidated", + "content_hash": "6a1075b946faa8b3217f48d596d415a240000937a2baa565f3e14d83905c44cd", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mylar3", + "provider": "linuxserver.io", + "title": "Mylar3", + "repository_name": "docker-mylar3", + "repository": "https://github.com/linuxserver/docker-mylar3", + "description": "Mylar3 is an automated Comic Book downloader (cbr/cbz) for use with NZB and torrents written in python. It supports SABnzbd, NZBGET, and many torrent clients in addition to DDL.", + "website": "https://github.com/MylarComics/mylar3", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mylar3-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T08:58:58Z", + "updated_at": "2026-04-06", + "main_image": "lscr.io/linuxserver/mylar3:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/mylar3.json", + "template_status": "generated-unvalidated", + "content_hash": "78809472914b50e026e8375fcabd83b1358389e5b0d2d99eb9929bcf6ab8e95f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "myspeed", + "source_app_id": "myspeed", + "provider": "germannewsmaker", + "template_family": "imported-compose", + "variant": null, + "title": "MySpeed", + "repository": "https://hub.docker.com/r/germannewsmaker/myspeed", + "description": "MySpeed is a speed test analysis software that stores the speed of your internet for up to 30 days. This can also be useful if you want to know when your network might have drops or if you want to check if your internet matches the booked values from your contract.", + "website": "https://myspeed.dev", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/MySpeed/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-05-21", + "main_image": "germannewsmaker/myspeed:latest", + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "template": "apps/myspeed.json", + "template_status": "generated-unvalidated", + "content_hash": "cbece9b22e1568f7e8116e1a113187f22463b9b1849530148b45a8131cc73e02", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "mysql-workbench", + "provider": "linuxserver.io", + "title": "Mysql Workbench", + "repository_name": "docker-mysql-workbench", + "repository": "https://github.com/linuxserver/docker-mysql-workbench", + "description": "MySQL Workbench is a unified visual tool for database architects, developers, and DBAs. MySQL Workbench provides data modeling, SQL development, and comprehensive administration tools for server configuration, user administration, backup, and much more.", + "website": "https://www.mysql.com/products/workbench/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/mysql-workbench-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T12:26:36Z", + "updated_at": "2026-05-18", + "main_image": "lscr.io/linuxserver/mysql-workbench:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/mysql-workbench.json", + "template_status": "generated-unvalidated", + "content_hash": "61e25e997378b8f98038de75f639e3f0072cd1007a6bd8b113dcd65e240a34f5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "n8n", + "source_app_id": "n8n", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "n8n", + "repository": "https://hub.docker.com/r/n8nio/n8n", + "description": "n8n is a powerful open-source workflow automation and conversational AI platform that blends the flexibility of coding with the simplicity of no-code development, empowering users to create efficient and secure automation workflows. It seamlessly connects any app with an API, leveraging native AI capabilities (like LangChain-based AI agent workflows) to process custom data, ideal for personal task management, team collaboration, or enterprise-grade automation. Its vibrant community offers over 400 integrations and 900+ ready-to-use templates, enabling users to deploy automations quickly.\n\nThe platform supports highly customizable workflow design, allowing users to write JavaScript/Python, add npm packages, or use an intuitive visual interface to manage data, catering to both simple tasks and complex processes. Enterprise-grade features like advanced permissions and air-gapped deployments ensure security, while multilingual support makes it accessible globally. n8n delivers a versatile and user-friendly automation solution.\n\nDiscover n8n\u2019s Automation Scenarios\nn8n\u2019s community resources provide extensive support and inspiration, helping users explore its scenario-based value and easily build automation workflows. Below are two key resources showcasing n8n\u2019s capabilities across various use cases:\n\n1. [n8n Official Community Forum](https://community.n8n.io/): \nThe forum is a hub for user collaboration and learning, offering resources from beginner guides to advanced workflow designs. Shared use cases include automating social media posts or real-time data syncing, such as using n8n to pull data from Google Sheets and send Slack notifications, boosting team collaboration and data efficiency.\n\n2. [n8n Official Template Library](https://n8n.io/workflows/): \nThe template library offers over 900 ready-to-use workflows for scenarios like marketing automation, data analytics, and customer support. For example, a template can link Shopify to Mailchimp, automatically adding new customers to mailing lists and sending welcome emails, making automation accessible to non-technical users. AI-driven workflows, like handling customer queries with LangChain, highlight n8n\u2019s strength in intelligent interactions.\n", + "website": "https://n8n.io", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/N8n/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-25", + "main_image": "n8nio/n8n:latest", + "category": "automation", + "category_label": "Automation & Scheduling", + "template": "apps/n8n.json", + "template_status": "generated-unvalidated", + "content_hash": "c91fc5bac65d36602aa8cd29fd9b56e0f2ba9274e3576a3c28dff6e99e2ba282", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "navidrome", + "source_app_id": "navidrome", + "provider": "deluan", + "template_family": "imported-compose", + "variant": null, + "title": "Navidrome", + "repository": "https://hub.docker.com/r/deluan/navidrome", + "description": "Navidrome is an open source web-based music collection server and streamer. It gives you freedom to listen to your music collection from any browser or mobile device. It's like your personal Spotify!", + "website": "https://www.navidrome.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Navidrome/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-12", + "main_image": "deluan/navidrome:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/navidrome.json", + "template_status": "generated-unvalidated", + "content_hash": "1fc0500c68a1fd4e75eca110968728ea9459e21139259dad8841d33a9801c95c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "netbird", + "source_app_id": "netbird", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "NetBird", + "repository": "https://hub.docker.com/r/netbirdio/netbird", + "description": "NetBird combines a WireGuard\u00ae-based overlay network with Zero Trust Network Access, providing a unified open source platform for reliable and secure connectivity.\n\n- Secure Remote Access \u2013 Enable least privilege network access in a few clicks\n- Zero-Config Deployment \u2013 Replace legacy VPNs with a peer-to-peer WireGuard\u00ae-based network\n- Seamless SSO with MFA \u2013 Secure your network access with session-based SSO & MFA\n- Dynamic Posture Checks \u2013 Grant access only to devices meeting your security rules\n- Centralized Network Management \u2013 Control your private network from a single place\n- Detailed Activity Logging \u2013 Identify who did what, and when in your network\n\n**Learn More:**\n- [NetBird Website](https://netbird.io)\n- [Documentation](https://docs.netbird.io)\n- [Self-Hosting Guide](https://docs.netbird.io/selfhosted/selfhosted-quickstart)\n- [NetBird GitHub](https://github.com/netbirdio/netbird)\n- [Slack Community](https://docs.netbird.io/slack-url)\n", + "website": "https://netbird.io", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/NetBird/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-01-12", + "main_image": "netbirdio/netbird:latest", + "category": "remote", + "category_label": "Remote Access & VPN", + "template": "apps/netbird.json", + "template_status": "generated-unvalidated", + "content_hash": "b5dc0075e3d7dbcd523e556eec67ed1233f7f2bc5e486a969004a1e4c334a37f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "netbox", + "provider": "linuxserver.io", + "title": "Netbox", + "repository_name": "docker-netbox", + "repository": "https://github.com/linuxserver/docker-netbox", + "description": "Netbox is an IP address management (IPAM) and data center infrastructure management (DCIM) tool. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It is intended to function as a domain-specific source of truth for network operations.", + "website": "https://github.com/netbox-community/netbox", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/netbox-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T18:59:34Z", + "updated_at": "2026-01-05", + "main_image": "lscr.io/linuxserver/netbox:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/netbox.json", + "template_status": "generated-unvalidated", + "content_hash": "71ea6310914895e2232ac0b7f9f14a40474e014bdf35953647c8eae57b9927d8", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "netdata", + "source_app_id": "netdata", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Netdata", + "repository": "https://hub.docker.com/r/netdata/netdata", + "description": "Netdata is a real-time performance and health monitoring solution that helps you visualize and understand the behavior of your systems.", + "website": "https://www.netdata.cloud", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Netdata/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "netdata/netdata:latest", + "category": "management", + "category_label": "Host Management", + "template": "apps/netdata.json", + "template_status": "generated-unvalidated", + "content_hash": "ca96f2cd8a2ed2c252c928dd29cf6065799a5ec024f5ce92797a880e508cb1ce", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": true, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": true, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "requires_security_confirmation": true, + "hidden": false + }, + { + "id": "netronome", + "source_app_id": "netronome", + "provider": "autobrr", + "template_family": "imported-compose", + "variant": null, + "title": "Netronome", + "repository": "https://ghcr.io/autobrr/netronome", + "description": "Netronome is a complete network performance monitoring solution with speed tests, continuous packet-loss monitoring, distributed server agents, automated alerts, visualizations, and historical tracking.", + "website": "https://netrono.me", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Netronome/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-07-30", + "main_image": "ghcr.io/autobrr/netronome:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/netronome.json", + "template_status": "generated-unvalidated", + "content_hash": "cc14c3acc44972385b678f72b5430de930b6be9b805616d031496677c4103c98", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "nextcloud", + "provider": "linuxserver.io", + "title": "Nextcloud", + "repository_name": "docker-nextcloud", + "repository": "https://github.com/linuxserver/docker-nextcloud", + "description": "Nextcloud gives you access to all your files wherever you are.", + "website": "https://nextcloud.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nextcloud-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T15:04:34Z", + "updated_at": "2025-07-10", + "main_image": "lscr.io/linuxserver/nextcloud:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/nextcloud.json", + "template_status": "laboratory-validated", + "content_hash": "3c6ab555a89e5881bafac6a24c53682080c6e8ddbe2177a49872db46f3fed42d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "nextcloud-official", + "source_app_id": "nextcloud", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Nextcloud", + "repository": "https://hub.docker.com/_/nextcloud", + "description": "Discover the ultimate solution for remote collaboration with Nextcloud. Unlike traditional office software, Nextcloud seamlessly integrates files, communication, and productivity tools into one platform, enhancing teamwork and streamlining your workflow. Say goodbye to the limitations of conventional tools and embrace a new era of collaboration.\n\nNextcloud stands out with its robust features tailored for every need. Enjoy secure file storage, real-time communication via Talk, comprehensive groupware, and powerful office integration, all in one place. Experience these top-notch features at an affordable price, making it accessible for everyone to elevate their collaboration game.\n\nDeploying Nextcloud on a self-hosted server private cloud device brings unparalleled convenience. Benefit from unlimited storage, secure data privacy, local network speeds, and multi-device access, ensuring you have everything you need at your fingertips.\n", + "website": "https://nextcloud.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Nextcloud/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-30", + "main_image": "nextcloud:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/nextcloud-official.json", + "template_status": "generated-unvalidated", + "content_hash": "5e352ee3d1f34671c31797279eeb1d04272cd4678bd8360713eb9726420a8859", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "nextcloud-stack", + "provider": "nextcloud", + "template_family": "curated-profile", + "title": "Nextcloud Stack", + "repository": "https://github.com/nextcloud/docker", + "description": "A three-service Nextcloud deployment adapted to native Proxmox OCI LXC containers.", + "website": "https://nextcloud.com/", + "icon": null, + "architectures": [ + "amd64" + ], + "updated_at": "2026-08-27", + "main_image": "nextcloud:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/nextcloud-stack.json", + "template": "apps/nextcloud-stack.json", + "template_status": "generated-unvalidated", + "content_hash": "67e00f5a913724022e4262ef62ed61d65c18a462dff103d862fd72c9dd9ce955", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "nginx", + "provider": "linuxserver.io", + "title": "Nginx", + "repository_name": "docker-nginx", + "repository": "https://github.com/linuxserver/docker-nginx", + "description": "Nginx is an HTTP web server, reverse proxy, content cache, load balancer, TCP/UDP proxy server, and mail proxy server.", + "website": "https://nginx.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nginx-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T09:03:57Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/nginx:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/nginx.json", + "template_status": "generated-unvalidated", + "content_hash": "9a03ac3c92a200386d640e96174d7dae2ff2c17f6a121445c5b15b4388e6e3df", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "nginxproxymanager", + "source_app_id": "nginxproxymanager", + "provider": "jc21", + "template_family": "imported-compose", + "variant": null, + "title": "Nginx Proxy Manager", + "repository": "https://hub.docker.com/r/jc21/nginx-proxy-manager", + "description": "Nginx Proxy Manager is a simple, powerful tool to help you host multiple websites on a single server.", + "website": "https://nginxproxymanager.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/NginxProxyManager/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-11-18", + "main_image": "jc21/nginx-proxy-manager:latest", + "category": "web", + "category_label": "Webservers & Proxies", + "template": "apps/nginxproxymanager.json", + "template_status": "generated-unvalidated", + "content_hash": "b77833e78c20f9610927f929cc961d65c092f94261f789fcd413980060c65d66", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ngircd", + "provider": "linuxserver.io", + "title": "Ngircd", + "repository_name": "docker-ngircd", + "repository": "https://github.com/linuxserver/docker-ngircd", + "description": "Ngircd is a free, portable and lightweight Internet Relay Chat server for small or private networks, developed under the GNU General Public License (GPL). It is easy to configure, can cope with dynamic IP addresses, and supports IPv6, SSL-protected connections as well as PAM for authentication. It is written from scratch and not based on the original IRCd.", + "website": "https://ngircd.barton.de/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ngircd-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-07-11T15:45:47Z", + "updated_at": "2024-10-14", + "main_image": "lscr.io/linuxserver/ngircd:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/ngircd.json", + "template_status": "generated-unvalidated", + "content_hash": "cc1a8c9d07caed3be713c73e24fae3d272d306788a954f7bc2027ff6db46ea6d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "node-red", + "source_app_id": "node-red", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Node-RED", + "repository": "https://hub.docker.com/r/nodered/node-red", + "description": "Node-RED is a flow-based low-code development platform that enables creating automation tasks and applications by connecting various nodes. A browser-based editor, simple to use, makes it ideal for users in home automation, industrial control, or other fields to quickly build data processing flows.\n\nCore features include a low-code flow editor and robust data handling. Built on Node.js with an event-driven, non-blocking model, the platform supports real-time data collection, transformation, and visualization. A palette with over 5000 nodes allows users to construct flows via drag-and-drop. A rich text editor enables creating JavaScript functions for enhanced customization.\n\nIt stores flows in JSON format, facilitating easy import and export for sharing. A built-in library allows saving useful functions, templates, or flows for reuse, and an online flow library supports sharing top flows globally. With ease of use and efficiency at the core, the platform delivers a modern solution for diverse automation needs.\n\n**Key Features:**\n- Browser-based low-code flow editor with drag-and-drop node connections\n- Real-time data collection, transformation, and visualization\n- Event-driven, non-blocking model with Node.js\n- Palette with over 5000 nodes for extended functionality\n- Rich text editor for creating JavaScript functions\n- JSON-based flow storage for easy sharing\n- Built-in library for saving functions, templates, and flows\n- Online flow library for sharing top flows\n\n**Learn More:**\n- [Node-RED Official Website](https://nodered.org/)\n- [Node-RED GitHub](https://github.com/node-red/node-red)\n", + "website": "https://nodered.org/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Node-RED/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-08", + "main_image": "nodered/node-red:latest", + "category": "smarthome", + "category_label": "IoT & Smart Home", + "template": "apps/node-red.json", + "template_status": "generated-unvalidated", + "content_hash": "128efc3f542c4daa1aa4655e20b7652964b364b4b5cecdffe81f3aa3637d0b98", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "nzbfast", + "source_app_id": "nzbfast", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "nzbfast", + "repository": "https://hub.docker.com/r/nzbfast/nzbfast", + "description": "nzbfast is a speed-focused Usenet (NZB) downloader written in Rust. It is one small binary with a low memory footprint, and it saturates a fast line with a handful of connections.\n\nArticles are verified while they arrive, so most jobs finish with no separate verify pass. Repair and unpack run only when they are actually needed, and extraction starts before the last article lands.\n\nThe web dashboard on port 6790 also serves a SABnzbd-compatible API, so Sonarr, Radarr, Prowlarr and friends work with no extra glue. Add an .nzb from the dashboard, or drop one into the watch folder.\n\nFirst run: open the dashboard, add your Usenet provider under Settings, and copy the API key it shows you into your *arr apps. If you would rather pin the key yourself so it survives a reinstall, set NZBFAST_APIKEY before the first start. Leave it empty and nzbfast generates one for you.", + "website": "https://nzbfast.github.io/nzbfast/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/nzbfast/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-09-01", + "main_image": "nzbfast/nzbfast:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/nzbfast.json", + "template_status": "generated-unvalidated", + "content_hash": "2524d33ba6db616fcf5d7d737c09b110b519764e429cad2f77be6d22c6c6fde3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "nzbget", + "provider": "linuxserver.io", + "title": "Nzbget", + "repository_name": "docker-nzbget", + "repository": "https://github.com/linuxserver/docker-nzbget", + "description": "Nzbget is a usenet downloader, written in C++ and designed with performance in mind to achieve maximum download speed by using very little system resources.", + "website": "http://nzbget.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nzbget-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T18:54:13Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/nzbget:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/nzbget.json", + "template_status": "generated-unvalidated", + "content_hash": "c1f0c1f10c4fd651436b305ea36755901d4d53c0e309de9cf6c0e27ef958fc58", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "nzbhydra2", + "provider": "linuxserver.io", + "title": "Nzbhydra2", + "repository_name": "docker-nzbhydra2", + "repository": "https://github.com/linuxserver/docker-nzbhydra2", + "description": "Nzbhydra2 is a meta search application for NZB indexers, the spiritual successor to NZBmegasearcH, and an evolution of the original application NZBHydra.", + "website": "https://github.com/theotherp/nzbhydra2", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/nzbhydra2-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T23:57:43Z", + "updated_at": "2024-07-18", + "main_image": "lscr.io/linuxserver/nzbhydra2:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/nzbhydra2.json", + "template_status": "generated-unvalidated", + "content_hash": "9904215820e2919283e2d348b9fbd0e1ff0c7d3ce3188a3a74be4077ea57b0d2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "obsidian", + "provider": "linuxserver.io", + "title": "Obsidian", + "repository_name": "docker-obsidian", + "repository": "https://github.com/linuxserver/docker-obsidian", + "description": "Obsidian is a note-taking app that lets you create, link, and organize your notes on your device, with hundreds of plugins and themes to customize your workflow. You can also publish your notes online, access them offline, and sync them securely with end-to-end encryption.", + "website": "https://obsidian.md", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/obsidian-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-06T14:25:02Z", + "updated_at": "2026-04-03", + "main_image": "lscr.io/linuxserver/obsidian:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/obsidian.json", + "template_status": "generated-unvalidated", + "content_hash": "67c69f6c9c0591f35736d94a6f5289d8fecbca454f1644bb6b5b4bba883c8663", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ollama", + "source_app_id": "ollama", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Ollama", + "repository": "https://hub.docker.com/r/ollama/ollama", + "description": "Ollama is a tool for running large language models locally, designed to help users quickly deploy and manage AI models via a simple command-line interface and server. Its intuitive Web interface and efficient design make it ideal for developers, researchers, and AI enthusiasts working on local hardware.\n\nThe tool's core features include local model execution and multi-model support. It enables running models like Llama 3, Mistral, and Gemma, with simple commands for downloading and switching models. All data processing occurs locally, ensuring privacy. Low resource usage optimizes model loading, allowing smooth operation on limited hardware.\n\nIt offers a RESTful API for application integration and supports tool calling (e.g., Llama 3.1) for complex tasks. Model management via Modelfile bundles weights and configurations for ease of use. The tool's efficiency and user control deliver a modern local AI solution.\n\n**Key Features:**\n- **Local Execution**: Run LLMs directly on your hardware without internet dependency\n- **Multiple Model Support**: Access to dozens of pre-trained models including Llama 3, Mistral, Gemma, Code Llama, and more\n- **Easy Model Management**: Simple commands to pull, run, and manage different models\n- **API Integration**: RESTful API for building applications and integrations\n- **Memory Efficient**: Optimized model loading and memory management\n- **Privacy-Focused**: All processing happens locally, ensuring data privacy\n\n**Supported Models:**\n- DeepSeek-R1 (1.5B, 7B, 8B, 14B, 32B, 70B, 671B parameters)\n- Gemma3n (2B, 4B parameters)\n- Gemma3 (1B, 4B, 12B, 27B parameters)\n- Qwen3 (0.6B, 1.7B, 4B, 8B, 14B, 30B, 32B, 235B parameters)\n- Qwen2.5vl (3B, 7B, 32B, 72B parameters)\n- Llama3.1 (8B, 70B, 405B parameters)\n- Llama3.2 (1B, 3B parameters)\n- Mistral (7B parameters)\n- And many more...\n\n**Use Cases:**\n- Local AI development and experimentation\n- Educational purposes and research\n- Building AI-powered applications\n- Code generation and assistance\n- Text generation and completion\n- Chatbots and conversational AI\n- Data analysis and insights\n\n**Learn More:**\n- [Ollama Official Website](https://ollama.com/)\n- [Ollama GitHub Repository](https://github.com/ollama/ollama)\n- [Model Library](https://ollama.com/library)\n", + "website": "https://ollama.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Ollama/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ollama/ollama:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/ollama.json", + "template_status": "generated-unvalidated", + "content_hash": "be933d7111c9ba289dbb51adb329a40a574d04de6d1bb0d8234c031c4952e0b0", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ombi", + "provider": "linuxserver.io", + "title": "Ombi", + "repository_name": "docker-ombi", + "repository": "https://github.com/linuxserver/docker-ombi", + "description": "Ombi allows you to host your own Plex Request and user management system.", + "website": "https://ombi.io", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ombi-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T00:20:56Z", + "updated_at": "2024-07-08", + "main_image": "lscr.io/linuxserver/ombi:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/ombi.json", + "template_status": "generated-unvalidated", + "content_hash": "9f9572f62a233b6608a5bb2832a91b5b023ce06b9548aa72be526ce5298a0890", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "onlyoffice", + "provider": "linuxserver.io", + "title": "Onlyoffice", + "repository_name": "docker-onlyoffice", + "repository": "https://github.com/linuxserver/docker-onlyoffice", + "description": "ONLYOFFICE provides a full range of tools to create, edit and collaborate on text documents, spreadsheets, presentations, PDF forms and regular PDF files on web, desktop and mobile platforms.", + "website": "https://www.onlyoffice.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/onlyoffice-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T11:35:22Z", + "updated_at": "2026-03-29", + "main_image": "lscr.io/linuxserver/onlyoffice:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/onlyoffice.json", + "template_status": "generated-unvalidated", + "content_hash": "617e57253991a4dbffe910e7e51851d187ccba621aec52bbed3e6c1f912538ec", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "open-webui", + "provider": "open-webui", + "template_family": "curated-profile", + "title": "Open WebUI", + "repository": "https://ghcr.io/open-webui/open-webui", + "description": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n", + "website": "https://openwebui.com", + "icon": null, + "architectures": [ + "amd64" + ], + "updated_at": null, + "main_image": "ghcr.io/open-webui/open-webui:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/open-webui.json", + "template": "apps/open-webui.json", + "template_status": "generated-unvalidated", + "content_hash": "5578979958bdfabcd228df3ec767f11dae6b519a67f8ddbeb7f71b9417bac20f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "open-webui-cuda", + "provider": "open-webui", + "template_family": "curated-profile", + "title": "Open WebUI CUDA", + "repository": "https://ghcr.io/open-webui/open-webui", + "description": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n", + "website": "https://openwebui.com", + "icon": null, + "architectures": [ + "amd64" + ], + "updated_at": null, + "main_image": "ghcr.io/open-webui/open-webui:cuda", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/open-webui-cuda.json", + "template": "apps/open-webui-cuda.json", + "template_status": "generated-unvalidated", + "content_hash": "bdd21c3576bbd6e99959eaa54ed2d4b14ca596ad99eac33dc63330540e9f5dc3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "open-webui-ollama", + "provider": "open-webui", + "template_family": "curated-profile", + "title": "Open WebUI + Ollama", + "repository": "https://ghcr.io/open-webui/open-webui", + "description": "Open WebUI is a feature-rich, user-friendly self-hosted AI platform designed for fully offline operation, supporting multiple large language model runners and API integration. Its intuitive Web interface provides powerful AI deployment capabilities, ideal for developers, researchers, and AI enthusiasts building localized intelligent applications.\n\nThe tool's core features include local model execution and Retrieval Augmented Generation (RAG). It supports Ollama and OpenAI-compatible APIs (e.g., LMStudio, GroqCloud), enabling seamless model switching and multi-model conversations. RAG enhances chat experiences through local document loading or web search integration (e.g., SearXNG, Google PSE). Granular permissions and role-based access control (RBAC) ensure security with customized user role management.\n\nIt supports Markdown and LaTeX for enriched interactions and offers hands-free voice and video call features for dynamic communication. Image generation integration (e.g., DALL-E, ComfyUI) enriches visual content, and a model builder enables creating and importing custom models via the interface. The Pipelines plugin framework supports Python plugins, extending functionality like function calling and real-time translation. The tool\u2019s offline privacy and flexibility deliver a modern AI interaction solution.\n\n**Key Features:**\n- Local execution of Ollama and OpenAI-compatible APIs with multi-model conversations\n- RAG support with local document and web search integration (e.g., SearXNG, Google PSE)\n- Granular permissions and role-based access control (RBAC)\n- Simultaneous interaction with multiple models, leveraging their strengths\n- Image generation integration with DALL-E, ComfyUI, and more\n- Full Markdown and LaTeX support\n- Hands-free voice and video call functionality\n- Pipelines plugin framework for custom Python functionality\n\n**Learn More:**\n- [Open WebUI Official Website](https://openwebui.com)\n- [Open WebUI Documentation](https://docs.openwebui.com)\n- [Open WebUI GitHub Repository](https://github.com/open-webui/open-webui)\n", + "website": "https://openwebui.com", + "icon": null, + "architectures": [ + "amd64" + ], + "updated_at": null, + "main_image": "ghcr.io/open-webui/open-webui:ollama", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "replaces_discovered_ids": [ + "open-webui-ollama" + ], + "curated_path": "catalog/curated/open-webui-ollama.json", + "template": "apps/open-webui-ollama.json", + "template_status": "generated-unvalidated", + "content_hash": "2b3a28b5b3ae2ca98fbf6a36751d2b1dd3ad2bda839704ead89405ab6900a4ac", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "openclaw", + "source_app_id": "openclaw", + "provider": "icewhaletech", + "template_family": "imported-compose", + "variant": null, + "title": "OpenClaw", + "repository": "https://hub.docker.com/r/icewhaletech/openclaw", + "description": "OpenClaw is an open-source personal AI assistant designed to extend the capabilities of large language models (LLMs) into intelligent agents that actively execute tasks, interact across multiple platforms, and operate continuously. It supports 24/7 operation on the user's own device or server and provides intelligent automation services through common communication tools. OpenClaw connects AI to existing chat channels (such as WhatsApp, Telegram, Discord, etc.) via a locally running \"gateway + agent\" architecture, enabling it not only to answer questions but also to proactively perform actions, manage schedules, process emails, automate workflows, and more.\n\n**Key Features**:\n\n- Multi-channel Communication Integration: Interact directly with AI through common communication platforms like WhatsApp, Telegram, Slack, Discord, Signal, iMessage, Microsoft Teams, etc., without the need for additional applications.\n\n- Continuous Online & Long-term Memory: OpenClaw can run 24/7, possessing persistent memory and context retention capabilities, allowing it to remember preferences, historical conversations, and provide personalized services.\n\n- Real Action Execution: Beyond text replies, it can perform system tasks (e.g., clear inbox, send emails, fill forms, schedule appointments, browse web, control browser, etc.).\n\n- Skill Expansion & Automated Workflows: Supports community plugins, extended skills, and custom automation scripts, enabling the AI to execute complex tasks in various scenarios.\n\n**Learn More:**\n\n- [Official Website](https://openclaw.ai)\n\n- [Official Documentation](https://docs.openclaw.ai/)\n\n- [OpenClaw GitHub Repository](https://github.com/openclaw/openclaw)\n\n- [Configure Guide](https://www.self-hosted serverspace.com/docs/self-hosted server/How-to-Deploy-OpenClaw)", + "website": "https://openclaw.ai", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/OpenClaw/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-13", + "main_image": "icewhaletech/openclaw:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/openclaw.json", + "template_status": "generated-unvalidated", + "content_hash": "8ed49fe47c989e6eb37aa8dd89cad262da7b31be070508dda249dfc9a0380196", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "openhab", + "source_app_id": "openhab", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "OpenHAB", + "repository": "https://hub.docker.com/r/openhab/openhab", + "description": "The open Home Automation Bus (openHAB, pronounced \u02c8\u0259\u028ap\u0259n\u02c8h\u00e6b) is an open source, technology agnostic home automation platform which runs as the center of your smart home! Its ability to integrate a multitude of other devices and systems. openHAB includes other home automation systems, (smart) devices and other technologies into a single solution. To provide a uniform user interface and a common approach to automation rules across the entire system, regardless of the number of manufacturers and sub-systems involved. Giving you the most flexible tool available to make almost any home automation wish come true; if you can think it, odds are that you can implement it with openHAB.", + "website": "https://www.openhab.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/OpenHAB/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-14", + "main_image": "openhab/openhab:latest", + "category": "smarthome", + "category_label": "IoT & Smart Home", + "template": "apps/openhab.json", + "template_status": "generated-unvalidated", + "content_hash": "70e86f17e7ceb691394c8021e61af8a671bb3f96a28f73a183c2fa89fc61cdc9", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "openhands", + "source_app_id": "openhands", + "provider": "all-hands-ai", + "template_family": "imported-compose", + "variant": null, + "title": "OpenHands", + "repository": "https://ghcr.io/all-hands-ai/openhands", + "description": "OpenHands is an open-source AI-powered coding assistant that provides developers with intelligent code completion, generation, and debugging capabilities. It runs in a sandboxed environment to ensure security and isolation while allowing access to various development tools and resources.\n\n**Key Features:**\n- AI-powered code completion and generation\n- Interactive debugging and error resolution\n- Support for multiple programming languages\n- Secure sandboxed execution environment\n- Customizable runtime configurations\n- Integration with Docker for containerized workflows\n\n**Learn More:**\n- [OpenHands Official Website](https://www.all-hands.dev)\n- [OpenHands GitHub Repository](https://github.com/All-Hands-AI/OpenHands)\n- [Documentation](https://docs.all-hands.dev)\n", + "website": "https://www.openhands.dev/", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/OpenHands/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-10-10", + "main_image": "ghcr.io/all-hands-ai/openhands:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/openhands.json", + "template_status": "generated-unvalidated", + "content_hash": "d12053234bd92b4e4a218072a912d75486828264c587bc8c2b34ee2f92604384", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "openlist", + "source_app_id": "openlist", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "OpenList", + "repository": "https://hub.docker.com/r/openlistteam/openlist", + "description": "OpenList is a community-driven, self-hosted file listing and cloud drive mounting service that supports multiple storage backends in one place.\nIt brings local storage plus services like OneDrive, Google Drive, S3, WebDAV, SMB, and many other providers into one browser-based file hub.\nWith previews, uploads, sharing, WebDAV, offline download, and package download built in, it works well for home NAS setups, personal cloud libraries, and lightweight team file portals.\n\n**Main Features:**\n- Connect local disks, cloud drives, object storage, and WebDAV or SMB endpoints in one place\n- Preview documents, images, audio, video, code, Markdown, and Office files directly in the browser\n- Upload, move, rename, copy, delete, and batch download files and folders from a single interface\n- Enable WebDAV, protected routes, sharing, dark mode, and multi-language support\n- Support offline downloads, cross-storage file copying, and multi-thread acceleration\n\n**Learn More:**\n- [OpenList Official Website](https://oplist.org/)\n- [OpenList GitHub](https://github.com/OpenListTeam/OpenList)\n", + "website": "https://oplist.org/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/OpenList/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-25", + "main_image": "openlistteam/openlist:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/openlist.json", + "template_status": "laboratory-validated", + "content_hash": "b3203fceb0965da9393f9fe3fd380a377df69a5080245da2ecf946763e1472cf", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "openshot", + "provider": "linuxserver.io", + "title": "Openshot", + "repository_name": "docker-openshot", + "repository": "https://github.com/linuxserver/docker-openshot", + "description": "OpenShot Video Editor is an award-winning free and open-source video editor for Linux, Mac, and Windows, and is dedicated to delivering high quality video editing and animation solutions to the world.", + "website": "https://openshot.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openshot-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "main", + "pushed_at": "2026-09-12T00:56:49Z", + "updated_at": "2026-08-07", + "main_image": "lscr.io/linuxserver/openshot:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/openshot.json", + "template_status": "generated-unvalidated", + "content_hash": "ed06e4e88482a7367eadac7ca014629d0144bc64e82b0a40774505945a85bfe9", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "openspeedtest", + "source_app_id": "openspeedtest", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "OpenSpeedTest", + "repository": "https://hub.docker.com/r/openspeedtest/latest", + "description": "An application for launching HTML5 Network Speed Test Server. You can test download & upload speed from any device within your network with a web browser that is IE10 or new.", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/OpenSpeedTest/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-01-09", + "main_image": "openspeedtest/latest:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/openspeedtest.json", + "template_status": "generated-unvalidated", + "content_hash": "08fb7d4b29331c86f918962b5f4eb0cfd25f7800a832a312cfed6b869796e38a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "openssh-server", + "provider": "linuxserver.io", + "title": "Openssh Server", + "repository_name": "docker-openssh-server", + "repository": "https://github.com/linuxserver/docker-openssh-server", + "description": "Openssh-server is a sandboxed environment that allows ssh access without giving keys to the entire server.", + "website": "https://www.openssh.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openssh-server-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-06T21:01:44Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/openssh-server:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/openssh-server.json", + "template_status": "laboratory-validated", + "content_hash": "c3b7c81dd77bc5739a1a6881cd3c94750774596e3fb53f3e549456c643bc194d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "openvscode-server", + "provider": "linuxserver.io", + "title": "Deprecation Notice", + "repository_name": "docker-openvscode-server", + "repository": "https://github.com/linuxserver/docker-openvscode-server", + "description": "Openvscode-server provides a version of VS Code that runs a server on a remote machine and allows access through a modern web browser.", + "website": "https://github.com/gitpod-io/openvscode-server", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/openvscode-server-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-07-16T16:49:20Z", + "updated_at": "2024-08-19", + "main_image": "lscr.io/linuxserver/openvscode-server:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/openvscode-server.json", + "template_status": "generated-unvalidated", + "content_hash": "8b2e77ba8ba0482319da163c58cb606d486d2caf43c29d01412f827fbd05d550", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "opera", + "provider": "linuxserver.io", + "title": "Opera", + "repository_name": "docker-opera", + "repository": "https://github.com/linuxserver/docker-opera", + "description": "Opera is a multi-platform web browser developed by its namesake company Opera. The browser is based on Chromium, but distinguishes itself from other Chromium-based browsers (Chrome, Edge, etc.) through its user interface and other features.", + "website": "https://www.opera.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/opera-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T14:55:26Z", + "updated_at": "2026-03-31", + "main_image": "lscr.io/linuxserver/opera:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/opera.json", + "template_status": "generated-unvalidated", + "content_hash": "a61303b8c14b0ae83335582fcb62a7f920cd88b2a167a61fe82f423fb5916824", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "opodsync", + "source_app_id": "opodsync", + "provider": "ganeshlab", + "template_family": "imported-compose", + "variant": null, + "title": "oPodSync", + "repository": "https://hub.docker.com/r/ganeshlab/opodsync", + "description": "oPodSync is a podcast synchronization service that allows users to sync their podcast subscriptions and listening progress across multiple devices. It provides a server-side solution for managing podcast data and ensures that users can seamlessly switch between their devices.\n\n**Key Features:**\n- Sync podcast subscriptions\n- Track listening progress across devices\n- Web-based management interface\n- Support for multiple podcast clients\n- Centralized data storage\n- Easy setup and configuration\n\n**Learn More:**\n- [oPodSync GitHub Repo](https://github.com/kd2org/oPodSync)\n", + "website": "https://fossil.kd2.org/opodsync/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/oPodSync/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-01", + "main_image": "ganeshlab/opodsync:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/opodsync.json", + "template_status": "generated-unvalidated", + "content_hash": "ddf2fa1a7a5be83f6c7fc9d0e51a83aea64414b5a95da75ab5b80ed6061750f2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "orcaslicer", + "provider": "linuxserver.io", + "title": "Orcaslicer", + "repository_name": "docker-orcaslicer", + "repository": "https://github.com/linuxserver/docker-orcaslicer", + "description": "Orca Slicer is an open source slicer for FDM printers. OrcaSlicer is fork of Bambu Studio, it was previously known as BambuStudio-SoftFever, Bambu Studio is forked from PrusaSlicer by Prusa Research, which is from Slic3r by Alessandro Ranellucci and the RepRap community", + "website": "https://github.com/SoftFever/OrcaSlicer", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/orcaslicer-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T17:21:08Z", + "updated_at": "2026-06-20", + "main_image": "lscr.io/linuxserver/orcaslicer:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/orcaslicer.json", + "template_status": "generated-unvalidated", + "content_hash": "7168aad5ee382925e6d4138fd2780f9c4872a602bfcd6d56be53be637d14299a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "oscam", + "provider": "linuxserver.io", + "title": "Oscam", + "repository_name": "docker-oscam", + "repository": "https://github.com/linuxserver/docker-oscam", + "description": "Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.", + "website": "https://git.streamboard.tv/common/oscam", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/oscam-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T13:22:43Z", + "updated_at": "2026-07-17", + "main_image": "lscr.io/linuxserver/oscam:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/oscam.json", + "template_status": "generated-unvalidated", + "content_hash": "8372c7d49f28c4a25472eee29955ba229ad9e54cebd4bd273b19f2ca9281e111", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "overseerr", + "source_app_id": "overseerr", + "provider": "linuxserver.io", + "template_family": "imported-compose", + "variant": null, + "title": "Overseerr", + "repository": "https://hub.docker.com/r/linuxserver/overseerr", + "description": "Overseerr is a free and open source software application for managing requests for your media library. It integrates with your existing services, such as Sonarr, Radarr, and Plex!", + "website": "https://overseerr.dev", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Overseerr/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-02-16", + "main_image": "linuxserver/overseerr:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/overseerr.json", + "template_status": "generated-unvalidated", + "content_hash": "be689b1022556d2c7f1d125d770bdff31e45044829926a7bfe72df82a9edc75c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pairdrop", + "provider": "linuxserver.io", + "title": "Pairdrop", + "repository_name": "docker-pairdrop", + "repository": "https://github.com/linuxserver/docker-pairdrop", + "description": "PairDrop is a sublime alternative to AirDrop that works on all platforms. Send images, documents or text via peer to peer connection to devices in the same local network/Wi-Fi or to paired devices.", + "website": "https://github.com/schlagmichdoch/PairDrop", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pairdrop-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-12T14:37:28Z", + "updated_at": "2025-07-05", + "main_image": "lscr.io/linuxserver/pairdrop:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/pairdrop.json", + "template_status": "generated-unvalidated", + "content_hash": "8ec4f8f374304aa4178cfb27949e5e203b00682057392a0f8a42bf6ccb92628b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "paperless-ngx", + "provider": "paperless-ngx", + "template_family": "curated-profile", + "title": "Paperless-ngx", + "repository": "https://github.com/paperless-ngx/paperless-ngx", + "description": "Official Paperless-ngx deployment with private PostgreSQL and Valkey dependencies.", + "website": "https://docs.paperless-ngx.com/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-13", + "main_image": "ghcr.io/paperless-ngx/paperless-ngx:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "replaces_discovered_ids": [ + "paperless-ngx" + ], + "curated_path": "catalog/curated/paperless-ngx.json", + "template": "apps/paperless-ngx.json", + "template_status": "laboratory-validated", + "content_hash": "62d8ee64c5818c4c0c564ea9a8cc6515ff98ed252361a5bf2d6a747a770e9e56", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pcsx2", + "provider": "linuxserver.io", + "title": "Pcsx2", + "repository_name": "docker-pcsx2", + "repository": "https://github.com/linuxserver/docker-pcsx2", + "description": "PCSX2 is an open source PS2 Emulator.", + "website": "https://pcsx2.net/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pcsx2-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T23:09:27Z", + "updated_at": "2026-04-29", + "main_image": "lscr.io/linuxserver/pcsx2:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/pcsx2.json", + "template_status": "generated-unvalidated", + "content_hash": "f39a306e91011977bf55b7eb29f80307950eea0fcc56b3713a6a45cd1ce2d732", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pdfding", + "source_app_id": "pdfding", + "provider": "mrmn", + "template_family": "imported-compose", + "variant": null, + "title": "PdfDing", + "repository": "https://hub.docker.com/r/mrmn/pdfding", + "description": "PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. It's designed to be minimal, fast, and easy to set up using Docker.\n\nWith features like seamless browser-based PDF viewing that remembers your current position, multi-level tagging, starring and archiving functionalities, PDF editing with comments, highlighting and drawings, clean intuitive UI with dark mode, SSO support via OIDC, PDF sharing with external audience, markdown notes, and progress bars showing reading progress, PdfDing ensures an excellent PDF management experience.\n\nDeploying PdfDing on private cloud devices like self-hosted server brings unmatched convenience with multi-device access, ensuring your PDF collection is always within reach and secure, no matter where you are.\n", + "website": "https://www.pdfding.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/PdfDing/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-12", + "main_image": "mrmn/pdfding:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/pdfding.json", + "template_status": "generated-unvalidated", + "content_hash": "fbb93793032b8b6cfcd7ed783296544fe6e255c643a53af8390d1b5855fe2f5b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "peanut", + "source_app_id": "peanut", + "provider": "brandawg93", + "template_family": "imported-compose", + "variant": null, + "title": "PeaNUT", + "repository": "https://hub.docker.com/r/brandawg93/peanut", + "description": "PeaNUT is a web-based UPS monitoring system specifically designed for monitoring Uninterruptible Power Supplies (UPS). It provides a user-friendly interface for monitoring UPS status, battery life, and power outage notifications to ensure your systems are always protected.\n\n**Key Features:**\n- Real-time UPS status monitoring and control\n- Battery life and charge level monitoring\n- Automatic power outage notifications via email/webhook\n- Historical data logging and reporting\n- Support for various UPS manufacturers and models\n- Mobile-friendly responsive web interface for remote access\n- Configurable warning thresholds and alerts\n- Docker-based deployment for easy installation\n\n**Learn More:**\n- [PeaNUT GitHub Repository](https://github.com/brandawg93/peanut)\n", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Peanut/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-02", + "main_image": "brandawg93/peanut:latest", + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "template": "apps/peanut.json", + "template_status": "generated-unvalidated", + "content_hash": "386b180d3aed2b59bec0b7ce9bf0437469fbd40cb09d59e5b938116fd83fa39b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pelorus", + "provider": "linuxserver.io", + "title": "Pelorus", + "repository_name": "docker-pelorus", + "repository": "https://github.com/linuxserver/docker-pelorus", + "description": "Pelorus is an AI navigator for Selkies-powered Linux desktops. Pelorus runs a FastAPI server that gives an LLM agent (Ollama, OpenAI-compatible, or Gemini) control over mouse, keyboard, screenshot, and window management via the Pixelflux computer-use backend, a Linux accessibility tree (AT-SPI), and optional KWin D-Bus integration.", + "website": "https://github.com/linuxserver/pelorus", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pelorus-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T05:58:26Z", + "updated_at": "2026-07-19", + "main_image": "lscr.io/linuxserver/pelorus:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/pelorus.json", + "template_status": "generated-unvalidated", + "content_hash": "ff9ffa5ec20c0bcb4c4edd6eb15555197d63d57e813b3c097078f0a3e05fbfe7", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "petio", + "source_app_id": "petio", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Petio", + "repository": "https://ghcr.io/petio-team/petio", + "description": "Petio is a third party companion app available to Plex server owners to allow their users to request, review and discover content. The app is built to appear instantly familiar and intuitive to even the most tech-agnostic users. Petio will help you manage requests from your users, connect to other third party apps such as Sonarr and Radarr, notify users when content is available and track request progress. Petio also allows users to discover media both on and off your server, quickly and easily find related content and review to leave their opinion for other users.\n\nPetio is an ongoing, forever free, always evolving project currently in alpha prototype stage and now available!\n", + "website": "https://petio.tv", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Petio/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ghcr.io/petio-team/petio:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/petio.json", + "template_status": "generated-unvalidated", + "content_hash": "81f3550079fe26a5635452491fe264f192d1ca2e9e9864eb19abd2531247f848", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "photoprism", + "source_app_id": "photoprism", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "PhotoPrism", + "repository": "https://hub.docker.com/r/photoprism/photoprism", + "description": "Your AI-Powered Photos App for the Decentralized Web\n\nPhotoPrism brings the magic of AI to your home TV, phone, and multiple devices, revolutionizing the way you manage and share your photos. Unlike traditional photo albums that require manual organization, PhotoPrism automatically tags and finds your pictures, making it easier than ever to relive your memories. Whether you're showing family photos on your TV or sharing vacation snapshots on your phone, PhotoPrism makes the experience seamless and enjoyable.\n\nPhotoPrism offers a host of features designed to enhance your photo management experience. With powerful search capabilities, automatic tagging, and a user-friendly interface, you'll find it easy to keep your photo collection organized. The app is free to use, with premium options available for those seeking additional features and support. Users can expect a smooth, intuitive experience that blends cutting-edge technology with everyday convenience.\n\nDeploying PhotoPrism on self-hosted server private cloud devices offers unparalleled convenience. Enjoy unlimited storage capacity, the speed of your local network, and access from multiple devices without the need for the internet. It's the perfect solution for NAS enthusiasts who value privacy and performance.\n", + "website": "https://www.photoprism.app", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/PhotoPrism/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-23", + "main_image": "photoprism/photoprism:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/photoprism.json", + "template_status": "generated-unvalidated", + "content_hash": "cd0cef614f9f3850e52f2b4f78d43af4c13a0c3ca8566adde4a4c3440d2dbabd", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "phpmyadmin", + "provider": "linuxserver.io", + "title": "Phpmyadmin", + "repository_name": "docker-phpmyadmin", + "repository": "https://github.com/linuxserver/docker-phpmyadmin", + "description": "Phpmyadmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB.", + "website": "https://github.com/phpmyadmin/phpmyadmin/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/phpmyadmin-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-11T23:39:09Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/phpmyadmin:latest", + "category": "databases", + "category_label": "Databases", + "template": "apps/phpmyadmin.json", + "template_status": "laboratory-validated", + "content_hash": "48030a8e4362e982a8c2137381e0f419132c53122032fb70c42fe9f63fcc00b4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pidgin", + "provider": "linuxserver.io", + "title": "Pidgin", + "repository_name": "docker-pidgin", + "repository": "https://github.com/linuxserver/docker-pidgin", + "description": "Pidgin is a chat program which lets you log into accounts on multiple chat networks simultaneously. This means that you can be chatting with friends on XMPP and sitting in an IRC channel at the same time.", + "website": "https://pidgin.im/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pidgin-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T21:47:20Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/pidgin:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/pidgin.json", + "template_status": "generated-unvalidated", + "content_hash": "d8de7834c0ffd9dd7134404c079ffdd689d940368810bc575e764504b3a39d95", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pihole", + "source_app_id": "pihole", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Pi-hole", + "repository": "https://hub.docker.com/r/pihole/pihole", + "description": "Pi-hole is a network-wide ad-blocking platform for Linux hardware, using DNS sinkhole technology to protect devices from unwanted content without requiring client-side software. Designed for home or enterprise networks, it offers efficient ad blocking and network optimization.\n\nCore features include network-wide ad blocking and content blocking in non-browser environments. It uses DNS sinkhole to block ads, covering mobile apps and smart TVs. Caching DNS queries speeds up everyday browsing. A command-line interface ensures interoperability with reliable control options.\n\nIt provides an intuitive web interface dashboard for viewing and managing system status. An optional DHCP server function automatically protects all devices. Capable of handling high query volumes on server-grade hardware, it supports ad blocking over IPv4 and IPv6. With efficiency and versatility at the core, the platform delivers a modern network protection solution.\n\n**Key Features:**\n- Network-wide ad blocking via DNS sinkhole technology\n- Blocking content in non-browser environments, including mobile apps and smart TVs\n- Caching DNS queries to speed up browsing\n- Command-line interface for interoperability\n- Intuitive web interface dashboard for system viewing and control\n- Optional DHCP server function for automatic device protection\n- Ad blocking support for IPv4 and IPv6\n\n**Learn More:**\n- [Pi-hole Official Website](https://pi-hole.net/)\n- [Pi-hole GitHub](https://github.com/pi-hole/pi-hole)\n", + "website": "https://pi-hole.net/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Pihole/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-11", + "main_image": "pihole/pihole:latest", + "category": "adblock", + "category_label": "Adblock & DNS", + "template": "apps/pihole.json", + "template_status": "generated-unvalidated", + "content_hash": "c13691710f10692c311cd9f013e2373a99b08fc6fae1d2c44686f89f0767d4c4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pinchflat", + "source_app_id": "pinchflat", + "provider": "kieraneglin", + "template_family": "imported-compose", + "variant": null, + "title": "Pinchflat", + "repository": "https://ghcr.io/kieraneglin/pinchflat", + "description": "Pinchflat is a self-hosted app for downloading YouTube content built using yt-dlp. It's designed to be lightweight, self-contained, and easy to use. You set up rules for how to download content from YouTube channels or playlists and it'll do the rest, periodically checking for new content.\n\nKey features include:\n- Self-contained - just one Docker container with no external dependencies\n- Powerful naming system so content is stored where and how you want it\n- Easy-to-use web interface with presets to get you started right away\n- First-class support for media center apps like Plex, Jellyfin, and Kodi\n- Supports serving RSS feeds to your favourite podcast app\n- Automatically downloads new content from channels and playlists\n- Supports downloading audio content\n- Custom rules for handling YouTube Shorts and livestreams\n- Apprise support for notifications\n- Optionally automatically delete old content\n- Advanced options like setting cutoff dates and filtering by title\n- Reliable hands-off operation\n- Can pass cookies to YouTube to download your private playlists\n- Sponsorblock integration\n- Supports running custom scripts when after downloading/deleting media\n\nPerfect for people who want to download content for use with a media center app or for those who want to archive media!\n", + "website": "", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/Pinchflat/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-09-27", + "main_image": "ghcr.io/kieraneglin/pinchflat:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/pinchflat.json", + "template_status": "generated-unvalidated", + "content_hash": "47460dc255e205dceaeda44ccd34e4083fa47430db0ba733c0c06d1c0eb5bbeb", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pingvin-share", + "source_app_id": "pingvin-share", + "provider": "stonith404", + "template_family": "imported-compose", + "variant": null, + "title": "Pingvin-Share", + "repository": "https://hub.docker.com/r/stonith404/pingvin-share", + "description": "Pingvin-Share is a self-hosted file sharing application compatible with Nextcloud apps, offering a modern and intuitive web interface. It enables users to securely store, organize, and share files without relying on external cloud services. The application supports multiple authentication methods and provides features such as share links, user accounts, and a responsive interface.\n\n**Key features:**\n- Modern, responsive web interface\n- User accounts with a permission system\n- Secure share links for files\n- Drag-and-drop file upload\n- Password-protected shares\n- Multiple authentication methods\n- Docker-based deployment for easy installation\n\n**Learn more:**\n- [Pingvin-Share GitHub](https://github.com/stonith404/pingvin-share)\n", + "website": "https://stonith404.github.io/pingvin-share/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Pingvin-Share/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-05-25", + "main_image": "stonith404/pingvin-share:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/pingvin-share.json", + "template_status": "generated-unvalidated", + "content_hash": "9a375311e43bfd178b3e59bfec107c9160e4041fe54a2dbbe7972eecc9c1d677", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "piper", + "provider": "linuxserver.io", + "title": "Piper", + "repository_name": "docker-piper", + "repository": "https://github.com/linuxserver/docker-piper", + "description": "Piper is a fast, local neural text to speech system that sounds great and is optimized for the Raspberry Pi 4. This container provides a Wyoming protocol server for Piper.", + "website": "https://github.com/rhasspy/wyoming-piper", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/piper-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-11T22:05:31Z", + "updated_at": "2026-07-14", + "main_image": "lscr.io/linuxserver/piper:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/piper.json", + "template_status": "generated-unvalidated", + "content_hash": "61e7e0b4a6bb0235f018a5a28fa40813092967d5f402efd94bdba47e18c01e41", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "piwigo", + "provider": "linuxserver.io", + "title": "Piwigo", + "repository_name": "docker-piwigo", + "repository": "https://github.com/linuxserver/docker-piwigo", + "description": "Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures.", + "website": "http://piwigo.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/piwigo-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T18:01:49Z", + "updated_at": "2026-01-04", + "main_image": "lscr.io/linuxserver/piwigo:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/piwigo.json", + "template_status": "generated-unvalidated", + "content_hash": "c643c6b64528ff7f9927cf22ef8bd580f67a8cb2f3c1c38bb184e247d590433d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "planka", + "provider": "linuxserver.io", + "title": "Planka", + "repository_name": "docker-planka", + "repository": "https://github.com/linuxserver/docker-planka", + "description": "Planka is an elegant open source project tracking tool.", + "website": "https://github.com/plankanban/planka/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/planka-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-10T18:53:49Z", + "updated_at": "2026-08-24", + "main_image": "lscr.io/linuxserver/planka:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/planka.json", + "template_status": "generated-unvalidated", + "content_hash": "c576006cd38cbc3beed40722fefad48ad1cca188da250f181ab67969dbec4dcd", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "playit-agent", + "source_app_id": "playit-agent", + "provider": "mafen", + "template_family": "imported-compose", + "variant": null, + "title": "Playit Agent", + "repository": "https://ghcr.io/mafen/playit-docker", + "description": "", + "website": "https://playit.gg", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/playit-agent/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-11-11", + "main_image": "ghcr.io/mafen/playit-docker:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/playit-agent.json", + "template_status": "generated-unvalidated", + "content_hash": "4d71b2b20908f9c5566f3fe7243d8c856a83f6a8f6a1ed6fd2415407b34ec821", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "plex", + "provider": "linuxserver.io", + "title": "Plex", + "repository_name": "docker-plex", + "repository": "https://github.com/linuxserver/docker-plex", + "description": "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.", + "website": "https://plex.tv", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/plex-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T19:57:19Z", + "updated_at": "2026-07-06", + "main_image": "lscr.io/linuxserver/plex:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/plex.json", + "template_status": "generated-unvalidated", + "content_hash": "3cc0184a9a584aa85af461c1178f634867cc30206b3fb961e6e9a32eb985511e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "plex-official", + "provider": "plex", + "template_family": "curated-profile", + "title": "Plex Official", + "repository": "https://github.com/plexinc/pms-docker", + "description": "Plex organizes video, music and photos from personal media libraries and streams them to smart TVs, streaming boxes and mobile devices. This container is packaged as a standalone Plex Media Server. Straightforward design and bulk actions mean getting things done faster.", + "website": "https://www.plex.tv/media-server-downloads/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/plex-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": null, + "main_image": "plexinc/pms-docker:latest", + "category": "media", + "category_label": "Media & Streaming", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/plex-official.json", + "template": "apps/plex-official.json", + "template_status": "generated-unvalidated", + "content_hash": "46158e92b2092dae2cb6bb1003e05e57d6c26a0386c784d1b7e3175d2de3d46f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pocketbase", + "source_app_id": "pocketbase", + "provider": "argonptg", + "template_family": "imported-compose", + "variant": null, + "title": "PocketBase", + "repository": "https://hub.docker.com/r/argonptg/pocketbase", + "description": "PocketBase is an open-source backend solution that combines a real-time database, authentication, file storage, and an admin dashboard into a single, portable executable.", + "website": "https://pocketbase.io", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/PocketBase/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-04-14", + "main_image": "argonptg/pocketbase:latest", + "category": "databases", + "category_label": "Databases", + "template": "apps/pocketbase.json", + "template_status": "generated-unvalidated", + "content_hash": "341dfae83886182322dbffc7a129ff8d87931be5f25d9572199c71b2046037d9", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "podfetch", + "source_app_id": "podfetch", + "provider": "samuel19982", + "template_family": "imported-compose", + "variant": null, + "title": "PodFetch", + "repository": "https://hub.docker.com/r/samuel19982/podfetch", + "description": "PodFetch is a sleek and efficient self-hosted podcast manager written in Rust. It automatically downloads new episodes of your favorite podcasts on a configurable interval and lets you listen to them from a clean, fast web UI on any device.\n\nIts standout feature is a GPodder-compatible sync API: keep using mobile podcast apps like AntennaPod while subscriptions, episode actions, and playback positions stay in sync with your server. PodFetch also supports multi-user setups with invites and roles, playlists, favorites, OPML import and export, podcast search via iTunes or Podcast Index, and optional OIDC or basic authentication.\n", + "website": "https://samtv12345.github.io/PodFetch/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/PodFetch/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-09-03", + "main_image": "samuel19982/podfetch:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/podfetch.json", + "template_status": "generated-unvalidated", + "content_hash": "ed235eb8c120384aa6fbaaf5741dc5512d9f4645996cb389af1a5d77669a31e1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "portainer", + "source_app_id": "portainer", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Portainer", + "repository": "https://hub.docker.com/r/portainer/portainer-ce", + "description": "Portainer Community Edition (CE) is a lightweight container management tool offering an intuitive Web interface to simplify building, managing, and monitoring containerized applications. With over 500,000 active users, it is widely appreciated for its ease of use and robust functionality, ideal for individual developers, home lab users, and small teams.\n\nThe tool's core features include multi-platform support, resource management, and real-time monitoring. It supports managing various container platforms, covering containers, images, volumes, and networks. Users can quickly create, deploy, and manage containers via a \u201csmart\u201d graphical interface or comprehensive API, without needing deep command-line expertise. It provides real-time container status monitoring, log viewing, and configuration management, ensuring efficient control over application operations.\n\nIts design philosophy is to \u201csimplify container complexity\u201d with an intuitive interface and default settings that lower the technical barrier. Users can manage containerized applications without complex configurations, saving time and boosting efficiency. It is completely free, with data stored locally, ensuring full user control. Community support via GitHub Discussions and Slack, along with rich documentation and regular updates, enhances the user experience, making it suitable for learning container technology or managing small projects.\n\n**Key Features:**\n- Intuitive Web interface for simplified containerized app management\n- Supports multiple container platforms for unified resource management\n- Real-time monitoring of container status and logs\n- Rapid container deployment and management via API\n- Community support with extensive documentation and assistance\n\n**Learn More:**\n- [Portainer Official Website](https://www.portainer.io/)\n- [Portainer GitHub Repository](https://github.com/portainer/portainer)\n", + "website": "https://www.portainer.io/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Portainer/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-07-03", + "main_image": "portainer/portainer-ce:latest", + "category": "containers", + "category_label": "Containers & Docker", + "template": "apps/portainer.json", + "template_status": "generated-unvalidated", + "content_hash": "4cb9afba4933fe8704ccfc60bcaacadf14de4ddd66a4dfcf24e60ee8bcb9f2e6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "postgresql", + "source_app_id": "postgresql", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "PostgreSQL", + "repository": "https://hub.docker.com/_/postgres", + "description": "PostgreSQL is a powerful, open source object-relational database system with over 35 years of active development that has earned it a strong reputation for reliability, feature robustness, and performance.\n\nPostgreSQL is a highly stable database backed by more than 20 years of development by the open-source community.\n\nPostgreSQL is used as a primary database for many web applications as well as mobile and analytics applications.\n", + "website": "https://www.postgresql.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/PostgreSQL/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-04-29", + "main_image": "postgres:latest", + "category": "databases", + "category_label": "Databases", + "template": "apps/postgresql.json", + "template_status": "generated-unvalidated", + "content_hash": "3a6329dff87774e7042dde96f2c5e658e0710adbc13e9100ee70682f82927fc4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ppsspp", + "provider": "linuxserver.io", + "title": "Ppsspp", + "repository_name": "docker-ppsspp", + "repository": "https://github.com/linuxserver/docker-ppsspp", + "description": "PPSSPP is a free and open-source PSP emulator for Windows, macOS, Linux, iOS, Android, Nintendo Wii U, Nintendo Switch, BlackBerry 10, MeeGo, Pandora, Xbox Series and Symbian with a focus on speed and portability.", + "website": "https://www.ppsspp.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ppsspp-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T13:01:28Z", + "updated_at": "2026-01-12", + "main_image": "lscr.io/linuxserver/ppsspp:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/ppsspp.json", + "template_status": "generated-unvalidated", + "content_hash": "227432244de320131318616f1f4395ba37fa6e3e766b5f05ddba66a10a31eca8", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "projectsend", + "provider": "linuxserver.io", + "title": "Projectsend", + "repository_name": "docker-projectsend", + "repository": "https://github.com/linuxserver/docker-projectsend", + "description": "Projectsend is a self-hosted application that lets you upload files and assign them to specific clients that you create yourself. Secure, private and easy. No more depending on external services or e-mail to send those files.", + "website": "http://www.projectsend.org", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/projectsend-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T23:43:11Z", + "updated_at": "2026-08-10", + "main_image": "lscr.io/linuxserver/projectsend:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/projectsend.json", + "template_status": "generated-unvalidated", + "content_hash": "ce567a95aab3b391085a9613456ab8dac506aa1d14a127c55d7b7452ca153151", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "prowlarr", + "provider": "linuxserver.io", + "title": "Prowlarr", + "repository_name": "docker-prowlarr", + "repository": "https://github.com/linuxserver/docker-prowlarr", + "description": "Prowlarr is a indexer manager/proxy built on the popular arr .net/reactjs base stack to integrate with your various PVR apps. Prowlarr supports both Torrent Trackers and Usenet Indexers. It integrates seamlessly with Sonarr, Radarr, Lidarr, and Readarr offering complete management of your indexers with no per app Indexer setup required (we do it all).", + "website": "https://github.com/Prowlarr/Prowlarr", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/prowlarr-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-13T06:10:16Z", + "updated_at": "2026-07-04", + "main_image": "lscr.io/linuxserver/prowlarr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/prowlarr.json", + "template_status": "generated-unvalidated", + "content_hash": "3ebe43e7d698bef3e0ccd21e2ae3cda172e6d467059a3e26a1bce565659aa3d3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "psitransfer", + "source_app_id": "psitransfer", + "provider": "psitrax", + "template_family": "imported-compose", + "variant": null, + "title": "PsiTransfer", + "repository": "https://hub.docker.com/r/psitrax/psitransfer", + "description": "PsiTransfer is a simple, self-hosted open-source file sharing service that allows you to share files securely and easily without registration.\n\n**Key Features:**\n- **No Registration Required:** Share files instantly without creating an account.\n- **Privacy and Control:** All files are stored on your own server, giving you complete control over your data.\n- **Password Protection:** Protect shared files with a password for enhanced security.\n- **Upload Expiry:** Set uploaded files to automatically expire after a specific time to save storage space.\n- **Admin Panel:** Manage all uploads through a clean admin panel.\n- **Delivery Target:** Send files to predefined email addresses (configuration required).\n- **Responsive Web Interface:** Clean and user-friendly interface that works perfectly on all devices.\n\n**Learn More:**\n- [PsiTransfer GitHub Repository](https://github.com/psi-4ward/psitransfer)\n", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/PsiTransfer/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-02-14", + "main_image": "psitrax/psitransfer:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/psitransfer.json", + "template_status": "generated-unvalidated", + "content_hash": "4748db83a75ddbc121a3db927a6edf226b87bf55e7cb270f95283bcc53a22255", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pwndrop", + "provider": "linuxserver.io", + "title": "Pwndrop", + "repository_name": "docker-pwndrop", + "repository": "https://github.com/linuxserver/docker-pwndrop", + "description": "Pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.", + "website": "https://github.com/kgretzky/pwndrop", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pwndrop-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T20:21:35Z", + "updated_at": "2026-07-17", + "main_image": "lscr.io/linuxserver/pwndrop:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/pwndrop.json", + "template_status": "generated-unvalidated", + "content_hash": "afec8b0e1bd578f48d19b933f282cb72332d16fdc686c56a28bad592f899e29a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pycharm", + "provider": "linuxserver.io", + "title": "Pycharm", + "repository_name": "docker-pycharm", + "repository": "https://github.com/linuxserver/docker-pycharm", + "description": "PyCharm offers out-of-the-box support for Python, databases, Jupyter, Git, Conda, PyTorch, TensorFlow, Hugging Face, Django, Flask, FastAPI, and more.", + "website": "https://www.jetbrains.com/pycharm/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pycharm-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T19:59:37Z", + "updated_at": "2026-04-04", + "main_image": "lscr.io/linuxserver/pycharm:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/pycharm.json", + "template_status": "generated-unvalidated", + "content_hash": "cee5e3c89d3d1163905746bc5bc1b88d66217be8df400dbfb424b6e7b7a09832", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pydio-cells", + "provider": "linuxserver.io", + "title": "Pydio Cells", + "repository_name": "docker-pydio-cells", + "repository": "https://github.com/linuxserver/docker-pydio-cells", + "description": "Pydio-cells is the nextgen file sharing platform for organizations. It is a full rewrite of the Pydio project using the Go language following a micro-service architecture.", + "website": "https://pydio.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pydio-cells-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-08-27T14:24:17Z", + "updated_at": "2026-07-17", + "main_image": "lscr.io/linuxserver/pydio-cells:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/pydio-cells.json", + "template_status": "generated-unvalidated", + "content_hash": "e1a803957605720af4dabadb265f5455d75ed37e2b3b0c254c34844fae14dbb4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "pyload-ng", + "provider": "linuxserver.io", + "title": "Pyload Ng", + "repository_name": "docker-pyload-ng", + "repository": "https://github.com/linuxserver/docker-pyload-ng", + "description": "pyLoad is a Free and Open Source download manager written in Python and designed to be extremely lightweight, easily extensible and fully manageable via web.", + "website": "https://pyload.net/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/pyload-ng-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-11T22:03:25Z", + "updated_at": "2026-01-09", + "main_image": "lscr.io/linuxserver/pyload-ng:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/pyload-ng.json", + "template_status": "generated-unvalidated", + "content_hash": "49914b770ad2514abff6e8308954e7c31b8aa76fbba583c10858741fbaf72aa9", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "qbittorrent", + "provider": "linuxserver.io", + "title": "Qbittorrent", + "repository_name": "docker-qbittorrent", + "repository": "https://github.com/linuxserver/docker-qbittorrent", + "description": "", + "website": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/qbittorrent-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T12:32:47Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/qbittorrent:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/qbittorrent.json", + "template_status": "laboratory-validated", + "content_hash": "684e5958ac36beffc1fa2503e38b9728b33efb28eeb8cc051883fe2cddbb8048", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "qbittorrent-hotio", + "source_app_id": "qbittorrent", + "provider": "hotio", + "template_family": "imported-compose", + "variant": null, + "title": "qBittorrent", + "repository": "https://ghcr.io/hotio/qbittorrent", + "description": "**Elevate Your Home Media Experience**. qBittorrent transforms your home media setup with a polished interface reminiscent of \u00b5Torrent, minus the ads. Unlike traditional download tools, it offers a streamlined, efficient, and ad-free experience. This makes it a perfect fit for those seeking a hassle-free way to manage and enjoy their media collections at home.\n\n**Feature-Rich and User-Friendly**. With qBittorrent, you gain access to a well-integrated and extensible search engine, allowing simultaneous searches across multiple torrent sites, and category-specific searches for books, music, and software. Its support for RSS feeds with advanced filters, magnet links, encrypted connections, and more, ensures you have complete control over your downloads. Available on all major platforms and in around 70 languages, qBittorrent is both versatile and accessible.\n\n**Seamless Integration with Private Clouds like self-hosted server**. Deploying qBittorrent on private cloud devices such as self-hosted server offers unparalleled convenience. Enjoy virtually unlimited storage, enhanced privacy for your data, and local network speeds that make downloading and streaming effortless. This setup ensures that your media library is always at your fingertips, securely and swiftly.\n", + "website": "https://www.qbittorrent.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/qBittorrent/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-04-09", + "main_image": "ghcr.io/hotio/qbittorrent:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/qbittorrent-hotio.json", + "template_status": "generated-unvalidated", + "content_hash": "6125765539ae698bb3b12c2be47b55d023df7367526e277ce5b37034fefd89cf", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "qdirstat", + "provider": "linuxserver.io", + "title": "Qdirstat", + "repository_name": "docker-qdirstat", + "repository": "https://github.com/linuxserver/docker-qdirstat", + "description": "QDirStat Qt-based directory statistics: KDirStat without any KDE -- from the author of the original KDirStat.", + "website": "https://github.com/shundhammer/qdirstat", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/qdirstat-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-06T22:49:49Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/qdirstat:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/qdirstat.json", + "template_status": "generated-unvalidated", + "content_hash": "46b5bab0e4c9df729f8f0ba94d68ae7014287556ea24b575599964877c9a849f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "qui", + "source_app_id": "qui", + "provider": "autobrr", + "template_family": "imported-compose", + "variant": null, + "title": "Qui", + "repository": "https://ghcr.io/autobrr/qui", + "description": "**One dashboard for all your qBittorrent instances.** Qui is a fast, modern web interface for qBittorrent. Instead of juggling several separate WebUI tabs, you connect every qBittorrent instance to Qui and manage them all from a single, responsive dashboard. It ships as a lightweight single binary, so it stays quick and resource-friendly even when you are watching thousands of torrents.\n\n**Automation and cross-seeding built in.** Built by the team behind autobrr, Qui goes well beyond basic torrent listing. It adds powerful rule-based automation, built-in cross-seeding that automatically finds and adds matching torrents across your trackers, scheduled backups with restore, and a clean multi-language interface. Point it at your Torznab-compatible indexers \u2014 such as Prowlarr or Jackett \u2014 to put cross-seeding on autopilot, then filter, search, and bulk-manage torrents across every instance at once.\n\n**Made for your private cloud.** Running Qui on a private cloud device like self-hosted server keeps everything in one place on hardware you control. Pair it with your qBittorrent containers for local-network speeds, full ownership of your data, and a single tidy interface for your entire download stack \u2014 accessible from any device in your home.\n", + "website": "https://getqui.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Qui/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ghcr.io/autobrr/qui:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/qui.json", + "template_status": "generated-unvalidated", + "content_hash": "25f46b4a176800da9ffc91509a53d3784c3080e660ae8bcf7275b91ca4641c6f", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "radarr", + "provider": "linuxserver.io", + "title": "Radarr", + "repository_name": "docker-radarr", + "repository": "https://github.com/linuxserver/docker-radarr", + "description": "Radarr - A fork of Sonarr to work with movies \u00e0 la Couchpotato.", + "website": "https://github.com/Radarr/Radarr", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/radarr-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T19:13:01Z", + "updated_at": "2026-07-04", + "main_image": "lscr.io/linuxserver/radarr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/radarr.json", + "template_status": "generated-unvalidated", + "content_hash": "7386a2462e5e1c1a9432428dfbc2a92105d470ca0712eeff8f50e08be5bcb286", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ragflow", + "source_app_id": "ragflow", + "provider": "icewhaletech", + "template_family": "imported-compose", + "variant": null, + "title": "RagFlow", + "repository": "https://hub.docker.com/r/icewhaletech/ragflow", + "description": "RagFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. It enables users to build their own private ChatGPT by leveraging the power of large language models and deep document parsing capabilities. RagFlow supports various document formats including PDF, Word, Markdown, and more, allowing users to create intelligent question-answering systems based on their own documents.\n\n**Key Features:**\n- Deep document understanding with advanced parsing capabilities\n- Support for multiple document formats (PDF, Word, Markdown, etc.)\n- Private knowledge base with data security assurance\n- Customizable RAG workflows for different use cases\n- Integration with popular large language models\n- Web-based interface for easy management and interaction\n\n**Hardware Requirements:**\n- CPU >= 4 cores\n- RAM >= 16 GB\n- Disk >= 50 GB\n\n**Learn More:**\n- [RagFlow Official Website](https://ragflow.io)\n- [RagFlow GitHub Repository](https://github.com/infiniflow/ragflow)\n", + "website": "https://ragflow.io", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/RagFlow/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "icewhaletech/ragflow:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/ragflow.json", + "template_status": "generated-review-required", + "content_hash": "9251e28c7942933f47665c6e60efa40a2cbfefeb91c942c7cddbfc33ec9825fb", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:ragflow-mysql:healthcheck-format", + "service:ragflow-redis:healthcheck-format", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "raneto", + "provider": "linuxserver.io", + "title": "Raneto", + "repository_name": "docker-raneto", + "repository": "https://github.com/linuxserver/docker-raneto", + "description": "Raneto - is an open source Knowledgebase platform that uses static Markdown files to power your Knowledgebase.", + "website": "http://raneto.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/raneto-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T23:38:17Z", + "updated_at": "2025-09-16", + "main_image": "lscr.io/linuxserver/raneto:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/raneto.json", + "template_status": "generated-unvalidated", + "content_hash": "1aba7fd8cb7a3b7a48453a6b3b2451feeb0ce06df30881f553f0e53737063d39", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "rawtherapee", + "provider": "linuxserver.io", + "title": "Rawtherapee", + "repository_name": "docker-rawtherapee", + "repository": "https://github.com/linuxserver/docker-rawtherapee", + "description": "RawTherapee is a free, cross-platform raw image processing program!", + "website": "https://rawtherapee.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rawtherapee-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-13T07:59:19Z", + "updated_at": "2026-07-26", + "main_image": "lscr.io/linuxserver/rawtherapee:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/rawtherapee.json", + "template_status": "generated-unvalidated", + "content_hash": "dea13f85c5b83b7a2415dc74f9238c9b4fcbda5bb7467bbe2ede999279d57fd6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "rclone", + "provider": "rclone", + "template_family": "curated-profile", + "title": "Rclone WebUI", + "repository": "https://github.com/rclone/rclone", + "description": "Official Rclone image adapted as a native Proxmox OCI LXC with persistent configuration, authenticated WebUI and optional FUSE publication for other LXCs.", + "website": "https://rclone.org/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-12", + "main_image": "rclone/rclone:latest", + "category": "backup", + "category_label": "Backup & Recovery", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/rclone.json", + "template": "apps/rclone.json", + "template_status": "laboratory-validated", + "content_hash": "458f9b53ad3ec232afc64183c1324083daf19d159bf62801d7a0aa888d52eef3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": true, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": true, + "hidden": false + }, + { + "id": "rdtclient", + "source_app_id": "rdtclient", + "provider": "rogerfar", + "template_family": "imported-compose", + "variant": null, + "title": "Real-Debrid Torrent Client", + "repository": "https://hub.docker.com/r/rogerfar/rdtclient", + "description": "", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/RDTClient/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-30", + "main_image": "rogerfar/rdtclient:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/rdtclient.json", + "template_status": "laboratory-validated", + "content_hash": "06e85d3f0feba79ab088f6f5b1099a4c76b77060ddca1417b571943713431652", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "readarr", + "source_app_id": "readarr", + "provider": "linuxserver.io", + "template_family": "imported-compose", + "variant": null, + "title": "Readarr", + "repository": "https://hub.docker.com/r/linuxserver/readarr", + "description": "Readarr is a ebook collection manager for Usenet and BitTorrent users. It can monitor multiple RSS feeds for new books from your favorite authors and will interface with clients and indexers to grab, sort, and rename them.", + "website": "https://readarr.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Readarr/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2023-12-07", + "main_image": "linuxserver/readarr:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/readarr.json", + "template_status": "generated-unvalidated", + "content_hash": "1f8539a356dd43d031fd381533a5b5044990b77cdde85200580c0921c226e1a6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "remmina", + "provider": "linuxserver.io", + "title": "Remmina", + "repository_name": "docker-remmina", + "repository": "https://github.com/linuxserver/docker-remmina", + "description": "Remmina is a remote desktop client written in GTK, aiming to be useful for system administrators and travellers, who need to work with lots of remote computers in front of either large or tiny screens. Remmina supports multiple network protocols, in an integrated and consistent user interface. Currently RDP, VNC, SPICE, SSH and EXEC are supported.", + "website": "https://remmina.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/remmina-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T18:26:31Z", + "updated_at": "2026-06-20", + "main_image": "lscr.io/linuxserver/remmina:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/remmina.json", + "template_status": "generated-unvalidated", + "content_hash": "fd2a7694158b46d8e4736753c0b917a6c2d363940473d9ceca338b8172766191", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "resilio-sync", + "provider": "linuxserver.io", + "title": "Resilio Sync", + "repository_name": "docker-resilio-sync", + "repository": "https://github.com/linuxserver/docker-resilio-sync", + "description": "Resilio-sync (formerly BitTorrent Sync) uses the BitTorrent protocol to sync files and folders between all of your devices. There are both free and paid versions, this container supports both. There is an official sync image but we created this one as it supports user mapping to simplify permissions for volumes.", + "website": "https://www.resilio.com/individuals/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/resilio-sync-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T01:30:09Z", + "updated_at": "2024-08-21", + "main_image": "lscr.io/linuxserver/resilio-sync:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/resilio-sync.json", + "template_status": "generated-unvalidated", + "content_hash": "d14178b19b3d372d6c8eb0f049468b04236f5d09ed6145dc0e558c021fcf2731", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "retroarch", + "provider": "linuxserver.io", + "title": "Retroarch", + "repository_name": "docker-retroarch", + "repository": "https://github.com/linuxserver/docker-retroarch", + "description": "RetroArch is a frontend for emulators, game engines and media players. It enables you to run classic games on a wide range of computers and consoles through its slick graphical interface.", + "website": "https://retroarch.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/retroarch-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T18:17:52Z", + "updated_at": "2026-04-19", + "main_image": "lscr.io/linuxserver/retroarch:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/retroarch.json", + "template_status": "generated-unvalidated", + "content_hash": "e0c34aa3121f19cb4b9c09acd78d3c0c88689ef1cd6c632b05cccc042b643a46", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "retroarch-inglebard", + "source_app_id": "retroarch", + "provider": "inglebard", + "template_family": "imported-compose", + "variant": null, + "title": "RetroArch", + "repository": "https://hub.docker.com/r/inglebard/retroarch-web", + "description": "RetroArch-web is a web-based classic game emulator that enables users to enjoy a wide range of retro games directly in modern browsers. Supporting platforms like GBA, N64, DOS games, and NES (FC), it brings nostalgic gaming to life. Built on the open-source RetroArch project, RetroArch-web delivers robust features, including high-quality graphics rendering, audio processing, input controls, and save/load game progress, ensuring a precise and smooth emulation experience.\n\nDesigned for ease of use, RetroArch-web requires no complex software installation, running seamlessly in browsers. Its flexible configuration options let users customize controller setups, visual filters, and audio settings to suit individual preferences. With broad cross-platform compatibility, it ensures stable performance across devices, offering retro gaming enthusiasts a consistent experience on the go.\n\nBacked by an active open-source community, RetroArch-web continually improves performance and expands supported game platforms. Whether revisiting classic arcade titles or exploring vintage console games, RetroArch-web stands out as the ideal choice for retro gamers, combining powerful emulation with a user-friendly interface.\n\n**Key Features:**\n- Polished interface for browsing game collections with thumbnails and animated backgrounds\n- Supports multiple emulators and game engines for running classic games and discs\n- Next-frame response time for near-native hardware low-latency experience\n- Highly configurable settings to tweak game performance and display options\n- Automatic controller configuration for easy multiplayer gaming\n- Shaders to enhance old game rendering and mimic CRT monitor effects\n- Netplay for multiplayer gaming and spectator mode\n- Achievements system to unlock trophies and badges in classic games\n- Recording and streaming for capturing gameplay or live streaming\n\n**Learn More:**\n- [RetroArch Official Website](https://www.retroarch.com)\n- [RetroArch GitHub Repository](https://github.com/libretro/RetroArch)\n", + "website": "https://www.retroarch.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/RetroArch/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-11-20", + "main_image": "inglebard/retroarch-web:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/retroarch-inglebard.json", + "template_status": "generated-unvalidated", + "content_hash": "209fd5aa52427c27557a53cc14fc3384673418a74bf3db42f8a4c203cf2421a6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "romm", + "source_app_id": "romm", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "RomM", + "repository": "https://hub.docker.com/r/rommapp/romm", + "description": "RomM is a self-hosted game collection management app designed for emulator enthusiasts, offering a convenient way to scan, enrich, browse, and play games. Its responsive Web interface allows users to manage collections via any modern browser, supporting over 400 platforms, ideal for retro gaming fans building personal game libraries.\n\nThe app's core features include robust library management and seamless gameplay. It fetches metadata from IGDB, Screenscraper, and MobyGames, and custom artwork from SteamGridDB, enhancing the visual appeal of collections. Users can play games directly in the browser using EmulatorJS and RuffleRS, with support for multi-disk games, DLCs, patches, and manuals. It also enables parsing and filtering by filename tags for tailored organization. Additionally, it supports multi-user accounts with limited access permissions, allowing library sharing with friends and displaying RetroAchievements.\n\nIt can be flexibly deployed on personal servers or NAS devices, with official apps for Playnite and muOS enhancing cross-device access. Users can upload, update, or delete games via the Web interface, with community support documentation expanding functionality. Whether managing a personal retro game library or sharing with others, the app's intuitive interface and high customizability deliver a modern game management platform, meeting diverse needs.\n\n**Key Features:**\n- Scan and enhance your game library with metadata from IGDB, Screenscraper and MobyGames\n- Fetch custom artwork from SteamGridDB\n- Display your achievements from Retroachievements\n- Metadata available for 400+ platforms\n- Play games directly from the browser using EmulatorJS and RuffleRS\n- Share your library with friends with limited access and permissions\n- Official apps for Playnite and muOS\n- Supports multi-disk games, DLCs, mods, hacks, patches, and manuals\n- Parse and filter by tags in filenames\n- View, upload, update, and delete games from any modern web browser\n\n**Learn More:**\n- [RomM Official Website](https://romm.app)\n- [RomM GitHub Repository](https://github.com/rommapp/romm)\n", + "website": "https://romm.app", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/RomM/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "rommapp/romm:latest", + "category": "gaming", + "category_label": "Gaming & Leisure", + "template": "apps/romm.json", + "template_status": "generated-unvalidated", + "content_hash": "45cf2bcf7bad0abb0e38bc074591c9dc3a3c38b7bf59fbf5f1e96b4e64c316f8", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "roonserver", + "provider": "roonlabs", + "template_family": "curated-profile", + "title": "Roon Server", + "repository": "https://ghcr.io/roonlabs/roonserver", + "description": "Roon music software transforms your listening experience with rich metadata, discovery features, and audiophile sound. It works with streaming services and local files.\n\nRoon brings all your music together and adds bios, reviews, photos, lyrics, tour dates, and cross-linked credits for performers, songwriters, producers, engineers, and composers. Everything about music - browsing, discovery, collecting, and listening - is more engaging with Roon.\n\nRoonServer is the central server component. It runs on a Linux amd64/x86_64 host, stores the Roon database and settings, and serves your library to Roon Remote clients and audio endpoints on your local network. It is controlled from the Roon app and does not provide a browser-based WebUI.\n", + "website": "https://roon.app", + "icon": null, + "architectures": [ + "amd64" + ], + "updated_at": null, + "main_image": "ghcr.io/roonlabs/roonserver:latest", + "category": "media", + "category_label": "Media & Streaming", + "replaces_discovered_ids": [ + "roonserver" + ], + "curated_path": "catalog/curated/roonserver.json", + "template": "apps/roonserver.json", + "template_status": "generated-unvalidated", + "content_hash": "7a03adeac910fb9cd8f21acfb3a62274a41bf77844fb71be788a3fcbe337154b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "requires_security_confirmation": true, + "hidden": false + }, + { + "id": "rpcs3", + "provider": "linuxserver.io", + "title": "Rpcs3", + "repository_name": "docker-rpcs3", + "repository": "https://github.com/linuxserver/docker-rpcs3", + "description": "RPCS3 is a multi-platform open-source Sony PlayStation 3 emulator and debugger written in C++ for Windows, Linux, macOS and FreeBSD.", + "website": "https://rpcs3.net/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rpcs3-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T18:49:58Z", + "updated_at": "2026-07-30", + "main_image": "lscr.io/linuxserver/rpcs3:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/rpcs3.json", + "template_status": "generated-unvalidated", + "content_hash": "6ddb459ac6d44627cdfd1f125c9d24ec751661792c6a724c2678d1e2985b5570", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "rsnapshot", + "provider": "linuxserver.io", + "title": "Rsnapshot", + "repository_name": "docker-rsnapshot", + "repository": "https://github.com/linuxserver/docker-rsnapshot", + "description": "Rsnapshot is a filesystem snapshot utility based on rsync. rsnapshot makes it easy to make periodic snapshots of local machines, and remote machines over ssh. The code makes extensive use of hard links whenever possible, to greatly reduce the disk space required.", + "website": "http://www.rsnapshot.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rsnapshot-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T09:13:39Z", + "updated_at": "2025-02-01", + "main_image": "lscr.io/linuxserver/rsnapshot:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/rsnapshot.json", + "template_status": "generated-unvalidated", + "content_hash": "5bfeb5cce3e9da1e47be019fc4ddff9842e33fd0c118436ebc6c470010797fb3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "rustdesk", + "provider": "linuxserver.io", + "title": "Rustdesk", + "repository_name": "docker-rustdesk", + "repository": "https://github.com/linuxserver/docker-rustdesk", + "description": "RustDesk is a full-featured open source remote control alternative for self-hosting and security with minimal configuration.", + "website": "https://rustdesk.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/rustdesk-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T18:43:55Z", + "updated_at": "2026-04-04", + "main_image": "lscr.io/linuxserver/rustdesk:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/rustdesk.json", + "template_status": "generated-unvalidated", + "content_hash": "09d90aa1f7c7e02bdc3a632cb19258b25f5ff04e7254ff965f12492b94dd8e44", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "sabnzbd", + "provider": "linuxserver.io", + "title": "Sabnzbd", + "repository_name": "docker-sabnzbd", + "repository": "https://github.com/linuxserver/docker-sabnzbd", + "description": "Sabnzbd makes Usenet as simple and streamlined as possible by automating everything we can. All you have to do is add an .nzb. SABnzbd takes over from there, where it will be automatically downloaded, verified, repaired, extracted and filed away with zero human interaction.", + "website": "http://sabnzbd.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sabnzbd-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T15:27:05Z", + "updated_at": "2026-07-04", + "main_image": "lscr.io/linuxserver/sabnzbd:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/sabnzbd.json", + "template_status": "generated-unvalidated", + "content_hash": "7eaab95a30677aedcdcbc8860dca443a256b4ebe28958a67758565f79c77dc18", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "scummvm", + "provider": "linuxserver.io", + "title": "Scummvm", + "repository_name": "docker-scummvm", + "repository": "https://github.com/linuxserver/docker-scummvm", + "description": "ScummVM is a program which allows you to run certain classic graphical adventure and role-playing games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed! ScummVM is a complete rewrite of these games' executables and is not an emulator.", + "website": "https://www.scummvm.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/scummvm-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T22:29:59Z", + "updated_at": "2026-06-20", + "main_image": "lscr.io/linuxserver/scummvm:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/scummvm.json", + "template_status": "generated-unvalidated", + "content_hash": "b00474648ab3e217e8e305a357aa2873601ac23c629bc912b52e8e96d386b865", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": true, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "sealskin", + "provider": "linuxserver.io", + "title": "Sealskin", + "repository_name": "docker-sealskin", + "repository": "https://github.com/linuxserver/docker-sealskin", + "description": "Sealskin is a self-hosted, client-server platform that enables users to run powerful, containerized desktop applications streamed directly to a web browser. It uses a browser extension to intercept user actions\u2014such as clicking a link or downloading a file and redirects them to a secure, isolated application environment running on a remote server.", + "website": "https://github.com/selkies-project/sealskin/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sealskin-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T18:38:38Z", + "updated_at": "2026-09-05", + "main_image": "lscr.io/linuxserver/sealskin:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/sealskin.json", + "template_status": "generated-unvalidated", + "content_hash": "ab76d53eea89231efa385f759751c1c72300d5955af35ee90e745a72140cd40b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "seerr", + "provider": "official", + "template_family": "curated-profile", + "title": "Seerr", + "repository": "https://github.com/seerr-team/seerr", + "description": "Media discovery and request management for Jellyfin, Plex and Emby.", + "website": "https://docs.seerr.dev/getting-started/docker/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": null, + "main_image": "ghcr.io/seerr-team/seerr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/seerr.json", + "template": "apps/seerr.json", + "template_status": "generated-unvalidated", + "content_hash": "7b0a15445e8a76bbe533df9dbb8aa6ae56ccaff3153b2c16b1c128b0a6d187f7", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "shadps4", + "provider": "linuxserver.io", + "title": "Shadps4", + "repository_name": "docker-shadps4", + "repository": "https://github.com/linuxserver/docker-shadps4", + "description": "shadPS4 is an early PlayStation 4 emulator for Windows, Linux and macOS written in C++.", + "website": "https://shadps4.net/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/shadps4-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T09:53:43Z", + "updated_at": "2026-02-25", + "main_image": "lscr.io/linuxserver/shadps4:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/shadps4.json", + "template_status": "generated-unvalidated", + "content_hash": "267bb1e36ed9cd607f8c27432e74f7801d52da1b18b08f675842269e1c121654", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "shotcut", + "provider": "linuxserver.io", + "title": "Shotcut", + "repository_name": "docker-shotcut", + "repository": "https://github.com/linuxserver/docker-shotcut", + "description": "Shotcut is a free, open source, cross-platform video editor.", + "website": "https://www.shotcut.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/shotcut-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "main", + "pushed_at": "2026-09-09T07:50:00Z", + "updated_at": "2026-03-30", + "main_image": "lscr.io/linuxserver/shotcut:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/shotcut.json", + "template_status": "generated-unvalidated", + "content_hash": "e97c11387cb6fcb482c2c5116cb49a5a4ca6be585193de71b0783911b5ed8dc1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "sickchill", + "source_app_id": "sickchill", + "provider": "linuxserver.io", + "template_family": "imported-compose", + "variant": null, + "title": "Sickchill", + "repository": "https://hub.docker.com/r/linuxserver/sickchill", + "description": "SickChill is an automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic: automatic torrent/nzb searching, downloading, and processing at the qualities you want.\n", + "website": "https://sickchill.github.io", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Sickchill/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-01-04", + "main_image": "linuxserver/sickchill:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/sickchill.json", + "template_status": "generated-unvalidated", + "content_hash": "629b42d7319685755295900f33c2a5a5e79f00b2cf2400fbdbcc5364f7903952", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "sickgear", + "provider": "linuxserver.io", + "title": "Sickgear", + "repository_name": "docker-sickgear", + "repository": "https://github.com/linuxserver/docker-sickgear", + "description": "SickGear provides management of TV shows and/or Anime, it detects new episodes, links downloader apps, and more..", + "website": "https://github.com/sickgear/sickgear", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sickgear-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T00:20:14Z", + "updated_at": "2025-07-09", + "main_image": "lscr.io/linuxserver/sickgear:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/sickgear.json", + "template_status": "generated-unvalidated", + "content_hash": "09946081c57eaddf709c81a6119f7051d63920cb3b2cdb379bd57dfcf17cd4a1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "signal", + "provider": "linuxserver.io", + "title": "Signal", + "repository_name": "docker-signal", + "repository": "https://github.com/linuxserver/docker-signal", + "description": "Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private.", + "website": "https://signal.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/signal-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T10:05:22Z", + "updated_at": "2026-04-04", + "main_image": "lscr.io/linuxserver/signal:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/signal.json", + "template_status": "generated-unvalidated", + "content_hash": "4e8fd61dbd630a87807b297be546c72795caf6703ffa579f3c490b53f7a23f92", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "siyuan-note", + "source_app_id": "siyuan-note", + "provider": "b3log", + "template_family": "imported-compose", + "variant": null, + "title": "SiYuan Note", + "repository": "https://hub.docker.com/r/b3log/siyuan", + "description": "Experience Seamless Knowledge Management with SiYuan. SiYuan redefines knowledge management by seamlessly integrating with your home TV, mobile devices, and other platforms. Unlike traditional knowledge systems, SiYuan offers a cohesive and flexible environment that adapts to your lifestyle, allowing you to access and organize information effortlessly across all your devices. Whether you are a creator or a regular consumer, SiYuan's innovative approach ensures your knowledge is always at your fingertips.\n\nPowerful Features, Minimal Cost. SiYuan stands out with its robust set of features, most of which are free, even for commercial use. Enjoy block-level referencing, two-way links, custom attributes, SQL query embeds, and the unique protocol siyuan://. The editor supports block-style, markdown WYSIWYG, list outlines, and block zoom-in. Handle large documents with ease and include mathematical formulas, charts, flowcharts, and more. Capture web content, annotate PDFs, and export in various formats including Markdown, PDF, Word, and HTML. SiYuan also offers AI-powered writing and Q/A chat via OpenAI API, Tesseract OCR, and multi-tab support for a comprehensive and seamless experience.\n\nUnlimited Storage, Local Speed, Multi-Device Access. Deploying Alist on self-hosted server private cloud devices brings unparalleled convenience. Enjoy unlimited storage, blazing-fast local network speeds, and access from multiple devices. This setup ensures that your data is always available, secure, and quickly accessible, providing a superior alternative to traditional cloud services.\n", + "website": "https://b3log.org/siyuan/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Siyuan-Note/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-21", + "main_image": "b3log/siyuan:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/siyuan-note.json", + "template_status": "generated-unvalidated", + "content_hash": "6c38e5bd772d7f9b3945a503d39e65f3218a41d089ac79bf340da3758c734c6a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "smokeping", + "provider": "linuxserver.io", + "title": "Smokeping", + "repository_name": "docker-smokeping", + "repository": "https://github.com/linuxserver/docker-smokeping", + "description": "Smokeping keeps track of your network latency. For a full example of what this application is capable of visit UCDavis.", + "website": "https://oss.oetiker.ch/smokeping/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/smokeping-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T23:14:48Z", + "updated_at": "2025-12-17", + "main_image": "lscr.io/linuxserver/smokeping:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/smokeping.json", + "template_status": "generated-unvalidated", + "content_hash": "69336f4b056f9013342f83aee1941a4f4024b5d7e1cf6a82662588a0928a56d7", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "snapdrop", + "source_app_id": "snapdrop", + "provider": "linuxserver.io", + "template_family": "imported-compose", + "variant": null, + "title": "snapdrop", + "repository": "https://hub.docker.com/r/linuxserver/snapdrop", + "description": "Snapdrop is a Progressive Web App (PWA) that allows you to transfer files between devices in the same network without having to install anything.", + "website": "https://snapdrop.net", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Snapdrop/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-07-18", + "main_image": "linuxserver/snapdrop:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/snapdrop.json", + "template_status": "generated-unvalidated", + "content_hash": "381b982092be587efad50abcadae4ae08b3bb2b009ab251ae1fc127c5fec873d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "snapotter", + "source_app_id": "snapotter", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "SnapOtter", + "repository": "https://hub.docker.com/r/snapotter/snapotter", + "description": "SnapOtter is an open-source, self-hosted file manipulation suite with 200+ tools across images, video, audio, PDFs, and files. It includes batch processing, reusable pipelines, local AI tools, a browser image editor, and a REST API so files stay on your own server.\n\nThis package uses SnapOtter's single-container embedded mode for an easy self-hosted server install. PostgreSQL 17 and Redis 8 run inside the container when DATABASE_URL and REDIS_URL are left unset, with persistent data stored under /data.\n\nDefault login is admin / admin. SnapOtter asks you to change the default password after first login.\n", + "website": "https://snapotter.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/SnapOtter/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-09-02", + "main_image": "snapotter/snapotter:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/snapotter.json", + "template_status": "laboratory-validated", + "content_hash": "56b8d4ec7d332055b24ec9a17d9cb7f19b2af4e8d6224debb718291b28c96237", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "sonarr", + "provider": "linuxserver.io", + "title": "Sonarr", + "repository_name": "docker-sonarr", + "repository": "https://github.com/linuxserver/docker-sonarr", + "description": "Sonarr (formerly NZBdrone) is a PVR for usenet and bittorrent users. It can monitor multiple RSS feeds for new episodes of your favorite shows and will grab, sort and rename them. It can also be configured to automatically upgrade the quality of files already downloaded when a better quality format becomes available.", + "website": "https://sonarr.tv/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sonarr-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T01:31:34Z", + "updated_at": "2026-07-09", + "main_image": "lscr.io/linuxserver/sonarr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "template": "apps/sonarr.json", + "template_status": "generated-unvalidated", + "content_hash": "eb5263221be311022817d6381a7cf376d0b589c52b2cca37188058c4c96e3292", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "speedtest-tracker", + "provider": "linuxserver.io", + "title": "Speedtest Tracker", + "repository_name": "docker-speedtest-tracker", + "repository": "https://github.com/linuxserver/docker-speedtest-tracker", + "description": "Speedtest-tracker is a self-hosted internet performance tracking application that runs speedtest checks against Ookla's Speedtest service.", + "website": "https://github.com/alexjustesen/speedtest-tracker", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/speedtest-tracker-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-12T22:58:07Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/speedtest-tracker:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/speedtest-tracker.json", + "template_status": "generated-unvalidated", + "content_hash": "bd2d1338d7115081530645b900f5a954755b58d06c85b6b89204da88a9af1644", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "spotube", + "provider": "linuxserver.io", + "title": "Spotube", + "repository_name": "docker-spotube", + "repository": "https://github.com/linuxserver/docker-spotube", + "description": "Spotube is an open source, cross-platform Spotify client compatible across multiple platforms utilizing Spotify's data API and YouTube, Piped.video or JioSaavn as an audio source, eliminating the need for Spotify Premium", + "website": "https://spotube.krtirtho.dev/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/spotube-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T19:02:13Z", + "updated_at": "2026-04-04", + "main_image": "lscr.io/linuxserver/spotube:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/spotube.json", + "template_status": "generated-unvalidated", + "content_hash": "3b64a7e47b91c6459677c454f52b3f60812a14afd07feb6df2da24a9b63d30d1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "sqlitebrowser", + "provider": "linuxserver.io", + "title": "Sqlitebrowser", + "repository_name": "docker-sqlitebrowser", + "repository": "https://github.com/linuxserver/docker-sqlitebrowser", + "description": "DB Browser for SQLite is a high quality, visual, open source tool to create, design, and edit database files compatible with SQLite.", + "website": "https://sqlitebrowser.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/sqlitebrowser-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T06:53:37Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/sqlitebrowser:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/sqlitebrowser.json", + "template_status": "generated-unvalidated", + "content_hash": "2185c873858ce1952734289caedfdba2cee9682b6bb173b8bca9346a93741ae3", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "stable-diffusion-webui-nvidia", + "source_app_id": "icewhale-stable-diffusion-webui", + "provider": "johnguan", + "template_family": "imported-compose", + "variant": "nvidia", + "title": "Stable Diffusion", + "repository": "https://hub.docker.com/r/johnguan/stable-diffusion-webui", + "description": "Stable Diffusion is a deep learning, text-to-image model released in 2022 based on diffusion techniques. It is primarily used to generate detailed images conditioned on text descriptions, though it can also be applied to other tasks such as inpainting, outpainting, and generating image-to-image translations guided by a text prompt.", + "website": "", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/StableDiffusionWebUI/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "johnguan/stable-diffusion-webui:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/stable-diffusion-webui-nvidia.json", + "template_status": "generated-unvalidated", + "content_hash": "52b935fdb7a25adc834933de6cfcb25b5da1701de3f02f90a7d5b08d843b32a9", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "steam", + "provider": "linuxserver.io", + "title": "Steam", + "repository_name": "docker-steam", + "repository": "https://github.com/linuxserver/docker-steam", + "description": "Steam is the ultimate destination for playing, discussing, and creating games.", + "website": "https://store.steampowered.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/steam-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T23:34:08Z", + "updated_at": "2026-02-04", + "main_image": "lscr.io/linuxserver/steam:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/steam.json", + "template_status": "generated-unvalidated", + "content_hash": "78be734cc7f82cc949c19d9f231c3a6d1db6034e53aaf980c95175725d04ad3e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": true, + "requires_security_confirmation": true, + "hidden": false + }, + { + "id": "stremio", + "provider": "tsaridas", + "template_family": "curated-profile", + "title": "Stremio", + "repository": "https://hub.docker.com/r/tsaridas/stremio-docker", + "description": "Stremio offers a secure, modern and seamless entertainment experience. With its easy-to-use interface and diverse content library, including 4K HDR support, users can enjoy their favorite movies and TV shows across all their devices. And with its commitment to security, Stremio is the ultimate choice for a worry-free, high-quality streaming experience.", + "website": "https://www.stremio.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": null, + "main_image": "tsaridas/stremio-docker:latest", + "category": "media", + "category_label": "Media & Streaming", + "replaces_discovered_ids": [ + "stremio" + ], + "curated_path": "catalog/curated/stremio.json", + "template": "apps/stremio.json", + "template_status": "generated-unvalidated", + "content_hash": "b2a5d41e58b5ebc2738588b20a4e2c3d10ecf109bdeb79a3aa10c11061dcff0a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "suite-arr", + "provider": "linuxserver.io", + "template_family": "curated-profile", + "title": "Suite Arr", + "repository": "https://github.com/linuxserver/docker-prowlarr", + "description": "Selectable Arr media suite with shared content and a choice of Jellyfin, Plex or Emby.", + "website": "https://github.com/Prowlarr/Prowlarr", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/prowlarr-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-07-04", + "main_image": "lscr.io/linuxserver/prowlarr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/suite-arr.json", + "template": "apps/suite-arr.json", + "template_status": "generated-unvalidated", + "content_hash": "eb33e0f47e1f84a258bf667988ef1a5e178e6c50f75df27f1cd3c92d526629de", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "sure", + "source_app_id": "sure", + "provider": "we-promise", + "template_family": "imported-compose", + "variant": null, + "title": "Sure", + "repository": "https://ghcr.io/we-promise/sure", + "description": "Sure is a personal finance management application designed to help you track your expenses, income, and investments in one place. With an intuitive interface and powerful features, Sure makes it easy to understand your financial situation and make informed decisions about your money.\n\n**Key Features:**\n- **Expense Tracking**: Easily log and categorize your expenses\n- **Income Management**: Track multiple income sources\n- **Investment Monitoring**: Keep an eye on your investments and their performance\n- **Budget Planning**: Create and maintain budgets to control your spending\n- **Financial Reports**: Generate detailed reports to understand your financial habits\n- **AI-Powered Insights**: Get personalized financial advice using AI technology\n\n**Use Cases:**\n- Personal budget management\n- Expense tracking and categorization\n- Investment portfolio monitoring\n- Financial goal setting and tracking\n- Cash flow analysis\n\n**Learn More:**\n- [Sure GitHub Repository](https://github.com/we-promise/sure)\n", + "website": "https://sure.am", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Sure/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "ghcr.io/we-promise/sure:latest", + "category": "finance", + "category_label": "Finance & Budgeting", + "template": "apps/sure.json", + "template_status": "generated-review-required", + "content_hash": "888b4584227859512cb9f43f5b8c7cc7cdafc727bc5151c87acec763d7a4c01b", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:sure-worker:compose-key:depends_on", + "service:sure-db:healthcheck-format", + "service:sure-redis:healthcheck-format", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "swag", + "provider": "linuxserver.io", + "title": "Swag", + "repository_name": "docker-swag", + "repository": "https://github.com/linuxserver/docker-swag", + "description": "Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.", + "website": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/swag-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T08:06:16Z", + "updated_at": "2026-07-19", + "main_image": "lscr.io/linuxserver/swag:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/swag.json", + "template_status": "generated-unvalidated", + "content_hash": "c25276bc6f6b54d95fb3dac8ac952ee2345b6ad095eb9f83261145f12b1cd9e8", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "swingmusic", + "source_app_id": "swingmusic", + "provider": "swingmx", + "template_family": "imported-compose", + "variant": null, + "title": "Swing Music", + "repository": "https://ghcr.io/swingmx/swingmusic", + "description": "Swing Music is a fast, beautiful, self-hosted music player designed for your local audio files, offering a sleek experience akin to Spotify but powered by your own music library. Simply run the app and access your music collection effortlessly through a web browser.\n\nSwing Music curates Daily Mixes based on your listening habits, ensures a clean and consistent library with metadata normalization, and supports album versioning (e.g., Deluxe, Remaster) alongside related artist and album recommendations. Browse your music library via folder view, manage playlists, and enjoy a seamless listening experience with silence detection and cross-fade. Additional features include listening statistics, lyrics view, Last.fm scrobbling, multi-user support, and personalized collections for grouping albums and artists.\n\nWith its stunning browser-based interface and robust functionality, Swing Music is the perfect choice for music enthusiasts seeking a beautiful and practical way to manage and enjoy their local music collection.\n", + "website": "https://swingmx.com", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/SwingMusic/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-01-18", + "main_image": "ghcr.io/swingmx/swingmusic:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/swingmusic.json", + "template_status": "generated-unvalidated", + "content_hash": "9dc5d638a714a54688c32f26a87504493d6652e72b582a1a78d7c6c434ad8527", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "synclounge", + "provider": "linuxserver.io", + "title": "Synclounge", + "repository_name": "docker-synclounge", + "repository": "https://github.com/linuxserver/docker-synclounge", + "description": "Synclounge is a third party tool that allows you to watch Plex in sync with your friends/family, wherever you are.", + "website": "https://github.com/samcm/synclounge", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/synclounge-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T17:58:13Z", + "updated_at": "2026-07-15", + "main_image": "lscr.io/linuxserver/synclounge:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/synclounge.json", + "template_status": "generated-unvalidated", + "content_hash": "63c40039616331f757dfef88c626e84bc5258bf0e4fe1e851a44f2d126588c6a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "syncthing", + "provider": "linuxserver.io", + "title": "Syncthing", + "repository_name": "docker-syncthing", + "repository": "https://github.com/linuxserver/docker-syncthing", + "description": "Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet.", + "website": "https://syncthing.net", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/syncthing-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T15:29:13Z", + "updated_at": "2026-09-10", + "main_image": "lscr.io/linuxserver/syncthing:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/syncthing.json", + "template_status": "generated-unvalidated", + "content_hash": "c939418e7fac97f3a8043da94bf0fa0044446263215638a16da27be7ce49324c", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "syslog-ng", + "provider": "linuxserver.io", + "title": "Syslog Ng", + "repository_name": "docker-syslog-ng", + "repository": "https://github.com/linuxserver/docker-syslog-ng", + "description": "syslog-ng allows you to flexibly collect, parse, classify, rewrite and correlate logs from across your infrastructure and store or route them to log analysis tools.", + "website": "https://www.syslog-ng.com/products/open-source-log-management/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/syslog-ng-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-10T21:27:28Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/syslog-ng:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/syslog-ng.json", + "template_status": "generated-unvalidated", + "content_hash": "59bb91b4371a26d4b98dcafa7b581665f7f761f96cd7a8b608c1f84a6bdc17d4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "tailscale", + "source_app_id": "tailscale", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Tailscale", + "repository": "https://hub.docker.com/r/tailscale/tailscale", + "description": "A modern self-hosted networking app built on WireGuard\u00ae, providing secure, encrypted connections between devices regardless of their location. Its zero-configuration networking eliminates the need for complex firewall rules, port forwarding, or network administration, making it ideal for businesses and individuals creating efficient, secure network environments.\n\nThe app's core features include seamless device connectivity and robust security. It uses WireGuard\u00ae for end-to-end encryption, ensuring traffic cannot be intercepted, with private keys stored solely on user devices. Automatic NAT traversal enables connections across computers, phones, servers, and IoT devices over different network types, forming a unified private network. It also offers identity-based access control, integrating with Google, Microsoft, GitHub, or custom SSO solutions for simple authentication, replacing traditional IP-based restrictions to enhance security.\n\nIt excels in delivering secure remote access to services and infrastructure. Users can effortlessly access home servers, connect to office networks while traveling, or establish secure links between cloud services. Subnet routing allows access to entire networks, exit nodes enable secure internet browsing, and MagicDNS simplifies device discovery. These features ensure efficient, secure access to resources from any location.\n\nIt supports nearly all platforms, including Linux, Windows, macOS, iOS, Android, and various router firmwares, with flexible deployment in cloud or on-premises environments. A user-friendly Web interface provides real-time monitoring of network topology, device status, and access controls, with community documentation aiding configuration optimization. Whether setting up secure access for small teams or managing enterprise-scale networks, the app\u2019s intuitive operation and high flexibility deliver a modern networking solution.\n\n**Key Features:**\n- End-to-end encryption via WireGuard\u00ae, ensuring uninterceptible traffic\n- Zero-configuration networking, eliminating complex firewall or port forwarding setup\n- Automatic NAT traversal for seamless device connectivity across network types\n- Identity-based access control with SSO integration (Google, Microsoft, GitHub)\n- Subnet routing for secure network-wide access\n- Exit nodes for safe internet browsing\n- MagicDNS for simplified device discovery\n\n**Learn More:**\n- [Tailscale Official Website](https://tailscale.com)\n- [Tailscale GitHub Repository](https://github.com/tailscale/tailscale)\n", + "website": "https://tailscale.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Tailscale/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-21", + "main_image": "tailscale/tailscale:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/tailscale.json", + "template_status": "generated-unvalidated", + "content_hash": "4ceee28e6d136b6e60deb806c69e43e286497b4842c5e21edb539cf2b6da0fcc", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "tandoor", + "provider": "tandoor", + "template_family": "curated-profile", + "title": "Tandoor Recipes", + "repository": "https://github.com/vabene1111/recipes", + "description": "Official Tandoor Recipes deployment with its integrated web server and an isolated PostgreSQL dependency.", + "website": "https://tandoor.dev/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-11", + "main_image": "vabene1111/recipes:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "replaces_discovered_ids": [ + "tandoor" + ], + "curated_path": "catalog/curated/tandoor.json", + "template": "apps/tandoor.json", + "template_status": "generated-unvalidated", + "content_hash": "4c3f02f82c51eb1c7303953eb63cc2f76786daac0d2ea7d082de53c4db8b603b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "taskingai", + "source_app_id": "taskingai", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "TaskingAI", + "repository": "https://hub.docker.com/r/taskingai/taskingai-console", + "description": "The developer-friendly cloud platform for building and running LLM agents for AI-native applications.", + "website": "https://docs.tasking.ai/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/TaskingAI/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "taskingai/taskingai-console:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/taskingai.json", + "template_status": "generated-review-required", + "content_hash": "56578d0ced633edb72bfbf42ca68193036b9b38d3f73182c0d3f777c43611fe2", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:backend-api:compose-key:depends_on", + "service:backend-web:compose-key:depends_on", + "service:db:healthcheck-format", + "service:cache:healthcheck-format", + "service:nginx:compose-key:configs", + "service:nginx:compose-key:depends_on", + "top-level-configs", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "tasmoadmin", + "provider": "TasmoAdmin", + "template_family": "curated-profile", + "title": "TasmoAdmin", + "repository": "https://github.com/TasmoAdmin/TasmoAdmin", + "description": "TasmoAdmin manages the devices on a network that run Tasmota firmware, from one web interface: it finds them by scanning an address range or through an MQTT broker, shows their sensor readings and configuration, sends commands and backs them up, and updates the firmware of several devices at once, downloading the release from the Tasmota OTA site.", + "website": "https://github.com/TasmoAdmin/TasmoAdmin", + "icon": "https://raw.githubusercontent.com/TasmoAdmin/TasmoAdmin/master/assets/logo.svg", + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-21", + "main_image": "ghcr.io/tasmoadmin/tasmoadmin:latest", + "category": "smarthome", + "category_label": "IoT & Smart Home", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/tasmoadmin.json", + "template": "apps/tasmoadmin.json", + "template_status": "generated-unvalidated", + "content_hash": "8b403ef48c0be77c8cb57f004fde5c5c11842859c3ee6b40505c61e379e3c737", + "hidden": false, + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "multi_container": false + }, + { + "id": "tautulli", + "provider": "linuxserver.io", + "title": "Tautulli", + "repository_name": "docker-tautulli", + "repository": "https://github.com/linuxserver/docker-tautulli", + "description": "Tautulli is a python based web application for monitoring, analytics and notifications for Plex Media Server.", + "website": "http://tautulli.com", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/tautulli-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T01:25:01Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/tautulli:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/tautulli.json", + "template_status": "generated-unvalidated", + "content_hash": "c0eadde7ca2891584aef7fc01360ede3a8b74e157eb9b3120e89dc2b9818a089", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "tdarr", + "provider": "HaveAGitGat", + "template_family": "curated-profile", + "title": "Tdarr", + "repository": "https://github.com/HaveAGitGat/Tdarr", + "description": "Tdarr keeps a media library in the formats and codecs chosen for it: it scans the library, checks the health of every file and transcodes what does not match, with its own worker node inside the container. The web interface is on port 8265 and the node listens on 8266.", + "website": "https://tdarr.io", + "icon": "https://raw.githubusercontent.com/HaveAGitGat/Tdarr/master/assets/tdarr.png", + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": "2026-09-20", + "main_image": "ghcr.io/haveagitgat/tdarr:latest", + "category": "media", + "category_label": "Media", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/tdarr.json", + "template": "apps/tdarr.json", + "template_status": "generated-unvalidated", + "content_hash": "9cd3c713326e31f4ce749ac1dc45b2265b3a28389140d7d57a5de95f491712bd", + "hidden": false, + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "multi_container": false + }, + { + "id": "teable", + "source_app_id": "teable", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Teable", + "repository": "https://hub.docker.com/r/teableio/teable", + "description": "Teable is a new generation open-source database platform. It provides an intuitive spreadsheet-like experience, while being powered by a high-performance Postgres database underneath, combining ease of use with powerful data processing capabilities.\n\n**Key Features:**\n- **High Performance**: Built on the Postgres core, it effortlessly handles millions of records with extremely fast response times.\n- **Modern Interface**: Offers multiple views including grid, kanban, gallery, and forms, with a clean and user-friendly design.\n- **Real-time Collaboration**: Supports multi-user online collaboration with real-time data synchronisation.\n- **Automation & API**: Provides powerful RESTful APIs to enable flexible integration and automation.\n\n**Learn More:**\n- [Teable Official Website](https://teable.ai)\n- [Teable GitHub Repository](https://github.com/teableio/teable)\n- [Help Documentation](https://help.teable.ai)\n", + "website": "https://teable.ai", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Teable/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "teableio/teable:latest", + "category": "databases", + "category_label": "Databases", + "template": "apps/teable.json", + "template_status": "generated-unvalidated", + "content_hash": "a9a80af10e1f23adb086d7e42dc0479771437427f1eba19da365c6a87720cb8b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "telegram", + "provider": "linuxserver.io", + "title": "Telegram", + "repository_name": "docker-telegram", + "repository": "https://github.com/linuxserver/docker-telegram", + "description": "Telegram is a cloud-based mobile and desktop messaging app.", + "website": "https://telegram.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/telegram-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T15:08:37Z", + "updated_at": "2026-04-04", + "main_image": "lscr.io/linuxserver/telegram:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/telegram.json", + "template_status": "generated-unvalidated", + "content_hash": "971f8fd3dc847c583541f3d47f90b0211d3fa007e377590a7109b7ccb52dee6b", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "thelounge", + "provider": "linuxserver.io", + "title": "Thelounge", + "repository_name": "docker-thelounge", + "repository": "https://github.com/linuxserver/docker-thelounge", + "description": "Thelounge (a fork of shoutIRC) is a web IRC client that you host on your own server.", + "website": "https://thelounge.github.io/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/thelounge-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T10:45:06Z", + "updated_at": "2025-07-27", + "main_image": "lscr.io/linuxserver/thelounge:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/thelounge.json", + "template_status": "laboratory-validated", + "content_hash": "d5d7aeabb2fa462b13b9c25f2aa2c0607b0f5a6da5f36485d9ecf2bbc420292a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "threadfin", + "source_app_id": "threadfin", + "provider": "fyb3roptik", + "template_family": "imported-compose", + "variant": null, + "title": "Threadfin", + "repository": "https://hub.docker.com/r/fyb3roptik/threadfin", + "description": "Threadfin is a M3U proxy server for Plex, Emby, Jellyfin and any client and provider which supports the .TS and .M3U8 (HLS) streaming formats.", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Threadfin/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-09-11", + "main_image": "fyb3roptik/threadfin:latest", + "category": "media", + "category_label": "Media & Streaming", + "template": "apps/threadfin.json", + "template_status": "generated-unvalidated", + "content_hash": "9617930786a3f035fde36f00806181daa74552590651c7851a8165337dd82c15", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "thunderbird", + "provider": "linuxserver.io", + "title": "Thunderbird", + "repository_name": "docker-thunderbird", + "repository": "https://github.com/linuxserver/docker-thunderbird", + "description": "Thunderbird is a free and open-source personal information manager primarily used as an e-mail client with a calendar and contactbook, as well as an RSS feed reader, chat client, and news client.", + "website": "https://www.thunderbird.net/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/thunderbird-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T16:54:04Z", + "updated_at": "2026-05-31", + "main_image": "lscr.io/linuxserver/thunderbird:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/thunderbird.json", + "template_status": "generated-unvalidated", + "content_hash": "e6e96a980490a5f72de2ed02de7fe049c4cb96b0f52823c325475386ef60c80e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "transmission", + "provider": "linuxserver.io", + "title": "Transmission", + "repository_name": "docker-transmission", + "repository": "https://github.com/linuxserver/docker-transmission", + "description": "Transmission is designed for easy, powerful use. Transmission has the features you want from a BitTorrent client: encryption, a web interface, peer exchange, magnet links, DHT, \u00b5TP, UPnP and NAT-PMP port forwarding, webseed support, watch directories, tracker editing, global and per-torrent speed limits, and more.", + "website": "https://www.transmissionbt.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/transmission-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T14:50:39Z", + "updated_at": "2026-05-31", + "main_image": "lscr.io/linuxserver/transmission:latest", + "category": "downloads", + "category_label": "Files & Downloads", + "template": "apps/transmission.json", + "template_status": "generated-unvalidated", + "content_hash": "240c2db38d35e939a7a415d05e6ee4122f78102605e9830f300f9631d1768c96", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "trilium", + "source_app_id": "trilium", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Trilium", + "repository": "https://hub.docker.com/r/triliumnext/trilium", + "description": "TriliumNext Notes is a cross-platform hierarchical note-taking tool focused on building large personal knowledge bases, offering robust organization and editing capabilities. Its intuitive interface and versatile features make it ideal for scholars, developers, and note-taking enthusiasts managing complex knowledge.\n\nThe tool's core features include hierarchical note organization and rich editing. Users can arrange notes in an arbitrarily deep tree structure, with single notes clonable to multiple locations. It supports a WYSIWYG editor with tables, images, math, and Markdown autoformatting for efficiency. Code notes feature syntax highlighting, while fast navigation includes full-text search and note hoisting. Seamless versioning and note attributes enable organization, querying, and advanced scripting.\n\nIt offers secure login (OpenID, TOTP), supports self-hosted synchronization servers or third-party services, and provides per-note encryption for privacy. Users can sketch diagrams with Excalidraw, create relation/link maps, mind maps with Mind Elixir, and geo maps with location pins and GPX tracks. A REST API enables automation, with scalability for over 100,000 notes. Touch-optimized mobile frontend, dark theme, user themes, Evernote/Markdown import/export, and Web Clipper enhance usability.\n\n**Key Features:**\n- Notes can be arranged into arbitrarily deep tree. Single note can be placed into multiple places in the tree (see [cloning](https://triliumnext.github.io/Docs/Wiki/cloning-notes))\n- Rich WYSIWYG note editor including e.g. tables, images and [math](https://triliumnext.github.io/Docs/Wiki/text-notes) with markdown [autoformat](https://triliumnext.github.io/Docs/Wiki/text-notes#autoformat)\n- Support for editing [notes with source code](https://triliumnext.github.io/Docs/Wiki/code-notes), including syntax highlighting\n- Fast and easy [navigation between notes](https://triliumnext.github.io/Docs/Wiki/note-navigation), full text search and [note hoisting](https://triliumnext.github.io/Docs/Wiki/note-hoisting)\n- Seamless [note versioning](https://triliumnext.github.io/Docs/Wiki/note-revisions)\n- Note [attributes](https://triliumnext.github.io/Docs/Wiki/attributes) can be used for note organization, querying and advanced [scripting](https://triliumnext.github.io/Docs/Wiki/scripts)\n- Direct [OpenID and TOTP integration](https://github.com/TriliumNext/Trilium/blob/main/docs/User%20Guide/User%20Guide/Installation%20%26%20Setup/Server%20Installation/Multi-Factor%20Authentication.md) for more secure login\n- [Synchronization](https://triliumnext.github.io/Docs/Wiki/synchronization) with self-hosted sync server\n - there's a [3rd party service for hosting synchronisation server](https://trilium.cc/paid-hosting)\n- [Sharing](https://triliumnext.github.io/Docs/Wiki/sharing) (publishing) notes to public internet\n- Strong [note encryption](https://triliumnext.github.io/Docs/Wiki/protected-notes) with per-note granularity\n- Sketching diagrams, based on [Excalidraw](https://excalidraw.com/) (note type canvas)\n- [Relation maps](https://triliumnext.github.io/Docs/Wiki/relation-map) and [link maps](https://triliumnext.github.io/Docs/Wiki/link-map) for visualizing notes and their relations\n- Mind maps, based on [Mind Elixir](https://docs.mind-elixir.com/)\n- [Geo maps](https://github.com/TriliumNext/Trilium/blob/main/docs/User%20Guide/User%20Guide/Note%20Types/Geo%20Map.md) with location pins and GPX tracks\n- [Scripting](https://triliumnext.github.io/Docs/Wiki/scripts) - see [Advanced showcases](https://triliumnext.github.io/Docs/Wiki/advanced-showcases)\n- [REST API](https://triliumnext.github.io/Docs/Wiki/etapi) for automation\n- Scales well in both usability and performance upwards of 100 000 notes\n- Touch optimized [mobile frontend](https://triliumnext.github.io/Docs/Wiki/mobile-frontend) for smartphones and tablets\n- Built-in [dark theme](https://triliumnext.github.io/Docs/Wiki/themes), support for user themes\n- [Evernote](https://triliumnext.github.io/Docs/Wiki/evernote-import) and [Markdown import & export](https://triliumnext.github.io/Docs/Wiki/markdown)\n- [Web Clipper](https://triliumnext.github.io/Docs/Wiki/web-clipper) for easy saving of web content\n- Customizable UI (sidebar buttons, user-defined widgets,...)\n- [Metrics](https://github.com/TriliumNext/Trilium/blob/main/docs/User%20Guide/User%20Guide/Advanced%20Usage/Metrics.md), along with a [Grafana Dashboard](https://github.com/TriliumNext/Trilium/blob/main/docs/User%20Guide/User%20Guide/Advanced%20Usage/Metrics/grafana-dashboard.json)\n\n**Learn More:**\n- [TriliumNext GitHub Repository](https://github.com/TriliumNext/Trilium)\n- [awesome-trilium](https://github.com/Nriver/awesome-trilium) for 3rd party themes, scripts, plugins and more\n- [TriliumRocks!](https://trilium.rocks/) for tutorials, guides, and much more\n", + "website": "https://triliumnext.github.io/Docs/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Trilium/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-13", + "main_image": "triliumnext/trilium:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/trilium.json", + "template_status": "laboratory-validated", + "content_hash": "da0994316a92ddb2ff74c12ce51440b1d3fc061fe7b22f6e3bc615a57960b7bf", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "turbodiffusion-nvidia", + "source_app_id": "turbodiffusion-nvidia", + "provider": "icewhaletech", + "template_family": "imported-compose", + "variant": "nvidia", + "title": "TurboDiffusion(Nvidia GPU)", + "repository": "https://hub.docker.com/r/icewhaletech/turbodiffusion", + "description": "TurboDiffusion is an accelerated text-to-video generation framework based on the Latent Consistency Model (LCM). It leverages various TurboWan2 models to rapidly generate high-quality videos from text descriptions. The framework supports both image and video generation and provides optimized checkpoints for different GPU configurations.\n\n**Key Features:**\n- Ultra-fast video and image generation\n- Intuitive Gradio WebUI\n- Optimized for different GPU configurations\n- Quantized and unquantized checkpoints\n- Flexible model configuration\n\n**Hardware Requirements:**\n- Recommended: RTX 3090 or above\n- GPU VRAM: > 30 GB\n- System RAM: > 40 GB\n- CUDA-compatible NVIDIA drivers\n\n**Learn More:**\n- [TurboDiffusion GitHub](https://github.com/thu-ml/TurboDiffusion)\n", + "website": "", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/TurboDiffusion_Nvidia/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "icewhaletech/turbodiffusion:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/turbodiffusion-nvidia.json", + "template_status": "generated-unvalidated", + "content_hash": "92708cc935adf96cf0b6cf990f172e5a3d10f7d56b272b99a8d0cbaae87c1e8d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "tvheadend", + "provider": "linuxserver.io", + "title": "Tvheadend", + "repository_name": "docker-tvheadend", + "repository": "https://github.com/linuxserver/docker-tvheadend", + "description": "Tvheadend works as a proxy server: is a TV streaming server and recorder for Linux, FreeBSD and Android supporting DVB-S, DVB-S2, DVB-C, DVB-T, ATSC, ISDB-T, IPTV, SAT>IP and HDHomeRun as input sources.", + "website": "https://www.tvheadend.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/tvheadend-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T18:05:33Z", + "updated_at": "2024-06-25", + "main_image": "lscr.io/linuxserver/tvheadend:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/tvheadend.json", + "template_status": "generated-unvalidated", + "content_hash": "5eba949f7de4e82e979919726c2760cedfc0938327154ca145f82c63dc6981e6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "twingate-connector", + "source_app_id": "twingate-connector", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Twingate", + "repository": "https://hub.docker.com/r/twingate/connector", + "description": "It's a connector for Twingate\".", + "website": "https://www.twingate.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Twingate/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-04-22", + "main_image": "twingate/connector:latest", + "category": "remote", + "category_label": "Remote Access & VPN", + "template": "apps/twingate-connector.json", + "template_status": "generated-unvalidated", + "content_hash": "fdbfc2b3ac8ce28f14ee1de2bd1a5bb0b76c7bdcb5b900ab75260f9e8a78b8ae", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ubooquity", + "provider": "linuxserver.io", + "title": "Ubooquity", + "repository_name": "docker-ubooquity", + "repository": "https://github.com/linuxserver/docker-ubooquity", + "description": "Ubooquity is a free, lightweight and easy-to-use home server for your comics and ebooks. Use it to access your files from anywhere, with a tablet, an e-reader, a phone or a computer.", + "website": "https://vaemendis.net/ubooquity/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ubooquity-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T00:39:52Z", + "updated_at": "2025-07-27", + "main_image": "lscr.io/linuxserver/ubooquity:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/ubooquity.json", + "template_status": "generated-unvalidated", + "content_hash": "00be4ce78bdf56e484c8cb9f6bc3fa1b8d7ae403b1c81f84fd0ab865264a7da6", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ungoogled-chromium", + "provider": "linuxserver.io", + "title": "Ungoogled Chromium", + "repository_name": "docker-ungoogled-chromium", + "repository": "https://github.com/linuxserver/docker-ungoogled-chromium", + "description": "Ungoogled Chromium is Google Chromium, sans dependency on Google web services.", + "website": "https://github.com/ungoogled-software/ungoogled-chromium", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/ungoogled-chromium-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T06:58:56Z", + "updated_at": "2026-03-31", + "main_image": "lscr.io/linuxserver/ungoogled-chromium:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/ungoogled-chromium.json", + "template_status": "generated-unvalidated", + "content_hash": "05e77f04e355ddb56edf94b8b5df047aca192b5ac908913411505ebc24127af2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "unifi-controller", + "source_app_id": "unifi-controller", + "provider": "linuxserver.io", + "template_family": "imported-compose", + "variant": null, + "title": "Unifi-controller [legacy]", + "repository": "https://hub.docker.com/r/linuxserver/unifi-controller", + "description": "For Unifi to adopt other devices, e.g. an Access Point, it is required to change the inform IP address. Because Unifi runs inside Docker by default it uses an IP address not accessible by other devices. To change this go to Settings > System Settings > Controller Configuration and set the Controller Hostname/IP to a hostname or IP address accessible by your devices. Additionally the checkbox \"Override inform host with controller hostname/IP\" has to be checked, so that devices can connect to the controller during adoption (devices use the inform-endpoint during adoption).", + "website": "https://ui.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Unifi-controller/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2023-12-01", + "main_image": "linuxserver/unifi-controller:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/unifi-controller.json", + "template_status": "generated-unvalidated", + "content_hash": "a0b504b1e69443e58b231aa03b01e2bc3f7654cff1988bf37020088a8b971567", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "unifi-network-application", + "provider": "linuxserver.io", + "title": "Unifi Network Application", + "repository_name": "docker-unifi-network-application", + "repository": "https://github.com/linuxserver/docker-unifi-network-application", + "description": "", + "website": null, + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/unifi-network-application-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-08T20:23:32Z", + "updated_at": "2026-07-14", + "main_image": "lscr.io/linuxserver/unifi-network-application:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/unifi-network-application.json", + "template_status": "generated-unvalidated", + "content_hash": "b30497c2ccc6d4341d7093c2b4f24684042aa39673e43d34556409a605afcbf4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "unpackerr", + "provider": "golift", + "template_family": "curated-profile", + "title": "Unpackerr", + "repository": "https://github.com/Unpackerr/unpackerr", + "description": "Background archive extraction for Arr download queues. No web interface.", + "website": "https://unpackerr.zip/docs/install/docker/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "updated_at": null, + "main_image": "golift/unpackerr:latest", + "category": "arr", + "category_label": "*Arr Suite", + "replaces_discovered_ids": [], + "curated_path": "catalog/curated/unpackerr.json", + "template": "apps/unpackerr.json", + "template_status": "generated-unvalidated", + "content_hash": "cf30efc8362f9b033807d908fd29b33151993c8ec483cbb70606700612c300f5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "uptimekuma", + "source_app_id": "uptimekuma", + "provider": "louislam", + "template_family": "imported-compose", + "variant": null, + "title": "Uptime Kuma", + "repository": "https://hub.docker.com/r/louislam/uptime-kuma", + "description": "Uptime Kuma is a free, easy-to-use self-hosted monitoring tool designed for real-time tracking of network services and infrastructure, offering a modern interface and robust functionality. It provides an intuitive Web dashboard for managing services, ideal for individual developers, home lab users, and small teams.\n\nThe tool's core features include comprehensive monitoring and diverse notification channels. It monitors HTTP/HTTPS, TCP ports, DNS records, databases, Ping, and Steam game servers, with interactive Ping charts visually displaying response times and status. Users can receive real-time alerts via Telegram, Discord, Slack, Email (SMTP), and over 95 other notification services. SSL certificate monitoring checks certificate validity and expiration, aiding timely renewals.\n\nIt supports 20-second monitoring intervals for rapid downtime detection and offers multiple status pages to share real-time service status with customers. Proxy support enables remote access via Cloudflare, Nginx, or similar services, enhancing flexibility. Two-factor authentication (2FA) and API keys bolster security, ensuring full user control over local data. The tool delivers an efficient monitoring solution with intuitive operation and community support.\n\n**Key Features:**\n- Monitor HTTP/HTTPS, TCP, DNS, databases, and other services\n- Notifications via Telegram, Discord, Slack, and over 95 other channels\n- Interactive Ping charts displaying response times and status\n- SSL certificate monitoring for validity and expiration\n- 20-second monitoring intervals for rapid downtime detection\n- Multiple status pages for sharing service status\n- Proxy support compatible with Cloudflare, Nginx, and more\n- Two-factor authentication (2FA) and API keys for enhanced security\n\n**Learn More:**\n- [Uptime Kuma Official Website](https://uptimekuma.org)\n- [Uptime Kuma GitHub Repository](https://github.com/louislam/uptime-kuma)\n", + "website": "https://uptimekuma.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/UptimeKuma/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-31", + "main_image": "louislam/uptime-kuma:latest", + "category": "monitoring", + "category_label": "Monitoring & Analytics", + "template": "apps/uptimekuma.json", + "template_status": "generated-unvalidated", + "content_hash": "b4b7d85780c731d7d68a596cdee4be771da54fc5bfbc27813c95dc5410976019", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "v2raya", + "source_app_id": "v2raya", + "provider": "mzz2017", + "template_family": "imported-compose", + "variant": null, + "title": "V2rayA", + "repository": "https://hub.docker.com/r/mzz2017/v2raya", + "description": "v2rayA is a V2Ray client supporting global transparent proxy, compatible with SS, SSR, Trojan (trojan-go), Tuic, and Juicity protocols. Designed for simplicity, it meets most user needs, ideal for scenarios requiring efficient proxy services.\n\nCore features include global transparent proxy and multi-outbound load balancing with traffic splitting. It provides proxy services for nearly all applications without requiring application-specific proxy support. Support for creating and connecting multiple outbound nodes ensures load balancing and efficient traffic splitting for optimal network performance.\n\nIt offers RoutingA, a custom routing language for V2Ray, providing powerful and convenient traffic splitting support. Multiple strategies address DNS pollution, with advanced settings enabling customized configurations. With simplicity and functionality at the core, the platform delivers a modern solution for proxy management.\n\n**Key Features:**\n- Web-based GUI for easy configuration and management\n- Support for multiple protocols: VMess, VLESS, SS, SSR, Trojan, Tuic, Juicity\n- Global transparent proxy for seamless application proxy services\n- Multi-outbound load balancing and traffic splitting\n- RoutingA custom routing for convenient traffic splitting\n- Multiple DNS pollution mitigation strategies with advanced custom settings\n\n**Learn More:**\n- [V2rayA Official Website](https://v2raya.org/)\n- [V2rayA GitHub](https://github.com/v2rayA/v2rayA)\n", + "website": "https://v2raya.org/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/V2rayA/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-01-25", + "main_image": "mzz2017/v2raya:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/v2raya.json", + "template_status": "generated-unvalidated", + "content_hash": "100ab96c062ab93155191ab6099e72098459058ff4f1701f256f1139ddcb55ae", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": true, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "vaultwarden", + "source_app_id": "vaultwarden", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Vaultwarden", + "repository": "https://hub.docker.com/r/vaultwarden/server", + "description": "Alternative implementation of the Bitwarden server API written in Rust and compatible with upstream Bitwarden clients*, perfect for self-hosted deployment where running the official resource-heavy service might not be ideal.", + "website": "https://vaultwarden.net", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Vaultwarden/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "vaultwarden/server:latest", + "category": "security", + "category_label": "Authentication & Security", + "template": "apps/vaultwarden.json", + "template_status": "generated-unvalidated", + "content_hash": "aca898dc33a75b19b6fa5485b28953720920a561d69d50b63a7c15ffce5e7543", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "virt-manager", + "source_app_id": "virt-manager", + "provider": "mber5", + "template_family": "imported-compose", + "variant": null, + "title": "Virtual Machine Manager", + "repository": "https://hub.docker.com/r/mber5/virt-manager", + "description": "A GTK Broadway web UI for libvirt and virt-manager, to run virtual machines using QEMU/KVM.", + "website": "https://virt-manager.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/VirtualMachineManager/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2023-02-01", + "main_image": "mber5/virt-manager:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/virt-manager.json", + "template_status": "generated-unvalidated", + "content_hash": "d4c674fc1093a8dc0afb9c346d3e3900a9636240f7fbb1b07a123e5a406986fb", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "vivaldi", + "provider": "linuxserver.io", + "title": "Vivaldi", + "repository_name": "docker-vivaldi", + "repository": "https://github.com/linuxserver/docker-vivaldi", + "description": "Vivaldi is a Norwegian freeware, cross-platform web browser with a built-in email client developed by Vivaldi Technologies.", + "website": "https://vivaldi.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vivaldi-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T05:43:20Z", + "updated_at": "2026-03-31", + "main_image": "lscr.io/linuxserver/vivaldi:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/vivaldi.json", + "template_status": "generated-unvalidated", + "content_hash": "891cf938d5bce12c3b457524bbbd9a99bb361e06868e9996fe13ebacd23a3d3e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "vlc", + "provider": "linuxserver.io", + "title": "Vlc", + "repository_name": "docker-vlc", + "repository": "https://github.com/linuxserver/docker-vlc", + "description": "VLC Media Player is a free and open source cross-platform multimedia player and framework that delivers dependable performance across multiple devices.", + "website": "https://www.videolan.org/vlc/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vlc-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T17:57:39Z", + "updated_at": "2026-03-30", + "main_image": "lscr.io/linuxserver/vlc:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/vlc.json", + "template_status": "generated-unvalidated", + "content_hash": "e02527d18fd43cafb94d8180a632047be108ae2f6da18bd92cb3ed60805ad1b1", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "vocechat", + "source_app_id": "vocechat", + "provider": "privoce", + "template_family": "imported-compose", + "variant": null, + "title": "VoceChat", + "repository": "https://hub.docker.com/r/privoce/vocechat-server", + "description": "VoceChat is a secure chat software designed for independent deployment, offering a flexible solution for seamless communication. It combines instant messaging with channel-based group chats, allowing you to engage in one-on-one conversations or create themed channels for group discussions.\n\nVoceChat supports a variety of message formats, including text, images, files, emojis, and rich text (Markdown), making your communication vibrant and expressive. Once deployed, it can be accessed via a WebAPP or mobile APP, ensuring a consistent experience across platforms.\n\nWith robust management features, VoceChat enables easy member and channel administration, giving you full control over your team or group\u2019s communication environment. Whether for individual users or enterprise teams, VoceChat delivers a secure, versatile, and efficient chat solution.\n", + "website": "https://voce.chat", + "icon": null, + "architectures": [ + "amd64" + ], + "default_branch": "main", + "source_path": "Apps/VoceChat/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2026-05-17", + "main_image": "privoce/vocechat-server:latest", + "category": "communication", + "category_label": "Communication & Community", + "template": "apps/vocechat.json", + "template_status": "generated-unvalidated", + "content_hash": "76d7fd941f9a3673cc5f3840b63ee3433d326259810bab4160f286b1047c9c1e", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "vscode", + "provider": "linuxserver.io", + "title": "Vscode", + "repository_name": "docker-vscode", + "repository": "https://github.com/linuxserver/docker-vscode", + "description": "VS Code is an integrated development environment developed by Microsoft. This container runs the full desktop application, for a web native version see Code Server.", + "website": "https://code.visualstudio.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscode-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T18:36:38Z", + "updated_at": "2026-04-04", + "main_image": "lscr.io/linuxserver/vscode:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/vscode.json", + "template_status": "generated-unvalidated", + "content_hash": "b0fa624781b3cdaa32b5cf7d70ec33f37f198190e7025c7f7adee8c54838c9a0", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "vscodium", + "provider": "linuxserver.io", + "title": "Vscodium", + "repository_name": "docker-vscodium", + "repository": "https://github.com/linuxserver/docker-vscodium", + "description": "VSCodium is a community-driven, freely-licensed binary distribution of Microsoft\u2019s editor VS Code.", + "website": "https://vscodium.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscodium-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T10:34:25Z", + "updated_at": "2026-04-04", + "main_image": "lscr.io/linuxserver/vscodium:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/vscodium.json", + "template_status": "generated-unvalidated", + "content_hash": "42e061febe0602119c45eddf245ec9df056c32786b877cc1931ab6666767c8f4", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "vscodium-web", + "provider": "linuxserver.io", + "title": "Vscodium Web", + "repository_name": "docker-vscodium-web", + "repository": "https://github.com/linuxserver/docker-vscodium-web", + "description": "Vscodium-web is a community-driven, freely-licensed binary distribution of the remote host web component of Microsoft's editor VS Code.", + "website": "https://vscodium.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/vscodium-web-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-09T12:15:12Z", + "updated_at": "2026-06-24", + "main_image": "lscr.io/linuxserver/vscodium-web:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/vscodium-web.json", + "template_status": "generated-unvalidated", + "content_hash": "fcd69129dfef13b4297e02c9bda504d82d22afd25978a07abd848b5d80b22c17", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "wallabag", + "source_app_id": "wallabag", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "Wallabag", + "repository": "https://hub.docker.com/r/wallabag/wallabag", + "description": "Wallabag is a web page saving app that allows users to save articles for offline reading, extracting content for a distraction-free experience. Its intuitive Web interface enables saving articles with a click, ensuring users can read them at their convenience.\n\nThe app's core features include convenient web page saving, optimized reading, and flexible content organization. It extracts only the article's content, removing pop-ups and ads, and displays it in a clean, comfortable view. Users can organize saved articles with tags and automatic tagging rules, creating a personalized content library accessible on demand. Browser extensions enable quick saving, compatible with Chrome, Firefox, Opera, and more. Cross-platform clients cover Android, iOS, and other devices, ensuring a seamless reading experience. It also supports multi-user collaboration for sharing saved articles.\n\nIt enables importing data from services like Pocket, Readability, Instapaper, or Pinboard, simplifying content library migration. RSS generation allows users to access saved articles in RSS readers. Community documentation enhances usability, and the app's high flexibility and intuitive operation deliver a modern web content management solution.\n\n**Key Features:**\n- Save web pages for offline reading\n- Extract pure content for a distraction-free reading view\n- Article classification with automatic tagging rules for a personalized content library\n- Browser extensions for quick web page saving\n- Cross-platform clients (Android, iOS, Chrome, Firefox, Opera)\n- Multi-user collaboration for sharing saved articles\n- Import data from Pocket, Readability, Instapaper, Pinboard and other services\n- RSS generation for accessing saved articles in readers\n\n**Learn More:**\n- [Wallabag Official Website](https://wallabag.org)\n- [Wallabag GitHub Repository](https://github.com/wallabag/wallabag)\n- [Wallabag Documentation](https://doc.wallabag.org)\n- [Wallabag Docker Image](https://hub.docker.com/r/wallabag/wallabag)\n", + "website": "https://wallabag.org", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Wallabag/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2025-10-07", + "main_image": "wallabag/wallabag:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/wallabag.json", + "template_status": "generated-unvalidated", + "content_hash": "51e1a782e78fa244f6628b4b5b51a7e5fd5a7f29fcb646bc3177fabbbaa5d233", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "webcord", + "provider": "linuxserver.io", + "title": "Webcord", + "repository_name": "docker-webcord", + "repository": "https://github.com/linuxserver/docker-webcord", + "description": "WebCord can be summarized as a pack of security and privacy hardenings, Discord features reimplementations, Electron / Chromium / Discord bugs workarounds, stylesheets, internal pages and wrapped https://discord.com page, designed to conform with ToS as much as it is possible (or hide the changes that might violate it from Discord's eyes).", + "website": "https://github.com/SpacingBat3/WebCord", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webcord-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T09:27:57Z", + "updated_at": "2026-04-04", + "main_image": "lscr.io/linuxserver/webcord:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/webcord.json", + "template_status": "generated-unvalidated", + "content_hash": "ba0930e8043ae3737ec4ea55692111eb35d55e080b2ff24446e191fbae6f91cf", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "webdav", + "source_app_id": "webdav", + "provider": "ugeek", + "template_family": "imported-compose", + "variant": null, + "title": "WebDAV", + "repository": "https://hub.docker.com/r/ugeek/webdav", + "description": "WebDAV is a web-based protocol that allows you to share and manage files over the internet, providing a collaborative environment for file editing and versioning.", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/WebDav/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2022-11-24", + "main_image": "ugeek/webdav:latest", + "category": "productivity", + "category_label": "Productivity & Workflows", + "template": "apps/webdav.json", + "template_status": "generated-unvalidated", + "content_hash": "bb9969e0330a0f6ed75e15cc9386ae27a7e168d17d9ea32b67e53003430de851", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "webgrabplus", + "provider": "linuxserver.io", + "title": "Webgrabplus", + "repository_name": "docker-webgrabplus", + "repository": "https://github.com/linuxserver/docker-webgrabplus", + "description": "Webgrabplus is a multi-site incremental xmltv epg grabber. It collects tv-program guide data from selected tvguide sites for your favourite channels.", + "website": "https://www.webgrabplus.com", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webgrabplus-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T15:25:37Z", + "updated_at": "2025-09-14", + "main_image": "lscr.io/linuxserver/webgrabplus:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/webgrabplus.json", + "template_status": "generated-unvalidated", + "content_hash": "d95c683641c930199d082b5a4cd0a7f8319fb22c0d7d0094e5f37f7e4709ce70", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "webstation", + "provider": "linuxserver.io", + "title": "Webstation", + "repository_name": "docker-webstation", + "repository": "https://github.com/linuxserver/docker-webstation", + "description": "Webstation is a web native emulation focused LXQt desktop based on Ubuntu.", + "website": "https://github.com/linuxserver/docker-webstation", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webstation-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T14:32:58Z", + "updated_at": "2026-08-21", + "main_image": "lscr.io/linuxserver/webstation:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/webstation.json", + "template_status": "generated-unvalidated", + "content_hash": "98b5ee5bd4e9cfde9a16c956050eb92dc69bc338a2025a274f6247aed82964ae", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "webtop", + "provider": "linuxserver.io", + "title": "Webtop", + "repository_name": "docker-webtop", + "repository": "https://github.com/linuxserver/docker-webtop", + "description": "Webtop - Alpine, Ubuntu, Fedora, and Arch based containers containing full desktop environments in officially supported flavors accessible via any modern web browser.", + "website": "https://github.com/linuxserver/docker-webtop", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/webtop-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T22:34:05Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/webtop:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/webtop.json", + "template_status": "generated-unvalidated", + "content_hash": "aad91f6c615364e5409d09ea3a66cbeba37df33e78431e1466cda87853487253", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "weixin", + "provider": "linuxserver.io", + "title": "Weixin", + "repository_name": "docker-weixin", + "repository": "https://github.com/linuxserver/docker-weixin", + "description": "Weixin (WeChat) is an instant messaging, social media, and mobile payment app developed by Tencent.", + "website": "https://weixin.qq.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/weixin-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T15:32:49Z", + "updated_at": "2026-03-29", + "main_image": "lscr.io/linuxserver/weixin:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/weixin.json", + "template_status": "generated-unvalidated", + "content_hash": "478228945042bca9aebc49d1e8124aac5b71c1f321b7fffe8ad49715b887f857", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "weknora", + "source_app_id": "weknora", + "provider": "wechatopenai", + "template_family": "imported-compose", + "variant": null, + "title": "WeKnora", + "repository": "https://hub.docker.com/r/wechatopenai/weknora-ui", + "description": "WeKnora is a deep document understanding and semantic retrieval framework based on Large Language Models (LLM), specifically designed for document scenarios with complex structures and heterogeneous content. It adopts a modular architecture, integrating key technologies such as multimodal preprocessing, semantic vector indexing, intelligent retrieval, and large model inference. Based on the Retrieval-Augmented Generation (RAG) paradigm, it achieves context-aware, high-quality Q&A capabilities. WeKnora can deeply understand document content in different formats, combine relevant document fragments with language model inference, and output accurate, coherent semantic results.\n\n**Key Features:**\n- Multimodal Deep Parsing: Supports structured content extraction from various formats such as PDF, Word, TXT, images, including OCR image text recognition.\n- Semantic Vector Indexing and Intelligent Retrieval: Achieves high-precision semantic matching and recall through a combination of vector retrieval, keyword retrieval, and even knowledge graph-enhanced retrieval.\n- RAG Closed-Loop Q&A Generation: Generates accurate and coherent content answers by leveraging large language model inference and retrieval fragment fusion.\n- Agent Mode Enhanced Capabilities: Supports ReACT Agent mode, which can call built-in tools, external web search, etc., during multi-round iterations, to improve complex task processing capabilities.\n- Multi-type Knowledge Base Management: Can create FAQ and document-type knowledge bases, and flexibly manage tags, batch import files or URLs.\n- Configurable Dialogue Strategy and UI: Provides an intuitive Web interface and REST API, allowing online adjustment of models, retrieval thresholds, and Prompt to control dialogue behavior.\n\n**Learn More:**\n- [Official Website](https://weknora.weixin.qq.com)\n- [GitHub Link](https://github.com/Tencent/WeKnora)\n", + "website": "https://weknora.weixin.qq.com", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/WeKnora/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "wechatopenai/weknora-ui:latest", + "category": "ai", + "category_label": "AI / Coding & Dev-Tools", + "template": "apps/weknora.json", + "template_status": "generated-review-required", + "content_hash": "5794e4e038acef62800013adbb93160b04da8e113928ed2ebda7be6518477f9c", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "service:app:compose-key:depends_on", + "service:weknora-docreader:healthcheck-format", + "service:weknora-postgres:healthcheck-format", + "service:neo4j:compose-key:profiles", + "service:qdrant:compose-key:profiles", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "wg-easy", + "source_app_id": "wg-easy", + "provider": "official", + "template_family": "imported-compose", + "variant": null, + "title": "WireGuard Easy", + "repository": "https://ghcr.io/wg-easy/wg-easy", + "description": "You have found the easiest way to install & manage WireGuard on any Linux host!", + "website": "", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/WireGuardEasy/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": "2024-07-16", + "main_image": "ghcr.io/wg-easy/wg-easy:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/wg-easy.json", + "template_status": "laboratory-validated", + "content_hash": "1dcc5a50a84c407cb5b9cc5903a7bce1656b1582f2db12494572b5221c37d25a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "wikijs", + "provider": "linuxserver.io", + "title": "Wikijs", + "repository_name": "docker-wikijs", + "repository": "https://github.com/linuxserver/docker-wikijs", + "description": "Wikijs A modern, lightweight and powerful wiki app built on NodeJS.", + "website": "https://github.com/Requarks/wiki", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wikijs-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-11T17:24:46Z", + "updated_at": "2025-10-14", + "main_image": "lscr.io/linuxserver/wikijs:latest", + "category": "documents", + "category_label": "Documents & Notes", + "template": "apps/wikijs.json", + "template_status": "generated-unvalidated", + "content_hash": "a342be87c339c4585e68f30b0d4346b08e9837f023e6510441022fb974381571", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "winegui", + "provider": "linuxserver.io", + "title": "Winegui", + "repository_name": "docker-winegui", + "repository": "https://github.com/linuxserver/docker-winegui", + "description": "WineGUI is a user-interface friendly Wine manager that provides a graphical frontend for creating and managing Wine bottles.", + "website": "https://gitlab.melroy.org/melroy/winegui", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/winegui-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T17:40:25Z", + "updated_at": "2026-04-22", + "main_image": "lscr.io/linuxserver/winegui:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/winegui.json", + "template_status": "generated-unvalidated", + "content_hash": "c0c8f281a8251cdf5828cf9f535216c7426ccbcac51c5babcf694b7321478f5a", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "wireguard", + "provider": "linuxserver.io", + "title": "Wireguard", + "repository_name": "docker-wireguard", + "repository": "https://github.com/linuxserver/docker-wireguard", + "description": "WireGuard\u00ae is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. It is currently under heavy development, but already it might be regarded as the most secure, easiest to use, and simplest VPN solution in the industry.", + "website": "https://www.wireguard.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wireguard-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-10T15:09:55Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/wireguard:latest", + "category": "remote", + "category_label": "Remote Access & VPN", + "template": "apps/wireguard.json", + "template_status": "laboratory-validated", + "content_hash": "2280c57351bfd17287bf450cea823e6fff3dd6cf99d30dde13b2cd4fcde9845d", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "wireshark", + "provider": "linuxserver.io", + "title": "Wireshark", + "repository_name": "docker-wireshark", + "repository": "https://github.com/linuxserver/docker-wireshark", + "description": "Wireshark is the world\u2019s foremost and widely-used network protocol analyzer. It lets you see what\u2019s happening on your network at a microscopic level and is the de facto (and often de jure) standard across many commercial and non-profit enterprises, government agencies, and educational institutions. Wireshark development thrives thanks to the volunteer contributions of networking experts around the globe and is the continuation of a project started by Gerald Combs in 1998.", + "website": "https://www.wireshark.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wireshark-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T19:32:17Z", + "updated_at": "2026-06-10", + "main_image": "lscr.io/linuxserver/wireshark:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/wireshark.json", + "template_status": "generated-unvalidated", + "content_hash": "a4301805cc1694ec90fd9ae0bb316e41e93bc736f791d045ea545a775fd15197", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "wps-office", + "provider": "linuxserver.io", + "title": "Wps Office", + "repository_name": "docker-wps-office", + "repository": "https://github.com/linuxserver/docker-wps-office", + "description": "WPS Office is a lightweight, feature-rich comprehensive office suite with high compatibility. As a handy and professional office software, WPS Office allows you to edit files in Writer, Presentation, Spreadsheet, and PDF to improve your work efficiency.", + "website": "https://www.wps.com/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/wps-office-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-07T17:45:52Z", + "updated_at": "2026-04-11", + "main_image": "lscr.io/linuxserver/wps-office:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/wps-office.json", + "template_status": "generated-unvalidated", + "content_hash": "b6bec2aab5f09d42185c54420022a7eb6f1ef59f21a23c0475f2550f53b576b5", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "xbackbone", + "provider": "linuxserver.io", + "title": "Xbackbone", + "repository_name": "docker-xbackbone", + "repository": "https://github.com/linuxserver/docker-xbackbone", + "description": "Xbackbone is a simple, self-hosted, lightweight PHP file manager that support the instant sharing tool ShareX and *NIX systems. It supports uploading and displaying images, GIF, video, code, formatted text, and file downloading and uploading. Also have a web UI with multi user management, past uploads history and search support.", + "website": "https://github.com/SergiX44/XBackBone", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/xbackbone-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-13T07:29:57Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/xbackbone:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/xbackbone.json", + "template_status": "generated-unvalidated", + "content_hash": "6255b5f8ca24964edd110dda06e8d597673649f56fd113bfbb6203cfb12e3c52", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "xemu", + "provider": "linuxserver.io", + "title": "Xemu", + "repository_name": "docker-xemu", + "repository": "https://github.com/linuxserver/docker-xemu", + "description": "xemu is a free and open-source application that emulates the original Microsoft Xbox game console, enabling people to play their original Xbox games on Windows, macOS, and Linux systems.", + "website": "https://xemu.app/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/xemu-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-08T00:04:23Z", + "updated_at": "2026-05-09", + "main_image": "lscr.io/linuxserver/xemu:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/xemu.json", + "template_status": "generated-unvalidated", + "content_hash": "23d26871dccef7cfd4dd1033de8a2e41aad54a5eaf89491a4a0afd0499144ee2", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "yaak", + "provider": "linuxserver.io", + "title": "Yaak", + "repository_name": "docker-yaak", + "repository": "https://github.com/linuxserver/docker-yaak", + "description": "Yaak is a desktop API client for organizing and executing REST, GraphQL, and gRPC requests. It's built using Tauri, Rust, and ReactJS.", + "website": "https://yaak.app/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/yaak-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "main", + "pushed_at": "2026-09-08T08:58:32Z", + "updated_at": "2026-04-20", + "main_image": "lscr.io/linuxserver/yaak:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/yaak.json", + "template_status": "generated-unvalidated", + "content_hash": "ed19a7d4fcbcee297a93cca4c257e6bc5f535e19364b8aaa36297913cad18799", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "your_spotify", + "provider": "linuxserver.io", + "title": "Your_Spotify", + "repository_name": "docker-your_spotify", + "repository": "https://github.com/linuxserver/docker-your_spotify", + "description": "Your_spotify is a self-hosted application that tracks what you listen and offers you a dashboard to explore statistics about it! It's composed of a web server which polls the Spotify API every now and then and a web application on which you can explore your statistics.", + "website": "https://github.com/Yooooomi/your_spotify", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/your_spotify-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "pushed_at": "2026-09-09T21:24:34Z", + "updated_at": "2026-07-05", + "main_image": "lscr.io/linuxserver/your_spotify:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/your_spotify.json", + "template_status": "generated-unvalidated", + "content_hash": "513c6c87abca5fe6af78b28e5cb1b838c223a130baa070694b205c61177b15e0", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + }, + { + "id": "zen", + "provider": "linuxserver.io", + "title": "Zen", + "repository_name": "docker-zen", + "repository": "https://github.com/linuxserver/docker-zen", + "description": "Zen Browser is a free and open-source fork of Mozilla Firefox with a focus on privacy, customizability and design.", + "website": "https://zen-browser.app/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/zen-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-12T17:01:50Z", + "updated_at": "2026-03-31", + "main_image": "lscr.io/linuxserver/zen:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/zen.json", + "template_status": "generated-unvalidated", + "content_hash": "72bfa0ed4079c6b8111b293068eb6ffd017a65b80d4528333a2cb0ae0872ec63", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "znc", + "provider": "linuxserver.io", + "title": "Znc", + "repository_name": "docker-znc", + "repository": "https://github.com/linuxserver/docker-znc", + "description": "Znc is an IRC network bouncer or BNC. It can detach the client from the actual IRC server, and also from selected channels. Multiple clients from different locations can connect to a single ZNC account simultaneously and therefore appear under the same nickname on IRC.", + "website": "http://wiki.znc.in/ZNC", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/znc-icon.png", + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "master", + "pushed_at": "2026-09-13T12:59:55Z", + "updated_at": "2025-07-27", + "main_image": "lscr.io/linuxserver/znc:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/znc.json", + "template_status": "generated-unvalidated", + "content_hash": "292b65cc31485609de0925f22036da98829f698e98479f8bc7f4477633909808", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "zotero", + "provider": "linuxserver.io", + "title": "Zotero", + "repository_name": "docker-zotero", + "repository": "https://github.com/linuxserver/docker-zotero", + "description": "Zotero is a free, easy-to-use tool to help you collect, organize, annotate, cite, and share research.", + "website": "https://www.zotero.org/", + "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/zotero-icon.png", + "architectures": [ + "amd64" + ], + "default_branch": "master", + "pushed_at": "2026-09-09T22:15:01Z", + "updated_at": "2026-03-30", + "main_image": "lscr.io/linuxserver/zotero:latest", + "category": "misc", + "category_label": "Miscellaneous", + "template": "apps/zotero.json", + "template_status": "generated-unvalidated", + "content_hash": "d37149cffd35aaed02da6f93edf483865ba4df6937bc1ad9fa6ee24361e27d96", + "automatic_install_candidate": true, + "untranslated_blockers": [], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": false + }, + { + "id": "ztnet", + "source_app_id": "ztnet", + "provider": "sinamics", + "template_family": "imported-compose", + "variant": null, + "title": "ZTnet", + "repository": "https://hub.docker.com/r/sinamics/ztnet", + "description": "ZTNET is a powerful ZeroTier network management tool that simplifies network configuration and management through an intuitive Web interface, ideal for teams and individual users. Its modern design and rich features provide an efficient solution for building secure, scalable virtual networks.\n\nThe tool centers on an intuitive Web interface and organization with multi-user support. Developed in TypeScript, it acts as an intermediary between users and the ZeroTier Controller API, enabling collaborative network management within organizations to streamline team tasks. Integration with ZeroTier Central API allows direct management of networks, nodes, and members through a user-friendly interface, enhancing configuration efficiency.\n\nIt supports custom private root servers to create isolated network environments, improving privacy and control. Personalized user spaces enable users to independently create and manage networks. Support for 6plane and rfc4193 IPv6 addressing enriches enterprise or personal networking capabilities. Compatibility with ARM64 and AMD64 architectures ensures broad device support. The tool focuses on user-friendly and flexible design to deliver a modern network management experience.\n\n**Key Features:**\n- Intuitive Web interface for simplified ZeroTier network management\n- Organization and multi-user support for team collaboration\n- Integration with ZeroTier Central API for managing networks and nodes\n- Custom private root server for enhanced privacy and control\n- Personalized user spaces for independent network creation and management\n- Support for 6plane and rfc4193 IPv6 addressing\n- Compatibility with ARM64 and AMD64 architectures for diverse devices\n\n**Learn More:**\n- [ZTnet Official Website](https://ztnet.network/)\n- [ZTnet GitHub](https://github.com/sinamics/ztnet)\n", + "website": "https://ztnet.network/", + "icon": null, + "architectures": [ + "amd64", + "arm64" + ], + "default_branch": "main", + "source_path": "Apps/Ztnet/docker-compose.yml", + "source_revision": "cc8ba5d955cef2446825f617471fa8221a52479e", + "pushed_at": "2026-09-11T10:43:22Z", + "updated_at": null, + "main_image": "sinamics/ztnet:latest", + "category": "network", + "category_label": "Network & Firewall", + "template": "apps/ztnet.json", + "template_status": "generated-review-required", + "content_hash": "4b2870e8eef8ae83f029495f4ab13755ec7aab1bad589cecc8d4bc02c4d2d891", + "automatic_install_candidate": false, + "untranslated_blockers": [ + "multi-service-compose", + "compose-key:depends_on", + "native-multi-lxc-orchestrator-not-yet-implemented" + ], + "requires_privileged_lxc": false, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "optional_relaxed_confinement": false, + "requires_security_confirmation": false, + "hidden": true + } + ], + "discovery": { + "linuxserver": { + "repositories_examined": 210, + "compose_applications": 199, + "skipped_count": 11, + "skipped": [ + { + "repository": "docker-build-agent", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-d2-builder", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-documentation", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-ffmpeg", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-lsio-api", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-python", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-socket-proxy", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-templates", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-unrar", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-xvfb", + "reason": "El README no contiene una seccion docker-compose reconocible" + }, + { + "repository": "docker-yq", + "reason": "El README no contiene una seccion docker-compose reconocible" + } + ] + }, + "imported_composes": { + "compose_applications": 178, + "included_count": 138, + "duplicate_count": 34, + "duplicates": [ + { + "source_id": "bazarr", + "source_path": "Apps/Bazarr/docker-compose.yml", + "main_image": "linuxserver/bazarr:1.5.6", + "matched_catalog_id": "bazarr", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "calibre-web", + "source_path": "Apps/Calibre-web/docker-compose.yml", + "main_image": "linuxserver/calibre-web:0.6.24", + "matched_catalog_id": "calibre-web", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "deluge", + "source_path": "Apps/Deluge/docker-compose.yml", + "main_image": "linuxserver/deluge:2.2.0", + "matched_catalog_id": "deluge", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "duckdns", + "source_path": "Apps/DuckDNS/docker-compose.yml", + "main_image": "lscr.io/linuxserver/duckdns:latest", + "matched_catalog_id": "duckdns", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "duplicati", + "source_path": "Apps/Duplicati/docker-compose.yml", + "main_image": "linuxserver/duplicati:2.1.0", + "matched_catalog_id": "duplicati", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "emby", + "source_path": "Apps/Emby/docker-compose.yml", + "main_image": "emby/embyserver:4.9.5.0", + "matched_catalog_id": "emby-official", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "emby-nvidia", + "source_path": "Apps/Emby_Nvidia/docker-compose.yml", + "main_image": "emby/embyserver:4.9.5.0", + "matched_catalog_id": "emby-official", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "fileflows", + "source_path": "Apps/FileFlows/docker-compose.yml", + "main_image": "revenz/fileflows:stable", + "matched_catalog_id": "fileflows", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "frigate", + "source_path": "Apps/Frigate/docker-compose.yml", + "main_image": "ghcr.io/blakeblackshear/frigate:0.17.2", + "matched_catalog_id": "frigate", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "immich", + "source_path": "Apps/Immich/docker-compose.yml", + "main_image": "ghcr.io/immich-app/immich-server:v2.7.2", + "matched_catalog_id": "immich", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "jackett", + "source_path": "Apps/Jackett/docker-compose.yml", + "main_image": "linuxserver/jackett:0.24.1985", + "matched_catalog_id": "jackett", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "jdownloader2", + "source_path": "Apps/JDownloader2/docker-compose.yml", + "main_image": "jlesage/jdownloader-2:latest", + "matched_catalog_id": "jdownloader", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "lazylibrarian", + "source_path": "Apps/Lazylibrarian/docker-compose.yml", + "main_image": "linuxserver/lazylibrarian:version-169e669f", + "matched_catalog_id": "lazylibrarian", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "lidarr", + "source_path": "Apps/Lidarr/docker-compose.yml", + "main_image": "linuxserver/lidarr:3.1.0", + "matched_catalog_id": "lidarr", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "llamacpp", + "source_path": "Apps/llama.cpp/docker-compose.yml", + "main_image": "ghcr.io/ggml-org/llama.cpp:server", + "matched_catalog_id": "llamacpp", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "mariadb", + "source_path": "Apps/MariaDB/docker-compose.yml", + "main_image": "linuxserver/mariadb:11.4.8", + "matched_catalog_id": "mariadb", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "mylar3", + "source_path": "Apps/Mylar3/docker-compose.yml", + "main_image": "linuxserver/mylar3:0.9.0", + "matched_catalog_id": "mylar3", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "nzbget", + "source_path": "Apps/Nzbget/docker-compose.yml", + "main_image": "linuxserver/nzbget:26.1.20260522", + "matched_catalog_id": "nzbget", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "obsidian", + "source_path": "Apps/Obsidian/docker-compose.yml", + "main_image": "lscr.io/linuxserver/obsidian:1.12.7", + "matched_catalog_id": "obsidian", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "ombi", + "source_path": "Apps/Ombi/docker-compose.yml", + "main_image": "linuxserver/ombi:4.53.5", + "matched_catalog_id": "ombi", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "open-webui-ollama", + "source_path": "Apps/OpenWebUI/docker-compose.yml", + "main_image": "ghcr.io/open-webui/open-webui:ollama", + "matched_catalog_id": "open-webui-ollama", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "prowlarr", + "source_path": "Apps/Prowlarr/docker-compose.yml", + "main_image": "linuxserver/prowlarr:2.5.2", + "matched_catalog_id": "prowlarr", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "pyload", + "source_path": "Apps/PyLoad/docker-compose.yml", + "main_image": "linuxserver/pyload-ng:0.5.0", + "matched_catalog_id": "pyload-ng", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "radarr", + "source_path": "Apps/Radarr/docker-compose.yml", + "main_image": "linuxserver/radarr:6.3.0", + "matched_catalog_id": "radarr", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "resilio-sync", + "source_path": "Apps/Resilio-sync/docker-compose.yml", + "main_image": "linuxserver/resilio-sync:3.1.2", + "matched_catalog_id": "resilio-sync", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "roonserver", + "source_path": "Apps/RoonServer/docker-compose.yml", + "main_image": "ghcr.io/roonlabs/roonserver:1.0.8", + "matched_catalog_id": "roonserver", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "sabnzbd", + "source_path": "Apps/Sabnzbd/docker-compose.yml", + "main_image": "linuxserver/sabnzbd:5.0.3", + "matched_catalog_id": "sabnzbd", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "smokeping", + "source_path": "Apps/Smokeping/docker-compose.yml", + "main_image": "linuxserver/smokeping:2.9.0", + "matched_catalog_id": "smokeping", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "sonarr", + "source_path": "Apps/Sonarr/docker-compose.yml", + "main_image": "linuxserver/sonarr:4.0.19", + "matched_catalog_id": "sonarr", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "stremio", + "source_path": "Apps/Stremio/docker-compose.yml", + "main_image": "tsaridas/stremio-docker:v1.3.4", + "matched_catalog_id": "stremio", + "reason": "replaced-by-curated-laboratory-profile" + }, + { + "source_id": "syncthing", + "source_path": "Apps/Syncthing/docker-compose.yml", + "main_image": "linuxserver/syncthing:1.29.7", + "matched_catalog_id": "syncthing", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "tautulli", + "source_path": "Apps/Tautulli/docker-compose.yml", + "main_image": "linuxserver/tautulli:2.17.1", + "matched_catalog_id": "tautulli", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "transmission", + "source_path": "Apps/Transmission/docker-compose.yml", + "main_image": "linuxserver/transmission:4.1.1", + "matched_catalog_id": "transmission", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + }, + { + "source_id": "unifi-network-application", + "source_path": "Apps/Unifi-Network-Application/docker-compose.yml", + "main_image": "lscr.io/linuxserver/unifi-network-application:latest", + "matched_catalog_id": "unifi-network-application", + "reason": "same-linuxserver-image-without-distinct-deployment-variant" + } + ], + "excluded_count": 6, + "excluded": [ + { + "source_id": "index-tts-nvidia", + "source_path": "Apps/Index-TTS_Nvidia/docker-compose.yml", + "reason": "same-image-hardware-profile-merged-into-index-tts" + }, + { + "source_id": "jellyfin", + "source_path": "Apps/Jellyfin/docker-compose.yml", + "reason": "same-image-hardware-profile-merged-into-linuxserver-jellyfin" + }, + { + "source_id": "jellyfin-nvidia", + "source_path": "Apps/Jellyfin_Nvidia/docker-compose.yml", + "reason": "same-image-hardware-profile-merged-into-linuxserver-jellyfin" + }, + { + "source_id": "ollama-nvidia", + "source_path": "Apps/Ollama_Nvidia/docker-compose.yml", + "reason": "same-image-hardware-profile-merged-into-ollama" + }, + { + "source_id": "plex", + "source_path": "Apps/Plex/docker-compose.yml", + "reason": "same-image-hardware-profile-merged-into-linuxserver-plex" + }, + { + "source_id": "plex-nvidia", + "source_path": "Apps/Plex_Nvidia/docker-compose.yml", + "reason": "same-image-hardware-profile-merged-into-linuxserver-plex" + } + ], + "skipped_count": 0, + "skipped": [] + }, + "curated_profiles": { + "included_count": 17 + } + } +} diff --git a/oci/catalog/overlays/2fauth.json b/oci/catalog/overlays/2fauth.json new file mode 100644 index 00000000..f381e993 --- /dev/null +++ b/oci/catalog/overlays/2fauth.json @@ -0,0 +1,51 @@ +{ + "container_contract": { + "environment": [ + { + "name": "APP_KEY", + "example": "", + "required": true, + "sensitive": true, + "source": "2fauth-env-example" + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "APP_KEY": { + "strategy": "token-hex", + "bytes": 16, + "prompt": true + } + }, + "volume_preparations": [ + { + "container_path": "/2fauth", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "volume_owner": { + "uid": 1000, + "gid": 1000 + }, + "tmpfs_mounts": [ + { + "id": "2fauth-nginx-run", + "container_path": "/run/nginx", + "default_size_mb": 8, + "minimum_size_mb": 1, + "prompt_size": false, + "mount_options": [ + "rw", + "nosuid", + "nodev", + "mode=0777" + ] + } + ] + } + } +} diff --git a/oci/catalog/overlays/adguardhome-sync.json b/oci/catalog/overlays/adguardhome-sync.json new file mode 100644 index 00000000..bd49eb37 --- /dev/null +++ b/oci/catalog/overlays/adguardhome-sync.json @@ -0,0 +1,132 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CONFIGFILE", + "example": "/config/adguardhome-sync.yaml", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "ORIGIN_URL", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Web address of the main AdGuard Home, whose settings are copied (e.g. http://192.168.1.2)", + "source": "adguardhome-sync-environment" + }, + { + "name": "ORIGIN_USERNAME", + "example": "", + "required": true, + "sensitive": false, + "prompt": "User of the main AdGuard Home", + "source": "adguardhome-sync-environment" + }, + { + "name": "ORIGIN_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the main AdGuard Home", + "source": "adguardhome-sync-environment" + }, + { + "name": "REPLICA1_URL", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Web address of the AdGuard Home that receives the settings (e.g. http://192.168.1.3)", + "source": "adguardhome-sync-environment" + }, + { + "name": "REPLICA1_USERNAME", + "example": "", + "required": true, + "sensitive": false, + "prompt": "User of the AdGuard Home that receives the settings", + "source": "adguardhome-sync-environment" + }, + { + "name": "REPLICA1_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the AdGuard Home that receives the settings", + "source": "adguardhome-sync-environment" + }, + { + "name": "API_USERNAME", + "example": "admin", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "adguardhome-sync-environment" + }, + { + "name": "API_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the Adguardhome Sync web interface", + "source": "adguardhome-sync-environment" + }, + { + "name": "HTTP_CLIENT_TIMEOUT", + "example": "10s", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "adguardhome-sync-environment" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "Adguardhome Sync web interface", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "API_USERNAME", + "password_environment": "API_PASSWORD", + "change_required": false, + "source": "adguardhome-sync-environment", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "API_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/airsonic-advanced.json b/oci/catalog/overlays/airsonic-advanced.json new file mode 100644 index 00000000..c1e815a5 --- /dev/null +++ b/oci/catalog/overlays/airsonic-advanced.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Airsonic Advanced web interface", + "type": "static-default", + "username": "admin", + "password": "admin", + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/alist-sync.json b/oci/catalog/overlays/alist-sync.json new file mode 100644 index 00000000..cf77c635 --- /dev/null +++ b/oci/catalog/overlays/alist-sync.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Alist Sync web interface", + "type": "static-default", + "username": "admin", + "password": "admin", + "change_required": true, + "source": "upstream-alist-sync-readme", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/alist.json b/oci/catalog/overlays/alist.json new file mode 100644 index 00000000..8f481fe2 --- /dev/null +++ b/oci/catalog/overlays/alist.json @@ -0,0 +1,19 @@ +{ + "first_run": { + "credentials": [ + { + "label": "AList initial login", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "alist-initial-admin-password-on-first-start", + "retrieval": { + "method": "container-console-pattern", + "pattern": "initial password is:\\s*(\\S+)", + "timeout_seconds": 180 + } + } + ] + } +} diff --git a/oci/catalog/overlays/altus.json b/oci/catalog/overlays/altus.json new file mode 100644 index 00000000..b38e50fc --- /dev/null +++ b/oci/catalog/overlays/altus.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-altus/master/Dockerfile", + "dockerfile_sha256": "c6e3ffa939d03cece6f29c8d30127ca78ec10c67840d714042f725c09b82f701", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/amule.json b/oci/catalog/overlays/amule.json new file mode 100644 index 00000000..a051e99b --- /dev/null +++ b/oci/catalog/overlays/amule.json @@ -0,0 +1,11 @@ +{ + "container_contract": { + "image": { + "reference": "ngosang/amule:develop", + "tag": "develop" + } + }, + "proxmox": { + "image_selection_note": "The develop tag carries the current aMule build, which is the one this catalog installs. The latest tag still points at 3.0.1-2 (21 August 2026); move back to latest once that release includes what develop carries today (develop-20260919-13a8c9f)." + } +} diff --git a/oci/catalog/overlays/anaconda3.json b/oci/catalog/overlays/anaconda3.json new file mode 100644 index 00000000..064329c6 --- /dev/null +++ b/oci/catalog/overlays/anaconda3.json @@ -0,0 +1,60 @@ +{ + "container_contract": { + "environment": [ + { + "name": "LANG", + "example": "C.UTF-8", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "LC_ALL", + "example": "C.UTF-8", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PATH", + "example": "/opt/conda/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "JUPYTER_TOKEN", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Access token of the Jupyter Lab web interface", + "source": "jupyter-server-documentation" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "Jupyter Lab (token only)", + "type": "configured-or-installer-generated", + "username": "Not required (token only)", + "password": null, + "password_environment": "JUPYTER_TOKEN", + "change_required": false, + "source": "jupyter-server-documentation", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "JUPYTER_TOKEN": { + "strategy": "token-hex", + "bytes": 16, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/archivebox.json b/oci/catalog/overlays/archivebox.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/archivebox.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/ardour.json b/oci/catalog/overlays/ardour.json new file mode 100644 index 00000000..cb6c9509 --- /dev/null +++ b/oci/catalog/overlays/ardour.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-ardour/master/Dockerfile", + "dockerfile_sha256": "9446e3b76e6b52a395a1641520f5306eae58f9b5f0d167ff3827f132af63e5b2", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/audacity.json b/oci/catalog/overlays/audacity.json new file mode 100644 index 00000000..9c0bacb7 --- /dev/null +++ b/oci/catalog/overlays/audacity.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-audacity/master/Dockerfile", + "dockerfile_sha256": "3feef0cf6583765091dae20ab79c21095c9a651e9d8b0f8edd05b3154c12584f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/babybuddy.json b/oci/catalog/overlays/babybuddy.json new file mode 100644 index 00000000..b4fe0dfd --- /dev/null +++ b/oci/catalog/overlays/babybuddy.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Baby Buddy web interface", + "type": "static-default", + "username": "admin", + "password": "admin", + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/blender.json b/oci/catalog/overlays/blender.json new file mode 100644 index 00000000..6071c2b7 --- /dev/null +++ b/oci/catalog/overlays/blender.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-blender/master/Dockerfile", + "dockerfile_sha256": "c8595b28e544bd2e573052b84a494cff4a2a17c201f10828fe1065b1453a2e68", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/boinc.json b/oci/catalog/overlays/boinc.json new file mode 100644 index 00000000..efc944a5 --- /dev/null +++ b/oci/catalog/overlays/boinc.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-boinc/master/Dockerfile", + "dockerfile_sha256": "dde889004f5e40e783d2aacc615dda55ae7fe0eac713423595bcb2fbd4b5c5bd", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/bookstack.json b/oci/catalog/overlays/bookstack.json new file mode 100644 index 00000000..1d842cb2 --- /dev/null +++ b/oci/catalog/overlays/bookstack.json @@ -0,0 +1,107 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_KEY", + "example": "", + "required": true, + "sensitive": true, + "source": "laravel-application-key" + }, + { + "name": "DB_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "3306", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USERNAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_DATABASE", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "QUEUE_CONNECTION", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "BookStack web interface", + "type": "static-default", + "username": "admin@admin.com", + "password": "password", + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "APP_KEY": { + "strategy": "token-hex", + "bytes": 16, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/calibre.json b/oci/catalog/overlays/calibre.json new file mode 100644 index 00000000..5617194c --- /dev/null +++ b/oci/catalog/overlays/calibre.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-calibre/master/Dockerfile", + "dockerfile_sha256": "796c5ec2f20a2f4d6e7a58b3f5a0f6b171276301aee42a0ca81e9610128b5730", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/calligra.json b/oci/catalog/overlays/calligra.json new file mode 100644 index 00000000..0ca4484e --- /dev/null +++ b/oci/catalog/overlays/calligra.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-calligra/master/Dockerfile", + "dockerfile_sha256": "01cf24c40c88e48b5329fcf6fe5d95e74312ea327a11cb7c3ca6dd1fb24c4cb9", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/chatbot-ui.json b/oci/catalog/overlays/chatbot-ui.json new file mode 100644 index 00000000..c331a72d --- /dev/null +++ b/oci/catalog/overlays/chatbot-ui.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Its image is no longer published in the registry" + } +} diff --git a/oci/catalog/overlays/clumoove.json b/oci/catalog/overlays/clumoove.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/clumoove.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/copyparty.json b/oci/catalog/overlays/copyparty.json new file mode 100644 index 00000000..d911c153 --- /dev/null +++ b/oci/catalog/overlays/copyparty.json @@ -0,0 +1,21 @@ +{ + "first_run": { + "credentials": [ + { + "label": "copyparty web interface", + "type": "static-default", + "username": "casaos", + "password": "casaos", + "change_required": true, + "source": "casaos-image-default-config", + "retrieval": null + } + ] + }, + "container_contract": { + "image": { + "reference": "icewhaletech/copyparty:1.20.13", + "tag": "1.20.13" + } + } +} diff --git a/oci/catalog/overlays/crafty.json b/oci/catalog/overlays/crafty.json new file mode 100644 index 00000000..a755e551 --- /dev/null +++ b/oci/catalog/overlays/crafty.json @@ -0,0 +1,60 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Crafty Controller default login", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "crafty-default-creds-file", + "retrieval": { + "method": "container-file", + "path": "/crafty/app/config/default-creds.txt", + "pattern": "\"password\"\\s*:\\s*\"([^\"]+)\"", + "timeout_seconds": 300 + } + } + ] + }, + "proxmox": { + "installer_profile": { + "volume_owner": { + "uid": 1000, + "gid": 0 + }, + "volume_preparations": [ + { + "container_path": "/crafty/backups", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/crafty/logs", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/crafty/servers", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/crafty/app/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/crafty/import", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ] + } + } +} diff --git a/oci/catalog/overlays/cura.json b/oci/catalog/overlays/cura.json new file mode 100644 index 00000000..7515df59 --- /dev/null +++ b/oci/catalog/overlays/cura.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-cura/master/Dockerfile", + "dockerfile_sha256": "70e5f3133d0847de7ff4cf47ab0ad2872c3fbec48bfcd6e523611180b87dcbd4", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/darktable.json b/oci/catalog/overlays/darktable.json new file mode 100644 index 00000000..1136afde --- /dev/null +++ b/oci/catalog/overlays/darktable.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-darktable/master/Dockerfile", + "dockerfile_sha256": "c43ed3fbf915e09c477b73fd47dec0f1172f74a3943b04dea05325252415b76f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/ddclient.json b/oci/catalog/overlays/ddclient.json new file mode 100644 index 00000000..efa59e56 --- /dev/null +++ b/oci/catalog/overlays/ddclient.json @@ -0,0 +1,9 @@ +{ + "proxmox": { + "installer_profile": { + "completion_notes": [ + "ddclient starts with the example configuration and updates nothing yet. Write your provider, login and domains in /config/ddclient.conf inside the container, then restart it." + ] + } + } +} diff --git a/oci/catalog/overlays/deepseek-ocr-nvidia.json b/oci/catalog/overlays/deepseek-ocr-nvidia.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/deepseek-ocr-nvidia.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/dify.json b/oci/catalog/overlays/dify.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/dify.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/diskover.json b/oci/catalog/overlays/diskover.json new file mode 100644 index 00000000..70a4f53c --- /dev/null +++ b/oci/catalog/overlays/diskover.json @@ -0,0 +1,14 @@ +{ + "proxmox": { + "stack_adaptation_notes": [ + "mem_limit is translated to the editable Proxmox memory default; ulimits is translated to native lxc.prlimit entries.", + "The upstream original_compose uses Elasticsearch 7.17.22. The normalized catalog candidate uses latest; tag availability and application compatibility must be reviewed before enabling installation.", + "The privileged elasticsearch-helper modifies host vm.max_map_count. No host sysctl is changed and this helper must not be discarded silently.", + "Elasticsearch persistence, healthchecks and host requirements still block the native stack." + ] + }, + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/doplarr.json b/oci/catalog/overlays/doplarr.json new file mode 100644 index 00000000..c70ab086 --- /dev/null +++ b/oci/catalog/overlays/doplarr.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Deprecated upstream: the image no longer receives updates" + } +} diff --git a/oci/catalog/overlays/doplarr_rs.json b/oci/catalog/overlays/doplarr_rs.json new file mode 100644 index 00000000..c45e0206 --- /dev/null +++ b/oci/catalog/overlays/doplarr_rs.json @@ -0,0 +1,10 @@ +{ + "proxmox": { + "installer_profile": { + "completion_notes": [ + "doplarr_rs starts from the example configuration and connects to nothing. Write the token of your Discord bot in discord_token in /config/config.toml inside the container.", + "Each /request command needs a backend: add a [[backends]] block in the same file with the url and api_key of your Sonarr, Radarr or Seerr instance, then restart the container." + ] + } + } +} diff --git a/oci/catalog/overlays/doublecommander.json b/oci/catalog/overlays/doublecommander.json new file mode 100644 index 00000000..60368c1f --- /dev/null +++ b/oci/catalog/overlays/doublecommander.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-doublecommander/master/Dockerfile", + "dockerfile_sha256": "6f679c5f1b33a4459369165c23f0fa12d3f97b8c9bf6336d46d805539a49a4e7", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/duckdns.json b/oci/catalog/overlays/duckdns.json new file mode 100644 index 00000000..e5db75ae --- /dev/null +++ b/oci/catalog/overlays/duckdns.json @@ -0,0 +1,65 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SUBDOMAINS", + "example": "", + "required": true, + "sensitive": false, + "prompt": "DuckDNS subdomain without .duckdns.org (comma separated for several)", + "source": "linuxserver-duckdns-readme" + }, + { + "name": "TOKEN", + "example": "", + "required": true, + "sensitive": true, + "prompt": "DuckDNS token from your account at duckdns.org", + "source": "linuxserver-duckdns-readme" + }, + { + "name": "UPDATE_IP", + "example": "ipv4", + "required": false, + "sensitive": false, + "prompt": "Addresses to update: ipv4, ipv6 or both (uses an external service)", + "source": "linuxserver-compose" + }, + { + "name": "LOG_FILE", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ] + }, + "proxmox": { + "installer_profile": { + "completion_notes": [ + "DuckDNS updates the subdomain every 5 minutes. Without UPDATE_IP, DuckDNS itself detects the public IPv4 address of the request." + ] + } + } +} diff --git a/oci/catalog/overlays/duplicati.json b/oci/catalog/overlays/duplicati.json new file mode 100644 index 00000000..a4c5ea28 --- /dev/null +++ b/oci/catalog/overlays/duplicati.json @@ -0,0 +1,79 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Duplicati web interface (password only)", + "type": "configured-or-installer-generated", + "username": "Not required (password only)", + "password": null, + "password_environment": "DUPLICATI__WEBSERVICE_PASSWORD", + "change_required": false, + "source": "linuxserver-readme-parameters", + "retrieval": null + } + ] + }, + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SETTINGS_ENCRYPTION_KEY", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "CLI_ARGS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DUPLICATI__WEBSERVICE_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the Duplicati web interface", + "source": "linuxserver-compose" + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "SETTINGS_ENCRYPTION_KEY": { + "strategy": "token-hex", + "bytes": 16, + "prompt": false + }, + "DUPLICATI__WEBSERVICE_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/etherpad.json b/oci/catalog/overlays/etherpad.json new file mode 100644 index 00000000..bc8c0d6a --- /dev/null +++ b/oci/catalog/overlays/etherpad.json @@ -0,0 +1,131 @@ +{ + "container_contract": { + "environment": [ + { + "name": "TITLE", + "example": "Etherpad", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEFAULT_PAD_TEXT", + "example": "", + "required": false, + "sensitive": false, + "source": "docker-compose", + "prompt": "Text that new pads start with (empty = the text of the image)" + }, + { + "name": "ADMIN_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the Etherpad admin user", + "source": "etherpad-docker-documentation" + }, + { + "name": "AUTHENTICATION_METHOD", + "example": "apikey", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_TYPE", + "example": "dirty", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DB_FILENAME", + "example": "/opt/etherpad-lite/var/dirty.db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TRUST_PROXY", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SHOW_SETTINGS_IN_ADMIN_PAGE", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REQUIRE_AUTHENTICATION", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REQUIRE_AUTHORIZATION", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ] + }, + "first_run": { + "endpoints": [ + { + "label": "Web UI", + "scheme": "http", + "port": 9001, + "path": "/", + "source": "compose-metadata" + }, + { + "label": "Admin page", + "scheme": "http", + "port": 9001, + "path": "/admin", + "source": "etherpad-docker-documentation" + } + ], + "credentials": [ + { + "label": "Etherpad admin page", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "password_environment": "ADMIN_PASSWORD", + "change_required": false, + "source": "etherpad-docker-documentation", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "ADMIN_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + }, + "volume_owner": { + "uid": 5001, + "gid": 0 + }, + "volume_preparations": [ + { + "container_path": "/opt/etherpad-lite/var", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ] + } + } +} diff --git a/oci/catalog/overlays/ferdium.json b/oci/catalog/overlays/ferdium.json new file mode 100644 index 00000000..f6d3bf5c --- /dev/null +++ b/oci/catalog/overlays/ferdium.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-ferdium/master/Dockerfile", + "dockerfile_sha256": "c47d21332c5d5516c76e7593905690c85c42a5d58aabfe0d0e099161b03b4755", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/filezilla.json b/oci/catalog/overlays/filezilla.json new file mode 100644 index 00000000..7d8b15b0 --- /dev/null +++ b/oci/catalog/overlays/filezilla.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-filezilla/master/Dockerfile", + "dockerfile_sha256": "57086f8b98f9470374b0c2a5144e4fe931db0d35efa9c81dc65b2066d5cc3982", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/flexget.json b/oci/catalog/overlays/flexget.json new file mode 100644 index 00000000..add488b7 --- /dev/null +++ b/oci/catalog/overlays/flexget.json @@ -0,0 +1,81 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FG_LOG_LEVEL", + "example": "info", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FG_LOG_FILE", + "example": "/config/flexget.log", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FG_CONFIG_FILE", + "example": "/config/.flexget/config.yml", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "FG_WEBUI_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the FlexGet web interface", + "source": "flexget-readme" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "FlexGet web interface", + "type": "configured-or-installer-generated", + "username": "flexget", + "password": null, + "password_environment": "FG_WEBUI_PASSWORD", + "change_required": false, + "source": "flexget-webserver-default-user", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "FG_WEBUI_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/flowise.json b/oci/catalog/overlays/flowise.json new file mode 100644 index 00000000..41cfe873 --- /dev/null +++ b/oci/catalog/overlays/flowise.json @@ -0,0 +1,73 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PORT", + "example": "3025", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DATABASE_PATH", + "example": "/root/.flowise", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "APIKEY_PATH", + "example": "/root/.flowise", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "flowise-documentation" + }, + { + "name": "SECRETKEY_PATH", + "example": "/root/.flowise", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "flowise-documentation" + }, + { + "name": "LOG_PATH", + "example": "/root/.flowise/logs", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "BLOB_STORAGE_PATH", + "example": "/root/.flowise/storage", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "FLOWISE_USERNAME", + "example": "flowise", + "required": false, + "sensitive": false, + "prompt": "User name of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)", + "source": "flowise-documentation" + }, + { + "name": "FLOWISE_PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "prompt": "Password of the deprecated Flowise application login (only read by Flowise versions before 3.0.1)", + "source": "flowise-documentation" + } + ] + }, + "proxmox": { + "installer_profile": { + "completion_notes": [ + "Flowise 3.0.1 and later create the administrator account from the web interface, the first time it is opened." + ] + } + } +} diff --git a/oci/catalog/overlays/freecad.json b/oci/catalog/overlays/freecad.json new file mode 100644 index 00000000..066cd755 --- /dev/null +++ b/oci/catalog/overlays/freecad.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-freecad/master/Dockerfile", + "dockerfile_sha256": "3e76dc197f77f9256bf7af2d507ff11e0ccedeb1f65a79ab05ee8ce9d3e42421", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/gimp.json b/oci/catalog/overlays/gimp.json new file mode 100644 index 00000000..670201f4 --- /dev/null +++ b/oci/catalog/overlays/gimp.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-gimp/master/Dockerfile", + "dockerfile_sha256": "586e73ccdd7e0e9856f9253cf6d44036ce5bcbfbb91c43fa122b0f232858f51f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/github-desktop.json b/oci/catalog/overlays/github-desktop.json new file mode 100644 index 00000000..65ff52bd --- /dev/null +++ b/oci/catalog/overlays/github-desktop.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-github-desktop/master/Dockerfile", + "dockerfile_sha256": "3bae15eb6f81e3dac69859063580744abe6e7df149f549ea98901cbe3f78b898", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/gitqlient.json b/oci/catalog/overlays/gitqlient.json new file mode 100644 index 00000000..0119bbcc --- /dev/null +++ b/oci/catalog/overlays/gitqlient.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-gitqlient/master/Dockerfile", + "dockerfile_sha256": "6b6e54e80e3fc8da86b02e68c7bc7a3da28b1a2f6dcbae581f48340b1c95ec0b", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/glances.json b/oci/catalog/overlays/glances.json new file mode 100644 index 00000000..b711bb9e --- /dev/null +++ b/oci/catalog/overlays/glances.json @@ -0,0 +1,99 @@ +{ + "status": "generated-unvalidated", + "catalog_ui": { + "tips": [ + "Optional host mode: shares the Proxmox IP and metrics. If declined, it installs unprivileged, with its own IP and metrics for the LXC ONLY.", + "Privileged access to the host PID/network and unconfined AppArmor: requires confirmation. Trusted networks only; the host firewall is the one that applies.", + "Neither docker.sock nor the host root directory is mounted. Docker inventory, SMART and capacity of all filesystems are not guaranteed.", + "LXCFS is skipped only in the monitor CT so that the limited container RAM/CPU is not shown.", + "Uses lxc.include with /etc/pve/lxc/proxmenux-host-monitor; this file is not included in vzdump and must be kept when restoring on another host.", + "The CPU limit is applied as cpulimit, without hiding processors through affinity." + ] + }, + "container_contract": { + "environment": [ + { + "name": "GLANCES_OPT", + "example": "-w", + "required": true, + "sensitive": false, + "source": "docker-compose", + "prompt_user": false + } + ], + "volumes": [] + }, + "proxmox": { + "defaults": { + "unprivileged": false, + "ostype": "unmanaged", + "memory_mb": 512, + "features": [] + }, + "security_profile": { + "requires_privileged_lxc": true, + "requires_host_pid_namespace": true, + "optional_privileged_lxc": false, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "confirmation_required": true, + "risk_level": "high", + "warning": "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks." + }, + "installer_profile": { + "host_monitor": "glances", + "host_monitor_optional": true, + "host_monitor_mounts": [ + { + "source": "/etc/os-release", + "target": "/etc/os-release" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 61208, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "verify_tls": false + }, + "security": { + "required_capabilities": [ + "SYS_PTRACE" + ], + "options": { + "apparmor_profile": "unconfined" + } + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "untranslated_blockers": [] + }, + "validation": { + "service_health": "passed-observed-2026-09-14", + "restart_persistence": "passed-observed-2026-09-14", + "backup_restore": "pending", + "update_preserves_data": "pending", + "latest_runtime_observation": { + "date": "2026-09-14", + "vmid": 101, + "architecture": "amd64", + "proxmox": "9.2.18", + "image_digest": "sha256:7bdd499825a9044ad495714421ea2049b73696d64f1fe6697e1ae07bfe164e2c", + "image_version": "v4.5.6", + "http_port": 61208, + "host_pid_namespace": true, + "host_network_namespace": true, + "host_memory_bytes": 16110522368, + "shutdown_start_passed": true, + "companion_include": "/etc/pve/lxc/proxmenux-host-monitor", + "companion_included_in_vzdump": false, + "rolling_tag_validation": "only-observed-digest", + "host_cpu_count": 16, + "host_process_count_observed": 559 + } + } +} diff --git a/oci/catalog/overlays/grafana.json b/oci/catalog/overlays/grafana.json new file mode 100644 index 00000000..1e9f3a0f --- /dev/null +++ b/oci/catalog/overlays/grafana.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Grafana web interface", + "type": "static-default", + "username": "admin", + "password": "admin", + "change_required": true, + "source": "upstream-grafana-docs", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/grocy.json b/oci/catalog/overlays/grocy.json new file mode 100644 index 00000000..00ce39f2 --- /dev/null +++ b/oci/catalog/overlays/grocy.json @@ -0,0 +1,14 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Grocy (new installation; restored data keeps its credentials)", + "type": "static-default", + "username": "admin", + "password": "admin", + "change_required": true, + "source": "https://docs.linuxserver.io/images/docker-grocy/" + } + ] + } +} diff --git a/oci/catalog/overlays/handbrake-jlesage.json b/oci/catalog/overlays/handbrake-jlesage.json new file mode 100644 index 00000000..1fa1266c --- /dev/null +++ b/oci/catalog/overlays/handbrake-jlesage.json @@ -0,0 +1,99 @@ +{ + "catalog_ui": { + "tips": [ + "Intel/AMD acceleration is enabled by passing /dev/dri to the LXC; it does not require making the LXC privileged.", + "The privileged request from the imported Compose is discarded because it is not part of the official jlesage/handbrake requirements." + ] + }, + "container_contract": { + "environment": [ + { + "name": "USER_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "jlesage-documentation" + }, + { + "name": "GROUP_ID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "jlesage-documentation" + }, + { + "name": "TZ", + "example": "Europe/Madrid", + "required": true, + "sensitive": false, + "source": "jlesage-documentation" + } + ] + }, + "proxmox": { + "security_profile": { + "requires_privileged_lxc": false, + "source_requests_privileged_lxc": true, + "optional_privileged_lxc": false, + "requires_host_pid_namespace": false, + "requires_relaxed_confinement": false, + "risk_level": "normal", + "confirmation_required": false, + "warning": "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged." + }, + "installer_profile": { + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "enable_prompt": "Enable Intel/AMD VA-API video acceleration", + "enabled_default": false, + "required_by_compose": false, + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "source_mapping": "/dev/dri/renderD128:/dev/dri/renderD128" + } + ], + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/storage", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/watch", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + }, + { + "container_path": "/output", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 5800, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + } + } +} diff --git a/oci/catalog/overlays/handbrake.json b/oci/catalog/overlays/handbrake.json new file mode 100644 index 00000000..92e8526f --- /dev/null +++ b/oci/catalog/overlays/handbrake.json @@ -0,0 +1,29 @@ +{ + "catalog_ui": { + "tips": [ + "The managed /config volume is prepared with the configured PUID/PGID before LinuxServer starts.", + "The installer verifies the HTTPS WebUI on port 3001 before reporting success." + ] + }, + "proxmox": { + "installer_profile": { + "volume_preparations": [ + { + "container_path": "/config", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "startup_healthcheck": { + "scheme": "https", + "port": 3001, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + } + } +} diff --git a/oci/catalog/overlays/hedgedoc.json b/oci/catalog/overlays/hedgedoc.json new file mode 100644 index 00000000..6ccee440 --- /dev/null +++ b/oci/catalog/overlays/hedgedoc.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Needs MariaDB or PostgreSQL in its own container; planned as a multi-container application" + } +} diff --git a/oci/catalog/overlays/hermes.json b/oci/catalog/overlays/hermes.json new file mode 100644 index 00000000..9c65599b --- /dev/null +++ b/oci/catalog/overlays/hermes.json @@ -0,0 +1,83 @@ +{ + "container_contract": { + "environment": [ + { + "name": "HERMES_DASHBOARD", + "example": "1", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "HERMES_DASHBOARD_BASIC_AUTH_USERNAME", + "example": "admin", + "required": true, + "sensitive": false, + "source": "official-image-environment" + }, + { + "name": "HERMES_DASHBOARD_BASIC_AUTH_PASSWORD", + "example": "${GENERATED_HERMES_DASHBOARD_PASSWORD}", + "required": true, + "sensitive": true, + "source": "official-image-environment" + }, + { + "name": "HERMES_DASHBOARD_BASIC_AUTH_SECRET", + "example": "${GENERATED_HERMES_DASHBOARD_SESSION_SECRET}", + "required": true, + "sensitive": true, + "source": "official-image-environment" + } + ] + }, + "first_run": { + "endpoints": [ + { + "label": "Hermes WebUI", + "scheme": "http", + "port": 9119, + "path": "/", + "source": "official-image-dashboard" + } + ], + "credentials": [ + { + "label": "Hermes WebUI", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "HERMES_DASHBOARD_BASIC_AUTH_USERNAME", + "password_environment": "HERMES_DASHBOARD_BASIC_AUTH_PASSWORD", + "change_required": false, + "source": "official-image-environment", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "HERMES_DASHBOARD_BASIC_AUTH_PASSWORD": { + "strategy": "token-hex", + "bytes": 16, + "prompt": true + }, + "HERMES_DASHBOARD_BASIC_AUTH_SECRET": { + "strategy": "token-hex", + "bytes": 32, + "prompt": false + } + }, + "startup_healthcheck": { + "scheme": "http", + "port": 9119, + "path": "/", + "verify_tls": true, + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "stability_seconds": 4 + } + } + } +} diff --git a/oci/catalog/overlays/homebridge.json b/oci/catalog/overlays/homebridge.json new file mode 100644 index 00000000..dcdbdd45 --- /dev/null +++ b/oci/catalog/overlays/homebridge.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Homebridge UI", + "type": "static-default", + "username": "admin", + "password": "admin", + "change_required": true, + "source": "upstream-homebridge-ui-readme", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/index-tts.json b/oci/catalog/overlays/index-tts.json new file mode 100644 index 00000000..35771f89 --- /dev/null +++ b/oci/catalog/overlays/index-tts.json @@ -0,0 +1,45 @@ +{ + "proxmox": { + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Execution engine for Index-TTS", + "default": "cpu", + "profiles": [ + { + "id": "cpu", + "label": "CPU", + "device_requests": [] + }, + { + "id": "nvidia", + "label": "NVIDIA (CUDA)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ] + } + ] + } + } + }, + "container_contract": { + "image": { + "reference": "icewhaletech/index-tts:2.0", + "tag": "2.0" + } + } +} diff --git a/oci/catalog/overlays/inkscape.json b/oci/catalog/overlays/inkscape.json new file mode 100644 index 00000000..984371ad --- /dev/null +++ b/oci/catalog/overlays/inkscape.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-inkscape/master/Dockerfile", + "dockerfile_sha256": "b7cee51c2f2cbc7a547b603b225dbed48b39154d3521f500757d6ae02d00992e", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/jellyfin.json b/oci/catalog/overlays/jellyfin.json new file mode 100644 index 00000000..e9bd06cd --- /dev/null +++ b/oci/catalog/overlays/jellyfin.json @@ -0,0 +1,317 @@ +{ + "catalog_ui": { + "title": { + "en_US": "Jellyfin" + }, + "tagline": { + "en_US": "LinuxServer Jellyfin with optional GPU passthrough" + }, + "tips": [ + "VA-API and OpenCL tone mapping are separate capabilities. The tested LinuxServer image provides AMD VA-API; AMD OpenCL required the official jellyfin-amd mod.", + "Choose AMD + OpenCL or Intel + OpenCL to install the corresponding official LinuxServer mod at startup. These are options for the same image, not additional catalog variants.", + "ProxMenux passes explicit device paths through ATTACHED_DEVICES_PERMS so the native LinuxServer init grants the service user access. No privileged LXC or mode 0777 is needed.", + "Optional Jellyfin settings are persisted in /config/encoding.xml. AMD OpenCL and VA-API were tested on Lucienne; Intel OpenCL remains untested in this laboratory. Dolby Vision support depends on the source profile and FFmpeg/GPU capabilities." + ] + }, + "proxmox": { + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Jellyfin", + "default": "none", + "profiles": [ + { + "id": "none", + "label": "No acceleration (CPU)", + "device_requests": [] + }, + { + "id": "vaapi", + "label": "Intel/AMD VA-API (no OpenCL mod)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "environment": [ + { + "name": "LIBVA_DRIVER_NAME", + "prompt": "VA-API driver", + "choices": [ + "auto", + "radeonsi", + "iHD", + "i965" + ], + "default": "auto", + "omit_values": [ + "auto" + ] + } + ] + } + ], + "environment_from_devices": { + "ATTACHED_DEVICES_PERMS": [ + "vaapi-render" + ] + } + }, + { + "id": "amd-opencl", + "label": "AMD VA-API + OpenCL (official mod)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x1002", + "0x1022" + ] + }, + { + "id": "amd-kfd", + "kind": "character-device", + "purpose": "amd-opencl", + "path_prompt": "AMD KFD device", + "host_path_default": "/dev/kfd", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid" + } + ], + "environment_from_devices": { + "ATTACHED_DEVICES_PERMS": [ + "vaapi-render", + "amd-kfd" + ] + }, + "environment": [ + { + "name": "DOCKER_MODS", + "value": "linuxserver/mods:jellyfin-amd" + } + ], + "post_start_configurations": [ + { + "id": "jellyfin-amd-opencl", + "type": "jellyfin-encoding-xml", + "enable_prompt": "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin", + "enabled_default": true, + "required": true, + "timeout_seconds": 120, + "candidate_paths": [ + "/config/encoding.xml" + ], + "settings": { + "HardwareAccelerationType": "vaapi", + "VaapiDevice": { + "device_path_from": "vaapi-render" + }, + "EnableHardwareEncoding": "true", + "EnableTonemapping": "true", + "EnableVppTonemapping": "false" + } + } + ], + "architectures": [ + "amd64" + ] + }, + { + "id": "intel-opencl", + "label": "Intel VA-API + OpenCL (official mod)", + "device_requests": [ + { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "path_prompt": "GPU render device", + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": false, + "gid_strategy": "host-device-gid", + "drm_vendor_ids": [ + "0x8086" + ] + } + ], + "environment_from_devices": { + "ATTACHED_DEVICES_PERMS": [ + "vaapi-render" + ] + }, + "environment": [ + { + "name": "DOCKER_MODS", + "value": "linuxserver/mods:jellyfin-opencl-intel" + } + ], + "post_start_configurations": [ + { + "id": "jellyfin-intel-opencl", + "type": "jellyfin-encoding-xml", + "enable_prompt": "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin", + "enabled_default": true, + "required": true, + "timeout_seconds": 120, + "candidate_paths": [ + "/config/encoding.xml" + ], + "settings": { + "HardwareAccelerationType": "vaapi", + "VaapiDevice": { + "device_path_from": "vaapi-render" + }, + "EnableHardwareEncoding": "true", + "EnableTonemapping": "true", + "EnableVppTonemapping": "false" + } + } + ], + "architectures": [ + "amd64" + ] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [ + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "device_selection": "all-requested-by-compose" + } + ], + "environment": [ + { + "name": "NVIDIA_VISIBLE_DEVICES", + "value": "all" + } + ] + } + ] + }, + "startup_healthcheck": { + "scheme": "http", + "port": 8096, + "path": "/System/Info/Public", + "timeout_seconds": 600, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + }, + "application_options": { + "hdr10_dolby_vision_tone_mapping": { + "show_in_catalog": true, + "selectable": true, + "provided_by_image": false, + "configuration": "Optional official LinuxServer GPU mod and persistent Jellyfin encoding settings", + "scope": "OpenCL tone mapping; not a guarantee for every HDR/Dolby Vision source" + } + }, + "defaults": { + "cores": 2, + "memory_mb": 2048 + }, + "gpu_lab_references": { + "amd_mod": "https://github.com/linuxserver/docker-mods/tree/jellyfin-amd", + "intel_mod": "https://github.com/linuxserver/docker-mods/tree/jellyfin-opencl-intel" + } + }, + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + } + ], + "volumes": [ + { + "id": "volume-0", + "container_path": "/config", + "compose_source_example": "/path/to/jellyfin/library", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 16 + } + }, + { + "id": "volume-1", + "container_path": "/data/tvshows", + "compose_source_example": "/path/to/tvseries", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/data/movies", + "compose_source_example": "/path/to/movies", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ] + } +} diff --git a/oci/catalog/overlays/jenkins.json b/oci/catalog/overlays/jenkins.json new file mode 100644 index 00000000..7f433641 --- /dev/null +++ b/oci/catalog/overlays/jenkins.json @@ -0,0 +1,19 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Jenkins unlock", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "jenkins-initial-admin-password", + "retrieval": { + "method": "container-file", + "path": "/var/jenkins_home/secrets/initialAdminPassword", + "timeout_seconds": 300 + } + } + ] + } +} diff --git a/oci/catalog/overlays/kali-linux.json b/oci/catalog/overlays/kali-linux.json new file mode 100644 index 00000000..9011f653 --- /dev/null +++ b/oci/catalog/overlays/kali-linux.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:kali", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-kali-linux/master/Dockerfile", + "dockerfile_sha256": "cd5947fea72f349b12b60aceb0c9c32629954f5e14ab3003f47d153160be9bc9", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/karakeep.json b/oci/catalog/overlays/karakeep.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/karakeep.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/kdenlive.json b/oci/catalog/overlays/kdenlive.json new file mode 100644 index 00000000..5131363c --- /dev/null +++ b/oci/catalog/overlays/kdenlive.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-kdenlive/master/Dockerfile", + "dockerfile_sha256": "cb69b193c30a69f2f5f2f3d667bae33d41beacb23c60847e69ce71265c29cb0c", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/keepassxc.json b/oci/catalog/overlays/keepassxc.json new file mode 100644 index 00000000..ff078d56 --- /dev/null +++ b/oci/catalog/overlays/keepassxc.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-keepassxc/master/Dockerfile", + "dockerfile_sha256": "a850d78ae65c5f6073cd972500b973c9fb7d78e7cea1b88a29add4cbe9c5ef08", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/kicad.json b/oci/catalog/overlays/kicad.json new file mode 100644 index 00000000..c7ce5df7 --- /dev/null +++ b/oci/catalog/overlays/kicad.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-kicad/master/Dockerfile", + "dockerfile_sha256": "663d142e3c9be4c5e244738aff0929a806a118330f5b78c8ab4570cb9116dd21", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/kimai.json b/oci/catalog/overlays/kimai.json new file mode 100644 index 00000000..33dbb4e1 --- /dev/null +++ b/oci/catalog/overlays/kimai.json @@ -0,0 +1,30 @@ +{ + "proxmox": { + "stack_completion_notes": [ + "Kimai has no default account. Enter the container with: pct enter {main_vmid}", + "Inside the LXC, create the administrator: console kimai:user:create YOUR_USERNAME YOUR_EMAIL ROLE_SUPER_ADMIN" + ], + "stack_environment_overrides": { + "kimai": { + "APP_SECRET": "${GENERATED_APP_SECRET}", + "DATABASE_URL": "mysql://kimai:${GENERATED_KIMAI_DB_PASSWORD}@mariadb:3306/kimai?charset=utf8mb4", + "TRUSTED_HOSTS": "^(?:[0-9]{1,3}[.]){3}[0-9]{1,3}$|^localhost$" + }, + "mariadb": { + "MYSQL_ROOT_PASSWORD": "${GENERATED_MARIADB_ROOT_PASSWORD}", + "MYSQL_DATABASE": "kimai", + "MYSQL_USER": "kimai", + "MYSQL_PASSWORD": "${GENERATED_KIMAI_DB_PASSWORD}" + } + }, + "stack_adaptation_notes": [ + "Both images remain LinuxServer images, including lscr.io/linuxserver/mariadb:latest; no database image substitution.", + "MariaDB persists /config and readiness requires an authenticated SELECT 1 as the application user.", + "The DATABASE_URL uses the shared generated database password and automatic server version detection.", + "Initial TRUSTED_HOSTS permits IPv4 hostnames and localhost. Set the intended domain when configuring a reverse proxy.", + "Create the first administrator using the upstream console kimai:user:create command inside the Kimai LXC; no default account is fabricated.", + "Installation, migrations, administrator creation and persistence remain unvalidated in a real OCI LXC." + ], + "stack_references": ["https://docs.linuxserver.io/images/docker-kimai/", "https://docs.linuxserver.io/images/docker-mariadb/"] + } +} diff --git a/oci/catalog/overlays/kometa.json b/oci/catalog/overlays/kometa.json new file mode 100644 index 00000000..4acc2184 --- /dev/null +++ b/oci/catalog/overlays/kometa.json @@ -0,0 +1,9 @@ +{ + "proxmox": { + "installer_profile": { + "completion_notes": [ + "Kometa reads its configuration from /config/config.yml and the container only ships /config/config.yml.template. Copy the template to config.yml, fill in the required Plex and TMDb connections, then restart the container." + ] + } + } +} diff --git a/oci/catalog/overlays/krita.json b/oci/catalog/overlays/krita.json new file mode 100644 index 00000000..5c6b1c51 --- /dev/null +++ b/oci/catalog/overlays/krita.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-krita/master/Dockerfile", + "dockerfile_sha256": "fc2b53881d92760de6ae19281175cfc73966986ce47ec673e2ef275827aa83d1", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/librechat.json b/oci/catalog/overlays/librechat.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/librechat.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/libredb-studio.json b/oci/catalog/overlays/libredb-studio.json new file mode 100644 index 00000000..6574e7e3 --- /dev/null +++ b/oci/catalog/overlays/libredb-studio.json @@ -0,0 +1,81 @@ +{ + "container_contract": { + "environment": [ + { + "name": "ADMIN_EMAIL", + "example": "admin@libredb.org", + "required": true, + "sensitive": false, + "prompt": "Email address of the LibreDB Studio administrator", + "source": "libredb-studio-documentation" + }, + { + "name": "ADMIN_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the LibreDB Studio administrator", + "source": "libredb-studio-documentation" + }, + { + "name": "JWT_SECRET", + "example": "", + "required": true, + "sensitive": true, + "source": "libredb-studio-documentation" + }, + { + "name": "STORAGE_PROVIDER", + "example": "sqlite", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "STORAGE_SQLITE_PATH", + "example": "/app/data/libredb-storage.db", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "AUTH_COOKIE_SECURE", + "example": "false", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "LibreDB Studio", + "type": "configured-or-installer-generated", + "username": "admin@libredb.org", + "password": null, + "username_environment": "ADMIN_EMAIL", + "password_environment": "ADMIN_PASSWORD", + "change_required": false, + "source": "libredb-studio-documentation", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "ADMIN_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + }, + "JWT_SECRET": { + "strategy": "token-hex", + "bytes": 32, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/libreoffice.json b/oci/catalog/overlays/libreoffice.json new file mode 100644 index 00000000..267b3da4 --- /dev/null +++ b/oci/catalog/overlays/libreoffice.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-libreoffice/master/Dockerfile", + "dockerfile_sha256": "95ca149b38966fc1819724c0e16f35b7c84faf7ebfe57694ec37927818f282b9", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/librewolf.json b/oci/catalog/overlays/librewolf.json new file mode 100644 index 00000000..0db8d0a8 --- /dev/null +++ b/oci/catalog/overlays/librewolf.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-librewolf/master/Dockerfile", + "dockerfile_sha256": "85e8f7956eb72f49b520008050bafb77fcd6c3983cdd5cae62aee0c9a6120e33", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/limnoria.json b/oci/catalog/overlays/limnoria.json new file mode 100644 index 00000000..d66444b7 --- /dev/null +++ b/oci/catalog/overlays/limnoria.json @@ -0,0 +1,10 @@ +{ + "proxmox": { + "installer_profile": { + "completion_notes": [ + "Limnoria joins no IRC network until its configuration file exists. Create it with the setup wizard from the Proxmox host: pct exec -- bash -c 'cd /config && limnoria-wizard'", + "The wizard writes a .conf file in /config. Restart the container afterwards so the bot starts with that configuration." + ] + } + } +} diff --git a/oci/catalog/overlays/linkwarden.json b/oci/catalog/overlays/linkwarden.json new file mode 100644 index 00000000..b03d9fac --- /dev/null +++ b/oci/catalog/overlays/linkwarden.json @@ -0,0 +1,14 @@ +{ + "proxmox": { + "stack_environment_overrides": { + "linkwarden": {"NEXT_PUBLIC_CREDENTIALS_ENABLED": "true", "STORAGE_FOLDER": "/data/data"} + }, + "stack_adaptation_notes": [ + "Credential login is a boolean option, never a generated secret.", + "STORAGE_FOLDER points to the persisted /data/data mount.", + "The same generated MEILI_MASTER_KEY is used by Linkwarden and Meilisearch.", + "Latest dependency tags remain selected; application compatibility must be checked by an actual installation." + ], + "stack_references": ["https://github.com/linkwarden/linkwarden/blob/main/docker-compose.yml", "https://docs.linkwarden.app/self-hosting/environment-variables", "https://www.meilisearch.com/docs/reference/api/health/get-health"] + } +} diff --git a/oci/catalog/overlays/llamacpp.json b/oci/catalog/overlays/llamacpp.json new file mode 100644 index 00000000..fdcc8861 --- /dev/null +++ b/oci/catalog/overlays/llamacpp.json @@ -0,0 +1,8 @@ +{ + "container_contract": { + "image": { + "reference": "ghcr.io/ggml-org/llama.cpp:server", + "tag": "server" + } + } +} diff --git a/oci/catalog/overlays/lollypop.json b/oci/catalog/overlays/lollypop.json new file mode 100644 index 00000000..ef33f90f --- /dev/null +++ b/oci/catalog/overlays/lollypop.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-lollypop/master/Dockerfile", + "dockerfile_sha256": "e5e217c30e00bbaeec0bd5f39108ad500fe39cb351513d65c7826604494e6b7f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/lucky.json b/oci/catalog/overlays/lucky.json new file mode 100644 index 00000000..e486c3c6 --- /dev/null +++ b/oci/catalog/overlays/lucky.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Lucky web interface", + "type": "static-default", + "username": "666", + "password": "666", + "change_required": true, + "source": "upstream-lucky-readme", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/mastodon.json b/oci/catalog/overlays/mastodon.json new file mode 100644 index 00000000..2eddd1fb --- /dev/null +++ b/oci/catalog/overlays/mastodon.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Needs PostgreSQL and Redis in their own containers; planned as a multi-container application" + } +} diff --git a/oci/catalog/overlays/maybe.json b/oci/catalog/overlays/maybe.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/maybe.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/mediaelch.json b/oci/catalog/overlays/mediaelch.json new file mode 100644 index 00000000..7dae83ee --- /dev/null +++ b/oci/catalog/overlays/mediaelch.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-mediaelch/master/Dockerfile", + "dockerfile_sha256": "4291ab245dee3d06037908bc3e51b079c352756901809177244185e41e80dfe0", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/memos.json b/oci/catalog/overlays/memos.json new file mode 100644 index 00000000..e6cdda52 --- /dev/null +++ b/oci/catalog/overlays/memos.json @@ -0,0 +1,8 @@ +{ + "container_contract": { + "image": { + "reference": "neosmemo/memos:stable", + "tag": "stable" + } + } +} diff --git a/oci/catalog/overlays/mineos-node.json b/oci/catalog/overlays/mineos-node.json new file mode 100644 index 00000000..80854ce8 --- /dev/null +++ b/oci/catalog/overlays/mineos-node.json @@ -0,0 +1,68 @@ +{ + "container_contract": { + "environment": [ + { + "name": "USE_HTTPS", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "SERVER_PORT", + "example": "8443", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "USER_NAME", + "example": "mc", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "USER_UID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "USER_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the MineOS web interface user", + "source": "mineos-node-entrypoint" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "MineOS web interface", + "type": "configured-or-installer-generated", + "username": "mc", + "password": null, + "username_environment": "USER_NAME", + "password_environment": "USER_PASSWORD", + "change_required": false, + "source": "mineos-node-entrypoint", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "USER_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/mongodb4.json b/oci/catalog/overlays/mongodb4.json new file mode 100644 index 00000000..18a235cb --- /dev/null +++ b/oci/catalog/overlays/mongodb4.json @@ -0,0 +1,19 @@ +{ + "container_contract": { + "image": { + "reference": "mongo:4", + "tag": "4" + } + }, + "catalog_ui": { + "tagline": { + "en_US": "MongoDB 4.4, the last series that runs on a CPU without AVX." + }, + "description": { + "en_US": "The 4.4 series of MongoDB, the document-oriented NoSQL database. MongoDB 5 and later require a CPU with AVX support and will not start without it, which leaves the low-power processors common in home servers unable to run them at all. This entry exists for those machines: it is pinned to the 4.4 series rather than following the latest release. The series reached its end of life in February 2024 and receives no further fixes, so where the processor does support AVX, the MongoDB entry installs a maintained release instead." + } + }, + "proxmox": { + "image_selection_note": "The upstream recipe is named mongodb4 and points at mongo:latest, so the entry promised a series it did not install. It is pinned to mongo:4 here, which is what the name says and the only series a processor without AVX can run." + } +} diff --git a/oci/catalog/overlays/monica-official.json b/oci/catalog/overlays/monica-official.json new file mode 100644 index 00000000..c53f49e9 --- /dev/null +++ b/oci/catalog/overlays/monica-official.json @@ -0,0 +1,17 @@ +{ + "proxmox": { + "stack_environment_overrides": { + "monica-db": {"MARIADB_RANDOM_ROOT_PASSWORD": "yes"}, + "monica": {"DB_DATABASE": "monica", "APP_URL": "http://localhost"} + }, + "stack_generators": { + "GENERATED_APP_KEY": {"encoding": "base64", "bytes": 32, "prefix": "base64:"} + }, + "stack_adaptation_notes": [ + "APP_KEY follows the official base64: plus 32 random bytes format; it is generated once per deployment and persisted in the LXC environment.", + "MARIADB_RANDOM_ROOT_PASSWORD is a boolean switch, not a password.", + "Create the first Monica account through its web setup. Internet exposure requires HTTPS configuration." + ], + "stack_references": ["https://github.com/monicahq/docker", "https://github.com/MariaDB/mariadb-docker/blob/master/healthcheck.sh"] + } +} diff --git a/oci/catalog/overlays/monica.json b/oci/catalog/overlays/monica.json new file mode 100644 index 00000000..c70ab086 --- /dev/null +++ b/oci/catalog/overlays/monica.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Deprecated upstream: the image no longer receives updates" + } +} diff --git a/oci/catalog/overlays/motioneye.json b/oci/catalog/overlays/motioneye.json new file mode 100644 index 00000000..c05415ce --- /dev/null +++ b/oci/catalog/overlays/motioneye.json @@ -0,0 +1,29 @@ +{ + "first_run": { + "credentials": [ + { + "label": "motionEye web interface", + "type": "static-default", + "username": "admin", + "password": "", + "change_required": true, + "source": "upstream-motioneye-readme", + "retrieval": null + } + ] + }, + "container_contract": { + "image": { + "reference": "ghcr.io/motioneye-project/motioneye:latest", + "tag": "latest", + "registry": "ghcr.io", + "repository": "ghcr.io/motioneye-project/motioneye" + } + }, + "catalog_ui": { + "architectures": [ + "amd64", + "arm64" + ] + } +} diff --git a/oci/catalog/overlays/msedge.json b/oci/catalog/overlays/msedge.json new file mode 100644 index 00000000..2cda841c --- /dev/null +++ b/oci/catalog/overlays/msedge.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-msedge/master/Dockerfile", + "dockerfile_sha256": "1ca2b22799881c9879c18eaba2ea62f1a00cf4809a193a6265f47f3c850d3743", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/mullvad-browser.json b/oci/catalog/overlays/mullvad-browser.json new file mode 100644 index 00000000..a4230dfc --- /dev/null +++ b/oci/catalog/overlays/mullvad-browser.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-mullvad-browser/master/Dockerfile", + "dockerfile_sha256": "1514544621cf06f20a7675f86b13ec6af9145d8a94d0a52f684cc7dd925370cd", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/mysql-workbench.json b/oci/catalog/overlays/mysql-workbench.json new file mode 100644 index 00000000..f7350b15 --- /dev/null +++ b/oci/catalog/overlays/mysql-workbench.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-mysql-workbench/master/Dockerfile", + "dockerfile_sha256": "10fef7181221fb1552c66caaaac5fdc5712f036153961ec2f086500b3b81b1f1", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/netbox.json b/oci/catalog/overlays/netbox.json new file mode 100644 index 00000000..9050c9c0 --- /dev/null +++ b/oci/catalog/overlays/netbox.json @@ -0,0 +1,197 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SUPERUSER_EMAIL", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Email address of the NetBox admin account", + "source": "netbox-readme" + }, + { + "name": "SUPERUSER_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the NetBox admin account", + "source": "netbox-readme" + }, + { + "name": "ALLOWED_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_NAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USER", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_HOST", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_PORT", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_USERNAME", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_DB_TASK", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REDIS_DB_CACHE", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "BASE_PATH", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "CSRF_TRUSTED_ORIGINS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_ENABLED", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_BACKEND", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_HEADER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_AUTO_CREATE_USER", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_DEFAULT_GROUPS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "REMOTE_AUTH_DEFAULT_PERMISSIONS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "NetBox", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "password_environment": "SUPERUSER_PASSWORD", + "change_required": false, + "source": "netbox-image-superuser", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/netdata.json b/oci/catalog/overlays/netdata.json new file mode 100644 index 00000000..24ef5646 --- /dev/null +++ b/oci/catalog/overlays/netdata.json @@ -0,0 +1,159 @@ +{ + "status": "generated-unvalidated", + "catalog_ui": { + "tips": [ + "Monitors host processes, CPU, memory and network; uses the host IP, not its own IP.", + "Privileged access to the host PID/network and unconfined AppArmor: requires confirmation. Trusted networks only; the host firewall is the one that applies.", + "Neither docker.sock nor the host root directory is mounted. Docker inventory, SMART and capacity of all filesystems are not guaranteed.", + "LXCFS is skipped only in the monitor CT so that the limited container RAM/CPU is not shown.", + "Uses lxc.include with /etc/pve/lxc/proxmenux-host-monitor; this file is not included in vzdump and must be kept when restoring on another host.", + "The CPU limit is applied as cpulimit, without hiding processors through affinity." + ] + }, + "container_contract": { + "volumes": [ + { + "id": "volume-0", + "container_path": "/etc/netdata", + "compose_source_example": "/DATA/AppData/Netdata/config", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-1", + "container_path": "/var/lib/netdata", + "compose_source_example": "/DATA/AppData/Netdata/lib", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + }, + { + "id": "volume-2", + "container_path": "/var/cache/netdata", + "compose_source_example": "/DATA/AppData/Netdata/cache", + "read_only": false, + "required": true, + "installation_choice": [ + "managed-volume", + "host-bind" + ], + "default": "managed-volume", + "managed_volume": { + "backup": true, + "default_size_gb": 8 + } + } + ] + }, + "proxmox": { + "defaults": { + "unprivileged": false, + "ostype": "unmanaged", + "memory_mb": 1024, + "features": [] + }, + "security_profile": { + "requires_privileged_lxc": true, + "requires_host_pid_namespace": true, + "optional_privileged_lxc": false, + "requires_relaxed_confinement": true, + "optional_relaxed_confinement": false, + "confirmation_required": true, + "risk_level": "high", + "warning": "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks." + }, + "installer_profile": { + "host_monitor": "netdata", + "host_monitor_mounts": [ + { + "source": "/proc", + "target": "/host/proc" + }, + { + "source": "/sys", + "target": "/host/sys" + }, + { + "source": "/etc/passwd", + "target": "/host/etc/passwd" + }, + { + "source": "/etc/group", + "target": "/host/etc/group" + }, + { + "source": "/etc/os-release", + "target": "/host/etc/os-release" + }, + { + "source": "/sys/fs/cgroup", + "target": "/host/sys/fs/cgroup" + } + ], + "startup_healthcheck": { + "scheme": "http", + "port": 19999, + "path": "/", + "timeout_seconds": 180, + "request_timeout_seconds": 5, + "verify_tls": false + }, + "security": { + "required_capabilities": [ + "SYS_PTRACE", + "SYS_ADMIN" + ], + "options": { + "apparmor_profile": "unconfined" + } + } + } + }, + "compatibility": { + "automatic_install_candidate": true, + "validated": false, + "untranslated_blockers": [] + }, + "validation": { + "service_health": "passed-observed-2026-09-14", + "restart_persistence": "passed-observed-2026-09-14", + "backup_restore": "pending", + "update_preserves_data": "pending", + "latest_runtime_observation": { + "date": "2026-09-14", + "vmid": 105, + "architecture": "amd64", + "proxmox": "9.2.18", + "image_digest": "sha256:9317b3621e0a1f7406051d2dda6b94bf81ecebc79f24447aedaa92405b0a171e", + "image_version": "v2.11.0-340-nightly", + "http_port": 19999, + "host_pid_namespace": true, + "host_network_namespace": true, + "host_memory_bytes": 16110522368, + "shutdown_start_passed": true, + "companion_include": "/etc/pve/lxc/proxmenux-host-monitor", + "companion_included_in_vzdump": false, + "rolling_tag_validation": "only-observed-digest", + "cgroup_charts_observed": 144, + "persistent_registry_uid_unchanged": true, + "managed_volumes_backup": true + } + } +} diff --git a/oci/catalog/overlays/nzbget.json b/oci/catalog/overlays/nzbget.json new file mode 100644 index 00000000..00d26a7c --- /dev/null +++ b/oci/catalog/overlays/nzbget.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "NZBGet web interface", + "type": "static-default", + "username": "nzbget", + "password": "tegbzn6789", + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/obsidian.json b/oci/catalog/overlays/obsidian.json new file mode 100644 index 00000000..39f50313 --- /dev/null +++ b/oci/catalog/overlays/obsidian.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-obsidian/master/Dockerfile", + "dockerfile_sha256": "daa45670e56f10924a93621d7d419c1b4ca4e8aa14636b1f5b5b32f2a55ba500", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/ollama.json b/oci/catalog/overlays/ollama.json new file mode 100644 index 00000000..ccf7256b --- /dev/null +++ b/oci/catalog/overlays/ollama.json @@ -0,0 +1,22 @@ +{ + "proxmox": { + "deployment_profile": {"variant": "hardware-selectable", "gpu_passthrough": "installer-selection"}, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Acceleration for Ollama", + "default": "cpu", + "profiles": [ + {"id": "cpu", "label": "CPU", "device_requests": []}, + { + "id": "nvidia", "label": "NVIDIA (CUDA)", + "device_requests": [{ + "id": "nvidia-runtime", "kind": "nvidia-runtime", "purpose": "nvidia-cuda", + "device_selection": "all-requested-by-compose" + }], + "environment": [{"name": "NVIDIA_VISIBLE_DEVICES", "value": "all"}] + } + ] + } + } + } +} diff --git a/oci/catalog/overlays/openclaw.json b/oci/catalog/overlays/openclaw.json new file mode 100644 index 00000000..fc7916be --- /dev/null +++ b/oci/catalog/overlays/openclaw.json @@ -0,0 +1,13 @@ +{ + "container_contract": { + "image": { + "reference": "icewhaletech/openclaw:2026.5.7", + "tag": "2026.5.7" + } + }, + "catalog_ui": { + "architectures": [ + "amd64" + ] + } +} diff --git a/oci/catalog/overlays/openhands.json b/oci/catalog/overlays/openhands.json new file mode 100644 index 00000000..e9ec25f0 --- /dev/null +++ b/oci/catalog/overlays/openhands.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Needs a Docker engine; a native OCI LXC has none" + } +} diff --git a/oci/catalog/overlays/openlist.json b/oci/catalog/overlays/openlist.json new file mode 100644 index 00000000..0dbb2ac6 --- /dev/null +++ b/oci/catalog/overlays/openlist.json @@ -0,0 +1,58 @@ +{ + "container_contract": { + "environment": [ + { + "name": "UMASK", + "example": "022", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "OPENLIST_ADMIN_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the OpenList admin user", + "source": "openlist-initial-admin" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "OpenList", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "password_environment": "OPENLIST_ADMIN_PASSWORD", + "change_required": false, + "source": "openlist-initial-admin", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "OPENLIST_ADMIN_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + }, + "volume_preparations": [ + { + "container_path": "/opt/openlist/data", + "remove_lost_found": true, + "owner_strategy": "mapped-application-user", + "only_when_mount_type": "managed-volume" + } + ], + "volume_owner": { + "uid": 999, + "gid": 1000 + } + } + } +} diff --git a/oci/catalog/overlays/openshot.json b/oci/catalog/overlays/openshot.json new file mode 100644 index 00000000..21308f73 --- /dev/null +++ b/oci/catalog/overlays/openshot.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-openshot/master/Dockerfile", + "dockerfile_sha256": "ee94083f4d4b9ba7db68310b5e6221c9a4e994c89e430cf5a033c9edd267a091", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/openssh-server.json b/oci/catalog/overlays/openssh-server.json new file mode 100644 index 00000000..7b03e38c --- /dev/null +++ b/oci/catalog/overlays/openssh-server.json @@ -0,0 +1,134 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PUBLIC_KEY", + "example": "yourpublickey", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "PUBLIC_KEY_FILE", + "example": "/path/to/file", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "PUBLIC_KEY_DIR", + "example": "/path/to/directory/containing/_only_/pubkeys", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "PUBLIC_KEY_URL", + "example": "https://github.com/username.keys", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "SUDO_ACCESS", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PASSWORD_ACCESS", + "example": "true", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "openssh-server-readme" + }, + { + "name": "USER_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password for the SSH login", + "source": "openssh-server-readme" + }, + { + "name": "USER_PASSWORD_FILE", + "example": "/path/to/file", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "USER_NAME", + "example": "linuxserver.io", + "required": true, + "sensitive": false, + "prompt": "User name for the SSH login", + "source": "openssh-server-readme" + }, + { + "name": "LOG_STDOUT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "SSH access", + "type": "configured-or-installer-generated", + "username": "linuxserver.io", + "password": null, + "username_environment": "USER_NAME", + "password_environment": "USER_PASSWORD", + "change_required": false, + "source": "openssh-server-readme", + "retrieval": null + } + ], + "endpoints": [] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "USER_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + } + } + }, + "catalog_ui": { + "launch": { + "scheme": "http", + "port": null, + "path": "/" + } + } +} diff --git a/oci/catalog/overlays/openvscode-server.json b/oci/catalog/overlays/openvscode-server.json new file mode 100644 index 00000000..c70ab086 --- /dev/null +++ b/oci/catalog/overlays/openvscode-server.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Deprecated upstream: the image no longer receives updates" + } +} diff --git a/oci/catalog/overlays/opera.json b/oci/catalog/overlays/opera.json new file mode 100644 index 00000000..eeaddbb7 --- /dev/null +++ b/oci/catalog/overlays/opera.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-opera/master/Dockerfile", + "dockerfile_sha256": "889ef38200d79dcadeda61535c2d06985b0f03d1d0a746704ff885ea813ffc21", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/pelorus.json b/oci/catalog/overlays/pelorus.json new file mode 100644 index 00000000..034cbc90 --- /dev/null +++ b/oci/catalog/overlays/pelorus.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-pelorus/master/Dockerfile", + "dockerfile_sha256": "0ce9c54fda7045fe7e106400657bc9c66aa30c00b24deb05e2a0981136dbafe9", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/petio.json b/oci/catalog/overlays/petio.json new file mode 100644 index 00000000..e299a37a --- /dev/null +++ b/oci/catalog/overlays/petio.json @@ -0,0 +1,11 @@ +{ + "proxmox": { + "stack_adaptation_notes": [ + "MongoDB implicit image volumes /data/db and /data/configdb receive managed Proxmox volumes with backup enabled.", + "MongoDB has no LAN interface; its unauthenticated upstream configuration is limited to the private stack network (also reachable by the Proxmox host).", + "Complete Petio web setup with MongoDB host mongo and port 27017. Plex credentials remain user-provided.", + "The latest MongoDB image requires compatible CPU instructions; application and hardware compatibility remain unvalidated." + ], + "stack_references": ["https://github.com/docker-library/docs/tree/master/mongo", "https://github.com/petio-team/petio"] + } +} diff --git a/oci/catalog/overlays/photoprism.json b/oci/catalog/overlays/photoprism.json new file mode 100644 index 00000000..d4d8e6e8 --- /dev/null +++ b/oci/catalog/overlays/photoprism.json @@ -0,0 +1,53 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PHOTOPRISM_ADMIN_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the PhotoPrism admin user (at least 8 characters)", + "source": "photoprism-config-flags" + }, + { + "name": "PHOTOPRISM_UPLOAD_NSFW", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "PhotoPrism", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "password_environment": "PHOTOPRISM_ADMIN_PASSWORD", + "change_required": false, + "source": "photoprism-config-flags", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "PHOTOPRISM_ADMIN_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/phpmyadmin.json b/oci/catalog/overlays/phpmyadmin.json new file mode 100644 index 00000000..726b20a9 --- /dev/null +++ b/oci/catalog/overlays/phpmyadmin.json @@ -0,0 +1,59 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PMA_ARBITRARY", + "example": "1", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "linuxserver-phpmyadmin-readme" + }, + { + "name": "PMA_HOST", + "example": "", + "required": false, + "sensitive": false, + "prompt": "Database server proposed on the login page (empty = typed at each login)", + "source": "phpmyadmin-docker-environment-variables" + }, + { + "name": "PMA_ABSOLUTE_URI", + "example": "", + "required": false, + "sensitive": false, + "prompt": "Public URL of phpMyAdmin when it is served behind a reverse proxy", + "source": "linuxserver-phpmyadmin-readme" + } + ] + }, + "proxmox": { + "installer_profile": { + "completion_notes": [ + "phpMyAdmin is installed with arbitrary server connections enabled: the login page has a Server field where the address of the MySQL or MariaDB server is entered, together with its user and password.", + "The database server must accept connections from the IP address of this container, with a user that is not limited to localhost." + ] + } + } +} diff --git a/oci/catalog/overlays/pidgin.json b/oci/catalog/overlays/pidgin.json new file mode 100644 index 00000000..1ade8eef --- /dev/null +++ b/oci/catalog/overlays/pidgin.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-pidgin/master/Dockerfile", + "dockerfile_sha256": "81f8176b9843bc7a4b9a7f762910f58e735f35d34d78834e191bae6e5ee851b2", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/planka.json b/oci/catalog/overlays/planka.json new file mode 100644 index 00000000..41a4953e --- /dev/null +++ b/oci/catalog/overlays/planka.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Needs PostgreSQL in its own container; planned as a multi-container application" + } +} diff --git a/oci/catalog/overlays/playit-agent.json b/oci/catalog/overlays/playit-agent.json new file mode 100644 index 00000000..9f252c41 --- /dev/null +++ b/oci/catalog/overlays/playit-agent.json @@ -0,0 +1,10 @@ +{ + "proxmox": { + "installer_profile": { + "completion_notes": [ + "playit.gg has to claim this agent before it forwards anything. The agent prints a one-time claim link on the container console and keeps it there until the link is opened.", + "Read the link with pct console CTID on the Proxmox host, or from the Console panel of the container in the Proxmox web interface, then open the https://playit.gg/claim/ address it shows in a browser and sign in to playit.gg. Ctrl+a q leaves pct console." + ] + } + } +} diff --git a/oci/catalog/overlays/plex.json b/oci/catalog/overlays/plex.json new file mode 100644 index 00000000..d849d938 --- /dev/null +++ b/oci/catalog/overlays/plex.json @@ -0,0 +1,58 @@ +{ + "catalog_ui": { + "launch": {"scheme": "http", "port": 32400, "path": "/web"} + }, + "container_contract": { + "ports": [{ + "container_port": 32400, + "published_example": 32400, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + }] + }, + "first_run": { + "endpoints": [{ + "label": "Plex WebUI", + "scheme": "http", + "port": 32400, + "path": "/web", + "source": "linuxserver-application-setup" + }] + }, + "proxmox": { + "deployment_profile": { + "variant": "hardware-selectable", + "gpu_passthrough": "installer-selection" + }, + "installer_profile": { + "hardware_acceleration": { + "prompt": "Hardware acceleration for Plex", + "default": "none", + "profiles": [ + {"id": "none", "label": "No acceleration (CPU)", "device_requests": []}, + { + "id": "vaapi", + "label": "Intel/AMD (VA-API)", + "environment_from_devices": {"ATTACHED_DEVICES_PERMS": ["vaapi-render"]}, + "device_requests": [{ + "id": "vaapi-render", "kind": "character-device", "purpose": "vaapi", + "path_prompt": "GPU render device", "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", "mode": "0660", "deny_write": false, + "gid_strategy": "host-device-gid" + }] + }, + { + "id": "nvidia", + "label": "NVIDIA (NVENC/NVDEC)", + "device_requests": [{ + "id": "nvidia-runtime", "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", "device_selection": "all-requested-by-compose" + }], + "environment": [{"name": "NVIDIA_VISIBLE_DEVICES", "value": "all"}] + } + ] + } + } + } +} diff --git a/oci/catalog/overlays/pocketbase.json b/oci/catalog/overlays/pocketbase.json new file mode 100644 index 00000000..c11479ef --- /dev/null +++ b/oci/catalog/overlays/pocketbase.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "PocketBase admin UI", + "type": "static-default", + "username": "casaos@admin.local", + "password": "adminpocketbase", + "change_required": true, + "source": "casaos-image-superuser", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/portainer.json b/oci/catalog/overlays/portainer.json new file mode 100644 index 00000000..e9ec25f0 --- /dev/null +++ b/oci/catalog/overlays/portainer.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Needs a Docker engine; a native OCI LXC has none" + } +} diff --git a/oci/catalog/overlays/postgresql.json b/oci/catalog/overlays/postgresql.json new file mode 100644 index 00000000..20e949ed --- /dev/null +++ b/oci/catalog/overlays/postgresql.json @@ -0,0 +1,80 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "$PUID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "PGID", + "example": "$PGID", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "TZ", + "example": "$TZ", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "POSTGRES_USER", + "example": "postgresql", + "required": true, + "sensitive": false, + "prompt": "Name of the PostgreSQL user created on the first start", + "source": "postgres-official-image" + }, + { + "name": "POSTGRES_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the PostgreSQL user", + "source": "postgres-official-image" + }, + { + "name": "POSTGRES_DB", + "example": "postgresql", + "required": true, + "sensitive": false, + "prompt": "Name of the database created on the first start", + "source": "postgres-official-image" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "PostgreSQL", + "type": "configured-or-installer-generated", + "username": "postgresql", + "password": null, + "username_environment": "POSTGRES_USER", + "password_environment": "POSTGRES_PASSWORD", + "change_required": false, + "source": "postgres-official-image", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "POSTGRES_PASSWORD": { + "strategy": "token-hex", + "bytes": 16, + "prompt": true + } + }, + "completion_notes": [ + "PostgreSQL creates the database named in POSTGRES_DB on the first start. The installer default is postgresql." + ] + } + } +} diff --git a/oci/catalog/overlays/pydio-cells.json b/oci/catalog/overlays/pydio-cells.json new file mode 100644 index 00000000..96d1200f --- /dev/null +++ b/oci/catalog/overlays/pydio-cells.json @@ -0,0 +1,52 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EXTERNALURL", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Address to reach Pydio Cells (https://domain or https://IP:8080)", + "source": "linuxserver-pydio-cells-readme" + }, + { + "name": "SERVER_IP", + "example": "", + "required": true, + "sensitive": false, + "prompt": "IP address of this container for the certificate (0.0.0.0 if unknown)", + "source": "linuxserver-pydio-cells-readme" + } + ] + }, + "proxmox": { + "installer_profile": { + "completion_notes": [ + "Pydio Cells needs an external MySQL or MariaDB database. The setup wizard asks for its address, database name and user on the first start.", + "The web interface uses a self-signed certificate, so the browser shows a warning the first time.", + "Pydio Cells redirects to the address given in EXTERNALURL. If the container changes address, edit lxc.environment.runtime: EXTERNALURL and SERVER_IP in /etc/pve/lxc/.conf with the container stopped, and delete /config/keys/cert.crt to regenerate the certificate." + ] + } + } +} diff --git a/oci/catalog/overlays/pyload-ng.json b/oci/catalog/overlays/pyload-ng.json new file mode 100644 index 00000000..47d84ccf --- /dev/null +++ b/oci/catalog/overlays/pyload-ng.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "pyLoad web interface", + "type": "static-default", + "username": "pyload", + "password": "pyload", + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/qbittorrent-hotio.json b/oci/catalog/overlays/qbittorrent-hotio.json new file mode 100644 index 00000000..10587b07 --- /dev/null +++ b/oci/catalog/overlays/qbittorrent-hotio.json @@ -0,0 +1,19 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Temporary login", + "type": "runtime-generated", + "username": "admin", + "password": null, + "change_required": true, + "source": "qbittorrent-temporary-password-on-first-start", + "retrieval": { + "method": "container-console-pattern", + "pattern_id": "linuxserver-temporary-password", + "timeout_seconds": 180 + } + } + ] + } +} diff --git a/oci/catalog/overlays/qdirstat.json b/oci/catalog/overlays/qdirstat.json new file mode 100644 index 00000000..0c80d228 --- /dev/null +++ b/oci/catalog/overlays/qdirstat.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-qdirstat/master/Dockerfile", + "dockerfile_sha256": "4757c227ff57423027521037d12ca2076874b5fe293f3486dea6d55df7be078e", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/ragflow.json b/oci/catalog/overlays/ragflow.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/ragflow.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/raneto.json b/oci/catalog/overlays/raneto.json new file mode 100644 index 00000000..e37147c3 --- /dev/null +++ b/oci/catalog/overlays/raneto.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "Raneto web interface", + "type": "static-default", + "username": "admin", + "password": "password", + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/rawtherapee.json b/oci/catalog/overlays/rawtherapee.json new file mode 100644 index 00000000..4e8db156 --- /dev/null +++ b/oci/catalog/overlays/rawtherapee.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-rawtherapee/master/Dockerfile", + "dockerfile_sha256": "7fb1fade53874b81555a04489475d47a8a64d733a689024b91c09b749fcec517", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/readarr.json b/oci/catalog/overlays/readarr.json new file mode 100644 index 00000000..8ac340cc --- /dev/null +++ b/oci/catalog/overlays/readarr.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Retired upstream: only nightly builds are published, with no stable release" + } +} diff --git a/oci/catalog/overlays/romm.json b/oci/catalog/overlays/romm.json new file mode 100644 index 00000000..a2c92958 --- /dev/null +++ b/oci/catalog/overlays/romm.json @@ -0,0 +1,36 @@ +{ + "proxmox": { + "stack_environment_overrides": { + "romm": { + "ROMM_DB_DRIVER": "mariadb", + "DB_PASSWD": "${GENERATED_MARIADB_PASSWORD}", + "IGDB_CLIENT_ID": "", + "IGDB_CLIENT_SECRET": "", + "SCREENSCRAPER_USER": "", + "SCREENSCRAPER_PASSWORD": "", + "STEAMGRIDDB_API_KEY": "" + } + }, + "stack_optional_environment": [ + {"service": "romm", "label": "IGDB", "fields": [ + {"name": "IGDB_CLIENT_ID", "label": "IGDB Client ID", "sensitive": false}, + {"name": "IGDB_CLIENT_SECRET", "label": "IGDB Client Secret", "sensitive": true} + ]}, + {"service": "romm", "label": "ScreenScraper", "fields": [ + {"name": "SCREENSCRAPER_USER", "label": "ScreenScraper username", "sensitive": false}, + {"name": "SCREENSCRAPER_PASSWORD", "label": "ScreenScraper password", "sensitive": true} + ]}, + {"service": "romm", "label": "SteamGridDB", "fields": [ + {"name": "STEAMGRIDDB_API_KEY", "label": "SteamGridDB API key", "sensitive": true} + ]} + ], + "stack_adaptation_notes": [ + "DB_PASSWD and MARIADB_PASSWORD share one generated secret. The MariaDB root password is independent.", + "External metadata credentials are optional user input, never randomly generated. Without them, associated metadata integrations are not configured.", + "Configuration, assets, library, resources and database volumes default to private backed-up Proxmox volumes. Users can select host directories explicitly.", + "The hook starts stopped dependencies before RomM. It does not propagate manual dependency restarts to the application like Compose depends_on restart:true.", + "Latest tags are retained; first boot, hardware and upstream version compatibility remain unvalidated." + ], + "stack_references": ["https://docs.romm.app/5.2.0/install/databases/", "https://docs.romm.app/5.2.0/reference/environment-variables/"] + } +} diff --git a/oci/catalog/overlays/rsnapshot.json b/oci/catalog/overlays/rsnapshot.json new file mode 100644 index 00000000..54cac4cf --- /dev/null +++ b/oci/catalog/overlays/rsnapshot.json @@ -0,0 +1,10 @@ +{ + "proxmox": { + "installer_profile": { + "completion_notes": [ + "rsnapshot starts with the default configuration, which backs up /data into /.snapshots. Edit /config/rsnapshot.conf inside the container to set your own backup points, snapshot root and retention intervals.", + "No backup is scheduled: the rsnapshot lines in /config/crontabs/root are commented out. Uncomment or adjust the intervals you want, then restart the container." + ] + } + } +} diff --git a/oci/catalog/overlays/rustdesk.json b/oci/catalog/overlays/rustdesk.json new file mode 100644 index 00000000..9fa50650 --- /dev/null +++ b/oci/catalog/overlays/rustdesk.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-rustdesk/master/Dockerfile", + "dockerfile_sha256": "f1b789a119aed58821c2e113e74a7381f671e97c2f71eac60416f45d5c1ade14", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/sealskin.json b/oci/catalog/overlays/sealskin.json new file mode 100644 index 00000000..e9ec25f0 --- /dev/null +++ b/oci/catalog/overlays/sealskin.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Needs a Docker engine; a native OCI LXC has none" + } +} diff --git a/oci/catalog/overlays/shotcut.json b/oci/catalog/overlays/shotcut.json new file mode 100644 index 00000000..8eccf0ed --- /dev/null +++ b/oci/catalog/overlays/shotcut.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-shotcut/master/Dockerfile", + "dockerfile_sha256": "2bf9ad9e5688aa694451425e906c8c4ad0158f8122dbf00148847c46a78db6b4", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/siyuan-note.json b/oci/catalog/overlays/siyuan-note.json new file mode 100644 index 00000000..990261e2 --- /dev/null +++ b/oci/catalog/overlays/siyuan-note.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "SiYuan access code", + "type": "static-default", + "username": "Not required (access code only)", + "password": "casaos", + "change_required": true, + "source": "casaos-tips", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/snapotter.json b/oci/catalog/overlays/snapotter.json new file mode 100644 index 00000000..8e55f1fd --- /dev/null +++ b/oci/catalog/overlays/snapotter.json @@ -0,0 +1,82 @@ +{ + "container_contract": { + "environment": [ + { + "name": "AUTH_ENABLED", + "example": "true", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEFAULT_USERNAME", + "example": "admin", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "DEFAULT_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Password of the SnapOtter admin user", + "source": "snapotter-documentation" + }, + { + "name": "MAX_UPLOAD_SIZE_MB", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "MAX_BATCH_SIZE", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "CONCURRENT_JOBS", + "example": "0", + "required": true, + "sensitive": false, + "source": "docker-compose" + }, + { + "name": "REDIS_MAXMEMORY", + "example": "512mb", + "required": true, + "sensitive": false, + "source": "docker-compose" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "SnapOtter", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "DEFAULT_USERNAME", + "password_environment": "DEFAULT_PASSWORD", + "change_required": true, + "source": "snapotter-documentation", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "DEFAULT_PASSWORD": { + "strategy": "token-hex", + "bytes": 12, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/speedtest-tracker.json b/oci/catalog/overlays/speedtest-tracker.json new file mode 100644 index 00000000..7127efb2 --- /dev/null +++ b/oci/catalog/overlays/speedtest-tracker.json @@ -0,0 +1,135 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "APP_KEY", + "example": "", + "required": true, + "sensitive": true, + "source": "laravel-application-key" + }, + { + "name": "APP_URL", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_CONNECTION", + "example": "sqlite", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SPEEDTEST_SCHEDULE", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SPEEDTEST_SERVERS", + "example": "", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_HOST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PORT", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_DATABASE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_USERNAME", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DB_PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "source": "linuxserver-compose" + }, + { + "name": "DISPLAY_TIMEZONE", + "example": "Etc/UTC", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PRUNE_RESULTS_OLDER_THAN", + "example": "0", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "Speedtest Tracker web interface", + "type": "static-default", + "username": "admin@example.com", + "password": "password", + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "APP_KEY": { + "strategy": "token-hex", + "bytes": 16, + "prompt": true + } + } + } + } +} diff --git a/oci/catalog/overlays/spotube.json b/oci/catalog/overlays/spotube.json new file mode 100644 index 00000000..c76601a1 --- /dev/null +++ b/oci/catalog/overlays/spotube.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-spotube/master/Dockerfile", + "dockerfile_sha256": "f283a559a359244aba83d787b9e1457554df5360f503faa370a181b26c8e1e65", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/sqlitebrowser.json b/oci/catalog/overlays/sqlitebrowser.json new file mode 100644 index 00000000..5002738b --- /dev/null +++ b/oci/catalog/overlays/sqlitebrowser.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-sqlitebrowser/master/Dockerfile", + "dockerfile_sha256": "730169e09e92074dbac9dfe5e16ad5841a2179d6c04413cf3522c98b45a57b51", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/sure.json b/oci/catalog/overlays/sure.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/sure.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/swag.json b/oci/catalog/overlays/swag.json new file mode 100644 index 00000000..020feea4 --- /dev/null +++ b/oci/catalog/overlays/swag.json @@ -0,0 +1,145 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "URL", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Domain for the certificate (example.com)", + "source": "linuxserver-swag-readme" + }, + { + "name": "VALIDATION", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)", + "source": "linuxserver-swag-readme" + }, + { + "name": "SUBDOMAINS", + "example": "", + "required": false, + "sensitive": false, + "prompt": "Subdomains for the certificate, comma separated (wildcard for *.domain)", + "source": "linuxserver-swag-readme" + }, + { + "name": "CERTPROVIDER", + "example": "", + "required": false, + "sensitive": false, + "prompt": "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL", + "source": "linuxserver-swag-readme" + }, + { + "name": "CERT_PROFILE", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "DNSPLUGIN", + "example": "cloudflare", + "required": false, + "sensitive": false, + "prompt": "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)", + "source": "linuxserver-swag-readme" + }, + { + "name": "PROPAGATION", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EMAIL", + "example": "", + "required": false, + "sensitive": false, + "prompt": "Email address for certificate expiry notices (required by ZeroSSL)", + "source": "linuxserver-swag-readme" + }, + { + "name": "ONLY_SUBDOMAINS", + "example": "false", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "EXTRA_DOMAINS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "STAGING", + "example": "false", + "required": false, + "sensitive": false, + "prompt": "Request a staging certificate for testing: true or false", + "source": "linuxserver-swag-readme" + }, + { + "name": "DISABLE_F2B", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SWAG_AUTORELOAD", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SWAG_AUTORELOAD_WATCHLIST", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ] + }, + "proxmox": { + "installer_profile": { + "completion_notes": [ + "The domain must resolve to the public address of this network before the certificate can be issued.", + "With http validation, port 80 of the router must be forwarded to port 80 of this container.", + "With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN= to /etc/pve/lxc/.conf with the container stopped.", + "With dns validation, write the provider credentials in /config/dns-conf/.ini inside the container and restart it.", + "Certificate errors are logged in /config/log/letsencrypt inside the container.", + "SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.", + "Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container." + ] + } + } +} diff --git a/oci/catalog/overlays/taskingai.json b/oci/catalog/overlays/taskingai.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/taskingai.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/teable.json b/oci/catalog/overlays/teable.json new file mode 100644 index 00000000..618bbdf7 --- /dev/null +++ b/oci/catalog/overlays/teable.json @@ -0,0 +1,19 @@ +{ + "proxmox": { + "stack_environment_overrides": { + "teable-cache": {"REDISCLI_AUTH": "${GENERATED_REDIS_PASSWORD}"}, + "teable": {"BACKEND_CACHE_REDIS_URI": "redis://default:${GENERATED_REDIS_PASSWORD}@teable-cache:6379/0"} + }, + "stack_command_overrides": { + "teable-cache": ["redis-server", "--requirepass", "${REDISCLI_AUTH}"] + }, + "stack_adaptation_notes": [ + "The malformed imported '--requirepass password' argument is translated to separate Redis command arguments, preserving its upstream entrypoint.", + "Redis, its authenticated healthcheck and Teable share one generated password. The hook contains no secret; redis-cli reads REDISCLI_AUTH inside the LXC.", + "The named internal Compose bridge becomes an automatically allocated private Proxmox bridge, avoiding fixed-name collisions.", + "Redis readiness requires the exact PONG response, not only redis-cli exit status.", + "Credentials persist in native LXC runtime metadata; administrator access can read them. Latest images and first boot remain unvalidated." + ], + "stack_references": ["https://github.com/teableio/teable", "https://redis.io/docs/latest/develop/tools/cli/"] + } +} diff --git a/oci/catalog/overlays/thelounge.json b/oci/catalog/overlays/thelounge.json new file mode 100644 index 00000000..d6c880f2 --- /dev/null +++ b/oci/catalog/overlays/thelounge.json @@ -0,0 +1,11 @@ +{ + "proxmox": { + "installer_profile": { + "completion_notes": [ + "The Lounge starts in public mode: anyone who reaches the address opens the client without logging in, and the IRC networks added are lost when the session ends.", + "Named accounts need private mode. Stop the container, set public: false in /config/config.js, start it again and create each user with: pct exec -- env THELOUNGE_HOME=/config s6-setuidgid abc thelounge add ", + "The command asks for a password that is not echoed. After creating the users, the web interface asks for a user name and a password." + ] + } + } +} diff --git a/oci/catalog/overlays/turbodiffusion-nvidia.json b/oci/catalog/overlays/turbodiffusion-nvidia.json new file mode 100644 index 00000000..6e6de6a9 --- /dev/null +++ b/oci/catalog/overlays/turbodiffusion-nvidia.json @@ -0,0 +1,8 @@ +{ + "container_contract": { + "image": { + "reference": "icewhaletech/turbodiffusion:20260312", + "tag": "20260312" + } + } +} diff --git a/oci/catalog/overlays/ungoogled-chromium.json b/oci/catalog/overlays/ungoogled-chromium.json new file mode 100644 index 00000000..532596f8 --- /dev/null +++ b/oci/catalog/overlays/ungoogled-chromium.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-ungoogled-chromium/master/Dockerfile", + "dockerfile_sha256": "8d4a62f74204c7ce4f5c909994b4ab1460a3c482a3fba32eef90f7c927b9618b", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/unifi-network-application.json b/oci/catalog/overlays/unifi-network-application.json new file mode 100644 index 00000000..b4665491 --- /dev/null +++ b/oci/catalog/overlays/unifi-network-application.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Needs MongoDB in its own container; planned as a multi-container application" + } +} diff --git a/oci/catalog/overlays/unpackerr.json b/oci/catalog/overlays/unpackerr.json new file mode 100644 index 00000000..a8357120 --- /dev/null +++ b/oci/catalog/overlays/unpackerr.json @@ -0,0 +1,10 @@ +{ + "proxmox": { + "installer_profile": { + "completion_notes": [ + "Unpackerr has no web interface and extracts nothing until it is pointed at a Starr application. Uncomment the [sonarr.0] or [radarr.0] section in /config/unpackerr.conf inside the container, set its url and api_key, then restart the container.", + "The same connection can be given as container variables instead of the file: UN_SONARR_0_URL and UN_SONARR_0_API_KEY, or the UN_RADARR_0_ equivalents." + ] + } + } +} diff --git a/oci/catalog/overlays/vaultwarden.json b/oci/catalog/overlays/vaultwarden.json new file mode 100644 index 00000000..49f7d047 --- /dev/null +++ b/oci/catalog/overlays/vaultwarden.json @@ -0,0 +1,74 @@ +{ + "catalog_ui": { + "launch": { + "scheme": "https", + "port": 443, + "path": "/" + }, + "tips": [ + "The Web Vault requires a secure context. ProxMenux enables Vaultwarden's native Rocket TLS listener on port 443.", + "A persistent self-signed certificate is generated under /data/tls. Browsers must trust or explicitly accept it; a trusted reverse proxy certificate can replace these files later." + ] + }, + "container_contract": { + "environment": [ + { + "name": "ROCKET_PORT", + "example": "443", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "vaultwarden-rocket-tls" + }, + { + "name": "ROCKET_TLS", + "example": "{certs=\"/data/tls/vaultwarden.crt\",key=\"/data/tls/vaultwarden.key\"}", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "vaultwarden-rocket-tls" + } + ], + "ports": [ + { + "container_port": 443, + "published_example": 443, + "protocol": "tcp", + "required": true, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" + } + ] + }, + "proxmox": { + "installer_profile": { + "self_signed_tls": { + "certificate_path": "/data/tls/vaultwarden.crt", + "private_key_path": "/data/tls/vaultwarden.key", + "common_name_from": "deployment-hostname", + "valid_days": 3650, + "preserve_existing": true + }, + "startup_healthcheck": { + "scheme": "https", + "port": 443, + "path": "/alive", + "timeout_seconds": 180, + "request_timeout_seconds": 10, + "stability_seconds": 4, + "verify_tls": false + } + } + }, + "first_run": { + "endpoints": [ + { + "label": "Vaultwarden Web Vault", + "scheme": "https", + "port": 443, + "path": "/", + "source": "vaultwarden-native-rocket-tls" + } + ], + "credentials": [] + } +} diff --git a/oci/catalog/overlays/virt-manager.json b/oci/catalog/overlays/virt-manager.json new file mode 100644 index 00000000..66ed2f9e --- /dev/null +++ b/oci/catalog/overlays/virt-manager.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Manages libvirt hosts, and Proxmox VE does not use libvirt" + } +} diff --git a/oci/catalog/overlays/wallabag.json b/oci/catalog/overlays/wallabag.json new file mode 100644 index 00000000..03fd265e --- /dev/null +++ b/oci/catalog/overlays/wallabag.json @@ -0,0 +1,43 @@ +{ + "container_contract": { + "environment": [ + { + "name": "SYMFONY__ENV__DOMAIN_NAME", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Address used to reach wallabag (http://IP or https://wallabag.example.com)", + "source": "wallabag-docker-readme" + }, + { + "name": "SYMFONY__ENV__SERVER_NAME", + "example": "Wallabag", + "required": true, + "sensitive": false, + "prompt": "Name of this wallabag instance, shown in the interface and in 2FA codes", + "source": "wallabag-docker-readme" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "wallabag web interface", + "type": "static-default", + "username": "wallabag", + "password": "wallabag", + "change_required": true, + "source": "upstream-wallabag-docker-readme", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "completion_notes": [ + "wallabag listens on port 80 of the container and stores its data in SQLite.", + "wallabag builds its links from the address given during the installation. If it does not match the address of the container, edit lxc.environment.runtime: SYMFONY__ENV__DOMAIN_NAME in /etc/pve/lxc/.conf with the container stopped, and start it again." + ] + } + } +} diff --git a/oci/catalog/overlays/webcord.json b/oci/catalog/overlays/webcord.json new file mode 100644 index 00000000..5be963dd --- /dev/null +++ b/oci/catalog/overlays/webcord.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-webcord/master/Dockerfile", + "dockerfile_sha256": "8af90f5928c6de1e2d89f96ca11cb1cfa1c09aa724c887e7f4767b90e64195f6", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/webdav.json b/oci/catalog/overlays/webdav.json new file mode 100644 index 00000000..197c21d0 --- /dev/null +++ b/oci/catalog/overlays/webdav.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "The image publishes only architecture-specific tags, has not been updated since 2022 and does not survive its first start" + } +} diff --git a/oci/catalog/overlays/webstation.json b/oci/catalog/overlays/webstation.json new file mode 100644 index 00000000..e19bc8e9 --- /dev/null +++ b/oci/catalog/overlays/webstation.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute AS dolphin", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-webstation/master/Dockerfile", + "dockerfile_sha256": "9785b95c2d38764864f9c11d4c8e79e8fad65cd246196f310d3cbdaed3834b80", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/weknora.json b/oci/catalog/overlays/weknora.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/weknora.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/overlays/wg-easy.json b/oci/catalog/overlays/wg-easy.json new file mode 100644 index 00000000..681474e9 --- /dev/null +++ b/oci/catalog/overlays/wg-easy.json @@ -0,0 +1,130 @@ +{ + "container_contract": { + "image": { + "reference": "ghcr.io/wg-easy/wg-easy:15", + "tag": "15" + }, + "environment": [ + { + "name": "PASSWORD", + "example": "", + "required": false, + "sensitive": true, + "prompt_user": false, + "source": "wg-easy-v15-refuses-to-start-with-this-variable" + }, + { + "name": "WG_HOST", + "example": "", + "required": false, + "sensitive": false, + "prompt_user": false, + "source": "wg-easy-v15-replaced-by-INIT_HOST" + }, + { + "name": "WG_PORT", + "example": "", + "required": false, + "sensitive": false, + "prompt_user": false, + "source": "wg-easy-v15-replaced-by-INIT_PORT" + }, + { + "name": "WG_DEFAULT_DNS", + "example": "", + "required": false, + "sensitive": false, + "prompt_user": false, + "source": "wg-easy-v15-replaced-by-INIT_DNS" + }, + { + "name": "INSECURE", + "example": "true", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "wg-easy-optional-configuration" + }, + { + "name": "INIT_ENABLED", + "example": "true", + "required": true, + "sensitive": false, + "prompt_user": false, + "source": "wg-easy-unattended-setup" + }, + { + "name": "INIT_USERNAME", + "example": "admin", + "required": true, + "sensitive": false, + "prompt": "User name of the administrator of the web interface", + "source": "wg-easy-unattended-setup" + }, + { + "name": "INIT_PASSWORD", + "example": "", + "required": true, + "sensitive": true, + "prompt": "Administrator password, at least 12 characters (empty = generated)", + "source": "wg-easy-unattended-setup" + }, + { + "name": "INIT_HOST", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Public address clients connect to (vpn.example.com or a public IP)", + "source": "wg-easy-unattended-setup" + }, + { + "name": "INIT_PORT", + "example": "51820", + "required": true, + "sensitive": false, + "prompt": "Public UDP port clients connect to", + "source": "wg-easy-unattended-setup" + }, + { + "name": "INIT_DNS", + "example": "1.1.1.1", + "required": true, + "sensitive": false, + "prompt": "DNS server written in the client configurations", + "source": "wg-easy-unattended-setup" + } + ] + }, + "first_run": { + "credentials": [ + { + "label": "WireGuard Easy web interface", + "type": "configured-or-installer-generated", + "username": "admin", + "password": null, + "username_environment": "INIT_USERNAME", + "password_environment": "INIT_PASSWORD", + "change_required": false, + "source": "wg-easy-unattended-setup", + "retrieval": null + } + ] + }, + "proxmox": { + "installer_profile": { + "generated_sensitive_environment": { + "INIT_PASSWORD": { + "strategy": "token-hex", + "bytes": 16, + "prompt": true + } + }, + "completion_notes": [ + "The administrator account, the public address and the UDP port are created on the first start, so the web interface opens directly on its login page.", + "The web interface is served over plain HTTP on port 51821 (INSECURE=true). Keep it inside the local network or publish it through a reverse proxy with TLS.", + "The initial user name and password stay written in /etc/pve/lxc/.conf as INIT_USERNAME and INIT_PASSWORD. They can be removed after the first login, with the container stopped.", + "Clients reach the VPN through the public address and the UDP port given during the installation, so that port must be forwarded to this container." + ] + } + } +} diff --git a/oci/catalog/overlays/wireguard.json b/oci/catalog/overlays/wireguard.json new file mode 100644 index 00000000..6ab6b619 --- /dev/null +++ b/oci/catalog/overlays/wireguard.json @@ -0,0 +1,100 @@ +{ + "container_contract": { + "environment": [ + { + "name": "PUID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "PGID", + "example": "1000", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "TZ", + "example": "Etc/UTC", + "required": true, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "SERVERURL", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Public address peers connect to, or auto to detect it (vpn.example.com)", + "source": "linuxserver-wireguard-readme" + }, + { + "name": "SERVERPORT", + "example": "51820", + "required": false, + "sensitive": false, + "prompt": "Public UDP port peers connect to", + "source": "linuxserver-wireguard-readme" + }, + { + "name": "PEERS", + "example": "", + "required": true, + "sensitive": false, + "prompt": "Peers to create: a number (3) or a list of names (phone,laptop)", + "source": "linuxserver-wireguard-readme" + }, + { + "name": "PEERDNS", + "example": "auto", + "required": false, + "sensitive": false, + "prompt": "DNS server written in the peer configurations (auto or an IP address)", + "source": "linuxserver-wireguard-readme" + }, + { + "name": "INTERNAL_SUBNET", + "example": "10.13.13.0", + "required": false, + "sensitive": false, + "prompt": "Internal subnet of the tunnel (change it only if it clashes)", + "source": "linuxserver-wireguard-readme" + }, + { + "name": "ALLOWEDIPS", + "example": "0.0.0.0/0", + "required": false, + "sensitive": false, + "prompt": "Networks the peers reach through the tunnel (0.0.0.0/0 = all traffic)", + "source": "linuxserver-wireguard-readme" + }, + { + "name": "PERSISTENTKEEPALIVE_PEERS", + "example": "", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + }, + { + "name": "LOG_CONFS", + "example": "true", + "required": false, + "sensitive": false, + "source": "linuxserver-compose" + } + ] + }, + "proxmox": { + "installer_profile": { + "completion_notes": [ + "Each peer gets its configuration and its QR code inside the container: /config/peer1/peer1.conf and /config/peer1/peer1.png, or /config/peer_/peer_.conf when names were given.", + "Show the QR code of a peer again with: pct exec -- /app/show-peer 1", + "Copy a peer configuration to the host with: pct pull /config/peer1/peer1.conf peer1.conf", + "Peers reach the server through the public address and the UDP port given during the installation, so that port must be forwarded to this container.", + "Adding peers later means raising PEERS in /etc/pve/lxc/.conf and restarting the container. The existing peer keys are kept." + ] + } + } +} diff --git a/oci/catalog/overlays/wireshark.json b/oci/catalog/overlays/wireshark.json new file mode 100644 index 00000000..4f34d0f3 --- /dev/null +++ b/oci/catalog/overlays/wireshark.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:alpine324", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-wireshark/master/Dockerfile", + "dockerfile_sha256": "6afcc209c79818fe574d869b1933df50194eaf978b26f16304ed0dce16f8a37a", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/wps-office.json b/oci/catalog/overlays/wps-office.json new file mode 100644 index 00000000..0ba007f0 --- /dev/null +++ b/oci/catalog/overlays/wps-office.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:arch", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-wps-office/master/Dockerfile", + "dockerfile_sha256": "195689c826f891fa8e50019092eef4aa817eca18bf7012175d6ba44474170e4b", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/yaak.json b/oci/catalog/overlays/yaak.json new file mode 100644 index 00000000..6c767fe8 --- /dev/null +++ b/oci/catalog/overlays/yaak.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:ubunturesolute", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-yaak/master/Dockerfile", + "dockerfile_sha256": "b6ce329b48b85150b2dbf4a1dabd353b1d12a2bec53adbd1adf92f80a290691f", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/your_spotify.json b/oci/catalog/overlays/your_spotify.json new file mode 100644 index 00000000..b4665491 --- /dev/null +++ b/oci/catalog/overlays/your_spotify.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Needs MongoDB in its own container; planned as a multi-container application" + } +} diff --git a/oci/catalog/overlays/znc.json b/oci/catalog/overlays/znc.json new file mode 100644 index 00000000..c8a575cd --- /dev/null +++ b/oci/catalog/overlays/znc.json @@ -0,0 +1,15 @@ +{ + "first_run": { + "credentials": [ + { + "label": "ZNC web interface", + "type": "static-default", + "username": "admin", + "password": "admin", + "change_required": true, + "source": "linuxserver-readme-application-setup", + "retrieval": null + } + ] + } +} diff --git a/oci/catalog/overlays/zotero.json b/oci/catalog/overlays/zotero.json new file mode 100644 index 00000000..513993bf --- /dev/null +++ b/oci/catalog/overlays/zotero.json @@ -0,0 +1,15 @@ +{ + "proxmox": { + "installer_profile": { + "selkies": { + "base": "FROM ghcr.io/linuxserver/baseimage-selkies:debiantrixie", + "dockerfile_url": "https://raw.githubusercontent.com/linuxserver/docker-zotero/master/Dockerfile", + "dockerfile_sha256": "7a4334dda5023bb812a3532498d92ede4eeccc4c4e4fa8b6652c6f0b137d00f4", + "reviewed_on": "2026-09-16", + "documentation": "https://docs.linuxserver.io/images/docker-baseimage-selkies/", + "nvidia": "not-offered-until-specific-host-and-image-validation", + "validation": "profile-generated; real streaming workload pending" + } + } + } +} diff --git a/oci/catalog/overlays/ztnet.json b/oci/catalog/overlays/ztnet.json new file mode 100644 index 00000000..cf30d72a --- /dev/null +++ b/oci/catalog/overlays/ztnet.json @@ -0,0 +1,6 @@ +{ + "catalog_ui": { + "hidden": true, + "hidden_reason": "Pending multi-container adaptation; retained for future work" + } +} diff --git a/oci/catalog/volume-policy.json b/oci/catalog/volume-policy.json new file mode 100644 index 00000000..e6670e89 --- /dev/null +++ b/oci/catalog/volume-policy.json @@ -0,0 +1,120 @@ +{ + "schema_version": "0.1.0", + "kind": "proxmenux.oci-volume-policy", + "description": "Paths that hold content of the user: media libraries, photos, shared files, downloads and model or backup collections. They are offered as a container volume or a host directory, and the installation asks which one. Every other path is application state and is kept in a container volume without asking.", + "shared_paths": [ + "/DATA", + "/Media", + "/Music", + "/RoonBackups", + "/app/Downloads", + "/audiobooks", + "/backups", + "/books", + "/comics", + "/data/downloads", + "/data/models", + "/data/movies", + "/data/nes/roms", + "/data/outputs", + "/data/tvshows", + "/data1", + "/data2", + "/download", + "/downloads", + "/files", + "/folder", + "/gallery", + "/home/nonroot/pdfding/media", + "/incomplete-downloads", + "/libraries", + "/mame", + "/manga", + "/media", + "/media/frigate", + "/mnt/share1", + "/mnt/share2", + "/models", + "/movies", + "/music", + "/notes", + "/opt/notebooks", + "/output", + "/photoprism/originals", + "/pictures", + "/playlist", + "/playlists", + "/podcasts", + "/project", + "/recordings", + "/romm/library", + "/source", + "/storage", + "/sync", + "/temp", + "/tv", + "/usr/src/paperless/consume", + "/usr/src/paperless/export", + "/var/file_drop_files", + "/w", + "/watch", + "/workspace/TurboDiffusion/checkpoints_host", + "/workspace/TurboDiffusion/outputs" + ], + "applications": { + "crafty": [ + "/crafty/import" + ], + "doublecommander": [ + "/data" + ], + "downtify": [ + "/data" + ], + "emulatorjs": [ + "/data" + ], + "flexget": [ + "/data" + ], + "immich": [ + "/data" + ], + "kavita": [ + "/data" + ], + "komga": [ + "/data" + ], + "navidrome": [ + "/data" + ], + "nextcloud": [ + "/data" + ], + "plex-official": [ + "/data" + ], + "projectsend": [ + "/data" + ], + "psitransfer": [ + "/data" + ], + "qdirstat": [ + "/data" + ], + "rclone": [ + "/data" + ], + "rsnapshot": [ + "/data" + ], + "snapotter": [ + "/data" + ], + "unpackerr": [ + "/data" + ] + } +} diff --git a/oci/proxmenux-oci.sh b/oci/proxmenux-oci.sh new file mode 100755 index 00000000..762290b2 --- /dev/null +++ b/oci/proxmenux-oci.sh @@ -0,0 +1,40 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +ROOT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd) +VENV_DIR="$ROOT_DIR/.venv" +REQUIREMENTS="$ROOT_DIR/requirements.txt" +STAMP="$VENV_DIR/.requirements.sha256" + +command -v python3 >/dev/null 2>&1 || { + echo "ERROR: se necesita Python 3 en el Mac." >&2 + exit 1 +} + +if python3 -c 'import yaml, jsonschema' >/dev/null 2>&1; then + PYTHON=python3 +else + if [[ ! -x "$VENV_DIR/bin/python" ]] || ! "$VENV_DIR/bin/python" -m pip --version >/dev/null 2>&1; then + echo "Preparando entorno Python local..." + rm -rf "$VENV_DIR" + python3 -m venv "$VENV_DIR" || { + echo "ERROR: no se pudo crear venv. En Debian instala python3-venv, python3-yaml y python3-jsonschema." >&2 + exit 1 + } + fi + if command -v shasum >/dev/null 2>&1; then + CURRENT_HASH=$(shasum -a 256 "$REQUIREMENTS" | awk '{print $1}') + else + CURRENT_HASH=$(sha256sum "$REQUIREMENTS" | awk '{print $1}') + fi + INSTALLED_HASH=$(cat "$STAMP" 2>/dev/null || true) + if [[ "$CURRENT_HASH" != "$INSTALLED_HASH" ]]; then + echo "Instalando dependencias verificables del conversor..." + "$VENV_DIR/bin/python" -m pip install --disable-pip-version-check -r "$REQUIREMENTS" + printf '%s\n' "$CURRENT_HASH" >"$STAMP" + fi + PYTHON="$VENV_DIR/bin/python" +fi + +export PYTHONPATH="$ROOT_DIR/src${PYTHONPATH:+:$PYTHONPATH}" +exec "$PYTHON" -m proxmenux_oci "$@" diff --git a/oci/remote/allocate_private_network.py b/oci/remote/allocate_private_network.py new file mode 100644 index 00000000..df846201 --- /dev/null +++ b/oci/remote/allocate_private_network.py @@ -0,0 +1,118 @@ +#!/usr/bin/env python3 +from __future__ import annotations + +import ipaddress +import json +import re +import subprocess +import sys +from pathlib import Path + +from oci_ui import translate + + +def command_output(*command: str) -> str: + result = subprocess.run(command, text=True, capture_output=True, check=False) + return result.stdout + + +def existing_bridges() -> set[str]: + bridges: set[str] = set() + for line in command_output("ip", "-o", "link", "show").splitlines(): + match = re.match(r"^\d+: ([^:@]+)", line) + if match: + bridges.add(match.group(1)) + for path in Path("/etc/pve/lxc").glob("*.conf"): + text = path.read_text(encoding="utf-8", errors="ignore") + bridges.update(re.findall(r"(?:^|,)bridge=([^,\s]+)", text, re.MULTILINE)) + interface_paths = [Path("/etc/network/interfaces")] + interface_paths.extend(Path("/etc/network/interfaces.d").glob("*")) + for path in interface_paths: + if not path.is_file(): + continue + text = path.read_text(encoding="utf-8", errors="ignore") + bridges.update( + re.findall(r"^(?:auto|iface)\s+(vmbr\d+)\b", text, re.MULTILINE) + ) + return bridges + + +def existing_networks() -> list[ipaddress.IPv4Network]: + networks: list[ipaddress.IPv4Network] = [] + for line in command_output("ip", "-4", "route", "show").splitlines(): + token = line.split(maxsplit=1)[0] + if token == "default": + continue + try: + networks.append(ipaddress.ip_network(token, strict=False)) + except ValueError: + pass + for path in Path("/etc/pve/lxc").glob("*.conf"): + text = path.read_text(encoding="utf-8", errors="ignore") + for address in re.findall(r"(?:^|,)ip=(\d+\.\d+\.\d+\.\d+/\d+)", text, re.MULTILINE): + try: + networks.append(ipaddress.ip_interface(address).network) + except ValueError: + pass + return networks + + +def allocate_network( + deployment: dict, + bridges: set[str], + occupied: list[ipaddress.IPv4Network], +) -> tuple[str, ipaddress.IPv4Network] | None: + network = deployment.get("network", {}) + if network.get("private_allocation") != "automatic": + return None + + original = ipaddress.ip_network(network["private_subnet"], strict=True) + if original.prefixlen != 24: + raise ValueError(translate("Automatic private network allocation requires a /24 subnet")) + + selected: tuple[str, ipaddress.IPv4Network] | None = None + for index in range(0, 178): + bridge = f"vmbr{10 + index}" + candidate = ipaddress.ip_network(f"10.77.{index}.0/24") + if bridge in bridges or any(candidate.overlaps(item) for item in occupied): + continue + selected = bridge, candidate + break + if selected is None: + raise SystemExit(translate("No free ProxMenux private /24 network is available")) + + bridge, candidate = selected + for key, value in list(network.items()): + if not key.endswith("_address") or not isinstance(value, str): + continue + interface = ipaddress.ip_interface(value) + if interface.ip not in original: + continue + host_offset = int(interface.ip) - int(original.network_address) + network[key] = f"{candidate.network_address + host_offset}/{candidate.prefixlen}" + network["private_bridge"] = bridge + network["private_subnet"] = str(candidate) + network["private_allocation"] = "allocated" + return bridge, candidate + + +def main() -> int: + if len(sys.argv) != 2: + raise SystemExit("usage: allocate_private_network.py DEPLOYMENT.json") + path = Path(sys.argv[1]) + deployment = json.loads(path.read_text(encoding="utf-8")) + try: + selected = allocate_network(deployment, existing_bridges(), existing_networks()) + except ValueError as exc: + raise SystemExit(str(exc)) from exc + if selected is None: + return 0 + + bridge, candidate = selected + path.write_text(json.dumps(deployment, indent=2, ensure_ascii=True) + "\n", encoding="utf-8") + print(f"{translate('Private network assigned automatically:')} {bridge} ({candidate})") + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/oci/remote/configure_jellyfin_encoding.py b/oci/remote/configure_jellyfin_encoding.py new file mode 100644 index 00000000..a54d6707 --- /dev/null +++ b/oci/remote/configure_jellyfin_encoding.py @@ -0,0 +1,101 @@ +#!/usr/bin/env python3 +from __future__ import annotations + +import json +import os +import shutil +import sys +import tempfile +import xml.etree.ElementTree as ET +from pathlib import Path + +from oci_ui import translate + + +def fail(message: str) -> None: + raise SystemExit(message) + + +def resolve_path(rootfs: Path, candidates: list[str]) -> Path: + rootfs = rootfs.resolve() + for candidate in candidates: + if not candidate.startswith("/") or "\x00" in candidate: + fail(f"{translate('Invalid configuration path:')} {candidate!r}") + resolved = (rootfs / candidate.lstrip("/")).resolve() + if rootfs not in resolved.parents: + fail(f"{translate('The path escapes the rootfs:')} {candidate}") + if resolved.is_file(): + return resolved + fail(translate("Jellyfin has not created encoding.xml in any declared path")) + + +def update_encoding(rootfs: Path, configuration: dict[str, object]) -> tuple[Path, bool]: + path = resolve_path(rootfs, list(configuration.get("candidate_paths", []))) + tree = ET.parse(path) + root = tree.getroot() + changed = False + + for tag, requested in dict(configuration.get("settings", {})).items(): + if not isinstance(requested, str): + fail(f"{translate('The setting has no final value:')} {tag}") + element = root.find(tag) + if element is None: + element = ET.SubElement(root, tag) + changed = True + if (element.text or "") != requested: + element.text = requested + changed = True + + for tag, requested_values in dict(configuration.get("lists", {})).items(): + if not isinstance(requested_values, list) or not all( + isinstance(value, str) for value in requested_values + ): + fail(f"{translate('Invalid list:')} {tag}") + element = root.find(tag) + if element is None: + element = ET.SubElement(root, tag) + changed = True + existing = [child.text or "" for child in list(element)] + if existing != requested_values: + for child in list(element): + element.remove(child) + for value in requested_values: + ET.SubElement(element, "string").text = value + changed = True + + if not changed: + return path, False + + backup = path.with_name(f"{path.name}.bak-proxmenux") + if not backup.exists(): + shutil.copy2(path, backup) + os.chown(backup, path.stat().st_uid, path.stat().st_gid) + + stat = path.stat() + fd, temporary_name = tempfile.mkstemp(prefix=f".{path.name}.", dir=path.parent) + temporary = Path(temporary_name) + try: + with os.fdopen(fd, "wb") as stream: + tree.write(stream, encoding="utf-8", xml_declaration=True) + stream.flush() + os.fsync(stream.fileno()) + os.chmod(temporary, stat.st_mode) + os.chown(temporary, stat.st_uid, stat.st_gid) + os.replace(temporary, path) + finally: + temporary.unlink(missing_ok=True) + return path, True + + +def main() -> None: + if len(sys.argv) != 3: + fail(f"{translate('Usage:')} configure_jellyfin_encoding.py ROOTFS CONFIGURATION_JSON") + rootfs = Path(sys.argv[1]) + configuration = json.loads(sys.argv[2]) + path, changed = update_encoding(rootfs, configuration) + state = "updated" if changed else "already applied" + print(f"Jellyfin configuration {state}: /{path.relative_to(rootfs.resolve())}") + + +if __name__ == "__main__": + main() diff --git a/oci/remote/configure_rclone_mount.sh b/oci/remote/configure_rclone_mount.sh new file mode 100755 index 00000000..013b9d32 --- /dev/null +++ b/oci/remote/configure_rclone_mount.sh @@ -0,0 +1,203 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +TEMPLATE_FILE=${1:?template JSON required} +DEPLOYMENT_FILE=${2:?deployment JSON required} +DRY_RUN=${3:-0} +SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd) +source "$SCRIPT_DIR/oci_ui.sh" +PUBLISHER_SOURCE="${SCRIPT_DIR}/rclone_mount_publish.py" + +die() { + stop_spinner + msg_error "$*" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + exit 1 +} + +UNEXPECTED_FAILURE=0 +report_unexpected_failure() { + local status=${1:-$?} + stop_spinner + if (( status != 0 && UNEXPECTED_FAILURE == 1 )); then + msg_error "$(translate "The configuration stopped because of an unexpected error")" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + fi + return 0 +} +trap 'report_unexpected_failure' EXIT +trap 'UNEXPECTED_FAILURE=1; oci_log "Command failed at line $LINENO (${FUNCNAME[0]:-main})"' ERR + +require_command() { + command -v "$1" >/dev/null 2>&1 || die "$(translate "Missing required command:") $1" +} + +jqr() { + jq -er "$1" "$DEPLOYMENT_FILE" +} + +safe_absolute_path() { + local path=$1 + [[ $path == /* && $path != / && $path != *[[:space:],]* && $path != *..* ]] +} + +[[ $EUID -eq 0 ]] || die "$(translate "The configuration must run as root on Proxmox VE")" +oci_log_init "rclone-mount" +for command in pct jq python3 mountpoint findmnt systemctl systemd-run lxc-info base64; do + require_command "$command" +done +[[ -r $PUBLISHER_SOURCE ]] || die "$(translate "The FUSE publication helper was not found")" + +VMID=$(jqr '.vmid') +REMOTE_NAME=$(jqr '.remote_name') +REMOTE_PATH=$(jq -r '.remote_path // ""' "$DEPLOYMENT_FILE") +MOUNT_NAME=$(jqr '.mount_name') +VFS_CACHE_MODE=$(jqr '.vfs_cache_mode') +SHARED_PARENT=$(jqr '.shared_mount_root_parent') +SHARED_RW=$(jqr '.shared_mount_root') +SHARED_RO=$(jqr '.shared_mount_read_only_root') +[[ $VMID =~ ^[0-9]+$ ]] || die "$(translate "Invalid VMID")" +[[ $REMOTE_NAME =~ ^[A-Za-z0-9._-]{1,64}$ ]] || die "$(translate "Invalid remote name")" +[[ $MOUNT_NAME =~ ^[A-Za-z0-9._-]{1,64}$ ]] || die "$(translate "Invalid mount name")" +[[ $REMOTE_PATH != /* && $REMOTE_PATH != *$'\n'* && $REMOTE_PATH != *$'\r'* ]] \ + || die "$(translate "Invalid remote path")" +case "$VFS_CACHE_MODE" in off|minimal|writes|full) ;; *) die "$(translate "Invalid VFS cache mode")" ;; esac +for path in "$SHARED_PARENT" "$SHARED_RW" "$SHARED_RO"; do + safe_absolute_path "$path" || die "$(translate "Invalid host path:") $path" +done +[[ $SHARED_RW == "$SHARED_PARENT"/* && $SHARED_RO == "$SHARED_PARENT"/* ]] \ + || die "$(translate "The published views must be inside the common root")" + +pct config "$VMID" >/dev/null 2>&1 || die "$(translate "The container does not exist:") CT $VMID" +CONFIG=$(cat "/etc/pve/lxc/${VMID}.conf") +grep -q '^unprivileged: 0$' <<<"$CONFIG" || die "$(translate "Rclone mount requires a privileged container")" +grep -Eq '^features: .*(^|,)fuse=1(,|$)' <<<"$CONFIG" \ + || grep -q 'fuse=1' <<<"$CONFIG" \ + || die "$(translate "The container does not have the fuse=1 feature enabled")" + +msg_info "$(translate "Checking the remote...")" +STATUS=$(pct status "$VMID" | awk '{print $2}') +if [[ $STATUS != running ]]; then + oci_log "Starting CT $VMID temporarily to check the remote" + oci_quiet pct start "$VMID" + for _ in $(seq 1 30); do + pct exec "$VMID" -- /usr/local/bin/rclone version >/dev/null 2>&1 && break + sleep 1 + done +fi +REMOTES=$(pct exec "$VMID" -- /usr/local/bin/rclone listremotes \ + --config /config/rclone/rclone.conf 2>/dev/null || true) +grep -Fxq "${REMOTE_NAME}:" <<<"$REMOTES" \ + || die "$(translate "The remote does not exist; create and authorize it first in the WebUI:") ${REMOTE_NAME}:" +msg_ok "$(translate "Remote verified:") ${REMOTE_NAME}:" + +if [[ $DRY_RUN == 1 ]]; then + msg_ok "$(translate "Dry run completed; the container and the mounts were not changed.")" + exit 0 +fi + +RC_USER=$(sed -n 's/^lxc\.environment\.runtime: RCLONE_RC_USER=//p' "/etc/pve/lxc/${VMID}.conf" | tail -n1) +RC_PASS=$(sed -n 's/^lxc\.environment\.runtime: RCLONE_RC_PASS=//p' "/etc/pve/lxc/${VMID}.conf" | tail -n1) +if [[ -z $RC_USER || -z $RC_PASS ]]; then + RC_USER=$(pct exec "$VMID" -- sh -c "sed -n 's/^username=//p' /config/rclone/webui.credentials" 2>/dev/null || true) + RC_PASS=$(pct exec "$VMID" -- sh -c "sed -n 's/^password=//p' /config/rclone/webui.credentials" 2>/dev/null || true) +fi +[[ -n $RC_USER && -n $RC_PASS ]] || die "$(translate "The persistent WebUI credentials were not found")" + +msg_info "$(translate "Applying the mount mode...")" +oci_quiet pct exec "$VMID" -- mkdir -p "/data/mounts/${MOUNT_NAME}" +oci_quiet pct stop "$VMID" + +BACKUP_CONF=$(mktemp "/tmp/proxmenux-rclone-${VMID}.conf.XXXXXX") +cp "/etc/pve/lxc/${VMID}.conf" "$BACKUP_CONF" +ROLLBACK=1 +rollback() { + local status=$? + report_unexpected_failure "$status" + if (( status != 0 && ROLLBACK == 1 )); then + msg_info "$(translate "Restoring the previous Rclone configuration...")" + systemctl stop "proxmenux-rclone-publish-${VMID}.service" >/dev/null 2>&1 || true + mountpoint -q "$SHARED_RO/$MOUNT_NAME" && umount -l "$SHARED_RO/$MOUNT_NAME" >>"$OCI_LOG" 2>&1 || true + mountpoint -q "$SHARED_RW/$MOUNT_NAME" && umount -l "$SHARED_RW/$MOUNT_NAME" >>"$OCI_LOG" 2>&1 || true + cp "$BACKUP_CONF" "/etc/pve/lxc/${VMID}.conf" || true + pct start "$VMID" >/dev/null 2>&1 || true + msg_ok "$(translate "Previous Rclone configuration restored")" + fi + rm -f "$BACKUP_CONF" + exit "$status" +} +trap rollback EXIT + +install -d -m 0755 /usr/local/libexec /var/lib/vz/snippets \ + "$SHARED_PARENT" "$SHARED_RW/$MOUNT_NAME" "$SHARED_RO/$MOUNT_NAME" +install -m 0755 "$PUBLISHER_SOURCE" /usr/local/libexec/proxmenux-oci-mount-publish + +WAITER=$(jq -er '.proxmox.laboratory_contract.generated_assets["mount-publication-waiter"].content' "$TEMPLATE_FILE") +printf '%s\n' "$WAITER" >/usr/local/libexec/proxmenux-oci-mount-wait +chmod 0755 /usr/local/libexec/proxmenux-oci-mount-wait + +HOOK=$(jq -er '.proxmox.laboratory_contract.generated_assets["proxmox-hookscript"].content_template' "$TEMPLATE_FILE") +HOOK=${HOOK//\{\{mount_name\}\}/$MOUNT_NAME} +HOOK=${HOOK//\{\{shared_mount_root\}\}/$SHARED_RW} +HOOK=${HOOK//\{\{shared_mount_read_only_root\}\}/$SHARED_RO} +HOOK=${HOOK//\{\{shared_mount_root_parent\}\}/$SHARED_PARENT} +HOOK_PATH="/var/lib/vz/snippets/proxmenux-rclone-${VMID}-fuse-hook.sh" +printf '%s\n' "$HOOK" >"$HOOK_PATH" +chmod 0755 "$HOOK_PATH" + +oci_quiet pct mount "$VMID" +ROOTFS="/var/lib/lxc/${VMID}/rootfs" +install -d -m 0755 "$ROOTFS/usr/local/bin" "$ROOTFS/config/rclone" +printf 'username=%s\npassword=%s\n' "$RC_USER" "$RC_PASS" \ + >"$ROOTFS/config/rclone/webui.credentials" +chmod 0600 "$ROOTFS/config/rclone/webui.credentials" +WRAPPER=$(jq -er '.proxmox.laboratory_contract.generated_assets["mount-mode-wrapper"].content_template' "$TEMPLATE_FILE") +REMOTE_NAME_B64=$(printf '%s' "$REMOTE_NAME" | base64 -w0) +REMOTE_PATH_B64=$(printf '%s' "$REMOTE_PATH" | base64 -w0) +WRAPPER=${WRAPPER//\{\{remote_name_base64\}\}/$REMOTE_NAME_B64} +WRAPPER=${WRAPPER//\{\{remote_path_base64\}\}/$REMOTE_PATH_B64} +WRAPPER=${WRAPPER//\{\{mount_name\}\}/$MOUNT_NAME} +WRAPPER=${WRAPPER//\{\{vfs_cache_mode\}\}/$VFS_CACHE_MODE} +WRAPPER=${WRAPPER//\{\{webui_port\}\}/5572} +printf '%s\n' "$WRAPPER" >"$ROOTFS/usr/local/bin/rclone-mount-lxc-start" +chmod 0755 "$ROOTFS/usr/local/bin/rclone-mount-lxc-start" +oci_quiet pct unmount "$VMID" + +sed -i -E '/^lxc\.environment\.runtime: RCLONE_RC_(USER|PASS)=/d' "/etc/pve/lxc/${VMID}.conf" +oci_quiet pct set "$VMID" --entrypoint /usr/local/bin/rclone-mount-lxc-start +sed -i -E '/^hookscript:/d' "/etc/pve/lxc/${VMID}.conf" +oci_quiet pct set "$VMID" --hookscript "local:snippets/$(basename "$HOOK_PATH")" +msg_ok "$(translate "Mount mode applied")" + +msg_info "$(translate "Starting Rclone and waiting for the FUSE mount...")" +oci_quiet pct start "$VMID" +PUBLISHED_RW="$SHARED_RW/$MOUNT_NAME" +PUBLISHED_RO="$SHARED_RO/$MOUNT_NAME" +for attempt in $(seq 1 120); do + if mountpoint -q "$PUBLISHED_RW" && mountpoint -q "$PUBLISHED_RO"; then + break + fi + [[ $(pct status "$VMID" 2>/dev/null) == 'status: running' ]] \ + || die "$(translate "The container stopped before publishing the mount")" + msg_progress "$(translate "Waiting for the FUSE mount:") ${attempt}/120 s" + sleep 1 +done +mountpoint -q "$PUBLISHED_RW" || die "$(translate "The read/write view was not published")" +mountpoint -q "$PUBLISHED_RO" || die "$(translate "The read-only view was not published")" +findmnt -T "$PUBLISHED_RO" -n -o VFS-OPTIONS | tr ',' '\n' | grep -qx ro \ + || die "$(translate "The read-only view does not apply the expected protection")" + +IP=$(lxc-info -n "$VMID" -iH 2>/dev/null | grep -m1 -E '^[0-9]+\.' || true) +RESULT=$(jq -nc --argjson vmid "$VMID" --arg ip "$IP" --arg remote "$REMOTE_NAME" \ + --arg mount "$MOUNT_NAME" --arg rw "$PUBLISHED_RW" --arg ro "$PUBLISHED_RO" \ + --arg log "$OCI_LOG" \ + '{vmid:$vmid,ip:(if $ip == "" then null else $ip end),remote:$remote,mount_name:$mount,read_write_path:$rw,read_only_path:$ro,log:$log}') +ROLLBACK=0 +msg_ok "$(translate "Rclone mount active")" +printf 'PROXMENUX_RESULT=%s\n' "$(printf '%s' "$RESULT" | base64 -w0)" diff --git a/oci/remote/haos_healthcheck.py b/oci/remote/haos_healthcheck.py new file mode 100644 index 00000000..da50a2fb --- /dev/null +++ b/oci/remote/haos_healthcheck.py @@ -0,0 +1,172 @@ +"""Verify the nested HAOS runtime without accepting its temporary landing page.""" +import argparse +import ipaddress +import json +import os +import shutil +import subprocess +import sys +import time +import traceback +import urllib.error +import urllib.request + +from oci_ui import log, msg_progress, translate + + +REQUIRED = ('hassio_supervisor', 'homeassistant', 'hassio_cli', 'hassio_dns', + 'hassio_audio', 'hassio_multicast', 'hassio_observer') +OCI_LOG = os.environ.get('OCI_LOG') + + +class Pending(RuntimeError): + """A known first-boot stage, safe to show without printing container secrets.""" + + +def note(text): + """Detail for the run log; without one, for stderr.""" + try: + if OCI_LOG: + log(OCI_LOG, text) + return + except OSError: + pass + print(text, file=sys.stderr, flush=True) + + +def show_progress(elapsed, timeout, reason): + text = f"{translate('Waiting for Home Assistant OS...')} {elapsed}/{timeout} s · {reason}" + width = max(20, shutil.get_terminal_size((80, 24)).columns - 6) + if len(text) > width: + text = text[:width - 1] + '…' + msg_progress(text) + + +def pending_reason(items, supervisor_logs=''): + if 'No Supervisor connectivity' in supervisor_logs: + return translate('Supervisor reports no connectivity; retrying to get versions and install components') + running = {i.get('Name', '').lstrip('/') for i in items + if isinstance(i, dict) and i.get('State', {}).get('Running') is True} + missing = [name for name in REQUIRED if name not in running] + if missing: + return translate('Pending components:') + ' ' + ', '.join(missing) + return translate('Core is still on the initial installation page') + + +def capture(argv, timeout=15, merge_stderr=False): + return subprocess.run(argv, check=True, stdout=subprocess.PIPE, + stderr=subprocess.STDOUT if merge_stderr else subprocess.PIPE, text=True, + timeout=timeout).stdout + + +def supervisor_ready(value): + return (isinstance(value, dict) and value.get('result') == 'ok' + and isinstance(value.get('data'), dict) + and value.get('data', {}).get('healthy') is True + and value.get('data', {}).get('supported') is True) + + +def containers_ready(items): + if not isinstance(items, list) or any(not isinstance(item, dict) for item in items): + return False + by_name = {item.get('Name', '').lstrip('/'): item for item in items} + return (all(by_name.get(name, {}).get('State', {}).get('Running') is True + for name in REQUIRED) + and 'landingpage' not in by_name['homeassistant'].get('Config', {}).get('Image', '').lower() + and bool(by_name['homeassistant'].get('Config', {}).get('Image'))) + + +def http_ready(url, timeout=5): + # Do not route private healthchecks through an environment HTTP proxy. + opener = urllib.request.build_opener(urllib.request.ProxyHandler({})) + try: + with opener.open(url, timeout=timeout) as response: + return response.status == 200 + except (OSError, urllib.error.URLError): + return False + + +def probe(vmid, ip, remaining): + def run(args): + return capture(args, timeout=max(0.1, min(15, remaining()))) + if run(['pct', 'status', str(vmid)]).strip() != 'status: running': + raise RuntimeError(translate('The LXC has stopped')) + docker = ['pct', 'exec', str(vmid), '--', 'docker', '-H', 'unix:///run/docker-real.sock'] + try: + containers = json.loads(run(docker + ['inspect', *REQUIRED])) + except subprocess.CalledProcessError as error: + # docker inspect returns existing objects and exit 1 for missing names. + containers = json.loads(error.stdout or '[]') + if not containers_ready(containers): + logs = '' + try: + logs = capture(docker + ['logs', '--tail', '25', 'hassio_supervisor'], + timeout=max(0.1, min(15, remaining())), merge_stderr=True) + except subprocess.SubprocessError: + pass + raise Pending(pending_reason(containers, logs)) + supervisor = json.loads(run(docker + ['exec', 'hassio_cli', 'ha', '--raw-json', 'supervisor', 'info'])) + if not supervisor_ready(supervisor): + raise Pending(translate('Supervisor does not confirm healthy and supported yet')) + if not http_ready(f'http://{ip}:4357/', max(0.1, min(5, remaining()))): + raise Pending(translate('Observer is not responding on port 4357')) + for port in (80, 8123): + if http_ready(f'http://{ip}:{port}/', max(0.1, min(5, remaining()))): + return [{'label': 'Home Assistant', 'url': f'http://{ip}:{port}/'}, + {'label': 'Home Assistant Observer', 'url': f'http://{ip}:4357/'}] + raise Pending(translate('Core is running, but not responding over HTTP on 80/8123')) + + +def wait_ready(vmid, ip, timeout): + started = time.monotonic() + remaining = lambda: timeout - (time.monotonic() - started) + last_reason = None + while remaining() > 0: + reason = translate('Docker/CLI not available yet or no valid answer') + try: + urls = probe(vmid, ip, remaining) + if urls and remaining() > 0: + note('HAOS: Supervisor healthy/supported, Core and internal services running.') + return urls + except Pending as error: + reason = str(error) + except (subprocess.SubprocessError, ValueError, KeyError, TypeError): + # Missing CLI/containers are expected while upstream pulls its images. + pass + elapsed = int(time.monotonic() - started) + if reason != last_reason: + note(f'Waiting for HAOS: {elapsed}/{timeout}s; {reason}.') + last_reason = reason + show_progress(elapsed, timeout, reason) + time.sleep(max(0, min(5, remaining()))) + raise RuntimeError(translate('Time is up; Home Assistant OS could not be confirmed as running')) + + +def main(): + parser = argparse.ArgumentParser() + parser.add_argument('--vmid', type=int, required=True) + parser.add_argument('--ip', required=True) + parser.add_argument('--timeout', type=int, default=1200) + args = parser.parse_args() + # stdout carries only the JSON result; progress lines go to stderr. + result_stream = sys.stdout + sys.stdout = sys.stderr + try: + ipaddress.IPv4Address(args.ip) + if args.vmid < 100 or not 60 <= args.timeout <= 3600: + parser.error(translate('Invalid VMID or timeout')) + urls = wait_ready(args.vmid, args.ip, args.timeout) + except RuntimeError as error: + note(str(error)) + return 1 + except Exception: + note(traceback.format_exc()) + return 1 + finally: + sys.stdout = result_stream + print(json.dumps(urls)) + return 0 + + +if __name__ == '__main__': + sys.exit(main()) diff --git a/oci/remote/install_generic_stack.py b/oci/remote/install_generic_stack.py new file mode 100644 index 00000000..82e0c9c7 --- /dev/null +++ b/oci/remote/install_generic_stack.py @@ -0,0 +1,775 @@ +#!/usr/bin/env python3 +"""Host-side orchestration; only standard-library dependencies are needed on Proxmox.""" +from __future__ import annotations + +import base64 +import copy +import configparser +import fcntl +import hashlib +import http.cookiejar +import ipaddress +import json +import os +from pathlib import Path +import re +import socket +import subprocess +import sys +import tempfile +import time +import urllib.request +import urllib.parse +import uuid +import xml.etree.ElementTree as ET + +from allocate_private_network import allocate_network, existing_bridges, existing_networks +import oci_instances +from oci_ui import translate, msg_info, msg_ok, msg_warn, msg_error, msg_info2, stop_spinner, log + +HERE = Path(__file__).resolve().parent +LOG_DIR = Path(os.environ.get('OCI_LOG_DIR', '/var/log/proxmenux/oci')) +LOG = os.environ.get('OCI_LOG') or None +RESULT_MARKER = b'PROXMENUX_RESULT=' +ERROR_REPORTED = False + + +class ServiceFailed(RuntimeError): + """The child installer already printed its own error and log tail.""" + + +def access_address(address, gateway): + """ip= and gw= options of an access interface: DHCP or a static IPv4.""" + if address == 'dhcp': + return 'ip=dhcp' + try: + interface = ipaddress.IPv4Interface(address) if '/' in address else None + router = ipaddress.IPv4Address(gateway) if gateway else None + except ValueError: + interface = None + if interface is None or (router is not None and (router not in interface.network or router == interface.ip)): + raise RuntimeError(f"{translate('Invalid access address:')} {address} {gateway or ''}".rstrip()) + return f'ip={interface}' + (f',gw={router}' if router else '') + + +def init_log(name): + """Private run log shared with every child installer through OCI_LOG.""" + global LOG + if not LOG: + LOG_DIR.mkdir(parents=True, exist_ok=True) + try: + LOG_DIR.chmod(0o700) + except OSError: + pass + safe = re.sub(r'[^A-Za-z0-9._-]', '_', name or 'stack') + path = LOG_DIR / f"{safe}-{time.strftime('%Y%m%d-%H%M%S')}.log" + os.close(os.open(path, os.O_WRONLY | os.O_CREAT | os.O_TRUNC, 0o600)) + path.chmod(0o600) + LOG = str(path) + os.environ['OCI_LOG'] = LOG + + +def log_tail(lines=12): + if not LOG: + return [] + try: + content = Path(LOG).read_text(errors='replace').splitlines() + except OSError: + return [] + return content[-lines:] + + +def report_error(text, tail=True): + """msg_error plus the end of the run log, like die() in the bash installers.""" + global ERROR_REPORTED + ERROR_REPORTED = True + msg_error(text) + if not LOG: + return + if tail: + for line in log_tail(): + sys.stderr.write(' '+line+'\n') + sys.stderr.write(f" {translate('Full log:')} {LOG}\n") + sys.stderr.flush() + + +def persist_instances(deployment, services, primary_id=None): + template = json.loads(Path(sys.argv[1]).read_text()) if primary_id is not None else {} + with oci_instances.locked(oci_instances.ROOT): + if primary_id is not None: + oci_instances.save_assembly(oci_instances.ROOT, primary_id, template, deployment, services) + oci_instances.resume_assembly(oci_instances.ROOT, primary_id) + else: + oci_instances.publish_stack(oci_instances.ROOT, None, template, deployment, services) + + +def run(*args, capture=True, timeout=180): + argv = list(map(str,args)) + if capture: + try: + return subprocess.run(argv, check=True, text=True, stdout=subprocess.PIPE, + stderr=subprocess.PIPE, timeout=timeout).stdout + except subprocess.CalledProcessError as error: + log(LOG, '$ '+' '.join(argv)+'\n'+(error.stdout or '')+(error.stderr or '')) + raise + # Command output belongs to the run log, never to the terminal. + with open(LOG or os.devnull, 'a') as output: + return subprocess.run(argv, check=True, text=True, stdout=output, + stderr=subprocess.STDOUT, timeout=timeout).stdout + + +def exists(vmid): + return any(Path('/etc/pve/nodes').glob(f'*/lxc/{vmid}.conf')) or any(Path('/etc/pve/nodes').glob(f'*/qemu-server/{vmid}.conf')) + + +def retire_stale_contract(path, primary_id): + if not path.exists(): + return + if path.is_symlink(): + raise RuntimeError(translate('The previous stack contract is not safe; review it before reusing it')) + try: + contract = json.loads(path.read_text()) + if contract.get('schema') != 1 or not isinstance(contract.get('dependencies'),list): + raise ValueError('unrecognized structure') + ids = {primary_id} + for dependency in contract['dependencies']: + vmid = dependency['vmid'] + if type(vmid) is not int or vmid < 100: + raise ValueError('invalid VMID') + ids.add(vmid) + except (ValueError, KeyError, TypeError, AttributeError) as error: + raise RuntimeError(translate('The previous stack contract is not valid; it is not archived automatically')) from error + live = sorted(vmid for vmid in ids if exists(vmid)) + if live: + raise RuntimeError(f"{translate('The previous stack contract still has containers or VMs:')} {', '.join(map(str,live))}") + archive = path.with_name(f'proxmenux-retired-stack-{primary_id}-{uuid.uuid4().hex}.json') + path.rename(archive) + msg_info2(f"{translate('Orphan stack contract archived:')} CT {primary_id} → {archive}") + log(LOG, 'The shared hookscript is kept.') + + +def write_json(path, value): + path.write_text(json.dumps(value,indent=2)+'\n') + path.chmod(0o600) + + +def create_service(service, directory): + template = directory / 'template.json' + deployment = directory / 'deployment.json' + write_json(template, service['template']) + child_plan = copy.deepcopy(service['deployment']) + child_plan['mounts'] = [] + child_plan['stack_managed'] = True + write_json(deployment, child_plan) + # The child shares this run log; its steps are relayed as they are drawn + # (spinner frames included) and its result line is kept (one stack result). + environment = dict(os.environ, OCI_LOG=LOG or '', + OCI_SPINNER='1' if sys.stdout.isatty() or os.environ.get('OCI_SPINNER') == '1' else '0') + process = subprocess.Popen(['bash', str(HERE/'install_oci.sh'),str(template),str(deployment),'0'], + stdout=subprocess.PIPE,stderr=subprocess.STDOUT,env=environment) + result = None + try: + result = relay_child_output(process.stdout) + if process.wait() or result is None: + raise ServiceFailed(f"{translate('Could not create the service:')} {service['name']}") + finally: + if process.poll() is None: + process.terminate() + process.wait(timeout=30) + return result + + +def relay_child_output(stream): + """Copy the child output to the terminal as it arrives; return its PROXMENUX_RESULT.""" + output = sys.stdout.buffer + sys.stdout.flush() + pending = b'' + line_start = True + result = None + + def parse(line): + return json.loads(base64.b64decode(line[len(RESULT_MARKER):].strip())) + + while True: + chunk = os.read(stream.fileno(), 4096) + if not chunk: + break + pending += chunk + while pending: + if line_start and pending.startswith(RESULT_MARKER): + end = pending.find(b'\n') + if end < 0: + break + result = parse(pending[:end]) + pending = pending[end+1:] + continue + if line_start and RESULT_MARKER.startswith(pending): + break + cuts = [index for index in (pending.find(b'\n'), pending.find(b'\r')) if index >= 0] + if cuts: + cut = min(cuts)+1 + output.write(pending[:cut]) + pending = pending[cut:] + line_start = True + else: + output.write(pending) + pending = b'' + line_start = False + output.flush() + if pending: + if line_start and pending.startswith(RESULT_MARKER): + result = parse(pending) + else: + output.write(pending) + output.flush() + return result + + +def lan_access_urls(services, subnet, strict=True): + urls = [] + for service in services: + endpoint = service['healthcheck'].get('endpoint') + if not endpoint or not (service['main'] or service.get('frontend')): + continue + try: + addresses = run('lxc-info','-n',service['vmid'],'-iH').splitlines() + candidates = [] + for value in addresses: + try: + address = ipaddress.ip_address(value.strip()) + except ValueError: + continue + if address.version==4 and address not in subnet and not ( + address.is_loopback or address.is_link_local or address.is_unspecified or address.is_multicast): + candidates.append(str(address)) + if not candidates: + raise RuntimeError(f"{translate('No LAN address was obtained for the service:')} {service['name']}") + urls.append({'label':service['name'], + 'url':f"{endpoint['scheme']}://{candidates[0]}:{endpoint['port']}{endpoint['path']}"}) + except Exception: + if strict: + raise + return urls + + +def attach_mounts(service, temporary): + """Populate new managed volumes from the image, preserving its ownership.""" + vmid = service['vmid'] + root = Path(f'/var/lib/lxc/{vmid}/rootfs') + for index, mount in enumerate(service['deployment']['mounts']): + target = root / mount['container_path'].lstrip('/') + seed = temporary / f'seed-{vmid}-{index}' + seed.mkdir() + run('pct','mount',vmid) + try: + if not target.resolve().is_relative_to(root.resolve()) or target.is_symlink(): + raise RuntimeError(translate('Unsafe volume path')) + if target.is_dir(): + stat = target.stat() + owner = (stat.st_uid,stat.st_gid,stat.st_mode & 0o777) + if mount['type']=='managed-volume': + run('cp','-a',str(target)+'/.',str(seed)) + else: + owner = (100000,100000,0o755) + finally: + run('pct','unmount',vmid) + if mount['type']=='managed-volume': + value=f"{mount['source']}:{mount['size_gb']},mp={mount['container_path']},backup=1" + else: + source=Path(mount['source']) + if not source.is_absolute() or ',' in str(source) or '\n' in str(source): + raise RuntimeError(translate('Invalid shared path')) + if not source.exists(): + source.mkdir(parents=True) + os.chown(source,*owner[:2]) + source.chmod(owner[2]) + if not source.is_dir(): + raise RuntimeError(translate('The shared destination is not a directory')) + value=f"{source},mp={mount['container_path']},backup=0" + run('pct','set',vmid,f'--mp{index}',value) + if mount['type']=='managed-volume': + run('pct','mount',vmid) + try: + lost=target/'lost+found' + if lost.is_dir() and not lost.is_symlink(): + lost.rmdir() + run('cp','-a',str(seed)+'/.',str(target)) + os.chown(target,*owner[:2]) + target.chmod(owner[2]) + finally: + run('pct','unmount',vmid) + + if mount.get('read_only'): + config = run('pct', 'config', vmid) + current = next(line.split(': ', 1)[1] for line in config.splitlines() + if line.startswith(f'mp{index}: ')) + run('pct', 'set', vmid, f'--mp{index}', current + ',ro=1') + + +def wait_web(primary, url): + deadline = time.monotonic()+primary['healthcheck']['timeout_seconds'] + opener = urllib.request.build_opener(urllib.request.ProxyHandler({})) + while True: + if run('pct','status',primary['vmid']).strip()!='status: running': + raise RuntimeError(f"{translate('The container stopped:')} {primary['name']} (CT {primary['vmid']})") + try: + with opener.open(url,timeout=4) as response: + if response.status<400: + return + except Exception: + pass + if time.monotonic()>=deadline: + raise RuntimeError(f"{translate('The application did not pass its HTTP check:')} {primary['name']}") + time.sleep(3) + + +def qbittorrent_password_hash(password): + salt = os.urandom(16) + digest = hashlib.pbkdf2_hmac('sha512', password.encode(), salt, 100000, 64) + return base64.b64encode(salt).decode()+':'+base64.b64encode(digest).decode() + + +def seed_qbittorrent(service): + """Seed the image's official defaults in its new persistent config volume.""" + vmid = service['vmid'] + root = Path(f'/var/lib/lxc/{vmid}/rootfs') + run('pct','mount',vmid) + try: + directory = root/'config/qBittorrent' + defaults = root/'defaults/qBittorrent.conf' + target = directory/'qBittorrent.conf' + for path in (directory, target, defaults): + if path.is_symlink() or not path.resolve().is_relative_to(root.resolve()): + raise RuntimeError(translate('Unsafe qBittorrent configuration path')) + if target.exists(): + raise RuntimeError(translate('qBittorrent already has a configuration; it is not overwritten')) + config = configparser.ConfigParser(interpolation=None) + config.optionxform = str + config.read_string(defaults.read_text()) + if not config.has_section('Preferences'): + raise RuntimeError(translate('Unrecognized qBittorrent configuration format')) + config['Preferences'][r'WebUI\Username'] = service['setup_credentials']['username'] + config['Preferences'][r'WebUI\Password_PBKDF2'] = '"@ByteArray('+qbittorrent_password_hash(service['setup_credentials']['password'])+')"' + directory.mkdir(exist_ok=True,mode=0o700) + owner = 101000 if service['deployment']['security']['unprivileged'] else 1000 + os.chown(directory,owner,owner) + fd = os.open(target, os.O_WRONLY | os.O_CREAT | os.O_EXCL, 0o600) + with os.fdopen(fd,'w') as output: + config.write(output,space_around_delimiters=False) + os.chown(target,owner,owner) + finally: + run('pct','unmount',vmid) + + +def same_download_path(actual, expected): + return isinstance(actual,str) and actual.startswith('/') and actual.rstrip('/')==expected.rstrip('/') + + +def configure_qbittorrent(service, selected): + port = service['healthcheck']['endpoint']['port'] + base = f"http://{service['ip']}:{port}" + cookies = http.cookiejar.CookieJar() + opener = urllib.request.build_opener(urllib.request.ProxyHandler({}),urllib.request.HTTPCookieProcessor(cookies)) + + def api(path, values=None, with_status=False): + request = urllib.request.Request(base+'/api/v2/'+path, + data=urllib.parse.urlencode(values).encode() if values is not None else None, + headers={'Referer':base+'/'}) + with opener.open(request,timeout=30) as response: + body = response.read() + return (getattr(response,'status',200),body) if with_status else body + + status, body = api('auth/login',service['setup_credentials'],with_status=True) + # 5.2 uses HTTP 204 and a port-scoped cookie; older releases return "Ok.". + legacy = status==200 and body.strip()==b'Ok.' + modern = status==204 and not body.strip() + cookie_name = f'QBT_SID_{port}' if modern else 'SID' + if not (legacy or modern) or not any(c.name==cookie_name and c.value for c in cookies): + raise RuntimeError(translate('qBittorrent: invalid login response or missing session cookie')) + try: + probe = json.loads(api('app/preferences')) + if not isinstance(probe,dict) or not isinstance(probe.get('save_path'),str): + raise RuntimeError(translate('qBittorrent: authenticated access to the preferences could not be verified')) + preferences = {'save_path':'/data/downloads/','temp_path':'/data/downloads/incomplete/', 'temp_path_enabled':True} + api('app/setPreferences',{'json':json.dumps(preferences)}) + actual = json.loads(api('app/preferences')) + if (not all(same_download_path(actual.get(k),preferences[k]) for k in ('save_path','temp_path')) + or actual.get('temp_path_enabled') is not True): + raise RuntimeError(translate('qBittorrent did not apply the download paths')) + categories = json.loads(api('torrents/categories')) + for app,category in [('sonarr','tv'),('radarr','movies')]: + if app not in selected: + continue + path = '/data/downloads/'+category + action = 'editCategory' if category in categories else 'createCategory' + api('torrents/'+action,{'category':category,'savePath':path}) + if not same_download_path(json.loads(api('torrents/categories')).get(category,{}).get('savePath'),path): + raise RuntimeError(f"{translate('qBittorrent did not apply the category:')} {category}") + finally: + api('auth/logout',{}) + + +def configure_arr(services): + """Use generated API keys and upstream schemas, without changing image files.""" + apps = {s['name']:s for s in services} + keys = {} + opener = urllib.request.build_opener(urllib.request.ProxyHandler({})) + for name, service in apps.items(): + if name == 'qbittorrent': + msg_info(translate('Configuring qBittorrent...')) + configure_qbittorrent(service,apps) + msg_ok(translate('qBittorrent configured')) + continue + if name not in ('prowlarr','sonarr','radarr','lidarr'): + continue + config = run('pct','exec',service['vmid'],'--','cat','/config/config.xml') + keys[name] = ET.fromstring(config).findtext('ApiKey') + if not keys[name]: + raise RuntimeError(f"{name}: {translate('the API key was not generated on the first start')}") + + def api(name, path, payload=None): + service = apps[name] + port = service['healthcheck']['endpoint']['port'] + request = urllib.request.Request(f"http://{service['ip']}:{port}{path}", + data=json.dumps(payload).encode() if payload is not None else None, + headers={'X-Api-Key':keys[name],'Content-Type':'application/json'}) + with opener.open(request, timeout=30) as response: + body = response.read() + return json.loads(body) if body else None + + for name, folder in (('sonarr','series'),('radarr','movies')): + if name not in apps: + continue + text = arr_texts(name) + msg_info(text['root_info']) + api(name,'/api/v3/system/status') + root = '/data/media/'+folder + if not any(x.get('path') == root for x in api(name,'/api/v3/rootfolder')): + api(name,'/api/v3/rootfolder',{'path':root}) + msg_ok(f"{text['root_ok']}: {root}") + if 'qbittorrent' in apps: + msg_info(text['client_info']) + qbit = apps['qbittorrent'] + schema = next((x for x in api(name,'/api/v3/downloadclient/schema') + if x.get('implementation')=='QBittorrent'),None) + if schema is None: + raise RuntimeError(f"{name}: {translate('the qBittorrent schema is not available')}") + schema.pop('id',None) + schema.update(name='qBittorrent',enable=True,priority=1) + category_key = 'tvCategory' if name=='sonarr' else 'movieCategory' + values = dict(qbit['setup_credentials'],host=qbit['ip'],port=qbit['healthcheck']['endpoint']['port'], + useSsl=False,urlBase='',apiKey='') + values[category_key] = 'tv' if name=='sonarr' else 'movies' + if not {'host','port','username','password',category_key}.issubset({f['name'] for f in schema['fields']}): + raise RuntimeError(f"{name}: {translate('incompatible qBittorrent schema')}") + for field in schema['fields']: + if field['name'] in values: + field['value'] = values[field['name']] + api(name,'/api/v3/downloadclient/test',schema) + api(name,'/api/v3/downloadclient',schema) + msg_ok(text['client_ok']) + if 'prowlarr' not in apps: + continue + msg_info(text['prowlarr_info']) + if any(x.get('name') == name for x in api('prowlarr','/api/v1/applications')): + msg_ok(text['prowlarr_ok']) + continue + schema = next((x for x in api('prowlarr','/api/v1/applications/schema') + if x.get('implementation','').lower()==name),None) + if schema is None: + raise RuntimeError(f"{translate('Prowlarr does not offer the application schema:')} {name}") + schema.pop('id',None) + schema.update(name=name,syncLevel='fullSync') + values = {'apiKey':keys[name], + 'baseUrl':f"http://{apps[name]['ip']}:{apps[name]['healthcheck']['endpoint']['port']}", + 'prowlarrUrl':f"http://{apps['prowlarr']['ip']}:{apps['prowlarr']['healthcheck']['endpoint']['port']}"} + for field in schema['fields']: + if field['name'] in values: + field['value'] = values[field['name']] + api('prowlarr','/api/v1/applications',schema) + msg_ok(text['prowlarr_ok']) + if 'qbittorrent' not in apps: + msg_info2(translate('The download client still needs to be configured.')) + msg_info2(translate('Indexers and quality profiles still need to be configured.')) + return keys + + +def arr_texts(name): + """Visible steps of the Sonarr/Radarr wiring, one literal per application.""" + if name == 'sonarr': + return {'root_info': translate('Configuring the Sonarr root folder...'), + 'root_ok': translate('Sonarr root folder configured'), + 'client_info': translate('Connecting Sonarr to qBittorrent...'), + 'client_ok': translate('Sonarr connected to qBittorrent'), + 'prowlarr_info': translate('Adding Sonarr to Prowlarr...'), + 'prowlarr_ok': translate('Sonarr added to Prowlarr')} + return {'root_info': translate('Configuring the Radarr root folder...'), + 'root_ok': translate('Radarr root folder configured'), + 'client_info': translate('Connecting Radarr to qBittorrent...'), + 'client_ok': translate('Radarr connected to qBittorrent'), + 'prowlarr_info': translate('Adding Radarr to Prowlarr...'), + 'prowlarr_ok': translate('Radarr added to Prowlarr')} + + +def prepare_suite_config(service): + """Prepare only newly allocated configuration volumes, never image binaries.""" + if service['name'] not in ('sabnzbd','seerr','unpackerr'): + return + vmid = service['vmid'] + root = Path(f'/var/lib/lxc/{vmid}/rootfs') + path = root/('app/config' if service['name']=='seerr' else 'config') + run('pct','mount',vmid) + try: + if path.is_symlink() or not path.resolve().is_relative_to(root.resolve()): + raise RuntimeError(translate('Unsafe private configuration path')) + if service.get('config_owner') is not None: + owner = service['config_owner'] + (100000 if service['deployment']['security']['unprivileged'] else 0) + os.chown(path,owner,owner) + if service['name']=='sabnzbd': + target = path/'sabnzbd.ini' + fd = os.open(target,os.O_WRONLY | os.O_CREAT | os.O_EXCL,0o600) + with os.fdopen(fd,'w') as output: + output.write('[misc]\ndownload_dir = /data/downloads/usenet-incomplete\ncomplete_dir = /data/downloads/usenet\n') + os.chown(target,101000,101000) + finally: + run('pct','unmount',vmid) + + +def configure_unpackerr(services, keys): + worker = next((s for s in services if s['name']=='unpackerr'),None) + if worker is None: + return + msg_info(translate('Configuring Unpackerr...')) + variables = {} + for service in services: + name = service['name'] + if name not in ('sonarr','radarr','lidarr'): + continue + prefix = 'UN_'+name.upper()+'_0_' + variables[prefix+'URL'] = f"http://{service['ip']}:{service['healthcheck']['endpoint']['port']}" + variables[prefix+'API_KEY'] = keys[name] + variables[prefix+'PATHS_0'] = '/data/downloads' + variables[prefix+'DELETE_ORIG'] = 'false' + config = Path(f"/etc/pve/lxc/{worker['vmid']}.conf") + content = config.read_text() + for key,value in variables.items(): + if '\n' in value or '\r' in value: + raise RuntimeError(translate('Invalid Unpackerr variable')) + content = re.sub(r'^lxc\.environment\.runtime: '+re.escape(key)+r'=.*\n','',content,flags=re.M) + content += 'lxc.environment.runtime: '+key+'='+value+'\n' + config.write_text(content) + run('pct','start',worker['vmid'],capture=False) + for _ in range(3): + time.sleep(1) + if run('pct','status',worker['vmid']).strip()!='status: running': + raise RuntimeError(translate('Unpackerr stopped during its first start')) + msg_ok(translate('Unpackerr configured')) + + +def finish_independent_suite(services, subnet): + log(LOG, 'First start to configure the applications; each container is independent.') + for service in services: + if service.get('deferred_setup'): + continue + msg_info(f"{translate('Starting the service:')} {service['name']}") + run('pct','start',service['vmid'],capture=False,timeout=600) + if service['healthcheck']['type']=='http': + wait_web(service,service['healthcheck']['url']) + msg_ok(f"{translate('Service ready:')} {service['name']}") + keys = configure_arr(services) + configure_unpackerr(services,keys) + result = {'suite_arr':True,'lifecycle_mode':'independent', + 'stack_vmids':{s['name']:s['vmid'] for s in services}, + 'urls':lan_access_urls(services,subnet),'credentials':[]} + for service in services: + if service['name']=='qbittorrent': + result['credentials'].append(dict(service['setup_credentials'],label='qBittorrent',change_required=False)) + return result + + +def main(): + deployment = json.loads(Path(sys.argv[2]).read_text()) + if deployment.get('deployment_kind') != 'generic-multi-lxc-stack': + raise RuntimeError(translate('Invalid stack contract')) + if len(sys.argv)>3 and sys.argv[3]=='1': + msg_info2(f"{translate('Containers:')} {len(deployment['services'])}") + msg_info2(translate('Startup: independent, without hookscript') if deployment.get('suite_arr') + else translate('Startup: coordinated by the stack startup hook')) + msg_ok(translate('Dry run completed; no changes were made.')) + return + if os.geteuid()!=0: + raise RuntimeError(translate('The installer must run as root on Proxmox VE')) + init_log(deployment.get('stack_name') or 'stack') + services = copy.deepcopy(deployment['services']) + independent = bool(deployment.get('suite_arr')) + primary = None if independent else next(s for s in services if s['main']) + created = [] + bridge_created = False + lifecycle = None + node = socket.gethostname() + # Serialize this installer's allocation through creation, and let pct enforce ownership. + msg_info(translate('Reserving a private network...')) + with open('/run/lock/proxmenux-private-network.lock','w') as lock, tempfile.TemporaryDirectory(prefix='proxmenux-stack-') as tmp: + fcntl.flock(lock,fcntl.LOCK_EX) + base = deployment.get('base_vmid') or int(run('pvesh','get','/cluster/nextid').strip()) + while any(exists(base+s['offset']) for s in services): + if deployment.get('base_vmid'): + raise RuntimeError(translate('The requested VMID block is already in use')) + base += 1 + selection = allocate_network(deployment,existing_bridges(),existing_networks()) + if selection is None: + raise RuntimeError(translate('The private network must be assigned automatically')) + bridge, subnet = selection + deployment['network'].update(private_bridge=bridge, private_subnet=str(subnet), + private_host_address=str(subnet.network_address+1)+'/24') + primary_id = base + aliases = [] + for s in services: + s['vmid'] = base+s['offset'] + s['ip'] = str(subnet.network_address+30+s['offset']) + for alias in s['aliases']: + if not re.fullmatch(r'[A-Za-z0-9][A-Za-z0-9_.-]*',alias): + raise RuntimeError(translate('Invalid service alias')) + aliases.append({'hostname':alias,'address':s['ip']}) + if not independent: + lifecycle = Path(f'/etc/pve/priv/proxmenux-stack-{primary_id}.json') + retire_stale_contract(lifecycle,primary_id) + try: + log(LOG, f"Stack {deployment['stack_name']}: CT {base}-{base+len(services)-1}; network {subnet} on {bridge}") + run('pvesh','create',f'/nodes/{node}/network','--iface',bridge,'--type','bridge','--autostart','1','--cidr',str(subnet.network_address+1)+'/24') + bridge_created = True + run('ip','link','add','name',bridge,'type','bridge') + run('ip','address','add',str(subnet.network_address+1)+'/24','dev',bridge) + run('ip','link','set',bridge,'up') + msg_ok(f"{translate('Private network:')} {bridge} ({subnet})") + if deployment.get('suite_arr') and deployment.get('shared_media'): + shared = Path(deployment['shared_media']) + for folder in [shared, shared/'downloads', shared/'downloads/incomplete', shared/'downloads/tv', + shared/'downloads/movies',shared/'downloads/music',shared/'downloads/usenet',shared/'downloads/usenet-incomplete', + shared/'media', shared/'media/series', shared/'media/movies',shared/'media/music']: + if not folder.exists(): + folder.mkdir(parents=True) + os.chown(folder,101000,101000) + folder.chmod(0o775) + results = {} + for order,s in enumerate(services,1): + plan = s['deployment'] + s['public_environment'] = {e['name']:e['value'] for e in plan['environment'] if '@STACK_LAN_IP@' in e['value']} + for e in plan['environment']: + e['value'] = e['value'].replace('@STACK_LAN_IP@',s['ip']) + plan['vmid'] = s['vmid'] + plan['extra_hosts'] = aliases + plan['network'].update(bridge=bridge,ipv4=s['ip']+'/24',gateway=None) + if exists(s['vmid']): + raise RuntimeError(f"{translate('The VMID was taken during the installation:')} {s['vmid']}") + msg_info2(f"{translate('Service:')} {s['name']}") + with tempfile.TemporaryDirectory(dir=tmp) as service_tmp: + results[s['name']] = create_service(s,Path(service_tmp)) + created.append(s['vmid']) + if s['deployment']['mounts']: + msg_info(translate('Attaching the volumes...')) + attach_mounts(s,Path(tmp)) + if s['deployment']['mounts']: + msg_ok(translate('Volumes attached')) + if deployment.get('suite_arr'): + prepare_suite_config(s) + if deployment.get('suite_arr') and s['name']=='qbittorrent': + seed_qbittorrent(s) + if not independent: + run('pct','set',s['vmid'],'--startup',f'order={order*10},up=5,down=30') + if s['main'] or s.get('frontend'): + address = access_address(s.get('frontend_ipv4') or 'dhcp', deployment['network'].get('frontend_gateway')) + run('pct','set',s['vmid'],'--net1',f"name=eth1,bridge={deployment['network']['frontend_bridge']},{address},host-managed=1,firewall=1,type=veth") + if s['healthcheck']['type']=='http': + endpoint = s['healthcheck']['endpoint'] + s['healthcheck']['url'] = f"{endpoint['scheme']}://{s['ip']}:{endpoint['port']}{endpoint['path']}" + if independent: + fcntl.flock(lock,fcntl.LOCK_UN) + result = finish_independent_suite(services,subnet) + persist_instances(deployment, services) + result.update(completion_notes=list(deployment.get('completion_notes',[])), log=LOG) + print('PROXMENUX_RESULT='+base64.b64encode(json.dumps(result).encode()).decode(),flush=True) + return + hook_spec = Path(tmp)/'lifecycle.json' + write_json(hook_spec,{'schema':1,'stack':deployment['stack_name'],'dependencies':[ + {'vmid':s['vmid'],'label':s['name'],'healthcheck':s['healthcheck']} for s in services if not s['main'] and not s.get('deferred_setup')]}) + if len(services) > 1: + msg_info(translate('Installing the stack startup hook...')) + run('bash',HERE/'stack_dependency_hook.sh','--install',primary_id,hook_spec,capture=False) + msg_ok(translate('Stack startup hook installed')) + fcntl.flock(lock,fcntl.LOCK_UN) + msg_info(translate('Starting the main container and its dependencies...') if len(services) > 1 + else translate('Starting the container...')) + run('pct','start',primary_id,capture=False,timeout=600) + msg_ok(f"{translate('Container started')}: CT {primary_id} ({primary['name']})") + endpoint = primary['healthcheck']['endpoint'] + url = f"{endpoint['scheme']}://{primary['ip']}:{endpoint['port']}{endpoint['path']}" + msg_info(translate('Waiting for the application to respond...')) + wait_web(primary,url) + addresses=run('lxc-info','-n',primary_id,'-iH').splitlines() + lan = next((a for a in addresses if re.fullmatch(r'\d+\.\d+\.\d+\.\d+',a) and ipaddress.ip_address(a) not in subnet),None) + if not lan: + raise RuntimeError(translate('No LAN address was obtained')) + public_url = f"{endpoint['scheme']}://{lan}:{endpoint['port']}{endpoint['path']}" + msg_ok(f"{translate('Application responding:')} {public_url}") + if primary['public_environment']: + msg_info(translate('Applying the LAN address to the application URLs...')) + run('pct','shutdown',primary_id,'--timeout','180',timeout=200) + config=Path(f'/etc/pve/lxc/{primary_id}.conf') + text=config.read_text() + for key,value in primary['public_environment'].items(): + if '\n' in value or '\r' in value: + raise RuntimeError(translate('Multi-line variables are not supported')) + text=re.sub(r'^lxc\.environment\.runtime: '+re.escape(key)+r'=.*\n','',text,flags=re.M) + text+='lxc.environment.runtime: '+key+'='+value.replace('@STACK_LAN_IP@',lan)+'\n' + config.write_text(text) + run('pct','start',primary_id,capture=False,timeout=600) + wait_web(primary,url) + msg_ok(translate('LAN address applied to the application URLs')) + result=results[primary['name']] + persist_instances(deployment, services, primary_id) + # The credentials of the main service come from its own installation. + result.update(vmid=primary_id,ip=lan,stack_vmids={s['name']:s['vmid'] for s in services}, + urls=[{'label':'Web UI','url':public_url}], + credentials=result.get('credentials') or []) + result.update(completion_notes=[note.replace('{main_vmid}',str(primary_id)) + for note in deployment.get('completion_notes', [])], log=LOG) + print('PROXMENUX_RESULT='+base64.b64encode(json.dumps(result).encode()).decode(),flush=True) + except BaseException as error: + # Keep volumes and configs for diagnosis; never delete a database on a late startup failure. + stop_spinner() + if isinstance(error, ServiceFailed): + report_error(str(error), tail=False) + elif isinstance(error, SystemExit): + if isinstance(error.code, str): + report_error(error.code) + else: + report_error(str(error) or type(error).__name__) + if created: + msg_warn(f"{translate('Installation incomplete. These containers and their data are kept:')} " + f"{', '.join('CT '+str(vmid) for vmid in created)}") + accesses = lan_access_urls([s for s in services if s.get('vmid') in created],subnet,strict=False) + if accesses: + msg_warn(translate('LAN access to the kept containers (stack configuration incomplete):')) + for access in accesses: + msg_info2(access['label']+': '+access['url']) + if not created and bridge_created: + with open(LOG or os.devnull, 'a') as output: + subprocess.run(['ip','link','delete',bridge,'type','bridge'],check=False,stdout=output,stderr=output) + subprocess.run(['pvesh','delete',f'/nodes/{node}/network/{bridge}'],check=False,stdout=output,stderr=output) + raise + + +if __name__=='__main__': + try: + main() + except (Exception, KeyboardInterrupt) as error: + if not ERROR_REPORTED: + report_error(str(error) or type(error).__name__) + sys.exit(1) + except SystemExit as error: + if isinstance(error.code, str): + if not ERROR_REPORTED: + report_error(error.code) + sys.exit(1) + raise diff --git a/oci/remote/install_generic_stack.sh b/oci/remote/install_generic_stack.sh new file mode 100755 index 00000000..8e3dfcfe --- /dev/null +++ b/oci/remote/install_generic_stack.sh @@ -0,0 +1,4 @@ +#!/usr/bin/env bash +set -Eeuo pipefail +SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd) +exec python3 "$SCRIPT_DIR/install_generic_stack.py" "$@" diff --git a/oci/remote/install_immich_stack.sh b/oci/remote/install_immich_stack.sh new file mode 100755 index 00000000..3291a121 --- /dev/null +++ b/oci/remote/install_immich_stack.sh @@ -0,0 +1,570 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +TEMPLATE_FILE=${1:?template JSON required} +DEPLOYMENT_FILE=${2:?deployment JSON required} +DRY_RUN=${3:-0} +SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd) +source "$SCRIPT_DIR/oci_ui.sh" +VERIFY_OCI_ARCHIVE="${SCRIPT_DIR}/verify_oci_archive.py" +ALLOCATE_PRIVATE_NETWORK="${SCRIPT_DIR}/allocate_private_network.py" +STACK_DEPENDENCY_HOOK="${SCRIPT_DIR}/stack_dependency_hook.sh" + +die() { + stop_spinner + msg_error "$*" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + exit 1 +} + +require_command() { + command -v "$1" >/dev/null 2>&1 || die "$(translate "Missing required command:") $1" +} + +jqr() { + jq -er "$1" "$DEPLOYMENT_FILE" +} + +set_runtime_env() { + local id=$1 key=$2 value=$3 config="/etc/pve/lxc/${1}.conf" + sed -i -E "/^lxc\.environment\.runtime: ${key}=/d" "$config" + printf 'lxc.environment.runtime: %s=%s\n' "$key" "$value" >>"$config" +} + +unset_runtime_env() { + local id=$1 key=$2 config="/etc/pve/lxc/${1}.conf" + sed -i -E "/^lxc\.environment\.runtime: ${key}=/d" "$config" +} + +set_lxc_directive() { + local id=$1 key=$2 value=$3 config="/etc/pve/lxc/${1}.conf" escaped_key + escaped_key=${key//./\.} + sed -i -E "/^${escaped_key}:/d" "$config" + printf '%s: %s\n' "$key" "$value" >>"$config" +} + +created_ids=() +INSTALL_COMPLETE=0 +PRIVATE_BRIDGE_CREATED=0 +LIFECYCLE_CONFIG_PATH="" +UNEXPECTED_FAILURE=0 +rollback() { + local status=$? index id + stop_spinner + if (( status != 0 && UNEXPECTED_FAILURE == 1 )); then + msg_error "$(translate "The installation stopped because of an unexpected error")" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + fi + if (( status != 0 && INSTALL_COMPLETE == 0 )); then + if declare -F oci_native_failed >/dev/null; then oci_native_failed; fi + if (( ${#created_ids[@]} > 0 || PRIVATE_BRIDGE_CREATED == 1 )); then + msg_info "$(translate "Removing the incomplete stack...")" + fi + for ((index=${#created_ids[@]}-1; index>=0; index--)); do + id=${created_ids[index]} + pct stop "$id" --skiplock 1 >/dev/null 2>&1 || true + pct destroy "$id" --force 1 --purge 1 >/dev/null 2>&1 \ + || pct destroy "$id" --purge 1 >/dev/null 2>&1 \ + || true + done + if (( PRIVATE_BRIDGE_CREATED == 1 )); then + oci_log "Removing the private bridge created by this installation" + ip link delete "$PRIVATE_BRIDGE" type bridge >/dev/null 2>&1 || true + pvesh delete "/nodes/${NODE}/network/${PRIVATE_BRIDGE}" >/dev/null 2>&1 || true + fi + [[ -z $LIFECYCLE_CONFIG_PATH ]] || rm -f "$LIFECYCLE_CONFIG_PATH" + if (( ${#created_ids[@]} > 0 || PRIVATE_BRIDGE_CREATED == 1 )); then + msg_ok "$(translate "Incomplete stack removed")" + fi + fi + exit "$status" +} +trap rollback EXIT +trap 'UNEXPECTED_FAILURE=1; oci_log "Command failed at line $LINENO (${FUNCNAME[0]:-main})"' ERR + +[[ $EUID -eq 0 ]] || die "$(translate "The installer must run as root on Proxmox VE")" +oci_log_init "$(jq -r '.stack_name // "immich"' "$DEPLOYMENT_FILE" 2>/dev/null || printf immich)" +for command in pct qm pvesh pvesm skopeo jq openssl python3 curl ip stat dpkg base64 mktemp flock; do + require_command "$command" +done +[[ -r $VERIFY_OCI_ARCHIVE ]] || die "$(translate "The OCI archive verifier was not found")" +[[ -r $ALLOCATE_PRIVATE_NETWORK ]] || die "$(translate "The private network allocator was not found")" +[[ -r $STACK_DEPENDENCY_HOOK ]] || die "$(translate "The stack startup hook was not found")" + +ML_ACCELERATION=$(jq -er '.machine_learning.acceleration // "cpu"' "$DEPLOYMENT_FILE") +source "$SCRIPT_DIR/oci_nvidia_setup.sh" +source "$SCRIPT_DIR/oci_immich_ml.sh" +validate_immich_ml_profile + +msg_info "$(translate "Reserving a private network...")" +exec 9>/run/lock/proxmenux-private-network.lock +flock 9 +oci_quiet python3 "$ALLOCATE_PRIVATE_NETWORK" "$DEPLOYMENT_FILE" \ + || die "$(translate "Could not reserve a private network for the stack")" + +STACK_NAME=$(jqr '.stack_name') +[[ $STACK_NAME =~ ^[a-z0-9][a-z0-9-]{0,31}$ ]] || die "$(translate "Invalid stack name")" +BASE_VMID=$(jq -r '.base_vmid // empty' "$DEPLOYMENT_FILE") +TEMPLATE_STORAGE=$(jqr '.template_storage') +ROOTFS_STORAGE=$(jqr '.rootfs_storage') +DATABASE_STORAGE=$(jqr '.database_storage') +DATABASE_SIZE=$(jqr '.database_size_gb') +MEDIA_MODE=$(jqr '.media.mode') +MEDIA_STORAGE=$(jq -r '.media.storage // empty' "$DEPLOYMENT_FILE") +MEDIA_SIZE=$(jq -r '.media.size_gb // empty' "$DEPLOYMENT_FILE") +MEDIA_ROOT=$(jq -r '.media.host_path // empty' "$DEPLOYMENT_FILE") +TIMEZONE=$(jqr '.timezone') +ONBOOT=$(jqr '.onboot | if . then 1 else 0 end') +START_AFTER=$(jqr '.start_after_create | if . then 1 else 0 end') +FRONTEND_BRIDGE=$(jqr '.network.frontend_bridge') +FRONTEND_IPV4=$(jq -r '.network.frontend_ipv4 // "dhcp"' "$DEPLOYMENT_FILE") +ML_FRONTEND_IPV4=$(jq -r '.network.machine_learning_frontend_ipv4 // "dhcp"' "$DEPLOYMENT_FILE") +FRONTEND_GATEWAY=$(jq -r '.network.frontend_gateway // empty' "$DEPLOYMENT_FILE") +oci_access_net "$FRONTEND_IPV4" "$FRONTEND_GATEWAY" \ + || die "$(translate "Invalid access address:") $FRONTEND_IPV4 $FRONTEND_GATEWAY" +FRONTEND_NET=$OCI_ACCESS_NET +oci_access_net "$ML_FRONTEND_IPV4" "$FRONTEND_GATEWAY" \ + || die "$(translate "Invalid access address:") $ML_FRONTEND_IPV4 $FRONTEND_GATEWAY" +ML_FRONTEND_NET=$OCI_ACCESS_NET +PRIVATE_BRIDGE=$(jqr '.network.private_bridge') +PRIVATE_SUBNET=$(jqr '.network.private_subnet') +PRIVATE_HOST_ADDRESS=$(jqr '.network.private_host_address') +SERVER_ADDRESS=$(jqr '.network.server_address') +ML_ADDRESS=$(jqr '.network.machine_learning_address') +DB_ADDRESS=$(jqr '.network.database_address') +VALKEY_ADDRESS=$(jqr '.network.valkey_address') +SERVER_IP=${SERVER_ADDRESS%/*} +ML_IP=${ML_ADDRESS%/*} +DB_IP=${DB_ADDRESS%/*} +VALKEY_IP=${VALKEY_ADDRESS%/*} +VIDEO_ACCELERATION=$(jqr '.video_transcoding.acceleration') +RENDER_DEVICE=$(jq -r '.video_transcoding.render_device // empty' "$DEPLOYMENT_FILE") +VAAPI_DRIVER=$(jqr '.video_transcoding.driver') +MODEL_CACHE_SIZE=$(jqr '.machine_learning.model_cache_size_gb') + +[[ $DATABASE_SIZE =~ ^[0-9]+$ ]] && (( DATABASE_SIZE >= 8 )) \ + || die "$(translate "The PostgreSQL volume needs at least 8 GB")" +case "$MEDIA_MODE" in + managed-volume) + [[ -n $MEDIA_STORAGE && $MEDIA_SIZE =~ ^[0-9]+$ ]] && (( MEDIA_SIZE >= 8 )) \ + || die "$(translate "Invalid media volume")" + ;; + host-bind) + [[ $MEDIA_ROOT == /* && $MEDIA_ROOT != *","* && $MEDIA_ROOT != *$'\n'* ]] \ + || die "$(translate "Invalid media path")" + ;; + *) die "$(translate "Unsupported media storage mode:") $MEDIA_MODE" ;; +esac +[[ $PRIVATE_BRIDGE =~ ^vmbr[0-9]+$ ]] || die "$(translate "Invalid private bridge")" +[[ $PRIVATE_SUBNET =~ ^10\.77\.[0-9]{1,3}\.0/24$ ]] || die "$(translate "Invalid private network")" + +vmid_block_free() { + local candidate=$1 offset + for offset in 0 1 2 3; do + pct config "$((candidate + offset))" >/dev/null 2>&1 && return 1 + qm config "$((candidate + offset))" >/dev/null 2>&1 && return 1 + done + return 0 +} + +if [[ -z $BASE_VMID ]]; then + BASE_VMID=$(pvesh get /cluster/nextid) + while ! vmid_block_free "$BASE_VMID"; do + BASE_VMID=$((BASE_VMID + 1)) + done +fi +[[ $BASE_VMID =~ ^[0-9]+$ ]] || die "$(translate "Invalid base VMID")" +vmid_block_free "$BASE_VMID" || die "$(translate "These VMIDs are not free:") ${BASE_VMID}-$((BASE_VMID + 3))" + +SERVER_ID=$BASE_VMID +ML_ID=$((BASE_VMID + 1)) +DB_ID=$((BASE_VMID + 2)) +VALKEY_ID=$((BASE_VMID + 3)) + +oci_log "Stack: $STACK_NAME; VMIDs: server=$SERVER_ID, machine-learning=$ML_ID, PostgreSQL=$DB_ID, Valkey=$VALKEY_ID" +oci_log "Private network: $PRIVATE_SUBNET on $PRIVATE_BRIDGE" + +if [[ $DRY_RUN == 1 ]]; then + msg_info2 "$(translate "Stack:") $STACK_NAME · CT ${SERVER_ID}-${VALKEY_ID}" + msg_info2 "$(translate "Private network:") $PRIVATE_BRIDGE ($PRIVATE_SUBNET)" + msg_ok "$(translate "Dry run completed; no containers were created.")" + exit 0 +fi + +NODE=$(hostname) +if ! pvesh get "/nodes/${NODE}/network/${PRIVATE_BRIDGE}" >/dev/null 2>&1; then + oci_log "Creating the persistent configuration for $PRIVATE_BRIDGE" + oci_quiet pvesh create "/nodes/${NODE}/network" --iface "$PRIVATE_BRIDGE" --type bridge \ + --autostart 1 --cidr "$PRIVATE_HOST_ADDRESS" + PRIVATE_BRIDGE_CREATED=1 +fi +if ! ip link show "$PRIVATE_BRIDGE" >/dev/null 2>&1; then + oci_log "Activating the private bridge $PRIVATE_BRIDGE" + oci_quiet ip link add name "$PRIVATE_BRIDGE" type bridge + oci_quiet ip address add "$PRIVATE_HOST_ADDRESS" dev "$PRIVATE_BRIDGE" + oci_quiet ip link set "$PRIVATE_BRIDGE" up +fi +ip -4 address show dev "$PRIVATE_BRIDGE" | grep -Fq "${PRIVATE_HOST_ADDRESS%/*}/" \ + || die "$(translate "The private bridge does not have the expected address:") $PRIVATE_BRIDGE ($PRIVATE_HOST_ADDRESS)" + +for address in "$SERVER_ADDRESS" "$ML_ADDRESS" "$DB_ADDRESS" "$VALKEY_ADDRESS"; do + if grep -RqsF "ip=${address}" /etc/pve/lxc/*.conf 2>/dev/null; then + die "$(translate "The private address is already assigned to another container:") ${address%/*}" + fi +done +flock -u 9 +msg_ok "$(translate "Private network:") $PRIVATE_BRIDGE ($PRIVATE_SUBNET)" + +ARCH=$(dpkg --print-architecture) +case "$ARCH" in amd64|arm64) ;; *) die "$(translate "Unsupported architecture:") $ARCH" ;; esac + +skopeo_transport_reference() { + local reference=$1 name digest + if [[ $reference == *@sha256:* ]]; then + name=${reference%@sha256:*} + digest="sha256:${reference##*@sha256:}" + [[ ${name##*/} == *:* ]] && name=${name%:*} + printf '%s@%s' "$name" "$digest" + else + printf '%s' "$reference" + fi +} + +resolve_image_manifest() { + local label=$1 image=$2 manifest_file error_file pid elapsed=0 status=0 + manifest_file=$(mktemp /tmp/proxmenux-oci-inspect.XXXXXX) + error_file="${manifest_file}.err" + oci_log "Querying the OCI registry for ${label}: ${image}" + skopeo inspect --no-tags --override-os linux --override-arch "$ARCH" \ + "docker://${image}" >"$manifest_file" 2>"$error_file" & + pid=$! + while kill -0 "$pid" 2>/dev/null; do + sleep 2 + elapsed=$((elapsed + 2)) + done + wait "$pid" || status=$? + if (( status != 0 )); then + cat "$error_file" >>"$OCI_LOG" + rm -f "$manifest_file" "$error_file" + return "$status" + fi + oci_log "Manifest for ${label} resolved in ${elapsed}s" + cat "$manifest_file" + rm -f "$manifest_file" "$error_file" +} + +ensure_image() { + local key=$1 image=$2 transport_image inspect digest short archive_name archive_volume archive_path + local partial log pid bytes elapsed status process_bytes pull_name + msg_info "$(translate "Checking the image in the registry...")" + oci_log "Resolving ${key}: ${image}" + transport_image=$(skopeo_transport_reference "$image") + if [[ $transport_image != "$image" ]]; then + oci_log "Digest-pinned reference in skopeo format: ${transport_image}" + fi + inspect=$(resolve_image_manifest "$key" "$transport_image") \ + || die "$(translate "Could not resolve the OCI manifest:") $image" + digest=$(jq -er '.Digest' <<<"$inspect") + oci_log "Selected digest for ${key}: ${digest}" + short=${digest#sha256:} + short=${short:0:16} + archive_name="image-immich-${key}_${ARCH}_${short}.tar" + archive_volume="${TEMPLATE_STORAGE}:vztmpl/${archive_name}" + archive_path=$(pvesm path "$archive_volume") + mkdir -p "$(dirname "$archive_path")" + if [[ -s $archive_path ]]; then + msg_info "$(translate "Verifying the image integrity...")" + fi + if [[ -s $archive_path ]] && oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$archive_path"; then + oci_log "Reusing ${archive_volume}" + else + rm -f "$archive_path" + partial="${archive_path}.partial.$$" + log="${partial}.log" + oci_log "Downloading ${image} by digest ${digest}" + pull_name=${transport_image%@sha256:*} + [[ ${pull_name##*/} != *:* ]] || pull_name=${pull_name%:*} + skopeo copy --override-os linux --override-arch "$ARCH" --retry-times 3 \ + --retry-delay 5s --image-parallel-copies 1 \ + "docker://${pull_name}@${digest}" "oci-archive:${partial}:image-immich-${key}" >"$log" 2>&1 & + pid=$! + elapsed=0 + while kill -0 "$pid" 2>/dev/null; do + bytes=$(stat -c %s "$partial" 2>/dev/null || printf 0) + process_bytes=$(awk '$1 == "rchar:" { print $2 }' "/proc/${pid}/io" 2>/dev/null || printf 0) + process_bytes=${process_bytes:-0} + (( process_bytes <= bytes )) || bytes=$process_bytes + msg_progress "$(translate "Downloading the image:") ${key} · $((bytes / 1048576)) MiB · ${elapsed}s" + sleep 2 + elapsed=$((elapsed + 2)) + done + status=0 + wait "$pid" || status=$? + cat "$log" >>"$OCI_LOG" + rm -f "$log" + (( status == 0 )) || { rm -f "$partial"; die "$(translate "Image download failed:") $image"; } + msg_info "$(translate "Verifying the image integrity...")" + oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$partial" \ + || { rm -f "$partial"; die "$(translate "The downloaded image is corrupt:") $image"; } + mv -f "$partial" "$archive_path" + fi + msg_ok "$(translate "Image:") $image" + RESOLVED_ARCHIVE=$archive_volume + RESOLVED_DIGEST=$digest +} + +SERVER_IMAGE=$(jq -er '.container_contract.image.reference' "$TEMPLATE_FILE") +ML_IMAGE=$(jq -er --arg profile "$ML_ACCELERATION" '.proxmox.application_options.machine_learning.profile_images[$profile]' "$TEMPLATE_FILE") +DB_IMAGE=$(jq -er '.compose_stack.services[] | select(.name == "database") | .image' "$TEMPLATE_FILE") +VALKEY_IMAGE=$(jq -er '.compose_stack.services[] | select(.name == "redis") | .image' "$TEMPLATE_FILE") + +ensure_image server "$SERVER_IMAGE"; SERVER_ARCHIVE=$RESOLVED_ARCHIVE; SERVER_DIGEST=$RESOLVED_DIGEST +ensure_image machine-learning "$ML_IMAGE"; ML_ARCHIVE=$RESOLVED_ARCHIVE +ensure_image postgres "$DB_IMAGE"; DB_ARCHIVE=$RESOLVED_ARCHIVE +ensure_image valkey "$VALKEY_IMAGE"; VALKEY_ARCHIVE=$RESOLVED_ARCHIVE + +source "$SCRIPT_DIR/oci_native_stack.sh" +oci_native_begin "$SERVER_ID" \ + --member server "$SERVER_ID" "$SERVER_IMAGE" "$SERVER_ARCHIVE" \ + --member machine-learning "$ML_ID" "$ML_IMAGE" "$ML_ARCHIVE" \ + --member database "$DB_ID" "$DB_IMAGE" "$DB_ARCHIVE" \ + --member valkey "$VALKEY_ID" "$VALKEY_IMAGE" "$VALKEY_ARCHIVE" + +DB_PASSWORD=$(openssl rand -hex 24) +if [[ $MEDIA_MODE == host-bind ]]; then + install -d -m 0750 -o 100000 -g 100000 "$MEDIA_ROOT" + SERVER_MEDIA_MOUNT="${MEDIA_ROOT},mp=/data,backup=0" +else + SERVER_MEDIA_MOUNT="${MEDIA_STORAGE}:${MEDIA_SIZE},mp=/data,backup=1" +fi +TAGS="media;oci;proxmenux" + +msg_info "$(translate "Creating the container...")" +oci_quiet pct create "$DB_ID" "$DB_ARCHIVE" --rootfs "${ROOTFS_STORAGE}:8" \ + --mp0 "${DATABASE_STORAGE}:${DATABASE_SIZE},mp=/var/lib/postgresql/data,backup=1" \ + --hostname "${STACK_NAME}-db" --cores 2 --memory 2048 --swap 512 \ + --net0 "name=eth0,bridge=${PRIVATE_BRIDGE},firewall=1,host-managed=1,ip=${DB_ADDRESS},type=veth" \ + --unprivileged 1 --features nesting=1 --cmode console --onboot "$ONBOOT" \ + --startup order=10,up=10,down=30 --tags "$TAGS" \ + --description 'Immich PostgreSQL VectorChord native OCI' +created_ids+=("$DB_ID") +oci_quiet pct set "$DB_ID" --entrypoint "/usr/local/bin/immich-docker-entrypoint.sh postgres -c config_file=/etc/postgresql/postgresql.conf -c listen_addresses=127.0.0.1,${DB_IP}" +set_lxc_directive "$DB_ID" lxc.init.cwd / +set_lxc_directive "$DB_ID" lxc.signal.halt SIGINT +set_runtime_env "$DB_ID" POSTGRES_USER postgres +set_runtime_env "$DB_ID" POSTGRES_DB immich +set_runtime_env "$DB_ID" POSTGRES_INITDB_ARGS --data-checksums +set_runtime_env "$DB_ID" PGDATA /var/lib/postgresql/data/pgdata +set_runtime_env "$DB_ID" DB_STORAGE_TYPE SSD +set_runtime_env "$DB_ID" POSTGRES_PASSWORD "$DB_PASSWORD" +oci_quiet pct mount "$DB_ID" +DB_ROOT="/var/lib/lxc/${DB_ID}/rootfs" +POSTGRES_UID=$(awk -F: '$1 == "postgres" {print $3}' "$DB_ROOT/etc/passwd") +POSTGRES_GID=$(awk -F: '$1 == "postgres" {print $4}' "$DB_ROOT/etc/passwd") +[[ -n $POSTGRES_UID && -n $POSTGRES_GID ]] || die "$(translate "The postgres user was not found in the image")" +rm -rf "$DB_ROOT/var/lib/postgresql/data/lost+found" +install -d -m 0700 -o "$((100000 + POSTGRES_UID))" -g "$((100000 + POSTGRES_GID))" \ + "$DB_ROOT/var/lib/postgresql/data/pgdata" +oci_quiet pct unmount "$DB_ID" +msg_ok "$(translate "Container created:") CT $DB_ID (PostgreSQL)" + +msg_info "$(translate "Creating the container...")" +oci_quiet pct create "$VALKEY_ID" "$VALKEY_ARCHIVE" --rootfs "${ROOTFS_STORAGE}:4" \ + --mp0 "${ROOTFS_STORAGE}:4,mp=/data,backup=1" \ + --hostname "${STACK_NAME}-valkey" --cores 1 --memory 512 --swap 256 \ + --net0 "name=eth0,bridge=${PRIVATE_BRIDGE},firewall=1,host-managed=1,ip=${VALKEY_ADDRESS},type=veth" \ + --unprivileged 1 --features nesting=1 --cmode console --onboot "$ONBOOT" \ + --startup order=20,up=5,down=15 --tags "$TAGS" --description 'Immich Valkey native OCI' +created_ids+=("$VALKEY_ID") +oci_quiet pct mount "$VALKEY_ID" +VALKEY_FACTORY_DIR="/var/lib/lxc/${VALKEY_ID}/rootfs/data/lost+found" +# Only remove the empty directory created by formatting this new managed disk. +if [[ -d $VALKEY_FACTORY_DIR && ! -L $VALKEY_FACTORY_DIR ]]; then + [[ $(stat -c '%i:%u:%g:%a' "$VALKEY_FACTORY_DIR") == 11:0:0:700 ]] \ + || die "$(translate "Unexpected formatting directory in the new Valkey volume")" + rmdir "$VALKEY_FACTORY_DIR" 2>>"$OCI_LOG" || die "$(translate "The new Valkey volume contains unexpected data")" +fi +oci_quiet pct unmount "$VALKEY_ID" +oci_quiet pct set "$VALKEY_ID" --entrypoint 'docker-entrypoint.sh valkey-server' +set_lxc_directive "$VALKEY_ID" lxc.init.cwd /data +set_lxc_directive "$VALKEY_ID" lxc.signal.halt SIGTERM +msg_ok "$(translate "Container created:") CT $VALKEY_ID (Valkey)" + +msg_info "$(translate "Creating the container...")" +oci_quiet pct create "$ML_ID" "$ML_ARCHIVE" --rootfs "${ROOTFS_STORAGE}:12" \ + --mp0 "${ROOTFS_STORAGE}:${MODEL_CACHE_SIZE},mp=/cache,backup=1" \ + --hostname "${STACK_NAME}-ml" "${ML_CPU_ARGS[@]}" --memory "$ML_MEMORY" --swap "$ML_SWAP" \ + --net0 "name=eth0,bridge=${FRONTEND_BRIDGE},firewall=1,host-managed=1,${ML_FRONTEND_NET},type=veth" \ + --net1 "name=eth1,bridge=${PRIVATE_BRIDGE},firewall=1,host-managed=1,ip=${ML_ADDRESS},type=veth" \ + --unprivileged 1 --features nesting=1 --cmode console --onboot "$ONBOOT" \ + --startup order=30,up=10,down=30 --tags "$TAGS" --description "Immich machine learning ${ML_ACCELERATION} native OCI" +created_ids+=("$ML_ID") +unset_runtime_env "$ML_ID" LD_PRELOAD +oci_quiet pct set "$ML_ID" --entrypoint 'env LD_PRELOAD=/usr/lib/libmimalloc.so.2 tini -- python -m immich_ml' +set_lxc_directive "$ML_ID" lxc.init.cwd /usr/src +set_lxc_directive "$ML_ID" lxc.signal.halt SIGTERM +set_runtime_env "$ML_ID" IMMICH_HOST "$ML_IP" +set_runtime_env "$ML_ID" IMMICH_PORT 3003 +set_runtime_env "$ML_ID" MACHINE_LEARNING_CACHE_FOLDER /cache +set_runtime_env "$ML_ID" TRANSFORMERS_CACHE /cache +set_runtime_env "$ML_ID" MACHINE_LEARNING_MODEL_INTRA_OP_THREADS 2 +set_runtime_env "$ML_ID" MACHINE_LEARNING_MODEL_INTER_OP_THREADS 1 +configure_immich_ml_gpu +oci_quiet pct mount "$ML_ID" +ML_ROOT="/var/lib/lxc/${ML_ID}/rootfs" +rm -rf "$ML_ROOT/cache/lost+found" +chown 100000:100000 "$ML_ROOT/cache" +chmod 0755 "$ML_ROOT/cache" +oci_quiet pct unmount "$ML_ID" +msg_ok "$(translate "Container created:") CT $ML_ID ($(translate "Machine learning"))" + +SERVER_DEVICE_ARGS=() +if [[ $VIDEO_ACCELERATION == vaapi ]]; then + [[ -c $RENDER_DEVICE ]] || die "$(translate "The VA-API device does not exist:") $RENDER_DEVICE" + RENDER_GID=$(stat -c %g "$RENDER_DEVICE") + SERVER_DEVICE_ARGS+=(--dev0 "path=${RENDER_DEVICE},gid=${RENDER_GID},mode=0660") +fi + +msg_info "$(translate "Creating the container...")" +oci_quiet pct create "$SERVER_ID" "$SERVER_ARCHIVE" --rootfs "${ROOTFS_STORAGE}:16" \ + --mp0 "$SERVER_MEDIA_MOUNT" --hostname "${STACK_NAME}-server" \ + --cores 4 --memory 3072 --swap 1024 \ + --net0 "name=eth0,bridge=${FRONTEND_BRIDGE},firewall=1,host-managed=1,${FRONTEND_NET},type=veth" \ + --net1 "name=eth1,bridge=${PRIVATE_BRIDGE},firewall=1,host-managed=1,ip=${SERVER_ADDRESS},type=veth" \ + "${SERVER_DEVICE_ARGS[@]}" --unprivileged 1 --features nesting=1 --cmode console \ + --onboot "$ONBOOT" --startup order=40,up=10,down=30 --tags "$TAGS" \ + --description 'Immich server native OCI' +created_ids+=("$SERVER_ID") + +oci_quiet pct mount "$SERVER_ID" +SERVER_ROOT="/var/lib/lxc/${SERVER_ID}/rootfs" +cat >"$SERVER_ROOT/usr/local/bin/immich-lxc-start" <<'EOF' +#!/bin/bash +set -e +for attempt in $(seq 1 60); do + if grep -qE '^eth0[[:space:]]+00000000[[:space:]]' /proc/net/route; then + sleep 3 + exec /bin/bash -c 'start.sh' + fi + sleep 1 +done +echo 'Immich frontend route was not ready after 60 seconds' >&2 +exit 1 +EOF +chmod 0755 "$SERVER_ROOT/usr/local/bin/immich-lxc-start" +chown 100000:100000 "$SERVER_ROOT/usr/local/bin/immich-lxc-start" +oci_quiet pct unmount "$SERVER_ID" + +oci_quiet pct set "$SERVER_ID" --entrypoint 'tini -- /usr/local/bin/immich-lxc-start' +set_lxc_directive "$SERVER_ID" lxc.init.cwd /usr/src/app +set_lxc_directive "$SERVER_ID" lxc.signal.halt SIGTERM +set_runtime_env "$SERVER_ID" TZ "$TIMEZONE" +set_runtime_env "$SERVER_ID" CPU_CORES 4 +set_runtime_env "$SERVER_ID" IMMICH_HOST 0.0.0.0 +set_runtime_env "$SERVER_ID" IMMICH_PORT 2283 +set_runtime_env "$SERVER_ID" DB_HOSTNAME "$DB_IP" +set_runtime_env "$SERVER_ID" DB_PORT 5432 +set_runtime_env "$SERVER_ID" DB_USERNAME postgres +set_runtime_env "$SERVER_ID" DB_DATABASE_NAME immich +set_runtime_env "$SERVER_ID" DB_VECTOR_EXTENSION vectorchord +set_runtime_env "$SERVER_ID" REDIS_HOSTNAME "$VALKEY_IP" +set_runtime_env "$SERVER_ID" REDIS_PORT 6379 +set_runtime_env "$SERVER_ID" IMMICH_MACHINE_LEARNING_URL "http://${ML_IP}:3003" +if [[ $VIDEO_ACCELERATION == vaapi && $VAAPI_DRIVER != auto ]]; then + set_runtime_env "$SERVER_ID" LIBVA_DRIVER_NAME "$VAAPI_DRIVER" +fi +set_runtime_env "$SERVER_ID" DB_PASSWORD "$DB_PASSWORD" +msg_ok "$(translate "Container created:") CT $SERVER_ID (Immich)" + +msg_info "$(translate "Installing the stack startup hook...")" +LIFECYCLE_SPEC=$(mktemp /tmp/proxmenux-stack-lifecycle.XXXXXX) +jq -nc --arg stack "$STACK_NAME" --argjson db "$DB_ID" --arg db_ip "$DB_IP" \ + --argjson valkey "$VALKEY_ID" --arg valkey_ip "$VALKEY_IP" \ + --argjson ml "$ML_ID" --arg ml_ip "$ML_IP" ' + { + schema: 1, + stack: $stack, + dependencies: [ + {vmid: $db, label: "PostgreSQL", healthcheck: { + type: "exec", timeout_seconds: 90, + argv: ["pg_isready", "-h", $db_ip, "-p", "5432", "-U", "postgres", "-d", "immich"] + }}, + {vmid: $valkey, label: "Valkey", healthcheck: { + type: "exec", timeout_seconds: 60, + argv: ["valkey-cli", "-h", $valkey_ip, "ping"] + }}, + {vmid: $ml, label: "Immich Machine Learning", healthcheck: { + type: "http", timeout_seconds: 180, url: ("http://" + $ml_ip + ":3003/ping") + }} + ] + }' >"$LIFECYCLE_SPEC" +LIFECYCLE_CONFIG_PATH="/etc/pve/priv/proxmenux-stack-${SERVER_ID}.json" +if ! oci_quiet bash "$STACK_DEPENDENCY_HOOK" --install "$SERVER_ID" "$LIFECYCLE_SPEC"; then + rm -f "$LIFECYCLE_SPEC" + die "$(translate "Could not install the stack startup hook")" +fi +rm -f "$LIFECYCLE_SPEC" +msg_ok "$(translate "Stack startup hook installed")" + +wait_command() { + local label=$1 retries=$2 + shift 2 + local attempt + for attempt in $(seq 1 "$retries"); do + "$@" >/dev/null 2>&1 && return 0 + sleep 2 + done + die "$(translate "Health check failed:") $label" +} + +SERVER_LAN_IP="" +if (( START_AFTER == 1 )); then + msg_info "$(translate "Starting the service:") PostgreSQL" + oci_quiet pct start "$DB_ID" + wait_command PostgreSQL 45 pct exec "$DB_ID" -- pg_isready -h "$DB_IP" -p 5432 -U postgres -d immich + msg_ok "$(translate "Service ready:") PostgreSQL" + msg_info "$(translate "Starting the service:") Valkey" + oci_quiet pct start "$VALKEY_ID" + wait_command Valkey 30 pct exec "$VALKEY_ID" -- valkey-cli -h "$VALKEY_IP" ping + msg_ok "$(translate "Service ready:") Valkey" + ML_LABEL=$(translate "Machine learning") + msg_info "$(translate "Starting the service:") $ML_LABEL" + oci_quiet pct start "$ML_ID" + wait_command "$ML_LABEL" 60 curl -fsS "http://${ML_IP}:3003/ping" + msg_ok "$(translate "Service ready:") $ML_LABEL" + validate_immich_ml_runtime \ + || die "$(translate "The requested machine learning GPU profile is not working; it is not replaced by CPU")" + msg_info "$(translate "Starting the service:") Immich" + oci_quiet pct start "$SERVER_ID" + msg_info "$(translate "Waiting for the application to respond...")" + wait_command Immich 90 curl -fsS "http://${SERVER_IP}:2283/api/server/ping" + SERVER_LAN_IP=$(pct exec "$SERVER_ID" -- node -e ' + const os = require("node:os"); + for (const addresses of Object.values(os.networkInterfaces())) { + for (const address of addresses ?? []) { + if (address.family === "IPv4" && !address.internal && !address.address.startsWith("10.77.")) { + process.stdout.write(address.address); process.exit(0); + } + } + } + process.exit(1); + ') + msg_ok "$(translate "Application responding:") http://${SERVER_LAN_IP}:2283/" +fi + +RESULT=$(jq -cn \ + --argjson vmid "$SERVER_ID" --argjson ml "$ML_ID" --argjson db "$DB_ID" \ + --argjson valkey "$VALKEY_ID" --arg ip "$SERVER_LAN_IP" --arg arch "$ARCH" \ + --arg digest "$SERVER_DIGEST" --arg log "$OCI_LOG" \ + '{vmid:$vmid,stack_vmids:{server:$vmid,machine_learning:$ml,database:$db,valkey:$valkey},ip:$ip,architecture:$arch,digest:$digest,urls:(if ($ip|length)>0 then [{label:"Immich WebUI",url:("http://"+$ip+":2283/")}] else [] end),credentials:[],log:$log}') +INSTALL_COMPLETE=1 +oci_native_finalize +printf 'PROXMENUX_RESULT=%s\n' "$(printf '%s' "$RESULT" | base64 -w0)" +INSTALL_COMPLETE=1 +trap - EXIT diff --git a/oci/remote/install_nextcloud_stack.sh b/oci/remote/install_nextcloud_stack.sh new file mode 100755 index 00000000..244610b4 --- /dev/null +++ b/oci/remote/install_nextcloud_stack.sh @@ -0,0 +1,553 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +TEMPLATE_FILE=${1:?template JSON required} +DEPLOYMENT_FILE=${2:?deployment JSON required} +DRY_RUN=${3:-0} +SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd) +source "$SCRIPT_DIR/oci_ui.sh" +VERIFY_OCI_ARCHIVE="${SCRIPT_DIR}/verify_oci_archive.py" +ALLOCATE_PRIVATE_NETWORK="${SCRIPT_DIR}/allocate_private_network.py" +STACK_DEPENDENCY_HOOK="${SCRIPT_DIR}/stack_dependency_hook.sh" + +die() { + stop_spinner + msg_error "$*" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + exit 1 +} + +require_command() { + command -v "$1" >/dev/null 2>&1 || die "$(translate "Missing required command:") $1" +} + +jqr() { + jq -er "$1" "$DEPLOYMENT_FILE" +} + +set_runtime_env() { + local id=$1 key=$2 value=$3 config="/etc/pve/lxc/${1}.conf" + sed -i -E "/^lxc\.environment\.runtime: ${key}=/d" "$config" + printf 'lxc.environment.runtime: %s=%s\n' "$key" "$value" >>"$config" +} + +set_lxc_directive() { + local id=$1 key=$2 value=$3 config="/etc/pve/lxc/${1}.conf" escaped_key + escaped_key=${key//./\.} + sed -i -E "/^${escaped_key}:/d" "$config" + printf '%s: %s\n' "$key" "$value" >>"$config" +} + +created_ids=() +INSTALL_COMPLETE=0 +PRIVATE_BRIDGE_CREATED=0 +LIFECYCLE_CONFIG_PATH="" +UNEXPECTED_FAILURE=0 +rollback() { + local status=$? index id + stop_spinner + if (( status != 0 && UNEXPECTED_FAILURE == 1 )); then + msg_error "$(translate "The installation stopped because of an unexpected error")" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + fi + if (( status != 0 && INSTALL_COMPLETE == 0 )); then + if declare -F oci_native_failed >/dev/null; then oci_native_failed; fi + if (( ${#created_ids[@]} > 0 || PRIVATE_BRIDGE_CREATED == 1 )); then + msg_info "$(translate "Removing the incomplete stack...")" + fi + for ((index=${#created_ids[@]}-1; index>=0; index--)); do + id=${created_ids[index]} + pct stop "$id" --skiplock 1 >/dev/null 2>&1 || true + pct destroy "$id" --force 1 --purge 1 >/dev/null 2>&1 \ + || pct destroy "$id" --purge 1 >/dev/null 2>&1 \ + || true + done + if (( PRIVATE_BRIDGE_CREATED == 1 )); then + oci_log "Removing the private bridge created by this installation" + ip link delete "$PRIVATE_BRIDGE" type bridge >/dev/null 2>&1 || true + pvesh delete "/nodes/${NODE}/network/${PRIVATE_BRIDGE}" >/dev/null 2>&1 || true + fi + [[ -z $LIFECYCLE_CONFIG_PATH ]] || rm -f "$LIFECYCLE_CONFIG_PATH" + if (( ${#created_ids[@]} > 0 || PRIVATE_BRIDGE_CREATED == 1 )); then + msg_ok "$(translate "Incomplete stack removed")" + fi + fi + exit "$status" +} +trap rollback EXIT +trap 'UNEXPECTED_FAILURE=1; oci_log "Command failed at line $LINENO (${FUNCNAME[0]:-main})"' ERR + +[[ $EUID -eq 0 ]] || die "$(translate "The installer must run as root on Proxmox VE")" +oci_log_init "$(jq -r '.stack_name // "nextcloud"' "$DEPLOYMENT_FILE" 2>/dev/null || printf nextcloud)" +for command in pct qm pvesh pvesm skopeo jq openssl python3 curl ip stat dpkg base64 mktemp lxc-info flock; do + require_command "$command" +done +[[ -r $VERIFY_OCI_ARCHIVE ]] || die "$(translate "The OCI archive verifier was not found")" +[[ -r $ALLOCATE_PRIVATE_NETWORK ]] || die "$(translate "The private network allocator was not found")" +[[ -r $STACK_DEPENDENCY_HOOK ]] || die "$(translate "The stack startup hook was not found")" + +msg_info "$(translate "Reserving a private network...")" +exec 9>/run/lock/proxmenux-private-network.lock +flock 9 +oci_quiet python3 "$ALLOCATE_PRIVATE_NETWORK" "$DEPLOYMENT_FILE" \ + || die "$(translate "Could not reserve a private network for the stack")" + +STACK_NAME=$(jqr '.stack_name') +[[ $STACK_NAME =~ ^[a-z0-9][a-z0-9-]{0,31}$ ]] || die "$(translate "Invalid stack name")" +BASE_VMID=$(jq -r '.base_vmid // empty' "$DEPLOYMENT_FILE") +TEMPLATE_STORAGE=$(jqr '.template_storage') +ROOTFS_STORAGE=$(jqr '.rootfs_storage') +DATABASE_STORAGE=$(jqr '.database_storage') +DATABASE_SIZE=$(jqr '.database_size_gb') +APPLICATION_MODE=$(jqr '.application.mode') +APPLICATION_STORAGE=$(jq -r '.application.storage // empty' "$DEPLOYMENT_FILE") +APPLICATION_SIZE=$(jq -r '.application.size_gb // empty' "$DEPLOYMENT_FILE") +APPLICATION_ROOT=$(jq -r '.application.host_path // empty' "$DEPLOYMENT_FILE") +ADMIN_USERNAME=$(jqr '.application.admin_username') +PHP_MEMORY_LIMIT=$(jqr '.application.php_memory_limit') +PHP_UPLOAD_LIMIT=$(jqr '.application.php_upload_limit') +APACHE_BODY_LIMIT=$(jqr '.application.apache_body_limit') +TIMEZONE=$(jqr '.timezone') +MAINTENANCE_WINDOW=$(jqr '.maintenance_window_start_utc') +PHONE_REGION=$(jqr '.default_phone_region') +ONBOOT=$(jqr '.onboot | if . then 1 else 0 end') +START_AFTER=$(jqr '.start_after_create | if . then 1 else 0 end') +FRONTEND_BRIDGE=$(jqr '.network.frontend_bridge') +FRONTEND_IPV4=$(jqr '.network.frontend_ipv4') +FRONTEND_GATEWAY=$(jq -r '.network.frontend_gateway // empty' "$DEPLOYMENT_FILE") +oci_access_net "$FRONTEND_IPV4" "$FRONTEND_GATEWAY" \ + || die "$(translate "Invalid access address:") $FRONTEND_IPV4 $FRONTEND_GATEWAY" +FRONTEND_NET=$OCI_ACCESS_NET +PRIVATE_BRIDGE=$(jqr '.network.private_bridge') +PRIVATE_SUBNET=$(jqr '.network.private_subnet') +PRIVATE_HOST_ADDRESS=$(jqr '.network.private_host_address') +APPLICATION_ADDRESS=$(jqr '.network.application_address') +DATABASE_ADDRESS=$(jqr '.network.database_address') +CACHE_ADDRESS=$(jqr '.network.cache_address') +APPLICATION_IP=${APPLICATION_ADDRESS%/*} +DATABASE_IP=${DATABASE_ADDRESS%/*} +CACHE_IP=${CACHE_ADDRESS%/*} + +[[ $DATABASE_SIZE =~ ^[0-9]+$ ]] && (( DATABASE_SIZE >= 8 )) \ + || die "$(translate "The PostgreSQL volume needs at least 8 GB")" +[[ $ADMIN_USERNAME =~ ^[A-Za-z0-9_.@-]+$ ]] || die "$(translate "Invalid administrator user name")" +case "$APPLICATION_MODE" in + managed-volume) + [[ -n $APPLICATION_STORAGE && $APPLICATION_SIZE =~ ^[0-9]+$ ]] \ + && (( APPLICATION_SIZE >= 8 )) || die "$(translate "Invalid Nextcloud volume")" + ;; + host-bind) + [[ $APPLICATION_ROOT == /* && $APPLICATION_ROOT != *","* && $APPLICATION_ROOT != *$'\n'* ]] \ + || die "$(translate "Invalid shared path")" + ;; + *) die "$(translate "Unsupported storage mode:") $APPLICATION_MODE" ;; +esac +[[ $PRIVATE_BRIDGE =~ ^vmbr[0-9]+$ ]] || die "$(translate "Invalid private bridge")" +[[ $PRIVATE_SUBNET =~ ^10\.77\.[0-9]{1,3}\.0/24$ ]] || die "$(translate "Invalid private network")" + +vmid_block_free() { + local candidate=$1 offset + for offset in 0 1 2; do + pct config "$((candidate + offset))" >/dev/null 2>&1 && return 1 + qm config "$((candidate + offset))" >/dev/null 2>&1 && return 1 + done + return 0 +} + +if [[ -z $BASE_VMID ]]; then + BASE_VMID=$(pvesh get /cluster/nextid) + while ! vmid_block_free "$BASE_VMID"; do + BASE_VMID=$((BASE_VMID + 1)) + done +fi +[[ $BASE_VMID =~ ^[0-9]+$ ]] || die "$(translate "Invalid base VMID")" +vmid_block_free "$BASE_VMID" || die "$(translate "These VMIDs are not free:") ${BASE_VMID}-$((BASE_VMID + 2))" + +APPLICATION_ID=$BASE_VMID +CACHE_ID=$((BASE_VMID + 1)) +DATABASE_ID=$((BASE_VMID + 2)) + +oci_log "Stack: $STACK_NAME; VMIDs: Nextcloud=$APPLICATION_ID, Redis=$CACHE_ID, PostgreSQL=$DATABASE_ID" +oci_log "Private network: $PRIVATE_SUBNET on $PRIVATE_BRIDGE" + +if [[ $DRY_RUN == 1 ]]; then + msg_info2 "$(translate "Stack:") $STACK_NAME · CT ${APPLICATION_ID}-${DATABASE_ID}" + msg_info2 "$(translate "Private network:") $PRIVATE_BRIDGE ($PRIVATE_SUBNET)" + msg_ok "$(translate "Dry run completed; no containers were created.")" + exit 0 +fi + +NODE=$(hostname) +if ! pvesh get "/nodes/${NODE}/network/${PRIVATE_BRIDGE}" >/dev/null 2>&1; then + oci_log "Creating the persistent configuration for $PRIVATE_BRIDGE" + oci_quiet pvesh create "/nodes/${NODE}/network" --iface "$PRIVATE_BRIDGE" --type bridge \ + --autostart 1 --cidr "$PRIVATE_HOST_ADDRESS" + PRIVATE_BRIDGE_CREATED=1 +fi +if ! ip link show "$PRIVATE_BRIDGE" >/dev/null 2>&1; then + oci_log "Activating the private bridge $PRIVATE_BRIDGE" + oci_quiet ip link add name "$PRIVATE_BRIDGE" type bridge + oci_quiet ip address add "$PRIVATE_HOST_ADDRESS" dev "$PRIVATE_BRIDGE" + oci_quiet ip link set "$PRIVATE_BRIDGE" up +fi +ip -4 address show dev "$PRIVATE_BRIDGE" | grep -Fq "${PRIVATE_HOST_ADDRESS%/*}/" \ + || die "$(translate "The private bridge does not have the expected address:") $PRIVATE_BRIDGE ($PRIVATE_HOST_ADDRESS)" + +for address in "$APPLICATION_ADDRESS" "$DATABASE_ADDRESS" "$CACHE_ADDRESS"; do + if grep -RqsF "ip=${address}" /etc/pve/lxc/*.conf 2>/dev/null; then + die "$(translate "The private address is already assigned to another container:") ${address%/*}" + fi +done +flock -u 9 +msg_ok "$(translate "Private network:") $PRIVATE_BRIDGE ($PRIVATE_SUBNET)" + +ARCH=$(dpkg --print-architecture) +case "$ARCH" in amd64|arm64) ;; *) die "$(translate "Unsupported architecture:") $ARCH" ;; esac + +skopeo_transport_reference() { + local reference=$1 name digest + if [[ $reference == *@sha256:* ]]; then + name=${reference%@sha256:*} + digest="sha256:${reference##*@sha256:}" + [[ ${name##*/} == *:* ]] && name=${name%:*} + printf '%s@%s' "$name" "$digest" + else + printf '%s' "$reference" + fi +} + +resolve_image_manifest() { + local label=$1 image=$2 manifest_file error_file pid elapsed=0 status=0 + manifest_file=$(mktemp /tmp/proxmenux-oci-inspect.XXXXXX) + error_file="${manifest_file}.err" + oci_log "Querying the OCI registry for ${label}: ${image}" + skopeo inspect --no-tags --override-os linux --override-arch "$ARCH" \ + "docker://${image}" >"$manifest_file" 2>"$error_file" & + pid=$! + while kill -0 "$pid" 2>/dev/null; do + sleep 2 + elapsed=$((elapsed + 2)) + done + wait "$pid" || status=$? + if (( status != 0 )); then + cat "$error_file" >>"$OCI_LOG" + rm -f "$manifest_file" "$error_file" + return "$status" + fi + oci_log "Manifest for ${label} resolved in ${elapsed}s" + cat "$manifest_file" + rm -f "$manifest_file" "$error_file" +} + +ensure_image() { + local key=$1 image=$2 transport_image inspect digest short archive_name archive_volume archive_path + local partial log pid bytes elapsed status + msg_info "$(translate "Checking the image in the registry...")" + oci_log "Resolving ${key}: ${image}" + transport_image=$(skopeo_transport_reference "$image") + inspect=$(resolve_image_manifest "$key" "$transport_image") \ + || die "$(translate "Could not resolve the OCI manifest:") $image" + digest=$(jq -er '.Digest' <<<"$inspect") + oci_log "Selected digest for ${key}: ${digest}" + short=${digest#sha256:} + short=${short:0:16} + archive_name="image-nextcloud-${key}_${ARCH}_${short}.tar" + archive_volume="${TEMPLATE_STORAGE}:vztmpl/${archive_name}" + archive_path=$(pvesm path "$archive_volume") + mkdir -p "$(dirname "$archive_path")" + if [[ -s $archive_path ]]; then + msg_info "$(translate "Verifying the image integrity...")" + fi + if [[ -s $archive_path ]] && oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$archive_path"; then + oci_log "Reusing ${archive_volume}" + else + rm -f "$archive_path" + partial="${archive_path}.partial.$$" + log="${partial}.log" + oci_log "Downloading ${image} by digest ${digest}" + skopeo copy --override-os linux --override-arch "$ARCH" --retry-times 3 \ + --retry-delay 5s --image-parallel-copies 1 \ + "docker://${transport_image}" "oci-archive:${partial}:image-nextcloud-${key}" >"$log" 2>&1 & + pid=$! + elapsed=0 + while kill -0 "$pid" 2>/dev/null; do + bytes=$(stat -c %s "$partial" 2>/dev/null || printf 0) + msg_progress "$(translate "Downloading the image:") ${key} · $((bytes / 1048576)) MiB · ${elapsed}s" + sleep 2 + elapsed=$((elapsed + 2)) + done + status=0 + wait "$pid" || status=$? + cat "$log" >>"$OCI_LOG" + rm -f "$log" + (( status == 0 )) || { rm -f "$partial"; die "$(translate "Image download failed:") $image"; } + msg_info "$(translate "Verifying the image integrity...")" + oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$partial" \ + || { rm -f "$partial"; die "$(translate "The downloaded image is corrupt:") $image"; } + mv -f "$partial" "$archive_path" + fi + msg_ok "$(translate "Image:") $image" + RESOLVED_ARCHIVE=$archive_volume + RESOLVED_DIGEST=$digest +} + +APPLICATION_IMAGE=$(jq -er '.container_contract.image.reference' "$TEMPLATE_FILE") +DATABASE_IMAGE=$(jq -er '.compose_stack.services[] | select(.name == "database") | .image' "$TEMPLATE_FILE") +CACHE_IMAGE=$(jq -er '.compose_stack.services[] | select(.name == "cache") | .image' "$TEMPLATE_FILE") + +ensure_image application "$APPLICATION_IMAGE" +APPLICATION_ARCHIVE=$RESOLVED_ARCHIVE +APPLICATION_DIGEST=$RESOLVED_DIGEST +ensure_image database "$DATABASE_IMAGE" +DATABASE_ARCHIVE=$RESOLVED_ARCHIVE +DATABASE_DIGEST=$RESOLVED_DIGEST +ensure_image cache "$CACHE_IMAGE" +CACHE_ARCHIVE=$RESOLVED_ARCHIVE +CACHE_DIGEST=$RESOLVED_DIGEST + +source "$SCRIPT_DIR/oci_native_stack.sh" +oci_native_begin "$APPLICATION_ID" \ + --member application "$APPLICATION_ID" "$APPLICATION_IMAGE" "$APPLICATION_ARCHIVE" \ + --member cache "$CACHE_ID" "$CACHE_IMAGE" "$CACHE_ARCHIVE" \ + --member database "$DATABASE_ID" "$DATABASE_IMAGE" "$DATABASE_ARCHIVE" + +DB_PASSWORD=$(openssl rand -hex 24) +ADMIN_PASSWORD=$(openssl rand -hex 16) +if [[ $APPLICATION_MODE == host-bind ]]; then + install -d -m 0750 -o 100000 -g 100000 "$APPLICATION_ROOT" + APPLICATION_MOUNT="${APPLICATION_ROOT},mp=/var/www/html,backup=0" +else + APPLICATION_MOUNT="${APPLICATION_STORAGE}:${APPLICATION_SIZE},mp=/var/www/html,backup=1" +fi +TAGS="productivity;oci;proxmenux" + +msg_info "$(translate "Creating the container...")" +oci_quiet pct create "$DATABASE_ID" "$DATABASE_ARCHIVE" --rootfs "${ROOTFS_STORAGE}:8" \ + --mp0 "${DATABASE_STORAGE}:${DATABASE_SIZE},mp=/var/lib/postgresql,backup=1" \ + --hostname "${STACK_NAME}-db" --cores 2 --memory 1024 --swap 512 \ + --net0 "name=eth0,bridge=${PRIVATE_BRIDGE},firewall=1,host-managed=1,ip=${DATABASE_ADDRESS},type=veth" \ + --unprivileged 1 --features nesting=1 --cmode console --onboot "$ONBOOT" \ + --startup order=10,up=10,down=30 --tags "$TAGS" \ + --description 'Nextcloud PostgreSQL native OCI' +created_ids+=("$DATABASE_ID") + +oci_quiet pct mount "$DATABASE_ID" +DATABASE_ROOT="/var/lib/lxc/${DATABASE_ID}/rootfs" +POSTGRES_UID=$(awk -F: '$1 == "postgres" {print $3}' "$DATABASE_ROOT/etc/passwd") +POSTGRES_GID=$(awk -F: '$1 == "postgres" {print $4}' "$DATABASE_ROOT/etc/passwd") +[[ -n $POSTGRES_UID && -n $POSTGRES_GID ]] || die "$(translate "The postgres user was not found in the image")" +rm -rf "$DATABASE_ROOT/var/lib/postgresql/lost+found" +install -d -m 0700 -o "$((100000 + POSTGRES_UID))" -g "$((100000 + POSTGRES_GID))" \ + "$DATABASE_ROOT/var/lib/postgresql/data/pgdata" +cat >"$DATABASE_ROOT/usr/local/bin/nextcloud-postgres-lxc-start" <"$APPLICATION_ROOTFS/usr/local/bin/nextcloud-lxc-start" <"$LIFECYCLE_SPEC" +LIFECYCLE_CONFIG_PATH="/etc/pve/priv/proxmenux-stack-${APPLICATION_ID}.json" +if ! oci_quiet bash "$STACK_DEPENDENCY_HOOK" --install "$APPLICATION_ID" "$LIFECYCLE_SPEC"; then + rm -f "$LIFECYCLE_SPEC" + die "$(translate "Could not install the stack startup hook")" +fi +rm -f "$LIFECYCLE_SPEC" +msg_ok "$(translate "Stack startup hook installed")" + +wait_command() { + local label=$1 retries=$2 + shift 2 + local attempt + for attempt in $(seq 1 "$retries"); do + "$@" >/dev/null 2>&1 && return 0 + sleep 2 + done + die "$(translate "Health check failed:") $label" +} + +APPLICATION_LAN_IP="" +if (( START_AFTER == 1 )); then + msg_info "$(translate "Starting the service:") PostgreSQL" + oci_quiet pct start "$DATABASE_ID" + wait_command PostgreSQL 60 pct exec "$DATABASE_ID" -- \ + pg_isready -h "$DATABASE_IP" -U nextcloud -d nextcloud + msg_ok "$(translate "Service ready:") PostgreSQL" + msg_info "$(translate "Starting the service:") Redis" + oci_quiet pct start "$CACHE_ID" + wait_command Redis 60 pct exec "$CACHE_ID" -- redis-cli -h "$CACHE_IP" ping + msg_ok "$(translate "Service ready:") Redis" + msg_info "$(translate "Starting the service:") Nextcloud" + oci_quiet pct start "$APPLICATION_ID" + + msg_info "$(translate "Waiting for the application to respond...")" + for _ in $(seq 1 120); do + APPLICATION_LAN_IP=$(lxc-info -n "$APPLICATION_ID" -iH 2>/dev/null \ + | grep -E '^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$' \ + | grep -vFx "$APPLICATION_IP" | head -n 1 || true) + if [[ -n $APPLICATION_LAN_IP ]] \ + && curl -fsS -H 'Host: localhost' \ + "http://${APPLICATION_LAN_IP}/status.php" >/dev/null 2>&1; then + break + fi + sleep 2 + done + [[ -n $APPLICATION_LAN_IP ]] \ + || die "$(translate "The application did not get an address on the access network:") Nextcloud" + # Nextcloud 34 validates status.php against trusted_domains before the LAN IP + # can be registered. localhost is the official image's initial trusted host. + STATUS_JSON=$(curl -fsS -H 'Host: localhost' \ + "http://${APPLICATION_LAN_IP}/status.php") + jq -e '.installed == true and .maintenance == false and .needsDbUpgrade == false' \ + <<<"$STATUS_JSON" >/dev/null \ + || die "$(translate "The application did not complete its initial setup:") Nextcloud" + msg_ok "$(translate "Application responding:") http://${APPLICATION_LAN_IP}/" + + msg_info "$(translate "Applying the initial Nextcloud settings...")" + OCC=(pct exec "$APPLICATION_ID" -- su -s /bin/sh www-data -c) + oci_quiet "${OCC[@]}" "php /var/www/html/occ config:system:set trusted_domains 1 --value='${APPLICATION_LAN_IP}'" + oci_quiet "${OCC[@]}" "php /var/www/html/occ config:system:set trusted_domains 2 --value='${STACK_NAME}'" + oci_quiet "${OCC[@]}" "php /var/www/html/occ config:system:set maintenance_window_start --type=integer --value='${MAINTENANCE_WINDOW}'" + oci_quiet "${OCC[@]}" "php /var/www/html/occ config:system:set default_phone_region --value='${PHONE_REGION}'" + oci_quiet "${OCC[@]}" "php /var/www/html/occ background:cron" + oci_quiet "${OCC[@]}" "php /var/www/html/occ maintenance:repair --include-expensive" + msg_ok "$(translate "Initial Nextcloud settings applied")" +fi + +RESULT=$(jq -nc \ + --argjson vmid "$APPLICATION_ID" \ + --arg ip "$APPLICATION_LAN_IP" \ + --argjson application_id "$APPLICATION_ID" \ + --argjson database_id "$DATABASE_ID" \ + --argjson cache_id "$CACHE_ID" \ + --arg admin_user "$ADMIN_USERNAME" \ + --arg admin_password "$ADMIN_PASSWORD" \ + --arg application_digest "$APPLICATION_DIGEST" \ + --arg database_digest "$DATABASE_DIGEST" \ + --arg cache_digest "$CACHE_DIGEST" \ + --arg admin_label "$(translate "Initial Nextcloud administrator")" \ + --arg log "$OCI_LOG" \ + '{ + vmid: $vmid, + ip: (if $ip == "" then null else $ip end), + stack_vmids: { + application: $application_id, + database: $database_id, + cache: $cache_id + }, + urls: (if $ip == "" then [] else [{label: "Nextcloud WebUI", url: ("http://" + $ip + "/")}] end), + credentials: [{ + label: $admin_label, + username: $admin_user, + password: $admin_password, + change_required: true + }], + image_digests: { + application: $application_digest, + database: $database_digest, + cache: $cache_digest + }, + log: $log + }') +INSTALL_COMPLETE=1 +oci_native_finalize +printf 'PROXMENUX_RESULT=%s\n' "$(printf '%s' "$RESULT" | base64 -w0)" diff --git a/oci/remote/install_oci.sh b/oci/remote/install_oci.sh new file mode 100755 index 00000000..647b54bc --- /dev/null +++ b/oci/remote/install_oci.sh @@ -0,0 +1,1918 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +TEMPLATE_FILE=${1:?template JSON required} +DEPLOYMENT_FILE=${2:?deployment JSON required} +DRY_RUN=${3:-0} + +SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd) +source "$SCRIPT_DIR/oci_ui.sh" +# A transaction captures this output in a private file: no spinner there. +[[ -z ${PROXMENUX_OCI_TRANSACTION:-} ]] || OCI_SPINNER=0 + +die() { + stop_spinner + msg_error "$*" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + exit 1 +} + +mount_ct_rootfs() { + oci_quiet pct mount "$VMID" || die "$(translate "Could not mount the container filesystem:") CT $VMID" +} + +merge_json_defaults() { + jq -n --slurpfile existing "$1" --slurpfile defaults "$2" ' + def fill($d): + if type != "object" then error("Existing JSON section is not an object") + else reduce ($d | keys_unsorted[]) as $key (.; + if has($key) then + if ($d[$key] | type) == "object" then .[$key] |= fill($d[$key]) else . end + else .[$key] = $d[$key] end) + end; + if ($existing | length) != 1 or ($defaults | length) != 1 + or ($defaults[0] | type) != "object" + then error("Expected one JSON object per file") + else $existing[0] | fill($defaults[0]) end' +} + +gpu_vendor_name() { + case "$1" in + 0x1002) printf 'AMD' ;; + 0x8086) printf 'Intel' ;; + 0x10de) printf 'NVIDIA' ;; + *) printf '%s' "$1" ;; + esac +} + +validate_gpu_vendors() { + local device path node vendor + while IFS= read -r device; do + path=$(jq -er '.host_path' <<<"$device") + [[ $path =~ ^/dev/dri/renderD[0-9]+$ && -c $path ]] \ + || die "$(translate "The selected render device does not exist:") $path" + node=${path##*/} + vendor=$(cat "/sys/class/drm/${node}/device/vendor" 2>/dev/null) \ + || die "$(translate "Cannot identify the vendor of the device:") $path" + jq -e --arg vendor "$vendor" '.drm_vendor_ids | index($vendor) != null' <<<"$device" >/dev/null \ + || die "$(translate "The GPU vendor does not match the selected GPU profile:") $path ($vendor)" + msg_ok "$(translate "GPU verified:") $path ($(gpu_vendor_name "$vendor"), GID $(stat -c '%g' "$path"))" + done < <(jq -c '.devices[]? | select(.drm_vendor_ids != null)' "$DEPLOYMENT_FILE") +} + +show_gpu_inventory() { + jq -e '.devices[]? | select(.kind == "nvidia-runtime" or + ((.host_path // "") | startswith("/dev/dri")) or .host_path == "/dev/kfd")' \ + "$DEPLOYMENT_FILE" >/dev/null || return 0 + local node vendor kind + oci_log "Host DRM inventory (additional GPUs are not passed through automatically):" + for node in /dev/dri/renderD*; do + [[ -c $node ]] || continue + vendor=$(cat "/sys/class/drm/${node##*/}/device/vendor" 2>/dev/null || true) + oci_log " $node vendor=${vendor:-unknown} uid=$(stat -c '%u' "$node") gid=$(stat -c '%g' "$node") mode=$(stat -c '%a' "$node")" + done + while IFS=$'\t' read -r node kind; do + if [[ $kind == character-device-tree ]]; then + [[ -d $node ]] || die "$(translate "The selected GPU directory does not exist:") $node" + else + [[ -c $node ]] || die "$(translate "The selected GPU device does not exist:") $node" + fi + done < <(jq -r '.devices[]? | select( + ((.host_path // "") | startswith("/dev/dri")) or .host_path == "/dev/kfd") | + [.host_path, (.kind // "character-device")] | @tsv' "$DEPLOYMENT_FILE") +} + +apply_native_device_permissions() { + [[ $(jq -r '.device_permissions.strategy // empty' "$DEPLOYMENT_FILE") == linuxserver-native-init ]] || return 0 + (( ${#RESOLVED_CHARACTER_DEVICES[@]} > 0 )) || return 0 + # Expand after NVIDIA/DVB discovery: directories and fixed renderD128 miss devices. + local value temporary + value=$(IFS=' '; printf '%s' "${RESOLVED_CHARACTER_DEVICES[*]}") + temporary=$(mktemp) + jq --arg value "$value" '.environment = + ([.environment[] | select(.name != "ATTACHED_DEVICES_PERMS")] + + [{name:"ATTACHED_DEVICES_PERMS", value:$value, sensitive:false}])' \ + "$DEPLOYMENT_FILE" >"$temporary" + cat "$temporary" >"$DEPLOYMENT_FILE" + rm -f "$temporary" +} + +check_native_device_permissions() { + [[ $(jq -r '.device_permissions.strategy // empty' "$DEPLOYMENT_FILE") == linuxserver-native-init ]] || return 0 + (( ${#RESOLVED_CHARACTER_DEVICES[@]} > 0 )) || return 0 + local attempt + msg_info "$(translate "Checking the device permissions for the application user...")" + oci_log "Checking device access as abc (this is not a codec test)." + for (( attempt=0; attempt<60; attempt++ )); do + pct status "$VMID" | grep -q 'status: running' \ + || die "$(translate "The container stopped before the GPU permissions were verified:") CT $VMID" + if pct exec "$VMID" -- s6-setuidgid abc sh -c \ + 'for path do test -r "$path" && test -w "$path" || exit 1; done' \ + check "${RESOLVED_CHARACTER_DEVICES[@]}" >/dev/null 2>&1; then + msg_ok "$(translate "Device permissions verified for the application user")" + return 0 + fi + sleep 2 + done + die "$(translate "The image did not grant the application user access to the devices; check its native init. Host permissions were not relaxed.")" +} + +configure_cpu_allocation() { + local mode + mode=$(jq -er '.proxmox.installer_profile.cpu_allocation // "cpuset"' "$TEMPLATE_FILE") + case "$mode" in + cpuset|quota) ;; + *) die "$(translate "Unsupported CPU allocation mode:") $mode" ;; + esac + if [[ $mode == quota || -n ${HOST_MONITOR:-} ]]; then + CPU_CREATE_ARGS=(--cpulimit "$CORES") + else + CPU_CREATE_ARGS=(--cores "$CORES") + fi +} + +validate_rlimits() { + local name soft hard + jq -e '(.resources.rlimits // []) | type == "array" and + (all(.[]; type == "object" and (.name|type)=="string" and + (.soft|type)=="string" and (.hard|type)=="string")) and + ((map(.name)|unique|length) == length)' "$DEPLOYMENT_FILE" >/dev/null \ + || die "$(translate "Invalid process limits format")" + while IFS=$'\t' read -r name soft hard; do + [[ $name =~ ^(as|core|cpu|data|fsize|locks|memlock|msgqueue|nice|nofile|nproc|rss|rtprio|rttime|sigpending|stack)$ ]] \ + || die "$(translate "Unsupported prlimit resource")" + [[ $soft =~ ^(unlimited|0|[1-9][0-9]{0,17})$ && $hard =~ ^(unlimited|0|[1-9][0-9]{0,17})$ ]] \ + || die "$(translate "Invalid prlimit value")" + if [[ $hard != unlimited ]]; then + [[ $soft != unlimited ]] && (( soft <= hard )) || die "$(translate "The prlimit soft value exceeds the hard value")" + fi + done < <(jq -r '.resources.rlimits[]? | [.name,.soft,.hard] | @tsv' "$DEPLOYMENT_FILE") +} + +apply_rlimits() { + local name soft hard + while IFS=$'\t' read -r name soft hard; do + set_lxc_directive "lxc.prlimit.${name}" "${soft}:${hard}" + done < <(jq -r '.resources.rlimits[]? | [.name,.soft,.hard] | @tsv' "$DEPLOYMENT_FILE") +} + +validate_host_monitor() { + HOST_MONITOR=$(jq -r '.host_monitor // empty' "$DEPLOYMENT_FILE") + [[ -n $HOST_MONITOR ]] || return 0 + local expected port + case "$HOST_MONITOR" in + glances) expected=nicolargo/glances:latest; port=61208 ;; + netdata) expected=netdata/netdata:latest; port=19999 ;; + *) die "$(translate "Unknown host monitor")" ;; + esac + [[ $APP_ID == "image-${HOST_MONITOR}" && $IMAGE_REF == "$expected" ]] \ + || die "$(translate "Image not allowed for the host monitor profile")" + [[ $(jq -r '.proxmox.installer_profile.host_monitor // empty' "$TEMPLATE_FILE") == "$HOST_MONITOR" ]] \ + || die "$(translate "Inconsistent host monitor profile")" + jq -e '.security.unprivileged == false and .security.privileged_acknowledged == true' "$DEPLOYMENT_FILE" >/dev/null \ + || die "$(translate "The host monitor needs consent for privileged access to the host")" + [[ $IPV4 == host && -z $MAC_ADDRESS && -z $GATEWAY ]] \ + || die "$(translate "The host monitor uses the host network, without DHCP or its own gateway")" + HOST_MONITOR_IP=$(ip -4 -o addr show dev "$BRIDGE" scope global | awk 'NR==1 {split($4,a,"/"); print a[1]}') + [[ -n $HOST_MONITOR_IP ]] || die "$(translate "The host has no IPv4 address on the selected bridge")" + require_command ss + [[ -z $(ss -H -ltn "sport = :${port}") ]] || die "$(translate "The host port is already in use:") ${port}" +} + +apply_host_monitor() { + [[ -n ${HOST_MONITOR:-} ]] || return 0 + # PVE permits lxc.include but not namespace keys directly in the CT config. + # This static, cluster-persistent companion must accompany cross-host restores. + local include=/etc/pve/lxc/proxmenux-host-monitor native + native=$'lxc.namespace.share.pid = 1\nlxc.namespace.share.net = 1' + if [[ -e $include ]]; then + [[ $(cat "$include") == "$native" ]] || die "$(translate "A different host monitor include already exists; it is not overwritten:") $include" + else + printf '%s\n' "$native" >"$include" + fi + [[ -z ${SYSCTL_INCLUDE:-} ]] || die "$(translate "The host monitor profile does not support another sysctl include")" + set_lxc_directive lxc.include "$include" + set_lxc_directive lxc.net.0.type none + # LXCFS reports cgroup-limited values, which would misrepresent the monitored host. + # Do not remove the Proxmox pre-start, autodev or post-stop hooks. + set_lxc_directive lxc.hook.mount "" + msg_ok "$(translate "Host monitor configured: shared PID and network namespaces, LXCFS disabled in this container")" + msg_info2 "$(translate "To restore it on another host, keep this file (not included in the vzdump backup):") $include" +} + +verify_host_monitor() { + [[ -n ${HOST_MONITOR:-} ]] || return 0 + local pid namespace actual + pid=$(lxc-info -n "$VMID" -pH) + [[ $pid =~ ^[0-9]+$ && $pid -gt 1 ]] || die "$(translate "Invalid host monitor PID")" + for namespace in pid net; do + actual=$(readlink "/proc/$pid/ns/$namespace") + [[ $actual == "$(readlink "/proc/1/ns/$namespace")" ]] \ + || die "$(translate "The host monitor does not share this host namespace:") $namespace" + done + [[ $(pct exec "$VMID" -- cat /proc/meminfo | sed -n '/^MemTotal:/p') == "$(sed -n '/^MemTotal:/p' /proc/meminfo)" ]] \ + || die "$(translate "The host monitor does not see the real host memory")" + msg_ok "$(translate "Host monitor verified: PID and network namespaces and memory match the host")" +} + +RUNTIME_CONSOLE_LOG="" +SYSCTL_INCLUDE="" +SECCOMP_PROFILE_FILE="" +CT_CREATED=0 +INSTALL_COMPLETE=0 +PRESERVE_FAILED_CT=0 + +cleanup_runtime_console_log() { + [[ -n $RUNTIME_CONSOLE_LOG ]] || return 0 + if [[ -f ${CONF:-} ]]; then + local temporary_conf + temporary_conf=$(mktemp) + awk ' + $0 !~ /^lxc\.console\.logfile:/ && + $0 !~ /^lxc\.console\.size:/ && + $0 !~ /^lxc\.console\.rotate:/ + ' "$CONF" >"$temporary_conf" + cat "$temporary_conf" >"$CONF" + rm -f "$temporary_conf" + fi + rm -f "$RUNTIME_CONSOLE_LOG" "${RUNTIME_CONSOLE_LOG}.1" + RUNTIME_CONSOLE_LOG="" +} + +# A derived check accepts any HTTP answer below 500: the application is up, +# even when its first page is a redirect or asks for a login. +healthcheck_probe() { + if [[ ${HC_ANY_STATUS:-false} == true ]]; then + local code + code=$(curl "${CURL_ARGS[@]}" "$HC_URL" 2>/dev/null) || return 1 + [[ $code =~ ^[1-4][0-9][0-9]$ ]] + else + curl "${CURL_ARGS[@]}" "$HC_URL" 2>/dev/null + fi +} + +cleanup_failed_install() { + local status=$? + stop_spinner + if [[ -n ${PROXMENUX_OCI_TRANSACTION:-} ]]; then + # The transaction owns recovery. Destroying this CT could destroy reused data. + cleanup_runtime_console_log || true + return "$status" + fi + if (( status != 0 )) && [[ -n ${INSTANCE_ID:-} ]]; then + oci_quiet python3 "${SCRIPT_DIR}/oci_instances.py" failed "$VMID" || true + fi + # A step may fail while the rootfs is mounted; the mount lock would block + # both keeping the CT usable and destroying it. + if (( status != 0 && CT_CREATED == 1 )); then + pct unmount "$VMID" >/dev/null 2>&1 || true + fi + if (( status != 0 && CT_CREATED == 1 && INSTALL_COMPLETE == 0 && PRESERVE_FAILED_CT == 1 )); then + oci_log "Container kept for inspection; console log: $RUNTIME_CONSOLE_LOG" + msg_warn "$(translate "Container kept with its data; the installation was not validated:") CT $VMID · $(translate "Full log:") ${OCI_LOG:-$RUNTIME_CONSOLE_LOG}" + [[ -z $RUNTIME_CONSOLE_LOG ]] || msg_info2 "$(translate "Console log:") $RUNTIME_CONSOLE_LOG" + return "$status" + fi + cleanup_runtime_console_log || true + if (( status != 0 && CT_CREATED == 1 && INSTALL_COMPLETE == 0 )); then + msg_info "$(translate "Rolling back the incomplete container") CT $VMID..." + oci_quiet pct stop "$VMID" || true + if oci_quiet pct destroy "$VMID" --purge 1 || oci_quiet pct destroy "$VMID"; then + msg_ok "$(translate "Incomplete container removed:") CT $VMID" + else + msg_warn "$(translate "The container could not be removed automatically:") CT $VMID" + fi + fi + # The include files belong to the CT: only remove them once it is gone. + if (( status != 0 )) && ! { [[ -n ${VMID:-} ]] && pct config "$VMID" >/dev/null 2>&1; }; then + [[ -z $SYSCTL_INCLUDE ]] || rm -f "$SYSCTL_INCLUDE" + [[ -z $SECCOMP_PROFILE_FILE ]] || rm -f "$SECCOMP_PROFILE_FILE" + fi + return "$status" +} + +ensure_rootfs_directory() { + local rootfs=$1 directory=$2 current parent i + local -a missing=() + [[ $directory == "$rootfs" || $directory == "$rootfs"/* ]] \ + || die "$(translate "The prepared directory escapes the rootfs:") $directory" + current=$directory + while [[ ! -e $current ]]; do + missing+=("$current") + current=$(dirname "$current") + done + [[ -d $current ]] || die "$(translate "The parent of the target is not a directory:") $current" + for ((i = ${#missing[@]} - 1; i >= 0; i--)); do + parent=$(dirname "${missing[$i]}") + mkdir "${missing[$i]}" + chown --reference="$parent" "${missing[$i]}" + chmod 0755 "${missing[$i]}" + done +} + +prepare_file_mount_target() { + local requested_target=$1 + local rootfs="/var/lib/lxc/${VMID}/rootfs" + local requested_parent resolved_parent target_path + local failed=0 + + mount_ct_rootfs + requested_parent=$(dirname "$requested_target") + resolved_parent=$(readlink -m "${rootfs}${requested_parent}") + if [[ $resolved_parent != "$rootfs" && $resolved_parent != "$rootfs"/* ]]; then + oci_quiet pct unmount "$VMID" || true + die "$(translate "The bind mount target escapes the rootfs:") $requested_target" + fi + target_path="${resolved_parent}/$(basename "$requested_target")" + PREPARED_FILE_TARGET="/${target_path#"${rootfs}/"}" + ensure_rootfs_directory "$rootfs" "$(dirname "$target_path")" + if [[ -L $target_path ]]; then + rm -f "$target_path" || failed=1 + elif [[ -e $target_path && ! -f $target_path ]]; then + oci_log "The file bind mount target cannot be replaced: $requested_target" + failed=1 + fi + if (( failed == 0 )) && [[ ! -e $target_path ]]; then + : >"$target_path" || failed=1 + chown --reference="$(dirname "$target_path")" "$target_path" || failed=1 + chmod 0644 "$target_path" || failed=1 + fi + oci_quiet pct unmount "$VMID" || failed=1 + (( failed == 0 )) \ + || die "$(translate "Could not prepare the file bind mount target:") $requested_target" +} + +run_pre_start_repair() { + local repair_json=$1 + local repair_id check_type python_path module check_package minimum_version + local repair_type package index_url target_version break_system_packages no_dependencies + local rootfs="/var/lib/lxc/${VMID}/rootfs" + local check_passed=0 failed=0 repaired=0 + local -a pip_args + + repair_id=$(jq -er '.id' <<<"$repair_json") + if ! jq -e --arg architecture "$ARCH" '.architectures | index($architecture) != null' \ + <<<"$repair_json" >/dev/null; then + oci_log "Skipping repair $repair_id for architecture $ARCH" + return 0 + fi + check_type=$(jq -er '.check.type' <<<"$repair_json") + python_path=$(jq -er '.check.python_path' <<<"$repair_json") + repair_type=$(jq -er '.repair.type' <<<"$repair_json") + package=$(jq -er '.repair.package' <<<"$repair_json") + index_url=$(jq -er '.repair.index' <<<"$repair_json") + break_system_packages=$(jq -r '.repair.break_system_packages // false' <<<"$repair_json") + no_dependencies=$(jq -r '.repair.no_dependencies // false' <<<"$repair_json") + [[ $python_path == /* && $python_path != *[[:space:]]* ]] \ + || die "$(translate "Invalid Python path in the repair:") $repair_id" + [[ $package =~ ^[A-Za-z0-9][A-Za-z0-9._-]*$ ]] || die "$(translate "Invalid Python package:") $package" + [[ $index_url == https://* && $index_url != *[[:space:]]* ]] \ + || die "$(translate "Invalid Python index:") $index_url" + [[ $break_system_packages == true && $no_dependencies == true ]] \ + || die "$(translate "The repair must preserve the image dependencies:") $repair_id" + + case "$check_type" in + python-import) + module=$(jq -er '.check.module' <<<"$repair_json") + [[ $module =~ ^[A-Za-z_][A-Za-z0-9_.]*$ ]] || die "$(translate "Invalid Python module:") $module" + ;; + python-package-minimum-version) + check_package=$(jq -er '.check.package' <<<"$repair_json") + minimum_version=$(jq -er '.check.minimum_version' <<<"$repair_json") + [[ $check_package =~ ^[A-Za-z0-9][A-Za-z0-9._-]*$ ]] \ + || die "$(translate "Invalid check package:") $check_package" + [[ $minimum_version =~ ^[0-9]+([.][0-9]+)*$ ]] \ + || die "$(translate "Invalid minimum version:") $minimum_version" + ;; + *) die "$(translate "Unsupported pre-start check:") $check_type" ;; + esac + + case "$repair_type" in + pip-reinstall-installed-version) ;; + pip-install-exact-version) + target_version=$(jq -er '.repair.version' <<<"$repair_json") + [[ $target_version =~ ^[A-Za-z0-9][A-Za-z0-9.+_-]*$ ]] \ + || die "$(translate "Invalid repair version:") $target_version" + ;; + *) die "$(translate "Unsupported pre-start repair:") $repair_type" ;; + esac + + mount_ct_rootfs + msg_info "$(translate "Checking the image compatibility:") $repair_id..." + case "$check_type" in + python-import) + chroot "$rootfs" "$python_path" -c "import ${module}" >/dev/null 2>&1 \ + && check_passed=1 + ;; + python-package-minimum-version) + chroot "$rootfs" "$python_path" -c \ + 'from importlib.metadata import version; from packaging.version import Version; import sys; sys.exit(0 if Version(version(sys.argv[1])) >= Version(sys.argv[2]) else 1)' \ + "$check_package" "$minimum_version" >/dev/null 2>&1 && check_passed=1 + ;; + esac + + if (( check_passed == 1 )); then + oci_log "Compatibility check passed for $repair_id; no changes applied" + else + if [[ $repair_type == pip-reinstall-installed-version ]]; then + target_version=$(chroot "$rootfs" "$python_path" -c \ + 'import importlib.metadata,sys; print(importlib.metadata.version(sys.argv[1]))' \ + "$package" 2>/dev/null) || failed=1 + if (( failed == 0 )) && [[ ! $target_version =~ ^[A-Za-z0-9][A-Za-z0-9.+_-]*$ ]]; then + oci_log "Invalid package version for $package: $target_version" + failed=1 + fi + fi + if (( failed == 0 )); then + oci_log "Compatibility check failed; installing ${package}==${target_version} without changing dependencies" + pip_args=(--disable-pip-version-check --no-cache-dir --force-reinstall) + [[ $break_system_packages == true ]] && pip_args+=(--break-system-packages) + [[ $no_dependencies == true ]] && pip_args+=(--no-deps) + oci_quiet chroot "$rootfs" "$python_path" -m pip install "${pip_args[@]}" \ + --index-url "$index_url" "${package}==${target_version}" || failed=1 + fi + if (( failed == 0 )); then + check_passed=0 + case "$check_type" in + python-import) + chroot "$rootfs" "$python_path" -c "import ${module}" >/dev/null 2>&1 \ + && check_passed=1 + ;; + python-package-minimum-version) + chroot "$rootfs" "$python_path" -c \ + 'from importlib.metadata import version; from packaging.version import Version; import sys; sys.exit(0 if Version(version(sys.argv[1])) >= Version(sys.argv[2]) else 1)' \ + "$check_package" "$minimum_version" >/dev/null 2>&1 && check_passed=1 + ;; + esac + (( check_passed == 1 )) || failed=1 + repaired=1 + fi + fi + oci_quiet pct unmount "$VMID" || failed=1 + (( failed == 0 )) || die "$(translate "Could not apply the pre-start repair:") $repair_id" + if (( repaired == 1 )); then + msg_ok "$(translate "Image compatibility restored:") ${package}==${target_version}" + else + msg_ok "$(translate "Image compatibility verified:") $repair_id" + fi +} + +apply_post_start_configuration() { + local configuration=$1 type configuration_id timeout required path found=0 elapsed=0 + local rootfs="/var/lib/lxc/${VMID}/rootfs" mounted=0 failed=0 + configuration_id=$(jq -er '.id' <<<"$configuration") + type=$(jq -er '.type' <<<"$configuration") + timeout=$(jq -r '.timeout_seconds // 120' <<<"$configuration") + required=$(jq -r '.required // true' <<<"$configuration") + [[ $timeout =~ ^[0-9]+$ && $timeout -gt 0 ]] \ + || die "$(translate "Invalid post-start timeout in the configuration:") $configuration_id" + + case "$type" in + jellyfin-encoding-xml) + msg_info "$(translate "Waiting for the initial Jellyfin configuration...")" + while (( elapsed < timeout )); do + while IFS= read -r path; do + [[ $path == /* && $path != *[[:space:]]* ]] \ + || die "$(translate "Invalid Jellyfin path:") $path" + if pct exec "$VMID" -- test -f "$path" >/dev/null 2>&1; then + found=1 + break + fi + done < <(jq -r '.candidate_paths[]?' <<<"$configuration") + (( found == 1 )) && break + sleep 2 + elapsed=$((elapsed + 2)) + msg_progress "$(translate "Waiting for the initial Jellyfin configuration...") ${elapsed}/${timeout} s" + done + if (( found == 0 )); then + if [[ $required == true ]]; then + die "$(translate "Jellyfin did not create encoding.xml before the timeout")" + fi + msg_warn "$(translate "Skipped because Jellyfin did not create encoding.xml:") $configuration_id" + return 0 + fi + + msg_info "$(translate "Applying the Jellyfin configuration:") $configuration_id..." + if ! pct shutdown "$VMID" --timeout "$SHUTDOWN_TIMEOUT" >/dev/null 2>&1; then + if [[ $(pct status "$VMID" 2>/dev/null || true) == "status: running" ]]; then + oci_quiet pct stop "$VMID" \ + || die "$(translate "The container did not stop to update its persistent configuration:") CT $VMID" + fi + fi + [[ $(pct status "$VMID" 2>/dev/null || true) == "status: stopped" ]] \ + || die "$(translate "The container did not stop to update its persistent configuration:") CT $VMID" + mount_ct_rootfs + mounted=1 + oci_quiet python3 "$JELLYFIN_CONFIGURATOR" "$rootfs" "$configuration" || failed=1 + oci_quiet pct unmount "$VMID" || failed=1 + mounted=0 + if (( failed != 0 )); then + (( mounted == 0 )) || pct unmount "$VMID" >/dev/null 2>&1 || true + die "$(translate "Could not apply the Jellyfin configuration:") $configuration_id" + fi + oci_quiet pct start "$VMID" || die "$(translate "The container could not be started:") CT $VMID" + msg_ok "$(translate "Jellyfin configuration applied:") $configuration_id" + ;; + *) die "$(translate "Unsupported post-start configuration:") $type" ;; + esac +} + +# $1: optional result label shown before the address. +detect_container_ipv4() { + local attempt addresses label=${1:-} + if [[ -n ${HOST_MONITOR:-} ]]; then + IP=$HOST_MONITOR_IP + msg_ok "${label:+$label · }$(translate "IP address:") $IP" + return 0 + fi + IP="" + for attempt in $(seq 1 15); do + IP=$(lxc-info -n "$VMID" -iH 2>/dev/null | grep -m1 -E '^[0-9]+\.' || true) + if [[ -z $IP ]]; then + addresses=$(pct exec "$VMID" -- hostname -I 2>/dev/null || true) + IP=$(tr ' ' '\n' <<<"$addresses" | grep -m1 -E '^[0-9]+\.' || true) + fi + [[ -n $IP ]] && break + msg_progress "$(translate "Waiting for the network address...") $((attempt * 2))/30 s" + sleep 2 + done + if [[ -n $IP ]]; then + msg_ok "${label:+$label · }$(translate "IP address:") $IP" + else + [[ -z $label ]] || msg_ok "$label" + msg_warn "$(translate "No IPv4 address was detected after 30 seconds.")" + fi +} + +trap cleanup_failed_install EXIT + +# A credential the image prints on its boot console, captured with the regular +# expression of the template (one capture group, the last match wins). +capture_console_credential() { + local logfile=$1 pattern=$2 timeout=$3 + local elapsed=0 password="" + while (( elapsed < timeout )); do + if [[ -s $logfile ]]; then + password=$(tr -d '\r' <"$logfile" | python3 -c 'import re, sys +matches = re.findall(sys.argv[1], sys.stdin.read()) +print(matches[-1] if matches else "")' "$pattern") + [[ -n $password ]] && break + fi + sleep 1 + elapsed=$((elapsed + 1)) + msg_progress "$(translate "Waiting for the temporary password...") ${elapsed}/${timeout} s" >&2 + done + printf '%s' "$password" +} + +# A credential that the application writes into a file of its own container. +capture_container_file_credential() { + local vmid=$1 path=$2 pattern=$3 timeout=$4 + local elapsed=0 content="" value="" + while (( elapsed < timeout )); do + content=$(pct exec "$vmid" -- cat "$path" 2>/dev/null) || content="" + if [[ -n $content ]]; then + if [[ -n $pattern ]]; then + value=$(printf '%s' "$content" | python3 -c 'import re, sys +match = re.search(sys.argv[1], sys.stdin.read(), re.M) +print(match.group(1) if match else "")' "$pattern") + else + value=$(head -n 1 <<<"$content") + fi + value=$(tr -d '\r\n' <<<"$value") + [[ -n $value ]] && { printf '%s' "$value"; return 0; } + fi + sleep 3 + elapsed=$((elapsed + 3)) + msg_progress "$(translate "Waiting for the password of the application...") ${elapsed}/${timeout} s" >&2 + done + return 1 +} + +require_command() { + command -v "$1" >/dev/null 2>&1 || die "$(translate "Required command not found:") $1" +} + +json_value() { + jq -er "$1" "$2" +} + +append_deployment_environment_csv() { + local name=$1 value=$2 temporary + temporary=$(mktemp) + jq --arg name "$name" --arg value "$value" ' + .environment = ((.environment // []) as $environment | + if ($environment | any(.name == $name)) then + $environment | map( + if .name == $name then + .value = (((.value // "") | split(",")) + [$value] + | map(select(length > 0)) | unique | join(",")) + else . end + ) + else + $environment + [{name: $name, value: $value, sensitive: false}] + end) + ' "$DEPLOYMENT_FILE" >"$temporary" + cat "$temporary" >"$DEPLOYMENT_FILE" + rm -f "$temporary" +} + +set_lxc_directive() { + local key=$1 value=$2 escaped_key temporary_conf + escaped_key=${key//./\.} + temporary_conf=$(mktemp) + sed -E "/^${escaped_key}:/d" "$CONF" >"$temporary_conf" + printf '%s: %s\n' "$key" "$value" >>"$temporary_conf" + cat "$temporary_conf" >"$CONF" + rm -f "$temporary_conf" +} + +add_device() { + local host_path=$1 expected_type=$2 mode_spec=$3 gid_strategy=$4 deny_write=$5 + local device_uid=${6:-} + local mode gid dev_value + [[ $host_path == /dev/* && $host_path != *[[:space:]]* && $host_path != *","* ]] \ + || die "$(translate "Invalid device path:") $host_path" + if [[ $expected_type == character ]]; then + [[ -c $host_path ]] || die "$(translate "The character device does not exist:") $host_path" + elif [[ $expected_type == block ]]; then + [[ -b $host_path ]] || die "$(translate "The block device does not exist:") $host_path" + else + die "$(translate "Unsupported native device type:") $expected_type" + fi + if [[ $mode_spec == preserve-host ]]; then + mode=$(stat -c '%a' "$host_path") + mode="0${mode}" + else + mode=$mode_spec + fi + [[ $mode =~ ^0?[0-7]{3}$ ]] || die "$(translate "Invalid device mode:") $mode" + dev_value="path=${host_path},mode=${mode},deny-write=${deny_write}" + if [[ -n $device_uid ]]; then + [[ $device_uid =~ ^[0-9]{1,10}$ ]] && (( device_uid < 4294967295 )) \ + || die "$(translate "Invalid device UID:") $device_uid" + dev_value="${dev_value},uid=${device_uid}" + fi + if [[ $gid_strategy == host-device-gid ]]; then + gid=$(stat -c '%g' "$host_path") + dev_value="${dev_value},gid=${gid}" + elif [[ $gid_strategy != none ]]; then + die "$(translate "Unsupported GID strategy:") $gid_strategy" + fi + oci_quiet pct set "$VMID" "--dev${DEVICE_INDEX}" "$dev_value" \ + || die "$(translate "Could not add the device to the container:") $host_path" + if [[ $expected_type == character ]]; then + RESOLVED_CHARACTER_DEVICES+=("$host_path") + fi + DEVICE_INDEX=$((DEVICE_INDEX + 1)) +} + +add_character_device() { + add_device "$1" character "$2" "$3" "$4" "${5:-}" +} + +prepare_nvidia_driver_links() { + local source=$1 target=$2 + local rootfs="/var/lib/lxc/${VMID}/rootfs" + local host_link link_target container_link failed=0 + [[ $target == /usr/lib/* ]] || return 0 + + mount_ct_rootfs + while IFS= read -r host_link; do + [[ $(readlink -f "$host_link") == "$source" ]] || continue + link_target=$(readlink "$host_link") + container_link="${rootfs}${host_link}" + if [[ -e $container_link && ! -f $container_link && ! -L $container_link ]]; then + oci_log "The NVIDIA link cannot replace this target: $host_link" + failed=1 + break + fi + ensure_rootfs_directory "$rootfs" "$(dirname "$container_link")" || failed=1 + rm -f "$container_link" || failed=1 + ln -s "$link_target" "$container_link" || failed=1 + done < <(find "$(dirname "$target")" -maxdepth 1 -type l -print 2>/dev/null | sort) + oci_quiet pct unmount "$VMID" || failed=1 + (( failed == 0 )) || die "$(translate "Could not prepare the NVIDIA driver links")" +} + +source "$SCRIPT_DIR/oci_nvidia_setup.sh" + +apply_extra_hosts() { + local count rootfs hosts_file temporary address hostname bridge_address failed=0 + count=$(jq '.extra_hosts? // [] | length' "$DEPLOYMENT_FILE") + (( count > 0 )) || return 0 + rootfs="/var/lib/lxc/${VMID}/rootfs" + hosts_file="${rootfs}/etc/hosts" + bridge_address=$(ip -4 -o addr show dev "$BRIDGE" 2>/dev/null \ + | awk '{split($4, parts, "/"); print parts[1]; exit}') + mount_ct_rootfs + if [[ ! -e $hosts_file ]]; then + install -D -m 0644 /dev/null "$hosts_file" || failed=1 + fi + temporary=$(mktemp) + awk ' + $0 == "# BEGIN PROXMENUX EXTRA HOSTS" {skip=1; next} + $0 == "# END PROXMENUX EXTRA HOSTS" {skip=0; next} + !skip {print} + ' "$hosts_file" >"$temporary" || failed=1 + if (( failed == 0 )); then + printf '\n# BEGIN PROXMENUX EXTRA HOSTS\n' >>"$temporary" + while IFS=$'\t' read -r hostname address; do + [[ -n $hostname ]] || continue + if [[ $address == host-gateway ]]; then + [[ -n $bridge_address ]] \ + || { oci_log "Could not resolve host-gateway on $BRIDGE"; failed=1; break; } + address=$bridge_address + fi + [[ $hostname =~ ^[A-Za-z0-9][A-Za-z0-9.-]*$ ]] \ + || { oci_log "Invalid extra hostname: $hostname"; failed=1; break; } + [[ $address =~ ^[0-9A-Fa-f:.]+$ ]] \ + || { oci_log "Invalid extra host address: $address"; failed=1; break; } + printf '%s %s\n' "$address" "$hostname" >>"$temporary" + done < <(jq -r '.extra_hosts[]? | [.hostname,.address] | @tsv' "$DEPLOYMENT_FILE") + printf '# END PROXMENUX EXTRA HOSTS\n' >>"$temporary" + fi + if (( failed == 0 )); then + cat "$temporary" >"$hosts_file" || failed=1 + chown "$HOST_ROOT_UID:$HOST_ROOT_GID" "$hosts_file" || failed=1 + fi + rm -f "$temporary" + oci_quiet pct unmount "$VMID" || failed=1 + (( failed == 0 )) || die "$(translate "Could not apply the Compose extra hosts")" +} + +apply_runtime_user() { + local user_spec=$1 rootfs passwd_file group_file user_part group_part uid gid failed=0 + rootfs="/var/lib/lxc/${VMID}/rootfs" + passwd_file="${rootfs}/etc/passwd" + group_file="${rootfs}/etc/group" + user_part=${user_spec%%:*} + group_part="" + [[ $user_spec == *:* ]] && group_part=${user_spec#*:} + mount_ct_rootfs + if [[ $user_part =~ ^[0-9]+$ ]]; then + uid=$user_part + gid=$(awk -F: -v id="$uid" '$3 == id {print $4; exit}' "$passwd_file" 2>/dev/null || true) + else + uid=$(awk -F: -v name="$user_part" '$1 == name {print $3; exit}' "$passwd_file" 2>/dev/null || true) + gid=$(awk -F: -v name="$user_part" '$1 == name {print $4; exit}' "$passwd_file" 2>/dev/null || true) + fi + if [[ -n $group_part ]]; then + if [[ $group_part =~ ^[0-9]+$ ]]; then + gid=$group_part + else + gid=$(awk -F: -v name="$group_part" '$1 == name {print $3; exit}' "$group_file" 2>/dev/null || true) + fi + fi + oci_quiet pct unmount "$VMID" || failed=1 + [[ $uid =~ ^[0-9]+$ && $gid =~ ^[0-9]+$ ]] || failed=1 + (( failed == 0 )) || die "$(translate "Could not resolve the Compose user:") $user_spec" + set_lxc_directive lxc.init.uid "$uid" + set_lxc_directive lxc.init.gid "$gid" +} + +apply_runtime_groups() { + local groups_csv=$1 rootfs="/var/lib/lxc/${VMID}/rootfs" + local group_file="${rootfs}/etc/group" existing resolved group failed=0 + local combined="" + existing=$(awk -F': ' '$1 == "lxc.init.groups" {print $2; exit}' "$CONF" 2>/dev/null || true) + [[ -n $existing ]] && combined=$existing + mount_ct_rootfs + IFS=',' read -ra GROUP_SPECS <<<"$groups_csv" + for group in "${GROUP_SPECS[@]}"; do + [[ -n $group ]] || continue + if [[ $group =~ ^[0-9]+$ ]]; then + resolved=$group + else + resolved=$(awk -F: -v name="$group" '$1 == name {print $3; exit}' "$group_file" 2>/dev/null || true) + fi + if [[ ! $resolved =~ ^[0-9]+$ ]]; then + oci_log "Could not resolve the Compose supplementary group: $group" + failed=1 + break + fi + if [[ ",${combined}," != *",${resolved},"* ]]; then + combined="${combined:+${combined},}${resolved}" + fi + done + oci_quiet pct unmount "$VMID" || failed=1 + (( failed == 0 )) || die "$(translate "Could not apply the Compose supplementary groups")" + [[ -n $combined ]] && set_lxc_directive lxc.init.groups "$combined" +} + +apply_installer_profile() { + local generated_count preparation_count tls_count mounted=0 failed=0 + local rootfs="/var/lib/lxc/${VMID}/rootfs" + local encoded item path mode owner destination target remove_lost_found owner_strategy + local only_when_mount_type selected_mount_type + local entrypoint working_directory halt_signal command_json compose_entrypoint_json user_spec + local supplemental_groups tls_config cert_path key_path cert_destination key_destination + local tls_directory valid_days common_name san + local generated_created=0 volumes_prepared=0 tls_state="" + + generated_count=$(jq '.proxmox.installer_profile.generated_files? // [] | length' "$TEMPLATE_FILE") + preparation_count=$(jq '.proxmox.installer_profile.volume_preparations? // [] | length' "$TEMPLATE_FILE") + tls_count=$(jq 'if .proxmox.installer_profile.self_signed_tls? then 1 else 0 end' "$TEMPLATE_FILE") + if (( generated_count > 0 || preparation_count > 0 || tls_count > 0 )); then + mount_ct_rootfs + mounted=1 + fi + + while IFS= read -r encoded; do + [[ -n $encoded ]] || continue + item=$(printf '%s' "$encoded" | base64 -d) + path=$(jq -er '.container_path' <<<"$item") + mode=$(jq -er '.mode' <<<"$item") + owner=$(jq -er '.owner' <<<"$item") + [[ $path == /* && $path != *[[:space:]]* && $path != *","* ]] \ + || { oci_log "Invalid generated file path: $path"; failed=1; break; } + [[ $mode =~ ^0?[0-7]{3}$ ]] \ + || { oci_log "Invalid generated file mode: $mode"; failed=1; break; } + destination="${rootfs}${path}" + [[ ! -L $destination ]] \ + || { oci_log "A generated file is not written over a link: $path"; failed=1; break; } + [[ ! -e $destination || -f $destination ]] \ + || { oci_log "The generated file target is not a regular file: $path"; failed=1; break; } + if [[ $(jq -r '.json_defaults // false' <<<"$item") == true ]]; then + local merged_file + merged_file=$(mktemp) + if ! merge_json_defaults \ + <(if [[ -e $destination ]]; then cat "$destination"; else printf '{}'; fi) \ + <(jq -er '.content' <<<"$item") >"$merged_file" 2>>"${OCI_LOG:-/dev/stderr}"; then + rm -f "$merged_file" + oci_log "Cannot merge the default JSON values: $path" + failed=1; break + fi + item=$(jq --rawfile content "$merged_file" '.content=$content | .only_if_missing=false' <<<"$item") + rm -f "$merged_file" + fi + if [[ $(jq -r '.only_if_missing // false' <<<"$item") == true && -e $destination ]]; then + oci_log "Keeping the existing persistent file: $path" + continue + fi + install -D -m "$mode" /dev/null "$destination" || { failed=1; break; } + jq -er '.content' <<<"$item" >"$destination" || { failed=1; break; } + case "$owner" in + mapped-root) chown "$HOST_ROOT_UID:$HOST_ROOT_GID" "$destination" || failed=1 ;; + mapped-application-user) chown "$HOST_BIND_UID:$HOST_BIND_GID" "$destination" || failed=1 ;; + *) oci_log "Unsupported generated file owner: $owner"; failed=1 ;; + esac + (( failed == 0 )) || break + oci_log "Generated file created: $path" + generated_created=$((generated_created + 1)) + done < <(jq -r '.proxmox.installer_profile.generated_files[]? | @base64' "$TEMPLATE_FILE") + + if (( failed == 0 )); then + while IFS= read -r encoded; do + [[ -n $encoded ]] || continue + item=$(printf '%s' "$encoded" | base64 -d) + target=$(jq -er '.container_path' <<<"$item") + remove_lost_found=$(jq -r '.remove_lost_found // false' <<<"$item") + owner_strategy=$(jq -er '.owner_strategy' <<<"$item") + only_when_mount_type=$(jq -r '.only_when_mount_type // empty' <<<"$item") + [[ $target == /* && $target != *[[:space:]]* && $target != *","* ]] \ + || { oci_log "Invalid volume preparation path: $target"; failed=1; break; } + if [[ -n $only_when_mount_type ]]; then + selected_mount_type=$(jq -r --arg target "$target" \ + '[.mounts[]? | select(.container_path == $target) | .type] | first // empty' \ + "$DEPLOYMENT_FILE") + if [[ $selected_mount_type != "$only_when_mount_type" ]]; then + oci_log "Skipping the preparation of $target for mount type ${selected_mount_type:-none}" + continue + fi + fi + [[ -d ${rootfs}${target} ]] \ + || { oci_log "The volume to prepare does not exist: $target"; failed=1; break; } + if [[ $remove_lost_found == true ]]; then + rm -rf "${rootfs}${target}/lost+found" || { failed=1; break; } + fi + case "$owner_strategy" in + mapped-root) chown "$HOST_ROOT_UID:$HOST_ROOT_GID" "${rootfs}${target}" || failed=1 ;; + mapped-application-user) + chown "$HOST_BIND_UID:$HOST_BIND_GID" "${rootfs}${target}" || failed=1 + ;; + *) oci_log "Unsupported owner strategy: $owner_strategy"; failed=1 ;; + esac + (( failed == 0 )) || break + oci_log "Volume prepared before the first start: $target" + volumes_prepared=$((volumes_prepared + 1)) + done < <(jq -r '.proxmox.installer_profile.volume_preparations[]? | @base64' "$TEMPLATE_FILE") + fi + + if (( failed == 0 && tls_count == 1 )); then + require_command openssl + tls_config=$(jq -c '.proxmox.installer_profile.self_signed_tls' "$TEMPLATE_FILE") + cert_path=$(jq -er '.certificate_path' <<<"$tls_config") + key_path=$(jq -er '.private_key_path' <<<"$tls_config") + valid_days=$(jq -er '.valid_days' <<<"$tls_config") + [[ $cert_path == /* && $key_path == /* ]] \ + || { oci_log "The TLS paths must be absolute"; failed=1; } + [[ $valid_days =~ ^[0-9]+$ && $valid_days -ge 1 ]] \ + || { oci_log "Invalid TLS validity"; failed=1; } + cert_destination="${rootfs}${cert_path}" + key_destination="${rootfs}${key_path}" + tls_directory=$(dirname "$cert_destination") + install -d -m 0700 "$tls_directory" || failed=1 + if (( failed == 0 )); then + chown "$HOST_ROOT_UID:$HOST_ROOT_GID" "$tls_directory" || failed=1 + fi + if (( failed == 0 )) && [[ ! -s $cert_destination || ! -s $key_destination ]]; then + common_name=$HOSTNAME + san="DNS:${HOSTNAME},DNS:${HOSTNAME}.local" + if [[ $IPV4 != dhcp ]]; then + san="${san},IP:${IPV4%%/*}" + fi + if (( failed == 0 )); then + openssl req -x509 -newkey rsa:3072 -sha256 -nodes \ + -days "$valid_days" -subj "/CN=${common_name}" \ + -addext "subjectAltName=${san}" \ + -keyout "$key_destination" -out "$cert_destination" >/dev/null 2>&1 \ + || failed=1 + fi + (( failed != 0 )) || tls_state=created + else + tls_state=reused + fi + if (( failed == 0 )); then + chmod 0600 "$key_destination" + chmod 0644 "$cert_destination" + chown "$HOST_ROOT_UID:$HOST_ROOT_GID" "$key_destination" "$cert_destination" + fi + fi + + if (( mounted == 1 )); then + oci_quiet pct unmount "$VMID" || failed=1 + fi + (( failed == 0 )) || die "$(translate "Could not apply the installer profile")" + if (( generated_created > 0 )); then + msg_ok "$(translate "Configuration files generated:") $generated_created" + fi + if (( volumes_prepared > 0 )); then + msg_ok "$(translate "Volumes prepared for the first start:") $volumes_prepared" + fi + case "$tls_state" in + created) msg_ok "$(translate "Self-signed TLS certificate created:") $cert_path" ;; + reused) msg_ok "$(translate "Existing TLS certificate reused:") $cert_path" ;; + esac + + entrypoint=$(jq -r '.proxmox.installer_profile.runtime.entrypoint // empty' "$TEMPLATE_FILE") + # An empty Compose command is no command at all: the image keeps its own. + command_json=$(jq -c '(.proxmox.installer_profile.runtime? // {}) as $runtime + | if ($runtime | has("command")) and ($runtime.command != null) + and ((($runtime.command | type) != "array") or (($runtime.command | length) > 0)) + then $runtime.command else null end' "$TEMPLATE_FILE") + compose_entrypoint_json=$(jq -c 'if (.proxmox.installer_profile.runtime? // {}) | has("compose_entrypoint") then .proxmox.installer_profile.runtime.compose_entrypoint else null end' "$TEMPLATE_FILE") + working_directory=$(jq -r '.proxmox.installer_profile.runtime.working_directory // empty' "$TEMPLATE_FILE") + user_spec=$(jq -r '.proxmox.installer_profile.runtime.user // empty' "$TEMPLATE_FILE") + supplemental_groups=$(jq -r '.proxmox.installer_profile.runtime.supplemental_groups? // [] | join(",")' "$TEMPLATE_FILE") + halt_signal=$(jq -r '.proxmox.installer_profile.runtime.halt_signal // empty' "$TEMPLATE_FILE") + if [[ -n $entrypoint ]]; then + [[ $entrypoint == /* && $entrypoint != *$'\n'* ]] || die "$(translate "Invalid declarative entrypoint")" + oci_quiet pct set "$VMID" --entrypoint "$entrypoint" \ + || die "$(translate "Could not set the container entrypoint")" + elif [[ $command_json != null || $compose_entrypoint_json != null ]]; then + entrypoint=$(python3 "$OCI_RUNTIME_RESOLVER" "$ARCHIVE_PATH" \ + "$command_json" "$compose_entrypoint_json" 2>>"${OCI_LOG:-/dev/stderr}") \ + || die "$(translate "Could not translate the Compose command/entrypoint")" + oci_quiet pct set "$VMID" --entrypoint "$entrypoint" \ + || die "$(translate "Could not set the container entrypoint")" + fi + if [[ -n $working_directory ]]; then + [[ $working_directory == /* && $working_directory != *[[:space:]]* ]] \ + || die "$(translate "Invalid declarative working directory")" + set_lxc_directive lxc.init.cwd "$working_directory" + fi + if [[ -n $user_spec ]]; then + apply_runtime_user "$user_spec" + fi + if [[ -n $supplemental_groups ]]; then + apply_runtime_groups "$supplemental_groups" + fi + if [[ -n $halt_signal ]]; then + [[ $halt_signal =~ ^SIG[A-Z0-9]+$ ]] || die "$(translate "Invalid declarative stop signal")" + set_lxc_directive lxc.signal.halt "$halt_signal" + fi +} + +[[ $EUID -eq 0 ]] || die "$(translate "The remote installer must run as root on Proxmox VE")" +for command in pct pvesh pvesm skopeo jq sha256sum python3 mktemp flock; do + require_command "$command" +done + +VERIFY_OCI_ARCHIVE="${SCRIPT_DIR}/verify_oci_archive.py" +OCI_RUNTIME_RESOLVER="${SCRIPT_DIR}/oci_runtime.py" +OCI_ROOTFS_UNSHIFTER="${SCRIPT_DIR}/unshift_oci_rootfs.py" +JELLYFIN_CONFIGURATOR="${SCRIPT_DIR}/configure_jellyfin_encoding.py" +[[ -r $VERIFY_OCI_ARCHIVE ]] || die "$(translate "Installer file not found:") $VERIFY_OCI_ARCHIVE" +[[ -r $OCI_RUNTIME_RESOLVER ]] || die "$(translate "Installer file not found:") $OCI_RUNTIME_RESOLVER" +[[ -r $OCI_ROOTFS_UNSHIFTER ]] || die "$(translate "Installer file not found:") $OCI_ROOTFS_UNSHIFTER" +[[ -r $JELLYFIN_CONFIGURATOR ]] || die "$(translate "Installer file not found:") $JELLYFIN_CONFIGURATOR" + +APP_ID=$(json_value '.id' "$TEMPLATE_FILE") +LOG_NAME=${APP_ID#image-} +oci_log_init "${LOG_NAME#linuxserver-}" +oci_log "OCI install: $APP_ID (dry run: $DRY_RUN)" +STATUS=$(json_value '.status' "$TEMPLATE_FILE") +IMAGE_REF=$(json_value '.container_contract.image.reference' "$TEMPLATE_FILE") +REVISION=$(json_value '.source.revision' "$TEMPLATE_FILE") +PROVIDER=$(jq -r '.source.provider // "unknown"' "$TEMPLATE_FILE") +CATEGORY=$(jq -r '.catalog_ui.category // "misc"' "$TEMPLATE_FILE") +CATEGORY=$(tr '[:upper:]' '[:lower:]' <<<"$CATEGORY" | tr -cs 'a-z0-9_.-' '-') +CATEGORY=${CATEGORY#-} +CATEGORY=${CATEGORY%-} +[[ -n $CATEGORY && $CATEGORY != linuxserver ]] || CATEGORY="misc" +STARTUP_HEALTHCHECK=$(jq -c '.proxmox.installer_profile.startup_healthcheck? // null' "$TEMPLATE_FILE") +HAOS_HEALTHCHECK=$(jq -r '.proxmox.installer_profile.haos_healthcheck.timeout_seconds? // 0' "$TEMPLATE_FILE") +if [[ $HAOS_HEALTHCHECK != 0 ]]; then + [[ $HAOS_HEALTHCHECK =~ ^[0-9]+$ && $HAOS_HEALTHCHECK -ge 60 && $HAOS_HEALTHCHECK -le 3600 ]] || die "$(translate "Invalid Home Assistant OS check timeout")" + [[ -r ${SCRIPT_DIR}/haos_healthcheck.py ]] || die "$(translate "Installer file not found:") ${SCRIPT_DIR}/haos_healthcheck.py" +fi +HAS_STARTUP_HEALTHCHECK=$(jq -r 'if . == null then 0 else 1 end' <<<"$STARTUP_HEALTHCHECK") +HAS_RUNNING_CHECK=0 +if [[ $HAS_STARTUP_HEALTHCHECK == 1 && $(jq -r '.type // "http"' <<<"$STARTUP_HEALTHCHECK") == running ]]; then + HAS_STARTUP_HEALTHCHECK=0 + HAS_RUNNING_CHECK=1 +fi +if [[ $HAS_STARTUP_HEALTHCHECK == 1 ]]; then + require_command curl +fi +HOST_MODULE_COUNT=$(jq '.security.host_modules? // [] | length' "$DEPLOYMENT_FILE") +if (( HOST_MODULE_COUNT > 0 )); then + require_command modprobe + while IFS= read -r HOST_MODULE; do + [[ $HOST_MODULE =~ ^[A-Za-z0-9_-]+$ ]] \ + || die "$(translate "Invalid host kernel module name:") $HOST_MODULE" + msg_info "$(translate "Loading the host kernel module:") $HOST_MODULE..." + oci_quiet modprobe "$HOST_MODULE" || die "$(translate "Could not load the host kernel module:") $HOST_MODULE" + MODULE_SYSFS=${HOST_MODULE//-/_} + [[ -d /sys/module/$MODULE_SYSFS ]] \ + || die "$(translate "The kernel module is not active:") $HOST_MODULE" + msg_ok "$(translate "Host kernel module loaded:") $HOST_MODULE" + done < <(jq -r '.security.host_modules[]?' "$DEPLOYMENT_FILE") +fi +VMID=$(jq -r '.vmid // empty' "$DEPLOYMENT_FILE") +if [[ -z $VMID ]]; then + VMID=$(pvesh get /cluster/nextid) +fi +[[ $VMID =~ ^[0-9]+$ ]] || die "$(translate "Invalid VMID:") $VMID" +pct config "$VMID" >/dev/null 2>&1 && die "$(translate "The CT already exists:") $VMID" + +HOSTNAME=$(json_value '.hostname' "$DEPLOYMENT_FILE") +ROOTFS_STORAGE=$(json_value '.rootfs.storage' "$DEPLOYMENT_FILE") +ROOTFS_SIZE=$(json_value '.rootfs.size_gb' "$DEPLOYMENT_FILE") +TEMPLATE_STORAGE=$(json_value '.template_storage' "$DEPLOYMENT_FILE") +CORES=$(json_value '.resources.cores' "$DEPLOYMENT_FILE") +CPU_UNITS=$(jq -r '.resources.cpu_units // empty' "$DEPLOYMENT_FILE") +MEMORY=$(json_value '.resources.memory_mb' "$DEPLOYMENT_FILE") +validate_rlimits +SWAP=$(json_value '.resources.swap_mb' "$DEPLOYMENT_FILE") +BRIDGE=$(json_value '.network.bridge' "$DEPLOYMENT_FILE") +IPV4=$(json_value '.network.ipv4' "$DEPLOYMENT_FILE") +MAC_ADDRESS=$(jq -r '.network.mac_address // empty' "$DEPLOYMENT_FILE") +GATEWAY=$(jq -r '.network.gateway // empty' "$DEPLOYMENT_FILE") +FIREWALL=$(json_value '.network.firewall | if . then 1 else 0 end' "$DEPLOYMENT_FILE") +validate_host_monitor +ONBOOT=$(json_value '.onboot | if . then 1 else 0 end' "$DEPLOYMENT_FILE") +START_AFTER=$(json_value '.start_after_create | if . then 1 else 0 end' "$DEPLOYMENT_FILE") +SHUTDOWN_TIMEOUT=$(json_value '.shutdown_timeout_seconds' "$DEPLOYMENT_FILE") +[[ $SHUTDOWN_TIMEOUT =~ ^[0-9]+$ && $SHUTDOWN_TIMEOUT -gt 0 ]] \ + || die "$(translate "Invalid shutdown timeout")" +ARCH=$(dpkg --print-architecture) +case "$ARCH" in + amd64|arm64) ;; + *) die "$(translate "Unsupported architecture:") $ARCH" ;; +esac +jq -e --arg architecture "$ARCH" '.catalog_ui.architectures | index($architecture) != null' \ + "$TEMPLATE_FILE" >/dev/null || die "$(translate "The image does not declare support for this architecture:") $ARCH" +SELECTED_HARDWARE_PROFILE=$(jq -r '.hardware_profile // empty' "$DEPLOYMENT_FILE") +if [[ -n $SELECTED_HARDWARE_PROFILE ]]; then + jq -e --arg profile "$SELECTED_HARDWARE_PROFILE" --arg architecture "$ARCH" ' + [.proxmox.installer_profile.hardware_acceleration.profiles[]? + | select(.id == $profile)] + | if length == 1 then + ((.[0].architectures // ["amd64", "arm64"]) | index($architecture) != null) + else false end + ' "$TEMPLATE_FILE" >/dev/null \ + || die "$(translate "The acceleration profile does not support this architecture:") $SELECTED_HARDWARE_PROFILE ($ARCH)" +fi + +show_gpu_inventory +validate_gpu_vendors +oci_log "Application: $APP_ID; image: $IMAGE_REF; CT $VMID ($HOSTNAME); architecture: $ARCH" + +if [[ $DRY_RUN == 1 ]]; then + msg_info2 "$(translate "Application:") $APP_ID" + msg_info2 "$(translate "Image:") $IMAGE_REF" + msg_info2 "CT $VMID ($HOSTNAME)" + msg_info2 "$(translate "Architecture:") $ARCH" + msg_ok "$(translate "Remote dry run completed; no container was created.")" + exit 0 +fi + +# Hold the registry lock through installation so reconciliation cannot race it. +INSTANCE_ROOT=${PROXMENUX_OCI_INSTANCE_ROOT:-/usr/local/share/proxmenux/oci/apps} +if [[ -n ${PROXMENUX_OCI_TRANSACTION:-} ]]; then + INSTANCE_ID=$(python3 "${SCRIPT_DIR}/oci_instance_transaction.py" --root "$INSTANCE_ROOT" \ + authorize-candidate "$VMID" --journal "$PROXMENUX_OCI_TRANSACTION" \ + --template "$TEMPLATE_FILE" --deployment "$DEPLOYMENT_FILE") +else +[[ ! -L $INSTANCE_ROOT && ! -L $INSTANCE_ROOT/.lock ]] || die "$(translate "The instance registry is not safe")" +install -d -m 0700 "$INSTANCE_ROOT" +exec 9>>"$INSTANCE_ROOT/.lock" +chmod 600 "$INSTANCE_ROOT/.lock" +flock -n 9 || die "$(translate "Another OCI operation is using the instance registry")" +export PROXMENUX_INSTANCE_LOCK_FD=9 +# pct start spawns long-lived monitors; they must not retain our registry lock. +pct() { command pct "$@" 9>&-; } +INSTANCE_ID=$(python3 "${SCRIPT_DIR}/oci_instances.py" prepare "$VMID" \ + --template "$TEMPLATE_FILE" --deployment "$DEPLOYMENT_FILE") +INSTANCE_CONTRACT="$INSTANCE_ROOT/$VMID/oci-compose.json" +# The persisted contract is the source for the actual installation inputs. +jq '.template' "$INSTANCE_CONTRACT" >"$TEMPLATE_FILE" +jq '.deployment' "$INSTANCE_CONTRACT" >"$DEPLOYMENT_FILE" +fi + +skopeo_transport_reference() { + local reference=$1 name digest + if [[ $reference == *@sha256:* ]]; then + name=${reference%@sha256:*} + digest="sha256:${reference##*@sha256:}" + [[ ${name##*/} == *:* ]] && name=${name%:*} + printf '%s@%s' "$name" "$digest" + else + printf '%s' "$reference" + fi +} + +resolve_image_manifest() { + local image=$1 manifest_file error_file pid elapsed=0 status=0 + manifest_file=$(mktemp /tmp/proxmenux-oci-inspect.XXXXXX) + error_file="${manifest_file}.err" + oci_log "Querying the registry for ${image} (${ARCH})" + skopeo inspect --no-tags --override-os linux --override-arch "$ARCH" \ + "docker://${image}" >"$manifest_file" 2>"$error_file" & + pid=$! + while kill -0 "$pid" 2>/dev/null; do + sleep 2 + elapsed=$((elapsed + 2)) + done + wait "$pid" || status=$? + if (( status != 0 )); then + [[ -z ${OCI_LOG:-} ]] || cat "$error_file" >>"$OCI_LOG" + rm -f "$manifest_file" "$error_file" + return "$status" + fi + oci_log "Manifest resolved in ${elapsed}s" + cat "$manifest_file" + rm -f "$manifest_file" "$error_file" +} + +if [[ -n ${PROXMENUX_OCI_TRANSACTION:-} ]]; then + ARCHIVE_PATH=$(jq -er '.archive' "$PROXMENUX_OCI_TRANSACTION") + ARCHIVE_VOLUME=$ARCHIVE_PATH + DIGEST=$(jq -er '.registry_digest' "$PROXMENUX_OCI_TRANSACTION") + CREATED="" + IMAGE_VERSION="" + msg_ok "$(translate "Using the image verified by the transaction")" +else +SKOPEO_IMAGE_REF=$(skopeo_transport_reference "$IMAGE_REF") +if [[ $SKOPEO_IMAGE_REF != "$IMAGE_REF" ]]; then + oci_log "Digest-pinned reference; Skopeo-compatible form: $SKOPEO_IMAGE_REF" +fi +msg_info "$(translate "Checking the image in the registry...")" +INSPECT=$(resolve_image_manifest "$SKOPEO_IMAGE_REF") \ + || die "$(translate "Could not resolve the OCI manifest of the image:") $IMAGE_REF" +DIGEST=$(jq -er '.Digest' <<<"$INSPECT") +oci_log "Selected digest: $DIGEST" +CREATED=$(jq -r '.Created // empty' <<<"$INSPECT") +IMAGE_VERSION=$(jq -r '.Labels["org.opencontainers.image.version"] // .Labels.build_version // empty' <<<"$INSPECT") +TOTAL_LAYER_BYTES=$(jq -r '[.LayersData[]?.Size] | add // 0' <<<"$INSPECT") +TOTAL_LAYER_COUNT=$(jq -r '[.LayersData[]?] | length' <<<"$INSPECT") +DIGEST_SHORT=${DIGEST#sha256:} +DIGEST_SHORT=${DIGEST_SHORT:0:16} +msg_ok "$(translate "Image:") $IMAGE_REF (${IMAGE_VERSION:-sha256:${DIGEST_SHORT:0:12}})" +SAFE_APP=$(tr -cs 'a-zA-Z0-9._-' '_' <<<"$APP_ID" | sed 's/_$//') +ARCHIVE_NAME="${SAFE_APP}_${ARCH}_${DIGEST_SHORT}.tar" +ARCHIVE_VOLUME="${TEMPLATE_STORAGE}:vztmpl/${ARCHIVE_NAME}" +ARCHIVE_PATH=$(pvesm path "$ARCHIVE_VOLUME") +mkdir -p "$(dirname "$ARCHIVE_PATH")" + +download_and_verify_archive() { + local attempt=$1 + local partial_path="${ARCHIVE_PATH}.partial.$$" + local download_log="${partial_path}.log" + local copy_pid elapsed current_bytes process_bytes display_bytes current_mib total_mib + local percentage copy_status started_layers last_bytes=-1 stalled_seconds=0 + local stall_timeout_seconds=180 + + rm -f "$partial_path" "$download_log" + oci_log "Downloading $IMAGE_REF by digest $DIGEST (attempt $attempt/2)" + skopeo copy --override-os linux --override-arch "$ARCH" \ + --retry-times 3 --retry-delay 5s --image-parallel-copies 1 \ + "docker://$SKOPEO_IMAGE_REF" "oci-archive:${partial_path}:${APP_ID}" \ + >"$download_log" 2>&1 & + copy_pid=$! + elapsed=0 + total_mib=$(( (TOTAL_LAYER_BYTES + 1048575) / 1048576 )) + while kill -0 "$copy_pid" 2>/dev/null; do + current_bytes=$(stat -c %s "$partial_path" 2>/dev/null || printf '0') + process_bytes=$(awk '$1 == "rchar:" { print $2 }' "/proc/${copy_pid}/io" 2>/dev/null || printf '0') + if (( process_bytes > current_bytes )); then + current_bytes=$process_bytes + fi + if (( current_bytes > last_bytes )); then + last_bytes=$current_bytes + stalled_seconds=0 + else + stalled_seconds=$((stalled_seconds + 2)) + fi + started_layers=$(awk '/^Copying blob / { count++ } END { print count + 0 }' "$download_log" 2>/dev/null || printf '0') + if (( TOTAL_LAYER_BYTES > 0 )); then + display_bytes=$current_bytes + if (( display_bytes >= TOTAL_LAYER_BYTES )); then + display_bytes=$((TOTAL_LAYER_BYTES * 99 / 100)) + fi + current_mib=$(( display_bytes / 1048576 )) + percentage=$(( display_bytes * 100 / TOTAL_LAYER_BYTES )) + if (( started_layers > TOTAL_LAYER_COUNT )); then + started_layers=$TOTAL_LAYER_COUNT + fi + if (( percentage > 99 )); then + percentage=99 + fi + msg_progress "$(translate "Downloading the image:") ${current_mib} / ${total_mib} MiB (${percentage}%), $(translate "layers") ${started_layers}/${TOTAL_LAYER_COUNT}, ${elapsed}s" + else + current_mib=$(( current_bytes / 1048576 )) + msg_progress "$(translate "Downloading the image:") ${current_mib} MiB, ${elapsed}s" + fi + if (( stalled_seconds >= stall_timeout_seconds )); then + oci_log "The download made no progress for ${stall_timeout_seconds}s; cancelling this attempt" + msg_warn "$(translate "The download stopped progressing; cancelling this attempt.")" + kill "$copy_pid" 2>/dev/null || true + sleep 2 + kill -9 "$copy_pid" 2>/dev/null || true + break + fi + sleep 2 + elapsed=$((elapsed + 2)) + done + + copy_status=0 + wait "$copy_pid" || copy_status=$? + if (( copy_status != 0 )); then + [[ -z ${OCI_LOG:-} ]] || cat "$download_log" >>"$OCI_LOG" + rm -f "$partial_path" "$download_log" + oci_log "The image download failed (exit code $copy_status)" + return 1 + fi + [[ -z ${OCI_LOG:-} ]] || cat "$download_log" >>"$OCI_LOG" + rm -f "$download_log" + msg_ok "$(translate "Image downloaded") ($(( ($(stat -c %s "$partial_path") + 1048575) / 1048576 )) MiB)" + msg_info "$(translate "Verifying the image integrity...")" + if ! oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$partial_path"; then + rm -f "$partial_path" + return 1 + fi + mv -f "$partial_path" "$ARCHIVE_PATH" + msg_ok "$(translate "Image integrity verified")" + return 0 +} + +if [[ -s $ARCHIVE_PATH ]]; then + oci_log "Verifying the cached image: $ARCHIVE_VOLUME" + msg_info "$(translate "Verifying the image integrity...")" + if oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$ARCHIVE_PATH"; then + msg_ok "$(translate "Using the verified image from the cache")" + else + msg_warn "$(translate "The cached image is damaged; it will be downloaded again.")" + rm -f "$ARCHIVE_PATH" + fi +fi + +if [[ ! -s $ARCHIVE_PATH ]]; then + for attempt in 1 2; do + download_and_verify_archive "$attempt" && break + if (( attempt == 2 )); then + die "$(translate "Could not obtain an intact image after two attempts")" + fi + msg_warn "$(translate "The image download did not complete correctly; downloading it again...")" + done +fi +fi + +DESCRIPTION="ProxMenux OCI: ${APP_ID}; image=${IMAGE_REF}; digest=${DIGEST}; source=${REVISION}; status=${STATUS}" +DESCRIPTION="${DESCRIPTION}; proxmenux-instance=${INSTANCE_ID}" +UNPRIVILEGED=$(jq -r 'if .security | has("unprivileged") then .security.unprivileged else true end' "$DEPLOYMENT_FILE") +case "$UNPRIVILEGED" in + true) UNPRIVILEGED_FLAG=1 ;; + false) UNPRIVILEGED_FLAG=0 ;; + *) die "$(translate "Invalid security.unprivileged value:") $UNPRIVILEGED" ;; +esac +if [[ $UNPRIVILEGED_FLAG == 0 ]] && \ + [[ $(jq -r '.security.privileged_acknowledged // false' "$DEPLOYMENT_FILE") != true ]]; then + die "$(translate "The privileged deployment does not include the required explicit consent")" +fi +PVE_TAGS="${CATEGORY};oci" +if [[ $PROVIDER == linuxserver.io ]]; then + PVE_TAGS="linuxserver;${PVE_TAGS}" +fi +PVE_TAGS="${PVE_TAGS};proxmenux" +NET="name=eth0,bridge=${BRIDGE},firewall=${FIREWALL},host-managed=1,ip=${IPV4},type=veth" +if [[ -n $GATEWAY ]]; then + NET="${NET},gw=${GATEWAY}" +fi +if [[ -n $MAC_ADDRESS ]]; then + [[ $MAC_ADDRESS =~ ^[0-9A-Fa-f]{2}(:[0-9A-Fa-f]{2}){5}$ ]] \ + || die "$(translate "Invalid MAC address:") $MAC_ADDRESS" + NET="${NET},hwaddr=${MAC_ADDRESS}" +fi + +CREATE_UNPRIVILEGED_FLAG=$UNPRIVILEGED_FLAG +if [[ $UNPRIVILEGED_FLAG == 0 ]]; then + # Proxmox 9.2 cannot extract OCI archives directly as privileged LXCs. + # Import with the standard idmap, unshift once while stopped, then switch the config. + CREATE_UNPRIVILEGED_FLAG=1 +fi +CREATE_ARGS=( + "$VMID" "$ARCHIVE_VOLUME" + --hostname "$HOSTNAME" + --rootfs "${ROOTFS_STORAGE}:${ROOTFS_SIZE}" + --memory "$MEMORY" + --swap "$SWAP" + --unprivileged "$CREATE_UNPRIVILEGED_FLAG" + --onboot "$ONBOOT" + --description "$DESCRIPTION" + --tags "$PVE_TAGS" +) +configure_cpu_allocation +CREATE_ARGS+=("${CPU_CREATE_ARGS[@]}") +if [[ -z $HOST_MONITOR ]]; then + CREATE_ARGS+=(--net0 "$NET") +fi + +OSTYPE=$(jq -r '.ostype // "auto-from-image"' "$DEPLOYMENT_FILE") +case "$OSTYPE" in + auto-from-image) ;; + unmanaged) CREATE_ARGS+=(--ostype unmanaged) ;; + *) die "$(translate "Unsupported declarative ostype:") $OSTYPE" ;; +esac + +if [[ -n $CPU_UNITS ]]; then + [[ $CPU_UNITS =~ ^[0-9]+$ && $CPU_UNITS -ge 8 && $CPU_UNITS -le 10000 ]] \ + || die "$(translate "cpuunits must be between 8 and 10000")" + CREATE_ARGS+=(--cpuunits "$CPU_UNITS") +fi + +FEATURES=$(jq -r '.features | join(",")' "$DEPLOYMENT_FILE") +if [[ -n $FEATURES ]]; then + CREATE_ARGS+=(--features "$FEATURES") +fi + +# pct keeps the OCI Entrypoint/Cmd/Env/User/WorkingDir/StopSignal metadata. +msg_info "$(translate "Creating the container...")" +oci_quiet pct create "${CREATE_ARGS[@]}" \ + || die "$(translate "Could not create the container:") CT $VMID" +CT_CREATED=1 +msg_ok "$(translate "Container created:") CT $VMID ($HOSTNAME)" + +CONF="/etc/pve/lxc/${VMID}.conf" +if [[ $UNPRIVILEGED_FLAG == 0 ]]; then + msg_info "$(translate "Converting the container to privileged...")" + mount_ct_rootfs + oci_quiet python3 "$OCI_ROOTFS_UNSHIFTER" "/var/lib/lxc/${VMID}/rootfs" || { + pct unmount "$VMID" >/dev/null 2>&1 || true + die "$(translate "Could not convert the OCI rootfs to privileged")" + } + oci_quiet pct unmount "$VMID" \ + || die "$(translate "Could not unmount the container filesystem:") CT $VMID" + sed -i -E 's/^unprivileged: 1$/unprivileged: 0/' "$CONF" + grep -q '^unprivileged: 0$' "$CONF" \ + || die "$(translate "Could not enable the privileged profile before the first start")" + msg_ok "$(translate "Container converted to privileged")" +fi +MOUNT_INDEX=0 +CONTAINER_PUID=$(jq -r '[.environment[]? | select(.name == "PUID" or .name == "USER_ID" or .name == "UID") | .value] | last // "0"' "$DEPLOYMENT_FILE") +CONTAINER_PGID=$(jq -r '[.environment[]? | select(.name == "PGID" or .name == "GROUP_ID" or .name == "GID") | .value] | last // "0"' "$DEPLOYMENT_FILE") +IMAGE_VOLUME_UID=$(jq -r '.proxmox.installer_profile.volume_owner.uid // empty' "$TEMPLATE_FILE") +IMAGE_VOLUME_GID=$(jq -r '.proxmox.installer_profile.volume_owner.gid // empty' "$TEMPLATE_FILE") +[[ -z $IMAGE_VOLUME_UID ]] || CONTAINER_PUID=$IMAGE_VOLUME_UID +[[ -z $IMAGE_VOLUME_GID ]] || CONTAINER_PGID=$IMAGE_VOLUME_GID +[[ $CONTAINER_PUID =~ ^[0-9]+$ ]] || CONTAINER_PUID=0 +[[ $CONTAINER_PGID =~ ^[0-9]+$ ]] || CONTAINER_PGID=0 +if [[ $UNPRIVILEGED_FLAG == 1 ]]; then + HOST_ROOT_UID=100000 + HOST_ROOT_GID=100000 + HOST_BIND_UID=$((100000 + CONTAINER_PUID)) + HOST_BIND_GID=$((100000 + CONTAINER_PGID)) +else + HOST_ROOT_UID=0 + HOST_ROOT_GID=0 + HOST_BIND_UID=$CONTAINER_PUID + HOST_BIND_GID=$CONTAINER_PGID +fi + +SYSCTL_COUNT=$(jq '.security.sysctls? // [] | length' "$DEPLOYMENT_FILE") +if (( SYSCTL_COUNT > 0 )); then + SYSCTL_INCLUDE="/etc/pve/lxc/${VMID}.proxmenux-sysctls" + SYSCTL_TEMP=$(mktemp) + while IFS=$'\t' read -r SYSCTL_NAME SYSCTL_VALUE; do + [[ -n $SYSCTL_NAME ]] || continue + [[ $SYSCTL_NAME =~ ^net\.(ipv4|ipv6)\.[A-Za-z0-9_.-]+$ ]] \ + || die "$(translate "Sysctl not namespaced or not valid:") $SYSCTL_NAME" + [[ -n $SYSCTL_VALUE && $SYSCTL_VALUE != *$'\n'* && $SYSCTL_VALUE != *$'\r'* ]] \ + || die "$(translate "Invalid sysctl value:") $SYSCTL_NAME" + printf 'lxc.sysctl.%s = %s\n' "$SYSCTL_NAME" "$SYSCTL_VALUE" >>"$SYSCTL_TEMP" + oci_log "Network sysctl prepared: ${SYSCTL_NAME}=${SYSCTL_VALUE}" + done < <(jq -r '.security.sysctls[]? | [.name,.value] | @tsv' "$DEPLOYMENT_FILE") + [[ ! -L $SYSCTL_INCLUDE ]] || die "$(translate "The sysctl include is a link:") $SYSCTL_INCLUDE" + # pmxcfs assigns its own permissions and rejects chmod. + cat "$SYSCTL_TEMP" >"$SYSCTL_INCLUDE" + rm -f "$SYSCTL_TEMP" + set_lxc_directive "lxc.include" "$SYSCTL_INCLUDE" + msg_ok "$(translate "Network sysctls prepared:") $SYSCTL_COUNT" +fi + +REQUIRED_CAPABILITIES=$(jq -r '.security.required_capabilities? // [] | join(",")' "$DEPLOYMENT_FILE") +if [[ -n $REQUIRED_CAPABILITIES ]]; then + msg_ok "$(translate "Compose capabilities validated in the LXC user namespace:") $REQUIRED_CAPABILITIES" +fi + +NO_NEW_PRIVILEGES=$(jq -r '.security.options.no_new_privileges? // false' "$DEPLOYMENT_FILE") +APPARMOR_PROFILE=$(jq -r '.security.options.apparmor_profile? // empty' "$DEPLOYMENT_FILE") +SECCOMP_PROFILE=$(jq -r '.security.options.seccomp_profile? // empty' "$DEPLOYMENT_FILE") +SELINUX_LABEL_DISABLED=$(jq -r '.security.options.selinux_label_disabled? // false' "$DEPLOYMENT_FILE") +if [[ $NO_NEW_PRIVILEGES == true ]]; then + set_lxc_directive "lxc.no_new_privs" "1" +fi +if [[ $(jq -r '.security.options.drop_all_capabilities? // false' "$DEPLOYMENT_FILE") == true ]]; then + [[ -z $REQUIRED_CAPABILITIES ]] || die "$(translate "Capabilities cannot be kept and all dropped at the same time")" + set_lxc_directive "lxc.cap.drop" "" + set_lxc_directive "lxc.cap.keep" "none" +fi +if [[ -n $APPARMOR_PROFILE || -n $SECCOMP_PROFILE ]]; then + [[ $(jq -r '.security.relaxation_acknowledged // false' "$DEPLOYMENT_FILE") == true ]] \ + || die "$(translate "The AppArmor/seccomp relaxation does not include the required consent")" +fi +if [[ -n $APPARMOR_PROFILE ]]; then + [[ $APPARMOR_PROFILE == unconfined ]] \ + || die "$(translate "Unsupported OCI-LXC AppArmor profile:") $APPARMOR_PROFILE" + set_lxc_directive "lxc.apparmor.profile" "unconfined" +fi +if [[ -n $SECCOMP_PROFILE ]]; then + [[ $SECCOMP_PROFILE == unconfined ]] \ + || die "$(translate "Unsupported OCI-LXC seccomp profile:") $SECCOMP_PROFILE" + SECCOMP_PROFILE_FILE="/etc/pve/lxc/${VMID}.proxmenux-seccomp" + printf '2\ndenylist\n[all]\n' >"$SECCOMP_PROFILE_FILE" + chmod 0640 "$SECCOMP_PROFILE_FILE" + set_lxc_directive "lxc.seccomp.profile" "$SECCOMP_PROFILE_FILE" +fi +if [[ $SELINUX_LABEL_DISABLED == true ]]; then + oci_log "label:disable kept as metadata; Proxmox uses AppArmor, not SELinux, for this LXC" +fi +MOUNT_ENTRIES=$(jq '.mounts | if type == "array" then length else 0 end' "$DEPLOYMENT_FILE") +MOUNT_NOTES=() +if (( MOUNT_ENTRIES > 0 )); then + msg_info "$(translate "Adding the mount points...")" +fi +while IFS=$'\t' read -r TYPE TARGET SOURCE SIZE BACKUP READ_ONLY CREATE_IF_MISSING; do + [[ -n $TYPE ]] || continue + [[ $TARGET == /* && $TARGET != *","* ]] || die "$(translate "Invalid container path:") $TARGET" + RO_OPT="" + [[ $READ_ONLY == true ]] && RO_OPT=",ro=1" + if [[ $TYPE == managed-volume ]]; then + [[ $SIZE =~ ^[0-9]+$ ]] || die "$(translate "Invalid volume size:") $TARGET" + if [[ -n ${PROXMENUX_OCI_TRANSACTION:-} ]]; then + REUSE_KEY=$(jq -r --arg path "$TARGET" \ + '.transaction_reuse_mounts[]? | select(.container_path == $path) | .key' "$DEPLOYMENT_FILE") + if [[ -n $REUSE_KEY ]]; then + REUSE_VMID=$(jq -er '.transaction_source_vmid' "$DEPLOYMENT_FILE") + oci_quiet pct move-volume "$REUSE_VMID" "$REUSE_KEY" --target-vmid "$VMID" \ + --target-volume "mp${MOUNT_INDEX}" \ + || die "$(translate "Could not reuse the persistent disk:") $TARGET" + MP_VALUE=$(pct config "$VMID" | awk -v key="mp${MOUNT_INDEX}: " \ + 'index($0,key)==1 { print substr($0,length(key)+1) }') + REUSED_VOLUME=${MP_VALUE%%,*} + [[ -n $REUSED_VOLUME ]] || die "$(translate "Cannot verify the reused disk:") $TARGET" + oci_quiet pct set "$VMID" "--mp${MOUNT_INDEX}" \ + "${REUSED_VOLUME},mp=${TARGET},backup=${BACKUP}${RO_OPT}" \ + || die "$(translate "Could not add the mount point:") $TARGET" + oci_log "Persistent disk reused: $TARGET" + MOUNT_NOTES+=("$(translate "Persistent disk reused:") $TARGET") + MOUNT_INDEX=$((MOUNT_INDEX + 1)) + continue + fi + fi + MP_VALUE="${SOURCE}:${SIZE},mp=${TARGET},backup=${BACKUP}${RO_OPT}" + elif [[ $TYPE == host-bind ]]; then + [[ $SOURCE == /* && $SOURCE != *","* ]] || die "$(translate "Invalid host path:") $SOURCE" + if [[ ! -e $SOURCE && $CREATE_IF_MISSING == true ]]; then + install -d -m 0775 -o "$HOST_BIND_UID" -g "$HOST_BIND_GID" "$SOURCE" + oci_log "Shared directory created: $SOURCE (uid=$HOST_BIND_UID gid=$HOST_BIND_GID)" + MOUNT_NOTES+=("$(translate "Shared directory created:") $SOURCE") + fi + [[ -e $SOURCE ]] || die "$(translate "The host bind source does not exist:") $SOURCE" + if [[ -d $SOURCE ]]; then + if [[ -n ${PROXMENUX_OCI_TRANSACTION:-} ]]; then + python3 "${SCRIPT_DIR}/oci_instance_transaction.py" --root "$INSTANCE_ROOT" \ + pin-host-source "$VMID" --journal "$PROXMENUX_OCI_TRANSACTION" --source "$SOURCE" + fi + MP_VALUE="${SOURCE},mp=${TARGET},backup=0${RO_OPT}" + elif [[ -f $SOURCE ]]; then + [[ $SOURCE != *[[:space:]]* && $TARGET != *[[:space:]]* ]] \ + || die "$(translate "File bind mounts do not support spaces:") $SOURCE -> $TARGET" + prepare_file_mount_target "$TARGET" + TARGET=$PREPARED_FILE_TARGET + TARGET_RELATIVE=${TARGET#/} + FILE_OPTIONS="bind,create=file" + [[ $READ_ONLY == true ]] && FILE_OPTIONS="${FILE_OPTIONS},ro" + printf 'lxc.mount.entry: %s %s none %s 0 0\n' \ + "$SOURCE" "$TARGET_RELATIVE" "$FILE_OPTIONS" >>"$CONF" + continue + else + die "$(translate "The host bind source is not a regular file or directory:") $SOURCE" + fi + else + die "$(translate "Unsupported mount type:") $TYPE" + fi + oci_quiet pct set "$VMID" "--mp${MOUNT_INDEX}" "$MP_VALUE" \ + || die "$(translate "Could not add the mount point:") $TARGET" + MOUNT_INDEX=$((MOUNT_INDEX + 1)) +done < <(jq -r '.mounts[] | [.type,.container_path,.source,(.size_gb // "-"),(.backup | if . then 1 else 0 end),.read_only,(.create_if_missing // false)] | @tsv' "$DEPLOYMENT_FILE") +if (( MOUNT_ENTRIES > 0 )); then + msg_ok "$(translate "Mount points added:") $MOUNT_ENTRIES" +fi +for MOUNT_NOTE in ${MOUNT_NOTES[@]+"${MOUNT_NOTES[@]}"}; do + msg_ok "$MOUNT_NOTE" +done + +while IFS=$'\t' read -r TARGET SIZE_MB OPTIONS; do + [[ -n $TARGET ]] || continue + [[ $TARGET == /* && $TARGET != *","* && $TARGET != *[[:space:]]* ]] \ + || die "$(translate "Invalid tmpfs path:") $TARGET" + [[ $SIZE_MB =~ ^[0-9]+$ && $SIZE_MB -gt 0 ]] || die "$(translate "Invalid tmpfs size:") $TARGET" + [[ $OPTIONS =~ ^(rw|ro|nosuid|nodev|noexec|mode=0[0-7]{3})(,(rw|ro|nosuid|nodev|noexec|mode=0[0-7]{3}))*$ ]] || die "$(translate "Invalid tmpfs options:") $TARGET" + TARGET_RELATIVE=${TARGET#/} + printf 'lxc.mount.entry: tmpfs %s tmpfs %s,size=%sM,create=dir 0 0\n' \ + "$TARGET_RELATIVE" "$OPTIONS" "$SIZE_MB" >>"$CONF" +done < <(jq -r '.tmpfs_mounts[]? | [.container_path,.size_mb,(.mount_options | join(","))] | @tsv' "$DEPLOYMENT_FILE") + +DEVICE_INDEX=0 +RESOLVED_CHARACTER_DEVICES=() +NVIDIA_RUNTIME_CONFIGURED=0 +NVIDIA_GID_ENV="" +NVIDIA_DEVICE_COUNT=0 +while IFS= read -r DEVICE_ENCODED; do + [[ -n $DEVICE_ENCODED ]] || continue + DEVICE=$(printf '%s' "$DEVICE_ENCODED" | base64 -d) + DEVICE_KIND=$(jq -r '.kind // "character-device"' <<<"$DEVICE") + DEVICE_GID_ENV=$(jq -r '.append_host_device_gid_to_environment // empty' <<<"$DEVICE") + if [[ $DEVICE_KIND == nvidia-runtime ]]; then + NVIDIA_GID_ENV=$DEVICE_GID_ENV + if (( NVIDIA_RUNTIME_CONFIGURED == 0 )); then + NVIDIA_FIRST_INDEX=$DEVICE_INDEX + configure_nvidia_runtime + NVIDIA_DEVICE_COUNT=$((DEVICE_INDEX - NVIDIA_FIRST_INDEX)) + fi + continue + fi + HOST_PATH=$(jq -er '.host_path' <<<"$DEVICE") + CONTAINER_PATH=$(jq -er '.container_path' <<<"$DEVICE") + MODE=$(jq -er '.mode' <<<"$DEVICE") + DENY_WRITE=$(jq -r '.deny_write | if . then 1 else 0 end' <<<"$DEVICE") + GID_STRATEGY=$(jq -er '.gid_strategy' <<<"$DEVICE") + [[ $HOST_PATH == /dev/* && $HOST_PATH == "$CONTAINER_PATH" ]] \ + || die "$(translate "The device must keep its /dev path inside the LXC:") $HOST_PATH" + case "$DEVICE_KIND" in + character-device) + DEVICE_UID=$(jq -r '.uid // empty' <<<"$DEVICE") + add_character_device "$HOST_PATH" "$MODE" "$GID_STRATEGY" "$DENY_WRITE" "$DEVICE_UID" + if [[ -n $DEVICE_GID_ENV ]]; then + append_deployment_environment_csv "$DEVICE_GID_ENV" "$(stat -c '%g' "$HOST_PATH")" + fi + ;; + block-device) + add_device "$HOST_PATH" block "$MODE" "$GID_STRATEGY" "$DENY_WRITE" + if [[ -n $DEVICE_GID_ENV ]]; then + append_deployment_environment_csv "$DEVICE_GID_ENV" "$(stat -c '%g' "$HOST_PATH")" + fi + ;; + character-device-tree) + [[ -d $HOST_PATH ]] || die "$(translate "The device directory does not exist:") $HOST_PATH" + FOUND_TREE_DEVICE=0 + while IFS= read -r TREE_DEVICE; do + [[ -n $TREE_DEVICE ]] || continue + add_character_device "$TREE_DEVICE" "$MODE" "$GID_STRATEGY" "$DENY_WRITE" + FOUND_TREE_DEVICE=1 + done < <(find "$HOST_PATH" -print 2>/dev/null | while IFS= read -r path; do + [[ -c $path ]] && printf '%s\n' "$path" + done | sort) + (( FOUND_TREE_DEVICE == 1 )) \ + || die "$(translate "The directory contains no character devices:") $HOST_PATH" + ;; + *) die "$(translate "Unsupported device type:") $DEVICE_KIND" ;; + esac +done < <(jq -r '.devices[]? | @base64' "$DEPLOYMENT_FILE") +if (( DEVICE_INDEX > NVIDIA_DEVICE_COUNT )); then + msg_ok "$(translate "Devices added to the container:") $((DEVICE_INDEX - NVIDIA_DEVICE_COUNT))" +fi + +apply_native_device_permissions + +# PVE represents the public env property as repeated native LXC runtime lines. +# Merge only Compose overrides while the newly-created CT is stopped. +while IFS=$'\t' read -r NAME ENCODED; do + [[ $NAME =~ ^[A-Za-z_][A-Za-z0-9_]*$ ]] || die "$(translate "Invalid variable name:") $NAME" + VALUE=$(printf '%s' "$ENCODED" | base64 -d) + [[ $VALUE != *$'\n'* && $VALUE != *$'\r'* ]] || die "$(translate "The variable contains line breaks:") $NAME" + if LC_ALL=C grep -q '[[:cntrl:]]' <<<"$VALUE"; then + die "$(translate "The variable contains control characters:") $NAME" + fi + TEMP_CONF=$(mktemp) + awk -v prefix="lxc.environment.runtime: ${NAME}=" 'index($0, prefix) != 1' "$CONF" >"$TEMP_CONF" + printf 'lxc.environment.runtime: %s=%s\n' "$NAME" "$VALUE" >>"$TEMP_CONF" + cat "$TEMP_CONF" >"$CONF" + rm -f "$TEMP_CONF" +done < <(jq -r '.environment[] | [.name, (.value | @base64)] | @tsv' "$DEPLOYMENT_FILE") + +apply_extra_hosts +apply_installer_profile +apply_rlimits +apply_host_monitor + +while IFS= read -r REPAIR_ENCODED; do + [[ -n $REPAIR_ENCODED ]] || continue + run_pre_start_repair "$(printf '%s' "$REPAIR_ENCODED" | base64 -d)" +done < <(jq -r '.proxmox.installer_profile.pre_start_repairs[]? | @base64' "$TEMPLATE_FILE") + +DEPLOYMENT_ENVIRONMENT=$(jq -c '.environment // []' "$DEPLOYMENT_FILE") +CREDENTIALS=$(jq -c --argjson environment "$DEPLOYMENT_ENVIRONMENT" ' + def env_value($name): + [$environment[]? | select(.name == $name) | .value] | last // null; + [.first_run.credentials[]? | + if .username_environment? then + .username = (env_value(.username_environment) // .username) + else . end | + if .password_environment? then + .password = (env_value(.password_environment) // .password) + else . end | + del(.username_environment, .password_environment) + ] +' "$TEMPLATE_FILE") +RUNTIME_CREDENTIALS=$(jq '[.[] | select(.retrieval.method? == "container-console-pattern")] | length' <<<"$CREDENTIALS") + +if [[ $START_AFTER == 1 && ( $RUNTIME_CREDENTIALS -gt 0 || $HAS_STARTUP_HEALTHCHECK == 1 || $HAS_RUNNING_CHECK == 1 || $HAOS_HEALTHCHECK != 0 ) ]]; then + RUNTIME_CONSOLE_DIR="/run/proxmenux-oci" + install -d -m 700 "$RUNTIME_CONSOLE_DIR" + RUNTIME_CONSOLE_LOG="${RUNTIME_CONSOLE_DIR}/ct-${VMID}.console.log" + install -m 600 /dev/null "$RUNTIME_CONSOLE_LOG" + printf 'lxc.console.logfile: %s\n' "$RUNTIME_CONSOLE_LOG" >>"$CONF" +fi + +oci_log "Configuration created for CT $VMID" +PASSWORD_STATE="" +if [[ $START_AFTER == 1 ]]; then + [[ $HAOS_HEALTHCHECK == 0 ]] || PRESERVE_FAILED_CT=1 + msg_info "$(translate "Starting the container...")" + oci_quiet pct start "$VMID" || die "$(translate "The container could not be started:") CT $VMID" + verify_host_monitor + if (( RUNTIME_CREDENTIALS > 0 )); then + while IFS= read -r encoded; do + [[ -n $encoded ]] || continue + credential=$(printf '%s' "$encoded" | base64 -d) + credential_label=$(jq -r '.label' <<<"$credential") + credential_pattern=$(jq -r '.retrieval.pattern // empty' <<<"$credential") + credential_timeout=$(jq -r '.retrieval.timeout_seconds // 90' <<<"$credential") + if [[ -z $credential_pattern ]]; then + case "$(jq -r '.retrieval.pattern_id // empty' <<<"$credential")" in + linuxserver-temporary-password) + credential_pattern='A temporary password is provided for this session:\s*(\S+)' ;; + *) die "$(translate "Unsupported credential pattern:") $credential_label" ;; + esac + fi + oci_log "Capturing the credential of ${credential_label} from the boot console" + msg_progress "$(translate "Waiting for the temporary password...")" + credential_value=$(capture_console_credential "$RUNTIME_CONSOLE_LOG" "$credential_pattern" "$credential_timeout") + if [[ -n $credential_value ]]; then + CREDENTIALS=$(jq -c --arg label "$credential_label" --arg password "$credential_value" \ + 'map(if .label == $label and .retrieval.method? == "container-console-pattern" then .password = $password else . end)' \ + <<<"$CREDENTIALS") + PASSWORD_STATE=retrieved + else + CREDENTIALS=$(jq -c --arg label "$credential_label" \ + 'map(if .label == $label and .retrieval.method? == "container-console-pattern" then + . + {retrieval_error: "The credential could not be retrieved from the boot console"} else . end)' \ + <<<"$CREDENTIALS") + oci_log "The credential of ${credential_label} could not be read from the console" + PASSWORD_STATE=missing + fi + done < <(jq -r '.[] | select(.retrieval.method? == "container-console-pattern") | @base64' <<<"$CREDENTIALS") + fi + FILE_CREDENTIALS=$(jq '[.[] | select(.retrieval.method? == "container-file")] | length' <<<"$CREDENTIALS") + if (( FILE_CREDENTIALS > 0 )); then + while IFS= read -r encoded; do + [[ -n $encoded ]] || continue + credential=$(printf '%s' "$encoded" | base64 -d) + credential_label=$(jq -r '.label' <<<"$credential") + credential_path=$(jq -r '.retrieval.path' <<<"$credential") + credential_pattern=$(jq -r '.retrieval.pattern // empty' <<<"$credential") + credential_timeout=$(jq -r '.retrieval.timeout_seconds // 180' <<<"$credential") + [[ $credential_path == /* && $credential_path != *[[:space:]]* ]] \ + || die "$(translate "Invalid credential file path:") $credential_path" + oci_log "Reading the credential of ${credential_label} from ${credential_path}" + if credential_value=$(capture_container_file_credential \ + "$VMID" "$credential_path" "$credential_pattern" "$credential_timeout"); then + CREDENTIALS=$(jq -c --arg label "$credential_label" --arg password "$credential_value" \ + 'map(if .label == $label and .retrieval.method? == "container-file" then .password = $password else . end)' \ + <<<"$CREDENTIALS") + PASSWORD_STATE=retrieved + else + CREDENTIALS=$(jq -c --arg label "$credential_label" \ + 'map(if .label == $label and .retrieval.method? == "container-file" then + . + {retrieval_error: "The credential could not be read from the container"} else . end)' \ + <<<"$CREDENTIALS") + oci_log "The credential of ${credential_label} could not be read" + PASSWORD_STATE=missing + fi + done < <(jq -r '.[] | select(.retrieval.method? == "container-file") | @base64' <<<"$CREDENTIALS") + fi + detect_container_ipv4 "$(translate "Container started")" + case "$PASSWORD_STATE" in + retrieved) msg_ok "$(translate "Temporary password retrieved")" ;; + missing) msg_warn "$(translate "The temporary password could not be retrieved.")" ;; + esac +else + IP="" + msg_ok "$(translate "Container configured (not started):") CT $VMID" +fi + +if [[ -z $IP && $IPV4 != dhcp ]]; then + IP=${IPV4%%/*} +fi + +POST_START_CONFIGURATION_COUNT=$(jq '.post_start_configurations? // [] | length' "$DEPLOYMENT_FILE") +if (( POST_START_CONFIGURATION_COUNT > 0 )); then + (( START_AFTER == 1 )) \ + || die "$(translate "The selected configuration needs to start the LXC during the installation")" + while IFS= read -r CONFIGURATION_ENCODED; do + [[ -n $CONFIGURATION_ENCODED ]] || continue + apply_post_start_configuration "$(printf '%s' "$CONFIGURATION_ENCODED" | base64 -d)" + done < <(jq -r '.post_start_configurations[]? | @base64' "$DEPLOYMENT_FILE") + msg_info "$(translate "Waiting for the network address...")" + detect_container_ipv4 + if [[ -z $IP && $IPV4 != dhcp ]]; then + IP=${IPV4%%/*} + fi +fi + +if [[ $START_AFTER == 1 && $HAS_STARTUP_HEALTHCHECK == 1 ]]; then + HC_SCHEME=$(jq -er '.scheme' <<<"$STARTUP_HEALTHCHECK") + HC_PORT=$(jq -er '.port' <<<"$STARTUP_HEALTHCHECK") + HC_PATH=$(jq -er '.path' <<<"$STARTUP_HEALTHCHECK") + HC_TIMEOUT=$(jq -er '.timeout_seconds' <<<"$STARTUP_HEALTHCHECK") + HC_REQUEST_TIMEOUT=$(jq -er '.request_timeout_seconds' <<<"$STARTUP_HEALTHCHECK") + HC_STABILITY=$(jq -r '.stability_seconds // 0' <<<"$STARTUP_HEALTHCHECK") + HC_VERIFY_TLS=$(jq -r '.verify_tls' <<<"$STARTUP_HEALTHCHECK") + [[ $HC_SCHEME == http || $HC_SCHEME == https ]] || die "$(translate "Invalid healthcheck scheme")" + [[ $HC_PORT =~ ^[0-9]+$ && $HC_PORT -ge 1 && $HC_PORT -le 65535 ]] \ + || die "$(translate "Invalid healthcheck port")" + [[ $HC_PATH == /* && $HC_PATH != *[[:space:]]* ]] || die "$(translate "Invalid healthcheck path")" + [[ $HC_TIMEOUT =~ ^[0-9]+$ && $HC_TIMEOUT -gt 0 ]] || die "$(translate "Invalid healthcheck timeout")" + [[ $HC_REQUEST_TIMEOUT =~ ^[0-9]+$ && $HC_REQUEST_TIMEOUT -gt 0 ]] \ + || die "$(translate "Invalid healthcheck request timeout")" + [[ $HC_STABILITY =~ ^[0-9]+$ ]] || die "$(translate "Invalid healthcheck stability period")" + (( HC_STABILITY < HC_TIMEOUT )) \ + || die "$(translate "The stability period must be shorter than the healthcheck timeout")" + [[ -n $IP ]] || die "$(translate "The healthcheck cannot run without an IP address")" + HC_URL="${HC_SCHEME}://${IP}:${HC_PORT}${HC_PATH}" + HC_ANY_STATUS=$(jq -r '.accept_any_status // false' <<<"$STARTUP_HEALTHCHECK") + if [[ $HC_ANY_STATUS == true ]]; then + CURL_ARGS=(-sS --noproxy '*' -o /dev/null -w '%{http_code}' --max-time "$HC_REQUEST_TIMEOUT") + else + CURL_ARGS=(-fsS --noproxy '*' -o /dev/null --max-time "$HC_REQUEST_TIMEOUT") + fi + [[ $HC_VERIFY_TLS == true ]] || CURL_ARGS+=(-k) + HC_OK=0 + HC_ELAPSED=0 + HC_STABLE_ELAPSED=0 + HC_STABLE_SINCE=0 + oci_log "Waiting for the service: $HC_URL" + msg_info "$(translate "Waiting for the application to respond...")" + while (( HC_ELAPSED < HC_TIMEOUT )); do + if [[ $(pct status "$VMID" 2>/dev/null || true) != "status: running" ]]; then + oci_log "The container stopped during its first start. Last console messages:" + [[ -s $RUNTIME_CONSOLE_LOG ]] && tr -d '\r' <"$RUNTIME_CONSOLE_LOG" | tail -n 100 >>"${OCI_LOG:-/dev/stderr}" + die "$(translate "The container stopped before the application responded:") CT $VMID" + fi + if healthcheck_probe; then + if (( HC_STABILITY == 0 )); then + HC_OK=1 + break + fi + HC_NOW=$(date +%s) + if (( HC_STABLE_SINCE == 0 )); then + HC_STABLE_SINCE=$HC_NOW + fi + HC_STABLE_ELAPSED=$((HC_NOW - HC_STABLE_SINCE)) + if (( HC_STABLE_ELAPSED >= HC_STABILITY )); then + HC_OK=1 + break + fi + else + HC_STABLE_ELAPSED=0 + HC_STABLE_SINCE=0 + fi + sleep 2 + HC_ELAPSED=$((HC_ELAPSED + 2)) + if (( HC_STABLE_ELAPSED > 0 )); then + msg_progress "$(translate "Application responding; checking its stability...") ${HC_STABLE_ELAPSED}/${HC_STABILITY} s" + else + msg_progress "$(translate "Waiting for the application to respond...") ${HC_ELAPSED}/${HC_TIMEOUT} s" + fi + done + if [[ $HC_OK != 1 ]]; then + oci_log "The service did not pass the healthcheck. Last console messages:" + [[ -s $RUNTIME_CONSOLE_LOG ]] && tr -d '\r' <"$RUNTIME_CONSOLE_LOG" | tail -n 100 >>"${OCI_LOG:-/dev/stderr}" + die "$(translate "The application did not respond in time:") $HC_URL" + fi + msg_ok "$(translate "Application responding:") $HC_URL" +fi + +# Applications without a web address: the container must keep running. +if [[ $START_AFTER == 1 && $HAS_RUNNING_CHECK == 1 ]]; then + RC_STABILITY=$(jq -r '.stability_seconds // 20' <<<"$STARTUP_HEALTHCHECK") + [[ $RC_STABILITY =~ ^[0-9]+$ && $RC_STABILITY -le 600 ]] || die "$(translate "Invalid healthcheck stability period")" + msg_info "$(translate "Checking that the container keeps running...")" + RC_START=$(date +%s) + while (( $(date +%s) - RC_START < RC_STABILITY )); do + if [[ $(pct status "$VMID" 2>/dev/null || true) != "status: running" ]]; then + oci_log "The container stopped after starting. Last console messages:" + [[ -s $RUNTIME_CONSOLE_LOG ]] && tr -d '\r' <"$RUNTIME_CONSOLE_LOG" | tail -n 100 >>"${OCI_LOG:-/dev/stderr}" + die "$(translate "The container stopped after starting:") CT $VMID" + fi + sleep 2 + done + msg_ok "$(translate "Container running steadily")" +fi + +HAOS_URLS="" +if [[ $START_AFTER == 1 && $HAOS_HEALTHCHECK != 0 ]]; then + PRESERVE_FAILED_CT=1 + [[ -n $IP ]] || die "$(translate "Home Assistant OS cannot be checked without an IP address")" + # The checker rewrites this line with its own progress on stderr. + msg_progress "$(translate "Waiting for Home Assistant OS...")" + HAOS_URLS=$(python3 "${SCRIPT_DIR}/haos_healthcheck.py" --vmid "$VMID" --ip "$IP" --timeout "$HAOS_HEALTHCHECK") \ + || die "$(translate "Home Assistant OS did not pass the Supervisor, Core and Observer checks")" + msg_ok "$(translate "Home Assistant OS ready: Supervisor, Core and Observer running")" +fi + +cleanup_runtime_console_log + +URLS=$(jq -c --arg ip "$IP" ' + if $ip == "" then [] + elif (.first_run.endpoints? // []) | length > 0 then + [.first_run.endpoints[] | { + label: .label, + url: (.scheme + "://" + $ip + ":" + (.port | tostring) + .path) + }] + elif .catalog_ui.launch.port != null then + [{ + label: "Web UI", + url: (.catalog_ui.launch.scheme + "://" + $ip + ":" + (.catalog_ui.launch.port | tostring) + .catalog_ui.launch.path) + }] + else [] end +' "$TEMPLATE_FILE") +if [[ -n $HAOS_URLS ]]; then + URLS=$HAOS_URLS +elif [[ $HAOS_HEALTHCHECK != 0 ]]; then + URLS='[]' + msg_info2 "$(translate "Home Assistant OS was not started: its addresses will be known once Core is running.")" +fi +INSTALL_COMPLETE=1 +if [[ $(jq -r '.stack_managed // false' "$DEPLOYMENT_FILE") == true ]]; then + msg_ok "$(translate "Container prepared for the stack:") CT $VMID ($HOSTNAME)" +elif [[ $START_AFTER == 1 ]]; then + check_native_device_permissions +fi +if [[ -z ${PROXMENUX_OCI_TRANSACTION:-} ]] && ! oci_quiet python3 "${SCRIPT_DIR}/oci_instances.py" complete "$VMID" \ + --archive "$ARCHIVE_PATH" --digest "$DIGEST"; then + msg_warn "$(translate "Container installed, but without a verifiable record for future updates.")" +fi +COMPLETION_NOTES=$(jq -c '.proxmox.installer_profile.completion_notes // []' "$TEMPLATE_FILE") +RESULT=$(jq -cn \ + --arg app_id "$APP_ID" \ + --arg image "$IMAGE_REF" \ + --arg digest "$DIGEST" \ + --arg architecture "$ARCH" \ + --arg image_version "$IMAGE_VERSION" \ + --arg image_created "$CREATED" \ + --arg ip "$IP" \ + --argjson urls "$URLS" \ + --argjson credentials "$CREDENTIALS" \ + --argjson completion_notes "$COMPLETION_NOTES" \ + --argjson vmid "$VMID" \ + --arg log "${OCI_LOG:-}" \ + '{app_id:$app_id,vmid:$vmid,image:$image,digest:$digest,architecture:$architecture,image_version:$image_version,image_created:$image_created,ip:$ip,urls:$urls,credentials:$credentials,completion_notes:$completion_notes,log:$log}') +printf 'PROXMENUX_RESULT=%s\n' "$(printf '%s' "$RESULT" | base64 | tr -d '\n')" diff --git a/oci/remote/install_paperless_stack.sh b/oci/remote/install_paperless_stack.sh new file mode 100755 index 00000000..bcab84a5 --- /dev/null +++ b/oci/remote/install_paperless_stack.sh @@ -0,0 +1,542 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +TEMPLATE_FILE=${1:?template JSON required} +DEPLOYMENT_FILE=${2:?deployment JSON required} +DRY_RUN=${3:-0} +SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd) +source "$SCRIPT_DIR/oci_ui.sh" +VERIFY_OCI_ARCHIVE="${SCRIPT_DIR}/verify_oci_archive.py" +ALLOCATE_PRIVATE_NETWORK="${SCRIPT_DIR}/allocate_private_network.py" +STACK_DEPENDENCY_HOOK="${SCRIPT_DIR}/stack_dependency_hook.sh" + +die() { + stop_spinner + msg_error "$*" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + exit 1 +} + +require_command() { + command -v "$1" >/dev/null 2>&1 || die "$(translate "Missing required command:") $1" +} + +jqr() { + jq -er "$1" "$DEPLOYMENT_FILE" +} + +set_runtime_env() { + local id=$1 key=$2 value=$3 config="/etc/pve/lxc/${1}.conf" + sed -i -E "/^lxc\.environment\.runtime: ${key}=/d" "$config" + printf 'lxc.environment.runtime: %s=%s\n' "$key" "$value" >>"$config" +} + +set_lxc_directive() { + local id=$1 key=$2 value=$3 config="/etc/pve/lxc/${1}.conf" escaped_key + escaped_key=${key//./\.} + sed -i -E "/^${escaped_key}:/d" "$config" + printf '%s: %s\n' "$key" "$value" >>"$config" +} + +created_ids=() +INSTALL_COMPLETE=0 +PRIVATE_BRIDGE_CREATED=0 +LIFECYCLE_CONFIG_PATH="" +UNEXPECTED_FAILURE=0 +rollback() { + local status=$? index id + stop_spinner + if (( status != 0 && UNEXPECTED_FAILURE == 1 )); then + msg_error "$(translate "The installation stopped because of an unexpected error")" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + fi + if (( status != 0 && INSTALL_COMPLETE == 0 )); then + if declare -F oci_native_failed >/dev/null; then oci_native_failed; fi + if (( ${#created_ids[@]} > 0 || PRIVATE_BRIDGE_CREATED == 1 )); then + msg_info "$(translate "Removing the incomplete stack...")" + fi + for ((index=${#created_ids[@]}-1; index>=0; index--)); do + id=${created_ids[index]} + pct stop "$id" --skiplock 1 >/dev/null 2>&1 || true + pct destroy "$id" --force 1 --purge 1 >/dev/null 2>&1 \ + || pct destroy "$id" --purge 1 >/dev/null 2>&1 \ + || true + done + if (( PRIVATE_BRIDGE_CREATED == 1 )); then + oci_log "Removing the private bridge created by this installation" + ip link delete "$PRIVATE_BRIDGE" type bridge >/dev/null 2>&1 || true + pvesh delete "/nodes/${NODE}/network/${PRIVATE_BRIDGE}" >/dev/null 2>&1 || true + fi + [[ -z $LIFECYCLE_CONFIG_PATH ]] || rm -f "$LIFECYCLE_CONFIG_PATH" + if (( ${#created_ids[@]} > 0 || PRIVATE_BRIDGE_CREATED == 1 )); then + msg_ok "$(translate "Incomplete stack removed")" + fi + fi + exit "$status" +} +trap rollback EXIT +trap 'UNEXPECTED_FAILURE=1; oci_log "Command failed at line $LINENO (${FUNCNAME[0]:-main})"' ERR + +[[ $EUID -eq 0 ]] || die "$(translate "The installer must run as root on Proxmox VE")" +oci_log_init "$(jq -r '.stack_name // "paperless"' "$DEPLOYMENT_FILE" 2>/dev/null || printf paperless)" +for command in pct qm pvesh pvesm skopeo jq openssl python3 curl ip stat dpkg base64 mktemp lxc-info flock; do + require_command "$command" +done +[[ -r $VERIFY_OCI_ARCHIVE ]] || die "$(translate "The OCI archive verifier was not found")" +[[ -r $ALLOCATE_PRIVATE_NETWORK ]] || die "$(translate "The private network allocator was not found")" +[[ -r $STACK_DEPENDENCY_HOOK ]] || die "$(translate "The stack startup hook was not found")" + +msg_info "$(translate "Reserving a private network...")" +exec 9>/run/lock/proxmenux-private-network.lock +flock 9 +oci_quiet python3 "$ALLOCATE_PRIVATE_NETWORK" "$DEPLOYMENT_FILE" \ + || die "$(translate "Could not reserve a private network for the stack")" + +STACK_NAME=$(jqr '.stack_name') +[[ $STACK_NAME =~ ^[a-z0-9][a-z0-9-]{0,31}$ ]] || die "$(translate "Invalid stack name")" +BASE_VMID=$(jq -r '.base_vmid // empty' "$DEPLOYMENT_FILE") +TEMPLATE_STORAGE=$(jqr '.template_storage') +ROOTFS_STORAGE=$(jqr '.rootfs_storage') +DATABASE_STORAGE=$(jqr '.database_storage') +DATABASE_SIZE=$(jqr '.database_size_gb') +BROKER_SIZE=$(jqr '.broker_size_gb') +APPLICATION_STORAGE=$(jqr '.application_storage') +DATA_SIZE=$(jqr '.data_size_gb') +MEDIA_SIZE=$(jqr '.media_size_gb') +TRANSFER_MODE=$(jqr '.transfer.mode') +TRANSFER_STORAGE=$(jq -r '.transfer.storage // empty' "$DEPLOYMENT_FILE") +TRANSFER_SIZE=$(jq -r '.transfer.size_gb // empty' "$DEPLOYMENT_FILE") +TRANSFER_ROOT=$(jq -r '.transfer.host_path // empty' "$DEPLOYMENT_FILE") +ADMIN_USERNAME=$(jqr '.application.admin_username') +OCR_LANGUAGE=$(jqr '.application.ocr_language') +TIMEZONE=$(jqr '.timezone') +ONBOOT=$(jqr '.onboot | if . then 1 else 0 end') +START_AFTER=$(jqr '.start_after_create | if . then 1 else 0 end') +FRONTEND_BRIDGE=$(jqr '.network.frontend_bridge') +FRONTEND_IPV4=$(jqr '.network.frontend_ipv4') +FRONTEND_GATEWAY=$(jq -r '.network.frontend_gateway // empty' "$DEPLOYMENT_FILE") +oci_access_net "$FRONTEND_IPV4" "$FRONTEND_GATEWAY" \ + || die "$(translate "Invalid access address:") $FRONTEND_IPV4 $FRONTEND_GATEWAY" +FRONTEND_NET=$OCI_ACCESS_NET +PRIVATE_BRIDGE=$(jqr '.network.private_bridge') +PRIVATE_SUBNET=$(jqr '.network.private_subnet') +PRIVATE_HOST_ADDRESS=$(jqr '.network.private_host_address') +APPLICATION_ADDRESS=$(jqr '.network.application_address') +DATABASE_ADDRESS=$(jqr '.network.database_address') +BROKER_ADDRESS=$(jqr '.network.broker_address') +APPLICATION_IP=${APPLICATION_ADDRESS%/*} +DATABASE_IP=${DATABASE_ADDRESS%/*} +BROKER_IP=${BROKER_ADDRESS%/*} + +[[ $DATABASE_SIZE =~ ^[0-9]+$ ]] && (( DATABASE_SIZE >= 8 )) \ + || die "$(translate "The PostgreSQL volume needs at least 8 GB")" +[[ $DATA_SIZE =~ ^[0-9]+$ && $MEDIA_SIZE =~ ^[0-9]+$ ]] \ + && (( DATA_SIZE >= 8 && MEDIA_SIZE >= 8 )) \ + || die "$(translate "The data and document volumes need at least 8 GB")" +[[ $BROKER_SIZE =~ ^[0-9]+$ ]] && (( BROKER_SIZE >= 1 )) \ + || die "$(translate "The Valkey volume needs at least 1 GB")" +[[ $ADMIN_USERNAME =~ ^[A-Za-z0-9_.@-]+$ ]] || die "$(translate "Invalid administrator user name")" +[[ $OCR_LANGUAGE =~ ^[a-z]{3}(\+[a-z]{3})*$ ]] \ + || die "$(translate "Invalid OCR language:") $OCR_LANGUAGE" +case "$TRANSFER_MODE" in + managed-volume) + [[ -n $TRANSFER_STORAGE && $TRANSFER_SIZE =~ ^[0-9]+$ ]] \ + && (( TRANSFER_SIZE >= 1 )) || die "$(translate "Invalid consume/export volumes")" + ;; + host-bind) + [[ $TRANSFER_ROOT == /* && $TRANSFER_ROOT != *","* && $TRANSFER_ROOT != *$'\n'* ]] \ + || die "$(translate "Invalid shared path")" + ;; + *) die "$(translate "Unsupported storage mode:") $TRANSFER_MODE" ;; +esac +[[ $PRIVATE_BRIDGE =~ ^vmbr[0-9]+$ ]] || die "$(translate "Invalid private bridge")" +[[ $PRIVATE_SUBNET =~ ^10\.77\.[0-9]{1,3}\.0/24$ ]] || die "$(translate "Invalid private network")" + +vmid_block_free() { + local candidate=$1 offset + for offset in 0 1 2; do + pct config "$((candidate + offset))" >/dev/null 2>&1 && return 1 + qm config "$((candidate + offset))" >/dev/null 2>&1 && return 1 + done + return 0 +} + +if [[ -z $BASE_VMID ]]; then + BASE_VMID=$(pvesh get /cluster/nextid) + while ! vmid_block_free "$BASE_VMID"; do + BASE_VMID=$((BASE_VMID + 1)) + done +fi +[[ $BASE_VMID =~ ^[0-9]+$ ]] || die "$(translate "Invalid base VMID")" +vmid_block_free "$BASE_VMID" || die "$(translate "These VMIDs are not free:") ${BASE_VMID}-$((BASE_VMID + 2))" + +APPLICATION_ID=$BASE_VMID +BROKER_ID=$((BASE_VMID + 1)) +DATABASE_ID=$((BASE_VMID + 2)) + +oci_log "Stack: $STACK_NAME; VMIDs: Paperless=$APPLICATION_ID, Valkey=$BROKER_ID, PostgreSQL=$DATABASE_ID" +oci_log "Private network: $PRIVATE_SUBNET on $PRIVATE_BRIDGE" + +if [[ $DRY_RUN == 1 ]]; then + msg_info2 "$(translate "Stack:") $STACK_NAME · CT ${APPLICATION_ID}-${DATABASE_ID}" + msg_info2 "$(translate "Private network:") $PRIVATE_BRIDGE ($PRIVATE_SUBNET)" + msg_ok "$(translate "Dry run completed; no containers were created.")" + exit 0 +fi + +NODE=$(hostname) +if ! pvesh get "/nodes/${NODE}/network/${PRIVATE_BRIDGE}" >/dev/null 2>&1; then + oci_log "Creating the persistent configuration for $PRIVATE_BRIDGE" + oci_quiet pvesh create "/nodes/${NODE}/network" --iface "$PRIVATE_BRIDGE" --type bridge \ + --autostart 1 --cidr "$PRIVATE_HOST_ADDRESS" + PRIVATE_BRIDGE_CREATED=1 +fi +if ! ip link show "$PRIVATE_BRIDGE" >/dev/null 2>&1; then + oci_log "Activating the private bridge $PRIVATE_BRIDGE" + oci_quiet ip link add name "$PRIVATE_BRIDGE" type bridge + oci_quiet ip address add "$PRIVATE_HOST_ADDRESS" dev "$PRIVATE_BRIDGE" + oci_quiet ip link set "$PRIVATE_BRIDGE" up +fi +ip -4 address show dev "$PRIVATE_BRIDGE" | grep -Fq "${PRIVATE_HOST_ADDRESS%/*}/" \ + || die "$(translate "The private bridge does not have the expected address:") $PRIVATE_BRIDGE ($PRIVATE_HOST_ADDRESS)" + +for address in "$APPLICATION_ADDRESS" "$DATABASE_ADDRESS" "$BROKER_ADDRESS"; do + if grep -RqsF "ip=${address}" /etc/pve/lxc/*.conf 2>/dev/null; then + die "$(translate "The private address is already assigned to another container:") ${address%/*}" + fi +done +flock -u 9 +msg_ok "$(translate "Private network:") $PRIVATE_BRIDGE ($PRIVATE_SUBNET)" + +ARCH=$(dpkg --print-architecture) +case "$ARCH" in amd64|arm64) ;; *) die "$(translate "Unsupported architecture:") $ARCH" ;; esac + +skopeo_transport_reference() { + local reference=$1 name digest + if [[ $reference == *@sha256:* ]]; then + name=${reference%@sha256:*} + digest="sha256:${reference##*@sha256:}" + [[ ${name##*/} == *:* ]] && name=${name%:*} + printf '%s@%s' "$name" "$digest" + else + printf '%s' "$reference" + fi +} + +resolve_image_manifest() { + local label=$1 image=$2 manifest_file error_file pid elapsed=0 status=0 + manifest_file=$(mktemp /tmp/proxmenux-oci-inspect.XXXXXX) + error_file="${manifest_file}.err" + oci_log "Querying the OCI registry for ${label}: ${image}" + skopeo inspect --no-tags --override-os linux --override-arch "$ARCH" \ + "docker://${image}" >"$manifest_file" 2>"$error_file" & + pid=$! + while kill -0 "$pid" 2>/dev/null; do + sleep 2 + elapsed=$((elapsed + 2)) + done + wait "$pid" || status=$? + if (( status != 0 )); then + cat "$error_file" >>"$OCI_LOG" + rm -f "$manifest_file" "$error_file" + return "$status" + fi + oci_log "Manifest for ${label} resolved in ${elapsed}s" + cat "$manifest_file" + rm -f "$manifest_file" "$error_file" +} + +ensure_image() { + local key=$1 image=$2 transport_image inspect digest short archive_name archive_volume archive_path + local partial log pid bytes elapsed status + msg_info "$(translate "Checking the image in the registry...")" + oci_log "Resolving ${key}: ${image}" + transport_image=$(skopeo_transport_reference "$image") + inspect=$(resolve_image_manifest "$key" "$transport_image") \ + || die "$(translate "Could not resolve the OCI manifest:") $image" + digest=$(jq -er '.Digest' <<<"$inspect") + oci_log "Selected digest for ${key}: ${digest}" + short=${digest#sha256:} + short=${short:0:16} + archive_name="image-paperless-${key}_${ARCH}_${short}.tar" + archive_volume="${TEMPLATE_STORAGE}:vztmpl/${archive_name}" + archive_path=$(pvesm path "$archive_volume") + mkdir -p "$(dirname "$archive_path")" + if [[ -s $archive_path ]]; then + msg_info "$(translate "Verifying the image integrity...")" + fi + if [[ -s $archive_path ]] && oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$archive_path"; then + oci_log "Reusing ${archive_volume}" + else + rm -f "$archive_path" + partial="${archive_path}.partial.$$" + log="${partial}.log" + oci_log "Downloading ${image} by digest ${digest}" + skopeo copy --override-os linux --override-arch "$ARCH" --retry-times 3 \ + --retry-delay 5s --image-parallel-copies 1 \ + "docker://${transport_image}" "oci-archive:${partial}:image-paperless-${key}" >"$log" 2>&1 & + pid=$! + elapsed=0 + while kill -0 "$pid" 2>/dev/null; do + bytes=$(stat -c %s "$partial" 2>/dev/null || printf 0) + msg_progress "$(translate "Downloading the image:") ${key} · $((bytes / 1048576)) MiB · ${elapsed}s" + sleep 2 + elapsed=$((elapsed + 2)) + done + status=0 + wait "$pid" || status=$? + cat "$log" >>"$OCI_LOG" + rm -f "$log" + (( status == 0 )) || { rm -f "$partial"; die "$(translate "Image download failed:") $image"; } + msg_info "$(translate "Verifying the image integrity...")" + oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$partial" \ + || { rm -f "$partial"; die "$(translate "The downloaded image is corrupt:") $image"; } + mv -f "$partial" "$archive_path" + fi + msg_ok "$(translate "Image:") $image" + RESOLVED_ARCHIVE=$archive_volume + RESOLVED_DIGEST=$digest +} + +APPLICATION_IMAGE=$(jq -er '.container_contract.image.reference' "$TEMPLATE_FILE") +DATABASE_IMAGE=$(jq -er '.compose_stack.services[] | select(.name == "db") | .image' "$TEMPLATE_FILE") +BROKER_IMAGE=$(jq -er '.compose_stack.services[] | select(.name == "broker") | .image' "$TEMPLATE_FILE") + +ensure_image application "$APPLICATION_IMAGE" +APPLICATION_ARCHIVE=$RESOLVED_ARCHIVE +APPLICATION_DIGEST=$RESOLVED_DIGEST +ensure_image database "$DATABASE_IMAGE" +DATABASE_ARCHIVE=$RESOLVED_ARCHIVE +DATABASE_DIGEST=$RESOLVED_DIGEST +ensure_image broker "$BROKER_IMAGE" +BROKER_ARCHIVE=$RESOLVED_ARCHIVE +BROKER_DIGEST=$RESOLVED_DIGEST + +source "$SCRIPT_DIR/oci_native_stack.sh" +oci_native_begin "$APPLICATION_ID" \ + --member application "$APPLICATION_ID" "$APPLICATION_IMAGE" "$APPLICATION_ARCHIVE" \ + --member broker "$BROKER_ID" "$BROKER_IMAGE" "$BROKER_ARCHIVE" \ + --member database "$DATABASE_ID" "$DATABASE_IMAGE" "$DATABASE_ARCHIVE" + +DB_PASSWORD=$(openssl rand -hex 24) +ADMIN_PASSWORD=$(openssl rand -hex 16) +SECRET_KEY=$(openssl rand -hex 64) +if [[ $TRANSFER_MODE == host-bind ]]; then + for path in "$TRANSFER_ROOT/consume" "$TRANSFER_ROOT/export"; do + if [[ -e $path ]]; then + [[ -d $path ]] || die "$(translate "The shared path exists but is not a directory:") $path" + else + install -d -m 0770 -o 101000 -g 101000 "$path" + fi + done + CONSUME_MOUNT="${TRANSFER_ROOT}/consume,mp=/usr/src/paperless/consume,backup=0" + EXPORT_MOUNT="${TRANSFER_ROOT}/export,mp=/usr/src/paperless/export,backup=0" +else + CONSUME_MOUNT="${TRANSFER_STORAGE}:${TRANSFER_SIZE},mp=/usr/src/paperless/consume,backup=1" + EXPORT_MOUNT="${TRANSFER_STORAGE}:${TRANSFER_SIZE},mp=/usr/src/paperless/export,backup=1" +fi +TAGS="productivity;oci;proxmenux" + +msg_info "$(translate "Creating the container...")" +oci_quiet pct create "$DATABASE_ID" "$DATABASE_ARCHIVE" --rootfs "${ROOTFS_STORAGE}:8" \ + --mp0 "${DATABASE_STORAGE}:${DATABASE_SIZE},mp=/var/lib/postgresql,backup=1" \ + --hostname "${STACK_NAME}-db" --cores 2 --memory 1024 --swap 512 \ + --net0 "name=eth0,bridge=${PRIVATE_BRIDGE},firewall=1,host-managed=1,ip=${DATABASE_ADDRESS},type=veth" \ + --unprivileged 1 --features nesting=1 --cmode console --onboot "$ONBOOT" \ + --startup order=10,up=10,down=30 --tags "$TAGS" \ + --description 'Paperless PostgreSQL native OCI' +created_ids+=("$DATABASE_ID") + +oci_quiet pct mount "$DATABASE_ID" +DATABASE_ROOT="/var/lib/lxc/${DATABASE_ID}/rootfs" +POSTGRES_UID=$(awk -F: '$1 == "postgres" {print $3}' "$DATABASE_ROOT/etc/passwd") +POSTGRES_GID=$(awk -F: '$1 == "postgres" {print $4}' "$DATABASE_ROOT/etc/passwd") +[[ -n $POSTGRES_UID && -n $POSTGRES_GID ]] || die "$(translate "The postgres user was not found in the image")" +rm -rf "$DATABASE_ROOT/var/lib/postgresql/lost+found" +cat >"$DATABASE_ROOT/usr/local/bin/paperless-postgres-lxc-start" <"$LIFECYCLE_SPEC" +LIFECYCLE_CONFIG_PATH="/etc/pve/priv/proxmenux-stack-${APPLICATION_ID}.json" +if ! oci_quiet bash "$STACK_DEPENDENCY_HOOK" --install "$APPLICATION_ID" "$LIFECYCLE_SPEC"; then + rm -f "$LIFECYCLE_SPEC" + die "$(translate "Could not install the stack startup hook")" +fi +rm -f "$LIFECYCLE_SPEC" +msg_ok "$(translate "Stack startup hook installed")" + +wait_command() { + local label=$1 retries=$2 + shift 2 + local attempt + for attempt in $(seq 1 "$retries"); do + "$@" >/dev/null 2>&1 && return 0 + sleep 2 + done + die "$(translate "Health check failed:") $label" +} + +APPLICATION_LAN_IP="" +if (( START_AFTER == 1 )); then + msg_info "$(translate "Starting the service:") PostgreSQL" + oci_quiet pct start "$DATABASE_ID" + wait_command PostgreSQL 60 pct exec "$DATABASE_ID" -- \ + pg_isready -h "$DATABASE_IP" -U paperless -d paperless + msg_ok "$(translate "Service ready:") PostgreSQL" + msg_info "$(translate "Starting the service:") Valkey" + oci_quiet pct start "$BROKER_ID" + wait_command Valkey 60 pct exec "$BROKER_ID" -- valkey-cli -h "$BROKER_IP" ping + msg_ok "$(translate "Service ready:") Valkey" + msg_info "$(translate "Starting the service:") Paperless-ngx" + oci_quiet pct start "$APPLICATION_ID" + + msg_info "$(translate "Waiting for the application to respond...")" + for _ in $(seq 1 180); do + APPLICATION_LAN_IP=$(lxc-info -n "$APPLICATION_ID" -iH 2>/dev/null \ + | grep -E '^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$' \ + | grep -vFx "$APPLICATION_IP" | head -n 1 || true) + if [[ -n $APPLICATION_LAN_IP ]] \ + && curl -fsS "http://${APPLICATION_LAN_IP}:8000/" >/dev/null 2>&1; then + break + fi + if [[ $(pct status "$APPLICATION_ID" 2>/dev/null) != *running* ]]; then + die "$(translate "The application stopped during its first start:") Paperless-ngx" + fi + sleep 2 + done + [[ -n $APPLICATION_LAN_IP ]] \ + || die "$(translate "The application did not get an address on the access network:") Paperless-ngx" + curl -fsS "http://${APPLICATION_LAN_IP}:8000/" >/dev/null 2>>"$OCI_LOG" \ + || die "$(translate "The application did not complete its initial setup:") Paperless-ngx" + msg_ok "$(translate "Application responding:") http://${APPLICATION_LAN_IP}:8000/" +fi + +RESULT=$(jq -nc \ + --argjson vmid "$APPLICATION_ID" \ + --arg ip "$APPLICATION_LAN_IP" \ + --argjson application_id "$APPLICATION_ID" \ + --argjson database_id "$DATABASE_ID" \ + --argjson broker_id "$BROKER_ID" \ + --arg admin_user "$ADMIN_USERNAME" \ + --arg admin_password "$ADMIN_PASSWORD" \ + --arg application_digest "$APPLICATION_DIGEST" \ + --arg database_digest "$DATABASE_DIGEST" \ + --arg broker_digest "$BROKER_DIGEST" \ + --arg admin_label "$(translate "Initial Paperless-ngx administrator")" \ + --arg log "$OCI_LOG" \ + '{ + vmid: $vmid, + ip: (if $ip == "" then null else $ip end), + stack_vmids: { + paperless: $application_id, + database: $database_id, + broker: $broker_id + }, + urls: (if $ip == "" then [] else [{label: "Paperless-ngx WebUI", url: ("http://" + $ip + ":8000/")}] end), + credentials: [{ + label: $admin_label, + username: $admin_user, + password: $admin_password, + change_required: true + }], + image_digests: { + application: $application_digest, + database: $database_digest, + broker: $broker_digest + }, + log: $log + }') +INSTALL_COMPLETE=1 +oci_native_finalize +printf 'PROXMENUX_RESULT=%s\n' "$(printf '%s' "$RESULT" | base64 -w0)" diff --git a/oci/remote/install_tandoor_stack.sh b/oci/remote/install_tandoor_stack.sh new file mode 100755 index 00000000..f8455244 --- /dev/null +++ b/oci/remote/install_tandoor_stack.sh @@ -0,0 +1,505 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +TEMPLATE_FILE=${1:?template JSON required} +DEPLOYMENT_FILE=${2:?deployment JSON required} +DRY_RUN=${3:-0} +SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd) +source "$SCRIPT_DIR/oci_ui.sh" +VERIFY_OCI_ARCHIVE="${SCRIPT_DIR}/verify_oci_archive.py" +ALLOCATE_PRIVATE_NETWORK="${SCRIPT_DIR}/allocate_private_network.py" +STACK_DEPENDENCY_HOOK="${SCRIPT_DIR}/stack_dependency_hook.sh" +INSTALL_STARTED_AT=$(date --iso-8601=seconds) + +die() { + stop_spinner + msg_error "$*" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + exit 1 +} + +require_command() { + command -v "$1" >/dev/null 2>&1 || die "$(translate "Missing required command:") $1" +} + +jqr() { + jq -er "$1" "$DEPLOYMENT_FILE" +} + +set_runtime_env() { + local id=$1 key=$2 value=$3 config="/etc/pve/lxc/${1}.conf" + sed -i -E "/^lxc\.environment\.runtime: ${key}=/d" "$config" + printf 'lxc.environment.runtime: %s=%s\n' "$key" "$value" >>"$config" +} + +set_lxc_directive() { + local id=$1 key=$2 value=$3 config="/etc/pve/lxc/${1}.conf" escaped_key + escaped_key=${key//./\.} + sed -i -E "/^${escaped_key}:/d" "$config" + printf '%s: %s\n' "$key" "$value" >>"$config" +} + +print_first_boot_diagnostics() { + local id=$1 label=$2 + { + printf '=== %s CT %s: Proxmox service ===\n' "$label" "$id" + journalctl -u "pve-container@${id}.service" --since "$INSTALL_STARTED_AT" \ + --no-pager -n 120 2>&1 || true + printf '\n=== Host: serious errors since the installation started ===\n' + journalctl -k --since "$INSTALL_STARTED_AT" --no-pager 2>&1 \ + | grep -iE 'segfault|general protection fault|mce:|hardware error|memory failure|out of memory|oom-kill' \ + | tail -n 120 || true + } >>"$OCI_LOG" +} + +created_ids=() +INSTALL_COMPLETE=0 +PRIVATE_BRIDGE_CREATED=0 +LIFECYCLE_CONFIG_PATH="" +UNEXPECTED_FAILURE=0 +rollback() { + local status=$? index id + stop_spinner + if (( status != 0 && UNEXPECTED_FAILURE == 1 )); then + msg_error "$(translate "The installation stopped because of an unexpected error")" + if [[ -n ${OCI_LOG:-} && -s ${OCI_LOG:-} ]]; then + oci_log_tail 12 >&2 + printf ' %s %s\n' "$(translate "Full log:")" "$OCI_LOG" >&2 + fi + fi + if (( status != 0 && INSTALL_COMPLETE == 0 )); then + if declare -F oci_native_failed >/dev/null; then oci_native_failed; fi + if (( ${#created_ids[@]} > 0 || PRIVATE_BRIDGE_CREATED == 1 )); then + msg_info "$(translate "Removing the incomplete stack...")" + fi + for ((index=${#created_ids[@]}-1; index>=0; index--)); do + id=${created_ids[index]} + pct stop "$id" --skiplock 1 >/dev/null 2>&1 || true + pct destroy "$id" --force 1 --purge 1 >/dev/null 2>&1 \ + || pct destroy "$id" --purge 1 >/dev/null 2>&1 \ + || true + done + if (( PRIVATE_BRIDGE_CREATED == 1 )); then + oci_log "Removing the private bridge created by this installation" + ip link delete "$PRIVATE_BRIDGE" type bridge >/dev/null 2>&1 || true + pvesh delete "/nodes/${NODE}/network/${PRIVATE_BRIDGE}" >/dev/null 2>&1 || true + fi + [[ -z $LIFECYCLE_CONFIG_PATH ]] || rm -f "$LIFECYCLE_CONFIG_PATH" + if (( ${#created_ids[@]} > 0 || PRIVATE_BRIDGE_CREATED == 1 )); then + msg_ok "$(translate "Incomplete stack removed")" + fi + fi + exit "$status" +} +trap rollback EXIT +trap 'UNEXPECTED_FAILURE=1; oci_log "Command failed at line $LINENO (${FUNCNAME[0]:-main})"' ERR + +[[ $EUID -eq 0 ]] || die "$(translate "The installer must run as root on Proxmox VE")" +oci_log_init "$(jq -r '.stack_name // "tandoor"' "$DEPLOYMENT_FILE" 2>/dev/null || printf tandoor)" +for command in pct qm pvesh pvesm skopeo jq openssl python3 curl ip stat dpkg base64 mktemp lxc-info flock journalctl tee; do + require_command "$command" +done +[[ -r $VERIFY_OCI_ARCHIVE ]] || die "$(translate "The OCI archive verifier was not found")" +[[ -r $ALLOCATE_PRIVATE_NETWORK ]] || die "$(translate "The private network allocator was not found")" +[[ -r $STACK_DEPENDENCY_HOOK ]] || die "$(translate "The stack startup hook was not found")" + +msg_info "$(translate "Reserving a private network...")" +exec 9>/run/lock/proxmenux-private-network.lock +flock 9 +oci_quiet python3 "$ALLOCATE_PRIVATE_NETWORK" "$DEPLOYMENT_FILE" \ + || die "$(translate "Could not reserve a private network for the stack")" + +STACK_NAME=$(jqr '.stack_name') +[[ $STACK_NAME =~ ^[a-z0-9][a-z0-9-]{0,31}$ ]] || die "$(translate "Invalid stack name")" +BASE_VMID=$(jq -r '.base_vmid // empty' "$DEPLOYMENT_FILE") +TEMPLATE_STORAGE=$(jqr '.template_storage') +ROOTFS_STORAGE=$(jqr '.rootfs_storage') +APPLICATION_STORAGE=$(jqr '.application_storage') +STATIC_SIZE=$(jqr '.static_size_gb') +DATABASE_STORAGE=$(jqr '.database_storage') +DATABASE_SIZE=$(jqr '.database_size_gb') +MEDIA_MODE=$(jqr '.media.mode') +MEDIA_STORAGE=$(jq -r '.media.storage // empty' "$DEPLOYMENT_FILE") +MEDIA_SIZE=$(jq -r '.media.size_gb // empty' "$DEPLOYMENT_FILE") +MEDIA_ROOT=$(jq -r '.media.host_path // empty' "$DEPLOYMENT_FILE") +ALLOWED_HOSTS=$(jqr '.application.allowed_hosts') +ADMIN_USERNAME=$(jqr '.application.admin_username') +ADMIN_EMAIL=$(jqr '.application.admin_email') +TIMEZONE=$(jqr '.timezone') +ONBOOT=$(jqr '.onboot | if . then 1 else 0 end') +START_AFTER=$(jqr '.start_after_create | if . then 1 else 0 end') +FRONTEND_BRIDGE=$(jqr '.network.frontend_bridge') +FRONTEND_IPV4=$(jqr '.network.frontend_ipv4') +FRONTEND_GATEWAY=$(jq -r '.network.frontend_gateway // empty' "$DEPLOYMENT_FILE") +oci_access_net "$FRONTEND_IPV4" "$FRONTEND_GATEWAY" \ + || die "$(translate "Invalid access address:") $FRONTEND_IPV4 $FRONTEND_GATEWAY" +FRONTEND_NET=$OCI_ACCESS_NET +PRIVATE_BRIDGE=$(jqr '.network.private_bridge') +PRIVATE_SUBNET=$(jqr '.network.private_subnet') +PRIVATE_HOST_ADDRESS=$(jqr '.network.private_host_address') +APPLICATION_ADDRESS=$(jqr '.network.application_address') +DATABASE_ADDRESS=$(jqr '.network.database_address') +APPLICATION_IP=${APPLICATION_ADDRESS%/*} +DATABASE_IP=${DATABASE_ADDRESS%/*} + +[[ $STATIC_SIZE =~ ^[0-9]+$ ]] && (( STATIC_SIZE >= 1 )) \ + || die "$(translate "The staticfiles volume needs at least 1 GB")" +[[ $DATABASE_SIZE =~ ^[0-9]+$ ]] && (( DATABASE_SIZE >= 4 )) \ + || die "$(translate "The PostgreSQL volume needs at least 4 GB")" +[[ $ALLOWED_HOSTS != *$'\n'* && $ALLOWED_HOSTS != *$'\r'* ]] \ + || die "$(translate "Invalid ALLOWED_HOSTS value")" +[[ $ADMIN_USERNAME =~ ^[A-Za-z0-9_.@-]+$ ]] || die "$(translate "Invalid administrator user name")" +[[ $ADMIN_EMAIL =~ ^[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}$ ]] \ + || die "$(translate "Invalid administrator email")" +case "$MEDIA_MODE" in + managed-volume) + [[ -n $MEDIA_STORAGE && $MEDIA_SIZE =~ ^[0-9]+$ ]] \ + && (( MEDIA_SIZE >= 2 )) || die "$(translate "Invalid mediafiles volume")" + ;; + host-bind) + [[ $MEDIA_ROOT == /* && $MEDIA_ROOT != *","* && $MEDIA_ROOT != *$'\n'* ]] \ + || die "$(translate "Invalid shared path")" + ;; + *) die "$(translate "Unsupported storage mode:") $MEDIA_MODE" ;; +esac +[[ $PRIVATE_BRIDGE =~ ^vmbr[0-9]+$ ]] || die "$(translate "Invalid private bridge")" +[[ $PRIVATE_SUBNET =~ ^10\.77\.[0-9]{1,3}\.0/24$ ]] || die "$(translate "Invalid private network")" + +vmid_block_free() { + local candidate=$1 offset + for offset in 0 1; do + pct config "$((candidate + offset))" >/dev/null 2>&1 && return 1 + qm config "$((candidate + offset))" >/dev/null 2>&1 && return 1 + done + return 0 +} + +if [[ -z $BASE_VMID ]]; then + BASE_VMID=$(pvesh get /cluster/nextid) + while ! vmid_block_free "$BASE_VMID"; do + BASE_VMID=$((BASE_VMID + 1)) + done +fi +[[ $BASE_VMID =~ ^[0-9]+$ ]] || die "$(translate "Invalid base VMID")" +vmid_block_free "$BASE_VMID" || die "$(translate "These VMIDs are not free:") ${BASE_VMID}-$((BASE_VMID + 1))" + +APPLICATION_ID=$BASE_VMID +DATABASE_ID=$((BASE_VMID + 1)) +oci_log "Stack: $STACK_NAME; VMIDs: Tandoor=$APPLICATION_ID, PostgreSQL=$DATABASE_ID" +oci_log "Private network: $PRIVATE_SUBNET on $PRIVATE_BRIDGE" + +if [[ $DRY_RUN == 1 ]]; then + msg_info2 "$(translate "Stack:") $STACK_NAME · CT ${APPLICATION_ID}-${DATABASE_ID}" + msg_info2 "$(translate "Private network:") $PRIVATE_BRIDGE ($PRIVATE_SUBNET)" + msg_ok "$(translate "Dry run completed; no containers were created.")" + exit 0 +fi + +NODE=$(hostname) +if ! pvesh get "/nodes/${NODE}/network/${PRIVATE_BRIDGE}" >/dev/null 2>&1; then + oci_log "Creating the persistent configuration for $PRIVATE_BRIDGE" + oci_quiet pvesh create "/nodes/${NODE}/network" --iface "$PRIVATE_BRIDGE" --type bridge \ + --autostart 1 --cidr "$PRIVATE_HOST_ADDRESS" + PRIVATE_BRIDGE_CREATED=1 +fi +if ! ip link show "$PRIVATE_BRIDGE" >/dev/null 2>&1; then + oci_log "Activating the private bridge $PRIVATE_BRIDGE" + oci_quiet ip link add name "$PRIVATE_BRIDGE" type bridge + oci_quiet ip address add "$PRIVATE_HOST_ADDRESS" dev "$PRIVATE_BRIDGE" + oci_quiet ip link set "$PRIVATE_BRIDGE" up +fi +ip -4 address show dev "$PRIVATE_BRIDGE" | grep -Fq "${PRIVATE_HOST_ADDRESS%/*}/" \ + || die "$(translate "The private bridge does not have the expected address:") $PRIVATE_BRIDGE ($PRIVATE_HOST_ADDRESS)" +for address in "$APPLICATION_ADDRESS" "$DATABASE_ADDRESS"; do + if grep -RqsF "ip=${address}" /etc/pve/lxc/*.conf 2>/dev/null; then + die "$(translate "The private address is already assigned to another container:") ${address%/*}" + fi +done +flock -u 9 +msg_ok "$(translate "Private network:") $PRIVATE_BRIDGE ($PRIVATE_SUBNET)" + +ARCH=$(dpkg --print-architecture) +case "$ARCH" in amd64|arm64) ;; *) die "$(translate "Unsupported architecture:") $ARCH" ;; esac + +skopeo_transport_reference() { + local reference=$1 name digest + if [[ $reference == *@sha256:* ]]; then + name=${reference%@sha256:*} + digest="sha256:${reference##*@sha256:}" + [[ ${name##*/} == *:* ]] && name=${name%:*} + printf '%s@%s' "$name" "$digest" + else + printf '%s' "$reference" + fi +} + +resolve_image_manifest() { + local label=$1 image=$2 manifest_file error_file pid elapsed=0 status=0 + manifest_file=$(mktemp /tmp/proxmenux-oci-inspect.XXXXXX) + error_file="${manifest_file}.err" + oci_log "Querying the OCI registry for ${label}: ${image}" + skopeo inspect --no-tags --override-os linux --override-arch "$ARCH" \ + "docker://${image}" >"$manifest_file" 2>"$error_file" & + pid=$! + while kill -0 "$pid" 2>/dev/null; do + sleep 2 + elapsed=$((elapsed + 2)) + done + wait "$pid" || status=$? + if (( status != 0 )); then + cat "$error_file" >>"$OCI_LOG" + rm -f "$manifest_file" "$error_file" + return "$status" + fi + oci_log "Manifest for ${label} resolved in ${elapsed}s" + cat "$manifest_file" + rm -f "$manifest_file" "$error_file" +} + +ensure_image() { + local key=$1 image=$2 transport_image inspect digest short archive_name archive_volume archive_path + local partial log pid bytes elapsed status + msg_info "$(translate "Checking the image in the registry...")" + oci_log "Resolving ${key}: ${image}" + transport_image=$(skopeo_transport_reference "$image") + inspect=$(resolve_image_manifest "$key" "$transport_image") \ + || die "$(translate "Could not resolve the OCI manifest:") $image" + digest=$(jq -er '.Digest' <<<"$inspect") + oci_log "Selected digest for ${key}: ${digest}" + short=${digest#sha256:} + short=${short:0:16} + archive_name="image-tandoor-${key}_${ARCH}_${short}.tar" + archive_volume="${TEMPLATE_STORAGE}:vztmpl/${archive_name}" + archive_path=$(pvesm path "$archive_volume") + mkdir -p "$(dirname "$archive_path")" + if [[ -s $archive_path ]]; then + msg_info "$(translate "Verifying the image integrity...")" + fi + if [[ -s $archive_path ]] && oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$archive_path"; then + oci_log "Reusing ${archive_volume}" + else + rm -f "$archive_path" + partial="${archive_path}.partial.$$" + log="${partial}.log" + oci_log "Downloading ${image} by digest ${digest}" + skopeo copy --override-os linux --override-arch "$ARCH" --retry-times 3 \ + --retry-delay 5s --image-parallel-copies 1 \ + "docker://${transport_image}" "oci-archive:${partial}:image-tandoor-${key}" >"$log" 2>&1 & + pid=$! + elapsed=0 + while kill -0 "$pid" 2>/dev/null; do + bytes=$(stat -c %s "$partial" 2>/dev/null || printf 0) + msg_progress "$(translate "Downloading the image:") ${key} · $((bytes / 1048576)) MiB · ${elapsed}s" + sleep 2 + elapsed=$((elapsed + 2)) + done + status=0 + wait "$pid" || status=$? + cat "$log" >>"$OCI_LOG" + rm -f "$log" + (( status == 0 )) || { rm -f "$partial"; die "$(translate "Image download failed:") $image"; } + msg_info "$(translate "Verifying the image integrity...")" + oci_quiet python3 "$VERIFY_OCI_ARCHIVE" "$partial" \ + || { rm -f "$partial"; die "$(translate "The downloaded image is corrupt:") $image"; } + mv -f "$partial" "$archive_path" + fi + msg_ok "$(translate "Image:") $image" + RESOLVED_ARCHIVE=$archive_volume + RESOLVED_DIGEST=$digest +} + +APPLICATION_IMAGE=$(jq -er '.container_contract.image.reference' "$TEMPLATE_FILE") +DATABASE_IMAGE=$(jq -er '.compose_stack.services[] | select(.name == "db_recipes") | .image' "$TEMPLATE_FILE") +ensure_image application "$APPLICATION_IMAGE" +APPLICATION_ARCHIVE=$RESOLVED_ARCHIVE +APPLICATION_DIGEST=$RESOLVED_DIGEST +ensure_image database "$DATABASE_IMAGE" +DATABASE_ARCHIVE=$RESOLVED_ARCHIVE +DATABASE_DIGEST=$RESOLVED_DIGEST + +source "$SCRIPT_DIR/oci_native_stack.sh" +oci_native_begin "$APPLICATION_ID" \ + --member application "$APPLICATION_ID" "$APPLICATION_IMAGE" "$APPLICATION_ARCHIVE" \ + --member database "$DATABASE_ID" "$DATABASE_IMAGE" "$DATABASE_ARCHIVE" + +DB_PASSWORD=$(openssl rand -hex 24) +SECRET_KEY=$(openssl rand -hex 48) +ADMIN_PASSWORD=$(openssl rand -hex 16) +if [[ $MEDIA_MODE == host-bind ]]; then + install -d -m 0775 -o 100000 -g 100000 "$MEDIA_ROOT" + MEDIA_MOUNT="${MEDIA_ROOT},mp=/opt/recipes/mediafiles,backup=0" +else + MEDIA_MOUNT="${MEDIA_STORAGE}:${MEDIA_SIZE},mp=/opt/recipes/mediafiles,backup=1" +fi +TAGS="productivity;oci;proxmenux" + +msg_info "$(translate "Creating the container...")" +oci_quiet pct create "$DATABASE_ID" "$DATABASE_ARCHIVE" --rootfs "${ROOTFS_STORAGE}:4" \ + --mp0 "${DATABASE_STORAGE}:${DATABASE_SIZE},mp=/var/lib/postgresql/data,backup=1" \ + --hostname "${STACK_NAME}-db" --cores 2 --memory 1024 --swap 512 \ + --net0 "name=eth0,bridge=${PRIVATE_BRIDGE},firewall=1,host-managed=1,ip=${DATABASE_ADDRESS},type=veth" \ + --unprivileged 1 --features nesting=1 --cmode console --onboot "$ONBOOT" \ + --startup order=10,up=10,down=30 --tags "$TAGS" \ + --description 'Tandoor PostgreSQL native OCI' +created_ids+=("$DATABASE_ID") + +oci_quiet pct mount "$DATABASE_ID" +DATABASE_ROOT="/var/lib/lxc/${DATABASE_ID}/rootfs" +POSTGRES_UID=$(awk -F: '$1 == "postgres" {print $3}' "$DATABASE_ROOT/etc/passwd") +POSTGRES_GID=$(awk -F: '$1 == "postgres" {print $4}' "$DATABASE_ROOT/etc/passwd") +[[ -n $POSTGRES_UID && -n $POSTGRES_GID ]] || die "$(translate "The postgres user was not found in the image")" +rm -rf "$DATABASE_ROOT/var/lib/postgresql/data/lost+found" +install -d -m 0700 -o "$((100000 + POSTGRES_UID))" -g "$((100000 + POSTGRES_GID))" \ + "$DATABASE_ROOT/var/lib/postgresql/data/pgdata" +cat >"$DATABASE_ROOT/usr/local/bin/tandoor-postgres-lxc-start" <"$LIFECYCLE_SPEC" +LIFECYCLE_CONFIG_PATH="/etc/pve/priv/proxmenux-stack-${APPLICATION_ID}.json" +if ! oci_quiet bash "$STACK_DEPENDENCY_HOOK" --install "$APPLICATION_ID" "$LIFECYCLE_SPEC"; then + rm -f "$LIFECYCLE_SPEC" + die "$(translate "Could not install the stack startup hook")" +fi +rm -f "$LIFECYCLE_SPEC" +msg_ok "$(translate "Stack startup hook installed")" + +wait_command() { + local label=$1 retries=$2 + shift 2 + local attempt + for attempt in $(seq 1 "$retries"); do + "$@" >/dev/null 2>&1 && return 0 + sleep 2 + done + die "$(translate "Health check failed:") $label" +} + +APPLICATION_LAN_IP="" +if (( START_AFTER == 1 )); then + msg_info "$(translate "Starting the service:") PostgreSQL" + oci_quiet pct start "$DATABASE_ID" + wait_command PostgreSQL 60 pct exec "$DATABASE_ID" -- \ + pg_isready -h "$DATABASE_IP" -U djangouser -d djangodb + msg_ok "$(translate "Service ready:") PostgreSQL" + msg_info "$(translate "Starting the service:") Tandoor" + oci_quiet pct start "$APPLICATION_ID" + + msg_info "$(translate "Waiting for the application to respond...")" + for _ in $(seq 1 180); do + APPLICATION_LAN_IP=$(lxc-info -n "$APPLICATION_ID" -iH 2>/dev/null \ + | grep -E '^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$' \ + | grep -vFx "$APPLICATION_IP" | head -n 1 || true) + if [[ -n $APPLICATION_LAN_IP ]] \ + && curl -fsS "http://${APPLICATION_LAN_IP}/" >/dev/null 2>&1; then + break + fi + if [[ $(pct status "$APPLICATION_ID" 2>/dev/null) != *running* ]]; then + print_first_boot_diagnostics "$APPLICATION_ID" tandoor + die "$(translate "The application stopped during its first start:") Tandoor" + fi + sleep 2 + done + if [[ -z $APPLICATION_LAN_IP ]]; then + print_first_boot_diagnostics "$APPLICATION_ID" tandoor + die "$(translate "The application did not get an address on the access network:") Tandoor" + fi + curl -fsS "http://${APPLICATION_LAN_IP}/" >/dev/null 2>>"$OCI_LOG" \ + || { print_first_boot_diagnostics "$APPLICATION_ID" tandoor; \ + die "$(translate "The application did not complete its initial setup:") Tandoor"; } + msg_ok "$(translate "Application responding:") http://${APPLICATION_LAN_IP}/" + msg_info "$(translate "Creating the initial administrator...")" + oci_quiet pct exec "$APPLICATION_ID" -- env DJANGO_SUPERUSER_PASSWORD="$ADMIN_PASSWORD" \ + DJANGO_SUPERUSER_USERNAME="$ADMIN_USERNAME" DJANGO_SUPERUSER_EMAIL="$ADMIN_EMAIL" \ + /bin/sh -c 'cd /opt/recipes && . venv/bin/activate && python manage.py createsuperuser --noinput' \ + || { print_first_boot_diagnostics "$APPLICATION_ID" tandoor; \ + die "$(translate "Could not create the initial administrator")"; } + msg_ok "$(translate "Initial administrator created:") $ADMIN_USERNAME" +fi + +RESULT=$(jq -nc \ + --argjson vmid "$APPLICATION_ID" \ + --arg ip "$APPLICATION_LAN_IP" \ + --argjson application_id "$APPLICATION_ID" \ + --argjson database_id "$DATABASE_ID" \ + --arg application_digest "$APPLICATION_DIGEST" \ + --arg database_digest "$DATABASE_DIGEST" \ + --arg admin_user "$ADMIN_USERNAME" \ + --arg admin_password "$ADMIN_PASSWORD" \ + --arg admin_label "$(translate "Initial Tandoor administrator")" \ + --arg log "$OCI_LOG" \ + '{ + vmid: $vmid, + ip: (if $ip == "" then null else $ip end), + stack_vmids: {tandoor: $application_id, database: $database_id}, + urls: (if $ip == "" then [] else [{label: "Tandoor WebUI", url: ("http://" + $ip + "/")}] end), + credentials: [{ + label: $admin_label, + username: $admin_user, + password: $admin_password, + change_required: true + }], + image_digests: {application: $application_digest, database: $database_digest}, + log: $log + }') +INSTALL_COMPLETE=1 +oci_native_finalize +printf 'PROXMENUX_RESULT=%s\n' "$(printf '%s' "$RESULT" | base64 -w0)" diff --git a/oci/remote/nvidia_lxc_mount_lab.sh b/oci/remote/nvidia_lxc_mount_lab.sh new file mode 100755 index 00000000..91f79d3b --- /dev/null +++ b/oci/remote/nvidia_lxc_mount_lab.sh @@ -0,0 +1,30 @@ +#!/bin/bash +# Experimental native LXC mount hook: PVE devN owns device creation/cgroups. +set -euo pipefail +[[ ${LXC_HOOK_TYPE:-${3:-}} == mount ]] || exit 1 +[[ ${LXC_HOOK_SECTION:-${2:-}} == lxc ]] || exit 1 +[[ ${NVIDIA_VISIBLE_DEVICES:-void} != void && -n ${NVIDIA_VISIBLE_DEVICES:-} ]] || exit 0 +[[ -n ${LXC_ROOTFS_MOUNT:-} && -d $LXC_ROOTFS_MOUNT ]] || exit 1 +# Do not use this hook outside an unprivileged user namespace. +awk '$1 == 0 && $2 == 0 && $3 == 4294967295 {exit 1}' /proc/self/uid_map || exit 1 +# Same process-only transition used by the upstream LXC NVIDIA mount hook. +# Fail closed if it is denied; do not disable host or container AppArmor. +if [[ -d /sys/kernel/security/apparmor ]]; then + printf 'changeprofile unconfined\n' > /proc/self/attr/current +fi +args=(--no-cgroups --no-devbind --ldconfig=@/usr/sbin/ldconfig) +args+=("--device=${NVIDIA_VISIBLE_DEVICES}") +capabilities=${NVIDIA_DRIVER_CAPABILITIES:-utility} +[[ $capabilities != all ]] || capabilities=compute,utility,video,graphics,display,compat32 +while [[ -n $capabilities ]]; do + capability=${capabilities%%,*} + if [[ $capabilities == *,* ]]; then capabilities=${capabilities#*,}; else capabilities=; fi + case "$capability" in + compute|utility|video|graphics|display|compat32) args+=("--${capability}") ;; + *) printf 'Unsupported NVIDIA capability: %s\n' "$capability" >&2; exit 1 ;; + esac +done +for requirement in $(compgen -e NVIDIA_REQUIRE_ || true); do + args+=("--require=${!requirement}") +done +exec nvidia-container-cli --user configure "${args[@]}" "$LXC_ROOTFS_MOUNT" diff --git a/oci/remote/oci_accelerators.py b/oci/remote/oci_accelerators.py new file mode 100644 index 00000000..353356bf --- /dev/null +++ b/oci/remote/oci_accelerators.py @@ -0,0 +1,124 @@ +"""Preservation profiles for native DRM devices and NVIDIA Toolkit runtimes.""" +from __future__ import annotations + +import re +import oci_runtime_settings as runtime_settings +import oci_nvidia_dynamic as dynamic +import oci_gpu_devices as drm +import oci_nvidia_runtime as nvidia +from oci_ui import translate + + +def dynamic_mode(deployment): + return any(d.get('kind') == 'nvidia-runtime' and d.get('runtime_mode') == 'dynamic' + for d in deployment.get('devices', [])) + + +def check_dynamic(config, value, deployment): + hooks = [line.split(': ', 1)[1] for line in config.decode().splitlines() + if line.startswith('lxc.hook.mount: ')] + if len(hooks) != 1: + raise ValueError(translate('The dynamic NVIDIA hook is missing or duplicated')) + match = re.fullmatch(r'/usr/local/lib/proxmenux/oci/nvidia-mount-([a-f0-9]{64})\.sh', hooks[0]) + if not match: + raise ValueError(translate('The NVIDIA hook path does not belong to the installer')) + capabilities = next((e['value'] for e in reversed(deployment.get('environment', [])) + if e['name'] == 'NVIDIA_DRIVER_CAPABILITIES'), 'compute,utility,video') + return dynamic.validate(config, value, value, hooks[0], match[1], capabilities) + + +def verify_baseline(expected, deployment): + if not dynamic_mode(deployment): + verify(expected) + return + drm.verify({p: v for p, v in expected.items() if p != nvidia.KEY}) + if dynamic.gpu_identity(expected[nvidia.KEY]) != dynamic.gpu_identity(nvidia.snapshot()): + raise ValueError(translate('The selected GPU changed')) + + +def drm_plan(deployment): + return dict(deployment, devices=[d for d in deployment.get('devices', []) if d.get('kind') != 'nvidia-runtime']) + + +def planned(deployment): + result = drm.planned(drm_plan(deployment)) + if nvidia.enabled(deployment): + value = nvidia.snapshot() + if set(result) & set(value['devices']): + raise ValueError(translate('Duplicated NVIDIA devices')) + result[nvidia.KEY] = value + return result + + +def verify(expected): + drm.verify({p: v for p, v in expected.items() if p != nvidia.KEY}) + if nvidia.KEY in expected: + nvidia.verify(expected[nvidia.KEY]) + + +def check(config, deployment): + config = runtime_settings.filter_config(config, deployment) + expected = planned(deployment) + value = expected.get(nvidia.KEY) + if value: + nvidia.check_devices(config, value) + if dynamic_mode(deployment): + check_dynamic(config, value, deployment) + else: + nvidia.check_mounts(config, value) + filtered = [] + for line in config.splitlines(keepends=True): + if re.match(rb'dev[0-9]+: ', line): + fields = dict(part.split('=', 1) for part in line.decode().strip().split(': ', 1)[1].split(',')) + if fields.get('path') in value['devices']: + continue + filtered.append(line) + filtered = b''.join(filtered) + drm.check(filtered, drm_plan(deployment)) + else: + if nvidia.mount_lines(config): + raise ValueError(translate('LXC entries outside the selected acceleration profile')) + drm.check(config, deployment) + return expected + + +def capture(config): + result = drm.capture(config) + if any(isinstance(p, str) and p.startswith('/dev/nvidia') for p in drm.actual_devices(config)): + result[nvidia.KEY] = nvidia.snapshot() + return result + + +def verify_observation(expected, observed): + if observed.get('gpu_devices', {}) != expected: + raise ValueError(translate('The acceleration evidence differs from the verified inventory')) + verify(expected) + + +def validate_runtime(vmid, deployment): + if nvidia.enabled(deployment): + value = nvidia.snapshot() + if dynamic_mode(deployment): + rows = nvidia.command('pct', 'exec', str(vmid), '--', 'nvidia-smi', nvidia.QUERY, '--format=csv,noheader') + if sorted(line.strip() for line in rows.splitlines() if line.strip()) != value['gpus']: + raise ValueError(translate('NVML does not match the current host driver')) + else: + nvidia.validate_runtime(vmid, value) + + +def check_recovery_entries(config, state): + runtime_settings.check_recovery(config, state) + for key in ('record', 'candidate_contract'): + config = runtime_settings.filter_config(config, state.get(key, {}).get('deployment', {})) + entries = nvidia.mount_lines(config) + if not entries: + return + values = [state.get(key, {}).get(nvidia.KEY) for key in ('original_gpu_devices', 'desired_gpu_devices')] + for value in values: + if value: + try: + nvidia.check_mounts(config, value, complete=False) + return + except ValueError: + continue + raise ValueError(translate('LXC entries outside the NVIDIA inventory of the journal')) diff --git a/oci/remote/oci_gpu_devices.py b/oci/remote/oci_gpu_devices.py new file mode 100644 index 00000000..2b0d46aa --- /dev/null +++ b/oci/remote/oci_gpu_devices.py @@ -0,0 +1,149 @@ +"""Native Intel/AMD device preservation. NVIDIA library mounts need a separate profile.""" +from __future__ import annotations + +import os +from pathlib import Path +import re +import stat + +from oci_installation_state import parse_config +from oci_ui import translate + + +def gpu_path(path): + return isinstance(path, str) and (re.fullmatch(r'/dev/dri/(renderD|card)[0-9]+', path) is not None or path == '/dev/kfd') + + +def peripheral_path(path): + return isinstance(path, str) and re.fullmatch( + r'/dev/(apex_[0-9]+|ttyUSB[0-9]+|ttyACM[0-9]+|bus/usb/[0-9]{3}/[0-9]{3})', path) is not None + + +def system_path(path): + """Fixed nodes the kernel always presents the same way. They carry no + identity beyond their device numbers, so there is no sysfs to interrogate: + the numbers and the permissions are the whole record.""" + return isinstance(path, str) and re.fullmatch( + r'/dev/(kvm|fuse|net/tun|video[0-9]+|sg[0-9]+)', path) is not None + + +def block_path(path): + return isinstance(path, str) and re.fullmatch(r'/dev/sr[0-9]+', path) is not None + + +def known_path(path): + return gpu_path(path) or peripheral_path(path) or system_path(path) or block_path(path) + + +def snapshot(path): + if not known_path(path): + raise ValueError(translate('Device node outside the supported profiles')) + info = Path(path).stat() + if block_path(path): + if not stat.S_ISBLK(info.st_mode): + raise ValueError(translate('The selected device is not a block device')) + elif not stat.S_ISCHR(info.st_mode): + raise ValueError(translate('The selected device is not a character device')) + value = {'path': str(Path(path).resolve()), 'major': os.major(info.st_rdev), + 'minor': os.minor(info.st_rdev), 'uid': info.st_uid, 'gid': info.st_gid, + 'mode': stat.S_IMODE(info.st_mode)} + if peripheral_path(path): + sysfs = Path('/sys/dev/char') / f'{value["major"]}:{value["minor"]}' + value['sysfs_path'] = str(sysfs.resolve(strict=True)) + if '/bus/usb/' in path: + for name in ('idVendor', 'idProduct', 'serial'): + field = sysfs / name + if field.is_file(): + value[name] = field.read_text().strip() + elif gpu_path(path) and path != '/dev/kfd': + sysfs = Path('/sys/class/drm') / Path(path).name / 'device' + value.update(vendor=(sysfs / 'vendor').read_text().strip(), pci_path=str(sysfs.resolve())) + if value['vendor'] not in ('0x1002', '0x8086'): + raise ValueError(translate('The DRM node is not an Intel or AMD GPU; NVIDIA requires its library profile')) + return value + + +def planned(deployment): + result = {} + for device in deployment.get('devices', []): + path = device.get('host_path') + kind = device.get('kind', 'character-device') + if kind == 'block-device': + allowed = block_path(path) + elif kind == 'character-device': + allowed = gpu_path(path) or peripheral_path(path) or system_path(path) + else: + allowed = False + if not allowed: + raise ValueError(translate('Device outside the supported profiles; NVIDIA and device trees require another profile')) + if device.get('container_path') != path or path in result: + raise ValueError(translate('The device must keep its native path without duplicates')) + value = snapshot(path) + vendors = device.get('drm_vendor_ids') + if vendors and value.get('vendor') not in vendors: + raise ValueError(translate('The GPU vendor differs from the requested profile')) + mode = device.get('mode', '0660') + if mode != 'preserve-host' and (not isinstance(mode, str) or not re.fullmatch(r'0?[0-7]{3}', mode)): + raise ValueError(translate('Invalid device mode')) + if device.get('gid_strategy') not in ('none', 'host-device-gid'): + raise ValueError(translate('Unsupported device GID strategy')) + result[path] = value + return result + + +def verify(expected): + for path, value in expected.items(): + if snapshot(path) != value: + raise ValueError(translate('The GPU identity or permissions changed; the container is not modified')) + + +def actual_devices(config): + result = {} + for key, value in parse_config(config).items(): + if re.fullmatch(r'dev[0-9]+', key): + fields = dict(part.split('=', 1) for part in value.split(',')) + path = fields.get('path') + if path in result: + raise ValueError(translate('Duplicated GPU device in the container')) + result[path] = fields + return result + + +def check(config, deployment): + expected = planned(deployment) + actual = actual_devices(config) + if actual.keys() != expected.keys(): + raise ValueError(translate('The container devices do not match the saved record')) + for device in deployment.get('devices', []): + path = device['host_path'] + fields = actual[path] + value = expected[path] + requested_mode = device.get('mode', '0660') + mode = value['mode'] if requested_mode == 'preserve-host' else int(requested_mode, 8) + gid = value['gid'] if device['gid_strategy'] == 'host-device-gid' else 0 + if (set(fields) - {'path', 'mode', 'gid', 'uid', 'deny-write'} + or int(fields.get('mode', '0660'), 8) != mode + or int(fields.get('gid', 0)) != gid + or int(fields.get('uid', 0)) != int(device.get('uid', 0)) + or fields.get('deny-write', '0') != ('1' if device.get('deny_write') else '0')): + raise ValueError(translate('The native GPU permissions were not kept')) + return expected + + +def verify_observation(expected, observed): + if observed.get('gpu_devices', {}) != expected: + raise ValueError(translate('The GPU evidence does not match the verified devices')) + verify(expected) + + +def capture(config): + result = {} + for path in actual_devices(config): + if not known_path(path): + continue + if gpu_path(path) and path != '/dev/kfd': + vendor = (Path('/sys/class/drm') / Path(path).name / 'device/vendor').read_text().strip() + if vendor not in ('0x1002', '0x8086'): + continue + result[path] = snapshot(path) + return result diff --git a/oci/remote/oci_host_mounts.py b/oci/remote/oci_host_mounts.py new file mode 100644 index 00000000..925f2812 --- /dev/null +++ b/oci/remote/oci_host_mounts.py @@ -0,0 +1,74 @@ +"""Read-only identity checks for directory bind mounts; never manage their data.""" +from __future__ import annotations + +from pathlib import Path, PurePosixPath +import re +import stat + +from oci_installation_state import parse_config +from oci_ui import translate + + +def valid_path(value): + if (not isinstance(value, str) or not value.startswith('/') or value == '/' + or any(c.isspace() or ord(c) < 32 or c == ',' for c in value) + or any(p in ('.', '..') for p in value.split('/')) + or str(PurePosixPath(value)) != value or value.startswith('//')): + raise ValueError(translate('Invalid absolute mount path')) + return value + + +def snapshot(source, allow_missing=False): + path = Path(source) + resolved = str(path.resolve()) + try: + info = path.stat() + except FileNotFoundError: + if not allow_missing or path.is_symlink(): + raise ValueError(f"{translate('The container is not modified because a host directory is not available:')} {source}") + return {'resolved_path': resolved, 'exists': False} + if not stat.S_ISDIR(info.st_mode): + raise ValueError(translate('This profile only supports directory bind mounts')) + return {'resolved_path': resolved, 'exists': True, 'device': info.st_dev, + 'inode': info.st_ino, 'uid': info.st_uid, 'gid': info.st_gid, + 'mode': stat.S_IMODE(info.st_mode)} + + +def validate_source(source, allow_missing=False): + valid_path(source) + value = snapshot(source, allow_missing) + protected = ('/etc', '/usr', '/bin', '/sbin', '/lib', '/lib64', '/dev', '/proc', '/sys', '/run') + protected += tuple(str(Path(p).resolve()) for p in protected) + resolved = value['resolved_path'] + if resolved == '/' or any(resolved == p or resolved.startswith(p + '/') for p in protected): + raise ValueError(translate('The shared directory points to a protected host path')) + return value + + +def same_source(a, b): + # Native application init may legitimately change permissions, not identity. + return all(a.get(k) == b.get(k) for k in ('resolved_path', 'exists', 'device', 'inode')) + + +def verify_sources(expected): + for source, previous in expected.items(): + current = validate_source(source, allow_missing=not previous['exists']) + if not same_source(previous, current): + raise ValueError(f"{translate('The operation was stopped because a shared directory changed its identity:')} {source}") + + +def verify_observation(expected, observed): + actual = observed.get('host_bind_sources', {}) + if actual.keys() != expected.keys() or any(not same_source(value, actual[source]) + for source, value in expected.items()): + raise ValueError(translate('The mount evidence does not match the verified directories')) + + +def capture_sources(config): + result = {} + for key, value in parse_config(config).items(): + if re.fullmatch(r'mp[0-9]+', key): + source = value.split(',', 1)[0] + if source.startswith('/'): + result[source] = snapshot(source) + return result diff --git a/oci/remote/oci_image_cache.py b/oci/remote/oci_image_cache.py new file mode 100644 index 00000000..34de491d --- /dev/null +++ b/oci/remote/oci_image_cache.py @@ -0,0 +1,107 @@ +#!/usr/bin/env python3 +"""Image archives that ProxMenux downloaded to the template storage and that +no installation uses any more are removed after a successful operation.""" +from __future__ import annotations + +import json +from pathlib import Path +import re +import sys +import time + +import oci_instances as instances + +# Names given by the OCI installers and by updates; other archives are never touched. +NAME = re.compile(r'(?:proxmenux-update-[a-z0-9]+-[0-9a-f]{64}' + r'|(?:image|linuxserver)-[A-Za-z0-9._-]+_[a-z0-9]+_[0-9a-f]{16})\.tar') +IN_PROGRESS = {'installing', 'assembling', 'updating', 'recovering'} +# A recent archive may belong to an installation that has not saved its record yet. +MIN_AGE_SECONDS = 3600 + + +def unused_archives(root=instances.ROOT): + """Archives no installed guest uses; empty while any operation is pending + or a record cannot be read.""" + keep, folders = set(), set() + for path in Path(root).glob('*/oci-compose.json'): + try: + record = json.loads(path.read_text()) + vmid = int(record['vmid']) + except (OSError, ValueError, KeyError, TypeError): + return [] + exists = instances.guest_exists(vmid) + if (record.get('pending_transaction') or record.get('pending_stack_transaction') + or (exists and record.get('status') in IN_PROGRESS)): + return [] + archive = (record.get('observed') or {}).get('archive_path') + if not archive: + continue + folders.add(Path(archive).parent) + if exists: + keep.add(Path(archive)) + now = time.time() + result = [] + for folder in folders: + for candidate in folder.glob('*.tar'): + if candidate in keep or not NAME.fullmatch(candidate.name) or candidate.is_symlink(): + continue + info = candidate.stat() + if candidate.is_file() and now - info.st_mtime >= MIN_AGE_SECONDS: + result.append((candidate, info.st_size)) + return result + + +def prune(root=instances.ROOT, lock=True): + """Removes the unused archives and returns them as (path, size). Callers + that already hold the registry lock pass lock=False.""" + if lock: + with instances.locked(root): + return prune(root, lock=False) + removed = [] + for candidate, size in unused_archives(root): + try: + candidate.unlink() + except OSError: + continue + removed.append((candidate, size)) + return removed + + +def archives_of(vmids, root=instances.ROOT): + """The downloaded archives the given installations were created from.""" + result = {} + for vmid in vmids: + archive = (instances.read(root, vmid).get('observed') or {}).get('archive_path') + path = Path(archive) if archive else None + if path and NAME.fullmatch(path.name) and path.is_file() and not path.is_symlink(): + result[path] = path.stat().st_size + return result + + +def main(arguments): + command = arguments[0] if arguments else 'prune' + if command == 'prune': + for path, size in prune(): + print(f'removed unused image archive: {path} ({size} bytes)') + return 0 + if command not in ('list', 'remove') or not all(a.isdigit() for a in arguments[1:]): + print('usage: oci_image_cache.py [prune | list VMID... | remove VMID...]', file=sys.stderr) + return 2 + with instances.locked(instances.ROOT): + archives = archives_of([int(a) for a in arguments[1:]]) + freed = 0 + if command == 'remove': + for path, size in archives.items(): + path.unlink() + freed += size + print(json.dumps({'archives': [{'path': str(p), 'size': s} for p, s in archives.items()], + 'freed': freed})) + return 0 + + +if __name__ == '__main__': + try: + sys.exit(main(sys.argv[1:])) + except (OSError, ValueError, BlockingIOError) as error: + print(f'image cache: {error}', file=sys.stderr) + sys.exit(1) diff --git a/oci/remote/oci_immich_ml.sh b/oci/remote/oci_immich_ml.sh new file mode 100755 index 00000000..20b48ca8 --- /dev/null +++ b/oci/remote/oci_immich_ml.sh @@ -0,0 +1,112 @@ +# Immich ML prerequisites and native GPU setup; no host driver installation. +validate_immich_ml_profile() { + ML_CPU_ARGS=(--cores 2) + ML_MEMORY=2048 + case "$ML_ACCELERATION" in + cpu) ;; + openvino) + ML_RENDER_DEVICE=$(jq -er '.machine_learning.render_device' "$DEPLOYMENT_FILE") + [[ $ML_RENDER_DEVICE =~ ^/dev/dri/renderD[0-9]+$ && -c $ML_RENDER_DEVICE ]] \ + || die "$(translate "The selected Intel render device does not exist:") $ML_RENDER_DEVICE" + [[ $(cat "/sys/class/drm/${ML_RENDER_DEVICE##*/}/device/vendor") == 0x8086 ]] \ + || die "$(translate "OpenVINO requires the render device of an Intel GPU")" + ML_CPU_ARGS=(--cpulimit 4) + ML_MEMORY=8192 + ;; + cuda) + command -v nvidia-container-cli >/dev/null 2>&1 \ + || die "$(translate "CUDA requires the NVIDIA Container Toolkit on the host")" + command -v nvidia-smi >/dev/null 2>&1 \ + || die "$(translate "CUDA requires a working NVIDIA driver")" + local inventory version capability + inventory=$(nvidia-smi --query-gpu=driver_version,compute_cap --format=csv,noheader) \ + || die "$(translate "Could not check the NVIDIA GPU")" + [[ -n $inventory ]] || die "$(translate "No NVIDIA GPU is available")" + while IFS=, read -r version capability; do + [[ $version =~ ^[0-9]+\.[0-9]+(\.[0-9]+)?$ ]] \ + || die "$(translate "Could not read the NVIDIA driver version")" + (( ${version%%.*} >= 545 )) || die "$(translate "Immich CUDA requires NVIDIA driver 545 or later")" + capability=${capability//[[:space:]]/} + [[ $capability =~ ^[0-9]+\.[0-9]+$ ]] \ + || die "$(translate "Could not read the CUDA compute capability")" + awk -v value="$capability" 'BEGIN {exit !(value >= 5.2)}' \ + || die "$(translate "Immich requires CUDA compute capability 5.2 or later")" + done <<<"$inventory" + [[ -r $SCRIPT_DIR/nvidia_lxc_mount_lab.sh ]] || die "$(translate "The dynamic NVIDIA hook is missing")" + ML_CPU_ARGS=(--cores 4) + ML_MEMORY=8192 + ;; + *) die "$(translate "Machine learning profile not implemented; it is not replaced by CPU:") $ML_ACCELERATION" ;; + esac + local cores allocation default_allocation + default_allocation=cpuset + [[ $ML_ACCELERATION != openvino ]] || default_allocation=quota + cores=$(jq -er --argjson fallback "${ML_CPU_ARGS[1]}" '.machine_learning.resources.cores // $fallback' "$DEPLOYMENT_FILE") + ML_MEMORY=$(jq -er --argjson fallback "$ML_MEMORY" '.machine_learning.resources.memory_mb // $fallback' "$DEPLOYMENT_FILE") + ML_SWAP=$(jq -er '.machine_learning.resources.swap_mb // 1024' "$DEPLOYMENT_FILE") + allocation=$(jq -er --arg fallback "$default_allocation" '.machine_learning.resources.cpu_allocation // $fallback' "$DEPLOYMENT_FILE") + [[ $cores =~ ^[1-9][0-9]*$ && $ML_MEMORY =~ ^[1-9][0-9]*$ && $ML_SWAP =~ ^(0|[1-9][0-9]*)$ ]] \ + || die "$(translate "Invalid machine learning resources")" + case "$allocation" in + quota) ML_CPU_ARGS=(--cpulimit "$cores") ;; + cpuset) + [[ $ML_ACCELERATION != openvino ]] || die "$(translate "OpenVINO requires a CPU quota to keep the CPU topology")" + ML_CPU_ARGS=(--cores "$cores") + ;; + *) die "$(translate "Invalid machine learning CPU allocation:") $allocation" ;; + esac +} + +configure_immich_ml_gpu() { + case "$ML_ACCELERATION" in + openvino) + oci_quiet pct set "$ML_ID" --dev0 "path=${ML_RENDER_DEVICE},gid=$(stat -c %g "$ML_RENDER_DEVICE"),mode=0660" + ;; + cuda) + # Isolate the shared standalone installer's runtime context from the stack. + ( + VMID=$ML_ID + CONF="/etc/pve/lxc/${ML_ID}.conf" + UNPRIVILEGED_FLAG=1 + DEVICE='{"kind":"nvidia-runtime","runtime_mode":"dynamic"}' + NVIDIA_GID_ENV="" + DEVICE_INDEX=0 + fragment=$(mktemp) + trap 'rm -f "$fragment"' EXIT + printf '%s\n' '{"environment":[{"name":"NVIDIA_DRIVER_CAPABILITIES","value":"compute,utility"}]}' >"$fragment" + DEPLOYMENT_FILE=$fragment + add_character_device() { + local path=$1 mode gid + [[ -c $path && $path == /dev/nvidia* ]] || die "$(translate "Invalid NVIDIA device:") $path" + mode="0$(stat -c %a "$path")" + gid=$(stat -c %g "$path") + oci_quiet pct set "$VMID" "--dev${DEVICE_INDEX}" "path=${path},mode=${mode},gid=${gid},deny-write=0" + DEVICE_INDEX=$((DEVICE_INDEX + 1)) + } + configure_nvidia_runtime + ) + ;; + esac +} + +validate_immich_ml_runtime() { + [[ $ML_ACCELERATION != cpu ]] || return 0 + msg_info "$(translate "Checking the GPU of the machine learning container...")" + oci_quiet pct exec "$ML_ID" -- python -c ' +import ctypes +import sys +import onnxruntime as ort +profile = sys.argv[1] +if profile == "openvino": + assert "OpenVINOExecutionProvider" in ort.get_available_providers() + devices = ort.capi._pybind_state.get_available_openvino_device_ids() + assert any(device.startswith("GPU") for device in devices), devices +else: + assert profile == "cuda" + assert "CUDAExecutionProvider" in ort.get_available_providers() + driver = ctypes.CDLL("libcuda.so.1") + assert driver.cuInit(0) == 0, "CUDA driver initialization failed" +print("Immich ML GPU runtime:", profile, "available; model inference is tested separately") +' "$ML_ACCELERATION" || return + msg_ok "$(translate "GPU available for machine learning:") $ML_ACCELERATION" +} diff --git a/oci/remote/oci_installation_state.py b/oci/remote/oci_installation_state.py new file mode 100644 index 00000000..0a047b60 --- /dev/null +++ b/oci/remote/oci_installation_state.py @@ -0,0 +1,244 @@ +#!/usr/bin/env python3 +"""Private installation evidence and read-only update diagnostics. No updater.""" +from __future__ import annotations + +import argparse +import contextlib +import datetime +import fcntl +import hashlib +import json +import os +from pathlib import Path +import re +import subprocess +import sys +import tarfile +import tempfile +import uuid + +from oci_ui import translate, msg_error, msg_ok + +ROOT = Path('/var/lib/proxmenux/oci-installations') +FIELDS = ('Entrypoint', 'Cmd', 'Env', 'User', 'WorkingDir', 'StopSignal', 'Volumes', 'ExposedPorts', 'Healthcheck') + + +def command(*args): + result = subprocess.run(args, capture_output=True, timeout=120) + if result.returncode: + # Tool errors may contain credentials or environment values. + raise RuntimeError(f"{args[0]} {translate('failed with exit code')} {result.returncode}") + return result.stdout + + +def sha(data): + return hashlib.sha256(data).hexdigest() + + +def image_from_archive(path): + with tarfile.open(path) as archive: + members = {m.name.removeprefix('./'): m for m in archive.getmembers() if m.isfile()} + + def read(name, digest=None): + member = members[name] + if member.size > 16 * 1024 * 1024: + raise ValueError(translate('OCI metadata too large')) + data = archive.extractfile(member).read() + if digest and 'sha256:' + sha(data) != digest: + raise ValueError(translate('OCI metadata integrity mismatch')) + return json.loads(data) + + def blob(digest): + if not re.fullmatch(r'sha256:[0-9a-f]{64}', digest): + raise ValueError(translate('Invalid OCI digest')) + return read('blobs/sha256/' + digest[7:], digest) + + descriptors = read('index.json')['manifests'] + if len(descriptors) != 1: + raise ValueError(translate('A single-platform OCI archive is required')) + digest = descriptors[0]['digest'] + manifest = blob(digest) + config = blob(manifest['config']['digest']) + return {'manifest_digest': digest, 'config_digest': manifest['config']['digest'], + 'architecture': config['architecture'], 'os': config.get('os'), + 'defaults': {k: config.get('config', {}).get(k) for k in FIELDS}} + + +def parse_config(data): + values = {} + for line in data.decode().splitlines(): + if line and not line.startswith('#') and ': ' in line: + key, value = line.split(': ', 1) + values[key] = value + return values + + +def private_directory(path): + path.mkdir(parents=True, exist_ok=True, mode=0o700) + if path.is_symlink() or path.stat().st_uid != os.geteuid(): + raise ValueError(translate('Unsafe registry directory')) + path.chmod(0o700) + + +def save_record(root, record): + private_directory(root) + with (root / '.lock').open('a') as lock: + os.chmod(root / '.lock', 0o600) + fcntl.flock(lock, fcntl.LOCK_EX) + path = root / f"{record['vmid']}.json" + if path.exists() or path.is_symlink(): + if path.is_symlink(): + raise ValueError(translate('Unsafe record')) + history = root / 'history' + private_directory(history) + # Keep the current record present until its replacement is durable. + os.link(path, history / f"{record['vmid']}-{uuid.uuid4().hex}.json") + fd, temporary = tempfile.mkstemp(dir=root, prefix='.record-') + try: + with os.fdopen(fd, 'w') as out: + json.dump(record, out, indent=2, ensure_ascii=True) + out.write('\n') + out.flush() + os.fsync(out.fileno()) + os.replace(temporary, path) + directory_fd = os.open(root, os.O_RDONLY) + try: + os.fsync(directory_fd) + finally: + os.close(directory_fd) + finally: + if os.path.exists(temporary): + os.unlink(temporary) + + +def record_install(args): + template = json.loads(Path(args.template).read_text()) + deployment = json.loads(Path(args.deployment).read_text()) + config = command('pct', 'config', str(args.vmid)) + image = image_from_archive(args.archive) + record = {'schema_version': 1, 'installation_id': str(uuid.uuid4()), 'vmid': args.vmid, + 'recorded_at': datetime.datetime.now(datetime.timezone.utc).isoformat(), + 'provenance': 'installer-completed', 'image': image, + 'reference': template['container_contract']['image']['reference'], + 'resolved_registry_digest': args.digest, 'archive_path': args.archive, + 'template': template, 'deployment': deployment, + 'config_sha256': sha(config), 'config': config.decode(), + 'start_after_create_requested': bool(deployment.get('start_after_create')), + 'automatic_update_enabled': False} + save_record(args.state_dir, record) + + +def resolve_candidate(reference, architecture): + repo = reference.split('@', 1)[0] + if ':' in repo.rsplit('/', 1)[-1]: + repo = repo.rsplit(':', 1)[0] + transport = reference + if '@' in reference: + transport = repo + '@' + reference.split('@', 1)[1] + raw = command('skopeo', 'inspect', '--raw', 'docker://' + transport) + manifest = json.loads(raw) + if 'manifests' in manifest: + matches = [m for m in manifest['manifests'] if m.get('platform', {}).get('architecture') == architecture + and m.get('platform', {}).get('os') == 'linux'] + if len(matches) != 1: + raise ValueError(translate('A single matching image platform cannot be resolved')) + digest = matches[0]['digest'] + raw = command('skopeo', 'inspect', '--raw', 'docker://' + repo + '@' + digest) + if 'sha256:' + sha(raw) != digest: + raise ValueError(translate('The manifest does not match its digest')) + digest = 'sha256:' + sha(raw) + config = json.loads(command('skopeo', 'inspect', '--config', 'docker://' + repo + '@' + digest)) + if config.get('architecture') != architecture or config.get('os') != 'linux': + raise ValueError(translate('Incompatible image platform')) + labels = config.get('config', {}).get('Labels') or {} + return {'manifest_digest': digest, 'defaults': {k: config.get('config', {}).get(k) for k in FIELDS}, + 'version': labels.get('org.opencontainers.image.version') or labels.get('build_version')} + + +def compare(record, current, candidate=None): + blockers = [] + cfg = parse_config(current) + if sha(current) != record['config_sha256']: + blockers.append('configuration-drift-or-vmid-reused') + mounts = [] + for key, value in cfg.items(): + if not re.fullmatch(r'mp\d+', key): + continue + parts = value.split(',') + source = parts[0].removeprefix('volume=') + options = dict(p.split('=', 1) for p in parts[1:] if '=' in p) + managed = not source.startswith('/') and ':' in source + mounts.append(options.get('mp')) + if not managed or options.get('backup') != '1': + blockers.append('persistent-mount-needs-backup:' + key) + declared = set(record['image']['defaults'].get('Volumes') or {}) + declared.update(v['container_path'] for v in record['template'].get('container_contract', {}).get('volumes', []) if v.get('container_path')) + for path in sorted(declared): + if path not in mounts: + blockers.append('image-volume-not-externalized:' + path) + deployment = record['deployment'] + if deployment.get('stack_managed'): + blockers.append('stack-member-requires-coordination') + if deployment.get('deployment_kind') not in (None, 'single-lxc'): + blockers.append('stack-or-special-deployment-requires-coordination') + if cfg.get('hookscript'): + blockers.append('hookscript-requires-coordination') + if record['template'].get('installer_profile', {}).get('post_start_configurations') or deployment.get('post_start_configurations'): + blockers.append('rootfs-adaptations-require-replay') + report = {'vmid': record['vmid'], 'registered': True, 'update_available': None, + 'automatic_update_enabled': False, 'blockers': blockers, + 'requires': ['consistent-backup', 'review-rootfs-only-data', 'transactional-updater-not-implemented']} + if candidate: + report['update_available'] = candidate['manifest_digest'] != record['image']['manifest_digest'] + report['changed_image_fields'] = [key for key in FIELDS if record['image']['defaults'].get(key) != candidate['defaults'].get(key)] + old_env = dict(v.split('=', 1) for v in record['image']['defaults'].get('Env') or [] if '=' in v) + new_env = dict(v.split('=', 1) for v in candidate['defaults'].get('Env') or [] if '=' in v) + report['changed_environment_names'] = sorted(k for k in old_env.keys() | new_env.keys() if old_env.get(k) != new_env.get(k)) + report['candidate_digest'] = candidate['manifest_digest'] + return report + + +def main(argv=None): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('--state-dir', type=Path, default=ROOT) + sub = parser.add_subparsers(dest='action', required=True) + sub.add_parser('inventory') + diagnose = sub.add_parser('diagnose') + diagnose.add_argument('vmid', type=int) + diagnose.add_argument('--check-registry', action='store_true') + record = sub.add_parser('record', help='Internal installer operation; not legacy adoption') + record.add_argument('vmid', type=int) + for flag in ('template', 'deployment', 'archive', 'digest'): + record.add_argument('--' + flag, required=True) + args = parser.parse_args(argv) + if os.geteuid() != 0: + parser.error(translate('Run as root on the Proxmox node; the registry contains private data')) + try: + if args.action == 'record': + record_install(args) + msg_ok(translate('Private installation record saved')) + elif args.action == 'inventory': + rows = command('pct', 'list').decode().splitlines()[1:] + print(json.dumps([{'vmid': int(row.split()[0]), 'registered': (args.state_dir / (row.split()[0] + '.json')).is_file()} + for row in rows if row.strip()], indent=2)) + else: + path = args.state_dir / f'{args.vmid}.json' + if not path.exists(): + print(json.dumps({'vmid': args.vmid, 'registered': False, 'automatic_update_enabled': False, + 'blockers': ['unregistered-installation-no-automatic-adoption']})) + return 0 + record = json.loads(path.read_text()) + if record.get('schema_version') != 1 or record.get('vmid') != args.vmid: + raise ValueError(translate('Incompatible record')) + current = command('pct', 'config', str(args.vmid)) + candidate = resolve_candidate(record['reference'], record['image']['architecture']) if args.check_registry else None + print(json.dumps(compare(record, current, candidate), indent=2)) + return 0 + except (OSError, ValueError, KeyError, RuntimeError, subprocess.TimeoutExpired, tarfile.TarError): + with contextlib.redirect_stdout(sys.stderr): + msg_error(translate('The record or diagnosis could not be completed; no update was run.')) + return 1 + + +if __name__ == '__main__': + raise SystemExit(main()) diff --git a/oci/remote/oci_instance_transaction.py b/oci/remote/oci_instance_transaction.py new file mode 100644 index 00000000..1a413a4b --- /dev/null +++ b/oci/remote/oci_instance_transaction.py @@ -0,0 +1,1239 @@ +#!/usr/bin/env python3 +"""Recoverable, explicit OCI operations using saved instance contracts. + +First execution profile: local, unprivileged standalone CTs with backed-up +managed mounts and explicitly acknowledged host directories. No automatic +adoption, stack updates or storage migration. +""" +from __future__ import annotations + +import argparse +import contextlib +import copy +import hashlib +import io +import json +import os +from pathlib import Path +import re +import shlex +import shutil +import socket +import subprocess +import stat +import sys +import time +import uuid + +import oci_instances as instances +from oci_installation_state import image_from_archive, parse_config, private_directory, sha +from verify_oci_archive import verify_archive +import oci_host_mounts as host_mounts +import oci_accelerators as gpu_devices +import oci_runtime_settings as runtime_settings +import oci_image_cache as image_cache +import oci_ui +from oci_ui import translate, msg_info, msg_ok, msg_warn, msg_error, msg_info2 + +TERMINAL = {'committed', 'rolled-back'} +BASIC = {'arch', 'cmode', 'console', 'tty', 'cores', 'cpulimit', 'cpuunits', 'description', + 'entrypoint', 'env', 'features', 'hostname', 'memory', 'net0', 'onboot', + 'ostype', 'rootfs', 'swap', 'tags', 'unprivileged', + 'lxc.init.cwd', 'lxc.init.uid', 'lxc.init.gid', 'lxc.init.groups', + 'lxc.signal.halt', 'lxc.environment.runtime'} +# Their output is data (and may hold saved secrets); it is never logged. +DATA_COMMANDS = {('pct', 'config'), ('pvesh', 'get')} +LOG_DIR = Path(os.environ.get('OCI_LOG_DIR', '/var/log/proxmenux/oci')) +ANSI = re.compile(r'\x1b\[[0-9;?]*[A-Za-z]') +SPINNER_FRAME = re.compile('^ ?[' + ''.join(oci_ui.FRAMES) + ']') +# The private log of this run, the journal that a failure leaves pending and, +# when the shared installer is what failed, its log and last lines. +_run = {'log': None, 'pending': [], 'journal': None, 'failed_log': None, 'failed_lines': None} + + +def screen_text(line): + """What a terminal shows for one output line, without colours.""" + parts = [SPINNER_FRAME.sub('', ANSI.sub('', part)).rstrip() for part in line.split('\r')] + parts = [part for part in parts if part.strip()] + return parts[-1] if parts else '' + + +def log(text): + """Private log of the operation; kept in memory until its directory exists.""" + if _run['log']: + try: + oci_ui.log(_run['log'], text) + except OSError: + pass + else: + _run['pending'].append(text) + del _run['pending'][:-2000] + + +def log_output(stdout=None, stderr=None, limit=40): + for content in (stdout, stderr): + if not content: + continue + if isinstance(content, bytes): + content = content.decode(errors='replace') + lines = [text for text in (screen_text(line) for line in content.split('\n')) if text] + if len(lines) > limit: + log(f' ... {len(lines) - limit} earlier lines omitted') + lines = lines[-limit:] + for text in lines: + log(' ' + text[:500]) + + +def _start_log(path): + fd = os.open(path, os.O_WRONLY | os.O_CREAT | os.O_APPEND | os.O_NOFOLLOW, 0o600) + with os.fdopen(fd, 'a', encoding='utf-8') as output: + output.write(f"=== {time.strftime('%Y-%m-%d %H:%M:%S')} " + f"{Path(sys.argv[0]).name} {' '.join(sys.argv[1:])}\n") + for line in _run['pending']: + output.write(line.rstrip('\n') + '\n') + _run.update(log=path, pending=[]) + # Helpers that follow the OCI_LOG convention (image verification) write here too. + os.environ['OCI_LOG'] = str(path) + + +def open_log(directory): + """transaction.log in the private directory of the operation.""" + if not _run['log']: + try: + _start_log(Path(directory) / 'transaction.log') + except OSError: + pass + return _run['log'] + + +def log_file(name): + """The log of this run; a run that stopped before its transaction + directory existed gets one in the OCI log directory.""" + if _run['log'] or not _run['pending']: + return _run['log'] + safe = re.sub(r'[^A-Za-z0-9._-]', '_', name) + try: + LOG_DIR.mkdir(parents=True, exist_ok=True, mode=0o700) + _start_log(LOG_DIR / f"{safe}-{time.strftime('%Y%m%d-%H%M%S')}.log") + except OSError: + return None + return _run['log'] + + +def log_tail(path, count=12): + with open(path, 'rb') as source: + source.seek(0, os.SEEK_END) + source.seek(max(0, source.tell() - 65536)) + data = source.read().decode(errors='replace') + lines = [screen_text(line) for line in data.split('\n')] + return [line for line in lines if line and not line.startswith('PROXMENUX_RESULT=')][-count:] + + +def command_name(cmd): + if isinstance(cmd, (list, tuple)) and cmd: + cmd = cmd[0] + return Path(str(cmd)).name + + +def error_text(error): + if isinstance(error, KeyError): + return translate('The saved OCI record is incomplete or has an unexpected format.') + if isinstance(error, subprocess.TimeoutExpired): + return f"{translate('A command did not finish in time:')} {command_name(error.cmd)}" + if isinstance(error, subprocess.CalledProcessError): + return f"{command_name(error.cmd)} {translate('failed with exit code')} {error.returncode}" + if isinstance(error, OSError): + detail = error.strerror or str(error) + return f"{translate('System error:')} {detail}" + (f' ({error.filename})' if error.filename else '') + return str(error) or type(error).__name__ + + +def installer_failure(path, count=10): + """The error reported by the shared installer and the log lines before it.""" + try: + lines = [screen_text(line).strip() for line in log_tail(path, 400)] + except OSError: + return None, [] + lines = [line for line in lines if line] + errors = [i for i, line in enumerate(lines) if line.startswith('[ERROR] ')] + if not errors: + return None, lines[-count:] + index = errors[-1] + # The installer repeats its own log tail after the error; the lines before it suffice. + first = next((i for i in errors if lines[i] == lines[index]), index) + return lines[index][len('[ERROR] '):], lines[max(0, first - count):first] + + +def report_error(error, name='oci-lifecycle'): + """Error line, the last lines of the private log and its path.""" + msg_error(error_text(error)) + path, lines = _run['failed_log'], _run['failed_lines'] + _run.update(failed_log=None, failed_lines=None) + if path is None: + path = log_file(name) + try: + lines = log_tail(path) if path else [] + except OSError: + lines = [] + for line in lines or []: + print(f'{oci_ui.TAB} {line}', flush=True) + if path: + print(f"{oci_ui.TAB}{translate('Full log:')} {path}", flush=True) + log(f'error: {type(error).__name__}: {error}') + + +def pending_journal(): + """The journal of this run when a failure left it open for recovery.""" + journal = _run['journal'] + if journal is None: + return None + try: + phase = json.loads(Path(journal).read_text()).get('phase') + except (OSError, ValueError): + return journal + return None if phase in TERMINAL else journal + + +def recovery_hint(after_recovery=False): + if after_recovery: + msg_warn(translate('The recovery did not complete. Review the log and choose "Recover" again for this container in the OCI management menu.')) + else: + msg_warn(translate('The operation stopped halfway. Choose "Recover" for this container in the OCI management menu to restore the previous installation.')) + + +def fit(text): + """A step line that is rewritten in place must not wrap.""" + width = max(shutil.get_terminal_size((80, 24)).columns - 8, 30) + return text if len(text) <= width else text[:width - 1] + '…' + + +def run(*args): + log('$ ' + shlex.join(str(arg) for arg in args)) + # OCI extraction enters an unprivileged user namespace; PVE's newly created + # traversal directories must not inherit a caller's restrictive umask. + pve_creation = (args[:2] in (('pct', 'create'), ('pct', 'restore')) + or args[0] == 'vzdump') + try: + result = subprocess.run(args, capture_output=True, timeout=1800, close_fds=True, + umask=0o022 if pve_creation else -1) + except subprocess.TimeoutExpired: + log(' timeout') + raise + if result.returncode: + log(f' exit {result.returncode}') + log_output(None if tuple(args[:2]) in DATA_COMMANDS else result.stdout, result.stderr) + if result.returncode: + raise RuntimeError(f"{args[0]} {translate('failed with exit code')} {result.returncode}") + return result.stdout + + +def filehash(path): + value = hashlib.sha256() + with Path(path).open('rb') as source: + for block in iter(lambda: source.read(1024 * 1024), b''): + value.update(block) + return value.hexdigest() + + +def checkpoint(path, state, phase): + state['phase'] = phase + instances.write(path, state) + log(f'phase: {phase}') + + +def mounts(config): + result = {} + for key, value in parse_config(config).items(): + if re.fullmatch(r'mp[0-9]+', key): + source, *options = value.split(',') + options = dict(item.split('=', 1) for item in options if '=' in item) + target = options.get('mp') + if not target or target in result: + raise ValueError(translate('Ambiguous mount points in the container')) + result[target] = {'key': key, 'value': value, 'volume': source, **options} + return result + + +def effective_healthcheck(template): + """The template's own health check or, when it has none, one derived from + its web address: any HTTP answer below 500 means the application is up.""" + profile = template.get('proxmox', {}).get('installer_profile', {}) + check = profile.get('startup_healthcheck') + if check or profile.get('haos_healthcheck') or profile.get('host_monitor'): + return check + for endpoint in template.get('first_run', {}).get('endpoints', []): + path = str(endpoint.get('path') or '/') + if (endpoint.get('scheme') in ('http', 'https') and str(endpoint.get('port', '')).isdigit() + and path.startswith('/') and not any(c.isspace() for c in path)): + return {'scheme': endpoint['scheme'], 'port': int(endpoint['port']), 'path': path, + 'timeout_seconds': 300, 'request_timeout_seconds': 10, 'stability_seconds': 4, + 'verify_tls': False, 'accept_any_status': True} + # Without a web address, the new image must at least keep the container running. + return {'type': 'running', 'timeout_seconds': 90, 'stability_seconds': 20} + + +def with_default_healthcheck(contract): + check = effective_healthcheck(contract['template']) + if check: + contract['template'].setdefault('proxmox', {}).setdefault('installer_profile', {})['startup_healthcheck'] = check + return contract + + +def candidate_contract(record, operation, proposal=None): + if record.get('status') != 'installed': + raise ValueError(translate('The instance is not ready; review its pending operation')) + if operation not in ('update', 'recreate'): + raise ValueError(translate('Unsupported operation')) + if operation == 'update': + if proposal is not None: + raise ValueError(translate('An update does not accept configuration changes')) + return with_default_healthcheck(copy.deepcopy(record)) + if not isinstance(proposal, dict) or proposal.get('operation') != 'recreate': + raise ValueError(translate('Recreating requires a confirmed proposal')) + if (proposal.get('base_config_sha256') is not None + and proposal['base_config_sha256'] != record['observed']['config_sha256']): + raise ValueError(translate('The instance changed while it was being edited; configure Recreate again')) + candidate = proposal['candidate'] + if (candidate.get('vmid') != record['vmid'] + or candidate.get('installation_id') != record['installation_id'] + or candidate['template']['id'] != record['template']['id'] + or candidate['deployment'].get('vmid') != record['vmid']): + raise ValueError(translate('The proposal changes the identity of the instance')) + # Only desired state is editable; caller cannot forge observed evidence. + result = copy.deepcopy(record) + result.update(template=copy.deepcopy(candidate['template']), + deployment=copy.deepcopy(candidate['deployment'])) + return with_default_healthcheck(result) + + +# Resource settings edited in Proxmox that the new container keeps. +ADOPTABLE = {'memory': ('resources', 'memory_mb'), 'swap': ('resources', 'swap_mb'), + 'cores': ('resources', 'cores'), 'cpulimit': ('resources', 'cores'), + 'cpuunits': ('resources', 'cpu_units'), 'onboot': (None, 'onboot')} + + +def external_changes(record, config, adopt=True): + """Settings changed in Proxmox since the last operation, as deployment + values. Any change the new container cannot keep is refused.""" + if sha(config) == record['observed']['config_sha256']: + return {} + before, now = parse_config(record['observed']['config'].encode()), parse_config(config) + changed = sorted(key for key in before.keys() | now.keys() if before.get(key) != now.get(key)) + cores_key = 'cpulimit' if 'cpulimit' in before and 'cores' not in before else 'cores' + values = {} + for key in changed if adopt else (): + value = now.get(key) + if key == 'onboot': + values[key] = value == '1' + elif key == 'cpuunits' and value is None: + values[key] = None + elif key in ('memory', 'swap', 'cpuunits', cores_key) and value and re.fullmatch(r'[0-9]+', value): + if int(value) > 0 or key == 'swap': + values[key] = int(value) + refused = [key for key in changed if key not in values] + if refused: + raise ValueError(f"{translate('The container was changed outside ProxMenux and an update would discard those changes:')} " + f"{', '.join(refused)}") + return values + + +def preflight(record, candidate, config, coordinated=None): + deployment = record['deployment'] + desired = candidate['deployment'] + if coordinated and (record.get('native_stack_intent') or deployment.get('rootfs_adaptation_replay_required')): + raise ValueError(translate('The dedicated adapter still requires replaying its rootfs changes')) + if not coordinated and (any(key in record for key in ('stack', 'stack_member', 'native_stack_intent')) or deployment.get('stack_managed')): + raise ValueError(translate('Stack members are updated together with their stack')) + if instances.identity(config) != record['installation_id']: + raise ValueError(translate('The container identity changed; the container is not replaced')) + for key, value in external_changes(record, config, adopt=not coordinated).items(): + section, name = ADOPTABLE[key] + recorded = deployment.get(section, {}) if section else deployment + target = desired.setdefault(section, {}) if section else desired + if target.get(name) == recorded.get(name): + target[name] = value + cfg = parse_config(config) + for key in ('lxc.init.uid', 'lxc.init.gid'): + if key in cfg and not re.fullmatch(r'[0-9]+', cfg[key]): + raise ValueError(translate('The imported OCI user or group is not numeric')) + if 'lxc.init.groups' in cfg and not re.fullmatch(r'(?:[0-9]+(?:[ ,][0-9]+)*)?', cfg['lxc.init.groups']): + raise ValueError(translate('The imported OCI groups are not numeric')) + keys = {line.split(': ', 1)[0] for line in config.decode().splitlines() if ': ' in line} + runtime_keys = {'lxc.mount.entry'} if gpu_devices.nvidia.enabled(deployment) else set() + if gpu_devices.dynamic_mode(deployment): + runtime_keys = {'lxc.hook.mount', 'lxc.environment'} + if deployment.get('tmpfs_mounts'): + runtime_keys.add('lxc.mount.entry') + if deployment.get('security', {}).get('sysctls'): + runtime_keys.add('lxc.include') + runtime_settings.check(config, deployment, record['vmid']) + coordinated_keys = {'net1', 'startup', 'hookscript'} if coordinated else set() + if '[' in config.decode() or keys - BASIC - runtime_keys - coordinated_keys - {k for k in keys if re.fullmatch(r'(mp|dev)[0-9]+', k)}: + raise ValueError(translate('The container has advanced Proxmox settings outside the supported profile')) + for plan in (deployment, desired): + security = plan.get('security', {}) + if (security.get('unprivileged') is not True + or security.get('options') or plan.get('host_monitor') + or plan.get('extra_hosts') + or plan.get('resources', {}).get('rlimits')): + raise ValueError(translate('Updates are not available yet in this beta for applications that use ' + 'a privileged container or advanced LXC settings')) + runtime_settings.sysctl_content(plan) + runtime_settings.tmpfs_lines(plan) + gpu_devices.planned(plan) + paths = [] + for mount in plan.get('mounts', []): + target = host_mounts.valid_path(mount['container_path']) + if (any(target == p or target.startswith(p.rstrip('/') + '/') + or p.startswith(target.rstrip('/') + '/') for p in paths)): + raise ValueError(translate('Mount paths must not overlap')) + if mount['type'] == 'managed-volume': + if mount.get('backup') is not True or not isinstance(mount.get('size_gb'), int) or mount['size_gb'] < 1: + raise ValueError(translate('Managed disks must have backup enabled and a valid size')) + elif mount['type'] == 'host-bind': + if mount.get('backup') is not False: + raise ValueError(translate('Host directories cannot be part of the vzdump backup')) + host_mounts.valid_path(mount['source']) + else: + raise ValueError(translate('Unsupported mount type')) + paths.append(target) + if cfg.get('unprivileged') != '1' or ':' not in cfg.get('rootfs', ''): + raise ValueError(translate('A managed rootfs and an unprivileged container are required')) + if desired['rootfs'] != deployment['rootfs']: + raise ValueError(translate('Changing the rootfs or its storage requires a separate migration')) + actual = mounts(config) + gpu_devices.check(config, deployment) + gpu_devices.verify_baseline(record['observed'].get('gpu_devices', {}), deployment) + old = {m['container_path']: m for m in deployment.get('mounts', [])} + new = {m['container_path']: m for m in desired.get('mounts', [])} + if set(actual) != set(old): + raise ValueError(translate('The container disks do not match the saved record')) + for target, mount in actual.items(): + host_bind = old[target]['type'] == 'host-bind' + if ((host_bind and (mount['volume'] != old[target]['source'] or mount.get('backup', '0') != '0')) + or (not host_bind and (mount.get('backup') != '1' or not mount['volume'].startswith(old[target]['source'] + ':'))) + or mount.get('ro', '0') != ('1' if old[target].get('read_only') else '0')): + raise ValueError(translate('A container mount has a source, backup or permission different from the saved record')) + for target in old.keys() & new.keys(): + if any(old[target].get(k) != new[target].get(k) for k in ('type', 'source', 'size_gb')): + raise ValueError(translate('Changing the storage or size of a disk requires a migration; empty disks are not created')) + protected = ('/bin', '/sbin', '/etc', '/usr', '/lib', '/lib64', '/proc', '/sys', '/dev', '/run') + for target in new.keys() - old.keys(): + if any(target == p or target.startswith(p + '/') or p.startswith(target + '/') for p in protected): + raise ValueError(translate('The additional path hides a system directory')) + for template, plan in ((record['template'], deployment), (candidate['template'], desired)): + required = {v['container_path'] for v in template['container_contract'].get('volumes', []) if v.get('required', True)} + if not required <= {m['container_path'] for m in plan.get('mounts', [])}: + raise ValueError(translate('Required persistent paths cannot be removed')) + image_paths = record['observed']['image']['defaults'].get('Volumes') or {} + if any(not any(p == target or p.startswith(target.rstrip('/') + '/') for target in old) for p in image_paths): + raise ValueError(translate('The image declares data paths that are still stored in the rootfs')) + check = effective_healthcheck(candidate['template']) + if not check and not coordinated: + raise ValueError(translate('Updates are not available yet for this application in this beta')) + mac = next((item[7:] for item in cfg['net0'].split(',') if item.startswith('hwaddr=')), None) + if not mac: + raise ValueError(translate('The MAC address of the container cannot be kept')) + return cfg, actual, mac + + +def freeze_host_sources(record, candidate, acknowledge_external_data): + old = {m['source'] for m in record['deployment'].get('mounts', []) if m['type'] == 'host-bind'} + wanted = {m['source']: m for m in candidate['deployment'].get('mounts', []) if m['type'] == 'host-bind'} + if (old or wanted) and not acknowledge_external_data: + raise ValueError(translate('Host data is not restored by the backup; confirm it with --acknowledge-external-data')) + baseline = record['observed'].get('host_bind_sources', {}) + original = {p: host_mounts.validate_source(p) for p in old} + for source, previous in baseline.items(): + if source in original and not host_mounts.same_source(previous, original[source]): + raise ValueError(translate('A shared source does not match its recorded identity')) + desired = {p: original[p] if p in original else + host_mounts.validate_source(p, allow_missing=m.get('create_if_missing') is True) + for p, m in wanted.items()} + if old or wanted: + log('host directories: not included in the backup and not reverted by a recovery') + if old - set(baseline): + log('host directories without a recorded identity: their current identity is pinned') + return original, desired + + +def check_runtime_mounts(config, deployment): + runtime_settings.check(config, deployment, deployment['vmid']) + actual = mounts(config) + declared = {m['container_path']: m for m in deployment.get('mounts', [])} + if actual.keys() != declared.keys(): + raise ValueError(translate('The mounts of the new container do not match the proposal')) + for target, value in actual.items(): + expected = declared[target] + source_ok = value['volume'] == expected['source'] if expected['type'] == 'host-bind' else value['volume'].startswith(expected['source'] + ':') + if (not source_ok or value.get('backup', '0') != ('1' if expected['backup'] else '0') + or value.get('ro', '0') != ('1' if expected.get('read_only') else '0')): + raise ValueError(translate('The mount source or options were not kept')) + + +def pin_host_source(root, vmid, journal, source): + state = json.loads(journal.read_text()) + record = instances.read(root, vmid) + if (state['vmid'] != vmid or state['phase'] != 'installing-candidate' + or record.get('transaction_id') != state['id'] or record.get('pending_transaction') != str(journal) + or record['installation_id'] != state['record']['installation_id'] or record['status'] != 'updating'): + raise ValueError(translate('Mount not authorized by the operation')) + expected = state['desired_host_sources'][source] + current = host_mounts.validate_source(source) + if ((expected['exists'] and not host_mounts.same_source(expected, current)) + or current['resolved_path'] != expected['resolved_path']): + raise ValueError(translate('The host directory changed before it was mounted')) + path = journal.parent / 'candidate-host-sources.json' + pinned = json.loads(path.read_text()) if path.exists() else {} + if source in pinned and not host_mounts.same_source(pinned[source], current): + raise ValueError(translate('A shared directory was replaced during the installation')) + pinned[source] = current + instances.write(path, pinned) + + +def candidate_host_sources(journal, state): + expected = state.get('desired_host_sources', {}) + if not expected: + return {} + path = journal.parent / 'candidate-host-sources.json' + pinned = json.loads(path.read_text()) + if pinned.keys() != expected.keys(): + raise ValueError(translate('Not all shared directories were verified')) + for source, previous in expected.items(): + if previous['exists'] and not host_mounts.same_source(previous, pinned[source]): + raise ValueError(translate('The mounted source differs from the configured directory')) + host_mounts.verify_sources(pinned) + return pinned + + +def stop(vmid): + if run('pct', 'status', str(vmid)).strip() == b'status: running': + run('pct', 'shutdown', str(vmid), '--timeout', '60') + if run('pct', 'status', str(vmid)).strip() != b'status: stopped': + raise ValueError(translate('The container did not stop; its disks are not touched')) + + +def healthcheck(vmid, template): + check = effective_healthcheck(template) + if not check: + return None + if check.get('type') == 'running': + stability = int(check.get('stability_seconds', 20)) + started = time.monotonic() + while time.monotonic() - started < stability: + if run('pct', 'status', str(vmid)).strip() != b'status: running': + raise ValueError(translate('The restored service stopped; the recovery is not confirmed')) + time.sleep(2) + log(f'container {vmid} kept running for {stability}s') + return None + scheme, port, path = check['scheme'], int(check['port']), check['path'] + timeout = int(check.get('timeout_seconds', 120)) + stability = int(check.get('stability_seconds', 0)) + if (scheme not in ('http', 'https') or not 1 <= port <= 65535 + or not path.startswith('/') or any(c.isspace() for c in path) + or not 0 <= stability < timeout <= 3600): + raise ValueError(translate('Invalid health check')) + started, stable_since = time.monotonic(), None + while time.monotonic() - started < timeout: + if run('pct', 'status', str(vmid)).strip() != b'status: running': + raise ValueError(translate('The restored service stopped; the recovery is not confirmed')) + addresses = run('lxc-info', '-n', str(vmid), '-iH').decode().splitlines() + ip = next((a for a in addresses if re.fullmatch(r'[0-9]+(?:\.[0-9]+){3}', a)), None) + ok = False + if ip: + any_status = check.get('accept_any_status', False) + args = ['curl', '-sS' if any_status else '-fsS', '--noproxy', '*', '-o', '/dev/null', + '--max-time', str(check.get('request_timeout_seconds', 5))] + if any_status: + args += ['-w', '%{http_code}'] + if not check.get('verify_tls', False): + args.append('-k') + try: + answer = run(*args, f'{scheme}://{ip}:{port}{path}') + ok = not any_status or re.fullmatch(rb'[1-4][0-9][0-9]', answer.strip()) is not None + except RuntimeError: + pass + if ok: + stable_since = stable_since or time.monotonic() + if time.monotonic() - stable_since >= stability: + log(f'restored service responding: {scheme}://{ip}:{port}{path}') + return f'{scheme}://{ip}:{port}{path}' + else: + stable_since = None + log(f'waiting for the restored service: {int(time.monotonic() - started)}s') + time.sleep(2) + raise ValueError(translate('The restored service did not pass its health check')) + + +def owned(vmid, marker): + data = run('pct', 'config', str(vmid)) + description = parse_config(data).get('description', '') + if marker not in description: + raise ValueError(translate('The VMID was reused or its identity is unknown; the operation is blocked')) + return data + + +def authorize(root, vmid, journal, template_file, deployment_file): + state = json.loads(journal.read_text()) + record = instances.read(root, vmid) + if (state['vmid'] != vmid or state['phase'] != 'installing-candidate' + or record.get('pending_transaction') != str(journal) + or record.get('transaction_id') != state['id'] or record['status'] != 'updating' + or record['installation_id'] != state['record']['installation_id'] + or json.loads(template_file.read_text()) != state['runtime_template'] + or json.loads(deployment_file.read_text()) != state['runtime_deployment'] + or filehash(state['archive']) != state['archive_sha256']): + raise ValueError(translate('The new container is not authorized by the operation journal')) + host_mounts.verify_sources(state.get('desired_host_sources', {})) + gpu_devices.verify(state.get('desired_gpu_devices', {})) + return record['installation_id'] + + +def child_step(path, position): + """The last step announced by the shared installer since position.""" + try: + with open(path, 'rb') as source: + source.seek(position) + data = source.read() + except OSError: + return position, None + end = data.rfind(b'\n') + 1 + step = None + for line in data[:end].decode(errors='replace').split('\n'): + match = re.fullmatch(r' {4}-(\S.*)', screen_text(line)) + if match: + step = match.group(1).strip() + return position + end, step + + +def install_candidate(root, journal, state, progress=None): + directory = journal.parent + template = directory / 'candidate-template.json' + deployment = directory / 'candidate-deployment.json' + instances.write(template, state['runtime_template']) + instances.write(deployment, state['runtime_deployment']) + installer_log = directory / 'installer.log' + # The installer writes its steps and command output to its own private log. + env = dict(os.environ, PROXMENUX_OCI_TRANSACTION=str(journal), + PROXMENUX_OCI_INSTANCE_ROOT=str(root), OCI_LOG=str(installer_log), OCI_SPINNER='0') + env.pop('PROXMENUX_INSTANCE_LOCK_FD', None) + fd = os.open(installer_log, os.O_WRONLY | os.O_CREAT | os.O_EXCL | os.O_APPEND, 0o600) + log(f'$ install_oci.sh {template} {deployment} (output: {installer_log})') + with os.fdopen(fd, 'w') as output: + process = subprocess.Popen(['bash', str(Path(__file__).with_name('install_oci.sh')), + str(template), str(deployment)], + stdout=output, stderr=subprocess.STDOUT, env=env, close_fds=True, + umask=0o022) + position, shown = 0, None + while process.poll() is None: + time.sleep(1) + if progress: + position, step = child_step(installer_log, position) + if step and step != shown: + shown = step + msg_info(fit(f'{progress} {step}')) + if process.returncode: + log(f' exit {process.returncode}') + detail, lines = installer_failure(installer_log) + _run.update(failed_log=installer_log, failed_lines=lines) + if detail: + log(f' installer error: {detail}') + raise RuntimeError(f"{translate('The new image could not be installed:')} {detail}") + raise RuntimeError(translate('The new image could not be installed')) + + +def commit(root, journal, state): + if state['phase'] not in ('health-passed', 'committing'): + raise ValueError(translate('The new container did not pass validation')) + current = instances.read(root, state['vmid']) + if current.get('last_transaction') == state['id']: + checkpoint(journal, state, 'committed') + return + if current.get('transaction_id') != state['id'] or current.get('pending_transaction') != str(journal): + raise ValueError(translate('The record no longer belongs to this operation')) + config = owned(state['vmid'], state['record']['installation_id']) + if sha(config) != state.get('validated_config_sha256'): + raise ValueError(translate('The configuration changed after the new container was validated')) + host_mounts.verify_sources(state.get('candidate_host_sources', {})) + gpu_devices.verify(state.get('desired_gpu_devices', {})) + gpu_devices.check(config, state['candidate_contract']['deployment']) + checkpoint(journal, state, 'committing') + result = copy.deepcopy(state['candidate_contract']) + result.update(status='installed', completed_at=instances.now(), + last_transaction=state['id'], + observed=instances.observe(state['vmid'], result['installation_id'], + state['archive'], state['registry_digest'])) + host_mounts.verify_sources(state.get('candidate_host_sources', {})) + host_mounts.verify_observation(state.get('candidate_host_sources', {}), result['observed']) + gpu_devices.verify_observation(state.get('desired_gpu_devices', {}), result['observed']) + result.pop('pending_transaction', None) + result.pop('transaction_id', None) + instances.write(instances.location(root, state['vmid']), result) + checkpoint(journal, state, 'committed') + + +def restore_firewall(vmid, state): + """pct destroy removes the CT firewall rules; the recreated CT gets them back.""" + saved = state.get('firewall_config') + if saved is not None: + Path(f'/etc/pve/firewall/{vmid}.fw').write_text(saved) + + +def release_stage(state): + """After a commit the holder CT only keeps its own rootfs: every parked + volume went back to the application. Anything still attached keeps it.""" + stage = state.get('stage') + if not stage: + return + try: + config = owned(stage, 'proxmenux-transaction=' + state['id']) + except (ValueError, RuntimeError, subprocess.CalledProcessError): + return + if mounts(config) or any(re.fullmatch(r'unused[0-9]+', key) for key in parse_config(config)): + return + run('pct', 'destroy', str(stage)) + + +def gib(size): + return f'{size / 1024**3:.1f} GB' + + +def backup_size(vmid): + """Bytes in use on the volumes that vzdump includes: the rootfs and the + mount points with backup enabled.""" + cfg = parse_config(run('pct', 'config', str(vmid))) + included = {'rootfs'} | {key for key, value in cfg.items() + if re.fullmatch(r'mp[0-9]+', key) and 'backup=1' in value.split(',')} + units = {'': 1, 'K': 1024, 'M': 1024**2, 'G': 1024**3, 'T': 1024**4, 'P': 1024**5} + total = 0 + for line in run('pct', 'df', str(vmid)).decode().splitlines()[1:]: + fields = line.split() + if not fields or fields[0] not in included: + continue + match = re.fullmatch(r'([0-9.]+)([KMGTP]?)', fields[3]) if len(fields) > 3 else None + if not match: + raise ValueError(translate('The disk usage of the container could not be read')) + total += int(float(match.group(1)) * units[match.group(2)]) + return total + + +def require_backup_space(directory, vmids): + """The data in use on the backed-up volumes, plus a margin, must fit in + `directory`; data that is already compressed does not shrink.""" + needed = int(sum(backup_size(vmid) for vmid in vmids) * 1.1) + 1024**3 + free = shutil.disk_usage(directory).free + if free < needed: + raise ValueError(f"{translate('Not enough free space for the backup')} " + f"({translate('needed')}: {gib(needed)}, {translate('free')}: {gib(free)}, {directory})") + + +def prune_backups(root, vmid): + """The backups of closed operations are removed once the container works + with its new image; their journal and log stay.""" + base = instances.location(root, vmid).parent / 'transactions' + for directory in base.iterdir(): + if directory.is_symlink() or not directory.is_dir(): + continue + try: + phase = json.loads((directory / 'transaction.json').read_text()).get('phase') + except (OSError, ValueError): + continue + if phase not in ('committed', 'rolled-back'): + continue + for backup in (directory / 'backup').glob('vzdump-lxc-*'): + if backup.is_file() and not backup.is_symlink(): + backup.unlink() + + +def check_archive(archive): + """Full integrity check of the image; its per-blob report goes to the log.""" + report = io.StringIO() + try: + with contextlib.redirect_stdout(report), contextlib.redirect_stderr(report): + verify_archive(archive) + except RuntimeError as exc: + log(f'integrity check: {exc}') + raise RuntimeError(translate('The image did not pass the integrity check')) from exc + finally: + log_output(report.getvalue()) + + +def apply(root, vmid, archive, operation, proposal=None, registry_digest=None, interrupt_after=None, + backup_compression='zstd', acknowledge_external_data=False, coordinated=None, progress=None): + # A coordinated member is shown by its stack; progress prefixes the installer steps. + show = not coordinated + update = operation == 'update' + if backup_compression not in ('zstd', 'gzip'): + raise ValueError(translate('Unsupported backup compression')) + if coordinated and backup_compression != 'zstd': + raise ValueError(translate('Coordinated backups require zstd')) + if show: + msg_info(translate('Preparing the update...') if update else translate('Preparing the recreation...')) + record = instances.read(root, vmid) + if coordinated and any(coordinated.get(flag) for flag in + ('nextcloud_replay', 'paperless_replay', 'tandoor_replay', 'immich_replay')): + import oci_stack_replay + project = (oci_stack_replay.immich_record if coordinated.get('immich_replay') + else oci_stack_replay.tandoor_record if coordinated.get('tandoor_replay') + else oci_stack_replay.paperless_record if coordinated.get('paperless_replay') + else oci_stack_replay.nextcloud_record) + record = project(record) + expected = coordinated['effective_record'] + if any(record.get(key) != expected.get(key) for key in + ('vmid', 'installation_id', 'template', 'deployment')): + raise ValueError(translate('The translated recipe changed during the preparation')) + if 'stack' in expected: + record['stack'] = copy.deepcopy(expected['stack']) + candidate = candidate_contract(record, operation, proposal) + before = run('pct', 'config', str(vmid)) + cfg, actual, mac = preflight(record, candidate, before, coordinated) + original_sources, desired_sources = freeze_host_sources(record, candidate, acknowledge_external_data) + original_gpu = gpu_devices.planned(record['deployment']) + desired_gpu = gpu_devices.planned(candidate['deployment']) + resources = json.loads(run('pvesh', 'get', '/cluster/ha/resources', '--output-format', 'json')) + if any(r.get('sid') == f'ct:{vmid}' for r in resources): + raise ValueError(translate('High availability resources are not supported by this profile')) + archive = archive.resolve(strict=True) + check_archive(archive) + image = image_from_archive(str(archive)) + previous = record['observed']['image'] + if image['architecture'] != previous['architecture'] or image['os'] != 'linux': + raise ValueError(translate('Incompatible image platform')) + if not coordinated and operation == 'update' and image['manifest_digest'] == previous['manifest_digest']: + msg_ok(translate('The image is already up to date; nothing was changed.')) + return None + required = {m['container_path'] for m in candidate['deployment'].get('mounts', [])} + if any(not any(p == target or p.startswith(target.rstrip('/') + '/') for target in required) + for p in (image['defaults'].get('Volumes') or {})): + raise ValueError(translate('The new image requires additional persistent paths; use Recreate')) + directory = instances.location(root, vmid).parent / 'transactions' / uuid.uuid4().hex + private_directory(directory) + open_log(directory) + if not coordinated: + require_backup_space(directory, [vmid]) + journal = directory / 'transaction.json' + runtime_deployment = copy.deepcopy(candidate['deployment']) + runtime_deployment['network']['mac_address'] = mac + runtime_deployment.update(onboot=False, start_after_create=not bool(coordinated), + transaction_reuse_mounts=[dict(m, container_path=p) + for p, m in actual.items() if p in required and not m['volume'].startswith('/')]) + state = {'schema_version': 1, 'id': directory.name, 'vmid': vmid, 'operation': operation, + 'record': record, 'candidate_contract': candidate, 'before_config': before.decode(), + 'archive': str(archive), 'archive_sha256': filehash(archive), + 'registry_digest': registry_digest or image['manifest_digest'], + 'runtime_template': candidate['template'], 'runtime_deployment': runtime_deployment, + 'backup_compression': backup_compression, + 'original_host_sources': original_sources, 'desired_host_sources': desired_sources, + 'external_data_acknowledged': acknowledge_external_data, + 'original_gpu_devices': original_gpu, 'desired_gpu_devices': desired_gpu, + 'was_running': run('pct', 'status', str(vmid)).strip() == b'status: running'} + if coordinated: + state['coordinated'] = coordinated + state['preserved_stack_config'] = {key: cfg[key] for key in ('net1', 'startup', 'hookscript') if key in cfg} + if operation == 'update': + state['preserved_stack_config'].update({key: cfg[key] for key in + ('net0', 'features', 'cmode', 'console', 'tty', 'cpuunits', 'tags') if key in cfg}) + checkpoint(journal, state, 'prepared') + pending = copy.deepcopy(record) + pending.update(status='updating', pending_transaction=str(journal), transaction_id=state['id']) + instances.write(instances.location(root, vmid), pending) + log(f'journal: {journal}') + if show: + _run['journal'] = journal + host_mounts.verify_sources(original_sources) + host_mounts.verify_sources(desired_sources) + gpu_devices.verify(original_gpu) + gpu_devices.verify(desired_gpu) + if show: + msg_ok(translate('Update prepared') if update else translate('Recreation prepared')) + if original_sources or desired_sources: + msg_warn(translate('Host directories are not included in the backup and are not reverted by a recovery.')) + msg_info(translate('Stopping the container...')) + stop(vmid) + if show: + msg_ok(translate('Container stopped')) + msg_info(translate('Creating a backup of the container...')) + checkpoint(journal, state, 'backing-up') + if coordinated: + backup = coordinated['backup'] + if filehash(backup['archive']) != backup['sha256']: + raise ValueError(translate('The coordinated backup was modified')) + run('zstd', '-t', backup['archive']) + state.update(backup=backup['archive'], backup_sha256=backup['sha256']) + else: + backup_dir = directory / 'backup' + private_directory(backup_dir) + run('vzdump', str(vmid), '--mode', 'stop', '--compress', backup_compression, + '--dumpdir', str(backup_dir), '--tmpdir', '/var/tmp') + suffix = 'zst' if backup_compression == 'zstd' else 'gz' + backups = list(backup_dir.glob(f'vzdump-lxc-*.tar.{suffix}')) + if len(backups) != 1: + raise ValueError(translate('The backup could not be identified; the image is not replaced')) + run('zstd' if backup_compression == 'zstd' else 'gzip', '-t', str(backups[0])) + state.update(backup=str(backups[0]), backup_sha256=filehash(backups[0])) + checkpoint(journal, state, 'backup-ready') + if show: + msg_ok(translate('Backup created')) + msg_info(translate('Moving the data volumes aside...')) + stage = int(run('pvesh', 'get', '/cluster/nextid').strip()) + state['stage'] = stage + state['runtime_deployment']['transaction_source_vmid'] = stage + checkpoint(journal, state, 'creating-stage') + run('pct', 'create', str(stage), str(archive), '--rootfs', + f"{record['deployment']['rootfs']['storage']}:{record['deployment']['rootfs']['size_gb']}", + '--hostname', 'oci-data-holder', '--ostype', 'unmanaged', '--unprivileged', '1', + '--memory', '128', '--cores', '1', '--onboot', '0', + '--description', 'proxmenux-transaction=' + state['id']) + checkpoint(journal, state, 'parking-data') + for mount in actual.values(): + owned(vmid, record['installation_id']) + host_mounts.verify_sources(original_sources) + if mount['volume'].startswith('/'): + run('pct', 'set', str(vmid), '--delete', mount['key']) + else: + owned(stage, 'proxmenux-transaction=' + state['id']) + run('pct', 'move-volume', str(vmid), mount['key'], '--target-vmid', str(stage), '--target-volume', mount['key']) + checkpoint(journal, state, 'data-parked') + if show: + msg_ok(translate('Data volumes protected')) + if interrupt_after == 'data-parked': + raise RuntimeError(translate('Lab interruption after protecting the data')) + if show: + msg_info(translate('Installing the new image...') if update else translate('Recreating the container...')) + current = owned(vmid, record['installation_id']) + expected = b''.join(line for line in before.splitlines(keepends=True) + if not re.match(rb'mp[0-9]+: ', line)) + if mounts(current) or current != expected: + raise ValueError(translate('A concurrent change was detected; the container is not removed')) + host_mounts.verify_sources(original_sources) + gpu_devices.verify(original_gpu) + gpu_devices.verify(desired_gpu) + firewall = Path(f'/etc/pve/firewall/{vmid}.fw') + state['firewall_config'] = firewall.read_text() if firewall.exists() else None + checkpoint(journal, state, 'replacing-root') + run('pct', 'destroy', str(vmid)) + checkpoint(journal, state, 'installing-candidate') + if show: + progress = translate('Installing the new image:') if update else translate('Recreating the container:') + install_candidate(root, journal, state, progress) + restore_firewall(vmid, state) + if coordinated: + for key, value in state['preserved_stack_config'].items(): + run('pct', 'set', str(vmid), '--' + key, value) + check_runtime_mounts(run('pct', 'config', str(vmid)), candidate['deployment']) + gpu_devices.check(run('pct', 'config', str(vmid)), candidate['deployment']) + state['staged_config_sha256'] = sha(owned(vmid, record['installation_id'])) + checkpoint(journal, state, 'candidate-installed') + return journal + gpu_devices.validate_runtime(vmid, candidate['deployment']) + state['candidate_host_sources'] = candidate_host_sources(journal, state) + checkpoint(journal, state, 'candidate-installed') + msg_ok(translate('New image installed') if update else translate('Container recreated')) + if interrupt_after == 'candidate-installed': + raise RuntimeError(translate('Lab interruption after installing the new container')) + msg_info(translate('Saving the new configuration...')) + check_runtime_mounts(run('pct', 'config', str(vmid)), candidate['deployment']) + gpu_devices.check(run('pct', 'config', str(vmid)), candidate['deployment']) + if not state['was_running']: + stop(vmid) + run('pct', 'set', str(vmid), '--onboot', '1' if candidate['deployment']['onboot'] else '0') + state['validated_config_sha256'] = sha(owned(vmid, record['installation_id'])) + checkpoint(journal, state, 'health-passed') + commit(root, journal, state) + cleanup_error = None + freed = 0 + try: + release_stage(state) + prune_backups(root, vmid) + for path, size in image_cache.prune(root, lock=False): + log(f'removed unused image archive: {path}') + freed += size + except (OSError, ValueError, RuntimeError, subprocess.CalledProcessError) as exc: + cleanup_error = exc + log(f'cleanup: {exc}') + msg_ok(translate('Update completed. Data kept.') if update + else translate('Recreation completed. Data kept.')) + if freed: + msg_ok(f"{translate('Unused images removed from the cache:')} {gib(freed)}") + if cleanup_error is not None: + msg_warn(f"{translate('The final cleanup did not complete:')} {cleanup_error}") + return journal + + +def remove_empty_format_directories(rootfs, deployment): + """Remove only empty, unmapped mkfs lost+found on restored managed disks.""" + root = Path(rootfs) + for mount in deployment.get('mounts', []): + if mount.get('type') != 'managed-volume' or not mount.get('backup'): + continue + current = root + for part in Path(mount['container_path']).parts[1:]: + if part in ('.', '..'): + raise ValueError(translate('Invalid restored volume path')) + current /= part + if current.is_symlink(): + raise ValueError(translate('Symbolic link in a restored volume path')) + candidate = current / 'lost+found' + if not candidate.exists() or candidate.is_symlink(): + continue + info = candidate.lstat() + if (stat.S_ISDIR(info.st_mode) and info.st_ino == 11 + and info.st_uid == 0 and info.st_gid == 0 + and stat.S_IMODE(info.st_mode) == 0o700): + if not any(candidate.iterdir()): + candidate.rmdir() + + +def cleanup_restored_format_dirs(vmid, deployment, installation_id): + owned(vmid, installation_id) + run('pct', 'mount', str(vmid)) + try: + remove_empty_format_directories(Path('/var/lib/lxc') / str(vmid) / 'rootfs', deployment) + finally: + run('pct', 'unmount', str(vmid)) + + +def complete_recovery(root, journal, state): + vmid = state['vmid'] + show = not state.get('coordinated') + if show: + msg_info(translate('Checking the restored installation...')) + host_mounts.verify_sources(state.get('original_host_sources', {})) + gpu_devices.verify(state.get('original_gpu_devices', {})) + config = owned(vmid, state['record']['installation_id']) + expected = state['restore_config_sha256'] + if sha(config) != expected: + raise ValueError(translate('The configuration changed after the backup was restored; the recovery is not confirmed')) + cleanup_restored_format_dirs(vmid, state['record']['deployment'], state['record']['installation_id']) + runtime_settings.restore(state['record']['deployment'], vmid) + check_runtime_mounts(config, state['record']['deployment']) + gpu_devices.check(config, state['record']['deployment']) + if show: + msg_ok(translate('Restored installation checked')) + if not state.get('coordinated') and run('pct', 'status', str(vmid)).strip() == b'status: stopped': + msg_info(translate('Starting the container...')) + run('pct', 'start', str(vmid)) + msg_ok(translate('Container started')) + if not state.get('coordinated'): + msg_info(translate('Waiting for the application to respond...')) + url = healthcheck(vmid, state['record']['template']) + gpu_devices.validate_runtime(vmid, state['record']['deployment']) + msg_ok(f"{translate('Application responding:')} {url}") + if not state['was_running']: + stop(vmid) + restored = copy.deepcopy(state['record']) + restored['observed'] = instances.observe(vmid, restored['installation_id'], + restored['observed']['archive_path'], restored['observed']['resolved_registry_digest'], + restored['observed']['image']) + host_mounts.verify_sources(state.get('original_host_sources', {})) + host_mounts.verify_observation(state.get('original_host_sources', {}), restored['observed']) + gpu_devices.verify_observation(state.get('original_gpu_devices', {}), restored['observed']) + restored['recovered_transaction'] = state['id'] + instances.write(instances.location(root, vmid), restored) + checkpoint(journal, state, 'rolled-back') + if show: + msg_ok(translate('Recovery completed. The displaced disks and the backup are kept; nothing was deleted automatically.')) + if state.get('original_host_sources') or state.get('desired_host_sources'): + msg_info2(translate('Shared host files are kept as they are; the backup does not restore their content.')) + + +def recover(root, journal): + state = json.loads(journal.read_text()) + vmid = state['vmid'] + show = not state.get('coordinated') + if show: + msg_info(translate('Checking the interrupted operation...')) + record = instances.read(root, vmid) + if state['phase'] in TERMINAL or record.get('last_transaction') == state['id']: + raise ValueError(translate('The operation already finished; it is not restored automatically')) + if (record.get('transaction_id') != state['id'] or record.get('pending_transaction') != str(journal) + or record['installation_id'] != state['record']['installation_id']): + raise ValueError(translate('The record does not belong to this operation')) + host_mounts.verify_sources(state.get('original_host_sources', {})) + gpu_devices.verify(state.get('original_gpu_devices', {})) + current_path = Path(f'/etc/pve/lxc/{vmid}.conf') + resources = json.loads(run('pvesh', 'get', '/cluster/resources', '--type', 'vm', '--output-format', 'json')) + if not isinstance(resources, list): + raise ValueError(translate('Incomplete Proxmox inventory; recovery blocked')) + for resource in resources: + if not isinstance(resource, dict) or resource.get('type') not in ('lxc', 'qemu') or not isinstance(resource.get('vmid'), int): + raise ValueError(translate('Unexpected Proxmox inventory; recovery blocked')) + if resource['vmid'] == vmid and (resource['type'] != 'lxc' or not current_path.exists() + or resource.get('node') != socket.gethostname().split('.', 1)[0]): + raise ValueError(translate('The VMID was reused or the container is on another node; it is not overwritten')) + if current_path.exists(): + owned(vmid, record['installation_id']) + backup = state.get('backup') + # A failure before the container was changed (while backing it up or + # creating the temporary container) leaves it exactly as it was. + untouched = current_path.exists() and run('pct', 'config', str(vmid)).decode() == state['before_config'] + if not backup or untouched: + if not untouched: + raise ValueError(translate('There is no verified backup; a modified container is not touched')) + release_stage(state) + if state['was_running'] and run('pct', 'status', str(vmid)).strip() == b'status: stopped': + run('pct', 'start', str(vmid)) + instances.write(instances.location(root, vmid), state['record']) + checkpoint(journal, state, 'rolled-back') + if show: + msg_ok(translate('Recovery completed. The container had not been modified yet.')) + return + if filehash(backup) != state['backup_sha256']: + raise ValueError(translate('The backup was altered; recovery blocked')) + run('gzip' if state.get('backup_compression') == 'gzip' else 'zstd', '-t', backup) + if show: + msg_ok(translate('Backup of the previous installation verified')) + if state['phase'] == 'checking-recovery' and state.get('restore_config_sha256'): + complete_recovery(root, journal, state) + return + if show: + msg_info(translate('Restoring the previous backup...')) + stage = state.get('stage') + if stage and Path(f'/etc/pve/lxc/{stage}.conf').exists(): + held = owned(stage, 'proxmenux-transaction=' + state['id']) + stop(stage) + else: + held = None + checkpoint(journal, state, 'recovering') + if current_path.exists(): + stop(vmid) + current = owned(vmid, record['installation_id']) + gpu_devices.check_recovery_entries(current, state) + if any(re.fullmatch(r'unused[0-9]+', k) for k in parse_config(current)): + raise ValueError(translate('There are extra disks or bind mounts outside the journal; the rootfs is not replaced')) + known_binds = {(m['source'], m['container_path']) + for plan in (state['record']['deployment'], state['candidate_contract']['deployment']) + for m in plan.get('mounts', []) if m['type'] == 'host-bind'} + if any(m['volume'].startswith('/') and (m['volume'], target) not in known_binds + for target, m in mounts(current).items()): + raise ValueError(translate('A host mount is not part of the journal; recovery blocked')) + if any(not m['volume'].startswith('/') for m in mounts(current).values()) and held is None: + raise ValueError(translate('There is no temporary container of this operation to keep the current disks')) + used = {m['key'] for m in mounts(held or b'').values()} + for mount in mounts(current).values(): + if mount['volume'].startswith('/'): + run('pct', 'set', str(vmid), '--delete', mount['key']) + continue + index = next(i for i in range(256) if f'mp{i}' not in used) + key = f'mp{index}' + owned(stage, 'proxmenux-transaction=' + state['id']) + # Unique inert targets make repeated recovery safe even when both the + # failed candidate and a restored backup contain the same app paths. + retained_target = '/transaction-retained/' + uuid.uuid4().hex + run('pct', 'set', str(vmid), '--' + mount['key'], + f"{mount['volume']},mp={retained_target},backup=1") + run('pct', 'move-volume', str(vmid), mount['key'], '--target-vmid', str(stage), '--target-volume', key) + used.add(key) + checkpoint(journal, state, 'restoring-backup') + host_mounts.verify_sources(state.get('original_host_sources', {})) + run('pct', 'restore', str(vmid), backup, '--force', '1', '--storage', + state['record']['deployment']['rootfs']['storage']) + state['restore_config_sha256'] = sha(owned(vmid, state['record']['installation_id'])) + checkpoint(journal, state, 'checking-recovery') + if show: + msg_ok(translate('Previous installation restored')) + complete_recovery(root, journal, state) + + +def phase_label(phase): + labels = { + 'prepared': translate('Prepared; the container was not modified yet'), + 'backing-up': translate('Creating the backup'), + 'backup-ready': translate('Backup created'), + 'creating-stage': translate('Creating the temporary data container'), + 'parking-data': translate('Moving the data volumes aside'), + 'data-parked': translate('Data volumes protected'), + 'replacing-root': translate('Removing the previous container'), + 'installing-candidate': translate('Installing the new image'), + 'candidate-installed': translate('New image installed, not verified yet'), + 'health-passed': translate('New image verified, not saved yet'), + 'committing': translate('Saving the new configuration'), + 'committed': translate('Completed'), + 'recovering': translate('Recovering the previous installation'), + 'restoring-backup': translate('Restoring the backup'), + 'checking-recovery': translate('Checking the restored installation'), + 'rolled-back': translate('Previous installation restored'), + } + return f'{labels[phase]} ({phase})' if phase in labels else str(phase) + + +def show_status(path, state): + operations = {'update': translate('Update'), 'recreate': translate('Recreate')} + msg_info2(f"{translate('Interrupted operation:')} {operations.get(state.get('operation'), state.get('operation'))} (CT {state['vmid']})") + msg_info2(f"{translate('Stopped at:')} {phase_label(state.get('phase'))}") + if state.get('stage'): + msg_info2(f"{translate('Temporary data container:')} CT {state['stage']}") + if state.get('backup'): + msg_info2(f"{translate('Backup:')} {state['backup']}") + log_path = path.parent / 'transaction.log' + msg_info2(f"{translate('Transaction log:')} {log_path if log_path.exists() else path.parent}") + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('--root', type=Path, default=instances.ROOT) + parser.add_argument('action', choices=['apply', 'status', 'recover', 'commit', 'authorize-candidate', 'pin-host-source']) + parser.add_argument('vmid', type=int) + parser.add_argument('--operation', choices=['update', 'recreate'], default='update') + parser.add_argument('--archive', type=Path) + parser.add_argument('--proposal', type=Path) + parser.add_argument('--registry-digest') + parser.add_argument('--journal', type=Path) + parser.add_argument('--template', type=Path) + parser.add_argument('--deployment', type=Path) + parser.add_argument('--source') + parser.add_argument('--acknowledge-external-data', action='store_true') + parser.add_argument('--interrupt-after', choices=['data-parked', 'candidate-installed']) + parser.add_argument('--backup-compression', choices=['zstd', 'gzip'], default='zstd') + args = parser.parse_args() + if os.geteuid() != 0: + parser.error(translate('Root privileges are required')) + # The shared installer reads the output of these two actions: their messages go to stderr. + output = sys.stderr if args.action in ('authorize-candidate', 'pin-host-source') else sys.stdout + try: + if args.action == 'authorize-candidate': + print(authorize(args.root, args.vmid, args.journal, args.template, args.deployment)) + return 0 + if args.action == 'pin-host-source': + pin_host_source(args.root, args.vmid, args.journal, args.source) + return 0 + with instances.locked(args.root): + if args.action == 'apply': + if args.archive is None: + raise ValueError(translate('apply requires the OCI archive of the resolved image')) + proposal = json.loads(args.proposal.read_text()) if args.proposal else None + apply(args.root, args.vmid, args.archive, args.operation, proposal, + args.registry_digest, args.interrupt_after, args.backup_compression, + args.acknowledge_external_data) + else: + path = args.journal or Path(instances.read(args.root, args.vmid)['pending_transaction']) + state = json.loads(path.read_text()) + if state['vmid'] != args.vmid: + raise ValueError(translate('The journal belongs to another VMID')) + if args.action == 'status': + show_status(path, state) + elif args.action == 'recover': + if state.get('coordinated'): + raise ValueError(translate('This container belongs to a stack; recover the whole stack')) + open_log(path.parent) + _run['journal'] = path + recover(args.root, path) + else: + if state.get('coordinated'): + raise ValueError(translate('This container belongs to a stack; publish the whole stack')) + commit(args.root, path, state) + return 0 + except BlockingIOError: + with contextlib.redirect_stdout(output): + msg_error(translate('Another OCI operation is using the registry. This operation was not started.')) + return 1 + except (OSError, ValueError, KeyError, RuntimeError, subprocess.SubprocessError) as error: + with contextlib.redirect_stdout(output): + report_error(error, f'oci-{args.action}-{args.vmid}') + if pending_journal(): + recovery_hint(after_recovery=args.action == 'recover') + return 1 + + +if __name__ == '__main__': + raise SystemExit(main()) diff --git a/oci/remote/oci_instances.py b/oci/remote/oci_instances.py new file mode 100644 index 00000000..eaba23fd --- /dev/null +++ b/oci/remote/oci_instances.py @@ -0,0 +1,387 @@ +#!/usr/bin/env python3 +"""Private OCI instance contracts. Does not recreate or update containers.""" +from __future__ import annotations + +import argparse +import contextlib +import copy +from contextlib import contextmanager +import datetime +import fcntl +import json +import os +from pathlib import Path +import re +import subprocess +import sys +import tempfile +import uuid + +from oci_installation_state import command, image_from_archive, private_directory, sha +from oci_host_mounts import capture_sources +from oci_accelerators import capture as capture_gpu_devices +from oci_ui import translate, msg_error, msg_ok + +ROOT = Path('/usr/local/share/proxmenux/oci/apps') +MARKER = 'proxmenux-instance=' +ACTIVE = {'installing', 'assembling', 'updating', 'recovering'} + + +def now(): + return datetime.datetime.now(datetime.timezone.utc).isoformat() + + +def location(root, vmid): + if not isinstance(vmid, int) or vmid < 100: + raise ValueError(translate('Invalid VMID')) + path = root / str(vmid) + if path.is_symlink(): + raise ValueError(translate('Unsafe instance directory')) + return path / 'oci-compose.json' + + +@contextmanager +def locked(root): + private_directory(root) + path = root / '.lock' + if path.is_symlink(): + raise ValueError(translate('Unsafe registry lock')) + inherited = os.environ.get('PROXMENUX_INSTANCE_LOCK_FD') + if inherited: + fd = int(inherited) + if os.fstat(fd).st_ino != path.stat().st_ino or os.fstat(fd).st_dev != path.stat().st_dev: + raise ValueError(translate('Wrong inherited registry lock')) + fcntl.flock(fd, fcntl.LOCK_EX | fcntl.LOCK_NB) + yield + else: + with path.open('a') as lock: + os.chmod(path, 0o600) + fcntl.flock(lock, fcntl.LOCK_EX | fcntl.LOCK_NB) + yield + + +def write(path, value): + private_directory(path.parent) + if path.is_symlink(): + raise ValueError(translate('Unsafe instance record')) + fd, tmp = tempfile.mkstemp(dir=path.parent, prefix='.compose-') + try: + with os.fdopen(fd, 'w') as out: + json.dump(value, out, indent=2) + out.write('\n') + out.flush() + os.fsync(out.fileno()) + os.replace(tmp, path) + fd = os.open(path.parent, os.O_RDONLY) + try: + os.fsync(fd) + finally: + os.close(fd) + finally: + if os.path.exists(tmp): + os.unlink(tmp) + + +def read(root, vmid): + path = location(root, vmid) + if path.is_symlink(): + raise ValueError(translate('Unsafe instance record')) + value = json.loads(path.read_text()) + if value.get('schema_version') != 1 or value.get('vmid') != vmid: + raise ValueError(translate('Incompatible instance record')) + uuid.UUID(value['installation_id']) + return value + + +def has_contract(root, vmid): + path = location(root, vmid) + if path.is_symlink(): + raise ValueError(translate('Unsafe instance record')) + if path.parent.exists() and not path.parent.is_dir(): + raise ValueError(translate('Incompatible instance directory')) + return path.exists() + + +def guest_exists(vmid): + nodes = Path('/etc/pve/nodes') + return any(nodes.glob(f'*/lxc/{vmid}.conf')) or any(nodes.glob(f'*/qemu-server/{vmid}.conf')) + + +def release_orphan(root, vmid): + """A record whose guest no longer exists on any node does not own the VMID: + a failed install, or a container deleted from the Proxmox UI. An update or + recovery left halfway keeps it, because its backup may still be needed. + The record stays in the same directory as history.""" + path = location(root, vmid) + if not path.exists(): + return True + previous = read(root, vmid) + if (previous.get('status') in ('updating', 'recovering') + or previous.get('pending_transaction') or previous.get('pending_stack_transaction') + or guest_exists(vmid)): + return False + path.replace(path.with_name(f"retired-{previous['installation_id']}.json")) + return True + + +def prepare(root, vmid, template, deployment): + path = location(root, vmid) + if not release_orphan(root, vmid): + raise ValueError(f"VMID {vmid} {translate('belongs to another OCI installation')}") + deployment = dict(deployment, vmid=vmid) + value = {'schema_version': 1, 'vmid': vmid, 'installation_id': str(uuid.uuid4()), + 'created_at': now(), 'status': 'installing', 'template': template, + 'deployment': deployment, 'observed': None, + 'automatic_update_enabled': False} + write(path, value) + return value + + +def observe(vmid, installation_id, archive, digest, image=None): + """Collect evidence before changing the current desired-state contract. + An installation observed again passes its saved image metadata, since the + downloaded archive may have been removed.""" + config = command('pct', 'config', str(vmid)) + if identity(config) != installation_id: + raise ValueError(translate('The container identity does not match')) + resources = json.loads(command('pvesh', 'get', '/cluster/resources', '--type', 'vm', '--output-format', 'json')) + node = next(r['node'] for r in resources if r.get('type') == 'lxc' and int(r['vmid']) == vmid) + api_config = command('pvesh', 'get', f'/nodes/{node}/lxc/{vmid}/config', '--output-format', 'json') + observed = { + 'config': config.decode(), 'config_sha256': sha(config), 'api_config_sha256': api_hash(api_config), + 'image': image if image is not None else image_from_archive(archive), 'archive_path': archive, + 'resolved_registry_digest': digest} + sources = capture_sources(config) + if sources: + observed['host_bind_sources'] = sources + gpu = capture_gpu_devices(config) + if gpu: + observed['gpu_devices'] = gpu + return observed + + +def finish(root, vmid, archive, digest): + value = read(root, vmid) + observed = observe(vmid, value['installation_id'], archive, digest) + value.update(status='assembling' if value['deployment'].get('stack_managed') else 'installed', + completed_at=now(), observed=observed) + write(location(root, vmid), value) + + +def publish_stack(root, primary_id, template, deployment, members): + """Preserve each recipe AND a complete, nonrecursive copy in the principal.""" + records = {} + for member in members: + vmid = int(member['vmid']) + record = read(root, vmid) + if identity(command('pct', 'config', str(vmid))) != record['installation_id']: + raise ValueError(translate('A stack member has a different identity')) + records[vmid] = record + if primary_id is not None and primary_id not in records: + raise ValueError(translate('The main member of the stack is missing')) + stack_id = records[primary_id]['installation_id'] if primary_id is not None else None + for member in members: + vmid = int(member['vmid']) + record = records[vmid] + if 'deployment' in member: + record['deployment'] = copy.deepcopy(member['deployment']) + record['deployment']['vmid'] = vmid + record['deployment']['stack_managed'] = primary_id is not None + write(location(root, vmid), record) + finish(root, vmid, record['observed']['archive_path'], record['observed']['resolved_registry_digest']) + record = read(root, vmid) + record['status'] = 'installed' + if stack_id: + record['stack_member'] = {'stack_id': stack_id, 'primary_vmid': primary_id, 'name': member['name']} + records[vmid] = record + if primary_id is not None: + recipes = [copy.deepcopy(records[int(m['vmid'])]) for m in members] + for recipe in recipes: + recipe.pop('stack', None) + records[primary_id]['stack'] = { + 'id': stack_id, 'template': copy.deepcopy(template), + 'deployment': copy.deepcopy(deployment), 'members': recipes, + 'reconstruction_requires_volume_verification': True, + } + records[primary_id]['stack']['deployment']['services'] = copy.deepcopy(members) + # Persist recovery recipes first, before publishing member completion. + write(location(root, primary_id), records[primary_id]) + for vmid, record in records.items(): + if vmid != primary_id: + write(location(root, vmid), record) + + +def identity(config): + # Description is URL-escaped by pct; UUID characters remain unchanged. + text = config.decode() + try: + description = json.loads(text).get('description', '') + except ValueError: + description = next((line[len('description: '):] for line in text.splitlines() + if line.startswith('description: ')), '') + match = re.search(r'proxmenux-instance=([0-9a-f-]{36})(?![0-9a-f-])', description) + return match.group(1) if match else None + + +def save_assembly(root, primary_id, template, deployment, members): + path = location(root, primary_id).parent / 'stack-assembly.json' + if path.exists() or path.is_symlink(): + raise ValueError(translate('A pending stack assembly already exists; it is not overwritten')) + ids = [int(m['vmid']) for m in members] + if primary_id not in ids or len(set(ids)) != len(ids): + raise ValueError(translate('Invalid stack members')) + expected = {str(vmid): read(root, vmid)['installation_id'] for vmid in ids} + write(path, {'schema_version': 1, 'primary_vmid': primary_id, 'created_at': now(), + 'expected_installation_ids': expected, 'template': template, + 'deployment': deployment, 'services': members}) + + +def resume_assembly(root, primary_id): + path = location(root, primary_id).parent / 'stack-assembly.json' + if path.is_symlink(): + raise ValueError(translate('Unsafe stack assembly')) + saved = json.loads(path.read_text()) + ids = [int(m['vmid']) for m in saved['services']] + if (saved.get('schema_version') != 1 or saved['primary_vmid'] != primary_id + or primary_id not in ids or len(set(ids)) != len(ids) + or set(saved['expected_installation_ids']) != {str(vmid) for vmid in ids}): + raise ValueError(translate('Incompatible stack assembly')) + for vmid in ids: + expected = saved['expected_installation_ids'][str(vmid)] + if read(root, vmid)['installation_id'] != expected: + raise ValueError(translate('The record of a member was replaced; the assembly is not resumed')) + if identity(command('pct', 'config', str(vmid))) != expected: + raise ValueError(translate('The container of a member was replaced; the assembly is not resumed')) + publish_stack(root, primary_id, saved['template'], saved['deployment'], saved['services']) + path.unlink() + + +def api_hash(config): + return sha(json.dumps(json.loads(config), sort_keys=True, separators=(',', ':')).encode()) + + +def reconcile(root, resources, configs): + """Caller holds lock and fetched a complete cluster inventory and configs.""" + if not isinstance(resources, list): + raise ValueError(translate('Invalid Proxmox inventory')) + for resource in resources: + if (not isinstance(resource, dict) or resource.get('type') not in ('lxc', 'qemu') + or not isinstance(resource.get('vmid'), int)): + raise ValueError(translate('Incomplete or incompatible Proxmox inventory')) + present = {int(r['vmid']): r for r in resources if r.get('type') in ('lxc', 'qemu')} + decisions = [] + pending = set() + for directory in root.iterdir(): + if directory.name.isdecimal(): + journal = location(root, int(directory.name)).parent / 'stack-assembly.json' + if journal.is_symlink(): + raise ValueError(translate('Unsafe stack assembly')) + if journal.exists(): + saved = json.loads(journal.read_text()) + if saved.get('schema_version') != 1: + raise ValueError(translate('Incompatible stack assembly')) + pending.update(int(vmid) for vmid in saved['expected_installation_ids']) + # Plan everything before removing anything: malformed records fail closed. + for directory in sorted(root.iterdir()): + if not directory.name.isdecimal(): + continue + vmid = int(directory.name) + if not has_contract(root, vmid): + # Orphan cleanup intentionally retains transaction history/backups. + continue + value = read(root, vmid) + row = {'vmid': vmid, 'status': value['status'], 'action': 'keep'} + if value['status'] in ACTIVE or vmid in pending or value.get('pending_stack_transaction'): + row['reason'] = 'operation-in-progress' + elif vmid not in present or present[vmid]['type'] != 'lxc': + row.update(action='delete', reason='container-absent-or-replaced') + else: + config = configs[vmid] + marker = identity(config) + if marker and marker != value['installation_id']: + row.update(action='delete', reason='different-installation') + elif not marker: + row['reason'] = 'identity-unconfirmed' + else: + row['reason'] = 'matched' + baseline = (value.get('observed') or {}).get('api_config_sha256') + row['configuration_changed'] = api_hash(config) != baseline if baseline else None + decisions.append(row) + if value.get('stack'): + row['missing_members'] = [m['vmid'] for m in value['stack']['members'] + if m['vmid'] not in present] + row['replaced_members'] = [m['vmid'] for m in value['stack']['members'] + if m['vmid'] in present and (present[m['vmid']]['type'] != 'lxc' or + (m['vmid'] in configs and identity(configs[m['vmid']]) not in (None, m['installation_id'])))] + for row in decisions: + if row['action'] == 'delete': + path = location(root, row['vmid']) + path.unlink() + # Never recursively delete history, backups, or unexpected files. + try: + path.parent.rmdir() + except OSError: + pass + return decisions + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('--root', type=Path, default=ROOT) + sub = parser.add_subparsers(dest='action', required=True) + for action in ('prepare', 'complete', 'failed'): + p = sub.add_parser(action) + p.add_argument('vmid', type=int) + if action == 'prepare': + p.add_argument('--template', required=True) + p.add_argument('--deployment', required=True) + if action == 'complete': + p.add_argument('--archive', required=True) + p.add_argument('--digest', required=True) + sub.add_parser('reconcile') + resume = sub.add_parser('resume-stack-recording') + resume.add_argument('vmid', type=int) + args = parser.parse_args() + if os.geteuid() != 0: + parser.error(translate('Root privileges are required')) + try: + with locked(args.root): + if args.action == 'resume-stack-recording': + resume_assembly(args.root, args.vmid) + msg_ok(translate('Stack records saved; no container was reinstalled.')) + elif args.action == 'prepare': + value = prepare(args.root, args.vmid, json.loads(Path(args.template).read_text()), + json.loads(Path(args.deployment).read_text())) + print(value['installation_id']) + elif args.action == 'complete': + finish(args.root, args.vmid, args.archive, args.digest) + elif args.action == 'failed': + value = read(args.root, args.vmid) + value.update(status='failed', failed_at=now()) + write(location(args.root, args.vmid), value) + else: + resources = json.loads(command('pvesh', 'get', '/cluster/resources', '--type', 'vm', '--output-format', 'json')) + configs = {} + wanted = set() + for directory in args.root.iterdir(): + if directory.name.isdecimal(): + if not has_contract(args.root, int(directory.name)): + continue + record = read(args.root, int(directory.name)) + wanted.add(record['vmid']) + wanted.update(m['vmid'] for m in record.get('stack', {}).get('members', [])) + for r in resources: + if r.get('type') == 'lxc' and int(r['vmid']) in wanted: + configs[int(r['vmid'])] = command('pvesh', 'get', f"/nodes/{r['node']}/lxc/{r['vmid']}/config", '--output-format', 'json') + # pvesh JSON contains the description and all repeated LXC entries. + print(json.dumps(reconcile(args.root, resources, configs), indent=2)) + return 0 + except (OSError, ValueError, KeyError, StopIteration, RuntimeError, subprocess.TimeoutExpired) as exc: + # stdout carries data read by the installers; the error goes to stderr. + with contextlib.redirect_stdout(sys.stderr): + msg_error(f"{translate('The instance record operation did not complete; no container was modified.')} ({exc})") + return 1 + + +if __name__ == '__main__': + raise SystemExit(main()) diff --git a/oci/remote/oci_native_stack.py b/oci/remote/oci_native_stack.py new file mode 100644 index 00000000..164606e0 --- /dev/null +++ b/oci/remote/oci_native_stack.py @@ -0,0 +1,180 @@ +#!/usr/bin/env python3 +"""Instance recording adapter for the existing dedicated stack installers.""" +import argparse +import copy +import json +import os +from pathlib import Path +import subprocess +import sys + +import oci_instances as instances +from oci_installation_state import command, image_from_archive, sha +import oci_stack_replay +from oci_ui import translate + + +def begin(root, primary, template, deployment, members, adapter): + ids = [int(m[1]) for m in members] + if primary not in ids or len(set(ids)) != len(ids): + raise ValueError(translate('Invalid stack members')) + resources = json.loads(command('pvesh', 'get', '/cluster/resources', '--type', 'vm', '--output-format', 'json')) + if not isinstance(resources, list): + raise ValueError(translate('Invalid Proxmox inventory')) + occupied = {int(r['vmid']) for r in resources} + for vmid in ids: + if vmid in occupied or not instances.release_orphan(root, vmid): + raise ValueError(translate('The VMID or its contract is already in use; it is not adopted')) + adapter_source = Path(adapter).read_text() + prepared = [] + for name, vmid, reference, archive in members: + archive_path = archive if archive.startswith('/') else command('pvesm', 'path', archive).decode().strip() + image = image_from_archive(archive_path) + child = {'id': template['id'] + '-' + name, + 'container_contract': {'image': {'reference': reference}}} + plan = {'deployment_kind': 'dedicated-stack-member', 'stack_managed': True, + 'role': name, 'archive_volume': archive, 'archive_path': archive_path, + 'image': image, 'rootfs_adaptation_replay_required': True, + 'mounts': []} + if Path(adapter).name == 'install_immich_stack.sh' and name == 'machine-learning': + plan['machine_learning'] = copy.deepcopy(deployment.get('machine_learning', {'acceleration': 'cpu'})) + if Path(adapter).name in oci_stack_replay.FILES: + plan['replay_profile'] = {'adapter': Path(adapter).name, 'role': name} + if not oci_stack_replay.FILES[Path(adapter).name][name]: + plan['rootfs_replay'] = {'schema_version': 1, 'adapter': Path(adapter).name, + 'role': name, 'files': []} + prepared.append((int(vmid), child, plan)) + for vmid, child, plan in prepared: + instances.prepare(root, vmid, child, plan) + parent = instances.read(root, primary) + parent['native_stack_intent'] = { + 'template': template, 'deployment': copy.deepcopy(deployment), + 'members': [{'name': m[0], 'vmid': int(m[1])} for m in members], + 'adapter': {'name': Path(adapter).name, 'sha256': sha(adapter_source.encode()), + 'source': adapter_source}, + } + parent['native_stack_intent']['deployment']['base_vmid'] = primary + instances.write(instances.location(root, primary), parent) + + +def create(root, args): + vmid = int(args[0]) + record = instances.read(root, vmid) + if record['status'] != 'installing' or args[1] != record['deployment']['archive_volume']: + raise ValueError(translate('The container creation does not match the prepared instance')) + argv = list(args) + description = '' + if '--description' in argv: + index = argv.index('--description') + description = argv[index + 1] + del argv[index:index + 2] + argv += ['--description', description + '; ' + instances.MARKER + record['installation_id']] + record['deployment']['create_arguments'] = argv + instances.write(instances.location(root, vmid), record) + # No inherited registry/network locks in long-lived Proxmox processes. + # Keep PVE extraction directories traversable inside its standard idmap. + return subprocess.run(['pct', 'create', *argv], close_fds=True, umask=0o022).returncode + + +def capture_rootfs(root, vmid): + record = instances.read(root, vmid) + profile = record['deployment'].get('replay_profile') + if not profile: + raise ValueError(translate('The stack member has no declared adaptation profile')) + if record['status'] != 'installing': + raise ValueError(translate('The rootfs capture only belongs to the running installation')) + mounts = [] + for line in command('pct', 'config', str(vmid)).decode().splitlines(): + key, sep, value = line.partition(': ') + if sep and key.startswith('mp') and key[2:].isdigit(): + options = dict(p.split('=', 1) for p in value.split(',')[1:] if '=' in p) + mounts.append({'container_path': options['mp']}) + record['deployment']['rootfs_replay'] = oci_stack_replay.capture( + Path('/var/lib/lxc') / str(vmid) / 'rootfs', profile['adapter'], profile['role'], mounts) + instances.write(instances.location(root, vmid), record) + + +def finalize(root, primary): + parent = instances.read(root, primary) + intent = parent['native_stack_intent'] + services = [] + for member in intent['members']: + vmid = member['vmid'] + record = instances.read(root, vmid) + plan = record['deployment'] + instances.finish(root, vmid, plan['archive_path'], plan['image']['manifest_digest']) + record = instances.read(root, vmid) + plan = record['deployment'] + # Store raw config: repeated LXC directives must not be collapsed. + plan['native_config'] = record['observed']['config'] + if plan.get('rootfs_replay'): + try: + plan['member_replay_projection'] = oci_stack_replay.normalize(record) + plan.pop('member_replay_projection_error', None) + except (ValueError, KeyError): + # Recording an unsupported projection must not roll back a + # healthy installation; it remains blocked for management. + plan.pop('member_replay_projection', None) + plan['member_replay_projection_error'] = 'native-config-requires-reviewed-conversion' + mounts = [] + for line in plan['native_config'].splitlines(): + key, sep, value = line.partition(': ') + if sep and key.startswith('mp') and key[2:].isdigit(): + parts = value.split(',') + options = dict(p.split('=', 1) for p in parts[1:] if '=' in p) + mounts.append({'container_path': options['mp'], 'source': parts[0], + 'type': 'host-bind' if parts[0].startswith('/') else 'managed-volume', + 'backup': options.get('backup') == '1', + 'read_only': options.get('ro') == '1', 'existing_volume': True}) + plan['mounts'] = mounts + services.append({'name': member['name'], 'vmid': vmid, 'deployment': plan}) + path = instances.location(root, primary).parent / 'stack-assembly.json' + if not path.exists(): + instances.save_assembly(root, primary, intent['template'], intent['deployment'], services) + instances.resume_assembly(root, primary) + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + sub = parser.add_subparsers(dest='action', required=True) + p = sub.add_parser('begin') + p.add_argument('primary', type=int) + for option in ('template', 'deployment', 'adapter'): + p.add_argument('--' + option, required=True) + p.add_argument('--member', action='append', nargs=4, required=True) + p = sub.add_parser('create') + p.add_argument('arguments', nargs=argparse.REMAINDER) + for action in ('finalize', 'failed'): + p = sub.add_parser(action) + p.add_argument('primary', type=int) + p = sub.add_parser('capture-rootfs') + p.add_argument('vmid', type=int) + args = parser.parse_args() + if os.geteuid() != 0: + parser.error(translate('Root privileges are required')) + try: + with instances.locked(instances.ROOT): + if args.action == 'begin': + begin(instances.ROOT, args.primary, json.loads(Path(args.template).read_text()), + json.loads(Path(args.deployment).read_text()), args.member, args.adapter) + elif args.action == 'create': + return create(instances.ROOT, args.arguments) + elif args.action == 'finalize': + finalize(instances.ROOT, args.primary) + elif args.action == 'capture-rootfs': + capture_rootfs(instances.ROOT, args.vmid) + else: + parent = instances.read(instances.ROOT, args.primary) + for member in parent['native_stack_intent']['members']: + record = instances.read(instances.ROOT, member['vmid']) + record['status'] = 'failed' + instances.write(instances.location(instances.ROOT, member['vmid']), record) + return 0 + except (OSError, ValueError, KeyError, RuntimeError, subprocess.TimeoutExpired) as exc: + print(f"ERROR: {translate('The stack registry is incomplete; review the private contracts.')} ({exc})", + file=sys.stderr) + return 1 + + +if __name__ == '__main__': + raise SystemExit(main()) diff --git a/oci/remote/oci_native_stack.sh b/oci/remote/oci_native_stack.sh new file mode 100755 index 00000000..80f3c05d --- /dev/null +++ b/oci/remote/oci_native_stack.sh @@ -0,0 +1,42 @@ +# Sourced by the dedicated installers after image resolution, before CT creation. +oci_native_begin() { + OCI_NATIVE_PRIMARY=$1 + shift + local root=/usr/local/share/proxmenux/oci/apps + [[ ! -L $root && ! -L $root/.lock ]] || die "$(translate "The instance registry is not safe")" + oci_quiet install -d -m 0700 "$root" + exec 8>>"$root/.lock" + chmod 600 "$root/.lock" + flock -n 8 || die "$(translate "Another OCI operation is using the instance registry")" + export PROXMENUX_INSTANCE_LOCK_FD=8 + oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" begin "$OCI_NATIVE_PRIMARY" \ + --template "$TEMPLATE_FILE" --deployment "$DEPLOYMENT_FILE" \ + --adapter "$0" "$@" + OCI_NATIVE_ACTIVE=1 +} + +# A failure returns to the caller instead of exiting inside a redirected call, +# so the caller's error report reaches the terminal and not the log. +pct() { + if [[ ${1:-} == unmount && ${OCI_NATIVE_ACTIVE:-0} == 1 ]]; then + if ! python3 "$SCRIPT_DIR/oci_native_stack.py" capture-rootfs "$2"; then + command pct unmount "$2" 8>&- 9>&- || true + return 1 + fi + fi + if [[ ${1:-} == create && ${OCI_NATIVE_ACTIVE:-0} == 1 ]]; then + shift + python3 "$SCRIPT_DIR/oci_native_stack.py" create "$@" || return + else + command pct "$@" 8>&- 9>&- || return + fi +} + +oci_native_finalize() { + oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" finalize "$OCI_NATIVE_PRIMARY" +} + +oci_native_failed() { + [[ ${OCI_NATIVE_ACTIVE:-0} == 1 ]] || return 0 + oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" failed "$OCI_NATIVE_PRIMARY" || true +} diff --git a/oci/remote/oci_nvidia_dynamic.py b/oci/remote/oci_nvidia_dynamic.py new file mode 100644 index 00000000..e806e6b6 --- /dev/null +++ b/oci/remote/oci_nvidia_dynamic.py @@ -0,0 +1,57 @@ +"""Validation for the experimental native-device/dynamic-library NVIDIA profile. + +Driver files are runtime evidence, not persistent desired-state dependencies. +This module does not enable transactions before the common installer supports +the same profile. +""" +from pathlib import Path +import hashlib + +import oci_nvidia_runtime as nv +from oci_ui import translate + + +def gpu_identity(inventory): + identities = [] + for row in inventory['gpus']: + fields = [part.strip() for part in row.split(',')] + if len(fields) != 3 or not all(fields): + raise ValueError(translate('Incomplete NVIDIA identity')) + identities.append(tuple(fields[:2])) + if not identities or len(set(identities)) != len(identities): + raise ValueError(translate('Empty or duplicated NVIDIA identity')) + return sorted(identities) + + +def validate(config, previous, current, hook, expected_hook_sha256, + capabilities='compute,utility,video'): + if gpu_identity(previous) != gpu_identity(current): + raise ValueError(translate('The selected GPU changed')) + if nv.mount_lines(config): + raise ValueError(translate('The dynamic profile does not support static driver mounts')) + hook = Path(hook) + info = hook.stat() + if (hook.is_symlink() or not hook.is_file() or info.st_uid != 0 + or info.st_mode & 0o022 or not info.st_mode & 0o111 + or hashlib.sha256(hook.read_bytes()).hexdigest() != expected_hook_sha256): + raise ValueError(translate('Untrusted or modified NVIDIA hook')) + allowed = {'lxc.hook.mount': str(hook), + 'lxc.environment': {'NVIDIA_VISIBLE_DEVICES=all', + f'NVIDIA_DRIVER_CAPABILITIES={capabilities}'}} + found_hook, environments = [], [] + for line in config.decode().splitlines(): + if not line.startswith('lxc.') or ': ' not in line: + continue + key, value = line.split(': ', 1) + if key == 'lxc.hook.mount': + found_hook.append(value) + elif key == 'lxc.environment': + environments.append(value) + elif key.startswith(('lxc.hook.', 'lxc.cgroup', 'lxc.apparmor')): + raise ValueError(translate('Security directive outside the dynamic profile')) + if found_hook != [allowed['lxc.hook.mount']] or ( + len(environments) != 2 or set(environments) != allowed['lxc.environment']): + raise ValueError(translate('The NVIDIA hook or environment differs from the declared one')) + nv.check_devices(config, current) + return {'gpu_identity': gpu_identity(current), 'hook_sha256': expected_hook_sha256, + 'driver_capabilities': capabilities, 'inventory': current} diff --git a/oci/remote/oci_nvidia_refresh.py b/oci/remote/oci_nvidia_refresh.py new file mode 100644 index 00000000..b9f6afa0 --- /dev/null +++ b/oci/remote/oci_nvidia_refresh.py @@ -0,0 +1,145 @@ +#!/usr/bin/env python3 +"""Explicit stopped-CT NVIDIA refresh. Never changes the desired deployment.""" +from __future__ import annotations + +import argparse +import copy +import os +from pathlib import Path +import subprocess + +import oci_instances as instances +import oci_nvidia_runtime as nv +from oci_ui import translate, msg_info, msg_ok, msg_error + + +def destination(root, name): + if not name.startswith('/') or '..' in Path(name).parts: + raise ValueError(translate('Invalid NVIDIA destination')) + parent = (root / name.lstrip('/')).parent.resolve() + if parent != root and root not in parent.parents: + raise ValueError(translate('The NVIDIA destination escapes the rootfs')) + return parent / Path(name).name + + +def prepare(root, plan): + root = root.resolve() + # Validate every destination before making any rootfs change. + files = {name: destination(root, name) for name in plan['inventory']['files']} + links = {name: destination(root, name) for name in plan['links']} + for path in list(files.values()) + list(links.values()): + if path.exists() and not path.is_file() and not path.is_symlink(): + raise ValueError(translate('The NVIDIA destination cannot be replaced')) + for path in files.values(): + create_parent(path.parent, root) + if path.is_symlink(): + path.unlink() + if not path.exists(): + fd = os.open(path, os.O_WRONLY | os.O_CREAT | os.O_EXCL, 0o644) + os.close(fd) + owner = path.parent.stat() + os.chown(path, owner.st_uid, owner.st_gid) + for name, path in links.items(): + create_parent(path.parent, root) + if path.exists() or path.is_symlink(): + path.unlink() + path.symlink_to(plan['links'][name]) + # Native LXC cannot mount onto an alias in a usr-merged image. + lines = [] + for line in plan['config'].decode().splitlines(): + if line.startswith('lxc.mount.entry: '): + fields = line.split(': ', 1)[1].split() + fields[1] = str(files['/' + fields[1]].relative_to(root)) + line = 'lxc.mount.entry: ' + ' '.join(fields) + lines.append(line) + return ('\n'.join(lines) + '\n').encode() + + +def create_parent(path, root): + if path.exists(): + if not path.is_dir(): + raise ValueError(translate('The parent of an NVIDIA destination is not a directory')) + return + if path == root: + raise ValueError(translate('The rootfs is not mounted')) + create_parent(path.parent, root) + path.mkdir(mode=0o755) + owner = path.parent.stat() + os.chown(path, owner.st_uid, owner.st_gid) + + +def refresh(root, vmid, apply=False): + with instances.locked(root): + record = instances.read(root, vmid) + if record['status'] != 'installed' or record.get('pending_transaction'): + raise ValueError(translate('The instance has a pending operation')) + if not nv.enabled(record['deployment']): + raise ValueError(translate('The instance does not use NVIDIA')) + config = instances.command('pct', 'config', str(vmid)) + if (instances.identity(config) != record['installation_id'] + or instances.sha(config) != record['observed']['config_sha256']): + raise ValueError(translate('The container identity or configuration changed')) + previous = record['observed']['gpu_devices'][nv.KEY] + plan = nv.refresh_plan(config, previous) + journal = instances.location(root, vmid).parent / 'nvidia-refresh.json' + if journal.exists() or journal.is_symlink(): + raise ValueError(translate('A previous NVIDIA refresh is pending review')) + if not apply: + msg_ok(translate('Current NVIDIA inventory resolved: a refresh is required') if plan['changed'] + else translate('Current NVIDIA inventory resolved: no refresh is required')) + return + if not plan['changed']: + msg_ok(translate('The NVIDIA runtime is up to date; the container is not modified or started')) + return + if instances.command('pct', 'status', str(vmid)).strip() != b'status: stopped': + raise ValueError(translate('Stop the container before the NVIDIA refresh')) + instances.write(journal, {'phase': 'preparing', 'record': record, + 'inventory': plan['inventory']}) + msg_info(translate('Refreshing the NVIDIA runtime...')) + instances.command('pct', 'mount', str(vmid)) + try: + candidate = prepare(Path(f'/var/lib/lxc/{vmid}/rootfs'), plan) + finally: + instances.command('pct', 'unmount', str(vmid)) + nv.verify(plan['inventory']) + if instances.command('pct', 'config', str(vmid)) != config: + raise ValueError(translate('The configuration changed during the NVIDIA refresh')) + conf = Path(f'/etc/pve/lxc/{vmid}.conf') + # Same native configuration file used by the common installer. + conf.write_bytes(candidate) + instances.write(journal, {'phase': 'validating', 'record': record, + 'inventory': plan['inventory']}) + instances.command('pct', 'start', str(vmid)) + try: + nv.validate_runtime(vmid, plan['inventory']) + finally: + instances.command('pct', 'shutdown', str(vmid), '--timeout', '30') + updated = copy.deepcopy(record) + updated['observed'] = instances.observe(vmid, record['installation_id'], + record['observed']['archive_path'], record['observed']['resolved_registry_digest'], + record['observed']['image']) + nv.check_mounts(updated['observed']['config'].encode(), plan['inventory']) + nv.check_devices(updated['observed']['config'].encode(), plan['inventory']) + if updated['observed']['gpu_devices'][nv.KEY] != plan['inventory']: + raise ValueError(translate('The observed inventory differs from the validated runtime')) + nv.verify(plan['inventory']) + instances.write(instances.location(root, vmid), updated) + journal.unlink() + msg_ok(translate('NVIDIA refresh validated; the container is stopped and its settings are kept')) + + +if __name__ == '__main__': + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('vmid', type=int) + parser.add_argument('--root', type=Path, default=instances.ROOT) + parser.add_argument('--apply', action='store_true') + args = parser.parse_args() + try: + refresh(args.root, args.vmid, args.apply) + except BlockingIOError: + msg_error(translate('Another OCI operation is using the registry. This operation was not started.')) + raise SystemExit(1) + except (OSError, ValueError, KeyError, RuntimeError, subprocess.SubprocessError) as error: + msg_error(str(error) if not isinstance(error, KeyError) else + translate('The saved OCI record is incomplete or has an unexpected format.')) + raise SystemExit(1) diff --git a/oci/remote/oci_nvidia_runtime.py b/oci/remote/oci_nvidia_runtime.py new file mode 100644 index 00000000..63452dbd --- /dev/null +++ b/oci/remote/oci_nvidia_runtime.py @@ -0,0 +1,165 @@ +"""Read-only NVIDIA Toolkit inventory and strict native runtime validation.""" +from __future__ import annotations + +import hashlib +import os +from pathlib import Path, PurePosixPath +import stat +import subprocess + +from oci_gpu_devices import actual_devices +from oci_ui import translate + +KEY = '_nvidia_runtime' +QUERY = '--query-gpu=uuid,pci.bus_id,driver_version' + + +def command(*args): + result = subprocess.run(args, capture_output=True, text=True, timeout=120) + if result.returncode: + raise RuntimeError(f"{args[0]} {translate('could not validate NVIDIA; exit code')} {result.returncode}") + return result.stdout + + +def enabled(deployment): + devices = [d for d in deployment.get('devices', []) if d.get('kind') == 'nvidia-runtime'] + if len(devices) > 1 or any(d.get('device_selection', 'all-requested-by-compose') != 'all-requested-by-compose' for d in devices): + raise ValueError(translate('NVIDIA selection not supported by this profile')) + return bool(devices) + + +def digest(path): + result = hashlib.sha256() + with path.open('rb') as source: + for block in iter(lambda: source.read(1024 * 1024), b''): + result.update(block) + return result.hexdigest() + + +def snapshot(): + gpus = sorted(line.strip() for line in command('nvidia-smi', QUERY, '--format=csv,noheader').splitlines() if line.strip()) + if not gpus: + raise ValueError(translate('No working NVIDIA GPU was found')) + version = command('nvidia-container-cli', '--version') + paths = command('nvidia-container-cli', 'list', '--device', 'all', '--libraries', '--binaries', '--firmwares', '--ipcs') + devices, files, links = {}, {}, {} + for name in sorted(set(paths.splitlines())): + if not name.startswith('/') or str(PurePosixPath(name)) != name or any(c.isspace() or c == ',' for c in name): + raise ValueError(translate('Invalid path in the NVIDIA inventory')) + path = Path(name) + info = path.stat() + basic = {'source': str(path.resolve()), 'uid': info.st_uid, + 'gid': info.st_gid, 'mode': stat.S_IMODE(info.st_mode)} + if stat.S_ISCHR(info.st_mode): + if not name.startswith('/dev/nvidia'): + raise ValueError(translate('NVIDIA device outside the expected native profile')) + devices[name] = dict(basic, major=os.major(info.st_rdev), minor=os.minor(info.st_rdev)) + elif stat.S_ISREG(info.st_mode): + files[name] = dict(basic, size=info.st_size, sha256=digest(path)) + if name.startswith('/usr/lib/'): + for link in path.parent.iterdir(): + if link.is_symlink() and str(link.resolve()) == basic['source']: + links[str(link)] = os.readlink(link) + # The common installer intentionally does not publish IPC sockets. + if not devices or not files: + raise ValueError(translate('Incomplete NVIDIA inventory')) + versions = [l for l in version.splitlines() if l.startswith(('cli-version:', 'lib-version:'))] + if len(versions) != 2: + raise ValueError(translate('The NVIDIA Container Toolkit version cannot be identified')) + return {'gpus': gpus, 'toolkit_version': versions, + 'devices': devices, 'files': files, 'links': links} + + +def verify(value): + if snapshot() != value: + raise ValueError(translate('The NVIDIA driver or inventory changed; the operation was stopped')) + + +def refresh_plan(config, previous, current=None): + """Resolve current host components without treating a driver version as intent. + + This only prepares a plan; applying it requires a stopped-CT transaction and + preparing file destinations/library links before the next native start. + """ + check_devices(config, previous) + check_mounts(config, previous) + current = snapshot() if current is None else current + def identities(value): + result = [] + for row in value['gpus']: + fields = [field.strip() for field in row.split(',')] + if len(fields) != 3 or not all(fields): + raise ValueError(translate('Incomplete NVIDIA identity')) + result.append(tuple(fields[:2])) + return sorted(result) + if identities(previous) != identities(current): + raise ValueError(translate('The physical NVIDIA selection changed')) + # Remove only entries already validated against our recorded inventory. + kept = [] + for line in config.decode().splitlines(): + if line.startswith('lxc.mount.entry: '): + continue + if line.startswith('dev') and ': ' in line: + key, properties = line.split(': ', 1) + if key[3:].isdigit(): + fields = dict(part.split('=', 1) for part in properties.split(',')) + if fields.get('path') in previous['devices']: + continue + kept.append(line) + occupied = {int(line.split(':', 1)[0][3:]) for line in kept + if line.startswith('dev') and line.split(':', 1)[0][3:].isdigit()} + for path, info in sorted(current['devices'].items()): + slot = next(i for i in range(256) if i not in occupied) + occupied.add(slot) + kept.append(f'dev{slot}: path={path},mode={info["mode"]:04o},gid={info["gid"]},deny-write=0') + for path, info in sorted(current['files'].items()): + kept.append(f'lxc.mount.entry: {info["source"]} {path.lstrip("/")} none ro,bind,create=file 0 0') + candidate = ('\n'.join(kept) + '\n').encode() + check_devices(candidate, current) + check_mounts(candidate, current) + return {'config': candidate, 'inventory': current, + 'links': dict(current['links']), 'changed': previous != current} + + +def mount_lines(config): + return [line.split(': ', 1)[1] for line in config.decode().splitlines() if line.startswith('lxc.mount.entry: ')] + + +def check_mounts(config, value, complete=True): + remaining = dict(value['files']) + seen = set() + for line in mount_lines(config): + parts = line.split() + if (len(parts) != 6 or parts[2] != 'none' or set(parts[3].split(',')) != {'ro', 'bind', 'create=file'} + or parts[4:] != ['0', '0'] or line in seen): + raise ValueError(translate('LXC entry outside the read-only NVIDIA profile')) + seen.add(line) + match = next((name for name, file in remaining.items() + if parts[0] == file['source'] and parts[1] in {name.lstrip('/'), file['source'].lstrip('/')}), None) + if match is None: + raise ValueError(translate('NVIDIA mount with an unauthorized source or target')) + del remaining[match] + if complete and remaining: + raise ValueError(translate('NVIDIA runtime libraries or components are missing')) + + +def check_devices(config, value): + actual = actual_devices(config) + for path, info in value['devices'].items(): + fields = actual.get(path, {}) + if (fields.get('path') != path or set(fields) - {'path', 'mode', 'gid', 'uid', 'deny-write'} + or int(fields.get('mode', '0'), 8) != info['mode'] + or int(fields.get('gid', 0)) != info['gid'] or int(fields.get('uid', 0)) != 0 + or fields.get('deny-write', '0') != '0'): + raise ValueError(translate('NVIDIA permissions or device nodes differ from the official inventory')) + + +def validate_runtime(vmid, value): + rows = command('pct', 'exec', str(vmid), '--', 'nvidia-smi', QUERY, '--format=csv,noheader') + if sorted(line.strip() for line in rows.splitlines() if line.strip()) != value['gpus']: + raise ValueError(translate('NVIDIA inside the container does not match the host driver or GPU')) + if value['links']: + arguments = [part for pair in sorted(value['links'].items()) for part in pair] + command('pct', 'exec', str(vmid), '--', 'sh', '-c', + 'while [ "$#" -gt 0 ]; do [ "$(readlink -- "$1")" = "$2" ] || exit 1; shift 2; done', + 'check-nvidia-links', *arguments) diff --git a/oci/remote/oci_nvidia_setup.sh b/oci/remote/oci_nvidia_setup.sh new file mode 100755 index 00000000..ab7efeb9 --- /dev/null +++ b/oci/remote/oci_nvidia_setup.sh @@ -0,0 +1,81 @@ +# Shared NVIDIA runtime setup for native OCI installers. +# Sourced by the installers: uses their msg_*, translate, oci_log and die. +configure_nvidia_runtime() { + local inventory path source target runtime_mode hook_hash hook_path capabilities + local device_count=0 mount_count=0 + declare -A configured_paths=() + msg_info "$(translate "Preparing the NVIDIA GPU...")" + command -v nvidia-smi >/dev/null 2>&1 \ + || die "$(translate "The image requests NVIDIA, but the host has no working NVIDIA driver")" + nvidia-smi -L >/dev/null 2>&1 \ + || die "$(translate "The host NVIDIA driver is not responding correctly")" + command -v nvidia-container-cli >/dev/null 2>&1 \ + || die "$(translate "NVIDIA Container Toolkit is missing on the host (nvidia-container-cli)")" + runtime_mode=$(jq -r '.runtime_mode // "static"' <<<"$DEVICE") + [[ $runtime_mode == static || $runtime_mode == dynamic ]] \ + || die "$(translate "Unsupported NVIDIA mode:") $runtime_mode" + if [[ $runtime_mode == dynamic ]]; then + [[ $UNPRIVILEGED_FLAG == 1 ]] || die "$(translate "The dynamic NVIDIA profile requires an unprivileged LXC")" + [[ -f ${SCRIPT_DIR}/nvidia_lxc_mount_lab.sh ]] || die "$(translate "The dynamic NVIDIA hook is missing")" + capabilities=$(jq -r '[.environment[]? | select(.name == "NVIDIA_DRIVER_CAPABILITIES") | .value] | last // "compute,utility,video"' "$DEPLOYMENT_FILE") + [[ $capabilities == all || $capabilities =~ ^(compute|utility|video|graphics|display|compat32)(,(compute|utility|video|graphics|display|compat32))*$ ]] \ + || die "$(translate "Unsupported dynamic NVIDIA capabilities:") $capabilities" + hook_hash=$(sha256sum "${SCRIPT_DIR}/nvidia_lxc_mount_lab.sh" | awk '{print $1}') + hook_path="/usr/local/lib/proxmenux/oci/nvidia-mount-${hook_hash}.sh" + install -d -m 0755 /usr/local/lib/proxmenux/oci + if [[ -e $hook_path || -L $hook_path ]]; then + [[ ! -L $hook_path && $(sha256sum "$hook_path" | awk '{print $1}') == "$hook_hash" ]] \ + || die "$(translate "The persistent NVIDIA hook does not match the installer:") $hook_path" + else + install -m 0755 "${SCRIPT_DIR}/nvidia_lxc_mount_lab.sh" "$hook_path" + fi + printf 'lxc.environment: NVIDIA_VISIBLE_DEVICES=all\nlxc.environment: NVIDIA_DRIVER_CAPABILITIES=%s\nlxc.hook.mount: %s\n' \ + "$capabilities" "$hook_path" >>"$CONF" + fi + + inventory=$(mktemp /tmp/proxmenux-nvidia-inventory.XXXXXX) + if ! nvidia-container-cli list --device all --libraries --binaries --firmwares --ipcs \ + 2>>"${OCI_LOG:-/dev/null}" | sort -u >"$inventory"; then + rm -f "$inventory" + die "$(translate "NVIDIA Container Toolkit could not generate the runtime inventory")" + fi + while IFS= read -r path; do + [[ $path == /* && $path != *[[:space:]]* && $path != *","* ]] || continue + [[ -z ${configured_paths[$path]+x} ]] || continue + if [[ -c $path ]]; then + add_character_device "$path" preserve-host host-device-gid 0 + if [[ -n ${NVIDIA_GID_ENV:-} ]]; then + append_deployment_environment_csv "$NVIDIA_GID_ENV" "$(stat -c '%g' "$path")" + fi + device_count=$((device_count + 1)) + elif [[ -f $path ]]; then + if [[ $runtime_mode == dynamic ]]; then + continue + fi + source=$(readlink -f "$path") + [[ -f $source ]] || continue + target=$path + prepare_file_mount_target "$target" + target=$PREPARED_FILE_TARGET + prepare_nvidia_driver_links "$source" "$target" + printf 'lxc.mount.entry: %s %s none ro,bind,create=file 0 0\n' \ + "$source" "${target#/}" >>"$CONF" + mount_count=$((mount_count + 1)) + else + continue + fi + configured_paths[$path]=1 + done <"$inventory" + rm -f "$inventory" + (( device_count > 0 )) || die "$(translate "The official inventory contains no NVIDIA devices")" + [[ $runtime_mode == dynamic ]] || (( mount_count > 0 )) \ + || die "$(translate "The official inventory contains no NVIDIA driver components")" + NVIDIA_RUNTIME_CONFIGURED=1 + if [[ $runtime_mode == dynamic ]]; then + oci_log "Dynamic NVIDIA runtime prepared: $device_count native devices; libraries resolved by the Toolkit at every start" + msg_ok "$(translate "NVIDIA GPU prepared:") $device_count $(translate "devices (dynamic runtime)")" + return + fi + oci_log "NVIDIA runtime prepared from NVIDIA Container Toolkit: $device_count devices and $mount_count read-only components" + msg_ok "$(translate "NVIDIA GPU prepared:") $device_count $(translate "devices") · $mount_count $(translate "driver components")" +} diff --git a/oci/remote/oci_remove.py b/oci/remote/oci_remove.py new file mode 100644 index 00000000..4b92fc51 --- /dev/null +++ b/oci/remote/oci_remove.py @@ -0,0 +1,167 @@ +#!/usr/bin/env python3 +"""Removes an OCI installation: its containers with the volumes they own, the +private network of a multi-container application and its saved record. Host +directories are left exactly as they are.""" +from __future__ import annotations + +import argparse +import ipaddress +import json +import os +from pathlib import Path +import re +import shutil +import socket +import subprocess +import sys + +import oci_image_cache as image_cache +import oci_instances as instances +from oci_installation_state import parse_config +from oci_ui import translate, msg_info, msg_ok, msg_warn, msg_error + +# The private networks ProxMenux creates for multi-container applications. +PRIVATE_STACK_NETWORK = ipaddress.ip_network('10.77.0.0/16') + + +def run(*args): + subprocess.run(args, check=True, capture_output=True) + + +def guest_config(vmid): + try: + return instances.command('pct', 'config', str(vmid)) + except (subprocess.CalledProcessError, RuntimeError, OSError): + return None + + +def members_of(root, vmid): + """Every container of the installation: one, or the whole stack when the + selected container belongs to one. The main container is removed last.""" + record = instances.read(root, vmid) + primary_id = (record.get('stack_member') or {}).get('primary_vmid', vmid) + try: + primary = instances.read(root, primary_id) + except (OSError, ValueError, KeyError): + primary, primary_id = record, vmid + stack = primary.get('stack') or {} + members = [int(member['vmid']) for member in stack.get('members', []) if member.get('vmid')] + if primary_id not in members: + members.append(primary_id) + if vmid not in members: + members.append(vmid) + ordered = [member for member in members if member != primary_id] + [primary_id] + return primary_id, primary, ordered + + +def host_directories(root, members): + """The host directories the containers were using, which are kept.""" + paths = [] + for vmid in members: + try: + record = instances.read(root, vmid) + except (OSError, ValueError, KeyError): + continue + for mount in record.get('deployment', {}).get('mounts', []): + if mount.get('type') == 'host-bind' and mount.get('source') not in paths: + paths.append(mount['source']) + return paths + + +def private_bridge(primary): + network = (primary.get('stack') or {}).get('deployment', {}).get('network', {}) + bridge = network.get('private_bridge') + subnet = network.get('private_subnet') + if not bridge or not re.fullmatch(r'vmbr[0-9]+', bridge): + return None + try: + if not ipaddress.ip_network(subnet).subnet_of(PRIVATE_STACK_NETWORK): + return None + except (TypeError, ValueError): + return None + return bridge + + +def bridge_in_use(bridge, removed): + """Whether a guest that is not being removed still uses the bridge.""" + for path in Path('/etc/pve/nodes').glob('*/lxc/*.conf'): + if int(path.stem) in removed: + continue + if re.search(rf'(?:^|[,\s])bridge={re.escape(bridge)}(?:[,\s]|$)', + path.read_text(encoding='utf-8', errors='ignore'), re.MULTILINE): + return True + for path in Path('/etc/pve/nodes').glob('*/qemu-server/*.conf'): + if re.search(rf'(?:^|[,\s])bridge={re.escape(bridge)}(?:[,\s]|$)', + path.read_text(encoding='utf-8', errors='ignore'), re.MULTILINE): + return True + return False + + +def release_bridge(bridge): + node = socket.gethostname().split('.', 1)[0] + subprocess.run(['ip', 'link', 'delete', bridge, 'type', 'bridge'], check=False, capture_output=True) + subprocess.run(['pvesh', 'delete', f'/nodes/{node}/network/{bridge}'], check=False, capture_output=True) + + +def remove(root, vmid): + primary_id, primary, members = members_of(root, vmid) + for member in members: + record = instances.read(root, member) + if record.get('pending_transaction') or record.get('pending_stack_transaction'): + raise ValueError(translate('An operation of this installation has not finished; ' + 'recover it from the management menu before removing it')) + kept = host_directories(root, members) + bridge = private_bridge(primary) + msg_info(translate('Removing the containers...')) + for member in members: + record = instances.read(root, member) + config = guest_config(member) + if config is None: + msg_warn(f"{translate('The container no longer exists:')} CT {member}") + elif instances.identity(config) != record['installation_id']: + msg_warn(f"{translate('The VMID belongs to another container now and is not touched:')} CT {member}") + else: + subprocess.run(['pct', 'stop', str(member), '--skiplock', '1'], check=False, capture_output=True) + run('pct', 'destroy', str(member), '--purge', '1', '--destroy-unreferenced-disks', '1') + msg_ok(f"{translate('Container removed:')} CT {member}") + if bridge and not bridge_in_use(bridge, set(members)): + release_bridge(bridge) + msg_ok(f"{translate('Private network of the application released:')} {bridge}") + elif bridge: + msg_warn(f"{translate('The private network is still used by another container and is kept:')} {bridge}") + lifecycle = Path(f'/etc/pve/priv/proxmenux-stack-{primary_id}.json') + if lifecycle.exists() and not lifecycle.is_symlink(): + lifecycle.unlink() + for member in members: + directory = instances.location(root, member).parent + if directory.is_dir() and not directory.is_symlink(): + shutil.rmtree(directory) + msg_ok(translate('Saved record removed')) + for path, size in image_cache.prune(root, lock=False): + msg_ok(f"{translate('Unused image removed from the cache:')} {path.name}") + for path in kept: + msg_warn(f"{translate('Host directory kept, with its content:')} {path}") + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('vmid', type=int) + parser.add_argument('--root', type=Path, default=instances.ROOT) + args = parser.parse_args() + if os.geteuid() != 0: + parser.error(translate('Root privileges are required')) + try: + with instances.locked(args.root): + remove(args.root, args.vmid) + except BlockingIOError: + msg_error(translate('Another OCI operation is using the instance registry')) + return 1 + except (OSError, ValueError, KeyError, RuntimeError, subprocess.CalledProcessError) as error: + msg_error(str(error) or type(error).__name__) + return 1 + msg_ok(translate('The application was removed')) + return 0 + + +if __name__ == '__main__': + raise SystemExit(main()) diff --git a/oci/remote/oci_runtime.py b/oci/remote/oci_runtime.py new file mode 100644 index 00000000..630795f2 --- /dev/null +++ b/oci/remote/oci_runtime.py @@ -0,0 +1,110 @@ +#!/usr/bin/env python3 +"""Resolve the effective OCI process after Compose runtime overrides.""" + +from __future__ import annotations + +import json +import shlex +import sys +import tarfile +from pathlib import Path +from typing import Any + +from oci_ui import translate + + +class RuntimeResolutionError(RuntimeError): + pass + + +def _member(archive: tarfile.TarFile, name: str) -> tarfile.TarInfo: + for item in archive.getmembers(): + if item.name.lstrip("./") == name: + return item + raise RuntimeResolutionError(f"{translate('Not found in the OCI archive:')} {name}") + + +def _json_member(archive: tarfile.TarFile, name: str) -> dict[str, Any]: + source = archive.extractfile(_member(archive, name)) + if source is None: + raise RuntimeResolutionError(f"{translate('Cannot read')} {name}") + value = json.load(source) + if not isinstance(value, dict): + raise RuntimeResolutionError(f"{translate('Not a JSON object:')} {name}") + return value + + +def _blob_name(digest: str) -> str: + algorithm, separator, value = digest.partition(":") + if separator != ":" or algorithm != "sha256" or len(value) != 64: + raise RuntimeResolutionError(f"{translate('Unsupported OCI digest:')} {digest}") + return f"blobs/sha256/{value}" + + +def image_entrypoint(archive_path: Path) -> list[str]: + with tarfile.open(archive_path, mode="r:*") as archive: + index = _json_member(archive, "index.json") + manifests = index.get("manifests") or [] + if len(manifests) != 1: + raise RuntimeResolutionError(translate("The OCI archive does not contain exactly one manifest")) + manifest = _json_member(archive, _blob_name(str(manifests[0]["digest"]))) + config = _json_member(archive, _blob_name(str(manifest["config"]["digest"]))) + entrypoint = (config.get("config") or {}).get("Entrypoint") or [] + if isinstance(entrypoint, str): + return [entrypoint] + if not isinstance(entrypoint, list) or not all(isinstance(item, str) for item in entrypoint): + raise RuntimeResolutionError(translate("Invalid OCI Entrypoint")) + return entrypoint + + +def _arguments(value: Any, label: str) -> list[str]: + if isinstance(value, str): + return shlex.split(value) + if isinstance(value, list) and all(isinstance(item, str) for item in value): + return value + raise RuntimeResolutionError(f"{translate('The Compose value must be text or a list:')} {label}") + + +def effective_entrypoint( + archive_path: Path, + command: Any, + compose_entrypoint: Any = None, +) -> str: + entrypoint = ( + image_entrypoint(archive_path) + if compose_entrypoint is None + else _arguments(compose_entrypoint, "entrypoint") + ) + if command is None: + arguments: list[str] = [] + elif isinstance(command, str): + arguments = shlex.split(command) + elif isinstance(command, list) and all(isinstance(item, str) for item in command): + arguments = command + else: + raise RuntimeResolutionError(f"{translate('The Compose value must be text or a list:')} command") + process = entrypoint + arguments + if not process: + raise RuntimeResolutionError(translate("The Entrypoint/Cmd combination is empty")) + return " ".join(shlex.quote(item) for item in process) + + +def main() -> int: + if len(sys.argv) not in (3, 4): + print( + f"{translate('Usage:')} {sys.argv[0]} OCI_ARCHIVE COMMAND_JSON [ENTRYPOINT_JSON]", + file=sys.stderr, + ) + return 2 + try: + command = json.loads(sys.argv[2]) + compose_entrypoint = json.loads(sys.argv[3]) if len(sys.argv) == 4 else None + print(effective_entrypoint(Path(sys.argv[1]), command, compose_entrypoint)) + except (OSError, tarfile.TarError, json.JSONDecodeError, KeyError, RuntimeResolutionError) as exc: + print(f"{translate('Cannot apply the Compose command:')} {exc}", file=sys.stderr) + return 1 + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/oci/remote/oci_runtime_settings.py b/oci/remote/oci_runtime_settings.py new file mode 100644 index 00000000..e04b1dfc --- /dev/null +++ b/oci/remote/oci_runtime_settings.py @@ -0,0 +1,115 @@ +"""Validate declared volatile mounts and native network sysctl includes.""" +import os +from pathlib import Path +import re +import stat +import tempfile + +from oci_ui import translate + + +def sysctl_content(deployment): + result = [] + seen = set() + for item in deployment.get('security', {}).get('sysctls', []): + name, value = item['name'], str(item['value']) + if (not re.fullmatch(r'net\.(ipv4|ipv6)\.[A-Za-z0-9_.-]+', name) + or name in seen or not value or any(ord(c) < 32 or ord(c) == 127 for c in value)): + raise ValueError(translate('Invalid or duplicated network sysctl')) + seen.add(name) + result.append(f'lxc.sysctl.{name} = {value}\n') + return ''.join(result) + + +def tmpfs_lines(deployment): + result = [] + targets = set() + persistent = [m['container_path'].rstrip('/') for m in deployment.get('mounts', [])] + for item in deployment.get('tmpfs_mounts', []): + target, size = item['container_path'], item['size_mb'] + if (not re.fullmatch(r'/[A-Za-z0-9_./-]+', target) or '..' in target.split('/') + or '//' in target or target.endswith('/') or target in ('/etc','/usr','/bin','/lib','/lib64','/sbin','/proc','/sys','/dev','/run') + or not (target.startswith(('/run/', '/tmp/', '/var/cache/')) or target == '/dev/shm') + or isinstance(size, bool) or not isinstance(size, int) or size < 1): + raise ValueError(translate('The tmpfs path or size is outside the supported profile')) + if any(target == p or target.startswith(p+'/') or p.startswith(target+'/') for p in [*persistent,*targets]): + raise ValueError(translate('A tmpfs mount overlaps another mount')) + options = item.get('mount_options', []) + if not options or any(not re.fullmatch(r'rw|ro|nosuid|nodev|noexec|mode=0[0-7]{3}', opt) for opt in options): + raise ValueError(translate('Unsupported tmpfs options')) + if len(options) != len(set(options)) or ('rw' in options and 'ro' in options): + raise ValueError(translate('Contradictory tmpfs options')) + targets.add(target) + result.append(f'tmpfs {target.lstrip("/")} tmpfs {",".join(options)},size={size}M,create=dir 0 0') + return result + + +def include_path(vmid): + return Path(f'/etc/pve/lxc/{int(vmid)}.proxmenux-sysctls') + + +def check(config, deployment, vmid): + expected = tmpfs_lines(deployment) + lines = config.decode().splitlines() + actual = [line.split(': ',1)[1] for line in lines if line.startswith('lxc.mount.entry: tmpfs ')] + if sorted(actual) != sorted(expected): + raise ValueError(translate('The tmpfs mounts of the container differ from the saved record')) + includes = [line.split(': ',1)[1] for line in lines if line.startswith('lxc.include: ')] + content = sysctl_content(deployment) + if includes != ([str(include_path(vmid))] if content else []): + raise ValueError(translate('The sysctl include is unknown or differs from the saved record')) + if content: + path = include_path(vmid) + info = path.lstat() + if not stat.S_ISREG(info.st_mode) or info.st_uid != 0 or info.st_mode & 0o022: + raise ValueError(translate('The sysctl include is not a safe host file')) + if path.read_text() != content: + raise ValueError(translate('The sysctl content was modified outside the saved record')) + + +def filter_config(config, deployment): + declared = set(tmpfs_lines(deployment)) + return b''.join(line for line in config.splitlines(keepends=True) + if not line.startswith(b'lxc.include: ') and not ( + line.startswith(b'lxc.mount.entry: ') + and line.decode().strip().split(': ',1)[1] in declared)) + + +def check_recovery(config, state): + plans = [state.get(key, {}).get('deployment', {}) for key in ('record', 'candidate_contract')] + permitted = {line for plan in plans for line in tmpfs_lines(plan)} + for line in config.decode().splitlines(): + if line.startswith('lxc.mount.entry: tmpfs ') and line.split(': ', 1)[1] not in permitted: + raise ValueError(translate('A tmpfs mount is not part of the journal; recovery blocked')) + if line.startswith('lxc.include: '): + path = include_path(state['vmid']) + if line.split(': ', 1)[1] != str(path): + raise ValueError(translate('An include is not part of the journal; recovery blocked')) + contents = {sysctl_content(plan) for plan in plans} - {''} + info = path.lstat() + if (not stat.S_ISREG(info.st_mode) or info.st_uid != 0 or info.st_mode & 0o022 + or path.read_text() not in contents): + raise ValueError(translate('An include was modified outside the journal; recovery blocked')) + + +def restore(deployment, vmid): + content = sysctl_content(deployment) + if not content: + return + path = include_path(vmid) + if path.is_symlink(): + raise ValueError(translate('The sysctl include is not restored over a symbolic link')) + fd, temporary = tempfile.mkstemp(dir=path.parent, prefix='.oci-sysctl-') + try: + with os.fdopen(fd, 'w') as output: + output.write(content) + output.flush() + os.fsync(output.fileno()) + # pmxcfs uses fixed permissions; ordinary filesystem fixtures still + # receive an explicit restrictive mode. + if path.parent != Path('/etc/pve/lxc'): + os.chmod(temporary, 0o640) + os.replace(temporary, path) + finally: + if os.path.exists(temporary): + os.unlink(temporary) diff --git a/oci/remote/oci_stack_native.py b/oci/remote/oci_stack_native.py new file mode 100644 index 00000000..d1e19ea4 --- /dev/null +++ b/oci/remote/oci_stack_native.py @@ -0,0 +1,720 @@ +#!/usr/bin/env python3 +"""Native, coordinated updates of portable generic OCI stacks on the local node.""" +import argparse +import copy +import json +import os +from pathlib import Path +import socket +import stat +import subprocess +import time +import uuid + +import oci_image_cache as image_cache +import oci_instances as instances +import oci_instance_transaction as member_tx +import oci_stack_plan +import oci_stack_transaction as stack_tx +import oci_stack_replay as replay +from oci_installation_state import image_from_archive, parse_config, private_directory, sha +from oci_update_current import resolve_archive +from oci_ui import translate, msg_info, msg_ok, msg_warn, msg_error + + +def validate_database_transition(previous, candidate): + def major(image): + values = image.get('defaults', {}).get('Env') or [] + return next((value.split('=', 1)[1] for value in values + if isinstance(value, str) and value.startswith('PG_MAJOR=')), None) + old, new = major(previous), major(candidate) + if old is not None and old != new: + raise ValueError(translate('The new image changes the PostgreSQL major version; the data must be migrated before updating')) + + +def nextcloud_plan(primary, records, inventory, lifecycle): + """Translate only the known three-member stack and retain rollback contracts.""" + intent = primary.get('native_stack_intent', {}) + if intent.get('adapter', {}).get('name') != 'install_nextcloud_stack.sh': + raise ValueError(f"{translate('Unrecognized stack adapter:')} Nextcloud") + translated = {vmid: replay.nextcloud_record(record) for vmid, record in records.items()} + roles = {record['deployment']['replay_profile']['role']: vmid + for vmid, record in translated.items()} + if len(translated) != 3 or set(roles) != {'application', 'cache', 'database'} or roles['application'] != primary['vmid']: + raise ValueError(f"{translate('Unrecognized stack structure:')} Nextcloud") + dependencies = lifecycle.get('dependencies', []) + if (lifecycle.get('schema') != 1 + or [d.get('vmid') for d in dependencies] != [roles['database'], roles['cache']]): + raise ValueError(f"{translate('Unrecognized dependency order of the stack:')} Nextcloud") + services = [{'vmid': d['vmid'], 'name': d['label'], 'healthcheck': copy.deepcopy(d['healthcheck'])} + for d in dependencies] + services.append({'vmid': primary['vmid'], 'name': 'Nextcloud', 'healthcheck': { + 'type': 'exec', 'timeout_seconds': 600, 'argv': ['php', '-r', + '$s=json_decode(file_get_contents("http://127.0.0.1/status.php"),true);' + 'exit(is_array($s)&&!empty($s["installed"])&&empty($s["maintenance"])' + '&&empty($s["needsDbUpgrade"])?0:1);']}}) + parent = translated[primary['vmid']] + parent['stack']['deployment']['services'] = services + parent['stack']['members'] = [] + for service in services: + snapshot = copy.deepcopy(translated[service['vmid']]) + snapshot.pop('stack', None) + parent['stack']['members'].append(snapshot) + plan = oci_stack_plan.build(parent, translated, inventory, 'update') + plan['original_members'] = copy.deepcopy(list(records.values())) + plan['nextcloud_replay'] = True + return plan + + +def paperless_plan(primary, records, inventory, lifecycle): + """Prepare the known Paperless stack without publishing translated recipes.""" + if primary.get('native_stack_intent', {}).get('adapter', {}).get('name') != 'install_paperless_stack.sh': + raise ValueError(f"{translate('Unrecognized stack adapter:')} Paperless") + translated = {vmid: replay.paperless_record(record) for vmid, record in records.items()} + roles = {r['deployment']['replay_profile']['role']: vmid for vmid, r in translated.items()} + if len(translated) != 3 or set(roles) != {'application', 'database', 'broker'} or roles['application'] != primary['vmid']: + raise ValueError(f"{translate('Unrecognized stack structure:')} Paperless") + dependencies = lifecycle.get('dependencies', []) + if lifecycle.get('schema') != 1 or [d.get('vmid') for d in dependencies] != [roles['database'], roles['broker']]: + raise ValueError(f"{translate('Unrecognized dependency order of the stack:')} Paperless") + services = [{'vmid': d['vmid'], 'name': d['label'], 'healthcheck': copy.deepcopy(d['healthcheck'])} + for d in dependencies] + services.append({'vmid': primary['vmid'], 'name': 'Paperless', 'healthcheck': { + 'type': 'exec', 'timeout_seconds': 600, 'argv': ['python3', '-c', + 'import urllib.request; urllib.request.urlopen("http://127.0.0.1:8000/", timeout=10).read(1)']}}) + parent = translated[primary['vmid']] + parent['stack']['deployment']['services'] = services + parent['stack']['members'] = [] + for service in services: + snapshot = copy.deepcopy(translated[service['vmid']]) + snapshot.pop('stack', None) + parent['stack']['members'].append(snapshot) + plan = oci_stack_plan.build(parent, translated, inventory, 'update') + plan['original_members'] = copy.deepcopy(list(records.values())) + plan['paperless_replay'] = True + return plan + + +def tandoor_plan(primary, records, inventory, lifecycle): + """Prepare exactly the application and PostgreSQL without publishing state.""" + if primary.get('native_stack_intent', {}).get('adapter', {}).get('name') != 'install_tandoor_stack.sh': + raise ValueError(f"{translate('Unrecognized stack adapter:')} Tandoor") + translated = {vmid: replay.tandoor_record(record) for vmid, record in records.items()} + roles = {r['deployment']['replay_profile']['role']: vmid for vmid, r in translated.items()} + if len(translated) != 2 or set(roles) != {'application', 'database'} or roles['application'] != primary['vmid']: + raise ValueError(f"{translate('Unrecognized stack structure:')} Tandoor") + dependencies = lifecycle.get('dependencies', []) + if lifecycle.get('schema') != 1 or [d.get('vmid') for d in dependencies] != [roles['database']]: + raise ValueError(f"{translate('Unrecognized dependency order of the stack:')} Tandoor") + services = [{'vmid': d['vmid'], 'name': d['label'], 'healthcheck': copy.deepcopy(d['healthcheck'])} + for d in dependencies] + services.append({'vmid': primary['vmid'], 'name': 'Tandoor', 'healthcheck': { + 'type': 'exec', 'timeout_seconds': 600, 'argv': ['python3', '-c', + 'import urllib.request; urllib.request.urlopen("http://127.0.0.1/", timeout=10).read(1)']}}) + parent = translated[primary['vmid']] + parent['stack']['deployment']['services'] = services + parent['stack']['members'] = [] + for service in services: + snapshot = copy.deepcopy(translated[service['vmid']]) + snapshot.pop('stack', None) + parent['stack']['members'].append(snapshot) + plan = oci_stack_plan.build(parent, translated, inventory, 'update') + plan['original_members'] = copy.deepcopy(list(records.values())) + plan['tandoor_replay'] = True + return plan + + +def immich_plan(primary, records, inventory, lifecycle): + if primary.get('native_stack_intent', {}).get('adapter', {}).get('name') != 'install_immich_stack.sh': + raise ValueError(f"{translate('Unrecognized stack adapter:')} Immich") + translated = {vmid: replay.immich_record(record) for vmid, record in records.items()} + roles = {r['deployment']['replay_profile']['role']: vmid for vmid, r in translated.items()} + if len(translated) != 4 or set(roles) != {'server', 'database', 'valkey', 'machine-learning'} or roles['server'] != primary['vmid']: + raise ValueError(f"{translate('Unrecognized stack structure:')} Immich") + dependencies = lifecycle.get('dependencies', []) + if lifecycle.get('schema') != 1 or [d.get('vmid') for d in dependencies] != [roles['database'], roles['valkey'], roles['machine-learning']]: + raise ValueError(f"{translate('Unrecognized dependency order of the stack:')} Immich") + services = [{'vmid': d['vmid'], 'name': d['label'], 'healthcheck': copy.deepcopy(d['healthcheck'])} for d in dependencies] + services.append({'vmid': primary['vmid'], 'name': 'Immich', 'healthcheck': { + 'type': 'exec', 'timeout_seconds': 600, 'argv': ['node', '-e', + 'fetch("http://127.0.0.1:2283/api/server/ping").then(r=>{if(!r.ok)process.exit(1)}).catch(()=>process.exit(1))']}}) + parent = translated[primary['vmid']] + parent['stack']['deployment']['services'] = services + parent['stack']['members'] = [] + for service in services: + snapshot = copy.deepcopy(translated[service['vmid']]) + snapshot.pop('stack', None) + parent['stack']['members'].append(snapshot) + plan = oci_stack_plan.build(parent, translated, inventory, 'update') + plan['original_members'] = copy.deepcopy(list(records.values())) + plan['immich_replay'] = True + return plan + + +class NativeAdapter: + def __init__(self, root, journal, plan, acknowledge_external_data=False): + self.root, self.journal, self.plan = root, Path(journal), plan + self.records = {m['vmid']: copy.deepcopy(m) for m in plan['members']} + self.original_records = {m['vmid']: copy.deepcopy(m) + for m in plan.get('original_members', plan['members'])} + primary = self.records[plan['primary_vmid']] + self.services = {s['vmid']: s for s in primary['stack']['deployment']['services']} + self.acknowledge = acknowledge_external_data + + def state(self): + return json.loads(self.journal.read_text()) + + def describe(self, vmid): + name = self.services.get(vmid, {}).get('name') + return f'{name} (CT {vmid})' if name else f'CT {vmid}' + + def validate(self, plan): + resources = json.loads(instances.command('pvesh', 'get', '/cluster/resources', + '--type', 'vm', '--output-format', 'json')) + if not isinstance(resources, list): + raise ValueError(translate('Incomplete Proxmox inventory')) + inventory = {} + for row in resources: + if (not isinstance(row, dict) or type(row.get('vmid')) is not int + or row.get('type') not in ('lxc', 'qemu')): + raise ValueError(translate('Invalid Proxmox inventory')) + if row['vmid'] in inventory: + raise ValueError(translate('Duplicated VMID in the Proxmox inventory')) + inventory[row['vmid']] = row + for vmid, record in self.records.items(): + row = inventory.get(vmid) + if row: + if row['type'] != 'lxc' or row.get('node') != socket.gethostname().split('.')[0]: + raise ValueError(translate('A member VMID is in use by another guest or is on another node')) + config = instances.command('pct', 'config', str(vmid)) + if instances.identity(config) != record['installation_id']: + raise ValueError(translate('The identity of a member was replaced')) + if (not self.journal.exists() or not self.state().get('replacement_intent')) and sha(config) != record['observed']['config_sha256']: + raise ValueError(translate('A member configuration changed during the preparation')) + else: + if Path('/etc/pve/lxc/%s.conf' % vmid).exists(): + raise ValueError(translate('The Proxmox inventory and the local configurations differ')) + if not self.journal.exists() or not self.state().get('replacement_intent'): + raise ValueError(translate('A member is missing before the replacement')) + current = instances.read(self.root, vmid) + if current['installation_id'] != record['installation_id']: + raise ValueError(translate('The record belongs to another container')) + pending = current.get('pending_stack_transaction') + if pending and pending != str(self.journal): + raise ValueError(translate('Another stack operation is pending')) + + def preflight(self): + self.validate(self.plan) + ha = json.loads(instances.command('pvesh', 'get', '/cluster/ha/resources', '--output-format', 'json')) + if not isinstance(ha, list) or any(r.get('sid') == 'ct:%s' % vmid for r in ha for vmid in self.records): + raise ValueError(translate('High availability resources are not supported for stacks')) + for vmid, record in self.records.items(): + if record.get('pending_transaction') or record.get('pending_stack_transaction'): + raise ValueError(translate('A member has a pending operation')) + if record['deployment'].get('post_start_configurations'): + raise ValueError(translate('The recipe requires configuration at startup; its coordinated replay is not available')) + config = instances.command('pct', 'config', str(vmid)) + member_tx.preflight(record, record, config, coordinated=True) + member_tx.freeze_host_sources(record, record, self.acknowledge) + check = self.services[vmid].get('healthcheck', {}) + if check.get('type') not in ('exec', 'http', 'running'): + raise ValueError(translate('A member has no reproducible service check')) + if check['type'] == 'exec' and not check.get('argv'): + raise ValueError(translate('Empty exec service check')) + if check['type'] == 'exec' and (not isinstance(check['argv'], list) + or any(not isinstance(arg, str) or not arg or '\0' in arg for arg in check['argv'])): + raise ValueError(translate('Invalid service check arguments')) + if check['type'] == 'http' and not check.get('url'): + raise ValueError(translate('HTTP service check without a saved URL')) + if check['type'] == 'http' and not check['url'].startswith(('http://', 'https://')): + raise ValueError(translate('Invalid service check URL')) + if not 0 < int(check.get('timeout_seconds', 120)) <= 3600: + raise ValueError(translate('Invalid service check timeout')) + primary_id = self.plan['primary_vmid'] + cfg = parse_config(instances.command('pct', 'config', str(primary_id))) + volume = cfg.get('hookscript', '') + if not volume.endswith(':snippets/proxmenux-stack-dependencies.sh'): + raise ValueError(translate('The stack does not have the expected native hook')) + hook = Path(instances.command('pvesm', 'path', volume).decode().strip()) + info = hook.lstat() + if (not stat.S_ISREG(info.st_mode) or info.st_uid != 0 or info.st_mode & 0o022 + or hook.read_bytes() != Path(__file__).with_name('stack_dependency_hook.sh').read_bytes()): + raise ValueError(translate('The dependency hook was modified; review it before updating')) + lifecycle = Path('/etc/pve/priv/proxmenux-stack-%s.json' % primary_id) + info = lifecycle.lstat() + if not stat.S_ISREG(info.st_mode) or info.st_uid != 0 or info.st_mode & 0o077: + raise ValueError(translate('Unsafe dependency hook contract')) + spec = json.loads(lifecycle.read_text()) + expected = [{'vmid': s['vmid'], 'label': s['name'], 'healthcheck': s['healthcheck']} + for s in self.services.values() if s['vmid'] != primary_id and not s.get('deferred_setup')] + if spec.get('schema') != 1 or spec.get('dependencies') != expected: + raise ValueError(translate('The dependency hook and the stack recipe differ')) + member_tx.require_backup_space(self.journal.parent, list(self.records)) + + def is_running(self, vmid): + return instances.command('pct', 'status', str(vmid)).strip() == b'status: running' + + def prepare(self, record, operation): + for vmid in self.records: + current = instances.read(self.root, vmid) + current['pending_stack_transaction'] = str(self.journal) + instances.write(instances.location(self.root, vmid), current) + config = instances.command('pct', 'config', str(record['vmid'])) + archive, digest = resolve_archive(record, config) + image = image_from_archive(str(archive)) + old = record['observed']['image'] + validate_database_transition(old, image) + if image['architecture'] != old['architecture'] or image['os'] != 'linux': + raise ValueError(translate('Incompatible image platform')) + paths = [m['container_path'] for m in record['deployment'].get('mounts', [])] + if any(not any(p == target or p.startswith(target.rstrip('/') + '/') for target in paths) + for p in (image['defaults'].get('Volumes') or {})): + raise ValueError(translate('The new image requires additional persistent paths')) + profile = record['deployment'].get('replay_profile', {}) + if profile.get('adapter') in ('install_nextcloud_stack.sh', 'install_paperless_stack.sh', 'install_tandoor_stack.sh', 'install_immich_stack.sh'): + msg_info(f"{translate('Checking the new image without starting it:')} {self.describe(record['vmid'])}") + self.probe_nextcloud_image(record, archive, image) + msg_ok(f"{translate('New image compatible:')} {self.describe(record['vmid'])}") + return {'archive': str(archive), 'digest': digest} + + def probe_nextcloud_image(self, record, archive, image): + """Import but never start a disposable rootfs before stopping the stack.""" + vmid = int(instances.command('pvesh', 'get', '/cluster/nextid').strip()) + marker = 'proxmenux-image-probe=' + uuid.uuid4().hex + directory = self.journal.parent / 'image-probes' + private_directory(directory) + descriptor = directory / ('%s.json' % vmid) + instances.write(descriptor, {'vmid': vmid, 'marker': marker}) + mounted = False + try: + member_tx.log('image probe: CT %s' % record['vmid']) + root = record['deployment']['rootfs'] + member_tx.run('pct', 'create', str(vmid), str(archive), '--rootfs', + '%s:%s' % (root['storage'], root['size_gb']), '--hostname', 'oci-image-probe', + '--ostype', 'unmanaged', '--unprivileged', '1', '--memory', '128', + '--cores', '1', '--onboot', '0', '--description', marker) + member_tx.owned(vmid, marker) + member_tx.run('pct', 'mount', str(vmid)) + mounted = True + profile = record['deployment']['replay_profile'] + check = {'install_paperless_stack.sh': replay.paperless_prerequisites, + 'install_nextcloud_stack.sh': replay.nextcloud_prerequisites, + 'install_tandoor_stack.sh': replay.tandoor_prerequisites, + 'install_immich_stack.sh': replay.immich_prerequisites}[profile['adapter']] + check(Path('/var/lib/lxc') / str(vmid) / 'rootfs', profile['role'], image) + finally: + if mounted: + member_tx.run('pct', 'unmount', str(vmid)) + if Path('/etc/pve/lxc/%s.conf' % vmid).exists(): + member_tx.owned(vmid, marker) + member_tx.run('pct', 'destroy', str(vmid)) + descriptor.unlink() + + def stop(self, vmid): + self.validate(self.plan) + if Path('/etc/pve/lxc/%s.conf' % vmid).exists(): + member_tx.stop(vmid) + + def backup(self, vmid, identity): + self.validate(self.plan) + directory = self.journal.parent / ('backup-%s' % vmid) + private_directory(directory) + member_tx.run('vzdump', str(vmid), '--mode', 'stop', '--compress', 'zstd', + '--dumpdir', str(directory), '--tmpdir', '/var/tmp') + backups = list(directory.glob('vzdump-lxc-*.tar.zst')) + if len(backups) != 1: + raise ValueError(translate('The backup of a member could not be identified')) + member_tx.run('zstd', '-t', str(backups[0])) + return {'archive': str(backups[0]), 'sha256': member_tx.filehash(backups[0])} + + def verify_backups(self, backups): + for backup in backups.values(): + if member_tx.filehash(backup['archive']) != backup['sha256']: + raise ValueError(translate('A backup was modified')) + member_tx.run('zstd', '-t', backup['archive']) + + def replace(self, vmid, prepared, identity): + self.validate(self.plan) + state = self.state() + context = {'journal': str(self.journal), 'id': identity, + 'backup': state['backups'][str(vmid)]} + if self.plan.get('nextcloud_replay'): + context.update(nextcloud_replay=True, effective_record=self.records[vmid]) + if self.plan.get('paperless_replay'): + context.update(paperless_replay=True, effective_record=self.records[vmid]) + if self.plan.get('tandoor_replay'): + context.update(tandoor_replay=True, effective_record=self.records[vmid]) + if self.plan.get('immich_replay'): + context.update(immich_replay=True, effective_record=self.records[vmid]) + member_tx.apply(self.root, vmid, Path(prepared['archive']), 'update', + registry_digest=prepared['digest'], acknowledge_external_data=self.acknowledge, + coordinated=context, progress=f"{translate('Updating')} {self.describe(vmid)}:") + + def start(self, vmid): + self.validate(self.plan) + if not self.is_running(vmid): + member_tx.run('pct', 'start', str(vmid)) + + def healthcheck(self, vmid): + check = self.services[vmid]['healthcheck'] + timeout = int(check.get('timeout_seconds', 120)) + if not 0 < timeout <= 3600: + raise ValueError(translate('Invalid service check timeout')) + deadline = time.monotonic() + timeout + while time.monotonic() < deadline: + if not self.is_running(vmid): + raise ValueError(f"{translate('A member stopped:')} {self.describe(vmid)}") + try: + if check['type'] == 'exec': + member_tx.run('pct', 'exec', str(vmid), '--', *check['argv']) + elif check['type'] == 'http': + member_tx.run('curl', '-fsS', '--noproxy', '*', '--max-time', '5', check['url']) + member_tx.gpu_devices.validate_runtime(vmid, self.records[vmid]['deployment']) + deployment = self.records[vmid]['deployment'] + if deployment.get('replay_profile') == {'adapter': 'install_immich_stack.sh', 'role': 'machine-learning'}: + acceleration = deployment.get('machine_learning', {}).get('acceleration', 'cpu') + if acceleration in ('openvino', 'cuda'): + member_tx.run('pct', 'exec', str(vmid), '--', 'python', '-c', + 'import sys,ctypes,onnxruntime as ort; p=sys.argv[1]; ' + 'assert ("OpenVINOExecutionProvider" if p=="openvino" else "CUDAExecutionProvider") ' + 'in ort.get_available_providers(); ' + 'assert (any(d.startswith("GPU") for d in ort.capi._pybind_state.get_available_openvino_device_ids()) ' + 'if p=="openvino" else ctypes.CDLL("libcuda.so.1").cuInit(0)==0)', acceleration) + return + except RuntimeError: + time.sleep(2) + raise ValueError(f"{translate('A member did not pass its service check:')} {self.describe(vmid)}") + + def validate_candidates(self, state): + self.validate(self.plan) + for vmid, original in self.records.items(): + current = instances.read(self.root, vmid) + journal = Path(current['pending_transaction']) + child = json.loads(journal.read_text()) + if child.get('coordinated', {}).get('id') != state['id']: + raise ValueError(translate('A member operation does not belong to the stack')) + config = instances.command('pct', 'config', str(vmid)) + if sha(config) != child.get('staged_config_sha256'): + raise ValueError(translate('The configuration of a new member changed after it was created')) + member_tx.check_runtime_mounts(config, original['deployment']) + member_tx.gpu_devices.check(config, original['deployment']) + child['candidate_host_sources'] = member_tx.candidate_host_sources(journal, child) + child['validated_config_sha256'] = sha(config) + instances.write(journal, child) + + def restore_running_state(self, running, order): + for vmid in order: + if running[str(vmid)]: + self.start(vmid) + for vmid in order: + if running[str(vmid)]: + self.healthcheck(vmid) + # Starting the primary can start dependencies through its native hook. + for vmid in reversed(order): + if not running[str(vmid)]: + self.stop(vmid) + if not self.state()['replacement_intent']: + self.restore_contracts(self.plan, self.state()['id']) + + def publish(self, state): + for vmid, original in self.records.items(): + current = instances.read(self.root, vmid) + journal = Path(current['pending_transaction']) + child = json.loads(journal.read_text()) + before = member_tx.owned(vmid, original['installation_id']) + if sha(before) != child.get('validated_config_sha256'): + raise ValueError(translate('A member configuration changed after the stack was checked')) + # Keep child journals available even if publication is interrupted. + links = self.journal.parent / ('member-%s.json' % vmid) + instances.write(links, {'journal': str(journal)}) + member_tx.run('pct', 'set', str(vmid), '--onboot', '1' if original['deployment']['onboot'] else '0') + after = member_tx.owned(vmid, original['installation_id']) + if ([line for line in before.splitlines() if not line.startswith(b'onboot: ')] + != [line for line in after.splitlines() if not line.startswith(b'onboot: ')]): + raise ValueError(translate('Concurrent change while restoring the start at boot setting')) + child['validated_config_sha256'] = sha(after) + member_tx.checkpoint(journal, child, 'health-passed') + member_tx.commit(self.root, journal, child) + primary_id = self.plan['primary_vmid'] + primary = instances.read(self.root, primary_id) + primary['stack']['members'] = [] + for vmid in self.plan['start_order']: + record = instances.read(self.root, vmid) + record.pop('stack', None) + record.pop('pending_stack_transaction', None) + primary['stack']['members'].append(record) + instances.write(instances.location(self.root, primary_id), primary) + + def restore(self, vmid, backup, identity): + self.validate(self.plan) + original = self.records[vmid] + current = instances.read(self.root, vmid) + link = self.journal.parent / ('member-%s.json' % vmid) + child_path = current.get('pending_transaction') + if not child_path and link.exists(): + child_path = json.loads(link.read_text())['journal'] + if child_path: + journal = Path(child_path) + synthetic = self.journal.parent / ('recovery-%s' % vmid) / 'transaction.json' + if (not journal.resolve().is_relative_to(instances.location(self.root, vmid).parent.resolve()) + and journal.resolve() != synthetic.resolve()): + raise ValueError(translate('The member journal is outside the registry')) + child = json.loads(journal.read_text()) + if child.get('coordinated', {}).get('id') != identity: + raise ValueError(translate('The member journal belongs to another stack operation')) + if child['phase'] == 'rolled-back': + if sha(member_tx.owned(vmid, original['installation_id'])) != child['restore_config_sha256']: + raise ValueError(translate('A member was modified after it was recovered')) + member_tx.cleanup_restored_format_dirs(vmid, original['deployment'], original['installation_id']) + return + else: + directory = self.journal.parent / ('recovery-%s' % vmid) + private_directory(directory) + journal = directory / 'transaction.json' + if journal.exists(): + child = json.loads(journal.read_text()) + else: + sources, _ = member_tx.freeze_host_sources(original, original, self.acknowledge) + child = {'id': uuid.uuid4().hex, 'vmid': vmid, 'record': original, + 'candidate_contract': original, 'before_config': original['observed']['config'], + 'backup': backup['archive'], 'backup_sha256': backup['sha256'], + 'backup_compression': 'zstd', 'was_running': False, + 'original_host_sources': sources, + 'original_gpu_devices': member_tx.gpu_devices.planned(original['deployment']), + 'coordinated': {'id': identity}, 'phase': 'backup-ready'} + instances.write(journal, child) + instances.write(link, {'journal': str(journal)}) + if not child.get('stage'): + child['stage'] = int(instances.command('pvesh', 'get', '/cluster/nextid').strip()) + instances.write(journal, child) + stage = child['stage'] + if not Path('/etc/pve/lxc/%s.conf' % stage).exists(): + archive = self.state()['prepared'][str(vmid)]['archive'] + member_tx.run('pct', 'create', str(stage), archive, '--rootfs', + '%s:%s' % (original['deployment']['rootfs']['storage'], original['deployment']['rootfs']['size_gb']), + '--hostname', 'oci-stack-recovery-holder', '--ostype', 'unmanaged', + '--unprivileged', '1', '--memory', '128', '--cores', '1', '--onboot', '0', + '--description', 'proxmenux-transaction=' + child['id']) + pending = copy.deepcopy(original) + pending.update(status='updating', pending_transaction=str(journal), transaction_id=child['id'], + pending_stack_transaction=str(self.journal)) + instances.write(instances.location(self.root, vmid), pending) + child['record'] = copy.deepcopy(child['record']) + child['record']['pending_stack_transaction'] = str(self.journal) + child.update(backup=backup['archive'], backup_sha256=backup['sha256'], backup_compression='zstd') + child['phase'] = 'backup-ready' + instances.write(journal, child) + member_tx.recover(self.root, journal) + + def restore_contracts(self, plan, identity): + self.validate(plan) + for vmid, original in self.original_records.items(): + record = copy.deepcopy(original) + config = member_tx.owned(vmid, record['installation_id']) + record['observed'] = instances.observe(vmid, record['installation_id'], + original['observed']['archive_path'], original['observed']['resolved_registry_digest'], + original['observed']['image']) + if any(self.plan.get(flag) for flag in ('nextcloud_replay', 'paperless_replay', 'tandoor_replay', 'immich_replay')): + record['deployment']['native_config'] = record['observed']['config'] + record['deployment']['member_replay_projection'] = replay.normalize(record) + record['pending_stack_transaction'] = str(self.journal) + instances.write(instances.location(self.root, vmid), record) + primary_id = plan['primary_vmid'] + primary = instances.read(self.root, primary_id) + snapshots = [] + for vmid in plan['start_order']: + snapshot = instances.read(self.root, vmid) + snapshot.pop('stack', None) + snapshot.pop('pending_stack_transaction', None) + snapshots.append(snapshot) + primary['stack']['members'] = snapshots + instances.write(instances.location(self.root, primary_id), primary) + + def finalize(self, state): + if state['phase'] not in stack_tx.TERMINAL: + raise ValueError(translate('The stack operation has not finished yet')) + self.validate(self.plan) + probes = self.journal.parent / 'image-probes' + if probes.exists(): + for descriptor in probes.glob('*.json'): + probe = json.loads(descriptor.read_text()) + vmid, marker = probe['vmid'], probe['marker'] + if type(vmid) is not int or not marker.startswith('proxmenux-image-probe='): + raise ValueError(translate('Invalid image probe descriptor')) + if Path('/etc/pve/lxc/%s.conf' % vmid).exists(): + member_tx.owned(vmid, marker) + if self.is_running(vmid): + raise ValueError(translate('An image probe container was started externally')) + if os.path.ismount('/var/lib/lxc/%s/rootfs' % vmid): + member_tx.run('pct', 'unmount', str(vmid)) + member_tx.run('pct', 'destroy', str(vmid)) + descriptor.unlink() + # Clear the primary last so interrupted cleanup remains discoverable. + order = [vmid for vmid in self.records if vmid != self.plan['primary_vmid']] + order.append(self.plan['primary_vmid']) + for vmid in order: + record = instances.read(self.root, vmid) + record.pop('pending_stack_transaction', None) + instances.write(instances.location(self.root, vmid), record) + try: + self.release_stages() + self.prune_backups(include_current=state['phase'] == 'committed') + for path, _ in image_cache.prune(self.root, lock=False): + member_tx.log(f'removed unused image archive: {path}') + except (OSError, ValueError) as exc: + member_tx.log(f'cleanup: {exc}') + + def release_stages(self): + """The temporary containers that held the data of each member; one + that still has a disk attached is kept.""" + for vmid in self.records: + folder = instances.location(self.root, vmid).parent / 'transactions' + for member_journal in folder.glob('*/transaction.json'): + try: + state = json.loads(member_journal.read_text()) + except (OSError, ValueError): + continue + if (state.get('coordinated') or {}).get('journal') == str(self.journal): + member_tx.release_stage(state) + + def prune_backups(self, include_current): + """The backups of closed operations are removed, those of this one + when the stack works with its new images; journals and logs stay.""" + for directory in self.journal.parent.parent.iterdir(): + if ((directory == self.journal.parent and not include_current) + or directory.is_symlink() or not directory.is_dir()): + continue + try: + phase = json.loads((directory / 'transaction.json').read_text()).get('phase') + except (OSError, ValueError): + continue + if phase in stack_tx.TERMINAL: + for backup in directory.glob('backup-*/vzdump-lxc-*'): + if backup.is_file() and not backup.is_symlink(): + backup.unlink() + + +# The stack journal of this run, for the summary after a failure. +_current = {'journal': None, 'primary': None} + + +def run(vmid, recover=False, acknowledge_external_data=False): + root = instances.ROOT + msg_info(translate('Checking the interrupted stack operation...') if recover + else translate('Checking the stack before the update...')) + with instances.locked(root): + selected = instances.read(root, vmid) + primary_id = selected.get('stack_member', {}).get('primary_vmid', vmid) + primary = instances.read(root, primary_id) + _current['primary'] = primary_id + if recover: + journal = Path(primary['pending_stack_transaction']) + if not journal.resolve().is_relative_to(instances.location(root, primary_id).parent.resolve()): + raise ValueError(translate('The stack journal is outside the registry')) + member_tx.open_log(journal.parent) + _current['journal'] = journal + state = json.loads(journal.read_text()) + if state.get('plan', {}).get('primary_vmid') != primary_id: + raise ValueError(translate('The journal belongs to another stack')) + if any(mount['type'] == 'host-bind' for member in state['plan']['members'] + for mount in member.get('deployment', {}).get('mounts', [])) and not acknowledge_external_data: + raise ValueError(translate('Confirm that host data is not reverted')) + adapter = NativeAdapter(root, journal, state['plan'], acknowledge_external_data) + if state.get('phase') in stack_tx.TERMINAL: + msg_ok(translate('The stack operation had already finished')) + msg_info(translate('Completing its final cleanup...')) + result = stack_tx.execute(journal, adapter) + msg_ok(translate('Final cleanup of the stack operation completed')) + return result + msg_ok(translate('Interrupted stack operation found')) + result = stack_tx.execute(journal, adapter) + msg_ok(translate('Stack recovery completed; every member is back to its previous installation.')) + return result + records, inventory = {}, {} + for snapshot in primary['stack']['members']: + member_id = snapshot['vmid'] + records[member_id] = instances.read(root, member_id) + inventory[member_id] = instances.identity(instances.command('pct', 'config', str(member_id))) + adapter_name = primary.get('native_stack_intent', {}).get('adapter', {}).get('name') + builders = {'install_nextcloud_stack.sh': nextcloud_plan, + 'install_paperless_stack.sh': paperless_plan, + 'install_tandoor_stack.sh': tandoor_plan, + 'install_immich_stack.sh': immich_plan} + if adapter_name in builders: + lifecycle = Path('/etc/pve/priv/proxmenux-stack-%s.json' % primary_id) + info = lifecycle.lstat() + if not stat.S_ISREG(info.st_mode) or info.st_uid != 0 or info.st_mode & 0o077: + raise ValueError(translate('Unsafe dependency contract')) + builder = builders[adapter_name] + plan = builder(primary, records, inventory, json.loads(lifecycle.read_text())) + else: + plan = oci_stack_plan.build(primary, records, inventory, 'update') + stack_tx.validate_plan(plan) + directory = instances.location(root, primary_id).parent / 'stack-transactions' / uuid.uuid4().hex + private_directory(directory) + member_tx.open_log(directory) + journal = directory / 'transaction.json' + _current['journal'] = journal + adapter = NativeAdapter(root, journal, plan, acknowledge_external_data) + adapter.preflight() + msg_ok(f"{translate('Stack checked:')} {len(plan['members'])} {translate('containers')}") + if any(mount['type'] == 'host-bind' for member in plan['members'] + for mount in member.get('deployment', {}).get('mounts', [])): + msg_warn(translate('Host directories are not included in the backups and are not reverted by a recovery.')) + result = stack_tx.execute(journal, adapter, plan) + msg_ok(translate('Stack update completed. Data kept.')) + return result + + +def failure_summary(recovering): + """What state the stack was left in after a failure, and what to do next.""" + journal = _current['journal'] + if journal is None or not journal.exists(): + return + try: + state = json.loads(journal.read_text()) + except (OSError, ValueError): + state = {} + phase = state.get('phase') + try: + pending = instances.read(instances.ROOT, _current['primary']).get('pending_stack_transaction') == str(journal) + except (OSError, ValueError, KeyError): + pending = True + if phase == 'rolled-back': + if recovering or state.get('stop_intent'): + msg_warn(translate('Every member of the stack is back to its previous installation.')) + else: + msg_warn(translate('No container of the stack was modified.')) + elif phase == 'committed': + msg_warn(translate('The stack update was saved.')) + else: + msg_warn(translate('The stack operation stopped halfway. Select the stack again in the OCI management menu to recover it.')) + return + if pending: + msg_warn(translate('Its final cleanup did not complete. Select the stack again in the OCI management menu to complete it.')) + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('vmid', type=int) + parser.add_argument('--recover', action='store_true') + parser.add_argument('--acknowledge-external-data', action='store_true') + args = parser.parse_args() + if os.geteuid() != 0: + parser.error(translate('Root privileges on the Proxmox node are required')) + try: + run(args.vmid, args.recover, args.acknowledge_external_data) + return 0 + except BlockingIOError: + msg_error(translate('Another OCI operation is using the registry. This operation was not started.')) + return 1 + except (ValueError, RuntimeError, OSError, KeyError, subprocess.SubprocessError) as error: + # An error that started an automatic recovery was already shown before it. + if not getattr(error, 'oci_reported', False): + member_tx.report_error(error, f'stack-{args.vmid}') + failure_summary(args.recover) + return 1 + + +if __name__ == '__main__': + raise SystemExit(main()) diff --git a/oci/remote/oci_stack_plan.py b/oci/remote/oci_stack_plan.py new file mode 100644 index 00000000..42c0569c --- /dev/null +++ b/oci/remote/oci_stack_plan.py @@ -0,0 +1,61 @@ +"""Read-only validation of a coordinated stack operation, before host changes.""" +import copy + +from oci_ui import translate + + +def build(primary, records, inventory, operation): + """Inventory maps VMIDs to installation UUIDs, including unrelated guests. + + Missing members are reported, not authorized for creation: their persistent + volumes still require separate verification before any destructive operation. + """ + if operation not in ('update', 'recreate'): + raise ValueError(translate('Invalid stack operation')) + stack = primary.get('stack') + if not stack or not stack.get('members'): + raise ValueError(translate('This is not a coordinated stack')) + snapshots = stack['members'] + ids = [member['vmid'] for member in snapshots] + if any(type(vmid) is not int or vmid < 100 for vmid in ids) or len(set(ids)) != len(ids): + raise ValueError(translate('Duplicated or invalid stack VMID')) + if primary['vmid'] not in ids: + raise ValueError(translate('The main member of the stack is missing')) + if stack.get('id') != primary['installation_id']: + raise ValueError(translate('Inconsistent stack identity')) + services = stack.get('deployment', {}).get('services', []) + order = [service['vmid'] for service in services] + if len(order) != len(ids) or set(order) != set(ids): + raise ValueError(translate('Incomplete dependency order')) + members, missing, blockers = [], [], [] + for snapshot in snapshots: + vmid = snapshot['vmid'] + identity = snapshot['installation_id'] + current = records.get(vmid, snapshot) + if current.get('installation_id') != identity: + raise ValueError(f"{translate('The saved record was replaced for')} CT {vmid}") + membership = current.get('stack_member', {}) + if membership.get('stack_id') != stack['id'] or membership.get('primary_vmid') != primary['vmid']: + raise ValueError(f"{translate('Inconsistent stack membership for')} CT {vmid}") + if current.get('status') != 'installed': + raise ValueError(f"{translate('A pending operation exists for')} CT {vmid}") + if vmid in inventory: + if inventory[vmid] != identity: + raise ValueError(f"{translate('Another instance uses')} VMID {vmid}") + if vmid not in records: + raise ValueError(f"{translate('The current record is missing for')} CT {vmid}") + else: + missing.append(vmid) + if current.get('deployment', {}).get('rootfs_adaptation_replay_required'): + blockers.append({'vmid': vmid, 'reason': 'dedicated-adapter-replay-required'}) + members.append(copy.deepcopy(current)) + if missing and operation == 'update': + raise ValueError(translate('Stack members are missing; recreate them after verifying their volumes')) + dependencies = [vmid for vmid in order if vmid != primary['vmid']] + return { + 'operation': operation, 'primary_vmid': primary['vmid'], + 'members': members, 'missing_members': missing, + 'start_order': dependencies + [primary['vmid']], + 'stop_order': [primary['vmid']] + list(reversed(dependencies)), + 'blockers': blockers, 'volume_verification_required': bool(missing), + } diff --git a/oci/remote/oci_stack_replay.py b/oci/remote/oci_stack_replay.py new file mode 100644 index 00000000..b002fc77 --- /dev/null +++ b/oci/remote/oci_stack_replay.py @@ -0,0 +1,571 @@ +"""Capture only declared, generated rootfs adapters; never application data.""" +import hashlib +import copy +from pathlib import Path +import re +import stat +import shlex +import os + +from oci_ui import translate + + +def nextcloud_menu_ready(primary): + """Offer only captured members whose declared persistence is fully covered.""" + return captured_menu_ready(primary, 'install_nextcloud_stack.sh', nextcloud_record, + {'application', 'database', 'cache'}) + + +def paperless_menu_ready(primary): + return captured_menu_ready(primary, 'install_paperless_stack.sh', paperless_record, + {'application', 'database', 'broker'}) + + +def tandoor_menu_ready(primary): + return captured_menu_ready(primary, 'install_tandoor_stack.sh', tandoor_record, + {'application', 'database'}) + + +def immich_menu_ready(primary): + try: + return captured_menu_ready(primary, 'install_immich_stack.sh', immich_record, + {'server', 'database', 'valkey', 'machine-learning'}) + except (RuntimeError, OSError): + return False + + +def immich_prerequisites(rootfs, role, image): + required = { + 'server': ('/bin/bash', 'tini', 'node', 'start.sh', 'grep', 'seq', 'sleep'), + 'database': ('/bin/sh', '/usr/local/bin/immich-docker-entrypoint.sh', 'postgres', 'pg_isready'), + 'valkey': ('/bin/sh', 'docker-entrypoint.sh', 'valkey-server', 'valkey-cli'), + 'machine-learning': ('/bin/sh', 'env', 'tini', 'python'), + } + # PostgreSQL's official entrypoint generates its configuration at startup. + return adapter_prerequisites(rootfs, role, image, 'install_immich_stack.sh', required) + + +def immich_record(record): + projection = normalize(record) + recipe = record['deployment']['rootfs_replay'] + if recipe['adapter'] != 'install_immich_stack.sh': + raise ValueError(translate('Unrecognized Immich adapter')) + role = recipe['role'] + # PostgreSQL's saved listen address is private, never guessed from the host. + net0 = projection['deployment']['network']['ipv4'].split('/')[0] + expected = { + 'server': ['tini', '--', '/usr/local/bin/immich-lxc-start'], + 'database': ['/usr/local/bin/immich-docker-entrypoint.sh', 'postgres', '-c', + 'config_file=/etc/postgresql/postgresql.conf', '-c', + 'listen_addresses=127.0.0.1,' + net0], + 'valkey': ['docker-entrypoint.sh', 'valkey-server'], + 'machine-learning': ['env', 'LD_PRELOAD=/usr/lib/libmimalloc.so.2', 'tini', '--', + 'python', '-m', 'immich_ml'], + } + runtime = projection['runtime'] + if shlex.split(runtime.get('entrypoint', '')) != expected[role]: + raise ValueError(translate('The Immich startup was modified or cannot be reproduced')) + acceleration = record['deployment'].get('machine_learning', {}).get('acceleration', 'cpu') + if role == 'machine-learning' and acceleration not in ('cpu', 'openvino', 'cuda'): + raise ValueError(translate('Immich GPU profile not validated')) + cuda = role == 'machine-learning' and acceleration == 'cuda' + devices = [{'kind': 'nvidia-runtime', 'runtime_mode': 'dynamic'}] if cuda else [] + for item in projection['native_devices']: + fields = dict(p.split('=', 1) for p in item['value'].split(',') if '=' in p) + path = fields.get('path') + if cuda and path and path.startswith('/dev/nvidia'): + continue + if not path or not re.fullmatch(r'/dev/dri/renderD[0-9]+', path): + raise ValueError(translate('Immich device without a validated translation')) + devices.append({'kind': 'character-device', 'host_path': path, 'container_path': path, + 'gid_strategy': 'host-device-gid', 'mode': fields.get('mode', '0660'), + 'drm_vendor_ids': ['0x8086'] if role == 'machine-learning' else ['0x8086', '0x1002']}) + if projection['preserved_raw_runtime'] and not cuda: + raise ValueError(translate('Immich runtime without a validated translation')) + if cuda: + import oci_accelerators + candidate = {'devices': devices, 'environment': [ + {'name': 'NVIDIA_DRIVER_CAPABILITIES', 'value': 'compute,utility'}]} + oci_accelerators.check(record['observed']['config'].encode(), candidate) + translated = {'compose_entrypoint': expected[role], 'command': []} + for native, target in (('lxc.init.cwd', 'working_directory'), ('lxc.signal.halt', 'halt_signal')): + if native in runtime: + translated[target] = runtime[native] + result = portable_record(record, {'generated_files': projection['generated_files'], 'runtime': translated}) + result['deployment']['devices'] = devices + if cuda: + result['deployment']['environment'] = [e for e in result['deployment']['environment'] + if e['name'] != 'NVIDIA_DRIVER_CAPABILITIES'] + result['deployment']['environment'].append({'name': 'NVIDIA_DRIVER_CAPABILITIES', 'value': 'compute,utility'}) + result['deployment']['machine_learning'] = copy.deepcopy(record['deployment'].get('machine_learning', {})) + return result + + +def captured_menu_ready(primary, adapter, convert, expected_roles): + if primary.get('native_stack_intent', {}).get('adapter', {}).get('name') != adapter: + return False + members = primary.get('stack', {}).get('members', []) + if len(members) != len(expected_roles): + return False + try: + converted = [convert(member) for member in members] + roles = {r['deployment']['replay_profile']['role'] for r in converted} + if roles != expected_roles: + return False + for member in converted: + targets = [m['container_path'] for m in member['deployment']['mounts']] + declared = member['observed']['image']['defaults'].get('Volumes') or {} + if any(not any(p == target or p.startswith(target.rstrip('/') + '/') for target in targets) + for p in declared): + return False + except (ValueError, KeyError, TypeError): + return False + return True + + +def image_executable(rootfs, path, executable=True): + """Resolve container symlinks inside its root, never against the host root.""" + root = Path(rootfs) + pending = list(Path(path).parts[1:]) + resolved, links = [], 0 + while pending: + part = pending.pop(0) + if part in ('', '.'): + continue + if part == '..': + if not resolved: + raise ValueError(translate('Symbolic link outside the rootfs of the new image')) + resolved.pop() + continue + destination = root.joinpath(*resolved, part) + info = destination.lstat() + if stat.S_ISLNK(info.st_mode): + links += 1 + if links > 40: + raise ValueError(translate('Symbolic link loop in the new image')) + target = os.readlink(destination) + if target.startswith('/'): + resolved = [] + pending = [p for p in target.split('/') if p] + pending + else: + resolved.append(part) + info = root.joinpath(*resolved).stat() + if not stat.S_ISREG(info.st_mode) or not info.st_mode & (0o111 if executable else 0o444): + raise ValueError(translate('The new image does not keep a required executable')) + return '/' + '/'.join(resolved) + + +def nextcloud_prerequisites(rootfs, role, image): + required = { + 'application': ('/bin/sh', '/entrypoint.sh', '/cron.sh', 'apache2-foreground', 'php'), + 'database': ('/bin/sh', 'docker-entrypoint.sh', 'postgres', 'pg_isready'), + 'cache': ('/bin/sh', 'docker-entrypoint.sh', 'redis-server', 'redis-cli'), + } + return adapter_prerequisites(rootfs, role, image, 'install_nextcloud_stack.sh', required) + + +def paperless_prerequisites(rootfs, role, image): + required = { + 'application': ('/bin/sh', '/init', 'python3'), + 'database': ('/bin/sh', 'docker-entrypoint.sh', 'postgres', 'pg_isready'), + 'broker': ('/bin/sh', 'tini', 'docker-entrypoint.sh', 'valkey-server', 'valkey-cli'), + } + return adapter_prerequisites(rootfs, role, image, 'install_paperless_stack.sh', required) + + +def tandoor_prerequisites(rootfs, role, image): + defaults = image.get('defaults', {}) + entrypoint = defaults.get('Entrypoint') or defaults.get('Cmd') or [] + if role == 'application' and (not isinstance(entrypoint, list) or not entrypoint + or not isinstance(entrypoint[0], str) or not entrypoint[0]): + raise ValueError(translate('The official Tandoor startup executable is missing')) + required = { + 'application': ('/bin/sh', entrypoint[0] if entrypoint else '/bin/sh', 'python3'), + 'database': ('/bin/sh', 'docker-entrypoint.sh', 'postgres', 'pg_isready'), + } + return adapter_prerequisites(rootfs, role, image, 'install_tandoor_stack.sh', required) + + +def adapter_prerequisites(rootfs, role, image, adapter, required): + if role not in required: + raise ValueError(translate('Unknown adapter role')) + defaults = image.get('defaults', {}) + if defaults.get('User') not in (None, '', 'root', '0', '0:0'): + raise ValueError(translate('The image changes the user expected by the adapter')) + path = next((entry[5:] for entry in defaults.get('Env') or [] + if entry.startswith('PATH=')), '') + directories = path.split(':') if path else [] + if any(not directory.startswith('/') or '..' in Path(directory).parts for directory in directories): + raise ValueError(translate('The PATH of the new image is outside the reproducible profile')) + checked = [] + for command in required[role]: + paths = [command] if command.startswith('/') else [directory.rstrip('/') + '/' + command for directory in directories] + for candidate in paths: + try: + checked.append(image_executable(rootfs, candidate)) + break + except FileNotFoundError: + continue + else: + raise ValueError(translate('An executable required by the adapter is missing in the new image')) + for path in FILES[adapter][role]: + current = Path(rootfs) + for part in Path(path).parts[1:]: + current /= part + if current.is_symlink(): + raise ValueError(translate('The new image adds a symbolic link in a generated path')) + return checked + + +def nextcloud_record(record): + """Build portable desired state from evidence, without writing the registry.""" + return portable_record(record, nextcloud_installer_profile(record)) + + +def paperless_record(record): + """Translate captured Paperless state; native activation remains separate.""" + return portable_record(record, paperless_installer_profile(record)) + + +def tandoor_record(record): + """Project the two-member Tandoor recipe without activating replacement.""" + return portable_record(record, tandoor_installer_profile(record)) + + +def portable_record(record, profile): + """Preserve data mounts and provenance without first-install preparations.""" + projection = normalize(record) + saved = record['deployment'].get('member_replay_projection') + if saved is not None and saved != projection: + raise ValueError(translate('The saved projection does not match the native evidence')) + result = copy.deepcopy(record) + deployment = projection['deployment'] + native = projection['preserved_native'] + for mount in deployment['mounts']: + mount.pop('existing_volume_id', None) + template_storage = record['deployment'].get('archive_volume', 'local:').split(':', 1)[0] + if template_storage.startswith('/'): + raise ValueError(translate('The OCI image storage was not kept')) + deployment.update(template_storage=template_storage, features=native.get('features', '').split(',') + if native.get('features') else [], stack_managed=True, + rootfs_adaptation_replay_required=False, + replay_profile=copy.deepcopy(record['deployment']['replay_profile']), + rootfs_replay=copy.deepcopy(record['deployment']['rootfs_replay'])) + if 'cpuunits' in native: + deployment['resources']['cpu_units'] = int(native['cpuunits']) + # Unknown settings cannot be silently lost during the first migration. + if native.get('ostype') == 'unmanaged': + deployment['ostype'] = 'unmanaged' + result['deployment'] = deployment + template = result['template'] + template.setdefault('schema_version', '0.5.0') + template.setdefault('kind', 'proxmenux.oci-template') + template.setdefault('status', 'generated-unvalidated') + template.setdefault('catalog_ui', {}).update( + architectures=[record['observed']['image']['architecture']], category='productivity') + template.setdefault('source', {}).setdefault('provider', 'official') + template['source'].setdefault('revision', record['observed']['image']['manifest_digest']) + template['container_contract']['volumes'] = [ + {'container_path': m['container_path'], 'required': True} + for m in deployment['mounts']] + if deployment['resources'].get('cpu_allocation') == 'quota': + profile = copy.deepcopy(profile) + profile['cpu_allocation'] = 'quota' + template.setdefault('proxmox', {})['installer_profile'] = profile + if 'native_stack_intent' in result: + result['dedicated_stack_recipe'] = result.pop('native_stack_intent') + return result + + +def paperless_installer_profile(record): + return official_application_profile(record, 'install_paperless_stack.sh', { + 'database': ['/usr/local/bin/paperless-postgres-lxc-start'], + 'broker': ['tini', '--', 'docker-entrypoint.sh', 'valkey-server'], + }) + + +def tandoor_installer_profile(record): + return official_application_profile(record, 'install_tandoor_stack.sh', { + 'database': ['/usr/local/bin/tandoor-postgres-lxc-start'], + }) + + +def official_application_profile(record, adapter, adapted_entrypoints): + projection = normalize(record) + recipe = record['deployment']['rootfs_replay'] + if recipe['adapter'] != adapter: + raise ValueError(translate('Stack adapter not recognized by the translator')) + if projection.get('native_devices') or projection.get('preserved_raw_runtime'): + raise ValueError(translate('The stack contains devices or directives without a translation')) + runtime = projection['runtime'] + entrypoint = runtime.get('entrypoint', '') + if not entrypoint or '\0' in entrypoint or '\n' in entrypoint: + raise ValueError(translate('A reproducible native startup is missing')) + arguments = shlex.split(entrypoint) + role = recipe['role'] + if role in adapted_entrypoints: + expected = adapted_entrypoints[role] + else: + defaults = record['observed']['image']['defaults'] + inherited = defaults.get('Entrypoint') or [] + command = defaults.get('Cmd') or [] + if not isinstance(inherited, list) or not isinstance(command, list): + raise ValueError(translate('The official startup cannot be reproduced')) + expected = inherited + command + if not expected or any(not isinstance(arg, str) for arg in expected): + raise ValueError(translate('The official startup of the application is missing')) + if arguments != expected: + raise ValueError(translate('The startup differs from the declared adapter')) + # The application follows the new image defaults, not the old entrypoint. + translated = {} if role == 'application' else {'compose_entrypoint': arguments, 'command': []} + for native, target in (('lxc.init.cwd', 'working_directory'), + ('lxc.signal.halt', 'halt_signal')): + if native in runtime: + translated[target] = runtime[native] + return {'generated_files': copy.deepcopy(projection['generated_files']), + 'runtime': translated} + + +def nextcloud_installer_profile(record): + """Translate captured startup settings, without authorizing replacement. + + Never include first-install volume preparations: existing database and + application disks must not be reseeded during image replacement. + """ + projection = normalize(record) + recipe = record['deployment']['rootfs_replay'] + if recipe['adapter'] != 'install_nextcloud_stack.sh': + raise ValueError(translate('This translator only supports the Nextcloud stack')) + if projection.get('native_devices') or projection.get('preserved_raw_runtime'): + raise ValueError(translate('The stack contains devices or directives without a translation')) + runtime = projection['runtime'] + entrypoint = runtime.get('entrypoint', '') + if not entrypoint or '\0' in entrypoint or '\n' in entrypoint: + raise ValueError(translate('A reproducible native startup is missing')) + try: + arguments = shlex.split(entrypoint) + except ValueError as exc: + raise ValueError(translate('Invalid native entrypoint')) from exc + role = recipe['role'] + expected = { + 'application': ['/usr/local/bin/nextcloud-lxc-start'], + 'database': ['/usr/local/bin/nextcloud-postgres-lxc-start'], + 'cache': ['docker-entrypoint.sh', 'redis-server'], + }[role] + if arguments != expected: + raise ValueError(translate('The startup differs from the declared Nextcloud adapter')) + translated = {'compose_entrypoint': arguments, 'command': []} + for native, target in (('lxc.init.cwd', 'working_directory'), + ('lxc.signal.halt', 'halt_signal')): + if native in runtime: + translated[target] = runtime[native] + return {'generated_files': copy.deepcopy(projection['generated_files']), + 'runtime': translated} + + +FILES = { + 'install_immich_stack.sh': { + 'database': (), 'valkey': (), 'machine-learning': (), + 'server': ('/usr/local/bin/immich-lxc-start',), + }, + 'install_nextcloud_stack.sh': { + 'database': ('/usr/local/bin/nextcloud-postgres-lxc-start',), + 'cache': (), 'application': ('/usr/local/bin/nextcloud-lxc-start',), + }, + 'install_paperless_stack.sh': { + 'database': ('/usr/local/bin/paperless-postgres-lxc-start',), + 'broker': (), 'application': (), + }, + 'install_tandoor_stack.sh': { + 'database': ('/usr/local/bin/tandoor-postgres-lxc-start',), + 'application': (), + }, +} + + +def capture(rootfs, adapter, role, mounts): + if adapter not in FILES or role not in FILES[adapter]: + raise ValueError(translate('Unrecognized stack adapter or role')) + root = Path(rootfs) + if root.is_symlink() or not root.is_dir(): + raise ValueError(translate('Unsafe rootfs for the capture')) + files = [] + for path in FILES[adapter][role]: + if any(path == m['container_path'] or path.startswith(m['container_path'].rstrip('/') + '/') + for m in mounts): + raise ValueError(translate('A rootfs adaptation is stored in persistent storage')) + destination = root + for part in Path(path).parts[1:]: + destination = destination / part + if destination.is_symlink(): + raise ValueError(translate('Symbolic link in the path of an adaptation')) + info = destination.stat() + if (not stat.S_ISREG(info.st_mode) or info.st_mode & 0o022 + or stat.S_IMODE(info.st_mode) != 0o755 + or info.st_uid != 100000 or info.st_gid != 100000): + raise ValueError(translate('Adaptation file with unexpected permissions or owner')) + if info.st_size > 65536: + raise ValueError(translate('Adaptation file too large')) + content = destination.read_text() + if not content.startswith(('#!/bin/sh\n', '#!/bin/bash\n')) or '\0' in content: + raise ValueError(translate('Unrecognized adaptation format')) + files.append({'container_path': path, 'mode': '0755', 'owner': 'mapped-root', + 'content': content, 'sha256': hashlib.sha256(content.encode()).hexdigest()}) + return {'schema_version': 1, 'adapter': adapter, 'role': role, 'files': files} + + +def validate(recipe): + adapter, role = recipe.get('adapter'), recipe.get('role') + if recipe.get('schema_version') != 1 or adapter not in FILES or role not in FILES[adapter]: + raise ValueError(translate('Unrecognized adaptation recipe')) + files = recipe.get('files', []) + if [item.get('container_path') for item in files] != list(FILES[adapter][role]): + raise ValueError(translate('Incomplete file recipe or unknown paths')) + for item in files: + content = item.get('content', '') + if (item.get('mode') != '0755' or item.get('owner') != 'mapped-root' + or not content.startswith(('#!/bin/sh\n', '#!/bin/bash\n')) + or len(content.encode()) > 65536 or '\0' in content + or hashlib.sha256(content.encode()).hexdigest() != item.get('sha256')): + raise ValueError(translate('The adaptation content was modified')) + return files + + +def normalize(record): + """Project a dedicated member into common desired state, without enabling it. + + Raw native config remains authoritative. The projection is evidence for the + future replay adapter, not authorization to discard unsupported directives. + """ + deployment = record['deployment'] + recipe = deployment['rootfs_replay'] + files = validate(recipe) + if deployment.get('replay_profile') != {'adapter': recipe['adapter'], 'role': recipe['role']}: + raise ValueError(translate('Inconsistent adaptation profile and recipe')) + config = record['observed']['config'] + config_hash = hashlib.sha256(config.encode()).hexdigest() + if record['observed'].get('config_sha256') != config_hash: + raise ValueError(translate('The configuration evidence does not match')) + values, environment, mount_lines = {}, [], [] + names = set() + def add_environment(value): + name, equals, content = value.partition('=') + if not equals or not re.fullmatch(r'[A-Za-z_][A-Za-z0-9_]*', name) or name in names: + raise ValueError(translate('Ambiguous or invalid environment variable')) + names.add(name) + environment.append({'name': name, 'value': content}) + for line in config.splitlines(): + key, sep, value = line.partition(': ') + if not sep: + if line.strip(): + raise ValueError(translate('Unrecognized native configuration')) + continue + if key == 'lxc.environment.runtime': + add_environment(value) + elif key == 'env': + for variable in value.split('\0'): + add_environment(variable) + elif re.fullmatch(r'mp[0-9]+', key): + mount_lines.append((key, value)) + else: + values.setdefault(key, []).append(value) + def single(key, default=None): + matches = values.get(key, []) + if len(matches) > 1: + raise ValueError(f"{translate('Duplicated native directive:')} {key}") + if not matches: + if default is not None: + return default + raise ValueError(f"{translate('Missing native directive:')} {key}") + return matches[0] + def options(value): + result = {} + for part in value.split(','): + key, equals, content = part.partition('=') + if equals: + if key in result: + raise ValueError(translate('Duplicated native option')) + result[key] = content + return result + def size(value): + match = re.fullmatch(r'([0-9]+)([GMT])', value or '') + if not match: + raise ValueError(translate('The disk size cannot be reproduced')) + number, unit = int(match[1]), match[2] + if unit == 'M': + if number % 1024: + raise ValueError(translate('The size of existing disks is not rounded')) + number //= 1024 + if unit == 'T': + number *= 1024 + if number < 1: + raise ValueError(translate('Disk too small for the common profile')) + return number + if single('unprivileged') != '1': + raise ValueError(translate('The native unprivileged idmap is required')) + rootfs = single('rootfs') + source = rootfs.split(',', 1)[0] + if source.startswith('/') or ':' not in source: + raise ValueError(translate('The rootfs is not managed by Proxmox')) + net = options(single('net0')) + if not net.get('bridge') or not net.get('ip') or not net.get('hwaddr'): + raise ValueError(translate('Incomplete primary network')) + mounts, targets = [], set() + for key, value in mount_lines: + source = value.split(',', 1)[0] + opts = options(value) + target = opts.get('mp', '') + if (not target.startswith('/') or target == '/' or '..' in Path(target).parts + or str(Path(target)) != target or any(target == other or target.startswith(other + '/') + or other.startswith(target + '/') for other in targets)): + raise ValueError(translate('Invalid or duplicated mount path')) + targets.add(target) + mount = {'container_path': target, 'read_only': opts.get('ro', '0') == '1'} + if source.startswith('/'): + if opts.get('backup', '0') != '0': + raise ValueError(translate('A host bind mount cannot be included in vzdump')) + mount.update(type='host-bind', source=source, backup=False, create_if_missing=False) + else: + if ':' not in source or opts.get('backup') != '1': + raise ValueError(translate('A managed volume with backup enabled is required')) + mount.update(type='managed-volume', source=source.split(':', 1)[0], backup=True, + size_gb=size(opts.get('size')), existing_volume_id=source) + mounts.append(mount) + quota = recipe['adapter'] == 'install_immich_stack.sh' and 'cores' not in values + if quota: + limit = single('cpulimit') + if not re.fullmatch(r'[1-9][0-9]*', limit): + raise ValueError(translate('The Immich CPU quota cannot be reproduced')) + cores = int(limit) + else: + cores = int(single('cores')) + resources = {'cores': cores, 'memory_mb': int(single('memory')), + 'swap_mb': int(single('swap', '0'))} + if quota: + resources['cpu_allocation'] = 'quota' + if resources['cores'] < 1 or resources['memory_mb'] < 1 or resources['swap_mb'] < 0: + raise ValueError(translate('Invalid resources')) + defaults = dict(item.split('=', 1) for item in record['observed'].get('image', {}).get('defaults', {}).get('Env', []) + if isinstance(item, str) and '=' in item) + overrides = [item for item in environment if defaults.get(item['name']) != item['value']] + plan = {'vmid': record['vmid'], 'hostname': single('hostname'), + 'rootfs': {'storage': rootfs.split(':', 1)[0], 'size_gb': size(options(rootfs).get('size'))}, + 'resources': resources, 'security': {'unprivileged': True}, + 'network': {'bridge': net['bridge'], 'ipv4': net['ip'], 'mac_address': net['hwaddr'], + 'firewall': net.get('firewall', '0') == '1'}, + 'onboot': single('onboot', '0') == '1', 'start_after_create': False, + 'shutdown_timeout_seconds': 60, 'mounts': mounts, 'environment': overrides} + if net.get('gw'): + plan['network']['gateway'] = net['gw'] + runtime = {key: single(key) for key in ('entrypoint', 'lxc.init.cwd', 'lxc.signal.halt') if key in values} + preserved = {key: single(key) for key in ('arch', 'ostype', 'cmode', 'console', 'tty', 'cpuunits', + 'net0', 'net1', 'startup', 'hookscript', 'features', 'tags') if key in values} + devices = [{'key': key, 'value': single(key)} for key in values if re.fullmatch(r'dev[0-9]+', key)] + raw_runtime = [line for line in config.splitlines() if line.startswith('lxc.') + and line.partition(': ')[0] not in ('lxc.environment.runtime', 'lxc.init.cwd', 'lxc.signal.halt')] + return {'schema_version': 1, 'deployment': plan, 'runtime': runtime, + 'preserved_native': preserved, 'generated_files': copy.deepcopy(files), + 'native_devices': devices, 'preserved_raw_runtime': raw_runtime, + 'observed_environment': environment, + 'native_config_sha256': config_hash, + 'activation_requires_native_compatibility_check': True} diff --git a/oci/remote/oci_stack_transaction.py b/oci/remote/oci_stack_transaction.py new file mode 100644 index 00000000..2f5f6662 --- /dev/null +++ b/oci/remote/oci_stack_transaction.py @@ -0,0 +1,209 @@ +"""Durable coordination protocol; native PVE adapters are supplied explicitly. + +This module does not enable stack updates by itself. The adapter must hold the +instance registry lock, verify guest identities on every call, and implement +idempotent restore/publication using the transaction ID. No individual member +may publish its contract from replace(). All adapter results must be JSON data. +""" +import copy +import fcntl +import json +import os +from pathlib import Path +import stat +import uuid + +from oci_installation_state import private_directory +from oci_instances import write +import oci_instance_transaction as member_tx +from oci_ui import translate, msg_info, msg_ok, msg_warn + + +TERMINAL = {'committed', 'rolled-back'} +PHASES = {'prepared', 'preparing', 'stopping', 'backing-up', 'replacing', + 'starting', 'checking', 'publishing', 'recovering', + 'recovery-failed'} | TERMINAL + + +def save(path, state, phase): + if state.get('phase') != phase: + member_tx.log(f'stack phase: {phase}') + state['phase'] = phase + write(path, state) + + +def member(adapter, vmid): + describe = getattr(adapter, 'describe', None) + return describe(vmid) if describe else f'CT {vmid}' + + +def validate_plan(plan): + if plan.get('operation') not in ('update', 'recreate'): + raise ValueError(translate('Invalid stack operation')) + if plan.get('blockers') or plan.get('missing_members'): + raise ValueError(translate('The stack needs member adaptations or a verification of missing volumes')) + members = plan.get('members', []) + ids = [member['vmid'] for member in members] + if not ids or any(type(vmid) is not int or vmid < 100 for vmid in ids): + raise ValueError(translate('Invalid stack members')) + if len(set(ids)) != len(ids) or plan.get('primary_vmid') not in ids: + raise ValueError(translate('Invalid main member or duplicated members')) + for key in ('start_order', 'stop_order'): + order = plan.get(key, []) + if len(order) != len(ids) or set(order) != set(ids): + raise ValueError(translate('Incomplete stack order')) + if plan['start_order'][-1] != plan['primary_vmid'] or plan['stop_order'][0] != plan['primary_vmid']: + raise ValueError(translate('The main member must stop first and start last')) + + +def recover_state(path, state, adapter): + """Recover every private backup once replacement could have begun. + + A dependency may receive database writes even when only the frontend was + replaced. Consequently rollback never restores just the failing member. + External host files are deliberately outside this recovery protocol. + """ + if state['phase'] in TERMINAL: + if hasattr(adapter, 'finalize'): + adapter.finalize(state) + return state + ids = {str(vmid) for vmid in state['plan']['start_order']} + if (set(state.get('running', {})) != ids + or any(type(value) is not bool for value in state['running'].values()) + or type(state.get('stop_intent')) is not bool + or type(state.get('replacement_intent')) is not bool): + raise ValueError(translate('The journal has an incomplete recovery state')) + if state['replacement_intent'] and (not state['stop_intent'] or set(state.get('backups', {})) != ids): + raise ValueError(translate('Stack backups are missing; a partial restore is not allowed')) + adapter.validate(state['plan']) + if state['replacement_intent'] and hasattr(adapter, 'verify_backups'): + msg_info(translate('Verifying the backups...')) + adapter.verify_backups(state['backups']) + msg_ok(translate('Backups verified')) + save(path, state, 'recovering') + try: + if state['stop_intent']: + msg_info(translate('Stopping the stack...')) + for vmid in state['plan']['stop_order']: + adapter.stop(vmid) + msg_ok(translate('Stack stopped')) + if state['replacement_intent']: + for vmid in state['plan']['start_order']: + backup = state['backups'].get(str(vmid)) + if backup is None: + raise ValueError(translate('A stack backup is missing; a partial restore is not allowed')) + for vmid in state['plan']['start_order']: + msg_info(f"{translate('Restoring')} {member(adapter, vmid)}...") + adapter.restore(vmid, state['backups'][str(vmid)], state['id']) + msg_ok(f"{translate('Restored:')} {member(adapter, vmid)}") + msg_info(translate('Restoring the stack records...')) + adapter.restore_contracts(state['plan'], state['id']) + msg_ok(translate('Stack records restored')) + if state['stop_intent']: + msg_info(translate('Returning the containers to their previous state...')) + adapter.restore_running_state(state['running'], state['plan']['start_order']) + msg_ok(translate('Containers returned to their previous state')) + save(path, state, 'rolled-back') + except Exception: + save(path, state, 'recovery-failed') + raise + if hasattr(adapter, 'finalize'): + adapter.finalize(state) + return state + + +def _apply(path, plan, adapter): + validate_plan(plan) + if path.exists(): + raise ValueError(translate('A journal already exists; review or recover it before trying again')) + adapter.validate(plan) + running = {str(vmid): adapter.is_running(vmid) for vmid in plan['start_order']} + if any(type(value) is not bool for value in running.values()): + raise ValueError(translate('Invalid running state')) + state = {'schema_version': 1, 'id': str(uuid.uuid4()), + 'plan': copy.deepcopy(plan), 'running': running, + 'prepared': {}, 'backups': {}, 'stop_intent': False, + 'replacement_intent': False} + save(path, state, 'prepared') + try: + # Resolve/download/verify every candidate before stopping any service. + save(path, state, 'preparing') + for candidate in plan['members']: + state['prepared'][str(candidate['vmid'])] = adapter.prepare(candidate, plan['operation']) + save(path, state, 'preparing') + adapter.validate(plan) + state['stop_intent'] = True + save(path, state, 'stopping') + msg_info(translate('Stopping the stack...')) + for vmid in plan['stop_order']: + adapter.stop(vmid) + msg_ok(translate('Stack stopped')) + save(path, state, 'backing-up') + for vmid in plan['start_order']: + msg_info(f"{translate('Creating a backup of')} {member(adapter, vmid)}...") + state['backups'][str(vmid)] = adapter.backup(vmid, state['id']) + save(path, state, 'backing-up') + msg_ok(f"{translate('Backup created:')} {member(adapter, vmid)}") + # The adapter must verify all archives, free space and device identities. + msg_info(translate('Verifying the backups...')) + adapter.verify_backups(state['backups']) + adapter.validate(plan) + msg_ok(translate('Backups verified')) + state['replacement_intent'] = True + save(path, state, 'replacing') + for vmid in plan['start_order']: + msg_info(f"{translate('Updating')} {member(adapter, vmid)}...") + adapter.replace(vmid, state['prepared'][str(vmid)], state['id']) + msg_ok(f"{translate('Updated:')} {member(adapter, vmid)}") + save(path, state, 'starting') + for vmid in plan['start_order']: + msg_info(f"{translate('Starting')} {member(adapter, vmid)}...") + adapter.start(vmid) + adapter.healthcheck(vmid) + msg_ok(f"{translate('Service responding:')} {member(adapter, vmid)}") + save(path, state, 'checking') + msg_info(translate('Checking the updated stack...')) + adapter.validate_candidates(state) + adapter.restore_running_state(running, plan['start_order']) + msg_ok(translate('Updated stack checked')) + save(path, state, 'publishing') + msg_info(translate('Saving the stack records...')) + adapter.publish(state) + save(path, state, 'committed') + msg_ok(translate('Stack records saved')) + except Exception as error: + member_tx.report_error(error) + try: + error.oci_reported = True + except AttributeError: + pass + if state['stop_intent']: + msg_warn(translate('Restoring the previous state of the stack...')) + recover_state(path, state, adapter) + raise + if hasattr(adapter, 'finalize'): + adapter.finalize(state) + return state + + +def execute(journal, adapter, plan=None): + """Apply when plan is supplied; otherwise explicitly recover an old journal.""" + path = Path(journal) + private_directory(path.parent) + lock = path.with_name(path.name + '.lock') + if path.is_symlink() or lock.is_symlink(): + raise ValueError(translate('Unsafe journal or lock file')) + with lock.open('a') as handle: + lock.chmod(0o600) + fcntl.flock(handle, fcntl.LOCK_EX | fcntl.LOCK_NB) + if plan is not None: + return _apply(path, plan, adapter) + attributes = path.lstat() + if (not stat.S_ISREG(attributes.st_mode) or attributes.st_uid != os.geteuid() + or attributes.st_mode & 0o077): + raise ValueError(translate('The private journal has an unsafe owner or permissions')) + state = json.loads(path.read_text()) + if state.get('schema_version') != 1 or state.get('phase') not in PHASES: + raise ValueError(translate('Invalid stack journal')) + validate_plan(state['plan']) + return recover_state(path, state, adapter) diff --git a/oci/remote/oci_ui.py b/oci/remote/oci_ui.py new file mode 100644 index 00000000..52cff6b0 --- /dev/null +++ b/oci/remote/oci_ui.py @@ -0,0 +1,118 @@ +"""Output helpers for the OCI host helpers written in Python: the look of the +ProxMenux utils.sh messages and the same translation cache (lang/.json).""" +from __future__ import annotations + +import json +import os +from pathlib import Path +import sys +import threading + +BASE_DIR = Path(os.environ.get("PMX_BASE_DIR", "/usr/local/share/proxmenux")) + +MG = "\033[1;35m" +GN = "\033[1;92m" +RD = "\033[01;31m" +YW = "\033[33m" +YWB = "\033[1;33m" +BOLD = "\033[1m" +CL = "\033[m" +TAB = " " +FRAMES = ("⠋", "⠙", "⠹", "⠸", "⠼", "⠴", "⠦", "⠧", "⠇", "⠏") + +_language: str | None = None +_cache: dict[str, str] | None = None +_spinner: tuple[threading.Thread, threading.Event] | None = None + + +def _load_language() -> str: + global _language + if _language is None: + try: + value = json.loads((BASE_DIR / "config.json").read_text(encoding="utf-8")).get("language") + except (OSError, ValueError, AttributeError): + value = None + _language = value if isinstance(value, str) and value else "en" + return _language + + +def translate(text: str) -> str: + global _cache + if _load_language() == "en": + return text + if _cache is None: + try: + data = json.loads((BASE_DIR / "lang" / f"{_load_language()}.json").read_text(encoding="utf-8")) + _cache = {str(k): str(v) for k, v in data.items()} if isinstance(data, dict) else {} + except (OSError, ValueError): + _cache = {} + return _cache.get(text) or text + + +def _write(text: str) -> None: + sys.stdout.write(text) + sys.stdout.flush() + + +def _spin(stop: threading.Event) -> None: + index = 0 + _write("\033[?25l") + while not stop.wait(0.1): + _write(f"\r {MG}{FRAMES[index]}{CL}") + index = (index + 1) % len(FRAMES) + + +def stop_spinner() -> None: + global _spinner + if _spinner is not None: + thread, stop = _spinner + stop.set() + thread.join() + _spinner = None + _write("\033[?25h") + + +def msg_info(text: str) -> None: + global _spinner + stop_spinner() + _write(f"\r\033[K{TAB}{MG}-{text}{CL}") + if sys.stdout.isatty() or os.environ.get("OCI_SPINNER") == "1": + stop = threading.Event() + thread = threading.Thread(target=_spin, args=(stop,), daemon=True) + _spinner = (thread, stop) + thread.start() + else: + _write("\n") + + +def msg_progress(text: str) -> None: + stop_spinner() + _write(f"\r\033[K{TAB}{MG}-{text}{CL}") + + +def msg_ok(text: str) -> None: + stop_spinner() + _write(f"\r\033[K{TAB}{GN}✓ {CL}{GN}{text}{CL}\n") + + +def msg_warn(text: str) -> None: + stop_spinner() + _write(f"\r\033[K{TAB}{CL} {YWB}{text}{CL}\n") + + +def msg_error(text: str) -> None: + stop_spinner() + _write(f"\r\033[K{TAB}{RD}[ERROR] {text}{CL}\n") + + +def msg_info2(text: str) -> None: + stop_spinner() + _write(f"\r\033[K{TAB}{BOLD}{YW}- {text}{CL}\n") + + +def log(path: str | os.PathLike | None, text: str) -> None: + """Appends a line to a private log; output that the user does not need goes here.""" + if not path: + return + with open(path, "a", encoding="utf-8") as handle: + handle.write(text.rstrip("\n") + "\n") diff --git a/oci/remote/oci_ui.sh b/oci/remote/oci_ui.sh new file mode 100644 index 00000000..b79ea456 --- /dev/null +++ b/oci/remote/oci_ui.sh @@ -0,0 +1,136 @@ +#!/usr/bin/env bash +# Helpers shared by the OCI installers: the look of the ProxMenux utils.sh +# messages, the same translation cache and the private log of each run. +# Safe under set -Eeuo pipefail. + +PMX_BASE_DIR=${PMX_BASE_DIR:-/usr/local/share/proxmenux} +OCI_LOG_DIR=${OCI_LOG_DIR:-/var/log/proxmenux/oci} +OCI_LOG=${OCI_LOG:-} + +_OCI_LANGUAGE=$(jq -r '.language // "en"' "$PMX_BASE_DIR/config.json" 2>/dev/null || true) +[[ -n $_OCI_LANGUAGE && $_OCI_LANGUAGE != null ]] || _OCI_LANGUAGE=en +_OCI_LANG_FILE="$PMX_BASE_DIR/lang/${_OCI_LANGUAGE}.json" + +_OCI_MG=$'\033[1;35m' +_OCI_GN=$'\033[1;92m' +_OCI_RD=$'\033[01;31m' +_OCI_YW=$'\033[33m' +_OCI_YWB=$'\033[1;33m' +_OCI_BOLD=$'\033[1m' +_OCI_CL=$'\033[m' +_OCI_TAB=" " +_OCI_SPINNER_PID="" + +translate() { + if [[ $_OCI_LANGUAGE == en || ! -s $_OCI_LANG_FILE ]]; then + printf '%s' "$1" + return 0 + fi + local value + value=$(jq -r --arg text "$1" '.[$text] // empty' "$_OCI_LANG_FILE" 2>/dev/null || true) + printf '%s' "${value:-$1}" +} + +_oci_spinner() { + local frames=('⠋' '⠙' '⠹' '⠸' '⠼' '⠴' '⠦' '⠧' '⠇' '⠏') i=0 + printf '\033[?25l' + while :; do + printf '\r %s%s%s' "$_OCI_MG" "${frames[i]}" "$_OCI_CL" + i=$(( (i + 1) % ${#frames[@]} )) + sleep 0.1 + done +} + +stop_spinner() { + if [[ -n $_OCI_SPINNER_PID ]]; then + kill "$_OCI_SPINNER_PID" 2>/dev/null || true + wait "$_OCI_SPINNER_PID" 2>/dev/null || true + _OCI_SPINNER_PID="" + fi + printf '\033[?25h' +} + +# The spinner is shown when the caller's terminal is interactive; OCI_SPINNER=1 +# is set by the Python front end, which relays this output to a terminal. +msg_info() { + stop_spinner + printf '\r\033[K%s%s-%s%s' "$_OCI_TAB" "$_OCI_MG" "$1" "$_OCI_CL" + if [[ -t 1 || ${OCI_SPINNER:-0} == 1 ]]; then + _oci_spinner & + _OCI_SPINNER_PID=$! + else + printf '\n' + fi +} + +# One line rewritten in place, for progress counters (no spinner). +msg_progress() { + stop_spinner + printf '\r\033[K%s%s-%s%s' "$_OCI_TAB" "$_OCI_MG" "$1" "$_OCI_CL" +} + +msg_ok() { + stop_spinner + printf '\r\033[K%s%s✓ %s%s%s%s\n' "$_OCI_TAB" "$_OCI_GN" "$_OCI_CL" "$_OCI_GN" "$1" "$_OCI_CL" +} + +msg_warn() { + stop_spinner + printf '\r\033[K%s%s %s%s%s\n' "$_OCI_TAB" "$_OCI_CL" "$_OCI_YWB" "$1" "$_OCI_CL" +} + +msg_error() { + stop_spinner + printf '\r\033[K%s%s[ERROR] %s%s\n' "$_OCI_TAB" "$_OCI_RD" "$1" "$_OCI_CL" +} + +msg_info2() { + stop_spinner + printf '\r\033[K%s%s%s- %s%s\n' "$_OCI_TAB" "$_OCI_BOLD" "$_OCI_YW" "$1" "$_OCI_CL" +} + +# Starts the private log of one run; every quiet command writes into it. +oci_log_init() { + local name=${1:-oci} + [[ -n $OCI_LOG ]] && return 0 + mkdir -p "$OCI_LOG_DIR" + chmod 0700 "$OCI_LOG_DIR" 2>/dev/null || true + OCI_LOG="$OCI_LOG_DIR/${name//[^A-Za-z0-9._-]/_}-$(date +%Y%m%d-%H%M%S).log" + : >"$OCI_LOG" + chmod 0600 "$OCI_LOG" + export OCI_LOG +} + +oci_log() { + [[ -n $OCI_LOG ]] && printf '%s\n' "$*" >>"$OCI_LOG" + return 0 +} + +# Runs a command with its output in the log instead of the terminal. +oci_quiet() { + if [[ -n $OCI_LOG ]]; then + "$@" >>"$OCI_LOG" 2>&1 + else + "$@" >/dev/null 2>&1 + fi +} + +# Last lines of the log, for the error report. +oci_log_tail() { + [[ -n $OCI_LOG && -s $OCI_LOG ]] || return 0 + tail -n "${1:-15}" "$OCI_LOG" | sed "s/^/${_OCI_TAB} /" +} + +# ip= and gw= options of an access interface, DHCP or a static IPv4 with an +# optional gateway, in OCI_ACCESS_NET. Returns 1 when a value is not valid. +oci_access_net() { + local octet='(25[0-5]|2[0-4][0-9]|1?[0-9]?[0-9])' + OCI_ACCESS_NET="" + if [[ $1 == dhcp ]]; then + OCI_ACCESS_NET="ip=dhcp" + return 0 + fi + [[ $1 =~ ^($octet\.){3}$octet/([89]|[12][0-9]|3[0-2])$ ]] || return 1 + [[ -z ${2:-} || $2 =~ ^($octet\.){3}$octet$ ]] || return 1 + OCI_ACCESS_NET="ip=$1${2:+,gw=$2}" +} diff --git a/oci/remote/oci_update_current.py b/oci/remote/oci_update_current.py new file mode 100644 index 00000000..7b318cdc --- /dev/null +++ b/oci/remote/oci_update_current.py @@ -0,0 +1,173 @@ +#!/usr/bin/env python3 +"""Resolve a saved image channel and invoke the native update transaction.""" +import argparse +import json +import os +from pathlib import Path +import re +import shlex +import subprocess +import sys +import tempfile + +import oci_instances as instances +import oci_instance_transaction as transaction +from oci_installation_state import image_from_archive +from oci_ui import translate, msg_info, msg_ok, msg_error, msg_info2 + + +def repository(reference): + repo = reference.split('@', 1)[0] + if ':' in repo.rsplit('/', 1)[-1]: + repo = repo.rsplit(':', 1)[0] + return repo + + +def run_quiet(args, error, capture=False): + """Runs a helper with its output in the private log; error is the message of a failure.""" + transaction.log('$ ' + shlex.join(args)) + process = subprocess.Popen(args, stdout=subprocess.PIPE, stderr=subprocess.PIPE, + env=dict(os.environ, PYTHONPATH=str(Path(__file__).parent))) + try: + while True: + try: + output, errors = process.communicate(timeout=5) + except subprocess.TimeoutExpired: + continue + if process.returncode: + transaction.log(f' exit {process.returncode}') + transaction.log_output(None if capture else output, errors) + if process.returncode: + raise RuntimeError(error) + return output + finally: + if process.poll() is None: + process.terminate() + try: + process.wait(timeout=10) + except subprocess.TimeoutExpired: + process.kill() + process.wait() + + +def resolve_archive(desired, config, current=None, check=None): + # Shared by individual and coordinated operations; no guest mutation here. + # When the registry still serves the current digest nothing is downloaded. + reference = desired['template']['container_contract']['image']['reference'] + architecture = transaction.parse_config(config)['arch'] + msg_info(translate('Checking the image in the registry...')) + transaction.log(f'image: {reference} ({architecture})') + code = ('import json,sys; from oci_installation_state import resolve_candidate; ' + 'print(json.dumps(resolve_candidate(sys.argv[1],sys.argv[2])))') + candidate = json.loads(run_quiet([sys.executable, '-c', code, reference, architecture], + translate('Could not query the image registry'), capture=True)) + digest = candidate['manifest_digest'] + if not re.fullmatch(r'sha256:[a-f0-9]{64}', digest): + raise ValueError(translate('Invalid registry digest')) + msg_ok(f"{translate('Image:')} {reference} ({candidate.get('version') or digest[7:19]})") + if digest == current: + return None, digest + if check: + check() + storage = desired['deployment']['template_storage'] + if not re.fullmatch(r'[A-Za-z0-9_-]+', storage): + raise ValueError(translate('Invalid template storage')) + archive = Path(instances.command('pvesm', 'path', + f'{storage}:vztmpl/proxmenux-update-{architecture}-{digest[7:]}.tar').decode().strip()) + archive.parent.mkdir(parents=True, exist_ok=True) + if archive.is_symlink(): + raise ValueError(translate('Unsafe OCI archive path')) + verifier = Path(__file__).with_name('verify_oci_archive.py') + cached = archive.exists() + if not cached: + msg_info(transaction.fit(f"{translate('Downloading the image:')} {reference}")) + fd, name = tempfile.mkstemp(prefix='.proxmenux-update-', suffix='.tar', dir=archive.parent) + os.close(fd) + partial = Path(name) + try: + run_quiet(['skopeo', 'copy', '--override-arch', architecture, + 'docker://' + repository(reference) + '@' + digest, + 'oci-archive:' + str(partial)], translate('Could not download the image')) + msg_ok(translate('Image downloaded')) + msg_info(translate('Verifying the image integrity...')) + run_quiet([sys.executable, str(verifier), str(partial)], + translate('The image did not pass the integrity check')) + if image_from_archive(str(partial))['manifest_digest'] != digest: + raise ValueError(translate('The downloaded image does not match its manifest')) + partial.chmod(0o644) + os.replace(partial, archive) + finally: + partial.unlink(missing_ok=True) + else: + msg_info(translate('Verifying the image integrity...')) + run_quiet([sys.executable, str(verifier), str(archive)], + translate('The image did not pass the integrity check')) + if image_from_archive(str(archive))['manifest_digest'] != digest: + raise ValueError(translate('The cached image does not match the current digest')) + msg_ok(translate('Using the verified image from the cache') if cached else translate('Image integrity verified')) + return archive, digest + + +def kept_settings(changes, deployment): + """Names of the settings changed in Proxmox that the new container keeps.""" + labels = {'memory': translate('Memory'), 'swap': translate('Swap'), 'cores': translate('CPU cores'), + 'cpulimit': translate('CPU cores'), 'cpuunits': translate('CPU priority'), + 'onboot': translate('Start with Proxmox')} + kept = [] + for key, value in changes.items(): + section, name = transaction.ADOPTABLE[key] + if (deployment.get(section, {}) if section else deployment).get(name) == value: + kept.append(labels[key]) + return kept + + +def update(vmid, acknowledge_external_data=False, proposal=None): + operation = 'recreate' if proposal is not None else 'update' + msg_info(translate('Checking the container before the update...') if operation == 'update' + else translate('Checking the container before recreating it...')) + with instances.locked(instances.ROOT): + record = instances.read(instances.ROOT, vmid) + if record['status'] != 'installed' or record.get('pending_transaction') or record.get('pending_stack_transaction'): + raise ValueError(translate('The instance is not ready to be updated')) + config = instances.command('pct', 'config', str(vmid)) + desired = transaction.candidate_contract(record, operation, proposal) + changes = transaction.external_changes(record, config) + transaction.preflight(record, desired, config) + msg_ok(translate('Container checked')) + current = record['observed']['image']['manifest_digest'] if operation == 'update' else None + archive, digest = resolve_archive(desired, config, current, lambda: transaction.require_backup_space( + instances.location(instances.ROOT, vmid).parent, [vmid])) + if archive is None: + msg_ok(translate('The image is already up to date; nothing was changed.')) + return + kept = kept_settings(changes, desired['deployment']) + if kept: + msg_info2(f"{translate('Keeping the settings changed in Proxmox:')} {', '.join(kept)}") + transaction.apply(instances.ROOT, vmid, archive, operation, proposal=proposal, + registry_digest=digest, acknowledge_external_data=acknowledge_external_data) + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('vmid', type=int) + parser.add_argument('--acknowledge-external-data', action='store_true') + parser.add_argument('--proposal', type=Path) + args = parser.parse_args() + if os.geteuid() != 0: + parser.error(translate('Root privileges are required')) + try: + proposal = json.loads(args.proposal.read_text()) if args.proposal else None + update(args.vmid, args.acknowledge_external_data, proposal) + return 0 + except BlockingIOError: + msg_error(translate('Another OCI operation is using the registry. This operation was not started.')) + return 1 + except (OSError, ValueError, KeyError, RuntimeError, subprocess.SubprocessError) as error: + transaction.report_error(error, f'update-{args.vmid}') + if transaction.pending_journal(): + transaction.recovery_hint() + return 1 + + +if __name__ == '__main__': + raise SystemExit(main()) diff --git a/oci/remote/oci_update_lab.py b/oci/remote/oci_update_lab.py new file mode 100644 index 00000000..afcfffff --- /dev/null +++ b/oci/remote/oci_update_lab.py @@ -0,0 +1,247 @@ +#!/usr/bin/env python3 +"""Recoverable nginx laboratory transaction. NOT a general OCI updater.""" +from __future__ import annotations + +import argparse +import copy +import fcntl +import hashlib +import json +import os +from pathlib import Path +import shutil +import subprocess +import tempfile +import time +import uuid + +from oci_installation_state import image_from_archive, parse_config, private_directory, save_record, sha +from verify_oci_archive import verify_archive, VerificationError + + +def run(*args): + print('Paso:', args[0], args[1] if len(args) > 1 else '', flush=True) + p = subprocess.run(args, capture_output=True, timeout=600) + if p.returncode: + raise RuntimeError(f'{args[0]} fallo con codigo {p.returncode}; transaccion conservada') + return p.stdout + + +def atomic(path, value): + fd, name = tempfile.mkstemp(dir=path.parent, prefix='.journal-') + try: + with os.fdopen(fd, 'w') as out: + json.dump(value, out, indent=2) + out.flush() + os.fsync(out.fileno()) + os.replace(name, path) + fd = os.open(path.parent, os.O_RDONLY) + try: + os.fsync(fd) + finally: + os.close(fd) + finally: + if os.path.exists(name): + os.unlink(name) + + +def checkpoint(path, state, phase): + state['phase'] = phase + atomic(path, state) + print('Estado:', phase, flush=True) + + +def filehash(path): + h = hashlib.sha256() + with open(path, 'rb') as f: + for block in iter(lambda: f.read(1024 * 1024), b''): + h.update(block) + return h.hexdigest() + + +def preflight(record, config): + cfg = parse_config(config) + if record['config_sha256'] != sha(config): + raise ValueError('Configuracion modificada desde el registro') + if cfg.get('hostname') != 'oci-update-lab' or record['reference'] != 'docker.io/library/nginx:alpine': + raise ValueError('Solo se admite el nginx de laboratorio') + allowed = {'arch', 'cores', 'description', 'entrypoint', 'env', 'hostname', 'memory', 'mp0', 'net0', + 'onboot', 'ostype', 'rootfs', 'swap', 'tags', 'unprivileged', 'lxc.init.cwd', + 'lxc.signal.halt', 'cmode', 'console', 'tty'} + if set(cfg) - allowed or '[' in config.decode(): + raise ValueError('Configuracion avanzada/snapshots no soportada') + if cfg.get('unprivileged') != '1' or cfg.get('onboot', '0') != '0': + raise ValueError('El laboratorio requiere unprivileged=1 y onboot=0') + mp = cfg.get('mp0', '') + if not mp.startswith('local-lvm:') or 'mp=/usr/share/nginx/html' not in mp or 'backup=1' not in mp: + raise ValueError('Solo se admite mp0 gestionado y respaldado del laboratorio') + if not cfg.get('rootfs', '').startswith('local-lvm:'): + raise ValueError('Storage de laboratorio no soportado') + return cfg + + +def health(vmid): + for _ in range(30): + try: + data = run('pct', 'exec', str(vmid), '--', 'wget', '-qO-', 'http://127.0.0.1/') + if data == b'oci-persistence-proof': + return + except RuntimeError: + pass + time.sleep(1) + raise RuntimeError('Healthcheck de datos/HTTP fallido') + + +def stop(vmid): + if b'running' in run('pct', 'status', str(vmid)): + run('pct', 'shutdown', str(vmid), '--timeout', '60') + + +def create(vmid, archive, cfg, hostname, marker): + run('pct', 'create', str(vmid), archive, '--rootfs', 'local-lvm:2', + '--hostname', hostname, '--cores', cfg.get('cores', '1'), + '--memory', cfg.get('memory', '256'), '--swap', cfg.get('swap', '128'), + '--unprivileged', '1', '--onboot', '0', '--tags', cfg.get('tags', 'lab'), + '--net0', cfg['net0'], '--description', marker) + + +def transaction(args, journal): + if journal.exists(): + raise ValueError('Ya existe una transaccion; consultar status o recover') + record = json.loads((args.state_dir / f'{args.vmid}.json').read_text()) + if record.get('vmid') != args.vmid or record.get('schema_version') != 1: + raise ValueError('Registro incompatible') + before = run('pct', 'config', str(args.vmid)) + cfg = preflight(record, before) + # Check HA separately; hostname/tags alone must never authorize mutation. + resources = json.loads(run('pvesh', 'get', '/cluster/ha/resources', '--output-format', 'json')) + if any(r.get('sid') == f'ct:{args.vmid}' for r in resources): + raise ValueError('HA no soportado') + if shutil.disk_usage(journal.parent).free < 8 * 1024**3: + raise ValueError('Se requieren 8 GiB libres para esta prueba y su backup') + archive = str(Path(args.archive).resolve()) + verify_archive(Path(archive)) + candidate = image_from_archive(archive) + if candidate['architecture'] != record['image']['architecture']: + raise ValueError('Arquitectura incompatible') + if candidate['manifest_digest'] == record['image']['manifest_digest']: + raise ValueError('La imagen ya coincide; no se requiere actualizar') + # This lab contract has no user runtime overrides or custom entrypoint. + if candidate['defaults'].get('Entrypoint') != record['image']['defaults'].get('Entrypoint') or candidate['defaults'].get('Cmd') != record['image']['defaults'].get('Cmd'): + raise ValueError('Cambio de comando fuera del alcance del laboratorio') + state = {'id': uuid.uuid4().hex, 'vmid': args.vmid, 'record': record, 'cfg': cfg, + 'archive': archive, 'candidate': candidate, 'was_running': b'running' in run('pct', 'status', str(args.vmid))} + checkpoint(journal, state, 'prepared') + stop(args.vmid) + checkpoint(journal, state, 'backing-up') + backup_dir = journal.parent / state['id'] + private_directory(backup_dir) + run('vzdump', str(args.vmid), '--mode', 'stop', '--compress', 'zstd', '--dumpdir', str(backup_dir), '--tmpdir', '/var/tmp') + backups = list(backup_dir.glob('vzdump-lxc-*.tar.zst')) + if len(backups) != 1: + raise ValueError('Backup no identificado') + run('zstd', '-t', str(backups[0])) + state.update(backup=str(backups[0]), backup_sha256=filehash(backups[0])) + checkpoint(journal, state, 'backup-ready') + stage = int(run('pvesh', 'get', '/cluster/nextid').strip()) + state['stage'] = stage + checkpoint(journal, state, 'creating-stage') + # Staging never starts, so it can retain the original MAC without collisions. + create(stage, archive, cfg, 'oci-update-stage', state['id']) + checkpoint(journal, state, 'parking-data') + run('pct', 'move-volume', str(args.vmid), 'mp0', '--target-vmid', str(stage), '--target-volume', 'mp0') + checkpoint(journal, state, 'data-parked') + if args.interrupt_after == 'data-parked': + raise RuntimeError('Interrupcion de laboratorio solicitada; ejecutar recover') + current = parse_config(run('pct', 'config', str(args.vmid))) + if current != {k: v for k, v in cfg.items() if k != 'mp0'}: + raise ValueError('Cambio concurrente detectado; no se destruye el CT') + checkpoint(journal, state, 'replacing-root') + run('pct', 'destroy', str(args.vmid)) + create(args.vmid, archive, cfg, cfg['hostname'], state['id']) + checkpoint(journal, state, 'root-replaced') + if args.interrupt_after == 'root-replaced': + raise RuntimeError('Interrupcion de laboratorio solicitada; ejecutar recover') + checkpoint(journal, state, 'returning-data') + run('pct', 'move-volume', str(stage), 'mp0', '--target-vmid', str(args.vmid), '--target-volume', 'mp0') + checkpoint(journal, state, 'checking-service') + run('pct', 'start', str(args.vmid)) + health(args.vmid) + if not state['was_running']: + stop(args.vmid) + updated = copy.deepcopy(record) + config = run('pct', 'config', str(args.vmid)) + updated.update(image=candidate, archive_path=archive, config=config.decode(), config_sha256=sha(config), + installation_id=str(uuid.uuid4()), previous_installation_id=record['installation_id'], + resolved_registry_digest=candidate['manifest_digest'], last_update_transaction=state['id']) + save_record(args.state_dir, updated) + checkpoint(journal, state, 'committed') + + +def recover(args, journal): + state = json.loads(journal.read_text()) + if state['phase'] in ('committed', 'rolled-back'): + raise ValueError('Transaccion terminada; no se restaura automaticamente') + backup = state.get('backup') + if not backup or filehash(backup) != state['backup_sha256']: + raise ValueError('No hay backup verificado; recuperar manualmente sin destruir datos') + vmid = state['vmid'] + path = Path(f'/etc/pve/lxc/{vmid}.conf') + if path.exists(): + config = run('pct', 'config', str(vmid)) + cfg = parse_config(config) + if state['id'] not in config.decode() and cfg.get('rootfs') != state['cfg']['rootfs']: + raise ValueError('VMID posiblemente reutilizado; recuperacion bloqueada') + stop(vmid) + if state.get('stage') and Path(f"/etc/pve/lxc/{state['stage']}.conf").exists(): + config = run('pct', 'config', str(state['stage'])) + if state['id'] not in config.decode(): + raise ValueError('Staging ajeno; recuperacion bloqueada') + stop(state['stage']) + checkpoint(journal, state, 'restoring-backup') + run('pct', 'restore', str(vmid), backup, '--force', '1', '--storage', 'local-lvm', '--description', state['id']) + run('pct', 'start', str(vmid)) + health(vmid) + if not state['was_running']: + stop(vmid) + restored = copy.deepcopy(state['record']) + config = run('pct', 'config', str(vmid)) + restored.update(config=config.decode(), config_sha256=sha(config), recovered_transaction=state['id']) + save_record(args.state_dir, restored) + checkpoint(journal, state, 'rolled-back') + print('Staging y backup conservados, sin limpieza automatica.') + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('action', choices=['apply', 'status', 'recover']) + parser.add_argument('vmid', type=int) + parser.add_argument('--state-dir', type=Path, required=True) + parser.add_argument('--transaction-dir', type=Path, required=True) + parser.add_argument('--archive') + parser.add_argument('--interrupt-after', choices=['data-parked', 'root-replaced']) + args = parser.parse_args() + if os.geteuid() != 0: + parser.error('Se requiere root') + private_directory(args.transaction_dir) + journal = args.transaction_dir / f'{args.vmid}.json' + with Path(f'/run/lock/proxmenux-oci-lab-{args.vmid}.lock').open('w') as lock: + try: + fcntl.flock(lock, fcntl.LOCK_EX | fcntl.LOCK_NB) + if args.action == 'status': + state = json.loads(journal.read_text()) + print(json.dumps({k: state.get(k) for k in ('id', 'vmid', 'stage', 'phase')}, indent=2)) + elif args.action == 'recover': + recover(args, journal) + else: + if not args.archive: + parser.error('apply requiere --archive') + transaction(args, journal) + except (OSError, ValueError, RuntimeError, KeyError, VerificationError, subprocess.TimeoutExpired) as error: + print(f'Proceso detenido ({type(error).__name__}). Diario privado: {journal}. Consultar status/recover.') + return 1 + return 0 + + +if __name__ == '__main__': + raise SystemExit(main()) diff --git a/oci/remote/rclone_mount_publish.py b/oci/remote/rclone_mount_publish.py new file mode 100644 index 00000000..df79c67f --- /dev/null +++ b/oci/remote/rclone_mount_publish.py @@ -0,0 +1,116 @@ +#!/usr/bin/env python3 +"""Clone a FUSE mount from an LXC namespace into the Proxmox host namespace.""" + +from __future__ import annotations + +import ctypes +import os +import platform +import sys + + +AT_FDCWD = -100 +AT_EMPTY_PATH = 0x1000 +AT_RECURSIVE = 0x8000 +CLONE_NEWNS = 0x00020000 +MOVE_MOUNT_F_EMPTY_PATH = 0x00000004 +MOUNT_ATTR_RDONLY = 0x00000001 +OPEN_TREE_CLONE = 1 + +SYSCALLS = { + "x86_64": (428, 429, 442), + "amd64": (428, 429, 442), + "aarch64": (428, 429, 442), + "arm64": (428, 429, 442), +} + + +class MountAttr(ctypes.Structure): + _fields_ = [ + ("attr_set", ctypes.c_uint64), + ("attr_clr", ctypes.c_uint64), + ("propagation", ctypes.c_uint64), + ("userns_fd", ctypes.c_uint64), + ] + + +def fail(step: str) -> None: + error = ctypes.get_errno() + raise OSError(error, f"{step}: {os.strerror(error)}") + + +def main() -> int: + if len(sys.argv) != 5 or sys.argv[4] not in {"rw", "ro"}: + print(f"usage: {sys.argv[0]} PID SOURCE TARGET rw|ro", file=sys.stderr) + return 2 + machine = platform.machine().lower() + if machine not in SYSCALLS: + print(f"unsupported host architecture: {machine}", file=sys.stderr) + return 2 + open_tree_nr, move_mount_nr, mount_setattr_nr = SYSCALLS[machine] + pid, source, target, mode = sys.argv[1:] + libc = ctypes.CDLL(None, use_errno=True) + libc.syscall.restype = ctypes.c_long + libc.setns.argtypes = (ctypes.c_int, ctypes.c_int) + libc.setns.restype = ctypes.c_int + + host_ns = os.open("/proc/self/ns/mnt", os.O_RDONLY | os.O_CLOEXEC) + host_root = os.open("/", os.O_PATH | os.O_DIRECTORY | os.O_CLOEXEC) + ct_ns = os.open(f"/proc/{pid}/ns/mnt", os.O_RDONLY | os.O_CLOEXEC) + ct_root = os.open(f"/proc/{pid}/root", os.O_PATH | os.O_DIRECTORY | os.O_CLOEXEC) + try: + if libc.setns(ct_ns, CLONE_NEWNS) != 0: + fail("enter container namespace") + os.fchdir(ct_root) + os.chroot(".") + os.chdir("/") + tree = libc.syscall( + open_tree_nr, + AT_FDCWD, + os.fsencode(source), + OPEN_TREE_CLONE | os.O_CLOEXEC, + ) + if tree < 0: + fail("clone source mount tree") + try: + if mode == "ro": + attributes = MountAttr(attr_set=MOUNT_ATTR_RDONLY) + result = libc.syscall( + mount_setattr_nr, + tree, + ctypes.c_char_p(b""), + AT_EMPTY_PATH | AT_RECURSIVE, + ctypes.byref(attributes), + ctypes.sizeof(attributes), + ) + if result != 0: + fail("make cloned mount tree read-only") + if libc.setns(host_ns, CLONE_NEWNS) != 0: + fail("return to host namespace") + os.fchdir(host_root) + os.chroot(".") + os.chdir("/") + result = libc.syscall( + move_mount_nr, + tree, + ctypes.c_char_p(b""), + AT_FDCWD, + os.fsencode(target), + MOVE_MOUNT_F_EMPTY_PATH, + ) + if result != 0: + fail("publish mount tree") + finally: + os.close(tree) + finally: + for descriptor in (ct_root, ct_ns, host_root, host_ns): + os.close(descriptor) + return 0 + + +if __name__ == "__main__": + try: + raise SystemExit(main()) + except OSError as exc: + print(exc, file=sys.stderr) + raise SystemExit(1) diff --git a/oci/remote/stack_dependency_hook.sh b/oci/remote/stack_dependency_hook.sh new file mode 100755 index 00000000..3c03b3e9 --- /dev/null +++ b/oci/remote/stack_dependency_hook.sh @@ -0,0 +1,128 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +PATH=/usr/sbin:/usr/bin:/sbin:/bin + +die() { + printf 'ERROR: %s\n' "$*" >&2 + exit 1 +} + +find_snippet_storage() { + local storage + if pvesm status --content snippets 2>/dev/null \ + | awk 'NR > 1 && $1 == "local" && $3 == "active" {found=1} END {exit !found}'; then + printf 'local' + return + fi + storage=$(pvesm status --content snippets 2>/dev/null \ + | awk 'NR > 1 && $3 == "active" {print $1; exit}') + [[ -n $storage ]] || die "No active storage supports snippets" + printf '%s' "$storage" +} + +install_hook() { + local main_id=${1:?missing main VMID} source_config=${2:?missing lifecycle JSON} + local storage hook_volume hook_path target_config + [[ $main_id =~ ^[0-9]+$ ]] || die "Invalid main VMID" + jq -e ' + .schema == 1 and + (.dependencies | type == "array") and + (.dependencies | length > 0) and + (all(.dependencies[]; + (.vmid | type == "number") and + (.label | type == "string") and + (.healthcheck.type | IN("exec", "http", "running")) and + (.healthcheck.timeout_seconds | type == "number") + )) + ' "$source_config" >/dev/null || die "Invalid dependency contract" + + storage=$(find_snippet_storage) + hook_volume="${storage}:snippets/proxmenux-stack-dependencies.sh" + hook_path=$(pvesm path "$hook_volume") + install -D -m 0755 "$0" "$hook_path" + + target_config="/etc/pve/priv/proxmenux-stack-${main_id}.json" + umask 077 + cat "$source_config" >"$target_config" + pct set "$main_id" --hookscript "$hook_volume" >/dev/null + printf 'Proxmox hookscript installed: CT %s starts its dependencies through %s\n' \ + "$main_id" "$hook_volume" +} + +dependency_is_healthy() { + local id=$1 healthcheck=$2 type url + type=$(jq -r '.type' <<<"$healthcheck") + case "$type" in + running) + [[ $(pct status "$id" 2>/dev/null || true) == "status: running" ]] + ;; + exec) + local -a command=() + mapfile -t command < <(jq -r '.argv[]' <<<"$healthcheck") + ((${#command[@]} > 0)) || return 1 + pct exec "$id" -- "${command[@]}" >/dev/null 2>&1 + ;; + http) + url=$(jq -r '.url' <<<"$healthcheck") + curl -fsS --max-time 3 "$url" >/dev/null 2>&1 + ;; + *) return 1 ;; + esac +} + +start_dependencies() { + local main_id=$1 config="/etc/pve/priv/proxmenux-stack-${1}.json" + local encoded dependency id label healthcheck timeout elapsed + [[ -r $config ]] || die "Missing dependency contract for main CT $main_id" + + exec 9>"/run/lock/proxmenux-stack-${main_id}.lock" + flock 9 + while IFS= read -r encoded; do + [[ -n $encoded ]] || continue + dependency=$(base64 -d <<<"$encoded") + id=$(jq -r '.vmid' <<<"$dependency") + label=$(jq -r '.label' <<<"$dependency") + healthcheck=$(jq -c '.healthcheck' <<<"$dependency") + timeout=$(jq -r '.healthcheck.timeout_seconds' <<<"$dependency") + [[ $id =~ ^[0-9]+$ && $timeout =~ ^[0-9]+$ && $timeout -gt 0 ]] \ + || die "Invalid dependency in $config" + pct config "$id" >/dev/null 2>&1 \ + || die "Dependency $label (CT $id) does not exist" + + if [[ $(pct status "$id" 2>/dev/null || true) != "status: running" ]]; then + printf 'Starting dependency %s (CT %s)...\n' "$label" "$id" + pct start "$id" || die "Could not start $label (CT $id)" + else + printf 'Dependency %s (CT %s) was already running.\n' "$label" "$id" + fi + + elapsed=0 + while (( elapsed < timeout )); do + if dependency_is_healthy "$id" "$healthcheck"; then + printf 'Dependency %s (CT %s): ready.\n' "$label" "$id" + break + fi + [[ $(pct status "$id" 2>/dev/null || true) == "status: running" ]] \ + || die "$label (CT $id) stopped while starting" + sleep 2 + elapsed=$((elapsed + 2)) + done + (( elapsed < timeout )) \ + || die "$label (CT $id) did not pass its health check within ${timeout}s" + done < <(jq -r '.dependencies[] | @base64' "$config") +} + +if [[ ${1:-} == "--install" ]]; then + shift + install_hook "$@" + exit 0 +fi + +vmid=${1:?missing VMID} +phase=${2:?missing lifecycle phase} +case "$phase" in + pre-start) start_dependencies "$vmid" ;; + post-start|pre-stop|post-stop) ;; + *) die "Unknown lifecycle phase: $phase" ;; +esac diff --git a/oci/remote/unshift_oci_rootfs.py b/oci/remote/unshift_oci_rootfs.py new file mode 100644 index 00000000..c61b26ea --- /dev/null +++ b/oci/remote/unshift_oci_rootfs.py @@ -0,0 +1,66 @@ +#!/usr/bin/env python3 +"""Convert an OCI rootfs imported with the default LXC idmap to host IDs.""" + +from __future__ import annotations + +import os +import stat +import sys + +from oci_ui import log, translate + + +def iter_paths(root: str): + yield root + for directory, names, files in os.walk(root, topdown=True, followlinks=False): + for name in names: + yield os.path.join(directory, name) + for name in files: + yield os.path.join(directory, name) + + +def note(text: str) -> None: + """Progress goes to the run log; without one, to stderr.""" + path = os.environ.get("OCI_LOG") + try: + if path: + log(path, text) + return + except OSError: + pass + print(text, file=sys.stderr, flush=True) + + +def main() -> int: + if len(sys.argv) != 2: + print(f"{translate('Usage:')} {sys.argv[0]} ROOTFS", file=sys.stderr) + return 2 + root = os.path.realpath(sys.argv[1]) + if not root.startswith("/var/lib/lxc/") or not root.endswith("/rootfs"): + print(f"{translate('Refusing an unexpected rootfs path:')} {root}", file=sys.stderr) + return 2 + root_device = os.lstat(root).st_dev + shifted = 0 + for path in iter_paths(root): + metadata = os.lstat(path) + if metadata.st_dev != root_device: + continue + uid = metadata.st_uid - 100000 if 100000 <= metadata.st_uid < 165536 else metadata.st_uid + gid = metadata.st_gid - 100000 if 100000 <= metadata.st_gid < 165536 else metadata.st_gid + if uid == metadata.st_uid and gid == metadata.st_gid: + continue + attributes: dict[str, bytes] = {} + for name in os.listxattr(path, follow_symlinks=False): + attributes[name] = os.getxattr(path, name, follow_symlinks=False) + os.chown(path, uid, gid, follow_symlinks=False) + for name, value in attributes.items(): + os.setxattr(path, name, value, follow_symlinks=False) + shifted += 1 + if shifted % 10000 == 0: + note(f" Owners converted: {shifted}") + note(f"OCI rootfs converted to privileged: {shifted} entries") + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/oci/remote/verify_oci_archive.py b/oci/remote/verify_oci_archive.py new file mode 100755 index 00000000..9504345d --- /dev/null +++ b/oci/remote/verify_oci_archive.py @@ -0,0 +1,130 @@ +#!/usr/bin/env python3 +"""Verify blob digests and gzip integrity in an OCI image archive.""" + +from __future__ import annotations + +import argparse +import hashlib +import os +import sys +import tarfile +import zlib +from pathlib import Path + +from oci_ui import log, translate + + +CHUNK_SIZE = 4 * 1024 * 1024 +PROGRESS_STEP = 128 * 1024 * 1024 + + +class VerificationError(RuntimeError): + pass + + +def human_mib(size: int) -> str: + return f"{size / (1024 * 1024):.1f} MiB" + + +def progress(text: str) -> None: + """Per-blob detail belongs to the run log, never to the terminal.""" + try: + log(os.environ.get("OCI_LOG"), text) + except OSError: + pass + + +def verify_blob(archive: tarfile.TarFile, member: tarfile.TarInfo, position: int, total: int) -> None: + expected_digest = member.name.rsplit("/", 1)[-1] + source = archive.extractfile(member) + if source is None: + raise VerificationError(f"{translate('Cannot read')} {member.name}") + + progress(f" Verifying blob {position}/{total}: {expected_digest[:12]} ({human_mib(member.size)})") + digest = hashlib.sha256() + decompressor: zlib.Decompress | None = None + processed = 0 + next_progress = PROGRESS_STEP + + while True: + chunk = source.read(CHUNK_SIZE) + if not chunk: + break + digest.update(chunk) + if processed == 0 and chunk.startswith(b"\x1f\x8b"): + decompressor = zlib.decompressobj(16 + zlib.MAX_WBITS) + if decompressor is not None: + try: + decompressor.decompress(chunk) + except zlib.error as exc: + raise VerificationError( + f"{translate('Corrupted gzip layer')} {expected_digest[:16]}: {exc}" + ) from exc + processed += len(chunk) + if member.size >= PROGRESS_STEP and processed >= next_progress: + percentage = min(100, processed * 100 // member.size) + progress(f" {human_mib(processed)} / {human_mib(member.size)} ({percentage}%)") + next_progress += PROGRESS_STEP + + if processed != member.size: + raise VerificationError( + f"{translate('Wrong size in')} {expected_digest[:16]}: {processed} != {member.size}" + ) + actual_digest = digest.hexdigest() + if actual_digest != expected_digest: + raise VerificationError( + f"{translate('Wrong SHA-256 in')} {expected_digest[:16]}: {actual_digest[:16]}" + ) + if decompressor is not None: + try: + decompressor.flush() + except zlib.error as exc: + raise VerificationError( + f"{translate('Corrupted gzip layer')} {expected_digest[:16]}: {exc}" + ) from exc + if not decompressor.eof: + raise VerificationError(f"{translate('Incomplete gzip layer')} {expected_digest[:16]}") + + +def verify_archive(path: Path) -> None: + if not path.is_file() or path.stat().st_size == 0: + raise VerificationError(f"{translate('The OCI archive does not exist or is empty:')} {path}") + + try: + with tarfile.open(path, mode="r:*") as archive: + members = archive.getmembers() + names = {member.name.lstrip("./") for member in members} + missing = {"index.json", "oci-layout"} - names + if missing: + raise VerificationError( + f"{translate('Missing OCI metadata:')} " + ", ".join(sorted(missing)) + ) + blobs = [ + member + for member in members + if member.isfile() + and member.name.lstrip("./").startswith("blobs/sha256/") + ] + if not blobs: + raise VerificationError(translate("The OCI archive contains no SHA-256 blobs")) + for position, member in enumerate(blobs, start=1): + verify_blob(archive, member, position, len(blobs)) + except (tarfile.TarError, OSError) as exc: + raise VerificationError(f"{translate('Cannot read the OCI archive:')} {exc}") from exc + progress(f"OCI integrity verified: {path}") + + +def main() -> int: + parser = argparse.ArgumentParser() + parser.add_argument("archive", type=Path) + args = parser.parse_args() + try: + verify_archive(args.archive) + except VerificationError as exc: + print(f"{translate('OCI verification failed:')} {exc}", file=sys.stderr, flush=True) + return 1 + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/oci/requirements.txt b/oci/requirements.txt new file mode 100644 index 00000000..ca07afa3 --- /dev/null +++ b/oci/requirements.txt @@ -0,0 +1,2 @@ +PyYAML==6.0.2 +jsonschema==4.25.1 diff --git a/oci/schemas/oci-template.schema.json b/oci/schemas/oci-template.schema.json new file mode 100644 index 00000000..49446a8e --- /dev/null +++ b/oci/schemas/oci-template.schema.json @@ -0,0 +1,346 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://proxmenux.example/schemas/oci-template.schema.json", + "title": "ProxMenux native OCI template", + "type": "object", + "required": [ + "schema_version", + "kind", + "id", + "status", + "catalog_ui", + "source", + "container_contract", + "proxmox", + "compatibility", + "validation", + "lifecycle" + ], + "properties": { + "schema_version": {"enum": ["0.2.0", "0.3.0", "0.4.0", "0.5.0"]}, + "kind": {"const": "proxmenux.oci-template"}, + "id": {"type": "string", "pattern": "^[a-z0-9][a-z0-9-]+$"}, + "status": { + "enum": ["generated-unvalidated", "generated-review-required", "laboratory-validated", "stable"] + }, + "catalog_ui": { + "type": "object", + "required": ["title", "description", "category", "architectures", "launch", "mini_changelog"], + "properties": { + "title": {"$ref": "#/$defs/localizedText"}, + "tagline": {"$ref": "#/$defs/localizedText"}, + "hidden": {"type": "boolean", "default": false}, + "hidden_reason": {"type": "string"}, + "description": {"$ref": "#/$defs/localizedText"}, + "category": {"type": "string"}, + "category_label": {"type": "string"}, + "author": {"type": ["string", "null"]}, + "developer": {"type": ["string", "null"]}, + "icon": {"type": ["string", "null"]}, + "thumbnail": {"type": ["string", "null"]}, + "screenshots": {"type": "array", "items": {"type": "string"}}, + "architectures": { + "type": "array", + "items": {"enum": ["amd64", "arm64", "armhf", "i386", "ppc64le", "s390x"]}, + "minItems": 1, + "uniqueItems": true + }, + "launch": { + "type": "object", + "required": ["scheme", "port", "path"], + "properties": { + "scheme": {"enum": ["http", "https"]}, + "port": {"type": ["integer", "null"], "minimum": 1, "maximum": 65535}, + "path": {"type": "string", "pattern": "^/"} + }, + "additionalProperties": false + }, + "website": {"type": ["string", "null"]}, + "documentation": {"type": ["string", "null"]}, + "repository": {"type": "string"}, + "tips": {"type": "array", "items": {"type": "string"}}, + "mini_changelog": { + "type": "array", + "items": { + "type": "object", + "required": ["date", "note"], + "properties": { + "date": {"type": "string", "format": "date"}, + "note": {"type": "string"} + }, + "additionalProperties": false + } + }, + "display_version": {"type": ["string", "null"]}, + "updated_at": {"type": ["string", "null"]} + }, + "additionalProperties": false + }, + "source": { + "type": "object", + "required": ["provider", "repository", "revision", "compose_sha256", "generated_at"], + "properties": { + "provider": {"type": "string", "minLength": 1}, + "repository": {"type": "string", "format": "uri"}, + "default_branch": {"type": "string"}, + "revision": {"type": "string", "pattern": "^(?:[0-9a-f]{40}|[0-9a-f]{64})$"}, + "readme_raw_url": {"type": "string", "format": "uri"}, + "image_repository_url": {"type": "string", "format": "uri"}, + "readme_pushed_at": {"type": "string"}, + "compose_sha256": {"type": "string", "pattern": "^[0-9a-f]{64}$"}, + "generated_at": {"type": "string", "format": "date-time"} + }, + "additionalProperties": false + }, + "container_contract": { + "type": "object", + "required": ["service_name", "container_name", "image", "environment", "volumes", "ports", "original_compose"], + "properties": { + "service_name": {"type": "string"}, + "container_name": {"type": "string"}, + "image": { + "type": "object", + "required": ["reference", "registry", "repository", "tag", "digest", "pull_policy"], + "properties": { + "reference": {"type": "string"}, + "registry": {"type": "string"}, + "repository": {"type": "string"}, + "tag": {"type": "string"}, + "digest": {"type": ["string", "null"]}, + "pull_policy": {"type": "string"} + }, + "additionalProperties": false + }, + "environment": { + "type": "array", + "items": { + "type": "object", + "required": ["name", "example", "required", "sensitive", "source"], + "properties": { + "name": {"type": "string", "pattern": "^[A-Za-z_][A-Za-z0-9_]*$"}, + "example": {"type": ["string", "null"]}, + "prompt": {"type": "string", "minLength": 1}, + "prompt_user": {"type": "boolean"}, + "required": {"type": "boolean"}, + "sensitive": {"type": "boolean"}, + "source": {"type": "string"} + }, + "additionalProperties": false + } + }, + "volumes": { + "type": "array", + "items": { + "type": "object", + "required": ["id", "container_path", "read_only", "required", "installation_choice", "default", "managed_volume"], + "properties": { + "id": {"type": "string"}, + "container_path": {"type": "string", "pattern": "^/"}, + "compose_source_example": {"type": ["string", "null"]}, + "read_only": {"type": "boolean"}, + "required": {"type": "boolean"}, + "installation_choice": { + "type": "array", + "items": {"enum": ["managed-volume", "host-bind", "skip"]}, + "uniqueItems": true + }, + "default": {"enum": ["managed-volume", "host-bind", "skip"]}, + "managed_volume": { + "type": "object", + "required": ["backup", "default_size_gb"], + "properties": { + "backup": {"type": "boolean"}, + "default_size_gb": {"type": "integer", "minimum": 1} + }, + "additionalProperties": false + } + }, + "additionalProperties": false + } + }, + "ports": { + "type": "array", + "items": { + "type": "object", + "required": ["container_port", "published_example", "protocol", "required", "proxmox_behavior"], + "properties": { + "container_port": {"type": "integer", "minimum": 1, "maximum": 65535}, + "container_port_end": {"type": "integer", "minimum": 1, "maximum": 65535}, + "published_example": {"type": ["integer", "null"], "minimum": 1, "maximum": 65535}, + "published_example_end": {"type": "integer", "minimum": 1, "maximum": 65535}, + "protocol": {"enum": ["tcp", "udp", "sctp"]}, + "required": {"type": "boolean"}, + "proxmox_behavior": {"type": "string"} + }, + "additionalProperties": false + } + }, + "related_services": { + "type": "array", + "items": { + "type": "object", + "required": ["name", "image"], + "properties": { + "name": {"type": "string", "minLength": 1}, + "image": {"type": ["string", "null"]} + }, + "additionalProperties": false + } + }, + "restart": {"type": ["string", "null"]}, + "stop_grace_period": {"type": ["string", "null"]}, + "original_compose": {"type": "string", "minLength": 1} + }, + "additionalProperties": false + }, + "first_run": { + "type": "object", + "required": ["endpoints", "credentials"], + "properties": { + "endpoints": { + "type": "array", + "items": { + "type": "object", + "required": ["label", "scheme", "port", "path", "source"], + "properties": { + "label": {"type": "string"}, + "scheme": {"enum": ["http", "https"]}, + "port": {"type": "integer", "minimum": 1, "maximum": 65535}, + "path": {"type": "string", "pattern": "^/"}, + "source": {"type": "string"} + }, + "additionalProperties": false + } + }, + "credentials": { + "type": "array", + "items": { + "type": "object", + "required": ["label", "username", "password", "change_required", "source"], + "properties": { + "label": {"type": "string"}, + "type": {"enum": ["static-default", "runtime-generated", "configured-or-installer-generated"]}, + "username": {"type": "string", "minLength": 1}, + "password": {"type": ["string", "null"]}, + "username_environment": {"type": "string", "pattern": "^[A-Za-z_][A-Za-z0-9_]*$"}, + "password_environment": {"type": "string", "pattern": "^[A-Za-z_][A-Za-z0-9_]*$"}, + "change_required": {"type": "boolean"}, + "source": {"type": "string"}, + "retrieval": { + "oneOf": [ + {"type": "null"}, + { + "type": "object", + "properties": { + "method": {"const": "container-console-pattern"}, + "pattern_id": {"const": "linuxserver-temporary-password"}, + "pattern": {"type": "string", "minLength": 1}, + "timeout_seconds": {"type": "integer", "minimum": 1, "maximum": 600} + }, + "required": ["method", "timeout_seconds"], + "anyOf": [{"required": ["pattern_id"]}, {"required": ["pattern"]}], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "method": {"const": "container-file"}, + "path": {"type": "string", "pattern": "^/[^\\s]*$"}, + "pattern": {"type": "string", "minLength": 1}, + "timeout_seconds": {"type": "integer", "minimum": 1, "maximum": 600} + }, + "required": ["method", "path", "timeout_seconds"], + "additionalProperties": false + } + ] + } + }, + "additionalProperties": false + } + } + }, + "additionalProperties": false + }, + "compose_stack": { + "type": "object", + "required": ["project_name", "deployment_model", "user_experience", "main_service", "service_count", "services", "top_level", "networking", "storage", "orchestration", "installer_inputs"], + "properties": { + "project_name": {"type": "string", "minLength": 1}, + "deployment_model": {"const": "one-native-oci-lxc-per-compose-service"}, + "user_experience": {"const": "single-application-install"}, + "main_service": {"type": "string", "minLength": 1}, + "service_count": {"type": "integer", "minimum": 1}, + "services": { + "type": "array", + "minItems": 1, + "items": { + "type": "object", + "required": ["name", "image", "is_main", "role", "vmid_offset", "depends_on", "frontend_network", "private_network", "compose"], + "properties": { + "name": {"type": "string", "minLength": 1}, + "image": {"type": ["string", "null"]}, + "is_main": {"type": "boolean"}, + "role": {"enum": ["frontend", "dependency"]}, + "vmid_offset": {"type": "integer", "minimum": 0}, + "depends_on": {"type": "array", "items": {"type": "string"}, "uniqueItems": true}, + "frontend_network": {"type": "boolean"}, + "private_network": {"type": "boolean"}, + "compose": {"type": "object"} + }, + "additionalProperties": false + } + }, + "top_level": {"type": "object"}, + "networking": {"type": "object"}, + "storage": {"type": "array", "items": {"type": "object"}}, + "orchestration": {"type": "object"}, + "installer_inputs": {"type": "object"} + }, + "additionalProperties": false + }, + "proxmox": {"type": "object"}, + "compatibility": { + "type": "object", + "required": ["automatic_install_candidate", "validated", "supported_compose_keys", "untranslated_blockers", "policy"], + "properties": { + "automatic_install_candidate": {"type": "boolean"}, + "validated": {"type": "boolean"}, + "supported_compose_keys": {"type": "array", "items": {"type": "string"}}, + "untranslated_blockers": {"type": "array", "items": {"type": "string"}}, + "policy": {"type": "string"} + }, + "additionalProperties": false + }, + "validation": {"type": "object"}, + "lifecycle": {"type": "object"} + }, + "additionalProperties": false, + "allOf": [ + { + "if": { + "properties": {"schema_version": {"enum": ["0.3.0", "0.4.0", "0.5.0"]}}, + "required": ["schema_version"] + }, + "then": {"required": ["first_run"]} + }, + { + "if": { + "properties": {"schema_version": {"const": "0.5.0"}}, + "required": ["schema_version"] + }, + "then": { + "required": ["compose_stack"], + "properties": { + "source": {"required": ["image_repository_url"]} + } + } + } + ], + "$defs": { + "localizedText": { + "type": "object", + "required": ["en_US"], + "additionalProperties": {"type": "string"} + } + } +} diff --git a/oci/src/proxmenux_oci/__init__.py b/oci/src/proxmenux_oci/__init__.py new file mode 100644 index 00000000..0d766640 --- /dev/null +++ b/oci/src/proxmenux_oci/__init__.py @@ -0,0 +1,3 @@ +"""ProxMenux LinuxServer-to-Proxmox OCI laboratory tools.""" + +__version__ = "0.1.0" diff --git a/oci/src/proxmenux_oci/__main__.py b/oci/src/proxmenux_oci/__main__.py new file mode 100644 index 00000000..a049ad7a --- /dev/null +++ b/oci/src/proxmenux_oci/__main__.py @@ -0,0 +1,5 @@ +from .cli import main + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/oci/src/proxmenux_oci/arr_suite.py b/oci/src/proxmenux_oci/arr_suite.py new file mode 100644 index 00000000..731e731f --- /dev/null +++ b/oci/src/proxmenux_oci/arr_suite.py @@ -0,0 +1,129 @@ +"""Selectable core Arr suite, reusing the catalog's individual image contracts.""" +import copy +import json +from pathlib import Path + +from .i18n import translate +from .stack import DefaultsUI, StackError + +PLAYERS = ('jellyfin', 'plex', 'emby') +MEDIA_APPS = {'sonarr','radarr','lidarr','qbittorrent','sabnzbd','bazarr','unpackerr',*PLAYERS} + + +class SuiteChildUI(DefaultsUI): + """Reuse image hardware questions without repeating the stack storage wizard.""" + def __init__(self, ui, profile): + self.ui = ui + self.prompts = set() + def visit(value): + if isinstance(value, dict): + for key, item in value.items(): + if key in ('prompt','path_prompt','enable_prompt') and isinstance(item,str): + # The installer may send either the template text or its translation. + self.prompts.add(item) + self.prompts.add(translate(item)) + visit(item) + elif isinstance(value,list): + for item in value: visit(item) + visit(profile) + + def ask(self, text, default=None, required=True): + return self.ui.ask(text,default,required) if text in self.prompts else super().ask(text,default,required) + + def choose(self, text, options, default=None): + return self.ui.choose(text,options,default) if text in self.prompts else default + + def confirm(self, text, default=False): + return self.ui.confirm(text,default) if text in self.prompts else default + + def password(self, text, required=True): + return self.ui.password(text,required=required) + + +def build_suite(template, ui): + from .installer import build_deployment, _hostname_default + choices = template['proxmox']['installer_profile']['applications'] + profile = template['proxmox']['installer_profile'] + selected = ui.checklist(translate('Arr suite: applications to install'), [(x, x.capitalize()) for x in choices], + profile.get('default_applications',['prowlarr','sonarr','radarr','qbittorrent'])) + if set(selected) - set(choices): + raise StackError(translate('Invalid suite application')) + player = ui.choose(translate('Media server'), [(x,x.capitalize()) for x in PLAYERS]+[('none',translate('None'))], 'jellyfin') + if player not in (*PLAYERS,'none'): + raise StackError(translate('Media server selection cancelled or invalid')) + if player != 'none': selected = list(selected)+[player] + if not selected: + raise StackError(translate('Select at least one suite application')) + if 'unpackerr' in selected and not set(selected) & {'sonarr','radarr','lidarr'}: + raise StackError(translate('Unpackerr requires Sonarr, Radarr or Lidarr in this suite')) + name = _hostname_default(ui.ask(translate('Stack name'), 'suite-arr')) + base = ui.ask(translate('Base VMID (empty = next free block)'), '', required=False) + from . import host + from . import network as access + from .installer import ask_bridge, ask_storage + storage = ask_storage(ui, translate('Storage for rootfs and private configuration'), 'rootdir', 'local-lvm') + cache = ask_storage(ui, translate('Storage for the OCI image cache'), 'vztmpl', 'local') + bridge = ask_bridge(ui, translate('Access bridge'), 'vmbr0') + reachable = [app for app in selected if app != 'unpackerr'] + labels, gateway = access.ask_addresses(ui, bridge, [app.capitalize() for app in reachable]) + addresses = dict(zip(reachable, labels.values())) + timezone = ui.ask(translate('Timezone'), host.timezone()) + onboot = ui.confirm(translate('Start each LXC with Proxmox (no coordinated startup)'), False) + shared = ui.ask(translate('Shared host media directory'), '/mnt/oci-shared/media') if set(selected) & MEDIA_APPS else None + if shared and (not shared.startswith('/') or shared == '/' or '..' in shared.split('/') or any(c in shared for c in ',\n\r')): + raise StackError(translate('Invalid shared path')) + ordered = list(selected) + services = [] + credentials = None + if 'qbittorrent' in selected: + password = ui.password(translate('qBittorrent WebUI password (user: admin)'), required=True) + if not password: + raise StackError(translate('qBittorrent requires a non-empty password')) + credentials = {'username':'admin','password':password} + for app in ordered: + path = Path(__file__).resolve().parents[2] / 'catalog/apps' / (app+'.json') + child = json.loads(path.read_text()) + if not child['compatibility']['automatic_install_candidate']: + raise StackError(f"{app}: {translate('individual template is blocked')}") + plan = build_deployment(copy.deepcopy(child), SuiteChildUI(ui,child['proxmox'].get('installer_profile',{}))) + plan.update(hostname=_hostname_default(name+'-'+app), start_after_create=False, onboot=onboot, template_storage=cache) + plan['rootfs']['storage'] = storage + for env in plan['environment']: + if env['name'] == 'TZ': env['value'] = timezone + if env['name'] in ('PUID','PGID'): env['value'] = '1000' + config_path = '/app/config' if app=='seerr' else '/config' + config = next(copy.deepcopy(m) for m in plan['mounts'] if m['container_path']==config_path) + config.update(type='managed-volume', source=storage, size_gb=max(config.get('size_gb') or 0,8), backup=True) + plan['mounts'] = [config] + if app in MEDIA_APPS: + plan['mounts'].append({'type':'host-bind','source':shared,'container_path':'/data','size_gb':None,'backup':False,'read_only':False,'create_if_missing':True}) + from .custom_mounts import ask_custom_mounts + ui.info(f"{translate('Additional paths for')} {app}") + plan['mounts'] = ask_custom_mounts(ui, plan['mounts'], storage) + endpoint = child['first_run']['endpoints'][0] if child['first_run']['endpoints'] else None + health = {'type':'http','timeout_seconds':360,'endpoint':endpoint} if endpoint else {'type':'running','timeout_seconds':60} + if app == 'qbittorrent': + child['first_run']['credentials'] = [] + services.append({'name':app,'main':False,'kind':'application','offset':len(services), + 'aliases':[app], 'frontend':app!='unpackerr', 'template':child,'deployment':plan, + 'healthcheck':health, 'frontend_ipv4':addresses.get(app)}) + if app in ('seerr','unpackerr'): + services[-1]['config_owner'] = 1000 + if app == 'unpackerr': + services[-1]['deferred_setup'] = True + if app == 'qbittorrent': + services[-1]['setup_credentials'] = credentials + return {'deployment_kind':'generic-multi-lxc-stack','suite_arr':True,'lifecycle_mode':'independent','stack_name':name, + 'base_vmid':int(base) if base else None,'services':services,'shared_media':shared,'media_player':player, + 'completion_notes':[ + translate('Independent LXCs: no main container or hookscript. Each one keeps its own Start with Proxmox setting.'), + f"{translate('Shared host content (not included in LXC backups):')} {shared} -> /data" + if shared else translate('No shared media content.'), + translate('Libraries: /data/media/movies, /data/media/series and /data/media/music. Select them in the media server.'), + translate('Complete the media server and Seerr accounts, the Bazarr providers and the SABnzbd Usenet credentials when they are selected.'), + translate('Seerr/Bazarr connections, the SABnzbd client and the Lidarr profiles, root folder and client are configured manually in this version.'), + translate('Gluetun/VPN not yet available: this suite does not route downloads through a VPN.') + ], + 'rootfs_storage':storage,'template_storage':cache,'onboot':onboot,'start_after_create':True, + 'network':{'frontend_bridge':bridge,'frontend_gateway':gateway,'private_allocation':'automatic','private_bridge':'vmbr10', + 'private_subnet':'10.77.0.0/24','private_host_address':'10.77.0.1/24'}} diff --git a/oci/src/proxmenux_oci/casaos.py b/oci/src/proxmenux_oci/casaos.py new file mode 100644 index 00000000..b1d47a32 --- /dev/null +++ b/oci/src/proxmenux_oci/casaos.py @@ -0,0 +1,989 @@ +from __future__ import annotations + +import hashlib +import re +from datetime import date, datetime, timezone +from typing import Any + +import yaml + +from .converter import ( + SENSITIVE_NAME, + SUPPORTED_SERVICE_KEYS, + ConversionError, + _compose_installer_profile, + _compose_option_blockers, + _compose_security_profile, + _compose_runtime_adaptations, + _duration_seconds, + _environment_contract, + _image_contract, + _mount_contract, + _optional_markers, + _port_contract, + _compose_requests_privileged_lxc, + _shm_size_mb, +) + + +CASAOS_CATEGORY_MAP = { + "AI": ("ai", "AI / Coding & Dev-Tools"), + "Developer": ("ai", "AI / Coding & Dev-Tools"), + "Finance": ("finance", "Finance & Budgeting"), + "Home": ("smarthome", "IoT & Smart Home"), + "Media": ("media", "Media & Streaming"), + "Networking": ("network", "Network & Firewall"), + "Productivity": ("productivity", "Productivity & Workflows"), + "Social": ("communication", "Communication & Community"), +} + +ARCHITECTURE_MAP = { + "amd64": "amd64", + "arm64": "arm64", +} + +CASAOS_TRANSLATED_SERVICE_KEYS = SUPPORTED_SERVICE_KEYS | {"deploy", "network_mode"} + + +def normalize_app_id(value: str) -> str: + normalized = re.sub(r"[^a-z0-9]+", "-", value.casefold()).strip("-") + if not normalized: + raise ConversionError(f"No se puede normalizar el identificador CasaOS: {value!r}") + return normalized + + +def _localized(value: Any, fallback: str = "") -> dict[str, str]: + if isinstance(value, dict): + result = {str(key): str(text) for key, text in value.items() if text not in (None, "")} + if "en_US" not in result: + result["en_US"] = next(iter(result.values()), fallback) + return result + if value not in (None, ""): + return {"en_US": str(value)} + return {"en_US": fallback} + + +def _json_safe(value: Any) -> Any: + if isinstance(value, dict): + return {str(key): _json_safe(item) for key, item in value.items()} + if isinstance(value, list): + return [_json_safe(item) for item in value] + if isinstance(value, (date, datetime)): + return value.isoformat() + return value + + +def _main_service(compose: dict[str, Any], metadata: dict[str, Any]) -> tuple[str, dict[str, Any]]: + services = compose.get("services") + if not isinstance(services, dict) or not services: + raise ConversionError("El Compose CasaOS no contiene servicios") + service_name = metadata.get("main") + if not service_name and len(services) == 1: + service_name = next(iter(services)) + if not service_name or service_name not in services: + raise ConversionError("x-casaos.main no identifica un servicio valido") + service = services[service_name] + if not isinstance(service, dict) or not service.get("image"): + raise ConversionError("El servicio principal CasaOS no declara una imagen") + return str(service_name), service + + +def _image_tail(image: str) -> str: + return normalize_app_id(canonical_image_repository(image).rsplit("/", 1)[-1]) + + +def image_repository(image: str) -> str: + reference = image.strip().split("@", 1)[0] + slash = reference.rfind("/") + colon = reference.rfind(":") + return reference[:colon] if colon > slash else reference + + +def canonical_image_repository(image: str) -> str: + repository = image_repository(image).casefold() + for prefix in ("lscr.io/linuxserver/", "ghcr.io/linuxserver/", "docker.io/linuxserver/"): + if repository.startswith(prefix): + return f"linuxserver/{repository.rsplit('/', 1)[-1]}" + return repository + + +def latest_image_reference(image: str) -> str: + return f"{image_repository(image)}:latest" + + +def image_repository_url(image: str) -> str: + repository = image_repository(image) + parts = repository.split("/") + if "." in parts[0] or ":" in parts[0] or parts[0] == "localhost": + registry = parts[0] + path = "/".join(parts[1:]) + else: + registry = "docker.io" + path = repository + if registry == "docker.io": + if "/" in path: + return f"https://hub.docker.com/r/{path}" + return f"https://hub.docker.com/_/{path}" + return f"https://{registry}/{path}" + + +def _variant(app_id: str, service: dict[str, Any]) -> str | None: + folded = app_id.casefold() + names = { + "nvidia": "nvidia", + "cuda": "nvidia", + "amd": "amd", + "rocm": "amd", + "intel": "intel", + "openvino": "intel", + "gpu": "gpu", + } + for marker, variant in names.items(): + if re.search(rf"(?:^|[-_]){marker}(?:$|[-_])", folded): + return variant + hardware_text = str( + { + "devices": service.get("devices"), + "runtime": service.get("runtime"), + "environment": service.get("environment"), + "deploy": service.get("deploy"), + } + ).casefold() + if "nvidia" in hardware_text or "cuda" in hardware_text: + return "nvidia" + if "rocm" in hardware_text or "/dev/kfd" in hardware_text: + return "amd" + if "openvino" in hardware_text: + return "intel" + if "/dev/dri" in hardware_text or "/dev/video" in hardware_text: + return "vaapi" + reservations = (((service.get("deploy") or {}).get("resources") or {}).get("reservations") or {}) + if reservations.get("devices"): + return "gpu" + return None + + +def _base_app_id(app_id: str) -> str: + return re.sub(r"-(?:nvidia|cuda|amd|rocm|intel|openvino|gpu)$", "", app_id, flags=re.I) + + +def _functional_base_id(app_id: str, distribution: str) -> str: + base_id = _base_app_id(app_id) + if base_id.startswith("icewhale-"): + base_id = base_id.removeprefix("icewhale-") + if distribution in {"official", "linuxserver"} or "-" not in base_id: + return base_id + prefix, remainder = base_id.split("-", 1) + if len(prefix) >= 5 and (distribution.startswith(prefix) or prefix.startswith(distribution)): + return remainder + return base_id + + +def image_distributor(image: str, base_app_id: str) -> str: + repository = canonical_image_repository(image) + if repository.startswith("linuxserver/"): + return "linuxserver" + parts = repository.split("/") + if len(parts) == 1: + return "official" + if "." in parts[0] and len(parts) > 1: + owner = parts[1] + else: + owner = parts[0] + owner_id = normalize_app_id(owner) + compact_owner = owner_id.replace("-", "") + compact_app = base_app_id.replace("-", "") + if compact_owner in compact_app or compact_app in compact_owner: + return "official" + return owner_id + + +def image_provider(distribution: str) -> str: + return "linuxserver.io" if distribution == "linuxserver" else distribution + + +def image_documentation_url(image: str) -> str | None: + if canonical_image_repository(image).startswith("linuxserver/"): + return f"https://docs.linuxserver.io/images/docker-{_image_tail(image)}/" + return None + + +def parse_casaos_compose(compose_text: str) -> tuple[dict[str, Any], dict[str, Any], str, dict[str, Any]]: + try: + compose = yaml.safe_load(compose_text) + except yaml.YAMLError as exc: + raise ConversionError(f"Docker Compose CasaOS no valido: {exc}") from exc + if not isinstance(compose, dict): + raise ConversionError("El documento CasaOS no es un objeto Compose") + metadata = compose.get("x-casaos") + if not isinstance(metadata, dict): + raise ConversionError("El Compose no contiene metadatos x-casaos") + service_name, service = _main_service(compose, metadata) + return compose, metadata, service_name, service + + +def summarize_casaos_compose(compose_text: str, source_path: str) -> dict[str, Any]: + compose, metadata, service_name, service = parse_casaos_compose(compose_text) + app_id = normalize_app_id(str(compose.get("name") or source_path.split("/")[-2])) + title = _localized(metadata.get("title"), app_id)["en_US"] + architectures = [] + for raw in metadata.get("architectures") or ["amd64"]: + architecture = ARCHITECTURE_MAP.get(str(raw).casefold()) + if architecture and architecture not in architectures: + architectures.append(architecture) + image = str(service["image"]) + identity_candidates = { + app_id, + normalize_app_id(service_name), + normalize_app_id(title), + _image_tail(image), + } + store_id = str(metadata.get("id") or "") + if store_id: + identity_candidates.add(normalize_app_id(store_id.rsplit(".", 1)[-1])) + distribution = image_distributor(image, _base_app_id(app_id)) + return { + "id": app_id, + "base_id": _functional_base_id(app_id, distribution), + "title": title, + "description": _neutral_localized(metadata.get("description"), "")["en_US"], + "website": metadata.get("website"), + "repository": metadata.get("repo"), + "icon": None, + "architectures": architectures or ["amd64"], + "updated_at": str(metadata.get("update_at") or ""), + "version": str(metadata.get("version") or ""), + "store_id": store_id, + "main_service": service_name, + "main_image": image, + "main_image_repository": canonical_image_repository(image), + "selected_image": latest_image_reference(image), + "variant": _variant(app_id, service), + "distribution": distribution, + "identity_candidates": sorted(identity_candidates), + } + + +def _endpoint(metadata: dict[str, Any], service: dict[str, Any]) -> list[dict[str, Any]]: + raw_port = metadata.get("port_map") + if raw_port in (None, ""): + return [] + try: + published_port = int(str(raw_port)) + except ValueError: + return [] + container_port = published_port + for item in service.get("ports") or []: + if isinstance(item, dict): + published = item.get("published") + target = item.get("target") + else: + port_text = str(item).split("/", 1)[0] + parts = port_text.split(":") + published = parts[-2] if len(parts) > 1 else None + target = parts[-1] + if str(published) == str(published_port): + try: + container_port = int(str(target)) + except ValueError: + pass + break + scheme = str(metadata.get("scheme") or "http").casefold() + if scheme not in {"http", "https"}: + scheme = "http" + path = str(metadata.get("index") or "/") + if re.search(r"casaos|zimaos|zima", path, re.I): + path = "/" + if not path.startswith("/"): + path = f"/{path}" + return [ + { + "label": "Web UI", + "scheme": scheme, + "port": container_port, + "path": path, + "source": "compose-metadata", + } + ] + + +def _credentials(metadata: dict[str, Any]) -> list[dict[str, Any]]: + tips = metadata.get("tips") or {} + if not isinstance(tips, dict): + return [] + before_install = tips.get("before_install") or {} + text = before_install.get("en_US", "") if isinstance(before_install, dict) else str(before_install) + lines = text.splitlines() + for index, line in enumerate(lines): + cells = [cell.strip().strip("`* ") for cell in line.strip().strip("|").split("|")] + if len(cells) < 2 or "user" not in cells[0].casefold() or "pass" not in cells[1].casefold(): + continue + for row in lines[index + 1 :]: + values = [cell.strip().strip("`* ") for cell in row.strip().strip("|").split("|")] + if len(values) < 2: + break + if all(re.fullmatch(r"[-: ]+", value or "-") for value in values[:2]): + continue + username, password = values[:2] + if not username or not password: + continue + dynamic = any(marker in password.casefold() for marker in ("from log", "in the log", "generated")) + if dynamic: + return [] + return [ + { + "label": "Default login", + "type": "static-default", + "username": username, + "password": password, + "change_required": True, + "source": "casaos-x-casaos-tips", + "retrieval": None, + } + ] + return [] + + +def _tips(metadata: dict[str, Any]) -> list[str]: + result: list[str] = [] + tips = metadata.get("tips") or {} + if not isinstance(tips, dict): + return result + for value in tips.values(): + if isinstance(value, dict): + text = value.get("en_US") or next(iter(value.values()), "") + else: + text = value + if text: + result.append(str(text)) + return result + + +def _neutral_localized(value: Any, fallback: str = "") -> dict[str, str]: + """The source English of a catalog field, with the upstream product name + neutralised. + + Only the source is kept. Copying the English into a second locale when + upstream carried no translation made the field look translated, which is + what stops it from ever being translated. Whatever reaches the reader goes + through `translate()` instead, like every other string in ProxMenux. + """ + english = _localized(value, fallback).get("en_US") or fallback + return {"en_US": re.sub(r"(?:CasaOS|ZimaOS|Zima)", "self-hosted server", + english, flags=re.I)} + + +def _neutral_scalar(value: Any, fallback: str | None = None) -> str | None: + if value in (None, ""): + return fallback + text = re.sub(r"(?:CasaOS|ZimaOS|Zima)", "", str(value), flags=re.I).strip(" -") + return text or fallback + + +def _neutralize_discovery_value(value: Any, replacement: str) -> Any: + if isinstance(value, dict): + return { + str(key): item if str(key) == "image" else _neutralize_discovery_value(item, replacement) + for key, item in value.items() + } + if isinstance(value, list): + return [_neutralize_discovery_value(item, replacement) for item in value] + if not isinstance(value, str): + return value + return re.sub(r"(?:CasaOS|ZimaOS|Zima)", replacement, value, flags=re.I) + + +def _environment_entries(value: Any) -> list[tuple[str, Any]]: + if isinstance(value, dict): + return [(str(name), raw) for name, raw in value.items()] + if isinstance(value, list): + return [ + (str(item).partition("=")[0], str(item).partition("=")[2]) + for item in value + if str(item).partition("=")[1] + ] + return [] + + +def _secret_binding_ids(services: dict[str, Any]) -> dict[tuple[str, str], str]: + records: list[tuple[str, str, str, tuple[str, ...]]] = [] + for service_name, service in services.items(): + if not isinstance(service, dict): + continue + for name, raw in _environment_entries(service.get("environment")): + if not SENSITIVE_NAME.search(name): + continue + text = str(raw or "") + reference = re.fullmatch( + r"\$\{?([A-Za-z_][A-Za-z0-9_]*)(?::-[^}]*)?\}?", text + ) + normalized_name = normalize_app_id(name) + database_password_names = { + "db-password", + "database-password", + "postgres-password", + "postgresql-password", + "mysql-password", + "mariadb-password", + } + family = "database-password" if normalized_name in database_password_names else normalized_name + group = ( + ("reference", reference.group(1)) + if reference + else ("literal", family, text) + ) + records.append((str(service_name), name, text, group)) + + grouped: dict[tuple[str, ...], list[tuple[str, str, str, tuple[str, ...]]]] = {} + for record in records: + grouped.setdefault(record[3], []).append(record) + + result: dict[tuple[str, str], str] = {} + for group, members in grouped.items(): + if group[0] == "reference": + secret_id = normalize_app_id(group[1]) + elif len(members) > 1: + names = [normalize_app_id(member[1]) for member in members] + secret_id = "db-password" if "db-password" in names else min(names, key=len) + else: + secret_id = normalize_app_id(members[0][1]) + for service_name, name, _, _ in members: + result[(service_name, name)] = secret_id + return result + + +def _generated_environment( + value: Any, + replacement: str, + service_name: str, + secret_ids: dict[tuple[str, str], str], +) -> Any: + def secret_placeholder(name: str) -> str: + secret_id = secret_ids[(service_name, name)].replace("-", "_").upper() + return f"${{GENERATED_{secret_id}}}" + + if isinstance(value, dict): + result = {} + for name, raw in value.items(): + name = str(name) + result[name] = ( + secret_placeholder(name) + if SENSITIVE_NAME.search(name) + else _neutralize_discovery_value(raw, replacement) + ) + return result + if isinstance(value, list): + result = [] + for raw in value: + name, separator, setting = str(raw).partition("=") + if separator and SENSITIVE_NAME.search(name): + result.append(f"{name}={secret_placeholder(name)}") + else: + result.append(_neutralize_discovery_value(raw, replacement)) + return result + return _neutralize_discovery_value(value, replacement) + + +def _normalized_compose(compose: dict[str, Any], project_name: str) -> tuple[dict[str, Any], str]: + normalized = _json_safe(compose) + normalized.pop("x-casaos", None) + secret_ids = _secret_binding_ids(compose.get("services") or {}) + for service_name, service in (normalized.get("services") or {}).items(): + if not isinstance(service, dict): + continue + service.pop("x-casaos", None) + if service.get("image"): + service["image"] = latest_image_reference(str(service["image"])) + if "environment" in service: + service["environment"] = _generated_environment( + service["environment"], project_name, str(service_name), secret_ids + ) + labels = service.get("labels") + if labels: + encoded_labels = str(labels) + if re.search(r"casaos|zimaos|icewhaletech/casaos-appstore", encoded_labels, re.I): + service.pop("labels", None) + normalized = _neutralize_discovery_value(normalized, project_name) + text = yaml.safe_dump(normalized, sort_keys=False, allow_unicode=False) + return normalized, text + + +def _generated_secrets(services: dict[str, Any]) -> list[dict[str, Any]]: + bindings: dict[str, list[dict[str, str]]] = {} + for service_name, service in services.items(): + if not isinstance(service, dict): + continue + environment = service.get("environment") or {} + if isinstance(environment, dict): + entries = [(str(name), str(value or "")) for name, value in environment.items()] + elif isinstance(environment, list): + entries = [ + (str(item).partition("=")[0], str(item).partition("=")[2]) + for item in environment + ] + else: + entries = [] + for name, value in entries: + match = re.fullmatch(r"\$\{GENERATED_([A-Z0-9_]+)\}", value) + if match: + bindings.setdefault(match.group(1).casefold().replace("_", "-"), []).append( + {"service": str(service_name), "environment_variable": name} + ) + return [ + { + "id": secret_id, + "strategy": "generate-cryptographically-random-at-install", + "bindings": secret_bindings, + } + for secret_id, secret_bindings in sorted(bindings.items()) + ] + + +def _dependency_names(service: dict[str, Any], service_names: set[str]) -> list[str]: + value = service.get("depends_on") or [] + names = value.keys() if isinstance(value, dict) else value + return sorted({str(name) for name in names if str(name) in service_names}) + + +def _service_order(services: dict[str, Any], main_service: str) -> list[str]: + names = set(services) + dependencies = { + str(name): _dependency_names(service, names) if isinstance(service, dict) else [] + for name, service in services.items() + } + ordered: list[str] = [] + visiting: set[str] = set() + + def visit(name: str) -> None: + if name in ordered or name in visiting: + return + visiting.add(name) + for dependency in dependencies[name]: + visit(dependency) + visiting.remove(name) + ordered.append(name) + + for name in sorted(names - {main_service}): + visit(name) + visit(main_service) + return ordered + + +def _stack_storage(services: dict[str, Any], markers: dict[str, set[str]]) -> list[dict[str, Any]]: + storage: list[dict[str, Any]] = [] + shared_targets = re.compile( + r"^/(?:data|downloads?|media|movies?|music|photos?|pictures?|recordings?|tv|videos?)(?:/|$)|/(?:library|uploads?)(?:/|$)", + re.I, + ) + disposable_targets = {"/cache", "/tmp", "/transcode"} + system_targets = {"/etc/localtime", "/etc/timezone"} + runtime_targets = {"/var/run/docker.sock", "/run/docker.sock"} + for service_name, service in services.items(): + if not isinstance(service, dict): + continue + mounts = _mount_contract(service.get("volumes"), markers["volumes"]) + for mount in mounts: + target = mount["container_path"] + source = mount.get("compose_source_example") + system_bind = target in system_targets + runtime_bind = target in runtime_targets + shareable = bool( + not system_bind + and not runtime_bind + and source + and str(source).startswith("/") + and shared_targets.search(target) + ) + if system_bind: + mode = "system-bind" + elif runtime_bind: + mode = "runtime-bind" + elif shareable: + mode = "host-bind" + else: + mode = "managed-volume" + storage.append( + { + "id": f"{normalize_app_id(str(service_name))}-{mount['id']}", + "service": str(service_name), + "container_path": target, + "mode": mode, + "user_selectable": shareable, + "backup": mode == "managed-volume" and target not in disposable_targets, + "shared_with_other_lxc": shareable, + "source_path": str(source) if system_bind else None, + "source_path_prompt": ( + f"Host directory for {service_name}:{target}" if shareable else None + ), + } + ) + return storage + + +def _compose_stack_contract( + compose: dict[str, Any], + normalized_compose: dict[str, Any], + main_service: str, + markers: dict[str, set[str]], +) -> dict[str, Any]: + services = compose["services"] + names = set(services) + start_order = _service_order(services, main_service) + service_contracts = [] + vmid_offsets = {main_service: 0} + vmid_offsets.update( + {name: offset for offset, name in enumerate((n for n in start_order if n != main_service), 1)} + ) + for name in start_order: + value = services[name] + normalized_service = normalized_compose["services"][name] + ports = value.get("ports") or [] if isinstance(value, dict) else [] + service_contracts.append( + { + "name": str(name), + "image": latest_image_reference(str(value.get("image"))) + if isinstance(value, dict) and value.get("image") + else None, + "is_main": name == main_service, + "role": "frontend" if name == main_service else "dependency", + "vmid_offset": vmid_offsets[name], + "depends_on": _dependency_names(value, names) if isinstance(value, dict) else [], + "frontend_network": bool(name == main_service or ports), + "private_network": len(services) > 1, + "compose": _json_safe(normalized_service), + } + ) + return { + "project_name": str(compose.get("name") or main_service), + "deployment_model": "one-native-oci-lxc-per-compose-service", + "user_experience": "single-application-install", + "main_service": main_service, + "service_count": len(services), + "services": service_contracts, + "top_level": _json_safe( + {key: value for key, value in normalized_compose.items() if key != "services"} + ), + "networking": { + "frontend": "selected-proxmox-bridge", + "private_required": len(services) > 1, + "private_creation": "automatic-create-if-missing", + "private_address_allocation": "automatic-static-address-per-service", + "service_discovery": "private-addresses-with-compose-service-host-aliases", + "dependency_external_access": "disabled-unless-service-publishes-ports", + "prompt_user_for_private_network": False, + }, + "storage": _stack_storage(normalized_compose["services"], markers), + "orchestration": { + "reserve_vmids_atomically": len(services), + "start_order": start_order, + "stop_order": list(reversed(start_order)), + "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", + "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes", + }, + "installer_inputs": { + "prompted": [ + "stack_name", + "base_vmid", + "rootfs_storage", + "persistent_data_destinations", + "frontend_bridge", + "frontend_ipv4_mode", + ], + "automatic": [ + "dependent_vmids", + "private_bridge", + "private_subnet", + "private_service_addresses", + "compose_service_aliases", + "generated_secrets", + "dependency_start_and_stop_order", + ], + "generated_secrets": _generated_secrets(normalized_compose["services"]), + }, + } + + +def _memory_mb(service: dict[str, Any]) -> int: + value = (((service.get("deploy") or {}).get("resources") or {}).get("reservations") or {}).get("memory") + match = re.fullmatch(r"\s*(\d+(?:\.\d+)?)\s*([KMG]?)B?\s*", str(value or ""), re.I) + if not match: + return 1024 + number = float(match.group(1)) + unit = match.group(2).upper() + factors = {"": 1 / (1024 * 1024), "K": 1 / 1024, "M": 1, "G": 1024} + return max(128, int(number * factors[unit])) + + +def _blockers( + compose: dict[str, Any], + main_service: str, + optional_devices: set[str] | None = None, +) -> list[str]: + blockers: list[str] = [] + services = compose.get("services") or {} + if len(services) > 1: + blockers.append("multi-service-compose") + for name, service in services.items(): + if not isinstance(service, dict): + blockers.append(f"service:{name}:invalid-definition") + continue + if not service.get("image"): + blockers.append(f"service:{name}:missing-image") + prefix = "" if name == main_service else f"service:{name}:" + unsupported = set(service) - CASAOS_TRANSLATED_SERVICE_KEYS - {"x-casaos"} + for key in sorted(unsupported): + blockers.append(f"{prefix}compose-key:{key}") + blockers.extend( + f"{prefix}{item}" + for item in _compose_option_blockers( + service, + optional_devices if name == main_service else None, + ) + ) + for key in ("configs",): + if compose.get(key): + blockers.append(f"top-level-{key}") + return list(dict.fromkeys(blockers)) + + +def convert_casaos_compose( + compose_text: str, + revision: str, + raw_url: str, + source_path: str, + pushed_at: str, + category: str | None = None, + category_label: str | None = None, + catalog_id: str | None = None, +) -> dict[str, Any]: + compose, metadata, service_name, service = parse_casaos_compose(compose_text) + summary = summarize_casaos_compose(compose_text, source_path) + markers = _optional_markers(compose_text) + ports = _port_contract(service.get("ports"), markers["ports"]) + endpoints = _endpoint(metadata, service) + primary_endpoint = endpoints[0] if endpoints else None + raw_category = str(metadata.get("category") or "") + fallback_category, fallback_label = CASAOS_CATEGORY_MAP.get(raw_category, ("misc", "Miscellaneous")) + category = category or fallback_category + category_label = category_label or fallback_label + stop_grace_period = service.get("stop_grace_period") + stop_grace_seconds = _duration_seconds(stop_grace_period) + blockers = _blockers(compose, service_name, markers["devices"]) + if stop_grace_period is not None and stop_grace_seconds is None: + blockers.append("stop-grace-period-format") + if service.get("shm_size") is not None and _shm_size_mb(service["shm_size"]) is None: + blockers.append("shm-size-format") + services = compose["services"] + untranslated_blockers = blockers + ( + ["native-multi-lxc-orchestrator-not-yet-implemented"] + if len(services) > 1 + else [] + ) + project_name = normalize_app_id(str(compose.get("name") or summary["id"])) + normalized_compose, normalized_compose_text = _normalized_compose(compose, project_name) + normalized_service = normalized_compose["services"][service_name] + related_services = [ + { + "name": str(name), + "image": str(normalized_compose["services"][name].get("image")) + if isinstance(value, dict) and value.get("image") + else None, + } + for name, value in services.items() + if name != service_name + ] + definition_hash = hashlib.sha256(normalized_compose_text.encode("utf-8")).hexdigest() + architectures = summary["architectures"] + generated_at = datetime.now(timezone.utc).replace(microsecond=0).isoformat() + source_image = str(service["image"]) + image = latest_image_reference(source_image) + repository_url = image_repository_url(source_image) + provider = image_provider(summary["distribution"]) + return { + "schema_version": "0.5.0", + "kind": "proxmenux.oci-template", + "id": f"image-{catalog_id or summary['id']}", + "status": ( + "generated-unvalidated" + if not untranslated_blockers + else "generated-review-required" + ), + "catalog_ui": { + "title": _neutral_localized(metadata.get("title"), summary["title"]), + "tagline": _neutral_localized(metadata.get("tagline"), summary["description"]), + "description": _neutral_localized(metadata.get("description"), summary["description"]), + "category": category, + "category_label": category_label, + "author": _neutral_scalar(metadata.get("developer"), provider), + "developer": _neutral_scalar(metadata.get("developer")), + "icon": None, + "thumbnail": None, + "screenshots": [], + "architectures": architectures, + "launch": { + "scheme": primary_endpoint["scheme"] if primary_endpoint else "http", + "port": primary_endpoint["port"] if primary_endpoint else None, + "path": primary_endpoint["path"] if primary_endpoint else "/", + }, + "website": metadata.get("website"), + "documentation": image_documentation_url(source_image), + "repository": repository_url, + "tips": [], + "mini_changelog": [], + "display_version": None, + "updated_at": None, + }, + "source": { + "provider": provider, + "repository": repository_url, + "revision": definition_hash, + "image_repository_url": repository_url, + "readme_pushed_at": pushed_at, + "compose_sha256": definition_hash, + "generated_at": generated_at, + }, + "container_contract": { + "service_name": service_name, + "container_name": service.get("container_name", service_name), + "image": _image_contract(image), + "environment": [ + {**item, "source": "docker-compose"} + for item in _environment_contract( + normalized_service.get("environment"), markers["environment"] + ) + ], + "volumes": _mount_contract(normalized_service.get("volumes"), markers["volumes"]), + "ports": ports, + "related_services": [ + { + "name": item["name"], + "image": item["image"], + } + for item in related_services + ], + "restart": service.get("restart"), + "stop_grace_period": None if stop_grace_period is None else str(stop_grace_period), + "original_compose": normalized_compose_text, + }, + "compose_stack": _compose_stack_contract( + compose, normalized_compose, service_name, markers + ), + "first_run": {"endpoints": endpoints, "credentials": []}, + "proxmox": { + "runtime": "native-oci-lxc", + "technology_status": "proxmox-technology-preview", + "defaults": { + "unprivileged": True, + "ostype": "auto-from-image", + "cores": 2, + "memory_mb": _memory_mb(service), + "swap_mb": 512, + "rootfs_size_gb": 8, + "rootfs_storage": "local-lvm", + "volume_storage": "local-lvm", + "template_storage": "local", + "bridge": "vmbr0", + "ipv4": "dhcp", + "firewall": True, + "host_managed_network": True, + "onboot": False, + "features": ["nesting=1"], + "shutdown_timeout_seconds": stop_grace_seconds or 30, + }, + "image_metadata_policy": { + "entrypoint": "import-from-oci-image", + "cmd": "import-from-oci-image", + "environment": "import-image-env-then-apply-compose-overrides", + "user": "import-from-oci-image", + "working_dir": "import-from-oci-image", + "stop_signal": "import-from-oci-image", + }, + **( + {"installer_profile": _compose_installer_profile(service, markers["devices"], markers["security_opt"])} + if _compose_installer_profile(service, markers["devices"], markers["security_opt"]) + else {} + ), + **( + {"security_profile": _compose_security_profile(service, markers["security_opt"])} + if _compose_security_profile(service, markers["security_opt"]) + else {} + ), + "adaptations": [ + { + "id": "imported-compose-source", + "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", + "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", + "reason": "Catalog import must not imply runtime compatibility.", + "behavioral_impact": "No automatic installation before review.", + "validation": "pending-per-application", + }, + { + "id": "rolling-latest-image", + "upstream_behavior": "A discovered Compose may pin a release tag or digest.", + "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", + "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", + "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", + "validation": "pending-per-application", + }, + { + "id": "dedicated-lxc-network", + "upstream_behavior": "Docker publishes selected container ports on the Docker host.", + "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", + "reason": "A native LXC has its own address and does not require Docker port NAT.", + "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", + "validation": "pending-per-application", + }, + { + "id": "compose-shm-size", + "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", + "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", + "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" if service.get("shm_size") is not None else "not-requested-by-compose", + }, + { + "id": "compose-command", + "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", + "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", + "reason": "Proxmox stores the effective OCI process as one entrypoint string.", + "behavioral_impact": "None expected.", + "validation": "pending-per-application" if service.get("command") is not None else "not-requested-by-compose", + }, + { + "id": "compose-privileged-mode", + "upstream_behavior": "Compose selects whether the container runs in privileged mode.", + "native_lxc_behavior": "ProxMenux keeps the LXC unprivileged by default and exposes the broad Compose privilege request only as an explicit compatibility option.", + "reason": "A Compose privilege request is source metadata, not proof that the image technically requires a privileged LXC.", + "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", + "validation": "optional-explicit-user-consent" if _compose_requests_privileged_lxc(service) else "native-equivalent", + }, + *_compose_runtime_adaptations(service), + ], + }, + "compatibility": { + "automatic_install_candidate": not untranslated_blockers, + "validated": False, + "supported_compose_keys": sorted(CASAOS_TRANSLATED_SERVICE_KEYS), + "untranslated_blockers": untranslated_blockers, + "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available.", + }, + "validation": { + "schema": "passed-at-generation", + "clean_install": "pending", + "service_health": "pending", + "restart_persistence": "pending", + "backup_restore": "pending", + "update_preserves_data": "pending", + }, + "lifecycle": { + "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", + "registry_state": { + "resolved_architecture": None, + "resolved_digest": None, + "image_version_label": None, + "image_created": None, + }, + "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", + "automatic_unattended_updates": False, + }, + } diff --git a/oci/src/proxmenux_oci/catalog.py b/oci/src/proxmenux_oci/catalog.py new file mode 100644 index 00000000..a05fa8f0 --- /dev/null +++ b/oci/src/proxmenux_oci/catalog.py @@ -0,0 +1,762 @@ +from __future__ import annotations + +import json +import hashlib +from concurrent.futures import ThreadPoolExecutor, as_completed +from datetime import datetime, timezone +from pathlib import Path +from typing import Any + +from .casaos import ( + canonical_image_repository, + convert_casaos_compose, + image_provider, + image_repository_url, + normalize_app_id, + summarize_casaos_compose, +) +from .converter import ConversionError, convert_readme, summarize_readme +from .github_source import GitHubSource, Repository, SourceError + +SUPPORTED_CATALOG_ARCHITECTURES = ("amd64", "arm64") +# Size of a container volume the installation does not ask about: its size is +# not the user's decision, so it is given room to grow. +MINIMUM_VOLUME_GB = 16 + + +def supported_architectures(values: list[str]) -> list[str]: + return [architecture for architecture in SUPPORTED_CATALOG_ARCHITECTURES if architecture in values] + + +def imported_catalog_id(summary: dict[str, Any], used_ids: set[str]) -> str: + if summary.get("variant"): + candidate = f"{summary['base_id']}-{summary['variant']}" + elif summary["base_id"] in used_ids: + candidate = f"{summary['base_id']}-{summary['distribution']}" + else: + candidate = summary["id"] + if candidate in used_ids: + candidate = f"{candidate}-{summary['distribution']}" + base_candidate = candidate + suffix = 2 + while candidate in used_ids: + candidate = f"{base_candidate}-{suffix}" + suffix += 1 + return candidate + + +MULTI_CONTAINER_TEMPLATES = {"image-immich", "image-nextcloud-stack", "image-paperless-ngx", "image-tandoor"} + + +def is_multi_container(template: dict[str, Any]) -> bool: + driver = template.get("proxmox", {}).get("installer_profile", {}).get("stack_driver") + return template.get("id") in MULTI_CONTAINER_TEMPLATES or driver in ("generic-multi-lxc-stack", "arr-suite") + + +class Catalog: + def __init__(self, root: Path, source: GitHubSource | None = None) -> None: + self.root = root + self.catalog_dir = root / "catalog" + self.apps_dir = self.catalog_dir / "apps" + self.curated_dir = self.catalog_dir / "curated" + self.overlays_dir = self.catalog_dir / "overlays" + self.exclusions_path = self.catalog_dir / "exclusions.json" + self.categories_path = self.catalog_dir / "categories.json" + self._categories: dict[str, Any] | None = None + self.volume_policy_path = self.catalog_dir / "volume-policy.json" + self._volume_policy: dict[str, Any] | None = None + self.index_path = self.catalog_dir / "index.json" + self.schema_path = root / "schemas" / "oci-template.schema.json" + self.source = source or GitHubSource() + + def sync_index(self) -> dict[str, Any]: + repos = self.source.list_linuxserver_repositories() + try: + proxmenux_metadata = self.source.proxmenux_app_metadata() + except (AttributeError, SourceError, OSError, RuntimeError): + proxmenux_metadata = {} + existing = self._existing_template_statuses() + discovered: list[tuple[Repository, dict[str, Any]]] = [] + linuxserver_skipped: list[dict[str, str]] = [] + + def inspect(repo: Repository) -> tuple[Repository, dict[str, Any]]: + readme = self.source.readme_at_branch(repo) + return repo, summarize_readme(repo, readme) + + with ThreadPoolExecutor(max_workers=8) as executor: + futures = {executor.submit(inspect, repo): repo for repo in repos} + for future in as_completed(futures): + repo = futures[future] + try: + discovered.append(future.result()) + except (ConversionError, OSError, RuntimeError) as exc: + linuxserver_skipped.append({"repository": repo.name, "reason": str(exc)}) + discovered.sort(key=lambda item: item[0].app_id.casefold()) + linuxserver_items = [ + { + "id": repo.app_id, + "provider": "linuxserver.io", + "title": summary["title"], + "repository_name": repo.name, + "repository": repo.html_url, + "description": summary["description"], + "website": summary["website"], + "icon": summary["icon"], + "architectures": supported_architectures(summary["architectures"]), + "default_branch": repo.default_branch, + "pushed_at": repo.pushed_at, + "updated_at": summary["updated_at"], + "main_image": summary["main_image"], + "category": proxmenux_metadata.get(repo.app_id, {}).get("category", "misc"), + "category_label": proxmenux_metadata.get(repo.app_id, {}).get( + "category_label", "Miscellaneous" + ), + "template": f"apps/{repo.app_id}.json" if repo.app_id in existing else None, + "template_status": existing.get(repo.app_id), + "content_hash": self._template_hash(repo.app_id) if repo.app_id in existing else None, + } + for repo, summary in discovered + ] + + curated_items = self._curated_items(existing) + + casaos_state = self.source.casaos_state() + casaos_discovered: list[tuple[str, dict[str, Any]]] = [] + casaos_skipped: list[dict[str, str]] = [] + + def inspect_casaos(path: str) -> tuple[str, dict[str, Any]]: + compose_text, _ = self.source.casaos_compose(path, casaos_state["revision"]) + return path, summarize_casaos_compose(compose_text, path) + + with ThreadPoolExecutor(max_workers=8) as executor: + futures = {executor.submit(inspect_casaos, path): path for path in casaos_state["paths"]} + for future in as_completed(futures): + path = futures[future] + try: + casaos_discovered.append(future.result()) + except (ConversionError, OSError, RuntimeError) as exc: + casaos_skipped.append({"path": path, "reason": str(exc)}) + casaos_discovered.sort(key=lambda item: item[1]["id"]) + imported_exclusions = self._imported_exclusions() + excluded_imports: list[dict[str, str]] = [] + + linuxserver_images = { + canonical_image_repository(item["main_image"]): item["id"] for item in linuxserver_items + } + duplicates: list[dict[str, Any]] = [] + casaos_items: list[dict[str, Any]] = [] + used_ids = {item["id"] for item in linuxserver_items + curated_items} + curated_replacements = { + source_id: item["id"] + for item in curated_items + for source_id in item.get("replaces_discovered_ids", []) + } + for path, summary in casaos_discovered: + if summary["id"] in imported_exclusions: + excluded_imports.append( + { + "source_id": summary["id"], + "source_path": path, + "reason": imported_exclusions[summary["id"]], + } + ) + continue + replaced_by = curated_replacements.get(summary["id"]) + if replaced_by: + duplicates.append( + { + "source_id": summary["id"], + "source_path": path, + "main_image": summary["main_image"], + "matched_catalog_id": replaced_by, + "reason": "replaced-by-curated-laboratory-profile", + } + ) + continue + matched_linuxserver = linuxserver_images.get(summary["main_image_repository"]) + if matched_linuxserver and summary["variant"] is None: + duplicates.append( + { + "source_id": summary["id"], + "source_path": path, + "main_image": summary["main_image"], + "matched_catalog_id": matched_linuxserver, + "reason": "same-linuxserver-image-without-distinct-deployment-variant", + } + ) + continue + catalog_id = imported_catalog_id(summary, used_ids) + used_ids.add(catalog_id) + metadata = proxmenux_metadata.get(summary["id"], {}) + if not metadata.get("category") and catalog_id in existing: + # The upstream metadata is keyed by the source application id + # and does not always carry a category, while the generated + # template has already resolved one. Without this the entry + # reaches the index under no category at all and the reader + # cannot find it by browsing. + try: + generated_ui = json.loads( + (self.apps_dir / f"{catalog_id}.json").read_text(encoding="utf-8") + )["catalog_ui"] + metadata = { + **metadata, + "category": generated_ui.get("category"), + "category_label": generated_ui.get("category_label"), + } + except (OSError, ValueError, KeyError): + pass + casaos_items.append( + { + "id": catalog_id, + "source_app_id": summary["id"], + "provider": image_provider(summary["distribution"]), + "template_family": "imported-compose", + "variant": summary["variant"], + "title": summary["title"], + "repository": image_repository_url(summary["main_image"]), + "description": summary["description"], + "website": summary["website"], + "icon": summary["icon"], + "architectures": supported_architectures(summary["architectures"]), + "default_branch": "main", + "source_path": path, + "source_revision": casaos_state["revision"], + "pushed_at": casaos_state["pushed_at"], + "updated_at": summary["updated_at"], + "main_image": summary["selected_image"], + "category": metadata.get("category"), + "category_label": metadata.get("category_label"), + "template": f"apps/{catalog_id}.json" if catalog_id in existing else None, + "template_status": existing.get(catalog_id), + "content_hash": self._template_hash(catalog_id) if catalog_id in existing else None, + } + ) + + applications = sorted( + linuxserver_items + curated_items + casaos_items, + key=lambda item: item["id"].casefold(), + ) + payload = { + "schema_version": "0.2.0", + "kind": "proxmenux.oci-catalog-index", + "provider": "multiple-container-images", + "generated_at": datetime.now(timezone.utc).replace(microsecond=0).isoformat(), + "applications": applications, + "discovery": { + "linuxserver": { + "repositories_examined": len(repos), + "compose_applications": len(discovered), + "skipped_count": len(linuxserver_skipped), + "skipped": sorted(linuxserver_skipped, key=lambda item: item["repository"]), + }, + "imported_composes": { + "compose_applications": len(casaos_discovered), + "included_count": len(casaos_items), + "duplicate_count": len(duplicates), + "duplicates": duplicates, + "excluded_count": len(excluded_imports), + "excluded": excluded_imports, + "skipped_count": len(casaos_skipped), + "skipped": sorted(casaos_skipped, key=lambda item: item["path"]), + }, + "curated_profiles": {"included_count": len(curated_items)}, + }, + } + self._enrich_index_from_templates(payload) + self.catalog_dir.mkdir(parents=True, exist_ok=True) + self._write_json(self.index_path, payload) + return payload + + def _imported_exclusions(self) -> dict[str, str]: + if not self.exclusions_path.exists(): + return {} + payload = json.loads(self.exclusions_path.read_text(encoding="utf-8")) + return { + str(item["id"]): str(item["reason"]) + for item in payload.get("imported_applications", []) + } + + def load_index(self) -> dict[str, Any]: + if not self.index_path.exists(): + return self.sync_index() + payload = json.loads(self.index_path.read_text(encoding="utf-8")) + self._enrich_index_from_templates(payload) + return payload + + def categories(self) -> dict[str, Any]: + """Category labels and the per-application corrections of categories.json.""" + if self._categories is None: + try: + data = json.loads(self.categories_path.read_text(encoding="utf-8")) + except (OSError, json.JSONDecodeError): + data = {} + self._categories = {"labels": data.get("labels", {}), "applications": data.get("applications", {})} + return self._categories + + def _apply_category(self, app_id: str, ui: dict[str, Any]) -> None: + data = self.categories() + key = data["applications"].get(app_id) or ui.get("category") or "misc" + ui["category"] = key + ui["category_label"] = data["labels"].get(key) or ui.get("category_label") or key + + def volume_policy(self) -> dict[str, Any]: + """Paths of volume-policy.json that hold content of the user.""" + if self._volume_policy is None: + try: + data = json.loads(self.volume_policy_path.read_text(encoding="utf-8")) + except (OSError, json.JSONDecodeError): + data = {} + self._volume_policy = {"shared_paths": set(data.get("shared_paths", [])), + "applications": data.get("applications", {})} + return self._volume_policy + + def _apply_volume_policy(self, app_id: str, contract: dict[str, Any]) -> None: + """A path that holds content of the user is offered as a container + volume or as a host directory, and the installation asks which one; the + state of the application stays in a container volume without asking.""" + policy = self.volume_policy() + shared = policy["shared_paths"] | set(policy["applications"].get(app_id, [])) + for volume in contract.get("volumes", []): + choices = volume.get("installation_choice", []) + if "managed-volume" not in choices: + continue + optional = "skip" in choices + if volume["container_path"] in shared or volume.get("default") == "host-bind": + volume["installation_choice"] = ["managed-volume", "host-bind"] + (["skip"] if optional else []) + continue + volume["installation_choice"] = ["managed-volume"] + (["skip"] if optional else []) + if volume.get("default") not in volume["installation_choice"]: + volume["default"] = "managed-volume" + managed = volume.get("managed_volume") + if isinstance(managed, dict): + managed["default_size_gb"] = max(int(managed.get("default_size_gb") or 0), MINIMUM_VOLUME_GB) + + def _enrich_index_from_templates(self, payload: dict[str, Any]) -> None: + for item in payload.get("applications", []): + overlay_path = self.overlays_dir / f"{item['id']}.json" + overlay_ui = json.loads(overlay_path.read_text(encoding="utf-8")).get("catalog_ui", {}) if overlay_path.exists() else {} + item["hidden"] = overlay_ui.get("hidden", False) + path = self.apps_dir / f"{item['id']}.json" + if not path.exists(): + item["architectures"] = supported_architectures( + item.get("architectures", []) + ) + continue + try: + template = json.loads(path.read_text(encoding="utf-8")) + compatibility = template["compatibility"] + ui = template["catalog_ui"] + item["hidden"] = overlay_ui.get("hidden", ui.get("hidden", False)) + item["template_status"] = template["status"] + item["automatic_install_candidate"] = compatibility[ + "automatic_install_candidate" + ] + item["untranslated_blockers"] = compatibility[ + "untranslated_blockers" + ] + item["requires_privileged_lxc"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("requires_privileged_lxc") + ) + item["optional_privileged_lxc"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("optional_privileged_lxc") + ) + item["requires_host_pid_namespace"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("requires_host_pid_namespace") + ) + item["requires_relaxed_confinement"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("requires_relaxed_confinement") + ) + item["optional_relaxed_confinement"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("optional_relaxed_confinement") + ) + item["requires_security_confirmation"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("confirmation_required") + ) + item["architectures"] = supported_architectures( + overlay_ui.get("architectures", ui["architectures"])) + self._apply_category(item["id"], ui) + item["category"] = ui["category"] + item["category_label"] = ui["category_label"] + item["multi_container"] = is_multi_container(template) + except (OSError, json.JSONDecodeError, KeyError, TypeError): + item["automatic_install_candidate"] = False + item["untranslated_blockers"] = ["invalid-generated-template"] + + def find_repo(self, app_id: str) -> Repository: + item = self.find_item(app_id) + if item.get("provider", "linuxserver.io") == "linuxserver.io": + metadata = { + "category": item.get("category"), + "category_label": item.get("category_label"), + } + if not metadata["category"]: + try: + metadata.update(self.source.proxmenux_app_metadata().get(app_id, {})) + except (AttributeError, SourceError, OSError, RuntimeError): + pass + return self._repository_from_item(item, metadata) + raise ConversionError(f"The application '{app_id}' does not come from LinuxServer") + + def find_item(self, app_id: str) -> dict[str, Any]: + folded = app_id.casefold() + for item in self.load_index()["applications"]: + if item["id"].casefold() == folded: + return item + raise ConversionError(f"The application '{app_id}' is not in the index") + + @staticmethod + def _repository_from_item( + item: dict[str, Any], + metadata: dict[str, Any] | None = None, + ) -> Repository: + metadata = metadata or {} + return Repository( + name=item["repository_name"], + description=item.get("description") or "", + default_branch=item.get("default_branch") or "master", + html_url=item["repository"], + pushed_at=item.get("pushed_at") or "", + category=metadata.get("category") or item.get("category") or "misc", + category_label=metadata.get("category_label") or item.get("category_label") or "Miscellaneous", + ) + + def _preserve_registry_state(self, app_id: str, template: dict[str, Any]) -> None: + existing_path = self.apps_dir / f"{app_id}.json" + if not existing_path.exists(): + return + try: + existing = json.loads(existing_path.read_text(encoding="utf-8")) + state = existing.get("lifecycle", {}).get("registry_state", {}) + if not state.get("resolved_digest"): + return + template["lifecycle"]["registry_state"] = state + template["catalog_ui"]["display_version"] = existing.get("catalog_ui", {}).get("display_version") + except (OSError, json.JSONDecodeError, KeyError, TypeError): + return + + def generate(self, app_id: str) -> tuple[Path, dict[str, Any]]: + item = self.find_item(app_id) + provider = item.get("provider", "linuxserver.io") + if item.get("template_family", "linuxserver-readme") == "linuxserver-readme": + repo = self._repository_from_item(item) + readme, revision, raw_url = self.source.readme(repo) + template = convert_readme(repo, readme, revision, raw_url) + elif item.get("template_family") == "imported-compose": + revision = item["source_revision"] + compose, raw_url = self.source.casaos_compose(item["source_path"], revision) + template = convert_casaos_compose( + compose, + revision, + raw_url, + item["source_path"], + item.get("pushed_at") or "", + item.get("category"), + item.get("category_label"), + item["id"], + ) + elif item.get("template_family") == "curated-profile": + template = json.loads((self.root / item["curated_path"]).read_text(encoding="utf-8")) + else: + raise ConversionError(f"Proveedor no soportado: {provider}") + catalog_id = item["id"] + self._apply_overlay(catalog_id, template) + self._preserve_registry_state(catalog_id, template) + self.validate(template) + self.apps_dir.mkdir(parents=True, exist_ok=True) + destination = self.apps_dir / f"{catalog_id}.json" + self._write_json(destination, template) + self._update_index_template(catalog_id, template["status"]) + return destination, template + + def generate_all(self, progress: Any | None = None, provider: str = "all") -> dict[str, Any]: + index = self.load_index() + applications = [ + item + for item in index["applications"] + if provider == "all" + or (provider == "imported" and item.get("template_family") == "imported-compose") + or (provider == "curated" and item.get("template_family") == "curated-profile") + or item.get("provider", "linuxserver.io") == provider + ] + if any(item.get("template_family", "linuxserver-readme") == "linuxserver-readme" for item in applications) and not self.source.token: + raise ConversionError( + "Bulk generation requires GITHUB_TOKEN to obtain an immutable revision per application" + ) + generated: list[str] = [] + failed: list[dict[str, str]] = [] + templates: dict[str, dict[str, Any]] = {} + + def convert(item: dict[str, Any]) -> tuple[str, dict[str, Any]]: + item_provider = item.get("provider", "linuxserver.io") + if item.get("template_family", "linuxserver-readme") == "linuxserver-readme": + repo = self._repository_from_item(item) + readme, revision, raw_url = self.source.readme(repo) + template = convert_readme(repo, readme, revision, raw_url) + elif item.get("template_family") == "imported-compose": + revision = item["source_revision"] + compose, raw_url = self.source.casaos_compose(item["source_path"], revision) + template = convert_casaos_compose( + compose, + revision, + raw_url, + item["source_path"], + item.get("pushed_at") or "", + item.get("category"), + item.get("category_label"), + item["id"], + ) + elif item.get("template_family") == "curated-profile": + template = json.loads( + (self.root / item["curated_path"]).read_text(encoding="utf-8") + ) + else: + raise ConversionError(f"Proveedor no soportado: {item_provider}") + self._apply_overlay(item["id"], template) + self._preserve_registry_state(item["id"], template) + self.validate(template) + return item["id"], template + + completed = 0 + with ThreadPoolExecutor(max_workers=8) as executor: + futures = {executor.submit(convert, item): item for item in applications} + for future in as_completed(futures): + item = futures[future] + completed += 1 + try: + app_id, template = future.result() + templates[app_id] = template + generated.append(app_id) + outcome = "ok" + except (ConversionError, OSError, RuntimeError) as exc: + failed.append({"id": item["id"], "reason": str(exc)}) + outcome = "error" + if progress: + progress(completed, len(applications), item["id"], outcome) + + self.apps_dir.mkdir(parents=True, exist_ok=True) + index_items = {item["id"]: item for item in applications} + for app_id in sorted(templates): + template = templates[app_id] + self._write_json(self.apps_dir / f"{app_id}.json", template) + item = index_items[app_id] + item["template"] = f"apps/{app_id}.json" + item["template_status"] = template["status"] + item["automatic_install_candidate"] = template["compatibility"][ + "automatic_install_candidate" + ] + item["untranslated_blockers"] = template["compatibility"][ + "untranslated_blockers" + ] + item["requires_privileged_lxc"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("requires_privileged_lxc") + ) + item["optional_privileged_lxc"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("optional_privileged_lxc") + ) + item["requires_host_pid_namespace"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("requires_host_pid_namespace") + ) + item["requires_relaxed_confinement"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("requires_relaxed_confinement") + ) + item["optional_relaxed_confinement"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("optional_relaxed_confinement") + ) + item["requires_security_confirmation"] = bool( + template.get("proxmox", {}) + .get("security_profile", {}) + .get("confirmation_required") + ) + item["architectures"] = supported_architectures( + template["catalog_ui"]["architectures"] + ) + item["content_hash"] = self._template_hash(app_id) + self._write_json(self.index_path, index) + generated.sort() + failed.sort(key=lambda item: item["id"]) + report = { + "generated": generated, + "generated_count": len(generated), + "failed": failed, + "failed_count": len(failed), + } + report_name = "generation-report.json" if provider == "all" else f"generation-report-{provider}.json" + self._write_json(self.catalog_dir / report_name, report) + return report + + def validate(self, template: dict[str, Any], required: bool = True) -> None: + # Templates ship already validated; on a node without python3-jsonschema + # the installer skips the check instead of adding a package to the host. + try: + from jsonschema import Draft202012Validator + except ImportError: + if required: + raise ConversionError("python3-jsonschema is required to generate templates") + return + schema = json.loads(self.schema_path.read_text(encoding="utf-8")) + errors = sorted(Draft202012Validator(schema).iter_errors(template), key=lambda error: list(error.path)) + if errors: + details = "; ".join(f"{'/'.join(map(str, error.path))}: {error.message}" for error in errors) + raise ConversionError(f"La plantilla generada no cumple el esquema: {details}") + + def compose(self, app_id: str) -> dict[str, Any]: + """The installable template, built only from the files shipped with + ProxMenux: the curated profile or the pre-generated template, with its + overlay applied. Nothing is downloaded and nothing is written.""" + item = self.find_item(app_id) + if item.get("template_family") == "curated-profile": + path = self.root / item["curated_path"] + else: + path = self.apps_dir / f"{item['id']}.json" + if not path.exists(): + raise ConversionError(f"No template is available for '{app_id}'") + template = json.loads(path.read_text(encoding="utf-8")) + self._apply_overlay(item["id"], template) + self._apply_category(item["id"], template["catalog_ui"]) + self._apply_volume_policy(item["id"], template["container_contract"]) + self.validate(template, required=False) + return template + + def load_template(self, app_id: str, generate_if_missing: bool = True) -> dict[str, Any]: + path = self.apps_dir / f"{app_id}.json" + if not path.exists() and generate_if_missing: + _, template = self.generate(app_id) + return template + template = json.loads(path.read_text(encoding="utf-8")) + self.validate(template) + return template + + def _existing_template_statuses(self) -> dict[str, str]: + result: dict[str, str] = {} + if not self.apps_dir.exists(): + return result + for path in self.apps_dir.glob("*.json"): + try: + payload = json.loads(path.read_text(encoding="utf-8")) + result[path.stem] = payload.get("status", "unknown") + except (OSError, json.JSONDecodeError): + result[path.stem] = "invalid" + return result + + def _curated_items(self, existing: dict[str, str]) -> list[dict[str, Any]]: + result: list[dict[str, Any]] = [] + if not self.curated_dir.exists(): + return result + for path in sorted(self.curated_dir.glob("*.json")): + template = json.loads(path.read_text(encoding="utf-8")) + self.validate(template) + app_id = template["id"].removeprefix("image-") + ui = template["catalog_ui"] + result.append( + { + "id": app_id, + "provider": template["source"]["provider"], + "template_family": "curated-profile", + "title": ui["title"].get("en_US") or app_id, + "repository": template["source"]["repository"], + "description": ui["description"].get("en_US") or "", + "website": ui.get("website"), + "icon": ui.get("icon"), + "architectures": supported_architectures(ui["architectures"]), + "updated_at": ui.get("updated_at"), + "main_image": template["container_contract"]["image"]["reference"], + "category": ui["category"], + "category_label": ui.get("category_label"), + "replaces_discovered_ids": template.get("proxmox", {}) + .get("catalog", {}) + .get("replaces_discovered_ids", []), + "curated_path": str(path.relative_to(self.root)), + "template": f"apps/{app_id}.json" if app_id in existing else None, + "template_status": existing.get(app_id), + "content_hash": self._template_hash(app_id) if app_id in existing else None, + } + ) + return result + + def _apply_overlay(self, app_id: str, template: dict[str, Any]) -> None: + path = self.overlays_dir / f"{app_id}.json" + if path.exists(): + overlay = json.loads(path.read_text(encoding="utf-8")) + self._deep_merge(template, overlay) + from .stack import apply_stack_support + apply_stack_support(template) + from .gpu import apply_gpu_contract + apply_gpu_contract(template) + + @classmethod + def _deep_merge(cls, target: dict[str, Any], overlay: dict[str, Any]) -> None: + for key, value in overlay.items(): + if isinstance(value, dict) and isinstance(target.get(key), dict): + cls._deep_merge(target[key], value) + else: + target[key] = value + + def _update_index_template(self, app_id: str, status: str) -> None: + index = self.load_index() + template = json.loads((self.apps_dir / f"{app_id}.json").read_text(encoding="utf-8")) + ui = template["catalog_ui"] + for item in index["applications"]: + if item["id"] == app_id: + item.update( + { + "provider": template["source"]["provider"], + "title": ui["title"].get("en_US") or app_id, + "repository": template["source"]["repository"], + "description": ui["description"].get("en_US") or "", + "website": ui.get("website"), + "icon": ui.get("icon"), + "architectures": supported_architectures(ui["architectures"]), + "updated_at": ui.get("updated_at"), + "main_image": template["container_contract"]["image"]["reference"], + "category": ui["category"], + "category_label": ui.get("category_label"), + "template": f"apps/{app_id}.json", + "template_status": status, + "automatic_install_candidate": template["compatibility"][ + "automatic_install_candidate" + ], + "untranslated_blockers": template["compatibility"][ + "untranslated_blockers" + ], + "content_hash": self._template_hash(app_id), + } + ) + if item.get("template_family") == "curated-profile": + item["replaces_discovered_ids"] = ( + template.get("proxmox", {}) + .get("catalog", {}) + .get("replaces_discovered_ids", []) + ) + break + self._write_json(self.index_path, index) + + @staticmethod + def _write_json(path: Path, payload: dict[str, Any]) -> None: + temporary = path.with_suffix(path.suffix + ".tmp") + temporary.write_text(json.dumps(payload, ensure_ascii=True, indent=2) + "\n", encoding="utf-8") + temporary.replace(path) + + def _template_hash(self, app_id: str) -> str: + return hashlib.sha256((self.apps_dir / f"{app_id}.json").read_bytes()).hexdigest() diff --git a/oci/src/proxmenux_oci/cli.py b/oci/src/proxmenux_oci/cli.py new file mode 100644 index 00000000..b9f76e22 --- /dev/null +++ b/oci/src/proxmenux_oci/cli.py @@ -0,0 +1,622 @@ +"""OCI manager Apps: catalog menus, installation flow and maintenance commands.""" +from __future__ import annotations + +import argparse +import json +import sys +import textwrap +import unicodedata +from pathlib import Path +from typing import Any + +from . import console, images +from .catalog import Catalog +from .converter import ConversionError +from .github_source import SourceError +from .i18n import N_, source_text, translate +from .installer import ( + ADVANCED_MODE, + DEFAULT_MODE, + InstallError, + build_deployment, + build_rclone_mount_deployment, + redacted, + run_remote_install, + run_remote_rclone_mount, +) +from .ui import APP_TITLE, UserCancelled, interactive_ui + + +PROJECT_ROOT = Path(__file__).resolve().parents[2] +DISPLAY_ARCHITECTURES = ("amd64", "arm64") +PUBLISHERS = {"linuxserver.io": "LinuxServer", "official": N_("Official image")} +STACK_LABELS = { + "server": N_("Server"), + "application": N_("Application"), + "machine_learning": N_("Machine learning"), + "database": "PostgreSQL", + "valkey": "Valkey", + "cache": "Redis", + "paperless": "Paperless-ngx", + "broker": "Valkey", + "tandoor": "Tandoor", +} + + +def _display_architectures(item: dict[str, Any]) -> str: + supported = [a for a in DISPLAY_ARCHITECTURES if a in item.get("architectures", [])] + return "/".join(supported) or "?" + + +def publisher(item: dict[str, Any]) -> str: + provider = str(item.get("provider") or "") + app_id = str(item.get("id") or "").casefold() + # A project that publishes its own image (immich, frigate, nextcloud...) is its official image. + if provider == "official" or (provider and app_id.startswith(provider.casefold())): + return translate(PUBLISHERS["official"]) + return PUBLISHERS.get(provider, provider or "?") + + +def is_tested(item: dict[str, Any]) -> bool: + return item.get("template_status") == "laboratory-validated" + + +MENU_SIZE = (22, 75, 15) +MULTI_LABEL = r"\Z4MULTI\Zn" +TESTED_LABEL = r"\Z2✓\Zn" + + +def _installable(applications: list[dict[str, Any]]) -> list[dict[str, Any]]: + return [item for item in applications if not item.get("hidden") and item.get("automatic_install_candidate")] + + +NAME_WIDTH, ARCH_WIDTH, SOURCE_WIDTH = 26, 12, 14 +ROW_WIDTH = 72 + + +def _app_menu(applications: list[dict[str, Any]], keep_order: bool = False + ) -> tuple[list[tuple[str, str]], dict[str, dict[str, Any]], str]: + """Numbered rows in the Helper Scripts layout (name, architecture, source, + verified) and the column header aligned with them.""" + options: list[tuple[str, str]] = [] + index: dict[str, dict[str, Any]] = {} + ordered = applications if keep_order else sorted( + applications, key=lambda entry: str(entry.get("title") or entry["id"]).casefold()) + for number, item in enumerate(ordered, 1): + title = str(item.get("title") or item["id"]) + name = " ".join("".join(ch for ch in title if unicodedata.category(ch) != "So").split()) + if item.get("multi_container"): + name = name[:NAME_WIDTH - 6] + cell = f"{name} {MULTI_LABEL}" + " " * (NAME_WIDTH - len(name) - 6) + else: + cell = f"{name[:NAME_WIDTH]:<{NAME_WIDTH}}" + row = f"{cell} {_display_architectures(item):<{ARCH_WIDTH}} {publisher(item)[:SOURCE_WIDTH]:<{SOURCE_WIDTH}}" + if is_tested(item): + row += f" {TESTED_LABEL}" + # Rows as wide as the list: dialog centers narrower lists, which would move them off the header. + options.append((str(number), f"{row:<{ROW_WIDTH}}")) + index[str(number)] = item + # dialog draws the rows after the list border and the tag column. + offset = " " * (len(str(len(ordered))) + 3) + header = (f"{offset}{translate('Name')[:NAME_WIDTH]:<{NAME_WIDTH}} " + f"{translate('Architecture')[:ARCH_WIDTH]:<{ARCH_WIDTH}} " + f"{translate('Source')[:SOURCE_WIDTH]:<{SOURCE_WIDTH}} {translate('Verified')}") + return options, index, header + + +def _yes_no(value: Any) -> str: + return translate("yes") if value else translate("no") + + +# ---------------------------------------------------------------- summaries + +DETAIL_WIDTH = 92 +SERVICE_KINDS = (("postgres", "PostgreSQL"), ("valkey", "Valkey"), ("redis", "Redis"), ("mariadb", "MariaDB"), + ("mysql", "MySQL"), ("mongo", "MongoDB"), ("meilisearch", "Meilisearch")) + + +def _image_label(reference: str) -> str: + return str(reference or "").split("@", 1)[0] + + +def _service_kind(service: dict[str, Any]) -> str: + image = str(service.get("image") or "").casefold() + name = str(service.get("name") or "").casefold() + if service.get("is_main"): + return translate("Application") + if "machine-learning" in name or "machine-learning" in image: + return translate("Machine learning") + for key, label in SERVICE_KINDS: + if key in image: + return label + return translate("Service") + + +def _recommended_storage(volume: dict[str, Any]) -> str: + """What the installation uses for this path, and the alternative when the + user can choose; the recommended one comes first.""" + choices = set(volume.get("installation_choice", [])) + default = volume.get("default") + if {"managed-volume", "host-bind"} <= choices: + both = f"{translate('Container volume')} / {translate('Host directory')}" + return f"{translate('Optional')}: {both}" if default == "skip" else both + if default == "skip": + return translate("Optional, not mounted by default") + return translate("Host system path") if default == "host-bind" else translate("Container volume") + + +def _app_detail_text(catalog: Catalog, item: dict[str, Any], template: dict[str, Any]) -> str: + ui = template["catalog_ui"] + contract = template["container_contract"] + profile = template.get("proxmox", {}).get("installer_profile", {}) + lines = [rf"\Zb{source_text(ui.get('title')) or item['id']}\Zn", ""] + # The one-line tagline, not the full upstream description: it is what the + # reader needs to know what this is, it survives translation without + # drifting, and it goes through translate() like every other string. + description = translate(source_text(ui.get("tagline")) or source_text(ui.get("description"))) + if description: + wrapped = textwrap.wrap(description, DETAIL_WIDTH) + if len(wrapped) > 8: + wrapped = wrapped[:8] + wrapped[-1] = wrapped[-1].rstrip(" .,;") + "…" + lines += wrapped + [""] + + def row(label: str, value: str) -> None: + lines.append(f"{label + ':':<17} {value}") + + row(translate("Source"), publisher(item)) + row(translate("Status"), translate("Verified by ProxMenux") if is_tested(item) + else translate("Not yet verified by ProxMenux (beta)")) + row(translate("Architectures"), _display_architectures(ui)) + endpoints = template.get("first_run", {}).get("endpoints", []) + if endpoints: + row(translate("Web access"), ", ".join( + f"{e.get('scheme', 'http')}://:{e.get('port')}{e.get('path') or '/'}" for e in endpoints)) + + if profile.get("stack_driver") == "arr-suite": + row(translate("Type"), translate("Application suite: one independent LXC per selected application")) + defaults = set(profile.get("default_applications") or ("prowlarr", "sonarr", "radarr", "qbittorrent")) + lines += ["", translate("Applications you can choose:")] + for app_id in profile.get("applications") or []: + try: + child = catalog.compose(app_id) + image = child["container_contract"]["image"]["reference"] + name = source_text(child["catalog_ui"]["title"]) or app_id + except (ConversionError, OSError, ValueError, KeyError): + image, name = "", app_id + mark = f" ({translate('selected by default')})" if app_id in defaults else "" + lines.append(f" {name + mark:<34} {_image_label(image)}") + lines.append(f" {translate('Media server') + ':':<34} Jellyfin, Plex, Emby {translate('or none')}") + elif item.get("multi_container"): + services = template.get("compose_stack", {}).get("services", []) + row(translate("Type"), translate("Multi-container application (experimental)")) + lines += ["", translate("Containers that will be created (one LXC per service, on a private network):")] + for service in services: + lines.append(f" {_service_kind(service):<20} {_image_label(service.get('image'))}") + else: + row(translate("Image"), _image_label(contract["image"]["reference"])) + volumes = contract.get("volumes", []) + if volumes: + width = max(28, *(len(volume["container_path"]) + 2 for volume in volumes)) + lines += ["", f"{translate('Persistent data:'):<{width + 2}} {translate('Recommended')}"] + for volume in volumes: + lines.append(f" {volume['container_path']:<{width}} {_recommended_storage(volume)}") + if any({"managed-volume", "host-bind"} <= set(volume.get("installation_choice", [])) + for volume in volumes): + lines.append(translate("The installation asks which one to use for these paths.")) + + hardware = profile.get("hardware_acceleration", {}).get("profiles", []) + if hardware: + lines += ["", translate("Hardware acceleration options:")] + lines += [f" {' '.join(translate(p.get('label', p['id'])).split())}" for p in hardware] + security = template.get("proxmox", {}).get("security_profile", {}) + if security.get("requires_privileged_lxc"): + lines += ["", f"{translate('Security') + ':':<17} {translate('needs a privileged LXC')}"] + elif security.get("requires_relaxed_confinement"): + lines += ["", f"{translate('Security') + ':':<17} {translate('needs a relaxed AppArmor or seccomp profile')}"] + return "\n".join(lines) + + +def _deployment_summary_text(template: dict[str, Any], deployment: dict[str, Any]) -> str: + plan = redacted(deployment) + title = source_text(template["catalog_ui"]["title"]) or template["id"] + lines = [title, ""] + + def row(label: str, value: Any) -> None: + lines.append(f"{label + ':':<16} {value}") + + on = translate("on") + if plan.get("suite_arr"): + lines.append(translate("Independent applications, without a main container.")) + else: + row(translate("Image"), template["container_contract"]["image"]["reference"]) + + if plan.get("deployment_kind"): + base_vmid = plan.get("base_vmid") + row(translate("Stack"), plan.get("stack_name", title)) + row(translate("Base VMID"), base_vmid if base_vmid is not None else translate("next free block")) + services = template.get("compose_stack", {}).get("services", []) + if plan.get("deployment_kind") == "generic-multi-lxc-stack": + services = [dict(s, vmid_offset=s["offset"]) for s in plan["services"]] + for service in sorted(services, key=lambda item: item.get("vmid_offset", 0)): + offset = service.get("vmid_offset", 0) + vmid = base_vmid + offset if base_vmid is not None else f"base+{offset}" + lines.append(f" - {service['name']}: CT {vmid}") + lines.append("") + row("Rootfs", plan.get("rootfs_storage", "-")) + row(translate("Image cache"), plan.get("template_storage", "-")) + if plan.get("database_storage"): + row("PostgreSQL", f"{plan.get('database_size_gb', '-')} GB {on} {plan['database_storage']}") + for service in plan.get("services", []): + child = service["deployment"] + lines.append(f" {service['name']}: {child['resources']['cores']} CPU, " + f"{child['resources']['memory_mb']} MB RAM") + for mount in child["mounts"]: + target = (f"{mount['size_gb']} GB {on} {mount['source']}" + if mount["type"] == "managed-volume" else mount["source"]) + lines.append(f" {mount['container_path']} → {target}") + for key, label in (("media", "Library"), ("application", "Application data"), ("transfer", "Consume/export")): + storage = plan.get(key) + if isinstance(storage, dict) and "mode" in storage: + if storage["mode"] == "host-bind": + row(translate(label), f"{translate('host directory')} {storage.get('host_path', '-')}") + else: + row(translate(label), f"{storage.get('size_gb', '-')} GB {on} {storage.get('storage', '-')}") + else: + row(translate("Container"), f"CT {plan.get('vmid') or translate('next free')} · {plan.get('hostname', '-')}") + + resources = plan.get("resources", {}) + if resources: + row(translate("Resources"), f"{resources.get('cores', '-')} CPU · {resources.get('memory_mb', '-')} MB RAM · " + f"{resources.get('swap_mb', '-')} MB swap") + rootfs = plan.get("rootfs") + if rootfs: + row(translate("Storage"), f"rootfs {rootfs['size_gb']} GB {on} {rootfs['storage']} · " + f"{translate('image cache on')} {plan.get('template_storage', '-')}") + mounts = plan.get("mounts", []) + if mounts: + lines.append(f"{translate('Data') + ':':<16}") + for mount in mounts: + if mount["type"] == "host-bind": + target = f"{translate('host directory')} {mount['source']}" + else: + target = f"{translate('Container volume')} {mount.get('size_gb', '-')} GB {on} {mount['source']}" + if mount.get("backup"): + target += f" ({translate('in backups')})" + if mount.get("read_only"): + target += f" ({translate('read-only')})" + lines.append(f" {mount['container_path']} → {target}") + network = plan.get("network", {}) + if plan.get("host_monitor"): + row(translate("Network"), translate("IP address and firewall of the host")) + elif "frontend_bridge" in network: + addresses = [network[key] for key in ("frontend_ipv4", "machine_learning_frontend_ipv4") if network.get(key)] + addresses += [service["frontend_ipv4"] for service in plan.get("services", []) if service.get("frontend_ipv4")] + static = [address for address in addresses if address != "dhcp"] + row(translate("Network"), f"{network['frontend_bridge']} · {', '.join(static) if static else 'DHCP'}" + + (f" · gw {network['frontend_gateway']}" if network.get("frontend_gateway") else "") + + f" · {translate('private network assigned automatically')}") + elif network: + ipv4 = network.get("ipv4", "dhcp") + row(translate("Network"), f"{network.get('bridge', '-')} · {'DHCP' if ipv4 == 'dhcp' else ipv4}" + + (f" · gw {network['gateway']}" if network.get("gateway") else "")) + devices = plan.get("devices", []) + if plan.get("hardware_profile") or devices: + profiles = (template.get("proxmox", {}).get("installer_profile", {}) + .get("hardware_acceleration", {}).get("profiles", [])) + selected = next((p for p in profiles if p["id"] == plan.get("hardware_profile")), None) + profile_label = (translate(selected["label"]).split(" ")[0] if selected + else plan.get("hardware_profile") or translate("custom")) + row(translate("Acceleration"), + ", ".join([profile_label, *[d.get("host_path") or d.get("kind", "-") for d in devices]])) + security = plan.get("security") + if security: + row(translate("Security"), + translate("unprivileged LXC") if security.get("unprivileged") else translate("privileged LXC")) + environment = plan.get("environment", []) + if environment: + row(translate("Variables"), ", ".join(f"{item['name']}={item['value']}" for item in environment)) + if plan.get("suite_arr"): + lines += ["", *[translate(note) for note in plan.get("completion_notes", [])]] + lines.append("") + row(translate("Start"), f"{translate('when finished')}: {_yes_no(plan.get('start_after_create'))} · " + f"{translate('with Proxmox')}: {_yes_no(plan.get('onboot'))}") + return "\n".join(lines) + + +def _print_installation_summary(result: dict[str, Any], images_removed: str | None = None) -> None: + console.msg_title(translate("Installation completed")) + if result.get("suite_arr"): + console.msg_ok(translate("Independent LXC applications installed")) + else: + console.msg_ok(f"CT {result['vmid']} · {translate('IP address')}: " + f"{result.get('ip') or translate('not available yet')}") + for name, vmid in (result.get("stack_vmids") or {}).items(): + console.msg_ok(f"{translate(STACK_LABELS.get(name, name))}: CT {vmid}") + for item in result.get("urls") or []: + console.msg_ok(f"{translate(item['label'])}: {item['url']}") + for item in result.get("credentials") or []: + console.msg_info2(translate(item["label"])) + username = str(item["username"]) + console.msg_ok(f"{translate('User')}: {translate(username) if ' ' in username else username}") + if item.get("password") is not None: + console.msg_ok(f"{translate('Password')}: {item['password'] or translate('(empty)')}") + else: + console.msg_warn(translate("The password could not be retrieved automatically")) + if item.get("change_required"): + console.msg_warn(translate("Change it after the first login.")) + if images_removed: + console.msg_ok(images_removed) + for note in result.get("completion_notes") or []: + console.msg_note(translate(note)) + if result.get("log"): + console.msg_note(f"{translate('Installation log:')} {result['log']}") + print() + console.msg_note(translate("OCI manager Apps is a beta: if something does not work as expected, " + "please report it on GitHub with the application name.")) + + +# ---------------------------------------------------------------- menus + +def _install(catalog: Catalog, ui, item: dict[str, Any], mode: str) -> None: + install_template(ui, catalog.compose(item["id"]), item["id"], mode) + + +def install_template(ui, template: dict[str, Any], identifier: str, mode: str) -> dict[str, Any] | None: + """Configures and installs one template, from the catalog or written from a + definition the user gave.""" + deployment = build_deployment(template, ui, mode) + if not ui.review(_deployment_summary_text(template, deployment), translate("Installation summary"), + question=translate("Install with this configuration?")): + return None + console.show_logo() + console.msg_title(f"{source_text(template['catalog_ui']['title']) or identifier} · {APP_TITLE}") + try: + result = run_remote_install(PROJECT_ROOT, template, deployment, "auto") + except InstallError as exc: + console.msg_error(str(exc)) + console.wait_for_enter(translate("Press Enter to return to the menu...")) + return None + if result: + vmids = {int(v) for v in [result.get("vmid"), *(result.get("stack_vmids") or {}).values()] if v} + _, removed = images.offer_removal(ui, sorted(vmids)) + _print_installation_summary(result, removed) + console.wait_for_enter(translate("Press Enter to return to the menu...")) + return result + + +def _rclone_mount(catalog: Catalog, ui) -> None: + template = catalog.compose("rclone") + deployment = build_rclone_mount_deployment(template, ui) + console.show_logo() + console.msg_title(translate("Rclone mount")) + result = run_remote_rclone_mount(PROJECT_ROOT, template, deployment, "auto") + if result: + console.msg_ok(f"Remote: {result['remote']}:") + console.msg_ok(f"{translate('Read/write')}: {result['read_write_path']}") + console.msg_ok(f"{translate('Read-only')}: {result['read_only_path']}") + console.wait_for_enter(translate("Press Enter to return to the menu...")) + + +def _app_detail(catalog: Catalog, ui, item: dict[str, Any]) -> None: + template = catalog.compose(item["id"]) + actions = [] + if item.get("multi_container"): + actions.append(("advanced", translate("Install (experimental)"))) + else: + actions += [("default", translate("Install with default settings")), + ("advanced", translate("Install with advanced settings"))] + if item["id"] == "rclone": + actions.append(("mount", translate("Enable a mount on an existing Rclone OCI container"))) + numbered = {str(number): action for number, (action, _) in enumerate(actions, 1)} + options = [(str(number), label) for number, (_, label) in enumerate(actions, 1)] + title = source_text(template["catalog_ui"]["title"]) or item["id"] + selection = ui.detail_menu(_app_detail_text(catalog, item, template), options, "1", title=title) + action = numbered.get(selection or "") + if action is None: + return + if action == "mount": + _rclone_mount(catalog, ui) + return + _install(catalog, ui, item, DEFAULT_MODE if action == "default" else ADVANCED_MODE) + + +def _app_list(catalog: Catalog, ui, applications: list[dict[str, Any]], title: str, + keep_order: bool = False) -> None: + options, index, header = _app_menu(applications, keep_order) + selection = None + while True: + selection = ui.choose(header, options, selection, title=title, size=MENU_SIZE, colors=True) + if selection is None: + return + if selection in index: + _app_detail(catalog, ui, index[selection]) + + +def _search(catalog: Catalog, ui, applications: list[dict[str, Any]]) -> None: + query = ui.ask(translate("Name or part of the description of the application"), required=False).strip() + if not query: + return + folded = query.casefold() + + def rank(item: dict[str, Any]) -> int | None: + names = (item["id"].casefold(), str(item.get("title") or "").casefold()) + if folded in names: + return 0 + if any(name.startswith(folded) for name in names): + return 1 + if any(folded in name for name in names): + return 2 + return 3 if folded in str(item.get("description") or "").casefold() else None + + ranked = sorted(((rank(item), str(item.get("title") or item["id"]).casefold(), item) for item in applications + if rank(item) is not None), key=lambda entry: entry[:2]) + matches = [item for _, _, item in ranked] + if not matches: + ui.message(f"{translate('No applications match')}: '{query}'") + return + _app_list(catalog, ui, matches, f"{translate('Search results for:')} '{query}' ({len(matches)})", + keep_order=True) + + +def interactive(catalog: Catalog) -> int: + ui = interactive_ui() + if not catalog.index_path.exists(): + ui.message(translate("The OCI catalog is not installed. Update ProxMenux and try again.")) + return 1 + applications = _installable(catalog.load_index()["applications"]) + categories: dict[str, list[dict[str, Any]]] = {} + labels: dict[str, str] = {} + for item in applications: + key = item.get("category") or "misc" + categories.setdefault(key, []).append(item) + labels[key] = item.get("category_label") or key + order = sorted(categories, key=lambda key: (key == "misc", translate(labels[key]).casefold())) + category_by_index = {str(number): key for number, key in enumerate(order, 1)} + options = [ + ("search", translate("Search applications")), + ("all", f"{translate('All applications'):<35} ({len(applications):>3})"), + ("manage", translate("Manage installed OCI applications")), + ("custom", translate("Install an image that is not in the catalog")), + ("", ""), + ] + [(number, f"{translate(labels[key]):<35} ({len(categories[key]):>3})") + for number, key in category_by_index.items()] + selection = "search" + while True: + selection = ui.choose(translate("Select a category or search for applications:"), options, selection, + size=MENU_SIZE) + if selection is None: + return 0 + try: + if selection == "search": + _search(catalog, ui, applications) + elif selection == "all": + _app_list(catalog, ui, applications, + f"{translate('All applications')} ({len(applications)})") + elif selection == "manage": + from .management import interactive_management + interactive_management(PROJECT_ROOT, ui) + elif selection == "custom": + from .custom import explore + explore(ui) + elif selection in category_by_index: + key = category_by_index[selection] + _app_list(catalog, ui, categories[key], translate(labels[key])) + except UserCancelled: + continue + except (ConversionError, InstallError, OSError, ValueError) as exc: + console.stop_spinner() + ui.message(f"{translate('The operation could not be completed')}:\n\n{exc}") + + +# ---------------------------------------------------------------- maintenance CLI + +def _template_summary_text(template: dict[str, Any]) -> str: + contract = template["container_contract"] + lines = [ + source_text(template["catalog_ui"]["title"]), + f"Image: {contract['image']['reference']}", + f"Status: {template['status']}", + "Ports: " + (", ".join(f"{p['container_port']}/{p['protocol']}" for p in contract["ports"]) or "none"), + "Volumes: " + (", ".join(v["container_path"] for v in contract["volumes"]) or "none"), + ] + blockers = template["compatibility"]["untranslated_blockers"] + if blockers: + lines.append(f"Blockers: {', '.join(blockers)}") + return "\n".join(lines) + + +def build_parser() -> argparse.ArgumentParser: + parser = argparse.ArgumentParser(prog="oci_manager_apps.sh", + description="ProxMenux OCI manager Apps (beta)") + subparsers = parser.add_subparsers(dest="command") + subparsers.add_parser("sync", help="Refresh the index from the image sources") + list_parser = subparsers.add_parser("list", help="List applications") + list_parser.add_argument("--filter", default="") + generate_parser = subparsers.add_parser("generate", help="Regenerate the template of one application") + generate_parser.add_argument("app") + generate_all_parser = subparsers.add_parser("generate-all", help="Regenerate the catalog templates") + generate_all_parser.add_argument("--provider", choices=["all", "linuxserver.io", "imported", "curated"], + default="all") + show_parser = subparsers.add_parser("show", help="Show the summary of a template") + show_parser.add_argument("app") + install_parser = subparsers.add_parser("install", help="Configure and install an application") + install_parser.add_argument("app") + install_parser.add_argument("--host", default="auto", help="'auto'/'local', or root@IP for development") + install_parser.add_argument("--advanced", action="store_true") + install_parser.add_argument("--dry-run", action="store_true") + rclone_parser = subparsers.add_parser("rclone-mount", help="Enable a mount on an installed Rclone OCI") + rclone_parser.add_argument("--host", default="auto") + rclone_parser.add_argument("--dry-run", action="store_true") + return parser + + +def main(argv: list[str] | None = None) -> int: + args = build_parser().parse_args(argv) + catalog = Catalog(PROJECT_ROOT) + try: + if not args.command: + return interactive(catalog) + if args.command == "sync": + payload = catalog.sync_index() + print(f"Index updated: {len(payload['applications'])} candidate applications") + return 0 + if args.command == "list": + query = args.filter.casefold() + for item in catalog.load_index()["applications"]: + if not item.get("hidden", False) and query in item["id"].casefold(): + candidate = item.get("automatic_install_candidate") + status = ("installable" if candidate else "pending adaptation" if candidate is False + else item.get("template_status") or "not generated") + print(f"{item['id']:<30} {_display_architectures(item):<12} {publisher(item):<14} {status}") + return 0 + if args.command == "generate": + path, template = catalog.generate(args.app) + print(f"{_template_summary_text(template)}\n\n{path}") + return 0 + if args.command == "generate-all": + def progress(current: int, total: int, app_id: str, outcome: str) -> None: + marker = "OK" if outcome == "ok" else "ERROR" + print(f"\r[{current:3}/{total}] {marker:<5} {app_id:<32}", end="", flush=True) + + report = catalog.generate_all(progress=progress, provider=args.provider) + print(f"\nGenerated: {report['generated_count']}; failed: {report['failed_count']}; " + f"family: {args.provider}") + return 0 if not report["failed"] else 2 + if args.command == "show": + print(_template_summary_text(catalog.compose(args.app))) + return 0 + if args.command == "install": + template = catalog.compose(args.app) + if not template["compatibility"]["automatic_install_candidate"]: + raise InstallError("Installation blocked: " + ", ".join(template["compatibility"]["untranslated_blockers"])) + deployment = build_deployment(template, None, ADVANCED_MODE if args.advanced else DEFAULT_MODE) + print(_deployment_summary_text(template, deployment)) + if not args.dry_run and input("\nInstall? [y/N]: ").strip().casefold() not in {"y", "yes"}: + print("Installation cancelled.") + return 0 + result = run_remote_install(PROJECT_ROOT, template, deployment, args.host, args.dry_run) + if result: + _print_installation_summary(result) + return 0 + if args.command == "rclone-mount": + template = catalog.compose("rclone") + deployment = build_rclone_mount_deployment(template) + print(json.dumps(deployment, ensure_ascii=False, indent=2)) + result = run_remote_rclone_mount(PROJECT_ROOT, template, deployment, args.host, args.dry_run) + if result: + print(f"Read/write: {result['read_write_path']}\nRead-only: {result['read_only_path']}") + return 0 + return 1 + except (KeyboardInterrupt, UserCancelled): + console.stop_spinner() + print(f"\n{translate('Operation cancelled.')}") + return 130 + except (ConversionError, SourceError, InstallError, OSError, ValueError) as exc: + console.stop_spinner() + print(f"ERROR: {exc}", file=sys.stderr) + return 1 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/oci/src/proxmenux_oci/console.py b/oci/src/proxmenux_oci/console.py new file mode 100644 index 00000000..f58a43c4 --- /dev/null +++ b/oci/src/proxmenux_oci/console.py @@ -0,0 +1,134 @@ +"""Terminal output in the ProxMenux style of utils.sh (msg_info, msg_ok, ...).""" +from __future__ import annotations + +import os +import shutil +import subprocess +import sys +import textwrap +import threading + +from .i18n import BASE_DIR + +MG = "\033[1;35m" +GN = "\033[1;92m" +RD = "\033[01;31m" +YW = "\033[33m" +YWB = "\033[1;33m" +BL = "\033[36m" +BOLD = "\033[1m" +CL = "\033[m" +BFR = "\r\033[K" +TAB = " " +HOLD = "-" +CM = f"{GN}✓ {CL}" +FRAMES = ("⠋", "⠙", "⠹", "⠸", "⠼", "⠴", "⠦", "⠧", "⠇", "⠏") + +_spinner: tuple[threading.Thread, threading.Event] | None = None + + +def _write(text: str) -> None: + sys.stdout.write(text) + sys.stdout.flush() + + +def _spin(stop: threading.Event) -> None: + index = 0 + _write("\033[?25l") + while not stop.wait(0.1): + _write(f"\r {MG}{FRAMES[index]}{CL}") + index = (index + 1) % len(FRAMES) + + +def stop_spinner(clear_line: bool = True) -> None: + global _spinner + if _spinner is not None: + thread, stop = _spinner + stop.set() + thread.join() + _spinner = None + if clear_line: + _write("\r\033[K") + _write("\033[?25h") + + +def msg_info(text: str) -> None: + global _spinner + stop_spinner() + _write(f"{TAB}{MG}{HOLD}{text}") + if sys.stdout.isatty(): + stop = threading.Event() + thread = threading.Thread(target=_spin, args=(stop,), daemon=True) + _spinner = (thread, stop) + thread.start() + else: + _write("\n") + + +def msg_ok(text: str) -> None: + stop_spinner(clear_line=False) + _write(f"{BFR}{TAB}{CM}{GN}{text}{CL}\n") + + +def msg_warn(text: str) -> None: + stop_spinner(clear_line=False) + _write(f"{BFR}{TAB}{CL} {YWB}{text}{CL}\n") + + +def msg_error(text: str) -> None: + stop_spinner(clear_line=False) + _write(f"{BFR}{TAB}{RD}[ERROR] {text}{CL}\n") + + +def msg_info2(text: str) -> None: + _write(f"{TAB}{BOLD}{YW}{HOLD} {text}{CL}\n") + + +def msg_note(text: str) -> None: + """Closing information, in the colour ProxMenux uses for paths and values.""" + stop_spinner(clear_line=False) + _write(f"{TAB}{BL}{text}{CL}\n") + + +def msg_success(text: str) -> None: + stop_spinner(clear_line=False) + _write(f"{TAB}{BOLD}{BL}{HOLD}{text}{CL}\n\n") + + +def ask_yes_no(text: str, default_yes: bool = True) -> bool: + """A question asked in the middle of the output: whiptail draws over the + terminal and restores it, so what was printed stays on screen.""" + width = 74 + lines = sum(max(1, len(textwrap.wrap(line, width - 6) or [''])) for line in text.splitlines() or ['']) + widget = ['whiptail', '--backtitle', 'ProxMenux', '--title', 'ProxMenux', + '--yesno', text, str(min(lines + 8, 20)), str(width)] + if not default_yes: + widget.insert(1, '--defaultno') + if shutil.which('whiptail'): + environment = dict(os.environ, NEWT_COLORS_FILE='/dev/null') + return subprocess.run(widget, env=environment, check=False).returncode == 0 + answer = input(f"{text} [{'Y/n' if default_yes else 'y/N'}]: ").strip().casefold() + return default_yes if not answer else answer in {'y', 'yes', 's', 'si'} + + +def msg_title(text: str) -> None: + _write(f"\n\n{TAB}{BOLD}{HOLD} | {text} | {HOLD}{CL}\n\n\n") + + +def show_logo() -> None: + """The ProxMenux banner; like show_proxmenux_logo it clears the screen.""" + stop_spinner() + utils = BASE_DIR / "utils.sh" + if utils.is_file() and sys.stdout.isatty(): + subprocess.run(["bash", "-c", 'source "$1" >/dev/null 2>&1; show_proxmenux_logo', "_", str(utils)], + check=False) + elif sys.stdout.isatty(): + _write("\033[H\033[2J") + + +def wait_for_enter(text: str) -> None: + msg_success(text) + try: + input() + except EOFError: + pass diff --git a/oci/src/proxmenux_oci/converter.py b/oci/src/proxmenux_oci/converter.py new file mode 100644 index 00000000..d0c84000 --- /dev/null +++ b/oci/src/proxmenux_oci/converter.py @@ -0,0 +1,1664 @@ +from __future__ import annotations + +import hashlib +import math +import re +from datetime import datetime, timezone +from typing import Any + +import yaml + +from .github_source import Repository + + +SUPPORTED_SERVICE_KEYS = { + "cap_add", + "command", + "container_name", + "cpu_shares", + "devices", + "entrypoint", + "environment", + "extra_hosts", + "group_add", + "healthcheck", + "hostname", + "image", + "init", + "ipc", + "labels", + "logging", + "mac_address", + "mem_limit", + "networks", + "network_mode", + "ports", + "privileged", + "restart", + "runtime", + "security_opt", + "shm_size", + "stdin_open", + "stop_grace_period", + "sysctls", + "tty", + "ulimits", + "user", + "volumes", + "working_dir", +} + +LINUX_CAPABILITIES = { + "AUDIT_CONTROL", "AUDIT_READ", "AUDIT_WRITE", "BLOCK_SUSPEND", "BPF", + "CHECKPOINT_RESTORE", "CHOWN", "DAC_OVERRIDE", "DAC_READ_SEARCH", "FOWNER", + "FSETID", "IPC_LOCK", "IPC_OWNER", "KILL", "LEASE", "LINUX_IMMUTABLE", + "MAC_ADMIN", "MAC_OVERRIDE", "MKNOD", "NET_ADMIN", "NET_BIND_SERVICE", + "NET_BROADCAST", "NET_RAW", "PERFMON", "SETFCAP", "SETGID", "SETPCAP", + "SETUID", "SYS_ADMIN", "SYS_BOOT", "SYS_CHROOT", "SYS_MODULE", "SYS_NICE", + "SYS_PACCT", "SYS_PTRACE", "SYS_RAWIO", "SYS_RESOURCE", "SYS_TIME", + "SYS_TTY_CONFIG", "SYSLOG", "WAKE_ALARM", +} + +SENSITIVE_NAME = re.compile( + r"(?:PASS|PASSWORD|TOKEN|SECRET|API_?KEY|PRIVATE_KEY|CREDENTIAL|(?:^|_)KEY(?:$|_))", + re.I, +) + + +class ConversionError(RuntimeError): + pass + + +def extract_compose(readme: str) -> str: + lines = readme.splitlines() + heading_index = next( + ( + index + for index, line in enumerate(lines) + if re.match(r"^#{2,5}\s+docker-compose\b", line.strip(), flags=re.I) + ), + None, + ) + if heading_index is None: + raise ConversionError("El README no contiene una seccion docker-compose reconocible") + + fence_start = next( + (index for index in range(heading_index + 1, len(lines)) if lines[index].strip().startswith("```")), + None, + ) + if fence_start is None: + raise ConversionError("La seccion docker-compose no contiene un bloque de codigo") + fence_end = next( + (index for index in range(fence_start + 1, len(lines)) if lines[index].strip() == "```"), + None, + ) + if fence_end is None: + raise ConversionError("El bloque docker-compose no esta cerrado") + + compose = "\n".join(lines[fence_start + 1 : fence_end]).strip() + "\n" + if "services:" not in compose: + raise ConversionError("El bloque encontrado no parece un Docker Compose") + return compose + + +def _optional_markers(compose: str) -> dict[str, set[str]]: + markers: dict[str, set[str]] = { + key: set() + for key in ("environment", "volumes", "ports", "devices", "security_opt") + } + active: str | None = None + active_indent = -1 + for line in compose.splitlines(): + stripped = line.strip() + indent = len(line) - len(line.lstrip()) + section_match = re.match( + r"^(environment|volumes|ports|devices|security_opt):\s*$", stripped + ) + if section_match: + active = section_match.group(1) + active_indent = indent + continue + if active and stripped and indent <= active_indent: + active = None + if active and "optional" in stripped.casefold() and "#" in stripped: + value = stripped.split("#", 1)[0].strip().removeprefix("- ").strip("'\"") + markers[active].add(value) + if active == "environment" and "=" in value: + markers[active].add(value.split("=", 1)[0]) + return markers + + +def _environment_contract(value: Any, optional: set[str]) -> list[dict[str, Any]]: + result: list[dict[str, Any]] = [] + if value is None: + return result + entries: list[tuple[str, Any]] = [] + if isinstance(value, dict): + entries = list(value.items()) + elif isinstance(value, list): + for item in value: + text = str(item) + name, separator, raw_value = text.partition("=") + entries.append((name, raw_value if separator else None)) + else: + raise ConversionError("environment debe ser una lista o un objeto") + + for name, raw_value in entries: + name = str(name) + result.append( + { + "name": name, + "example": None if raw_value is None else str(raw_value), + "required": name not in optional, + "sensitive": bool(SENSITIVE_NAME.search(name)), + "source": "linuxserver-compose", + } + ) + return result + + +def _environment_names(value: Any) -> set[str]: + if isinstance(value, dict): + return {str(name) for name in value} + if isinstance(value, list): + return {str(item).partition("=")[0] for item in value} + return set() + + +def _split_short_mount(value: str) -> tuple[str | None, str, str | None]: + parts = value.split(":") + if len(parts) == 1: + return None, parts[0], None + if len(parts) == 2: + return parts[0], parts[1], None + return ":".join(parts[:-2]), parts[-2], parts[-1] + + +def _mount_contract(value: Any, optional: set[str]) -> list[dict[str, Any]]: + if value is None: + return [] + if not isinstance(value, list): + raise ConversionError("volumes debe ser una lista") + result: list[dict[str, Any]] = [] + for index, item in enumerate(value): + if isinstance(item, dict): + source = item.get("source") + target = item.get("target") + read_only = bool(item.get("read_only", False)) + raw = str(target or "") + else: + raw = str(item) + source, target, mode = _split_short_mount(raw) + read_only = mode == "ro" + if not target or not str(target).startswith("/"): + raise ConversionError(f"Ruta de volumen no valida: {item!r}") + target = str(target) + runtime_socket = target in {"/var/run/docker.sock", "/run/docker.sock"} + source_text = str(source or "") + system_files = { + "/etc/group", "/etc/hosts", "/etc/localtime", "/etc/os-release", + "/etc/passwd", "/etc/resolv.conf", "/etc/timezone", "/lib/modules", + } + system_prefixes = ("/dev/", "/proc/", "/sys/", "/run/", "/var/run/") + system_bind = ( + target in system_files + or source_text in system_files + or target.startswith(system_prefixes) + or source_text.startswith(system_prefixes) + ) + is_optional = runtime_socket or raw in optional or any( + marker.endswith(f":{target}") for marker in optional + ) + private_default = target == "/config" or not is_optional + choices = ( + ["host-bind", "skip"] + if runtime_socket or (system_bind and is_optional) + else ["host-bind"] + if system_bind + else ["managed-volume", "host-bind"] + (["skip"] if is_optional else []) + ) + result.append( + { + "id": f"volume-{index}", + "container_path": target, + "compose_source_example": None if source is None else str(source), + "read_only": read_only, + "required": not is_optional, + "installation_choice": choices, + "default": ( + "host-bind" + if system_bind and not is_optional + else "managed-volume" + if private_default + else "skip" + ), + "managed_volume": { + "backup": target not in {"/cache", "/tmp", "/transcode"}, + "default_size_gb": 4 if target == "/config" else 8, + }, + } + ) + return result + + +def _port_contract(value: Any, optional: set[str]) -> list[dict[str, Any]]: + if value is None: + return [] + if not isinstance(value, list): + raise ConversionError("ports debe ser una lista") + result: list[dict[str, Any]] = [] + for item in value: + if isinstance(item, dict): + container = item.get("target") + published = item.get("published") + protocol = item.get("protocol", "tcp") + raw = str(container) + else: + raw = str(item) + port_text, slash, protocol = raw.rpartition("/") + if not slash: + port_text, protocol = raw, "tcp" + parts = port_text.split(":") + container = parts[-1] + published = parts[-2] if len(parts) > 1 else None + def port_span(raw_port: Any) -> tuple[int, int | None]: + text = str(raw_port) + if "-" in text: + start_text, end_text = text.split("-", 1) + start, end = int(start_text), int(end_text) + if end < start: + raise ValueError + return start, end + return int(text), None + + try: + container_port, container_port_end = port_span(container) + if published is None: + published_port, published_port_end = None, None + else: + published_port, published_port_end = port_span(published) + except ValueError as exc: + raise ConversionError(f"Puerto no valido: {item!r}") from exc + contract = { + "container_port": container_port, + "published_example": published_port, + "protocol": str(protocol), + "required": raw not in optional, + "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat", + } + if container_port_end is not None: + contract["container_port_end"] = container_port_end + if published_port_end is not None: + contract["published_example_end"] = published_port_end + result.append(contract) + return result + + +def _image_contract(image: str) -> dict[str, Any]: + digest = None + without_digest = image + if "@" in image: + without_digest, digest = image.rsplit("@", 1) + slash_index = without_digest.rfind("/") + colon_index = without_digest.rfind(":") + if colon_index > slash_index: + repository, tag = without_digest[:colon_index], without_digest[colon_index + 1 :] + reference = image + else: + repository, tag = without_digest, "latest" + reference = f"{repository}:latest" if digest is None else image + registry = repository.split("/", 1)[0] if "." in repository.split("/", 1)[0] else "docker.io" + return { + "reference": reference, + "registry": registry, + "repository": repository, + "tag": tag, + "digest": digest, + "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install", + } + + +def _image_name(image: Any) -> str: + value = str(image or "").split("@", 1)[0] + return value.rsplit("/", 1)[-1].split(":", 1)[0] + + +def _catalog_identifier(app_id: str) -> str: + normalized = re.sub(r"[^a-z0-9]+", "-", app_id.casefold()).strip("-") + if not normalized: + raise ConversionError(f"No se puede normalizar el identificador: {app_id!r}") + return f"linuxserver-{normalized}" + + +def _duration_seconds(value: Any) -> int | None: + if value in (None, ""): + return None + text = str(value).strip().casefold() + units = {"s": 1, "m": 60, "h": 3600} + matches = list(re.finditer(r"(\d+)([smh])", text)) + if not matches or "".join(match.group(0) for match in matches) != text: + return None + return sum(int(match.group(1)) * units[match.group(2)] for match in matches) + + +def _shm_size_mb(value: Any) -> int | None: + if value in (None, ""): + return None + if isinstance(value, (int, float)) and not isinstance(value, bool): + if not math.isfinite(value): + return None + return max(1, math.ceil(float(value) / (1024 * 1024))) if value > 0 else None + match = re.fullmatch( + r"\s*(\d+(?:\.\d+)?)\s*(b|k|kb|ki|kib|m|mb|mi|mib|g|gb|gi|gib)?\s*", + str(value), + flags=re.I, + ) + if not match: + return None + number = float(match.group(1)) + if number <= 0: + return None + unit = (match.group(2) or "b").casefold() + factors = { + "b": 1 / (1024 * 1024), + "k": 1 / 1024, + "kb": 1 / 1024, + "ki": 1 / 1024, + "kib": 1 / 1024, + "m": 1, + "mb": 1, + "mi": 1, + "mib": 1, + "g": 1024, + "gb": 1024, + "gi": 1024, + "gib": 1024, + } + return max(1, math.ceil(number * factors[unit])) + + +def _shm_installer_profile(value: Any) -> dict[str, Any]: + size_mb = _shm_size_mb(value) + if size_mb is None: + return {} + return { + "tmpfs_mounts": [ + { + "id": "compose-shm", + "container_path": "/dev/shm", + "default_size_mb": size_mb, + "minimum_size_mb": 1, + "size_prompt": "Size of the /dev/shm shared memory in MB", + "mount_options": ["rw", "nosuid", "nodev"], + } + ] + } + + +def _healthcheck_installer_profile(value: Any) -> dict[str, Any]: + if not isinstance(value, dict) or value.get("disable") is True: + return {} + test = value.get("test") + if isinstance(test, list): + command = " ".join(str(item) for item in test) + elif isinstance(test, str): + command = test + else: + return {} + if re.search(r"(?:^|\s)NONE(?:\s|$)", command, flags=re.I): + return {} + match = re.search( + r"https?://(?:localhost|127\.0\.0\.1)(?::(?P\d+))?(?P/[^\s'\"]*)?", + command, + flags=re.I, + ) + if not match: + return {} + scheme = match.group(0).split(":", 1)[0].casefold() + port = int(match.group("port") or (443 if scheme == "https" else 80)) + if not 1 <= port <= 65535: + return {} + interval = _duration_seconds(value.get("interval")) or 30 + request_timeout = _duration_seconds(value.get("timeout")) or 5 + start_period = _duration_seconds(value.get("start_period")) or 0 + try: + retries = max(1, int(value.get("retries", 3))) + except (TypeError, ValueError): + return {} + return { + "startup_healthcheck": { + "type": "http", + "scheme": scheme, + "port": port, + "path": match.group("path") or "/", + "timeout_seconds": max(30, start_period + interval * retries), + "request_timeout_seconds": max(1, request_timeout), + "stability_seconds": 0, + "verify_tls": scheme != "https", + "required": True, + "source": "compose-healthcheck", + } + } + + +def _extra_hosts(value: Any) -> list[dict[str, str]] | None: + if value is None: + return [] + entries: list[tuple[Any, Any]] = [] + if isinstance(value, dict): + entries = list(value.items()) + elif isinstance(value, list): + for item in value: + if not isinstance(item, str): + return None + host, separator, address = item.partition("=") + if not separator: + host, separator, address = item.partition(":") + if not separator: + return None + entries.append((host, address)) + else: + return None + result: list[dict[str, str]] = [] + for raw_host, raw_address in entries: + host = str(raw_host).strip() + address = str(raw_address).strip() + if not re.fullmatch(r"[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?", host): + return None + if address != "host-gateway" and not re.fullmatch(r"[0-9A-Fa-f:.]+", address): + return None + result.append({"hostname": host, "address": address}) + return result + + +def _device_mapping(item: Any) -> tuple[str, str] | None: + if isinstance(item, str): + source, target, _ = _split_short_mount(item) + source = source or target + elif isinstance(item, dict): + source = item.get("source") or item.get("path") + target = item.get("target") or source + else: + return None + source = str(source or "").strip() + target = str(target or "").strip() + if not source.startswith("/dev/") or not target.startswith("/dev/"): + return None + if any(part == ".." for part in source.split("/")) or any( + part == ".." for part in target.split("/") + ): + return None + return source, target + + +def _nvidia_requested(service: dict[str, Any]) -> bool: + if str(service.get("runtime") or "").casefold() == "nvidia": + return True + reservations = ( + (((service.get("deploy") or {}).get("resources") or {}).get("reservations") or {}) + .get("devices") + or [] + ) + return any( + isinstance(item, dict) + and str(item.get("driver") or "").casefold() == "nvidia" + and "gpu" in {str(value).casefold() for value in item.get("capabilities") or []} + for item in reservations + ) + + +def _device_request( + source: str, + target: str, + *, + optional: bool, + nvidia_requested: bool, +) -> dict[str, Any]: + slug = re.sub(r"[^a-z0-9]+", "-", source.casefold()).strip("-") + labels = { + "/dev/dri": ("VA-API video acceleration", "GPU render device"), + "/dev/snd": ("Host audio devices", "Audio device directory"), + "/dev/dvb": ("Host DVB tuners", "DVB device directory"), + "/dev/bus/usb": ("Host USB bus", "USB bus directory"), + } + if source == "/dev/dri": + return { + "id": "vaapi-render", + "kind": "character-device", + "purpose": "vaapi", + "enable_prompt": labels[source][0], + "enabled_default": not optional and not nvidia_requested, + "required_by_compose": not optional, + "path_prompt": labels[source][1], + "host_path_default": "/dev/dri/renderD128", + "container_path_strategy": "same-as-host", + "mode": "0660", + "deny_write": False, + "gid_strategy": "host-device-gid", + "source_mapping": f"{source}:{target}", + } + if source in {"/dev/snd", "/dev/dvb", "/dev/bus/usb"}: + enable_label, path_label = labels[source] + return { + "id": slug, + "kind": "character-device-tree", + "purpose": { + "/dev/snd": "audio", + "/dev/dvb": "dvb", + "/dev/bus/usb": "usb", + }[source], + "enable_prompt": enable_label, + "enabled_default": not optional, + "required_by_compose": not optional, + "path_prompt": path_label, + "host_path_default": source, + "container_path": target, + "mode": "preserve-host", + "deny_write": False, + "gid_strategy": "host-device-gid", + "source_mapping": f"{source}:{target}", + } + purpose = "generic-device" + if source == "/dev/kvm": + purpose = "kvm" + elif source == "/dev/net/tun": + purpose = "tun" + elif source == "/dev/fuse": + purpose = "fuse" + elif source.startswith("/dev/video"): + purpose = "video-capture" + elif source.startswith("/dev/tty"): + purpose = "serial" + elif source in {"/dev/vchiq", "/dev/vcsm"}: + purpose = "raspberry-pi-media" + return { + "id": slug, + "kind": "character-device", + "purpose": purpose, + "enable_prompt": f"Pass {source} to the LXC", + "enabled_default": not optional, + "required_by_compose": not optional, + "path_prompt": f"Host device for {source}", + "host_path_default": source, + "container_path": target, + "mode": "preserve-host", + "deny_write": False, + "gid_strategy": "host-device-gid", + "source_mapping": f"{source}:{target}", + } + + +def _device_installer_profile( + service: dict[str, Any], optional: set[str] | None = None +) -> tuple[dict[str, Any], list[str]]: + optional = optional or set() + raw_devices = service.get("devices") + requests: list[dict[str, Any]] = [] + blockers: list[str] = [] + nvidia_requested = _nvidia_requested(service) + if raw_devices is not None: + if not isinstance(raw_devices, list): + blockers.append("devices-format") + else: + for item in raw_devices: + raw = str(item).split("#", 1)[0].strip().strip("'\"") + if "/path/to/device" in raw: + is_optional = raw in optional + requests.append( + { + "id": "user-selected-device", + "kind": "character-device", + "purpose": "user-selected-device", + "enable_prompt": "Pass a host device to the LXC", + "enabled_default": not is_optional, + "required_by_compose": not is_optional, + "path_prompt": "Actual device path on the host", + "host_path_default": "/dev/ttyUSB0", + "container_path_strategy": "same-as-host", + "mode": "preserve-host", + "deny_write": False, + "gid_strategy": "host-device-gid", + "source_mapping": raw, + } + ) + continue + mapping = _device_mapping(item) + if mapping is None: + blockers.append(f"device-mapping:{item}") + continue + source, target = mapping + is_optional = raw in optional or any( + marker.startswith(f"{source}:") for marker in optional + ) + request = _device_request( + source, + target, + optional=is_optional, + nvidia_requested=nvidia_requested, + ) + if request["id"] not in {item["id"] for item in requests}: + requests.append(request) + if nvidia_requested: + requests.insert( + 0, + { + "id": "nvidia-runtime", + "kind": "nvidia-runtime", + "purpose": "nvidia-cuda-nvenc-nvdec", + "enable_prompt": "Enable the NVIDIA GPU requested by the image", + "enabled_default": True, + "required_by_compose": True, + "risk_level": "hardware-access", + "device_selection": "all-requested-by-compose", + "driver_libraries": "bind-compatible-host-driver-libraries-read-only", + }, + ) + return ({"device_requests": requests} if requests else {}), blockers + + +def _merge_installer_profile(target: dict[str, Any], extra: dict[str, Any]) -> None: + for key, value in extra.items(): + if isinstance(value, list): + target.setdefault(key, []).extend(value) + elif isinstance(value, dict): + target.setdefault(key, {}).update(value) + else: + target[key] = value + + +def _network_mode(value: Any) -> str | None: + if value in (None, ""): + return None + mode = str(value).casefold() + return mode if mode in {"bridge", "default", "host"} else "" + + +def _capability_contract(value: Any) -> list[str] | None: + if value is None: + return [] + if not isinstance(value, list): + return None + result: list[str] = [] + for item in value: + capability = str(item).strip().upper().removeprefix("CAP_") + if capability not in LINUX_CAPABILITIES: + return None + if capability not in result: + result.append(capability) + return result + + +def _host_module_requirements( + service: dict[str, Any], capabilities: list[str] | None +) -> list[dict[str, Any]] | None: + if not capabilities or "SYS_MODULE" not in capabilities: + return [] + image = str(service.get("image") or "").casefold() + if any(marker in image for marker in ("wireguard", "wg-easy", "uusec/firefly")): + return [ + { + "name": "wireguard", + "enable_prompt": "Load and verify the WireGuard module on the Proxmox host", + "enabled_default": True, + "required_by_compose": True, + } + ] + return None + + +def _sysctl_contract(value: Any) -> list[dict[str, str]] | None: + if value is None: + return [] + entries: list[tuple[Any, Any]] = [] + if isinstance(value, dict): + entries = list(value.items()) + elif isinstance(value, list): + for item in value: + if not isinstance(item, str): + return None + name, separator, raw_value = item.partition("=") + if not separator: + return None + entries.append((name, raw_value)) + else: + return None + result: list[dict[str, str]] = [] + for raw_name, raw_value in entries: + name = str(raw_name).strip() + sysctl_value = str(raw_value).strip() + # Restrict this generic adapter to kernel settings known to be + # namespaced; host-global sysctls need an application review. + if not re.fullmatch(r"net\.(?:ipv4|ipv6)\.[A-Za-z0-9_.-]+", name): + return None + if not sysctl_value or any(char in sysctl_value for char in "\r\n"): + return None + result.append({"name": name, "value": sysctl_value}) + return result + + +def _security_options_contract(value: Any) -> dict[str, Any] | None: + if value is None: + return {} + if not isinstance(value, list): + return None + result: dict[str, Any] = {} + for item in value: + option = str(item).strip().casefold() + if option in {"no-new-privileges:true", "no-new-privileges=true"}: + result["no_new_privileges"] = True + elif option == "seccomp:unconfined": + result["seccomp_profile"] = "unconfined" + elif option == "apparmor:unconfined": + result["apparmor_profile"] = "unconfined" + elif option == "apparmor:rootlesskit": + result["apparmor_profile"] = "unconfined" + result["apparmor_source_profile"] = "rootlesskit" + elif option == "label:disable": + result["selinux_label_disabled"] = True + else: + return None + return result + + +def _security_option_sets( + value: Any, optional: set[str] | None = None +) -> tuple[dict[str, Any] | None, list[dict[str, Any]] | None]: + if value is None: + return {}, [] + if not isinstance(value, list): + return None, None + optional = {item.casefold() for item in (optional or set())} + required_items: list[Any] = [] + optional_items: list[Any] = [] + for item in value: + target = optional_items if str(item).strip().casefold() in optional else required_items + target.append(item) + required = _security_options_contract(required_items) + if required is None: + return None, None + optional_contracts: list[dict[str, Any]] = [] + for item in optional_items: + options = _security_options_contract([item]) + if options is None: + return None, None + slug = re.sub(r"[^a-z0-9]+", "-", str(item).casefold()).strip("-") + optional_contracts.append( + { + "id": slug, + "enable_prompt": f"Apply optional security relaxation {item}", + "enabled_default": False, + "options": options, + } + ) + return required, optional_contracts + + +def _supplemental_groups(value: Any) -> list[str] | None: + if value is None: + return [] + if not isinstance(value, list): + return None + result: list[str] = [] + for item in value: + group = str(item).strip() + if not re.fullmatch(r"(?:[0-9]+|[A-Za-z_][A-Za-z0-9_.-]*)", group): + return None + if group not in result: + result.append(group) + return result + + +RLIMIT_NAMES = {'as', 'core', 'cpu', 'data', 'fsize', 'locks', 'memlock', + 'msgqueue', 'nice', 'nofile', 'nproc', 'rss', 'rtprio', + 'rttime', 'sigpending', 'stack'} + + +def _ulimits_contract(value: Any) -> list[dict[str, str]] | None: + if value is None: + return [] + if not isinstance(value, dict): + return None + result = [] + for name, limit in value.items(): + if name not in RLIMIT_NAMES: + return None + pair = limit if isinstance(limit, dict) else {'soft': limit, 'hard': limit} + if set(pair) != {'soft', 'hard'}: + return None + if any(type(v) is not int or not -1 <= v <= 999999999999999999 for v in pair.values()): + return None + soft, hard = pair['soft'], pair['hard'] + if hard != -1 and (soft == -1 or soft > hard): + return None + result.append({'name': name, 'soft': 'unlimited' if soft == -1 else str(soft), + 'hard': 'unlimited' if hard == -1 else str(hard)}) + return result + + +def _compose_option_blockers( + service: dict[str, Any], optional_devices: set[str] | None = None +) -> list[str]: + blockers: list[str] = [] + if service.get('mem_limit') is not None: + memory = _shm_size_mb(service['mem_limit']) + if memory is None or memory < 16: + blockers.append('mem-limit-format-or-below-proxmox-minimum') + deploy_memory = (((service.get('deploy') or {}).get('resources') or {}).get('limits') or {}).get('memory') + if deploy_memory is not None and str(service['mem_limit']) != str(deploy_memory): + blockers.append('mem-limit-deploy-consistency-review') + if _ulimits_contract(service.get('ulimits')) is None: + blockers.append('ulimits-format-or-resource') + if service.get("healthcheck") is not None and not _healthcheck_installer_profile( + service["healthcheck"] + ): + healthcheck = service["healthcheck"] + if not (isinstance(healthcheck, dict) and healthcheck.get("disable") is True): + blockers.append("healthcheck-format") + if service.get("extra_hosts") is not None and _extra_hosts(service["extra_hosts"]) is None: + blockers.append("extra-hosts-format") + if service.get("cpu_shares") is not None: + try: + if int(service["cpu_shares"]) <= 0: + raise ValueError + except (TypeError, ValueError): + blockers.append("cpu-shares-format") + if service.get("user") is not None and not isinstance(service["user"], (str, int)): + blockers.append("user-format") + if service.get("entrypoint") is not None and not ( + isinstance(service["entrypoint"], str) + or ( + isinstance(service["entrypoint"], list) + and all(isinstance(item, str) for item in service["entrypoint"]) + ) + ): + blockers.append("entrypoint-format") + if service.get("working_dir") is not None and not re.fullmatch( + r"/[^\r\n]*", str(service["working_dir"]) + ): + blockers.append("working-dir-format") + logging = service.get("logging") + if logging is not None and not ( + isinstance(logging, dict) + and logging.get("driver", "json-file") in {"json-file", "local"} + ): + blockers.append("logging-driver") + mac_address = service.get("mac_address") + if mac_address is not None and not re.fullmatch( + r"[0-9A-Fa-f]{2}(?::[0-9A-Fa-f]{2}){5}", str(mac_address) + ): + blockers.append("mac-address-format") + _, device_blockers = _device_installer_profile(service, optional_devices) + blockers.extend(device_blockers) + runtime = service.get("runtime") + if runtime is not None and str(runtime).casefold() != "nvidia": + blockers.append(f"runtime-value:{runtime}") + ipc = service.get("ipc") + if ipc is not None and str(ipc).casefold() != "host": + blockers.append(f"ipc-value:{ipc}") + if service.get("network_mode") is not None and _network_mode(service["network_mode"]) == "": + blockers.append(f"network-mode-value:{service['network_mode']}") + capabilities = _capability_contract(service.get("cap_add")) + if capabilities is None: + blockers.append("cap-add-format") + elif _host_module_requirements(service, capabilities) is None: + blockers.append("capability-host-global:SYS_MODULE") + if service.get("sysctls") is not None and _sysctl_contract(service["sysctls"]) is None: + blockers.append("sysctls-format-or-nonnamespaced") + if service.get("security_opt") is not None and _security_options_contract( + service["security_opt"] + ) is None: + blockers.append("security-options-value") + if service.get("group_add") is not None and _supplemental_groups( + service["group_add"] + ) is None: + blockers.append("group-add-format") + return blockers + + +def _compose_installer_profile( + service: dict[str, Any], + optional_devices: set[str] | None = None, + optional_security: set[str] | None = None, +) -> dict[str, Any]: + profile = _shm_installer_profile(service.get("shm_size")) + if str(service.get("image", "")).split("@", 1)[0].split(":", 1)[0] == "lscr.io/linuxserver/libreoffice": + # LXC's volatile /run hides the directory shipped in the OCI rootfs. + profile.setdefault("tmpfs_mounts", []).append({ + "id": "nginx-runtime", + "container_path": "/run/nginx", + "default_size_mb": 1, + "minimum_size_mb": 1, + "prompt_size": False, + "mount_options": ["rw", "nosuid", "nodev", "mode=0755"], + }) + profile["startup_healthcheck"] = { + "scheme": "https", "port": 3001, "path": "/", + "timeout_seconds": 180, "request_timeout_seconds": 10, + "stability_seconds": 4, "verify_tls": False, + } + memory = _shm_size_mb(service.get('mem_limit')) + if memory is not None and memory >= 16: + profile.setdefault('resources', {})['memory_default_mb'] = memory + limits = _ulimits_contract(service.get('ulimits')) + if limits: + profile.setdefault('resources', {})['rlimits'] = limits + healthcheck = _healthcheck_installer_profile(service.get("healthcheck")) + if healthcheck: + profile.update(healthcheck) + if "command" in service and service["command"] is not None: + profile.setdefault("runtime", {})["command"] = service["command"] + if "entrypoint" in service and service["entrypoint"] is not None: + profile.setdefault("runtime", {})["compose_entrypoint"] = service["entrypoint"] + if service.get("working_dir") is not None: + profile.setdefault("runtime", {})["working_directory"] = str(service["working_dir"]) + if service.get("user") is not None: + profile.setdefault("runtime", {})["user"] = str(service["user"]) + supplemental_groups = _supplemental_groups(service.get("group_add")) + if supplemental_groups: + profile.setdefault("runtime", {})["supplemental_groups"] = supplemental_groups + if service.get("hostname") is not None: + profile.setdefault("runtime", {})["hostname"] = str(service["hostname"]) + if service.get("cpu_shares") is not None: + profile.setdefault("resources", {})["cpu_shares"] = int(service["cpu_shares"]) + extra_hosts = _extra_hosts(service.get("extra_hosts")) + if extra_hosts: + profile["extra_hosts"] = extra_hosts + mac_address = str(service.get("mac_address") or "") + if mac_address and mac_address != "00:00:00:00:00:00": + profile.setdefault("network", {})["mac_address"] = mac_address.casefold() + if "SETTINGS_ENCRYPTION_KEY" in _environment_names(service.get("environment")): + profile.setdefault("generated_sensitive_environment", {})[ + "SETTINGS_ENCRYPTION_KEY" + ] = {"strategy": "token-hex", "bytes": 16, "prompt": False} + device_profile, _ = _device_installer_profile(service, optional_devices) + _merge_installer_profile(profile, device_profile) + if str(service.get("ipc") or "").casefold() == "host" and "tmpfs_mounts" not in profile: + profile["tmpfs_mounts"] = [ + { + "id": "compose-ipc-shm", + "container_path": "/dev/shm", + "default_size_mb": 1024, + "minimum_size_mb": 64, + "size_prompt": "Shared memory size for the GPU workload in MB", + "mount_options": ["rw", "nosuid", "nodev"], + } + ] + network_mode = _network_mode(service.get("network_mode")) + if network_mode: + profile.setdefault("network", {})["compose_mode"] = network_mode + capabilities = _capability_contract(service.get("cap_add")) + sysctls = _sysctl_contract(service.get("sysctls")) + if capabilities: + profile.setdefault("security", {})["required_capabilities"] = capabilities + host_modules = _host_module_requirements(service, capabilities) + if host_modules: + profile.setdefault("security", {})["host_modules"] = host_modules + if sysctls: + profile.setdefault("security", {})["sysctls"] = sysctls + security_options, optional_relaxations = _security_option_sets( + service.get("security_opt"), optional_security + ) + if security_options: + profile.setdefault("security", {})["options"] = security_options + if optional_relaxations: + profile.setdefault("security", {})["optional_relaxations"] = optional_relaxations + return profile + + +def _compose_requests_privileged_lxc(service: dict[str, Any]) -> bool: + return service.get("privileged") in (True, 1, "true", "True") + + +def _compose_security_profile( + service: dict[str, Any], optional_security: set[str] | None = None +) -> dict[str, Any]: + requests_privileged = _compose_requests_privileged_lxc(service) + requests_host_pid = str(service.get("pid") or "").casefold() == "host" + options, optional_relaxations = _security_option_sets( + service.get("security_opt"), optional_security + ) + options = options or {} + optional_relaxations = optional_relaxations or [] + requires_relaxed = options.get("apparmor_profile") == "unconfined" or options.get( + "seccomp_profile" + ) == "unconfined" + optional_relaxed = any( + item["options"].get("apparmor_profile") == "unconfined" + or item["options"].get("seccomp_profile") == "unconfined" + for item in optional_relaxations + ) + if not requests_privileged and not requests_host_pid and not requires_relaxed and not optional_relaxed: + return {} + warnings: list[str] = [] + if requests_privileged: + warnings.append( + "The source Compose requests privileged: true, but this does not prove " + "that the image needs a privileged LXC. ProxMenux will use an unprivileged " + "LXC by default and will offer the broad mode only as an option." + ) + if requests_host_pid: + warnings.append( + "The Compose requests pid: host to observe host processes. This is " + "namespace access distinct from privileged and does not yet have a " + "validated safe translation for LXC." + ) + if requires_relaxed: + warnings.append( + "The image requests disabling part of the AppArmor or seccomp confinement." + ) + if optional_relaxed: + warnings.append( + "The Compose offers an optional AppArmor or seccomp relaxation; it will stay " + "disabled unless the user selects it." + ) + all_security_options = [options, *(item["options"] for item in optional_relaxations)] + if any(item.get("apparmor_source_profile") == "rootlesskit" for item in all_security_options): + warnings.append( + "The Docker rootlesskit profile does not exist in LXC and will be replaced by " + "AppArmor unconfined, which is less restrictive." + ) + return { + "requires_privileged_lxc": False, + "source_requests_privileged_lxc": requests_privileged, + "optional_privileged_lxc": requests_privileged, + "requires_host_pid_namespace": requests_host_pid, + "source_requests_relaxed_confinement": requires_relaxed or optional_relaxed, + "requires_relaxed_confinement": requires_relaxed, + "optional_relaxed_confinement": optional_relaxed, + "risk_level": "high", + "confirmation_required": requires_relaxed, + "warning": " ".join(warnings) + " Continue only if you trust the image and accept this risk.", + } + + +def _compose_runtime_adaptations(service: dict[str, Any]) -> list[dict[str, str]]: + def state(*keys: str) -> str: + return ( + "pending-per-application" + if any(key in service for key in keys) + else "not-requested-by-compose" + ) + + return [ + { + "id": "compose-process-runtime", + "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", + "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", + "reason": "The OCI process must start with the same identity, command and working directory without Docker.", + "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", + "validation": state( + "entrypoint", "user", "group_add", "working_dir", "init", "stdin_open", "tty" + ), + }, + { + "id": "compose-healthcheck", + "upstream_behavior": "Docker periodically executes the declared container healthcheck.", + "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", + "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", + "behavioral_impact": "The check runs during installation rather than continuously after installation.", + "validation": state("healthcheck"), + }, + { + "id": "compose-cpu-priority", + "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", + "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", + "reason": "Both settings express relative CPU priority on different scales.", + "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", + "validation": state("cpu_shares"), + }, + { + "id": "compose-resource-limits", + "upstream_behavior": "mem_limit sets the memory ceiling; ulimits sets process soft/hard resource limits.", + "native_lxc_behavior": "mem_limit supplies the editable Proxmox memory default, rounded up to MiB; ulimits maps to lxc.prlimit with -1 represented as unlimited.", + "reason": "Use native Proxmox memory and LXC prlimits, without a wrapper or changing the host kernel configuration.", + "behavioral_impact": "User-selected memory overrides Compose. Swap is a separate choice. Kernel restrictions still apply; nproc counts processes by real UID, not by container.", + "validation": state("mem_limit", "ulimits"), + }, + { + "id": "compose-network-identity", + "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", + "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", + "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", + "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", + "validation": state("hostname", "mac_address", "extra_hosts", "networks"), + }, + { + "id": "compose-network-mode", + "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", + "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", + "reason": "The LXC is the application host and already has its own address and port namespace.", + "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", + "validation": state("network_mode"), + }, + { + "id": "compose-capabilities-and-sysctls", + "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", + "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", + "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", + "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", + "validation": state("cap_add", "sysctls"), + }, + { + "id": "docker-engine-metadata", + "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", + "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", + "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", + "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", + "validation": state("labels", "logging"), + }, + { + "id": "compose-device-passthrough", + "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", + "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", + "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", + "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", + "validation": state("devices", "runtime"), + }, + { + "id": "compose-host-ipc", + "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", + "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", + "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", + "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", + "validation": state("ipc"), + }, + ] + + +def _title_from_readme(readme: str, fallback: str) -> str: + for line in readme.splitlines(): + match = re.match(r"^#\s+\[(?:linuxserver/)?([^\]]+)\]", line, flags=re.I) + if not match: + match = re.match(r"^#\s+(?:linuxserver/)?(.+?)\s*$", line, flags=re.I) + if match: + return match.group(1).strip().replace("-", " ").title() + return fallback.replace("-", " ").title() + + +def _application_intro(readme: str) -> tuple[str, str | None]: + found_title = False + for line in readme.splitlines(): + if not found_title: + if re.match(r"^#\s+", line): + found_title = True + continue + stripped = line.strip() + if not stripped or stripped.startswith("[![") or stripped.startswith("